Patch set version 3 looks good to me. I have reviewed and tested the changes 

Reviewed-by: Ashish Singhal <>
Tested-by: Ashish Singhal <>

From: Ard Biesheuvel <>
Sent: Wednesday, March 25, 2020 9:29 AM
To: <>
Cc: Ard Biesheuvel <>; Laszlo Ersek 
<>; Leif Lindholm <>; Ashish Singhal 
Subject: [PATCH v3 0/3] ArmPkg/ArmMmuLib AARCH64: correctness fix

External email: Use caution opening links or attachments

The new ArmMmuLib code is easier to reason about, so that is what I did:
currently, when we create mappings that cover existing table entries, we
may end up overwriting those with block entries without taking the mapping
attributes of the original table entries into account. So let's fix this.

I honestly don't know whether the original code was better at dealing with
this: I do remember some changes from Heyi that may have been related, but
the old code is not easy to follow. In any case, I didn't manage to hit this
case in practice, given that we typically start out with large mappings, and
break them down later (to set permissions), rather than the other way around.

Patch #1 adds some helpers to hide the insane way the type bits change
meaning when you change to level 3.

Patch #2 ensures that we only replace (and free) table entries with block
entries if it is guaranteed that doing so will not lose any attribute

Changes since v2:
- add patch to limit recursion to levels < 3 in FreePageTablesRecursive()

Changes since v1:
- zero newly allocated pages before splitting a block entry into a table
  entry, to avoid garbage in that page being misidentified as entry type
  attributes - this should fix the crash observed by Laszlo

Cc: Laszlo Ersek <>
Cc: Leif Lindholm <>
Cc: Ashish Singhal <>

Ard Biesheuvel (3):
  ArmPkg/ArmMmuLib AARCH64: limit recursion when freeing page tables
  ArmPkg/ArmMmuLib AARCH64: use helpers to determine table entry types
  ArmPkg/ArmMmuLib AARCH64: preserve attributes when replacing a table

 .../Library/ArmMmuLib/AArch64/ArmMmuLibCore.c | 83 +++++++++++++++----
 1 file changed, 68 insertions(+), 15 deletions(-)


This email message is for the sole use of the intended recipient(s) and may 
confidential information.  Any unauthorized review, use, disclosure or 
is prohibited.  If you are not the intended recipient, please contact the 
sender by
reply email and destroy all copies of the original message.

-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group.

View/Reply Online (#56307):
Mute This Topic:
Group Owner:
Unsubscribe:  []

Reply via email to