mail archive of the barebox mailing list
 help / color / mirror / Atom feed
* [PATCH master] ARM64: efi-header: declare the code section writable
@ 2026-08-25  7:52 Ahmad Fatoum
  2026-08-28 14:23 ` Sascha Hauer
  0 siblings, 1 reply; 2+ messages in thread
From: Ahmad Fatoum @ 2026-08-25  7:52 UTC (permalink / raw)
  To: barebox; +Cc: Ahmad Fatoum

CONFIG_PBL_FULLY_PIC was initially introduced to make the enough of the
early PBL position-independent, so it can execute until barebox is
relocated to EFI allocated RWX memory.
This was required because the EDK-II EFI firmware I tested against
mapped the barebox code section read-only.

While W^X is desirable, the current setup is broken: We do not check at
compile-time that there are no relocations, so compiler updates and code
changes can make this regress. Also the memory barebox allocates for
itself is RWX as we do not ask for other types of memory via NX_COMPAT.

For this reason, correctly reflect in the PE header's characteristics
that barebox as EFI payload needs to run with code section mapped RWX.

barebox running as EFI loader is unaffected.

Assisted-by: Claude:fable-5
Signed-off-by: Ahmad Fatoum <a.fatoum@pengutronix.de>
---
 arch/arm/cpu/efi-header-aarch64.S | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/arch/arm/cpu/efi-header-aarch64.S b/arch/arm/cpu/efi-header-aarch64.S
index 941d0d8fdcaa..b2e891b3872c 100644
--- a/arch/arm/cpu/efi-header-aarch64.S
+++ b/arch/arm/cpu/efi-header-aarch64.S
@@ -94,8 +94,17 @@
 	.long	0					// PointerToLineNumbers
 	.short	0					// NumberOfRelocations
 	.short	0					// NumberOfLineNumbers
+	/*
+	 * TODO: drop the WRITE here and set NX_COMPAT flag
+	 *
+	 * Before we can do this however, we will need a restructure of the PBL:
+	 * early relocation code will need to go into its own section that's
+	 * enforced at build-time to be clear of any relocations and only then
+	 * we can set RX for it and RW for the data.
+	 */
 	.long	IMAGE_SCN_CNT_CODE | \
 		IMAGE_SCN_MEM_READ | \
+		IMAGE_SCN_MEM_WRITE | \
 		IMAGE_SCN_MEM_EXECUTE			// Characteristics
 
 	.ascii	".data\0\0\0"
-- 
2.47.3




^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH master] ARM64: efi-header: declare the code section writable
  2026-08-25  7:52 [PATCH master] ARM64: efi-header: declare the code section writable Ahmad Fatoum
@ 2026-08-28 14:23 ` Sascha Hauer
  0 siblings, 0 replies; 2+ messages in thread
From: Sascha Hauer @ 2026-08-28 14:23 UTC (permalink / raw)
  To: barebox, Ahmad Fatoum


On Tue, 25 Aug 2026 09:52:46 +0200, Ahmad Fatoum wrote:
> CONFIG_PBL_FULLY_PIC was initially introduced to make the enough of the
> early PBL position-independent, so it can execute until barebox is
> relocated to EFI allocated RWX memory.
> This was required because the EDK-II EFI firmware I tested against
> mapped the barebox code section read-only.
> 
> While W^X is desirable, the current setup is broken: We do not check at
> compile-time that there are no relocations, so compiler updates and code
> changes can make this regress. Also the memory barebox allocates for
> itself is RWX as we do not ask for other types of memory via NX_COMPAT.
> 
> [...]

Applied, thanks!

[1/1] ARM64: efi-header: declare the code section writable
      https://git.pengutronix.de/cgit/barebox/commit/?id=42e510a258d7 (link may not be stable)

Best regards,
-- 
Sascha Hauer <s.hauer@pengutronix.de>




^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-28 14:25 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-25  7:52 [PATCH master] ARM64: efi-header: declare the code section writable Ahmad Fatoum
2026-08-28 14:23 ` Sascha Hauer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox