Yocto Project Discussions
 help / color / mirror / Atom feed
From: "akuster" <akuster808@gmail.com>
To: Naveen Saini <naveen.kumar.saini@intel.com>,
	yocto@lists.yoctoproject.org
Subject: Re: [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices
Date: Fri, 9 Oct 2020 07:24:18 -0700	[thread overview]
Message-ID: <d4c64563-e92b-5632-3a71-ec059cc060c1@gmail.com> (raw)
In-Reply-To: <20201002025352.18830-1-naveen.kumar.saini@intel.com>



On 10/1/20 7:53 PM, Naveen Saini wrote:
> Detection of USB devices by the kernel is slow enough. We need to
> keep trying for a while (default: 5s seconds, controlled by roottimeout=<seconds>)
> and sleep between each attempt (default: one second, rootdelay=<seconds>).
>
> Fix is based on https://git.yoctoproject.org/cgit.cgi/poky/commit/meta/recipes-core/initrdscripts/initramfs-framework/rootfs?id=ee6a6c3461694ce09789bf4d852cea2e22fc95e4
>
> Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
> ---
>  .../initramfs-framework/dmverity              | 64 +++++++++++--------
>  1 file changed, 37 insertions(+), 27 deletions(-)

series merge.

thanks
>
> diff --git a/recipes-core/initrdscripts/initramfs-framework/dmverity b/recipes-core/initrdscripts/initramfs-framework/dmverity
> index bb07aab..888052c 100644
> --- a/recipes-core/initrdscripts/initramfs-framework/dmverity
> +++ b/recipes-core/initrdscripts/initramfs-framework/dmverity
> @@ -10,33 +10,43 @@ dmverity_run() {
>  
>      . /usr/share/misc/dm-verity.env
>  
> -    case "${bootparam_root}" in
> -        ID=*)
> -            RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> -            ;;
> -        LABEL=*)
> -            RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> -            ;;
> -        PARTLABEL=*)
> -            RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> -            ;;
> -        PARTUUID=*)
> -            RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> -            ;;
> -        PATH=*)
> -            RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> -            ;;
> -        UUID=*)
> -            RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> -            ;;
> -        *)
> -            RDEV="${bootparam_root}"
> -    esac
> -
> -    if ! [ -b "${RDEV}" ]; then
> -        echo "Root device resolution failed"
> -        exit 1
> -    fi
> +    C=0
> +    delay=${bootparam_rootdelay:-1}
> +    timeout=${bootparam_roottimeout:-5}
> +    RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> +    while [ ! -b "${RDEV}" ]; do
> +        if [ $(( $C * $delay )) -gt $timeout ]; then
> +            fatal "Root device resolution failed"
> +            exit 1
> +        fi
> +
> +        case "${bootparam_root}" in
> +            ID=*)
> +                RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> +                ;;
> +            LABEL=*)
> +                RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> +                ;;
> +            PARTLABEL=*)
> +                RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> +                ;;
> +            PARTUUID=*)
> +                RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> +                ;;
> +            PATH=*)
> +                RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> +                ;;
> +            UUID=*)
> +                RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> +                ;;
> +            *)
> +                RDEV="${bootparam_root}"
> +        esac
> +        debug "Sleeping for $delay second(s) to wait root to settle..."
> +        sleep $delay
> +        C=$(( $C + 1 ))
> +
> +    done
>  
>      veritysetup \
>          --data-block-size=1024 \
>
> 
>


      parent reply	other threads:[~2020-10-09 14:24 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-10-02  2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
2020-10-02  2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
2020-10-02  2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
2020-10-09 14:24 ` akuster [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d4c64563-e92b-5632-3a71-ec059cc060c1@gmail.com \
    --to=akuster808@gmail.com \
    --cc=naveen.kumar.saini@intel.com \
    --cc=yocto@lists.yoctoproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox