/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.119 Revision 1.264
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.119 2006/02/05 02:25:58 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.264 2014/03/21 05:27:21 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.264 2014/03/21 05:27:21 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.119 2006/02/05 02:25:58 solar Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static int scanelf_elfobj(elfobj *elf); 18static int file_matches_list(const char *filename, char **matchlist);
21static int scanelf_elf(const char *filename, int fd, size_t len);
22static int scanelf_archive(const char *filename, int fd, size_t len);
23static void scanelf_file(const char *filename);
24static void scanelf_dir(const char *path);
25static void scanelf_ldpath(void);
26static void scanelf_envpath(void);
27static void usage(int status);
28static void parseargs(int argc, char *argv[]);
29static char *xstrdup(const char *s);
30static void *xmalloc(size_t size);
31static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
32#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
33static inline void xchrcat(char **dst, const char append, size_t *curr_len);
34 19
35/* variables to control behavior */ 20/* variables to control behavior */
36static char match_etypes[126] = ""; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
37static char *ldpaths[256]; 22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
38static char scan_ldpath = 0; 23static char scan_ldpath = 0;
39static char scan_envpath = 0; 24static char scan_envpath = 0;
40static char scan_symlink = 1; 25static char scan_symlink = 1;
41static char scan_archives = 0; 26static char scan_archives = 0;
42static char dir_recurse = 0; 27static char dir_recurse = 0;
43static char dir_crossmount = 1; 28static char dir_crossmount = 1;
44static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
45static char show_phdr = 0; 32static char show_phdr = 0;
46static char show_textrel = 0; 33static char show_textrel = 0;
47static char show_rpath = 0; 34static char show_rpath = 0;
48static char show_needed = 0; 35static char show_needed = 0;
49static char show_interp = 0; 36static char show_interp = 0;
50static char show_bind = 0; 37static char show_bind = 0;
51static char show_soname = 0; 38static char show_soname = 0;
52static char show_textrels = 0; 39static char show_textrels = 0;
53static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
54static char be_quiet = 0; 44static char be_quiet = 0;
55static char be_verbose = 0; 45static char be_verbose = 0;
56static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
57static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
58static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
59static char *out_format = NULL; 55static char *out_format = NULL;
60static char *search_path = NULL; 56static char *search_path = NULL;
61static char fix_elf = 0; 57static char fix_elf = 0;
62static char gmatch = 0; 58static char g_match = 0;
63static char use_ldcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
64 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
65 66
66caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
67size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
68 72
73static const char *objdump;
74
75/* find the path to a file by name */
76static const char *which(const char *fname, const char *envvar)
77{
78 size_t path_len, fname_len;
79 const char *env_path;
80 char *path, *p, *ep;
81
82 p = getenv(envvar);
83 if (p)
84 return p;
85
86 env_path = getenv("PATH");
87 if (!env_path)
88 return NULL;
89
90 /* Create a copy of the $PATH that we can safely modify.
91 * Make it a little bigger so we can append "/fname".
92 * We do this twice -- once for a perm copy, and once for
93 * room at the end of the last element. */
94 path_len = strlen(env_path);
95 fname_len = strlen(fname);
96 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
97 memcpy(path, env_path, path_len + 1);
98
99 p = path + path_len + 1 + fname_len + 1;
100 *p = '/';
101 memcpy(p + 1, fname, fname_len + 1);
102
103 /* Repoint fname to the copy in the env string as it has
104 * the leading slash which we can include in a single memcpy.
105 * Increase the fname len to include the '/' and '\0'. */
106 fname = p;
107 fname_len += 2;
108
109 p = path;
110 while (p) {
111 ep = strchr(p, ':');
112 /* Append the /foo path to the current element. */
113 if (ep)
114 memcpy(ep, fname, fname_len);
115 else
116 memcpy(path + path_len, fname, fname_len);
117
118 if (access(p, R_OK) != -1)
119 return p;
120
121 p = ep;
122 if (ep) {
123 /* If not the last element, restore the chunk we clobbered. */
124 size_t offset = ep - path;
125 size_t restore = min(path_len - offset, fname_len);
126 memcpy(ep, env_path + offset, restore);
127 ++p;
128 }
129 }
130
131 free(path);
132 return NULL;
133}
134
135static FILE *fopenat_r(int dir_fd, const char *path)
136{
137 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
138 if (fd == -1)
139 return NULL;
140 return fdopen(fd, "re");
141}
142
143static const char *root_rel_path(const char *path)
144{
145 /*
146 * openat() will ignore the dirfd if path starts with
147 * a /, so consume all of that noise
148 *
149 * XXX: we don't handle relative paths like ../ that
150 * break out of the --root option, but for now, just
151 * don't do that :P.
152 */
153 if (root_fd != AT_FDCWD) {
154 while (*path == '/')
155 ++path;
156 if (*path == '\0')
157 path = ".";
158 }
159
160 return path;
161}
162
69/* sub-funcs for scanelf_file() */ 163/* sub-funcs for scanelf_fileat() */
70static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 164static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
71{ 165{
72 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 166 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
167
168 /* debug sections */
169 void *symtab = elf_findsecbyname(elf, ".symtab");
170 void *strtab = elf_findsecbyname(elf, ".strtab");
171 /* runtime sections */
172 void *dynsym = elf_findsecbyname(elf, ".dynsym");
173 void *dynstr = elf_findsecbyname(elf, ".dynstr");
174
175 /*
176 * If the sections are marked NOBITS, then they don't exist, so we just
177 * skip them. This let's us work sanely with splitdebug ELFs (rather
178 * than spewing a lot of "corrupt ELF" messages later on). In malformed
179 * ELFs, the section might be wrongly set to NOBITS, but screw em.
180 */
73#define GET_SYMTABS(B) \ 181#define GET_SYMTABS(B) \
74 if (elf->elf_class == ELFCLASS ## B) { \ 182 if (elf->elf_class == ELFCLASS ## B) { \
75 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 183 Elf ## B ## _Shdr *esymtab = symtab; \
76 /* debug sections */ \ 184 Elf ## B ## _Shdr *estrtab = strtab; \
77 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 185 Elf ## B ## _Shdr *edynsym = dynsym; \
78 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 186 Elf ## B ## _Shdr *edynstr = dynstr; \
79 /* runtime sections */ \ 187 \
80 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 188 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
81 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 189 symtab = NULL; \
190 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
191 dynsym = NULL; \
82 if (symtab && dynsym) { \ 192 if (symtab && dynsym) \
83 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 193 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
84 } else { \ 194 else \
85 *sym = (void*)(symtab ? symtab : dynsym); \ 195 *sym = symtab ? symtab : dynsym; \
86 } \ 196 \
197 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
198 strtab = NULL; \
199 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
200 dynstr = NULL; \
87 if (strtab && dynstr) { \ 201 if (strtab && dynstr) \
88 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 202 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
89 } else { \ 203 else \
90 *tab = (void*)(strtab ? strtab : dynstr); \ 204 *str = strtab ? strtab : dynstr; \
91 } \
92 } 205 }
93 GET_SYMTABS(32) 206 GET_SYMTABS(32)
94 GET_SYMTABS(64) 207 GET_SYMTABS(64)
208
209 if (*sym && *str)
210 return;
211
212 /*
213 * damn, they're really going to make us work for it huh?
214 * reconstruct the section header info out of the dynamic
215 * tags so we can see what symbols this guy uses at runtime.
216 */
217#define GET_SYMTABS_DT(B) \
218 if (elf->elf_class == ELFCLASS ## B) { \
219 size_t i; \
220 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
221 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
222 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
223 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
224 Elf ## B ## _Dyn *dyn; \
225 Elf ## B ## _Off offset; \
226 \
227 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
228 vsym = vstr = vhash = vgnu_hash = 0; \
229 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
230 memset(&str_shdr, 0, sizeof(str_shdr)); \
231 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
232 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
233 continue; \
234 \
235 offset = EGET(phdr[i].p_offset); \
236 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
237 continue; \
238 \
239 dyn = DYN ## B (elf->vdata + offset); \
240 while (EGET(dyn->d_tag) != DT_NULL) { \
241 switch (EGET(dyn->d_tag)) { \
242 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
243 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
244 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
245 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
246 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
247 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
248 } \
249 ++dyn; \
250 } \
251 if (vsym && vstr) \
252 break; \
253 } \
254 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
255 return; \
256 \
257 /* calc offset into the ELF by finding the load addr of the syms */ \
258 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
259 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
260 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
261 offset = EGET(phdr[i].p_offset); \
262 \
263 if (EGET(phdr[i].p_type) != PT_LOAD) \
264 continue; \
265 \
266 if (vhash >= vaddr && vhash < vaddr + filesz) { \
267 /* Scan the hash table to see how many entries we have */ \
268 Elf32_Word max_sym_idx = 0; \
269 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
270 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
271 Elf32_Word nchains = EGET(hashtbl[1]); \
272 Elf32_Word *buckets = &hashtbl[2]; \
273 Elf32_Word *chains = &buckets[nbuckets]; \
274 Elf32_Word sym_idx; \
275 \
276 for (b = 0; b < nbuckets; ++b) { \
277 if (!buckets[b]) \
278 continue; \
279 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
280 if (max_sym_idx < sym_idx) \
281 max_sym_idx = sym_idx; \
282 } \
283 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
284 } \
285 \
286 if (vsym >= vaddr && vsym < vaddr + filesz) { \
287 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
288 *sym = &sym_shdr; \
289 } \
290 \
291 if (vstr >= vaddr && vstr < vaddr + filesz) { \
292 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
293 *str = &str_shdr; \
294 } \
295 } \
296 }
297 GET_SYMTABS_DT(32)
298 GET_SYMTABS_DT(64)
95} 299}
300
96static char *scanelf_file_pax(elfobj *elf, char *found_pax) 301static char *scanelf_file_pax(elfobj *elf, char *found_pax)
97{ 302{
98 static char ret[7]; 303 static char ret[7];
99 unsigned long i, shown; 304 unsigned long i, shown;
100 305
109 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 314 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
110 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 315 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
111 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 316 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
112 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 317 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
113 continue; \ 318 continue; \
114 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 319 if (fix_elf && setpax) { \
320 /* set the paxctl flags */ \
321 ESET(phdr[i].p_flags, setpax); \
322 } \
323 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
115 continue; \ 324 continue; \
116 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 325 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
117 *found_pax = 1; \ 326 *found_pax = 1; \
118 ++shown; \ 327 ++shown; \
119 break; \ 328 break; \
120 } \ 329 } \
121 } 330 }
122 SHOW_PAX(32) 331 SHOW_PAX(32)
123 SHOW_PAX(64) 332 SHOW_PAX(64)
124 } 333 }
334
335 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
336 * was found. This is known to break ELFs on glibc systems,
337 * and mainline PaX has deprecated use of this for a long time.
