* [OE-core][PATCH v7 1/5] lib/oe/kernel_module.py: add get_ext_mod function for module signing
2026-08-26 23:34 [OE-core][PATCH v7 0/5] Make signed kernel modules stripped Anis Bougrine
@ 2026-08-26 23:34 ` Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
` (3 subsequent siblings)
4 siblings, 0 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-26 23:34 UTC (permalink / raw)
To: openembedded-core; +Cc: richard.purdie, Anis Bougrine, Ross Burton
Fixes [YOCTO #12927]
Out-of-tree module Makefiles invoke the kernel Makefile by appending
the M= (the module directory) variable to the MAKEFLAGS.
However, they usually do not provide a modules_sign target. Therefore,
the kernel modules_sign target has to be invoked manually after retrieving
M= variable from package source code Makefile.
This function retrieves the M= variable from an external module Makefile.
Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
meta/lib/oe/__init__.py | 2 +-
meta/lib/oe/kernel_module.py | 21 +++++++++++++++++++++
2 files changed, 22 insertions(+), 1 deletion(-)
diff --git a/meta/lib/oe/__init__.py b/meta/lib/oe/__init__.py
index d8db84dc9a..7357a71f27 100644
--- a/meta/lib/oe/__init__.py
+++ b/meta/lib/oe/__init__.py
@@ -12,4 +12,4 @@ __path__ = extend_path(__path__, __name__)
BBIMPORTS = ["qa", "data", "path", "utils", "types", "package", "packagedata", \
"packagegroup", "sstatesig", "lsb", "cachedpath", "license", "qemu", \
"reproducible", "rust", "buildcfg", "go", "spdx30_tasks", "spdx_common", \
- "cve_check", "tune", "classextend", "purl", "kernel", "sanity"]
+ "cve_check", "tune", "classextend", "purl", "kernel", "kernel_module", "sanity"]
diff --git a/meta/lib/oe/kernel_module.py b/meta/lib/oe/kernel_module.py
index 0d27fbaa57..edf723033f 100644
--- a/meta/lib/oe/kernel_module.py
+++ b/meta/lib/oe/kernel_module.py
@@ -25,3 +25,24 @@ def kernel_module_os_env(d, env_dict):
env_dict['KBUILD_EXTRA_SYMBOLS'] = kbuild_extra_symbols
else:
env_dict['KBUILD_EXTRA_SYMBOLS'] = ''
+
+def get_ext_mod(d):
+ """
+ Extract the resolved Kbuild M= variable from an out of tree module Makefile variable database.
+ """
+ import re
+ import bb.process
+
+ try:
+ output = bb.process.run(
+ "make -C %s --dry-run --print-data-base" % d.getVar("B")
+ )[0]
+ except bb.process.ExecutionError:
+ return d.getVar("S")
+
+ for line in output.splitlines():
+ m = re.match(r'^M\s*=\s*(.*)$', line)
+ if m:
+ return m.group(1).strip()
+
+ return d.getVar("S")
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 10+ messages in thread* [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process
2026-08-26 23:34 [OE-core][PATCH v7 0/5] Make signed kernel modules stripped Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 1/5] lib/oe/kernel_module.py: add get_ext_mod function for module signing Anis Bougrine
@ 2026-08-26 23:34 ` Anis Bougrine
2026-09-05 7:39 ` Richard Purdie
2026-08-26 23:34 ` [OE-core][PATCH v7 3/5] package.py: remove stripping and splitting skip for signed kernel modules Anis Bougrine
` (2 subsequent siblings)
4 siblings, 1 reply; 10+ messages in thread
From: Anis Bougrine @ 2026-08-26 23:34 UTC (permalink / raw)
To: openembedded-core; +Cc: richard.purdie, Anis Bougrine, Ross Burton
Fixes [YOCTO #12927]
Currently, signed kernel modules are not stripped in order to preserve
their valid signatures. See commit 4c47e5f.
Therefore, this commit makes kernel modules stripped and correctly
signed. Two options are possible:
- Strip the kernel modules after installation and before signing.
- Re-sign the kernel modules after stripping and before package splitting.
The first option was rejected because debug symbols would be dropped early
in the build workflow, which may impact the SPDX process.
The second option is adopted because it does not impact the build flow.
Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
.../kernel-module-split.bbclass | 25 +++++++++++++++++++
1 file changed, 25 insertions(+)
diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
index ab2f0d1c37..2b40437cc2 100644
--- a/meta/classes-recipe/kernel-module-split.bbclass
+++ b/meta/classes-recipe/kernel-module-split.bbclass
@@ -35,6 +35,11 @@ modprobedir ??= "${@bb.utils.contains('DISTRO_FEATURES', 'systemd', '${nonarch_b
KERNEL_SPLIT_MODULES ?= "1"
PACKAGESPLITFUNCS =+ "split_kernel_module_packages"
+# Order matters:
+# 1. Strip the modules
+# 2. Re-sign the modules (if enabled)
+# 3. Split the packages
+PACKAGESPLITFUNCS =+ "post_strip_kernel_modules_signing"
KERNEL_MODULES_META_PACKAGE ?= "${@ d.getVar("KERNEL_PACKAGE_NAME") or "kernel" }-modules"
@@ -42,6 +47,26 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
+# This function supports both in-tree and out-of-tree modules.
+post_strip_kernel_modules_signing(){
+ # Read .config values to determine if module auto-signing is enabled
+ is_modules="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULES)"
+ is_module_sig="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG)"
+ is_module_sig_all="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG_ALL)"
+
+ if [ "$is_modules" = "y" ] && [ "$is_module_sig" = "y" ] && [ "$is_module_sig_all" = "y" ]; then
+ # Sign modules under ${PKGD}, with M= if out-of-tree module.
+ # Out-of-tree module Makefiles invoke the kernel Makefile by appending M= (the module directory) to MAKEFLAGS.
+ # However, they usually do not provide a modules_sign target. Therefore, the kernel modules_sign target has to
+ # be invoked manually after retrieving M= variable from package source code Makefile.
+ oe_runmake \
+ -C ${KBUILD_OUTPUT} \
+ MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
+ ${@'M=%s' % oe.kernel_module.get_ext_mod(d) if not "virtual/kernel" in d.getVar('PROVIDES') else ''} \
+ modules_sign
+ fi
+}
+
python split_kernel_module_packages () {
import re
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 10+ messages in thread* Re: [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process
2026-08-26 23:34 ` [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
@ 2026-09-05 7:39 ` Richard Purdie
2026-09-07 10:28 ` Bougrine Anis
0 siblings, 1 reply; 10+ messages in thread
From: Richard Purdie @ 2026-09-05 7:39 UTC (permalink / raw)
To: Anis Bougrine, openembedded-core; +Cc: Ross Burton, Bruce Ashfield
On Thu, 2026-08-27 at 01:34 +0200, Anis Bougrine wrote:
> Fixes [YOCTO #12927]
>
> Currently, signed kernel modules are not stripped in order to preserve
> their valid signatures. See commit 4c47e5f.
>
> Therefore, this commit makes kernel modules stripped and correctly
> signed. Two options are possible:
>
> - Strip the kernel modules after installation and before signing.
> - Re-sign the kernel modules after stripping and before package splitting.
>
> The first option was rejected because debug symbols would be dropped early
> in the build workflow, which may impact the SPDX process.
>
> The second option is adopted because it does not impact the build flow.
>
> Reported-by: Ross Burton <ross.burton@arm.com>
> Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
> ---
> .../kernel-module-split.bbclass | 25 +++++++++++++++++++
> 1 file changed, 25 insertions(+)
>
> diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
> index ab2f0d1c37..2b40437cc2 100644
> --- a/meta/classes-recipe/kernel-module-split.bbclass
> +++ b/meta/classes-recipe/kernel-module-split.bbclass
> @@ -35,6 +35,11 @@ modprobedir ??= "${@bb.utils.contains('DISTRO_FEATURES', 'systemd', '${nonarch_b
>
> KERNEL_SPLIT_MODULES ?= "1"
> PACKAGESPLITFUNCS =+ "split_kernel_module_packages"
> +# Order matters:
> +# 1. Strip the modules
> +# 2. Re-sign the modules (if enabled)
> +# 3. Split the packages
> +PACKAGESPLITFUNCS =+ "post_strip_kernel_modules_signing"
>
> KERNEL_MODULES_META_PACKAGE ?= "${@ d.getVar("KERNEL_PACKAGE_NAME") or "kernel" }-modules"
>
> @@ -42,6 +47,26 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
> KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
> KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
>
> +# This function supports both in-tree and out-of-tree modules.
> +post_strip_kernel_modules_signing(){
> + # Read .config values to determine if module auto-signing is enabled
> + is_modules="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULES)"
> + is_module_sig="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG)"
> + is_module_sig_all="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG_ALL)"
> +
> + if [ "$is_modules" = "y" ] && [ "$is_module_sig" = "y" ] && [ "$is_module_sig_all" = "y" ]; then
> + # Sign modules under ${PKGD}, with M= if out-of-tree module.
> + # Out-of-tree module Makefiles invoke the kernel Makefile by appending M= (the module directory) to MAKEFLAGS.
> + # However, they usually do not provide a modules_sign target. Therefore, the kernel modules_sign target has to
> + # be invoked manually after retrieving M= variable from package source code Makefile.
> + oe_runmake \
> + -C ${KBUILD_OUTPUT} \
> + MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
> + ${@'M=%s' % oe.kernel_module.get_ext_mod(d) if not "virtual/kernel" in d.getVar('PROVIDES') else ''} \
> + modules_sign
> + fi
> +}
This has merged and I'm really happy to see the signing code improved.
There is a weird bug this as introduced though where the eSDK is
breaking in kernel module compile tests.
This is an example failure:
https://autobuilder.yoctoproject.org/valkyrie/#/builders/30/builds/4551
In the bad environment, you can source the test eSDK environment:
. /srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/environment-setup-core2-32-poky-linux
Rerun the compile step:
/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/tmp/work/qemux86-poky-linux/kernel-module-hello-world/1.0+git/temp/run.do_compile
where you see hello-world.ko get generated:
make[2]: Entering directory '/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/workspace/sources/kernel-module-hello-world'
LD [M] hello-world.ko
make[2]: Leaving directory '/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/workspace/sources/kernel-module-hello-world'
then watch:
devtool build kernel-module-hello-world
fail as above, noting that the hello-world.ko file disappears by the time it runs.
To cut a long story short (hours of debugging), this happens during
parsing of the kernel-module-hello-world recipe. If you add a
bb.warn("Executing make") to oe.kernel_module.get_ext_mod() in
meta/lib/oe/kernel_module.py, you will see it runs make during parsing
and that make command deletes the .ko file.
This raises a few questions:
a) why is make being run during parsing?
The shell function is being expanded to work out dependencies
and that triggers the python function call. This should definitely not
be happening during parsing so that is a bug.
b) why does calling --dry-run on the kernel makefile delete files?
We need to fix this somehow to avoid the failures/bad behaviour. I at
least wanted to explain the issue now I'd found the underlying area of
the problem. I've not really had a chance to think about solutions yet.
Cheers,
Richard
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process
2026-09-05 7:39 ` Richard Purdie
@ 2026-09-07 10:28 ` Bougrine Anis
2026-09-09 13:56 ` Martin Jansa
0 siblings, 1 reply; 10+ messages in thread
From: Bougrine Anis @ 2026-09-07 10:28 UTC (permalink / raw)
To: Richard Purdie; +Cc: openembedded-core, Ross Burton, Bruce Ashfield
[-- Attachment #1: Type: text/plain, Size: 6133 bytes --]
Hello Richard,
Sorry to hear that, and sorry for making you debug this for hours.
I just saw your patch, “kernel-module-split: Remove get_ext_mod”. I’m OK
with that workaround.
On my side, I’ll think about a better solution to cover all out-of-tree
module use cases.
I’m rebuilding my PC for an upgrade, so it will take a while.
Thank you.
BR,
Anis
On Sat 5 Sep 2026 at 09:39, Richard Purdie <
richard.purdie@linuxfoundation.org> wrote:
> On Thu, 2026-08-27 at 01:34 +0200, Anis Bougrine wrote:
> > Fixes [YOCTO #12927]
> >
> > Currently, signed kernel modules are not stripped in order to preserve
> > their valid signatures. See commit 4c47e5f.
> >
> > Therefore, this commit makes kernel modules stripped and correctly
> > signed. Two options are possible:
> >
> > - Strip the kernel modules after installation and before signing.
> > - Re-sign the kernel modules after stripping and before package
> splitting.
> >
> > The first option was rejected because debug symbols would be dropped
> early
> > in the build workflow, which may impact the SPDX process.
> >
> > The second option is adopted because it does not impact the build flow.
> >
> > Reported-by: Ross Burton <ross.burton@arm.com>
> > Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
> > ---
> > .../kernel-module-split.bbclass | 25 +++++++++++++++++++
> > 1 file changed, 25 insertions(+)
> >
> > diff --git a/meta/classes-recipe/kernel-module-split.bbclass
> b/meta/classes-recipe/kernel-module-split.bbclass
> > index ab2f0d1c37..2b40437cc2 100644
> > --- a/meta/classes-recipe/kernel-module-split.bbclass
> > +++ b/meta/classes-recipe/kernel-module-split.bbclass
> > @@ -35,6 +35,11 @@ modprobedir ??=
> "${@bb.utils.contains('DISTRO_FEATURES', 'systemd', '${nonarch_b
> >
> > KERNEL_SPLIT_MODULES ?= "1"
> > PACKAGESPLITFUNCS =+ "split_kernel_module_packages"
> > +# Order matters:
> > +# 1. Strip the modules
> > +# 2. Re-sign the modules (if enabled)
> > +# 3. Split the packages
> > +PACKAGESPLITFUNCS =+ "post_strip_kernel_modules_signing"
> >
> > KERNEL_MODULES_META_PACKAGE ?= "${@ d.getVar("KERNEL_PACKAGE_NAME") or
> "kernel" }-modules"
> >
> > @@ -42,6 +47,26 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
> > KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
> > KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
> >
> > +# This function supports both in-tree and out-of-tree modules.
> > +post_strip_kernel_modules_signing(){
> > + # Read .config values to determine if module auto-signing is enabled
> > + is_modules="$(${STAGING_KERNEL_DIR}/scripts/config --file
> ${KBUILD_OUTPUT}/.config --state MODULES)"
> > + is_module_sig="$(${STAGING_KERNEL_DIR}/scripts/config --file
> ${KBUILD_OUTPUT}/.config --state MODULE_SIG)"
> > + is_module_sig_all="$(${STAGING_KERNEL_DIR}/scripts/config --file
> ${KBUILD_OUTPUT}/.config --state MODULE_SIG_ALL)"
> > +
> > + if [ "$is_modules" = "y" ] && [ "$is_module_sig" = "y" ] && [
> "$is_module_sig_all" = "y" ]; then
> > + # Sign modules under ${PKGD}, with M= if out-of-tree module.
> > + # Out-of-tree module Makefiles invoke the kernel Makefile by
> appending M= (the module directory) to MAKEFLAGS.
> > + # However, they usually do not provide a modules_sign target.
> Therefore, the kernel modules_sign target has to
> > + # be invoked manually after retrieving M= variable from package
> source code Makefile.
> > + oe_runmake \
> > + -C ${KBUILD_OUTPUT} \
> > +
> MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
> > + ${@'M=%s' % oe.kernel_module.get_ext_mod(d) if not
> "virtual/kernel" in d.getVar('PROVIDES') else ''} \
> > + modules_sign
> > + fi
> > +}
>
> This has merged and I'm really happy to see the signing code improved.
> There is a weird bug this as introduced though where the eSDK is
> breaking in kernel module compile tests.
>
> This is an example failure:
>
> https://autobuilder.yoctoproject.org/valkyrie/#/builders/30/builds/4551
>
> In the bad environment, you can source the test eSDK environment:
>
> .
> /srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/environment-setup-core2-32-poky-linux
>
> Rerun the compile step:
>
>
> /srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/tmp/work/qemux86-poky-linux/kernel-module-hello-world/1.0+git/temp/run.do_compile
>
> where you see hello-world.ko get generated:
>
> make[2]: Entering directory
> '/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/workspace/sources/kernel-module-hello-world'
> LD [M] hello-world.ko
> make[2]: Leaving directory
> '/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/workspace/sources/kernel-module-hello-world'
>
> then watch:
>
> devtool build kernel-module-hello-world
>
> fail as above, noting that the hello-world.ko file disappears by the time
> it runs.
>
> To cut a long story short (hours of debugging), this happens during
> parsing of the kernel-module-hello-world recipe. If you add a
> bb.warn("Executing make") to oe.kernel_module.get_ext_mod() in
> meta/lib/oe/kernel_module.py, you will see it runs make during parsing
> and that make command deletes the .ko file.
>
> This raises a few questions:
>
> a) why is make being run during parsing?
>
> The shell function is being expanded to work out dependencies
> and that triggers the python function call. This should definitely not
> be happening during parsing so that is a bug.
>
> b) why does calling --dry-run on the kernel makefile delete files?
>
> We need to fix this somehow to avoid the failures/bad behaviour. I at
> least wanted to explain the issue now I'd found the underlying area of
> the problem. I've not really had a chance to think about solutions yet.
>
> Cheers,
>
> Richard
>
>
>
>
>
[-- Attachment #2: Type: text/html, Size: 7728 bytes --]
^ permalink raw reply [flat|nested] 10+ messages in thread* Re: [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process
2026-09-07 10:28 ` Bougrine Anis
@ 2026-09-09 13:56 ` Martin Jansa
0 siblings, 0 replies; 10+ messages in thread
From: Martin Jansa @ 2026-09-09 13:56 UTC (permalink / raw)
To: anis.bougrine10
Cc: Richard Purdie, openembedded-core, Ross Burton, Bruce Ashfield
Hello, I'm seeing one more issue caused by this change.
Then you enable both:
CONFIG_MODULE_SIG
and
CONFIG_MODULE_COMPRESS/CONFIG_MODULE_COMPRESS_XZ/CONFIG_MODULE_COMPRESS_ALL
then the do_package fails in module_sign:
| DEBUG: Executing shell function post_strip_kernel_modules_signing
| NOTE: make ARCH=x86 CC=x86_64-oe-linux-gcc -fuse-ld=bfd
-fcanon-prefix-map
-ffile-prefix-map=/OE/build/oe-core/tmp/work-shared/qemux86-64/kernel-source=/usr/src/debug/linux-yocto/7.2.4+git
-ffile-prefix-map=/OE/build/oe-core/tmp/wor
k/qemux86_64-oe-linux/linux-yocto/7.2.4+git/linux-qemux86_64-standard-build=/usr/src/debug/linux-yocto/7.2.4+git
-ffile-prefix-map=/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot=
-ffile-prefix-map=/O
E/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot-native=
-ffile-prefix-map=/OE/build/oe-core/tmp/work-shared/qemux86-64/kernel-source=/usr/src/kernel
-ffile-prefix-map=/OE/build/oe-core/tmp/work-shared/
qemux86-64/kernel-build-artifacts=/usr/src/kernel
LD=x86_64-oe-linux-ld.bfd OBJCOPY=x86_64-oe-linux-objcopy
STRIP=x86_64-oe-linux-strip HOSTCC=gcc
HOSTCFLAGS=-isystem/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git
/recipe-sysroot-native/usr/include -O2 -pipe
HOSTLDFLAGS=-L/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot-native/usr/lib
-L/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-y
octo/7.2.4+git/recipe-sysroot-native/lib
-Wl,--enable-new-dtags
-Wl,-rpath-link,/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot-native/usr/lib
-Wl,-rpath-link,/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot-native/lib
-Wl,-rpath,/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sys
root-native/usr/lib
-Wl,-rpath,/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot-native/lib
-Wl,-O1 -Wl,--allow-shlib-undefined
-Wl,--dynamic-linker=/OE/bui
ld/oe-core/tmp/sysroots-uninative/x86_64-linux/lib/ld-linux-x86-64.so.2
-pthread HOSTCPP=gcc -E HOSTCXX=g++
HOSTCXXFLAGS=-isystem/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/recipe-sysroot-native/usr/include
-O2
-pipe HOSTPKG_CONFIG=pkg-config-native PAHOLE=false -C
/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/linux-qemux86_64-standard-build
MODLIB=/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/packag
e/usr/lib/modules/7.2.4-yocto-standard modules_sign
| make: Entering directory
'/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/linux-qemux86_64-standard-build'
| SIGN /OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/package/usr/lib/modules/7.2.4-yocto-standard/kernel/fs/nls/nls_cp737.ko
| At main.c:247:
| - SSL error:FFFFFFFF80000002:system library::No such file or
directory: ../sources/openssl-4.0.2/crypto/bio/bss_file.c:73
| - SSL error:10000080:BIO routines::no such file:
../sources/openssl-4.0.2/crypto/bio/bss_file.c:81
| sign-file: /OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/package/usr/lib/modules/7.2.4-yocto-standard/kernel/fs/nls/nls_cp737.ko
| make[2]: *** [/OE/build/oe-core/tmp/work-shared/qemux86-64/kernel-source/scripts/Makefile.modinst:141:
/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/package/usr/lib/modules/7.2.4-yocto-standard/kernel/fs/nls/nls_c
p737.ko] Error 1
| make[1]: *** [/OE/build/oe-core/tmp/work-shared/qemux86-64/kernel-source/Makefile:2104:
modules_install] Error 2
| make: Leaving directory
'/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/linux-qemux86_64-standard-build'
| make: *** [/OE/build/oe-core/tmp/work-shared/qemux86-64/kernel-source/Makefile:248:
__sub-make] Error 2
oe-core $ ls /OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/package/usr/lib/modules/7.2.4-yocto-standard/kernel/fs/nls/nls_cp737*
/OE/build/oe-core/tmp/work/qemux86_64-oe-linux/linux-yocto/7.2.4+git/package/usr/lib/modules/7.2.4-yocto-standard/kernel/fs/nls/nls_cp737.ko.xz
because the .ko files no longer exist, only .ko.xz are. Not sure if
there is a better place where to call module_sign or just disable this
post_strip one when CONFIG_MODULE_COMPRESS_* is set?
Easily reproduced with just oe-core:
diff --git a/meta/recipes-kernel/linux/files/module-sig.cfg
b/meta/recipes-kernel/linux/files/module-sig.cfg
new file mode 100644
index 0000000000..e2be1688cc
--- /dev/null
+++ b/meta/recipes-kernel/linux/files/module-sig.cfg
@@ -0,0 +1,4 @@
+CONFIG_MODULE_COMPRESS=y
+CONFIG_MODULE_COMPRESS_XZ=y
+CONFIG_MODULE_COMPRESS_ALL=y
+CONFIG_MODULE_SIG=y
diff --git a/meta/recipes-kernel/linux/linux-yocto_7.2.bb
b/meta/recipes-kernel/linux/linux-yocto_7.2.bb
index e3edaaada5..58278fc525 100644
--- a/meta/recipes-kernel/linux/linux-yocto_7.2.bb
+++ b/meta/recipes-kernel/linux/linux-yocto_7.2.bb
@@ -40,6 +40,7 @@ PN:class-devupstream = "linux-yocto-upstream"
KBRANCH:class-devupstream = "v7.2/base"
SRC_URI = "git://git.yoctoproject.org/linux-yocto.git;name=machine;branch=${KBRANCH};protocol=https
\
+ file://module-sig.cfg \
git://git.yoctoproject.org/yocto-kernel-cache;type=kmeta;name=meta;branch=yocto-7.2;destsuffix=${KMETA};protocol=https"
LIC_FILES_CHKSUM = "file://COPYING;md5=6bc538ed5bd9a7fc9398086aedcd7e46"
Or with just MODULE_SIG for raspberrypi builds as the default
defconfig already has MODULE_COMPRESS in:
arch/arm64/configs/bcm2711_defconfig:CONFIG_MODULE_COMPRESS=y
arch/arm64/configs/bcm2711_defconfig:CONFIG_MODULE_COMPRESS_XZ=y
arch/arm64/configs/bcm2711_rt_defconfig:CONFIG_MODULE_COMPRESS=y
arch/arm64/configs/bcm2711_rt_defconfig:CONFIG_MODULE_COMPRESS_XZ=y
arch/arm64/configs/bcm2712_defconfig:CONFIG_MODULE_COMPRESS=y
arch/arm64/configs/bcm2712_defconfig:CONFIG_MODULE_COMPRESS_XZ=y
Regards,
On Mon, Sep 7, 2026 at 12:28 PM Anis Bougrine via
lists.openembedded.org
<anis.bougrine10=gmail.com@lists.openembedded.org> wrote:
>
> Hello Richard,
>
> Sorry to hear that, and sorry for making you debug this for hours.
