All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends
@ 2026-08-27 13:37 Rasmus Villemoes
  2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes
  0 siblings, 1 reply; 5+ messages in thread
From: Rasmus Villemoes @ 2026-08-27 13:37 UTC (permalink / raw)
  To: meta-arm; +Cc: Jon Mason, Jan Kiszka, Jan Luebbe, Rasmus Villemoes

From: Rasmus Villemoes <ravi@prevas.dk>

If two different .bbappends both try to add an "early TA" by appending
an EARLY_TA_PATHS="..." to EXTRA_OEMAKE, only one of them will
actually take effect.

For example, meta-arm itself has a .bbappend in optee-ftpm which adds
the ftpm TA if optee-ftpm is in MACHINE_FEATURES. If the BSP developer
wants to add another early TA, he has to take that into account and
very carefully ensure to create an EARLY_TA_PATHS="..." argument which
contains both the ftpm value as well as his desired extra TA.

Instead, let the main recipe define a variable which can simply be
appended to in the normal way, and which is used for deriving the
single EARLY_TA_PATHS="" argument in the make command line.

Handle the in-tree TAs similarly.

Signed-off-by: Rasmus Villemoes <ravi@prevas.dk>
---
 meta-arm/recipes-security/optee/optee-os.inc | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/meta-arm/recipes-security/optee/optee-os.inc b/meta-arm/recipes-security/optee/optee-os.inc
index 95c41fb1..b90e379a 100644
--- a/meta-arm/recipes-security/optee/optee-os.inc
+++ b/meta-arm/recipes-security/optee/optee-os.inc
@@ -35,6 +35,21 @@ EXTRA_OEMAKE += " CROSS_COMPILE64=${HOST_PREFIX}"
 # Enable BTI in optee
 EXTRA_OEMAKE += "${@bb.utils.contains('MACHINE_FEATURES', 'arm-branch-protection', ' CFG_TA_BTI=1 CFG_CORE_PAUTH=y CFG_TA_PAUTH=y', '', d)}"
 
+# If several .bbappends wants to add an early TA, and they both do
+# EXTRA_OEMAKE += 'EARLY_TA_PATHS="..."', only one of them will take
+# effect. Instead, create a bitbake variable holding the entire list,
+# which the .bbappends can append to, and add a single EARLY_TA_PATHS=
+# to the make cmdline here. Similarly for the in-tree ones.
+#
+# Note that it is not necessary to explicitly pass CFG_EARLY_TA=y as
+# the build systems sets that itself if either list is non-empty (and
+# errors out if CFG_EARLY_TA was explicitly set to n).
+EARLY_TA_PATHS = ""
+CFG_IN_TREE_EARLY_TAS = ""
+
+EXTRA_OEMAKE += "${@'EARLY_TA_PATHS="' + d.getVar('EARLY_TA_PATHS') + '"' if d.getVar('EARLY_TA_PATHS') else ''}"
+EXTRA_OEMAKE += "${@'CFG_IN_TREE_EARLY_TAS="' + d.getVar('CFG_IN_TREE_EARLY_TAS') + '"' if d.getVar('CFG_IN_TREE_EARLY_TAS') else ''}"
+
 LDFLAGS[unexport] = "1"
 CPPFLAGS[unexport] = "1"
 AS[unexport] = "1"
-- 
2.55.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable
  2026-08-27 13:37 [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends Rasmus Villemoes
@ 2026-08-27 13:37 ` Rasmus Villemoes
  2026-08-27 17:00   ` Jan Kiszka
  0 siblings, 1 reply; 5+ messages in thread
From: Rasmus Villemoes @ 2026-08-27 13:37 UTC (permalink / raw)
  To: meta-arm; +Cc: Jon Mason, Jan Kiszka, Jan Luebbe, Rasmus Villemoes

From: Rasmus Villemoes <ravi@prevas.dk>

If anything else in the BSP also wants or needs to add an early TA to
optee, that will conflict with this .bbappend adding its own
EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE.

Instead, add the path to the ftpm TA to the newly introduced
EARLY_TA_PATHS bitbake variable, which the main recipe will use to
produce the make argument.

Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build
system sets that automatically if the EARLY_TA_PATHS list is
non-empty.

CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with
other .bbappends that might have an opinion on its proper (minimum)
value. For now, keep adding it explicitly to EXTRA_OEMAKE.

Signed-off-by: Rasmus Villemoes <ravi@prevas.dk>
---
 .../recipes-security/optee-ftpm/optee-os_%.bbappend    | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
index 92c11157..74bde25e 100644
--- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
+++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
@@ -4,8 +4,8 @@ DEPENDS:append = "\
     ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \
 "
 
-EXTRA_OEMAKE:append = "\
-    ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \
-        'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \
-        '', d)} \
-"
+python() {
+    if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d):
+        d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf')
+        d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072')
+}
-- 
2.55.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable
  2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes
@ 2026-08-27 17:00   ` Jan Kiszka
  2026-09-04  9:36     ` Rasmus Villemoes
  0 siblings, 1 reply; 5+ messages in thread
From: Jan Kiszka @ 2026-08-27 17:00 UTC (permalink / raw)
  To: Rasmus Villemoes, meta-arm; +Cc: Jon Mason, Jan Luebbe

On 27.08.26 15:37, Rasmus Villemoes wrote:
> From: Rasmus Villemoes <ravi@prevas.dk>
> 
> If anything else in the BSP also wants or needs to add an early TA to
> optee, that will conflict with this .bbappend adding its own
> EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE.
> 
> Instead, add the path to the ftpm TA to the newly introduced
> EARLY_TA_PATHS bitbake variable, which the main recipe will use to
> produce the make argument.
> 
> Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build
> system sets that automatically if the EARLY_TA_PATHS list is
> non-empty.
> 
> CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with
> other .bbappends that might have an opinion on its proper (minimum)
> value. For now, keep adding it explicitly to EXTRA_OEMAKE.
> 
> Signed-off-by: Rasmus Villemoes <ravi@prevas.dk>
> ---
>  .../recipes-security/optee-ftpm/optee-os_%.bbappend    | 10 +++++-----
>  1 file changed, 5 insertions(+), 5 deletions(-)
> 
> diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
> index 92c11157..74bde25e 100644
> --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
> +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
> @@ -4,8 +4,8 @@ DEPENDS:append = "\
>      ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \
>  "
>  
> -EXTRA_OEMAKE:append = "\
> -    ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \
> -        'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \
> -        '', d)} \
> -"
> +python() {
> +    if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d):
> +        d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf')
> +        d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072')
> +}

Both patches look good to me, but I currently have no nothing in place 
to test.

Also good to know that CFG_EARLY_TA=y can be dropped - I have it 
elsewhere redundantly in use as well.

In case you are currently using optee_ftpm, I hope you are aware that
this layer probably needs more updates. See [1] and [2] for what we did 
in isar-cip-core to update the TPM core and add recent CVE fixes. If all 
goes well, at least optee_ftpm patch will become part of the next optee 
release. But there is more.

Jan

[1] https://gitlab.com/cip-project/cip-core/isar-cip-core/-/commit/d233084880dffef3fd5037b3159c88e3b35259ac
[2] https://gitlab.com/cip-project/cip-core/isar-cip-core/-/commit/77f75df8c69868f335ffa36f671fe06b1f983247

-- 
Siemens AG, Foundational Technologies
Linux Expert Center


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable
  2026-08-27 17:00   ` Jan Kiszka
@ 2026-09-04  9:36     ` Rasmus Villemoes
  2026-09-04  9:47       ` Jan Kiszka
  0 siblings, 1 reply; 5+ messages in thread
From: Rasmus Villemoes @ 2026-09-04  9:36 UTC (permalink / raw)
  To: Jan Kiszka; +Cc: meta-arm, Jon Mason, Jan Luebbe

On Thu, Aug 27 2026, Jan Kiszka <jan.kiszka@siemens.com> wrote:

> On 27.08.26 15:37, Rasmus Villemoes wrote:
>> From: Rasmus Villemoes <ravi@prevas.dk>
>> 
>> If anything else in the BSP also wants or needs to add an early TA to
>> optee, that will conflict with this .bbappend adding its own
>> EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE.
>> 
>> Instead, add the path to the ftpm TA to the newly introduced
>> EARLY_TA_PATHS bitbake variable, which the main recipe will use to
>> produce the make argument.
>> 
>> Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build
>> system sets that automatically if the EARLY_TA_PATHS list is
>> non-empty.
>> 
>> CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with
>> other .bbappends that might have an opinion on its proper (minimum)
>> value. For now, keep adding it explicitly to EXTRA_OEMAKE.
>> 
>> Signed-off-by: Rasmus Villemoes <ravi@prevas.dk>
>> ---
>>  .../recipes-security/optee-ftpm/optee-os_%.bbappend    | 10 +++++-----
>>  1 file changed, 5 insertions(+), 5 deletions(-)
>> 
>> diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
>> index 92c11157..74bde25e 100644
>> --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
>> +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
>> @@ -4,8 +4,8 @@ DEPENDS:append = "\
>>      ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \
>>  "
>>  
>> -EXTRA_OEMAKE:append = "\
>> -    ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \
>> -        'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \
>> -        '', d)} \
>> -"
>> +python() {
>> +    if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d):
>> +        d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf')
>> +        d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072')
>> +}
>
> Both patches look good to me, but I currently have no nothing in place 
> to test.

Thanks. I have tested locally that the resulting op-tee works as
expected with this refactoring, and inspected the run.do_compile scripts
to see that they are sensible.

Anything more I need to do on my end to get these merged? And when that
is done, are they eligible for backporting to wrynose if I then resend
with [wrynose] in $subject?

Rasmus


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable
  2026-09-04  9:36     ` Rasmus Villemoes
@ 2026-09-04  9:47       ` Jan Kiszka
  0 siblings, 0 replies; 5+ messages in thread
From: Jan Kiszka @ 2026-09-04  9:47 UTC (permalink / raw)
  To: Rasmus Villemoes, meta-arm; +Cc: Jon Mason, Jan Luebbe

On 04.09.26 11:36, Rasmus Villemoes wrote:
> On Thu, Aug 27 2026, Jan Kiszka <jan.kiszka@siemens.com> wrote:
> 
>> On 27.08.26 15:37, Rasmus Villemoes wrote:
>>> From: Rasmus Villemoes <ravi@prevas.dk>
>>>
>>> If anything else in the BSP also wants or needs to add an early TA to
>>> optee, that will conflict with this .bbappend adding its own
>>> EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE.
>>>
>>> Instead, add the path to the ftpm TA to the newly introduced
>>> EARLY_TA_PATHS bitbake variable, which the main recipe will use to
>>> produce the make argument.
>>>
>>> Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build
>>> system sets that automatically if the EARLY_TA_PATHS list is
>>> non-empty.
>>>
>>> CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with
>>> other .bbappends that might have an opinion on its proper (minimum)
>>> value. For now, keep adding it explicitly to EXTRA_OEMAKE.
>>>
>>> Signed-off-by: Rasmus Villemoes <ravi@prevas.dk>
>>> ---
>>>  .../recipes-security/optee-ftpm/optee-os_%.bbappend    | 10 +++++-----
>>>  1 file changed, 5 insertions(+), 5 deletions(-)
>>>
>>> diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
>>> index 92c11157..74bde25e 100644
>>> --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
>>> +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend
>>> @@ -4,8 +4,8 @@ DEPENDS:append = "\
>>>      ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \
>>>  "
>>>  
>>> -EXTRA_OEMAKE:append = "\
>>> -    ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \
>>> -        'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \
>>> -        '', d)} \
>>> -"
>>> +python() {
>>> +    if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d):
>>> +        d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf')
>>> +        d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072')
>>> +}
>>
>> Both patches look good to me, but I currently have no nothing in place 
>> to test.
> 
> Thanks. I have tested locally that the resulting op-tee works as
> expected with this refactoring, and inspected the run.do_compile scripts
> to see that they are sensible.
> 
> Anything more I need to do on my end to get these merged? And when that
> is done, are they eligible for backporting to wrynose if I then resend
> with [wrynose] in $subject?
> 

I'm not the maintainer here :)

Jan

-- 
Siemens AG, Foundational Technologies
Linux Expert Center


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-04  9:47 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-27 13:37 [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends Rasmus Villemoes
2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes
2026-08-27 17:00   ` Jan Kiszka
2026-09-04  9:36     ` Rasmus Villemoes
2026-09-04  9:47       ` Jan Kiszka

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.