docs/dasharo-menu-docs: describe main page and ME menu

Signed-off-by: Michał Żygowski <michal.zygowski@3mdeb.com>
This commit is contained in:
Michał Żygowski
2022-12-20 17:22:28 +01:00
parent 5a5ae39054
commit 31300a0610
14 changed files with 213 additions and 2 deletions
@@ -0,0 +1,3 @@
# Boot Maintenance Manager
This section is under construction...
@@ -0,0 +1,70 @@
# Dasharo System Features
When entering the `Dasharo System Features` menu, one may see the following
submenus to appear:
- [Dasharo System Features](#dasharo-system-features)
+ [Dasharo Security Options](#dasharo-security-options)
+ [Networking Options](#networking-options)
+ [USB Configuration](#usb-configuration)
+ [Intel Management Engine Options](#intel-management-engine-options)
+ [Chipset Configuration](#chipset-configuration)
![](/images/menus/dasharo_features.jpeg)
## Dasharo Security Options
This section is under construction...
## Networking Options
This section is under construction...
## USB Configuration
This section is under construction...
## Intel Management Engine Options
This submenu is used to access Intel Management Engine related options.
Currently the only option available is `Intel ME mode` which allows to enable
or disable Management Engine:
![](/images/menus/me_menu.jpeg)
On the right side of the window there is a help section describing the option
meaning. If the windows is too small, the help section may be divided. To
scroll the help section use `D` or `d` keys to scroll down and `U` or `u` to
scroll up.
Intel ME can be disabled in two ways:
- `Disabled (Soft)` - when set, causes the Dasharo firmware to send
`ME_DISABLE` command via MEI/HECI. MEI/HECI interface is being hidden from OS
when ME is disabled.
- `Disabled (HAP)` - when set, causes the Dasharo firmware to set HAP bit in
the flash descriptor. MEI/HECI interface is being hidden from OS when ME is
disabled. HAP method is much more efficient as it halts the ME firmware
execution even earlier than Soft Disable described above
![](/images/menus/me_menu2.jpeg)
When the mode is set to `Enabled`, Dasharo enables the Intel Management engine
by either sending `ME_ENABLE` command via MEI/HECI or clearing the HAP bit in
flash descriptor, depending on the previously active ME mode. MEI/HECI device
should be functional in OS when ME is enabled.
Any change in the Dasharo firmware setup requires saving the changes and a
platform reset (unless specified otherwise).
For more information about neutering and disabling ME see also
[me_cleaner](https://github.com/corna/me_cleaner).
NOTE: [me_cleaner](https://github.com/corna/me_cleaner) is not supported on all
platforms! If a platform supports [me_cleaner](https://github.com/corna/me_cleaner)
(i.e. ME version is lower or equal 11.x) it is recommended to set HAP bit and
clean the ME region with `me_cleaner` script permanently.
## Chipset Configuration
This section is under construction...
+3
View File
@@ -0,0 +1,3 @@
# Device manager
This section is under construction...
+130 -2
View File
@@ -15,5 +15,133 @@ can see checkbox results on Dasharo firmware.
## Dasharo menu guides
This section is under construction and will contain guides for each Dasharo
menu feature available in our products.
The main menu is entered by executing Setup application either through
[Boot Manager Menu](#boot-manager-menu) or platform-specific hotkey. You may
find the right key in the top-left corner when booting the platform (when logo
shows up), for example `DEL`:
```txt
DEL to enter Setup
F11 to enter Boot Manager Menu
ENTER to boot directly
```
* [Setup Main Page](#main-page)
- [User Password Management](user-passwd-mgmt.md)
- [Device Manager](device-manager.md)
- [Dasharo System Features](dasharo-system-features.md)
- [One Time Boot](#one-time-boot)
- [Boot Maintenance Manager](boot-maintenance-mgr.md)
NOTE: Some sections may still be under construction.
* [Boot Manager Menu](#boot-manager-menu) - entered with a different key than
used for setup application. Lists all bootable options and allows one to
override the boot path.
### Main Page
![](/images/menus/main_page.jpeg)
The page is the main view of the firmware setup application. It contains the
board model (`MS-7D25`), installed CPU and firmware version in the top-left
corner. In the top-right corner the CPU frequency and system RAM amount is
shown.
From the main page one may access all menus and submenus available in the
firmware setup. Besides the menus there is also an option to:
1. Change the language (currently only English is supported)
2. `Continue` - execute the top first boot order priority
3. `Reset` - resets the platform.
The currently available menus/submenus are as follows:
* [User Password Management](user-passwd-mgmt.md) - allows to set firmware
setup password
* [Device Manager](device-manager.md) - allows configuring various devices and
features like: UEFI Secure Boot, TPM device, SATA and TCG OPAL password, etc.
It may also contain informational menus like Driver Health Manager, Network
Device List and others.
* [Dasharo System Features](dasharo-system-features.md)- contains submenus for
features specific to Dasharo products and Dasharo supported platforms
* [One Time Boot](#one-time-boot) - allows to choose which boot entry to
execute. It simply lists all available boot options and allows to select one
the same way as [Boot Manager Menu](#boot-manager-menu)
* [Boot Maintenance Manager](boot-maintenance-mgr.md) - allows to manipulate
various UEFI standard variables responsible for console and boot options. One
may choose which devices should be used for input and output, choose to boot
an arbitrary file or modify the boot options and boot order.
NOTE: not all submenus may be available on your platform.
[Contact Dasharo Team](mailto:contact@dasharo.com) for more information and
possible feature extension of your platform.
### Boot Manager Menu
Boot Manager Menu is an application that lists all bootable options and allows
one to override the boot path.
Boot Manager Menu is entered with a different key than setup application. It
may be customized on your platform. The right key to use is always printed on
the screen in the top-left corner, for example `F11`:
```txt
DEL to enter Setup
F11 to enter Boot Manager Menu
ENTER to boot directly
```
After pressing the right hotkey for Boot Manager Menu, a window should pop up:
![](/images/menus/boot_manager.jpeg)
One may use up and down arrows to move to desired position. Pressing enter will
cause the execution of selected option. Pressing ESC will cause the firmware to
boot the first boot priority according to the configured boot order.
### One Time Boot
When setup application is entered, one of the menus is called `One Time Boot`.
As the name suggests it allows to override the boot just one time (not
permanently). The usage principles are the same as for [Boot Manager Menu](#boot-manager-menu).
Example view of `One Time Boot` submenu:
![](/images/menus/one_time_boot.jpeg)
On the right side of the menu window, there is a `DevicePath` which is a
UEFI-compliant path to the device or file being executed. Depending on the
file/device type, these paths may be different:
![](/images/menus/one_time_boot.jpeg)
![](/images/menus/one_time_boot3.jpeg)
For example:
* `HD(1,GPT,CF917E4F-3AD1-4293-B4E8-C4EA7BC6FAFD,0x800,0x100000)/\EFI\ubuntu\shimx64.efi`
means to boot a file named `\EFI\ubuntu\shimx64.efi` from GPT paritioned hard
disk no. 1 from partition with UUID `CF917E4F-3AD1-4293-B4E8-C4EA7BC6FAFD`
* `PciRoot(0x0)/Pci(0x1D,0x0)/Pci(0x0,0x0)/NVMe(0x1,A7-6C-B1-11-B1-38-25-00)`
means to boot from NVMe disk namespace 1 and Extended Unique Identifier (EUI)
`A7-6C-B1-11-B1-38-25-00` which is connected to PCIe Root Port with device
number 0x1d function 0. As there is no file name appended at the end, the
UEFI specification automatically looks for `\EFI\BOOT\BOOTX64.EFI` file (for
x86 64 bit architecture). Note if such file is not present on a FAT32
partition on the disk, it will not be recognized as bootable.
* `PciRoot(0x0)/Pci(0x14,0x0)/USB(0x15,0x0)` means to boot from USB disk
connected to USB controller at PCI device 0x14 function 0. The last part
informs it is an USB device connected to port 0x15 (21 in decimal). As there
is no file name appended at the end, the UEFI specification automatically
looks for `\EFI\BOOT\BOOTX64.EFI` file (for x86 64 bit architecture). Note
if such file is not present on a FAT32 partition on the disk, it will not be
recognized as bootable.
* `MemoryMapped(0xB,0x860000,0x15FFFFF)/FvFile(7C04A583-9E3E-4F1C-AD65-E05268D0B4D1)`
points to UEFI Shell application inside the UEFI Payload binary which has
been loaded into memory at address range (0x860000 - 0x15FFFFF). The exact
file to be loaded is indicated by `FvFile` and the file GUID
`7C04A583-9E3E-4F1C-AD65-E05268D0B4D1`
There are many others `DevicePaths` defined in [UEFI Specification](https://uefi.org/specifications).
If you are interested in decoding those, read through the specification
carefully.
@@ -0,0 +1,3 @@
# User Password Management
This section is under construction...
Binary file not shown.

After

Width:  |  Height:  |  Size: 38 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 55 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 46 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 72 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 76 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 53 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 50 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 55 KiB

+4
View File
@@ -186,6 +186,10 @@ nav:
- 'Glossary': glossary.md
- 'Dasharo menu documentation':
- 'Overview': dasharo-menu-docs/overview.md
- 'Boot Maintenance Manager': dasharo-menu-docs/boot-maintenance-mgr.md
- 'User Password Management': dasharo-menu-docs/user-passwd-mgmt.md
- 'Device Manager': dasharo-menu-docs/device-manager.md
- 'Dasharo System Features': dasharo-menu-docs/dasharo-system-features.md
- 'Checkbox certification software usage': common-coreboot-docs/checkbox.md
- 'Dumping logs': common-coreboot-docs/dumping_logs.md
# - 'Trolling Topics List':