altfw: add the ability to disable rollback APIs

Adds a flag to VbSelectAndLoadKernelParams that will disable TPM
rollback APIs. This is necessary for altfw depthcharge because the real
depthcharge locks the rollback area of the TPM before handing off to
altfw, so any attempt to access these values will fail.

TEST=successfully booted depthcharge -> altfw -> ChromeOS

Change-Id: Ib7e042f9894058a23efe553546868b0711112aaa
Reviewed-by: Simon Shields <>
5 files changed