Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
GenFw: auto set nxcompat flag (#456)
## Description GenFw will now automatically set the nxcompat if the PE file meets the requirements. Those requirements are: 1. A 64 bit PE file 2. Has 4K alignment or is evenly divisible by 4K 3. No section has both Write and Execute This fixup takes place inside the main function, scoped to only when the PE's OptionalHeader's Magic is EFI_IMAGE_NT_OPTIONAL_HDR64_MAGIC - [x] Impacts functionality? - **Functionality** - Does the change ultimately impact how firmware functions? - Examples: Add a new library, publish a new PPI, update an algorithm, ... - [x] Impacts security? - **Security** - Does the change have a direct security impact on an application, flow, or firmware? - Examples: Crypto algorithm change, buffer overflow fix, parameter validation improvement, ... - [ ] Breaking change? - **Breaking change** - Will anyone consuming this change experience a break in build or boot behavior? - Examples: Add a new library class, move a module to a different repo, call a function in a new library class in a pre-existing module, ... - [ ] Includes tests? - **Tests** - Does the change include any explicit test code? - Examples: Unit tests, integration tests, robot tests, ... - [ ] Includes documentation? - **Documentation** - Does the change contain explicit documentation additions outside direct code modifications (and comments)? - Examples: Update readme file, add feature readme file, link to documentation on an a separate Web page, ... ## How This Was Tested 1. Verified proper build on Windows and Fedora 2. Verified proper build on Windows with /NXCOMPAT and SUBSYSTEM:CONSOLE removed from VS2022 X64 DLINK_FLAGS 1. Verified nxcompat flags were properly set on binaries built with GCC5 and VS2022 2. Verified MemoryProtectionTestApp.efi passes all `Security.NxProtection` tests on QemuQ35 and Sbsa VS2022 / GCC5 3. Verified MemoryAttributeProtocolFuncTestApp.efi, DxePagingAuditTestApp.efi pass on QemuQ35 VS2022 / GCC5 ## Integration Instructions N/A --------- Signed-off-by: Joey Vagedes <[email protected]> Co-authored-by: Michael Kubacki <[email protected]>
- Loading branch information