Commit Graph

89 Commits

Author SHA1 Message Date
BrentHoltsclaw 71bb8103b6 Update is_supported to not run if bootscript is not found
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-12-05 15:51:13 -08:00
BrentHoltsclaw 6be52acec2 Remove smbios bios_version module
The module is currently not stable and causing issues.  Given it is an Informational Check, it is being removed for the time being.
Similar functionality exists within chipsec util.

Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-11-18 15:23:45 -08:00
Erik Bjorge 40ff7cffbf Get extended BIOS R/W access information
Use the Flash Descriptor Observability registers to OR in the settings
from the flash descriptor to the existing FRAP register fields.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-11-18 15:13:59 -08:00
nick 6817e43149 remap module not applicable for atom 2019-11-18 15:12:19 -08:00
Erik Bjorge 736871e5f9 Adding initial SMBIOS support (#722)
* Initial SMBIOS HAL and Command

- Only searches for the Entry Point structure
- Currently only detects 2.x structures correctly

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Added support for 64bit 3.x entry point

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Updated command processing

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Added ability to parse structures based on header

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Updated command processing

- Made command processing a bit more flexible
- Improved logging messages
- Added place holders for future functionality

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Added ability to get structures by type

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Added string extraction support

- Also added some initial code for decoding type 0 structure information
- Updated interface to make things cleaner

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Added decode support

- Only supports partial decode of Type 0 (2.0) structure

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Removed unused variable

- Also fixed tool name in timing string

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Adding basic BIOS Information module

- Adding module to get the BIOS Information SMBIOS data

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>

* Python 3 updates

- Requires additional Python 3 UEFI HAL changes

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-10-31 14:17:47 -07:00
Erik Bjorge c2f13379e7 Fixing Python 3 bug
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-10-24 14:11:06 -07:00
Erik Bjorge af7fdb6d37 Fixing imports and __init__ function
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-10-24 14:11:06 -07:00
Frinzell 7eafa42649 Minor typo in debugenabled 2019-10-21 13:12:05 -07:00
Erik Bjorge d5c4d234c9 Adding CPU Info module
This new module just displays general CPU data.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-10-21 13:11:00 -07:00
BrentHoltsclaw b38d1e02f0 Fix import error and cleanup imports for tools.secureboot.te
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-24 12:23:01 -07:00
BrentHoltsclaw b1bfb491a7 Satisfy unittest errors
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-24 12:22:28 -07:00
BrentHoltsclaw e7f23c76b6 Fixup lgtm module errors
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-24 12:22:28 -07:00
BrentHoltsclaw eb7d40e23c Remove dumpstr from tools.secureboot.te
Function is unused and causing build/install errors within py2

Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-17 15:26:30 -07:00
BrentHoltsclaw abb0f3231f Fix ia32cfg verbose error
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-04 14:04:28 -07:00
BrentHoltsclaw c390e0378a requested changes
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-04 09:17:56 -07:00
BrentHoltsclaw 30312c7905 Cleanup ia32cfg modules
Cleanup of imports
Enabled check per thread

Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-04 09:17:56 -07:00
Frinzell f0e0410788 Optimize a check 2019-09-03 11:13:21 -07:00
Frinzell 288b4d3e32 Updates to memlock 2019-09-03 11:13:21 -07:00
BrentHoltsclaw 877ecb1ad8 Fixes to make uefivar_fuzz python3 compatible
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-03 10:06:46 -07:00
BrentHoltsclaw 4ce1127743 Add cs_input to fix compatability issues with input/raw_input
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-03 10:06:46 -07:00
BrentHoltsclaw 3827ec6b7e Fix setup.py install errors
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-03 10:06:46 -07:00
BrentHoltsclaw 6fccb31877 Fixup spd_wd to work with python3
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-08-16 14:19:26 -07:00
BrentHoltsclaw 73485556d7 Cleanup bugs - Division compliant with python3
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-08-16 14:19:02 -07:00
BrentHoltsclaw 18827a8574 Cleanup use is for None type compare
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-08-16 14:18:47 -07:00
BrentHoltsclaw 2efeda4345 Merge python3-rc2 branch into master (#656) 2019-08-15 14:11:20 -07:00
BrentHoltsclaw abf3f627e6 Cleanup of debug_cleanup module
Removed hardcoded offsets

Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-07-23 11:13:19 -07:00
Erik Bjorge f4408c5cf8 Adding case for PRMRR Base/Mask set to zero.
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-07-23 11:12:53 -07:00
Jesse Michael cbb6ea45c0 Use logger functions instead of print and set self.res before returning in case of error 2019-06-13 13:15:25 -07:00
Jesse Michael 6fa21fc97c If SPD_WD is not set, fail the check if SPDs only are detected, informational message otherwise 2019-06-13 13:15:25 -07:00
Jesse Michael 1f52d84777 Add vulnerability check to verify that SPD Write Disable bit in SMBus controller bit is set 2019-06-13 13:15:25 -07:00
nha 95b9d51273 using primitives for variable Name,Attribute,Data fields 2019-05-31 12:40:21 -07:00
Erik Bjorge fe6513ff73 Only validate registers defined in platform
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-05-29 09:33:19 -07:00
Erik Bjorge 989db9f8b8 Updated messages in sinkhole tool
Some additional information was requested to make the failure/success cases more clear.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-05-23 14:47:01 -07:00
BrentHoltsclaw 789314a142 Normalizing logging for various sections of chipsec:
HAL now only use logger().HAL
helpers now only use logger.DEBUG
modules now only use logger.VERBOSE
2019-04-25 14:19:08 -07:00
Nathaniel Mitchell 221e524c51 Added check to see if S3 Boot script was found
If the S3 boot script was not found, it will tell the user that instead of giving a false error.

Signed-off-by: Nathaniel Mitchell <nathaniel.p.mitchell@intel.com>
2019-04-18 08:32:49 -07:00
Erik Bjorge 5d3541c005 Additional documentation fixes
- Remove warnings when processing doc strings
- Fix some formatting issues

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-03-05 17:25:06 -08:00
Erik Bjorge ed5e424d28 Cleaned up some of the module documenation.
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-03-05 17:25:06 -08:00
Erik Bjorge 2cb3e7b8a2 STIBP may not be enabled by default by the OS.
The OS may choose to only enable STIBP in specific situations to
reduce the performance impact. An OS may also choosed to only
enable STIBP for specific processes or by using an opt-in setting.
It should not be assumed that STIBP will be enabled on all logical
processors.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-03-01 12:09:18 -08:00
Erik Bjorge 9a580d4649 Updated test to check for register definition in is_supported.
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-02-04 10:04:08 -08:00
BrentHoltsclaw c37c3b852e Enabling OSX support for common modules and update install
Functionality was added, but the modules were never updated.
2019-01-09 11:00:39 -08:00
Erik Bjorge 2ff813db77 Skip SGX test when not supported by processor
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-12-13 16:56:25 -08:00
Frinzell d074b65114 Minor format updates to memlock 2018-12-13 16:55:51 -08:00
Erik Bjorge 0446d1583a Add code to only check registers defined by the platform
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-13 15:10:05 -08:00
Erik Bjorge 7ec76d865e Added section breaks in test
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-13 15:09:22 -08:00
Erik Bjorge d5b8526399 Clean up SGX test results to match CHIPSEC module expectations
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-13 15:09:22 -08:00
Erik Bjorge 31764f0538 Update test to check controls and not specific registers
This test has been updated to use controls.  The test should check that
the control exists and not a specific register.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-12 15:43:38 -08:00
Erik Bjorge 80a306cc92 Fixed formatting issues in doc strings.
- Removed non-ASCII character
- Removed tab characters
- Removed extra blank line in documentation

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-11 19:15:00 -08:00
Erik Bjorge 525a3fe7b3 Updated link to HackingTeam UEFI Rootkit
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-10-29 13:30:31 -07:00
Jesse Michael d3f7cfd70a Add support for checking if ME Manufacturing Mode is enabled based on publicly-available info in coreboot repo (#452)
https://github.com/coreboot/coreboot/blob/master/src/southbridge/intel/lynxpoint/me.h
https://github.com/coreboot/coreboot/blob/master/src/southbridge/intel/lynxpoint/me_status.c
2018-10-09 13:55:35 -07:00
Erik Bjorge 1ea5ea3c04 Adding LoJax to UEFI module blacklist
More information about LoJax can be found at this link.
https://www.welivesecurity.com/2018/09/27/lojax-first-uefi-rootkit-found-wild-courtesy-sednit-group/

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-10-03 11:30:25 -07:00