From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Wed, 16 Apr 2025 19:18:31 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-lf1-f57.google.com (mail-lf1-f57.google.com [209.85.167.57]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 53GHIUij011431 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 16 Apr 2025 19:18:31 +0200 Received: by mail-lf1-f57.google.com with SMTP id 2adb3069b0e04-549b3bf4664sf3219247e87.1 for ; Wed, 16 Apr 2025 10:18:31 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1744823905; cv=pass; d=google.com; s=arc-20240605; b=lg/LRUSMqVpJhxc1+vv2BXoAMLAWu2WC5SUfQDZzfc4lBZyQemTbVBydG1u2teymPI aSNfbSOS4TC/bRDmjxzKYfNUexMaC5f622klUAaOkTUGT65wTEGh9ZN0ee/BLzCBcj9p MkL0vDz+k1bfxXhpXwjUnIlE/7Ez8RQQpgplh1SRGs2n9373eAjaPP0QryVBbPEVHxQE imndaWCM9vCzLTFLTtPV3mA6uzTtzSuwB7Gev6g2u6bdJ6R8ag1hTlQhhHDLtae6qV3H xQlTDwB/5OyAHTcXplSJyiHdfPZ9j3HRWE7J7b/H2U9ORBbFikw/91OxNmHAjk0rbb17 mMag== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:feedback-id:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=ZoeuBYM/yFYr6Qfefff0FDaH1VBBGzpVXnHF8Mxp3Gw=; fh=/0PzKWlRwpn80imTMb4JrYMfv75pRlufxgBod5KuxUg=; b=IWGgh4Hd9EVOmnOTVwh63wrHdVTT1lf9Pbg1yk59qv8Of31gYBefhI/A9G/nNilaVp Cp/aa80dOz7eKXQ8pqhxf//XnAfyfDKTebarNRLZ9TExdaFyeS5se0PTNZk6c7aIkKUP wQgD2j21Fw+v3HtJP8hXkVOanTTi+fKUVuifxL7/Lx+rG+uHCUSlFCNAXzCFmFKMfWV3 f8yYp2wm7unECwzzHCjwy4njnAsdJqp7tCJxMSIZ0NJm/V9ENxtdGXuWooVry5zc/70i +pckoIwOBbfclwsc7Lz7IsOUVvHFcjsIny4P1YyKg6S6xplc0DEz0wnnXlbZnHwGYPX2 DGvQ==; darn=ilbers.de ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=fm2 header.b=OEUz5DMS; spf=pass (google.com: domain of fm-1328731-20250416171818f71083f1e27b52dfb5-5akl8l@rts-flowmailer.siemens.com designates 185.136.64.225 as permitted sender) smtp.mailfrom=fm-1328731-20250416171818f71083f1e27b52dfb5-5Akl8l@rts-flowmailer.siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1744823905; x=1745428705; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:feedback-id :mime-version:references:in-reply-to:message-id:date:subject:cc:to :from:from:to:cc:subject:date:message-id:reply-to; bh=ZoeuBYM/yFYr6Qfefff0FDaH1VBBGzpVXnHF8Mxp3Gw=; b=ozAYX8wL42beWi6MCwbnL2k7K4yP7WmDPIaTc6F85W9kk69bv4DRl910f+CBJJNDDn 8wnyu8BH1zwRYTvqMFBed/6CV6Cpx5ki3X4gTR9elNoT6/sI9ZDY4fzhzaQijIR2mh8W nguPJ6MJgSdzD/FciRzu/hzdCrA4Td/f6UkJvVH/3bj2htfkENHyxn06vC5MeMCobSou TpWx0Y3cz1jQpK2v76qU7AetIJoE7NPj4U11YTA9lyepd7Jmxr1477UtrOQv+97uUAdf uWVXxm2Cw8JIoxWrV8pK2lS8Yg3t3WAVywIv1GLa6VAomv7LXKIDyAAqt3Z66dc3olLp JwZw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1744823905; x=1745428705; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:feedback-id :mime-version:references:in-reply-to:message-id:date:subject:cc:to :from:x-beenthere:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ZoeuBYM/yFYr6Qfefff0FDaH1VBBGzpVXnHF8Mxp3Gw=; b=aExr5XsWe5vbc6wFLaLdRI4/fXUS1IXA486A2qG6M3UVNxGtjETIIT+aRPfO9cRQHo grNWhsz4o691cY0ukrEtw3YOROSBUu7Hi04ljO9h/ftQu54aVzMRKf7Vu3lE7KhWJF4F