From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mx1.redhat.com (mx1.redhat.com [209.132.183.28]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ml01.01.org (Postfix) with ESMTPS id 57D4681EC8 for ; Thu, 17 Nov 2016 07:59:58 -0800 (PST) Received: from int-mx14.intmail.prod.int.phx2.redhat.com (int-mx14.intmail.prod.int.phx2.redhat.com [10.5.11.27]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 250341ACD15; Thu, 17 Nov 2016 16:00:03 +0000 (UTC) Received: from lacos-laptop-7.usersys.redhat.com (ovpn-116-6.phx2.redhat.com [10.3.116.6]) by int-mx14.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id uAHG015s015779; Thu, 17 Nov 2016 11:00:02 -0500 To: Jiewen Yao , edk2-devel@ml01.01.org References: <1479390021-5976-1-git-send-email-jiewen.yao@intel.com> Cc: Jordan Justen From: Laszlo Ersek Message-ID: <69059775-21b0-29f5-90d5-3a890d2526fb@redhat.com> Date: Thu, 17 Nov 2016 17:00:01 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.4.0 MIME-Version: 1.0 In-Reply-To: <1479390021-5976-1-git-send-email-jiewen.yao@intel.com> X-Scanned-By: MIMEDefang 2.68 on 10.5.11.27 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.39]); Thu, 17 Nov 2016 16:00:03 +0000 (UTC) Subject: Re: [PATCH V2] Add 4K PE alignment to enable SMM page level protection. X-BeenThere: edk2-devel@lists.01.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: EDK II Development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 17 Nov 2016 15:59:58 -0000 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit On 11/17/16 14:40, Jiewen Yao wrote: > Tested boot with below configuration: > IA32 > IA32X64 > X64 > > Tested boot with XD enabled/disabled. > > Requested-by: Laszlo Ersek > Cc: Jordan Justen > Cc: Laszlo Ersek > Contributed-under: TianoCore Contribution Agreement 1.0 > Signed-off-by: Jiewen Yao > --- > OvmfPkg/OvmfPkgIa32.dsc | 5 +++++ > OvmfPkg/OvmfPkgIa32X64.dsc | 5 +++++ > OvmfPkg/OvmfPkgX64.dsc | 5 +++++ > 3 files changed, 15 insertions(+) I have two requests before you commit the patch: (1) please prefix the subject line with "OvmfPkg: ", (2) please commit this patch only after you commit the patch "UefiCpuPkg/PiSmmCpu: Check XdSupport before set NX." Please do not forget these requests. Tested-by: Laszlo Ersek Reviewed-by: Laszlo Ersek Thank you, Laszlo > diff --git a/OvmfPkg/OvmfPkgIa32.dsc b/OvmfPkg/OvmfPkgIa32.dsc > index 3f4d42d..ed43c45 100644 > --- a/OvmfPkg/OvmfPkgIa32.dsc > +++ b/OvmfPkg/OvmfPkgIa32.dsc > @@ -56,6 +56,11 @@ > [BuildOptions.common.EDKII.DXE_RUNTIME_DRIVER] > GCC:*_*_*_DLINK_FLAGS = -z common-page-size=0x1000 > > +# Force PE/COFF sections to be aligned at 4KB boundaries to support page level > +# protection of DXE_SMM_DRIVER/SMM_CORE modules > +[BuildOptions.common.EDKII.DXE_SMM_DRIVER, BuildOptions.common.EDKII.SMM_CORE] > + GCC:*_*_*_DLINK_FLAGS = -z common-page-size=0x1000 > + > ################################################################################ > # > # SKU Identification section - list of all SKU IDs supported by this Platform. > diff --git a/OvmfPkg/OvmfPkgIa32X64.dsc b/OvmfPkg/OvmfPkgIa32X64.dsc > index 5688475..ccd156d 100644 > --- a/OvmfPkg/OvmfPkgIa32X64.dsc > +++ b/OvmfPkg/OvmfPkgIa32X64.dsc > @@ -61,6 +61,11 @@ > [BuildOptions.common.EDKII.DXE_RUNTIME_DRIVER] > GCC:*_*_*_DLINK_FLAGS = -z common-page-size=0x1000 > > +# Force PE/COFF sections to be aligned at 4KB boundaries to support page level > +# protection of DXE_SMM_DRIVER/SMM_CORE modules > +[BuildOptions.common.EDKII.DXE_SMM_DRIVER, BuildOptions.common.EDKII.SMM_CORE] > + GCC:*_*_*_DLINK_FLAGS = -z common-page-size=0x1000 > + > ################################################################################ > # > # SKU Identification section - list of all SKU IDs supported by this Platform. > diff --git a/OvmfPkg/OvmfPkgX64.dsc b/OvmfPkg/OvmfPkgX64.dsc > index dcf64b9..012ce85 100644 > --- a/OvmfPkg/OvmfPkgX64.dsc > +++ b/OvmfPkg/OvmfPkgX64.dsc > @@ -61,6 +61,11 @@ > [BuildOptions.common.EDKII.DXE_RUNTIME_DRIVER] > GCC:*_*_*_DLINK_FLAGS = -z common-page-size=0x1000 > > +# Force PE/COFF sections to be aligned at 4KB boundaries to support page level > +# protection of DXE_SMM_DRIVER/SMM_CORE modules > +[BuildOptions.common.EDKII.DXE_SMM_DRIVER, BuildOptions.common.EDKII.SMM_CORE] > + GCC:*_*_*_DLINK_FLAGS = -z common-page-size=0x1000 > + > ################################################################################ > # > # SKU Identification section - list of all SKU IDs supported by this Platform. >