The series is also available at:

V5 changes:
For patch 11, as suggested by Star:
* Refine the UpdateLockBox() API description comment to be more precise;
* Ensure the parameter for macro 'EFI_SIZE_TO_PAGES' is of type 'UINTN';

Since the changes are minor, I still keep the origin 'Reviewed-by' from
Ray and the 'Acked-by' tag from Laszlo.

For patch 12, sync the UpdateLockBox() API description comment with the
change made in patch 11.

Since the changes are minor, I still keep the origin 'Reviewed-by' from
Laszlo an Ray.

For patch 13, additional handling logic to prevent NULL pointer
de-reference, just as what has been done in commit

V4 history:

As suggested by Laszlo, add a new patch to sync the API description
comment for UpdateLockBox() in file
"OvmfPkg/Library/LockBoxLib/LockBoxLib.c" with its counterparts in

For patch 13 (compared with patch 12 in V3), minor type refinement in
structure definition 'OPAL_DEVICE_LOCKBOX_DATA'.

V3 history:

For patch 2, reuse the definitions within AtaPassThru protocol header file
to reduce code duplication.

For patch 4, add detailed comments to illustrate the content that will be
stored in the newly introduced LockBox.

For patch 6, device path validity check refinement within function

For patch 7:
* Remove a redundant check within function NvmeS3SkipThisController();
* Replace internal implementation of GetNextDevicePathInstance() with
  GetDevicePathInstanceSize(), which avoids unnecessary memory allocation.

For patch 8:
* Device path validity check refinement within function
* Remove a redundant check within function AhciS3GetEumeratePorts();
* Replace internal implementation of GetNextDevicePathInstance() with
  GetDevicePathInstanceSize(), which avoids unnecessary memory allocation.

For patch 11:
* Remove the ASSERT() for memory allocation failure. Since error handling
  codes already exist, no new code is added for this;
* Refine the codes to only allocate new SMM buffer when the required
  LockBox size is greater than the size of origin pages allocated;
* Add additional parameter check for 'Offset' & 'Length' to prevent
  potential numeric overflow.

V2 history:

For patch 8, the new series removes the codes to produce the Block IO PPIs
from the AhciPei driver.

The task to produce the Block IO services is out of the scope of BZ-1409
(actually covered by BZ-1483). And we will later propose seperate patch(s)
to address this.

V1 history:

For the below 2 types of storage device:

1. NVM Express devices;
2. ATA hard disk devices working under AHCI mode.

the OpalPassword driver supports auto-unlocking those devices during S3

Current implementation of the OpalPassword driver is handling the device
initialization (using boot script to restore the host controller PCI
configuration space also counts) in the PEI phase during S3 resume by

Meanwhile, the NvmExpressPei driver in MdeModulePkg also handles the NVME
device initialization during the PEI phase in order to produce the Block

Moreover, there is a Bugzilla request (BZ-1483) for adding the Block IO
PPI support for ATA device as well. So there is likely to be an PEI driver
for ATA device that will handle the ATA device initialization.

In order to remove code duplication, the series will split the S3 phase
device initialization related codes out from the OpalPassword driver. And
let the existing NvmExpressPei driver and the new AhciPei driver to handle
the task.

After this remodel, NvmExpressPei and AhciPei drivers will produce a PPI
called Storage Security Command PPI. And the OpalPassword driver will
consume this PPI to perform the device auto-unlock in S3 resume.

Patch   1~4: Add the definitions of PPIs and GUIDs;
Patch     5: Refinement for the NvmExpressPei driver;
Patch   6~7: Update the NvmExpressPei driver to produce the PPI needed by
Patch     8: Add the Ahci mode ATA device support in the PEI phase, it
             will produce the PPI needed by OpalPassword;
Patch  9~10: Refinements for the SmmLockBoxLib;
Patch    11: Support LockBox enlarge for LockBoxLib API UpdateLockBox();
Patch    12: Remove the hardware initialization codes from the
             OpalPassword driver. And consume the SSC PPI to unlock device
             in S3 resume.

Cc: Jian J Wang <>
Cc: Ray Ni <>
Cc: Eric Dong <>
Cc: Star Zeng <>
Cc: Chao Zhang <>
Cc: Jiewen Yao <>
Cc: Laszlo Ersek <>

Hao Wu (12):
  MdeModulePkg: Add definitions for ATA AHCI host controller PPI
  MdeModulePkg: Add definitions for EDKII PEI ATA PassThru PPI
  MdeModulePkg: Add definitions for Storage Security Command PPI
  MdeModulePkg: Add GUID for LockBox to save storage dev to init in S3
  MdeModulePkg/NvmExpressPei: Avoid updating the module-level variable
  MdeModulePkg/NvmExpressPei: Add logic to produce SSC PPI
  MdeModulePkg/NvmExpressPei: Consume S3StorageDeviceInitList LockBox
  MdeModulePkg/AhciPei: Add AHCI mode ATA device support in PEI
  MdeModulePkg/SmmLockBoxLib: Use 'DEBUG_' prefix instead of 'EFI_D_'
  MdeModulePkg/SmmLockBox(PEI): Remove an ASSERT in RestoreLockBox()
  MdeModulePkg/SmmLockBoxLib: Support LockBox enlarge in UpdateLockBox()
  OvmfPkg/LockBoxLib: Update the comments for API UpdateLockBox()
  SecurityPkg/OpalPassword: Remove HW init codes and consume SSC PPI

 MdeModulePkg/MdeModulePkg.dec                                     |   12 +
 MdeModulePkg/MdeModulePkg.dsc                                     |    1 +
 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.inf                          |   74 +
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPei.inf              |   18 +-
 SecurityPkg/Tcg/Opal/OpalPassword/OpalPasswordDxe.inf             |    6 +-
 SecurityPkg/Tcg/Opal/OpalPassword/OpalPasswordPei.inf             |   12 +-
 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.h                            |  708 
 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiPassThru.h                    |  184 ++
 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiStorageSecurity.h             |  247 +++
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPei.h                |  106 +-
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPeiHci.h             |   20 +-
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPeiStorageSecurity.h |  247 +++
 MdeModulePkg/Include/Guid/S3StorageDeviceInitList.h               |   64 +
 MdeModulePkg/Include/Library/LockBoxLib.h                         |    7 +-
 MdeModulePkg/Include/Ppi/AtaAhciController.h                      |   89 +
 MdeModulePkg/Include/Ppi/AtaPassThru.h                            |  219 +++
 MdeModulePkg/Include/Ppi/StorageSecurityCommand.h                 |  283 +++
 SecurityPkg/Tcg/Opal/OpalPassword/OpalAhciMode.h                  |  412 ----
 SecurityPkg/Tcg/Opal/OpalPassword/OpalDriver.h                    |    4 +-
 SecurityPkg/Tcg/Opal/OpalPassword/OpalNvmeMode.h                  |  327 ----
 SecurityPkg/Tcg/Opal/OpalPassword/OpalNvmeReg.h                   |  815 
 SecurityPkg/Tcg/Opal/OpalPassword/OpalPasswordCommon.h            |   45 +-
 SecurityPkg/Tcg/Opal/OpalPassword/OpalPasswordPei.h               |  106 +-
 MdeModulePkg/Bus/Ata/AhciPei/AhciMode.c                           | 2015 
 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.c                            |  304 +++
 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiPassThru.c                    |  521 +++++
 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiS3.c                          |  139 ++
 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiStorageSecurity.c             |  391 ++++
 MdeModulePkg/Bus/Ata/AhciPei/DevicePath.c                         |  284 +++
 MdeModulePkg/Bus/Ata/AhciPei/DmaMem.c                             |  270 +++
 MdeModulePkg/Bus/Pci/NvmExpressPei/DevicePath.c                   |  284 +++
 MdeModulePkg/Bus/Pci/NvmExpressPei/DmaMem.c                       |  153 +-
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPei.c                |  166 +-
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPeiHci.c             |   32 +-
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPeiS3.c              |  114 ++
 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPeiStorageSecurity.c |  423 ++++
 MdeModulePkg/Library/LockBoxNullLib/LockBoxNullLib.c              |    7 +-
 MdeModulePkg/Library/SmmLockBoxLib/SmmLockBoxDxeLib.c             |   27 +-
 MdeModulePkg/Library/SmmLockBoxLib/SmmLockBoxPeiLib.c             |   32 +-
 MdeModulePkg/Library/SmmLockBoxLib/SmmLockBoxSmmLib.c             |  148 +-
 OvmfPkg/Library/LockBoxLib/LockBoxLib.c                           |   11 +-
 SecurityPkg/Tcg/Opal/OpalPassword/OpalAhciMode.c                  | 1282 
 SecurityPkg/Tcg/Opal/OpalPassword/OpalDriver.c                    |  416 ++--
 SecurityPkg/Tcg/Opal/OpalPassword/OpalNvmeMode.c                  | 1823 
 SecurityPkg/Tcg/Opal/OpalPassword/OpalPasswordPei.c               |  757 
 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.uni                          |   21 +
 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiExtra.uni                     |   19 +
 47 files changed, 7755 insertions(+), 5890 deletions(-)
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.inf
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.h
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiPassThru.h
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiStorageSecurity.h
 create mode 100644 
 create mode 100644 MdeModulePkg/Include/Guid/S3StorageDeviceInitList.h
 create mode 100644 MdeModulePkg/Include/Ppi/AtaAhciController.h
 create mode 100644 MdeModulePkg/Include/Ppi/AtaPassThru.h
 create mode 100644 MdeModulePkg/Include/Ppi/StorageSecurityCommand.h
 delete mode 100644 SecurityPkg/Tcg/Opal/OpalPassword/OpalAhciMode.h
 delete mode 100644 SecurityPkg/Tcg/Opal/OpalPassword/OpalNvmeMode.h
 delete mode 100644 SecurityPkg/Tcg/Opal/OpalPassword/OpalNvmeReg.h
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciMode.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiPassThru.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiS3.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiStorageSecurity.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/DevicePath.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/DmaMem.c
 create mode 100644 MdeModulePkg/Bus/Pci/NvmExpressPei/DevicePath.c
 create mode 100644 MdeModulePkg/Bus/Pci/NvmExpressPei/NvmExpressPeiS3.c
 create mode 100644 
 delete mode 100644 SecurityPkg/Tcg/Opal/OpalPassword/OpalAhciMode.c
 delete mode 100644 SecurityPkg/Tcg/Opal/OpalPassword/OpalNvmeMode.c
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPei.uni
 create mode 100644 MdeModulePkg/Bus/Ata/AhciPei/AhciPeiExtra.uni


edk2-devel mailing list

Reply via email to