mirror of
https://git.proxmox.com/git/fwupd
synced 2026-03-27 21:30:22 +00:00
Semantically it is the desire of the security attribute, not the bios attribute, i.e. you could imagine that a specific attribute would have to be *foo or bar or baz* for HSI-1 and *only foo* for HSI-2 Also make it easier to add possible BIOS attribute target values in plugin code. |
||
|---|---|---|
| .. | ||
| fu-plugin-msr.c | ||
| fwupd-msr.conf | ||
| meson.build | ||
| msr.conf | ||
| msr.quirk | ||
| README.md | ||
MSR
Introduction
This plugin checks if the Model-specific registers (MSRs) indicate the Direct Connect Interface (DCI) is enabled.
DCI allows debugging of Intel processors using the USB3 port. DCI should always be disabled and locked on production hardware as it allows the attacker to disable other firmware protection methods.
The result will be stored in a security attribute for HSI.
External Interface Access
This plugin requires read access to /sys/class/msr.