Measure DBT into PCR[7] when it is updated between initial measure and ExitBootService. Measure "SecureBoot" change after PK update. Spec version : TCG PC Client PFP 00.37. http://www.trustedcomputinggroup.org/wp-content/uploads/PC-ClientSpecific_Platform_Profile_for_TPM_2p0_Systems_v21.pdf Cc: Star Zeng <star.zeng@intel.com> Cc: Yao Jiewen <jiewen.yao@intel.com> Contributed-under: TianoCore Contribution Agreement 1.0 Signed-off-by: Chao Zhang <chao.b.zhang@intel.com> Reviewed-by: Star Zeng <star.zeng@intel.com> Reviewed-by: Yao Jiewen <jiewen.yao@intel.com>
		
			
				
	
	
		
			94 lines
		
	
	
		
			3.4 KiB
		
	
	
	
		
			INI
		
	
	
	
	
	
			
		
		
	
	
			94 lines
		
	
	
		
			3.4 KiB
		
	
	
	
		
			INI
		
	
	
	
	
	
| ## @file
 | |
| #  Runtime DXE part corresponding to SMM authenticated variable module.
 | |
| #
 | |
| #  This module installs variable arch protocol and variable write arch protocol to provide
 | |
| #  variable service. This module need work together with SMM authenticated variable module.
 | |
| #
 | |
| #  Caution: This module requires additional review when modified.
 | |
| #  This driver will have external input - variable data.
 | |
| #  This external input must be validated carefully to avoid security issues such as
 | |
| #  buffer overflow or integer overflow.
 | |
| #    The whole SMM authentication variable design relies on the integrity of flash part and SMM.
 | |
| #  which is assumed to be protected by platform.  All variable code and metadata in flash/SMM Memory
 | |
| #  may not be modified without authorization. If platform fails to protect these resources,
 | |
| #  the authentication service provided in this driver will be broken, and the behavior is undefined.
 | |
| #
 | |
| # Copyright (c) 2010 - 2017, Intel Corporation. All rights reserved.<BR>
 | |
| # This program and the accompanying materials
 | |
| # are licensed and made available under the terms and conditions of the BSD License
 | |
| # which accompanies this distribution. The full text of the license may be found at
 | |
| # http://opensource.org/licenses/bsd-license.php
 | |
| # THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
 | |
| # WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
 | |
| #
 | |
| ##
 | |
| 
 | |
| [Defines]
 | |
|   INF_VERSION                    = 0x00010005
 | |
|   BASE_NAME                      = VariableSmmRuntimeDxe
 | |
|   MODULE_UNI_FILE                = VariableSmmRuntimeDxe.uni
 | |
|   FILE_GUID                      = 9F7DCADE-11EA-448a-A46F-76E003657DD1
 | |
|   MODULE_TYPE                    = DXE_RUNTIME_DRIVER
 | |
|   VERSION_STRING                 = 1.0
 | |
|   ENTRY_POINT                    = VariableSmmRuntimeInitialize
 | |
| 
 | |
| #
 | |
| # The following information is for reference only and not required by the build tools.
 | |
| #
 | |
| #  VALID_ARCHITECTURES           = IA32 X64
 | |
| #
 | |
| #  VIRTUAL_ADDRESS_MAP_CALLBACK  =  VariableAddressChangeEvent
 | |
| #
 | |
| 
 | |
| [Sources]
 | |
|   VariableSmmRuntimeDxe.c
 | |
|   Measurement.c
 | |
| 
 | |
| [Packages]
 | |
|   MdePkg/MdePkg.dec
 | |
|   MdeModulePkg/MdeModulePkg.dec
 | |
| 
 | |
| [LibraryClasses]
 | |
|   MemoryAllocationLib
 | |
|   BaseLib
 | |
|   UefiBootServicesTableLib
 | |
|   DebugLib
 | |
|   UefiRuntimeLib
 | |
|   DxeServicesTableLib
 | |
|   UefiDriverEntryPoint
 | |
|   TpmMeasurementLib
 | |
| 
 | |
| [Protocols]
 | |
|   gEfiVariableWriteArchProtocolGuid             ## PRODUCES
 | |
|   gEfiVariableArchProtocolGuid                  ## PRODUCES
 | |
|   gEfiSmmCommunicationProtocolGuid              ## CONSUMES
 | |
|   ## CONSUMES
 | |
|   ## NOTIFY
 | |
|   ## UNDEFINED # Used to do smm communication
 | |
|   gEfiSmmVariableProtocolGuid
 | |
|   gEdkiiVariableLockProtocolGuid                ## PRODUCES
 | |
|   gEdkiiVarCheckProtocolGuid                    ## PRODUCES
 | |
| 
 | |
| [Guids]
 | |
|   gEfiEventVirtualAddressChangeGuid             ## CONSUMES ## Event
 | |
|   gEfiEventExitBootServicesGuid                 ## CONSUMES ## Event
 | |
|   ## CONSUMES ## GUID # Locate protocol
 | |
|   ## CONSUMES ## GUID # Protocol notify
 | |
|   gSmmVariableWriteGuid
 | |
| 
 | |
|   ## SOMETIMES_CONSUMES   ## Variable:L"PK"
 | |
|   ## SOMETIMES_CONSUMES   ## Variable:L"KEK"
 | |
|   ## SOMETIMES_CONSUMES   ## Variable:L"SecureBoot"
 | |
|   gEfiGlobalVariableGuid
 | |
| 
 | |
|   ## SOMETIMES_CONSUMES   ## Variable:L"db"
 | |
|   ## SOMETIMES_CONSUMES   ## Variable:L"dbx"
 | |
|   ## SOMETIMES_CONSUMES   ## Variable:L"dbt"
 | |
|   gEfiImageSecurityDatabaseGuid
 | |
| 
 | |
| [Depex]
 | |
|   gEfiSmmCommunicationProtocolGuid
 | |
| 
 | |
| [UserExtensions.TianoCore."ExtraFiles"]
 | |
|   VariableSmmRuntimeDxeExtra.uni
 |