* [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends @ 2026-08-27 13:37 Rasmus Villemoes 2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes 0 siblings, 1 reply; 5+ messages in thread From: Rasmus Villemoes @ 2026-08-27 13:37 UTC (permalink / raw) To: meta-arm; +Cc: Jon Mason, Jan Kiszka, Jan Luebbe, Rasmus Villemoes From: Rasmus Villemoes <ravi@prevas.dk> If two different .bbappends both try to add an "early TA" by appending an EARLY_TA_PATHS="..." to EXTRA_OEMAKE, only one of them will actually take effect. For example, meta-arm itself has a .bbappend in optee-ftpm which adds the ftpm TA if optee-ftpm is in MACHINE_FEATURES. If the BSP developer wants to add another early TA, he has to take that into account and very carefully ensure to create an EARLY_TA_PATHS="..." argument which contains both the ftpm value as well as his desired extra TA. Instead, let the main recipe define a variable which can simply be appended to in the normal way, and which is used for deriving the single EARLY_TA_PATHS="" argument in the make command line. Handle the in-tree TAs similarly. Signed-off-by: Rasmus Villemoes <ravi@prevas.dk> --- meta-arm/recipes-security/optee/optee-os.inc | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/meta-arm/recipes-security/optee/optee-os.inc b/meta-arm/recipes-security/optee/optee-os.inc index 95c41fb1..b90e379a 100644 --- a/meta-arm/recipes-security/optee/optee-os.inc +++ b/meta-arm/recipes-security/optee/optee-os.inc @@ -35,6 +35,21 @@ EXTRA_OEMAKE += " CROSS_COMPILE64=${HOST_PREFIX}" # Enable BTI in optee EXTRA_OEMAKE += "${@bb.utils.contains('MACHINE_FEATURES', 'arm-branch-protection', ' CFG_TA_BTI=1 CFG_CORE_PAUTH=y CFG_TA_PAUTH=y', '', d)}" +# If several .bbappends wants to add an early TA, and they both do +# EXTRA_OEMAKE += 'EARLY_TA_PATHS="..."', only one of them will take +# effect. Instead, create a bitbake variable holding the entire list, +# which the .bbappends can append to, and add a single EARLY_TA_PATHS= +# to the make cmdline here. Similarly for the in-tree ones. +# +# Note that it is not necessary to explicitly pass CFG_EARLY_TA=y as +# the build systems sets that itself if either list is non-empty (and +# errors out if CFG_EARLY_TA was explicitly set to n). +EARLY_TA_PATHS = "" +CFG_IN_TREE_EARLY_TAS = "" + +EXTRA_OEMAKE += "${@'EARLY_TA_PATHS="' + d.getVar('EARLY_TA_PATHS') + '"' if d.getVar('EARLY_TA_PATHS') else ''}" +EXTRA_OEMAKE += "${@'CFG_IN_TREE_EARLY_TAS="' + d.getVar('CFG_IN_TREE_EARLY_TAS') + '"' if d.getVar('CFG_IN_TREE_EARLY_TAS') else ''}" + LDFLAGS[unexport] = "1" CPPFLAGS[unexport] = "1" AS[unexport] = "1" -- 2.55.0 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable 2026-08-27 13:37 [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends Rasmus Villemoes @ 2026-08-27 13:37 ` Rasmus Villemoes 2026-08-27 17:00 ` Jan Kiszka 0 siblings, 1 reply; 5+ messages in thread From: Rasmus Villemoes @ 2026-08-27 13:37 UTC (permalink / raw) To: meta-arm; +Cc: Jon Mason, Jan Kiszka, Jan Luebbe, Rasmus Villemoes From: Rasmus Villemoes <ravi@prevas.dk> If anything else in the BSP also wants or needs to add an early TA to optee, that will conflict with this .bbappend adding its own EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE. Instead, add the path to the ftpm TA to the newly introduced EARLY_TA_PATHS bitbake variable, which the main recipe will use to produce the make argument. Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build system sets that automatically if the EARLY_TA_PATHS list is non-empty. CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with other .bbappends that might have an opinion on its proper (minimum) value. For now, keep adding it explicitly to EXTRA_OEMAKE. Signed-off-by: Rasmus Villemoes <ravi@prevas.dk> --- .../recipes-security/optee-ftpm/optee-os_%.bbappend | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend index 92c11157..74bde25e 100644 --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend @@ -4,8 +4,8 @@ DEPENDS:append = "\ ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \ " -EXTRA_OEMAKE:append = "\ - ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \ - 'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \ - '', d)} \ -" +python() { + if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d): + d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf') + d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072') +} -- 2.55.0 ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable 2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes @ 2026-08-27 17:00 ` Jan Kiszka 2026-09-04 9:36 ` Rasmus Villemoes 0 siblings, 1 reply; 5+ messages in thread From: Jan Kiszka @ 2026-08-27 17:00 UTC (permalink / raw) To: Rasmus Villemoes, meta-arm; +Cc: Jon Mason, Jan Luebbe On 27.08.26 15:37, Rasmus Villemoes wrote: > From: Rasmus Villemoes <ravi@prevas.dk> > > If anything else in the BSP also wants or needs to add an early TA to > optee, that will conflict with this .bbappend adding its own > EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE. > > Instead, add the path to the ftpm TA to the newly introduced > EARLY_TA_PATHS bitbake variable, which the main recipe will use to > produce the make argument. > > Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build > system sets that automatically if the EARLY_TA_PATHS list is > non-empty. > > CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with > other .bbappends that might have an opinion on its proper (minimum) > value. For now, keep adding it explicitly to EXTRA_OEMAKE. > > Signed-off-by: Rasmus Villemoes <ravi@prevas.dk> > --- > .../recipes-security/optee-ftpm/optee-os_%.bbappend | 10 +++++----- > 1 file changed, 5 insertions(+), 5 deletions(-) > > diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend > index 92c11157..74bde25e 100644 > --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend > +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend > @@ -4,8 +4,8 @@ DEPENDS:append = "\ > ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \ > " > > -EXTRA_OEMAKE:append = "\ > - ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \ > - 'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \ > - '', d)} \ > -" > +python() { > + if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d): > + d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf') > + d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072') > +} Both patches look good to me, but I currently have no nothing in place to test. Also good to know that CFG_EARLY_TA=y can be dropped - I have it elsewhere redundantly in use as well. In case you are currently using optee_ftpm, I hope you are aware that this layer probably needs more updates. See [1] and [2] for what we did in isar-cip-core to update the TPM core and add recent CVE fixes. If all goes well, at least optee_ftpm patch will become part of the next optee release. But there is more. Jan [1] https://gitlab.com/cip-project/cip-core/isar-cip-core/-/commit/d233084880dffef3fd5037b3159c88e3b35259ac [2] https://gitlab.com/cip-project/cip-core/isar-cip-core/-/commit/77f75df8c69868f335ffa36f671fe06b1f983247 -- Siemens AG, Foundational Technologies Linux Expert Center ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable 2026-08-27 17:00 ` Jan Kiszka @ 2026-09-04 9:36 ` Rasmus Villemoes 2026-09-04 9:47 ` Jan Kiszka 0 siblings, 1 reply; 5+ messages in thread From: Rasmus Villemoes @ 2026-09-04 9:36 UTC (permalink / raw) To: Jan Kiszka; +Cc: meta-arm, Jon Mason, Jan Luebbe On Thu, Aug 27 2026, Jan Kiszka <jan.kiszka@siemens.com> wrote: > On 27.08.26 15:37, Rasmus Villemoes wrote: >> From: Rasmus Villemoes <ravi@prevas.dk> >> >> If anything else in the BSP also wants or needs to add an early TA to >> optee, that will conflict with this .bbappend adding its own >> EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE. >> >> Instead, add the path to the ftpm TA to the newly introduced >> EARLY_TA_PATHS bitbake variable, which the main recipe will use to >> produce the make argument. >> >> Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build >> system sets that automatically if the EARLY_TA_PATHS list is >> non-empty. >> >> CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with >> other .bbappends that might have an opinion on its proper (minimum) >> value. For now, keep adding it explicitly to EXTRA_OEMAKE. >> >> Signed-off-by: Rasmus Villemoes <ravi@prevas.dk> >> --- >> .../recipes-security/optee-ftpm/optee-os_%.bbappend | 10 +++++----- >> 1 file changed, 5 insertions(+), 5 deletions(-) >> >> diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend >> index 92c11157..74bde25e 100644 >> --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend >> +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend >> @@ -4,8 +4,8 @@ DEPENDS:append = "\ >> ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \ >> " >> >> -EXTRA_OEMAKE:append = "\ >> - ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \ >> - 'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \ >> - '', d)} \ >> -" >> +python() { >> + if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d): >> + d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf') >> + d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072') >> +} > > Both patches look good to me, but I currently have no nothing in place > to test. Thanks. I have tested locally that the resulting op-tee works as expected with this refactoring, and inspected the run.do_compile scripts to see that they are sensible. Anything more I need to do on my end to get these merged? And when that is done, are they eligible for backporting to wrynose if I then resend with [wrynose] in $subject? Rasmus ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable 2026-09-04 9:36 ` Rasmus Villemoes @ 2026-09-04 9:47 ` Jan Kiszka 0 siblings, 0 replies; 5+ messages in thread From: Jan Kiszka @ 2026-09-04 9:47 UTC (permalink / raw) To: Rasmus Villemoes, meta-arm; +Cc: Jon Mason, Jan Luebbe On 04.09.26 11:36, Rasmus Villemoes wrote: > On Thu, Aug 27 2026, Jan Kiszka <jan.kiszka@siemens.com> wrote: > >> On 27.08.26 15:37, Rasmus Villemoes wrote: >>> From: Rasmus Villemoes <ravi@prevas.dk> >>> >>> If anything else in the BSP also wants or needs to add an early TA to >>> optee, that will conflict with this .bbappend adding its own >>> EARLY_TA_PATHS="..." argument to EXTRA_OEMAKE. >>> >>> Instead, add the path to the ftpm TA to the newly introduced >>> EARLY_TA_PATHS bitbake variable, which the main recipe will use to >>> produce the make argument. >>> >>> Passing CFG_EARLY_TA=y explicitly is not needed, as optee-os' build >>> system sets that automatically if the EARLY_TA_PATHS list is >>> non-empty. >>> >>> CFG_CORE_HEAP_SIZE is somewhat harder to make play along nicely with >>> other .bbappends that might have an opinion on its proper (minimum) >>> value. For now, keep adding it explicitly to EXTRA_OEMAKE. >>> >>> Signed-off-by: Rasmus Villemoes <ravi@prevas.dk> >>> --- >>> .../recipes-security/optee-ftpm/optee-os_%.bbappend | 10 +++++----- >>> 1 file changed, 5 insertions(+), 5 deletions(-) >>> >>> diff --git a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend >>> index 92c11157..74bde25e 100644 >>> --- a/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend >>> +++ b/meta-arm/recipes-security/optee-ftpm/optee-os_%.bbappend >>> @@ -4,8 +4,8 @@ DEPENDS:append = "\ >>> ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', 'optee-ftpm', '' , d)} \ >>> " >>> >>> -EXTRA_OEMAKE:append = "\ >>> - ${@bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', \ >>> - 'CFG_CORE_HEAP_SIZE=131072 CFG_EARLY_TA=y EARLY_TA_PATHS="${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf"', \ >>> - '', d)} \ >>> -" >>> +python() { >>> + if bb.utils.contains('MACHINE_FEATURES', 'optee-ftpm', True, False, d): >>> + d.appendVar('EARLY_TA_PATHS', ' ${STAGING_DIR_TARGET}/${base_libdir}/optee_armtz/${FTPM_UUID}.stripped.elf') >>> + d.appendVar('EXTRA_OEMAKE', ' CFG_CORE_HEAP_SIZE=131072') >>> +} >> >> Both patches look good to me, but I currently have no nothing in place >> to test. > > Thanks. I have tested locally that the resulting op-tee works as > expected with this refactoring, and inspected the run.do_compile scripts > to see that they are sensible. > > Anything more I need to do on my end to get these merged? And when that > is done, are they eligible for backporting to wrynose if I then resend > with [wrynose] in $subject? > I'm not the maintainer here :) Jan -- Siemens AG, Foundational Technologies Linux Expert Center ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-04 9:47 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-27 13:37 [PATCH 1/2] optee-os: make early TAs more convenient to add for .bbappends Rasmus Villemoes 2026-08-27 13:37 ` [PATCH 2/2] optee-ftpm: rewrite its optee-os bbappend to use EARLY_TA_PATHS bitbake variable Rasmus Villemoes 2026-08-27 17:00 ` Jan Kiszka 2026-09-04 9:36 ` Rasmus Villemoes 2026-09-04 9:47 ` Jan Kiszka
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.