2 This module implements TCG EFI Protocol.
4 Copyright (c) 2005 - 2012, Intel Corporation. All rights reserved.<BR>
5 This program and the accompanying materials
6 are licensed and made available under the terms and conditions of the BSD License
7 which accompanies this distribution. The full text of the license may be found at
8 http://opensource.org/licenses/bsd-license.php
10 THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
11 WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
16 #include <IndustryStandard/Tpm12.h>
17 #include <IndustryStandard/Acpi.h>
18 #include <IndustryStandard/PeImage.h>
19 #include <IndustryStandard/SmBios.h>
21 #include <Guid/GlobalVariable.h>
22 #include <Guid/SmBios.h>
23 #include <Guid/HobList.h>
24 #include <Guid/TcgEventHob.h>
25 #include <Guid/EventGroup.h>
26 #include <Protocol/DevicePath.h>
27 #include <Protocol/TcgService.h>
28 #include <Protocol/AcpiTable.h>
30 #include <Library/DebugLib.h>
31 #include <Library/BaseMemoryLib.h>
32 #include <Library/UefiRuntimeServicesTableLib.h>
33 #include <Library/UefiDriverEntryPoint.h>
34 #include <Library/HobLib.h>
35 #include <Library/UefiBootServicesTableLib.h>
36 #include <Library/BaseLib.h>
37 #include <Library/MemoryAllocationLib.h>
38 #include <Library/PrintLib.h>
39 #include <Library/TpmCommLib.h>
40 #include <Library/PcdLib.h>
41 #include <Library/UefiLib.h>
45 #define EFI_TCG_LOG_AREA_SIZE 0x10000
49 typedef struct _EFI_TCG_CLIENT_ACPI_TABLE
{
50 EFI_ACPI_DESCRIPTION_HEADER Header
;
53 EFI_PHYSICAL_ADDRESS Lasa
;
54 } EFI_TCG_CLIENT_ACPI_TABLE
;
56 typedef struct _EFI_TCG_SERVER_ACPI_TABLE
{
57 EFI_ACPI_DESCRIPTION_HEADER Header
;
61 EFI_PHYSICAL_ADDRESS Lasa
;
68 EFI_ACPI_3_0_GENERIC_ADDRESS_STRUCTURE BaseAddress
;
70 EFI_ACPI_3_0_GENERIC_ADDRESS_STRUCTURE ConfigAddress
;
75 } EFI_TCG_SERVER_ACPI_TABLE
;
79 #define TCG_DXE_DATA_FROM_THIS(this) \
80 BASE_CR (this, TCG_DXE_DATA, TcgProtocol)
82 typedef struct _TCG_DXE_DATA
{
83 EFI_TCG_PROTOCOL TcgProtocol
;
84 TCG_EFI_BOOT_SERVICE_CAPABILITY BsCap
;
85 EFI_TCG_CLIENT_ACPI_TABLE
*TcgClientAcpiTable
;
86 EFI_TCG_SERVER_ACPI_TABLE
*TcgServerAcpiTable
;
89 TIS_TPM_HANDLE TpmHandle
;
94 EFI_TCG_CLIENT_ACPI_TABLE mTcgClientAcpiTemplate
= {
96 EFI_ACPI_3_0_TRUSTED_COMPUTING_PLATFORM_ALLIANCE_CAPABILITIES_TABLE_SIGNATURE
,
97 sizeof (mTcgClientAcpiTemplate
),
100 // Compiler initializes the remaining bytes to 0
101 // These fields should be filled in in production
104 0, // 0 for PC Client Platform Class
105 0, // Log Area Max Length
106 (EFI_PHYSICAL_ADDRESS
) (SIZE_4GB
- 1) // Log Area Start Address
110 // The following EFI_TCG_SERVER_ACPI_TABLE default setting is just one example,
111 // the TPM device connectes to LPC, and also defined the ACPI _UID as 0xFF,
112 // this _UID can be changed and should match with the _UID setting of the TPM
113 // ACPI device object
115 EFI_TCG_SERVER_ACPI_TABLE mTcgServerAcpiTemplate
= {
117 EFI_ACPI_3_0_TRUSTED_COMPUTING_PLATFORM_ALLIANCE_CAPABILITIES_TABLE_SIGNATURE
,
118 sizeof (mTcgServerAcpiTemplate
),
121 // Compiler initializes the remaining bytes to 0
122 // These fields should be filled in in production
125 1, // 1 for Server Platform Class
127 0, // Log Area Max Length
128 (EFI_PHYSICAL_ADDRESS
) (SIZE_4GB
- 1), // Log Area Start Address
129 0x0100, // TCG Specification revision 1.0
131 0, // Interrupt Flags
133 {0}, // Reserved 3 bytes
134 0, // Global System Interrupt
136 EFI_ACPI_3_0_SYSTEM_MEMORY
,
140 TPM_BASE_ADDRESS
// Base Address
143 {0}, // Configuration Address
144 0xFF, // ACPI _UID value of the device, can be changed for different platforms
145 0, // ACPI _UID value of the device, can be changed for different platforms
146 0, // ACPI _UID value of the device, can be changed for different platforms
147 0 // ACPI _UID value of the device, can be changed for different platforms
150 UINTN mBootAttempts
= 0;
151 CHAR16 mBootVarName
[] = L
"BootOrder";
154 This service provides EFI protocol capability information, state information
155 about the TPM, and Event Log state information.
157 @param[in] This Indicates the calling context
158 @param[out] ProtocolCapability The callee allocates memory for a TCG_BOOT_SERVICE_CAPABILITY
159 structure and fills in the fields with the EFI protocol
160 capability information and the current TPM state information.
161 @param[out] TCGFeatureFlags This is a pointer to the feature flags. No feature
162 flags are currently defined so this parameter
163 MUST be set to 0. However, in the future,
164 feature flags may be defined that, for example,
165 enable hash algorithm agility.
166 @param[out] EventLogLocation This is a pointer to the address of the event log in memory.
167 @param[out] EventLogLastEntry If the Event Log contains more than one entry,
168 this is a pointer to the address of the start of
169 the last entry in the event log in memory.
171 @retval EFI_SUCCESS Operation completed successfully.
172 @retval EFI_INVALID_PARAMETER ProtocolCapability does not match TCG capability.
178 IN EFI_TCG_PROTOCOL
*This
,
179 OUT TCG_EFI_BOOT_SERVICE_CAPABILITY
*ProtocolCapability
,
180 OUT UINT32
*TCGFeatureFlags
,
181 OUT EFI_PHYSICAL_ADDRESS
*EventLogLocation
,
182 OUT EFI_PHYSICAL_ADDRESS
*EventLogLastEntry
185 TCG_DXE_DATA
*TcgData
;
187 TcgData
= TCG_DXE_DATA_FROM_THIS (This
);
189 if (ProtocolCapability
!= NULL
) {
190 *ProtocolCapability
= TcgData
->BsCap
;
193 if (TCGFeatureFlags
!= NULL
) {
194 *TCGFeatureFlags
= 0;
197 if (EventLogLocation
!= NULL
) {
198 if (PcdGet8 (PcdTpmPlatformClass
) == TCG_PLATFORM_TYPE_CLIENT
) {
199 *EventLogLocation
= TcgData
->TcgClientAcpiTable
->Lasa
;
201 *EventLogLocation
= TcgData
->TcgServerAcpiTable
->Lasa
;
205 if (EventLogLastEntry
!= NULL
) {
206 if (TcgData
->BsCap
.TPMDeactivatedFlag
) {
207 *EventLogLastEntry
= (EFI_PHYSICAL_ADDRESS
)(UINTN
)0;
209 *EventLogLastEntry
= (EFI_PHYSICAL_ADDRESS
)(UINTN
)TcgData
->LastEvent
;
217 This service abstracts the capability to do a hash operation on a data buffer.
219 @param[in] This Indicates the calling context
220 @param[in] HashData Pointer to the data buffer to be hashed
221 @param[in] HashDataLen Length of the data buffer to be hashed
222 @param[in] AlgorithmId Identification of the Algorithm to use for the hashing operation
223 @param[in, out] HashedDataLen Resultant length of the hashed data
224 @param[in, out] HashedDataResult Resultant buffer of the hashed data
226 @retval EFI_SUCCESS Operation completed successfully.
227 @retval EFI_INVALID_PARAMETER HashDataLen is NULL.
228 @retval EFI_INVALID_PARAMETER HashDataLenResult is NULL.
229 @retval EFI_OUT_OF_RESOURCES Cannot allocate buffer of size *HashedDataLen.
230 @retval EFI_UNSUPPORTED AlgorithmId not supported.
231 @retval EFI_BUFFER_TOO_SMALL *HashedDataLen < sizeof (TCG_DIGEST).
237 IN EFI_TCG_PROTOCOL
*This
,
239 IN UINT64 HashDataLen
,
240 IN TCG_ALGORITHM_ID AlgorithmId
,
241 IN OUT UINT64
*HashedDataLen
,
242 IN OUT UINT8
**HashedDataResult
245 if (HashedDataLen
== NULL
|| HashedDataResult
== NULL
) {
246 return EFI_INVALID_PARAMETER
;
249 switch (AlgorithmId
) {
251 if (*HashedDataLen
== 0) {
252 *HashedDataLen
= sizeof (TPM_DIGEST
);
253 *HashedDataResult
= AllocatePool ((UINTN
) *HashedDataLen
);
254 if (*HashedDataResult
== NULL
) {
255 return EFI_OUT_OF_RESOURCES
;
259 if (*HashedDataLen
< sizeof (TPM_DIGEST
)) {
260 *HashedDataLen
= sizeof (TPM_DIGEST
);
261 return EFI_BUFFER_TOO_SMALL
;
263 *HashedDataLen
= sizeof (TPM_DIGEST
);
265 if (*HashedDataResult
== NULL
) {
266 *HashedDataResult
= AllocatePool ((UINTN
) *HashedDataLen
);
269 return TpmCommHashAll (
272 (TPM_DIGEST
*)*HashedDataResult
275 return EFI_UNSUPPORTED
;
280 Add a new entry to the Event Log.
282 @param[in] TcgData TCG_DXE_DATA structure.
283 @param[in] NewEventHdr Pointer to a TCG_PCR_EVENT_HDR data structure.
284 @param[in] NewEventData Pointer to the new event data.
286 @retval EFI_SUCCESS The new event log entry was added.
287 @retval EFI_OUT_OF_RESOURCES No enough memory to log the new event.
293 IN TCG_DXE_DATA
*TcgData
,
294 IN TCG_PCR_EVENT_HDR
*NewEventHdr
,
295 IN UINT8
*NewEventData
298 if (PcdGet8 (PcdTpmPlatformClass
) == TCG_PLATFORM_TYPE_CLIENT
) {
299 TcgData
->LastEvent
= (UINT8
*)(UINTN
)TcgData
->TcgClientAcpiTable
->Lasa
;
300 return TpmCommLogEvent (
302 &TcgData
->EventLogSize
,
303 (UINTN
)TcgData
->TcgClientAcpiTable
->Laml
,
308 TcgData
->LastEvent
= (UINT8
*)(UINTN
)TcgData
->TcgServerAcpiTable
->Lasa
;
309 return TpmCommLogEvent (
311 &TcgData
->EventLogSize
,
312 (UINTN
)TcgData
->TcgServerAcpiTable
->Laml
,
320 This service abstracts the capability to add an entry to the Event Log.
322 @param[in] This Indicates the calling context
323 @param[in] TCGLogData Pointer to the start of the data buffer containing
324 the TCG_PCR_EVENT data structure. All fields in
325 this structure are properly filled by the caller.
326 @param[in, out] EventNumber The event number of the event just logged
327 @param[in] Flags Indicate additional flags. Only one flag has been
328 defined at this time, which is 0x01 and means the
329 extend operation should not be performed. All
330 other bits are reserved.
332 @retval EFI_SUCCESS Operation completed successfully.
333 @retval EFI_OUT_OF_RESOURCES Insufficient memory in the event log to complete this action.
339 IN EFI_TCG_PROTOCOL
*This
,
340 IN TCG_PCR_EVENT
*TCGLogData
,
341 IN OUT UINT32
*EventNumber
,
345 TCG_DXE_DATA
*TcgData
;
347 TcgData
= TCG_DXE_DATA_FROM_THIS (This
);
349 if (TcgData
->BsCap
.TPMDeactivatedFlag
) {
350 return EFI_DEVICE_ERROR
;
352 return TcgDxeLogEventI (
354 (TCG_PCR_EVENT_HDR
*)TCGLogData
,
360 This service is a proxy for commands to the TPM.
362 @param[in] This Indicates the calling context
363 @param[in] TpmInputParameterBlockSize Size of the TPM input parameter block
364 @param[in] TpmInputParameterBlock Pointer to the TPM input parameter block
365 @param[in] TpmOutputParameterBlockSize Size of the TPM output parameter block
366 @param[in] TpmOutputParameterBlock Pointer to the TPM output parameter block
368 @retval EFI_SUCCESS Operation completed successfully.
369 @retval EFI_INVALID_PARAMETER Invalid ordinal.
370 @retval EFI_UNSUPPORTED Current Task Priority Level >= EFI_TPL_CALLBACK.
371 @retval EFI_TIMEOUT The TIS timed-out.
376 TcgDxePassThroughToTpm (
377 IN EFI_TCG_PROTOCOL
*This
,
378 IN UINT32 TpmInputParameterBlockSize
,
379 IN UINT8
*TpmInputParameterBlock
,
380 IN UINT32 TpmOutputParameterBlockSize
,
381 IN UINT8
*TpmOutputParameterBlock
384 TCG_DXE_DATA
*TcgData
;
386 TcgData
= TCG_DXE_DATA_FROM_THIS (This
);
388 return TisPcExecute (
391 TpmInputParameterBlock
,
392 (UINTN
) TpmInputParameterBlockSize
,
393 TpmOutputParameterBlock
,
394 (UINTN
) TpmOutputParameterBlockSize
399 Do a hash operation on a data buffer, extend a specific TPM PCR with the hash result,
400 and add an entry to the Event Log.
402 @param[in] TcgData TCG_DXE_DATA structure.
403 @param[in] HashData Physical address of the start of the data buffer
404 to be hashed, extended, and logged.
405 @param[in] HashDataLen The length, in bytes, of the buffer referenced by HashData
406 @param[in, out] NewEventHdr Pointer to a TCG_PCR_EVENT_HDR data structure.
407 @param[in] NewEventData Pointer to the new event data.
409 @retval EFI_SUCCESS Operation completed successfully.
410 @retval EFI_OUT_OF_RESOURCES No enough memory to log the new event.
411 @retval EFI_DEVICE_ERROR The command was unsuccessful.
416 TcgDxeHashLogExtendEventI (
417 IN TCG_DXE_DATA
*TcgData
,
419 IN UINT64 HashDataLen
,
420 IN OUT TCG_PCR_EVENT_HDR
*NewEventHdr
,
421 IN UINT8
*NewEventData
426 if (HashDataLen
> 0) {
427 Status
= TpmCommHashAll (
432 ASSERT_EFI_ERROR (Status
);
435 Status
= TpmCommExtend (
437 &NewEventHdr
->Digest
,
438 NewEventHdr
->PCRIndex
,
441 if (!EFI_ERROR (Status
)) {
442 Status
= TcgDxeLogEventI (TcgData
, NewEventHdr
, NewEventData
);
449 This service abstracts the capability to do a hash operation on a data buffer,
450 extend a specific TPM PCR with the hash result, and add an entry to the Event Log
452 @param[in] This Indicates the calling context
453 @param[in] HashData Physical address of the start of the data buffer
454 to be hashed, extended, and logged.
455 @param[in] HashDataLen The length, in bytes, of the buffer referenced by HashData
456 @param[in] AlgorithmId Identification of the Algorithm to use for the hashing operation
457 @param[in, out] TCGLogData The physical address of the start of the data
458 buffer containing the TCG_PCR_EVENT data structure.
459 @param[in, out] EventNumber The event number of the event just logged.
460 @param[out] EventLogLastEntry Physical address of the first byte of the entry
461 just placed in the Event Log. If the Event Log was
462 empty when this function was called then this physical
463 address will be the same as the physical address of
464 the start of the Event Log.
466 @retval EFI_SUCCESS Operation completed successfully.
467 @retval EFI_UNSUPPORTED AlgorithmId != TPM_ALG_SHA.
468 @retval EFI_UNSUPPORTED Current TPL >= EFI_TPL_CALLBACK.
469 @retval EFI_DEVICE_ERROR The command was unsuccessful.
474 TcgDxeHashLogExtendEvent (
475 IN EFI_TCG_PROTOCOL
*This
,
476 IN EFI_PHYSICAL_ADDRESS HashData
,
477 IN UINT64 HashDataLen
,
478 IN TPM_ALGORITHM_ID AlgorithmId
,
479 IN OUT TCG_PCR_EVENT
*TCGLogData
,
480 IN OUT UINT32
*EventNumber
,
481 OUT EFI_PHYSICAL_ADDRESS
*EventLogLastEntry
484 TCG_DXE_DATA
*TcgData
;
486 TcgData
= TCG_DXE_DATA_FROM_THIS (This
);
488 if (TcgData
->BsCap
.TPMDeactivatedFlag
) {
489 return EFI_DEVICE_ERROR
;
492 if (AlgorithmId
!= TPM_ALG_SHA
) {
493 return EFI_UNSUPPORTED
;
496 return TcgDxeHashLogExtendEventI (
498 (UINT8
*) (UINTN
) HashData
,
500 (TCG_PCR_EVENT_HDR
*)TCGLogData
,
505 TCG_DXE_DATA mTcgDxeData
= {
510 TcgDxePassThroughToTpm
,
511 TcgDxeHashLogExtendEvent
514 sizeof (mTcgDxeData
.BsCap
),
521 &mTcgClientAcpiTemplate
,
522 &mTcgServerAcpiTemplate
,
529 Initialize the Event Log and log events passed from the PEI phase.
531 @retval EFI_SUCCESS Operation completed successfully.
532 @retval EFI_OUT_OF_RESOURCES Out of memory.
542 TCG_PCR_EVENT
*TcgEvent
;
543 EFI_PEI_HOB_POINTERS GuidHob
;
544 EFI_PHYSICAL_ADDRESS Lasa
;
546 if (PcdGet8 (PcdTpmPlatformClass
) == TCG_PLATFORM_TYPE_CLIENT
) {
547 Lasa
= mTcgClientAcpiTemplate
.Lasa
;
549 Status
= gBS
->AllocatePages (
552 EFI_SIZE_TO_PAGES (EFI_TCG_LOG_AREA_SIZE
),
555 if (EFI_ERROR (Status
)) {
558 mTcgClientAcpiTemplate
.Lasa
= Lasa
;
560 // To initialize them as 0xFF is recommended
561 // because the OS can know the last entry for that.
563 SetMem ((VOID
*)(UINTN
)mTcgClientAcpiTemplate
.Lasa
, EFI_TCG_LOG_AREA_SIZE
, 0xFF);
564 mTcgClientAcpiTemplate
.Laml
= EFI_TCG_LOG_AREA_SIZE
;
567 Lasa
= mTcgServerAcpiTemplate
.Lasa
;
569 Status
= gBS
->AllocatePages (
572 EFI_SIZE_TO_PAGES (EFI_TCG_LOG_AREA_SIZE
),
575 if (EFI_ERROR (Status
)) {
578 mTcgServerAcpiTemplate
.Lasa
= Lasa
;
580 // To initialize them as 0xFF is recommended
581 // because the OS can know the last entry for that.
583 SetMem ((VOID
*)(UINTN
)mTcgServerAcpiTemplate
.Lasa
, EFI_TCG_LOG_AREA_SIZE
, 0xFF);
584 mTcgServerAcpiTemplate
.Laml
= EFI_TCG_LOG_AREA_SIZE
;
587 GuidHob
.Raw
= GetHobList ();
588 while (!EFI_ERROR (Status
) &&
589 (GuidHob
.Raw
= GetNextGuidHob (&gTcgEventEntryHobGuid
, GuidHob
.Raw
)) != NULL
) {
590 TcgEvent
= GET_GUID_HOB_DATA (GuidHob
.Guid
);
591 GuidHob
.Raw
= GET_NEXT_HOB (GuidHob
);
592 Status
= TcgDxeLogEventI (
594 (TCG_PCR_EVENT_HDR
*)TcgEvent
,
603 Measure and log an action string, and extend the measurement result into PCR[5].
605 @param[in] String A specific string that indicates an Action event.
607 @retval EFI_SUCCESS Operation completed successfully.
608 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
617 TCG_PCR_EVENT_HDR TcgEvent
;
619 TcgEvent
.PCRIndex
= 5;
620 TcgEvent
.EventType
= EV_EFI_ACTION
;
621 TcgEvent
.EventSize
= (UINT32
)AsciiStrLen (String
);
622 return TcgDxeHashLogExtendEventI (
632 Measure and log EFI handoff tables, and extend the measurement result into PCR[1].
634 @retval EFI_SUCCESS Operation completed successfully.
635 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
640 MeasureHandoffTables (
645 SMBIOS_TABLE_ENTRY_POINT
*SmbiosTable
;
646 TCG_PCR_EVENT_HDR TcgEvent
;
647 EFI_HANDOFF_TABLE_POINTERS HandoffTables
;
649 Status
= EfiGetSystemConfigurationTable (
650 &gEfiSmbiosTableGuid
,
651 (VOID
**) &SmbiosTable
654 if (!EFI_ERROR (Status
)) {
655 ASSERT (SmbiosTable
!= NULL
);
657 TcgEvent
.PCRIndex
= 1;
658 TcgEvent
.EventType
= EV_EFI_HANDOFF_TABLES
;
659 TcgEvent
.EventSize
= sizeof (HandoffTables
);
661 HandoffTables
.NumberOfTables
= 1;
662 HandoffTables
.TableEntry
[0].VendorGuid
= gEfiSmbiosTableGuid
;
663 HandoffTables
.TableEntry
[0].VendorTable
= SmbiosTable
;
665 DEBUG ((DEBUG_INFO
, "The Smbios Table starts at: 0x%x\n", SmbiosTable
->TableAddress
));
666 DEBUG ((DEBUG_INFO
, "The Smbios Table size: 0x%x\n", SmbiosTable
->TableLength
));
668 Status
= TcgDxeHashLogExtendEventI (
670 (UINT8
*)(UINTN
)SmbiosTable
->TableAddress
,
671 SmbiosTable
->TableLength
,
673 (UINT8
*)&HandoffTables
681 Measure and log Separator event, and extend the measurement result into a specific PCR.
683 @param[in] PCRIndex PCR index.
685 @retval EFI_SUCCESS Operation completed successfully.
686 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
691 MeasureSeparatorEvent (
692 IN TPM_PCRINDEX PCRIndex
695 TCG_PCR_EVENT_HDR TcgEvent
;
699 TcgEvent
.PCRIndex
= PCRIndex
;
700 TcgEvent
.EventType
= EV_SEPARATOR
;
701 TcgEvent
.EventSize
= (UINT32
)sizeof (EventData
);
702 return TcgDxeHashLogExtendEventI (
712 Read an EFI Variable.
714 This function allocates a buffer to return the contents of the variable. The caller is
715 responsible for freeing the buffer.
717 @param[in] VarName A Null-terminated string that is the name of the vendor's variable.
718 @param[in] VendorGuid A unique identifier for the vendor.
719 @param[out] VarSize The size of the variable data.
721 @return A pointer to the buffer to return the contents of the variable.Otherwise NULL.
728 IN EFI_GUID
*VendorGuid
,
736 Status
= gRT
->GetVariable (
743 if (Status
!= EFI_BUFFER_TOO_SMALL
) {
747 VarData
= AllocatePool (*VarSize
);
748 if (VarData
!= NULL
) {
749 Status
= gRT
->GetVariable (
756 if (EFI_ERROR (Status
)) {
766 Measure and log an EFI variable, and extend the measurement result into a specific PCR.
768 @param[in] PCRIndex PCR Index.
769 @param[in] EventType Event type.
770 @param[in] VarName A Null-terminated string that is the name of the vendor's variable.
771 @param[in] VendorGuid A unique identifier for the vendor.
772 @param[in] VarData The content of the variable data.
773 @param[in] VarSize The size of the variable data.
775 @retval EFI_SUCCESS Operation completed successfully.
776 @retval EFI_OUT_OF_RESOURCES Out of memory.
777 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
783 IN TPM_PCRINDEX PCRIndex
,
784 IN TCG_EVENTTYPE EventType
,
786 IN EFI_GUID
*VendorGuid
,
792 TCG_PCR_EVENT_HDR TcgEvent
;
794 EFI_VARIABLE_DATA
*VarLog
;
796 VarNameLength
= StrLen (VarName
);
797 TcgEvent
.PCRIndex
= PCRIndex
;
798 TcgEvent
.EventType
= EventType
;
799 TcgEvent
.EventSize
= (UINT32
)(sizeof (*VarLog
) + VarNameLength
* sizeof (*VarName
) + VarSize
800 - sizeof (VarLog
->UnicodeName
) - sizeof (VarLog
->VariableData
));
802 VarLog
= (EFI_VARIABLE_DATA
*)AllocatePool (TcgEvent
.EventSize
);
803 if (VarLog
== NULL
) {
804 return EFI_OUT_OF_RESOURCES
;
807 VarLog
->VariableName
= *VendorGuid
;
808 VarLog
->UnicodeNameLength
= VarNameLength
;
809 VarLog
->VariableDataLength
= VarSize
;
813 VarNameLength
* sizeof (*VarName
)
816 (CHAR16
*)VarLog
->UnicodeName
+ VarNameLength
,
821 Status
= TcgDxeHashLogExtendEventI (
833 Read then Measure and log an EFI boot variable, and extend the measurement result into PCR[5].
835 @param[in] VarName A Null-terminated string that is the name of the vendor's variable.
836 @param[in] VendorGuid A unique identifier for the vendor.
837 @param[out] VarSize The size of the variable data.
838 @param[out] VarData Pointer to the content of the variable.
840 @retval EFI_SUCCESS Operation completed successfully.
841 @retval EFI_OUT_OF_RESOURCES Out of memory.
