Introduce optional quiet mode (move technical output from console to /tmp/debug.log)#1863
Closed
tlaurion wants to merge 11 commits intolinuxboot:masterfrom
Closed
Introduce optional quiet mode (move technical output from console to /tmp/debug.log)#1863tlaurion wants to merge 11 commits intolinuxboot:masterfrom
tlaurion wants to merge 11 commits intolinuxboot:masterfrom
Conversation
Collaborator
Author
|
Current PR state videos ( as of a9c3284 ) TLDR default boot screenshot of console output:Videos:
The "technical output" redirected to /tmp/debug.log per same commit: |
…d containing 'export CONFIG_QUIET_MODE=y' for output comparison between debug, prod and quiet mode Signed-off-by: Thierry Laurion <[email protected]>
…now all passed to LOG (quiet mode doesn't show them and logs them to /tmp/debug.log) Signed-off-by: Thierry Laurion <[email protected]>
Signed-off-by: Thierry Laurion <[email protected]>
…l information can be seen running 'cat /tmp/debug.log' from Recovery Shell Signed-off-by: Thierry Laurion <[email protected]>
…needed Signed-off-by: Thierry Laurion <[email protected]>
Signed-off-by: Thierry Laurion <[email protected]>
…onfirm_gpg_card presence call, echo for now, warn to input GPG User PIN when asked to unlock GPG card Mitigate misunderstands and show GPG User/Admin PIN counts until proper output exists under hotp_verification info to reduce global confusion Add TODO under initrd/bin/seal-hotpkey to not foget to fix output since now outputting counter of 8 for Admin PIN which makes no sense at all under hotp_verification 1.6 Nitrokey/nitrokey-hotp-verification#38 Signed-off-by: Thierry Laurion <[email protected]>
dd72313 to
ae97467
Compare
Collaborator
Author
|
Current state demo of ae97467 state qemu needing to inject pubkey (no persistence) + tpm reset, resealing hotp, signing /boot
2024-12-03.14-11-40.mp4Default boot output on screen with TPM DUK enabled: 2024-12-03.14-21-43.mp4 |
…s when needed Signed-off-by: Thierry Laurion <[email protected]>
Signed-off-by: Thierry Laurion <[email protected]>
…rw/ro Signed-off-by: Thierry Laurion <[email protected]>
…ut of gpg on screen and safeguard PIN that would be word splitted Signed-off-by: Thierry Laurion <[email protected]>
Collaborator
Author
|
Replaced and integrated for testing under #1884 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

WiP
qemu-coreboot-fbwhiptail-tpm2-hotp-prod_quiet board addition
qemu-coreboot-fbwhiptail-tpm2-hotp-prod_quietfor building a coreboot ROM that works in the QEMU emulator with graphical mode support, HOTP support, TPM2 integration but runs in prod+quiet mode.Logging Improvements:
LOG()function ininitrd/etc/ash_functionsto handle different logging modes based onCONFIG_QUIET_MODEandCONFIG_DEBUG_OUTPUTsettings. This ensures that logs are directed to the appropriate output (console or debug log) based on the configuration.initrd/etc/ash_functions,initrd/init,initrd/sbin/insmod) to use the updatedLOG()function for consistent logging behavior. This includes logging TPM-related messages and other debug information. [1] [2]Supression of output
Added output:
confirm_gpg_card()function to extract and display GPG PIN retry counters.Initialization Script Updates:
initrd/initto inform users when quiet mode is enabled, directing them to check the debug log for technical output.initrd/initby adding error redirection togrepcommands to avoid unnecessary output.TODOs:
Notes: OEM can add quiet mode as part of their rebranding prior of releases.
WiP demo:
Old state of output (videos and /tmp/debug.log content) at #1863 (comment)
Newer demo of current status of codebase at #1863 (comment)