On Wed, Aug 12, 2026 at 9:07 AM Anis Bougrine via
lists.openembedded.org
<[email protected]> wrote:
>
> Currently, signed kernel modules skip the stripping process in order
> to preserve the file contents after signing. See commit:
> 4c47e5f171fa2603355e2f9183065ce8137a18c7
>
> However, the kernel install Makefile supports stripping modules before
> signing them. This allows signed modules to be stripped while preserving
> a valid signature.
>
> Make non-signed kernel modules follow the standard Yocto stripping flow,
> while signed kernel modules use the kernel Makefile stripping flow.
>
> Fixes [YOCTO #12927]
>
> Reported-by: [email protected]
> Signed-off-by: Anis Bougrine <[email protected]>
> ---
>  meta/classes-recipe/kernel.bbclass | 16 +++++++++++++++-
>  1 file changed, 15 insertions(+), 1 deletion(-)
>
> diff --git a/meta/classes-recipe/kernel.bbclass 
> b/meta/classes-recipe/kernel.bbclass
> index a82bdf7ecb..0d8d370e9d 100644
> --- a/meta/classes-recipe/kernel.bbclass
> +++ b/meta/classes-recipe/kernel.bbclass
> @@ -453,7 +453,21 @@ kernel_do_install() {
>         #
>         unset CFLAGS CPPFLAGS CXXFLAGS LDFLAGS MACHINE
>         if (grep -q -i -e '^CONFIG_MODULES=y$' .config); then
> -               oe_runmake DEPMOD=echo 
> MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} 
> INSTALL_FW_PATH=${D}${firmwaredir} modules_install
> +               # If the module will be auto-signed, perform stripping before 
> signing.
> +               if grep -q '^CONFIG_MODULE_SIG=y$' .config && grep -q 
> '^CONFIG_MODULE_SIG_ALL=y$' .config; then
> +                       oe_runmake \
> +                               INSTALL_MOD_STRIP="--strip-debug 
> --remove-section=.comment --remove-section=.note --preserve-dates" \
> +                               DEPMOD=echo \
> +                               
> MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
> +                               
> INSTALL_FW_PATH=${D}${nonarch_base_libdir}/firmware \
> +                               modules_install
> +               else
> +                       oe_runmake \
> +                               DEPMOD=echo \
> +                               
> MODLIB=${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION} \
> +                               
> INSTALL_FW_PATH=${D}${nonarch_base_libdir}/firmware \
> +                               modules_install

Am I misreading the patch (it has been known to happen :)) ? is the
only differnece
between the two conditions the INSTALL_MOD_STRIP ? if so, why not just use a
variable and put $INSTALL_MOD_STRIP (or whatever) in the oe_runmake line ?

Better to have the variable be conditional, than duplicating the
actual call to strip
the modules.

Bruce

> +               fi
>                 rm -f 
> "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/build"
>                 rm -f 
> "${D}${nonarch_base_libdir}/modules/${KERNEL_VERSION}/source"
>                 # Remove empty module directories to prevent QA issues
> --
> 2.50.1 (Apple Git-155)
>
>
> 
>


-- 
- Thou shalt not follow the NULL pointer, for chaos and madness await
thee at its end
- "Use the force Harry" - Gandalf, Star Trek II
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243291): 
https://lists.openembedded.org/g/openembedded-core/message/243291
Mute This Topic: https://lists.openembedded.org/mt/120717114/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to