From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 59241C624A4 for ; Thu, 3 Sep 2026 16:43:56 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:In-Reply-To:From:References:Cc:To:Subject:MIME-Version:Date: Message-ID:Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=5Ede0e387x+HQCpBdPP2HNIRIIInugEd1SB3bO3qFo4=; b=A+UtXBw8M6Ax+wzD71mlXa9cT5 blNvLTkBCBWe/j8xoOu5C/YA1SIy65FSjYEo367R45KEQGA65ID+KF7sj2y9jC7WXAprvbyxc4LxP 9yJS3dDROuq5MXSYICXdHlxgehKrixW2dDAkA6PmZboqCd/zp78F7i0ArOhCV3XtT6uWU4RHqxFFG 4IbHgqBk9wNl3qYTO+FrzGAUqsh1k+PWUzMClABcXSMEompIOj75lZQQ/EN/xi+E+e+EMf4dzWmYG biax9l7pxiirqejSmhtLa8dckModGio4etPuCqsMlNosVirdBKP7ji1X5RU7ZMF6/uQr6I/ss3Up8 Ero7v8gQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x2AXQ-00000000CSW-2WAC; Thu, 03 Sep 2026 16:43:44 +0000 Received: from foss.arm.com ([217.140.110.172]) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x2AXO-00000000CRW-3tKn for linux-arm-kernel@lists.infradead.org; Thu, 03 Sep 2026 16:43:44 +0000 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 2372F1596; Thu, 3 Sep 2026 09:43:38 -0700 (PDT) Received: from [10.57.6.2] (unknown [10.57.6.2]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 9C5783F673; Thu, 3 Sep 2026 09:43:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1788453821; bh=LGH60093kePcPptb+SpjSkJD67LELfnSlCC5XNQthoY=; h=Date:Subject:To:Cc:References:From:In-Reply-To:From; b=usg/2W97KxtpPb0rbSiin0EMXPV4w0HH0wivxuLqD9D8WF9a/IxWQbf33irU5NcIs t+AESg1jykQrwQQ+OpEffiAiB7bjQR5A+ro4tLgjh6rSfVCZ3Z4i+icA8eK/ambLRv H3Q/wAzcDeqxVLbywNWPKevYysTO3L1fWzG7g0Xc= Message-ID: <5fa69046-e29b-43c2-ba8a-97532251e7d4@arm.com> Date: Thu, 3 Sep 2026 18:43:32 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH RFC v9 03/25] arm64: mm: Enable overlays for all EL1 indirect permissions To: Linu Cherian Cc: linux-hardening@vger.kernel.org, Andrew Morton , Andy Lutomirski , Catalin Marinas , Dave Hansen , "David Hildenbrand (Arm)" , Jann Horn , Jeff Xu , Joey Gouly , Kees Cook , Linus Walleij , Marc Zyngier , Mark Brown , Matthew Wilcox , Maxwell Bland , "Mike Rapoport (IBM)" , Peter Zijlstra , Pierre Langlois , =?UTF-8?Q?Pierre-Cl=C3=A9ment_Tosi?= , Quentin Perret , Rick Edgecombe , Ryan Roberts , Vlastimil Babka , Will Deacon , Yang Shi , Yeoreum Yun , linux-arm-kernel@lists.infradead.org, linux-mm@kvack.org, x86@kernel.org, Ira Weiny , Lorenzo Stoakes , Thomas Gleixner References: <20260818-kpkeys-v9-0-743ad31b2c8f@arm.com> <20260818-kpkeys-v9-3-743ad31b2c8f@arm.com> From: Kevin Brodsky Content-Language: en-GB In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260903_094343_056575_CECC4E7A X-CRM114-Status: GOOD ( 16.19 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On 01/09/2026 16:41, Linu Cherian wrote: > Kevin, > > On Tue, Aug 18, 2026 at 03:08:45PM +0100, Kevin Brodsky wrote: >> In preparation of using POE inside the kernel, enable "Overlay >> applied" for kernel memory types in PIR_EL1. This ensures that the >> permissions set in POR_EL1 affect all kernel mappings. >> >> User memory types must be left untouched (overlays not applied) >> because any privileged access to user memory (e.g. futex atomic >> without FEAT_LSUI) would then be mistakenly checked against POR_EL1. >> >> Reviewed-by: David Hildenbrand (Arm) >> Signed-off-by: Kevin Brodsky >> --- >> arch/arm64/include/asm/pgtable-prot.h | 8 ++++---- >> 1 file changed, 4 insertions(+), 4 deletions(-) >> >> diff --git a/arch/arm64/include/asm/pgtable-prot.h b/arch/arm64/include/asm/pgtable-prot.h >> index 212ce1b02e15..d4d45ab86a5a 100644 >> --- a/arch/arm64/include/asm/pgtable-prot.h >> +++ b/arch/arm64/include/asm/pgtable-prot.h >> @@ -183,9 +183,9 @@ static inline bool __pure lpa2_is_enabled(void) >> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED_EXEC), PIE_RW) | \ >> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY), PIE_R) | \ >> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED), PIE_RW) | \ >> - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_ROX), PIE_RX) | \ >> - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_EXEC), PIE_RWX) | \ >> - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_RO), PIE_R) | \ >> - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL), PIE_RW)) >> + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_ROX), PIE_RX_O) | \ >> + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_EXEC), PIE_RWX_O) | \ > As part of hardening, should we really add more constraints to the > KERNEL_EXEC by making it PIE_X_O. The name PAGE_KERNEL_EXEC seems to be a legacy from the times before STRICT_KERNEL_RWX, where X implied RW - nowadays it should really be PAGE_KERNEL_RWX. It should rarely be used with rodata=on (the default), see for instance kernel_exec_prot() in arch/arm64/mm/mmu.c. - Kevin