Hi Ard,
For all the patches I haven't explicitly asked any questions about:
Reviewed-by: Leif Lindholm <quic_llindhol@quicinc.com>
On Mon, Mar 13, 2023 at 18:16:36 +0100, Ard Biesheuvel wrote:
> Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369
>
> This v5 now covers a lot more ground, and has ballooned quite
> substantially as a result. The series is essentially a proof of concept
> of a way to implement rigorous W^X memory protections from SEC all the
> way to booting the OS.
>
> In particular:
> - the AArch64 WXN control is enabled so that NX is implied for all
> writable memory regions, which is rather helpful when testing changes
> such as these;
> - avoid PEIM shadowing where possible, as that would involve managing
> the executable permissions of the shadowed code
> - remap the DXE core code section read-only explicitly from IPL
> - equip the DXE core with a way to manage memory permissions before the
> CPU arch protocol driver is dispatched;
> - permit the NX memory protection policy to apply to code memory type
> regions as well
> - check the NX compat DLL flag and section alignment to decide whether
> an image can be loaded when the NX policy is applied to such a code
> region
> - implement the EFI memory attributes protocol (for ARM and AArch64
> only) so that such NX compat compliant images have a way to create
> executable mappings
>
> v4:
> - major cleanup of the 32-bit ARM code
> - add support for EFI_MEMORY_RP using the access flag
> - enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP)
> - incorporate optimization from other series [0] to avoid splitting
> block entries unnecessarily
>
> v3:
> - fix ARM32 bug in attribute conversion
> - add Liming's ack to patch #1
> - include draft patch (NOT FOR MERGE) used to test the changes
>
> v2:
> - drop patch to bump exposed UEFI revision to v2.10
> - add missing permitted return values to protocol definition
>
> [0] https://edk2.groups.io/g/devel/message/99801
>
> Cc: Michael Kinney <michael.d.kinney@intel.com>
> Cc: Liming Gao <gaoliming@byosoft.com.cn>
> Cc: Jiewen Yao <jiewen.yao@intel.com>
> Cc: Michael Kubacki <michael.kubacki@microsoft.com>
> Cc: Sean Brogan <sean.brogan@microsoft.com>
> Cc: Rebecca Cran <quic_rcran@quicinc.com>
> Cc: Leif Lindholm <quic_llindhol@quicinc.com>
> Cc: Sami Mujawar <sami.mujawar@arm.com>
> Cc: Taylor Beebe <t@taylorbeebe.com>
>
> Ard Biesheuvel (38):
> ArmPkg/ArmMmuLib ARM: Remove half baked large page support
> ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field
> ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion
> ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask
> ArmPkg/ArmMmuLib ARM: Clear individual permission bits
> ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag
> ArmVirtPkg: Enable stack guard
> ArmPkg/ArmMmuLib: Avoid splitting block entries if possible
> ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion
> MdePkg: Add Memory Attribute Protocol definition
> ArmPkg/CpuDxe: Implement EFI memory attributes protocol
> ArmPkg/CpuDxe: Perform preliminary NX remap of free memory
> MdeModulePkg/DxeCore: Unconditionally set memory protections
> ArmPkg/Mmu: Remove handling of NONSECURE memory regions
> ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory
> MdePkg/BasePeCoffLib: Add API to keep track of relocation range
> MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default
> MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch
> MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time
> MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback
> ArmPkg: Implement ArmSetMemoryOverrideLib
> MdeModulePkg/PcdPeim: Permit unshadowed execution
> EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution
> ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default
> ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs
> ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code
> flash
> BaseTools/GccBase AARCH64: Avoid page sharing between code and data
> ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory
> permissions
> MdePkg/PeCoffLib: Capture DLL characteristics field in image context
> MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics
> MdeModulePkg/DxeCore: Remove redundant DEBUG statements
> MdeModulePkg/DxeCore: Update memory protections before freeing a
> region
> MdeModulePkg/DxeCore: Disregard runtime alignment for image protection
> MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage()
> MdeModulePkg/DxeCore: Clear NX permissions on non-protected images
> MdeModulePkg/DxeCore: Permit NX protection for code regions
> MdeModulePkg/DxeCore: Check NX compat when using restricted code
> regions
> MdeModulePkg DEC: Remove inaccurate comment
>
> ArmPkg/ArmPkg.dec | 5 +
> ArmPkg/ArmPkg.dsc | 1 +
> ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c | 25 +-
> ArmPkg/Drivers/CpuDxe/Arm/Mmu.c | 96 +++++--
> ArmPkg/Drivers/CpuDxe/CpuDxe.c | 87 ++++++
> ArmPkg/Drivers/CpuDxe/CpuDxe.h | 17 ++
> ArmPkg/Drivers/CpuDxe/CpuDxe.inf | 5 +
> ArmPkg/Drivers/CpuDxe/MemoryAttribute.c | 271 ++++++++++++++++++
> ArmPkg/Include/Chipset/ArmV7Mmu.h | 131 ++++-----
> ArmPkg/Include/Library/ArmLib.h | 17 +-
> ArmPkg/Include/Library/ArmMmuLib.h | 34 +++
> ArmPkg/Library/ArmLib/Arm/ArmV7Support.S | 2 +
> ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c | 103 ++++++-
> ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c | 8 +-
> ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c | 51 ++--
> ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c | 173 ++++++++++--
> ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c | 78 ++++++
> ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf | 28 ++
> ArmVirtPkg/ArmVirt.dsc.inc | 3 +
> ArmVirtPkg/ArmVirtQemu.dsc | 11 +-
> ArmVirtPkg/ArmVirtQemuKernel.dsc | 1 +
> ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S | 2 +-
> ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c | 4 +-
> BaseTools/Scripts/GccBase.lds | 13 +-
> EmbeddedPkg/Include/Library/PrePiLib.h | 16 --
> EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c | 51 ++++
> EmbeddedPkg/Library/PrePiLib/PrePi.h | 13 +
> EmbeddedPkg/Library/PrePiLib/PrePiLib.c | 4 +
> EmbeddedPkg/Library/PrePiLib/PrePiLib.inf | 12 +
> EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c | 23 ++
> MdeModulePkg/Core/Dxe/DxeMain.h | 6 +-
> MdeModulePkg/Core/Dxe/Image/Image.c | 8 +-
> MdeModulePkg/Core/Dxe/Mem/Page.c | 15 +-
> MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c | 288 +++++++++++---------
> MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c | 73 +++++
> MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf | 6 +-
> MdeModulePkg/Core/DxeIplPeim/DxeLoad.c | 24 +-
> MdeModulePkg/MdeModulePkg.dec | 7 +-
> MdeModulePkg/Universal/PCD/Pei/Pcd.c | 112 ++++----
> MdeModulePkg/Universal/PCD/Pei/Pcd.inf | 1 +
> MdePkg/Include/IndustryStandard/PeImage.h | 15 +
> MdePkg/Include/Library/PeCoffLib.h | 27 ++
> MdePkg/Include/Protocol/MemoryAttribute.h | 142 ++++++++++
> MdePkg/Library/BasePeCoffLib/BasePeCoff.c | 105 ++++++-
> MdePkg/MdePkg.dec | 3 +
> 45 files changed, 1682 insertions(+), 435 deletions(-)
> create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c
> create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c
> create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf
> create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c
> create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c
> create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h
>
> --
> 2.39.2
>
>
>
>
>
>
-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#101275): https://edk2.groups.io/g/devel/message/101275
Mute This Topic: https://groups.io/mt/97585979/1787277
Group Owner: devel+owner@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/leave/3901457/1787277/102458076/xyzzy [importer@patchew.org]
-=-=-=-=-=-=-=-=-=-=-=-