[PATCH v4 3/5] AArch64 tests: remove RWX permissions on segments

Richard Earnshaw Richard.Earnshaw@arm.com
Tue Jun 10 16:32:53 GMT 2025


On 22/05/2025 15:35, Matthieu Longo wrote:
> aarch64.ld is the linker script used by most of the relocation tests in AArch64
> testsuite. The script does not provide information enough to the linker to assess
> the right set of permisssions on segments (i.e. Read/Write/Execute).
> This insufficiency caused the linker to bundle all the sections in a same segment
> with the union of all the required permissions, i.e. RWX.
> A segment with such lax permissions constitutes a security hole, so the linker
> emits the following warning message:
>      <ELF file> has a LOAD segment with RWX permissions.
> This warning message is noisy in the tests, and has no reason to exist.
> 
> This issue can be addressed in two ways:
> - either by providing the right set of permissions on a section so that the
>    linker assigns them to a segment with compatible permissions.
> - or by providing alignment constraints so that the linker can move the sections
>    automatically to a new segment and set the right permission for non-executable
>    data.
> 
> The second option seems to be the preferred approach, even if not explicitly
> recommended. Examples of linker scripts for AArch64 are available at [1].
> 
> [1]: https://developer.arm.com/documentation/dui0474/m/gnu-ld-script-support-in
>       -armlink/default-gnu-ld-scripts-used-by-armlink/default-ld-script-when
>       -building-an-executable?lang=en
> ---
>   ld/testsuite/ld-aarch64/aarch64.ld          | 20 ++++---
>   ld/testsuite/ld-aarch64/gc-got-relocs.d     | 15 +++---
>   ld/testsuite/ld-aarch64/gc-plt-relocs.d     | 60 ++++++++++-----------
>   ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d |  4 +-
>   ld/testsuite/ld-aarch64/gc-relocs-257.d     |  4 +-
>   ld/testsuite/ld-aarch64/gc-tls-relocs.d     | 14 ++---
>   6 files changed, 61 insertions(+), 56 deletions(-)
> 
> diff --git a/ld/testsuite/ld-aarch64/aarch64.ld b/ld/testsuite/ld-aarch64/aarch64.ld
> index 4676cd41f1c..3d7958c6044 100644
> --- a/ld/testsuite/ld-aarch64/aarch64.ld
> +++ b/ld/testsuite/ld-aarch64/aarch64.ld
> @@ -3,17 +3,23 @@ OUTPUT_ARCH(aarch64)
>   ENTRY(_start)
>   SECTIONS
>   {
> -  /* Read-only sections, merged into text segment: */
> -  PROVIDE (__executable_start = 0x8000); . = 0x8000;
> -  .text           :
> +  PROVIDE (__executable_start = 0x8000);
> +  . = SEGMENT_START("text-segment", 0x8000) + SIZEOF_HEADERS;
> +  /* Start of the executable code region.  */
> +  . = 0x9000;
> +  .plt              : ALIGN(16) { *(.plt) *(.iplt) }
> +  . = 0x10000;
> +  .text             :
>     {
>       *(.before)
>       *(.text)
>       *(.after)
>     } =0
> -  . = 0x9000;
> -  .got            : { *(.got) *(.got.plt)}
>     . = 0x12340000;
> -  .far : { *(.far) }
> -  .ARM.attributes 0 : { *(.ARM.attributes) }
> +  .far              : { *(.far) }
> +  /* Start of the Read Write Data region.  */
> +  . = ALIGN (CONSTANT (MAXPAGESIZE)) - ((CONSTANT (MAXPAGESIZE) - .) & (CONSTANT (MAXPAGESIZE) - 1));
> +  .got              : { *(.got) *(.got.plt)}
> +  /* Start of the metadata region.  */
> +  .ARM.attributes 0 : { KEEP (*(.ARM.atttributes)) }

This re-introduces the typo that you fixed in the previous patch.

Otherwise OK.

R.
>   }
> diff --git a/ld/testsuite/ld-aarch64/gc-got-relocs.d b/ld/testsuite/ld-aarch64/gc-got-relocs.d
> index 6525d10119c..a1821c38305 100644
> --- a/ld/testsuite/ld-aarch64/gc-got-relocs.d
> +++ b/ld/testsuite/ld-aarch64/gc-got-relocs.d
> @@ -12,15 +12,14 @@
>   .*:     file format elf64-(little|big)aarch64
>   
>   SYMBOL TABLE:
> -0+8000 l    d  \.text	0+ \.text
> -0+0000 l    df \*ABS\*	0+ .*
> -0+8000 g       \.text	0+ _start
> +0+10000 l    d  \.text	0+ \.text
> +0+00000 l    df \*ABS\*	0+ .*
> +0+10000 g       \.text	0+ _start
>   
>   Contents of section .text:
> - 8000 1f2003d5                             .*
> + 10000 1f2003d5                             .*
>   
> -Disassembly of section .text:
> -
> -0+8000 \<_start>:
> -    8000:	d503201f 	nop
> +Disassembly of section \.text:
>   
> +0+10000 \<_start>:
> +   10000:	d503201f 	nop
> diff --git a/ld/testsuite/ld-aarch64/gc-plt-relocs.d b/ld/testsuite/ld-aarch64/gc-plt-relocs.d
> index 5c9b5fe5577..ac455f81e94 100644
> --- a/ld/testsuite/ld-aarch64/gc-plt-relocs.d
> +++ b/ld/testsuite/ld-aarch64/gc-plt-relocs.d
> @@ -13,36 +13,36 @@
>   .*:     file format elf64-(little|big)aarch64
>   
>   DYNAMIC SYMBOL TABLE:
> -0+8000 g    DF \.text	0+4 _start
> -0+0000      D  \*UND\*	0+ foo
> -0+8008 g    DF \.text	0+ bar
> +0+10000 g    DF \.text	0+4 _start
> +0+00000      D  \*UND\*	0+ foo
> +0+10008 g    DF \.text	0+ bar
> +
> +Disassembly of section \.plt:
> +
> +0+9000 \<\.plt\>:
> +    9000:	a9bf7bf0 	stp	x16, x30, \[sp, #-16\]!
> +    9004:	f00919b0 	adrp	x16, 12340000 \<_GLOBAL_OFFSET_TABLE_\>
> +    9008:	f9400e11 	ldr	x17, \[x16, #24\]
> +    900c:	91006210 	add	x16, x16, #0x18
> +    9010:	d61f0220 	br	x17
> +    9014:	d503201f 	nop
> +    9018:	d503201f 	nop
> +    901c:	d503201f 	nop
> +    9020:	f00919b0 	adrp	x16, 12340000 \<_GLOBAL_OFFSET_TABLE_\>
> +    9024:	f9401211 	ldr	x17, \[x16, #32\]
> +    9028:	91008210 	add	x16, x16, #0x20
> +    902c:	d61f0220 	br	x17
>   
>   Disassembly of section .text:
>   
> -0+8000 \<_start\>:
> -    8000:	9400000c 	bl	8030 \<.*>
> -
> -0+8004 \<hidfn\>:
> -    8004:	8a000000 	and	x0, x0, x0
> -
> -0+8008 \<bar\>:
> -    8008:	14000001 	b	800c \<foo\>
> -
> -0+800c \<foo\>:
> -    800c:	97fffffe 	bl	8004 \<hidfn\>
> -
> -Disassembly of section .plt:
> -
> -0+8010 \<\.plt\>:
> -    8010:	a9bf7bf0 	stp	x16, x30, \[sp, #-16\]!
> -    8014:	b0000010 	adrp	x16, 9000 .*
> -    8018:	f9400e11 	ldr	x17, \[x16, #24\]
> -    801c:	91006210 	add	x16, x16, #0x18
> -    8020:	d61f0220 	br	x17
> -    8024:	d503201f 	nop
> -    8028:	d503201f 	nop
> -    802c:	d503201f 	nop
> -    8030:	b0000010 	adrp	x16, 9000 .*
> -    8034:	f9401211 	ldr	x17, \[x16, #32\]
> -    8038:	91008210 	add	x16, x16, #0x20
> -    803c:	d61f0220 	br	x17
> +0+10000 \<_start\>:
> +   10000:	97ffe408 	bl	9020 \<\.plt\+0x20>
> +
> +0+10004 \<hidfn\>:
> +   10004:	8a000000 	and	x0, x0, x0
> +
> +0+10008 \<bar\>:
> +   10008:	14000001 	b	1000c \<foo\>
> +
> +0+1000c \<foo\>:
> +   1000c:	97fffffe 	bl	10004 \<hidfn\>
> diff --git a/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d b/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d
> index 56fcfa4fdc4..2e5e4c61db0 100644
> --- a/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d
> +++ b/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d
> @@ -13,5 +13,5 @@
>   
>   Disassembly of section .text:
>   
> -0+8000 \<_start\>:
> -    8000:	d503201f 	nop
> +0+10000 \<_start\>:
> +   10000:	d503201f 	nop
> diff --git a/ld/testsuite/ld-aarch64/gc-relocs-257.d b/ld/testsuite/ld-aarch64/gc-relocs-257.d
> index ffa75719027..022b407f4d6 100644
> --- a/ld/testsuite/ld-aarch64/gc-relocs-257.d
> +++ b/ld/testsuite/ld-aarch64/gc-relocs-257.d
> @@ -12,5 +12,5 @@
>   
>   Disassembly of section .text:
>   
> -0+8000 \<_start\>:
> -    8000:	d503201f 	nop
> +0+10000 \<_start\>:
> +   10000:	d503201f 	nop
> diff --git a/ld/testsuite/ld-aarch64/gc-tls-relocs.d b/ld/testsuite/ld-aarch64/gc-tls-relocs.d
> index 38637dce07c..2f2210ce592 100644
> --- a/ld/testsuite/ld-aarch64/gc-tls-relocs.d
> +++ b/ld/testsuite/ld-aarch64/gc-tls-relocs.d
> @@ -13,15 +13,15 @@
>   .*:     file format elf64-(little|big)aarch64
>   
>   SYMBOL TABLE:
> -0+8000 l    d  \.text	0+ \.text
> -0+0000 l    df \*ABS\*	0+ .*
> -0+8000 g       \.text	0+ _start
> +0+10000 l    d  \.text	0+ \.text
> +0+00000 l    df \*ABS\*	0+ .*
> +0+10000 g       \.text	0+ _start
>   
>   Contents of section .text:
> - 8000 1f2003d5                             .*
> + 10000 1f2003d5                             .*
>   
> -Disassembly of section .text:
> +Disassembly of section \.text:
>   
> -0+8000 \<_start>:
> -    8000:	d503201f 	nop
> +0+10000 \<_start>:
> +   10000:	d503201f 	nop
>   



More information about the Binutils mailing list