Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369
This v5 now covers a lot more ground, and has ballooned quite substantially as a result. The series is essentially a proof of concept of a way to implement rigorous W^X memory protections from SEC all the way to booting the OS. In particular: - the AArch64 WXN control is enabled so that NX is implied for all writable memory regions, which is rather helpful when testing changes such as these; - avoid PEIM shadowing where possible, as that would involve managing the executable permissions of the shadowed code - remap the DXE core code section read-only explicitly from IPL - equip the DXE core with a way to manage memory permissions before the CPU arch protocol driver is dispatched; - permit the NX memory protection policy to apply to code memory type regions as well - check the NX compat DLL flag and section alignment to decide whether an image can be loaded when the NX policy is applied to such a code region - implement the EFI memory attributes protocol (for ARM and AArch64 only) so that such NX compat compliant images have a way to create executable mappings v4: - major cleanup of the 32-bit ARM code - add support for EFI_MEMORY_RP using the access flag - enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP) - incorporate optimization from other series [0] to avoid splitting block entries unnecessarily v3: - fix ARM32 bug in attribute conversion - add Liming's ack to patch #1 - include draft patch (NOT FOR MERGE) used to test the changes v2: - drop patch to bump exposed UEFI revision to v2.10 - add missing permitted return values to protocol definition [0] https://edk2.groups.io/g/devel/message/99801 Cc: Michael Kinney <michael.d.kin...@intel.com> Cc: Liming Gao <gaolim...@byosoft.com.cn> Cc: Jiewen Yao <jiewen....@intel.com> Cc: Michael Kubacki <michael.kuba...@microsoft.com> Cc: Sean Brogan <sean.bro...@microsoft.com> Cc: Rebecca Cran <quic_rc...@quicinc.com> Cc: Leif Lindholm <quic_llind...@quicinc.com> Cc: Sami Mujawar <sami.muja...@arm.com> Cc: Taylor Beebe <t...@taylorbeebe.com> Ard Biesheuvel (38): ArmPkg/ArmMmuLib ARM: Remove half baked large page support ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask ArmPkg/ArmMmuLib ARM: Clear individual permission bits ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag ArmVirtPkg: Enable stack guard ArmPkg/ArmMmuLib: Avoid splitting block entries if possible ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion MdePkg: Add Memory Attribute Protocol definition ArmPkg/CpuDxe: Implement EFI memory attributes protocol ArmPkg/CpuDxe: Perform preliminary NX remap of free memory MdeModulePkg/DxeCore: Unconditionally set memory protections ArmPkg/Mmu: Remove handling of NONSECURE memory regions ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory MdePkg/BasePeCoffLib: Add API to keep track of relocation range MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback ArmPkg: Implement ArmSetMemoryOverrideLib MdeModulePkg/PcdPeim: Permit unshadowed execution EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code flash BaseTools/GccBase AARCH64: Avoid page sharing between code and data ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory permissions MdePkg/PeCoffLib: Capture DLL characteristics field in image context MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics MdeModulePkg/DxeCore: Remove redundant DEBUG statements MdeModulePkg/DxeCore: Update memory protections before freeing a region MdeModulePkg/DxeCore: Disregard runtime alignment for image protection MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage() MdeModulePkg/DxeCore: Clear NX permissions on non-protected images MdeModulePkg/DxeCore: Permit NX protection for code regions MdeModulePkg/DxeCore: Check NX compat when using restricted code regions MdeModulePkg DEC: Remove inaccurate comment ArmPkg/ArmPkg.dec | 5 + ArmPkg/ArmPkg.dsc | 1 + ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c | 25 +- ArmPkg/Drivers/CpuDxe/Arm/Mmu.c | 96 +++++-- ArmPkg/Drivers/CpuDxe/CpuDxe.c | 87 ++++++ ArmPkg/Drivers/CpuDxe/CpuDxe.h | 17 ++ ArmPkg/Drivers/CpuDxe/CpuDxe.inf | 5 + ArmPkg/Drivers/CpuDxe/MemoryAttribute.c | 271 ++++++++++++++++++ ArmPkg/Include/Chipset/ArmV7Mmu.h | 131 ++++----- ArmPkg/Include/Library/ArmLib.h | 17 +- ArmPkg/Include/Library/ArmMmuLib.h | 34 +++ ArmPkg/Library/ArmLib/Arm/ArmV7Support.S | 2 + ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c | 103 ++++++- ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c | 8 +- ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c | 51 ++-- ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c | 173 ++++++++++-- ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c | 78 ++++++ ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf | 28 ++ ArmVirtPkg/ArmVirt.dsc.inc | 3 + ArmVirtPkg/ArmVirtQemu.dsc | 11 +- ArmVirtPkg/ArmVirtQemuKernel.dsc | 1 + ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S | 2 +- ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c | 4 +- BaseTools/Scripts/GccBase.lds | 13 +- EmbeddedPkg/Include/Library/PrePiLib.h | 16 -- EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c | 51 ++++ EmbeddedPkg/Library/PrePiLib/PrePi.h | 13 + EmbeddedPkg/Library/PrePiLib/PrePiLib.c | 4 + EmbeddedPkg/Library/PrePiLib/PrePiLib.inf | 12 + EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c | 23 ++ MdeModulePkg/Core/Dxe/DxeMain.h | 6 +- MdeModulePkg/Core/Dxe/Image/Image.c | 8 +- MdeModulePkg/Core/Dxe/Mem/Page.c | 15 +- MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c | 288 +++++++++++--------- MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c | 73 +++++ MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf | 6 +- MdeModulePkg/Core/DxeIplPeim/DxeLoad.c | 24 +- MdeModulePkg/MdeModulePkg.dec | 7 +- MdeModulePkg/Universal/PCD/Pei/Pcd.c | 112 ++++---- MdeModulePkg/Universal/PCD/Pei/Pcd.inf | 1 + MdePkg/Include/IndustryStandard/PeImage.h | 15 + MdePkg/Include/Library/PeCoffLib.h | 27 ++ MdePkg/Include/Protocol/MemoryAttribute.h | 142 ++++++++++ MdePkg/Library/BasePeCoffLib/BasePeCoff.c | 105 ++++++- MdePkg/MdePkg.dec | 3 + 45 files changed, 1682 insertions(+), 435 deletions(-) create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c create mode 100644 ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h -- 2.39.2 -=-=-=-=-=-=-=-=-=-=-=- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#101104): https://edk2.groups.io/g/devel/message/101104 Mute This Topic: https://groups.io/mt/97585979/21656 Group Owner: devel+ow...@edk2.groups.io Unsubscribe: https://edk2.groups.io/g/devel/unsub [arch...@mail-archive.com] -=-=-=-=-=-=-=-=-=-=-=-