/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Contents of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1.133 - (show annotations) (download) (as text)
Wed Mar 8 05:32:53 2006 UTC (8 years, 8 months ago) by vapier
Branch: MAIN
Changes since 1.132: +5 -5 lines
File MIME type: text/x-csrc
declare a few more things const

1 /*
2 * Copyright 2003-2006 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/scanelf.c,v 1.132 2006/03/07 17:48:17 solar Exp $
5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org>
8 */
9
10 #include "paxinc.h"
11
12 static const char *rcsid = "$Id: scanelf.c,v 1.132 2006/03/07 17:48:17 solar Exp $";
13 #define argv0 "scanelf"
14
15 #define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 #define do_state(option, flag) \
19 if (islower(option)) { \
20 flags &= ~PF_##flag; \
21 flags |= PF_NO##flag; \
22 } else { \
23 flags &= ~PF_NO##flag; \
24 flags |= PF_##flag; \
25 }
26
27
28 /* prototypes */
29 static int scanelf_elfobj(elfobj *elf);
30 static int scanelf_elf(const char *filename, int fd, size_t len);
31 static int scanelf_archive(const char *filename, int fd, size_t len);
32 static void scanelf_file(const char *filename);
33 static void scanelf_dir(const char *path);
34 static void scanelf_ldpath(void);
35 static void scanelf_envpath(void);
36 static void usage(int status);
37 static void parseargs(int argc, char *argv[]);
38 static char *xstrdup(const char *s);
39 static void *xmalloc(size_t size);
40 static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
41 #define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
42 static inline void xchrcat(char **dst, const char append, size_t *curr_len);
43
44 /* variables to control behavior */
45 static char match_etypes[126] = "";
46 static char *ldpaths[256];
47 static char scan_ldpath = 0;
48 static char scan_envpath = 0;
49 static char scan_symlink = 1;
50 static char scan_archives = 0;
51 static char dir_recurse = 0;
52 static char dir_crossmount = 1;
53 static char show_pax = 0;
54 static char show_phdr = 0;
55 static char show_textrel = 0;
56 static char show_rpath = 0;
57 static char show_needed = 0;
58 static char show_interp = 0;
59 static char show_bind = 0;
60 static char show_soname = 0;
61 static char show_textrels = 0;
62 static char show_banner = 1;
63 static char be_quiet = 0;
64 static char be_verbose = 0;
65 static char be_wewy_wewy_quiet = 0;
66 static char be_semi_verbose = 0;
67 static char *find_sym = NULL, *versioned_symname = NULL;
68 static char *find_lib = NULL;
69 static char *find_section = NULL;
70 static char *out_format = NULL;
71 static char *search_path = NULL;
72 static char fix_elf = 0;
73 static char gmatch = 0;
74 static char use_ldcache = 0;
75
76 int match_bits = 0;
77 caddr_t ldcache = 0;
78 size_t ldcache_size = 0;
79 unsigned long setpax = 0UL;
80
81 /* sub-funcs for scanelf_file() */
82 static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab)
83 {
84 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
85 #define GET_SYMTABS(B) \
86 if (elf->elf_class == ELFCLASS ## B) { \
87 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \
88 /* debug sections */ \
89 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \
90 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \
91 /* runtime sections */ \
92 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \
93 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \
94 if (symtab && dynsym) { \
95 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \
96 } else { \
97 *sym = (void*)(symtab ? symtab : dynsym); \
98 } \
99 if (strtab && dynstr) { \
100 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \
101 } else { \
102 *tab = (void*)(strtab ? strtab : dynstr); \
103 } \
104 }
105 GET_SYMTABS(32)
106 GET_SYMTABS(64)
107 }
108
109 static char *scanelf_file_pax(elfobj *elf, char *found_pax)
110 {
111 static char ret[7];
112 unsigned long i, shown;
113
114 if (!show_pax) return NULL;
115
116 shown = 0;
117 memset(&ret, 0, sizeof(ret));
118
119 if (elf->phdr) {
120 #define SHOW_PAX(B) \
121 if (elf->elf_class == ELFCLASS ## B) { \
122 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
123 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
124 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
125 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
126 continue; \
127 if (fix_elf && setpax) { \
128 /* set the paxctl flags */ \
129 ESET(phdr[i].p_flags, setpax); \
130 } \
131 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
132 continue; \
133 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
134 *found_pax = 1; \
135 ++shown; \
136 break; \
137 } \
138 }
139 SHOW_PAX(32)
140 SHOW_PAX(64)
141 }
142
143
144 if (fix_elf && setpax) {
145 /* set the chpax settings */
146 if (elf->elf_class == ELFCLASS32) {
147 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
148 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
149 } else {
150 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
151 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
152 }
153 }
154
155 /* fall back to EI_PAX if no PT_PAX was found */
156 if (!*ret) {
157 static char *paxflags;
158 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
159 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
160 *found_pax = 1;
161 return (be_wewy_wewy_quiet ? NULL : paxflags);
162 }
163 strncpy(ret, paxflags, sizeof(ret));
164 }
165
166 if (be_wewy_wewy_quiet || (be_quiet && !shown))
167 return NULL;
168 else
169 return ret;
170 }
171
172 static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
173 {
174 static char ret[12];
175 char *found;
176 unsigned long i, shown, multi_stack, multi_relro, multi_load;
177 int max_pt_load;
178
179 if (!show_phdr) return NULL;
180
181 memcpy(ret, "--- --- ---\0", 12);
182
183 shown = 0;
184 multi_stack = multi_relro = multi_load = 0;
185 max_pt_load = elf_max_pt_load(elf);
186
187 #define NOTE_GNU_STACK ".note.GNU-stack"
188 #define SHOW_PHDR(B) \
189 if (elf->elf_class == ELFCLASS ## B) { \
190 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
191 Elf ## B ## _Off offset; \
192 uint32_t flags, check_flags; \
193 if (elf->phdr != NULL) { \
194 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
195 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
196 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
197 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
198 found = found_phdr; \
199 offset = 0; \
200 check_flags = PF_X; \
201 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
202 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
203 found = found_relro; \
204 offset = 4; \
205 check_flags = PF_X; \
206 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
207 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \
208 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
209 found = found_load; \
210 offset = 8; \
211 check_flags = PF_W|PF_X; \
212 } else \
213 continue; \
214 flags = EGET(phdr[i].p_flags); \
215 if (be_quiet && ((flags & check_flags) != check_flags)) \
216 continue; \
217 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
218 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
219 ret[3] = ret[7] = '!'; \
220 flags = EGET(phdr[i].p_flags); \
221 } \
222 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
223 *found = 1; \
224 ++shown; \
225 } \
226 } else if (elf->shdr != NULL) { \
227 /* no program headers which means this is prob an object file */ \
228 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
229 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
230 char *str; \
231 if ((void*)strtbl > (void*)elf->data_end) \
232 goto skip_this_shdr##B; \
233 check_flags = SHF_WRITE|SHF_EXECINSTR; \
234 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
235 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
236 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
237 str = elf->data + offset; \
238 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
239 if (!strcmp(str, NOTE_GNU_STACK)) { \
240 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
241 flags = EGET(shdr[i].sh_flags); \
242 if (be_quiet && ((flags & check_flags) != check_flags)) \
243 continue; \
244 ++*found_phdr; \
245 shown = 1; \
246 if (flags & SHF_WRITE) ret[0] = 'W'; \
247 if (flags & SHF_ALLOC) ret[1] = 'A'; \
248 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
249 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
250 break; \
251 } \
252 } \
253 skip_this_shdr##B: \
254 if (!multi_stack) { \
255 *found_phdr = 1; \
256 shown = 1; \
257 memcpy(ret, "!WX", 3); \
258 } \
259 } \
260 }
261 SHOW_PHDR(32)
262 SHOW_PHDR(64)
263
264 if (be_wewy_wewy_quiet || (be_quiet && !shown))
265 return NULL;
266 else
267 return ret;
268 }
269 static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
270 {
271 static const char *ret = "TEXTREL";
272 unsigned long i;
273
274 if (!show_textrel && !show_textrels) return NULL;
275
276 if (elf->phdr) {
277 #define SHOW_TEXTREL(B) \
278 if (elf->elf_class == ELFCLASS ## B) { \
279 Elf ## B ## _Dyn *dyn; \
280 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
281 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
282 Elf ## B ## _Off offset; \
283 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
284 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
285 offset = EGET(phdr[i].p_offset); \
286 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
287 dyn = DYN ## B (elf->data + offset); \
288 while (EGET(dyn->d_tag) != DT_NULL) { \
289 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
290 *found_textrel = 1; \
291 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
292 return (be_wewy_wewy_quiet ? NULL : ret); \
293 } \
294 ++dyn; \
295 } \
296 } }
297 SHOW_TEXTREL(32)
298 SHOW_TEXTREL(64)
299 }
300
301 if (be_quiet || be_wewy_wewy_quiet)
302 return NULL;
303 else
304 return " - ";
305 }
306 static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
307 {
308 unsigned long s, r, rmax;
309 void *symtab_void, *strtab_void, *text_void;
310
311 if (!show_textrels) return NULL;
312
313 /* don't search for TEXTREL's if the ELF doesn't have any */
314 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
315 if (!*found_textrel) return NULL;
316
317 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
318 text_void = elf_findsecbyname(elf, ".text");
319
320 if (symtab_void && strtab_void && text_void && elf->shdr) {
321 #define SHOW_TEXTRELS(B) \
322 if (elf->elf_class == ELFCLASS ## B) { \
323 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
324 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
325 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
326 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
327 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
328 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
329 uint ## B ## _t memsz = EGET(text->sh_size); \
330 Elf ## B ## _Rel *rel; \
331 Elf ## B ## _Rela *rela; \
332 /* search the section headers for relocations */ \
333 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
334 uint32_t sh_type = EGET(shdr[s].sh_type); \
335 if (sh_type == SHT_REL) { \
336 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \
337 rela = NULL; \
338 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
339 } else if (sh_type == SHT_RELA) { \
340 rel = NULL; \
341 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \
342 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
343 } else \
344 continue; \
345 /* now see if any of the relocs are in the .text */ \
346 for (r = 0; r < rmax; ++r) { \
347 unsigned long sym_max; \
348 Elf ## B ## _Addr offset_tmp; \
349 Elf ## B ## _Sym *func; \
350 Elf ## B ## _Sym *sym; \
351 Elf ## B ## _Addr r_offset; \
352 uint ## B ## _t r_info; \
353 if (sh_type == SHT_REL) { \
354 r_offset = EGET(rel[r].r_offset); \
355 r_info = EGET(rel[r].r_info); \
356 } else { \
357 r_offset = EGET(rela[r].r_offset); \
358 r_info = EGET(rela[r].r_info); \
359 } \
360 /* make sure this relocation is inside of the .text */ \
361 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
362 if (be_verbose <= 2) continue; \
363 } else \
364 *found_textrels = 1; \
365 /* locate this relocation symbol name */ \
366 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
367 if ((void*)sym > (void*)elf->data_end) { \
368 warn("%s: corrupt ELF symbol", elf->filename); \
369 continue; \
370 } \
371 sym_max = ELF ## B ## _R_SYM(r_info); \
372 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
373 sym += sym_max; \
374 else \
375 sym = NULL; \
376 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
377 /* show the raw details about this reloc */ \
378 printf(" %s: ", elf->base_filename); \
379 if (sym && sym->st_name) \
380 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \
381 else \
382 printf("(memory/fake?)"); \
383 printf(" [0x%lX]", (unsigned long)r_offset); \
384 /* now try to find the closest symbol that this rel is probably in */ \
385 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
386 func = NULL; \
387 offset_tmp = 0; \
388 while (sym_max--) { \
389 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
390 func = sym; \
391 offset_tmp = EGET(sym->st_value); \
392 } \
393 ++sym; \
394 } \
395 printf(" in "); \
396 if (func && func->st_name) \
397 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \
398 else \
399 printf("(NULL: fake?)"); \
400 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
401 } \
402 } }
403 SHOW_TEXTRELS(32)
404 SHOW_TEXTRELS(64)
405 }
406 if (!*found_textrels)
407 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
408
409 return NULL;
410 }
411
412 static void rpath_security_checks(elfobj *, char *, const char *);
413 static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
414 {
415 struct stat st;
416 switch (*item) {
417 case '/': break;
418 case '.':
419 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
420 break;
421 case ':':
422 case '\0':
423 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
424 break;
425 case '$':
426 if (fstat(elf->fd, &st) != -1)
427 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
428 warnf("Security problem with %s='%s' in %s with mode set of %o",
429 dt_type, item, elf->filename, st.st_mode & 07777);
430 break;
431 default:
432 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
433 break;
434 }
435 }
436 static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
437 {
438 unsigned long i, s;
439 char *rpath, *runpath, **r;
440 void *strtbl_void;
441
442 if (!show_rpath) return;
443
444 strtbl_void = elf_findsecbyname(elf, ".dynstr");
445 rpath = runpath = NULL;
446
447 if (elf->phdr && strtbl_void) {
448 #define SHOW_RPATH(B) \
449 if (elf->elf_class == ELFCLASS ## B) { \
450 Elf ## B ## _Dyn *dyn; \
451 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
452 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
453 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
454 Elf ## B ## _Off offset; \
455 Elf ## B ## _Xword word; \
456 /* Scan all the program headers */ \
457 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
458 /* Just scan dynamic headers */ \
459 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
460 offset = EGET(phdr[i].p_offset); \
461 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
462 /* Just scan dynamic RPATH/RUNPATH headers */ \
463 dyn = DYN ## B (elf->data + offset); \
464 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
465 if (word == DT_RPATH) { \
466 r = &rpath; \
467 } else if (word == DT_RUNPATH) { \
468 r = &runpath; \
469 } else { \
470 ++dyn; \
471 continue; \
472 } \
473 /* Verify the memory is somewhat sane */ \
474 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
475 if (offset < (Elf ## B ## _Off)elf->len) { \
476 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
477 *r = (char*)(elf->data + offset); \
478 /* cache the length in case we need to nuke this section later on */ \
479 if (fix_elf) \
480 offset = strlen(*r); \
481 /* If quiet, don't output paths in ld.so.conf */ \
482 if (be_quiet) { \
483 size_t len; \
484 char *start, *end; \
485 /* note that we only 'chop' off leading known paths. */ \
486 /* since *r is read-only memory, we can only move the ptr forward. */ \
487 start = *r; \
488 /* scan each path in : delimited list */ \
489 while (start) { \
490 rpath_security_checks(elf, start, get_elfdtype(word)); \
491 end = strchr(start, ':'); \
492 len = (end ? abs(end - start) : strlen(start)); \
493 if (use_ldcache) \
494 for (s = 0; ldpaths[s]; ++s) \
495 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \
496 *r = end; \
497 /* corner case ... if RPATH reads "/usr/lib:", we want \
498 * to show ':' rather than '' */ \
499 if (end && end[1] != '\0') \
500 (*r)++; \
501 break; \
502 } \
503 if (!*r || !end) \
504 break; \
505 else \
506 start = start + len + 1; \
507 } \
508 } \
509 if (*r) { \
510 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
511 /* just nuke it */ \
512 nuke_it##B: \
513 memset(*r, 0x00, offset); \
514 *r = NULL; \
515 ESET(dyn->d_tag, DT_DEBUG); \
516 ESET(dyn->d_un.d_ptr, 0); \
517 } else if (fix_elf) { \
518 /* try to clean "bad" paths */ \
519 size_t len, tmpdir_len; \
520 char *start, *end; \
521 const char *tmpdir; \
522 start = *r; \
523 tmpdir = (getenv("TMPDIR") ? : "."); \
524 tmpdir_len = strlen(tmpdir); \
525 while (1) { \
526 end = strchr(start, ':'); \
527 if (start == end) { \
528 eat_this_path##B: \
529 len = strlen(end); \
530 memmove(start, end+1, len); \
531 start[len-1] = '\0'; \
532 end = start - 1; \
533 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
534 if (!end) { \
535 if (start == *r) \
536 goto nuke_it##B; \
537 *--start = '\0'; \
538 } else \
539 goto eat_this_path##B; \
540 } \
541 if (!end) \
542 break; \
543 start = end + 1; \
544 } \
545 if (**r == '\0') \
546 goto nuke_it##B; \
547 } \
548 if (*r) \
549 *found_rpath = 1; \
550 } \
551 } \
552 ++dyn; \
553 } \
554 } }
555 SHOW_RPATH(32)
556 SHOW_RPATH(64)
557 }
558
559 if (be_wewy_wewy_quiet) return;
560
561 if (rpath && runpath) {
562 if (!strcmp(rpath, runpath)) {
563 xstrcat(ret, runpath, ret_len);
564 } else {
565 fprintf(stderr, "RPATH [%s] != RUNPATH [%s]\n", rpath, runpath);
566 xchrcat(ret, '{', ret_len);
567 xstrcat(ret, rpath, ret_len);
568 xchrcat(ret, ',', ret_len);
569 xstrcat(ret, runpath, ret_len);
570 xchrcat(ret, '}', ret_len);
571 }
572 } else if (rpath || runpath)
573 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
574 else if (!be_quiet)
575 xstrcat(ret, " - ", ret_len);
576 }
577
578 #define LDSO_CACHE_MAGIC "ld.so-"
579 #define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
580 #define LDSO_CACHE_VER "1.7.0"
581 #define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
582 #define FLAG_ANY -1
583 #define FLAG_TYPE_MASK 0x00ff
584 #define FLAG_LIBC4 0x0000
585 #define FLAG_ELF 0x0001
586 #define FLAG_ELF_LIBC5 0x0002
587 #define FLAG_ELF_LIBC6 0x0003
588 #define FLAG_REQUIRED_MASK 0xff00
589 #define FLAG_SPARC_LIB64 0x0100
590 #define FLAG_IA64_LIB64 0x0200
591 #define FLAG_X8664_LIB64 0x0300
592 #define FLAG_S390_LIB64 0x0400
593 #define FLAG_POWERPC_LIB64 0x0500
594 #define FLAG_MIPS64_LIBN32 0x0600
595 #define FLAG_MIPS64_LIBN64 0x0700
596
597 static char *lookup_cache_lib(elfobj *, char *);
598 static char *lookup_cache_lib(elfobj *elf, char *fname)
599 {
600 int fd = 0;
601 char *strs;
602 static char buf[__PAX_UTILS_PATH_MAX] = "";
603 const char *cachefile = "/etc/ld.so.cache";
604 struct stat st;
605
606 typedef struct {
607 char magic[LDSO_CACHE_MAGIC_LEN];
608 char version[LDSO_CACHE_VER_LEN];
609 int nlibs;
610 } header_t;
611 header_t *header;
612
613 typedef struct {
614 int flags;
615 int sooffset;
616 int liboffset;
617 } libentry_t;
618 libentry_t *libent;
619
620 if (fname == NULL)
621 return NULL;
622
623 if (ldcache == 0) {
624 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1)
625 return NULL;
626
627 /* cache these values so we only map/unmap the cache file once */
628 ldcache_size = st.st_size;
629 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
630
631 close(fd);
632
633 if (ldcache == (caddr_t)-1) {
634 ldcache = 0;
635 return NULL;
636 }
637
638 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN))
639 return NULL;
640 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
641 return NULL;
642 }
643
644 header = (header_t *) ldcache;
645 libent = (libentry_t *) (ldcache + sizeof(header_t));
646 strs = (char *) &libent[header->nlibs];
647
648 for (fd = 0; fd < header->nlibs; fd++) {
649 /* this should be more fine grained, but for now we assume that
650 * diff arches will not be cached together. and we ignore the
651 * the different multilib mips cases. */
652 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
653 continue;
654 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
655 continue;
656
657 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
658 continue;
659 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
660 }
661 return buf;
662 }
663
664
665 static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
666 {
667 unsigned long i;
668 char *needed;
669 void *strtbl_void;
670 char *p;
671
672 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL;
673
674 strtbl_void = elf_findsecbyname(elf, ".dynstr");
675
676 if (elf->phdr && strtbl_void) {
677 #define SHOW_NEEDED(B) \
678 if (elf->elf_class == ELFCLASS ## B) { \
679 Elf ## B ## _Dyn *dyn; \
680 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
681 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
682 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
683 Elf ## B ## _Off offset; \
684 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
685 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
686 offset = EGET(phdr[i].p_offset); \
687 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
688 dyn = DYN ## B (elf->data + offset); \
689 while (EGET(dyn->d_tag) != DT_NULL) { \
690 if (EGET(dyn->d_tag) == DT_NEEDED) { \
691 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
692 if (offset >= (Elf ## B ## _Off)elf->len) { \
693 ++dyn; \
694 continue; \
695 } \
696 needed = (char*)(elf->data + offset); \
697 if (op == 0) { \
698 if (!be_wewy_wewy_quiet) { \
699 if (*found_needed) xchrcat(ret, ',', ret_len); \
700 if (use_ldcache) \
701 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
702 needed = p; \
703 xstrcat(ret, needed, ret_len); \
704 } \
705 *found_needed = 1; \
706 } else { \
707 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \
708 *found_lib = 1; \
709 return (be_wewy_wewy_quiet ? NULL : needed); \
710 } \
711 } \
712 } \
713 ++dyn; \
714 } \
715 } }
716 SHOW_NEEDED(32)
717 SHOW_NEEDED(64)
718 if (op == 0 && !*found_needed && be_verbose)
719 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
720 }
721
722 return NULL;
723 }
724 static char *scanelf_file_interp(elfobj *elf, char *found_interp)
725 {
726 void *strtbl_void;
727
728 if (!show_interp) return NULL;
729
730 strtbl_void = elf_findsecbyname(elf, ".interp");
731
732 if (strtbl_void) {
733 #define SHOW_INTERP(B) \
734 if (elf->elf_class == ELFCLASS ## B) { \
735 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
736 *found_interp = 1; \
737 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
738 }
739 SHOW_INTERP(32)
740 SHOW_INTERP(64)
741 }
742 return NULL;
743 }
744 static char *scanelf_file_bind(elfobj *elf, char *found_bind)
745 {
746 unsigned long i;
747 struct stat s;
748 char dynamic = 0;
749
750 if (!show_bind) return NULL;
751 if (!elf->phdr) return NULL;
752
753 #define SHOW_BIND(B) \
754 if (elf->elf_class == ELFCLASS ## B) { \
755 Elf ## B ## _Dyn *dyn; \
756 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
757 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
758 Elf ## B ## _Off offset; \
759 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
760 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
761 dynamic = 1; \
762 offset = EGET(phdr[i].p_offset); \
763 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
764 dyn = DYN ## B (elf->data + offset); \
765 while (EGET(dyn->d_tag) != DT_NULL) { \
766 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
767 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
768 { \
769 if (be_quiet) return NULL; \
770 *found_bind = 1; \
771 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
772 } \
773 ++dyn; \
774 } \
775 } \
776 }
777 SHOW_BIND(32)
778 SHOW_BIND(64)
779
780 if (be_wewy_wewy_quiet) return NULL;
781
782 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) {
783 return NULL;
784 } else {
785 *found_bind = 1;
786 return (char *) (dynamic ? "LAZY" : "STATIC");
787 }
788 }
789 static char *scanelf_file_soname(elfobj *elf, char *found_soname)
790 {
791 unsigned long i;
792 char *soname;
793 void *strtbl_void;
794
795 if (!show_soname) return NULL;
796
797 strtbl_void = elf_findsecbyname(elf, ".dynstr");
798
799 if (elf->phdr && strtbl_void) {
800 #define SHOW_SONAME(B) \
801 if (elf->elf_class == ELFCLASS ## B) { \
802 Elf ## B ## _Dyn *dyn; \
803 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
804 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
805 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
806 Elf ## B ## _Off offset; \
807 /* only look for soname in shared objects */ \
808 if (ehdr->e_type != ET_DYN) \
809 return NULL; \
810 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
811 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
812 offset = EGET(phdr[i].p_offset); \
813 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
814 dyn = DYN ## B (elf->data + offset); \
815 while (EGET(dyn->d_tag) != DT_NULL) { \
816 if (EGET(dyn->d_tag) == DT_SONAME) { \
817 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
818 if (offset >= (Elf ## B ## _Off)elf->len) { \
819 ++dyn; \
820 continue; \
821 } \
822 soname = (char*)(elf->data + offset); \
823 *found_soname = 1; \
824 return (be_wewy_wewy_quiet ? NULL : soname); \
