Julius Werner has posted comments on this change. ( https://review.coreboot.org/c/coreboot/+/32705 )
Change subject: security/lockdown: Write-protect WP_RO
......................................................................
Patch Set 5:
(3 comments)
https://review.coreboot.org/c/coreboot/+/32705/5/src/include/boot_device.h
File src/include/boot_device.h:
https://review.coreboot.org/c/coreboot/+/32705/5/src/include/boot_device.h@7...
PS5, Line 78: Looks
Locks
https://review.coreboot.org/c/coreboot/+/32705/5/src/security/lockdown/Kconf...
File src/security/lockdown/Kconfig:
https://review.coreboot.org/c/coreboot/+/32705/5/src/security/lockdown/Kconf...
PS5, Line 61: chip
nit: should probably say "boot media", not "chip"
https://review.coreboot.org/c/coreboot/+/32705/5/src/security/vboot/verstage...
File src/security/vboot/verstage.c:
https://review.coreboot.org/c/coreboot/+/32705/5/src/security/vboot/verstage...
PS5, Line 35: boot_device_security_lockdown(NULL);
Note that this code is only executed in CONFIG_SEPARATE_VERSTAGE builds. You probably want to put it in verstage_main() instead.
--
To view, visit
https://review.coreboot.org/c/coreboot/+/32705
To unsubscribe, or for help writing mail filters, visit
https://review.coreboot.org/settings
Gerrit-Project: coreboot
Gerrit-Branch: master
Gerrit-Change-Id: I72c3e1a0720514b9b85b0433944ab5fb7109b2a2
Gerrit-Change-Number: 32705
Gerrit-PatchSet: 5
Gerrit-Owner: Patrick Rudolph
patrick.rudolph@9elements.com
Gerrit-Reviewer: Aaron Durbin
adurbin@chromium.org
Gerrit-Reviewer: Christian Walter
christian.walter@9elements.com
Gerrit-Reviewer: Frans Hendriks
fhendriks@eltan.com
Gerrit-Reviewer: Martin Roth
martinroth@google.com
Gerrit-Reviewer: Nico Huber
nico.h@gmx.de
Gerrit-Reviewer: Patrick Georgi
pgeorgi@google.com
Gerrit-Reviewer: Patrick Rudolph
patrick.rudolph@9elements.com
Gerrit-Reviewer: build bot (Jenkins)
no-reply@coreboot.org
Gerrit-CC: Julius Werner
jwerner@chromium.org
Gerrit-CC: Patrick Rudolph
siro@das-labor.org
Gerrit-CC: Paul Menzel
paulepanter@users.sourceforge.net
Gerrit-CC: Philipp Deppenwiese
zaolin.daisuki@gmail.com
Gerrit-Comment-Date: Fri, 16 Aug 2019 23:41:31 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Gerrit-MessageType: comment