1.1 --- /dev/null Thu Jan 01 00:00:00 1970 +0000
1.2 +++ b/patches/binutils/2.19/140-pt-pax-flags-20081101.patch Sun Aug 01 14:23:08 2010 +0200
1.3 @@ -0,0 +1,249 @@
1.4 +Original patch from Gentoo:
1.5 +gentoo/src/patchsets/binutils/2.19/63_all_binutils-2.19-pt-pax-flags-20081101.patch
1.6 +
1.7 +diff -durN binutils-2.19.orig/bfd/elf-bfd.h binutils-2.19/bfd/elf-bfd.h
1.8 +--- binutils-2.19.orig/bfd/elf-bfd.h 2008-08-21 01:28:58.000000000 +0200
1.9 ++++ binutils-2.19/bfd/elf-bfd.h 2008-11-23 16:31:09.000000000 +0100
1.10 +@@ -1526,6 +1526,9 @@
1.11 + /* Segment flags for the PT_GNU_STACK segment. */
1.12 + unsigned int stack_flags;
1.13 +
1.14 ++ /* Segment flags for the PT_PAX_FLAGS segment. */
1.15 ++ unsigned int pax_flags;
1.16 ++
1.17 + /* Symbol version definitions in external objects. */
1.18 + Elf_Internal_Verdef *verdef;
1.19 +
1.20 +diff -durN binutils-2.19.orig/bfd/elf.c binutils-2.19/bfd/elf.c
1.21 +--- binutils-2.19.orig/bfd/elf.c 2008-10-09 14:18:23.000000000 +0200
1.22 ++++ binutils-2.19/bfd/elf.c 2008-11-23 16:31:09.000000000 +0100
1.23 +@@ -1136,6 +1136,7 @@
1.24 + case PT_GNU_EH_FRAME: pt = "EH_FRAME"; break;
1.25 + case PT_GNU_STACK: pt = "STACK"; break;
1.26 + case PT_GNU_RELRO: pt = "RELRO"; break;
1.27 ++ case PT_PAX_FLAGS: pt = "PAX_FLAGS"; break;
1.28 + default: pt = NULL; break;
1.29 + }
1.30 + return pt;
1.31 +@@ -2442,6 +2443,9 @@
1.32 + case PT_GNU_RELRO:
1.33 + return _bfd_elf_make_section_from_phdr (abfd, hdr, index, "relro");
1.34 +
1.35 ++ case PT_PAX_FLAGS:
1.36 ++ return _bfd_elf_make_section_from_phdr (abfd, hdr, index, "pax_flags");
1.37 ++
1.38 + default:
1.39 + /* Check for any processor-specific program segment types. */
1.40 + bed = get_elf_backend_data (abfd);
1.41 +@@ -3404,6 +3408,11 @@
1.42 + ++segs;
1.43 + }
1.44 +
1.45 ++ {
1.46 ++ /* We need a PT_PAX_FLAGS segment. */
1.47 ++ ++segs;
1.48 ++ }
1.49 ++
1.50 + for (s = abfd->sections; s != NULL; s = s->next)
1.51 + {
1.52 + if ((s->flags & SEC_LOAD) != 0
1.53 +@@ -3983,6 +3992,20 @@
1.54 + }
1.55 + }
1.56 +
1.57 ++ {
1.58 ++ amt = sizeof (struct elf_segment_map);
1.59 ++ m = bfd_zalloc (abfd, amt);
1.60 ++ if (m == NULL)
1.61 ++ goto error_return;
1.62 ++ m->next = NULL;
1.63 ++ m->p_type = PT_PAX_FLAGS;
1.64 ++ m->p_flags = elf_tdata (abfd)->pax_flags;
1.65 ++ m->p_flags_valid = 1;
1.66 ++
1.67 ++ *pm = m;
1.68 ++ pm = &m->next;
1.69 ++ }
1.70 ++
1.71 + free (sections);
1.72 + elf_tdata (abfd)->segment_map = mfirst;
1.73 + }
1.74 +@@ -5173,7 +5196,8 @@
1.75 + 6. PT_TLS segment includes only SHF_TLS sections.
1.76 + 7. SHF_TLS sections are only in PT_TLS or PT_LOAD segments.
1.77 + 8. PT_DYNAMIC should not contain empty sections at the beginning
1.78 +- (with the possible exception of .dynamic). */
1.79 ++ (with the possible exception of .dynamic).
1.80 ++ 9. PT_PAX_FLAGS segments does not include any sections. */
1.81 + #define IS_SECTION_IN_INPUT_SEGMENT(section, segment, bed) \
1.82 + ((((segment->p_paddr \
1.83 + ? IS_CONTAINED_BY_LMA (section, segment, segment->p_paddr) \
1.84 +@@ -5181,6 +5205,7 @@
1.85 + && (section->flags & SEC_ALLOC) != 0) \
1.86 + || IS_NOTE (segment, section)) \
1.87 + && segment->p_type != PT_GNU_STACK \
1.88 ++ && segment->p_type != PT_PAX_FLAGS \
1.89 + && (segment->p_type != PT_TLS \
1.90 + || (section->flags & SEC_THREAD_LOCAL)) \
1.91 + && (segment->p_type == PT_LOAD \
1.92 +diff -durN binutils-2.19.orig/bfd/elflink.c binutils-2.19/bfd/elflink.c
1.93 +--- binutils-2.19.orig/bfd/elflink.c 2008-08-22 10:32:39.000000000 +0200
1.94 ++++ binutils-2.19/bfd/elflink.c 2008-11-23 16:31:09.000000000 +0100
1.95 +@@ -5397,16 +5397,30 @@
1.96 + return TRUE;
1.97 +
1.98 + bed = get_elf_backend_data (output_bfd);
1.99 ++ elf_tdata (output_bfd)->pax_flags = PF_NORANDEXEC;
1.100 ++
1.101 ++ if (info->execheap)
1.102 ++ elf_tdata (output_bfd)->pax_flags |= PF_NOMPROTECT;
1.103 ++ else if (info->noexecheap)
1.104 ++ elf_tdata (output_bfd)->pax_flags |= PF_MPROTECT;
1.105 ++
1.106 + if (info->execstack)
1.107 +- elf_tdata (output_bfd)->stack_flags = PF_R | PF_W | PF_X;
1.108 ++ {
1.109 ++ elf_tdata (output_bfd)->stack_flags = PF_R | PF_W | PF_X;
1.110 ++ elf_tdata (output_bfd)->pax_flags |= PF_EMUTRAMP;
1.111 ++ }
1.112 + else if (info->noexecstack)
1.113 +- elf_tdata (output_bfd)->stack_flags = PF_R | PF_W;
1.114 ++ {
1.115 ++ elf_tdata (output_bfd)->stack_flags = PF_R | PF_W;
1.116 ++ elf_tdata (output_bfd)->pax_flags |= PF_NOEMUTRAMP;
1.117 ++ }
1.118 + else
1.119 + {
1.120 + bfd *inputobj;
1.121 + asection *notesec = NULL;
1.122 + int exec = 0;
1.123 +
1.124 ++ elf_tdata (output_bfd)->pax_flags |= PF_NOEMUTRAMP;
1.125 + for (inputobj = info->input_bfds;
1.126 + inputobj;
1.127 + inputobj = inputobj->link_next)
1.128 +@@ -5419,7 +5433,11 @@
1.129 + if (s)
1.130 + {
1.131 + if (s->flags & SEC_CODE)
1.132 +- exec = PF_X;
1.133 ++ {
1.134 ++ elf_tdata (output_bfd)->pax_flags &= ~PF_NOEMUTRAMP;
1.135 ++ elf_tdata (output_bfd)->pax_flags |= PF_EMUTRAMP;
1.136 ++ exec = PF_X;
1.137 ++ }
1.138 + notesec = s;
1.139 + }
1.140 + else if (bed->default_execstack)
1.141 +diff -durN binutils-2.19.orig/binutils/readelf.c binutils-2.19/binutils/readelf.c
1.142 +--- binutils-2.19.orig/binutils/readelf.c 2008-09-17 11:00:44.000000000 +0200
1.143 ++++ binutils-2.19/binutils/readelf.c 2008-11-23 16:31:09.000000000 +0100
1.144 +@@ -2505,6 +2505,7 @@
1.145 + return "GNU_EH_FRAME";
1.146 + case PT_GNU_STACK: return "GNU_STACK";
1.147 + case PT_GNU_RELRO: return "GNU_RELRO";
1.148 ++ case PT_PAX_FLAGS: return "PAX_FLAGS";
1.149 +
1.150 + default:
1.151 + if ((p_type >= PT_LOPROC) && (p_type <= PT_HIPROC))
1.152 +diff -durN binutils-2.19.orig/include/bfdlink.h binutils-2.19/include/bfdlink.h
1.153 +--- binutils-2.19.orig/include/bfdlink.h 2008-08-17 05:12:50.000000000 +0200
1.154 ++++ binutils-2.19/include/bfdlink.h 2008-11-23 16:31:09.000000000 +0100
1.155 +@@ -319,6 +319,14 @@
1.156 + /* TRUE if PT_GNU_RELRO segment should be created. */
1.157 + unsigned int relro: 1;
1.158 +
1.159 ++ /* TRUE if PT_PAX_FLAGS segment should be created with PF_NOMPROTECT
1.160 ++ flags. */
1.161 ++ unsigned int execheap: 1;
1.162 ++
1.163 ++ /* TRUE if PT_PAX_FLAGS segment should be created with PF_MPROTECT
1.164 ++ flags. */
1.165 ++ unsigned int noexecheap: 1;
1.166 ++
1.167 + /* TRUE if we should warn when adding a DT_TEXTREL to a shared object. */
1.168 + unsigned int warn_shared_textrel: 1;
1.169 +
1.170 +diff -durN binutils-2.19.orig/include/elf/common.h binutils-2.19/include/elf/common.h
1.171 +--- binutils-2.19.orig/include/elf/common.h 2008-08-04 01:20:42.000000000 +0200
1.172 ++++ binutils-2.19/include/elf/common.h 2008-11-23 16:31:09.000000000 +0100
1.173 +@@ -360,6 +360,7 @@
1.174 + #define PT_SUNW_EH_FRAME PT_GNU_EH_FRAME /* Solaris uses the same value */
1.175 + #define PT_GNU_STACK (PT_LOOS + 0x474e551) /* Stack flags */
1.176 + #define PT_GNU_RELRO (PT_LOOS + 0x474e552) /* Read-only after relocation */
1.177 ++#define PT_PAX_FLAGS (PT_LOOS + 0x5041580) /* PaX flags */
1.178 +
1.179 + /* Program segment permissions, in program header p_flags field. */
1.180 +
1.181 +@@ -370,6 +371,21 @@
1.182 + #define PF_MASKOS 0x0FF00000 /* New value, Oct 4, 1999 Draft */
1.183 + #define PF_MASKPROC 0xF0000000 /* Processor-specific reserved bits */
1.184 +
1.185 ++/* Flags to control PaX behavior. */
1.186 ++
1.187 ++#define PF_PAGEEXEC (1 << 4) /* Enable PAGEEXEC */
1.188 ++#define PF_NOPAGEEXEC (1 << 5) /* Disable PAGEEXEC */
1.189 ++#define PF_SEGMEXEC (1 << 6) /* Enable SEGMEXEC */
1.190 ++#define PF_NOSEGMEXEC (1 << 7) /* Disable SEGMEXEC */
1.191 ++#define PF_MPROTECT (1 << 8) /* Enable MPROTECT */
1.192 ++#define PF_NOMPROTECT (1 << 9) /* Disable MPROTECT */
1.193 ++#define PF_RANDEXEC (1 << 10) /* Enable RANDEXEC */
1.194 ++#define PF_NORANDEXEC (1 << 11) /* Disable RANDEXEC */
1.195 ++#define PF_EMUTRAMP (1 << 12) /* Enable EMUTRAMP */
1.196 ++#define PF_NOEMUTRAMP (1 << 13) /* Disable EMUTRAMP */
1.197 ++#define PF_RANDMMAP (1 << 14) /* Enable RANDMMAP */
1.198 ++#define PF_NORANDMMAP (1 << 15) /* Disable RANDMMAP */
1.199 ++
1.200 + /* Values for section header, sh_type field. */
1.201 +
1.202 + #define SHT_NULL 0 /* Section header table entry unused */
1.203 +diff -durN binutils-2.19.orig/ld/emultempl/elf32.em binutils-2.19/ld/emultempl/elf32.em
1.204 +--- binutils-2.19.orig/ld/emultempl/elf32.em 2008-11-23 16:30:36.000000000 +0100
1.205 ++++ binutils-2.19/ld/emultempl/elf32.em 2008-11-23 16:31:09.000000000 +0100
1.206 +@@ -2146,6 +2146,16 @@
1.207 + link_info.noexecstack = TRUE;
1.208 + link_info.execstack = FALSE;
1.209 + }
1.210 ++ else if (strcmp (optarg, "execheap") == 0)
1.211 ++ {
1.212 ++ link_info.execheap = TRUE;
1.213 ++ link_info.noexecheap = FALSE;
1.214 ++ }
1.215 ++ else if (strcmp (optarg, "noexecheap") == 0)
1.216 ++ {
1.217 ++ link_info.noexecheap = TRUE;
1.218 ++ link_info.execheap = FALSE;
1.219 ++ }
1.220 + EOF
1.221 +
1.222 + if test -n "$COMMONPAGESIZE"; then
1.223 +@@ -2229,6 +2239,8 @@
1.224 + fprintf (file, _("\
1.225 + -z execstack Mark executable as requiring executable stack\n"));
1.226 + fprintf (file, _("\
1.227 ++ -z execheap\t\tMark executable as requiring executable heap\n"));
1.228 ++ fprintf (file, _("\
1.229 + -z initfirst Mark DSO to be initialized first at runtime\n"));
1.230 + fprintf (file, _("\
1.231 + -z interpose Mark object to interpose all DSOs but executable\n"));
1.232 +@@ -2252,6 +2264,8 @@
1.233 + -z nodump Mark DSO not available to dldump\n"));
1.234 + fprintf (file, _("\
1.235 + -z noexecstack Mark executable as not requiring executable stack\n"));
1.236 ++ fprintf (file, _("\
1.237 ++ -z noexecheap\tMark executable as not requiring executable heap\n"));
1.238 + EOF
1.239 +
1.240 + if test -n "$COMMONPAGESIZE"; then
1.241 +diff -durN binutils-2.19.orig/ld/ldgram.y binutils-2.19/ld/ldgram.y
1.242 +--- binutils-2.19.orig/ld/ldgram.y 2008-07-06 15:38:36.000000000 +0200
1.243 ++++ binutils-2.19/ld/ldgram.y 2008-11-23 16:31:09.000000000 +0100
1.244 +@@ -1112,6 +1112,8 @@
1.245 + $$ = exp_intop (0x6474e550);
1.246 + else if (strcmp (s, "PT_GNU_STACK") == 0)
1.247 + $$ = exp_intop (0x6474e551);
1.248 ++ else if (strcmp (s, "PT_PAX_FLAGS") == 0)
1.249 ++ $$ = exp_intop (0x65041580);
1.250 + else
1.251 + {
1.252 + einfo (_("\