Kconfig.cbfs_verification: Update TOCTOU_SAFETY combination with VBOOT
Now that VBOOT_CBFS_INTEGRATION exists, it is possible to use TOCTOU_SAFETY with VBOOT. Change-Id: I9f84574f611ec397060404c61e71312009d92ba7 Signed-off-by: Julius Werner <jwerner@chromium.org> Reviewed-on: https://review.coreboot.org/c/coreboot/+/78915 Reviewed-by: Yu-Ping Wu <yupingso@google.com> Tested-by: build bot (Jenkins) <no-reply@coreboot.org> Reviewed-by: Arthur Heymans <arthur@aheymans.xyz>
This commit is contained in:
parent
ca71588620
commit
c7120e38e7
|
@ -25,7 +25,7 @@ config TOCTOU_SAFETY
|
|||
depends on !NO_FMAP_CACHE
|
||||
depends on !NO_CBFS_MCACHE
|
||||
depends on !USE_OPTION_TABLE && !FSP_CAR # Known to access CBFS before CBMEM init
|
||||
depends on !VBOOT # TODO: can only allow this once vboot fully integrated
|
||||
depends on !VBOOT || VBOOT_CBFS_INTEGRATION
|
||||
depends on NO_XIP_EARLY_STAGES
|
||||
help
|
||||
Say yes here to eliminate time-of-check vs. time-of-use vulnerabilities
|
||||
|
|
Loading…
Reference in New Issue