Alexander Graf | ed980b8 | 2016-03-04 01:10:07 +0100 | [diff] [blame] | 1 | config EFI_LOADER |
Heinrich Schuchardt | 9363fd2 | 2019-05-11 10:27:58 +0200 | [diff] [blame] | 2 | bool "Support running UEFI applications" |
Heinrich Schuchardt | b20bb09 | 2019-11-17 10:44:16 +0100 | [diff] [blame] | 3 | depends on OF_LIBFDT && ( \ |
Heinrich Schuchardt | 38064ee | 2019-11-19 04:19:09 +0100 | [diff] [blame] | 4 | ARM && (SYS_CPU = arm1136 || \ |
| 5 | SYS_CPU = arm1176 || \ |
| 6 | SYS_CPU = armv7 || \ |
| 7 | SYS_CPU = armv8) || \ |
Heinrich Schuchardt | b20bb09 | 2019-11-17 10:44:16 +0100 | [diff] [blame] | 8 | X86 || RISCV || SANDBOX) |
Alexander Graf | 6698bb3 | 2018-01-24 14:54:21 +0100 | [diff] [blame] | 9 | # We need EFI_STUB_64BIT to be set on x86_64 with EFI_STUB |
| 10 | depends on !EFI_STUB || !X86_64 || EFI_STUB_64BIT |
| 11 | # We need EFI_STUB_32BIT to be set on x86_32 with EFI_STUB |
| 12 | depends on !EFI_STUB || !X86 || X86_64 || EFI_STUB_32BIT |
Heinrich Schuchardt | 6919619 | 2021-09-07 08:56:47 +0200 | [diff] [blame] | 13 | depends on BLK |
Simon Glass | c779e0d | 2021-09-24 18:30:17 -0600 | [diff] [blame] | 14 | depends on DM_ETH || !NET |
Simon Glass | e16c47f | 2021-11-03 21:09:07 -0600 | [diff] [blame] | 15 | depends on !EFI_APP |
Heinrich Schuchardt | b7cdecf | 2019-11-20 18:48:02 +0100 | [diff] [blame] | 16 | default y if !ARM || SYS_CPU = armv7 || SYS_CPU = armv8 |
Heinrich Schuchardt | d30924f | 2022-05-02 06:27:00 +0200 | [diff] [blame] | 17 | select CHARSET |
AKASHI Takahiro | a9bf024 | 2022-04-19 10:05:12 +0900 | [diff] [blame] | 18 | select DM_EVENT |
Jan Kiszka | 6ae4948 | 2022-04-27 07:47:15 +0200 | [diff] [blame] | 19 | select EVENT |
AKASHI Takahiro | a9bf024 | 2022-04-19 10:05:12 +0900 | [diff] [blame] | 20 | select EVENT_DYNAMIC |
Adam Ford | a451bc2 | 2018-02-06 12:14:28 -0600 | [diff] [blame] | 21 | select LIB_UUID |
AKASHI Takahiro | 7a06fd7 | 2022-04-19 10:01:56 +0900 | [diff] [blame] | 22 | imply PARTITION_UUIDS |
Adam Ford | 1811a92 | 2018-02-06 12:43:56 -0600 | [diff] [blame] | 23 | select HAVE_BLOCK_DEVICE |
Heinrich Schuchardt | dba5148 | 2019-01-22 21:35:23 +0100 | [diff] [blame] | 24 | select REGEX |
Heinrich Schuchardt | 93f6201 | 2020-03-21 20:45:50 +0100 | [diff] [blame] | 25 | imply FAT |
| 26 | imply FAT_WRITE |
Heinrich Schuchardt | 8876e1b | 2019-12-04 22:58:58 +0100 | [diff] [blame] | 27 | imply USB_KEYBOARD_FN_KEYS |
Heinrich Schuchardt | faadc04 | 2020-01-15 00:49:35 +0100 | [diff] [blame] | 28 | imply VIDEO_ANSI |
Alexander Graf | ed980b8 | 2016-03-04 01:10:07 +0100 | [diff] [blame] | 29 | help |
Heinrich Schuchardt | 9363fd2 | 2019-05-11 10:27:58 +0200 | [diff] [blame] | 30 | Select this option if you want to run UEFI applications (like GNU |
| 31 | GRUB or iPXE) on top of U-Boot. If this option is enabled, U-Boot |
| 32 | will expose the UEFI API to a loaded application, enabling it to |
| 33 | reuse U-Boot's device drivers. |
Alexander Graf | 51735ae | 2016-05-11 18:25:48 +0200 | [diff] [blame] | 34 | |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 35 | if EFI_LOADER |
Alexander Graf | 5fbb289 | 2019-02-11 15:24:00 +0100 | [diff] [blame] | 36 | |
Heinrich Schuchardt | ff2f532 | 2021-01-15 19:02:50 +0100 | [diff] [blame] | 37 | config CMD_BOOTEFI_BOOTMGR |
| 38 | bool "UEFI Boot Manager" |
| 39 | default y |
| 40 | help |
| 41 | Select this option if you want to select the UEFI binary to be booted |
| 42 | via UEFI variables Boot####, BootOrder, and BootNext. This enables the |
| 43 | 'bootefi bootmgr' command. |
| 44 | |
AKASHI Takahiro | c57c943 | 2020-10-29 13:47:45 +0900 | [diff] [blame] | 45 | config EFI_SETUP_EARLY |
| 46 | bool |
AKASHI Takahiro | a9bf024 | 2022-04-19 10:05:12 +0900 | [diff] [blame] | 47 | default y |
AKASHI Takahiro | c57c943 | 2020-10-29 13:47:45 +0900 | [diff] [blame] | 48 | |
Heinrich Schuchardt | be66b89 | 2020-07-14 19:18:33 +0200 | [diff] [blame] | 49 | choice |
| 50 | prompt "Store for non-volatile UEFI variables" |
| 51 | default EFI_VARIABLE_FILE_STORE |
| 52 | help |
| 53 | Select where non-volatile UEFI variables shall be stored. |
| 54 | |
Heinrich Schuchardt | 5f7dcf0 | 2020-03-19 18:21:58 +0000 | [diff] [blame] | 55 | config EFI_VARIABLE_FILE_STORE |
| 56 | bool "Store non-volatile UEFI variables as file" |
| 57 | depends on FAT_WRITE |
Heinrich Schuchardt | 5f7dcf0 | 2020-03-19 18:21:58 +0000 | [diff] [blame] | 58 | help |
Heinrich Schuchardt | be66b89 | 2020-07-14 19:18:33 +0200 | [diff] [blame] | 59 | Select this option if you want non-volatile UEFI variables to be |
| 60 | stored as file /ubootefi.var on the EFI system partition. |
| 61 | |
| 62 | config EFI_MM_COMM_TEE |
| 63 | bool "UEFI variables storage service via OP-TEE" |
| 64 | depends on OPTEE |
| 65 | help |
| 66 | If OP-TEE is present and running StandAloneMM, dispatch all UEFI |
| 67 | variable related operations to that. The application will verify, |
| 68 | authenticate and store the variables on an RPMB. |
| 69 | |
Tom Saeger | f2288a2 | 2022-03-22 15:21:10 -0600 | [diff] [blame] | 70 | config EFI_VARIABLE_NO_STORE |
| 71 | bool "Don't persist non-volatile UEFI variables" |
| 72 | help |
| 73 | If you choose this option, non-volatile variables cannot be persisted. |
| 74 | You could still provide non-volatile variables via |
| 75 | EFI_VARIABLES_PRESEED. |
| 76 | |
Heinrich Schuchardt | be66b89 | 2020-07-14 19:18:33 +0200 | [diff] [blame] | 77 | endchoice |
Heinrich Schuchardt | 5f7dcf0 | 2020-03-19 18:21:58 +0000 | [diff] [blame] | 78 | |
Heinrich Schuchardt | 7dda163 | 2020-07-14 21:25:28 +0200 | [diff] [blame] | 79 | config EFI_VARIABLES_PRESEED |
| 80 | bool "Initial values for UEFI variables" |
Tom Saeger | f2288a2 | 2022-03-22 15:21:10 -0600 | [diff] [blame] | 81 | depends on !EFI_MM_COMM_TEE |
Heinrich Schuchardt | 7dda163 | 2020-07-14 21:25:28 +0200 | [diff] [blame] | 82 | help |
| 83 | Include a file with the initial values for non-volatile UEFI variables |
| 84 | into the U-Boot binary. If this configuration option is set, changes |
