/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.23 Revision 1.229
1/* 1/*
2 * Copyright 2003 Ned Ludd <solar@gentoo.org>
3 * Copyright 1999-2005 Gentoo Foundation 2 * Copyright 2003-2007 Gentoo Foundation
4 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
5 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.23 2005/04/03 18:27:45 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.229 2011/09/27 19:29:19 vapier Exp $
6 * 5 *
7 ******************************************************************** 6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
8 * This program is free software; you can redistribute it and/or 7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
9 * modify it under the terms of the GNU General Public License as
10 * published by the Free Software Foundation; either version 2 of the
11 * License, or (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place - Suite 330, Boston,
21 * MA 02111-1307, USA.
22 */ 8 */
23 9
24#include <stdio.h>
25#include <stdlib.h>
26#include <sys/types.h>
27#include <string.h>
28#include <errno.h>
29#include <unistd.h>
30#include <sys/stat.h>
31#include <dirent.h>
32#include <getopt.h>
33#include <assert.h>
34
35#include "paxelf.h"
36
37static const char *rcsid = "$Id: scanelf.c,v 1.23 2005/04/03 18:27:45 vapier Exp $"; 10static const char *rcsid = "$Id: scanelf.c,v 1.229 2011/09/27 19:29:19 vapier Exp $";
11const char argv0[] = "scanelf";
38 12
13#include "paxinc.h"
39 14
40/* helper functions for showing errors */ 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
41#define argv0 "scanelf" /*((*argv != NULL) ? argv[0] : __FILE__ "\b\b")*/
42#define warn(fmt, args...) \
43 fprintf(stderr, "%s: " fmt "\n", argv0, ## args)
44#define warnf(fmt, args...) warn("%s(): " fmt, __FUNCTION__, ## args)
45#define err(fmt, args...) \
46 do { \
47 warn(fmt, ## args); \
48 exit(EXIT_FAILURE); \
49 } while (0)
50
51
52 16
53/* prototypes */ 17/* prototypes */
54static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
55static void scanelf_dir(const char *path);
56static void scanelf_ldpath();
57static void scanelf_envpath();
58static void usage(int status);
59static void parseargs(int argc, char *argv[]);
60 19
61/* variables to control behavior */ 20/* variables to control behavior */
21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
62static char scan_ldpath = 0; 23static char scan_ldpath = 0;
63static char scan_envpath = 0; 24static char scan_envpath = 0;
25static char scan_symlink = 1;
26static char scan_archives = 0;
64static char dir_recurse = 0; 27static char dir_recurse = 0;
65static char dir_crossmount = 1; 28static char dir_crossmount = 1;
66static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
67static char show_stack = 0; 31static char show_size = 0;
32static char show_phdr = 0;
68static char show_textrel = 0; 33static char show_textrel = 0;
69static char show_rpath = 0; 34static char show_rpath = 0;
35static char show_needed = 0;
36static char show_interp = 0;
37static char show_bind = 0;
38static char show_soname = 0;
39static char show_textrels = 0;
70static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
71static char be_quiet = 0; 44static char be_quiet = 0;
72static char be_verbose = 0; 45static char be_verbose = 0;
46static char be_wewy_wewy_quiet = 0;
47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
53static char *out_format = NULL;
54static char *search_path = NULL;
55static char fix_elf = 0;
56static char g_match = 0;
57static char use_ldcache = 0;
73 58
59static char **qa_textrels = NULL;
60static char **qa_execstack = NULL;
61static char **qa_wx_load = NULL;
62static char *root;
74 63
64static int match_bits = 0;
65static unsigned int match_perms = 0;
66static void *ldcache = NULL;
67static size_t ldcache_size = 0;
68static unsigned long setpax = 0UL;
69
70static int has_objdump = 0;
71
72/* find the path to a file by name */
73static char *which(const char *fname)
74{
75 static char fullpath[__PAX_UTILS_PATH_MAX];
76 char *path, *p;
77
78 path = getenv("PATH");
79 if (!path)
80 return NULL;
81
82 path = xstrdup(path);
83 while ((p = strrchr(path, ':')) != NULL) {
84 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
85 *p = 0;
86 if (access(fullpath, R_OK) != -1) {
87 free(path);
88 return fullpath;
89 }
90 }
91 free(path);
92 return NULL;
93}
94
95/* 1 on failure. 0 otherwise */
96static int rematch(const char *regex, const char *match, int cflags)
97{
98 regex_t preg;
99 int ret;
100
101 if ((match == NULL) || (regex == NULL))
102 return EXIT_FAILURE;
103
104 if ((ret = regcomp(&preg, regex, cflags))) {
105 char err[256];
106
107 if (regerror(ret, &preg, err, sizeof(err)))
108 fprintf(stderr, "regcomp failed: %s", err);
109 else
110 fprintf(stderr, "regcomp failed");
111
112 return EXIT_FAILURE;
113 }
114 ret = regexec(&preg, match, 0, NULL, 0);
115 regfree(&preg);
116
117 return ret;
118}
119
120/* sub-funcs for scanelf_file() */
121static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab)
122{
123 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
124
125 /* debug sections */
126 void *symtab = elf_findsecbyname(elf, ".symtab");
127 void *strtab = elf_findsecbyname(elf, ".strtab");
128 /* runtime sections */
129 void *dynsym = elf_findsecbyname(elf, ".dynsym");
130 void *dynstr = elf_findsecbyname(elf, ".dynstr");
131
132#define GET_SYMTABS(B) \
133 if (elf->elf_class == ELFCLASS ## B) { \
134 if (symtab && dynsym) { \
135 Elf ## B ## _Shdr *esymtab = symtab; \
136 Elf ## B ## _Shdr *edynsym = dynsym; \
137 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
138 } else \
139 *sym = symtab ? symtab : dynsym; \
140 if (strtab && dynstr) { \
141 Elf ## B ## _Shdr *estrtab = strtab; \
142 Elf ## B ## _Shdr *edynstr = dynstr; \
143 *tab = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
144 } else \
145 *tab = strtab ? strtab : dynstr; \
146 }
147 GET_SYMTABS(32)
148 GET_SYMTABS(64)
149}
150
151static char *scanelf_file_pax(elfobj *elf, char *found_pax)
152{
153 static char ret[7];
154 unsigned long i, shown;
155
156 if (!show_pax) return NULL;
157
158 shown = 0;
159 memset(&ret, 0, sizeof(ret));
160
161 if (elf->phdr) {
162#define SHOW_PAX(B) \
163 if (elf->elf_class == ELFCLASS ## B) { \
164 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
165 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
166 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
167 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
168 continue; \
169 if (fix_elf && setpax) { \
170 /* set the paxctl flags */ \
171 ESET(phdr[i].p_flags, setpax); \
172 } \
173 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
174 continue; \
175 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
176 *found_pax = 1; \
177 ++shown; \
178 break; \
179 } \
180 }
181 SHOW_PAX(32)
182 SHOW_PAX(64)
183 }
184
185 if (fix_elf && setpax) {
186 /* set the chpax settings */
187 if (elf->elf_class == ELFCLASS32) {
188 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
189 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
190 } else {
191 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
192 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
193 }
194 }
195
196 /* fall back to EI_PAX if no PT_PAX was found */
197 if (!*ret) {
198 static char *paxflags;
199 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
200 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
201 *found_pax = 1;
202 return (be_wewy_wewy_quiet ? NULL : paxflags);
203 }
204 strncpy(ret, paxflags, sizeof(ret));
205 }
206
207 if (be_wewy_wewy_quiet || (be_quiet && !shown))
208 return NULL;
209 else
210 return ret;
211}
212
213static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
214{
215 static char ret[12];
216 char *found;
217 unsigned long i, shown, multi_stack, multi_relro, multi_load;
218 int max_pt_load;
219
220 if (!show_phdr) return NULL;
221
222 memcpy(ret, "--- --- ---\0", 12);
223
224 shown = 0;
225 multi_stack = multi_relro = multi_load = 0;
226 max_pt_load = elf_max_pt_load(elf);
227
228#define NOTE_GNU_STACK ".note.GNU-stack"
229#define SHOW_PHDR(B) \
230 if (elf->elf_class == ELFCLASS ## B) { \
231 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
232 Elf ## B ## _Off offset; \
233 uint32_t flags, check_flags; \
234 if (elf->phdr != NULL) { \
235 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
236 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
237 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
238 if (multi_stack++) \
239 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
240 if (file_matches_list(elf->filename, qa_execstack)) \
241 continue; \
242 found = found_phdr; \
243 offset = 0; \
244 check_flags = PF_X; \
245 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
246 if (multi_relro++) \
247 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
248 found = found_relro; \
249 offset = 4; \
250 check_flags = PF_X; \
251 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
252 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
253 if (multi_load++ > max_pt_load) \
254 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
255 if (file_matches_list(elf->filename, qa_wx_load)) \
256 continue; \
257 found = found_load; \
258 offset = 8; \
259 check_flags = PF_W|PF_X; \
260 } else \
261 continue; \
262 flags = EGET(phdr[i].p_flags); \
263 if (be_quiet && ((flags & check_flags) != check_flags)) \
264 continue; \
265 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
266 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
267 ret[3] = ret[7] = '!'; \
268 flags = EGET(phdr[i].p_flags); \
269 } \
270 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
271 *found = 1; \
272 ++shown; \
273 } \
274 } else if (elf->shdr != NULL) { \
275 /* no program headers which means this is prob an object file */ \
276 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
277 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
278 char *str; \
279 if ((void*)strtbl > elf->data_end) \
280 goto skip_this_shdr##B; \
281 check_flags = SHF_WRITE|SHF_EXECINSTR; \
282 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
283 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
284 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
285 str = elf->data + offset; \
286 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
287 if (!strcmp(str, NOTE_GNU_STACK)) { \
288 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
289 flags = EGET(shdr[i].sh_flags); \
290 if (be_quiet && ((flags & check_flags) != check_flags)) \
291 continue; \
292 ++*found_phdr; \
293 shown = 1; \
294 if (flags & SHF_WRITE) ret[0] = 'W'; \
295 if (flags & SHF_ALLOC) ret[1] = 'A'; \
296 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
297 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
298 break; \
299 } \
300 } \
301 skip_this_shdr##B: \
302 if (!multi_stack) { \
303 if (file_matches_list(elf->filename, qa_execstack)) \
304 return NULL; \
305 *found_phdr = 1; \
306 shown = 1; \
307 memcpy(ret, "!WX", 3); \
308 } \
309 } \
310 }
311 SHOW_PHDR(32)
312 SHOW_PHDR(64)
313
314 if (be_wewy_wewy_quiet || (be_quiet && !shown))
315 return NULL;
316 else
317 return ret;
318}
319
320/*
321 * See if this ELF contains a DT_TEXTREL tag in any of its
322 * PT_DYNAMIC sections.
323 */
324static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
325{
326 static const char *ret = "TEXTREL";
327 unsigned long i;
328
329 if (!show_textrel && !show_textrels) return NULL;
330
331 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
332
333 if (elf->phdr) {
334#define SHOW_TEXTREL(B) \
335 if (elf->elf_class == ELFCLASS ## B) { \
336 Elf ## B ## _Dyn *dyn; \
337 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
338 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
339 Elf ## B ## _Off offset; \
340 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
341 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
342 offset = EGET(phdr[i].p_offset); \
343 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
344 dyn = DYN ## B (elf->vdata + offset); \
345 while (EGET(dyn->d_tag) != DT_NULL) { \
346 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
347 *found_textrel = 1; \
348 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
349 return (be_wewy_wewy_quiet ? NULL : ret); \
350 } \
351 ++dyn; \
352 } \
353 } }
354 SHOW_TEXTREL(32)
355 SHOW_TEXTREL(64)
356 }
357
358 if (be_quiet || be_wewy_wewy_quiet)
359 return NULL;
360 else
361 return " - ";
362}
363
364/*
365 * Scan the .text section to see if there are any relocations in it.
366 * Should rewrite this to check PT_LOAD sections that are marked
367 * Executable rather than the section named '.text'.
368 */
369static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
370{
371 unsigned long s, r, rmax;
372 void *symtab_void, *strtab_void, *text_void;
373
374 if (!show_textrels) return NULL;
375
376 /* don't search for TEXTREL's if the ELF doesn't have any */
377 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
378 if (!*found_textrel) return NULL;
379
380 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
381 text_void = elf_findsecbyname(elf, ".text");
382
383 if (symtab_void && strtab_void && text_void && elf->shdr) {
384#define SHOW_TEXTRELS(B) \
385 if (elf->elf_class == ELFCLASS ## B) { \
386 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
387 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
388 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
389 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
390 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
391 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
392 uint ## B ## _t memsz = EGET(text->sh_size); \
393 Elf ## B ## _Rel *rel; \
394 Elf ## B ## _Rela *rela; \
395 /* search the section headers for relocations */ \
396 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
397 uint32_t sh_type = EGET(shdr[s].sh_type); \
398 if (sh_type == SHT_REL) { \
399 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
400 rela = NULL; \
401 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
402 } else if (sh_type == SHT_RELA) { \
403 rel = NULL; \
404 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
405 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
406 } else \
407 continue; \
408 /* now see if any of the relocs are in the .text */ \
409 for (r = 0; r < rmax; ++r) { \
410 unsigned long sym_max; \
411 Elf ## B ## _Addr offset_tmp; \
412 Elf ## B ## _Sym *func; \
413 Elf ## B ## _Sym *sym; \
414 Elf ## B ## _Addr r_offset; \
415 uint ## B ## _t r_info; \
416 if (sh_type == SHT_REL) { \
417 r_offset = EGET(rel[r].r_offset); \
418 r_info = EGET(rel[r].r_info); \
419 } else { \
420 r_offset = EGET(rela[r].r_offset); \
421 r_info = EGET(rela[r].r_info); \
422 } \
423 /* make sure this relocation is inside of the .text */ \
424 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
425 if (be_verbose <= 2) continue; \
426 } else \
427 *found_textrels = 1; \
428 /* locate this relocation symbol name */ \
429 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
430 if ((void*)sym > elf->data_end) { \
431 warn("%s: corrupt ELF symbol", elf->filename); \
432 continue; \
433 } \
434 sym_max = ELF ## B ## _R_SYM(r_info); \
435 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
436 sym += sym_max; \
437 else \
438 sym = NULL; \
439 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
440 /* show the raw details about this reloc */ \
441 printf(" %s: ", elf->base_filename); \
442 if (sym && sym->st_name) \
443 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
444 else \
445 printf("(memory/data?)"); \
446 printf(" [0x%lX]", (unsigned long)r_offset); \
447 /* now try to find the closest symbol that this rel is probably in */ \
448 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
449 func = NULL; \
450 offset_tmp = 0; \
451 while (sym_max--) { \
452 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
453 func = sym; \
454 offset_tmp = EGET(sym->st_value); \
455 } \
456 ++sym; \
457 } \
458 printf(" in "); \
459 if (func && func->st_name) { \
460 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
461 if (r_offset > EGET(func->st_size)) \
462 printf("(optimized out: previous %s)", func_name); \
463 else \
464 printf("%s", func_name); \
465 } else \
466 printf("(optimized out)"); \
467 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
468 if (be_verbose && has_objdump) { \
469 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
470 char *sysbuf; \
471 size_t syslen; \
472 int sysret; \
473 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
474 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
475 sysbuf = xmalloc(syslen); \
476 if (end_addr < r_offset) \
477 /* not uncommon when things are optimized out */ \
478 end_addr = r_offset + 0x100; \
479 snprintf(sysbuf, syslen, sysfmt, \
480 (unsigned long)offset_tmp, \
481 (unsigned long)end_addr, \
482 elf->filename, \
483 (unsigned long)r_offset); \
484 fflush(stdout); \
485 sysret = system(sysbuf); \
486 fflush(stdout); \
487 free(sysbuf); \
488 } \
489 } \
490 } }
491 SHOW_TEXTRELS(32)
492 SHOW_TEXTRELS(64)
493 }
494 if (!*found_textrels)
495 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
496
497 return NULL;
498}
499
500static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
501{
502 struct stat st;
503 switch (*item) {
504 case '/': break;
505 case '.':
506 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
507 break;
508 case ':':
509 case '\0':
510 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
511 break;
512 case '$':
513 if (fstat(elf->fd, &st) != -1)
514 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
515 warnf("Security problem with %s='%s' in %s with mode set of %o",
516 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
517 break;
518 default:
519 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
520 break;
521 }
522}
523static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
524{
525 unsigned long i;
526 char *rpath, *runpath, **r;
527 void *strtbl_void;
528
529 if (!show_rpath) return;
530
531 strtbl_void = elf_findsecbyname(elf, ".dynstr");
532 rpath = runpath = NULL;
533
534 if (elf->phdr && strtbl_void) {
535#define SHOW_RPATH(B) \
536 if (elf->elf_class == ELFCLASS ## B) { \
537 Elf ## B ## _Dyn *dyn; \
538 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
539 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
540 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
541 Elf ## B ## _Off offset; \
542 Elf ## B ## _Xword word; \
543 /* Scan all the program headers */ \
544 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
545 /* Just scan dynamic headers */ \
546 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
547 offset = EGET(phdr[i].p_offset); \
548 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
549 /* Just scan dynamic RPATH/RUNPATH headers */ \
550 dyn = DYN ## B (elf->vdata + offset); \
551 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
552 if (word == DT_RPATH) { \
553 r = &rpath; \
554 } else if (word == DT_RUNPATH) { \
555 r = &runpath; \
556 } else { \
557 ++dyn; \
558 continue; \
559 } \
560 /* Verify the memory is somewhat sane */ \
561 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
562 if (offset < (Elf ## B ## _Off)elf->len) { \
563 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
564 *r = elf->data + offset; \
565 /* cache the length in case we need to nuke this section later on */ \
566 if (fix_elf) \
567 offset = strlen(*r); \
568 /* If quiet, don't output paths in ld.so.conf */ \
569 if (be_quiet) { \
570 size_t len; \
571 char *start, *end; \
572 /* note that we only 'chop' off leading known paths. */ \
573 /* since *r is read-only memory, we can only move the ptr forward. */ \
574 start = *r; \
575 /* scan each path in : delimited list */ \
576 while (start) { \
577 rpath_security_checks(elf, start, get_elfdtype(word)); \
578 end = strchr(start, ':'); \
579 len = (end ? abs(end - start) : strlen(start)); \
580 if (use_ldcache) { \
581 size_t n; \
582 const char *ldpath; \
583 array_for_each(ldpaths, n, ldpath) \
584 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
585 *r = end; \
586 /* corner case ... if RPATH reads "/usr/lib:", we want \
587 * to show ':' rather than '' */ \
588 if (end && end[1] != '\0') \
589 (*r)++; \
590 break; \
591 } \
592 } \
593 if (!*r || !end) \
594 break; \
595 else \
596 start = start + len + 1; \
597 } \
598 } \
599 if (*r) { \
600 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
601 /* just nuke it */ \
602 nuke_it##B: \
603 memset(*r, 0x00, offset); \
604 *r = NULL; \
605 ESET(dyn->d_tag, DT_DEBUG); \
606 ESET(dyn->d_un.d_ptr, 0); \
607 } else if (fix_elf) { \
608 /* try to clean "bad" paths */ \
609 size_t len, tmpdir_len; \
610 char *start, *end; \
611 const char *tmpdir; \
612 start = *r; \
613 tmpdir = (getenv("TMPDIR") ? : "."); \
614 tmpdir_len = strlen(tmpdir); \
615 while (1) { \
616 end = strchr(start, ':'); \
617 if (start == end) { \
618 eat_this_path##B: \
619 len = strlen(end); \
620 memmove(start, end+1, len); \
621 start[len-1] = '\0'; \
622 end = start - 1; \
623 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
624 if (!end) { \
625 if (start == *r) \
626 goto nuke_it##B; \
627 *--start = '\0'; \
628 } else \
629 goto eat_this_path##B; \
630 } \
631 if (!end) \
632 break; \
633 start = end + 1; \
634 } \
635 if (**r == '\0') \
636 goto nuke_it##B; \
637 } \
638 if (*r) \
639 *found_rpath = 1; \
640 } \
641 } \
642 ++dyn; \
643 } \
644 } }
645 SHOW_RPATH(32)
646 SHOW_RPATH(64)
647 }
648
649 if (be_wewy_wewy_quiet) return;
650
651 if (rpath && runpath) {
652 if (!strcmp(rpath, runpath)) {
653 xstrcat(ret, runpath, ret_len);
654 } else {
655 fprintf(stderr, "RPATH [%s] != RUNPATH [%s]\n", rpath, runpath);
656 xchrcat(ret, '{', ret_len);
657 xstrcat(ret, rpath, ret_len);
658 xchrcat(ret, ',', ret_len);
659 xstrcat(ret, runpath, ret_len);
660 xchrcat(ret, '}', ret_len);
661 }
662 } else if (rpath || runpath)
663 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
664 else if (!be_quiet)
665 xstrcat(ret, " - ", ret_len);
666}
667
668#define LDSO_CACHE_MAGIC "ld.so-"
669#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
670#define LDSO_CACHE_VER "1.7.0"
671#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
672#define FLAG_ANY -1
673#define FLAG_TYPE_MASK 0x00ff
674#define FLAG_LIBC4 0x0000
675#define FLAG_ELF 0x0001
676#define FLAG_ELF_LIBC5 0x0002
677#define FLAG_ELF_LIBC6 0x0003
678#define FLAG_REQUIRED_MASK 0xff00
679#define FLAG_SPARC_LIB64 0x0100
680#define FLAG_IA64_LIB64 0x0200
681#define FLAG_X8664_LIB64 0x0300
682#define FLAG_S390_LIB64 0x0400
683#define FLAG_POWERPC_LIB64 0x0500
684#define FLAG_MIPS64_LIBN32 0x0600
685#define FLAG_MIPS64_LIBN64 0x0700
686
687#if defined(__GLIBC__) || defined(__UCLIBC__)
688
689static char *lookup_cache_lib(elfobj *elf, char *fname)
690{
691 int fd;
692 char *strs;
693 static char buf[__PAX_UTILS_PATH_MAX] = "";
694 const char cachefile[] = "/etc/ld.so.cache";
695 struct stat st;
696
697 typedef struct {
698 char magic[LDSO_CACHE_MAGIC_LEN];
699 char version[LDSO_CACHE_VER_LEN];
700 int nlibs;
701 } header_t;
702 header_t *header;
703
704 typedef struct {
705 int flags;
706 int sooffset;
707 int liboffset;
708 } libentry_t;
709 libentry_t *libent;
710
711 if (fname == NULL)
712 return NULL;
713
714 if (ldcache == NULL) {
715 if (stat(cachefile, &st))
716 return NULL;
717
718 fd = open(cachefile, O_RDONLY);
719 if (fd == -1)
720 return NULL;
721
722 /* cache these values so we only map/unmap the cache file once */
723 ldcache_size = st.st_size;
724 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
725 close(fd);
726
727 if (ldcache == MAP_FAILED) {
728 ldcache = NULL;
729 return NULL;
730 }
731
732 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
733 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
734 {
735 munmap(ldcache, ldcache_size);
736 ldcache = NULL;
737 return NULL;
738 }
739 } else
740 header = ldcache;
741
742 libent = ldcache + sizeof(header_t);
743 strs = (char *) &libent[header->nlibs];
744
745 for (fd = 0; fd < header->nlibs; ++fd) {
746 /* This should be more fine grained, but for now we assume that
747 * diff arches will not be cached together, and we ignore the
748 * the different multilib mips cases.
749 */
750 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
751 continue;
752 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
753 continue;
754
755 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
756 continue;
757
758 /* Return first hit because that is how the ldso rolls */
759 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
760 break;
761 }
762
763 return buf;
764}
765
766#elif defined(__NetBSD__)
767static char *lookup_cache_lib(elfobj *elf, char *fname)
768{
769 static char buf[__PAX_UTILS_PATH_MAX] = "";
770 static struct stat st;
771 size_t n;
772 char *ldpath;
773
774 array_for_each(ldpath, n, ldpath) {
775 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
776 continue; /* if the pathname is too long, or something went wrong, ignore */
777
778 if (stat(buf, &st) != 0)
779 continue; /* if the lib doesn't exist in *ldpath, look further */
780
781 /* NetBSD doesn't actually do sanity checks, it just loads the file
782 * and if that doesn't work, continues looking in other directories.
783 * This cannot easily be safely emulated, unfortunately. For now,
784 * just assume that if it exists, it's a valid library. */
785
786 return buf;
787 }
788
789 /* not found in any path */
790 return NULL;
791}
792#else
793#ifdef __ELF__
794#warning Cache support not implemented for your target
795#endif
796static char *lookup_cache_lib(elfobj *elf, char *fname)
797{
798 return NULL;
799}
800#endif
801
802static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
803{
804 unsigned long i;
805 char *needed;
806 void *strtbl_void;
807 char *p;
808
809 /*
810 * -n -> op==0 -> print all
811 * -N -> op==1 -> print requested
812 */
813 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
814 return NULL;
815
816 strtbl_void = elf_findsecbyname(elf, ".dynstr");
817
818 if (elf->phdr && strtbl_void) {
819#define SHOW_NEEDED(B) \
820 if (elf->elf_class == ELFCLASS ## B) { \
821 Elf ## B ## _Dyn *dyn; \
822 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
823 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
824 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
825 Elf ## B ## _Off offset; \
826 size_t matched = 0; \
827 /* Walk all the program headers to find the PT_DYNAMIC */ \
828 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
829 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
830 continue; \
831 offset = EGET(phdr[i].p_offset); \
832 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
833 continue; \
834 /* Walk all the dynamic tags to find NEEDED entries */ \
835 dyn = DYN ## B (elf->vdata + offset); \
836 while (EGET(dyn->d_tag) != DT_NULL) { \
837 if (EGET(dyn->d_tag) == DT_NEEDED) { \
838 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
839 if (offset >= (Elf ## B ## _Off)elf->len) { \
840 ++dyn; \
841 continue; \
842 } \
843 needed = elf->data + offset; \
844 if (op == 0) { \
845 /* -n -> print all entries */ \
846 if (!be_wewy_wewy_quiet) { \
847 if (*found_needed) xchrcat(ret, ',', ret_len); \
848 if (use_ldcache) \
849 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
850 needed = p; \
851 xstrcat(ret, needed, ret_len); \
852 } \
853 *found_needed = 1; \
854 } else { \
855 /* -N -> print matching entries */ \
856 size_t n; \
857 const char *find_lib_name; \
858 \
859 array_for_each(find_lib_arr, n, find_lib_name) \
860 if (!strcmp(find_lib_name, needed)) \
861 ++matched; \
862 \
863 if (matched == array_cnt(find_lib_arr)) { \
864 *found_lib = 1; \
865 return (be_wewy_wewy_quiet ? NULL : find_lib); \
866 } \
867 } \
868 } \
869 ++dyn; \
870 } \
871 } }
872 SHOW_NEEDED(32)
873 SHOW_NEEDED(64)
874 if (op == 0 && !*found_needed && be_verbose)
875 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
876 }
877
878 return NULL;
879}
880static char *scanelf_file_interp(elfobj *elf, char *found_interp)
881{
882 void *strtbl_void;
883
884 if (!show_interp) return NULL;
885
886 strtbl_void = elf_findsecbyname(elf, ".interp");
887
888 if (strtbl_void) {
889#define SHOW_INTERP(B) \
890 if (elf->elf_class == ELFCLASS ## B) { \
891 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
892 *found_interp = 1; \
893 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
894 }
895 SHOW_INTERP(32)
896 SHOW_INTERP(64)
897 }
898 return NULL;
899}
900static char *scanelf_file_bind(elfobj *elf, char *found_bind)
901{
902 unsigned long i;
903 struct stat s;
904 char dynamic = 0;
905
906 if (!show_bind) return NULL;
907 if (!elf->phdr) return NULL;
908
909#define SHOW_BIND(B) \
910 if (elf->elf_class == ELFCLASS ## B) { \
911 Elf ## B ## _Dyn *dyn; \
912 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
913 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
914 Elf ## B ## _Off offset; \
915 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
916 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
917 dynamic = 1; \
918 offset = EGET(phdr[i].p_offset); \
919 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
920 dyn = DYN ## B (elf->vdata + offset); \
921 while (EGET(dyn->d_tag) != DT_NULL) { \
922 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
923 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
924 { \
925 if (be_quiet) return NULL; \
926 *found_bind = 1; \
927 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
928 } \
929 ++dyn; \
930 } \
931 } \
932 }
933 SHOW_BIND(32)
934 SHOW_BIND(64)
935
936 if (be_wewy_wewy_quiet) return NULL;
937
938 /* don't output anything if quiet mode and the ELF is static or not setuid */
939 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
940 return NULL;
941 } else {
942 *found_bind = 1;
943 return (char *)(dynamic ? "LAZY" : "STATIC");
944 }
945}
946static char *scanelf_file_soname(elfobj *elf, char *found_soname)
947{
948 unsigned long i;
949 char *soname;
950 void *strtbl_void;
951
952 if (!show_soname) return NULL;
953
954 strtbl_void = elf_findsecbyname(elf, ".dynstr");
955
956 if (elf->phdr && strtbl_void) {
957#define SHOW_SONAME(B) \
958 if (elf->elf_class == ELFCLASS ## B) { \
959 Elf ## B ## _Dyn *dyn; \
960 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
961 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
962 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
963 Elf ## B ## _Off offset; \
964 /* only look for soname in shared objects */ \
965 if (EGET(ehdr->e_type) != ET_DYN) \
966 return NULL; \
967 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
968 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
969 offset = EGET(phdr[i].p_offset); \
970 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
971 dyn = DYN ## B (elf->vdata + offset); \
972 while (EGET(dyn->d_tag) != DT_NULL) { \
973 if (EGET(dyn->d_tag) == DT_SONAME) { \
974 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
975 if (offset >= (Elf ## B ## _Off)elf->len) { \
976 ++dyn; \
977 continue; \
978 } \
979 soname = elf->data + offset; \
980 *found_soname = 1; \
981 return (be_wewy_wewy_quiet ? NULL : soname); \
982 } \
983 ++dyn; \
984 } \
985 } }
986 SHOW_SONAME(32)
987 SHOW_SONAME(64)
988 }
989
990 return NULL;
991}
992
993/*
994 * We support the symbol form:
995 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
996 * If the symbol name is empty, then all symbols are matched.
997 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
998 * Do not rely on this output format at all.
999 * Otherwise the symbol name is used to search (either regex or string compare).
1000 * If the first char of the symbol name is a plus ("+"), then only match
1001 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1002 * Putting modifiers in between the percent signs allows for more in depth
1003 * filters. There are groups of modifiers. If you don't specify a member
1004 * of a group, then all types in that group are matched. The current
1005 * groups and their types are:
1006 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f SST_FILE:F
1007 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1008 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1009 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1010 * You can search for multiple symbols at once by seperating with a comma (",").
1011 *
1012 * Some examples:
1013 * ELFs with a weak function "foo":
1014 * scanelf -s %wf%foo <ELFs>
1015 * ELFs that define the symbol "main":
1016 * scanelf -s +main <ELFs>
1017 * scanelf -s %d%main <ELFs>
1018 * ELFs that refer to the undefined symbol "brk":
1019 * scanelf -s -brk <ELFs>
1020 * scanelf -s %u%brk <ELFs>
1021 * All global defined objects in an ELF:
1022 * scanelf -s %ogd% <ELF>
1023 */
1024static void
1025scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1026 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1027{
1028 char *this_sym, *next_sym, saved = saved;
1029
1030 /* allow the user to specify a comma delimited list of symbols to search for */
1031 next_sym = NULL;
1032 do {
1033 bool inc_notype, inc_object, inc_func, inc_file,
1034 inc_local, inc_global, inc_weak,
1035 inc_def, inc_undef, inc_abs, inc_common;
1036
1037 if (next_sym) {
1038 next_sym[-1] = saved;
1039 this_sym = next_sym;
1040 } else
1041 this_sym = find_sym;
1042 if ((next_sym = strchr(this_sym, ','))) {
1043 /* make parsing easier by killing the comma temporarily */
1044 saved = *next_sym;
1045 *next_sym = '\0';
1046 next_sym += 1;
1047 }
1048
1049 /* symbol selection! */
1050 inc_notype = inc_object = inc_func = inc_file = \
1051 inc_local = inc_global = inc_weak = \
1052 inc_def = inc_undef = inc_abs = inc_common = \
1053 (*this_sym != '%');
1054
1055 /* parse the contents of %...% */
1056 if (!inc_notype) {
1057 while (*(this_sym++)) {
1058 if (*this_sym == '%') {
1059 ++this_sym;
1060 break;
1061 }
1062 switch (*this_sym) {
1063 case 'n': inc_notype = true; break;
1064 case 'o': inc_object = true; break;
1065 case 'f': inc_func = true; break;
1066 case 'F': inc_file = true; break;
1067 case 'l': inc_local = true; break;
1068 case 'g': inc_global = true; break;
1069 case 'w': inc_weak = true; break;
1070 case 'd': inc_def = true; break;
1071 case 'u': inc_undef = true; break;
1072 case 'a': inc_abs = true; break;
1073 case 'c': inc_common = true; break;
1074 default: err("invalid symbol selector '%c'", *this_sym);
1075 }
1076 }
1077
1078 /* If no types are matched, not match all */
1079 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1080 inc_notype = inc_object = inc_func = inc_file = true;
1081 if (!inc_local && !inc_global && !inc_weak)
1082 inc_local = inc_global = inc_weak = true;
1083 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1084 inc_def = inc_undef = inc_abs = inc_common = true;
1085
1086 /* backwards compat for defined/undefined short hand */
1087 } else if (*this_sym == '+') {
1088 inc_undef = false;
1089 ++this_sym;
1090 } else if (*this_sym == '-') {
1091 inc_def = inc_abs = inc_common = false;
1092 ++this_sym;
1093 }
1094
1095 /* filter symbols */
1096 if ((!inc_notype && stt == STT_NOTYPE) || \
1097 (!inc_object && stt == STT_OBJECT) || \
1098 (!inc_func && stt == STT_FUNC ) || \
1099 (!inc_file && stt == STT_FILE ) || \
1100 (!inc_local && stb == STB_LOCAL ) || \
1101 (!inc_global && stb == STB_GLOBAL) || \
1102 (!inc_weak && stb == STB_WEAK ) || \
1103 (!inc_def && shn && shn < SHN_LORESERVE) || \
1104 (!inc_undef && shn == SHN_UNDEF ) || \
1105 (!inc_abs && shn == SHN_ABS ) || \
1106 (!inc_common && shn == SHN_COMMON))
1107 continue;
1108
1109 if (*this_sym == '*') {
1110 /* a "*" symbol gets you debug output */
1111 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1112 ((*found_sym == 0) ? "\n\t" : "\t"),
1113 elf->base_filename,
1114 size,
1115 get_elfstttype(stt),
1116 get_elfstbtype(stb),
1117 get_elfshntype(shn),
1118 symname);
1119 goto matched;
1120
1121 } else {
1122 if (g_match) {
1123 /* regex match the symbol */
1124 if (rematch(this_sym, symname, REG_EXTENDED) != 0)
1125 continue;
1126
1127 } else if (*this_sym) {
1128 /* give empty symbols a "pass", else do a normal compare */
1129 const size_t len = strlen(this_sym);
1130 if (!(strncmp(this_sym, symname, len) == 0 &&
1131 /* Accept unversioned symbol names */
1132 (symname[len] == '\0' || symname[len] == '@')))
1133 continue;
1134 }
1135
1136 if (be_semi_verbose) {
1137 char buf[1024];
1138 snprintf(buf, sizeof(buf), "%lX %s %s",
1139 size,
1140 get_elfstttype(stt),
1141 this_sym);
1142 *ret = xstrdup(buf);
1143 } else {
1144 if (*ret) xchrcat(ret, ',', ret_len);
1145 xstrcat(ret, symname, ret_len);
1146 }
1147
1148 goto matched;
1149 }
1150 } while (next_sym);
1151
1152 return;
1153
1154 matched:
1155 *found_sym = 1;
1156 if (next_sym)
1157 next_sym[-1] = saved;
1158}
1159
1160static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
1161{
1162 unsigned long i;
1163 char *ret;
1164 void *symtab_void, *strtab_void;
1165
1166 if (!find_sym) return NULL;
1167 ret = NULL;
1168
1169 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
1170
1171 if (symtab_void && strtab_void) {
1172#define FIND_SYM(B) \
1173 if (elf->elf_class == ELFCLASS ## B) { \
1174 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
1175 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
1176 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
1177 unsigned long cnt = EGET(symtab->sh_entsize); \
1178 char *symname; \
1179 size_t ret_len = 0; \
1180 if (cnt) \
1181 cnt = EGET(symtab->sh_size) / cnt; \
1182 for (i = 0; i < cnt; ++i) { \
1183 if ((void*)sym > elf->data_end) { \
1184 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1185 goto break_out; \
1186 } \
1187 if (sym->st_name) { \
1188 /* make sure the symbol name is in acceptable memory range */ \
1189 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
1190 if ((void*)symname > elf->data_end) { \
1191 warnf("%s: corrupt ELF symbols", elf->filename); \
1192 ++sym; \
1193 continue; \
1194 } \
1195 scanelf_match_symname(elf, found_sym, \
1196 &ret, &ret_len, symname, \
1197 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1198 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1199 EGET(sym->st_shndx), \
1200 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1201 EGET(sym->st_size)); \
1202 } \
1203 ++sym; \
1204 } }
1205 FIND_SYM(32)
1206 FIND_SYM(64)
1207 }
1208
1209break_out:
1210 if (be_wewy_wewy_quiet) return NULL;
1211
1212 if (*find_sym != '*' && *found_sym)
1213 return ret;
1214 if (be_quiet)
1215 return NULL;
1216 else
1217 return " - ";
1218}
1219
1220static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1221{
1222 if (!find_section)
1223 return NULL;
1224
1225#define FIND_SECTION(B) \
1226 if (elf->elf_class == ELFCLASS ## B) { \
1227 size_t matched, n; \
1228 int invert; \
1229 const char *section_name; \
1230 Elf ## B ## _Shdr *section; \
1231 \
1232 matched = 0; \
1233 array_for_each(find_section_arr, n, section_name) { \
1234 invert = (*section_name == '!' ? 1 : 0); \
1235 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1236 if ((section == NULL && invert) || (section != NULL && !invert)) \
1237 ++matched; \
1238 } \
1239 \
1240 if (matched == array_cnt(find_section_arr)) \
1241 *found_section = 1; \
1242 }
1243 FIND_SECTION(32)
1244 FIND_SECTION(64)
1245
1246 if (be_wewy_wewy_quiet)
1247 return NULL;
1248
1249 if (*found_section)
1250 return find_section;
1251
1252 if (be_quiet)
1253 return NULL;
1254 else
1255 return " - ";
1256}
75 1257
76/* scan an elf file and show all the fun stuff */ 1258/* scan an elf file and show all the fun stuff */
77static void scanelf_file(const char *filename) 1259#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
1260static int scanelf_elfobj(elfobj *elf)
78{ 1261{
79 int i; 1262 unsigned long i;
80 char found_pax, found_stack, found_relro, found_textrel, found_rpath; 1263 char found_pax, found_phdr, found_relro, found_load, found_textrel,
81 Elf_Dyn *dyn; 1264 found_rpath, found_needed, found_interp, found_bind, found_soname,
82 elfobj *elf = NULL; 1265 found_sym, found_lib, found_file, found_textrels, found_section;
1266 static char *out_buffer = NULL;
1267 static size_t out_len;
83 1268
84 found_pax = found_stack = found_relro = found_textrel = found_rpath = 0; 1269 found_pax = found_phdr = found_relro = found_load = found_textrel = \
1270 found_rpath = found_needed = found_interp = found_bind = found_soname = \
1271 found_sym = found_lib = found_file = found_textrels = found_section = 0;
85 1272
86 /* verify this is real ELF */ 1273 if (be_verbose > 2)
87 if ((elf = readelf(filename)) == NULL) { 1274 printf("%s: scanning file {%s,%s}\n", elf->filename,
88 if (be_verbose > 1) printf("%s: not an ELF\n", filename); 1275 get_elfeitype(EI_CLASS, elf->elf_class),
89 return; 1276 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
90 } 1277 else if (be_verbose > 1)
91
92 if (be_verbose) printf("%s: scanning file\n", filename); 1278 printf("%s: scanning file\n", elf->filename);
1279
1280 /* init output buffer */
1281 if (!out_buffer) {
1282 out_len = sizeof(char) * 80;
1283 out_buffer = xmalloc(out_len);
1284 }
1285 *out_buffer = '\0';
93 1286
94 /* show the header */ 1287 /* show the header */
95 if (!be_quiet && show_banner) { 1288 if (!be_quiet && show_banner) {
96 printf(" TYPE "); 1289 for (i = 0; out_format[i]; ++i) {
97 if (show_pax) printf(" PAX "); 1290 if (!IS_MODIFIER(out_format[i])) continue;
98 if (show_stack) printf(" STK/REL "); 1291
99 if (show_textrel) printf("TEXTREL "); 1292 switch (out_format[++i]) {
100 if (show_rpath) printf("RPATH "); 1293 case '+': break;
1294 case '%': break;
1295 case '#': break;
1296 case 'F':
1297 case 'p':
1298 case 'f': prints("FILE "); found_file = 1; break;
1299 case 'o': prints(" TYPE "); break;
1300 case 'x': prints(" PAX "); break;
1301 case 'e': prints("STK/REL/PTL "); break;
1302 case 't': prints("TEXTREL "); break;
1303 case 'r': prints("RPATH "); break;
1304 case 'M': prints("CLASS "); break;
1305 case 'n': prints("NEEDED "); break;
1306 case 'i': prints("INTERP "); break;
1307 case 'b': prints("BIND "); break;
1308 case 'Z': prints("SIZE "); break;
1309 case 'S': prints("SONAME "); break;
1310 case 's': prints("SYM "); break;
1311 case 'N': prints("LIB "); break;
1312 case 'T': prints("TEXTRELS "); break;
1313 case 'k': prints("SECTION "); break;
1314 case 'a': prints("ARCH "); break;
1315 case 'I': prints("OSABI "); break;
1316 case 'Y': prints("EABI "); break;
1317 case 'O': prints("PERM "); break;
1318 case 'D': prints("ENDIAN "); break;
1319 default: warnf("'%c' has no title ?", out_format[i]);
1320 }
1321 }
1322 if (!found_file) prints("FILE ");
101 printf(" FILE\n"); 1323 prints("\n");
1324 found_file = 0;
102 show_banner = 0; 1325 show_banner = 0;
103 } 1326 }
104 1327
105 /* dump all the good stuff */ 1328 /* dump all the good stuff */
106 if (!be_quiet) 1329 for (i = 0; out_format[i]; ++i) {
107 printf("%-7s ", get_elfetype(elf->ehdr->e_type)); 1330 const char *out;
108 1331 const char *tmp;
109 if (show_pax) { 1332 static char ubuf[sizeof(unsigned long)*2];
110 char *paxflags = pax_short_hf_flags(PAX_FLAGS(elf)); 1333 if (!IS_MODIFIER(out_format[i])) {
111 if (!be_quiet || (be_quiet && strncmp(paxflags, "PeMRxS", 6))) { 1334 xchrcat(&out_buffer, out_format[i], &out_len);
112 found_pax = 1;
113 printf("%s ", pax_short_hf_flags(PAX_FLAGS(elf)));
114 }
115 }
116
117 /* stack fun */
118 if (show_stack) {
119 for (i = 0; i < elf->ehdr->e_phnum; i++) {
120 if (elf->phdr[i].p_type != PT_GNU_STACK && \
121 elf->phdr[i].p_type != PT_GNU_RELRO) continue;
122
123 if (be_quiet && !(elf->phdr[i].p_flags & PF_X))
124 continue; 1335 continue;
125
126 if (elf->phdr[i].p_type == PT_GNU_STACK)
127 found_stack = 1;
128 if (elf->phdr[i].p_type == PT_GNU_RELRO)
129 found_relro = 1;
130
131 printf("%s ", gnu_short_stack_flags(elf->phdr[i].p_flags));
132 }
133 if (!be_quiet && !found_stack) printf("--- ");
134 if (!be_quiet && !found_relro) printf("--- ");
135 } 1336 }
136 1337
137 /* textrel fun */ 1338 out = NULL;
138 if (show_textrel) { 1339 be_wewy_wewy_quiet = (out_format[i] == '#');
139 for (i = 0; i < elf->ehdr->e_phnum; i++) { 1340 be_semi_verbose = (out_format[i] == '+');
140 if (elf->phdr[i].p_type != PT_DYNAMIC) continue; 1341 switch (out_format[++i]) {
141 1342 case '+':
142 dyn = (Elf_Dyn *)(elf->data + elf->phdr[i].p_offset); 1343 case '%':
143 while (dyn->d_tag != DT_NULL) { 1344 case '#':
144 if (dyn->d_tag == DT_TEXTREL) { //dyn->d_tag != DT_FLAGS) 1345 xchrcat(&out_buffer, out_format[i], &out_len); break;
145 found_textrel = 1; 1346 case 'F':
146// if (dyn->d_un.d_val & DF_TEXTREL) 1347 found_file = 1;
147 printf("TEXTREL "); 1348 if (be_wewy_wewy_quiet) break;
148 } 1349 xstrcat(&out_buffer, elf->filename, &out_len);
149 ++dyn; 1350 break;
1351 case 'p':
1352 found_file = 1;
1353 if (be_wewy_wewy_quiet) break;
1354 tmp = elf->filename;
1355 if (search_path) {
1356 ssize_t len_search = strlen(search_path);
1357 ssize_t len_file = strlen(elf->filename);
1358 if (!strncmp(elf->filename, search_path, len_search) && \
1359 len_file > len_search)
1360 tmp += len_search;
1361 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
150 } 1362 }
151 } 1363 xstrcat(&out_buffer, tmp, &out_len);
152 if (!be_quiet && !found_textrel) printf("------- "); 1364 break;
1365 case 'f':
1366 found_file = 1;
1367 if (be_wewy_wewy_quiet) break;
1368 tmp = strrchr(elf->filename, '/');
1369 tmp = (tmp == NULL ? elf->filename : tmp+1);
1370 xstrcat(&out_buffer, tmp, &out_len);
1371 break;
1372 case 'o': out = get_elfetype(elf); break;
1373 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1374 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1375 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1376 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1377 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1378 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1379 case 'D': out = get_endian(elf); break;
1380 case 'O': out = strfileperms(elf->filename); break;
1381 case 'n':
1382 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1383 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1384 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1385 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1386 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1387 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1388 case 'a': out = get_elfemtype(elf); break;
1389 case 'I': out = get_elfosabi(elf); break;
1390 case 'Y': out = get_elf_eabi(elf); break;
1391 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
1392 default: warnf("'%c' has no scan code?", out_format[i]);
153 } 1393 }
1394 if (out)
1395 xstrcat(&out_buffer, out, &out_len);
1396 }
154 1397
155 /* rpath fun */ 1398#define FOUND_SOMETHING() \
156 /* TODO: if be_quiet, only output RPATH's which aren't in /etc/ld.so.conf */ 1399 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
157 if (show_rpath) { 1400 found_rpath || found_needed || found_interp || found_bind || \
158 char *rpath, *runpath; 1401 found_soname || found_sym || found_lib || found_textrels || found_section )
159 Elf_Shdr *strtbl = elf_findsecbyname(elf, ".dynstr");
160 rpath = runpath = NULL;
161 1402
162 if (strtbl) 1403 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
163 for (i = 0; i < elf->ehdr->e_phnum; i++) { 1404 xchrcat(&out_buffer, ' ', &out_len);
164 if (elf->phdr[i].p_type != PT_DYNAMIC) continue; 1405 xstrcat(&out_buffer, elf->filename, &out_len);
1406 }
1407 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
1408 puts(out_buffer);
1409 fflush(stdout);
1410 }
165 1411
166 dyn = (Elf_Dyn *)(elf->data + elf->phdr[i].p_offset); 1412 return 0;
167 while (dyn->d_tag != DT_NULL) { 1413}
168 if (dyn->d_tag == DT_RPATH) { //|| dyn->d_tag != DT_RUNPATH) 1414
169 rpath = elf->data + strtbl->sh_offset + dyn->d_un.d_ptr; 1415/* scan a single elf */
170 found_rpath = 1; 1416static int scanelf_elf(const char *filename, int fd, size_t len)
171 } else if (dyn->d_tag == DT_RUNPATH) { 1417{
172 runpath = elf->data + strtbl->sh_offset + dyn->d_un.d_ptr; 1418 int ret = 1;
173 found_rpath = 1; 1419 elfobj *elf;
174 } 1420
175 ++dyn; 1421 /* verify this is real ELF */
1422 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1423 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1424 return ret;
1425 }
1426 switch (match_bits) {
1427 case 32:
1428 if (elf->elf_class != ELFCLASS32)
1429 goto label_done;
1430 break;
1431 case 64:
1432 if (elf->elf_class != ELFCLASS64)
1433 goto label_done;
1434 break;
1435 default: break;
1436 }
1437 if (match_etypes) {
1438 char sbuf[126];
1439 strncpy(sbuf, match_etypes, sizeof(sbuf));
1440 if (strchr(match_etypes, ',') != NULL) {
1441 char *p;
1442 while ((p = strrchr(sbuf, ',')) != NULL) {
1443 *p = 0;
1444 if (etype_lookup(p+1) == get_etype(elf))
1445 goto label_ret;
176 } 1446 }
177 } 1447 }
178 if (rpath && runpath) { 1448 if (etype_lookup(sbuf) != get_etype(elf))
179 if (!strcmp(rpath, runpath)) 1449 goto label_done;
180 printf("%-5s ", runpath);
181 else {
182 fprintf(stderr, "%s's RPATH [%s] != RUNPATH [%s]\n", filename, rpath, runpath);
183 printf("{%s,%s} ", rpath, runpath);
184 }
185 } else if (rpath || runpath)
186 printf("%-5s ", (runpath ? runpath : rpath));
187 else if (!be_quiet && !found_rpath)
188 printf(" - ");
189 } 1450 }
190 1451
191 if (!be_quiet || found_pax || found_stack || found_textrel || found_rpath) 1452label_ret:
192 puts(filename); 1453 ret = scanelf_elfobj(elf);
193 1454
1455label_done:
194 unreadelf(elf); 1456 unreadelf(elf);
1457 return ret;
1458}
1459
1460/* scan an archive of elfs */
1461static int scanelf_archive(const char *filename, int fd, size_t len)
1462{
1463 archive_handle *ar;
1464 archive_member *m;
1465 char *ar_buffer;
1466 elfobj *elf;
1467
1468 ar = ar_open_fd(filename, fd);
1469 if (ar == NULL)
1470 return 1;
1471
1472 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1473 while ((m = ar_next(ar)) != NULL) {
1474 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1475 if (cur_pos == -1)
1476 errp("lseek() failed");
1477 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1478 if (elf) {
1479 scanelf_elfobj(elf);
1480 unreadelf(elf);
1481 }
1482 }
1483 munmap(ar_buffer, len);
1484
1485 return 0;
1486}
1487/* scan a file which may be an elf or an archive or some other magical beast */
1488static int scanelf_file(const char *filename, const struct stat *st_cache)
1489{
1490 const struct stat *st = st_cache;
1491 struct stat symlink_st;
1492 int fd;
1493
1494 /* always handle regular files and handle symlinked files if no -y */
1495 if (S_ISLNK(st->st_mode)) {
1496 if (!scan_symlink) return 1;
1497 stat(filename, &symlink_st);
1498 st = &symlink_st;
1499 }
1500
1501 if (!S_ISREG(st->st_mode)) {
1502 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1503 return 1;
1504 }
1505
1506 if (match_perms) {
1507 if ((st->st_mode | match_perms) != st->st_mode)
1508 return 1;
1509 }
1510 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1)
1511 return 1;
1512
1513 if (scanelf_elf(filename, fd, st->st_size) == 1 && scan_archives)
1514 /* if it isn't an ELF, maybe it's an .a archive */
1515 scanelf_archive(filename, fd, st->st_size);
1516
1517 close(fd);
1518 return 0;
1519}
1520
1521static const char *maybe_add_root(const char *fname, char *buf)
1522{
1523 if (root && strncmp(fname, root, strlen(root))) {
1524 strcpy(buf, root);
1525 strncat(buf, fname, __PAX_UTILS_PATH_MAX - strlen(root) - 1);
1526 fname = buf;
1527 }
1528 return fname;
195} 1529}
196 1530
197/* scan a directory for ET_EXEC files and print when we find one */ 1531/* scan a directory for ET_EXEC files and print when we find one */
198static void scanelf_dir(const char *path) 1532static int scanelf_dir(const char *path)
199{ 1533{
200 register DIR *dir; 1534 register DIR *dir;
201 register struct dirent *dentry; 1535 register struct dirent *dentry;
202 struct stat st_top, st; 1536 struct stat st_top, st;
203 char buf[_POSIX_PATH_MAX]; 1537 char buf[__PAX_UTILS_PATH_MAX];
204 size_t len = 0; 1538 char _path[__PAX_UTILS_PATH_MAX];
1539 size_t pathlen = 0, len = 0;
1540 int ret = 0;
1541
1542 path = maybe_add_root(path, _path);
205 1543
206 /* make sure path exists */ 1544 /* make sure path exists */
207 if (lstat(path, &st_top) == -1) 1545 if (lstat(path, &st_top) == -1) {
1546 if (be_verbose > 2) printf("%s: does not exist\n", path);
208 return; 1547 return 1;
1548 }
209 1549
210 /* ok, if it isn't a directory, assume we can open it */ 1550 /* ok, if it isn't a directory, assume we can open it */
211 if (!S_ISDIR(st_top.st_mode)) { 1551 if (!S_ISDIR(st_top.st_mode)) {
212 scanelf_file(path); 1552 return scanelf_file(path, &st_top);
213 return;
214 } 1553 }
215 1554
216 /* now scan the dir looking for fun stuff */ 1555 /* now scan the dir looking for fun stuff */
217 if ((dir = opendir(path)) == NULL) { 1556 if ((dir = opendir(path)) == NULL) {
218 warnf("could not opendir %s: %s", path, strerror(errno)); 1557 warnf("could not opendir %s: %s", path, strerror(errno));
219 return; 1558 return 1;
220 } 1559 }
221 if (be_verbose) printf("%s: scanning dir\n", path); 1560 if (be_verbose > 1) printf("%s: scanning dir\n", path);
222 1561
1562 pathlen = strlen(path);
223 while ((dentry = readdir(dir))) { 1563 while ((dentry = readdir(dir))) {
224 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1564 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
225 continue; 1565 continue;
226 len = (strlen(path) + 2 + strlen(dentry->d_name)); 1566 len = (pathlen + 1 + strlen(dentry->d_name) + 1);
227 assert(len < sizeof(buf)); 1567 if (len >= sizeof(buf)) {
228 strncpy(buf, path, len); 1568 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
229 strncat(buf, "/", len); 1569 (unsigned long)len, (unsigned long)sizeof(buf));
230 strncat(buf, dentry->d_name, len); 1570 continue;
231 buf[sizeof(buf)] = 0; 1571 }
1572 snprintf(buf, sizeof(buf), "%s%s%s", path, (path[pathlen-1] == '/') ? "" : "/", dentry->d_name);
232 if (lstat(buf, &st) != -1) { 1573 if (lstat(buf, &st) != -1) {
233 if (S_ISREG(st.st_mode)) 1574 if (S_ISREG(st.st_mode))
234 scanelf_file(buf); 1575 ret = scanelf_file(buf, &st);
235 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1576 else if (dir_recurse && S_ISDIR(st.st_mode)) {
236 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1577 if (dir_crossmount || (st_top.st_dev == st.st_dev))
237 scanelf_dir(buf); 1578 ret = scanelf_dir(buf);
238 } 1579 }
239 } 1580 }
240 } 1581 }
241 closedir(dir); 1582 closedir(dir);
1583 return ret;
242} 1584}
1585
1586static int scanelf_from_file(const char *filename)
1587{
1588 FILE *fp = NULL;
1589 char *p;
1590 char path[__PAX_UTILS_PATH_MAX];
1591 int ret = 0;
1592
1593 if (strcmp(filename, "-") == 0)
1594 fp = stdin;
1595 else if ((fp = fopen(filename, "r")) == NULL)
1596 return 1;
1597
1598 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1599 if ((p = strchr(path, '\n')) != NULL)
1600 *p = 0;
1601 search_path = path;
1602 ret = scanelf_dir(path);
1603 }
1604 if (fp != stdin)
1605 fclose(fp);
1606 return ret;
1607}
1608
1609#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1610
1611static int load_ld_cache_config(int i, const char *fname)
1612{
1613 FILE *fp = NULL;
1614 char *p;
1615 char path[__PAX_UTILS_PATH_MAX];
1616 char _fname[__PAX_UTILS_PATH_MAX];
1617
1618 fname = maybe_add_root(fname, _fname);
1619
1620 if ((fp = fopen(fname, "r")) == NULL)
1621 return i;
1622
1623 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
1624 if ((p = strrchr(path, '\r')) != NULL)
1625 *p = 0;
1626 if ((p = strchr(path, '\n')) != NULL)
1627 *p = 0;
1628
1629 /* recursive includes of the same file will make this segfault. */
1630 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1631 glob_t gl;
1632 size_t x;
1633 char gpath[__PAX_UTILS_PATH_MAX];
1634
1635 memset(gpath, 0, sizeof(gpath));
1636 if (root)
1637 strcpy(gpath, root);
1638
1639 if (path[8] != '/')
1640 snprintf(gpath+strlen(gpath), sizeof(gpath)-strlen(gpath), "/etc/%s", &path[8]);
1641 else
1642 strncpy(gpath+strlen(gpath), &path[8], sizeof(gpath)-strlen(gpath));
1643
1644 if (glob(gpath, 0, NULL, &gl) == 0) {
1645 for (x = 0; x < gl.gl_pathc; ++x) {
1646 /* try to avoid direct loops */
1647 if (strcmp(gl.gl_pathv[x], fname) == 0)
1648 continue;
1649 i = load_ld_cache_config(i, gl.gl_pathv[x]);
1650 }
1651 globfree(&gl);
1652 continue;
1653 }
1654 }
1655
1656 if (*path != '/')
1657 continue;
1658
1659 xarraypush(ldpaths, path, strlen(path));
1660 }
1661
1662 fclose(fp);
1663 return i;
1664}
1665
1666#elif defined(__FreeBSD__) || defined(__DragonFly__)
1667
1668static int load_ld_cache_config(int i, const char *fname)
1669{
1670 FILE *fp = NULL;
1671 char *b = NULL, *p;
1672 struct elfhints_hdr hdr;
1673 char _fname[__PAX_UTILS_PATH_MAX];
1674
1675 fname = maybe_add_root(fname, _fname);
1676
1677 if ((fp = fopen(fname, "r")) == NULL)
1678 return i;
1679
1680 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1681 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1682 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1683 {
1684 fclose(fp);
1685 return i;
1686 }
1687
1688 b = xmalloc(hdr.dirlistlen + 1);
1689 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1690 fclose(fp);
1691 free(b);
1692 return i;
1693 }
1694
1695 while ((p = strsep(&b, ":"))) {
1696 if (*p == '\0')
1697 continue;
1698 xarraypush(ldpaths, p, strlen(p));
1699 }
1700
1701 free(b);
1702 fclose(fp);
1703 return i;
1704}
1705
1706#else
1707#ifdef __ELF__
1708#warning Cache config support not implemented for your target
1709#endif
1710static int load_ld_cache_config(int i, const char *fname)
1711{
1712 return 0;
1713}
1714#endif
243 1715
244/* scan /etc/ld.so.conf for paths */ 1716/* scan /etc/ld.so.conf for paths */
245static void scanelf_ldpath() 1717static void scanelf_ldpath(void)
246{ 1718{
247 char scan_l, scan_ul, scan_ull; 1719 char scan_l, scan_ul, scan_ull;
248 char *path, *p; 1720 size_t n;
249 FILE *fp; 1721 const char *ldpath;
1722 int i = 0;
250 1723
251 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1724 if (array_cnt(ldpaths) == 0)
252 err("Unable to open ld.so.conf: %s", strerror(errno)); 1725 err("Unable to load any paths from ld.so.conf");
253 1726
254 scan_l = scan_ul = scan_ull = 0; 1727 scan_l = scan_ul = scan_ull = 0;
255 1728
256 path = malloc(_POSIX_PATH_MAX); 1729 array_for_each(ldpaths, n, ldpath) {
257 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL)
258 if (*path == '/') {
259 if ((p = strrchr(path, '\r')) != NULL)
260 *p = 0;
261 if ((p = strrchr(path, '\n')) != NULL)
262 *p = 0;
263 if (!scan_l && !strcmp(path, "/lib")) scan_l = 1; 1730 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = 1;
264 if (!scan_ul && !strcmp(path, "/usr/lib")) scan_ul = 1; 1731 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = 1;
265 if (!scan_ull && !strcmp(path, "/usr/local/lib")) scan_ull = 1; 1732 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = 1;
266 scanelf_dir(path); 1733 scanelf_dir(ldpath);
1734 ++i;
267 } 1735 }
268 free(path);
269 1736
270 if (!scan_l) scanelf_dir("/lib"); 1737 if (!scan_l) scanelf_dir("/lib");
271 if (!scan_ul) scanelf_dir("/usr/lib"); 1738 if (!scan_ul) scanelf_dir("/usr/lib");
272 if (!scan_ull) scanelf_dir("/usr/local/lib"); 1739 if (!scan_ull) scanelf_dir("/usr/local/lib");
273
274 fclose(fp);
275} 1740}
276 1741
277/* scan env PATH for paths */ 1742/* scan env PATH for paths */
278static void scanelf_envpath() 1743static void scanelf_envpath(void)
279{ 1744{
280 char *path, *p; 1745 char *path, *p;
281 1746
282 path = getenv("PATH"); 1747 path = getenv("PATH");
283 if (!path) 1748 if (!path)
284 err("PATH is not set in your env !"); 1749 err("PATH is not set in your env !");
285 1750 path = xstrdup(path);
286 if ((path = strdup(path)) == NULL)
287 err("stdup failed: %s", strerror(errno));
288 1751
289 while ((p = strrchr(path, ':')) != NULL) { 1752 while ((p = strrchr(path, ':')) != NULL) {
290 scanelf_dir(p + 1); 1753 scanelf_dir(p + 1);
291 *p = 0; 1754 *p = 0;
292 } 1755 }
293 1756
294 free(path); 1757 free(path);
295} 1758}
296 1759
297 1760/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
298 1761#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
299/* usage / invocation handling functions */ 1762#define a_argument required_argument
300#define PARSE_FLAGS "plRmxetro:aqvBhV"
301static struct option const long_opts[] = { 1763static struct option const long_opts[] = {
302 {"path", no_argument, NULL, 'p'}, 1764 {"path", no_argument, NULL, 'p'},
303 {"ldpath", no_argument, NULL, 'l'}, 1765 {"ldpath", no_argument, NULL, 'l'},
1766 {"root", a_argument, NULL, 128},
304 {"recursive", no_argument, NULL, 'R'}, 1767 {"recursive", no_argument, NULL, 'R'},
305 {"mount", no_argument, NULL, 'm'}, 1768 {"mount", no_argument, NULL, 'm'},
1769 {"symlink", no_argument, NULL, 'y'},
1770 {"archives", no_argument, NULL, 'A'},
1771 {"ldcache", no_argument, NULL, 'L'},
1772 {"fix", no_argument, NULL, 'X'},
1773 {"setpax", a_argument, NULL, 'z'},
306 {"pax", no_argument, NULL, 'x'}, 1774 {"pax", no_argument, NULL, 'x'},
307 {"header", no_argument, NULL, 'e'}, 1775 {"header", no_argument, NULL, 'e'},
308 {"textrel", no_argument, NULL, 't'}, 1776 {"textrel", no_argument, NULL, 't'},
309 {"rpath", no_argument, NULL, 'r'}, 1777 {"rpath", no_argument, NULL, 'r'},
310 {"file",required_argument, NULL, 'o'}, 1778 {"needed", no_argument, NULL, 'n'},
1779 {"interp", no_argument, NULL, 'i'},
1780 {"bind", no_argument, NULL, 'b'},
1781 {"soname", no_argument, NULL, 'S'},
1782 {"symbol", a_argument, NULL, 's'},
1783 {"section", a_argument, NULL, 'k'},
1784 {"lib", a_argument, NULL, 'N'},
1785 {"gmatch", no_argument, NULL, 'g'},
1786 {"textrels", no_argument, NULL, 'T'},
1787 {"etype", a_argument, NULL, 'E'},
1788 {"bits", a_argument, NULL, 'M'},
1789 {"endian", no_argument, NULL, 'D'},
1790 {"osabi", no_argument, NULL, 'I'},
1791 {"eabi", no_argument, NULL, 'Y'},
1792 {"perms", a_argument, NULL, 'O'},
1793 {"size", no_argument, NULL, 'Z'},
311 {"all", no_argument, NULL, 'a'}, 1794 {"all", no_argument, NULL, 'a'},
312 {"quiet", no_argument, NULL, 'q'}, 1795 {"quiet", no_argument, NULL, 'q'},
313 {"verbose", no_argument, NULL, 'v'}, 1796 {"verbose", no_argument, NULL, 'v'},
1797 {"format", a_argument, NULL, 'F'},
1798 {"from", a_argument, NULL, 'f'},
1799 {"file", a_argument, NULL, 'o'},
1800 {"nocolor", no_argument, NULL, 'C'},
314 {"nobanner", no_argument, NULL, 'B'}, 1801 {"nobanner", no_argument, NULL, 'B'},
315 {"help", no_argument, NULL, 'h'}, 1802 {"help", no_argument, NULL, 'h'},
316 {"version", no_argument, NULL, 'V'}, 1803 {"version", no_argument, NULL, 'V'},
317 {NULL, no_argument, NULL, 0x0} 1804 {NULL, no_argument, NULL, 0x0}
318}; 1805};
1806
319static char *opts_help[] = { 1807static const char * const opts_help[] = {
320 "Scan all directories in PATH environment", 1808 "Scan all directories in PATH environment",
321 "Scan all directories in /etc/ld.so.conf", 1809 "Scan all directories in /etc/ld.so.conf",
1810 "Root directory (use with -l or -p)",
322 "Scan directories recursively", 1811 "Scan directories recursively",
323 "Don't recursively cross mount points\n", 1812 "Don't recursively cross mount points",
1813 "Don't scan symlinks",
1814 "Scan archives (.a files)",
1815 "Utilize ld.so.cache information (use with -r/-n)",
1816 "Try and 'fix' bad things (use with -r/-e)",
1817 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
324 "Print PaX markings", 1818 "Print PaX markings",
325 "Print GNU_STACK markings", 1819 "Print GNU_STACK/PT_LOAD markings",
326 "Print TEXTREL information", 1820 "Print TEXTREL information",
327 "Print RPATH information", 1821 "Print RPATH information",
328 "Write output stream to a filename", 1822 "Print NEEDED information",
329 "Print all scanned info (-x -e -t -r)\n", 1823 "Print INTERP information",
1824 "Print BIND information",
1825 "Print SONAME information",
1826 "Find a specified symbol",
1827 "Find a specified section",
1828 "Find a specified library",
1829 "Use regex matching rather than string compare (use with -s)",
1830 "Locate cause of TEXTREL",
1831 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1832 "Print only ELF files matching numeric bits",
1833 "Print Endianness",
1834 "Print OSABI",
1835 "Print EABI (EM_ARM Only)",
1836 "Print only ELF files matching octal permissions",
1837 "Print ELF file size",
1838 "Print all useful/simple info\n",
330 "Only output 'bad' things", 1839 "Only output 'bad' things",
331 "Be verbose (can be specified more than once)", 1840 "Be verbose (can be specified more than once)",
1841 "Use specified format for output",
1842 "Read input stream from a filename",
1843 "Write output stream to a filename",
1844 "Don't emit color in output",
332 "Don't display the header", 1845 "Don't display the header",
333 "Print this help and exit", 1846 "Print this help and exit",
334 "Print version and exit", 1847 "Print version and exit",
335 NULL 1848 NULL
336}; 1849};
337 1850
338/* display usage and exit */ 1851/* display usage and exit */
339static void usage(int status) 1852static void usage(int status)
340{ 1853{
1854 unsigned long i;
1855 printf("* Scan ELF binaries for stuff\n\n"
1856 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1857 printf("Options: -[%s]\n", PARSE_FLAGS);
1858 for (i = 0; long_opts[i].name; ++i)
1859 if (long_opts[i].has_arg == no_argument)
1860 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
1861 long_opts[i].name, opts_help[i]);
1862 else if (long_opts[i].val > '~')
1863 printf(" --%-7s <arg> * %s\n",
1864 long_opts[i].name, opts_help[i]);
1865 else
1866 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
1867 long_opts[i].name, opts_help[i]);
1868
1869 puts("\nFor more information, see the scanelf(1) manpage");
1870 exit(status);
1871}
1872
1873/* parse command line arguments and preform needed actions */
1874#define do_pax_state(option, flag) \
1875 if (islower(option)) { \
1876 flags &= ~PF_##flag; \
1877 flags |= PF_NO##flag; \
1878 } else { \
1879 flags &= ~PF_NO##flag; \
1880 flags |= PF_##flag; \
1881 }
1882static int parseargs(int argc, char *argv[])
1883{
341 int i; 1884 int i;
342 printf(" Scan ELF binaries for stuff\n\n" 1885 const char *from_file = NULL;
343 "Usage: %s [options] <dir1> [dir2 dirN ...]\n\n", argv0); 1886 int ret = 0;
344 printf("Options:\n");
345 for (i = 0; long_opts[i].name; ++i)
346 printf(" -%c, --%-12s %s\n", long_opts[i].val,
347 long_opts[i].name, opts_help[i]);
348#ifdef MANLYPAGE
349 for (i = 0; long_opts[i].name; ++i)
350 printf(".TP\n\\fB\\-%c, \\-\\-%s\\fR\n%s\n", long_opts[i].val,
351 long_opts[i].name, opts_help[i]);
352#endif
353 exit(status);
354}
355
356/* parse command line arguments and preform needed actions */
357static void parseargs(int argc, char *argv[])
358{
359 int flag;
360 1887
361 opterr = 0; 1888 opterr = 0;
362 while ((flag=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 1889 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
363 switch (flag) { 1890 switch (i) {
364 1891
365 case 'V': /* version info */ 1892 case 'V':
366 printf("%s compiled %s\n%s\n" 1893 printf("pax-utils-%s: %s compiled %s\n%s\n"
367 "%s written for Gentoo Linux by <solar and vapier @ gentoo.org>\n", 1894 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
368 __FILE__, __DATE__, rcsid, argv0); 1895 VERSION, __FILE__, __DATE__, rcsid, argv0);
369 exit(EXIT_SUCCESS); 1896 exit(EXIT_SUCCESS);
370 break; 1897 break;
371 case 's': /* reserved for -s, --symbol= */
372 case 'h': usage(EXIT_SUCCESS); break; 1898 case 'h': usage(EXIT_SUCCESS); break;
373
374 case 'o': 1899 case 'f':
375 { 1900 if (from_file) warn("You prob don't want to specify -f twice");
376 FILE *fp = NULL; 1901 from_file = optarg;
377 fp = freopen(optarg, "w", stdout);
378 if (fp == NULL) {
379 fputs("open ", stderr);
380 perror(optarg);
381 } else
382 stdout = fp;
383 break; 1902 break;
1903 case 'E':
1904 match_etypes = optarg;
1905 break;
1906 case 'M':
1907 match_bits = atoi(optarg);
1908 if (match_bits == 0) {
1909 if (strcmp(optarg, "ELFCLASS32") == 0)
1910 match_bits = 32;
1911 if (strcmp(optarg, "ELFCLASS64") == 0)
1912 match_bits = 64;
384 } 1913 }
1914 break;
1915 case 'O':
1916 if (sscanf(optarg, "%o", &match_perms) == -1)
1917 match_bits = 0;
1918 break;
1919 case 'o': {
1920 if (freopen(optarg, "w", stdout) == NULL)
1921 err("Could not open output stream '%s': %s", optarg, strerror(errno));
1922 break;
1923 }
1924 case 'k':
1925 xarraypush(find_section_arr, optarg, strlen(optarg));
1926 break;
1927 case 's': {
1928 if (find_sym) warn("You prob don't want to specify -s twice");
1929 find_sym = optarg;
1930 break;
1931 }
1932 case 'N':
1933 xarraypush(find_lib_arr, optarg, strlen(optarg));
1934 break;
1935 case 'F': {
1936 if (out_format) warn("You prob don't want to specify -F twice");
1937 out_format = optarg;
1938 break;
1939 }
1940 case 'z': {
1941 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1942 size_t x;
1943
1944 for (x = 0; x < strlen(optarg); x++) {
1945 switch (optarg[x]) {
1946 case 'p':
1947 case 'P':
1948 do_pax_state(optarg[x], PAGEEXEC);
1949 break;
1950 case 's':
1951 case 'S':
1952 do_pax_state(optarg[x], SEGMEXEC);
1953 break;
1954 case 'm':
1955 case 'M':
1956 do_pax_state(optarg[x], MPROTECT);
1957 break;
1958 case 'e':
1959 case 'E':
1960 do_pax_state(optarg[x], EMUTRAMP);
1961 break;
1962 case 'r':
1963 case 'R':
1964 do_pax_state(optarg[x], RANDMMAP);
1965 break;
1966 case 'x':
1967 case 'X':
1968 do_pax_state(optarg[x], RANDEXEC);
1969 break;
1970 default:
1971 break;
1972 }
1973 }
1974 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
1975 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
1976 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
1977 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
1978 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1979 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1980 setpax = flags;
1981 break;
1982 }
1983 case 'Z': show_size = 1; break;
1984 case 'g': g_match = 1; break;
1985 case 'L': use_ldcache = 1; break;
1986 case 'y': scan_symlink = 0; break;
1987 case 'A': scan_archives = 1; break;
1988 case 'C': color_init(true); break;
385 case 'B': show_banner = 0; break; 1989 case 'B': show_banner = 0; break;
386 case 'l': scan_ldpath = 1; break; 1990 case 'l': scan_ldpath = 1; break;
387 case 'p': scan_envpath = 1; break; 1991 case 'p': scan_envpath = 1; break;
388 case 'R': dir_recurse = 1; break; 1992 case 'R': dir_recurse = 1; break;
389 case 'm': dir_crossmount = 0; break; 1993 case 'm': dir_crossmount = 0; break;
1994 case 'X': ++fix_elf; break;
390 case 'x': show_pax = 1; break; 1995 case 'x': show_pax = 1; break;
391 case 'e': show_stack = 1; break; 1996 case 'e': show_phdr = 1; break;
392 case 't': show_textrel = 1; break; 1997 case 't': show_textrel = 1; break;
393 case 'r': show_rpath = 1; break; 1998 case 'r': show_rpath = 1; break;
1999 case 'n': show_needed = 1; break;
2000 case 'i': show_interp = 1; break;
2001 case 'b': show_bind = 1; break;
2002 case 'S': show_soname = 1; break;
2003 case 'T': show_textrels = 1; break;
394 case 'q': be_quiet = 1; break; 2004 case 'q': be_quiet = 1; break;
395 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2005 case 'v': be_verbose = (be_verbose % 20) + 1; break;
396 case 'a': show_pax = show_stack = show_textrel = show_rpath = 1; break; 2006 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
397 2007 case 'D': show_endian = 1; break;
2008 case 'I': show_osabi = 1; break;
2009 case 'Y': show_eabi = 1; break;
2010 case 128:
2011 root = optarg;
2012 break;
398 case ':': 2013 case ':':
399 warn("Option missing parameter"); 2014 err("Option '%c' is missing parameter", optopt);
400 usage(EXIT_FAILURE);
401 break;
402 case '?': 2015 case '?':
403 warn("Unknown option"); 2016 err("Unknown option '%c' or argument missing", optopt);
404 usage(EXIT_FAILURE);
405 break;
406 default: 2017 default:
407 err("Unhandled option '%c'", flag); 2018 err("Unhandled option '%c'; please report this", i);
408 break; 2019 }
2020 }
2021 if (show_textrels && be_verbose) {
2022 if (which("objdump") != NULL)
2023 has_objdump = 1;
2024 }
2025 /* flatten arrays for display */
2026 if (array_cnt(find_lib_arr))
2027 find_lib = array_flatten_str(find_lib_arr);
2028 if (array_cnt(find_section_arr))
2029 find_section = array_flatten_str(find_section_arr);
2030 /* let the format option override all other options */
2031 if (out_format) {
2032 show_pax = show_phdr = show_textrel = show_rpath = \
2033 show_needed = show_interp = show_bind = show_soname = \
2034 show_textrels = show_perms = show_endian = show_size = \
2035 show_osabi = show_eabi = 0;
2036 for (i = 0; out_format[i]; ++i) {
2037 if (!IS_MODIFIER(out_format[i])) continue;
2038
2039 switch (out_format[++i]) {
2040 case '+': break;
2041 case '%': break;
2042 case '#': break;
2043 case 'F': break;
2044 case 'p': break;
2045 case 'f': break;
2046 case 'k': break;
2047 case 's': break;
2048 case 'N': break;
2049 case 'o': break;
2050 case 'a': break;
2051 case 'M': break;
2052 case 'Z': show_size = 1; break;
2053 case 'D': show_endian = 1; break;
2054 case 'I': show_osabi = 1; break;
2055 case 'Y': show_eabi = 1; break;
2056 case 'O': show_perms = 1; break;
2057 case 'x': show_pax = 1; break;
2058 case 'e': show_phdr = 1; break;
2059 case 't': show_textrel = 1; break;
2060 case 'r': show_rpath = 1; break;
2061 case 'n': show_needed = 1; break;
2062 case 'i': show_interp = 1; break;
2063 case 'b': show_bind = 1; break;
2064 case 'S': show_soname = 1; break;
2065 case 'T': show_textrels = 1; break;
2066 default:
2067 err("Invalid format specifier '%c' (byte %i)",
2068 out_format[i], i+1);
409 } 2069 }
410 } 2070 }
411 2071
412 if (be_quiet && be_verbose) 2072 /* construct our default format */
413 err("You can be quiet or you can be verbose, not both, stupid"); 2073 } else {
2074 size_t fmt_len = 30;
2075 out_format = xmalloc(sizeof(char) * fmt_len);
2076 *out_format = '\0';
2077 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
2078 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2079 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2080 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2081 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2082 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2083 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
2084 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
2085 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
2086 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
2087 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
2088 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
2089 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
2090 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
2091 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
2092 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2093 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
2094 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
2095 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
2096 }
2097 if (be_verbose > 2) printf("Format: %s\n", out_format);
414 2098
2099 /* now lets actually do the scanning */
2100 if (scan_ldpath || use_ldcache)
2101 load_ld_cache_config(0, __PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
415 if (scan_ldpath) scanelf_ldpath(); 2102 if (scan_ldpath) scanelf_ldpath();
416 if (scan_envpath) scanelf_envpath(); 2103 if (scan_envpath) scanelf_envpath();
2104 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2105 from_file = "-";
2106 if (from_file) {
2107 scanelf_from_file(from_file);
2108 from_file = *argv;
2109 }
2110 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
2111 err("Nothing to scan !?");
417 while (optind < argc) 2112 while (optind < argc) {
418 scanelf_dir(argv[optind++]); 2113 search_path = argv[optind++];
419} 2114 ret = scanelf_dir(search_path);
2115 }
420 2116
2117 /* clean up */
2118 xarrayfree(ldpaths);
2119 xarrayfree(find_lib_arr);
2120 xarrayfree(find_section_arr);
2121 free(find_lib);
2122 free(find_section);
421 2123
2124 if (ldcache != 0)
2125 munmap(ldcache, ldcache_size);
2126 return ret;
2127}
2128
2129static char **get_split_env(const char *envvar)
2130{
2131 const char *delims = " \t\n";
2132 char **envvals = NULL;
2133 char *env, *s;
2134 int nentry;
2135
2136 if ((env = getenv(envvar)) == NULL)
2137 return NULL;
2138
2139 env = xstrdup(env);
2140 if (env == NULL)
2141 return NULL;
2142
2143 s = strtok(env, delims);
2144 if (s == NULL) {
2145 free(env);
2146 return NULL;
2147 }
2148
2149 nentry = 0;
2150 while (s != NULL) {
2151 ++nentry;
2152 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2153 envvals[nentry-1] = s;
2154 s = strtok(NULL, delims);
2155 }
2156 envvals[nentry] = NULL;
2157
2158 /* don't want to free(env) as it contains the memory that backs
2159 * the envvals array of strings */
2160 return envvals;
2161}
2162
2163static void parseenv(void)
2164{
2165 color_init(false);
2166 qa_textrels = get_split_env("QA_TEXTRELS");
2167 qa_execstack = get_split_env("QA_EXECSTACK");
2168 qa_wx_load = get_split_env("QA_WX_LOAD");
2169}
2170
2171#ifdef __PAX_UTILS_CLEANUP
2172static void cleanup(void)
2173{
2174 free(out_format);
2175 free(qa_textrels);
2176 free(qa_execstack);
2177 free(qa_wx_load);
2178}
2179#endif
422 2180
423int main(int argc, char *argv[]) 2181int main(int argc, char *argv[])
424{ 2182{
2183 int ret;
425 if (argc < 2) 2184 if (argc < 2)
426 usage(EXIT_FAILURE); 2185 usage(EXIT_FAILURE);
2186 parseenv();
427 parseargs(argc, argv); 2187 ret = parseargs(argc, argv);
428 fclose(stdout); 2188 fclose(stdout);
429 return EXIT_SUCCESS; 2189#ifdef __PAX_UTILS_CLEANUP
2190 cleanup();
2191 warn("The calls to add/delete heap should be off:\n"
2192 "\t- 1 due to the out_buffer not being freed in scanelf_file()\n"
2193 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
2194#endif
2195 return ret;
430} 2196}
2197
2198/* Match filename against entries in matchlist, return TRUE
2199 * if the file is listed */
2200static int file_matches_list(const char *filename, char **matchlist)
2201{
2202 char **file;
2203 char *match;
2204 char buf[__PAX_UTILS_PATH_MAX];
2205
2206 if (matchlist == NULL)
2207 return 0;
2208
2209 for (file = matchlist; *file != NULL; file++) {
2210 if (search_path) {
2211 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2212 match = buf;
2213 } else {
2214 match = *file;
2215 }
2216 if (fnmatch(match, filename, 0) == 0)
2217 return 1;
2218 }
2219 return 0;
2220}

Legend:
Removed from v.1.23  
changed lines
  Added in v.1.229

  ViewVC Help
Powered by ViewVC 1.1.20