/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Contents of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1.192 - (show annotations) (download) (as text)
Mon Sep 29 06:01:22 2008 UTC (5 years, 6 months ago) by vapier
Branch: MAIN
Changes since 1.191: +7 -4 lines
File MIME type: text/x-csrc
only issue warnings on missing cache code when targeting an ELF system

1 /*
2 * Copyright 2003-2007 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/scanelf.c,v 1.191 2008/06/17 17:07:57 solar Exp $
5 *
6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
8 */
9
10 static const char *rcsid = "$Id: scanelf.c,v 1.191 2008/06/17 17:07:57 solar Exp $";
11 const char * const argv0 = "scanelf";
12
13 #include "paxinc.h"
14
15 #define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17 /* prototypes */
18 static int file_matches_list(const char *filename, char **matchlist);
19 static int scanelf_elfobj(elfobj *elf);
20 static int scanelf_elf(const char *filename, int fd, size_t len);
21 static int scanelf_archive(const char *filename, int fd, size_t len);
22 static int scanelf_file(const char *filename, const struct stat *st_cache);
23 static int scanelf_dir(const char *path);
24 static void scanelf_ldpath(void);
25 static void scanelf_envpath(void);
26 static void usage(int status);
27 static char **get_split_env(const char *envvar);
28 static void parseenv(void);
29 static int parseargs(int argc, char *argv[]);
30 static int rematch(const char *regex, const char *match, int cflags);
31
32 /* variables to control behavior */
33 static char match_etypes[126] = "";
34 static char *ldpaths[256];
35 static char scan_ldpath = 0;
36 static char scan_envpath = 0;
37 static char scan_symlink = 1;
38 static char scan_archives = 0;
39 static char dir_recurse = 0;
40 static char dir_crossmount = 1;
41 static char show_pax = 0;
42 static char show_perms = 0;
43 static char show_size = 0;
44 static char show_phdr = 0;
45 static char show_textrel = 0;
46 static char show_rpath = 0;
47 static char show_needed = 0;
48 static char show_interp = 0;
49 static char show_bind = 0;
50 static char show_soname = 0;
51 static char show_textrels = 0;
52 static char show_banner = 1;
53 static char show_endian = 0;
54 static char show_osabi = 0;
55 static char show_eabi = 0;
56 static char be_quiet = 0;
57 static char be_verbose = 0;
58 static char be_wewy_wewy_quiet = 0;
59 static char be_semi_verbose = 0;
60 static char *find_sym = NULL, *versioned_symname = NULL;
61 static char *find_lib = NULL;
62 static char *find_section = NULL;
63 static char *out_format = NULL;
64 static char *search_path = NULL;
65 static char fix_elf = 0;
66 static char g_match = 0;
67 static char use_ldcache = 0;
68
69 static char **qa_textrels = NULL;
70 static char **qa_execstack = NULL;
71 static char **qa_wx_load = NULL;
72
73 int match_bits = 0;
74 unsigned int match_perms = 0;
75 caddr_t ldcache = 0;
76 size_t ldcache_size = 0;
77 unsigned long setpax = 0UL;
78
79 int has_objdump = 0;
80
81 static char *getstr_perms(const char *fname);
82 static char *getstr_perms(const char *fname)
83 {
84 struct stat st;
85 static char buf[8];
86
87 if ((stat(fname, &st)) == (-1))
88 return (char *) "";
89
90 snprintf(buf, sizeof(buf), "%o", st.st_mode);
91
92 return (char *) buf + 2;
93 }
94
95 /* find the path to a file by name */
96 static char *which(const char *fname)
97 {
98 static char fullpath[BUFSIZ];
99 char *path, *p;
100
101 path = getenv("PATH");
102 if (!path)
103 return NULL;
104
105 path = xstrdup(path);
106 while ((p = strrchr(path, ':')) != NULL) {
107 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
108 *p = 0;
109 if (access(fullpath, R_OK) != (-1)) {
110 free(path);
111 return (char *) fullpath;
112 }
113 }
114 free(path);
115 return NULL;
116 }
117
118 /* 1 on failure. 0 otherwise */
119 static int rematch(const char *regex, const char *match, int cflags)
120 {
121 regex_t preg;
122 int ret;
123
124 if ((match == NULL) || (regex == NULL))
125 return EXIT_FAILURE;
126
127 if ((ret = regcomp(&preg, regex, cflags))) {
128 char err[256];
129
130 if (regerror(ret, &preg, err, sizeof(err)))
131 fprintf(stderr, "regcomp failed: %s", err);
132 else
133 fprintf(stderr, "regcomp failed");
134
135 return EXIT_FAILURE;
136 }
137 ret = regexec(&preg, match, 0, NULL, 0);
138 regfree(&preg);
139
140 return ret;
141 }
142
143 /* sub-funcs for scanelf_file() */
144 static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab)
145 {
146 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
147 #define GET_SYMTABS(B) \
148 if (elf->elf_class == ELFCLASS ## B) { \
149 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \
150 /* debug sections */ \
151 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \
152 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \
153 /* runtime sections */ \
154 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \
155 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \
156 if (symtab && dynsym) { \
157 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \
158 } else { \
159 *sym = (void*)(symtab ? symtab : dynsym); \
160 } \
161 if (strtab && dynstr) { \
162 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \
163 } else { \
164 *tab = (void*)(strtab ? strtab : dynstr); \
165 } \
166 }
167 GET_SYMTABS(32)
168 GET_SYMTABS(64)
169 }
170
171 static char *scanelf_file_pax(elfobj *elf, char *found_pax)
172 {
173 static char ret[7];
174 unsigned long i, shown;
175
176 if (!show_pax) return NULL;
177
178 shown = 0;
179 memset(&ret, 0, sizeof(ret));
180
181 if (elf->phdr) {
182 #define SHOW_PAX(B) \
183 if (elf->elf_class == ELFCLASS ## B) { \
184 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
185 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
186 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
187 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
188 continue; \
189 if (fix_elf && setpax) { \
190 /* set the paxctl flags */ \
191 ESET(phdr[i].p_flags, setpax); \
192 } \
193 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
194 continue; \
195 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
196 *found_pax = 1; \
197 ++shown; \
198 break; \
199 } \
200 }
201 SHOW_PAX(32)
202 SHOW_PAX(64)
203 }
204
205 if (fix_elf && setpax) {
206 /* set the chpax settings */
207 if (elf->elf_class == ELFCLASS32) {
208 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
209 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
210 } else {
211 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
212 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
213 }
214 }
215
216 /* fall back to EI_PAX if no PT_PAX was found */
217 if (!*ret) {
218 static char *paxflags;
219 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
220 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
221 *found_pax = 1;
222 return (be_wewy_wewy_quiet ? NULL : paxflags);
223 }
224 strncpy(ret, paxflags, sizeof(ret));
225 }
226
227 if (be_wewy_wewy_quiet || (be_quiet && !shown))
228 return NULL;
229 else
230 return ret;
231 }
232
233 static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
234 {
235 static char ret[12];
236 char *found;
237 unsigned long i, shown, multi_stack, multi_relro, multi_load;
238 int max_pt_load;
239
240 if (!show_phdr) return NULL;
241
242 memcpy(ret, "--- --- ---\0", 12);
243
244 shown = 0;
245 multi_stack = multi_relro = multi_load = 0;
246 max_pt_load = elf_max_pt_load(elf);
247
248 #define NOTE_GNU_STACK ".note.GNU-stack"
249 #define SHOW_PHDR(B) \
250 if (elf->elf_class == ELFCLASS ## B) { \
251 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
252 Elf ## B ## _Off offset; \
253 uint32_t flags, check_flags; \
254 if (elf->phdr != NULL) { \
255 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
256 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
257 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
258 if (multi_stack++) \
259 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
260 if (file_matches_list(elf->filename, qa_execstack)) \
261 continue; \
262 found = found_phdr; \
263 offset = 0; \
264 check_flags = PF_X; \
265 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
266 if (multi_relro++) \
267 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
268 found = found_relro; \
269 offset = 4; \
270 check_flags = PF_X; \
271 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
272 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
273 if (multi_load++ > max_pt_load) \
274 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
275 if (file_matches_list(elf->filename, qa_wx_load)) \
276 continue; \
277 found = found_load; \
278 offset = 8; \
279 check_flags = PF_W|PF_X; \
280 } else \
281 continue; \
282 flags = EGET(phdr[i].p_flags); \
283 if (be_quiet && ((flags & check_flags) != check_flags)) \
284 continue; \
285 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
286 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
287 ret[3] = ret[7] = '!'; \
288 flags = EGET(phdr[i].p_flags); \
289 } \
290 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
291 *found = 1; \
292 ++shown; \
293 } \
294 } else if (elf->shdr != NULL) { \
295 /* no program headers which means this is prob an object file */ \
296 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
297 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
298 char *str; \
299 if ((void*)strtbl > (void*)elf->data_end) \
300 goto skip_this_shdr##B; \
301 check_flags = SHF_WRITE|SHF_EXECINSTR; \
302 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
303 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
304 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
305 str = elf->data + offset; \
306 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
307 if (!strcmp(str, NOTE_GNU_STACK)) { \
308 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
309 flags = EGET(shdr[i].sh_flags); \
310 if (be_quiet && ((flags & check_flags) != check_flags)) \
311 continue; \
312 ++*found_phdr; \
313 shown = 1; \
314 if (flags & SHF_WRITE) ret[0] = 'W'; \
315 if (flags & SHF_ALLOC) ret[1] = 'A'; \
316 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
317 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
318 break; \
319 } \
320 } \
321 skip_this_shdr##B: \
322 if (!multi_stack) { \
323 if (file_matches_list(elf->filename, qa_execstack)) \
324 return NULL; \
325 *found_phdr = 1; \
326 shown = 1; \
327 memcpy(ret, "!WX", 3); \
328 } \
329 } \
330 }
331 SHOW_PHDR(32)
332 SHOW_PHDR(64)
333
334 if (be_wewy_wewy_quiet || (be_quiet && !shown))
335 return NULL;
336 else
337 return ret;
338 }
339
340 /*
341 * See if this ELF contains a DT_TEXTREL tag in any of its
342 * PT_DYNAMIC sections.
343 */
344 static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
345 {
346 static const char *ret = "TEXTREL";
347 unsigned long i;
348
349 if (!show_textrel && !show_textrels) return NULL;
350
351 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
352
353 if (elf->phdr) {
354 #define SHOW_TEXTREL(B) \
355 if (elf->elf_class == ELFCLASS ## B) { \
356 Elf ## B ## _Dyn *dyn; \
357 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
358 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
359 Elf ## B ## _Off offset; \
360 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
361 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
362 offset = EGET(phdr[i].p_offset); \
363 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
364 dyn = DYN ## B (elf->data + offset); \
365 while (EGET(dyn->d_tag) != DT_NULL) { \
366 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
367 *found_textrel = 1; \
368 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
369 return (be_wewy_wewy_quiet ? NULL : ret); \
370 } \
371 ++dyn; \
372 } \
373 } }
374 SHOW_TEXTREL(32)
375 SHOW_TEXTREL(64)
376 }
377
378 if (be_quiet || be_wewy_wewy_quiet)
379 return NULL;
380 else
381 return " - ";
382 }
383
384 /*
385 * Scan the .text section to see if there are any relocations in it.
386 * Should rewrite this to check PT_LOAD sections that are marked
387 * Executable rather than the section named '.text'.
388 */
389 static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
390 {
391 unsigned long s, r, rmax;
392 void *symtab_void, *strtab_void, *text_void;
393
394 if (!show_textrels) return NULL;
395
396 /* don't search for TEXTREL's if the ELF doesn't have any */
397 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
398 if (!*found_textrel) return NULL;
399
400 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
401 text_void = elf_findsecbyname(elf, ".text");
402
403 if (symtab_void && strtab_void && text_void && elf->shdr) {
404 #define SHOW_TEXTRELS(B) \
405 if (elf->elf_class == ELFCLASS ## B) { \
406 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
407 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
408 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
409 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
410 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
411 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
412 uint ## B ## _t memsz = EGET(text->sh_size); \
413 Elf ## B ## _Rel *rel; \
414 Elf ## B ## _Rela *rela; \
415 /* search the section headers for relocations */ \
416 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
417 uint32_t sh_type = EGET(shdr[s].sh_type); \
418 if (sh_type == SHT_REL) { \
419 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \
420 rela = NULL; \
421 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
422 } else if (sh_type == SHT_RELA) { \
423 rel = NULL; \
424 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \
425 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
426 } else \
427 continue; \
428 /* now see if any of the relocs are in the .text */ \
429 for (r = 0; r < rmax; ++r) { \
430 unsigned long sym_max; \
431 Elf ## B ## _Addr offset_tmp; \
432 Elf ## B ## _Sym *func; \
433 Elf ## B ## _Sym *sym; \
434 Elf ## B ## _Addr r_offset; \
435 uint ## B ## _t r_info; \
436 if (sh_type == SHT_REL) { \
437 r_offset = EGET(rel[r].r_offset); \
438 r_info = EGET(rel[r].r_info); \
439 } else { \
440 r_offset = EGET(rela[r].r_offset); \
441 r_info = EGET(rela[r].r_info); \
442 } \
443 /* make sure this relocation is inside of the .text */ \
444 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
445 if (be_verbose <= 2) continue; \
446 } else \
447 *found_textrels = 1; \
448 /* locate this relocation symbol name */ \
449 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
450 if ((void*)sym > (void*)elf->data_end) { \
451 warn("%s: corrupt ELF symbol", elf->filename); \
452 continue; \
453 } \
454 sym_max = ELF ## B ## _R_SYM(r_info); \
455 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
456 sym += sym_max; \
457 else \
458 sym = NULL; \
459 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
460 /* show the raw details about this reloc */ \
461 printf(" %s: ", elf->base_filename); \
462 if (sym && sym->st_name) \
463 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \
464 else \
465 printf("(memory/data?)"); \
466 printf(" [0x%lX]", (unsigned long)r_offset); \
467 /* now try to find the closest symbol that this rel is probably in */ \
468 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
469 func = NULL; \
470 offset_tmp = 0; \
471 while (sym_max--) { \
472 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
473 func = sym; \
474 offset_tmp = EGET(sym->st_value); \
475 } \
476 ++sym; \
477 } \
478 printf(" in "); \
479 if (func && func->st_name) { \
480 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
481 if (r_offset > EGET(func->st_size)) \
482 printf("(optimized out: previous %s)", func_name); \
483 else \
484 printf("%s", func_name); \
485 } else \
486 printf("(optimized out)"); \
487 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
488 if (be_verbose && has_objdump) { \
489 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
490 char *sysbuf; \
491 size_t syslen; \
492 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
493 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
494 sysbuf = xmalloc(syslen); \
495 if (end_addr < r_offset) \
496 /* not uncommon when things are optimized out */ \
497 end_addr = r_offset + 0x100; \
498 snprintf(sysbuf, syslen, sysfmt, \
499 (unsigned long)offset_tmp, \
500 (unsigned long)end_addr, \
501 elf->filename, \
502 (unsigned long)r_offset); \
503 fflush(stdout); \
504 system(sysbuf); \
505 fflush(stdout); \
506 free(sysbuf); \
507 } \
508 } \
509 } }
510 SHOW_TEXTRELS(32)
511 SHOW_TEXTRELS(64)
512 }
513 if (!*found_textrels)
514 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
515
516 return NULL;
517 }
518
519 static void rpath_security_checks(elfobj *, char *, const char *);
520 static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
521 {
522 struct stat st;
523 switch (*item) {
524 case '/': break;
525 case '.':
526 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
527 break;
528 case ':':
529 case '\0':
530 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
531 break;
532 case '$':
533 if (fstat(elf->fd, &st) != -1)
534 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
535 warnf("Security problem with %s='%s' in %s with mode set of %o",
536 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
537 break;
538 default:
539 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
540 break;
541 }
542 }
543 static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
544 {
545 unsigned long i, s;
546 char *rpath, *runpath, **r;
547 void *strtbl_void;
548
549 if (!show_rpath) return;
550
551 strtbl_void = elf_findsecbyname(elf, ".dynstr");
552 rpath = runpath = NULL;
553
554 if (elf->phdr && strtbl_void) {
555 #define SHOW_RPATH(B) \
556 if (elf->elf_class == ELFCLASS ## B) { \
557 Elf ## B ## _Dyn *dyn; \
558 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
559 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
560 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
561 Elf ## B ## _Off offset; \
562 Elf ## B ## _Xword word; \
563 /* Scan all the program headers */ \
564 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
565 /* Just scan dynamic headers */ \
566 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
567 offset = EGET(phdr[i].p_offset); \
568 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
569 /* Just scan dynamic RPATH/RUNPATH headers */ \
570 dyn = DYN ## B (elf->data + offset); \
571 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
572 if (word == DT_RPATH) { \
573 r = &rpath; \
574 } else if (word == DT_RUNPATH) { \
575 r = &runpath; \
576 } else { \
577 ++dyn; \
578 continue; \
579 } \
580 /* Verify the memory is somewhat sane */ \
581 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
582 if (offset < (Elf ## B ## _Off)elf->len) { \
583 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
584 *r = (char*)(elf->data + offset); \
585 /* cache the length in case we need to nuke this section later on */ \
586 if (fix_elf) \
587 offset = strlen(*r); \
588 /* If quiet, don't output paths in ld.so.conf */ \
589 if (be_quiet) { \
590 size_t len; \
591 char *start, *end; \
592 /* note that we only 'chop' off leading known paths. */ \
593 /* since *r is read-only memory, we can only move the ptr forward. */ \
594 start = *r; \
595 /* scan each path in : delimited list */ \
596 while (start) { \
597 rpath_security_checks(elf, start, get_elfdtype(word)); \
598 end = strchr(start, ':'); \
599 len = (end ? abs(end - start) : strlen(start)); \
600 if (use_ldcache) \
601 for (s = 0; ldpaths[s]; ++s) \
602 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \
603 *r = end; \
604 /* corner case ... if RPATH reads "/usr/lib:", we want \
605 * to show ':' rather than '' */ \
606 if (end && end[1] != '\0') \
607 (*r)++; \
608 break; \
609 } \
610 if (!*r || !end) \
611 break; \
612 else \
613 start = start + len + 1; \
614 } \
615 } \
616 if (*r) { \
617 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
618 /* just nuke it */ \
619 nuke_it##B: \
620 memset(*r, 0x00, offset); \
621 *r = NULL; \
622 ESET(dyn->d_tag, DT_DEBUG); \
623 ESET(dyn->d_un.d_ptr, 0); \
624 } else if (fix_elf) { \
625 /* try to clean "bad" paths */ \
626 size_t len, tmpdir_len; \
627 char *start, *end; \
628 const char *tmpdir; \
629 start = *r; \
630 tmpdir = (getenv("TMPDIR") ? : "."); \
631 tmpdir_len = strlen(tmpdir); \
632 while (1) { \
633 end = strchr(start, ':'); \
634 if (start == end) { \
635 eat_this_path##B: \
636 len = strlen(end); \
637 memmove(start, end+1, len); \
638 start[len-1] = '\0'; \
639 end = start - 1; \
640 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
641 if (!end) { \
642 if (start == *r) \
643 goto nuke_it##B; \
644 *--start = '\0'; \
645 } else \
646 goto eat_this_path##B; \
647 } \
648 if (!end) \
649 break; \
650 start = end + 1; \
651 } \
652 if (**r == '\0') \
653 goto nuke_it##B; \
654 } \
655 if (*r) \
656 *found_rpath = 1; \
657 } \
658 } \
659 ++dyn; \
660 } \
661 } }
662 SHOW_RPATH(32)
663 SHOW_RPATH(64)
664 }
665
666 if (be_wewy_wewy_quiet) return;
667
668 if (rpath && runpath) {
669 if (!strcmp(rpath, runpath)) {
670 xstrcat(ret, runpath, ret_len);
671 } else {
672 fprintf(stderr, "RPATH [%s] != RUNPATH [%s]\n", rpath, runpath);
673 xchrcat(ret, '{', ret_len);
674 xstrcat(ret, rpath, ret_len);
675 xchrcat(ret, ',', ret_len);
676 xstrcat(ret, runpath, ret_len);
677 xchrcat(ret, '}', ret_len);
678 }
679 } else if (rpath || runpath)
680 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
681 else if (!be_quiet)
682 xstrcat(ret, " - ", ret_len);
683 }
684
685 #define LDSO_CACHE_MAGIC "ld.so-"
686 #define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
687 #define LDSO_CACHE_VER "1.7.0"
688 #define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
689 #define FLAG_ANY -1
690 #define FLAG_TYPE_MASK 0x00ff
691 #define FLAG_LIBC4 0x0000
692 #define FLAG_ELF 0x0001
693 #define FLAG_ELF_LIBC5 0x0002
694 #define FLAG_ELF_LIBC6 0x0003
695 #define FLAG_REQUIRED_MASK 0xff00
696 #define FLAG_SPARC_LIB64 0x0100
697 #define FLAG_IA64_LIB64 0x0200
698 #define FLAG_X8664_LIB64 0x0300
699 #define FLAG_S390_LIB64 0x0400
700 #define FLAG_POWERPC_LIB64 0x0500
701 #define FLAG_MIPS64_LIBN32 0x0600
702 #define FLAG_MIPS64_LIBN64 0x0700
703
704 static char *lookup_cache_lib(elfobj *, char *);
705
706 #if defined(__GLIBC__) || defined(__UCLIBC__)
707
708 static char *lookup_cache_lib(elfobj *elf, char *fname)
709 {
710 int fd = 0;
711 char *strs;
712 static char buf[__PAX_UTILS_PATH_MAX] = "";
713 const char *cachefile = "/etc/ld.so.cache";
714 struct stat st;
715
716 typedef struct {
717 char magic[LDSO_CACHE_MAGIC_LEN];
718 char version[LDSO_CACHE_VER_LEN];
719 int nlibs;
720 } header_t;
721 header_t *header;
722
723 typedef struct {
724 int flags;
725 int sooffset;
726 int liboffset;
727 } libentry_t;
728 libentry_t *libent;
729
730 if (fname == NULL)
731 return NULL;
732
733 if (ldcache == 0) {
734 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1)
735 return NULL;
736
737 /* cache these values so we only map/unmap the cache file once */
738 ldcache_size = st.st_size;
739 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
740
741 close(fd);
742
743 if (ldcache == (caddr_t)-1) {
744 ldcache = 0;
745 return NULL;
746 }
747
748 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN))
749 return NULL;
750 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
751 return NULL;
752 }
753
754 header = (header_t *) ldcache;
755 libent = (libentry_t *) (ldcache + sizeof(header_t));
756 strs = (char *) &libent[header->nlibs];
757
758 for (fd = 0; fd < header->nlibs; fd++) {
759 /* this should be more fine grained, but for now we assume that
760 * diff arches will not be cached together. and we ignore the
761 * the different multilib mips cases. */
762 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
763 continue;
764 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
765 continue;
766
767 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
768 continue;
769 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
770 }
771 return buf;
772 }
773 #elif defined(__NetBSD__)
774 static char *lookup_cache_lib(elfobj *elf, char *fname)
775 {
776 static char buf[__PAX_UTILS_PATH_MAX] = "";
777 static struct stat st;
778
779 char **ldpath;
780 for (ldpath = ldpaths; *ldpath != NULL; ldpath++) {
781 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", *ldpath, fname) >= sizeof(buf))
782 continue; /* if the pathname is too long, or something went wrong, ignore */
783
784 if (stat(buf, &st) != 0)
785 continue; /* if the lib doesn't exist in *ldpath, look further */
786
787 /* NetBSD doesn't actually do sanity checks, it just loads the file
788 * and if that doesn't work, continues looking in other directories.
789 * This cannot easily be safely emulated, unfortunately. For now,
790 * just assume that if it exists, it's a valid library. */
791
792 return buf;
793 }
794
795 /* not found in any path */
796 return NULL;
797 }
798 #else
799 #ifdef __ELF__
800 #warning Cache support not implemented for your target
801 #endif
802 static char *lookup_cache_lib(elfobj *elf, char *fname)
803 {
804 return NULL;
805 }
806 #endif
807
808 static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
809 {
810 unsigned long i;
811 char *needed;
812 void *strtbl_void;
813 char *p;
814
815 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL;
816
817 strtbl_void = elf_findsecbyname(elf, ".dynstr");
818
819 if (elf->phdr && strtbl_void) {
820 #define SHOW_NEEDED(B) \
821 if (elf->elf_class == ELFCLASS ## B) { \
822 Elf ## B ## _Dyn *dyn; \
823 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
824 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
825 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
826 Elf ## B ## _Off offset; \
827 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
828 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
829 offset = EGET(phdr[i].p_offset); \
830 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
831 dyn = DYN ## B (elf->data + offset); \
832 while (EGET(dyn->d_tag) != DT_NULL) { \
833 if (EGET(dyn->d_tag) == DT_NEEDED) { \
834 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
835 if (offset >= (Elf ## B ## _Off)elf->len) { \
836 ++dyn; \
837 continue; \
838 } \
839 needed = (char*)(elf->data + offset); \
840 if (op == 0) { \
841 if (!be_wewy_wewy_quiet) { \
842 if (*found_needed) xchrcat(ret, ',', ret_len); \
843 if (use_ldcache) \
844 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
845 needed = p; \
846 xstrcat(ret, needed, ret_len); \
847 } \
848 *found_needed = 1; \
849 } else { \
850 if (!strncmp(find_lib, needed, strlen( !g_match ? needed : find_lib))) { \
851 *found_lib = 1; \
852 return (be_wewy_wewy_quiet ? NULL : needed); \
853 } \
854 } \
855 } \
856 ++dyn; \
857 } \
858 } }
859 SHOW_NEEDED(32)
860 SHOW_NEEDED(64)
861 if (op == 0 && !*found_needed && be_verbose)
862 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
863 }
864
865 return NULL;
866 }
867 static char *scanelf_file_interp(elfobj *elf, char *found_interp)
868 {
869 void *strtbl_void;
870
871 if (!show_interp) return NULL;
872
873 strtbl_void = elf_findsecbyname(elf, ".interp");
874
875 if (strtbl_void) {
876 #define SHOW_INTERP(B) \
877 if (elf->elf_class == ELFCLASS ## B) { \
878 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
879 *found_interp = 1; \
880 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
881 }
882 SHOW_INTERP(32)
883 SHOW_INTERP(64)
884 }
885 return NULL;
886 }
887 static char *scanelf_file_bind(elfobj *elf, char *found_bind)
888 {
889 unsigned long i;
890 struct stat s;
891 char dynamic = 0;
892
893 if (!show_bind) return NULL;
894 if (!elf->phdr) return NULL;
895
896 #define SHOW_BIND(B) \
897 if (elf->elf_class == ELFCLASS ## B) { \
898 Elf ## B ## _Dyn *dyn; \
899 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
900 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
901 Elf ## B ## _Off offset; \
902 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
903 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
904 dynamic = 1; \
905 offset = EGET(phdr[i].p_offset); \
906 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
907 dyn = DYN ## B (elf->data + offset); \
908 while (EGET(dyn->d_tag) != DT_NULL) { \
909 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
910 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
911 { \
912 if (be_quiet) return NULL; \
913 *found_bind = 1; \
914 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
915 } \
916 ++dyn; \
917 } \
918 } \
919 }
920 SHOW_BIND(32)
921 SHOW_BIND(64)
922
923 if (be_wewy_wewy_quiet) return NULL;
924
925 /* don't output anything if quiet mode and the ELF is static or not setuid */
926 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
927 return NULL;
928 } else {
929 *found_bind = 1;
930 return (char *) (dynamic ? "LAZY" : "STATIC");
931 }
932 }
933 static char *scanelf_file_soname(elfobj *elf, char *found_soname)
934 {
935 unsigned long i;
936 char *soname;
937 void *strtbl_void;
938
939 if (!show_soname) return NULL;
940
941 strtbl_void = elf_findsecbyname(elf, ".dynstr");
942
943 if (elf->phdr && strtbl_void) {
944 #define SHOW_SONAME(B) \
945 if (elf->elf_class == ELFCLASS ## B) { \
946 Elf ## B ## _Dyn *dyn; \
947 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
948 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
949 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
950 Elf ## B ## _Off offset; \
951 /* only look for soname in shared objects */ \
952 if (EGET(ehdr->e_type) != ET_DYN) \
953 return NULL; \
954 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
955 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
956 offset = EGET(phdr[i].p_offset); \
957 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
958 dyn = DYN ## B (elf->data + offset); \
959 while (EGET(dyn->d_tag) != DT_NULL) { \
960 if (EGET(dyn->d_tag) == DT_SONAME) { \
961 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
962 if (offset >= (Elf ## B ## _Off)elf->len) { \
963 ++dyn; \
964 continue; \
965 } \
966 soname = (char*)(elf->data + offset); \
967 *found_soname = 1; \
968 return (be_wewy_wewy_quiet ? NULL : soname); \
969 } \
970 ++dyn; \
971 } \
972 } }
973 SHOW_SONAME(32)
974 SHOW_SONAME(64)
975 }
976
977 return NULL;
978 }
979
980 static char *scanelf_file_sym(elfobj *elf, char *found_sym)
981 {
982 unsigned long i;
983 char *ret;
984 void *symtab_void, *strtab_void;
985
986 if (!find_sym) return NULL;
987 ret = find_sym;
988
989 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
990
991 if (symtab_void && strtab_void) {
992 #define FIND_SYM(B) \
993 if (elf->elf_class == ELFCLASS ## B) { \
994 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
995 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
996 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
997 unsigned long cnt = EGET(symtab->sh_entsize); \
998 char *symname; \
999 if (cnt) \
1000 cnt = EGET(symtab->sh_size) / cnt; \
1001 for (i = 0; i < cnt; ++i) { \
1002 if (sym->st_name) { \
1003 /* make sure the symbol name is in acceptable memory range */ \
1004 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
1005 if ((void*)symname > (void*)elf->data_end) { \
1006 warnf("%s: corrupt ELF symbols", elf->filename); \
1007 ++sym; \
1008 continue; \
1009 } \
1010 /* debug display ... show all symbols and some extra info */ \
1011 if (g_match ? rematch(ret, symname, REG_EXTENDED) == 0 : *ret == '*') { \
1012 printf("%s(%s) %5lX %15s %s %s\n", \
1013 ((*found_sym == 0) ? "\n\t" : "\t"), \
1014 elf->base_filename, \
1015 (unsigned long)sym->st_size, \
1016 get_elfstttype(sym->st_info), \
1017 sym->st_shndx == SHN_UNDEF ? "U" : "D", symname); \
1018 *found_sym = 1; \
1019 } else { \
1020 /* allow the user to specify a comma delimited list of symbols to search for */ \
1021 char *this_sym, *this_sym_ver, *next_sym; \
1022 this_sym = ret; \
1023 this_sym_ver = versioned_symname; \
1024 do { \
1025 next_sym = strchr(this_sym, ','); \
1026 if (next_sym == NULL) \
1027 next_sym = this_sym + strlen(this_sym); \
1028 /* do we want a defined symbol ? */ \
1029 if (*this_sym == '+') { \
1030 if (sym->st_shndx == SHN_UNDEF) \
1031 goto skip_this_sym##B; \
1032 ++this_sym; \
1033 ++this_sym_ver; \
1034 /* do we want an undefined symbol ? */ \
1035 } else if (*this_sym == '-') { \
1036 if (sym->st_shndx != SHN_UNDEF) \
1037 goto skip_this_sym##B; \
1038 ++this_sym; \
1039 ++this_sym_ver; \
1040 } \
1041 /* ok, lets compare the name now */ \
1042 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
1043 (strncmp(this_sym_ver, symname, strlen(this_sym_ver)) == 0)) { \
1044 if (be_semi_verbose) { \
1045 char buf[126]; \
1046 snprintf(buf, sizeof(buf), "%lX %s %s", \
1047 (unsigned long)sym->st_size, get_elfstttype(sym->st_info), this_sym); \
1048 ret = buf; \
1049 } else \
1050 ret = this_sym; \
1051 (*found_sym)++; \
1052 goto break_out; \
1053 } \
1054 skip_this_sym##B: this_sym = next_sym + 1; \
1055 } while (*next_sym != '\0'); \
1056 } \
1057 } \
1058 ++sym; \
1059 } }
1060 FIND_SYM(32)
1061 FIND_SYM(64)
1062 }
1063
1064 break_out:
1065 if (be_wewy_wewy_quiet) return NULL;
1066
1067 if (*find_sym != '*' && *found_sym)
1068 return ret;
1069 if (be_quiet)
1070 return NULL;
1071 else
1072 return (char *)" - ";
1073 }
1074
1075 static char *scanelf_file_sections(elfobj *elf, char *found_section)
1076 {
1077 if (!find_section)
1078 return NULL;
1079
1080 #define FIND_SECTION(B) \
1081 if (elf->elf_class == ELFCLASS ## B) { \
1082 int invert; \
1083 Elf ## B ## _Shdr *section; \
1084 invert = (*find_section == '!' ? 1 : 0); \
1085 section = SHDR ## B (elf_findsecbyname(elf, find_section+invert)); \
1086 if ((section == NULL && invert) || (section != NULL && !invert)) \
1087 *found_section = 1; \
1088 }
1089 FIND_SECTION(32)
1090 FIND_SECTION(64)
1091
1092 if (be_wewy_wewy_quiet)
1093 return NULL;
1094
1095 if (*found_section)
1096 return find_section;
1097
1098 if (be_quiet)
1099 return NULL;
1100 else
1101 return (char *)" - ";
1102 }
1103
1104 /* scan an elf file and show all the fun stuff */
1105 #define prints(str) write(fileno(stdout), str, strlen(str))
1106 static int scanelf_elfobj(elfobj *elf)
1107 {
1108 unsigned long i;
1109 char found_pax, found_phdr, found_relro, found_load, found_textrel,
1110 found_rpath, found_needed, found_interp, found_bind, found_soname,
1111 found_sym, found_lib, found_file, found_textrels, found_section;
1112 static char *out_buffer = NULL;
1113 static size_t out_len;
1114
1115 found_pax = found_phdr = found_relro = found_load = found_textrel = \
1116 found_rpath = found_needed = found_interp = found_bind = found_soname = \
1117 found_sym = found_lib = found_file = found_textrels = found_section = 0;
1118
1119 if (be_verbose > 2)
1120 printf("%s: scanning file {%s,%s}\n", elf->filename,
1121 get_elfeitype(EI_CLASS, elf->elf_class),
1122 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
1123 else if (be_verbose > 1)
1124 printf("%s: scanning file\n", elf->filename);
1125
1126 /* init output buffer */
1127 if (!out_buffer) {
1128 out_len = sizeof(char) * 80;
1129 out_buffer = xmalloc(out_len);
1130 }
1131 *out_buffer = '\0';
1132
1133 /* show the header */
1134 if (!be_quiet && show_banner) {
1135 for (i = 0; out_format[i]; ++i) {
1136 if (!IS_MODIFIER(out_format[i])) continue;
1137
1138 switch (out_format[++i]) {
1139 case '+': break;
1140 case '%': break;
1141 case '#': break;
1142 case 'F':
1143 case 'p':
1144 case 'f': prints("FILE "); found_file = 1; break;
1145 case 'o': prints(" TYPE "); break;
1146 case 'x': prints(" PAX "); break;
1147 case 'e': prints("STK/REL/PTL "); break;
1148 case 't': prints("TEXTREL "); break;
1149 case 'r': prints("RPATH "); break;
1150 case 'M': prints("CLASS "); break;
1151 case 'n': prints("NEEDED "); break;
1152 case 'i': prints("INTERP "); break;
1153 case 'b': prints("BIND "); break;
1154 case 'Z': prints("SIZE "); break;
1155 case 'S': prints("SONAME "); break;
1156 case 's': prints("SYM "); break;
1157 case 'N': prints("LIB "); break;
1158 case 'T': prints("TEXTRELS "); break;
1159 case 'k': prints("SECTION "); break;
1160 case 'a': prints("ARCH "); break;
1161 case 'I': prints("OSABI "); break;
1162 case 'Y': prints("EABI "); break;
1163 case 'O': prints("PERM "); break;
1164 case 'D': prints("ENDIAN "); break;
1165 default: warnf("'%c' has no title ?", out_format[i]);
1166 }
1167 }
1168 if (!found_file) prints("FILE ");
1169 prints("\n");
1170 found_file = 0;
1171 show_banner = 0;
1172 }
1173
1174 /* dump all the good stuff */
1175 for (i = 0; out_format[i]; ++i) {
1176 const char *out;
1177 const char *tmp;
1178 static char ubuf[sizeof(unsigned long)*2];
1179 if (!IS_MODIFIER(out_format[i])) {
1180 xchrcat(&out_buffer, out_format[i], &out_len);
1181 continue;
1182 }
1183
1184 out = NULL;
1185 be_wewy_wewy_quiet = (out_format[i] == '#');
1186 be_semi_verbose = (out_format[i] == '+');
1187 switch (out_format[++i]) {
1188 case '+':
1189 case '%':
1190 case '#':
1191 xchrcat(&out_buffer, out_format[i], &out_len); break;
1192 case 'F':
1193 found_file = 1;
1194 if (be_wewy_wewy_quiet) break;
1195 xstrcat(&out_buffer, elf->filename, &out_len);
1196 break;
1197 case 'p':
1198 found_file = 1;
1199 if (be_wewy_wewy_quiet) break;
1200 tmp = elf->filename;
1201 if (search_path) {
1202 ssize_t len_search = strlen(search_path);
1203 ssize_t len_file = strlen(elf->filename);
1204 if (!strncmp(elf->filename, search_path, len_search) && \
1205 len_file > len_search)
1206 tmp += len_search;
1207 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
1208 }
1209 xstrcat(&out_buffer, tmp, &out_len);
1210 break;
1211 case 'f':
1212 found_file = 1;
1213 if (be_wewy_wewy_quiet) break;
1214 tmp = strrchr(elf->filename, '/');
1215 tmp = (tmp == NULL ? elf->filename : tmp+1);
1216 xstrcat(&out_buffer, tmp, &out_len);
1217 break;
1218 case 'o': out = get_elfetype(elf); break;
1219 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1220 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1221 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1222 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1223 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1224 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1225 case 'D': out = get_endian(elf); break;
1226 case 'O': out = getstr_perms(elf->filename); break;
1227 case 'n':
1228 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1229 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1230 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1231 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1232 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1233 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1234 case 'a': out = get_elfemtype(elf); break;
1235 case 'I': out = get_elfosabi(elf); break;
1236 case 'Y': out = get_elf_eabi(elf); break;
1237 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", elf->len); out = ubuf; break;;
1238 default: warnf("'%c' has no scan code?", out_format[i]);
1239 }
1240 if (out) {
1241 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
1242 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
1243 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1244 else
1245 xstrcat(&out_buffer, out, &out_len);
1246 }
1247 }
1248
1249 #define FOUND_SOMETHING() \
1250 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1251 found_rpath || found_needed || found_interp || found_bind || \
1252 found_soname || found_sym || found_lib || found_textrels || found_section )
1253
1254 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1255 xchrcat(&out_buffer, ' ', &out_len);
1256 xstrcat(&out_buffer, elf->filename, &out_len);
1257 }
1258 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
1259 puts(out_buffer);
1260 fflush(stdout);
1261 }
1262
1263 return 0;
1264 }
1265
1266 /* scan a single elf */
1267 static int scanelf_elf(const char *filename, int fd, size_t len)
1268 {
1269 int ret = 1;
1270 elfobj *elf;
1271
1272 /* verify this is real ELF */
1273 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1274 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1275 return ret;
1276 }
1277 switch (match_bits) {
1278 case 32:
1279 if (elf->elf_class != ELFCLASS32)
1280 goto label_done;
1281 break;
1282 case 64:
1283 if (elf->elf_class != ELFCLASS64)
1284 goto label_done;
1285 break;
1286 default: break;
1287 }
1288 if (strlen(match_etypes)) {
1289 char sbuf[126];
1290 strncpy(sbuf, match_etypes, sizeof(sbuf));
1291 if (strchr(match_etypes, ',') != NULL) {
1292 char *p;
1293 while ((p = strrchr(sbuf, ',')) != NULL) {
1294 *p = 0;
1295 if (etype_lookup(p+1) == get_etype(elf))
1296 goto label_ret;
1297 }
1298 }
1299 if (etype_lookup(sbuf) != get_etype(elf))
1300 goto label_done;
1301 }
1302
1303 label_ret:
1304 ret = scanelf_elfobj(elf);
1305
1306 label_done:
1307 unreadelf(elf);
1308 return ret;
1309 }
1310
1311 /* scan an archive of elfs */
1312 static int scanelf_archive(const char *filename, int fd, size_t len)
1313 {
1314 archive_handle *ar;
1315 archive_member *m;
1316 char *ar_buffer;
1317 elfobj *elf;
1318
1319 ar = ar_open_fd(filename, fd);
1320 if (ar == NULL)
1321 return 1;
1322
1323 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1324 while ((m=ar_next(ar)) != NULL) {
1325 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size);
1326 if (elf) {
1327 scanelf_elfobj(elf);
1328 unreadelf(elf);
1329 }
1330 }
1331 munmap(ar_buffer, len);
1332
1333 return 0;
1334 }
1335 /* scan a file which may be an elf or an archive or some other magical beast */
1336 static int scanelf_file(const char *filename, const struct stat *st_cache)
1337 {
1338 const struct stat *st = st_cache;
1339 struct stat symlink_st;
1340 int fd;
1341
1342 /* always handle regular files and handle symlinked files if no -y */
1343 if (S_ISLNK(st->st_mode)) {
1344 if (!scan_symlink) return 1;
1345 stat(filename, &symlink_st);
1346 st = &symlink_st;
1347 }
1348
1349 if (!S_ISREG(st->st_mode)) {
1350 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1351 return 1;
1352 }
1353
1354 if (match_perms) {
1355 if ((st->st_mode | match_perms) != st->st_mode)
1356 return 1;
1357 }
1358 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1)
1359 return 1;
1360
1361 if (scanelf_elf(filename, fd, st->st_size) == 1 && scan_archives)
1362 /* if it isn't an ELF, maybe it's an .a archive */
1363 scanelf_archive(filename, fd, st->st_size);
1364
1365 close(fd);
1366 return 0;
1367 }
1368
1369 /* scan a directory for ET_EXEC files and print when we find one */
1370 static int scanelf_dir(const char *path)
1371 {
1372 register DIR *dir;
1373 register struct dirent *dentry;
1374 struct stat st_top, st;
1375 char buf[__PAX_UTILS_PATH_MAX];
1376 size_t pathlen = 0, len = 0;
1377 int ret = 0;
1378
1379 /* make sure path exists */
1380 if (lstat(path, &st_top) == -1) {
1381 if (be_verbose > 2) printf("%s: does not exist\n", path);
1382 return 1;
1383 }
1384
1385 /* ok, if it isn't a directory, assume we can open it */
1386 if (!S_ISDIR(st_top.st_mode)) {
1387 return scanelf_file(path, &st_top);
1388 }
1389
1390 /* now scan the dir looking for fun stuff */
1391 if ((dir = opendir(path)) == NULL) {
1392 warnf("could not opendir %s: %s", path, strerror(errno));
1393 return 1;
1394 }
1395 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1396
1397 pathlen = strlen(path);
1398 while ((dentry = readdir(dir))) {
1399 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1400 continue;
1401 len = (pathlen + 1 + strlen(dentry->d_name) + 1);
1402 if (len >= sizeof(buf)) {
1403 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
1404 (unsigned long)len, (unsigned long)sizeof(buf));
1405 continue;
1406 }
1407 snprintf(buf, sizeof(buf), "%s%s%s", path, (path[pathlen-1] == '/') ? "" : "/", dentry->d_name);
1408 if (lstat(buf, &st) != -1) {
1409 if (S_ISREG(st.st_mode))
1410 ret = scanelf_file(buf, &st);
1411 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1412 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1413 ret = scanelf_dir(buf);
1414 }
1415 }
1416 }
1417 closedir(dir);
1418 return ret;
1419 }
1420
1421 static int scanelf_from_file(const char *filename)
1422 {
1423 FILE *fp = NULL;
1424 char *p;
1425 char path[__PAX_UTILS_PATH_MAX];
1426 int ret = 0;
1427
1428 if (strcmp(filename, "-") == 0)
1429 fp = stdin;
1430 else if ((fp = fopen(filename, "r")) == NULL)
1431 return 1;
1432
1433 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1434 if ((p = strchr(path, '\n')) != NULL)
1435 *p = 0;
1436 search_path = path;
1437 ret = scanelf_dir(path);
1438 }
1439 if (fp != stdin)
1440 fclose(fp);
1441 return ret;
1442 }
1443
1444 #if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1445
1446 static int load_ld_cache_config(int i, const char *fname)
1447 {
1448 FILE *fp = NULL;
1449 char *p;
1450 char path[__PAX_UTILS_PATH_MAX];
1451
1452 if (i + 1 == ARRAY_SIZE(ldpaths))
1453 return i;
1454
1455 if ((fp = fopen(fname, "r")) == NULL)
1456 return i;
1457
1458 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1459 if ((p = strrchr(path, '\r')) != NULL)
1460 *p = 0;
1461 if ((p = strchr(path, '\n')) != NULL)
1462 *p = 0;
1463 #ifdef __linux__
1464 /* recursive includes of the same file will make this segfault. */
1465 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1466 glob64_t gl;
1467 size_t x;
1468 char gpath[__PAX_UTILS_PATH_MAX];
1469
1470 memset(gpath, 0, sizeof(gpath));
1471
1472 if (path[8] != '/')
1473 snprintf(gpath, sizeof(gpath), "/etc/%s", &path[8]);
1474 else
1475 strncpy(gpath, &path[8], sizeof(gpath));
1476
1477 if ((glob64(gpath, 0, NULL, &gl)) == 0) {
1478 for (x = 0; x < gl.gl_pathc; ++x) {
1479 /* try to avoid direct loops */
1480 if (strcmp(gl.gl_pathv[x], fname) == 0)
1481 continue;
1482 i = load_ld_cache_config(i, gl.gl_pathv[x]);
1483 if (i + 1 >= ARRAY_SIZE(ldpaths)) {
1484 globfree64(&gl);
1485 return i;
1486 }
1487 }
1488 globfree64 (&gl);
1489 continue;
1490 }
1491 }
1492 #endif
1493 if (*path != '/')
1494 continue;
1495
1496 ldpaths[i++] = xstrdup(path);
1497
1498 if (i + 1 == ARRAY_SIZE(ldpaths))
1499 break;
1500 }
1501 ldpaths[i] = NULL;
1502
1503 fclose(fp);
1504 return i;
1505 }
1506
1507 #elif defined(__FreeBSD__) || (__DragonFly__)
1508
1509 static int load_ld_cache_config(int i, const char *fname)
1510 {
1511 FILE *fp = NULL;
1512 char *b = NULL, *p;
1513 struct elfhints_hdr hdr;
1514
1515 if (i + 1 == ARRAY_SIZE(ldpaths))
1516 return i;
1517
1518 if ((fp = fopen(fname, "r")) == NULL)
1519 return i;
1520
1521 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1522 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1523 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1524 {
1525 fclose(fp);
1526 return i;
1527 }
1528
1529 b = xmalloc(hdr.dirlistlen + 1);
1530 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1531 fclose(fp);
1532 free(b);
1533 return i;
1534 }
1535
1536 while ((p = strsep(&b, ":"))) {
1537 if (*p == '\0') continue;
1538 ldpaths[i++] = xstrdup(p);
1539
1540 if (i + 1 == ARRAY_SIZE(ldpaths))
1541 break;
1542 }
1543 ldpaths[i] = NULL;
1544
1545 free(b);
1546 fclose(fp);
1547 return i;
1548 }
1549
1550 #else
1551 #ifdef __ELF__
1552 #warning Cache config support not implemented for your target
1553 #endif
1554 static int load_ld_cache_config(int i, const char *fname)
1555 {
1556 memset(ldpaths, 0x00, sizeof(ldpaths));
1557 return 0;
1558 }
1559 #endif
1560
1561 /* scan /etc/ld.so.conf for paths */
1562 static void scanelf_ldpath(void)
1563 {
1564 char scan_l, scan_ul, scan_ull;
