-
-
Notifications
You must be signed in to change notification settings - Fork 187
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Introduce optional quiet mode (move technical output from console to /tmp/debug.log) #1863
base: master
Are you sure you want to change the base?
Conversation
Current PR state videos ( as of a9c3284 ) TLDR default boot screenshot of console output:Videos:
The "technical output" redirected to /tmp/debug.log per same commit:
|
…d containing 'export CONFIG_QUIET_MODE=y' for output comparison between debug, prod and quiet mode Signed-off-by: Thierry Laurion <[email protected]>
…now all passed to LOG (quiet mode doesn't show them and logs them to /tmp/debug.log) Signed-off-by: Thierry Laurion <[email protected]>
Signed-off-by: Thierry Laurion <[email protected]>
…l information can be seen running 'cat /tmp/debug.log' from Recovery Shell Signed-off-by: Thierry Laurion <[email protected]>
…needed Signed-off-by: Thierry Laurion <[email protected]>
Signed-off-by: Thierry Laurion <[email protected]>
…onfirm_gpg_card presence call, echo for now, warn to input GPG User PIN when asked to unlock GPG card Mitigate misunderstands and show GPG User/Admin PIN counts until proper output exists under hotp_verification info to reduce global confusion Add TODO under initrd/bin/seal-hotpkey to not foget to fix output since now outputting counter of 8 for Admin PIN which makes no sense at all under hotp_verification 1.6 Nitrokey/nitrokey-hotp-verification#38 Signed-off-by: Thierry Laurion <[email protected]>
dd72313
to
ae97467
Compare
Current state demo of ae97467 state qemu needing to inject pubkey (no persistence) + tpm reset, resealing hotp, signing /boot
2024-12-03.14-11-40.mp4Default boot output on screen with TPM DUK enabled: 2024-12-03.14-21-43.mp4 |
…s when needed Signed-off-by: Thierry Laurion <[email protected]>
Signed-off-by: Thierry Laurion <[email protected]>
…rw/ro Signed-off-by: Thierry Laurion <[email protected]>
…ut of gpg on screen and safeguard PIN that would be word splitted Signed-off-by: Thierry Laurion <[email protected]>
WiP
qemu-coreboot-fbwhiptail-tpm2-hotp-prod_quiet board addition
qemu-coreboot-fbwhiptail-tpm2-hotp-prod_quiet
for building a coreboot ROM that works in the QEMU emulator with graphical mode support, HOTP support, TPM2 integration but runs in prod+quiet mode.Logging Improvements:
LOG()
function ininitrd/etc/ash_functions
to handle different logging modes based onCONFIG_QUIET_MODE
andCONFIG_DEBUG_OUTPUT
settings. This ensures that logs are directed to the appropriate output (console or debug log) based on the configuration.initrd/etc/ash_functions
,initrd/init
,initrd/sbin/insmod
) to use the updatedLOG()
function for consistent logging behavior. This includes logging TPM-related messages and other debug information. [1] [2]Supression of output
Added output:
confirm_gpg_card()
function to extract and display GPG PIN retry counters.Initialization Script Updates:
initrd/init
to inform users when quiet mode is enabled, directing them to check the debug log for technical output.initrd/init
by adding error redirection togrep
commands to avoid unnecessary output.TODOs:
Notes: OEM can add quiet mode as part of their rebranding prior of releases.
WiP demo:
Old state of output (videos and /tmp/debug.log content) at #1863 (comment)
Newer demo of current status of codebase at #1863 (comment)