Configuration modification method of access control service, server and computer program product
By creating a data structure during server startup and writing the ACS register flag bit during target device initialization, the problem of complex ACS function modification operations in the prior art is solved, and simplified ACS function control is achieved.
Patent Information
- Application Number
- CN202511335435.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-09-18
AI Technical Summary
In the existing technology, modifying the access control service (ACS) function of a PCIe device requires additional modifications or the development of new code, which is a relatively complicated process. Furthermore, BIOS option modifications only affect the boot process and do not affect the ACS function configuration under the operating system.
During server startup, based on the user's start/stop option modification, a data structure is created to store the target's valid values. These values are then obtained through the platform's configuration data acquisition function during target device initialization. The flag bits are directly written to the registers corresponding to the access control service to enable or disable the ACS function.
This allows for enabling or disabling the ACS function of each target device with a single modification during the entire server startup process, simplifying the operation and eliminating the need to separately enable and disable the ACS function within the operating system.
Smart Images

Figure CN120832689A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of servers, and particularly relates to a configuration modification method of an access control service, a server and a computer program product. BACKGROUND
[0002] Access Control Services (ACS) is a key security function in the PCIe (Peripheral Component Interconnect Express) standard, which can provide hardware-level access control and isolation, but also has a high performance overhead.
[0003] Different customers may have different requirements for the opening or not of the ACS function in different demand scenarios, and some customers select whether to open the ACS function by modifying the start option (Enable option) of the ACS in the BIOS (Basic Input / Output System) option. However, modifying the BIOS option can only change the opening or prohibition of the ACS function in the BIOS startup stage, and does not affect the opening and closing of the ACS function of the PCIe device. The related technology further opens or prohibits the ACS function of the PCIe device by additionally performing a modification operation or developing new code, and the operation process is relatively cumbersome. SUMMARY
[0004] The present application provides a configuration modification method of an access control service, a server and a computer program product to at least solve the problem that the related art further opens or prohibits the ACS function of the PCIe device by additionally performing a modification operation or developing new code, and the operation process is relatively cumbersome.
[0005] The present application provides a configuration modification method of an access control service, which is applied to a basic input / output system of a server and includes the following steps. In a current startup process of the server, a first data structure for storing a target effective value after modification is created based on a modification operation of a start-stop option of the access control service by a user before the current startup, and the first data structure is a data structure for describing and storing platform configuration data; In an initialization process of each target device, the target device is a device supporting the Peripheral Component Interconnect Express bus, and the target effective value in the first data structure is obtained through a platform configuration data obtaining function in a case where it is determined that the target device currently being initialized supports the access control service; Based on the target effective value in the first data structure, a flag bit is written into a register corresponding to the corresponding access control service of the target device to enable or close the access control service of the target device.
[0006] The application further provides a server, which comprises a central processing unit, a basic input / output system and target devices; the target devices are devices supporting peripheral component interconnect express (PCIe) bus; The basic input / output system triggers server restart based on a modification operation of a user on a start / stop option of the access control service; The central processing unit is configured to start the basic input / output system after the server is powered on; The basic input / output system is configured to create a first data structure for storing a modified target effective value based on a modification operation of a user on a start / stop option of the access control service before the current start of the server during the current start of the server, and the first data structure is a data structure for describing and storing platform configuration data; The basic input / output system is configured to acquire the target effective value in the first data structure through a platform configuration data acquisition function in the case that the current initialized target device supports the access control service during the initialization of the target devices; The basic input / output system is further configured to perform flag bit writing on a register corresponding to the access control service of the target device based on the target effective value in the first data structure, so as to enable or close the access control service of the target device.
[0007] The application further provides a computer program product applied to a basic input / output system of a server, comprising: A creating module, configured to create a first data structure for storing a modified target effective value based on a modification operation of a user on a start / stop option of the access control service before the current start of the server during the current start of the server, and the first data structure is a data structure for describing and storing platform configuration data; A processing module, configured to acquire the target effective value in the first data structure through a platform configuration data acquisition function in the case that the current initialized target device supports the access control service during the initialization of the target devices; A configuration module, configured to perform flag bit writing on a register corresponding to the access control service of the target device based on the target effective value in the first data structure, so as to enable or close the access control service of the target device. The application further provides a server, which comprises a basic input / output system, and the basic input / output system comprises the computer program product.
[0008] The application further provides an electronic device, which comprises a memory for storing a computer program and a processor for executing the computer program to implement the steps of the configuration modification method of any one of the access control services.
[0009] The application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program.
[0010] The application further provides another computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the steps of the configuration modification method of the access control service.
[0011] According to the application, during the current startup process of the server, the first data structure for storing the modified target effective value is created based on the modification operation of the user on the start-stop option of the access control service before the current startup, and the first data structure is a data structure for describing and storing platform configuration data. The creation of the first data structure can make the modified target effective value pass to the initialization process of the target device, and lay the foundation for the subsequent modification of the access control service function of the target device.
[0012] Then, during the initialization process of each target device, if it is determined that the current initialized target device supports the access control service, the target effective value in the first data structure is obtained through a platform configuration data obtaining function; and based on the target effective value in the first data structure, a flag bit is written into the register corresponding to the access control service of the target device to enable or close the access control service of the target device. This can solve the problem in the related art that the ACS function of the PCIe device is further enabled or disabled through additional modification operations or the development of new codes, and the operation process is relatively cumbersome. The access control service function of the target device is modified during the initialization process of the target device, and the effect of enabling or closing the access control service function of each target device during the whole server startup process is achieved through one modification operation. The access control service function does not need to be separately opened and closed under the operating system, and the operation process is greatly simplified. BRIEF DESCRIPTION OF DRAWINGS
[0013] In order to more clearly illustrate the embodiments of the application, the drawings needed in the embodiments will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0014] Figure 1 An exemplary hardware architecture schematic diagram is provided for the embodiments of the application. Figure 2 One of the flowcharts of the configuration modification method of the access control service provided by the embodiments of the application; Figure 3A second flowchart of a method for modifying the configuration of an access control service provided in an embodiment of the present application; Figure 4 A schematic diagram of the structure of a computer program product provided in an embodiment of the present application. DETAILED DESCRIPTION
[0015] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, other embodiments obtained by ordinary technicians in this field without making any creative work are all within the scope of protection of this application.
[0016] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.
