lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAMzpN2g9QNnYhxkGvkO2YcOJTmJGf75qFhKiEQQY18ZaEPQNdw@mail.gmail.com>
Date: Wed, 17 Dec 2025 21:16:08 -0500
From: Brian Gerst <brgerst@...il.com>
To: "H. Peter Anvin" <hpa@...or.com>
Cc: "Jason A. Donenfeld" <Jason@...c4.com>, "Peter Zijlstra (Intel)" <peterz@...radead.org>, "Theodore Ts'o" <tytso@....edu>, 
	Thomas Weißschuh <thomas.weissschuh@...utronix.de>, 
	Xin Li <xin@...or.com>, Andrew Cooper <andrew.cooper3@...rix.com>, 
	Andy Lutomirski <luto@...nel.org>, Ard Biesheuvel <ardb@...nel.org>, Borislav Petkov <bp@...en8.de>, 
	Dave Hansen <dave.hansen@...ux.intel.com>, Ingo Molnar <mingo@...hat.com>, 
	James Morse <james.morse@....com>, Jarkko Sakkinen <jarkko@...nel.org>, 
	Josh Poimboeuf <jpoimboe@...nel.org>, Kees Cook <kees@...nel.org>, Nam Cao <namcao@...utronix.de>, 
	Oleg Nesterov <oleg@...hat.com>, Perry Yuan <perry.yuan@....com>, 
	Thomas Gleixner <tglx@...utronix.de>, Thomas Huth <thuth@...hat.com>, Uros Bizjak <ubizjak@...il.com>, 
	linux-kernel@...r.kernel.org, linux-mm@...ck.org, linux-sgx@...r.kernel.org, 
	x86@...nel.org
Subject: Re: [PATCH v4 07/10] x86/entry/vdso: include GNU_PROPERTY and
 GNU_STACK PHDRs

On Tue, Dec 16, 2025 at 4:26 PM H. Peter Anvin <hpa@...or.com> wrote:
>
> Currently the vdso doesn't include .note.gnu.property or a GNU noexec
> stack annotation (the -z noexecstack in the linker script is
> ineffective because we specify PHDRs explicitly.)
>
> The motivation is that the dynamic linker currently do not check
> these.
>
> However, this is a weak excuse: the vdso*.so are also supposed to be
> usable at link libraries, and there is no reason why the dynamic
> linker might not want or need to check these in the future, so add
> them back in -- it is trivial enough.
>
> Use symbolic constants for the PHDR permission flags.
>
> [ v4: drop unrelated formatting changes ]
>
> Signed-off-by: H. Peter Anvin (Intel) <hpa@...or.com>
> ---
>  arch/x86/entry/vdso/common/vdso-layout.lds.S | 38 ++++++++++++--------
>  1 file changed, 23 insertions(+), 15 deletions(-)
>
> diff --git a/arch/x86/entry/vdso/common/vdso-layout.lds.S b/arch/x86/entry/vdso/common/vdso-layout.lds.S
> index ec1ac191a057..a1e30be3e83d 100644
> --- a/arch/x86/entry/vdso/common/vdso-layout.lds.S
> +++ b/arch/x86/entry/vdso/common/vdso-layout.lds.S
> @@ -47,18 +47,18 @@ SECTIONS
>                 *(.gnu.linkonce.b.*)
>         }                                               :text
>
> -       /*
> -        * Discard .note.gnu.property sections which are unused and have
> -        * different alignment requirement from vDSO note sections.
> -        */
> -       /DISCARD/ : {
> +       .note.gnu.property : {
>                 *(.note.gnu.property)
> -       }
> -       .note           : { *(.note.*) }                :text   :note
> -
> -       .eh_frame_hdr   : { *(.eh_frame_hdr) }          :text   :eh_frame_hdr
> -       .eh_frame       : { KEEP (*(.eh_frame)) }       :text
> +       }                                       :text :note :gnu_property
> +       .note           : {
> +               *(.note*)
> +       }                                       :text :note
>
> +       .eh_frame_hdr   : { *(.eh_frame_hdr) }  :text :eh_frame_hdr
> +       .eh_frame       : {
> +               KEEP (*(.eh_frame))
> +               *(.eh_frame.*)
> +       }                                       :text
>
>         /*
>          * Text is well-separated from actual data: there's plenty of
> @@ -87,15 +87,23 @@ SECTIONS
>   * Very old versions of ld do not recognize this name token; use the constant.
>   */
>  #define PT_GNU_EH_FRAME        0x6474e550
> +#define PT_GNU_STACK   0x6474e551
> +#define PT_GNU_PROPERTY        0x6474e553

Do we even still support the old linkers that need these constants?


Brian Gerst

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