1565 int i = 0;
1566
1567 if (!ldpaths[0])
1568 err("Unable to load any paths from ld.so.conf");
1569
1570 scan_l = scan_ul = scan_ull = 0;
1571
1572 while (ldpaths[i]) {
1573 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1574 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1575 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1576 scanelf_dir(ldpaths[i]);
1577 ++i;
1578 }
1579
1580 if (!scan_l) scanelf_dir("/lib");
1581 if (!scan_ul) scanelf_dir("/usr/lib");
1582 if (!scan_ull) scanelf_dir("/usr/local/lib");
1583 }
1584
1585 /* scan env PATH for paths */
1586 static void scanelf_envpath(void)
1587 {
1588 char *path, *p;
1589
1590 path = getenv("PATH");
1591 if (!path)
1592 err("PATH is not set in your env !");
1593 path = xstrdup(path);
1594
1595 while ((p = strrchr(path, ':')) != NULL) {
1596 scanelf_dir(p + 1);
1597 *p = 0;
1598 }
1599
1600 free(path);
1601 }
1602
1603 /* usage / invocation handling functions */ /* Free Flags: c d j u w C G H J K P Q U W */
1604 #define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZBhV"
1605 #define a_argument required_argument
1606 static struct option const long_opts[] = {
1607 {"path", no_argument, NULL, 'p'},
1608 {"ldpath", no_argument, NULL, 'l'},
1609 {"recursive", no_argument, NULL, 'R'},
1610 {"mount", no_argument, NULL, 'm'},
1611 {"symlink", no_argument, NULL, 'y'},
1612 {"archives", no_argument, NULL, 'A'},
1613 {"ldcache", no_argument, NULL, 'L'},
1614 {"fix", no_argument, NULL, 'X'},
1615 {"setpax", a_argument, NULL, 'z'},
1616 {"pax", no_argument, NULL, 'x'},
1617 {"header", no_argument, NULL, 'e'},
1618 {"textrel", no_argument, NULL, 't'},
1619 {"rpath", no_argument, NULL, 'r'},
1620 {"needed", no_argument, NULL, 'n'},
1621 {"interp", no_argument, NULL, 'i'},
1622 {"bind", no_argument, NULL, 'b'},
1623 {"soname", no_argument, NULL, 'S'},
1624 {"symbol", a_argument, NULL, 's'},
1625 {"section", a_argument, NULL, 'k'},
1626 {"lib", a_argument, NULL, 'N'},
1627 {"gmatch", no_argument, NULL, 'g'},
1628 {"textrels", no_argument, NULL, 'T'},
1629 {"etype", a_argument, NULL, 'E'},
1630 {"bits", a_argument, NULL, 'M'},
1631 {"endian", no_argument, NULL, 'D'},
1632 {"osabi", no_argument, NULL, 'I'},
1633 {"eabi", no_argument, NULL, 'Y'},
1634 {"perms", a_argument, NULL, 'O'},
1635 {"size", no_argument, NULL, 'Z'},
1636 {"all", no_argument, NULL, 'a'},
1637 {"quiet", no_argument, NULL, 'q'},
1638 {"verbose", no_argument, NULL, 'v'},
1639 {"format", a_argument, NULL, 'F'},
1640 {"from", a_argument, NULL, 'f'},
1641 {"file", a_argument, NULL, 'o'},
1642 {"nobanner", no_argument, NULL, 'B'},
1643 {"help", no_argument, NULL, 'h'},
1644 {"version", no_argument, NULL, 'V'},
1645 {NULL, no_argument, NULL, 0x0}
1646 };
1647
1648 static const char *opts_help[] = {
1649 "Scan all directories in PATH environment",
1650 "Scan all directories in /etc/ld.so.conf",
1651 "Scan directories recursively",
1652 "Don't recursively cross mount points",
1653 "Don't scan symlinks",
1654 "Scan archives (.a files)",
1655 "Utilize ld.so.cache information (use with -r/-n)",
1656 "Try and 'fix' bad things (use with -r/-e)",
1657 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1658 "Print PaX markings",
1659 "Print GNU_STACK/PT_LOAD markings",
1660 "Print TEXTREL information",
1661 "Print RPATH information",
1662 "Print NEEDED information",
1663 "Print INTERP information",
1664 "Print BIND information",
1665 "Print SONAME information",
1666 "Find a specified symbol",
1667 "Find a specified section",
1668 "Find a specified library",
1669 "Use strncmp to match libraries. (use with -N)",
1670 "Locate cause of TEXTREL",
1671 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1672 "Print only ELF files matching numeric bits",
1673 "Print Endianness",
1674 "Print OSABI",
1675 "Print EABI (EM_ARM Only)",
1676 "Print only ELF files matching octal permissions",
1677 "Print ELF file size",
1678 "Print all scanned info (-x -e -t -r -b)\n",
1679 "Only output 'bad' things",
1680 "Be verbose (can be specified more than once)",
1681 "Use specified format for output",
1682 "Read input stream from a filename",
1683 "Write output stream to a filename",
1684 "Don't display the header",
1685 "Print this help and exit",
1686 "Print version and exit",
1687 NULL
1688 };
1689
1690 /* display usage and exit */
1691 static void usage(int status)
1692 {
1693 unsigned long i;
1694 printf("* Scan ELF binaries for stuff\n\n"
1695 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1696 printf("Options: -[%s]\n", PARSE_FLAGS);
1697 for (i = 0; long_opts[i].name; ++i)
1698 if (long_opts[i].has_arg == no_argument)
1699 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
1700 long_opts[i].name, opts_help[i]);
1701 else
1702 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
1703 long_opts[i].name, opts_help[i]);
1704
1705 puts("\nFor more information, see the scanelf(1) manpage");
1706 exit(status);
1707 }
1708
1709 /* parse command line arguments and preform needed actions */
1710 #define do_pax_state(option, flag) \
1711 if (islower(option)) { \
1712 flags &= ~PF_##flag; \
1713 flags |= PF_NO##flag; \
1714 } else { \
1715 flags &= ~PF_NO##flag; \
1716 flags |= PF_##flag; \
1717 }
1718 static int parseargs(int argc, char *argv[])
1719 {
1720 int i;
1721 const char *from_file = NULL;
1722 int ret = 0;
1723
1724 opterr = 0;
1725 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1726 switch (i) {
1727
1728 case 'V':
1729 printf("pax-utils-%s: %s compiled %s\n%s\n"
1730 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
1731 VERSION, __FILE__, __DATE__, rcsid, argv0);
1732 exit(EXIT_SUCCESS);
1733 break;
1734 case 'h': usage(EXIT_SUCCESS); break;
1735 case 'f':
1736 if (from_file) warn("You prob don't want to specify -f twice");
1737 from_file = optarg;
1738 break;
1739 case 'E':
1740 strncpy(match_etypes, optarg, sizeof(match_etypes));
1741 break;
1742 case 'M':
1743 match_bits = atoi(optarg);
1744 if (match_bits == 0) {
1745 if (strcmp(optarg, "ELFCLASS32") == 0)
1746 match_bits = 32;
1747 if (strcmp(optarg, "ELFCLASS64") == 0)
1748 match_bits = 64;
1749 }
1750 break;
1751 case 'O':
1752 if (sscanf(optarg, "%o", &match_perms) == (-1))
1753 match_bits = 0;
1754 break;
1755 case 'o': {
1756 if (freopen(optarg, "w", stdout) == NULL)
1757 err("Could not open output stream '%s': %s", optarg, strerror(errno));
1758 break;
1759 }
1760 case 'k':
1761 if (find_section) warn("You prob don't want to specify -k twice");
1762 find_section = optarg;
1763 break;
1764 case 's': {
1765 if (find_sym) warn("You prob don't want to specify -s twice");
1766 find_sym = optarg;
1767 versioned_symname = xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1768 sprintf(versioned_symname, "%s@", find_sym);
1769 break;
1770 }
1771 case 'N': {
1772 if (find_lib) warn("You prob don't want to specify -N twice");
1773 find_lib = optarg;
1774 break;
1775 }
1776
1777 case 'F': {
1778 if (out_format) warn("You prob don't want to specify -F twice");
1779 out_format = optarg;
1780 break;
1781 }
1782 case 'z': {
1783 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1784 size_t x;
1785
1786 for (x = 0; x < strlen(optarg); x++) {
1787 switch (optarg[x]) {
1788 case 'p':
1789 case 'P':
1790 do_pax_state(optarg[x], PAGEEXEC);
1791 break;
1792 case 's':
1793 case 'S':
1794 do_pax_state(optarg[x], SEGMEXEC);
1795 break;
1796 case 'm':
1797 case 'M':
1798 do_pax_state(optarg[x], MPROTECT);
1799 break;
1800 case 'e':
1801 case 'E':
1802 do_pax_state(optarg[x], EMUTRAMP);
1803 break;
1804 case 'r':
1805 case 'R':
1806 do_pax_state(optarg[x], RANDMMAP);
1807 break;
1808 case 'x':
1809 case 'X':
1810 do_pax_state(optarg[x], RANDEXEC);
1811 break;
1812 default:
1813 break;
1814 }
1815 }
1816 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
1817 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
1818 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
1819 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
1820 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1821 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1822 setpax = flags;
1823 break;
1824 }
1825 case 'Z': show_size = 1; break;
1826 case 'g': g_match = 1; break;
1827 case 'L': use_ldcache = 1; break;
1828 case 'y': scan_symlink = 0; break;
1829 case 'A': scan_archives = 1; break;
1830 case 'B': show_banner = 0; break;
1831 case 'l': scan_ldpath = 1; break;
1832 case 'p': scan_envpath = 1; break;
1833 case 'R': dir_recurse = 1; break;
1834 case 'm': dir_crossmount = 0; break;
1835 case 'X': ++fix_elf; break;
1836 case 'x': show_pax = 1; break;
1837 case 'e': show_phdr = 1; break;
1838 case 't': show_textrel = 1; break;
1839 case 'r': show_rpath = 1; break;
1840 case 'n': show_needed = 1; break;
1841 case 'i': show_interp = 1; break;
1842 case 'b': show_bind = 1; break;
1843 case 'S': show_soname = 1; break;
1844 case 'T': show_textrels = 1; break;
1845 case 'q': be_quiet = 1; break;
1846 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1847 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1848 case 'D': show_endian = 1; break;
1849 case 'I': show_osabi = 1; break;
1850 case 'Y': show_eabi = 1; break;
1851 case ':':
1852 err("Option '%c' is missing parameter", optopt);
1853 case '?':
1854 err("Unknown option '%c' or argument missing", optopt);
1855 default:
1856 err("Unhandled option '%c'; please report this", i);
1857 }
1858 }
1859 if (show_textrels && be_verbose) {
1860 if (which("objdump") != NULL)
1861 has_objdump = 1;
1862 }
1863 /* let the format option override all other options */
1864 if (out_format) {
1865 show_pax = show_phdr = show_textrel = show_rpath = \
1866 show_needed = show_interp = show_bind = show_soname = \
1867 show_textrels = show_perms = show_endian = show_size = \
1868 show_osabi = show_eabi = 0;
1869 for (i = 0; out_format[i]; ++i) {
1870 if (!IS_MODIFIER(out_format[i])) continue;
1871
1872 switch (out_format[++i]) {
1873 case '+': break;
1874 case '%': break;
1875 case '#': break;
1876 case 'F': break;
1877 case 'p': break;
1878 case 'f': break;
1879 case 'k': break;
1880 case 's': break;
1881 case 'N': break;
1882 case 'o': break;
1883 case 'a': break;
1884 case 'M': break;
1885 case 'Z': show_size = 1; break;
1886 case 'D': show_endian = 1; break;
1887 case 'I': show_osabi = 1; break;
1888 case 'Y': show_eabi = 1; break;
1889 case 'O': show_perms = 1; break;
1890 case 'x': show_pax = 1; break;
1891 case 'e': show_phdr = 1; break;
1892 case 't': show_textrel = 1; break;
1893 case 'r': show_rpath = 1; break;
1894 case 'n': show_needed = 1; break;
1895 case 'i': show_interp = 1; break;
1896 case 'b': show_bind = 1; break;
1897 case 'S': show_soname = 1; break;
1898 case 'T': show_textrels = 1; break;
1899 default:
1900 err("Invalid format specifier '%c' (byte %i)",
1901 out_format[i], i+1);
1902 }
1903 }
1904
1905 /* construct our default format */
1906 } else {
1907 size_t fmt_len = 30;
1908 out_format = xmalloc(sizeof(char) * fmt_len);
1909 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1910 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
1911 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
1912 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
1913 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
1914 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
1915 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1916 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1917 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1918 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1919 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1920 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1921 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1922 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1923 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1924 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
1925 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1926 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1927 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1928 }
1929 if (be_verbose > 2) printf("Format: %s\n", out_format);
1930
1931 /* now lets actually do the scanning */
1932 if (scan_ldpath || use_ldcache)
1933 load_ld_cache_config(0, __PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1934 if (scan_ldpath) scanelf_ldpath();
1935 if (scan_envpath) scanelf_envpath();
1936 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
1937 from_file = "-";
1938 if (from_file) {
1939 scanelf_from_file(from_file);
1940 from_file = *argv;
1941 }
1942 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1943 err("Nothing to scan !?");
1944 while (optind < argc) {
1945 search_path = argv[optind++];
1946 ret = scanelf_dir(search_path);
1947 }
1948
1949 /* clean up */
1950 free(versioned_symname);
1951 for (i = 0; ldpaths[i]; ++i)
1952 free(ldpaths[i]);
1953
1954 if (ldcache != 0)
1955 munmap(ldcache, ldcache_size);
1956 return ret;
1957 }
1958
1959 static char **get_split_env(const char *envvar)
1960 {
1961 const char *delims = " \t\n";
1962 char **envvals = NULL;
1963 char *env, *s;
1964 int nentry;
1965
1966 if ((env = getenv(envvar)) == NULL)
1967 return NULL;
1968
1969 env = xstrdup(env);
1970 if (env == NULL)
1971 return NULL;
1972
1973 s = strtok(env, delims);
1974 if (s == NULL) {
1975 free(env);
1976 return NULL;
1977 }
1978
1979 nentry = 0;
1980 while (s != NULL) {
1981 ++nentry;
1982 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
1983 envvals[nentry-1] = s;
1984 s = strtok(NULL, delims);
1985 }
1986 envvals[nentry] = NULL;
1987
1988 /* don't want to free(env) as it contains the memory that backs
1989 * the envvals array of strings */
1990 return envvals;
1991 }
1992
1993 static void parseenv(void)
1994 {
1995 qa_textrels = get_split_env("QA_TEXTRELS");
1996 qa_execstack = get_split_env("QA_EXECSTACK");
1997 qa_wx_load = get_split_env("QA_WX_LOAD");
1998 }
1999
2000 #ifdef __PAX_UTILS_CLEANUP
2001 static void cleanup(void)
2002 {
2003 free(out_format);
2004 free(qa_textrels);
2005 free(qa_execstack);
2006 free(qa_wx_load);
2007 }
2008 #endif
2009
2010 int main(int argc, char *argv[])
2011 {
2012 int ret;
2013 if (argc < 2)
2014 usage(EXIT_FAILURE);
2015 parseenv();
2016 ret = parseargs(argc, argv);
2017 fclose(stdout);
2018 #ifdef __PAX_UTILS_CLEANUP
2019 cleanup();
2020 warn("The calls to add/delete heap should be off:\n"
2021 "\t- 1 due to the out_buffer not being freed in scanelf_file()\n"
2022 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
2023 #endif
2024 return ret;
2025 }
2026
2027 /* Match filename against entries in matchlist, return TRUE
2028 * if the file is listed */
2029 static int file_matches_list(const char *filename, char **matchlist)
2030 {
2031 char **file;
2032 char *match;
2033 char buf[__PAX_UTILS_PATH_MAX];
2034
2035 if (matchlist == NULL)
2036 return 0;
2037
2038 for (file = matchlist; *file != NULL; file++) {
2039 if (search_path) {
2040 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2041 match = buf;
2042 } else {
2043 match = *file;
2044 }
2045 if (fnmatch(match, filename, 0) == 0)
2046 return 1;
2047 }
2048 return 0;
2049 }

  ViewVC Help
Powered by ViewVC 1.1.20