CIP-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Jan Kiszka <jan.kiszka@siemens.com>
To: "Heinisch,
	Alexander (FT RPD CED SES-AT)" <alexander.heinisch@siemens.com>,
	cip-dev@lists.cip-project.org
Cc: Sai Sree Kartheek Adivi <s-adivi@ti.com>,
	Quirin Gylstorff <quirin.gylstorff@siemens.com>
Subject: Re: [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper
Date: Wed, 26 Aug 2026 09:54:18 +0200	[thread overview]
Message-ID: <e9769fed-d36f-484e-b659-72c3c3abdff0@siemens.com> (raw)
In-Reply-To: <12c4eff1-4a75-47ad-b5e5-6ac08dee982b@siemens.com>

On 26.08.26 09:51, Heinisch, Alexander (FT RPD CED SES-AT) wrote:
> 
> 
> Am 26.08.2026 um 07:41 schrieb Jan Kiszka:
>> From: Jan Kiszka <jan.kiszka@siemens.com>
>>
>> Will allow initramfs hooks to determine whether UEFI secure boot is
>> enabled. The user is responsible for deploying cmp and mountpoint
>> binaries into the initramfs.
>>
>> Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
>> ---
>>   .../files/cip-initramfs-functions                | 16 ++++++++++++++++
>>   1 file changed, 16 insertions(+)
>>
>> diff --git a/recipes-initramfs/initramfs-cip-functions/files/cip-
>> initramfs-functions b/recipes-initramfs/initramfs-cip-functions/files/
>> cip-initramfs-functions
>> index a4c1fed6..f14956d5 100644
>> --- a/recipes-initramfs/initramfs-cip-functions/files/cip-initramfs-
>> functions
>> +++ b/recipes-initramfs/initramfs-cip-functions/files/cip-initramfs-
>> functions
>> @@ -68,3 +68,19 @@ scan_for_partitions() {
>>       fi
>>       return 1
>>   }
>> +
>> +# check if system was securely booted via UEFI
>> +secure_boot_enabled() {
>> +    efivars=/sys/firmware/efi/efivars
>> +    if ! mountpoint -q $efivars; then
>> +        mount -t efivarfs none $efivars
>> +    fi
>> +
>> +    secure_boot="$efivars/SecureBoot-8be4df61-93ca-11d2-
>> aa0d-00e098032b8c"
>> +    setup_mode="$efivars/SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c"
>> +    if printf '\001' | cmp -s -i 4:0 $secure_boot &&
>> +       printf '\000' | cmp -s -i 4:0 $setup_mode; then
> What about audit mode?

You mean, I should check for != 1 instead? Seems that this is what the
kernel does as well...

Jan

-- 
Siemens AG, Foundational Technologies
Linux Expert Center


  reply	other threads:[~2026-08-26  7:54 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26  5:41 [isar-cip-core][PATCH 0/7] Provide measured boot via fTPM for arm64, early deploy EFI keys Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 1/7] secure-boot-efi-keys: Add recipe to create " Jan Kiszka
2026-08-26  8:31   ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  8:44     ` Jan Kiszka
2026-08-26  8:47       ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  5:41 ` [isar-cip-core][PATCH 2/7] cip-initramfs-functions: Add secure_boot_enabled helper Jan Kiszka
2026-08-26  7:51   ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  7:54     ` Jan Kiszka [this message]
2026-08-26  9:33       ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  5:41 ` [isar-cip-core][PATCH 3/7] cip-core-initramfs: Automatically deploy secure boot keys on first boot Jan Kiszka
2026-08-26  8:17   ` Heinisch, Alexander (FT RPD CED SES-AT)
2026-08-26  8:43     ` Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 4/7] u-boot: Add patches to enable measured boot with fTPM Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 5/7] u-boot: Refactor ftpm-stmm.cfg to enable measured boot for all Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 6/7] u-boot: Drop obsolete config workaround Jan Kiszka
2026-08-26  5:41 ` [isar-cip-core][PATCH 7/7] initramfs-crypt-hook: Prevent encryption without secure boot Jan Kiszka
2026-08-27  7:42 ` [isar-cip-core][PATCH 8/7] doc: Update README.secureboot regarding recent deployment enhancements Jan Kiszka

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e9769fed-d36f-484e-b659-72c3c3abdff0@siemens.com \
    --to=jan.kiszka@siemens.com \
    --cc=alexander.heinisch@siemens.com \
    --cc=cip-dev@lists.cip-project.org \
    --cc=quirin.gylstorff@siemens.com \
    --cc=s-adivi@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox