All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jan Kiszka <jan.kiszka@siemens.com>
To: "Heinisch,
	Alexander (FT RPD CED SES-AT)" <alexander.heinisch@siemens.com>,
	cip-dev@lists.cip-project.org
Cc: Sai Sree Kartheek Adivi <s-adivi@ti.com>,
	Quirin Gylstorff <quirin.gylstorff@siemens.com>
Subject: Re: [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper
Date: Wed, 26 Aug 2026 09:54:18 +0200	[thread overview]
Message-ID: <e9769fed-d36f-484e-b659-72c3c3abdff0@siemens.com> (raw)
In-Reply-To: <12c4eff1-4a75-47ad-b5e5-6ac08dee982b@siemens.com>

On 26.08.26 09:51, Heinisch, Alexander (FT RPD CED SES-AT) wrote:
> 
> 
> Am 26.08.2026 um 07:41 schrieb Jan Kiszka:
>> From: Jan Kiszka <jan.kiszka@siemens.com>
>>
>> Will allow initramfs hooks to determine whether UEFI secure boot is
>> enabled. The user is responsible for deploying cmp and mountpoint
>> binaries into the initramfs.
>>
>> Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
>> ---
>>   .../files/cip-initramfs-functions                | 16 ++++++++++++++++
>>   1 file changed, 16 insertions(+)
>>
>> diff --git a/recipes-initramfs/initramfs-cip-functions/files/cip-
>> initramfs-functions b/recipes-initramfs/initramfs-cip-functions/files/
>> cip-initramfs-functions
>> index a4c1fed6..f14956d5 100644
>> --- a/recipes-initramfs/initramfs-cip-functions/files/cip-initramfs-
>> functions
>> +++ b/recipes-initramfs/initramfs-cip-functions/files/cip-initramfs-
>> functions
>> @@ -68,3 +68,19 @@ scan_for_partitions() {
>>       fi
>>       return 1
>>   }
>> +
>> +# check if system was securely booted via UEFI
>> +secure_boot_enabled() {
>> +    efivars=/sys/firmware/efi/efivars
>> +    if ! mountpoint -q $efivars; then
>> +        mount -t efivarfs none $efivars
>> +    fi
>> +
>> +    secure_boot="$efivars/SecureBoot-8be4df61-93ca-11d2-
>> aa0d-00e098032b8c"
>> +    setup_mode="$efivars/SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c"
>> +    if printf '\001' | cmp -s -i 4:0 $secure_boot &&
>> +       printf '\000' | cmp -s -i 4:0 $setup_mode; then
> What about audit mode?

You mean, I should check for != 1 instead? Seems that this is what the
kernel does as well...

Jan

-- 
Siemens AG, Foundational Technologies
Linux Expert Center


  reply	other threads:[~2026-08-26  7:54 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26  5:41 [isar-cip-core][PATCH 0/7] Provide measured boot via fTPM for arm64, early deploy EFI keys Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 1/7] secure-boot-efi-keys: Add recipe to create " Jan Kiszka
2026-08-26  8:31   ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  8:44     ` Jan Kiszka
2026-08-26  8:47       ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  5:41 ` [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper Jan Kiszka
2026-08-26  7:51   ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  7:54     ` Jan Kiszka [this message]
2026-08-26  9:33       ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  5:41 ` [isar-cip-core][PATCH 3/7] cip-core-initramfs: Automatically deploy secure boot keys on first boot Jan Kiszka
2026-08-26  8:17   ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  8:43     ` Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 4/7] u-boot: Add patches to enable measured boot with fTPM Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 5/7] u-boot: Refactor ftpm-stmm.cfg to enable measured boot for all Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 6/7] u-boot: Drop obsolete config workaround Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 7/7] initramfs-crypt-hook: Prevent encryption without secure boot Jan Kiszka
2026-10-01  9:41   ` Quirin Gylstorff
2026-10-01 16:16     ` Jan Kiszka
2026-08-27  7:42 ` [isar-cip-core][PATCH 8/7] doc: Update README.secureboot regarding recent deployment enhancements Jan Kiszka

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e9769fed-d36f-484e-b659-72c3c3abdff0@siemens.com \
    --to=jan.kiszka@siemens.com \
    --cc=alexander.heinisch@siemens.com \
    --cc=cip-dev@lists.cip-project.org \
    --cc=quirin.gylstorff@siemens.com \
    --cc=s-adivi@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.