Handling node policies in a firmware framework
Systems and methods for handling node policies in a firmware framework. In some embodiments, an Information Handling System (IHS) may include a controller, where the controller comprises firmware that, upon execution by a processing core, causes the processing core to instantiate an orchestrator; and a plurality of devices coupled to the controller, where each device comprises firmware that, upon execution by a corresponding processing core, causes the corresponding processing core to instantiate a node as part of a firmware framework, and where the orchestrator is configured to distribute a policy to at least a given node without any involvement by any Operating System (OS) of the IHS.
1 . An Information Handling System (IHS), comprising:
a controller, wherein the controller comprises firmware that, upon execution by a processor core, causes the processor core to instantiate an orchestrator; and
a plurality of devices coupled to the controller at least in part by a hardware interconnect coupled to at least one IHS host processor, wherein each device comprises firmware configured to, upon execution by a respective processor core, cause the respective processor core to instantiate a node as part of a firmware framework, wherein the orchestrator is configured to perform operations that comprise:
distribute a policy to at least a given node without any involvement by any Operating System (OS) of the IHS;
instantiate a telemetry service configured to perform operations that comprise:
maintain a list of telemetry capabilities accessible through available interfaces; and
in response to receipt of a telemetry collection request, route the telemetry collection request to appropriate collector node(s), set one or more parent node(s) of the collector node(s) as aggregator node(s) or bypass node(s), and select communication paths or protocols which depend at least in part upon a telemetry policy stored in a policies module of the firmware framework, wherein policy rules that govern telemetry collection, path and protocol selection, and node classification, are based upon contextual information; and
instantiate a security service configured to perform operations that comprise:
in response to connection of a new node to the firmware framework, query the new node for firmware image details;
verify the firmware image, based at least in part on the firmware image details; and
in response to a determination that verification of the firmware image was successful, enable discovery and participation in the firmware framework for the new node.
2 . The IHS of claim 1 , wherein the controller comprises an Embedded Controller (EC) or Baseband Management Controller (BMC).
3 . The IHS of claim 1 , wherein the plurality of devices comprises at least one of: a sensor, a sensor hub, a Central Processing Unit (CPU), a Graphical Processing Unit (GPU), an audio Digital Signal Processor (aDSP), a Neural Processing Unit (NPU), a Tensor Processing Unit (TSU), a Neural Network Processor (NNP), an Intelligence Processing Unit (IPU), an Image Signal Processor (ISP), a Video Processing Unit (VPU), a camera controller, an audio controller, a memory, a Universal Serial Bus (USB) device, a Peripheral Component Interconnect express (PCIe) device, or a Trusted Platform Module (TPM).
4 . The IHS of claim 1 , wherein at least one of the plurality of devices is coupled to the controller via at least one of: a Systems-on-Chip (SoC) interconnect, a Peripheral Component Interconnect Express (PCIe) bus, or a Universal Serial Bus (USB) port.
5 . The IHS of claim 4 , wherein the SoC interconnect comprises at least one of: an Advanced Microcontroller Bus Architecture (AMBA) bus, a QuickPath Interconnect (QPI) bus, or a HyperTransport (HT) bus.
6 . The IHS of claim 1 , wherein the policy comprises identification of, for the given node, one or more of: an enumeration setting, a threshold value, a security posture, or a runtime filter setting.
7 . The IHS of claim 1 , wherein the policy is configured to trigger, in the given node, an operation to be performed in cooperation with another node of the firmware framework without involvement by any OS of the IHS.
8 . The IHS of claim 7 , wherein the given node corresponds to a sensor hub or Human Presence Detection (HPD) sensor, and wherein the other node corresponds to a display controller.
9 . The IHS of claim 8 , wherein the policy configures the sensor hub or HPD to send a message to the display controller to disable video output to enforce a privacy, confidentiality, or security rule.
10 . The IHS of claim 9 , wherein the orchestrator is configured to enable the video output in response to a user command to override the policy.
11 . The IHS of claim 7 , wherein the given node corresponds to at least one of: a sensor hub, a network controller, or a Global Positioning System (GPS) device, and wherein the other node corresponds to at least one of: a Universal Serial Bus (USB) controller, a display controller, or a Human Presence Detection (HPD) sensor.
12 . The IHS of claim 11 , wherein the policy configures the sensor hub, network controller, or GPS device to send a message to the USB controller to disable or enable a USB port.
13 . The IHS of claim 11 , wherein the policy configures the sensor hub, network controller, or GPS device to send a message to the display controller to adjust a brightness setting.
14 . The IHS of claim 11 , wherein the policy configures the sensor hub, network controller, or GPS device to send a message to the HPD sensor to adjust a detection threshold.
15 . The IHS of claim 1 , wherein the orchestrator is configured to select the given node in response to a determination that a temperature of the given node is above a threshold value, and wherein the policy indicates a capability or performance setting to be applied to a processor core respective to the given node.
16 . The IHS of claim 15 , wherein the capability or performance setting comprises at least one of: core park, power limit, or core offline.
17 . A method, comprising:
producing, via a controller, an orchestrator of a firmware framework configured for an Information Handling System (IHS); and
producing, via a plurality of devices coupled to the controller at least in part, by a hardware interconnect coupled to at least one IHS host processor, a plurality of nodes in the firmware framework, wherein the orchestrator is configured to perform operations that comprise:
distributing a policy to at least a given node, and advertising a capability of at least the given node, without any involvement by any Operating System (OS) of the IHS;
instantiating a telemetry service configured to perform operations that comprise:
maintaining a list of telemetry capabilities accessible through available interfaces; and
in response to receiving a telemetry collection request, routing the telemetry collection request to appropriate collector node(s), setting one or more parent node(s) of the collector node(s) as aggregator node(s) or bypass node(s), and selecting communication paths or protocols which depend at least in part upon a telemetry policy stored in a policies module of the firmware framework, wherein policy rules that govern telemetry collection, path and protocol selection, and node classification are based upon contextual information; and
instantiating a security service configured to perform operations that comprise:
in response to connection of a new node to the firmware framework, querying the new node for firmware image details;
verifying the firmware image, based at least in part on the firmware image details; and
in response to determining that verification of the firmware image was successful, enabling discovery and participation in the firmware framework for the new node.
18 . The method of claim 17 , wherein the orchestrator is configured to select the given node in response to a determination that a temperature of the given node is above a threshold value, and wherein the policy indicates at least one of: a core parking setting, a power limiting setting, or core offlining setting to be applied to a processing core corresponding to the given node.
19 . An Embedded Controller (EC) integrated into or coupled to a heterogeneous computing platform of an Information Handling System (IHS), the EC comprising:
a processor core distinct from any host processor of the heterogeneous computing platform; and
a memory coupled to the processor core, the memory configured with firmware instructions stored thereon that, upon execution by the processor core, cause the EC to perform operations that comprise:
produce an orchestrator as part of a firmware framework; and
distribute a policy to at least a given node and another node of a plurality of nodes of the firmware framework implemented by a respective plurality of devices, wherein the respective plurality of devices are coupled to the EC, at least in part, by a hardware interconnect coupled to at least one host processor of the heterogeneous computing platform, and wherein the orchestrator is configured to:
instantiate a telemetry service configured to perform operations that comprise:
maintain a list of telemetry capabilities accessible through available interfaces;
in response to receipt of a telemetry collection request, route the telemetry collection request to appropriate collector node(s), set one or more parent node(s) of the collector node(s) as aggregator node(s) or bypass node(s), r and select communication paths or protocols which depend at least in part upon a telemetry policy stored in a policies module of the firmware framework, wherein policy rules that govern telemetry collection, path and protocol selection, and node classification are based upon contextual information;
capture telemetry data that comprises Thermal, Power, Performance, or Acoustic (TPPA) data which includes at least one of temperature, power state, performance state, operation frequency, fan speed, availability, or sound pressure level from at least a selected node of the plurality of nodes;
store at least a subset of the captured telemetry data in a storage medium that is persistent across reboots, via a data module of the firmware framework; and
provide access to the persistently stored subset of the captured telemetry data, without any involvement by any Operating System (OS) of the IHS;
instantiate a security service configured to perform operations that comprise:
in response to connection of a new node to the firmware framework, query the new node for firmware image details;
verify the firmware image, based at least in part on the firmware image details; and
in response to a determination that verification of the firmware image was successful, enable discovery and participation in the firmware framework for the new node.
20 . The EC of claim 19 , wherein the given node is respective to at least one of: a sensor hub, a network controller, or a Global Positioning System (GPS) device, and wherein the other node is respective to at least one of: a Universal Serial Bus (USB) controller, a display controller, or a Human Presence Detection (HPD) sensor.