nuttx/libs/libc/elf/elf_unload.c
Marco Casaroli 1aa32bbc07 libs/libc/elf: Place an FDPIC object's segments independently.
An ET_DYN object is loaded into one allocation with its data behind its
text, because its data references sit at a fixed distance from the code
that makes them.  An FDPIC object does not work that way: it reaches its
data through a base register, so the two segments can be placed wherever
suits, and the point of the format is that the read-only one is left on
the media and executed there while only the writable one is copied.  One
copy of the text then serves every instance.

So libelf_load() grows a second case.  The object announces itself in the
OS/ABI byte, which is noted once in libelf_loadhdrs() rather than
re-derived; e_flags cannot be used for this, as an FDPIC object's are an
unremarkable EABI version and testing them would reject every valid
module.  Text is taken from the media address plus the segment's own file
offset -- the same arithmetic the ET_REL path already does with
sh_offset -- and libelf_loadfile() does not read it.  If the filesystem
cannot show its media, the loader copies the text to RAM instead.  The
module then loses the shared text and the flash saving, but it runs.

Obtaining that address needs two mechanisms, and they are not
interchangeable.  A compacting filesystem can move a file's blocks, so it
hands out an address only with a pin that holds them still and expects
the pin back; xipfs is the one in tree.  A filesystem whose layout never
changes has nothing to hold and answers FIOC_XIPBASE with a bare address;
romfs and tmpfs are those.  libelf_xipacquire() asks for the pin first,
because a filesystem that needs one is not safe without it, and
libelf_unload() gives it back.  The loader asks for a pin only if it can
hold one, or the pin would stay for ever.

The pin is thus not specific to FDPIC.  Any module that executes in place
from a compacting filesystem takes one, and gives it back at unload.

mmap() is not used, though both filesystems implement it.  The mapping
would be recorded against whichever task called the loader, while the
release happens when the module's own task exits, which is a different
group -- so the pin would outlive the module and the extent would never
become movable again.

Unloading has to change with placement: the existing path frees only
textalloc because ET_DYN had a single allocation, which would leak an
FDPIC object's data and free media the filesystem only lent us.

Nothing here runs for a non-FDPIC object; every branch is behind the flag
and the single-allocation path is untouched.  Built and booted
mps3-an547:picostest, which is CONFIG_ELF with CONFIG_PIC, with no change
in behaviour.

Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-09-08 16:31:16 -03:00

172 lines
4.8 KiB
C

/****************************************************************************
* libs/libc/elf/elf_unload.c
*
* SPDX-License-Identifier: Apache-2.0
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <stdlib.h>
#include <nuttx/debug.h>
#include <nuttx/arch.h>
#include <nuttx/lib/elf.h>
#include "libc.h"
#include "elf/elf.h"
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: libelf_unload
*
* Description:
* This function unloads the object from memory. This essentially undoes
* the actions of libelf_load(). It is called only under certain error
* conditions after the module has been loaded but not yet started.
*
* Returned Value:
* 0 (OK) is returned on success and a negated errno is returned on
* failure.
*
****************************************************************************/
int libelf_unload(FAR struct mod_loadinfo_s *loadinfo)
{
/* Free all working buffers */
libelf_freebuffers(loadinfo);
#ifdef HAVE_LIBC_ELF_PIN
/* Give the pin back if the loader took one, so the filesystem can
* reclaim the extent.
*/
if (loadinfo->pinfile != NULL)
{
libelf_pinrelease(&loadinfo->pinfile);
}
#endif
#ifdef CONFIG_ARCH_ADDRENV
if (loadinfo->addrenv != NULL)
{
libelf_addrenv_free(loadinfo);
}
else
#endif
/* Release memory holding the relocated ELF image */
/* An FDPIC object placed its two segments separately. Free each one. If
* the text stayed on the media, it was never allocated, thus leave it.
*/
if (loadinfo->fdpic)
{
if (loadinfo->textalloc != 0 && loadinfo->xipbase == 0)
{
#ifdef CONFIG_ARCH_USE_TEXT_HEAP
up_textheap_free((FAR void *)loadinfo->textalloc);
#else
lib_free((FAR void *)loadinfo->textalloc);
#endif
}
if (loadinfo->datastart != 0)
{
lib_free((FAR void *)loadinfo->datastart);
loadinfo->datastart = 0;
}
loadinfo->textalloc = 0;
loadinfo->textsize = 0;
loadinfo->datasize = 0;
}
/* Any other ET_DYN has a single allocation so we only free textalloc */
else if (loadinfo->ehdr.e_type != ET_DYN)
{
#ifdef CONFIG_ARCH_USE_SEPARATED_SECTION
int i;
for (i = 0; loadinfo->sectalloc[i] != 0 &&
i < loadinfo->ehdr.e_shnum; i++)
{
# ifdef CONFIG_ARCH_USE_TEXT_HEAP
if (up_textheap_heapmember((FAR void *)loadinfo->sectalloc[i]))
{
up_textheap_free((FAR void *)loadinfo->sectalloc[i]);
}
else
# endif
# ifdef CONFIG_ARCH_USE_DATA_HEAP
if (up_dataheap_heapmember((FAR void *)loadinfo->sectalloc[i]))
{
up_dataheap_free((FAR void *)loadinfo->sectalloc[i]);
}
else
# endif
{
lib_free((FAR void *)loadinfo->sectalloc[i]);
}
}
lib_free(loadinfo->sectalloc);
#else
if (loadinfo->textalloc != 0 && loadinfo->xipbase == 0)
{
# if defined(CONFIG_ARCH_USE_TEXT_HEAP)
up_textheap_free((FAR void *)loadinfo->textalloc);
# else
lib_free((FAR void *)loadinfo->textalloc);
# endif
}
if (loadinfo->datastart != 0)
{
# if defined(CONFIG_ARCH_USE_DATA_HEAP)
up_dataheap_free((FAR void *)loadinfo->datastart);
# else
lib_free((FAR void *)loadinfo->datastart);
# endif
}
#endif
}
else
{
lib_free((FAR void *)loadinfo->textalloc);
}
/* Clear out all indications of the allocated address environment */
loadinfo->textalloc = 0;
loadinfo->datastart = 0;
loadinfo->textsize = 0;
loadinfo->datasize = 0;
return OK;
}