[PATCH RFC 4/6] arm64/efi: Honor EFI_MEMORY_ISA_MASK for Device-nGnRnE vs -nGnRE

From: Sven Peter

Date: Wed Jul 08 2026 - 03:23:10 EST


On Apple Silicon, access to MMIO requires Device-nGnRnE while Device-nGnRE
results in SErrors. UEFI defines the EFI_MEMORY_ISA_MASK for cases like
that which just contains the MAIR attribute bits. We cannot support any
other Device- types without changing MAIR so just warn and fall back to
the previous default, Device-nGnRE, if we encounter anything else.

Signed-off-by: Sven Peter <sven@xxxxxxxxxx>
---
arch/arm64/kernel/efi.c | 24 +++++++++++++++++++++++-
1 file changed, 23 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/kernel/efi.c b/arch/arm64/kernel/efi.c
index e40885567f9e..50ba8e9112fc 100644
--- a/arch/arm64/kernel/efi.c
+++ b/arch/arm64/kernel/efi.c
@@ -7,6 +7,7 @@
* Copyright (C) 2013, 2014 Linaro Ltd.
*/

+#include <linux/bitfield.h>
#include <linux/efi.h>
#include <linux/init.h>
#include <linux/kmemleak.h>
@@ -16,6 +17,7 @@

#include <asm/efi.h>
#include <asm/stacktrace.h>
+#include <asm/sysreg.h>
#include <asm/vmap_stack.h>


@@ -38,7 +40,27 @@ static __init ptval_t create_mapping_protection(efi_memory_desc_t *md)
u32 type = md->type;

if (type == EFI_MEMORY_MAPPED_IO) {
- pgprot_t prot = __pgprot(PROT_DEVICE_nGnRE);
+ pgprot_t prot;
+
+ if (attr & EFI_MEMORY_ISA_VALID) {
+ u8 mair = FIELD_GET(EFI_MEMORY_ISA_MASK, attr);
+
+ switch (mair) {
+ case MAIR_ATTR_DEVICE_nGnRnE:
+ prot = __pgprot(PROT_DEVICE_nGnRnE);
+ break;
+ case MAIR_ATTR_DEVICE_nGnRE:
+ prot = __pgprot(PROT_DEVICE_nGnRE);
+ break;
+ default:
+ prot = __pgprot(PROT_DEVICE_nGnRE);
+ pr_warn("unsupported MAIR attribute %#x for EFI MMIO region at 0x%llx, using Device-nGnRE\n",
+ mair, md->phys_addr);
+ break;
+ }
+ } else {
+ prot = __pgprot(PROT_DEVICE_nGnRE);
+ }

if (arm64_is_protected_mmio(md->phys_addr,
md->num_pages << EFI_PAGE_SHIFT))

--
2.55.0