From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Fri, 28 Aug 2026 16:25:17 +0200 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzxW8-008BZI-1U for lore@lore.pengutronix.de; Fri, 28 Aug 2026 16:25:17 +0200 Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id 1581E202429 for ; Fri, 28 Aug 2026 16:25:17 +0200 (CEST) Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=lists.infradead.org header.s=bombadil.20210309 header.b=DGVn6iVu; dmarc=none; spf=pass (mx1.white.stw.pengutronix.de: domain of "barebox-bounces+lore=pengutronix.de@lists.infradead.org" designates 2607:7c80:54:3::133 as permitted sender) smtp.mailfrom="barebox-bounces+lore=pengutronix.de@lists.infradead.org" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: Content-Type:MIME-Version:Date:Message-Id:Subject:References:In-Reply-To:To: From:Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=N9qlp6xRTsllBEcMM53YvPSBbHfg8Db3utgglblpcoc=; b=DGVn6iVuUQtVsNx9vPMDEYo0Vi KdOdpu2pCmAXeeTmSyPNmGUPcQN7sp/Hj1jLalLN+ko6Gbb1rBrUQjItF1qhHDkZLCAroYU0YwgeA ja9lbf0Zciszpvz/7pnW47RYu5+TWo+QjGeEKt96dGri595n75HLWmic89tcWqzuRAzVYas9kv6hI tVVNkyfSumQPRy80YztrHfMV+snRSfdOviG02p1aGt/Jw+2UuGhDxbNOlTJdVNIy4CTy3osAXBH+U YpZSrcKyGa41dlkyjE3NY1LJ9Wx4Fi2/tYD8+Ot6M272FyDtezeFTu+oO58Rjnoty6eAuMQ2jTGnJ 3SCwc9ew==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1wzxUz-00000005yQO-1gZH; Fri, 28 Aug 2026 14:24:05 +0000 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1wzxUv-00000005yPW-2SOU for barebox@lists.infradead.org; Fri, 28 Aug 2026 14:24:04 +0000 Received: from drehscheibe.grey.stw.pengutronix.de (drehscheibe.grey.stw.pengutronix.de [IPv6:2a0a:edc0:0:c01:1d::a2]) (Authenticated sender: relay-from-drehscheibe.grey.stw.pengutronix.de) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPSA id 7477D201D34; Fri, 28 Aug 2026 16:23:59 +0200 (CEST) Received: from dude02.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::28]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzxUt-003mfW-1D; Fri, 28 Aug 2026 16:23:59 +0200 Received: from [::1] (helo=dude02.red.stw.pengutronix.de) by dude02.red.stw.pengutronix.de with esmtp (Exim 4.98.2) (envelope-from ) id 1wzxUt-00000002Bq1-1JtT; Fri, 28 Aug 2026 16:23:59 +0200 From: Sascha Hauer To: barebox@lists.infradead.org, Ahmad Fatoum In-Reply-To: <20260825075248.1014060-1-a.fatoum@pengutronix.de> References: <20260825075248.1014060-1-a.fatoum@pengutronix.de> Subject: Re: [PATCH master] ARM64: efi-header: declare the code section writable Message-Id: <178792703930.522043.10001836408925445051.b4-ty@pengutronix.de> Date: Fri, 28 Aug 2026 16:23:59 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit X-Mailer: b4 0.14.3 X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260828_072401_777751_AF7C1960 X-CRM114-Status: UNSURE ( 8.98 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -1.9 (-) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: On Tue, 25 Aug 2026 09:52:46 +0200, Ahmad Fatoum wrote: > CONFIG_PBL_FULLY_PIC was initially introduced to make the enough of the > early PBL position-independent, so it can execute until barebox is [...] Content analysis details: (-1.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] 0.0 DMARC_MISSING Missing DMARC policy X-BeenThere: barebox@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "barebox" X-Spamd-Result: default: False [-57.81 / 15.00]; RECEIVED_AUTHENTICATED_BY_MX1(-50.00)[]; BAYES_HAM(-3.00)[99.99%]; DWL_DNSWL_MED(-2.00)[infradead.org:dkim]; KNOWN_LIST_ID(-1.00)[barebox.lists.infradead.org]; RCVD_IN_DNSWL_MED(-0.60)[2607:7c80:54:3::133:from,2a0a:edc0:0:1101:1d::28:received,2a0a:edc0:0:c01:1d::a2:received]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; MAILLIST(-0.20)[mailman]; R_SPF_ALLOW(-0.20)[+mx:c]; R_DKIM_ALLOW(-0.20)[lists.infradead.org:s=bombadil.20210309]; MIME_GOOD(-0.10)[text/plain]; HAS_LIST_UNSUB(-0.01)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; RCPT_COUNT_TWO(0.00)[2]; DMARC_NA(0.00)[pengutronix.de]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; RCVD_TLS_LAST(0.00)[]; ASN(0.00)[asn:7247, ipnet:2607:7c80:54::/48, country:US]; DKIM_TRACE(0.00)[lists.infradead.org:+]; RCVD_COUNT_FIVE(0.00)[5]; FROM_NEQ_ENVFROM(0.00)[s.hauer@pengutronix.de,barebox-bounces@lists.infradead.org]; FROM_HAS_DN(0.00)[]; TAGGED_FROM(0.00)[lore=pengutronix.de]; NEURAL_HAM(-0.00)[-0.997]; RCVD_VIA_SMTP_AUTH(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; TO_DN_SOME(0.00)[]; FORGED_SENDER_MAILLIST(0.00)[] X-Rspamd-Action: no action X-Rspamd-Server: mx1 X-Stat-Signature: n6hajg3qhoxztgzh958a74xmeeg3werw X-Rspamd-Queue-Id: 1581E202429 On Tue, 25 Aug 2026 09:52:46 +0200, Ahmad Fatoum wrote: > CONFIG_PBL_FULLY_PIC was initially introduced to make the enough of the > early PBL position-independent, so it can execute until barebox is > relocated to EFI allocated RWX memory. > This was required because the EDK-II EFI firmware I tested against > mapped the barebox code section read-only. > > While W^X is desirable, the current setup is broken: We do not check at > compile-time that there are no relocations, so compiler updates and code > changes can make this regress. Also the memory barebox allocates for > itself is RWX as we do not ask for other types of memory via NX_COMPAT. > > [...] Applied, thanks! [1/1] ARM64: efi-header: declare the code section writable https://git.pengutronix.de/cgit/barebox/commit/?id=42e510a258d7 (link may not be stable) Best regards, -- Sascha Hauer