Benjamin Doron has posted comments on this change. ( https://review.coreboot.org/c/coreboot/+/40830 )
Change subject: [WIP]security/intel: Add option to eanble SMM flash access only
......................................................................
Patch Set 1:
(1 comment)
https://review.coreboot.org/c/coreboot/+/40830/1/src/security/lockdown/Kconf...
File src/security/lockdown/Kconfig:
https://review.coreboot.org/c/coreboot/+/40830/1/src/security/lockdown/Kconf...
PS1, Line 103: BOOTMEDIA_SMM_BWP
The SMM_BWP bit is not being set, which may be necessary as per https://www.kb.cert. […]
My mistake, SMM_BWP is the EISS bit ("Enable InSMM.STS").
--
To view, visit
https://review.coreboot.org/c/coreboot/+/40830
To unsubscribe, or for help writing mail filters, visit
https://review.coreboot.org/settings
Gerrit-Project: coreboot
Gerrit-Branch: master
Gerrit-Change-Id: I157db885b5f1d0f74009ede6fb2342b20d9429fa
Gerrit-Change-Number: 40830
Gerrit-PatchSet: 1
Gerrit-Owner: Patrick Rudolph
patrick.rudolph@9elements.com
Gerrit-Reviewer: Patrick Rudolph
siro@das-labor.org
Gerrit-Reviewer: build bot (Jenkins)
no-reply@coreboot.org
Gerrit-CC: Benjamin Doron
benjamin.doron00@gmail.com
Gerrit-Comment-Date: Mon, 15 Jun 2020 16:53:49 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: Benjamin Doron
benjamin.doron00@gmail.com
Gerrit-MessageType: comment