spl: prevent loading args file in secure falcon mode
authorAnshul Dalal <anshuld@ti.com>
Thu, 9 Oct 2025 11:58:44 +0000 (17:28 +0530)
committerTom Rini <trini@konsulko.com>
Mon, 20 Oct 2025 17:54:33 +0000 (11:54 -0600)
commit82e04e768fc21c1ac43df5d5a68ec8aaf008c0a8
treef37cddc78a31292dc836f831947b8c7eaf147291
parentb1a3ed068869d7289747dddd6dc13ecb9f9840a6
spl: prevent loading args file in secure falcon mode

The expected payload for the SPL in secure falcon mode is a fitImage
that contains the kernel image and the DT. This removes the need to load
an additional args file, which exposes an additional attack vector since
it can not be verified.

Therefore this patch disables loading of the arg file when
SPL_OS_BOOT_SECURE is set.

Reviewed-by: Tom Rini <trini@konsulko.com>
Signed-off-by: Anshul Dalal <anshuld@ti.com>
common/spl/Kconfig