Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Kevin Brodsky <kevin.brodsky@arm.com>
To: linux-hardening@vger.kernel.org
Cc: "Kevin Brodsky" <kevin.brodsky@arm.com>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"Andy Lutomirski" <luto@kernel.org>,
	"Catalin Marinas" <catalin.marinas@arm.com>,
	"Dave Hansen" <dave.hansen@linux.intel.com>,
	"David Hildenbrand (Arm)" <david@kernel.org>,
	"Jann Horn" <jannh@google.com>, "Jeff Xu" <jeffxu@chromium.org>,
	"Joey Gouly" <joey.gouly@arm.com>, "Kees Cook" <kees@kernel.org>,
	"Linu Cherian" <linu.cherian@arm.com>,
	"Linus Walleij" <linusw@kernel.org>,
	"Marc Zyngier" <maz@kernel.org>,
	"Mark Brown" <broonie@kernel.org>,
	"Matthew Wilcox" <willy@infradead.org>,
	"Maxwell Bland" <mbland@motorola.com>,
	"Mike Rapoport (IBM)" <rppt@kernel.org>,
	"Peter Zijlstra" <peterz@infradead.org>,
	"Pierre Langlois" <pierre.langlois@arm.com>,
	"Pierre-Clément Tosi" <ptosi@google.com>,
	"Quentin Perret" <qperret@google.com>,
	"Rick Edgecombe" <rick.p.edgecombe@intel.com>,
	"Ryan Roberts" <ryan.roberts@arm.com>,
	"Vlastimil Babka" <vbabka@kernel.org>,
	"Will Deacon" <will@kernel.org>,
	"Yang Shi" <yang@os.amperecomputing.com>,
	"Yeoreum Yun" <yeoreum.yun@arm.com>,
	linux-arm-kernel@lists.infradead.org, linux-mm@kvack.org,
	x86@kernel.org, "Ira Weiny" <iweiny@kernel.org>,
	"Lorenzo Stoakes" <ljs@kernel.org>,
	"Thomas Gleixner" <tglx@kernel.org>
Subject: [PATCH RFC v9 05/25] arm64: Implement asm/kpkeys.h using POE
Date: Tue, 18 Aug 2026 15:08:47 +0100	[thread overview]
Message-ID: <20260818-kpkeys-v9-5-743ad31b2c8f@arm.com> (raw)
In-Reply-To: <20260818-kpkeys-v9-0-743ad31b2c8f@arm.com>

Implement the kpkeys interface if CONFIG_ARM64_POE is enabled.
The permissions for pkey 0 are set to RWX as this pkey is also used
for code mappings. POR_EL1 is left untouched if we have already
entered the requested context.

To allow <asm/kpkeys.h> to be included from assembly, also add
appropriate #ifdef's to <asm/por.h>.

Signed-off-by: Kevin Brodsky <kevin.brodsky@arm.com>
---
 arch/arm64/include/asm/kpkeys.h       | 67 +++++++++++++++++++++++++++++++++++
 arch/arm64/include/asm/kpkeys_types.h | 15 ++++++++
 arch/arm64/include/asm/por.h          |  4 +++
 3 files changed, 86 insertions(+)

diff --git a/arch/arm64/include/asm/kpkeys.h b/arch/arm64/include/asm/kpkeys.h
new file mode 100644
index 000000000000..09fd5a849cb0
--- /dev/null
+++ b/arch/arm64/include/asm/kpkeys.h
@@ -0,0 +1,67 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+#ifndef __ASM_KPKEYS_H
+#define __ASM_KPKEYS_H
+
+#include <linux/kpkeys_types.h>
+
+#include <asm/barrier.h>
+#include <asm/cpufeature.h>
+#include <asm/por.h>
+
+/*
+ * Equivalent to por_set_kpkeys_context(0, KPKEYS_CTX_DEFAULT), but can also be
+ * used in assembly.
+ */
+#define POR_EL1_INIT	POR_ELx_PERM_PREP(0, POE_RWX)
+
+#ifndef __ASSEMBLY__
+
+static inline bool arch_supports_kpkeys(void)
+{
+	return system_supports_poe();
+}
+
+#ifdef CONFIG_ARM64_POE
+
+static inline u64 por_set_kpkeys_context(u64 por, enum kpkeys_ctx ctx)
+{
+	por = por_elx_set_pkey_perms(por, 0, POE_RWX);
+
+	return por;
+}
+
+static __always_inline void __kpkeys_set_pkey_reg_nosync(u64 pkey_reg)
+{
+	write_sysreg_s(pkey_reg, SYS_POR_EL1);
+}
+
+static __always_inline
+struct kpkeys_state arch_kpkeys_enter_context(enum kpkeys_ctx ctx)
+{
+	const u64 prev_por = read_sysreg_s(SYS_POR_EL1);
+	const u64 new_por = por_set_kpkeys_context(prev_por, ctx);
+
+	if (prev_por == new_por)
+		return (struct kpkeys_state) { .entered_context = false };
+
+	__kpkeys_set_pkey_reg_nosync(new_por);
+	isb();
+
+	return (struct kpkeys_state) {
+		.entered_context = true,
+		.arch_state.por = prev_por,
+	};
+}
+
+static __always_inline
+void arch_kpkeys_leave_context(const struct kpkeys_state *state)
+{
+	__kpkeys_set_pkey_reg_nosync(state->arch_state.por);
+	isb();
+}
+
+#endif /* CONFIG_ARM64_POE */
+
+#endif	/* __ASSEMBLY__ */
+
+#endif	/* __ASM_KPKEYS_H */
diff --git a/arch/arm64/include/asm/kpkeys_types.h b/arch/arm64/include/asm/kpkeys_types.h
new file mode 100644
index 000000000000..e9c59a26ee7a
--- /dev/null
+++ b/arch/arm64/include/asm/kpkeys_types.h
@@ -0,0 +1,15 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+#ifndef __ASM_KPKEYS_TYPES_H
+#define __ASM_KPKEYS_TYPES_H
+
+#include <linux/types.h>
+
+#ifndef __ASSEMBLY__
+
+struct arch_kpkeys_state {
+	u64 por;
+};
+
+#endif	/* __ASSEMBLY__ */
+
+#endif	/* __ASM_KPKEYS_TYPES_H */
diff --git a/arch/arm64/include/asm/por.h b/arch/arm64/include/asm/por.h
index 19b3dd1d43a0..dddabf6ffae6 100644
--- a/arch/arm64/include/asm/por.h
+++ b/arch/arm64/include/asm/por.h
@@ -10,6 +10,8 @@
 
 #define POR_EL0_INIT	POR_ELx_PERM_PREP(0, POE_RWX)
 
+#ifndef __ASSEMBLY__
+
 static inline bool por_elx_allows_read(u64 por, u8 pkey)
 {
 	u8 perm = POR_ELx_PERM_GET(pkey, por);
@@ -38,4 +40,6 @@ static inline u64 por_elx_set_pkey_perms(u64 por, u8 pkey, u8 perms)
 	return (por & ~(POE_MASK << shift)) | ((u64)perms << shift);
 }
 
+#endif	/* __ASSEMBLY__ */
+
 #endif /* _ASM_ARM64_POR_H */

-- 
2.51.2



  parent reply	other threads:[~2026-08-18 14:12 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-18 14:08 [PATCH RFC v9 00/25] pkeys-based page table hardening Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 01/25] mm: Introduce kpkeys Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 02/25] set_memory: Introduce set_memory_pkey() stub Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 03/25] arm64: mm: Enable overlays for all EL1 indirect permissions Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 04/25] arm64: Introduce por_elx_set_pkey_perms() helper Kevin Brodsky
2026-08-18 14:08 ` Kevin Brodsky [this message]
2026-08-18 14:08 ` [PATCH RFC v9 06/25] arm64: set_memory: Implement set_memory_pkey() Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 07/25] arm64: Context-switch POR_EL1 Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 08/25] arm64: Initialize POR_EL1 register on cpu_resume() Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 09/25] arm64: Enable kpkeys Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 10/25] memblock: Move INIT_MEMBLOCK_* macros to header Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 11/25] mm: kpkeys: Introduce kpkeys_hardened_pgtables feature Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 12/25] mm: kpkeys: Protect regular page tables Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 13/25] mm: kpkeys: Introduce early page table allocator Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 14/25] mm: kpkeys: Protect vmemmap page tables Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 15/25] mm: kpkeys: Introduce hook for protecting static " Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 16/25] arm64: kpkeys: Implement arch_supports_kpkeys_early() Kevin Brodsky
2026-08-18 14:08 ` [PATCH RFC v9 17/25] arm64: kpkeys: Support KPKEYS_CTX_PGTABLES Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 18/25] arm64: kpkeys: Ensure the linear map can be modified Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 19/25] arm64: kpkeys: Protect early page tables Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 20/25] arm64: mm: Map kernel image alias of init_pg_dir read-only Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 21/25] arm64: kpkeys: Protect init_pg_dir Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 22/25] arm64: kpkeys: Guard page table writes Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 23/25] arm64: kpkeys: Batch KPKEYS_CTX_PGTABLES switches Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 24/25] arm64: kpkeys: Enable kpkeys_hardened_pgtables support Kevin Brodsky
2026-08-18 14:09 ` [PATCH RFC v9 25/25] mm: Add basic tests for kpkeys_hardened_pgtables Kevin Brodsky

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260818-kpkeys-v9-5-743ad31b2c8f@arm.com \
    --to=kevin.brodsky@arm.com \
    --cc=akpm@linux-foundation.org \
    --cc=broonie@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=david@kernel.org \
    --cc=iweiny@kernel.org \
    --cc=jannh@google.com \
    --cc=jeffxu@chromium.org \
    --cc=joey.gouly@arm.com \
    --cc=kees@kernel.org \
    --cc=linu.cherian@arm.com \
    --cc=linusw@kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-hardening@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=luto@kernel.org \
    --cc=maz@kernel.org \
    --cc=mbland@motorola.com \
    --cc=peterz@infradead.org \
    --cc=pierre.langlois@arm.com \
    --cc=ptosi@google.com \
    --cc=qperret@google.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=rppt@kernel.org \
    --cc=ryan.roberts@arm.com \
    --cc=tglx@kernel.org \
    --cc=vbabka@kernel.org \
    --cc=will@kernel.org \
    --cc=willy@infradead.org \
    --cc=x86@kernel.org \
    --cc=yang@os.amperecomputing.com \
    --cc=yeoreum.yun@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox