[edk2-devel] [PATCH v5 00/38] Implement strict memory permissions throughout

Ard Biesheuvel posted 38 patches 1 year, 1 month ago
Failed in applying to current master (apply log)
ArmPkg/ArmPkg.dec                                                  |   5 +
ArmPkg/ArmPkg.dsc                                                  |   1 +
ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c                                |  25 +-
ArmPkg/Drivers/CpuDxe/Arm/Mmu.c                                    |  96 +++++--
ArmPkg/Drivers/CpuDxe/CpuDxe.c                                     |  87 ++++++
ArmPkg/Drivers/CpuDxe/CpuDxe.h                                     |  17 ++
ArmPkg/Drivers/CpuDxe/CpuDxe.inf                                   |   5 +
ArmPkg/Drivers/CpuDxe/MemoryAttribute.c                            | 271 ++++++++++++++++++
ArmPkg/Include/Chipset/ArmV7Mmu.h                                  | 131 ++++-----
ArmPkg/Include/Library/ArmLib.h                                    |  17 +-
ArmPkg/Include/Library/ArmMmuLib.h                                 |  34 +++
ArmPkg/Library/ArmLib/Arm/ArmV7Support.S                           |   2 +
ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c                   | 103 ++++++-
ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c                    |   8 +-
ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c                       |  51 ++--
ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c                     | 173 ++++++++++--
ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c   |  78 ++++++
ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf |  28 ++
ArmVirtPkg/ArmVirt.dsc.inc                                         |   3 +
ArmVirtPkg/ArmVirtQemu.dsc                                         |  11 +-
ArmVirtPkg/ArmVirtQemuKernel.dsc                                   |   1 +
ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S  |   2 +-
ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c         |   4 +-
BaseTools/Scripts/GccBase.lds                                      |  13 +-
EmbeddedPkg/Include/Library/PrePiLib.h                             |  16 --
EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c                    |  51 ++++
EmbeddedPkg/Library/PrePiLib/PrePi.h                               |  13 +
EmbeddedPkg/Library/PrePiLib/PrePiLib.c                            |   4 +
EmbeddedPkg/Library/PrePiLib/PrePiLib.inf                          |  12 +
EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c                    |  23 ++
MdeModulePkg/Core/Dxe/DxeMain.h                                    |   6 +-
MdeModulePkg/Core/Dxe/Image/Image.c                                |   8 +-
MdeModulePkg/Core/Dxe/Mem/Page.c                                   |  15 +-
MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c                      | 288 +++++++++++---------
MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c                     |  73 +++++
MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf                            |   6 +-
MdeModulePkg/Core/DxeIplPeim/DxeLoad.c                             |  24 +-
MdeModulePkg/MdeModulePkg.dec                                      |   7 +-
MdeModulePkg/Universal/PCD/Pei/Pcd.c                               | 112 ++++----
MdeModulePkg/Universal/PCD/Pei/Pcd.inf                             |   1 +
MdePkg/Include/IndustryStandard/PeImage.h                          |  15 +
MdePkg/Include/Library/PeCoffLib.h                                 |  27 ++
MdePkg/Include/Protocol/MemoryAttribute.h                          | 142 ++++++++++
MdePkg/Library/BasePeCoffLib/BasePeCoff.c                          | 105 ++++++-
MdePkg/MdePkg.dec                                                  |   3 +
45 files changed, 1682 insertions(+), 435 deletions(-)
create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c
create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c
create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf
create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c
create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c
create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h
[edk2-devel] [PATCH v5 00/38] Implement strict memory permissions throughout
Posted by Ard Biesheuvel 1 year, 1 month ago
Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369

This v5 now covers a lot more ground, and has ballooned quite
substantially as a result. The series is essentially a proof of concept
of a way to implement rigorous W^X memory protections from SEC all the
way to booting the OS.

In particular:
- the AArch64 WXN control is enabled so that NX is implied for all
  writable memory regions, which is rather helpful when testing changes
  such as these;
- avoid PEIM shadowing where possible, as that would involve managing
  the executable permissions of the shadowed code
- remap the DXE core code section read-only explicitly from IPL
- equip the DXE core with a way to manage memory permissions before the
  CPU arch protocol driver is dispatched;
- permit the NX memory protection policy to apply to code memory type
  regions as well
- check the NX compat DLL flag and section alignment to decide whether
  an image can be loaded when the NX policy is applied to such a code
  region 
- implement the EFI memory attributes protocol (for ARM and AArch64
  only) so that such NX compat compliant images have a way to create
  executable mappings 

v4:
- major cleanup of the 32-bit ARM code
- add support for EFI_MEMORY_RP using the access flag
- enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP)
- incorporate optimization from other series [0] to avoid splitting
  block entries unnecessarily

v3:
- fix ARM32 bug in attribute conversion
- add Liming's ack to patch #1
- include draft patch (NOT FOR MERGE) used to test the changes

v2:
- drop patch to bump exposed UEFI revision to v2.10
- add missing permitted return values to protocol definition

[0] https://edk2.groups.io/g/devel/message/99801

Cc: Michael Kinney <michael.d.kinney@intel.com>
Cc: Liming Gao <gaoliming@byosoft.com.cn>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Michael Kubacki <michael.kubacki@microsoft.com>
Cc: Sean Brogan <sean.brogan@microsoft.com>
Cc: Rebecca Cran <quic_rcran@quicinc.com>
Cc: Leif Lindholm <quic_llindhol@quicinc.com>
Cc: Sami Mujawar <sami.mujawar@arm.com>
Cc: Taylor Beebe <t@taylorbeebe.com>

Ard Biesheuvel (38):
  ArmPkg/ArmMmuLib ARM: Remove half baked large page support
  ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field
  ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion
  ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask
  ArmPkg/ArmMmuLib ARM: Clear individual permission bits
  ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag
  ArmVirtPkg: Enable stack guard
  ArmPkg/ArmMmuLib: Avoid splitting block entries if possible
  ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion
  MdePkg: Add Memory Attribute Protocol definition
  ArmPkg/CpuDxe: Implement EFI memory attributes protocol
  ArmPkg/CpuDxe: Perform preliminary NX remap of free memory
  MdeModulePkg/DxeCore: Unconditionally set memory protections
  ArmPkg/Mmu: Remove handling of NONSECURE memory regions
  ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory
  MdePkg/BasePeCoffLib: Add API to keep track of relocation range
  MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default
  MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch
  MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time
  MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback
  ArmPkg: Implement ArmSetMemoryOverrideLib
  MdeModulePkg/PcdPeim: Permit unshadowed execution
  EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution
  ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default
  ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs
  ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code
    flash
  BaseTools/GccBase AARCH64: Avoid page sharing between code and data
  ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory
    permissions
  MdePkg/PeCoffLib: Capture DLL characteristics field in image context
  MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics
  MdeModulePkg/DxeCore: Remove redundant DEBUG statements
  MdeModulePkg/DxeCore: Update memory protections before freeing a
    region
  MdeModulePkg/DxeCore: Disregard runtime alignment for image protection
  MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage()
  MdeModulePkg/DxeCore: Clear NX permissions on non-protected images
  MdeModulePkg/DxeCore: Permit NX protection for code regions
  MdeModulePkg/DxeCore: Check NX compat when using restricted code
    regions
  MdeModulePkg DEC: Remove inaccurate comment

 ArmPkg/ArmPkg.dec                                                  |   5 +
 ArmPkg/ArmPkg.dsc                                                  |   1 +
 ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c                                |  25 +-
 ArmPkg/Drivers/CpuDxe/Arm/Mmu.c                                    |  96 +++++--
 ArmPkg/Drivers/CpuDxe/CpuDxe.c                                     |  87 ++++++
 ArmPkg/Drivers/CpuDxe/CpuDxe.h                                     |  17 ++
 ArmPkg/Drivers/CpuDxe/CpuDxe.inf                                   |   5 +
 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c                            | 271 ++++++++++++++++++
 ArmPkg/Include/Chipset/ArmV7Mmu.h                                  | 131 ++++-----
 ArmPkg/Include/Library/ArmLib.h                                    |  17 +-
 ArmPkg/Include/Library/ArmMmuLib.h                                 |  34 +++
 ArmPkg/Library/ArmLib/Arm/ArmV7Support.S                           |   2 +
 ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c                   | 103 ++++++-
 ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c                    |   8 +-
 ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c                       |  51 ++--
 ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c                     | 173 ++++++++++--
 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c   |  78 ++++++
 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf |  28 ++
 ArmVirtPkg/ArmVirt.dsc.inc                                         |   3 +
 ArmVirtPkg/ArmVirtQemu.dsc                                         |  11 +-
 ArmVirtPkg/ArmVirtQemuKernel.dsc                                   |   1 +
 ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S  |   2 +-
 ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c         |   4 +-
 BaseTools/Scripts/GccBase.lds                                      |  13 +-
 EmbeddedPkg/Include/Library/PrePiLib.h                             |  16 --
 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c                    |  51 ++++
 EmbeddedPkg/Library/PrePiLib/PrePi.h                               |  13 +
 EmbeddedPkg/Library/PrePiLib/PrePiLib.c                            |   4 +
 EmbeddedPkg/Library/PrePiLib/PrePiLib.inf                          |  12 +
 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c                    |  23 ++
 MdeModulePkg/Core/Dxe/DxeMain.h                                    |   6 +-
 MdeModulePkg/Core/Dxe/Image/Image.c                                |   8 +-
 MdeModulePkg/Core/Dxe/Mem/Page.c                                   |  15 +-
 MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c                      | 288 +++++++++++---------
 MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c                     |  73 +++++
 MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf                            |   6 +-
 MdeModulePkg/Core/DxeIplPeim/DxeLoad.c                             |  24 +-
 MdeModulePkg/MdeModulePkg.dec                                      |   7 +-
 MdeModulePkg/Universal/PCD/Pei/Pcd.c                               | 112 ++++----
 MdeModulePkg/Universal/PCD/Pei/Pcd.inf                             |   1 +
 MdePkg/Include/IndustryStandard/PeImage.h                          |  15 +
 MdePkg/Include/Library/PeCoffLib.h                                 |  27 ++
 MdePkg/Include/Protocol/MemoryAttribute.h                          | 142 ++++++++++
 MdePkg/Library/BasePeCoffLib/BasePeCoff.c                          | 105 ++++++-
 MdePkg/MdePkg.dec                                                  |   3 +
 45 files changed, 1682 insertions(+), 435 deletions(-)
 create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c
 create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c
 create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf
 create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c
 create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c
 create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h

-- 
2.39.2



-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#101104): https://edk2.groups.io/g/devel/message/101104
Mute This Topic: https://groups.io/mt/97585979/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-
Re: [edk2-devel] [PATCH v5 00/38] Implement strict memory permissions throughout
Posted by Oliver Smith-Denny 1 year, 1 month ago
Hi Ard,

For the patchset:

Reviewed- and Tested-by: Oliver Smith-Denny <osd@smith-denny.com>

Thanks for sending this out! I tested with some integrations to Project 
Mu on both a virtual and physical platform.

Oliver

On 3/13/2023 10:16 AM, Ard Biesheuvel wrote:
> Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369
> 
> 
> 
> This v5 now covers a lot more ground, and has ballooned quite
> 
> substantially as a result. The series is essentially a proof of concept
> 
> of a way to implement rigorous W^X memory protections from SEC all the
> 
> way to booting the OS.
> 
> 
> 
> In particular:
> 
> - the AArch64 WXN control is enabled so that NX is implied for all
> 
>    writable memory regions, which is rather helpful when testing changes
> 
>    such as these;
> 
> - avoid PEIM shadowing where possible, as that would involve managing
> 
>    the executable permissions of the shadowed code
> 
> - remap the DXE core code section read-only explicitly from IPL
> 
> - equip the DXE core with a way to manage memory permissions before the
> 
>    CPU arch protocol driver is dispatched;
> 
> - permit the NX memory protection policy to apply to code memory type
> 
>    regions as well
> 
> - check the NX compat DLL flag and section alignment to decide whether
> 
>    an image can be loaded when the NX policy is applied to such a code
> 
>    region
> 
> - implement the EFI memory attributes protocol (for ARM and AArch64
> 
>    only) so that such NX compat compliant images have a way to create
> 
>    executable mappings
> 
> 
> 
> v4:
> 
> - major cleanup of the 32-bit ARM code
> 
> - add support for EFI_MEMORY_RP using the access flag
> 
> - enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP)
> 
> - incorporate optimization from other series [0] to avoid splitting
> 
>    block entries unnecessarily
> 
> 
> 
> v3:
> 
> - fix ARM32 bug in attribute conversion
> 
> - add Liming's ack to patch #1
> 
> - include draft patch (NOT FOR MERGE) used to test the changes
> 
> 
> 
> v2:
> 
> - drop patch to bump exposed UEFI revision to v2.10
> 
> - add missing permitted return values to protocol definition
> 
> 
> 
> [0] https://edk2.groups.io/g/devel/message/99801
> 
> 
> 
> Cc: Michael Kinney <michael.d.kinney@intel.com>
> 
> Cc: Liming Gao <gaoliming@byosoft.com.cn>
> 
> Cc: Jiewen Yao <jiewen.yao@intel.com>
> 
> Cc: Michael Kubacki <michael.kubacki@microsoft.com>
> 
> Cc: Sean Brogan <sean.brogan@microsoft.com>
> 
> Cc: Rebecca Cran <quic_rcran@quicinc.com>
> 
> Cc: Leif Lindholm <quic_llindhol@quicinc.com>
> 
> Cc: Sami Mujawar <sami.mujawar@arm.com>
> 
> Cc: Taylor Beebe <t@taylorbeebe.com>
> 
> 
> 
> Ard Biesheuvel (38):
> 
>    ArmPkg/ArmMmuLib ARM: Remove half baked large page support
> 
>    ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field
> 
>    ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion
> 
>    ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask
> 
>    ArmPkg/ArmMmuLib ARM: Clear individual permission bits
> 
>    ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag
> 
>    ArmVirtPkg: Enable stack guard
> 
>    ArmPkg/ArmMmuLib: Avoid splitting block entries if possible
> 
>    ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion
> 
>    MdePkg: Add Memory Attribute Protocol definition
> 
>    ArmPkg/CpuDxe: Implement EFI memory attributes protocol
> 
>    ArmPkg/CpuDxe: Perform preliminary NX remap of free memory
> 
>    MdeModulePkg/DxeCore: Unconditionally set memory protections
> 
>    ArmPkg/Mmu: Remove handling of NONSECURE memory regions
> 
>    ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory
> 
>    MdePkg/BasePeCoffLib: Add API to keep track of relocation range
> 
>    MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default
> 
>    MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch
> 
>    MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time
> 
>    MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback
> 
>    ArmPkg: Implement ArmSetMemoryOverrideLib
> 
>    MdeModulePkg/PcdPeim: Permit unshadowed execution
> 
>    EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution
> 
>    ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default
> 
>    ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs
> 
>    ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code
> 
>      flash
> 
>    BaseTools/GccBase AARCH64: Avoid page sharing between code and data
> 
>    ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory
> 
>      permissions
> 
>    MdePkg/PeCoffLib: Capture DLL characteristics field in image context
> 
>    MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics
> 
>    MdeModulePkg/DxeCore: Remove redundant DEBUG statements
> 
>    MdeModulePkg/DxeCore: Update memory protections before freeing a
> 
>      region
> 
>    MdeModulePkg/DxeCore: Disregard runtime alignment for image protection
> 
