From: Jan Kiszka <jan.kiszka@siemens.com>
To: "Heinisch,
Alexander (FT RPD CED SES-AT)" <alexander.heinisch@siemens.com>,
cip-dev@lists.cip-project.org
Cc: Sai Sree Kartheek Adivi <s-adivi@ti.com>,
Quirin Gylstorff <quirin.gylstorff@siemens.com>
Subject: Re: [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper
Date: Wed, 26 Aug 2026 09:54:18 +0200 [thread overview]
Message-ID: <e9769fed-d36f-484e-b659-72c3c3abdff0@siemens.com> (raw)
In-Reply-To: <12c4eff1-4a75-47ad-b5e5-6ac08dee982b@siemens.com>
On 26.08.26 09:51, Heinisch, Alexander (FT RPD CED SES-AT) wrote:
>
>
> Am 26.08.2026 um 07:41 schrieb Jan Kiszka:
>> From: Jan Kiszka <jan.kiszka@siemens.com>
>>
>> Will allow initramfs hooks to determine whether UEFI secure boot is
>> enabled. The user is responsible for deploying cmp and mountpoint
>> binaries into the initramfs.
>>
>> Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
>> ---
>> .../files/cip-initramfs-functions | 16 ++++++++++++++++
>> 1 file changed, 16 insertions(+)
>>
>> diff --git a/recipes-initramfs/initramfs-cip-functions/files/cip-
>> initramfs-functions b/recipes-initramfs/initramfs-cip-functions/files/
>> cip-initramfs-functions
>> index a4c1fed6..f14956d5 100644
>> --- a/recipes-initramfs/initramfs-cip-functions/files/cip-initramfs-
>> functions
>> +++ b/recipes-initramfs/initramfs-cip-functions/files/cip-initramfs-
>> functions
>> @@ -68,3 +68,19 @@ scan_for_partitions() {
>> fi
>> return 1
>> }
>> +
>> +# check if system was securely booted via UEFI
>> +secure_boot_enabled() {
>> + efivars=/sys/firmware/efi/efivars
>> + if ! mountpoint -q $efivars; then
>> + mount -t efivarfs none $efivars
>> + fi
>> +
>> + secure_boot="$efivars/SecureBoot-8be4df61-93ca-11d2-
>> aa0d-00e098032b8c"
>> + setup_mode="$efivars/SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c"
>> + if printf '\001' | cmp -s -i 4:0 $secure_boot &&
>> + printf '\000' | cmp -s -i 4:0 $setup_mode; then
> What about audit mode?
You mean, I should check for != 1 instead? Seems that this is what the
kernel does as well...
Jan
--
Siemens AG, Foundational Technologies
Linux Expert Center
next prev parent reply other threads:[~2026-08-26 7:54 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 5:41 [isar-cip-core][PATCH 0/7] Provide measured boot via fTPM for arm64, early deploy EFI keys Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 1/7] secure-boot-efi-keys: Add recipe to create " Jan Kiszka
2026-08-26 8:31 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 8:44 ` Jan Kiszka
2026-08-26 8:47 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 5:41 ` [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper Jan Kiszka
2026-08-26 7:51 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 7:54 ` Jan Kiszka [this message]
2026-08-26 9:33 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 5:41 ` [isar-cip-core][PATCH 3/7] cip-core-initramfs: Automatically deploy secure boot keys on first boot Jan Kiszka
2026-08-26 8:17 ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26 8:43 ` Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 4/7] u-boot: Add patches to enable measured boot with fTPM Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 5/7] u-boot: Refactor ftpm-stmm.cfg to enable measured boot for all Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 6/7] u-boot: Drop obsolete config workaround Jan Kiszka
2026-08-26 5:41 ` [isar-cip-core][PATCH 7/7] initramfs-crypt-hook: Prevent encryption without secure boot Jan Kiszka
2026-08-27 7:42 ` [isar-cip-core][PATCH 8/7] doc: Update README.secureboot regarding recent deployment enhancements Jan Kiszka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e9769fed-d36f-484e-b659-72c3c3abdff0@siemens.com \
--to=jan.kiszka@siemens.com \
--cc=alexander.heinisch@siemens.com \
--cc=cip-dev@lists.cip-project.org \
--cc=quirin.gylstorff@siemens.com \
--cc=s-adivi@ti.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox