Skip to content

docs/variants/asrock_turind8ud/releases.md: Add HSI breakdown - #1308

Open
mkopec wants to merge 7 commits into
masterfrom
asrock_turind8ud_sbom_hsi
Open

docs/variants/asrock_turind8ud/releases.md: Add HSI breakdown#1308
mkopec wants to merge 7 commits into
masterfrom
asrock_turind8ud_sbom_hsi

Conversation

@mkopec

@mkopec mkopec commented Aug 19, 2026

Copy link
Copy Markdown
Member

No description provided.

Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
mkopec added 4 commits August 19, 2026 11:17
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
…mplates

Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
✘ Linux kernel lockdown: Disabled
✘ Linux swap: Unencrypted
✘ UEFI secure boot: Disabled
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@BeataZdunczyk, you added me to this review, but I think we should discuss this internally:

  • Is that templated so other platforms can automatically benefit and will automatically get this information?
  • Is this the best visualization form we are able to achieve?
  • Are we gathering those statistics automatically or still manually?
  • How and when will we address failures?

Security ███████████████████████░░░░░░░░░░░░░░░░░ 9 (56.2%)
Integrity ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 3 (18.8%)
Doc Meta ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 3 (18.8%)
License ███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 1 (6.2%)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What about Phase 1? What are the issues right now? Where will those be tracked?

Comment thread docs/variants/asrock_turind8ud/releases.md Outdated
Comment thread docs/variants/asrock_turind8ud/releases.md Outdated

- Platform Secure Boot is currently not implemented in Dasharo firmware.
- [SPI Write Protection can be fixed by selecting SMM BIOS Write Protection in the UEFI Setup Menu.](https://docs.dasharo.com/dasharo-menu-docs/dasharo-system-features/#dasharo-security-options)
- SPI Replay Protection (RPMC) is unsupported by the board's SPI BIOS chip.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That motherboard has a socketable SPI chip, AFAIK. Why don't you buy a chip that supports RPMC?

Comment thread docs/variants/asrock_turind8ud/releases.md Outdated
- Pre-boot DMA protection is currently not supported for AMD platforms in
Dasharo firmware.
- Suspend-to-idle isn't supported on server hardware.
- Encrypted RAM is currently not supported in Dasharo firmware.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Those comments are not enough; you have to answer typical questions:

  • Why?
  • When would it be supported, if ever?
  • Where we can dive deeper and start discussion about this feature

mkopec added 2 commits August 21, 2026 11:18
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
… stats

Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants