Hi Ard,

For the patchset:

Reviewed- and Tested-by: Oliver Smith-Denny <o...@smith-denny.com>

Thanks for sending this out! I tested with some integrations to Project Mu on both a virtual and physical platform.

Oliver

On 3/13/2023 10:16 AM, Ard Biesheuvel wrote:
Link: https://bugzilla.tianocore.org/show_bug.cgi?id=4369



This v5 now covers a lot more ground, and has ballooned quite

substantially as a result. The series is essentially a proof of concept

of a way to implement rigorous W^X memory protections from SEC all the

way to booting the OS.



In particular:

- the AArch64 WXN control is enabled so that NX is implied for all

   writable memory regions, which is rather helpful when testing changes

   such as these;

- avoid PEIM shadowing where possible, as that would involve managing

   the executable permissions of the shadowed code

- remap the DXE core code section read-only explicitly from IPL

- equip the DXE core with a way to manage memory permissions before the

   CPU arch protocol driver is dispatched;

- permit the NX memory protection policy to apply to code memory type

   regions as well

- check the NX compat DLL flag and section alignment to decide whether

   an image can be loaded when the NX policy is applied to such a code

   region

- implement the EFI memory attributes protocol (for ARM and AArch64

   only) so that such NX compat compliant images have a way to create

   executable mappings



v4:

- major cleanup of the 32-bit ARM code

- add support for EFI_MEMORY_RP using the access flag

- enable stack guard in ArmVirtPkg (which uses EFI_MEMORY_RP)

- incorporate optimization from other series [0] to avoid splitting

   block entries unnecessarily



v3:

- fix ARM32 bug in attribute conversion

- add Liming's ack to patch #1

- include draft patch (NOT FOR MERGE) used to test the changes



v2:

- drop patch to bump exposed UEFI revision to v2.10

- add missing permitted return values to protocol definition



[0] https://edk2.groups.io/g/devel/message/99801



Cc: Michael Kinney <michael.d.kin...@intel.com>

Cc: Liming Gao <gaolim...@byosoft.com.cn>

Cc: Jiewen Yao <jiewen....@intel.com>

Cc: Michael Kubacki <michael.kuba...@microsoft.com>

Cc: Sean Brogan <sean.bro...@microsoft.com>

Cc: Rebecca Cran <quic_rc...@quicinc.com>

Cc: Leif Lindholm <quic_llind...@quicinc.com>

Cc: Sami Mujawar <sami.muja...@arm.com>

Cc: Taylor Beebe <t...@taylorbeebe.com>



Ard Biesheuvel (38):

   ArmPkg/ArmMmuLib ARM: Remove half baked large page support

   ArmPkg/ArmMmuLib ARM: Split off XN page descriptor bit from type field

   ArmPkg/CpuDxe ARM: Fix page-to-section attribute conversion

   ArmPkg/ArmMmuLib ARM: Isolate the access flag from AP mask

   ArmPkg/ArmMmuLib ARM: Clear individual permission bits

   ArmPkg/ArmMmuLib: Implement EFI_MEMORY_RP using access flag

   ArmVirtPkg: Enable stack guard

   ArmPkg/ArmMmuLib: Avoid splitting block entries if possible

   ArmPkg/CpuDxe: Expose unified region-to-EFI attribute conversion

   MdePkg: Add Memory Attribute Protocol definition

   ArmPkg/CpuDxe: Implement EFI memory attributes protocol

   ArmPkg/CpuDxe: Perform preliminary NX remap of free memory

   MdeModulePkg/DxeCore: Unconditionally set memory protections

   ArmPkg/Mmu: Remove handling of NONSECURE memory regions

   ArmPkg/ArmMmuLib: Introduce region types for RO/XP WB cached memory

   MdePkg/BasePeCoffLib: Add API to keep track of relocation range

   MdeModulePkg/DxeIpl: Avoid shadowing IPL PEIM by default

   MdeModulePkg/DxeIpl AARCH64: Remap DXE core code section before launch

   MdeModulePkg/DxeCore: Reduce range of W+X remaps at EBS time

   MdeModulePkg/DxeCore: Permit preliminary CPU arch fallback

   ArmPkg: Implement ArmSetMemoryOverrideLib

   MdeModulePkg/PcdPeim: Permit unshadowed execution

   EmbeddedPkg/PrePiLib AARCH64: Remap DXE core before execution

   ArmVirtPkg/ArmVirtQemu: Use XP memory mappings by default

   ArmVirtPkg/ArmVirtQemu: Use PEI flavor of ArmMmuLib for all PEIMs

   ArmVirtPkg/ArmVirtQemu: Use read-only memory region type for code

     flash

   BaseTools/GccBase AARCH64: Avoid page sharing between code and data

   ArmVirtPkg/ArmVirtQemu: Enable hardware enforced W^X memory

     permissions

   MdePkg/PeCoffLib: Capture DLL characteristics field in image context

   MdePkg/IndustryStandard: PeImage.h: Import DLL characteristics

   MdeModulePkg/DxeCore: Remove redundant DEBUG statements

   MdeModulePkg/DxeCore: Update memory protections before freeing a

     region

   MdeModulePkg/DxeCore: Disregard runtime alignment for image protection

   MdeModulePkg/DxeCore: Deal with failure in UefiProtectImage()

   MdeModulePkg/DxeCore: Clear NX permissions on non-protected images

   MdeModulePkg/DxeCore: Permit NX protection for code regions

   MdeModulePkg/DxeCore: Check NX compat when using restricted code

     regions

   MdeModulePkg DEC: Remove inaccurate comment



  ArmPkg/ArmPkg.dec                                                  |   5 +

  ArmPkg/ArmPkg.dsc                                                  |   1 +

  ArmPkg/Drivers/CpuDxe/AArch64/Mmu.c                                |  25 +-

  ArmPkg/Drivers/CpuDxe/Arm/Mmu.c                                    |  96 
+++++--

  ArmPkg/Drivers/CpuDxe/CpuDxe.c                                     |  87 
++++++

  ArmPkg/Drivers/CpuDxe/CpuDxe.h                                     |  17 ++

  ArmPkg/Drivers/CpuDxe/CpuDxe.inf                                   |   5 +

  ArmPkg/Drivers/CpuDxe/MemoryAttribute.c                            | 271 
++++++++++++++++++

  ArmPkg/Include/Chipset/ArmV7Mmu.h                                  | 131 
++++-----

  ArmPkg/Include/Library/ArmLib.h                                    |  17 +-

  ArmPkg/Include/Library/ArmMmuLib.h                                 |  34 +++

  ArmPkg/Library/ArmLib/Arm/ArmV7Support.S                           |   2 +

  ArmPkg/Library/ArmMmuLib/AArch64/ArmMmuLibCore.c                   | 103 
++++++-

  ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibConvert.c                    |   8 +-

  ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibCore.c                       |  51 ++--

  ArmPkg/Library/ArmMmuLib/Arm/ArmMmuLibUpdate.c                     | 173 
++++++++++--

  ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c   |  78 
++++++

  ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf |  28 ++

  ArmVirtPkg/ArmVirt.dsc.inc                                         |   3 +

  ArmVirtPkg/ArmVirtQemu.dsc                                         |  11 +-

  ArmVirtPkg/ArmVirtQemuKernel.dsc                                   |   1 +

  ArmVirtPkg/Library/ArmPlatformLibQemu/AArch64/ArmPlatformHelper.S  |   2 +-

  ArmVirtPkg/Library/QemuVirtMemInfoLib/QemuVirtMemInfoLib.c         |   4 +-

  BaseTools/Scripts/GccBase.lds                                      |  13 +-

  EmbeddedPkg/Include/Library/PrePiLib.h                             |  16 --

  EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c                    |  51 ++++

  EmbeddedPkg/Library/PrePiLib/PrePi.h                               |  13 +

  EmbeddedPkg/Library/PrePiLib/PrePiLib.c                            |   4 +

  EmbeddedPkg/Library/PrePiLib/PrePiLib.inf                          |  12 +

  EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c                    |  23 ++

  MdeModulePkg/Core/Dxe/DxeMain.h                                    |   6 +-

  MdeModulePkg/Core/Dxe/Image/Image.c                                |   8 +-

  MdeModulePkg/Core/Dxe/Mem/Page.c                                   |  15 +-

  MdeModulePkg/Core/Dxe/Misc/MemoryProtection.c                      | 288 
+++++++++++---------

  MdeModulePkg/Core/DxeIplPeim/Arm/DxeLoadFunc.c                     |  73 +++++

  MdeModulePkg/Core/DxeIplPeim/DxeIpl.inf                            |   6 +-

  MdeModulePkg/Core/DxeIplPeim/DxeLoad.c                             |  24 +-

  MdeModulePkg/MdeModulePkg.dec                                      |   7 +-

  MdeModulePkg/Universal/PCD/Pei/Pcd.c                               | 112 
++++----

  MdeModulePkg/Universal/PCD/Pei/Pcd.inf                             |   1 +

  MdePkg/Include/IndustryStandard/PeImage.h                          |  15 +

  MdePkg/Include/Library/PeCoffLib.h                                 |  27 ++

  MdePkg/Include/Protocol/MemoryAttribute.h                          | 142 
++++++++++

  MdePkg/Library/BasePeCoffLib/BasePeCoff.c                          | 105 
++++++-

  MdePkg/MdePkg.dec                                                  |   3 +

  45 files changed, 1682 insertions(+), 435 deletions(-)

  create mode 100644 ArmPkg/Drivers/CpuDxe/MemoryAttribute.c

  create mode 100644 
ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.c

  create mode 100644 
ArmPkg/Library/ArmSetMemoryOverrideLib/ArmSetMemoryOverrideLib.inf

  create mode 100644 EmbeddedPkg/Library/PrePiLib/Arm/RemapDxeCore.c

  create mode 100644 EmbeddedPkg/Library/PrePiLib/X86/RemapDxeCore.c

  create mode 100644 MdePkg/Include/Protocol/MemoryAttribute.h





-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links: You receive all messages sent to this group.
View/Reply Online (#101373): https://edk2.groups.io/g/devel/message/101373
Mute This Topic: https://groups.io/mt/97585979/21656
Group Owner: devel+ow...@edk2.groups.io
Unsubscribe: https://edk2.groups.io/g/devel/unsub [arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-


Reply via email to