mirror of
https://github.com/linuxboot/heads.git
synced 2024-12-18 20:47:55 +00:00
codebase: CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE -> CONFIG_FINALIZE_PLATFORM_LOCKING
Signed-off-by: Thierry Laurion <insurgo@riseup.net>
This commit is contained in:
parent
de1ee26fe3
commit
e999c90a16
@ -22,7 +22,7 @@ CONFIG_TPMTOTP=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
# Dependencies for a graphical menu. Enable CONFIG_SLANG and CONFIG_NEWT instead
|
# Dependencies for a graphical menu. Enable CONFIG_SLANG and CONFIG_NEWT instead
|
||||||
|
@ -22,7 +22,7 @@ CONFIG_TPMTOTP=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
# Dependencies for a graphical menu. Enable CONFIG_SLANG and CONFIG_NEWT instead
|
# Dependencies for a graphical menu. Enable CONFIG_SLANG and CONFIG_NEWT instead
|
||||||
|
@ -32,7 +32,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -49,7 +49,7 @@ CONFIG_HOTPKEY=y
|
|||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
# This prevents SPI from being writeable outside of Heads
|
# This prevents SPI from being writeable outside of Heads
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Nitrokey Storage admin tool (deprecated)
|
#Nitrokey Storage admin tool (deprecated)
|
||||||
#CONFIG_NKSTORECLI=n
|
#CONFIG_NKSTORECLI=n
|
||||||
|
@ -49,7 +49,7 @@ CONFIG_TPMTOTP=y
|
|||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
# This prevents SPI from being writeable outside of Heads
|
# This prevents SPI from being writeable outside of Heads
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Nitrokey Storage admin tool (deprecated)
|
#Nitrokey Storage admin tool (deprecated)
|
||||||
#CONFIG_NKSTORECLI=n
|
#CONFIG_NKSTORECLI=n
|
||||||
|
@ -49,7 +49,7 @@ CONFIG_HOTPKEY=y
|
|||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
# This prevents SPI from being writeable outside of Heads
|
# This prevents SPI from being writeable outside of Heads
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Nitrokey Storage admin tool (deprecated)
|
#Nitrokey Storage admin tool (deprecated)
|
||||||
#CONFIG_NKSTORECLI=n
|
#CONFIG_NKSTORECLI=n
|
||||||
|
@ -49,7 +49,7 @@ CONFIG_TPMTOTP=y
|
|||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
# This prevents SPI from being writeable outside of Heads
|
# This prevents SPI from being writeable outside of Heads
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Nitrokey Storage admin tool (deprecated)
|
#Nitrokey Storage admin tool (deprecated)
|
||||||
#CONFIG_NKSTORECLI=n
|
#CONFIG_NKSTORECLI=n
|
||||||
|
@ -32,7 +32,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
#TPM based requirements
|
#TPM based requirements
|
||||||
|
@ -31,7 +31,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
#TPM based requirements
|
#TPM based requirements
|
||||||
|
@ -30,7 +30,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
#TPM based requirements
|
#TPM based requirements
|
||||||
|
@ -30,7 +30,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -31,7 +31,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -31,7 +31,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -31,7 +31,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -31,7 +31,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -32,7 +32,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
#TPM based requirements
|
#TPM based requirements
|
||||||
|
@ -32,7 +32,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
#TPM based requirements
|
#TPM based requirements
|
||||||
|
@ -43,7 +43,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -49,7 +49,7 @@ CONFIG_HOTPKEY=y
|
|||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
# This prevents SPI from being writeable outside of Heads
|
# This prevents SPI from being writeable outside of Heads
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
#Nitrokey Storage admin tool (deprecated)
|
#Nitrokey Storage admin tool (deprecated)
|
||||||
#CONFIG_NKSTORECLI=n
|
#CONFIG_NKSTORECLI=n
|
||||||
|
@ -39,7 +39,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -43,7 +43,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -34,7 +34,7 @@ CONFIG_PCIUTILS=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
|
|
||||||
#Remote attestation support
|
#Remote attestation support
|
||||||
|
@ -43,7 +43,7 @@ CONFIG_TPMTOTP=y
|
|||||||
|
|
||||||
#platform locking finalization (PR0)
|
#platform locking finalization (PR0)
|
||||||
CONFIG_IO386=y
|
CONFIG_IO386=y
|
||||||
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE=y
|
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
|
||||||
|
|
||||||
# Dependencies for a graphical menu. Enable CONFIG_SLANG and CONFIG_NEWT instead
|
# Dependencies for a graphical menu. Enable CONFIG_SLANG and CONFIG_NEWT instead
|
||||||
# for a console-based menu.
|
# for a console-based menu.
|
||||||
|
@ -85,7 +85,7 @@ while true; do
|
|||||||
'Z' " $(get_config_display_action "$CONFIG_DEBUG_OUTPUT") $CONFIG_BRAND_NAME debug and function tracing output"
|
'Z' " $(get_config_display_action "$CONFIG_DEBUG_OUTPUT") $CONFIG_BRAND_NAME debug and function tracing output"
|
||||||
)
|
)
|
||||||
|
|
||||||
[ "$CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE" = "y" ] && dynamic_config_options+=(
|
[ "$CONFIG_FINALIZE_PLATFORM_LOCKING" = "y" ] && dynamic_config_options+=(
|
||||||
't' ' Deactivate Platform Locking to permit OS write access to firmware'
|
't' ' Deactivate Platform Locking to permit OS write access to firmware'
|
||||||
)
|
)
|
||||||
|
|
||||||
@ -105,8 +105,8 @@ while true; do
|
|||||||
|
|
||||||
case "$menu_choice" in
|
case "$menu_choice" in
|
||||||
"t" )
|
"t" )
|
||||||
unset CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE
|
unset CONFIG_FINALIZE_PLATFORM_LOCKING
|
||||||
replace_config /etc/config.user "CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE" "n"
|
replace_config /etc/config.user "CONFIG_FINALIZE_PLATFORM_LOCKING" "n"
|
||||||
combine_configs
|
combine_configs
|
||||||
. /tmp/config
|
. /tmp/config
|
||||||
;;
|
;;
|
||||||
|
@ -170,7 +170,7 @@ if [ "$CONFIG_TPM" = "y" ]; then
|
|||||||
tpmr kexec_finalize
|
tpmr kexec_finalize
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [ -x /bin/io386 -a "$CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE" = "y" ]; then
|
if [ -x /bin/io386 -a "$CONFIG_FINALIZE_PLATFORM_LOCKING" = "y" ]; then
|
||||||
lock_chip
|
lock_chip
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
@ -9,7 +9,7 @@
|
|||||||
. /etc/ash_functions
|
. /etc/ash_functions
|
||||||
|
|
||||||
TRACE "Under /bin/lock_chip"
|
TRACE "Under /bin/lock_chip"
|
||||||
if [ "$CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE" = "y" ]; then
|
if [ "$CONFIG_FINALIZE_PLATFORM_LOCKING" = "y" ]; then
|
||||||
APM_CNT=0xb2
|
APM_CNT=0xb2
|
||||||
FIN_CODE=0xcb
|
FIN_CODE=0xcb
|
||||||
fi
|
fi
|
||||||
|
Loading…
Reference in New Issue
Block a user