Linux Confidential Computing Development
 help / color / mirror / Atom feed
* [PATCH] x86/ioremap: Maintain consistent IORES_MAP_ENCRYPTED for BIOS data
@ 2025-03-31 23:14 Dan Williams
  2025-04-01  5:57 ` Nikolay Borisov
  2025-04-01  7:57 ` Kirill Shutemov
  0 siblings, 2 replies; 11+ messages in thread
From: Dan Williams @ 2025-03-31 23:14 UTC (permalink / raw)
  To: dave.hansen
  Cc: x86, Vishal Annapurve, Kirill Shutemov, Nikolay Borisov,
	Nikolay Borisov, stable, linux-coco

Nikolay reports [1] that accessing BIOS data (first 1MB of the physical
address space) via /dev/mem results in an SEPT violation.

The cause is ioremap() (via xlate_dev_mem_ptr()) establishing an
unencrypted mapping where the kernel had established an encrypted
mapping previously.

Teach __ioremap_check_other() that this address space shall always be
mapped as encrypted as historically it is memory resident data, not MMIO
with side-effects.

Cc: <x86@kernel.org>
Cc: Vishal Annapurve <vannapurve@google.com>
Cc: Kirill Shutemov <kirill.shutemov@linux.intel.com>
Reported-by: Nikolay Borisov <nik.borisov@suse.com>
Closes: http://lore.kernel.org/20250318113604.297726-1-nik.borisov@suse.com [1]
Tested-by: Nikolay Borisov <nik.borisov@suse.com>
Fixes: 9aa6ea69852c ("x86/tdx: Make pages shared in ioremap()")
Cc: <stable@vger.kernel.org>
Signed-off-by: Dan Williams <dan.j.williams@intel.com>
---
 arch/x86/mm/ioremap.c |    4 ++++
 1 file changed, 4 insertions(+)

diff --git a/arch/x86/mm/ioremap.c b/arch/x86/mm/ioremap.c
index 42c90b420773..9e81286a631e 100644
--- a/arch/x86/mm/ioremap.c
+++ b/arch/x86/mm/ioremap.c
@@ -122,6 +122,10 @@ static void __ioremap_check_other(resource_size_t addr, struct ioremap_desc *des
 		return;
 	}
 
+	/* Ensure BIOS data (see devmem_is_allowed()) is consistently mapped */
+	if (PHYS_PFN(addr) < 256)
+		desc->flags |= IORES_MAP_ENCRYPTED;
+
 	if (!IS_ENABLED(CONFIG_EFI))
 		return;
 


^ permalink raw reply related	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2025-04-03 12:15 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-03-31 23:14 [PATCH] x86/ioremap: Maintain consistent IORES_MAP_ENCRYPTED for BIOS data Dan Williams
2025-04-01  5:57 ` Nikolay Borisov
2025-04-02 20:55   ` Dan Williams
2025-04-01  7:57 ` Kirill Shutemov
2025-04-01 15:07   ` Tom Lendacky
2025-04-01 17:59     ` Dave Hansen
2025-04-02 21:03       ` Dan Williams
2025-04-02 18:55     ` Naveen N Rao
2025-04-02 21:36       ` Dan Williams
2025-04-03 12:11         ` Naveen N Rao
2025-04-02 20:56   ` Dan Williams

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox