+ ## This PCD is to control which drivers need memory profile data.<BR><BR>\r
+ # For example:<BR>\r
+ # One image only (Shell):<BR>\r
+ # Header GUID<BR>\r
+ # {0x04, 0x06, 0x14, 0x00, 0x83, 0xA5, 0x04, 0x7C, 0x3E, 0x9E, 0x1C, 0x4F, 0xAD, 0x65, 0xE0, 0x52, 0x68, 0xD0, 0xB4, 0xD1,<BR>\r
+ # 0x7F, 0xFF, 0x04, 0x00}<BR>\r
+ # Two or more images (Shell + WinNtSimpleFileSystem):<BR>\r
+ # {0x04, 0x06, 0x14, 0x00, 0x83, 0xA5, 0x04, 0x7C, 0x3E, 0x9E, 0x1C, 0x4F, 0xAD, 0x65, 0xE0, 0x52, 0x68, 0xD0, 0xB4, 0xD1,<BR>\r
+ # 0x7F, 0x01, 0x04, 0x00,<BR>\r
+ # 0x04, 0x06, 0x14, 0x00, 0x8B, 0xE1, 0x25, 0x9C, 0xBA, 0x76, 0xDA, 0x43, 0xA1, 0x32, 0xDB, 0xB0, 0x99, 0x7C, 0xEF, 0xEF,<BR>\r
+ # 0x7F, 0xFF, 0x04, 0x00}<BR>\r
+ # @Prompt Memory profile driver path.\r
+ gEfiMdeModulePkgTokenSpaceGuid.PcdMemoryProfileDriverPath|{0x0}|VOID*|0x00001043\r
+\r
+ ## Set image protection policy. The policy is bitwise.\r
+ # If a bit is set, the image will be protected by DxeCore if it is aligned.\r
+ # The code section becomes read-only, and the data section becomes non-executable.\r
+ # If a bit is clear, the image will not be protected.<BR><BR>\r
+ # BIT0 - Image from unknown device. <BR>\r
+ # BIT1 - Image from firmware volume.<BR>\r
+ # @Prompt Set image protection policy.\r
+ # @ValidRange 0x80000002 | 0x00000000 - 0x0000001F\r
+ gEfiMdeModulePkgTokenSpaceGuid.PcdImageProtectionPolicy|0x00000002|UINT32|0x00001047\r
+\r
+ ## Set DXE memory protection policy. The policy is bitwise.\r
+ # If a bit is set, memory regions of the associated type will be mapped\r
+ # non-executable.<BR><BR>\r
+ #\r
+ # Below is bit mask for this PCD: (Order is same as UEFI spec)<BR>\r
+ # EfiReservedMemoryType 0x0001<BR>\r
+ # EfiLoaderCode 0x0002<BR>\r
+ # EfiLoaderData 0x0004<BR>\r
+ # EfiBootServicesCode 0x0008<BR>\r
+ # EfiBootServicesData 0x0010<BR>\r
+ # EfiRuntimeServicesCode 0x0020<BR>\r
+ # EfiRuntimeServicesData 0x0040<BR>\r
+ # EfiConventionalMemory 0x0080<BR>\r
+ # EfiUnusableMemory 0x0100<BR>\r
+ # EfiACPIReclaimMemory 0x0200<BR>\r
+ # EfiACPIMemoryNVS 0x0400<BR>\r
+ # EfiMemoryMappedIO 0x0800<BR>\r
+ # EfiMemoryMappedIOPortSpace 0x1000<BR>\r
+ # EfiPalCode 0x2000<BR>\r
+ # EfiPersistentMemory 0x4000<BR>\r
+ # OEM Reserved 0x4000000000000000<BR>\r
+ # OS Reserved 0x8000000000000000<BR>\r
+ #\r
+ # NOTE: User must NOT set NX protection for EfiLoaderCode / EfiBootServicesCode / EfiRuntimeServicesCode. <BR>\r
+ # User MUST set the same NX protection for EfiBootServicesData and EfiConventionalMemory. <BR>\r
+ #\r
+ # e.g. 0x7FD5 can be used for all memory except Code. <BR>\r
+ # e.g. 0x7BD4 can be used for all memory except Code and ACPINVS/Reserved. <BR>\r
+ #\r
+ # @Prompt Set DXE memory protection policy.\r
+ gEfiMdeModulePkgTokenSpaceGuid.PcdDxeNxMemoryProtectionPolicy|0x0000000|UINT64|0x00001048\r
+\r