All of lore.kernel.org
 help / color / mirror / Atom feed
From: Atharv Dubey <a-dubey@ti.com>
To: <meta-ti@lists.yoctoproject.org>, <reatmon@ti.com>
Cc: <denys@konsulko.com>, <a-limaye@ti.com>, <u-kumar1@ti.com>,
	<m-chawdhry@ti.com>
Subject: [meta-ti][master][PATCH v5 1/3] dm-verity-upstream: Add dynamic layer for meta-security dm-verity
Date: Mon, 5 Oct 2026 17:42:16 +0530	[thread overview]
Message-ID: <20261005121218.844998-1-a-dubey@ti.com> (raw)

Add an optional dynamic layer enabling dm-verity block-level integrity
verification of the root filesystem for TI K3 platforms, using
meta-security's stock dm-verity mechanism as-is. Requires meta-security
to be present in bblayers.conf.

dm-verity hashes the rootfs at build time; at boot, a dedicated
initramfs loads the root hash and the kernel checks every block read
against it. Set DM_VERITY_IMAGE to enable all the verity-related
recipes for that image; other images build as usual.

Signed-off-by: Atharv Dubey <a-dubey@ti.com>

---
v5:
 - unify the python functions
v4:
 - Use ti-core-initramfs instead of a separate dm-verity initramfs
 - Instead of a DISTRO_FEATURE, just check if DM_VERITY_IMAGE is set
v3:
 - Disabled the automount rules from udev-aragoconf, so don't need the
   ignorelist for dm-verity
v2:
 - Replaced hardcoded /dev/mmcblk1p2 with a PARTUUID
---
 meta-ti-bsp/conf/layer.conf                   |  3 +++
 meta-ti-bsp/conf/machine/include/k3.inc       |  7 +++++++
 .../conf/include/dm-verity-upstream.inc       | 21 +++++++++++++++++++
 .../udev/udev-aragoconf_%.bbappend            |  5 +++++
 .../udev/udev-extraconf_%.bbappend            |  6 ++++++
 meta-ti-bsp/files/wic/k3-verity.wks.in        |  5 +++++
 6 files changed, 47 insertions(+)
 create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
 create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
 create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
 create mode 100644 meta-ti-bsp/files/wic/k3-verity.wks.in

diff --git a/meta-ti-bsp/conf/layer.conf b/meta-ti-bsp/conf/layer.conf
index 3cc54aa4..aca35cd3 100644
--- a/meta-ti-bsp/conf/layer.conf
+++ b/meta-ti-bsp/conf/layer.conf
@@ -20,12 +20,15 @@ LAYERDEPENDS_meta-ti-bsp = " \
 LAYERRECOMMENDS_meta-ti-bsp = " \
     openembedded-layer \
     tpm-layer \
+    security \
 "
 
 BBFILES_DYNAMIC += " \
     openembedded-layer:${LAYERDIR}/dynamic-layers/openembedded-layer/recipes*/*/*.bbappend \
     tpm-layer:${LAYERDIR}/dynamic-layers/tpm-layer/recipes*/*/*.bb \
     tpm-layer:${LAYERDIR}/dynamic-layers/tpm-layer/recipes*/*/*.bbappend \
+    security:${LAYERDIR}/dynamic-layers/security-layer/recipes*/*/*.bb \
+    security:${LAYERDIR}/dynamic-layers/security-layer/recipes*/*/*.bbappend \
 "
 
 SIGGEN_EXCLUDERECIPES_ABISAFE += " \
diff --git a/meta-ti-bsp/conf/machine/include/k3.inc b/meta-ti-bsp/conf/machine/include/k3.inc
index 2ebbfb9e..f19db45f 100644
--- a/meta-ti-bsp/conf/machine/include/k3.inc
+++ b/meta-ti-bsp/conf/machine/include/k3.inc
@@ -64,3 +64,10 @@ FALCON_INCLUDE = ""
 FALCON_INCLUDE:ti-falcon = "conf/machine/include/ti-falcon.inc"
 
 require ${FALCON_INCLUDE}
+
+# dm-verity protects the rootfs listed in DM_VERITY_IMAGE; see dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc for what that turns on.
+DM_VERITY_IMAGE ??= ""
+
+DM_VERITY_UPSTREAM_INCLUDE = "${@'dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc' if d.getVar('DM_VERITY_IMAGE') else ''}"
+
+require ${DM_VERITY_UPSTREAM_INCLUDE}
diff --git a/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc b/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
new file mode 100644
index 00000000..e9353fcc
--- /dev/null
+++ b/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
@@ -0,0 +1,21 @@
+# Enables dm-verity to check the rootfs for tampering on TI K3 boards.
+DM_VERITY_IMAGE_TYPE = "ext4"
+IMAGE_CLASSES += "dm-verity-img"
+
+# ti-core-initramfs.bbappend already wires the initramfs into the boot partition once dm-verity is enabled, so we don't need to do it here.
+
+python () {
+    import uuid
+
+    if d.getVar('PN') != d.getVar('DM_VERITY_IMAGE'):
+        return
+
+    # Derive the root partition's UUID from MACHINE so everyone computes the same one.
+    if not d.getVar('DM_VERITY_ROOT_PARTUUID'):
+        d.setVar('DM_VERITY_ROOT_PARTUUID',
+                 str(uuid.uuid5(uuid.NAMESPACE_DNS, 'dm-verity-root-%s' % d.getVar('MACHINE'))))
+
+    d.setVar('WKS_FILE', 'k3-verity.wks.in')
+    d.appendVar('EXTRA_IMAGE_FEATURES', ' read-only-rootfs')
+    d.appendVar('WICVARS', ' DM_VERITY_IMAGE DM_VERITY_IMAGE_TYPE IMAGE_NAME_SUFFIX IMGDEPLOYDIR DM_VERITY_ROOT_PARTUUID')
+}
diff --git a/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
new file mode 100644
index 00000000..e5f6c1b2
--- /dev/null
+++ b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
@@ -0,0 +1,5 @@
+do_install:append() {
+    if ${@'true' if d.getVar('DM_VERITY_IMAGE') else 'false'}; then
+        : > ${D}${libdir}/udev/rules.d/50-arago.rules
+    fi
+}
diff --git a/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
new file mode 100644
index 00000000..a14e21ea
--- /dev/null
+++ b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
@@ -0,0 +1,6 @@
+# Nothing should ever get auto-mounted under dm-verity, so just kill the automounter.
+do_install:append() {
+    if ${@'true' if d.getVar('DM_VERITY_IMAGE') else 'false'}; then
+        : > ${D}${sysconfdir}/udev/rules.d/automount.rules
+    fi
+}
diff --git a/meta-ti-bsp/files/wic/k3-verity.wks.in b/meta-ti-bsp/files/wic/k3-verity.wks.in
new file mode 100644
index 00000000..62ae0ec1
--- /dev/null
+++ b/meta-ti-bsp/files/wic/k3-verity.wks.in
@@ -0,0 +1,5 @@
+# Disk layout for a board that boots with dm-verity enabled.
+
+bootloader --timeout=3 --append="rootfstype=ext4 root=PARTUUID=${DM_VERITY_ROOT_PARTUUID} ${TI_WKS_BOOTLOADER_APPEND}"
+part --source bootimg-efi --sourceparams="loader=${EFI_PROVIDER}${TI_WKS_INITRAMFS}" --fstype=vfat --label boot --active --align 1024 --use-uuid --fixed-size 128M
+part / --source rawcopy --sourceparams="file=${IMGDEPLOYDIR}/${DM_VERITY_IMAGE}-${MACHINE}${IMAGE_NAME_SUFFIX}.${DM_VERITY_IMAGE_TYPE}.verity" --align 1024 --uuid ${DM_VERITY_ROOT_PARTUUID}
-- 
2.34.1



             reply	other threads:[~2026-10-05 12:12 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 12:12 Atharv Dubey [this message]
2026-10-05 12:12 ` [meta-ti][master][PATCH v5 2/3] linux-ti-staging: Add dm-verity kernel config Atharv Dubey
2026-10-05 12:12 ` [meta-ti][master][PATCH v5 3/3] ti-core-initramfs: Extend with dm-verity support Atharv Dubey
2026-10-05 12:15 ` [meta-ti][master][PATCH v5 1/3] dm-verity-upstream: Add dynamic layer for meta-security dm-verity PRC Automation
2026-10-07 20:11 ` Denys Dmytriyenko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005121218.844998-1-a-dubey@ti.com \
    --to=a-dubey@ti.com \
    --cc=a-limaye@ti.com \
    --cc=denys@konsulko.com \
    --cc=m-chawdhry@ti.com \
    --cc=meta-ti@lists.yoctoproject.org \
    --cc=reatmon@ti.com \
    --cc=u-kumar1@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.