| 85 | to authentication related variables (PK, KEK, db, dbx) are not |
| 86 | allowed. |
| 87 | |
| 88 | if EFI_VARIABLES_PRESEED |
| 89 | |
| 90 | config EFI_VAR_SEED_FILE |
| 91 | string "File with initial values of non-volatile UEFI variables" |
| 92 | default ubootefi.var |
| 93 | help |
| 94 | File with initial values of non-volatile UEFI variables. The file must |
| 95 | be in the same format as the storage in the EFI system partition. The |
| 96 | easiest way to create it is by setting the non-volatile variables in |
| 97 | U-Boot. If a relative file path is used, it is relative to the source |
| 98 | directory. |
| 99 | |
| 100 | endif |
| 101 | |
Heinrich Schuchardt | c0c21d6 | 2020-12-20 11:05:38 +0100 | [diff] [blame] | 102 | config EFI_VAR_BUF_SIZE |
| 103 | int "Memory size of the UEFI variable store" |
| 104 | default 16384 |
| 105 | range 4096 2147483647 |
| 106 | help |
| 107 | This defines the size in bytes of the memory area reserved for keeping |
| 108 | UEFI variables. |
| 109 | |
| 110 | When using StandAloneMM (CONFIG_EFI_MM_COMM_TEE=y) this value should |
| 111 | match the value of PcdFlashNvStorageVariableSize used to compile the |
| 112 | StandAloneMM module. |
| 113 | |
| 114 | Minimum 4096, default 16384. |
| 115 | |
Heinrich Schuchardt | 5ec48e3 | 2019-05-31 22:56:02 +0200 | [diff] [blame] | 116 | config EFI_GET_TIME |
| 117 | bool "GetTime() runtime service" |
| 118 | depends on DM_RTC |
| 119 | default y |
| 120 | help |
| 121 | Provide the GetTime() runtime service at boottime. This service |
| 122 | can be used by an EFI application to read the real time clock. |
| 123 | |
| 124 | config EFI_SET_TIME |
| 125 | bool "SetTime() runtime service" |
| 126 | depends on EFI_GET_TIME |
Heinrich Schuchardt | 31cadc3 | 2020-11-21 20:52:18 +0100 | [diff] [blame] | 127 | default y if ARCH_QEMU || SANDBOX |
Heinrich Schuchardt | 5ec48e3 | 2019-05-31 22:56:02 +0200 | [diff] [blame] | 128 | help |
| 129 | Provide the SetTime() runtime service at boottime. This service |
| 130 | can be used by an EFI application to adjust the real time clock. |
| 131 | |
AKASHI Takahiro | 2bc27ca | 2020-11-17 09:27:55 +0900 | [diff] [blame] | 132 | config EFI_HAVE_CAPSULE_SUPPORT |
| 133 | bool |
| 134 | |
| 135 | config EFI_RUNTIME_UPDATE_CAPSULE |
| 136 | bool "UpdateCapsule() runtime service" |
AKASHI Takahiro | 2bc27ca | 2020-11-17 09:27:55 +0900 | [diff] [blame] | 137 | select EFI_HAVE_CAPSULE_SUPPORT |
| 138 | help |
| 139 | Select this option if you want to use UpdateCapsule and |
| 140 | QueryCapsuleCapabilities API's. |
| 141 | |
AKASHI Takahiro | c74cd8b | 2020-11-17 09:27:56 +0900 | [diff] [blame] | 142 | config EFI_CAPSULE_ON_DISK |
| 143 | bool "Enable capsule-on-disk support" |
Masami Hiramatsu | 7660cfe | 2022-03-21 22:37:56 +0900 | [diff] [blame] | 144 | depends on SYSRESET |
AKASHI Takahiro | c74cd8b | 2020-11-17 09:27:56 +0900 | [diff] [blame] | 145 | select EFI_HAVE_CAPSULE_SUPPORT |
AKASHI Takahiro | c74cd8b | 2020-11-17 09:27:56 +0900 | [diff] [blame] | 146 | help |
| 147 | Select this option if you want to use capsule-on-disk feature, |
| 148 | that is, capsules can be fetched and executed from files |
| 149 | under a specific directory on UEFI system partition instead of |
| 150 | via UpdateCapsule API. |
| 151 | |
Ilias Apalodimas | 0fa5020 | 2021-06-29 07:55:51 +0300 | [diff] [blame] | 152 | config EFI_IGNORE_OSINDICATIONS |
| 153 | bool "Ignore OsIndications for CapsuleUpdate on-disk" |
| 154 | depends on EFI_CAPSULE_ON_DISK |
Ilias Apalodimas | 0fa5020 | 2021-06-29 07:55:51 +0300 | [diff] [blame] | 155 | help |
| 156 | There are boards where U-Boot does not support SetVariable at runtime. |
| 157 | Select this option if you want to use the capsule-on-disk feature |
| 158 | without setting the EFI_OS_INDICATIONS_FILE_CAPSULE_DELIVERY_SUPPORTED |
| 159 | flag in variable OsIndications. |
| 160 | |
AKASHI Takahiro | c74cd8b | 2020-11-17 09:27:56 +0900 | [diff] [blame] | 161 | config EFI_CAPSULE_ON_DISK_EARLY |
| 162 | bool "Initiate capsule-on-disk at U-Boot boottime" |
| 163 | depends on EFI_CAPSULE_ON_DISK |
AKASHI Takahiro | c74cd8b | 2020-11-17 09:27:56 +0900 | [diff] [blame] | 164 | select EFI_SETUP_EARLY |
| 165 | help |
| 166 | Normally, without this option enabled, capsules will be |
| 167 | executed only at the first time of invoking one of efi command. |
| 168 | If this option is enabled, capsules will be enforced to be |
| 169 | executed as part of U-Boot initialisation so that they will |
| 170 | surely take place whatever is set to distro_bootcmd. |
| 171 | |
AKASHI Takahiro | bb7e71d | 2020-11-17 09:28:00 +0900 | [diff] [blame] | 172 | config EFI_CAPSULE_FIRMWARE |
| 173 | bool |
AKASHI Takahiro | bb7e71d | 2020-11-17 09:28:00 +0900 | [diff] [blame] | 174 | |
AKASHI Takahiro | 8d99026 | 2020-11-30 18:12:11 +0900 | [diff] [blame] | 175 | config EFI_CAPSULE_FIRMWARE_MANAGEMENT |
| 176 | bool "Capsule: Firmware Management Protocol" |
| 177 | depends on EFI_HAVE_CAPSULE_SUPPORT |
| 178 | default y |
| 179 | help |
| 180 | Select this option if you want to enable capsule-based |
| 181 | firmware update using Firmware Management Protocol. |
| 182 | |
Ilias Apalodimas | b891ff1 | 2021-06-22 17:38:52 +0300 | [diff] [blame] | 183 | config EFI_CAPSULE_FIRMWARE_FIT |
| 184 | bool "FMP driver for FIT images" |
| 185 | depends on FIT |
| 186 | depends on EFI_CAPSULE_FIRMWARE_MANAGEMENT |
| 187 | select UPDATE_FIT |
| 188 | select DFU |
Sughosh Ganu | a9e6f01 | 2022-04-15 11:29:37 +0530 | [diff] [blame] | 189 | select SET_DFU_ALT_INFO |
Ilias Apalodimas | b891ff1 | 2021-06-22 17:38:52 +0300 | [diff] [blame] | 190 | select EFI_CAPSULE_FIRMWARE |
| 191 | help |
| 192 | Select this option if you want to enable firmware management protocol |
| 193 | driver for FIT image |
| 194 | |
| 195 | config EFI_CAPSULE_FIRMWARE_RAW |
| 196 | bool "FMP driver for raw images" |
| 197 | depends on EFI_CAPSULE_FIRMWARE_MANAGEMENT |
| 198 | depends on SANDBOX || (!SANDBOX && !EFI_CAPSULE_FIRMWARE_FIT) |
| 199 | select DFU_WRITE_ALT |
