From nobody Sun Feb 8 17:21:16 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+106350+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+106350+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=kernel.org ARC-Seal: i=1; a=rsa-sha256; t=1687768617; cv=none; d=zohomail.com; s=zohoarc; b=ZPYZAJ9AIOad7qqbt7YoSw0y0U6XC5j1wG4CETnlbQQf1Pcs0ixgSqhmIQcjGYuoWzdDiG37o5tasVMnDAE6/TYpVa8BZYI4ISVpNmrxZBqR2Kn/GghvNqD3cLhzuJsyn0U17MBAE4JsTshmYmiX66XSGZs16xbJDkBTuWAUqsM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1687768617; h=Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:References:Sender:Subject:To; bh=PMn2APq0RtW02UrO7c0WmsRUSgArP5Ws/rxHDZt1vy4=; b=mVxP5ua0nOnEGv6K7YdLEkprAjUJurVI9BYhJYYzJyFqvdGGikUIxpzAeQxi0DDJt+tZeimpUChpb+WWZ+6ZGcmkEArggDCFpf43t7re3NSVbQFFdoTCEwgM/zzs31EHqlD8XuHBperhtuKULP3BTzt/etCUOK0d9annM9W4cOA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+106350+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 16877686171618.212123543203234; Mon, 26 Jun 2023 01:36:57 -0700 (PDT) Return-Path: X-Received: by 127.0.0.2 with SMTP id DaqDYY1788612xps5H3Flxyn; Mon, 26 Jun 2023 01:36:56 -0700 X-Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) by mx.groups.io with SMTP id smtpd.web10.3285.1687768616323683607 for ; Mon, 26 Jun 2023 01:36:56 -0700 X-Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id D4C6560D30; Mon, 26 Jun 2023 08:36:55 +0000 (UTC) X-Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3B9CFC433CC; Mon, 26 Jun 2023 08:36:54 +0000 (UTC) From: "Ard Biesheuvel" To: devel@edk2.groups.io Cc: Ard Biesheuvel , Sami Mujawar , Leif Lindholm Subject: [edk2-devel] [PATCH 3/3] ArmPkg/OpteeLib: Map shared communication buffer non-executable Date: Mon, 26 Jun 2023 10:36:44 +0200 Message-Id: <20230626083644.1011698-4-ardb@kernel.org> In-Reply-To: <20230626083644.1011698-1-ardb@kernel.org> References: <20230626083644.1011698-1-ardb@kernel.org> MIME-Version: 1.0 Precedence: Bulk List-Unsubscribe: List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,ardb@kernel.org X-Gm-Message-State: aHipGIHAtGqgO3uqXpPbiss1x1787277AA= Content-Transfer-Encoding: quoted-printable DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=groups.io; q=dns/txt; s=20140610; t=1687768616; bh=mMnBArCZmoWE1SIuGNd/4TPos04LlpWv3k+WjuNBI+s=; h=Cc:Date:From:Reply-To:Subject:To; b=Pz8sS6u6kDqFC13VEPHEchc5R1D8zfpQpSM4AlK8cr0a66t7mqATFBkPg3l5CuGnyYi RwHwa5Ff7KRdSiBLq7UlMkItABEBMRKHUgzvfrPi4iQ5eqsgCnzdEh756/tGAxbo4rMFP /KeAnPTQAaqYPY1ZHCrX/xiFIi8jWkSN0cg= X-ZohoMail-DKIM: pass (identity @groups.io) X-ZM-MESSAGEID: 1687768618700100013 Content-Type: text/plain; charset="utf-8" The OP-TEE secure OS exposes a non-secure memory region for communication between the secure OS itself and any clients in the non-secure firmware. This memory is writable by non-secure and is not used for code only data, and so it should be mapped non-executable. Signed-off-by: Ard Biesheuvel Reviewed-by: Leif Lindholm --- ArmPkg/Library/OpteeLib/Optee.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/ArmPkg/Library/OpteeLib/Optee.c b/ArmPkg/Library/OpteeLib/Opte= e.c index 46464f17ef06653e..3acf172b68a2d34c 100644 --- a/ArmPkg/Library/OpteeLib/Optee.c +++ b/ArmPkg/Library/OpteeLib/Optee.c @@ -86,7 +86,12 @@ OpteeSharedMemoryRemap ( return EFI_BUFFER_TOO_SMALL; } =20 - Status =3D ArmSetMemoryAttributes (PhysicalAddress, Size, EFI_MEMORY_WB,= 0); + Status =3D ArmSetMemoryAttributes ( + PhysicalAddress, + Size, + EFI_MEMORY_WB | EFI_MEMORY_XP, + 0 + ); if (EFI_ERROR (Status)) { return Status; } --=20 2.39.2 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#106350): https://edk2.groups.io/g/devel/message/106350 Mute This Topic: https://groups.io/mt/99783775/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-