From nobody Mon Feb 9 05:53:24 2026 Received: from mail-wm1-f74.google.com (mail-wm1-f74.google.com [209.85.128.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 50E051CAA64 for ; Sat, 1 Feb 2025 17:21:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.74 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1738430507; cv=none; b=mLyd4/OO5WOLAV7JbBFOIN1wSs42iIgRIDwxITl/cNhF7jM6tNq6HSzfgeRdcoEGTt4+OMpXQ75n0WudqGg3JqKZbYrbXk13lMr6xYOQtJ4Ewi4MPzFujPbwfabjNC12SMTsJJmdXdqdrg206xn+hhGIVIPCgGYypx5iKnxHX34= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1738430507; c=relaxed/simple; bh=esqqEYo0++dYji/MtqD/F6i+A6z6+qF0OS2a7BNstg8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=X8Gp7oGfwTLsm75UkZdpjuVHh+svaOIJGDYYPEHcK52fNKwQ6DEzLeLf/wgnnokTH8GNdJIqAuQF9socnMkybiLsHshrHA0PHyrGWw8xqKW4QSMnvu5ip0k44Gr0dofnhAnU8lM32q/KH92wRlj67vdonLZ6XzxAEG6MuIp7nko= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=XwdPMfhE; arc=none smtp.client-ip=209.85.128.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="XwdPMfhE" Received: by mail-wm1-f74.google.com with SMTP id 5b1f17b1804b1-4361efc9d1fso22834855e9.2 for ; Sat, 01 Feb 2025 09:21:45 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1738430503; x=1739035303; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=u+/I2FOukc3Dk/asy1e7U9EZH1wtrOizoGOwl5SdtH4=; b=XwdPMfhEOhQhS38ol2WNJPz4Zu74+kQAXwT3cTKHhjms1GkbLAD/XZInKPIQ1TYH01 wmW5NPfY++GKcbfJLp+52AOxspXzhwxM7bCOrvc5YCa8a7EB5SnLqkGArisTLzY4C5kg B3dxTZ/dgzbu1BS0JGEA1qu+zlkyoS611YG/Edhy0Ym/vRDWPpeAI+jboo0putl+GJ9i Z/AsZJrJTlra2q36EvW15vnmcNKRPDYuf42ofPtgh4QsET9hkTiKDWHRsDatuIyxBSx5 mVwJjzRsfLmYKadCPNNSRNMCuj/HkpI7i5x27V2S5sM7S4f8z94An9NIOdtxBWFtsjxr Aakw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1738430503; x=1739035303; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=u+/I2FOukc3Dk/asy1e7U9EZH1wtrOizoGOwl5SdtH4=; b=Ic+1nwG2wBUgGDeXZdRgUjxr44X+7RRCXwQfDEVKOGEo27Vd0yzdUz91CZnlxec2yK 3TA9OUp8F7FgyamQp1qtDtr+NAluFienni5fnSXxHhpZtPJhd/CZVLhxsk+KCX7PxpLq naWSezy32M3c4PLCOSMmgf1n51JZcNVY/zJuWodXX6h1KNYf4ewjSLkONjnU2hiluCee 4qiLVo+APAWX/rU0DVQ2XV0O6gpCYCq8I5OLMBgWQGF278//lZ/QTklN/tiL634MIu0S ly+bgPjEFIei3PwE7miHiy28PWVJZmb785TJVHkOPpgbNqt65tcm10LXF64bS3hisr63 8Y7g== X-Gm-Message-State: AOJu0YyFsywHWyuI+y9ade29DvCQ9cc5MWr5yeYrC/BkK7yybnfyoc01 H9aDe3jksP0peGTfJgniosz+hGKIH/U0a2DwUbKPSSGTI3x+/1T+Gw02zlXQbKiaGoPDhA== X-Google-Smtp-Source: AGHT+IH4Sk//KUgQXbsaN7PuwigW7TIUt60j0OUYDwXcBLIFBYQIS6PTHwK/yF3wuAJQ2njkwqWraLJl X-Received: from wmgg2.prod.google.com ([2002:a05:600d:2:b0:434:a7ab:5eea]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:c17:b0:438:a290:3ce0 with SMTP id 5b1f17b1804b1-438dc3be2efmr142365605e9.8.1738430503789; Sat, 01 Feb 2025 09:21:43 -0800 (PST) Date: Sat, 1 Feb 2025 18:21:35 +0100 In-Reply-To: <20250201172133.3592112-4-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20250201172133.3592112-4-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=4536; i=ardb@kernel.org; h=from:subject; bh=sIXXXHX/WANPcyo/QtzvHZEcmMFcszZ6NY8ZNAqvLco=; b=owGbwMvMwCFmkMcZplerG8N4Wi2JIX1ehILt1oaPSlPdDVk12a/7nBCrzZdSmPytp37mgcXZq UIddhYdpSwMYhwMsmKKLAKz/77beXqiVK3zLFmYOaxMIEMYuDgFYCJNGxn+5xpsvem/oGOpWIha 86SHIv1WNTmdK2IOXzsT16vjlFPqx8gwoblTSD52xq3Dpts+20xWMHx3vuJ3Iv+/9L4rEsscYiO 4AA== X-Mailer: git-send-email 2.48.1.362.g079036d154-goog Message-ID: <20250201172133.3592112-5-ardb+git@google.com> Subject: [PATCH 1/2] efi: Avoid cold plugged memory for placing the kernel From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel , stable@vger.kernel.org Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel UEFI 2.11 introduced EFI_MEMORY_HOT_PLUGGABLE to annotate system memory regions that are 'cold plugged' at boot, i.e., hot pluggable memory that is available from early boot, and described as system RAM by the firmware. Existing loaders and EFI applications running in the boot context will happily use this memory for allocating data structures that cannot be freed or moved at runtime, and this prevents the memory from being unplugged. Going forward, the new EFI_MEMORY_HOT_PLUGGABLE attribute should be tested, and memory annotated as such should be avoided for such allocations. In the EFI stub, there are a couple of occurrences where, instead of the high-level AllocatePages() UEFI boot service, a low-level code sequence is used that traverses the EFI memory map and carves out the requested number of pages from a free region. This is needed, e.g., for allocating as low as possible, or for allocating pages at random. While AllocatePages() should presumably avoid special purpose memory and cold plugged regions, this manual approach needs to incorporate this logic itself, in order to prevent the kernel itself from ending up in a hot unpluggable region, preventing it from being unplugged. So add the EFI_MEMORY_HOTPLUGGABLE macro definition, and check for it where appropriate. Cc: Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/efi.c | 6 ++++-- drivers/firmware/efi/libstub/randomalloc.c | 3 +++ drivers/firmware/efi/libstub/relocate.c | 3 +++ include/linux/efi.h | 1 + 4 files changed, 11 insertions(+), 2 deletions(-) diff --git a/drivers/firmware/efi/efi.c b/drivers/firmware/efi/efi.c index 8296bf985d1d..7309394b8fc9 100644 --- a/drivers/firmware/efi/efi.c +++ b/drivers/firmware/efi/efi.c @@ -934,13 +934,15 @@ char * __init efi_md_typeattr_format(char *buf, size_= t size, EFI_MEMORY_WB | EFI_MEMORY_UCE | EFI_MEMORY_RO | EFI_MEMORY_WP | EFI_MEMORY_RP | EFI_MEMORY_XP | EFI_MEMORY_NV | EFI_MEMORY_SP | EFI_MEMORY_CPU_CRYPTO | - EFI_MEMORY_RUNTIME | EFI_MEMORY_MORE_RELIABLE)) + EFI_MEMORY_MORE_RELIABLE | EFI_MEMORY_HOT_PLUGGABLE | + EFI_MEMORY_RUNTIME)) snprintf(pos, size, "|attr=3D0x%016llx]", (unsigned long long)attr); else snprintf(pos, size, - "|%3s|%2s|%2s|%2s|%2s|%2s|%2s|%2s|%2s|%3s|%2s|%2s|%2s|%2s]", + "|%3s|%2s|%2s|%2s|%2s|%2s|%2s|%2s|%2s|%2s|%3s|%2s|%2s|%2s|%2s]", attr & EFI_MEMORY_RUNTIME ? "RUN" : "", + attr & EFI_MEMORY_HOT_PLUGGABLE ? "HP" : "", attr & EFI_MEMORY_MORE_RELIABLE ? "MR" : "", attr & EFI_MEMORY_CPU_CRYPTO ? "CC" : "", attr & EFI_MEMORY_SP ? "SP" : "", diff --git a/drivers/firmware/efi/libstub/randomalloc.c b/drivers/firmware/= efi/libstub/randomalloc.c index e5872e38d9a4..5a732018be36 100644 --- a/drivers/firmware/efi/libstub/randomalloc.c +++ b/drivers/firmware/efi/libstub/randomalloc.c @@ -25,6 +25,9 @@ static unsigned long get_entry_num_slots(efi_memory_desc_= t *md, if (md->type !=3D EFI_CONVENTIONAL_MEMORY) return 0; =20 + if (md->attribute & EFI_MEMORY_HOT_PLUGGABLE) + return 0; + if (efi_soft_reserve_enabled() && (md->attribute & EFI_MEMORY_SP)) return 0; diff --git a/drivers/firmware/efi/libstub/relocate.c b/drivers/firmware/efi= /libstub/relocate.c index 99b45d1cd624..d4264bfb6dc1 100644 --- a/drivers/firmware/efi/libstub/relocate.c +++ b/drivers/firmware/efi/libstub/relocate.c @@ -53,6 +53,9 @@ efi_status_t efi_low_alloc_above(unsigned long size, unsi= gned long align, if (desc->type !=3D EFI_CONVENTIONAL_MEMORY) continue; =20 + if (desc->attribute & EFI_MEMORY_HOT_PLUGGABLE) + continue; + if (efi_soft_reserve_enabled() && (desc->attribute & EFI_MEMORY_SP)) continue; diff --git a/include/linux/efi.h b/include/linux/efi.h index 053c57e61869..db293d7de686 100644 --- a/include/linux/efi.h +++ b/include/linux/efi.h @@ -128,6 +128,7 @@ typedef struct { #define EFI_MEMORY_RO ((u64)0x0000000000020000ULL) /* read-only */ #define EFI_MEMORY_SP ((u64)0x0000000000040000ULL) /* soft reserved */ #define EFI_MEMORY_CPU_CRYPTO ((u64)0x0000000000080000ULL) /* supports enc= ryption */ +#define EFI_MEMORY_HOT_PLUGGABLE BIT_ULL(20) /* supports unplugging at run= time */ #define EFI_MEMORY_RUNTIME ((u64)0x8000000000000000ULL) /* range requires = runtime mapping */ #define EFI_MEMORY_DESCRIPTOR_VERSION 1 =20 --=20 2.48.1.362.g079036d154-goog From nobody Mon Feb 9 05:53:24 2026 Received: from mail-wm1-f74.google.com (mail-wm1-f74.google.com [209.85.128.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 375841CAA86 for ; Sat, 1 Feb 2025 17:21:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.74 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1738430508; cv=none; b=RLXrhvJXAKV0hpScrX9qbSs2lKMRuOUe8Nyen+uSpJ2FEP0Gyt235xoK00Xk2CGnHRpqFSwwyQCdbrmbcCG38RivwohyeHUoM5+F2uW0uoTuvv6ESFiDWEIba4myrR/iE5lKfhPPcXBP1S4SyDB36GyzBb1jNIQr0fxUnb7f5qA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1738430508; c=relaxed/simple; bh=w2yE63sC9zTFdtn+p5RI02eYUbqFYisRzY88vTigVQ8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=DgnJbC3PHRLTwKEDTqE13ALhyGWm35bVfwsvx6S4TcuXKxQXirseEKCfZiwgi/E01TQXVENpOq4IgtBdzsYNok7NIDHWGFOp8fHssR8AoBhEvmZ85tSL+WRX21/CasU3UPZR+ZbGpZmFQNANWsipFDzVm2AMY9A7pvODULajmpg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=3HnG7SsI; arc=none smtp.client-ip=209.85.128.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ardb.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="3HnG7SsI" Received: by mail-wm1-f74.google.com with SMTP id 5b1f17b1804b1-4362552ce62so14482255e9.0 for ; Sat, 01 Feb 2025 09:21:46 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1738430505; x=1739035305; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=QKhrV4FS3BfHHv6JJTxTRxWjSBLuqt9pDuTg8aZsHJY=; b=3HnG7SsIWIsRo9+jKmIuReiOuRYnWgQ/WuSOsUMI8DqP/TpCPKxzohpo8fBFFcZZlp lTYg9cgvDofn6mC2W0nD39vGBKqqPIKa+hS1qAyjoQg27X47JmAp3aJtvGsqoZf7vrE4 gnyrUMmxZjCzl9WD8ntjiaMpLJHpCtnXYySmOrqJTa2SXqvFNd9u2z1Lp+SS4wI+2sUo 6jvsR1fyYcR0jUnFLANH+DKxPfdYDU4agbKderV/qiNtnkGSl/ldJGVHGWV5bmw9VkQA sKu2VNVYJwGpp65v4vXNBVrBjP9y94toBDtznzYOAyQYoULzJmlC9cmEzRNZHo9T5WVk uewQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1738430505; x=1739035305; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=QKhrV4FS3BfHHv6JJTxTRxWjSBLuqt9pDuTg8aZsHJY=; b=bIM8a8Nc30fUvi008nokuRByoNFNC35chLs2SiKhtuu9hJj4njG+y2o9irjl/nt8jx NZu1IAaRxaDMf2eDPe4lge0Xgd9lbTqDCUpQPNDj4LmfD46U9jF8DoHDoopwGMg2TQP5 MoTs8L6T04kJ9kdpbIieMNSl23titiU4ZAFwIbx0PSHrqlSS4BQtGFnTP5lAEJByA1uQ A+BevkVVHeP5rHaT7Rj66orEc8BwyWDK7ykrudxqP5RlRPKP3Mj2d2pexr0wqoy1dygc l5fEvz4i0wy+W/vt2ubZE+GdE3wdzeaNpnO/3bDh7NSpwv/C90A4W25RTWn/U+Hl7TCI gIIQ== X-Gm-Message-State: AOJu0YzR2Cx6/+shpihUuUwFTSU4maOMMPEBDKb4ZFwFFKUhh5w9DqXq OyLaflcrKP4e1lDnPjnXePJFAQL9ehMLBUoc+1ON1sF+mTIE9YB3/oRIT7ISn+26FCrw5w== X-Google-Smtp-Source: AGHT+IGl49RmvVvO8Sge+Xfhu5Xb697EHYs3pjwLnJJB9vvdkzBIhC9IKEmbhFm4+dhHZDqj4Kiz8Dwm X-Received: from wmqa17.prod.google.com ([2002:a05:600c:3491:b0:436:1796:9989]) (user=ardb job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:5119:b0:434:f917:2b11 with SMTP id 5b1f17b1804b1-438dc40bd8dmr126035295e9.21.1738430505708; Sat, 01 Feb 2025 09:21:45 -0800 (PST) Date: Sat, 1 Feb 2025 18:21:36 +0100 In-Reply-To: <20250201172133.3592112-4-ardb+git@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20250201172133.3592112-4-ardb+git@google.com> X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-Developer-Signature: v=1; a=openpgp-sha256; l=2648; i=ardb@kernel.org; h=from:subject; bh=ATsogwx9msMMPfBwlwd/1Ve/e6sf91DL+ruiHYM3nIk=; b=owGbwMvMwCFmkMcZplerG8N4Wi2JIX1ehGLFp8w1E/O2M52LujTDf2ON7vl3m2dttKjJlwn02 d1yVqG0o5SFQYyDQVZMkUVg9t93O09PlKp1niULM4eVCWQIAxenAEzk1BmGX0yi+V2zeVdcW1pn POuBeZbQ9k0dkmuWu0/JPtydySNcycvI8FeLOW1XONMtU9eGKStmzDVp+Vn7eOeHYC/mdq0uqQe HWAE= X-Mailer: git-send-email 2.48.1.362.g079036d154-goog Message-ID: <20250201172133.3592112-6-ardb+git@google.com> Subject: [PATCH 2/2] efi: Use BIT_ULL() constants for memory attributes From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-kernel@vger.kernel.org, Ard Biesheuvel Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Ard Biesheuvel For legibility, use the existing BIT_ULL() to generate the u64 type EFI memory attribute macros. Signed-off-by: Ard Biesheuvel --- include/linux/efi.h | 30 ++++++++++---------- 1 file changed, 15 insertions(+), 15 deletions(-) diff --git a/include/linux/efi.h b/include/linux/efi.h index db293d7de686..7d63d1d75f22 100644 --- a/include/linux/efi.h +++ b/include/linux/efi.h @@ -114,22 +114,22 @@ typedef struct { #define EFI_MAX_MEMORY_TYPE 16 =20 /* Attribute values: */ -#define EFI_MEMORY_UC ((u64)0x0000000000000001ULL) /* uncached */ -#define EFI_MEMORY_WC ((u64)0x0000000000000002ULL) /* write-coalescing */ -#define EFI_MEMORY_WT ((u64)0x0000000000000004ULL) /* write-through */ -#define EFI_MEMORY_WB ((u64)0x0000000000000008ULL) /* write-back */ -#define EFI_MEMORY_UCE ((u64)0x0000000000000010ULL) /* uncached, exported= */ -#define EFI_MEMORY_WP ((u64)0x0000000000001000ULL) /* write-protect */ -#define EFI_MEMORY_RP ((u64)0x0000000000002000ULL) /* read-protect */ -#define EFI_MEMORY_XP ((u64)0x0000000000004000ULL) /* execute-protect */ -#define EFI_MEMORY_NV ((u64)0x0000000000008000ULL) /* non-volatile */ -#define EFI_MEMORY_MORE_RELIABLE \ - ((u64)0x0000000000010000ULL) /* higher reliability */ -#define EFI_MEMORY_RO ((u64)0x0000000000020000ULL) /* read-only */ -#define EFI_MEMORY_SP ((u64)0x0000000000040000ULL) /* soft reserved */ -#define EFI_MEMORY_CPU_CRYPTO ((u64)0x0000000000080000ULL) /* supports enc= ryption */ +#define EFI_MEMORY_UC BIT_ULL(0) /* uncached */ +#define EFI_MEMORY_WC BIT_ULL(1) /* write-coalescing */ +#define EFI_MEMORY_WT BIT_ULL(2) /* write-through */ +#define EFI_MEMORY_WB BIT_ULL(3) /* write-back */ +#define EFI_MEMORY_UCE BIT_ULL(4) /* uncached, exported */ +#define EFI_MEMORY_WP BIT_ULL(12) /* write-protect */ +#define EFI_MEMORY_RP BIT_ULL(13) /* read-protect */ +#define EFI_MEMORY_XP BIT_ULL(14) /* execute-protect */ +#define EFI_MEMORY_NV BIT_ULL(15) /* non-volatile */ +#define EFI_MEMORY_MORE_RELIABLE BIT_ULL(16) /* higher reliability */ +#define EFI_MEMORY_RO BIT_ULL(17) /* read-only */ +#define EFI_MEMORY_SP BIT_ULL(18) /* soft reserved */ +#define EFI_MEMORY_CPU_CRYPTO BIT_ULL(19) /* supports encryption */ #define EFI_MEMORY_HOT_PLUGGABLE BIT_ULL(20) /* supports unplugging at run= time */ -#define EFI_MEMORY_RUNTIME ((u64)0x8000000000000000ULL) /* range requires = runtime mapping */ +#define EFI_MEMORY_RUNTIME BIT_ULL(63) /* range requires runtime mapping = */ + #define EFI_MEMORY_DESCRIPTOR_VERSION 1 =20 #define EFI_PAGE_SHIFT 12 --=20 2.48.1.362.g079036d154-goog