Skip to content

Commit 0cff229

Browse files
committed
ns50: add PR0 chipset locking requirements to board config and coreboot config
Signed-off-by: Thierry Laurion <insurgo@riseup.net>
1 parent b14d32e commit 0cff229

File tree

2 files changed

+14
-3
lines changed

2 files changed

+14
-3
lines changed

boards/nitropad-ns50/nitropad-ns50.config

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,12 @@ CONFIG_UTIL_LINUX=y
2929
CONFIG_LVM2=y
3030
CONFIG_MBEDTLS=y
3131
CONFIG_PCIUTILS=y
32-
CONFIG_MSRTOOLS=y
32+
33+
#platform locking finalization (PR0)
34+
CONFIG_IO386=y
35+
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
36+
37+
3338
#Remote attestation support
3439
# TPM2 requirements
3540
CONFIG_TPM2_TSS=y

config/coreboot-nitropad-ns50.config

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -428,6 +428,7 @@ CONFIG_SOC_INTEL_COMMON_BLOCK_XHCI_ELOG=y
428428
CONFIG_SOC_INTEL_COMMON_PCH_CLIENT=y
429429
CONFIG_SOC_INTEL_COMMON_PCH_BASE=y
430430
CONFIG_SOC_INTEL_COMMON_PCH_LOCKDOWN=y
431+
CONFIG_SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM=y
431432
CONFIG_PCH_SPECIFIC_BASE_OPTIONS=y
432433
CONFIG_PCH_SPECIFIC_DISCRETE_OPTIONS=y
433434
CONFIG_PCH_SPECIFIC_CLIENT_OPTIONS=y
@@ -489,8 +490,10 @@ CONFIG_PCIEXP_HOTPLUG=y
489490
CONFIG_INTEL_DESCRIPTOR_MODE_REQUIRED=y
490491
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SMBUS=y
491492
CONFIG_SOUTHBRIDGE_INTEL_COMMON_PIRQ_ACPI_GEN=y
493+
CONFIG_HAVE_INTEL_CHIPSET_LOCKDOWN=y
492494
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
493495
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
496+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
494497
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000
495498
CONFIG_RCBA_LENGTH=0x4000
496499

@@ -617,6 +620,7 @@ CONFIG_MRC_SETTINGS_PROTECT=y
617620
CONFIG_SPI_FLASH=y
618621
CONFIG_BOOT_DEVICE_SPI_FLASH_RW_NOMMAP=y
619622
CONFIG_BOOT_DEVICE_SPI_FLASH_RW_NOMMAP_EARLY=y
623+
CONFIG_SPI_FLASH_SMM=y
620624
# CONFIG_SPI_FLASH_NO_FAST_READ is not set
621625
CONFIG_TPM_INIT_RAMSTAGE=y
622626
# CONFIG_TPM_PPI is not set
@@ -729,9 +733,11 @@ CONFIG_INTEL_TXT_LIB=y
729733
# CONFIG_INTEL_TXT is not set
730734
# CONFIG_STM is not set
731735
# CONFIG_INTEL_CBNT_SUPPORT is not set
732-
CONFIG_BOOTMEDIA_LOCK_NONE=y
733-
# CONFIG_BOOTMEDIA_LOCK_CONTROLLER is not set
736+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
737+
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
734738
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
739+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
740+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
735741
# CONFIG_BOOTMEDIA_SMM_BWP is not set
736742
# end of Security
737743

0 commit comments

Comments
 (0)