Skip to content

Commit 14e7a76

Browse files
committed
coreboot config: correct CONFIG_INTEL_CHIPSET_LOCKDOWN behavior to make sure none locks
1 parent a4f5965 commit 14e7a76

16 files changed

+48
-26
lines changed

config/coreboot-p8z77-m_pro-tpm1.config

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -327,7 +327,7 @@ CONFIG_SOUTHBRIDGE_INTEL_COMMON_FINALIZE=y
327327
CONFIG_SOUTHBRIDGE_INTEL_COMMON_USB_DEBUG=y
328328
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
329329
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
330-
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
330+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
331331
CONFIG_TCO_SPACE_NOT_YET_SPLIT=y
332332
CONFIG_SOUTHBRIDGE_INTEL_COMMON_WATCHDOG=y
333333
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000

config/coreboot-t420-maximized.config

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -328,14 +328,14 @@ CONFIG_SOUTHBRIDGE_INTEL_COMMON_SPI=y
328328
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SPI_ICH9=y
329329
CONFIG_SOUTHBRIDGE_INTEL_COMMON_PIRQ_ACPI_GEN=y
330330
CONFIG_SOUTHBRIDGE_INTEL_COMMON_RCBA_PIRQ=y
331-
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
331+
CONFIG_HAVE_INTEL_CHIPSET_LOCKDOWN=y
332332
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SMM=y
333333
CONFIG_SOUTHBRIDGE_INTEL_COMMON_ACPI_MADT=y
334334
CONFIG_SOUTHBRIDGE_INTEL_COMMON_FINALIZE=y
335335
CONFIG_SOUTHBRIDGE_INTEL_COMMON_USB_DEBUG=y
336336
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
337337
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
338-
CONFIG_INTEL_CHIPSET_LOCKDOWN=y
338+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
339339
CONFIG_TCO_SPACE_NOT_YET_SPLIT=y
340340
CONFIG_SOUTHBRIDGE_INTEL_COMMON_WATCHDOG=y
341341
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000
@@ -541,9 +541,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
541541

542542
# CONFIG_INTEL_TXT is not set
543543
# CONFIG_STM is not set
544-
CONFIG_BOOTMEDIA_LOCK_NONE=y
544+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
545545
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
546546
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
547+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
548+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
547549
# CONFIG_BOOTMEDIA_SMM_BWP is not set
548550
# end of Security
549551

config/coreboot-t420.config

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -334,7 +334,7 @@ CONFIG_SOUTHBRIDGE_INTEL_COMMON_FINALIZE=y
334334
CONFIG_SOUTHBRIDGE_INTEL_COMMON_USB_DEBUG=y
335335
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
336336
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
337-
CONFIG_INTEL_CHIPSET_LOCKDOWN=y
337+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
338338
CONFIG_TCO_SPACE_NOT_YET_SPLIT=y
339339
CONFIG_SOUTHBRIDGE_INTEL_COMMON_WATCHDOG=y
340340
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000

config/coreboot-t430-legacy.config

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -332,7 +332,7 @@ CONFIG_SOUTHBRIDGE_INTEL_COMMON_FINALIZE=y
332332
CONFIG_SOUTHBRIDGE_INTEL_COMMON_USB_DEBUG=y
333333
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
334334
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
335-
CONFIG_INTEL_CHIPSET_LOCKDOWN=y
335+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
336336
CONFIG_TCO_SPACE_NOT_YET_SPLIT=y
337337
CONFIG_SOUTHBRIDGE_INTEL_COMMON_WATCHDOG=y
338338
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000

config/coreboot-t430-maximized.config

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -541,9 +541,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
541541

542542
# CONFIG_INTEL_TXT is not set
543543
# CONFIG_STM is not set
544-
CONFIG_BOOTMEDIA_LOCK_NONE=y
544+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
545545
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
546546
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
547+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
548+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
547549
# CONFIG_BOOTMEDIA_SMM_BWP is not set
548550
# end of Security
549551

config/coreboot-t520-maximized.config

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -329,14 +329,14 @@ CONFIG_SOUTHBRIDGE_INTEL_COMMON_SPI=y
329329
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SPI_ICH9=y
330330
CONFIG_SOUTHBRIDGE_INTEL_COMMON_PIRQ_ACPI_GEN=y
331331
CONFIG_SOUTHBRIDGE_INTEL_COMMON_RCBA_PIRQ=y
332-
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
332+
CONFIG_HAVE_INTEL_CHIPSET_LOCKDOWN=y
333333
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SMM=y
334334
CONFIG_SOUTHBRIDGE_INTEL_COMMON_ACPI_MADT=y
335335
CONFIG_SOUTHBRIDGE_INTEL_COMMON_FINALIZE=y
336336
CONFIG_SOUTHBRIDGE_INTEL_COMMON_USB_DEBUG=y
337337
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
338338
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
339-
CONFIG_INTEL_CHIPSET_LOCKDOWN=y
339+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
340340
CONFIG_TCO_SPACE_NOT_YET_SPLIT=y
341341
CONFIG_SOUTHBRIDGE_INTEL_COMMON_WATCHDOG=y
342342
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000
@@ -537,9 +537,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
537537

538538
# CONFIG_INTEL_TXT is not set
539539
# CONFIG_STM is not set
540-
CONFIG_BOOTMEDIA_LOCK_NONE=y
540+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
541541
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
542542
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
543+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
544+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
543545
# CONFIG_BOOTMEDIA_SMM_BWP is not set
544546
# end of Security
545547

config/coreboot-t530-dgpu-maximized.config

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -334,14 +334,14 @@ CONFIG_SOUTHBRIDGE_INTEL_COMMON_SPI=y
334334
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SPI_ICH9=y
335335
CONFIG_SOUTHBRIDGE_INTEL_COMMON_PIRQ_ACPI_GEN=y
336336
CONFIG_SOUTHBRIDGE_INTEL_COMMON_RCBA_PIRQ=y
337-
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
337+
CONFIG_HAVE_INTEL_CHIPSET_LOCKDOWN=y
338338
CONFIG_SOUTHBRIDGE_INTEL_COMMON_SMM=y
339339
CONFIG_SOUTHBRIDGE_INTEL_COMMON_ACPI_MADT=y
340340
CONFIG_SOUTHBRIDGE_INTEL_COMMON_FINALIZE=y
341341
CONFIG_SOUTHBRIDGE_INTEL_COMMON_USB_DEBUG=y
342342
CONFIG_INTEL_DESCRIPTOR_MODE_CAPABLE=y
343343
# CONFIG_VALIDATE_INTEL_DESCRIPTOR is not set
344-
CONFIG_INTEL_CHIPSET_LOCKDOWN=y
344+
# CONFIG_INTEL_CHIPSET_LOCKDOWN is not set
345345
CONFIG_TCO_SPACE_NOT_YET_SPLIT=y
346346
CONFIG_SOUTHBRIDGE_INTEL_COMMON_WATCHDOG=y
347347
CONFIG_FIXED_RCBA_MMIO_BASE=0xfed1c000
@@ -542,9 +542,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
542542

543543
# CONFIG_INTEL_TXT is not set
544544
# CONFIG_STM is not set
545-
CONFIG_BOOTMEDIA_LOCK_NONE=y
545+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
546546
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
547547
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
548+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
549+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
548550
# CONFIG_BOOTMEDIA_SMM_BWP is not set
549551
# end of Security
550552

config/coreboot-t530-maximized.config

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -543,9 +543,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
543543

544544
# CONFIG_INTEL_TXT is not set
545545
# CONFIG_STM is not set
546-
CONFIG_BOOTMEDIA_LOCK_NONE=y
546+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
547547
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
548548
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
549+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
550+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
549551
# CONFIG_BOOTMEDIA_SMM_BWP is not set
550552
# end of Security
551553

config/coreboot-w530-dgpu-K1000m-maximized.config

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -543,9 +543,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
543543

544544
# CONFIG_INTEL_TXT is not set
545545
# CONFIG_STM is not set
546-
CONFIG_BOOTMEDIA_LOCK_NONE=y
546+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
547547
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
548548
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
549+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
550+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
549551
# CONFIG_BOOTMEDIA_SMM_BWP is not set
550552
# end of Security
551553

config/coreboot-w530-dgpu-K2000m-maximized.config

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -543,9 +543,11 @@ CONFIG_PLATFORM_HAS_DRAM_CLEAR=y
543543

544544
# CONFIG_INTEL_TXT is not set
545545
# CONFIG_STM is not set
546-
CONFIG_BOOTMEDIA_LOCK_NONE=y
546+
# CONFIG_BOOTMEDIA_LOCK_NONE is not set
547547
CONFIG_BOOTMEDIA_LOCK_CONTROLLER=y
548548
# CONFIG_BOOTMEDIA_LOCK_CHIP is not set
549+
CONFIG_BOOTMEDIA_LOCK_WHOLE_RO=y
550+
# CONFIG_BOOTMEDIA_LOCK_WHOLE_NO_ACCESS is not set
549551
# CONFIG_BOOTMEDIA_SMM_BWP is not set
550552
# end of Security
551553

0 commit comments

Comments
 (0)