Public bug reported:
[Impact]
This bug tracks the changes needed to enable kernel signing for Xilinx
on Ubuntu 24.04 LTS (Noble). It also covers building and packaging
signed FIT images for Ubuntu Core on AMD Kria boards.
The changes span linux-xilinx and linux-signed-xilinx. The main kernel
package needs to provide the unsigned arm64 image consumed by the
signing workflow. The signed package needs to assemble the Ubuntu Core
FIT image, submit it for signing and package the result.
[Fix]
In linux-xilinx, enable signed-image packaging for arm64 so that the
expected unsigned kernel package is produced.
In linux-signed-xilinx, add a custom FIT image builder that combines the
Xilinx kernel, an Ubuntu Core initramfs with the required platform
modules, and Kria device trees. Enable RSA-2048/SHA-256 signatures for
each FIT configuration, covering the kernel, initramfs and device tree.
Include the signed FIT image, snapd metadata and public signing
certificate in the Ubuntu Core image package. Add the device tree
compiler and U-Boot tools needed to build FIT images.
The FIT image includes configurations for the K26 SOM, KR260 and KV260
revisions A/B, and KD240 revision A.
[Test Plan]
Build linux-xilinx for arm64 and check that it produces the expected
unsigned kernel package. Run the linux-signed-xilinx build and signing
workflow, then check the contents of the resulting Ubuntu Core package.
Verify the FIT signatures and boot the resulting kernel snap on
supported Kria hardware. With signature enforcement enabled in the
bootloader, confirm that a modified FIT payload is rejected.
Also check that the existing EFI signing path still works.
[Where problems could occur]
The main risks are package dependency mismatches, failures in image
generation, and missing modules or device trees in the FIT image.
Incorrect FIT contents or signatures could prevent Ubuntu Core from
booting.
The custom-builder changes also affect shared image generation code, so
the existing path for images without a custom builder needs to keep
working.
** Affects: linux (Ubuntu)
Importance: Undecided
Status: New
** Affects: linux (Ubuntu Noble)
Importance: High
Assignee: Krystian Kaniewski (kkaniewski)
Status: Confirmed
** Also affects: linux (Ubuntu Noble)
Importance: Undecided
Status: New
** Changed in: linux (Ubuntu Noble)
Assignee: (unassigned) => Krystian Kaniewski (kkaniewski)
** Changed in: linux (Ubuntu Noble)
Importance: Undecided => High
** Changed in: linux (Ubuntu Noble)
Status: New => Confirmed
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167309
Title:
[Noble] Enable signing for Xilinx kernels and Ubuntu Core FIT images
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/2167309/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs