From: Jason Gunthorpe <jgg@nvidia.com>
To: Alexandre Ghiti <alex@ghiti.fr>,
Albert Ou <aou@eecs.berkeley.edu>,
Ard Biesheuvel <ardb@kernel.org>, Arnd Bergmann <arnd@arndb.de>,
Catalin Marinas <catalin.marinas@arm.com>,
Jonathan Corbet <corbet@lwn.net>, David Sterba <dsterba@suse.com>,
Ilias Apalodimas <ilias.apalodimas@linaro.org>,
linux-arch@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
linux-doc@vger.kernel.org, linux-efi@vger.kernel.org,
linux-riscv@lists.infradead.org,
Mark Rutland <mark.rutland@arm.com>,
Palmer Dabbelt <palmer@dabbelt.com>,
Paul Walmsley <pjw@kernel.org>,
Randy Dunlap <rdunlap@infradead.org>,
Simon Glass <sjg@chromium.org>,
Shuah Khan <skhan@linuxfoundation.org>,
Nick Terrell <terrelln@fb.com>, Will Deacon <will@kernel.org>
Cc: Alexandre Ghiti <alexghiti@rivosinc.com>,
Conor Dooley <conor.dooley@microchip.com>,
linux-integrity@vger.kernel.org,
Palmer Dabbelt <palmer@rivosinc.com>,
patches@lists.linux.dev,
Ross Philipson <ross.philipson@gmail.com>,
Sami Tolvanen <samitolvanen@google.com>,
Song Shuai <songshuaishuai@tinylab.org>
Subject: [PATCH 10/16] efi: Add a __efi_data_handoff section annotation
Date: Thu, 24 Sep 2026 10:53:13 -0300 [thread overview]
Message-ID: <10-v1-27d06b313981+8b-arm64_drtm_jgg@nvidia.com> (raw)
In-Reply-To: <0-v1-27d06b313981+8b-arm64_drtm_jgg@nvidia.com>
For a clean DRTM measurement, data written by the stub in the image must
not fall within the measured range. __efi_data_handoff can be used to mark
this data so it is placed outside the measured .data or .init.data
section, and also ensure it is force allocated and not part of .bss.
For DRTM data marked this way will need eventual hardening when the kernel
consumes it. For example sysfb_primary_display eventually leads to a blind
ioremap. Later series will look at hardening these flows.
The arch-agnostic sysfb_primary_display is the first user. The embedded
stub writes it.
Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
---
drivers/firmware/efi/efi-init.c | 2 +-
include/linux/efi.h | 12 ++++++++++++
2 files changed, 13 insertions(+), 1 deletion(-)
diff --git a/drivers/firmware/efi/efi-init.c b/drivers/firmware/efi/efi-init.c
index 6103b1a082d247..b00c4c03ca810a 100644
--- a/drivers/firmware/efi/efi-init.c
+++ b/drivers/firmware/efi/efi-init.c
@@ -61,7 +61,7 @@ extern __weak const efi_config_table_type_t efi_arch_tables[];
* it even without EFI, everything else can get them from here.
*/
#if !defined(CONFIG_X86) && (defined(CONFIG_SYSFB) || defined(CONFIG_EFI_EARLYCON) || defined(CONFIG_FIRMWARE_EDID))
-struct sysfb_display_info sysfb_primary_display __section(".data");
+struct sysfb_display_info sysfb_primary_display __efi_data_handoff;
EXPORT_SYMBOL_GPL(sysfb_primary_display);
#endif
diff --git a/include/linux/efi.h b/include/linux/efi.h
index aa15ff88539bdf..a77bb604b1d1fd 100644
--- a/include/linux/efi.h
+++ b/include/linux/efi.h
@@ -29,6 +29,18 @@
struct screen_info;
+/*
+ * Data the stub wants to pass to the kernel must not land in .bss so it doesn't
+ * get zero'd during early boot, and when DRTM is enabled must not land in the
+ * measured sections. The offset of such data can be passed to both EFI stubs
+ * using a mechanism like struct efi_image_info.
+ */
+#ifdef CONFIG_EFI_STUB_DRTM
+#define __efi_data_handoff __section(".unmeasured.data")
+#else
+#define __efi_data_handoff __section(".data")
+#endif
+
#define EFI_SUCCESS 0
#define EFI_LOAD_ERROR ( 1 | (1UL << (BITS_PER_LONG-1)))
#define EFI_INVALID_PARAMETER ( 2 | (1UL << (BITS_PER_LONG-1)))
--
2.43.0
next prev parent reply other threads:[~2026-09-24 13:53 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 13:53 [PATCH 00/16] arm64: DRTM, boot portion Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 01/16] efi/libstub: Fix error unwind freeing fdt in allocate_new_fdt_and_exit_boot() Jason Gunthorpe
2026-09-24 22:42 ` Jonathan Cameron
2026-09-24 23:44 ` Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 02/16] efi/riscv: libstub: Don't set image_size in handle_kernel_image() Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 03/16] efi/libstub: Free cmdline_ptr in efi_pe_entry Jason Gunthorpe
2026-09-24 22:49 ` Jonathan Cameron
2026-09-25 12:59 ` Jason Gunthorpe
2026-09-25 13:20 ` Ard Biesheuvel
2026-09-24 13:53 ` [PATCH 04/16] vmlinux.lds: Move DATA_LE32() from arm64 to the common linker script Jason Gunthorpe
2026-09-24 22:53 ` Jonathan Cameron
2026-09-24 23:50 ` Jason Gunthorpe
2026-09-25 13:30 ` Ard Biesheuvel
2026-09-24 13:53 ` [PATCH 05/16] efi/libstub: Add a general way to get symbols from the vmlinux into zboot Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 06/16] arm64/efi: Use CONFIG_EFI_STUB_IMAGE_INFO for code_size Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 07/16] efi/zboot: Lift efi_cache_sync_image() from efi_zboot_decompress() Jason Gunthorpe
2026-09-24 22:57 ` Jonathan Cameron
2026-09-24 23:53 ` Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 08/16] efi/libstub: Add generic arch callbacks for DRTM Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 09/16] efi/libstub: Have efi_kaslr_relocate_kernel() handle extra_size Jason Gunthorpe
2026-09-24 13:53 ` Jason Gunthorpe [this message]
2026-09-24 13:53 ` [PATCH 11/16] efi/libstub: Put the stub's writable data in unique sections for DRTM Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 12/16] arm64: drtm: Add macro definitions for DEN0113 Jason Gunthorpe
2026-09-25 0:29 ` Jonathan Cameron
2026-09-26 18:27 ` Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 13/16] arm64: drtm: Update the linker script for EFI_STUB_DRTM Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 14/16] arm64: drtm: Add drtm_entry point to head.S Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 15/16] arm64: drtm: Call UNPROTECT_MEMORY Jason Gunthorpe
2026-09-24 13:53 ` [PATCH 16/16] efi/arm64: Implement ARM64 DRTM in the stub Jason Gunthorpe
2026-09-25 18:37 ` Jonathan Cameron
2026-09-26 18:45 ` Jason Gunthorpe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=10-v1-27d06b313981+8b-arm64_drtm_jgg@nvidia.com \
--to=jgg@nvidia.com \
--cc=alex@ghiti.fr \
--cc=alexghiti@rivosinc.com \
--cc=aou@eecs.berkeley.edu \
--cc=ardb@kernel.org \
--cc=arnd@arndb.de \
--cc=catalin.marinas@arm.com \
--cc=conor.dooley@microchip.com \
--cc=corbet@lwn.net \
--cc=dsterba@suse.com \
--cc=ilias.apalodimas@linaro.org \
--cc=linux-arch@vger.kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-efi@vger.kernel.org \
--cc=linux-integrity@vger.kernel.org \
--cc=linux-riscv@lists.infradead.org \
--cc=mark.rutland@arm.com \
--cc=palmer@dabbelt.com \
--cc=palmer@rivosinc.com \
--cc=patches@lists.linux.dev \
--cc=pjw@kernel.org \
--cc=rdunlap@infradead.org \
--cc=ross.philipson@gmail.com \
--cc=samitolvanen@google.com \
--cc=sjg@chromium.org \
--cc=skhan@linuxfoundation.org \
--cc=songshuaishuai@tinylab.org \
--cc=terrelln@fb.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox