From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 59318CD98CF for ; Tue, 16 Jun 2026 10:45:23 +0000 (UTC) Received: from list by lists.xenproject.org with outflank-mailman.1339101.1600225 (Exim 4.92) (envelope-from ) id 1wZRI4-00065x-Mu; Tue, 16 Jun 2026 10:45:08 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version Received: by outflank-mailman (output) from mailman id 1339101.1600225; Tue, 16 Jun 2026 10:45:08 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wZRI4-00065q-Ja; Tue, 16 Jun 2026 10:45:08 +0000 Received: by outflank-mailman (input) for mailman id 1339101; Tue, 16 Jun 2026 10:45:07 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wZRI3-00065R-Af for xen-devel@lists.xenproject.org; Tue, 16 Jun 2026 10:45:07 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wZRI1-00GLzT-FE for xen-devel@lists.xenproject.org; Tue, 16 Jun 2026 12:45:05 +0200 Received: from [10.42.69.4] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a31292b-2eae-0a2a0a5409dd-0a2a4504ba0e-18 for ; Tue, 16 Jun 2026 12:45:05 +0200 Received: from [103.168.172.156] (helo=fhigh-a5-smtp.messagingengine.com) by tlsNG-ebf023.mxtls.expurgate.net with ESMTPS (eXpurgate 4.56.1) (envelope-from ) id 6a312930-1dec-0a2a45040019-67a8ac9c9fcf-3 for ; Tue, 16 Jun 2026 12:45:05 +0200 Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfhigh.phl.internal (Postfix) with ESMTP id ED856140014F; Tue, 16 Jun 2026 06:45:03 -0400 (EDT) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-05.internal (MEProxy); Tue, 16 Jun 2026 06:45:03 -0400 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Tue, 16 Jun 2026 06:45:00 -0400 (EDT) X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=fm1 header.d=invisiblethingslab.com header.i="@invisiblethingslab.com" header.h="Cc:Content-Type:Date:From:In-Reply-To:Message-ID:MIME-Version:References:Subject:To"; dkim=pass header.s=fm1 header.d=messagingengine.com header.i="@messagingengine.com" header.h="Cc:Content-Type:Date:Feedback-ID:From:In-Reply-To:Message-ID:MIME-Version:References:Subject:To:X-ME-Proxy:X-ME-Sender" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= invisiblethingslab.com; h=cc:cc:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm1; t=1781606703; x=1781693103; bh=NaLuUNbId44MtYuD6WuLs2HYXlOO5ZupT+0ImB0gTGg=; b= ia0JtE7WRVWUsr+jdmgIFaBuetRRUY15SHmBmSFbflsA4D3eDwyLzxutL60/1XUO zeYQfj6VwGhNwBW8yJtJmNBbsCsqPpM3xCevgCgGruYbdBGYEPvK0+yfXqM7mPsl hSlLGdhl96FcNM1wM+esZgw5Djv/quAUG1a0kPHotTacfa8hc/Z0G/PZxORGAkfj 2H1IU7uiPpV6OetOP+9HkpMjpgjD+7zG85wsxlFXKptrfvk+LYV4HLC/J0PhohLI rsogAtuGgcAQD49eElIAHubPE+MAKmfAUOwqhxqgi79CwIH9+y36tb5pmr4pU356 Dk+hAfIP0fFJ+httR1mEXg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm1; t= 1781606703; x=1781693103; bh=NaLuUNbId44MtYuD6WuLs2HYXlOO5ZupT+0 ImB0gTGg=; b=DDkSg2S2FoyhRwFi8pmSR/cc7d/0qKwfyHG+UQXnYbHnnB+x4Ii erVWpp6rFK8rB542KzaS/rY25Nq1/cxAP9DLRfkPDFgxWxagnoYzY/BnqgeMkvRh 7BK0A01cUKoItTfxcue1LZT5xBvyTwuvabqKN79piWhtCJAYy5QM2prNAb5J5G9A UWlxnh+1sf+ERnpsRqHe9Xag+6zpkVaxZm269/B5lZuIYA8Y/mjewVCQc20qJHqH zx8ZoevliNPRUq4IPFSzuCQbkTwQNDuvjPidA10INPzLbtO2+4pcfZ/DjF5DxhrS 1nqqjrA9n67L09RELW3qEumCHAgmMirtOKQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTGY7Z9jmGa2+aGtWmkJ6P7gvTnJn0JJoC8QAnKrKY5wY8eR61XouW5oy6AOCchx3J z1vWPLRrRchgyl/bBj/m5h3Pu1XAOwo9iJDR/OK1YoVglt4MbEgnXWwbe2m2U5lBBk3OSV MT6OGK91OkhDxvklW8Wiyj87XPJ0xZd7uPvVL1mcj5lDS2+kn2KkYWz6/e5CFioiistVgc P27N5s/gP2zIwBiMTEIRa2eWooQd18ELmExWWfxN6Z6ypJUn7iS2SZvXUEzvLgZomSVVqK xIOqeIERmxQYRM1dRcnElxCTeRwMBfVlCcjYhneVq8Rj0YCi7o/NhkkQUqanLC5DR4uzJG 6Hxbyg0SZYWw5AqFqxxtigVoH4HOMbwuCeOb18Jsq7OztpLFucJGX04JIGnMqV0LcEHhmi b0x4elul5rAerjqBfMox8vpXagdBPOhRUl0WWS4ZQCIohzGHOv6Ny5UcoJOrLw3NZ5caiZ JrcFZYsWH/G6vzdCAqUGXqeXf+j+7RUhPuRBk3EZc3R+j5djsE1+cfUFzidvtS8OqFxOzR NX8ztY7rT0VDa1SeddWg4aw/DvQzz+PvJrVFOXAtq0JvecdlYeVgbSMNmC4HWtT26+urtE Cl12H4NBssSrzuJixmzQekViEGIsuGapyMFbUpio1Na40PncGjAJy35XJxog X-ME-Proxy: Feedback-ID: i1568416f:Fastmail Date: Tue, 16 Jun 2026 12:44:58 +0200 From: Marek =?utf-8?Q?Marczykowski-G=C3=B3recki?= To: Frediano Ziglio Cc: xen-devel@lists.xenproject.org, Frediano Ziglio , Jan Beulich , Andrew Cooper , Roger Pau =?utf-8?B?TW9ubsOp?= , Teddy Astie , Frediano Ziglio Subject: Re: [PATCH v3 1/4] Align relevant sections to 4KB Message-ID: References: <20260616101336.44009-1-frediano.ziglio@citrix.com> <20260616101336.44009-2-frediano.ziglio@citrix.com> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="Zx7VUxsfvZUqjHQo" Content-Disposition: inline In-Reply-To: <20260616101336.44009-2-frediano.ziglio@citrix.com> X-purgate-ID: tlsNG-ebf023/1781606705-2BD6C3FF-6B28B3A8/0/0 X-purgate-type: clean X-purgate-size: 3277 --Zx7VUxsfvZUqjHQo Content-Type: text/plain; protected-headers=v1; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Date: Tue, 16 Jun 2026 12:44:58 +0200 From: Marek =?utf-8?Q?Marczykowski-G=C3=B3recki?= To: Frediano Ziglio Cc: xen-devel@lists.xenproject.org, Frediano Ziglio , Jan Beulich , Andrew Cooper , Roger Pau =?utf-8?B?TW9ubsOp?= , Teddy Astie , Frediano Ziglio Subject: Re: [PATCH v3 1/4] Align relevant sections to 4KB On Tue, Jun 16, 2026 at 11:13:33AM +0100, Frediano Ziglio wrote: > From: Frediano Ziglio >=20 > Required by UEFI CA memory mitigation. >=20 > It is a requirement for NX_COMPAT so the PE can be loaded with W^X perms > in the pagetables. >=20 > NX_COMPAT is a requirement from shim-review, > https://github.com/rhboot/shim-review#do-you-have-the-nx-bit-set-in-your-= shim-if-so-is-your-entire-boot-stack-nx-compatible-and-what-testing-have-yo= u-done-to-ensure-such-compatibility >=20 > Sections with different permissions must be in separate pages. > In the case of debug sections they are contiguous and have the same > permissions so it's not an issue if they are not aligned to the page. >=20 > Signed-off-by: Frediano Ziglio Acked-by: Marek Marczykowski-G=C3=B3recki > -- > Changes since v1: > - Change subject. >=20 > Changes since v2: > - Improved commit message and subject. > --- > xen/arch/x86/xen.lds.S | 5 +++-- > 1 file changed, 3 insertions(+), 2 deletions(-) >=20 > diff --git a/xen/arch/x86/xen.lds.S b/xen/arch/x86/xen.lds.S > index b9e888e596..f758940674 100644 > --- a/xen/arch/x86/xen.lds.S > +++ b/xen/arch/x86/xen.lds.S > @@ -162,8 +162,8 @@ SECTIONS > __note_gnu_build_id_end =3D .; > } PHDR(note) PHDR(text) > #elif defined(BUILD_ID_EFI) > - /* Workaround bug in binutils < 2.36 */ > - . =3D ALIGN(32); > + /* Align to satisfy UEFI CA memory mitigation. */ > + . =3D ALIGN(PAGE_SIZE); > DECL_SECTION(.buildid) { > __note_gnu_build_id_start =3D .; > *(.buildid) > @@ -330,6 +330,7 @@ SECTIONS > __2M_rwdata_end =3D ALIGN(SECTION_ALIGN); > =20 > #ifdef EFI > + . =3D ALIGN(PAGE_SIZE); > .reloc ALIGN(4) : { > __base_relocs_start =3D .; > *(.reloc) > --=20 > 2.43.0 >=20 --=20 Best Regards, Marek Marczykowski-G=C3=B3recki Invisible Things Lab --Zx7VUxsfvZUqjHQo Content-Type: application/pgp-signature; name=signature.asc -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEhrpukzGPukRmQqkK24/THMrX1ywFAmoxKSoACgkQ24/THMrX 1yyDUQf/fkB5FPNxB5IQto4U6LzRvBzSElebdq4QVipEgSWjTyv8dEqVF99lx1QL mW6fBFVrw0wNt7ep/8B7gioyvx6iHFLWqrfnKf/dIgqqIQlG0bLNVPvpP4aPAn4H pfgit8QYgxBG3NI1H1/DL1SPgIOhKECBFkr98umhKWHc3xJTLsBy7fjGLLdG7Pze GWWVLSfEMnDI4fSjrjA75su8mzfNbsAhslL60P0gGVyZvIkJ3C9Rk7IkHYdDArTj sbNe1jNbBgIG4r13aQxm9Jo4Vf7lL3z8Z3qmm6vImZIHiZFgzJCVn1uSJYbcjElU KqmZDO6ho5YScy3mdxhBkFKbhefQwQ== =/fEy -----END PGP SIGNATURE----- --Zx7VUxsfvZUqjHQo--