/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.119 Revision 1.266
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.119 2006/02/05 02:25:58 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.266 2014/06/18 03:16:52 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.266 2014/06/18 03:16:52 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.119 2006/02/05 02:25:58 solar Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static int scanelf_elfobj(elfobj *elf); 18static int file_matches_list(const char *filename, char **matchlist);
21static int scanelf_elf(const char *filename, int fd, size_t len);
22static int scanelf_archive(const char *filename, int fd, size_t len);
23static void scanelf_file(const char *filename);
24static void scanelf_dir(const char *path);
25static void scanelf_ldpath(void);
26static void scanelf_envpath(void);
27static void usage(int status);
28static void parseargs(int argc, char *argv[]);
29static char *xstrdup(const char *s);
30static void *xmalloc(size_t size);
31static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
32#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
33static inline void xchrcat(char **dst, const char append, size_t *curr_len);
34 19
35/* variables to control behavior */ 20/* variables to control behavior */
36static char match_etypes[126] = ""; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
37static char *ldpaths[256]; 22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
38static char scan_ldpath = 0; 23static char scan_ldpath = 0;
39static char scan_envpath = 0; 24static char scan_envpath = 0;
40static char scan_symlink = 1; 25static char scan_symlink = 1;
41static char scan_archives = 0; 26static char scan_archives = 0;
42static char dir_recurse = 0; 27static char dir_recurse = 0;
43static char dir_crossmount = 1; 28static char dir_crossmount = 1;
44static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
45static char show_phdr = 0; 32static char show_phdr = 0;
46static char show_textrel = 0; 33static char show_textrel = 0;
47static char show_rpath = 0; 34static char show_rpath = 0;
48static char show_needed = 0; 35static char show_needed = 0;
49static char show_interp = 0; 36static char show_interp = 0;
50static char show_bind = 0; 37static char show_bind = 0;
51static char show_soname = 0; 38static char show_soname = 0;
52static char show_textrels = 0; 39static char show_textrels = 0;
53static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
54static char be_quiet = 0; 44static char be_quiet = 0;
55static char be_verbose = 0; 45static char be_verbose = 0;
56static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
57static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
58static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
59static char *out_format = NULL; 55static char *out_format = NULL;
60static char *search_path = NULL; 56static char *search_path = NULL;
61static char fix_elf = 0; 57static char fix_elf = 0;
62static char gmatch = 0; 58static char g_match = 0;
63static char use_ldcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
64 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
65 66
66caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
67size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
68 72
73static const char *objdump;
74
75/* Find the path to a file by name. Note: we do not currently handle the
76 * empty path element correctly (should behave by searching $PWD). */
77static const char *which(const char *fname, const char *envvar)
78{
79 size_t path_len, fname_len;
80 const char *env_path;
81 char *path, *p, *ep;
82
83 p = getenv(envvar);
84 if (p)
85 return p;
86
87 env_path = getenv("PATH");
88 if (!env_path)
89 return NULL;
90
91 /* Create a copy of the $PATH that we can safely modify.
92 * Make it a little bigger so we can append "/fname".
93 * We do this twice -- once for a perm copy, and once for
94 * room at the end of the last element. */
95 path_len = strlen(env_path);
96 fname_len = strlen(fname);
97 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
98 memcpy(path, env_path, path_len + 1);
99
100 p = path + path_len + 1 + fname_len + 1;
101 *p = '/';
102 memcpy(p + 1, fname, fname_len + 1);
103
104 /* Repoint fname to the copy in the env string as it has
105 * the leading slash which we can include in a single memcpy.
106 * Increase the fname len to include the '/' and '\0'. */
107 fname = p;
108 fname_len += 2;
109
110 p = path;
111 while (p) {
112 ep = strchr(p, ':');
113 /* Append the /foo path to the current element. */
114 if (ep)
115 memcpy(ep, fname, fname_len);
116 else
117 memcpy(path + path_len, fname, fname_len);
118
119 if (access(p, R_OK) != -1)
120 return p;
121
122 p = ep;
123 if (ep) {
124 /* If not the last element, restore the chunk we clobbered. */
125 size_t offset = ep - path;
126 size_t restore = min(path_len - offset, fname_len);
127 memcpy(ep, env_path + offset, restore);
128 ++p;
129 }
130 }
131
132 free(path);
133 return NULL;
134}
135
136static FILE *fopenat_r(int dir_fd, const char *path)
137{
138 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
139 if (fd == -1)
140 return NULL;
141 return fdopen(fd, "re");
142}
143
144static const char *root_rel_path(const char *path)
145{
146 /*
147 * openat() will ignore the dirfd if path starts with
148 * a /, so consume all of that noise
149 *
150 * XXX: we don't handle relative paths like ../ that
151 * break out of the --root option, but for now, just
152 * don't do that :P.
153 */
154 if (root_fd != AT_FDCWD) {
155 while (*path == '/')
156 ++path;
157 if (*path == '\0')
158 path = ".";
159 }
160
161 return path;
162}
163
69/* sub-funcs for scanelf_file() */ 164/* sub-funcs for scanelf_fileat() */
70static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 165static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
71{ 166{
72 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 167 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
168
169 /* debug sections */
170 void *symtab = elf_findsecbyname(elf, ".symtab");
171 void *strtab = elf_findsecbyname(elf, ".strtab");
172 /* runtime sections */
173 void *dynsym = elf_findsecbyname(elf, ".dynsym");
174 void *dynstr = elf_findsecbyname(elf, ".dynstr");
175
176 /*
177 * If the sections are marked NOBITS, then they don't exist, so we just
178 * skip them. This let's us work sanely with splitdebug ELFs (rather
179 * than spewing a lot of "corrupt ELF" messages later on). In malformed
180 * ELFs, the section might be wrongly set to NOBITS, but screw em.
181 */
73#define GET_SYMTABS(B) \ 182#define GET_SYMTABS(B) \
74 if (elf->elf_class == ELFCLASS ## B) { \ 183 if (elf->elf_class == ELFCLASS ## B) { \
75 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 184 Elf ## B ## _Shdr *esymtab = symtab; \
76 /* debug sections */ \ 185 Elf ## B ## _Shdr *estrtab = strtab; \
77 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 186 Elf ## B ## _Shdr *edynsym = dynsym; \
78 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 187 Elf ## B ## _Shdr *edynstr = dynstr; \
79 /* runtime sections */ \ 188 \
80 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 189 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
81 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 190 symtab = NULL; \
191 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
192 dynsym = NULL; \
82 if (symtab && dynsym) { \ 193 if (symtab && dynsym) \
83 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 194 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
84 } else { \ 195 else \
85 *sym = (void*)(symtab ? symtab : dynsym); \ 196 *sym = symtab ? symtab : dynsym; \
86 } \ 197 \
198 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
199 strtab = NULL; \
200 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
201 dynstr = NULL; \
87 if (strtab && dynstr) { \ 202 if (strtab && dynstr) \
88 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 203 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
89 } else { \ 204 else \
90 *tab = (void*)(strtab ? strtab : dynstr); \ 205 *str = strtab ? strtab : dynstr; \
91 } \
92 } 206 }
93 GET_SYMTABS(32) 207 GET_SYMTABS(32)
94 GET_SYMTABS(64) 208 GET_SYMTABS(64)
209
210 if (*sym && *str)
211 return;
212
213 /*
214 * damn, they're really going to make us work for it huh?
215 * reconstruct the section header info out of the dynamic
216 * tags so we can see what symbols this guy uses at runtime.
217 */
218#define GET_SYMTABS_DT(B) \
219 if (elf->elf_class == ELFCLASS ## B) { \
220 size_t i; \
221 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
222 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
223 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
224 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
225 Elf ## B ## _Dyn *dyn; \
226 Elf ## B ## _Off offset; \
227 \
228 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
229 vsym = vstr = vhash = vgnu_hash = 0; \
230 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
231 memset(&str_shdr, 0, sizeof(str_shdr)); \
232 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
233 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
234 continue; \
235 \
236 offset = EGET(phdr[i].p_offset); \
237 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
238 continue; \
239 \
240 dyn = DYN ## B (elf->vdata + offset); \
241 while (EGET(dyn->d_tag) != DT_NULL) { \
242 switch (EGET(dyn->d_tag)) { \
243 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
244 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
245 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
246 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
247 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
248 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
249 } \
250 ++dyn; \
251 } \
252 if (vsym && vstr) \
253 break; \
254 } \
255 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
256 return; \
257 \
258 /* calc offset into the ELF by finding the load addr of the syms */ \
259 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
260 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
261 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
262 offset = EGET(phdr[i].p_offset); \
263 \
264 if (EGET(phdr[i].p_type) != PT_LOAD) \
265 continue; \
266 \
267 if (vhash >= vaddr && vhash < vaddr + filesz) { \
268 /* Scan the hash table to see how many entries we have */ \
269 Elf32_Word max_sym_idx = 0; \
270 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
271 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
272 Elf32_Word nchains = EGET(hashtbl[1]); \
273 Elf32_Word *buckets = &hashtbl[2]; \
274 Elf32_Word *chains = &buckets[nbuckets]; \
275 Elf32_Word sym_idx; \
276 \
277 for (b = 0; b < nbuckets; ++b) { \
278 if (!buckets[b]) \
279 continue; \
280 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
281 if (max_sym_idx < sym_idx) \
282 max_sym_idx = sym_idx; \
283 } \
284 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
285 } \
286 \
287 if (vsym >= vaddr && vsym < vaddr + filesz) { \
288 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
289 *sym = &sym_shdr; \
290 } \
291 \
292 if (vstr >= vaddr && vstr < vaddr + filesz) { \
293 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
294 *str = &str_shdr; \
295 } \
296 } \
297 }
298 GET_SYMTABS_DT(32)
299 GET_SYMTABS_DT(64)
95} 300}
301
96static char *scanelf_file_pax(elfobj *elf, char *found_pax) 302static char *scanelf_file_pax(elfobj *elf, char *found_pax)
97{ 303{
98 static char ret[7]; 304 static char ret[7];
99 unsigned long i, shown; 305 unsigned long i, shown;
100 306
109 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 315 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
110 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 316 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
111 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 317 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
112 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 318 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
113 continue; \ 319 continue; \
114 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 320 if (fix_elf && setpax) { \
321 /* set the paxctl flags */ \
322 ESET(phdr[i].p_flags, setpax); \
323 } \
324 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
115 continue; \ 325 continue; \
116 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 326 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
117 *found_pax = 1; \ 327 *found_pax = 1; \
118 ++shown; \ 328 ++shown; \
119 break; \ 329 break; \
120 } \ 330 } \
121 } 331 }
122 SHOW_PAX(32) 332 SHOW_PAX(32)
123 SHOW_PAX(64) 333 SHOW_PAX(64)
124 } 334 }
335
336 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
337 * was found. This is known to break ELFs on glibc systems,
338 * and mainline PaX has deprecated use of this for a long time.
