/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.119 Revision 1.268
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.119 2006/02/05 02:25:58 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.268 2014/11/05 02:02:03 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.268 2014/11/05 02:02:03 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.119 2006/02/05 02:25:58 solar Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static int scanelf_elfobj(elfobj *elf); 18static int file_matches_list(const char *filename, char **matchlist);
21static int scanelf_elf(const char *filename, int fd, size_t len);
22static int scanelf_archive(const char *filename, int fd, size_t len);
23static void scanelf_file(const char *filename);
24static void scanelf_dir(const char *path);
25static void scanelf_ldpath(void);
26static void scanelf_envpath(void);
27static void usage(int status);
28static void parseargs(int argc, char *argv[]);
29static char *xstrdup(const char *s);
30static void *xmalloc(size_t size);
31static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
32#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
33static inline void xchrcat(char **dst, const char append, size_t *curr_len);
34 19
35/* variables to control behavior */ 20/* variables to control behavior */
36static char match_etypes[126] = ""; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
37static char *ldpaths[256]; 22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
38static char scan_ldpath = 0; 23static char scan_ldpath = 0;
39static char scan_envpath = 0; 24static char scan_envpath = 0;
40static char scan_symlink = 1; 25static char scan_symlink = 1;
41static char scan_archives = 0; 26static char scan_archives = 0;
42static char dir_recurse = 0; 27static char dir_recurse = 0;
43static char dir_crossmount = 1; 28static char dir_crossmount = 1;
44static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
45static char show_phdr = 0; 32static char show_phdr = 0;
46static char show_textrel = 0; 33static char show_textrel = 0;
47static char show_rpath = 0; 34static char show_rpath = 0;
48static char show_needed = 0; 35static char show_needed = 0;
49static char show_interp = 0; 36static char show_interp = 0;
50static char show_bind = 0; 37static char show_bind = 0;
51static char show_soname = 0; 38static char show_soname = 0;
52static char show_textrels = 0; 39static char show_textrels = 0;
53static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
54static char be_quiet = 0; 44static char be_quiet = 0;
55static char be_verbose = 0; 45static char be_verbose = 0;
56static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
57static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
58static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
59static char *out_format = NULL; 55static char *out_format = NULL;
60static char *search_path = NULL; 56static char *search_path = NULL;
61static char fix_elf = 0; 57static char fix_elf = 0;
62static char gmatch = 0; 58static char g_match = 0;
63static char use_ldcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
64 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
65 66
66caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
67size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
68 72
73static const char *objdump;
74
75/* Find the path to a file by name. Note: we do not currently handle the
76 * empty path element correctly (should behave by searching $PWD). */
77static const char *which(const char *fname, const char *envvar)
78{
79 size_t path_len, fname_len;
80 const char *env_path;
81 char *path, *p, *ep;
82
83 p = getenv(envvar);
84 if (p)
85 return p;
86
87 env_path = getenv("PATH");
88 if (!env_path)
89 return NULL;
90
91 /* Create a copy of the $PATH that we can safely modify.
92 * Make it a little bigger so we can append "/fname".
93 * We do this twice -- once for a perm copy, and once for
94 * room at the end of the last element. */
95 path_len = strlen(env_path);
96 fname_len = strlen(fname);
97 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
98 memcpy(path, env_path, path_len + 1);
99
100 p = path + path_len + 1 + fname_len + 1;
101 *p = '/';
102 memcpy(p + 1, fname, fname_len + 1);
103
104 /* Repoint fname to the copy in the env string as it has
105 * the leading slash which we can include in a single memcpy.
106 * Increase the fname len to include the '/' and '\0'. */
107 fname = p;
108 fname_len += 2;
109
110 p = path;
111 while (p) {
112 ep = strchr(p, ':');
113 /* Append the /foo path to the current element. */
114 if (ep)
115 memcpy(ep, fname, fname_len);
116 else
117 memcpy(path + path_len, fname, fname_len);
118
119 if (access(p, R_OK) != -1)
120 return p;
121
122 p = ep;
123 if (ep) {
124 /* If not the last element, restore the chunk we clobbered. */
125 size_t offset = ep - path;
126 size_t restore = min(path_len - offset, fname_len);
127 memcpy(ep, env_path + offset, restore);
128 ++p;
129 }
130 }
131
132 free(path);
133 return NULL;
134}
135
136static FILE *fopenat_r(int dir_fd, const char *path)
137{
138 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
139 if (fd == -1)
140 return NULL;
141 return fdopen(fd, "re");
142}
143
144static const char *root_rel_path(const char *path)
145{
146 /*
147 * openat() will ignore the dirfd if path starts with
148 * a /, so consume all of that noise
149 *
150 * XXX: we don't handle relative paths like ../ that
151 * break out of the --root option, but for now, just
152 * don't do that :P.
153 */
154 if (root_fd != AT_FDCWD) {
155 while (*path == '/')
156 ++path;
157 if (*path == '\0')
158 path = ".";
159 }
160
161 return path;
162}
163
69/* sub-funcs for scanelf_file() */ 164/* sub-funcs for scanelf_fileat() */
70static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 165static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
71{ 166{
72 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 167 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
168
169 /* debug sections */
170 void *symtab = elf_findsecbyname(elf, ".symtab");
171 void *strtab = elf_findsecbyname(elf, ".strtab");
172 /* runtime sections */
173 void *dynsym = elf_findsecbyname(elf, ".dynsym");
174 void *dynstr = elf_findsecbyname(elf, ".dynstr");
175
176 /*
177 * If the sections are marked NOBITS, then they don't exist, so we just
178 * skip them. This let's us work sanely with splitdebug ELFs (rather
179 * than spewing a lot of "corrupt ELF" messages later on). In malformed
180 * ELFs, the section might be wrongly set to NOBITS, but screw em.
181 *
182 * We need to make sure the debug/runtime sym/str sets are used together
183 * as they are generated in sync. Trying to mix them won't work.
184 */
73#define GET_SYMTABS(B) \ 185#define GET_SYMTABS(B) \
74 if (elf->elf_class == ELFCLASS ## B) { \ 186 if (elf->elf_class == ELFCLASS ## B) { \
75 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 187 Elf ## B ## _Shdr *esymtab = symtab; \
76 /* debug sections */ \ 188 Elf ## B ## _Shdr *estrtab = strtab; \
77 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 189 Elf ## B ## _Shdr *edynsym = dynsym; \
78 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 190 Elf ## B ## _Shdr *edynstr = dynstr; \
79 /* runtime sections */ \ 191 \
80 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 192 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
81 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 193 symtab = NULL; \
82 if (symtab && dynsym) { \ 194 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
83 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 195 dynsym = NULL; \
196 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
197 strtab = NULL; \
198 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
199 dynstr = NULL; \
200 \
201 /* Use the set with more symbols if both exist. */ \
202 if (symtab && dynsym && strtab && dynstr) { \
203 if (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) \
204 goto debug##B; \
205 else \
206 goto runtime##B; \
207 } else if (symtab && strtab) { \
208 debug##B: \
209 *sym = symtab; \
210 *str = strtab; \
211 return; \
212 } else if (dynsym && dynstr) { \
213 runtime##B: \
214 *sym = dynsym; \
215 *str = dynstr; \
216 return; \
84 } else { \ 217 } else { \
85 *sym = (void*)(symtab ? symtab : dynsym); \ 218 *sym = *str = NULL; \
86 } \ 219 } \
87 if (strtab && dynstr) { \
88 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \
89 } else { \
90 *tab = (void*)(strtab ? strtab : dynstr); \
91 } \
92 } 220 }
93 GET_SYMTABS(32) 221 GET_SYMTABS(32)
94 GET_SYMTABS(64) 222 GET_SYMTABS(64)
223
224 if (*sym && *str)
225 return;
226
227 /*
228 * damn, they're really going to make us work for it huh?
229 * reconstruct the section header info out of the dynamic
230 * tags so we can see what symbols this guy uses at runtime.
231 */
232#define GET_SYMTABS_DT(B) \
233 if (elf->elf_class == ELFCLASS ## B) { \
234 size_t i; \
235 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
236 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
237 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
238 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
239 Elf ## B ## _Dyn *dyn; \
240 Elf ## B ## _Off offset; \
241 \
242 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
243 vsym = vstr = vhash = vgnu_hash = 0; \
244 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
245 memset(&str_shdr, 0, sizeof(str_shdr)); \
246 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
247 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
248 continue; \
249 \
250 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
252 continue; \
253 \
254 dyn = DYN ## B (elf->vdata + offset); \
255 while (EGET(dyn->d_tag) != DT_NULL) { \
256 switch (EGET(dyn->d_tag)) { \
257 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
258 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
259 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
260 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
261 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
262 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
263 } \
264 ++dyn; \
265 } \
266 if (vsym && vstr) \
267 break; \
268 } \
269 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
270 return; \
271 \
272 /* calc offset into the ELF by finding the load addr of the syms */ \
273 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
274 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
275 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
276 offset = EGET(phdr[i].p_offset); \
277 \
278 if (EGET(phdr[i].p_type) != PT_LOAD) \
279 continue; \
280 \
281 if (vhash >= vaddr && vhash < vaddr + filesz) { \
282 /* Scan the hash table to see how many entries we have */ \
283 Elf32_Word max_sym_idx = 0; \
284 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
285 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
286 Elf32_Word nchains = EGET(hashtbl[1]); \
287 Elf32_Word *buckets = &hashtbl[2]; \
288 Elf32_Word *chains = &buckets[nbuckets]; \
289 Elf32_Word sym_idx; \
290 \
291 for (b = 0; b < nbuckets; ++b) { \
292 if (!buckets[b]) \
293 continue; \
294 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
295 if (max_sym_idx < sym_idx) \
296 max_sym_idx = sym_idx; \
297 } \
298 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
299 } \
300 \
301 if (vsym >= vaddr && vsym < vaddr + filesz) { \
302 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
303 *sym = &sym_shdr; \
304 } \
305 \
306 if (vstr >= vaddr && vstr < vaddr + filesz) { \
307 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
308 *str = &str_shdr; \
309 } \
310 } \
311 }
312 GET_SYMTABS_DT(32)
313 GET_SYMTABS_DT(64)
95} 314}
315
96static char *scanelf_file_pax(elfobj *elf, char *found_pax) 316static char *scanelf_file_pax(elfobj *elf, char *found_pax)
97{ 317{
98 static char ret[7]; 318 static char ret[7];
99 unsigned long i, shown; 319 unsigned long i, shown;
100 320
109 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 329 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
110 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 330 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
111 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 331 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
112 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 332 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
113 continue; \ 333 continue; \
114 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 334 if (fix_elf && setpax) { \
335 /* set the paxctl flags */ \
336 ESET(phdr[i].p_flags, setpax); \
337 } \
338 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
115 continue; \ 339 continue; \
116 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 340 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
117 *found_pax = 1; \ 341 *found_pax = 1; \
118 ++shown; \ 342 ++shown; \
119 break; \ 343 break; \
120 } \ 344 } \
121 } 345 }
122 SHOW_PAX(32) 346 SHOW_PAX(32)
123 SHOW_PAX(64) 347 SHOW_PAX(64)
124 } 348 }
349
350 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
351 * was found. This is known to break ELFs on glibc systems,
352 * and mainline PaX has deprecated use of this for a long time.
353 * We could support changing PT_GNU_STACK, but that doesn't
354 * seem like it's worth the effort. #411919
355 */
125 356
126 /* fall back to EI_PAX if no PT_PAX was found */ 357 /* fall back to EI_PAX if no PT_PAX was found */
127 if (!*ret) { 358 if (!*ret) {
128 static char *paxflags; 359 static char *paxflags;
129 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 360 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
143static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 374static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
144{ 375{
145 static char ret[12]; 376 static char ret[12];
146 char *found; 377 char *found;
147 unsigned long i, shown, multi_stack, multi_relro, multi_load; 378 unsigned long i, shown, multi_stack, multi_relro, multi_load;
148 int max_pt_load;
149 379
150 if (!show_phdr) return NULL; 380 if (!show_phdr) return NULL;
151 381
152 memcpy(ret, "--- --- ---\0", 12); 382 memcpy(ret, "--- --- ---\0", 12);
153 383
154 shown = 0; 384 shown = 0;
155 multi_stack = multi_relro = multi_load = 0; 385 multi_stack = multi_relro = multi_load = 0;
156 max_pt_load = elf_max_pt_load(elf);
157 386
158#define NOTE_GNU_STACK ".note.GNU-stack" 387#define NOTE_GNU_STACK ".note.GNU-stack"
159#define SHOW_PHDR(B) \ 388#define SHOW_PHDR(B) \
160 if (elf->elf_class == ELFCLASS ## B) { \ 389 if (elf->elf_class == ELFCLASS ## B) { \
161 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 390 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
163 uint32_t flags, check_flags; \ 392 uint32_t flags, check_flags; \
164 if (elf->phdr != NULL) { \ 393 if (elf->phdr != NULL) { \
165 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 394 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
166 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 395 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
167 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 396 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
397 if (multi_stack++) \
168 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 398 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
399 if (file_matches_list(elf->filename, qa_execstack)) \
400 continue; \
169 found = found_phdr; \ 401 found = found_phdr; \
170 offset = 0; \ 402 offset = 0; \
171 check_flags = PF_X; \ 403 check_flags = PF_X; \
172 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 404 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
405 if (multi_relro++) \
173 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 406 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
174 found = found_relro; \ 407 found = found_relro; \
175 offset = 4; \ 408 offset = 4; \
176 check_flags = PF_X; \ 409 check_flags = PF_X; \
177 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 410 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
178 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \ 411 if (file_matches_list(elf->filename, qa_wx_load)) \
179 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \ 412 continue; \
180 found = found_load; \ 413 found = found_load; \
181 offset = 8; \ 414 offset = 8; \
182 check_flags = PF_W|PF_X; \ 415 check_flags = PF_W|PF_X; \
183 } else \ 416 } else \
184 continue; \ 417 continue; \
185 flags = EGET(phdr[i].p_flags); \ 418 flags = EGET(phdr[i].p_flags); \
186 if (be_quiet && ((flags & check_flags) != check_flags)) \ 419 if (be_quiet && ((flags & check_flags) != check_flags)) \
187 continue; \ 420 continue; \
188 if (fix_elf && ((flags & PF_X) != flags)) { \ 421 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
189 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \ 422 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
190 ret[3] = ret[7] = '!'; \ 423 ret[3] = ret[7] = '!'; \
191 flags = EGET(phdr[i].p_flags); \ 424 flags = EGET(phdr[i].p_flags); \
192 } \ 425 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 426 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
197 } else if (elf->shdr != NULL) { \ 430 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 431 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 432 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 433 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
201 char *str; \ 434 char *str; \
202 if ((void*)strtbl > (void*)elf->data_end) \ 435 if ((void*)strtbl > elf->data_end) \
203 goto skip_this_shdr##B; \ 436 goto skip_this_shdr##B; \
437 /* let's flag -w/+x object files since the final ELF will most likely \
438 * need write access to the stack (who doesn't !?). so the combined \
439 * output will bring in +w automatically and that's bad. \
440 */ \
204 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 441 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
205 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 442 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
206 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 443 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
207 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 444 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
208 str = elf->data + offset; \ 445 str = elf->data + offset; \
209 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \ 446 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
221 break; \ 458 break; \
222 } \ 459 } \
223 } \ 460 } \
224 skip_this_shdr##B: \ 461 skip_this_shdr##B: \
225 if (!multi_stack) { \ 462 if (!multi_stack) { \
463 if (file_matches_list(elf->filename, qa_execstack)) \
464 return NULL; \
226 *found_phdr = 1; \ 465 *found_phdr = 1; \
227 shown = 1; \ 466 shown = 1; \
228 memcpy(ret, "!WX", 3); \ 467 memcpy(ret, "!WX", 3); \
229 } \ 468 } \
230 } \ 469 } \
235 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 474 if (be_wewy_wewy_quiet || (be_quiet && !shown))
236 return NULL; 475 return NULL;
237 else 476 else
238 return ret; 477 return ret;
239} 478}
479
480/*
481 * See if this ELF contains a DT_TEXTREL tag in any of its
482 * PT_DYNAMIC sections.
483 */
240static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 484static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
241{ 485{
242 static const char *ret = "TEXTREL"; 486 static const char *ret = "TEXTREL";
243 unsigned long i; 487 unsigned long i;
244 488
245 if (!show_textrel && !show_textrels) return NULL; 489 if (!show_textrel && !show_textrels) return NULL;
490
491 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
246 492
247 if (elf->phdr) { 493 if (elf->phdr) {
248#define SHOW_TEXTREL(B) \ 494#define SHOW_TEXTREL(B) \
249 if (elf->elf_class == ELFCLASS ## B) { \ 495 if (elf->elf_class == ELFCLASS ## B) { \
250 Elf ## B ## _Dyn *dyn; \ 496 Elf ## B ## _Dyn *dyn; \
251 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 497 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
252 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 498 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
253 Elf ## B ## _Off offset; \ 499 Elf ## B ## _Off offset; \
254 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 500 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
255 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 501 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
256 offset = EGET(phdr[i].p_offset); \ 502 offset = EGET(phdr[i].p_offset); \
257 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 503 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
258 dyn = DYN ## B (elf->data + offset); \ 504 dyn = DYN ## B (elf->vdata + offset); \
259 while (EGET(dyn->d_tag) != DT_NULL) { \ 505 while (EGET(dyn->d_tag) != DT_NULL) { \
260 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 506 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
261 *found_textrel = 1; \ 507 *found_textrel = 1; \
262 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 508 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
263 return (be_wewy_wewy_quiet ? NULL : ret); \ 509 return (be_wewy_wewy_quiet ? NULL : ret); \
272 if (be_quiet || be_wewy_wewy_quiet) 518 if (be_quiet || be_wewy_wewy_quiet)
273 return NULL; 519 return NULL;
274 else 520 else
275 return " - "; 521 return " - ";
276} 522}
523
524/*
525 * Scan the .text section to see if there are any relocations in it.
526 * Should rewrite this to check PT_LOAD sections that are marked
527 * Executable rather than the section named '.text'.
528 */
277static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 529static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
278{ 530{
279 unsigned long s, r, rmax; 531 unsigned long s, r, rmax;
280 void *symtab_void, *strtab_void, *text_void; 532 void *symtab_void, *strtab_void, *text_void;
281 533
302 Elf ## B ## _Rela *rela; \ 554 Elf ## B ## _Rela *rela; \
303 /* search the section headers for relocations */ \ 555 /* search the section headers for relocations */ \
304 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 556 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
305 uint32_t sh_type = EGET(shdr[s].sh_type); \ 557 uint32_t sh_type = EGET(shdr[s].sh_type); \
306 if (sh_type == SHT_REL) { \ 558 if (sh_type == SHT_REL) { \
307 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 559 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
308 rela = NULL; \ 560 rela = NULL; \
309 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 561 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
310 } else if (sh_type == SHT_RELA) { \ 562 } else if (sh_type == SHT_RELA) { \
311 rel = NULL; \ 563 rel = NULL; \
312 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 564 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
313 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 565 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
314 } else \ 566 } else \
315 continue; \ 567 continue; \
316 /* now see if any of the relocs are in the .text */ \ 568 /* now see if any of the relocs are in the .text */ \
317 for (r = 0; r < rmax; ++r) { \ 569 for (r = 0; r < rmax; ++r) { \
332 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 584 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
333 if (be_verbose <= 2) continue; \ 585 if (be_verbose <= 2) continue; \
334 } else \ 586 } else \
335 *found_textrels = 1; \ 587 *found_textrels = 1; \
336 /* locate this relocation symbol name */ \ 588 /* locate this relocation symbol name */ \
337 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 589 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
338 if ((void*)sym > (void*)elf->data_end) { \ 590 if ((void*)sym > elf->data_end) { \
339 warn("%s: corrupt ELF symbol", elf->filename); \ 591 warn("%s: corrupt ELF symbol", elf->filename); \
340 continue; \ 592 continue; \
341 } \ 593 } \
342 sym_max = ELF ## B ## _R_SYM(r_info); \ 594 sym_max = ELF ## B ## _R_SYM(r_info); \
343 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 595 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
346 sym = NULL; \ 598 sym = NULL; \
347 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 599 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
348 /* show the raw details about this reloc */ \ 600 /* show the raw details about this reloc */ \
349 printf(" %s: ", elf->base_filename); \ 601 printf(" %s: ", elf->base_filename); \
350 if (sym && sym->st_name) \ 602 if (sym && sym->st_name) \
351 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 603 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
352 else \ 604 else \
353 printf("(memory/fake?)"); \ 605 printf("(memory/data?)"); \
354 printf(" [0x%lX]", (unsigned long)r_offset); \ 606 printf(" [0x%lX]", (unsigned long)r_offset); \
355 /* now try to find the closest symbol that this rel is probably in */ \ 607 /* now try to find the closest symbol that this rel is probably in */ \
356 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 608 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
357 func = NULL; \ 609 func = NULL; \
358 offset_tmp = 0; \ 610 offset_tmp = 0; \
359 while (sym_max--) { \ 611 while (sym_max--) { \
360 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 612 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
361 func = sym; \ 613 func = sym; \
362 offset_tmp = EGET(sym->st_value); \ 614 offset_tmp = EGET(sym->st_value); \
363 } \ 615 } \
364 ++sym; \ 616 ++sym; \
365 } \ 617 } \
366 printf(" in "); \ 618 printf(" in "); \
367 if (func && func->st_name) \ 619 if (func && func->st_name) { \
368 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 620 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
621 if (r_offset > EGET(func->st_size)) \
622 printf("(optimized out: previous %s)", func_name); \
369 else \ 623 else \
370 printf("(NULL: fake?)"); \ 624 printf("%s", func_name); \
625 } else \
626 printf("(optimized out)"); \
371 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 627 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
628 if (be_verbose && objdump) { \
629 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
630 char *sysbuf; \
631 size_t syslen; \
632 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
633 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
634 sysbuf = xmalloc(syslen); \
635 if (end_addr < r_offset) \
636 /* not uncommon when things are optimized out */ \
637 end_addr = r_offset + 0x100; \
638 snprintf(sysbuf, syslen, sysfmt, \
639 objdump, \
640 (unsigned long)offset_tmp, \
641 (unsigned long)end_addr, \
642 elf->filename, \
643 (unsigned long)r_offset); \
644 fflush(stdout); \
645 if (system(sysbuf)) {/* don't care */} \
646 fflush(stdout); \
647 free(sysbuf); \
648 } \
372 } \ 649 } \
373 } } 650 } }
374 SHOW_TEXTRELS(32) 651 SHOW_TEXTRELS(32)
375 SHOW_TEXTRELS(64) 652 SHOW_TEXTRELS(64)
376 } 653 }
378 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 655 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
379 656
380 return NULL; 657 return NULL;
381} 658}
382 659
383static void rpath_security_checks(elfobj *, char *, const char *);
384static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type) 660static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
385{ 661{
386 struct stat st; 662 struct stat st;
387 switch (*item) { 663 switch (*item) {
388 case '/': break; 664 case '/': break;
394 warnf("Security problem NULL %s in %s", dt_type, elf->filename); 670 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
395 break; 671 break;
396 case '$': 672 case '$':
397 if (fstat(elf->fd, &st) != -1) 673 if (fstat(elf->fd, &st) != -1)
398 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 674 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
399 warnf("Security problem with %s='%s' in %s with mode set of %o", 675 warnf("Security problem with %s='%s' in %s with mode set of %o",
400 dt_type, item, elf->filename, st.st_mode & 07777); 676 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
401 break; 677 break;
402 default: 678 default:
403 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename); 679 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
404 break; 680 break;
405 } 681 }
406} 682}
407static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 683static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
408{ 684{
409 unsigned long i, s; 685 unsigned long i;
410 char *rpath, *runpath, **r; 686 char *rpath, *runpath, **r;
411 void *strtbl_void; 687 void *strtbl_void;
412 688
413 if (!show_rpath) return; 689 if (!show_rpath) return;
414 690
425 Elf ## B ## _Off offset; \ 701 Elf ## B ## _Off offset; \
426 Elf ## B ## _Xword word; \ 702 Elf ## B ## _Xword word; \
427 /* Scan all the program headers */ \ 703 /* Scan all the program headers */ \
428 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 704 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
429 /* Just scan dynamic headers */ \ 705 /* Just scan dynamic headers */ \
430 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 706 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
431 offset = EGET(phdr[i].p_offset); \ 707 offset = EGET(phdr[i].p_offset); \
432 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 708 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
433 /* Just scan dynamic RPATH/RUNPATH headers */ \ 709 /* Just scan dynamic RPATH/RUNPATH headers */ \
434 dyn = DYN ## B (elf->data + offset); \ 710 dyn = DYN ## B (elf->vdata + offset); \
435 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 711 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
436 if (word == DT_RPATH) { \ 712 if (word == DT_RPATH) { \
437 r = &rpath; \ 713 r = &rpath; \
438 } else if (word == DT_RUNPATH) { \ 714 } else if (word == DT_RUNPATH) { \
439 r = &runpath; \ 715 r = &runpath; \
443 } \ 719 } \
444 /* Verify the memory is somewhat sane */ \ 720 /* Verify the memory is somewhat sane */ \
445 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 721 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
446 if (offset < (Elf ## B ## _Off)elf->len) { \ 722 if (offset < (Elf ## B ## _Off)elf->len) { \
447 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 723 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
448 *r = (char*)(elf->data + offset); \ 724 *r = elf->data + offset; \
449 /* cache the length in case we need to nuke this section later on */ \ 725 /* cache the length in case we need to nuke this section later on */ \
450 if (fix_elf) \ 726 if (fix_elf) \
451 offset = strlen(*r); \ 727 offset = strlen(*r); \
452 /* If quiet, don't output paths in ld.so.conf */ \ 728 /* If quiet, don't output paths in ld.so.conf */ \
453 if (be_quiet) { \ 729 if (be_quiet) { \
459 /* scan each path in : delimited list */ \ 735 /* scan each path in : delimited list */ \
460 while (start) { \ 736 while (start) { \
461 rpath_security_checks(elf, start, get_elfdtype(word)); \ 737 rpath_security_checks(elf, start, get_elfdtype(word)); \
462 end = strchr(start, ':'); \ 738 end = strchr(start, ':'); \
463 len = (end ? abs(end - start) : strlen(start)); \ 739 len = (end ? abs(end - start) : strlen(start)); \
464 if (use_ldcache) \ 740 if (use_ldcache) { \
465 for (s = 0; ldpaths[s]; ++s) \ 741 size_t n; \
742 const char *ldpath; \
743 array_for_each(ldpaths, n, ldpath) \
466 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 744 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
467 *r = end; \ 745 *r = end; \
468 /* corner case ... if RPATH reads "/usr/lib:", we want \ 746 /* corner case ... if RPATH reads "/usr/lib:", we want \
469 * to show ':' rather than '' */ \ 747 * to show ':' rather than '' */ \
470 if (end && end[1] != '\0') \ 748 if (end && end[1] != '\0') \
471 (*r)++; \ 749 (*r)++; \
472 break; \ 750 break; \
473 } \ 751 } \
752 } \
474 if (!*r || !end) \ 753 if (!*r || !end) \
475 break; \ 754 break; \
476 else \ 755 else \
477 start = start + len + 1; \ 756 start = start + len + 1; \
478 } \ 757 } \
544 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 823 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
545 else if (!be_quiet) 824 else if (!be_quiet)
546 xstrcat(ret, " - ", ret_len); 825 xstrcat(ret, " - ", ret_len);
547} 826}
548 827
828/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
549#define LDSO_CACHE_MAGIC "ld.so-" 829#define LDSO_CACHE_MAGIC "ld.so-"
550#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 830#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
551#define LDSO_CACHE_VER "1.7.0" 831#define LDSO_CACHE_VER "1.7.0"
552#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 832#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
553#define FLAG_ANY -1 833#define FLAG_ANY -1
562#define FLAG_X8664_LIB64 0x0300 842#define FLAG_X8664_LIB64 0x0300
563#define FLAG_S390_LIB64 0x0400 843#define FLAG_S390_LIB64 0x0400
564#define FLAG_POWERPC_LIB64 0x0500 844#define FLAG_POWERPC_LIB64 0x0500
565#define FLAG_MIPS64_LIBN32 0x0600 845#define FLAG_MIPS64_LIBN32 0x0600
566#define FLAG_MIPS64_LIBN64 0x0700 846#define FLAG_MIPS64_LIBN64 0x0700
847#define FLAG_X8664_LIBX32 0x0800
848#define FLAG_ARM_LIBHF 0x0900
849#define FLAG_AARCH64_LIB64 0x0a00
567 850
568static char *lookup_cache_lib(elfobj *, char *); 851#if defined(__GLIBC__) || defined(__UCLIBC__)
852
569static char *lookup_cache_lib(elfobj *elf, char *fname) 853static char *lookup_cache_lib(elfobj *elf, const char *fname)
570{ 854{
571 int fd = 0; 855 int fd;
572 char *strs; 856 char *strs;
573 static char buf[__PAX_UTILS_PATH_MAX] = ""; 857 static char buf[__PAX_UTILS_PATH_MAX] = "";
574 const char *cachefile = "/etc/ld.so.cache"; 858 const char *cachefile = root_rel_path("/etc/ld.so.cache");
575 struct stat st; 859 struct stat st;
576 860
577 typedef struct { 861 typedef struct {
578 char magic[LDSO_CACHE_MAGIC_LEN]; 862 char magic[LDSO_CACHE_MAGIC_LEN];
579 char version[LDSO_CACHE_VER_LEN]; 863 char version[LDSO_CACHE_VER_LEN];
589 libentry_t *libent; 873 libentry_t *libent;
590 874
591 if (fname == NULL) 875 if (fname == NULL)
592 return NULL; 876 return NULL;
593 877
594 if (ldcache == 0) { 878 if (ldcache == NULL) {
595 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 879 if (fstatat(root_fd, cachefile, &st, 0))
880 return NULL;
881
882 fd = openat(root_fd, cachefile, O_RDONLY);
883 if (fd == -1)
596 return NULL; 884 return NULL;
597 885
598 /* cache these values so we only map/unmap the cache file once */ 886 /* cache these values so we only map/unmap the cache file once */
599 ldcache_size = st.st_size; 887 ldcache_size = st.st_size;
600 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 888 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
601
602 close(fd); 889 close(fd);
603 890
604 if (ldcache == (caddr_t)-1) { 891 if (ldcache == MAP_FAILED) {
605 ldcache = 0; 892 ldcache = NULL;
606 return NULL; 893 return NULL;
607 } 894 }
608 895
609 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 896 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
897 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
898 {
899 munmap(ldcache, ldcache_size);
900 ldcache = NULL;
610 return NULL; 901 return NULL;
611 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
612 return NULL;
613 } 902 }
903 } else
904 header = ldcache;
614 905
615 header = (header_t *) ldcache;
616 libent = (libentry_t *) (ldcache + sizeof(header_t)); 906 libent = ldcache + sizeof(header_t);
617 strs = (char *) &libent[header->nlibs]; 907 strs = (char *) &libent[header->nlibs];
618 908
619 for (fd = 0; fd < header->nlibs; fd++) { 909 for (fd = 0; fd < header->nlibs; ++fd) {
620 /* this should be more fine grained, but for now we assume that 910 /* This should be more fine grained, but for now we assume that
621 * diff arches will not be cached together. and we ignore the 911 * diff arches will not be cached together, and we ignore the
622 * the different multilib mips cases. */ 912 * the different multilib mips cases.
913 */
623 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 914 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
624 continue; 915 continue;
625 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 916 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
626 continue; 917 continue;
627 918
628 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 919 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
629 continue; 920 continue;
921
922 /* Return first hit because that is how the ldso rolls */
630 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 923 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
924 break;
631 } 925 }
926
632 return buf; 927 return buf;
633} 928}
634 929
930#elif defined(__NetBSD__)
931static char *lookup_cache_lib(elfobj *elf, const char *fname)
932{
933 static char buf[__PAX_UTILS_PATH_MAX] = "";
934 static struct stat st;
935 size_t n;
936 char *ldpath;
937
938 array_for_each(ldpath, n, ldpath) {
939 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
940 continue; /* if the pathname is too long, or something went wrong, ignore */
941
942 if (stat(buf, &st) != 0)
943 continue; /* if the lib doesn't exist in *ldpath, look further */
944
945 /* NetBSD doesn't actually do sanity checks, it just loads the file
946 * and if that doesn't work, continues looking in other directories.
947 * This cannot easily be safely emulated, unfortunately. For now,
948 * just assume that if it exists, it's a valid library. */
949
950 return buf;
951 }
952
953 /* not found in any path */
954 return NULL;
955}
956#else
957#ifdef __ELF__
958#warning Cache support not implemented for your target
959#endif
960static char *lookup_cache_lib(elfobj *elf, const char *fname)
961{
962 return NULL;
963}
964#endif
965
966static char *lookup_config_lib(const char *fname)
967{
968 static char buf[__PAX_UTILS_PATH_MAX] = "";
969 const char *ldpath;
970 size_t n;
971
972 array_for_each(ldpaths, n, ldpath) {
973 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
974 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
975 return buf;
976 }
977
978 return NULL;
979}
635 980
636static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 981static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
637{ 982{
638 unsigned long i; 983 unsigned long i;
639 char *needed; 984 char *needed;
640 void *strtbl_void; 985 void *strtbl_void;
641 char *p; 986 char *p;
642 987
988 /*
989 * -n -> op==0 -> print all
990 * -N -> op==1 -> print requested
991 */
643 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 992 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
993 return NULL;
644 994
645 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 995 strtbl_void = elf_findsecbyname(elf, ".dynstr");
646 996
647 if (elf->phdr && strtbl_void) { 997 if (elf->phdr && strtbl_void) {
648#define SHOW_NEEDED(B) \ 998#define SHOW_NEEDED(B) \
650 Elf ## B ## _Dyn *dyn; \ 1000 Elf ## B ## _Dyn *dyn; \
651 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1001 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
652 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1002 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
653 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1003 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
654 Elf ## B ## _Off offset; \ 1004 Elf ## B ## _Off offset; \
1005 size_t matched = 0; \
1006 /* Walk all the program headers to find the PT_DYNAMIC */ \
655 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1007 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
656 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1008 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
1009 continue; \
657 offset = EGET(phdr[i].p_offset); \ 1010 offset = EGET(phdr[i].p_offset); \
658 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1011 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
1012 continue; \
1013 /* Walk all the dynamic tags to find NEEDED entries */ \
659 dyn = DYN ## B (elf->data + offset); \ 1014 dyn = DYN ## B (elf->vdata + offset); \
660 while (EGET(dyn->d_tag) != DT_NULL) { \ 1015 while (EGET(dyn->d_tag) != DT_NULL) { \
661 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 1016 if (EGET(dyn->d_tag) == DT_NEEDED) { \
662 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1017 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
663 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1018 if (offset >= (Elf ## B ## _Off)elf->len) { \
664 ++dyn; \ 1019 ++dyn; \
665 continue; \ 1020 continue; \
666 } \ 1021 } \
667 needed = (char*)(elf->data + offset); \ 1022 needed = elf->data + offset; \
668 if (op == 0) { \ 1023 if (op == 0) { \
1024 /* -n -> print all entries */ \
669 if (!be_wewy_wewy_quiet) { \ 1025 if (!be_wewy_wewy_quiet) { \
670 if (*found_needed) xchrcat(ret, ',', ret_len); \ 1026 if (*found_needed) xchrcat(ret, ',', ret_len); \
671 if (use_ldcache) \ 1027 if (use_ldpath) { \
1028 if ((p = lookup_config_lib(needed)) != NULL) \
1029 needed = p; \
1030 } else if (use_ldcache) { \
672 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 1031 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
673 needed = p; \ 1032 needed = p; \
1033 } \
674 xstrcat(ret, needed, ret_len); \ 1034 xstrcat(ret, needed, ret_len); \
675 } \ 1035 } \
676 *found_needed = 1; \ 1036 *found_needed = 1; \
677 } else { \ 1037 } else { \
678 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1038 /* -N -> print matching entries */ \
1039 size_t n; \
1040 const char *find_lib_name; \
1041 \
1042 array_for_each(find_lib_arr, n, find_lib_name) { \
1043 int invert = 1; \
1044 if (find_lib_name[0] == '!') \
1045 invert = 0, ++find_lib_name; \
1046 if (!strcmp(find_lib_name, needed) == invert) \
1047 ++matched; \
1048 } \
1049 \
1050 if (matched == array_cnt(find_lib_arr)) { \
679 *found_lib = 1; \ 1051 *found_lib = 1; \
680 return (be_wewy_wewy_quiet ? NULL : needed); \ 1052 return (be_wewy_wewy_quiet ? NULL : find_lib); \
681 } \ 1053 } \
682 } \ 1054 } \
683 } \ 1055 } \
684 ++dyn; \ 1056 ++dyn; \
685 } \ 1057 } \
707 *found_interp = 1; \ 1079 *found_interp = 1; \
708 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1080 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
709 } 1081 }
710 SHOW_INTERP(32) 1082 SHOW_INTERP(32)
711 SHOW_INTERP(64) 1083 SHOW_INTERP(64)
1084 } else {
1085 /* Walk all the program headers to find the PT_INTERP */
1086#define SHOW_PT_INTERP(B) \
1087 if (elf->elf_class == ELFCLASS ## B) { \
1088 unsigned long i; \
1089 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1090 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1091 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1092 if (EGET(phdr[i].p_type) != PT_INTERP) \
1093 continue; \
1094 *found_interp = 1; \
1095 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1096 } \
712 } 1097 }
1098 SHOW_PT_INTERP(32)
1099 SHOW_PT_INTERP(64)
1100 }
1101
713 return NULL; 1102 return NULL;
714} 1103}
715static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1104static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
716{ 1105{
717 unsigned long i; 1106 unsigned long i;
718 struct stat s; 1107 struct stat s;
1108 bool dynamic = false;
719 1109
720 if (!show_bind) return NULL; 1110 if (!show_bind) return NULL;
721 if (!elf->phdr) return NULL; 1111 if (!elf->phdr) return NULL;
722 1112
723#define SHOW_BIND(B) \ 1113#define SHOW_BIND(B) \
725 Elf ## B ## _Dyn *dyn; \ 1115 Elf ## B ## _Dyn *dyn; \
726 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1116 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
727 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1117 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
728 Elf ## B ## _Off offset; \ 1118 Elf ## B ## _Off offset; \
729 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
730 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1120 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1121 dynamic = true; \
731 offset = EGET(phdr[i].p_offset); \ 1122 offset = EGET(phdr[i].p_offset); \
732 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1123 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
733 dyn = DYN ## B (elf->data + offset); \ 1124 dyn = DYN ## B (elf->vdata + offset); \
734 while (EGET(dyn->d_tag) != DT_NULL) { \ 1125 while (EGET(dyn->d_tag) != DT_NULL) { \
735 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1126 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
736 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1127 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
737 { \ 1128 { \
738 if (be_quiet) return NULL; \ 1129 if (be_quiet) return NULL; \
746 SHOW_BIND(32) 1137 SHOW_BIND(32)
747 SHOW_BIND(64) 1138 SHOW_BIND(64)
748 1139
749 if (be_wewy_wewy_quiet) return NULL; 1140 if (be_wewy_wewy_quiet) return NULL;
750 1141
1142 /* don't output anything if quiet mode and the ELF is static or not setuid */
751 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1143 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
752 return NULL; 1144 return NULL;
753 } else { 1145 } else {
754 *found_bind = 1; 1146 *found_bind = 1;
755 return (char *) "LAZY"; 1147 return dynamic ? "LAZY" : "STATIC";
756 } 1148 }
757} 1149}
758static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1150static char *scanelf_file_soname(elfobj *elf, char *found_soname)
759{ 1151{
760 unsigned long i; 1152 unsigned long i;
772 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1164 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
773 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1165 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
774 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1166 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
775 Elf ## B ## _Off offset; \ 1167 Elf ## B ## _Off offset; \
776 /* only look for soname in shared objects */ \ 1168 /* only look for soname in shared objects */ \
777 if (ehdr->e_type != ET_DYN) \ 1169 if (EGET(ehdr->e_type) != ET_DYN) \
778 return NULL; \ 1170 return NULL; \
779 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1171 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
780 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1172 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
781 offset = EGET(phdr[i].p_offset); \ 1173 offset = EGET(phdr[i].p_offset); \
782 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1174 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
783 dyn = DYN ## B (elf->data + offset); \ 1175 dyn = DYN ## B (elf->vdata + offset); \
784 while (EGET(dyn->d_tag) != DT_NULL) { \ 1176 while (EGET(dyn->d_tag) != DT_NULL) { \
785 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1177 if (EGET(dyn->d_tag) == DT_SONAME) { \
786 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1178 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
787 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1179 if (offset >= (Elf ## B ## _Off)elf->len) { \
788 ++dyn; \ 1180 ++dyn; \
789 continue; \ 1181 continue; \
790 } \ 1182 } \
791 soname = (char*)(elf->data + offset); \ 1183 soname = elf->data + offset; \
792 *found_soname = 1; \ 1184 *found_soname = 1; \
793 return (be_wewy_wewy_quiet ? NULL : soname); \ 1185 return (be_wewy_wewy_quiet ? NULL : soname); \
794 } \ 1186 } \
795 ++dyn; \ 1187 ++dyn; \
796 } \ 1188 } \
799 SHOW_SONAME(64) 1191 SHOW_SONAME(64)
800 } 1192 }
801 1193
802 return NULL; 1194 return NULL;
803} 1195}
1196
1197/*
1198 * We support the symbol form:
1199 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1200 * If the symbol name is empty, then all symbols are matched.