842 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
847 ReadAndMeasureBootVariable (
849 IN EFI_GUID
*VendorGuid
,
856 *VarData
= ReadVariable (VarName
, VendorGuid
, VarSize
);
857 if (*VarData
== NULL
) {
858 return EFI_NOT_FOUND
;
861 Status
= MeasureVariable (
863 EV_EFI_VARIABLE_BOOT
,
873 Measure and log all EFI boot variables, and extend the measurement result into a specific PCR.
875 The EFI boot variables are BootOrder and Boot#### variables.
877 @retval EFI_SUCCESS Operation completed successfully.
878 @retval EFI_OUT_OF_RESOURCES Out of memory.
879 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
884 MeasureAllBootVariables (
895 Status
= ReadAndMeasureBootVariable (
897 &gEfiGlobalVariableGuid
,
901 if (Status
== EFI_NOT_FOUND
) {
904 ASSERT (BootOrder
!= NULL
);
906 if (EFI_ERROR (Status
)) {
907 FreePool (BootOrder
);
911 BootCount
/= sizeof (*BootOrder
);
912 for (Index
= 0; Index
< BootCount
; Index
++) {
913 UnicodeSPrint (mBootVarName
, sizeof (mBootVarName
), L
"Boot%04x", BootOrder
[Index
]);
914 Status
= ReadAndMeasureBootVariable (
916 &gEfiGlobalVariableGuid
,
920 if (!EFI_ERROR (Status
)) {
921 FreePool (BootVarData
);
925 FreePool (BootOrder
);
930 Ready to Boot Event notification handler.
932 Sequence of OS boot events is measured in this event notification handler.
934 @param[in] Event Event whose notification function is being invoked
935 @param[in] Context Pointer to the notification function's context
946 TPM_PCRINDEX PcrIndex
;
948 if (mBootAttempts
== 0) {
951 // Measure handoff tables.
953 Status
= MeasureHandoffTables ();
954 if (EFI_ERROR (Status
)) {
955 DEBUG ((EFI_D_ERROR
, "HOBs not Measured. Error!\n"));
959 // Measure BootOrder & Boot#### variables.
961 Status
= MeasureAllBootVariables ();
962 if (EFI_ERROR (Status
)) {
963 DEBUG ((EFI_D_ERROR
, "Boot Variables not Measured. Error!\n"));
967 // 1. This is the first boot attempt.
969 Status
= TcgMeasureAction (
970 EFI_CALLING_EFI_APPLICATION
972 ASSERT_EFI_ERROR (Status
);
975 // 2. Draw a line between pre-boot env and entering post-boot env.
977 for (PcrIndex
= 0; PcrIndex
< 8; PcrIndex
++) {
978 Status
= MeasureSeparatorEvent (PcrIndex
);
979 ASSERT_EFI_ERROR (Status
);
983 // 3. Measure GPT. It would be done in SAP driver.
987 // 4. Measure PE/COFF OS loader. It would be done in SAP driver.
991 // 5. Read & Measure variable. BootOrder already measured.
995 // 6. Not first attempt, meaning a return from last attempt
997 Status
= TcgMeasureAction (
998 EFI_RETURNING_FROM_EFI_APPLICATOIN
1000 ASSERT_EFI_ERROR (Status
);
1003 DEBUG ((EFI_D_INFO
, "TPM TcgDxe Measure Data when ReadyToBoot\n"));
1005 // Increase boot attempt counter.
1011 Install TCG ACPI Table when ACPI Table Protocol is available.
1013 A system's firmware uses an ACPI table to identify the system's TCG capabilities
1014 to the Post-Boot environment. The information in this ACPI table is not guaranteed
1015 to be valid until the Host Platform transitions from pre-boot state to post-boot state.
1017 @param[in] Event Event whose notification function is being invoked
1018 @param[in] Context Pointer to the notification function's context
1029 EFI_ACPI_TABLE_PROTOCOL
*AcpiTable
;
1032 Status
= gBS
->LocateProtocol (&gEfiAcpiTableProtocolGuid
, NULL
, (VOID
**)&AcpiTable
);
1033 if (EFI_ERROR (Status
)) {
1037 if (PcdGet8 (PcdTpmPlatformClass
) == TCG_PLATFORM_TYPE_CLIENT
) {
1040 // The ACPI table must be checksumed before calling the InstallAcpiTable()
1041 // service of the ACPI table protocol to install it.
