blob: 95be7abc5751ad091f173c701419a54cb8d72a8d [file] [log] [blame]
Troy Lee26bcba22020-12-02 10:34:53 +08001MACHINE ??= "evb-ast2600"
2DISTRO ?= "openbmc-phosphor"
Andrew Jeffery605c37c2021-09-15 09:12:36 +09303PACKAGE_CLASSES ?= "package_ipk"
Patrick Williamsed2ee5d2021-08-06 09:03:46 -05004SANITY_TESTED_DISTROS:append ?= " *"
5EXTRA_IMAGE_FEATURES ?= "debug-tweaks"
6USER_CLASSES ?= "buildstats"
Troy Lee26bcba22020-12-02 10:34:53 +08007PATCHRESOLVE = "noop"
Patrick Williamsed2ee5d2021-08-06 09:03:46 -05008BB_DISKMON_DIRS ??= "\
Troy Lee26bcba22020-12-02 10:34:53 +08009 STOPTASKS,${TMPDIR},1G,100K \
10 STOPTASKS,${DL_DIR},1G,100K \
11 STOPTASKS,${SSTATE_DIR},1G,100K \
12 STOPTASKS,/tmp,100M,100K \
George Liub6bf8da2022-04-12 14:01:21 +080013 HALT,${TMPDIR},100M,1K \
14 HALT,${DL_DIR},100M,1K \
15 HALT,${SSTATE_DIR},100M,1K \
16 HALT,/tmp,10M,1K"
Patrick Williamseebb12c2021-08-10 05:48:58 -050017CONF_VERSION = "2"
Troy Leef51034c2021-01-13 02:39:35 +000018
Stefan Bergerddb02fe2023-03-28 10:16:54 -040019DISTRO_FEATURES:append = " integrity"
20
21# Enable IMA kernel support
22# DISTRO_FEATURES:append = " ima"
23
24# Once ima-evm-rootfs is activated we need the keys below for signing
25# executables and libraries
26# IMAGE_CLASSES += "ima-evm-rootfs"
27
28# Modify the following variables to point to your own directory and keys
29# The CA must be able to verify the x509 cert:
30# openssl verify -CAfile ${IMA_EVM_ROOT_CA} ${IMA_EVM_X509}
31#
32# IMA_EVM_KEY_DIR = "${INTEGRITY_BASE}/data/debug-keys"
33# IMA_EVM_PRIVKEY = "${IMA_EVM_KEY_DIR}/privkey_ima.pem"
34# IMA_EVM_X509 = "${IMA_EVM_KEY_DIR}/x509_ima.der"
35# IMA_EVM_ROOT_CA = "${IMA_EVM_KEY_DIR}/ima-local-ca.pem"
36
37# The following policy enforces IMA & EVM signatures
38# IMA_EVM_POLICY = "${INTEGRITY_BASE}/recipes-security/ima_policy_appraise_all/files/ima_policy_appraise_all"
39
Stefan Berger08d9ce32023-04-26 20:19:36 -040040# Useful debugging tools
41# IMAGE_INSTALL:append = " attr-tools"
42
Troy Leef51034c2021-01-13 02:39:35 +000043require conf/machine/include/obmc-bsp-common.inc