339 * We could support changing PT_GNU_STACK, but that doesn't
340 * seem like it's worth the effort. #411919
341 */
125 342
126 /* fall back to EI_PAX if no PT_PAX was found */ 343 /* fall back to EI_PAX if no PT_PAX was found */
127 if (!*ret) { 344 if (!*ret) {
128 static char *paxflags; 345 static char *paxflags;
129 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 346 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
143static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 360static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
144{ 361{
145 static char ret[12]; 362 static char ret[12];
146 char *found; 363 char *found;
147 unsigned long i, shown, multi_stack, multi_relro, multi_load; 364 unsigned long i, shown, multi_stack, multi_relro, multi_load;
148 int max_pt_load;
149 365
150 if (!show_phdr) return NULL; 366 if (!show_phdr) return NULL;
151 367
152 memcpy(ret, "--- --- ---\0", 12); 368 memcpy(ret, "--- --- ---\0", 12);
153 369
154 shown = 0; 370 shown = 0;
155 multi_stack = multi_relro = multi_load = 0; 371 multi_stack = multi_relro = multi_load = 0;
156 max_pt_load = elf_max_pt_load(elf);
157 372
158#define NOTE_GNU_STACK ".note.GNU-stack" 373#define NOTE_GNU_STACK ".note.GNU-stack"
159#define SHOW_PHDR(B) \ 374#define SHOW_PHDR(B) \
160 if (elf->elf_class == ELFCLASS ## B) { \ 375 if (elf->elf_class == ELFCLASS ## B) { \
161 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 376 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
163 uint32_t flags, check_flags; \ 378 uint32_t flags, check_flags; \
164 if (elf->phdr != NULL) { \ 379 if (elf->phdr != NULL) { \
165 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 380 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
166 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 381 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
167 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 382 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
383 if (multi_stack++) \
168 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 384 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
385 if (file_matches_list(elf->filename, qa_execstack)) \
386 continue; \
169 found = found_phdr; \ 387 found = found_phdr; \
170 offset = 0; \ 388 offset = 0; \
171 check_flags = PF_X; \ 389 check_flags = PF_X; \
172 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 390 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
391 if (multi_relro++) \
173 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 392 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
174 found = found_relro; \ 393 found = found_relro; \
175 offset = 4; \ 394 offset = 4; \
176 check_flags = PF_X; \ 395 check_flags = PF_X; \
177 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 396 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
178 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \ 397 if (file_matches_list(elf->filename, qa_wx_load)) \
179 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \ 398 continue; \
180 found = found_load; \ 399 found = found_load; \
181 offset = 8; \ 400 offset = 8; \
182 check_flags = PF_W|PF_X; \ 401 check_flags = PF_W|PF_X; \
183 } else \ 402 } else \
184 continue; \ 403 continue; \
185 flags = EGET(phdr[i].p_flags); \ 404 flags = EGET(phdr[i].p_flags); \
186 if (be_quiet && ((flags & check_flags) != check_flags)) \ 405 if (be_quiet && ((flags & check_flags) != check_flags)) \
187 continue; \ 406 continue; \
188 if (fix_elf && ((flags & PF_X) != flags)) { \ 407 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
189 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \ 408 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
190 ret[3] = ret[7] = '!'; \ 409 ret[3] = ret[7] = '!'; \
191 flags = EGET(phdr[i].p_flags); \ 410 flags = EGET(phdr[i].p_flags); \
192 } \ 411 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 412 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
197 } else if (elf->shdr != NULL) { \ 416 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 417 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 418 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 419 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
201 char *str; \ 420 char *str; \
202 if ((void*)strtbl > (void*)elf->data_end) \ 421 if ((void*)strtbl > elf->data_end) \
203 goto skip_this_shdr##B; \ 422 goto skip_this_shdr##B; \
423 /* let's flag -w/+x object files since the final ELF will most likely \
424 * need write access to the stack (who doesn't !?). so the combined \
425 * output will bring in +w automatically and that's bad. \
426 */ \
204 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 427 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
205 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 428 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
206 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 429 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
207 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 430 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
208 str = elf->data + offset; \ 431 str = elf->data + offset; \
209 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \ 432 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
221 break; \ 444 break; \
222 } \ 445 } \
223 } \ 446 } \
224 skip_this_shdr##B: \ 447 skip_this_shdr##B: \
225 if (!multi_stack) { \ 448 if (!multi_stack) { \
449 if (file_matches_list(elf->filename, qa_execstack)) \
450 return NULL; \
226 *found_phdr = 1; \ 451 *found_phdr = 1; \
227 shown = 1; \ 452 shown = 1; \
228 memcpy(ret, "!WX", 3); \ 453 memcpy(ret, "!WX", 3); \
229 } \ 454 } \
230 } \ 455 } \
235 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 460 if (be_wewy_wewy_quiet || (be_quiet && !shown))
236 return NULL; 461 return NULL;
237 else 462 else
238 return ret; 463 return ret;
239} 464}
465
466/*
467 * See if this ELF contains a DT_TEXTREL tag in any of its
468 * PT_DYNAMIC sections.
469 */
240static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 470static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
241{ 471{
242 static const char *ret = "TEXTREL"; 472 static const char *ret = "TEXTREL";
243 unsigned long i; 473 unsigned long i;
244 474
245 if (!show_textrel && !show_textrels) return NULL; 475 if (!show_textrel && !show_textrels) return NULL;
476
477 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
246 478
247 if (elf->phdr) { 479 if (elf->phdr) {
248#define SHOW_TEXTREL(B) \ 480#define SHOW_TEXTREL(B) \
249 if (elf->elf_class == ELFCLASS ## B) { \ 481 if (elf->elf_class == ELFCLASS ## B) { \
250 Elf ## B ## _Dyn *dyn; \ 482 Elf ## B ## _Dyn *dyn; \
251 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 483 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
252 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 484 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
253 Elf ## B ## _Off offset; \ 485 Elf ## B ## _Off offset; \
254 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 486 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
255 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 487 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
256 offset = EGET(phdr[i].p_offset); \ 488 offset = EGET(phdr[i].p_offset); \
257 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 489 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
258 dyn = DYN ## B (elf->data + offset); \ 490 dyn = DYN ## B (elf->vdata + offset); \
259 while (EGET(dyn->d_tag) != DT_NULL) { \ 491 while (EGET(dyn->d_tag) != DT_NULL) { \
260 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 492 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
261 *found_textrel = 1; \ 493 *found_textrel = 1; \
262 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 494 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
263 return (be_wewy_wewy_quiet ? NULL : ret); \ 495 return (be_wewy_wewy_quiet ? NULL : ret); \
272 if (be_quiet || be_wewy_wewy_quiet) 504 if (be_quiet || be_wewy_wewy_quiet)
273 return NULL; 505 return NULL;
274 else 506 else
275 return " - "; 507 return " - ";
276} 508}
509
510/*
511 * Scan the .text section to see if there are any relocations in it.
512 * Should rewrite this to check PT_LOAD sections that are marked
513 * Executable rather than the section named '.text'.
514 */
277static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 515static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
278{ 516{
279 unsigned long s, r, rmax; 517 unsigned long s, r, rmax;
280 void *symtab_void, *strtab_void, *text_void; 518 void *symtab_void, *strtab_void, *text_void;
281 519
302 Elf ## B ## _Rela *rela; \ 540 Elf ## B ## _Rela *rela; \
303 /* search the section headers for relocations */ \ 541 /* search the section headers for relocations */ \
304 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 542 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
305 uint32_t sh_type = EGET(shdr[s].sh_type); \ 543 uint32_t sh_type = EGET(shdr[s].sh_type); \
306 if (sh_type == SHT_REL) { \ 544 if (sh_type == SHT_REL) { \
307 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 545 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
308 rela = NULL; \ 546 rela = NULL; \
309 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 547 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
310 } else if (sh_type == SHT_RELA) { \ 548 } else if (sh_type == SHT_RELA) { \
311 rel = NULL; \ 549 rel = NULL; \
312 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 550 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
313 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 551 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
314 } else \ 552 } else \
315 continue; \ 553 continue; \
316 /* now see if any of the relocs are in the .text */ \ 554 /* now see if any of the relocs are in the .text */ \
317 for (r = 0; r < rmax; ++r) { \ 555 for (r = 0; r < rmax; ++r) { \
332 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 570 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
333 if (be_verbose <= 2) continue; \ 571 if (be_verbose <= 2) continue; \
334 } else \ 572 } else \
335 *found_textrels = 1; \ 573 *found_textrels = 1; \
336 /* locate this relocation symbol name */ \ 574 /* locate this relocation symbol name */ \
337 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 575 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
338 if ((void*)sym > (void*)elf->data_end) { \ 576 if ((void*)sym > elf->data_end) { \
339 warn("%s: corrupt ELF symbol", elf->filename); \ 577 warn("%s: corrupt ELF symbol", elf->filename); \
340 continue; \ 578 continue; \
341 } \ 579 } \
342 sym_max = ELF ## B ## _R_SYM(r_info); \ 580 sym_max = ELF ## B ## _R_SYM(r_info); \
343 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 581 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
346 sym = NULL; \ 584 sym = NULL; \
347 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 585 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
348 /* show the raw details about this reloc */ \ 586 /* show the raw details about this reloc */ \
349 printf(" %s: ", elf->base_filename); \ 587 printf(" %s: ", elf->base_filename); \
350 if (sym && sym->st_name) \ 588 if (sym && sym->st_name) \
351 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 589 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
352 else \ 590 else \
353 printf("(memory/fake?)"); \ 591 printf("(memory/data?)"); \
354 printf(" [0x%lX]", (unsigned long)r_offset); \ 592 printf(" [0x%lX]", (unsigned long)r_offset); \
355 /* now try to find the closest symbol that this rel is probably in */ \ 593 /* now try to find the closest symbol that this rel is probably in */ \
356 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 594 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
357 func = NULL; \ 595 func = NULL; \
358 offset_tmp = 0; \ 596 offset_tmp = 0; \
359 while (sym_max--) { \ 597 while (sym_max--) { \
360 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 598 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
361 func = sym; \ 599 func = sym; \
362 offset_tmp = EGET(sym->st_value); \ 600 offset_tmp = EGET(sym->st_value); \
363 } \ 601 } \
364 ++sym; \ 602 ++sym; \
365 } \ 603 } \
366 printf(" in "); \ 604 printf(" in "); \
367 if (func && func->st_name) \ 605 if (func && func->st_name) { \
368 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 606 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
607 if (r_offset > EGET(func->st_size)) \
608 printf("(optimized out: previous %s)", func_name); \
369 else \ 609 else \
370 printf("(NULL: fake?)"); \ 610 printf("%s", func_name); \
611 } else \
612 printf("(optimized out)"); \
371 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 613 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
614 if (be_verbose && objdump) { \
615 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
616 char *sysbuf; \
617 size_t syslen; \
618 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
619 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
620 sysbuf = xmalloc(syslen); \
621 if (end_addr < r_offset) \
622 /* not uncommon when things are optimized out */ \
623 end_addr = r_offset + 0x100; \
624 snprintf(sysbuf, syslen, sysfmt, \
625 objdump, \
626 (unsigned long)offset_tmp, \
627 (unsigned long)end_addr, \
628 elf->filename, \
629 (unsigned long)r_offset); \
630 fflush(stdout); \
631 if (system(sysbuf)) {/* don't care */} \
632 fflush(stdout); \
633 free(sysbuf); \
634 } \
372 } \ 635 } \
373 } } 636 } }
374 SHOW_TEXTRELS(32) 637 SHOW_TEXTRELS(32)
375 SHOW_TEXTRELS(64) 638 SHOW_TEXTRELS(64)
376 } 639 }
378 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 641 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
379 642
380 return NULL; 643 return NULL;
381} 644}
382 645
383static void rpath_security_checks(elfobj *, char *, const char *);
384static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type) 646static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
385{ 647{
386 struct stat st; 648 struct stat st;
387 switch (*item) { 649 switch (*item) {
388 case '/': break; 650 case '/': break;
394 warnf("Security problem NULL %s in %s", dt_type, elf->filename); 656 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
395 break; 657 break;
396 case '$': 658 case '$':
397 if (fstat(elf->fd, &st) != -1) 659 if (fstat(elf->fd, &st) != -1)
398 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 660 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
399 warnf("Security problem with %s='%s' in %s with mode set of %o", 661 warnf("Security problem with %s='%s' in %s with mode set of %o",
400 dt_type, item, elf->filename, st.st_mode & 07777); 662 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
401 break; 663 break;
402 default: 664 default:
403 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename); 665 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
404 break; 666 break;
405 } 667 }
406} 668}
407static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 669static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
408{ 670{
409 unsigned long i, s; 671 unsigned long i;
410 char *rpath, *runpath, **r; 672 char *rpath, *runpath, **r;
411 void *strtbl_void; 673 void *strtbl_void;
412 674
413 if (!show_rpath) return; 675 if (!show_rpath) return;
414 676
425 Elf ## B ## _Off offset; \ 687 Elf ## B ## _Off offset; \
426 Elf ## B ## _Xword word; \ 688 Elf ## B ## _Xword word; \
427 /* Scan all the program headers */ \ 689 /* Scan all the program headers */ \
428 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 690 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
429 /* Just scan dynamic headers */ \ 691 /* Just scan dynamic headers */ \
430 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 692 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
431 offset = EGET(phdr[i].p_offset); \ 693 offset = EGET(phdr[i].p_offset); \
432 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 694 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
433 /* Just scan dynamic RPATH/RUNPATH headers */ \ 695 /* Just scan dynamic RPATH/RUNPATH headers */ \
434 dyn = DYN ## B (elf->data + offset); \ 696 dyn = DYN ## B (elf->vdata + offset); \
435 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 697 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
436 if (word == DT_RPATH) { \ 698 if (word == DT_RPATH) { \
437 r = &rpath; \ 699 r = &rpath; \
438 } else if (word == DT_RUNPATH) { \ 700 } else if (word == DT_RUNPATH) { \
439 r = &runpath; \ 701 r = &runpath; \
443 } \ 705 } \
444 /* Verify the memory is somewhat sane */ \ 706 /* Verify the memory is somewhat sane */ \
445 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 707 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
446 if (offset < (Elf ## B ## _Off)elf->len) { \ 708 if (offset < (Elf ## B ## _Off)elf->len) { \
447 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 709 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
448 *r = (char*)(elf->data + offset); \ 710 *r = elf->data + offset; \
449 /* cache the length in case we need to nuke this section later on */ \ 711 /* cache the length in case we need to nuke this section later on */ \
