[coreboot] Patch merged into coreboot/master: 3c53d33 ifdtool: Add locking/unlocking and dumping of access permissions

gerrit at coreboot.org gerrit at coreboot.org
Fri Nov 9 18:59:42 CET 2012


the following patch was just integrated into master:
commit 3c53d33c780f67666e9f8645fd87035d42bfb947
Author: Stefan Reinauer <reinauer at chromium.org>
Date:   Wed Sep 26 17:33:39 2012 -0700

    ifdtool: Add locking/unlocking and dumping of access permissions
    
    ifdtool will now dump access permissions of system comonents to
    certain IFD sections:
    
    Found Master Section
    FLMSTR1:   0xffff0000 (Host CPU/BIOS)
      Platform Data Region Write Access: enabled
      GbE Region Write Access:           enabled
      Intel ME Region Write Access:      enabled
      Host CPU/BIOS Region Write Access: enabled
      Flash Descriptor Write Access:     enabled
      Platform Data Region Read Access:  enabled
      GbE Region Read Access:            enabled
      Intel ME Region Read Access:       enabled
      Host CPU/BIOS Region Read Access:  enabled
      Flash Descriptor Read Access:      enabled
      Requester ID:                      0x0000
    
    FLMSTR2:   0x0c0d0000 (Intel ME)
      Platform Data Region Write Access: disabled
      GbE Region Write Access:           enabled
      Intel ME Region Write Access:      enabled
      Host CPU/BIOS Region Write Access: disabled
      Flash Descriptor Write Access:     disabled
      Platform Data Region Read Access:  disabled
      GbE Region Read Access:            enabled
      Intel ME Region Read Access:       enabled
      Host CPU/BIOS Region Read Access:  disabled
      Flash Descriptor Read Access:      enabled
      Requester ID:                      0x0000
    
    FLMSTR3:   0x08080118 (GbE)
      Platform Data Region Write Access: disabled
      GbE Region Write Access:           enabled
      Intel ME Region Write Access:      disabled
      Host CPU/BIOS Region Write Access: disabled
      Flash Descriptor Write Access:     disabled
      Platform Data Region Read Access:  disabled
      GbE Region Read Access:            enabled
      Intel ME Region Read Access:       disabled
      Host CPU/BIOS Region Read Access:  disabled
      Flash Descriptor Read Access:      disabled
      Requester ID:                      0x0118
    
    Also, ifdtool -u /path/to/image will unlock the host's
    access to the firmware descriptor and ME region.
    ifdtool -l /path/to/image will lock down the host's
    access to the firmware descriptor and ME region.
    
    Change-Id: I3e081b80a9bcb398772416f143b794bf307b1c36
    Signed-off-by: Stefan Reinauer <reinauer at google.com>
    Reviewed-on: http://review.coreboot.org/1755
    Reviewed-by: Ronald G. Minnich <rminnich at gmail.com>
    Tested-by: build bot (Jenkins)

Build-Tested: build bot (Jenkins) at Fri Nov  9 18:17:56 2012, giving +1
See http://review.coreboot.org/1755 for details.

-gerrit




More information about the coreboot mailing list