From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.1 required=3.0 tests=DKIMWL_WL_HIGH,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS, USER_AGENT_GIT autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 22B78C2D0C6 for ; Fri, 27 Dec 2019 16:34:15 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id E9FFF21775 for ; Fri, 27 Dec 2019 16:34:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1577464455; bh=sTA+SCCcCVyN0cayyjtEmIQOaDiD+MCeqJ+oW6iy5bQ=; h=From:To:Cc:Subject:Date:List-ID:From; b=1HXjTrXTGZAtTNum+Qo1kG2p0H9HHujjITk23B2nQIZp9GtjmM31ERYZ4WfUPOHnh 4esiQzM9eBeSWnacCUWBem1YPqdBG04CDHZ/1aTLBwLpIyDlHHhtBaKiPq3aA9wflG sM3px05mTgIRjzoCuPHrZUyXJ58zUqNXvrwI+i1k= Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726562AbfL0QeO (ORCPT ); Fri, 27 Dec 2019 11:34:14 -0500 Received: from mail.kernel.org ([198.145.29.99]:46518 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726379AbfL0QeO (ORCPT ); Fri, 27 Dec 2019 11:34:14 -0500 Received: from e123331-lin.home (amontpellier-657-1-18-247.w109-210.abo.wanadoo.fr [109.210.65.247]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 272B120CC7; Fri, 27 Dec 2019 16:34:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1577464453; bh=sTA+SCCcCVyN0cayyjtEmIQOaDiD+MCeqJ+oW6iy5bQ=; h=From:To:Cc:Subject:Date:From; b=MFI0fbKYjSJGP/o6cub+0qyMcH17A+gU8kADJiDxaR82U8C6nDYZaTYoPTle9D8wl BmgmdBEVPNp2LjL+WNdyh5x3DFj46jW7EjRDpqAnpqGYoCRIWcs0cJCIbXTKNw2ML3 FnKKkga+7tXQD8xeEhsi/uOgbitgjabv+hH3zhAQ= From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: nivedita@alum.mit.edu, hdegoede@redhat.com, Ard Biesheuvel , Andy Lutomirski , Ingo Molnar Subject: [PATCH 0/3] efi/x86: righten memory protections at runtime Date: Fri, 27 Dec 2019 17:34:15 +0100 Message-Id: <20191227163418.16139-1-ardb@kernel.org> X-Mailer: git-send-email 2.17.1 Sender: linux-efi-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-efi@vger.kernel.org For historical reasons, the EFI startup code uses R/W/X mappings for most memory regions that it maps, and in the mixed mode case, it even maps all of DRAM R/W/X in its 1:1 mapping. Let's tighten this a bit, and use the NX bit where possible, and ensure that at least the kernel text+rodata are not mapped RWX in the mixed mode case. Cc: Andy Lutomirski Cc: Ingo Molnar Ard Biesheuvel (3): x86/mm: fix NX bit clearing issue in kernel_map_pages_in_pgd efi/x86: don't map the entire kernel text RW for mixed mode efi/x86: avoid RWX mappings for all of DRAM arch/x86/mm/pageattr.c | 8 +------- arch/x86/platform/efi/efi_64.c | 21 ++++++++++++++------ 2 files changed, 16 insertions(+), 13 deletions(-) -- 2.17.1