1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
|
/** @file
File managing the MMU for ARMv8 architecture in S-EL0
Copyright (c) 2017 - 2024, Arm Limited. All rights reserved.<BR>
Copyright (c) 2021, Linaro Limited
SPDX-License-Identifier: BSD-2-Clause-Patent
@par Reference(s):
- [1] SPM based on the MM interface.
(https://trustedfirmware-a.readthedocs.io/en/latest/components/
secure-partition-manager-mm.html)
- [2] Arm Firmware Framework for Armv8-A, DEN0077, version 1.2
(https://developer.arm.com/documentation/den0077/latest/)
- [3] FF-A Memory Management Protocol, DEN0140, version 1.2
(https://developer.arm.com/documentation/den0140/latest/)
**/
#include <Uefi.h>
#include <IndustryStandard/ArmMmSvc.h>
#include <IndustryStandard/ArmFfaSvc.h>
#include <Library/ArmLib.h>
#include <Library/ArmMmuLib.h>
#include <Library/ArmFfaLib.h>
#include <Library/ArmSvcLib.h>
#include <Library/BaseLib.h>
#include <Library/BaseMemoryLib.h>
#include <Library/DebugLib.h>
#include <Library/PcdLib.h>
/**
Utility function to determine whether ABIs in FF-A to set and get
memory permissions can be used. Ideally, this should be invoked once in the
library constructor and set a flag that can be used at runtime. However, the
StMM Core invokes this library before constructors are called and before the
StMM image itself is relocated.
@retval TRUE Use FF-A MemPerm ABIs.
@retval FALSE Use MM MemPerm ABIs.
**/
STATIC
BOOLEAN
EFIAPI
IsFfaMemoryAbiSupported (
IN VOID
)
{
EFI_STATUS Status;
UINT16 CurrentMajorVersion;
UINT16 CurrentMinorVersion;
Status = ArmFfaLibGetVersion (
ARM_FFA_MAJOR_VERSION,
ARM_FFA_MINOR_VERSION,
&CurrentMajorVersion,
&CurrentMinorVersion
);
if (EFI_ERROR (Status)) {
return FALSE;
}
return TRUE;
}
/**
Convert FFA return code to EFI_STATUS.
@param [in] SpmMmStatus SPM_MM return code
@retval EFI_STATUS correspond EFI_STATUS to SpmMmStatus
**/
STATIC
EFI_STATUS
SpmMmStatusToEfiStatus (
IN UINTN SpmMmStatus
)
{
switch (SpmMmStatus) {
case ARM_SPM_MM_RET_SUCCESS:
return EFI_SUCCESS;
case ARM_SPM_MM_RET_INVALID_PARAMS:
return EFI_INVALID_PARAMETER;
case ARM_SPM_MM_RET_DENIED:
return EFI_ACCESS_DENIED;
case ARM_SPM_MM_RET_NO_MEMORY:
return EFI_OUT_OF_RESOURCES;
default:
return EFI_UNSUPPORTED;
}
}
/** Send a request the target to get/set the memory permission.
@param [in] UseFfaAbis Use FF-A abis or not.
@param [in, out] SvcArgs Pointer to SVC arguments to send. On
return it contains the response parameters.
@param [out] RetVal Pointer to return the response value.
@retval EFI_SUCCESS Request successfull.
@retval EFI_INVALID_PARAMETER A parameter is invalid.
@retval EFI_NOT_READY Callee is busy or not in a state to handle
this request.
@retval EFI_UNSUPPORTED This function is not implemented by the
callee.
@retval EFI_ABORTED Message target ran into an unexpected error
and has aborted.
@retval EFI_ACCESS_DENIED Access denied.
@retval EFI_OUT_OF_RESOURCES Out of memory to perform operation.
**/
STATIC
EFI_STATUS
SendMemoryPermissionRequest (
IN BOOLEAN UseFfaAbis,
IN OUT ARM_SVC_ARGS *SvcArgs,
OUT INT32 *RetVal
)
{
if ((SvcArgs == NULL) || (RetVal == NULL)) {
return EFI_INVALID_PARAMETER;
}
ArmCallSvc (SvcArgs);
if (UseFfaAbis) {
if (IS_FID_FFA_ERROR (SvcArgs->Arg0)) {
return FfaStatusToEfiStatus (SvcArgs->Arg2);
}
*RetVal = SvcArgs->Arg2;
} else {
// Check error response from Callee.
// Bit 31 set means there is an error returned
// See [1], Section 13.5.5.1 MM_SP_MEMORY_ATTRIBUTES_GET_AARCH64 and
// Section 13.5.5.2 MM_SP_MEMORY_ATTRIBUTES_SET_AARCH64.
if ((SvcArgs->Arg0 & BIT31) != 0) {
return SpmMmStatusToEfiStatus (SvcArgs->Arg0);
}
*RetVal = SvcArgs->Arg0;
}
return EFI_SUCCESS;
}
/** Request the permission attributes of a memory region from S-EL0.
@param [in] UseFfaAbis Use FF-A abis or not.
@param [in] BaseAddress Base address for the memory region.
@param [out] MemoryAttributes Pointer to return the memory attributes.
@retval EFI_SUCCESS Request successfull.
@retval EFI_INVALID_PARAMETER A parameter is invalid.
@retval EFI_NOT_READY Callee is busy or not in a state to handle
this request.
@retval EFI_UNSUPPORTED This function is not implemented by the
callee.
@retval EFI_ABORTED Message target ran into an unexpected error
and has aborted.
@retval EFI_ACCESS_DENIED Access denied.
@retval EFI_OUT_OF_RESOURCES Out of memory to perform operation.
**/
STATIC
EFI_STATUS
GetMemoryPermissions (
IN BOOLEAN UseFfaAbis,
IN EFI_PHYSICAL_ADDRESS BaseAddress,
OUT UINT32 *MemoryAttributes
)
{
EFI_STATUS Status;
INT32 Ret;
ARM_SVC_ARGS SvcArgs;
UINTN Fid;
if (MemoryAttributes == NULL) {
return EFI_INVALID_PARAMETER;
}
// Prepare the message parameters.
// See [1], Section 13.5.5.1 MM_SP_MEMORY_ATTRIBUTES_GET_AARCH64.
// See [3], Section 2.8 FFA_MEM_PERM_GET
Fid = (UseFfaAbis) ? ARM_FID_FFA_MEM_PERM_GET : ARM_FID_SPM_MM_SP_GET_MEM_ATTRIBUTES;
ZeroMem (&SvcArgs, sizeof (ARM_SVC_ARGS));
SvcArgs.Arg0 = Fid;
SvcArgs.Arg1 = BaseAddress;
Status = SendMemoryPermissionRequest (UseFfaAbis, &SvcArgs, &Ret);
if (EFI_ERROR (Status)) {
*MemoryAttributes = 0;
} else {
*MemoryAttributes = Ret;
}
return Status;
}
/** Request the permission attributes of the S-EL0 memory region to be updated.
@param [in] UseFfaAbis Use FF-A abis or not.
@param [in] BaseAddress Base address for the memory region.
@param [in] Length Length of the memory region.
@param [in] Permissions Memory access controls attributes.
@retval EFI_SUCCESS Request successfull.
@retval EFI_INVALID_PARAMETER A parameter is invalid.
@retval EFI_NOT_READY Callee is busy or not in a state to handle
this request.
@retval EFI_UNSUPPORTED This function is not implemented by the
callee.
@retval EFI_ABORTED Message target ran into an unexpected error
and has aborted.
@retval EFI_ACCESS_DENIED Access denied.
@retval EFI_OUT_OF_RESOURCES Out of memory to perform operation.
**/
STATIC
EFI_STATUS
RequestMemoryPermissionChange (
IN BOOLEAN UseFfaAbis,
IN EFI_PHYSICAL_ADDRESS BaseAddress,
IN UINT64 Length,
IN UINT32 Permissions
)
{
INT32 Ret;
ARM_SVC_ARGS SvcArgs;
UINTN Fid;
// Prepare the message parameters.
// See [1], Section 13.5.5.2 MM_SP_MEMORY_ATTRIBUTES_SET_AARCH64.
// See [3], Section 2.9 FFA_MEM_PERM_SET
Fid = (UseFfaAbis) ? ARM_FID_FFA_MEM_PERM_SET : ARM_FID_SPM_MM_SP_SET_MEM_ATTRIBUTES;
ZeroMem (&SvcArgs, sizeof (ARM_SVC_ARGS));
SvcArgs.Arg0 = Fid;
SvcArgs.Arg1 = BaseAddress;
SvcArgs.Arg2 = EFI_SIZE_TO_PAGES (Length);
SvcArgs.Arg3 = Permissions;
return SendMemoryPermissionRequest (UseFfaAbis, &SvcArgs, &Ret);
}
EFI_STATUS
ArmSetMemoryRegionNoExec (
IN EFI_PHYSICAL_ADDRESS BaseAddress,
IN UINT64 Length
)
{
EFI_STATUS Status;
UINT32 MemoryAttributes;
UINT32 PermissionRequest;
BOOLEAN UseFfaAbis;
UINTN Size;
UseFfaAbis = IsFfaMemoryAbiSupported ();
Size = EFI_PAGE_SIZE;
while (Length > 0) {
Status = GetMemoryPermissions (UseFfaAbis, BaseAddress, &MemoryAttributes);
if (EFI_ERROR (Status)) {
break;
}
if (UseFfaAbis) {
PermissionRequest = ARM_FFA_SET_MEM_ATTR_MAKE_PERM_REQUEST (
MemoryAttributes,
ARM_FFA_SET_MEM_ATTR_CODE_PERM_XN
);
} else {
PermissionRequest = ARM_SPM_MM_SET_MEM_ATTR_MAKE_PERM_REQUEST (
MemoryAttributes,
ARM_SPM_MM_SET_MEM_ATTR_CODE_PERM_XN
);
}
if (Length < Size) {
Length = Size;
}
Status = RequestMemoryPermissionChange (
UseFfaAbis,
BaseAddress,
Size,
PermissionRequest
);
if (EFI_ERROR (Status)) {
return Status;
}
Length -= Size;
BaseAddress += Size;
} // while
return Status;
}
EFI_STATUS
ArmClearMemoryRegionNoExec (
IN EFI_PHYSICAL_ADDRESS BaseAddress,
IN UINT64 Length
)
{
EFI_STATUS Status;
UINT32 MemoryAttributes;
UINT32 PermissionRequest;
BOOLEAN UseFfaAbis;
UINTN Size;
UseFfaAbis = IsFfaMemoryAbiSupported ();
Size = EFI_PAGE_SIZE;
while (Length > 0) {
Status = GetMemoryPermissions (UseFfaAbis, BaseAddress, &MemoryAttributes);
if (EFI_ERROR (Status)) {
break;
}
if (UseFfaAbis) {
PermissionRequest = ARM_FFA_SET_MEM_ATTR_MAKE_PERM_REQUEST (
MemoryAttributes,
ARM_FFA_SET_MEM_ATTR_CODE_PERM_X
);
} else {
PermissionRequest = ARM_SPM_MM_SET_MEM_ATTR_MAKE_PERM_REQUEST (
MemoryAttributes,
ARM_SPM_MM_SET_MEM_ATTR_CODE_PERM_X
);
}
if (Length < Size) {
Length = Size;
}
Status = RequestMemoryPermissionChange (
UseFfaAbis,
BaseAddress,
Size,
PermissionRequest
);
if (EFI_ERROR (Status)) {
return Status;
}
Length -= Size;
BaseAddress += Size;
} // while
return Status;
}
EFI_STATUS
ArmSetMemoryRegionReadOnly (
IN EFI_PHYSICAL_ADDRESS BaseAddress,
IN UINT64 Length
)
{
EFI_STATUS Status;
UINT32 MemoryAttributes;
UINT32 PermissionRequest;
BOOLEAN UseFfaAbis;
UINTN Size;
UseFfaAbis = IsFfaMemoryAbiSupported ();
Size = EFI_PAGE_SIZE;
while (Length > 0) {
Status = GetMemoryPermissions (UseFfaAbis, BaseAddress, &MemoryAttributes);
if (EFI_ERROR (Status)) {
break;
}
if (UseFfaAbis) {
PermissionRequest = ARM_FFA_SET_MEM_ATTR_MAKE_PERM_REQUEST (
ARM_FFA_SET_MEM_ATTR_DATA_PERM_RO,
(MemoryAttributes >> ARM_FFA_SET_MEM_ATTR_CODE_PERM_SHIFT)
);
} else {
PermissionRequest = ARM_SPM_MM_SET_MEM_ATTR_MAKE_PERM_REQUEST (
ARM_SPM_MM_SET_MEM_ATTR_DATA_PERM_RO,
(MemoryAttributes >> ARM_SPM_MM_SET_MEM_ATTR_CODE_PERM_SHIFT)
);
}
if (Length < Size) {
Length = Size;
}
Status = RequestMemoryPermissionChange (
UseFfaAbis,
BaseAddress,
Size,
PermissionRequest
);
if (EFI_ERROR (Status)) {
return Status;
}
Length -= Size;
BaseAddress += Size;
} // while
return Status;
}
EFI_STATUS
ArmClearMemoryRegionReadOnly (
IN EFI_PHYSICAL_ADDRESS BaseAddress,
IN UINT64 Length
)
{
EFI_STATUS Status;
UINT32 MemoryAttributes;
UINT32 PermissionRequest;
BOOLEAN UseFfaAbis;
UINTN Size;
UseFfaAbis = IsFfaMemoryAbiSupported ();
Size = EFI_PAGE_SIZE;
while (Length > 0) {
Status = GetMemoryPermissions (UseFfaAbis, BaseAddress, &MemoryAttributes);
if (EFI_ERROR (Status)) {
break;
}
if (UseFfaAbis) {
PermissionRequest = ARM_FFA_SET_MEM_ATTR_MAKE_PERM_REQUEST (
ARM_FFA_SET_MEM_ATTR_DATA_PERM_RW,
(MemoryAttributes >> ARM_FFA_SET_MEM_ATTR_CODE_PERM_SHIFT)
);
} else {
PermissionRequest = ARM_SPM_MM_SET_MEM_ATTR_MAKE_PERM_REQUEST (
ARM_SPM_MM_SET_MEM_ATTR_DATA_PERM_RW,
(MemoryAttributes >> ARM_SPM_MM_SET_MEM_ATTR_CODE_PERM_SHIFT)
);
}
if (Length < Size) {
Length = Size;
}
Status = RequestMemoryPermissionChange (
UseFfaAbis,
BaseAddress,
Size,
PermissionRequest
);
if (EFI_ERROR (Status)) {
return Status;
}
Length -= Size;
BaseAddress += Size;
} // while
return Status;
}
|