* [PATCH] arm: mach-k3: security: Lower verbosity of cert message for GP
@ 2024-04-10 18:38 Andrew Davis
2024-04-10 18:57 ` Jon Humphreys
2024-04-18 3:40 ` Tom Rini
0 siblings, 2 replies; 3+ messages in thread
From: Andrew Davis @ 2024-04-10 18:38 UTC (permalink / raw)
To: Neha Malcom Francis, Vignesh Raghavendra, Nishanth Menon,
Simon Glass, Tom Rini
Cc: Jon Humphreys, u-boot, Andrew Davis
When we find a certificate on an image to be booted on a GP device we
print out a message explaining that the certificate is being skipped.
This message is rather long and is printed for every image. Shorten
the message and make the long version into a debug message.
Signed-off-by: Andrew Davis <afd@ti.com>
---
arch/arm/mach-k3/security.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/arch/arm/mach-k3/security.c b/arch/arm/mach-k3/security.c
index 22697a263a8..7c46914d9dd 100644
--- a/arch/arm/mach-k3/security.c
+++ b/arch/arm/mach-k3/security.c
@@ -50,7 +50,7 @@ void ti_secure_image_check_binary(void **p_image, size_t *p_size)
if (get_device_type() == K3_DEVICE_TYPE_GP) {
if (ti_secure_cert_detected(*p_image)) {
- printf("Warning: Detected image signing certificate on GP device. "
+ debug("Warning: Detected image signing certificate on GP device. "
"Skipping certificate to prevent boot failure. "
"This will fail if the image was also encrypted\n");
@@ -60,6 +60,7 @@ void ti_secure_image_check_binary(void **p_image, size_t *p_size)
return;
}
+ printf("Skipping authentication on GP device\n");
*p_image += cert_length;
*p_size -= cert_length;
}
--
2.39.2
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH] arm: mach-k3: security: Lower verbosity of cert message for GP
2024-04-10 18:38 [PATCH] arm: mach-k3: security: Lower verbosity of cert message for GP Andrew Davis
@ 2024-04-10 18:57 ` Jon Humphreys
2024-04-18 3:40 ` Tom Rini
1 sibling, 0 replies; 3+ messages in thread
From: Jon Humphreys @ 2024-04-10 18:57 UTC (permalink / raw)
To: Andrew Davis, Neha Malcom Francis, Vignesh Raghavendra,
Nishanth Menon, Simon Glass, Tom Rini
Cc: u-boot, Andrew Davis
Andrew Davis <afd@ti.com> writes:
> When we find a certificate on an image to be booted on a GP device we
> print out a message explaining that the certificate is being skipped.
> This message is rather long and is printed for every image. Shorten
> the message and make the long version into a debug message.
>
> Signed-off-by: Andrew Davis <afd@ti.com>
> ---
> arch/arm/mach-k3/security.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/arch/arm/mach-k3/security.c b/arch/arm/mach-k3/security.c
> index 22697a263a8..7c46914d9dd 100644
> --- a/arch/arm/mach-k3/security.c
> +++ b/arch/arm/mach-k3/security.c
> @@ -50,7 +50,7 @@ void ti_secure_image_check_binary(void **p_image, size_t *p_size)
>
> if (get_device_type() == K3_DEVICE_TYPE_GP) {
> if (ti_secure_cert_detected(*p_image)) {
> - printf("Warning: Detected image signing certificate on GP device. "
> + debug("Warning: Detected image signing certificate on GP device. "
> "Skipping certificate to prevent boot failure. "
> "This will fail if the image was also encrypted\n");
>
> @@ -60,6 +60,7 @@ void ti_secure_image_check_binary(void **p_image, size_t *p_size)
> return;
> }
>
> + printf("Skipping authentication on GP device\n");
> *p_image += cert_length;
> *p_size -= cert_length;
> }
> --
> 2.39.2
Would be nice if it only emitted the message once!
Tested-by: Jonathan Humphreys <j-humphreys@ti.com>
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH] arm: mach-k3: security: Lower verbosity of cert message for GP
2024-04-10 18:38 [PATCH] arm: mach-k3: security: Lower verbosity of cert message for GP Andrew Davis
2024-04-10 18:57 ` Jon Humphreys
@ 2024-04-18 3:40 ` Tom Rini
1 sibling, 0 replies; 3+ messages in thread
From: Tom Rini @ 2024-04-18 3:40 UTC (permalink / raw)
To: Neha Malcom Francis, Vignesh Raghavendra, Nishanth Menon,
Simon Glass, Andrew Davis
Cc: Jon Humphreys, u-boot
On Wed, 10 Apr 2024 13:38:34 -0500, Andrew Davis wrote:
> When we find a certificate on an image to be booted on a GP device we
> print out a message explaining that the certificate is being skipped.
> This message is rather long and is printed for every image. Shorten
> the message and make the long version into a debug message.
>
>
Applied to u-boot/master, thanks!
--
Tom
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2024-04-18 3:41 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-04-10 18:38 [PATCH] arm: mach-k3: security: Lower verbosity of cert message for GP Andrew Davis
2024-04-10 18:57 ` Jon Humphreys
2024-04-18 3:40 ` Tom Rini
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox