From: Anis Bougrine <anis.bougrine10@gmail.com>
To: openembedded-core@lists.openembedded.org
Cc: mathieu.dubois-briand@bootlin.com,
richard.purdie@linuxfoundation.org, peter.kjellerstedt@axis.com,
Anis Bougrine <anis.bougrine10@gmail.com>,
Ross Burton <ross.burton@arm.com>
Subject: [OE-core][PATCH v5 3/5] package.py: remove stripping and splitting skip for signed kernel modules
Date: Tue, 25 Aug 2026 22:49:28 +0200 [thread overview]
Message-ID: <20260825204931.17628-4-anis.bougrine10@gmail.com> (raw)
In-Reply-To: <20260825204931.17628-1-anis.bougrine10@gmail.com>
Fixes [YOCTO #12927]
Now kernel modules are re-signed after package stripping process.
Therefore, they can be stripped and splitted securely.
Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
meta/lib/oe/package.py | 26 +++-----------------------
1 file changed, 3 insertions(+), 23 deletions(-)
diff --git a/meta/lib/oe/package.py b/meta/lib/oe/package.py
index 4a244ec980..1657eaad93 100644
--- a/meta/lib/oe/package.py
+++ b/meta/lib/oe/package.py
@@ -36,16 +36,9 @@ def runstrip(file, elftype, strip, extra_strip_sections=''):
os.chmod(file, newmode)
stripcmd = [strip]
- skip_strip = False
- # kernel module: use --strip-debug and --preserve-dates (required for
- # module signing to remain valid after stripping)
+ # kernel module
if elftype & 16:
- if is_kernel_module_signed(file):
- bb.debug(1, "Skip strip on signed module %s" % file)
- skip_strip = True
- else:
- stripcmd.extend(["--strip-debug", "--remove-section=.comment",
- "--remove-section=.note", "--preserve-dates"])
+ stripcmd.extend(["--strip-debug", "--remove-section=.comment", "--remove-section=.note"])
# .so and shared library
elif ".so" in file and elftype & 8:
stripcmd.extend(["--remove-section=.comment", "--remove-section=.note", "--strip-unneeded"])
@@ -59,8 +52,7 @@ def runstrip(file, elftype, strip, extra_strip_sections=''):
stripcmd.append(file)
bb.debug(1, "runstrip: %s" % stripcmd)
- if not skip_strip:
- output = subprocess.check_output(stripcmd, stderr=subprocess.STDOUT)
+ output = subprocess.check_output(stripcmd, stderr=subprocess.STDOUT)
if newmode:
os.chmod(file, origmode)
@@ -70,13 +62,6 @@ def is_kernel_module(path):
with open(path) as f:
return mmap.mmap(f.fileno(), 0, prot=mmap.PROT_READ).find(b"vermagic=") >= 0
-# Detect if .ko module is signed
-def is_kernel_module_signed(path):
- with open(path, "rb") as f:
- f.seek(-28, 2)
- module_tail = f.read()
- return "Module signature appended" in "".join(chr(c) for c in bytearray(module_tail))
-
# Return type (bits):
# 0 - not elf
# 1 - ELF
@@ -810,11 +795,6 @@ def splitdebuginfo(file, dvar, dv, d):
debugfile = dvar + dest
sources = []
- if file.endswith(".ko") and file.find("/lib/modules/") != -1:
- if oe.package.is_kernel_module_signed(file):
- bb.debug(1, "Skip strip on signed module %s" % file)
- return (file, sources)
-
# Split the file...
bb.utils.mkdirhier(os.path.dirname(debugfile))
#bb.note("Split %s -> %s" % (file, debugfile))
--
2.50.1 (Apple Git-155)
next prev parent reply other threads:[~2026-08-25 20:50 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
2026-08-25 20:49 ` [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing Anis Bougrine
2026-08-26 8:33 ` Richard Purdie
2026-08-26 9:55 ` Bougrine Anis
2026-08-25 20:49 ` [OE-core][PATCH v5 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
2026-08-25 20:49 ` Anis Bougrine [this message]
2026-08-25 20:49 ` [OE-core][PATCH v5 4/5] kernel: centralize kernel module installation path in one variable Anis Bougrine
2026-08-25 20:49 ` [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
2026-08-25 21:03 ` Patchtest results for " patchtest
2026-08-26 7:24 ` Antonin Godard
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825204931.17628-4-anis.bougrine10@gmail.com \
--to=anis.bougrine10@gmail.com \
--cc=mathieu.dubois-briand@bootlin.com \
--cc=openembedded-core@lists.openembedded.org \
--cc=peter.kjellerstedt@axis.com \
--cc=richard.purdie@linuxfoundation.org \
--cc=ross.burton@arm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox