Git Product home page Git Product logo

Comments (5)

stanleyintel avatar stanleyintel commented on June 30, 2024

Hi Sharkblue,

Please check Test ID SPI_07 in RDC# 617151 to know how to get FPT tool work.

from slimbootloader.

sharkblue2009 avatar sharkblue2009 commented on June 30, 2024

Hi Stanley,

From the Debug FSP log, if the SPI flash write protection was sucessful disabled? I just want to make sure.

I am following the instructions from "System Tools - Intel® Converged Security Engine Firmware 15.40 User guide" to run FPT.
I had look through the SPI_07 as you suggested.

by the log, the FPT fails on specific block 5644 when erase, if its conflict with "CSE manufacturing mode"?

ps: "mtdinfo /dev/mtd0" still show the device is "writeable: false"

from slimbootloader.

stanleyintel avatar stanleyintel commented on June 30, 2024

Hi Sharkblue,

You may misunderstand about the SPI flash write protection and FPT.

For SPI Flash Write Protection: Intel does not recommend any customer to disable it. Let me repeat what Maurice mentioned in a related thread first:.

For security concerns, SBL will lock down SPI flash write-protect at the end of Stage2 for normal boot flow.
And as a result, it prevents any SPI write access from OS or application. So flashrom won't work by default.

However, if you fully understand the security risk, or the platform is used in a debug / testing environment, and you want to allow runtime SPI write in OS, it is also possible to disable SPI write protection in SBL. But it is not recommended in production since any malware in OS might be able to write to the flash.

For FPT: FPT (in SPI_07 case) is to check the design of Flash Descriptor Override (per board).

from slimbootloader.

stanleyintel avatar stanleyintel commented on June 30, 2024

For further questions related to FPT, please file an IPS case, because FPT is not released by SBL project and the mix use of FPT with PchLockDownBiosInterface/PchLockDownBiosLock is not a standard use case so you may need some help from CSE team via IPS case.

from slimbootloader.

sharkblue2009 avatar sharkblue2009 commented on June 30, 2024

well, thanks a lot!

from slimbootloader.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.