FmpDevicePkg provides the common resources necessary to manage the firmware on a given device. The UEFI Specification defines several elements used in the firmware management process that are implemented or depended upon in FmpDevicePkg such as:
EFI_FIRMWARE_MANAGEMENT_PROTOCOLFmpDxe is the central driver in FmpDevicePkg. It produces the Firmware Management Protocol (EFI_FIRMWARE_MANAGEMENT_PROTOCOL) and coordinates with the supporting modules and libraries listed later in this document to carry out a firmware update. This section describes the high level design of that update flow.
The firmware update capsule must be signed. FmpDxe verifies the integrity of the capsule contents. The actual capsule data is preceded by an EFI_FIRMWARE_IMAGE_AUTHENTICATION structure. This structure contains a monotonic count and a WIN_CERTIFICATE_UEFI_GUID member that contains a signature that covers both the monotonic count and the capsule payload data. These two elements ensure replay protection across update operations and authentication. The certificate type used must be EFI_CERT_TYPE_PKCS7_GUID.
An EDK II implementation of signature verification is available in the following FmpAuthenticationLib instance: SecurityPkg/Library/FmpAuthenticationLibPkcs7.
The EFI_FIRMWARE_IMAGE_DESCRIPTOR structure contains Version and LowestSupportedImageVersion fields that are used to check for compliance during firmware update. The incoming capsule image‘s Version must be greater than or equal to the current firmware’s LowestSupportedImageVersion. The capsule‘s Version may be lower than, equal to, or higher than the firmware’s current Version, only the LowestSupportedImageVersion minimum is enforced.
FmpDxe performs this check directly. The value used for LowestSupportedImageVersion is the greatest of the build-time PcdFmpDeviceBuildTimeLowestSupportedVersion PCD value, the value returned by the FmpDeviceLib instance‘s FmpDeviceGetLowestSupportedVersion() function, and the lowest supported version most recently saved from an applied capsule’s FMP Payload Header.
A capsule can target firmware update to a diverse set of devices on a system. Each device might bring unique logic and requirements to the firmware update process. Therefore, a library class called FmpDeviceLib exists that allows for instances written specific to a particular device.
The UEFI Specification 2.8 version introduced support for expressing dependencies between components involved in a capsule update. For instance, FWx can require FWy to be at least version 2.0 to install. This information is primarily conveyed to FmpDxe through the FmpDependencyCheckLib and FmpDependencyLib library classes.
More information about the overall infrastructure is available in:
A library class (CapsuleUpdatePolicyLib) is used to make platform-specific policy decisions available to the firmware update process. This includes information such as whether the system power/thermal state permits firmware to be updated. A few functions also exist to modify expected behavior such as ignoring the LowestSupportedImageVersion check or not locking the firmware device for update when the FMP lock event is signaled. It is important to note that the latter functions should only be used in very rare special cases such as during manufacturing flows.
This section briefly describes the package modules and libraries.
EFI_FIRMWARE_MANAGEMENT_PROTOCOL) that is used to support updates to a firmware image stored on a firmware deviceSeveral documents describe important elements involved in understanding FmpDevicePkg. Consult the following resource for more information on a particular topic.
FmpDevicePkg Overview
UEFI Specification Definitions for Firmware Updating and Reporting
Technical Overview of the EDK II Capsule Update and Recovery Flow
Windows UEFI Firmware Update Resources
NIST Guidelines for Authenticated Firmware Update