9 comments:
File Documentation/security/vboot/measured_boot.md:
Patch Set #22, Line 22: SMM is currently excluded from measurements but will be added in a later stage.
phase
Patch Set #22, Line 26: by measuring code before it is loaded. At the moment measurements of cbfs and
CBFS
Patch Set #22, Line 27: FMAP content is possible. This includes the Intel IFD as well.
are
list which partitions could be measured
File src/security/vboot/vboot_crtm.c:
Patch Set #22, Line 80: if (fmap_locate_area_as_rdev("SI_ME", &fmap) == 0)
TPM_RUNTIME_DATA_PCR
Patch Set #22, Line 85: if (fmap_locate_area_as_rdev("SI_EC", &fmap) == 0)
TPM_RUNTIME_DATA_PCR
Patch Set #22, Line 95: if (fmap_locate_area_as_rdev("SI_PDR", &fmap) == 0)
TPM_RUNTIME_DATA_PCR
Patch Set #22, Line 116: /* fmap measurement */
FMAP
Patch Set #22, Line 267: if (!strcmp("COREBOOT", name) ||
Use FMAP flags to detect a "CBFS" FMAP partition.
To view, visit change 31597. To unsubscribe, or for help writing mail filters, visit settings.