Re: [meta-ti][master][PATCH v4 1/3] linux-ti-staging: Add LUKS encryption config
Ryan Eatmon <[email protected]>
| Newsgroups | org.yoctoproject.lists.meta-ti |
|---|---|
| Message-ID | <[email protected]> |
On 3/5/2026 11:21 AM, Shiva Tripathi wrote: > Add conditional kernel configuration fragment for LUKS encryption with > fTPM support. This enables dm-crypt and necessary crypto algorithms > when MACHINE_FEATURES contains 'luks-encryption'. > > Signed-off-by: Shiva Tripathi <[email protected]> > --- > .../linux/linux-ti-staging-6.18/luks-ftpm.cfg | 28 +++++++++++++++++++ > .../linux/linux-ti-staging_6.18.bb | 9 ++++++ > 2 files changed, 37 insertions(+) > create mode 100644 meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-ftpm.cfg > > diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-ftpm.cfg b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-ftpm.cfg > new file mode 100644 > index 00000000..234cc087 > --- /dev/null > +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-ftpm.cfg > @@ -0,0 +1,28 @@ > +# Device Mapper support > +CONFIG_MD=y > +CONFIG_BLK_DEV_DM=y > +CONFIG_DM_CRYPT=y > + > +# Crypto algorithms for LUKS > +CONFIG_CRYPTO_XTS=y > +CONFIG_CRYPTO_AES=y > +CONFIG_CRYPTO_AES_ARM64=y > +CONFIG_CRYPTO_AES_ARM64_CE=y > +CONFIG_CRYPTO_AES_ARM64_CE_BLK=y > +CONFIG_CRYPTO_SHA256=y > +CONFIG_CRYPTO_SHA256_ARM64=y > +CONFIG_CRYPTO_SHA512=y > +CONFIG_CRYPTO_USER_API_HASH=y > +CONFIG_CRYPTO_USER_API_SKCIPHER=y > + > +# Additional crypto support for LUKS2 > +CONFIG_CRYPTO_CBC=y > +CONFIG_CRYPTO_ECB=y > +CONFIG_CRYPTO_ESSIV=y > +CONFIG_CRYPTO_LRW=y > +CONFIG_CRYPTO_PCBC=y > + > +# TPM kernel modules needed for initramfs > +CONFIG_TCG_TIS_CORE=m > +CONFIG_TCG_CRB=m > + > diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb > index 8e4ccd7d..69d6217f 100644 > --- a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb > +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb > @@ -35,3 +35,12 @@ module_conf_rpmsg_client_sample = "blacklist rpmsg_client_sample" > module_conf_ti_k3_r5_remoteproc = "softdep ti_k3_r5_remoteproc pre: virtio_rpmsg_bus" > module_conf_ti_k3_dsp_remoteproc = "softdep ti_k3_dsp_remoteproc pre: virtio_rpmsg_bus" > KERNEL_MODULE_PROBECONF += "rpmsg_client_sample ti_k3_r5_remoteproc ti_k3_dsp_remoteproc" > + After thinking about this a little more... I'm thinking that the luks-encryption is more of a DISTRO_FEATURE and not a MACHINE_FEATURE. "tpm" would be a MACHINE_FEATURE. And the best most correct thing to do would be to do some combination of the two. I assume that only some of our boards have tpm support, right? So I would go through the effort to add that to all of the correct boards, and then change the logic to check both variables. I'll reply on the other patches with those changes. > +# LUKS encryption with fTPM kernel configuration > +SRC_URI:append:k3 = " \ > + ${@bb.utils.contains('MACHINE_FEATURES', 'luks-encryption', 'file://luks-ftpm.cfg', '', d)} \ ${@bb.utils.contains('DISTRO_FEATURES', 'luks', 'file://luks-ftpm.cfg', '', d)} > +" > +KERNEL_CONFIG_FRAGMENTS:append:k3 = " \ > + ${@bb.utils.contains('MACHINE_FEATURES', 'luks-encryption', '${UNPACKDIR}/luks-ftpm.cfg', '', d)} \ > +" > + ${@bb.utils.contains('DISTRO_FEATURES', 'luks', '${UNPACKDIR}/luks-ftpm.cfg', '', d)} -- Ryan Eatmon [email protected] ----------------------------------------- Texas Instruments, Inc. - LCPD - MGTS