/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.18 Revision 1.146
1/* 1/*
2 * Copyright 2003 Ned Ludd <solar@gentoo.org>
3 * Copyright 1999-2005 Gentoo Foundation 2 * Copyright 2003-2006 Gentoo Foundation
4 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
5 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.18 2005/04/02 03:25:38 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.146 2006/05/14 21:04:25 vapier Exp $
6 * 5 *
7 ******************************************************************** 6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org>
8 * This program is free software; you can redistribute it and/or 7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org>
9 * modify it under the terms of the GNU General Public License as
10 * published by the Free Software Foundation; either version 2 of the
11 * License, or (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place - Suite 330, Boston,
21 * MA 02111-1307, USA.
22 */ 8 */
23 9
24#include <stdio.h>
25#include <stdlib.h>
26#include <sys/types.h>
27#include <string.h>
28#include <errno.h>
29#include <unistd.h>
30#include <sys/stat.h>
31#include <dirent.h>
32#include <getopt.h>
33
34#include "paxelf.h" 10#include "paxinc.h"
11#if defined(__GLIBC__) || defined(__UCLIBC__)
12 #include <glob.h>
13#endif
14#if defined(__FreeBSD__) || defined(__DragonFly__)
15 #include <elf-hints.h>
16#endif
35 17
36static const char *rcsid = "$Id: scanelf.c,v 1.18 2005/04/02 03:25:38 vapier Exp $"; 18static const char *rcsid = "$Id: scanelf.c,v 1.146 2006/05/14 21:04:25 vapier Exp $";
19#define argv0 "scanelf"
37 20
21#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
38 22
39/* helper functions for showing errors */ 23#define do_state(option, flag) \
40#define argv0 "scanelf" /*((*argv != NULL) ? argv[0] : __FILE__ "\b\b")*/ 24 if (islower(option)) { \
41#define warn(fmt, args...) \ 25 flags &= ~PF_##flag; \
42 fprintf(stderr, "%s: " fmt "\n", argv0, ## args) 26 flags |= PF_NO##flag; \
43#define warnf(fmt, args...) warn("%s(): " fmt, __FUNCTION__, ## args) 27 } else { \
44#define err(fmt, args...) \ 28 flags &= ~PF_NO##flag; \
45 do { \ 29 flags |= PF_##flag; \
46 warn(fmt, ## args); \ 30 }
47 exit(EXIT_FAILURE); \
48 } while (0)
49
50 31
51 32
52/* prototypes */ 33/* prototypes */
34static int file_matches_list(const char *filename, char **matchlist);
35static int scanelf_elfobj(elfobj *elf);
36static int scanelf_elf(const char *filename, int fd, size_t len);
37static int scanelf_archive(const char *filename, int fd, size_t len);
53static void scanelf_file(const char *filename); 38static void scanelf_file(const char *filename);
54static void scanelf_dir(const char *path); 39static void scanelf_dir(const char *path);
55static void scanelf_ldpath(); 40static void scanelf_ldpath(void);
56static void scanelf_envpath(); 41static void scanelf_envpath(void);
57static void usage(int status); 42static void usage(int status);
43static char **get_split_env(const char *envvar);
44static void parseenv(void);
58static void parseargs(int argc, char *argv[]); 45static void parseargs(int argc, char *argv[]);
46static char *xstrdup(const char *s);
47static void *xmalloc(size_t size);
48static void *xrealloc(void *ptr, size_t size);
49static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
50#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
51static inline void xchrcat(char **dst, const char append, size_t *curr_len);
59 52
60/* variables to control behavior */ 53/* variables to control behavior */
54static char match_etypes[126] = "";
55static char *ldpaths[256];
61static char scan_ldpath = 0; 56static char scan_ldpath = 0;
62static char scan_envpath = 0; 57static char scan_envpath = 0;
58static char scan_symlink = 1;
59static char scan_archives = 0;
63static char dir_recurse = 0; 60static char dir_recurse = 0;
64static char dir_crossmount = 1; 61static char dir_crossmount = 1;
65static char show_pax = 0; 62static char show_pax = 0;
66static char show_stack = 0; 63static char show_phdr = 0;
67static char show_textrel = 0; 64static char show_textrel = 0;
68static char show_rpath = 0; 65static char show_rpath = 0;
66static char show_needed = 0;
67static char show_interp = 0;
68static char show_bind = 0;
69static char show_soname = 0;
70static char show_textrels = 0;
69static char show_banner = 1; 71static char show_banner = 1;
70static char be_quiet = 0; 72static char be_quiet = 0;
71static char be_verbose = 0; 73static char be_verbose = 0;
74static char be_wewy_wewy_quiet = 0;
75static char be_semi_verbose = 0;
76static char *find_sym = NULL, *versioned_symname = NULL;
77static char *find_lib = NULL;
78static char *find_section = NULL;
79static char *out_format = NULL;
80static char *search_path = NULL;
81static char fix_elf = 0;
82static char gmatch = 0;
83static char use_ldcache = 0;
72 84
85static char **qa_textrels = NULL;
86static char **qa_execstack = NULL;
87static char **qa_wx_load = NULL;
73 88
89int match_bits = 0;
90caddr_t ldcache = 0;
91size_t ldcache_size = 0;
92unsigned long setpax = 0UL;
93
94/* utility funcs */
95static char *xstrdup(const char *s)
96{
97 char *ret = strdup(s);
98 if (!ret) err("Could not strdup(): %s", strerror(errno));
99 return ret;
100}
101static void *xmalloc(size_t size)
102{
103 void *ret = malloc(size);
104 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
105 return ret;
106}
107static void *xrealloc(void *ptr, size_t size)
108{
109 void *ret = realloc(ptr, size);
110 if (!ret) err("Could not realloc() %li bytes", (unsigned long)size);
111 return ret;
112}
113static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
114{
115 size_t new_len;
116
117 new_len = strlen(*dst) + strlen(src);
118 if (*curr_len <= new_len) {
119 *curr_len = new_len + (*curr_len / 2);
120 *dst = realloc(*dst, *curr_len);
121 if (!*dst)
122 err("could not realloc() %li bytes", (unsigned long)*curr_len);
123 }
124
125 if (n)
126 strncat(*dst, src, n);
127 else
128 strcat(*dst, src);
129}
130static inline void xchrcat(char **dst, const char append, size_t *curr_len)
131{
132 static char my_app[2];
133 my_app[0] = append;
134 my_app[1] = '\0';
135 xstrcat(dst, my_app, curr_len);
136}
137
138/* Match filename against entries in matchlist, return TRUE
139 * if the file is listed */
140static int file_matches_list(const char *filename, char **matchlist) {
141 char **file;
142 char *match;
143 char buf[__PAX_UTILS_PATH_MAX];
144
145 if (matchlist == NULL)
146 return 0;
147
148 for (file = matchlist; *file != NULL; file++) {
149 if (search_path) {
150 snprintf(buf,__PAX_UTILS_PATH_MAX, "%s%s", search_path, *file);
151 match=buf;
152 } else {
153 match=*file;
154 }
155 if (fnmatch(match, filename, 0) == 0)
156 return 1; /* TRUE */
157 }
158 return 0; /* FALSE */
159}
160
161/* sub-funcs for scanelf_file() */
162static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab)
163{
164 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
165#define GET_SYMTABS(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \
168 /* debug sections */ \
169 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \
170 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \
171 /* runtime sections */ \
172 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \
173 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \
174 if (symtab && dynsym) { \
175 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \
176 } else { \
177 *sym = (void*)(symtab ? symtab : dynsym); \
178 } \
179 if (strtab && dynstr) { \
180 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \
181 } else { \
182 *tab = (void*)(strtab ? strtab : dynstr); \
183 } \
184 }
185 GET_SYMTABS(32)
186 GET_SYMTABS(64)
187}
188
189static char *scanelf_file_pax(elfobj *elf, char *found_pax)
190{
191 static char ret[7];
192 unsigned long i, shown;
193
194 if (!show_pax) return NULL;
195
196 shown = 0;
197 memset(&ret, 0, sizeof(ret));
198
199 if (elf->phdr) {
200#define SHOW_PAX(B) \
201 if (elf->elf_class == ELFCLASS ## B) { \
202 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
203 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
204 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
205 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
206 continue; \
207 if (fix_elf && setpax) { \
208 /* set the paxctl flags */ \
209 ESET(phdr[i].p_flags, setpax); \
210 } \
211 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
212 continue; \
213 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
214 *found_pax = 1; \
215 ++shown; \
216 break; \
217 } \
218 }
219 SHOW_PAX(32)
220 SHOW_PAX(64)
221 }
222
223
224 if (fix_elf && setpax) {
225 /* set the chpax settings */
226 if (elf->elf_class == ELFCLASS32) {
227 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
228 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
229 } else {
230 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
231 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
232 }
233 }
234
235 /* fall back to EI_PAX if no PT_PAX was found */
236 if (!*ret) {
237 static char *paxflags;
238 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
239 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
240 *found_pax = 1;
241 return (be_wewy_wewy_quiet ? NULL : paxflags);
242 }
243 strncpy(ret, paxflags, sizeof(ret));
244 }
245
246 if (be_wewy_wewy_quiet || (be_quiet && !shown))
247 return NULL;
248 else
249 return ret;
250}
251
252static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
253{
254 static char ret[12];
255 char *found;
256 unsigned long i, shown, multi_stack, multi_relro, multi_load;
257 int max_pt_load;
258
259 if (!show_phdr) return NULL;
260
261 memcpy(ret, "--- --- ---\0", 12);
262
263 shown = 0;
264 multi_stack = multi_relro = multi_load = 0;
265 max_pt_load = elf_max_pt_load(elf);
266
267#define NOTE_GNU_STACK ".note.GNU-stack"
268#define SHOW_PHDR(B) \
269 if (elf->elf_class == ELFCLASS ## B) { \
270 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
271 Elf ## B ## _Off offset; \
272 uint32_t flags, check_flags; \
273 if (elf->phdr != NULL) { \
274 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
275 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
276 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
277 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
278 if (!file_matches_list(elf->filename, qa_execstack)) {\
279 found = found_phdr; \
280 offset = 0; \
281 check_flags = PF_X; \
282 } else continue; \
283 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
284 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
285 found = found_relro; \
286 offset = 4; \
287 check_flags = PF_X; \
288 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
289 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \
290 if (multi_load++ > max_pt_load) warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
291 if (!file_matches_list(elf->filename, qa_wx_load)) {\
292 found = found_load; \
293 offset = 8; \
294 check_flags = PF_W|PF_X; \
295 } else continue; \
296 } else \
297 continue; \
298 flags = EGET(phdr[i].p_flags); \
299 if (be_quiet && ((flags & check_flags) != check_flags)) \
300 continue; \
301 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
302 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
303 ret[3] = ret[7] = '!'; \
304 flags = EGET(phdr[i].p_flags); \
305 } \
306 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
307 *found = 1; \
308 ++shown; \
309 } \
310 } else if (elf->shdr != NULL) { \
311 /* no program headers which means this is prob an object file */ \
312 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
313 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
314 char *str; \
315 if ((void*)strtbl > (void*)elf->data_end) \
316 goto skip_this_shdr##B; \
317 check_flags = SHF_WRITE|SHF_EXECINSTR; \
318 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
319 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
320 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
321 str = elf->data + offset; \
322 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
323 if (!strcmp(str, NOTE_GNU_STACK)) { \
324 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
325 flags = EGET(shdr[i].sh_flags); \
326 if (be_quiet && ((flags & check_flags) != check_flags)) \
327 continue; \
328 ++*found_phdr; \
329 shown = 1; \
330 if (flags & SHF_WRITE) ret[0] = 'W'; \
331 if (flags & SHF_ALLOC) ret[1] = 'A'; \
332 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
333 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
334 break; \
335 } \
336 } \
337 skip_this_shdr##B: \
338 if (!multi_stack) { \
339 *found_phdr = 1; \
340 shown = 1; \
341 memcpy(ret, "!WX", 3); \
342 } \
343 } \
344 }
345 SHOW_PHDR(32)
346 SHOW_PHDR(64)
347
348 if (be_wewy_wewy_quiet || (be_quiet && !shown))
349 return NULL;
350 else
351 return ret;
352}
353
354static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
355{
356 static const char *ret = "TEXTREL";
357 unsigned long i;
358
359 if (!show_textrel && !show_textrels) return NULL;
360
361 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
362
363 if (elf->phdr) {
364#define SHOW_TEXTREL(B) \
365 if (elf->elf_class == ELFCLASS ## B) { \
366 Elf ## B ## _Dyn *dyn; \
367 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
368 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
369 Elf ## B ## _Off offset; \
370 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
371 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
372 offset = EGET(phdr[i].p_offset); \
373 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
374 dyn = DYN ## B (elf->data + offset); \
375 while (EGET(dyn->d_tag) != DT_NULL) { \
376 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
377 *found_textrel = 1; \
378 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
379 return (be_wewy_wewy_quiet ? NULL : ret); \
380 } \
381 ++dyn; \
382 } \
383 } }
384 SHOW_TEXTREL(32)
385 SHOW_TEXTREL(64)
386 }
387
388 if (be_quiet || be_wewy_wewy_quiet)
389 return NULL;
390 else
391 return " - ";
392}
393static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
394{
395 unsigned long s, r, rmax;
396 void *symtab_void, *strtab_void, *text_void;
397
398 if (!show_textrels) return NULL;
399
400 /* don't search for TEXTREL's if the ELF doesn't have any */
401 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
402 if (!*found_textrel) return NULL;
403
404 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
405 text_void = elf_findsecbyname(elf, ".text");
406
407 if (symtab_void && strtab_void && text_void && elf->shdr) {
408#define SHOW_TEXTRELS(B) \
409 if (elf->elf_class == ELFCLASS ## B) { \
410 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
411 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
412 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
413 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
414 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
415 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
416 uint ## B ## _t memsz = EGET(text->sh_size); \
417 Elf ## B ## _Rel *rel; \
418 Elf ## B ## _Rela *rela; \
419 /* search the section headers for relocations */ \
420 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
421 uint32_t sh_type = EGET(shdr[s].sh_type); \
422 if (sh_type == SHT_REL) { \
423 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \
424 rela = NULL; \
425 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
426 } else if (sh_type == SHT_RELA) { \
427 rel = NULL; \
428 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \
429 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
430 } else \
431 continue; \
432 /* now see if any of the relocs are in the .text */ \
433 for (r = 0; r < rmax; ++r) { \
434 unsigned long sym_max; \
435 Elf ## B ## _Addr offset_tmp; \
436 Elf ## B ## _Sym *func; \
437 Elf ## B ## _Sym *sym; \
438 Elf ## B ## _Addr r_offset; \
439 uint ## B ## _t r_info; \
440 if (sh_type == SHT_REL) { \
441 r_offset = EGET(rel[r].r_offset); \
442 r_info = EGET(rel[r].r_info); \
443 } else { \
444 r_offset = EGET(rela[r].r_offset); \
445 r_info = EGET(rela[r].r_info); \
446 } \
447 /* make sure this relocation is inside of the .text */ \
448 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
449 if (be_verbose <= 2) continue; \
450 } else \
451 *found_textrels = 1; \
452 /* locate this relocation symbol name */ \
453 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
454 if ((void*)sym > (void*)elf->data_end) { \
455 warn("%s: corrupt ELF symbol", elf->filename); \
456 continue; \
457 } \
458 sym_max = ELF ## B ## _R_SYM(r_info); \
459 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
460 sym += sym_max; \
461 else \
462 sym = NULL; \
463 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
464 /* show the raw details about this reloc */ \
465 printf(" %s: ", elf->base_filename); \
466 if (sym && sym->st_name) \
467 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \
468 else \
469 printf("(memory/fake?)"); \
470 printf(" [0x%lX]", (unsigned long)r_offset); \
471 /* now try to find the closest symbol that this rel is probably in */ \
472 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
473 func = NULL; \
474 offset_tmp = 0; \
475 while (sym_max--) { \
476 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
477 func = sym; \
478 offset_tmp = EGET(sym->st_value); \
479 } \
480 ++sym; \
481 } \
482 printf(" in "); \
483 if (func && func->st_name) \
484 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \
485 else \
486 printf("(NULL: fake?)"); \
487 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
488 } \
489 } }
490 SHOW_TEXTRELS(32)
491 SHOW_TEXTRELS(64)
492 }
493 if (!*found_textrels)
494 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
495
496 return NULL;
497}
498
499static void rpath_security_checks(elfobj *, char *, const char *);
500static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
501{
502 struct stat st;
503 switch (*item) {
504 case '/': break;
505 case '.':
506 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
507 break;
508 case ':':
509 case '\0':
510 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
511 break;
512 case '$':
513 if (fstat(elf->fd, &st) != -1)
514 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
515 warnf("Security problem with %s='%s' in %s with mode set of %o",
516 dt_type, item, elf->filename, st.st_mode & 07777);
517 break;
518 default:
519 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
520 break;
521 }
522}
523static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
524{
525 unsigned long i, s;
526 char *rpath, *runpath, **r;
527 void *strtbl_void;
528
529 if (!show_rpath) return;
530
531 strtbl_void = elf_findsecbyname(elf, ".dynstr");
532 rpath = runpath = NULL;
533
534 if (elf->phdr && strtbl_void) {
535#define SHOW_RPATH(B) \
536 if (elf->elf_class == ELFCLASS ## B) { \
537 Elf ## B ## _Dyn *dyn; \
538 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
539 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
540 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
541 Elf ## B ## _Off offset; \
542 Elf ## B ## _Xword word; \
543 /* Scan all the program headers */ \
544 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
545 /* Just scan dynamic headers */ \
546 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
547 offset = EGET(phdr[i].p_offset); \
548 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
549 /* Just scan dynamic RPATH/RUNPATH headers */ \
550 dyn = DYN ## B (elf->data + offset); \
551 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
552 if (word == DT_RPATH) { \
553 r = &rpath; \
554 } else if (word == DT_RUNPATH) { \
555 r = &runpath; \
556 } else { \
557 ++dyn; \
558 continue; \
559 } \
560 /* Verify the memory is somewhat sane */ \
561 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
562 if (offset < (Elf ## B ## _Off)elf->len) { \
563 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
564 *r = (char*)(elf->data + offset); \
565 /* cache the length in case we need to nuke this section later on */ \
566 if (fix_elf) \
567 offset = strlen(*r); \
568 /* If quiet, don't output paths in ld.so.conf */ \
569 if (be_quiet) { \
570 size_t len; \
571 char *start, *end; \
572 /* note that we only 'chop' off leading known paths. */ \
573 /* since *r is read-only memory, we can only move the ptr forward. */ \
574 start = *r; \
575 /* scan each path in : delimited list */ \
576 while (start) { \
577 rpath_security_checks(elf, start, get_elfdtype(word)); \
578 end = strchr(start, ':'); \
579 len = (end ? abs(end - start) : strlen(start)); \
580 if (use_ldcache) \
581 for (s = 0; ldpaths[s]; ++s) \
582 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \
583 *r = end; \
584 /* corner case ... if RPATH reads "/usr/lib:", we want \
585 * to show ':' rather than '' */ \
586 if (end && end[1] != '\0') \
587 (*r)++; \
588 break; \
589 } \
590 if (!*r || !end) \
591 break; \
592 else \
593 start = start + len + 1; \
594 } \
595 } \
596 if (*r) { \
597 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
598 /* just nuke it */ \
599 nuke_it##B: \
600 memset(*r, 0x00, offset); \
601 *r = NULL; \
602 ESET(dyn->d_tag, DT_DEBUG); \
603 ESET(dyn->d_un.d_ptr, 0); \
604 } else if (fix_elf) { \
605 /* try to clean "bad" paths */ \
606 size_t len, tmpdir_len; \
607 char *start, *end; \
608 const char *tmpdir; \
609 start = *r; \
610 tmpdir = (getenv("TMPDIR") ? : "."); \
611 tmpdir_len = strlen(tmpdir); \
612 while (1) { \
613 end = strchr(start, ':'); \
614 if (start == end) { \
615 eat_this_path##B: \
616 len = strlen(end); \
617 memmove(start, end+1, len); \
618 start[len-1] = '\0'; \
619 end = start - 1; \
620 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
621 if (!end) { \
622 if (start == *r) \
623 goto nuke_it##B; \
624 *--start = '\0'; \
625 } else \
626 goto eat_this_path##B; \
627 } \
628 if (!end) \
629 break; \
630 start = end + 1; \
631 } \
632 if (**r == '\0') \
633 goto nuke_it##B; \
634 } \
635 if (*r) \
636 *found_rpath = 1; \
637 } \
638 } \
639 ++dyn; \
640 } \
641 } }
642 SHOW_RPATH(32)
643 SHOW_RPATH(64)
644 }
645
646 if (be_wewy_wewy_quiet) return;
647
648 if (rpath && runpath) {
649 if (!strcmp(rpath, runpath)) {
650 xstrcat(ret, runpath, ret_len);
651 } else {
652 fprintf(stderr, "RPATH [%s] != RUNPATH [%s]\n", rpath, runpath);
653 xchrcat(ret, '{', ret_len);
654 xstrcat(ret, rpath, ret_len);
655 xchrcat(ret, ',', ret_len);
656 xstrcat(ret, runpath, ret_len);
657 xchrcat(ret, '}', ret_len);
658 }
659 } else if (rpath || runpath)
660 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
661 else if (!be_quiet)
662 xstrcat(ret, " - ", ret_len);
663}
664
665#define LDSO_CACHE_MAGIC "ld.so-"
666#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
667#define LDSO_CACHE_VER "1.7.0"
668#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
669#define FLAG_ANY -1
670#define FLAG_TYPE_MASK 0x00ff
671#define FLAG_LIBC4 0x0000
672#define FLAG_ELF 0x0001
673#define FLAG_ELF_LIBC5 0x0002
674#define FLAG_ELF_LIBC6 0x0003
675#define FLAG_REQUIRED_MASK 0xff00
676#define FLAG_SPARC_LIB64 0x0100
677#define FLAG_IA64_LIB64 0x0200
678#define FLAG_X8664_LIB64 0x0300
679#define FLAG_S390_LIB64 0x0400
680#define FLAG_POWERPC_LIB64 0x0500
681#define FLAG_MIPS64_LIBN32 0x0600
682#define FLAG_MIPS64_LIBN64 0x0700
683
684static char *lookup_cache_lib(elfobj *, char *);
685#if defined(__GLIBC__) || defined(__UCLIBC__)
686static char *lookup_cache_lib(elfobj *elf, char *fname)
687{
688 int fd = 0;
689 char *strs;
690 static char buf[__PAX_UTILS_PATH_MAX] = "";
691 const char *cachefile = "/etc/ld.so.cache";
692 struct stat st;
693
694 typedef struct {
695 char magic[LDSO_CACHE_MAGIC_LEN];
696 char version[LDSO_CACHE_VER_LEN];
697 int nlibs;
698 } header_t;
699 header_t *header;
700
701 typedef struct {
702 int flags;
703 int sooffset;
704 int liboffset;
705 } libentry_t;
706 libentry_t *libent;
707
708 if (fname == NULL)
709 return NULL;
710
711 if (ldcache == 0) {
712 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1)
713 return NULL;
714
715 /* cache these values so we only map/unmap the cache file once */
716 ldcache_size = st.st_size;
717 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
718
719 close(fd);
720
721 if (ldcache == (caddr_t)-1) {
722 ldcache = 0;
723 return NULL;
724 }
725
726 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN))
727 return NULL;
728 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
729 return NULL;
730 }
731
732 header = (header_t *) ldcache;
733 libent = (libentry_t *) (ldcache + sizeof(header_t));
734 strs = (char *) &libent[header->nlibs];
735
736 for (fd = 0; fd < header->nlibs; fd++) {
737 /* this should be more fine grained, but for now we assume that
738 * diff arches will not be cached together. and we ignore the
739 * the different multilib mips cases. */
740 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
741 continue;
742 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
743 continue;
744
745 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
746 continue;
747 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
748 }
749 return buf;
750}
751#else
752#warning Cache support not implemented for your current target.
753static char *lookup_cache_lib(elfobj *elf, char *fname)
754{
755 return NULL;
756}
757#endif
758
759static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
760{
761 unsigned long i;
762 char *needed;
763 void *strtbl_void;
764 char *p;
765
766 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL;
767
768 strtbl_void = elf_findsecbyname(elf, ".dynstr");
769
770 if (elf->phdr && strtbl_void) {
771#define SHOW_NEEDED(B) \
772 if (elf->elf_class == ELFCLASS ## B) { \
773 Elf ## B ## _Dyn *dyn; \
774 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
775 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
776 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
777 Elf ## B ## _Off offset; \
778 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
779 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
780 offset = EGET(phdr[i].p_offset); \
781 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
782 dyn = DYN ## B (elf->data + offset); \
783 while (EGET(dyn->d_tag) != DT_NULL) { \
784 if (EGET(dyn->d_tag) == DT_NEEDED) { \
785 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
786 if (offset >= (Elf ## B ## _Off)elf->len) { \
787 ++dyn; \
788 continue; \
789 } \
790 needed = (char*)(elf->data + offset); \
791 if (op == 0) { \
792 if (!be_wewy_wewy_quiet) { \
793 if (*found_needed) xchrcat(ret, ',', ret_len); \
794 if (use_ldcache) \
795 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
796 needed = p; \
797 xstrcat(ret, needed, ret_len); \
798 } \
799 *found_needed = 1; \
800 } else { \
801 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \
802 *found_lib = 1; \
803 return (be_wewy_wewy_quiet ? NULL : needed); \
804 } \
805 } \
806 } \
807 ++dyn; \
808 } \
809 } }
810 SHOW_NEEDED(32)
811 SHOW_NEEDED(64)
812 if (op == 0 && !*found_needed && be_verbose)
813 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
814 }
815
816 return NULL;
817}
818static char *scanelf_file_interp(elfobj *elf, char *found_interp)
819{
820 void *strtbl_void;
821
822 if (!show_interp) return NULL;
823
824 strtbl_void = elf_findsecbyname(elf, ".interp");
825
826 if (strtbl_void) {
827#define SHOW_INTERP(B) \
828 if (elf->elf_class == ELFCLASS ## B) { \
829 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
830 *found_interp = 1; \
831 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
832 }
833 SHOW_INTERP(32)
834 SHOW_INTERP(64)
835 }
836 return NULL;
837}
838static char *scanelf_file_bind(elfobj *elf, char *found_bind)
839{
840 unsigned long i;
841 struct stat s;
842 char dynamic = 0;
843
844 if (!show_bind) return NULL;
845 if (!elf->phdr) return NULL;
846
847#define SHOW_BIND(B) \
848 if (elf->elf_class == ELFCLASS ## B) { \
849 Elf ## B ## _Dyn *dyn; \
850 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
851 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
852 Elf ## B ## _Off offset; \
853 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
854 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
855 dynamic = 1; \
856 offset = EGET(phdr[i].p_offset); \
857 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
858 dyn = DYN ## B (elf->data + offset); \
859 while (EGET(dyn->d_tag) != DT_NULL) { \
860 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
861 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
862 { \
863 if (be_quiet) return NULL; \
864 *found_bind = 1; \
865 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
866 } \
867 ++dyn; \
868 } \
869 } \
870 }
871 SHOW_BIND(32)
872 SHOW_BIND(64)
873
874 if (be_wewy_wewy_quiet) return NULL;
875
876 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) {
877 return NULL;
878 } else {
879 *found_bind = 1;
880 return (char *) (dynamic ? "LAZY" : "STATIC");
881 }
882}
883static char *scanelf_file_soname(elfobj *elf, char *found_soname)
884{
885 unsigned long i;
886 char *soname;
887 void *strtbl_void;
888
889 if (!show_soname) return NULL;
890
891 strtbl_void = elf_findsecbyname(elf, ".dynstr");
892
893 if (elf->phdr && strtbl_void) {
894#define SHOW_SONAME(B) \
895 if (elf->elf_class == ELFCLASS ## B) { \
896 Elf ## B ## _Dyn *dyn; \
897 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
898 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
899 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
900 Elf ## B ## _Off offset; \
901 /* only look for soname in shared objects */ \
902 if (ehdr->e_type != ET_DYN) \
903 return NULL; \
904 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
905 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
906 offset = EGET(phdr[i].p_offset); \
907 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
908 dyn = DYN ## B (elf->data + offset); \
909 while (EGET(dyn->d_tag) != DT_NULL) { \
910 if (EGET(dyn->d_tag) == DT_SONAME) { \
911 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
912 if (offset >= (Elf ## B ## _Off)elf->len) { \
913 ++dyn; \
914 continue; \
915 } \
916 soname = (char*)(elf->data + offset); \
917 *found_soname = 1; \
918 return (be_wewy_wewy_quiet ? NULL : soname); \
919 } \
920 ++dyn; \
921 } \
922 } }
923 SHOW_SONAME(32)
924 SHOW_SONAME(64)
925 }
926
927 return NULL;
928}
929static char *scanelf_file_sym(elfobj *elf, char *found_sym)
930{
931 unsigned long i;
932 char *ret;
933 void *symtab_void, *strtab_void;
934
935 if (!find_sym) return NULL;
936 ret = find_sym;
937
938 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
939
940 if (symtab_void && strtab_void) {
941#define FIND_SYM(B) \
942 if (elf->elf_class == ELFCLASS ## B) { \
943 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
944 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
945 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
946 unsigned long cnt = EGET(symtab->sh_entsize); \
947 char *symname; \
948 if (cnt) \
949 cnt = EGET(symtab->sh_size) / cnt; \
950 for (i = 0; i < cnt; ++i) { \
951 if (sym->st_name) { \
952 /* make sure the symbol name is in acceptable memory range */ \
953 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
954 if ((void*)symname > (void*)elf->data_end) { \
955 warnf("%s: corrupt ELF symbols", elf->filename); \
956 ++sym; \
957 continue; \
958 } \
959 /* debug display ... show all symbols and some extra info */ \
960 if (*ret == '*') { \
961 printf("%s(%s) %5lX %15s %s\n", \
962 ((*found_sym == 0) ? "\n\t" : "\t"), \
963 elf->base_filename, \
964 (unsigned long)sym->st_size, \
965 get_elfstttype(sym->st_info), \
966 symname); \
967 *found_sym = 1; \
968 } else { \
969 /* allow the user to specify a comma delimited list of symbols to search for */ \
970 char *this_sym, *next_sym; \
971 this_sym = ret; \
972 do { \
973 next_sym = strchr(this_sym, ','); \
974 if (next_sym == NULL) \
975 next_sym = this_sym + strlen(this_sym); \
976 /* do we want a defined symbol ? */ \
977 if (*this_sym == '+') { \
978 if (sym->st_shndx == SHN_UNDEF) \
979 goto skip_this_sym##B; \
980 ++this_sym; \
981 /* do we want an undefined symbol ? */ \
982 } else if (*this_sym == '-') { \
983 if (sym->st_shndx != SHN_UNDEF) \
984 goto skip_this_sym##B; \
985 ++this_sym; \
986 } \
987 /* ok, lets compare the name now */ \
988 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
989 (strncmp(symname, versioned_symname, strlen(versioned_symname)) == 0)) { \
990 if (be_semi_verbose) { \
991 char buf[126]; \
992 snprintf(buf, sizeof(buf), "%lX %s %s", \
993 (unsigned long)sym->st_size, get_elfstttype(sym->st_info), this_sym); \
994 ret = buf; \
995 } else \
996 ret = this_sym; \
997 (*found_sym)++; \
998 goto break_out; \
999 } \
1000 skip_this_sym##B: this_sym = next_sym + 1; \
1001 } while (*next_sym != '\0'); \
1002 } \
1003 } \
1004 ++sym; \
1005 } }
1006 FIND_SYM(32)
1007 FIND_SYM(64)
1008 }
1009
1010break_out:
1011 if (be_wewy_wewy_quiet) return NULL;
1012
1013 if (*find_sym != '*' && *found_sym)
1014 return ret;
1015 if (be_quiet)
1016 return NULL;
1017 else
1018 return (char *)" - ";
1019}
1020
1021
1022static char *scanelf_file_sections(elfobj *elf, char *found_section)
1023{
1024 if (!find_section)
1025 return NULL;
1026
1027#define FIND_SECTION(B) \
1028 if (elf->elf_class == ELFCLASS ## B) { \
1029 int invert; \
1030 Elf ## B ## _Shdr *section; \
1031 invert = (*find_section == '!' ? 1 : 0); \
1032 section = SHDR ## B (elf_findsecbyname(elf, find_section+invert)); \
1033 if ((section == NULL && invert) || (section != NULL && !invert)) \
1034 *found_section = 1; \
1035 }
1036 FIND_SECTION(32)
1037 FIND_SECTION(64)
1038
1039 if (be_wewy_wewy_quiet)
1040 return NULL;
1041
1042 if (*found_section)
1043 return find_section;
1044
1045 if (be_quiet)
1046 return NULL;
1047 else
1048 return (char *)" - ";
1049}
74 1050
75/* scan an elf file and show all the fun stuff */ 1051/* scan an elf file and show all the fun stuff */
76static void scanelf_file(const char *filename) 1052#define prints(str) write(fileno(stdout), str, strlen(str))
1053static int scanelf_elfobj(elfobj *elf)
77{ 1054{
78 int i; 1055 unsigned long i;
79 char found_pax, found_stack, found_relro, found_textrel, found_rpath; 1056 char found_pax, found_phdr, found_relro, found_load, found_textrel,
80 Elf_Dyn *dyn; 1057 found_rpath, found_needed, found_interp, found_bind, found_soname,
81 elfobj *elf = NULL; 1058 found_sym, found_lib, found_file, found_textrels, found_section;
1059 static char *out_buffer = NULL;
1060 static size_t out_len;
82 1061
83 found_pax = found_stack = found_relro = found_textrel = found_rpath = 0; 1062 found_pax = found_phdr = found_relro = found_load = found_textrel = \
1063 found_rpath = found_needed = found_interp = found_bind = found_soname = \
1064 found_sym = found_lib = found_file = found_textrels = found_section = 0;
84 1065
85 /* verify this is real ELF */ 1066 if (be_verbose > 2)
86 if ((elf = readelf(filename)) == NULL) { 1067 printf("%s: scanning file {%s,%s}\n", elf->filename,
87 if (be_verbose > 1) printf("%s: not an ELF\n", filename); 1068 get_elfeitype(EI_CLASS, elf->elf_class),
88 return; 1069 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
89 } 1070 else if (be_verbose > 1)
90 if (check_elf_header(elf->ehdr) || !IS_ELF(elf)) {
91 if (be_verbose > 1) printf("%s: cannot handle ELF :(\n", filename);
92 goto bail;
93 }
94
95 if (be_verbose) printf("%s: scanning file\n", filename); 1071 printf("%s: scanning file\n", elf->filename);
1072
1073 /* init output buffer */
1074 if (!out_buffer) {
1075 out_len = sizeof(char) * 80;
1076 out_buffer = (char*)xmalloc(out_len);
1077 }
1078 *out_buffer = '\0';
96 1079
97 /* show the header */ 1080 /* show the header */
98 if (!be_quiet && show_banner) { 1081 if (!be_quiet && show_banner) {
99 fputs(" TYPE ", stdout); 1082 for (i = 0; out_format[i]; ++i) {
100 if (show_pax) fputs(" PAX ", stdout); 1083 if (!IS_MODIFIER(out_format[i])) continue;
101 if (show_stack) fputs(" STK/REL ", stdout); 1084
102 if (show_textrel) fputs("TEXTREL ", stdout); 1085 switch (out_format[++i]) {
103 if (show_rpath) fputs("RPATH ", stdout); 1086 case '+': break;
104 fputs(" FILE\n", stdout); 1087 case '%': break;
1088 case '#': break;
1089 case 'F':
1090 case 'p':
1091 case 'f': prints("FILE "); found_file = 1; break;
1092 case 'o': prints(" TYPE "); break;
1093 case 'x': prints(" PAX "); break;
1094 case 'e': prints("STK/REL/PTL "); break;
1095 case 't': prints("TEXTREL "); break;
1096 case 'r': prints("RPATH "); break;
1097 case 'n': prints("NEEDED "); break;
1098 case 'i': prints("INTERP "); break;
1099 case 'b': prints("BIND "); break;
1100 case 'S': prints("SONAME "); break;
1101 case 's': prints("SYM "); break;
1102 case 'N': prints("LIB "); break;
1103 case 'T': prints("TEXTRELS "); break;
1104 case 'k': prints("SECTION "); break;
1105 default: warnf("'%c' has no title ?", out_format[i]);
1106 }
1107 }
1108 if (!found_file) prints("FILE ");
1109 prints("\n");
1110 found_file = 0;
105 show_banner = 0; 1111 show_banner = 0;
106 } 1112 }
107 1113
108 /* dump all the good stuff */ 1114 /* dump all the good stuff */
109 if (!be_quiet) 1115 for (i = 0; out_format[i]; ++i) {
110 printf("%-7s ", get_elfetype(elf->ehdr->e_type)); 1116 const char *out;
1117 const char *tmp;
111 1118
112 if (show_pax) { 1119 if (!IS_MODIFIER(out_format[i])) {
113 char *paxflags = pax_short_hf_flags(PAX_FLAGS(elf)); 1120 xchrcat(&out_buffer, out_format[i], &out_len);
114 if (!be_quiet || (be_quiet && strncmp(paxflags, "PeMRxS", 6))) {
115 found_pax = 1;
116 printf("%s ", pax_short_hf_flags(PAX_FLAGS(elf)));
117 }
118 }
119
120 /* stack fun */
121 if (show_stack) {
122 for (i = 0; i < elf->ehdr->e_phnum; i++) {
123 if (elf->phdr[i].p_type != PT_GNU_STACK && \
124 elf->phdr[i].p_type != PT_GNU_RELRO) continue;
125
126 if (be_quiet && !(elf->phdr[i].p_flags & PF_X))
127 continue; 1121 continue;
128
129 if (elf->phdr[i].p_type == PT_GNU_STACK)
130 found_stack = 1;
131 if (elf->phdr[i].p_type == PT_GNU_RELRO)
132 found_relro = 1;
133
134 printf("%s ", gnu_short_stack_flags(elf->phdr[i].p_flags));
135 }
136 if (!be_quiet && !found_stack) fputs("--- ", stdout);
137 if (!be_quiet && !found_relro) fputs("--- ", stdout);
138 } 1122 }
139 1123
140 /* textrel fun */ 1124 out = NULL;
141 if (show_textrel) { 1125 be_wewy_wewy_quiet = (out_format[i] == '#');
142 for (i = 0; i < elf->ehdr->e_phnum; i++) { 1126 be_semi_verbose = (out_format[i] == '+');
143 if (elf->phdr[i].p_type != PT_DYNAMIC) continue; 1127 switch (out_format[++i]) {
144 1128 case '+':
145 dyn = (Elf_Dyn *)(elf->data + elf->phdr[i].p_offset); 1129 case '%':
146 while (dyn->d_tag != DT_NULL) { 1130 case '#':
147 if (dyn->d_tag == DT_TEXTREL) { //dyn->d_tag != DT_FLAGS) 1131 xchrcat(&out_buffer, out_format[i], &out_len); break;
148 found_textrel = 1; 1132 case 'F':
149// if (dyn->d_un.d_val & DF_TEXTREL) 1133 found_file = 1;
150 fputs("TEXTREL ", stdout); 1134 if (be_wewy_wewy_quiet) break;
151 } 1135 xstrcat(&out_buffer, elf->filename, &out_len);
152 ++dyn; 1136 break;
1137 case 'p':
1138 found_file = 1;
1139 if (be_wewy_wewy_quiet) break;
1140 tmp = elf->filename;
1141 if (search_path) {
1142 ssize_t len_search = strlen(search_path);
1143 ssize_t len_file = strlen(elf->filename);
1144 if (!strncmp(elf->filename, search_path, len_search) && \
1145 len_file > len_search)
1146 tmp += len_search;
1147 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
153 } 1148 }
154 } 1149 xstrcat(&out_buffer, tmp, &out_len);
155 if (!be_quiet && !found_textrel) fputs("------- ", stdout); 1150 break;
1151 case 'f':
1152 found_file = 1;
1153 if (be_wewy_wewy_quiet) break;
1154 tmp = strrchr(elf->filename, '/');
1155 tmp = (tmp == NULL ? elf->filename : tmp+1);
1156 xstrcat(&out_buffer, tmp, &out_len);
1157 break;
1158 case 'o': out = get_elfetype(elf); break;
1159 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1160 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1161 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1162 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1163 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1164 case 'n':
1165 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1166 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1167 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1168 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1169 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1170 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1171 default: warnf("'%c' has no scan code?", out_format[i]);
156 } 1172 }
157 1173 if (out) {
158 /* rpath fun */ 1174 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
159 /* TODO: if be_quiet, only output RPATH's which aren't in /etc/ld.so.conf */ 1175 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
160 if (show_rpath) { 1176 xstrncat(&out_buffer, out, &out_len, (tmp-out));
161 Elf_Shdr *strtbl = elf_findsecbyname(elf, ".dynstr"); 1177 else
162 1178 xstrcat(&out_buffer, out, &out_len);
163 if (strtbl)
164 for (i = 0; i < elf->ehdr->e_phnum; i++) {
165 if (elf->phdr[i].p_type != PT_DYNAMIC) continue;
166
167 dyn = (Elf_Dyn *)(elf->data + elf->phdr[i].p_offset);
168 while (dyn->d_tag != DT_NULL) {
169 if (dyn->d_tag == DT_RPATH) { //|| dyn->d_tag != DT_RUNPATH)
170 char *rpath = elf->data + strtbl->sh_offset + dyn->d_un.d_ptr;
171 found_rpath = 1;
172 printf("%s ", rpath);
173 } 1179 }
174 ++dyn; 1180 }
1181
1182#define FOUND_SOMETHING() \
1183 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
1184 found_rpath || found_needed || found_interp || found_bind || \
1185 found_soname || found_sym || found_lib || found_textrels || found_section )
1186
1187 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1188 xchrcat(&out_buffer, ' ', &out_len);
1189 xstrcat(&out_buffer, elf->filename, &out_len);
1190 }
1191 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
1192 puts(out_buffer);
1193 fflush(stdout);
1194 }
1195
1196 return 0;
1197}
1198
1199/* scan a single elf */
1200static int scanelf_elf(const char *filename, int fd, size_t len)
1201{
1202 int ret = 1;
1203 elfobj *elf;
1204
1205 /* verify this is real ELF */
1206 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1207 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1208 return ret;
1209 }
1210 switch (match_bits) {
1211 case 32:
1212 if (elf->elf_class != ELFCLASS32)
1213 goto label_done;
1214 break;
1215 case 64:
1216 if (elf->elf_class != ELFCLASS64)
1217 goto label_done;
1218 break;
1219 default: break;
1220 }
1221 if (strlen(match_etypes)) {
1222 char sbuf[126];
1223 strncpy(sbuf, match_etypes, sizeof(sbuf));
1224 if (strchr(match_etypes, ',') != NULL) {
1225 char *p;
1226 while((p = strrchr(sbuf, ',')) != NULL) {
1227 *p = 0;
1228 if (etype_lookup(p+1) == get_etype(elf))
1229 goto label_ret;
175 } 1230 }
176 } 1231 }
177 if (!be_quiet && !found_rpath) fputs(" - ", stdout); 1232 if (etype_lookup(sbuf) != get_etype(elf))
1233 goto label_done;
178 } 1234 }
179 1235
180 if (!be_quiet || found_pax || found_stack || found_textrel || found_rpath) 1236label_ret:
181 puts(filename); 1237 ret = scanelf_elfobj(elf);
182 1238
183bail: 1239label_done:
184 unreadelf(elf); 1240 unreadelf(elf);
1241 return ret;
1242}
1243
1244/* scan an archive of elfs */
1245static int scanelf_archive(const char *filename, int fd, size_t len)
1246{
1247 archive_handle *ar;
1248 archive_member *m;
1249 char *ar_buffer;
1250 elfobj *elf;
1251
1252 ar = ar_open_fd(filename, fd);
1253 if (ar == NULL)
1254 return 1;
1255
1256 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1257 while ((m=ar_next(ar)) != NULL) {
1258 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size);
1259 if (elf) {
1260 scanelf_elfobj(elf);
1261 unreadelf(elf);
1262 }
1263 }
1264 munmap(ar_buffer, len);
1265
1266 return 0;
1267}
1268/* scan a file which may be an elf or an archive or some other magical beast */
1269static void scanelf_file(const char *filename)
1270{
1271 struct stat st;
1272 int fd;
1273
1274 /* make sure 'filename' exists */
1275 if (lstat(filename, &st) == -1) {
1276 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1277 return;
1278 }
1279
1280 /* always handle regular files and handle symlinked files if no -y */
1281 if (S_ISLNK(st.st_mode)) {
1282 if (!scan_symlink) return;
1283 stat(filename, &st);
1284 }
1285 if (!S_ISREG(st.st_mode)) {
1286 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1287 return;
1288 }
1289
1290 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1)
1291 return;
1292
1293 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives)
1294 /* if it isn't an ELF, maybe it's an .a archive */
1295 scanelf_archive(filename, fd, st.st_size);
1296
1297 close(fd);
185} 1298}
186 1299
187/* scan a directory for ET_EXEC files and print when we find one */ 1300/* scan a directory for ET_EXEC files and print when we find one */
188static void scanelf_dir(const char *path) 1301static void scanelf_dir(const char *path)
189{ 1302{
190 register DIR *dir; 1303 register DIR *dir;
191 register struct dirent *dentry; 1304 register struct dirent *dentry;
192 struct stat st_top, st; 1305 struct stat st_top, st;
193 char *p; 1306 char buf[__PAX_UTILS_PATH_MAX];
194 int len = 0; 1307 size_t pathlen = 0, len = 0;
195 1308
196 /* make sure path exists */ 1309 /* make sure path exists */
197 if (lstat(path, &st_top) == -1) 1310 if (lstat(path, &st_top) == -1) {
1311 if (be_verbose > 2) printf("%s: does not exist\n", path);
198 return; 1312 return;
1313 }
199 1314
200 /* ok, if it isn't a directory, assume we can open it */ 1315 /* ok, if it isn't a directory, assume we can open it */
201 if (!S_ISDIR(st_top.st_mode)) { 1316 if (!S_ISDIR(st_top.st_mode)) {
202 scanelf_file(path); 1317 scanelf_file(path);
203 return; 1318 return;
206 /* now scan the dir looking for fun stuff */ 1321 /* now scan the dir looking for fun stuff */
207 if ((dir = opendir(path)) == NULL) { 1322 if ((dir = opendir(path)) == NULL) {
208 warnf("could not opendir %s: %s", path, strerror(errno)); 1323 warnf("could not opendir %s: %s", path, strerror(errno));
209 return; 1324 return;
210 } 1325 }
211 if (be_verbose) printf("%s: scanning dir\n", path); 1326 if (be_verbose > 1) printf("%s: scanning dir\n", path);
212 1327
1328 pathlen = strlen(path);
213 while ((dentry = readdir(dir))) { 1329 while ((dentry = readdir(dir))) {
214 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1330 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
215 continue; 1331 continue;
216 len = (strlen(path) + 2 + strlen(dentry->d_name)); 1332 len = (pathlen + 1 + strlen(dentry->d_name) + 1);
217 p = malloc(len); 1333 if (len >= sizeof(buf)) {
218 if (!p) 1334 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
219 err("scanelf_dir(): Could not malloc: %s", strerror(errno)); 1335 (unsigned long)len, (unsigned long)sizeof(buf));
220 strncpy(p, path, len); 1336 continue;
221 strncat(p, "/", len); 1337 }
222 strncat(p, dentry->d_name, len); 1338 snprintf(buf, sizeof(buf), "%s%s%s", path, (path[pathlen-1] == '/') ? "" : "/", dentry->d_name);
223 if (lstat(p, &st) != -1) { 1339 if (lstat(buf, &st) != -1) {
224 if (S_ISREG(st.st_mode)) 1340 if (S_ISREG(st.st_mode))
225 scanelf_file(p); 1341 scanelf_file(buf);
226 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1342 else if (dir_recurse && S_ISDIR(st.st_mode)) {
227 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1343 if (dir_crossmount || (st_top.st_dev == st.st_dev))
228 scanelf_dir(p); 1344 scanelf_dir(buf);
229 } 1345 }
230 } 1346 }
231 free(p);
232 } 1347 }
233 closedir(dir); 1348 closedir(dir);
234} 1349}
1350
1351static int scanelf_from_file(const char *filename)
1352{
1353 FILE *fp = NULL;
1354 char *p;
1355 char path[__PAX_UTILS_PATH_MAX];
1356
1357 if (strcmp(filename, "-") == 0)
1358 fp = stdin;
1359 else if ((fp = fopen(filename, "r")) == NULL)
1360 return 1;
1361
1362 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1363 if ((p = strchr(path, '\n')) != NULL)
1364 *p = 0;
1365 search_path = path;
1366 scanelf_dir(path);
1367 }
1368 if (fp != stdin)
1369 fclose(fp);
1370 return 0;
1371}
1372
1373#if defined(__GLIBC__) || defined(__UCLIBC__)
1374static int load_ld_so_conf(int i, const char *fname)
1375{
1376 FILE *fp = NULL;
1377 char *p;
1378 char path[__PAX_UTILS_PATH_MAX];
1379
1380 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1381 return i;
1382
1383 if ((fp = fopen(fname, "r")) == NULL)
1384 return i;
1385
1386 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1387 if ((p = strrchr(path, '\r')) != NULL)
1388 *p = 0;
1389 if ((p = strchr(path, '\n')) != NULL)
1390 *p = 0;
1391 // recursive includes of the same file will make this segfault.
1392 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1393 glob64_t gl;
1394 size_t x;
1395 char gpath[__PAX_UTILS_PATH_MAX];
1396
1397 memset(gpath, 0, sizeof(gpath));
1398
1399 if (path[8] != '/')
1400 snprintf(gpath, sizeof(gpath), "/etc/%s", &path[8]);
1401 else
1402 strncpy(gpath, &path[8], sizeof(gpath));
1403
1404 if ((glob64(gpath, 0, NULL, &gl)) == 0) {
1405 for (x = 0; x < gl.gl_pathc; ++x) {
1406 /* try to avoid direct loops */
1407 if (strcmp(gl.gl_pathv[x], fname) == 0)
1408 continue;
1409 i = load_ld_so_conf(i, gl.gl_pathv[x]);
1410 if (i + 1 >= sizeof(ldpaths) / sizeof(*ldpaths)) {
1411 globfree64(&gl);
1412 return i;
1413 }
1414 }
1415 globfree64 (&gl);
1416 continue;
1417 } else
1418 abort();
1419 }
1420 if (*path != '/')
1421 continue;
1422
1423 ldpaths[i++] = xstrdup(path);
1424
1425 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1426 break;
1427 }
1428 ldpaths[i] = NULL;
1429
1430 fclose(fp);
1431 return i;
1432}
1433#endif
1434
1435#if defined(__FreeBSD__) || (__DragonFly__)
1436static int load_ld_so_hints(int i, const char *fname)
1437{
1438 FILE *fp = NULL;
1439 char *b = NULL, *p;
1440 struct elfhints_hdr hdr;
1441
1442 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1443 return i;
1444
1445 if ((fp = fopen(fname, "r")) == NULL)
1446 return i;
1447
1448 if ( fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1449 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1450 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1
1451 ) {
1452 fclose(fp);
1453 return i;
1454 }
1455
1456 b = (char*)malloc(hdr.dirlistlen+1);
1457 if ( fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1 ) {
1458 fclose(fp);
1459 free(b);
1460 return i;
1461 }
1462
1463 while ( (p = strsep(&b, ":")) ) {
1464 if ( *p == '\0' ) continue;
1465 ldpaths[i++] = xstrdup(p);
1466
1467 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths))
1468 break;
1469 }
1470 ldpaths[i] = NULL;
1471
1472 free(b);
1473 fclose(fp);
1474 return i;
1475}
1476#endif
235 1477
236/* scan /etc/ld.so.conf for paths */ 1478/* scan /etc/ld.so.conf for paths */
237static void scanelf_ldpath() 1479static void scanelf_ldpath()
238{ 1480{
239 char scan_l, scan_ul, scan_ull; 1481 char scan_l, scan_ul, scan_ull;
240 char *path, *p; 1482 int i = 0;
241 FILE *fp;
242 1483
243 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1484 if (!ldpaths[0])
244 err("Unable to open ld.so.conf: %s", strerror(errno)); 1485 err("Unable to load any paths from ld.so.conf");
245 1486
246 scan_l = scan_ul = scan_ull = 0; 1487 scan_l = scan_ul = scan_ull = 0;
247 1488
248 path = malloc(_POSIX_PATH_MAX); 1489 while (ldpaths[i]) {
249 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL)
250 if (*path == '/') {
251 if ((p = strrchr(path, '\r')) != NULL)
252 *p = 0;
253 if ((p = strrchr(path, '\n')) != NULL)
254 *p = 0;
255 if (!scan_l && !strcmp(path, "/lib")) scan_l = 1; 1490 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
256 if (!scan_ul && !strcmp(path, "/usr/lib")) scan_ul = 1; 1491 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
257 if (!scan_ull && !strcmp(path, "/usr/local/lib")) scan_ull = 1; 1492 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
258 scanelf_dir(path); 1493 scanelf_dir(ldpaths[i]);
1494 ++i;
259 } 1495 }
260 free(path);
261 1496
262 if (!scan_l) scanelf_dir("/lib"); 1497 if (!scan_l) scanelf_dir("/lib");
263 if (!scan_ul) scanelf_dir("/usr/lib"); 1498 if (!scan_ul) scanelf_dir("/usr/lib");
264 if (!scan_ull) scanelf_dir("/usr/local/lib"); 1499 if (!scan_ull) scanelf_dir("/usr/local/lib");
265
266 fclose(fp);
267} 1500}
268 1501
269/* scan env PATH for paths */ 1502/* scan env PATH for paths */
270static void scanelf_envpath() 1503static void scanelf_envpath()
271{ 1504{
272 char *path, *p; 1505 char *path, *p;
273 1506
274 path = getenv("PATH"); 1507 path = getenv("PATH");
275 if (!path) 1508 if (!path)
276 err("PATH is not set in your env !"); 1509 err("PATH is not set in your env !");
277 1510 path = xstrdup(path);
278 if ((path = strdup(path)) == NULL)
279 err("stdup failed: %s", strerror(errno));
280 1511
281 while ((p = strrchr(path, ':')) != NULL) { 1512 while ((p = strrchr(path, ':')) != NULL) {
282 scanelf_dir(p + 1); 1513 scanelf_dir(p + 1);
283 *p = 0; 1514 *p = 0;
284 } 1515 }
285 1516
286 free(path); 1517 free(path);
287} 1518}
288 1519
289
290
291/* usage / invocation handling functions */ 1520/* usage / invocation handling functions */
292#define PARSE_FLAGS "plRmxetraqvBhV" 1521#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:BhV"
1522#define a_argument required_argument
293static struct option const long_opts[] = { 1523static struct option const long_opts[] = {
294 {"path", no_argument, NULL, 'p'}, 1524 {"path", no_argument, NULL, 'p'},
295 {"ldpath", no_argument, NULL, 'l'}, 1525 {"ldpath", no_argument, NULL, 'l'},
296 {"recursive", no_argument, NULL, 'R'}, 1526 {"recursive", no_argument, NULL, 'R'},
297 {"mount", no_argument, NULL, 'm'}, 1527 {"mount", no_argument, NULL, 'm'},
1528 {"symlink", no_argument, NULL, 'y'},
1529 {"archives", no_argument, NULL, 'A'},
1530 {"ldcache", no_argument, NULL, 'L'},
1531 {"fix", no_argument, NULL, 'X'},
1532 {"setpax", a_argument, NULL, 'z'},
298 {"pax", no_argument, NULL, 'x'}, 1533 {"pax", no_argument, NULL, 'x'},
299 {"header", no_argument, NULL, 'e'}, 1534 {"header", no_argument, NULL, 'e'},
300 {"textrel", no_argument, NULL, 't'}, 1535 {"textrel", no_argument, NULL, 't'},
301 {"rpath", no_argument, NULL, 'r'}, 1536 {"rpath", no_argument, NULL, 'r'},
1537 {"needed", no_argument, NULL, 'n'},
1538 {"interp", no_argument, NULL, 'i'},
1539 {"bind", no_argument, NULL, 'b'},
1540 {"soname", no_argument, NULL, 'S'},
1541 {"symbol", a_argument, NULL, 's'},
1542 {"section", a_argument, NULL, 'k'},
1543 {"lib", a_argument, NULL, 'N'},
1544 {"gmatch", no_argument, NULL, 'g'},
1545 {"textrels", no_argument, NULL, 'T'},
1546 {"etype", a_argument, NULL, 'E'},
1547 {"bits", a_argument, NULL, 'M'},
302 {"all", no_argument, NULL, 'a'}, 1548 {"all", no_argument, NULL, 'a'},
303 {"quiet", no_argument, NULL, 'q'}, 1549 {"quiet", no_argument, NULL, 'q'},
304 {"verbose", no_argument, NULL, 'v'}, 1550 {"verbose", no_argument, NULL, 'v'},
1551 {"format", a_argument, NULL, 'F'},
1552 {"from", a_argument, NULL, 'f'},
1553 {"file", a_argument, NULL, 'o'},
305 {"nobanner", no_argument, NULL, 'B'}, 1554 {"nobanner", no_argument, NULL, 'B'},
306 {"help", no_argument, NULL, 'h'}, 1555 {"help", no_argument, NULL, 'h'},
307 {"version", no_argument, NULL, 'V'}, 1556 {"version", no_argument, NULL, 'V'},
308 {NULL, no_argument, NULL, 0x0} 1557 {NULL, no_argument, NULL, 0x0}
309}; 1558};
1559
310static char *opts_help[] = { 1560static const char *opts_help[] = {
311 "Scan all directories in PATH environment", 1561 "Scan all directories in PATH environment",
312 "Scan all directories in /etc/ld.so.conf", 1562 "Scan all directories in /etc/ld.so.conf",
313 "Scan directories recursively", 1563 "Scan directories recursively",
314 "Don't recursively cross mount points\n", 1564 "Don't recursively cross mount points",
1565 "Don't scan symlinks",
1566 "Scan archives (.a files)",
1567 "Utilize ld.so.cache information (use with -r/-n)",
1568 "Try and 'fix' bad things (use with -r/-e)",
1569 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
315 "Print PaX markings", 1570 "Print PaX markings",
316 "Print GNU_STACK markings", 1571 "Print GNU_STACK/PT_LOAD markings",
317 "Print TEXTREL information", 1572 "Print TEXTREL information",
318 "Print RPATH information", 1573 "Print RPATH information",
1574 "Print NEEDED information",
1575 "Print INTERP information",
1576 "Print BIND information",
1577 "Print SONAME information",
1578 "Find a specified symbol",
1579 "Find a specified section",
1580 "Find a specified library",
1581 "Use strncmp to match libraries. (use with -N)",
1582 "Locate cause of TEXTREL",
1583 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1584 "Print only ELF files matching numeric bits",
319 "Print all scanned info (-x -e -t -r)\n", 1585 "Print all scanned info (-x -e -t -r -b)\n",
320 "Only output 'bad' things", 1586 "Only output 'bad' things",
321 "Be verbose (can be specified more than once)", 1587 "Be verbose (can be specified more than once)",
1588 "Use specified format for output",
1589 "Read input stream from a filename",
1590 "Write output stream to a filename",
322 "Don't display the header", 1591 "Don't display the header",
323 "Print this help and exit", 1592 "Print this help and exit",
324 "Print version and exit", 1593 "Print version and exit",
325 NULL 1594 NULL
326}; 1595};
327 1596
328/* display usage and exit */ 1597/* display usage and exit */
329static void usage(int status) 1598static void usage(int status)
330{ 1599{
331 int i; 1600 unsigned long i;
332 printf(" Scan ELF binaries for stuff\n\n" 1601 printf("* Scan ELF binaries for stuff\n\n"
333 "Usage: %s [options] <dir1> [dir2 dirN ...]\n\n", argv0); 1602 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
334 fputs("Options:\n", stdout); 1603 printf("Options: -[%s]\n", PARSE_FLAGS);
335 for (i = 0; long_opts[i].name; ++i) 1604 for (i = 0; long_opts[i].name; ++i)
1605 if (long_opts[i].has_arg == no_argument)
336 printf(" -%c, --%-12s %s\n", long_opts[i].val, 1606 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
337 long_opts[i].name, opts_help[i]); 1607 long_opts[i].name, opts_help[i]);
338#ifdef MANLYPAGE 1608 else
339 for (i = 0; long_opts[i].name; ++i) 1609 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
340 printf(".TP\n\\fB\\-%c, \\-\\-%s\\fR\n%s\n", long_opts[i].val,
341 long_opts[i].name, opts_help[i]); 1610 long_opts[i].name, opts_help[i]);
342#endif 1611
1612 if (status != EXIT_SUCCESS)
1613 exit(status);
1614
1615 puts("\nThe format modifiers for the -F option are:");
1616 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1617 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1618 puts(" i INTERP \tb BIND \ts symbol");
1619 puts(" N library \to Type \tT TEXTRELs");
1620 puts(" S SONAME \tk section");
1621 puts(" p filename (with search path removed)");
1622 puts(" f filename (short name/basename)");
1623 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1624
1625 puts("\nELF Etypes:");
1626 print_etypes(stdout);
1627
343 exit(status); 1628 exit(status);
344} 1629}
345 1630
346/* parse command line arguments and preform needed actions */ 1631/* parse command line arguments and preform needed actions */
347static void parseargs(int argc, char *argv[]) 1632static void parseargs(int argc, char *argv[])
348{ 1633{
349 int flag; 1634 int i;
1635 const char *from_file = NULL;
350 1636
351 opterr = 0; 1637 opterr = 0;
352 while ((flag=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 1638 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
353 switch (flag) { 1639 switch (i) {
354 1640
355 case 'V': /* version info */ 1641 case 'V':
356 printf("%s compiled %s\n" 1642 printf("pax-utils-%s: %s compiled %s\n%s\n"
357 "%s written for Gentoo Linux by <solar and vapier @ gentoo.org>\n" 1643 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
358 "%s\n",
359 __FILE__, __DATE__, argv0, rcsid); 1644 VERSION, __FILE__, __DATE__, rcsid, argv0);
360 exit(EXIT_SUCCESS); 1645 exit(EXIT_SUCCESS);
361 break; 1646 break;
362 case 's': /* reserved for -s, --symbol= */
363 case 'h': usage(EXIT_SUCCESS); break; 1647 case 'h': usage(EXIT_SUCCESS); break;
1648 case 'f':
1649 if (from_file) warn("You prob don't want to specify -f twice");
1650 from_file = optarg;
1651 break;
1652 case 'E':
1653 strncpy(match_etypes, optarg, sizeof(match_etypes));
1654 break;
1655 case 'M':
1656 match_bits = atoi(optarg);
1657 break;
1658 case 'o': {
1659 if (freopen(optarg, "w", stdout) == NULL)
1660 err("Could not open output stream '%s': %s", optarg, strerror(errno));
1661 break;
1662 }
1663 case 'k':
1664 if (find_section) warn("You prob don't want to specify -k twice");
1665 find_section = optarg;
1666 break;
1667 case 's': {
1668 if (find_sym) warn("You prob don't want to specify -s twice");
1669 find_sym = optarg;
1670 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1671 sprintf(versioned_symname, "%s@", find_sym);
1672 break;
1673 }
1674 case 'N': {
1675 if (find_lib) warn("You prob don't want to specify -N twice");
1676 find_lib = optarg;
1677 break;
1678 }
364 1679
1680 case 'F': {
1681 if (out_format) warn("You prob don't want to specify -F twice");
1682 out_format = optarg;
1683 break;
1684 }
1685 case 'z': {
1686 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1687 size_t x;
1688
1689 for (x = 0 ; x < strlen(optarg); x++) {
1690 switch(optarg[x]) {
1691 case 'p':
1692 case 'P':
1693 do_state(optarg[x], PAGEEXEC);
1694 break;
1695 case 's':
1696 case 'S':
1697 do_state(optarg[x], SEGMEXEC);
1698 break;
1699 case 'm':
1700 case 'M':
1701 do_state(optarg[x], MPROTECT);
1702 break;
1703 case 'e':
1704 case 'E':
1705 do_state(optarg[x], EMUTRAMP);
1706 break;
1707 case 'r':
1708 case 'R':
1709 do_state(optarg[x], RANDMMAP);
1710 break;
1711 case 'x':
1712 case 'X':
1713 do_state(optarg[x], RANDEXEC);
1714 break;
1715 default:
1716 break;
1717 }
1718 }
1719 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
1720 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
1721 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
1722 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
1723 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1724 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1725 setpax = flags;
1726 break;
1727 }
1728 case 'g': gmatch = 1; break;
1729 case 'L': use_ldcache = 1; break;
1730 case 'y': scan_symlink = 0; break;
1731 case 'A': scan_archives = 1; break;
365 case 'B': show_banner = 0; break; 1732 case 'B': show_banner = 0; break;
366 case 'l': scan_ldpath = 1; break; 1733 case 'l': scan_ldpath = 1; break;
367 case 'p': scan_envpath = 1; break; 1734 case 'p': scan_envpath = 1; break;
368 case 'R': dir_recurse = 1; break; 1735 case 'R': dir_recurse = 1; break;
369 case 'm': dir_crossmount = 0; break; 1736 case 'm': dir_crossmount = 0; break;
1737 case 'X': ++fix_elf; break;
370 case 'x': show_pax = 1; break; 1738 case 'x': show_pax = 1; break;
371 case 'e': show_stack = 1; break; 1739 case 'e': show_phdr = 1; break;
372 case 't': show_textrel = 1; break; 1740 case 't': show_textrel = 1; break;
373 case 'r': show_rpath = 1; break; 1741 case 'r': show_rpath = 1; break;
1742 case 'n': show_needed = 1; break;
1743 case 'i': show_interp = 1; break;
1744 case 'b': show_bind = 1; break;
1745 case 'S': show_soname = 1; break;
1746 case 'T': show_textrels = 1; break;
374 case 'q': be_quiet = 1; break; 1747 case 'q': be_quiet = 1; break;
375 case 'v': be_verbose = (be_verbose % 20) + 1; break; 1748 case 'v': be_verbose = (be_verbose % 20) + 1; break;
376 case 'a': show_pax = show_stack = show_textrel = show_rpath = 1; break; 1749 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break;
377 1750
378 case ':': 1751 case ':':
379 warn("Option missing parameter"); 1752 err("Option '%c' is missing parameter", optopt);
380 usage(EXIT_FAILURE);
381 break;
382 case '?': 1753 case '?':
383 warn("Unknown option"); 1754 err("Unknown option '%c' or argument missing", optopt);
384 usage(EXIT_FAILURE);
385 break;
386 default: 1755 default:
387 err("Unhandled option '%c'", flag); 1756 err("Unhandled option '%c'; please report this", i);
388 break; 1757 }
1758 }
1759
1760 /* let the format option override all other options */
1761 if (out_format) {
1762 show_pax = show_phdr = show_textrel = show_rpath = \
1763 show_needed = show_interp = show_bind = show_soname = \
1764 show_textrels = 0;
1765 for (i = 0; out_format[i]; ++i) {
1766 if (!IS_MODIFIER(out_format[i])) continue;
1767
1768 switch (out_format[++i]) {
1769 case '+': break;
1770 case '%': break;
1771 case '#': break;
1772 case 'F': break;
1773 case 'p': break;
1774 case 'f': break;
1775 case 'k': break;
1776 case 's': break;
1777 case 'N': break;
1778 case 'o': break;
1779 case 'x': show_pax = 1; break;
1780 case 'e': show_phdr = 1; break;
1781 case 't': show_textrel = 1; break;
1782 case 'r': show_rpath = 1; break;
1783 case 'n': show_needed = 1; break;
1784 case 'i': show_interp = 1; break;
1785 case 'b': show_bind = 1; break;
1786 case 'S': show_soname = 1; break;
1787 case 'T': show_textrels = 1; break;
1788 default:
1789 err("Invalid format specifier '%c' (byte %i)",
1790 out_format[i], i+1);
389 } 1791 }
390 } 1792 }
391 1793
392 if (be_quiet && be_verbose) 1794 /* construct our default format */
393 err("You can be quiet or you can be verbose, not both, stupid"); 1795 } else {
1796 size_t fmt_len = 30;
1797 out_format = (char*)xmalloc(sizeof(char) * fmt_len);
1798 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1799 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
1800 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1801 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1802 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1803 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1804 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1805 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1806 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1807 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1808 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
1809 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1810 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1811 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1812 }
1813 if (be_verbose > 2) printf("Format: %s\n", out_format);
394 1814
1815 /* now lets actually do the scanning */
1816 if (scan_ldpath || use_ldcache)
1817#if defined(__GLIBC__) || defined(__UCLIBC__)
1818 load_ld_so_conf(0, "/etc/ld.so.conf");
1819#elif defined(__FreeBSD__) || defined(__DragonFly__)
1820 load_ld_so_hints(0, _PATH_ELF_HINTS);
1821#endif
395 if (scan_ldpath) scanelf_ldpath(); 1822 if (scan_ldpath) scanelf_ldpath();
396 if (scan_envpath) scanelf_envpath(); 1823 if (scan_envpath) scanelf_envpath();
1824 if (!from_file && optind == argc && ttyname(0) == NULL)
1825 from_file = "-";
1826 if (from_file) {
1827 scanelf_from_file(from_file);
1828 from_file = *argv;
1829 }
1830 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1831 err("Nothing to scan !?");
397 while (optind < argc) 1832 while (optind < argc) {
398 scanelf_dir(argv[optind++]); 1833 search_path = argv[optind++];
1834 scanelf_dir(search_path);
1835 }
1836
1837 /* clean up */
1838 if (versioned_symname) free(versioned_symname);
1839 for (i = 0; ldpaths[i]; ++i)
1840 free(ldpaths[i]);
1841
1842 if (ldcache != 0)
1843 munmap(ldcache, ldcache_size);
1844}
1845
1846static char **get_split_env(const char *envvar) {
1847 char **envvals = NULL;
1848 char *saveptr = NULL;
1849 char *env;
1850 char *s;
1851 int nentry;
1852
1853 if ((env = getenv(envvar)) == NULL)
1854 return NULL;
1855
1856 env = xstrdup(env);
1857 if (env == NULL)
1858 return NULL;
1859
1860 nentry = 0;
1861 for (s = strtok_r(env, " \t\n", &saveptr); s != NULL; s = strtok_r(NULL, " \t\n", &saveptr)) {
1862 if ((envvals = xrealloc(envvals, sizeof(char *)*(nentry+1))) == NULL)
1863 return NULL;
1864 envvals[nentry++] = s;
1865 }
1866 envvals[nentry] = NULL;
1867
1868 return envvals;
1869}
1870
1871static void parseenv() {
1872 qa_textrels=get_split_env("QA_TEXTRELS");
1873 qa_execstack=get_split_env("QA_EXECSTACK");
1874 qa_wx_load=get_split_env("QA_WX_LOAD");
399} 1875}
400 1876
401 1877
402 1878
403int main(int argc, char *argv[]) 1879int main(int argc, char *argv[])
404{ 1880{
405 if (argc < 2) 1881 if (argc < 2)
406 usage(EXIT_FAILURE); 1882 usage(EXIT_FAILURE);
1883 parseenv();
407 parseargs(argc, argv); 1884 parseargs(argc, argv);
1885 fclose(stdout);
1886#ifdef __BOUNDS_CHECKING_ON
1887 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()");
1888#endif
408 return EXIT_SUCCESS; 1889 return EXIT_SUCCESS;
409} 1890}

Legend:
Removed from v.1.18  
changed lines
  Added in v.1.146

  ViewVC Help
Powered by ViewVC 1.1.20