PCR 12337 - Add support for Privileged Access Never (PAN)
Summary: Add support for Privileged Access Never (PAN)
Status: NEW
Alias: None
Product: Kernel
Classification: Deos
Component: Kernel (show other PCRs)
Version: mainline
Hardware: ARM Deos
: Hold
: Enhancement
Target Milestone: mainline
Assignee: .Kernel
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2020-02-13 09:43 MST by rroffelsen
Modified: 2023-08-18 09:34 MST (History)
0 users

See Also:
Impact Assessment: Medium
Organization: DDC-I, Inc.


Attachments

Note You need to log in before you can comment on or make changes to this PCR.
Description rroffelsen 2020-02-13 09:43:54 MST
Allow boot to enable Privileged Access Never to prevent kernel mode code from accessing data that can be accessed in user mode.

Some things to be concerned about when adding this feature:
 - The use of ACCESS_USER_READABLE_READ from kernel mode. 
 - kernelModeCallback(). Perhaps the kernel can clear PAN when kernelModeCallback() calls the user provided function or globally when  debug services honored is enabled.
Comment 1 deosbugs.ccb 2021-03-26 09:38:10 MST
CCB visited this PCR on 2021-03-26-57787
Comment 2 deosbugs.ccb 2023-08-14 11:07:28 MST
CCB visited this PCR on 2023-08-14-64795
Comment 3 deosbugs.ccb 2023-08-18 09:34:37 MST
PCR to remain on HOLD for kismet, given time constraints.