1201 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1202 * Do not rely on this output format at all.
1203 * Otherwise the symbol name is used to search (either regex or string compare).
1204 * If the first char of the symbol name is a plus ("+"), then only match
1205 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1206 * Putting modifiers in between the percent signs allows for more in depth
1207 * filters. There are groups of modifiers. If you don't specify a member
1208 * of a group, then all types in that group are matched. The current
1209 * groups and their types are:
1210 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1211 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1212 * STV group: STV_DEFAULT:p STV_INTERNAL:i STV_HIDDEN:h STV_PROTECTED:P
1213 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1214 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1215 * You can search for multiple symbols at once by seperating with a comma (",").
1216 *
1217 * Some examples:
1218 * ELFs with a weak function "foo":
1219 * scanelf -s %wf%foo <ELFs>
1220 * ELFs that define the symbol "main":
1221 * scanelf -s +main <ELFs>
1222 * scanelf -s %d%main <ELFs>
1223 * ELFs that refer to the undefined symbol "brk":
1224 * scanelf -s -brk <ELFs>
1225 * scanelf -s %u%brk <ELFs>
1226 * All global defined objects in an ELF:
1227 * scanelf -s %ogd% <ELF>
1228 */
1229static void
1230scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1231 unsigned int stt, unsigned int stb, unsigned int stv, unsigned int shn, unsigned long size)
1232{
1233 const char *this_sym;
1234 size_t n;
1235
1236 array_for_each(find_sym_arr, n, this_sym) {
1237 bool inc_notype, inc_object, inc_func, inc_file,
1238 inc_local, inc_global, inc_weak,
1239 inc_visdef, inc_intern, inc_hidden, inc_prot,
1240 inc_def, inc_undef, inc_abs, inc_common;
1241
1242 /* symbol selection! */
1243 inc_notype = inc_object = inc_func = inc_file =
1244 inc_local = inc_global = inc_weak =
1245 inc_visdef = inc_intern = inc_hidden = inc_prot =
1246 inc_def = inc_undef = inc_abs = inc_common =
1247 (*this_sym != '%');
1248
1249 /* parse the contents of %...% */
1250 if (!inc_notype) {
1251 while (*(this_sym++)) {
1252 if (*this_sym == '%') {
1253 ++this_sym;
1254 break;
1255 }
1256 switch (*this_sym) {
1257 case 'n': inc_notype = true; break;
1258 case 'o': inc_object = true; break;
1259 case 'f': inc_func = true; break;
1260 case 'F': inc_file = true; break;
1261 case 'l': inc_local = true; break;
1262 case 'g': inc_global = true; break;
1263 case 'w': inc_weak = true; break;
1264 case 'p': inc_visdef = true; break;
1265 case 'i': inc_intern = true; break;
1266 case 'h': inc_hidden = true; break;
1267 case 'P': inc_prot = true; break;
1268 case 'd': inc_def = true; break;
1269 case 'u': inc_undef = true; break;
1270 case 'a': inc_abs = true; break;
1271 case 'c': inc_common = true; break;
1272 default: err("invalid symbol selector '%c'", *this_sym);
1273 }
1274 }
1275
1276 /* If no types are matched, not match all */
1277 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1278 inc_notype = inc_object = inc_func = inc_file = true;
1279 if (!inc_local && !inc_global && !inc_weak)
1280 inc_local = inc_global = inc_weak = true;
1281 if (!inc_visdef && !inc_intern && !inc_hidden && !inc_prot)
1282 inc_visdef = inc_intern = inc_hidden = inc_prot = true;
1283 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1284 inc_def = inc_undef = inc_abs = inc_common = true;
1285
1286 /* backwards compat for defined/undefined short hand */
1287 } else if (*this_sym == '+') {
1288 inc_undef = false;
1289 ++this_sym;
1290 } else if (*this_sym == '-') {
1291 inc_def = inc_abs = inc_common = false;
1292 ++this_sym;
1293 }
1294
1295 /* filter symbols */
1296 if ((!inc_notype && stt == STT_NOTYPE ) || \
1297 (!inc_object && stt == STT_OBJECT ) || \
1298 (!inc_func && stt == STT_FUNC ) || \
1299 (!inc_file && stt == STT_FILE ) || \
1300 (!inc_local && stb == STB_LOCAL ) || \
1301 (!inc_global && stb == STB_GLOBAL ) || \
1302 (!inc_weak && stb == STB_WEAK ) || \
1303 (!inc_visdef && stv == STV_DEFAULT ) || \
1304 (!inc_intern && stv == STV_INTERNAL ) || \
1305 (!inc_hidden && stv == STV_HIDDEN ) || \
1306 (!inc_prot && stv == STV_PROTECTED) || \
1307 (!inc_def && shn && shn < SHN_LORESERVE) || \
1308 (!inc_undef && shn == SHN_UNDEF ) || \
1309 (!inc_abs && shn == SHN_ABS ) || \
1310 (!inc_common && shn == SHN_COMMON ))
1311 continue;
1312
1313 if (*this_sym == '*') {
1314 /* a "*" symbol gets you debug output */
1315 printf("%s(%s) %5lX %-15s %-15s %-15s %-15s %s\n",
1316 ((*found_sym == 0) ? "\n\t" : "\t"),
1317 elf->base_filename,
1318 size,
1319 get_elfstttype(stt),
1320 get_elfstbtype(stb),
1321 get_elfstvtype(stv),
1322 get_elfshntype(shn),
1323 symname);
1324 goto matched;
1325
1326 } else {
1327 if (g_match) {
1328 /* regex match the symbol */
1329 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1330 continue;
1331
1332 } else if (*this_sym) {
1333 /* give empty symbols a "pass", else do a normal compare */
1334 const size_t len = strlen(this_sym);
1335 if (!(strncmp(this_sym, symname, len) == 0 &&
1336 /* Accept unversioned symbol names */
1337 (symname[len] == '\0' || symname[len] == '@')))
1338 continue;
1339 }
1340
1341 if (be_semi_verbose) {
1342 char buf[1024];
1343 snprintf(buf, sizeof(buf), "%lX %s %s",
1344 size,
1345 get_elfstttype(stt),
1346 this_sym);
1347 *ret = xstrdup(buf);
1348 } else {
1349 if (*ret) xchrcat(ret, ',', ret_len);
1350 xstrcat(ret, symname, ret_len);
1351 }
1352
1353 goto matched;
1354 }
1355 }
1356
1357 return;
1358
1359 matched:
1360 *found_sym = 1;
1361}
1362
804static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1363static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
805{ 1364{
806 unsigned long i;
807 char *ret; 1365 char *ret;
808 void *symtab_void, *strtab_void; 1366 void *symtab_void, *strtab_void;
809 1367
810 if (!find_sym) return NULL; 1368 if (!find_sym) return NULL;
811 ret = find_sym; 1369 ret = NULL;
812 1370
813 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1371 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
814 1372
815 if (symtab_void && strtab_void) { 1373 if (symtab_void && strtab_void) {
816#define FIND_SYM(B) \ 1374#define FIND_SYM(B) \
817 if (elf->elf_class == ELFCLASS ## B) { \ 1375 if (elf->elf_class == ELFCLASS ## B) { \
818 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1376 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
819 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1377 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
820 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1378 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
821 unsigned long cnt = EGET(symtab->sh_entsize); \ 1379 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
822 char *symname; \ 1380 char *symname; \
1381 size_t ret_len = 0; \
823 if (cnt) \ 1382 if (cnt) \
824 cnt = EGET(symtab->sh_size) / cnt; \ 1383 cnt = EGET(symtab->sh_size) / cnt; \
825 for (i = 0; i < cnt; ++i) { \ 1384 for (i = 0; i < cnt; ++i) { \
1385 if ((void*)sym > elf->data_end) { \
1386 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1387 goto break_out; \
1388 } \
826 if (sym->st_name) { \ 1389 if (sym->st_name) { \
1390 /* make sure the symbol name is in acceptable memory range */ \
827 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1391 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
828 if ((void*)symname > (void*)elf->data_end) { \ 1392 if ((void*)symname > elf->data_end) { \
829 warnf("%s: corrupt ELF symbols", elf->filename); \ 1393 warnf("%s: corrupt ELF symbols", elf->filename); \
1394 ++sym; \
830 continue; \ 1395 continue; \
831 } \ 1396 } \
832 if (*find_sym == '*') { \ 1397 scanelf_match_symname(elf, found_sym, \
833 printf("%s(%s) %5lX %15s %s\n", \ 1398 &ret, &ret_len, symname, \
834 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1399 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
835 elf->base_filename, \ 1400 ELF##B##_ST_BIND(EGET(sym->st_info)), \
836 (unsigned long)sym->st_size, \ 1401 ELF##B##_ST_VISIBILITY(EGET(sym->st_other)), \
837 get_elfstttype(sym->st_info), \ 1402 EGET(sym->st_shndx), \
838 symname); \ 1403 /* st_size can be 64bit, but no one is really that big, so screw em */ \
839 *found_sym = 1; \ 1404 EGET(sym->st_size)); \
840 } else { \
841 char *this_sym, *next_sym; \
842 this_sym = find_sym; \
843 do { \
844 next_sym = strchr(this_sym, ','); \
845 if (next_sym == NULL) \
846 next_sym = this_sym + strlen(this_sym); \
847 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
848 (strcmp(symname, versioned_symname) == 0)) { \
849 ret = this_sym; \
850 (*found_sym)++; \
851 goto break_out; \
852 } \
853 this_sym = next_sym + 1; \
854 } while (*next_sym != '\0'); \
855 } \
856 } \ 1405 } \
857 ++sym; \ 1406 ++sym; \
858 } } 1407 } \
1408 }
859 FIND_SYM(32) 1409 FIND_SYM(32)
860 FIND_SYM(64) 1410 FIND_SYM(64)
861 } 1411 }
862 1412
863break_out: 1413break_out:
866 if (*find_sym != '*' && *found_sym) 1416 if (*find_sym != '*' && *found_sym)
867 return ret; 1417 return ret;
868 if (be_quiet) 1418 if (be_quiet)
869 return NULL; 1419 return NULL;
870 else 1420 else
871 return (char *)" - "; 1421 return " - ";
872} 1422}
873 1423
1424static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1425{
1426 if (!find_section)
1427 return NULL;
1428
1429#define FIND_SECTION(B) \
1430 if (elf->elf_class == ELFCLASS ## B) { \
1431 size_t matched, n; \
1432 int invert; \
1433 const char *section_name; \
1434 Elf ## B ## _Shdr *section; \
1435 \
1436 matched = 0; \
1437 array_for_each(find_section_arr, n, section_name) { \
1438 invert = (*section_name == '!' ? 1 : 0); \
1439 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1440 if ((section == NULL && invert) || (section != NULL && !invert)) \
1441 ++matched; \
1442 } \
1443 \
1444 if (matched == array_cnt(find_section_arr)) \
1445 *found_section = 1; \
1446 }
1447 FIND_SECTION(32)
1448 FIND_SECTION(64)
1449
1450 if (be_wewy_wewy_quiet)
1451 return NULL;
1452
1453 if (*found_section)
1454 return find_section;
1455
1456 if (be_quiet)
1457 return NULL;
1458 else
1459 return " - ";
1460}
874 1461
875/* scan an elf file and show all the fun stuff */ 1462/* scan an elf file and show all the fun stuff */
876#define prints(str) write(fileno(stdout), str, strlen(str)) 1463#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
877static int scanelf_elfobj(elfobj *elf) 1464static int scanelf_elfobj(elfobj *elf)
878{ 1465{
879 unsigned long i; 1466 unsigned long i;
880 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1467 char found_pax, found_phdr, found_relro, found_load, found_textrel,
881 found_rpath, found_needed, found_interp, found_bind, found_soname, 1468 found_rpath, found_needed, found_interp, found_bind, found_soname,
882 found_sym, found_lib, found_file, found_textrels; 1469 found_sym, found_lib, found_file, found_textrels, found_section;
883 static char *out_buffer = NULL; 1470 static char *out_buffer = NULL;
884 static size_t out_len; 1471 static size_t out_len;
885 1472
886 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1473 found_pax = found_phdr = found_relro = found_load = found_textrel = \
887 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1474 found_rpath = found_needed = found_interp = found_bind = found_soname = \
888 found_sym = found_lib = found_file = found_textrels = 0; 1475 found_sym = found_lib = found_file = found_textrels = found_section = 0;
889 1476
890 if (be_verbose > 2) 1477 if (be_verbose > 2)
891 printf("%s: scanning file {%s,%s}\n", elf->filename, 1478 printf("%s: scanning file {%s,%s}\n", elf->filename,
892 get_elfeitype(EI_CLASS, elf->elf_class), 1479 get_elfeitype(EI_CLASS, elf->elf_class),
893 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1480 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
895 printf("%s: scanning file\n", elf->filename); 1482 printf("%s: scanning file\n", elf->filename);
896 1483
897 /* init output buffer */ 1484 /* init output buffer */
898 if (!out_buffer) { 1485 if (!out_buffer) {
899 out_len = sizeof(char) * 80; 1486 out_len = sizeof(char) * 80;
900 out_buffer = (char*)xmalloc(out_len); 1487 out_buffer = xmalloc(out_len);
901 } 1488 }
902 *out_buffer = '\0'; 1489 *out_buffer = '\0';
903 1490
904 /* show the header */ 1491 /* show the header */
905 if (!be_quiet && show_banner) { 1492 if (!be_quiet && show_banner) {
906 for (i = 0; out_format[i]; ++i) { 1493 for (i = 0; out_format[i]; ++i) {
907 if (!IS_MODIFIER(out_format[i])) continue; 1494 if (!IS_MODIFIER(out_format[i])) continue;
908 1495
909 switch (out_format[++i]) { 1496 switch (out_format[++i]) {
1497 case '+': break;
910 case '%': break; 1498 case '%': break;
911 case '#': break; 1499 case '#': break;
912 case 'F': 1500 case 'F':
913 case 'p': 1501 case 'p':
914 case 'f': prints("FILE "); found_file = 1; break; 1502 case 'f': prints("FILE "); found_file = 1; break;
915 case 'o': prints(" TYPE "); break; 1503 case 'o': prints(" TYPE "); break;
916 case 'x': prints(" PAX "); break; 1504 case 'x': prints(" PAX "); break;
917 case 'e': prints("STK/REL/PTL "); break; 1505 case 'e': prints("STK/REL/PTL "); break;
918 case 't': prints("TEXTREL "); break; 1506 case 't': prints("TEXTREL "); break;
919 case 'r': prints("RPATH "); break; 1507 case 'r': prints("RPATH "); break;
1508 case 'M': prints("CLASS "); break;
1509 case 'l':
920 case 'n': prints("NEEDED "); break; 1510 case 'n': prints("NEEDED "); break;
921 case 'i': prints("INTERP "); break; 1511 case 'i': prints("INTERP "); break;
922 case 'b': prints("BIND "); break; 1512 case 'b': prints("BIND "); break;
1513 case 'Z': prints("SIZE "); break;
923 case 'S': prints("SONAME "); break; 1514 case 'S': prints("SONAME "); break;
924 case 's': prints("SYM "); break; 1515 case 's': prints("SYM "); break;
925 case 'N': prints("LIB "); break; 1516 case 'N': prints("LIB "); break;
926 case 'T': prints("TEXTRELS "); break; 1517 case 'T': prints("TEXTRELS "); break;
1518 case 'k': prints("SECTION "); break;
1519 case 'a': prints("ARCH "); break;
1520 case 'I': prints("OSABI "); break;
1521 case 'Y': prints("EABI "); break;
1522 case 'O': prints("PERM "); break;
1523 case 'D': prints("ENDIAN "); break;
927 default: warnf("'%c' has no title ?", out_format[i]); 1524 default: warnf("'%c' has no title ?", out_format[i]);
928 } 1525 }
929 } 1526 }
930 if (!found_file) prints("FILE "); 1527 if (!found_file) prints("FILE ");
931 prints("\n"); 1528 prints("\n");
935 1532
936 /* dump all the good stuff */ 1533 /* dump all the good stuff */
937 for (i = 0; out_format[i]; ++i) { 1534 for (i = 0; out_format[i]; ++i) {
938 const char *out; 1535 const char *out;
939 const char *tmp; 1536 const char *tmp;
940 1537 static char ubuf[sizeof(unsigned long)*2];
941 /* make sure we trim leading spaces in quiet mode */
942 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
943 *out_buffer = '\0';
944
945 if (!IS_MODIFIER(out_format[i])) { 1538 if (!IS_MODIFIER(out_format[i])) {
946 xchrcat(&out_buffer, out_format[i], &out_len); 1539 xchrcat(&out_buffer, out_format[i], &out_len);
947 continue; 1540 continue;
948 } 1541 }
949 1542
950 out = NULL; 1543 out = NULL;
951 be_wewy_wewy_quiet = (out_format[i] == '#'); 1544 be_wewy_wewy_quiet = (out_format[i] == '#');
1545 be_semi_verbose = (out_format[i] == '+');
952 switch (out_format[++i]) { 1546 switch (out_format[++i]) {
1547 case '+':
953 case '%': 1548 case '%':
954 case '#': 1549 case '#':
955 xchrcat(&out_buffer, out_format[i], &out_len); break; 1550 xchrcat(&out_buffer, out_format[i], &out_len); break;
956 case 'F': 1551 case 'F':
957 found_file = 1; 1552 found_file = 1;
983 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1578 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
984 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1579 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
985 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1580 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
986 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1581 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
987 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1582 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1583 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1584 case 'D': out = get_endian(elf); break;
1585 case 'O': out = strfileperms(elf->filename); break;
988 case 'n': 1586 case 'n':
989 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1587 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
990 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1588 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
991 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1589 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
992 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1590 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
993 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1591 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1592 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1593 case 'a': out = get_elfemtype(elf); break;
1594 case 'I': out = get_elfosabi(elf); break;
1595 case 'Y': out = get_elf_eabi(elf); break;
1596 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
994 default: warnf("'%c' has no scan code?", out_format[i]); 1597 default: warnf("'%c' has no scan code?", out_format[i]);
995 } 1598 }
996 if (out) { 1599 if (out)
997 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
998 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
999 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1000 else
1001 xstrcat(&out_buffer, out, &out_len); 1600 xstrcat(&out_buffer, out, &out_len);
1002 }
1003 } 1601 }
1004 1602
1005#define FOUND_SOMETHING() \ 1603#define FOUND_SOMETHING() \
1006 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1604 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1007 found_rpath || found_needed || found_interp || found_bind || \ 1605 found_rpath || found_needed || found_interp || found_bind || \
1008 found_soname || found_sym || found_lib || found_textrels) 1606 found_soname || found_sym || found_lib || found_textrels || found_section )
1009 1607
1010 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1608 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1011 xchrcat(&out_buffer, ' ', &out_len); 1609 xchrcat(&out_buffer, ' ', &out_len);
1012 xstrcat(&out_buffer, elf->filename, &out_len); 1610 xstrcat(&out_buffer, elf->filename, &out_len);
1013 } 1611 }
1020} 1618}
1021 1619
1022/* scan a single elf */ 1620/* scan a single elf */
1023static int scanelf_elf(const char *filename, int fd, size_t len) 1621static int scanelf_elf(const char *filename, int fd, size_t len)
1024{ 1622{
1025 int ret; 1623 int ret = 1;
1624 size_t n;
1625 const char *match_etype;
1026 elfobj *elf; 1626 elfobj *elf;
1027 1627
1028 /* verify this is real ELF */ 1628 /* Verify this is a real ELF */
1029 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) { 1629 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1030 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 1630 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1031 return 1; 1631 return 2;
1032 }
1033
1034 if (strlen(match_etypes)) {
1035 char sbuf[126];
1036 strncpy(sbuf, match_etypes, sizeof(sbuf));
1037 if (strchr(match_etypes, ',') != NULL) {
1038 char *p;
1039 while((p = strrchr(sbuf, ',')) != NULL) {
1040 *p = 0;
1041 if (atoi(p+1) == get_etype(elf))
1042 goto label_ret;
1043 }
1044 } 1632 }
1045 if (atoi(sbuf) != get_etype(elf)) { 1633
1046 ret = 1; 1634 /* Possibly filter based on ELF bitness */
1635 switch (match_bits) {
1636 case 32:
1637 if (elf->elf_class != ELFCLASS32)
1047 goto label_done; 1638 goto done;
1639 break;
1640 case 64:
1641 if (elf->elf_class != ELFCLASS64)
1642 goto done;
1643 break;
1048 } 1644 }
1049 }
1050 1645
1051label_ret: 1646 /* Possibly filter based on the ELF's e_type field */
1647 array_for_each(match_etypes, n, match_etype)
1648 if (etype_lookup(match_etype) == get_etype(elf))
1649 goto scanit;
1650 if (array_cnt(match_etypes))
1651 goto done;
1652
1653 scanit:
1052 ret = scanelf_elfobj(elf); 1654 ret = scanelf_elfobj(elf);
1053 1655
1054label_done: 1656 done:
1055 unreadelf(elf); 1657 unreadelf(elf);
1056 return ret; 1658 return ret;
1057} 1659}
1058 1660
1059/* scan an archive of elfs */ 1661/* scan an archive of elfs */
1066 1668
1067 ar = ar_open_fd(filename, fd); 1669 ar = ar_open_fd(filename, fd);
1068 if (ar == NULL) 1670 if (ar == NULL)
1069 return 1; 1671 return 1;
1070 1672
1071 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0); 1673 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1072 while ((m=ar_next(ar)) != NULL) { 1674 while ((m = ar_next(ar)) != NULL) {
1675 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1676 if (cur_pos == -1)
1677 errp("lseek() failed");
1073 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size); 1678 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1074 if (elf) { 1679 if (elf) {
1075 scanelf_elfobj(elf); 1680 scanelf_elfobj(elf);
1076 unreadelf(elf); 1681 unreadelf(elf);
1077 } 1682 }
1078 } 1683 }
1079 munmap(ar_buffer, len); 1684 munmap(ar_buffer, len);
1080 1685
1081 return 0; 1686 return 0;
1082} 1687}
1083/* scan a file which may be an elf or an archive or some other magical beast */ 1688/* scan a file which may be an elf or an archive or some other magical beast */
1084static void scanelf_file(const char *filename) 1689static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1085{ 1690{
1691 const struct stat *st = st_cache;
1086 struct stat st; 1692 struct stat symlink_st;
1087 int fd; 1693 int fd;
1088 1694
1089 /* make sure 'filename' exists */
1090 if (lstat(filename, &st) == -1) {
1091 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1092 return;
1093 }
1094
1095 /* always handle regular files and handle symlinked files if no -y */ 1695 /* always handle regular files and handle symlinked files if no -y */
1096 if (S_ISLNK(st.st_mode)) { 1696 if (S_ISLNK(st->st_mode)) {
1097 if (!scan_symlink) return; 1697 if (!scan_symlink)
1098 stat(filename, &st); 1698 return 1;
1699 fstatat(dir_fd, filename, &symlink_st, 0);
1700 st = &symlink_st;
1099 } 1701 }
1702
1100 if (!S_ISREG(st.st_mode)) { 1703 if (!S_ISREG(st->st_mode)) {
1101 if (be_verbose > 2) printf("%s: skipping non-file\n", filename); 1704 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1102 return; 1705 return 1;
1103 } 1706 }
1104 1707
1105 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1) 1708 if (match_perms) {
1709 if ((st->st_mode | match_perms) != st->st_mode)
1710 return 1;
1711 }
1712 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1713 if (fd == -1) {
1714 if (fix_elf && errno == ETXTBSY)
1715 warnp("%s: could not fix", filename);
1716 else if (be_verbose > 2)
1717 printf("%s: skipping file: %s\n", filename, strerror(errno));
1106 return; 1718 return 1;
1719 }
1107 1720
1108 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives) 1721 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1109 /* if it isn't an ELF, maybe it's an .a archive */ 1722 /* if it isn't an ELF, maybe it's an .a archive */
1723 if (scan_archives)
1110 scanelf_archive(filename, fd, st.st_size); 1724 scanelf_archive(filename, fd, st->st_size);
1111 1725
1726 /*
1727 * unreadelf() implicitly closes its fd, so only close it
1728 * when we are returning it in the non-ELF case
1729 */
1112 close(fd); 1730 close(fd);
1731 }
1732
1733 return 0;
1113} 1734}
1114 1735
1115/* scan a directory for ET_EXEC files and print when we find one */ 1736/* scan a directory for ET_EXEC files and print when we find one */
1116static void scanelf_dir(const char *path) 1737static int scanelf_dirat(int dir_fd, const char *path)
1117{ 1738{
1118 register DIR *dir; 1739 register DIR *dir;
1119 register struct dirent *dentry; 1740 register struct dirent *dentry;
1120 struct stat st_top, st; 1741 struct stat st_top, st;
1121 char buf[__PAX_UTILS_PATH_MAX]; 1742 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1122 size_t pathlen = 0, len = 0; 1743 size_t pathlen = 0, len = 0;
1744 int ret = 0;
1745 int subdir_fd;
1123 1746
1124 /* make sure path exists */ 1747 /* make sure path exists */
1125 if (lstat(path, &st_top) == -1) { 1748 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1126 if (be_verbose > 2) printf("%s: does not exist\n", path); 1749 if (be_verbose > 2) printf("%s: does not exist\n", path);
1127 return; 1750 return 1;
1128 } 1751 }
1129 1752
1130 /* ok, if it isn't a directory, assume we can open it */ 1753 /* ok, if it isn't a directory, assume we can open it */
1131 if (!S_ISDIR(st_top.st_mode)) { 1754 if (!S_ISDIR(st_top.st_mode))
1132 scanelf_file(path); 1755 return scanelf_fileat(dir_fd, path, &st_top);
1133 return;
1134 }
1135 1756
1136 /* now scan the dir looking for fun stuff */ 1757 /* now scan the dir looking for fun stuff */
1137 if ((dir = opendir(path)) == NULL) { 1758 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1138 warnf("could not opendir %s: %s", path, strerror(errno)); 1759 if (subdir_fd == -1)
1760 dir = NULL;
1761 else
1762 dir = fdopendir(subdir_fd);
1763 if (dir == NULL) {
1764 if (subdir_fd != -1)
1765 close(subdir_fd);
1766 else if (be_verbose > 2)
1767 printf("%s: skipping dir: %s\n", path, strerror(errno));
1139 return; 1768 return 1;
1140 } 1769 }
1141 if (be_verbose > 1) printf("%s: scanning dir\n", path); 1770 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1142 1771
1143 pathlen = strlen(path); 1772 subpath = stpcpy(buf, path);
1773 if (subpath[-1] != '/')
1774 *subpath++ = '/';
1775 pathlen = subpath - buf;
1144 while ((dentry = readdir(dir))) { 1776 while ((dentry = readdir(dir))) {
1145 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1777 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1146 continue; 1778 continue;
1779
1780 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1781 continue;
1782
1147 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1783 len = strlen(dentry->d_name);
1148 if (len >= sizeof(buf)) { 1784 if (len + pathlen + 1 >= sizeof(buf)) {
1149 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1785 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1150 (unsigned long)len, (unsigned long)sizeof(buf)); 1786 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1151 continue; 1787 continue;
1152 } 1788 }
1153 sprintf(buf, "%s/%s", path, dentry->d_name); 1789 memcpy(subpath, dentry->d_name, len);
1154 if (lstat(buf, &st) != -1) { 1790 subpath[len] = '\0';
1791
1155 if (S_ISREG(st.st_mode)) 1792 if (S_ISREG(st.st_mode))
1156 scanelf_file(buf); 1793 ret = scanelf_fileat(dir_fd, buf, &st);
1157 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1794 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1158 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1795 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1159 scanelf_dir(buf); 1796 ret = scanelf_dirat(dir_fd, buf);
1160 }
1161 } 1797 }
1162 } 1798 }
1163 closedir(dir); 1799 closedir(dir);
1164}
1165 1800
1801 return ret;
1802}
1803static int scanelf_dir(const char *path)
1804{
1805 return scanelf_dirat(root_fd, root_rel_path(path));
1806}
1807
1166static int scanelf_from_file(char *filename) 1808static int scanelf_from_file(const char *filename)
1167{ 1809{
1168 FILE *fp = NULL; 1810 FILE *fp;
1169 char *p; 1811 char *p, *path;
1170 char path[__PAX_UTILS_PATH_MAX]; 1812 size_t len;
1813 int ret;
1171 1814
1172 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1815 if (strcmp(filename, "-") == 0)
1173 fp = stdin; 1816 fp = stdin;
1174 else if ((fp = fopen(filename, "r")) == NULL) 1817 else if ((fp = fopen(filename, "r")) == NULL)
1175 return 1; 1818 return 1;
1176 1819
1177 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1820 path = NULL;
1821 len = 0;
1822 ret = 0;
1823 while (getline(&path, &len, fp) != -1) {
1178 if ((p = strchr(path, '\n')) != NULL) 1824 if ((p = strchr(path, '\n')) != NULL)
1179 *p = 0; 1825 *p = 0;
1180 search_path = path; 1826 search_path = path;
1181 scanelf_dir(path); 1827 ret = scanelf_dir(path);
1182 } 1828 }
1829 free(path);
1830
1183 if (fp != stdin) 1831 if (fp != stdin)
1184 fclose(fp); 1832 fclose(fp);
1833
1185 return 0; 1834 return ret;
1186} 1835}
1187 1836
1188static void load_ld_so_conf() 1837#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1838
1839static int _load_ld_cache_config(const char *fname)
1189{ 1840{
1190 FILE *fp = NULL; 1841 FILE *fp = NULL;
1191 char *p; 1842 char *p, *path;
1192 char path[__PAX_UTILS_PATH_MAX]; 1843 size_t len;
1193 int i = 0; 1844 int curr_fd = -1;
1194 1845
1195 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1846 fp = fopenat_r(root_fd, root_rel_path(fname));
1847 if (fp == NULL)
1196 return; 1848 return -1;
1197 1849
1198 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1850 path = NULL;
1199 if (*path != '/') 1851 len = 0;
1200 continue; 1852 while (getline(&path, &len, fp) != -1) {
1201
1202 if ((p = strrchr(path, '\r')) != NULL) 1853 if ((p = strrchr(path, '\r')) != NULL)
1203 *p = 0; 1854 *p = 0;
1204 if ((p = strchr(path, '\n')) != NULL) 1855 if ((p = strchr(path, '\n')) != NULL)
1205 *p = 0; 1856 *p = 0;
1206 1857
1207 ldpaths[i++] = xstrdup(path); 1858 /* recursive includes of the same file will make this segfault. */
1859 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1860 glob_t gl;
1861 size_t x;
1862 const char *gpath;
1208 1863
1209 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1864 /* re-use existing path buffer ... need to be creative */
1210 break; 1865 if (path[8] != '/')
1866 gpath = memcpy(path + 3, "/etc/", 5);
1867 else
1868 gpath = path + 8;
1869 if (root_fd != AT_FDCWD) {
1870 if (curr_fd == -1) {
1871 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1872 if (fchdir(root_fd))
1873 errp("unable to change to root dir");
1874 }
1875 gpath = root_rel_path(gpath);
1876 }
1877
1878 if (glob(gpath, 0, NULL, &gl) == 0) {
1879 for (x = 0; x < gl.gl_pathc; ++x) {
1880 /* try to avoid direct loops */
1881 if (strcmp(gl.gl_pathv[x], fname) == 0)
1882 continue;
1883 _load_ld_cache_config(gl.gl_pathv[x]);
1884 }
1885 globfree(&gl);
1886 }
1887
1888 /* failed globs are ignored by glibc */
1889 continue;
1211 } 1890 }
1212 ldpaths[i] = NULL; 1891
1892 if (*path != '/')
1893 continue;
1894
1895 xarraypush_str(ldpaths, path);
1896 }
1897 free(path);
1213 1898
1214 fclose(fp); 1899 fclose(fp);
1900
1901 if (curr_fd != -1) {
1902 if (fchdir(curr_fd))
1903 {/* don't care */}
1904 close(curr_fd);
1905 }
1906
1907 return 0;
1908}
1909
1910#elif defined(__FreeBSD__) || defined(__DragonFly__)
1911
1912static int _load_ld_cache_config(const char *fname)
1913{
1914 FILE *fp = NULL;
1915 char *b = NULL, *p;
1916 struct elfhints_hdr hdr;
1917
1918 fp = fopenat_r(root_fd, root_rel_path(fname));
1919 if (fp == NULL)
1920 return -1;
1921
1922 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1923 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1924 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1925 {
1926 fclose(fp);
1927 return -1;
1928 }
1929
1930 b = xmalloc(hdr.dirlistlen + 1);
1931 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1932 fclose(fp);
1933 free(b);
1934 return -1;
1935 }
1936
1937 while ((p = strsep(&b, ":"))) {
1938 if (*p == '\0')
1939 continue;
1940 xarraypush_str(ldpaths, p);
1941 }
1942
1943 free(b);
1944 fclose(fp);
1945 return 0;
1946}
1947
1948#else
1949#ifdef __ELF__
1950#warning Cache config support not implemented for your target
1951#endif
1952static int _load_ld_cache_config(const char *fname)
1953{
1954 return 0;
1955}
1956#endif
1957
1958static void load_ld_cache_config(const char *fname)
1959{
1960 bool scan_l, scan_ul, scan_ull;
1961 size_t n;
1962 const char *ldpath;
1963
1964 _load_ld_cache_config(fname);
1965
1966 scan_l = scan_ul = scan_ull = false;
1967 array_for_each(ldpaths, n, ldpath) {
1968 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1969 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1970 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1971 }
1972
1973 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1974 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1975 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1215} 1976}
1216 1977
1217/* scan /etc/ld.so.conf for paths */ 1978/* scan /etc/ld.so.conf for paths */
1218static void scanelf_ldpath() 1979static void scanelf_ldpath(void)
1219{ 1980{
1220 char scan_l, scan_ul, scan_ull; 1981 size_t n;
1221 int i = 0; 1982 const char *ldpath;
1222 1983
1223 if (!ldpaths[0]) 1984 array_for_each(ldpaths, n, ldpath)
1224 err("Unable to load any paths from ld.so.conf");
1225
1226 scan_l = scan_ul = scan_ull = 0;
1227
1228 while (ldpaths[i]) {
1229 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1230 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1231 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1232 scanelf_dir(ldpaths[i]); 1985 scanelf_dir(ldpath);
1233 ++i;
1234 }
1235
1236 if (!scan_l) scanelf_dir("/lib");
1237 if (!scan_ul) scanelf_dir("/usr/lib");
1238 if (!scan_ull) scanelf_dir("/usr/local/lib");
1239} 1986}
1240 1987
1241/* scan env PATH for paths */ 1988/* scan env PATH for paths */
1242static void scanelf_envpath() 1989static void scanelf_envpath(void)
1243{ 1990{
1244 char *path, *p; 1991 char *path, *p;
1245 1992
1246 path = getenv("PATH"); 1993 path = getenv("PATH");
1247 if (!path) 1994 if (!path)
1254 } 2001 }
1255 2002
1256 free(path); 2003 free(path);
1257} 2004}
1258 2005
1259 2006/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1260/* usage / invocation handling functions */
1261#define PARSE_FLAGS "plRmyAXxetrnLibSs:gN:TaqvF:f:o:E:BhV" 2007#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1262#define a_argument required_argument 2008#define a_argument required_argument
1263static struct option const long_opts[] = { 2009static struct option const long_opts[] = {
1264 {"path", no_argument, NULL, 'p'}, 2010 {"path", no_argument, NULL, 'p'},
1265 {"ldpath", no_argument, NULL, 'l'}, 2011 {"ldpath", no_argument, NULL, 'l'},
2012 {"use-ldpath",no_argument, NULL, 129},
2013 {"root", a_argument, NULL, 128},
1266 {"recursive", no_argument, NULL, 'R'}, 2014 {"recursive", no_argument, NULL, 'R'},
1267 {"mount", no_argument, NULL, 'm'}, 2015 {"mount", no_argument, NULL, 'm'},
1268 {"symlink", no_argument, NULL, 'y'}, 2016 {"symlink", no_argument, NULL, 'y'},
1269 {"archives", no_argument, NULL, 'A'}, 2017 {"archives", no_argument, NULL, 'A'},
1270 {"ldcache", no_argument, NULL, 'L'}, 2018 {"ldcache", no_argument, NULL, 'L'},
1271 {"fix", no_argument, NULL, 'X'}, 2019 {"fix", no_argument, NULL, 'X'},
2020 {"setpax", a_argument, NULL, 'z'},
1272 {"pax", no_argument, NULL, 'x'}, 2021 {"pax", no_argument, NULL, 'x'},
1273 {"header", no_argument, NULL, 'e'}, 2022 {"header", no_argument, NULL, 'e'},
1274 {"textrel", no_argument, NULL, 't'}, 2023 {"textrel", no_argument, NULL, 't'},
1275 {"rpath", no_argument, NULL, 'r'}, 2024 {"rpath", no_argument, NULL, 'r'},
1276 {"needed", no_argument, NULL, 'n'}, 2025 {"needed", no_argument, NULL, 'n'},
1277 {"interp", no_argument, NULL, 'i'}, 2026 {"interp", no_argument, NULL, 'i'},
1278 {"bind", no_argument, NULL, 'b'}, 2027 {"bind", no_argument, NULL, 'b'},
1279 {"soname", no_argument, NULL, 'S'}, 2028 {"soname", no_argument, NULL, 'S'},
1280 {"symbol", a_argument, NULL, 's'}, 2029 {"symbol", a_argument, NULL, 's'},
2030 {"section", a_argument, NULL, 'k'},
1281 {"lib", a_argument, NULL, 'N'}, 2031 {"lib", a_argument, NULL, 'N'},
1282 {"gmatch", no_argument, NULL, 'g'}, 2032 {"gmatch", no_argument, NULL, 'g'},
1283 {"textrels", no_argument, NULL, 'T'}, 2033 {"textrels", no_argument, NULL, 'T'},
1284 {"etype", a_argument, NULL, 'E'}, 2034 {"etype", a_argument, NULL, 'E'},
2035 {"bits", a_argument, NULL, 'M'},
2036 {"endian", no_argument, NULL, 'D'},
2037 {"osabi", no_argument, NULL, 'I'},
2038 {"eabi", no_argument, NULL, 'Y'},
2039 {"perms", a_argument, NULL, 'O'},
2040 {"size", no_argument, NULL, 'Z'},
1285 {"all", no_argument, NULL, 'a'}, 2041 {"all", no_argument, NULL, 'a'},
1286 {"quiet", no_argument, NULL, 'q'}, 2042 {"quiet", no_argument, NULL, 'q'},
1287 {"verbose", no_argument, NULL, 'v'}, 2043 {"verbose", no_argument, NULL, 'v'},
1288 {"format", a_argument, NULL, 'F'}, 2044 {"format", a_argument, NULL, 'F'},
1289 {"from", a_argument, NULL, 'f'}, 2045 {"from", a_argument, NULL, 'f'},
1290 {"file", a_argument, NULL, 'o'}, 2046 {"file", a_argument, NULL, 'o'},
2047 {"nocolor", no_argument, NULL, 'C'},
1291 {"nobanner", no_argument, NULL, 'B'}, 2048 {"nobanner", no_argument, NULL, 'B'},
1292 {"help", no_argument, NULL, 'h'}, 2049 {"help", no_argument, NULL, 'h'},
1293 {"version", no_argument, NULL, 'V'}, 2050 {"version", no_argument, NULL, 'V'},
1294 {NULL, no_argument, NULL, 0x0} 2051 {NULL, no_argument, NULL, 0x0}
1295}; 2052};
1296 2053
1297static const char *opts_help[] = { 2054static const char * const opts_help[] = {
1298 "Scan all directories in PATH environment", 2055 "Scan all directories in PATH environment",
1299 "Scan all directories in /etc/ld.so.conf", 2056 "Scan all directories in /etc/ld.so.conf",
2057 "Use ld.so.conf to show full path (use with -r/-n)",
2058 "Root directory (use with -l or -p)",
1300 "Scan directories recursively", 2059 "Scan directories recursively",
1301 "Don't recursively cross mount points", 2060 "Don't recursively cross mount points",
1302 "Don't scan symlinks", 2061 "Don't scan symlinks",
1303 "Scan archives (.a files)", 2062 "Scan archives (.a files)",
1304 "Utilize ld.so.cache information (use with -r/-n)", 2063 "Utilize ld.so.cache to show full path (use with -r/-n)",
1305 "Try and 'fix' bad things (use with -r/-e)\n", 2064 "Try and 'fix' bad things (use with -r/-e)",
2065 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1306 "Print PaX markings", 2066 "Print PaX markings",
1307 "Print GNU_STACK/PT_LOAD markings", 2067 "Print GNU_STACK/PT_LOAD markings",
1308 "Print TEXTREL information", 2068 "Print TEXTREL information",
1309 "Print RPATH information", 2069 "Print RPATH information",
1310 "Print NEEDED information", 2070 "Print NEEDED information",
1311 "Print INTERP information", 2071 "Print INTERP information",
1312 "Print BIND information", 2072 "Print BIND information",
1313 "Print SONAME information", 2073 "Print SONAME information",
1314 "Find a specified symbol", 2074 "Find a specified symbol",
2075 "Find a specified section",
1315 "Find a specified library", 2076 "Find a specified library",
1316 "Use strncmp to match libraries. (use with -N)", 2077 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1317 "Locate cause of TEXTREL", 2078 "Locate cause of TEXTREL",
2079 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1318 "Print only ELF files matching numeric constant", 2080 "Print only ELF files matching numeric bits",
1319 "Print all scanned info (-x -e -t -r -b)\n", 2081 "Print Endianness",
2082 "Print OSABI",
2083 "Print EABI (EM_ARM Only)",
2084 "Print only ELF files matching octal permissions",
2085 "Print ELF file size",
2086 "Print all useful/simple info\n",
1320 "Only output 'bad' things", 2087 "Only output 'bad' things",
1321 "Be verbose (can be specified more than once)", 2088 "Be verbose (can be specified more than once)",
1322 "Use specified format for output", 2089 "Use specified format for output",
1323 "Read input stream from a filename", 2090 "Read input stream from a filename",
1324 "Write output stream to a filename", 2091 "Write output stream to a filename",
2092 "Don't emit color in output",
1325 "Don't display the header", 2093 "Don't display the header",
1326 "Print this help and exit", 2094 "Print this help and exit",
1327 "Print version and exit", 2095 "Print version and exit",
1328 NULL 2096 NULL
1329}; 2097};
1330 2098
1331/* display usage and exit */ 2099/* display usage and exit */
1332static void usage(int status) 2100static void usage(int status)
1333{ 2101{
1334 unsigned long i; 2102 const char a_arg[] = "<arg>";
2103 size_t a_arg_len = strlen(a_arg) + 2;
2104 size_t i;
2105 int optlen;
1335 printf("* Scan ELF binaries for stuff\n\n" 2106 printf("* Scan ELF binaries for stuff\n\n"
1336 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0); 2107 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1337 printf("Options: -[%s]\n", PARSE_FLAGS); 2108 printf("Options: -[%s]\n", PARSE_FLAGS);
2109
2110 /* prescan the --long opt length to auto-align */
2111 optlen = 0;
1338 for (i = 0; long_opts[i].name; ++i) 2112 for (i = 0; long_opts[i].name; ++i) {
2113 int l = strlen(long_opts[i].name);
2114 if (long_opts[i].has_arg == a_argument)
2115 l += a_arg_len;
2116 optlen = max(l, optlen);
2117 }
2118
2119 for (i = 0; long_opts[i].name; ++i) {
2120 /* first output the short flag if it has one */
2121 if (long_opts[i].val > '~')
2122 printf(" ");
2123 else
2124 printf(" -%c, ", long_opts[i].val);
2125
2126 /* then the long flag */
1339 if (long_opts[i].has_arg == no_argument) 2127 if (long_opts[i].has_arg == no_argument)
1340 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2128 printf("--%-*s", optlen, long_opts[i].name);
1341 long_opts[i].name, opts_help[i]);
1342 else 2129 else
1343 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2130 printf("--%s %s %*s", long_opts[i].name, a_arg,
1344 long_opts[i].name, opts_help[i]); 2131 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1345 2132
1346 if (status != EXIT_SUCCESS) 2133 /* finally the help text */
1347 exit(status); 2134 printf("* %s\n", opts_help[i]);
2135 }
1348 2136
1349 puts("\nThe format modifiers for the -F option are:"); 2137 puts("\nFor more information, see the scanelf(1) manpage");
1350 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1351 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1352 puts(" i INTERP \tb BIND \ts symbol");
1353 puts(" N library \to Type \tT TEXTRELs");
1354 puts(" S SONAME");
1355 puts(" p filename (with search path removed)");
1356 puts(" f filename (short name/basename)");
1357 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1358
1359 exit(status); 2138 exit(status);
1360} 2139}
1361 2140
1362/* parse command line arguments and preform needed actions */ 2141/* parse command line arguments and preform needed actions */
2142#define do_pax_state(option, flag) \
2143 if (islower(option)) { \
2144 flags &= ~PF_##flag; \
2145 flags |= PF_NO##flag; \
2146 } else { \
2147 flags &= ~PF_NO##flag; \
2148 flags |= PF_##flag; \
2149 }
2150static void parse_delimited(array_t *arr, char *arg, const char *delim)
2151{
2152 char *ele = strtok(arg, delim);
2153 if (!ele) /* edge case: -s '' */
2154 xarraypush_str(arr, "");
2155 while (ele) {
2156 xarraypush_str(arr, ele);
2157 ele = strtok(NULL, delim);
2158 }
2159}
1363static void parseargs(int argc, char *argv[]) 2160static int parseargs(int argc, char *argv[])
1364{ 2161{
1365 int i; 2162 int i;
1366 char *from_file = NULL; 2163 const char *from_file = NULL;
2164 int ret = 0;
2165 char load_cache_config = 0;
1367 2166
1368 opterr = 0; 2167 opterr = 0;
1369 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2168 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1370 switch (i) { 2169 switch (i) {
1371 2170
1379 case 'f': 2178 case 'f':
1380 if (from_file) warn("You prob don't want to specify -f twice"); 2179 if (from_file) warn("You prob don't want to specify -f twice");
1381 from_file = optarg; 2180 from_file = optarg;
1382 break; 2181 break;
1383 case 'E': 2182 case 'E':
1384 strncpy(match_etypes, optarg, sizeof(match_etypes)); 2183 /* historically, this was comma delimited */
2184 parse_delimited(match_etypes, optarg, ",");
2185 break;
2186 case 'M':
2187 match_bits = atoi(optarg);
2188 if (match_bits == 0) {
2189 if (strcmp(optarg, "ELFCLASS32") == 0)
2190 match_bits = 32;
2191 if (strcmp(optarg, "ELFCLASS64") == 0)
2192 match_bits = 64;
2193 }
2194 break;
2195 case 'O':
2196 if (sscanf(optarg, "%o", &match_perms) == -1)
2197 match_bits = 0;
1385 break; 2198 break;
1386 case 'o': { 2199 case 'o': {
1387 FILE *fp = NULL;
1388 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2200 if (freopen(optarg, "w", stdout) == NULL)
1389 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2201 errp("Could not freopen(%s)", optarg);
1390 SET_STDOUT(fp);
1391 break; 2202 break;
1392 } 2203 }
1393
1394 case 's': { 2204 case 'k':
1395 if (find_sym) warn("You prob don't want to specify -s twice"); 2205 xarraypush_str(find_section_arr, optarg);
1396 find_sym = optarg;
1397 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1398 sprintf(versioned_symname, "%s@", find_sym);
1399 break; 2206 break;
1400 }
1401 case 'N': { 2207 case 's':
1402 if (find_lib) warn("You prob don't want to specify -N twice"); 2208 /* historically, this was comma delimited */
1403 find_lib = optarg; 2209 parse_delimited(find_sym_arr, optarg, ",");
1404 break; 2210 break;
1405 } 2211 case 'N':
1406 2212 xarraypush_str(find_lib_arr, optarg);
2213 break;
1407 case 'F': { 2214 case 'F': {
1408 if (out_format) warn("You prob don't want to specify -F twice"); 2215 if (out_format) warn("You prob don't want to specify -F twice");
1409 out_format = optarg; 2216 out_format = optarg;
1410 break; 2217 break;
1411 } 2218 }
2219 case 'z': {
2220 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2221 size_t x;
1412 2222
1413 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2223 for (x = 0; x < strlen(optarg); x++) {
2224 switch (optarg[x]) {
2225 case 'p':
2226 case 'P':
2227 do_pax_state(optarg[x], PAGEEXEC);
2228 break;
2229 case 's':
2230 case 'S':
2231 do_pax_state(optarg[x], SEGMEXEC);
2232 break;
2233 case 'm':
2234 case 'M':
2235 do_pax_state(optarg[x], MPROTECT);
2236 break;
2237 case 'e':
2238 case 'E':
2239 do_pax_state(optarg[x], EMUTRAMP);
2240 break;
2241 case 'r':
2242 case 'R':
2243 do_pax_state(optarg[x], RANDMMAP);
2244 break;
2245 case 'x':
2246 case 'X':
2247 do_pax_state(optarg[x], RANDEXEC);
2248 break;
2249 default:
2250 break;
2251 }
2252 }
2253 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2254 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2255 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2256 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2257 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2258 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2259 setpax = flags;
2260 break;
2261 }
2262 case 'Z': show_size = 1; break;
2263 case 'g': ++g_match; break;
1414 case 'L': use_ldcache = 1; break; 2264 case 'L': load_cache_config = use_ldcache = 1; break;
1415 case 'y': scan_symlink = 0; break; 2265 case 'y': scan_symlink = 0; break;
1416 case 'A': scan_archives = 1; break; 2266 case 'A': scan_archives = 1; break;
2267 case 'C': color_init(true); break;
1417 case 'B': show_banner = 0; break; 2268 case 'B': show_banner = 0; break;
1418 case 'l': scan_ldpath = 1; break; 2269 case 'l': load_cache_config = scan_ldpath = 1; break;
1419 case 'p': scan_envpath = 1; break; 2270 case 'p': scan_envpath = 1; break;
1420 case 'R': dir_recurse = 1; break; 2271 case 'R': dir_recurse = 1; break;
1421 case 'm': dir_crossmount = 0; break; 2272 case 'm': dir_crossmount = 0; break;
1422 case 'X': ++fix_elf; break; 2273 case 'X': ++fix_elf; break;
1423 case 'x': show_pax = 1; break; 2274 case 'x': show_pax = 1; break;
1427 case 'n': show_needed = 1; break; 2278 case 'n': show_needed = 1; break;
1428 case 'i': show_interp = 1; break; 2279 case 'i': show_interp = 1; break;
1429 case 'b': show_bind = 1; break; 2280 case 'b': show_bind = 1; break;
1430 case 'S': show_soname = 1; break; 2281 case 'S': show_soname = 1; break;
1431 case 'T': show_textrels = 1; break; 2282 case 'T': show_textrels = 1; break;
1432 case 'q': be_quiet = 1; break; 2283 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1433 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2284 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1434 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2285 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1435 2286 case 'D': show_endian = 1; break;
2287 case 'I': show_osabi = 1; break;
2288 case 'Y': show_eabi = 1; break;
2289 case 128:
2290 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2291 if (root_fd == -1)
2292 err("Could not open root: %s", optarg);
2293 break;
2294 case 129: load_cache_config = use_ldpath = 1; break;
1436 case ':': 2295 case ':':
1437 err("Option '%c' is missing parameter", optopt); 2296 err("Option '%c' is missing parameter", optopt);
1438 case '?': 2297 case '?':
1439 err("Unknown option '%c' or argument missing", optopt); 2298 err("Unknown option '%c' or argument missing", optopt);
1440 default: 2299 default:
1441 err("Unhandled option '%c'; please report this", i); 2300 err("Unhandled option '%c'; please report this", i);
1442 } 2301 }
1443 } 2302 }
2303 if (show_textrels && be_verbose)
2304 objdump = which("objdump", "OBJDUMP");
2305 /* precompile all the regexes */
2306 if (g_match) {
2307 regex_t preg;
2308 const char *this_sym;
2309 size_t n;
2310 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1444 2311
2312 array_for_each(find_sym_arr, n, this_sym) {
2313 /* see scanelf_match_symname for logic info */
2314 switch (this_sym[0]) {
2315 case '%':
2316 while (*(this_sym++))
2317 if (*this_sym == '%') {
2318 ++this_sym;
2319 break;
2320 }
2321 break;
2322 case '+':
2323 case '-':
2324 ++this_sym;
2325 break;
2326 }
2327 if (*this_sym == '*')
2328 ++this_sym;
2329
2330 ret = regcomp(&preg, this_sym, flags);
2331 if (ret) {
2332 char err[256];
2333 regerror(ret, &preg, err, sizeof(err));
2334 err("regcomp of %s failed: %s", this_sym, err);
2335 }
2336 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2337 }
2338 }
2339 /* flatten arrays for display */
2340 find_sym = array_flatten_str(find_sym_arr);
2341 find_lib = array_flatten_str(find_lib_arr);
2342 find_section = array_flatten_str(find_section_arr);
1445 /* let the format option override all other options */ 2343 /* let the format option override all other options */
1446 if (out_format) { 2344 if (out_format) {
1447 show_pax = show_phdr = show_textrel = show_rpath = \ 2345 show_pax = show_phdr = show_textrel = show_rpath = \
1448 show_needed = show_interp = show_bind = show_soname = \ 2346 show_needed = show_interp = show_bind = show_soname = \
1449 show_textrels = 0; 2347 show_textrels = show_perms = show_endian = show_size = \
2348 show_osabi = show_eabi = 0;
1450 for (i = 0; out_format[i]; ++i) { 2349 for (i = 0; out_format[i]; ++i) {
1451 if (!IS_MODIFIER(out_format[i])) continue; 2350 if (!IS_MODIFIER(out_format[i])) continue;
1452 2351
1453 switch (out_format[++i]) { 2352 switch (out_format[++i]) {
2353 case '+': break;
1454 case '%': break; 2354 case '%': break;
1455 case '#': break; 2355 case '#': break;
1456 case 'F': break; 2356 case 'F': break;
1457 case 'p': break; 2357 case 'p': break;
1458 case 'f': break; 2358 case 'f': break;
2359 case 'k': break;
1459 case 's': break; 2360 case 's': break;
1460 case 'N': break; 2361 case 'N': break;
1461 case 'o': break; 2362 case 'o': break;
2363 case 'a': break;
2364 case 'M': break;
2365 case 'Z': show_size = 1; break;
2366 case 'D': show_endian = 1; break;
2367 case 'I': show_osabi = 1; break;
2368 case 'Y': show_eabi = 1; break;
2369 case 'O': show_perms = 1; break;
1462 case 'x': show_pax = 1; break; 2370 case 'x': show_pax = 1; break;
1463 case 'e': show_phdr = 1; break; 2371 case 'e': show_phdr = 1; break;
1464 case 't': show_textrel = 1; break; 2372 case 't': show_textrel = 1; break;
1465 case 'r': show_rpath = 1; break; 2373 case 'r': show_rpath = 1; break;
1466 case 'n': show_needed = 1; break; 2374 case 'n': show_needed = 1; break;
1467 case 'i': show_interp = 1; break; 2375 case 'i': show_interp = 1; break;
1468 case 'b': show_bind = 1; break; 2376 case 'b': show_bind = 1; break;
1469 case 'S': show_soname = 1; break; 2377 case 'S': show_soname = 1; break;
1470 case 'T': show_textrels = 1; break; 2378 case 'T': show_textrels = 1; break;
1471 default: 2379 default:
1472 err("Invalid format specifier '%c' (byte %i)", 2380 err("invalid format specifier '%c' (byte %i)",
1473 out_format[i], i+1); 2381 out_format[i], i+1);
1474 } 2382 }
1475 } 2383 }
1476 2384
1477 /* construct our default format */ 2385 /* construct our default format */
1478 } else { 2386 } else {
1479 size_t fmt_len = 30; 2387 size_t fmt_len = 30;
1480 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2388 out_format = xmalloc(sizeof(char) * fmt_len);
2389 *out_format = '\0';
1481 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2390 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1482 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2391 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2392 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2393 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2394 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2395 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2396 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1483 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2397 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1484 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2398 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1485 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2399 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1486 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2400 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1487 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2401 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1488 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2402 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1489 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2403 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1490 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2404 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1491 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2405 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2406 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1492 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2407 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1493 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2408 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1494 } 2409 }
1495 if (be_verbose > 2) printf("Format: %s\n", out_format); 2410 if (be_verbose > 2) printf("Format: %s\n", out_format);
1496 2411
1497 /* now lets actually do the scanning */ 2412 /* now lets actually do the scanning */
1498 if (scan_ldpath || use_ldcache) 2413 if (load_cache_config)
1499 load_ld_so_conf(); 2414 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1500 if (scan_ldpath) scanelf_ldpath(); 2415 if (scan_ldpath) scanelf_ldpath();
1501 if (scan_envpath) scanelf_envpath(); 2416 if (scan_envpath) scanelf_envpath();
2417 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2418 from_file = "-";
1502 if (from_file) { 2419 if (from_file) {
1503 scanelf_from_file(from_file); 2420 scanelf_from_file(from_file);
1504 from_file = *argv; 2421 from_file = *argv;
1505 } 2422 }
1506 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2423 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1507 err("Nothing to scan !?"); 2424 err("Nothing to scan !?");
1508 while (optind < argc) { 2425 while (optind < argc) {
1509 search_path = argv[optind++]; 2426 search_path = argv[optind++];
1510 scanelf_dir(search_path); 2427 ret = scanelf_dir(search_path);
1511 } 2428 }
1512 2429
2430#ifdef __PAX_UTILS_CLEANUP
1513 /* clean up */ 2431 /* clean up */
1514 if (versioned_symname) free(versioned_symname);
1515 for (i = 0; ldpaths[i]; ++i)
1516 free(ldpaths[i]); 2432 xarrayfree(ldpaths);
2433 xarrayfree(find_sym_arr);
2434 xarrayfree(find_lib_arr);
2435 xarrayfree(find_section_arr);
2436 free(find_sym);
2437 free(find_lib);
2438 free(find_section);
2439 {
2440 size_t n;
2441 regex_t *preg;
2442 array_for_each(find_sym_regex_arr, n, preg)
2443 regfree(preg);
2444 xarrayfree(find_sym_regex_arr);
2445 }
1517 2446
1518 if (ldcache != 0) 2447 if (ldcache != 0)
1519 munmap(ldcache, ldcache_size); 2448 munmap(ldcache, ldcache_size);
1520} 2449#endif
1521 2450
1522
1523
1524/* utility funcs */
1525static char *xstrdup(const char *s)
1526{
1527 char *ret = strdup(s);
1528 if (!ret) err("Could not strdup(): %s", strerror(errno));
1529 return ret; 2451 return ret;
1530} 2452}
1531static void *xmalloc(size_t size)
1532{
1533 void *ret = malloc(size);
1534 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1535 return ret;
1536}
1537static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1538{
1539 size_t new_len;
1540 2453
1541 new_len = strlen(*dst) + strlen(src); 2454static char **get_split_env(const char *envvar)
1542 if (*curr_len <= new_len) {
1543 *curr_len = new_len + (*curr_len / 2);
1544 *dst = realloc(*dst, *curr_len);
1545 if (!*dst)
1546 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1547 }
1548
1549 if (n)
1550 strncat(*dst, src, n);
1551 else
1552 strcat(*dst, src);
1553}
1554static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1555{ 2455{
1556 static char my_app[2]; 2456 const char *delims = " \t\n";
1557 my_app[0] = append; 2457 char **envvals = NULL;
1558 my_app[1] = '\0'; 2458 char *env, *s;
1559 xstrcat(dst, my_app, curr_len); 2459 int nentry;
1560}
1561 2460
2461 if ((env = getenv(envvar)) == NULL)
2462 return NULL;
1562 2463
2464 env = xstrdup(env);
2465 if (env == NULL)
2466 return NULL;
2467
2468 s = strtok(env, delims);
2469 if (s == NULL) {
2470 free(env);
2471 return NULL;
2472 }
2473
2474 nentry = 0;
2475 while (s != NULL) {
2476 ++nentry;
2477 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2478 envvals[nentry-1] = s;
2479 s = strtok(NULL, delims);
2480 }
2481 envvals[nentry] = NULL;
2482
2483 /* don't want to free(env) as it contains the memory that backs
2484 * the envvals array of strings */
2485 return envvals;
2486}
2487
2488static void parseenv(void)
2489{
2490 color_init(false);
2491 qa_textrels = get_split_env("QA_TEXTRELS");
2492 qa_execstack = get_split_env("QA_EXECSTACK");
2493 qa_wx_load = get_split_env("QA_WX_LOAD");
2494}
2495
2496#ifdef __PAX_UTILS_CLEANUP
2497static void cleanup(void)
2498{
2499 free(out_format);
2500 free(qa_textrels);
2501 free(qa_execstack);
2502 free(qa_wx_load);
2503}
2504#endif
1563 2505
1564int main(int argc, char *argv[]) 2506int main(int argc, char *argv[])
1565{ 2507{
2508 int ret;
1566 if (argc < 2) 2509 if (argc < 2)
1567 usage(EXIT_FAILURE); 2510 usage(EXIT_FAILURE);
2511 parseenv();
1568 parseargs(argc, argv); 2512 ret = parseargs(argc, argv);
1569 fclose(stdout); 2513 fclose(stdout);
1570#ifdef __BOUNDS_CHECKING_ON 2514#ifdef __PAX_UTILS_CLEANUP
1571 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2515 cleanup();
2516 warn("The calls to add/delete heap should be off:\n"
2517 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2518 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1572#endif 2519#endif
1573 return EXIT_SUCCESS; 2520 return ret;
1574} 2521}
2522
2523/* Match filename against entries in matchlist, return TRUE
2524 * if the file is listed */
2525static int file_matches_list(const char *filename, char **matchlist)
2526{
2527 char **file;
2528 char *match;
2529 char buf[__PAX_UTILS_PATH_MAX];
2530
2531 if (matchlist == NULL)
2532 return 0;
2533
2534 for (file = matchlist; *file != NULL; file++) {
2535 if (search_path) {
2536 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2537 match = buf;
2538 } else {
2539 match = *file;
2540 }
2541 if (fnmatch(match, filename, 0) == 0)
2542 return 1;
2543 }
2544 return 0;
2545}

Legend:
Removed from v.1.119  
changed lines
  Added in v.1.268

  ViewVC Help
Powered by ViewVC 1.1.20