From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 00DB9C433F5 for ; Fri, 4 Mar 2022 18:00:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-Id:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=qAyekjJ4lNtXP9NsxX5kLB7TplscEJZva2wE3k20cFU=; b=c9046K0dExlEP5 SMAFF0Bv5IPnx6jR/wrDJJrwpqV9AuB/sRoOdK8Dzp1wWVNY92FoaLKmUTgVf0MShPd966w+SY+Jj 0xKfwCqYyBONrsknuCya6X1KqpNEUJmIcnnoIw26O25Hj12qxqw4HtwE9EQ4Cx7tukwfPVm7nKr0L k9P++dj66Qw6UROukAUby33Ss/ljLDQvMWvKkOmqGYcK1pLIF5kycwO99GUwE6GWgEc8PwaiYm6on eOn/B9oqzFrl0tMi8ptBM4QiIemhNsGMfHNrMjsOhQ5Z26jZZ6d5YjhbbUixyoBx14rXQvfYUCTWB bPf+823Gv9+g4FZ+4SUw==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1nQCCr-00BTVP-4j; Fri, 04 Mar 2022 17:59:09 +0000 Received: from dfw.source.kernel.org ([2604:1380:4641:c500::1]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1nQCBb-00BSui-3Y for linux-arm-kernel@lists.infradead.org; Fri, 04 Mar 2022 17:57:52 +0000 Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id AC46C60BA2; Fri, 4 Mar 2022 17:57:50 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 295E8C36AE7; Fri, 4 Mar 2022 17:57:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1646416670; bh=thRPx6W255lc3aw89zELR0kqQnywEvVWsTrfjjtYIIk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=H2qqkOH5nrus++rtNmwtvMiBiV5CtWW1qjRpYy4br8SjYYR/nr8VUC5/C8auxrmY8 kBcEn711bupUj601Jw1m6lfH29goiEWEKLcidT1tYmDvEH+nP9MHEqeazhlb1mfi0w oqtiAhz/Uz6Mo9mPIguR0dqVpubJ/IpJNNsUZ4NSHP+7ayi+qIp8eUYY5F2nigSGX/ i+NUDYmR+dM5FXGu187NmnkMz3yz+yrIKxEkgRBlMKJqB7XDvuFUuwIaKzPljCfd6o OJeOWfOG4bw5xOaPRUVdBXinYthAB1TO9SL8l7pze+eTpKtWFfM//IzykmDr2lSBXI SsQcgUcOkqL2A== From: Ard Biesheuvel To: linux-arm-kernel@lists.infradead.org Cc: mark.rutland@arm.com, android-kvm@google.com, Ard Biesheuvel , Marc Zyngier , Will Deacon Subject: [RFC PATCH 8/8] arm64: efi: leave MMU and caches on when handing over to the core kernel Date: Fri, 4 Mar 2022 18:56:57 +0100 Message-Id: <20220304175657.2744400-9-ardb@kernel.org> X-Mailer: git-send-email 2.30.2 In-Reply-To: <20220304175657.2744400-1-ardb@kernel.org> References: <20220304175657.2744400-1-ardb@kernel.org> MIME-Version: 1.0 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20220304_095751_247710_454E8EA2 X-CRM114-Status: GOOD ( 14.29 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org Instead of cleaning the entire kernel image to the PoC and enter with the MMU and caches disabled, leave them on and let the primary boot code deal with this if we are executing at EL1. Signed-off-by: Ard Biesheuvel --- arch/arm64/kernel/efi-entry.S | 20 ++++++++++---------- drivers/firmware/efi/libstub/fdt.c | 6 ++++-- 2 files changed, 14 insertions(+), 12 deletions(-) diff --git a/arch/arm64/kernel/efi-entry.S b/arch/arm64/kernel/efi-entry.S index 61a87fa1c305..7eca829869b4 100644 --- a/arch/arm64/kernel/efi-entry.S +++ b/arch/arm64/kernel/efi-entry.S @@ -23,6 +23,10 @@ SYM_CODE_START(efi_enter_kernel) add x19, x0, x2 // relocated Image entrypoint mov x20, x1 // DTB address + mrs x0, CurrentEL + cmp x0, #CurrentEL_EL2 + b.ne 1f + /* * Clean the copied Image to the PoC, and ensure it is not shadowed by * stale icache entries from before relocation. @@ -41,29 +45,25 @@ SYM_CODE_START(efi_enter_kernel) bl dcache_clean_poc 0: /* Turn off Dcache and MMU */ - mrs x0, CurrentEL - cmp x0, #CurrentEL_EL2 - b.ne 1f mrs x0, sctlr_el2 bic x0, x0, #1 << 0 // clear SCTLR.M bic x0, x0, #1 << 2 // clear SCTLR.C pre_disable_mmu_workaround msr sctlr_el2, x0 isb + mov x1, xzr b 2f 1: - mrs x0, sctlr_el1 - bic x0, x0, #1 << 0 // clear SCTLR.M - bic x0, x0, #1 << 2 // clear SCTLR.C - pre_disable_mmu_workaround - msr sctlr_el1, x0 - isb + ldr_l x1, kaslr_seed 2: /* Jump to kernel entry point */ mov x0, x20 - mov x1, xzr mov x2, xzr mov x3, xzr br x19 3: SYM_CODE_END(efi_enter_kernel) + + .section ".bss", "aw", %nobits + .align 3 +SYM_DATA(kaslr_seed, .quad 0x0) diff --git a/drivers/firmware/efi/libstub/fdt.c b/drivers/firmware/efi/libstub/fdt.c index fe567be0f118..ec34c29d311d 100644 --- a/drivers/firmware/efi/libstub/fdt.c +++ b/drivers/firmware/efi/libstub/fdt.c @@ -137,11 +137,13 @@ static efi_status_t update_fdt(void *orig_fdt, unsigned long orig_fdt_size, goto fdt_set_fail; if (IS_ENABLED(CONFIG_RANDOMIZE_BASE) && !efi_nokaslr) { + extern u64 kaslr_seed; efi_status_t efi_status; - efi_status = efi_get_random_bytes(sizeof(fdt_val64), - (u8 *)&fdt_val64); + efi_status = efi_get_random_bytes(sizeof(kaslr_seed), + (u8 *)&kaslr_seed); if (efi_status == EFI_SUCCESS) { + fdt_val64 = cpu_to_fdt64(kaslr_seed); status = fdt_setprop_var(fdt, node, "kaslr-seed", fdt_val64); if (status) goto fdt_set_fail; -- 2.30.2 _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel