lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date:   Fri, 15 Oct 2021 10:16:25 -0000
From:   "tip-bot2 for Sebastian Andrzej Siewior" <>
Cc:     Thomas Gleixner <>,
        Sebastian Andrzej Siewior <>,
        Ard Biesheuvel <>,,
Subject: [tip: efi/core] efi: Disable runtime services on RT

The following commit has been merged into the efi/core branch of tip:

Commit-ID:     d9f283ae71afef6560a7101c0a31d7ddb5b0f29a
Author:        Sebastian Andrzej Siewior <>
AuthorDate:    Fri, 24 Sep 2021 15:49:18 +02:00
Committer:     Ard Biesheuvel <>
CommitterDate: Tue, 28 Sep 2021 22:43:53 +02:00

efi: Disable runtime services on RT

Based on measurements the EFI functions get_variable /
get_next_variable take up to 2us which looks okay.
The functions get_time, set_time take around 10ms. These 10ms are too
much. Even one ms would be too much.
Ard mentioned that SetVariable might even trigger larger latencies if
the firmware will erase flash blocks on NOR.

The time-functions are used by efi-rtc and can be triggered during
run-time (either via explicit read/write or ntp sync).

The variable write could be used by pstore.
These functions can be disabled without much of a loss. The poweroff /
reboot hooks may be provided by PSCI.

Disable EFI's runtime wrappers on PREEMPT_RT.

This was observed on "EFI v2.60 by SoftIron Overdrive 1000".

Acked-by: Thomas Gleixner <>
Signed-off-by: Sebastian Andrzej Siewior <>
Signed-off-by: Ard Biesheuvel <>
 drivers/firmware/efi/efi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/firmware/efi/efi.c b/drivers/firmware/efi/efi.c
index 847f33f..39031cf 100644
--- a/drivers/firmware/efi/efi.c
+++ b/drivers/firmware/efi/efi.c
@@ -66,7 +66,7 @@ struct mm_struct efi_mm = {
 struct workqueue_struct *efi_rts_wq;
-static bool disable_runtime;
+static bool disable_runtime = IS_ENABLED(CONFIG_PREEMPT_RT);
 static int __init setup_noefi(char *arg)
 	disable_runtime = true;

Powered by blists - more mailing lists