Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Peter Korsgaard <peter@korsgaard.com>
To: Fiona Klute via buildroot <buildroot@buildroot.org>
Cc: Fiona Klute <fiona.klute@gmx.de>
Subject: Re: [Buildroot] [PATCH next 1/3] fs/common.mk: add optional hook to build a verity hash tree
Date: Mon, 31 Aug 2026 21:16:34 +0200	[thread overview]
Message-ID: <87mru2je25.fsf@dell.be.48ers.dk> (raw)
In-Reply-To: <20260831125103.841338-1-fiona.klute@gmx.de> (Fiona Klute via buildroot's message of "Mon, 31 Aug 2026 14:51:01 +0200")

>>>>> "Fiona" == Fiona Klute via buildroot <buildroot@buildroot.org> writes:

 > From: "Fiona Klute (othermo GmbH)" <fiona.klute@gmx.de>
 > Using dm-verity may be useful for any read-only filesystem read from a
 > block device, the new hook will build the required hash tree if
 > enabled by a per-filesystem config option.

 > Signed-off-by: Fiona Klute (othermo GmbH) <fiona.klute@gmx.de>
 > ---
 > The change is small, but it's a new feature, so I assume it's for next.
 > ;-)

 >  fs/common.mk | 9 +++++++++
 >  1 file changed, 9 insertions(+)

 > diff --git a/fs/common.mk b/fs/common.mk
 > index 2f3f8bcc7e..794423476d 100644
 > --- a/fs/common.mk
 > +++ b/fs/common.mk
 > @@ -215,6 +215,15 @@ TARGETS_ROOTFS += rootfs-$(1)
 >  PACKAGES += $$(filter-out rootfs-%,$$(ROOTFS_$(2)_FINAL_RECURSIVE_DEPENDENCIES))
 >  endif
 
 > +ifeq ($$(BR2_TARGET_ROOTFS_$(2)_VERITY),y)
 > +ROOTFS_$(2)_DEPENDENCIES += host-cryptsetup
 > +define ROOTFS_$(2)_VERITY_FORMAT
 > +	@$$(call MESSAGE,"Generating verity hash tree $$(@F).verity")
 > +	$(HOST_DIR)/sbin/veritysetup format --root-hash-file $$@.verity.root-hash $$@ $$@.verity

What about the user configurable settings such as hash/data block size,
uuid, salt, ...?

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

  parent reply	other threads:[~2026-08-31 19:16 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31 12:51 [Buildroot] [PATCH next 1/3] fs/common.mk: add optional hook to build a verity hash tree Fiona Klute via buildroot
2026-08-31 12:51 ` [Buildroot] [PATCH next 2/3] fs/squashfs: add option to build verity tree Fiona Klute via buildroot
2026-08-31 12:51 ` [Buildroot] [PATCH next 3/3] support/testing/tests/fs/test_squashfs.py: add test with dm-verity Fiona Klute via buildroot
2026-08-31 19:16 ` Peter Korsgaard [this message]
2026-08-31 21:10   ` [Buildroot] [PATCH next 1/3] fs/common.mk: add optional hook to build a verity hash tree Fiona Klute via buildroot
2026-09-01  6:41     ` Peter Korsgaard
2026-09-01 10:26       ` Fiona Klute via buildroot
2026-09-01 11:38         ` Peter Korsgaard
2026-09-01 12:53           ` Fiona Klute via buildroot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87mru2je25.fsf@dell.be.48ers.dk \
    --to=peter@korsgaard.com \
    --cc=buildroot@buildroot.org \
    --cc=fiona.klute@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox