[PATCH master] ARM64: efi-header: declare the code section writable
Ahmad Fatoum
a.fatoum at pengutronix.de
Tue Aug 25 00:52:46 PDT 2026
CONFIG_PBL_FULLY_PIC was initially introduced to make the enough of the
early PBL position-independent, so it can execute until barebox is
relocated to EFI allocated RWX memory.
This was required because the EDK-II EFI firmware I tested against
mapped the barebox code section read-only.
While W^X is desirable, the current setup is broken: We do not check at
compile-time that there are no relocations, so compiler updates and code
changes can make this regress. Also the memory barebox allocates for
itself is RWX as we do not ask for other types of memory via NX_COMPAT.
For this reason, correctly reflect in the PE header's characteristics
that barebox as EFI payload needs to run with code section mapped RWX.
barebox running as EFI loader is unaffected.
Assisted-by: Claude:fable-5
Signed-off-by: Ahmad Fatoum <a.fatoum at pengutronix.de>
---
arch/arm/cpu/efi-header-aarch64.S | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/arch/arm/cpu/efi-header-aarch64.S b/arch/arm/cpu/efi-header-aarch64.S
index 941d0d8fdcaa..b2e891b3872c 100644
--- a/arch/arm/cpu/efi-header-aarch64.S
+++ b/arch/arm/cpu/efi-header-aarch64.S
@@ -94,8 +94,17 @@
.long 0 // PointerToLineNumbers
.short 0 // NumberOfRelocations
.short 0 // NumberOfLineNumbers
+ /*
+ * TODO: drop the WRITE here and set NX_COMPAT flag
+ *
+ * Before we can do this however, we will need a restructure of the PBL:
+ * early relocation code will need to go into its own section that's
+ * enforced at build-time to be clear of any relocations and only then
+ * we can set RX for it and RW for the data.
+ */
.long IMAGE_SCN_CNT_CODE | \
IMAGE_SCN_MEM_READ | \
+ IMAGE_SCN_MEM_WRITE | \
IMAGE_SCN_MEM_EXECUTE // Characteristics
.ascii ".data\0\0\0"
--
2.47.3
More information about the barebox
mailing list