All of lore.kernel.org
 help / color / mirror / Atom feed
From: Denys Dmytriyenko <denis@denix.org>
To: a-dubey@ti.com
Cc: meta-ti@lists.yoctoproject.org, reatmon@ti.com,
	denys@konsulko.com, a-limaye@ti.com, u-kumar1@ti.com,
	m-chawdhry@ti.com
Subject: Re: [meta-ti][master][PATCH v5 1/3] dm-verity-upstream: Add dynamic layer for meta-security dm-verity
Date: Wed, 7 Oct 2026 16:11:09 -0400	[thread overview]
Message-ID: <20261007201109.GO4190@denix.org> (raw)
In-Reply-To: <20261005121218.844998-1-a-dubey@ti.com>

Looks good to me, thank you for addressing the feedback comments.


On Mon, Oct 05, 2026 at 05:42:16PM +0530, Atharv Dubey via lists.yoctoproject.org wrote:
> Add an optional dynamic layer enabling dm-verity block-level integrity
> verification of the root filesystem for TI K3 platforms, using
> meta-security's stock dm-verity mechanism as-is. Requires meta-security
> to be present in bblayers.conf.
> 
> dm-verity hashes the rootfs at build time; at boot, a dedicated
> initramfs loads the root hash and the kernel checks every block read
> against it. Set DM_VERITY_IMAGE to enable all the verity-related
> recipes for that image; other images build as usual.
> 
> Signed-off-by: Atharv Dubey <a-dubey@ti.com>
> 
> ---
> v5:
>  - unify the python functions
> v4:
>  - Use ti-core-initramfs instead of a separate dm-verity initramfs
>  - Instead of a DISTRO_FEATURE, just check if DM_VERITY_IMAGE is set
> v3:
>  - Disabled the automount rules from udev-aragoconf, so don't need the
>    ignorelist for dm-verity
> v2:
>  - Replaced hardcoded /dev/mmcblk1p2 with a PARTUUID
> ---
>  meta-ti-bsp/conf/layer.conf                   |  3 +++
>  meta-ti-bsp/conf/machine/include/k3.inc       |  7 +++++++
>  .../conf/include/dm-verity-upstream.inc       | 21 +++++++++++++++++++
>  .../udev/udev-aragoconf_%.bbappend            |  5 +++++
>  .../udev/udev-extraconf_%.bbappend            |  6 ++++++
>  meta-ti-bsp/files/wic/k3-verity.wks.in        |  5 +++++
>  6 files changed, 47 insertions(+)
>  create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
>  create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
>  create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
>  create mode 100644 meta-ti-bsp/files/wic/k3-verity.wks.in
> 
> diff --git a/meta-ti-bsp/conf/layer.conf b/meta-ti-bsp/conf/layer.conf
> index 3cc54aa4..aca35cd3 100644
> --- a/meta-ti-bsp/conf/layer.conf
> +++ b/meta-ti-bsp/conf/layer.conf
> @@ -20,12 +20,15 @@ LAYERDEPENDS_meta-ti-bsp = " \
>  LAYERRECOMMENDS_meta-ti-bsp = " \
>      openembedded-layer \
>      tpm-layer \
> +    security \
>  "
>  
>  BBFILES_DYNAMIC += " \
>      openembedded-layer:${LAYERDIR}/dynamic-layers/openembedded-layer/recipes*/*/*.bbappend \
>      tpm-layer:${LAYERDIR}/dynamic-layers/tpm-layer/recipes*/*/*.bb \
>      tpm-layer:${LAYERDIR}/dynamic-layers/tpm-layer/recipes*/*/*.bbappend \
> +    security:${LAYERDIR}/dynamic-layers/security-layer/recipes*/*/*.bb \
> +    security:${LAYERDIR}/dynamic-layers/security-layer/recipes*/*/*.bbappend \
>  "
>  
>  SIGGEN_EXCLUDERECIPES_ABISAFE += " \
> diff --git a/meta-ti-bsp/conf/machine/include/k3.inc b/meta-ti-bsp/conf/machine/include/k3.inc
> index 2ebbfb9e..f19db45f 100644
> --- a/meta-ti-bsp/conf/machine/include/k3.inc
> +++ b/meta-ti-bsp/conf/machine/include/k3.inc
> @@ -64,3 +64,10 @@ FALCON_INCLUDE = ""
>  FALCON_INCLUDE:ti-falcon = "conf/machine/include/ti-falcon.inc"
>  
>  require ${FALCON_INCLUDE}
> +
> +# dm-verity protects the rootfs listed in DM_VERITY_IMAGE; see dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc for what that turns on.
> +DM_VERITY_IMAGE ??= ""
> +
> +DM_VERITY_UPSTREAM_INCLUDE = "${@'dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc' if d.getVar('DM_VERITY_IMAGE') else ''}"
> +
> +require ${DM_VERITY_UPSTREAM_INCLUDE}
> diff --git a/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc b/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
> new file mode 100644
> index 00000000..e9353fcc
> --- /dev/null
> +++ b/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
> @@ -0,0 +1,21 @@
> +# Enables dm-verity to check the rootfs for tampering on TI K3 boards.
> +DM_VERITY_IMAGE_TYPE = "ext4"
> +IMAGE_CLASSES += "dm-verity-img"
> +
> +# ti-core-initramfs.bbappend already wires the initramfs into the boot partition once dm-verity is enabled, so we don't need to do it here.
> +
> +python () {
> +    import uuid
> +
> +    if d.getVar('PN') != d.getVar('DM_VERITY_IMAGE'):
> +        return
> +
> +    # Derive the root partition's UUID from MACHINE so everyone computes the same one.
> +    if not d.getVar('DM_VERITY_ROOT_PARTUUID'):
> +        d.setVar('DM_VERITY_ROOT_PARTUUID',
> +                 str(uuid.uuid5(uuid.NAMESPACE_DNS, 'dm-verity-root-%s' % d.getVar('MACHINE'))))
> +
> +    d.setVar('WKS_FILE', 'k3-verity.wks.in')
> +    d.appendVar('EXTRA_IMAGE_FEATURES', ' read-only-rootfs')
> +    d.appendVar('WICVARS', ' DM_VERITY_IMAGE DM_VERITY_IMAGE_TYPE IMAGE_NAME_SUFFIX IMGDEPLOYDIR DM_VERITY_ROOT_PARTUUID')
> +}
> diff --git a/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
> new file mode 100644
> index 00000000..e5f6c1b2
> --- /dev/null
> +++ b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
> @@ -0,0 +1,5 @@
> +do_install:append() {
> +    if ${@'true' if d.getVar('DM_VERITY_IMAGE') else 'false'}; then
> +        : > ${D}${libdir}/udev/rules.d/50-arago.rules
> +    fi
> +}
> diff --git a/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
> new file mode 100644
> index 00000000..a14e21ea
> --- /dev/null
> +++ b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
> @@ -0,0 +1,6 @@
> +# Nothing should ever get auto-mounted under dm-verity, so just kill the automounter.
> +do_install:append() {
> +    if ${@'true' if d.getVar('DM_VERITY_IMAGE') else 'false'}; then
> +        : > ${D}${sysconfdir}/udev/rules.d/automount.rules
> +    fi
> +}
> diff --git a/meta-ti-bsp/files/wic/k3-verity.wks.in b/meta-ti-bsp/files/wic/k3-verity.wks.in
> new file mode 100644
> index 00000000..62ae0ec1
> --- /dev/null
> +++ b/meta-ti-bsp/files/wic/k3-verity.wks.in
> @@ -0,0 +1,5 @@
> +# Disk layout for a board that boots with dm-verity enabled.
> +
> +bootloader --timeout=3 --append="rootfstype=ext4 root=PARTUUID=${DM_VERITY_ROOT_PARTUUID} ${TI_WKS_BOOTLOADER_APPEND}"
> +part --source bootimg-efi --sourceparams="loader=${EFI_PROVIDER}${TI_WKS_INITRAMFS}" --fstype=vfat --label boot --active --align 1024 --use-uuid --fixed-size 128M
> +part / --source rawcopy --sourceparams="file=${IMGDEPLOYDIR}/${DM_VERITY_IMAGE}-${MACHINE}${IMAGE_NAME_SUFFIX}.${DM_VERITY_IMAGE_TYPE}.verity" --align 1024 --uuid ${DM_VERITY_ROOT_PARTUUID}
> -- 
> 2.34.1
> 


      parent reply	other threads:[~2026-10-07 20:11 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 12:12 [meta-ti][master][PATCH v5 1/3] dm-verity-upstream: Add dynamic layer for meta-security dm-verity Atharv Dubey
2026-10-05 12:12 ` [meta-ti][master][PATCH v5 2/3] linux-ti-staging: Add dm-verity kernel config Atharv Dubey
2026-10-05 12:12 ` [meta-ti][master][PATCH v5 3/3] ti-core-initramfs: Extend with dm-verity support Atharv Dubey
2026-10-05 12:15 ` [meta-ti][master][PATCH v5 1/3] dm-verity-upstream: Add dynamic layer for meta-security dm-verity PRC Automation
2026-10-07 20:11 ` Denys Dmytriyenko [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007201109.GO4190@denix.org \
    --to=denis@denix.org \
    --cc=a-dubey@ti.com \
    --cc=a-limaye@ti.com \
    --cc=denys@konsulko.com \
    --cc=m-chawdhry@ti.com \
    --cc=meta-ti@lists.yoctoproject.org \
    --cc=reatmon@ti.com \
    --cc=u-kumar1@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.