soc/amd/cezanne & picasso: Add Kconfig for hardcoded Soft Fuse bits

Currently, some of the PSP Soft Fuse bits are hardcoded in the Cezanne
and Picasso makefiles.
This makes it impossible for platforms to change them.  This change puts
the hardcoded bits in Kconfig, allowing them to be modified by the
platform.

BUG=b:185514903
TEST=Verify that the correct Soft Fuse bits are set.

Signed-off-by: Martin Roth <martinroth@chromium.org>
Change-Id: I190ebf47cb7ae46983733dc6541776bf19a2382f
Reviewed-on: https://review.coreboot.org/c/coreboot/+/52422
Reviewed-by: Marshall Dawson <marshalldawson3rd@gmail.com>
Tested-by: build bot (Jenkins) <no-reply@coreboot.org>
diff --git a/src/soc/amd/picasso/Kconfig b/src/soc/amd/picasso/Kconfig
index 63fa010..fe09e11 100644
--- a/src/soc/amd/picasso/Kconfig
+++ b/src/soc/amd/picasso/Kconfig
@@ -425,6 +425,17 @@
 	help
 	  Add psp_verstage signature token to the build & PSP Directory Table
 
+config PSP_SOFTFUSE_BITS
+	string "PSP Soft Fuse bits to enable"
+	default "28"
+	help
+	  Space separated list of Soft Fuse bits to enable.
+	  Bit 0:  Enable secure debug (Set by PSP_UNLOCK_SECURE_DEBUG)
+	  Bit 15: PSP post code destination: 0=LPC 1=eSPI
+	  Bit 29: Disable MP2 firmware loading (Set by PSP_LOAD_MP2_FW)
+
+	  See #55758 (NDA) for additional bit definitions.
+
 endmenu
 
 config VBOOT
diff --git a/src/soc/amd/picasso/Makefile.inc b/src/soc/amd/picasso/Makefile.inc
index e8ee087..081a65f 100644
--- a/src/soc/amd/picasso/Makefile.inc
+++ b/src/soc/amd/picasso/Makefile.inc
@@ -107,6 +107,9 @@
 PSP_SOFTFUSE_BITS += 29
 endif
 
+# Use additional Soft Fuse bits specified in Kconfig
+PSP_SOFTFUSE_BITS += $(CONFIG_PSP_SOFTFUSE_BITS)
+
 ifeq ($(CONFIG_PSP_LOAD_S0I3_FW),y)
 OPT_PSP_LOAD_S0I3_FW="--load-s0i3"
 endif
@@ -147,10 +150,9 @@
 PSP_VERSTAGE_SIG_FILE=$(call strip_quotes,$(CONFIG_PSP_VERSTAGE_SIGNING_TOKEN))
 endif # CONFIG_VBOOT_STARTS_BEFORE_BOOTBLOCK
 
-# type = 0xb - See #55758 (NDA) for bit definitions.
-PSP_SOFTFUSE_BITS += 28
 
 # Helper function to return a value with given bit set
+# Soft Fuse type = 0xb - See #55758 (NDA) for bit definitions.
 set-bit=$(call int-shift-left, 1 $(call _toint,$1))
 PSP_SOFTFUSE=$(shell A=$(call int-add, \
 		$(foreach bit,$(PSP_SOFTFUSE_BITS),$(call set-bit,$(bit)))); printf "0x%x" $$A)