* [PATCH] arm64: Fix PIE_E1 mapping for _PAGE_READONLY_EXEC
[not found] <CGME20251227070633epcas1p3a8f7c19c9f5114a46765073fa16ba449@epcas1p3.samsung.com>
@ 2025-12-27 7:06 ` Seongsu Park
2025-12-27 15:46 ` Yeo Reum Yun
0 siblings, 1 reply; 3+ messages in thread
From: Seongsu Park @ 2025-12-27 7:06 UTC (permalink / raw)
To: catalin.marinas, will; +Cc: linux-arm-kernel, linux-kernel, Seongsu Park
_PAGE_READONLY_EXEC should map to PIE_RX instead of PIE_R in PIE_E1
Signed-off-by: Seongsu Park <sgsu.park@samsung.com>
---
arch/arm64/include/asm/pgtable-prot.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/arch/arm64/include/asm/pgtable-prot.h b/arch/arm64/include/asm/pgtable-prot.h
index 161e8660eddd..ca14f61dee81 100644
--- a/arch/arm64/include/asm/pgtable-prot.h
+++ b/arch/arm64/include/asm/pgtable-prot.h
@@ -180,7 +180,7 @@ static inline bool __pure lpa2_is_enabled(void)
PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_GCS), PIE_NONE_O) | \
PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_GCS_RO), PIE_NONE_O) | \
PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_EXECONLY), PIE_NONE_O) | \
- PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY_EXEC), PIE_R) | \
+ PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY_EXEC), PIE_RX) | \
PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED_EXEC), PIE_RW) | \
PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY), PIE_R) | \
PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED), PIE_RW) | \
--
2.25.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] arm64: Fix PIE_E1 mapping for _PAGE_READONLY_EXEC
2025-12-27 7:06 ` [PATCH] arm64: Fix PIE_E1 mapping for _PAGE_READONLY_EXEC Seongsu Park
@ 2025-12-27 15:46 ` Yeo Reum Yun
2025-12-27 17:38 ` Seongsu Park
0 siblings, 1 reply; 3+ messages in thread
From: Yeo Reum Yun @ 2025-12-27 15:46 UTC (permalink / raw)
To: Seongsu Park, Catalin Marinas, will; +Cc: linux-arm-kernel, linux-kernel
Hi Seongsu,
> diff --git a/arch/arm64/include/asm/pgtable-prot.h b/arch/arm64/include/asm/pgtable-prot.h
> index 161e8660eddd..ca14f61dee81 100644
> --- a/arch/arm64/include/asm/pgtable-prot.h
> +++ b/arch/arm64/include/asm/pgtable-prot.h
> @@ -180,7 +180,7 @@ static inline bool __pure lpa2_is_enabled(void)
> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_GCS), PIE_NONE_O) | \
> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_GCS_RO), PIE_NONE_O) | \
> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_EXECONLY), PIE_NONE_O) | \
> - PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY_EXEC), PIE_R) | \
> + PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY_EXEC), PIE_RX) | \
> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED_EXEC), PIE_RW) | \
> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_READONLY), PIE_R) | \
> PIRx_ELx_PERM_PREP(pte_pi_index(_PAGE_SHARED), PIE_RW) | \
NIT: This looks like it allows executing user code from the kernel.
Why is this necessary?
--
Sincerely,
Yeoreum Yun
^ permalink raw reply [flat|nested] 3+ messages in thread
* RE: [PATCH] arm64: Fix PIE_E1 mapping for _PAGE_READONLY_EXEC
2025-12-27 15:46 ` Yeo Reum Yun
@ 2025-12-27 17:38 ` Seongsu Park
0 siblings, 0 replies; 3+ messages in thread
From: Seongsu Park @ 2025-12-27 17:38 UTC (permalink / raw)
To: 'Yeo Reum Yun'
Cc: 'Catalin Marinas', will, linux-arm-kernel, linux-kernel
Hi Yeoreum,
> NIT: This looks like it allows executing user code from the kernel.
> Why is this necessary?
Good Catch. You're absolutely right.
I misunderstood how PIE separates EL0/EL1 permissions.
The kernel should only have read access to the executing user code pages.
The original PIE_EL1 mapping to PIE_R is correct.
My patch would be a security regression. Please disregard.
Thanks for the careful review,
Seongsu Park.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2025-12-27 17:39 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <CGME20251227070633epcas1p3a8f7c19c9f5114a46765073fa16ba449@epcas1p3.samsung.com>
2025-12-27 7:06 ` [PATCH] arm64: Fix PIE_E1 mapping for _PAGE_READONLY_EXEC Seongsu Park
2025-12-27 15:46 ` Yeo Reum Yun
2025-12-27 17:38 ` Seongsu Park
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®