/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.229 Revision 1.251
1/* 1/*
2 * Copyright 2003-2007 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.229 2011/09/27 19:29:19 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.251 2012/11/10 09:43:00 vapier Exp $
5 * 5 *
6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char *rcsid = "$Id: scanelf.c,v 1.229 2011/09/27 19:29:19 vapier Exp $"; 10static const char rcsid[] = "$Id: scanelf.c,v 1.251 2012/11/10 09:43:00 vapier Exp $";
11const char argv0[] = "scanelf"; 11const char argv0[] = "scanelf";
12 12
13#include "paxinc.h" 13#include "paxinc.h"
14 14
15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
44static char be_quiet = 0; 44static char be_quiet = 0;
45static char be_verbose = 0; 45static char be_verbose = 0;
46static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
47static char be_semi_verbose = 0; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL; 48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
49static char *find_lib = NULL; 51static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr; 52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL; 53static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr; 54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
53static char *out_format = NULL; 55static char *out_format = NULL;
54static char *search_path = NULL; 56static char *search_path = NULL;
55static char fix_elf = 0; 57static char fix_elf = 0;
56static char g_match = 0; 58static char g_match = 0;
57static char use_ldcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
58 61
59static char **qa_textrels = NULL; 62static char **qa_textrels = NULL;
60static char **qa_execstack = NULL; 63static char **qa_execstack = NULL;
61static char **qa_wx_load = NULL; 64static char **qa_wx_load = NULL;
62static char *root; 65static int root_fd = AT_FDCWD;
63 66
64static int match_bits = 0; 67static int match_bits = 0;
65static unsigned int match_perms = 0; 68static unsigned int match_perms = 0;
66static void *ldcache = NULL; 69static void *ldcache = NULL;
67static size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
68static unsigned long setpax = 0UL; 71static unsigned long setpax = 0UL;
69 72
70static int has_objdump = 0; 73static int has_objdump = 0;
71 74
72/* find the path to a file by name */ 75/* find the path to a file by name */
73static char *which(const char *fname) 76static int bin_in_path(const char *fname)
74{ 77{
75 static char fullpath[__PAX_UTILS_PATH_MAX]; 78 char fullpath[__PAX_UTILS_PATH_MAX];
76 char *path, *p; 79 char *path, *p;
77 80
78 path = getenv("PATH"); 81 path = getenv("PATH");
79 if (!path) 82 if (!path)
80 return NULL; 83 return 0;
81 84
82 path = xstrdup(path);
83 while ((p = strrchr(path, ':')) != NULL) { 85 while ((p = strrchr(path, ':')) != NULL) {
84 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname); 86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
85 *p = 0; 87 *p = 0;
86 if (access(fullpath, R_OK) != -1) { 88 if (access(fullpath, R_OK) != -1)
87 free(path); 89 return 1;
88 return fullpath;
89 } 90 }
90 } 91
91 free(path); 92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
92 return NULL; 99 return NULL;
100 return fdopen(fd, "re");
93} 101}
94 102
95/* 1 on failure. 0 otherwise */ 103static const char *root_rel_path(const char *path)
96static int rematch(const char *regex, const char *match, int cflags)
97{ 104{
98 regex_t preg; 105 /*
99 int ret; 106 * openat() will ignore the dirfd if path starts with
100 107 * a /, so consume all of that noise
101 if ((match == NULL) || (regex == NULL)) 108 *
102 return EXIT_FAILURE; 109 * XXX: we don't handle relative paths like ../ that
103 110 * break out of the --root option, but for now, just
104 if ((ret = regcomp(&preg, regex, cflags))) { 111 * don't do that :P.
105 char err[256]; 112 */
106 113 if (root_fd != AT_FDCWD) {
107 if (regerror(ret, &preg, err, sizeof(err))) 114 while (*path == '/')
108 fprintf(stderr, "regcomp failed: %s", err); 115 ++path;
109 else 116 if (*path == '\0')
110 fprintf(stderr, "regcomp failed"); 117 path = ".";
111
112 return EXIT_FAILURE;
113 } 118 }
114 ret = regexec(&preg, match, 0, NULL, 0);
115 regfree(&preg);
116 119
117 return ret; 120 return path;
118} 121}
119 122
120/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
121static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
122{ 125{
123 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
124 127
125 /* debug sections */ 128 /* debug sections */
126 void *symtab = elf_findsecbyname(elf, ".symtab"); 129 void *symtab = elf_findsecbyname(elf, ".symtab");
127 void *strtab = elf_findsecbyname(elf, ".strtab"); 130 void *strtab = elf_findsecbyname(elf, ".strtab");
128 /* runtime sections */ 131 /* runtime sections */
129 void *dynsym = elf_findsecbyname(elf, ".dynsym"); 132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
130 void *dynstr = elf_findsecbyname(elf, ".dynstr"); 133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
131 134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
132#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
133 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
134 if (symtab && dynsym) { \
135 Elf ## B ## _Shdr *esymtab = symtab; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
144 Elf ## B ## _Shdr *estrtab = strtab; \
136 Elf ## B ## _Shdr *edynsym = dynsym; \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
146 Elf ## B ## _Shdr *edynstr = dynstr; \
147 \
148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
152 if (symtab && dynsym) \
137 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
138 } else \ 154 else \
139 *sym = symtab ? symtab : dynsym; \ 155 *sym = symtab ? symtab : dynsym; \
156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
140 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
141 Elf ## B ## _Shdr *estrtab = strtab; \
142 Elf ## B ## _Shdr *edynstr = dynstr; \
143 *tab = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
144 } else \ 163 else \
145 *tab = strtab ? strtab : dynstr; \ 164 *str = strtab ? strtab : dynstr; \
146 } 165 }
147 GET_SYMTABS(32) 166 GET_SYMTABS(32)
148 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
149} 259}
150 260
151static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
152{ 262{
153 static char ret[7]; 263 static char ret[7];
180 } 290 }
181 SHOW_PAX(32) 291 SHOW_PAX(32)
182 SHOW_PAX(64) 292 SHOW_PAX(64)
183 } 293 }
184 294
185 if (fix_elf && setpax) { 295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
186 /* set the chpax settings */ 296 * was found. This is known to break ELFs on glibc systems,
187 if (elf->elf_class == ELFCLASS32) { 297 * and mainline PaX has deprecated use of this for a long time.
188 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC) 298 * We could support changing PT_GNU_STACK, but that doesn't
189 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax)); 299 * seem like it's worth the effort. #411919
190 } else { 300 */
191 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
192 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
193 }
194 }
195 301
196 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
197 if (!*ret) { 303 if (!*ret) {
198 static char *paxflags; 304 static char *paxflags;
199 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
467 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 573 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
468 if (be_verbose && has_objdump) { \ 574 if (be_verbose && has_objdump) { \
469 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \ 575 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
470 char *sysbuf; \ 576 char *sysbuf; \
471 size_t syslen; \ 577 size_t syslen; \
472 int sysret; \
473 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \ 578 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
474 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \ 579 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
475 sysbuf = xmalloc(syslen); \ 580 sysbuf = xmalloc(syslen); \
476 if (end_addr < r_offset) \ 581 if (end_addr < r_offset) \
477 /* not uncommon when things are optimized out */ \ 582 /* not uncommon when things are optimized out */ \
480 (unsigned long)offset_tmp, \ 585 (unsigned long)offset_tmp, \
481 (unsigned long)end_addr, \ 586 (unsigned long)end_addr, \
482 elf->filename, \ 587 elf->filename, \
483 (unsigned long)r_offset); \ 588 (unsigned long)r_offset); \
484 fflush(stdout); \ 589 fflush(stdout); \
485 sysret = system(sysbuf); \ 590 if (system(sysbuf)) /* don't care */; \
486 fflush(stdout); \ 591 fflush(stdout); \
487 free(sysbuf); \ 592 free(sysbuf); \
488 } \ 593 } \
489 } \ 594 } \
490 } } 595 } }
684#define FLAG_MIPS64_LIBN32 0x0600 789#define FLAG_MIPS64_LIBN32 0x0600
685#define FLAG_MIPS64_LIBN64 0x0700 790#define FLAG_MIPS64_LIBN64 0x0700
686 791
687#if defined(__GLIBC__) || defined(__UCLIBC__) 792#if defined(__GLIBC__) || defined(__UCLIBC__)
688 793
689static char *lookup_cache_lib(elfobj *elf, char *fname) 794static char *lookup_cache_lib(elfobj *elf, const char *fname)
690{ 795{
691 int fd; 796 int fd;
692 char *strs; 797 char *strs;
693 static char buf[__PAX_UTILS_PATH_MAX] = ""; 798 static char buf[__PAX_UTILS_PATH_MAX] = "";
694 const char cachefile[] = "/etc/ld.so.cache"; 799 const char *cachefile = root_rel_path("/etc/ld.so.cache");
695 struct stat st; 800 struct stat st;
696 801
697 typedef struct { 802 typedef struct {
698 char magic[LDSO_CACHE_MAGIC_LEN]; 803 char magic[LDSO_CACHE_MAGIC_LEN];
699 char version[LDSO_CACHE_VER_LEN]; 804 char version[LDSO_CACHE_VER_LEN];
710 815
711 if (fname == NULL) 816 if (fname == NULL)
712 return NULL; 817 return NULL;
713 818
714 if (ldcache == NULL) { 819 if (ldcache == NULL) {
715 if (stat(cachefile, &st)) 820 if (fstatat(root_fd, cachefile, &st, 0))
716 return NULL; 821 return NULL;
717 822
718 fd = open(cachefile, O_RDONLY); 823 fd = openat(root_fd, cachefile, O_RDONLY);
719 if (fd == -1) 824 if (fd == -1)
720 return NULL; 825 return NULL;
721 826
722 /* cache these values so we only map/unmap the cache file once */ 827 /* cache these values so we only map/unmap the cache file once */
723 ldcache_size = st.st_size; 828 ldcache_size = st.st_size;
762 867
763 return buf; 868 return buf;
764} 869}
765 870
766#elif defined(__NetBSD__) 871#elif defined(__NetBSD__)
767static char *lookup_cache_lib(elfobj *elf, char *fname) 872static char *lookup_cache_lib(elfobj *elf, const char *fname)
768{ 873{
769 static char buf[__PAX_UTILS_PATH_MAX] = ""; 874 static char buf[__PAX_UTILS_PATH_MAX] = "";
770 static struct stat st; 875 static struct stat st;
771 size_t n; 876 size_t n;
772 char *ldpath; 877 char *ldpath;
791} 896}
792#else 897#else
793#ifdef __ELF__ 898#ifdef __ELF__
794#warning Cache support not implemented for your target 899#warning Cache support not implemented for your target
795#endif 900#endif
796static char *lookup_cache_lib(elfobj *elf, char *fname) 901static char *lookup_cache_lib(elfobj *elf, const char *fname)
797{ 902{
798 return NULL; 903 return NULL;
799} 904}
800#endif 905#endif
906
907static char *lookup_config_lib(elfobj *elf, char *fname)
908{
909 static char buf[__PAX_UTILS_PATH_MAX] = "";
910 const char *ldpath;
911 size_t n;
912
913 array_for_each(ldpaths, n, ldpath) {
914 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
915 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
916 return buf;
917 }
918
919 return NULL;
920}
801 921
802static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 922static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
803{ 923{
804 unsigned long i; 924 unsigned long i;
805 char *needed; 925 char *needed;
843 needed = elf->data + offset; \ 963 needed = elf->data + offset; \
844 if (op == 0) { \ 964 if (op == 0) { \
845 /* -n -> print all entries */ \ 965 /* -n -> print all entries */ \
846 if (!be_wewy_wewy_quiet) { \ 966 if (!be_wewy_wewy_quiet) { \
847 if (*found_needed) xchrcat(ret, ',', ret_len); \ 967 if (*found_needed) xchrcat(ret, ',', ret_len); \
848 if (use_ldcache) \ 968 if (use_ldpath) { \
969 if ((p = lookup_config_lib(elf, needed)) != NULL) \
970 needed = p; \
971 } else if (use_ldcache) { \
849 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 972 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
850 needed = p; \ 973 needed = p; \
974 } \
851 xstrcat(ret, needed, ret_len); \ 975 xstrcat(ret, needed, ret_len); \
852 } \ 976 } \
853 *found_needed = 1; \ 977 *found_needed = 1; \
854 } else { \ 978 } else { \
855 /* -N -> print matching entries */ \ 979 /* -N -> print matching entries */ \
856 size_t n; \ 980 size_t n; \
857 const char *find_lib_name; \ 981 const char *find_lib_name; \
858 \ 982 \
859 array_for_each(find_lib_arr, n, find_lib_name) \ 983 array_for_each(find_lib_arr, n, find_lib_name) { \
984 int invert = 1; \
985 if (find_lib_name[0] == '!') \
986 invert = 0, ++find_lib_name; \
860 if (!strcmp(find_lib_name, needed)) \ 987 if (!strcmp(find_lib_name, needed) == invert) \
861 ++matched; \ 988 ++matched; \
989 } \
862 \ 990 \
863 if (matched == array_cnt(find_lib_arr)) { \ 991 if (matched == array_cnt(find_lib_arr)) { \
864 *found_lib = 1; \ 992 *found_lib = 1; \
865 return (be_wewy_wewy_quiet ? NULL : find_lib); \ 993 return (be_wewy_wewy_quiet ? NULL : find_lib); \
866 } \ 994 } \
892 *found_interp = 1; \ 1020 *found_interp = 1; \
893 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1021 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
894 } 1022 }
895 SHOW_INTERP(32) 1023 SHOW_INTERP(32)
896 SHOW_INTERP(64) 1024 SHOW_INTERP(64)
1025 } else {
1026 /* Walk all the program headers to find the PT_INTERP */
1027#define SHOW_PT_INTERP(B) \
1028 if (elf->elf_class == ELFCLASS ## B) { \
1029 unsigned long i; \
1030 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1031 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1032 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1033 if (EGET(phdr[i].p_type) != PT_INTERP) \
1034 continue; \
1035 *found_interp = 1; \
1036 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1037 } \
897 } 1038 }
1039 SHOW_PT_INTERP(32)
1040 SHOW_PT_INTERP(64)
1041 }
1042
898 return NULL; 1043 return NULL;
899} 1044}
900static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1045static char *scanelf_file_bind(elfobj *elf, char *found_bind)
901{ 1046{
902 unsigned long i; 1047 unsigned long i;
1001 * defined symbols. If it's a minus ("-"), only match undefined symbols. 1146 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1002 * Putting modifiers in between the percent signs allows for more in depth 1147 * Putting modifiers in between the percent signs allows for more in depth
1003 * filters. There are groups of modifiers. If you don't specify a member 1148 * filters. There are groups of modifiers. If you don't specify a member
1004 * of a group, then all types in that group are matched. The current 1149 * of a group, then all types in that group are matched. The current
1005 * groups and their types are: 1150 * groups and their types are:
1006 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f SST_FILE:F 1151 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1007 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w 1152 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1008 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d 1153 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1009 * The "defined" value in the SHN group does not correspond to a SHN_xxx define. 1154 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1010 * You can search for multiple symbols at once by seperating with a comma (","). 1155 * You can search for multiple symbols at once by seperating with a comma (",").
1011 * 1156 *
1023 */ 1168 */
1024static void 1169static void
1025scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname, 1170scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1026 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size) 1171 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1027{ 1172{
1028 char *this_sym, *next_sym, saved = saved; 1173 const char *this_sym;
1174 size_t n;
1029 1175
1030 /* allow the user to specify a comma delimited list of symbols to search for */ 1176 array_for_each(find_sym_arr, n, this_sym) {
1031 next_sym = NULL;
1032 do {
1033 bool inc_notype, inc_object, inc_func, inc_file, 1177 bool inc_notype, inc_object, inc_func, inc_file,
1034 inc_local, inc_global, inc_weak, 1178 inc_local, inc_global, inc_weak,
1035 inc_def, inc_undef, inc_abs, inc_common; 1179 inc_def, inc_undef, inc_abs, inc_common;
1036
1037 if (next_sym) {
1038 next_sym[-1] = saved;
1039 this_sym = next_sym;
1040 } else
1041 this_sym = find_sym;
1042 if ((next_sym = strchr(this_sym, ','))) {
1043 /* make parsing easier by killing the comma temporarily */
1044 saved = *next_sym;
1045 *next_sym = '\0';
1046 next_sym += 1;
1047 }
1048 1180
1049 /* symbol selection! */ 1181 /* symbol selection! */
1050 inc_notype = inc_object = inc_func = inc_file = \ 1182 inc_notype = inc_object = inc_func = inc_file = \
1051 inc_local = inc_global = inc_weak = \ 1183 inc_local = inc_global = inc_weak = \
1052 inc_def = inc_undef = inc_abs = inc_common = \ 1184 inc_def = inc_undef = inc_abs = inc_common = \
1119 goto matched; 1251 goto matched;
1120 1252
1121 } else { 1253 } else {
1122 if (g_match) { 1254 if (g_match) {
1123 /* regex match the symbol */ 1255 /* regex match the symbol */
1124 if (rematch(this_sym, symname, REG_EXTENDED) != 0) 1256 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1125 continue; 1257 continue;
1126 1258
1127 } else if (*this_sym) { 1259 } else if (*this_sym) {
1128 /* give empty symbols a "pass", else do a normal compare */ 1260 /* give empty symbols a "pass", else do a normal compare */
1129 const size_t len = strlen(this_sym); 1261 const size_t len = strlen(this_sym);
1145 xstrcat(ret, symname, ret_len); 1277 xstrcat(ret, symname, ret_len);
1146 } 1278 }
1147 1279
1148 goto matched; 1280 goto matched;
1149 } 1281 }
1150 } while (next_sym); 1282 }
1151 1283
1152 return; 1284 return;
1153 1285
1154 matched: 1286 matched:
1155 *found_sym = 1; 1287 *found_sym = 1;
1156 if (next_sym)
1157 next_sym[-1] = saved;
1158} 1288}
1159 1289
1160static const char *scanelf_file_sym(elfobj *elf, char *found_sym) 1290static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
1161{ 1291{
1162 unsigned long i;
1163 char *ret; 1292 char *ret;
1164 void *symtab_void, *strtab_void; 1293 void *symtab_void, *strtab_void;
1165 1294
1166 if (!find_sym) return NULL; 1295 if (!find_sym) return NULL;
1167 ret = NULL; 1296 ret = NULL;
1172#define FIND_SYM(B) \ 1301#define FIND_SYM(B) \
1173 if (elf->elf_class == ELFCLASS ## B) { \ 1302 if (elf->elf_class == ELFCLASS ## B) { \
1174 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1303 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
1175 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1304 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
1176 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \ 1305 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
1177 unsigned long cnt = EGET(symtab->sh_entsize); \ 1306 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
1178 char *symname; \ 1307 char *symname; \
1179 size_t ret_len = 0; \ 1308 size_t ret_len = 0; \
1180 if (cnt) \ 1309 if (cnt) \
1181 cnt = EGET(symtab->sh_size) / cnt; \ 1310 cnt = EGET(symtab->sh_size) / cnt; \
1182 for (i = 0; i < cnt; ++i) { \ 1311 for (i = 0; i < cnt; ++i) { \
1199 EGET(sym->st_shndx), \ 1328 EGET(sym->st_shndx), \
1200 /* st_size can be 64bit, but no one is really that big, so screw em */ \ 1329 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1201 EGET(sym->st_size)); \ 1330 EGET(sym->st_size)); \
1202 } \ 1331 } \
1203 ++sym; \ 1332 ++sym; \
1204 } } 1333 } \
1334 }
1205 FIND_SYM(32) 1335 FIND_SYM(32)
1206 FIND_SYM(64) 1336 FIND_SYM(64)
1207 } 1337 }
1208 1338
1209break_out: 1339break_out:
1300 case 'x': prints(" PAX "); break; 1430 case 'x': prints(" PAX "); break;
1301 case 'e': prints("STK/REL/PTL "); break; 1431 case 'e': prints("STK/REL/PTL "); break;
1302 case 't': prints("TEXTREL "); break; 1432 case 't': prints("TEXTREL "); break;
1303 case 'r': prints("RPATH "); break; 1433 case 'r': prints("RPATH "); break;
1304 case 'M': prints("CLASS "); break; 1434 case 'M': prints("CLASS "); break;
1435 case 'l':
1305 case 'n': prints("NEEDED "); break; 1436 case 'n': prints("NEEDED "); break;
1306 case 'i': prints("INTERP "); break; 1437 case 'i': prints("INTERP "); break;
1307 case 'b': prints("BIND "); break; 1438 case 'b': prints("BIND "); break;
1308 case 'Z': prints("SIZE "); break; 1439 case 'Z': prints("SIZE "); break;
1309 case 'S': prints("SONAME "); break; 1440 case 'S': prints("SONAME "); break;
1419 elfobj *elf; 1550 elfobj *elf;
1420 1551
1421 /* verify this is real ELF */ 1552 /* verify this is real ELF */
1422 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) { 1553 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1423 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 1554 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1424 return ret; 1555 return 2;
1425 } 1556 }
1426 switch (match_bits) { 1557 switch (match_bits) {
1427 case 32: 1558 case 32:
1428 if (elf->elf_class != ELFCLASS32) 1559 if (elf->elf_class != ELFCLASS32)
1429 goto label_done; 1560 goto label_done;
1483 munmap(ar_buffer, len); 1614 munmap(ar_buffer, len);
1484 1615
1485 return 0; 1616 return 0;
1486} 1617}
1487/* scan a file which may be an elf or an archive or some other magical beast */ 1618/* scan a file which may be an elf or an archive or some other magical beast */
1488static int scanelf_file(const char *filename, const struct stat *st_cache) 1619static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1489{ 1620{
1490 const struct stat *st = st_cache; 1621 const struct stat *st = st_cache;
1491 struct stat symlink_st; 1622 struct stat symlink_st;
1492 int fd; 1623 int fd;
1493 1624
1494 /* always handle regular files and handle symlinked files if no -y */ 1625 /* always handle regular files and handle symlinked files if no -y */
1495 if (S_ISLNK(st->st_mode)) { 1626 if (S_ISLNK(st->st_mode)) {
1496 if (!scan_symlink) return 1; 1627 if (!scan_symlink)
1628 return 1;
1497 stat(filename, &symlink_st); 1629 fstatat(dir_fd, filename, &symlink_st, 0);
1498 st = &symlink_st; 1630 st = &symlink_st;
1499 } 1631 }
1500 1632
1501 if (!S_ISREG(st->st_mode)) { 1633 if (!S_ISREG(st->st_mode)) {
1502 if (be_verbose > 2) printf("%s: skipping non-file\n", filename); 1634 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1505 1637
1506 if (match_perms) { 1638 if (match_perms) {
1507 if ((st->st_mode | match_perms) != st->st_mode) 1639 if ((st->st_mode | match_perms) != st->st_mode)
1508 return 1; 1640 return 1;
1509 } 1641 }
1510 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1) 1642 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1643 if (fd == -1) {
1644 if (fix_elf && errno == ETXTBSY)
1645 warnp("%s: could not fix", filename);
1646 else if (be_verbose > 2)
1647 printf("%s: skipping file: %s\n", filename, strerror(errno));
1511 return 1; 1648 return 1;
1649 }
1512 1650
1513 if (scanelf_elf(filename, fd, st->st_size) == 1 && scan_archives) 1651 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1514 /* if it isn't an ELF, maybe it's an .a archive */ 1652 /* if it isn't an ELF, maybe it's an .a archive */
1653 if (scan_archives)
1515 scanelf_archive(filename, fd, st->st_size); 1654 scanelf_archive(filename, fd, st->st_size);
1516 1655
1656 /*
1657 * unreadelf() implicitly closes its fd, so only close it
1658 * when we are returning it in the non-ELF case
1659 */
1517 close(fd); 1660 close(fd);
1661 }
1662
1518 return 0; 1663 return 0;
1519} 1664}
1520 1665
1521static const char *maybe_add_root(const char *fname, char *buf)
1522{
1523 if (root && strncmp(fname, root, strlen(root))) {
1524 strcpy(buf, root);
1525 strncat(buf, fname, __PAX_UTILS_PATH_MAX - strlen(root) - 1);
1526 fname = buf;
1527 }
1528 return fname;
1529}
1530
1531/* scan a directory for ET_EXEC files and print when we find one */ 1666/* scan a directory for ET_EXEC files and print when we find one */
1532static int scanelf_dir(const char *path) 1667static int scanelf_dirat(int dir_fd, const char *path)
1533{ 1668{
1534 register DIR *dir; 1669 register DIR *dir;
1535 register struct dirent *dentry; 1670 register struct dirent *dentry;
1536 struct stat st_top, st; 1671 struct stat st_top, st;
1537 char buf[__PAX_UTILS_PATH_MAX]; 1672 char buf[__PAX_UTILS_PATH_MAX], *subpath;
1538 char _path[__PAX_UTILS_PATH_MAX];
1539 size_t pathlen = 0, len = 0; 1673 size_t pathlen = 0, len = 0;
1540 int ret = 0; 1674 int ret = 0;
1541 1675 int subdir_fd;
1542 path = maybe_add_root(path, _path);
1543 1676
1544 /* make sure path exists */ 1677 /* make sure path exists */
1545 if (lstat(path, &st_top) == -1) { 1678 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1546 if (be_verbose > 2) printf("%s: does not exist\n", path); 1679 if (be_verbose > 2) printf("%s: does not exist\n", path);
1547 return 1; 1680 return 1;
1548 } 1681 }
1549 1682
1550 /* ok, if it isn't a directory, assume we can open it */ 1683 /* ok, if it isn't a directory, assume we can open it */
1551 if (!S_ISDIR(st_top.st_mode)) { 1684 if (!S_ISDIR(st_top.st_mode))
1552 return scanelf_file(path, &st_top); 1685 return scanelf_fileat(dir_fd, path, &st_top);
1553 }
1554 1686
1555 /* now scan the dir looking for fun stuff */ 1687 /* now scan the dir looking for fun stuff */
1556 if ((dir = opendir(path)) == NULL) { 1688 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1557 warnf("could not opendir %s: %s", path, strerror(errno)); 1689 if (subdir_fd == -1)
1690 dir = NULL;
1691 else
1692 dir = fdopendir(subdir_fd);
1693 if (dir == NULL) {
1694 if (subdir_fd != -1)
1695 close(subdir_fd);
1696 warnfp("could not opendir(%s)", path);
1558 return 1; 1697 return 1;
1559 } 1698 }
1560 if (be_verbose > 1) printf("%s: scanning dir\n", path); 1699 if (be_verbose > 1) printf("%s: scanning dir\n", path);
1561 1700
1562 pathlen = strlen(path); 1701 subpath = stpcpy(buf, path);
1702 if (subpath[-1] != '/')
1703 *subpath++ = '/';
1704 pathlen = subpath - buf;
1563 while ((dentry = readdir(dir))) { 1705 while ((dentry = readdir(dir))) {
1564 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1706 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
1565 continue; 1707 continue;
1566 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1708
1567 if (len >= sizeof(buf)) { 1709 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1568 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
1569 (unsigned long)len, (unsigned long)sizeof(buf));
1570 continue; 1710 continue;
1711
1712 len = strlen(dentry->d_name);
1713 if (len + pathlen + 1 >= sizeof(buf)) {
1714 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1715 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1716 continue;
1571 } 1717 }
1572 snprintf(buf, sizeof(buf), "%s%s%s", path, (path[pathlen-1] == '/') ? "" : "/", dentry->d_name); 1718 memcpy(subpath, dentry->d_name, len);
1573 if (lstat(buf, &st) != -1) { 1719 subpath[len] = '\0';
1720
1574 if (S_ISREG(st.st_mode)) 1721 if (S_ISREG(st.st_mode))
1575 ret = scanelf_file(buf, &st); 1722 ret = scanelf_fileat(dir_fd, buf, &st);
1576 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1723 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1577 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1724 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1578 ret = scanelf_dir(buf); 1725 ret = scanelf_dirat(dir_fd, buf);
1579 }
1580 } 1726 }
1581 } 1727 }
1582 closedir(dir); 1728 closedir(dir);
1729
1583 return ret; 1730 return ret;
1584} 1731}
1732static int scanelf_dir(const char *path)
1733{
1734 return scanelf_dirat(root_fd, root_rel_path(path));
1735}
1585 1736
1586static int scanelf_from_file(const char *filename) 1737static int scanelf_from_file(const char *filename)
1587{ 1738{
1588 FILE *fp = NULL; 1739 FILE *fp;
1589 char *p; 1740 char *p, *path;
1590 char path[__PAX_UTILS_PATH_MAX]; 1741 size_t len;
1591 int ret = 0; 1742 int ret;
1592 1743
1593 if (strcmp(filename, "-") == 0) 1744 if (strcmp(filename, "-") == 0)
1594 fp = stdin; 1745 fp = stdin;
1595 else if ((fp = fopen(filename, "r")) == NULL) 1746 else if ((fp = fopen(filename, "r")) == NULL)
1596 return 1; 1747 return 1;
1597 1748
1598 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1749 path = NULL;
1750 len = 0;
1751 ret = 0;
1752 while (getline(&path, &len, fp) != -1) {
1599 if ((p = strchr(path, '\n')) != NULL) 1753 if ((p = strchr(path, '\n')) != NULL)
1600 *p = 0; 1754 *p = 0;
1601 search_path = path; 1755 search_path = path;
1602 ret = scanelf_dir(path); 1756 ret = scanelf_dir(path);
1603 } 1757 }
1758 free(path);
1759
1604 if (fp != stdin) 1760 if (fp != stdin)
1605 fclose(fp); 1761 fclose(fp);
1762
1606 return ret; 1763 return ret;
1607} 1764}
1608 1765
1609#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__) 1766#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1610 1767
1611static int load_ld_cache_config(int i, const char *fname) 1768static int _load_ld_cache_config(const char *fname)
1612{ 1769{
1613 FILE *fp = NULL; 1770 FILE *fp = NULL;
1614 char *p; 1771 char *p, *path;
1615 char path[__PAX_UTILS_PATH_MAX]; 1772 size_t len;
1616 char _fname[__PAX_UTILS_PATH_MAX]; 1773 int curr_fd = -1;
1617 1774
1618 fname = maybe_add_root(fname, _fname); 1775 fp = fopenat_r(root_fd, root_rel_path(fname));
1619 1776 if (fp == NULL)
1620 if ((fp = fopen(fname, "r")) == NULL)
1621 return i; 1777 return -1;
1622 1778
1623 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) { 1779 path = NULL;
1780 len = 0;
1781 while (getline(&path, &len, fp) != -1) {
1624 if ((p = strrchr(path, '\r')) != NULL) 1782 if ((p = strrchr(path, '\r')) != NULL)
1625 *p = 0; 1783 *p = 0;
1626 if ((p = strchr(path, '\n')) != NULL) 1784 if ((p = strchr(path, '\n')) != NULL)
1627 *p = 0; 1785 *p = 0;
1628 1786
1629 /* recursive includes of the same file will make this segfault. */ 1787 /* recursive includes of the same file will make this segfault. */
1630 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) { 1788 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1631 glob_t gl; 1789 glob_t gl;
1632 size_t x; 1790 size_t x;
1633 char gpath[__PAX_UTILS_PATH_MAX]; 1791 const char *gpath;
1634 1792
1635 memset(gpath, 0, sizeof(gpath)); 1793 /* re-use existing path buffer ... need to be creative */
1636 if (root)
1637 strcpy(gpath, root);
1638
1639 if (path[8] != '/') 1794 if (path[8] != '/')
1640 snprintf(gpath+strlen(gpath), sizeof(gpath)-strlen(gpath), "/etc/%s", &path[8]); 1795 gpath = memcpy(path + 3, "/etc/", 5);
1641 else 1796 else
1642 strncpy(gpath+strlen(gpath), &path[8], sizeof(gpath)-strlen(gpath)); 1797 gpath = path + 8;
1798 if (root_fd != AT_FDCWD) {
1799 if (curr_fd == -1) {
1800 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1801 if (fchdir(root_fd))
1802 errp("unable to change to root dir");
1803 }
1804 gpath = root_rel_path(gpath);
1805 }
1643 1806
1644 if (glob(gpath, 0, NULL, &gl) == 0) { 1807 if (glob(gpath, 0, NULL, &gl) == 0) {
1645 for (x = 0; x < gl.gl_pathc; ++x) { 1808 for (x = 0; x < gl.gl_pathc; ++x) {
1646 /* try to avoid direct loops */ 1809 /* try to avoid direct loops */
1647 if (strcmp(gl.gl_pathv[x], fname) == 0) 1810 if (strcmp(gl.gl_pathv[x], fname) == 0)
1648 continue; 1811 continue;
1649 i = load_ld_cache_config(i, gl.gl_pathv[x]); 1812 _load_ld_cache_config(gl.gl_pathv[x]);
1650 } 1813 }
1651 globfree(&gl); 1814 globfree(&gl);
1652 continue;
1653 } 1815 }
1816
1817 /* failed globs are ignored by glibc */
1818 continue;
1654 } 1819 }
1655 1820
1656 if (*path != '/') 1821 if (*path != '/')
1657 continue; 1822 continue;
1658 1823
1659 xarraypush(ldpaths, path, strlen(path)); 1824 xarraypush_str(ldpaths, path);
1660 } 1825 }
1826 free(path);
1661 1827
1662 fclose(fp); 1828 fclose(fp);
1829
1830 if (curr_fd != -1) {
1831 if (fchdir(curr_fd))
1832 /* don't care */;
1833 close(curr_fd);
1834 }
1835
1663 return i; 1836 return 0;
1664} 1837}
1665 1838
1666#elif defined(__FreeBSD__) || defined(__DragonFly__) 1839#elif defined(__FreeBSD__) || defined(__DragonFly__)
1667 1840
1668static int load_ld_cache_config(int i, const char *fname) 1841static int _load_ld_cache_config(const char *fname)
1669{ 1842{
1670 FILE *fp = NULL; 1843 FILE *fp = NULL;
1671 char *b = NULL, *p; 1844 char *b = NULL, *p;
1672 struct elfhints_hdr hdr; 1845 struct elfhints_hdr hdr;
1673 char _fname[__PAX_UTILS_PATH_MAX];
1674 1846
1675 fname = maybe_add_root(fname, _fname); 1847 fp = fopenat_r(root_fd, root_rel_path(fname));
1676 1848 if (fp == NULL)
1677 if ((fp = fopen(fname, "r")) == NULL)
1678 return i; 1849 return -1;
1679 1850
1680 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) || 1851 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1681 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 || 1852 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1682 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1) 1853 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1683 { 1854 {
1684 fclose(fp); 1855 fclose(fp);
1685 return i; 1856 return -1;
1686 } 1857 }
1687 1858
1688 b = xmalloc(hdr.dirlistlen + 1); 1859 b = xmalloc(hdr.dirlistlen + 1);
1689 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) { 1860 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1690 fclose(fp); 1861 fclose(fp);
1691 free(b); 1862 free(b);
1692 return i; 1863 return -1;
1693 } 1864 }
1694 1865
1695 while ((p = strsep(&b, ":"))) { 1866 while ((p = strsep(&b, ":"))) {
1696 if (*p == '\0') 1867 if (*p == '\0')
1697 continue; 1868 continue;
1698 xarraypush(ldpaths, p, strlen(p)); 1869 xarraypush_str(ldpaths, p);
1699 } 1870 }
1700 1871
1701 free(b); 1872 free(b);
1702 fclose(fp); 1873 fclose(fp);
1703 return i; 1874 return 0;
1704} 1875}
1705 1876
1706#else 1877#else
1707#ifdef __ELF__ 1878#ifdef __ELF__
1708#warning Cache config support not implemented for your target 1879#warning Cache config support not implemented for your target
1709#endif 1880#endif
1710static int load_ld_cache_config(int i, const char *fname) 1881static int _load_ld_cache_config(const char *fname)
1711{ 1882{
1712 return 0; 1883 return 0;
1713} 1884}
1714#endif 1885#endif
1886
1887static void load_ld_cache_config(const char *fname)
1888{
1889 bool scan_l, scan_ul, scan_ull;
1890 size_t n;
1891 const char *ldpath;
1892
1893 _load_ld_cache_config(fname);
1894
1895 scan_l = scan_ul = scan_ull = false;
1896 if (array_cnt(ldpaths)) {
1897 array_for_each(ldpaths, n, ldpath) {
1898 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1899 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1900 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1901 }
1902 }
1903
1904 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1905 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1906 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1907}
1715 1908
1716/* scan /etc/ld.so.conf for paths */ 1909/* scan /etc/ld.so.conf for paths */
1717static void scanelf_ldpath(void) 1910static void scanelf_ldpath(void)
1718{ 1911{
1719 char scan_l, scan_ul, scan_ull;
1720 size_t n; 1912 size_t n;
1721 const char *ldpath; 1913 const char *ldpath;
1722 int i = 0;
1723 1914
1724 if (array_cnt(ldpaths) == 0)
1725 err("Unable to load any paths from ld.so.conf");
1726
1727 scan_l = scan_ul = scan_ull = 0;
1728
1729 array_for_each(ldpaths, n, ldpath) { 1915 array_for_each(ldpaths, n, ldpath)
1730 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = 1;
1731 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = 1;
1732 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = 1;
1733 scanelf_dir(ldpath); 1916 scanelf_dir(ldpath);
1734 ++i;
1735 }
1736
1737 if (!scan_l) scanelf_dir("/lib");
1738 if (!scan_ul) scanelf_dir("/usr/lib");
1739 if (!scan_ull) scanelf_dir("/usr/local/lib");
1740} 1917}
1741 1918
1742/* scan env PATH for paths */ 1919/* scan env PATH for paths */
1743static void scanelf_envpath(void) 1920static void scanelf_envpath(void)
1744{ 1921{
1761#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV" 1938#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1762#define a_argument required_argument 1939#define a_argument required_argument
1763static struct option const long_opts[] = { 1940static struct option const long_opts[] = {
1764 {"path", no_argument, NULL, 'p'}, 1941 {"path", no_argument, NULL, 'p'},
1765 {"ldpath", no_argument, NULL, 'l'}, 1942 {"ldpath", no_argument, NULL, 'l'},
1943 {"use-ldpath",no_argument, NULL, 129},
1766 {"root", a_argument, NULL, 128}, 1944 {"root", a_argument, NULL, 128},
1767 {"recursive", no_argument, NULL, 'R'}, 1945 {"recursive", no_argument, NULL, 'R'},
1768 {"mount", no_argument, NULL, 'm'}, 1946 {"mount", no_argument, NULL, 'm'},
1769 {"symlink", no_argument, NULL, 'y'}, 1947 {"symlink", no_argument, NULL, 'y'},
1770 {"archives", no_argument, NULL, 'A'}, 1948 {"archives", no_argument, NULL, 'A'},
1805}; 1983};
1806 1984
1807static const char * const opts_help[] = { 1985static const char * const opts_help[] = {
1808 "Scan all directories in PATH environment", 1986 "Scan all directories in PATH environment",
1809 "Scan all directories in /etc/ld.so.conf", 1987 "Scan all directories in /etc/ld.so.conf",
1988 "Use ld.so.conf to show full path (use with -r/-n)",
1810 "Root directory (use with -l or -p)", 1989 "Root directory (use with -l or -p)",
1811 "Scan directories recursively", 1990 "Scan directories recursively",
1812 "Don't recursively cross mount points", 1991 "Don't recursively cross mount points",
1813 "Don't scan symlinks", 1992 "Don't scan symlinks",
1814 "Scan archives (.a files)", 1993 "Scan archives (.a files)",
1815 "Utilize ld.so.cache information (use with -r/-n)", 1994 "Utilize ld.so.cache to show full path (use with -r/-n)",
1816 "Try and 'fix' bad things (use with -r/-e)", 1995 "Try and 'fix' bad things (use with -r/-e)",
1817 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n", 1996 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1818 "Print PaX markings", 1997 "Print PaX markings",
1819 "Print GNU_STACK/PT_LOAD markings", 1998 "Print GNU_STACK/PT_LOAD markings",
1820 "Print TEXTREL information", 1999 "Print TEXTREL information",
1824 "Print BIND information", 2003 "Print BIND information",
1825 "Print SONAME information", 2004 "Print SONAME information",
1826 "Find a specified symbol", 2005 "Find a specified symbol",
1827 "Find a specified section", 2006 "Find a specified section",
1828 "Find a specified library", 2007 "Find a specified library",
1829 "Use regex matching rather than string compare (use with -s)", 2008 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1830 "Locate cause of TEXTREL", 2009 "Locate cause of TEXTREL",
1831 "Print only ELF files matching etype ET_DYN,ET_EXEC ...", 2010 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1832 "Print only ELF files matching numeric bits", 2011 "Print only ELF files matching numeric bits",
1833 "Print Endianness", 2012 "Print Endianness",
1834 "Print OSABI", 2013 "Print OSABI",
1853{ 2032{
1854 unsigned long i; 2033 unsigned long i;
1855 printf("* Scan ELF binaries for stuff\n\n" 2034 printf("* Scan ELF binaries for stuff\n\n"
1856 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0); 2035 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1857 printf("Options: -[%s]\n", PARSE_FLAGS); 2036 printf("Options: -[%s]\n", PARSE_FLAGS);
1858 for (i = 0; long_opts[i].name; ++i) 2037 for (i = 0; long_opts[i].name; ++i) {
2038 /* first output the short flag if it has one */
2039 if (long_opts[i].val > '~')
2040 printf(" ");
2041 else
2042 printf(" -%c, ", long_opts[i].val);
2043
2044 /* then the long flag */
1859 if (long_opts[i].has_arg == no_argument) 2045 if (long_opts[i].has_arg == no_argument)
1860 printf(" -%c, --%-14s* %s\n", long_opts[i].val, 2046 printf("--%-14s", long_opts[i].name);
1861 long_opts[i].name, opts_help[i]);
1862 else if (long_opts[i].val > '~')
1863 printf(" --%-7s <arg> * %s\n",
1864 long_opts[i].name, opts_help[i]);
1865 else 2047 else
1866 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val, 2048 printf("--%-7s <arg> ", long_opts[i].name);
1867 long_opts[i].name, opts_help[i]); 2049
2050 /* finally the help text */
2051 printf("* %s\n", opts_help[i]);
2052 }
1868 2053
1869 puts("\nFor more information, see the scanelf(1) manpage"); 2054 puts("\nFor more information, see the scanelf(1) manpage");
1870 exit(status); 2055 exit(status);
1871} 2056}
1872 2057
1882static int parseargs(int argc, char *argv[]) 2067static int parseargs(int argc, char *argv[])
1883{ 2068{
1884 int i; 2069 int i;
1885 const char *from_file = NULL; 2070 const char *from_file = NULL;
1886 int ret = 0; 2071 int ret = 0;
2072 char load_cache_config = 0;
1887 2073
1888 opterr = 0; 2074 opterr = 0;
1889 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2075 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1890 switch (i) { 2076 switch (i) {
1891 2077
1916 if (sscanf(optarg, "%o", &match_perms) == -1) 2102 if (sscanf(optarg, "%o", &match_perms) == -1)
1917 match_bits = 0; 2103 match_bits = 0;
1918 break; 2104 break;
1919 case 'o': { 2105 case 'o': {
1920 if (freopen(optarg, "w", stdout) == NULL) 2106 if (freopen(optarg, "w", stdout) == NULL)
1921 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2107 errp("Could not freopen(%s)", optarg);
1922 break; 2108 break;
1923 } 2109 }
1924 case 'k': 2110 case 'k':
1925 xarraypush(find_section_arr, optarg, strlen(optarg)); 2111 xarraypush_str(find_section_arr, optarg);
1926 break; 2112 break;
1927 case 's': { 2113 case 's': {
1928 if (find_sym) warn("You prob don't want to specify -s twice"); 2114 /* historically, this was comma delimited */
1929 find_sym = optarg; 2115 char *this_sym = strtok(optarg, ",");
2116 if (!this_sym) /* edge case: -s '' */
2117 xarraypush_str(find_sym_arr, "");
2118 while (this_sym) {
2119 xarraypush_str(find_sym_arr, this_sym);
2120 this_sym = strtok(NULL, ",");
2121 }
1930 break; 2122 break;
1931 } 2123 }
1932 case 'N': 2124 case 'N':
1933 xarraypush(find_lib_arr, optarg, strlen(optarg)); 2125 xarraypush_str(find_lib_arr, optarg);
1934 break; 2126 break;
1935 case 'F': { 2127 case 'F': {
1936 if (out_format) warn("You prob don't want to specify -F twice"); 2128 if (out_format) warn("You prob don't want to specify -F twice");
1937 out_format = optarg; 2129 out_format = optarg;
1938 break; 2130 break;
1979 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)))) 2171 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1980 setpax = flags; 2172 setpax = flags;
1981 break; 2173 break;
1982 } 2174 }
1983 case 'Z': show_size = 1; break; 2175 case 'Z': show_size = 1; break;
1984 case 'g': g_match = 1; break; 2176 case 'g': ++g_match; break;
1985 case 'L': use_ldcache = 1; break; 2177 case 'L': load_cache_config = use_ldcache = 1; break;
1986 case 'y': scan_symlink = 0; break; 2178 case 'y': scan_symlink = 0; break;
1987 case 'A': scan_archives = 1; break; 2179 case 'A': scan_archives = 1; break;
1988 case 'C': color_init(true); break; 2180 case 'C': color_init(true); break;
1989 case 'B': show_banner = 0; break; 2181 case 'B': show_banner = 0; break;
1990 case 'l': scan_ldpath = 1; break; 2182 case 'l': load_cache_config = scan_ldpath = 1; break;
1991 case 'p': scan_envpath = 1; break; 2183 case 'p': scan_envpath = 1; break;
1992 case 'R': dir_recurse = 1; break; 2184 case 'R': dir_recurse = 1; break;
1993 case 'm': dir_crossmount = 0; break; 2185 case 'm': dir_crossmount = 0; break;
1994 case 'X': ++fix_elf; break; 2186 case 'X': ++fix_elf; break;
1995 case 'x': show_pax = 1; break; 2187 case 'x': show_pax = 1; break;
2006 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break; 2198 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
2007 case 'D': show_endian = 1; break; 2199 case 'D': show_endian = 1; break;
2008 case 'I': show_osabi = 1; break; 2200 case 'I': show_osabi = 1; break;
2009 case 'Y': show_eabi = 1; break; 2201 case 'Y': show_eabi = 1; break;
2010 case 128: 2202 case 128:
2011 root = optarg; 2203 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2204 if (root_fd == -1)
2205 err("Could not open root: %s", optarg);
2012 break; 2206 break;
2207 case 129: load_cache_config = use_ldpath = 1; break;
2013 case ':': 2208 case ':':
2014 err("Option '%c' is missing parameter", optopt); 2209 err("Option '%c' is missing parameter", optopt);
2015 case '?': 2210 case '?':
2016 err("Unknown option '%c' or argument missing", optopt); 2211 err("Unknown option '%c' or argument missing", optopt);
2017 default: 2212 default:
2018 err("Unhandled option '%c'; please report this", i); 2213 err("Unhandled option '%c'; please report this", i);
2019 } 2214 }
2020 } 2215 }
2021 if (show_textrels && be_verbose) { 2216 if (show_textrels && be_verbose)
2022 if (which("objdump") != NULL) 2217 has_objdump = bin_in_path("objdump");
2023 has_objdump = 1; 2218 /* precompile all the regexes */
2219 if (g_match) {
2220 regex_t preg;
2221 const char *this_sym;
2222 size_t n;
2223 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2224
2225 array_for_each(find_sym_arr, n, this_sym) {
2226 /* see scanelf_match_symname for logic info */
2227 switch (this_sym[0]) {
2228 case '%':
2229 while (*(this_sym++))
2230 if (*this_sym == '%') {
2231 ++this_sym;
2232 break;
2233 }
2234 break;
2235 case '+':
2236 case '-':
2237 ++this_sym;
2238 break;
2239 }
2240 if (*this_sym == '*')
2241 ++this_sym;
2242
2243 ret = regcomp(&preg, this_sym, flags);
2244 if (ret) {
2245 char err[256];
2246 regerror(ret, &preg, err, sizeof(err));
2247 err("regcomp of %s failed: %s", this_sym, err);
2248 }
2249 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2250 }
2024 } 2251 }
2025 /* flatten arrays for display */ 2252 /* flatten arrays for display */
2253 if (array_cnt(find_sym_arr))
2254 find_sym = array_flatten_str(find_sym_arr);
2026 if (array_cnt(find_lib_arr)) 2255 if (array_cnt(find_lib_arr))
2027 find_lib = array_flatten_str(find_lib_arr); 2256 find_lib = array_flatten_str(find_lib_arr);
2028 if (array_cnt(find_section_arr)) 2257 if (array_cnt(find_section_arr))
2029 find_section = array_flatten_str(find_section_arr); 2258 find_section = array_flatten_str(find_section_arr);
2030 /* let the format option override all other options */ 2259 /* let the format option override all other options */
2062 case 'i': show_interp = 1; break; 2291 case 'i': show_interp = 1; break;
2063 case 'b': show_bind = 1; break; 2292 case 'b': show_bind = 1; break;
2064 case 'S': show_soname = 1; break; 2293 case 'S': show_soname = 1; break;
2065 case 'T': show_textrels = 1; break; 2294 case 'T': show_textrels = 1; break;
2066 default: 2295 default:
2067 err("Invalid format specifier '%c' (byte %i)", 2296 err("invalid format specifier '%c' (byte %i)",
2068 out_format[i], i+1); 2297 out_format[i], i+1);
2069 } 2298 }
2070 } 2299 }
2071 2300
2072 /* construct our default format */ 2301 /* construct our default format */
2095 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2324 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
2096 } 2325 }
2097 if (be_verbose > 2) printf("Format: %s\n", out_format); 2326 if (be_verbose > 2) printf("Format: %s\n", out_format);
2098 2327
2099 /* now lets actually do the scanning */ 2328 /* now lets actually do the scanning */
2100 if (scan_ldpath || use_ldcache) 2329 if (load_cache_config)
2101 load_ld_cache_config(0, __PAX_UTILS_DEFAULT_LD_CACHE_CONFIG); 2330 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
2102 if (scan_ldpath) scanelf_ldpath(); 2331 if (scan_ldpath) scanelf_ldpath();
2103 if (scan_envpath) scanelf_envpath(); 2332 if (scan_envpath) scanelf_envpath();
2104 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath) 2333 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2105 from_file = "-"; 2334 from_file = "-";
2106 if (from_file) { 2335 if (from_file) {
2112 while (optind < argc) { 2341 while (optind < argc) {
2113 search_path = argv[optind++]; 2342 search_path = argv[optind++];
2114 ret = scanelf_dir(search_path); 2343 ret = scanelf_dir(search_path);
2115 } 2344 }
2116 2345
2346#ifdef __PAX_UTILS_CLEANUP
2117 /* clean up */ 2347 /* clean up */
2118 xarrayfree(ldpaths); 2348 xarrayfree(ldpaths);
2349 xarrayfree(find_sym_arr);
2119 xarrayfree(find_lib_arr); 2350 xarrayfree(find_lib_arr);
2120 xarrayfree(find_section_arr); 2351 xarrayfree(find_section_arr);
2352 free(find_sym);
2121 free(find_lib); 2353 free(find_lib);
2122 free(find_section); 2354 free(find_section);
2355 {
2356 size_t n;
2357 regex_t *preg;
2358 array_for_each(find_sym_regex_arr, n, preg)
2359 regfree(preg);
2360 xarrayfree(find_sym_regex_arr);
2361 }
2123 2362
2124 if (ldcache != 0) 2363 if (ldcache != 0)
2125 munmap(ldcache, ldcache_size); 2364 munmap(ldcache, ldcache_size);
2365#endif
2366
2126 return ret; 2367 return ret;
2127} 2368}
2128 2369
2129static char **get_split_env(const char *envvar) 2370static char **get_split_env(const char *envvar)
2130{ 2371{
2187 ret = parseargs(argc, argv); 2428 ret = parseargs(argc, argv);
2188 fclose(stdout); 2429 fclose(stdout);
2189#ifdef __PAX_UTILS_CLEANUP 2430#ifdef __PAX_UTILS_CLEANUP
2190 cleanup(); 2431 cleanup();
2191 warn("The calls to add/delete heap should be off:\n" 2432 warn("The calls to add/delete heap should be off:\n"
2192 "\t- 1 due to the out_buffer not being freed in scanelf_file()\n" 2433 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2193 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD"); 2434 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
2194#endif 2435#endif
2195 return ret; 2436 return ret;
2196} 2437}
2197 2438

Legend:
Removed from v.1.229  
changed lines
  Added in v.1.251

  ViewVC Help
Powered by ViewVC 1.1.20