MCPcopy Create free account
hub / github.com/coreboot/coreboot / ec_protect_flash

Function ec_protect_flash

src/security/vboot/ec_sync.c:189–224  ·  view source on GitHub ↗

* Asks the EC to protect or unprotect the specified flash region. */

Source from the content-addressed store, hash-verified

187 * Asks the EC to protect or unprotect the specified flash region.
188 */
189static vb2_error_t ec_protect_flash(int enable)
190{
191 struct ec_response_flash_protect resp;
192 uint32_t protected_region = EC_FLASH_PROTECT_ALL_NOW;
193 const uint32_t mask = EC_FLASH_PROTECT_ALL_NOW | EC_FLASH_PROTECT_ALL_AT_BOOT;
194
195 if (google_chromeec_flash_protect(mask, enable ? mask : 0, &resp) != 0)
196 return VB2_ERROR_UNKNOWN;
197
198 if (!enable) {
199 /* If protection is still enabled, need reboot */
200 if (resp.flags & protected_region)
201 return VB2_REQUEST_REBOOT_EC_TO_RO;
202
203 return VB2_SUCCESS;
204 }
205
206 /*
207 * If write protect and ro-at-boot aren't both asserted, don't expect
208 * protection enabled.
209 */
210 if ((~resp.flags) & (EC_FLASH_PROTECT_GPIO_ASSERTED |
211 EC_FLASH_PROTECT_RO_AT_BOOT))
212 return VB2_SUCCESS;
213
214 /* If flash is protected now, success */
215 if (resp.flags & EC_FLASH_PROTECT_ALL_NOW)
216 return VB2_SUCCESS;
217
218 /* If RW will be protected at boot but not now, need a reboot */
219 if (resp.flags & EC_FLASH_PROTECT_ALL_AT_BOOT)
220 return VB2_REQUEST_REBOOT_EC_TO_RO;
221
222 /* Otherwise, it's an error */
223 return VB2_ERROR_UNKNOWN;
224}
225
226/* Convert a firmware image type to an EC flash region */
227static enum ec_flash_region vboot_to_ec_region(enum vb2_firmware_selection select)

Callers 2

ec_update_imageFunction · 0.85
vb2ex_ec_protectFunction · 0.85

Calls 1

Tested by

no test coverage detected