Wim Vervoorn has posted comments on this change. ( https://review.coreboot.org/c/coreboot/+/36504 )
Change subject: mb/facebook/fbg1701: Add public key to bootblock_verify_list ......................................................................
Patch Set 7:
(1 comment)
https://review.coreboot.org/c/coreboot/+/36504/5/src/mainboard/facebook/fbg1... File src/mainboard/facebook/fbg1701/board_verified_boot.c:
https://review.coreboot.org/c/coreboot/+/36504/5/src/mainboard/facebook/fbg1... PS5, Line 19: the bootblock will not measure the : * items to the TPM
This seems to contradict the commit message that the key ends up in PCR0, or is the same structure u […]
You are absolutely right, the PCR remark in the commit message is amistake. The PCR item in the boot_block_verify list is just a dummy and is not used as indicated in the comments. I update the commit message.