Add RMEM DXE ACPI FW-Reserved/Carveout reporting - #1893
Eeshan Londhe (eeshanl) merged 27 commits into
Conversation
✅ QEMU Validation PassedSource Dependencies
Results
Workflow run: https://github.com/microsoft/mu_basecore/actions/runs/36770975752 This comment was automatically generated by the Mu QEMU PR Validation workflow. |
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## release/202608 #1893 +/- ##
=================================================
Coverage ? 1.47%
=================================================
Files ? 1185
Lines ? 378965
Branches ? 3460
=================================================
Hits ? 5587
Misses ? 373304
Partials ? 74
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Sean Brogan (spbrogan)
left a comment
There was a problem hiding this comment.
this looks great.
I added a few comments
|
Please also change the target merge branch to release/202608 |
|
Also, since we plan to upstream this to edk2, please add #MU_CHANGE start/end tags to any changes in existing files. |
Move the proposed RMEM interfaces into MdeModulePkg, mark changes to existing files for upstream tracking, and document range conflict handling. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use SharedMemory for category value 2 to cover reserved memory shared across firmware execution environments without limiting its meaning to communication buffers. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
12ef943 to
05f6f80
Compare
Document that RMEM_LABEL_MAX_LEN includes the null terminator and that registration accepts at most 31 label characters. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
|
Rebased the target branch to release/202608 RMEM related source code is moved to MdeModulePkg Add MU_CHANGE for the upstream |
Present RMEM Revision 1 as Microsoft's recommended reserved-memory reporting interface for silicon partners and OEMs building Windows devices while retaining its EDK II/Mu ownership distinction. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Rename category value 5 from NpuReserved to AiAcceleratorReserved so the interface covers silicon-partner terminology beyond NPUs without changing the wire value. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep RMEM entries at 52 bytes while reducing category and label fields, reserving seven bytes for future revisions, and validating that reserved fields remain zero. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Expand the RMEM table header and entries to 64 bytes, reserve the additional space for future revisions, and update validation, tests, and the PowerShell decoder. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sean Brogan (spbrogan)
left a comment
There was a problem hiding this comment.
Added a few more suggestions but overall looks great.
Define an RMEM entry flag that lets producers redact physical base addresses from the published ACPI table while retaining actual addresses for validation and overlap detection. Reject undefined flags and document consumer behavior. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Validate page alignment and platform physical-address limits, reject duplicate ranges, and diagnose invalid registrations. Skip malformed HOB records in release builds so valid records remain publishable, while asserting producer errors in debug builds. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Require a valid CPU HOB before publishing RMEM, return and check initialization and import statuses, and avoid exposing hidden base addresses in diagnostics. Preserve best-effort import of malformed individual RMEM records. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Extend the RMEM PowerShell example to validate and total reported ranges, compare them with Windows' estimated hardware-reserved memory, reject visible overlap, and summarize entries by category. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use EntryOffset in the table header and matching 48-byte ACPI and HOB records with 16-bit category and flag fields. Remove HOB-local revision and reserved fields, and document the category semantics in the authoritative header. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Use 16-bit entry count and offset fields so the Revision 1 header is 40 bytes and the 48-byte entry array begins at an 8-byte-aligned offset. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Describe Windows hardware-reserved memory as the difference between the API-reported installed and OS-available physical memory values, rather than calling that calculation an estimate. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
587366f
into
microsoft:release/202608
Description
This PR adds the Reserved Memory Reporting (RMEM) Revision 1 interface to
MdeModulePkg.RMEM is the Microsoft-recommended firmware interface for silicon partners and OEMs building Windows devices to describe reserved physical-memory regions and their intended purpose.
Firmware may reserve physical memory for security services, firmware runtime use, shared-memory buffers, graphics, AI accelerators, crash handling, and other platform functions. Operating systems generally expose only the aggregate hardware-reserved amount or EFI memory descriptors, making it difficult to identify the purpose of individual reservations.
This change introduces:
ReadyToBoot.EFI_ACPI_TABLE_PROTOCOL.For details on how to complete these options and their meaning refer to CONTRIBUTING.md.
This change adds a new opt-in interface and does not modify an existing interface.
RMEM has security and privacy implications because the table can expose physical addresses, sizes, categories, and diagnostic labels to operating-system consumers. Producers must not place secrets, product codenames, unique device information, or memory contents in labels.
The
ADDRESS_HIDDENflag allows a producer to redact an address from the serialized table. The producer must still provide the actual address to firmware so overflow and overlap validation remain deterministic.The RMEM table is diagnostic metadata only. It does not grant access to a reported range and must not be used as the sole source for access-control or memory-ownership decisions.
Public interface and data-format documentation is included in the headers and the RMEM driver README.
How This Was Tested
The checks were run with:
stuart_ci_build.exe
-c .pytool\CISettings.py-p MdeModulePkg
-a X64-t NOOPT
CompilerPlugin=skipHostUnitTestCompilerPlugin=skip