[0017] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0018] With the rise of artificial intelligence (AI), the use of AI servers has reached a peak. AI servers are high-performance computing systems optimized for AI and high-performance computing (HPC) workloads. They are widely used in scenarios requiring large-scale data processing, complex model training, and real-time inference. Specific application scenarios include machine learning (ML) and deep learning (DL) model training, real-time inference, the integration of big data analysis and AI, scientific computing, and simulation. These scenarios all require substantial computing power, which is invaluable in both the central processing unit (CPU) and the graphics processing unit (GPU).
[0019] In GPUs, especially in scenarios for AI, high-performance computing, and virtualization, the function of ACS (Access Control Services) mainly revolves around hardware resource isolation, secure access control, and virtualization support. Its specific application scenarios are as follows: 1. GPU sharing and isolation in virtualized environments, specifically including: Scenario requirements: In cloud computing or enterprise data centers, multiple virtual machines (VMs) or containers need to share the same physical GPU resources while ensuring: (1) Isolation: Prevent interference or unauthorized access between VMs; (2) Security: Block malicious users from attacking the host or other VMs through DMA (Direct Memory Access).
[0020] Role of ACS: IOMMU (Input-Output Memory Management Unit) integration: IOMMU is a hardware unit of the CPU that manages device (such as GPU, network card, etc.) access to system memory, providing address translation and access control functions. ACS (Access Control Services) works with IOMMU (such as Intel VT-d, AMD-Vi) to restrict PCIe access of the GPU to the memory range allocated to a specific VM.
[0021] ACS is a key security feature in the PCIe (Peripheral Component Interconnect Express) standard, mainly used to enhance I / O (Input / Output) virtualization security and device isolation capabilities. It is commonly used in network management to provide authentication, authorization, and accounting (AAA) services, ensuring that authorized users or devices can access network resources.
[0022] For example: In the NVIDIA vGPU or AMD MxGPU solution, ACS ensures that each vGPU can only access the memory region allocated to it.
[0023] SR-IOV (Single Root I / O Virtualization) support: In GPUs that support SR-IOV (such as NVIDIA A100 / A30, AMD Instinct MI200), ACS manages the permissions of virtual functions (VF), preventing VF from bypassing host control to directly access hardware.
[0024] 2. Prevent DMA attacks (GPU as attack vector), including: Risk background: GPUs can initiate DMA operations through PCIe bus, directly read and write system memory, and may be exploited by malicious software (such as attacking host kernels or stealing data).
[0025] ACS solution: DMA protection: After enabling ACS, DMA requests initiated by the GPU need to be translated by the IOMMU and checked for permissions, allowing access to authorized memory regions.
[0026] For example: Hopper architecture GPUs support ACS address translation services (ATS) that work with IOMMU to block illegal DMA.
[0027] Device whitelist: restrict some PCIe devices (such as GPUs) that can initiate DMA requests through ACS policies at the firmware level (e.g., UEFI, BIOS).
[0028] 3. Security isolation for multi-tenant AI training / inference Scenario requirements: In an AI server cluster, multiple tenants may share the same GPU node, and the following needs to be ensured: Model and data isolation: Tenant A cannot read tenant B's model weights or input data.
[0029] Performance isolation: avoid a tenant's GPU kernel from occupying all computing resources.
[0030] ACS implementation: GPU slicing (Time-Slicing): ACS works with GPU schedulers (such as NVIDIA MIG, AMD CDNA2) to divide GPU computing units into independent instances, each instance bound to a specific tenant.
[0031] For example: In MIG (Multi-Instance GPU) mode of NVIDIA A100, ACS ensures that the memory and computing units of each instance are completely isolated.
[0032] Memory encryption: in AMD's GPU that supports SEV (Secure Encrypted Virtualization) (such as Instinct MI300), ACS manages access permissions to encrypted memory regions.
[0033] SEV is a hardware-level virtualization security technology proposed by AMD, aiming to ensure that the data of virtual machines is not accessed by the host, other virtual machines or unauthorized users by encrypting the memory of each virtual machine. SEV effectively increases the security in the virtualization environment by providing encryption protection at the hardware level, especially in multi-tenant environments.
[0034] 4. Device access control in edge computing Scenario requirement: In edge servers (such as smart cameras, autonomous driving vehicle computers), GPUs need to process sensitive data, but may face physical tampering risks.
[0035] Functions of ACS: Firmware signature verification: ACS prevents unsigned GPU firmware or kernel drivers from being loaded (such as NVIDIA's GSP firmware verification).
[0036] Principle of least privilege: Limit the access rights of edge applications to the necessary GPU functions (such as enabling one of multiple functions, which can be enabling inference API and disabling debug interface).
[0037] Since the application of ACS functions in GPU servers is very extensive, customizing ACS functions for different scenarios is one of the developers' work. The development principle of customizing according to the previous options is that the BIOS provides scripts to use the SCE (Secure Computing Environment) tool to modify the current value of the option in the OS (Operating System) to the value required by the customer or directly modify the default value of the CBS (Common BIOS Settings) option in the code to the value required by the customer.
[0038] Related technologies modify through the following three schemes: The first scheme is the one with the least workload, which is to directly use scripts combined with SCE tools to modify the current value of the option. This way, the customer's demand development can be realized using the general version + script method, without modifying the code, avoiding unnecessary changes when compiling the code, and the customer can also quickly operate through hotkeys when they want to restore the default value. Because this scheme has small workload and is easy to implement, it is the mainstream scheme for modifying options at present.
[0039] The second scheme is to directly pull branches or add code overrides to provide customized versions for customers. This scheme can avoid the problem of inconsistency between the current value and the default value of the option modified by scripts, and is beneficial to customer operation and management.
[0040] The third option is to ship the system to the customer using a generic version, allowing them to adjust the options based on their needs upon receiving the machine. This solution is suitable for customers with larger server requirements, as these customers have their own operations and maintenance teams and BIOS development teams. During the debugging process, customers can verify the optimal configuration options based on their application scenarios and then quickly deploy them using the operations and maintenance scripts.
[0041] However, although using scripts to modify the current value of options is convenient and time-saving, this solution has the following two problems. First, the script can only modify the current value of the option and cannot modify the default value. When customers view the option value under the OS, they will see that the default value is inconsistent with the current value, which is not conducive to customer understanding. Second, customers need to separately manage the script, which is not convenient in operation and maintenance. This is also the reason why some customers do not accept script customization.
[0042] While developing customized versions to meet customer needs can solve the script customization problem, directly modifying option values in the code requires modifying multiple files, and the modification of customized options cannot affect general functions. This requires adding code overrides or pulling branches for customization, doubling the code and version maintenance work, which is very disadvantageous for developers.
[0043] For the Access Control Service (ACS) function, modifying the BIOS option value only changes the ACS function during the BIOS boot phase. Changing the Access Control Service (ACS) Enable option on the Setup interface does not affect the value of the ACS register in the PCIe configuration space under the OS. It only affects whether the ACS register is displayed. Therefore, if you want to dynamically adjust the ACS register value, you still need to develop the function.
[0044] To solve the above problems, the present application provides a configuration modification method, server and computer program product for an access control service.
[0045] In conjunction with the specific application environment architecture or specific hardware architecture on which the execution of the configuration modification method of the access control service depends, the specific application environment architecture or specific hardware architecture is described herein.
[0046] See also Figure 1 , an embodiment of the present application provides an exemplary hardware architecture diagram, in which a subsequent configuration modification method of an access control service can be executed.
[0047] The hardware architecture diagram includes a server, which includes a central processing unit (CPU), a basic input / output system (BIOS), a target device, and registers corresponding to the access control service of the target device (subsequently referred to as ACS registers).
[0048] BIOS is one of the core firmware programs in server hardware. It is a set of programs stored on a ROM chip on the computer's motherboard. It stores the computer's most important basic input and output programs, the post-boot self-test program, and the system startup program. It also reads and writes specific information about system settings. It provides the foundation for loading the operating system and serves as the interface between the server hardware and the operating system.
[0049] The server's BIOS is responsible for initializing hardware, performing system self-tests, configuring hardware resources, setting the boot sequence, and booting the operating system. It also provides security and power management features. The BIOS plays a crucial role in the server system's boot process.
[0050] The interaction process includes: ① The user modifies the start and stop options of the access control service; ②The BIOS can respond to the user's modification of the start and stop options of the access control service and trigger a server restart.
[0051] ③After the CPU is powered on on the server, it loads the BIOS image to initialize the BIOS, thereby starting the BIOS.
[0052] ④ After the BIOS is successfully started, it may execute: during the current server startup process, based on the user's modification operation on the start and stop options of the access control service before the current startup, creating a first data structure for storing the modified target effective value, the first data structure being a data structure for describing and storing platform configuration data; ⑤BIOS triggers the initialization of each target device; ⑥ During the initialization process of each target device, if the target device supports a high-speed bus for peripheral component interconnection, the BIOS, upon determining that the currently initialized target device supports access control services, obtains the target valid value in the first data structure through the platform configuration data acquisition function. Based on the target valid value in the first data structure, the BIOS writes a flag bit to the register corresponding to the target device's access control service to enable or disable the target device's access control service under the operating system. The detailed process is described in the subsequent section.
[0053] Embodiments of the present application provide a configuration modification method of an access control service. The method is described in detail in combination with an execution flow of the configuration modification method of the access control service.
[0054] The execution subject of the configuration modification method of the access control service provided by the embodiments of the present application can be a BIOS of a server.
[0055] Referring to Figure 2 The embodiments of the present application provide one of flowcharts of a configuration modification method of an access control service, which includes the following steps 210, 220 and 230. In step 210, during a current startup process of a server, a first data structure for storing a target effective value after modification is created based on a modification operation of a user on a start-stop option of the access control service before the current startup, and the first data structure is a data structure for describing and storing platform configuration data.
[0056] Both customers and R&Ds will think of modifying the option value of the start-stop option (ACS Enable) of the access control service when they want to turn on or turn off the ACS function.
[0057] ACS Enable refers to an option for enabling the ACS function in a PCIe system. After enabling ACS, the system will enforce access control and restrict direct access between different devices. This is usually used to enhance security, especially in virtualization environments or multi-tenant systems, to ensure that communication between devices complies with predetermined security and isolation policies.
[0058] Some platforms open this option for customers to choose whether to enable or disable the ACS function, and the option value has three choices: Enabled (or enabled), Disabled (or disabled), and Auto.
[0059] The modification operation of modifying the option value of the ACS Enable option includes several methods, such as directly modifying in a configuration Setup interface, directly modifying through an SCE (System Configuration Environment Tool) in an OS system, and directly modifying the option value in code.
[0060] The modification operation includes a target effective value after modification, which can be any one of Enabled, Disabled, and Auto.
[0061] After the modification is completed, the server needs to be restarted to make the function take effect.
[0062] In the next boot-up process (this boot-up), the BIOS will create a first data structure for storing the modified target valid value in the PEI (Pre-EFI Initialization) stage of the boot-up, and the first data structure is a data structure for describing and storing platform configuration data.
[0063] The PEI stage is the first stage in the UEFI (Unified Extensible Firmware Interface) boot-up process, mainly used for hardware initialization and preparation for boot loading. It occurs when the computer starts up, after the hardware power is turned on, and before the operating system is loaded. The purpose of the PEI stage is to ensure that the hardware is ready so that it can enter the next stage, the DXE (Driver Execution Environment) stage.
[0064] The DXE stage is the second stage in the UEFI boot-up process, responsible for loading and initializing drivers, and preparing for the boot of the operating system. The goal of the DXE stage is to enable the system to normally load the boot loader of the operating system, and provide the necessary hardware support and services for the operation of the operating system.
[0065] In general, the PEI stage mainly completes the basic initialization of the hardware, ensuring that the memory and basic hardware are ready, while the DXE stage continues to execute driver loading and service initialization work after the completion of the PEI stage. The two stages work together to ensure that the UEFI boot-up process is smooth, and the hardware and drivers can be correctly loaded at system startup, ultimately providing support for the boot of the operating system.
[0066] Specifically, the first data structure can be PcdCfgACSEnable, which is a PCD (Platform Configuration Data) configuration item in the UEFI environment, a configuration mechanism for managing and storing platform configuration data such as hardware parameters, firmware settings, and driver options. PCD provides a standardized way for developers to dynamically adjust configurations at compile time or runtime without modifying source code, and is usually used to store values related to platform (hardware and firmware) configuration.
[0067] PcdCfgACSEnable is one of the specific settings, usually related to the function switch of ACPI (Advanced Configuration and Power Interface) or other power management functions.
[0068] The benefits of storing data in PCDs primarily include flexibility, maintainability, security, storage efficiency, and development efficiency. This storage method makes platform or system configuration more dynamic, allowing for adjustments based on specific needs while also improving platform scalability and maintainability. PCDs are a crucial configuration management tool in embedded systems, firmware development, and multi-platform systems.
[0069] Step 220: During the initialization process of each target device, if the target device is a device that supports a high-speed bus for interconnecting peripheral components, and if it is determined that the currently initialized target device supports access control services, the target valid value in the first data structure is obtained through the platform configuration data acquisition function.
[0070] The target device refers to a device that supports the PCIe standard, referred to as a PCIe device. PCIe devices include, but are not limited to, network interface cards (NICs), graphics processing units (GPUs), solid-state drives (SSDs), USB (Universal Serial Bus) controller cards, and at least some of the following: tensor processing units (TPUs).
[0071] In the later stage of the DXE phase, during the initialization of each PCIe device (PCIe device initialization is usually triggered by the BIOS), the BIOS will first read the PCIe configuration space of the PCIe device to confirm whether the PCIe device on the current machine supports the ACS function. Because some manufacturers' PCIe devices do not support the ACS function, forcing the ACS function on the card will inevitably cause the card to malfunction, thereby affecting the operation of the entire machine.
[0072] When the BIOS determines that the currently initialized target device supports the access control service, the BIOS will then obtain the value of PcdCfgACSEnable through the PCD acquisition function. The value of PcdCfgACSEnable is the aforementioned target valid value.
[0073] Step 230: Based on the target effective value in the first data structure, write a flag bit into the register corresponding to the corresponding access control service of the target device to enable or disable the access control service of the target device.
[0074] After the BIOS obtains the target effective value in the first data structure (i.e., the target effective value stored in PcdCfgACSEnable), the BIOS writes a flag bit for an ACS register according to the target effective value, and the flag bit is specifically an ACS_CNT flag bit, which is used to control the start of the access control service of the PCIe device. When the target effective value in the first data structure represents enabling, the value of the ACS_CNT flag bit can be a first value, which can be 1, so as to enable the access control service of the target device. When the target effective value in the first data structure represents disabling, the value of the ACS_CNT flag bit can be a second value, which can be 0, so as to disable the access control service of the target device.
[0075] The method for modifying the configuration of the access control service provided in the embodiments of the present application can create the first data structure for storing the modified target effective value based on the modification operation of the user on the start-stop option of the access control service before the current start of the server during the current start of the server. The first data structure is a data structure for describing and storing platform configuration data. The creation of the first data structure can make the modified target effective value be passed to the initialization process of the target device, and lay the foundation for the modification of the access control service function of the target device in the future.
[0076] Then, in the initialization process of each target device, the target effective value in the first data structure is obtained through a platform configuration data obtaining function when it is determined that the currently initialized target device supports the access control service. Based on the target effective value in the first data structure, a flag bit of a register corresponding to the access control service of the target device is written, so as to enable or disable the access control service of the target device. This can solve the problem that in the related art, the ACS function of the PCIe device is further enabled or disabled through an additional modification operation or the development of new code, and the operation process is relatively cumbersome. The access control service function of the target device is modified in the initialization stage of the target device, and the effect of enabling or disabling the access control service function of each target device in the whole start process of the server is achieved through one modification operation. The access control service function no longer needs to be separately opened and closed under the operating system, and the operation process is greatly simplified.
[0077] In some embodiments, the flag bit of the register corresponding to the access control service of the target device is written based on the target effective value in the first data structure, and the writing includes: When the target effective value in the first data structure represents enabling, a first value is written to the flag bit of the register, so as to enable the access control service of the target device. In the case that the target valid value in the first data structure represents disabling, a second value is written to a flag bit of the register to turn off the access control service of the target device.
[0078] The foregoing embodiment has illustrated that, after the BIOS confirms that the current PCIe device supports the ACS function, the BIOS will then obtain the target valid value in PcdCfgACSEnable through a Pcd getting function. If the target valid value in PcdCfgACSEnable obtained is enabling, the BIOS will directly modify the ACS_CNT flag bit in the ACS register to 1 by means of a PCIe configuration space modifying function to enable the access control service ACS function under the OS.
[0079] If the target valid value in the first data structure PcdCfgACSEnable obtained is disabling, the BIOS will directly modify the ACS_CNT flag bit in the ACS register to 0 to disable the ACS function under the OS.
[0080] The embodiment of the present application performs flag bit writing on the register of the access control function of the target device based on the target valid value in the first data structure, which can associate the opening and closing of the ACS function with the modification of the start-stop option ACS Enable, and thus enables the access control service function of each target device to be started and stopped during the whole server starting process through one modification operation, and the access control service function under the operating system no longer needs to be separately opened and closed, which greatly simplifies the operation process.
[0081] In some embodiments, after the first data structure for storing the modified target valid value is created, the method further includes: The target valid value in the first data structure is updated to the default value of the start-stop option of the access control service in the core starting service variable by means of an option reading and writing function to replace the original default value.
[0082] The CBS (Common BIOS Settings) variable is a set of parameter options for configuring the CPU, chip set and system bottom function. These options are usually directed to advanced users, developers or OEM manufacturers, and allow more detailed tuning of the hardware behavior.
[0083] In the BIOS settings, the CBS variable is usually related to some variables or parameters of the hardware configuration and system performance. These variables will be different according to the hardware of the computer and the version of the BIOS, and can affect the behavior of the hardware during the system starting process.
[0084] After the BIOS creates the PcdCfgACSEnable for storing the target valid value, the BIOS will call the AMD option read-write function to update the target valid value in the PcdCfgACSEnable into the default value of the ACS Enable option in the core boot service variable (CBS Variable), thereby replacing the logic of originally forcing the initial value of the ACSEnable in the AMD code, ensuring that the latest value of the access control service ACS Enable will be updated into the default value every time the machine is started, obtaining a new default value, thereby solving the problem that the current value of the option modified by the Setup interface or the SCE tool is different from the default value, and from an intuitive point of view, the customer can feel the rigor of the BIOS code, and the doubt of the customer about the different values of the options is avoided.
[0085] In some embodiments, after the target valid value in the first data structure is updated into the default value of the start-stop option of the access control service in the core boot service variable through the option read-write function, the method further comprises: obtaining the new default value of the start-stop option of the access control service, and displaying the new default value on the configuration interface.
[0086] After the target valid value is updated into the default value of the start-stop option of the access control service in the core boot service variable, the new default value can be obtained, and then the BIOS obtains the new default value of the ACS Enable and displays it on the Setup interface. Next, the current value and the default value of each BIOS option exported by the SCE tool under the OS can be consistent, from an intuitive point of view, the customer can feel the rigor of the BIOS code, and the doubt of the customer about the different values of the options is avoided.
[0087] In some embodiments, based on the modification operation of the user on the start-stop option of the access control service before this start, a first data structure for storing the modified target valid value is created, comprising: In the case that the modification operation is a first modification operation or a second modification operation, the core boot service variable is initialized in the pre-extensible firmware interface initialization stage to store the target valid value through the core boot service variable; reading the target valid value in the core boot service variable, and creating a target handover block through a handover block creation function to store the target valid value in the target handover block; In the driver execution environment stage, the target valid value in the target handover block is read, and a first data structure for storing the modified target valid value is created; the first modification operation is an operation of modifying the start-stop option on the configuration interface of the server; and the second modification operation is an operation of modifying the start-stop option through the system configuration and the engineering tool.
[0088] The modification operation of the embodiment of the present application can be the first modification operation or the second modification operation, in which case, the BIOS will initialize the core boot service variable CBS Variable in the PEI stage of the booting through gEfiPeiReadOnlyVariable2PpiGuid in AMD AGESA (Generic Encapsulated Software Architecture) code, so as to store the target effective value in the CBS Variable.
[0089] Then, the BIOS reads the target effective value stored in the CBS Variable, and creates a target hand-off block (target HOB) through a hand-off block (HOB) creation function, so as to store the target effective value in the target HOB.
[0090] In the booting process of UEFI (Unified Extensible Firmware Interface), the HOB is a key data structure for passing system information between the PEI stage and the DXE stage.
[0091] In the DXE stage, the BIOS will create the PCD PcdCfgACSEnable based on the target effective value in the target HOB created in the PEI stage, and will read the target effective value of ACS Enable in the target HOB and assign it to PcdCfgACSEnable, so that the modified target effective value of the ACS function can be saved and passed in the whole booting process, which lays a foundation for the modification of the access control service function of the target device in the future.
[0092] In some embodiments, after reading the target effective value in the target HOB and creating the first data structure for storing the modified target effective value, the method further comprises: Disabling the target HOB.
[0093] Since the embodiment of the present application supports the PEI and DXE stages due to the passing of the HOB, the BIOS will disable (or discard) the target HOB after storing the effective value of ACS Enable in PcdCfgACSEnable, thereby saving the consumption of computing resources.
[0094] In some embodiments, based on the modification operation of the user on the start-stop option of the access control service before this booting, the creation of the first data structure for storing the modified target effective value further comprises: In a case that the modification operation is the third modification operation, the third modification operation is an operation of modifying the start-stop option of the access control service in a service definition language code file of the access control service, and the first data structure is created based on a modified target effective value in the service definition language code file.
[0095] In addition to supporting the scheme of modifying the option value of the ACS Enable option under the OS through the SCE tool and the scheme of directly modifying the option value of the ACS Enable option in the Setup interface, the embodiments of the present application can also support a third modification operation, which is an operation of modifying the start-stop option of the access control service in a service definition language (SDL) code file of the access control service, and specifically can be a Chipset Resource Block (CRB) code.
[0096] The CRB is a data structure that manages chipset resources during the boot process, especially in the UEFI firmware phase. It is commonly used to store data related to hardware initialization and configuration, including memory mapping, I / O resource allocation, hardware device identification, etc. These resources are crucial for the boot process of the system, as they provide critical information about hardware configuration and allocation, helping the system transition smoothly to the next phase.
[0097] For the scheme of directly modifying the option value in the code, the related technology is to need AMD's Vfr and.c file, and multiple overrides are needed to distinguish from general code. The scheme of the embodiments of the present application modifies the value of PcdCfgACSEnable in the sdl file to pass the value of ACS Enable in the entire BIOS boot process, and only one PCD value needs to be modified in the sdl file, thereby greatly reducing the multiple overrides in the code, greatly reducing the workload of the R&D personnel, and avoiding the maintenance workload of the script for the customer, thereby achieving a win-win effect.
[0098] In some embodiments, before the server starts this time, the method further comprises any one of the following: After detecting the first modification operation, in a case that a save operation and an exit operation of the configuration interface by the user are detected, triggering the server to restart; After detecting the second modification operation, in a case that a restart operation of the server triggered by the user is detected, triggering the server to restart; After detecting the third modification operation, in a case that a start operation of the server triggered by the user is detected, triggering the server to start.
[0099] The foregoing embodiments have illustrated that the option of ACS Enable can be modified by any one of the foregoing first modification operation, second modification operation and third modification operation, and the user needs to perform the Save and Exit options after triggering the first modification operation to restart the setup to make the function effective; the user needs to trigger the server restart under the OS after triggering the second modification operation, so as to make the function effective; and the user needs to trigger the server startup after triggering the third operation, so as to make the function effective.
[0100] The embodiments of the present application support the above various modification operations, provide a flexible one-time modification mode for the user, and increase the flexibility of the modification operation.
[0101] In some embodiments, during the initialization process of each target device, the method further comprises: In a case where it is determined that the currently initialized target device does not support the access control service, skipping the configuration modification of the access control service of the target device.
[0102] The embodiments of the present application skip the configuration modification of the access control service of the target device in a case where it is determined that the currently initialized target device does not support the access control service, avoid affecting the operation of the whole machine, and save resources.
[0103] In some embodiments, determining that the currently initialized target device supports the access control service comprises: In a case where it is determined that the target device has the target bit identifier in the peripheral component interconnect express bus configuration space, determining that the target device supports the access control service; Determining that the currently initialized target device does not support the access control service comprises: In a case where it is determined that the target device does not have the target bit identifier in the peripheral component interconnect express bus configuration space, determining that the target device does not support the access control service.
[0104] The embodiments of the present application determine whether the target device supports the access control service through whether the target device has the target bit identifier in the PCIe configuration space. The bit identifier is a way of representing a certain state or characteristic by setting a specific binary bit. The target bit identifier can be a preset bit identifier, which is used to record whether the target device supports the ACS function. In a case where the target device has the target bit identifier of the ACS in the PCIe configuration space, the BIOS determines that the target device supports the access control service. In a case where the target device does not have the target bit identifier of the access control service in the peripheral component interconnect express bus configuration space, the BIOS determines that the target device does not support the access control service.
[0105] Referring to Figure 3The embodiment of the application provides a flowchart of a configuration modification method of an access control service, which comprises the following steps: Step 301, starting; performing step 302, step 303 or step 304; Step 302, modifying the start-stop option of the access control service through a first modification operation; the first modification operation is an operation of modifying the start-stop option on a configuration interface of a server; performing step 305; Step 303, modifying the start-stop option of the access control service through a second modification operation; the second modification operation is an operation of modifying the start-stop option through a system configuration and an engineering tool; performing step 306; Step 304, modifying the start-stop option of the access control service through a third modification operation; the third modification operation is an operation of modifying the start-stop option of the access control service in a service definition language code file of the access control service; performing step 307; Step 305, in the case that a saving operation and an exiting operation of the configuration interface of a user are detected, triggering server restart; performing step 308; Step 306, in the case that a server restart operation triggered by a user is detected, triggering server restart; performing step 308; Step 307, in the case that a server starting operation triggered by a user is detected, triggering server start; performing step 319; Step 308, in a pre-extensible firmware interface initialization stage, initializing a core start service variable to store a target effective value in the core start service variable; performing step 309; Step 309, reading the target effective value in the core start service variable, and creating a target handover block through a handover block creation function, and storing the target effective value in the target handover block; performing step 310; Step 310, in a driver execution environment stage, reading the target effective value in the target handover block, and creating a first data structure for storing the modified target effective value; the first data structure is a data structure for describing and storing platform configuration data; performing step 311; Step 311, updating the target effective value in the first data structure to the default value of the start-stop option of the access control service in the core start service variable through an option reading and writing function, to replace the original default value; performing step 312; Step 312, disabling the target handover block; performing step 313; Step 313, judging whether the target device currently initialized supports the access control service; if yes, performing step 314; if not, performing step 318; Step 314, obtaining the target effective value in the first data structure through a platform configuration data obtaining function; performing step 315; Step 315, judging whether the target effective value in the first data structure represents enabling; if yes, executing step 316; if no, executing step 317; Step 316, writing the first value to the flag bit of the register to enable the access control service of the target device; executing step 321; Step 317, writing the second value to the flag bit of the register to disable the access control service of the target device; executing step 321; Step 318, skipping the configuration modification of the access control service of the target device; Step 319, creating the first data structure based on the modified target effective value in the service definition language code file; executing step 320; Step 320, updating the default value of the start-stop option of the access control service in the core start service variable by the target effective value in the first data structure through the option read-write function to replace the original default value; executing step 313; Step 321, ending.
[0106] Through the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment.
[0107] The embodiment of the application provides a server, which comprises a central processing unit, a basic input output system and a target device; the target device is a device supporting a peripheral component interconnect express bus; The basic input output system triggers server restart based on a modification operation of a user on a start-stop option of an access control service; The central processing unit is configured to start the basic input output system after the server is powered on; The basic input output system is configured to create a first data structure for storing a modified target effective value based on a modification operation of a user on a start-stop option of an access control service before the current start in a current start process of the server, and the first data structure is a data structure for describing and storing platform configuration data; The basic input output system is configured to acquire the target effective value in the first data structure through a platform configuration data acquisition function in the initialization process of each target device under the condition that the current initialized target device supports the access control service; The basic input output system is further configured to perform flag bit writing on a register corresponding to the access control service of the target device based on the target effective value in the first data structure, so as to enable or disable the access control service of the target device.
[0108] In some embodiments, the basic input output system is further configured to: In a case that the target valid value in the first data structure represents enablement, write a first value to a flag bit of the register to enable the access control service of the target device; In a case that the target valid value in the first data structure represents disablement, write a second value to the flag bit of the register to disable the access control service of the target device.
[0109] In some embodiments, the basic input output system is further configured to, after creating the first data structure for storing the modified target valid value, update, by the option read-write function, a default value of the start-stop option of the access control service in the core start service variable with the target valid value in the first data structure to replace an original default value.
[0110] In some embodiments, the basic input output system is further configured to, after updating, by the option read-write function, the default value of the start-stop option of the access control service in the core start service variable with the target valid value in the first data structure, obtain the new default value of the start-stop option of the access control service, and display the new default value in the configuration interface.
[0111] In some embodiments, the basic input output system is further configured to: In a case that the modification operation is a first modification operation or a second modification operation, initialize the core start service variable to store the target valid value in the core start service variable in a pre-extensible firmware interface initialization stage; read the target valid value in the core start service variable, and create a target handoff block to store the target valid value in the target handoff block by a handoff block creation function; read the target valid value in the target handoff block, and create a first data structure for storing the modified target valid value in a driver execution environment stage; the first modification operation is an operation of modifying the start-stop option in the configuration interface of the server; the second modification operation is an operation of modifying the start-stop option by a system configuration and an engineering tool.
[0112] In some embodiments, the basic input output system is further configured to, after reading the target valid value in the target handoff block and creating the first data structure for storing the modified target valid value, disable the target handoff block.
[0113] In some embodiments, the basic input output system is further configured to: In a case that the modification operation is a third modification operation, the third modification operation is an operation of modifying the start-stop option of the access control service in a service definition language code file of the access control service, and create the first data structure based on the modified target valid value in the service definition language code file.
[0114] In some embodiments, the basic input and output system is further configured to: after detecting the first modification operation, in a case where a save operation and a quit operation of the configuration interface performed by the user are detected, triggering a server restart; after detecting the second modification operation, in a case where a server-triggered restart operation performed by the user is detected, triggering a server restart; after detecting the third modification operation, in a case where a server-triggered startup operation performed by the user is detected, triggering a server startup.
[0115] In some embodiments, the basic input and output system is further configured to: during initialization of each target device, in a case where it is determined that the target device currently being initialized does not support the access control service, skipping configuration modification of the access control service of the target device.
[0116] In some embodiments, the basic input and output system is further configured to: in a case where it is determined that the target device has a target bit identifier of the access control service in a peripheral component interconnect express bus configuration space of the target device, determining that the target device supports the access control service; in a case where it is determined that the target device does not have a target bit identifier of the access control service in the peripheral component interconnect express bus configuration space of the target device, determining that the target device does not support the access control service.
