Submitted By: Robert Connolly (ashes) Date: 2007-04-01 Initial Package Version: 2.17.50.0.14 Upstream Status: Not Submitted Origin: http://pax.grsecurity.net/binutils-2.17-pt-pax-flags-200606282220.patch Plus i386 testsuite modifications. Description: This adds PT_PAX_FLAGS to Binutils. See: http://pax.grsecurity.net/ diff -Naur binutils-2.17.50.0.14.orig/bfd/elf-bfd.h binutils-2.17.50.0.14/bfd/elf-bfd.h --- binutils-2.17.50.0.14.orig/bfd/elf-bfd.h 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/bfd/elf-bfd.h 2007-04-01 22:40:20.000000000 +0000 @@ -1366,6 +1366,9 @@ /* Segment flags for the PT_GNU_STACK segment. */ unsigned int stack_flags; + /* Segment flags for the PT_PAX_FLAGS segment. */ + unsigned int pax_flags; + /* Symbol version definitions in external objects. */ Elf_Internal_Verdef *verdef; diff -Naur binutils-2.17.50.0.14.orig/bfd/elf.c binutils-2.17.50.0.14/bfd/elf.c --- binutils-2.17.50.0.14.orig/bfd/elf.c 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/bfd/elf.c 2007-04-01 22:40:20.000000000 +0000 @@ -1109,6 +1109,7 @@ case PT_GNU_EH_FRAME: pt = "EH_FRAME"; break; case PT_GNU_STACK: pt = "STACK"; break; case PT_GNU_RELRO: pt = "RELRO"; break; + case PT_PAX_FLAGS: pt = "PAX_FLAGS"; break; default: pt = NULL; break; } return pt; @@ -2668,6 +2669,9 @@ case PT_GNU_RELRO: return _bfd_elf_make_section_from_phdr (abfd, hdr, index, "relro"); + case PT_PAX_FLAGS: + return _bfd_elf_make_section_from_phdr (abfd, hdr, index, "pax_flags"); + default: /* Check for any processor-specific program segment types. */ bed = get_elf_backend_data (abfd); @@ -3640,6 +3644,11 @@ ++segs; } + { + /* We need a PT_PAX_FLAGS segment. */ + ++segs; + } + for (s = abfd->sections; s != NULL; s = s->next) { if ((s->flags & SEC_LOAD) != 0 @@ -4227,6 +4236,20 @@ pm = &m->next; } + { + amt = sizeof (struct elf_segment_map); + m = bfd_zalloc (abfd, amt); + if (m == NULL) + goto error_return; + m->next = NULL; + m->p_type = PT_PAX_FLAGS; + m->p_flags = elf_tdata (abfd)->pax_flags; + m->p_flags_valid = 1; + + *pm = m; + pm = &m->next; + } + free (sections); elf_tdata (abfd)->segment_map = mfirst; } @@ -5409,7 +5432,8 @@ 6. PT_TLS segment includes only SHF_TLS sections. 7. SHF_TLS sections are only in PT_TLS or PT_LOAD segments. 8. PT_DYNAMIC should not contain empty sections at the beginning - (with the possible exception of .dynamic). */ + (with the possible exception of .dynamic). + 9. PT_PAX_FLAGS segments do not include any sections. */ #define IS_SECTION_IN_INPUT_SEGMENT(section, segment, bed) \ ((((segment->p_paddr \ ? IS_CONTAINED_BY_LMA (section, segment, segment->p_paddr) \ @@ -5417,6 +5441,7 @@ && (section->flags & SEC_ALLOC) != 0) \ || IS_COREFILE_NOTE (segment, section)) \ && segment->p_type != PT_GNU_STACK \ + && segment->p_type != PT_PAX_FLAGS \ && (segment->p_type != PT_TLS \ || (section->flags & SEC_THREAD_LOCAL)) \ && (segment->p_type == PT_LOAD \ diff -Naur binutils-2.17.50.0.14.orig/bfd/elflink.c binutils-2.17.50.0.14/bfd/elflink.c --- binutils-2.17.50.0.14.orig/bfd/elflink.c 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/bfd/elflink.c 2007-04-01 22:40:20.000000000 +0000 @@ -5295,17 +5295,31 @@ if (!is_elf_hash_table (info->hash)) return TRUE; + elf_tdata (output_bfd)->pax_flags = PF_NORANDEXEC; + + if (info->execheap) + elf_tdata (output_bfd)->pax_flags |= PF_NOMPROTECT; + else if (info->noexecheap) + elf_tdata (output_bfd)->pax_flags |= PF_MPROTECT; + bed = get_elf_backend_data (output_bfd); if (info->execstack) - elf_tdata (output_bfd)->stack_flags = PF_R | PF_W | PF_X; + { + elf_tdata (output_bfd)->stack_flags = PF_R | PF_W | PF_X; + elf_tdata (output_bfd)->pax_flags |= PF_EMUTRAMP; + } else if (info->noexecstack) - elf_tdata (output_bfd)->stack_flags = PF_R | PF_W; + { + elf_tdata (output_bfd)->stack_flags = PF_R | PF_W; + elf_tdata (output_bfd)->pax_flags |= PF_NOEMUTRAMP; + } else { bfd *inputobj; asection *notesec = NULL; int exec = 0; + elf_tdata (output_bfd)->pax_flags |= PF_NOEMUTRAMP; for (inputobj = info->input_bfds; inputobj; inputobj = inputobj->link_next) @@ -5318,7 +5332,11 @@ if (s) { if (s->flags & SEC_CODE) - exec = PF_X; + { + elf_tdata (output_bfd)->pax_flags &= ~PF_NOEMUTRAMP; + elf_tdata (output_bfd)->pax_flags |= PF_EMUTRAMP; + exec = PF_X; + } notesec = s; } else if (bed->default_execstack) diff -Naur binutils-2.17.50.0.14.orig/binutils/readelf.c binutils-2.17.50.0.14/binutils/readelf.c --- binutils-2.17.50.0.14.orig/binutils/readelf.c 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/binutils/readelf.c 2007-04-01 22:40:20.000000000 +0000 @@ -2467,6 +2467,7 @@ return "GNU_EH_FRAME"; case PT_GNU_STACK: return "GNU_STACK"; case PT_GNU_RELRO: return "GNU_RELRO"; + case PT_PAX_FLAGS: return "PAX_FLAGS"; default: if ((p_type >= PT_LOPROC) && (p_type <= PT_HIPROC)) diff -Naur binutils-2.17.50.0.14.orig/include/bfdlink.h binutils-2.17.50.0.14/include/bfdlink.h --- binutils-2.17.50.0.14.orig/include/bfdlink.h 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/include/bfdlink.h 2007-04-01 22:40:20.000000000 +0000 @@ -317,6 +317,14 @@ flags. */ unsigned int noexecstack: 1; + /* TRUE if PT_PAX_FLAGS segment should be created with PF_NOMPROTECT + flags. */ + unsigned int execheap: 1; + + /* TRUE if PT_PAX_FLAGS segment should be created with PF_MPROTECT + flags. */ + unsigned int noexecheap: 1; + /* TRUE if PT_GNU_RELRO segment should be created. */ unsigned int relro: 1; diff -Naur binutils-2.17.50.0.14.orig/include/elf/common.h binutils-2.17.50.0.14/include/elf/common.h --- binutils-2.17.50.0.14.orig/include/elf/common.h 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/include/elf/common.h 2007-04-01 22:40:20.000000000 +0000 @@ -309,12 +309,29 @@ #define PT_GNU_STACK (PT_LOOS + 0x474e551) /* Stack flags */ #define PT_GNU_RELRO (PT_LOOS + 0x474e552) /* Read-only after relocation */ #define PT_GNU_SHR (PT_LOOS + 0x474e554) /* Sharable segment */ +#define PT_PAX_FLAGS (PT_LOOS + 0x5041580) /* PaX flags */ /* Program segment permissions, in program header p_flags field. */ #define PF_X (1 << 0) /* Segment is executable */ #define PF_W (1 << 1) /* Segment is writable */ #define PF_R (1 << 2) /* Segment is readable */ + +/* Flags to control PaX behaviour. */ + +#define PF_PAGEEXEC (1U << 4) /* Enable PAGEEXEC */ +#define PF_NOPAGEEXEC (1U << 5) /* Disable PAGEEXEC */ +#define PF_SEGMEXEC (1U << 6) /* Enable SEGMEXEC */ +#define PF_NOSEGMEXEC (1U << 7) /* Disable SEGMEXEC */ +#define PF_MPROTECT (1U << 8) /* Enable MPROTECT */ +#define PF_NOMPROTECT (1U << 9) /* Disable MPROTECT */ +#define PF_RANDEXEC (1U << 10) /* Enable RANDEXEC */ +#define PF_NORANDEXEC (1U << 11) /* Disable RANDEXEC */ +#define PF_EMUTRAMP (1U << 12) /* Enable EMUTRAMP */ +#define PF_NOEMUTRAMP (1U << 13) /* Disable EMUTRAMP */ +#define PF_RANDMMAP (1U << 14) /* Enable RANDMMAP */ +#define PF_NORANDMMAP (1U << 15) /* Disable RANDMMAP */ + /* #define PF_MASKOS 0x0F000000 *//* OS-specific reserved bits */ #define PF_MASKOS 0x0FF00000 /* New value, Oct 4, 1999 Draft */ #define PF_MASKPROC 0xF0000000 /* Processor-specific reserved bits */ diff -Naur binutils-2.17.50.0.14.orig/ld/emultempl/elf32.em binutils-2.17.50.0.14/ld/emultempl/elf32.em --- binutils-2.17.50.0.14.orig/ld/emultempl/elf32.em 2007-03-23 15:42:51.000000000 +0000 +++ binutils-2.17.50.0.14/ld/emultempl/elf32.em 2007-04-01 22:40:20.000000000 +0000 @@ -1905,6 +1905,16 @@ link_info.noexecstack = TRUE; link_info.execstack = FALSE; } + else if (strcmp (optarg, "execheap") == 0) + { + link_info.execheap = TRUE; + link_info.noexecheap = FALSE; + } + else if (strcmp (optarg, "noexecheap") == 0) + { + link_info.noexecheap = TRUE; + link_info.execheap = FALSE; + } EOF if test -n "$COMMONPAGESIZE"; then @@ -1977,6 +1987,7 @@ fprintf (file, _(" -z combreloc\t\tMerge dynamic relocs into one section and sort\n")); fprintf (file, _(" -z defs\t\tReport unresolved symbols in object files.\n")); fprintf (file, _(" -z execstack\t\tMark executable as requiring executable stack\n")); + fprintf (file, _(" -z execheap\t\tMark executable as requiring executable heap\n")); fprintf (file, _(" -z initfirst\t\tMark DSO to be initialized first at runtime\n")); fprintf (file, _(" -z interpose\t\tMark object to interpose all DSOs but executable\n")); fprintf (file, _(" -z lazy\t\tMark object lazy runtime binding (default)\n")); @@ -1989,6 +2000,7 @@ fprintf (file, _(" -z nodlopen\t\tMark DSO not available to dlopen\n")); fprintf (file, _(" -z nodump\t\tMark DSO not available to dldump\n")); fprintf (file, _(" -z noexecstack\tMark executable as not requiring executable stack\n")); + fprintf (file, _(" -z noexecheap\tMark executable as not requiring executable heap\n")); EOF if test -n "$COMMONPAGESIZE"; then diff -Naur binutils-2.17.50.0.14.orig/ld/ldgram.y binutils-2.17.50.0.14/ld/ldgram.y --- binutils-2.17.50.0.14.orig/ld/ldgram.y 2007-01-26 02:45:24.000000000 +0000 +++ binutils-2.17.50.0.14/ld/ldgram.y 2007-04-01 22:40:20.000000000 +0000 @@ -1093,6 +1093,8 @@ $$ = exp_intop (0x6474e550); else if (strcmp (s, "PT_GNU_STACK") == 0) $$ = exp_intop (0x6474e551); + else if (strcmp (s, "PT_PAX_FLAGS") == 0) + $$ = exp_intop (0x65041580); else { einfo (_("\ diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsbin.rd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsbin.rd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsbin.rd 2006-10-20 18:50:59.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsbin.rd 2007-04-01 22:40:20.000000000 +0000 @@ -33,7 +33,7 @@ Elf file type is EXEC \(Executable file\) Entry point 0x8049178 -There are 6 program headers, starting at offset [0-9]+ +There are 7 program headers, starting at offset [0-9]+ Program Headers: Type +Offset +VirtAddr +PhysAddr +FileSiz +MemSiz +Flg Align @@ -44,6 +44,7 @@ LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+a0 R +0x1000 + PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: Segment Sections... @@ -53,6 +54,7 @@ 03 +.tdata .dynamic .got .got.plt * 04 +.dynamic * 05 +.tdata .tbss * + 06 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 9 entries: Offset +Info +Type +Sym.Value +Sym. Name diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsbindesc.rd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsbindesc.rd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsbindesc.rd 2006-10-20 18:50:59.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsbindesc.rd 2007-04-01 22:40:20.000000000 +0000 @@ -31,7 +31,7 @@ Elf file type is EXEC \(Executable file\) Entry point 0x8049158 -There are 6 program headers, starting at offset [0-9]+ +There are 7 program headers, starting at offset [0-9]+ Program Headers: Type +Offset +VirtAddr +PhysAddr +FileSiz +MemSiz +Flg Align @@ -42,6 +42,7 @@ LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+a0 R +0x1000 + PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: Segment Sections... @@ -51,6 +52,7 @@ 03 +.tdata .dynamic .got .got.plt * 04 +.dynamic * 05 +.tdata .tbss * + 06 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 9 entries: Offset +Info +Type +Sym.Value +Sym. Name diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsdesc.rd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsdesc.rd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsdesc.rd 2006-10-20 18:50:59.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsdesc.rd 2007-04-01 22:40:20.000000000 +0000 @@ -39,6 +39,7 @@ LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+80 R +0x1 + PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: Segment Sections... @@ -46,6 +47,7 @@ 01 +.tdata .dynamic .got .got.plt * 02 +.dynamic * 03 +.tdata .tbss * + 04 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 20 entries: Offset +Info +Type +Sym.Value +Sym. Name diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsdesc.sd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsdesc.sd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsdesc.sd 2006-10-20 18:50:59.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsdesc.sd 2007-04-01 22:43:23.000000000 +0000 @@ -14,7 +14,7 @@ [0-9a-f]+ 6c000000 b4ffffff 4c000000 68000000 .* [0-9a-f]+ 50000000 70000000 00000000 bcffffff .* Contents of section \.got\.plt: - [0-9a-f]+ b0150000 00000000 00000000 00000000 .* + [0-9a-f]+ d0150000 00000000 00000000 00000000 .* [0-9a-f]+ 20000000 00000000 60000000 00000000 .* [0-9a-f]+ 00000000 00000000 00000000 00000000 .* [0-9a-f]+ 40000000 +.* diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsgdesc.rd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsgdesc.rd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsgdesc.rd 2006-10-20 18:50:59.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsgdesc.rd 2007-04-01 22:40:20.000000000 +0000 @@ -36,12 +36,14 @@ LOAD.* LOAD.* DYNAMIC.* + PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: Segment Sections... 00 +.hash .dynsym .dynstr .rel.dyn .rel.plt .plt .text * 01 +.dynamic .got .got.plt * 02 +.dynamic * + 03 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 8 entries: Offset +Info +Type +Sym.Value +Sym. Name diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsnopic.rd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsnopic.rd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlsnopic.rd 2006-10-20 18:50:59.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlsnopic.rd 2007-04-01 22:40:20.000000000 +0000 @@ -29,7 +29,7 @@ Elf file type is DYN \(Shared object file\) Entry point 0x1000 -There are 4 program headers, starting at offset [0-9]+ +There are 5 program headers, starting at offset [0-9]+ Program Headers: Type +Offset +VirtAddr +PhysAddr +FileSiz +MemSiz +Flg Align @@ -37,6 +37,7 @@ LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+ 0x0+24 R +0x1 + PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: Segment Sections... @@ -44,6 +45,7 @@ 01 +.dynamic .got .got.plt * 02 +.dynamic * 03 +.tbss * + 04 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 20 entries: Offset +Info +Type +Sym.Value +Sym. Name diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlspic.rd binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlspic.rd --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-i386/tlspic.rd 2006-10-20 18:51:00.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-i386/tlspic.rd 2007-04-01 22:40:20.000000000 +0000 @@ -40,6 +40,7 @@ LOAD.* DYNAMIC.* TLS +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x0+60 0x0+80 R +0x1 + PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: Segment Sections... @@ -47,6 +48,7 @@ 01 +.tdata .dynamic .got .got.plt * 02 +.dynamic * 03 +.tdata .tbss * + 04 * Relocation section '.rel.dyn' at offset 0x[0-9a-f]+ contains 26 entries: Offset +Info +Type +Sym.Value +Sym. Name diff -Naur binutils-2.17.50.0.14.orig/ld/testsuite/ld-scripts/empty-aligned.d binutils-2.17.50.0.14/ld/testsuite/ld-scripts/empty-aligned.d --- binutils-2.17.50.0.14.orig/ld/testsuite/ld-scripts/empty-aligned.d 2005-08-22 19:27:46.000000000 +0000 +++ binutils-2.17.50.0.14/ld/testsuite/ld-scripts/empty-aligned.d 2007-04-01 22:40:20.000000000 +0000 @@ -7,7 +7,9 @@ Program Headers: +Type +Offset +VirtAddr +PhysAddr +FileSiz +MemSiz +Flg +Align +LOAD +0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ 0x[0-9a-f]+ [RWE ]+ +0x[0-9a-f]+ + +PAX_FLAGS +0x000000 0x00000000 0x00000000 0x00000 0x00000 +0x4 Section to Segment mapping: +Segment Sections\.\.\. +00 +.text + +01 +