[PATCH v4 3/5] AArch64 tests: remove RWX permissions on segments
Richard Earnshaw
Richard.Earnshaw@arm.com
Tue Jun 10 16:32:53 GMT 2025
On 22/05/2025 15:35, Matthieu Longo wrote:
> aarch64.ld is the linker script used by most of the relocation tests in AArch64
> testsuite. The script does not provide information enough to the linker to assess
> the right set of permisssions on segments (i.e. Read/Write/Execute).
> This insufficiency caused the linker to bundle all the sections in a same segment
> with the union of all the required permissions, i.e. RWX.
> A segment with such lax permissions constitutes a security hole, so the linker
> emits the following warning message:
> <ELF file> has a LOAD segment with RWX permissions.
> This warning message is noisy in the tests, and has no reason to exist.
>
> This issue can be addressed in two ways:
> - either by providing the right set of permissions on a section so that the
> linker assigns them to a segment with compatible permissions.
> - or by providing alignment constraints so that the linker can move the sections
> automatically to a new segment and set the right permission for non-executable
> data.
>
> The second option seems to be the preferred approach, even if not explicitly
> recommended. Examples of linker scripts for AArch64 are available at [1].
>
> [1]: https://developer.arm.com/documentation/dui0474/m/gnu-ld-script-support-in
> -armlink/default-gnu-ld-scripts-used-by-armlink/default-ld-script-when
> -building-an-executable?lang=en
> ---
> ld/testsuite/ld-aarch64/aarch64.ld | 20 ++++---
> ld/testsuite/ld-aarch64/gc-got-relocs.d | 15 +++---
> ld/testsuite/ld-aarch64/gc-plt-relocs.d | 60 ++++++++++-----------
> ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d | 4 +-
> ld/testsuite/ld-aarch64/gc-relocs-257.d | 4 +-
> ld/testsuite/ld-aarch64/gc-tls-relocs.d | 14 ++---
> 6 files changed, 61 insertions(+), 56 deletions(-)
>
> diff --git a/ld/testsuite/ld-aarch64/aarch64.ld b/ld/testsuite/ld-aarch64/aarch64.ld
> index 4676cd41f1c..3d7958c6044 100644
> --- a/ld/testsuite/ld-aarch64/aarch64.ld
> +++ b/ld/testsuite/ld-aarch64/aarch64.ld
> @@ -3,17 +3,23 @@ OUTPUT_ARCH(aarch64)
> ENTRY(_start)
> SECTIONS
> {
> - /* Read-only sections, merged into text segment: */
> - PROVIDE (__executable_start = 0x8000); . = 0x8000;
> - .text :
> + PROVIDE (__executable_start = 0x8000);
> + . = SEGMENT_START("text-segment", 0x8000) + SIZEOF_HEADERS;
> + /* Start of the executable code region. */
> + . = 0x9000;
> + .plt : ALIGN(16) { *(.plt) *(.iplt) }
> + . = 0x10000;
> + .text :
> {
> *(.before)
> *(.text)
> *(.after)
> } =0
> - . = 0x9000;
> - .got : { *(.got) *(.got.plt)}
> . = 0x12340000;
> - .far : { *(.far) }
> - .ARM.attributes 0 : { *(.ARM.attributes) }
> + .far : { *(.far) }
> + /* Start of the Read Write Data region. */
> + . = ALIGN (CONSTANT (MAXPAGESIZE)) - ((CONSTANT (MAXPAGESIZE) - .) & (CONSTANT (MAXPAGESIZE) - 1));
> + .got : { *(.got) *(.got.plt)}
> + /* Start of the metadata region. */
> + .ARM.attributes 0 : { KEEP (*(.ARM.atttributes)) }
This re-introduces the typo that you fixed in the previous patch.
Otherwise OK.
R.
> }
> diff --git a/ld/testsuite/ld-aarch64/gc-got-relocs.d b/ld/testsuite/ld-aarch64/gc-got-relocs.d
> index 6525d10119c..a1821c38305 100644
> --- a/ld/testsuite/ld-aarch64/gc-got-relocs.d
> +++ b/ld/testsuite/ld-aarch64/gc-got-relocs.d
> @@ -12,15 +12,14 @@
> .*: file format elf64-(little|big)aarch64
>
> SYMBOL TABLE:
> -0+8000 l d \.text 0+ \.text
> -0+0000 l df \*ABS\* 0+ .*
> -0+8000 g \.text 0+ _start
> +0+10000 l d \.text 0+ \.text
> +0+00000 l df \*ABS\* 0+ .*
> +0+10000 g \.text 0+ _start
>
> Contents of section .text:
> - 8000 1f2003d5 .*
> + 10000 1f2003d5 .*
>
> -Disassembly of section .text:
> -
> -0+8000 \<_start>:
> - 8000: d503201f nop
> +Disassembly of section \.text:
>
> +0+10000 \<_start>:
> + 10000: d503201f nop
> diff --git a/ld/testsuite/ld-aarch64/gc-plt-relocs.d b/ld/testsuite/ld-aarch64/gc-plt-relocs.d
> index 5c9b5fe5577..ac455f81e94 100644
> --- a/ld/testsuite/ld-aarch64/gc-plt-relocs.d
> +++ b/ld/testsuite/ld-aarch64/gc-plt-relocs.d
> @@ -13,36 +13,36 @@
> .*: file format elf64-(little|big)aarch64
>
> DYNAMIC SYMBOL TABLE:
> -0+8000 g DF \.text 0+4 _start
> -0+0000 D \*UND\* 0+ foo
> -0+8008 g DF \.text 0+ bar
> +0+10000 g DF \.text 0+4 _start
> +0+00000 D \*UND\* 0+ foo
> +0+10008 g DF \.text 0+ bar
> +
> +Disassembly of section \.plt:
> +
> +0+9000 \<\.plt\>:
> + 9000: a9bf7bf0 stp x16, x30, \[sp, #-16\]!
> + 9004: f00919b0 adrp x16, 12340000 \<_GLOBAL_OFFSET_TABLE_\>
> + 9008: f9400e11 ldr x17, \[x16, #24\]
> + 900c: 91006210 add x16, x16, #0x18
> + 9010: d61f0220 br x17
> + 9014: d503201f nop
> + 9018: d503201f nop
> + 901c: d503201f nop
> + 9020: f00919b0 adrp x16, 12340000 \<_GLOBAL_OFFSET_TABLE_\>
> + 9024: f9401211 ldr x17, \[x16, #32\]
> + 9028: 91008210 add x16, x16, #0x20
> + 902c: d61f0220 br x17
>
> Disassembly of section .text:
>
> -0+8000 \<_start\>:
> - 8000: 9400000c bl 8030 \<.*>
> -
> -0+8004 \<hidfn\>:
> - 8004: 8a000000 and x0, x0, x0
> -
> -0+8008 \<bar\>:
> - 8008: 14000001 b 800c \<foo\>
> -
> -0+800c \<foo\>:
> - 800c: 97fffffe bl 8004 \<hidfn\>
> -
> -Disassembly of section .plt:
> -
> -0+8010 \<\.plt\>:
> - 8010: a9bf7bf0 stp x16, x30, \[sp, #-16\]!
> - 8014: b0000010 adrp x16, 9000 .*
> - 8018: f9400e11 ldr x17, \[x16, #24\]
> - 801c: 91006210 add x16, x16, #0x18
> - 8020: d61f0220 br x17
> - 8024: d503201f nop
> - 8028: d503201f nop
> - 802c: d503201f nop
> - 8030: b0000010 adrp x16, 9000 .*
> - 8034: f9401211 ldr x17, \[x16, #32\]
> - 8038: 91008210 add x16, x16, #0x20
> - 803c: d61f0220 br x17
> +0+10000 \<_start\>:
> + 10000: 97ffe408 bl 9020 \<\.plt\+0x20>
> +
> +0+10004 \<hidfn\>:
> + 10004: 8a000000 and x0, x0, x0
> +
> +0+10008 \<bar\>:
> + 10008: 14000001 b 1000c \<foo\>
> +
> +0+1000c \<foo\>:
> + 1000c: 97fffffe bl 10004 \<hidfn\>
> diff --git a/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d b/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d
> index 56fcfa4fdc4..2e5e4c61db0 100644
> --- a/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d
> +++ b/ld/testsuite/ld-aarch64/gc-relocs-257-dyn.d
> @@ -13,5 +13,5 @@
>
> Disassembly of section .text:
>
> -0+8000 \<_start\>:
> - 8000: d503201f nop
> +0+10000 \<_start\>:
> + 10000: d503201f nop
> diff --git a/ld/testsuite/ld-aarch64/gc-relocs-257.d b/ld/testsuite/ld-aarch64/gc-relocs-257.d
> index ffa75719027..022b407f4d6 100644
> --- a/ld/testsuite/ld-aarch64/gc-relocs-257.d
> +++ b/ld/testsuite/ld-aarch64/gc-relocs-257.d
> @@ -12,5 +12,5 @@
>
> Disassembly of section .text:
>
> -0+8000 \<_start\>:
> - 8000: d503201f nop
> +0+10000 \<_start\>:
> + 10000: d503201f nop
> diff --git a/ld/testsuite/ld-aarch64/gc-tls-relocs.d b/ld/testsuite/ld-aarch64/gc-tls-relocs.d
> index 38637dce07c..2f2210ce592 100644
> --- a/ld/testsuite/ld-aarch64/gc-tls-relocs.d
> +++ b/ld/testsuite/ld-aarch64/gc-tls-relocs.d
> @@ -13,15 +13,15 @@
> .*: file format elf64-(little|big)aarch64
>
> SYMBOL TABLE:
> -0+8000 l d \.text 0+ \.text
> -0+0000 l df \*ABS\* 0+ .*
> -0+8000 g \.text 0+ _start
> +0+10000 l d \.text 0+ \.text
> +0+00000 l df \*ABS\* 0+ .*
> +0+10000 g \.text 0+ _start
>
> Contents of section .text:
> - 8000 1f2003d5 .*
> + 10000 1f2003d5 .*
>
> -Disassembly of section .text:
> +Disassembly of section \.text:
>
> -0+8000 \<_start>:
> - 8000: d503201f nop
> +0+10000 \<_start>:
> + 10000: d503201f nop
>
More information about the Binutils
mailing list