Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 1 | .. SPDX-License-Identifier: GPL-2.0+ |
| 2 | .. (C) Copyright 2022, Masahisa Kojima <masahisa.kojima@linaro.org> |
| 3 | |
Heinrich Schuchardt | 1b0c316 | 2024-01-14 14:53:13 +0100 | [diff] [blame] | 4 | .. index:: |
| 5 | single: eficonfig (command) |
| 6 | |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 7 | eficonfig command |
| 8 | ================= |
| 9 | |
| 10 | Synopsis |
| 11 | -------- |
| 12 | :: |
| 13 | |
| 14 | eficonfig |
| 15 | |
| 16 | Description |
| 17 | ----------- |
| 18 | |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 19 | The "eficonfig" command uses the U-Boot menu interface to provide a |
| 20 | menu-driven UEFI variable maintenance feature. These are the top level menu |
| 21 | entries: |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 22 | |
| 23 | Add Boot Option |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 24 | Add a new UEFI Boot Option. |
| 25 | The user can edit description, file path, and optional_data. |
| 26 | The new boot opiton is appended to the boot order in the *BootOrder* |
| 27 | variable. The user may want to update the boot order using the |
| 28 | *Change Boot Order* menu entry. |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 29 | |
| 30 | Edit Boot Option |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 31 | Edit an existing UEFI Boot Option. |
| 32 | The User can edit description, file path, and optional_data. |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 33 | |
| 34 | Change Boot Order |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 35 | Change the boot order updating the UEFI BootOrder variable. |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 36 | |
| 37 | Delete Boot Option |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 38 | Delete a UEFI Boot Option |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 39 | |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 40 | Secure Boot Configuration |
| 41 | Edit the UEFI Secure Boot Configuration |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 42 | |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 43 | How to boot the system with a newly added UEFI Boot Option |
| 44 | '''''''''''''''''''''''''''''''''''''''''''''''''''''''''' |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 45 | |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 46 | The "eficonfig" command is used to set the UEFI boot options which are stored |
| 47 | in the UEFI variable Boot#### where #### is a hexadecimal number. |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 48 | |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 49 | The command *bootefi bootmgr* can be used to boot by trying in sequence all |
| 50 | boot options selected by the variable *BootOrder*. |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 51 | |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 52 | If the bootmenu is enabled, CONFIG_BOOTMENU_DISABLE_UBOOT_CONSOLE is enabled, |
| 53 | and "eficonfig" is configured as preboot command, the newly added Boot Options |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 54 | are enumerated in the bootmenu when the user exits from the eficonfig menu. |
| 55 | The user may select the entry in the bootmenu to boot the system, or follow |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 56 | the U-Boot configuration the system already has. |
| 57 | |
| 58 | Auto boot with the UEFI Boot Option |
| 59 | ''''''''''''''''''''''''''''''''''' |
| 60 | |
| 61 | To do auto boot according to the UEFI BootOrder variable, |
| 62 | add "bootefi bootmgr" entry as a default or first bootmenu entry:: |
| 63 | |
| 64 | CONFIG_PREBOOT="setenv bootmenu_0 UEFI Boot Manager=bootefi bootmgr; setenv bootmenu_1 UEFI Maintenance Menu=eficonfig" |
| 65 | |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 66 | UEFI Secure Boot Configuration |
| 67 | '''''''''''''''''''''''''''''' |
| 68 | |
| 69 | The user can enroll the variables PK, KEK, db and dbx by selecting a file. |
| 70 | The "eficonfig" command only accepts signed EFI Signature List(s) with an |
| 71 | authenticated header, typically a ".auth" file. |
| 72 | |
| 73 | To clear the PK, KEK, db and dbx, the user needs to enroll a null value |
| 74 | signed by PK or KEK. |
| 75 | |
| 76 | Configuration |
| 77 | ------------- |
| 78 | |
| 79 | The "eficonfig" command is enabled by:: |
| 80 | |
| 81 | CONFIG_CMD_EFICONFIG=y |
| 82 | |
| 83 | If CONFIG_BOOTMENU_DISABLE_UBOOT_CONSOLE is enabled, the user can not enter |
| 84 | U-Boot console. In this case, the bootmenu can be used to invoke "eficonfig":: |
| 85 | |
| 86 | CONFIG_USE_PREBOOT=y |
| 87 | CONFIG_PREBOOT="setenv bootmenu_0 UEFI Maintenance Menu=eficonfig" |
| 88 | |
| 89 | The only way U-Boot can currently store EFI variables on a tamper |
| 90 | resistant medium is via OP-TEE. The Kconfig option that enables that is:: |
| 91 | |
| 92 | CONFIG_EFI_MM_COMM_TEE=y. |
| 93 | |
| 94 | It enables storing EFI variables on the RPMB partition of an eMMC device. |
| 95 | |
| 96 | The UEFI Secure Boot Configuration menu entry is only available if the following |
| 97 | options are enabled:: |
| 98 | |
| 99 | CONFIG_EFI_SECURE_BOOT=y |
| 100 | CONFIG_EFI_MM_COMM_TEE=y |
| 101 | |
Masahisa Kojima | dfcf0e5 | 2022-09-12 17:33:58 +0900 | [diff] [blame] | 102 | See also |
| 103 | -------- |
Masahisa Kojima | 0746842 | 2022-12-02 13:59:37 +0900 | [diff] [blame] | 104 | |
| 105 | * :doc:`bootmenu<bootmenu>` provides a simple mechanism for creating menus with |
| 106 | different boot items |