mirror of https://github.com/acidanthera/audk.git
ArmPkg/Mmu: set required XN attributes for device mappings
To prevent speculative intruction fetches from MMIO ranges that may have side effects on reads, the architecture requires device mappings to be created with the XN or UXN/PXN bits set (for the ARM/EL2 and EL1&0 translation regimes, respectively.) Note that, in the ARM case, this involves moving all accesses to a client domain since permission attributes like XN are ignored from a manager domain. The use of a client domain is actually mandated explicitly by the UEFI spec. Reported-by: Heyi Guo <heyi.guo@linaro.org> Contributed-under: TianoCore Contribution Agreement 1.0 Signed-off-by: Ard Biesheuvel <ard.biesheuvel@linaro.org> Reviewed-by: Leif Lindholm <leif.lindholm@linaro.org> git-svn-id: https://svn.code.sf.net/p/edk2/code/trunk/edk2@18891 6f19259b-4bc3-4df7-8a09-765794883524
This commit is contained in:
parent
19bb46c411
commit
6bc35cbaca
|
@ -192,6 +192,7 @@
|
||||||
TT_DESCRIPTOR_SECTION_S_NOT_SHARED | \
|
TT_DESCRIPTOR_SECTION_S_NOT_SHARED | \
|
||||||
TT_DESCRIPTOR_SECTION_DOMAIN(0) | \
|
TT_DESCRIPTOR_SECTION_DOMAIN(0) | \
|
||||||
TT_DESCRIPTOR_SECTION_AP_RW_RW | \
|
TT_DESCRIPTOR_SECTION_AP_RW_RW | \
|
||||||
|
TT_DESCRIPTOR_SECTION_XN_MASK | \
|
||||||
TT_DESCRIPTOR_SECTION_CACHE_POLICY_SHAREABLE_DEVICE)
|
TT_DESCRIPTOR_SECTION_CACHE_POLICY_SHAREABLE_DEVICE)
|
||||||
#define TT_DESCRIPTOR_SECTION_UNCACHED(NonSecure) (TT_DESCRIPTOR_SECTION_TYPE_SECTION | \
|
#define TT_DESCRIPTOR_SECTION_UNCACHED(NonSecure) (TT_DESCRIPTOR_SECTION_TYPE_SECTION | \
|
||||||
((NonSecure) ? TT_DESCRIPTOR_SECTION_NS : 0) | \
|
((NonSecure) ? TT_DESCRIPTOR_SECTION_NS : 0) | \
|
||||||
|
@ -215,6 +216,7 @@
|
||||||
TT_DESCRIPTOR_PAGE_NG_GLOBAL | \
|
TT_DESCRIPTOR_PAGE_NG_GLOBAL | \
|
||||||
TT_DESCRIPTOR_PAGE_S_NOT_SHARED | \
|
TT_DESCRIPTOR_PAGE_S_NOT_SHARED | \
|
||||||
TT_DESCRIPTOR_PAGE_AP_RW_RW | \
|
TT_DESCRIPTOR_PAGE_AP_RW_RW | \
|
||||||
|
TT_DESCRIPTOR_PAGE_XN_MASK | \
|
||||||
TT_DESCRIPTOR_PAGE_CACHE_POLICY_SHAREABLE_DEVICE)
|
TT_DESCRIPTOR_PAGE_CACHE_POLICY_SHAREABLE_DEVICE)
|
||||||
#define TT_DESCRIPTOR_PAGE_UNCACHED (TT_DESCRIPTOR_PAGE_TYPE_PAGE | \
|
#define TT_DESCRIPTOR_PAGE_UNCACHED (TT_DESCRIPTOR_PAGE_TYPE_PAGE | \
|
||||||
TT_DESCRIPTOR_PAGE_NG_GLOBAL | \
|
TT_DESCRIPTOR_PAGE_NG_GLOBAL | \
|
||||||
|
|
|
@ -50,7 +50,10 @@ ArmMemoryAttributeToPageAttribute (
|
||||||
ASSERT(0);
|
ASSERT(0);
|
||||||
case ARM_MEMORY_REGION_ATTRIBUTE_DEVICE:
|
case ARM_MEMORY_REGION_ATTRIBUTE_DEVICE:
|
||||||
case ARM_MEMORY_REGION_ATTRIBUTE_NONSECURE_DEVICE:
|
case ARM_MEMORY_REGION_ATTRIBUTE_NONSECURE_DEVICE:
|
||||||
return TT_ATTR_INDX_DEVICE_MEMORY;
|
if (ArmReadCurrentEL () == AARCH64_EL2)
|
||||||
|
return TT_ATTR_INDX_DEVICE_MEMORY | TT_TABLE_XN;
|
||||||
|
else
|
||||||
|
return TT_ATTR_INDX_DEVICE_MEMORY | TT_TABLE_UXN | TT_TABLE_PXN;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
|
@ -294,7 +294,7 @@ ArmConfigureMmu (
|
||||||
DOMAIN_ACCESS_CONTROL_NONE( 3) |
|
DOMAIN_ACCESS_CONTROL_NONE( 3) |
|
||||||
DOMAIN_ACCESS_CONTROL_NONE( 2) |
|
DOMAIN_ACCESS_CONTROL_NONE( 2) |
|
||||||
DOMAIN_ACCESS_CONTROL_NONE( 1) |
|
DOMAIN_ACCESS_CONTROL_NONE( 1) |
|
||||||
DOMAIN_ACCESS_CONTROL_MANAGER(0));
|
DOMAIN_ACCESS_CONTROL_CLIENT(0));
|
||||||
|
|
||||||
ArmEnableInstructionCache();
|
ArmEnableInstructionCache();
|
||||||
ArmEnableDataCache();
|
ArmEnableDataCache();
|
||||||
|
|
Loading…
Reference in New Issue