diff options
| author | Alexander Stein <alexander.stein@ew.tq-group.com> | 2025-03-05 08:25:47 +0100 |
|---|---|---|
| committer | Alexander Stein <alexander.stein@ew.tq-group.com> | 2025-03-05 08:25:47 +0100 |
| commit | 7fb496c9c30a72846ac45e8d773052fb80c9957d (patch) | |
| tree | 4652e5c814f3504cdab6740c52a8f984c91d91af /recipes-security | |
| parent | 02940c32c8df155d142eaca9aca3d7811e64c669 (diff) | |
| download | meta-freescale-7fb496c9c30a72846ac45e8d773052fb80c9957d.tar.gz | |
optee-os: Remove upstreamed patches
Both patches have been upstreamed since 3.19.
Signed-off-by: Alexander Stein <alexander.stein@ew.tq-group.com>
Diffstat (limited to 'recipes-security')
3 files changed, 0 insertions, 202 deletions
diff --git a/recipes-security/optee-imx/optee-os/0003-arm32-libutils-libutee-ta-add-.note.GNU-stack-sectio.patch b/recipes-security/optee-imx/optee-os/0003-arm32-libutils-libutee-ta-add-.note.GNU-stack-sectio.patch deleted file mode 100644 index 1c5753c7f..000000000 --- a/recipes-security/optee-imx/optee-os/0003-arm32-libutils-libutee-ta-add-.note.GNU-stack-sectio.patch +++ /dev/null | |||
| @@ -1,133 +0,0 @@ | |||
| 1 | From 6f738803a59613ec4a683ddbc1747ebffd75a4e6 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Jerome Forissier <jerome.forissier@linaro.org> | ||
| 3 | Date: Tue, 23 Aug 2022 12:31:46 +0000 | ||
| 4 | Subject: [PATCH 3/4] arm32: libutils, libutee, ta: add .note.GNU-stack section | ||
| 5 | to | ||
| 6 | |||
| 7 | .S files | ||
| 8 | |||
| 9 | When building for arm32 with GNU binutils 2.39, the linker outputs | ||
| 10 | warnings when linking Trusted Applications: | ||
| 11 | |||
| 12 | arm-unknown-linux-uclibcgnueabihf-ld.bfd: warning: utee_syscalls_a32.o: missing .note.GNU-stack section implies executable stack | ||
| 13 | arm-unknown-linux-uclibcgnueabihf-ld.bfd: NOTE: This behaviour is deprecated and will be removed in a future version of the linker | ||
| 14 | |||
| 15 | We could silence the warning by adding the '-z execstack' option to the | ||
| 16 | TA link flags, like we did in the parent commit for the TEE core and | ||
| 17 | ldelf. Indeed, ldelf always allocates a non-executable piece of memory | ||
| 18 | for the TA to use as a stack. | ||
| 19 | |||
| 20 | However it seems preferable to comply with the common ELF practices in | ||
| 21 | this case. A better fix is therefore to add the missing .note.GNU-stack | ||
| 22 | sections in the assembler files. | ||
| 23 | |||
| 24 | Signed-off-by: Jerome Forissier <jerome.forissier@linaro.org> | ||
| 25 | |||
| 26 | Signed-off-by: Anton Antonov <Anton.Antonov@arm.com> | ||
| 27 | Upstream-Status: Backport [https://github.com/OP-TEE/optee_os/pull/5499] | ||
| 28 | Signed-off-by: Oleksandr Suvorov <oleksandr.suvorov@foundries.io> | ||
| 29 | --- | ||
| 30 | |||
| 31 | lib/libutee/arch/arm/utee_syscalls_a32.S | 2 ++ | ||
| 32 | lib/libutils/ext/arch/arm/atomic_a32.S | 2 ++ | ||
| 33 | lib/libutils/ext/arch/arm/mcount_a32.S | 2 ++ | ||
| 34 | lib/libutils/isoc/arch/arm/arm32_aeabi_divmod_a32.S | 2 ++ | ||
| 35 | lib/libutils/isoc/arch/arm/arm32_aeabi_ldivmod_a32.S | 2 ++ | ||
| 36 | lib/libutils/isoc/arch/arm/setjmp_a32.S | 2 ++ | ||
| 37 | ta/arch/arm/ta_entry_a32.S | 2 ++ | ||
| 38 | 7 files changed, 14 insertions(+) | ||
| 39 | |||
| 40 | diff --git a/lib/libutee/arch/arm/utee_syscalls_a32.S b/lib/libutee/arch/arm/utee_syscalls_a32.S | ||
| 41 | index 2dea83ab8..668b65a86 100644 | ||
| 42 | --- a/lib/libutee/arch/arm/utee_syscalls_a32.S | ||
| 43 | +++ b/lib/libutee/arch/arm/utee_syscalls_a32.S | ||
| 44 | @@ -9,6 +9,8 @@ | ||
| 45 | |||
| 46 | .section .note.GNU-stack,"",%progbits | ||
| 47 | |||
| 48 | + .section .note.GNU-stack,"",%progbits | ||
| 49 | + | ||
| 50 | .section .text | ||
| 51 | .balign 4 | ||
| 52 | .code 32 | ||
| 53 | diff --git a/lib/libutils/ext/arch/arm/atomic_a32.S b/lib/libutils/ext/arch/arm/atomic_a32.S | ||
| 54 | index 2be73ffad..87ddf1065 100644 | ||
| 55 | --- a/lib/libutils/ext/arch/arm/atomic_a32.S | ||
| 56 | +++ b/lib/libutils/ext/arch/arm/atomic_a32.S | ||
| 57 | @@ -7,6 +7,8 @@ | ||
| 58 | |||
| 59 | .section .note.GNU-stack,"",%progbits | ||
| 60 | |||
| 61 | + .section .note.GNU-stack,"",%progbits | ||
| 62 | + | ||
| 63 | /* uint32_t atomic_inc32(uint32_t *v); */ | ||
| 64 | FUNC atomic_inc32 , : | ||
| 65 | ldrex r1, [r0] | ||
| 66 | diff --git a/lib/libutils/ext/arch/arm/mcount_a32.S b/lib/libutils/ext/arch/arm/mcount_a32.S | ||
| 67 | index 54dc3c02d..2f24632b8 100644 | ||
| 68 | --- a/lib/libutils/ext/arch/arm/mcount_a32.S | ||
| 69 | +++ b/lib/libutils/ext/arch/arm/mcount_a32.S | ||
| 70 | @@ -9,6 +9,8 @@ | ||
| 71 | |||
| 72 | .section .note.GNU-stack,"",%progbits | ||
| 73 | |||
| 74 | + .section .note.GNU-stack,"",%progbits | ||
| 75 | + | ||
| 76 | /* | ||
| 77 | * Convert return address to call site address by subtracting the size of the | ||
| 78 | * mcount call instruction (blx __gnu_mcount_nc). | ||
| 79 | diff --git a/lib/libutils/isoc/arch/arm/arm32_aeabi_divmod_a32.S b/lib/libutils/isoc/arch/arm/arm32_aeabi_divmod_a32.S | ||
| 80 | index 37ae9ec6f..bc6c48b1a 100644 | ||
| 81 | --- a/lib/libutils/isoc/arch/arm/arm32_aeabi_divmod_a32.S | ||
| 82 | +++ b/lib/libutils/isoc/arch/arm/arm32_aeabi_divmod_a32.S | ||
| 83 | @@ -7,6 +7,8 @@ | ||
| 84 | |||
| 85 | .section .note.GNU-stack,"",%progbits | ||
| 86 | |||
| 87 | + .section .note.GNU-stack,"",%progbits | ||
| 88 | + | ||
| 89 | /* | ||
| 90 | * signed ret_idivmod_values(signed quot, signed rem); | ||
| 91 | * return quotient and remaining the EABI way (regs r0,r1) | ||
| 92 | diff --git a/lib/libutils/isoc/arch/arm/arm32_aeabi_ldivmod_a32.S b/lib/libutils/isoc/arch/arm/arm32_aeabi_ldivmod_a32.S | ||
| 93 | index 5c3353e2c..9fb5e0283 100644 | ||
| 94 | --- a/lib/libutils/isoc/arch/arm/arm32_aeabi_ldivmod_a32.S | ||
| 95 | +++ b/lib/libutils/isoc/arch/arm/arm32_aeabi_ldivmod_a32.S | ||
| 96 | @@ -7,6 +7,8 @@ | ||
| 97 | |||
| 98 | .section .note.GNU-stack,"",%progbits | ||
| 99 | |||
| 100 | + .section .note.GNU-stack,"",%progbits | ||
| 101 | + | ||
| 102 | /* | ||
| 103 | * __value_in_regs lldiv_t __aeabi_ldivmod( long long n, long long d) | ||
| 104 | */ | ||
| 105 | diff --git a/lib/libutils/isoc/arch/arm/setjmp_a32.S b/lib/libutils/isoc/arch/arm/setjmp_a32.S | ||
| 106 | index f8a0b70df..37d7cb88e 100644 | ||
| 107 | --- a/lib/libutils/isoc/arch/arm/setjmp_a32.S | ||
| 108 | +++ b/lib/libutils/isoc/arch/arm/setjmp_a32.S | ||
| 109 | @@ -53,6 +53,8 @@ | ||
| 110 | |||
| 111 | .section .note.GNU-stack,"",%progbits | ||
| 112 | |||
| 113 | + .section .note.GNU-stack,"",%progbits | ||
| 114 | + | ||
| 115 | /* Arm/Thumb interworking support: | ||
| 116 | |||
| 117 | The interworking scheme expects functions to use a BX instruction | ||
| 118 | diff --git a/ta/arch/arm/ta_entry_a32.S b/ta/arch/arm/ta_entry_a32.S | ||
| 119 | index cd9a12f9d..ccdc19928 100644 | ||
| 120 | --- a/ta/arch/arm/ta_entry_a32.S | ||
| 121 | +++ b/ta/arch/arm/ta_entry_a32.S | ||
| 122 | @@ -7,6 +7,8 @@ | ||
| 123 | |||
| 124 | .section .note.GNU-stack,"",%progbits | ||
| 125 | |||
| 126 | + .section .note.GNU-stack,"",%progbits | ||
| 127 | + | ||
| 128 | /* | ||
| 129 | * This function is the bottom of the user call stack. Mark it as such so that | ||
| 130 | * the unwinding code won't try to go further down. | ||
| 131 | -- | ||
| 132 | 2.43.2 | ||
| 133 | |||
diff --git a/recipes-security/optee-imx/optee-os/0004-core-link-add-no-warn-rwx-segments.patch b/recipes-security/optee-imx/optee-os/0004-core-link-add-no-warn-rwx-segments.patch deleted file mode 100644 index f32b2284f..000000000 --- a/recipes-security/optee-imx/optee-os/0004-core-link-add-no-warn-rwx-segments.patch +++ /dev/null | |||
| @@ -1,67 +0,0 @@ | |||
| 1 | From a63f82f74e015eb662242cdb51ef814e3f576829 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Jerome Forissier <jerome.forissier@linaro.org> | ||
| 3 | Date: Fri, 5 Aug 2022 09:48:03 +0200 | ||
| 4 | Subject: [PATCH 4/4] core: link: add --no-warn-rwx-segments | ||
| 5 | |||
| 6 | Signed-off-by: Anton Antonov <Anton.Antonov@arm.com> | ||
| 7 | Upstream-Status: Backport [https://github.com/OP-TEE/optee_os/pull/5474] | ||
| 8 | |||
| 9 | binutils ld.bfd generates one RWX LOAD segment by merging several sections | ||
| 10 | with mixed R/W/X attributes (.text, .rodata, .data). After version 2.38 it | ||
| 11 | also warns by default when that happens [1], which breaks the build due to | ||
| 12 | --fatal-warnings. The RWX segment is not a problem for the TEE core, since | ||
| 13 | that information is not used to set memory permissions. Therefore, silence | ||
| 14 | the warning. | ||
| 15 | |||
| 16 | Link: [1] https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=ba951afb99912da01a6e8434126b8fac7aa75107 | ||
| 17 | Link: https://sourceware.org/bugzilla/show_bug.cgi?id=29448 | ||
| 18 | Reported-by: Dominique Martinet <dominique.martinet@atmark-techno.com> | ||
| 19 | Signed-off-by: Jerome Forissier <jerome.forissier@linaro.org> | ||
| 20 | Acked-by: Jens Wiklander <jens.wiklander@linaro.org> | ||
| 21 | Signed-off-by: Oleksandr Suvorov <oleksandr.suvorov@foundries.io> | ||
| 22 | --- | ||
| 23 | |||
| 24 | core/arch/arm/kernel/link.mk | 6 ++++-- | ||
| 25 | 1 file changed, 4 insertions(+), 2 deletions(-) | ||
| 26 | |||
| 27 | diff --git a/core/arch/arm/kernel/link.mk b/core/arch/arm/kernel/link.mk | ||
| 28 | index 49e9f4fa1..9e1cc172f 100644 | ||
| 29 | --- a/core/arch/arm/kernel/link.mk | ||
| 30 | +++ b/core/arch/arm/kernel/link.mk | ||
| 31 | @@ -37,6 +37,7 @@ link-ldflags += --sort-section=alignment | ||
| 32 | link-ldflags += --fatal-warnings | ||
| 33 | link-ldflags += --gc-sections | ||
| 34 | link-ldflags += $(link-ldflags-common) | ||
| 35 | +link-ldflags += $(call ld-option,--no-warn-rwx-segments) | ||
| 36 | |||
| 37 | link-ldadd = $(LDADD) | ||
| 38 | link-ldadd += $(ldflags-external) | ||
| 39 | @@ -61,6 +62,7 @@ link-script-cppflags := \ | ||
| 40 | $(cppflagscore)) | ||
| 41 | |||
| 42 | ldargs-all_objs := -T $(link-script-dummy) --no-check-sections \ | ||
| 43 | + $(call ld-option,--no-warn-rwx-segments) \ | ||
| 44 | $(link-ldflags-common) \ | ||
| 45 | $(link-objs) $(link-ldadd) $(libgcccore) | ||
| 46 | cleanfiles += $(link-out-dir)/all_objs.o | ||
| 47 | @@ -75,7 +77,7 @@ $(link-out-dir)/unpaged_entries.txt: $(link-out-dir)/all_objs.o | ||
| 48 | $(AWK) '/ ____keep_pager/ { printf "-u%s ", $$3 }' > $@ | ||
| 49 | |||
| 50 | unpaged-ldargs := -T $(link-script-dummy) --no-check-sections --gc-sections \ | ||
| 51 | - $(link-ldflags-common) | ||
| 52 | + $(link-ldflags-common) $(call ld-option,--no-warn-rwx-segments) | ||
| 53 | unpaged-ldadd := $(objs) $(link-ldadd) $(libgcccore) | ||
| 54 | cleanfiles += $(link-out-dir)/unpaged.o | ||
| 55 | $(link-out-dir)/unpaged.o: $(link-out-dir)/unpaged_entries.txt | ||
| 56 | @@ -104,7 +106,7 @@ $(link-out-dir)/init_entries.txt: $(link-out-dir)/all_objs.o | ||
| 57 | $(AWK) '/ ____keep_init/ { printf "-u%s ", $$3 }' > $@ | ||
| 58 | |||
| 59 | init-ldargs := -T $(link-script-dummy) --no-check-sections --gc-sections \ | ||
| 60 | - $(link-ldflags-common) | ||
| 61 | + $(link-ldflags-common) $(call ld-option,--no-warn-rwx-segments) | ||
| 62 | init-ldadd := $(link-objs-init) $(link-out-dir)/version.o $(link-ldadd) \ | ||
| 63 | $(libgcccore) | ||
| 64 | cleanfiles += $(link-out-dir)/init.o | ||
| 65 | -- | ||
| 66 | 2.43.2 | ||
| 67 | |||
diff --git a/recipes-security/optee-imx/optee-os_4.2.0.imx.bb b/recipes-security/optee-imx/optee-os_4.2.0.imx.bb index ada545a63..11da204e9 100644 --- a/recipes-security/optee-imx/optee-os_4.2.0.imx.bb +++ b/recipes-security/optee-imx/optee-os_4.2.0.imx.bb | |||
| @@ -5,8 +5,6 @@ require optee-os-fslc-imx.inc | |||
| 5 | SRC_URI += " \ | 5 | SRC_URI += " \ |
| 6 | file://0001-core-Define-section-attributes-for-clang.patch \ | 6 | file://0001-core-Define-section-attributes-for-clang.patch \ |
| 7 | file://0002-optee-enable-clang-support.patch \ | 7 | file://0002-optee-enable-clang-support.patch \ |
| 8 | file://0003-arm32-libutils-libutee-ta-add-.note.GNU-stack-sectio.patch \ | ||
| 9 | file://0004-core-link-add-no-warn-rwx-segments.patch \ | ||
| 10 | " | 8 | " |
| 11 | SRCBRANCH = "lf-6.6.36_2.1.0" | 9 | SRCBRANCH = "lf-6.6.36_2.1.0" |
| 12 | SRCREV = "612bc5a642a4608d282abeee2349d86de996d7ee" | 10 | SRCREV = "612bc5a642a4608d282abeee2349d86de996d7ee" |
