vboot: Add support for recovery hash space in TPM

Hardware / Coreboot - Furquan Shaikh [chromium.org] - 10 November 2016 11:10 EST

1. Add a new index for recovery hash space in TPM - 0x100b 2. Add helper functions to read/write/lock recovery hash space in TPM 3. Add Kconfig option that can be selected by mainboards that want to define this space. 4. Lock this new space while jumping from RO to RW.

BUG=chrome-os-partner:59355 BRANCH=None TEST=Verified use of recovery hash space on reef.

Change-Id: I1cacd54f0a896d0f2af32d4b7c9ae581a918f9bb

b038f41 vboot: Add support for recovery hash space in TPM
src/include/antirollback.h | 9 ++++
src/vboot/Kconfig | 8 ++++
src/vboot/Makefile.inc | 8 ++++
src/vboot/secdata_mock.c | 5 +++
src/vboot/secdata_tpm.c | 97 ++++++++++++++++++++++++++++++++++++++++++++
src/vboot/vboot_logic.c | 13 ++++++
6 files changed, 140 insertions(+)

Upstream: review.coreboot.org


  • Share