1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
|
/** @file
Produced the Monotonic Counter Services as defined in the DXE CIS.
Copyright (c) 2006, Intel Corporation
All rights reserved. This program and the accompanying materials
are licensed and made available under the terms and conditions of the BSD License
which accompanies this distribution. The full text of the license may be found at
http://opensource.org/licenses/bsd-license.php
THE PROGRAM IS DISTRIBUTED UNDER THE BSD LICENSE ON AN "AS IS" BASIS,
WITHOUT WARRANTIES OR REPRESENTATIONS OF ANY KIND, EITHER EXPRESS OR IMPLIED.
**/
#include "MonotonicCounter.h"
//
// The Monotonic Counter Handle
//
EFI_HANDLE mMonotonicCounterHandle = NULL;
//
// The current Monotonic count value
//
UINT64 mEfiMtc;
//
// Event to use to update the Mtc's high part when wrapping
//
EFI_EVENT mEfiMtcEvent;
//
// EfiMtcName - Variable name of the MTC value
//
CHAR16 *mEfiMtcName = (CHAR16 *) L"MTC";
//
// EfiMtcGuid - Guid of the MTC value
//
EFI_GUID mEfiMtcGuid = { 0xeb704011, 0x1402, 0x11d3, { 0x8e, 0x77, 0x0, 0xa0, 0xc9, 0x69, 0x72, 0x3b } };
//
// Worker functions
//
STATIC
EFI_STATUS
EFIAPI
MonotonicCounterDriverGetNextMonotonicCount (
OUT UINT64 *Count
)
/*++
Routine Description:
Arguments:
Returns:
--*/
{
EFI_TPL OldTpl;
//
// Can not be called after ExitBootServices()
//
if (EfiAtRuntime ()) {
return EFI_UNSUPPORTED;
}
//
// Check input parameters
//
if (Count == NULL) {
return EFI_INVALID_PARAMETER;
}
//
// Update the monotonic counter with a lock
//
OldTpl = gBS->RaiseTPL (TPL_HIGH_LEVEL);
*Count = mEfiMtc;
mEfiMtc++;
gBS->RestoreTPL (OldTpl);
//
// If the MSB bit of the low part toggled, then signal that the high
// part needs updated now
//
if ((((UINT32) mEfiMtc) ^ ((UINT32) *Count)) & 0x80000000) {
gBS->SignalEvent (mEfiMtcEvent);
}
return EFI_SUCCESS;
}
/**
Returns the next high 32 bits of the platform's monotonic counter.
The GetNextHighMonotonicCount() function returns the next high 32 bits
of the platform's monotonic counter. The platform's monotonic counter is
comprised of two 32 bit quantities: the high 32 bits and the low 32 bits.
During boot service time the low 32 bit value is volatile: it is reset to
zero on every system reset and is increased by 1 on every call to GetNextMonotonicCount().
The high 32 bit value is non-volatile and is increased by 1 whenever the system resets
or whenever the low 32 bit count [returned by GetNextMonoticCount()] overflows.
The GetNextMonotonicCount() function is only available at boot services time.
If the operating system wishes to extend the platform monotonic counter to runtime,
it may do so by utilizing GetNextHighMonotonicCount(). To do this, before calling
ExitBootServices() the operating system would call GetNextMonotonicCount() to obtain
the current platform monotonic count. The operating system would then provide an
interface that returns the next count by:
Adding 1 to the last count.
Before the lower 32 bits of the count overflows, call GetNextHighMonotonicCount().
This will increase the high 32 bits of the platform's non-volatile portion of the monotonic
count by 1.
This function may only be called at Runtime.
@param[out] HighCount Pointer to returned value.
@retval EFI_INVALID_PARAMETER If HighCount is NULL.
@retval EFI_SUCCESS Operation is successful.
@retval EFI_OUT_OF_RESOURCES If variable service reports that not enough storage
is available to hold the variable and its data.
@retval EFI_DEVICE_ERROR The variable could not be saved due to a hardware failure.
**/
STATIC
EFI_STATUS
EFIAPI
MonotonicCounterDriverGetNextHighMonotonicCount (
OUT UINT32 *HighCount
)
/*++
Routine Description:
Arguments:
Returns:
--*/
{
EFI_TPL OldTpl;
//
// Check input parameters
//
if (HighCount == NULL) {
return EFI_INVALID_PARAMETER;
}
if (!EfiAtRuntime ()) {
//
// Use a lock if called before ExitBootServices()
//
OldTpl = gBS->RaiseTPL (TPL_HIGH_LEVEL);
*HighCount = (UINT32) RShiftU64 (mEfiMtc, 32) + 1;
mEfiMtc = LShiftU64 (*HighCount, 32);
gBS->RestoreTPL (OldTpl);
} else {
*HighCount = (UINT32) RShiftU64 (mEfiMtc, 32) + 1;
mEfiMtc = LShiftU64 (*HighCount, 32);
}
//
// Update the NvRam store to match the new high part
//
return EfiSetVariable (
mEfiMtcName,
&mEfiMtcGuid,
EFI_VARIABLE_NON_VOLATILE | EFI_VARIABLE_RUNTIME_ACCESS | EFI_VARIABLE_BOOTSERVICE_ACCESS,
sizeof (UINT32),
HighCount
);
}
STATIC
VOID
EFIAPI
EfiMtcEventHandler (
IN EFI_EVENT Event,
IN VOID *Context
)
/*++
Routine Description:
Monotonic count event handler. This handler updates the high monotonic count.
Arguments:
Event The event to handle
Context The event context
Returns:
EFI_SUCCESS The event has been handled properly
EFI_NOT_FOUND An error occurred updating the variable.
--*/
{
UINT32 HighCount;
MonotonicCounterDriverGetNextHighMonotonicCount (&HighCount);
}
EFI_STATUS
EFIAPI
MonotonicCounterDriverInitialize (
IN EFI_HANDLE ImageHandle,
IN EFI_SYSTEM_TABLE *SystemTable
)
/*++
Routine Description:
Arguments:
(Standard EFI Image entry - EFI_IMAGE_ENTRY_POINT)
Returns:
--*/
{
EFI_STATUS Status;
UINT32 HighCount;
UINTN BufferSize;
//
// Make sure the Monotonic Counter Architectural Protocol is not already installed in the system
//
ASSERT_PROTOCOL_ALREADY_INSTALLED (NULL, &gEfiMonotonicCounterArchProtocolGuid);
//
// Initialize event to handle overflows
//
Status = gBS->CreateEvent (
EVT_NOTIFY_SIGNAL,
TPL_CALLBACK,
EfiMtcEventHandler,
NULL,
&mEfiMtcEvent
);
ASSERT_EFI_ERROR (Status);
//
// Read the last high part
//
BufferSize = sizeof (UINT32);
Status = EfiGetVariable (
mEfiMtcName,
&mEfiMtcGuid,
NULL,
&BufferSize,
&HighCount
);
if (EFI_ERROR (Status)) {
HighCount = 0;
}
//
// Set the current value
//
mEfiMtc = LShiftU64 (HighCount, 32);
//
// Increment the upper 32 bits for this boot
// Continue even if it fails. It will only fail if the variable services are
// not functional.
//
Status = MonotonicCounterDriverGetNextHighMonotonicCount (&HighCount);
//
// Fill in the EFI Boot Services and EFI Runtime Services Monotonic Counter Fields
//
gBS->GetNextMonotonicCount = MonotonicCounterDriverGetNextMonotonicCount;
gRT->GetNextHighMonotonicCount = MonotonicCounterDriverGetNextHighMonotonicCount;
//
// Install the Monotonic Counter Architctural Protocol onto a new handle
//
Status = gBS->InstallMultipleProtocolInterfaces (
&mMonotonicCounterHandle,
&gEfiMonotonicCounterArchProtocolGuid,
NULL,
NULL
);
ASSERT_EFI_ERROR (Status);
return EFI_SUCCESS;
}
|