[PATCH 0/2] efi: cosmetic patches for the error messages when loading certificates

Lee, Chun-Yi joeyli.kernel at gmail.com
Thu Dec 12 09:38:10 UTC 2019


When loading certificates list from EFI variables, the error
message and efi status code always be emitted to dmesg. It looks
ugly:

[    2.335031] Couldn't get size: 0x800000000000000e
[    2.335032] Couldn't get UEFI MokListRT 
[    2.339985] Couldn't get size: 0x800000000000000e
[    2.339987] Couldn't get UEFI dbx list

This cosmetic patch set moved the above messages to the error
handling code path. And, it adds a function to transfer EFI status
code to string to improve the readability of debug log. The function
can also be used in other EFI log.

Lee, Chun-Yi (2):
  efi: add a function for transferring status to string
  efi: show error messages only when loading certificates is failed

 include/linux/efi.h                           | 26 +++++++++++++++++
 security/integrity/platform_certs/load_uefi.c | 41 ++++++++++++++-------------
 2 files changed, 48 insertions(+), 19 deletions(-)

-- 
2.16.4



More information about the Linux-security-module-archive mailing list