* [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices
@ 2020-10-02 2:53 Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Naveen Saini @ 2020-10-02 2:53 UTC (permalink / raw)
To: yocto
Detection of USB devices by the kernel is slow enough. We need to
keep trying for a while (default: 5s seconds, controlled by roottimeout=<seconds>)
and sleep between each attempt (default: one second, rootdelay=<seconds>).
Fix is based on https://git.yoctoproject.org/cgit.cgi/poky/commit/meta/recipes-core/initrdscripts/initramfs-framework/rootfs?id=ee6a6c3461694ce09789bf4d852cea2e22fc95e4
Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
---
.../initramfs-framework/dmverity | 64 +++++++++++--------
1 file changed, 37 insertions(+), 27 deletions(-)
diff --git a/recipes-core/initrdscripts/initramfs-framework/dmverity b/recipes-core/initrdscripts/initramfs-framework/dmverity
index bb07aab..888052c 100644
--- a/recipes-core/initrdscripts/initramfs-framework/dmverity
+++ b/recipes-core/initrdscripts/initramfs-framework/dmverity
@@ -10,33 +10,43 @@ dmverity_run() {
. /usr/share/misc/dm-verity.env
- case "${bootparam_root}" in
- ID=*)
- RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
- ;;
- LABEL=*)
- RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
- ;;
- PARTLABEL=*)
- RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
- ;;
- PARTUUID=*)
- RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
- ;;
- PATH=*)
- RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
- ;;
- UUID=*)
- RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
- ;;
- *)
- RDEV="${bootparam_root}"
- esac
-
- if ! [ -b "${RDEV}" ]; then
- echo "Root device resolution failed"
- exit 1
- fi
+ C=0
+ delay=${bootparam_rootdelay:-1}
+ timeout=${bootparam_roottimeout:-5}
+ RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
+ while [ ! -b "${RDEV}" ]; do
+ if [ $(( $C * $delay )) -gt $timeout ]; then
+ fatal "Root device resolution failed"
+ exit 1
+ fi
+
+ case "${bootparam_root}" in
+ ID=*)
+ RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
+ ;;
+ LABEL=*)
+ RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
+ ;;
+ PARTLABEL=*)
+ RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
+ ;;
+ PARTUUID=*)
+ RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
+ ;;
+ PATH=*)
+ RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
+ ;;
+ UUID=*)
+ RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
+ ;;
+ *)
+ RDEV="${bootparam_root}"
+ esac
+ debug "Sleeping for $delay second(s) to wait root to settle..."
+ sleep $delay
+ C=$(( $C + 1 ))
+
+ done
veritysetup \
--data-block-size=1024 \
--
2.17.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity
2020-10-02 2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
@ 2020-10-02 2:53 ` Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
2020-10-09 14:24 ` [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices akuster
2 siblings, 0 replies; 4+ messages in thread
From: Naveen Saini @ 2020-10-02 2:53 UTC (permalink / raw)
To: yocto
Based on systemd-bootdisk-microcode.wks.in, this adds
the dm-verity image similar to the beaglebone wks
already in meta-security.
Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
---
wic/systemd-bootdisk-dmverity.wks.in | 15 +++++++++++++++
1 file changed, 15 insertions(+)
create mode 100644 wic/systemd-bootdisk-dmverity.wks.in
diff --git a/wic/systemd-bootdisk-dmverity.wks.in b/wic/systemd-bootdisk-dmverity.wks.in
new file mode 100644
index 0000000..ef114ca
--- /dev/null
+++ b/wic/systemd-bootdisk-dmverity.wks.in
@@ -0,0 +1,15 @@
+# A dm-verity variant of the regular wks for IA machines. We need to fetch
+# the partition images from the IMGDEPLOYDIR as the rootfs source plugin will
+# not recreate the exact block device corresponding with the hash tree. We must
+# not alter the label or any other setting on the image.
+# Based on OE-core's systemd-bootdisk.wks and meta-security's beaglebone-yocto-verity.wks.in file
+#
+# This .wks only works with the dm-verity-img class.
+
+part /boot --source bootimg-efi --sourceparams="loader=systemd-boot,initrd=microcode.cpio" --ondisk sda --label msdos --active --align 1024 --use-uuid
+
+part / --source rawcopy --ondisk sda --sourceparams="file=${IMGDEPLOYDIR}/${DM_VERITY_IMAGE}-${MACHINE}.${DM_VERITY_IMAGE_TYPE}.verity" --use-uuid
+
+part swap --ondisk sda --size 44 --label swap1 --fstype=swap --use-uuid
+
+bootloader --ptable gpt --timeout=5 --append=" "
--
2.17.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed
2020-10-02 2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
@ 2020-10-02 2:53 ` Naveen Saini
2020-10-09 14:24 ` [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices akuster
2 siblings, 0 replies; 4+ messages in thread
From: Naveen Saini @ 2020-10-02 2:53 UTC (permalink / raw)
To: yocto
Add checks that include dm-verity specific kernel config fragment
when dm-verity-img.bbclass is used.
Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
---
recipes-kernel/linux/linux-%_5.%.bbappend | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/recipes-kernel/linux/linux-%_5.%.bbappend b/recipes-kernel/linux/linux-%_5.%.bbappend
index 76b5df5..6bc40cd 100644
--- a/recipes-kernel/linux/linux-%_5.%.bbappend
+++ b/recipes-kernel/linux/linux-%_5.%.bbappend
@@ -1,4 +1,4 @@
KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "apparmor", " features/apparmor/apparmor.scc", "" ,d)}"
KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "smack", " features/smack/smack.scc", "" ,d)}"
KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "yama", " features/yama/yama.scc", "" ,d)}"
-
+KERNEL_FEATURES_append = " ${@bb.utils.contains("IMAGE_CLASSES", "dm-verity-img", " features/device-mapper/dm-verity.scc", "" ,d)}"
--
2.17.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices
2020-10-02 2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
@ 2020-10-09 14:24 ` akuster
2 siblings, 0 replies; 4+ messages in thread
From: akuster @ 2020-10-09 14:24 UTC (permalink / raw)
To: Naveen Saini, yocto
On 10/1/20 7:53 PM, Naveen Saini wrote:
> Detection of USB devices by the kernel is slow enough. We need to
> keep trying for a while (default: 5s seconds, controlled by roottimeout=<seconds>)
> and sleep between each attempt (default: one second, rootdelay=<seconds>).
>
> Fix is based on https://git.yoctoproject.org/cgit.cgi/poky/commit/meta/recipes-core/initrdscripts/initramfs-framework/rootfs?id=ee6a6c3461694ce09789bf4d852cea2e22fc95e4
>
> Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
> ---
> .../initramfs-framework/dmverity | 64 +++++++++++--------
> 1 file changed, 37 insertions(+), 27 deletions(-)
series merge.
thanks
>
> diff --git a/recipes-core/initrdscripts/initramfs-framework/dmverity b/recipes-core/initrdscripts/initramfs-framework/dmverity
> index bb07aab..888052c 100644
> --- a/recipes-core/initrdscripts/initramfs-framework/dmverity
> +++ b/recipes-core/initrdscripts/initramfs-framework/dmverity
> @@ -10,33 +10,43 @@ dmverity_run() {
>
> . /usr/share/misc/dm-verity.env
>
> - case "${bootparam_root}" in
> - ID=*)
> - RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> - ;;
> - LABEL=*)
> - RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> - ;;
> - PARTLABEL=*)
> - RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> - ;;
> - PARTUUID=*)
> - RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> - ;;
> - PATH=*)
> - RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> - ;;
> - UUID=*)
> - RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> - ;;
> - *)
> - RDEV="${bootparam_root}"
> - esac
> -
> - if ! [ -b "${RDEV}" ]; then
> - echo "Root device resolution failed"
> - exit 1
> - fi
> + C=0
> + delay=${bootparam_rootdelay:-1}
> + timeout=${bootparam_roottimeout:-5}
> + RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> + while [ ! -b "${RDEV}" ]; do
> + if [ $(( $C * $delay )) -gt $timeout ]; then
> + fatal "Root device resolution failed"
> + exit 1
> + fi
> +
> + case "${bootparam_root}" in
> + ID=*)
> + RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> + ;;
> + LABEL=*)
> + RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> + ;;
> + PARTLABEL=*)
> + RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> + ;;
> + PARTUUID=*)
> + RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> + ;;
> + PATH=*)
> + RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> + ;;
> + UUID=*)
> + RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> + ;;
> + *)
> + RDEV="${bootparam_root}"
> + esac
> + debug "Sleeping for $delay second(s) to wait root to settle..."
> + sleep $delay
> + C=$(( $C + 1 ))
> +
> + done
>
> veritysetup \
> --data-block-size=1024 \
>
>
>
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2020-10-09 14:24 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-10-02 2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
2020-10-02 2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
2020-10-09 14:24 ` [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices akuster
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox