[PATCH 0/2] Add bulk signing support for PKCS#11 keys
From: Massimiliano Marretta
Date: Fri Oct 09 2026 - 06:22:12 EST
Add support for signing kernel modules in bulk when the signing
key is stored on a PKCS#11 token.
Currently scripts/sign-file signs one module per invocation. When
the key lives on a PKCS#11 token (e.g. a Nitrokey HSM or a
SmartCard-HSM), every invocation pays a fixed initialization cost
of 25-36 seconds, which dominates the actual signing time. For a
typical build with hundreds of modules this is impractical.
This series adds a '-b' (bulk) option to scripts/sign-file and
teaches the kbuild system to use it automatically when the signing
key is provided as a PKCS#11 URI. The classic one-module-at-a-time
behavior is preserved when the key is a PEM file.
Patch 1/2 also extracts the body of the signing logic into a
dedicated sign_single_file() helper. This is done to keep the
new bulk loop in main() readable and to avoid duplicating the
argument parsing logic. The extracted function contains no
functional changes with respect to the current upstream code.
Measured on a build with 50 modules and the key stored on a
SmartCard-HSM:
- before: ~24 minutes
- after: ~3 min 17 s
Note on checkpatch: the series produces a few "trailing statements
should be on next line" errors on sign-file.c. These come from the
switch statement in main() that is moved within the file by patch
1/2. The affected lines use the exact same style as the current
upstream sources (case 'x': stmt; break;) and are not introduced
by this series.
Massimiliano Marretta (2):
scripts/sign-file: add bulk module signing support
kbuild: sign modules in bulk when the signing key is on PKCS#11
scripts/Makefile.modinst | 43 ++++++++++-
scripts/sign-file.c | 159 ++++++++++++++++++++++++---------------
2 files changed, 142 insertions(+), 60 deletions(-)
--
2.43.0