338 * We could support changing PT_GNU_STACK, but that doesn't
339 * seem like it's worth the effort. #411919
340 */
125 341
126 /* fall back to EI_PAX if no PT_PAX was found */ 342 /* fall back to EI_PAX if no PT_PAX was found */
127 if (!*ret) { 343 if (!*ret) {
128 static char *paxflags; 344 static char *paxflags;
129 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 345 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
143static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 359static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
144{ 360{
145 static char ret[12]; 361 static char ret[12];
146 char *found; 362 char *found;
147 unsigned long i, shown, multi_stack, multi_relro, multi_load; 363 unsigned long i, shown, multi_stack, multi_relro, multi_load;
148 int max_pt_load;
149 364
150 if (!show_phdr) return NULL; 365 if (!show_phdr) return NULL;
151 366
152 memcpy(ret, "--- --- ---\0", 12); 367 memcpy(ret, "--- --- ---\0", 12);
153 368
154 shown = 0; 369 shown = 0;
155 multi_stack = multi_relro = multi_load = 0; 370 multi_stack = multi_relro = multi_load = 0;
156 max_pt_load = elf_max_pt_load(elf);
157 371
158#define NOTE_GNU_STACK ".note.GNU-stack" 372#define NOTE_GNU_STACK ".note.GNU-stack"
159#define SHOW_PHDR(B) \ 373#define SHOW_PHDR(B) \
160 if (elf->elf_class == ELFCLASS ## B) { \ 374 if (elf->elf_class == ELFCLASS ## B) { \
161 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 375 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
163 uint32_t flags, check_flags; \ 377 uint32_t flags, check_flags; \
164 if (elf->phdr != NULL) { \ 378 if (elf->phdr != NULL) { \
165 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 379 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
166 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 380 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
167 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 381 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
382 if (multi_stack++) \
168 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 383 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
384 if (file_matches_list(elf->filename, qa_execstack)) \
385 continue; \
169 found = found_phdr; \ 386 found = found_phdr; \
170 offset = 0; \ 387 offset = 0; \
171 check_flags = PF_X; \ 388 check_flags = PF_X; \
172 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 389 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
390 if (multi_relro++) \
173 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 391 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
174 found = found_relro; \ 392 found = found_relro; \
175 offset = 4; \ 393 offset = 4; \
176 check_flags = PF_X; \ 394 check_flags = PF_X; \
177 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 395 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
178 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \ 396 if (file_matches_list(elf->filename, qa_wx_load)) \
179 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \ 397 continue; \
180 found = found_load; \ 398 found = found_load; \
181 offset = 8; \ 399 offset = 8; \
182 check_flags = PF_W|PF_X; \ 400 check_flags = PF_W|PF_X; \
183 } else \ 401 } else \
184 continue; \ 402 continue; \
185 flags = EGET(phdr[i].p_flags); \ 403 flags = EGET(phdr[i].p_flags); \
186 if (be_quiet && ((flags & check_flags) != check_flags)) \ 404 if (be_quiet && ((flags & check_flags) != check_flags)) \
187 continue; \ 405 continue; \
188 if (fix_elf && ((flags & PF_X) != flags)) { \ 406 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
189 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \ 407 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
190 ret[3] = ret[7] = '!'; \ 408 ret[3] = ret[7] = '!'; \
191 flags = EGET(phdr[i].p_flags); \ 409 flags = EGET(phdr[i].p_flags); \
192 } \ 410 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 411 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
197 } else if (elf->shdr != NULL) { \ 415 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 416 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 417 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 418 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
201 char *str; \ 419 char *str; \
202 if ((void*)strtbl > (void*)elf->data_end) \ 420 if ((void*)strtbl > elf->data_end) \
203 goto skip_this_shdr##B; \ 421 goto skip_this_shdr##B; \
422 /* let's flag -w/+x object files since the final ELF will most likely \
423 * need write access to the stack (who doesn't !?). so the combined \
424 * output will bring in +w automatically and that's bad. \
425 */ \
204 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 426 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
205 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 427 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
206 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 428 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
207 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 429 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
208 str = elf->data + offset; \ 430 str = elf->data + offset; \
209 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \ 431 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
221 break; \ 443 break; \
222 } \ 444 } \
223 } \ 445 } \
224 skip_this_shdr##B: \ 446 skip_this_shdr##B: \
225 if (!multi_stack) { \ 447 if (!multi_stack) { \
448 if (file_matches_list(elf->filename, qa_execstack)) \
449 return NULL; \
226 *found_phdr = 1; \ 450 *found_phdr = 1; \
227 shown = 1; \ 451 shown = 1; \
228 memcpy(ret, "!WX", 3); \ 452 memcpy(ret, "!WX", 3); \
229 } \ 453 } \
230 } \ 454 } \
235 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 459 if (be_wewy_wewy_quiet || (be_quiet && !shown))
236 return NULL; 460 return NULL;
237 else 461 else
238 return ret; 462 return ret;
239} 463}
464
465/*
466 * See if this ELF contains a DT_TEXTREL tag in any of its
467 * PT_DYNAMIC sections.
468 */
240static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 469static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
241{ 470{
242 static const char *ret = "TEXTREL"; 471 static const char *ret = "TEXTREL";
243 unsigned long i; 472 unsigned long i;
244 473
245 if (!show_textrel && !show_textrels) return NULL; 474 if (!show_textrel && !show_textrels) return NULL;
475
476 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
246 477
247 if (elf->phdr) { 478 if (elf->phdr) {
248#define SHOW_TEXTREL(B) \ 479#define SHOW_TEXTREL(B) \
249 if (elf->elf_class == ELFCLASS ## B) { \ 480 if (elf->elf_class == ELFCLASS ## B) { \
250 Elf ## B ## _Dyn *dyn; \ 481 Elf ## B ## _Dyn *dyn; \
251 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 482 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
252 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 483 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
253 Elf ## B ## _Off offset; \ 484 Elf ## B ## _Off offset; \
254 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 485 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
255 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 486 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
256 offset = EGET(phdr[i].p_offset); \ 487 offset = EGET(phdr[i].p_offset); \
257 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 488 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
258 dyn = DYN ## B (elf->data + offset); \ 489 dyn = DYN ## B (elf->vdata + offset); \
259 while (EGET(dyn->d_tag) != DT_NULL) { \ 490 while (EGET(dyn->d_tag) != DT_NULL) { \
260 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 491 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
261 *found_textrel = 1; \ 492 *found_textrel = 1; \
262 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 493 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
263 return (be_wewy_wewy_quiet ? NULL : ret); \ 494 return (be_wewy_wewy_quiet ? NULL : ret); \
272 if (be_quiet || be_wewy_wewy_quiet) 503 if (be_quiet || be_wewy_wewy_quiet)
273 return NULL; 504 return NULL;
274 else 505 else
275 return " - "; 506 return " - ";
276} 507}
508
509/*
510 * Scan the .text section to see if there are any relocations in it.
511 * Should rewrite this to check PT_LOAD sections that are marked
512 * Executable rather than the section named '.text'.
513 */
277static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 514static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
278{ 515{
279 unsigned long s, r, rmax; 516 unsigned long s, r, rmax;
280 void *symtab_void, *strtab_void, *text_void; 517 void *symtab_void, *strtab_void, *text_void;
281 518
302 Elf ## B ## _Rela *rela; \ 539 Elf ## B ## _Rela *rela; \
303 /* search the section headers for relocations */ \ 540 /* search the section headers for relocations */ \
304 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 541 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
305 uint32_t sh_type = EGET(shdr[s].sh_type); \ 542 uint32_t sh_type = EGET(shdr[s].sh_type); \
306 if (sh_type == SHT_REL) { \ 543 if (sh_type == SHT_REL) { \
307 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 544 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
308 rela = NULL; \ 545 rela = NULL; \
309 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 546 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
310 } else if (sh_type == SHT_RELA) { \ 547 } else if (sh_type == SHT_RELA) { \
311 rel = NULL; \ 548 rel = NULL; \
312 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 549 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
313 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 550 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
314 } else \ 551 } else \
315 continue; \ 552 continue; \
316 /* now see if any of the relocs are in the .text */ \ 553 /* now see if any of the relocs are in the .text */ \
317 for (r = 0; r < rmax; ++r) { \ 554 for (r = 0; r < rmax; ++r) { \
332 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 569 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
333 if (be_verbose <= 2) continue; \ 570 if (be_verbose <= 2) continue; \
334 } else \ 571 } else \
335 *found_textrels = 1; \ 572 *found_textrels = 1; \
336 /* locate this relocation symbol name */ \ 573 /* locate this relocation symbol name */ \
337 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 574 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
338 if ((void*)sym > (void*)elf->data_end) { \ 575 if ((void*)sym > elf->data_end) { \
339 warn("%s: corrupt ELF symbol", elf->filename); \ 576 warn("%s: corrupt ELF symbol", elf->filename); \
340 continue; \ 577 continue; \
341 } \ 578 } \
342 sym_max = ELF ## B ## _R_SYM(r_info); \ 579 sym_max = ELF ## B ## _R_SYM(r_info); \
343 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 580 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
346 sym = NULL; \ 583 sym = NULL; \
347 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 584 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
348 /* show the raw details about this reloc */ \ 585 /* show the raw details about this reloc */ \
349 printf(" %s: ", elf->base_filename); \ 586 printf(" %s: ", elf->base_filename); \
350 if (sym && sym->st_name) \ 587 if (sym && sym->st_name) \
351 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 588 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
352 else \ 589 else \
353 printf("(memory/fake?)"); \ 590 printf("(memory/data?)"); \
354 printf(" [0x%lX]", (unsigned long)r_offset); \ 591 printf(" [0x%lX]", (unsigned long)r_offset); \
355 /* now try to find the closest symbol that this rel is probably in */ \ 592 /* now try to find the closest symbol that this rel is probably in */ \
356 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 593 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
357 func = NULL; \ 594 func = NULL; \
358 offset_tmp = 0; \ 595 offset_tmp = 0; \
359 while (sym_max--) { \ 596 while (sym_max--) { \
360 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 597 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
361 func = sym; \ 598 func = sym; \
362 offset_tmp = EGET(sym->st_value); \ 599 offset_tmp = EGET(sym->st_value); \
363 } \ 600 } \
364 ++sym; \ 601 ++sym; \
365 } \ 602 } \
366 printf(" in "); \ 603 printf(" in "); \
367 if (func && func->st_name) \ 604 if (func && func->st_name) { \
368 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 605 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
606 if (r_offset > EGET(func->st_size)) \
607 printf("(optimized out: previous %s)", func_name); \
369 else \ 608 else \
370 printf("(NULL: fake?)"); \ 609 printf("%s", func_name); \
610 } else \
611 printf("(optimized out)"); \
371 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 612 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
613 if (be_verbose && objdump) { \
614 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
615 char *sysbuf; \
616 size_t syslen; \
617 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
618 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
619 sysbuf = xmalloc(syslen); \
620 if (end_addr < r_offset) \
621 /* not uncommon when things are optimized out */ \
622 end_addr = r_offset + 0x100; \
623 snprintf(sysbuf, syslen, sysfmt, \
624 objdump, \
625 (unsigned long)offset_tmp, \
626 (unsigned long)end_addr, \
627 elf->filename, \
628 (unsigned long)r_offset); \
629 fflush(stdout); \
630 if (system(sysbuf)) {/* don't care */} \
631 fflush(stdout); \
632 free(sysbuf); \
633 } \
372 } \ 634 } \
373 } } 635 } }
374 SHOW_TEXTRELS(32) 636 SHOW_TEXTRELS(32)
375 SHOW_TEXTRELS(64) 637 SHOW_TEXTRELS(64)
376 } 638 }
378 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 640 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
379 641
380 return NULL; 642 return NULL;
381} 643}
382 644
383static void rpath_security_checks(elfobj *, char *, const char *);
384static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type) 645static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
385{ 646{
386 struct stat st; 647 struct stat st;
387 switch (*item) { 648 switch (*item) {
388 case '/': break; 649 case '/': break;
394 warnf("Security problem NULL %s in %s", dt_type, elf->filename); 655 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
395 break; 656 break;
396 case '$': 657 case '$':
397 if (fstat(elf->fd, &st) != -1) 658 if (fstat(elf->fd, &st) != -1)
398 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 659 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
399 warnf("Security problem with %s='%s' in %s with mode set of %o", 660 warnf("Security problem with %s='%s' in %s with mode set of %o",
400 dt_type, item, elf->filename, st.st_mode & 07777); 661 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
401 break; 662 break;
402 default: 663 default:
403 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename); 664 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
404 break; 665 break;
405 } 666 }
406} 667}
407static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 668static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
408{ 669{
409 unsigned long i, s; 670 unsigned long i;
410 char *rpath, *runpath, **r; 671 char *rpath, *runpath, **r;
411 void *strtbl_void; 672 void *strtbl_void;
412 673
413 if (!show_rpath) return; 674 if (!show_rpath) return;
414 675
425 Elf ## B ## _Off offset; \ 686 Elf ## B ## _Off offset; \
426 Elf ## B ## _Xword word; \ 687 Elf ## B ## _Xword word; \
427 /* Scan all the program headers */ \ 688 /* Scan all the program headers */ \
428 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 689 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
429 /* Just scan dynamic headers */ \ 690 /* Just scan dynamic headers */ \
430 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 691 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
431 offset = EGET(phdr[i].p_offset); \ 692 offset = EGET(phdr[i].p_offset); \
432 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 693 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
433 /* Just scan dynamic RPATH/RUNPATH headers */ \ 694 /* Just scan dynamic RPATH/RUNPATH headers */ \
434 dyn = DYN ## B (elf->data + offset); \ 695 dyn = DYN ## B (elf->vdata + offset); \
435 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 696 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
436 if (word == DT_RPATH) { \ 697 if (word == DT_RPATH) { \
437 r = &rpath; \ 698 r = &rpath; \
438 } else if (word == DT_RUNPATH) { \ 699 } else if (word == DT_RUNPATH) { \
439 r = &runpath; \ 700 r = &runpath; \
443 } \ 704 } \
444 /* Verify the memory is somewhat sane */ \ 705 /* Verify the memory is somewhat sane */ \
445 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 706 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
446 if (offset < (Elf ## B ## _Off)elf->len) { \ 707 if (offset < (Elf ## B ## _Off)elf->len) { \
447 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 708 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
448 *r = (char*)(elf->data + offset); \ 709 *r = elf->data + offset; \
449 /* cache the length in case we need to nuke this section later on */ \ 710 /* cache the length in case we need to nuke this section later on */ \
450 if (fix_elf) \ 711 if (fix_elf) \
451 offset = strlen(*r); \ 712 offset = strlen(*r); \
452 /* If quiet, don't output paths in ld.so.conf */ \ 713 /* If quiet, don't output paths in ld.so.conf */ \
453 if (be_quiet) { \ 714 if (be_quiet) { \
459 /* scan each path in : delimited list */ \ 720 /* scan each path in : delimited list */ \
460 while (start) { \ 721 while (start) { \
461 rpath_security_checks(elf, start, get_elfdtype(word)); \ 722 rpath_security_checks(elf, start, get_elfdtype(word)); \
462 end = strchr(start, ':'); \ 723 end = strchr(start, ':'); \
463 len = (end ? abs(end - start) : strlen(start)); \ 724 len = (end ? abs(end - start) : strlen(start)); \
464 if (use_ldcache) \ 725 if (use_ldcache) { \
465 for (s = 0; ldpaths[s]; ++s) \ 726 size_t n; \
727 const char *ldpath; \
728 array_for_each(ldpaths, n, ldpath) \
466 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 729 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
467 *r = end; \ 730 *r = end; \
468 /* corner case ... if RPATH reads "/usr/lib:", we want \ 731 /* corner case ... if RPATH reads "/usr/lib:", we want \
469 * to show ':' rather than '' */ \ 732 * to show ':' rather than '' */ \
470 if (end && end[1] != '\0') \ 733 if (end && end[1] != '\0') \
471 (*r)++; \ 734 (*r)++; \
472 break; \ 735 break; \
473 } \ 736 } \
737 } \
474 if (!*r || !end) \ 738 if (!*r || !end) \
475 break; \ 739 break; \
476 else \ 740 else \
477 start = start + len + 1; \ 741 start = start + len + 1; \
478 } \ 742 } \
544 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 808 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
545 else if (!be_quiet) 809 else if (!be_quiet)
546 xstrcat(ret, " - ", ret_len); 810 xstrcat(ret, " - ", ret_len);
547} 811}
548 812
813/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
549#define LDSO_CACHE_MAGIC "ld.so-" 814#define LDSO_CACHE_MAGIC "ld.so-"
550#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 815#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
551#define LDSO_CACHE_VER "1.7.0" 816#define LDSO_CACHE_VER "1.7.0"
552#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 817#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
553#define FLAG_ANY -1 818#define FLAG_ANY -1
562#define FLAG_X8664_LIB64 0x0300 827#define FLAG_X8664_LIB64 0x0300
563#define FLAG_S390_LIB64 0x0400 828#define FLAG_S390_LIB64 0x0400
564#define FLAG_POWERPC_LIB64 0x0500 829#define FLAG_POWERPC_LIB64 0x0500
565#define FLAG_MIPS64_LIBN32 0x0600 830#define FLAG_MIPS64_LIBN32 0x0600
566#define FLAG_MIPS64_LIBN64 0x0700 831#define FLAG_MIPS64_LIBN64 0x0700
832#define FLAG_X8664_LIBX32 0x0800
833#define FLAG_ARM_LIBHF 0x0900
834#define FLAG_AARCH64_LIB64 0x0a00
567 835
568static char *lookup_cache_lib(elfobj *, char *); 836#if defined(__GLIBC__) || defined(__UCLIBC__)
837
569static char *lookup_cache_lib(elfobj *elf, char *fname) 838static char *lookup_cache_lib(elfobj *elf, const char *fname)
570{ 839{
571 int fd = 0; 840 int fd;
572 char *strs; 841 char *strs;
573 static char buf[__PAX_UTILS_PATH_MAX] = ""; 842 static char buf[__PAX_UTILS_PATH_MAX] = "";
574 const char *cachefile = "/etc/ld.so.cache"; 843 const char *cachefile = root_rel_path("/etc/ld.so.cache");
575 struct stat st; 844 struct stat st;
576 845
577 typedef struct { 846 typedef struct {
578 char magic[LDSO_CACHE_MAGIC_LEN]; 847 char magic[LDSO_CACHE_MAGIC_LEN];
579 char version[LDSO_CACHE_VER_LEN]; 848 char version[LDSO_CACHE_VER_LEN];
589 libentry_t *libent; 858 libentry_t *libent;
590 859
591 if (fname == NULL) 860 if (fname == NULL)
592 return NULL; 861 return NULL;
593 862
594 if (ldcache == 0) { 863 if (ldcache == NULL) {
595 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 864 if (fstatat(root_fd, cachefile, &st, 0))
865 return NULL;
866
867 fd = openat(root_fd, cachefile, O_RDONLY);
868 if (fd == -1)
596 return NULL; 869 return NULL;
597 870
598 /* cache these values so we only map/unmap the cache file once */ 871 /* cache these values so we only map/unmap the cache file once */
599 ldcache_size = st.st_size; 872 ldcache_size = st.st_size;
600 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 873 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
601
602 close(fd); 874 close(fd);
603 875
604 if (ldcache == (caddr_t)-1) { 876 if (ldcache == MAP_FAILED) {
605 ldcache = 0; 877 ldcache = NULL;
606 return NULL; 878 return NULL;
607 } 879 }
608 880
609 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 881 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
882 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
883 {
884 munmap(ldcache, ldcache_size);
885 ldcache = NULL;
610 return NULL; 886 return NULL;
611 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
612 return NULL;
613 } 887 }
888 } else
889 header = ldcache;
614 890
615 header = (header_t *) ldcache;
616 libent = (libentry_t *) (ldcache + sizeof(header_t)); 891 libent = ldcache + sizeof(header_t);
617 strs = (char *) &libent[header->nlibs]; 892 strs = (char *) &libent[header->nlibs];
618 893
619 for (fd = 0; fd < header->nlibs; fd++) { 894 for (fd = 0; fd < header->nlibs; ++fd) {
620 /* this should be more fine grained, but for now we assume that 895 /* This should be more fine grained, but for now we assume that
621 * diff arches will not be cached together. and we ignore the 896 * diff arches will not be cached together, and we ignore the
622 * the different multilib mips cases. */ 897 * the different multilib mips cases.
898 */
623 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 899 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
624 continue; 900 continue;
625 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 901 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
626 continue; 902 continue;
627 903
628 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 904 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
629 continue; 905 continue;
906
907 /* Return first hit because that is how the ldso rolls */
630 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 908 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
909 break;
631 } 910 }
911
632 return buf; 912 return buf;
633} 913}
634 914
915#elif defined(__NetBSD__)
916static char *lookup_cache_lib(elfobj *elf, const char *fname)
917{
918 static char buf[__PAX_UTILS_PATH_MAX] = "";
919 static struct stat st;
920 size_t n;
921 char *ldpath;
922
923 array_for_each(ldpath, n, ldpath) {
924 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
925 continue; /* if the pathname is too long, or something went wrong, ignore */
926
927 if (stat(buf, &st) != 0)
928 continue; /* if the lib doesn't exist in *ldpath, look further */
929
930 /* NetBSD doesn't actually do sanity checks, it just loads the file
931 * and if that doesn't work, continues looking in other directories.
932 * This cannot easily be safely emulated, unfortunately. For now,
933 * just assume that if it exists, it's a valid library. */
934
935 return buf;
936 }
937
938 /* not found in any path */
939 return NULL;
940}
941#else
942#ifdef __ELF__
943#warning Cache support not implemented for your target
944#endif
945static char *lookup_cache_lib(elfobj *elf, const char *fname)
946{
947 return NULL;
948}
949#endif
950
951static char *lookup_config_lib(const char *fname)
952{
953 static char buf[__PAX_UTILS_PATH_MAX] = "";
954 const char *ldpath;
955 size_t n;
956
957 array_for_each(ldpaths, n, ldpath) {
958 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
959 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
960 return buf;
961 }
962
963 return NULL;
964}
635 965
636static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 966static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
637{ 967{
638 unsigned long i; 968 unsigned long i;
639 char *needed; 969 char *needed;
640 void *strtbl_void; 970 void *strtbl_void;
641 char *p; 971 char *p;
642 972
973 /*
974 * -n -> op==0 -> print all
975 * -N -> op==1 -> print requested
976 */
643 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 977 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
978 return NULL;
644 979
645 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 980 strtbl_void = elf_findsecbyname(elf, ".dynstr");
646 981
647 if (elf->phdr && strtbl_void) { 982 if (elf->phdr && strtbl_void) {
648#define SHOW_NEEDED(B) \ 983#define SHOW_NEEDED(B) \
650 Elf ## B ## _Dyn *dyn; \ 985 Elf ## B ## _Dyn *dyn; \
651 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 986 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
652 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 987 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
653 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 988 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
654 Elf ## B ## _Off offset; \ 989 Elf ## B ## _Off offset; \
990 size_t matched = 0; \
991 /* Walk all the program headers to find the PT_DYNAMIC */ \
655 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 992 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
656 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 993 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
994 continue; \
657 offset = EGET(phdr[i].p_offset); \ 995 offset = EGET(phdr[i].p_offset); \
658 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 996 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
997 continue; \
998 /* Walk all the dynamic tags to find NEEDED entries */ \
659 dyn = DYN ## B (elf->data + offset); \ 999 dyn = DYN ## B (elf->vdata + offset); \
660 while (EGET(dyn->d_tag) != DT_NULL) { \ 1000 while (EGET(dyn->d_tag) != DT_NULL) { \
661 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 1001 if (EGET(dyn->d_tag) == DT_NEEDED) { \
662 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1002 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
663 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1003 if (offset >= (Elf ## B ## _Off)elf->len) { \
664 ++dyn; \ 1004 ++dyn; \
665 continue; \ 1005 continue; \
666 } \ 1006 } \
667 needed = (char*)(elf->data + offset); \ 1007 needed = elf->data + offset; \
668 if (op == 0) { \ 1008 if (op == 0) { \
1009 /* -n -> print all entries */ \
669 if (!be_wewy_wewy_quiet) { \ 1010 if (!be_wewy_wewy_quiet) { \
670 if (*found_needed) xchrcat(ret, ',', ret_len); \ 1011 if (*found_needed) xchrcat(ret, ',', ret_len); \
671 if (use_ldcache) \ 1012 if (use_ldpath) { \
1013 if ((p = lookup_config_lib(needed)) != NULL) \
1014 needed = p; \
1015 } else if (use_ldcache) { \
672 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 1016 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
673 needed = p; \ 1017 needed = p; \
1018 } \
674 xstrcat(ret, needed, ret_len); \ 1019 xstrcat(ret, needed, ret_len); \
675 } \ 1020 } \
676 *found_needed = 1; \ 1021 *found_needed = 1; \
677 } else { \ 1022 } else { \
678 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1023 /* -N -> print matching entries */ \
1024 size_t n; \
1025 const char *find_lib_name; \
1026 \
1027 array_for_each(find_lib_arr, n, find_lib_name) { \
1028 int invert = 1; \
1029 if (find_lib_name[0] == '!') \
1030 invert = 0, ++find_lib_name; \
1031 if (!strcmp(find_lib_name, needed) == invert) \
1032 ++matched; \
1033 } \
1034 \
1035 if (matched == array_cnt(find_lib_arr)) { \
679 *found_lib = 1; \ 1036 *found_lib = 1; \
680 return (be_wewy_wewy_quiet ? NULL : needed); \ 1037 return (be_wewy_wewy_quiet ? NULL : find_lib); \
681 } \ 1038 } \
682 } \ 1039 } \
683 } \ 1040 } \
684 ++dyn; \ 1041 ++dyn; \
685 } \ 1042 } \
707 *found_interp = 1; \ 1064 *found_interp = 1; \
708 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1065 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
709 } 1066 }
710 SHOW_INTERP(32) 1067 SHOW_INTERP(32)
711 SHOW_INTERP(64) 1068 SHOW_INTERP(64)
1069 } else {
1070 /* Walk all the program headers to find the PT_INTERP */
1071#define SHOW_PT_INTERP(B) \
1072 if (elf->elf_class == ELFCLASS ## B) { \
1073 unsigned long i; \
1074 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1075 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1076 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1077 if (EGET(phdr[i].p_type) != PT_INTERP) \
1078 continue; \
1079 *found_interp = 1; \
1080 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1081 } \
712 } 1082 }
1083 SHOW_PT_INTERP(32)
1084 SHOW_PT_INTERP(64)
1085 }
1086
713 return NULL; 1087 return NULL;
714} 1088}
715static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1089static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
716{ 1090{
717 unsigned long i; 1091 unsigned long i;
718 struct stat s; 1092 struct stat s;
1093 bool dynamic = false;
719 1094
720 if (!show_bind) return NULL; 1095 if (!show_bind) return NULL;
721 if (!elf->phdr) return NULL; 1096 if (!elf->phdr) return NULL;
722 1097
723#define SHOW_BIND(B) \ 1098#define SHOW_BIND(B) \
725 Elf ## B ## _Dyn *dyn; \ 1100 Elf ## B ## _Dyn *dyn; \
726 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1101 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
727 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1102 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
728 Elf ## B ## _Off offset; \ 1103 Elf ## B ## _Off offset; \
729 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1104 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
730 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1105 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1106 dynamic = true; \
731 offset = EGET(phdr[i].p_offset); \ 1107 offset = EGET(phdr[i].p_offset); \
732 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1108 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
733 dyn = DYN ## B (elf->data + offset); \ 1109 dyn = DYN ## B (elf->vdata + offset); \
734 while (EGET(dyn->d_tag) != DT_NULL) { \ 1110 while (EGET(dyn->d_tag) != DT_NULL) { \
735 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1111 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
736 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1112 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
737 { \ 1113 { \
738 if (be_quiet) return NULL; \ 1114 if (be_quiet) return NULL; \
746 SHOW_BIND(32) 1122 SHOW_BIND(32)
747 SHOW_BIND(64) 1123 SHOW_BIND(64)
748 1124
749 if (be_wewy_wewy_quiet) return NULL; 1125 if (be_wewy_wewy_quiet) return NULL;
750 1126
1127 /* don't output anything if quiet mode and the ELF is static or not setuid */
751 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1128 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
752 return NULL; 1129 return NULL;
753 } else { 1130 } else {
754 *found_bind = 1; 1131 *found_bind = 1;
755 return (char *) "LAZY"; 1132 return dynamic ? "LAZY" : "STATIC";
756 } 1133 }
757} 1134}
758static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1135static char *scanelf_file_soname(elfobj *elf, char *found_soname)
759{ 1136{
760 unsigned long i; 1137 unsigned long i;
772 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1149 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
773 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1150 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
774 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1151 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
775 Elf ## B ## _Off offset; \ 1152 Elf ## B ## _Off offset; \
776 /* only look for soname in shared objects */ \ 1153 /* only look for soname in shared objects */ \
777 if (ehdr->e_type != ET_DYN) \ 1154 if (EGET(ehdr->e_type) != ET_DYN) \
778 return NULL; \ 1155 return NULL; \
779 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1156 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
780 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1157 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
781 offset = EGET(phdr[i].p_offset); \ 1158 offset = EGET(phdr[i].p_offset); \
782 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1159 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
783 dyn = DYN ## B (elf->data + offset); \ 1160 dyn = DYN ## B (elf->vdata + offset); \
784 while (EGET(dyn->d_tag) != DT_NULL) { \ 1161 while (EGET(dyn->d_tag) != DT_NULL) { \
785 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1162 if (EGET(dyn->d_tag) == DT_SONAME) { \
786 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1163 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
787 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1164 if (offset >= (Elf ## B ## _Off)elf->len) { \
788 ++dyn; \ 1165 ++dyn; \
789 continue; \ 1166 continue; \
790 } \ 1167 } \
791 soname = (char*)(elf->data + offset); \ 1168 soname = elf->data + offset; \
792 *found_soname = 1; \ 1169 *found_soname = 1; \
793 return (be_wewy_wewy_quiet ? NULL : soname); \ 1170 return (be_wewy_wewy_quiet ? NULL : soname); \
794 } \ 1171 } \
795 ++dyn; \ 1172 ++dyn; \
796 } \ 1173 } \
799 SHOW_SONAME(64) 1176 SHOW_SONAME(64)
800 } 1177 }
801 1178
802 return NULL; 1179 return NULL;
803} 1180}
1181
1182/*
1183 * We support the symbol form:
1184 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1185 * If the symbol name is empty, then all symbols are matched.
1186 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1187 * Do not rely on this output format at all.
1188 * Otherwise the symbol name is used to search (either regex or string compare).
1189 * If the first char of the symbol name is a plus ("+"), then only match
1190 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1191 * Putting modifiers in between the percent signs allows for more in depth
1192 * filters. There are groups of modifiers. If you don't specify a member
1193 * of a group, then all types in that group are matched. The current
1194 * groups and their types are:
1195 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1196 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1197 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1198 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1199 * You can search for multiple symbols at once by seperating with a comma (",").
1200 *
1201 * Some examples:
1202 * ELFs with a weak function "foo":
1203 * scanelf -s %wf%foo <ELFs>
1204 * ELFs that define the symbol "main":
1205 * scanelf -s +main <ELFs>
1206 * scanelf -s %d%main <ELFs>
1207 * ELFs that refer to the undefined symbol "brk":
1208 * scanelf -s -brk <ELFs>
1209 * scanelf -s %u%brk <ELFs>
1210 * All global defined objects in an ELF:
1211 * scanelf -s %ogd% <ELF>
1212 */
1213static void
1214scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1215 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1216{
1217 const char *this_sym;
1218 size_t n;
1219
1220 array_for_each(find_sym_arr, n, this_sym) {
1221 bool inc_notype, inc_object, inc_func, inc_file,
1222 inc_local, inc_global, inc_weak,
1223 inc_def, inc_undef, inc_abs, inc_common;
1224
1225 /* symbol selection! */
1226 inc_notype = inc_object = inc_func = inc_file = \
1227 inc_local = inc_global = inc_weak = \
1228 inc_def = inc_undef = inc_abs = inc_common = \
1229 (*this_sym != '%');
1230
1231 /* parse the contents of %...% */
1232 if (!inc_notype) {
1233 while (*(this_sym++)) {
1234 if (*this_sym == '%') {
1235 ++this_sym;
1236 break;
1237 }
1238 switch (*this_sym) {
1239 case 'n': inc_notype = true; break;
1240 case 'o': inc_object = true; break;
1241 case 'f': inc_func = true; break;
1242 case 'F': inc_file = true; break;
1243 case 'l': inc_local = true; break;
1244 case 'g': inc_global = true; break;
1245 case 'w': inc_weak = true; break;
1246 case 'd': inc_def = true; break;
1247 case 'u': inc_undef = true; break;
1248 case 'a': inc_abs = true; break;
1249 case 'c': inc_common = true; break;
1250 default: err("invalid symbol selector '%c'", *this_sym);
1251 }
1252 }
1253
1254 /* If no types are matched, not match all */
1255 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1256 inc_notype = inc_object = inc_func = inc_file = true;
1257 if (!inc_local && !inc_global && !inc_weak)
1258 inc_local = inc_global = inc_weak = true;
1259 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1260 inc_def = inc_undef = inc_abs = inc_common = true;
1261
1262 /* backwards compat for defined/undefined short hand */
1263 } else if (*this_sym == '+') {
1264 inc_undef = false;
1265 ++this_sym;
1266 } else if (*this_sym == '-') {
1267 inc_def = inc_abs = inc_common = false;
1268 ++this_sym;
1269 }
1270
1271 /* filter symbols */
1272 if ((!inc_notype && stt == STT_NOTYPE) || \
1273 (!inc_object && stt == STT_OBJECT) || \
1274 (!inc_func && stt == STT_FUNC ) || \
1275 (!inc_file && stt == STT_FILE ) || \
1276 (!inc_local && stb == STB_LOCAL ) || \
1277 (!inc_global && stb == STB_GLOBAL) || \
1278 (!inc_weak && stb == STB_WEAK ) || \
1279 (!inc_def && shn && shn < SHN_LORESERVE) || \
1280 (!inc_undef && shn == SHN_UNDEF ) || \
1281 (!inc_abs && shn == SHN_ABS ) || \
1282 (!inc_common && shn == SHN_COMMON))
1283 continue;
1284
1285 if (*this_sym == '*') {
1286 /* a "*" symbol gets you debug output */
1287 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1288 ((*found_sym == 0) ? "\n\t" : "\t"),
1289 elf->base_filename,
1290 size,
1291 get_elfstttype(stt),
1292 get_elfstbtype(stb),
1293 get_elfshntype(shn),
1294 symname);
1295 goto matched;
1296
1297 } else {
1298 if (g_match) {
1299 /* regex match the symbol */
1300 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1301 continue;
1302
1303 } else if (*this_sym) {
1304 /* give empty symbols a "pass", else do a normal compare */
1305 const size_t len = strlen(this_sym);
1306 if (!(strncmp(this_sym, symname, len) == 0 &&
1307 /* Accept unversioned symbol names */
1308 (symname[len] == '\0' || symname[len] == '@')))
1309 continue;
1310 }
1311
1312 if (be_semi_verbose) {
1313 char buf[1024];
1314 snprintf(buf, sizeof(buf), "%lX %s %s",
1315 size,
1316 get_elfstttype(stt),
1317 this_sym);
1318 *ret = xstrdup(buf);
1319 } else {
1320 if (*ret) xchrcat(ret, ',', ret_len);
1321 xstrcat(ret, symname, ret_len);
1322 }
1323
1324 goto matched;
1325 }
1326 }
1327
1328 return;
1329
1330 matched:
1331 *found_sym = 1;
1332}
1333
804static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1334static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
805{ 1335{
806 unsigned long i;
807 char *ret; 1336 char *ret;
808 void *symtab_void, *strtab_void; 1337 void *symtab_void, *strtab_void;
809 1338
810 if (!find_sym) return NULL; 1339 if (!find_sym) return NULL;
811 ret = find_sym; 1340 ret = NULL;
812 1341
813 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1342 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
814 1343
815 if (symtab_void && strtab_void) { 1344 if (symtab_void && strtab_void) {
816#define FIND_SYM(B) \ 1345#define FIND_SYM(B) \
817 if (elf->elf_class == ELFCLASS ## B) { \ 1346 if (elf->elf_class == ELFCLASS ## B) { \
818 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1347 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
819 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1348 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
820 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1349 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
821 unsigned long cnt = EGET(symtab->sh_entsize); \ 1350 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
822 char *symname; \ 1351 char *symname; \
1352 size_t ret_len = 0; \
823 if (cnt) \ 1353 if (cnt) \
824 cnt = EGET(symtab->sh_size) / cnt; \ 1354 cnt = EGET(symtab->sh_size) / cnt; \
825 for (i = 0; i < cnt; ++i) { \ 1355 for (i = 0; i < cnt; ++i) { \
1356 if ((void*)sym > elf->data_end) { \
1357 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1358 goto break_out; \
1359 } \
826 if (sym->st_name) { \ 1360 if (sym->st_name) { \
1361 /* make sure the symbol name is in acceptable memory range */ \
827 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1362 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
828 if ((void*)symname > (void*)elf->data_end) { \ 1363 if ((void*)symname > elf->data_end) { \
829 warnf("%s: corrupt ELF symbols", elf->filename); \ 1364 warnf("%s: corrupt ELF symbols", elf->filename); \
1365 ++sym; \
830 continue; \ 1366 continue; \
831 } \ 1367 } \
832 if (*find_sym == '*') { \ 1368 scanelf_match_symname(elf, found_sym, \
833 printf("%s(%s) %5lX %15s %s\n", \ 1369 &ret, &ret_len, symname, \
834 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1370 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
835 elf->base_filename, \ 1371 ELF##B##_ST_BIND(EGET(sym->st_info)), \
836 (unsigned long)sym->st_size, \ 1372 EGET(sym->st_shndx), \
837 get_elfstttype(sym->st_info), \ 1373 /* st_size can be 64bit, but no one is really that big, so screw em */ \
838 symname); \ 1374 EGET(sym->st_size)); \
839 *found_sym = 1; \
840 } else { \
841 char *this_sym, *next_sym; \
842 this_sym = find_sym; \
843 do { \
844 next_sym = strchr(this_sym, ','); \
845 if (next_sym == NULL) \
846 next_sym = this_sym + strlen(this_sym); \
847 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
848 (strcmp(symname, versioned_symname) == 0)) { \
849 ret = this_sym; \
850 (*found_sym)++; \
851 goto break_out; \
852 } \
853 this_sym = next_sym + 1; \
854 } while (*next_sym != '\0'); \
855 } \
856 } \ 1375 } \
857 ++sym; \ 1376 ++sym; \
858 } } 1377 } \
1378 }
859 FIND_SYM(32) 1379 FIND_SYM(32)
860 FIND_SYM(64) 1380 FIND_SYM(64)
861 } 1381 }
862 1382
863break_out: 1383break_out:
866 if (*find_sym != '*' && *found_sym) 1386 if (*find_sym != '*' && *found_sym)
867 return ret; 1387 return ret;
868 if (be_quiet) 1388 if (be_quiet)
869 return NULL; 1389 return NULL;
870 else 1390 else
871 return (char *)" - "; 1391 return " - ";
872} 1392}
873 1393
1394static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1395{
1396 if (!find_section)
1397 return NULL;
1398
1399#define FIND_SECTION(B) \
1400 if (elf->elf_class == ELFCLASS ## B) { \
1401 size_t matched, n; \
1402 int invert; \
1403 const char *section_name; \
1404 Elf ## B ## _Shdr *section; \
1405 \
1406 matched = 0; \
1407 array_for_each(find_section_arr, n, section_name) { \
1408 invert = (*section_name == '!' ? 1 : 0); \
1409 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1410 if ((section == NULL && invert) || (section != NULL && !invert)) \
1411 ++matched; \
1412 } \
1413 \
1414 if (matched == array_cnt(find_section_arr)) \
1415 *found_section = 1; \
1416 }
1417 FIND_SECTION(32)
1418 FIND_SECTION(64)
1419
1420 if (be_wewy_wewy_quiet)
1421 return NULL;
1422
1423 if (*found_section)
1424 return find_section;
1425
1426 if (be_quiet)
1427 return NULL;
1428 else
1429 return " - ";
1430}
874 1431
875/* scan an elf file and show all the fun stuff */ 1432/* scan an elf file and show all the fun stuff */
876#define prints(str) write(fileno(stdout), str, strlen(str)) 1433#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
877static int scanelf_elfobj(elfobj *elf) 1434static int scanelf_elfobj(elfobj *elf)
878{ 1435{
879 unsigned long i; 1436 unsigned long i;
880 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1437 char found_pax, found_phdr, found_relro, found_load, found_textrel,
881 found_rpath, found_needed, found_interp, found_bind, found_soname, 1438 found_rpath, found_needed, found_interp, found_bind, found_soname,
882 found_sym, found_lib, found_file, found_textrels; 1439 found_sym, found_lib, found_file, found_textrels, found_section;
883 static char *out_buffer = NULL; 1440 static char *out_buffer = NULL;
884 static size_t out_len; 1441 static size_t out_len;
885 1442
886 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1443 found_pax = found_phdr = found_relro = found_load = found_textrel = \
887 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1444 found_rpath = found_needed = found_interp = found_bind = found_soname = \
888 found_sym = found_lib = found_file = found_textrels = 0; 1445 found_sym = found_lib = found_file = found_textrels = found_section = 0;
889 1446
890 if (be_verbose > 2) 1447 if (be_verbose > 2)
891 printf("%s: scanning file {%s,%s}\n", elf->filename, 1448 printf("%s: scanning file {%s,%s}\n", elf->filename,
892 get_elfeitype(EI_CLASS, elf->elf_class), 1449 get_elfeitype(EI_CLASS, elf->elf_class),
893 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1450 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
895 printf("%s: scanning file\n", elf->filename); 1452 printf("%s: scanning file\n", elf->filename);
896 1453
897 /* init output buffer */ 1454 /* init output buffer */
898 if (!out_buffer) { 1455 if (!out_buffer) {
899 out_len = sizeof(char) * 80; 1456 out_len = sizeof(char) * 80;
900 out_buffer = (char*)xmalloc(out_len); 1457 out_buffer = xmalloc(out_len);
901 } 1458 }
902 *out_buffer = '\0'; 1459 *out_buffer = '\0';
903 1460
904 /* show the header */ 1461 /* show the header */
905 if (!be_quiet && show_banner) { 1462 if (!be_quiet && show_banner) {
906 for (i = 0; out_format[i]; ++i) { 1463 for (i = 0; out_format[i]; ++i) {
907 if (!IS_MODIFIER(out_format[i])) continue; 1464 if (!IS_MODIFIER(out_format[i])) continue;
908 1465
909 switch (out_format[++i]) { 1466 switch (out_format[++i]) {
1467 case '+': break;
910 case '%': break; 1468 case '%': break;
911 case '#': break; 1469 case '#': break;
912 case 'F': 1470 case 'F':
913 case 'p': 1471 case 'p':
914 case 'f': prints("FILE "); found_file = 1; break; 1472 case 'f': prints("FILE "); found_file = 1; break;
915 case 'o': prints(" TYPE "); break; 1473 case 'o': prints(" TYPE "); break;
916 case 'x': prints(" PAX "); break; 1474 case 'x': prints(" PAX "); break;
917 case 'e': prints("STK/REL/PTL "); break; 1475 case 'e': prints("STK/REL/PTL "); break;
918 case 't': prints("TEXTREL "); break; 1476 case 't': prints("TEXTREL "); break;
919 case 'r': prints("RPATH "); break; 1477 case 'r': prints("RPATH "); break;
1478 case 'M': prints("CLASS "); break;
1479 case 'l':
920 case 'n': prints("NEEDED "); break; 1480 case 'n': prints("NEEDED "); break;
921 case 'i': prints("INTERP "); break; 1481 case 'i': prints("INTERP "); break;
922 case 'b': prints("BIND "); break; 1482 case 'b': prints("BIND "); break;
1483 case 'Z': prints("SIZE "); break;
923 case 'S': prints("SONAME "); break; 1484 case 'S': prints("SONAME "); break;
924 case 's': prints("SYM "); break; 1485 case 's': prints("SYM "); break;
925 case 'N': prints("LIB "); break; 1486 case 'N': prints("LIB "); break;
926 case 'T': prints("TEXTRELS "); break; 1487 case 'T': prints("TEXTRELS "); break;
1488 case 'k': prints("SECTION "); break;
1489 case 'a': prints("ARCH "); break;
1490 case 'I': prints("OSABI "); break;
1491 case 'Y': prints("EABI "); break;
1492 case 'O': prints("PERM "); break;
1493 case 'D': prints("ENDIAN "); break;
927 default: warnf("'%c' has no title ?", out_format[i]); 1494 default: warnf("'%c' has no title ?", out_format[i]);
928 } 1495 }
929 } 1496 }
930 if (!found_file) prints("FILE "); 1497 if (!found_file) prints("FILE ");
931 prints("\n"); 1498 prints("\n");
935 1502
936 /* dump all the good stuff */ 1503 /* dump all the good stuff */
937 for (i = 0; out_format[i]; ++i) { 1504 for (i = 0; out_format[i]; ++i) {
938 const char *out; 1505 const char *out;
939 const char *tmp; 1506 const char *tmp;
940 1507 static char ubuf[sizeof(unsigned long)*2];
941 /* make sure we trim leading spaces in quiet mode */
942 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
943 *out_buffer = '\0';
944
945 if (!IS_MODIFIER(out_format[i])) { 1508 if (!IS_MODIFIER(out_format[i])) {
946 xchrcat(&out_buffer, out_format[i], &out_len); 1509 xchrcat(&out_buffer, out_format[i], &out_len);
947 continue; 1510 continue;
948 } 1511 }
949 1512
950 out = NULL; 1513 out = NULL;
951 be_wewy_wewy_quiet = (out_format[i] == '#'); 1514 be_wewy_wewy_quiet = (out_format[i] == '#');
1515 be_semi_verbose = (out_format[i] == '+');
952 switch (out_format[++i]) { 1516 switch (out_format[++i]) {
1517 case '+':
953 case '%': 1518 case '%':
954 case '#': 1519 case '#':
955 xchrcat(&out_buffer, out_format[i], &out_len); break; 1520 xchrcat(&out_buffer, out_format[i], &out_len); break;
956 case 'F': 1521 case 'F':
957 found_file = 1; 1522 found_file = 1;
983 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1548 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
984 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1549 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
985 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1550 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
986 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1551 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
987 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1552 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1553 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1554 case 'D': out = get_endian(elf); break;
1555 case 'O': out = strfileperms(elf->filename); break;
988 case 'n': 1556 case 'n':
989 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1557 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
990 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1558 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
991 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1559 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
992 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1560 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
993 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1561 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1562 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1563 case 'a': out = get_elfemtype(elf); break;
1564 case 'I': out = get_elfosabi(elf); break;
1565 case 'Y': out = get_elf_eabi(elf); break;
1566 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
994 default: warnf("'%c' has no scan code?", out_format[i]); 1567 default: warnf("'%c' has no scan code?", out_format[i]);
995 } 1568 }
996 if (out) { 1569 if (out)
997 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
998 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
999 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1000 else
1001 xstrcat(&out_buffer, out, &out_len); 1570 xstrcat(&out_buffer, out, &out_len);
1002 }
1003 } 1571 }
1004 1572
1005#define FOUND_SOMETHING() \ 1573#define FOUND_SOMETHING() \
1006 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1574 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1007 found_rpath || found_needed || found_interp || found_bind || \ 1575 found_rpath || found_needed || found_interp || found_bind || \
1008 found_soname || found_sym || found_lib || found_textrels) 1576 found_soname || found_sym || found_lib || found_textrels || found_section )
1009 1577
1010 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1578 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1011 xchrcat(&out_buffer, ' ', &out_len); 1579 xchrcat(&out_buffer, ' ', &out_len);
1012 xstrcat(&out_buffer, elf->filename, &out_len); 1580 xstrcat(&out_buffer, elf->filename, &out_len);
1013 } 1581 }
1020} 1588}
1021 1589
1022/* scan a single elf */ 1590/* scan a single elf */
1023static int scanelf_elf(const char *filename, int fd, size_t len) 1591static int scanelf_elf(const char *filename, int fd, size_t len)
1024{ 1592{
1025 int ret; 1593 int ret = 1;
1594 size_t n;
1595 const char *match_etype;
1026 elfobj *elf; 1596 elfobj *elf;
1027 1597
1028 /* verify this is real ELF */ 1598 /* Verify this is a real ELF */
1029 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) { 1599 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1030 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 1600 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1031 return 1; 1601 return 2;
1032 }
1033
1034 if (strlen(match_etypes)) {
1035 char sbuf[126];
1036 strncpy(sbuf, match_etypes, sizeof(sbuf));
1037 if (strchr(match_etypes, ',') != NULL) {
1038 char *p;
1039 while((p = strrchr(sbuf, ',')) != NULL) {
1040 *p = 0;
1041 if (atoi(p+1) == get_etype(elf))
1042 goto label_ret;
1043 }
1044 } 1602 }
1045 if (atoi(sbuf) != get_etype(elf)) { 1603
1046 ret = 1; 1604 /* Possibly filter based on ELF bitness */
1605 switch (match_bits) {
1606 case 32:
1607 if (elf->elf_class != ELFCLASS32)
1047 goto label_done; 1608 goto done;
1609 break;
1610 case 64:
1611 if (elf->elf_class != ELFCLASS64)
1612 goto done;
1613 break;
1048 } 1614 }
1049 }
1050 1615
1051label_ret: 1616 /* Possibly filter based on the ELF's e_type field */
1617 array_for_each(match_etypes, n, match_etype)
1618 if (etype_lookup(match_etype) == get_etype(elf))
1619 goto scanit;
1620 if (array_cnt(match_etypes))
1621 goto done;
1622
1623 scanit:
1052 ret = scanelf_elfobj(elf); 1624 ret = scanelf_elfobj(elf);
1053 1625
1054label_done: 1626 done:
1055 unreadelf(elf); 1627 unreadelf(elf);
1056 return ret; 1628 return ret;
1057} 1629}
1058 1630
1059/* scan an archive of elfs */ 1631/* scan an archive of elfs */
1066 1638
1067 ar = ar_open_fd(filename, fd); 1639 ar = ar_open_fd(filename, fd);
1068 if (ar == NULL) 1640 if (ar == NULL)
1069 return 1; 1641 return 1;
1070 1642
1071 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0); 1643 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1072 while ((m=ar_next(ar)) != NULL) { 1644 while ((m = ar_next(ar)) != NULL) {
1645 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1646 if (cur_pos == -1)
1647 errp("lseek() failed");
1073 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size); 1648 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1074 if (elf) { 1649 if (elf) {
1075 scanelf_elfobj(elf); 1650 scanelf_elfobj(elf);
1076 unreadelf(elf); 1651 unreadelf(elf);
1077 } 1652 }
1078 } 1653 }
1079 munmap(ar_buffer, len); 1654 munmap(ar_buffer, len);
1080 1655
1081 return 0; 1656 return 0;
1082} 1657}
1083/* scan a file which may be an elf or an archive or some other magical beast */ 1658/* scan a file which may be an elf or an archive or some other magical beast */
1084static void scanelf_file(const char *filename) 1659static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1085{ 1660{
1661 const struct stat *st = st_cache;
1086 struct stat st; 1662 struct stat symlink_st;
1087 int fd; 1663 int fd;
1088 1664
1089 /* make sure 'filename' exists */
1090 if (lstat(filename, &st) == -1) {
1091 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1092 return;
1093 }
1094
1095 /* always handle regular files and handle symlinked files if no -y */ 1665 /* always handle regular files and handle symlinked files if no -y */
1096 if (S_ISLNK(st.st_mode)) { 1666 if (S_ISLNK(st->st_mode)) {
1097 if (!scan_symlink) return; 1667 if (!scan_symlink)
1098 stat(filename, &st); 1668 return 1;
1669 fstatat(dir_fd, filename, &symlink_st, 0);
1670 st = &symlink_st;
1099 } 1671 }
1672
1100 if (!S_ISREG(st.st_mode)) { 1673 if (!S_ISREG(st->st_mode)) {
1101 if (be_verbose > 2) printf("%s: skipping non-file\n", filename); 1674 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1102 return; 1675 return 1;
1103 } 1676 }
1104 1677
1105 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1) 1678 if (match_perms) {
1679 if ((st->st_mode | match_perms) != st->st_mode)
1680 return 1;
1681 }
1682 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1683 if (fd == -1) {
1684 if (fix_elf && errno == ETXTBSY)
1685 warnp("%s: could not fix", filename);
1686 else if (be_verbose > 2)
1687 printf("%s: skipping file: %s\n", filename, strerror(errno));
1106 return; 1688 return 1;
1689 }
1107 1690
1108 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives) 1691 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1109 /* if it isn't an ELF, maybe it's an .a archive */ 1692 /* if it isn't an ELF, maybe it's an .a archive */
1693 if (scan_archives)
1110 scanelf_archive(filename, fd, st.st_size); 1694 scanelf_archive(filename, fd, st->st_size);
1111 1695
1696 /*
1697 * unreadelf() implicitly closes its fd, so only close it
1698 * when we are returning it in the non-ELF case
1699 */
1112 close(fd); 1700 close(fd);
1701 }
1702
1703 return 0;
1113} 1704}
1114 1705
1115/* scan a directory for ET_EXEC files and print when we find one */ 1706/* scan a directory for ET_EXEC files and print when we find one */
1116static void scanelf_dir(const char *path) 1707static int scanelf_dirat(int dir_fd, const char *path)
1117{ 1708{
1118 register DIR *dir; 1709 register DIR *dir;
1119 register struct dirent *dentry; 1710 register struct dirent *dentry;
1120 struct stat st_top, st; 1711 struct stat st_top, st;
1121 char buf[__PAX_UTILS_PATH_MAX]; 1712 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1122 size_t pathlen = 0, len = 0; 1713 size_t pathlen = 0, len = 0;
1714 int ret = 0;
1715 int subdir_fd;
1123 1716
1124 /* make sure path exists */ 1717 /* make sure path exists */
1125 if (lstat(path, &st_top) == -1) { 1718 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1126 if (be_verbose > 2) printf("%s: does not exist\n", path); 1719 if (be_verbose > 2) printf("%s: does not exist\n", path);
1127 return; 1720 return 1;
1128 } 1721 }
1129 1722
1130 /* ok, if it isn't a directory, assume we can open it */ 1723 /* ok, if it isn't a directory, assume we can open it */
1131 if (!S_ISDIR(st_top.st_mode)) { 1724 if (!S_ISDIR(st_top.st_mode))
1132 scanelf_file(path); 1725 return scanelf_fileat(dir_fd, path, &st_top);
1133 return;
1134 }
1135 1726
1136 /* now scan the dir looking for fun stuff */ 1727 /* now scan the dir looking for fun stuff */
1137 if ((dir = opendir(path)) == NULL) { 1728 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1138 warnf("could not opendir %s: %s", path, strerror(errno)); 1729 if (subdir_fd == -1)
1730 dir = NULL;
1731 else
1732 dir = fdopendir(subdir_fd);
1733 if (dir == NULL) {
1734 if (subdir_fd != -1)
1735 close(subdir_fd);
1736 else if (be_verbose > 2)
1737 printf("%s: skipping dir: %s\n", path, strerror(errno));
1139 return; 1738 return 1;
1140 } 1739 }
1141 if (be_verbose > 1) printf("%s: scanning dir\n", path); 1740 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1142 1741
1143 pathlen = strlen(path); 1742 subpath = stpcpy(buf, path);
1743 if (subpath[-1] != '/')
1744 *subpath++ = '/';
1745 pathlen = subpath - buf;
1144 while ((dentry = readdir(dir))) { 1746 while ((dentry = readdir(dir))) {
1145 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1747 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1146 continue; 1748 continue;
1749
1750 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1751 continue;
1752
1147 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1753 len = strlen(dentry->d_name);
1148 if (len >= sizeof(buf)) { 1754 if (len + pathlen + 1 >= sizeof(buf)) {
1149 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1755 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1150 (unsigned long)len, (unsigned long)sizeof(buf)); 1756 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1151 continue; 1757 continue;
1152 } 1758 }
1153 sprintf(buf, "%s/%s", path, dentry->d_name); 1759 memcpy(subpath, dentry->d_name, len);
1154 if (lstat(buf, &st) != -1) { 1760 subpath[len] = '\0';
1761
1155 if (S_ISREG(st.st_mode)) 1762 if (S_ISREG(st.st_mode))
1156 scanelf_file(buf); 1763 ret = scanelf_fileat(dir_fd, buf, &st);
1157 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1764 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1158 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1765 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1159 scanelf_dir(buf); 1766 ret = scanelf_dirat(dir_fd, buf);
1160 }
1161 } 1767 }
1162 } 1768 }
1163 closedir(dir); 1769 closedir(dir);
1164}
1165 1770
1771 return ret;
1772}
1773static int scanelf_dir(const char *path)
1774{
1775 return scanelf_dirat(root_fd, root_rel_path(path));
1776}
1777
1166static int scanelf_from_file(char *filename) 1778static int scanelf_from_file(const char *filename)
1167{ 1779{
1168 FILE *fp = NULL; 1780 FILE *fp;
1169 char *p; 1781 char *p, *path;
1170 char path[__PAX_UTILS_PATH_MAX]; 1782 size_t len;
1783 int ret;
1171 1784
1172 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1785 if (strcmp(filename, "-") == 0)
1173 fp = stdin; 1786 fp = stdin;
1174 else if ((fp = fopen(filename, "r")) == NULL) 1787 else if ((fp = fopen(filename, "r")) == NULL)
1175 return 1; 1788 return 1;
1176 1789
1177 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1790 path = NULL;
1791 len = 0;
1792 ret = 0;
1793 while (getline(&path, &len, fp) != -1) {
1178 if ((p = strchr(path, '\n')) != NULL) 1794 if ((p = strchr(path, '\n')) != NULL)
1179 *p = 0; 1795 *p = 0;
1180 search_path = path; 1796 search_path = path;
1181 scanelf_dir(path); 1797 ret = scanelf_dir(path);
1182 } 1798 }
1799 free(path);
1800
1183 if (fp != stdin) 1801 if (fp != stdin)
1184 fclose(fp); 1802 fclose(fp);
1803
1185 return 0; 1804 return ret;
1186} 1805}
1187 1806
1188static void load_ld_so_conf() 1807#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1808
1809static int _load_ld_cache_config(const char *fname)
1189{ 1810{
1190 FILE *fp = NULL; 1811 FILE *fp = NULL;
1191 char *p; 1812 char *p, *path;
1192 char path[__PAX_UTILS_PATH_MAX]; 1813 size_t len;
1193 int i = 0; 1814 int curr_fd = -1;
1194 1815
1195 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1816 fp = fopenat_r(root_fd, root_rel_path(fname));
1817 if (fp == NULL)
1196 return; 1818 return -1;
1197 1819
1198 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1820 path = NULL;
1199 if (*path != '/') 1821 len = 0;
1200 continue; 1822 while (getline(&path, &len, fp) != -1) {
1201
1202 if ((p = strrchr(path, '\r')) != NULL) 1823 if ((p = strrchr(path, '\r')) != NULL)
1203 *p = 0; 1824 *p = 0;
1204 if ((p = strchr(path, '\n')) != NULL) 1825 if ((p = strchr(path, '\n')) != NULL)
1205 *p = 0; 1826 *p = 0;
1206 1827
1207 ldpaths[i++] = xstrdup(path); 1828 /* recursive includes of the same file will make this segfault. */
1829 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1830 glob_t gl;
1831 size_t x;
1832 const char *gpath;
1208 1833
1209 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1834 /* re-use existing path buffer ... need to be creative */
1210 break; 1835 if (path[8] != '/')
1836 gpath = memcpy(path + 3, "/etc/", 5);
1837 else
1838 gpath = path + 8;
1839 if (root_fd != AT_FDCWD) {
1840 if (curr_fd == -1) {
1841 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1842 if (fchdir(root_fd))
1843 errp("unable to change to root dir");
1844 }
1845 gpath = root_rel_path(gpath);
1846 }
1847
1848 if (glob(gpath, 0, NULL, &gl) == 0) {
1849 for (x = 0; x < gl.gl_pathc; ++x) {
1850 /* try to avoid direct loops */
1851 if (strcmp(gl.gl_pathv[x], fname) == 0)
1852 continue;
1853 _load_ld_cache_config(gl.gl_pathv[x]);
1854 }
1855 globfree(&gl);
1856 }
1857
1858 /* failed globs are ignored by glibc */
1859 continue;
1211 } 1860 }
1212 ldpaths[i] = NULL; 1861
1862 if (*path != '/')
1863 continue;
1864
1865 xarraypush_str(ldpaths, path);
1866 }
1867 free(path);
1213 1868
1214 fclose(fp); 1869 fclose(fp);
1870
1871 if (curr_fd != -1) {
1872 if (fchdir(curr_fd))
1873 {/* don't care */}
1874 close(curr_fd);
1875 }
1876
1877 return 0;
1878}
1879
1880#elif defined(__FreeBSD__) || defined(__DragonFly__)
1881
1882static int _load_ld_cache_config(const char *fname)
1883{
1884 FILE *fp = NULL;
1885 char *b = NULL, *p;
1886 struct elfhints_hdr hdr;
1887
1888 fp = fopenat_r(root_fd, root_rel_path(fname));
1889 if (fp == NULL)
1890 return -1;
1891
1892 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1893 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1894 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1895 {
1896 fclose(fp);
1897 return -1;
1898 }
1899
1900 b = xmalloc(hdr.dirlistlen + 1);
1901 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1902 fclose(fp);
1903 free(b);
1904 return -1;
1905 }
1906
1907 while ((p = strsep(&b, ":"))) {
1908 if (*p == '\0')
1909 continue;
1910 xarraypush_str(ldpaths, p);
1911 }
1912
1913 free(b);
1914 fclose(fp);
1915 return 0;
1916}
1917
1918#else
1919#ifdef __ELF__
1920#warning Cache config support not implemented for your target
1921#endif
1922static int _load_ld_cache_config(const char *fname)
1923{
1924 return 0;
1925}
1926#endif
1927
1928static void load_ld_cache_config(const char *fname)
1929{
1930 bool scan_l, scan_ul, scan_ull;
1931 size_t n;
1932 const char *ldpath;
1933
1934 _load_ld_cache_config(fname);
1935
1936 scan_l = scan_ul = scan_ull = false;
1937 array_for_each(ldpaths, n, ldpath) {
1938 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1939 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1940 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1941 }
1942
1943 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1944 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1945 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1215} 1946}
1216 1947
1217/* scan /etc/ld.so.conf for paths */ 1948/* scan /etc/ld.so.conf for paths */
1218static void scanelf_ldpath() 1949static void scanelf_ldpath(void)
1219{ 1950{
1220 char scan_l, scan_ul, scan_ull; 1951 size_t n;
1221 int i = 0; 1952 const char *ldpath;
1222 1953
1223 if (!ldpaths[0]) 1954 array_for_each(ldpaths, n, ldpath)
1224 err("Unable to load any paths from ld.so.conf");
1225
1226 scan_l = scan_ul = scan_ull = 0;
1227
1228 while (ldpaths[i]) {
1229 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1230 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1231 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1232 scanelf_dir(ldpaths[i]); 1955 scanelf_dir(ldpath);
1233 ++i;
1234 }
1235
1236 if (!scan_l) scanelf_dir("/lib");
1237 if (!scan_ul) scanelf_dir("/usr/lib");
1238 if (!scan_ull) scanelf_dir("/usr/local/lib");
1239} 1956}
1240 1957
1241/* scan env PATH for paths */ 1958/* scan env PATH for paths */
1242static void scanelf_envpath() 1959static void scanelf_envpath(void)
1243{ 1960{
1244 char *path, *p; 1961 char *path, *p;
1245 1962
1246 path = getenv("PATH"); 1963 path = getenv("PATH");
1247 if (!path) 1964 if (!path)
1254 } 1971 }
1255 1972
1256 free(path); 1973 free(path);
1257} 1974}
1258 1975
1259 1976/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1260/* usage / invocation handling functions */
1261#define PARSE_FLAGS "plRmyAXxetrnLibSs:gN:TaqvF:f:o:E:BhV" 1977#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1262#define a_argument required_argument 1978#define a_argument required_argument
1263static struct option const long_opts[] = { 1979static struct option const long_opts[] = {
1264 {"path", no_argument, NULL, 'p'}, 1980 {"path", no_argument, NULL, 'p'},
1265 {"ldpath", no_argument, NULL, 'l'}, 1981 {"ldpath", no_argument, NULL, 'l'},
1982 {"use-ldpath",no_argument, NULL, 129},
1983 {"root", a_argument, NULL, 128},
1266 {"recursive", no_argument, NULL, 'R'}, 1984 {"recursive", no_argument, NULL, 'R'},
1267 {"mount", no_argument, NULL, 'm'}, 1985 {"mount", no_argument, NULL, 'm'},
1268 {"symlink", no_argument, NULL, 'y'}, 1986 {"symlink", no_argument, NULL, 'y'},
1269 {"archives", no_argument, NULL, 'A'}, 1987 {"archives", no_argument, NULL, 'A'},
1270 {"ldcache", no_argument, NULL, 'L'}, 1988 {"ldcache", no_argument, NULL, 'L'},
1271 {"fix", no_argument, NULL, 'X'}, 1989 {"fix", no_argument, NULL, 'X'},
1990 {"setpax", a_argument, NULL, 'z'},
1272 {"pax", no_argument, NULL, 'x'}, 1991 {"pax", no_argument, NULL, 'x'},
1273 {"header", no_argument, NULL, 'e'}, 1992 {"header", no_argument, NULL, 'e'},
1274 {"textrel", no_argument, NULL, 't'}, 1993 {"textrel", no_argument, NULL, 't'},
1275 {"rpath", no_argument, NULL, 'r'}, 1994 {"rpath", no_argument, NULL, 'r'},
1276 {"needed", no_argument, NULL, 'n'}, 1995 {"needed", no_argument, NULL, 'n'},
1277 {"interp", no_argument, NULL, 'i'}, 1996 {"interp", no_argument, NULL, 'i'},
1278 {"bind", no_argument, NULL, 'b'}, 1997 {"bind", no_argument, NULL, 'b'},
1279 {"soname", no_argument, NULL, 'S'}, 1998 {"soname", no_argument, NULL, 'S'},
1280 {"symbol", a_argument, NULL, 's'}, 1999 {"symbol", a_argument, NULL, 's'},
2000 {"section", a_argument, NULL, 'k'},
1281 {"lib", a_argument, NULL, 'N'}, 2001 {"lib", a_argument, NULL, 'N'},
1282 {"gmatch", no_argument, NULL, 'g'}, 2002 {"gmatch", no_argument, NULL, 'g'},
1283 {"textrels", no_argument, NULL, 'T'}, 2003 {"textrels", no_argument, NULL, 'T'},
1284 {"etype", a_argument, NULL, 'E'}, 2004 {"etype", a_argument, NULL, 'E'},
2005 {"bits", a_argument, NULL, 'M'},
2006 {"endian", no_argument, NULL, 'D'},
2007 {"osabi", no_argument, NULL, 'I'},
2008 {"eabi", no_argument, NULL, 'Y'},
2009 {"perms", a_argument, NULL, 'O'},
2010 {"size", no_argument, NULL, 'Z'},
1285 {"all", no_argument, NULL, 'a'}, 2011 {"all", no_argument, NULL, 'a'},
1286 {"quiet", no_argument, NULL, 'q'}, 2012 {"quiet", no_argument, NULL, 'q'},
1287 {"verbose", no_argument, NULL, 'v'}, 2013 {"verbose", no_argument, NULL, 'v'},
1288 {"format", a_argument, NULL, 'F'}, 2014 {"format", a_argument, NULL, 'F'},
1289 {"from", a_argument, NULL, 'f'}, 2015 {"from", a_argument, NULL, 'f'},
1290 {"file", a_argument, NULL, 'o'}, 2016 {"file", a_argument, NULL, 'o'},
2017 {"nocolor", no_argument, NULL, 'C'},
1291 {"nobanner", no_argument, NULL, 'B'}, 2018 {"nobanner", no_argument, NULL, 'B'},
1292 {"help", no_argument, NULL, 'h'}, 2019 {"help", no_argument, NULL, 'h'},
1293 {"version", no_argument, NULL, 'V'}, 2020 {"version", no_argument, NULL, 'V'},
1294 {NULL, no_argument, NULL, 0x0} 2021 {NULL, no_argument, NULL, 0x0}
1295}; 2022};
1296 2023
1297static const char *opts_help[] = { 2024static const char * const opts_help[] = {
1298 "Scan all directories in PATH environment", 2025 "Scan all directories in PATH environment",
1299 "Scan all directories in /etc/ld.so.conf", 2026 "Scan all directories in /etc/ld.so.conf",
2027 "Use ld.so.conf to show full path (use with -r/-n)",
2028 "Root directory (use with -l or -p)",
1300 "Scan directories recursively", 2029 "Scan directories recursively",
1301 "Don't recursively cross mount points", 2030 "Don't recursively cross mount points",
1302 "Don't scan symlinks", 2031 "Don't scan symlinks",
1303 "Scan archives (.a files)", 2032 "Scan archives (.a files)",
1304 "Utilize ld.so.cache information (use with -r/-n)", 2033 "Utilize ld.so.cache to show full path (use with -r/-n)",
1305 "Try and 'fix' bad things (use with -r/-e)\n", 2034 "Try and 'fix' bad things (use with -r/-e)",
2035 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1306 "Print PaX markings", 2036 "Print PaX markings",
1307 "Print GNU_STACK/PT_LOAD markings", 2037 "Print GNU_STACK/PT_LOAD markings",
1308 "Print TEXTREL information", 2038 "Print TEXTREL information",
1309 "Print RPATH information", 2039 "Print RPATH information",
1310 "Print NEEDED information", 2040 "Print NEEDED information",
1311 "Print INTERP information", 2041 "Print INTERP information",
1312 "Print BIND information", 2042 "Print BIND information",
1313 "Print SONAME information", 2043 "Print SONAME information",
1314 "Find a specified symbol", 2044 "Find a specified symbol",
2045 "Find a specified section",
1315 "Find a specified library", 2046 "Find a specified library",
1316 "Use strncmp to match libraries. (use with -N)", 2047 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1317 "Locate cause of TEXTREL", 2048 "Locate cause of TEXTREL",
2049 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1318 "Print only ELF files matching numeric constant", 2050 "Print only ELF files matching numeric bits",
1319 "Print all scanned info (-x -e -t -r -b)\n", 2051 "Print Endianness",
2052 "Print OSABI",
2053 "Print EABI (EM_ARM Only)",
2054 "Print only ELF files matching octal permissions",
2055 "Print ELF file size",
2056 "Print all useful/simple info\n",
1320 "Only output 'bad' things", 2057 "Only output 'bad' things",
1321 "Be verbose (can be specified more than once)", 2058 "Be verbose (can be specified more than once)",
1322 "Use specified format for output", 2059 "Use specified format for output",
1323 "Read input stream from a filename", 2060 "Read input stream from a filename",
1324 "Write output stream to a filename", 2061 "Write output stream to a filename",
2062 "Don't emit color in output",
1325 "Don't display the header", 2063 "Don't display the header",
1326 "Print this help and exit", 2064 "Print this help and exit",
1327 "Print version and exit", 2065 "Print version and exit",
1328 NULL 2066 NULL
1329}; 2067};
1330 2068
1331/* display usage and exit */ 2069/* display usage and exit */
1332static void usage(int status) 2070static void usage(int status)
1333{ 2071{
1334 unsigned long i; 2072 const char a_arg[] = "<arg>";
2073 size_t a_arg_len = strlen(a_arg) + 2;
2074 size_t i;
2075 int optlen;
1335 printf("* Scan ELF binaries for stuff\n\n" 2076 printf("* Scan ELF binaries for stuff\n\n"
1336 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0); 2077 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1337 printf("Options: -[%s]\n", PARSE_FLAGS); 2078 printf("Options: -[%s]\n", PARSE_FLAGS);
2079
2080 /* prescan the --long opt length to auto-align */
2081 optlen = 0;
1338 for (i = 0; long_opts[i].name; ++i) 2082 for (i = 0; long_opts[i].name; ++i) {
2083 int l = strlen(long_opts[i].name);
2084 if (long_opts[i].has_arg == a_argument)
2085 l += a_arg_len;
2086 optlen = max(l, optlen);
2087 }
2088
2089 for (i = 0; long_opts[i].name; ++i) {
2090 /* first output the short flag if it has one */
2091 if (long_opts[i].val > '~')
2092 printf(" ");
2093 else
2094 printf(" -%c, ", long_opts[i].val);
2095
2096 /* then the long flag */
1339 if (long_opts[i].has_arg == no_argument) 2097 if (long_opts[i].has_arg == no_argument)
1340 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2098 printf("--%-*s", optlen, long_opts[i].name);
1341 long_opts[i].name, opts_help[i]);
1342 else 2099 else
1343 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2100 printf("--%s %s %*s", long_opts[i].name, a_arg,
1344 long_opts[i].name, opts_help[i]); 2101 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1345 2102
1346 if (status != EXIT_SUCCESS) 2103 /* finally the help text */
1347 exit(status); 2104 printf("* %s\n", opts_help[i]);
2105 }
1348 2106
1349 puts("\nThe format modifiers for the -F option are:"); 2107 puts("\nFor more information, see the scanelf(1) manpage");
1350 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1351 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1352 puts(" i INTERP \tb BIND \ts symbol");
1353 puts(" N library \to Type \tT TEXTRELs");
1354 puts(" S SONAME");
1355 puts(" p filename (with search path removed)");
1356 puts(" f filename (short name/basename)");
1357 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1358
1359 exit(status); 2108 exit(status);
1360} 2109}
1361 2110
1362/* parse command line arguments and preform needed actions */ 2111/* parse command line arguments and preform needed actions */
2112#define do_pax_state(option, flag) \
2113 if (islower(option)) { \
2114 flags &= ~PF_##flag; \
2115 flags |= PF_NO##flag; \
2116 } else { \
2117 flags &= ~PF_NO##flag; \
2118 flags |= PF_##flag; \
2119 }
2120static void parse_delimited(array_t *arr, char *arg, const char *delim)
2121{
2122 char *ele = strtok(arg, delim);
2123 if (!ele) /* edge case: -s '' */
2124 xarraypush_str(arr, "");
2125 while (ele) {
2126 xarraypush_str(arr, ele);
2127 ele = strtok(NULL, delim);
2128 }
2129}
1363static void parseargs(int argc, char *argv[]) 2130static int parseargs(int argc, char *argv[])
1364{ 2131{
1365 int i; 2132 int i;
1366 char *from_file = NULL; 2133 const char *from_file = NULL;
2134 int ret = 0;
2135 char load_cache_config = 0;
1367 2136
1368 opterr = 0; 2137 opterr = 0;
1369 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2138 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1370 switch (i) { 2139 switch (i) {
1371 2140
1379 case 'f': 2148 case 'f':
1380 if (from_file) warn("You prob don't want to specify -f twice"); 2149 if (from_file) warn("You prob don't want to specify -f twice");
1381 from_file = optarg; 2150 from_file = optarg;
1382 break; 2151 break;
1383 case 'E': 2152 case 'E':
1384 strncpy(match_etypes, optarg, sizeof(match_etypes)); 2153 /* historically, this was comma delimited */
2154 parse_delimited(match_etypes, optarg, ",");
2155 break;
2156 case 'M':
2157 match_bits = atoi(optarg);
2158 if (match_bits == 0) {
2159 if (strcmp(optarg, "ELFCLASS32") == 0)
2160 match_bits = 32;
2161 if (strcmp(optarg, "ELFCLASS64") == 0)
2162 match_bits = 64;
2163 }
2164 break;
2165 case 'O':
2166 if (sscanf(optarg, "%o", &match_perms) == -1)
2167 match_bits = 0;
1385 break; 2168 break;
1386 case 'o': { 2169 case 'o': {
1387 FILE *fp = NULL;
1388 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2170 if (freopen(optarg, "w", stdout) == NULL)
1389 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2171 errp("Could not freopen(%s)", optarg);
1390 SET_STDOUT(fp);
1391 break; 2172 break;
1392 } 2173 }
1393
1394 case 's': { 2174 case 'k':
1395 if (find_sym) warn("You prob don't want to specify -s twice"); 2175 xarraypush_str(find_section_arr, optarg);
1396 find_sym = optarg;
1397 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1398 sprintf(versioned_symname, "%s@", find_sym);
1399 break; 2176 break;
1400 }
1401 case 'N': { 2177 case 's':
1402 if (find_lib) warn("You prob don't want to specify -N twice"); 2178 /* historically, this was comma delimited */
1403 find_lib = optarg; 2179 parse_delimited(find_sym_arr, optarg, ",");
1404 break; 2180 break;
1405 } 2181 case 'N':
1406 2182 xarraypush_str(find_lib_arr, optarg);
2183 break;
1407 case 'F': { 2184 case 'F': {
1408 if (out_format) warn("You prob don't want to specify -F twice"); 2185 if (out_format) warn("You prob don't want to specify -F twice");
1409 out_format = optarg; 2186 out_format = optarg;
1410 break; 2187 break;
1411 } 2188 }
2189 case 'z': {
2190 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2191 size_t x;
1412 2192
1413 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2193 for (x = 0; x < strlen(optarg); x++) {
2194 switch (optarg[x]) {
2195 case 'p':
2196 case 'P':
2197 do_pax_state(optarg[x], PAGEEXEC);
2198 break;
2199 case 's':
2200 case 'S':
2201 do_pax_state(optarg[x], SEGMEXEC);
2202 break;
2203 case 'm':
2204 case 'M':
2205 do_pax_state(optarg[x], MPROTECT);
2206 break;
2207 case 'e':
2208 case 'E':
2209 do_pax_state(optarg[x], EMUTRAMP);
2210 break;
2211 case 'r':
2212 case 'R':
2213 do_pax_state(optarg[x], RANDMMAP);
2214 break;
2215 case 'x':
2216 case 'X':
2217 do_pax_state(optarg[x], RANDEXEC);
2218 break;
2219 default:
2220 break;
2221 }
2222 }
2223 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2224 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2225 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2226 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2227 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2228 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2229 setpax = flags;
2230 break;
2231 }
2232 case 'Z': show_size = 1; break;
2233 case 'g': ++g_match; break;
1414 case 'L': use_ldcache = 1; break; 2234 case 'L': load_cache_config = use_ldcache = 1; break;
1415 case 'y': scan_symlink = 0; break; 2235 case 'y': scan_symlink = 0; break;
1416 case 'A': scan_archives = 1; break; 2236 case 'A': scan_archives = 1; break;
2237 case 'C': color_init(true); break;
1417 case 'B': show_banner = 0; break; 2238 case 'B': show_banner = 0; break;
1418 case 'l': scan_ldpath = 1; break; 2239 case 'l': load_cache_config = scan_ldpath = 1; break;
1419 case 'p': scan_envpath = 1; break; 2240 case 'p': scan_envpath = 1; break;
1420 case 'R': dir_recurse = 1; break; 2241 case 'R': dir_recurse = 1; break;
1421 case 'm': dir_crossmount = 0; break; 2242 case 'm': dir_crossmount = 0; break;
1422 case 'X': ++fix_elf; break; 2243 case 'X': ++fix_elf; break;
1423 case 'x': show_pax = 1; break; 2244 case 'x': show_pax = 1; break;
1427 case 'n': show_needed = 1; break; 2248 case 'n': show_needed = 1; break;
1428 case 'i': show_interp = 1; break; 2249 case 'i': show_interp = 1; break;
1429 case 'b': show_bind = 1; break; 2250 case 'b': show_bind = 1; break;
1430 case 'S': show_soname = 1; break; 2251 case 'S': show_soname = 1; break;
1431 case 'T': show_textrels = 1; break; 2252 case 'T': show_textrels = 1; break;
1432 case 'q': be_quiet = 1; break; 2253 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1433 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2254 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1434 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2255 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1435 2256 case 'D': show_endian = 1; break;
2257 case 'I': show_osabi = 1; break;
2258 case 'Y': show_eabi = 1; break;
2259 case 128:
2260 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2261 if (root_fd == -1)
2262 err("Could not open root: %s", optarg);
2263 break;
2264 case 129: load_cache_config = use_ldpath = 1; break;
1436 case ':': 2265 case ':':
1437 err("Option '%c' is missing parameter", optopt); 2266 err("Option '%c' is missing parameter", optopt);
1438 case '?': 2267 case '?':
1439 err("Unknown option '%c' or argument missing", optopt); 2268 err("Unknown option '%c' or argument missing", optopt);
1440 default: 2269 default:
1441 err("Unhandled option '%c'; please report this", i); 2270 err("Unhandled option '%c'; please report this", i);
1442 } 2271 }
1443 } 2272 }
2273 if (show_textrels && be_verbose)
2274 objdump = which("objdump", "OBJDUMP");
2275 /* precompile all the regexes */
2276 if (g_match) {
2277 regex_t preg;
2278 const char *this_sym;
2279 size_t n;
2280 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1444 2281
2282 array_for_each(find_sym_arr, n, this_sym) {
2283 /* see scanelf_match_symname for logic info */
2284 switch (this_sym[0]) {
2285 case '%':
2286 while (*(this_sym++))
2287 if (*this_sym == '%') {
2288 ++this_sym;
2289 break;
2290 }
2291 break;
2292 case '+':
2293 case '-':
2294 ++this_sym;
2295 break;
2296 }
2297 if (*this_sym == '*')
2298 ++this_sym;
2299
2300 ret = regcomp(&preg, this_sym, flags);
2301 if (ret) {
2302 char err[256];
2303 regerror(ret, &preg, err, sizeof(err));
2304 err("regcomp of %s failed: %s", this_sym, err);
2305 }
2306 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2307 }
2308 }
2309 /* flatten arrays for display */
2310 find_sym = array_flatten_str(find_sym_arr);
2311 find_lib = array_flatten_str(find_lib_arr);
2312 find_section = array_flatten_str(find_section_arr);
1445 /* let the format option override all other options */ 2313 /* let the format option override all other options */
1446 if (out_format) { 2314 if (out_format) {
1447 show_pax = show_phdr = show_textrel = show_rpath = \ 2315 show_pax = show_phdr = show_textrel = show_rpath = \
1448 show_needed = show_interp = show_bind = show_soname = \ 2316 show_needed = show_interp = show_bind = show_soname = \
1449 show_textrels = 0; 2317 show_textrels = show_perms = show_endian = show_size = \
2318 show_osabi = show_eabi = 0;
1450 for (i = 0; out_format[i]; ++i) { 2319 for (i = 0; out_format[i]; ++i) {
1451 if (!IS_MODIFIER(out_format[i])) continue; 2320 if (!IS_MODIFIER(out_format[i])) continue;
1452 2321
1453 switch (out_format[++i]) { 2322 switch (out_format[++i]) {
2323 case '+': break;
1454 case '%': break; 2324 case '%': break;
1455 case '#': break; 2325 case '#': break;
1456 case 'F': break; 2326 case 'F': break;
1457 case 'p': break; 2327 case 'p': break;
1458 case 'f': break; 2328 case 'f': break;
2329 case 'k': break;
1459 case 's': break; 2330 case 's': break;
1460 case 'N': break; 2331 case 'N': break;
1461 case 'o': break; 2332 case 'o': break;
2333 case 'a': break;
2334 case 'M': break;
2335 case 'Z': show_size = 1; break;
2336 case 'D': show_endian = 1; break;
2337 case 'I': show_osabi = 1; break;
2338 case 'Y': show_eabi = 1; break;
2339 case 'O': show_perms = 1; break;
1462 case 'x': show_pax = 1; break; 2340 case 'x': show_pax = 1; break;
1463 case 'e': show_phdr = 1; break; 2341 case 'e': show_phdr = 1; break;
1464 case 't': show_textrel = 1; break; 2342 case 't': show_textrel = 1; break;
1465 case 'r': show_rpath = 1; break; 2343 case 'r': show_rpath = 1; break;
1466 case 'n': show_needed = 1; break; 2344 case 'n': show_needed = 1; break;
1467 case 'i': show_interp = 1; break; 2345 case 'i': show_interp = 1; break;
1468 case 'b': show_bind = 1; break; 2346 case 'b': show_bind = 1; break;
1469 case 'S': show_soname = 1; break; 2347 case 'S': show_soname = 1; break;
1470 case 'T': show_textrels = 1; break; 2348 case 'T': show_textrels = 1; break;
1471 default: 2349 default:
1472 err("Invalid format specifier '%c' (byte %i)", 2350 err("invalid format specifier '%c' (byte %i)",
1473 out_format[i], i+1); 2351 out_format[i], i+1);
1474 } 2352 }
1475 } 2353 }
1476 2354
1477 /* construct our default format */ 2355 /* construct our default format */
1478 } else { 2356 } else {
1479 size_t fmt_len = 30; 2357 size_t fmt_len = 30;
1480 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2358 out_format = xmalloc(sizeof(char) * fmt_len);
2359 *out_format = '\0';
1481 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2360 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1482 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2361 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2362 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2363 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2364 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2365 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2366 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1483 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2367 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1484 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2368 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1485 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2369 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1486 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2370 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1487 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2371 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1488 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2372 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1489 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2373 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1490 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2374 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1491 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2375 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2376 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1492 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2377 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1493 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2378 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1494 } 2379 }
1495 if (be_verbose > 2) printf("Format: %s\n", out_format); 2380 if (be_verbose > 2) printf("Format: %s\n", out_format);
1496 2381
1497 /* now lets actually do the scanning */ 2382 /* now lets actually do the scanning */
1498 if (scan_ldpath || use_ldcache) 2383 if (load_cache_config)
1499 load_ld_so_conf(); 2384 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1500 if (scan_ldpath) scanelf_ldpath(); 2385 if (scan_ldpath) scanelf_ldpath();
1501 if (scan_envpath) scanelf_envpath(); 2386 if (scan_envpath) scanelf_envpath();
2387 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2388 from_file = "-";
1502 if (from_file) { 2389 if (from_file) {
1503 scanelf_from_file(from_file); 2390 scanelf_from_file(from_file);
1504 from_file = *argv; 2391 from_file = *argv;
1505 } 2392 }
1506 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2393 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1507 err("Nothing to scan !?"); 2394 err("Nothing to scan !?");
1508 while (optind < argc) { 2395 while (optind < argc) {
1509 search_path = argv[optind++]; 2396 search_path = argv[optind++];
1510 scanelf_dir(search_path); 2397 ret = scanelf_dir(search_path);
1511 } 2398 }
1512 2399
2400#ifdef __PAX_UTILS_CLEANUP
1513 /* clean up */ 2401 /* clean up */
1514 if (versioned_symname) free(versioned_symname);
1515 for (i = 0; ldpaths[i]; ++i)
1516 free(ldpaths[i]); 2402 xarrayfree(ldpaths);
2403 xarrayfree(find_sym_arr);
2404 xarrayfree(find_lib_arr);
2405 xarrayfree(find_section_arr);
2406 free(find_sym);
2407 free(find_lib);
2408 free(find_section);
2409 {
2410 size_t n;
2411 regex_t *preg;
2412 array_for_each(find_sym_regex_arr, n, preg)
2413 regfree(preg);
2414 xarrayfree(find_sym_regex_arr);
2415 }
1517 2416
1518 if (ldcache != 0) 2417 if (ldcache != 0)
1519 munmap(ldcache, ldcache_size); 2418 munmap(ldcache, ldcache_size);
1520} 2419#endif
1521 2420
1522
1523
1524/* utility funcs */
1525static char *xstrdup(const char *s)
1526{
1527 char *ret = strdup(s);
1528 if (!ret) err("Could not strdup(): %s", strerror(errno));
1529 return ret; 2421 return ret;
1530} 2422}
1531static void *xmalloc(size_t size)
1532{
1533 void *ret = malloc(size);
1534 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1535 return ret;
1536}
1537static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1538{
1539 size_t new_len;
1540 2423
1541 new_len = strlen(*dst) + strlen(src); 2424static char **get_split_env(const char *envvar)
1542 if (*curr_len <= new_len) {
1543 *curr_len = new_len + (*curr_len / 2);
1544 *dst = realloc(*dst, *curr_len);
1545 if (!*dst)
1546 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1547 }
1548
1549 if (n)
1550 strncat(*dst, src, n);
1551 else
1552 strcat(*dst, src);
1553}
1554static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1555{ 2425{
1556 static char my_app[2]; 2426 const char *delims = " \t\n";
1557 my_app[0] = append; 2427 char **envvals = NULL;
1558 my_app[1] = '\0'; 2428 char *env, *s;
1559 xstrcat(dst, my_app, curr_len); 2429 int nentry;
1560}
1561 2430
2431 if ((env = getenv(envvar)) == NULL)
2432 return NULL;
1562 2433
2434 env = xstrdup(env);
2435 if (env == NULL)
2436 return NULL;
2437
2438 s = strtok(env, delims);
2439 if (s == NULL) {
2440 free(env);
2441 return NULL;
2442 }
2443
2444 nentry = 0;
2445 while (s != NULL) {
2446 ++nentry;
2447 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2448 envvals[nentry-1] = s;
2449 s = strtok(NULL, delims);
2450 }
2451 envvals[nentry] = NULL;
2452
2453 /* don't want to free(env) as it contains the memory that backs
2454 * the envvals array of strings */
2455 return envvals;
2456}
2457
2458static void parseenv(void)
2459{
2460 color_init(false);
2461 qa_textrels = get_split_env("QA_TEXTRELS");
2462 qa_execstack = get_split_env("QA_EXECSTACK");
2463 qa_wx_load = get_split_env("QA_WX_LOAD");
2464}
2465
2466#ifdef __PAX_UTILS_CLEANUP
2467static void cleanup(void)
2468{
2469 free(out_format);
2470 free(qa_textrels);
2471 free(qa_execstack);
2472 free(qa_wx_load);
2473}
2474#endif
1563 2475
1564int main(int argc, char *argv[]) 2476int main(int argc, char *argv[])
1565{ 2477{
2478 int ret;
1566 if (argc < 2) 2479 if (argc < 2)
1567 usage(EXIT_FAILURE); 2480 usage(EXIT_FAILURE);
2481 parseenv();
1568 parseargs(argc, argv); 2482 ret = parseargs(argc, argv);
1569 fclose(stdout); 2483 fclose(stdout);
1570#ifdef __BOUNDS_CHECKING_ON 2484#ifdef __PAX_UTILS_CLEANUP
1571 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2485 cleanup();
2486 warn("The calls to add/delete heap should be off:\n"
2487 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2488 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1572#endif 2489#endif
1573 return EXIT_SUCCESS; 2490 return ret;
1574} 2491}
2492
2493/* Match filename against entries in matchlist, return TRUE
2494 * if the file is listed */
2495static int file_matches_list(const char *filename, char **matchlist)
2496{
2497 char **file;
2498 char *match;
2499 char buf[__PAX_UTILS_PATH_MAX];
2500
2501 if (matchlist == NULL)
2502 return 0;
2503
2504 for (file = matchlist; *file != NULL; file++) {
2505 if (search_path) {
2506 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2507 match = buf;
2508 } else {
2509 match = *file;
2510 }
2511 if (fnmatch(match, filename, 0) == 0)
2512 return 1;
2513 }
2514 return 0;
2515}

Legend:
Removed from v.1.119  
changed lines
  Added in v.1.264

  ViewVC Help
Powered by ViewVC 1.1.20