36 Commits

Author SHA1 Message Date
BrentHoltsclaw abb0f3231f Fix ia32cfg verbose error
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-04 14:04:28 -07:00
BrentHoltsclaw c390e0378a requested changes
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-04 09:17:56 -07:00
BrentHoltsclaw 30312c7905 Cleanup ia32cfg modules
Cleanup of imports
Enabled check per thread

Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-09-04 09:17:56 -07:00
Frinzell f0e0410788 Optimize a check 2019-09-03 11:13:21 -07:00
Frinzell 288b4d3e32 Updates to memlock 2019-09-03 11:13:21 -07:00
BrentHoltsclaw 6fccb31877 Fixup spd_wd to work with python3
Signed-off-by: BrentHoltsclaw <brent.holtsclaw@intel.com>
2019-08-16 14:19:26 -07:00
BrentHoltsclaw 2efeda4345 Merge python3-rc2 branch into master (#656) 2019-08-15 14:11:20 -07:00
Erik Bjorge f4408c5cf8 Adding case for PRMRR Base/Mask set to zero.
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-07-23 11:12:53 -07:00
Jesse Michael cbb6ea45c0 Use logger functions instead of print and set self.res before returning in case of error 2019-06-13 13:15:25 -07:00
Jesse Michael 6fa21fc97c If SPD_WD is not set, fail the check if SPDs only are detected, informational message otherwise 2019-06-13 13:15:25 -07:00
Jesse Michael 1f52d84777 Add vulnerability check to verify that SPD Write Disable bit in SMBus controller bit is set 2019-06-13 13:15:25 -07:00
Erik Bjorge fe6513ff73 Only validate registers defined in platform
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-05-29 09:33:19 -07:00
Erik Bjorge ed5e424d28 Cleaned up some of the module documenation.
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-03-05 17:25:06 -08:00
Erik Bjorge 2cb3e7b8a2 STIBP may not be enabled by default by the OS.
The OS may choose to only enable STIBP in specific situations to
reduce the performance impact. An OS may also choosed to only
enable STIBP for specific processes or by using an opt-in setting.
It should not be assumed that STIBP will be enabled on all logical
processors.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-03-01 12:09:18 -08:00
Erik Bjorge 9a580d4649 Updated test to check for register definition in is_supported.
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2019-02-04 10:04:08 -08:00
BrentHoltsclaw c37c3b852e Enabling OSX support for common modules and update install
Functionality was added, but the modules were never updated.
2019-01-09 11:00:39 -08:00
Erik Bjorge 2ff813db77 Skip SGX test when not supported by processor
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-12-13 16:56:25 -08:00
Frinzell d074b65114 Minor format updates to memlock 2018-12-13 16:55:51 -08:00
Erik Bjorge 7ec76d865e Added section breaks in test
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-13 15:09:22 -08:00
Erik Bjorge d5b8526399 Clean up SGX test results to match CHIPSEC module expectations
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-13 15:09:22 -08:00
Erik Bjorge 31764f0538 Update test to check controls and not specific registers
This test has been updated to use controls.  The test should check that
the control exists and not a specific register.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-12 15:43:38 -08:00
Erik Bjorge 80a306cc92 Fixed formatting issues in doc strings.
- Removed non-ASCII character
- Removed tab characters
- Removed extra blank line in documentation

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-11-11 19:15:00 -08:00
Jesse Michael d3f7cfd70a Add support for checking if ME Manufacturing Mode is enabled based on publicly-available info in coreboot repo (#452)
https://github.com/coreboot/coreboot/blob/master/src/southbridge/intel/lynxpoint/me.h
https://github.com/coreboot/coreboot/blob/master/src/southbridge/intel/lynxpoint/me_status.c
2018-10-09 13:55:35 -07:00
Erik Bjorge 25d4531aa3 Adding test for WRSDIS being set in SPI controller
Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-10-03 11:29:56 -07:00
Aaron Frinzell 2633197646 Minor updates to sgx_check 2018-09-10 10:17:41 -07:00
DCG RED TEAM 61f3d7831e adding MSR register to xml and check on debug register in sgx module 2018-08-22 13:26:49 -07:00
Sushmith Hiremath 45b50782c9 Module to check SGX configuration and capabilities 2018-05-21 18:02:05 -07:00
Erik Bjorge 73a2d47d5b Memlock workaround for Atom processors on UEFI Shell
When accessing this MSR from the UEFI Shell the system will hang.
Skipping this test when running on Atom processors.

Signed-off-by: Erik Bjorge <erik.c.bjorge@intel.com>
2018-05-21 18:01:15 -07:00
Alex 792b9d4a28 add memlock module (#356)
* add memlock module

* moved MSR to config file
2018-02-22 19:40:37 -08:00
c7zero dd66ef454a Added new module checking for Spectre variant 2
The module checks if system includes hardware mitigations for
Speculative Execution Side Channel. Specifically, it verifies that the
system supports CPU mitigations for
Branch Target Injection vulnerability a.k.a. Spectre Variant 2
(CVE-2017-5715)
2018-01-18 14:08:33 -08:00
Erik Bjorge e8b8ce6651 Adding SPI Access test.
This test checks the SPI Flash region access permissions programmed in
the flash descriptor.
2017-08-30 14:52:21 -07:00
Takaaki Fukai 3f8d612b56 Fix the range check in bios_wp.py 2017-07-24 09:26:56 -07:00
c7zero 5102229c6a Workaround for module errors on macOS (#184)
- added is_macos()
- calling is_macos in modules which require functionality not yet
implemented by osx helper such as MSR, port IO and EFI variables
- added EFI_supported always returning False in osx helper to skip
modules requiring EFI runtime API
2017-03-18 10:39:18 -07:00
Andrew Furtak 14904f35e6 RWE helper added. SMRR support check added where required. HyperV workaround for SMRR msrs. 2017-02-22 13:07:36 -08:00
Thiébaud Weksteen 1a284132f8 Use HALBase for all HAL modules (#124) 2016-11-17 23:21:26 -08:00
abazhaniuk 94fe7f02f1 change setup.py build driver by default. change root directory of chipsec. move WARNING.txt to chipsec. remove PKG-INFO (#107) 2016-10-18 18:19:42 -07:00