env: Kconfig: disable external env in secure os boot
authorAnshul Dalal <anshuld@ti.com>
Thu, 9 Oct 2025 12:34:34 +0000 (18:04 +0530)
committerTom Rini <trini@konsulko.com>
Thu, 16 Oct 2025 21:02:14 +0000 (15:02 -0600)
commit1e470ddd0743bbd1f229421e11e9ad2093f7fd20
tree620f71bc83efc814a40db782cfeffecf3445f5a1
parent3a71bae9af71515893483be2c022f05c8d4704aa
env: Kconfig: disable external env in secure os boot

Falcon mode uses falcon_image_file from the env during mmc fs boot, but
external env can be compromised. Therefore disable access to external
env by setting SPL_ENV_IS_NOWHERE when SPL_OS_BOOT_SECURE is set.

Signed-off-by: Anshul Dalal <anshuld@ti.com>
Reviewed-by: Tom Rini <trini@konsulko.com>
env/Kconfig