Thanks for addressing all the comments - this now looks reasonable to me.
On Thu, Mar 19, 2026 at 10:28:30PM +0530, Shiva Tripathi via
lists.yoctoproject.org wrote:
> This patch series adds LUKS full disk encryption support using firmware TPM
> (fTPM) for TI K3 platforms. The implementation provides hardware-backed
> encryption with keys sealed by TPM running in OP-TEE and stored in eMMC RPMB.
>
> Background:
> TI K3 platforms do not have integrated discrete TPM hardware. To provide
> TPM 2.0 functionality, this implementation uses firmware TPM (fTPM) - a
> Trusted Application running in OP-TEE secure world. The fTPM provides
> standard TPM 2.0 interfaces while leveraging ARM TrustZone for isolation
> and eMMC RPMB (Replay Protected Memory Block) for secure persistent storage.
>
> Key features:
> - Conditional builds: Enabled via DISTRO_FEATURES += "luks" with
> MACHINE_FEATURES as 'optee-ftpm'
> - No impact on default SDK builds
> - In-place encryption on first boot
> - TPM persistent handle for key storage (0x81080001)
> - Secure key storage in eMMC RPMB via OP-TEE
> - Security model similar to CIP Core
>
> Use case:
> This is designed for K3 platforms requiring secure boot and encrypted
> storage, such as industrial automation, automotive, and IoT gateways where
> discrete TPM chips are cost-prohibitive but security requirements demand
> hardware-backed encryption.
>
> Testing:
> - Tested on AM62x platform with kernel 6.18
> - First boot: Successful in-place LUKS encryption
> - Subsequent boots: Successful TPM unsealing and boot
>
> The series is structured as follows:
> 1. Kernel configuration for LUKS and crypto support
> 2. LUKS encryption initramfs module with fTPM key management
> 3. Dynamic layer registration and initramfs configuration
>
> ---
> Changes in v8:
> - Update 'meta-security' to 'tpm-layer' collection name in LAYERRECOMMENDS
> - Only register 'tpm-layer' in BBFILES_DYNAMIC (removed 'security' collection)
> - Rename dynamic-layers/security/ to dynamic-layers/tpm-layer/ to match
> collection
> - Add S = "${UNPACKDIR}" to initramfs-module-luks-ftpm recipe to fix build
> warning
> - Link to v7:
> https://lore.kernel.org/all/[email protected]/
>
> Changes in v7:
> - Added 'tpm-layer' collection registration to BBFILES_DYNAMIC for TPM
> packages
> - Added meta-security to LAYERRECOMMENDS
> - Link to v6:
> https://lore.kernel.org/all/[email protected]/
>
> Changes in v6:
> - Moved initramfs-module-luks-ftpm to dynamic-layers/security/
> - Added BBFILES_DYNAMIC registration for 'security' layer in layer.conf
> - Eliminates hard dependency on meta-security layer
> - Packagegroup LUKS logic moved from base .bb to dynamic-layers bbappend
> - Link to v5:
> https://lore.kernel.org/all/[email protected]/
>
> Changes in v5:
> - change from MACHINE_FEATURES 'luks-encryption' to DISTRO_FEATURES 'luks'
> - implement dual gating using existing MACHINE_FEATURES 'optee-ftpm'
> - optimize kernel config - remove unnecessary CBC, ECB, ESSIV, LRW, PCBC,
> SHA256_ARM64
> - packagegroup-ti-core-initramfs.bb changes moved to patch 3 from patch2
> - Link to v4:
> https://lore.kernel.org/all/[email protected]/
>
> Changes in v4:
> - remove encrypted-boot-common.inc and use existing ti-core-initramfs.inc
> - Link to v3:
> https://lore.kernel.org/all/[email protected]/
>
> Changes in v3:
> - remove separate sdimage.wks for encrypted boot, default works
> - update encrypted-boot-common.inc to use existing hook for adding
> TI_CORE_INITRAMFS_ENABLED dependency on luks-encryption flag
> - add logic to verify if partition has enough space for LUKS header before
> starting encryption
>
> Changes in v2:
> - changes to use existing ti-core-initramfs instead of adding separate
> - cleanup in previous init script as per comments in v1
> - /usr/bin/busybox logs updated to echo, mesg, info
> - WORKDIR changed to UNPACKDIR
> - Link to v1:
> https://lore.kernel.org/all/[email protected]/
>
> Shiva Tripathi (3):
> linux-ti-staging: Add LUKS encryption config
> initramfs-module-luks-ftpm: Add fTPM support
> conf: Enable dynamic tpm-layer support for LUKS
>
> meta-ti-bsp/conf/layer.conf | 3 +
> .../machine/include/ti-core-initramfs.inc | 2 +-
> .../initramfs-module-luks-ftpm/luksftpm | 341 ++++++++++++++++++
> .../initramfs-module-luks-ftpm_1.0.bb | 43 +++
> .../packagegroup-ti-core-initramfs.bbappend | 3 +
> .../linux/linux-ti-staging-6.18/luks-ftpm.cfg | 22 ++
> .../linux/linux-ti-staging_6.18.bb | 8 +
> 7 files changed, 421 insertions(+), 1 deletion(-)
> create mode 100644
> meta-ti-bsp/dynamic-layers/tpm-layer/recipes-ti/initramfs/initramfs-module-luks-ftpm/luksftpm
> create mode 100644
> meta-ti-bsp/dynamic-layers/tpm-layer/recipes-ti/initramfs/initramfs-module-luks-ftpm_1.0.bb
> create mode 100644
> meta-ti-bsp/dynamic-layers/tpm-layer/recipes-ti/initramfs/packagegroup-ti-core-initramfs.bbappend
> create mode 100644
> meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-ftpm.cfg
>
> --
> 2.34.1
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#19787):
https://lists.yoctoproject.org/g/meta-ti/message/19787
Mute This Topic: https://lists.yoctoproject.org/mt/118403784/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-