← Documents Documentation/ABI/testing/sysfs-class-firmware-attributes GitHub 원문 ↗

Linux 6.18.37 · ABI / testing

Firmware configuration attributes sysfs ABI

공통 BIOS attribute schema, Dell·HP·Lenovo 확장, password·certificate authentication, reboot·reset·save와 HP SPM·Sure Start log ABI를 설명합니다.

Source pathDocumentation/ABI/testing/sysfs-class-firmware-attributes
Source versionLinux v6.18.37
TranslationDUJINLABS 전문 번역 + 해설

요약·해설과 원문, 전문 번역을 서로 분리했습니다. API 이름, symbol, source path는 원문 표기를 사용합니다.

1. 요약·해설

원문의 핵심 논리와 kernel programming 관점의 보충 설명입니다. 아래의 전문 번역과는 별도로 작성했습니다.

Attribute types and vendor extensions

sysfs-class-firmware-attributes:1-148

Enumeration·integer·string·ordered-list type의 공통 metadata와 Dell modifier·value modifier, HP priority list를 정의합니다.

Password and certificate authentication

sysfs-class-firmware-attributes:149-329

BIOS Admin·System·drive password session과 Dell·Lenovo·HP validation, Lenovo certificate workflow와 SPM role을 설명합니다.

Reboot, reset, save, and debug control

sysfs-class-firmware-attributes:330-430

Pending reboot 표시, BIOS reset profile, Lenovo single·bulk save mode와 vendor 권고 debug command를 제공합니다.

HP SPM and Sure Start audit data

sysfs-class-firmware-attributes:432-494

SPM endorsement·signing RSA key, JSON provisioning status와 Sure Start audit log의 binary layout·entry metadata를 정의합니다.

2. 영어 원문 전체

번역 기준이 된 Linux v6.18.37 원문입니다. 줄 번호는 이 버전의 파일 좌표입니다.

원문 전체 펼치기
1 What: /sys/class/firmware-attributes/*/attributes/*/
2 Date: February 2021
3 KernelVersion: 5.11
4 Contact: Divya Bharathi <Divya.Bharathi@Dell.com>,
5 Prasanth KSR <prasanth.ksr@dell.com>
6 Dell.Client.Kernel@dell.com
7 Description:
8 A sysfs interface for systems management software to enable
9 configuration capability on supported systems. This directory
10 exposes interfaces for interacting with configuration options.
11
12 Unless otherwise specified in an attribute description all attributes are optional
13 and will accept UTF-8 input.
14
15 type:
16 A file that can be read to obtain the type of attribute.
17 This attribute is mandatory.
18
19 The following are known types:
20
21 - enumeration: a set of pre-defined valid values
22 - integer: a range of numerical values
23 - string
24
25 HP specific types
26 -----------------
27 - ordered-list - a set of ordered list valid values
28
29
30 All attribute types support the following values:
31
32 current_value:
33 A file that can be read to obtain the current
34 value of the <attr>.
35
36 This file can also be written to in order to update the value of a
37 <attr>
38
39 This attribute is mandatory.
40
41 default_value:
42 A file that can be read to obtain the default
43 value of the <attr>
44
45 display_name:
46 A file that can be read to obtain a user friendly
47 description of the at <attr>
48
49 display_name_language_code:
50 A file that can be read to obtain
51 the IETF language tag corresponding to the
52 "display_name" of the <attr>
53
54 "enumeration"-type specific properties:
55
56 possible_values:
57 A file that can be read to obtain the possible
58 values of the <attr>. Values are separated using
59 semi-colon (``;``).
60
61 "integer"-type specific properties:
62
63 min_value:
64 A file that can be read to obtain the lower
65 bound value of the <attr>
66
67 max_value:
68 A file that can be read to obtain the upper
69 bound value of the <attr>
70
71 scalar_increment:
72 A file that can be read to obtain the scalar value used for
73 increments of current_value this attribute accepts.
74
75 "string"-type specific properties:
76
77 max_length:
78 A file that can be read to obtain the maximum
79 length value of the <attr>
80
81 min_length:
82 A file that can be read to obtain the minimum
83 length value of the <attr>
84
85 Dell specific class extensions
86 ------------------------------
87
88 On Dell systems the following additional attributes are available:
89
90 dell_modifier:
91 A file that can be read to obtain attribute-level
92 dependency rule. It says an attribute X will become read-only or
93 suppressed, if/if-not attribute Y is configured.
94
95 modifier rules can be in following format::
96
97 [ReadOnlyIf:<attribute>=<value>]
98 [ReadOnlyIfNot:<attribute>=<value>]
99 [SuppressIf:<attribute>=<value>]
100 [SuppressIfNot:<attribute>=<value>]
101
102 For example::
103
104 AutoOnFri/dell_modifier has value,
105 [SuppressIfNot:AutoOn=SelectDays]
106
107 This means AutoOnFri will be suppressed in BIOS setup if AutoOn
108 attribute is not "SelectDays" and its value will not be effective
109 through sysfs until this rule is met.
110
111 Enumeration attributes also support the following:
112
113 dell_value_modifier:
114 A file that can be read to obtain value-level dependency.
115 This file is similar to dell_modifier but here, an
116 attribute's current value will be forcefully changed based
117 dependent attributes value.
118
119 dell_value_modifier rules can be in following format::
120
121 <value>[ForceIf:<attribute>=<value>]
122 <value>[ForceIfNot:<attribute>=<value>]
123
124 For example::
125
126 LegacyOrom/dell_value_modifier has value:
127 Disabled[ForceIf:SecureBoot=Enabled]
128
129 This means LegacyOrom's current value will be forced to
130 "Disabled" in BIOS setup if SecureBoot is Enabled and its
131 value will not be effective through sysfs until this rule is
132 met.
133
134 HP specific class extensions
135 ------------------------------
136
137 On HP systems the following additional attributes are available:
138
139 "ordered-list"-type specific properties:
140
141 elements:
142 A file that can be read to obtain the possible
143 list of values of the <attr>. Values are separated using
144 semi-colon (``;``) and listed according to their priority.
145 An element listed first has the highest priority. Writing
146 the list in a different order to current_value alters
147 the priority order for the particular attribute.
148
149 What: /sys/class/firmware-attributes/*/authentication/
150 Date: February 2021
151 KernelVersion: 5.11
152 Contact: Divya Bharathi <Divya.Bharathi@Dell.com>,
153 Prasanth KSR <prasanth.ksr@dell.com>
154 Dell.Client.Kernel@dell.com
155 Description:
156 Devices support various authentication mechanisms which can be exposed
157 as a separate configuration object.
158
159 For example a "BIOS Admin" password and "System" Password can be set,
160 reset or cleared using these attributes.
161
162 - An "Admin" password is used for preventing modification to the BIOS
163 settings.
164 - A "System" password is required to boot a machine.
165
166 Change in any of these two authentication methods will also generate an
167 uevent KOBJ_CHANGE.
168
169 is_enabled:
170 A file that can be read to obtain a 0/1 flag to see if
171 <attr> authentication is enabled.
172 This attribute is mandatory.
173
174 role:
175 The type of authentication used.
176 This attribute is mandatory.
177
178 Known types:
179 bios-admin:
180 Representing BIOS administrator password
181 power-on:
182 Representing a password required to use
183 the system
184 system-mgmt:
185 Representing System Management password.
186 See Lenovo extensions section for details
187 HDD:
188 Representing HDD password
189 See Lenovo extensions section for details
190 NVMe:
191 Representing NVMe password
192 See Lenovo extensions section for details
193
194 mechanism:
195 The means of authentication. This attribute is mandatory.
196 Supported types are "password" or "certificate".
197
198 max_password_length:
199 A file that can be read to obtain the
200 maximum length of the Password
201
202 min_password_length:
203 A file that can be read to obtain the
204 minimum length of the Password
205
206 current_password:
207 A write only value used for privileged access such as
208 setting attributes when a system or admin password is set
209 or resetting to a new password
210
211 This attribute is mandatory when mechanism == "password".
212
213 new_password:
214 A write only value that when used in tandem with
215 current_password will reset a system or admin password.
216
217 Note, password management is session specific. If Admin password is set,
218 same password must be written into current_password file (required for
219 password-validation) and must be cleared once the session is over.
220 For example::
221
222 echo "password" > current_password
223 echo "disabled" > TouchScreen/current_value
224 echo "" > current_password
225
226 Drivers may emit a CHANGE uevent when a password is set or unset
227 userspace may check it again.
228
229 On Dell, Lenovo and HP systems, if Admin password is set, then all BIOS attributes
230 require password validation.
231 On Lenovo systems if you change the Admin password the new password is not active until
232 the next boot.
233
234 Lenovo specific class extensions
235 --------------------------------
236
237 On Lenovo systems the following additional settings are available:
238
239 role: system-mgmt This gives the same authority as the bios-admin password to control
240 security related features. The authorities allocated can be set via
241 the BIOS menu SMP Access Control Policy
242
243 role: HDD & NVMe This password is used to unlock access to the drive at boot. Note see
244 'level' and 'index' extensions below.
245
246 lenovo_encoding:
247 The encoding method that is used. This can be either "ascii"
248 or "scancode". Default is set to "ascii"
249
250 lenovo_kbdlang:
251 The keyboard language method that is used. This is generally a
252 two char code (e.g. "us", "fr", "gr") and may vary per platform.
253 Default is set to "us"
254
255 level:
256 Available for HDD and NVMe authentication to set 'user' or 'master'
257 privilege level.
258 If only the user password is configured then this should be used to
259 unlock the drive at boot. If both master and user passwords are set
260 then either can be used. If a master password is set a user password
261 is required.
262 This attribute defaults to 'user' level
263
264 index:
265 Used with HDD and NVME authentication to set the drive index
266 that is being referenced (e.g hdd1, hdd2 etc)
267 This attribute defaults to device 1.
268
269 certificate, signature, save_signature:
270 These attributes are used for certificate based authentication. This is
271 used in conjunction with a signing server as an alternative to password
272 based authentication.
273 The user writes to the attribute(s) with a BASE64 encoded string obtained
274 from the signing server.
275 The attributes can be displayed to check the stored value.
276
277 Some usage examples:
278
279 Installing a certificate to enable feature::
280
281 echo "supervisor password" > authentication/Admin/current_password
282 echo "signed certificate" > authentication/Admin/certificate
283
284 Updating the installed certificate::
285
286 echo "signature" > authentication/Admin/signature
287 echo "signed certificate" > authentication/Admin/certificate
288
289 Removing the installed certificate::
290
291 echo "signature" > authentication/Admin/signature
292 echo "" > authentication/Admin/certificate
293
294 Changing a BIOS setting::
295
296 echo "signature" > authentication/Admin/signature
297 echo "save signature" > authentication/Admin/save_signature
298 echo Enable > attribute/PasswordBeep/current_value
299
300 You cannot enable certificate authentication if a supervisor password
301 has not been set.
302 Clearing the certificate results in no bios-admin authentication method
303 being configured allowing anyone to make changes.
304 After any of these operations the system must reboot for the changes to
305 take effect.
306 Admin and System certificates are supported from 2025 systems onward.
307
308 certificate_thumbprint:
309 Read only attribute used to display the MD5, SHA1 and SHA256 thumbprints
310 for the certificate installed in the BIOS.
311
312 certificate_to_password:
313 Write only attribute used to switch from certificate based authentication
314 back to password based.
315 Usage::
316
317 echo "signature" > authentication/Admin/signature
318 echo "password" > authentication/Admin/certificate_to_password
319
320 HP specific class extensions
321 --------------------------------
322
323 On HP systems the following additional settings are available:
324
325 role: enhanced-bios-auth:
326 This role is specific to Secure Platform Management (SPM) attribute.
327 It requires configuring an endorsement (kek) and signing certificate (sk).
328
329
330 What: /sys/class/firmware-attributes/*/attributes/pending_reboot
331 Date: February 2021
332 KernelVersion: 5.11
333 Contact: Divya Bharathi <Divya.Bharathi@Dell.com>,
334 Prasanth KSR <prasanth.ksr@dell.com>
335 Dell.Client.Kernel@dell.com
336 Description:
337 A read-only attribute reads 1 if a reboot is necessary to apply
338 pending BIOS attribute changes. Also, an uevent_KOBJ_CHANGE is
339 generated when it changes to 1.
340
341 == =========================================
342 0 All BIOS attributes setting are current
343 1 A reboot is necessary to get pending BIOS
344 attribute changes applied
345 == =========================================
346
347 Note, userspace applications need to follow below steps for efficient
348 BIOS management,
349
350 1. Check if admin password is set. If yes, follow session method for
351 password management as briefed under authentication section above.
352 2. Before setting any attribute, check if it has any modifiers
353 or value_modifiers. If yes, incorporate them and then modify
354 attribute.
355
356 Drivers may emit a CHANGE uevent when this value changes and userspace
357 may check it again.
358
359 What: /sys/class/firmware-attributes/*/attributes/reset_bios
360 Date: February 2021
361 KernelVersion: 5.11
362 Contact: Divya Bharathi <Divya.Bharathi@Dell.com>,
363 Prasanth KSR <prasanth.ksr@dell.com>
364 Dell.Client.Kernel@dell.com
365 Description:
366 This attribute can be used to reset the BIOS Configuration.
367 Specifically, it tells which type of reset BIOS configuration is being
368 requested on the host.
369
370 Reading from it returns a list of supported options encoded as:
371
372 - 'builtinsafe' (Built in safe configuration profile)
373 - 'lastknowngood' (Last known good saved configuration profile)
374 - 'factory' (Default factory settings configuration profile)
375 - 'custom' (Custom saved configuration profile)
376
377 The currently selected option is printed in square brackets as
378 shown below::
379
380 # echo "factory" > /sys/class/firmware-attributes/*/device/attributes/reset_bios
381 # cat /sys/class/firmware-attributes/*/device/attributes/reset_bios
382 builtinsafe lastknowngood [factory] custom
383
384 Note that any changes to this attribute requires a reboot
385 for changes to take effect.
386
387 What: /sys/class/firmware-attributes/*/attributes/save_settings
388 Date: August 2023
389 KernelVersion: 6.6
390 Contact: Mark Pearson <mpearson-lenovo@squebb.ca>
391 Description:
392 On Lenovo platforms there is a limitation in the number of times an attribute can be
393 saved. This is an architectural limitation and it limits the number of attributes
394 that can be modified to 48.
395 A solution for this is instead of the attribute being saved after every modification,
396 to allow a user to bulk set the attributes, and then trigger a final save. This allows
397 unlimited attributes.
398
399 Read the attribute to check what save mode is enabled (single or bulk).
400 E.g:
401 # cat /sys/class/firmware-attributes/thinklmi/attributes/save_settings
402 single
403
404 Write the attribute with 'bulk' to enable bulk save mode.
405 Write the attribute with 'single' to enable saving, after every attribute set.
406 The default setting is single mode.
407 E.g:
408 # echo bulk > /sys/class/firmware-attributes/thinklmi/attributes/save_settings
409
410 When in bulk mode write 'save' to trigger a save of all currently modified attributes.
411 Note, once a save has been triggered, in bulk mode, attributes can no longer be set and
412 will return a permissions error. This is to prevent users hitting the 48+ save limitation
413 (which requires entering the BIOS to clear the error condition)
414 E.g:
415 # echo save > /sys/class/firmware-attributes/thinklmi/attributes/save_settings
416
417 What: /sys/class/firmware-attributes/*/attributes/debug_cmd
418 Date: July 2021
419 KernelVersion: 5.14
420 Contact: Mark Pearson <markpearson@lenovo.com>
421 Description:
422 This write only attribute can be used to send debug commands to the BIOS.
423 This should only be used when recommended by the BIOS vendor. Vendors may
424 use it to enable extra debug attributes or BIOS features for testing purposes.
425
426 Note that any changes to this attribute requires a reboot for changes to take effect.
427
428
429 HP specific class extensions - Secure Platform Manager (SPM)
430 --------------------------------
431
432 What: /sys/class/firmware-attributes/*/authentication/SPM/kek
433 Date: March 2023
434 KernelVersion: 5.18
435 Contact: "Jorge Lopez" <jorge.lopez2@hp.com>
436 Description:
437 'kek' Key-Encryption-Key is a write-only file that can be used to configure the
438 RSA public key that will be used by the BIOS to verify
439 signatures when setting the signing key. When written,
440 the bytes should correspond to the KEK certificate
441 (x509 .DER format containing an OU). The size of the
442 certificate must be less than or equal to 4095 bytes.
443
444 What: /sys/class/firmware-attributes/*/authentication/SPM/sk
445 Date: March 2023
446 KernelVersion: 5.18
447 Contact: "Jorge Lopez" <jorge.lopez2@hp.com>
448 Description:
449 'sk' Signature Key is a write-only file that can be used to configure the RSA
450 public key that will be used by the BIOS to verify signatures
451 when configuring BIOS settings and security features. When
452 written, the bytes should correspond to the modulus of the
453 public key. The exponent is assumed to be 0x10001.
454
455 What: /sys/class/firmware-attributes/*/authentication/SPM/status
456 Date: March 2023
457 KernelVersion: 5.18
458 Contact: "Jorge Lopez" <jorge.lopez2@hp.com>
459 Description:
460 'status' is a read-only file that returns ASCII text in JSON format reporting
461 the status information.
462
463 "State": "not provisioned | provisioned | provisioning in progress",
464 "Version": "Major.Minor",
465 "Nonce": <16-bit unsigned number display in base 10>,
466 "FeaturesInUse": <16-bit unsigned number display in base 10>,
467 "EndorsementKeyMod": "<256 bytes in base64>",
468 "SigningKeyMod": "<256 bytes in base64>"
469
470 What: /sys/class/firmware-attributes/*/attributes/Sure_Start/audit_log_entries
471 Date: March 2023
472 KernelVersion: 5.18
473 Contact: "Jorge Lopez" <jorge.lopez2@hp.com>
474 Description:
475 'audit_log_entries' is a read-only file that returns the events in the log.
476
477 Audit log entry format
478
479 Byte 0-15: Requested Audit Log entry (Each Audit log is 16 bytes)
480 Byte 16-127: Unused
481
482 What: /sys/class/firmware-attributes/*/attributes/Sure_Start/audit_log_entry_count
483 Date: March 2023
484 KernelVersion: 5.18
485 Contact: "Jorge Lopez" <jorge.lopez2@hp.com>
486 Description:
487 'audit_log_entry_count' is a read-only file that returns the number of existing
488 audit log events available to be read. Values are separated using comma. (``,``)
489
490 [No of entries],[log entry size],[Max number of entries supported]
491
492 log entry size identifies audit log size for the current BIOS version.
493 The current size is 16 bytes but it can be up to 128 bytes long in future BIOS
494 versions.
495

3. 한국어 전문 번역

영어 원문의 문단 순서와 의미를 유지한 전체 번역입니다. 코드, 함수명, symbol과 URL은 원문 표기를 유지합니다.

Firmware configuration attribute schema

1-148
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/*/
Date2021년 2월
KernelVersion5.11
ContactDivya Bharathi <Divya.Bharathi@Dell.com>, Prasanth KSR <prasanth.ksr@dell.com>, Dell.Client.Kernel@dell.com
Description지원되는 system에서 system management software가 configuration 기능을 사용할 수 있게 하는 sysfs interface입니다. 이 directory는 configuration option과 상호 작용하는 interface를 노출합니다. Attribute 설명에서 달리 지정하지 않는 한 모든 attribute는 선택 사항이며 UTF-8 입력을 받습니다.
Firmware attribute type
Type의미범위
enumeration미리 정의된 유효 값 집합공통
integer숫자 값 범위공통
string문자열공통
ordered-list우선순위가 있는 유효 값 목록HP 전용

type file은 필수이며 attribute 종류를 읽어 확인합니다.

모든 type의 공통 property
Property접근설명
typeRead-only, 필수Attribute type
current_valueRead/write, 필수현재 값을 읽고 새 값으로 갱신
default_valueRead-only기본값
display_nameRead-only사용자 친화적인 attribute 설명
display_name_language_codeRead-onlydisplay_name에 대응하는 IETF language tag

모든 attribute type이 지원하는 file과 필수 여부입니다.

Type별 property
TypeProperty설명
enumerationpossible_values세미콜론(;)으로 구분한 가능한 값
integermin_value허용 범위의 하한
integermax_value허용 범위의 상한
integerscalar_incrementcurrent_value가 받는 증가 단위
stringmax_length최대 문자열 길이
stringmin_length최소 문자열 길이
ordered-listelements세미콜론으로 구분하고 우선순위순으로 나열한 값

Enumeration·integer·string·HP ordered-list에 추가되는 metadata입니다.

Dell 전용 class 확장

Dell system은 dell_modifier를 추가로 제공합니다. 이 file은 attribute 수준 dependency rule을 읽는 데 사용합니다. Attribute Y의 configuration 여부나 값에 따라 attribute X를 read-only로 만들거나 BIOS setup에서 숨길 수 있습니다.

[ReadOnlyIf:<attribute>=<value>]
[ReadOnlyIfNot:<attribute>=<value>]
[SuppressIf:<attribute>=<value>]
[SuppressIfNot:<attribute>=<value>]
AutoOnFri/dell_modifier:
[SuppressIfNot:AutoOn=SelectDays]

이 예시는 AutoOn attribute가 "SelectDays"가 아니면 AutoOnFri가 BIOS setup에서 숨겨지고, rule을 만족할 때까지 sysfs로 설정한 값이 효력을 갖지 않는다는 뜻입니다.

Enumeration attribute는 dell_value_modifier도 지원합니다. 이는 dell_modifier와 비슷하지만 dependent attribute 값에 따라 현재 값을 강제로 변경하는 value-level dependency입니다.

<value>[ForceIf:<attribute>=<value>]
<value>[ForceIfNot:<attribute>=<value>]

LegacyOrom/dell_value_modifier:
Disabled[ForceIf:SecureBoot=Enabled]

이 예시는 SecureBoot가 Enabled이면 BIOS setup에서 LegacyOrom의 현재 값을 "Disabled"로 강제하고, 해당 rule을 만족할 때까지 sysfs를 통한 값이 효력을 갖지 않는다는 뜻입니다.

HP 전용 ordered-list 확장

HP system의 ordered-list type에서 elements file은 가능한 값을 세미콜론으로 구분해 우선순위순으로 표시합니다. 먼저 나오는 element의 우선순위가 가장 높습니다. current_value에 목록을 다른 순서로 쓰면 해당 attribute의 우선순위 순서가 변경됩니다.

Firmware authentication object

149-329
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/authentication/
Date2021년 2월
KernelVersion5.11
ContactDivya Bharathi <Divya.Bharathi@Dell.com>, Prasanth KSR <prasanth.ksr@dell.com>, Dell.Client.Kernel@dell.com
DescriptionDevice가 지원하는 여러 authentication mechanism을 별도 configuration object로 노출합니다. 예를 들어 이 attribute로 "BIOS Admin" password와 "System" password를 설정·재설정·삭제할 수 있습니다. Admin password는 BIOS 설정 변경을 막고, System password는 machine boot에 필요합니다. 두 authentication 방식 중 하나가 바뀌면 KOBJ_CHANGE uevent도 생성됩니다.
Authentication 공통 property
Property접근·필수 여부설명
is_enabledRead-only, 필수Authentication 활성 여부 0/1
roleRead-only, 필수사용하는 authentication type
mechanismRead-only, 필수password 또는 certificate
max_password_lengthRead-onlyPassword 최대 길이
min_password_lengthRead-onlyPassword 최소 길이
current_passwordWrite-only, password mechanism에서 필수권한 확인 또는 새 password 설정에 쓰는 현재 password
new_passwordWrite-onlycurrent_password와 함께 system/admin password 재설정

Authentication object의 상태·role·mechanism과 password field입니다.

알려진 authentication role
Role의미
bios-adminBIOS administrator password
power-onSystem 사용에 필요한 password
system-mgmtSystem Management password, Lenovo 확장 참조
HDDHDD password, Lenovo 확장 참조
NVMeNVMe password, Lenovo 확장 참조

Role 문자열과 보호 대상을 정리합니다.

Password session 관리

Password 관리는 session별로 이뤄집니다. Admin password가 설정되어 있으면 password validation을 위해 같은 값을 current_password에 쓰고, session이 끝나면 반드시 비워야 합니다.

echo "password" > current_password
echo "disabled" > TouchScreen/current_value
echo "" > current_password

Driver는 password가 설정되거나 해제될 때 CHANGE uevent를 보낼 수 있고 userspace는 상태를 다시 확인할 수 있습니다. Dell·Lenovo·HP system에서 Admin password가 설정되어 있으면 모든 BIOS attribute에 password validation이 필요합니다. Lenovo system에서 Admin password를 변경하면 새 password는 다음 boot 전까지 활성화되지 않습니다.

Lenovo 전용 class 확장

Lenovo authentication 설정
설정설명기본값
role: system-mgmtSecurity feature를 제어하는 bios-admin과 같은 권한이며 BIOS SMP Access Control Policy로 권한 할당-
role: HDD / NVMeBoot 때 drive 접근을 unlock하며 level·index 확장과 함께 사용-
lenovo_encodingascii 또는 scancode encodingascii
lenovo_kbdlangPlatform별 두 글자 keyboard language code(예: us, fr, gr)us
levelHDD·NVMe의 user 또는 master 권한 수준user
index참조하는 HDD·NVMe drive 번호(예: hdd1, hdd2)device 1

System management, drive password와 입력 encoding을 위한 추가 attribute입니다.

HDD·NVMe level에서 user password만 설정했다면 boot 때 drive를 unlock하는 데 user를 사용합니다. Master와 user password가 모두 있으면 둘 중 하나를 쓸 수 있으며, master password를 설정하려면 user password도 필요합니다.

Lenovo certificate authentication

certificate, signature, save_signature attribute는 signing server와 함께 사용하는 certificate 기반 authentication용이며 password 방식의 대안입니다. 사용자는 signing server에서 받은 BASE64 encoded 문자열을 해당 attribute에 씁니다. 저장된 값은 표시해 확인할 수 있습니다.

# Certificate 설치
 echo "supervisor password" > authentication/Admin/current_password
 echo "signed certificate" > authentication/Admin/certificate

# 설치된 certificate 갱신
 echo "signature" > authentication/Admin/signature
 echo "signed certificate" > authentication/Admin/certificate

# 설치된 certificate 제거
 echo "signature" > authentication/Admin/signature
 echo "" > authentication/Admin/certificate

# BIOS 설정 변경
 echo "signature" > authentication/Admin/signature
 echo "save signature" > authentication/Admin/save_signature
 echo Enable > attribute/PasswordBeep/current_value

Supervisor password가 설정되지 않으면 certificate authentication을 활성화할 수 없습니다. Certificate를 지우면 bios-admin authentication 방식이 하나도 남지 않아 누구나 변경할 수 있습니다. 위 작업 후 변경을 적용하려면 system을 reboot해야 합니다. Admin과 System certificate는 2025년 이후 system에서 지원됩니다.

certificate_thumbprint는 BIOS에 설치된 certificate의 MD5·SHA1·SHA256 thumbprint를 표시하는 read-only attribute입니다. certificate_to_password는 certificate 기반 authentication에서 password 기반 방식으로 되돌리는 write-only attribute입니다.

echo "signature" > authentication/Admin/signature
echo "password" > authentication/Admin/certificate_to_password

HP 전용 class 확장

HP system의 role "enhanced-bios-auth"는 Secure Platform Management(SPM) attribute 전용입니다. 이 role은 endorsement certificate(kek)와 signing certificate(sk)를 구성해야 합니다.

Pending BIOS 변경의 reboot 요구

330-357
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/pending_reboot
Date2021년 2월
KernelVersion5.11
ContactDivya Bharathi <Divya.Bharathi@Dell.com>, Prasanth KSR <prasanth.ksr@dell.com>, Dell.Client.Kernel@dell.com
DescriptionRead-only attribute입니다. Pending BIOS attribute 변경을 적용하려면 reboot가 필요할 때 1을 읽습니다. 값이 1로 바뀌면 uevent_KOBJ_CHANGE도 생성됩니다.
pending_reboot 값
의미
0모든 BIOS attribute 설정이 현재 상태임
1Pending BIOS attribute 변경 적용에 reboot 필요

BIOS 설정의 적용 상태를 나타냅니다.

효율적인 BIOS 관리를 위해 userspace application은 먼저 Admin password가 설정되었는지 확인하고, 설정되어 있다면 authentication 절의 session password 관리 절차를 따라야 합니다. Attribute를 설정하기 전에는 modifier 또는 value_modifier가 있는지 확인하고, 있다면 이를 반영한 뒤 attribute를 변경해야 합니다. Driver는 값 변경 시 CHANGE uevent를 보낼 수 있으며 userspace는 값을 다시 확인할 수 있습니다.

BIOS configuration reset profile

359-385
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/reset_bios
Date2021년 2월
KernelVersion5.11
ContactDivya Bharathi <Divya.Bharathi@Dell.com>, Prasanth KSR <prasanth.ksr@dell.com>, Dell.Client.Kernel@dell.com
DescriptionBIOS configuration을 reset하는 데 사용하며 host에서 요청하는 reset BIOS configuration의 종류를 지정합니다. 읽으면 지원 option 목록을 반환하고, 현재 선택한 option은 대괄호로 표시합니다. 이 attribute의 변경을 적용하려면 reboot가 필요합니다.
reset_bios option
OptionProfile
builtinsafeBuilt-in safe configuration
lastknowngood마지막으로 저장된 정상 configuration
factory기본 factory setting
custom사용자 저장 configuration

지원되는 네 가지 BIOS configuration profile입니다.

# echo "factory" > /sys/class/firmware-attributes/*/device/attributes/reset_bios
# cat /sys/class/firmware-attributes/*/device/attributes/reset_bios
builtinsafe lastknowngood [factory] custom

Lenovo BIOS setting save mode

387-415
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/save_settings
Date2023년 8월
KernelVersion6.6
ContactMark Pearson <mpearson-lenovo@squebb.ca>
DescriptionLenovo platform에는 attribute를 저장할 수 있는 횟수에 architecture상 제한이 있어 수정 가능한 attribute 수가 48개로 제한됩니다. 매번 수정할 때 저장하는 대신 여러 attribute를 일괄 설정하고 마지막에 한 번 저장하면 제한 없이 attribute를 다룰 수 있습니다. 이 attribute를 읽어 single 또는 bulk save mode를 확인합니다. 'bulk'를 쓰면 bulk mode, 'single'을 쓰면 attribute를 설정할 때마다 저장하는 mode가 됩니다. 기본값은 single입니다. Bulk mode에서 'save'를 쓰면 현재 수정한 모든 attribute를 저장합니다. Bulk mode에서 한 번 save를 시작한 뒤에는 attribute를 더 설정할 수 없고 permission error가 반환됩니다. 이는 BIOS에 들어가야 해제할 수 있는 48회 초과 save 오류를 막기 위한 것입니다.
# cat /sys/class/firmware-attributes/thinklmi/attributes/save_settings
single

# echo bulk > /sys/class/firmware-attributes/thinklmi/attributes/save_settings
# echo save > /sys/class/firmware-attributes/thinklmi/attributes/save_settings
save_settings mode
입력·mode동작
single각 attribute 설정 뒤 저장, 기본 mode
bulk여러 attribute를 저장하지 않고 먼저 수정
saveBulk mode의 모든 수정 사항을 최종 저장

Lenovo attribute 저장 시점과 bulk mode의 final action입니다.

BIOS debug command

417-430
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/debug_cmd
Date2021년 7월
KernelVersion5.14
ContactMark Pearson <markpearson@lenovo.com>
DescriptionBIOS에 debug command를 보내는 write-only attribute입니다. BIOS vendor가 권고할 때만 사용해야 합니다. Vendor는 testing 목적으로 추가 debug attribute나 BIOS feature를 활성화하는 데 사용할 수 있습니다. 이 attribute의 변경을 적용하려면 reboot가 필요합니다. 이어지는 항목은 HP 전용 Secure Platform Manager(SPM) class 확장입니다.

SPM Key-Encryption-Key certificate

432-442
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/authentication/SPM/kek
Date2023년 3월
KernelVersion5.18
Contact"Jorge Lopez" <jorge.lopez2@hp.com>
Description'kek' Key-Encryption-Key는 signing key를 설정할 때 BIOS가 signature를 검증하는 데 사용할 RSA public key를 구성하는 write-only file입니다. 쓰는 byte는 OU를 포함한 x509 .DER 형식 KEK certificate여야 하며 certificate 크기는 4095 byte 이하여야 합니다.

SPM signature key

444-453
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/authentication/SPM/sk
Date2023년 3월
KernelVersion5.18
Contact"Jorge Lopez" <jorge.lopez2@hp.com>
Description'sk' Signature Key는 BIOS setting과 security feature를 구성할 때 BIOS가 signature를 검증하는 데 사용할 RSA public key를 설정하는 write-only file입니다. 쓰는 byte는 public key modulus여야 하며 exponent는 0x10001로 가정합니다.

SPM provisioning 상태

455-468
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/authentication/SPM/status
Date2023년 3월
KernelVersion5.18
Contact"Jorge Lopez" <jorge.lopez2@hp.com>
Description'status'는 상태 정보를 보고하는 JSON 형식 ASCII text를 반환하는 read-only file입니다.
"State": "not provisioned | provisioned | provisioning in progress",
"Version": "Major.Minor",
"Nonce": <16-bit unsigned number display in base 10>,
"FeaturesInUse": <16-bit unsigned number display in base 10>,
"EndorsementKeyMod": "<256 bytes in base64>",
"SigningKeyMod": "<256 bytes in base64>"
SPM status field
Field형식
Statenot provisioned | provisioned | provisioning in progress
VersionMajor.Minor
Nonce16-bit unsigned, base 10
FeaturesInUse16-bit unsigned, base 10
EndorsementKeyMod256 bytes, base64
SigningKeyMod256 bytes, base64

JSON text에 포함되는 provisioning·version·nonce·key field입니다.

Sure Start audit log entry

470-480
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/Sure_Start/audit_log_entries
Date2023년 3월
KernelVersion5.18
Contact"Jorge Lopez" <jorge.lopez2@hp.com>
Description'audit_log_entries'는 log의 event를 반환하는 read-only file입니다. Byte 0-15에는 요청한 Audit Log entry가 들어가며 각 Audit Log는 16 byte입니다. Byte 16-127은 사용하지 않습니다.
Sure Start audit log buffer
Byte range내용
0-15요청한 16-byte Audit Log entry
16-127미사용

현재 128-byte 반환 영역에서 실제 entry와 미사용 영역을 구분합니다.

Sure Start audit log metadata

482-494
항목한국어 전문 번역
What/sys/class/firmware-attributes/*/attributes/Sure_Start/audit_log_entry_count
Date2023년 3월
KernelVersion5.18
Contact"Jorge Lopez" <jorge.lopez2@hp.com>
Description'audit_log_entry_count'는 읽을 수 있는 기존 audit log event 수를 반환하는 read-only file입니다. 값은 comma로 구분한 [entry 수],[log entry 크기],[지원하는 최대 entry 수] 형식입니다. log entry 크기는 현재 BIOS version의 audit log 크기를 나타냅니다. 현재 크기는 16 byte이지만 향후 BIOS version에서는 최대 128 byte까지 늘어날 수 있습니다.
[No of entries],[log entry size],[Max number of entries supported]