From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mga17.intel.com (mga17.intel.com [192.55.52.151]) by mx.groups.io with SMTP id smtpd.web12.561.1577774662173275928 for ; Mon, 30 Dec 2019 22:44:22 -0800 Authentication-Results: mx.groups.io; dkim=missing; spf=pass (domain: intel.com, ip: 192.55.52.151, mailfrom: jiewen.yao@intel.com) X-Amp-Result: SKIPPED(no attachment in message) X-Amp-File-Uploaded: False Received: from fmsmga005.fm.intel.com ([10.253.24.32]) by fmsmga107.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 30 Dec 2019 22:44:21 -0800 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.69,378,1571727600"; d="scan'208";a="419160576" Received: from jyao1-mobl2.ccr.corp.intel.com ([10.254.209.225]) by fmsmga005.fm.intel.com with ESMTP; 30 Dec 2019 22:44:19 -0800 From: "Yao, Jiewen" To: devel@edk2.groups.io Cc: Jian J Wang , Chao Zhang Subject: [PATCH 0/6] TCG: Add TCG PFP rev 105 and 800-155 event support. Date: Tue, 31 Dec 2019 14:44:06 +0800 Message-Id: <20191231064412.22988-1-jiewen.yao@intel.com> X-Mailer: git-send-email 2.19.2.windows.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit REF: https://bugzilla.tianocore.org/show_bug.cgi?id=2439 This patch series adds TCG PFP rev 105 and 800-155 event support. TCG published Platform Firmware Profile spec revision 105 (https://trustedcomputinggroup.org/wp-content/uploads/TCG_PCClient_PFP_r1p05_05_3feb20.pdf) and Firmware Integrity Measurement spec (https://trustedcomputinggroup.org/wp-content/uploads/TCG_PC_Client-FIM_v1r24_3feb20.pdf) 2 major impact to the BIOS: 1) Need add 800-155 event at the beginning of the TCG2 event log. 2) Need use EV_EFI_PLATFORM_FIRMWARE_BLOB2 to replace EV_EFI_PLATFORM_FIRMWARE_BLOB and use EV_EFI_HANDOFF_TABLES2 to replace EV_EFI_HANDOFF_TABLES. TCG2 DXE update: Add 800-155 event handling. TCG2 PEI update: Use EV_EFI_PLATFORM_FIRMWARE_BLOB2. Smbios Update: Use EV_EFI_HANDOFF_TABLES2. This patch series is tested on EmulatorPkg with TPM2 simulator. (https://github.com/jyao1/edk2/tree/feature_tpm_emulator). The new entries - 800-155 event, EV_EFI_PLATFORM_FIRMWARE_BLOB2, EV_EFI_HANDOFF_TABLES2, can be dumpped with UEFI Tcg2DumpLog tool. (https://github.com/jyao1/EdkiiShellTool/tree/master/EdkiiShellToolPkg/Tcg2DumpLog) NOTE: To support the full 800-155 requirement in TCG, a platform need report the platform specific 800-155 event. If the platform chooses to report in PEI, it can refer to the example at https://github.com/jyao1/edk2/tree/feature_tpm_emulator/EmulatorPkg/Tpm2/Platform800155EventPei. If the platform chooses to report in DXE, it can refer to the example at https://github.com/jyao1/edk2/tree/feature_tpm_emulator/EmulatorPkg/Tpm2/Platform800155EventDxe. Multiple 800-155 events are support. Cc: Jian J Wang Cc: Chao Zhang Signed-off-by: Jiewen Yao Jiewen Yao (6): SecurityPkg/Guid: Add TCG 800-155 event GUID definition. SecurityPkg/Tcg2Dxe: Add Tcg2Dxe to support 800-155 event. MdeModulePkg/Smbios: Done measure Smbios multiple times. MdeModulePkg/dec: add PcdTcgPfpMeasurementRevision PCD MdeModulePkg/Smbios: Add TCG PFP rev 105 support. SecurityPkg/Tcg2Pei: Add TCG PFP 105 support. MdeModulePkg/MdeModulePkg.dec | 8 + .../SmbiosMeasurementDxe.c | 39 ++++- .../SmbiosMeasurementDxe.inf | 3 + SecurityPkg/Include/Guid/TcgEventHob.h | 11 ++ SecurityPkg/SecurityPkg.dec | 4 + SecurityPkg/Tcg/Tcg2Dxe/Tcg2Dxe.c | 157 ++++++++++++++---- SecurityPkg/Tcg/Tcg2Dxe/Tcg2Dxe.inf | 1 + SecurityPkg/Tcg/Tcg2Pei/Tcg2Pei.c | 91 +++++++++- SecurityPkg/Tcg/Tcg2Pei/Tcg2Pei.inf | 2 + 9 files changed, 273 insertions(+), 43 deletions(-) -- 2.19.2.windows.1