1 /* SPDX-License-Identifier: GPL-2.0 */
3 * ld script for the x86 kernel
5 * Historic 32-bit version written by Martin Mares <mj@atrey.karlin.mff.cuni.cz>
7 * Modernisation, unification and other changes and fixes:
8 * Copyright (C) 2007-2009 Sam Ravnborg <sam@ravnborg.org>
11 * Don't define absolute symbols until and unless you know that symbol
12 * value is should remain constant even if kernel image is relocated
13 * at run time. Absolute symbols are not relocated. If symbol value should
14 * change if kernel is relocated, make the symbol section relative and
15 * put it inside the section definition.
19 #define LOAD_OFFSET __PAGE_OFFSET
21 #define LOAD_OFFSET __START_KERNEL_map
24 #define RUNTIME_DISCARD_EXIT
26 #define RO_EXCEPTION_TABLE_ALIGN 16
28 #include <asm-generic/vmlinux.lds.h>
29 #include <asm/asm-offsets.h>
30 #include <asm/thread_info.h>
31 #include <asm/page_types.h>
32 #include <asm/orc_lookup.h>
33 #include <asm/cache.h>
36 #undef i386 /* in case the preprocessor is a 32bit one */
38 OUTPUT_FORMAT(CONFIG_OUTPUT_FORMAT)
42 ENTRY(phys_startup_32)
44 OUTPUT_ARCH(i386:x86-64)
45 ENTRY(phys_startup_64)
50 #if defined(CONFIG_X86_64)
52 * On 64-bit, align RODATA to 2MB so we retain large page mappings for
53 * boundaries spanning kernel text, rodata and data sections.
55 * However, kernel identity mappings will have different RWX permissions
56 * to the pages mapping to text and to the pages padding (which are freed) the
57 * text section. Hence kernel identity mappings will be broken to smaller
58 * pages. For 64-bit, kernel text and kernel identity mappings are different,
59 * so we can enable protection checks as well as retain 2MB large page
60 * mappings for kernel text.
62 #define X86_ALIGN_RODATA_BEGIN . = ALIGN(HPAGE_SIZE);
64 #define X86_ALIGN_RODATA_END \
65 . = ALIGN(HPAGE_SIZE); \
66 __end_rodata_hpage_align = .; \
67 __end_rodata_aligned = .;
69 #define ALIGN_ENTRY_TEXT_BEGIN . = ALIGN(PMD_SIZE);
70 #define ALIGN_ENTRY_TEXT_END . = ALIGN(PMD_SIZE);
73 * This section contains data which will be mapped as decrypted. Memory
74 * encryption operates on a page basis. Make this section PMD-aligned
75 * to avoid splitting the pages while mapping the section early.
77 * Note: We use a separate section so that only this section gets
78 * decrypted to avoid exposing more than we wish.
80 #define BSS_DECRYPTED \
81 . = ALIGN(PMD_SIZE); \
82 __start_bss_decrypted = .; \
84 . = ALIGN(PAGE_SIZE); \
85 __start_bss_decrypted_unused = .; \
86 . = ALIGN(PMD_SIZE); \
87 __end_bss_decrypted = .; \
91 #define X86_ALIGN_RODATA_BEGIN
92 #define X86_ALIGN_RODATA_END \
93 . = ALIGN(PAGE_SIZE); \
94 __end_rodata_aligned = .;
96 #define ALIGN_ENTRY_TEXT_BEGIN
97 #define ALIGN_ENTRY_TEXT_END
103 text PT_LOAD FLAGS(5); /* R_E */
104 data PT_LOAD FLAGS(6); /* RW_ */
107 percpu PT_LOAD FLAGS(6); /* RW_ */
109 init PT_LOAD FLAGS(7); /* RWE */
111 note PT_NOTE FLAGS(0); /* ___ */
117 . = LOAD_OFFSET + LOAD_PHYSICAL_ADDR;
118 phys_startup_32 = ABSOLUTE(startup_32 - LOAD_OFFSET);
121 phys_startup_64 = ABSOLUTE(startup_64 - LOAD_OFFSET);
124 /* Text and read-only data */
125 .text : AT(ADDR(.text) - LOAD_OFFSET) {
128 /* bootstrapping code */
135 ALIGN_ENTRY_TEXT_BEGIN
136 #ifdef CONFIG_CPU_SRSO
137 *(.text..__x86.rethunk_untrain)
142 #ifdef CONFIG_CPU_SRSO
144 * See the comment above srso_alias_untrain_ret()'s
147 . = srso_alias_untrain_ret | (1 << 2) | (1 << 8) | (1 << 14) | (1 << 20);
148 *(.text..__x86.rethunk_safe)
156 #ifdef CONFIG_RETPOLINE
157 __indirect_thunk_start = .;
158 *(.text..__x86.indirect_thunk)
159 *(.text..__x86.return_thunk)
160 __indirect_thunk_end = .;
164 /* End of text section, which should occupy whole number of pages */
167 . = ALIGN(PAGE_SIZE);
169 X86_ALIGN_RODATA_BEGIN
174 .data : AT(ADDR(.data) - LOAD_OFFSET) {
175 /* Start of data section */
179 INIT_TASK_DATA(THREAD_SIZE)
182 /* 32 bit has nosave before _edata */
186 PAGE_ALIGNED_DATA(PAGE_SIZE)
188 CACHELINE_ALIGNED_DATA(L1_CACHE_BYTES)
193 /* rarely changed data like cpu maps */
194 READ_MOSTLY_DATA(INTERNODE_CACHE_BYTES)
196 /* End of data section */
204 . = ALIGN(PAGE_SIZE);
207 .vvar : AT(ADDR(.vvar) - LOAD_OFFSET) {
208 /* work around gold bug 13023 */
209 __vvar_beginning_hack = .;
211 /* Place all vvars at the offsets in asm/vvar.h. */
212 #define EMIT_VVAR(name, offset) \
213 . = __vvar_beginning_hack + offset; \
215 #include <asm/vvar.h>
219 * Pad the rest of the page with zeros. Otherwise the loader
220 * can leave garbage here.
222 . = __vvar_beginning_hack + PAGE_SIZE;
225 . = ALIGN(__vvar_page + PAGE_SIZE, PAGE_SIZE);
227 /* Init code and data - will be freed after init */
228 . = ALIGN(PAGE_SIZE);
229 .init.begin : AT(ADDR(.init.begin) - LOAD_OFFSET) {
230 __init_begin = .; /* paired with __init_end */
233 #if defined(CONFIG_X86_64) && defined(CONFIG_SMP)
235 * percpu offsets are zero-based on SMP. PERCPU_VADDR() changes the
236 * output PHDR, so the next output section - .init.text - should
237 * start another segment - init.
239 PERCPU_VADDR(INTERNODE_CACHE_BYTES, 0, :percpu)
240 ASSERT(SIZEOF(.data..percpu) < CONFIG_PHYSICAL_START,
241 "per-CPU data too large - increase CONFIG_PHYSICAL_START")
244 INIT_TEXT_SECTION(PAGE_SIZE)
250 * Section for code used exclusively before alternatives are run. All
251 * references to such code must be patched out by alternatives, normally
252 * by using X86_FEATURE_ALWAYS CPU feature bit.
254 * See static_cpu_has() for an example.
256 .altinstr_aux : AT(ADDR(.altinstr_aux) - LOAD_OFFSET) {
260 INIT_DATA_SECTION(16)
262 .x86_cpu_dev.init : AT(ADDR(.x86_cpu_dev.init) - LOAD_OFFSET) {
263 __x86_cpu_dev_start = .;
265 __x86_cpu_dev_end = .;
268 #ifdef CONFIG_X86_INTEL_MID
269 .x86_intel_mid_dev.init : AT(ADDR(.x86_intel_mid_dev.init) - \
271 __x86_intel_mid_dev_start = .;
272 *(.x86_intel_mid_dev.init)
273 __x86_intel_mid_dev_end = .;
278 * start address and size of operations which during runtime
279 * can be patched with virtualization friendly instructions or
280 * baremetal native ones. Think page table operations.
281 * Details in paravirt_types.h
284 .parainstructions : AT(ADDR(.parainstructions) - LOAD_OFFSET) {
285 __parainstructions = .;
287 __parainstructions_end = .;
290 #ifdef CONFIG_RETPOLINE
292 * List of instructions that call/jmp/jcc to retpoline thunks
293 * __x86_indirect_thunk_*(). These instructions can be patched along
294 * with alternatives, after which the section can be freed.
297 .retpoline_sites : AT(ADDR(.retpoline_sites) - LOAD_OFFSET) {
298 __retpoline_sites = .;
300 __retpoline_sites_end = .;
304 .return_sites : AT(ADDR(.return_sites) - LOAD_OFFSET) {
307 __return_sites_end = .;
312 * struct alt_inst entries. From the header (alternative.h):
313 * "Alternative instructions for different CPU types or capabilities"
314 * Think locking instructions on spinlocks.
317 .altinstructions : AT(ADDR(.altinstructions) - LOAD_OFFSET) {
318 __alt_instructions = .;
320 __alt_instructions_end = .;
324 * And here are the replacement instructions. The linker sticks
325 * them as binary blobs. The .altinstructions has enough data to
326 * get the address and the length of them to patch the kernel safely.
328 .altinstr_replacement : AT(ADDR(.altinstr_replacement) - LOAD_OFFSET) {
329 *(.altinstr_replacement)
333 * struct iommu_table_entry entries are injected in this section.
334 * It is an array of IOMMUs which during run time gets sorted depending
335 * on its dependency order. After rootfs_initcall is complete
336 * this section can be safely removed.
338 .iommu_table : AT(ADDR(.iommu_table) - LOAD_OFFSET) {
341 __iommu_table_end = .;
345 .apicdrivers : AT(ADDR(.apicdrivers) - LOAD_OFFSET) {
348 __apicdrivers_end = .;
353 * .exit.text is discarded at runtime, not link time, to deal with
354 * references from .altinstructions
356 .exit.text : AT(ADDR(.exit.text) - LOAD_OFFSET) {
360 .exit.data : AT(ADDR(.exit.data) - LOAD_OFFSET) {
364 #if !defined(CONFIG_X86_64) || !defined(CONFIG_SMP)
365 PERCPU_SECTION(INTERNODE_CACHE_BYTES)
368 . = ALIGN(PAGE_SIZE);
370 /* freed after init ends here */
371 .init.end : AT(ADDR(.init.end) - LOAD_OFFSET) {
376 * smp_locks might be freed after init
377 * start/end must be page aligned
379 . = ALIGN(PAGE_SIZE);
380 .smp_locks : AT(ADDR(.smp_locks) - LOAD_OFFSET) {
383 . = ALIGN(PAGE_SIZE);
388 .data_nosave : AT(ADDR(.data_nosave) - LOAD_OFFSET) {
394 . = ALIGN(PAGE_SIZE);
395 .bss : AT(ADDR(.bss) - LOAD_OFFSET) {
397 *(.bss..page_aligned)
398 . = ALIGN(PAGE_SIZE);
401 . = ALIGN(PAGE_SIZE);
406 * The memory occupied from _text to here, __end_of_kernel_reserve, is
407 * automatically reserved in setup_arch(). Anything after here must be
408 * explicitly reserved using memblock_reserve() or it will be discarded
409 * and treated as available memory.
411 __end_of_kernel_reserve = .;
413 . = ALIGN(PAGE_SIZE);
414 .brk : AT(ADDR(.brk) - LOAD_OFFSET) {
416 . += 64 * 1024; /* 64k alignment slop space */
417 *(.bss..brk) /* areas brk users have reserved */
421 . = ALIGN(PAGE_SIZE); /* keep VO_INIT_SIZE page aligned */
424 #ifdef CONFIG_AMD_MEM_ENCRYPT
426 * Early scratch/workarea section: Lives outside of the kernel proper
429 * Resides after _end because even though the .brk section is after
430 * __end_of_kernel_reserve, the .brk section is later reserved as a
431 * part of the kernel. Since it is located after __end_of_kernel_reserve
432 * it will be discarded and become part of the available memory. As
433 * such, it can only be used by very early boot code and must not be
436 * Currently used by SME for performing in-place encryption of the
437 * kernel during boot. Resides on a 2MB boundary to simplify the
438 * pagetable setup used for SME in-place encryption.
440 . = ALIGN(HPAGE_SIZE);
441 .init.scratch : AT(ADDR(.init.scratch) - LOAD_OFFSET) {
442 __init_scratch_begin = .;
444 . = ALIGN(HPAGE_SIZE);
445 __init_scratch_end = .;
456 * Make sure that the .got.plt is either completely empty or it
457 * contains only the lazy dispatch entries.
459 .got.plt (INFO) : { *(.got.plt) }
460 ASSERT(SIZEOF(.got.plt) == 0 ||
462 SIZEOF(.got.plt) == 0x18,
464 SIZEOF(.got.plt) == 0xc,
466 "Unexpected GOT/PLT entries detected!")
469 * Sections that should stay zero sized, which is safer to
470 * explicitly check instead of blindly discarding.
475 ASSERT(SIZEOF(.got) == 0, "Unexpected GOT entries detected!")
478 *(.plt) *(.plt.*) *(.iplt)
480 ASSERT(SIZEOF(.plt) == 0, "Unexpected run-time procedure linkages detected!")
485 ASSERT(SIZEOF(.rel.dyn) == 0, "Unexpected run-time relocations (.rel) detected!")
488 *(.rela.*) *(.rela_*)
490 ASSERT(SIZEOF(.rela.dyn) == 0, "Unexpected run-time relocations (.rela) detected!")
495 * The ASSERT() sink to . is intentional, for binutils 2.14 compatibility:
497 . = ASSERT((_end - LOAD_OFFSET <= KERNEL_IMAGE_SIZE),
498 "kernel image bigger than KERNEL_IMAGE_SIZE");
501 * Per-cpu symbols which need to be offset from __per_cpu_load
502 * for the boot processor.
504 #define INIT_PER_CPU(x) init_per_cpu__##x = ABSOLUTE(x) + __per_cpu_load
505 INIT_PER_CPU(gdt_page);
506 INIT_PER_CPU(fixed_percpu_data);
507 INIT_PER_CPU(irq_stack_backing_store);
510 * Build-time check on the image size:
512 . = ASSERT((_end - _text <= KERNEL_IMAGE_SIZE),
513 "kernel image bigger than KERNEL_IMAGE_SIZE");
516 . = ASSERT((fixed_percpu_data == 0),
517 "fixed_percpu_data is not at start of per-cpu area");
520 #ifdef CONFIG_RETHUNK
521 . = ASSERT((retbleed_return_thunk & 0x3f) == 0, "retbleed_return_thunk not cacheline-aligned");
522 . = ASSERT((srso_safe_ret & 0x3f) == 0, "srso_safe_ret not cacheline-aligned");
525 #ifdef CONFIG_CPU_SRSO
527 * GNU ld cannot do XOR until 2.41.
528 * https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=f6f78318fca803c4907fb8d7f6ded8295f1947b1
530 * LLVM lld cannot do XOR until lld-17.
531 * https://github.com/llvm/llvm-project/commit/fae96104d4378166cbe5c875ef8ed808a356f3fb
533 * Instead do: (A | B) - (A & B) in order to compute the XOR
534 * of the two function addresses:
536 . = ASSERT(((ABSOLUTE(srso_alias_untrain_ret) | srso_alias_safe_ret) -
537 (ABSOLUTE(srso_alias_untrain_ret) & srso_alias_safe_ret)) == ((1 << 2) | (1 << 8) | (1 << 14) | (1 << 20)),
538 "SRSO function pair won't alias");
541 #endif /* CONFIG_X86_32 */
543 #ifdef CONFIG_KEXEC_CORE
544 #include <asm/kexec.h>
546 . = ASSERT(kexec_control_code_size <= KEXEC_CONTROL_CODE_MAX_SIZE,
547 "kexec control code size is too big");