Branch: refs/heads/master
Home: https://github.com/tianocore/edk2
Commit: 92fea5c9c1a42542f25b4f897ced7ae082e8c0c7
https://github.com/tianocore/edk2/commit/92fea5c9c1a42542f25b4f897ced7ae082e8c0c7
Author: Jon Kohler <[email protected]>
Date: 2026-06-13 (Sat, 13 Jun 2026)
Changed paths:
M MdePkg/Include/IndustryStandard/WindowsSmmSecurityMitigationTable.h
Log Message:
-----------
MdePkg: Update WSMT (Windows SMM Security Mitigation Table) Docs
The WSMT table ProtectionFlags represent a pinky promise from the
firmware that it will implement various secure processes and features,
but we should know what that pinky promise actually represents with
in-code documentation.
Revise the documentation for the Windows SMM Security Mitigation Table
to include detailed descriptions of the Protection Flags, which are
directly drawn from Microsoft's docs.
Update the stable URL to the latest Microsoft docs for cross reference.
Cc: Paolo Bonzini <[email protected]>
Signed-off-by: Jon Kohler <[email protected]>
Commit: 837f6fce3b524f646b14ce4112770b378d779f42
https://github.com/tianocore/edk2/commit/837f6fce3b524f646b14ce4112770b378d779f42
Author: Jon Kohler <[email protected]>
Date: 2026-06-13 (Sat, 13 Jun 2026)
Changed paths:
M OvmfPkg/OvmfPkgIa32X64.dsc
M OvmfPkg/OvmfPkgIa32X64.fdf
M OvmfPkg/OvmfPkgX64.dsc
M OvmfPkg/OvmfPkgX64.fdf
A OvmfPkg/WsmtDxe/WsmtDxe.c
A OvmfPkg/WsmtDxe/WsmtDxe.inf
Log Message:
-----------
OvmfPkg: Add WSMT ACPI table for SMM builds
Windows uses the Windows SMM Security Mitigation Table to decide
whether SMM firmware advertises the communication-buffer protections
needed by VBS [1].
WSMT ProtectionFlags represent a pinky promise that the underlying
firmware will implement various security practices [2].
Add a small DXE driver that installs a revision 1 WSMT table for the
OvmfPkgIa32X64 and OvmfPkgX64 builds.
WSMT ProtectionFlags are set to 0x3, asserting:
EFI_WSMT_PROTECTION_FLAGS_FIXED_COMM_BUFFERS
EFI_WSMT_PROTECTION_FLAGS_COMM_BUFFER_NESTED_PTR_PROTECTION
Note, we are intentionally not asserting
EFI_WSMT_PROTECTION_FLAGS_SYSTEM_RESOURCE_PROTECTION, as the QEMU side
is not yet tuned up to enforce this protection.
Note: when Windows Hypervisor Enforced Code Integrity is enabled,
Windows msinfo -> Virtualization-based security Available Security
Properties will NOT include "SMM Security Mitigations 1.0", due to
the missing SYSTEM_RESOURCE_PROTECTION flag. Note, WSMT is required
for default enablement of HVCI [3], so we're taking a step in the right
direction here, but not yet 100% complete as of this patch.
References:
[1]
https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-vbs
[2]
https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-uefi-wsmt
[3]
https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-hvci-enablement#check-results-of-memory-integrity-default-enablement
Cc: Paolo Bonzini <[email protected]>
Signed-off-by: Jon Kohler <[email protected]>
Compare: https://github.com/tianocore/edk2/compare/c6c02f8cae26...837f6fce3b52
To unsubscribe from these emails, change your notification settings at
https://github.com/tianocore/edk2/settings/notifications
_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits