On 3/6/26 01:43, Andrew Davis wrote:
> On 3/5/26 11:21 AM, Shiva Tripathi via lists.yoctoproject.org wrote:
>> Add conditional kernel configuration fragment for LUKS encryption with
>> fTPM support. This enables dm-crypt and necessary crypto algorithms
>> when MACHINE_FEATURES contains 'luks-encryption'.
>>
>> Signed-off-by: Shiva Tripathi <[email protected]>
>> ---
>> .../linux/linux-ti-staging-6.18/luks-ftpm.cfg | 28 +++++++++++++++++++
>> .../linux/linux-ti-staging_6.18.bb | 9 ++++++
>> 2 files changed, 37 insertions(+)
>> create mode 100644 meta-ti-bsp/recipes-kernel/linux/linux-ti-
>> staging-6.18/luks-ftpm.cfg
>>
>> diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/
>> luks-ftpm.cfg b/meta-ti-bsp/recipes-kernel/linux/linux-ti-
>> staging-6.18/luks-ftpm.cfg
>> new file mode 100644
>> index 00000000..234cc087
>> --- /dev/null
>> +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-
>> ftpm.cfg
>> @@ -0,0 +1,28 @@
>> +# Device Mapper support
>> +CONFIG_MD=y
>> +CONFIG_BLK_DEV_DM=y
>> +CONFIG_DM_CRYPT=y
>> +
>> +# Crypto algorithms for LUKS
>> +CONFIG_CRYPTO_XTS=y
>> +CONFIG_CRYPTO_AES=y
>> +CONFIG_CRYPTO_AES_ARM64=y
>> +CONFIG_CRYPTO_AES_ARM64_CE=y
>> +CONFIG_CRYPTO_AES_ARM64_CE_BLK=y
>> +CONFIG_CRYPTO_SHA256=y
>> +CONFIG_CRYPTO_SHA256_ARM64=y
>
> Tell me more about this symbol, why did you pick it and what does it do.
>
> Andrew
My understanding was adding this helps optimize SHA-256 on ARM64. But on
digging deeper, realized it's a Kconfig dependency chain which gets
selected automatically when SHA2_ARM64_CE/CONFIG_CRYPTO_SHA2_ARM64_CE is
enabled, so shouldn't be explicitly enabled here.
Also re-evaluated all other symbols in patch, not all were needed. The
required ones are:
"
# Device Mapper support
CONFIG_MD=y
CONFIG_BLK_DEV_DM=y
CONFIG_DM_CRYPT=y
# Core crypto algorithms for LUKS encryption
CONFIG_CRYPTO_AES=y
CONFIG_CRYPTO_XTS=y
CONFIG_CRYPTO_SHA256=y
CONFIG_CRYPTO_SHA512=y
# ARM64 optimized crypto for better performance
CONFIG_CRYPTO_AES_ARM64=y
CONFIG_CRYPTO_AES_ARM64_CE=y
CONFIG_CRYPTO_AES_ARM64_CE_BLK=y
# Userspace crypto API for cryptsetup
CONFIG_CRYPTO_USER_API_HASH=y
CONFIG_CRYPTO_USER_API_SKCIPHER=y
"
Few above are already present in ti-linux-kernel, but think it's good to
keep an inclusive set required for LUKS in case a user deviates from
ti-linux-kernel config and start observing failures here. Will send the
updated patch.
Thanks,
Shiva
>
>> +CONFIG_CRYPTO_SHA512=y
>> +CONFIG_CRYPTO_USER_API_HASH=y
>> +CONFIG_CRYPTO_USER_API_SKCIPHER=y
>> +
>> +# Additional crypto support for LUKS2
>> +CONFIG_CRYPTO_CBC=y
>> +CONFIG_CRYPTO_ECB=y
>> +CONFIG_CRYPTO_ESSIV=y
>> +CONFIG_CRYPTO_LRW=y
>> +CONFIG_CRYPTO_PCBC=y
>> +
>> +# TPM kernel modules needed for initramfs
>> +CONFIG_TCG_TIS_CORE=m
>> +CONFIG_TCG_CRB=m
>> +
>> diff --git a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> index 8e4ccd7d..69d6217f 100644
>> --- a/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> +++ b/meta-ti-bsp/recipes-kernel/linux/linux-ti-staging_6.18.bb
>> @@ -35,3 +35,12 @@ module_conf_rpmsg_client_sample = "blacklist
>> rpmsg_client_sample"
>> module_conf_ti_k3_r5_remoteproc = "softdep ti_k3_r5_remoteproc pre:
>> virtio_rpmsg_bus"
>> module_conf_ti_k3_dsp_remoteproc = "softdep ti_k3_dsp_remoteproc
>> pre: virtio_rpmsg_bus"
>> KERNEL_MODULE_PROBECONF += "rpmsg_client_sample ti_k3_r5_remoteproc
>> ti_k3_dsp_remoteproc"
>> +
>> +# LUKS encryption with fTPM kernel configuration
>> +SRC_URI:append:k3 = " \
>> + ${@bb.utils.contains('MACHINE_FEATURES', 'luks-encryption',
>> 'file://luks-ftpm.cfg', '', d)} \
>> +"
>> +KERNEL_CONFIG_FRAGMENTS:append:k3 = " \
>> + ${@bb.utils.contains('MACHINE_FEATURES', 'luks-encryption',
>> '${UNPACKDIR}/luks-ftpm.cfg', '', d)} \
>> +"
>> +
>>
>>
>>
>>
>>
>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#19664):
https://lists.yoctoproject.org/g/meta-ti/message/19664
Mute This Topic: https://lists.yoctoproject.org/mt/118155818/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-