Linux Documentation
 help / color / mirror / Atom feed
From: Jason Gunthorpe <jgg@nvidia.com>
To: Alexandre Ghiti <alex@ghiti.fr>,
	Albert Ou <aou@eecs.berkeley.edu>,
	Ard Biesheuvel <ardb@kernel.org>, Arnd Bergmann <arnd@arndb.de>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Jonathan Corbet <corbet@lwn.net>, David Sterba <dsterba@suse.com>,
	Ilias Apalodimas <ilias.apalodimas@linaro.org>,
	linux-arch@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
	linux-doc@vger.kernel.org, linux-efi@vger.kernel.org,
	linux-riscv@lists.infradead.org,
	Mark Rutland <mark.rutland@arm.com>,
	Palmer Dabbelt <palmer@dabbelt.com>,
	Paul Walmsley <pjw@kernel.org>,
	Randy Dunlap <rdunlap@infradead.org>,
	Simon Glass <sjg@chromium.org>,
	Shuah Khan <skhan@linuxfoundation.org>,
	Nick Terrell <terrelln@fb.com>, Will Deacon <will@kernel.org>
Cc: "Alexandre Ghiti" <alexghiti@rivosinc.com>,
	"Conor Dooley" <conor.dooley@microchip.com>,
	"Jonathan Cameron" <jonathan.cameron@oss.qualcomm.com>,
	linux-integrity@vger.kernel.org,
	"Palmer Dabbelt" <palmer@rivosinc.com>,
	patches@lists.linux.dev, "Piotr Król" <piotr.krol@3mdeb.com>,
	"Ross Philipson" <ross.philipson@gmail.com>,
	"Sami Tolvanen" <samitolvanen@google.com>,
	"Song Shuai" <songshuaishuai@tinylab.org>
Subject: [PATCH v2 10/15] efi/libstub: Put the stub's writable data in unique sections for DRTM
Date: Fri,  2 Oct 2026 20:31:47 -0300	[thread overview]
Message-ID: <10-v2-989a18390eb1+486-arm64_drtm_jgg@nvidia.com> (raw)
In-Reply-To: <0-v2-989a18390eb1+486-arm64_drtm_jgg@nvidia.com>

Currently the EFI stub's .bss and .data are both placed in .init.data,
which allows them to be discarded after boot, but places them within the
region of memory we need to measure as part of a DRTM launch.

If the EFI stub modifies the measured data before the measurement, then we
can no longer get a predictable measurement.

Give them unique section names; the arch's linker script has to put
these sections outside the measured range.

Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
---
 drivers/firmware/efi/libstub/Makefile  | 10 ++++++++++
 drivers/firmware/efi/libstub/zboot.lds |  2 +-
 2 files changed, 11 insertions(+), 1 deletion(-)

diff --git a/drivers/firmware/efi/libstub/Makefile b/drivers/firmware/efi/libstub/Makefile
index 77a2b2d74f3f62..3f1921e6c334d1 100644
--- a/drivers/firmware/efi/libstub/Makefile
+++ b/drivers/firmware/efi/libstub/Makefile
@@ -142,6 +142,16 @@ STUBCOPY_FLAGS-$(CONFIG_ARM64)	+= --prefix-alloc-sections=.init \
 				   --prefix-symbols=__efistub_
 STUBCOPY_RELOC-$(CONFIG_ARM64)	:= R_AARCH64_ABS
 
+# Give writable stub state a dedicated section namespace.  objcopy applies
+# section renames before section prefixes, irrespective of their command line
+# ordering, so these become .init.efidata and .init.efibss.
+#
+# The names must stay outside the .init.data.* namespace.  INIT_DATA collects
+# *(.init.data .init.data.*) into a measured kernel output section that the
+# arm64 linker script emits first.
+STUBCOPY_FLAGS-$(CONFIG_EFI_STUB_DRTM) += --rename-section .data=.efidata \
+					   --rename-section .bss=.efibss,load,alloc
+
 # For RISC-V, we don't need anything special other than arm64. Keep all the
 # symbols in .init section and make sure that no absolute symbols references
 # exist.
diff --git a/drivers/firmware/efi/libstub/zboot.lds b/drivers/firmware/efi/libstub/zboot.lds
index 8d32be32931494..568b9ce4857f43 100644
--- a/drivers/firmware/efi/libstub/zboot.lds
+++ b/drivers/firmware/efi/libstub/zboot.lds
@@ -38,7 +38,7 @@ SECTIONS
 
 	.data : ALIGN(4096) {
 		_data = .;
-		*(.data* .init.data*)
+		*(.data* .init.data* .init.efidata* .init.efibss*)
 		_edata = ALIGN(512);
 		. = _edata;
 	}
-- 
2.43.0


  parent reply	other threads:[~2026-10-02 23:32 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 23:31 [PATCH v2 00/15] arm64: DRTM, boot portion Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 01/15] efi/libstub: Fix error unwind freeing fdt in allocate_new_fdt_and_exit_boot() Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 02/15] efi/riscv: libstub: Don't set image_size in handle_kernel_image() Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 03/15] efi/libstub: Free cmdline_ptr in efi_pe_entry Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 04/15] efi/libstub: Add a general way to get symbols from the vmlinux into zboot Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 05/15] arm64/efi: Use CONFIG_EFI_STUB_IMAGE_INFO for code_size Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 06/15] efi/zboot: Lift efi_cache_sync_image() from efi_zboot_decompress() Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 07/15] efi/libstub: Add generic arch callbacks for DRTM Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 08/15] efi/libstub: Have efi_kaslr_relocate_kernel() handle extra_size Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 09/15] efi: Add a __efi_data_handoff section annotation Jason Gunthorpe
2026-10-02 23:31 ` Jason Gunthorpe [this message]
2026-10-02 23:31 ` [PATCH v2 11/15] arm64: drtm: Add macro definitions for DEN0113 Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 12/15] arm64: drtm: Update the linker script for EFI_STUB_DRTM Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 13/15] arm64: drtm: Add drtm_entry point to head.S Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 14/15] arm64: drtm: Call UNPROTECT_MEMORY Jason Gunthorpe
2026-10-02 23:31 ` [PATCH v2 15/15] efi/arm64: Implement ARM64 DRTM in the stub Jason Gunthorpe
2026-10-06 10:30 ` [PATCH v2 00/15] arm64: DRTM, boot portion Ard Biesheuvel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=10-v2-989a18390eb1+486-arm64_drtm_jgg@nvidia.com \
    --to=jgg@nvidia.com \
    --cc=alex@ghiti.fr \
    --cc=alexghiti@rivosinc.com \
    --cc=aou@eecs.berkeley.edu \
    --cc=ardb@kernel.org \
    --cc=arnd@arndb.de \
    --cc=catalin.marinas@arm.com \
    --cc=conor.dooley@microchip.com \
    --cc=corbet@lwn.net \
    --cc=dsterba@suse.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=jonathan.cameron@oss.qualcomm.com \
    --cc=linux-arch@vger.kernel.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-doc@vger.kernel.org \
    --cc=linux-efi@vger.kernel.org \
    --cc=linux-integrity@vger.kernel.org \
    --cc=linux-riscv@lists.infradead.org \
    --cc=mark.rutland@arm.com \
    --cc=palmer@dabbelt.com \
    --cc=palmer@rivosinc.com \
    --cc=patches@lists.linux.dev \
    --cc=piotr.krol@3mdeb.com \
    --cc=pjw@kernel.org \
    --cc=rdunlap@infradead.org \
    --cc=ross.philipson@gmail.com \
    --cc=samitolvanen@google.com \
    --cc=sjg@chromium.org \
    --cc=skhan@linuxfoundation.org \
    --cc=songshuaishuai@tinylab.org \
    --cc=terrelln@fb.com \
    --cc=will@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox