diff --git a/src/security/vboot/Kconfig b/src/security/vboot/Kconfig index e2a3f20792..8d8e120abb 100644 --- a/src/security/vboot/Kconfig +++ b/src/security/vboot/Kconfig @@ -303,8 +303,12 @@ config GBB_FLAG_FORCE_DEV_BOOT_FASTBOOT_FULL_CAP bool "Allow fastboot even if dev_boot_fastboot_full_cap=0" default n -config GBB_FLAG_ENABLE_SERIAL - bool "Tell vboot to enable serial console" +config GBB_FLAG_FORCE_MANUAL_RECOVERY + bool "Always assume manual recovery in recovery mode" + default n + +config GBB_FLAG_DISABLE_FWMP + bool "Disable Firmware Management Parameters (FWMP)" default n endmenu # GBB diff --git a/src/security/vboot/Makefile.inc b/src/security/vboot/Makefile.inc index 75ecff3b21..53462d9531 100644 --- a/src/security/vboot/Makefile.inc +++ b/src/security/vboot/Makefile.inc @@ -182,7 +182,8 @@ GBB_FLAGS := $(call int-add, \ $(call bool-to-mask,$(CONFIG_GBB_FLAG_DISABLE_PD_SOFTWARE_SYNC),0x800) \ $(call bool-to-mask,$(CONFIG_GBB_FLAG_DISABLE_LID_SHUTDOWN),0x1000) \ $(call bool-to-mask,$(CONFIG_GBB_FLAG_FORCE_DEV_BOOT_FASTBOOT_FULL_CAP),0x2000) \ - $(call bool-to-mask,$(CONFIG_GBB_FLAG_ENABLE_SERIAL),0x4000) \ + $(call bool-to-mask,$(CONFIG_GBB_FLAG_FORCE_MANUAL_RECOVERY),0x4000) \ + $(call bool-to-mask,$(CONFIG_GBB_FLAG_DISABLE_FWMP),0x8000) \ ) ifneq ($(CONFIG_GBB_BMPFV_FILE),)