Skip to content

Require the Memory Attribute Protocol if Enhanced Memory Protection is supported - #170

Open
vstehle wants to merge 1 commit into
ARM-software:mainfrom
vstehle:memattr
Open

Require the Memory Attribute Protocol if Enhanced Memory Protection is supported#170
vstehle wants to merge 1 commit into
ARM-software:mainfrom
vstehle:memattr

Conversation

@vstehle

@vstehle vstehle commented Aug 20, 2026

Copy link
Copy Markdown
Collaborator

Require the EFI_MEMORY_ATTRIBUTE_PROTOCOL when the firmware supports Enhanced Memory Protection.

This allows boot components such as shim, systemd or the Linux EFI stub to control memory permissions.

https://microsoft.github.io/mu/WhatAndWhy/enhancedmemoryprotection/#enhanced-uefi-memory-protection
https://uefi.org/sites/default/files/resources/Hardening%20the%20Core%20Enhanced%20Memory%20Protection_Beebe.pdf

Require the EFI_MEMORY_ATTRIBUTE_PROTOCOL when the firmware supports
Enhanced Memory Protection, to allow boot components such as shim, systemd
or the Linux EFI stub to control memory permissions.

Signed-off-by: Vincent Stehlé <vincent.stehle@arm.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant