mirror of
https://github.com/linuxboot/heads.git
synced 2024-12-25 23:51:08 +00:00
0cae2d7805
Add CONFIG_TPM_NO_LUKS_DISK_UNLOCK to allow Librem boards to opt out of using TPM to store LUKS key, and use it to guard the user option to add the disk encryption key to the TPM. Select this option for all Librem boards; all other boards which select CONFIG_TPM=y will have no change in functionality. Signed-off-by: Matt DeVillier <matt.devillier@puri.sm>
41 lines
1.1 KiB
Plaintext
41 lines
1.1 KiB
Plaintext
# Configuration for a librem15v4
|
|
|
|
# The L15v4 Linux config is the same as the L13v2 linux config
|
|
CONFIG_LINUX_CONFIG=config/linux-librem13v2.config
|
|
CONFIG_COREBOOT_CONFIG=config/coreboot-librem15v4.config
|
|
|
|
export CONFIG_COREBOOT=y
|
|
CONFIG_CRYPTSETUP=y
|
|
CONFIG_FLASHROM=y
|
|
CONFIG_FLASHTOOLS=y
|
|
CONFIG_GPG2=y
|
|
CONFIG_KEXEC=y
|
|
CONFIG_UTIL_LINUX=y
|
|
CONFIG_LVM2=y
|
|
CONFIG_MBEDTLS=y
|
|
CONFIG_PCIUTILS=y
|
|
CONFIG_POPT=y
|
|
CONFIG_QRENCODE=y
|
|
CONFIG_TPMTOTP=y
|
|
|
|
#CONFIG_SLANG=y
|
|
#CONFIG_NEWT=y
|
|
CONFIG_CAIRO=y
|
|
CONFIG_FBWHIPTAIL=y
|
|
CONFIG_LIBREMKEY=y
|
|
|
|
CONFIG_LINUX_USB=y
|
|
|
|
export CONFIG_TPM=y
|
|
export CONFIG_TPM_NO_LUKS_DISK_UNLOCK=y
|
|
export CONFIG_BOOTSCRIPT=/bin/gui-init
|
|
export CONFIG_BOOT_REQ_HASH=n
|
|
export CONFIG_BOOT_REQ_ROLLBACK=n
|
|
export CONFIG_BOOT_KERNEL_ADD="intel_iommu=on"
|
|
export CONFIG_BOOT_KERNEL_REMOVE=""
|
|
export CONFIG_BOOT_DEV="/dev/nvme0n1p1"
|
|
export CONFIG_BOOT_GUI_MENU_NAME="Purism Librem 15v4 Heads Boot Menu"
|
|
export CONFIG_WARNING_BG_COLOR="--background-gradient 0 0 0 150 125 0"
|
|
export CONFIG_ERROR_BG_COLOR="--background-gradient 0 0 0 150 0 0"
|
|
export CONFIG_FLASHROM_OPTIONS="-p internal"
|