>
> I just saw your patch, “kernel-module-split: Remove get_ext_mod”. I’m OK with that workaround.
>
> On my side, I’ll think about a better solution to cover all out-of-tree module use cases.
>
> I’m rebuilding my PC for an upgrade, so it will take a while.
>
> Thank you.
>
> BR,
> Anis
>
>
> On Sat 5 Sep 2026 at 09:39, Richard Purdie <richard.purdie@linuxfoundation.org> wrote:
>>
>> On Thu, 2026-08-27 at 01:34 +0200, Anis Bougrine wrote:
>> > Fixes [YOCTO #12927]
>> >
>> > Currently, signed kernel modules are not stripped in order to preserve
>> > their valid signatures. See commit 4c47e5f.
>> >
>> > Therefore, this commit makes kernel modules stripped and correctly
>> > signed. Two options are possible:
>> >
>> > - Strip the kernel modules after installation and before signing.
>> > - Re-sign the kernel modules after stripping and before package splitting.
>> >
>> > The first option was rejected because debug symbols would be dropped early
>> > in the build workflow, which may impact the SPDX process.
>> >
>> > The second option is adopted because it does not impact the build flow.
>> >
>> > Reported-by: Ross Burton <ross.burton@arm.com>
>> > Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
>> > ---
>> > .../kernel-module-split.bbclass | 25 +++++++++++++++++++
>> > 1 file changed, 25 insertions(+)
>> >
>> > diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
>> > index ab2f0d1c37..2b40437cc2 100644
>> > --- a/meta/classes-recipe/kernel-module-split.bbclass
>> > +++ b/meta/classes-recipe/kernel-module-split.bbclass
>> > @@ -35,6 +35,11 @@ modprobedir ??= "${@bb.utils.contains('DISTRO_FEATURES', 'systemd', '${nonarch_b
>> >
>> > KERNEL_SPLIT_MODULES ?= "1"
>> > PACKAGESPLITFUNCS =+ "split_kernel_module_packages"
>> > +# Order matters:
>> > +# 1. Strip the modules
>> > +# 2. Re-sign the modules (if enabled)
>> > +# 3. Split the packages
>> > +PACKAGESPLITFUNCS =+ "post_strip_kernel_modules_signing"
>> >
>> > KERNEL_MODULES_META_PACKAGE ?= "${@ d.getVar("KERNEL_PACKAGE_NAME") or "kernel" }-modules"
>> >
>> > @@ -42,6 +47,26 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
>> > KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
>> > KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
>> >
>> > +# This function supports both in-tree and out-of-tree modules.
>> > +post_strip_kernel_modules_signing(){
>> > + # Read .config values to determine if module auto-signing is enabled
>> > + is_modules="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULES)"
>> > + is_module_sig="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG)"
>> > + is_module_sig_all="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG_ALL)"
>> > +
>> > + if [ "$is_modules" = "y" ] && [ "$is_module_sig" = "y" ] && [ "$is_module_sig_all" = "y" ]; then
>> > + # Sign modules under ${PKGD}, with M= if out-of-tree module.
>> > + # Out-of-tree module Makefiles invoke the kernel Makefile by appending M= (the module directory) to MAKEFLAGS.
>> > + # However, they usually do not provide a modules_sign target. Therefore, the kernel modules_sign target has to
>> > + # be invoked manually after retrieving M= variable from package source code Makefile.
>> > + oe_runmake \
>> > + -C ${KBUILD_OUTPUT} \
>> > + MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
>> > + ${@'M=%s' % oe.kernel_module.get_ext_mod(d) if not "virtual/kernel" in d.getVar('PROVIDES') else ''} \
>> > + modules_sign
>> > + fi
>> > +}
>>
>> This has merged and I'm really happy to see the signing code improved.
>> There is a weird bug this as introduced though where the eSDK is
>> breaking in kernel module compile tests.
>>
>> This is an example failure:
>>
>> https://autobuilder.yoctoproject.org/valkyrie/#/builders/30/builds/4551
>>
>> In the bad environment, you can source the test eSDK environment:
>>
>> . /srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/environment-setup-core2-32-poky-linux
>>
>> Rerun the compile step:
>>
>> /srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/tmp/work/qemux86-poky-linux/kernel-module-hello-world/1.0+git/temp/run.do_compile
>>
>> where you see hello-world.ko get generated:
>>
>> make[2]: Entering directory '/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/workspace/sources/kernel-module-hello-world'
>> LD [M] hello-world.ko
>> make[2]: Leaving directory '/srv/pokybuild/yocto-worker/qemux86/build/build/tmp/work/qemux86-poky-linux/core-image-sato/1.0/testsdkext/workspace/sources/kernel-module-hello-world'
>>
>> then watch:
>>
>> devtool build kernel-module-hello-world
>>
>> fail as above, noting that the hello-world.ko file disappears by the time it runs.
>>
>> To cut a long story short (hours of debugging), this happens during
>> parsing of the kernel-module-hello-world recipe. If you add a
>> bb.warn("Executing make") to oe.kernel_module.get_ext_mod() in
>> meta/lib/oe/kernel_module.py, you will see it runs make during parsing
>> and that make command deletes the .ko file.
>>
>> This raises a few questions:
>>
>> a) why is make being run during parsing?
>>
>> The shell function is being expanded to work out dependencies
>> and that triggers the python function call. This should definitely not
>> be happening during parsing so that is a bug.
>>
>> b) why does calling --dry-run on the kernel makefile delete files?
>>
>> We need to fix this somehow to avoid the failures/bad behaviour. I at
>> least wanted to explain the issue now I'd found the underlying area of
>> the problem. I've not really had a chance to think about solutions yet.
>>
>> Cheers,
>>
>> Richard
>>
>>
>>
>>
>
> -=-=-=-=-=-=-=-=-=-=-=-
> Links: You receive all messages sent to this group.
> View/Reply Online (#245243): https://lists.openembedded.org/g/openembedded-core/message/245243
> Mute This Topic: https://lists.openembedded.org/mt/120949282/3617156
> Group Owner: openembedded-core+owner@lists.openembedded.org
> Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [martin.jansa@gmail.com]
> -=-=-=-=-=-=-=-=-=-=-=-
>
^ permalink raw reply related [flat|nested] 10+ messages in thread
* [OE-core][PATCH v7 3/5] package.py: remove stripping and splitting skip for signed kernel modules
2026-08-26 23:34 [OE-core][PATCH v7 0/5] Make signed kernel modules stripped Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 1/5] lib/oe/kernel_module.py: add get_ext_mod function for module signing Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
@ 2026-08-26 23:34 ` Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 4/5] kernel: centralize kernel module installation path in one variable Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
4 siblings, 0 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-26 23:34 UTC (permalink / raw)
To: openembedded-core; +Cc: richard.purdie, Anis Bougrine, Ross Burton
Fixes [YOCTO #12927]
Now kernel modules are re-signed after package stripping process.
Therefore, they can be stripped and splitted securely.
Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
meta/lib/oe/package.py | 26 +++-----------------------
1 file changed, 3 insertions(+), 23 deletions(-)
diff --git a/meta/lib/oe/package.py b/meta/lib/oe/package.py
index 4a244ec980..1657eaad93 100644
--- a/meta/lib/oe/package.py
+++ b/meta/lib/oe/package.py
@@ -36,16 +36,9 @@ def runstrip(file, elftype, strip, extra_strip_sections=''):
os.chmod(file, newmode)
stripcmd = [strip]
- skip_strip = False
- # kernel module: use --strip-debug and --preserve-dates (required for
- # module signing to remain valid after stripping)
+ # kernel module
if elftype & 16:
- if is_kernel_module_signed(file):
- bb.debug(1, "Skip strip on signed module %s" % file)
- skip_strip = True
- else:
- stripcmd.extend(["--strip-debug", "--remove-section=.comment",
- "--remove-section=.note", "--preserve-dates"])
+ stripcmd.extend(["--strip-debug", "--remove-section=.comment", "--remove-section=.note"])
# .so and shared library
elif ".so" in file and elftype & 8:
stripcmd.extend(["--remove-section=.comment", "--remove-section=.note", "--strip-unneeded"])
@@ -59,8 +52,7 @@ def runstrip(file, elftype, strip, extra_strip_sections=''):
stripcmd.append(file)
bb.debug(1, "runstrip: %s" % stripcmd)
- if not skip_strip:
- output = subprocess.check_output(stripcmd, stderr=subprocess.STDOUT)
+ output = subprocess.check_output(stripcmd, stderr=subprocess.STDOUT)
if newmode:
os.chmod(file, origmode)
@@ -70,13 +62,6 @@ def is_kernel_module(path):
with open(path) as f:
return mmap.mmap(f.fileno(), 0, prot=mmap.PROT_READ).find(b"vermagic=") >= 0
-# Detect if .ko module is signed
-def is_kernel_module_signed(path):
- with open(path, "rb") as f:
- f.seek(-28, 2)
- module_tail = f.read()
- return "Module signature appended" in "".join(chr(c) for c in bytearray(module_tail))
-
# Return type (bits):
# 0 - not elf
# 1 - ELF
@@ -810,11 +795,6 @@ def splitdebuginfo(file, dvar, dv, d):
debugfile = dvar + dest
sources = []
- if file.endswith(".ko") and file.find("/lib/modules/") != -1:
- if oe.package.is_kernel_module_signed(file):
- bb.debug(1, "Skip strip on signed module %s" % file)
- return (file, sources)
-
# Split the file...
bb.utils.mkdirhier(os.path.dirname(debugfile))
#bb.note("Split %s -> %s" % (file, debugfile))
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 10+ messages in thread* [OE-core][PATCH v7 4/5] kernel: centralize kernel module installation path in one variable
2026-08-26 23:34 [OE-core][PATCH v7 0/5] Make signed kernel modules stripped Anis Bougrine
` (2 preceding siblings ...)
2026-08-26 23:34 ` [OE-core][PATCH v7 3/5] package.py: remove stripping and splitting skip for signed kernel modules Anis Bougrine
@ 2026-08-26 23:34 ` Anis Bougrine
2026-08-26 23:34 ` [OE-core][PATCH v7 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
4 siblings, 0 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-26 23:34 UTC (permalink / raw)
To: openembedded-core; +Cc: richard.purdie, Anis Bougrine
The kernel module installation path is currently defined in multiple
places, although it is used 10 times throughout the code. This
increases the risk of bugs due to inconsistencies or desynchronization.
Centralizing the path in a single variable makes the code more
reliable and easier to maintain.
This commit introduce KERNEL_MODULE_INSTALL_PREFIX to resolve this issue.
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
meta/classes-recipe/kernel-arch.bbclass | 1 +
meta/classes-recipe/kernel-module-split.bbclass | 2 +-
meta/classes-recipe/kernel.bbclass | 12 ++++++------
meta/classes-recipe/module.bbclass | 2 +-
4 files changed, 9 insertions(+), 8 deletions(-)
diff --git a/meta/classes-recipe/kernel-arch.bbclass b/meta/classes-recipe/kernel-arch.bbclass
index 26b8a1a67f..91cceb8dc1 100644
--- a/meta/classes-recipe/kernel-arch.bbclass
+++ b/meta/classes-recipe/kernel-arch.bbclass
@@ -10,6 +10,7 @@ TARGET_CC_KERNEL_ARCH ?= ""
TARGET_LD_KERNEL_ARCH ?= ""
TARGET_AR_KERNEL_ARCH ?= ""
TARGET_OBJCOPY_KERNEL_ARCH ?= ""
+KERNEL_MODULE_INSTALL_PREFIX ?= "${nonarch_base_libdir}/modules/${KERNEL_VERSION}"
KERNEL_CC:toolchain-gcc = "${CCACHE}${HOST_PREFIX}gcc ${TARGET_CC_KERNEL_ARCH} \
-fuse-ld=bfd ${DEBUG_PREFIX_MAP} \
diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
index 2b40437cc2..413f39d641 100644
--- a/meta/classes-recipe/kernel-module-split.bbclass
+++ b/meta/classes-recipe/kernel-module-split.bbclass
@@ -61,7 +61,7 @@ post_strip_kernel_modules_signing(){
# be invoked manually after retrieving M= variable from package source code Makefile.
oe_runmake \
-C ${KBUILD_OUTPUT} \
- MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
+ MODLIB=${PKGD}${KERNEL_MODULE_INSTALL_PREFIX} \
${@'M=%s' % oe.kernel_module.get_ext_mod(d) if not "virtual/kernel" in d.getVar('PROVIDES') else ''} \
modules_sign
fi
diff --git a/meta/classes-recipe/kernel.bbclass b/meta/classes-recipe/kernel.bbclass
index a82bdf7ecb..0a6d754108 100644
--- a/meta/classes-recipe/kernel.bbclass
+++ b/meta/classes-recipe/kernel.bbclass
@@ -453,11 +453,11 @@ kernel_do_install() {
#
unset CFLAGS CPPFLAGS CXXFLAGS LDFLAGS MACHINE
if (grep -q -i -e '^CONFIG_MODULES=y$' .config); then
- oe_runmake DEPMOD=echo MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} INSTALL_FW_PATH=${D}${firmwaredir} modules_install
- rm -f "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/build"
- rm -f "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/source"
+ oe_runmake DEPMOD=echo MODLIB=${D}${KERNEL_MODULE_INSTALL_PREFIX} INSTALL_FW_PATH=${D}${firmwaredir} modules_install
+ rm -f "${D}${KERNEL_MODULE_INSTALL_PREFIX}/build"
+ rm -f "${D}${KERNEL_MODULE_INSTALL_PREFIX}/source"
# Remove empty module directories to prevent QA issues
- [ -d "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/kernel" ] && find "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/kernel" -type d -empty -delete
+ [ -d "${D}${KERNEL_MODULE_INSTALL_PREFIX}/kernel" ] && find "${D}${KERNEL_MODULE_INSTALL_PREFIX}/kernel" -type d -empty -delete
else
bbnote "no modules to install"
fi
@@ -680,9 +680,9 @@ EXPORT_FUNCTIONS do_compile do_transform_kernel do_transform_bundled_initramfs d
# kernel-image becomes kernel-image-${KERNEL_VERSION}
PACKAGES = "${KERNEL_PACKAGE_NAME} ${KERNEL_PACKAGE_NAME}-base ${KERNEL_PACKAGE_NAME}-vmlinux ${KERNEL_PACKAGE_NAME}-image ${KERNEL_PACKAGE_NAME}-dev ${KERNEL_PACKAGE_NAME}-modules ${KERNEL_PACKAGE_NAME}-dbg"
FILES:${PN} = ""
-FILES:${KERNEL_PACKAGE_NAME}-base = "${nonarch_base_libdir}/modules/${KERNEL_VERSION}/modules.order ${nonarch_base_libdir}/modules/${KERNEL_VERSION}/modules.builtin ${nonarch_base_libdir}/modules/${KERNEL_VERSION}/modules.builtin.modinfo"
+FILES:${KERNEL_PACKAGE_NAME}-base = "${KERNEL_MODULE_INSTALL_PREFIX}/modules.order ${KERNEL_MODULE_INSTALL_PREFIX}/modules.builtin ${KERNEL_MODULE_INSTALL_PREFIX}/modules.builtin.modinfo"
FILES:${KERNEL_PACKAGE_NAME}-image = ""
-FILES:${KERNEL_PACKAGE_NAME}-dev = "/${KERNEL_IMAGEDEST}/System.map* /${KERNEL_IMAGEDEST}/Module.symvers* /${KERNEL_IMAGEDEST}/config* ${KERNEL_SRC_PATH} ${nonarch_base_libdir}/modules/${KERNEL_VERSION}/build"
+FILES:${KERNEL_PACKAGE_NAME}-dev = "/${KERNEL_IMAGEDEST}/System.map* /${KERNEL_IMAGEDEST}/Module.symvers* /${KERNEL_IMAGEDEST}/config* ${KERNEL_SRC_PATH} ${KERNEL_MODULE_INSTALL_PREFIX}/build"
FILES:${KERNEL_PACKAGE_NAME}-vmlinux = "/${KERNEL_IMAGEDEST}/vmlinux-${KERNEL_VERSION_NAME}"
FILES:${KERNEL_PACKAGE_NAME}-modules = ""
FILES:${KERNEL_PACKAGE_NAME}-dbg = "/usr/lib/debug /usr/src/debug"
diff --git a/meta/classes-recipe/module.bbclass b/meta/classes-recipe/module.bbclass
index ce5898125b..985c24bed5 100644
--- a/meta/classes-recipe/module.bbclass
+++ b/meta/classes-recipe/module.bbclass
@@ -46,7 +46,7 @@ module_do_compile() {
module_do_install() {
unset CFLAGS CPPFLAGS CXXFLAGS LDFLAGS
- oe_runmake DEPMOD=echo MODLIB="${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}" \
+ oe_runmake DEPMOD=echo MODLIB="${D}${KERNEL_MODULE_INSTALL_PREFIX}" \
INSTALL_FW_PATH="${D}${firmwaredir}" \
CC="${KERNEL_CC}" LD="${KERNEL_LD}" OBJCOPY="${KERNEL_OBJCOPY}" \
STRIP="${KERNEL_STRIP}" \
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 10+ messages in thread* [OE-core][PATCH v7 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable
2026-08-26 23:34 [OE-core][PATCH v7 0/5] Make signed kernel modules stripped Anis Bougrine
` (3 preceding siblings ...)
2026-08-26 23:34 ` [OE-core][PATCH v7 4/5] kernel: centralize kernel module installation path in one variable Anis Bougrine
@ 2026-08-26 23:34 ` Anis Bougrine
2026-08-26 23:48 ` Patchtest results for " patchtest
4 siblings, 1 reply; 10+ messages in thread
From: Anis Bougrine @ 2026-08-26 23:34 UTC (permalink / raw)
To: openembedded-core; +Cc: richard.purdie, Anis Bougrine
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
meta/conf/documentation.conf | 1 +
1 file changed, 1 insertion(+)
diff --git a/meta/conf/documentation.conf b/meta/conf/documentation.conf
index 72513296e2..93949c7ff8 100644
--- a/meta/conf/documentation.conf
+++ b/meta/conf/documentation.conf
@@ -239,6 +239,7 @@ KERNEL_FEATURES[doc] = "Includes additional metadata from the Yocto Project kern
KERNEL_IMAGETYPE[doc] = "The type of kernel to build for a device, usually set by the machine configuration files and defaults to 'zImage'."
KERNEL_IMAGETYPES[doc] = "The list of types of kernel to build for a device, usually set by the machine configuration files and defaults to KERNEL_IMAGETYPE."
KERNEL_MODULE_AUTOLOAD[doc] = "Lists kernel modules that need to be auto-loaded during boot"
+KERNEL_MODULE_INSTALL_PREFIX[doc] = "When a recipe inherits the module class, this variable specifies the directory to which kernel modules are installed on target."
KERNEL_MODULE_PROBECONF[doc] = "Lists kernel modules for which the build system expects to find module_conf_* values that specify configuration for each of the modules"
KERNEL_PACKAGE_NAME[doc] = "Name prefix for kernel packages. Defaults to 'kernel'."
KERNEL_PATH[doc] = "The location of the kernel sources. This variable is set to the value of the STAGING_KERNEL_DIR within the module class (module.bbclass)."
--
2.50.1 (Apple Git-155)
^ permalink raw reply related [flat|nested] 10+ messages in thread* Patchtest results for [OE-core][PATCH v7 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable
2026-08-26 23:34 ` [OE-core][PATCH v7 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
@ 2026-08-26 23:48 ` patchtest
0 siblings, 0 replies; 10+ messages in thread
From: patchtest @ 2026-08-26 23:48 UTC (permalink / raw)
To: Anis Bougrine; +Cc: openembedded-core
[-- Attachment #1: Type: text/plain, Size: 3324 bytes --]
Thank you for your submission. Patchtest identified one
or more issues with the patch. Please see the log below for
more information:
---
Testing patch /home/patchtest/share/mboxes/v7-5-5-documentation.conf-add-documentation-for-KERNEL_MODULE_INSTALL_PREFIX-variable.patch
FAIL: test commit message presence: Please include a commit message on your patch explaining the change (test_mbox.TestMbox.test_commit_message_presence)
PASS: test Signed-off-by presence (test_mbox.TestMbox.test_signed_off_by_presence)
PASS: test auh changelog truncation notice (test_mbox.TestMbox.test_auh_changelog_truncation_notice)
PASS: test author valid (test_mbox.TestMbox.test_author_valid)
PASS: test commit message user tags (test_mbox.TestMbox.test_commit_message_user_tags)
PASS: test max line length (test_metadata.TestMetadata.test_max_line_length)
PASS: test mbox format (test_mbox.TestMbox.test_mbox_format)
PASS: test non-AUH upgrade (test_mbox.TestMbox.test_non_auh_upgrade)
PASS: test shortlog format (test_mbox.TestMbox.test_shortlog_format)
PASS: test shortlog length (test_mbox.TestMbox.test_shortlog_length)
PASS: test target mailing list (test_mbox.TestMbox.test_target_mailing_list)
SKIP: pretest pylint: No python related patches, skipping test (test_python_pylint.PyLint.pretest_pylint)
SKIP: pretest src uri left files: No modified recipes, skipping pretest (test_metadata.TestMetadata.pretest_src_uri_left_files)
SKIP: test CVE check ignore: No modified recipes or older target branch, skipping test (test_metadata.TestMetadata.test_cve_check_ignore)
SKIP: test CVE tag format: No new source patches introduced (test_patch.TestPatch.test_cve_tag_format)
SKIP: test Signed-off-by presence: No new source patches introduced (test_patch.TestPatch.test_signed_off_by_presence)
SKIP: test Upstream-Status presence: No new source patches introduced (test_patch.TestPatch.test_upstream_status_presence_format)
SKIP: test bugzilla entry format: No bug ID found (test_mbox.TestMbox.test_bugzilla_entry_format)
SKIP: test lic files chksum modified not mentioned: No modified recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_modified_not_mentioned)
SKIP: test lic files chksum presence: No added recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_presence)
SKIP: test license presence: No added recipes, skipping test (test_metadata.TestMetadata.test_license_presence)
SKIP: test pylint: No python related patches, skipping test (test_python_pylint.PyLint.test_pylint)
SKIP: test series merge on head: Merge test is disabled for now (test_mbox.TestMbox.test_series_merge_on_head)
SKIP: test src uri left files: No modified recipes, skipping test (test_metadata.TestMetadata.test_src_uri_left_files)
SKIP: test summary presence: No added recipes, skipping test (test_metadata.TestMetadata.test_summary_presence)
---
Please address the issues identified and
submit a new revision of the patch, or alternatively, reply to this
email with an explanation of why the patch should be accepted. If you
believe these results are due to an error in patchtest, please submit a
bug at https://bugzilla.yoctoproject.org/ (use the 'Patchtest' category
under 'Yocto Project Subprojects'). For more information on specific
failures, see: https://wiki.yoctoproject.org/wiki/Patchtest. Thank
you!
^ permalink raw reply [flat|nested] 10+ messages in thread