/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Contents of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log


Revision 1.275 - (show annotations) (download) (as text)
Tue Feb 24 06:58:39 2015 UTC (4 days, 8 hours ago) by vapier
Branch: MAIN
CVS Tags: HEAD
Changes since 1.274: +11 -3 lines
File MIME type: text/x-csrc
scanelf: handle corrupted hash chains that have infinite loops

1 /*
2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/scanelf.c,v 1.274 2015/02/22 02:27:39 vapier Exp $
5 *
6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */
9
10 static const char rcsid[] = "$Id: scanelf.c,v 1.274 2015/02/22 02:27:39 vapier Exp $";
11 const char argv0[] = "scanelf";
12
13 #include "paxinc.h"
14
15 #define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17 /* prototypes */
18 static int file_matches_list(const char *filename, char **matchlist);
19
20 /* variables to control behavior */
21 static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
22 static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
23 static char scan_ldpath = 0;
24 static char scan_envpath = 0;
25 static char scan_symlink = 1;
26 static char scan_archives = 0;
27 static char dir_recurse = 0;
28 static char dir_crossmount = 1;
29 static char show_pax = 0;
30 static char show_perms = 0;
31 static char show_size = 0;
32 static char show_phdr = 0;
33 static char show_textrel = 0;
34 static char show_rpath = 0;
35 static char show_needed = 0;
36 static char show_interp = 0;
37 static char show_bind = 0;
38 static char show_soname = 0;
39 static char show_textrels = 0;
40 static char show_banner = 1;
41 static char show_endian = 0;
42 static char show_osabi = 0;
43 static char show_eabi = 0;
44 static char be_quiet = 0;
45 static char be_verbose = 0;
46 static char be_wewy_wewy_quiet = 0;
47 static char be_semi_verbose = 0;
48 static char *find_sym = NULL;
49 static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50 static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
51 static char *find_lib = NULL;
52 static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53 static char *find_section = NULL;
54 static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
55 static char *out_format = NULL;
56 static char *search_path = NULL;
57 static char fix_elf = 0;
58 static char g_match = 0;
59 static char use_ldcache = 0;
60 static char use_ldpath = 0;
61
62 static char **qa_textrels = NULL;
63 static char **qa_execstack = NULL;
64 static char **qa_wx_load = NULL;
65 static int root_fd = AT_FDCWD;
66
67 static int match_bits = 0;
68 static unsigned int match_perms = 0;
69 static void *ldcache = NULL;
70 static size_t ldcache_size = 0;
71 static unsigned long setpax = 0UL;
72
73 static const char *objdump;
74
75 /* Find the path to a file by name. Note: we do not currently handle the
76 * empty path element correctly (should behave by searching $PWD). */
77 static const char *which(const char *fname, const char *envvar)
78 {
79 size_t path_len, fname_len;
80 const char *env_path;
81 char *path, *p, *ep;
82
83 p = getenv(envvar);
84 if (p)
85 return p;
86
87 env_path = getenv("PATH");
88 if (!env_path)
89 return NULL;
90
91 /* Create a copy of the $PATH that we can safely modify.
92 * Make it a little bigger so we can append "/fname".
93 * We do this twice -- once for a perm copy, and once for
94 * room at the end of the last element. */
95 path_len = strlen(env_path);
96 fname_len = strlen(fname);
97 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
98 memcpy(path, env_path, path_len + 1);
99
100 p = path + path_len + 1 + fname_len + 1;
101 *p = '/';
102 memcpy(p + 1, fname, fname_len + 1);
103
104 /* Repoint fname to the copy in the env string as it has
105 * the leading slash which we can include in a single memcpy.
106 * Increase the fname len to include the '/' and '\0'. */
107 fname = p;
108 fname_len += 2;
109
110 p = path;
111 while (p) {
112 ep = strchr(p, ':');
113 /* Append the /foo path to the current element. */
114 if (ep)
115 memcpy(ep, fname, fname_len);
116 else
117 memcpy(path + path_len, fname, fname_len);
118
119 if (access(p, R_OK) != -1)
120 return p;
121
122 p = ep;
123 if (ep) {
124 /* If not the last element, restore the chunk we clobbered. */
125 size_t offset = ep - path;
126 size_t restore = min(path_len - offset, fname_len);
127 memcpy(ep, env_path + offset, restore);
128 ++p;
129 }
130 }
131
132 free(path);
133 return NULL;
134 }
135
136 static FILE *fopenat_r(int dir_fd, const char *path)
137 {
138 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
139 if (fd == -1)
140 return NULL;
141 return fdopen(fd, "re");
142 }
143
144 static const char *root_rel_path(const char *path)
145 {
146 /*
147 * openat() will ignore the dirfd if path starts with
148 * a /, so consume all of that noise
149 *
150 * XXX: we don't handle relative paths like ../ that
151 * break out of the --root option, but for now, just
152 * don't do that :P.
153 */
154 if (root_fd != AT_FDCWD) {
155 while (*path == '/')
156 ++path;
157 if (*path == '\0')
158 path = ".";
159 }
160
161 return path;
162 }
163
164 /* sub-funcs for scanelf_fileat() */
165 static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
166 {
167 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
168
169 /* debug sections */
170 void *symtab = elf_findsecbyname(elf, ".symtab");
171 void *strtab = elf_findsecbyname(elf, ".strtab");
172 /* runtime sections */
173 void *dynsym = elf_findsecbyname(elf, ".dynsym");
174 void *dynstr = elf_findsecbyname(elf, ".dynstr");
175
176 /*
177 * If the sections are marked NOBITS, then they don't exist, so we just
178 * skip them. This let's us work sanely with splitdebug ELFs (rather
179 * than spewing a lot of "corrupt ELF" messages later on). In malformed
180 * ELFs, the section might be wrongly set to NOBITS, but screw em.
181 *
182 * We need to make sure the debug/runtime sym/str sets are used together
183 * as they are generated in sync. Trying to mix them won't work.
184 */
185 #define GET_SYMTABS(B) \
186 if (elf->elf_class == ELFCLASS ## B) { \
187 Elf ## B ## _Shdr *esymtab = symtab; \
188 Elf ## B ## _Shdr *estrtab = strtab; \
189 Elf ## B ## _Shdr *edynsym = dynsym; \
190 Elf ## B ## _Shdr *edynstr = dynstr; \
191 \
192 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
193 symtab = NULL; \
194 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
195 dynsym = NULL; \
196 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
197 strtab = NULL; \
198 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
199 dynstr = NULL; \
200 \
201 /* Use the set with more symbols if both exist. */ \
202 if (symtab && dynsym && strtab && dynstr) { \
203 if (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) \
204 goto debug##B; \
205 else \
206 goto runtime##B; \
207 } else if (symtab && strtab) { \
208 debug##B: \
209 *sym = symtab; \
210 *str = strtab; \
211 return; \
212 } else if (dynsym && dynstr) { \
213 runtime##B: \
214 *sym = dynsym; \
215 *str = dynstr; \
216 return; \
217 } else { \
218 *sym = *str = NULL; \
219 } \
220 }
221 GET_SYMTABS(32)
222 GET_SYMTABS(64)
223
224 if (*sym && *str)
225 return;
226
227 /*
228 * damn, they're really going to make us work for it huh?
229 * reconstruct the section header info out of the dynamic
230 * tags so we can see what symbols this guy uses at runtime.
231 */
232 if (!elf->phdr)
233 return;
234 #define GET_SYMTABS_DT(B) \
235 if (elf->elf_class == ELFCLASS ## B) { \
236 size_t i; \
237 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
238 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
239 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
240 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
241 Elf ## B ## _Dyn *dyn; \
242 Elf ## B ## _Off offset; \
243 \
244 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
245 vsym = vstr = vhash = vgnu_hash = 0; \
246 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
247 memset(&str_shdr, 0, sizeof(str_shdr)); \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
250 continue; \
251 \
252 offset = EGET(phdr[i].p_offset); \
253 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
254 continue; \
255 \
256 dyn = DYN ## B (elf->vdata + offset); \
257 while (EGET(dyn->d_tag) != DT_NULL) { \
258 switch (EGET(dyn->d_tag)) { \
259 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
260 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
261 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
262 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
263 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
264 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
265 } \
266 ++dyn; \
267 } \
268 if (vsym && vstr) \
269 break; \
270 } \
271 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
272 return; \
273 \
274 /* calc offset into the ELF by finding the load addr of the syms */ \
275 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
276 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
277 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
278 offset = EGET(phdr[i].p_offset); \
279 \
280 if (EGET(phdr[i].p_type) != PT_LOAD) \
281 continue; \
282 \
283 if (vhash >= vaddr && vhash < vaddr + filesz) { \
284 /* Scan the hash table to see how many entries we have */ \
285 Elf32_Word max_sym_idx = 0; \
286 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
287 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
288 Elf32_Word nchains = EGET(hashtbl[1]); \
289 Elf32_Word *buckets = &hashtbl[2]; \
290 Elf32_Word *chains = &buckets[nbuckets]; \
291 Elf32_Word sym_idx; \
292 Elf32_Word chained; \
293 \
294 for (b = 0; b < nbuckets; ++b) { \
295 if (!buckets[b]) \
296 continue; \
297 for (sym_idx = buckets[b], chained = 0; \
298 sym_idx < nchains && sym_idx && chained <= nchains; \
299 sym_idx = chains[sym_idx], ++chained) { \
300 if (max_sym_idx < sym_idx) \
301 max_sym_idx = sym_idx; \
302 } \
303 if (chained > nchains) { \
304 warnf("corrupt ELF bucket"); \
305 break; \
306 } \
307 } \
308 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
309 } \
310 \
311 if (vsym >= vaddr && vsym < vaddr + filesz) { \
312 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
313 *sym = &sym_shdr; \
314 } \
315 \
316 if (vstr >= vaddr && vstr < vaddr + filesz) { \
317 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
318 *str = &str_shdr; \
319 } \
320 } \
321 }
322 GET_SYMTABS_DT(32)
323 GET_SYMTABS_DT(64)
324 }
325
326 static char *scanelf_file_pax(elfobj *elf, char *found_pax)
327 {
328 static char ret[7];
329 unsigned long i, shown;
330
331 if (!show_pax) return NULL;
332
333 shown = 0;
334 memset(&ret, 0, sizeof(ret));
335
336 if (elf->phdr) {
337 #define SHOW_PAX(B) \
338 if (elf->elf_class == ELFCLASS ## B) { \
339 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
340 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
341 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
342 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
343 continue; \
344 if (fix_elf && setpax) { \
345 /* set the paxctl flags */ \
346 ESET(phdr[i].p_flags, setpax); \
347 } \
348 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
349 continue; \
350 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
351 *found_pax = 1; \
352 ++shown; \
353 break; \
354 } \
355 }
356 SHOW_PAX(32)
357 SHOW_PAX(64)
358 }
359
360 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
361 * was found. This is known to break ELFs on glibc systems,
362 * and mainline PaX has deprecated use of this for a long time.
363 * We could support changing PT_GNU_STACK, but that doesn't
364 * seem like it's worth the effort. #411919
365 */
366
367 /* fall back to EI_PAX if no PT_PAX was found */
368 if (!*ret) {
369 static char *paxflags;
370 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
371 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
372 *found_pax = 1;
373 return (be_wewy_wewy_quiet ? NULL : paxflags);
374 }
375 strncpy(ret, paxflags, sizeof(ret));
376 }
377
378 if (be_wewy_wewy_quiet || (be_quiet && !shown))
379 return NULL;
380 else
381 return ret;
382 }
383
384 static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
385 {
386 static char ret[12];
387 char *found;
388 unsigned long i, shown, multi_stack, multi_relro, multi_load;
389
390 if (!show_phdr) return NULL;
391
392 memcpy(ret, "--- --- ---\0", 12);
393
394 shown = 0;
395 multi_stack = multi_relro = multi_load = 0;
396
397 #define NOTE_GNU_STACK ".note.GNU-stack"
398 #define SHOW_PHDR(B) \
399 if (elf->elf_class == ELFCLASS ## B) { \
400 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
401 Elf ## B ## _Off offset; \
402 uint32_t flags, check_flags; \
403 if (elf->phdr != NULL) { \
404 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
405 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
406 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
407 if (multi_stack++) \
408 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
409 if (file_matches_list(elf->filename, qa_execstack)) \
410 continue; \
411 found = found_phdr; \
412 offset = 0; \
413 check_flags = PF_X; \
414 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
415 if (multi_relro++) \
416 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
417 found = found_relro; \
418 offset = 4; \
419 check_flags = PF_X; \
420 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
421 if (file_matches_list(elf->filename, qa_wx_load)) \
422 continue; \
423 found = found_load; \
424 offset = 8; \
425 check_flags = PF_W|PF_X; \
426 } else \
427 continue; \
428 flags = EGET(phdr[i].p_flags); \
429 if (be_quiet && ((flags & check_flags) != check_flags)) \
430 continue; \
431 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
432 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
433 ret[3] = ret[7] = '!'; \
434 flags = EGET(phdr[i].p_flags); \
435 } \
436 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
437 *found = 1; \
438 ++shown; \
439 } \
440 } else if (elf->shdr != NULL) { \
441 /* no program headers which means this is prob an object file */ \
442 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
443 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
444 if ((void*)strtbl > elf->data_end) \
445 goto skip_this_shdr##B; \
446 /* let's flag -w/+x object files since the final ELF will most likely \
447 * need write access to the stack (who doesn't !?). so the combined \
448 * output will bring in +w automatically and that's bad. \
449 */ \
450 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
451 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
452 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
453 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
454 if (offset >= elf->len - sizeof(NOTE_GNU_STACK)) \
455 continue; \
456 if (!strcmp(elf->data + offset, NOTE_GNU_STACK)) { \
457 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
458 flags = EGET(shdr[i].sh_flags); \
459 if (be_quiet && ((flags & check_flags) != check_flags)) \
460 continue; \
461 ++*found_phdr; \
462 shown = 1; \
463 if (flags & SHF_WRITE) ret[0] = 'W'; \
464 if (flags & SHF_ALLOC) ret[1] = 'A'; \
465 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
466 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
467 break; \
468 } \
469 } \
470 skip_this_shdr##B: \
471 if (!multi_stack) { \
472 if (file_matches_list(elf->filename, qa_execstack)) \
473 return NULL; \
474 *found_phdr = 1; \
475 shown = 1; \
476 memcpy(ret, "!WX", 3); \
477 } \
478 } \
479 }
480 SHOW_PHDR(32)
481 SHOW_PHDR(64)
482
483 if (be_wewy_wewy_quiet || (be_quiet && !shown))
484 return NULL;
485 else
486 return ret;
487 }
488
489 /*
490 * See if this ELF contains a DT_TEXTREL tag in any of its
491 * PT_DYNAMIC sections.
492 */
493 static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
494 {
495 static const char *ret = "TEXTREL";
496 unsigned long i;
497
498 if (!show_textrel && !show_textrels) return NULL;
499
500 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
501
502 if (elf->phdr) {
503 #define SHOW_TEXTREL(B) \
504 if (elf->elf_class == ELFCLASS ## B) { \
505 Elf ## B ## _Dyn *dyn; \
506 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
507 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
508 Elf ## B ## _Off offset; \
509 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
510 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
511 offset = EGET(phdr[i].p_offset); \
512 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
513 dyn = DYN ## B (elf->vdata + offset); \
514 while (EGET(dyn->d_tag) != DT_NULL) { \
515 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
516 *found_textrel = 1; \
517 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
518 return (be_wewy_wewy_quiet ? NULL : ret); \
519 } \
520 ++dyn; \
521 } \
522 } }
523 SHOW_TEXTREL(32)
524 SHOW_TEXTREL(64)
525 }
526
527 if (be_quiet || be_wewy_wewy_quiet)
528 return NULL;
529 else
530 return " - ";
531 }
532
533 /*
534 * Scan the .text section to see if there are any relocations in it.
535 * Should rewrite this to check PT_LOAD sections that are marked
536 * Executable rather than the section named '.text'.
537 */
538 static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
539 {
540 unsigned long s, r, rmax;
541 void *symtab_void, *strtab_void, *text_void;
542
543 if (!show_textrels) return NULL;
544
545 /* don't search for TEXTREL's if the ELF doesn't have any */
546 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
547 if (!*found_textrel) return NULL;
548
549 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
550 text_void = elf_findsecbyname(elf, ".text");
551
552 if (symtab_void && strtab_void && text_void && elf->shdr) {
553 #define SHOW_TEXTRELS(B) \
554 if (elf->elf_class == ELFCLASS ## B) { \
555 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
556 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
557 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
558 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
559 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
560 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
561 uint ## B ## _t memsz = EGET(text->sh_size); \
562 Elf ## B ## _Rel *rel; \
563 Elf ## B ## _Rela *rela; \
564 /* search the section headers for relocations */ \
565 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
566 uint32_t sh_type = EGET(shdr[s].sh_type); \
567 if (sh_type == SHT_REL) { \
568 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
569 rela = NULL; \
570 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
571 } else if (sh_type == SHT_RELA) { \
572 rel = NULL; \
573 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
574 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
575 } else \
576 continue; \
577 /* now see if any of the relocs are in the .text */ \
578 for (r = 0; r < rmax; ++r) { \
579 unsigned long sym_max; \
580 Elf ## B ## _Addr offset_tmp; \
581 Elf ## B ## _Sym *func; \
582 Elf ## B ## _Sym *sym; \
583 Elf ## B ## _Addr r_offset; \
584 uint ## B ## _t r_info; \
585 if (sh_type == SHT_REL) { \
586 r_offset = EGET(rel[r].r_offset); \
587 r_info = EGET(rel[r].r_info); \
588 } else { \
589 r_offset = EGET(rela[r].r_offset); \
590 r_info = EGET(rela[r].r_info); \
591 } \
592 /* make sure this relocation is inside of the .text */ \
593 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
594 if (be_verbose <= 2) continue; \
595 } else \
596 *found_textrels = 1; \
597 /* locate this relocation symbol name */ \
598 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
599 if ((void*)sym > elf->data_end) { \
600 warn("%s: corrupt ELF symbol", elf->filename); \
601 continue; \
602 } \
603 sym_max = ELF ## B ## _R_SYM(r_info); \
604 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
605 sym += sym_max; \
606 else \
607 sym = NULL; \
608 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
609 /* show the raw details about this reloc */ \
610 printf(" %s: ", elf->base_filename); \
611 if (sym && sym->st_name) \
612 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
613 else \
614 printf("(memory/data?)"); \
615 printf(" [0x%lX]", (unsigned long)r_offset); \
616 /* now try to find the closest symbol that this rel is probably in */ \
617 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
618 func = NULL; \
619 offset_tmp = 0; \
620 while (sym_max--) { \
621 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
622 func = sym; \
623 offset_tmp = EGET(sym->st_value); \
624 } \
625 ++sym; \
626 } \
627 printf(" in "); \
628 if (func && func->st_name) { \
629 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
630 if (r_offset > EGET(func->st_size)) \
631 printf("(optimized out: previous %s)", func_name); \
632 else \
633 printf("%s", func_name); \
634 } else \
635 printf("(optimized out)"); \
636 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
637 if (be_verbose && objdump) { \
638 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
639 char *sysbuf; \
640 size_t syslen; \
641 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
642 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
643 sysbuf = xmalloc(syslen); \
644 if (end_addr < r_offset) \
645 /* not uncommon when things are optimized out */ \
646 end_addr = r_offset + 0x100; \
647 snprintf(sysbuf, syslen, sysfmt, \
648 objdump, \
649 (unsigned long)offset_tmp, \
650 (unsigned long)end_addr, \
651 elf->filename, \
652 (unsigned long)r_offset); \
653 fflush(stdout); \
654 if (system(sysbuf)) {/* don't care */} \
655 fflush(stdout); \
656 free(sysbuf); \
657 } \
658 } \
659 } }
660 SHOW_TEXTRELS(32)
661 SHOW_TEXTRELS(64)
662 }
663 if (!*found_textrels)
664 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
665
666 return NULL;
667 }
668
669 static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
670 {
671 struct stat st;
672 switch (*item) {
673 case '/': break;
674 case '.':
675 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
676 break;
677 case ':':
678 case '\0':
679 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
680 break;
681 case '$':
682 if (fstat(elf->fd, &st) != -1)
683 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
684 warnf("Security problem with %s='%s' in %s with mode set of %o",
685 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
686 break;
687 default:
688 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
689 break;
690 }
691 if (fix_elf)
692 warnf("Note: RPATH has been automatically fixed, but this should be fixed in the package itself");
693 }
694 static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
695 {
696 unsigned long i;
697 char *rpath, *runpath, **r;
698 void *strtbl_void;
699
700 if (!show_rpath) return;
701
702 strtbl_void = elf_findsecbyname(elf, ".dynstr");
703 rpath = runpath = NULL;
704
705 if (elf->phdr && strtbl_void) {
706 #define SHOW_RPATH(B) \
707 if (elf->elf_class == ELFCLASS ## B) { \
708 Elf ## B ## _Dyn *dyn; \
709 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
710 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
711 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
712 Elf ## B ## _Off offset; \
713 Elf ## B ## _Xword word; \
714 /* Scan all the program headers */ \
715 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
716 /* Just scan dynamic headers */ \
717 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
718 offset = EGET(phdr[i].p_offset); \
719 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
720 /* Just scan dynamic RPATH/RUNPATH headers */ \
721 dyn = DYN ## B (elf->vdata + offset); \
722 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
723 if (word == DT_RPATH) { \
724 r = &rpath; \
725 } else if (word == DT_RUNPATH) { \
726 r = &runpath; \
727 } else { \
728 ++dyn; \
729 continue; \
730 } \
731 /* Verify the memory is somewhat sane */ \
732 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
733 if (offset < (Elf ## B ## _Off)elf->len) { \
734 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
735 *r = elf->data + offset; \
736 /* cache the length in case we need to nuke this section later on */ \
737 if (fix_elf) \
738 offset = strlen(*r); \
739 /* If quiet, don't output paths in ld.so.conf */ \
740 if (be_quiet) { \
741 size_t len; \
742 char *start, *end; \
743 /* note that we only 'chop' off leading known paths. */ \
744 /* since *r is read-only memory, we can only move the ptr forward. */ \
745 start = *r; \
746 /* scan each path in : delimited list */ \
747 while (start) { \
748 rpath_security_checks(elf, start, get_elfdtype(word)); \
749 end = strchr(start, ':'); \
750 len = (end ? abs(end - start) : strlen(start)); \
751 if (use_ldcache) { \
752 size_t n; \
753 const char *ldpath; \
754 array_for_each(ldpaths, n, ldpath) \
755 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
756 *r = end; \
757 /* corner case ... if RPATH reads "/usr/lib:", we want \
758 * to show ':' rather than '' */ \
759 if (end && end[1] != '\0') \
760 (*r)++; \
761 break; \
762 } \
763 } \
764 if (!*r || !end) \
765 break; \
766 else \
767 start = start + len + 1; \
768 } \
769 } \
770 if (*r) { \
771 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
772 /* just nuke it */ \
773 nuke_it##B: \
774 memset(*r, 0x00, offset); \
775 *r = NULL; \
776 ESET(dyn->d_tag, DT_DEBUG); \
777 ESET(dyn->d_un.d_ptr, 0); \
778 } else if (fix_elf) { \
779 /* try to clean "bad" paths */ \
780 size_t len, tmpdir_len; \
781 char *start, *end; \
782 const char *tmpdir; \
783 start = *r; \
784 tmpdir = (getenv("TMPDIR") ? : "."); \
785 tmpdir_len = strlen(tmpdir); \
786 while (1) { \
787 end = strchr(start, ':'); \
788 if (start == end) { \
789 eat_this_path##B: \
790 len = strlen(end); \
791 memmove(start, end+1, len); \
792 start[len-1] = '\0'; \
793 end = start - 1; \
794 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
795 if (!end) { \
796 if (start == *r) \
797 goto nuke_it##B; \
798 *--start = '\0'; \
799 } else \
800 goto eat_this_path##B; \
801 } \
802 if (!end) \
803 break; \
804 start = end + 1; \
805 } \
806 if (**r == '\0') \
807 goto nuke_it##B; \
808 } \
809 if (*r) \
810 *found_rpath = 1; \
811 } \
812 } \
813 ++dyn; \
814 } \
815 } }
816 SHOW_RPATH(32)
817 SHOW_RPATH(64)
818 }
819
820 if (be_wewy_wewy_quiet) return;
821
822 if (rpath && runpath) {
823 if (!strcmp(rpath, runpath)) {
824 xstrcat(ret, runpath, ret_len);
825 } else {
826 fprintf(stderr, "RPATH [%s] != RUNPATH [%s]\n", rpath, runpath);
827 xchrcat(ret, '{', ret_len);
828 xstrcat(ret, rpath, ret_len);
829 xchrcat(ret, ',', ret_len);
830 xstrcat(ret, runpath, ret_len);
831 xchrcat(ret, '}', ret_len);
832 }
833 } else if (rpath || runpath)
834 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
835 else if (!be_quiet)
836 xstrcat(ret, " - ", ret_len);
837 }
838
839 /* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
840 #define LDSO_CACHE_MAGIC "ld.so-"
841 #define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
842 #define LDSO_CACHE_VER "1.7.0"
843 #define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
844 #define FLAG_ANY -1
845 #define FLAG_TYPE_MASK 0x00ff
846 #define FLAG_LIBC4 0x0000
847 #define FLAG_ELF 0x0001
848 #define FLAG_ELF_LIBC5 0x0002
849 #define FLAG_ELF_LIBC6 0x0003
850 #define FLAG_REQUIRED_MASK 0xff00
851 #define FLAG_SPARC_LIB64 0x0100
852 #define FLAG_IA64_LIB64 0x0200
853 #define FLAG_X8664_LIB64 0x0300
854 #define FLAG_S390_LIB64 0x0400
855 #define FLAG_POWERPC_LIB64 0x0500
856 #define FLAG_MIPS64_LIBN32 0x0600
857 #define FLAG_MIPS64_LIBN64 0x0700
858 #define FLAG_X8664_LIBX32 0x0800
859 #define FLAG_ARM_LIBHF 0x0900
860 #define FLAG_AARCH64_LIB64 0x0a00
861
862 #if defined(__GLIBC__) || defined(__UCLIBC__)
863
864 static char *lookup_cache_lib(elfobj *elf, const char *fname)
865 {
866 int fd;
867 char *strs;
868 static char buf[__PAX_UTILS_PATH_MAX] = "";
869 const char *cachefile = root_rel_path("/etc/ld.so.cache");
870 struct stat st;
871
872 typedef struct {
873 char magic[LDSO_CACHE_MAGIC_LEN];
874 char version[LDSO_CACHE_VER_LEN];
875 int nlibs;
876 } header_t;
877 header_t *header;
878
879 typedef struct {
880 int flags;
881 int sooffset;
882 int liboffset;
883 } libentry_t;
884 libentry_t *libent;
885
886 if (fname == NULL)
887 return NULL;
888
889 if (ldcache == NULL) {
890 if (fstatat(root_fd, cachefile, &st, 0))
891 return NULL;
892
893 fd = openat(root_fd, cachefile, O_RDONLY);
894 if (fd == -1)
895 return NULL;
896
897 /* cache these values so we only map/unmap the cache file once */
898 ldcache_size = st.st_size;
899 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
900 close(fd);
901
902 if (ldcache == MAP_FAILED) {
903 ldcache = NULL;
904 return NULL;
905 }
906
907 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
908 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
909 {
910 munmap(ldcache, ldcache_size);
911 ldcache = NULL;
912 return NULL;
913 }
914 } else
915 header = ldcache;
916
917 libent = ldcache + sizeof(header_t);
918 strs = (char *) &libent[header->nlibs];
919
920 for (fd = 0; fd < header->nlibs; ++fd) {
921 /* This should be more fine grained, but for now we assume that
922 * diff arches will not be cached together, and we ignore the
923 * the different multilib mips cases.
924 */
925 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
926 continue;
927 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
928 continue;
929
930 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
931 continue;
932
933 /* Return first hit because that is how the ldso rolls */
934 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
935 break;
936 }
937
938 return buf;
939 }
940
941 #elif defined(__NetBSD__)
942 static char *lookup_cache_lib(elfobj *elf, const char *fname)
943 {
944 static char buf[__PAX_UTILS_PATH_MAX] = "";
945 static struct stat st;
946 size_t n;
947 char *ldpath;
948
949 array_for_each(ldpath, n, ldpath) {
950 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
951 continue; /* if the pathname is too long, or something went wrong, ignore */
952
953 if (stat(buf, &st) != 0)
954 continue; /* if the lib doesn't exist in *ldpath, look further */
955
956 /* NetBSD doesn't actually do sanity checks, it just loads the file
957 * and if that doesn't work, continues looking in other directories.
958 * This cannot easily be safely emulated, unfortunately. For now,
959 * just assume that if it exists, it's a valid library. */
960
961 return buf;
962 }
963
964 /* not found in any path */
965 return NULL;
966 }
967 #else
968 #ifdef __ELF__
969 #warning Cache support not implemented for your target
970 #endif
971 static char *lookup_cache_lib(elfobj *elf, const char *fname)
972 {
973 return NULL;
974 }
975 #endif
976
977 static char *lookup_config_lib(const char *fname)
978 {
979 static char buf[__PAX_UTILS_PATH_MAX] = "";
980 const char *ldpath;
981 size_t n;
982
983 array_for_each(ldpaths, n, ldpath) {
984 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
985 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
986 return buf;
987 }
988
989 return NULL;
990 }
991
992 static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
993 {
994 unsigned long i;
995 char *needed;
996 void *strtbl_void;
997 char *p;
998
999 /*
1000 * -n -> op==0 -> print all
1001 * -N -> op==1 -> print requested
1002 */
1003 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
1004 return NULL;
1005
1006 strtbl_void = elf_findsecbyname(elf, ".dynstr");
1007
1008 if (elf->phdr && strtbl_void) {
1009 #define SHOW_NEEDED(B) \
1010 if (elf->elf_class == ELFCLASS ## B) { \
1011 Elf ## B ## _Dyn *dyn; \
1012 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1013 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1014 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
1015 Elf ## B ## _Off offset; \
1016 size_t matched = 0; \
1017 /* Walk all the program headers to find the PT_DYNAMIC */ \
1018 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1019 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
1020 continue; \
1021 offset = EGET(phdr[i].p_offset); \
1022 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
1023 continue; \
1024 /* Walk all the dynamic tags to find NEEDED entries */ \
1025 dyn = DYN ## B (elf->vdata + offset); \
1026 while (EGET(dyn->d_tag) != DT_NULL) { \
1027 if (EGET(dyn->d_tag) == DT_NEEDED) { \
1028 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
1029 if (offset >= (Elf ## B ## _Off)elf->len) { \
1030 ++dyn; \
1031 continue; \
1032 } \
1033 needed = elf->data + offset; \
1034 if (op == 0) { \
1035 /* -n -> print all entries */ \
1036 if (!be_wewy_wewy_quiet) { \
1037 if (*found_needed) xchrcat(ret, ',', ret_len); \
1038 if (use_ldpath) { \
1039 if ((p = lookup_config_lib(needed)) != NULL) \
1040 needed = p; \
1041 } else if (use_ldcache) { \
1042 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
1043 needed = p; \
1044 } \
1045 xstrcat(ret, needed, ret_len); \
1046 } \
1047 *found_needed = 1; \
1048 } else { \
1049 /* -N -> print matching entries */ \
1050 size_t n; \
1051 const char *find_lib_name; \
1052 \
1053 array_for_each(find_lib_arr, n, find_lib_name) { \
1054 int invert = 1; \
1055 if (find_lib_name[0] == '!') \
1056 invert = 0, ++find_lib_name; \
1057 if (!strcmp(find_lib_name, needed) == invert) \
1058 ++matched; \
1059 } \
1060 \
1061 if (matched == array_cnt(find_lib_arr)) { \
1062 *found_lib = 1; \
1063 return (be_wewy_wewy_quiet ? NULL : find_lib); \
1064 } \
1065 } \
1066 } \
1067 ++dyn; \
1068 } \
1069 } }
1070 SHOW_NEEDED(32)
1071 SHOW_NEEDED(64)
1072 if (op == 0 && !*found_needed && be_verbose)
1073 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
1074 }
1075
1076 return NULL;
1077 }
1078 static char *scanelf_file_interp(elfobj *elf, char *found_interp)
1079 {
1080 uint64_t offset = 0;
1081
1082 if (!show_interp) return NULL;
1083
1084 if (elf->phdr) {
1085 /* Walk all the program headers to find the PT_INTERP */
1086 #define SHOW_PT_INTERP(B) \
1087 if (elf->elf_class == ELFCLASS ## B) { \
1088 size_t i; \
1089 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1090 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1091 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
1092 if (EGET(phdr[i].p_type) == PT_INTERP) { \
1093 offset = EGET(phdr[i].p_offset); \
1094 break; \
1095 } \
1096 } \
1097 }
1098 SHOW_PT_INTERP(32)
1099 SHOW_PT_INTERP(64)
1100 } else if (elf->shdr) {
1101 /* Use the section headers to find it */
1102 void *strtbl_void = elf_findsecbyname(elf, ".interp");
1103
1104 #define SHOW_INTERP(B) \
1105 if (elf->elf_class == ELFCLASS ## B) { \
1106 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
1107 offset = EGET(strtbl->sh_offset); \
1108 }
1109 if (strtbl_void) {
1110 SHOW_INTERP(32)
1111 SHOW_INTERP(64)
1112 }
1113 }
1114
1115 /* Validate the pointer even if we don't use it in output */
1116 if (offset && offset <= (uint64_t)elf->len) {
1117 char *interp = elf->data + offset;
1118
1119 /* If it isn't a C pointer, it's garbage */
1120 if (memchr(interp, 0, elf->len - offset)) {
1121 *found_interp = 1;
1122 if (!be_wewy_wewy_quiet)
1123 return interp;
1124 }
1125 }
1126
1127 return NULL;
1128 }
1129 static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
1130 {
1131 unsigned long i;
1132 struct stat s;
1133 bool dynamic = false;
1134
1135 if (!show_bind) return NULL;
1136 if (!elf->phdr) return NULL;
1137
1138 #define SHOW_BIND(B) \
1139 if (elf->elf_class == ELFCLASS ## B) { \
1140 Elf ## B ## _Dyn *dyn; \
1141 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1142 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1143 Elf ## B ## _Off offset; \
1144 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1145 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1146 dynamic = true; \
1147 offset = EGET(phdr[i].p_offset); \
1148 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
1149 dyn = DYN ## B (elf->vdata + offset); \
1150 while (EGET(dyn->d_tag) != DT_NULL) { \
1151 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
1152 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
1153 { \
1154 if (be_quiet) return NULL; \
1155 *found_bind = 1; \
1156 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
1157 } \
1158 ++dyn; \
1159 } \
1160 } \
1161 }
1162 SHOW_BIND(32)
1163 SHOW_BIND(64)
1164
1165 if (be_wewy_wewy_quiet) return NULL;
1166
1167 /* don't output anything if quiet mode and the ELF is static or not setuid */
1168 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
1169 return NULL;
1170 } else {
1171 *found_bind = 1;
1172 return dynamic ? "LAZY" : "STATIC";
1173 }
1174 }
1175 static char *scanelf_file_soname(elfobj *elf, char *found_soname)
1176 {
1177 unsigned long i;
1178 char *soname;
1179 void *strtbl_void;
1180
1181 if (!show_soname) return NULL;
1182
1183 strtbl_void = elf_findsecbyname(elf, ".dynstr");
1184
1185 if (elf->phdr && strtbl_void) {
1186 #define SHOW_SONAME(B) \
1187 if (elf->elf_class == ELFCLASS ## B) { \
1188 Elf ## B ## _Dyn *dyn; \
1189 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1190 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1191 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
1192 Elf ## B ## _Off offset; \
1193 /* only look for soname in shared objects */ \
1194 if (EGET(ehdr->e_type) != ET_DYN) \
1195 return NULL; \
1196 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1197 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1198 offset = EGET(phdr[i].p_offset); \
1199 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
1200 dyn = DYN ## B (elf->vdata + offset); \
1201 while (EGET(dyn->d_tag) != DT_NULL) { \
1202 if (EGET(dyn->d_tag) == DT_SONAME) { \
1203 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
1204 if (offset >= (Elf ## B ## _Off)elf->len) { \
1205 ++dyn; \
1206 continue; \
1207 } \
1208 soname = elf->data + offset; \
1209 *found_soname = 1; \
1210 return (be_wewy_wewy_quiet ? NULL : soname); \
1211 } \
1212 ++dyn; \
1213 } \
1214 } }
1215 SHOW_SONAME(32)
1216 SHOW_SONAME(64)
1217 }
1218
1219 return NULL;
1220 }
1221
1222 /*
1223 * We support the symbol form:
1224 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1225 * If the symbol name is empty, then all symbols are matched.
1226 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1227 * Do not rely on this output format at all.
1228 * Otherwise the symbol name is used to search (either regex or string compare).
1229 * If the first char of the symbol name is a plus ("+"), then only match
1230 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1231 * Putting modifiers in between the percent signs allows for more in depth
1232 * filters. There are groups of modifiers. If you don't specify a member
1233 * of a group, then all types in that group are matched. The current
1234 * groups and their types are:
1235 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1236 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1237 * STV group: STV_DEFAULT:p STV_INTERNAL:i STV_HIDDEN:h STV_PROTECTED:P
1238 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1239 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1240 * You can search for multiple symbols at once by seperating with a comma (",").
1241 *
1242 * Some examples:
1243 * ELFs with a weak function "foo":
1244 * scanelf -s %wf%foo <ELFs>
1245 * ELFs that define the symbol "main":
1246 * scanelf -s +main <ELFs>
1247 * scanelf -s %d%main <ELFs>
1248 * ELFs that refer to the undefined symbol "brk":
1249 * scanelf -s -brk <ELFs>
1250 * scanelf -s %u%brk <ELFs>
1251 * All global defined objects in an ELF:
1252 * scanelf -s %ogd% <ELF>
1253 */
1254 static void
1255 scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1256 unsigned int stt, unsigned int stb, unsigned int stv, unsigned int shn, unsigned long size)
1257 {
1258 const char *this_sym;
1259 size_t n;
1260
1261 array_for_each(find_sym_arr, n, this_sym) {
1262 bool inc_notype, inc_object, inc_func, inc_file,
1263 inc_local, inc_global, inc_weak,
1264 inc_visdef, inc_intern, inc_hidden, inc_prot,
1265 inc_def, inc_undef, inc_abs, inc_common;
1266
1267 /* symbol selection! */
1268 inc_notype = inc_object = inc_func = inc_file =
1269 inc_local = inc_global = inc_weak =
1270 inc_visdef = inc_intern = inc_hidden = inc_prot =
1271 inc_def = inc_undef = inc_abs = inc_common =
1272 (*this_sym != '%');
1273
1274 /* parse the contents of %...% */
1275 if (!inc_notype) {
1276 while (*(this_sym++)) {
1277 if (*this_sym == '%') {
1278 ++this_sym;
1279 break;
1280 }
1281 switch (*this_sym) {
1282 case 'n': inc_notype = true; break;
1283 case 'o': inc_object = true; break;
1284 case 'f': inc_func = true; break;
1285 case 'F': inc_file = true; break;
1286 case 'l': inc_local = true; break;
1287 case 'g': inc_global = true; break;
1288 case 'w': inc_weak = true; break;
1289 case 'p': inc_visdef = true; break;
1290 case 'i': inc_intern = true; break;
1291 case 'h': inc_hidden = true; break;
1292 case 'P': inc_prot = true; break;
1293 case 'd': inc_def = true; break;
1294 case 'u': inc_undef = true; break;
1295 case 'a': inc_abs = true; break;
1296 case 'c': inc_common = true; break;
1297 default: err("invalid symbol selector '%c'", *this_sym);
1298 }
1299 }
1300
1301 /* If no types are matched, not match all */
1302 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1303 inc_notype = inc_object = inc_func = inc_file = true;
1304 if (!inc_local && !inc_global && !inc_weak)
1305 inc_local = inc_global = inc_weak = true;
1306 if (!inc_visdef && !inc_intern && !inc_hidden && !inc_prot)
1307 inc_visdef = inc_intern = inc_hidden = inc_prot = true;
1308 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1309 inc_def = inc_undef = inc_abs = inc_common = true;
1310
1311 /* backwards compat for defined/undefined short hand */
1312 } else if (*this_sym == '+') {
1313 inc_undef = false;
1314 ++this_sym;
1315 } else if (*this_sym == '-') {
1316 inc_def = inc_abs = inc_common = false;
1317 ++this_sym;
1318 }
1319
1320 /* filter symbols */
1321 if ((!inc_notype && stt == STT_NOTYPE ) || \
1322 (!inc_object && stt == STT_OBJECT ) || \
1323 (!inc_func && stt == STT_FUNC ) || \
1324 (!inc_file && stt == STT_FILE ) || \
1325 (!inc_local && stb == STB_LOCAL ) || \
1326 (!inc_global && stb == STB_GLOBAL ) || \
1327 (!inc_weak && stb == STB_WEAK ) || \
1328 (!inc_visdef && stv == STV_DEFAULT ) || \
1329 (!inc_intern && stv == STV_INTERNAL ) || \
1330 (!inc_hidden && stv == STV_HIDDEN ) || \
1331 (!inc_prot && stv == STV_PROTECTED) || \
1332 (!inc_def && shn && shn < SHN_LORESERVE) || \
1333 (!inc_undef && shn == SHN_UNDEF ) || \
1334 (!inc_abs && shn == SHN_ABS ) || \
1335 (!inc_common && shn == SHN_COMMON ))
1336 continue;
1337
1338 if (*this_sym == '*') {
1339 /* a "*" symbol gets you debug output */
1340 printf("%s(%s) %5lX %-15s %-15s %-15s %-15s %s\n",
1341 ((*found_sym == 0) ? "\n\t" : "\t"),
1342 elf->base_filename,
1343 size,
1344 get_elfstttype(stt),
1345 get_elfstbtype(stb),
1346 get_elfstvtype(stv),
1347 get_elfshntype(shn),
1348 symname);
1349 goto matched;
1350
1351 } else {
1352 if (g_match) {
1353 /* regex match the symbol */
1354 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1355 continue;
1356
1357 } else if (*this_sym) {
1358 /* give empty symbols a "pass", else do a normal compare */
1359 const size_t len = strlen(this_sym);
1360 if (!(strncmp(this_sym, symname, len) == 0 &&
1361 /* Accept unversioned symbol names */
1362 (symname[len] == '\0' || symname[len] == '@')))
1363 continue;
1364 }
1365
1366 if (be_semi_verbose) {
1367 char buf[1024];
1368 snprintf(buf, sizeof(buf), "%lX %s %s",
1369 size,
1370 get_elfstttype(stt),
1371 this_sym);
1372 *ret = xstrdup(buf);
1373 } else {
1374 if (*ret) xchrcat(ret, ',', ret_len);
1375 xstrcat(ret, symname, ret_len);
1376 }
1377
1378 goto matched;
1379 }
1380 }
1381
1382 return;
1383
1384 matched:
1385 *found_sym = 1;
1386 }
1387
1388 static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
1389 {
1390 char *ret;
1391 void *symtab_void, *strtab_void;
1392
1393 if (!find_sym) return NULL;
1394 ret = NULL;
1395
1396 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
1397
1398 if (symtab_void && strtab_void) {
1399 #define FIND_SYM(B) \
1400 if (elf->elf_class == ELFCLASS ## B) { \
1401 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
1402 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
1403 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
1404 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
1405 char *symname; \
1406 size_t ret_len = 0; \
1407 if (cnt) \
1408 cnt = EGET(symtab->sh_size) / cnt; \
1409 for (i = 0; i < cnt; ++i) { \
1410 if ((void*)sym > elf->data_end) { \
1411 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1412 goto break_out; \
1413 } \
1414 if (sym->st_name) { \
1415 /* make sure the symbol name is in acceptable memory range */ \
1416 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
1417 if ((void*)symname > elf->data_end) { \
1418 warnf("%s: corrupt ELF symbols", elf->filename); \
1419 ++sym; \
1420 continue; \
1421 } \
1422 scanelf_match_symname(elf, found_sym, \
1423 &ret, &ret_len, symname, \
1424 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1425 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1426 ELF##B##_ST_VISIBILITY(EGET(sym->st_other)), \
1427 EGET(sym->st_shndx), \
1428 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1429 EGET(sym->st_size)); \
1430 } \
1431 ++sym; \
1432 } \
1433 }
1434 FIND_SYM(32)
1435 FIND_SYM(64)
1436 }
1437
1438 break_out:
1439 if (be_wewy_wewy_quiet) return NULL;
1440
1441 if (*find_sym != '*' && *found_sym)
1442 return ret;
1443 if (be_quiet)
1444 return NULL;
1445 else
1446 return " - ";
1447 }
1448
1449 static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1450 {
1451 if (!find_section)
1452 return NULL;
1453
1454 #define FIND_SECTION(B) \
1455 if (elf->elf_class == ELFCLASS ## B) { \
1456 size_t matched, n; \
1457 int invert; \
1458 const char *section_name; \
1459 Elf ## B ## _Shdr *section; \
1460 \
1461 matched = 0; \
1462 array_for_each(find_section_arr, n, section_name) { \
1463 invert = (*section_name == '!' ? 1 : 0); \
1464 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1465 if ((section == NULL && invert) || (section != NULL && !invert)) \
1466 ++matched; \
1467 } \
1468 \
1469 if (matched == array_cnt(find_section_arr)) \
1470 *found_section = 1; \
1471 }
1472 FIND_SECTION(32)
1473 FIND_SECTION(64)
1474
1475 if (be_wewy_wewy_quiet)
1476 return NULL;
1477
1478 if (*found_section)
1479 return find_section;
1480
1481 if (be_quiet)
1482 return NULL;
1483 else
1484 return " - ";
1485 }
1486
1487 /* scan an elf file and show all the fun stuff */
1488 #define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
1489 static int scanelf_elfobj(elfobj *elf)
1490 {
1491 unsigned long i;
1492 char found_pax, found_phdr, found_relro, found_load, found_textrel,
1493 found_rpath, found_needed, found_interp, found_bind, found_soname,
1494 found_sym, found_lib, found_file, found_textrels, found_section;
1495 static char *out_buffer = NULL;
1496 static size_t out_len;
1497
1498 found_pax = found_phdr = found_relro = found_load = found_textrel = \
1499 found_rpath = found_needed = found_interp = found_bind = found_soname = \
1500 found_sym = found_lib = found_file = found_textrels = found_section = 0;
1501
1502 if (be_verbose > 2)
1503 printf("%s: scanning file {%s,%s}\n", elf->filename,
1504 get_elfeitype(EI_CLASS, elf->elf_class),
1505 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
1506 else if (be_verbose > 1)
1507 printf("%s: scanning file\n", elf->filename);
1508
1509 /* init output buffer */
1510 if (!out_buffer) {
1511 out_len = sizeof(char) * 80;
1512 out_buffer = xmalloc(out_len);
1513 }
1514 *out_buffer = '\0';
1515
1516 /* show the header */
1517 if (!be_quiet && show_banner) {
1518 for (i = 0; out_format[i]; ++i) {
1519 if (!IS_MODIFIER(out_format[i])) continue;
1520
1521 switch (out_format[++i]) {
1522 case '+': break;
1523 case '%': break;
1524 case '#': break;
1525 case 'F':
1526 case 'p':
1527 case 'f': prints("FILE "); found_file = 1; break;
1528 case 'o': prints(" TYPE "); break;
1529 case 'x': prints(" PAX "); break;
1530 case 'e': prints("STK/REL/PTL "); break;
1531 case 't': prints("TEXTREL "); break;
1532 case 'r': prints("RPATH "); break;
1533 case 'M': prints("CLASS "); break;
1534 case 'l':
1535 case 'n': prints("NEEDED "); break;
1536 case 'i': prints("INTERP "); break;
1537 case 'b': prints("BIND "); break;
1538 case 'Z': prints("SIZE "); break;
1539 case 'S': prints("SONAME "); break;
1540 case 's': prints("SYM "); break;
1541 case 'N': prints("LIB "); break;
1542 case 'T': prints("TEXTRELS "); break;
1543 case 'k': prints("SECTION "); break;
1544 case 'a': prints("ARCH "); break;
1545 case 'I': prints("OSABI "); break;
1546 case 'Y': prints("EABI "); break;
1547 case 'O': prints("PERM "); break;
1548 case 'D': prints("ENDIAN "); break;
1549 default: warnf("'%c' has no title ?", out_format[i]);
1550 }
1551 }
1552 if (!found_file) prints("FILE ");
1553 prints("\n");
1554 found_file = 0;
1555 show_banner = 0;
1556 }
1557
1558 /* dump all the good stuff */
1559 for (i = 0; out_format[i]; ++i) {
1560 const char *out;
1561 const char *tmp;
1562 static char ubuf[sizeof(unsigned long)*2];
1563 if (!IS_MODIFIER(out_format[i])) {
1564 xchrcat(&out_buffer, out_format[i], &out_len);
1565 continue;
1566 }
1567
1568 out = NULL;
1569 be_wewy_wewy_quiet = (out_format[i] == '#');
1570 be_semi_verbose = (out_format[i] == '+');
1571 switch (out_format[++i]) {
1572 case '+':
1573 case '%':
1574 case '#':
1575 xchrcat(&out_buffer, out_format[i], &out_len); break;
1576 case 'F':
1577 found_file = 1;
1578 if (be_wewy_wewy_quiet) break;
1579 xstrcat(&out_buffer, elf->filename, &out_len);
1580 break;
1581 case 'p':
1582 found_file = 1;
1583 if (be_wewy_wewy_quiet) break;
1584 tmp = elf->filename;
1585 if (search_path) {
1586 ssize_t len_search = strlen(search_path);
1587 ssize_t len_file = strlen(elf->filename);
1588 if (!strncmp(elf->filename, search_path, len_search) && \
1589 len_file > len_search)
1590 tmp += len_search;
1591 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
1592 }
1593 xstrcat(&out_buffer, tmp, &out_len);
1594 break;
1595 case 'f':
1596 found_file = 1;
1597 if (be_wewy_wewy_quiet) break;
1598 tmp = strrchr(elf->filename, '/');
1599 tmp = (tmp == NULL ? elf->filename : tmp+1);
1600 xstrcat(&out_buffer, tmp, &out_len);
1601 break;
1602 case 'o': out = get_elfetype(elf); break;
1603 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1604 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1605 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1606 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1607 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1608 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1609 case 'D': out = get_endian(elf); break;
1610 case 'O': out = strfileperms(elf->filename); break;
1611 case 'n':
1612 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1613 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1614 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1615 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1616 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1617 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1618 case 'a': out = get_elfemtype(elf); break;
1619 case 'I': out = get_elfosabi(elf); break;
1620 case 'Y': out = get_elf_eabi(elf); break;
1621 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
1622 default: warnf("'%c' has no scan code?", out_format[i]);
1623 }
1624 if (out)
1625 xstrcat(&out_buffer, out, &out_len);
1626 }
1627
1628 #define FOUND_SOMETHING() \
1629 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1630 found_rpath || found_needed || found_interp || found_bind || \
1631 found_soname || found_sym || found_lib || found_textrels || found_section )
1632
1633 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1634 xchrcat(&out_buffer, ' ', &out_len);
1635 xstrcat(&out_buffer, elf->filename, &out_len);
1636 }
1637 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
1638 puts(out_buffer);
1639 fflush(stdout);
1640 }
1641
1642 return 0;
1643 }
1644
1645 /* scan a single elf */
1646 static int scanelf_elf(const char *filename, int fd, size_t len)
1647 {
1648 int ret = 1;
1649 size_t n;
1650 const char *match_etype;
1651 elfobj *elf;
1652
1653 /* Verify this is a real ELF */
1654 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1655 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1656 return 2;
1657 }
1658
1659 /* Possibly filter based on ELF bitness */
1660 switch (match_bits) {
1661 case 32:
1662 if (elf->elf_class != ELFCLASS32)
1663 goto done;
1664 break;
1665 case 64:
1666 if (elf->elf_class != ELFCLASS64)
1667 goto done;
1668 break;
1669 }
1670
1671 /* Possibly filter based on the ELF's e_type field */
1672 array_for_each(match_etypes, n, match_etype)
1673 if (etype_lookup(match_etype) == get_etype(elf))
1674 goto scanit;
1675 if (array_cnt(match_etypes))
1676 goto done;
1677
1678 scanit:
1679 ret = scanelf_elfobj(elf);
1680
1681 done:
1682 unreadelf(elf);
1683 return ret;
1684 }
1685
1686 /* scan an archive of elfs */
1687 static int scanelf_archive(const char *filename, int fd, size_t len)
1688 {
1689 archive_handle *ar;
1690 archive_member *m;
1691 char *ar_buffer;
1692 elfobj *elf;
1693
1694 ar = ar_open_fd(filename, fd);
1695 if (ar == NULL)
1696 return 1;
1697
1698 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1699 while ((m = ar_next(ar)) != NULL) {
1700 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1701 if (cur_pos == -1)
1702 errp("lseek() failed");
1703 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1704 if (elf) {
1705 scanelf_elfobj(elf);
1706 unreadelf(elf);
1707 }
1708 }
1709 munmap(ar_buffer, len);
1710
1711 return 0;
1712 }
1713 /* scan a file which may be an elf or an archive or some other magical beast */
1714 static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1715 {
1716 const struct stat *st = st_cache;
1717 struct stat symlink_st;
1718 int fd;
1719
1720 /* always handle regular files and handle symlinked files if no -y */
1721 if (S_ISLNK(st->st_mode)) {
1722 if (!scan_symlink)
1723 return 1;
1724 fstatat(dir_fd, filename, &symlink_st, 0);
1725 st = &symlink_st;
1726 }
1727
1728 if (!S_ISREG(st->st_mode)) {
1729 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1730 return 1;
1731 }
1732
1733 if (match_perms) {
1734 if ((st->st_mode | match_perms) != st->st_mode)
1735 return 1;
1736 }
1737 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1738 if (fd == -1) {
1739 if (fix_elf && errno == ETXTBSY)
1740 warnp("%s: could not fix", filename);
1741 else if (be_verbose > 2)
1742 printf("%s: skipping file: %s\n", filename, strerror(errno));
1743 return 1;
1744 }
1745
1746 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1747 /* if it isn't an ELF, maybe it's an .a archive */
1748 if (scan_archives)
1749 scanelf_archive(filename, fd, st->st_size);
1750
1751 /*
1752 * unreadelf() implicitly closes its fd, so only close it
1753 * when we are returning it in the non-ELF case
1754 */
1755 close(fd);
1756 }
1757
1758 return 0;
1759 }
1760
1761 /* scan a directory for ET_EXEC files and print when we find one */
1762 static int scanelf_dirat(int dir_fd, const char *path)
1763 {
1764 register DIR *dir;
1765 register struct dirent *dentry;
1766 struct stat st_top, st;
1767 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1768 size_t pathlen = 0, len = 0;
1769 int ret = 0;
1770 int subdir_fd;
1771
1772 /* make sure path exists */
1773 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1774 if (be_verbose > 2) printf("%s: does not exist\n", path);
1775 return 1;
1776 }
1777
1778 /* ok, if it isn't a directory, assume we can open it */
1779 if (!S_ISDIR(st_top.st_mode))
1780 return scanelf_fileat(dir_fd, path, &st_top);
1781
1782 /* now scan the dir looking for fun stuff */
1783 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1784 if (subdir_fd == -1)
1785 dir = NULL;
1786 else
1787 dir = fdopendir(subdir_fd);
1788 if (dir == NULL) {
1789 if (subdir_fd != -1)
1790 close(subdir_fd);
1791 else if (be_verbose > 2)
1792 printf("%s: skipping dir: %s\n", path, strerror(errno));
1793 return 1;
1794 }
1795 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1796
1797 subpath = stpcpy(buf, path);
1798 if (subpath[-1] != '/')
1799 *subpath++ = '/';
1800 pathlen = subpath - buf;
1801 while ((dentry = readdir(dir))) {
1802 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1803 continue;
1804
1805 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1806 continue;
1807
1808 len = strlen(dentry->d_name);
1809 if (len + pathlen + 1 >= sizeof(buf)) {
1810 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1811 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1812 continue;
1813 }
1814 memcpy(subpath, dentry->d_name, len);
1815 subpath[len] = '\0';
1816
1817 if (S_ISREG(st.st_mode))
1818 ret = scanelf_fileat(dir_fd, buf, &st);
1819 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1820 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1821 ret = scanelf_dirat(dir_fd, buf);
1822 }
1823 }
1824 closedir(dir);
1825
1826 return ret;
1827 }
1828 static int scanelf_dir(const char *path)
1829 {
1830 return scanelf_dirat(root_fd, root_rel_path(path));
1831 }
1832
1833 static int scanelf_from_file(const char *filename)
1834 {
1835 FILE *fp;
1836 char *p, *path;
1837 size_t len;
1838 int ret;
1839
1840 if (strcmp(filename, "-") == 0)
1841 fp = stdin;
1842 else if ((fp = fopen(filename, "r")) == NULL)
1843 return 1;
1844
1845 path = NULL;
1846 len = 0;
1847 ret = 0;
1848 while (getline(&path, &len, fp) != -1) {
1849 if ((p = strchr(path, '\n')) != NULL)
1850 *p = 0;
1851 search_path = path;
1852 ret = scanelf_dir(path);
1853 }
1854 free(path);
1855
1856 if (fp != stdin)
1857 fclose(fp);
1858
1859 return ret;
1860 }
1861
1862 #if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1863
1864 static int _load_ld_cache_config(const char *fname)
1865 {
1866 FILE *fp = NULL;
1867 char *p, *path;
1868 size_t len;
1869 int curr_fd = -1;
1870
1871 fp = fopenat_r(root_fd, root_rel_path(fname));
1872 if (fp == NULL)
1873 return -1;
1874
1875 path = NULL;
1876 len = 0;
1877 while (getline(&path, &len, fp) != -1) {
1878 if ((p = strrchr(path, '\r')) != NULL)
1879 *p = 0;
1880 if ((p = strchr(path, '\n')) != NULL)
1881 *p = 0;
1882
1883 /* recursive includes of the same file will make this segfault. */
1884 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1885 glob_t gl;
1886 size_t x;
1887 const char *gpath;
1888
1889 /* re-use existing path buffer ... need to be creative */
1890 if (path[8] != '/')
1891 gpath = memcpy(path + 3, "/etc/", 5);
1892 else
1893 gpath = path + 8;
1894 if (root_fd != AT_FDCWD) {
1895 if (curr_fd == -1) {
1896 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1897 if (fchdir(root_fd))
1898 errp("unable to change to root dir");
1899 }
1900 gpath = root_rel_path(gpath);
1901 }
1902
1903 if (glob(gpath, 0, NULL, &gl) == 0) {
1904 for (x = 0; x < gl.gl_pathc; ++x) {
1905 /* try to avoid direct loops */
1906 if (strcmp(gl.gl_pathv[x], fname) == 0)
1907 continue;
1908 _load_ld_cache_config(gl.gl_pathv[x]);
1909 }
1910 globfree(&gl);
1911 }
1912
1913 /* failed globs are ignored by glibc */
1914 continue;
1915 }
1916
1917 if (*path != '/')
1918 continue;
1919
1920 xarraypush_str(ldpaths, path);
1921 }
1922 free(path);
1923
1924 fclose(fp);
1925
1926 if (curr_fd != -1) {
1927 if (fchdir(curr_fd))
1928 {/* don't care */}
1929 close(curr_fd);
1930 }
1931
1932 return 0;
1933 }
1934
1935 #elif defined(__FreeBSD__) || defined(__DragonFly__)
1936
1937 static int _load_ld_cache_config(const char *fname)
1938 {
1939 FILE *fp = NULL;
1940 char *b = NULL, *p;
1941 struct elfhints_hdr hdr;
1942
1943 fp = fopenat_r(root_fd, root_rel_path(fname));
1944 if (fp == NULL)
1945 return -1;
1946
1947 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1948 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1949 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1950 {
1951 fclose(fp);
1952 return -1;
1953 }
1954
1955 b = xmalloc(hdr.dirlistlen + 1);
1956 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1957 fclose(fp);
1958 free(b);
1959 return -1;
1960 }
1961
1962 while ((p = strsep(&b, ":"))) {
1963 if (*p == '\0')
1964 continue;
1965 xarraypush_str(ldpaths, p);
1966 }
1967
1968 free(b);
1969 fclose(fp);
1970 return 0;
1971 }
1972
1973 #else
1974 #ifdef __ELF__
1975 #warning Cache config support not implemented for your target
1976 #endif
1977 static int _load_ld_cache_config(const char *fname)
1978 {
1979 return 0;
1980 }
1981 #endif
1982
1983 static void load_ld_cache_config(const char *fname)
1984 {
1985 bool scan_l, scan_ul, scan_ull;
1986 size_t n;
1987 const char *ldpath;
1988
1989 _load_ld_cache_config(fname);
1990
1991 scan_l = scan_ul = scan_ull = false;
1992 array_for_each(ldpaths, n, ldpath) {
1993 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1994 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1995 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1996 }
1997
1998 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1999 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
2000 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
2001 }
2002
2003 /* scan /etc/ld.so.conf for paths */
2004 static void scanelf_ldpath(void)
2005 {
2006 size_t n;
2007 const char *ldpath;
2008
2009 array_for_each(ldpaths, n, ldpath)
2010 scanelf_dir(ldpath);
2011 }
2012
2013 /* scan env PATH for paths */
2014 static void scanelf_envpath(void)
2015 {
2016 char *path, *p;
2017
2018 path = getenv("PATH");
2019 if (!path)
2020 err("PATH is not set in your env !");
2021 path = xstrdup(path);
2022
2023 while ((p = strrchr(path, ':')) != NULL) {
2024 scanelf_dir(p + 1);
2025 *p = 0;
2026 }
2027
2028 free(path);
2029 }
2030
2031 /* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
2032 #define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
2033 #define a_argument required_argument
2034 static struct option const long_opts[] = {
2035 {"path", no_argument, NULL, 'p'},
2036 {"ldpath", no_argument, NULL, 'l'},
2037 {"use-ldpath",no_argument, NULL, 129},
2038 {"root", a_argument, NULL, 128},
2039 {"recursive", no_argument, NULL, 'R'},
2040 {"mount", no_argument, NULL, 'm'},
2041 {"symlink", no_argument, NULL, 'y'},
2042 {"archives", no_argument, NULL, 'A'},
2043 {"ldcache", no_argument, NULL, 'L'},
2044 {"fix", no_argument, NULL, 'X'},
2045 {"setpax", a_argument, NULL, 'z'},
2046 {"pax", no_argument, NULL, 'x'},
2047 {"header", no_argument, NULL, 'e'},
2048 {"textrel", no_argument, NULL, 't'},
2049 {"rpath", no_argument, NULL, 'r'},
2050 {"needed", no_argument, NULL, 'n'},
2051 {"interp", no_argument, NULL, 'i'},
2052 {"bind", no_argument, NULL, 'b'},
2053 {"soname", no_argument, NULL, 'S'},
2054 {"symbol", a_argument, NULL, 's'},
2055 {"section", a_argument, NULL, 'k'},
2056 {"lib", a_argument, NULL, 'N'},
2057 {"gmatch", no_argument, NULL, 'g'},
2058 {"textrels", no_argument, NULL, 'T'},
2059 {"etype", a_argument, NULL, 'E'},
2060 {"bits", a_argument, NULL, 'M'},
2061 {"endian", no_argument, NULL, 'D'},
2062 {"osabi", no_argument, NULL, 'I'},
2063 {"eabi", no_argument, NULL, 'Y'},
2064 {"perms", a_argument, NULL, 'O'},
2065 {"size", no_argument, NULL, 'Z'},
2066 {"all", no_argument, NULL, 'a'},
2067 {"quiet", no_argument, NULL, 'q'},
2068 {"verbose", no_argument, NULL, 'v'},
2069 {"format", a_argument, NULL, 'F'},
2070 {"from", a_argument, NULL, 'f'},
2071 {"file", a_argument, NULL, 'o'},
2072 {"nocolor", no_argument, NULL, 'C'},
2073 {"nobanner", no_argument, NULL, 'B'},
2074 {"help", no_argument, NULL, 'h'},
2075 {"version", no_argument, NULL, 'V'},
2076 {NULL, no_argument, NULL, 0x0}
2077 };
2078
2079 static const char * const opts_help[] = {
2080 "Scan all directories in PATH environment",
2081 "Scan all directories in /etc/ld.so.conf",
2082 "Use ld.so.conf to show full path (use with -r/-n)",
2083 "Root directory (use with -l or -p)",
2084 "Scan directories recursively",
2085 "Don't recursively cross mount points",
2086 "Don't scan symlinks",
2087 "Scan archives (.a files)",
2088 "Utilize ld.so.cache to show full path (use with -r/-n)",
2089 "Try and 'fix' bad things (use with -r/-e)",
2090 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
2091 "Print PaX markings",
2092 "Print GNU_STACK/PT_LOAD markings",
2093 "Print TEXTREL information",
2094 "Print RPATH information",
2095 "Print NEEDED information",
2096 "Print INTERP information",
2097 "Print BIND information",
2098 "Print SONAME information",
2099 "Find a specified symbol",
2100 "Find a specified section",
2101 "Find a specified library",
2102 "Use regex rather than string compare (with -s); specify twice for case insensitive",
2103 "Locate cause of TEXTREL",
2104 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2105 "Print only ELF files matching numeric bits",
2106 "Print Endianness",
2107 "Print OSABI",
2108 "Print EABI (EM_ARM Only)",
2109 "Print only ELF files matching octal permissions",
2110 "Print ELF file size",
2111 "Print all useful/simple info\n",
2112 "Only output 'bad' things",
2113 "Be verbose (can be specified more than once)",
2114 "Use specified format for output",
2115 "Read input stream from a filename",
2116 "Write output stream to a filename",
2117 "Don't emit color in output",
2118 "Don't display the header",
2119 "Print this help and exit",
2120 "Print version and exit",
2121 NULL
2122 };
2123
2124 /* display usage and exit */
2125 static void usage(int status)
2126 {
2127 const char a_arg[] = "<arg>";
2128 size_t a_arg_len = strlen(a_arg) + 2;
2129 size_t i;
2130 int optlen;
2131 printf("* Scan ELF binaries for stuff\n\n"
2132 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
2133 printf("Options: -[%s]\n", PARSE_FLAGS);
2134
2135 /* prescan the --long opt length to auto-align */
2136 optlen = 0;
2137 for (i = 0; long_opts[i].name; ++i) {
2138 int l = strlen(long_opts[i].name);
2139 if (long_opts[i].has_arg == a_argument)
2140 l += a_arg_len;
2141 optlen = max(l, optlen);
2142 }
2143
2144 for (i = 0; long_opts[i].name; ++i) {
2145 /* first output the short flag if it has one */
2146 if (long_opts[i].val > '~')
2147 printf(" ");
2148 else
2149 printf(" -%c, ", long_opts[i].val);
2150
2151 /* then the long flag */
2152 if (long_opts[i].has_arg == no_argument)
2153 printf("--%-*s", optlen, long_opts[i].name);
2154 else
2155 printf("--%s %s %*s", long_opts[i].name, a_arg,
2156 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
2157
2158 /* finally the help text */
2159 printf("* %s\n", opts_help[i]);
2160 }
2161
2162 puts("\nFor more information, see the scanelf(1) manpage");
2163 exit(status);
2164 }
2165
2166 /* parse command line arguments and preform needed actions */
2167 #define do_pax_state(option, flag) \
2168 if (islower(option)) { \
2169 flags &= ~PF_##flag; \
2170 flags |= PF_NO##flag; \
2171 } else { \
2172 flags &= ~PF_NO##flag; \
2173 flags |= PF_##flag; \
2174 }
2175 static void parse_delimited(array_t *arr, char *arg, const char *delim)
2176 {
2177 char *ele = strtok(arg, delim);
2178 if (!ele) /* edge case: -s '' */
2179 xarraypush_str(arr, "");
2180 while (ele) {
2181 xarraypush_str(arr, ele);
2182 ele = strtok(NULL, delim);
2183 }
2184 }
2185 static int parseargs(int argc, char *argv[])
2186 {
2187 int i;
2188 const char *from_file = NULL;
2189 int ret = 0;
2190 char load_cache_config = 0;
2191
2192 opterr = 0;
2193 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
2194 switch (i) {
2195
2196 case 'V':
2197 printf("pax-utils-%s: %s\n%s\n"
2198 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
2199 VERSION, __FILE__, rcsid, argv0);
2200 exit(EXIT_SUCCESS);
2201 break;
2202 case 'h': usage(EXIT_SUCCESS); break;
2203 case 'f':
2204 if (from_file) warn("You prob don't want to specify -f twice");
2205 from_file = optarg;
2206 break;
2207 case 'E':
2208 /* historically, this was comma delimited */
2209 parse_delimited(match_etypes, optarg, ",");
2210 break;
2211 case 'M':
2212 match_bits = atoi(optarg);
2213 if (match_bits == 0) {
2214 if (strcmp(optarg, "ELFCLASS32") == 0)
2215 match_bits = 32;
2216 if (strcmp(optarg, "ELFCLASS64") == 0)
2217 match_bits = 64;
2218 }
2219 break;
2220 case 'O':
2221 if (sscanf(optarg, "%o", &match_perms) == -1)
2222 match_bits = 0;
2223 break;
2224 case 'o': {
2225 if (freopen(optarg, "w", stdout) == NULL)
2226 errp("Could not freopen(%s)", optarg);
2227 break;
2228 }
2229 case 'k':
2230 xarraypush_str(find_section_arr, optarg);
2231 break;
2232 case 's':
2233 /* historically, this was comma delimited */
2234 parse_delimited(find_sym_arr, optarg, ",");
2235 break;
2236 case 'N':
2237 xarraypush_str(find_lib_arr, optarg);
2238 break;
2239 case 'F': {
2240 if (out_format) warn("You prob don't want to specify -F twice");
2241 out_format = optarg;
2242 break;
2243 }
2244 case 'z': {
2245 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2246 size_t x;
2247
2248 for (x = 0; x < strlen(optarg); x++) {
2249 switch (optarg[x]) {
2250 case 'p':
2251 case 'P':
2252 do_pax_state(optarg[x], PAGEEXEC);
2253 break;
2254 case 's':
2255 case 'S':
2256 do_pax_state(optarg[x], SEGMEXEC);
2257 break;
2258 case 'm':
2259 case 'M':
2260 do_pax_state(optarg[x], MPROTECT);
2261 break;
2262 case 'e':
2263 case 'E':
2264 do_pax_state(optarg[x], EMUTRAMP);
2265 break;
2266 case 'r':
2267 case 'R':
2268 do_pax_state(optarg[x], RANDMMAP);
2269 break;
2270 case 'x':
2271 case 'X':
2272 do_pax_state(optarg[x], RANDEXEC);
2273 break;
2274 default:
2275 break;
2276 }
2277 }
2278 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2279 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2280 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2281 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2282 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2283 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2284 setpax = flags;
2285 break;
2286 }
2287 case 'Z': show_size = 1; break;
2288 case 'g': ++g_match; break;
2289 case 'L': load_cache_config = use_ldcache = 1; break;
2290 case 'y': scan_symlink = 0; break;
2291 case 'A': scan_archives = 1; break;
2292 case 'C': color_init(true); break;
2293 case 'B': show_banner = 0; break;
2294 case 'l': load_cache_config = scan_ldpath = 1; break;
2295 case 'p': scan_envpath = 1; break;
2296 case 'R': dir_recurse = 1; break;
2297 case 'm': dir_crossmount = 0; break;
2298 case 'X': ++fix_elf; break;
2299 case 'x': show_pax = 1; break;
2300 case 'e': show_phdr = 1; break;
2301 case 't': show_textrel = 1; break;
2302 case 'r': show_rpath = 1; break;
2303 case 'n': show_needed = 1; break;
2304 case 'i': show_interp = 1; break;
2305 case 'b': show_bind = 1; break;
2306 case 'S': show_soname = 1; break;
2307 case 'T': show_textrels = 1; break;
2308 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
2309 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
2310 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
2311 case 'D': show_endian = 1; break;
2312 case 'I': show_osabi = 1; break;
2313 case 'Y': show_eabi = 1; break;
2314 case 128:
2315 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2316 if (root_fd == -1)
2317 err("Could not open root: %s", optarg);
2318 break;
2319 case 129: load_cache_config = use_ldpath = 1; break;
2320 case ':':
2321 err("Option '%c' is missing parameter", optopt);
2322 case '?':
2323 err("Unknown option '%c' or argument missing", optopt);
2324 default:
2325 err("Unhandled option '%c'; please report this", i);
2326 }
2327 }
2328 if (show_textrels && be_verbose)
2329 objdump = which("objdump", "OBJDUMP");
2330 /* precompile all the regexes */
2331 if (g_match) {
2332 regex_t preg;
2333 const char *this_sym;
2334 size_t n;
2335 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2336
2337 array_for_each(find_sym_arr, n, this_sym) {
2338 /* see scanelf_match_symname for logic info */
2339 switch (this_sym[0]) {
2340 case '%':
2341 while (*(this_sym++))
2342 if (*this_sym == '%') {
2343 ++this_sym;
2344 break;
2345 }
2346 break;
2347 case '+':
2348 case '-':
2349 ++this_sym;
2350 break;
2351 }
2352 if (*this_sym == '*')
2353 ++this_sym;
2354
2355 ret = regcomp(&preg, this_sym, flags);
2356 if (ret) {
2357 char err[256];
2358 regerror(ret, &preg, err, sizeof(err));
2359 err("regcomp of %s failed: %s", this_sym, err);
2360 }
2361 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2362 }
2363 }
2364 /* flatten arrays for display */
2365 find_sym = array_flatten_str(find_sym_arr);
2366 find_lib = array_flatten_str(find_lib_arr);
2367 find_section = array_flatten_str(find_section_arr);
2368 /* let the format option override all other options */
2369 if (out_format) {
2370 show_pax = show_phdr = show_textrel = show_rpath = \
2371 show_needed = show_interp = show_bind = show_soname = \
2372 show_textrels = show_perms = show_endian = show_size = \
2373 show_osabi = show_eabi = 0;
2374 for (i = 0; out_format[i]; ++i) {
2375 if (!IS_MODIFIER(out_format[i])) continue;
2376
2377 switch (out_format[++i]) {
2378 case '+': break;
2379 case '%': break;
2380 case '#': break;
2381 case 'F': break;
2382 case 'p': break;
2383 case 'f': break;
2384 case 'k': break;
2385 case 's': break;
2386 case 'N': break;
2387 case 'o': break;
2388 case 'a': break;
2389 case 'M': break;
2390 case 'Z': show_size = 1; break;
2391 case 'D': show_endian = 1; break;
2392 case 'I': show_osabi = 1; break;
2393 case 'Y': show_eabi = 1; break;
2394 case 'O': show_perms = 1; break;
2395 case 'x': show_pax = 1; break;
2396 case 'e': show_phdr = 1; break;
2397 case 't': show_textrel = 1; break;
2398 case 'r': show_rpath = 1; break;
2399 case 'n': show_needed = 1; break;
2400 case 'i': show_interp = 1; break;
2401 case 'b': show_bind = 1; break;
2402 case 'S': show_soname = 1; break;
2403 case 'T': show_textrels = 1; break;
2404 default:
2405 err("invalid format specifier '%c' (byte %i)",
2406 out_format[i], i+1);
2407 }
2408 }
2409
2410 /* construct our default format */
2411 } else {
2412 size_t fmt_len = 30;
2413 out_format = xmalloc(sizeof(char) * fmt_len);
2414 *out_format = '\0';
2415 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
2416 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2417 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2418 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2419 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2420 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2421 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
2422 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
2423 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
2424 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
2425 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
2426 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
2427 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
2428 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
2429 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
2430 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2431 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
2432 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
2433 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
2434 }
2435 if (be_verbose > 2) printf("Format: %s\n", out_format);
2436
2437 /* now lets actually do the scanning */
2438 if (load_cache_config)
2439 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
2440 if (scan_ldpath) scanelf_ldpath();
2441 if (scan_envpath) scanelf_envpath();
2442 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2443 from_file = "-";
2444 if (from_file) {
2445 scanelf_from_file(from_file);
2446 from_file = *argv;
2447 }
2448 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
2449 err("Nothing to scan !?");
2450 while (optind < argc) {
2451 search_path = argv[optind++];
2452 ret = scanelf_dir(search_path);
2453 }
2454
2455 #ifdef __PAX_UTILS_CLEANUP
2456 /* clean up */
2457 xarrayfree(ldpaths);
2458 xarrayfree(find_sym_arr);
2459 xarrayfree(find_lib_arr);
2460 xarrayfree(find_section_arr);
2461 free(find_sym);
2462 free(find_lib);
2463 free(find_section);
2464 {
2465 size_t n;
2466 regex_t *preg;
2467 array_for_each(find_sym_regex_arr, n, preg)
2468 regfree(preg);
2469 xarrayfree(find_sym_regex_arr);
2470 }
2471
2472 if (ldcache != 0)
2473 munmap(ldcache, ldcache_size);
2474 #endif
2475
2476 return ret;
2477 }
2478
2479 static char **get_split_env(const char *envvar)
2480 {
2481 const char *delims = " \t\n";
2482 char **envvals = NULL;
2483 char *env, *s;
2484 int nentry;
2485
2486 if ((env = getenv(envvar)) == NULL)
2487 return NULL;
2488
2489 env = xstrdup(env);
2490 if (env == NULL)
2491 return NULL;
2492
2493 s = strtok(env, delims);
2494 if (s == NULL) {
2495 free(env);
2496 return NULL;
2497 }
2498
2499 nentry = 0;
2500 while (s != NULL) {
2501 ++nentry;
2502 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2503 envvals[nentry-1] = s;
2504 s = strtok(NULL, delims);
2505 }
2506 envvals[nentry] = NULL;
2507
2508 /* don't want to free(env) as it contains the memory that backs
2509 * the envvals array of strings */
2510 return envvals;
2511 }
2512
2513 static void parseenv(void)
2514 {
2515 color_init(false);
2516 qa_textrels = get_split_env("QA_TEXTRELS");
2517 qa_execstack = get_split_env("QA_EXECSTACK");
2518 qa_wx_load = get_split_env("QA_WX_LOAD");
2519 }
2520
2521 #ifdef __PAX_UTILS_CLEANUP
2522 static void cleanup(void)
2523 {
2524 free(out_format);
2525 free(qa_textrels);
2526 free(qa_execstack);
2527 free(qa_wx_load);
2528 }
2529 #endif
2530
2531 int main(int argc, char *argv[])
2532 {
2533 int ret;
2534 if (argc < 2)
2535 usage(EXIT_FAILURE);
2536 parseenv();
2537 ret = parseargs(argc, argv);
2538 fclose(stdout);
2539 #ifdef __PAX_UTILS_CLEANUP
2540 cleanup();
2541 warn("The calls to add/delete heap should be off:\n"
2542 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2543 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
2544 #endif
2545 return ret;
2546 }
2547
2548 /* Match filename against entries in matchlist, return TRUE
2549 * if the file is listed */
2550 static int file_matches_list(const char *filename, char **matchlist)
2551 {
2552 char **file;
2553 char *match;
2554 char buf[__PAX_UTILS_PATH_MAX];
2555
2556 if (matchlist == NULL)
2557 return 0;
2558
2559 for (file = matchlist; *file != NULL; file++) {
2560 if (search_path) {
2561 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2562 match = buf;
2563 } else {
2564 match = *file;
2565 }
2566 if (fnmatch(match, filename, 0) == 0)
2567 return 1;
2568 }
2569 return 0;
2570 }

  ViewVC Help
Powered by ViewVC 1.1.20