[0117] Embodiments of the present application also provide a computer program product applied to a basic input and output system of a server.
[0118] Referring to Figure 4 , the embodiments of the present application provide a structural schematic diagram of a computer program product, which comprises: The creating module 410 is configured to, during a current startup process of the server, based on a modification operation of an enable / disable option of the access control service performed by the user before the current startup, create a first data structure for storing a target effective value after modification, the first data structure being a data structure for describing and storing platform configuration data; The processing module 420 is configured to, during initialization of each target device, in a case where the target device is a peripheral component interconnect express bus supported device, and in a case where it is determined that the target device currently being initialized supports the access control service, acquiring the target effective value in the first data structure through a platform configuration data acquisition function; The configuration module 430 is configured to, based on the target effective value in the first data structure, performing flag bit writing on a register corresponding to the access control service of the target device, so as to enable or close the access control service of the target device.
[0119] In some embodiments, the configuration module 430 is specifically configured to: In case the target valid value in the first data structure represents enablement, writing a first value to a flag bit of the register to enable the access control service of the target device; In case the target valid value in the first data structure represents disablement, writing a second value to the flag bit of the register to disable the access control service of the target device.
[0120] In some embodiments, the computer program product further comprises: The updating module is configured to, after the creating module 410 creates the first data structure for storing the modified target valid value, update the target valid value in the first data structure into a default value of the start-stop option of the access control service in the core start service variable by the option read-write function to replace the original default value.
[0121] In some embodiments, the computer program product further comprises: The displaying module is configured to, after the updating module updates the target valid value in the first data structure into the new default value of the start-stop option of the access control service in the core start service variable by the option read-write function, acquire the new default value of the start-stop option of the access control service and display the new default value on the configuration interface.
[0122] In some embodiments, the creating module 410 is configured to: In case the modification operation is the first modification operation or the second modification operation, initialize the core start service variable in the pre-extensible firmware interface initialization stage to store the target valid value in the core start service variable; read the target valid value in the core start service variable and create a target handoff block by the handoff block creating function to store the target valid value in the target handoff block; read the target valid value in the target handoff block in the driver execution environment stage, and create the first data structure for storing the modified target valid value; the first modification operation is an operation of modifying the start-stop option on the configuration interface of the server; the second modification operation is an operation of modifying the start-stop option by the system configuration and the engineering tool.
[0123] In some embodiments, the computer program product further comprises: The disabling module is configured to, after the creating module 410 reads the target valid value in the target handoff block and creates the first data structure for storing the modified target valid value, disable the target handoff block.
[0124] In some embodiments, the creating module 410 is further configured to: In a case where the modification operation is the third modification operation, the third modification operation is an operation of modifying a start-stop option of the access control service in a service definition language code file of the access control service, and the first data structure is created based on a modified target effective value in the service definition language code file.
[0125] In some embodiments, the processing module 420 is further configured to, in the initialization process of each target device, in a case where it is determined that the target device currently being initialized does not support the access control service, skip the configuration modification of the access control service of the target device.
[0126] In some embodiments, the processing module 420 is further configured to, in a case where it is determined that the target bit identification of the access control service is present in the peripheral component interconnect express bus configuration space of the target device, determine that the target device supports the access control service; and in a case where it is determined that the target bit identification of the access control service is not present in the peripheral component interconnect express bus configuration space of the target device, determine that the target device does not support the access control service.
[0127] The descriptions of the features in the embodiments of the computer program product can refer to the descriptions of the embodiments of the method for configuration modification of the access control service, which will not be repeated here.
[0128] Embodiments of the present application also provide a server, comprising a basic input output system, and the aforementioned computer program product.
[0129] Embodiments of the present application also provide an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the computer program to perform the steps in any of the embodiments of the method for configuration modification of the access control service.
[0130] Embodiments of the present application also provide a computer readable storage medium, which stores a computer program, wherein the computer program is configured to perform the steps in any of the embodiments of the method for configuration modification of the access control service when executed.
[0131] In an example embodiment, the aforementioned computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0132] The embodiment of the present application further provides another computer program product, which comprises a computer program, and the computer program realizes the steps in any of the access control service configuration modification method embodiments when executed by a processor.
[0133] The embodiment of the present application further provides another computer program product, which comprises a computer program, and the computer program realizes the steps in any of the access control service configuration modification method embodiments when executed by a processor.
[0134] Those skilled in the art can further understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in the above description in a general manner. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0135] The above describes in detail the access control service configuration modification method, server and computer program product provided by the present application. The principles and implementation modes of the present application are described herein by applying specific examples, and the above description of the embodiments is only applicable to help understand the method of the present application and its core idea. It should be pointed out that, for those skilled in the art, without departing from the principles of the present application, some improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A method of configuration modification of an access control service, characterized in that, A basic input / output system applied to a server, comprising: During a current startup process of the server, based on a modification operation of a user on a start-stop option of the access control service before the current startup, a first data structure for storing a modified target effective value is created, the first data structure being a data structure for describing and storing platform configuration data; During an initialization process of each target device, the target device being a device supporting a peripheral component interconnect express bus, if it is determined that the target device currently being initialized supports the access control service, a target effective value in the first data structure is acquired through a platform configuration data acquisition function; Based on the target effective value in the first data structure, a flag bit of a register corresponding to the access control service of the target device is written to, so as to enable or disable the access control service of the target device.
2. The method of claim 1, wherein, The writing of the flag bit of the register based on the target effective value in the first data structure comprises: If the target effective value in the first data structure represents enabling, a first value is written to the flag bit of the register to enable the access control service of the target device; If the target effective value in the first data structure represents disabling, a second value is written to the flag bit of the register to disable the access control service of the target device.
3. The method of claim 1, wherein, After the first data structure for storing the modified target effective value is created, the method further comprises: The target effective value in the first data structure is updated to a default value of the start-stop option of the access control service in a core startup service variable through an option read-write function to replace an original default value.
4. The method of claim 3, wherein, After the target effective value in the first data structure is updated to the default value of the start-stop option of the access control service in the core startup service variable through the option read-write function, the method further comprises: A new default value of the start-stop option of the access control service is acquired, and the new default value is displayed on a configuration interface.
