forked from torvalds/linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
powerpc: Detect the secure boot mode of the system
This patch defines a function to detect the secure boot state of a PowerNV system. The PPC_SECURE_BOOT config represents the base enablement of secure boot for powerpc. Signed-off-by: Nayna Jain <[email protected]> Signed-off-by: Eric Richter <[email protected]> [mpe: Fold in change from Nayna to add "ibm,secureboot" to ids] Signed-off-by: Michael Ellerman <[email protected]> Link: https://lore.kernel.org/r/[email protected]
- Loading branch information
Showing
4 changed files
with
70 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
/* SPDX-License-Identifier: GPL-2.0 */ | ||
/* | ||
* Secure boot definitions | ||
* | ||
* Copyright (C) 2019 IBM Corporation | ||
* Author: Nayna Jain | ||
*/ | ||
#ifndef _ASM_POWER_SECURE_BOOT_H | ||
#define _ASM_POWER_SECURE_BOOT_H | ||
|
||
#ifdef CONFIG_PPC_SECURE_BOOT | ||
|
||
bool is_ppc_secureboot_enabled(void); | ||
|
||
#else | ||
|
||
static inline bool is_ppc_secureboot_enabled(void) | ||
{ | ||
return false; | ||
} | ||
|
||
#endif | ||
#endif |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,35 @@ | ||
// SPDX-License-Identifier: GPL-2.0 | ||
/* | ||
* Copyright (C) 2019 IBM Corporation | ||
* Author: Nayna Jain | ||
*/ | ||
#include <linux/types.h> | ||
#include <linux/of.h> | ||
#include <asm/secure_boot.h> | ||
|
||
static struct device_node *get_ppc_fw_sb_node(void) | ||
{ | ||
static const struct of_device_id ids[] = { | ||
{ .compatible = "ibm,secureboot", }, | ||
{ .compatible = "ibm,secureboot-v1", }, | ||
{ .compatible = "ibm,secureboot-v2", }, | ||
{}, | ||
}; | ||
|
||
return of_find_matching_node(NULL, ids); | ||
} | ||
|
||
bool is_ppc_secureboot_enabled(void) | ||
{ | ||
struct device_node *node; | ||
bool enabled = false; | ||
|
||
node = get_ppc_fw_sb_node(); | ||
enabled = of_property_read_bool(node, "os-secureboot-enforcing"); | ||
|
||
of_node_put(node); | ||
|
||
pr_info("Secure boot mode %s\n", enabled ? "enabled" : "disabled"); | ||
|
||
return enabled; | ||
} |