All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sam Edwards <cfsworks@gmail.com>
To: Tom Rini <trini@konsulko.com>,
	Heinrich Schuchardt <xypron.glpk@gmx.de>,
	Ilias Apalodimas <ilias.apalodimas@linaro.org>,
	Simon Glass <sjg@chromium.org>, Bin Meng <bmeng.cn@gmail.com>
Cc: Marek Vasut <marek.vasut+renesas@mailbox.org>,
	Sumit Garg <sumit.garg@linaro.org>,
	Peter Robinson <pbrobinson@gmail.com>,
	Richard Henderson <richard.henderson@linaro.org>,
	u-boot@lists.denx.de, Sam Edwards <CFSworks@gmail.com>
Subject: [PATCH 13/17] makefile: Add `norelro` linker option
Date: Sun, 23 Feb 2025 21:55:20 -0800	[thread overview]
Message-ID: <20250224055524.1334929-14-CFSworks@gmail.com> (raw)
In-Reply-To: <20250224055524.1334929-1-CFSworks@gmail.com>

RELRO is an instruction to a dynamic loader to make a memory range
read-only after relocations are applied, for added security. Some
linkers (e.g. LLD) require that all sections covered by the RELRO are
contiguous, so that only a single RELRO is needed. U-Boot at present
neither satisfies this requirement (e.g. x86_64 linker script currently
puts .dynamic too far from .got) nor preserves the RELRO when converting
away from ELF, therefore add `-z norelro` to global linker options.

Signed-off-by: Sam Edwards <CFSworks@gmail.com>
---
 Makefile | 1 +
 1 file changed, 1 insertion(+)

diff --git a/Makefile b/Makefile
index 87b07d8989a..c869b5c55fa 100644
--- a/Makefile
+++ b/Makefile
@@ -820,6 +820,7 @@ KBUILD_AFLAGS += $(KAFLAGS)
 KBUILD_CFLAGS += $(KCFLAGS)
 
 KBUILD_LDFLAGS  += -z noexecstack
+KBUILD_LDFLAGS  += -z norelro
 KBUILD_LDFLAGS  += $(call ld-option,--no-warn-rwx-segments)
 
 KBUILD_HOSTCFLAGS += $(if $(CONFIG_TOOLS_DEBUG),-g)
-- 
2.45.2


  parent reply	other threads:[~2025-02-24  5:57 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-02-24  5:55 [PATCH 00/17] Various toolchain compatibility fixes/improvements Sam Edwards
2025-02-24  5:55 ` [PATCH 01/17] arm: Remove stray .mmutable reference in linker script Sam Edwards
2025-02-26 14:44   ` Ilias Apalodimas
2025-02-24  5:55 ` [PATCH 02/17] arm: Exclude eabi_compat from LTO Sam Edwards
2025-03-09  8:47   ` Ilias Apalodimas
2025-02-24  5:55 ` [PATCH 03/17] arm: Add __aeabi_memclr in eabi_compat Sam Edwards
2025-03-09  8:45   ` Ilias Apalodimas
2025-02-24  5:55 ` [PATCH 04/17] arm: Add aligned-memory aliases to eabi_compat Sam Edwards
2025-03-09  8:51   ` Ilias Apalodimas
2025-02-24  5:55 ` [PATCH 05/17] arm: Discard unwanted sections in linker script Sam Edwards
2025-02-24  5:55 ` [PATCH 06/17] arm: Use -mstrict-align when the MMU is off Sam Edwards
2025-02-24  8:20   ` Heinrich Schuchardt
2025-02-24 11:21   ` Mark Kettenis
2025-02-24  5:55 ` [PATCH 07/17] arm: Replace 'adrl' in EFI crt0 Sam Edwards
2025-02-24  8:42   ` Heinrich Schuchardt
2025-02-25  2:16     ` Sam Edwards
2025-02-24  5:55 ` [PATCH 08/17] x86: Fix call64's section flags Sam Edwards
2025-02-24  5:55 ` [PATCH 09/17] spl: riscv: opensbi: Error on misaligned FDT Sam Edwards
2025-02-24  8:54   ` Heinrich Schuchardt
2025-02-24 14:54     ` Tom Rini
2025-02-25  2:29       ` Sam Edwards
2025-02-24  5:55 ` [PATCH 10/17] spl: Align FDT load address Sam Edwards
2025-02-24  8:59   ` Heinrich Schuchardt
2025-02-24 14:56     ` Tom Rini
2025-02-24 15:54       ` Heinrich Schuchardt
2025-02-24 16:03         ` Tom Rini
2025-02-25  2:48           ` Sam Edwards
2025-02-24  5:55 ` [PATCH 11/17] makefile: Fix symbol typo in binary_size_check Sam Edwards
2025-02-24  9:17   ` Heinrich Schuchardt
2025-02-25 13:04     ` Simon Glass
2025-02-24  5:55 ` [PATCH 12/17] makefile: Avoid objcopy --gap-fill for .hex/.srec Sam Edwards
2025-02-24  5:55 ` Sam Edwards [this message]
2025-03-11 14:31   ` [PATCH 13/17] makefile: Add `norelro` linker option Ilias Apalodimas
2025-02-24  5:55 ` [PATCH 14/17] makefile: Add READELF command variable Sam Edwards
2025-02-24  9:20   ` Heinrich Schuchardt
2025-02-26  9:51   ` Ilias Apalodimas
2025-02-24  5:55 ` [PATCH 15/17] efi_loader: Remove ENTRY(_start) from linker script Sam Edwards
2025-02-24  9:36   ` Heinrich Schuchardt
2025-02-25  2:21     ` Sam Edwards
2025-02-24  5:55 ` [PATCH 16/17] efi_loader: Move .dynamic out of .text in EFI Sam Edwards
2025-02-24  7:34   ` Heinrich Schuchardt
2025-03-04  2:37     ` Sam Edwards
2025-02-24  5:55 ` [PATCH 17/17] scripts/Makefile.lib: efi: Preserve the .dynstr section as well Sam Edwards
2025-02-24  9:46   ` Heinrich Schuchardt
2025-03-06  3:46 ` [PATCH 00/17] Various toolchain compatibility fixes/improvements Sam Edwards
2025-03-06 13:15   ` Ilias Apalodimas
2025-03-06 15:47   ` Tom Rini
2025-03-08  6:48     ` Sam Edwards
2025-03-10 14:07       ` Tom Rini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250224055524.1334929-14-CFSworks@gmail.com \
    --to=cfsworks@gmail.com \
    --cc=bmeng.cn@gmail.com \
    --cc=ilias.apalodimas@linaro.org \
    --cc=marek.vasut+renesas@mailbox.org \
    --cc=pbrobinson@gmail.com \
    --cc=richard.henderson@linaro.org \
    --cc=sjg@chromium.org \
    --cc=sumit.garg@linaro.org \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.denx.de \
    --cc=xypron.glpk@gmx.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.