Skip to content

Force enable PTI on ARM64 CPUs - #333

Merged
adrelanos merged 3 commits into
Kicksecure:masterfrom
raja-grewal:kpti
Dec 3, 2025
Merged

adrelanos merged 3 commits into
Kicksecure:masterfrom
raja-grewal:kpti

Conversation

@raja-grewal

Copy link
Copy Markdown
Contributor

This pull request force enables PTI of user and kernel address spaces on ARM64 CPUs mitigating the Meltdown vulnerability.

This was previously missed as the already used pti=on parameter only applies to X86_64 CPUs. See the kernel docs for details.

In various other areas documentation has been approved making the applicability to different architectures clearer.

Changes

Set the kpti=1 kernel boot parameter.

Update documentation in other areas relating to ARM64.

Mandatory Checklist

  • Legal agreements accepted. By contributing to this organisation, you acknowledge you have read, understood, and agree to be bound by these these agreements:

Terms of Service, Privacy Policy, Cookie Policy, E-Sign Consent, DMCA, Imprint

Optional Checklist

The following items are optional but might be requested in certain cases.

  • I have tested it locally
  • I have reviewed and updated any documentation if relevant
  • I am providing new code and test(s) for it

@ArrayBolt3

ArrayBolt3 commented Nov 30, 2025 •

Copy link
Copy Markdown
Contributor

I'm slightly confused why the README now states that page table isolation is only enabled on x86_64 CPUs when we're also adding an option that enables it on arm64 CPUs? If there aren't any objections, I'll revert that part when I merge this into my arraybolt3/trixie branch. I'm also wondering if maybe pti=on should move into cpu_mitigations.cfg.

In the event we start running out of kernel command line space, we might want to think about making some parameters arch-dependent, like pti=on and kpti=1. Not something we need to worry about right now.

@ArrayBolt3

Copy link
Copy Markdown
Contributor

Merged, but added a mention of arm64 CPUs to the README rather than removing the x86_64 mention. Ultimately the whole bit about PTI probably needs to move out of the "kernel space" section, but this will make it less confusing for the time being until we move that section.

@adrelanos
adrelanos merged commit b73a830 into Kicksecure:master Dec 3, 2025
@raja-grewal
raja-grewal deleted the kpti branch December 11, 2025 01:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants