From: Ahmad Fatoum <a.fatoum@pengutronix.de>
To: barebox@lists.infradead.org
Cc: Ahmad Fatoum <a.fatoum@pengutronix.de>
Subject: [PATCH master] ARM64: efi-header: declare the code section writable
Date: Tue, 25 Aug 2026 09:52:46 +0200 [thread overview]
Message-ID: <20260825075248.1014060-1-a.fatoum@pengutronix.de> (raw)
CONFIG_PBL_FULLY_PIC was initially introduced to make the enough of the
early PBL position-independent, so it can execute until barebox is
relocated to EFI allocated RWX memory.
This was required because the EDK-II EFI firmware I tested against
mapped the barebox code section read-only.
While W^X is desirable, the current setup is broken: We do not check at
compile-time that there are no relocations, so compiler updates and code
changes can make this regress. Also the memory barebox allocates for
itself is RWX as we do not ask for other types of memory via NX_COMPAT.
For this reason, correctly reflect in the PE header's characteristics
that barebox as EFI payload needs to run with code section mapped RWX.
barebox running as EFI loader is unaffected.
Assisted-by: Claude:fable-5
Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de>
---
| 9 +++++++++
1 file changed, 9 insertions(+)
--git a/arch/arm/cpu/efi-header-aarch64.S b/arch/arm/cpu/efi-header-aarch64.S
index 941d0d8fdcaa..b2e891b3872c 100644
--- a/arch/arm/cpu/efi-header-aarch64.S
+++ b/arch/arm/cpu/efi-header-aarch64.S
@@ -94,8 +94,17 @@
.long 0 // PointerToLineNumbers
.short 0 // NumberOfRelocations
.short 0 // NumberOfLineNumbers
+ /*
+ * TODO: drop the WRITE here and set NX_COMPAT flag
+ *
+ * Before we can do this however, we will need a restructure of the PBL:
+ * early relocation code will need to go into its own section that's
+ * enforced at build-time to be clear of any relocations and only then
+ * we can set RX for it and RW for the data.
+ */
.long IMAGE_SCN_CNT_CODE | \
IMAGE_SCN_MEM_READ | \
+ IMAGE_SCN_MEM_WRITE | \
IMAGE_SCN_MEM_EXECUTE // Characteristics
.ascii ".data\0\0\0"
--
2.47.3
next reply other threads:[~2026-08-25 7:53 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 7:52 Ahmad Fatoum [this message]
2026-08-28 14:23 ` Sascha Hauer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825075248.1014060-1-a.fatoum@pengutronix.de \
--to=a.fatoum@pengutronix.de \
--cc=barebox@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox