summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorFrans Hendriks <fhendriks@eltan.com>2023-04-25 11:43:29 +0200
committerFelix Held <felix-coreboot@felixheld.de>2023-08-09 22:00:33 +0000
commit0648267c1a77d3f3f41547ede3a19a832842cf6e (patch)
tree17d531a24574ef1d051e3af690e871951e69331d
parent472d83bb0af27875f41232ec75e04b082108b0e1 (diff)
mb/facebook/fbg1701: Add config to additional list
´config´ is removed from measure list (CB:74750) Add 'config' to ram_stage_additional_list[] to have it measured and verified. BUG=NA TEST=boot and verify coreboot logs on facebook FBG1701 Change-Id: Id4119bc3a01e11f14a091facf81964d1a71092c1 Signed-off-by: Frans Hendriks <fhendriks@eltan.com> Reviewed-on: https://review.coreboot.org/c/coreboot/+/74752 Tested-by: build bot (Jenkins) <no-reply@coreboot.org> Reviewed-by: Himanshu Sahdev <himanshu.sahdev@intel.com> Reviewed-by: Martin L Roth <gaumless@gmail.com>
-rw-r--r--src/mainboard/facebook/fbg1701/board_verified_boot.c4
-rw-r--r--src/mainboard/facebook/fbg1701/manifest.h3
-rw-r--r--src/vendorcode/eltan/security/verified_boot/Kconfig1
3 files changed, 7 insertions, 1 deletions
diff --git a/src/mainboard/facebook/fbg1701/board_verified_boot.c b/src/mainboard/facebook/fbg1701/board_verified_boot.c
index 8b644cbef1..4932964409 100644
--- a/src/mainboard/facebook/fbg1701/board_verified_boot.c
+++ b/src/mainboard/facebook/fbg1701/board_verified_boot.c
@@ -60,6 +60,10 @@ const verify_item_t postcar_verify_list[] = {
* romstage verify list
*/
static const verify_item_t ram_stage_additional_list[] = {
+#if CONFIG(INCLUDE_CONFIG_FILE)
+ { VERIFY_FILE, "config", { { NULL, CBFS_TYPE_RAW } },
+ HASH_IDX_CONFIG, MBOOT_PCR_INDEX_0 },
+#endif
{ VERIFY_FILE, OP_ROM_VBT, { { NULL, CBFS_TYPE_RAW } },
HASH_IDX_OPROM, MBOOT_PCR_INDEX_2 },
#if CONFIG(BMP_LOGO)
diff --git a/src/mainboard/facebook/fbg1701/manifest.h b/src/mainboard/facebook/fbg1701/manifest.h
index b1043546d9..a89de20f0a 100644
--- a/src/mainboard/facebook/fbg1701/manifest.h
+++ b/src/mainboard/facebook/fbg1701/manifest.h
@@ -18,5 +18,6 @@
#define HASH_IDX_DSDT 8
#define HASH_IDX_POSTCAR_STAGE 9
#define HASH_IDX_PUBLICKEY 10
-#define HASH_IDX_BOOTBLOCK 11 /* Should always be the last one */
+#define HASH_IDX_CONFIG 11
+#define HASH_IDX_BOOTBLOCK 12 /* Should always be the last one */
#endif
diff --git a/src/vendorcode/eltan/security/verified_boot/Kconfig b/src/vendorcode/eltan/security/verified_boot/Kconfig
index 7741782650..50638db5c2 100644
--- a/src/vendorcode/eltan/security/verified_boot/Kconfig
+++ b/src/vendorcode/eltan/security/verified_boot/Kconfig
@@ -33,6 +33,7 @@ config VENDORCODE_ELTAN_VBOOT_MANIFEST
config VENDORCODE_ELTAN_OEM_MANIFEST_ITEMS
int "Manifest Items"
+ default 13 if INCLUDE_CONFIG_FILE
default 12
config VENDORCODE_ELTAN_OEM_MANIFEST_ITEM_SIZE