Patrick Rudolph has posted comments on this change. ( https://review.coreboot.org/c/coreboot/+/32704 )
Change subject: security: Add common boot media write protection
......................................................................
Patch Set 9:
(2 comments)
https://review.coreboot.org/c/coreboot/+/32704/8/src/security/lockdown/Kconf...
File src/security/lockdown/Kconfig:
https://review.coreboot.org/c/coreboot/+/32704/8/src/security/lockdown/Kconf...
PS8, Line 17: (e.g. by the payload or the OS).
The help text should explain that this is only supported on certain controllers (e.g. Intel).
Done
https://review.coreboot.org/c/coreboot/+/32704/8/src/security/lockdown/Kconf...
PS8, Line 28: The locking will take place during the chipset lockdown, which
: is either triggered by coreboot (when INTEL_CHIPSET_LOCKDOWN is set)
: or has to be triggered later (e.g. by the payload or the OS).
This is wrong for chip lockdown, isn't it? It happens immediately when the lockdown code runs.
Done
--
To view, visit
https://review.coreboot.org/c/coreboot/+/32704
To unsubscribe, or for help writing mail filters, visit
https://review.coreboot.org/settings
Gerrit-Project: coreboot
Gerrit-Branch: master
Gerrit-Change-Id: Iceb3ecf0bde5cec562bc62d1d5c79da35305d183
Gerrit-Change-Number: 32704
Gerrit-PatchSet: 9
Gerrit-Owner: Patrick Rudolph
patrick.rudolph@9elements.com
Gerrit-Reviewer: Arthur Heymans
arthur@aheymans.xyz
Gerrit-Reviewer: Christian Walter
christian.walter@9elements.com
Gerrit-Reviewer: Frans Hendriks
fhendriks@eltan.com
Gerrit-Reviewer: Julius Werner
jwerner@chromium.org
Gerrit-Reviewer: Martin Roth
martinroth@google.com
Gerrit-Reviewer: Nico Huber
nico.h@gmx.de
Gerrit-Reviewer: Patrick Georgi
pgeorgi@google.com
Gerrit-Reviewer: Patrick Rudolph
patrick.rudolph@9elements.com
Gerrit-Reviewer: Patrick Rudolph
siro@das-labor.org
Gerrit-Reviewer: Philipp Deppenwiese
zaolin.daisuki@gmail.com
Gerrit-Reviewer: build bot (Jenkins)
no-reply@coreboot.org
Gerrit-CC: Aaron Durbin
adurbin@chromium.org
Gerrit-CC: Michael Niewöhner
Gerrit-CC: Paul Menzel
paulepanter@users.sourceforge.net
Gerrit-Comment-Date: Tue, 31 Mar 2020 09:19:31 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: Julius Werner
jwerner@chromium.org
Gerrit-MessageType: comment