arm/uefi-secureboot: fix race with secureboot keys

gen-sbkeys creates and installs the secure boot signing keys, certificates,
and database used by U-Boot and systemd-boot.  Both recipes require these
files during do_compile, but there was no dependency ensuring that
gen-sbkeys:do_install completed first.

Add an explicit do_compile dependency on gen-sbkeys:do_install for both
U-Boot and systemd-boot to prevent the race, which was causing intermittent
CI failures.

The uki.bbclass also requires the secure boot keys and certificates, but
depends on systemd-boot:do_deploy, which ensures the keys are available before
they are needed.

Issues being tracked in meta-secure-core
https://github.com/Wind-River/meta-secure-core/issues/145
https://github.com/Wind-River/meta-secure-core/issues/146

Signed-off-by: Jon Mason <jon.mason@arm.com>
This commit is contained in:
Jon Mason
2026-08-25 14:00:04 -04:00
parent c6f7492f4a
commit b0ff16aba4
2 changed files with 7 additions and 2 deletions
@@ -4,12 +4,11 @@ SRC_URI += "file://uefi-secureboot.cfg \
file://0001-efi_loader-fix-building-with-CONFIG_EFI_VARIABLES_PR.patch \
"
inherit sbsign
require ${@bb.utils.contains('MACHINE_FEATURES', 'uefi-http-boot', 'u-boot-uefi-http-boot.inc', '', d)}
require ${@bb.utils.contains('MACHINE_FEATURES', 'uefi-capsule-update', 'u-boot-capsule-update.inc', '', d)}
DEPENDS += 'python3-pyopenssl-native'
DEPENDS += 'gen-sbkeys'
do_compile:prepend() {
export CRYPTOGRAPHY_OPENSSL_NO_LEGACY=1
@@ -20,3 +19,6 @@ do_compile:prepend() {
"${S}"/tools/efivar.py set -i "${S}"/ubootefi.var -n dbx -d "${SBSIGN_KEYS_DIR}"/dbx.esl -t file
"${S}"/tools/efivar.py print -i "${S}"/ubootefi.var
}
# Make sure the contents of SBSIGN_KEYS_DIR are actually there
do_compile[depends] += "gen-sbkeys:do_install"
@@ -5,3 +5,6 @@ SBSIGN_TARGET_BINARY = "${B}/src/boot/systemd-boot${EFI_ARCH}.efi"
do_compile:append() {
do_sbsign
}
# Make sure the keys are actually there before trying to sign
do_compile[depends] += "gen-sbkeys:do_install"