From nobody Mon Feb 9 02:28:26 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) client-ip=66.175.222.108; envelope-from=bounce+27952+109429+1787277+3901457@groups.io; helo=mail02.groups.io; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+109429+1787277+3901457@groups.io; dmarc=fail(p=none dis=none) header.from=gmail.com ARC-Seal: i=1; a=rsa-sha256; t=1696810092; cv=none; d=zohomail.com; s=zohoarc; b=Csb4I6wOJz6ggSs0nIxbSXZP3lG/zovsZ0f3RadddaOA/RcBwWiMaXvZe/UW/wivenYJyGaqL5Uv4R203J1ldZBxvG2Wq8kKz+uO7h4Grs1EFAGM6MMnrekzmoQ8N4jDtGpgOCIkzxB0vGSD/s5+RJCCbup1IHwweB/gZ2WYaNM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1696810092; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Reply-To:Reply-To:References:Sender:Subject:Subject:To:To:Message-Id; bh=sO+UyiM+zhhGl+bbckTLP+OeOBY/zB25/TQGfAhqgQU=; b=Pb7A0NLAgHqvo2b10t8u28KGCIP8BXft5weXuL0FMxCdV1k2j4iW0+x7O1St0JfcoO9HX3778mM3CtH7SCNYlWHuG6qrufR9Jhf1qOt1auTtVGmz+CWuY/O8lBRfkopLrFHRavz5ryUXZFoATcu7dKtyliaJH5RuEvDvctq65S0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of groups.io designates 66.175.222.108 as permitted sender) smtp.mailfrom=bounce+27952+109429+1787277+3901457@groups.io; dmarc=fail header.from= (p=none dis=none) Received: from mail02.groups.io (mail02.groups.io [66.175.222.108]) by mx.zohomail.com with SMTPS id 1696810092732649.0873494641895; Sun, 8 Oct 2023 17:08:12 -0700 (PDT) Return-Path: DKIM-Signature: a=rsa-sha256; bh=CBMNsgMntKX10ywZgGudhVp56ITo6Mq/hclebKofzec=; c=relaxed/simple; d=groups.io; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References:MIME-Version:Precedence:List-Subscribe:List-Help:Sender:List-Id:Mailing-List:Delivered-To:Reply-To:List-Unsubscribe-Post:List-Unsubscribe:Content-Transfer-Encoding; s=20140610; t=1696810092; v=1; b=d1jaTCJFZ+zEo/e2bSc90yvFO0ZmdQGBVcMFu3jCvG9Ml2vHaPGtIN7ogOeyAD3+VW7Q76Zq HkmdKLilq9NZoFQwFrqfGlEEYRhfKu3Ksei6V/Tt1hKVLshn2RpTHBnWQv4GHgitp4B/9vsS2Ch k93muGP+SGu614as9oZWwdQY= X-Received: by 127.0.0.2 with SMTP id Bd62YY1788612xfhd1BqlQ9d; Sun, 08 Oct 2023 17:08:12 -0700 X-Received: from mail-io1-f44.google.com (mail-io1-f44.google.com [209.85.166.44]) by mx.groups.io with SMTP id smtpd.web10.50232.1696810091827614370 for ; Sun, 08 Oct 2023 17:08:11 -0700 X-Received: by mail-io1-f44.google.com with SMTP id ca18e2360f4ac-79fb64b5265so175819939f.1 for ; Sun, 08 Oct 2023 17:08:11 -0700 (PDT) X-Gm-Message-State: Yd0vQRYXi0xtF0xHcGz5VS9Dx1787277AA= X-Google-Smtp-Source: AGHT+IG2tRvZSgqhKuAqzfYWQbl59f0dmaQF4uPvTubbekh4PzuXDwPP6YvHV3jHLMjdCAoluXZ5bQ== X-Received: by 2002:a05:6e02:1521:b0:34a:c618:b904 with SMTP id i1-20020a056e02152100b0034ac618b904mr17483853ilu.22.1696810090976; Sun, 08 Oct 2023 17:08:10 -0700 (PDT) X-Received: from localhost.localdomain ([50.46.253.1]) by smtp.gmail.com with ESMTPSA id t20-20020a62ea14000000b0068fcc7f6b00sm5048320pfh.74.2023.10.08.17.08.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 08 Oct 2023 17:08:10 -0700 (PDT) From: "Taylor Beebe" To: devel@edk2.groups.io Cc: Ard Biesheuvel , Leif Lindholm , Sami Mujawar , Gerd Hoffmann Subject: [edk2-devel] [PATCH v5 24/28] ArmVirtPkg: Apply Memory Protections via SetMemoryProtectionsLib Date: Sun, 8 Oct 2023 17:07:36 -0700 Message-ID: <20231009000742.1792-25-taylor.d.beebe@gmail.com> In-Reply-To: <20231009000742.1792-1-taylor.d.beebe@gmail.com> References: <20231009000742.1792-1-taylor.d.beebe@gmail.com> MIME-Version: 1.0 Precedence: Bulk List-Subscribe: List-Help: Sender: devel@edk2.groups.io List-Id: Mailing-List: list devel@edk2.groups.io; contact devel+owner@edk2.groups.io Reply-To: devel@edk2.groups.io,taylor.d.beebe@gmail.com List-Unsubscribe-Post: List-Unsubscribe=One-Click List-Unsubscribe: Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @groups.io) X-ZM-MESSAGEID: 1696810094588100102 Content-Type: text/plain; charset="utf-8" Set the memory protections on Arm virtual platforms. Because the QemuFg parser is not currently available in ArmVirtPkg, use the GrubCompat profile by default. Signed-off-by: Taylor Beebe Cc: Ard Biesheuvel Cc: Leif Lindholm Cc: Sami Mujawar Cc: Gerd Hoffmann --- ArmVirtPkg/MemoryInitPei/MemoryInitPeim.c | 7 +++++++ ArmVirtPkg/ArmVirtPkg.dec | 7 +++++++ ArmVirtPkg/MemoryInitPei/MemoryInitPeim.inf | 3 +++ 3 files changed, 17 insertions(+) diff --git a/ArmVirtPkg/MemoryInitPei/MemoryInitPeim.c b/ArmVirtPkg/MemoryI= nitPei/MemoryInitPeim.c index ef88a9df1d62..aaf2af9abccf 100644 --- a/ArmVirtPkg/MemoryInitPei/MemoryInitPeim.c +++ b/ArmVirtPkg/MemoryInitPei/MemoryInitPeim.c @@ -11,6 +11,7 @@ #include #include #include +#include #include #include #include @@ -100,5 +101,11 @@ InitializeMemory ( ); ASSERT_EFI_ERROR (Status); =20 + ASSERT (FixedPcdGet8 (PcdDxeMemoryProtectionProfile) < DxeMemoryProtecti= onSettingsMax); + SetDxeMemoryProtectionSettings ( + NULL, + (DXE_MEMORY_PROTECTION_PROFILE_INDEX)FixedPcdGet8 (PcdDxeMemoryProtect= ionProfile) + ); + return Status; } diff --git a/ArmVirtPkg/ArmVirtPkg.dec b/ArmVirtPkg/ArmVirtPkg.dec index 4645c91a8375..d90e492fa56a 100644 --- a/ArmVirtPkg/ArmVirtPkg.dec +++ b/ArmVirtPkg/ArmVirtPkg.dec @@ -67,3 +67,10 @@ [PcdsFixedAtBuild, PcdsPatchableInModule] # Cloud Hypervisor has no other way to pass Rsdp address to the guest ex= cept use a PCD. # gArmVirtTokenSpaceGuid.PcdCloudHvAcpiRsdpBaseAddress|0x0|UINT64|0x000000= 05 + + ## + # This value will be used to determine the level of memory protection ea= ch boot. + # See DXE_MEMORY_PROTECTION_PROFILE_INDEX in + # MdeModulePkg/Include/Library/SetMemoryProtectionsLib.h for index defin= itions. + # + gArmVirtTokenSpaceGuid.PcdDxeMemoryProtectionProfile|0x3|UINT8|0x00000006 diff --git a/ArmVirtPkg/MemoryInitPei/MemoryInitPeim.inf b/ArmVirtPkg/Memor= yInitPei/MemoryInitPeim.inf index 2039f71a0ebe..9cfd10bc44ef 100644 --- a/ArmVirtPkg/MemoryInitPei/MemoryInitPeim.inf +++ b/ArmVirtPkg/MemoryInitPei/MemoryInitPeim.inf @@ -26,6 +26,7 @@ [Packages] EmbeddedPkg/EmbeddedPkg.dec ArmPkg/ArmPkg.dec ArmPlatformPkg/ArmPlatformPkg.dec + ArmVirtPkg/ArmVirtPkg.dec =20 [LibraryClasses] PeimEntryPoint @@ -34,6 +35,7 @@ [LibraryClasses] ArmLib ArmPlatformLib MemoryInitPeiLib + SetMemoryProtectionsLib =20 [Guids] gEfiMemoryTypeInformationGuid @@ -44,6 +46,7 @@ [FeaturePcd] [FixedPcd] gArmTokenSpaceGuid.PcdSystemMemoryBase gArmPlatformTokenSpaceGuid.PcdSystemMemoryUefiRegionSize + gArmVirtTokenSpaceGuid.PcdDxeMemoryProtectionProfile =20 gEmbeddedTokenSpaceGuid.PcdMemoryTypeEfiACPIReclaimMemory gEmbeddedTokenSpaceGuid.PcdMemoryTypeEfiACPIMemoryNVS --=20 2.42.0.windows.2 -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#109429): https://edk2.groups.io/g/devel/message/109429 Mute This Topic: https://groups.io/mt/101843368/1787277 Group Owner: devel+owner@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [importer@patchew.org] -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-