2 This library is intended to be used by BDS modules.
3 This library will execute TPM2 request.
5 Copyright (c) 2015 - 2018, Intel Corporation. All rights reserved.<BR>
6 SPDX-License-Identifier: BSD-2-Clause-Patent
10 #ifndef _TCG2_PHYSICAL_PRESENCE_LIB_H_
11 #define _TCG2_PHYSICAL_PRESENCE_LIB_H_
13 #include <IndustryStandard/Tpm20.h>
14 #include <IndustryStandard/TcgPhysicalPresence.h>
15 #include <Protocol/Tcg2Protocol.h>
18 // UEFI TCG2 library definition bit of the BIOS TPM Management Flags
21 #define TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_CLEAR BIT1
23 #define TCG2_LIB_PP_FLAG_RESET_TRACK BIT3
24 #define TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_TURN_ON BIT4
25 #define TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_TURN_OFF BIT5
26 #define TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_CHANGE_EPS BIT6
27 #define TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_CHANGE_PCRS BIT7
30 // UEFI TCG2 library definition bit of the BIOS Information Flags
32 #define TCG2_BIOS_INFORMATION_FLAG_HIERARCHY_CONTROL_STORAGE_DISABLE BIT8
33 #define TCG2_BIOS_INFORMATION_FLAG_HIERARCHY_CONTROL_ENDORSEMENT_DISABLE BIT9
36 // UEFI TCG2 library definition bit of the BIOS Storage Management Flags
38 #define TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_PP_REQUIRED_FOR_ENABLE_BLOCK_SID BIT16
39 #define TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_PP_REQUIRED_FOR_DISABLE_BLOCK_SID BIT17
40 #define TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_ENABLE_BLOCK_SID BIT18
45 #define TCG2_BIOS_TPM_MANAGEMENT_FLAG_DEFAULT (TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_TURN_OFF | \
46 TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_CLEAR | \
47 TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_CHANGE_EPS | \
48 TCG2_BIOS_TPM_MANAGEMENT_FLAG_PP_REQUIRED_FOR_CHANGE_PCRS)
53 #define TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_DEFAULT (TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_PP_REQUIRED_FOR_ENABLE_BLOCK_SID | \
54 TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_PP_REQUIRED_FOR_DISABLE_BLOCK_SID |\
55 TCG2_BIOS_STORAGE_MANAGEMENT_FLAG_ENABLE_BLOCK_SID)
58 Check and execute the pending TPM request.
60 The TPM request may come from OS or BIOS. This API will display request information and wait
61 for user confirmation if TPM request exists. The TPM request will be sent to TPM device after
62 the TPM request is confirmed, and one or more reset may be required to make TPM request to
65 This API should be invoked after console in and console out are all ready as they are required
66 to display request information and get user input to confirm the request.
68 @param PlatformAuth platform auth value. NULL means no platform auth change.
72 Tcg2PhysicalPresenceLibProcessRequest (
73 IN TPM2B_AUTH
*PlatformAuth OPTIONAL
77 Check if the pending TPM request needs user input to confirm.
79 The TPM request may come from OS. This API will check if TPM request exists and need user
80 input to confirmation.
82 @retval TRUE TPM needs input to confirm user physical presence.
83 @retval FALSE TPM doesn't need input to confirm user physical presence.
88 Tcg2PhysicalPresenceLibNeedUserConfirm (
93 Return TPM2 ManagementFlags set by PP interface.
95 @retval ManagementFlags TPM2 Management Flags.
99 Tcg2PhysicalPresenceLibGetManagementFlags (
104 The handler for TPM physical presence function:
105 Return TPM Operation Response to OS Environment.
107 This API should be invoked in OS runtime phase to interface with ACPI method.
109 @param[out] MostRecentRequest Most recent operation request.
110 @param[out] Response Response to the most recent operation request.
112 @return Return Code for Return TPM Operation Response to OS Environment.
116 Tcg2PhysicalPresenceLibReturnOperationResponseToOsFunction (
117 OUT UINT32
*MostRecentRequest
,
122 The handler for TPM physical presence function:
123 Submit TPM Operation Request to Pre-OS Environment and
124 Submit TPM Operation Request to Pre-OS Environment 2.
126 This API should be invoked in OS runtime phase to interface with ACPI method.
128 Caution: This function may receive untrusted input.
130 @param[in, out] Pointer to OperationRequest TPM physical presence operation request.
131 @param[in, out] Pointer to RequestParameter TPM physical presence operation request parameter.
133 @return Return Code for Submit TPM Operation Request to Pre-OS Environment and
134 Submit TPM Operation Request to Pre-OS Environment 2.
137 Tcg2PhysicalPresenceLibSubmitRequestToPreOSFunctionEx (
138 IN OUT UINT32
*OperationRequest
,
139 IN OUT UINT32
*RequestParameter
143 The handler for TPM physical presence function:
144 Submit TPM Operation Request to Pre-OS Environment and
145 Submit TPM Operation Request to Pre-OS Environment 2.
147 This API should be invoked in OS runtime phase to interface with ACPI method.
149 Caution: This function may receive untrusted input.
151 @param[in] OperationRequest TPM physical presence operation request.
152 @param[in] RequestParameter TPM physical presence operation request parameter.
154 @return Return Code for Submit TPM Operation Request to Pre-OS Environment and
155 Submit TPM Operation Request to Pre-OS Environment 2.
159 Tcg2PhysicalPresenceLibSubmitRequestToPreOSFunction (
160 IN UINT32 OperationRequest
,
161 IN UINT32 RequestParameter
165 The handler for TPM physical presence function:
166 Get User Confirmation Status for Operation.
168 This API should be invoked in OS runtime phase to interface with ACPI method.
170 Caution: This function may receive untrusted input.
172 @param[in] OperationRequest TPM physical presence operation request.
174 @return Return Code for Get User Confirmation Status for Operation.
178 Tcg2PhysicalPresenceLibGetUserConfirmationStatusFunction (
179 IN UINT32 OperationRequest