1043 Checksum
= CalculateCheckSum8 ((UINT8
*)&mTcgClientAcpiTemplate
, sizeof (mTcgClientAcpiTemplate
));
1044 mTcgClientAcpiTemplate
.Header
.Checksum
= Checksum
;
1046 Status
= AcpiTable
->InstallAcpiTable (
1048 &mTcgClientAcpiTemplate
,
1049 sizeof (mTcgClientAcpiTemplate
),
1055 // The ACPI table must be checksumed before calling the InstallAcpiTable()
1056 // service of the ACPI table protocol to install it.
1058 Checksum
= CalculateCheckSum8 ((UINT8
*)&mTcgServerAcpiTemplate
, sizeof (mTcgServerAcpiTemplate
));
1059 mTcgServerAcpiTemplate
.Header
.Checksum
= Checksum
;
1061 Status
= AcpiTable
->InstallAcpiTable (
1063 &mTcgServerAcpiTemplate
,
1064 sizeof (mTcgServerAcpiTemplate
),
1068 ASSERT_EFI_ERROR (Status
);
1072 Exit Boot Services Event notification handler.
1074 Measure invocation and success of ExitBootServices.
1076 @param[in] Event Event whose notification function is being invoked
1077 @param[in] Context Pointer to the notification function's context
1082 OnExitBootServices (
1090 // Measure invocation of ExitBootServices,
1092 Status
= TcgMeasureAction (
1093 EFI_EXIT_BOOT_SERVICES_INVOCATION
1095 ASSERT_EFI_ERROR (Status
);
1098 // Measure success of ExitBootServices
1100 Status
= TcgMeasureAction (
1101 EFI_EXIT_BOOT_SERVICES_SUCCEEDED
1103 ASSERT_EFI_ERROR (Status
);
1107 Get TPM Deactivated state.
1109 @param[out] TPMDeactivatedFlag Returns TPM Deactivated state.
1111 @retval EFI_SUCCESS Operation completed successfully.
1112 @retval EFI_DEVICE_ERROR The operation was unsuccessful.
1117 OUT BOOLEAN
*TPMDeactivatedFlag
1121 TPM_STCLEAR_FLAGS VFlags
;
1123 Status
= TpmCommGetFlags (
1124 mTcgDxeData
.TpmHandle
,
1125 TPM_CAP_FLAG_VOLATILE
,
1129 if (!EFI_ERROR (Status
)) {
1130 *TPMDeactivatedFlag
= VFlags
.deactivated
;
1137 The driver's entry point.
1139 It publishes EFI TCG Protocol.
1141 @param[in] ImageHandle The firmware allocated handle for the EFI image.
1142 @param[in] SystemTable A pointer to the EFI System Table.
1144 @retval EFI_SUCCESS The entry point is executed successfully.
1145 @retval other Some error occurs when executing this entry point.
1151 IN EFI_HANDLE ImageHandle
,
1152 IN EFI_SYSTEM_TABLE
*SystemTable
1159 mTcgDxeData
.TpmHandle
= (TIS_TPM_HANDLE
)(UINTN
)TPM_BASE_ADDRESS
;
1160 Status
= TisPcRequestUseTpm (mTcgDxeData
.TpmHandle
);
1161 if (EFI_ERROR (Status
)) {
1162 DEBUG ((EFI_D_ERROR
, "TPM not detected!\n"));
1166 Status
= GetTpmStatus (&mTcgDxeData
.BsCap
.TPMDeactivatedFlag
);
1167 if (EFI_ERROR (Status
)) {
1170 "Line %d in file " __FILE__
":\n "
1171 "DriverEntry: TPM not working properly\n",
1177 Status
= gBS
->InstallProtocolInterface (
1179 &gEfiTcgProtocolGuid
,
1180 EFI_NATIVE_INTERFACE
,
1181 &mTcgDxeData
.TcgProtocol
1183 if (!EFI_ERROR (Status
) && !mTcgDxeData
.BsCap
.TPMDeactivatedFlag
) {
1185 // Setup the log area and copy event log from hob list to it
1187 Status
= SetupEventLog ();
1188 ASSERT_EFI_ERROR (Status
);
1191 // Measure handoff tables, Boot#### variables etc.
1193 Status
= EfiCreateEventReadyToBootEx (
1200 Status
= gBS
->CreateEventEx (
1205 &gEfiEventExitBootServicesGuid
,
1211 // Install ACPI Table
1213 EfiCreateProtocolNotifyEvent (&gEfiAcpiTableProtocolGuid
, TPL_CALLBACK
, InstallAcpiTable
, NULL
, &Registration
);