[PATCH] arm64/efi: Avoid voluntary preemption with efi_mm installed
Ard Biesheuvel
ardb at kernel.org
Tue Aug 11 07:19:30 PDT 2026
On Tue, 11 Aug 2026, at 16:04, Will Deacon wrote:
> Gus reports a bad kernel memory access when using software PAN
> (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime
> services:
>
> Unable to handle kernel access to user memory outside uaccess routines
> at virtual address 00000000f322ff30
> Mem abort info:
> ESR = 0x0000000096000004
> FSC = 0x04: level 0 translation fault
> Internal error: Oops: 0000000096000004 [#1] SMP
> Workqueue: efi_rts_wq efi_call_rts
> pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
> pc : efi_call_rts+0xd8/0x288
> Call trace:
> efi_call_rts+0xd8/0x288 (P)
> process_one_work+0x178/0x4f8
> worker_thread+0x194/0x328
>
> This is because the fpsimd context management code called from
> __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI
> code with an incorrect value for TTBR0_EL1 thanks to the deferred mm
> switching used by the software PAN implementation.
>
> Since EFI runtime services cannot preempt voluntarily and because the
> fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply
> reorder the fpsimd switch so that it occurs before we change the
> page-table.
>
> Cc: Ard Biesheuvel <ardb at kernel.org>
> Reported-by: Gus Bourg <gus at bourg.net>
> Tested-by: Gus Bourg <gus at bourg.net>
> Fixes: a5baf582f4c0 ("arm64/efi: Call EFI runtime services without
> disabling preemption")
> Link:
> https://lore.kernel.org/all/20260806000144.3388823-1-gus@bourg.net/
> Signed-off-by: Will Deacon <will at kernel.org>
Reviewed-by: Ard Biesheuvel <ardb at kernel.org>
More information about the linux-arm-kernel
mailing list