>    MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage()
> 
>    MdeModulePkg/DxeCore: Clear NX permissions on non-protected images
> 
>    MdeModulePkg/DxeCore: Permit NX protection for code regions
> 
>    MdeModulePkg/DxeCore: Check NX compat when using restricted code
> 
>      regions
> 
>    MdeModulePkg DEC: Remove inaccurate comment
> 
> 
> 
>   ArmPkg/ArmPkg.dec                                                  |   5 +
> 
>   ArmPkg/ArmPkg.dsc                                                  |   1 +
> 
>   ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c                                |  25 +-
> 
>   ArmPkg/Drivers/CpuDxe/Arm/Mmu.c                                    |  96 +++++--
> 
>   ArmPkg/Drivers/CpuDxe/CpuDxe.c                                     |  87 ++++++
> 
>   ArmPkg/Drivers/CpuDxe/CpuDxe.h                                     |  17 ++
> 
>   ArmPkg/Drivers/CpuDxe/CpuDxe.inf                                   |   5 +
> 
>   ArmPkg/Drivers/CpuDxe/MemoryAttribute.c                            | 271 ++++++++++++++++++
> 
>   ArmPkg/Include/Chipset/ArmV7Mmu.h                                  | 131 ++++-----
> 
>   ArmPkg/Include/Library/ArmLib.h                                    |  17 +-
> 
>   ArmPkg/Include/Library/ArmMmuLib.h                                 |  34 +++
> 
>   ArmPkg/Library/ArmLib/Arm/ArmV7Support.S                           |   2 +
> 
>   ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c                   | 103 ++++++-
> 
>   ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c                    |   8 +-
> 
>   ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c                       |  51 ++--
> 
>   ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c                     | 173 ++++++++++--
> 
>   ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c   |  78 ++++++
> 
>   ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf |  28 ++
> 
>   ArmVirtPkg/ArmVirt.dsc.inc                                         |   3 +
> 
>   ArmVirtPkg/ArmVirtQemu.dsc                                         |  11 +-
> 
>   ArmVirtPkg/ArmVirtQemuKernel.dsc                                   |   1 +
> 
>   ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S  |   2 +-
> 
>   ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c         |   4 +-
> 
>   BaseTools/Scripts/GccBase.lds                                      |  13 +-
> 
>   EmbeddedPkg/Include/Library/PrePiLib.h                             |  16 --
> 
>   EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c                    |  51 ++++
> 
>   EmbeddedPkg/Library/PrePiLib/PrePi.h                               |  13 +
> 
>   EmbeddedPkg/Library/PrePiLib/PrePiLib.c                            |   4 +
> 
>   EmbeddedPkg/Library/PrePiLib/PrePiLib.inf                          |  12 +
> 
>   EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c                    |  23 ++
> 
>   MdeModulePkg/Core/Dxe/DxeMain.h                                    |   6 +-
> 
>   MdeModulePkg/Core/Dxe/Image/Image.c                                |   8 +-
> 
>   MdeModulePkg/Core/Dxe/Mem/Page.c                                   |  15 +-
> 
>   MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c                      | 288 +++++++++++---------
> 
>   MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c                     |  73 +++++
> 
>   MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf                            |   6 +-
> 
>   MdeModulePkg/Core/DxeIplPeim/DxeLoad.c                             |  24 +-
> 
>   MdeModulePkg/MdeModulePkg.dec                                      |   7 +-
> 
>   MdeModulePkg/Universal/PCD/Pei/Pcd.c                               | 112 ++++----
> 
>   MdeModulePkg/Universal/PCD/Pei/Pcd.inf                             |   1 +
> 
>   MdePkg/Include/IndustryStandard/PeImage.h                          |  15 +
> 
>   MdePkg/Include/Library/PeCoffLib.h                                 |  27 ++
> 
>   MdePkg/Include/Protocol/MemoryAttribute.h                          | 142 ++++++++++
> 
>   MdePkg/Library/BasePeCoffLib/BasePeCoff.c                          | 105 ++++++-
> 
>   MdePkg/MdePkg.dec                                                  |   3 +
> 
>   45 files changed, 1682 insertions(+), 435 deletions(-)
> 
>   create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c
> 
>   create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c
> 
>   create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf
> 
>   create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c
> 
>   create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c
> 
>   create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h
> 
> 
> 


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#101373): https://edk2.groups.io/g/devel/message/101373
Mute This Topic: https://groups.io/mt/97585979/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-
Re: [edk2-devel] [PATCH v5 00/38] Implement strict memory permissions throughout
Posted by Leif Lindholm 1 year, 1 month ago
Hi Ard,

For all the patches I haven't explicitly asked any questions about:
Reviewed-by: Leif Lindholm <quic_llindhol@quicinc.com>


On Mon, Mar 13, 2023 at 18:16:36 +0100, Ard Biesheuvel wrote:
> Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369
> 
> This v5 now covers a lot more ground, and has ballooned quite
> substantially as a result. The series is essentially a proof of concept
> of a way to implement rigorous W^X memory protections from SEC all the
> way to booting the OS.
> 
> In particular:
> - the AArch64 WXN control is enabled so that NX is implied for all
>   writable memory regions, which is rather helpful when testing changes
>   such as these;
> - avoid PEIM shadowing where possible, as that would involve managing
>   the executable permissions of the shadowed code
> - remap the DXE core code section read-only explicitly from IPL
> - equip the DXE core with a way to manage memory permissions before the
>   CPU arch protocol driver is dispatched;
> - permit the NX memory protection policy to apply to code memory type
>   regions as well
> - check the NX compat DLL flag and section alignment to decide whether
>   an image can be loaded when the NX policy is applied to such a code
>   region 
> - implement the EFI memory attributes protocol (for ARM and AArch64
>   only) so that such NX compat compliant images have a way to create
>   executable mappings 
> 
> v4:
> - major cleanup of the 32-bit ARM code
> - add support for EFI_MEMORY_RP using the access flag
> - enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP)
> - incorporate optimization from other series [0] to avoid splitting
>   block entries unnecessarily
> 
> v3:
> - fix ARM32 bug in attribute conversion
> - add Liming's ack to patch #1
> - include draft patch (NOT FOR MERGE) used to test the changes
> 
> v2:
> - drop patch to bump exposed UEFI revision to v2.10
> - add missing permitted return values to protocol definition
> 
> [0] https://edk2.groups.io/g/devel/message/99801
> 
> Cc: Michael Kinney <michael.d.kinney@intel.com>
> Cc: Liming Gao <gaoliming@byosoft.com.cn>
> Cc: Jiewen Yao <jiewen.yao@intel.com>
> Cc: Michael Kubacki <michael.kubacki@microsoft.com>
> Cc: Sean Brogan <sean.brogan@microsoft.com>
> Cc: Rebecca Cran <quic_rcran@quicinc.com>
> Cc: Leif Lindholm <quic_llindhol@quicinc.com>
> Cc: Sami Mujawar <sami.mujawar@arm.com>
> Cc: Taylor Beebe <t@taylorbeebe.com>
> 
> Ard Biesheuvel (38):
>   ArmPkg/ArmMmuLib ARM: Remove half baked large page support
>   ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field
>   ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion
>   ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask
>   ArmPkg/ArmMmuLib ARM: Clear individual permission bits
>   ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag
>   ArmVirtPkg: Enable stack guard
>   ArmPkg/ArmMmuLib: Avoid splitting block entries if possible
>   ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion
>   MdePkg: Add Memory Attribute Protocol definition
>   ArmPkg/CpuDxe: Implement EFI memory attributes protocol
>   ArmPkg/CpuDxe: Perform preliminary NX remap of free memory
>   MdeModulePkg/DxeCore: Unconditionally set memory protections
>   ArmPkg/Mmu: Remove handling of NONSECURE memory regions
>   ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory
>   MdePkg/BasePeCoffLib: Add API to keep track of relocation range
>   MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default
>   MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch
>   MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time
>   MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback
>   ArmPkg: Implement ArmSetMemoryOverrideLib
>   MdeModulePkg/PcdPeim: Permit unshadowed execution
>   EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution
>   ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default
>   ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs
>   ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code
>     flash
>   BaseTools/GccBase AARCH64: Avoid page sharing between code and data
>   ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory
>     permissions
>   MdePkg/PeCoffLib: Capture DLL characteristics field in image context
>   MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics
>   MdeModulePkg/DxeCore: Remove redundant DEBUG statements
>   MdeModulePkg/DxeCore: Update memory protections before freeing a
>     region
>   MdeModulePkg/DxeCore: Disregard runtime alignment for image protection
>   MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage()
>   MdeModulePkg/DxeCore: Clear NX permissions on non-protected images
>   MdeModulePkg/DxeCore: Permit NX protection for code regions
>   MdeModulePkg/DxeCore: Check NX compat when using restricted code
>     regions
>   MdeModulePkg DEC: Remove inaccurate comment
> 
>  ArmPkg/ArmPkg.dec                                                  |   5 +
>  ArmPkg/ArmPkg.dsc                                                  |   1 +
>  ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c                                |  25 +-
>  ArmPkg/Drivers/CpuDxe/Arm/Mmu.c                                    |  96 +++++--
>  ArmPkg/Drivers/CpuDxe/CpuDxe.c                                     |  87 ++++++
>  ArmPkg/Drivers/CpuDxe/CpuDxe.h                                     |  17 ++
>  ArmPkg/Drivers/CpuDxe/CpuDxe.inf                                   |   5 +
>  ArmPkg/Drivers/CpuDxe/MemoryAttribute.c                            | 271 ++++++++++++++++++
>  ArmPkg/Include/Chipset/ArmV7Mmu.h                                  | 131 ++++-----
>  ArmPkg/Include/Library/ArmLib.h                                    |  17 +-
>  ArmPkg/Include/Library/ArmMmuLib.h                                 |  34 +++
>  ArmPkg/Library/ArmLib/Arm/ArmV7Support.S                           |   2 +
>  ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c                   | 103 ++++++-
>  ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c                    |   8 +-
>  ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c                       |  51 ++--
>  ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c                     | 173 ++++++++++--
>  ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c   |  78 ++++++
>  ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf |  28 ++
>  ArmVirtPkg/ArmVirt.dsc.inc                                         |   3 +
>  ArmVirtPkg/ArmVirtQemu.dsc                                         |  11 +-
>  ArmVirtPkg/ArmVirtQemuKernel.dsc                                   |   1 +
>  ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S  |   2 +-
>  ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c         |   4 +-
>  BaseTools/Scripts/GccBase.lds                                      |  13 +-
>  EmbeddedPkg/Include/Library/PrePiLib.h                             |  16 --
>  EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c                    |  51 ++++
>  EmbeddedPkg/Library/PrePiLib/PrePi.h                               |  13 +
>  EmbeddedPkg/Library/PrePiLib/PrePiLib.c                            |   4 +
>  EmbeddedPkg/Library/PrePiLib/PrePiLib.inf                          |  12 +
>  EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c                    |  23 ++
>  MdeModulePkg/Core/Dxe/DxeMain.h                                    |   6 +-
>  MdeModulePkg/Core/Dxe/Image/Image.c                                |   8 +-
>  MdeModulePkg/Core/Dxe/Mem/Page.c                                   |  15 +-
>  MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c                      | 288 +++++++++++---------
>  MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c                     |  73 +++++
>  MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf                            |   6 +-
>  MdeModulePkg/Core/DxeIplPeim/DxeLoad.c                             |  24 +-
>  MdeModulePkg/MdeModulePkg.dec                                      |   7 +-
>  MdeModulePkg/Universal/PCD/Pei/Pcd.c                               | 112 ++++----
>  MdeModulePkg/Universal/PCD/Pei/Pcd.inf                             |   1 +
>  MdePkg/Include/IndustryStandard/PeImage.h                          |  15 +
>  MdePkg/Include/Library/PeCoffLib.h                                 |  27 ++
>  MdePkg/Include/Protocol/MemoryAttribute.h                          | 142 ++++++++++
>  MdePkg/Library/BasePeCoffLib/BasePeCoff.c                          | 105 ++++++-
>  MdePkg/MdePkg.dec                                                  |   3 +
>  45 files changed, 1682 insertions(+), 435 deletions(-)
>  create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c
>  create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c
>  create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf
>  create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c
>  create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c
>  create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h
> 
> -- 
> 2.39.2
> 
> 
> 
> 
> 
> 


-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#101275): https://edk2.groups.io/g/devel/message/101275
Mute This Topic: https://groups.io/mt/97585979/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/leave/3901457/1787277/102458076/xyzzy [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-