Skip to content

Glossary

RELRO

Relocation Read-Only: a linker and loader feature that makes the GOT and other relocation data read-only after startup, so they cannot be overwritten.

RELRO (Relocation Read-Only) protects the data structures the dynamic loader fills in when a program starts, chiefly the Global Offset Table (GOT) that holds addresses of library functions. Partial RELRO (-Wl,-z,relro) makes most of this data read-only after relocation but leaves the lazily bound .got.plt writable. Full RELRO adds -Wl,-z,now, resolving every symbol at startup so the whole GOT can be locked.

Full RELRO removes a classic way of redirecting a library call through a memory-corruption bug, at the cost of slightly slower startup for binaries with many imports. Check it with readelf -l (GNU_RELRO) and readelf -d (BIND_NOW). See binary hardening flags.