Re: [PATCH] arm64/efi: Avoid voluntary preemption with efi_mm installed

"Ard Biesheuvel" <[email protected]>
Newsgroups org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel
Message-ID <[email protected]>

On Tue, 11 Aug 2026, at 16:04, Will Deacon wrote:
> Gus reports a bad kernel memory access when using software PAN
> (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime
> services:
>
>   Unable to handle kernel access to user memory outside uaccess routines
>     at virtual address 00000000f322ff30
>   Mem abort info:
>     ESR = 0x0000000096000004
>     FSC = 0x04: level 0 translation fault
>   Internal error: Oops: 0000000096000004 [#1]  SMP
>   Workqueue: efi_rts_wq efi_call_rts
>   pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)
>   pc : efi_call_rts+0xd8/0x288
>   Call trace:
>    efi_call_rts+0xd8/0x288 (P)
>    process_one_work+0x178/0x4f8
>    worker_thread+0x194/0x328
>
> This is because the fpsimd context management code called from
> __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI
> code with an incorrect value for TTBR0_EL1 thanks to the deferred mm
> switching used by the software PAN implementation.
>
> Since EFI runtime services cannot preempt voluntarily and because the
> fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply
> reorder the fpsimd switch so that it occurs before we change the
> page-table.
>
> Cc: Ard Biesheuvel <[email protected]>
> Reported-by: Gus Bourg <[email protected]>
> Tested-by: Gus Bourg <[email protected]>
> Fixes: a5baf582f4c0 ("arm64/efi: Call EFI runtime services without 
> disabling preemption")
> Link: 
> https://lore.kernel.org/all/[email protected]/
> Signed-off-by: Will Deacon <[email protected]>

Reviewed-by: Ard Biesheuvel <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.