450 if (fix_elf) \ 712 if (fix_elf) \
451 offset = strlen(*r); \ 713 offset = strlen(*r); \
452 /* If quiet, don't output paths in ld.so.conf */ \ 714 /* If quiet, don't output paths in ld.so.conf */ \
453 if (be_quiet) { \ 715 if (be_quiet) { \
459 /* scan each path in : delimited list */ \ 721 /* scan each path in : delimited list */ \
460 while (start) { \ 722 while (start) { \
461 rpath_security_checks(elf, start, get_elfdtype(word)); \ 723 rpath_security_checks(elf, start, get_elfdtype(word)); \
462 end = strchr(start, ':'); \ 724 end = strchr(start, ':'); \
463 len = (end ? abs(end - start) : strlen(start)); \ 725 len = (end ? abs(end - start) : strlen(start)); \
464 if (use_ldcache) \ 726 if (use_ldcache) { \
465 for (s = 0; ldpaths[s]; ++s) \ 727 size_t n; \
728 const char *ldpath; \
729 array_for_each(ldpaths, n, ldpath) \
466 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 730 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
467 *r = end; \ 731 *r = end; \
468 /* corner case ... if RPATH reads "/usr/lib:", we want \ 732 /* corner case ... if RPATH reads "/usr/lib:", we want \
469 * to show ':' rather than '' */ \ 733 * to show ':' rather than '' */ \
470 if (end && end[1] != '\0') \ 734 if (end && end[1] != '\0') \
471 (*r)++; \ 735 (*r)++; \
472 break; \ 736 break; \
473 } \ 737 } \
738 } \
474 if (!*r || !end) \ 739 if (!*r || !end) \
475 break; \ 740 break; \
476 else \ 741 else \
477 start = start + len + 1; \ 742 start = start + len + 1; \
478 } \ 743 } \
544 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 809 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
545 else if (!be_quiet) 810 else if (!be_quiet)
546 xstrcat(ret, " - ", ret_len); 811 xstrcat(ret, " - ", ret_len);
547} 812}
548 813
814/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
549#define LDSO_CACHE_MAGIC "ld.so-" 815#define LDSO_CACHE_MAGIC "ld.so-"
550#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 816#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
551#define LDSO_CACHE_VER "1.7.0" 817#define LDSO_CACHE_VER "1.7.0"
552#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 818#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
553#define FLAG_ANY -1 819#define FLAG_ANY -1
562#define FLAG_X8664_LIB64 0x0300 828#define FLAG_X8664_LIB64 0x0300
563#define FLAG_S390_LIB64 0x0400 829#define FLAG_S390_LIB64 0x0400
564#define FLAG_POWERPC_LIB64 0x0500 830#define FLAG_POWERPC_LIB64 0x0500
565#define FLAG_MIPS64_LIBN32 0x0600 831#define FLAG_MIPS64_LIBN32 0x0600
566#define FLAG_MIPS64_LIBN64 0x0700 832#define FLAG_MIPS64_LIBN64 0x0700
833#define FLAG_X8664_LIBX32 0x0800
834#define FLAG_ARM_LIBHF 0x0900
835#define FLAG_AARCH64_LIB64 0x0a00
567 836
568static char *lookup_cache_lib(elfobj *, char *); 837#if defined(__GLIBC__) || defined(__UCLIBC__)
838
569static char *lookup_cache_lib(elfobj *elf, char *fname) 839static char *lookup_cache_lib(elfobj *elf, const char *fname)
570{ 840{
571 int fd = 0; 841 int fd;
572 char *strs; 842 char *strs;
573 static char buf[__PAX_UTILS_PATH_MAX] = ""; 843 static char buf[__PAX_UTILS_PATH_MAX] = "";
574 const char *cachefile = "/etc/ld.so.cache"; 844 const char *cachefile = root_rel_path("/etc/ld.so.cache");
575 struct stat st; 845 struct stat st;
576 846
577 typedef struct { 847 typedef struct {
578 char magic[LDSO_CACHE_MAGIC_LEN]; 848 char magic[LDSO_CACHE_MAGIC_LEN];
579 char version[LDSO_CACHE_VER_LEN]; 849 char version[LDSO_CACHE_VER_LEN];
589 libentry_t *libent; 859 libentry_t *libent;
590 860
591 if (fname == NULL) 861 if (fname == NULL)
592 return NULL; 862 return NULL;
593 863
594 if (ldcache == 0) { 864 if (ldcache == NULL) {
595 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 865 if (fstatat(root_fd, cachefile, &st, 0))
866 return NULL;
867
868 fd = openat(root_fd, cachefile, O_RDONLY);
869 if (fd == -1)
596 return NULL; 870 return NULL;
597 871
598 /* cache these values so we only map/unmap the cache file once */ 872 /* cache these values so we only map/unmap the cache file once */
599 ldcache_size = st.st_size; 873 ldcache_size = st.st_size;
600 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 874 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
601
602 close(fd); 875 close(fd);
603 876
604 if (ldcache == (caddr_t)-1) { 877 if (ldcache == MAP_FAILED) {
605 ldcache = 0; 878 ldcache = NULL;
606 return NULL; 879 return NULL;
607 } 880 }
608 881
609 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 882 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
883 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
884 {
885 munmap(ldcache, ldcache_size);
886 ldcache = NULL;
610 return NULL; 887 return NULL;
611 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
612 return NULL;
613 } 888 }
889 } else
890 header = ldcache;
614 891
615 header = (header_t *) ldcache;
616 libent = (libentry_t *) (ldcache + sizeof(header_t)); 892 libent = ldcache + sizeof(header_t);
617 strs = (char *) &libent[header->nlibs]; 893 strs = (char *) &libent[header->nlibs];
618 894
619 for (fd = 0; fd < header->nlibs; fd++) { 895 for (fd = 0; fd < header->nlibs; ++fd) {
620 /* this should be more fine grained, but for now we assume that 896 /* This should be more fine grained, but for now we assume that
621 * diff arches will not be cached together. and we ignore the 897 * diff arches will not be cached together, and we ignore the
622 * the different multilib mips cases. */ 898 * the different multilib mips cases.
899 */
623 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 900 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
624 continue; 901 continue;
625 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 902 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
626 continue; 903 continue;
627 904
628 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 905 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
629 continue; 906 continue;
907
908 /* Return first hit because that is how the ldso rolls */
630 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 909 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
910 break;
631 } 911 }
912
632 return buf; 913 return buf;
633} 914}
634 915
916#elif defined(__NetBSD__)
917static char *lookup_cache_lib(elfobj *elf, const char *fname)
918{
919 static char buf[__PAX_UTILS_PATH_MAX] = "";
920 static struct stat st;
921 size_t n;
922 char *ldpath;
923
924 array_for_each(ldpath, n, ldpath) {
925 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
926 continue; /* if the pathname is too long, or something went wrong, ignore */
927
928 if (stat(buf, &st) != 0)
929 continue; /* if the lib doesn't exist in *ldpath, look further */
930
931 /* NetBSD doesn't actually do sanity checks, it just loads the file
932 * and if that doesn't work, continues looking in other directories.
933 * This cannot easily be safely emulated, unfortunately. For now,
934 * just assume that if it exists, it's a valid library. */
935
936 return buf;
937 }
938
939 /* not found in any path */
940 return NULL;
941}
942#else
943#ifdef __ELF__
944#warning Cache support not implemented for your target
945#endif
946static char *lookup_cache_lib(elfobj *elf, const char *fname)
947{
948 return NULL;
949}
950#endif
951
952static char *lookup_config_lib(const char *fname)
953{
954 static char buf[__PAX_UTILS_PATH_MAX] = "";
955 const char *ldpath;
956 size_t n;
957
958 array_for_each(ldpaths, n, ldpath) {
959 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
960 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
961 return buf;
962 }
963
964 return NULL;
965}
635 966
636static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 967static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
637{ 968{
638 unsigned long i; 969 unsigned long i;
639 char *needed; 970 char *needed;
640 void *strtbl_void; 971 void *strtbl_void;
641 char *p; 972 char *p;
642 973
974 /*
975 * -n -> op==0 -> print all
976 * -N -> op==1 -> print requested
977 */
643 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 978 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
979 return NULL;
644 980
645 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 981 strtbl_void = elf_findsecbyname(elf, ".dynstr");
646 982
647 if (elf->phdr && strtbl_void) { 983 if (elf->phdr && strtbl_void) {
648#define SHOW_NEEDED(B) \ 984#define SHOW_NEEDED(B) \
650 Elf ## B ## _Dyn *dyn; \ 986 Elf ## B ## _Dyn *dyn; \
651 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 987 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
652 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 988 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
653 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 989 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
654 Elf ## B ## _Off offset; \ 990 Elf ## B ## _Off offset; \
991 size_t matched = 0; \
992 /* Walk all the program headers to find the PT_DYNAMIC */ \
655 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 993 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
656 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 994 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
995 continue; \
657 offset = EGET(phdr[i].p_offset); \ 996 offset = EGET(phdr[i].p_offset); \
658 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 997 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
998 continue; \
999 /* Walk all the dynamic tags to find NEEDED entries */ \
659 dyn = DYN ## B (elf->data + offset); \ 1000 dyn = DYN ## B (elf->vdata + offset); \
660 while (EGET(dyn->d_tag) != DT_NULL) { \ 1001 while (EGET(dyn->d_tag) != DT_NULL) { \
661 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 1002 if (EGET(dyn->d_tag) == DT_NEEDED) { \
662 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1003 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
663 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1004 if (offset >= (Elf ## B ## _Off)elf->len) { \
664 ++dyn; \ 1005 ++dyn; \
665 continue; \ 1006 continue; \
666 } \ 1007 } \
667 needed = (char*)(elf->data + offset); \ 1008 needed = elf->data + offset; \
668 if (op == 0) { \ 1009 if (op == 0) { \
1010 /* -n -> print all entries */ \
669 if (!be_wewy_wewy_quiet) { \ 1011 if (!be_wewy_wewy_quiet) { \
670 if (*found_needed) xchrcat(ret, ',', ret_len); \ 1012 if (*found_needed) xchrcat(ret, ',', ret_len); \
671 if (use_ldcache) \ 1013 if (use_ldpath) { \
1014 if ((p = lookup_config_lib(needed)) != NULL) \
1015 needed = p; \
1016 } else if (use_ldcache) { \
672 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 1017 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
673 needed = p; \ 1018 needed = p; \
1019 } \
674 xstrcat(ret, needed, ret_len); \ 1020 xstrcat(ret, needed, ret_len); \
675 } \ 1021 } \
676 *found_needed = 1; \ 1022 *found_needed = 1; \
677 } else { \ 1023 } else { \
678 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1024 /* -N -> print matching entries */ \
1025 size_t n; \
1026 const char *find_lib_name; \
1027 \
1028 array_for_each(find_lib_arr, n, find_lib_name) { \
1029 int invert = 1; \
1030 if (find_lib_name[0] == '!') \
1031 invert = 0, ++find_lib_name; \
1032 if (!strcmp(find_lib_name, needed) == invert) \
1033 ++matched; \
1034 } \
1035 \
1036 if (matched == array_cnt(find_lib_arr)) { \
679 *found_lib = 1; \ 1037 *found_lib = 1; \
680 return (be_wewy_wewy_quiet ? NULL : needed); \ 1038 return (be_wewy_wewy_quiet ? NULL : find_lib); \
681 } \ 1039 } \
682 } \ 1040 } \
683 } \ 1041 } \
684 ++dyn; \ 1042 ++dyn; \
685 } \ 1043 } \
707 *found_interp = 1; \ 1065 *found_interp = 1; \
708 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1066 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
709 } 1067 }
710 SHOW_INTERP(32) 1068 SHOW_INTERP(32)
711 SHOW_INTERP(64) 1069 SHOW_INTERP(64)
1070 } else {
1071 /* Walk all the program headers to find the PT_INTERP */
1072#define SHOW_PT_INTERP(B) \
1073 if (elf->elf_class == ELFCLASS ## B) { \
1074 unsigned long i; \
1075 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1076 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1077 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1078 if (EGET(phdr[i].p_type) != PT_INTERP) \
1079 continue; \
1080 *found_interp = 1; \
1081 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1082 } \
712 } 1083 }
1084 SHOW_PT_INTERP(32)
1085 SHOW_PT_INTERP(64)
1086 }
1087
713 return NULL; 1088 return NULL;
714} 1089}
715static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1090static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
716{ 1091{
717 unsigned long i; 1092 unsigned long i;
718 struct stat s; 1093 struct stat s;
1094 bool dynamic = false;
719 1095
720 if (!show_bind) return NULL; 1096 if (!show_bind) return NULL;
721 if (!elf->phdr) return NULL; 1097 if (!elf->phdr) return NULL;
722 1098
723#define SHOW_BIND(B) \ 1099#define SHOW_BIND(B) \
725 Elf ## B ## _Dyn *dyn; \ 1101 Elf ## B ## _Dyn *dyn; \
726 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1102 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
727 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1103 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
728 Elf ## B ## _Off offset; \ 1104 Elf ## B ## _Off offset; \
729 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1105 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
730 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1106 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1107 dynamic = true; \
731 offset = EGET(phdr[i].p_offset); \ 1108 offset = EGET(phdr[i].p_offset); \
732 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1109 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
733 dyn = DYN ## B (elf->data + offset); \ 1110 dyn = DYN ## B (elf->vdata + offset); \
734 while (EGET(dyn->d_tag) != DT_NULL) { \ 1111 while (EGET(dyn->d_tag) != DT_NULL) { \
735 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1112 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
736 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1113 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
737 { \ 1114 { \
738 if (be_quiet) return NULL; \ 1115 if (be_quiet) return NULL; \
746 SHOW_BIND(32) 1123 SHOW_BIND(32)
747 SHOW_BIND(64) 1124 SHOW_BIND(64)
748 1125
749 if (be_wewy_wewy_quiet) return NULL; 1126 if (be_wewy_wewy_quiet) return NULL;
750 1127
1128 /* don't output anything if quiet mode and the ELF is static or not setuid */
751 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1129 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
752 return NULL; 1130 return NULL;
753 } else { 1131 } else {
754 *found_bind = 1; 1132 *found_bind = 1;
755 return (char *) "LAZY"; 1133 return dynamic ? "LAZY" : "STATIC";
756 } 1134 }
757} 1135}
758static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1136static char *scanelf_file_soname(elfobj *elf, char *found_soname)
759{ 1137{
760 unsigned long i; 1138 unsigned long i;
772 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1150 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
773 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1151 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
774 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1152 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
775 Elf ## B ## _Off offset; \ 1153 Elf ## B ## _Off offset; \
776 /* only look for soname in shared objects */ \ 1154 /* only look for soname in shared objects */ \
777 if (ehdr->e_type != ET_DYN) \ 1155 if (EGET(ehdr->e_type) != ET_DYN) \
778 return NULL; \ 1156 return NULL; \
779 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1157 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
780 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1158 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
781 offset = EGET(phdr[i].p_offset); \ 1159 offset = EGET(phdr[i].p_offset); \
782 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1160 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
783 dyn = DYN ## B (elf->data + offset); \ 1161 dyn = DYN ## B (elf->vdata + offset); \
784 while (EGET(dyn->d_tag) != DT_NULL) { \ 1162 while (EGET(dyn->d_tag) != DT_NULL) { \
785 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1163 if (EGET(dyn->d_tag) == DT_SONAME) { \
786 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1164 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
787 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1165 if (offset >= (Elf ## B ## _Off)elf->len) { \
788 ++dyn; \ 1166 ++dyn; \
789 continue; \ 1167 continue; \
790 } \ 1168 } \
791 soname = (char*)(elf->data + offset); \ 1169 soname = elf->data + offset; \
792 *found_soname = 1; \ 1170 *found_soname = 1; \
793 return (be_wewy_wewy_quiet ? NULL : soname); \ 1171 return (be_wewy_wewy_quiet ? NULL : soname); \
794 } \ 1172 } \
795 ++dyn; \ 1173 ++dyn; \
796 } \ 1174 } \
799 SHOW_SONAME(64) 1177 SHOW_SONAME(64)
800 } 1178 }
801 1179
802 return NULL; 1180 return NULL;
803} 1181}
1182
1183/*
1184 * We support the symbol form:
1185 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1186 * If the symbol name is empty, then all symbols are matched.