5. The method of claim 1, wherein, The creation of the first data structure for storing the modified target effective value based on the modification operation of the user on the start-stop option of the access control service before the current startup comprises: If the modification operation is a first modification operation or a second modification operation, a core startup service variable is initialized in a pre-extensible firmware interface initialization stage to store the target effective value in the core startup service variable; The target effective value in the core startup service variable is read, and a target handover block is created through a handover block creation function to store the target effective value in the target handover block; In a driver execution environment stage, the target effective value in the target handover block is read, and the first data structure for storing the modified target effective value is created; the first modification operation is an operation of modifying the start-stop option on a configuration interface of the server; and the second modification operation is an operation of modifying the start-stop option through a system configuration and an engineering tool.
6. The method of claim 5, wherein, After the reading of the target valid value in the target handoff block and the creating of the first data structure for storing the modified target valid value, the method further comprises: Disabling the target handoff block.
7. The method of claim 5, wherein the access control service is configured to, The creating of the first data structure for storing the modified target valid value based on the modification operation of the user on the start-stop option of the access control service before the current start of the server further comprises: In the case that the modification operation is a third modification operation, the third modification operation is an operation of modifying the start-stop option of the access control service in a service definition language code file of the access control service, and the first data structure is created based on the modified target valid value in the service definition language code file.
8. The method of claim 7, wherein, Before the current start process of the server, the method further comprises any one of the following: After detecting the first modification operation, in the case of detecting the save operation and the exit operation of the user on the configuration interface, triggering the server to restart; After detecting the second modification operation, in the case of detecting the server restart operation triggered by the user, triggering the server to restart; After detecting the third modification operation, in the case of detecting the server start operation triggered by the user, triggering the server to start.
9. The method of configuration modification of an access control service according to any of claims 1 to 8, characterized in that, In the initialization process of each target device, the method further comprises: In the case of determining that the currently initialized target device does not support the access control service, skipping the configuration and modification of the access control service of the target device.
10. The method of claim 9, wherein, The determination that the currently initialized target device supports the access control service comprises: In the case of determining that the target device has the target bit identifier of the access control service in the peripheral component interconnect express bus configuration space, determining that the target device supports the access control service. The determination that the currently initialized target device does not support the access control service comprises: In the case of determining that the target device does not have the target bit identifier of the access control service in the peripheral component interconnect express bus configuration space, determining that the target device does not support the access control service.
11. A server, characterized by The server comprises a central processing unit, a basic input output system and a target device; the target device is a device supporting the peripheral component interconnect express bus; The basic input output system triggers the server to restart based on the modification operation of the user on the start-stop option of the access control service; The central processing unit is configured to start the basic input output system after the server is powered on; The basic input output system is configured to, in the current start process of the server, create a first data structure for storing a modified target valid value based on a modification operation of a user on a start-stop option of an access control service before a current start of the server, the first data structure being a data structure for describing and storing platform configuration data; The basic input output system is configured to, in an initialization process of each target device, acquire a target valid value in the first data structure through a platform configuration data acquisition function in the case of determining that a currently initialized target device supports the access control service; The basic input and output system is further configured to write a flag bit of a register corresponding to the target device and corresponding access control service based on a target effective value in the first data structure, to enable or disable the access control service of the target device.
12. The server of claim 11, wherein, The basic input and output system is configured to: write a first value to the flag bit of the register to enable the access control service of the target device when the target effective value in the first data structure represents enablement; write a second value to the flag bit of the register to disable the access control service of the target device when the target effective value in the first data structure represents disablement.
13. The server of claim 11, wherein, The basic input and output system is further configured to update a default value of an enable / disable option of the access control service in a core startup service variable with a target effective value in the first data structure after the first data structure for storing the modified target effective value is created, to replace an original default value, by using an option read / write function.
14. The server of claim 13, wherein, The basic input and output system is further configured to obtain a new default value of the enable / disable option of the access control service after the default value of the enable / disable option of the access control service in the core startup service variable is updated with the target effective value in the first data structure by using the option read / write function, and display the new default value in a configuration interface.
15. The server of claim 11, wherein, The basic input and output system is configured to: initialize a core startup service variable to store the target effective value in the core startup service variable in a pre-extensible firmware interface initialization stage when the modification operation is a first modification operation or a second modification operation; read the target effective value in the core startup service variable, and create a target handover block by using a handover block creation function to store the target effective value in the target handover block; read the target effective value in the target handover block, and create a first data structure for storing a modified target effective value in a driver execution environment stage; the first modification operation is an operation of modifying the enable / disable option in a configuration interface of the server; and the second modification operation is an operation of modifying the enable / disable option by using a system configuration and engineering tool.
16. The server of claim 11, wherein, The basic input and output system is further configured to: create the first data structure based on a modified target effective value in a service definition language code file of the access control service when the modification operation is a third modification operation, the third modification operation being an operation of modifying the enable / disable option of the access control service in the service definition language code file of the access control service.
17. A computer program product, characterised in that, A basic input and output system applied to a server, comprising: a creation module configured to create a first data structure for storing a modified target effective value based on a modification operation of an enable / disable option of an access control service by a user before a current startup of the server during the current startup of the server, the first data structure being a data structure for describing and storing platform configuration data; The processing module is configured to, during an initialization process of each target device, which is a device supporting a peripheral component interconnect express bus, acquire a target valid value in the first data structure through a platform configuration data obtaining function in a case where it is determined that the target device currently being initialized supports an access control service; The configuration module is configured to perform flag bit writing on a register corresponding to the access control service of the target device based on the target valid value in the first data structure, so as to enable or close the access control service of the target device.
18. A server, characterized by The server includes a basic input / output system, and the basic input / output system includes the computer program product of claim 17.
19. An electronic device, comprising: Comprise: A memory for storing a computer program; A processor for implementing the steps of the access control service configuration modification method of any one of claims 1 to 10 when executing the computer program.
20. A computer-readable storage medium, characterized in that, The computer program is stored in the computer readable storage medium, and when the computer program is executed by the processor, the steps of the access control service configuration modification method of any one of claims 1 to 10 are implemented.
Citation Information
Patent Citations
ACS function control method and device, storage medium and computer equipment
CN111709042A
Upgrading method and device of basic input and output system and storage medium
CN118349262A
Method and device for reporting setting option information, computer equipment and storage medium
CN119938155A
License management in pre-boot environments
US20170235928A1