Attention is currently required from: Raul Rangel, Julius Werner, Yu-Ping Wu, Karthik Ramasubramanian.
Kangheui Won has posted comments on this change. ( https://review.coreboot.org/c/coreboot/+/68953 )
Change subject: security/vboot: Update build rules using x86 SHA extension ......................................................................
Patch Set 1:
(1 comment)
File src/security/vboot/Makefile.inc:
https://review.coreboot.org/c/coreboot/+/68953/comment/db5f4a22_a6be9416 PS1, Line 26: ifeq ($(CONFIG_VBOOT_STARTS_BEFORE_BOOTBLOCK),y)
Actually, the help text of `VBOOT_X86_SHA256_ACCELERATION` says `Use sha extension for sha256 hash c […]
With CBFS verification all stages may use the vboot verification functions. The main intention here is to enable `VBOOT_X86_SHA256_ACCELERATION` for other stages but disable it in verstage since psp-verstage runs on ARM PSP.
I don't know much about Kconfig so not sure if we can select different options for different stages, but AMD platforms should able to select `VBOOT_X86_SHA256_ACCELERATION` for other stages but disable it for psp-verstage.