[PATCH] elf: Check PDE load address with non-empty text section

Aurelien Jarno aurelien@aurel32.net
Sun Jan 5 12:10:58 GMT 2025


On 2024-12-02 14:36, H.J. Lu wrote:
> On Mon, Dec 2, 2024 at 9:15 AM H.J. Lu <hjl.tools@gmail.com> wrote:
> >
> > On Sat, Nov 30, 2024 at 12:18 PM H.J. Lu <hjl.tools@gmail.com> wrote:
> > >
> > > On Sat, Nov 30, 2024, 12:52 AM Florian Weimer <fweimer@redhat.com> wrote:
> > >>
> > >> * H. J. Lu:
> > >>
> > >> > +ifneq (,$(load-address-ldflag))
> > >> > +tests += \
> > >> > +  tst-pie-address \
> > >> > +  # tests
> > >> > +tests-pie += \
> > >> > +  tst-pie-address \
> > >> > +  # tests-pie
> > >> > +LDFLAGS-tst-pie-address += $(load-address-ldflag)=$(pde-load-address)
> > >> > +ifeq (yes,$(enable-static-pie))
> > >> > +tests += \
> > >> > +  tst-pie-address-static \
> > >> > +  # tests
> > >> > +tests-static += \
> > >> > +  tst-pie-address-static \
> > >> > +  # tests-static
> > >> > +LDFLAGS-tst-pie-address-static += \
> > >> > +  $(load-address-ldflag)=$(pde-load-address)
> > >> > +endif
> > >> > +endif
> > >>
> > >> These tests fail on aarch64 and s390x for us:
> > >>
> > >> =====FAIL: elf/tst-pie-address.out=====
> > >> =====FAIL: elf/tst-pie-address.test-result=====
> > >> FAIL: elf/tst-pie-address
> > >> original exit status 139
> > >> =====FAIL: elf/tst-pie-address-static.out=====
> > >> =====FAIL: elf/tst-pie-address-static.test-result=====
> > >> FAIL: elf/tst-pie-address-static
> > >> original exit status 132
> > >
> > >
> > > Do they fail without -Ttext-segment=? My change doesn't
> > > touch dynamic PIE.  If it fails, it may be due to glibc or ld bugs.
> > >
> > >>
> > >> The configure checks report this
> > >>
> > >> checking whether -fPIE is default... no
> > >> checking PDE load address... 0x0000000001000000
> >
> > Somehow aarch64 got
> >
> > pde-load-address =
> >
> > in config.make.  I will take a look.
> >
> 
> Does this patch it for you?
> 

Unfortunately those tests still fail here on aarch64, even with that
patch installed, even if the PDE load address seems correctly detected:

| checking whether -fPIE is default... yes
| checking PDE load address... 0x0000000000400000
| checking for linker that supports -Ttext-segment=0x0000000000400000... yes
| checking if we can build programs as PIE... yes

I have found that they only fail with a compiler defaulting to
-mbranch-protection=standard. This can also be reproduced by
running:

CC="gcc -mbranch-protection=standard" CXX="g++ -mbranch-protection=standard" ../glibc/configure --prefix=/usr && make -j4 && make -j4 check

-- 
Aurelien Jarno                          GPG: 4096R/1DDD8C9B
aurelien@aurel32.net                     http://aurel32.net


More information about the Libc-alpha mailing list