On Wed, Aug 12, 2026 at 9:07 AM Anis Bougrine via
lists.openembedded.org
<[email protected]> wrote:
>
> Currently, signed kernel modules skip the stripping process in order
> to preserve the file contents after signing. See commit:
> 4c47e5f171fa2603355e2f9183065ce8137a18c7
>
> However, the kernel install Makefile supports stripping modules before
> signing them. This allows signed modules to be stripped while preserving
> a valid signature.
>
> Make non-signed kernel modules follow the standard Yocto stripping flow,
> while signed kernel modules use the kernel Makefile stripping flow.
>
> Fixes [YOCTO #12927]
>
> Reported-by: [email protected]
> Signed-off-by: Anis Bougrine <[email protected]>
> ---
> meta/classes-recipe/kernel.bbclass | 16 +++++++++++++++-
> 1 file changed, 15 insertions(+), 1 deletion(-)
>
> diff --git a/meta/classes-recipe/kernel.bbclass
> b/meta/classes-recipe/kernel.bbclass
> index a82bdf7ecb..0d8d370e9d 100644
> --- a/meta/classes-recipe/kernel.bbclass
> +++ b/meta/classes-recipe/kernel.bbclass
> @@ -453,7 +453,21 @@ kernel_do_install() {
> #
> unset CFLAGS CPPFLAGS CXXFLAGS LDFLAGS MACHINE
> if (grep -q -i -e '^CONFIG_MODULES=y$' .config); then
> - oe_runmake DEPMOD=echo
> MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}
> INSTALL_FW_PATH=${D}${firmwaredir} modules_install
> + # If the module will be auto-signed, perform stripping before
> signing.
> + if grep -q '^CONFIG_MODULE_SIG=y$' .config && grep -q
> '^CONFIG_MODULE_SIG_ALL=y$' .config; then
> + oe_runmake \
> + INSTALL_MOD_STRIP="--strip-debug
> --remove-section=.comment --remove-section=.note --preserve-dates" \
> + DEPMOD=echo \
> +
> MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
> +
> INSTALL_FW_PATH=${D}${nonarch_base_libdir}/firmware \
> + modules_install
> + else
> + oe_runmake \
> + DEPMOD=echo \
> +
> MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
> +
> INSTALL_FW_PATH=${D}${nonarch_base_libdir}/firmware \
> + modules_install
Am I misreading the patch (it has been known to happen :)) ? is the
only differnece
between the two conditions the INSTALL_MOD_STRIP ? if so, why not just use a
variable and put $INSTALL_MOD_STRIP (or whatever) in the oe_runmake line ?
Better to have the variable be conditional, than duplicating the
actual call to strip
the modules.
Bruce
> + fi
> rm -f
> "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/build"
> rm -f
> "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/source"
> # Remove empty module directories to prevent QA issues
> --
> 2.50.1 (Apple Git-155)
>
>
>
>
--
- Thou shalt not follow the NULL pointer, for chaos and madness await
thee at its end
- "Use the force Harry" - Gandalf, Star Trek II
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243291):
https://lists.openembedded.org/g/openembedded-core/message/243291
Mute This Topic: https://lists.openembedded.org/mt/120717114/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-