heads
heads copied to clipboard
PRR and FLOCKDN are not set
trafficstars

The protected range registers and flash lockdown should be set before invoking the kexec.
Discussion of this on the coreboot mailing list: https://mail.coreboot.org/pipermail/coreboot/2017-July/084766.html
@osresearch :
The finalization procedure usually doesn't lock the SPI flash. We added some options to Sandy/Ivy Bridge (mistakenly called LOCK_SPI_ON_RESUME_) but those were never ported to newer chipsets, AFAIK." SRC: https://mail.coreboot.org/pipermail/coreboot/2017-July/084770.html
#326