Openembedded Core Discussions
 help / color / mirror / Atom feed
* [OE-core][PATCH v5 0/5] Make signed kernel modules stripped
@ 2026-08-25 20:49 Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing Anis Bougrine
                   ` (4 more replies)
  0 siblings, 5 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-25 20:49 UTC (permalink / raw)
  To: openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt,
	Anis Bougrine

- Re-sign kernel modules after the package stripping process.
- Remove the package-stripping skip for signed kernel modules from package.py.
- Add KERNEL_MODULE_INSTALL_PREFIX variable

Note that tests have been made on core-minimal-image for in-tree modules
and on crypto-dev and lttng-modules for out-of-tree modules.

changes in V5:

    - Adapt signing function for out-of-tree modules.

changes in v4:

    - Re-sign kernel modules after package stripping process
    - Remove package-stripping skip in package.py
    - Add MOD_INSTALL_PREFIX variable

changes in v3:

    - Fixing rebase issue.

changes in v2:

    - Use the conditional INSTALL_MOD_STRIP environment variable to avoid
      duplicating the oe_runmake call.
    - Use `scripts/config` script instead of grepping .config file.# Please edit the description for the branch

Anis Bougrine (5):
  kernel-module-split.bbclass: add get_ext_mod function for module
    signing
  kernel: re-sign kernel modules after package stripping process
  package.py: remove stripping and splitting skip for signed kernel
    modules
  kernel: centralize kernel module installation path in one variable
  documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX
    variable

 meta/classes-recipe/kernel-arch.bbclass       |  1 +
 .../kernel-module-split.bbclass               | 46 +++++++++++++++++++
 meta/classes-recipe/kernel.bbclass            | 12 ++---
 meta/classes-recipe/module.bbclass            |  2 +-
 meta/conf/documentation.conf                  |  1 +
 meta/lib/oe/package.py                        | 26 ++---------
 6 files changed, 58 insertions(+), 30 deletions(-)

-- 
2.50.1 (Apple Git-155)



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing
  2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
@ 2026-08-25 20:49 ` Anis Bougrine
  2026-08-26  8:33   ` Richard Purdie
  2026-08-25 20:49 ` [OE-core][PATCH v5 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
                   ` (3 subsequent siblings)
  4 siblings, 1 reply; 10+ messages in thread
From: Anis Bougrine @ 2026-08-25 20:49 UTC (permalink / raw)
  To: openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt,
	Anis Bougrine, Ross Burton

Fixes [YOCTO #12927]

Out-of-tree module Makefiles invoke the kernel Makefile by appending
the M= (the module directory) variable to the MAKEFLAGS.
However, they usually do not provide a modules_sign target. Therefore,
the kernel modules_sign target has to be invoked manually after retrieving
M= variable from package source code Makefile.

This function retrieves the M= variable from an external module Makefile.

Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
 .../kernel-module-split.bbclass               | 21 +++++++++++++++++++
 1 file changed, 21 insertions(+)

diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
index ab2f0d1c37..bde7cd02dd 100644
--- a/meta/classes-recipe/kernel-module-split.bbclass
+++ b/meta/classes-recipe/kernel-module-split.bbclass
@@ -42,6 +42,27 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
 KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
 KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
 
+def get_ext_mod(d):
+    """
+    Extract the resolved Kbuild M= variable from an out of tree module Makefile variable database.
+    """
+    import re
+    import bb.process
+
+    try:
+        output = bb.process.run(
+            "make -C %s --dry-run --print-data-base" % d.getVar("B")
+        )[0]
+    except bb.process.ExecutionError:
+        return d.getVar("S")
+
+    for line in output.splitlines():
+        m = re.match(r'^M\s*=\s*(.*)$', line)
+        if m:
+            return m.group(1).strip()
+
+    return d.getVar("S")
+
 python split_kernel_module_packages () {
     import re
 
-- 
2.50.1 (Apple Git-155)



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [OE-core][PATCH v5 2/5] kernel: re-sign kernel modules after package stripping process
  2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing Anis Bougrine
@ 2026-08-25 20:49 ` Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 3/5] package.py: remove stripping and splitting skip for signed kernel modules Anis Bougrine
                   ` (2 subsequent siblings)
  4 siblings, 0 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-25 20:49 UTC (permalink / raw)
  To: openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt,
	Anis Bougrine, Ross Burton

Fixes [YOCTO #12927]

Currently, signed kernel modules are not stripped in order to preserve
their valid signatures. See commit 4c47e5f.

Therefore, this commit makes kernel modules stripped and correctly
signed. Two options are possible:

    - Strip the kernel modules after installation and before signing.
    - Re-sign the kernel modules after stripping and before package splitting.

The first option was rejected because debug symbols would be dropped early
in the build workflow, which may impact the SPDX process.

The second option is adopted because it does not impact the build flow.

Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
 .../kernel-module-split.bbclass               | 25 +++++++++++++++++++
 1 file changed, 25 insertions(+)

diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
index bde7cd02dd..da7b30e99f 100644
--- a/meta/classes-recipe/kernel-module-split.bbclass
+++ b/meta/classes-recipe/kernel-module-split.bbclass
@@ -35,6 +35,11 @@ modprobedir ??= "${@bb.utils.contains('DISTRO_FEATURES', 'systemd', '${nonarch_b
 
 KERNEL_SPLIT_MODULES ?= "1"
 PACKAGESPLITFUNCS =+ "split_kernel_module_packages"
+# Order matters:
+# 1. Strip the modules
+# 2. Re-sign the modules (if enabled)
+# 3. Split the packages
+PACKAGESPLITFUNCS =+ "post_strip_kernel_modules_signing"
 
 KERNEL_MODULES_META_PACKAGE ?= "${@ d.getVar("KERNEL_PACKAGE_NAME") or "kernel" }-modules"
 
@@ -63,6 +68,26 @@ def get_ext_mod(d):
 
     return d.getVar("S")
 
+# This function supports both in-tree and out-of-tree modules.
+post_strip_kernel_modules_signing(){
+    # Read .config values to determine if module auto-signing is enabled
+    is_modules="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULES)"
+    is_module_sig="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG)"
+    is_module_sig_all="$(${STAGING_KERNEL_DIR}/scripts/config --file ${KBUILD_OUTPUT}/.config --state MODULE_SIG_ALL)"
+
+    if [ "$is_modules" = "y" ] && [ "$is_module_sig" = "y" ] && [ "$is_module_sig_all" = "y" ]; then
+        # Sign modules under ${PKGD}, with M= if out-of-tree module.
+        # Out-of-tree module Makefiles invoke the kernel Makefile by appending M= (the module directory) to MAKEFLAGS.
+        # However, they usually do not provide a modules_sign target. Therefore, the kernel modules_sign target has to
+        # be invoked manually after retrieving M= variable from package source code Makefile.
+        oe_runmake \
+            -C ${KBUILD_OUTPUT}  \
+            MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
+            ${@'M=${@get_ext_mod(d)}' if not "virtual/kernel" in d.getVar('PROVIDES') else ''} \
+            modules_sign
+    fi
+}
+
 python split_kernel_module_packages () {
     import re
 
-- 
2.50.1 (Apple Git-155)



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [OE-core][PATCH v5 3/5] package.py: remove stripping and splitting skip for signed kernel modules
  2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
@ 2026-08-25 20:49 ` Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 4/5] kernel: centralize kernel module installation path in one variable Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
  4 siblings, 0 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-25 20:49 UTC (permalink / raw)
  To: openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt,
	Anis Bougrine, Ross Burton

Fixes [YOCTO #12927]

Now kernel modules are re-signed after package stripping process.
Therefore, they can be stripped and splitted securely.

Reported-by: Ross Burton <ross.burton@arm.com>
Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
 meta/lib/oe/package.py | 26 +++-----------------------
 1 file changed, 3 insertions(+), 23 deletions(-)

diff --git a/meta/lib/oe/package.py b/meta/lib/oe/package.py
index 4a244ec980..1657eaad93 100644
--- a/meta/lib/oe/package.py
+++ b/meta/lib/oe/package.py
@@ -36,16 +36,9 @@ def runstrip(file, elftype, strip, extra_strip_sections=''):
         os.chmod(file, newmode)
 
     stripcmd = [strip]
-    skip_strip = False
-    # kernel module: use --strip-debug and --preserve-dates (required for
-    # module signing to remain valid after stripping)
+    # kernel module
     if elftype & 16:
-        if is_kernel_module_signed(file):
-            bb.debug(1, "Skip strip on signed module %s" % file)
-            skip_strip = True
-        else:
-            stripcmd.extend(["--strip-debug", "--remove-section=.comment",
-                "--remove-section=.note", "--preserve-dates"])
+        stripcmd.extend(["--strip-debug", "--remove-section=.comment", "--remove-section=.note"])
     # .so and shared library
     elif ".so" in file and elftype & 8:
         stripcmd.extend(["--remove-section=.comment", "--remove-section=.note", "--strip-unneeded"])
@@ -59,8 +52,7 @@ def runstrip(file, elftype, strip, extra_strip_sections=''):
     stripcmd.append(file)
     bb.debug(1, "runstrip: %s" % stripcmd)
 
-    if not skip_strip:
-        output = subprocess.check_output(stripcmd, stderr=subprocess.STDOUT)
+    output = subprocess.check_output(stripcmd, stderr=subprocess.STDOUT)
 
     if newmode:
         os.chmod(file, origmode)
@@ -70,13 +62,6 @@ def is_kernel_module(path):
     with open(path) as f:
         return mmap.mmap(f.fileno(), 0, prot=mmap.PROT_READ).find(b"vermagic=") >= 0
 
-# Detect if .ko module is signed
-def is_kernel_module_signed(path):
-    with open(path, "rb") as f:
-        f.seek(-28, 2)
-        module_tail = f.read()
-        return "Module signature appended" in "".join(chr(c) for c in bytearray(module_tail))
-
 # Return type (bits):
 # 0 - not elf
 # 1 - ELF
@@ -810,11 +795,6 @@ def splitdebuginfo(file, dvar, dv, d):
     debugfile = dvar + dest
     sources = []
 
-    if file.endswith(".ko") and file.find("/lib/modules/") != -1:
-        if oe.package.is_kernel_module_signed(file):
-            bb.debug(1, "Skip strip on signed module %s" % file)
-            return (file, sources)
-
     # Split the file...
     bb.utils.mkdirhier(os.path.dirname(debugfile))
     #bb.note("Split %s -> %s" % (file, debugfile))
-- 
2.50.1 (Apple Git-155)



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [OE-core][PATCH v5 4/5] kernel: centralize kernel module installation path in one variable
  2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
                   ` (2 preceding siblings ...)
  2026-08-25 20:49 ` [OE-core][PATCH v5 3/5] package.py: remove stripping and splitting skip for signed kernel modules Anis Bougrine
@ 2026-08-25 20:49 ` Anis Bougrine
  2026-08-25 20:49 ` [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
  4 siblings, 0 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-25 20:49 UTC (permalink / raw)
  To: openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt,
	Anis Bougrine

The kernel module installation path is currently defined in multiple
places, although it is used 10 times throughout the code. This
increases the risk of bugs due to inconsistencies or desynchronization.

Centralizing the path in a single variable makes the code more
reliable and easier to maintain.

This commit introduce KERNEL_MODULE_INSTALL_PREFIX to resolve this issue.

Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
 meta/classes-recipe/kernel-arch.bbclass         |  1 +
 meta/classes-recipe/kernel-module-split.bbclass |  2 +-
 meta/classes-recipe/kernel.bbclass              | 12 ++++++------
 meta/classes-recipe/module.bbclass              |  2 +-
 4 files changed, 9 insertions(+), 8 deletions(-)

diff --git a/meta/classes-recipe/kernel-arch.bbclass b/meta/classes-recipe/kernel-arch.bbclass
index 26b8a1a67f..91cceb8dc1 100644
--- a/meta/classes-recipe/kernel-arch.bbclass
+++ b/meta/classes-recipe/kernel-arch.bbclass
@@ -10,6 +10,7 @@ TARGET_CC_KERNEL_ARCH ?= ""
 TARGET_LD_KERNEL_ARCH ?= ""
 TARGET_AR_KERNEL_ARCH ?= ""
 TARGET_OBJCOPY_KERNEL_ARCH ?= ""
+KERNEL_MODULE_INSTALL_PREFIX ?= "${nonarch_base_libdir}/modules/${KERNEL_VERSION}"
 
 KERNEL_CC:toolchain-gcc = "${CCACHE}${HOST_PREFIX}gcc ${TARGET_CC_KERNEL_ARCH} \
  -fuse-ld=bfd ${DEBUG_PREFIX_MAP} \
diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
index da7b30e99f..158fa98c50 100644
--- a/meta/classes-recipe/kernel-module-split.bbclass
+++ b/meta/classes-recipe/kernel-module-split.bbclass
@@ -82,7 +82,7 @@ post_strip_kernel_modules_signing(){
         # be invoked manually after retrieving M= variable from package source code Makefile.
         oe_runmake \
             -C ${KBUILD_OUTPUT}  \
-            MODLIB=${PKGD}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
+            MODLIB=${PKGD}${KERNEL_MODULE_INSTALL_PREFIX} \
             ${@'M=${@get_ext_mod(d)}' if not "virtual/kernel" in d.getVar('PROVIDES') else ''} \
             modules_sign
     fi
diff --git a/meta/classes-recipe/kernel.bbclass b/meta/classes-recipe/kernel.bbclass
index a82bdf7ecb..0a6d754108 100644
--- a/meta/classes-recipe/kernel.bbclass
+++ b/meta/classes-recipe/kernel.bbclass
@@ -453,11 +453,11 @@ kernel_do_install() {
 	#
 	unset CFLAGS CPPFLAGS CXXFLAGS LDFLAGS MACHINE
 	if (grep -q -i -e '^CONFIG_MODULES=y$' .config); then
-		oe_runmake DEPMOD=echo MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} INSTALL_FW_PATH=${D}${firmwaredir} modules_install
-		rm -f "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/build"
-		rm -f "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/source"
+		oe_runmake DEPMOD=echo MODLIB=${D}${KERNEL_MODULE_INSTALL_PREFIX} INSTALL_FW_PATH=${D}${firmwaredir} modules_install
+		rm -f "${D}${KERNEL_MODULE_INSTALL_PREFIX}/build"
+		rm -f "${D}${KERNEL_MODULE_INSTALL_PREFIX}/source"
 		# Remove empty module directories to prevent QA issues
-		[ -d "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/kernel" ] && find "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/kernel" -type d -empty -delete
+		[ -d "${D}${KERNEL_MODULE_INSTALL_PREFIX}/kernel" ] && find "${D}${KERNEL_MODULE_INSTALL_PREFIX}/kernel" -type d -empty -delete
 	else
 		bbnote "no modules to install"
 	fi
@@ -680,9 +680,9 @@ EXPORT_FUNCTIONS do_compile do_transform_kernel do_transform_bundled_initramfs d
 # kernel-image becomes kernel-image-${KERNEL_VERSION}
 PACKAGES = "${KERNEL_PACKAGE_NAME} ${KERNEL_PACKAGE_NAME}-base ${KERNEL_PACKAGE_NAME}-vmlinux ${KERNEL_PACKAGE_NAME}-image ${KERNEL_PACKAGE_NAME}-dev ${KERNEL_PACKAGE_NAME}-modules ${KERNEL_PACKAGE_NAME}-dbg"
 FILES:${PN} = ""
-FILES:${KERNEL_PACKAGE_NAME}-base = "${nonarch_base_libdir}/modules/${KERNEL_VERSION}/modules.order ${nonarch_base_libdir}/modules/${KERNEL_VERSION}/modules.builtin ${nonarch_base_libdir}/modules/${KERNEL_VERSION}/modules.builtin.modinfo"
+FILES:${KERNEL_PACKAGE_NAME}-base = "${KERNEL_MODULE_INSTALL_PREFIX}/modules.order ${KERNEL_MODULE_INSTALL_PREFIX}/modules.builtin ${KERNEL_MODULE_INSTALL_PREFIX}/modules.builtin.modinfo"
 FILES:${KERNEL_PACKAGE_NAME}-image = ""
-FILES:${KERNEL_PACKAGE_NAME}-dev = "/${KERNEL_IMAGEDEST}/System.map* /${KERNEL_IMAGEDEST}/Module.symvers* /${KERNEL_IMAGEDEST}/config* ${KERNEL_SRC_PATH} ${nonarch_base_libdir}/modules/${KERNEL_VERSION}/build"
+FILES:${KERNEL_PACKAGE_NAME}-dev = "/${KERNEL_IMAGEDEST}/System.map* /${KERNEL_IMAGEDEST}/Module.symvers* /${KERNEL_IMAGEDEST}/config* ${KERNEL_SRC_PATH} ${KERNEL_MODULE_INSTALL_PREFIX}/build"
 FILES:${KERNEL_PACKAGE_NAME}-vmlinux = "/${KERNEL_IMAGEDEST}/vmlinux-${KERNEL_VERSION_NAME}"
 FILES:${KERNEL_PACKAGE_NAME}-modules = ""
 FILES:${KERNEL_PACKAGE_NAME}-dbg = "/usr/lib/debug /usr/src/debug"
diff --git a/meta/classes-recipe/module.bbclass b/meta/classes-recipe/module.bbclass
index ce5898125b..985c24bed5 100644
--- a/meta/classes-recipe/module.bbclass
+++ b/meta/classes-recipe/module.bbclass
@@ -46,7 +46,7 @@ module_do_compile() {
 
 module_do_install() {
 	unset CFLAGS CPPFLAGS CXXFLAGS LDFLAGS
-	oe_runmake DEPMOD=echo MODLIB="${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}" \
+	oe_runmake DEPMOD=echo MODLIB="${D}${KERNEL_MODULE_INSTALL_PREFIX}" \
 	           INSTALL_FW_PATH="${D}${firmwaredir}" \
 	           CC="${KERNEL_CC}" LD="${KERNEL_LD}" OBJCOPY="${KERNEL_OBJCOPY}" \
 	           STRIP="${KERNEL_STRIP}" \
-- 
2.50.1 (Apple Git-155)



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable
  2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
                   ` (3 preceding siblings ...)
  2026-08-25 20:49 ` [OE-core][PATCH v5 4/5] kernel: centralize kernel module installation path in one variable Anis Bougrine
@ 2026-08-25 20:49 ` Anis Bougrine
  2026-08-25 21:03   ` Patchtest results for " patchtest
  2026-08-26  7:24   ` Antonin Godard
  4 siblings, 2 replies; 10+ messages in thread
From: Anis Bougrine @ 2026-08-25 20:49 UTC (permalink / raw)
  To: openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt,
	Anis Bougrine

Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
---
 meta/conf/documentation.conf | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/conf/documentation.conf b/meta/conf/documentation.conf
index 72513296e2..05945b9702 100644
--- a/meta/conf/documentation.conf
+++ b/meta/conf/documentation.conf
@@ -282,6 +282,7 @@ MAINTAINER[doc] = "The email address of the distribution maintainer."
 MIRRORS[doc] = "Specifies additional paths from which the OpenEmbedded build system gets source code."
 MLPREFIX[doc] = "Specifies a prefix has been added to PN to create a special version of a recipe or package, such as a Multilib version."
 MODULE_TARBALL_DEPLOY[doc] = "Controls creation of the modules-*.tgz file. Set this variable to "0" to disable creation of this file, which contains all of the kernel modules resulting from a kernel build."
+KERNEL_MODULE_INSTALL_PREFIX[doc] = "When a recipe inherits the module class, this variable specifies the directory to which kernel modules are installed on target."
 MULTIMACH_TARGET_SYS[doc] = "Separates files for different machines such that you can build for multiple target machines using the same output directories."
 
 #N
-- 
2.50.1 (Apple Git-155)



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Patchtest results for [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable
  2026-08-25 20:49 ` [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
@ 2026-08-25 21:03   ` patchtest
  2026-08-26  7:24   ` Antonin Godard
  1 sibling, 0 replies; 10+ messages in thread
From: patchtest @ 2026-08-25 21:03 UTC (permalink / raw)
  To: Anis Bougrine; +Cc: openembedded-core

[-- Attachment #1: Type: text/plain, Size: 3324 bytes --]

Thank you for your submission. Patchtest identified one
or more issues with the patch. Please see the log below for
more information:

---
Testing patch /home/patchtest/share/mboxes/v5-5-5-documentation.conf-add-documentation-for-KERNEL_MODULE_INSTALL_PREFIX-variable.patch

FAIL: test commit message presence: Please include a commit message on your patch explaining the change (test_mbox.TestMbox.test_commit_message_presence)

PASS: test Signed-off-by presence (test_mbox.TestMbox.test_signed_off_by_presence)
PASS: test auh changelog truncation notice (test_mbox.TestMbox.test_auh_changelog_truncation_notice)
PASS: test author valid (test_mbox.TestMbox.test_author_valid)
PASS: test commit message user tags (test_mbox.TestMbox.test_commit_message_user_tags)
PASS: test max line length (test_metadata.TestMetadata.test_max_line_length)
PASS: test mbox format (test_mbox.TestMbox.test_mbox_format)
PASS: test non-AUH upgrade (test_mbox.TestMbox.test_non_auh_upgrade)
PASS: test shortlog format (test_mbox.TestMbox.test_shortlog_format)
PASS: test shortlog length (test_mbox.TestMbox.test_shortlog_length)
PASS: test target mailing list (test_mbox.TestMbox.test_target_mailing_list)

SKIP: pretest pylint: No python related patches, skipping test (test_python_pylint.PyLint.pretest_pylint)
SKIP: pretest src uri left files: No modified recipes, skipping pretest (test_metadata.TestMetadata.pretest_src_uri_left_files)
SKIP: test CVE check ignore: No modified recipes or older target branch, skipping test (test_metadata.TestMetadata.test_cve_check_ignore)
SKIP: test CVE tag format: No new source patches introduced (test_patch.TestPatch.test_cve_tag_format)
SKIP: test Signed-off-by presence: No new source patches introduced (test_patch.TestPatch.test_signed_off_by_presence)
SKIP: test Upstream-Status presence: No new source patches introduced (test_patch.TestPatch.test_upstream_status_presence_format)
SKIP: test bugzilla entry format: No bug ID found (test_mbox.TestMbox.test_bugzilla_entry_format)
SKIP: test lic files chksum modified not mentioned: No modified recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_modified_not_mentioned)
SKIP: test lic files chksum presence: No added recipes, skipping test (test_metadata.TestMetadata.test_lic_files_chksum_presence)
SKIP: test license presence: No added recipes, skipping test (test_metadata.TestMetadata.test_license_presence)
SKIP: test pylint: No python related patches, skipping test (test_python_pylint.PyLint.test_pylint)
SKIP: test series merge on head: Merge test is disabled for now (test_mbox.TestMbox.test_series_merge_on_head)
SKIP: test src uri left files: No modified recipes, skipping test (test_metadata.TestMetadata.test_src_uri_left_files)
SKIP: test summary presence: No added recipes, skipping test (test_metadata.TestMetadata.test_summary_presence)

---

Please address the issues identified and
submit a new revision of the patch, or alternatively, reply to this
email with an explanation of why the patch should be accepted. If you
believe these results are due to an error in patchtest, please submit a
bug at https://bugzilla.yoctoproject.org/ (use the 'Patchtest' category
under 'Yocto Project Subprojects'). For more information on specific
failures, see: https://wiki.yoctoproject.org/wiki/Patchtest. Thank
you!

^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable
  2026-08-25 20:49 ` [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
  2026-08-25 21:03   ` Patchtest results for " patchtest
@ 2026-08-26  7:24   ` Antonin Godard
  1 sibling, 0 replies; 10+ messages in thread
From: Antonin Godard @ 2026-08-26  7:24 UTC (permalink / raw)
  To: anis.bougrine10, openembedded-core
  Cc: mathieu.dubois-briand, richard.purdie, peter.kjellerstedt

On Tue Aug 25, 2026 at 10:49 PM CEST, Anis Bougrine via lists.openembedded.org wrote:
> Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
> ---
>  meta/conf/documentation.conf | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/meta/conf/documentation.conf b/meta/conf/documentation.conf
> index 72513296e2..05945b9702 100644
> --- a/meta/conf/documentation.conf
> +++ b/meta/conf/documentation.conf
> @@ -282,6 +282,7 @@ MAINTAINER[doc] = "The email address of the distribution maintainer."
>  MIRRORS[doc] = "Specifies additional paths from which the OpenEmbedded build system gets source code."
>  MLPREFIX[doc] = "Specifies a prefix has been added to PN to create a special version of a recipe or package, such as a Multilib version."
>  MODULE_TARBALL_DEPLOY[doc] = "Controls creation of the modules-*.tgz file. Set this variable to "0" to disable creation of this file, which contains all of the kernel modules resulting from a kernel build."
> +KERNEL_MODULE_INSTALL_PREFIX[doc] = "When a recipe inherits the module class, this variable specifies the directory to which kernel modules are installed on target."

You forgot to alphabetically order this new variable, I think

Antonin


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing
  2026-08-25 20:49 ` [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing Anis Bougrine
@ 2026-08-26  8:33   ` Richard Purdie
  2026-08-26  9:55     ` Bougrine Anis
  0 siblings, 1 reply; 10+ messages in thread
From: Richard Purdie @ 2026-08-26  8:33 UTC (permalink / raw)
  To: Anis Bougrine, openembedded-core
  Cc: mathieu.dubois-briand, peter.kjellerstedt, Ross Burton

On Tue, 2026-08-25 at 22:49 +0200, Anis Bougrine wrote:
> Fixes [YOCTO #12927]
> 
> Out-of-tree module Makefiles invoke the kernel Makefile by appending
> the M= (the module directory) variable to the MAKEFLAGS.
> However, they usually do not provide a modules_sign target. Therefore,
> the kernel modules_sign target has to be invoked manually after retrieving
> M= variable from package source code Makefile.
> 
> This function retrieves the M= variable from an external module Makefile.
> 
> Reported-by: Ross Burton <ross.burton@arm.com>
> Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
> ---
>  .../kernel-module-split.bbclass               | 21 +++++++++++++++++++
>  1 file changed, 21 insertions(+)
> 
> diff --git a/meta/classes-recipe/kernel-module-split.bbclass b/meta/classes-recipe/kernel-module-split.bbclass
> index ab2f0d1c37..bde7cd02dd 100644
> --- a/meta/classes-recipe/kernel-module-split.bbclass
> +++ b/meta/classes-recipe/kernel-module-split.bbclass
> @@ -42,6 +42,27 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
>  KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
>  KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
>  
> +def get_ext_mod(d):
> +    """
> +    Extract the resolved Kbuild M= variable from an out of tree module Makefile variable database.
> +    """
> +    import re
> +    import bb.process
> +
> +    try:
> +        output = bb.process.run(
> +            "make -C %s --dry-run --print-data-base" % d.getVar("B")
> +        )[0]
> +    except bb.process.ExecutionError:
> +        return d.getVar("S")
> +
> +    for line in output.splitlines():
> +        m = re.match(r'^M\s*=\s*(.*)$', line)
> +        if m:
> +            return m.group(1).strip()
> +
> +    return d.getVar("S")
> +
>  python split_kernel_module_packages () {
>      import re
> 

Sorry, a couple of more things. I'm not sure if it helps but there is a
scripts/makefile-getvar which may be a simpler way to do this? It was
created for this kind of usage.

Also, we're aiming to move python functions into meta/lib/oe, probably
kernel.py in this case so new functions should really go in there.

Cheers,

Richard


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing
  2026-08-26  8:33   ` Richard Purdie
@ 2026-08-26  9:55     ` Bougrine Anis
  0 siblings, 0 replies; 10+ messages in thread
From: Bougrine Anis @ 2026-08-26  9:55 UTC (permalink / raw)
  To: Richard Purdie
  Cc: openembedded-core, mathieu.dubois-briand, peter.kjellerstedt,
	Ross Burton

[-- Attachment #1: Type: text/plain, Size: 3136 bytes --]

Hello Richard,

Thank you for your precious feedback.
In fact, "makefile-getvar" script is minimalistic and it reads only
variables defined directly in the Makefile and does not retrieve the
complete Make variable database.
For example, in "cryptodev-module" out-of-tree module Makefile, "M" was
defined through "KERNEL_MAKE_OPTS" variable:

In Makefile:
...
KERNEL_MAKE_OPTS := -C $(KERNEL_DIR) M=$(CURDIR)
...
modules_install:
$(MAKE) $(KERNEL_MAKE_OPTS) modules_install
...

In this case, "cryptodev-module" can read the "KERNEL_MAKE_OPTS" variable
but can not read the "M" variable.
Therefore, I think it's a good idea to follow your suggestion and move the
Python function to "meta/lib/oe".

BR,
Anis

On Wed, Aug 26, 2026 at 10:34 AM Richard Purdie <
richard.purdie@linuxfoundation.org> wrote:

> On Tue, 2026-08-25 at 22:49 +0200, Anis Bougrine wrote:
> > Fixes [YOCTO #12927]
> >
> > Out-of-tree module Makefiles invoke the kernel Makefile by appending
> > the M= (the module directory) variable to the MAKEFLAGS.
> > However, they usually do not provide a modules_sign target. Therefore,
> > the kernel modules_sign target has to be invoked manually after
> retrieving
> > M= variable from package source code Makefile.
> >
> > This function retrieves the M= variable from an external module Makefile.
> >
> > Reported-by: Ross Burton <ross.burton@arm.com>
> > Signed-off-by: Anis Bougrine <anis.bougrine10@gmail.com>
> > ---
> >  .../kernel-module-split.bbclass               | 21 +++++++++++++++++++
> >  1 file changed, 21 insertions(+)
> >
> > diff --git a/meta/classes-recipe/kernel-module-split.bbclass
> b/meta/classes-recipe/kernel-module-split.bbclass
> > index ab2f0d1c37..bde7cd02dd 100644
> > --- a/meta/classes-recipe/kernel-module-split.bbclass
> > +++ b/meta/classes-recipe/kernel-module-split.bbclass
> > @@ -42,6 +42,27 @@ KERNEL_MODULE_PACKAGE_PREFIX ?= ""
> >  KERNEL_MODULE_PACKAGE_SUFFIX ?= "-${KERNEL_VERSION}"
> >  KERNEL_MODULE_PROVIDE_VIRTUAL ?= "1"
> >
> > +def get_ext_mod(d):
> > +    """
> > +    Extract the resolved Kbuild M= variable from an out of tree module
> Makefile variable database.
> > +    """
> > +    import re
> > +    import bb.process
> > +
> > +    try:
> > +        output = bb.process.run(
> > +            "make -C %s --dry-run --print-data-base" % d.getVar("B")
> > +        )[0]
> > +    except bb.process.ExecutionError:
> > +        return d.getVar("S")
> > +
> > +    for line in output.splitlines():
> > +        m = re.match(r'^M\s*=\s*(.*)$', line)
> > +        if m:
> > +            return m.group(1).strip()
> > +
> > +    return d.getVar("S")
> > +
> >  python split_kernel_module_packages () {
> >      import re
> >
>
> Sorry, a couple of more things. I'm not sure if it helps but there is a
> scripts/makefile-getvar which may be a simpler way to do this? It was
> created for this kind of usage.
>
> Also, we're aiming to move python functions into meta/lib/oe, probably
> kernel.py in this case so new functions should really go in there.
>
> Cheers,
>
> Richard
>

[-- Attachment #2: Type: text/html, Size: 4669 bytes --]

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-08-26  9:56 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25 20:49 [OE-core][PATCH v5 0/5] Make signed kernel modules stripped Anis Bougrine
2026-08-25 20:49 ` [OE-core][PATCH v5 1/5] kernel-module-split.bbclass: add get_ext_mod function for module signing Anis Bougrine
2026-08-26  8:33   ` Richard Purdie
2026-08-26  9:55     ` Bougrine Anis
2026-08-25 20:49 ` [OE-core][PATCH v5 2/5] kernel: re-sign kernel modules after package stripping process Anis Bougrine
2026-08-25 20:49 ` [OE-core][PATCH v5 3/5] package.py: remove stripping and splitting skip for signed kernel modules Anis Bougrine
2026-08-25 20:49 ` [OE-core][PATCH v5 4/5] kernel: centralize kernel module installation path in one variable Anis Bougrine
2026-08-25 20:49 ` [OE-core][PATCH v5 5/5] documentation.conf: add documentation for KERNEL_MODULE_INSTALL_PREFIX variable Anis Bougrine
2026-08-25 21:03   ` Patchtest results for " patchtest
2026-08-26  7:24   ` Antonin Godard

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox