summaryrefslogtreecommitdiffstats
path: root/src/security/memory
diff options
context:
space:
mode:
Diffstat (limited to 'src/security/memory')
-rw-r--r--src/security/memory/Kconfig34
-rw-r--r--src/security/memory/Makefile.inc3
-rw-r--r--src/security/memory/memory.c33
-rw-r--r--src/security/memory/memory.h19
4 files changed, 89 insertions, 0 deletions
diff --git a/src/security/memory/Kconfig b/src/security/memory/Kconfig
new file mode 100644
index 000000000000..5436119ba5b7
--- /dev/null
+++ b/src/security/memory/Kconfig
@@ -0,0 +1,34 @@
+## This file is part of the coreboot project.
+##
+## Copyright (C) 2019 Facebook Inc.
+## Copyright (C) 2019 9elements Agency GmbH
+##
+## This program is free software; you can redistribute it and/or modify
+## it under the terms of the GNU General Public License as published by
+## the Free Software Foundation; version 2 of the License.
+##
+## This program is distributed in the hope that it will be useful,
+## but WITHOUT ANY WARRANTY; without even the implied warranty of
+## MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+## GNU General Public License for more details.
+##
+
+menu "Memory initialization"
+
+config PLATFORM_HAS_DRAM_CLEAR
+ bool
+ default n
+ help
+ Selected by platforms that support clearing all DRAM
+ after DRAM initialization.
+
+config SECURITY_CLEAR_DRAM_ON_REGULAR_BOOT
+ depends on PLATFORM_HAS_DRAM_CLEAR
+ bool "Always clear all DRAM on regular boot"
+ help
+ Always clear the DRAM after DRAM initialization regardless
+ of additional security implementations in use.
+ This increases boot time depending on the amount of DRAM
+ installed.
+
+endmenu #Memory initialization
diff --git a/src/security/memory/Makefile.inc b/src/security/memory/Makefile.inc
new file mode 100644
index 000000000000..525c4dbb4de5
--- /dev/null
+++ b/src/security/memory/Makefile.inc
@@ -0,0 +1,3 @@
+romstage-$(CONFIG_PLATFORM_HAS_DRAM_CLEAR) += memory.c
+postcar-$(CONFIG_PLATFORM_HAS_DRAM_CLEAR) += memory.c
+ramstage-$(CONFIG_PLATFORM_HAS_DRAM_CLEAR) += memory.c
diff --git a/src/security/memory/memory.c b/src/security/memory/memory.c
new file mode 100644
index 000000000000..14f28578b5ee
--- /dev/null
+++ b/src/security/memory/memory.c
@@ -0,0 +1,33 @@
+/*
+ * This file is part of the coreboot project.
+ *
+ * Copyright (C) 2019 9elements Agency GmbH
+ * Copyright (C) 2019 Facebook Inc.
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; version 2 of the License.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ */
+
+#include <stdint.h>
+#include "memory.h"
+
+/**
+ * To be called after DRAM init.
+ * Tells the caller if DRAM must be cleared as requested by the user,
+ * firmware or security framework.
+ */
+bool security_clear_dram_request(void)
+{
+ if (CONFIG(SECURITY_CLEAR_DRAM_ON_REGULAR_BOOT))
+ return true;
+
+ /* TODO: Add TEE environments here */
+
+ return false;
+}
diff --git a/src/security/memory/memory.h b/src/security/memory/memory.h
new file mode 100644
index 000000000000..ccb07d76adba
--- /dev/null
+++ b/src/security/memory/memory.h
@@ -0,0 +1,19 @@
+/*
+ * This file is part of the coreboot project.
+ *
+ * Copyright (C) 2019 9elements Agency GmbH
+ * Copyright (C) 2019 Facebook Inc.
+ *
+ * This program is free software; you can redistribute it and/or modify
+ * it under the terms of the GNU General Public License as published by
+ * the Free Software Foundation; version 2 of the License.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU General Public License for more details.
+ */
+
+#include <stdint.h>
+
+bool security_clear_dram_request(void);