Brief description
The redundancy feature shall be compatible with Intel Boot Guard.
Brief description
This task is about ensuring that the provisioning scripts are compatible with top swap-enabled SPI flash images and resolving any incompatibilities.
With the redundancy feature, both bootblocks (normal and top swap) shall contain ACMs and be signed by Boot Guard.
Essentially, the top swap and "real" bootblock in the binary need to be be identical.
The boot guard protected ranges should be set in such a way, that only the currently active bootblock CBFS is covered by protection.
Deliverables
PR to repository containing provisioning scripts
Existing Intel Boot Guard tests should pass