825 } \
826 ++dyn; \
827 } \
828 } }
829 SHOW_SONAME(32)
830 SHOW_SONAME(64)
831 }
832
833 return NULL;
834 }
835 static char *scanelf_file_sym(elfobj *elf, char *found_sym)
836 {
837 unsigned long i;
838 char *ret;
839 void *symtab_void, *strtab_void;
840
841 if (!find_sym) return NULL;
842 ret = find_sym;
843
844 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
845
846 if (symtab_void && strtab_void) {
847 #define FIND_SYM(B) \
848 if (elf->elf_class == ELFCLASS ## B) { \
849 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
850 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
851 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
852 unsigned long cnt = EGET(symtab->sh_entsize); \
853 char *symname; \
854 if (cnt) \
855 cnt = EGET(symtab->sh_size) / cnt; \
856 for (i = 0; i < cnt; ++i) { \
857 if (sym->st_name) { \
858 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
859 if ((void*)symname > (void*)elf->data_end) { \
860 warnf("%s: corrupt ELF symbols", elf->filename); \
861 continue; \
862 } \
863 if (*find_sym == '*') { \
864 printf("%s(%s) %5lX %15s %s\n", \
865 ((*found_sym == 0) ? "\n\t" : "\t"), \
866 elf->base_filename, \
867 (unsigned long)sym->st_size, \
868 get_elfstttype(sym->st_info), \
869 symname); \
870 *found_sym = 1; \
871 } else { \
872 char *this_sym, *next_sym; \
873 this_sym = find_sym; \
874 do { \
875 next_sym = strchr(this_sym, ','); \
876 if (next_sym == NULL) \
877 next_sym = this_sym + strlen(this_sym); \
878 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
879 (strcmp(symname, versioned_symname) == 0)) { \
880 if (be_semi_verbose) { \
881 char buf[126]; \
882 snprintf(buf, sizeof(buf), "%lX %s %s", \
883 (unsigned long)sym->st_size, get_elfstttype(sym->st_info), this_sym); \
884 ret = buf; \
885 } else \
886 ret = this_sym; \
887 (*found_sym)++; \
888 goto break_out; \
889 } \
890 this_sym = next_sym + 1; \
891 } while (*next_sym != '\0'); \
892 } \
893 } \
894 ++sym; \
895 } }
896 FIND_SYM(32)
897 FIND_SYM(64)
898 }
899
900 break_out:
901 if (be_wewy_wewy_quiet) return NULL;
902
903 if (*find_sym != '*' && *found_sym)
904 return ret;
905 if (be_quiet)
906 return NULL;
907 else
908 return (char *)" - ";
909 }
910
911
912 static char *scanelf_file_sections(elfobj *elf, char *found_section)
913 {
914 if (!find_section)
915 return NULL;
916
917 #define FIND_SECTION(B) \
918 if (elf->elf_class == ELFCLASS ## B) { \
919 Elf ## B ## _Shdr *section; \
920 section = SHDR ## B (elf_findsecbyname(elf, find_section)); \
921 if (section != NULL) \
922 *found_section = 1; \
923 }
924 FIND_SECTION(32)
925 FIND_SECTION(64)
926
927
928 if (be_wewy_wewy_quiet) return NULL;
929
930 if (*found_section)
931 return find_section;
932
933 if (be_quiet)
934 return NULL;
935 else
936 return (char *)" - ";
937 }
938
939 /* scan an elf file and show all the fun stuff */
940 #define prints(str) write(fileno(stdout), str, strlen(str))
941 static int scanelf_elfobj(elfobj *elf)
942 {
943 unsigned long i;
944 char found_pax, found_phdr, found_relro, found_load, found_textrel,
945 found_rpath, found_needed, found_interp, found_bind, found_soname,
946 found_sym, found_lib, found_file, found_textrels, found_section;
947 static char *out_buffer = NULL;
948 static size_t out_len;
949
950 found_pax = found_phdr = found_relro = found_load = found_textrel = \
951 found_rpath = found_needed = found_interp = found_bind = found_soname = \
952 found_sym = found_lib = found_file = found_textrels = found_section = 0;
953
954 if (be_verbose > 2)
955 printf("%s: scanning file {%s,%s}\n", elf->filename,
956 get_elfeitype(EI_CLASS, elf->elf_class),
957 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
958 else if (be_verbose > 1)
959 printf("%s: scanning file\n", elf->filename);
960
961 /* init output buffer */
962 if (!out_buffer) {
963 out_len = sizeof(char) * 80;
964 out_buffer = (char*)xmalloc(out_len);
965 }
966 *out_buffer = '\0';
967
968 /* show the header */
969 if (!be_quiet && show_banner) {
970 for (i = 0; out_format[i]; ++i) {
971 if (!IS_MODIFIER(out_format[i])) continue;
972
973 switch (out_format[++i]) {
974 case '+': break;
975 case '%': break;
976 case '#': break;
977 case 'F':
978 case 'p':
979 case 'f': prints("FILE "); found_file = 1; break;
980 case 'o': prints(" TYPE "); break;
981 case 'x': prints(" PAX "); break;
982 case 'e': prints("STK/REL/PTL "); break;
983 case 't': prints("TEXTREL "); break;
984 case 'r': prints("RPATH "); break;
985 case 'n': prints("NEEDED "); break;
986 case 'i': prints("INTERP "); break;
987 case 'b': prints("BIND "); break;
988 case 'S': prints("SONAME "); break;
989 case 's': prints("SYM "); break;
990 case 'N': prints("LIB "); break;
991 case 'T': prints("TEXTRELS "); break;
992 case 'k': prints("SECTION "); break;
993 default: warnf("'%c' has no title ?", out_format[i]);
994 }
995 }
996 if (!found_file) prints("FILE ");
997 prints("\n");
998 found_file = 0;
999 show_banner = 0;
1000 }
1001
1002 /* dump all the good stuff */
1003 for (i = 0; out_format[i]; ++i) {
1004 const char *out;
1005 const char *tmp;
1006
1007 if (!IS_MODIFIER(out_format[i])) {
1008 xchrcat(&out_buffer, out_format[i], &out_len);
1009 continue;
1010 }
1011
1012 out = NULL;
1013 be_wewy_wewy_quiet = (out_format[i] == '#');
1014 be_semi_verbose = (out_format[i] == '+');
1015 switch (out_format[++i]) {
1016 case '+':
1017 case '%':
1018 case '#':
1019 xchrcat(&out_buffer, out_format[i], &out_len); break;
1020 case 'F':
1021 found_file = 1;
1022 if (be_wewy_wewy_quiet) break;
1023 xstrcat(&out_buffer, elf->filename, &out_len);
1024 break;
1025 case 'p':
1026 found_file = 1;
1027 if (be_wewy_wewy_quiet) break;
1028 tmp = elf->filename;
1029 if (search_path) {
1030 ssize_t len_search = strlen(search_path);
1031 ssize_t len_file = strlen(elf->filename);
1032 if (!strncmp(elf->filename, search_path, len_search) && \
1033 len_file > len_search)
1034 tmp += len_search;
1035 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
1036 }
1037 xstrcat(&out_buffer, tmp, &out_len);
1038 break;
1039 case 'f':
1040 found_file = 1;
1041 if (be_wewy_wewy_quiet) break;
1042 tmp = strrchr(elf->filename, '/');
1043 tmp = (tmp == NULL ? elf->filename : tmp+1);
1044 xstrcat(&out_buffer, tmp, &out_len);
1045 break;
1046 case 'o': out = get_elfetype(elf); break;
1047 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1048 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1049 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1050 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1051 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1052 case 'n':
1053 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1054 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1055 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1056 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1057 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1058 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1059 default: warnf("'%c' has no scan code?", out_format[i]);
1060 }
1061 if (out) {
1062 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
1063 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
1064 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1065 else
1066 xstrcat(&out_buffer, out, &out_len);
1067 }
1068 }
1069
1070 #define FOUND_SOMETHING() \
1071 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1072 found_rpath || found_needed || found_interp || found_bind || \
1073 found_soname || found_sym || found_lib || found_textrels || found_section )
1074
1075 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1076 xchrcat(&out_buffer, ' ', &out_len);
1077 xstrcat(&out_buffer, elf->filename, &out_len);
1078 }
1079 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
1080 puts(out_buffer);
1081 fflush(stdout);
1082 }
1083
1084 return 0;
1085 }
1086
1087 /* scan a single elf */
1088 static int scanelf_elf(const char *filename, int fd, size_t len)
1089 {
1090 int ret = 1;
1091 elfobj *elf;
1092
1093 /* verify this is real ELF */
1094 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1095 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1096 return ret;
1097 }
1098 switch (match_bits) {
1099 case 32:
1100 if (elf->elf_class != ELFCLASS32)
1101 goto label_done;
1102 break;
1103 case 64:
1104 if (elf->elf_class != ELFCLASS64)
1105 goto label_done;
1106 break;
1107 default: break;
1108 }
1109 if (strlen(match_etypes)) {
1110 char sbuf[126];
1111 strncpy(sbuf, match_etypes, sizeof(sbuf));
1112 if (strchr(match_etypes, ',') != NULL) {
1113 char *p;
1114 while((p = strrchr(sbuf, ',')) != NULL) {
1115 *p = 0;
1116 if (etype_lookup(p+1) == get_etype(elf))
1117 goto label_ret;
1118 }
1119 }
1120 if (etype_lookup(sbuf) != get_etype(elf))
1121 goto label_done;
1122 }
1123
1124 label_ret:
1125 ret = scanelf_elfobj(elf);
1126
1127 label_done:
1128 unreadelf(elf);
1129 return ret;
1130 }
1131
1132 /* scan an archive of elfs */
1133 static int scanelf_archive(const char *filename, int fd, size_t len)
1134 {
1135 archive_handle *ar;
1136 archive_member *m;
1137 char *ar_buffer;
1138 elfobj *elf;
1139
1140 ar = ar_open_fd(filename, fd);
1141 if (ar == NULL)
1142 return 1;
1143
1144 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1145 while ((m=ar_next(ar)) != NULL) {
1146 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size);
1147 if (elf) {
1148 scanelf_elfobj(elf);
1149 unreadelf(elf);
1150 }
1151 }
1152 munmap(ar_buffer, len);
1153
1154 return 0;
1155 }
1156 /* scan a file which may be an elf or an archive or some other magical beast */
1157 static void scanelf_file(const char *filename)
1158 {
1159 struct stat st;
1160 int fd;
1161
1162 /* make sure 'filename' exists */
1163 if (lstat(filename, &st) == -1) {
1164 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1165 return;
1166 }
1167
1168 /* always handle regular files and handle symlinked files if no -y */
1169 if (S_ISLNK(st.st_mode)) {
1170 if (!scan_symlink) return;
1171 stat(filename, &st);
1172 }
1173 if (!S_ISREG(st.st_mode)) {
1174 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1175 return;
1176 }
1177
1178 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1)
1179 return;
1180
1181 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives)
1182 /* if it isn't an ELF, maybe it's an .a archive */
1183 scanelf_archive(filename, fd, st.st_size);
1184
1185 close(fd);
1186 }
1187
1188 /* scan a directory for ET_EXEC files and print when we find one */
1189 static void scanelf_dir(const char *path)
1190 {
1191 register DIR *dir;
1192 register struct dirent *dentry;
1193 struct stat st_top, st;
1194 char buf[__PAX_UTILS_PATH_MAX];
1195 size_t pathlen = 0, len = 0;
1196
1197 /* make sure path exists */
1198 if (lstat(path, &st_top) == -1) {
1199 if (be_verbose > 2) printf("%s: does not exist\n", path);
1200 return;
1201 }
1202
1203 /* ok, if it isn't a directory, assume we can open it */
1204 if (!S_ISDIR(st_top.st_mode)) {
1205 scanelf_file(path);
1206 return;
1207 }
1208
1209 /* now scan the dir looking for fun stuff */
1210 if ((dir = opendir(path)) == NULL) {
1211 warnf("could not opendir %s: %s", path, strerror(errno));
1212 return;
1213 }
1214 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1215
1216 pathlen = strlen(path);
1217 while ((dentry = readdir(dir))) {
1218 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1219 continue;
1220 len = (pathlen + 1 + strlen(dentry->d_name) + 1);
1221 if (len >= sizeof(buf)) {
1222 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
1223 (unsigned long)len, (unsigned long)sizeof(buf));
1224 continue;
1225 }
1226 sprintf(buf, "%s/%s", path, dentry->d_name);
1227 if (lstat(buf, &st) != -1) {
1228 if (S_ISREG(st.st_mode))
1229 scanelf_file(buf);
1230 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1231 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1232 scanelf_dir(buf);
1233 }
1234 }
1235 }
1236 closedir(dir);
1237 }
1238
1239 static int scanelf_from_file(const char *filename)
1240 {
1241 FILE *fp = NULL;
1242 char *p;
1243 char path[__PAX_UTILS_PATH_MAX];
1244
1245 if (strcmp(filename, "-") == 0)
1246 fp = stdin;
1247 else if ((fp = fopen(filename, "r")) == NULL)
1248 return 1;
1249
1250 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1251 if ((p = strchr(path, '\n')) != NULL)
1252 *p = 0;
1253 search_path = path;
1254 scanelf_dir(path);
1255 }
1256 if (fp != stdin)
1257 fclose(fp);
1258 return 0;
1259 }
1260
1261 static int load_ld_so_conf(int i, const char *fname)
1262 {
1263 FILE *fp = NULL;
1264 char *p;
1265 char path[__PAX_UTILS_PATH_MAX];
1266
1267 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1268 return i;
1269
1270 if ((fp = fopen(fname, "r")) == NULL)
1271 return i;
1272
1273 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1274 if ((p = strrchr(path, '\r')) != NULL)
1275 *p = 0;
1276 if ((p = strchr(path, '\n')) != NULL)
1277 *p = 0;
1278 #ifdef HAVE_GLOB
1279 // recursive includes of the same file will make this segfault.
1280 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1281 glob64_t gl;
1282 size_t x;
1283 char gpath[__PAX_UTILS_PATH_MAX];
1284
1285 memset(gpath, 0, sizeof(gpath));
1286
1287 if (path[8] != '/')
1288 snprintf(gpath, sizeof(gpath), "/etc/%s", &path[8]);
1289 else
1290 strncpy(gpath, &path[8], sizeof(gpath));
1291
1292 if ((glob64(gpath, 0, NULL, &gl)) == 0) {
1293 for (x = 0; x < gl.gl_pathc; ++x) {
1294 /* try to avoid direct loops */
1295 if (strcmp(gl.gl_pathv[x], fname) == 0)
1296 continue;
1297 i = load_ld_so_conf(i, gl.gl_pathv[x]);
1298 if (i + 1 >= sizeof(ldpaths) / sizeof(*ldpaths)) {
1299 globfree64(&gl);
1300 return i;
1301 }
1302 }
1303 globfree64 (&gl);
1304 continue;
1305 } else
1306 abort();
1307 }
1308 #endif
1309 if (*path != '/')
1310 continue;
1311
1312 ldpaths[i++] = xstrdup(path);
1313
1314 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1315 break;
1316 }
1317 ldpaths[i] = NULL;
1318
1319 fclose(fp);
1320 return i;
1321 }
1322
1323 /* scan /etc/ld.so.conf for paths */
1324 static void scanelf_ldpath()
1325 {
1326 char scan_l, scan_ul, scan_ull;
1327 int i = 0;
1328
1329 if (!ldpaths[0])
1330 err("Unable to load any paths from ld.so.conf");
1331
1332 scan_l = scan_ul = scan_ull = 0;
1333
1334 while (ldpaths[i]) {
1335 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1336 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1337 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1338 scanelf_dir(ldpaths[i]);
1339 ++i;
1340 }
1341
1342 if (!scan_l) scanelf_dir("/lib");
1343 if (!scan_ul) scanelf_dir("/usr/lib");
1344 if (!scan_ull) scanelf_dir("/usr/local/lib");
1345 }
1346
1347 /* scan env PATH for paths */
1348 static void scanelf_envpath()
1349 {
1350 char *path, *p;
1351
1352 path = getenv("PATH");
1353 if (!path)
1354 err("PATH is not set in your env !");
1355 path = xstrdup(path);
1356
1357 while ((p = strrchr(path, ':')) != NULL) {
1358 scanelf_dir(p + 1);
1359 *p = 0;
1360 }
1361
1362 free(path);
1363 }
1364
1365 /* usage / invocation handling functions */
1366 #define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:BhV"
1367 #define a_argument required_argument
1368 static struct option const long_opts[] = {
1369 {"path", no_argument, NULL, 'p'},
1370 {"ldpath", no_argument, NULL, 'l'},
1371 {"recursive", no_argument, NULL, 'R'},
1372 {"mount", no_argument, NULL, 'm'},
1373 {"symlink", no_argument, NULL, 'y'},
1374 {"archives", no_argument, NULL, 'A'},
1375 {"ldcache", no_argument, NULL, 'L'},
1376 {"fix", no_argument, NULL, 'X'},
1377 {"setpax", a_argument, NULL, 'z'},
1378 {"pax", no_argument, NULL, 'x'},
1379 {"header", no_argument, NULL, 'e'},
1380 {"textrel", no_argument, NULL, 't'},
1381 {"rpath", no_argument, NULL, 'r'},
1382 {"needed", no_argument, NULL, 'n'},
1383 {"interp", no_argument, NULL, 'i'},
1384 {"bind", no_argument, NULL, 'b'},
1385 {"soname", no_argument, NULL, 'S'},
1386 {"symbol", a_argument, NULL, 's'},
1387 {"section", a_argument, NULL, 'k'},
1388 {"lib", a_argument, NULL, 'N'},
1389 {"gmatch", no_argument, NULL, 'g'},
1390 {"textrels", no_argument, NULL, 'T'},
1391 {"etype", a_argument, NULL, 'E'},
1392 {"bits", a_argument, NULL, 'M'},
1393 {"all", no_argument, NULL, 'a'},
1394 {"quiet", no_argument, NULL, 'q'},
1395 {"verbose", no_argument, NULL, 'v'},
1396 {"format", a_argument, NULL, 'F'},
1397 {"from", a_argument, NULL, 'f'},
1398 {"file", a_argument, NULL, 'o'},
1399 {"nobanner", no_argument, NULL, 'B'},
1400 {"help", no_argument, NULL, 'h'},
1401 {"version", no_argument, NULL, 'V'},
1402 {NULL, no_argument, NULL, 0x0}
1403 };
1404
1405 static const char *opts_help[] = {
1406 "Scan all directories in PATH environment",
1407 "Scan all directories in /etc/ld.so.conf",
1408 "Scan directories recursively",
1409 "Don't recursively cross mount points",
1410 "Don't scan symlinks",
1411 "Scan archives (.a files)",
1412 "Utilize ld.so.cache information (use with -r/-n)",
1413 "Try and 'fix' bad things (use with -r/-e)",
1414 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1415 "Print PaX markings",
1416 "Print GNU_STACK/PT_LOAD markings",
1417 "Print TEXTREL information",
1418 "Print RPATH information",
1419 "Print NEEDED information",
1420 "Print INTERP information",
1421 "Print BIND information",
1422 "Print SONAME information",
1423 "Find a specified symbol",
1424 "Find a specified section",
1425 "Find a specified library",
1426 "Use strncmp to match libraries. (use with -N)",
1427 "Locate cause of TEXTREL",
1428 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1429 "Print only ELF files matching numeric bits",
1430 "Print all scanned info (-x -e -t -r -b)\n",
1431 "Only output 'bad' things",
1432 "Be verbose (can be specified more than once)",
1433 "Use specified format for output",
1434 "Read input stream from a filename",
1435 "Write output stream to a filename",
1436 "Don't display the header",
1437 "Print this help and exit",
1438 "Print version and exit",
1439 NULL
1440 };
1441
1442 /* display usage and exit */
1443 static void usage(int status)
1444 {
1445 unsigned long i;
1446 printf("* Scan ELF binaries for stuff\n\n"
1447 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1448 printf("Options: -[%s]\n", PARSE_FLAGS);
1449 for (i = 0; long_opts[i].name; ++i)
1450 if (long_opts[i].has_arg == no_argument)
1451 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
1452 long_opts[i].name, opts_help[i]);
1453 else
1454 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
1455 long_opts[i].name, opts_help[i]);
1456
1457 if (status != EXIT_SUCCESS)
1458 exit(status);
1459
1460 puts("\nThe format modifiers for the -F option are:");
1461 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1462 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1463 puts(" i INTERP \tb BIND \ts symbol");
1464 puts(" N library \to Type \tT TEXTRELs");
1465 puts(" S SONAME \tk section");
1466 puts(" p filename (with search path removed)");
1467 puts(" f filename (short name/basename)");
1468 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1469
1470 puts("\nELF Etypes:");
1471 print_etypes(stdout);
1472
1473 exit(status);
1474 }
1475
1476 /* parse command line arguments and preform needed actions */
1477 static void parseargs(int argc, char *argv[])
1478 {
1479 int i;
1480 const char *from_file = NULL;
1481
1482 opterr = 0;
1483 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1484 switch (i) {
1485
1486 case 'V':
1487 printf("pax-utils-%s: %s compiled %s\n%s\n"
1488 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
1489 VERSION, __FILE__, __DATE__, rcsid, argv0);
1490 exit(EXIT_SUCCESS);
1491 break;
1492 case 'h': usage(EXIT_SUCCESS); break;
1493 case 'f':
1494 if (from_file) warn("You prob don't want to specify -f twice");
1495 from_file = optarg;
1496 break;
1497 case 'E':
1498 strncpy(match_etypes, optarg, sizeof(match_etypes));
1499 break;
1500 case 'M':
1501 match_bits = atoi(optarg);
1502 break;
1503 case 'o': {
1504 FILE *fp = NULL;
1505 if ((fp = freopen(optarg, "w", stdout)) == NULL)
1506 err("Could not open output stream '%s': %s", optarg, strerror(errno));
1507 SET_STDOUT(fp);
1508 break;
1509 }
1510 case 'k':
1511 if (find_section) warn("You prob don't want to specify -k twice");
1512 find_section = optarg;
1513 break;
1514 case 's': {
1515 if (find_sym) warn("You prob don't want to specify -s twice");
1516 find_sym = optarg;
1517 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1518 sprintf(versioned_symname, "%s@", find_sym);
1519 break;
1520 }
1521 case 'N': {
1522 if (find_lib) warn("You prob don't want to specify -N twice");
1523 find_lib = optarg;
1524 break;
1525 }
1526
1527 case 'F': {
1528 if (out_format) warn("You prob don't want to specify -F twice");
1529 out_format = optarg;
1530 break;
1531 }
1532 case 'z': {
1533 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1534 size_t x;
1535
1536 for (x = 0 ; x < strlen(optarg); x++) {
1537 switch(optarg[x]) {
1538 case 'p':
1539 case 'P':
1540 do_state(optarg[x], PAGEEXEC);
1541 break;
1542 case 's':
1543 case 'S':
1544 do_state(optarg[x], SEGMEXEC);
1545 break;
1546 case 'm':
1547 case 'M':
1548 do_state(optarg[x], MPROTECT);
1549 break;
1550 case 'e':
1551 case 'E':
1552 do_state(optarg[x], EMUTRAMP);
1553 break;
1554 case 'r':
1555 case 'R':
1556 do_state(optarg[x], RANDMMAP);
1557 break;
1558 case 'x':
1559 case 'X':
1560 do_state(optarg[x], RANDEXEC);
1561 break;
1562 default:
1563 break;
1564 }
1565 }
1566 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
1567 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
1568 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
1569 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
1570 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1571 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1572 setpax = flags;
1573 break;
1574 }
1575 case 'g': gmatch = 1; break;
1576 case 'L': use_ldcache = 1; break;
1577 case 'y': scan_symlink = 0; break;
1578 case 'A': scan_archives = 1; break;
1579 case 'B': show_banner = 0; break;
1580 case 'l': scan_ldpath = 1; break;
1581 case 'p': scan_envpath = 1; break;
1582 case 'R': dir_recurse = 1; break;
1583 case 'm': dir_crossmount = 0; break;
1584 case 'X': ++fix_elf; break;
1585 case 'x': show_pax = 1; break;
1586 case 'e': show_phdr = 1; break;
1587 case 't': show_textrel = 1; break;
1588 case 'r': show_rpath = 1; break;
1589 case 'n': show_needed = 1; break;
1590 case 'i': show_interp = 1; break;
1591 case 'b': show_bind = 1; break;
1592 case 'S': show_soname = 1; break;
1593 case 'T': show_textrels = 1; break;
1594 case 'q': be_quiet = 1; break;
1595 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1596 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break;
1597
1598 case ':':
1599 err("Option '%c' is missing parameter", optopt);
1600 case '?':
1601 err("Unknown option '%c' or argument missing", optopt);
1602 default:
1603 err("Unhandled option '%c'; please report this", i);
1604 }
1605 }
1606
1607 /* let the format option override all other options */
1608 if (out_format) {
1609 show_pax = show_phdr = show_textrel = show_rpath = \
1610 show_needed = show_interp = show_bind = show_soname = \
1611 show_textrels = 0;
1612 for (i = 0; out_format[i]; ++i) {
1613 if (!IS_MODIFIER(out_format[i])) continue;
1614
1615 switch (out_format[++i]) {
1616 case '+': break;
1617 case '%': break;
1618 case '#': break;
1619 case 'F': break;
1620 case 'p': break;
1621 case 'f': break;
1622 case 'k': break;
1623 case 's': break;
1624 case 'N': break;
1625 case 'o': break;
1626 case 'x': show_pax = 1; break;
1627 case 'e': show_phdr = 1; break;
1628 case 't': show_textrel = 1; break;
1629 case 'r': show_rpath = 1; break;
1630 case 'n': show_needed = 1; break;
1631 case 'i': show_interp = 1; break;
1632 case 'b': show_bind = 1; break;
1633 case 'S': show_soname = 1; break;
1634 case 'T': show_textrels = 1; break;
1635 default:
1636 err("Invalid format specifier '%c' (byte %i)",
1637 out_format[i], i+1);
1638 }
1639 }
1640
1641 /* construct our default format */
1642 } else {
1643 size_t fmt_len = 30;
1644 out_format = (char*)xmalloc(sizeof(char) * fmt_len);
1645 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1646 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
1647 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1648 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1649 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1650 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1651 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1652 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1653 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1654 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1655 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
1656 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1657 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1658 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1659 }
1660 if (be_verbose > 2) printf("Format: %s\n", out_format);
1661
1662 /* now lets actually do the scanning */
1663 if (scan_ldpath || use_ldcache)
1664 load_ld_so_conf(0, "/etc/ld.so.conf");
1665 if (scan_ldpath) scanelf_ldpath();
1666 if (scan_envpath) scanelf_envpath();
1667 if (!from_file && ttyname(0) == NULL)
1668 from_file = "-";
1669 if (from_file) {
1670 scanelf_from_file(from_file);
1671 from_file = *argv;
1672 }
1673 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1674 err("Nothing to scan !?");
1675 while (optind < argc) {
1676 search_path = argv[optind++];
1677 scanelf_dir(search_path);
1678 }
1679
1680 /* clean up */
1681 if (versioned_symname) free(versioned_symname);
1682 for (i = 0; ldpaths[i]; ++i)
1683 free(ldpaths[i]);
1684
1685 if (ldcache != 0)
1686 munmap(ldcache, ldcache_size);
1687 }
1688
1689
1690
1691 /* utility funcs */
1692 static char *xstrdup(const char *s)
1693 {
1694 char *ret = strdup(s);
1695 if (!ret) err("Could not strdup(): %s", strerror(errno));
1696 return ret;
1697 }
1698 static void *xmalloc(size_t size)
1699 {
1700 void *ret = malloc(size);
1701 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1702 return ret;
1703 }
1704 static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1705 {
1706 size_t new_len;
1707
1708 new_len = strlen(*dst) + strlen(src);
1709 if (*curr_len <= new_len) {
1710 *curr_len = new_len + (*curr_len / 2);
1711 *dst = realloc(*dst, *curr_len);
1712 if (!*dst)
1713 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1714 }
1715
1716 if (n)
1717 strncat(*dst, src, n);
1718 else
1719 strcat(*dst, src);
1720 }
1721 static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1722 {
1723 static char my_app[2];
1724 my_app[0] = append;
1725 my_app[1] = '\0';
1726 xstrcat(dst, my_app, curr_len);
1727 }
1728
1729
1730
1731 int main(int argc, char *argv[])
1732 {
1733 if (argc < 2)
1734 usage(EXIT_FAILURE);
1735 parseargs(argc, argv);
1736 fclose(stdout);
1737 #ifdef __BOUNDS_CHECKING_ON
1738 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()");
1739 #endif
1740 return EXIT_SUCCESS;
1741 }

  ViewVC Help
Powered by ViewVC 1.1.20