Re: [meta-ti][master][PATCH v4 1/3] linux-ti-staging: Add LUKS encryption config

Shiva Tripathi <[email protected]>
Newsgroups org.yoctoproject.lists.meta-ti
Message-ID <[email protected]>

On 3/6/26 01:43, Andrew Davis wrote:
> On 3/5/26 11:21 AM, Shiva Tripathi via lists.yoctoproject.org wrote:
>> Add conditional kernel configuration fragment for LUKS encryption with
>> fTPM support. This enables dm-crypt and necessary crypto algorithms
>> when MACHINE_FEATURES contains 'luks-encryption'.
>>
>> Signed-off-by: Shiva Tripathi <[email protected]>
>> ---
>>   .../linux/linux-ti-staging-6.18/luks-ftpm.cfg | 28 +++++++++++++++++++
>>   .../linux/linux-ti-staging_6.18.bb            |  9 ++++++
>>   2 files changed, 37 insertions(+)
>>   create mode 100644 meta-ti-bsp/recipes-kernel/linux/linux-ti-
>> staging-6.18/luks-ftpm.cfg
>>
>> diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/
>> luks-ftpm.cfg b/meta-ti-bsp/recipes-kernel/linux/linux-ti-
>> staging-6.18/luks-ftpm.cfg
>> new file mode 100644
>> index 00000000..234cc087
>> --- /dev/null
>> +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-
>> ftpm.cfg
>> @@ -0,0 +1,28 @@
>> +# Device Mapper support
>> +CONFIG_MD=y
>> +CONFIG_BLK_DEV_DM=y
>> +CONFIG_DM_CRYPT=y
>> +
>> +# Crypto algorithms for LUKS
>> +CONFIG_CRYPTO_XTS=y
>> +CONFIG_CRYPTO_AES=y
>> +CONFIG_CRYPTO_AES_ARM64=y
>> +CONFIG_CRYPTO_AES_ARM64_CE=y
>> +CONFIG_CRYPTO_AES_ARM64_CE_BLK=y
>> +CONFIG_CRYPTO_SHA256=y
>> +CONFIG_CRYPTO_SHA256_ARM64=y
> 
> Tell me more about this symbol, why did you pick it and what does it do.
> 
> Andrew

My understanding was adding this helps optimize SHA-256 on ARM64. But on
digging deeper, realized it's a Kconfig dependency chain which gets
selected automatically when SHA2_ARM64_CE/CONFIG_CRYPTO_SHA2_ARM64_CE is
enabled, so shouldn't be explicitly enabled here.

Also re-evaluated all other symbols in patch, not all were needed. The
required ones are:
"
# Device Mapper support
CONFIG_MD=y
CONFIG_BLK_DEV_DM=y
CONFIG_DM_CRYPT=y

# Core crypto algorithms for LUKS encryption
CONFIG_CRYPTO_AES=y
CONFIG_CRYPTO_XTS=y
CONFIG_CRYPTO_SHA256=y
CONFIG_CRYPTO_SHA512=y

# ARM64 optimized crypto for better performance
CONFIG_CRYPTO_AES_ARM64=y
CONFIG_CRYPTO_AES_ARM64_CE=y
CONFIG_CRYPTO_AES_ARM64_CE_BLK=y

# Userspace crypto API for cryptsetup
CONFIG_CRYPTO_USER_API_HASH=y
CONFIG_CRYPTO_USER_API_SKCIPHER=y
"
Few above are already present in ti-linux-kernel, but think it's good to
keep an inclusive set required for LUKS in case a user deviates from
ti-linux-kernel config and start observing failures here. Will send the
updated patch.

Thanks,
Shiva

> 
>> +CONFIG_CRYPTO_SHA512=y
>> +CONFIG_CRYPTO_USER_API_HASH=y
>> +CONFIG_CRYPTO_USER_API_SKCIPHER=y
>> +
>> +# Additional crypto support for LUKS2
>> +CONFIG_CRYPTO_CBC=y
>> +CONFIG_CRYPTO_ECB=y
>> +CONFIG_CRYPTO_ESSIV=y
>> +CONFIG_CRYPTO_LRW=y
>> +CONFIG_CRYPTO_PCBC=y
>> +
>> +# TPM kernel modules needed for initramfs
>> +CONFIG_TCG_TIS_CORE=m
>> +CONFIG_TCG_CRB=m
>> +
>> diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> index 8e4ccd7d..69d6217f 100644
>> --- a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> @@ -35,3 +35,12 @@ module_conf_rpmsg_client_sample = "blacklist
>> rpmsg_client_sample"
>>   module_conf_ti_k3_r5_remoteproc = "softdep ti_k3_r5_remoteproc pre:
>> virtio_rpmsg_bus"
>>   module_conf_ti_k3_dsp_remoteproc = "softdep ti_k3_dsp_remoteproc
>> pre: virtio_rpmsg_bus"
>>   KERNEL_MODULE_PROBECONF += "rpmsg_client_sample ti_k3_r5_remoteproc
>> ti_k3_dsp_remoteproc"
>> +
>> +# LUKS encryption with fTPM kernel configuration
>> +SRC_URI:append:k3 = " \
>> +    ${@bb.utils.contains('MACHINE_FEATURES', 'luks-encryption',
>> 'file://luks-ftpm.cfg', '', d)} \
>> +"
>> +KERNEL_CONFIG_FRAGMENTS:append:k3 = " \
>> +    ${@bb.utils.contains('MACHINE_FEATURES', 'luks-encryption',
>> '${UNPACKDIR}/luks-ftpm.cfg', '', d)} \
>> +"
>> +
>>
>>
>>
>> -=-=-=-=-=-=-=-=-=-=-=-
>> Links: You receive all messages sent to this group.
>> View/Reply Online (#19655): https://lists.yoctoproject.org/g/meta-ti/
>> message/19655
>> Mute This Topic: https://lists.yoctoproject.org/mt/118155818/3619733
>> Group Owner: [email protected]
>> Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub [[email protected]]
>> -=-=-=-=-=-=-=-=-=-=-=-
>>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.