1. Remove memory allocation code in runtime. 2. Exclude NULL terminator in VariableName for serialization data in time-based variable authentication. 3. Add support for enroll PK with WRITE_ACCESS attribute. 4. Initialize SetupMode variable with correct NV attribute. 5. Add support for APPEND_WRITE attribute for non-existing Variable. 6. Clear KEK, DB and DBX as well as PK when user request to clear platform keys. 7. Check duplicated EFI_SIGNATURE_DATA for Variable formatted as EFI_SIGNATURE_LIST when APPEND_WRITE attribute is set. 8. Not change SecureBoot Variable in runtime, only update it in boot time since this Variable indicates firmware operating mode. 9. Save time stamp of PK when PK is set with TIME_BASED_WRITE_ACCESS attribute in setup mode. 10. Update to use PcdMaxVariableSize instead of PcdMaxAppendVariableSize for append operation. Signed-off-by: xdu2 Reviewed-by: tye git-svn-id: https://edk2.svn.sourceforge.net/svnroot/edk2/trunk/edk2@12599 6f19259b-4bc3-4df7-8a09-765794883524
100 lines
3.1 KiB
INI
100 lines
3.1 KiB
INI
## @file
|
|
# Component description file for Authenticated Variable module.
|
|
#
|
|
# Copyright (c) 2009 - 2011, Intel Corporation. All rights reserved.<BR>
|
|
# This program and the accompanying materials
|
|
# are licensed and made available under the terms and conditions of the BSD License
|
|
# which accompanies this distribution. The full text of the license may be found at
|
|
# http://opensource.org/licenses/bsd-license.php
|
|
# THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
|
|
#
|
|
##
|
|
|
|
[Defines]
|
|
INF_VERSION = 0x00010005
|
|
BASE_NAME = VariableRuntimeDxe
|
|
FILE_GUID = 2226F30F-3D5B-402d-9936-A97184EB4516
|
|
MODULE_TYPE = DXE_RUNTIME_DRIVER
|
|
VERSION_STRING = 1.0
|
|
ENTRY_POINT = VariableServiceInitialize
|
|
|
|
#
|
|
# The following information is for reference only and not required by the build tools.
|
|
#
|
|
# VALID_ARCHITECTURES = IA32 X64 EBC
|
|
#
|
|
# VIRTUAL_ADDRESS_MAP_CALLBACK = VariableClassAddressChangeEvent
|
|
#
|
|
|
|
[Sources]
|
|
Reclaim.c
|
|
Variable.c
|
|
VariableDxe.c
|
|
Variable.h
|
|
AuthService.c
|
|
AuthService.h
|
|
|
|
[Packages]
|
|
MdePkg/MdePkg.dec
|
|
MdeModulePkg/MdeModulePkg.dec
|
|
CryptoPkg/CryptoPkg.dec
|
|
SecurityPkg/SecurityPkg.dec
|
|
|
|
[LibraryClasses]
|
|
MemoryAllocationLib
|
|
BaseLib
|
|
SynchronizationLib
|
|
UefiLib
|
|
UefiBootServicesTableLib
|
|
BaseMemoryLib
|
|
DebugLib
|
|
UefiRuntimeLib
|
|
DxeServicesTableLib
|
|
UefiDriverEntryPoint
|
|
PcdLib
|
|
BaseCryptLib
|
|
PlatformSecureLib
|
|
HobLib
|
|
|
|
[Protocols]
|
|
gEfiFirmwareVolumeBlockProtocolGuid ## SOMETIMES_CONSUMES
|
|
gEfiVariableWriteArchProtocolGuid ## ALWAYS_PRODUCES
|
|
gEfiVariableArchProtocolGuid ## ALWAYS_PRODUCES
|
|
gEfiFaultTolerantWriteProtocolGuid ## SOMETIMES_CONSUMES
|
|
|
|
[Guids]
|
|
gEfiAuthenticatedVariableGuid ## PRODUCES ## Configuration Table Guid
|
|
gEfiGlobalVariableGuid ## PRODUCES ## Variable Guid
|
|
gEfiEventVirtualAddressChangeGuid ## PRODUCES ## Event
|
|
gEfiCertRsa2048Sha256Guid
|
|
gEfiImageSecurityDatabaseGuid
|
|
gEfiCertX509Guid
|
|
gEfiCertPkcs7Guid
|
|
gEfiCertRsa2048Guid
|
|
gEfiSecureBootEnableDisableGuid
|
|
|
|
[Pcd]
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdFlashNvStorageVariableSize
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdFlashNvStorageVariableBase
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdFlashNvStorageVariableBase64
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdMaxVariableSize
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdMaxHardwareErrorVariableSize
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdVariableStoreSize
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdHwErrStorageSize
|
|
|
|
[FeaturePcd]
|
|
gEfiMdeModulePkgTokenSpaceGuid.PcdVariableCollectStatistics ## SOMETIME_CONSUMES (statistic the information of variable.)
|
|
|
|
[Depex]
|
|
gEfiFirmwareVolumeBlockProtocolGuid AND gEfiFaultTolerantWriteProtocolGuid
|
|
|
|
# [Event]
|
|
# ##
|
|
# # Event will be signaled for VIRTUAL_ADDRESS_CHANGE event.
|
|
# #
|
|
# EVENT_TYPE_NOTIFY_SIGNAL ## PRODUCES
|
|
#
|
|
#
|
|
|