From: "akuster" <akuster808@gmail.com>
To: Naveen Saini <naveen.kumar.saini@intel.com>,
yocto@lists.yoctoproject.org
Subject: Re: [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices
Date: Fri, 9 Oct 2020 07:24:18 -0700 [thread overview]
Message-ID: <d4c64563-e92b-5632-3a71-ec059cc060c1@gmail.com> (raw)
In-Reply-To: <20201002025352.18830-1-naveen.kumar.saini@intel.com>
On 10/1/20 7:53 PM, Naveen Saini wrote:
> Detection of USB devices by the kernel is slow enough. We need to
> keep trying for a while (default: 5s seconds, controlled by roottimeout=<seconds>)
> and sleep between each attempt (default: one second, rootdelay=<seconds>).
>
> Fix is based on https://git.yoctoproject.org/cgit.cgi/poky/commit/meta/recipes-core/initrdscripts/initramfs-framework/rootfs?id=ee6a6c3461694ce09789bf4d852cea2e22fc95e4
>
> Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
> ---
> .../initramfs-framework/dmverity | 64 +++++++++++--------
> 1 file changed, 37 insertions(+), 27 deletions(-)
series merge.
thanks
>
> diff --git a/recipes-core/initrdscripts/initramfs-framework/dmverity b/recipes-core/initrdscripts/initramfs-framework/dmverity
> index bb07aab..888052c 100644
> --- a/recipes-core/initrdscripts/initramfs-framework/dmverity
> +++ b/recipes-core/initrdscripts/initramfs-framework/dmverity
> @@ -10,33 +10,43 @@ dmverity_run() {
>
> . /usr/share/misc/dm-verity.env
>
> - case "${bootparam_root}" in
> - ID=*)
> - RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> - ;;
> - LABEL=*)
> - RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> - ;;
> - PARTLABEL=*)
> - RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> - ;;
> - PARTUUID=*)
> - RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> - ;;
> - PATH=*)
> - RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> - ;;
> - UUID=*)
> - RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> - ;;
> - *)
> - RDEV="${bootparam_root}"
> - esac
> -
> - if ! [ -b "${RDEV}" ]; then
> - echo "Root device resolution failed"
> - exit 1
> - fi
> + C=0
> + delay=${bootparam_rootdelay:-1}
> + timeout=${bootparam_roottimeout:-5}
> + RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> + while [ ! -b "${RDEV}" ]; do
> + if [ $(( $C * $delay )) -gt $timeout ]; then
> + fatal "Root device resolution failed"
> + exit 1
> + fi
> +
> + case "${bootparam_root}" in
> + ID=*)
> + RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> + ;;
> + LABEL=*)
> + RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> + ;;
> + PARTLABEL=*)
> + RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> + ;;
> + PARTUUID=*)
> + RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> + ;;
> + PATH=*)
> + RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> + ;;
> + UUID=*)
> + RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> + ;;
> + *)
> + RDEV="${bootparam_root}"
> + esac
> + debug "Sleeping for $delay second(s) to wait root to settle..."
> + sleep $delay
> + C=$(( $C + 1 ))
> +
> + done
>
> veritysetup \
> --data-block-size=1024 \
>
>
>
prev parent reply other threads:[~2020-10-09 14:24 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-10-02 2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
2020-10-09 14:24 ` akuster [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d4c64563-e92b-5632-3a71-ec059cc060c1@gmail.com \
--to=akuster808@gmail.com \
--cc=naveen.kumar.saini@intel.com \
--cc=yocto@lists.yoctoproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox