mirror of
https://github.com/chipsec/chipsec
synced 2026-06-08 13:31:00 +00:00
0654edca19
Revision 1.2.0 -------------- This version includes the following new or updated modules: #. Merged common.secureboot.keys module into common.secureboot.variables module #. Updated tools.secureboot.te module to be able to test PE/TE issue on Linux or UEFI shell #. Updated tools.smm.smm_ptr module This version includes the following updates: #. Added the *controls* abstraction. Modules are encouraged to use ``get_control`` and ``set_control`` when interacting with platform registers. This permits greater flexibility in case the register that controls a given feature or configuration changes between platform generations. The controls are defined in the platform XML file. At this time, only a small number of controls are defined. We plan to move existing modules over to this new mechanism. #. Added XML Schema for the XML configuration files #. Support for reading, writing, and listing UEFI variables from the UEFI Shell environment has been added. #. Added support for decompression while SPI flash parsing via ``decode`` or ``uefi decode`` commands in Linux #. Added basic ACPI table parsing to HAL (RSDP, RSDT/XSDT, APIC, DMAR) #. Added UEFI tables searching and parsing to HAL (EFI system table, runtime services table, boot services table, DXE services table, EFI configuration table) #. Added DIMM Serial Presence Detect (SPD) ROM dumping and parsing to HAL #. Added ``uefi s3bootscript`` command parsing the S3 boot script to chipsec_util.py #. Added virtual-to-physical address translation function to Linux/EFI/Windows helpers #. Added support of server platforms (Haswell server and Ivy Town) to chipset.py This version has the following known issues: #. Decompression of images in SPI flash parsing is not available in UEFI shell. #. When calling alloc_phys_mem, the argument to set maximum physical address (max_pa) for allocation is ignored on linux. A message will be printed in dmesg if the allocation is above the max_pa that is passed in, but the call will return anyway. #. UEFI Shell environment does not support ``cpuid`` or ``get_thread_count``. There are functions that simply warn that they are not supported. #. Size of PCIEXBAR (MMCFG) is calculated incorrectly
100 lines
3.6 KiB
Python
100 lines
3.6 KiB
Python
#!/usr/local/bin/python
|
|
#CHIPSEC: Platform Security Assessment Framework
|
|
#Copyright (c) 2010-2015, Intel Corporation
|
|
#
|
|
#This program is free software; you can redistribute it and/or
|
|
#modify it under the terms of the GNU General Public License
|
|
#as published by the Free Software Foundation; Version 2.
|
|
#
|
|
#This program is distributed in the hope that it will be useful,
|
|
#but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
#MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
#GNU General Public License for more details.
|
|
#
|
|
#You should have received a copy of the GNU General Public License
|
|
#along with this program; if not, write to the Free Software
|
|
#Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
|
|
#
|
|
#Contact information:
|
|
#chipsec@intel.com
|
|
#
|
|
|
|
|
|
|
|
__version__ = '1.0'
|
|
|
|
import os
|
|
import sys
|
|
import time
|
|
|
|
import chipsec_util
|
|
|
|
from chipsec.logger import *
|
|
from chipsec.file import *
|
|
|
|
from chipsec.hal.ucode import Ucode, dump_ucode_update_header
|
|
|
|
# ###################################################################
|
|
#
|
|
# Microcode patches
|
|
#
|
|
# ###################################################################
|
|
def ucode(argv):
|
|
"""
|
|
>>> chipsec_util ucode id|load|decode [ucode_update_file (in .PDB or .BIN format)] [cpu_id]
|
|
|
|
Examples:
|
|
|
|
>>> chipsec_util ucode id
|
|
>>> chipsec_util ucode load ucode.bin 0
|
|
>>> chipsec_util ucode decode ucode.pdb
|
|
"""
|
|
if 3 > len(argv):
|
|
print ucode.__doc__
|
|
return
|
|
|
|
ucode_op = argv[2]
|
|
t = time.time()
|
|
|
|
if ( 'load' == ucode_op ):
|
|
if (4 == len(argv)):
|
|
ucode_filename = argv[3]
|
|
logger().log( "[CHIPSEC] Loading Microcode update on all cores from '%s'" % ucode_filename )
|
|
chipsec_util._cs.ucode.update_ucode_all_cpus( ucode_filename )
|
|
elif (5 == len(argv)):
|
|
ucode_filename = argv[3]
|
|
cpu_thread_id = int(argv[4],16)
|
|
logger().log( "[CHIPSEC] Loading Microcode update on CPU%d from '%s'" % (cpu_thread_id, ucode_filename) )
|
|
chipsec_util._cs.ucode.update_ucode( cpu_thread_id, ucode_filename )
|
|
else:
|
|
print ucode.__doc__
|
|
return
|
|
elif ( 'decode' == ucode_op ):
|
|
if (4 == len(argv)):
|
|
ucode_filename = argv[3]
|
|
if (not ucode_filename.endswith('.pdb')):
|
|
logger().log( "[CHIPSEC] Ucode update file is not PDB file: '%s'" % ucode_filename )
|
|
return
|
|
pdb_ucode_buffer = read_file( ucode_filename )
|
|
logger().log( "[CHIPSEC] Decoding Microcode Update header of PDB file: '%s'" % ucode_filename )
|
|
dump_ucode_update_header( pdb_ucode_buffer )
|
|
elif ( 'id' == ucode_op ):
|
|
if (3 == len(argv)):
|
|
for tid in range(chipsec_util._cs.msr.get_cpu_thread_count()):
|
|
ucode_update_id = chipsec_util._cs.ucode.ucode_update_id( tid )
|
|
logger().log( "[CHIPSEC] CPU%d: Microcode update ID = 0x%08X" % (tid, ucode_update_id) )
|
|
elif (4 == len(argv)):
|
|
cpu_thread_id = int(argv[3],16)
|
|
ucode_update_id = chipsec_util._cs.ucode.ucode_update_id( cpu_thread_id )
|
|
logger().log( "[CHIPSEC] CPU%d: Microcode update ID = 0x%08X" % (cpu_thread_id, ucode_update_id) )
|
|
else:
|
|
logger().error( "unknown command-line option '%.32s'" % ucode_op )
|
|
print ucode.__doc__
|
|
return
|
|
|
|
logger().log( "[CHIPSEC] (ucode) time elapsed %.3f" % (time.time()-t) )
|
|
|
|
|
|
|
|
chipsec_util.commands['ucode'] = {'func' : ucode, 'start_driver' : True, 'help' : ucode.__doc__ }
|