/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.63 Revision 1.229
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2007 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.63 2005/05/29 18:44:48 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.229 2011/09/27 19:29:19 vapier Exp $
5 * 5 *
6 ******************************************************************** 6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
7 * This program is free software; you can redistribute it and/or 7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
8 * modify it under the terms of the GNU General Public License as
9 * published by the Free Software Foundation; either version 2 of the
10 * License, or (at your option) any later version.
11 *
12 * This program is distributed in the hope that it will be useful, but
13 * WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * General Public License for more details.
16 *
17 * You should have received a copy of the GNU General Public License
18 * along with this program; if not, write to the Free Software
19 * Foundation, Inc., 59 Temple Place - Suite 330, Boston,
20 * MA 02111-1307, USA.
21 */ 8 */
22 9
23#include <stdio.h> 10static const char *rcsid = "$Id: scanelf.c,v 1.229 2011/09/27 19:29:19 vapier Exp $";
24#include <stdlib.h> 11const char argv0[] = "scanelf";
25#include <sys/types.h> 12
26#include <libgen.h>
27#include <limits.h>
28#define __USE_GNU
29#include <string.h>
30#include <errno.h>
31#include <unistd.h>
32#include <sys/stat.h>
33#include <dirent.h>
34#include <getopt.h>
35#include <assert.h>
36#include "paxelf.h" 13#include "paxinc.h"
37 14
38static const char *rcsid = "$Id: scanelf.c,v 1.63 2005/05/29 18:44:48 solar Exp $"; 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
39#define argv0 "scanelf"
40
41
42 16
43/* prototypes */ 17/* prototypes */
44static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
45static void scanelf_dir(const char *path);
46static void scanelf_ldpath();
47static void scanelf_envpath();
48static void usage(int status);
49static void parseargs(int argc, char *argv[]);
50static char *xstrdup(const char *s);
51static void *xmalloc(size_t size);
52static void xstrcat(char **dst, const char *src, size_t *curr_len);
53static inline void xchrcat(char **dst, const char append, size_t *curr_len);
54 19
55/* variables to control behavior */ 20/* variables to control behavior */
56static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
57static char scan_ldpath = 0; 23static char scan_ldpath = 0;
58static char scan_envpath = 0; 24static char scan_envpath = 0;
59static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
60static char dir_recurse = 0; 27static char dir_recurse = 0;
61static char dir_crossmount = 1; 28static char dir_crossmount = 1;
62static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
63static char show_stack = 0; 31static char show_size = 0;
32static char show_phdr = 0;
64static char show_textrel = 0; 33static char show_textrel = 0;
65static char show_rpath = 0; 34static char show_rpath = 0;
66static char show_needed = 0; 35static char show_needed = 0;
67static char show_interp = 0; 36static char show_interp = 0;
68static char show_bind = 0; 37static char show_bind = 0;
38static char show_soname = 0;
39static char show_textrels = 0;
69static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
70static char be_quiet = 0; 44static char be_quiet = 0;
71static char be_verbose = 0; 45static char be_verbose = 0;
72static char *find_sym = NULL, *versioned_symname = NULL; 46static char be_wewy_wewy_quiet = 0;
47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
73static char *out_format = NULL; 53static char *out_format = NULL;
54static char *search_path = NULL;
55static char fix_elf = 0;
56static char g_match = 0;
57static char use_ldcache = 0;
74 58
59static char **qa_textrels = NULL;
60static char **qa_execstack = NULL;
61static char **qa_wx_load = NULL;
62static char *root;
63
64static int match_bits = 0;
65static unsigned int match_perms = 0;
66static void *ldcache = NULL;
67static size_t ldcache_size = 0;
68static unsigned long setpax = 0UL;
69
70static int has_objdump = 0;
71
72/* find the path to a file by name */
73static char *which(const char *fname)
74{
75 static char fullpath[__PAX_UTILS_PATH_MAX];
76 char *path, *p;
77
78 path = getenv("PATH");
79 if (!path)
80 return NULL;
81
82 path = xstrdup(path);
83 while ((p = strrchr(path, ':')) != NULL) {
84 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
85 *p = 0;
86 if (access(fullpath, R_OK) != -1) {
87 free(path);
88 return fullpath;
89 }
90 }
91 free(path);
92 return NULL;
93}
94
95/* 1 on failure. 0 otherwise */
96static int rematch(const char *regex, const char *match, int cflags)
97{
98 regex_t preg;
99 int ret;
100
101 if ((match == NULL) || (regex == NULL))
102 return EXIT_FAILURE;
103
104 if ((ret = regcomp(&preg, regex, cflags))) {
105 char err[256];
106
107 if (regerror(ret, &preg, err, sizeof(err)))
108 fprintf(stderr, "regcomp failed: %s", err);
109 else
110 fprintf(stderr, "regcomp failed");
111
112 return EXIT_FAILURE;
113 }
114 ret = regexec(&preg, match, 0, NULL, 0);
115 regfree(&preg);
116
117 return ret;
118}
75 119
76/* sub-funcs for scanelf_file() */ 120/* sub-funcs for scanelf_file() */
121static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab)
122{
123 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
124
125 /* debug sections */
126 void *symtab = elf_findsecbyname(elf, ".symtab");
127 void *strtab = elf_findsecbyname(elf, ".strtab");
128 /* runtime sections */
129 void *dynsym = elf_findsecbyname(elf, ".dynsym");
130 void *dynstr = elf_findsecbyname(elf, ".dynstr");
131
132#define GET_SYMTABS(B) \
133 if (elf->elf_class == ELFCLASS ## B) { \
134 if (symtab && dynsym) { \
135 Elf ## B ## _Shdr *esymtab = symtab; \
136 Elf ## B ## _Shdr *edynsym = dynsym; \
137 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
138 } else \
139 *sym = symtab ? symtab : dynsym; \
140 if (strtab && dynstr) { \
141 Elf ## B ## _Shdr *estrtab = strtab; \
142 Elf ## B ## _Shdr *edynstr = dynstr; \
143 *tab = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
144 } else \
145 *tab = strtab ? strtab : dynstr; \
146 }
147 GET_SYMTABS(32)
148 GET_SYMTABS(64)
149}
150
77static char *scanelf_file_pax(elfobj *elf, char *found_pax) 151static char *scanelf_file_pax(elfobj *elf, char *found_pax)
78{ 152{
79 static char *paxflags;
80 static char ret[7]; 153 static char ret[7];
81 unsigned long i, shown; 154 unsigned long i, shown;
82
83 155
84 if (!show_pax) return NULL; 156 if (!show_pax) return NULL;
85 157
86 shown = 0; 158 shown = 0;
87 memset(&ret, 0, sizeof(ret)); 159 memset(&ret, 0, sizeof(ret));
92 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 164 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
93 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 165 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
94 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 166 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
95 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 167 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
96 continue; \ 168 continue; \
97 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 169 if (fix_elf && setpax) { \
170 /* set the paxctl flags */ \
171 ESET(phdr[i].p_flags, setpax); \
172 } \
173 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
98 continue; \ 174 continue; \
99 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 175 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
100 *found_pax = 1; \ 176 *found_pax = 1; \
101 ++shown; \ 177 ++shown; \
102 break; \ 178 break; \
104 } 180 }
105 SHOW_PAX(32) 181 SHOW_PAX(32)
106 SHOW_PAX(64) 182 SHOW_PAX(64)
107 } 183 }
108 184
185 if (fix_elf && setpax) {
186 /* set the chpax settings */
187 if (elf->elf_class == ELFCLASS32) {
188 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
189 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
190 } else {
191 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
192 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
193 }
194 }
195
109 /* fall back to EI_PAX if no PT_PAX was found */ 196 /* fall back to EI_PAX if no PT_PAX was found */
110 if (!*ret) { 197 if (!*ret) {
198 static char *paxflags;
111 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 199 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
112 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) { 200 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
113 *found_pax = 1; 201 *found_pax = 1;
114 return paxflags; 202 return (be_wewy_wewy_quiet ? NULL : paxflags);
115 } 203 }
116 strncpy(ret, paxflags, sizeof(ret)); 204 strncpy(ret, paxflags, sizeof(ret));
117 // ++shown;
118 } 205 }
119 206
120 if (be_quiet && !shown) 207 if (be_wewy_wewy_quiet || (be_quiet && !shown))
121 return NULL;
122 return ret;
123
124}
125static char *scanelf_file_stack(elfobj *elf, char *found_stack, char *found_relro)
126{
127 static char ret[8] = "--- ---";
128 char *found;
129 unsigned long i, off, shown;
130
131 if (!show_stack) return NULL;
132
133 shown = 0;
134
135 if (elf->phdr) {
136#define SHOW_STACK(B) \
137 if (elf->elf_class == ELFCLASS ## B) { \
138 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
139 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
140 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
141 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
142 found = found_stack; \
143 off = 0; \
144 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
145 found = found_relro; \
146 off = 4; \
147 } else \
148 continue; \
149 if (be_quiet && !(EGET(phdr[i].p_flags) & PF_X)) \
150 continue; \
151 memcpy(ret+off, gnu_short_stack_flags(EGET(phdr[i].p_flags)), 3); \
152 *found = 1; \
153 ++shown; \
154 } \
155 }
156 SHOW_STACK(32)
157 SHOW_STACK(64)
158 }
159
160 if (be_quiet && !shown)
161 return NULL; 208 return NULL;
162 else 209 else
163 return ret; 210 return ret;
164} 211}
212
213static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
214{
215 static char ret[12];
216 char *found;
217 unsigned long i, shown, multi_stack, multi_relro, multi_load;
218 int max_pt_load;
219
220 if (!show_phdr) return NULL;
221
222 memcpy(ret, "--- --- ---\0", 12);
223
224 shown = 0;
225 multi_stack = multi_relro = multi_load = 0;
226 max_pt_load = elf_max_pt_load(elf);
227
228#define NOTE_GNU_STACK ".note.GNU-stack"
229#define SHOW_PHDR(B) \
230 if (elf->elf_class == ELFCLASS ## B) { \
231 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
232 Elf ## B ## _Off offset; \
233 uint32_t flags, check_flags; \
234 if (elf->phdr != NULL) { \
235 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
236 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
237 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
238 if (multi_stack++) \
239 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
240 if (file_matches_list(elf->filename, qa_execstack)) \
241 continue; \
242 found = found_phdr; \
243 offset = 0; \
244 check_flags = PF_X; \
245 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
246 if (multi_relro++) \
247 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
248 found = found_relro; \
249 offset = 4; \
250 check_flags = PF_X; \
251 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
252 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
253 if (multi_load++ > max_pt_load) \
254 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
255 if (file_matches_list(elf->filename, qa_wx_load)) \
256 continue; \
257 found = found_load; \
258 offset = 8; \
259 check_flags = PF_W|PF_X; \
260 } else \
261 continue; \
262 flags = EGET(phdr[i].p_flags); \
263 if (be_quiet && ((flags & check_flags) != check_flags)) \
264 continue; \
265 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
266 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
267 ret[3] = ret[7] = '!'; \
268 flags = EGET(phdr[i].p_flags); \
269 } \
270 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
271 *found = 1; \
272 ++shown; \
273 } \
274 } else if (elf->shdr != NULL) { \
275 /* no program headers which means this is prob an object file */ \
276 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
277 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
278 char *str; \
279 if ((void*)strtbl > elf->data_end) \
280 goto skip_this_shdr##B; \
281 check_flags = SHF_WRITE|SHF_EXECINSTR; \
282 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
283 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
284 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
285 str = elf->data + offset; \
286 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
287 if (!strcmp(str, NOTE_GNU_STACK)) { \
288 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
289 flags = EGET(shdr[i].sh_flags); \
290 if (be_quiet && ((flags & check_flags) != check_flags)) \
291 continue; \
292 ++*found_phdr; \
293 shown = 1; \
294 if (flags & SHF_WRITE) ret[0] = 'W'; \
295 if (flags & SHF_ALLOC) ret[1] = 'A'; \
296 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
297 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
298 break; \
299 } \
300 } \
301 skip_this_shdr##B: \
302 if (!multi_stack) { \
303 if (file_matches_list(elf->filename, qa_execstack)) \
304 return NULL; \
305 *found_phdr = 1; \
306 shown = 1; \
307 memcpy(ret, "!WX", 3); \
308 } \
309 } \
310 }
311 SHOW_PHDR(32)
312 SHOW_PHDR(64)
313
314 if (be_wewy_wewy_quiet || (be_quiet && !shown))
315 return NULL;
316 else
317 return ret;
318}
319
320/*
321 * See if this ELF contains a DT_TEXTREL tag in any of its
322 * PT_DYNAMIC sections.
323 */
165static char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 324static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
166{ 325{
167 static char *ret = "TEXTREL"; 326 static const char *ret = "TEXTREL";
168 unsigned long i; 327 unsigned long i;
169 328
170 if (!show_textrel) return NULL; 329 if (!show_textrel && !show_textrels) return NULL;
330
331 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
171 332
172 if (elf->phdr) { 333 if (elf->phdr) {
173#define SHOW_TEXTREL(B) \ 334#define SHOW_TEXTREL(B) \
174 if (elf->elf_class == ELFCLASS ## B) { \ 335 if (elf->elf_class == ELFCLASS ## B) { \
175 Elf ## B ## _Dyn *dyn; \ 336 Elf ## B ## _Dyn *dyn; \
176 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 337 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
177 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 338 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
178 Elf ## B ## _Off offset; \ 339 Elf ## B ## _Off offset; \
179 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
180 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 341 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
181 offset = EGET(phdr[i].p_offset); \ 342 offset = EGET(phdr[i].p_offset); \
182 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 343 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
183 dyn = DYN ## B (elf->data + offset); \ 344 dyn = DYN ## B (elf->vdata + offset); \
184 while (EGET(dyn->d_tag) != DT_NULL) { \ 345 while (EGET(dyn->d_tag) != DT_NULL) { \
185 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 346 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
186 *found_textrel = 1; \ 347 *found_textrel = 1; \
187 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 348 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
188 return ret; \ 349 return (be_wewy_wewy_quiet ? NULL : ret); \
189 } \ 350 } \
190 ++dyn; \ 351 ++dyn; \
191 } \ 352 } \
192 } } 353 } }
193 SHOW_TEXTREL(32) 354 SHOW_TEXTREL(32)
194 SHOW_TEXTREL(64) 355 SHOW_TEXTREL(64)
195 } 356 }
196 357
197 if (be_quiet) 358 if (be_quiet || be_wewy_wewy_quiet)
198 return NULL; 359 return NULL;
199 else 360 else
200 return " - "; 361 return " - ";
201} 362}
363
364/*
365 * Scan the .text section to see if there are any relocations in it.
366 * Should rewrite this to check PT_LOAD sections that are marked
367 * Executable rather than the section named '.text'.
368 */
369static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
370{
371 unsigned long s, r, rmax;
372 void *symtab_void, *strtab_void, *text_void;
373
374 if (!show_textrels) return NULL;
375
376 /* don't search for TEXTREL's if the ELF doesn't have any */
377 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
378 if (!*found_textrel) return NULL;
379
380 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
381 text_void = elf_findsecbyname(elf, ".text");
382
383 if (symtab_void && strtab_void && text_void && elf->shdr) {
384#define SHOW_TEXTRELS(B) \
385 if (elf->elf_class == ELFCLASS ## B) { \
386 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
387 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
388 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
389 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
390 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
391 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
392 uint ## B ## _t memsz = EGET(text->sh_size); \
393 Elf ## B ## _Rel *rel; \
394 Elf ## B ## _Rela *rela; \
395 /* search the section headers for relocations */ \
396 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
397 uint32_t sh_type = EGET(shdr[s].sh_type); \
398 if (sh_type == SHT_REL) { \
399 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
400 rela = NULL; \
401 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
402 } else if (sh_type == SHT_RELA) { \
403 rel = NULL; \
404 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
405 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
406 } else \
407 continue; \
408 /* now see if any of the relocs are in the .text */ \
409 for (r = 0; r < rmax; ++r) { \
410 unsigned long sym_max; \
411 Elf ## B ## _Addr offset_tmp; \
412 Elf ## B ## _Sym *func; \
413 Elf ## B ## _Sym *sym; \
414 Elf ## B ## _Addr r_offset; \
415 uint ## B ## _t r_info; \
416 if (sh_type == SHT_REL) { \
417 r_offset = EGET(rel[r].r_offset); \
418 r_info = EGET(rel[r].r_info); \
419 } else { \
420 r_offset = EGET(rela[r].r_offset); \
421 r_info = EGET(rela[r].r_info); \
422 } \
423 /* make sure this relocation is inside of the .text */ \
424 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
425 if (be_verbose <= 2) continue; \
426 } else \
427 *found_textrels = 1; \
428 /* locate this relocation symbol name */ \
429 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
430 if ((void*)sym > elf->data_end) { \
431 warn("%s: corrupt ELF symbol", elf->filename); \
432 continue; \
433 } \
434 sym_max = ELF ## B ## _R_SYM(r_info); \
435 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
436 sym += sym_max; \
437 else \
438 sym = NULL; \
439 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
440 /* show the raw details about this reloc */ \
441 printf(" %s: ", elf->base_filename); \
442 if (sym && sym->st_name) \
443 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
444 else \
445 printf("(memory/data?)"); \
446 printf(" [0x%lX]", (unsigned long)r_offset); \
447 /* now try to find the closest symbol that this rel is probably in */ \
448 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
449 func = NULL; \
450 offset_tmp = 0; \
451 while (sym_max--) { \
452 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
453 func = sym; \
454 offset_tmp = EGET(sym->st_value); \
455 } \
456 ++sym; \
457 } \
458 printf(" in "); \
459 if (func && func->st_name) { \
460 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
461 if (r_offset > EGET(func->st_size)) \
462 printf("(optimized out: previous %s)", func_name); \
463 else \
464 printf("%s", func_name); \
465 } else \
466 printf("(optimized out)"); \
467 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
468 if (be_verbose && has_objdump) { \
469 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
470 char *sysbuf; \
471 size_t syslen; \
472 int sysret; \
473 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
474 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
475 sysbuf = xmalloc(syslen); \
476 if (end_addr < r_offset) \
477 /* not uncommon when things are optimized out */ \
478 end_addr = r_offset + 0x100; \
479 snprintf(sysbuf, syslen, sysfmt, \
480 (unsigned long)offset_tmp, \
481 (unsigned long)end_addr, \
482 elf->filename, \
483 (unsigned long)r_offset); \
484 fflush(stdout); \
485 sysret = system(sysbuf); \
486 fflush(stdout); \
487 free(sysbuf); \
488 } \
489 } \
490 } }
491 SHOW_TEXTRELS(32)
492 SHOW_TEXTRELS(64)
493 }
494 if (!*found_textrels)
495 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
496
497 return NULL;
498}
499
500static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
501{
502 struct stat st;
503 switch (*item) {
504 case '/': break;
505 case '.':
506 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
507 break;
508 case ':':
509 case '\0':
510 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
511 break;
512 case '$':
513 if (fstat(elf->fd, &st) != -1)
514 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
515 warnf("Security problem with %s='%s' in %s with mode set of %o",
516 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
517 break;
518 default:
519 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
520 break;
521 }
522}
202static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 523static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
203{ 524{
204 /* TODO: when checking RPATH entries, check each subpath (between :) in ld.so.conf */
205 unsigned long i, s; 525 unsigned long i;
206 char *rpath, *runpath, **r; 526 char *rpath, *runpath, **r;
207 void *strtbl_void; 527 void *strtbl_void;
208 528
209 if (!show_rpath) return; 529 if (!show_rpath) return;
210 530
221 Elf ## B ## _Off offset; \ 541 Elf ## B ## _Off offset; \
222 Elf ## B ## _Xword word; \ 542 Elf ## B ## _Xword word; \
223 /* Scan all the program headers */ \ 543 /* Scan all the program headers */ \
224 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 544 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
225 /* Just scan dynamic headers */ \ 545 /* Just scan dynamic headers */ \
226 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 546 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
227 offset = EGET(phdr[i].p_offset); \ 547 offset = EGET(phdr[i].p_offset); \
228 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 548 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
229 /* Just scan dynamic RPATH/RUNPATH headers */ \ 549 /* Just scan dynamic RPATH/RUNPATH headers */ \
230 dyn = DYN ## B (elf->data + offset); \ 550 dyn = DYN ## B (elf->vdata + offset); \
231 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 551 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
232 if (word == DT_RPATH) { \ 552 if (word == DT_RPATH) { \
233 r = &rpath; \ 553 r = &rpath; \
234 } else if (word == DT_RUNPATH) { \ 554 } else if (word == DT_RUNPATH) { \
235 r = &runpath; \ 555 r = &runpath; \
237 ++dyn; \ 557 ++dyn; \
238 continue; \ 558 continue; \
239 } \ 559 } \
240 /* Verify the memory is somewhat sane */ \ 560 /* Verify the memory is somewhat sane */ \
241 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 561 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
242 if (offset < elf->len) { \ 562 if (offset < (Elf ## B ## _Off)elf->len) { \
243 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 563 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
244 *r = (char*)(elf->data + offset); \ 564 *r = elf->data + offset; \
565 /* cache the length in case we need to nuke this section later on */ \
566 if (fix_elf) \
567 offset = strlen(*r); \
245 /* If quiet, don't output paths in ld.so.conf */ \ 568 /* If quiet, don't output paths in ld.so.conf */ \
246 if (be_quiet) \ 569 if (be_quiet) { \
247 for (s = 0; ldpaths[s]; ++s) \ 570 size_t len; \
248 if (!strcmp(ldpaths[s], *r)) { \ 571 char *start, *end; \
572 /* note that we only 'chop' off leading known paths. */ \
573 /* since *r is read-only memory, we can only move the ptr forward. */ \
574 start = *r; \
575 /* scan each path in : delimited list */ \
576 while (start) { \
577 rpath_security_checks(elf, start, get_elfdtype(word)); \
578 end = strchr(start, ':'); \
579 len = (end ? abs(end - start) : strlen(start)); \
580 if (use_ldcache) { \
581 size_t n; \
582 const char *ldpath; \
583 array_for_each(ldpaths, n, ldpath) \
584 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
249 *r = NULL; \ 585 *r = end; \
586 /* corner case ... if RPATH reads "/usr/lib:", we want \
587 * to show ':' rather than '' */ \
588 if (end && end[1] != '\0') \
589 (*r)++; \
590 break; \
591 } \
592 } \
593 if (!*r || !end) \
250 break; \ 594 break; \
595 else \
596 start = start + len + 1; \
597 } \
598 } \
599 if (*r) { \
600 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
601 /* just nuke it */ \
602 nuke_it##B: \
603 memset(*r, 0x00, offset); \
604 *r = NULL; \
605 ESET(dyn->d_tag, DT_DEBUG); \
606 ESET(dyn->d_un.d_ptr, 0); \
607 } else if (fix_elf) { \
608 /* try to clean "bad" paths */ \
609 size_t len, tmpdir_len; \
610 char *start, *end; \
611 const char *tmpdir; \
612 start = *r; \
613 tmpdir = (getenv("TMPDIR") ? : "."); \
614 tmpdir_len = strlen(tmpdir); \
615 while (1) { \
616 end = strchr(start, ':'); \
617 if (start == end) { \
618 eat_this_path##B: \
619 len = strlen(end); \
620 memmove(start, end+1, len); \
621 start[len-1] = '\0'; \
622 end = start - 1; \
623 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
624 if (!end) { \
625 if (start == *r) \
626 goto nuke_it##B; \
627 *--start = '\0'; \
628 } else \
629 goto eat_this_path##B; \
630 } \
631 if (!end) \
632 break; \
633 start = end + 1; \
251 } \ 634 } \
635 if (**r == '\0') \
636 goto nuke_it##B; \
637 } \
638 if (*r) \
252 if (*r) *found_rpath = 1; \ 639 *found_rpath = 1; \
640 } \
253 } \ 641 } \
254 ++dyn; \ 642 ++dyn; \
255 } \ 643 } \
256 } } 644 } }
257 SHOW_RPATH(32) 645 SHOW_RPATH(32)
258 SHOW_RPATH(64) 646 SHOW_RPATH(64)
259 } 647 }
648
649 if (be_wewy_wewy_quiet) return;
260 650
261 if (rpath && runpath) { 651 if (rpath && runpath) {
262 if (!strcmp(rpath, runpath)) { 652 if (!strcmp(rpath, runpath)) {
263 xstrcat(ret, runpath, ret_len); 653 xstrcat(ret, runpath, ret_len);
264 } else { 654 } else {
272 } else if (rpath || runpath) 662 } else if (rpath || runpath)
273 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 663 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
274 else if (!be_quiet) 664 else if (!be_quiet)
275 xstrcat(ret, " - ", ret_len); 665 xstrcat(ret, " - ", ret_len);
276} 666}
667
668#define LDSO_CACHE_MAGIC "ld.so-"
669#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
670#define LDSO_CACHE_VER "1.7.0"
671#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
672#define FLAG_ANY -1
673#define FLAG_TYPE_MASK 0x00ff
674#define FLAG_LIBC4 0x0000
675#define FLAG_ELF 0x0001
676#define FLAG_ELF_LIBC5 0x0002
677#define FLAG_ELF_LIBC6 0x0003
678#define FLAG_REQUIRED_MASK 0xff00
679#define FLAG_SPARC_LIB64 0x0100
680#define FLAG_IA64_LIB64 0x0200
681#define FLAG_X8664_LIB64 0x0300
682#define FLAG_S390_LIB64 0x0400
683#define FLAG_POWERPC_LIB64 0x0500
684#define FLAG_MIPS64_LIBN32 0x0600
685#define FLAG_MIPS64_LIBN64 0x0700
686
687#if defined(__GLIBC__) || defined(__UCLIBC__)
688
689static char *lookup_cache_lib(elfobj *elf, char *fname)
690{
691 int fd;
692 char *strs;
693 static char buf[__PAX_UTILS_PATH_MAX] = "";
694 const char cachefile[] = "/etc/ld.so.cache";
695 struct stat st;
696
697 typedef struct {
698 char magic[LDSO_CACHE_MAGIC_LEN];
699 char version[LDSO_CACHE_VER_LEN];
700 int nlibs;
701 } header_t;
702 header_t *header;
703
704 typedef struct {
705 int flags;
706 int sooffset;
707 int liboffset;
708 } libentry_t;
709 libentry_t *libent;
710
711 if (fname == NULL)
712 return NULL;
713
714 if (ldcache == NULL) {
715 if (stat(cachefile, &st))
716 return NULL;
717
718 fd = open(cachefile, O_RDONLY);
719 if (fd == -1)
720 return NULL;
721
722 /* cache these values so we only map/unmap the cache file once */
723 ldcache_size = st.st_size;
724 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
725 close(fd);
726
727 if (ldcache == MAP_FAILED) {
728 ldcache = NULL;
729 return NULL;
730 }
731
732 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
733 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
734 {
735 munmap(ldcache, ldcache_size);
736 ldcache = NULL;
737 return NULL;
738 }
739 } else
740 header = ldcache;
741
742 libent = ldcache + sizeof(header_t);
743 strs = (char *) &libent[header->nlibs];
744
745 for (fd = 0; fd < header->nlibs; ++fd) {
746 /* This should be more fine grained, but for now we assume that
747 * diff arches will not be cached together, and we ignore the
748 * the different multilib mips cases.
749 */
750 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
751 continue;
752 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
753 continue;
754
755 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
756 continue;
757
758 /* Return first hit because that is how the ldso rolls */
759 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
760 break;
761 }
762
763 return buf;
764}
765
766#elif defined(__NetBSD__)
767static char *lookup_cache_lib(elfobj *elf, char *fname)
768{
769 static char buf[__PAX_UTILS_PATH_MAX] = "";
770 static struct stat st;
771 size_t n;
772 char *ldpath;
773
774 array_for_each(ldpath, n, ldpath) {
775 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
776 continue; /* if the pathname is too long, or something went wrong, ignore */
777
778 if (stat(buf, &st) != 0)
779 continue; /* if the lib doesn't exist in *ldpath, look further */
780
781 /* NetBSD doesn't actually do sanity checks, it just loads the file
782 * and if that doesn't work, continues looking in other directories.
783 * This cannot easily be safely emulated, unfortunately. For now,
784 * just assume that if it exists, it's a valid library. */
785
786 return buf;
787 }
788
789 /* not found in any path */
790 return NULL;
791}
792#else
793#ifdef __ELF__
794#warning Cache support not implemented for your target
795#endif
796static char *lookup_cache_lib(elfobj *elf, char *fname)
797{
798 return NULL;
799}
800#endif
801
277static void scanelf_file_needed(elfobj *elf, char *found_needed, char **ret, size_t *ret_len) 802static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
278{ 803{
279 unsigned long i; 804 unsigned long i;
280 char *needed; 805 char *needed;
281 void *strtbl_void; 806 void *strtbl_void;
807 char *p;
282 808
283 if (!show_needed) return; 809 /*
810 * -n -> op==0 -> print all
811 * -N -> op==1 -> print requested
812 */
813 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
814 return NULL;
284 815
285 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 816 strtbl_void = elf_findsecbyname(elf, ".dynstr");
286 817
287 if (elf->phdr && strtbl_void) { 818 if (elf->phdr && strtbl_void) {
288#define SHOW_NEEDED(B) \ 819#define SHOW_NEEDED(B) \
290 Elf ## B ## _Dyn *dyn; \ 821 Elf ## B ## _Dyn *dyn; \
291 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 822 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
292 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 823 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
293 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 824 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
294 Elf ## B ## _Off offset; \ 825 Elf ## B ## _Off offset; \
826 size_t matched = 0; \
827 /* Walk all the program headers to find the PT_DYNAMIC */ \
295 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 828 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
296 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 829 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
830 continue; \
297 offset = EGET(phdr[i].p_offset); \ 831 offset = EGET(phdr[i].p_offset); \
298 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 832 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
833 continue; \
834 /* Walk all the dynamic tags to find NEEDED entries */ \
299 dyn = DYN ## B (elf->data + offset); \ 835 dyn = DYN ## B (elf->vdata + offset); \
300 while (EGET(dyn->d_tag) != DT_NULL) { \ 836 while (EGET(dyn->d_tag) != DT_NULL) { \
301 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 837 if (EGET(dyn->d_tag) == DT_NEEDED) { \
302 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 838 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
303 if (offset >= elf->len) { \ 839 if (offset >= (Elf ## B ## _Off)elf->len) { \
304 ++dyn; \ 840 ++dyn; \
305 continue; \ 841 continue; \
306 } \ 842 } \
307 needed = (char*)(elf->data + offset); \ 843 needed = elf->data + offset; \
844 if (op == 0) { \
845 /* -n -> print all entries */ \
846 if (!be_wewy_wewy_quiet) { \
308 if (*found_needed) xchrcat(ret, ',', ret_len); \ 847 if (*found_needed) xchrcat(ret, ',', ret_len); \
848 if (use_ldcache) \
849 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
850 needed = p; \
309 xstrcat(ret, needed, ret_len); \ 851 xstrcat(ret, needed, ret_len); \
852 } \
310 *found_needed = 1; \ 853 *found_needed = 1; \
854 } else { \
855 /* -N -> print matching entries */ \
856 size_t n; \
857 const char *find_lib_name; \
858 \
859 array_for_each(find_lib_arr, n, find_lib_name) \
860 if (!strcmp(find_lib_name, needed)) \
861 ++matched; \
862 \
863 if (matched == array_cnt(find_lib_arr)) { \
864 *found_lib = 1; \
865 return (be_wewy_wewy_quiet ? NULL : find_lib); \
866 } \
867 } \
311 } \ 868 } \
312 ++dyn; \ 869 ++dyn; \
313 } \ 870 } \
314 } } 871 } }
315 SHOW_NEEDED(32) 872 SHOW_NEEDED(32)
316 SHOW_NEEDED(64) 873 SHOW_NEEDED(64)
874 if (op == 0 && !*found_needed && be_verbose)
875 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
317 } 876 }
877
878 return NULL;
318} 879}
319static char *scanelf_file_interp(elfobj *elf, char *found_interp) 880static char *scanelf_file_interp(elfobj *elf, char *found_interp)
320{ 881{
321 void *strtbl_void; 882 void *strtbl_void;
322 883
327 if (strtbl_void) { 888 if (strtbl_void) {
328#define SHOW_INTERP(B) \ 889#define SHOW_INTERP(B) \
329 if (elf->elf_class == ELFCLASS ## B) { \ 890 if (elf->elf_class == ELFCLASS ## B) { \
330 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 891 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
331 *found_interp = 1; \ 892 *found_interp = 1; \
332 return elf->data + EGET(strtbl->sh_offset); \ 893 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
333 } 894 }
334 SHOW_INTERP(32) 895 SHOW_INTERP(32)
335 SHOW_INTERP(64) 896 SHOW_INTERP(64)
336 } 897 }
337 return NULL; 898 return NULL;
338} 899}
339static char *scanelf_file_bind(elfobj *elf, char *found_bind) 900static char *scanelf_file_bind(elfobj *elf, char *found_bind)
340{ 901{
341 unsigned long i; 902 unsigned long i;
342 struct stat s; 903 struct stat s;
904 char dynamic = 0;
343 905
344 if (!show_bind) return NULL; 906 if (!show_bind) return NULL;
345 if (!elf->phdr) return NULL; 907 if (!elf->phdr) return NULL;
346 908
347#define SHOW_BIND(B) \ 909#define SHOW_BIND(B) \
349 Elf ## B ## _Dyn *dyn; \ 911 Elf ## B ## _Dyn *dyn; \
350 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 912 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
351 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 913 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
352 Elf ## B ## _Off offset; \ 914 Elf ## B ## _Off offset; \
353 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 915 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
354 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 916 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
917 dynamic = 1; \
355 offset = EGET(phdr[i].p_offset); \ 918 offset = EGET(phdr[i].p_offset); \
356 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 919 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
357 dyn = DYN ## B (elf->data + offset); \ 920 dyn = DYN ## B (elf->vdata + offset); \
358 while (EGET(dyn->d_tag) != DT_NULL) { \ 921 while (EGET(dyn->d_tag) != DT_NULL) { \
359 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 922 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
360 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 923 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
361 { \ 924 { \
362 if (be_quiet) return NULL; \ 925 if (be_quiet) return NULL; \
363 *found_bind = 1; \ 926 *found_bind = 1; \
364 return "NOW"; \ 927 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
365 } \ 928 } \
366 ++dyn; \ 929 ++dyn; \
367 } \ 930 } \
368 } \ 931 } \
369 } 932 }
370 SHOW_BIND(32) 933 SHOW_BIND(32)
371 SHOW_BIND(64) 934 SHOW_BIND(64)
372 935
936 if (be_wewy_wewy_quiet) return NULL;
937
938 /* don't output anything if quiet mode and the ELF is static or not setuid */
373 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 939 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
374 return NULL; 940 return NULL;
375 } else { 941 } else {
376 *found_bind = 1; 942 *found_bind = 1;
377 return "LAZY"; 943 return (char *)(dynamic ? "LAZY" : "STATIC");
378 } 944 }
379} 945}
380static char *scanelf_file_sym(elfobj *elf, char *found_sym, const char *filename) 946static char *scanelf_file_soname(elfobj *elf, char *found_soname)
381{ 947{
382 unsigned long i; 948 unsigned long i;
949 char *soname;
950 void *strtbl_void;
951
952 if (!show_soname) return NULL;
953
954 strtbl_void = elf_findsecbyname(elf, ".dynstr");
955
956 if (elf->phdr && strtbl_void) {
957#define SHOW_SONAME(B) \
958 if (elf->elf_class == ELFCLASS ## B) { \
959 Elf ## B ## _Dyn *dyn; \
960 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
961 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
962 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
963 Elf ## B ## _Off offset; \
964 /* only look for soname in shared objects */ \
965 if (EGET(ehdr->e_type) != ET_DYN) \
966 return NULL; \
967 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
968 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
969 offset = EGET(phdr[i].p_offset); \
970 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
971 dyn = DYN ## B (elf->vdata + offset); \
972 while (EGET(dyn->d_tag) != DT_NULL) { \
973 if (EGET(dyn->d_tag) == DT_SONAME) { \
974 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
975 if (offset >= (Elf ## B ## _Off)elf->len) { \
976 ++dyn; \
977 continue; \
978 } \
979 soname = elf->data + offset; \
980 *found_soname = 1; \
981 return (be_wewy_wewy_quiet ? NULL : soname); \
982 } \
983 ++dyn; \
984 } \
985 } }
986 SHOW_SONAME(32)
987 SHOW_SONAME(64)
988 }
989
990 return NULL;
991}
992
993/*
994 * We support the symbol form:
995 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
996 * If the symbol name is empty, then all symbols are matched.
997 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
998 * Do not rely on this output format at all.
999 * Otherwise the symbol name is used to search (either regex or string compare).
1000 * If the first char of the symbol name is a plus ("+"), then only match
1001 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1002 * Putting modifiers in between the percent signs allows for more in depth
1003 * filters. There are groups of modifiers. If you don't specify a member
1004 * of a group, then all types in that group are matched. The current
1005 * groups and their types are:
1006 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f SST_FILE:F
1007 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1008 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1009 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1010 * You can search for multiple symbols at once by seperating with a comma (",").
1011 *
1012 * Some examples:
1013 * ELFs with a weak function "foo":
1014 * scanelf -s %wf%foo <ELFs>
1015 * ELFs that define the symbol "main":
1016 * scanelf -s +main <ELFs>
1017 * scanelf -s %d%main <ELFs>
1018 * ELFs that refer to the undefined symbol "brk":
1019 * scanelf -s -brk <ELFs>
1020 * scanelf -s %u%brk <ELFs>
1021 * All global defined objects in an ELF:
1022 * scanelf -s %ogd% <ELF>
1023 */
1024static void
1025scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1026 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1027{
1028 char *this_sym, *next_sym, saved = saved;
1029
1030 /* allow the user to specify a comma delimited list of symbols to search for */
1031 next_sym = NULL;
1032 do {
1033 bool inc_notype, inc_object, inc_func, inc_file,
1034 inc_local, inc_global, inc_weak,
1035 inc_def, inc_undef, inc_abs, inc_common;
1036
1037 if (next_sym) {
1038 next_sym[-1] = saved;
1039 this_sym = next_sym;
1040 } else
1041 this_sym = find_sym;
1042 if ((next_sym = strchr(this_sym, ','))) {
1043 /* make parsing easier by killing the comma temporarily */
1044 saved = *next_sym;
1045 *next_sym = '\0';
1046 next_sym += 1;
1047 }
1048
1049 /* symbol selection! */
1050 inc_notype = inc_object = inc_func = inc_file = \
1051 inc_local = inc_global = inc_weak = \
1052 inc_def = inc_undef = inc_abs = inc_common = \
1053 (*this_sym != '%');
1054
1055 /* parse the contents of %...% */
1056 if (!inc_notype) {
1057 while (*(this_sym++)) {
1058 if (*this_sym == '%') {
1059 ++this_sym;
1060 break;
1061 }
1062 switch (*this_sym) {
1063 case 'n': inc_notype = true; break;
1064 case 'o': inc_object = true; break;
1065 case 'f': inc_func = true; break;
1066 case 'F': inc_file = true; break;
1067 case 'l': inc_local = true; break;
1068 case 'g': inc_global = true; break;
1069 case 'w': inc_weak = true; break;
1070 case 'd': inc_def = true; break;
1071 case 'u': inc_undef = true; break;
1072 case 'a': inc_abs = true; break;
1073 case 'c': inc_common = true; break;
1074 default: err("invalid symbol selector '%c'", *this_sym);
1075 }
1076 }
1077
1078 /* If no types are matched, not match all */
1079 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1080 inc_notype = inc_object = inc_func = inc_file = true;
1081 if (!inc_local && !inc_global && !inc_weak)
1082 inc_local = inc_global = inc_weak = true;
1083 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1084 inc_def = inc_undef = inc_abs = inc_common = true;
1085
1086 /* backwards compat for defined/undefined short hand */
1087 } else if (*this_sym == '+') {
1088 inc_undef = false;
1089 ++this_sym;
1090 } else if (*this_sym == '-') {
1091 inc_def = inc_abs = inc_common = false;
1092 ++this_sym;
1093 }
1094
1095 /* filter symbols */
1096 if ((!inc_notype && stt == STT_NOTYPE) || \
1097 (!inc_object && stt == STT_OBJECT) || \
1098 (!inc_func && stt == STT_FUNC ) || \
1099 (!inc_file && stt == STT_FILE ) || \
1100 (!inc_local && stb == STB_LOCAL ) || \
1101 (!inc_global && stb == STB_GLOBAL) || \
1102 (!inc_weak && stb == STB_WEAK ) || \
1103 (!inc_def && shn && shn < SHN_LORESERVE) || \
1104 (!inc_undef && shn == SHN_UNDEF ) || \
1105 (!inc_abs && shn == SHN_ABS ) || \
1106 (!inc_common && shn == SHN_COMMON))
1107 continue;
1108
1109 if (*this_sym == '*') {
1110 /* a "*" symbol gets you debug output */
1111 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1112 ((*found_sym == 0) ? "\n\t" : "\t"),
1113 elf->base_filename,
1114 size,
1115 get_elfstttype(stt),
1116 get_elfstbtype(stb),
1117 get_elfshntype(shn),
1118 symname);
1119 goto matched;
1120
1121 } else {
1122 if (g_match) {
1123 /* regex match the symbol */
1124 if (rematch(this_sym, symname, REG_EXTENDED) != 0)
1125 continue;
1126
1127 } else if (*this_sym) {
1128 /* give empty symbols a "pass", else do a normal compare */
1129 const size_t len = strlen(this_sym);
1130 if (!(strncmp(this_sym, symname, len) == 0 &&
1131 /* Accept unversioned symbol names */
1132 (symname[len] == '\0' || symname[len] == '@')))
1133 continue;
1134 }
1135
1136 if (be_semi_verbose) {
1137 char buf[1024];
1138 snprintf(buf, sizeof(buf), "%lX %s %s",
1139 size,
1140 get_elfstttype(stt),
1141 this_sym);
1142 *ret = xstrdup(buf);
1143 } else {
1144 if (*ret) xchrcat(ret, ',', ret_len);
1145 xstrcat(ret, symname, ret_len);
1146 }
1147
1148 goto matched;
1149 }
1150 } while (next_sym);
1151
1152 return;
1153
1154 matched:
1155 *found_sym = 1;
1156 if (next_sym)
1157 next_sym[-1] = saved;
1158}
1159
1160static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
1161{
1162 unsigned long i;
1163 char *ret;
383 void *symtab_void, *strtab_void; 1164 void *symtab_void, *strtab_void;
384 1165
385 if (!find_sym) return NULL; 1166 if (!find_sym) return NULL;
1167 ret = NULL;
386 1168
387 symtab_void = elf_findsecbyname(elf, ".symtab"); 1169 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
388 strtab_void = elf_findsecbyname(elf, ".strtab");
389 1170
390 if (symtab_void && strtab_void) { 1171 if (symtab_void && strtab_void) {
391 char *base, *basemem;
392 basemem = xstrdup(filename);
393 base = basename(basemem);
394#define FIND_SYM(B) \ 1172#define FIND_SYM(B) \
395 if (elf->elf_class == ELFCLASS ## B) { \ 1173 if (elf->elf_class == ELFCLASS ## B) { \
396 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1174 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
397 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1175 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
398 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1176 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
399 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1177 unsigned long cnt = EGET(symtab->sh_entsize); \
400 char *symname; \ 1178 char *symname; \
1179 size_t ret_len = 0; \
1180 if (cnt) \
1181 cnt = EGET(symtab->sh_size) / cnt; \
401 for (i = 0; i < cnt; ++i) { \ 1182 for (i = 0; i < cnt; ++i) { \
1183 if ((void*)sym > elf->data_end) { \
1184 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1185 goto break_out; \
1186 } \
402 if (sym->st_name) { \ 1187 if (sym->st_name) { \
1188 /* make sure the symbol name is in acceptable memory range */ \
403 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1189 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
404 if (*find_sym == '*') { \ 1190 if ((void*)symname > elf->data_end) { \
405 printf("%s(%s) %5lX %15s %s\n", \ 1191 warnf("%s: corrupt ELF symbols", elf->filename); \
406 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1192 ++sym; \
407 base, \ 1193 continue; \
408 (long)sym->st_size, \ 1194 } \
409 (char *)get_elfstttype(sym->st_info), \ 1195 scanelf_match_symname(elf, found_sym, \
410 symname); \ 1196 &ret, &ret_len, symname, \
411 *found_sym = 1; \ 1197 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
412 } else if ((strcmp(find_sym, symname) == 0) || \ 1198 ELF##B##_ST_BIND(EGET(sym->st_info)), \
413 (strcmp(symname, versioned_symname) == 0)) \ 1199 EGET(sym->st_shndx), \
414 (*found_sym)++; \ 1200 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1201 EGET(sym->st_size)); \
415 } \ 1202 } \
416 ++sym; \ 1203 ++sym; \
417 } } 1204 } }
418 FIND_SYM(32) 1205 FIND_SYM(32)
419 FIND_SYM(64) 1206 FIND_SYM(64)
420 free(basemem);
421 } 1207 }
1208
1209break_out:
1210 if (be_wewy_wewy_quiet) return NULL;
1211
422 if (*find_sym != '*' && *found_sym) 1212 if (*find_sym != '*' && *found_sym)
423 return find_sym; 1213 return ret;
424 if (be_quiet) 1214 if (be_quiet)
425 return NULL; 1215 return NULL;
426 else 1216 else
427 return " - "; 1217 return " - ";
428} 1218}
1219
1220static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1221{
1222 if (!find_section)
1223 return NULL;
1224
1225#define FIND_SECTION(B) \
1226 if (elf->elf_class == ELFCLASS ## B) { \
1227 size_t matched, n; \
1228 int invert; \
1229 const char *section_name; \
1230 Elf ## B ## _Shdr *section; \
1231 \
1232 matched = 0; \
1233 array_for_each(find_section_arr, n, section_name) { \
1234 invert = (*section_name == '!' ? 1 : 0); \
1235 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1236 if ((section == NULL && invert) || (section != NULL && !invert)) \
1237 ++matched; \
1238 } \
1239 \
1240 if (matched == array_cnt(find_section_arr)) \
1241 *found_section = 1; \
1242 }
1243 FIND_SECTION(32)
1244 FIND_SECTION(64)
1245
1246 if (be_wewy_wewy_quiet)
1247 return NULL;
1248
1249 if (*found_section)
1250 return find_section;
1251
1252 if (be_quiet)
1253 return NULL;
1254 else
1255 return " - ";
1256}
1257
429/* scan an elf file and show all the fun stuff */ 1258/* scan an elf file and show all the fun stuff */
430// #define prints(str) fputs(str, stdout)
431#define prints(str) write(fileno(stdout), str, strlen(str)) 1259#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
432static void scanelf_file(const char *filename) 1260static int scanelf_elfobj(elfobj *elf)
433{ 1261{
434 unsigned long i; 1262 unsigned long i;
435 char found_pax, found_stack, found_relro, found_textrel, 1263 char found_pax, found_phdr, found_relro, found_load, found_textrel,
436 found_rpath, found_needed, found_interp, found_bind, 1264 found_rpath, found_needed, found_interp, found_bind, found_soname,
437 found_sym, found_file; 1265 found_sym, found_lib, found_file, found_textrels, found_section;
438 elfobj *elf;
439 struct stat st;
440 static char *out_buffer = NULL; 1266 static char *out_buffer = NULL;
441 static size_t out_len; 1267 static size_t out_len;
442 1268
443 /* make sure 'filename' exists */
444 if (lstat(filename, &st) == -1) {
445 if (be_verbose > 2) printf("%s: does not exist\n", filename);
446 return;
447 }
448 /* always handle regular files and handle symlinked files if no -y */
449 if (S_ISLNK(st.st_mode)) {
450 if (!scan_symlink) return;
451 stat(filename, &st);
452 }
453 if (!S_ISREG(st.st_mode)) {
454 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
455 return;
456 }
457
458 found_pax = found_stack = found_relro = found_textrel = \ 1269 found_pax = found_phdr = found_relro = found_load = found_textrel = \
459 found_rpath = found_needed = found_interp = found_bind = \ 1270 found_rpath = found_needed = found_interp = found_bind = found_soname = \
460 found_sym = found_file = 0; 1271 found_sym = found_lib = found_file = found_textrels = found_section = 0;
461 1272
462 /* verify this is real ELF */
463 if ((elf = readelf(filename)) == NULL) {
464 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
465 return;
466 }
467
468 if (be_verbose > 1) 1273 if (be_verbose > 2)
469 printf("%s: scanning file {%s,%s}\n", filename, 1274 printf("%s: scanning file {%s,%s}\n", elf->filename,
470 get_elfeitype(elf, EI_CLASS, elf->elf_class), 1275 get_elfeitype(EI_CLASS, elf->elf_class),
471 get_elfeitype(elf, EI_DATA, elf->data[EI_DATA])); 1276 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
472 else if (be_verbose) 1277 else if (be_verbose > 1)
473 printf("%s: scanning file\n", filename); 1278 printf("%s: scanning file\n", elf->filename);
474 1279
475 /* init output buffer */ 1280 /* init output buffer */
476 if (!out_buffer) { 1281 if (!out_buffer) {
477 out_len = sizeof(char) * 80; 1282 out_len = sizeof(char) * 80;
478 out_buffer = (char*)xmalloc(out_len); 1283 out_buffer = xmalloc(out_len);
479 } 1284 }
480 *out_buffer = '\0'; 1285 *out_buffer = '\0';
481 1286
482 /* show the header */ 1287 /* show the header */
483 if (!be_quiet && show_banner) { 1288 if (!be_quiet && show_banner) {
484 for (i = 0; out_format[i]; ++i) { 1289 for (i = 0; out_format[i]; ++i) {
485 if (out_format[i] != '%') continue; 1290 if (!IS_MODIFIER(out_format[i])) continue;
486 1291
487 switch (out_format[++i]) { 1292 switch (out_format[++i]) {
1293 case '+': break;
488 case '%': break; 1294 case '%': break;
1295 case '#': break;
1296 case 'F':
1297 case 'p':
489 case 'F': prints("FILE "); found_file = 1; break; 1298 case 'f': prints("FILE "); found_file = 1; break;
490 case 'o': prints(" TYPE "); break; 1299 case 'o': prints(" TYPE "); break;
491 case 'x': prints(" PAX "); break; 1300 case 'x': prints(" PAX "); break;
492 case 'e': prints("STK/REL "); break; 1301 case 'e': prints("STK/REL/PTL "); break;
493 case 't': prints("TEXTREL "); break; 1302 case 't': prints("TEXTREL "); break;
494 case 'r': prints("RPATH "); break; 1303 case 'r': prints("RPATH "); break;
1304 case 'M': prints("CLASS "); break;
495 case 'n': prints("NEEDED "); break; 1305 case 'n': prints("NEEDED "); break;
496 case 'i': prints("INTERP "); break; 1306 case 'i': prints("INTERP "); break;
497 case 'b': prints("BIND "); break; 1307 case 'b': prints("BIND "); break;
1308 case 'Z': prints("SIZE "); break;
1309 case 'S': prints("SONAME "); break;
498 case 's': prints("SYM "); break; 1310 case 's': prints("SYM "); break;
1311 case 'N': prints("LIB "); break;
1312 case 'T': prints("TEXTRELS "); break;
1313 case 'k': prints("SECTION "); break;
1314 case 'a': prints("ARCH "); break;
1315 case 'I': prints("OSABI "); break;
1316 case 'Y': prints("EABI "); break;
1317 case 'O': prints("PERM "); break;
1318 case 'D': prints("ENDIAN "); break;
1319 default: warnf("'%c' has no title ?", out_format[i]);
499 } 1320 }
500 } 1321 }
501 if (!found_file) prints("FILE "); 1322 if (!found_file) prints("FILE ");
502 prints("\n"); 1323 prints("\n");
503 found_file = 0; 1324 found_file = 0;
505 } 1326 }
506 1327
507 /* dump all the good stuff */ 1328 /* dump all the good stuff */
508 for (i = 0; out_format[i]; ++i) { 1329 for (i = 0; out_format[i]; ++i) {
509 const char *out; 1330 const char *out;
510 1331 const char *tmp;
511 /* make sure we trim leading spaces in quiet mode */ 1332 static char ubuf[sizeof(unsigned long)*2];
512 if (be_quiet && *out_buffer == ' ' && !out_buffer[1]) 1333 if (!IS_MODIFIER(out_format[i])) {
513 *out_buffer = '\0';
514
515 if (out_format[i] != '%') {
516 xchrcat(&out_buffer, out_format[i], &out_len); 1334 xchrcat(&out_buffer, out_format[i], &out_len);
517 continue; 1335 continue;
518 } 1336 }
519 1337
520 out = NULL; 1338 out = NULL;
1339 be_wewy_wewy_quiet = (out_format[i] == '#');
1340 be_semi_verbose = (out_format[i] == '+');
521 switch (out_format[++i]) { 1341 switch (out_format[++i]) {
1342 case '+':
1343 case '%':
1344 case '#':
522 case '%': xchrcat(&out_buffer, '%', &out_len); break; 1345 xchrcat(&out_buffer, out_format[i], &out_len); break;
523 case 'F': found_file = 1; xstrcat(&out_buffer, filename, &out_len); break; 1346 case 'F':
1347 found_file = 1;
1348 if (be_wewy_wewy_quiet) break;
1349 xstrcat(&out_buffer, elf->filename, &out_len);
1350 break;
1351 case 'p':
1352 found_file = 1;
1353 if (be_wewy_wewy_quiet) break;
1354 tmp = elf->filename;
1355 if (search_path) {
1356 ssize_t len_search = strlen(search_path);
1357 ssize_t len_file = strlen(elf->filename);
1358 if (!strncmp(elf->filename, search_path, len_search) && \
1359 len_file > len_search)
1360 tmp += len_search;
1361 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
1362 }
1363 xstrcat(&out_buffer, tmp, &out_len);
1364 break;
1365 case 'f':
1366 found_file = 1;
1367 if (be_wewy_wewy_quiet) break;
1368 tmp = strrchr(elf->filename, '/');
1369 tmp = (tmp == NULL ? elf->filename : tmp+1);
1370 xstrcat(&out_buffer, tmp, &out_len);
1371 break;
524 case 'o': out = get_elfetype(elf); break; 1372 case 'o': out = get_elfetype(elf); break;
525 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1373 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
526 case 'e': out = scanelf_file_stack(elf, &found_stack, &found_relro); break; 1374 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
527 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1375 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1376 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
528 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1377 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1378 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1379 case 'D': out = get_endian(elf); break;
1380 case 'O': out = strfileperms(elf->filename); break;
1381 case 'n':
529 case 'n': scanelf_file_needed(elf, &found_needed, &out_buffer, &out_len); break; 1382 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
530 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1383 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
531 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1384 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1385 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
532 case 's': out = scanelf_file_sym(elf, &found_sym, filename); break; 1386 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1387 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1388 case 'a': out = get_elfemtype(elf); break;
1389 case 'I': out = get_elfosabi(elf); break;
1390 case 'Y': out = get_elf_eabi(elf); break;
1391 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
1392 default: warnf("'%c' has no scan code?", out_format[i]);
533 } 1393 }
1394 if (out)
534 if (out) xstrcat(&out_buffer, out, &out_len); 1395 xstrcat(&out_buffer, out, &out_len);
535 } 1396 }
536 1397
537#define FOUND_SOMETHING() \ 1398#define FOUND_SOMETHING() \
538 (found_pax || found_stack || found_textrel || found_rpath || \ 1399 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
539 found_needed || found_interp || found_bind || found_sym) 1400 found_rpath || found_needed || found_interp || found_bind || \
1401 found_soname || found_sym || found_lib || found_textrels || found_section )
540 1402
541 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1403 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
542 xchrcat(&out_buffer, ' ', &out_len); 1404 xchrcat(&out_buffer, ' ', &out_len);
543 xstrcat(&out_buffer, filename, &out_len); 1405 xstrcat(&out_buffer, elf->filename, &out_len);
544 } 1406 }
545 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) 1407 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
546 puts(out_buffer); 1408 puts(out_buffer);
1409 fflush(stdout);
1410 }
547 1411
1412 return 0;
1413}
1414
1415/* scan a single elf */
1416static int scanelf_elf(const char *filename, int fd, size_t len)
1417{
1418 int ret = 1;
1419 elfobj *elf;
1420
1421 /* verify this is real ELF */
1422 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1423 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1424 return ret;
1425 }
1426 switch (match_bits) {
1427 case 32:
1428 if (elf->elf_class != ELFCLASS32)
1429 goto label_done;
1430 break;
1431 case 64:
1432 if (elf->elf_class != ELFCLASS64)
1433 goto label_done;
1434 break;
1435 default: break;
1436 }
1437 if (match_etypes) {
1438 char sbuf[126];
1439 strncpy(sbuf, match_etypes, sizeof(sbuf));
1440 if (strchr(match_etypes, ',') != NULL) {
1441 char *p;
1442 while ((p = strrchr(sbuf, ',')) != NULL) {
1443 *p = 0;
1444 if (etype_lookup(p+1) == get_etype(elf))
1445 goto label_ret;
1446 }
1447 }
1448 if (etype_lookup(sbuf) != get_etype(elf))
1449 goto label_done;
1450 }
1451
1452label_ret:
1453 ret = scanelf_elfobj(elf);
1454
1455label_done:
548 unreadelf(elf); 1456 unreadelf(elf);
1457 return ret;
1458}
1459
1460/* scan an archive of elfs */
1461static int scanelf_archive(const char *filename, int fd, size_t len)
1462{
1463 archive_handle *ar;
1464 archive_member *m;
1465 char *ar_buffer;
1466 elfobj *elf;
1467
1468 ar = ar_open_fd(filename, fd);
1469 if (ar == NULL)
1470 return 1;
1471
1472 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1473 while ((m = ar_next(ar)) != NULL) {
1474 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1475 if (cur_pos == -1)
1476 errp("lseek() failed");
1477 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1478 if (elf) {
1479 scanelf_elfobj(elf);
1480 unreadelf(elf);
1481 }
1482 }
1483 munmap(ar_buffer, len);
1484
1485 return 0;
1486}
1487/* scan a file which may be an elf or an archive or some other magical beast */
1488static int scanelf_file(const char *filename, const struct stat *st_cache)
1489{
1490 const struct stat *st = st_cache;
1491 struct stat symlink_st;
1492 int fd;
1493
1494 /* always handle regular files and handle symlinked files if no -y */
1495 if (S_ISLNK(st->st_mode)) {
1496 if (!scan_symlink) return 1;
1497 stat(filename, &symlink_st);
1498 st = &symlink_st;
1499 }
1500
1501 if (!S_ISREG(st->st_mode)) {
1502 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1503 return 1;
1504 }
1505
1506 if (match_perms) {
1507 if ((st->st_mode | match_perms) != st->st_mode)
1508 return 1;
1509 }
1510 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1)
1511 return 1;
1512
1513 if (scanelf_elf(filename, fd, st->st_size) == 1 && scan_archives)
1514 /* if it isn't an ELF, maybe it's an .a archive */
1515 scanelf_archive(filename, fd, st->st_size);
1516
1517 close(fd);
1518 return 0;
1519}
1520
1521static const char *maybe_add_root(const char *fname, char *buf)
1522{
1523 if (root && strncmp(fname, root, strlen(root))) {
1524 strcpy(buf, root);
1525 strncat(buf, fname, __PAX_UTILS_PATH_MAX - strlen(root) - 1);
1526 fname = buf;
1527 }
1528 return fname;
549} 1529}
550 1530
551/* scan a directory for ET_EXEC files and print when we find one */ 1531/* scan a directory for ET_EXEC files and print when we find one */
552static void scanelf_dir(const char *path) 1532static int scanelf_dir(const char *path)
553{ 1533{
554 register DIR *dir; 1534 register DIR *dir;
555 register struct dirent *dentry; 1535 register struct dirent *dentry;
556 struct stat st_top, st; 1536 struct stat st_top, st;
557 char buf[_POSIX_PATH_MAX]; 1537 char buf[__PAX_UTILS_PATH_MAX];
1538 char _path[__PAX_UTILS_PATH_MAX];
558 size_t pathlen = 0, len = 0; 1539 size_t pathlen = 0, len = 0;
1540 int ret = 0;
1541
1542 path = maybe_add_root(path, _path);
559 1543
560 /* make sure path exists */ 1544 /* make sure path exists */
561 if (lstat(path, &st_top) == -1) { 1545 if (lstat(path, &st_top) == -1) {
562 if (be_verbose > 2) printf("%s: does not exist\n", path); 1546 if (be_verbose > 2) printf("%s: does not exist\n", path);
563 return; 1547 return 1;
564 } 1548 }
565 1549
566 /* ok, if it isn't a directory, assume we can open it */ 1550 /* ok, if it isn't a directory, assume we can open it */
567 if (!S_ISDIR(st_top.st_mode)) { 1551 if (!S_ISDIR(st_top.st_mode)) {
568 scanelf_file(path); 1552 return scanelf_file(path, &st_top);
569 return;
570 } 1553 }
571 1554
572 /* now scan the dir looking for fun stuff */ 1555 /* now scan the dir looking for fun stuff */
573 if ((dir = opendir(path)) == NULL) { 1556 if ((dir = opendir(path)) == NULL) {
574 warnf("could not opendir %s: %s", path, strerror(errno)); 1557 warnf("could not opendir %s: %s", path, strerror(errno));
575 return; 1558 return 1;
576 } 1559 }
577 if (be_verbose) printf("%s: scanning dir\n", path); 1560 if (be_verbose > 1) printf("%s: scanning dir\n", path);
578 1561
579 pathlen = strlen(path); 1562 pathlen = strlen(path);
580 while ((dentry = readdir(dir))) { 1563 while ((dentry = readdir(dir))) {
581 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1564 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
582 continue; 1565 continue;
583 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1566 len = (pathlen + 1 + strlen(dentry->d_name) + 1);
584 if (len >= sizeof(buf)) { 1567 if (len >= sizeof(buf)) {
585 warnf("Skipping '%s': len > sizeof(buf); %d > %d\n", path, (int)len, (int)sizeof(buf)); 1568 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
1569 (unsigned long)len, (unsigned long)sizeof(buf));
586 continue; 1570 continue;
587 } 1571 }
588 sprintf(buf, "%s/%s", path, dentry->d_name); 1572 snprintf(buf, sizeof(buf), "%s%s%s", path, (path[pathlen-1] == '/') ? "" : "/", dentry->d_name);
589 if (lstat(buf, &st) != -1) { 1573 if (lstat(buf, &st) != -1) {
590 if (S_ISREG(st.st_mode)) 1574 if (S_ISREG(st.st_mode))
591 scanelf_file(buf); 1575 ret = scanelf_file(buf, &st);
592 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1576 else if (dir_recurse && S_ISDIR(st.st_mode)) {
593 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1577 if (dir_crossmount || (st_top.st_dev == st.st_dev))
594 scanelf_dir(buf); 1578 ret = scanelf_dir(buf);
595 } 1579 }
596 } 1580 }
597 } 1581 }
598 closedir(dir); 1582 closedir(dir);
1583 return ret;
599} 1584}
600 1585
601static int scanelf_from_file(char *filename) 1586static int scanelf_from_file(const char *filename)
602{ 1587{
603 FILE *fp = NULL; 1588 FILE *fp = NULL;
604 char *p; 1589 char *p;
605 char path[_POSIX_PATH_MAX]; 1590 char path[__PAX_UTILS_PATH_MAX];
1591 int ret = 0;
606 1592
607 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1593 if (strcmp(filename, "-") == 0)
608 fp = stdin; 1594 fp = stdin;
609 else if ((fp = fopen(filename, "r")) == NULL) 1595 else if ((fp = fopen(filename, "r")) == NULL)
610 return 1; 1596 return 1;
611 1597
612 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1598 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
613 if ((p = strchr(path, '\n')) != NULL) 1599 if ((p = strchr(path, '\n')) != NULL)
614 *p = 0; 1600 *p = 0;
1601 search_path = path;
615 scanelf_dir(path); 1602 ret = scanelf_dir(path);
616 } 1603 }
617 if (fp != stdin) 1604 if (fp != stdin)
618 fclose(fp); 1605 fclose(fp);
619 return 0; 1606 return ret;
620} 1607}
621 1608
622static void load_ld_so_conf() 1609#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1610
1611static int load_ld_cache_config(int i, const char *fname)
623{ 1612{
624 FILE *fp = NULL; 1613 FILE *fp = NULL;
625 char *p; 1614 char *p;
626 char path[_POSIX_PATH_MAX]; 1615 char path[__PAX_UTILS_PATH_MAX];
627 int i = 0; 1616 char _fname[__PAX_UTILS_PATH_MAX];
628 1617
1618 fname = maybe_add_root(fname, _fname);
1619
629 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1620 if ((fp = fopen(fname, "r")) == NULL)
630 return; 1621 return i;
631 1622
632 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1623 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
633 if (*path != '/')
634 continue;
635
636 if ((p = strrchr(path, '\r')) != NULL) 1624 if ((p = strrchr(path, '\r')) != NULL)
637 *p = 0; 1625 *p = 0;
638 if ((p = strchr(path, '\n')) != NULL) 1626 if ((p = strchr(path, '\n')) != NULL)
639 *p = 0; 1627 *p = 0;
640 1628
641 ldpaths[i++] = xstrdup(path); 1629 /* recursive includes of the same file will make this segfault. */
1630 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1631 glob_t gl;
1632 size_t x;
1633 char gpath[__PAX_UTILS_PATH_MAX];
642 1634
643 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1635 memset(gpath, 0, sizeof(gpath));
644 break; 1636 if (root)
1637 strcpy(gpath, root);
1638
1639 if (path[8] != '/')
1640 snprintf(gpath+strlen(gpath), sizeof(gpath)-strlen(gpath), "/etc/%s", &path[8]);
1641 else
1642 strncpy(gpath+strlen(gpath), &path[8], sizeof(gpath)-strlen(gpath));
1643
1644 if (glob(gpath, 0, NULL, &gl) == 0) {
1645 for (x = 0; x < gl.gl_pathc; ++x) {
1646 /* try to avoid direct loops */
1647 if (strcmp(gl.gl_pathv[x], fname) == 0)
1648 continue;
1649 i = load_ld_cache_config(i, gl.gl_pathv[x]);
1650 }
1651 globfree(&gl);
1652 continue;
1653 }
645 } 1654 }
646 ldpaths[i] = NULL; 1655
1656 if (*path != '/')
1657 continue;
1658
1659 xarraypush(ldpaths, path, strlen(path));
1660 }
647 1661
648 fclose(fp); 1662 fclose(fp);
1663 return i;
649} 1664}
1665
1666#elif defined(__FreeBSD__) || defined(__DragonFly__)
1667
1668static int load_ld_cache_config(int i, const char *fname)
1669{
1670 FILE *fp = NULL;
1671 char *b = NULL, *p;
1672 struct elfhints_hdr hdr;
1673 char _fname[__PAX_UTILS_PATH_MAX];
1674
1675 fname = maybe_add_root(fname, _fname);
1676
1677 if ((fp = fopen(fname, "r")) == NULL)
1678 return i;
1679
1680 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1681 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1682 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1683 {
1684 fclose(fp);
1685 return i;
1686 }
1687
1688 b = xmalloc(hdr.dirlistlen + 1);
1689 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1690 fclose(fp);
1691 free(b);
1692 return i;
1693 }
1694
1695 while ((p = strsep(&b, ":"))) {
1696 if (*p == '\0')
1697 continue;
1698 xarraypush(ldpaths, p, strlen(p));
1699 }
1700
1701 free(b);
1702 fclose(fp);
1703 return i;
1704}
1705
1706#else
1707#ifdef __ELF__
1708#warning Cache config support not implemented for your target
1709#endif
1710static int load_ld_cache_config(int i, const char *fname)
1711{
1712 return 0;
1713}
1714#endif
650 1715
651/* scan /etc/ld.so.conf for paths */ 1716/* scan /etc/ld.so.conf for paths */
652static void scanelf_ldpath() 1717static void scanelf_ldpath(void)
653{ 1718{
654 char scan_l, scan_ul, scan_ull; 1719 char scan_l, scan_ul, scan_ull;
1720 size_t n;
1721 const char *ldpath;
655 int i = 0; 1722 int i = 0;
656 1723
657 if (!ldpaths[0]) 1724 if (array_cnt(ldpaths) == 0)
658 err("Unable to load any paths from ld.so.conf"); 1725 err("Unable to load any paths from ld.so.conf");
659 1726
660 scan_l = scan_ul = scan_ull = 0; 1727 scan_l = scan_ul = scan_ull = 0;
661 1728
662 while (ldpaths[i]) { 1729 array_for_each(ldpaths, n, ldpath) {
663 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1; 1730 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = 1;
664 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1; 1731 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = 1;
665 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1; 1732 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = 1;
666 scanelf_dir(ldpaths[i]); 1733 scanelf_dir(ldpath);
667 ++i; 1734 ++i;
668 } 1735 }
669 1736
670 if (!scan_l) scanelf_dir("/lib"); 1737 if (!scan_l) scanelf_dir("/lib");
671 if (!scan_ul) scanelf_dir("/usr/lib"); 1738 if (!scan_ul) scanelf_dir("/usr/lib");
672 if (!scan_ull) scanelf_dir("/usr/local/lib"); 1739 if (!scan_ull) scanelf_dir("/usr/local/lib");
673} 1740}
674 1741
675/* scan env PATH for paths */ 1742/* scan env PATH for paths */
676static void scanelf_envpath() 1743static void scanelf_envpath(void)
677{ 1744{
678 char *path, *p; 1745 char *path, *p;
679 1746
680 path = getenv("PATH"); 1747 path = getenv("PATH");
681 if (!path) 1748 if (!path)
688 } 1755 }
689 1756
690 free(path); 1757 free(path);
691} 1758}
692 1759
693 1760/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
694
695/* usage / invocation handling functions */
696#define PARSE_FLAGS "plRmyxetrnibs:aqvF:f:o:BhV" 1761#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
697#define a_argument required_argument 1762#define a_argument required_argument
698static struct option const long_opts[] = { 1763static struct option const long_opts[] = {
699 {"path", no_argument, NULL, 'p'}, 1764 {"path", no_argument, NULL, 'p'},
700 {"ldpath", no_argument, NULL, 'l'}, 1765 {"ldpath", no_argument, NULL, 'l'},
1766 {"root", a_argument, NULL, 128},
701 {"recursive", no_argument, NULL, 'R'}, 1767 {"recursive", no_argument, NULL, 'R'},
702 {"mount", no_argument, NULL, 'm'}, 1768 {"mount", no_argument, NULL, 'm'},
703 {"symlink", no_argument, NULL, 'y'}, 1769 {"symlink", no_argument, NULL, 'y'},
1770 {"archives", no_argument, NULL, 'A'},
1771 {"ldcache", no_argument, NULL, 'L'},
1772 {"fix", no_argument, NULL, 'X'},
1773 {"setpax", a_argument, NULL, 'z'},
704 {"pax", no_argument, NULL, 'x'}, 1774 {"pax", no_argument, NULL, 'x'},
705 {"header", no_argument, NULL, 'e'}, 1775 {"header", no_argument, NULL, 'e'},
706 {"textrel", no_argument, NULL, 't'}, 1776 {"textrel", no_argument, NULL, 't'},
707 {"rpath", no_argument, NULL, 'r'}, 1777 {"rpath", no_argument, NULL, 'r'},
708 {"needed", no_argument, NULL, 'n'}, 1778 {"needed", no_argument, NULL, 'n'},
709 {"interp", no_argument, NULL, 'i'}, 1779 {"interp", no_argument, NULL, 'i'},
710 {"bind", no_argument, NULL, 'b'}, 1780 {"bind", no_argument, NULL, 'b'},
1781 {"soname", no_argument, NULL, 'S'},
711 {"symbol", a_argument, NULL, 's'}, 1782 {"symbol", a_argument, NULL, 's'},
1783 {"section", a_argument, NULL, 'k'},
1784 {"lib", a_argument, NULL, 'N'},
1785 {"gmatch", no_argument, NULL, 'g'},
1786 {"textrels", no_argument, NULL, 'T'},
1787 {"etype", a_argument, NULL, 'E'},
1788 {"bits", a_argument, NULL, 'M'},
1789 {"endian", no_argument, NULL, 'D'},
1790 {"osabi", no_argument, NULL, 'I'},
1791 {"eabi", no_argument, NULL, 'Y'},
1792 {"perms", a_argument, NULL, 'O'},
1793 {"size", no_argument, NULL, 'Z'},
712 {"all", no_argument, NULL, 'a'}, 1794 {"all", no_argument, NULL, 'a'},
713 {"quiet", no_argument, NULL, 'q'}, 1795 {"quiet", no_argument, NULL, 'q'},
714 {"verbose", no_argument, NULL, 'v'}, 1796 {"verbose", no_argument, NULL, 'v'},
715 {"format", a_argument, NULL, 'F'}, 1797 {"format", a_argument, NULL, 'F'},
716 {"from", a_argument, NULL, 'f'}, 1798 {"from", a_argument, NULL, 'f'},
717 {"file", a_argument, NULL, 'o'}, 1799 {"file", a_argument, NULL, 'o'},
1800 {"nocolor", no_argument, NULL, 'C'},
718 {"nobanner", no_argument, NULL, 'B'}, 1801 {"nobanner", no_argument, NULL, 'B'},
719 {"help", no_argument, NULL, 'h'}, 1802 {"help", no_argument, NULL, 'h'},
720 {"version", no_argument, NULL, 'V'}, 1803 {"version", no_argument, NULL, 'V'},
721 {NULL, no_argument, NULL, 0x0} 1804 {NULL, no_argument, NULL, 0x0}
722}; 1805};
723 1806
724static char *opts_help[] = { 1807static const char * const opts_help[] = {
725 "Scan all directories in PATH environment", 1808 "Scan all directories in PATH environment",
726 "Scan all directories in /etc/ld.so.conf", 1809 "Scan all directories in /etc/ld.so.conf",
1810 "Root directory (use with -l or -p)",
727 "Scan directories recursively", 1811 "Scan directories recursively",
728 "Don't recursively cross mount points", 1812 "Don't recursively cross mount points",
729 "Don't scan symlinks\n", 1813 "Don't scan symlinks",
1814 "Scan archives (.a files)",
1815 "Utilize ld.so.cache information (use with -r/-n)",
1816 "Try and 'fix' bad things (use with -r/-e)",
1817 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
730 "Print PaX markings", 1818 "Print PaX markings",
731 "Print GNU_STACK markings", 1819 "Print GNU_STACK/PT_LOAD markings",
732 "Print TEXTREL information", 1820 "Print TEXTREL information",
733 "Print RPATH information", 1821 "Print RPATH information",
734 "Print NEEDED information", 1822 "Print NEEDED information",
735 "Print INTERP information", 1823 "Print INTERP information",
736 "Print BIND information", 1824 "Print BIND information",
1825 "Print SONAME information",
737 "Find a specified symbol", 1826 "Find a specified symbol",
738 "Print all scanned info (-x -e -t -r -n -i -b)\n", 1827 "Find a specified section",
1828 "Find a specified library",
1829 "Use regex matching rather than string compare (use with -s)",
1830 "Locate cause of TEXTREL",
1831 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1832 "Print only ELF files matching numeric bits",
1833 "Print Endianness",
1834 "Print OSABI",
1835 "Print EABI (EM_ARM Only)",
1836 "Print only ELF files matching octal permissions",
1837 "Print ELF file size",
1838 "Print all useful/simple info\n",
739 "Only output 'bad' things", 1839 "Only output 'bad' things",
740 "Be verbose (can be specified more than once)", 1840 "Be verbose (can be specified more than once)",
741 "Use specified format for output", 1841 "Use specified format for output",
742 "Read input stream from a filename", 1842 "Read input stream from a filename",
743 "Write output stream to a filename", 1843 "Write output stream to a filename",
1844 "Don't emit color in output",
744 "Don't display the header", 1845 "Don't display the header",
745 "Print this help and exit", 1846 "Print this help and exit",
746 "Print version and exit", 1847 "Print version and exit",
747 NULL 1848 NULL
748}; 1849};
750/* display usage and exit */ 1851/* display usage and exit */
751static void usage(int status) 1852static void usage(int status)
752{ 1853{
753 unsigned long i; 1854 unsigned long i;
754 printf("* Scan ELF binaries for stuff\n\n" 1855 printf("* Scan ELF binaries for stuff\n\n"
755 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 1856 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
756 printf("Options: -[%s]\n", PARSE_FLAGS); 1857 printf("Options: -[%s]\n", PARSE_FLAGS);
757 for (i = 0; long_opts[i].name; ++i) 1858 for (i = 0; long_opts[i].name; ++i)
758 if (long_opts[i].has_arg == no_argument) 1859 if (long_opts[i].has_arg == no_argument)
759 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 1860 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
1861 long_opts[i].name, opts_help[i]);
1862 else if (long_opts[i].val > '~')
1863 printf(" --%-7s <arg> * %s\n",
760 long_opts[i].name, opts_help[i]); 1864 long_opts[i].name, opts_help[i]);
761 else 1865 else
762 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 1866 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
763 long_opts[i].name, opts_help[i]); 1867 long_opts[i].name, opts_help[i]);
764 1868
765 if (status != EXIT_SUCCESS) 1869 puts("\nFor more information, see the scanelf(1) manpage");
766 exit(status);
767
768 puts("\nThe format modifiers for the -F option are:");
769 puts(" %F Filename \t%x PaX Flags \t%e STACK/RELRO");
770 puts(" %t TEXTREL \t%r RPATH \t%n NEEDED");
771 puts(" %i INTERP \t%b BIND \t%s symbol");
772
773 exit(status); 1870 exit(status);
774} 1871}
775 1872
776/* parse command line arguments and preform needed actions */ 1873/* parse command line arguments and preform needed actions */
1874#define do_pax_state(option, flag) \
1875 if (islower(option)) { \
1876 flags &= ~PF_##flag; \
1877 flags |= PF_NO##flag; \
1878 } else { \
1879 flags &= ~PF_NO##flag; \
1880 flags |= PF_##flag; \
1881 }
777static void parseargs(int argc, char *argv[]) 1882static int parseargs(int argc, char *argv[])
778{ 1883{
779 int i; 1884 int i;
780 char *from_file = NULL; 1885 const char *from_file = NULL;
1886 int ret = 0;
781 1887
782 opterr = 0; 1888 opterr = 0;
783 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 1889 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
784 switch (i) { 1890 switch (i) {
785 1891
786 case 'V': 1892 case 'V':
787 printf("%s compiled %s\n%s\n" 1893 printf("pax-utils-%s: %s compiled %s\n%s\n"
788 "%s written for Gentoo Linux by <solar and vapier @ gentoo.org>\n", 1894 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
789 __FILE__, __DATE__, rcsid, argv0); 1895 VERSION, __FILE__, __DATE__, rcsid, argv0);
790 exit(EXIT_SUCCESS); 1896 exit(EXIT_SUCCESS);
791 break; 1897 break;
792 case 'h': usage(EXIT_SUCCESS); break; 1898 case 'h': usage(EXIT_SUCCESS); break;
793 case 'f': 1899 case 'f':
794 if (from_file == NULL) 1900 if (from_file) warn("You prob don't want to specify -f twice");
795 from_file = xstrdup(optarg); 1901 from_file = optarg;
796 else 1902 break;
797 err("Don't specify -f twice"); 1903 case 'E':
1904 match_etypes = optarg;
1905 break;
1906 case 'M':
1907 match_bits = atoi(optarg);
1908 if (match_bits == 0) {
1909 if (strcmp(optarg, "ELFCLASS32") == 0)
1910 match_bits = 32;
1911 if (strcmp(optarg, "ELFCLASS64") == 0)
1912 match_bits = 64;
1913 }
1914 break;
1915 case 'O':
1916 if (sscanf(optarg, "%o", &match_perms) == -1)
1917 match_bits = 0;
798 break; 1918 break;
799 case 'o': { 1919 case 'o': {
800 FILE *fp = NULL;
801 fp = freopen(optarg, "w", stdout); 1920 if (freopen(optarg, "w", stdout) == NULL)
802 if (fp == NULL)
803 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 1921 err("Could not open output stream '%s': %s", optarg, strerror(errno));
804 stdout = fp;
805 break; 1922 break;
806 } 1923 }
807 1924 case 'k':
1925 xarraypush(find_section_arr, optarg, strlen(optarg));
1926 break;
808 case 's': { 1927 case 's': {
809 size_t len; 1928 if (find_sym) warn("You prob don't want to specify -s twice");
810 if (!find_sym)
811 err("Don't specify -s twice");
812 find_sym = xstrdup(optarg); 1929 find_sym = optarg;
813 len = strlen(find_sym) + 1;
814 versioned_symname = (char*)xmalloc(sizeof(char) * (len+1));
815 sprintf(versioned_symname, "%s@", find_sym);
816 break; 1930 break;
817 } 1931 }
818 1932 case 'N':
1933 xarraypush(find_lib_arr, optarg, strlen(optarg));
1934 break;
819 case 'F': { 1935 case 'F': {
820 if (!out_format) 1936 if (out_format) warn("You prob don't want to specify -F twice");
821 out_format = xstrdup(optarg); 1937 out_format = optarg;
822 else
823 err("Don't specify -F twice");
824 break; 1938 break;
825 } 1939 }
1940 case 'z': {
1941 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1942 size_t x;
826 1943
1944 for (x = 0; x < strlen(optarg); x++) {
1945 switch (optarg[x]) {
1946 case 'p':
1947 case 'P':
1948 do_pax_state(optarg[x], PAGEEXEC);
1949 break;
1950 case 's':
1951 case 'S':
1952 do_pax_state(optarg[x], SEGMEXEC);
1953 break;
1954 case 'm':
1955 case 'M':
1956 do_pax_state(optarg[x], MPROTECT);
1957 break;
1958 case 'e':
1959 case 'E':
1960 do_pax_state(optarg[x], EMUTRAMP);
1961 break;
1962 case 'r':
1963 case 'R':
1964 do_pax_state(optarg[x], RANDMMAP);
1965 break;
1966 case 'x':
1967 case 'X':
1968 do_pax_state(optarg[x], RANDEXEC);
1969 break;
1970 default:
1971 break;
1972 }
1973 }
1974 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
1975 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
1976 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
1977 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
1978 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1979 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1980 setpax = flags;
1981 break;
1982 }
1983 case 'Z': show_size = 1; break;
1984 case 'g': g_match = 1; break;
1985 case 'L': use_ldcache = 1; break;
827 case 'y': scan_symlink = 0; break; 1986 case 'y': scan_symlink = 0; break;
1987 case 'A': scan_archives = 1; break;
1988 case 'C': color_init(true); break;
828 case 'B': show_banner = 0; break; 1989 case 'B': show_banner = 0; break;
829 case 'l': scan_ldpath = 1; break; 1990 case 'l': scan_ldpath = 1; break;
830 case 'p': scan_envpath = 1; break; 1991 case 'p': scan_envpath = 1; break;
831 case 'R': dir_recurse = 1; break; 1992 case 'R': dir_recurse = 1; break;
832 case 'm': dir_crossmount = 0; break; 1993 case 'm': dir_crossmount = 0; break;
1994 case 'X': ++fix_elf; break;
833 case 'x': show_pax = 1; break; 1995 case 'x': show_pax = 1; break;
834 case 'e': show_stack = 1; break; 1996 case 'e': show_phdr = 1; break;
835 case 't': show_textrel = 1; break; 1997 case 't': show_textrel = 1; break;
836 case 'r': show_rpath = 1; break; 1998 case 'r': show_rpath = 1; break;
837 case 'n': show_needed = 1; break; 1999 case 'n': show_needed = 1; break;
838 case 'i': show_interp = 1; break; 2000 case 'i': show_interp = 1; break;
839 case 'b': show_bind = 1; break; 2001 case 'b': show_bind = 1; break;
2002 case 'S': show_soname = 1; break;
2003 case 'T': show_textrels = 1; break;
840 case 'q': be_quiet = 1; break; 2004 case 'q': be_quiet = 1; break;
841 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2005 case 'v': be_verbose = (be_verbose % 20) + 1; break;
842 case 'a': show_pax = show_stack = show_textrel = show_rpath = \ 2006 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
843 show_needed = show_interp = show_bind = 1; break; 2007 case 'D': show_endian = 1; break;
844 2008 case 'I': show_osabi = 1; break;
2009 case 'Y': show_eabi = 1; break;
2010 case 128:
2011 root = optarg;
2012 break;
845 case ':': 2013 case ':':
846 err("Option missing parameter\n"); 2014 err("Option '%c' is missing parameter", optopt);
847 case '?': 2015 case '?':
848 err("Unknown option\n"); 2016 err("Unknown option '%c' or argument missing", optopt);
849 default: 2017 default:
850 err("Unhandled option '%c'", i); 2018 err("Unhandled option '%c'; please report this", i);
851 }
852 } 2019 }
853 2020 }
2021 if (show_textrels && be_verbose) {
2022 if (which("objdump") != NULL)
2023 has_objdump = 1;
2024 }
2025 /* flatten arrays for display */
2026 if (array_cnt(find_lib_arr))
2027 find_lib = array_flatten_str(find_lib_arr);
2028 if (array_cnt(find_section_arr))
2029 find_section = array_flatten_str(find_section_arr);
854 /* let the format option override all other options */ 2030 /* let the format option override all other options */
855 if (out_format) { 2031 if (out_format) {
856 show_pax = show_stack = show_textrel = show_rpath = \ 2032 show_pax = show_phdr = show_textrel = show_rpath = \
857 show_needed = show_interp = show_bind = 0; 2033 show_needed = show_interp = show_bind = show_soname = \
2034 show_textrels = show_perms = show_endian = show_size = \
2035 show_osabi = show_eabi = 0;
858 for (i = 0; out_format[i]; ++i) { 2036 for (i = 0; out_format[i]; ++i) {
859 if (out_format[i] != '%') continue; 2037 if (!IS_MODIFIER(out_format[i])) continue;
860 2038
861 switch (out_format[++i]) { 2039 switch (out_format[++i]) {
2040 case '+': break;
862 case '%': break; 2041 case '%': break;
2042 case '#': break;
863 case 'F': break; 2043 case 'F': break;
2044 case 'p': break;
2045 case 'f': break;
2046 case 'k': break;
864 case 's': break; 2047 case 's': break;
2048 case 'N': break;
865 case 'o': break; 2049 case 'o': break;
2050 case 'a': break;
2051 case 'M': break;
2052 case 'Z': show_size = 1; break;
2053 case 'D': show_endian = 1; break;
2054 case 'I': show_osabi = 1; break;
2055 case 'Y': show_eabi = 1; break;
2056 case 'O': show_perms = 1; break;
866 case 'x': show_pax = 1; break; 2057 case 'x': show_pax = 1; break;
867 case 'e': show_stack = 1; break; 2058 case 'e': show_phdr = 1; break;
868 case 't': show_textrel = 1; break; 2059 case 't': show_textrel = 1; break;
869 case 'r': show_rpath = 1; break; 2060 case 'r': show_rpath = 1; break;
870 case 'n': show_needed = 1; break; 2061 case 'n': show_needed = 1; break;
871 case 'i': show_interp = 1; break; 2062 case 'i': show_interp = 1; break;
872 case 'b': show_bind = 1; break; 2063 case 'b': show_bind = 1; break;
2064 case 'S': show_soname = 1; break;
2065 case 'T': show_textrels = 1; break;
873 default: 2066 default:
874 err("Invalid format specifier '%c' (byte %i)", 2067 err("Invalid format specifier '%c' (byte %i)",
875 out_format[i], i+1); 2068 out_format[i], i+1);
876 } 2069 }
877 } 2070 }
878 2071
879 /* construct our default format */ 2072 /* construct our default format */
880 } else { 2073 } else {
881 size_t fmt_len = 30; 2074 size_t fmt_len = 30;
882 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2075 out_format = xmalloc(sizeof(char) * fmt_len);
2076 *out_format = '\0';
883 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2077 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
884 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2078 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2079 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2080 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2081 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
885 if (show_stack) xstrcat(&out_format, "%e ", &fmt_len); 2082 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2083 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
2084 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
886 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2085 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
887 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2086 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
888 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2087 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
889 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2088 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
890 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2089 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
2090 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
2091 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
891 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2092 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2093 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
2094 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
892 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2095 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
893 } 2096 }
894 if (be_verbose > 2) printf("Format: %s\n", out_format); 2097 if (be_verbose > 2) printf("Format: %s\n", out_format);
895 2098
896 /* now lets actually do the scanning */ 2099 /* now lets actually do the scanning */
897 if (scan_ldpath || (show_rpath && be_quiet)) 2100 if (scan_ldpath || use_ldcache)
898 load_ld_so_conf(); 2101 load_ld_cache_config(0, __PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
899 if (scan_ldpath) scanelf_ldpath(); 2102 if (scan_ldpath) scanelf_ldpath();
900 if (scan_envpath) scanelf_envpath(); 2103 if (scan_envpath) scanelf_envpath();
2104 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2105 from_file = "-";
901 if (from_file) { 2106 if (from_file) {
902 scanelf_from_file(from_file); 2107 scanelf_from_file(from_file);
903 free(from_file);
904 from_file = *argv; 2108 from_file = *argv;
905 } 2109 }
906 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2110 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
907 err("Nothing to scan !?"); 2111 err("Nothing to scan !?");
908 while (optind < argc) 2112 while (optind < argc) {
909 scanelf_dir(argv[optind++]); 2113 search_path = argv[optind++];
2114 ret = scanelf_dir(search_path);
2115 }
910 2116
911 /* clean up */ 2117 /* clean up */
912 if (find_sym) { 2118 xarrayfree(ldpaths);
2119 xarrayfree(find_lib_arr);
2120 xarrayfree(find_section_arr);
913 free(find_sym); 2121 free(find_lib);
914 free(versioned_symname); 2122 free(find_section);
915 }
916 if (out_format) free(out_format);
917 for (i = 0; ldpaths[i]; ++i)
918 free(ldpaths[i]);
919}
920 2123
921 2124 if (ldcache != 0)
922 2125 munmap(ldcache, ldcache_size);
923/* utility funcs */
924static char *xstrdup(const char *s)
925{
926 char *ret = strdup(s);
927 if (!ret) err("Could not strdup(): %s", strerror(errno));
928 return ret; 2126 return ret;
929} 2127}
930 2128
931static void *xmalloc(size_t size) 2129static char **get_split_env(const char *envvar)
932{ 2130{
933 void *ret = malloc(size); 2131 const char *delims = " \t\n";
934 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size); 2132 char **envvals = NULL;
935 return ret; 2133 char *env, *s;
936} 2134 int nentry;
937 2135
938static void xstrcat(char **dst, const char *src, size_t *curr_len) 2136 if ((env = getenv(envvar)) == NULL)
939{ 2137 return NULL;
940 long new_len;
941 2138
942 new_len = strlen(*dst) + strlen(src); 2139 env = xstrdup(env);
943 if (*curr_len <= new_len) { 2140 if (env == NULL)
944 *curr_len = new_len + (*curr_len / 2); 2141 return NULL;
945 *dst = realloc(*dst, *curr_len);
946 if (!*dst)
947 err("could not realloc %li bytes", (unsigned long)*curr_len);
948 }
949 2142
950 strcat(*dst, src); 2143 s = strtok(env, delims);
951} 2144 if (s == NULL) {
2145 free(env);
2146 return NULL;
2147 }
952 2148
953static inline void xchrcat(char **dst, const char append, size_t *curr_len) 2149 nentry = 0;
954{ 2150 while (s != NULL) {
955 static char my_app[2]; 2151 ++nentry;
956 my_app[0] = append; 2152 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
957 my_app[1] = '\0'; 2153 envvals[nentry-1] = s;
958 xstrcat(dst, my_app, curr_len); 2154 s = strtok(NULL, delims);
959} 2155 }
2156 envvals[nentry] = NULL;
960 2157
2158 /* don't want to free(env) as it contains the memory that backs
2159 * the envvals array of strings */
2160 return envvals;
2161}
2162
2163static void parseenv(void)
2164{
2165 color_init(false);
2166 qa_textrels = get_split_env("QA_TEXTRELS");
2167 qa_execstack = get_split_env("QA_EXECSTACK");
2168 qa_wx_load = get_split_env("QA_WX_LOAD");
2169}
2170
2171#ifdef __PAX_UTILS_CLEANUP
2172static void cleanup(void)
2173{
2174 free(out_format);
2175 free(qa_textrels);
2176 free(qa_execstack);
2177 free(qa_wx_load);
2178}
2179#endif
961 2180
962int main(int argc, char *argv[]) 2181int main(int argc, char *argv[])
963{ 2182{
2183 int ret;
964 if (argc < 2) 2184 if (argc < 2)
965 usage(EXIT_FAILURE); 2185 usage(EXIT_FAILURE);
2186 parseenv();
966 parseargs(argc, argv); 2187 ret = parseargs(argc, argv);
967 fclose(stdout); 2188 fclose(stdout);
968#ifdef __BOUNDS_CHECKING_ON 2189#ifdef __PAX_UTILS_CLEANUP
969 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2190 cleanup();
2191 warn("The calls to add/delete heap should be off:\n"
2192 "\t- 1 due to the out_buffer not being freed in scanelf_file()\n"
2193 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
970#endif 2194#endif
971 return EXIT_SUCCESS; 2195 return ret;
972} 2196}
2197
2198/* Match filename against entries in matchlist, return TRUE
2199 * if the file is listed */
2200static int file_matches_list(const char *filename, char **matchlist)
2201{
2202 char **file;
2203 char *match;
2204 char buf[__PAX_UTILS_PATH_MAX];
2205
2206 if (matchlist == NULL)
2207 return 0;
2208
2209 for (file = matchlist; *file != NULL; file++) {
2210 if (search_path) {
2211 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2212 match = buf;
2213 } else {
2214 match = *file;
2215 }
2216 if (fnmatch(match, filename, 0) == 0)
2217 return 1;
2218 }
2219 return 0;
2220}

Legend:
Removed from v.1.63  
changed lines
  Added in v.1.229

  ViewVC Help
Powered by ViewVC 1.1.20