docs/variants/asrock_turind8ud/releases.md: Add HSI breakdown - #1308
Open
mkopec wants to merge 7 commits into
Open
docs/variants/asrock_turind8ud/releases.md: Add HSI breakdown#1308mkopec wants to merge 7 commits into
mkopec wants to merge 7 commits into
Conversation
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
…mplates Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
pietrushnic
requested changes
Aug 21, 2026
| ✘ Linux kernel lockdown: Disabled | ||
| ✘ Linux swap: Unencrypted | ||
| ✘ UEFI secure boot: Disabled | ||
| ``` |
Contributor
There was a problem hiding this comment.
@BeataZdunczyk, you added me to this review, but I think we should discuss this internally:
- Is that templated so other platforms can automatically benefit and will automatically get this information?
- Is this the best visualization form we are able to achieve?
- Are we gathering those statistics automatically or still manually?
- How and when will we address failures?
| Security ███████████████████████░░░░░░░░░░░░░░░░░ 9 (56.2%) | ||
| Integrity ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 3 (18.8%) | ||
| Doc Meta ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 3 (18.8%) | ||
| License ███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 1 (6.2%) |
Contributor
There was a problem hiding this comment.
What about Phase 1? What are the issues right now? Where will those be tracked?
|
|
||
| - Platform Secure Boot is currently not implemented in Dasharo firmware. | ||
| - [SPI Write Protection can be fixed by selecting SMM BIOS Write Protection in the UEFI Setup Menu.](https://docs.dasharo.com/dasharo-menu-docs/dasharo-system-features/#dasharo-security-options) | ||
| - SPI Replay Protection (RPMC) is unsupported by the board's SPI BIOS chip. |
Contributor
There was a problem hiding this comment.
That motherboard has a socketable SPI chip, AFAIK. Why don't you buy a chip that supports RPMC?
| - Pre-boot DMA protection is currently not supported for AMD platforms in | ||
| Dasharo firmware. | ||
| - Suspend-to-idle isn't supported on server hardware. | ||
| - Encrypted RAM is currently not supported in Dasharo firmware. |
Contributor
There was a problem hiding this comment.
Those comments are not enough; you have to answer typical questions:
- Why?
- When would it be supported, if ever?
- Where we can dive deeper and start discussion about this feature
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
… stats Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.