Skip to content

coreboot Redundancy / Intel Boot Guard compatibility / Implementation #1484

@mkopec

Description

@mkopec

Brief description

The redundancy feature shall be compatible with Intel Boot Guard.

Brief description

This task is about ensuring that the provisioning scripts are compatible with top swap-enabled SPI flash images and resolving any incompatibilities.

With the redundancy feature, both bootblocks (normal and top swap) shall contain ACMs and be signed by Boot Guard.
Essentially, the top swap and "real" bootblock in the binary need to be be identical.

The boot guard protected ranges should be set in such a way, that only the currently active bootblock CBFS is covered by protection.

Deliverables

PR to repository containing provisioning scripts

Existing Intel Boot Guard tests should pass

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions