/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.127 Revision 1.263
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.127 2006/02/17 07:13:54 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.263 2014/03/20 08:08:37 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.263 2014/03/20 08:08:37 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.127 2006/02/17 07:13:54 solar Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static int scanelf_elfobj(elfobj *elf); 18static int file_matches_list(const char *filename, char **matchlist);
21static int scanelf_elf(const char *filename, int fd, size_t len);
22static int scanelf_archive(const char *filename, int fd, size_t len);
23static void scanelf_file(const char *filename);
24static void scanelf_dir(const char *path);
25static void scanelf_ldpath(void);
26static void scanelf_envpath(void);
27static void usage(int status);
28static void parseargs(int argc, char *argv[]);
29static char *xstrdup(const char *s);
30static void *xmalloc(size_t size);
31static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
32#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
33static inline void xchrcat(char **dst, const char append, size_t *curr_len);
34 19
35/* variables to control behavior */ 20/* variables to control behavior */
36static char match_etypes[126] = ""; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
37static char *ldpaths[256]; 22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
38static char scan_ldpath = 0; 23static char scan_ldpath = 0;
39static char scan_envpath = 0; 24static char scan_envpath = 0;
40static char scan_symlink = 1; 25static char scan_symlink = 1;
41static char scan_archives = 0; 26static char scan_archives = 0;
42static char dir_recurse = 0; 27static char dir_recurse = 0;
43static char dir_crossmount = 1; 28static char dir_crossmount = 1;
44static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
45static char show_phdr = 0; 32static char show_phdr = 0;
46static char show_textrel = 0; 33static char show_textrel = 0;
47static char show_rpath = 0; 34static char show_rpath = 0;
48static char show_needed = 0; 35static char show_needed = 0;
49static char show_interp = 0; 36static char show_interp = 0;
50static char show_bind = 0; 37static char show_bind = 0;
51static char show_soname = 0; 38static char show_soname = 0;
52static char show_textrels = 0; 39static char show_textrels = 0;
53static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
54static char be_quiet = 0; 44static char be_quiet = 0;
55static char be_verbose = 0; 45static char be_verbose = 0;
56static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
57static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
58static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
59static char *find_section = NULL; 53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
60static char *out_format = NULL; 55static char *out_format = NULL;
61static char *search_path = NULL; 56static char *search_path = NULL;
62static char fix_elf = 0; 57static char fix_elf = 0;
63static char gmatch = 0; 58static char g_match = 0;
64static char use_ldcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
65 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
66
66int match_bits = 0; 67static int match_bits = 0;
67caddr_t ldcache = 0; 68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
68size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
69unsigned long setpax = 0UL; 71static unsigned long setpax = 0UL;
70 72
73static int has_objdump = 0;
74
75/* find the path to a file by name */
76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
80
81 path = getenv("PATH");
82 if (!path)
83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
71/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
72static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
73{ 125{
74 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
75#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
76 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
77 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
78 /* debug sections */ \ 144 Elf ## B ## _Shdr *estrtab = strtab; \
79 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
80 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 146 Elf ## B ## _Shdr *edynstr = dynstr; \
81 /* runtime sections */ \ 147 \
82 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
83 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
84 if (symtab && dynsym) { \ 152 if (symtab && dynsym) \
85 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
86 } else { \ 154 else \
87 *sym = (void*)(symtab ? symtab : dynsym); \ 155 *sym = symtab ? symtab : dynsym; \
88 } \ 156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
89 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
90 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
91 } else { \ 163 else \
92 *tab = (void*)(strtab ? strtab : dynstr); \ 164 *str = strtab ? strtab : dynstr; \
93 } \
94 } 165 }
95 GET_SYMTABS(32) 166 GET_SYMTABS(32)
96 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
97} 259}
98 260
99static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
100{ 262{
101 static char ret[7]; 263 static char ret[7];
116 continue; \ 278 continue; \
117 if (fix_elf && setpax) { \ 279 if (fix_elf && setpax) { \
118 /* set the paxctl flags */ \ 280 /* set the paxctl flags */ \
119 ESET(phdr[i].p_flags, setpax); \ 281 ESET(phdr[i].p_flags, setpax); \
120 } \ 282 } \
121 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
122 continue; \ 284 continue; \
123 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
124 *found_pax = 1; \ 286 *found_pax = 1; \
125 ++shown; \ 287 ++shown; \
126 break; \ 288 break; \
128 } 290 }
129 SHOW_PAX(32) 291 SHOW_PAX(32)
130 SHOW_PAX(64) 292 SHOW_PAX(64)
131 } 293 }
132 294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
301
133 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
134 if (!*ret) { 303 if (!*ret) {
135 static char *paxflags; 304 static char *paxflags;
136
137 if (fix_elf && setpax) {
138 /* set the chpax settings */
139 // ESET(EHDR ## B (elf->ehdr)->e_ident[EI_PAX]), setpax);
140 }
141
142 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
143 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) { 306 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
144 *found_pax = 1; 307 *found_pax = 1;
145 return (be_wewy_wewy_quiet ? NULL : paxflags); 308 return (be_wewy_wewy_quiet ? NULL : paxflags);
146 } 309 }
156static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
157{ 320{
158 static char ret[12]; 321 static char ret[12];
159 char *found; 322 char *found;
160 unsigned long i, shown, multi_stack, multi_relro, multi_load; 323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
161 int max_pt_load;
162 324
163 if (!show_phdr) return NULL; 325 if (!show_phdr) return NULL;
164 326
165 memcpy(ret, "--- --- ---\0", 12); 327 memcpy(ret, "--- --- ---\0", 12);
166 328
167 shown = 0; 329 shown = 0;
168 multi_stack = multi_relro = multi_load = 0; 330 multi_stack = multi_relro = multi_load = 0;
169 max_pt_load = elf_max_pt_load(elf);
170 331
171#define NOTE_GNU_STACK ".note.GNU-stack" 332#define NOTE_GNU_STACK ".note.GNU-stack"
172#define SHOW_PHDR(B) \ 333#define SHOW_PHDR(B) \
173 if (elf->elf_class == ELFCLASS ## B) { \ 334 if (elf->elf_class == ELFCLASS ## B) { \
174 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
176 uint32_t flags, check_flags; \ 337 uint32_t flags, check_flags; \
177 if (elf->phdr != NULL) { \ 338 if (elf->phdr != NULL) { \
178 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
179 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
180 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
181 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
182 found = found_phdr; \ 346 found = found_phdr; \
183 offset = 0; \ 347 offset = 0; \
184 check_flags = PF_X; \ 348 check_flags = PF_X; \
185 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
350 if (multi_relro++) \
186 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
187 found = found_relro; \ 352 found = found_relro; \
188 offset = 4; \ 353 offset = 4; \
189 check_flags = PF_X; \ 354 check_flags = PF_X; \
190 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
191 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \ 356 if (file_matches_list(elf->filename, qa_wx_load)) \
192 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \ 357 continue; \
193 found = found_load; \ 358 found = found_load; \
194 offset = 8; \ 359 offset = 8; \
195 check_flags = PF_W|PF_X; \ 360 check_flags = PF_W|PF_X; \
196 } else \ 361 } else \
197 continue; \ 362 continue; \
198 flags = EGET(phdr[i].p_flags); \ 363 flags = EGET(phdr[i].p_flags); \
199 if (be_quiet && ((flags & check_flags) != check_flags)) \ 364 if (be_quiet && ((flags & check_flags) != check_flags)) \
200 continue; \ 365 continue; \
201 if (fix_elf && ((flags & PF_X) != flags)) { \ 366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
202 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \ 367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
203 ret[3] = ret[7] = '!'; \ 368 ret[3] = ret[7] = '!'; \
204 flags = EGET(phdr[i].p_flags); \ 369 flags = EGET(phdr[i].p_flags); \
205 } \ 370 } \
206 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
210 } else if (elf->shdr != NULL) { \ 375 } else if (elf->shdr != NULL) { \
211 /* no program headers which means this is prob an object file */ \ 376 /* no program headers which means this is prob an object file */ \
212 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
213 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
214 char *str; \ 379 char *str; \
215 if ((void*)strtbl > (void*)elf->data_end) \ 380 if ((void*)strtbl > elf->data_end) \
216 goto skip_this_shdr##B; \ 381 goto skip_this_shdr##B; \
382 /* let's flag -w/+x object files since the final ELF will most likely \
383 * need write access to the stack (who doesn't !?). so the combined \
384 * output will bring in +w automatically and that's bad. \
385 */ \
217 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 386 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
218 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 387 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
219 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 388 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
220 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 389 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
221 str = elf->data + offset; \ 390 str = elf->data + offset; \
222 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \ 391 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
234 break; \ 403 break; \
235 } \ 404 } \
236 } \ 405 } \
237 skip_this_shdr##B: \ 406 skip_this_shdr##B: \
238 if (!multi_stack) { \ 407 if (!multi_stack) { \
408 if (file_matches_list(elf->filename, qa_execstack)) \
409 return NULL; \
239 *found_phdr = 1; \ 410 *found_phdr = 1; \
240 shown = 1; \ 411 shown = 1; \
241 memcpy(ret, "!WX", 3); \ 412 memcpy(ret, "!WX", 3); \
242 } \ 413 } \
243 } \ 414 } \
248 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 419 if (be_wewy_wewy_quiet || (be_quiet && !shown))
249 return NULL; 420 return NULL;
250 else 421 else
251 return ret; 422 return ret;
252} 423}
424
425/*
426 * See if this ELF contains a DT_TEXTREL tag in any of its
427 * PT_DYNAMIC sections.
428 */
253static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 429static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
254{ 430{
255 static const char *ret = "TEXTREL"; 431 static const char *ret = "TEXTREL";
256 unsigned long i; 432 unsigned long i;
257 433
258 if (!show_textrel && !show_textrels) return NULL; 434 if (!show_textrel && !show_textrels) return NULL;
435
436 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
259 437
260 if (elf->phdr) { 438 if (elf->phdr) {
261#define SHOW_TEXTREL(B) \ 439#define SHOW_TEXTREL(B) \
262 if (elf->elf_class == ELFCLASS ## B) { \ 440 if (elf->elf_class == ELFCLASS ## B) { \
263 Elf ## B ## _Dyn *dyn; \ 441 Elf ## B ## _Dyn *dyn; \
264 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 442 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
265 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 443 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
266 Elf ## B ## _Off offset; \ 444 Elf ## B ## _Off offset; \
267 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 445 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
268 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 446 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
269 offset = EGET(phdr[i].p_offset); \ 447 offset = EGET(phdr[i].p_offset); \
270 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 448 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
271 dyn = DYN ## B (elf->data + offset); \ 449 dyn = DYN ## B (elf->vdata + offset); \
272 while (EGET(dyn->d_tag) != DT_NULL) { \ 450 while (EGET(dyn->d_tag) != DT_NULL) { \
273 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 451 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
274 *found_textrel = 1; \ 452 *found_textrel = 1; \
275 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 453 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
276 return (be_wewy_wewy_quiet ? NULL : ret); \ 454 return (be_wewy_wewy_quiet ? NULL : ret); \
285 if (be_quiet || be_wewy_wewy_quiet) 463 if (be_quiet || be_wewy_wewy_quiet)
286 return NULL; 464 return NULL;
287 else 465 else
288 return " - "; 466 return " - ";
289} 467}
468
469/*
470 * Scan the .text section to see if there are any relocations in it.
471 * Should rewrite this to check PT_LOAD sections that are marked
472 * Executable rather than the section named '.text'.
473 */
290static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 474static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
291{ 475{
292 unsigned long s, r, rmax; 476 unsigned long s, r, rmax;
293 void *symtab_void, *strtab_void, *text_void; 477 void *symtab_void, *strtab_void, *text_void;
294 478
315 Elf ## B ## _Rela *rela; \ 499 Elf ## B ## _Rela *rela; \
316 /* search the section headers for relocations */ \ 500 /* search the section headers for relocations */ \
317 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 501 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
318 uint32_t sh_type = EGET(shdr[s].sh_type); \ 502 uint32_t sh_type = EGET(shdr[s].sh_type); \
319 if (sh_type == SHT_REL) { \ 503 if (sh_type == SHT_REL) { \
320 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 504 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
321 rela = NULL; \ 505 rela = NULL; \
322 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 506 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
323 } else if (sh_type == SHT_RELA) { \ 507 } else if (sh_type == SHT_RELA) { \
324 rel = NULL; \ 508 rel = NULL; \
325 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 509 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
326 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 510 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
327 } else \ 511 } else \
328 continue; \ 512 continue; \
329 /* now see if any of the relocs are in the .text */ \ 513 /* now see if any of the relocs are in the .text */ \
330 for (r = 0; r < rmax; ++r) { \ 514 for (r = 0; r < rmax; ++r) { \
345 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 529 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
346 if (be_verbose <= 2) continue; \ 530 if (be_verbose <= 2) continue; \
347 } else \ 531 } else \
348 *found_textrels = 1; \ 532 *found_textrels = 1; \
349 /* locate this relocation symbol name */ \ 533 /* locate this relocation symbol name */ \
350 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 534 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
351 if ((void*)sym > (void*)elf->data_end) { \ 535 if ((void*)sym > elf->data_end) { \
352 warn("%s: corrupt ELF symbol", elf->filename); \ 536 warn("%s: corrupt ELF symbol", elf->filename); \
353 continue; \ 537 continue; \
354 } \ 538 } \
355 sym_max = ELF ## B ## _R_SYM(r_info); \ 539 sym_max = ELF ## B ## _R_SYM(r_info); \
356 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 540 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
359 sym = NULL; \ 543 sym = NULL; \
360 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 544 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
361 /* show the raw details about this reloc */ \ 545 /* show the raw details about this reloc */ \
362 printf(" %s: ", elf->base_filename); \ 546 printf(" %s: ", elf->base_filename); \
363 if (sym && sym->st_name) \ 547 if (sym && sym->st_name) \
364 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 548 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
365 else \ 549 else \
366 printf("(memory/fake?)"); \ 550 printf("(memory/data?)"); \
367 printf(" [0x%lX]", (unsigned long)r_offset); \ 551 printf(" [0x%lX]", (unsigned long)r_offset); \
368 /* now try to find the closest symbol that this rel is probably in */ \ 552 /* now try to find the closest symbol that this rel is probably in */ \
369 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 553 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
370 func = NULL; \ 554 func = NULL; \
371 offset_tmp = 0; \ 555 offset_tmp = 0; \
372 while (sym_max--) { \ 556 while (sym_max--) { \
373 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 557 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
374 func = sym; \ 558 func = sym; \
375 offset_tmp = EGET(sym->st_value); \ 559 offset_tmp = EGET(sym->st_value); \
376 } \ 560 } \
377 ++sym; \ 561 ++sym; \
378 } \ 562 } \
379 printf(" in "); \ 563 printf(" in "); \
380 if (func && func->st_name) \ 564 if (func && func->st_name) { \
381 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 565 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
566 if (r_offset > EGET(func->st_size)) \
567 printf("(optimized out: previous %s)", func_name); \
382 else \ 568 else \
383 printf("(NULL: fake?)"); \ 569 printf("%s", func_name); \
570 } else \
571 printf("(optimized out)"); \
384 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 572 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
573 if (be_verbose && has_objdump) { \
574 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
575 char *sysbuf; \
576 size_t syslen; \
577 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
578 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
579 sysbuf = xmalloc(syslen); \
580 if (end_addr < r_offset) \
581 /* not uncommon when things are optimized out */ \
582 end_addr = r_offset + 0x100; \
583 snprintf(sysbuf, syslen, sysfmt, \
584 (unsigned long)offset_tmp, \
585 (unsigned long)end_addr, \
586 elf->filename, \
587 (unsigned long)r_offset); \
588 fflush(stdout); \
589 if (system(sysbuf)) {/* don't care */} \
590 fflush(stdout); \
591 free(sysbuf); \
592 } \
385 } \ 593 } \
386 } } 594 } }
387 SHOW_TEXTRELS(32) 595 SHOW_TEXTRELS(32)
388 SHOW_TEXTRELS(64) 596 SHOW_TEXTRELS(64)
389 } 597 }
391 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 599 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
392 600
393 return NULL; 601 return NULL;
394} 602}
395 603
396static void rpath_security_checks(elfobj *, char *, const char *);
397static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type) 604static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
398{ 605{
399 struct stat st; 606 struct stat st;
400 switch (*item) { 607 switch (*item) {
401 case '/': break; 608 case '/': break;
407 warnf("Security problem NULL %s in %s", dt_type, elf->filename); 614 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
408 break; 615 break;
409 case '$': 616 case '$':
410 if (fstat(elf->fd, &st) != -1) 617 if (fstat(elf->fd, &st) != -1)
411 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 618 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
412 warnf("Security problem with %s='%s' in %s with mode set of %o", 619 warnf("Security problem with %s='%s' in %s with mode set of %o",
413 dt_type, item, elf->filename, st.st_mode & 07777); 620 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
414 break; 621 break;
415 default: 622 default:
416 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename); 623 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
417 break; 624 break;
418 } 625 }
419} 626}
420static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 627static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
421{ 628{
422 unsigned long i, s; 629 unsigned long i;
423 char *rpath, *runpath, **r; 630 char *rpath, *runpath, **r;
424 void *strtbl_void; 631 void *strtbl_void;
425 632
426 if (!show_rpath) return; 633 if (!show_rpath) return;
427 634
438 Elf ## B ## _Off offset; \ 645 Elf ## B ## _Off offset; \
439 Elf ## B ## _Xword word; \ 646 Elf ## B ## _Xword word; \
440 /* Scan all the program headers */ \ 647 /* Scan all the program headers */ \
441 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 648 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
442 /* Just scan dynamic headers */ \ 649 /* Just scan dynamic headers */ \
443 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 650 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
444 offset = EGET(phdr[i].p_offset); \ 651 offset = EGET(phdr[i].p_offset); \
445 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 652 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
446 /* Just scan dynamic RPATH/RUNPATH headers */ \ 653 /* Just scan dynamic RPATH/RUNPATH headers */ \
447 dyn = DYN ## B (elf->data + offset); \ 654 dyn = DYN ## B (elf->vdata + offset); \
448 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 655 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
449 if (word == DT_RPATH) { \ 656 if (word == DT_RPATH) { \
450 r = &rpath; \ 657 r = &rpath; \
451 } else if (word == DT_RUNPATH) { \ 658 } else if (word == DT_RUNPATH) { \
452 r = &runpath; \ 659 r = &runpath; \
456 } \ 663 } \
457 /* Verify the memory is somewhat sane */ \ 664 /* Verify the memory is somewhat sane */ \
458 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 665 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
459 if (offset < (Elf ## B ## _Off)elf->len) { \ 666 if (offset < (Elf ## B ## _Off)elf->len) { \
460 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 667 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
461 *r = (char*)(elf->data + offset); \ 668 *r = elf->data + offset; \
462 /* cache the length in case we need to nuke this section later on */ \ 669 /* cache the length in case we need to nuke this section later on */ \
463 if (fix_elf) \ 670 if (fix_elf) \
464 offset = strlen(*r); \ 671 offset = strlen(*r); \
465 /* If quiet, don't output paths in ld.so.conf */ \ 672 /* If quiet, don't output paths in ld.so.conf */ \
466 if (be_quiet) { \ 673 if (be_quiet) { \
472 /* scan each path in : delimited list */ \ 679 /* scan each path in : delimited list */ \
473 while (start) { \ 680 while (start) { \
474 rpath_security_checks(elf, start, get_elfdtype(word)); \ 681 rpath_security_checks(elf, start, get_elfdtype(word)); \
475 end = strchr(start, ':'); \ 682 end = strchr(start, ':'); \
476 len = (end ? abs(end - start) : strlen(start)); \ 683 len = (end ? abs(end - start) : strlen(start)); \
477 if (use_ldcache) \ 684 if (use_ldcache) { \
478 for (s = 0; ldpaths[s]; ++s) \ 685 size_t n; \
686 const char *ldpath; \
687 array_for_each(ldpaths, n, ldpath) \
479 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 688 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
480 *r = end; \ 689 *r = end; \
481 /* corner case ... if RPATH reads "/usr/lib:", we want \ 690 /* corner case ... if RPATH reads "/usr/lib:", we want \
482 * to show ':' rather than '' */ \ 691 * to show ':' rather than '' */ \
483 if (end && end[1] != '\0') \ 692 if (end && end[1] != '\0') \
484 (*r)++; \ 693 (*r)++; \
485 break; \ 694 break; \
486 } \ 695 } \
696 } \
487 if (!*r || !end) \ 697 if (!*r || !end) \
488 break; \ 698 break; \
489 else \ 699 else \
490 start = start + len + 1; \ 700 start = start + len + 1; \
491 } \ 701 } \
557 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 767 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
558 else if (!be_quiet) 768 else if (!be_quiet)
559 xstrcat(ret, " - ", ret_len); 769 xstrcat(ret, " - ", ret_len);
560} 770}
561 771
772/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
562#define LDSO_CACHE_MAGIC "ld.so-" 773#define LDSO_CACHE_MAGIC "ld.so-"
563#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 774#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
564#define LDSO_CACHE_VER "1.7.0" 775#define LDSO_CACHE_VER "1.7.0"
565#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 776#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
566#define FLAG_ANY -1 777#define FLAG_ANY -1
575#define FLAG_X8664_LIB64 0x0300 786#define FLAG_X8664_LIB64 0x0300
576#define FLAG_S390_LIB64 0x0400 787#define FLAG_S390_LIB64 0x0400
577#define FLAG_POWERPC_LIB64 0x0500 788#define FLAG_POWERPC_LIB64 0x0500
578#define FLAG_MIPS64_LIBN32 0x0600 789#define FLAG_MIPS64_LIBN32 0x0600
579#define FLAG_MIPS64_LIBN64 0x0700 790#define FLAG_MIPS64_LIBN64 0x0700
791#define FLAG_X8664_LIBX32 0x0800
792#define FLAG_ARM_LIBHF 0x0900
793#define FLAG_AARCH64_LIB64 0x0a00
580 794
581static char *lookup_cache_lib(elfobj *, char *); 795#if defined(__GLIBC__) || defined(__UCLIBC__)
796
582static char *lookup_cache_lib(elfobj *elf, char *fname) 797static char *lookup_cache_lib(elfobj *elf, const char *fname)
583{ 798{
584 int fd = 0; 799 int fd;
585 char *strs; 800 char *strs;
586 static char buf[__PAX_UTILS_PATH_MAX] = ""; 801 static char buf[__PAX_UTILS_PATH_MAX] = "";
587 const char *cachefile = "/etc/ld.so.cache"; 802 const char *cachefile = root_rel_path("/etc/ld.so.cache");
588 struct stat st; 803 struct stat st;
589 804
590 typedef struct { 805 typedef struct {
591 char magic[LDSO_CACHE_MAGIC_LEN]; 806 char magic[LDSO_CACHE_MAGIC_LEN];
592 char version[LDSO_CACHE_VER_LEN]; 807 char version[LDSO_CACHE_VER_LEN];
602 libentry_t *libent; 817 libentry_t *libent;
603 818
604 if (fname == NULL) 819 if (fname == NULL)
605 return NULL; 820 return NULL;
606 821
607 if (ldcache == 0) { 822 if (ldcache == NULL) {
608 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 823 if (fstatat(root_fd, cachefile, &st, 0))
824 return NULL;
825
826 fd = openat(root_fd, cachefile, O_RDONLY);
827 if (fd == -1)
609 return NULL; 828 return NULL;
610 829
611 /* cache these values so we only map/unmap the cache file once */ 830 /* cache these values so we only map/unmap the cache file once */
612 ldcache_size = st.st_size; 831 ldcache_size = st.st_size;
613 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 832 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
614
615 close(fd); 833 close(fd);
616 834
617 if (ldcache == (caddr_t)-1) { 835 if (ldcache == MAP_FAILED) {
618 ldcache = 0; 836 ldcache = NULL;
619 return NULL; 837 return NULL;
620 } 838 }
621 839
622 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 840 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
841 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
842 {
843 munmap(ldcache, ldcache_size);
844 ldcache = NULL;
623 return NULL; 845 return NULL;
624 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
625 return NULL;
626 } 846 }
847 } else
848 header = ldcache;
627 849
628 header = (header_t *) ldcache;
629 libent = (libentry_t *) (ldcache + sizeof(header_t)); 850 libent = ldcache + sizeof(header_t);
630 strs = (char *) &libent[header->nlibs]; 851 strs = (char *) &libent[header->nlibs];
631 852
632 for (fd = 0; fd < header->nlibs; fd++) { 853 for (fd = 0; fd < header->nlibs; ++fd) {
633 /* this should be more fine grained, but for now we assume that 854 /* This should be more fine grained, but for now we assume that
634 * diff arches will not be cached together. and we ignore the 855 * diff arches will not be cached together, and we ignore the
635 * the different multilib mips cases. */ 856 * the different multilib mips cases.
857 */
636 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 858 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
637 continue; 859 continue;
638 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 860 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
639 continue; 861 continue;
640 862
641 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 863 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
642 continue; 864 continue;
865
866 /* Return first hit because that is how the ldso rolls */
643 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 867 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
868 break;
644 } 869 }
870
645 return buf; 871 return buf;
646} 872}
647 873
874#elif defined(__NetBSD__)
875static char *lookup_cache_lib(elfobj *elf, const char *fname)
876{
877 static char buf[__PAX_UTILS_PATH_MAX] = "";
878 static struct stat st;
879 size_t n;
880 char *ldpath;
881
882 array_for_each(ldpath, n, ldpath) {
883 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
884 continue; /* if the pathname is too long, or something went wrong, ignore */
885
886 if (stat(buf, &st) != 0)
887 continue; /* if the lib doesn't exist in *ldpath, look further */
888
889 /* NetBSD doesn't actually do sanity checks, it just loads the file
890 * and if that doesn't work, continues looking in other directories.
891 * This cannot easily be safely emulated, unfortunately. For now,
892 * just assume that if it exists, it's a valid library. */
893
894 return buf;
895 }
896
897 /* not found in any path */
898 return NULL;
899}
900#else
901#ifdef __ELF__
902#warning Cache support not implemented for your target
903#endif
904static char *lookup_cache_lib(elfobj *elf, const char *fname)
905{
906 return NULL;
907}
908#endif
909
910static char *lookup_config_lib(const char *fname)
911{
912 static char buf[__PAX_UTILS_PATH_MAX] = "";
913 const char *ldpath;
914 size_t n;
915
916 array_for_each(ldpaths, n, ldpath) {
917 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
918 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
919 return buf;
920 }
921
922 return NULL;
923}
648 924
649static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 925static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
650{ 926{
651 unsigned long i; 927 unsigned long i;
652 char *needed; 928 char *needed;
653 void *strtbl_void; 929 void *strtbl_void;
654 char *p; 930 char *p;
655 931
932 /*
933 * -n -> op==0 -> print all
934 * -N -> op==1 -> print requested
935 */
656 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 936 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
937 return NULL;
657 938
658 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 939 strtbl_void = elf_findsecbyname(elf, ".dynstr");
659 940
660 if (elf->phdr && strtbl_void) { 941 if (elf->phdr && strtbl_void) {
661#define SHOW_NEEDED(B) \ 942#define SHOW_NEEDED(B) \
663 Elf ## B ## _Dyn *dyn; \ 944 Elf ## B ## _Dyn *dyn; \
664 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 945 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
665 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 946 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
666 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 947 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
667 Elf ## B ## _Off offset; \ 948 Elf ## B ## _Off offset; \
949 size_t matched = 0; \
950 /* Walk all the program headers to find the PT_DYNAMIC */ \
668 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 951 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
669 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 952 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
953 continue; \
670 offset = EGET(phdr[i].p_offset); \ 954 offset = EGET(phdr[i].p_offset); \
671 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 955 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
956 continue; \
957 /* Walk all the dynamic tags to find NEEDED entries */ \
672 dyn = DYN ## B (elf->data + offset); \ 958 dyn = DYN ## B (elf->vdata + offset); \
673 while (EGET(dyn->d_tag) != DT_NULL) { \ 959 while (EGET(dyn->d_tag) != DT_NULL) { \
674 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 960 if (EGET(dyn->d_tag) == DT_NEEDED) { \
675 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 961 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
676 if (offset >= (Elf ## B ## _Off)elf->len) { \ 962 if (offset >= (Elf ## B ## _Off)elf->len) { \
677 ++dyn; \ 963 ++dyn; \
678 continue; \ 964 continue; \
679 } \ 965 } \
680 needed = (char*)(elf->data + offset); \ 966 needed = elf->data + offset; \
681 if (op == 0) { \ 967 if (op == 0) { \
968 /* -n -> print all entries */ \
682 if (!be_wewy_wewy_quiet) { \ 969 if (!be_wewy_wewy_quiet) { \
683 if (*found_needed) xchrcat(ret, ',', ret_len); \ 970 if (*found_needed) xchrcat(ret, ',', ret_len); \
684 if (use_ldcache) \ 971 if (use_ldpath) { \
972 if ((p = lookup_config_lib(needed)) != NULL) \
973 needed = p; \
974 } else if (use_ldcache) { \
685 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 975 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
686 needed = p; \ 976 needed = p; \
977 } \
687 xstrcat(ret, needed, ret_len); \ 978 xstrcat(ret, needed, ret_len); \
688 } \ 979 } \
689 *found_needed = 1; \ 980 *found_needed = 1; \
690 } else { \ 981 } else { \
691 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 982 /* -N -> print matching entries */ \
983 size_t n; \
984 const char *find_lib_name; \
985 \
986 array_for_each(find_lib_arr, n, find_lib_name) { \
987 int invert = 1; \
988 if (find_lib_name[0] == '!') \
989 invert = 0, ++find_lib_name; \
990 if (!strcmp(find_lib_name, needed) == invert) \
991 ++matched; \
992 } \
993 \
994 if (matched == array_cnt(find_lib_arr)) { \
692 *found_lib = 1; \ 995 *found_lib = 1; \
693 return (be_wewy_wewy_quiet ? NULL : needed); \ 996 return (be_wewy_wewy_quiet ? NULL : find_lib); \
694 } \ 997 } \
695 } \ 998 } \
696 } \ 999 } \
697 ++dyn; \ 1000 ++dyn; \
698 } \ 1001 } \
720 *found_interp = 1; \ 1023 *found_interp = 1; \
721 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1024 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
722 } 1025 }
723 SHOW_INTERP(32) 1026 SHOW_INTERP(32)
724 SHOW_INTERP(64) 1027 SHOW_INTERP(64)
1028 } else {
1029 /* Walk all the program headers to find the PT_INTERP */
1030#define SHOW_PT_INTERP(B) \
1031 if (elf->elf_class == ELFCLASS ## B) { \
1032 unsigned long i; \
1033 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1034 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1035 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1036 if (EGET(phdr[i].p_type) != PT_INTERP) \
1037 continue; \
1038 *found_interp = 1; \
1039 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1040 } \
725 } 1041 }
1042 SHOW_PT_INTERP(32)
1043 SHOW_PT_INTERP(64)
1044 }
1045
726 return NULL; 1046 return NULL;
727} 1047}
728static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1048static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
729{ 1049{
730 unsigned long i; 1050 unsigned long i;
731 struct stat s; 1051 struct stat s;
1052 bool dynamic = false;
732 1053
733 if (!show_bind) return NULL; 1054 if (!show_bind) return NULL;
734 if (!elf->phdr) return NULL; 1055 if (!elf->phdr) return NULL;
735 1056
736#define SHOW_BIND(B) \ 1057#define SHOW_BIND(B) \
738 Elf ## B ## _Dyn *dyn; \ 1059 Elf ## B ## _Dyn *dyn; \
739 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1060 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
740 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1061 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
741 Elf ## B ## _Off offset; \ 1062 Elf ## B ## _Off offset; \
742 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1063 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
743 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1064 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1065 dynamic = true; \
744 offset = EGET(phdr[i].p_offset); \ 1066 offset = EGET(phdr[i].p_offset); \
745 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1067 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
746 dyn = DYN ## B (elf->data + offset); \ 1068 dyn = DYN ## B (elf->vdata + offset); \
747 while (EGET(dyn->d_tag) != DT_NULL) { \ 1069 while (EGET(dyn->d_tag) != DT_NULL) { \
748 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1070 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
749 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1071 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
750 { \ 1072 { \
751 if (be_quiet) return NULL; \ 1073 if (be_quiet) return NULL; \
759 SHOW_BIND(32) 1081 SHOW_BIND(32)
760 SHOW_BIND(64) 1082 SHOW_BIND(64)
761 1083
762 if (be_wewy_wewy_quiet) return NULL; 1084 if (be_wewy_wewy_quiet) return NULL;
763 1085
1086 /* don't output anything if quiet mode and the ELF is static or not setuid */
764 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1087 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
765 return NULL; 1088 return NULL;
766 } else { 1089 } else {
767 *found_bind = 1; 1090 *found_bind = 1;
768 return (char *) "LAZY"; 1091 return dynamic ? "LAZY" : "STATIC";
769 } 1092 }
770} 1093}
771static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1094static char *scanelf_file_soname(elfobj *elf, char *found_soname)
772{ 1095{
773 unsigned long i; 1096 unsigned long i;
785 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1108 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
786 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1109 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
787 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1110 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
788 Elf ## B ## _Off offset; \ 1111 Elf ## B ## _Off offset; \
789 /* only look for soname in shared objects */ \ 1112 /* only look for soname in shared objects */ \
790 if (ehdr->e_type != ET_DYN) \ 1113 if (EGET(ehdr->e_type) != ET_DYN) \
791 return NULL; \ 1114 return NULL; \
792 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1115 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
793 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1116 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
794 offset = EGET(phdr[i].p_offset); \ 1117 offset = EGET(phdr[i].p_offset); \
795 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1118 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
796 dyn = DYN ## B (elf->data + offset); \ 1119 dyn = DYN ## B (elf->vdata + offset); \
797 while (EGET(dyn->d_tag) != DT_NULL) { \ 1120 while (EGET(dyn->d_tag) != DT_NULL) { \
798 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1121 if (EGET(dyn->d_tag) == DT_SONAME) { \
799 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1122 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
800 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1123 if (offset >= (Elf ## B ## _Off)elf->len) { \
801 ++dyn; \ 1124 ++dyn; \
802 continue; \ 1125 continue; \
803 } \ 1126 } \
804 soname = (char*)(elf->data + offset); \ 1127 soname = elf->data + offset; \
805 *found_soname = 1; \ 1128 *found_soname = 1; \
806 return (be_wewy_wewy_quiet ? NULL : soname); \ 1129 return (be_wewy_wewy_quiet ? NULL : soname); \
807 } \ 1130 } \
808 ++dyn; \ 1131 ++dyn; \
809 } \ 1132 } \
812 SHOW_SONAME(64) 1135 SHOW_SONAME(64)
813 } 1136 }
814 1137
815 return NULL; 1138 return NULL;
816} 1139}
1140
1141/*
1142 * We support the symbol form:
1143 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1144 * If the symbol name is empty, then all symbols are matched.
1145 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1146 * Do not rely on this output format at all.
1147 * Otherwise the symbol name is used to search (either regex or string compare).
1148 * If the first char of the symbol name is a plus ("+"), then only match
1149 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1150 * Putting modifiers in between the percent signs allows for more in depth
1151 * filters. There are groups of modifiers. If you don't specify a member
1152 * of a group, then all types in that group are matched. The current
1153 * groups and their types are:
1154 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1155 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1156 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1157 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1158 * You can search for multiple symbols at once by seperating with a comma (",").
1159 *
1160 * Some examples:
1161 * ELFs with a weak function "foo":
1162 * scanelf -s %wf%foo <ELFs>
1163 * ELFs that define the symbol "main":
1164 * scanelf -s +main <ELFs>
1165 * scanelf -s %d%main <ELFs>
1166 * ELFs that refer to the undefined symbol "brk":
1167 * scanelf -s -brk <ELFs>
1168 * scanelf -s %u%brk <ELFs>
1169 * All global defined objects in an ELF:
1170 * scanelf -s %ogd% <ELF>
1171 */
1172static void
1173scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1174 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1175{
1176 const char *this_sym;
1177 size_t n;
1178
1179 array_for_each(find_sym_arr, n, this_sym) {
1180 bool inc_notype, inc_object, inc_func, inc_file,
1181 inc_local, inc_global, inc_weak,
1182 inc_def, inc_undef, inc_abs, inc_common;
1183
1184 /* symbol selection! */
1185 inc_notype = inc_object = inc_func = inc_file = \
1186 inc_local = inc_global = inc_weak = \
1187 inc_def = inc_undef = inc_abs = inc_common = \
1188 (*this_sym != '%');
1189
1190 /* parse the contents of %...% */
1191 if (!inc_notype) {
1192 while (*(this_sym++)) {
1193 if (*this_sym == '%') {
1194 ++this_sym;
1195 break;
1196 }
1197 switch (*this_sym) {
1198 case 'n': inc_notype = true; break;
1199 case 'o': inc_object = true; break;
1200 case 'f': inc_func = true; break;
1201 case 'F': inc_file = true; break;
1202 case 'l': inc_local = true; break;
1203 case 'g': inc_global = true; break;
1204 case 'w': inc_weak = true; break;
1205 case 'd': inc_def = true; break;
1206 case 'u': inc_undef = true; break;
1207 case 'a': inc_abs = true; break;
1208 case 'c': inc_common = true; break;
1209 default: err("invalid symbol selector '%c'", *this_sym);
1210 }
1211 }
1212
1213 /* If no types are matched, not match all */
1214 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1215 inc_notype = inc_object = inc_func = inc_file = true;
1216 if (!inc_local && !inc_global && !inc_weak)
1217 inc_local = inc_global = inc_weak = true;
1218 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1219 inc_def = inc_undef = inc_abs = inc_common = true;
1220
1221 /* backwards compat for defined/undefined short hand */
1222 } else if (*this_sym == '+') {
1223 inc_undef = false;
1224 ++this_sym;
1225 } else if (*this_sym == '-') {
1226 inc_def = inc_abs = inc_common = false;
1227 ++this_sym;
1228 }
1229
1230 /* filter symbols */
1231 if ((!inc_notype && stt == STT_NOTYPE) || \
1232 (!inc_object && stt == STT_OBJECT) || \
1233 (!inc_func && stt == STT_FUNC ) || \
1234 (!inc_file && stt == STT_FILE ) || \
1235 (!inc_local && stb == STB_LOCAL ) || \
1236 (!inc_global && stb == STB_GLOBAL) || \
1237 (!inc_weak && stb == STB_WEAK ) || \
1238 (!inc_def && shn && shn < SHN_LORESERVE) || \
1239 (!inc_undef && shn == SHN_UNDEF ) || \
1240 (!inc_abs && shn == SHN_ABS ) || \
1241 (!inc_common && shn == SHN_COMMON))
1242 continue;
1243
1244 if (*this_sym == '*') {
1245 /* a "*" symbol gets you debug output */
1246 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1247 ((*found_sym == 0) ? "\n\t" : "\t"),
1248 elf->base_filename,
1249 size,
1250 get_elfstttype(stt),
1251 get_elfstbtype(stb),
1252 get_elfshntype(shn),
1253 symname);
1254 goto matched;
1255
1256 } else {
1257 if (g_match) {
1258 /* regex match the symbol */
1259 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1260 continue;
1261
1262 } else if (*this_sym) {
1263 /* give empty symbols a "pass", else do a normal compare */
1264 const size_t len = strlen(this_sym);
1265 if (!(strncmp(this_sym, symname, len) == 0 &&
1266 /* Accept unversioned symbol names */
1267 (symname[len] == '\0' || symname[len] == '@')))
1268 continue;
1269 }
1270
1271 if (be_semi_verbose) {
1272 char buf[1024];
1273 snprintf(buf, sizeof(buf), "%lX %s %s",
1274 size,
1275 get_elfstttype(stt),
1276 this_sym);
1277 *ret = xstrdup(buf);
1278 } else {
1279 if (*ret) xchrcat(ret, ',', ret_len);
1280 xstrcat(ret, symname, ret_len);
1281 }
1282
1283 goto matched;
1284 }
1285 }
1286
1287 return;
1288
1289 matched:
1290 *found_sym = 1;
1291}
1292
817static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1293static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
818{ 1294{
819 unsigned long i;
820 char *ret; 1295 char *ret;
821 void *symtab_void, *strtab_void; 1296 void *symtab_void, *strtab_void;
822 1297
823 if (!find_sym) return NULL; 1298 if (!find_sym) return NULL;
824 ret = find_sym; 1299 ret = NULL;
825 1300
826 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1301 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
827 1302
828 if (symtab_void && strtab_void) { 1303 if (symtab_void && strtab_void) {
829#define FIND_SYM(B) \ 1304#define FIND_SYM(B) \
830 if (elf->elf_class == ELFCLASS ## B) { \ 1305 if (elf->elf_class == ELFCLASS ## B) { \
831 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1306 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
832 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1307 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
833 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1308 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
834 unsigned long cnt = EGET(symtab->sh_entsize); \ 1309 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
835 char *symname; \ 1310 char *symname; \
1311 size_t ret_len = 0; \
836 if (cnt) \ 1312 if (cnt) \
837 cnt = EGET(symtab->sh_size) / cnt; \ 1313 cnt = EGET(symtab->sh_size) / cnt; \
838 for (i = 0; i < cnt; ++i) { \ 1314 for (i = 0; i < cnt; ++i) { \
1315 if ((void*)sym > elf->data_end) { \
1316 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1317 goto break_out; \
1318 } \
839 if (sym->st_name) { \ 1319 if (sym->st_name) { \
1320 /* make sure the symbol name is in acceptable memory range */ \
840 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1321 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
841 if ((void*)symname > (void*)elf->data_end) { \ 1322 if ((void*)symname > elf->data_end) { \
842 warnf("%s: corrupt ELF symbols", elf->filename); \ 1323 warnf("%s: corrupt ELF symbols", elf->filename); \
1324 ++sym; \
843 continue; \ 1325 continue; \
844 } \ 1326 } \
845 if (*find_sym == '*') { \ 1327 scanelf_match_symname(elf, found_sym, \
846 printf("%s(%s) %5lX %15s %s\n", \ 1328 &ret, &ret_len, symname, \
847 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1329 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
848 elf->base_filename, \ 1330 ELF##B##_ST_BIND(EGET(sym->st_info)), \
849 (unsigned long)sym->st_size, \ 1331 EGET(sym->st_shndx), \
850 get_elfstttype(sym->st_info), \ 1332 /* st_size can be 64bit, but no one is really that big, so screw em */ \
851 symname); \ 1333 EGET(sym->st_size)); \
852 *found_sym = 1; \
853 } else { \
854 char *this_sym, *next_sym; \
855 this_sym = find_sym; \
856 do { \
857 next_sym = strchr(this_sym, ','); \
858 if (next_sym == NULL) \
859 next_sym = this_sym + strlen(this_sym); \
860 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
861 (strcmp(symname, versioned_symname) == 0)) { \
862 ret = this_sym; \
863 (*found_sym)++; \
864 goto break_out; \
865 } \
866 this_sym = next_sym + 1; \
867 } while (*next_sym != '\0'); \
868 } \
869 } \ 1334 } \
870 ++sym; \ 1335 ++sym; \
871 } } 1336 } \
1337 }
872 FIND_SYM(32) 1338 FIND_SYM(32)
873 FIND_SYM(64) 1339 FIND_SYM(64)
874 } 1340 }
875 1341
876break_out: 1342break_out:
879 if (*find_sym != '*' && *found_sym) 1345 if (*find_sym != '*' && *found_sym)
880 return ret; 1346 return ret;
881 if (be_quiet) 1347 if (be_quiet)
882 return NULL; 1348 return NULL;
883 else 1349 else
884 return (char *)" - "; 1350 return " - ";
885} 1351}
886 1352
887
888static char *scanelf_file_sections(elfobj *elf, char *found_section) 1353static const char *scanelf_file_sections(elfobj *elf, char *found_section)
889{ 1354{
890 if (!find_section) 1355 if (!find_section)
891 return NULL; 1356 return NULL;
892 1357
893#define FIND_SECTION(B) \ 1358#define FIND_SECTION(B) \
894 if (elf->elf_class == ELFCLASS ## B) { \ 1359 if (elf->elf_class == ELFCLASS ## B) { \
1360 size_t matched, n; \
1361 int invert; \
1362 const char *section_name; \
895 Elf ## B ## _Shdr *section; \ 1363 Elf ## B ## _Shdr *section; \
1364 \
1365 matched = 0; \
1366 array_for_each(find_section_arr, n, section_name) { \
1367 invert = (*section_name == '!' ? 1 : 0); \
896 section = SHDR ## B (elf_findsecbyname(elf, find_section)); \ 1368 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
897 if (section != NULL) \ 1369 if ((section == NULL && invert) || (section != NULL && !invert)) \
1370 ++matched; \
1371 } \
1372 \
1373 if (matched == array_cnt(find_section_arr)) \
898 *found_section = 1; \ 1374 *found_section = 1; \
899 } 1375 }
900 FIND_SECTION(32) 1376 FIND_SECTION(32)
901 FIND_SECTION(64) 1377 FIND_SECTION(64)
902 1378
903
904 if (be_wewy_wewy_quiet) return NULL; 1379 if (be_wewy_wewy_quiet)
1380 return NULL;
905 1381
906 if (*found_section) 1382 if (*found_section)
907 return find_section; 1383 return find_section;
908 1384
909 if (be_quiet) 1385 if (be_quiet)
910 return NULL; 1386 return NULL;
911 else 1387 else
912 return (char *)" - "; 1388 return " - ";
913} 1389}
914 1390
915/* scan an elf file and show all the fun stuff */ 1391/* scan an elf file and show all the fun stuff */
916#define prints(str) write(fileno(stdout), str, strlen(str)) 1392#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
917static int scanelf_elfobj(elfobj *elf) 1393static int scanelf_elfobj(elfobj *elf)
918{ 1394{
919 unsigned long i; 1395 unsigned long i;
920 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1396 char found_pax, found_phdr, found_relro, found_load, found_textrel,
921 found_rpath, found_needed, found_interp, found_bind, found_soname, 1397 found_rpath, found_needed, found_interp, found_bind, found_soname,
922 found_sym, found_lib, found_file, found_textrels, found_section; 1398 found_sym, found_lib, found_file, found_textrels, found_section;
923 static char *out_buffer = NULL; 1399 static char *out_buffer = NULL;
924 static size_t out_len; 1400 static size_t out_len;
925 1401
926 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1402 found_pax = found_phdr = found_relro = found_load = found_textrel = \
935 printf("%s: scanning file\n", elf->filename); 1411 printf("%s: scanning file\n", elf->filename);
936 1412
937 /* init output buffer */ 1413 /* init output buffer */
938 if (!out_buffer) { 1414 if (!out_buffer) {
939 out_len = sizeof(char) * 80; 1415 out_len = sizeof(char) * 80;
940 out_buffer = (char*)xmalloc(out_len); 1416 out_buffer = xmalloc(out_len);
941 } 1417 }
942 *out_buffer = '\0'; 1418 *out_buffer = '\0';
943 1419
944 /* show the header */ 1420 /* show the header */
945 if (!be_quiet && show_banner) { 1421 if (!be_quiet && show_banner) {
946 for (i = 0; out_format[i]; ++i) { 1422 for (i = 0; out_format[i]; ++i) {
947 if (!IS_MODIFIER(out_format[i])) continue; 1423 if (!IS_MODIFIER(out_format[i])) continue;
948 1424
949 switch (out_format[++i]) { 1425 switch (out_format[++i]) {
1426 case '+': break;
950 case '%': break; 1427 case '%': break;
951 case '#': break; 1428 case '#': break;
952 case 'F': 1429 case 'F':
953 case 'p': 1430 case 'p':
954 case 'f': prints("FILE "); found_file = 1; break; 1431 case 'f': prints("FILE "); found_file = 1; break;
955 case 'o': prints(" TYPE "); break; 1432 case 'o': prints(" TYPE "); break;
956 case 'x': prints(" PAX "); break; 1433 case 'x': prints(" PAX "); break;
957 case 'e': prints("STK/REL/PTL "); break; 1434 case 'e': prints("STK/REL/PTL "); break;
958 case 't': prints("TEXTREL "); break; 1435 case 't': prints("TEXTREL "); break;
959 case 'r': prints("RPATH "); break; 1436 case 'r': prints("RPATH "); break;
1437 case 'M': prints("CLASS "); break;
1438 case 'l':
960 case 'n': prints("NEEDED "); break; 1439 case 'n': prints("NEEDED "); break;
961 case 'i': prints("INTERP "); break; 1440 case 'i': prints("INTERP "); break;
962 case 'b': prints("BIND "); break; 1441 case 'b': prints("BIND "); break;
1442 case 'Z': prints("SIZE "); break;
963 case 'S': prints("SONAME "); break; 1443 case 'S': prints("SONAME "); break;
964 case 's': prints("SYM "); break; 1444 case 's': prints("SYM "); break;
965 case 'N': prints("LIB "); break; 1445 case 'N': prints("LIB "); break;
966 case 'T': prints("TEXTRELS "); break; 1446 case 'T': prints("TEXTRELS "); break;
967 case 'k': prints("SECTION "); break; 1447 case 'k': prints("SECTION "); break;
1448 case 'a': prints("ARCH "); break;
1449 case 'I': prints("OSABI "); break;
1450 case 'Y': prints("EABI "); break;
1451 case 'O': prints("PERM "); break;
1452 case 'D': prints("ENDIAN "); break;
968 default: warnf("'%c' has no title ?", out_format[i]); 1453 default: warnf("'%c' has no title ?", out_format[i]);
969 } 1454 }
970 } 1455 }
971 if (!found_file) prints("FILE "); 1456 if (!found_file) prints("FILE ");
972 prints("\n"); 1457 prints("\n");
976 1461
977 /* dump all the good stuff */ 1462 /* dump all the good stuff */
978 for (i = 0; out_format[i]; ++i) { 1463 for (i = 0; out_format[i]; ++i) {
979 const char *out; 1464 const char *out;
980 const char *tmp; 1465 const char *tmp;
981 1466 static char ubuf[sizeof(unsigned long)*2];
982 if (!IS_MODIFIER(out_format[i])) { 1467 if (!IS_MODIFIER(out_format[i])) {
983 xchrcat(&out_buffer, out_format[i], &out_len); 1468 xchrcat(&out_buffer, out_format[i], &out_len);
984 continue; 1469 continue;
985 } 1470 }
986 1471
987 out = NULL; 1472 out = NULL;
988 be_wewy_wewy_quiet = (out_format[i] == '#'); 1473 be_wewy_wewy_quiet = (out_format[i] == '#');
1474 be_semi_verbose = (out_format[i] == '+');
989 switch (out_format[++i]) { 1475 switch (out_format[++i]) {
1476 case '+':
990 case '%': 1477 case '%':
991 case '#': 1478 case '#':
992 xchrcat(&out_buffer, out_format[i], &out_len); break; 1479 xchrcat(&out_buffer, out_format[i], &out_len); break;
993 case 'F': 1480 case 'F':
994 found_file = 1; 1481 found_file = 1;
1020 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1507 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1021 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1508 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1022 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1509 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1023 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1510 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1024 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1511 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1512 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1513 case 'D': out = get_endian(elf); break;
1514 case 'O': out = strfileperms(elf->filename); break;
1025 case 'n': 1515 case 'n':
1026 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1516 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1027 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1517 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1028 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1518 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1029 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1519 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1030 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1520 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1031 case 'k': out = scanelf_file_sections(elf, &found_section); break; 1521 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1522 case 'a': out = get_elfemtype(elf); break;
1523 case 'I': out = get_elfosabi(elf); break;
1524 case 'Y': out = get_elf_eabi(elf); break;
1525 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
1032 default: warnf("'%c' has no scan code?", out_format[i]); 1526 default: warnf("'%c' has no scan code?", out_format[i]);
1033 } 1527 }
1034 if (out) { 1528 if (out)
1035 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
1036 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
1037 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1038 else
1039 xstrcat(&out_buffer, out, &out_len); 1529 xstrcat(&out_buffer, out, &out_len);
1040 }
1041 } 1530 }
1042 1531
1043#define FOUND_SOMETHING() \ 1532#define FOUND_SOMETHING() \
1044 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1533 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1045 found_rpath || found_needed || found_interp || found_bind || \ 1534 found_rpath || found_needed || found_interp || found_bind || \
1059 1548
1060/* scan a single elf */ 1549/* scan a single elf */
1061static int scanelf_elf(const char *filename, int fd, size_t len) 1550static int scanelf_elf(const char *filename, int fd, size_t len)
1062{ 1551{
1063 int ret = 1; 1552 int ret = 1;
1553 size_t n;
1554 const char *match_etype;
1064 elfobj *elf; 1555 elfobj *elf;
1065 1556
1066 /* verify this is real ELF */ 1557 /* Verify this is a real ELF */
1067 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) { 1558 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1068 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 1559 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1069 return ret; 1560 return 2;
1070 } 1561 }
1562
1563 /* Possibly filter based on ELF bitness */
1071 switch (match_bits) { 1564 switch (match_bits) {
1072 case 32: 1565 case 32:
1073 if (elf->elf_class != ELFCLASS32) 1566 if (elf->elf_class != ELFCLASS32)
1074 goto label_done; 1567 goto done;
1075 break; 1568 break;
1076 case 64: 1569 case 64:
1077 if (elf->elf_class != ELFCLASS64) 1570 if (elf->elf_class != ELFCLASS64)
1078 goto label_done; 1571 goto done;
1079 break; 1572 break;
1080 default: break;
1081 }
1082 if (strlen(match_etypes)) {
1083 char sbuf[126];
1084 strncpy(sbuf, match_etypes, sizeof(sbuf));
1085 if (strchr(match_etypes, ',') != NULL) {
1086 char *p;
1087 while((p = strrchr(sbuf, ',')) != NULL) {
1088 *p = 0;
1089 if (atoi(p+1) == get_etype(elf))
1090 goto label_ret;
1091 }
1092 } 1573 }
1093 if (atoi(sbuf) != get_etype(elf)) 1574
1575 /* Possibly filter based on the ELF's e_type field */
1576 array_for_each(match_etypes, n, match_etype)
1577 if (etype_lookup(match_etype) == get_etype(elf))
1578 goto scanit;
1579 if (array_cnt(match_etypes))
1094 goto label_done; 1580 goto done;
1095 }
1096 1581
1097label_ret: 1582 scanit:
1098 ret = scanelf_elfobj(elf); 1583 ret = scanelf_elfobj(elf);
1099 1584
1100label_done: 1585 done:
1101 unreadelf(elf); 1586 unreadelf(elf);
1102 return ret; 1587 return ret;
1103} 1588}
1104 1589
1105/* scan an archive of elfs */ 1590/* scan an archive of elfs */
1112 1597
1113 ar = ar_open_fd(filename, fd); 1598 ar = ar_open_fd(filename, fd);
1114 if (ar == NULL) 1599 if (ar == NULL)
1115 return 1; 1600 return 1;
1116 1601
1117 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0); 1602 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1118 while ((m=ar_next(ar)) != NULL) { 1603 while ((m = ar_next(ar)) != NULL) {
1604 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1605 if (cur_pos == -1)
1606 errp("lseek() failed");
1119 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size); 1607 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1120 if (elf) { 1608 if (elf) {
1121 scanelf_elfobj(elf); 1609 scanelf_elfobj(elf);
1122 unreadelf(elf); 1610 unreadelf(elf);
1123 } 1611 }
1124 } 1612 }
1125 munmap(ar_buffer, len); 1613 munmap(ar_buffer, len);
1126 1614
1127 return 0; 1615 return 0;
1128} 1616}
1129/* scan a file which may be an elf or an archive or some other magical beast */ 1617/* scan a file which may be an elf or an archive or some other magical beast */
1130static void scanelf_file(const char *filename) 1618static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1131{ 1619{
1620 const struct stat *st = st_cache;
1132 struct stat st; 1621 struct stat symlink_st;
1133 int fd; 1622 int fd;
1134 1623
1135 /* make sure 'filename' exists */
1136 if (lstat(filename, &st) == -1) {
1137 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1138 return;
1139 }
1140
1141 /* always handle regular files and handle symlinked files if no -y */ 1624 /* always handle regular files and handle symlinked files if no -y */
1142 if (S_ISLNK(st.st_mode)) { 1625 if (S_ISLNK(st->st_mode)) {
1143 if (!scan_symlink) return; 1626 if (!scan_symlink)
1144 stat(filename, &st); 1627 return 1;
1628 fstatat(dir_fd, filename, &symlink_st, 0);
1629 st = &symlink_st;
1145 } 1630 }
1631
1146 if (!S_ISREG(st.st_mode)) { 1632 if (!S_ISREG(st->st_mode)) {
1147 if (be_verbose > 2) printf("%s: skipping non-file\n", filename); 1633 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1148 return; 1634 return 1;
1149 } 1635 }
1150 1636
1151 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1) 1637 if (match_perms) {
1638 if ((st->st_mode | match_perms) != st->st_mode)
1639 return 1;
1640 }
1641 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1642 if (fd == -1) {
1643 if (fix_elf && errno == ETXTBSY)
1644 warnp("%s: could not fix", filename);
1645 else if (be_verbose > 2)
1646 printf("%s: skipping file: %s\n", filename, strerror(errno));
1152 return; 1647 return 1;
1648 }
1153 1649
1154 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives) 1650 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1155 /* if it isn't an ELF, maybe it's an .a archive */ 1651 /* if it isn't an ELF, maybe it's an .a archive */
1652 if (scan_archives)
1156 scanelf_archive(filename, fd, st.st_size); 1653 scanelf_archive(filename, fd, st->st_size);
1157 1654
1655 /*
1656 * unreadelf() implicitly closes its fd, so only close it
1657 * when we are returning it in the non-ELF case
1658 */
1158 close(fd); 1659 close(fd);
1660 }
1661
1662 return 0;
1159} 1663}
1160 1664
1161/* scan a directory for ET_EXEC files and print when we find one */ 1665/* scan a directory for ET_EXEC files and print when we find one */
1162static void scanelf_dir(const char *path) 1666static int scanelf_dirat(int dir_fd, const char *path)
1163{ 1667{
1164 register DIR *dir; 1668 register DIR *dir;
1165 register struct dirent *dentry; 1669 register struct dirent *dentry;
1166 struct stat st_top, st; 1670 struct stat st_top, st;
1167 char buf[__PAX_UTILS_PATH_MAX]; 1671 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1168 size_t pathlen = 0, len = 0; 1672 size_t pathlen = 0, len = 0;
1673 int ret = 0;
1674 int subdir_fd;
1169 1675
1170 /* make sure path exists */ 1676 /* make sure path exists */
1171 if (lstat(path, &st_top) == -1) { 1677 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1172 if (be_verbose > 2) printf("%s: does not exist\n", path); 1678 if (be_verbose > 2) printf("%s: does not exist\n", path);
1173 return; 1679 return 1;
1174 } 1680 }
1175 1681
1176 /* ok, if it isn't a directory, assume we can open it */ 1682 /* ok, if it isn't a directory, assume we can open it */
1177 if (!S_ISDIR(st_top.st_mode)) { 1683 if (!S_ISDIR(st_top.st_mode))
1178 scanelf_file(path); 1684 return scanelf_fileat(dir_fd, path, &st_top);
1179 return;
1180 }
1181 1685
1182 /* now scan the dir looking for fun stuff */ 1686 /* now scan the dir looking for fun stuff */
1183 if ((dir = opendir(path)) == NULL) { 1687 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1184 warnf("could not opendir %s: %s", path, strerror(errno)); 1688 if (subdir_fd == -1)
1689 dir = NULL;
1690 else
1691 dir = fdopendir(subdir_fd);
1692 if (dir == NULL) {
1693 if (subdir_fd != -1)
1694 close(subdir_fd);
1695 else if (be_verbose > 2)
1696 printf("%s: skipping dir: %s\n", path, strerror(errno));
1185 return; 1697 return 1;
1186 } 1698 }
1187 if (be_verbose > 1) printf("%s: scanning dir\n", path); 1699 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1188 1700
1189 pathlen = strlen(path); 1701 subpath = stpcpy(buf, path);
1702 if (subpath[-1] != '/')
1703 *subpath++ = '/';
1704 pathlen = subpath - buf;
1190 while ((dentry = readdir(dir))) { 1705 while ((dentry = readdir(dir))) {
1191 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1706 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1192 continue; 1707 continue;
1708
1709 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1710 continue;
1711
1193 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1712 len = strlen(dentry->d_name);
1194 if (len >= sizeof(buf)) { 1713 if (len + pathlen + 1 >= sizeof(buf)) {
1195 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1714 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1196 (unsigned long)len, (unsigned long)sizeof(buf)); 1715 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1197 continue; 1716 continue;
1198 } 1717 }
1199 sprintf(buf, "%s/%s", path, dentry->d_name); 1718 memcpy(subpath, dentry->d_name, len);
1200 if (lstat(buf, &st) != -1) { 1719 subpath[len] = '\0';
1720
1201 if (S_ISREG(st.st_mode)) 1721 if (S_ISREG(st.st_mode))
1202 scanelf_file(buf); 1722 ret = scanelf_fileat(dir_fd, buf, &st);
1203 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1723 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1204 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1724 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1205 scanelf_dir(buf); 1725 ret = scanelf_dirat(dir_fd, buf);
1206 }
1207 } 1726 }
1208 } 1727 }
1209 closedir(dir); 1728 closedir(dir);
1210}
1211 1729
1730 return ret;
1731}
1732static int scanelf_dir(const char *path)
1733{
1734 return scanelf_dirat(root_fd, root_rel_path(path));
1735}
1736
1212static int scanelf_from_file(char *filename) 1737static int scanelf_from_file(const char *filename)
1213{ 1738{
1214 FILE *fp = NULL; 1739 FILE *fp;
1215 char *p; 1740 char *p, *path;
1216 char path[__PAX_UTILS_PATH_MAX]; 1741 size_t len;
1742 int ret;
1217 1743
1218 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1744 if (strcmp(filename, "-") == 0)
1219 fp = stdin; 1745 fp = stdin;
1220 else if ((fp = fopen(filename, "r")) == NULL) 1746 else if ((fp = fopen(filename, "r")) == NULL)
1221 return 1; 1747 return 1;
1222 1748
1223 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1749 path = NULL;
1750 len = 0;
1751 ret = 0;
1752 while (getline(&path, &len, fp) != -1) {
1224 if ((p = strchr(path, '\n')) != NULL) 1753 if ((p = strchr(path, '\n')) != NULL)
1225 *p = 0; 1754 *p = 0;
1226 search_path = path; 1755 search_path = path;
1227 scanelf_dir(path); 1756 ret = scanelf_dir(path);
1228 } 1757 }
1758 free(path);
1759
1229 if (fp != stdin) 1760 if (fp != stdin)
1230 fclose(fp); 1761 fclose(fp);
1762
1231 return 0; 1763 return ret;
1232} 1764}
1233 1765
1766#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1767
1234static int load_ld_so_conf(int i, const char *fname) 1768static int _load_ld_cache_config(const char *fname)
1235{ 1769{
1236 FILE *fp = NULL; 1770 FILE *fp = NULL;
1237 char *p; 1771 char *p, *path;
1238 char path[__PAX_UTILS_PATH_MAX]; 1772 size_t len;
1773 int curr_fd = -1;
1239 1774
1240 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1775 fp = fopenat_r(root_fd, root_rel_path(fname));
1776 if (fp == NULL)
1241 return i; 1777 return -1;
1242 1778
1243 if ((fp = fopen(fname, "r")) == NULL) 1779 path = NULL;
1244 return i; 1780 len = 0;
1245 1781 while (getline(&path, &len, fp) != -1) {
1246 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1247 if ((p = strrchr(path, '\r')) != NULL) 1782 if ((p = strrchr(path, '\r')) != NULL)
1248 *p = 0; 1783 *p = 0;
1249 if ((p = strchr(path, '\n')) != NULL) 1784 if ((p = strchr(path, '\n')) != NULL)
1250 *p = 0; 1785 *p = 0;
1251#ifdef HAVE_GLOB 1786
1252 // recursive includes of the same file will make this segfault. 1787 /* recursive includes of the same file will make this segfault. */
1253 if ((*path == 'i') && (strncmp(path, "include", 7) == 0) && isblank(path[7])) { 1788 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1254 glob64_t gl; 1789 glob_t gl;
1255 size_t x; 1790 size_t x;
1256 char gpath[__PAX_UTILS_PATH_MAX]; 1791 const char *gpath;
1257 1792
1258 gpath[sizeof(gpath)] = 0; 1793 /* re-use existing path buffer ... need to be creative */
1259
1260 if (path[8] != '/') 1794 if (path[8] != '/')
1261 snprintf(gpath, sizeof(gpath)-1, "/etc/%s", &path[8]); 1795 gpath = memcpy(path + 3, "/etc/", 5);
1262 else 1796 else
1263 strncpy(gpath, &path[8], sizeof(gpath)-1); 1797 gpath = path + 8;
1798 if (root_fd != AT_FDCWD) {
1799 if (curr_fd == -1) {
1800 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1801 if (fchdir(root_fd))
1802 errp("unable to change to root dir");
1803 }
1804 gpath = root_rel_path(gpath);
1805 }
1264 1806
1265 if ((glob64(gpath, 0, NULL, &gl)) == 0) { 1807 if (glob(gpath, 0, NULL, &gl) == 0) {
1266 for (x = 0; x < gl.gl_pathc; ++x) { 1808 for (x = 0; x < gl.gl_pathc; ++x) {
1267 /* try to avoid direct loops */ 1809 /* try to avoid direct loops */
1268 if (strcmp(gl.gl_pathv[x], fname) == 0) 1810 if (strcmp(gl.gl_pathv[x], fname) == 0)
1269 continue; 1811 continue;
1270 i = load_ld_so_conf(i, gl.gl_pathv[x]); 1812 _load_ld_cache_config(gl.gl_pathv[x]);
1271 if (i + 1 >= sizeof(ldpaths) / sizeof(*ldpaths)) {
1272 globfree64(&gl);
1273 return i;
1274 }
1275 } 1813 }
1276 globfree64 (&gl); 1814 globfree(&gl);
1815 }
1816
1817 /* failed globs are ignored by glibc */
1277 continue; 1818 continue;
1278 } else
1279 abort();
1280 } 1819 }
1281#endif 1820
1282 if (*path != '/') 1821 if (*path != '/')
1283 continue; 1822 continue;
1284 1823
1285 ldpaths[i++] = xstrdup(path); 1824 xarraypush_str(ldpaths, path);
1286
1287 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1288 break;
1289 } 1825 }
1290 ldpaths[i] = NULL; 1826 free(path);
1291 1827
1292 fclose(fp); 1828 fclose(fp);
1829
1830 if (curr_fd != -1) {
1831 if (fchdir(curr_fd))
1832 {/* don't care */}
1833 close(curr_fd);
1834 }
1835
1293 return i; 1836 return 0;
1837}
1838
1839#elif defined(__FreeBSD__) || defined(__DragonFly__)
1840
1841static int _load_ld_cache_config(const char *fname)
1842{
1843 FILE *fp = NULL;
1844 char *b = NULL, *p;
1845 struct elfhints_hdr hdr;
1846
1847 fp = fopenat_r(root_fd, root_rel_path(fname));
1848 if (fp == NULL)
1849 return -1;
1850
1851 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1852 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1853 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1854 {
1855 fclose(fp);
1856 return -1;
1857 }
1858
1859 b = xmalloc(hdr.dirlistlen + 1);
1860 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1861 fclose(fp);
1862 free(b);
1863 return -1;
1864 }
1865
1866 while ((p = strsep(&b, ":"))) {
1867 if (*p == '\0')
1868 continue;
1869 xarraypush_str(ldpaths, p);
1870 }
1871
1872 free(b);
1873 fclose(fp);
1874 return 0;
1875}
1876
1877#else
1878#ifdef __ELF__
1879#warning Cache config support not implemented for your target
1880#endif
1881static int _load_ld_cache_config(const char *fname)
1882{
1883 return 0;
1884}
1885#endif
1886
1887static void load_ld_cache_config(const char *fname)
1888{
1889 bool scan_l, scan_ul, scan_ull;
1890 size_t n;
1891 const char *ldpath;
1892
1893 _load_ld_cache_config(fname);
1894
1895 scan_l = scan_ul = scan_ull = false;
1896 array_for_each(ldpaths, n, ldpath) {
1897 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1898 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1899 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1900 }
1901
1902 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1903 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1904 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1294} 1905}
1295 1906
1296/* scan /etc/ld.so.conf for paths */ 1907/* scan /etc/ld.so.conf for paths */
1297static void scanelf_ldpath() 1908static void scanelf_ldpath(void)
1298{ 1909{
1299 char scan_l, scan_ul, scan_ull; 1910 size_t n;
1300 int i = 0; 1911 const char *ldpath;
1301 1912
1302 if (!ldpaths[0]) 1913 array_for_each(ldpaths, n, ldpath)
1303 err("Unable to load any paths from ld.so.conf");
1304
1305 scan_l = scan_ul = scan_ull = 0;
1306
1307 while (ldpaths[i]) {
1308 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1309 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1310 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1311 scanelf_dir(ldpaths[i]); 1914 scanelf_dir(ldpath);
1312 ++i;
1313 }
1314
1315 if (!scan_l) scanelf_dir("/lib");
1316 if (!scan_ul) scanelf_dir("/usr/lib");
1317 if (!scan_ull) scanelf_dir("/usr/local/lib");
1318} 1915}
1319 1916
1320/* scan env PATH for paths */ 1917/* scan env PATH for paths */
1321static void scanelf_envpath() 1918static void scanelf_envpath(void)
1322{ 1919{
1323 char *path, *p; 1920 char *path, *p;
1324 1921
1325 path = getenv("PATH"); 1922 path = getenv("PATH");
1326 if (!path) 1923 if (!path)
1333 } 1930 }
1334 1931
1335 free(path); 1932 free(path);
1336} 1933}
1337 1934
1338/* usage / invocation handling functions */ 1935/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1339#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:BhV" 1936#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1340#define a_argument required_argument 1937#define a_argument required_argument
1341static struct option const long_opts[] = { 1938static struct option const long_opts[] = {
1342 {"path", no_argument, NULL, 'p'}, 1939 {"path", no_argument, NULL, 'p'},
1343 {"ldpath", no_argument, NULL, 'l'}, 1940 {"ldpath", no_argument, NULL, 'l'},
1941 {"use-ldpath",no_argument, NULL, 129},
1942 {"root", a_argument, NULL, 128},
1344 {"recursive", no_argument, NULL, 'R'}, 1943 {"recursive", no_argument, NULL, 'R'},
1345 {"mount", no_argument, NULL, 'm'}, 1944 {"mount", no_argument, NULL, 'm'},
1346 {"symlink", no_argument, NULL, 'y'}, 1945 {"symlink", no_argument, NULL, 'y'},
1347 {"archives", no_argument, NULL, 'A'}, 1946 {"archives", no_argument, NULL, 'A'},
1348 {"ldcache", no_argument, NULL, 'L'}, 1947 {"ldcache", no_argument, NULL, 'L'},
1361 {"lib", a_argument, NULL, 'N'}, 1960 {"lib", a_argument, NULL, 'N'},
1362 {"gmatch", no_argument, NULL, 'g'}, 1961 {"gmatch", no_argument, NULL, 'g'},
1363 {"textrels", no_argument, NULL, 'T'}, 1962 {"textrels", no_argument, NULL, 'T'},
1364 {"etype", a_argument, NULL, 'E'}, 1963 {"etype", a_argument, NULL, 'E'},
1365 {"bits", a_argument, NULL, 'M'}, 1964 {"bits", a_argument, NULL, 'M'},
1965 {"endian", no_argument, NULL, 'D'},
1966 {"osabi", no_argument, NULL, 'I'},
1967 {"eabi", no_argument, NULL, 'Y'},
1968 {"perms", a_argument, NULL, 'O'},
1969 {"size", no_argument, NULL, 'Z'},
1366 {"all", no_argument, NULL, 'a'}, 1970 {"all", no_argument, NULL, 'a'},
1367 {"quiet", no_argument, NULL, 'q'}, 1971 {"quiet", no_argument, NULL, 'q'},
1368 {"verbose", no_argument, NULL, 'v'}, 1972 {"verbose", no_argument, NULL, 'v'},
1369 {"format", a_argument, NULL, 'F'}, 1973 {"format", a_argument, NULL, 'F'},
1370 {"from", a_argument, NULL, 'f'}, 1974 {"from", a_argument, NULL, 'f'},
1371 {"file", a_argument, NULL, 'o'}, 1975 {"file", a_argument, NULL, 'o'},
1976 {"nocolor", no_argument, NULL, 'C'},
1372 {"nobanner", no_argument, NULL, 'B'}, 1977 {"nobanner", no_argument, NULL, 'B'},
1373 {"help", no_argument, NULL, 'h'}, 1978 {"help", no_argument, NULL, 'h'},
1374 {"version", no_argument, NULL, 'V'}, 1979 {"version", no_argument, NULL, 'V'},
1375 {NULL, no_argument, NULL, 0x0} 1980 {NULL, no_argument, NULL, 0x0}
1376}; 1981};
1377 1982
1378static const char *opts_help[] = { 1983static const char * const opts_help[] = {
1379 "Scan all directories in PATH environment", 1984 "Scan all directories in PATH environment",
1380 "Scan all directories in /etc/ld.so.conf", 1985 "Scan all directories in /etc/ld.so.conf",
1986 "Use ld.so.conf to show full path (use with -r/-n)",
1987 "Root directory (use with -l or -p)",
1381 "Scan directories recursively", 1988 "Scan directories recursively",
1382 "Don't recursively cross mount points", 1989 "Don't recursively cross mount points",
1383 "Don't scan symlinks", 1990 "Don't scan symlinks",
1384 "Scan archives (.a files)", 1991 "Scan archives (.a files)",
1385 "Utilize ld.so.cache information (use with -r/-n)", 1992 "Utilize ld.so.cache to show full path (use with -r/-n)",
1386 "Try and 'fix' bad things (use with -r/-e)", 1993 "Try and 'fix' bad things (use with -r/-e)",
1387 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n", 1994 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1388 "Print PaX markings", 1995 "Print PaX markings",
1389 "Print GNU_STACK/PT_LOAD markings", 1996 "Print GNU_STACK/PT_LOAD markings",
1390 "Print TEXTREL information", 1997 "Print TEXTREL information",
1394 "Print BIND information", 2001 "Print BIND information",
1395 "Print SONAME information", 2002 "Print SONAME information",
1396 "Find a specified symbol", 2003 "Find a specified symbol",
1397 "Find a specified section", 2004 "Find a specified section",
1398 "Find a specified library", 2005 "Find a specified library",
1399 "Use strncmp to match libraries. (use with -N)", 2006 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1400 "Locate cause of TEXTREL", 2007 "Locate cause of TEXTREL",
1401 "Print only ELF files matching numeric constant type", 2008 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1402 "Print only ELF files matching numeric bits", 2009 "Print only ELF files matching numeric bits",
1403 "Print all scanned info (-x -e -t -r -b)\n", 2010 "Print Endianness",
2011 "Print OSABI",
2012 "Print EABI (EM_ARM Only)",
2013 "Print only ELF files matching octal permissions",
2014 "Print ELF file size",
2015 "Print all useful/simple info\n",
1404 "Only output 'bad' things", 2016 "Only output 'bad' things",
1405 "Be verbose (can be specified more than once)", 2017 "Be verbose (can be specified more than once)",
1406 "Use specified format for output", 2018 "Use specified format for output",
1407 "Read input stream from a filename", 2019 "Read input stream from a filename",
1408 "Write output stream to a filename", 2020 "Write output stream to a filename",
2021 "Don't emit color in output",
1409 "Don't display the header", 2022 "Don't display the header",
1410 "Print this help and exit", 2023 "Print this help and exit",
1411 "Print version and exit", 2024 "Print version and exit",
1412 NULL 2025 NULL
1413}; 2026};
1414 2027
1415/* display usage and exit */ 2028/* display usage and exit */
1416static void usage(int status) 2029static void usage(int status)
1417{ 2030{
1418 unsigned long i; 2031 const char a_arg[] = "<arg>";
2032 size_t a_arg_len = strlen(a_arg) + 2;
2033 size_t i;
2034 int optlen;
1419 printf("* Scan ELF binaries for stuff\n\n" 2035 printf("* Scan ELF binaries for stuff\n\n"
1420 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0); 2036 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1421 printf("Options: -[%s]\n", PARSE_FLAGS); 2037 printf("Options: -[%s]\n", PARSE_FLAGS);
2038
2039 /* prescan the --long opt length to auto-align */
2040 optlen = 0;
1422 for (i = 0; long_opts[i].name; ++i) 2041 for (i = 0; long_opts[i].name; ++i) {
2042 int l = strlen(long_opts[i].name);
2043 if (long_opts[i].has_arg == a_argument)
2044 l += a_arg_len;
2045 optlen = max(l, optlen);
2046 }
2047
2048 for (i = 0; long_opts[i].name; ++i) {
2049 /* first output the short flag if it has one */
2050 if (long_opts[i].val > '~')
2051 printf(" ");
2052 else
2053 printf(" -%c, ", long_opts[i].val);
2054
2055 /* then the long flag */
1423 if (long_opts[i].has_arg == no_argument) 2056 if (long_opts[i].has_arg == no_argument)
1424 printf(" -%c, --%-14s* %s\n", long_opts[i].val, 2057 printf("--%-*s", optlen, long_opts[i].name);
1425 long_opts[i].name, opts_help[i]);
1426 else 2058 else
1427 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val, 2059 printf("--%s %s %*s", long_opts[i].name, a_arg,
1428 long_opts[i].name, opts_help[i]); 2060 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1429 2061
1430 if (status != EXIT_SUCCESS) 2062 /* finally the help text */
1431 exit(status); 2063 printf("* %s\n", opts_help[i]);
1432 2064 }
1433 puts("\nThe format modifiers for the -F option are:");
1434 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1435 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1436 puts(" i INTERP \tb BIND \ts symbol");
1437 puts(" N library \to Type \tT TEXTRELs");
1438 puts(" S SONAME \tk section");
1439 puts(" p filename (with search path removed)");
1440 puts(" f filename (short name/basename)");
1441 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1442 2065
1443 puts("\nELF Etypes:"); 2066 puts("\nFor more information, see the scanelf(1) manpage");
1444 print_etypes(stdout);
1445
1446 exit(status); 2067 exit(status);
1447} 2068}
1448 2069
1449/* parse command line arguments and preform needed actions */ 2070/* parse command line arguments and preform needed actions */
2071#define do_pax_state(option, flag) \
2072 if (islower(option)) { \
2073 flags &= ~PF_##flag; \
2074 flags |= PF_NO##flag; \
2075 } else { \
2076 flags &= ~PF_NO##flag; \
2077 flags |= PF_##flag; \
2078 }
2079static void parse_delimited(array_t *arr, char *arg, const char *delim)
2080{
2081 char *ele = strtok(arg, delim);
2082 if (!ele) /* edge case: -s '' */
2083 xarraypush_str(arr, "");
2084 while (ele) {
2085 xarraypush_str(arr, ele);
2086 ele = strtok(NULL, delim);
2087 }
2088}
1450static void parseargs(int argc, char *argv[]) 2089static int parseargs(int argc, char *argv[])
1451{ 2090{
1452 int i; 2091 int i;
1453 char *from_file = NULL; 2092 const char *from_file = NULL;
2093 int ret = 0;
2094 char load_cache_config = 0;
1454 2095
1455 opterr = 0; 2096 opterr = 0;
1456 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2097 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1457 switch (i) { 2098 switch (i) {
1458 2099
1466 case 'f': 2107 case 'f':
1467 if (from_file) warn("You prob don't want to specify -f twice"); 2108 if (from_file) warn("You prob don't want to specify -f twice");
1468 from_file = optarg; 2109 from_file = optarg;
1469 break; 2110 break;
1470 case 'E': 2111 case 'E':
1471 strncpy(match_etypes, optarg, sizeof(match_etypes)); 2112 /* historically, this was comma delimited */
2113 parse_delimited(match_etypes, optarg, ",");
1472 break; 2114 break;
1473 case 'M': 2115 case 'M':
1474 match_bits = atoi(optarg); 2116 match_bits = atoi(optarg);
2117 if (match_bits == 0) {
2118 if (strcmp(optarg, "ELFCLASS32") == 0)
2119 match_bits = 32;
2120 if (strcmp(optarg, "ELFCLASS64") == 0)
2121 match_bits = 64;
2122 }
2123 break;
2124 case 'O':
2125 if (sscanf(optarg, "%o", &match_perms) == -1)
2126 match_bits = 0;
1475 break; 2127 break;
1476 case 'o': { 2128 case 'o': {
1477 FILE *fp = NULL;
1478 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2129 if (freopen(optarg, "w", stdout) == NULL)
1479 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2130 errp("Could not freopen(%s)", optarg);
1480 SET_STDOUT(fp);
1481 break; 2131 break;
1482 } 2132 }
1483 case 'k': 2133 case 'k':
1484 if (find_section) warn("You prob don't want to specify -k twice"); 2134 xarraypush_str(find_section_arr, optarg);
1485 find_section = optarg;
1486 break; 2135 break;
1487 case 's': { 2136 case 's':
1488 if (find_sym) warn("You prob don't want to specify -s twice"); 2137 /* historically, this was comma delimited */
1489 find_sym = optarg; 2138 parse_delimited(find_sym_arr, optarg, ",");
1490 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1491 sprintf(versioned_symname, "%s@", find_sym);
1492 break; 2139 break;
1493 }
1494 case 'N': { 2140 case 'N':
1495 if (find_lib) warn("You prob don't want to specify -N twice"); 2141 xarraypush_str(find_lib_arr, optarg);
1496 find_lib = optarg;
1497 break; 2142 break;
1498 }
1499
1500 case 'F': { 2143 case 'F': {
1501 if (out_format) warn("You prob don't want to specify -F twice"); 2144 if (out_format) warn("You prob don't want to specify -F twice");
1502 out_format = optarg; 2145 out_format = optarg;
1503 break; 2146 break;
1504 } 2147 }
1505 case 'z': { 2148 case 'z': {
1506 unsigned long flags = 10240; 2149 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1507 size_t x; 2150 size_t x;
1508 2151
1509#define do_state(option, flag) \
1510 if (islower(option)) { \
1511 flags &= ~PF_##flag; \
1512 flags |= PF_NO##flag; \
1513 } else { \
1514 flags &= ~PF_NO##flag; \
1515 flags |= PF_##flag; \
1516 }
1517
1518 for (x = 0 ; x < strlen(optarg); x++) { 2152 for (x = 0; x < strlen(optarg); x++) {
1519 switch(optarg[x]) { 2153 switch (optarg[x]) {
1520 case 'p': 2154 case 'p':
1521 case 'P': 2155 case 'P':
1522 do_state(optarg[x], PAGEEXEC); 2156 do_pax_state(optarg[x], PAGEEXEC);
1523 break; 2157 break;
1524 case 's': 2158 case 's':
1525 case 'S': 2159 case 'S':
1526 do_state(optarg[x], SEGMEXEC); 2160 do_pax_state(optarg[x], SEGMEXEC);
1527 break; 2161 break;
1528 case 'm': 2162 case 'm':
1529 case 'M': 2163 case 'M':
1530 do_state(optarg[x], MPROTECT); 2164 do_pax_state(optarg[x], MPROTECT);
1531 break; 2165 break;
1532 case 'e': 2166 case 'e':
1533 case 'E': 2167 case 'E':
1534 do_state(optarg[x], EMUTRAMP); 2168 do_pax_state(optarg[x], EMUTRAMP);
1535 break; 2169 break;
1536 case 'r': 2170 case 'r':
1537 case 'R': 2171 case 'R':
1538 do_state(optarg[x], RANDMMAP); 2172 do_pax_state(optarg[x], RANDMMAP);
1539 break; 2173 break;
1540 case 'x': 2174 case 'x':
1541 case 'X': 2175 case 'X':
1542 do_state(optarg[x], RANDEXEC); 2176 do_pax_state(optarg[x], RANDEXEC);
1543 break; 2177 break;
1544 default: 2178 default:
1545 break; 2179 break;
1546 } 2180 }
1547 } 2181 }
1552 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) || 2186 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1553 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)))) 2187 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1554 setpax = flags; 2188 setpax = flags;
1555 break; 2189 break;
1556 } 2190 }
2191 case 'Z': show_size = 1; break;
1557 case 'g': gmatch = 1; break; 2192 case 'g': ++g_match; break;
1558 case 'L': use_ldcache = 1; break; 2193 case 'L': load_cache_config = use_ldcache = 1; break;
1559 case 'y': scan_symlink = 0; break; 2194 case 'y': scan_symlink = 0; break;
1560 case 'A': scan_archives = 1; break; 2195 case 'A': scan_archives = 1; break;
2196 case 'C': color_init(true); break;
1561 case 'B': show_banner = 0; break; 2197 case 'B': show_banner = 0; break;
1562 case 'l': scan_ldpath = 1; break; 2198 case 'l': load_cache_config = scan_ldpath = 1; break;
1563 case 'p': scan_envpath = 1; break; 2199 case 'p': scan_envpath = 1; break;
1564 case 'R': dir_recurse = 1; break; 2200 case 'R': dir_recurse = 1; break;
1565 case 'm': dir_crossmount = 0; break; 2201 case 'm': dir_crossmount = 0; break;
1566 case 'X': ++fix_elf; break; 2202 case 'X': ++fix_elf; break;
1567 case 'x': show_pax = 1; break; 2203 case 'x': show_pax = 1; break;
1571 case 'n': show_needed = 1; break; 2207 case 'n': show_needed = 1; break;
1572 case 'i': show_interp = 1; break; 2208 case 'i': show_interp = 1; break;
1573 case 'b': show_bind = 1; break; 2209 case 'b': show_bind = 1; break;
1574 case 'S': show_soname = 1; break; 2210 case 'S': show_soname = 1; break;
1575 case 'T': show_textrels = 1; break; 2211 case 'T': show_textrels = 1; break;
1576 case 'q': be_quiet = 1; break; 2212 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1577 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2213 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1578 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2214 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1579 2215 case 'D': show_endian = 1; break;
2216 case 'I': show_osabi = 1; break;
2217 case 'Y': show_eabi = 1; break;
2218 case 128:
2219 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2220 if (root_fd == -1)
2221 err("Could not open root: %s", optarg);
2222 break;
2223 case 129: load_cache_config = use_ldpath = 1; break;
1580 case ':': 2224 case ':':
1581 err("Option '%c' is missing parameter", optopt); 2225 err("Option '%c' is missing parameter", optopt);
1582 case '?': 2226 case '?':
1583 err("Unknown option '%c' or argument missing", optopt); 2227 err("Unknown option '%c' or argument missing", optopt);
1584 default: 2228 default:
1585 err("Unhandled option '%c'; please report this", i); 2229 err("Unhandled option '%c'; please report this", i);
1586 } 2230 }
1587 } 2231 }
2232 if (show_textrels && be_verbose)
2233 has_objdump = bin_in_path("objdump");
2234 /* precompile all the regexes */
2235 if (g_match) {
2236 regex_t preg;
2237 const char *this_sym;
2238 size_t n;
2239 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1588 2240
2241 array_for_each(find_sym_arr, n, this_sym) {
2242 /* see scanelf_match_symname for logic info */
2243 switch (this_sym[0]) {
2244 case '%':
2245 while (*(this_sym++))
2246 if (*this_sym == '%') {
2247 ++this_sym;
2248 break;
2249 }
2250 break;
2251 case '+':
2252 case '-':
2253 ++this_sym;
2254 break;
2255 }
2256 if (*this_sym == '*')
2257 ++this_sym;
2258
2259 ret = regcomp(&preg, this_sym, flags);
2260 if (ret) {
2261 char err[256];
2262 regerror(ret, &preg, err, sizeof(err));
2263 err("regcomp of %s failed: %s", this_sym, err);
2264 }
2265 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2266 }
2267 }
2268 /* flatten arrays for display */
2269 find_sym = array_flatten_str(find_sym_arr);
2270 find_lib = array_flatten_str(find_lib_arr);
2271 find_section = array_flatten_str(find_section_arr);
1589 /* let the format option override all other options */ 2272 /* let the format option override all other options */
1590 if (out_format) { 2273 if (out_format) {
1591 show_pax = show_phdr = show_textrel = show_rpath = \ 2274 show_pax = show_phdr = show_textrel = show_rpath = \
1592 show_needed = show_interp = show_bind = show_soname = \ 2275 show_needed = show_interp = show_bind = show_soname = \
1593 show_textrels = 0; 2276 show_textrels = show_perms = show_endian = show_size = \
2277 show_osabi = show_eabi = 0;
1594 for (i = 0; out_format[i]; ++i) { 2278 for (i = 0; out_format[i]; ++i) {
1595 if (!IS_MODIFIER(out_format[i])) continue; 2279 if (!IS_MODIFIER(out_format[i])) continue;
1596 2280
1597 switch (out_format[++i]) { 2281 switch (out_format[++i]) {
2282 case '+': break;
1598 case '%': break; 2283 case '%': break;
1599 case '#': break; 2284 case '#': break;
1600 case 'F': break; 2285 case 'F': break;
1601 case 'p': break; 2286 case 'p': break;
1602 case 'f': break; 2287 case 'f': break;
1603 case 'k': break; 2288 case 'k': break;
1604 case 's': break; 2289 case 's': break;
1605 case 'N': break; 2290 case 'N': break;
1606 case 'o': break; 2291 case 'o': break;
2292 case 'a': break;
2293 case 'M': break;
2294 case 'Z': show_size = 1; break;
2295 case 'D': show_endian = 1; break;
2296 case 'I': show_osabi = 1; break;
2297 case 'Y': show_eabi = 1; break;
2298 case 'O': show_perms = 1; break;
1607 case 'x': show_pax = 1; break; 2299 case 'x': show_pax = 1; break;
1608 case 'e': show_phdr = 1; break; 2300 case 'e': show_phdr = 1; break;
1609 case 't': show_textrel = 1; break; 2301 case 't': show_textrel = 1; break;
1610 case 'r': show_rpath = 1; break; 2302 case 'r': show_rpath = 1; break;
1611 case 'n': show_needed = 1; break; 2303 case 'n': show_needed = 1; break;
1612 case 'i': show_interp = 1; break; 2304 case 'i': show_interp = 1; break;
1613 case 'b': show_bind = 1; break; 2305 case 'b': show_bind = 1; break;
1614 case 'S': show_soname = 1; break; 2306 case 'S': show_soname = 1; break;
1615 case 'T': show_textrels = 1; break; 2307 case 'T': show_textrels = 1; break;
1616 default: 2308 default:
1617 err("Invalid format specifier '%c' (byte %i)", 2309 err("invalid format specifier '%c' (byte %i)",
1618 out_format[i], i+1); 2310 out_format[i], i+1);
1619 } 2311 }
1620 } 2312 }
1621 2313
1622 /* construct our default format */ 2314 /* construct our default format */
1623 } else { 2315 } else {
1624 size_t fmt_len = 30; 2316 size_t fmt_len = 30;
1625 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2317 out_format = xmalloc(sizeof(char) * fmt_len);
2318 *out_format = '\0';
1626 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2319 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1627 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2320 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2321 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2322 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2323 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2324 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2325 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1628 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2326 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1629 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2327 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1630 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2328 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1631 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2329 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1632 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2330 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1639 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2337 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1640 } 2338 }
1641 if (be_verbose > 2) printf("Format: %s\n", out_format); 2339 if (be_verbose > 2) printf("Format: %s\n", out_format);
1642 2340
1643 /* now lets actually do the scanning */ 2341 /* now lets actually do the scanning */
1644 if (scan_ldpath || use_ldcache) 2342 if (load_cache_config)
1645 load_ld_so_conf(0, "/etc/ld.so.conf"); 2343 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1646 if (scan_ldpath) scanelf_ldpath(); 2344 if (scan_ldpath) scanelf_ldpath();
1647 if (scan_envpath) scanelf_envpath(); 2345 if (scan_envpath) scanelf_envpath();
2346 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2347 from_file = "-";
1648 if (from_file) { 2348 if (from_file) {
1649 scanelf_from_file(from_file); 2349 scanelf_from_file(from_file);
1650 from_file = *argv; 2350 from_file = *argv;
1651 } 2351 }
1652 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2352 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1653 err("Nothing to scan !?"); 2353 err("Nothing to scan !?");
1654 while (optind < argc) { 2354 while (optind < argc) {
1655 search_path = argv[optind++]; 2355 search_path = argv[optind++];
1656 scanelf_dir(search_path); 2356 ret = scanelf_dir(search_path);
1657 } 2357 }
1658 2358
2359#ifdef __PAX_UTILS_CLEANUP
1659 /* clean up */ 2360 /* clean up */
1660 if (versioned_symname) free(versioned_symname);
1661 for (i = 0; ldpaths[i]; ++i)
1662 free(ldpaths[i]); 2361 xarrayfree(ldpaths);
2362 xarrayfree(find_sym_arr);
2363 xarrayfree(find_lib_arr);
2364 xarrayfree(find_section_arr);
2365 free(find_sym);
2366 free(find_lib);
2367 free(find_section);
2368 {
2369 size_t n;
2370 regex_t *preg;
2371 array_for_each(find_sym_regex_arr, n, preg)
2372 regfree(preg);
2373 xarrayfree(find_sym_regex_arr);
2374 }
1663 2375
1664 if (ldcache != 0) 2376 if (ldcache != 0)
1665 munmap(ldcache, ldcache_size); 2377 munmap(ldcache, ldcache_size);
1666} 2378#endif
1667 2379
1668
1669
1670/* utility funcs */
1671static char *xstrdup(const char *s)
1672{
1673 char *ret = strdup(s);
1674 if (!ret) err("Could not strdup(): %s", strerror(errno));
1675 return ret; 2380 return ret;
1676} 2381}
1677static void *xmalloc(size_t size)
1678{
1679 void *ret = malloc(size);
1680 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1681 return ret;
1682}
1683static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1684{
1685 size_t new_len;
1686 2382
1687 new_len = strlen(*dst) + strlen(src); 2383static char **get_split_env(const char *envvar)
1688 if (*curr_len <= new_len) {
1689 *curr_len = new_len + (*curr_len / 2);
1690 *dst = realloc(*dst, *curr_len);
1691 if (!*dst)
1692 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1693 }
1694
1695 if (n)
1696 strncat(*dst, src, n);
1697 else
1698 strcat(*dst, src);
1699}
1700static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1701{ 2384{
1702 static char my_app[2]; 2385 const char *delims = " \t\n";
1703 my_app[0] = append; 2386 char **envvals = NULL;
1704 my_app[1] = '\0'; 2387 char *env, *s;
1705 xstrcat(dst, my_app, curr_len); 2388 int nentry;
1706}
1707 2389
2390 if ((env = getenv(envvar)) == NULL)
2391 return NULL;
1708 2392
2393 env = xstrdup(env);
2394 if (env == NULL)
2395 return NULL;
2396
2397 s = strtok(env, delims);
2398 if (s == NULL) {
2399 free(env);
2400 return NULL;
2401 }
2402
2403 nentry = 0;
2404 while (s != NULL) {
2405 ++nentry;
2406 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2407 envvals[nentry-1] = s;
2408 s = strtok(NULL, delims);
2409 }
2410 envvals[nentry] = NULL;
2411
2412 /* don't want to free(env) as it contains the memory that backs
2413 * the envvals array of strings */
2414 return envvals;
2415}
2416
2417static void parseenv(void)
2418{
2419 color_init(false);
2420 qa_textrels = get_split_env("QA_TEXTRELS");
2421 qa_execstack = get_split_env("QA_EXECSTACK");
2422 qa_wx_load = get_split_env("QA_WX_LOAD");
2423}
2424
2425#ifdef __PAX_UTILS_CLEANUP
2426static void cleanup(void)
2427{
2428 free(out_format);
2429 free(qa_textrels);
2430 free(qa_execstack);
2431 free(qa_wx_load);
2432}
2433#endif
1709 2434
1710int main(int argc, char *argv[]) 2435int main(int argc, char *argv[])
1711{ 2436{
2437 int ret;
1712 if (argc < 2) 2438 if (argc < 2)
1713 usage(EXIT_FAILURE); 2439 usage(EXIT_FAILURE);
2440 parseenv();
1714 parseargs(argc, argv); 2441 ret = parseargs(argc, argv);
1715 fclose(stdout); 2442 fclose(stdout);
1716#ifdef __BOUNDS_CHECKING_ON 2443#ifdef __PAX_UTILS_CLEANUP
1717 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2444 cleanup();
2445 warn("The calls to add/delete heap should be off:\n"
2446 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2447 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1718#endif 2448#endif
1719 return EXIT_SUCCESS; 2449 return ret;
1720} 2450}
2451
2452/* Match filename against entries in matchlist, return TRUE
2453 * if the file is listed */
2454static int file_matches_list(const char *filename, char **matchlist)
2455{
2456 char **file;
2457 char *match;
2458 char buf[__PAX_UTILS_PATH_MAX];
2459
2460 if (matchlist == NULL)
2461 return 0;
2462
2463 for (file = matchlist; *file != NULL; file++) {
2464 if (search_path) {
2465 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2466 match = buf;
2467 } else {
2468 match = *file;
2469 }
2470 if (fnmatch(match, filename, 0) == 0)
2471 return 1;
2472 }
2473 return 0;
2474}

Legend:
Removed from v.1.127  
changed lines
  Added in v.1.263

  ViewVC Help
Powered by ViewVC 1.1.20