]> git.proxmox.com Git - mirror_edk2.git/blame - OvmfPkg/IntelTdx/IntelTdxX64.fdf
OvmfPkg/IntelTdx: Enable RTMR based measurement and measure boot
[mirror_edk2.git] / OvmfPkg / IntelTdx / IntelTdxX64.fdf
CommitLineData
44a53a3b
MX
1## @file\r
2# Open Virtual Machine Firmware: FDF\r
3#\r
4# Copyright (c) 2006 - 2019, Intel Corporation. All rights reserved.<BR>\r
5# (C) Copyright 2016 Hewlett Packard Enterprise Development LP<BR>\r
6#\r
7# SPDX-License-Identifier: BSD-2-Clause-Patent\r
8#\r
9##\r
10\r
11################################################################################\r
12\r
13[Defines]\r
14!include OvmfPkg/OvmfPkgDefines.fdf.inc\r
15\r
16#\r
17# Build the variable store and the firmware code as one unified flash device\r
18# image.\r
19#\r
20[FD.OVMF]\r
21BaseAddress = $(FW_BASE_ADDRESS)\r
22Size = $(FW_SIZE)\r
23ErasePolarity = 1\r
24BlockSize = $(BLOCK_SIZE)\r
25NumBlocks = $(FW_BLOCKS)\r
26\r
27!include OvmfPkg/VarStore.fdf.inc\r
28\r
29$(VARS_SIZE)|$(FVMAIN_SIZE)\r
30FV = FVMAIN_COMPACT\r
31\r
32$(SECFV_OFFSET)|$(SECFV_SIZE)\r
33FV = SECFV\r
34\r
35#\r
36# Build the variable store and the firmware code as separate flash device\r
37# images.\r
38#\r
39[FD.OVMF_VARS]\r
40BaseAddress = $(FW_BASE_ADDRESS)\r
41Size = $(VARS_SIZE)\r
42ErasePolarity = 1\r
43BlockSize = $(BLOCK_SIZE)\r
44NumBlocks = $(VARS_BLOCKS)\r
45\r
46!include OvmfPkg/VarStore.fdf.inc\r
47\r
48[FD.OVMF_CODE]\r
49BaseAddress = $(CODE_BASE_ADDRESS)\r
50Size = $(CODE_SIZE)\r
51ErasePolarity = 1\r
52BlockSize = $(BLOCK_SIZE)\r
53NumBlocks = $(CODE_BLOCKS)\r
54\r
550x00000000|$(FVMAIN_SIZE)\r
56FV = FVMAIN_COMPACT\r
57\r
58$(FVMAIN_SIZE)|$(SECFV_SIZE)\r
59FV = SECFV\r
60\r
61################################################################################\r
62\r
63[FD.MEMFD]\r
64BaseAddress = $(MEMFD_BASE_ADDRESS)\r
65Size = 0xD00000\r
66ErasePolarity = 1\r
67BlockSize = 0x10000\r
68NumBlocks = 0xD0\r
69\r
700x000000|0x006000\r
71gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPageTablesBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPageTablesSize\r
72\r
730x006000|0x001000\r
74gUefiOvmfPkgTokenSpaceGuid.PcdOvmfLockBoxStorageBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfLockBoxStorageSize\r
75\r
760x007000|0x001000\r
77gEfiMdePkgTokenSpaceGuid.PcdGuidedExtractHandlerTableAddress|gUefiOvmfPkgTokenSpaceGuid.PcdGuidedExtractHandlerTableSize\r
78\r
790x008000|0x001000\r
80gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecGhcbPageTableBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecGhcbPageTableSize\r
81\r
820x009000|0x002000\r
83gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecGhcbBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecGhcbSize\r
84\r
850x00B000|0x001000\r
86gUefiOvmfPkgTokenSpaceGuid.PcdOvmfWorkAreaBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfWorkAreaSize\r
87\r
880x00C000|0x001000\r
89gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecGhcbBackupBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecGhcbBackupSize\r
90\r
910x00D000|0x001000\r
92gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSnpSecretsBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSnpSecretsSize\r
93\r
940x00E000|0x001000\r
95gUefiOvmfPkgTokenSpaceGuid.PcdOvmfCpuidBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfCpuidSize\r
96\r
970x010000|0x010000\r
98gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPeiTempRamBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfSecPeiTempRamSize\r
99\r
1000x100000|0xC00000\r
101gUefiOvmfPkgTokenSpaceGuid.PcdOvmfDxeMemFvBase|gUefiOvmfPkgTokenSpaceGuid.PcdOvmfDxeMemFvSize\r
102FV = DXEFV\r
103\r
104##########################################################################################\r
105# Set the SEV-ES specific work area PCDs\r
106#\r
107SET gUefiCpuPkgTokenSpaceGuid.PcdSevEsWorkAreaBase = $(MEMFD_BASE_ADDRESS) + gUefiOvmfPkgTokenSpaceGuid.PcdOvmfWorkAreaBase + gUefiOvmfPkgTokenSpaceGuid.PcdOvmfConfidentialComputingWorkAreaHeader\r
108SET gUefiCpuPkgTokenSpaceGuid.PcdSevEsWorkAreaSize = gUefiOvmfPkgTokenSpaceGuid.PcdOvmfWorkAreaSize - gUefiOvmfPkgTokenSpaceGuid.PcdOvmfConfidentialComputingWorkAreaHeader\r
109\r
110\r
111##########################################################################################\r
112\r
113################################################################################\r
114\r
115[FV.SECFV]\r
116FvNameGuid = 763BED0D-DE9F-48F5-81F1-3E90E1B1A015\r
117BlockSize = 0x1000\r
118FvAlignment = 16\r
119ERASE_POLARITY = 1\r
120MEMORY_MAPPED = TRUE\r
121STICKY_WRITE = TRUE\r
122LOCK_CAP = TRUE\r
123LOCK_STATUS = TRUE\r
124WRITE_DISABLED_CAP = TRUE\r
125WRITE_ENABLED_CAP = TRUE\r
126WRITE_STATUS = TRUE\r
127WRITE_LOCK_CAP = TRUE\r
128WRITE_LOCK_STATUS = TRUE\r
129READ_DISABLED_CAP = TRUE\r
130READ_ENABLED_CAP = TRUE\r
131READ_STATUS = TRUE\r
132READ_LOCK_CAP = TRUE\r
133READ_LOCK_STATUS = TRUE\r
134\r
135#\r
136# SEC Phase modules\r
137#\r
138# The code in this FV handles the initial firmware startup, and\r
139# decompresses the PEI and DXE FVs which handles the rest of the boot sequence.\r
140#\r
141INF OvmfPkg/IntelTdx/Sec/SecMain.inf\r
142\r
