From: Jagadeesh Ujja <jagadeesh.ujja@arm.com>
To: edk2-devel@lists.01.org, liming.gao@intel.com,
chao.b.zhang@intel.com, lersek@readhat.com,
leif.lindholm@linaro.org, ard.biesheuvel@linaro.org
Subject: [RFC PATCH v2 00/11] Extend secure variable service to be usable from Standalone MM
Date: Tue, 27 Nov 2018 16:56:15 +0530 [thread overview]
Message-ID: <20181127112626.7854-1-jagadeesh.ujja@arm.com> (raw)
Changes since v1:
- Addressed all the comments from Liming Gao
- Removed the use of #ifdef/#else/#endif and used a Pcd instead to
select between MM and non-MM paths.
- Removed all dependencies on edk2-platforms.
- Dropped the use of mMmst and used gSmst instead.
- Added a dummy implementation UefiRuntimeServiceTableLib for
MM_STANDALONE usage
- Replaced all uses of AsmLfence with MemoryFence from variable
service code.
- Add a new StandaloneMmRuntimeDxe library to for use by non-MM code.
This RFC patch series extends the existing secure variable service support
for use with Standalone MM. This is applicable to paltforms that use
Standalone Management Mode to protect access to non-volatile memory (NOR
flash in case of these patches) used to store the secure EFI variables.
The first patch pulls in additional libraries from the staging branch of
StandaloneMmPkg into the edk2's StandaloneMmPkg. The existing secure
variable service implementation supports only the traditional MM mode
and so the rest of the patches extends the existing secure variable
service support to be useable with Standalone MM mode as well.
This patch series is being posted as an RFC to get feedback on the
approach taken in these patches.
Jagadeesh Ujja (11):
MdeModulePkg/Variable: replace all uses of AsmLfence with MemoryFence
StandaloneMmPkg: Pull in additonal libraries from staging branch
MdeModulePkg/Library: Add StandaloneMmRuntimeDxe library
ArmPlatformPkg/NorFlashDxe: allow reusability as a MM driver
MdeModulePkg/FaultTolerantWriteDxe: allow reusability as a MM driver
MdeModulePkg/Variable/RuntimeDxe: adapt for usability with MM
Standalone
MdeModulePkg/Variable/RuntimeDxe: adapt as a MM Standalone driver
SecurityPkg/AuthVariableLib: allow MM_STANDALONE drivers to use this
library
MdeModulePkg/VarCheckLib: allow MM_STANDALONE drivers to use this
library
CryptoPkg/BaseCryptLib: allow MM_STANDALONE drivers to use this
library
CryptoPkg/BaseCryptLib: Hack to get time in MM Standalone mode
.../Drivers/NorFlashDxe/NorFlashDxe.inf | 3 +
.../NorFlashDxe/NorFlashStandaloneMm.inf | 76 ++
.../Library/BaseCryptLib/BaseCryptLib.inf | 8 +-
.../Library/BaseCryptLib/RuntimeCryptLib.inf | 5 +
.../StandaloneMmRuntimeDxe.inf | 43 +
.../Library/VarCheckLib/VarCheckLib.inf | 5 +-
.../FaultTolerantWriteDxe.inf | 2 +
.../FaultTolerantWriteStandaloneMm.inf | 102 +++
.../RuntimeDxe/VariableRuntimeDxe.inf | 2 +
.../RuntimeDxe/VariableSmmRuntimeDxe.inf | 4 +
.../RuntimeDxe/VariableStandaloneMm.inf | 132 +++
.../AuthVariableLib/AuthVariableLib.inf | 5 +-
.../StandaloneMmCoreHobLib.inf | 2 +-
.../StandaloneMmHobLib/StandaloneMmHobLib.inf | 48 +
.../StandaloneMmMemoryAllocationLib.inf | 45 +
.../StandaloneMmServicesTableLib.inf | 36 +
.../Drivers/NorFlashDxe/NorFlashDxe.h | 5 +-
.../Include/Library/StandaloneMmRuntimeDxe.h | 39 +
.../Library/StandaloneMmServicesTableLib.h | 47 +
.../Drivers/NorFlashDxe/NorFlashBlockIoDxe.c | 2 +-
.../Drivers/NorFlashDxe/NorFlashDxe.c | 211 ++++-
.../Drivers/NorFlashDxe/NorFlashFvbDxe.c | 96 +-
.../BaseCryptLib/SysCall/TimerWrapper.c | 27 +-
.../StandaloneMmRuntimeDxe.c | 36 +
.../FaultTolerantWriteSmm.c | 207 +++--
.../UpdateWorkingBlock.c | 27 +-
.../Variable/RuntimeDxe/LoadFenceSmm.c | 2 +-
.../Universal/Variable/RuntimeDxe/Variable.c | 37 +-
.../Variable/RuntimeDxe/VariableSmm.c | 201 ++++-
.../RuntimeDxe/VariableSmmRuntimeDxe.c | 31 +-
MdePkg/Library/BaseLib/X86MemoryFence.c | 2 +-
.../AArch64/StandaloneMmCoreHobLibInternal.c | 64 ++
.../StandaloneMmHobLib/StandaloneMmHobLib.c | 655 ++++++++++++++
.../StandaloneMmMemoryAllocationLib.c | 824 ++++++++++++++++++
.../StandaloneMmServicesTableLib.c | 64 ++
35 files changed, 2860 insertions(+), 235 deletions(-)
create mode 100644 ArmPlatformPkg/Drivers/NorFlashDxe/NorFlashStandaloneMm.inf
create mode 100644 MdeModulePkg/Library/StandaloneMmRuntimeDxe/StandaloneMmRuntimeDxe.inf
create mode 100644 MdeModulePkg/Universal/FaultTolerantWriteDxe/FaultTolerantWriteStandaloneMm.inf
create mode 100644 MdeModulePkg/Universal/Variable/RuntimeDxe/VariableStandaloneMm.inf
create mode 100644 StandaloneMmPkg/Library/StandaloneMmHobLib/StandaloneMmHobLib.inf
create mode 100644 StandaloneMmPkg/Library/StandaloneMmMemoryAllocationLib/StandaloneMmMemoryAllocationLib.inf
create mode 100644 StandaloneMmPkg/Library/StandaloneMmServicesTableLib/StandaloneMmServicesTableLib.inf
create mode 100644 MdeModulePkg/Include/Library/StandaloneMmRuntimeDxe.h
create mode 100644 StandaloneMmPkg/Include/Library/StandaloneMmServicesTableLib.h
create mode 100644 MdeModulePkg/Library/StandaloneMmRuntimeDxe/StandaloneMmRuntimeDxe.c
create mode 100644 StandaloneMmPkg/Library/StandaloneMmHobLib/AArch64/StandaloneMmCoreHobLibInternal.c
create mode 100644 StandaloneMmPkg/Library/StandaloneMmHobLib/StandaloneMmHobLib.c
create mode 100644 StandaloneMmPkg/Library/StandaloneMmMemoryAllocationLib/StandaloneMmMemoryAllocationLib.c
create mode 100644 StandaloneMmPkg/Library/StandaloneMmServicesTableLib/StandaloneMmServicesTableLib.c
--
2.19.1
next reply other threads:[~2018-11-27 11:26 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-11-27 11:26 Jagadeesh Ujja [this message]
2018-11-27 11:26 ` [RFC PATCH v2 01/11] MdeModulePkg/Variable: replace all uses of AsmLfence with MemoryFence Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 02/11] StandaloneMmPkg: Pull in additonal libraries from staging branch Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 03/11] MdeModulePkg/Library: Add StandaloneMmRuntimeDxe library Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 04/11] ArmPlatformPkg/NorFlashDxe: allow reusability as a MM driver Jagadeesh Ujja
2018-11-27 11:52 ` Leif Lindholm
2018-11-27 11:26 ` [RFC PATCH v2 05/11] MdeModulePkg/FaultTolerantWriteDxe: " Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 06/11] MdeModulePkg/Variable/RuntimeDxe: adapt for usability with MM Standalone Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 07/11] MdeModulePkg/Variable/RuntimeDxe: adapt as a MM Standalone driver Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 08/11] SecurityPkg/AuthVariableLib: allow MM_STANDALONE drivers to use this library Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 09/11] MdeModulePkg/VarCheckLib: " Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 10/11] CryptoPkg/BaseCryptLib: " Jagadeesh Ujja
2018-11-27 11:26 ` [RFC PATCH v2 11/11] CryptoPkg/BaseCryptLib: Hack to get time in MM Standalone mode Jagadeesh Ujja
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-list from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20181127112626.7854-1-jagadeesh.ujja@arm.com \
--to=devel@edk2.groups.io \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox