From: "Ard Biesheuvel" <ardb@kernel.org>
To: devel@edk2.groups.io
Cc: Ard Biesheuvel <ardb@kernel.org>,
Michael Kinney <michael.d.kinney@intel.com>,
Liming Gao <gaoliming@byosoft.com.cn>,
Jiewen Yao <jiewen.yao@intel.com>,
Michael Kubacki <michael.kubacki@microsoft.com>,
Sean Brogan <sean.brogan@microsoft.com>,
Rebecca Cran <quic_rcran@quicinc.com>,
Leif Lindholm <quic_llindhol@quicinc.com>,
Sami Mujawar <sami.mujawar@arm.com>,
Taylor Beebe <t@taylorbeebe.com>
Subject: [PATCH v5 00/38] Implement strict memory permissions throughout
Date: Mon, 13 Mar 2023 18:16:36 +0100 [thread overview]
Message-ID: <20230313171714.3866151-1-ardb@kernel.org> (raw)
Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369
This v5 now covers a lot more ground, and has ballooned quite
substantially as a result. The series is essentially a proof of concept
of a way to implement rigorous W^X memory protections from SEC all the
way to booting the OS.
In particular:
- the AArch64 WXN control is enabled so that NX is implied for all
writable memory regions, which is rather helpful when testing changes
such as these;
- avoid PEIM shadowing where possible, as that would involve managing
the executable permissions of the shadowed code
- remap the DXE core code section read-only explicitly from IPL
- equip the DXE core with a way to manage memory permissions before the
CPU arch protocol driver is dispatched;
- permit the NX memory protection policy to apply to code memory type
regions as well
- check the NX compat DLL flag and section alignment to decide whether
an image can be loaded when the NX policy is applied to such a code
region
- implement the EFI memory attributes protocol (for ARM and AArch64
only) so that such NX compat compliant images have a way to create
executable mappings
v4:
- major cleanup of the 32-bit ARM code
- add support for EFI_MEMORY_RP using the access flag
- enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP)
- incorporate optimization from other series [0] to avoid splitting
block entries unnecessarily
v3:
- fix ARM32 bug in attribute conversion
- add Liming's ack to patch #1
- include draft patch (NOT FOR MERGE) used to test the changes
v2:
- drop patch to bump exposed UEFI revision to v2.10
- add missing permitted return values to protocol definition
[0] https://edk2.groups.io/g/devel/message/99801
Cc: Michael Kinney <michael.d.kinney@intel.com>
Cc: Liming Gao <gaoliming@byosoft.com.cn>
Cc: Jiewen Yao <jiewen.yao@intel.com>
Cc: Michael Kubacki <michael.kubacki@microsoft.com>
Cc: Sean Brogan <sean.brogan@microsoft.com>
Cc: Rebecca Cran <quic_rcran@quicinc.com>
Cc: Leif Lindholm <quic_llindhol@quicinc.com>
Cc: Sami Mujawar <sami.mujawar@arm.com>
Cc: Taylor Beebe <t@taylorbeebe.com>
Ard Biesheuvel (38):
ArmPkg/ArmMmuLib ARM: Remove half baked large page support
ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field
ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion
ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask
ArmPkg/ArmMmuLib ARM: Clear individual permission bits
ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag
ArmVirtPkg: Enable stack guard
ArmPkg/ArmMmuLib: Avoid splitting block entries if possible
ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion
MdePkg: Add Memory Attribute Protocol definition
ArmPkg/CpuDxe: Implement EFI memory attributes protocol
ArmPkg/CpuDxe: Perform preliminary NX remap of free memory
MdeModulePkg/DxeCore: Unconditionally set memory protections
ArmPkg/Mmu: Remove handling of NONSECURE memory regions
ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory
MdePkg/BasePeCoffLib: Add API to keep track of relocation range
MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default
MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch
MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time
MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback
ArmPkg: Implement ArmSetMemoryOverrideLib
MdeModulePkg/PcdPeim: Permit unshadowed execution
EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution
ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default
ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs
ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code
flash
BaseTools/GccBase AARCH64: Avoid page sharing between code and data
ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory
permissions
MdePkg/PeCoffLib: Capture DLL characteristics field in image context
MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics
MdeModulePkg/DxeCore: Remove redundant DEBUG statements
MdeModulePkg/DxeCore: Update memory protections before freeing a
region
MdeModulePkg/DxeCore: Disregard runtime alignment for image protection
MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage()
MdeModulePkg/DxeCore: Clear NX permissions on non-protected images
MdeModulePkg/DxeCore: Permit NX protection for code regions
MdeModulePkg/DxeCore: Check NX compat when using restricted code
regions
MdeModulePkg DEC: Remove inaccurate comment
ArmPkg/ArmPkg.dec | 5 +
ArmPkg/ArmPkg.dsc | 1 +
ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c | 25 +-
ArmPkg/Drivers/CpuDxe/Arm/Mmu.c | 96 +++++--
ArmPkg/Drivers/CpuDxe/CpuDxe.c | 87 ++++++
ArmPkg/Drivers/CpuDxe/CpuDxe.h | 17 ++
ArmPkg/Drivers/CpuDxe/CpuDxe.inf | 5 +
ArmPkg/Drivers/CpuDxe/MemoryAttribute.c | 271 ++++++++++++++++++
ArmPkg/Include/Chipset/ArmV7Mmu.h | 131 ++++-----
ArmPkg/Include/Library/ArmLib.h | 17 +-
ArmPkg/Include/Library/ArmMmuLib.h | 34 +++
ArmPkg/Library/ArmLib/Arm/ArmV7Support.S | 2 +
ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c | 103 ++++++-
ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c | 8 +-
ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c | 51 ++--
ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c | 173 ++++++++++--
ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c | 78 ++++++
ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf | 28 ++
ArmVirtPkg/ArmVirt.dsc.inc | 3 +
ArmVirtPkg/ArmVirtQemu.dsc | 11 +-
ArmVirtPkg/ArmVirtQemuKernel.dsc | 1 +
ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S | 2 +-
ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c | 4 +-
BaseTools/Scripts/GccBase.lds | 13 +-
EmbeddedPkg/Include/Library/PrePiLib.h | 16 --
EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c | 51 ++++
EmbeddedPkg/Library/PrePiLib/PrePi.h | 13 +
EmbeddedPkg/Library/PrePiLib/PrePiLib.c | 4 +
EmbeddedPkg/Library/PrePiLib/PrePiLib.inf | 12 +
EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c | 23 ++
MdeModulePkg/Core/Dxe/DxeMain.h | 6 +-
MdeModulePkg/Core/Dxe/Image/Image.c | 8 +-
MdeModulePkg/Core/Dxe/Mem/Page.c | 15 +-
MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c | 288 +++++++++++---------
MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c | 73 +++++
MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf | 6 +-
MdeModulePkg/Core/DxeIplPeim/DxeLoad.c | 24 +-
MdeModulePkg/MdeModulePkg.dec | 7 +-
MdeModulePkg/Universal/PCD/Pei/Pcd.c | 112 ++++----
MdeModulePkg/Universal/PCD/Pei/Pcd.inf | 1 +
MdePkg/Include/IndustryStandard/PeImage.h | 15 +
MdePkg/Include/Library/PeCoffLib.h | 27 ++
MdePkg/Include/Protocol/MemoryAttribute.h | 142 ++++++++++
MdePkg/Library/BasePeCoffLib/BasePeCoff.c | 105 ++++++-
MdePkg/MdePkg.dec | 3 +
45 files changed, 1682 insertions(+), 435 deletions(-)
create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c
create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c
create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf
create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c
create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c
create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h
--
2.39.2
next reply other threads:[~2023-03-13 17:17 UTC|newest]
Thread overview: 63+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-03-13 17:16 Ard Biesheuvel [this message]
2023-03-13 17:16 ` [PATCH v5 01/38] ArmPkg/ArmMmuLib ARM: Remove half baked large page support Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 02/38] ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field Ard Biesheuvel
2023-03-14 17:24 ` Leif Lindholm
2023-03-13 17:16 ` [PATCH v5 03/38] ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 04/38] ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask Ard Biesheuvel
2023-03-14 17:55 ` [edk2-devel] " Leif Lindholm
2023-03-13 17:16 ` [PATCH v5 05/38] ArmPkg/ArmMmuLib ARM: Clear individual permission bits Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 06/38] ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 07/38] ArmVirtPkg: Enable stack guard Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 08/38] ArmPkg/ArmMmuLib: Avoid splitting block entries if possible Ard Biesheuvel
2023-03-14 18:13 ` [edk2-devel] " Leif Lindholm
2023-03-14 18:29 ` Ard Biesheuvel
2023-03-15 18:02 ` Leif Lindholm
2023-03-13 17:16 ` [PATCH v5 09/38] ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion Ard Biesheuvel
2023-03-15 18:08 ` [edk2-devel] " Leif Lindholm
2023-03-13 17:16 ` [PATCH v5 10/38] MdePkg: Add Memory Attribute Protocol definition Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 11/38] ArmPkg/CpuDxe: Implement EFI memory attributes protocol Ard Biesheuvel
2023-03-15 18:31 ` Leif Lindholm
2023-03-16 7:19 ` [edk2-devel] " Ard Biesheuvel
2023-03-16 9:27 ` Ard Biesheuvel
2023-03-16 11:41 ` Leif Lindholm
2023-03-13 17:16 ` [PATCH v5 12/38] ArmPkg/CpuDxe: Perform preliminary NX remap of free memory Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 13/38] MdeModulePkg/DxeCore: Unconditionally set memory protections Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 14/38] ArmPkg/Mmu: Remove handling of NONSECURE memory regions Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 15/38] ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 16/38] MdePkg/BasePeCoffLib: Add API to keep track of relocation range Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 17/38] MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 18/38] MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch Ard Biesheuvel
2023-03-16 22:20 ` [edk2-devel] " osd
2023-03-13 17:16 ` [PATCH v5 19/38] MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 20/38] MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 21/38] ArmPkg: Implement ArmSetMemoryOverrideLib Ard Biesheuvel
2023-03-16 13:27 ` [edk2-devel] " Leif Lindholm
2023-03-16 14:20 ` Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 22/38] MdeModulePkg/PcdPeim: Permit unshadowed execution Ard Biesheuvel
2023-03-13 17:16 ` [PATCH v5 23/38] EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution Ard Biesheuvel
2023-03-16 13:33 ` Leif Lindholm
2023-03-16 13:50 ` [edk2-devel] " Ard Biesheuvel
2023-03-16 14:09 ` Leif Lindholm
2023-03-13 17:17 ` [PATCH v5 24/38] ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 25/38] ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 26/38] ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code flash Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 27/38] BaseTools/GccBase AARCH64: Avoid page sharing between code and data Ard Biesheuvel
2023-03-16 13:46 ` [edk2-devel] " Leif Lindholm
2023-03-16 14:30 ` Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 28/38] ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory permissions Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 29/38] MdePkg/PeCoffLib: Capture DLL characteristics field in image context Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 30/38] MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 31/38] MdeModulePkg/DxeCore: Remove redundant DEBUG statements Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 32/38] MdeModulePkg/DxeCore: Update memory protections before freeing a region Ard Biesheuvel
2023-03-16 13:51 ` Leif Lindholm
2023-03-16 14:00 ` [edk2-devel] " Ard Biesheuvel
2023-03-16 14:52 ` Leif Lindholm
2023-03-13 17:17 ` [PATCH v5 33/38] MdeModulePkg/DxeCore: Disregard runtime alignment for image protection Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 34/38] MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage() Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 35/38] MdeModulePkg/DxeCore: Clear NX permissions on non-protected images Ard Biesheuvel
2023-03-17 20:04 ` [edk2-devel] " Oliver Smith-Denny
2023-03-13 17:17 ` [PATCH v5 36/38] MdeModulePkg/DxeCore: Permit NX protection for code regions Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 37/38] MdeModulePkg/DxeCore: Check NX compat when using restricted " Ard Biesheuvel
2023-03-13 17:17 ` [PATCH v5 38/38] MdeModulePkg DEC: Remove inaccurate comment Ard Biesheuvel
2023-03-16 14:04 ` [edk2-devel] [PATCH v5 00/38] Implement strict memory permissions throughout Leif Lindholm
2023-03-17 21:41 ` Oliver Smith-Denny
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-list from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20230313171714.3866151-1-ardb@kernel.org \
--to=devel@edk2.groups.io \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox