/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.127 Revision 1.270
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.127 2006/02/17 07:13:54 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.270 2015/02/21 19:30:59 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.270 2015/02/21 19:30:59 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.127 2006/02/17 07:13:54 solar Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static int scanelf_elfobj(elfobj *elf); 18static int file_matches_list(const char *filename, char **matchlist);
21static int scanelf_elf(const char *filename, int fd, size_t len);
22static int scanelf_archive(const char *filename, int fd, size_t len);
23static void scanelf_file(const char *filename);
24static void scanelf_dir(const char *path);
25static void scanelf_ldpath(void);
26static void scanelf_envpath(void);
27static void usage(int status);
28static void parseargs(int argc, char *argv[]);
29static char *xstrdup(const char *s);
30static void *xmalloc(size_t size);
31static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
32#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
33static inline void xchrcat(char **dst, const char append, size_t *curr_len);
34 19
35/* variables to control behavior */ 20/* variables to control behavior */
36static char match_etypes[126] = ""; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
37static char *ldpaths[256]; 22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
38static char scan_ldpath = 0; 23static char scan_ldpath = 0;
39static char scan_envpath = 0; 24static char scan_envpath = 0;
40static char scan_symlink = 1; 25static char scan_symlink = 1;
41static char scan_archives = 0; 26static char scan_archives = 0;
42static char dir_recurse = 0; 27static char dir_recurse = 0;
43static char dir_crossmount = 1; 28static char dir_crossmount = 1;
44static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
45static char show_phdr = 0; 32static char show_phdr = 0;
46static char show_textrel = 0; 33static char show_textrel = 0;
47static char show_rpath = 0; 34static char show_rpath = 0;
48static char show_needed = 0; 35static char show_needed = 0;
49static char show_interp = 0; 36static char show_interp = 0;
50static char show_bind = 0; 37static char show_bind = 0;
51static char show_soname = 0; 38static char show_soname = 0;
52static char show_textrels = 0; 39static char show_textrels = 0;
53static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
54static char be_quiet = 0; 44static char be_quiet = 0;
55static char be_verbose = 0; 45static char be_verbose = 0;
56static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
57static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
58static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
59static char *find_section = NULL; 53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
60static char *out_format = NULL; 55static char *out_format = NULL;
61static char *search_path = NULL; 56static char *search_path = NULL;
62static char fix_elf = 0; 57static char fix_elf = 0;
63static char gmatch = 0; 58static char g_match = 0;
64static char use_ldcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
65 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
66
66int match_bits = 0; 67static int match_bits = 0;
67caddr_t ldcache = 0; 68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
68size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
69unsigned long setpax = 0UL; 71static unsigned long setpax = 0UL;
70 72
73static const char *objdump;
74
75/* Find the path to a file by name. Note: we do not currently handle the
76 * empty path element correctly (should behave by searching $PWD). */
77static const char *which(const char *fname, const char *envvar)
78{
79 size_t path_len, fname_len;
80 const char *env_path;
81 char *path, *p, *ep;
82
83 p = getenv(envvar);
84 if (p)
85 return p;
86
87 env_path = getenv("PATH");
88 if (!env_path)
89 return NULL;
90
91 /* Create a copy of the $PATH that we can safely modify.
92 * Make it a little bigger so we can append "/fname".
93 * We do this twice -- once for a perm copy, and once for
94 * room at the end of the last element. */
95 path_len = strlen(env_path);
96 fname_len = strlen(fname);
97 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
98 memcpy(path, env_path, path_len + 1);
99
100 p = path + path_len + 1 + fname_len + 1;
101 *p = '/';
102 memcpy(p + 1, fname, fname_len + 1);
103
104 /* Repoint fname to the copy in the env string as it has
105 * the leading slash which we can include in a single memcpy.
106 * Increase the fname len to include the '/' and '\0'. */
107 fname = p;
108 fname_len += 2;
109
110 p = path;
111 while (p) {
112 ep = strchr(p, ':');
113 /* Append the /foo path to the current element. */
114 if (ep)
115 memcpy(ep, fname, fname_len);
116 else
117 memcpy(path + path_len, fname, fname_len);
118
119 if (access(p, R_OK) != -1)
120 return p;
121
122 p = ep;
123 if (ep) {
124 /* If not the last element, restore the chunk we clobbered. */
125 size_t offset = ep - path;
126 size_t restore = min(path_len - offset, fname_len);
127 memcpy(ep, env_path + offset, restore);
128 ++p;
129 }
130 }
131
132 free(path);
133 return NULL;
134}
135
136static FILE *fopenat_r(int dir_fd, const char *path)
137{
138 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
139 if (fd == -1)
140 return NULL;
141 return fdopen(fd, "re");
142}
143
144static const char *root_rel_path(const char *path)
145{
146 /*
147 * openat() will ignore the dirfd if path starts with
148 * a /, so consume all of that noise
149 *
150 * XXX: we don't handle relative paths like ../ that
151 * break out of the --root option, but for now, just
152 * don't do that :P.
153 */
154 if (root_fd != AT_FDCWD) {
155 while (*path == '/')
156 ++path;
157 if (*path == '\0')
158 path = ".";
159 }
160
161 return path;
162}
163
71/* sub-funcs for scanelf_file() */ 164/* sub-funcs for scanelf_fileat() */
72static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 165static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
73{ 166{
74 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 167 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
168
169 /* debug sections */
170 void *symtab = elf_findsecbyname(elf, ".symtab");
171 void *strtab = elf_findsecbyname(elf, ".strtab");
172 /* runtime sections */
173 void *dynsym = elf_findsecbyname(elf, ".dynsym");
174 void *dynstr = elf_findsecbyname(elf, ".dynstr");
175
176 /*
177 * If the sections are marked NOBITS, then they don't exist, so we just
178 * skip them. This let's us work sanely with splitdebug ELFs (rather
179 * than spewing a lot of "corrupt ELF" messages later on). In malformed
180 * ELFs, the section might be wrongly set to NOBITS, but screw em.
181 *
182 * We need to make sure the debug/runtime sym/str sets are used together
183 * as they are generated in sync. Trying to mix them won't work.
184 */
75#define GET_SYMTABS(B) \ 185#define GET_SYMTABS(B) \
76 if (elf->elf_class == ELFCLASS ## B) { \ 186 if (elf->elf_class == ELFCLASS ## B) { \
77 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 187 Elf ## B ## _Shdr *esymtab = symtab; \
78 /* debug sections */ \ 188 Elf ## B ## _Shdr *estrtab = strtab; \
79 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 189 Elf ## B ## _Shdr *edynsym = dynsym; \
80 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 190 Elf ## B ## _Shdr *edynstr = dynstr; \
81 /* runtime sections */ \ 191 \
82 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 192 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
83 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 193 symtab = NULL; \
84 if (symtab && dynsym) { \ 194 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
85 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 195 dynsym = NULL; \
196 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
197 strtab = NULL; \
198 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
199 dynstr = NULL; \
200 \
201 /* Use the set with more symbols if both exist. */ \
202 if (symtab && dynsym && strtab && dynstr) { \
203 if (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) \
204 goto debug##B; \
205 else \
206 goto runtime##B; \
207 } else if (symtab && strtab) { \
208 debug##B: \
209 *sym = symtab; \
210 *str = strtab; \
211 return; \
212 } else if (dynsym && dynstr) { \
213 runtime##B: \
214 *sym = dynsym; \
215 *str = dynstr; \
216 return; \
86 } else { \ 217 } else { \
87 *sym = (void*)(symtab ? symtab : dynsym); \ 218 *sym = *str = NULL; \
88 } \ 219 } \
89 if (strtab && dynstr) { \
90 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \
91 } else { \
92 *tab = (void*)(strtab ? strtab : dynstr); \
93 } \
94 } 220 }
95 GET_SYMTABS(32) 221 GET_SYMTABS(32)
96 GET_SYMTABS(64) 222 GET_SYMTABS(64)
223
224 if (*sym && *str)
225 return;
226
227 /*
228 * damn, they're really going to make us work for it huh?
229 * reconstruct the section header info out of the dynamic
230 * tags so we can see what symbols this guy uses at runtime.
231 */
232#define GET_SYMTABS_DT(B) \
233 if (elf->elf_class == ELFCLASS ## B) { \
234 size_t i; \
235 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
236 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
237 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
238 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
239 Elf ## B ## _Dyn *dyn; \
240 Elf ## B ## _Off offset; \
241 \
242 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
243 vsym = vstr = vhash = vgnu_hash = 0; \
244 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
245 memset(&str_shdr, 0, sizeof(str_shdr)); \
246 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
247 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
248 continue; \
249 \
250 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
252 continue; \
253 \
254 dyn = DYN ## B (elf->vdata + offset); \
255 while (EGET(dyn->d_tag) != DT_NULL) { \
256 switch (EGET(dyn->d_tag)) { \
257 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
258 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
259 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
260 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
261 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
262 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
263 } \
264 ++dyn; \
265 } \
266 if (vsym && vstr) \
267 break; \
268 } \
269 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
270 return; \
271 \
272 /* calc offset into the ELF by finding the load addr of the syms */ \
273 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
274 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
275 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
276 offset = EGET(phdr[i].p_offset); \
277 \
278 if (EGET(phdr[i].p_type) != PT_LOAD) \
279 continue; \
280 \
281 if (vhash >= vaddr && vhash < vaddr + filesz) { \
282 /* Scan the hash table to see how many entries we have */ \
283 Elf32_Word max_sym_idx = 0; \
284 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
285 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
286 Elf32_Word nchains = EGET(hashtbl[1]); \
287 Elf32_Word *buckets = &hashtbl[2]; \
288 Elf32_Word *chains = &buckets[nbuckets]; \
289 Elf32_Word sym_idx; \
290 \
291 for (b = 0; b < nbuckets; ++b) { \
292 if (!buckets[b]) \
293 continue; \
294 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
295 if (max_sym_idx < sym_idx) \
296 max_sym_idx = sym_idx; \
297 } \
298 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
299 } \
300 \
301 if (vsym >= vaddr && vsym < vaddr + filesz) { \
302 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
303 *sym = &sym_shdr; \
304 } \
305 \
306 if (vstr >= vaddr && vstr < vaddr + filesz) { \
307 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
308 *str = &str_shdr; \
309 } \
310 } \
311 }
312 GET_SYMTABS_DT(32)
313 GET_SYMTABS_DT(64)
97} 314}
98 315
99static char *scanelf_file_pax(elfobj *elf, char *found_pax) 316static char *scanelf_file_pax(elfobj *elf, char *found_pax)
100{ 317{
101 static char ret[7]; 318 static char ret[7];
116 continue; \ 333 continue; \
117 if (fix_elf && setpax) { \ 334 if (fix_elf && setpax) { \
118 /* set the paxctl flags */ \ 335 /* set the paxctl flags */ \
119 ESET(phdr[i].p_flags, setpax); \ 336 ESET(phdr[i].p_flags, setpax); \
120 } \ 337 } \
121 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 338 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
122 continue; \ 339 continue; \
123 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 340 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
124 *found_pax = 1; \ 341 *found_pax = 1; \
125 ++shown; \ 342 ++shown; \
126 break; \ 343 break; \
128 } 345 }
129 SHOW_PAX(32) 346 SHOW_PAX(32)
130 SHOW_PAX(64) 347 SHOW_PAX(64)
131 } 348 }
132 349
350 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
351 * was found. This is known to break ELFs on glibc systems,
352 * and mainline PaX has deprecated use of this for a long time.
353 * We could support changing PT_GNU_STACK, but that doesn't
354 * seem like it's worth the effort. #411919
355 */
356
133 /* fall back to EI_PAX if no PT_PAX was found */ 357 /* fall back to EI_PAX if no PT_PAX was found */
134 if (!*ret) { 358 if (!*ret) {
135 static char *paxflags; 359 static char *paxflags;
136
137 if (fix_elf && setpax) {
138 /* set the chpax settings */
139 // ESET(EHDR ## B (elf->ehdr)->e_ident[EI_PAX]), setpax);
140 }
141
142 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 360 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
143 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) { 361 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
144 *found_pax = 1; 362 *found_pax = 1;
145 return (be_wewy_wewy_quiet ? NULL : paxflags); 363 return (be_wewy_wewy_quiet ? NULL : paxflags);
146 } 364 }
156static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 374static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
157{ 375{
158 static char ret[12]; 376 static char ret[12];
159 char *found; 377 char *found;
160 unsigned long i, shown, multi_stack, multi_relro, multi_load; 378 unsigned long i, shown, multi_stack, multi_relro, multi_load;
161 int max_pt_load;
162 379
163 if (!show_phdr) return NULL; 380 if (!show_phdr) return NULL;
164 381
165 memcpy(ret, "--- --- ---\0", 12); 382 memcpy(ret, "--- --- ---\0", 12);
166 383
167 shown = 0; 384 shown = 0;
168 multi_stack = multi_relro = multi_load = 0; 385 multi_stack = multi_relro = multi_load = 0;
169 max_pt_load = elf_max_pt_load(elf);
170 386
171#define NOTE_GNU_STACK ".note.GNU-stack" 387#define NOTE_GNU_STACK ".note.GNU-stack"
172#define SHOW_PHDR(B) \ 388#define SHOW_PHDR(B) \
173 if (elf->elf_class == ELFCLASS ## B) { \ 389 if (elf->elf_class == ELFCLASS ## B) { \
174 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 390 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
176 uint32_t flags, check_flags; \ 392 uint32_t flags, check_flags; \
177 if (elf->phdr != NULL) { \ 393 if (elf->phdr != NULL) { \
178 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 394 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
179 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 395 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
180 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 396 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
397 if (multi_stack++) \
181 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 398 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
399 if (file_matches_list(elf->filename, qa_execstack)) \
400 continue; \
182 found = found_phdr; \ 401 found = found_phdr; \
183 offset = 0; \ 402 offset = 0; \
184 check_flags = PF_X; \ 403 check_flags = PF_X; \
185 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 404 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
405 if (multi_relro++) \
186 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 406 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
187 found = found_relro; \ 407 found = found_relro; \
188 offset = 4; \ 408 offset = 4; \
189 check_flags = PF_X; \ 409 check_flags = PF_X; \
190 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 410 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
191 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \ 411 if (file_matches_list(elf->filename, qa_wx_load)) \
192 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \ 412 continue; \
193 found = found_load; \ 413 found = found_load; \
194 offset = 8; \ 414 offset = 8; \
195 check_flags = PF_W|PF_X; \ 415 check_flags = PF_W|PF_X; \
196 } else \ 416 } else \
197 continue; \ 417 continue; \
198 flags = EGET(phdr[i].p_flags); \ 418 flags = EGET(phdr[i].p_flags); \
199 if (be_quiet && ((flags & check_flags) != check_flags)) \ 419 if (be_quiet && ((flags & check_flags) != check_flags)) \
200 continue; \ 420 continue; \
201 if (fix_elf && ((flags & PF_X) != flags)) { \ 421 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
202 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \ 422 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
203 ret[3] = ret[7] = '!'; \ 423 ret[3] = ret[7] = '!'; \
204 flags = EGET(phdr[i].p_flags); \ 424 flags = EGET(phdr[i].p_flags); \
205 } \ 425 } \
206 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 426 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
210 } else if (elf->shdr != NULL) { \ 430 } else if (elf->shdr != NULL) { \
211 /* no program headers which means this is prob an object file */ \ 431 /* no program headers which means this is prob an object file */ \
212 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 432 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
213 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 433 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
214 char *str; \ 434 char *str; \
215 if ((void*)strtbl > (void*)elf->data_end) \ 435 if ((void*)strtbl > elf->data_end) \
216 goto skip_this_shdr##B; \ 436 goto skip_this_shdr##B; \
437 /* let's flag -w/+x object files since the final ELF will most likely \
438 * need write access to the stack (who doesn't !?). so the combined \
439 * output will bring in +w automatically and that's bad. \
440 */ \
217 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 441 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
218 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 442 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
219 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 443 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
220 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 444 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
221 str = elf->data + offset; \ 445 str = elf->data + offset; \
222 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \ 446 if (str + sizeof(NOTE_GNU_STACK) > elf->data + elf->len) continue; \
223 if (!strcmp(str, NOTE_GNU_STACK)) { \ 447 if (!strcmp(str, NOTE_GNU_STACK)) { \
224 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 448 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
225 flags = EGET(shdr[i].sh_flags); \ 449 flags = EGET(shdr[i].sh_flags); \
226 if (be_quiet && ((flags & check_flags) != check_flags)) \ 450 if (be_quiet && ((flags & check_flags) != check_flags)) \
227 continue; \ 451 continue; \
234 break; \ 458 break; \
235 } \ 459 } \
236 } \ 460 } \
237 skip_this_shdr##B: \ 461 skip_this_shdr##B: \
238 if (!multi_stack) { \ 462 if (!multi_stack) { \
463 if (file_matches_list(elf->filename, qa_execstack)) \
464 return NULL; \
239 *found_phdr = 1; \ 465 *found_phdr = 1; \
240 shown = 1; \ 466 shown = 1; \
241 memcpy(ret, "!WX", 3); \ 467 memcpy(ret, "!WX", 3); \
242 } \ 468 } \
243 } \ 469 } \
248 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 474 if (be_wewy_wewy_quiet || (be_quiet && !shown))
249 return NULL; 475 return NULL;
250 else 476 else
251 return ret; 477 return ret;
252} 478}
479
480/*
481 * See if this ELF contains a DT_TEXTREL tag in any of its
482 * PT_DYNAMIC sections.
483 */
253static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 484static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
254{ 485{
255 static const char *ret = "TEXTREL"; 486 static const char *ret = "TEXTREL";
256 unsigned long i; 487 unsigned long i;
257 488
258 if (!show_textrel && !show_textrels) return NULL; 489 if (!show_textrel && !show_textrels) return NULL;
490
491 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
259 492
260 if (elf->phdr) { 493 if (elf->phdr) {
261#define SHOW_TEXTREL(B) \ 494#define SHOW_TEXTREL(B) \
262 if (elf->elf_class == ELFCLASS ## B) { \ 495 if (elf->elf_class == ELFCLASS ## B) { \
263 Elf ## B ## _Dyn *dyn; \ 496 Elf ## B ## _Dyn *dyn; \
264 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 497 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
265 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 498 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
266 Elf ## B ## _Off offset; \ 499 Elf ## B ## _Off offset; \
267 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 500 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
268 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 501 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
269 offset = EGET(phdr[i].p_offset); \ 502 offset = EGET(phdr[i].p_offset); \
270 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 503 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
271 dyn = DYN ## B (elf->data + offset); \ 504 dyn = DYN ## B (elf->vdata + offset); \
272 while (EGET(dyn->d_tag) != DT_NULL) { \ 505 while (EGET(dyn->d_tag) != DT_NULL) { \
273 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 506 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
274 *found_textrel = 1; \ 507 *found_textrel = 1; \
275 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 508 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
276 return (be_wewy_wewy_quiet ? NULL : ret); \ 509 return (be_wewy_wewy_quiet ? NULL : ret); \
285 if (be_quiet || be_wewy_wewy_quiet) 518 if (be_quiet || be_wewy_wewy_quiet)
286 return NULL; 519 return NULL;
287 else 520 else
288 return " - "; 521 return " - ";
289} 522}
523
524/*
525 * Scan the .text section to see if there are any relocations in it.
526 * Should rewrite this to check PT_LOAD sections that are marked
527 * Executable rather than the section named '.text'.
528 */
290static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 529static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
291{ 530{
292 unsigned long s, r, rmax; 531 unsigned long s, r, rmax;
293 void *symtab_void, *strtab_void, *text_void; 532 void *symtab_void, *strtab_void, *text_void;
294 533
315 Elf ## B ## _Rela *rela; \ 554 Elf ## B ## _Rela *rela; \
316 /* search the section headers for relocations */ \ 555 /* search the section headers for relocations */ \
317 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 556 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
318 uint32_t sh_type = EGET(shdr[s].sh_type); \ 557 uint32_t sh_type = EGET(shdr[s].sh_type); \
319 if (sh_type == SHT_REL) { \ 558 if (sh_type == SHT_REL) { \
320 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 559 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
321 rela = NULL; \ 560 rela = NULL; \
322 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 561 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
323 } else if (sh_type == SHT_RELA) { \ 562 } else if (sh_type == SHT_RELA) { \
324 rel = NULL; \ 563 rel = NULL; \
325 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 564 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
326 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 565 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
327 } else \ 566 } else \
328 continue; \ 567 continue; \
329 /* now see if any of the relocs are in the .text */ \ 568 /* now see if any of the relocs are in the .text */ \
330 for (r = 0; r < rmax; ++r) { \ 569 for (r = 0; r < rmax; ++r) { \
345 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 584 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
346 if (be_verbose <= 2) continue; \ 585 if (be_verbose <= 2) continue; \
347 } else \ 586 } else \
348 *found_textrels = 1; \ 587 *found_textrels = 1; \
349 /* locate this relocation symbol name */ \ 588 /* locate this relocation symbol name */ \
350 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 589 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
351 if ((void*)sym > (void*)elf->data_end) { \ 590 if ((void*)sym > elf->data_end) { \
352 warn("%s: corrupt ELF symbol", elf->filename); \ 591 warn("%s: corrupt ELF symbol", elf->filename); \
353 continue; \ 592 continue; \
354 } \ 593 } \
355 sym_max = ELF ## B ## _R_SYM(r_info); \ 594 sym_max = ELF ## B ## _R_SYM(r_info); \
356 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 595 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
359 sym = NULL; \ 598 sym = NULL; \
360 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 599 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
361 /* show the raw details about this reloc */ \ 600 /* show the raw details about this reloc */ \
362 printf(" %s: ", elf->base_filename); \ 601 printf(" %s: ", elf->base_filename); \
363 if (sym && sym->st_name) \ 602 if (sym && sym->st_name) \
364 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 603 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
365 else \ 604 else \
366 printf("(memory/fake?)"); \ 605 printf("(memory/data?)"); \
367 printf(" [0x%lX]", (unsigned long)r_offset); \ 606 printf(" [0x%lX]", (unsigned long)r_offset); \
368 /* now try to find the closest symbol that this rel is probably in */ \ 607 /* now try to find the closest symbol that this rel is probably in */ \
369 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 608 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
370 func = NULL; \ 609 func = NULL; \
371 offset_tmp = 0; \ 610 offset_tmp = 0; \
372 while (sym_max--) { \ 611 while (sym_max--) { \
373 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 612 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
374 func = sym; \ 613 func = sym; \
375 offset_tmp = EGET(sym->st_value); \ 614 offset_tmp = EGET(sym->st_value); \
376 } \ 615 } \
377 ++sym; \ 616 ++sym; \
378 } \ 617 } \
379 printf(" in "); \ 618 printf(" in "); \
380 if (func && func->st_name) \ 619 if (func && func->st_name) { \
381 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 620 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
621 if (r_offset > EGET(func->st_size)) \
622 printf("(optimized out: previous %s)", func_name); \
382 else \ 623 else \
383 printf("(NULL: fake?)"); \ 624 printf("%s", func_name); \
625 } else \
626 printf("(optimized out)"); \
384 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 627 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
628 if (be_verbose && objdump) { \
629 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
630 char *sysbuf; \
631 size_t syslen; \
632 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
633 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
634 sysbuf = xmalloc(syslen); \
635 if (end_addr < r_offset) \
636 /* not uncommon when things are optimized out */ \
637 end_addr = r_offset + 0x100; \
638 snprintf(sysbuf, syslen, sysfmt, \
639 objdump, \
640 (unsigned long)offset_tmp, \
641 (unsigned long)end_addr, \
642 elf->filename, \
643 (unsigned long)r_offset); \
644 fflush(stdout); \
645 if (system(sysbuf)) {/* don't care */} \
646 fflush(stdout); \
647 free(sysbuf); \
648 } \
385 } \ 649 } \
386 } } 650 } }
387 SHOW_TEXTRELS(32) 651 SHOW_TEXTRELS(32)
388 SHOW_TEXTRELS(64) 652 SHOW_TEXTRELS(64)
389 } 653 }
391 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 655 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
392 656
393 return NULL; 657 return NULL;
394} 658}
395 659
396static void rpath_security_checks(elfobj *, char *, const char *);
397static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type) 660static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
398{ 661{
399 struct stat st; 662 struct stat st;
400 switch (*item) { 663 switch (*item) {
401 case '/': break; 664 case '/': break;
407 warnf("Security problem NULL %s in %s", dt_type, elf->filename); 670 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
408 break; 671 break;
409 case '$': 672 case '$':
410 if (fstat(elf->fd, &st) != -1) 673 if (fstat(elf->fd, &st) != -1)
411 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 674 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
412 warnf("Security problem with %s='%s' in %s with mode set of %o", 675 warnf("Security problem with %s='%s' in %s with mode set of %o",
413 dt_type, item, elf->filename, st.st_mode & 07777); 676 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
414 break; 677 break;
415 default: 678 default:
416 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename); 679 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
417 break; 680 break;
418 } 681 }
682 if (fix_elf)
683 warnf("Note: RPATH has been automatically fixed, but this should be fixed in the package itself");
419} 684}
420static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 685static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
421{ 686{
422 unsigned long i, s; 687 unsigned long i;
423 char *rpath, *runpath, **r; 688 char *rpath, *runpath, **r;
424 void *strtbl_void; 689 void *strtbl_void;
425 690
426 if (!show_rpath) return; 691 if (!show_rpath) return;
427 692
438 Elf ## B ## _Off offset; \ 703 Elf ## B ## _Off offset; \
439 Elf ## B ## _Xword word; \ 704 Elf ## B ## _Xword word; \
440 /* Scan all the program headers */ \ 705 /* Scan all the program headers */ \
441 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 706 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
442 /* Just scan dynamic headers */ \ 707 /* Just scan dynamic headers */ \
443 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 708 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
444 offset = EGET(phdr[i].p_offset); \ 709 offset = EGET(phdr[i].p_offset); \
445 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 710 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
446 /* Just scan dynamic RPATH/RUNPATH headers */ \ 711 /* Just scan dynamic RPATH/RUNPATH headers */ \
447 dyn = DYN ## B (elf->data + offset); \ 712 dyn = DYN ## B (elf->vdata + offset); \
448 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 713 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
449 if (word == DT_RPATH) { \ 714 if (word == DT_RPATH) { \
450 r = &rpath; \ 715 r = &rpath; \
451 } else if (word == DT_RUNPATH) { \ 716 } else if (word == DT_RUNPATH) { \
452 r = &runpath; \ 717 r = &runpath; \
456 } \ 721 } \
457 /* Verify the memory is somewhat sane */ \ 722 /* Verify the memory is somewhat sane */ \
458 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 723 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
459 if (offset < (Elf ## B ## _Off)elf->len) { \ 724 if (offset < (Elf ## B ## _Off)elf->len) { \
460 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 725 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
461 *r = (char*)(elf->data + offset); \ 726 *r = elf->data + offset; \
462 /* cache the length in case we need to nuke this section later on */ \ 727 /* cache the length in case we need to nuke this section later on */ \
463 if (fix_elf) \ 728 if (fix_elf) \
464 offset = strlen(*r); \ 729 offset = strlen(*r); \
465 /* If quiet, don't output paths in ld.so.conf */ \ 730 /* If quiet, don't output paths in ld.so.conf */ \
466 if (be_quiet) { \ 731 if (be_quiet) { \
472 /* scan each path in : delimited list */ \ 737 /* scan each path in : delimited list */ \
473 while (start) { \ 738 while (start) { \
474 rpath_security_checks(elf, start, get_elfdtype(word)); \ 739 rpath_security_checks(elf, start, get_elfdtype(word)); \
475 end = strchr(start, ':'); \ 740 end = strchr(start, ':'); \
476 len = (end ? abs(end - start) : strlen(start)); \ 741 len = (end ? abs(end - start) : strlen(start)); \
477 if (use_ldcache) \ 742 if (use_ldcache) { \
478 for (s = 0; ldpaths[s]; ++s) \ 743 size_t n; \
744 const char *ldpath; \
745 array_for_each(ldpaths, n, ldpath) \
479 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 746 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
480 *r = end; \ 747 *r = end; \
481 /* corner case ... if RPATH reads "/usr/lib:", we want \ 748 /* corner case ... if RPATH reads "/usr/lib:", we want \
482 * to show ':' rather than '' */ \ 749 * to show ':' rather than '' */ \
483 if (end && end[1] != '\0') \ 750 if (end && end[1] != '\0') \
484 (*r)++; \ 751 (*r)++; \
485 break; \ 752 break; \
486 } \ 753 } \
754 } \
487 if (!*r || !end) \ 755 if (!*r || !end) \
488 break; \ 756 break; \
489 else \ 757 else \
490 start = start + len + 1; \ 758 start = start + len + 1; \
491 } \ 759 } \
557 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 825 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
558 else if (!be_quiet) 826 else if (!be_quiet)
559 xstrcat(ret, " - ", ret_len); 827 xstrcat(ret, " - ", ret_len);
560} 828}
561 829
830/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
562#define LDSO_CACHE_MAGIC "ld.so-" 831#define LDSO_CACHE_MAGIC "ld.so-"
563#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 832#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
564#define LDSO_CACHE_VER "1.7.0" 833#define LDSO_CACHE_VER "1.7.0"
565#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 834#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
566#define FLAG_ANY -1 835#define FLAG_ANY -1
575#define FLAG_X8664_LIB64 0x0300 844#define FLAG_X8664_LIB64 0x0300
576#define FLAG_S390_LIB64 0x0400 845#define FLAG_S390_LIB64 0x0400
577#define FLAG_POWERPC_LIB64 0x0500 846#define FLAG_POWERPC_LIB64 0x0500
578#define FLAG_MIPS64_LIBN32 0x0600 847#define FLAG_MIPS64_LIBN32 0x0600
579#define FLAG_MIPS64_LIBN64 0x0700 848#define FLAG_MIPS64_LIBN64 0x0700
849#define FLAG_X8664_LIBX32 0x0800
850#define FLAG_ARM_LIBHF 0x0900
851#define FLAG_AARCH64_LIB64 0x0a00
580 852
581static char *lookup_cache_lib(elfobj *, char *); 853#if defined(__GLIBC__) || defined(__UCLIBC__)
854
582static char *lookup_cache_lib(elfobj *elf, char *fname) 855static char *lookup_cache_lib(elfobj *elf, const char *fname)
583{ 856{
584 int fd = 0; 857 int fd;
585 char *strs; 858 char *strs;
586 static char buf[__PAX_UTILS_PATH_MAX] = ""; 859 static char buf[__PAX_UTILS_PATH_MAX] = "";
587 const char *cachefile = "/etc/ld.so.cache"; 860 const char *cachefile = root_rel_path("/etc/ld.so.cache");
588 struct stat st; 861 struct stat st;
589 862
590 typedef struct { 863 typedef struct {
591 char magic[LDSO_CACHE_MAGIC_LEN]; 864 char magic[LDSO_CACHE_MAGIC_LEN];
592 char version[LDSO_CACHE_VER_LEN]; 865 char version[LDSO_CACHE_VER_LEN];
602 libentry_t *libent; 875 libentry_t *libent;
603 876
604 if (fname == NULL) 877 if (fname == NULL)
605 return NULL; 878 return NULL;
606 879
607 if (ldcache == 0) { 880 if (ldcache == NULL) {
608 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 881 if (fstatat(root_fd, cachefile, &st, 0))
882 return NULL;
883
884 fd = openat(root_fd, cachefile, O_RDONLY);
885 if (fd == -1)
609 return NULL; 886 return NULL;
610 887
611 /* cache these values so we only map/unmap the cache file once */ 888 /* cache these values so we only map/unmap the cache file once */
612 ldcache_size = st.st_size; 889 ldcache_size = st.st_size;
613 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 890 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
614
615 close(fd); 891 close(fd);
616 892
617 if (ldcache == (caddr_t)-1) { 893 if (ldcache == MAP_FAILED) {
618 ldcache = 0; 894 ldcache = NULL;
619 return NULL; 895 return NULL;
620 } 896 }
621 897
622 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 898 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
899 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
900 {
901 munmap(ldcache, ldcache_size);
902 ldcache = NULL;
623 return NULL; 903 return NULL;
624 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
625 return NULL;
626 } 904 }
905 } else
906 header = ldcache;
627 907
628 header = (header_t *) ldcache;
629 libent = (libentry_t *) (ldcache + sizeof(header_t)); 908 libent = ldcache + sizeof(header_t);
630 strs = (char *) &libent[header->nlibs]; 909 strs = (char *) &libent[header->nlibs];
631 910
632 for (fd = 0; fd < header->nlibs; fd++) { 911 for (fd = 0; fd < header->nlibs; ++fd) {
633 /* this should be more fine grained, but for now we assume that 912 /* This should be more fine grained, but for now we assume that
634 * diff arches will not be cached together. and we ignore the 913 * diff arches will not be cached together, and we ignore the
635 * the different multilib mips cases. */ 914 * the different multilib mips cases.
915 */
636 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 916 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
637 continue; 917 continue;
638 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 918 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
639 continue; 919 continue;
640 920
641 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 921 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
642 continue; 922 continue;
923
924 /* Return first hit because that is how the ldso rolls */
643 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 925 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
926 break;
644 } 927 }
928
645 return buf; 929 return buf;
646} 930}
647 931
932#elif defined(__NetBSD__)
933static char *lookup_cache_lib(elfobj *elf, const char *fname)
934{
935 static char buf[__PAX_UTILS_PATH_MAX] = "";
936 static struct stat st;
937 size_t n;
938 char *ldpath;
939
940 array_for_each(ldpath, n, ldpath) {
941 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
942 continue; /* if the pathname is too long, or something went wrong, ignore */
943
944 if (stat(buf, &st) != 0)
945 continue; /* if the lib doesn't exist in *ldpath, look further */
946
947 /* NetBSD doesn't actually do sanity checks, it just loads the file
948 * and if that doesn't work, continues looking in other directories.
949 * This cannot easily be safely emulated, unfortunately. For now,
950 * just assume that if it exists, it's a valid library. */
951
952 return buf;
953 }
954
955 /* not found in any path */
956 return NULL;
957}
958#else
959#ifdef __ELF__
960#warning Cache support not implemented for your target
961#endif
962static char *lookup_cache_lib(elfobj *elf, const char *fname)
963{
964 return NULL;
965}
966#endif
967
968static char *lookup_config_lib(const char *fname)
969{
970 static char buf[__PAX_UTILS_PATH_MAX] = "";
971 const char *ldpath;
972 size_t n;
973
974 array_for_each(ldpaths, n, ldpath) {
975 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
976 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
977 return buf;
978 }
979
980 return NULL;
981}
648 982
649static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 983static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
650{ 984{
651 unsigned long i; 985 unsigned long i;
652 char *needed; 986 char *needed;
653 void *strtbl_void; 987 void *strtbl_void;
654 char *p; 988 char *p;
655 989
990 /*
991 * -n -> op==0 -> print all
992 * -N -> op==1 -> print requested
993 */
656 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 994 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
995 return NULL;
657 996
658 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 997 strtbl_void = elf_findsecbyname(elf, ".dynstr");
659 998
660 if (elf->phdr && strtbl_void) { 999 if (elf->phdr && strtbl_void) {
661#define SHOW_NEEDED(B) \ 1000#define SHOW_NEEDED(B) \
663 Elf ## B ## _Dyn *dyn; \ 1002 Elf ## B ## _Dyn *dyn; \
664 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1003 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
665 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1004 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
666 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1005 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
667 Elf ## B ## _Off offset; \ 1006 Elf ## B ## _Off offset; \
1007 size_t matched = 0; \
1008 /* Walk all the program headers to find the PT_DYNAMIC */ \
668 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1009 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
669 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1010 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
1011 continue; \
670 offset = EGET(phdr[i].p_offset); \ 1012 offset = EGET(phdr[i].p_offset); \
671 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1013 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
1014 continue; \
1015 /* Walk all the dynamic tags to find NEEDED entries */ \
672 dyn = DYN ## B (elf->data + offset); \ 1016 dyn = DYN ## B (elf->vdata + offset); \
673 while (EGET(dyn->d_tag) != DT_NULL) { \ 1017 while (EGET(dyn->d_tag) != DT_NULL) { \
674 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 1018 if (EGET(dyn->d_tag) == DT_NEEDED) { \
675 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1019 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
676 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1020 if (offset >= (Elf ## B ## _Off)elf->len) { \
677 ++dyn; \ 1021 ++dyn; \
678 continue; \ 1022 continue; \
679 } \ 1023 } \
680 needed = (char*)(elf->data + offset); \ 1024 needed = elf->data + offset; \
681 if (op == 0) { \ 1025 if (op == 0) { \
1026 /* -n -> print all entries */ \
682 if (!be_wewy_wewy_quiet) { \ 1027 if (!be_wewy_wewy_quiet) { \
683 if (*found_needed) xchrcat(ret, ',', ret_len); \ 1028 if (*found_needed) xchrcat(ret, ',', ret_len); \
684 if (use_ldcache) \ 1029 if (use_ldpath) { \
1030 if ((p = lookup_config_lib(needed)) != NULL) \
1031 needed = p; \
1032 } else if (use_ldcache) { \
685 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 1033 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
686 needed = p; \ 1034 needed = p; \
1035 } \
687 xstrcat(ret, needed, ret_len); \ 1036 xstrcat(ret, needed, ret_len); \
688 } \ 1037 } \
689 *found_needed = 1; \ 1038 *found_needed = 1; \
690 } else { \ 1039 } else { \
691 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1040 /* -N -> print matching entries */ \
1041 size_t n; \
1042 const char *find_lib_name; \
1043 \
1044 array_for_each(find_lib_arr, n, find_lib_name) { \
1045 int invert = 1; \
1046 if (find_lib_name[0] == '!') \
1047 invert = 0, ++find_lib_name; \
1048 if (!strcmp(find_lib_name, needed) == invert) \
1049 ++matched; \
1050 } \
1051 \
1052 if (matched == array_cnt(find_lib_arr)) { \
692 *found_lib = 1; \ 1053 *found_lib = 1; \
693 return (be_wewy_wewy_quiet ? NULL : needed); \ 1054 return (be_wewy_wewy_quiet ? NULL : find_lib); \
694 } \ 1055 } \
695 } \ 1056 } \
696 } \ 1057 } \
697 ++dyn; \ 1058 ++dyn; \
698 } \ 1059 } \
720 *found_interp = 1; \ 1081 *found_interp = 1; \
721 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1082 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
722 } 1083 }
723 SHOW_INTERP(32) 1084 SHOW_INTERP(32)
724 SHOW_INTERP(64) 1085 SHOW_INTERP(64)
1086 } else {
1087 /* Walk all the program headers to find the PT_INTERP */
1088#define SHOW_PT_INTERP(B) \
1089 if (elf->elf_class == ELFCLASS ## B) { \
1090 unsigned long i; \
1091 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1092 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1093 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1094 if (EGET(phdr[i].p_type) != PT_INTERP) \
1095 continue; \
1096 *found_interp = 1; \
1097 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1098 } \
725 } 1099 }
1100 SHOW_PT_INTERP(32)
1101 SHOW_PT_INTERP(64)
1102 }
1103
726 return NULL; 1104 return NULL;
727} 1105}
728static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1106static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
729{ 1107{
730 unsigned long i; 1108 unsigned long i;
731 struct stat s; 1109 struct stat s;
1110 bool dynamic = false;
732 1111
733 if (!show_bind) return NULL; 1112 if (!show_bind) return NULL;
734 if (!elf->phdr) return NULL; 1113 if (!elf->phdr) return NULL;
735 1114
736#define SHOW_BIND(B) \ 1115#define SHOW_BIND(B) \
738 Elf ## B ## _Dyn *dyn; \ 1117 Elf ## B ## _Dyn *dyn; \
739 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1118 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
740 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1119 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
741 Elf ## B ## _Off offset; \ 1120 Elf ## B ## _Off offset; \
742 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1121 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
743 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1122 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1123 dynamic = true; \
744 offset = EGET(phdr[i].p_offset); \ 1124 offset = EGET(phdr[i].p_offset); \
745 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1125 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
746 dyn = DYN ## B (elf->data + offset); \ 1126 dyn = DYN ## B (elf->vdata + offset); \
747 while (EGET(dyn->d_tag) != DT_NULL) { \ 1127 while (EGET(dyn->d_tag) != DT_NULL) { \
748 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1128 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
749 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1129 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
750 { \ 1130 { \
751 if (be_quiet) return NULL; \ 1131 if (be_quiet) return NULL; \
759 SHOW_BIND(32) 1139 SHOW_BIND(32)
760 SHOW_BIND(64) 1140 SHOW_BIND(64)
761 1141
762 if (be_wewy_wewy_quiet) return NULL; 1142 if (be_wewy_wewy_quiet) return NULL;
763 1143
1144 /* don't output anything if quiet mode and the ELF is static or not setuid */
764 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1145 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
765 return NULL; 1146 return NULL;
766 } else { 1147 } else {
767 *found_bind = 1; 1148 *found_bind = 1;
768 return (char *) "LAZY"; 1149 return dynamic ? "LAZY" : "STATIC";
769 } 1150 }
770} 1151}
771static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1152static char *scanelf_file_soname(elfobj *elf, char *found_soname)
772{ 1153{
773 unsigned long i; 1154 unsigned long i;
785 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1166 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
786 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1167 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
787 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1168 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
788 Elf ## B ## _Off offset; \ 1169 Elf ## B ## _Off offset; \
789 /* only look for soname in shared objects */ \ 1170 /* only look for soname in shared objects */ \
790 if (ehdr->e_type != ET_DYN) \ 1171 if (EGET(ehdr->e_type) != ET_DYN) \
791 return NULL; \ 1172 return NULL; \
792 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1173 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
793 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1174 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
794 offset = EGET(phdr[i].p_offset); \ 1175 offset = EGET(phdr[i].p_offset); \
795 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1176 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
796 dyn = DYN ## B (elf->data + offset); \ 1177 dyn = DYN ## B (elf->vdata + offset); \
797 while (EGET(dyn->d_tag) != DT_NULL) { \ 1178 while (EGET(dyn->d_tag) != DT_NULL) { \
798 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1179 if (EGET(dyn->d_tag) == DT_SONAME) { \
799 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1180 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
800 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1181 if (offset >= (Elf ## B ## _Off)elf->len) { \
801 ++dyn; \ 1182 ++dyn; \
802 continue; \ 1183 continue; \
803 } \ 1184 } \
804 soname = (char*)(elf->data + offset); \ 1185 soname = elf->data + offset; \
805 *found_soname = 1; \ 1186 *found_soname = 1; \
806 return (be_wewy_wewy_quiet ? NULL : soname); \ 1187 return (be_wewy_wewy_quiet ? NULL : soname); \
807 } \ 1188 } \
808 ++dyn; \ 1189 ++dyn; \
809 } \ 1190 } \
812 SHOW_SONAME(64) 1193 SHOW_SONAME(64)
813 } 1194 }
814 1195
815 return NULL; 1196 return NULL;
816} 1197}
1198
1199/*
1200 * We support the symbol form:
1201 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1202 * If the symbol name is empty, then all symbols are matched.
1203 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1204 * Do not rely on this output format at all.
1205 * Otherwise the symbol name is used to search (either regex or string compare).
1206 * If the first char of the symbol name is a plus ("+"), then only match
1207 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1208 * Putting modifiers in between the percent signs allows for more in depth
1209 * filters. There are groups of modifiers. If you don't specify a member
1210 * of a group, then all types in that group are matched. The current
1211 * groups and their types are:
1212 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1213 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1214 * STV group: STV_DEFAULT:p STV_INTERNAL:i STV_HIDDEN:h STV_PROTECTED:P
1215 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1216 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1217 * You can search for multiple symbols at once by seperating with a comma (",").
1218 *
1219 * Some examples:
1220 * ELFs with a weak function "foo":
1221 * scanelf -s %wf%foo <ELFs>
1222 * ELFs that define the symbol "main":
1223 * scanelf -s +main <ELFs>
1224 * scanelf -s %d%main <ELFs>
1225 * ELFs that refer to the undefined symbol "brk":
1226 * scanelf -s -brk <ELFs>
1227 * scanelf -s %u%brk <ELFs>
1228 * All global defined objects in an ELF:
1229 * scanelf -s %ogd% <ELF>
1230 */
1231static void
1232scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1233 unsigned int stt, unsigned int stb, unsigned int stv, unsigned int shn, unsigned long size)
1234{
1235 const char *this_sym;
1236 size_t n;
1237
1238 array_for_each(find_sym_arr, n, this_sym) {
1239 bool inc_notype, inc_object, inc_func, inc_file,
1240 inc_local, inc_global, inc_weak,
1241 inc_visdef, inc_intern, inc_hidden, inc_prot,
1242 inc_def, inc_undef, inc_abs, inc_common;
1243
1244 /* symbol selection! */
1245 inc_notype = inc_object = inc_func = inc_file =
1246 inc_local = inc_global = inc_weak =
1247 inc_visdef = inc_intern = inc_hidden = inc_prot =
1248 inc_def = inc_undef = inc_abs = inc_common =
1249 (*this_sym != '%');
1250
1251 /* parse the contents of %...% */
1252 if (!inc_notype) {
1253 while (*(this_sym++)) {
1254 if (*this_sym == '%') {
1255 ++this_sym;
1256 break;
1257 }
1258 switch (*this_sym) {
1259 case 'n': inc_notype = true; break;
1260 case 'o': inc_object = true; break;
1261 case 'f': inc_func = true; break;
1262 case 'F': inc_file = true; break;
1263 case 'l': inc_local = true; break;
1264 case 'g': inc_global = true; break;
1265 case 'w': inc_weak = true; break;
1266 case 'p': inc_visdef = true; break;
1267 case 'i': inc_intern = true; break;
1268 case 'h': inc_hidden = true; break;
1269 case 'P': inc_prot = true; break;
1270 case 'd': inc_def = true; break;
1271 case 'u': inc_undef = true; break;
1272 case 'a': inc_abs = true; break;
1273 case 'c': inc_common = true; break;
1274 default: err("invalid symbol selector '%c'", *this_sym);
1275 }
1276 }
1277
1278 /* If no types are matched, not match all */
1279 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1280 inc_notype = inc_object = inc_func = inc_file = true;
1281 if (!inc_local && !inc_global && !inc_weak)
1282 inc_local = inc_global = inc_weak = true;
1283 if (!inc_visdef && !inc_intern && !inc_hidden && !inc_prot)
1284 inc_visdef = inc_intern = inc_hidden = inc_prot = true;
1285 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1286 inc_def = inc_undef = inc_abs = inc_common = true;
1287
1288 /* backwards compat for defined/undefined short hand */
1289 } else if (*this_sym == '+') {
1290 inc_undef = false;
1291 ++this_sym;
1292 } else if (*this_sym == '-') {
1293 inc_def = inc_abs = inc_common = false;
1294 ++this_sym;
1295 }
1296
1297 /* filter symbols */
1298 if ((!inc_notype && stt == STT_NOTYPE ) || \
1299 (!inc_object && stt == STT_OBJECT ) || \
1300 (!inc_func && stt == STT_FUNC ) || \
1301 (!inc_file && stt == STT_FILE ) || \
1302 (!inc_local && stb == STB_LOCAL ) || \
1303 (!inc_global && stb == STB_GLOBAL ) || \
1304 (!inc_weak && stb == STB_WEAK ) || \
1305 (!inc_visdef && stv == STV_DEFAULT ) || \
1306 (!inc_intern && stv == STV_INTERNAL ) || \
1307 (!inc_hidden && stv == STV_HIDDEN ) || \
1308 (!inc_prot && stv == STV_PROTECTED) || \
1309 (!inc_def && shn && shn < SHN_LORESERVE) || \
1310 (!inc_undef && shn == SHN_UNDEF ) || \
1311 (!inc_abs && shn == SHN_ABS ) || \
1312 (!inc_common && shn == SHN_COMMON ))
1313 continue;
1314
1315 if (*this_sym == '*') {
1316 /* a "*" symbol gets you debug output */
1317 printf("%s(%s) %5lX %-15s %-15s %-15s %-15s %s\n",
1318 ((*found_sym == 0) ? "\n\t" : "\t"),
1319 elf->base_filename,
1320 size,
1321 get_elfstttype(stt),
1322 get_elfstbtype(stb),
1323 get_elfstvtype(stv),
1324 get_elfshntype(shn),
1325 symname);
1326 goto matched;
1327
1328 } else {
1329 if (g_match) {
1330 /* regex match the symbol */
1331 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1332 continue;
1333
1334 } else if (*this_sym) {
1335 /* give empty symbols a "pass", else do a normal compare */
1336 const size_t len = strlen(this_sym);
1337 if (!(strncmp(this_sym, symname, len) == 0 &&
1338 /* Accept unversioned symbol names */
1339 (symname[len] == '\0' || symname[len] == '@')))
1340 continue;
1341 }
1342
1343 if (be_semi_verbose) {
1344 char buf[1024];
1345 snprintf(buf, sizeof(buf), "%lX %s %s",
1346 size,
1347 get_elfstttype(stt),
1348 this_sym);
1349 *ret = xstrdup(buf);
1350 } else {
1351 if (*ret) xchrcat(ret, ',', ret_len);
1352 xstrcat(ret, symname, ret_len);
1353 }
1354
1355 goto matched;
1356 }
1357 }
1358
1359 return;
1360
1361 matched:
1362 *found_sym = 1;
1363}
1364
817static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1365static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
818{ 1366{
819 unsigned long i;
820 char *ret; 1367 char *ret;
821 void *symtab_void, *strtab_void; 1368 void *symtab_void, *strtab_void;
822 1369
823 if (!find_sym) return NULL; 1370 if (!find_sym) return NULL;
824 ret = find_sym; 1371 ret = NULL;
825 1372
826 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1373 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
827 1374
828 if (symtab_void && strtab_void) { 1375 if (symtab_void && strtab_void) {
829#define FIND_SYM(B) \ 1376#define FIND_SYM(B) \
830 if (elf->elf_class == ELFCLASS ## B) { \ 1377 if (elf->elf_class == ELFCLASS ## B) { \
831 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1378 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
832 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1379 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
833 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1380 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
834 unsigned long cnt = EGET(symtab->sh_entsize); \ 1381 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
835 char *symname; \ 1382 char *symname; \
1383 size_t ret_len = 0; \
836 if (cnt) \ 1384 if (cnt) \
837 cnt = EGET(symtab->sh_size) / cnt; \ 1385 cnt = EGET(symtab->sh_size) / cnt; \
838 for (i = 0; i < cnt; ++i) { \ 1386 for (i = 0; i < cnt; ++i) { \
1387 if ((void*)sym > elf->data_end) { \
1388 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1389 goto break_out; \
1390 } \
839 if (sym->st_name) { \ 1391 if (sym->st_name) { \
1392 /* make sure the symbol name is in acceptable memory range */ \
840 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1393 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
841 if ((void*)symname > (void*)elf->data_end) { \ 1394 if ((void*)symname > elf->data_end) { \
842 warnf("%s: corrupt ELF symbols", elf->filename); \ 1395 warnf("%s: corrupt ELF symbols", elf->filename); \
1396 ++sym; \
843 continue; \ 1397 continue; \
844 } \ 1398 } \
845 if (*find_sym == '*') { \ 1399 scanelf_match_symname(elf, found_sym, \
846 printf("%s(%s) %5lX %15s %s\n", \ 1400 &ret, &ret_len, symname, \
847 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1401 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
848 elf->base_filename, \ 1402 ELF##B##_ST_BIND(EGET(sym->st_info)), \
849 (unsigned long)sym->st_size, \ 1403 ELF##B##_ST_VISIBILITY(EGET(sym->st_other)), \
850 get_elfstttype(sym->st_info), \ 1404 EGET(sym->st_shndx), \
851 symname); \ 1405 /* st_size can be 64bit, but no one is really that big, so screw em */ \
852 *found_sym = 1; \ 1406 EGET(sym->st_size)); \
853 } else { \
854 char *this_sym, *next_sym; \
855 this_sym = find_sym; \
856 do { \
857 next_sym = strchr(this_sym, ','); \
858 if (next_sym == NULL) \
859 next_sym = this_sym + strlen(this_sym); \
860 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
861 (strcmp(symname, versioned_symname) == 0)) { \
862 ret = this_sym; \
863 (*found_sym)++; \
864 goto break_out; \
865 } \
866 this_sym = next_sym + 1; \
867 } while (*next_sym != '\0'); \
868 } \
869 } \ 1407 } \
870 ++sym; \ 1408 ++sym; \
871 } } 1409 } \
1410 }
872 FIND_SYM(32) 1411 FIND_SYM(32)
873 FIND_SYM(64) 1412 FIND_SYM(64)
874 } 1413 }
875 1414
876break_out: 1415break_out:
879 if (*find_sym != '*' && *found_sym) 1418 if (*find_sym != '*' && *found_sym)
880 return ret; 1419 return ret;
881 if (be_quiet) 1420 if (be_quiet)
882 return NULL; 1421 return NULL;
883 else 1422 else
884 return (char *)" - "; 1423 return " - ";
885} 1424}
886 1425
887
888static char *scanelf_file_sections(elfobj *elf, char *found_section) 1426static const char *scanelf_file_sections(elfobj *elf, char *found_section)
889{ 1427{
890 if (!find_section) 1428 if (!find_section)
891 return NULL; 1429 return NULL;
892 1430
893#define FIND_SECTION(B) \ 1431#define FIND_SECTION(B) \
894 if (elf->elf_class == ELFCLASS ## B) { \ 1432 if (elf->elf_class == ELFCLASS ## B) { \
1433 size_t matched, n; \
1434 int invert; \
1435 const char *section_name; \
895 Elf ## B ## _Shdr *section; \ 1436 Elf ## B ## _Shdr *section; \
1437 \
1438 matched = 0; \
1439 array_for_each(find_section_arr, n, section_name) { \
1440 invert = (*section_name == '!' ? 1 : 0); \
896 section = SHDR ## B (elf_findsecbyname(elf, find_section)); \ 1441 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
897 if (section != NULL) \ 1442 if ((section == NULL && invert) || (section != NULL && !invert)) \
1443 ++matched; \
1444 } \
1445 \
1446 if (matched == array_cnt(find_section_arr)) \
898 *found_section = 1; \ 1447 *found_section = 1; \
899 } 1448 }
900 FIND_SECTION(32) 1449 FIND_SECTION(32)
901 FIND_SECTION(64) 1450 FIND_SECTION(64)
902 1451
903
904 if (be_wewy_wewy_quiet) return NULL; 1452 if (be_wewy_wewy_quiet)
1453 return NULL;
905 1454
906 if (*found_section) 1455 if (*found_section)
907 return find_section; 1456 return find_section;
908 1457
909 if (be_quiet) 1458 if (be_quiet)
910 return NULL; 1459 return NULL;
911 else 1460 else
912 return (char *)" - "; 1461 return " - ";
913} 1462}
914 1463
915/* scan an elf file and show all the fun stuff */ 1464/* scan an elf file and show all the fun stuff */
916#define prints(str) write(fileno(stdout), str, strlen(str)) 1465#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
917static int scanelf_elfobj(elfobj *elf) 1466static int scanelf_elfobj(elfobj *elf)
918{ 1467{
919 unsigned long i; 1468 unsigned long i;
920 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1469 char found_pax, found_phdr, found_relro, found_load, found_textrel,
921 found_rpath, found_needed, found_interp, found_bind, found_soname, 1470 found_rpath, found_needed, found_interp, found_bind, found_soname,
922 found_sym, found_lib, found_file, found_textrels, found_section; 1471 found_sym, found_lib, found_file, found_textrels, found_section;
923 static char *out_buffer = NULL; 1472 static char *out_buffer = NULL;
924 static size_t out_len; 1473 static size_t out_len;
925 1474
926 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1475 found_pax = found_phdr = found_relro = found_load = found_textrel = \
935 printf("%s: scanning file\n", elf->filename); 1484 printf("%s: scanning file\n", elf->filename);
936 1485
937 /* init output buffer */ 1486 /* init output buffer */
938 if (!out_buffer) { 1487 if (!out_buffer) {
939 out_len = sizeof(char) * 80; 1488 out_len = sizeof(char) * 80;
940 out_buffer = (char*)xmalloc(out_len); 1489 out_buffer = xmalloc(out_len);
941 } 1490 }
942 *out_buffer = '\0'; 1491 *out_buffer = '\0';
943 1492
944 /* show the header */ 1493 /* show the header */
945 if (!be_quiet && show_banner) { 1494 if (!be_quiet && show_banner) {
946 for (i = 0; out_format[i]; ++i) { 1495 for (i = 0; out_format[i]; ++i) {
947 if (!IS_MODIFIER(out_format[i])) continue; 1496 if (!IS_MODIFIER(out_format[i])) continue;
948 1497
949 switch (out_format[++i]) { 1498 switch (out_format[++i]) {
1499 case '+': break;
950 case '%': break; 1500 case '%': break;
951 case '#': break; 1501 case '#': break;
952 case 'F': 1502 case 'F':
953 case 'p': 1503 case 'p':
954 case 'f': prints("FILE "); found_file = 1; break; 1504 case 'f': prints("FILE "); found_file = 1; break;
955 case 'o': prints(" TYPE "); break; 1505 case 'o': prints(" TYPE "); break;
956 case 'x': prints(" PAX "); break; 1506 case 'x': prints(" PAX "); break;
957 case 'e': prints("STK/REL/PTL "); break; 1507 case 'e': prints("STK/REL/PTL "); break;
958 case 't': prints("TEXTREL "); break; 1508 case 't': prints("TEXTREL "); break;
959 case 'r': prints("RPATH "); break; 1509 case 'r': prints("RPATH "); break;
1510 case 'M': prints("CLASS "); break;
1511 case 'l':
960 case 'n': prints("NEEDED "); break; 1512 case 'n': prints("NEEDED "); break;
961 case 'i': prints("INTERP "); break; 1513 case 'i': prints("INTERP "); break;
962 case 'b': prints("BIND "); break; 1514 case 'b': prints("BIND "); break;
1515 case 'Z': prints("SIZE "); break;
963 case 'S': prints("SONAME "); break; 1516 case 'S': prints("SONAME "); break;
964 case 's': prints("SYM "); break; 1517 case 's': prints("SYM "); break;
965 case 'N': prints("LIB "); break; 1518 case 'N': prints("LIB "); break;
966 case 'T': prints("TEXTRELS "); break; 1519 case 'T': prints("TEXTRELS "); break;
967 case 'k': prints("SECTION "); break; 1520 case 'k': prints("SECTION "); break;
1521 case 'a': prints("ARCH "); break;
1522 case 'I': prints("OSABI "); break;
1523 case 'Y': prints("EABI "); break;
1524 case 'O': prints("PERM "); break;
1525 case 'D': prints("ENDIAN "); break;
968 default: warnf("'%c' has no title ?", out_format[i]); 1526 default: warnf("'%c' has no title ?", out_format[i]);
969 } 1527 }
970 } 1528 }
971 if (!found_file) prints("FILE "); 1529 if (!found_file) prints("FILE ");
972 prints("\n"); 1530 prints("\n");
976 1534
977 /* dump all the good stuff */ 1535 /* dump all the good stuff */
978 for (i = 0; out_format[i]; ++i) { 1536 for (i = 0; out_format[i]; ++i) {
979 const char *out; 1537 const char *out;
980 const char *tmp; 1538 const char *tmp;
981 1539 static char ubuf[sizeof(unsigned long)*2];
982 if (!IS_MODIFIER(out_format[i])) { 1540 if (!IS_MODIFIER(out_format[i])) {
983 xchrcat(&out_buffer, out_format[i], &out_len); 1541 xchrcat(&out_buffer, out_format[i], &out_len);
984 continue; 1542 continue;
985 } 1543 }
986 1544
987 out = NULL; 1545 out = NULL;
988 be_wewy_wewy_quiet = (out_format[i] == '#'); 1546 be_wewy_wewy_quiet = (out_format[i] == '#');
1547 be_semi_verbose = (out_format[i] == '+');
989 switch (out_format[++i]) { 1548 switch (out_format[++i]) {
1549 case '+':
990 case '%': 1550 case '%':
991 case '#': 1551 case '#':
992 xchrcat(&out_buffer, out_format[i], &out_len); break; 1552 xchrcat(&out_buffer, out_format[i], &out_len); break;
993 case 'F': 1553 case 'F':
994 found_file = 1; 1554 found_file = 1;
1020 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1580 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1021 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1581 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1022 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1582 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1023 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1583 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1024 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1584 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1585 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1586 case 'D': out = get_endian(elf); break;
1587 case 'O': out = strfileperms(elf->filename); break;
1025 case 'n': 1588 case 'n':
1026 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1589 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1027 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1590 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1028 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1591 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1029 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1592 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1030 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1593 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1031 case 'k': out = scanelf_file_sections(elf, &found_section); break; 1594 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1595 case 'a': out = get_elfemtype(elf); break;
1596 case 'I': out = get_elfosabi(elf); break;
1597 case 'Y': out = get_elf_eabi(elf); break;
1598 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
1032 default: warnf("'%c' has no scan code?", out_format[i]); 1599 default: warnf("'%c' has no scan code?", out_format[i]);
1033 } 1600 }
1034 if (out) { 1601 if (out)
1035 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
1036 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
1037 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1038 else
1039 xstrcat(&out_buffer, out, &out_len); 1602 xstrcat(&out_buffer, out, &out_len);
1040 }
1041 } 1603 }
1042 1604
1043#define FOUND_SOMETHING() \ 1605#define FOUND_SOMETHING() \
1044 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1606 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1045 found_rpath || found_needed || found_interp || found_bind || \ 1607 found_rpath || found_needed || found_interp || found_bind || \
1059 1621
1060/* scan a single elf */ 1622/* scan a single elf */
1061static int scanelf_elf(const char *filename, int fd, size_t len) 1623static int scanelf_elf(const char *filename, int fd, size_t len)
1062{ 1624{
1063 int ret = 1; 1625 int ret = 1;
1626 size_t n;
1627 const char *match_etype;
1064 elfobj *elf; 1628 elfobj *elf;
1065 1629
1066 /* verify this is real ELF */ 1630 /* Verify this is a real ELF */
1067 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) { 1631 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1068 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 1632 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1069 return ret; 1633 return 2;
1070 } 1634 }
1635
1636 /* Possibly filter based on ELF bitness */
1071 switch (match_bits) { 1637 switch (match_bits) {
1072 case 32: 1638 case 32:
1073 if (elf->elf_class != ELFCLASS32) 1639 if (elf->elf_class != ELFCLASS32)
1074 goto label_done; 1640 goto done;
1075 break; 1641 break;
1076 case 64: 1642 case 64:
1077 if (elf->elf_class != ELFCLASS64) 1643 if (elf->elf_class != ELFCLASS64)
1078 goto label_done; 1644 goto done;
1079 break; 1645 break;
1080 default: break;
1081 }
1082 if (strlen(match_etypes)) {
1083 char sbuf[126];
1084 strncpy(sbuf, match_etypes, sizeof(sbuf));
1085 if (strchr(match_etypes, ',') != NULL) {
1086 char *p;
1087 while((p = strrchr(sbuf, ',')) != NULL) {
1088 *p = 0;
1089 if (atoi(p+1) == get_etype(elf))
1090 goto label_ret;
1091 }
1092 } 1646 }
1093 if (atoi(sbuf) != get_etype(elf)) 1647
1648 /* Possibly filter based on the ELF's e_type field */
1649 array_for_each(match_etypes, n, match_etype)
1650 if (etype_lookup(match_etype) == get_etype(elf))
1651 goto scanit;
1652 if (array_cnt(match_etypes))
1094 goto label_done; 1653 goto done;
1095 }
1096 1654
1097label_ret: 1655 scanit:
1098 ret = scanelf_elfobj(elf); 1656 ret = scanelf_elfobj(elf);
1099 1657
1100label_done: 1658 done:
1101 unreadelf(elf); 1659 unreadelf(elf);
1102 return ret; 1660 return ret;
1103} 1661}
1104 1662
1105/* scan an archive of elfs */ 1663/* scan an archive of elfs */
1112 1670
1113 ar = ar_open_fd(filename, fd); 1671 ar = ar_open_fd(filename, fd);
1114 if (ar == NULL) 1672 if (ar == NULL)
1115 return 1; 1673 return 1;
1116 1674
1117 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0); 1675 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1118 while ((m=ar_next(ar)) != NULL) { 1676 while ((m = ar_next(ar)) != NULL) {
1677 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1678 if (cur_pos == -1)
1679 errp("lseek() failed");
1119 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size); 1680 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1120 if (elf) { 1681 if (elf) {
1121 scanelf_elfobj(elf); 1682 scanelf_elfobj(elf);
1122 unreadelf(elf); 1683 unreadelf(elf);
1123 } 1684 }
1124 } 1685 }
1125 munmap(ar_buffer, len); 1686 munmap(ar_buffer, len);
1126 1687
1127 return 0; 1688 return 0;
1128} 1689}
1129/* scan a file which may be an elf or an archive or some other magical beast */ 1690/* scan a file which may be an elf or an archive or some other magical beast */
1130static void scanelf_file(const char *filename) 1691static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1131{ 1692{
1693 const struct stat *st = st_cache;
1132 struct stat st; 1694 struct stat symlink_st;
1133 int fd; 1695 int fd;
1134 1696
1135 /* make sure 'filename' exists */
1136 if (lstat(filename, &st) == -1) {
1137 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1138 return;
1139 }
1140
1141 /* always handle regular files and handle symlinked files if no -y */ 1697 /* always handle regular files and handle symlinked files if no -y */
1142 if (S_ISLNK(st.st_mode)) { 1698 if (S_ISLNK(st->st_mode)) {
1143 if (!scan_symlink) return; 1699 if (!scan_symlink)
1144 stat(filename, &st); 1700 return 1;
1701 fstatat(dir_fd, filename, &symlink_st, 0);
1702 st = &symlink_st;
1145 } 1703 }
1704
1146 if (!S_ISREG(st.st_mode)) { 1705 if (!S_ISREG(st->st_mode)) {
1147 if (be_verbose > 2) printf("%s: skipping non-file\n", filename); 1706 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1148 return; 1707 return 1;
1149 } 1708 }
1150 1709
1151 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1) 1710 if (match_perms) {
1711 if ((st->st_mode | match_perms) != st->st_mode)
1712 return 1;
1713 }
1714 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1715 if (fd == -1) {
1716 if (fix_elf && errno == ETXTBSY)
1717 warnp("%s: could not fix", filename);
1718 else if (be_verbose > 2)
1719 printf("%s: skipping file: %s\n", filename, strerror(errno));
1152 return; 1720 return 1;
1721 }
1153 1722
1154 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives) 1723 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1155 /* if it isn't an ELF, maybe it's an .a archive */ 1724 /* if it isn't an ELF, maybe it's an .a archive */
1725 if (scan_archives)
1156 scanelf_archive(filename, fd, st.st_size); 1726 scanelf_archive(filename, fd, st->st_size);
1157 1727
1728 /*
1729 * unreadelf() implicitly closes its fd, so only close it
1730 * when we are returning it in the non-ELF case
1731 */
1158 close(fd); 1732 close(fd);
1733 }
1734
1735 return 0;
1159} 1736}
1160 1737
1161/* scan a directory for ET_EXEC files and print when we find one */ 1738/* scan a directory for ET_EXEC files and print when we find one */
1162static void scanelf_dir(const char *path) 1739static int scanelf_dirat(int dir_fd, const char *path)
1163{ 1740{
1164 register DIR *dir; 1741 register DIR *dir;
1165 register struct dirent *dentry; 1742 register struct dirent *dentry;
1166 struct stat st_top, st; 1743 struct stat st_top, st;
1167 char buf[__PAX_UTILS_PATH_MAX]; 1744 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1168 size_t pathlen = 0, len = 0; 1745 size_t pathlen = 0, len = 0;
1746 int ret = 0;
1747 int subdir_fd;
1169 1748
1170 /* make sure path exists */ 1749 /* make sure path exists */
1171 if (lstat(path, &st_top) == -1) { 1750 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1172 if (be_verbose > 2) printf("%s: does not exist\n", path); 1751 if (be_verbose > 2) printf("%s: does not exist\n", path);
1173 return; 1752 return 1;
1174 } 1753 }
1175 1754
1176 /* ok, if it isn't a directory, assume we can open it */ 1755 /* ok, if it isn't a directory, assume we can open it */
1177 if (!S_ISDIR(st_top.st_mode)) { 1756 if (!S_ISDIR(st_top.st_mode))
1178 scanelf_file(path); 1757 return scanelf_fileat(dir_fd, path, &st_top);
1179 return;
1180 }
1181 1758
1182 /* now scan the dir looking for fun stuff */ 1759 /* now scan the dir looking for fun stuff */
1183 if ((dir = opendir(path)) == NULL) { 1760 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1184 warnf("could not opendir %s: %s", path, strerror(errno)); 1761 if (subdir_fd == -1)
1762 dir = NULL;
1763 else
1764 dir = fdopendir(subdir_fd);
1765 if (dir == NULL) {
1766 if (subdir_fd != -1)
1767 close(subdir_fd);
1768 else if (be_verbose > 2)
1769 printf("%s: skipping dir: %s\n", path, strerror(errno));
1185 return; 1770 return 1;
1186 } 1771 }
1187 if (be_verbose > 1) printf("%s: scanning dir\n", path); 1772 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1188 1773
1189 pathlen = strlen(path); 1774 subpath = stpcpy(buf, path);
1775 if (subpath[-1] != '/')
1776 *subpath++ = '/';
1777 pathlen = subpath - buf;
1190 while ((dentry = readdir(dir))) { 1778 while ((dentry = readdir(dir))) {
1191 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1779 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1192 continue; 1780 continue;
1781
1782 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1783 continue;
1784
1193 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1785 len = strlen(dentry->d_name);
1194 if (len >= sizeof(buf)) { 1786 if (len + pathlen + 1 >= sizeof(buf)) {
1195 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1787 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1196 (unsigned long)len, (unsigned long)sizeof(buf)); 1788 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1197 continue; 1789 continue;
1198 } 1790 }
1199 sprintf(buf, "%s/%s", path, dentry->d_name); 1791 memcpy(subpath, dentry->d_name, len);
1200 if (lstat(buf, &st) != -1) { 1792 subpath[len] = '\0';
1793
1201 if (S_ISREG(st.st_mode)) 1794 if (S_ISREG(st.st_mode))
1202 scanelf_file(buf); 1795 ret = scanelf_fileat(dir_fd, buf, &st);
1203 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1796 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1204 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1797 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1205 scanelf_dir(buf); 1798 ret = scanelf_dirat(dir_fd, buf);
1206 }
1207 } 1799 }
1208 } 1800 }
1209 closedir(dir); 1801 closedir(dir);
1210}
1211 1802
1803 return ret;
1804}
1805static int scanelf_dir(const char *path)
1806{
1807 return scanelf_dirat(root_fd, root_rel_path(path));
1808}
1809
1212static int scanelf_from_file(char *filename) 1810static int scanelf_from_file(const char *filename)
1213{ 1811{
1214 FILE *fp = NULL; 1812 FILE *fp;
1215 char *p; 1813 char *p, *path;
1216 char path[__PAX_UTILS_PATH_MAX]; 1814 size_t len;
1815 int ret;
1217 1816
1218 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1817 if (strcmp(filename, "-") == 0)
1219 fp = stdin; 1818 fp = stdin;
1220 else if ((fp = fopen(filename, "r")) == NULL) 1819 else if ((fp = fopen(filename, "r")) == NULL)
1221 return 1; 1820 return 1;
1222 1821
1223 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1822 path = NULL;
1823 len = 0;
1824 ret = 0;
1825 while (getline(&path, &len, fp) != -1) {
1224 if ((p = strchr(path, '\n')) != NULL) 1826 if ((p = strchr(path, '\n')) != NULL)
1225 *p = 0; 1827 *p = 0;
1226 search_path = path; 1828 search_path = path;
1227 scanelf_dir(path); 1829 ret = scanelf_dir(path);
1228 } 1830 }
1831 free(path);
1832
1229 if (fp != stdin) 1833 if (fp != stdin)
1230 fclose(fp); 1834 fclose(fp);
1835
1231 return 0; 1836 return ret;
1232} 1837}
1233 1838
1839#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1840
1234static int load_ld_so_conf(int i, const char *fname) 1841static int _load_ld_cache_config(const char *fname)
1235{ 1842{
1236 FILE *fp = NULL; 1843 FILE *fp = NULL;
1237 char *p; 1844 char *p, *path;
1238 char path[__PAX_UTILS_PATH_MAX]; 1845 size_t len;
1846 int curr_fd = -1;
1239 1847
1240 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1848 fp = fopenat_r(root_fd, root_rel_path(fname));
1849 if (fp == NULL)
1241 return i; 1850 return -1;
1242 1851
1243 if ((fp = fopen(fname, "r")) == NULL) 1852 path = NULL;
1244 return i; 1853 len = 0;
1245 1854 while (getline(&path, &len, fp) != -1) {
1246 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1247 if ((p = strrchr(path, '\r')) != NULL) 1855 if ((p = strrchr(path, '\r')) != NULL)
1248 *p = 0; 1856 *p = 0;
1249 if ((p = strchr(path, '\n')) != NULL) 1857 if ((p = strchr(path, '\n')) != NULL)
1250 *p = 0; 1858 *p = 0;
1251#ifdef HAVE_GLOB 1859
1252 // recursive includes of the same file will make this segfault. 1860 /* recursive includes of the same file will make this segfault. */
1253 if ((*path == 'i') && (strncmp(path, "include", 7) == 0) && isblank(path[7])) { 1861 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1254 glob64_t gl; 1862 glob_t gl;
1255 size_t x; 1863 size_t x;
1256 char gpath[__PAX_UTILS_PATH_MAX]; 1864 const char *gpath;
1257 1865
1258 gpath[sizeof(gpath)] = 0; 1866 /* re-use existing path buffer ... need to be creative */
1259
1260 if (path[8] != '/') 1867 if (path[8] != '/')
1261 snprintf(gpath, sizeof(gpath)-1, "/etc/%s", &path[8]); 1868 gpath = memcpy(path + 3, "/etc/", 5);
1262 else 1869 else
1263 strncpy(gpath, &path[8], sizeof(gpath)-1); 1870 gpath = path + 8;
1871 if (root_fd != AT_FDCWD) {
1872 if (curr_fd == -1) {
1873 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1874 if (fchdir(root_fd))
1875 errp("unable to change to root dir");
1876 }
1877 gpath = root_rel_path(gpath);
1878 }
1264 1879
1265 if ((glob64(gpath, 0, NULL, &gl)) == 0) { 1880 if (glob(gpath, 0, NULL, &gl) == 0) {
1266 for (x = 0; x < gl.gl_pathc; ++x) { 1881 for (x = 0; x < gl.gl_pathc; ++x) {
1267 /* try to avoid direct loops */ 1882 /* try to avoid direct loops */
1268 if (strcmp(gl.gl_pathv[x], fname) == 0) 1883 if (strcmp(gl.gl_pathv[x], fname) == 0)
1269 continue; 1884 continue;
1270 i = load_ld_so_conf(i, gl.gl_pathv[x]); 1885 _load_ld_cache_config(gl.gl_pathv[x]);
1271 if (i + 1 >= sizeof(ldpaths) / sizeof(*ldpaths)) {
1272 globfree64(&gl);
1273 return i;
1274 }
1275 } 1886 }
1276 globfree64 (&gl); 1887 globfree(&gl);
1888 }
1889
1890 /* failed globs are ignored by glibc */
1277 continue; 1891 continue;
1278 } else
1279 abort();
1280 } 1892 }
1281#endif 1893
1282 if (*path != '/') 1894 if (*path != '/')
1283 continue; 1895 continue;
1284 1896
1285 ldpaths[i++] = xstrdup(path); 1897 xarraypush_str(ldpaths, path);
1286
1287 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1288 break;
1289 } 1898 }
1290 ldpaths[i] = NULL; 1899 free(path);
1291 1900
1292 fclose(fp); 1901 fclose(fp);
1902
1903 if (curr_fd != -1) {
1904 if (fchdir(curr_fd))
1905 {/* don't care */}
1906 close(curr_fd);
1907 }
1908
1293 return i; 1909 return 0;
1910}
1911
1912#elif defined(__FreeBSD__) || defined(__DragonFly__)
1913
1914static int _load_ld_cache_config(const char *fname)
1915{
1916 FILE *fp = NULL;
1917 char *b = NULL, *p;
1918 struct elfhints_hdr hdr;
1919
1920 fp = fopenat_r(root_fd, root_rel_path(fname));
1921 if (fp == NULL)
1922 return -1;
1923
1924 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1925 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1926 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1927 {
1928 fclose(fp);
1929 return -1;
1930 }
1931
1932 b = xmalloc(hdr.dirlistlen + 1);
1933 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1934 fclose(fp);
1935 free(b);
1936 return -1;
1937 }
1938
1939 while ((p = strsep(&b, ":"))) {
1940 if (*p == '\0')
1941 continue;
1942 xarraypush_str(ldpaths, p);
1943 }
1944
1945 free(b);
1946 fclose(fp);
1947 return 0;
1948}
1949
1950#else
1951#ifdef __ELF__
1952#warning Cache config support not implemented for your target
1953#endif
1954static int _load_ld_cache_config(const char *fname)
1955{
1956 return 0;
1957}
1958#endif
1959
1960static void load_ld_cache_config(const char *fname)
1961{
1962 bool scan_l, scan_ul, scan_ull;
1963 size_t n;
1964 const char *ldpath;
1965
1966 _load_ld_cache_config(fname);
1967
1968 scan_l = scan_ul = scan_ull = false;
1969 array_for_each(ldpaths, n, ldpath) {
1970 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1971 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1972 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1973 }
1974
1975 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1976 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1977 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1294} 1978}
1295 1979
1296/* scan /etc/ld.so.conf for paths */ 1980/* scan /etc/ld.so.conf for paths */
1297static void scanelf_ldpath() 1981static void scanelf_ldpath(void)
1298{ 1982{
1299 char scan_l, scan_ul, scan_ull; 1983 size_t n;
1300 int i = 0; 1984 const char *ldpath;
1301 1985
1302 if (!ldpaths[0]) 1986 array_for_each(ldpaths, n, ldpath)
1303 err("Unable to load any paths from ld.so.conf");
1304
1305 scan_l = scan_ul = scan_ull = 0;
1306
1307 while (ldpaths[i]) {
1308 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1309 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1310 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1311 scanelf_dir(ldpaths[i]); 1987 scanelf_dir(ldpath);
1312 ++i;
1313 }
1314
1315 if (!scan_l) scanelf_dir("/lib");
1316 if (!scan_ul) scanelf_dir("/usr/lib");
1317 if (!scan_ull) scanelf_dir("/usr/local/lib");
1318} 1988}
1319 1989
1320/* scan env PATH for paths */ 1990/* scan env PATH for paths */
1321static void scanelf_envpath() 1991static void scanelf_envpath(void)
1322{ 1992{
1323 char *path, *p; 1993 char *path, *p;
1324 1994
1325 path = getenv("PATH"); 1995 path = getenv("PATH");
1326 if (!path) 1996 if (!path)
1333 } 2003 }
1334 2004
1335 free(path); 2005 free(path);
1336} 2006}
1337 2007
1338/* usage / invocation handling functions */ 2008/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1339#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:BhV" 2009#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1340#define a_argument required_argument 2010#define a_argument required_argument
1341static struct option const long_opts[] = { 2011static struct option const long_opts[] = {
1342 {"path", no_argument, NULL, 'p'}, 2012 {"path", no_argument, NULL, 'p'},
1343 {"ldpath", no_argument, NULL, 'l'}, 2013 {"ldpath", no_argument, NULL, 'l'},
2014 {"use-ldpath",no_argument, NULL, 129},
2015 {"root", a_argument, NULL, 128},
1344 {"recursive", no_argument, NULL, 'R'}, 2016 {"recursive", no_argument, NULL, 'R'},
1345 {"mount", no_argument, NULL, 'm'}, 2017 {"mount", no_argument, NULL, 'm'},
1346 {"symlink", no_argument, NULL, 'y'}, 2018 {"symlink", no_argument, NULL, 'y'},
1347 {"archives", no_argument, NULL, 'A'}, 2019 {"archives", no_argument, NULL, 'A'},
1348 {"ldcache", no_argument, NULL, 'L'}, 2020 {"ldcache", no_argument, NULL, 'L'},
1361 {"lib", a_argument, NULL, 'N'}, 2033 {"lib", a_argument, NULL, 'N'},
1362 {"gmatch", no_argument, NULL, 'g'}, 2034 {"gmatch", no_argument, NULL, 'g'},
1363 {"textrels", no_argument, NULL, 'T'}, 2035 {"textrels", no_argument, NULL, 'T'},
1364 {"etype", a_argument, NULL, 'E'}, 2036 {"etype", a_argument, NULL, 'E'},
1365 {"bits", a_argument, NULL, 'M'}, 2037 {"bits", a_argument, NULL, 'M'},
2038 {"endian", no_argument, NULL, 'D'},
2039 {"osabi", no_argument, NULL, 'I'},
2040 {"eabi", no_argument, NULL, 'Y'},
2041 {"perms", a_argument, NULL, 'O'},
2042 {"size", no_argument, NULL, 'Z'},
1366 {"all", no_argument, NULL, 'a'}, 2043 {"all", no_argument, NULL, 'a'},
1367 {"quiet", no_argument, NULL, 'q'}, 2044 {"quiet", no_argument, NULL, 'q'},
1368 {"verbose", no_argument, NULL, 'v'}, 2045 {"verbose", no_argument, NULL, 'v'},
1369 {"format", a_argument, NULL, 'F'}, 2046 {"format", a_argument, NULL, 'F'},
1370 {"from", a_argument, NULL, 'f'}, 2047 {"from", a_argument, NULL, 'f'},
1371 {"file", a_argument, NULL, 'o'}, 2048 {"file", a_argument, NULL, 'o'},
2049 {"nocolor", no_argument, NULL, 'C'},
1372 {"nobanner", no_argument, NULL, 'B'}, 2050 {"nobanner", no_argument, NULL, 'B'},
1373 {"help", no_argument, NULL, 'h'}, 2051 {"help", no_argument, NULL, 'h'},
1374 {"version", no_argument, NULL, 'V'}, 2052 {"version", no_argument, NULL, 'V'},
1375 {NULL, no_argument, NULL, 0x0} 2053 {NULL, no_argument, NULL, 0x0}
1376}; 2054};
1377 2055
1378static const char *opts_help[] = { 2056static const char * const opts_help[] = {
1379 "Scan all directories in PATH environment", 2057 "Scan all directories in PATH environment",
1380 "Scan all directories in /etc/ld.so.conf", 2058 "Scan all directories in /etc/ld.so.conf",
2059 "Use ld.so.conf to show full path (use with -r/-n)",
2060 "Root directory (use with -l or -p)",
1381 "Scan directories recursively", 2061 "Scan directories recursively",
1382 "Don't recursively cross mount points", 2062 "Don't recursively cross mount points",
1383 "Don't scan symlinks", 2063 "Don't scan symlinks",
1384 "Scan archives (.a files)", 2064 "Scan archives (.a files)",
1385 "Utilize ld.so.cache information (use with -r/-n)", 2065 "Utilize ld.so.cache to show full path (use with -r/-n)",
1386 "Try and 'fix' bad things (use with -r/-e)", 2066 "Try and 'fix' bad things (use with -r/-e)",
1387 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n", 2067 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1388 "Print PaX markings", 2068 "Print PaX markings",
1389 "Print GNU_STACK/PT_LOAD markings", 2069 "Print GNU_STACK/PT_LOAD markings",
1390 "Print TEXTREL information", 2070 "Print TEXTREL information",
1394 "Print BIND information", 2074 "Print BIND information",
1395 "Print SONAME information", 2075 "Print SONAME information",
1396 "Find a specified symbol", 2076 "Find a specified symbol",
1397 "Find a specified section", 2077 "Find a specified section",
1398 "Find a specified library", 2078 "Find a specified library",
1399 "Use strncmp to match libraries. (use with -N)", 2079 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1400 "Locate cause of TEXTREL", 2080 "Locate cause of TEXTREL",
1401 "Print only ELF files matching numeric constant type", 2081 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1402 "Print only ELF files matching numeric bits", 2082 "Print only ELF files matching numeric bits",
1403 "Print all scanned info (-x -e -t -r -b)\n", 2083 "Print Endianness",
2084 "Print OSABI",
2085 "Print EABI (EM_ARM Only)",
2086 "Print only ELF files matching octal permissions",
2087 "Print ELF file size",
2088 "Print all useful/simple info\n",
1404 "Only output 'bad' things", 2089 "Only output 'bad' things",
1405 "Be verbose (can be specified more than once)", 2090 "Be verbose (can be specified more than once)",
1406 "Use specified format for output", 2091 "Use specified format for output",
1407 "Read input stream from a filename", 2092 "Read input stream from a filename",
1408 "Write output stream to a filename", 2093 "Write output stream to a filename",
2094 "Don't emit color in output",
1409 "Don't display the header", 2095 "Don't display the header",
1410 "Print this help and exit", 2096 "Print this help and exit",
1411 "Print version and exit", 2097 "Print version and exit",
1412 NULL 2098 NULL
1413}; 2099};
1414 2100
1415/* display usage and exit */ 2101/* display usage and exit */
1416static void usage(int status) 2102static void usage(int status)
1417{ 2103{
1418 unsigned long i; 2104 const char a_arg[] = "<arg>";
2105 size_t a_arg_len = strlen(a_arg) + 2;
2106 size_t i;
2107 int optlen;
1419 printf("* Scan ELF binaries for stuff\n\n" 2108 printf("* Scan ELF binaries for stuff\n\n"
1420 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0); 2109 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1421 printf("Options: -[%s]\n", PARSE_FLAGS); 2110 printf("Options: -[%s]\n", PARSE_FLAGS);
2111
2112 /* prescan the --long opt length to auto-align */
2113 optlen = 0;
1422 for (i = 0; long_opts[i].name; ++i) 2114 for (i = 0; long_opts[i].name; ++i) {
2115 int l = strlen(long_opts[i].name);
2116 if (long_opts[i].has_arg == a_argument)
2117 l += a_arg_len;
2118 optlen = max(l, optlen);
2119 }
2120
2121 for (i = 0; long_opts[i].name; ++i) {
2122 /* first output the short flag if it has one */
2123 if (long_opts[i].val > '~')
2124 printf(" ");
2125 else
2126 printf(" -%c, ", long_opts[i].val);
2127
2128 /* then the long flag */
1423 if (long_opts[i].has_arg == no_argument) 2129 if (long_opts[i].has_arg == no_argument)
1424 printf(" -%c, --%-14s* %s\n", long_opts[i].val, 2130 printf("--%-*s", optlen, long_opts[i].name);
1425 long_opts[i].name, opts_help[i]);
1426 else 2131 else
1427 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val, 2132 printf("--%s %s %*s", long_opts[i].name, a_arg,
1428 long_opts[i].name, opts_help[i]); 2133 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1429 2134
1430 if (status != EXIT_SUCCESS) 2135 /* finally the help text */
1431 exit(status); 2136 printf("* %s\n", opts_help[i]);
1432 2137 }
1433 puts("\nThe format modifiers for the -F option are:");
1434 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1435 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1436 puts(" i INTERP \tb BIND \ts symbol");
1437 puts(" N library \to Type \tT TEXTRELs");
1438 puts(" S SONAME \tk section");
1439 puts(" p filename (with search path removed)");
1440 puts(" f filename (short name/basename)");
1441 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1442 2138
1443 puts("\nELF Etypes:"); 2139 puts("\nFor more information, see the scanelf(1) manpage");
1444 print_etypes(stdout);
1445
1446 exit(status); 2140 exit(status);
1447} 2141}
1448 2142
1449/* parse command line arguments and preform needed actions */ 2143/* parse command line arguments and preform needed actions */
2144#define do_pax_state(option, flag) \
2145 if (islower(option)) { \
2146 flags &= ~PF_##flag; \
2147 flags |= PF_NO##flag; \
2148 } else { \
2149 flags &= ~PF_NO##flag; \
2150 flags |= PF_##flag; \
2151 }
2152static void parse_delimited(array_t *arr, char *arg, const char *delim)
2153{
2154 char *ele = strtok(arg, delim);
2155 if (!ele) /* edge case: -s '' */
2156 xarraypush_str(arr, "");
2157 while (ele) {
2158 xarraypush_str(arr, ele);
2159 ele = strtok(NULL, delim);
2160 }
2161}
1450static void parseargs(int argc, char *argv[]) 2162static int parseargs(int argc, char *argv[])
1451{ 2163{
1452 int i; 2164 int i;
1453 char *from_file = NULL; 2165 const char *from_file = NULL;
2166 int ret = 0;
2167 char load_cache_config = 0;
1454 2168
1455 opterr = 0; 2169 opterr = 0;
1456 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2170 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1457 switch (i) { 2171 switch (i) {
1458 2172
1466 case 'f': 2180 case 'f':
1467 if (from_file) warn("You prob don't want to specify -f twice"); 2181 if (from_file) warn("You prob don't want to specify -f twice");
1468 from_file = optarg; 2182 from_file = optarg;
1469 break; 2183 break;
1470 case 'E': 2184 case 'E':
1471 strncpy(match_etypes, optarg, sizeof(match_etypes)); 2185 /* historically, this was comma delimited */
2186 parse_delimited(match_etypes, optarg, ",");
1472 break; 2187 break;
1473 case 'M': 2188 case 'M':
1474 match_bits = atoi(optarg); 2189 match_bits = atoi(optarg);
2190 if (match_bits == 0) {
2191 if (strcmp(optarg, "ELFCLASS32") == 0)
2192 match_bits = 32;
2193 if (strcmp(optarg, "ELFCLASS64") == 0)
2194 match_bits = 64;
2195 }
2196 break;
2197 case 'O':
2198 if (sscanf(optarg, "%o", &match_perms) == -1)
2199 match_bits = 0;
1475 break; 2200 break;
1476 case 'o': { 2201 case 'o': {
1477 FILE *fp = NULL;
1478 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2202 if (freopen(optarg, "w", stdout) == NULL)
1479 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2203 errp("Could not freopen(%s)", optarg);
1480 SET_STDOUT(fp);
1481 break; 2204 break;
1482 } 2205 }
1483 case 'k': 2206 case 'k':
1484 if (find_section) warn("You prob don't want to specify -k twice"); 2207 xarraypush_str(find_section_arr, optarg);
1485 find_section = optarg;
1486 break; 2208 break;
1487 case 's': { 2209 case 's':
1488 if (find_sym) warn("You prob don't want to specify -s twice"); 2210 /* historically, this was comma delimited */
1489 find_sym = optarg; 2211 parse_delimited(find_sym_arr, optarg, ",");
1490 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1491 sprintf(versioned_symname, "%s@", find_sym);
1492 break; 2212 break;
1493 }
1494 case 'N': { 2213 case 'N':
1495 if (find_lib) warn("You prob don't want to specify -N twice"); 2214 xarraypush_str(find_lib_arr, optarg);
1496 find_lib = optarg;
1497 break; 2215 break;
1498 }
1499
1500 case 'F': { 2216 case 'F': {
1501 if (out_format) warn("You prob don't want to specify -F twice"); 2217 if (out_format) warn("You prob don't want to specify -F twice");
1502 out_format = optarg; 2218 out_format = optarg;
1503 break; 2219 break;
1504 } 2220 }
1505 case 'z': { 2221 case 'z': {
1506 unsigned long flags = 10240; 2222 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1507 size_t x; 2223 size_t x;
1508 2224
1509#define do_state(option, flag) \
1510 if (islower(option)) { \
1511 flags &= ~PF_##flag; \
1512 flags |= PF_NO##flag; \
1513 } else { \
1514 flags &= ~PF_NO##flag; \
1515 flags |= PF_##flag; \
1516 }
1517
1518 for (x = 0 ; x < strlen(optarg); x++) { 2225 for (x = 0; x < strlen(optarg); x++) {
1519 switch(optarg[x]) { 2226 switch (optarg[x]) {
1520 case 'p': 2227 case 'p':
1521 case 'P': 2228 case 'P':
1522 do_state(optarg[x], PAGEEXEC); 2229 do_pax_state(optarg[x], PAGEEXEC);
1523 break; 2230 break;
1524 case 's': 2231 case 's':
1525 case 'S': 2232 case 'S':
1526 do_state(optarg[x], SEGMEXEC); 2233 do_pax_state(optarg[x], SEGMEXEC);
1527 break; 2234 break;
1528 case 'm': 2235 case 'm':
1529 case 'M': 2236 case 'M':
1530 do_state(optarg[x], MPROTECT); 2237 do_pax_state(optarg[x], MPROTECT);
1531 break; 2238 break;
1532 case 'e': 2239 case 'e':
1533 case 'E': 2240 case 'E':
1534 do_state(optarg[x], EMUTRAMP); 2241 do_pax_state(optarg[x], EMUTRAMP);
1535 break; 2242 break;
1536 case 'r': 2243 case 'r':
1537 case 'R': 2244 case 'R':
1538 do_state(optarg[x], RANDMMAP); 2245 do_pax_state(optarg[x], RANDMMAP);
1539 break; 2246 break;
1540 case 'x': 2247 case 'x':
1541 case 'X': 2248 case 'X':
1542 do_state(optarg[x], RANDEXEC); 2249 do_pax_state(optarg[x], RANDEXEC);
1543 break; 2250 break;
1544 default: 2251 default:
1545 break; 2252 break;
1546 } 2253 }
1547 } 2254 }
1552 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) || 2259 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1553 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)))) 2260 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1554 setpax = flags; 2261 setpax = flags;
1555 break; 2262 break;
1556 } 2263 }
2264 case 'Z': show_size = 1; break;
1557 case 'g': gmatch = 1; break; 2265 case 'g': ++g_match; break;
1558 case 'L': use_ldcache = 1; break; 2266 case 'L': load_cache_config = use_ldcache = 1; break;
1559 case 'y': scan_symlink = 0; break; 2267 case 'y': scan_symlink = 0; break;
1560 case 'A': scan_archives = 1; break; 2268 case 'A': scan_archives = 1; break;
2269 case 'C': color_init(true); break;
1561 case 'B': show_banner = 0; break; 2270 case 'B': show_banner = 0; break;
1562 case 'l': scan_ldpath = 1; break; 2271 case 'l': load_cache_config = scan_ldpath = 1; break;
1563 case 'p': scan_envpath = 1; break; 2272 case 'p': scan_envpath = 1; break;
1564 case 'R': dir_recurse = 1; break; 2273 case 'R': dir_recurse = 1; break;
1565 case 'm': dir_crossmount = 0; break; 2274 case 'm': dir_crossmount = 0; break;
1566 case 'X': ++fix_elf; break; 2275 case 'X': ++fix_elf; break;
1567 case 'x': show_pax = 1; break; 2276 case 'x': show_pax = 1; break;
1571 case 'n': show_needed = 1; break; 2280 case 'n': show_needed = 1; break;
1572 case 'i': show_interp = 1; break; 2281 case 'i': show_interp = 1; break;
1573 case 'b': show_bind = 1; break; 2282 case 'b': show_bind = 1; break;
1574 case 'S': show_soname = 1; break; 2283 case 'S': show_soname = 1; break;
1575 case 'T': show_textrels = 1; break; 2284 case 'T': show_textrels = 1; break;
1576 case 'q': be_quiet = 1; break; 2285 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1577 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2286 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1578 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2287 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1579 2288 case 'D': show_endian = 1; break;
2289 case 'I': show_osabi = 1; break;
2290 case 'Y': show_eabi = 1; break;
2291 case 128:
2292 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2293 if (root_fd == -1)
2294 err("Could not open root: %s", optarg);
2295 break;
2296 case 129: load_cache_config = use_ldpath = 1; break;
1580 case ':': 2297 case ':':
1581 err("Option '%c' is missing parameter", optopt); 2298 err("Option '%c' is missing parameter", optopt);
1582 case '?': 2299 case '?':
1583 err("Unknown option '%c' or argument missing", optopt); 2300 err("Unknown option '%c' or argument missing", optopt);
1584 default: 2301 default:
1585 err("Unhandled option '%c'; please report this", i); 2302 err("Unhandled option '%c'; please report this", i);
1586 } 2303 }
1587 } 2304 }
2305 if (show_textrels && be_verbose)
2306 objdump = which("objdump", "OBJDUMP");
2307 /* precompile all the regexes */
2308 if (g_match) {
2309 regex_t preg;
2310 const char *this_sym;
2311 size_t n;
2312 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1588 2313
2314 array_for_each(find_sym_arr, n, this_sym) {
2315 /* see scanelf_match_symname for logic info */
2316 switch (this_sym[0]) {
2317 case '%':
2318 while (*(this_sym++))
2319 if (*this_sym == '%') {
2320 ++this_sym;
2321 break;
2322 }
2323 break;
2324 case '+':
2325 case '-':
2326 ++this_sym;
2327 break;
2328 }
2329 if (*this_sym == '*')
2330 ++this_sym;
2331
2332 ret = regcomp(&preg, this_sym, flags);
2333 if (ret) {
2334 char err[256];
2335 regerror(ret, &preg, err, sizeof(err));
2336 err("regcomp of %s failed: %s", this_sym, err);
2337 }
2338 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2339 }
2340 }
2341 /* flatten arrays for display */
2342 find_sym = array_flatten_str(find_sym_arr);
2343 find_lib = array_flatten_str(find_lib_arr);
2344 find_section = array_flatten_str(find_section_arr);
1589 /* let the format option override all other options */ 2345 /* let the format option override all other options */
1590 if (out_format) { 2346 if (out_format) {
1591 show_pax = show_phdr = show_textrel = show_rpath = \ 2347 show_pax = show_phdr = show_textrel = show_rpath = \
1592 show_needed = show_interp = show_bind = show_soname = \ 2348 show_needed = show_interp = show_bind = show_soname = \
1593 show_textrels = 0; 2349 show_textrels = show_perms = show_endian = show_size = \
2350 show_osabi = show_eabi = 0;
1594 for (i = 0; out_format[i]; ++i) { 2351 for (i = 0; out_format[i]; ++i) {
1595 if (!IS_MODIFIER(out_format[i])) continue; 2352 if (!IS_MODIFIER(out_format[i])) continue;
1596 2353
1597 switch (out_format[++i]) { 2354 switch (out_format[++i]) {
2355 case '+': break;
1598 case '%': break; 2356 case '%': break;
1599 case '#': break; 2357 case '#': break;
1600 case 'F': break; 2358 case 'F': break;
1601 case 'p': break; 2359 case 'p': break;
1602 case 'f': break; 2360 case 'f': break;
1603 case 'k': break; 2361 case 'k': break;
1604 case 's': break; 2362 case 's': break;
1605 case 'N': break; 2363 case 'N': break;
1606 case 'o': break; 2364 case 'o': break;
2365 case 'a': break;
2366 case 'M': break;
2367 case 'Z': show_size = 1; break;
2368 case 'D': show_endian = 1; break;
2369 case 'I': show_osabi = 1; break;
2370 case 'Y': show_eabi = 1; break;
2371 case 'O': show_perms = 1; break;
1607 case 'x': show_pax = 1; break; 2372 case 'x': show_pax = 1; break;
1608 case 'e': show_phdr = 1; break; 2373 case 'e': show_phdr = 1; break;
1609 case 't': show_textrel = 1; break; 2374 case 't': show_textrel = 1; break;
1610 case 'r': show_rpath = 1; break; 2375 case 'r': show_rpath = 1; break;
1611 case 'n': show_needed = 1; break; 2376 case 'n': show_needed = 1; break;
1612 case 'i': show_interp = 1; break; 2377 case 'i': show_interp = 1; break;
1613 case 'b': show_bind = 1; break; 2378 case 'b': show_bind = 1; break;
1614 case 'S': show_soname = 1; break; 2379 case 'S': show_soname = 1; break;
1615 case 'T': show_textrels = 1; break; 2380 case 'T': show_textrels = 1; break;
1616 default: 2381 default:
1617 err("Invalid format specifier '%c' (byte %i)", 2382 err("invalid format specifier '%c' (byte %i)",
1618 out_format[i], i+1); 2383 out_format[i], i+1);
1619 } 2384 }
1620 } 2385 }
1621 2386
1622 /* construct our default format */ 2387 /* construct our default format */
1623 } else { 2388 } else {
1624 size_t fmt_len = 30; 2389 size_t fmt_len = 30;
1625 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2390 out_format = xmalloc(sizeof(char) * fmt_len);
2391 *out_format = '\0';
1626 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2392 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1627 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2393 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2394 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2395 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2396 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2397 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2398 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1628 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2399 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1629 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2400 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1630 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2401 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1631 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2402 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1632 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2403 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1639 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2410 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1640 } 2411 }
1641 if (be_verbose > 2) printf("Format: %s\n", out_format); 2412 if (be_verbose > 2) printf("Format: %s\n", out_format);
1642 2413
1643 /* now lets actually do the scanning */ 2414 /* now lets actually do the scanning */
1644 if (scan_ldpath || use_ldcache) 2415 if (load_cache_config)
1645 load_ld_so_conf(0, "/etc/ld.so.conf"); 2416 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1646 if (scan_ldpath) scanelf_ldpath(); 2417 if (scan_ldpath) scanelf_ldpath();
1647 if (scan_envpath) scanelf_envpath(); 2418 if (scan_envpath) scanelf_envpath();
2419 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2420 from_file = "-";
1648 if (from_file) { 2421 if (from_file) {
1649 scanelf_from_file(from_file); 2422 scanelf_from_file(from_file);
1650 from_file = *argv; 2423 from_file = *argv;
1651 } 2424 }
1652 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2425 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1653 err("Nothing to scan !?"); 2426 err("Nothing to scan !?");
1654 while (optind < argc) { 2427 while (optind < argc) {
1655 search_path = argv[optind++]; 2428 search_path = argv[optind++];
1656 scanelf_dir(search_path); 2429 ret = scanelf_dir(search_path);
1657 } 2430 }
1658 2431
2432#ifdef __PAX_UTILS_CLEANUP
1659 /* clean up */ 2433 /* clean up */
1660 if (versioned_symname) free(versioned_symname);
1661 for (i = 0; ldpaths[i]; ++i)
1662 free(ldpaths[i]); 2434 xarrayfree(ldpaths);
2435 xarrayfree(find_sym_arr);
2436 xarrayfree(find_lib_arr);
2437 xarrayfree(find_section_arr);
2438 free(find_sym);
2439 free(find_lib);
2440 free(find_section);
2441 {
2442 size_t n;
2443 regex_t *preg;
2444 array_for_each(find_sym_regex_arr, n, preg)
2445 regfree(preg);
2446 xarrayfree(find_sym_regex_arr);
2447 }
1663 2448
1664 if (ldcache != 0) 2449 if (ldcache != 0)
1665 munmap(ldcache, ldcache_size); 2450 munmap(ldcache, ldcache_size);
1666} 2451#endif
1667 2452
1668
1669
1670/* utility funcs */
1671static char *xstrdup(const char *s)
1672{
1673 char *ret = strdup(s);
1674 if (!ret) err("Could not strdup(): %s", strerror(errno));
1675 return ret; 2453 return ret;
1676} 2454}
1677static void *xmalloc(size_t size)
1678{
1679 void *ret = malloc(size);
1680 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1681 return ret;
1682}
1683static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1684{
1685 size_t new_len;
1686 2455
1687 new_len = strlen(*dst) + strlen(src); 2456static char **get_split_env(const char *envvar)
1688 if (*curr_len <= new_len) {
1689 *curr_len = new_len + (*curr_len / 2);
1690 *dst = realloc(*dst, *curr_len);
1691 if (!*dst)
1692 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1693 }
1694
1695 if (n)
1696 strncat(*dst, src, n);
1697 else
1698 strcat(*dst, src);
1699}
1700static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1701{ 2457{
1702 static char my_app[2]; 2458 const char *delims = " \t\n";
1703 my_app[0] = append; 2459 char **envvals = NULL;
1704 my_app[1] = '\0'; 2460 char *env, *s;
1705 xstrcat(dst, my_app, curr_len); 2461 int nentry;
1706}
1707 2462
2463 if ((env = getenv(envvar)) == NULL)
2464 return NULL;
1708 2465
2466 env = xstrdup(env);
2467 if (env == NULL)
2468 return NULL;
2469
2470 s = strtok(env, delims);
2471 if (s == NULL) {
2472 free(env);
2473 return NULL;
2474 }
2475
2476 nentry = 0;
2477 while (s != NULL) {
2478 ++nentry;
2479 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2480 envvals[nentry-1] = s;
2481 s = strtok(NULL, delims);
2482 }
2483 envvals[nentry] = NULL;
2484
2485 /* don't want to free(env) as it contains the memory that backs
2486 * the envvals array of strings */
2487 return envvals;
2488}
2489
2490static void parseenv(void)
2491{
2492 color_init(false);
2493 qa_textrels = get_split_env("QA_TEXTRELS");
2494 qa_execstack = get_split_env("QA_EXECSTACK");
2495 qa_wx_load = get_split_env("QA_WX_LOAD");
2496}
2497
2498#ifdef __PAX_UTILS_CLEANUP
2499static void cleanup(void)
2500{
2501 free(out_format);
2502 free(qa_textrels);
2503 free(qa_execstack);
2504 free(qa_wx_load);
2505}
2506#endif
1709 2507
1710int main(int argc, char *argv[]) 2508int main(int argc, char *argv[])
1711{ 2509{
2510 int ret;
1712 if (argc < 2) 2511 if (argc < 2)
1713 usage(EXIT_FAILURE); 2512 usage(EXIT_FAILURE);
2513 parseenv();
1714 parseargs(argc, argv); 2514 ret = parseargs(argc, argv);
1715 fclose(stdout); 2515 fclose(stdout);
1716#ifdef __BOUNDS_CHECKING_ON 2516#ifdef __PAX_UTILS_CLEANUP
1717 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2517 cleanup();
2518 warn("The calls to add/delete heap should be off:\n"
2519 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2520 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1718#endif 2521#endif
1719 return EXIT_SUCCESS; 2522 return ret;
1720} 2523}
2524
2525/* Match filename against entries in matchlist, return TRUE
2526 * if the file is listed */
2527static int file_matches_list(const char *filename, char **matchlist)
2528{
2529 char **file;
2530 char *match;
2531 char buf[__PAX_UTILS_PATH_MAX];
2532
2533 if (matchlist == NULL)
2534 return 0;
2535
2536 for (file = matchlist; *file != NULL; file++) {
2537 if (search_path) {
2538 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2539 match = buf;
2540 } else {
2541 match = *file;
2542 }
2543 if (fnmatch(match, filename, 0) == 0)
2544 return 1;
2545 }
2546 return 0;
2547}

Legend:
Removed from v.1.127  
changed lines
  Added in v.1.270

  ViewVC Help
Powered by ViewVC 1.1.20