1187 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1188 * Do not rely on this output format at all.
1189 * Otherwise the symbol name is used to search (either regex or string compare).
1190 * If the first char of the symbol name is a plus ("+"), then only match
1191 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1192 * Putting modifiers in between the percent signs allows for more in depth
1193 * filters. There are groups of modifiers. If you don't specify a member
1194 * of a group, then all types in that group are matched. The current
1195 * groups and their types are:
1196 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1197 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1198 * STV group: STV_DEFAULT:p STV_INTERNAL:i STV_HIDDEN:h STV_PROTECTED:P
1199 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1200 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1201 * You can search for multiple symbols at once by seperating with a comma (",").
1202 *
1203 * Some examples:
1204 * ELFs with a weak function "foo":
1205 * scanelf -s %wf%foo <ELFs>
1206 * ELFs that define the symbol "main":
1207 * scanelf -s +main <ELFs>
1208 * scanelf -s %d%main <ELFs>
1209 * ELFs that refer to the undefined symbol "brk":
1210 * scanelf -s -brk <ELFs>
1211 * scanelf -s %u%brk <ELFs>
1212 * All global defined objects in an ELF:
1213 * scanelf -s %ogd% <ELF>
1214 */
1215static void
1216scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1217 unsigned int stt, unsigned int stb, unsigned int stv, unsigned int shn, unsigned long size)
1218{
1219 const char *this_sym;
1220 size_t n;
1221
1222 array_for_each(find_sym_arr, n, this_sym) {
1223 bool inc_notype, inc_object, inc_func, inc_file,
1224 inc_local, inc_global, inc_weak,
1225 inc_visdef, inc_intern, inc_hidden, inc_prot,
1226 inc_def, inc_undef, inc_abs, inc_common;
1227
1228 /* symbol selection! */
1229 inc_notype = inc_object = inc_func = inc_file =
1230 inc_local = inc_global = inc_weak =
1231 inc_visdef = inc_intern = inc_hidden = inc_prot =
1232 inc_def = inc_undef = inc_abs = inc_common =
1233 (*this_sym != '%');
1234
1235 /* parse the contents of %...% */
1236 if (!inc_notype) {
1237 while (*(this_sym++)) {
1238 if (*this_sym == '%') {
1239 ++this_sym;
1240 break;
1241 }
1242 switch (*this_sym) {
1243 case 'n': inc_notype = true; break;
1244 case 'o': inc_object = true; break;
1245 case 'f': inc_func = true; break;
1246 case 'F': inc_file = true; break;
1247 case 'l': inc_local = true; break;
1248 case 'g': inc_global = true; break;
1249 case 'w': inc_weak = true; break;
1250 case 'p': inc_visdef = true; break;
1251 case 'i': inc_intern = true; break;
1252 case 'h': inc_hidden = true; break;
1253 case 'P': inc_prot = true; break;
1254 case 'd': inc_def = true; break;
1255 case 'u': inc_undef = true; break;
1256 case 'a': inc_abs = true; break;
1257 case 'c': inc_common = true; break;
1258 default: err("invalid symbol selector '%c'", *this_sym);
1259 }
1260 }
1261
1262 /* If no types are matched, not match all */
1263 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1264 inc_notype = inc_object = inc_func = inc_file = true;
1265 if (!inc_local && !inc_global && !inc_weak)
1266 inc_local = inc_global = inc_weak = true;
1267 if (!inc_visdef && !inc_intern && !inc_hidden && !inc_prot)
1268 inc_visdef = inc_intern = inc_hidden = inc_prot = true;
1269 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1270 inc_def = inc_undef = inc_abs = inc_common = true;
1271
1272 /* backwards compat for defined/undefined short hand */
1273 } else if (*this_sym == '+') {
1274 inc_undef = false;
1275 ++this_sym;
1276 } else if (*this_sym == '-') {
1277 inc_def = inc_abs = inc_common = false;
1278 ++this_sym;
1279 }
1280
1281 /* filter symbols */
1282 if ((!inc_notype && stt == STT_NOTYPE ) || \
1283 (!inc_object && stt == STT_OBJECT ) || \
1284 (!inc_func && stt == STT_FUNC ) || \
1285 (!inc_file && stt == STT_FILE ) || \
1286 (!inc_local && stb == STB_LOCAL ) || \
1287 (!inc_global && stb == STB_GLOBAL ) || \
1288 (!inc_weak && stb == STB_WEAK ) || \
1289 (!inc_visdef && stv == STV_DEFAULT ) || \
1290 (!inc_intern && stv == STV_INTERNAL ) || \
1291 (!inc_hidden && stv == STV_HIDDEN ) || \
1292 (!inc_prot && stv == STV_PROTECTED) || \
1293 (!inc_def && shn && shn < SHN_LORESERVE) || \
1294 (!inc_undef && shn == SHN_UNDEF ) || \
1295 (!inc_abs && shn == SHN_ABS ) || \
1296 (!inc_common && shn == SHN_COMMON ))
1297 continue;
1298
1299 if (*this_sym == '*') {
1300 /* a "*" symbol gets you debug output */
1301 printf("%s(%s) %5lX %-15s %-15s %-15s %-15s %s\n",
1302 ((*found_sym == 0) ? "\n\t" : "\t"),
1303 elf->base_filename,
1304 size,
1305 get_elfstttype(stt),
1306 get_elfstbtype(stb),
1307 get_elfstvtype(stv),
1308 get_elfshntype(shn),
1309 symname);
1310 goto matched;
1311
1312 } else {
1313 if (g_match) {
1314 /* regex match the symbol */
1315 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1316 continue;
1317
1318 } else if (*this_sym) {
1319 /* give empty symbols a "pass", else do a normal compare */
1320 const size_t len = strlen(this_sym);
1321 if (!(strncmp(this_sym, symname, len) == 0 &&
1322 /* Accept unversioned symbol names */
1323 (symname[len] == '\0' || symname[len] == '@')))
1324 continue;
1325 }
1326
1327 if (be_semi_verbose) {
1328 char buf[1024];
1329 snprintf(buf, sizeof(buf), "%lX %s %s",
1330 size,
1331 get_elfstttype(stt),
1332 this_sym);
1333 *ret = xstrdup(buf);
1334 } else {
1335 if (*ret) xchrcat(ret, ',', ret_len);
1336 xstrcat(ret, symname, ret_len);
1337 }
1338
1339 goto matched;
1340 }
1341 }
1342
1343 return;
1344
1345 matched:
1346 *found_sym = 1;
1347}
1348
804static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1349static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
805{ 1350{
806 unsigned long i;
807 char *ret; 1351 char *ret;
808 void *symtab_void, *strtab_void; 1352 void *symtab_void, *strtab_void;
809 1353
810 if (!find_sym) return NULL; 1354 if (!find_sym) return NULL;
811 ret = find_sym; 1355 ret = NULL;
812 1356
813 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1357 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
814 1358
815 if (symtab_void && strtab_void) { 1359 if (symtab_void && strtab_void) {
816#define FIND_SYM(B) \ 1360#define FIND_SYM(B) \
817 if (elf->elf_class == ELFCLASS ## B) { \ 1361 if (elf->elf_class == ELFCLASS ## B) { \
818 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1362 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
819 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1363 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
820 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1364 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
821 unsigned long cnt = EGET(symtab->sh_entsize); \ 1365 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
822 char *symname; \ 1366 char *symname; \
1367 size_t ret_len = 0; \
823 if (cnt) \ 1368 if (cnt) \
824 cnt = EGET(symtab->sh_size) / cnt; \ 1369 cnt = EGET(symtab->sh_size) / cnt; \
825 for (i = 0; i < cnt; ++i) { \ 1370 for (i = 0; i < cnt; ++i) { \
1371 if ((void*)sym > elf->data_end) { \
1372 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1373 goto break_out; \
1374 } \
826 if (sym->st_name) { \ 1375 if (sym->st_name) { \
1376 /* make sure the symbol name is in acceptable memory range */ \
827 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1377 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
828 if ((void*)symname > (void*)elf->data_end) { \ 1378 if ((void*)symname > elf->data_end) { \
829 warnf("%s: corrupt ELF symbols", elf->filename); \ 1379 warnf("%s: corrupt ELF symbols", elf->filename); \
1380 ++sym; \
830 continue; \ 1381 continue; \
831 } \ 1382 } \
832 if (*find_sym == '*') { \ 1383 scanelf_match_symname(elf, found_sym, \
833 printf("%s(%s) %5lX %15s %s\n", \ 1384 &ret, &ret_len, symname, \
834 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1385 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
835 elf->base_filename, \ 1386 ELF##B##_ST_BIND(EGET(sym->st_info)), \
836 (unsigned long)sym->st_size, \ 1387 ELF##B##_ST_VISIBILITY(EGET(sym->st_other)), \
837 get_elfstttype(sym->st_info), \ 1388 EGET(sym->st_shndx), \
838 symname); \ 1389 /* st_size can be 64bit, but no one is really that big, so screw em */ \
839 *found_sym = 1; \ 1390 EGET(sym->st_size)); \
840 } else { \
841 char *this_sym, *next_sym; \
842 this_sym = find_sym; \
843 do { \
844 next_sym = strchr(this_sym, ','); \
845 if (next_sym == NULL) \
846 next_sym = this_sym + strlen(this_sym); \
847 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
848 (strcmp(symname, versioned_symname) == 0)) { \
849 ret = this_sym; \
850 (*found_sym)++; \
851 goto break_out; \
852 } \
853 this_sym = next_sym + 1; \
854 } while (*next_sym != '\0'); \
855 } \
856 } \ 1391 } \
857 ++sym; \ 1392 ++sym; \
858 } } 1393 } \
1394 }
859 FIND_SYM(32) 1395 FIND_SYM(32)
860 FIND_SYM(64) 1396 FIND_SYM(64)
861 } 1397 }
862 1398
863break_out: 1399break_out:
866 if (*find_sym != '*' && *found_sym) 1402 if (*find_sym != '*' && *found_sym)
867 return ret; 1403 return ret;
868 if (be_quiet) 1404 if (be_quiet)
869 return NULL; 1405 return NULL;
870 else 1406 else
871 return (char *)" - "; 1407 return " - ";
872} 1408}
873 1409
1410static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1411{
1412 if (!find_section)
1413 return NULL;
1414
1415#define FIND_SECTION(B) \
1416 if (elf->elf_class == ELFCLASS ## B) { \
1417 size_t matched, n; \
1418 int invert; \
1419 const char *section_name; \
1420 Elf ## B ## _Shdr *section; \
1421 \
1422 matched = 0; \
1423 array_for_each(find_section_arr, n, section_name) { \
1424 invert = (*section_name == '!' ? 1 : 0); \
1425 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1426 if ((section == NULL && invert) || (section != NULL && !invert)) \
1427 ++matched; \
1428 } \
1429 \
1430 if (matched == array_cnt(find_section_arr)) \
1431 *found_section = 1; \
1432 }
1433 FIND_SECTION(32)
1434 FIND_SECTION(64)
1435
1436 if (be_wewy_wewy_quiet)
1437 return NULL;
1438
1439 if (*found_section)
1440 return find_section;
1441
1442 if (be_quiet)
1443 return NULL;
1444 else
1445 return " - ";
1446}
874 1447
875/* scan an elf file and show all the fun stuff */ 1448/* scan an elf file and show all the fun stuff */
876#define prints(str) write(fileno(stdout), str, strlen(str)) 1449#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
877static int scanelf_elfobj(elfobj *elf) 1450static int scanelf_elfobj(elfobj *elf)
878{ 1451{
879 unsigned long i; 1452 unsigned long i;
880 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1453 char found_pax, found_phdr, found_relro, found_load, found_textrel,
881 found_rpath, found_needed, found_interp, found_bind, found_soname, 1454 found_rpath, found_needed, found_interp, found_bind, found_soname,
882 found_sym, found_lib, found_file, found_textrels; 1455 found_sym, found_lib, found_file, found_textrels, found_section;
883 static char *out_buffer = NULL; 1456 static char *out_buffer = NULL;
884 static size_t out_len; 1457 static size_t out_len;
885 1458
886 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1459 found_pax = found_phdr = found_relro = found_load = found_textrel = \
887 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1460 found_rpath = found_needed = found_interp = found_bind = found_soname = \
888 found_sym = found_lib = found_file = found_textrels = 0; 1461 found_sym = found_lib = found_file = found_textrels = found_section = 0;
889 1462
890 if (be_verbose > 2) 1463 if (be_verbose > 2)
891 printf("%s: scanning file {%s,%s}\n", elf->filename, 1464 printf("%s: scanning file {%s,%s}\n", elf->filename,
892 get_elfeitype(EI_CLASS, elf->elf_class), 1465 get_elfeitype(EI_CLASS, elf->elf_class),
893 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1466 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
895 printf("%s: scanning file\n", elf->filename); 1468 printf("%s: scanning file\n", elf->filename);
896 1469
897 /* init output buffer */ 1470 /* init output buffer */
898 if (!out_buffer) { 1471 if (!out_buffer) {
899 out_len = sizeof(char) * 80; 1472 out_len = sizeof(char) * 80;
900 out_buffer = (char*)xmalloc(out_len); 1473 out_buffer = xmalloc(out_len);
901 } 1474 }
902 *out_buffer = '\0'; 1475 *out_buffer = '\0';
903 1476
904 /* show the header */ 1477 /* show the header */
905 if (!be_quiet && show_banner) { 1478 if (!be_quiet && show_banner) {
906 for (i = 0; out_format[i]; ++i) { 1479 for (i = 0; out_format[i]; ++i) {
907 if (!IS_MODIFIER(out_format[i])) continue; 1480 if (!IS_MODIFIER(out_format[i])) continue;
908 1481
909 switch (out_format[++i]) { 1482 switch (out_format[++i]) {
1483 case '+': break;
910 case '%': break; 1484 case '%': break;
911 case '#': break; 1485 case '#': break;
912 case 'F': 1486 case 'F':
913 case 'p': 1487 case 'p':
914 case 'f': prints("FILE "); found_file = 1; break; 1488 case 'f': prints("FILE "); found_file = 1; break;
915 case 'o': prints(" TYPE "); break; 1489 case 'o': prints(" TYPE "); break;
916 case 'x': prints(" PAX "); break; 1490 case 'x': prints(" PAX "); break;
917 case 'e': prints("STK/REL/PTL "); break; 1491 case 'e': prints("STK/REL/PTL "); break;
918 case 't': prints("TEXTREL "); break; 1492 case 't': prints("TEXTREL "); break;
919 case 'r': prints("RPATH "); break; 1493 case 'r': prints("RPATH "); break;
1494 case 'M': prints("CLASS "); break;
1495 case 'l':
920 case 'n': prints("NEEDED "); break; 1496 case 'n': prints("NEEDED "); break;
921 case 'i': prints("INTERP "); break; 1497 case 'i': prints("INTERP "); break;
922 case 'b': prints("BIND "); break; 1498 case 'b': prints("BIND "); break;
1499 case 'Z': prints("SIZE "); break;
923 case 'S': prints("SONAME "); break; 1500 case 'S': prints("SONAME "); break;
924 case 's': prints("SYM "); break; 1501 case 's': prints("SYM "); break;
925 case 'N': prints("LIB "); break; 1502 case 'N': prints("LIB "); break;
926 case 'T': prints("TEXTRELS "); break; 1503 case 'T': prints("TEXTRELS "); break;
1504 case 'k': prints("SECTION "); break;
1505 case 'a': prints("ARCH "); break;
1506 case 'I': prints("OSABI "); break;
1507 case 'Y': prints("EABI "); break;
1508 case 'O': prints("PERM "); break;
1509 case 'D': prints("ENDIAN "); break;
927 default: warnf("'%c' has no title ?", out_format[i]); 1510 default: warnf("'%c' has no title ?", out_format[i]);
928 } 1511 }
929 } 1512 }
930 if (!found_file) prints("FILE "); 1513 if (!found_file) prints("FILE ");
931 prints("\n"); 1514 prints("\n");
935 1518
936 /* dump all the good stuff */ 1519 /* dump all the good stuff */
937 for (i = 0; out_format[i]; ++i) { 1520 for (i = 0; out_format[i]; ++i) {
938 const char *out; 1521 const char *out;
939 const char *tmp; 1522 const char *tmp;
940 1523 static char ubuf[sizeof(unsigned long)*2];
941 /* make sure we trim leading spaces in quiet mode */
942 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
943 *out_buffer = '\0';
944
945 if (!IS_MODIFIER(out_format[i])) { 1524 if (!IS_MODIFIER(out_format[i])) {
946 xchrcat(&out_buffer, out_format[i], &out_len); 1525 xchrcat(&out_buffer, out_format[i], &out_len);
947 continue; 1526 continue;
948 } 1527 }
949 1528
950 out = NULL; 1529 out = NULL;
951 be_wewy_wewy_quiet = (out_format[i] == '#'); 1530 be_wewy_wewy_quiet = (out_format[i] == '#');
1531 be_semi_verbose = (out_format[i] == '+');
952 switch (out_format[++i]) { 1532 switch (out_format[++i]) {
1533 case '+':
953 case '%': 1534 case '%':
954 case '#': 1535 case '#':
955 xchrcat(&out_buffer, out_format[i], &out_len); break; 1536 xchrcat(&out_buffer, out_format[i], &out_len); break;
956 case 'F': 1537 case 'F':
957 found_file = 1; 1538 found_file = 1;
983 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1564 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
984 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1565 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
985 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1566 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
986 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1567 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
987 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1568 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1569 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1570 case 'D': out = get_endian(elf); break;
1571 case 'O': out = strfileperms(elf->filename); break;
988 case 'n': 1572 case 'n':
989 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1573 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
990 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1574 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
991 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1575 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
992 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1576 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
993 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1577 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1578 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1579 case 'a': out = get_elfemtype(elf); break;
1580 case 'I': out = get_elfosabi(elf); break;
1581 case 'Y': out = get_elf_eabi(elf); break;
1582 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
994 default: warnf("'%c' has no scan code?", out_format[i]); 1583 default: warnf("'%c' has no scan code?", out_format[i]);
995 } 1584 }
996 if (out) { 1585 if (out)
997 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
998 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
999 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1000 else
1001 xstrcat(&out_buffer, out, &out_len); 1586 xstrcat(&out_buffer, out, &out_len);
1002 }
1003 } 1587 }
1004 1588
1005#define FOUND_SOMETHING() \ 1589#define FOUND_SOMETHING() \
1006 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1590 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1007 found_rpath || found_needed || found_interp || found_bind || \ 1591 found_rpath || found_needed || found_interp || found_bind || \
1008 found_soname || found_sym || found_lib || found_textrels) 1592 found_soname || found_sym || found_lib || found_textrels || found_section )
1009 1593
1010 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1594 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1011 xchrcat(&out_buffer, ' ', &out_len); 1595 xchrcat(&out_buffer, ' ', &out_len);
1012 xstrcat(&out_buffer, elf->filename, &out_len); 1596 xstrcat(&out_buffer, elf->filename, &out_len);
1013 } 1597 }
1020} 1604}
1021 1605
1022/* scan a single elf */ 1606/* scan a single elf */
1023static int scanelf_elf(const char *filename, int fd, size_t len) 1607static int scanelf_elf(const char *filename, int fd, size_t len)
1024{ 1608{
1025 int ret; 1609 int ret = 1;
1610 size_t n;
1611 const char *match_etype;
1026 elfobj *elf; 1612 elfobj *elf;
1027 1613
1028 /* verify this is real ELF */ 1614 /* Verify this is a real ELF */
1029 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) { 1615 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1030 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 1616 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1031 return 1; 1617 return 2;
1032 }
1033
1034 if (strlen(match_etypes)) {
1035 char sbuf[126];
1036 strncpy(sbuf, match_etypes, sizeof(sbuf));
1037 if (strchr(match_etypes, ',') != NULL) {
1038 char *p;
1039 while((p = strrchr(sbuf, ',')) != NULL) {
1040 *p = 0;
1041 if (atoi(p+1) == get_etype(elf))
1042 goto label_ret;
1043 }
1044 } 1618 }
1045 if (atoi(sbuf) != get_etype(elf)) { 1619
1046 ret = 1; 1620 /* Possibly filter based on ELF bitness */
1621 switch (match_bits) {
1622 case 32:
1623 if (elf->elf_class != ELFCLASS32)
1047 goto label_done; 1624 goto done;
1625 break;
1626 case 64:
1627 if (elf->elf_class != ELFCLASS64)
1628 goto done;
1629 break;
1048 } 1630 }
1049 }
1050 1631
1051label_ret: 1632 /* Possibly filter based on the ELF's e_type field */
1633 array_for_each(match_etypes, n, match_etype)
1634 if (etype_lookup(match_etype) == get_etype(elf))
1635 goto scanit;
1636 if (array_cnt(match_etypes))
1637 goto done;
1638
1639 scanit:
1052 ret = scanelf_elfobj(elf); 1640 ret = scanelf_elfobj(elf);
1053 1641
1054label_done: 1642 done:
1055 unreadelf(elf); 1643 unreadelf(elf);
1056 return ret; 1644 return ret;
1057} 1645}
1058 1646
1059/* scan an archive of elfs */ 1647/* scan an archive of elfs */
1066 1654
1067 ar = ar_open_fd(filename, fd); 1655 ar = ar_open_fd(filename, fd);
1068 if (ar == NULL) 1656 if (ar == NULL)
1069 return 1; 1657 return 1;
1070 1658
1071 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0); 1659 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1072 while ((m=ar_next(ar)) != NULL) { 1660 while ((m = ar_next(ar)) != NULL) {
1661 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1662 if (cur_pos == -1)
1663 errp("lseek() failed");
1073 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size); 1664 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1074 if (elf) { 1665 if (elf) {
1075 scanelf_elfobj(elf); 1666 scanelf_elfobj(elf);
1076 unreadelf(elf); 1667 unreadelf(elf);
1077 } 1668 }
1078 } 1669 }
1079 munmap(ar_buffer, len); 1670 munmap(ar_buffer, len);
1080 1671
1081 return 0; 1672 return 0;
1082} 1673}
1083/* scan a file which may be an elf or an archive or some other magical beast */ 1674/* scan a file which may be an elf or an archive or some other magical beast */
1084static void scanelf_file(const char *filename) 1675static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1085{ 1676{
1677 const struct stat *st = st_cache;
1086 struct stat st; 1678 struct stat symlink_st;
1087 int fd; 1679 int fd;
1088 1680
1089 /* make sure 'filename' exists */
1090 if (lstat(filename, &st) == -1) {
1091 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1092 return;
1093 }
1094
1095 /* always handle regular files and handle symlinked files if no -y */ 1681 /* always handle regular files and handle symlinked files if no -y */
1096 if (S_ISLNK(st.st_mode)) { 1682 if (S_ISLNK(st->st_mode)) {
1097 if (!scan_symlink) return; 1683 if (!scan_symlink)
1098 stat(filename, &st); 1684 return 1;
1685 fstatat(dir_fd, filename, &symlink_st, 0);
1686 st = &symlink_st;
1099 } 1687 }
1688
1100 if (!S_ISREG(st.st_mode)) { 1689 if (!S_ISREG(st->st_mode)) {
1101 if (be_verbose > 2) printf("%s: skipping non-file\n", filename); 1690 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1102 return; 1691 return 1;
1103 } 1692 }
1104 1693
1105 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1) 1694 if (match_perms) {
1695 if ((st->st_mode | match_perms) != st->st_mode)
1696 return 1;
1697 }
1698 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1699 if (fd == -1) {
1700 if (fix_elf && errno == ETXTBSY)
1701 warnp("%s: could not fix", filename);
1702 else if (be_verbose > 2)
1703 printf("%s: skipping file: %s\n", filename, strerror(errno));
1106 return; 1704 return 1;
1705 }
1107 1706
1108 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives) 1707 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1109 /* if it isn't an ELF, maybe it's an .a archive */ 1708 /* if it isn't an ELF, maybe it's an .a archive */
1709 if (scan_archives)
1110 scanelf_archive(filename, fd, st.st_size); 1710 scanelf_archive(filename, fd, st->st_size);
1111 1711
1712 /*
1713 * unreadelf() implicitly closes its fd, so only close it
1714 * when we are returning it in the non-ELF case
1715 */
1112 close(fd); 1716 close(fd);
1717 }
1718
1719 return 0;
1113} 1720}
1114 1721
1115/* scan a directory for ET_EXEC files and print when we find one */ 1722/* scan a directory for ET_EXEC files and print when we find one */
1116static void scanelf_dir(const char *path) 1723static int scanelf_dirat(int dir_fd, const char *path)
1117{ 1724{
1118 register DIR *dir; 1725 register DIR *dir;
1119 register struct dirent *dentry; 1726 register struct dirent *dentry;
1120 struct stat st_top, st; 1727 struct stat st_top, st;
1121 char buf[__PAX_UTILS_PATH_MAX]; 1728 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1122 size_t pathlen = 0, len = 0; 1729 size_t pathlen = 0, len = 0;
1730 int ret = 0;
1731 int subdir_fd;
1123 1732
1124 /* make sure path exists */ 1733 /* make sure path exists */
1125 if (lstat(path, &st_top) == -1) { 1734 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1126 if (be_verbose > 2) printf("%s: does not exist\n", path); 1735 if (be_verbose > 2) printf("%s: does not exist\n", path);
1127 return; 1736 return 1;
1128 } 1737 }
1129 1738
1130 /* ok, if it isn't a directory, assume we can open it */ 1739 /* ok, if it isn't a directory, assume we can open it */
1131 if (!S_ISDIR(st_top.st_mode)) { 1740 if (!S_ISDIR(st_top.st_mode))
1132 scanelf_file(path); 1741 return scanelf_fileat(dir_fd, path, &st_top);
1133 return;
1134 }
1135 1742
1136 /* now scan the dir looking for fun stuff */ 1743 /* now scan the dir looking for fun stuff */
1137 if ((dir = opendir(path)) == NULL) { 1744 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1138 warnf("could not opendir %s: %s", path, strerror(errno)); 1745 if (subdir_fd == -1)
1746 dir = NULL;
1747 else
1748 dir = fdopendir(subdir_fd);
1749 if (dir == NULL) {
1750 if (subdir_fd != -1)
1751 close(subdir_fd);
1752 else if (be_verbose > 2)
1753 printf("%s: skipping dir: %s\n", path, strerror(errno));
1139 return; 1754 return 1;
1140 } 1755 }
1141 if (be_verbose > 1) printf("%s: scanning dir\n", path); 1756 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1142 1757
1143 pathlen = strlen(path); 1758 subpath = stpcpy(buf, path);
1759 if (subpath[-1] != '/')
1760 *subpath++ = '/';
1761 pathlen = subpath - buf;
1144 while ((dentry = readdir(dir))) { 1762 while ((dentry = readdir(dir))) {
1145 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1763 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1146 continue; 1764 continue;
1765
1766 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1767 continue;
1768
1147 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1769 len = strlen(dentry->d_name);
1148 if (len >= sizeof(buf)) { 1770 if (len + pathlen + 1 >= sizeof(buf)) {
1149 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1771 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1150 (unsigned long)len, (unsigned long)sizeof(buf)); 1772 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1151 continue; 1773 continue;
1152 } 1774 }
1153 sprintf(buf, "%s/%s", path, dentry->d_name); 1775 memcpy(subpath, dentry->d_name, len);
1154 if (lstat(buf, &st) != -1) { 1776 subpath[len] = '\0';
1777
1155 if (S_ISREG(st.st_mode)) 1778 if (S_ISREG(st.st_mode))
1156 scanelf_file(buf); 1779 ret = scanelf_fileat(dir_fd, buf, &st);
1157 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1780 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1158 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1781 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1159 scanelf_dir(buf); 1782 ret = scanelf_dirat(dir_fd, buf);
1160 }
1161 } 1783 }
1162 } 1784 }
1163 closedir(dir); 1785 closedir(dir);
1164}
1165 1786
1787 return ret;
1788}
1789static int scanelf_dir(const char *path)
1790{
1791 return scanelf_dirat(root_fd, root_rel_path(path));
1792}
1793
1166static int scanelf_from_file(char *filename) 1794static int scanelf_from_file(const char *filename)
1167{ 1795{
1168 FILE *fp = NULL; 1796 FILE *fp;
1169 char *p; 1797 char *p, *path;
1170 char path[__PAX_UTILS_PATH_MAX]; 1798 size_t len;
1799 int ret;
1171 1800
1172 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1801 if (strcmp(filename, "-") == 0)
1173 fp = stdin; 1802 fp = stdin;
1174 else if ((fp = fopen(filename, "r")) == NULL) 1803 else if ((fp = fopen(filename, "r")) == NULL)
1175 return 1; 1804 return 1;
1176 1805
1177 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1806 path = NULL;
1807 len = 0;
1808 ret = 0;
1809 while (getline(&path, &len, fp) != -1) {
1178 if ((p = strchr(path, '\n')) != NULL) 1810 if ((p = strchr(path, '\n')) != NULL)
1179 *p = 0; 1811 *p = 0;
1180 search_path = path; 1812 search_path = path;
1181 scanelf_dir(path); 1813 ret = scanelf_dir(path);
1182 } 1814 }
1815 free(path);
1816
1183 if (fp != stdin) 1817 if (fp != stdin)
1184 fclose(fp); 1818 fclose(fp);
1819
1185 return 0; 1820 return ret;
1186} 1821}
1187 1822
1188static void load_ld_so_conf() 1823#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1824
1825static int _load_ld_cache_config(const char *fname)
1189{ 1826{
1190 FILE *fp = NULL; 1827 FILE *fp = NULL;
1191 char *p; 1828 char *p, *path;
1192 char path[__PAX_UTILS_PATH_MAX]; 1829 size_t len;
1193 int i = 0; 1830 int curr_fd = -1;
1194 1831
1195 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1832 fp = fopenat_r(root_fd, root_rel_path(fname));
1833 if (fp == NULL)
1196 return; 1834 return -1;
1197 1835
1198 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1836 path = NULL;
1199 if (*path != '/') 1837 len = 0;
1200 continue; 1838 while (getline(&path, &len, fp) != -1) {
1201
1202 if ((p = strrchr(path, '\r')) != NULL) 1839 if ((p = strrchr(path, '\r')) != NULL)
1203 *p = 0; 1840 *p = 0;
1204 if ((p = strchr(path, '\n')) != NULL) 1841 if ((p = strchr(path, '\n')) != NULL)
1205 *p = 0; 1842 *p = 0;
1206 1843
1207 ldpaths[i++] = xstrdup(path); 1844 /* recursive includes of the same file will make this segfault. */
1845 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1846 glob_t gl;
1847 size_t x;
1848 const char *gpath;
1208 1849
1209 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1850 /* re-use existing path buffer ... need to be creative */
1210 break; 1851 if (path[8] != '/')
1852 gpath = memcpy(path + 3, "/etc/", 5);
1853 else
1854 gpath = path + 8;
1855 if (root_fd != AT_FDCWD) {
1856 if (curr_fd == -1) {
1857 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1858 if (fchdir(root_fd))
1859 errp("unable to change to root dir");
1860 }
1861 gpath = root_rel_path(gpath);
1862 }
1863
1864 if (glob(gpath, 0, NULL, &gl) == 0) {
1865 for (x = 0; x < gl.gl_pathc; ++x) {
1866 /* try to avoid direct loops */
1867 if (strcmp(gl.gl_pathv[x], fname) == 0)
1868 continue;
1869 _load_ld_cache_config(gl.gl_pathv[x]);
1870 }
1871 globfree(&gl);
1872 }
1873
1874 /* failed globs are ignored by glibc */
1875 continue;
1211 } 1876 }
1212 ldpaths[i] = NULL; 1877
1878 if (*path != '/')
1879 continue;
1880
1881 xarraypush_str(ldpaths, path);
1882 }
1883 free(path);
1213 1884
1214 fclose(fp); 1885 fclose(fp);
1886
1887 if (curr_fd != -1) {
1888 if (fchdir(curr_fd))
1889 {/* don't care */}
1890 close(curr_fd);
1891 }
1892
1893 return 0;
1894}
1895
1896#elif defined(__FreeBSD__) || defined(__DragonFly__)
1897
1898static int _load_ld_cache_config(const char *fname)
1899{
1900 FILE *fp = NULL;
1901 char *b = NULL, *p;
1902 struct elfhints_hdr hdr;
1903
1904 fp = fopenat_r(root_fd, root_rel_path(fname));
1905 if (fp == NULL)
1906 return -1;
1907
1908 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1909 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1910 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1911 {
1912 fclose(fp);
1913 return -1;
1914 }
1915
1916 b = xmalloc(hdr.dirlistlen + 1);
1917 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1918 fclose(fp);
1919 free(b);
1920 return -1;
1921 }
1922
1923 while ((p = strsep(&b, ":"))) {
1924 if (*p == '\0')
1925 continue;
1926 xarraypush_str(ldpaths, p);
1927 }
1928
1929 free(b);
1930 fclose(fp);
1931 return 0;
1932}
1933
1934#else
1935#ifdef __ELF__
1936#warning Cache config support not implemented for your target
1937#endif
1938static int _load_ld_cache_config(const char *fname)
1939{
1940 return 0;
1941}
1942#endif
1943
1944static void load_ld_cache_config(const char *fname)
1945{
1946 bool scan_l, scan_ul, scan_ull;
1947 size_t n;
1948 const char *ldpath;
1949
1950 _load_ld_cache_config(fname);
1951
1952 scan_l = scan_ul = scan_ull = false;
1953 array_for_each(ldpaths, n, ldpath) {
1954 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1955 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1956 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1957 }
1958
1959 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1960 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1961 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1215} 1962}
1216 1963
1217/* scan /etc/ld.so.conf for paths */ 1964/* scan /etc/ld.so.conf for paths */
1218static void scanelf_ldpath() 1965static void scanelf_ldpath(void)
1219{ 1966{
1220 char scan_l, scan_ul, scan_ull; 1967 size_t n;
1221 int i = 0; 1968 const char *ldpath;
1222 1969
1223 if (!ldpaths[0]) 1970 array_for_each(ldpaths, n, ldpath)
1224 err("Unable to load any paths from ld.so.conf");
1225
1226 scan_l = scan_ul = scan_ull = 0;
1227
1228 while (ldpaths[i]) {
1229 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1230 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1231 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1232 scanelf_dir(ldpaths[i]); 1971 scanelf_dir(ldpath);
1233 ++i;
1234 }
1235
1236 if (!scan_l) scanelf_dir("/lib");
1237 if (!scan_ul) scanelf_dir("/usr/lib");
1238 if (!scan_ull) scanelf_dir("/usr/local/lib");
1239} 1972}
1240 1973
1241/* scan env PATH for paths */ 1974/* scan env PATH for paths */
1242static void scanelf_envpath() 1975static void scanelf_envpath(void)
1243{ 1976{
1244 char *path, *p; 1977 char *path, *p;
1245 1978
1246 path = getenv("PATH"); 1979 path = getenv("PATH");
1247 if (!path) 1980 if (!path)
1254 } 1987 }
1255 1988
1256 free(path); 1989 free(path);
1257} 1990}
1258 1991
1259 1992/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1260/* usage / invocation handling functions */
1261#define PARSE_FLAGS "plRmyAXxetrnLibSs:gN:TaqvF:f:o:E:BhV" 1993#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1262#define a_argument required_argument 1994#define a_argument required_argument
1263static struct option const long_opts[] = { 1995static struct option const long_opts[] = {
1264 {"path", no_argument, NULL, 'p'}, 1996 {"path", no_argument, NULL, 'p'},
1265 {"ldpath", no_argument, NULL, 'l'}, 1997 {"ldpath", no_argument, NULL, 'l'},
1998 {"use-ldpath",no_argument, NULL, 129},
1999 {"root", a_argument, NULL, 128},
1266 {"recursive", no_argument, NULL, 'R'}, 2000 {"recursive", no_argument, NULL, 'R'},
1267 {"mount", no_argument, NULL, 'm'}, 2001 {"mount", no_argument, NULL, 'm'},
1268 {"symlink", no_argument, NULL, 'y'}, 2002 {"symlink", no_argument, NULL, 'y'},
1269 {"archives", no_argument, NULL, 'A'}, 2003 {"archives", no_argument, NULL, 'A'},
1270 {"ldcache", no_argument, NULL, 'L'}, 2004 {"ldcache", no_argument, NULL, 'L'},
1271 {"fix", no_argument, NULL, 'X'}, 2005 {"fix", no_argument, NULL, 'X'},
2006 {"setpax", a_argument, NULL, 'z'},
1272 {"pax", no_argument, NULL, 'x'}, 2007 {"pax", no_argument, NULL, 'x'},
1273 {"header", no_argument, NULL, 'e'}, 2008 {"header", no_argument, NULL, 'e'},
1274 {"textrel", no_argument, NULL, 't'}, 2009 {"textrel", no_argument, NULL, 't'},
1275 {"rpath", no_argument, NULL, 'r'}, 2010 {"rpath", no_argument, NULL, 'r'},
1276 {"needed", no_argument, NULL, 'n'}, 2011 {"needed", no_argument, NULL, 'n'},
1277 {"interp", no_argument, NULL, 'i'}, 2012 {"interp", no_argument, NULL, 'i'},
1278 {"bind", no_argument, NULL, 'b'}, 2013 {"bind", no_argument, NULL, 'b'},
1279 {"soname", no_argument, NULL, 'S'}, 2014 {"soname", no_argument, NULL, 'S'},
1280 {"symbol", a_argument, NULL, 's'}, 2015 {"symbol", a_argument, NULL, 's'},
2016 {"section", a_argument, NULL, 'k'},
1281 {"lib", a_argument, NULL, 'N'}, 2017 {"lib", a_argument, NULL, 'N'},
1282 {"gmatch", no_argument, NULL, 'g'}, 2018 {"gmatch", no_argument, NULL, 'g'},
1283 {"textrels", no_argument, NULL, 'T'}, 2019 {"textrels", no_argument, NULL, 'T'},
1284 {"etype", a_argument, NULL, 'E'}, 2020 {"etype", a_argument, NULL, 'E'},
2021 {"bits", a_argument, NULL, 'M'},
2022 {"endian", no_argument, NULL, 'D'},
2023 {"osabi", no_argument, NULL, 'I'},
2024 {"eabi", no_argument, NULL, 'Y'},
2025 {"perms", a_argument, NULL, 'O'},
2026 {"size", no_argument, NULL, 'Z'},
1285 {"all", no_argument, NULL, 'a'}, 2027 {"all", no_argument, NULL, 'a'},
1286 {"quiet", no_argument, NULL, 'q'}, 2028 {"quiet", no_argument, NULL, 'q'},
1287 {"verbose", no_argument, NULL, 'v'}, 2029 {"verbose", no_argument, NULL, 'v'},
1288 {"format", a_argument, NULL, 'F'}, 2030 {"format", a_argument, NULL, 'F'},
1289 {"from", a_argument, NULL, 'f'}, 2031 {"from", a_argument, NULL, 'f'},
1290 {"file", a_argument, NULL, 'o'}, 2032 {"file", a_argument, NULL, 'o'},
2033 {"nocolor", no_argument, NULL, 'C'},
1291 {"nobanner", no_argument, NULL, 'B'}, 2034 {"nobanner", no_argument, NULL, 'B'},
1292 {"help", no_argument, NULL, 'h'}, 2035 {"help", no_argument, NULL, 'h'},
1293 {"version", no_argument, NULL, 'V'}, 2036 {"version", no_argument, NULL, 'V'},
1294 {NULL, no_argument, NULL, 0x0} 2037 {NULL, no_argument, NULL, 0x0}
1295}; 2038};
1296 2039
1297static const char *opts_help[] = { 2040static const char * const opts_help[] = {
1298 "Scan all directories in PATH environment", 2041 "Scan all directories in PATH environment",
1299 "Scan all directories in /etc/ld.so.conf", 2042 "Scan all directories in /etc/ld.so.conf",
2043 "Use ld.so.conf to show full path (use with -r/-n)",
2044 "Root directory (use with -l or -p)",
1300 "Scan directories recursively", 2045 "Scan directories recursively",
1301 "Don't recursively cross mount points", 2046 "Don't recursively cross mount points",
1302 "Don't scan symlinks", 2047 "Don't scan symlinks",
1303 "Scan archives (.a files)", 2048 "Scan archives (.a files)",
1304 "Utilize ld.so.cache information (use with -r/-n)", 2049 "Utilize ld.so.cache to show full path (use with -r/-n)",
1305 "Try and 'fix' bad things (use with -r/-e)\n", 2050 "Try and 'fix' bad things (use with -r/-e)",
2051 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1306 "Print PaX markings", 2052 "Print PaX markings",
1307 "Print GNU_STACK/PT_LOAD markings", 2053 "Print GNU_STACK/PT_LOAD markings",
1308 "Print TEXTREL information", 2054 "Print TEXTREL information",
1309 "Print RPATH information", 2055 "Print RPATH information",
1310 "Print NEEDED information", 2056 "Print NEEDED information",
1311 "Print INTERP information", 2057 "Print INTERP information",
1312 "Print BIND information", 2058 "Print BIND information",
1313 "Print SONAME information", 2059 "Print SONAME information",
1314 "Find a specified symbol", 2060 "Find a specified symbol",
2061 "Find a specified section",
1315 "Find a specified library", 2062 "Find a specified library",
1316 "Use strncmp to match libraries. (use with -N)", 2063 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1317 "Locate cause of TEXTREL", 2064 "Locate cause of TEXTREL",
2065 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1318 "Print only ELF files matching numeric constant", 2066 "Print only ELF files matching numeric bits",
1319 "Print all scanned info (-x -e -t -r -b)\n", 2067 "Print Endianness",
2068 "Print OSABI",
2069 "Print EABI (EM_ARM Only)",
2070 "Print only ELF files matching octal permissions",
2071 "Print ELF file size",
2072 "Print all useful/simple info\n",
1320 "Only output 'bad' things", 2073 "Only output 'bad' things",
1321 "Be verbose (can be specified more than once)", 2074 "Be verbose (can be specified more than once)",
1322 "Use specified format for output", 2075 "Use specified format for output",
1323 "Read input stream from a filename", 2076 "Read input stream from a filename",
1324 "Write output stream to a filename", 2077 "Write output stream to a filename",
2078 "Don't emit color in output",
1325 "Don't display the header", 2079 "Don't display the header",
1326 "Print this help and exit", 2080 "Print this help and exit",
1327 "Print version and exit", 2081 "Print version and exit",
1328 NULL 2082 NULL
1329}; 2083};
1330 2084
1331/* display usage and exit */ 2085/* display usage and exit */
1332static void usage(int status) 2086static void usage(int status)
1333{ 2087{
1334 unsigned long i; 2088 const char a_arg[] = "<arg>";
2089 size_t a_arg_len = strlen(a_arg) + 2;
2090 size_t i;
2091 int optlen;
1335 printf("* Scan ELF binaries for stuff\n\n" 2092 printf("* Scan ELF binaries for stuff\n\n"
1336 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0); 2093 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1337 printf("Options: -[%s]\n", PARSE_FLAGS); 2094 printf("Options: -[%s]\n", PARSE_FLAGS);
2095
2096 /* prescan the --long opt length to auto-align */
2097 optlen = 0;
1338 for (i = 0; long_opts[i].name; ++i) 2098 for (i = 0; long_opts[i].name; ++i) {
2099 int l = strlen(long_opts[i].name);
2100 if (long_opts[i].has_arg == a_argument)
2101 l += a_arg_len;
2102 optlen = max(l, optlen);
2103 }
2104
2105 for (i = 0; long_opts[i].name; ++i) {
2106 /* first output the short flag if it has one */
2107 if (long_opts[i].val > '~')
2108 printf(" ");
2109 else
2110 printf(" -%c, ", long_opts[i].val);
2111
2112 /* then the long flag */
1339 if (long_opts[i].has_arg == no_argument) 2113 if (long_opts[i].has_arg == no_argument)
1340 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2114 printf("--%-*s", optlen, long_opts[i].name);
1341 long_opts[i].name, opts_help[i]);
1342 else 2115 else
1343 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2116 printf("--%s %s %*s", long_opts[i].name, a_arg,
1344 long_opts[i].name, opts_help[i]); 2117 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1345 2118
1346 if (status != EXIT_SUCCESS) 2119 /* finally the help text */
1347 exit(status); 2120 printf("* %s\n", opts_help[i]);
2121 }
1348 2122
1349 puts("\nThe format modifiers for the -F option are:"); 2123 puts("\nFor more information, see the scanelf(1) manpage");
1350 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1351 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1352 puts(" i INTERP \tb BIND \ts symbol");
1353 puts(" N library \to Type \tT TEXTRELs");
1354 puts(" S SONAME");
1355 puts(" p filename (with search path removed)");
1356 puts(" f filename (short name/basename)");
1357 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1358
1359 exit(status); 2124 exit(status);
1360} 2125}
1361 2126
1362/* parse command line arguments and preform needed actions */ 2127/* parse command line arguments and preform needed actions */
2128#define do_pax_state(option, flag) \
2129 if (islower(option)) { \
2130 flags &= ~PF_##flag; \
2131 flags |= PF_NO##flag; \
2132 } else { \
2133 flags &= ~PF_NO##flag; \
2134 flags |= PF_##flag; \
2135 }
2136static void parse_delimited(array_t *arr, char *arg, const char *delim)
2137{
2138 char *ele = strtok(arg, delim);
2139 if (!ele) /* edge case: -s '' */
2140 xarraypush_str(arr, "");
2141 while (ele) {
2142 xarraypush_str(arr, ele);
2143 ele = strtok(NULL, delim);
2144 }
2145}
1363static void parseargs(int argc, char *argv[]) 2146static int parseargs(int argc, char *argv[])
1364{ 2147{
1365 int i; 2148 int i;
1366 char *from_file = NULL; 2149 const char *from_file = NULL;
2150 int ret = 0;
2151 char load_cache_config = 0;
1367 2152
1368 opterr = 0; 2153 opterr = 0;
1369 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2154 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1370 switch (i) { 2155 switch (i) {
1371 2156
1379 case 'f': 2164 case 'f':
1380 if (from_file) warn("You prob don't want to specify -f twice"); 2165 if (from_file) warn("You prob don't want to specify -f twice");
1381 from_file = optarg; 2166 from_file = optarg;
1382 break; 2167 break;
1383 case 'E': 2168 case 'E':
1384 strncpy(match_etypes, optarg, sizeof(match_etypes)); 2169 /* historically, this was comma delimited */
2170 parse_delimited(match_etypes, optarg, ",");
2171 break;
2172 case 'M':
2173 match_bits = atoi(optarg);
2174 if (match_bits == 0) {
2175 if (strcmp(optarg, "ELFCLASS32") == 0)
2176 match_bits = 32;
2177 if (strcmp(optarg, "ELFCLASS64") == 0)
2178 match_bits = 64;
2179 }
2180 break;
2181 case 'O':
2182 if (sscanf(optarg, "%o", &match_perms) == -1)
2183 match_bits = 0;
1385 break; 2184 break;
1386 case 'o': { 2185 case 'o': {
1387 FILE *fp = NULL;
1388 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2186 if (freopen(optarg, "w", stdout) == NULL)
1389 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2187 errp("Could not freopen(%s)", optarg);
1390 SET_STDOUT(fp);
1391 break; 2188 break;
1392 } 2189 }
1393
1394 case 's': { 2190 case 'k':
1395 if (find_sym) warn("You prob don't want to specify -s twice"); 2191 xarraypush_str(find_section_arr, optarg);
1396 find_sym = optarg;
1397 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1398 sprintf(versioned_symname, "%s@", find_sym);
1399 break; 2192 break;
1400 }
1401 case 'N': { 2193 case 's':
1402 if (find_lib) warn("You prob don't want to specify -N twice"); 2194 /* historically, this was comma delimited */
1403 find_lib = optarg; 2195 parse_delimited(find_sym_arr, optarg, ",");
1404 break; 2196 break;
1405 } 2197 case 'N':
1406 2198 xarraypush_str(find_lib_arr, optarg);
2199 break;
1407 case 'F': { 2200 case 'F': {
1408 if (out_format) warn("You prob don't want to specify -F twice"); 2201 if (out_format) warn("You prob don't want to specify -F twice");
1409 out_format = optarg; 2202 out_format = optarg;
1410 break; 2203 break;
1411 } 2204 }
2205 case 'z': {
2206 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2207 size_t x;
1412 2208
1413 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2209 for (x = 0; x < strlen(optarg); x++) {
2210 switch (optarg[x]) {
2211 case 'p':
2212 case 'P':
2213 do_pax_state(optarg[x], PAGEEXEC);
2214 break;
2215 case 's':
2216 case 'S':
2217 do_pax_state(optarg[x], SEGMEXEC);
2218 break;
2219 case 'm':
2220 case 'M':
2221 do_pax_state(optarg[x], MPROTECT);
2222 break;
2223 case 'e':
2224 case 'E':
2225 do_pax_state(optarg[x], EMUTRAMP);
2226 break;
2227 case 'r':
2228 case 'R':
2229 do_pax_state(optarg[x], RANDMMAP);
2230 break;
2231 case 'x':
2232 case 'X':
2233 do_pax_state(optarg[x], RANDEXEC);
2234 break;
2235 default:
2236 break;
2237 }
2238 }
2239 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2240 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2241 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2242 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2243 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2244 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2245 setpax = flags;
2246 break;
2247 }
2248 case 'Z': show_size = 1; break;
2249 case 'g': ++g_match; break;
1414 case 'L': use_ldcache = 1; break; 2250 case 'L': load_cache_config = use_ldcache = 1; break;
1415 case 'y': scan_symlink = 0; break; 2251 case 'y': scan_symlink = 0; break;
1416 case 'A': scan_archives = 1; break; 2252 case 'A': scan_archives = 1; break;
2253 case 'C': color_init(true); break;
1417 case 'B': show_banner = 0; break; 2254 case 'B': show_banner = 0; break;
1418 case 'l': scan_ldpath = 1; break; 2255 case 'l': load_cache_config = scan_ldpath = 1; break;
1419 case 'p': scan_envpath = 1; break; 2256 case 'p': scan_envpath = 1; break;
1420 case 'R': dir_recurse = 1; break; 2257 case 'R': dir_recurse = 1; break;
1421 case 'm': dir_crossmount = 0; break; 2258 case 'm': dir_crossmount = 0; break;
1422 case 'X': ++fix_elf; break; 2259 case 'X': ++fix_elf; break;
1423 case 'x': show_pax = 1; break; 2260 case 'x': show_pax = 1; break;
1427 case 'n': show_needed = 1; break; 2264 case 'n': show_needed = 1; break;
1428 case 'i': show_interp = 1; break; 2265 case 'i': show_interp = 1; break;
1429 case 'b': show_bind = 1; break; 2266 case 'b': show_bind = 1; break;
1430 case 'S': show_soname = 1; break; 2267 case 'S': show_soname = 1; break;
1431 case 'T': show_textrels = 1; break; 2268 case 'T': show_textrels = 1; break;
1432 case 'q': be_quiet = 1; break; 2269 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1433 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2270 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1434 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2271 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1435 2272 case 'D': show_endian = 1; break;
2273 case 'I': show_osabi = 1; break;
2274 case 'Y': show_eabi = 1; break;
2275 case 128:
2276 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2277 if (root_fd == -1)
2278 err("Could not open root: %s", optarg);
2279 break;
2280 case 129: load_cache_config = use_ldpath = 1; break;
1436 case ':': 2281 case ':':
1437 err("Option '%c' is missing parameter", optopt); 2282 err("Option '%c' is missing parameter", optopt);
1438 case '?': 2283 case '?':
1439 err("Unknown option '%c' or argument missing", optopt); 2284 err("Unknown option '%c' or argument missing", optopt);
1440 default: 2285 default:
1441 err("Unhandled option '%c'; please report this", i); 2286 err("Unhandled option '%c'; please report this", i);
1442 } 2287 }
1443 } 2288 }
2289 if (show_textrels && be_verbose)
2290 objdump = which("objdump", "OBJDUMP");
2291 /* precompile all the regexes */
2292 if (g_match) {
2293 regex_t preg;
2294 const char *this_sym;
2295 size_t n;
2296 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1444 2297
2298 array_for_each(find_sym_arr, n, this_sym) {
2299 /* see scanelf_match_symname for logic info */
2300 switch (this_sym[0]) {
2301 case '%':
2302 while (*(this_sym++))
2303 if (*this_sym == '%') {
2304 ++this_sym;
2305 break;
2306 }
2307 break;
2308 case '+':
2309 case '-':
2310 ++this_sym;
2311 break;
2312 }
2313 if (*this_sym == '*')
2314 ++this_sym;
2315
2316 ret = regcomp(&preg, this_sym, flags);
2317 if (ret) {
2318 char err[256];
2319 regerror(ret, &preg, err, sizeof(err));
2320 err("regcomp of %s failed: %s", this_sym, err);
2321 }
2322 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2323 }
2324 }
2325 /* flatten arrays for display */
2326 find_sym = array_flatten_str(find_sym_arr);
2327 find_lib = array_flatten_str(find_lib_arr);
2328 find_section = array_flatten_str(find_section_arr);
1445 /* let the format option override all other options */ 2329 /* let the format option override all other options */
1446 if (out_format) { 2330 if (out_format) {
1447 show_pax = show_phdr = show_textrel = show_rpath = \ 2331 show_pax = show_phdr = show_textrel = show_rpath = \
1448 show_needed = show_interp = show_bind = show_soname = \ 2332 show_needed = show_interp = show_bind = show_soname = \
1449 show_textrels = 0; 2333 show_textrels = show_perms = show_endian = show_size = \
2334 show_osabi = show_eabi = 0;
1450 for (i = 0; out_format[i]; ++i) { 2335 for (i = 0; out_format[i]; ++i) {
1451 if (!IS_MODIFIER(out_format[i])) continue; 2336 if (!IS_MODIFIER(out_format[i])) continue;
1452 2337
1453 switch (out_format[++i]) { 2338 switch (out_format[++i]) {
2339 case '+': break;
1454 case '%': break; 2340 case '%': break;
1455 case '#': break; 2341 case '#': break;
1456 case 'F': break; 2342 case 'F': break;
1457 case 'p': break; 2343 case 'p': break;
1458 case 'f': break; 2344 case 'f': break;
2345 case 'k': break;
1459 case 's': break; 2346 case 's': break;
1460 case 'N': break; 2347 case 'N': break;
1461 case 'o': break; 2348 case 'o': break;
2349 case 'a': break;
2350 case 'M': break;
2351 case 'Z': show_size = 1; break;
2352 case 'D': show_endian = 1; break;
2353 case 'I': show_osabi = 1; break;
2354 case 'Y': show_eabi = 1; break;
2355 case 'O': show_perms = 1; break;
1462 case 'x': show_pax = 1; break; 2356 case 'x': show_pax = 1; break;
1463 case 'e': show_phdr = 1; break; 2357 case 'e': show_phdr = 1; break;
1464 case 't': show_textrel = 1; break; 2358 case 't': show_textrel = 1; break;
1465 case 'r': show_rpath = 1; break; 2359 case 'r': show_rpath = 1; break;
1466 case 'n': show_needed = 1; break; 2360 case 'n': show_needed = 1; break;
1467 case 'i': show_interp = 1; break; 2361 case 'i': show_interp = 1; break;
1468 case 'b': show_bind = 1; break; 2362 case 'b': show_bind = 1; break;
1469 case 'S': show_soname = 1; break; 2363 case 'S': show_soname = 1; break;
1470 case 'T': show_textrels = 1; break; 2364 case 'T': show_textrels = 1; break;
1471 default: 2365 default:
1472 err("Invalid format specifier '%c' (byte %i)", 2366 err("invalid format specifier '%c' (byte %i)",
1473 out_format[i], i+1); 2367 out_format[i], i+1);
1474 } 2368 }
1475 } 2369 }
1476 2370
1477 /* construct our default format */ 2371 /* construct our default format */
1478 } else { 2372 } else {
1479 size_t fmt_len = 30; 2373 size_t fmt_len = 30;
1480 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2374 out_format = xmalloc(sizeof(char) * fmt_len);
2375 *out_format = '\0';
1481 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2376 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1482 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2377 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2378 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2379 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2380 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2381 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2382 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1483 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2383 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1484 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2384 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1485 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2385 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1486 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2386 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1487 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2387 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1488 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2388 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1489 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2389 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1490 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2390 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1491 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2391 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2392 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1492 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2393 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1493 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2394 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1494 } 2395 }
1495 if (be_verbose > 2) printf("Format: %s\n", out_format); 2396 if (be_verbose > 2) printf("Format: %s\n", out_format);
1496 2397
1497 /* now lets actually do the scanning */ 2398 /* now lets actually do the scanning */
1498 if (scan_ldpath || use_ldcache) 2399 if (load_cache_config)
1499 load_ld_so_conf(); 2400 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1500 if (scan_ldpath) scanelf_ldpath(); 2401 if (scan_ldpath) scanelf_ldpath();
1501 if (scan_envpath) scanelf_envpath(); 2402 if (scan_envpath) scanelf_envpath();
2403 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2404 from_file = "-";
1502 if (from_file) { 2405 if (from_file) {
1503 scanelf_from_file(from_file); 2406 scanelf_from_file(from_file);
1504 from_file = *argv; 2407 from_file = *argv;
1505 } 2408 }
1506 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2409 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1507 err("Nothing to scan !?"); 2410 err("Nothing to scan !?");
1508 while (optind < argc) { 2411 while (optind < argc) {
1509 search_path = argv[optind++]; 2412 search_path = argv[optind++];
1510 scanelf_dir(search_path); 2413 ret = scanelf_dir(search_path);
1511 } 2414 }
1512 2415
2416#ifdef __PAX_UTILS_CLEANUP
1513 /* clean up */ 2417 /* clean up */
1514 if (versioned_symname) free(versioned_symname);
1515 for (i = 0; ldpaths[i]; ++i)
1516 free(ldpaths[i]); 2418 xarrayfree(ldpaths);
2419 xarrayfree(find_sym_arr);
2420 xarrayfree(find_lib_arr);
2421 xarrayfree(find_section_arr);
2422 free(find_sym);
2423 free(find_lib);
2424 free(find_section);
2425 {
2426 size_t n;
2427 regex_t *preg;
2428 array_for_each(find_sym_regex_arr, n, preg)
2429 regfree(preg);
2430 xarrayfree(find_sym_regex_arr);
2431 }
1517 2432
1518 if (ldcache != 0) 2433 if (ldcache != 0)
1519 munmap(ldcache, ldcache_size); 2434 munmap(ldcache, ldcache_size);
1520} 2435#endif
1521 2436
1522
1523
1524/* utility funcs */
1525static char *xstrdup(const char *s)
1526{
1527 char *ret = strdup(s);
1528 if (!ret) err("Could not strdup(): %s", strerror(errno));
1529 return ret; 2437 return ret;
1530} 2438}
1531static void *xmalloc(size_t size)
1532{
1533 void *ret = malloc(size);
1534 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1535 return ret;
1536}
1537static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1538{
1539 size_t new_len;
1540 2439
1541 new_len = strlen(*dst) + strlen(src); 2440static char **get_split_env(const char *envvar)
1542 if (*curr_len <= new_len) {
1543 *curr_len = new_len + (*curr_len / 2);
1544 *dst = realloc(*dst, *curr_len);
1545 if (!*dst)
1546 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1547 }
1548
1549 if (n)
1550 strncat(*dst, src, n);
1551 else
1552 strcat(*dst, src);
1553}
1554static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1555{ 2441{
1556 static char my_app[2]; 2442 const char *delims = " \t\n";
1557 my_app[0] = append; 2443 char **envvals = NULL;
1558 my_app[1] = '\0'; 2444 char *env, *s;
1559 xstrcat(dst, my_app, curr_len); 2445 int nentry;
1560}
1561 2446
2447 if ((env = getenv(envvar)) == NULL)
2448 return NULL;
1562 2449
2450 env = xstrdup(env);
2451 if (env == NULL)
2452 return NULL;
2453
2454 s = strtok(env, delims);
2455 if (s == NULL) {
2456 free(env);
2457 return NULL;
2458 }
2459
2460 nentry = 0;
2461 while (s != NULL) {
2462 ++nentry;
2463 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2464 envvals[nentry-1] = s;
2465 s = strtok(NULL, delims);
2466 }
2467 envvals[nentry] = NULL;
2468
2469 /* don't want to free(env) as it contains the memory that backs
2470 * the envvals array of strings */
2471 return envvals;
2472}
2473
2474static void parseenv(void)
2475{
2476 color_init(false);
2477 qa_textrels = get_split_env("QA_TEXTRELS");
2478 qa_execstack = get_split_env("QA_EXECSTACK");
2479 qa_wx_load = get_split_env("QA_WX_LOAD");
2480}
2481
2482#ifdef __PAX_UTILS_CLEANUP
2483static void cleanup(void)
2484{
2485 free(out_format);
2486 free(qa_textrels);
2487 free(qa_execstack);
2488 free(qa_wx_load);
2489}
2490#endif
1563 2491
1564int main(int argc, char *argv[]) 2492int main(int argc, char *argv[])
1565{ 2493{
2494 int ret;
1566 if (argc < 2) 2495 if (argc < 2)
1567 usage(EXIT_FAILURE); 2496 usage(EXIT_FAILURE);
2497 parseenv();
1568 parseargs(argc, argv); 2498 ret = parseargs(argc, argv);
1569 fclose(stdout); 2499 fclose(stdout);
1570#ifdef __BOUNDS_CHECKING_ON 2500#ifdef __PAX_UTILS_CLEANUP
1571 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2501 cleanup();
2502 warn("The calls to add/delete heap should be off:\n"
2503 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2504 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1572#endif 2505#endif
1573 return EXIT_SUCCESS; 2506 return ret;
1574} 2507}
2508
2509/* Match filename against entries in matchlist, return TRUE
2510 * if the file is listed */
2511static int file_matches_list(const char *filename, char **matchlist)
2512{
2513 char **file;
2514 char *match;
2515 char buf[__PAX_UTILS_PATH_MAX];
2516
2517 if (matchlist == NULL)
2518 return 0;
2519
2520 for (file = matchlist; *file != NULL; file++) {
2521 if (search_path) {
2522 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2523 match = buf;
2524 } else {
2525 match = *file;
2526 }
2527 if (fnmatch(match, filename, 0) == 0)
2528 return 1;
2529 }
2530 return 0;
2531}

Legend:
Removed from v.1.119  
changed lines
  Added in v.1.266

  ViewVC Help
Powered by ViewVC 1.1.20