From patchwork Fri Mar 10 12:50:25 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 13169245 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 0A475C64EC4 for ; Fri, 10 Mar 2023 12:51:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:MIME-Version:References:In-Reply-To: Message-Id:Date:Subject:Cc:To:From:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=9sWuJzmCF4WGT9DEHN3so7yQuJzLwSzMvMfCdPAaPI8=; b=XWUdvVRaWfbNgX vmSw9peUovdGsanMWeudsJnbrx+CPwh9r1QKwoZkm6ABJUcneIRsYsDRv8vN9eAfo2oSpsiFxCEFU wFC7rlZ4vpcgAewoKv8af5K0BdpFwYNrWu7Qx1YsaBucq3U74oZ3K5jcQ0pxFnPtzwVhzJOVgovU/ /cgf2Tw2r2kYhrI+JyrlaSrT9fkeb+BoUGROc+ED5esyKYZwsHYhZ8tY+ZVTCM5kkKJaE/LXuKCaN D7qeTMGHXXaHd26hlZmh00ezhBwNBXBk9cd/YVPZPWbIk8N5IE/sLL8yB+O1cyH+QoWmHPnO8Z2Zn FiyVS+YqE/HfYPdEnYvg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1pacCq-00EXyA-9v; Fri, 10 Mar 2023 12:50:44 +0000 Received: from dfw.source.kernel.org ([2604:1380:4641:c500::1]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1pacCi-00EXvt-AE for linux-arm-kernel@lists.infradead.org; Fri, 10 Mar 2023 12:50:37 +0000 Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id AC18960AEE; Fri, 10 Mar 2023 12:50:35 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0C40CC4339B; Fri, 10 Mar 2023 12:50:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1678452635; bh=Q2hOEReJ8XL6o95bm/6W8U9iYAmkT6SKYEkF7NI1eIw=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=XoiL+vJBoLsAmX7P8HQkr4D55apLMLxZaJaUCSJrV9J1Kx+QzH+rF5to/b5fvDdvE 5J5bScmOsuvOdfz2er5gq0Br2NaJQ5zQmJu096jBgVSUuitwlAynvtA2exRj6WnOuD mQaDr6eALypLDiNZ980OYby6dJ+6jSmQjt/T/qZtrhD0BYJ2iSGunYYLGjHldGNWtB 5caQI7c3m+aCsUAOEjhxc1WjUTiq0ajCcrFOCH1DFMMfm8G3OiwEq4Tr5AoBkMq38u PceoZvpuT0NaSCJof+78Ua59YdxANzTK4SvWykDiMlR3jCBRFFIBGqY+vFQpYf5uH/ MLTkkm2EZ/Ozg== From: Ard Biesheuvel To: linux-efi@vger.kernel.org Cc: linux-arm-kernel@lists.infradead.org, Ard Biesheuvel , Peter Jones , Gerd Hoffmann , Ilias Apalodimas , Kees Cook Subject: [PATCH 2/3] efi/libstub: arm64: Remap relocated image with strict permissions Date: Fri, 10 Mar 2023 13:50:25 +0100 Message-Id: <20230310125026.3390928-3-ardb@kernel.org> X-Mailer: git-send-email 2.39.2 In-Reply-To: <20230310125026.3390928-1-ardb@kernel.org> References: <20230310125026.3390928-1-ardb@kernel.org> MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=882; i=ardb@kernel.org; h=from:subject; bh=Q2hOEReJ8XL6o95bm/6W8U9iYAmkT6SKYEkF7NI1eIw=; b=owGbwMvMwCFmkMcZplerG8N4Wi2JIYVbfWKK9zeVjV22gjuF5uRNe374UkPTX735e3cw96x9v 2D/JNbzHaUsDGIcDLJiiiwCs/++23l6olSt8yxZmDmsTCBDGLg4BWAiBcsZGZ5W7fvSdHshb8jE QFbVW0qS/T8OBjKvWqXMzS688EPj7UkM/9PjfVaYij98tG797J/z/iw00M9+NenJusoGw/Ico3J HaW4A X-Developer-Key: i=ardb@kernel.org; a=openpgp; fpr=F43D03328115A198C90016883D200E9CA6329909 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230310_045036_406166_12AAF9C9 X-CRM114-Status: GOOD ( 10.07 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org After relocating the executable image, use the EFI memory attributes protocol to remap the code and data regions with the appropriate permissions. Signed-off-by: Ard Biesheuvel --- drivers/firmware/efi/libstub/arm64-stub.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/firmware/efi/libstub/arm64-stub.c b/drivers/firmware/efi/libstub/arm64-stub.c index d4a6b12a87413024..b996553cdb4c3587 100644 --- a/drivers/firmware/efi/libstub/arm64-stub.c +++ b/drivers/firmware/efi/libstub/arm64-stub.c @@ -139,6 +139,7 @@ efi_status_t handle_kernel_image(unsigned long *image_addr, *image_addr = *reserve_addr; memcpy((void *)*image_addr, _text, kernel_size); caches_clean_inval_pou(*image_addr, *image_addr + kernel_codesize); + efi_remap_image(*image_addr, *reserve_size, kernel_codesize); return EFI_SUCCESS; }