From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 0791AC624D4 for ; Tue, 1 Sep 2026 14:39:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:In-Reply-To:Content-Type: MIME-Version:References:Message-ID:Subject:Cc:To:From:Date:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=hGPRzkwM3s4uAqmW6A+0BM2kjJ4fklHUcyodXSytQxo=; b=aQyCdoHJChtjTutzyiDwHHgz8d aMk4lnpUmXL7vdTjbWL2xe2NBrZbEtiLjT7uOWj7vFGObGF4zn4yasaImh2ETCSmGz7Qqs0cNeoH4 dRHs5AjdrsuZG94rt55y81/pzWH4fCSdbud8MMUpErYuMKExITFnf6X7efykC73+TuL9vKc1Ib6M9 ejCeZ04tgQuGyK1Im2tnOqz2F8ijHLNO35AFDb1UmxfZ34l5LpNYbNIJTseEI6rZ7z4fHkC4b3KgA L51GUmECwDmbrgcaybixK+74QFNYLBojAix+lmDEX9iN53WKiMYaAJvxBKYo3DAmBsUFySyJvvi22 nnZb1nIQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x1PeI-0000000CMYR-2XSQ; Tue, 01 Sep 2026 14:39:42 +0000 Received: from foss.arm.com ([217.140.110.172]) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x1PeG-0000000CMXk-0fB2 for linux-arm-kernel@lists.infradead.org; Tue, 01 Sep 2026 14:39:41 +0000 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 96AD21756; Tue, 1 Sep 2026 07:39:34 -0700 (PDT) Received: from localhost (a079125.arm.com [10.164.21.43]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPSA id 98E993F882; Tue, 1 Sep 2026 07:39:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1788273578; bh=KmiAFVuFMCiQ3kijocFjf2AEfhNaMl006eWKr1VxZWw=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=UaaDtqHcIV5ry2ml0i7WogPk4YgXZq6+Vz7uOn4AHpoOLjAHrS3Gt0mi0drzIiTGw QJ2c3z9zO9IlLLoALRJ0uXpCEpw+yPtuAEkE+DluchNpazNFM+uecD/ULnvr3RZxj0 lmNvFugY29d55iuycNOG+caifQwbMfIUamHeDOCQ= Date: Tue, 1 Sep 2026 20:09:34 +0530 From: Linu Cherian To: Kevin Brodsky Cc: linux-hardening@vger.kernel.org, Andrew Morton , Andy Lutomirski , Catalin Marinas , Dave Hansen , "David Hildenbrand (Arm)" , Jann Horn , Jeff Xu , Joey Gouly , Kees Cook , Linus Walleij , Marc Zyngier , Mark Brown , Matthew Wilcox , Maxwell Bland , "Mike Rapoport (IBM)" , Peter Zijlstra , Pierre Langlois , =?iso-8859-1?Q?Pierre-Cl=E9ment?= Tosi , Quentin Perret , Rick Edgecombe , Ryan Roberts , Vlastimil Babka , Will Deacon , Yang Shi , Yeoreum Yun , linux-arm-kernel@lists.infradead.org, linux-mm@kvack.org, x86@kernel.org, Ira Weiny , Lorenzo Stoakes , Thomas Gleixner Subject: Re: [PATCH RFC v9 03/25] arm64: mm: Enable overlays for all EL1 indirect permissions Message-ID: References: <20260818-kpkeys-v9-0-743ad31b2c8f@arm.com> <20260818-kpkeys-v9-3-743ad31b2c8f@arm.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260818-kpkeys-v9-3-743ad31b2c8f@arm.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260901_073940_275756_E0D6CE57 X-CRM114-Status: GOOD ( 17.58 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org Kevin, On Tue, Aug 18, 2026 at 03:08:45PM +0100, Kevin Brodsky wrote: > In preparation of using POE inside the kernel, enable "Overlay > applied" for kernel memory types in PIR_EL1. This ensures that the > permissions set in POR_EL1 affect all kernel mappings. > > User memory types must be left untouched (overlays not applied) > because any privileged access to user memory (e.g. futex atomic > without FEAT_LSUI) would then be mistakenly checked against POR_EL1. > > Reviewed-by: David Hildenbrand (Arm) > Signed-off-by: Kevin Brodsky > --- > arch/arm64/include/asm/pgtable-prot.h | 8 ++++---- > 1 file changed, 4 insertions(+), 4 deletions(-) > > diff --git a/arch/arm64/include/asm/pgtable-prot.h b/arch/arm64/include/asm/pgtable-prot.h > index 212ce1b02e15..d4d45ab86a5a 100644 > --- a/arch/arm64/include/asm/pgtable-prot.h > +++ b/arch/arm64/include/asm/pgtable-prot.h > @@ -183,9 +183,9 @@ static inline bool __pure lpa2_is_enabled(void) > PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED_EXEC), PIE_RW) | \ > PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY), PIE_R) | \ > PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED), PIE_RW) | \ > - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_ROX), PIE_RX) | \ > - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_EXEC), PIE_RWX) | \ > - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_RO), PIE_R) | \ > - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL), PIE_RW)) > + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_ROX), PIE_RX_O) | \ > + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_EXEC), PIE_RWX_O) | \ > + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL_RO), PIE_R_O) | \ > + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_KERNEL), PIE_RW_O)) > > #endif /* __ASM_PGTABLE_PROT_H */ IMHO its better to have this patch just before, "arm64: Enable kpkeys" for easier review. Otherwise, Reviewed-by: Linu Cherian