--- binutils-2.19/bfd/elf-bfd.h +++ binutils-2.19/bfd/elf-bfd.h @@ -1526,6 +1526,9 @@ struct elf_obj_tdata /* Segment flags for the PT_GNU_STACK segment. */ unsigned int stack_flags; + /* Segment flags for the PT_PAX_FLAGS segment. */ + unsigned int pax_flags; + /* Symbol version definitions in external objects. */ Elf_Internal_Verdef *verdef; --- binutils-2.19/bfd/elf.c +++ binutils-2.19/bfd/elf.c @@ -1136,6 +1136,7 @@ get_segment_type (unsigned int p_type) case PT_GNU_EH_FRAME: pt = "EH_FRAME"; break; case PT_GNU_STACK: pt = "STACK"; break; case PT_GNU_RELRO: pt = "RELRO"; break; + case PT_PAX_FLAGS: pt = "PAX_FLAGS"; break; default: pt = NULL; break; } return pt; @@ -2442,6 +2443,9 @@ bfd_section_from_phdr (bfd *abfd, Elf_Internal_Phdr *hdr, int index) case PT_GNU_RELRO: return _bfd_elf_make_section_from_phdr (abfd, hdr, index, "relro"); + case PT_PAX_FLAGS: + return _bfd_elf_make_section_from_phdr (abfd, hdr, index, "pax_flags"); + default: /* Check for any processor-specific program segment types. */ bed = get_elf_backend_data (abfd); @@ -3404,6 +3408,11 @@ get_program_header_size (bfd *abfd, struct bfd_link_info *info) ++segs; } + { + /* We need a PT_PAX_FLAGS segment. */ + ++segs; + } + for (s = abfd->sections; s != NULL; s = s->next) { if ((s->flags & SEC_LOAD) != 0 @@ -3983,6 +3992,20 @@ _bfd_elf_map_sections_to_segments (bfd *abfd, struct bfd_link_info *info) } } + { + amt = sizeof (struct elf_segment_map); + m = bfd_zalloc (abfd, amt); + if (m == NULL) + goto error_return; + m->next = NULL; + m->p_type = PT_PAX_FLAGS; + m->p_flags = elf_tdata (abfd)->pax_flags; + m->p_flags_valid = 1; + + *pm = m; + pm = &m->next; + } + free (sections); elf_tdata (abfd)->segment_map = mfirst; } @@ -5173,7 +5196,8 @@ rewrite_elf_program_header (bfd *ibfd, bfd *obfd) 6. PT_TLS segment includes only SHF_TLS sections. 7. SHF_TLS sections are only in PT_TLS or PT_LOAD segments. 8. PT_DYNAMIC should not contain empty sections at the beginning - (with the possible exception of .dynamic). */ + (with the possible exception of .dynamic). + 9. PT_PAX_FLAGS segments do not include any sections. */ #define IS_SECTION_IN_INPUT_SEGMENT(section, segment, bed) \ ((((segment->p_paddr \ ? IS_CONTAINED_BY_LMA (section, segment, segment->p_paddr) \ @@ -5181,6 +5205,7 @@ rewrite_elf_program_header (bfd *ibfd, bfd *obfd) && (section->flags & SEC_ALLOC) != 0) \ || IS_NOTE (segment, section)) \ && segment->p_type != PT_GNU_STACK \ + && segment->p_type != PT_PAX_FLAGS \ && (segment->p_type != PT_TLS \ || (section->flags & SEC_THREAD_LOCAL)) \ && (segment->p_type == PT_LOAD \ --- binutils-2.19/bfd/elflink.c +++ binutils-2.19/bfd/elflink.c @@ -5397,16 +5397,30 @@ bfd_elf_size_dynamic_sections (bfd *output_bfd, return TRUE; bed = get_elf_backend_data (output_bfd); + + elf_tdata (output_bfd)->pax_flags = PF_NORANDEXEC; + if (info->execheap) + elf_tdata (output_bfd)->pax_flags |= PF_NOMPROTECT; + else if (info->noexecheap) + elf_tdata (output_bfd)->pax_flags |= PF_MPROTECT; + if (info->execstack) - elf_tdata (output_bfd)->stack_flags = PF_R | PF_W | PF_X; + { + elf_tdata (output_bfd)->stack_flags = PF_R | PF_W | PF_X; + elf_tdata (output_bfd)->pax_flags |= PF_EMUTRAMP; + } else if (info->noexecstack) - elf_tdata (output_bfd)->stack_flags = PF_R | PF_W; + { + elf_tdata (output_bfd)->stack_flags = PF_R | PF_W; + elf_tdata (output_bfd)->pax_flags |= PF_NOEMUTRAMP; + } else { bfd *inputobj; asection *notesec = NULL; int exec = 0; + elf_tdata (output_bfd)->pax_flags |= PF_NOEMUTRAMP; for (inputobj = info->input_bfds; inputobj; inputobj = inputobj->link_next) @@ -5419,7 +5433,11 @@ bfd_elf_size_dynamic_sections (bfd *output_bfd, if (s) { if (s->flags & SEC_CODE) - exec = PF_X; + { + elf_tdata (output_bfd)->pax_flags &= ~PF_NOEMUTRAMP; + elf_tdata (output_bfd)->pax_flags |= PF_EMUTRAMP; + exec = PF_X; + } notesec = s; } else if (bed->default_execstack) --- binutils-2.19/binutils/readelf.c +++ binutils-2.19/binutils/readelf.c @@ -2505,6 +2505,7 @@ get_segment_type (unsigned long p_type) return "GNU_EH_FRAME"; case PT_GNU_STACK: return "GNU_STACK"; case PT_GNU_RELRO: return "GNU_RELRO"; + case PT_PAX_FLAGS: return "PAX_FLAGS"; default: if ((p_type >= PT_LOPROC) && (p_type <= PT_HIPROC)) --- binutils-2.19/include/bfdlink.h +++ binutils-2.19/include/bfdlink.h @@ -319,6 +319,14 @@ struct bfd_link_info /* TRUE if PT_GNU_RELRO segment should be created. */ unsigned int relro: 1; + /* TRUE if PT_PAX_FLAGS segment should be created with PF_NOMPROTECT + flags. */ + unsigned int execheap: 1; + + /* TRUE if PT_PAX_FLAGS segment should be created with PF_MPROTECT + flags. */ + unsigned int noexecheap: 1; + /* TRUE if we should warn when adding a DT_TEXTREL to a shared object. */ unsigned int warn_shared_textrel: 1; --- binutils-2.19/include/elf/common.h +++ binutils-2.19/include/elf/common.h @@ -360,6 +360,7 @@ #define PT_SUNW_EH_FRAME PT_GNU_EH_FRAME /* Solaris uses the same value */ #define PT_GNU_STACK (PT_LOOS + 0x474e551) /* Stack flags */ #define PT_GNU_RELRO (PT_LOOS + 0x474e552) /* Read-only after relocation */ +#define PT_PAX_FLAGS (PT_LOOS + 0x5041580) /* PaX flags */ /* Program segment permissions, in program header p_flags field. */ @@ -370,6 +371,21 @@ #define PF_MASKOS 0x0FF00000 /* New value, Oct 4, 1999 Draft */ #define PF_MASKPROC 0xF0000000 /* Processor-specific reserved bits */ +/* Flags to control PaX behavior. */ + +#define PF_PAGEEXEC (1 << 4) /* Enable PAGEEXEC */ +#define PF_NOPAGEEXEC (1 << 5) /* Disable PAGEEXEC */ +#define PF_SEGMEXEC (1 << 6) /* Enable SEGMEXEC */ +#define PF_NOSEGMEXEC (1 << 7) /* Disable SEGMEXEC */ +#define PF_MPROTECT (1 << 8) /* Enable MPROTECT */ +#define PF_NOMPROTECT (1 << 9) /* Disable MPROTECT */ +#define PF_RANDEXEC (1 << 10) /* Enable RANDEXEC */ +#define PF_NORANDEXEC (1 << 11) /* Disable RANDEXEC */ +#define PF_EMUTRAMP (1 << 12) /* Enable EMUTRAMP */ +#define PF_NOEMUTRAMP (1 << 13) /* Disable EMUTRAMP */ +#define PF_RANDMMAP (1 << 14) /* Enable RANDMMAP */ +#define PF_NORANDMMAP (1 << 15) /* Disable RANDMMAP */ + /* Values for section header, sh_type field. */ #define SHT_NULL 0 /* Section header table entry unused */ --- binutils-2.19/ld/emultempl/elf32.em +++ binutils-2.19/ld/emultempl/elf32.em @@ -2146,6 +2146,16 @@ fragment <: -[ ]*[a-f0-9]+: e8 cf fe ff ff call 0 +[ ]*[a-f0-9]+: e8 [a-f0-9]{2} fe ff ff call 0 [ ]*[a-f0-9]+: c3 ret #pass --- binutils-2.19/ld/testsuite/ld-i386/tlsbin.rd +++ binutils-2.19/ld/testsuite/ld-i386/tlsbin.rd @@ -44,6 +44,7 @@ Program Headers: LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+a0 R +0x1000 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x4 Section to Segment mapping: Segment Sections... @@ -53,6 +54,7 @@ Program Headers: 03 +.tdata .dynamic .got .got.plt * 04 +.dynamic * 05 +.tdata .tbss * + 06 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 9 entries: Offset +Info +Type +Sym.Value +Sym. Name --- binutils-2.19/ld/testsuite/ld-i386/tlsbindesc.rd +++ binutils-2.19/ld/testsuite/ld-i386/tlsbindesc.rd @@ -42,6 +42,7 @@ Program Headers: LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+a0 R +0x1000 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x4 Section to Segment mapping: Segment Sections... @@ -51,6 +52,7 @@ Program Headers: 03 +.tdata .dynamic .got .got.plt * 04 +.dynamic * 05 +.tdata .tbss * + 06 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 9 entries: Offset +Info +Type +Sym.Value +Sym. Name --- binutils-2.19/ld/testsuite/ld-i386/tlsdesc.rd +++ binutils-2.19/ld/testsuite/ld-i386/tlsdesc.rd @@ -39,6 +39,7 @@ Program Headers: LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+80 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x4 Section to Segment mapping: Segment Sections... @@ -46,6 +47,7 @@ Program Headers: 01 +.tdata .dynamic .got .got.plt * 02 +.dynamic * 03 +.tdata .tbss * + 04 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 20 entries: Offset +Info +Type +Sym.Value +Sym. Name --- binutils-2.19/ld/testsuite/ld-i386/tlsdesc.sd +++ binutils-2.19/ld/testsuite/ld-i386/tlsdesc.sd @@ -14,7 +14,7 @@ Contents of section \.got: [0-9a-f]+ 6c000000 b4ffffff 4c000000 68000000 .* [0-9a-f]+ 50000000 70000000 00000000 bcffffff .* Contents of section \.got\.plt: - [0-9a-f]+ b0150000 00000000 00000000 00000000 .* + [0-9a-f]+ d0150000 00000000 00000000 00000000 .* [0-9a-f]+ 20000000 00000000 60000000 00000000 .* [0-9a-f]+ 00000000 00000000 00000000 00000000 .* [0-9a-f]+ 40000000 +.* --- binutils-2.19/ld/testsuite/ld-i386/tlsgdesc.rd +++ binutils-2.19/ld/testsuite/ld-i386/tlsgdesc.rd @@ -36,12 +36,14 @@ Program Headers: LOAD.* LOAD.* DYNAMIC.* + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x4 Section to Segment mapping: Segment Sections... 00 +.hash .dynsym .dynstr .rel.dyn .rel.plt .plt .text * 01 +.dynamic .got .got.plt * 02 +.dynamic * + 03 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 8 entries: Offset +Info +Type +Sym.Value +Sym. Name --- binutils-2.19/ld/testsuite/ld-i386/tlsnopic.rd +++ binutils-2.19/ld/testsuite/ld-i386/tlsnopic.rd @@ -37,6 +37,7 @@ Program Headers: LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+ 0x0+24 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x4 Section to Segment mapping: Segment Sections... @@ -44,6 +45,7 @@ Program Headers: 01 +.dynamic .got .got.plt * 02 +.dynamic * 03 +.tbss * + 04 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 20 entries: Offset +Info +Type +Sym.Value +Sym. Name --- binutils-2.19/ld/testsuite/ld-i386/tlspic.rd +++ binutils-2.19/ld/testsuite/ld-i386/tlspic.rd @@ -40,6 +40,7 @@ Program Headers: LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+80 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x4 Section to Segment mapping: Segment Sections... @@ -47,6 +48,7 @@ Program Headers: 01 +.tdata .dynamic .got .got.plt * 02 +.dynamic * 03 +.tdata .tbss * + 04 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 26 entries: Offset +Info +Type +Sym.Value +Sym. Name --- binutils-2.19/ld/testsuite/ld-scripts/empty-aligned.d +++ binutils-2.19/ld/testsuite/ld-scripts/empty-aligned.d @@ -7,7 +7,9 @@ Program Headers: +Type +Offset +VirtAddr +PhysAddr +FileSiz +MemSiz +Flg +Align +LOAD +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ [RWE ]+ +0x[0-9a-f]+ + +PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x[48] Section to Segment mapping: +Segment Sections\.\.\. +00 +.text + +01 + --- binutils-2.19/ld/testsuite/ld-x86-64/hidden2.d +++ binutils-2.19/ld/testsuite/ld-x86-64/hidden2.d @@ -8,6 +8,6 @@ Disassembly of section .text: [a-f0-9]+ : -[ ]*[a-f0-9]+: e8 33 fe ff ff callq 0 +[ ]*[a-f0-9]+: e8 [a-f0-9]{2} fe ff ff callq 0 [ ]*[a-f0-9]+: c3 retq #pass --- binutils-2.19/ld/testsuite/ld-x86-64/tlsbin.rd +++ binutils-2.19/ld/testsuite/ld-x86-64/tlsbin.rd @@ -44,6 +44,7 @@ Program Headers: LOAD +0x0+122a 0x0+60122a 0x0+60122a 0x0+1e6 0x0+1e6 RW 0x200000 DYNAMIC +0x0+1290 0x0+601290 0x0+601290 0x0+140 0x0+140 RW 0x8 TLS +0x0+122a 0x0+60122a 0x0+60122a 0x0+60 0x0+a0 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x8 Section to Segment mapping: Segment Sections... @@ -53,6 +54,7 @@ Program Headers: 03 +.tdata .dynamic .got .got.plt * 04 +.dynamic * 05 +.tdata .tbss * + 06 + Relocation section '.rela.dyn' at offset 0x[0-9a-f]+ contains 4 entries: +Offset +Info +Type +Symbol's Value Symbol's Name \+ Addend --- binutils-2.19/ld/testsuite/ld-x86-64/tlsbindesc.rd +++ binutils-2.19/ld/testsuite/ld-x86-64/tlsbindesc.rd @@ -42,6 +42,7 @@ Program Headers: LOAD +0x0+11f6 0x0+6011f6 0x0+6011f6 0x0+19a 0x0+19a RW 0x200000 DYNAMIC +0x0+1258 0x0+601258 0x0+601258 0x0+100 0x0+100 RW 0x8 TLS +0x0+11f6 0x0+6011f6 0x0+6011f6 0x0+60 0x0+a0 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x8 Section to Segment mapping: Segment Sections... @@ -51,6 +52,7 @@ Program Headers: 03 +.tdata .dynamic .got .got.plt * 04 +.dynamic * 05 +.tdata .tbss * + 06 + Relocation section '.rela.dyn' at offset 0x[0-9a-f]+ contains 4 entries: +Offset +Info +Type +Symbol's Value Symbol's Name \+ Addend --- binutils-2.19/ld/testsuite/ld-x86-64/tlsdesc.rd +++ binutils-2.19/ld/testsuite/ld-x86-64/tlsdesc.rd @@ -15,7 +15,7 @@ Section Headers: +\[[ 0-9]+\] .dynstr +.* +\[[ 0-9]+\] .rela.dyn +.* +\[[ 0-9]+\] .rela.plt +.* - +\[[ 0-9]+\] .plt +PROGBITS +0+450 0+450 0+20 10 +AX +0 +0 +4 + +\[[ 0-9]+\] .plt +PROGBITS +0+488 0+488 0+20 10 +AX +0 +0 +4 +\[[ 0-9]+\] .text +PROGBITS +0+1000 0+1000 0+154 00 +AX +0 +0 4096 +\[[ 0-9]+\] .tdata +PROGBITS +0+201154 0+1154 0+60 00 WAT +0 +0 +1 +\[[ 0-9]+\] .tbss +NOBITS +0+2011b4 0+11b4 0+20 00 WAT +0 +0 +1 @@ -40,6 +40,7 @@ Program Headers: LOAD +0x0+1154 0x0+201154 0x0+201154 0x0+264 0x0+264 RW +0x200000 DYNAMIC +0x0+11b8 0x0+2011b8 0x0+2011b8 0x0+150 0x0+150 RW +0x8 TLS +0x0+1154 0x0+201154 0x0+201154 0x0+60 0x0+80 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x8 Section to Segment mapping: Segment Sections... @@ -47,6 +48,7 @@ Program Headers: 01 +.tdata .dynamic .got .got.plt * 02 +.dynamic * 03 +.tdata .tbss * + 04 + Dynamic section at offset 0x[0-9a-f]+ contains 16 entries: +Tag +Type +Name/Value @@ -59,7 +61,7 @@ Dynamic section at offset 0x[0-9a-f]+ contains 16 entries: 0x[0-9a-f]+ +\(PLTRELSZ\).* 0x[0-9a-f]+ +\(PLTREL\).* 0x[0-9a-f]+ +\(JMPREL\).* - 0x[0-9a-f]+ +\(TLSDESC_PLT\) +0x460 + 0x[0-9a-f]+ +\(TLSDESC_PLT\) +0x498 0x[0-9a-f]+ +\(TLSDESC_GOT\) +0x201348 0x[0-9a-f]+ +\(RELA\).* 0x[0-9a-f]+ +\(RELASZ\).* --- binutils-2.19/ld/testsuite/ld-x86-64/tlsgdesc.rd +++ binutils-2.19/ld/testsuite/ld-x86-64/tlsgdesc.rd @@ -36,12 +36,14 @@ Program Headers: LOAD.* LOAD.* DYNAMIC.* + PAX_FLAGS.* Section to Segment mapping: Segment Sections... 00 +.hash .dynsym .dynstr .rela.dyn .rela.plt .plt .text * 01 +.dynamic .got .got.plt * 02 +.dynamic * + 03 + Relocation section '.rela.dyn' at offset 0x[0-9a-f]+ contains 8 entries: +Offset +Info +Type +Symbol's Value Symbol's Name \+ Addend --- binutils-2.19/ld/testsuite/ld-x86-64/tlspic.rd +++ binutils-2.19/ld/testsuite/ld-x86-64/tlspic.rd @@ -40,6 +40,7 @@ Program Headers: LOAD +0x0+11ac 0x0+2011ac 0x0+2011ac 0x0+244 0x0+244 RW +0x200000 DYNAMIC +0x0+1210 0x0+201210 0x0+201210 0x0+130 0x0+130 RW +0x8 TLS +0x0+11ac 0x0+2011ac 0x0+2011ac 0x0+60 0x0+80 R +0x1 + PAX_FLAGS +0x0+ 0x0+ 0x0+ 0x0+ 0x0+ +0x8 Section to Segment mapping: Segment Sections... @@ -47,6 +48,7 @@ Program Headers: 01 +.tdata .dynamic .got .got.plt * 02 +.dynamic * 03 +.tdata .tbss * + 04 + Relocation section '.rela.dyn' at offset 0x[0-9a-f]+ contains 14 entries: +Offset +Info +Type +Symbol's Value +Symbol's Name \+ Addend