In the kconfig menu you can select "Protect flash regions" or "Flash write protect during lockdown", although I'm not positive which of the runtime features it enables. Which version of coreboot are you building?
I do not know what version of coreboot, probably latest version since I build from source. Could you explain what these two options do? Would this accomplish what I am wanting to do (prevent internal flashing but still allow external flashing)?
Thank you