From fc9433ae81324e898646a1d820f84da2f901c292 Mon Sep 17 00:00:00 2001 From: Richard Woh Date: Wed, 2 Sep 2026 19:59:45 -0700 Subject: [PATCH 1/5] fix: use non-error log levels for success and info messages Add SEC_LOG_INFO and SEC_LOG_WARNING macros and use them for messages that are not errors, so successful SoC TA provisioning no longer shows up as ERROR in the logs. Fixes #85 --- include/sec_security.h | 10 ++++++++++ src/sec_adapter_soc_provisioning.c | 26 +++++++++++++------------- src/sec_adapter_utils.c | 4 ++-- 3 files changed, 25 insertions(+), 15 deletions(-) diff --git a/include/sec_security.h b/include/sec_security.h index b260d7a..17ffbc7 100644 --- a/include/sec_security.h +++ b/include/sec_security.h @@ -122,6 +122,16 @@ extern "C" { SEC_LOG("ERROR: " txt, ##__VA_ARGS__); \ } while (0) +#define SEC_LOG_WARNING(txt, ...) \ + do { \ + SEC_LOG("WARNING: " txt, ##__VA_ARGS__); \ + } while (0) + +#define SEC_LOG_INFO(txt, ...) \ + do { \ + SEC_LOG("INFO: " txt, ##__VA_ARGS__); \ + } while (0) + #define SEC_TRACE(enabled, txt, ...) \ do { \ if (enabled) { \ diff --git a/src/sec_adapter_soc_provisioning.c b/src/sec_adapter_soc_provisioning.c index cef664e..ad123c8 100644 --- a/src/sec_adapter_soc_provisioning.c +++ b/src/sec_adapter_soc_provisioning.c @@ -553,42 +553,42 @@ Sec_Result SecSocProv_Ta_Provision(Sec_ProcessorHandle* processorHandle, sa_key_ switch (key_type) { case WIDEVINE_OEM_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_WIDEVINE - SEC_LOG_ERROR("Handling Widevine provisioning"); + SEC_LOG_INFO("Handling Widevine provisioning"); status = provisioning_ta(processorHandle, WIDEVINE_OBJ, WIDEVINE_OEM_SOC_PROVISIONING, sizeof(WidevineOemProvisioning)); #endif break; case PLAYREADY_MODEL_3K_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_PLAYREADY_3K - SEC_LOG_ERROR("Handling PlayReady 3K provisioning"); + SEC_LOG_INFO("Handling PlayReady 3K provisioning"); status = provisioning_ta(processorHandle, PLAY_READY_OBJ, PLAYREADY_MODEL_3K_SOC_PROVISIONING, sizeof(PlayReadyProvisioning)); #endif break; case PLAYREADY_MODEL_2K_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_PLAYREADY_2K - SEC_LOG_ERROR("Handling PlayReady 2K provisioning"); + SEC_LOG_INFO("Handling PlayReady 2K provisioning"); status = provisioning_ta(processorHandle, PLAY_READY_OBJ, PLAYREADY_MODEL_2K_SOC_PROVISIONING, sizeof(PlayReadyProvisioning)); #endif break; case APPLE_MFI_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_MFI - SEC_LOG_ERROR("Handling Apple MFI provisioning"); + SEC_LOG_INFO("Handling Apple MFI provisioning"); status = provisioning_ta(processorHandle, APPLE_MFI_OBJ, APPLE_MFI_SOC_PROVISIONING, sizeof(AppleMfiProvisioning)); #endif break; case APPLE_FAIRPLAY_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_FAIRPLAY - SEC_LOG_ERROR("Handling Apple FairPlay provisioning"); + SEC_LOG_INFO("Handling Apple FairPlay provisioning"); status = provisioning_ta(processorHandle, APPLE_FAIR_PLAY_OBJ, APPLE_FAIRPLAY_SOC_PROVISIONING, sizeof(AppleFairPlayProvisioning)); #endif break; case NETFLIX_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_NETFLIX - SEC_LOG_ERROR("Handling Netflix provisioning"); + SEC_LOG_INFO("Handling Netflix provisioning"); status = provisioning_ta(processorHandle, NETFLIX_OBJ, NETFLIX_SOC_PROVISIONING, sizeof(NetflixProvisioning)); #endif break; @@ -629,7 +629,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Falied sa_key_provision_ta call in widevine"); return SEC_RESULT_FAILURE; } - SEC_LOG_ERROR("Widevine provisioning completed successfully"); + SEC_LOG_INFO("Widevine provisioning completed successfully"); break; case PLAYREADY_MODEL_2K_SOC_PROVISIONING: @@ -645,7 +645,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Falied sa_key_provision_ta call in playready 2k"); return SEC_RESULT_FAILURE; } - SEC_LOG_ERROR("PlayReady Model 2K provisioning completed successfully"); + SEC_LOG_INFO("PlayReady Model 2K provisioning completed successfully"); break; case PLAYREADY_MODEL_3K_SOC_PROVISIONING: @@ -661,7 +661,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Falied sa_key_provision_ta call in playready 3k"); return SEC_RESULT_FAILURE; } - SEC_LOG_ERROR("PlayReady Model 3K provisioning completed successfully"); + SEC_LOG_INFO("PlayReady Model 3K provisioning completed successfully"); break; case APPLE_MFI_SOC_PROVISIONING: @@ -677,7 +677,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple_Mfi"); return SEC_RESULT_FAILURE; } - SEC_LOG_ERROR("Apple_Mfi provisioning completed successfully"); + SEC_LOG_INFO("Apple_Mfi provisioning completed successfully"); break; case APPLE_FAIRPLAY_SOC_PROVISIONING: @@ -693,11 +693,11 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Failed to call sa_key_provision_ta in AppleFairplay"); return SEC_RESULT_FAILURE; } - SEC_LOG_ERROR("AppeFairplay provisioning completed successfully"); + SEC_LOG_INFO("AppleFairplay provisioning completed successfully"); break; case NETFLIX_SOC_PROVISIONING: - SEC_LOG_ERROR("Handling Netflix provisioning"); + SEC_LOG_INFO("Handling Netflix provisioning"); NetflixProvisioning* netflixProvisioningData = NULL; if (readNetflixData(processorHandle, &netflixProvisioningData) == false) { SEC_LOG_ERROR("Failed to read Netflix provisioning data"); @@ -710,7 +710,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Netflix"); return SEC_RESULT_FAILURE; } - SEC_LOG_ERROR("Netflix provisioning completed successfully"); + SEC_LOG_INFO("Netflix provisioning completed successfully"); break; default: diff --git a/src/sec_adapter_utils.c b/src/sec_adapter_utils.c index a2c07dd..2bffa96 100644 --- a/src/sec_adapter_utils.c +++ b/src/sec_adapter_utils.c @@ -314,7 +314,7 @@ Sec_Result SecUtils_MkDir(const char* path) { if (*p == '/') { *p = 0; if (mkdir(tmp, S_IRWXU) != 0 && errno != EEXIST) { - SEC_LOG_ERROR("Warning Mkdir %s failed", tmp); + SEC_LOG_WARNING("Mkdir %s failed", tmp); //return SEC_RESULT_FAILURE; } @@ -323,7 +323,7 @@ Sec_Result SecUtils_MkDir(const char* path) { } if (mkdir(tmp, S_IRWXU) != 0 && errno != EEXIST) { - SEC_LOG_ERROR("Warning Mkdir %s failed", tmp); + SEC_LOG_WARNING("Mkdir %s failed", tmp); //return SEC_RESULT_FAILURE; } From b4c4cf469d5c74ab056c4e2e95ebbd412bf02307 Mon Sep 17 00:00:00 2001 From: Richard Woh Date: Wed, 2 Sep 2026 20:02:31 -0700 Subject: [PATCH 2/5] refactor: use existing SEC_LOG instead of new logging macros Avoid changing the public sec_security.h header; the existing SEC_LOG macro already logs without the ERROR prefix. --- include/sec_security.h | 10 ---------- src/sec_adapter_soc_provisioning.c | 26 +++++++++++++------------- src/sec_adapter_utils.c | 4 ++-- 3 files changed, 15 insertions(+), 25 deletions(-) diff --git a/include/sec_security.h b/include/sec_security.h index 17ffbc7..b260d7a 100644 --- a/include/sec_security.h +++ b/include/sec_security.h @@ -122,16 +122,6 @@ extern "C" { SEC_LOG("ERROR: " txt, ##__VA_ARGS__); \ } while (0) -#define SEC_LOG_WARNING(txt, ...) \ - do { \ - SEC_LOG("WARNING: " txt, ##__VA_ARGS__); \ - } while (0) - -#define SEC_LOG_INFO(txt, ...) \ - do { \ - SEC_LOG("INFO: " txt, ##__VA_ARGS__); \ - } while (0) - #define SEC_TRACE(enabled, txt, ...) \ do { \ if (enabled) { \ diff --git a/src/sec_adapter_soc_provisioning.c b/src/sec_adapter_soc_provisioning.c index ad123c8..6a4fc76 100644 --- a/src/sec_adapter_soc_provisioning.c +++ b/src/sec_adapter_soc_provisioning.c @@ -553,42 +553,42 @@ Sec_Result SecSocProv_Ta_Provision(Sec_ProcessorHandle* processorHandle, sa_key_ switch (key_type) { case WIDEVINE_OEM_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_WIDEVINE - SEC_LOG_INFO("Handling Widevine provisioning"); + SEC_LOG("Handling Widevine provisioning"); status = provisioning_ta(processorHandle, WIDEVINE_OBJ, WIDEVINE_OEM_SOC_PROVISIONING, sizeof(WidevineOemProvisioning)); #endif break; case PLAYREADY_MODEL_3K_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_PLAYREADY_3K - SEC_LOG_INFO("Handling PlayReady 3K provisioning"); + SEC_LOG("Handling PlayReady 3K provisioning"); status = provisioning_ta(processorHandle, PLAY_READY_OBJ, PLAYREADY_MODEL_3K_SOC_PROVISIONING, sizeof(PlayReadyProvisioning)); #endif break; case PLAYREADY_MODEL_2K_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_PLAYREADY_2K - SEC_LOG_INFO("Handling PlayReady 2K provisioning"); + SEC_LOG("Handling PlayReady 2K provisioning"); status = provisioning_ta(processorHandle, PLAY_READY_OBJ, PLAYREADY_MODEL_2K_SOC_PROVISIONING, sizeof(PlayReadyProvisioning)); #endif break; case APPLE_MFI_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_MFI - SEC_LOG_INFO("Handling Apple MFI provisioning"); + SEC_LOG("Handling Apple MFI provisioning"); status = provisioning_ta(processorHandle, APPLE_MFI_OBJ, APPLE_MFI_SOC_PROVISIONING, sizeof(AppleMfiProvisioning)); #endif break; case APPLE_FAIRPLAY_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_FAIRPLAY - SEC_LOG_INFO("Handling Apple FairPlay provisioning"); + SEC_LOG("Handling Apple FairPlay provisioning"); status = provisioning_ta(processorHandle, APPLE_FAIR_PLAY_OBJ, APPLE_FAIRPLAY_SOC_PROVISIONING, sizeof(AppleFairPlayProvisioning)); #endif break; case NETFLIX_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_NETFLIX - SEC_LOG_INFO("Handling Netflix provisioning"); + SEC_LOG("Handling Netflix provisioning"); status = provisioning_ta(processorHandle, NETFLIX_OBJ, NETFLIX_SOC_PROVISIONING, sizeof(NetflixProvisioning)); #endif break; @@ -629,7 +629,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Falied sa_key_provision_ta call in widevine"); return SEC_RESULT_FAILURE; } - SEC_LOG_INFO("Widevine provisioning completed successfully"); + SEC_LOG("Widevine provisioning completed successfully"); break; case PLAYREADY_MODEL_2K_SOC_PROVISIONING: @@ -645,7 +645,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Falied sa_key_provision_ta call in playready 2k"); return SEC_RESULT_FAILURE; } - SEC_LOG_INFO("PlayReady Model 2K provisioning completed successfully"); + SEC_LOG("PlayReady Model 2K provisioning completed successfully"); break; case PLAYREADY_MODEL_3K_SOC_PROVISIONING: @@ -661,7 +661,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Falied sa_key_provision_ta call in playready 3k"); return SEC_RESULT_FAILURE; } - SEC_LOG_INFO("PlayReady Model 3K provisioning completed successfully"); + SEC_LOG("PlayReady Model 3K provisioning completed successfully"); break; case APPLE_MFI_SOC_PROVISIONING: @@ -677,7 +677,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple_Mfi"); return SEC_RESULT_FAILURE; } - SEC_LOG_INFO("Apple_Mfi provisioning completed successfully"); + SEC_LOG("Apple_Mfi provisioning completed successfully"); break; case APPLE_FAIRPLAY_SOC_PROVISIONING: @@ -693,11 +693,11 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Failed to call sa_key_provision_ta in AppleFairplay"); return SEC_RESULT_FAILURE; } - SEC_LOG_INFO("AppleFairplay provisioning completed successfully"); + SEC_LOG("AppleFairplay provisioning completed successfully"); break; case NETFLIX_SOC_PROVISIONING: - SEC_LOG_INFO("Handling Netflix provisioning"); + SEC_LOG("Handling Netflix provisioning"); NetflixProvisioning* netflixProvisioningData = NULL; if (readNetflixData(processorHandle, &netflixProvisioningData) == false) { SEC_LOG_ERROR("Failed to read Netflix provisioning data"); @@ -710,7 +710,7 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Netflix"); return SEC_RESULT_FAILURE; } - SEC_LOG_INFO("Netflix provisioning completed successfully"); + SEC_LOG("Netflix provisioning completed successfully"); break; default: diff --git a/src/sec_adapter_utils.c b/src/sec_adapter_utils.c index 2bffa96..12d044e 100644 --- a/src/sec_adapter_utils.c +++ b/src/sec_adapter_utils.c @@ -314,7 +314,7 @@ Sec_Result SecUtils_MkDir(const char* path) { if (*p == '/') { *p = 0; if (mkdir(tmp, S_IRWXU) != 0 && errno != EEXIST) { - SEC_LOG_WARNING("Mkdir %s failed", tmp); + SEC_LOG("Warning: Mkdir %s failed", tmp); //return SEC_RESULT_FAILURE; } @@ -323,7 +323,7 @@ Sec_Result SecUtils_MkDir(const char* path) { } if (mkdir(tmp, S_IRWXU) != 0 && errno != EEXIST) { - SEC_LOG_WARNING("Mkdir %s failed", tmp); + SEC_LOG("Warning: Mkdir %s failed", tmp); //return SEC_RESULT_FAILURE; } From deebc7f61a6b4d9ec731bc7bb7657b8e9084463c Mon Sep 17 00:00:00 2001 From: Richard Woh Date: Tue, 8 Sep 2026 08:09:47 -0700 Subject: [PATCH 3/5] fix: address PR review comments on SoC provisioning logging - Change provisioning_ta to return Sec_Result instead of bool; the implementation already returned SEC_RESULT_*, so a bool return meant false on success and true on failure. - Free the sa_import_parameters_soc allocation on every read*Data early return, which previously leaked on provisioning-data read failures. - Fix 'Falied' -> 'Failed' typos in the widevine and playready logs. - Use consistent 'Apple MFi' / 'Apple Fairplay' product naming across handling, error and success logs. - Drop the duplicate 'Handling Netflix provisioning' log inside provisioning_ta; SecSocProv_Ta_Provision already emits it and no other provisioning type logs it there. - Include strerror(errno) in the non-fatal SecUtils_MkDir warnings. --- src/sec_adapter_soc_provisioning.c | 34 ++++++++++++++++++------------ src/sec_adapter_soc_provisioning.h | 5 +++-- src/sec_adapter_utils.c | 4 ++-- 3 files changed, 25 insertions(+), 18 deletions(-) diff --git a/src/sec_adapter_soc_provisioning.c b/src/sec_adapter_soc_provisioning.c index 6a4fc76..372c2d3 100644 --- a/src/sec_adapter_soc_provisioning.c +++ b/src/sec_adapter_soc_provisioning.c @@ -574,14 +574,14 @@ Sec_Result SecSocProv_Ta_Provision(Sec_ProcessorHandle* processorHandle, sa_key_ case APPLE_MFI_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_MFI - SEC_LOG("Handling Apple MFI provisioning"); + SEC_LOG("Handling Apple MFi provisioning"); status = provisioning_ta(processorHandle, APPLE_MFI_OBJ, APPLE_MFI_SOC_PROVISIONING, sizeof(AppleMfiProvisioning)); #endif break; case APPLE_FAIRPLAY_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_FAIRPLAY - SEC_LOG("Handling Apple FairPlay provisioning"); + SEC_LOG("Handling Apple Fairplay provisioning"); status = provisioning_ta(processorHandle, APPLE_FAIR_PLAY_OBJ, APPLE_FAIRPLAY_SOC_PROVISIONING, sizeof(AppleFairPlayProvisioning)); #endif break; @@ -601,12 +601,13 @@ Sec_Result SecSocProv_Ta_Provision(Sec_ProcessorHandle* processorHandle, sa_key_ } -bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_key_type_soc_ta provisioningType, size_t dataSize) { +Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_key_type_soc_ta provisioningType, + size_t dataSize) { sa_status status; sa_import_parameters_soc* parameters = (sa_import_parameters_soc*)malloc(sizeof(sa_import_parameters_soc)); if (!parameters) { SEC_LOG_ERROR("Failed to allocate memory"); - return false; + return SEC_RESULT_FAILURE; } parameters->length[0] = (sizeof(sa_import_parameters_soc) >> 8) & 0xff; @@ -620,13 +621,14 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k WidevineOemProvisioning* provisioningData = NULL; if (readWidevineData(processorHandle, &provisioningData) == false) { SEC_LOG_ERROR("Failed to read widevine provisioning data"); + SEC_FREE(parameters); return SEC_RESULT_FAILURE; } status = sa_key_provision_ta(WIDEVINE_OEM_PROVISIONING, provisioningData, dataSize, parameters); SEC_FREE(provisioningData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Falied sa_key_provision_ta call in widevine"); + SEC_LOG_ERROR("Failed sa_key_provision_ta call in widevine"); return SEC_RESULT_FAILURE; } SEC_LOG("Widevine provisioning completed successfully"); @@ -636,13 +638,14 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k PlayReadyProvisioning* playReadyprovisioning2kData = NULL; if (readPlayReadyData(processorHandle, &playReadyprovisioning2kData, PLAYREADY_MODEL_2K) == false) { SEC_LOG_ERROR("Failed to read PlayReady 2k provisioning data"); + SEC_FREE(parameters); return SEC_RESULT_FAILURE; } status = sa_key_provision_ta(PLAYREADY_MODEL_PROVISIONING, playReadyprovisioning2kData, dataSize, parameters); SEC_FREE(playReadyprovisioning2kData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Falied sa_key_provision_ta call in playready 2k"); + SEC_LOG_ERROR("Failed sa_key_provision_ta call in playready 2k"); return SEC_RESULT_FAILURE; } SEC_LOG("PlayReady Model 2K provisioning completed successfully"); @@ -652,13 +655,14 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k PlayReadyProvisioning* playReadyprovisioning3kData = NULL; if (readPlayReadyData(processorHandle, &playReadyprovisioning3kData, PLAYREADY_MODEL_3K) == false) { SEC_LOG_ERROR("Failed to read PlayReady 3k provisioning data"); + SEC_FREE(parameters); return SEC_RESULT_FAILURE; } status = sa_key_provision_ta(PLAYREADY_MODEL_PROVISIONING, playReadyprovisioning3kData, dataSize, parameters); SEC_FREE(playReadyprovisioning3kData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Falied sa_key_provision_ta call in playready 3k"); + SEC_LOG_ERROR("Failed sa_key_provision_ta call in playready 3k"); return SEC_RESULT_FAILURE; } SEC_LOG("PlayReady Model 3K provisioning completed successfully"); @@ -667,40 +671,42 @@ bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_k case APPLE_MFI_SOC_PROVISIONING: AppleMfiProvisioning* appleMfiprovisioningData = NULL; if (readAppleMfiData(processorHandle, &appleMfiprovisioningData) == false) { - SEC_LOG_ERROR("Failed to read ApplaMFI provisioning data"); + SEC_LOG_ERROR("Failed to read Apple MFi provisioning data"); + SEC_FREE(parameters); return SEC_RESULT_FAILURE; } status = sa_key_provision_ta(APPLE_MFI_PROVISIONING, appleMfiprovisioningData, dataSize, parameters); SEC_FREE(appleMfiprovisioningData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple_Mfi"); + SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple MFi"); return SEC_RESULT_FAILURE; } - SEC_LOG("Apple_Mfi provisioning completed successfully"); + SEC_LOG("Apple MFi provisioning completed successfully"); break; case APPLE_FAIRPLAY_SOC_PROVISIONING: AppleFairPlayProvisioning* appleFairplayProvisioningData = NULL; if (readAppleFairPlayData(processorHandle, &appleFairplayProvisioningData) == false) { - SEC_LOG_ERROR("Failed to read ApplyFairplay provisioning data"); + SEC_LOG_ERROR("Failed to read Apple Fairplay provisioning data"); + SEC_FREE(parameters); return SEC_RESULT_FAILURE; } status = sa_key_provision_ta(APPLE_FAIRPLAY_PROVISIONING, appleFairplayProvisioningData, dataSize, parameters); SEC_FREE(appleFairplayProvisioningData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Failed to call sa_key_provision_ta in AppleFairplay"); + SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple Fairplay"); return SEC_RESULT_FAILURE; } - SEC_LOG("AppleFairplay provisioning completed successfully"); + SEC_LOG("Apple Fairplay provisioning completed successfully"); break; case NETFLIX_SOC_PROVISIONING: - SEC_LOG("Handling Netflix provisioning"); NetflixProvisioning* netflixProvisioningData = NULL; if (readNetflixData(processorHandle, &netflixProvisioningData) == false) { SEC_LOG_ERROR("Failed to read Netflix provisioning data"); + SEC_FREE(parameters); return SEC_RESULT_FAILURE; } status = sa_key_provision_ta(NETFLIX_PROVISIONING, netflixProvisioningData, dataSize, parameters); diff --git a/src/sec_adapter_soc_provisioning.h b/src/sec_adapter_soc_provisioning.h index 55d4686..ba0313d 100644 --- a/src/sec_adapter_soc_provisioning.h +++ b/src/sec_adapter_soc_provisioning.h @@ -116,9 +116,10 @@ Sec_Result store_raw_data(Sec_ProcessorHandle* processorHandle, Sec_StorageLoc l * @param numPaths The number of paths for provisioning. * @param provisioningType The type of provisioning to be used. * @param dataSize The size of the data associated with the provisioning. - * @return true if successful, false otherwise. + * @return Result of the operation. */ -bool provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths,sa_key_type_soc_ta provisioningType, size_t dataSize); +Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths, sa_key_type_soc_ta provisioningType, + size_t dataSize); /** * @brief Initiates provisioning using a trusted application key type. diff --git a/src/sec_adapter_utils.c b/src/sec_adapter_utils.c index 12d044e..d676268 100644 --- a/src/sec_adapter_utils.c +++ b/src/sec_adapter_utils.c @@ -314,7 +314,7 @@ Sec_Result SecUtils_MkDir(const char* path) { if (*p == '/') { *p = 0; if (mkdir(tmp, S_IRWXU) != 0 && errno != EEXIST) { - SEC_LOG("Warning: Mkdir %s failed", tmp); + SEC_LOG("Warning: Mkdir %s failed: %s", tmp, strerror(errno)); //return SEC_RESULT_FAILURE; } @@ -323,7 +323,7 @@ Sec_Result SecUtils_MkDir(const char* path) { } if (mkdir(tmp, S_IRWXU) != 0 && errno != EEXIST) { - SEC_LOG("Warning: Mkdir %s failed", tmp); + SEC_LOG("Warning: Mkdir %s failed: %s", tmp, strerror(errno)); //return SEC_RESULT_FAILURE; } From bb64e1063f1bdb95025f77582459dbaeb3505643 Mon Sep 17 00:00:00 2001 From: riwoh <107917169+riwoh@users.noreply.github.com> Date: Tue, 8 Sep 2026 08:58:21 -0700 Subject: [PATCH 4/5] Potential fix for pull request finding Fairplay -> FairPlay (fixing case) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> --- src/sec_adapter_soc_provisioning.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/sec_adapter_soc_provisioning.c b/src/sec_adapter_soc_provisioning.c index 372c2d3..1066f99 100644 --- a/src/sec_adapter_soc_provisioning.c +++ b/src/sec_adapter_soc_provisioning.c @@ -581,7 +581,7 @@ Sec_Result SecSocProv_Ta_Provision(Sec_ProcessorHandle* processorHandle, sa_key_ case APPLE_FAIRPLAY_SOC_PROVISIONING: #if ENABLE_SOC_PROVISION_APPLE_FAIRPLAY - SEC_LOG("Handling Apple Fairplay provisioning"); + SEC_LOG("Handling Apple FairPlay provisioning"); status = provisioning_ta(processorHandle, APPLE_FAIR_PLAY_OBJ, APPLE_FAIRPLAY_SOC_PROVISIONING, sizeof(AppleFairPlayProvisioning)); #endif break; From 2cc8e9e35f25f3771d3fbcd1fad46317d7dd623a Mon Sep 17 00:00:00 2001 From: Richard Woh Date: Tue, 8 Sep 2026 09:14:52 -0700 Subject: [PATCH 5/5] Fix DRM product name casing in provisioning log messages --- src/sec_adapter_soc_provisioning.c | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) diff --git a/src/sec_adapter_soc_provisioning.c b/src/sec_adapter_soc_provisioning.c index 1066f99..aa3e27b 100644 --- a/src/sec_adapter_soc_provisioning.c +++ b/src/sec_adapter_soc_provisioning.c @@ -620,7 +620,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths case WIDEVINE_OEM_SOC_PROVISIONING: WidevineOemProvisioning* provisioningData = NULL; if (readWidevineData(processorHandle, &provisioningData) == false) { - SEC_LOG_ERROR("Failed to read widevine provisioning data"); + SEC_LOG_ERROR("Failed to read Widevine provisioning data"); SEC_FREE(parameters); return SEC_RESULT_FAILURE; } @@ -628,7 +628,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths SEC_FREE(provisioningData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Failed sa_key_provision_ta call in widevine"); + SEC_LOG_ERROR("Failed sa_key_provision_ta call in Widevine"); return SEC_RESULT_FAILURE; } SEC_LOG("Widevine provisioning completed successfully"); @@ -637,7 +637,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths case PLAYREADY_MODEL_2K_SOC_PROVISIONING: PlayReadyProvisioning* playReadyprovisioning2kData = NULL; if (readPlayReadyData(processorHandle, &playReadyprovisioning2kData, PLAYREADY_MODEL_2K) == false) { - SEC_LOG_ERROR("Failed to read PlayReady 2k provisioning data"); + SEC_LOG_ERROR("Failed to read PlayReady 2K provisioning data"); SEC_FREE(parameters); return SEC_RESULT_FAILURE; } @@ -645,7 +645,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths SEC_FREE(playReadyprovisioning2kData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Failed sa_key_provision_ta call in playready 2k"); + SEC_LOG_ERROR("Failed sa_key_provision_ta call in PlayReady 2K"); return SEC_RESULT_FAILURE; } SEC_LOG("PlayReady Model 2K provisioning completed successfully"); @@ -654,7 +654,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths case PLAYREADY_MODEL_3K_SOC_PROVISIONING: PlayReadyProvisioning* playReadyprovisioning3kData = NULL; if (readPlayReadyData(processorHandle, &playReadyprovisioning3kData, PLAYREADY_MODEL_3K) == false) { - SEC_LOG_ERROR("Failed to read PlayReady 3k provisioning data"); + SEC_LOG_ERROR("Failed to read PlayReady 3K provisioning data"); SEC_FREE(parameters); return SEC_RESULT_FAILURE; } @@ -662,7 +662,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths SEC_FREE(playReadyprovisioning3kData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Failed sa_key_provision_ta call in playready 3k"); + SEC_LOG_ERROR("Failed sa_key_provision_ta call in PlayReady 3K"); return SEC_RESULT_FAILURE; } SEC_LOG("PlayReady Model 3K provisioning completed successfully"); @@ -688,7 +688,7 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths case APPLE_FAIRPLAY_SOC_PROVISIONING: AppleFairPlayProvisioning* appleFairplayProvisioningData = NULL; if (readAppleFairPlayData(processorHandle, &appleFairplayProvisioningData) == false) { - SEC_LOG_ERROR("Failed to read Apple Fairplay provisioning data"); + SEC_LOG_ERROR("Failed to read Apple FairPlay provisioning data"); SEC_FREE(parameters); return SEC_RESULT_FAILURE; } @@ -696,10 +696,10 @@ Sec_Result provisioning_ta(Sec_ProcessorHandle* processorHandle, size_t numPaths SEC_FREE(appleFairplayProvisioningData); SEC_FREE(parameters); if (status != SA_STATUS_OK) { - SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple Fairplay"); + SEC_LOG_ERROR("Failed to call sa_key_provision_ta in Apple FairPlay"); return SEC_RESULT_FAILURE; } - SEC_LOG("Apple Fairplay provisioning completed successfully"); + SEC_LOG("Apple FairPlay provisioning completed successfully"); break; case NETFLIX_SOC_PROVISIONING: