[PATCH 14/19] ARM: linker script: create separate PT_LOAD segments for text, rodata, and data
Sascha Hauer
s.hauer at pengutronix.de
Mon Jan 5 03:26:55 PST 2026
Fix the linker scripts to generate three distinct PT_LOAD segments with
correct permissions instead of combining .rodata with .data.
Before this fix, the linker auto-generated only two PT_LOAD segments:
1. Text segment (PF_R|PF_X)
2. Data segment (PF_R|PF_W) - containing .rodata, .data, .bss, etc.
This caused .rodata to be mapped with write permissions when
pbl_mmu_setup_from_elf() set up MMU permissions based on ELF segments,
defeating the W^X protection that commit d9ccb0cf14 intended to provide.
With explicit PHDRS directives, we now generate three segments:
1. text segment (PF_R|PF_X): .text and related code sections
2. rodata segment (PF_R): .rodata and unwind tables
3. data segment (PF_R|PF_W): .data, .bss, and related sections
This ensures pbl_mmu_setup_from_elf() correctly maps .rodata as
read-only (MAP_CACHED_RO) instead of read-write (MAP_CACHED).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
Signed-off-by: Sascha Hauer <s.hauer at pengutronix.de>
---
arch/arm/include/asm/barebox.lds.h | 14 +++++++-------
arch/arm/lib/pbl.lds.S | 2 +-
arch/arm/lib32/barebox.lds.S | 35 +++++++++++++++++++++++------------
arch/arm/lib64/barebox.lds.S | 31 +++++++++++++++++++++----------
4 files changed, 52 insertions(+), 30 deletions(-)
diff --git a/arch/arm/include/asm/barebox.lds.h b/arch/arm/include/asm/barebox.lds.h
index 72aabe155b5c9e8b9159c7da6c6f0fa1f7b93375..a3ccea91196ccce71c54483c5e1ad5caeb3c1d32 100644
--- a/arch/arm/include/asm/barebox.lds.h
+++ b/arch/arm/include/asm/barebox.lds.h
@@ -14,13 +14,13 @@
#define BAREBOX_RELOCATION_TYPE rela
#endif
-#define BAREBOX_RELOCATION_TABLE \
- .rel_dyn_start : { *(.__rel_dyn_start) } \
- .BAREBOX_RELOCATION_TYPE.dyn : { *(.BAREBOX_RELOCATION_TYPE*) } \
- .rel_dyn_end : { *(.__rel_dyn_end) } \
- .__dynsym_start : { *(.__dynsym_start) } \
- .dynsym : { *(.dynsym) } \
- .__dynsym_end : { *(.__dynsym_end) }
+#define BAREBOX_RELOCATION_TABLE(PHDR) \
+ .rel_dyn_start : { *(.__rel_dyn_start) } PHDR \
+ .BAREBOX_RELOCATION_TYPE.dyn : { *(.BAREBOX_RELOCATION_TYPE*) } PHDR \
+ .rel_dyn_end : { *(.__rel_dyn_end) } PHDR \
+ .__dynsym_start : { *(.__dynsym_start) } PHDR \
+ .dynsym : { *(.dynsym) } PHDR \
+ .__dynsym_end : { *(.__dynsym_end) } PHDR
#include <asm-generic/barebox.lds.h>
diff --git a/arch/arm/lib/pbl.lds.S b/arch/arm/lib/pbl.lds.S
index 53b21084cff2e3d916cd37485281f2f78166c37d..98e25a543525e2bc16b8d10ec24c2ba6b8cbec90 100644
--- a/arch/arm/lib/pbl.lds.S
+++ b/arch/arm/lib/pbl.lds.S
@@ -95,7 +95,7 @@ SECTIONS
}
__shasum_end = .;
- BAREBOX_RELOCATION_TABLE
+ BAREBOX_RELOCATION_TABLE()
pbl_code_size = .;
diff --git a/arch/arm/lib32/barebox.lds.S b/arch/arm/lib32/barebox.lds.S
index 9b2b65e2f17d62d5134fc367621cce733dcea06a..c91c101d6aa5c2a0fcbf79a151a4234d924b3881 100644
--- a/arch/arm/lib32/barebox.lds.S
+++ b/arch/arm/lib32/barebox.lds.S
@@ -7,14 +7,23 @@
OUTPUT_FORMAT(BAREBOX_OUTPUT_FORMAT)
OUTPUT_ARCH(BAREBOX_OUTPUT_ARCH)
ENTRY(start)
+
+PHDRS
+{
+ text PT_LOAD FLAGS(5); /* PF_R | PF_X */
+ rodata PT_LOAD FLAGS(4); /* PF_R */
+ data PT_LOAD FLAGS(6); /* PF_R | PF_W */
+ dynamic PT_DYNAMIC FLAGS(6); /* PF_R | PF_W */
+}
+
SECTIONS
{
. = 0x0;
- .image_start : { *(.__image_start) }
+ .image_start : { *(.__image_start) } :text
. = ALIGN(4);
- ._text : { *(._text) }
+ ._text : { *(._text) } :text
.text :
{
_stext = .;
@@ -31,7 +40,7 @@ SECTIONS
KEEP(*(.text_inplace_exceptions*))
__inplace_exceptions_stop = .;
*(.text*)
- }
+ } :text
BAREBOX_BARE_INIT_SIZE
. = ALIGN(4096);
@@ -39,7 +48,7 @@ SECTIONS
.rodata : {
*(.rodata*)
RO_DATA_SECTION
- }
+ } :rodata
#ifdef CONFIG_ARM_UNWIND
/*
@@ -50,12 +59,12 @@ SECTIONS
__start_unwind_idx = .;
*(.ARM.exidx*)
__stop_unwind_idx = .;
- }
+ } :rodata
.ARM.unwind_tab : {
__start_unwind_tab = .;
*(.ARM.extab*)
__stop_unwind_tab = .;
- }
+ } :rodata
#endif
. = ALIGN(4096);
__end_rodata = .;
@@ -65,19 +74,21 @@ SECTIONS
. = ALIGN(4);
.data : { *(.data*)
CONSTRUCTORS
- }
+ } :data
+
+ .dynamic : { *(.dynamic) } :data :dynamic
. = .;
- BAREBOX_RELOCATION_TABLE
+ BAREBOX_RELOCATION_TABLE(:data)
_edata = .;
- .image_end : { *(.__image_end) }
+ .image_end : { *(.__image_end) } :data
. = ALIGN(4);
- .__bss_start : { *(.__bss_start) }
- .bss : { *(.bss*) }
- .__bss_stop : { *(.__bss_stop) }
+ .__bss_start : { *(.__bss_start) } :data
+ .bss : { *(.bss*) } :data
+ .__bss_stop : { *(.__bss_stop) } :data
#ifdef CONFIG_ARM_SECURE_MONITOR
. = ALIGN(16);
diff --git a/arch/arm/lib64/barebox.lds.S b/arch/arm/lib64/barebox.lds.S
index e2f1164c47f7e5d300028d112a6e90e2fa368c65..603e0ab77490d3221fbfd3341250e6dcae840d91 100644
--- a/arch/arm/lib64/barebox.lds.S
+++ b/arch/arm/lib64/barebox.lds.S
@@ -6,14 +6,23 @@
OUTPUT_FORMAT(BAREBOX_OUTPUT_FORMAT)
OUTPUT_ARCH(BAREBOX_OUTPUT_ARCH)
ENTRY(start)
+
+PHDRS
+{
+ text PT_LOAD FLAGS(5); /* PF_R | PF_X */
+ rodata PT_LOAD FLAGS(4); /* PF_R */
+ data PT_LOAD FLAGS(6); /* PF_R | PF_W */
+ dynamic PT_DYNAMIC FLAGS(6); /* PF_R | PF_W */
+}
+
SECTIONS
{
. = 0x0;
- .image_start : { *(.__image_start) }
+ .image_start : { *(.__image_start) } :text
. = ALIGN(4);
- ._text : { *(._text) }
+ ._text : { *(._text) } :text
.text :
{
_stext = .;
@@ -22,7 +31,7 @@ SECTIONS
*(.text_bare_init*)
__bare_init_end = .;
*(.text*)
- }
+ } :text
BAREBOX_BARE_INIT_SIZE
. = ALIGN(4096);
@@ -30,7 +39,7 @@ SECTIONS
.rodata : {
*(.rodata*)
RO_DATA_SECTION
- }
+ } :rodata
. = ALIGN(4096);
@@ -38,18 +47,20 @@ SECTIONS
_etext = .;
_sdata = .;
- .data : { *(.data*) }
+ .data : { *(.data*) } :data
+
+ .dynamic : { *(.dynamic) } :data :dynamic
- BAREBOX_RELOCATION_TABLE
+ BAREBOX_RELOCATION_TABLE(:data)
_edata = .;
- .image_end : { *(.__image_end) }
+ .image_end : { *(.__image_end) } :data
. = ALIGN(4);
- .__bss_start : { *(.__bss_start) }
- .bss : { *(.bss*) }
- .__bss_stop : { *(.__bss_stop) }
+ .__bss_start : { *(.__bss_start) } :data
+ .bss : { *(.bss*) } :data
+ .__bss_stop : { *(.__bss_stop) } :data
_end = .;
_barebox_image_size = __bss_start;
}
--
2.47.3
More information about the barebox
mailing list