@@ -428,6 +428,7 @@ CONFIG_SOC_INTEL_COMMON_BLOCK_XHCI_ELOG=y
428428CONFIG_SOC_INTEL_COMMON_PCH_CLIENT=y
429429CONFIG_SOC_INTEL_COMMON_PCH_BASE=y
430430CONFIG_SOC_INTEL_COMMON_PCH_LOCKDOWN=y
431+ CONFIG_SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM=y
431432CONFIG_PCH_SPECIFIC_BASE_OPTIONS=y
432433CONFIG_PCH_SPECIFIC_DISCRETE_OPTIONS=y
433434CONFIG_PCH_SPECIFIC_CLIENT_OPTIONS=y
@@ -489,8 +490,10 @@ CONFIG_PCIEXP_HOTPLUG=y
489490CONFIG_INTEL_DESCRIPTOR_MODE_REQUIRED=y
490491CONFIG_SOUTHBRIDGE_INTEL_COMMON_SMBUS=y
491492CONFIG_SOUTHBRIDGE_INTEL_COMMON_PIRQ_ACPI_GEN=y
493+ CONFIG_HAVE_INTEL_CHIPSET_LOCKDOWN=y
492494CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
493495# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
496+ # CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
494497CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000
495498CONFIG_RCBA_LENGTH=0x4000
496499
@@ -617,6 +620,7 @@ CONFIG_MRC_SETTINGS_PROTECT=y
617620CONFIG_SPI_FLASH=y
618621CONFIG_BOOT_DEVICE_SPI_FLASH_RW_NOMMAP=y
619622CONFIG_BOOT_DEVICE_SPI_FLASH_RW_NOMMAP_EARLY=y
623+ CONFIG_SPI_FLASH_SMM=y
620624# CONFIG_SPI_FLASH_NO_FAST_READ is not set
621625CONFIG_TPM_INIT_RAMSTAGE=y
622626# CONFIG_TPM_PPI is not set
@@ -729,9 +733,11 @@ CONFIG_INTEL_TXT_LIB=y
729733# CONFIG_INTEL_TXT is not set
730734# CONFIG_STM is not set
731735# CONFIG_INTEL_CBNT_SUPPORT is not set
732- CONFIG_BOOTMEDIA_LOCK_NONE=y
733- # CONFIG_BOOTMEDIA_LOCK_CONTROLLER is not set
736+ # CONFIG_BOOTMEDIA_LOCK_NONE is not set
737+ CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
734738# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
739+ CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
740+ # CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
735741# CONFIG_BOOTMEDIA_SMM_BWP is not set
736742# end of Security
737743
0 commit comments