143INF RuleOverride=RESET_VECTOR OvmfPkg/ResetVector/ResetVector.inf\r
144\r
145################################################################################\r
146\r
147[FV.DXEFV]\r
148FvForceRebase = FALSE\r
149FvNameGuid = 7CB8BDC9-F8EB-4F34-AAEA-3EE4AF6516A1\r
150BlockSize = 0x10000\r
151FvAlignment = 16\r
152ERASE_POLARITY = 1\r
153MEMORY_MAPPED = TRUE\r
154STICKY_WRITE = TRUE\r
155LOCK_CAP = TRUE\r
156LOCK_STATUS = TRUE\r
157WRITE_DISABLED_CAP = TRUE\r
158WRITE_ENABLED_CAP = TRUE\r
159WRITE_STATUS = TRUE\r
160WRITE_LOCK_CAP = TRUE\r
161WRITE_LOCK_STATUS = TRUE\r
162READ_DISABLED_CAP = TRUE\r
163READ_ENABLED_CAP = TRUE\r
164READ_STATUS = TRUE\r
165READ_LOCK_CAP = TRUE\r
166READ_LOCK_STATUS = TRUE\r
167\r
168APRIORI DXE {\r
169 INF MdeModulePkg/Universal/DevicePathDxe/DevicePathDxe.inf\r
170 INF MdeModulePkg/Universal/PCD/Dxe/Pcd.inf\r
171 INF OvmfPkg/TdxDxe/TdxDxe.inf\r
172 INF OvmfPkg/QemuFlashFvbServicesRuntimeDxe/FvbServicesRuntimeDxe.inf\r
173}\r
174\r
175#\r
176# DXE Phase modules\r
177#\r
178INF MdeModulePkg/Core/Dxe/DxeMain.inf\r
179\r
180INF MdeModulePkg/Universal/ReportStatusCodeRouter/RuntimeDxe/ReportStatusCodeRouterRuntimeDxe.inf\r
181INF MdeModulePkg/Universal/StatusCodeHandler/RuntimeDxe/StatusCodeHandlerRuntimeDxe.inf\r
182INF MdeModulePkg/Universal/PCD/Dxe/Pcd.inf\r
183\r
184INF MdeModulePkg/Core/RuntimeDxe/RuntimeDxe.inf\r
185INF MdeModulePkg/Universal/SecurityStubDxe/SecurityStubDxe.inf\r
186INF MdeModulePkg/Universal/EbcDxe/EbcDxe.inf\r
187INF UefiCpuPkg/CpuIo2Dxe/CpuIo2Dxe.inf\r
deee7a10 188\r
44a53a3b 189INF UefiCpuPkg/CpuDxe/CpuDxe.inf\r
deee7a10
MX
190INF FILE_GUID = $(UP_CPU_DXE_GUID) UefiCpuPkg/CpuDxe/CpuDxe.inf\r
191\r
44a53a3b
MX
192INF OvmfPkg/LocalApicTimerDxe/LocalApicTimerDxe.inf\r
193INF OvmfPkg/IncompatiblePciDeviceSupportDxe/IncompatiblePciDeviceSupport.inf\r
194INF OvmfPkg/PciHotPlugInitDxe/PciHotPlugInit.inf\r
195INF MdeModulePkg/Bus/Pci/PciHostBridgeDxe/PciHostBridgeDxe.inf\r
196INF MdeModulePkg/Bus/Pci/PciBusDxe/PciBusDxe.inf\r
197INF MdeModulePkg/Universal/ResetSystemRuntimeDxe/ResetSystemRuntimeDxe.inf\r
198INF MdeModulePkg/Universal/Metronome/Metronome.inf\r
199INF PcAtChipsetPkg/PcatRealTimeClockRuntimeDxe/PcatRealTimeClockRuntimeDxe.inf\r
200\r
201INF OvmfPkg/VirtioPciDeviceDxe/VirtioPciDeviceDxe.inf\r
202INF OvmfPkg/Virtio10Dxe/Virtio10.inf\r
203INF OvmfPkg/VirtioBlkDxe/VirtioBlk.inf\r
204INF OvmfPkg/VirtioScsiDxe/VirtioScsi.inf\r
205INF OvmfPkg/VirtioRngDxe/VirtioRng.inf\r
206!if $(PVSCSI_ENABLE) == TRUE\r
207INF OvmfPkg/PvScsiDxe/PvScsiDxe.inf\r
208!endif\r
209!if $(MPT_SCSI_ENABLE) == TRUE\r
210INF OvmfPkg/MptScsiDxe/MptScsiDxe.inf\r
211!endif\r
212!if $(LSI_SCSI_ENABLE) == TRUE\r
213INF OvmfPkg/LsiScsiDxe/LsiScsiDxe.inf\r
214!endif\r
215\r
216!if $(SECURE_BOOT_ENABLE) == TRUE\r
217 INF SecurityPkg/VariableAuthenticated/SecureBootConfigDxe/SecureBootConfigDxe.inf\r
218!endif\r
219\r
220INF MdeModulePkg/Universal/WatchdogTimerDxe/WatchdogTimer.inf\r
221INF MdeModulePkg/Universal/MonotonicCounterRuntimeDxe/MonotonicCounterRuntimeDxe.inf\r
222INF MdeModulePkg/Universal/CapsuleRuntimeDxe/CapsuleRuntimeDxe.inf\r
223INF MdeModulePkg/Universal/Console/ConPlatformDxe/ConPlatformDxe.inf\r
224INF MdeModulePkg/Universal/Console/ConSplitterDxe/ConSplitterDxe.inf\r
225INF MdeModulePkg/Universal/Console/GraphicsConsoleDxe/GraphicsConsoleDxe.inf\r
226INF MdeModulePkg/Universal/Console/TerminalDxe/TerminalDxe.inf\r
227INF MdeModulePkg/Universal/DriverHealthManagerDxe/DriverHealthManagerDxe.inf\r
228INF MdeModulePkg/Universal/BdsDxe/BdsDxe.inf\r
229INF MdeModulePkg/Application/UiApp/UiApp.inf\r
230INF OvmfPkg/QemuKernelLoaderFsDxe/QemuKernelLoaderFsDxe.inf\r
231INF MdeModulePkg/Universal/DevicePathDxe/DevicePathDxe.inf\r
232INF MdeModulePkg/Universal/Disk/DiskIoDxe/DiskIoDxe.inf\r
233INF MdeModulePkg/Universal/Disk/PartitionDxe/PartitionDxe.inf\r
234INF MdeModulePkg/Universal/Disk/RamDiskDxe/RamDiskDxe.inf\r
235INF MdeModulePkg/Universal/Disk/UnicodeCollation/EnglishDxe/EnglishDxe.inf\r
236INF MdeModulePkg/Bus/Scsi/ScsiBusDxe/ScsiBusDxe.inf\r
237INF MdeModulePkg/Bus/Scsi/ScsiDiskDxe/ScsiDiskDxe.inf\r
238INF OvmfPkg/SataControllerDxe/SataControllerDxe.inf\r
239INF MdeModulePkg/Bus/Ata/AtaAtapiPassThru/AtaAtapiPassThru.inf\r
240INF MdeModulePkg/Bus/Ata/AtaBusDxe/AtaBusDxe.inf\r
241INF MdeModulePkg/Bus/Pci/NvmExpressDxe/NvmExpressDxe.inf\r
242INF MdeModulePkg/Universal/HiiDatabaseDxe/HiiDatabaseDxe.inf\r
243INF MdeModulePkg/Universal/SetupBrowserDxe/SetupBrowserDxe.inf\r
244INF MdeModulePkg/Universal/DisplayEngineDxe/DisplayEngineDxe.inf\r
245INF MdeModulePkg/Universal/MemoryTest/NullMemoryTestDxe/NullMemoryTestDxe.inf\r
246\r
247INF OvmfPkg/SioBusDxe/SioBusDxe.inf\r
248INF MdeModulePkg/Bus/Pci/PciSioSerialDxe/PciSioSerialDxe.inf\r
249INF MdeModulePkg/Bus/Isa/Ps2KeyboardDxe/Ps2KeyboardDxe.inf\r
250\r
251INF MdeModulePkg/Universal/SmbiosDxe/SmbiosDxe.inf\r
252INF OvmfPkg/SmbiosPlatformDxe/SmbiosPlatformDxe.inf\r
253\r
254INF MdeModulePkg/Universal/Acpi/AcpiTableDxe/AcpiTableDxe.inf\r
255INF OvmfPkg/AcpiPlatformDxe/AcpiPlatformDxe.inf\r
256INF MdeModulePkg/Universal/Acpi/S3SaveStateDxe/S3SaveStateDxe.inf\r
257INF MdeModulePkg/Universal/Acpi/BootScriptExecutorDxe/BootScriptExecutorDxe.inf\r
258INF MdeModulePkg/Universal/Acpi/BootGraphicsResourceTableDxe/BootGraphicsResourceTableDxe.inf\r
259\r
260INF FatPkg/EnhancedFatDxe/Fat.inf\r
261INF MdeModulePkg/Universal/Disk/UdfDxe/UdfDxe.inf\r
262INF OvmfPkg/VirtioFsDxe/VirtioFsDxe.inf\r
263\r
264!if $(TOOL_CHAIN_TAG) != "XCODE5"\r
265INF OvmfPkg/LinuxInitrdDynamicShellCommand/LinuxInitrdDynamicShellCommand.inf\r
266!endif\r
267INF ShellPkg/Application/Shell/Shell.inf\r
268\r
269INF MdeModulePkg/Logo/LogoDxe.inf\r
270\r
271INF OvmfPkg/TdxDxe/TdxDxe.inf\r
272\r
273#\r
274# Usb Support\r
275#\r
276INF MdeModulePkg/Bus/Pci/UhciDxe/UhciDxe.inf\r
277INF MdeModulePkg/Bus/Pci/EhciDxe/EhciDxe.inf\r
278INF MdeModulePkg/Bus/Pci/XhciDxe/XhciDxe.inf\r
279INF MdeModulePkg/Bus/Usb/UsbBusDxe/UsbBusDxe.inf\r
280INF MdeModulePkg/Bus/Usb/UsbKbDxe/UsbKbDxe.inf\r
281INF MdeModulePkg/Bus/Usb/UsbMassStorageDxe/UsbMassStorageDxe.inf\r
282\r
283INF OvmfPkg/QemuVideoDxe/QemuVideoDxe.inf\r
284\r
285INF OvmfPkg/QemuRamfbDxe/QemuRamfbDxe.inf\r
286INF OvmfPkg/VirtioGpuDxe/VirtioGpu.inf\r
287INF OvmfPkg/PlatformDxe/Platform.inf\r
288INF OvmfPkg/IoMmuDxe/IoMmuDxe.inf\r
289\r
290#\r
291# Variable driver stack (non-SMM)\r
292#\r
293INF OvmfPkg/QemuFlashFvbServicesRuntimeDxe/FvbServicesRuntimeDxe.inf\r
294INF OvmfPkg/EmuVariableFvbRuntimeDxe/Fvb.inf\r
295INF MdeModulePkg/Universal/FaultTolerantWriteDxe/FaultTolerantWriteDxe.inf\r
296INF MdeModulePkg/Universal/Variable/RuntimeDxe/VariableRuntimeDxe.inf\r
297\r
0a4019ec
MX
298#\r
299# EFI_CC_MEASUREMENT_PROTOCOL\r
300#\r
301INF OvmfPkg/IntelTdx/TdTcg2Dxe/TdTcg2Dxe.inf\r
302\r
44a53a3b
MX
303################################################################################\r
304\r
305[FV.FVMAIN_COMPACT]\r
306FvNameGuid = 48DB5E17-707C-472D-91CD-1613E7EF51B0\r
307FvAlignment = 16\r
308ERASE_POLARITY = 1\r
309MEMORY_MAPPED = TRUE\r
310STICKY_WRITE = TRUE\r
311LOCK_CAP = TRUE\r
312LOCK_STATUS = TRUE\r
313WRITE_DISABLED_CAP = TRUE\r
314WRITE_ENABLED_CAP = TRUE\r
315WRITE_STATUS = TRUE\r
316WRITE_LOCK_CAP = TRUE\r
317WRITE_LOCK_STATUS = TRUE\r
318READ_DISABLED_CAP = TRUE\r
319READ_ENABLED_CAP = TRUE\r
320READ_STATUS = TRUE\r
321READ_LOCK_CAP = TRUE\r
322READ_LOCK_STATUS = TRUE\r
323\r
324FILE FV_IMAGE = 9E21FD93-9C72-4c15-8C4B-E77F1DB2D792 {\r
325 SECTION GUIDED EE4E5898-3914-4259-9D6E-DC7BD79403CF PROCESSING_REQUIRED = TRUE {\r
326 #\r
327 # These firmware volumes will have files placed in them uncompressed,\r
328 # and then both firmware volumes will be compressed in a single\r
329 # compression operation in order to achieve better overall compression.\r
330 #\r
331 SECTION FV_IMAGE = DXEFV\r
332 }\r
333 }\r
334\r
335# !include OvmfPkg/FvmainCompactScratchEnd.fdf.inc\r
336\r
337################################################################################\r
338\r
339[Rule.Common.SEC]\r
340 FILE SEC = $(NAMED_GUID) {\r
341 PE32 PE32 $(INF_OUTPUT)/$(MODULE_NAME).efi\r
342 UI STRING ="$(MODULE_NAME)" Optional\r
343 VERSION STRING ="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
344 }\r
345\r
346[Rule.Common.DXE_CORE]\r
347 FILE DXE_CORE = $(NAMED_GUID) {\r
348 PE32 PE32 $(INF_OUTPUT)/$(MODULE_NAME).efi\r
349 UI STRING="$(MODULE_NAME)" Optional\r
350 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
351 }\r
352\r
353[Rule.Common.DXE_DRIVER]\r
354 FILE DRIVER = $(NAMED_GUID) {\r
355 DXE_DEPEX DXE_DEPEX Optional $(INF_OUTPUT)/$(MODULE_NAME).depex\r
356 PE32 PE32 $(INF_OUTPUT)/$(MODULE_NAME).efi\r
357 UI STRING="$(MODULE_NAME)" Optional\r
358 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
359 RAW ACPI Optional |.acpi\r
360 RAW ASL Optional |.aml\r
361 }\r
362\r
363[Rule.Common.DXE_RUNTIME_DRIVER]\r
364 FILE DRIVER = $(NAMED_GUID) {\r
365 DXE_DEPEX DXE_DEPEX Optional $(INF_OUTPUT)/$(MODULE_NAME).depex\r
366 PE32 PE32 $(INF_OUTPUT)/$(MODULE_NAME).efi\r
367 UI STRING="$(MODULE_NAME)" Optional\r
368 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
369 }\r
370\r
371[Rule.Common.UEFI_DRIVER]\r
372 FILE DRIVER = $(NAMED_GUID) {\r
373 DXE_DEPEX DXE_DEPEX Optional $(INF_OUTPUT)/$(MODULE_NAME).depex\r
374 PE32 PE32 $(INF_OUTPUT)/$(MODULE_NAME).efi\r
375 UI STRING="$(MODULE_NAME)" Optional\r
376 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
377 }\r
378\r
379[Rule.Common.UEFI_DRIVER.BINARY]\r
380 FILE DRIVER = $(NAMED_GUID) {\r
381 DXE_DEPEX DXE_DEPEX Optional |.depex\r
382 PE32 PE32 |.efi\r
383 UI STRING="$(MODULE_NAME)" Optional\r
384 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
385 }\r
386\r
387[Rule.Common.UEFI_APPLICATION]\r
388 FILE APPLICATION = $(NAMED_GUID) {\r
389 PE32 PE32 $(INF_OUTPUT)/$(MODULE_NAME).efi\r
390 UI STRING="$(MODULE_NAME)" Optional\r
391 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
392 }\r
393\r
394[Rule.Common.UEFI_APPLICATION.BINARY]\r
395 FILE APPLICATION = $(NAMED_GUID) {\r
396 PE32 PE32 |.efi\r
397 UI STRING="$(MODULE_NAME)" Optional\r
398 VERSION STRING="$(INF_VERSION)" Optional BUILD_NUM=$(BUILD_NUMBER)\r
399 }\r
400\r
401[Rule.Common.USER_DEFINED.CSM]\r
402 FILE FREEFORM = $(NAMED_GUID) {\r
403 RAW BIN |.bin\r
404 }\r
405\r
406[Rule.Common.SEC.RESET_VECTOR]\r
407 FILE RAW = $(NAMED_GUID) {\r
408 RAW BIN Align = 16 |.bin\r
409 }\r