From: Rasmus Villemoes <ravi@prevas.dk>
To: meta-arm@lists.yoctoproject.org
Cc: Jon Mason <jon.mason@arm.com>,
Jan Kiszka <jan.kiszka@siemens.com>,
Jan Luebbe <jlu@pengutronix.de>,
Rasmus Villemoes <ravi@prevas.dk>
Subject: [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends
Date: Thu, 27 Aug 2026 15:37:19 +0200 [thread overview]
Message-ID: <20260827133720.3246210-1-ravi@prevas.dk> (raw)
From: Rasmus Villemoes <ravi@prevas.dk>
If two different .bbappends both try to add an "early TA" by appending
an EARLY_TA_PATHS="..." to EXTRA_OEMAKE, only one of them will
actually take effect.
For example, meta-arm itself has a .bbappend in optee-ftpm which adds
the ftpm TA if optee-ftpm is in MACHINE_FEATURES. If the BSP developer
wants to add another early TA, he has to take that into account and
very carefully ensure to create an EARLY_TA_PATHS="..." argument which
contains both the ftpm value as well as his desired extra TA.
Instead, let the main recipe define a variable which can simply be
appended to in the normal way, and which is used for deriving the
single EARLY_TA_PATHS="" argument in the make command line.
Handle the in-tree TAs similarly.
Signed-off-by: Rasmus Villemoes <ravi@prevas.dk>
---
meta-arm/recipes-security/optee/optee-os.inc | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/meta-arm/recipes-security/optee/optee-os.inc b/meta-arm/recipes-security/optee/optee-os.inc
index 95c41fb1..b90e379a 100644
--- a/meta-arm/recipes-security/optee/optee-os.inc
+++ b/meta-arm/recipes-security/optee/optee-os.inc
@@ -35,6 +35,21 @@ EXTRA_OEMAKE += " CROSS_COMPILE64=${HOST_PREFIX}"
# Enable BTI in optee
EXTRA_OEMAKE += "${@bb.utils.contains('MACHINE_FEATURES', 'arm-branch-protection', ' CFG_TA_BTI=1 CFG_CORE_PAUTH=y CFG_TA_PAUTH=y', '', d)}"
+# If several .bbappends wants to add an early TA, and they both do
+# EXTRA_OEMAKE += 'EARLY_TA_PATHS="..."', only one of them will take
+# effect. Instead, create a bitbake variable holding the entire list,
+# which the .bbappends can append to, and add a single EARLY_TA_PATHS=
+# to the make cmdline here. Similarly for the in-tree ones.
+#
+# Note that it is not necessary to explicitly pass CFG_EARLY_TA=y as
+# the build systems sets that itself if either list is non-empty (and
+# errors out if CFG_EARLY_TA was explicitly set to n).
+EARLY_TA_PATHS = ""
+CFG_IN_TREE_EARLY_TAS = ""
+
+EXTRA_OEMAKE += "${@'EARLY_TA_PATHS="' + d.getVar('EARLY_TA_PATHS') + '"' if d.getVar('EARLY_TA_PATHS') else ''}"
+EXTRA_OEMAKE += "${@'CFG_IN_TREE_EARLY_TAS="' + d.getVar('CFG_IN_TREE_EARLY_TAS') + '"' if d.getVar('CFG_IN_TREE_EARLY_TAS') else ''}"
+
LDFLAGS[unexport] = "1"
CPPFLAGS[unexport] = "1"
AS[unexport] = "1"
--
2.55.0
next reply other threads:[~2026-08-27 13:37 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-27 13:37 Rasmus Villemoes [this message]
2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes
2026-08-27 17:00 ` Jan Kiszka
2026-09-04 9:36 ` Rasmus Villemoes
2026-09-04 9:47 ` Jan Kiszka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260827133720.3246210-1-ravi@prevas.dk \
--to=ravi@prevas.dk \
--cc=jan.kiszka@siemens.com \
--cc=jlu@pengutronix.de \
--cc=jon.mason@arm.com \
--cc=meta-arm@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.