| 200 | select DFU |
Sughosh Ganu | a9e6f01 | 2022-04-15 11:29:37 +0530 | [diff] [blame] | 201 | select SET_DFU_ALT_INFO |
Ilias Apalodimas | b891ff1 | 2021-06-22 17:38:52 +0300 | [diff] [blame] | 202 | select EFI_CAPSULE_FIRMWARE |
| 203 | help |
| 204 | Select this option if you want to enable firmware management protocol |
| 205 | driver for raw image |
| 206 | |
Sughosh Ganu | 04be98b | 2020-12-30 19:27:09 +0530 | [diff] [blame] | 207 | config EFI_CAPSULE_AUTHENTICATE |
| 208 | bool "Update Capsule authentication" |
| 209 | depends on EFI_CAPSULE_FIRMWARE |
| 210 | depends on EFI_CAPSULE_ON_DISK |
| 211 | depends on EFI_CAPSULE_FIRMWARE_MANAGEMENT |
Alexandru Gagniuc | 464010b | 2021-05-24 14:28:57 -0500 | [diff] [blame] | 212 | select HASH |
Sughosh Ganu | 04be98b | 2020-12-30 19:27:09 +0530 | [diff] [blame] | 213 | select SHA256 |
| 214 | select RSA |
| 215 | select RSA_VERIFY |
| 216 | select RSA_VERIFY_WITH_PKEY |
| 217 | select X509_CERTIFICATE_PARSER |
| 218 | select PKCS7_MESSAGE_PARSER |
| 219 | select PKCS7_VERIFY |
Sughosh Ganu | dd40cf6 | 2021-04-07 17:23:31 +0530 | [diff] [blame] | 220 | select IMAGE_SIGN_INFO |
Masahisa Kojima | f6081a8 | 2021-05-14 09:53:36 +0900 | [diff] [blame] | 221 | select EFI_SIGNATURE_SUPPORT |
Sughosh Ganu | 04be98b | 2020-12-30 19:27:09 +0530 | [diff] [blame] | 222 | help |
| 223 | Select this option if you want to enable capsule |
| 224 | authentication |
| 225 | |
Heinrich Schuchardt | 64b5ba4 | 2019-05-11 09:53:33 +0200 | [diff] [blame] | 226 | config EFI_DEVICE_PATH_TO_TEXT |
| 227 | bool "Device path to text protocol" |
| 228 | default y |
| 229 | help |
| 230 | The device path to text protocol converts device nodes and paths to |
| 231 | human readable strings. |
| 232 | |
Heinrich Schuchardt | 59593a5 | 2021-01-16 09:44:25 +0100 | [diff] [blame] | 233 | config EFI_DEVICE_PATH_UTIL |
| 234 | bool "Device path utilities protocol" |
| 235 | default y |
| 236 | help |
| 237 | The device path utilities protocol creates and manipulates device |
| 238 | paths and device nodes. It is required to run the EFI Shell. |
| 239 | |
Heinrich Schuchardt | 4cb07d8 | 2021-01-16 09:33:24 +0100 | [diff] [blame] | 240 | config EFI_DT_FIXUP |
| 241 | bool "Device tree fixup protocol" |
| 242 | depends on !GENERATE_ACPI_TABLE |
| 243 | default y |
| 244 | help |
| 245 | The EFI device-tree fix-up protocol provides a function to let the |
| 246 | firmware apply fix-ups. This may be used by boot loaders. |
| 247 | |
Alexander Graf | 5fbb289 | 2019-02-11 15:24:00 +0100 | [diff] [blame] | 248 | config EFI_LOADER_HII |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 249 | bool "HII protocols" |
Heinrich Schuchardt | 084f093 | 2019-04-07 23:58:50 +0200 | [diff] [blame] | 250 | default y |
Alexander Graf | 5fbb289 | 2019-02-11 15:24:00 +0100 | [diff] [blame] | 251 | help |
| 252 | The Human Interface Infrastructure is a complicated framework that |
| 253 | allows UEFI applications to draw fancy menus and hook strings using |
| 254 | a translation framework. |
| 255 | |
| 256 | U-Boot implements enough of its features to be able to run the UEFI |
Heinrich Schuchardt | 084f093 | 2019-04-07 23:58:50 +0200 | [diff] [blame] | 257 | Shell, but not more than that. |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 258 | |
Heinrich Schuchardt | 95ab381 | 2019-05-16 07:52:58 +0200 | [diff] [blame] | 259 | config EFI_UNICODE_COLLATION_PROTOCOL2 |
Heinrich Schuchardt | 3349973 | 2019-05-08 23:24:26 +0200 | [diff] [blame] | 260 | bool "Unicode collation protocol" |
| 261 | default y |
| 262 | help |
| 263 | The Unicode collation protocol is used for lexical comparisons. It is |
| 264 | required to run the UEFI shell. |
| 265 | |
Heinrich Schuchardt | 95ab381 | 2019-05-16 07:52:58 +0200 | [diff] [blame] | 266 | if EFI_UNICODE_COLLATION_PROTOCOL2 |
Heinrich Schuchardt | 3349973 | 2019-05-08 23:24:26 +0200 | [diff] [blame] | 267 | |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 268 | config EFI_UNICODE_CAPITALIZATION |
| 269 | bool "Support Unicode capitalization" |
| 270 | default y |
| 271 | help |
| 272 | Select this option to enable correct handling of the capitalization of |
| 273 | Unicode codepoints in the range 0x0000-0xffff. If this option is not |
| 274 | set, only the the correct handling of the letters of the codepage |
| 275 | used by the FAT file system is ensured. |
| 276 | |
Heinrich Schuchardt | 3349973 | 2019-05-08 23:24:26 +0200 | [diff] [blame] | 277 | endif |
| 278 | |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 279 | config EFI_LOADER_BOUNCE_BUFFER |
| 280 | bool "EFI Applications use bounce buffers for DMA operations" |
| 281 | depends on ARM64 |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 282 | help |
| 283 | Some hardware does not support DMA to full 64bit addresses. For this |
| 284 | hardware we can create a bounce buffer so that payloads don't have to |
| 285 | worry about platform details. |
| 286 | |
| 287 | config EFI_PLATFORM_LANG_CODES |
| 288 | string "Language codes supported by firmware" |
| 289 | default "en-US" |
| 290 | help |
| 291 | This value is used to initialize the PlatformLangCodes variable. Its |
| 292 | value is a semicolon (;) separated list of language codes in native |
| 293 | RFC 4646 format, e.g. "en-US;de-DE". The first language code is used |
| 294 | to initialize the PlatformLang variable. |
| 295 | |
Heinrich Schuchardt | 953661a | 2019-07-05 18:12:16 +0200 | [diff] [blame] | 296 | config EFI_HAVE_RUNTIME_RESET |
| 297 | # bool "Reset runtime service is available" |
| 298 | bool |
| 299 | default y |
Heinrich Schuchardt | 9c54729 | 2020-12-02 16:22:11 +0100 | [diff] [blame] | 300 | depends on ARCH_BCM283X || FSL_LAYERSCAPE || PSCI_RESET || \ |
| 301 | SANDBOX || SYSRESET_X86 |
Heinrich Schuchardt | 953661a | 2019-07-05 18:12:16 +0200 | [diff] [blame] | 302 | |
Heinrich Schuchardt | 6f3badb | 2019-07-22 22:04:36 +0200 | [diff] [blame] | 303 | config EFI_GRUB_ARM32_WORKAROUND |
| 304 | bool "Workaround for GRUB on 32bit ARM" |
Heinrich Schuchardt | 4bad14a | 2021-03-03 14:05:05 +0100 | [diff] [blame] | 305 | default n if ARCH_BCM283X || ARCH_SUNXI || ARCH_QEMU |
Heinrich Schuchardt | 6f3badb | 2019-07-22 22:04:36 +0200 | [diff] [blame] | 306 | default y |
| 307 | depends on ARM && !ARM64 |
| 308 | help |
| 309 | GRUB prior to version 2.04 requires U-Boot to disable caches. This |
| 310 | workaround currently is also needed on systems with caches that |
| 311 | cannot be managed via CP15. |
Sughosh Ganu | f552fa4 | 2019-12-29 00:01:05 +0530 | [diff] [blame] | 312 | |
| 313 | config EFI_RNG_PROTOCOL |
| 314 | bool "EFI_RNG_PROTOCOL support" |
| 315 | depends on DM_RNG |
Peter Robinson | bdf329e | 2020-04-01 11:15:01 +0100 | [diff] [blame] | 316 | default y |
Sughosh Ganu | f552fa4 | 2019-12-29 00:01:05 +0530 | [diff] [blame] | 317 | help |
Heinrich Schuchardt | 0e22885 | 2020-02-14 23:28:58 +0100 | [diff] [blame] | 318 | Provide a EFI_RNG_PROTOCOL implementation using the hardware random |
| 319 | number generator of the platform. |
Sughosh Ganu | f552fa4 | 2019-12-29 00:01:05 +0530 | [diff] [blame] | 320 | |
Ilias Apalodimas | c1c0210 | 2020-11-11 11:18:11 +0200 | [diff] [blame] | 321 | config EFI_TCG2_PROTOCOL |
| 322 | bool "EFI_TCG2_PROTOCOL support" |
Ilias Apalodimas | 48ee084 | 2021-05-11 14:40:58 +0300 | [diff] [blame] | 323 | default y |
Ilias Apalodimas | c1c0210 | 2020-11-11 11:18:11 +0200 | [diff] [blame] | 324 | depends on TPM_V2 |
Masahisa Kojima | 54bec17 | 2021-12-07 14:15:31 +0900 | [diff] [blame] | 325 | # Sandbox TPM currently fails on GetCapabilities needed for TCG2 |
| 326 | depends on !SANDBOX |
Ilias Apalodimas | 48ee084 | 2021-05-11 14:40:58 +0300 | [diff] [blame] | 327 | select SHA1 |
| 328 | select SHA256 |
Ilias Apalodimas | 48ee084 | 2021-05-11 14:40:58 +0300 | [diff] [blame] | 329 | select SHA384 |
| 330 | select SHA512 |
Masahisa Kojima | 163a0d7 | 2021-05-26 12:09:58 +0900 | [diff] [blame] | 331 | select HASH |
Masahisa Kojima | 3d49ee8 | 2021-10-26 17:27:24 +0900 | [diff] [blame] | 332 | select SMBIOS_PARSER |
Ilias Apalodimas | c1c0210 | 2020-11-11 11:18:11 +0200 | [diff] [blame] | 333 | help |
| 334 | Provide a EFI_TCG2_PROTOCOL implementation using the TPM hardware |
| 335 | of the platform. |
| 336 | |
Ilias Apalodimas | c8d0fd5 | 2020-11-30 11:47:40 +0200 | [diff] [blame] | 337 | config EFI_TCG2_PROTOCOL_EVENTLOG_SIZE |
| 338 | int "EFI_TCG2_PROTOCOL EventLog size" |
| 339 | depends on EFI_TCG2_PROTOCOL |
Masahisa Kojima | d934ed5 | 2021-07-14 22:00:01 +0900 | [diff] [blame] | 340 | default 65536 |
Ilias Apalodimas | c8d0fd5 | 2020-11-30 11:47:40 +0200 | [diff] [blame] | 341 | help |
| 342 | Define the size of the EventLog for EFI_TCG2_PROTOCOL. Note that |
| 343 | this is going to be allocated twice. One for the eventlog it self |
| 344 | and one for the configuration table that is required from the spec |
| 345 | |
Ilias Apalodimas | ec80b47 | 2020-02-21 09:55:45 +0200 | [diff] [blame] | 346 | config EFI_LOAD_FILE2_INITRD |
| 347 | bool "EFI_FILE_LOAD2_PROTOCOL for Linux initial ramdisk" |
Ilias Apalodimas | 53f6a5a | 2021-03-17 21:55:00 +0200 | [diff] [blame] | 348 | default y |
Ilias Apalodimas | ec80b47 | 2020-02-21 09:55:45 +0200 | [diff] [blame] | 349 | help |
Ilias Apalodimas | 53f6a5a | 2021-03-17 21:55:00 +0200 | [diff] [blame] | 350 | Linux v5.7 and later can make use of this option. If the boot option |
| 351 | selected by the UEFI boot manager specifies an existing file to be used |
| 352 | as initial RAM disk, a Linux specific Load File2 protocol will be |
| 353 | installed and Linux 5.7+ will ignore any initrd=<ramdisk> command line |
| 354 | argument. |
Ilias Apalodimas | ec80b47 | 2020-02-21 09:55:45 +0200 | [diff] [blame] | 355 | |
AKASHI Takahiro | 9bf09b5 | 2020-04-14 11:51:38 +0900 | [diff] [blame] | 356 | config EFI_SECURE_BOOT |
| 357 | bool "Enable EFI secure boot support" |
Simon Glass | 1eccbb1 | 2021-09-25 19:43:29 -0600 | [diff] [blame] | 358 | depends on EFI_LOADER && FIT_SIGNATURE |
Alexandru Gagniuc | 464010b | 2021-05-24 14:28:57 -0500 | [diff] [blame] | 359 | select HASH |
AKASHI Takahiro | 9bf09b5 | 2020-04-14 11:51:38 +0900 | [diff] [blame] | 360 | select SHA256 |
| 361 | select RSA |
| 362 | select RSA_VERIFY_WITH_PKEY |
| 363 | select IMAGE_SIGN_INFO |
| 364 | select ASYMMETRIC_KEY_TYPE |
| 365 | select ASYMMETRIC_PUBLIC_KEY_SUBTYPE |
| 366 | select X509_CERTIFICATE_PARSER |
| 367 | select PKCS7_MESSAGE_PARSER |
AKASHI Takahiro | 1115edd | 2020-07-21 19:35:22 +0900 | [diff] [blame] | 368 | select PKCS7_VERIFY |
Masahisa Kojima | f6081a8 | 2021-05-14 09:53:36 +0900 | [diff] [blame] | 369 | select EFI_SIGNATURE_SUPPORT |
AKASHI Takahiro | 9bf09b5 | 2020-04-14 11:51:38 +0900 | [diff] [blame] | 370 | help |
| 371 | Select this option to enable EFI secure boot support. |
| 372 | Once SecureBoot mode is enforced, any EFI binary can run only if |
| 373 | it is signed with a trusted key. To do that, you need to install, |
| 374 | at least, PK, KEK and db. |
| 375 | |
Masahisa Kojima | f6081a8 | 2021-05-14 09:53:36 +0900 | [diff] [blame] | 376 | config EFI_SIGNATURE_SUPPORT |
| 377 | bool |
| 378 | |
Jose Marinho | 64a8aae | 2021-03-02 17:26:38 +0000 | [diff] [blame] | 379 | config EFI_ESRT |
| 380 | bool "Enable the UEFI ESRT generation" |
| 381 | depends on EFI_CAPSULE_FIRMWARE_MANAGEMENT |
| 382 | default y |
| 383 | help |
| 384 | Enabling this option creates the ESRT UEFI system table. |
| 385 | |
Sunil V L | 1ccf871 | 2022-01-28 20:48:44 +0530 | [diff] [blame] | 386 | config EFI_RISCV_BOOT_PROTOCOL |
| 387 | bool "RISCV_EFI_BOOT_PROTOCOL support" |
| 388 | default y |
| 389 | depends on RISCV |
| 390 | help |
| 391 | The EFI_RISCV_BOOT_PROTOCOL is used to transfer the boot hart ID |
| 392 | to the next boot stage. It should be enabled as it is meant to |
| 393 | replace the transfer via the device-tree. The latter is not |
| 394 | possible on systems using ACPI. |
| 395 | |
Heinrich Schuchardt | 5684c8d | 2019-05-08 23:17:38 +0200 | [diff] [blame] | 396 | endif |