Yocto Project Discussions
 help / color / mirror / Atom feed
* [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices
@ 2020-10-02  2:53 Naveen Saini
  2020-10-02  2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Naveen Saini @ 2020-10-02  2:53 UTC (permalink / raw)
  To: yocto

Detection of USB devices by the kernel is slow enough. We need to
keep trying for a while (default: 5s seconds, controlled by roottimeout=<seconds>)
and sleep between each attempt (default: one second, rootdelay=<seconds>).

Fix is based on https://git.yoctoproject.org/cgit.cgi/poky/commit/meta/recipes-core/initrdscripts/initramfs-framework/rootfs?id=ee6a6c3461694ce09789bf4d852cea2e22fc95e4

Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
---
 .../initramfs-framework/dmverity              | 64 +++++++++++--------
 1 file changed, 37 insertions(+), 27 deletions(-)

diff --git a/recipes-core/initrdscripts/initramfs-framework/dmverity b/recipes-core/initrdscripts/initramfs-framework/dmverity
index bb07aab..888052c 100644
--- a/recipes-core/initrdscripts/initramfs-framework/dmverity
+++ b/recipes-core/initrdscripts/initramfs-framework/dmverity
@@ -10,33 +10,43 @@ dmverity_run() {
 
     . /usr/share/misc/dm-verity.env
 
-    case "${bootparam_root}" in
-        ID=*)
-            RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
-            ;;
-        LABEL=*)
-            RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
-            ;;
-        PARTLABEL=*)
-            RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
-            ;;
-        PARTUUID=*)
-            RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
-            ;;
-        PATH=*)
-            RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
-            ;;
-        UUID=*)
-            RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
-            ;;
-        *)
-            RDEV="${bootparam_root}"
-    esac
-
-    if ! [ -b "${RDEV}" ]; then
-        echo "Root device resolution failed"
-        exit 1
-    fi
+    C=0
+    delay=${bootparam_rootdelay:-1}
+    timeout=${bootparam_roottimeout:-5}
+    RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
+    while [ ! -b "${RDEV}" ]; do
+        if [ $(( $C * $delay )) -gt $timeout ]; then
+            fatal "Root device resolution failed"
+            exit 1
+        fi
+
+        case "${bootparam_root}" in
+            ID=*)
+                RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
+                ;;
+            LABEL=*)
+                RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
+                ;;
+            PARTLABEL=*)
+                RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
+                ;;
+            PARTUUID=*)
+                RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
+                ;;
+            PATH=*)
+                RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
+                ;;
+            UUID=*)
+                RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
+                ;;
+            *)
+                RDEV="${bootparam_root}"
+        esac
+        debug "Sleeping for $delay second(s) to wait root to settle..."
+        sleep $delay
+        C=$(( $C + 1 ))
+
+    done
 
     veritysetup \
         --data-block-size=1024 \
-- 
2.17.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity
  2020-10-02  2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
@ 2020-10-02  2:53 ` Naveen Saini
  2020-10-02  2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
  2020-10-09 14:24 ` [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices akuster
  2 siblings, 0 replies; 4+ messages in thread
From: Naveen Saini @ 2020-10-02  2:53 UTC (permalink / raw)
  To: yocto

Based on systemd-bootdisk-microcode.wks.in, this adds
the dm-verity image similar to the beaglebone wks
already in meta-security.

Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
---
 wic/systemd-bootdisk-dmverity.wks.in | 15 +++++++++++++++
 1 file changed, 15 insertions(+)
 create mode 100644 wic/systemd-bootdisk-dmverity.wks.in

diff --git a/wic/systemd-bootdisk-dmverity.wks.in b/wic/systemd-bootdisk-dmverity.wks.in
new file mode 100644
index 0000000..ef114ca
--- /dev/null
+++ b/wic/systemd-bootdisk-dmverity.wks.in
@@ -0,0 +1,15 @@
+# A dm-verity variant of the regular wks for IA machines. We need to fetch
+# the partition images from the IMGDEPLOYDIR as the rootfs source plugin will
+# not recreate the exact block device corresponding with the hash tree. We must
+# not alter the label or any other setting on the image.
+# Based on OE-core's systemd-bootdisk.wks and meta-security's beaglebone-yocto-verity.wks.in file
+#
+# This .wks only works with the dm-verity-img class.
+
+part /boot --source bootimg-efi --sourceparams="loader=systemd-boot,initrd=microcode.cpio" --ondisk sda --label msdos --active --align 1024 --use-uuid
+
+part / --source rawcopy --ondisk sda  --sourceparams="file=${IMGDEPLOYDIR}/${DM_VERITY_IMAGE}-${MACHINE}.${DM_VERITY_IMAGE_TYPE}.verity" --use-uuid
+
+part swap --ondisk sda --size 44 --label swap1 --fstype=swap --use-uuid
+
+bootloader --ptable gpt --timeout=5 --append=" "
-- 
2.17.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed
  2020-10-02  2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
  2020-10-02  2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
@ 2020-10-02  2:53 ` Naveen Saini
  2020-10-09 14:24 ` [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices akuster
  2 siblings, 0 replies; 4+ messages in thread
From: Naveen Saini @ 2020-10-02  2:53 UTC (permalink / raw)
  To: yocto

Add checks that include dm-verity specific kernel config fragment
when dm-verity-img.bbclass is used.

Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
---
 recipes-kernel/linux/linux-%_5.%.bbappend | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/recipes-kernel/linux/linux-%_5.%.bbappend b/recipes-kernel/linux/linux-%_5.%.bbappend
index 76b5df5..6bc40cd 100644
--- a/recipes-kernel/linux/linux-%_5.%.bbappend
+++ b/recipes-kernel/linux/linux-%_5.%.bbappend
@@ -1,4 +1,4 @@
 KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "apparmor", " features/apparmor/apparmor.scc", "" ,d)}"
 KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "smack", " features/smack/smack.scc", "" ,d)}"
 KERNEL_FEATURES_append = " ${@bb.utils.contains("DISTRO_FEATURES", "yama", " features/yama/yama.scc", "" ,d)}"
-
+KERNEL_FEATURES_append = " ${@bb.utils.contains("IMAGE_CLASSES", "dm-verity-img", " features/device-mapper/dm-verity.scc", "" ,d)}"
-- 
2.17.1


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices
  2020-10-02  2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
  2020-10-02  2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
  2020-10-02  2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
@ 2020-10-09 14:24 ` akuster
  2 siblings, 0 replies; 4+ messages in thread
From: akuster @ 2020-10-09 14:24 UTC (permalink / raw)
  To: Naveen Saini, yocto



On 10/1/20 7:53 PM, Naveen Saini wrote:
> Detection of USB devices by the kernel is slow enough. We need to
> keep trying for a while (default: 5s seconds, controlled by roottimeout=<seconds>)
> and sleep between each attempt (default: one second, rootdelay=<seconds>).
>
> Fix is based on https://git.yoctoproject.org/cgit.cgi/poky/commit/meta/recipes-core/initrdscripts/initramfs-framework/rootfs?id=ee6a6c3461694ce09789bf4d852cea2e22fc95e4
>
> Signed-off-by: Naveen Saini <naveen.kumar.saini@intel.com>
> ---
>  .../initramfs-framework/dmverity              | 64 +++++++++++--------
>  1 file changed, 37 insertions(+), 27 deletions(-)

series merge.

thanks
>
> diff --git a/recipes-core/initrdscripts/initramfs-framework/dmverity b/recipes-core/initrdscripts/initramfs-framework/dmverity
> index bb07aab..888052c 100644
> --- a/recipes-core/initrdscripts/initramfs-framework/dmverity
> +++ b/recipes-core/initrdscripts/initramfs-framework/dmverity
> @@ -10,33 +10,43 @@ dmverity_run() {
>  
>      . /usr/share/misc/dm-verity.env
>  
> -    case "${bootparam_root}" in
> -        ID=*)
> -            RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> -            ;;
> -        LABEL=*)
> -            RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> -            ;;
> -        PARTLABEL=*)
> -            RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> -            ;;
> -        PARTUUID=*)
> -            RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> -            ;;
> -        PATH=*)
> -            RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> -            ;;
> -        UUID=*)
> -            RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> -            ;;
> -        *)
> -            RDEV="${bootparam_root}"
> -    esac
> -
> -    if ! [ -b "${RDEV}" ]; then
> -        echo "Root device resolution failed"
> -        exit 1
> -    fi
> +    C=0
> +    delay=${bootparam_rootdelay:-1}
> +    timeout=${bootparam_roottimeout:-5}
> +    RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> +    while [ ! -b "${RDEV}" ]; do
> +        if [ $(( $C * $delay )) -gt $timeout ]; then
> +            fatal "Root device resolution failed"
> +            exit 1
> +        fi
> +
> +        case "${bootparam_root}" in
> +            ID=*)
> +                RDEV="$(realpath /dev/disk/by-id/${bootparam_root#ID=})"
> +                ;;
> +            LABEL=*)
> +                RDEV="$(realpath /dev/disk/by-label/${bootparam_root#LABEL=})"
> +                ;;
> +            PARTLABEL=*)
> +                RDEV="$(realpath /dev/disk/by-partlabel/${bootparam_root#PARTLABEL=})"
> +                ;;
> +            PARTUUID=*)
> +                RDEV="$(realpath /dev/disk/by-partuuid/${bootparam_root#PARTUUID=})"
> +                ;;
> +            PATH=*)
> +                RDEV="$(realpath /dev/disk/by-path/${bootparam_root#PATH=})"
> +                ;;
> +            UUID=*)
> +                RDEV="$(realpath /dev/disk/by-uuid/${bootparam_root#UUID=})"
> +                ;;
> +            *)
> +                RDEV="${bootparam_root}"
> +        esac
> +        debug "Sleeping for $delay second(s) to wait root to settle..."
> +        sleep $delay
> +        C=$(( $C + 1 ))
> +
> +    done
>  
>      veritysetup \
>          --data-block-size=1024 \
>
> 
>


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2020-10-09 14:24 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-10-02  2:53 [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices Naveen Saini
2020-10-02  2:53 ` [meta-security][PATCH 2/3] wic: add wks.in for intel dm-verity Naveen Saini
2020-10-02  2:53 ` [meta-security][PATCH 3/3] linux-%/5.x: Add dm-verity fragment as needed Naveen Saini
2020-10-09 14:24 ` [yocto] [meta-security][PATCH 1/3] initramfs-framework/dmverity: add retry loop for slow boot devices akuster

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox