Method, apparatus, device, and medium for dumping server BIOS image
By connecting the BIOS memory with the BMC in the server, dumping the BIOS image and hash value fields, and restoring the control of the BIOS firmware program, the problem of failure cannot be detected when ME is damaged or PECI is dead, and the dumping of the BIOS image and the acquisition of the configuration content of the BIOS firmware program is realized.
Patent Information
- Application Number
- CN202211308255.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-25
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-10-25
AI Technical Summary
When the management engine ME is damaged or the data interface communication bus PECI is dead, the existing ACD tools cannot communicate with the CPU and cannot obtain CPU register information, which affects the troubleshooting of the online computer room.
The board management controller BMC sends link strobe switching commands to the complex programmable logic device CPLD to realize the communication between the BIOS memory and the BMC, reads and dumps the BIOS image and hash value fields, and verifies the accuracy of the image file through the hash value, and finally restores the control rights of the BIOS firmware program.
It realizes that the server BIOS image can still be dumped when the ME is damaged or PECI is dead, helps with troubleshooting, and obtains the BIOS firmware program configuration content when the server is powered on.
Smart Images

Figure CN115599583B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of server monitoring and management, and in particular to a method, an operation method, an apparatus, a computer device and a storage medium for dumping a server BIOS image. Background Art
[0002] As the functions of servers become increasingly powerful and complex, the size of the Basic Input Output System (BIOS) firmware program is getting larger and larger. The BIOS firmware program is usually stored in Flash. At present, Flash generally uses low-speed interfaces such as Serial Peripheral Interface (SPI) to interconnect with the CPU in the server.
[0003] For server monitoring and management, the current industry-wide tool commonly used is the online crash dump (ACD) tool officially released by Intel, which has limitations in fault diagnosis of computer rooms. When the server is in normal mode, the baseboard management controller (BMC) can communicate with the management engine ME on the integrated south bridge (PCH). When the server crashes or other failures occur, there is no server-side method to communicate with the management engine ME on the integrated south bridge (PCH) through the baseboard management controller (BMC), and the fault problem needs to be troubleshooted. When the ME is damaged and the data interface communication bus (PECI, proposed by Intel) is hung, the ACD tool cannot communicate with the CPU and cannot obtain CPU register information, which affects the online computer room problem troubleshooting. Summary of the invention
[0004] Based on this, it is necessary to provide a method, operation method, device, computer equipment and storage medium for dumping server BIOS image to address the above-mentioned technical problems, which can solve the technical problem that when ME is damaged and the data interface communication bus (PECI) is hung, the ACD tool cannot communicate with the CPU and cannot obtain CPU register information, affecting the online computer room problem troubleshooting.
[0005] On the one hand, a method for dumping a server BIOS image is provided, the method comprising:
[0006] The baseboard management controller BMC sends a link gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path gating chip to switch the gating link to realize that the BIOS memory is connected to the baseboard management controller BMC through the path gating chip (Switch mux);
[0007] Mount the BIOS memory (BIOS ROM) under the file system of the baseboard management controller BMC;
[0008] Read and dump the BIOS image and the hash value field generated each time the BIOS firmware program starts according to the size of the BIOS memory (BIOS ROM);
[0009] After the BIOS image and the hash value field are dumped, use the hash value in the hash value field to verify the accuracy of the dumped BIOS image file;
[0010] Restore the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), and enable the baseboard management controller BMC to communicate with the integrated south bridge PCH through the path selection chip (Switch mux).
[0011] In one embodiment, the integrated south bridge PCH stores a management engine ME;
[0012] Before the baseboard management controller BMC sends a link selection switch command to the complex programmable logic device CPLD, it further includes: selecting whether to enter the management engine ME into the recovery mode; when the server system is not down, select the management engine ME to enter the recovery mode, and when the server system is down, select the management engine ME not to enter the recovery mode;
[0013] When the management engine ME enters the recovery mode, after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), it further includes: switching the management engine ME to the normal mode to enable the baseboard management controller BMC to communicate with the management engine ME on the integrated south bridge PCH.
[0014] In one embodiment, when the server system is down, before dumping the BIOS image and before restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), it further includes:
[0015] Uninstall and reinstall the BIOS firmware program from the file system of the baseboard management controller BMC.
[0016] In one embodiment, the step of reading and dumping the BIOS image and the hash value field generated each time the BIOS firmware program starts according to the size of the BIOS memory (BIOS ROM) includes:
[0017] Configure the read and write length of the BIOS flash memory (BIOS Flash) size file in the BIOS memory (BIOS ROM), wherein the BIOS image and the hash value field are stored in the BIOS flash memory;
[0018] The BIOS image and the hash value field are read and dumped according to the actual read and write length of the BIOS flash memory.
[0019] In one of the embodiments, after each startup of the BIOS firmware program, all images will generate corresponding hash values according to the SHA256 algorithm and save them in a fixed address of the BIOS flash memory;
[0020] After the dumping of the BIOS image and the hash value field is completed, the step of using the hash value in the hash value field to verify the accuracy of the dumped BIOS image file specifically includes: recalculating the generated hash value according to the SHA256 algorithm and comparing it with the hash value in the hash value field; when the hash values are the same, it is determined that the dumped BIOS image and the hash value field content are correct; when the hash values are different, it is determined that the dumped BIOS image and the hash value field content are wrong, and the BIOS image and the hash value field are dumped again. In this way, the accuracy of the BIOS image file is verified.
[0021] In one of the embodiments, the baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD and the BIOS memory are all connected to the switch mux chip through a serial peripheral interface SPI link; the BIOS image and the hash value field data in the BIOS flash memory are read and dumped according to the SPI bus protocol;
[0022] The integrated south bridge PCH is connected to the processor CPU; after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), the baseboard management controller BMC and the processor CPU are interacted in real time, and the baseboard management controller BMC obtains the temperature information of the processor CPU.
[0023] On the other hand, a method for dumping a server BIOS image is provided, comprising the steps of:
[0024] A baseboard management controller BMC in the server is configured to be interconnected with an integrated south bridge PCH, a complex programmable logic device CPLD, and a BIOS memory storing a BIOS firmware program through a path selection chip;
[0025] A dump tool is installed in the baseboard management controller BMC; the dump tool includes a computer program for implementing the method of dumping the server BIOS image as described above;
[0026] Running the dump tool to download the BIOS image to the file system of the baseboard management controller BMC; and
[0027] Use the wget command or the scp command to copy the downloaded BIOS image to the local storage medium.
[0028] On the other hand, a device for dumping a server BIOS image is provided, the device comprising:
[0029] A link switching control module, used for the baseboard management controller BMC to send a link gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path gating chip to switch the gating link to realize that the BIOS memory is connected to the baseboard management controller BMC through the path gating chip (Switch mux);
[0030] A control transfer module, used for mounting the BIOS memory (BIOS ROM) to the file system of the baseboard management controller BMC;
[0031] A dump execution module, used for reading and dumping the BIOS image and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory (BIOS ROM);
[0032] A BIOS image file verification module, configured to verify the accuracy of the dumped BIOS image file using the hash value in the hash value field after the dumping of the BIOS image and the hash value field is completed;
[0033] The control right recovery module is used to recover the control right of the BIOS firmware program in the BIOS memory (BIOS ROM) so as to realize the baseboard management controller BMC being connected to the integrated south bridge PCH through the switch mux chip.
[0034] In one embodiment, the device further comprises:
[0035] The ME mode switching module is used to selectively enable the management engine ME stored in the integrated south bridge PCH to enter a recovery mode; and is used to switch the management engine ME from the recovery mode to the normal mode, so as to enable the baseboard management controller BMC to communicate with the management engine ME on the integrated south bridge PCH.
[0036] In another aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are implemented:
[0037] The baseboard management controller BMC sends a link gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path gating chip to switch the gating link to realize that the BIOS memory is connected to the baseboard management controller BMC through the path gating chip (Switch mux);
[0038] Mounting the BIOS memory (BIOS ROM) to the file system of the baseboard management controller BMC;
[0039] Read and dump the BIOS image and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory (BIOS ROM);
[0040] After the BIOS image and the hash value field are dumped, the accuracy of the dumped BIOS image file is verified using the hash value in the hash value field;
[0041] The control right of the BIOS firmware program in the BIOS memory (BIOS ROM) is restored, so that the baseboard management controller BMC is connected to the integrated south bridge PCH through the switch mux chip.
[0042] In another aspect, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0043] The baseboard management controller BMC sends a link gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path gating chip to switch the gating link to realize that the BIOS memory is connected to the baseboard management controller BMC through the path gating chip (Switch mux);
[0044] Mounting the BIOS memory (BIOS ROM) to the file system of the baseboard management controller BMC;
[0045] Read and dump the BIOS image and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory (BIOS ROM);
[0046] After the BIOS image and the hash value field are dumped, use the hash value in the hash value field to verify the accuracy of the dumped BIOS image file;
[0047] Restore the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), and implement the communication between the baseboard management controller BMC and the integrated south bridge PCH through the path selection chip (Switch mux).
[0048] The above method, operation method, device, computer device and storage medium for dumping the server BIOS image realize the connection between the BIOS memory and the baseboard management controller BMC by using a complex programmable logic device CPLD to control the path selection chip to switch the selected link, and then mount the BIOS memory (BIOS ROM) to the file system of the baseboard management controller BMC to dump the BIOS image and the hash value field. Use the hash value in the hash value field to verify the accuracy of the dumped BIOS image file, and then restore the control right of the BIOS firmware program in the BIOS memory, realizing the dumping of the BIOS image file for reproducing problems of the BIOS firmware program, checking whether the ME image is damaged, and also obtaining the configuration content of the BIOS firmware program in a user-unaware manner when the server is powered on. Brief Description of the Drawings
[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0050] Figure 1 It is an application environment diagram of the method and operation method for dumping the server BIOS image in an embodiment;
[0051] Figure 2 It is a flowchart of the method for dumping the server BIOS image in an embodiment;
[0052] Figure 3 It is a flowchart of the step of reading and dumping the BIOS image in the BIOS memory and the hash value field generated each time the BIOS firmware program starts according to the size of the BIOS memory in an embodiment;
[0053] Figure 4 It is a flowchart of the operation method for dumping the server BIOS image in an embodiment;
[0054] Figure 5Structural block diagram of a device for dumping a server BIOS image in an embodiment;
[0055] Figure 6 Internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0056] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0057] As described in the background art, in the normal mode of the server, the baseboard management controller (BMC) can communicate with the management engine ME on the integrated south bridge (PCH). In order to be able to dump and obtain the BIOS image file in the BIOS memory (BIOS ROM) when the ME is damaged and the data interface communication bus (PECI) hangs up and the ACD tool cannot communicate with the CPU either, so as to reproduce the BIOS firmware program problem, check whether the ME image is damaged, and obtain the BIOS firmware program configuration content in a user-invisible manner when the server is powered on. In the embodiments of the present invention, a method for dumping a server BIOS image is creatively proposed. The implementation process of the method for dumping the server BIOS image is compiled into an app and placed under the BMC. When the server crashes, the app tool can be manually executed. At this time, a command will be sent to the CPLD, and the CPLD will operate the hardware. With the help of the app tool, the operation of dumping the BIOS image is realized, and finally the control right of the BIOS firmware program in the BIOS memory is restored to restore the server.
[0058] The method for dumping a server BIOS image provided by the present application can be applied to, for example Figure 1In the application environment shown. Among them, the server includes a path selection and gating chip (Switch mux), a baseboard management controller BMC, an integrated south bridge PCH of a storage management engine ME, a complex programmable logic device CPLD, and a BIOS memory for storing a BIOS firmware program. The baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD, and the BIOS memory are all connected to the path selection and gating chip (Switch mux) through a serial peripheral interface SPI link. Among them, the baseboard management controller BMC is interconnected with the integrated south bridge PCH, the complex programmable logic device CPLD, and the BIOS memory for storing the BIOS firmware program through the path selection and gating chip (Switch mux). Switch mux is a path selection and gating interconnection chip with 8 built-in channels (channels), and the CPLD can control which two channels communicate with each other. ME refers to a microprocessor independent of the CPU and the operating system in the integrated south bridge PCH. There are functions for remote management in the ME, and when a serious vulnerability occurs, the computer can be remotely managed without user control.
[0059] Among them, the integrated south bridge PCH is connected to the processor CPU. The integrated south bridge PCH is an external low-speed expansion interface for CPU startup. In the normal mode of the server, the baseboard management controller (BMC) communicates with the management engine ME on the integrated south bridge (PCH) to achieve real-time interaction between the baseboard management controller BMC and the processor CPU. The baseboard management controller BMC obtains the temperature information of the processor CPU, and when the temperature of the processor CPU exceeds the temperature threshold, an alarm message is sent and the fan speed is adjusted.
[0060] In one embodiment, as Figure 2 shown, a method for dumping the server BIOS image is provided. Taking the server in Figure 1 as an example for description, it includes the following steps:
[0061] Step S2, the baseboard management controller BMC sends a link selection and gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path selection and gating chip to switch the selected link to enable the BIOS memory to be connected to the baseboard management controller BMC through the path selection and gating chip (Switch mux);
[0062] Step S3, mount the BIOS memory (BIOS ROM) under the file system of the baseboard management controller BMC;
[0063] Step S4: Read and dump the BIOS image in the BIOS memory (BIOS ROM) and the hash value field generated by the BIOS firmware program each time it starts up.
[0064] Step S5: After the BIOS image and the hash value field are dumped, use the hash value in the hash value field to verify the accuracy of the dumped BIOS image file.
[0065] Step S7: Restore the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), so that the baseboard management controller BMC is connected to the integrated south bridge PCH through the path selection chip (Switch mux).
[0066] In this embodiment, since the management engine ME is stored in the integrated south bridge PCH. As Figure 2 shown, before the baseboard management controller BMC sends a link selection switching command to the complex programmable logic device CPLD, it further includes: Step S1: Select whether to enter the management engine ME into the recovery mode; when the server system is not down, select the management engine ME to enter the recovery mode, and when the server system is down, select the management engine ME not to enter the recovery mode.
[0067] It can be understood that when the server system is not down, the management engine ME enters the recovery mode so that using this tool when the system is not down does not affect the normal use of the OS. Whether to execute the step of the management engine ME not entering the recovery mode can be determined by parameters to cover the scenario when ME hangs. When the management engine ME enters the recovery mode, it is possible to dump the BIOS image and the hash value field generated by the BIOS firmware program each time it starts up, check whether the BIOS firmware program or the ME image is damaged, and obtain the BIOS configuration option content in a user-invisible manner when the server is powered on.
[0068] As Figure 2 shown, when the management engine ME enters the recovery mode, after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), it further includes: Step S8: Switch the management engine ME to the normal mode, so that the baseboard management controller BMC communicates with the management engine ME on the integrated south bridge PCH.
[0069] As Figure 2As shown, in this embodiment, when the server system crashes, after dumping the BIOS image and before restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), it further includes:
[0070] Step S6, unload and reinstall the BIOS firmware program from the file system of the baseboard management controller BMC.
[0071] It can be understood that when the server system does not crash, it is optional not to reinstall the BIOS firmware program, or manual control operations can be used to unload and reinstall the BIOS firmware program from the file system of the baseboard management controller BMC.
[0072] Such as Figure 3 As shown, in this embodiment, the step of reading and dumping the BIOS image in the BIOS memory (BIOS ROM) and the hash value field generated each time the BIOS firmware program starts includes:
[0073] Step S41, configure the file read / write length according to the size of the BIOS flash (BIOS Flash) in the BIOS memory, and the BIOS flash stores the BIOS image and the hash value field;
[0074] Step S42, read and dump the BIOS image and the hash value field according to the actual read / write length of the BIOS flash.
[0075] In this embodiment, after each startup of the BIOS firmware program, the entire image will generate a corresponding hash value according to the SHA256 algorithm and be saved at a fixed address in the BIOS flash;
[0076] After the BIOS image and the hash value field are dumped, step S5 of verifying the accuracy of the dumped BIOS image file by using the hash value in the hash value field specifically includes: calculating the hash value again according to the SHA256 algorithm and comparing it with the hash value in the hash value field; when the hash values are the same, it is determined that the dumped BIOS image and the content of the hash value field are correct; when the hash values are different, it is determined that the dumped BIOS image and the content of the hash value field are incorrect, and the BIOS image and the hash value field are redumped. In this way, the accuracy of the BIOS image file is verified.
[0077] Among them, the hash value length used by the SHA256 algorithm is 256 bits. This is an abstract class. The only implementation of this class is SHA256Managed. SHA256 is a hash function. Hash function, also known as hash algorithm, is a method of creating a small digital "fingerprint" from any kind of data. The hash function compresses the message or data into a summary, making the data smaller and fixing the format of the data. The function shuffles and mixes the data to recreate a fingerprint called a hash value (or hash value). The hash value is usually represented by a short string of random letters and numbers. For messages of any length, SHA256 will generate a 256-bit hash value, called a message digest.
[0078] In this embodiment, the baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD and the BIOS memory are all linked to the switch mux through a serial peripheral interface SPI link; the BIOS image and the hash value field data in the BIOS flash memory are read and dumped according to the SPI bus protocol; the integrated south bridge PCH is connected to the processor CPU; after restoring the control of the BIOS firmware program in the BIOS memory (BIOS ROM), the baseboard management controller BMC and the processor CPU are interacted in real time, and the baseboard management controller BMC obtains the temperature information of the processor CPU.
[0079] On the other hand, Figure 4 As shown, a method for dumping a server BIOS image is provided, comprising the steps of:
[0080] Step S11, setting the baseboard management controller BMC in the server to be interconnected with the integrated south bridge PCH, the complex programmable logic device CPLD and the BIOS memory storing the BIOS firmware program through the path gating chip;
[0081] Step S12, installing a dump tool in the baseboard management controller BMC; the dump tool includes a computer program for implementing the method for dumping the server BIOS image as described above;
[0082] Step S13, running the dump tool to download the BIOS image to the file system of the baseboard management controller BMC; and
[0083] Step S14, copying the downloaded BIOS image to a local storage medium through a wget command or an scp command.
[0084] like Figure 1As shown, the principle of the operation method of the dump server BIOS image can refer to the previous content and will not be elaborated here.
[0085] In the operation method of the dump server BIOS image, the computer program of the method for the dump server BIOS image described above is compiled into an app and placed under the BMC. When the server crashes, the app tool can be manually executed. At this time, a command will be sent to the CPLD, and the CPLD will operate the hardware. With the help of this app tool, the operation of dumping the BIOS image is realized, and finally the control right of the BIOS firmware program in the BIOS memory is restored to restore the server.
[0086] In the above method and operation method for dumping the server BIOS image, the complex programmable logic device CPLD is used to control the path selection chip to switch the selected link to connect the BIOS memory to the baseboard management controller BMC, and then the BIOS memory (BIOS ROM) is mounted to the file system of the baseboard management controller BMC to dump the BIOS image and the hash value field. The accuracy of the dumped BIOS image file is verified by using the hash value in the hash value field, and then the control right of the BIOS firmware program in the BIOS memory is restored, realizing the dumping of the BIOS image file for reproducing the BIOS firmware program problem, checking whether the ME image is damaged, and also obtaining the BIOS firmware program configuration content in a user-unaware manner when the server is powered on.
[0087] It should be understood that although Figures 2-4 the steps in the flowchart are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, Figures 2-6 at least a part of the steps in
[0088] may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps. Figure 5 In one embodiment, as
[0089] The link switching control module 1 is used for the baseboard management controller (BMC) to send a link strobe switching command to the complex programmable logic device (CPLD). The CPLD controls the path selection chip to switch the selected link, so as to realize the connection between the BIOS memory and the BMC through the path selection chip (Switch mux).
[0090] The control right transfer module 2 is used to mount the BIOS memory (BIOS ROM) under the file system of the BMC.
[0091] The dump execution module 3 is used to read and dump the BIOS image and the hash value field generated each time the BIOS firmware program starts according to the size of the BIOS memory (BIOS ROM).
[0092] The BIOS image file verification module 4 is used to verify the accuracy of the dumped BIOS image file by using the hash value in the hash value field after the BIOS image and the hash value field are dumped.
[0093] The control right recovery module 5 is used to recover the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), so as to realize the connection between the BMC and the integrated south bridge PCH through the path selection chip (Switch mux).
[0094] The ME mode switching module 6 is used to selectively enter the management engine ME stored in the integrated south bridge PCH into the recovery mode; and is used to switch the management engine ME from the recovery mode to the normal mode, so as to realize the communication between the BMC and the management engine ME on the integrated south bridge PCH.
[0095] In this embodiment, the management engine ME is stored in the integrated south bridge PCH; as Figure 5 shown, the device 10 for dumping the server BIOS image further includes: an ME mode switching module 7. The ME mode switching module 7 is used to selectively enter the management engine ME stored in the integrated south bridge PCH into the recovery mode; and is used to switch the management engine ME from the recovery mode to the normal mode, so as to realize the communication between the BMC and the management engine ME on the integrated south bridge PCH.
[0096] Specifically, before the Baseboard Management Controller (BMC) sends a link strobe switching command to the Complex Programmable Logic Device (CPLD), the ME mode switching module 7 is used to select whether to enter the management engine ME into the recovery mode; when the server system is not down, select the management engine ME to enter the recovery mode, and when the server system is down, select the management engine ME not to enter the recovery mode.
[0097] When the management engine ME enters the recovery mode, after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), the ME mode switching module 7 is used to: switch the management engine ME to the normal mode to enable communication between the Baseboard Management Controller (BMC) and the management engine ME on the integrated south bridge PCH.
[0098] As Figure 5 shown, in this embodiment, the device 10 for dumping the server BIOS image further includes: a BIOS firmware program management module 8. When the server system is down, after dumping the BIOS image and before restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), the BIOS firmware program management module 8 is used to: unload and reinstall the BIOS firmware program from the file system of the Baseboard Management Controller (BMC).
[0099] In this embodiment, the step of reading and dumping the BIOS image in the BIOS memory (BIOS ROM) and the hash value field generated each time the BIOS firmware program is started includes:
[0100] Configure the file read / write length according to the size of the BIOS flash (BIOS Flash) in the BIOS memory (BIOS ROM), where the BIOS flash stores the BIOS image and the hash value field;
[0101] Read and dump the BIOS image and the hash value field according to the actual read / write length of the BIOS flash.
[0102] In this embodiment, after each startup of the BIOS firmware program, the entire image will be generated into a corresponding hash value according to the SHA256 algorithm and saved at a fixed address in the BIOS flash.
[0103] After the dumping of the BIOS image and the hash value field is completed, the step of using the hash value in the hash value field to verify the accuracy of the dumped BIOS image file specifically includes: recalculating the generated hash value according to the SHA256 algorithm and comparing it with the hash value in the hash value field; when the hash values are the same, it is determined that the dumped BIOS image and the hash value field content are correct; when the hash values are different, it is determined that the dumped BIOS image and the hash value field content are wrong, and the BIOS image and the hash value field are dumped again. In this way, the accuracy of the BIOS image file is verified.
[0104] In this embodiment, the baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD and the BIOS memory are all connected to the switch mux chip through a serial peripheral interface SPI link; the BIOS image and the hash value field data in the BIOS flash memory are read and dumped according to the SPI bus protocol;
[0105] The integrated south bridge PCH is connected to the processor CPU; after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), the baseboard management controller BMC and the processor CPU are interacted in real time, and the baseboard management controller BMC obtains the temperature information of the processor CPU.
[0106] In the above-mentioned device for dumping the server BIOS image, the BIOS memory is connected to the baseboard management controller BMC by using a complex programmable logic device CPLD to control the path gating chip to switch the gating link, and then the BIOS memory (BIOS ROM) is mounted to the file system of the baseboard management controller BMC to dump the BIOS image and hash value field, and the accuracy of the dumped BIOS image file is verified by using the hash value in the hash value field, and then the control right of the BIOS firmware program in the BIOS memory is restored, thereby realizing the dumping of the BIOS image file, so as to reproduce the BIOS firmware program problem and check whether the ME image is damaged. The BIOS firmware program configuration content can also be obtained in a user-imperceptible manner when the server is turned on.
[0107] For the specific limitations of the apparatus for dumping the server BIOS image, reference may be made to the limitations of the method for dumping the server BIOS image in the foregoing text, which will not be elaborated herein. Each module in the above apparatus for dumping the server BIOS image can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.
[0108] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 6 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and programs in the non-volatile storage medium. The database of the computer device is used to store data of the server BIOS image. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a method for dumping the server BIOS image.
[0109] Those skilled in the art can understand that Figure 6 the structure shown in
[0110] is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0111] The baseboard management controller (BMC) sends a link strobe switching command to the complex programmable logic device (CPLD), and the complex programmable logic device (CPLD) controls the path strobe chip to switch the strobe link to enable the BIOS memory to communicate with the baseboard management controller (BMC) through the path strobe chip (Switch mux);
[0112] Mount the BIOS memory (BIOS ROM) under the file system of the baseboard management controller (BMC);
[0113] Read and dump the BIOS image and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory (BIOS ROM);
[0114] After the BIOS image and the hash value field are dumped, the accuracy of the dumped BIOS image file is verified using the hash value in the hash value field;
[0115] The control right of the BIOS firmware program in the BIOS memory (BIOS ROM) is restored, so that the baseboard management controller BMC is connected to the integrated south bridge PCH through the switch mux chip.
[0116] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0117] The integrated south bridge PCH stores a management engine ME;
[0118] Before the baseboard management controller BMC sends the link gating switching command to the complex programmable logic device CPLD, it also includes: selecting whether to put the management engine ME into recovery mode; when the server system is not down, the management engine ME is selected to enter the recovery mode, and when the server system is down, the management engine ME is selected not to enter the recovery mode;
[0119] When the management engine ME enters recovery mode, after restoring the control right of the BIOS firmware program in the BIOS memory (BIOSROM), it also includes: switching the management engine ME to normal mode to enable the baseboard management controller BMC to communicate with the management engine ME on the integrated south bridge PCH.
[0120] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0121] When the server system is down, after dumping the BIOS image and before restoring the control right of the BIOS firmware program in the BIOS memory (BIOSROM), the method further includes:
[0122] The BIOS firmware program is uninstalled from the file system of the baseboard management controller BMC and then reinstalled.
[0123] In one embodiment, when the processor executes the computer program, the processor further implements the following steps:
[0124] The steps of reading and dumping the BIOS image in the BIOS memory (BIOS ROM) and the hash value field generated each time the BIOS firmware program is started include:
[0125] Configure the read / write length according to the size of the BIOS flash (BIOS Flash) in the BIOS memory (BIOS ROM), where the BIOS flash stores the BIOS image and the hash value field;
[0126] Read and dump the BIOS image and the hash value field according to the actual read / write length of the BIOS flash.
[0127] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0128] After the BIOS firmware program is started and completed each time, generate the corresponding hash value for all images according to the SHA256 algorithm and save it at a fixed address in the BIOS flash;
[0129] After the BIOS image and the hash value field are dumped, the steps of verifying the accuracy of the dumped BIOS image file by using the hash value in the hash value field specifically include: calculating the hash value again according to the SHA256 algorithm and comparing it with the hash value in the hash value field; when the hash values are the same, it is determined that the dumped BIOS image and the content of the hash value field are correct; when the hash values are different, it is determined that the dumped BIOS image and the content of the hash value field are incorrect, and the BIOS image and the hash value field are dumped again. In this way, the accuracy of the BIOS image file is verified.
[0130] In one embodiment, when the processor executes the computer program, the following steps are also implemented:
[0131] The baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD, and the BIOS memory are all linked to the path selection chip (Switch mux) through a serial peripheral interface SPI link; read and dump the BIOS image and the hash value field data in the BIOS flash according to the SPI bus protocol;
[0132] The integrated south bridge PCH is connected to the processor CPU; after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), realize real-time interaction between the baseboard management controller BMC and the processor CPU, and the baseboard management controller BMC obtains the temperature information of the processor CPU, when the processor CPU.
[0133] For specific limitations on the steps implemented when the processor executes the computer program, please refer to the limitations on the method for dumping the server BIOS image above, which will not be repeated here.
[0134] In one embodiment, a computer readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0135] The baseboard management controller BMC sends a link gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path gating chip to switch the gating link to realize that the BIOS memory is connected to the baseboard management controller BMC through the path gating chip (Switch mux);
[0136] Mounting the BIOS memory (BIOS ROM) to the file system of the baseboard management controller BMC;
[0137] Read and dump the BIOS image and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory (BIOS ROM);
[0138] After the BIOS image and the hash value field are dumped, the accuracy of the dumped BIOS image file is verified using the hash value in the hash value field;
[0139] The control right of the BIOS firmware program in the BIOS memory (BIOS ROM) is restored, so that the baseboard management controller BMC is connected to the integrated south bridge PCH through the switch mux chip.
[0140] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0141] The integrated south bridge PCH stores a management engine ME;
[0142] Before the baseboard management controller BMC sends the link gating switching command to the complex programmable logic device CPLD, it also includes: selecting whether to put the management engine ME into recovery mode; when the server system is not down, the management engine ME is selected to enter the recovery mode, and when the server system is down, the management engine ME is selected not to enter the recovery mode;
[0143] When the management engine ME enters the recovery mode, after recovering the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), it further includes: switching the management engine ME to the normal mode to enable communication between the baseboard management controller BMC and the management engine ME on the integrated south bridge PCH.
[0144] In one embodiment, when the computer program is executed by a processor, it further implements the following steps:
[0145] When the server system crashes, after dumping the BIOS image and before recovering the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), it further includes:
[0146] Unloading and reinstalling the BIOS firmware program from the file system of the baseboard management controller BMC.
[0147] In one embodiment, when the computer program is executed by a processor, it further implements the following steps:
[0148] The step of reading and dumping the BIOS image and the hash value field generated each time the BIOS firmware program starts according to the size of the BIOS memory (BIOS ROM) includes:
[0149] Configuring the file read / write length according to the size of the BIOS flash (BIOS Flash) in the BIOS memory, where the BIOS image and the hash value field are stored in the BIOS flash memory;
[0150] Reading and dumping the BIOS image and the hash value field according to the actual read / write length of the BIOS flash.
[0151] In one embodiment, when the computer program is executed by a processor, it further implements the following steps:
[0152] After each startup of the BIOS firmware program is completed, the entire image is generated into a corresponding hash value according to the SHA256 algorithm and saved at a fixed address in the BIOS flash.
[0153] After the dumping of the BIOS image and the hash value field is completed, the step of using the hash value in the hash value field to verify the accuracy of the dumped BIOS image file specifically includes: recalculating the generated hash value according to the SHA256 algorithm and comparing it with the hash value in the hash value field; when the hash values are the same, it is determined that the dumped BIOS image and the hash value field content are correct; when the hash values are different, it is determined that the dumped BIOS image and the hash value field content are wrong, and the BIOS image and the hash value field are dumped again. In this way, the accuracy of the BIOS image file is verified.
[0154] In one embodiment, when the computer program is executed by a processor, the following steps are also implemented:
[0155] The baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD and the BIOS memory are all connected to the switch mux chip through a serial peripheral interface SPI link; the BIOS image and the hash value field data in the BIOS flash memory are read and dumped according to the SPI bus protocol;
[0156] The integrated south bridge PCH is connected to the processor CPU; after restoring the control right of the BIOS firmware program in the BIOS memory (BIOS ROM), the baseboard management controller BMC and the processor CPU are interacted in real time, and the baseboard management controller BMC obtains the temperature information of the processor CPU.
[0157] For specific limitations on the steps implemented when the computer program is executed by the processor, please refer to the limitations on the method for dumping the server BIOS image above, which will not be repeated here.
[0158] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0159] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0160] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A method for dumping a server BIOS image. It is characterized in that Applicable to a baseboard management controller BMC, the baseboard management controller BMC is interconnected with an integrated south bridge PCH, a complex programmable logic device CPLD and a BIOS memory storing a BIOS firmware program through a path gating chip, and a management engine ME is stored in the integrated south bridge PCH; the method comprises: Choose whether to put the management engine ME into recovery mode; The baseboard management controller BMC sends a link gating switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path gating chip to switch the gating link to enable the BIOS memory to be connected to the baseboard management controller BMC through the path gating chip; Mounting the BIOS memory to the file system of the baseboard management controller BMC; Read and dump the BIOS image therein and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory; After the BIOS image and the hash value field are dumped, the accuracy of the dumped BIOS image file is verified using the hash value in the hash value field; Restoring the control right of the BIOS firmware program in the BIOS memory, so that the baseboard management controller BMC is connected to the integrated south bridge PCH through the path gating chip; When the management engine ME enters the recovery mode, after the control right of the BIOS firmware program in the BIOS memory is restored, the management engine ME is switched to the normal mode to enable the baseboard management controller BMC to communicate with the management engine ME on the integrated south bridge PCH.
2. The method for dumping a server BIOS image according to claim 1, It is characterized in that The method further comprises: when the server system is not down, selecting the management engine ME to enter the recovery mode, and when the server system is down, selecting the management engine ME not to enter the recovery mode.
3. The method for dumping a server BIOS image according to claim 2, It is characterized in that When the server system is down, after dumping the BIOS image and before restoring the control right of the BIOS firmware program in the BIOS memory, the method further includes: The BIOS firmware program is uninstalled from the file system of the baseboard management controller BMC and then reinstalled.
4. The method for dumping a server BIOS image according to claim 1, It is characterized in that The step of reading and dumping the BIOS image and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory comprises: According to the BIOS flash memory size configuration file read and write length in the BIOS memory, the BIOS image and hash value field are stored in the BIOS flash memory; The BIOS image and the hash value field are read and dumped according to the actual read and write length of the BIOS flash memory.
5. The method for dumping a server BIOS image according to claim 4, It is characterized in that After each startup of the BIOS firmware program is completed, all images are used to generate corresponding hash values according to the SHA256 algorithm and saved at a fixed address in the BIOS flash memory; After the BIOS image and the hash value field are dumped, the steps for verifying the accuracy of the dumped BIOS image file by using the hash value in the hash value field specifically include: calculating the hash value again according to the SHA256 algorithm and comparing it with the hash value in the hash value field; When the hash values are the same, it is determined that the dumped BIOS image and the content of the hash value field are correct; when the hash values are different, it is determined that the dumped BIOS image and the content of the hash value field are incorrect, and the BIOS image and the hash value field are dumped again.
6. The method for dumping the server BIOS image according to claim 4, wherein, the baseboard management controller BMC, the integrated south bridge PCH, the complex programmable logic device CPLD, and the BIOS memory are all connected to the path selection chip through a serial peripheral interface SPI link; read and dump the BIOS image and the hash value field data in the BIOS flash memory according to the SPI bus protocol; the integrated south bridge PCH is connected to the processor CPU; After restoring the control right of the BIOS firmware program in the BIOS memory, real-time interaction between the baseboard management controller BMC and the processor CPU is realized. The baseboard management controller BMC obtains the temperature information of the processor CPU, and issues an alarm message and adjusts the fan speed when the temperature of the processor CPU exceeds the temperature threshold.
7. An operation method for dumping the server BIOS image, wherein, it includes the steps: Set the baseboard management controller BMC in the server to be interconnected with the integrated south bridge PCH, the complex programmable logic device CPLD, and the BIOS memory storing the BIOS firmware program through the path selection chip respectively; Install a dumping tool in the baseboard management controller BMC; the dumping tool includes a computer program for implementing the method for dumping the server BIOS image according to any one of claims 1 to 6; Run the dumping tool to download the BIOS image to the file system of the baseboard management controller BMC; Copy the downloaded BIOS image to the local storage medium through the wget command or the scp command.
8. An apparatus for dumping the server BIOS image, wherein, the apparatus includes: A link switching control module, configured to select whether to enter the recovery mode for the management engine ME, and the baseboard management controller BMC sends a link selection switching command to the complex programmable logic device CPLD, and the complex programmable logic device CPLD controls the path selection chip to switch the selected link to enable the BIOS memory to be connected to the baseboard management controller BMC through the path selection chip; A control right transfer module, configured to mount the BIOS memory under the file system of the baseboard management controller BMC; A dump execution module, used for reading and dumping the BIOS image therein and the hash value field generated each time the BIOS firmware program is started according to the size of the BIOS memory; A BIOS image file verification module, configured to verify the accuracy of the dumped BIOS image file using the hash value in the hash value field after the dumping of the BIOS image and the hash value field is completed; A control right recovery module is used to recover the control right of the BIOS firmware program in the BIOS memory, so that the baseboard management controller BMC is connected to the integrated south bridge PCH through the path selection chip, and when the management engine ME enters the recovery mode, after the control right of the BIOS firmware program in the BIOS memory is recovered, the management engine ME is switched to the normal mode, so that the baseboard management controller BMC communicates with the management engine ME on the integrated south bridge PCH.
9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, It is characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
A system and method for secure boot of server
CN110109715A
Firmware recovery method, device and system, computer equipment and storage medium
CN111949449A