odKjlmLTOmqCjwa+OmMZzM9vTFfaymWeKvGQd8Vp3piDFCSMKWBoeuB+3cdU7mbEJSss QYZJlx3OZZXxlD1dy4UYieaDngbHF5wOvcMWm7J+Qbjbwt5BIK/vc/ei9IeX9hV16/TL /bzr4JGw3wvsVqIzOtLvoTvkZ8TjGt9G9jJ5Fb+wjHmeFQiI2grW3h4AIEwfnxRvmW5Q GhPA== X-Forwarded-Encrypted: i=2; AJvYcCU5LO4qz2Ab5a9XKCRmLmJEkmIGfkXFKca3UlOtGFZk8XCt9fzTM0IvF+h7+oFZs20Dk0uS@ilbers.de X-Gm-Message-State: AOJu0Yw4bZuyPC4Vn0ASHEraApTovFZRRQPTLGV8bucpWIjCbu32191l LT0jHyGbtxGIKAPbZSdauw58W2Ns7UcjvcuKHn8n1n1way8KEnBE X-Google-Smtp-Source: AGHT+IGZjGpDko9qERBC27kMyZRgr79ZqjpJun+Zqnivy3DxZyYwLrFCGFe4ACvhQi6QdEkLZn2M+A== X-Received: by 2002:a05:6512:3f03:b0:54c:a49:d3ee with SMTP id 2adb3069b0e04-54d64a7a4e3mr1040558e87.3.1744823903860; Wed, 16 Apr 2025 10:18:23 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h=ARLLPAJ9JUfbqZokfTqoxbNoYzgH/XJm07uYqIl7mPX544drUA== Received: by 2002:a19:ca0b:0:b0:549:9b17:deaf with SMTP id 2adb3069b0e04-54d68bc611dls19240e87.0.-pod-prod-02-eu; Wed, 16 Apr 2025 10:18:19 -0700 (PDT) X-Received: by 2002:a05:6512:158f:b0:545:576:cbca with SMTP id 2adb3069b0e04-54d64a7abc3mr980565e87.8.1744823899319; Wed, 16 Apr 2025 10:18:19 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1744823899; cv=none; d=google.com; s=arc-20240605; b=JfcYZc0YN9E+tUqkokVD95utk/ZBIcxpK+ayicDHdOQpF4m2TkY2dGdqG/8OaULN5R AtPTkUwjLegveQpoJ15XwWDfu24TTjKKIjObsb1VHRY2hFRhylOJvNDuWS5TVX61kX1J Yv8VY6vXwh/pFU5adVbd+RL2VZCOR8AaGsbnd0lZriopFK8rk7LnL8xSuIXZGYtK1leM SKSVdNTPTWgvAtnF7lRqtCM87a5beUiSmmuR+Slc890JwDEIUQLQN9YQZ3qCmqUfFQlV Iuhz9ayVEa0JvXymR9tkclbFotQeFmOGSc9cOZ9iwrekl7NjooTiXSr4XwsIaj8vYngu TB9Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=feedback-id:content-transfer-encoding:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:dkim-signature; bh=M/iSOQM6rtGVleG0mHybbWpk1BUAClnsRc1LwnKKYy4=; fh=7H56SyJ75bwGZUIqRCOBd3K5XpBD2YtSSm9HZ9E1Jq8=; b=UvOtNlWEV3AhjwVNVfXHckDK8CPR66SmoJK7XtF6gwjdIyYxS009YWewZcMQS0Zcqn 6jj1aGUMLxNyJTvwqwtIgiZuuZ/Ah0Inwly2PhEGnbaAaTD1R8XO7TuJouHGGQd0Hbfu 9RzMxuSVTTrEBif12qejOTbzIhKAfDQnQI/SeKAHXGfTSdASaGO1bY3vwXTHlUpXZAtA DCm0SOltO/oj1Sf4tJAzs7IHzZBr1Wbw+KjKn/ut6PTOdY2CnLof23R0Pw+COzmqOFI8 tsTNUizx2XJLGtVWWQWe5TkziDt+VxgVZ4l5a5dLrRjpUgeKvHFjCzK6Vyu7o8J7ogTf btow==; dara=google.com ARC-Authentication-Results: i=1; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=fm2 header.b=OEUz5DMS; spf=pass (google.com: domain of fm-1328731-20250416171818f71083f1e27b52dfb5-5akl8l@rts-flowmailer.siemens.com designates 185.136.64.225 as permitted sender) smtp.mailfrom=fm-1328731-20250416171818f71083f1e27b52dfb5-5Akl8l@rts-flowmailer.siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from mta-64-225.siemens.flowmailer.net (mta-64-225.siemens.flowmailer.net. [185.136.64.225]) by gmr-mx.google.com with ESMTPS id 38308e7fff4ca-30f464c97e3si1117871fa.1.2025.04.16.10.18.19 for (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 16 Apr 2025 10:18:19 -0700 (PDT) Received-SPF: pass (google.com: domain of fm-1328731-20250416171818f71083f1e27b52dfb5-5akl8l@rts-flowmailer.siemens.com designates 185.136.64.225 as permitted sender) client-ip=185.136.64.225; Received: by mta-64-225.siemens.flowmailer.net with ESMTPSA id 20250416171818f71083f1e27b52dfb5 for ; Wed, 16 Apr 2025 19:18:18 +0200 From: "'Gokhan Cetin' via isar-users" To: isar-users@googlegroups.com Cc: gokhan.cetin@siemens.com, jan.kiszka@siemens.com Subject: [PATCH v2 4/5] meta/recipes-kernel/linux-module: add option to set default signing profile and dependencies Date: Wed, 16 Apr 2025 19:17:08 +0200 Message-Id: <20250416171709.742191-5-gokhan.cetin@siemens.com> In-Reply-To: <20250416171709.742191-1-gokhan.cetin@siemens.com> References: <20250416171709.742191-1-gokhan.cetin@siemens.com> MIME-Version: 1.0 X-Flowmailer-Platform: Siemens Feedback-ID: 519:519-1328731:519-21489:flowmailer X-Original-Sender: gokhan.cetin@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=fm2 header.b=OEUz5DMS; spf=pass (google.com: domain of fm-1328731-20250416171818f71083f1e27b52dfb5-5akl8l@rts-flowmailer.siemens.com designates 185.136.64.225 as permitted sender) smtp.mailfrom=fm-1328731-20250416171818f71083f1e27b52dfb5-5Akl8l@rts-flowmailer.siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: Gokhan Cetin Reply-To: Gokhan Cetin Content-Type: text/plain; charset="UTF-8" Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2,RCVD_IN_RP_CERTIFIED, RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: BBRwNc5TC/6G Introduces single control variable (`KERNEL_MODULE_SIGNATURES`) to set all predefined build profile and dependencies need to be configured for kernel module signing. By using this option, downstreams will be able to enable build-wide signing of kernel modules which include module.inc without appending any additional configuration into their module recipes. Signed-off-by: Gokhan Cetin --- meta/recipes-kernel/linux-module/module.inc | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/meta/recipes-kernel/linux-module/module.inc b/meta/recipes-kernel/linux-module/module.inc index 45d88d48..8fe5eed4 100644 --- a/meta/recipes-kernel/linux-module/module.inc +++ b/meta/recipes-kernel/linux-module/module.inc @@ -28,6 +28,13 @@ SIGNATURE_CERTFILE ??= "/usr/share/secure-boot-secrets/secure-boot.pem" SIGNATURE_HASHFN ??= "sha256" SIGNATURE_SIGNWITH ??= "/usr/bin/sign-module.sh" +KERNEL_MODULE_SIGNATURES ??= "" + +# Define signing profile and dependencies if KERNEL_MODULE_SIGNATURES is set to "1" +DEB_BUILD_PROFILES += "${@'pkg.signwith' if bb.utils.to_boolean(d.getVar('KERNEL_MODULE_SIGNATURES')) else ''}" +DEPENDS += "${@'module-signer secure-boot-secrets' if bb.utils.to_boolean(d.getVar('KERNEL_MODULE_SIGNATURES')) else ''}" +DEBIAN_BUILD_DEPENDS .= "${@', module-signer, secure-boot-secrets' if bb.utils.to_boolean(d.getVar('KERNEL_MODULE_SIGNATURES')) else ''}" + SRC_URI += "file://debian/" AUTOLOAD ?= "" -- 2.39.2 -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/20250416171709.742191-5-gokhan.cetin%40siemens.com.