/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.32 Revision 1.254
1/* 1/*
2 * Copyright 2003 Ned Ludd <solar@gentoo.org>
3 * Copyright 1999-2005 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
4 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
5 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.32 2005/04/07 00:01:40 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.254 2013/04/02 21:13:05 vapier Exp $
6 * 5 *
7 ******************************************************************** 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
8 * This program is free software; you can redistribute it and/or 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
9 * modify it under the terms of the GNU General Public License as
10 * published by the Free Software Foundation; either version 2 of the
11 * License, or (at your option) any later version.
12 *
13 * This program is distributed in the hope that it will be useful, but
14 * WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 * General Public License for more details.
17 *
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place - Suite 330, Boston,
21 * MA 02111-1307, USA.
22 */ 8 */
23 9
24#include <stdio.h>
25#include <stdlib.h>
26#include <sys/types.h>
27#define __USE_GNU
28#include <string.h>
29#include <errno.h>
30#include <unistd.h>
31#include <sys/stat.h>
32#include <dirent.h>
33#include <getopt.h>
34#include <assert.h>
35
36#include "paxelf.h"
37
38static const char *rcsid = "$Id: scanelf.c,v 1.32 2005/04/07 00:01:40 vapier Exp $"; 10static const char rcsid[] = "$Id: scanelf.c,v 1.254 2013/04/02 21:13:05 vapier Exp $";
11const char argv0[] = "scanelf";
39 12
13#include "paxinc.h"
40 14
41/* helper functions for showing errors */ 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
42#define argv0 "scanelf" /*((*argv != NULL) ? argv[0] : __FILE__ "\b\b")*/
43#define warn(fmt, args...) \
44 fprintf(stderr, "%s: " fmt "\n", argv0, ## args)
45#define warnf(fmt, args...) warn("%s(): " fmt, __FUNCTION__, ## args)
46#define err(fmt, args...) \
47 do { \
48 warn(fmt, ## args); \
49 exit(EXIT_FAILURE); \
50 } while (0)
51
52
53 16
54/* prototypes */ 17/* prototypes */
55static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
56static void scanelf_dir(const char *path);
57static void scanelf_ldpath();
58static void scanelf_envpath();
59static void usage(int status);
60static void parseargs(int argc, char *argv[]);
61 19
62/* variables to control behavior */ 20/* variables to control behavior */
21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
63static char scan_ldpath = 0; 23static char scan_ldpath = 0;
64static char scan_envpath = 0; 24static char scan_envpath = 0;
25static char scan_symlink = 1;
26static char scan_archives = 0;
65static char dir_recurse = 0; 27static char dir_recurse = 0;
66static char dir_crossmount = 1; 28static char dir_crossmount = 1;
67static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
68static char show_stack = 0; 31static char show_size = 0;
32static char show_phdr = 0;
69static char show_textrel = 0; 33static char show_textrel = 0;
70static char show_rpath = 0; 34static char show_rpath = 0;
71static char show_needed = 0; 35static char show_needed = 0;
36static char show_interp = 0;
37static char show_bind = 0;
38static char show_soname = 0;
39static char show_textrels = 0;
72static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
73static char be_quiet = 0; 44static char be_quiet = 0;
74static char be_verbose = 0; 45static char be_verbose = 0;
46static char be_wewy_wewy_quiet = 0;
47static char be_semi_verbose = 0;
75static char *find_sym = NULL; 48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
55static char *out_format = NULL;
56static char *search_path = NULL;
57static char fix_elf = 0;
58static char g_match = 0;
59static char use_ldcache = 0;
60static char use_ldpath = 0;
76 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
77 66
67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
78 72
79/* scan an elf file and show all the fun stuff */ 73static int has_objdump = 0;
80static void scanelf_file(const char *filename)
81{
82 int i;
83 char found_pax, found_stack, found_relro, found_textrel,
84 found_rpath, found_needed, found_sym;
85 elfobj *elf;
86 74
87 found_pax = found_stack = found_relro = found_textrel = \ 75/* find the path to a file by name */
88 found_rpath = found_needed = found_sym = 0; 76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
89 80
90 /* verify this is real ELF */ 81 path = getenv("PATH");
91 if ((elf = readelf(filename)) == NULL) { 82 if (!path)
92 if (be_verbose > 2) printf("%s: not an ELF\n", filename); 83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
123/* sub-funcs for scanelf_fileat() */
124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
125{
126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
141#define GET_SYMTABS(B) \
142 if (elf->elf_class == ELFCLASS ## B) { \
143 Elf ## B ## _Shdr *esymtab = symtab; \
144 Elf ## B ## _Shdr *estrtab = strtab; \
145 Elf ## B ## _Shdr *edynsym = dynsym; \
146 Elf ## B ## _Shdr *edynstr = dynstr; \
147 \
148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
152 if (symtab && dynsym) \
153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
154 else \
155 *sym = symtab ? symtab : dynsym; \
156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
161 if (strtab && dynstr) \
162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
163 else \
164 *str = strtab ? strtab : dynstr; \
165 }
166 GET_SYMTABS(32)
167 GET_SYMTABS(64)
168
169 if (*sym && *str)
93 return; 170 return;
94 }
95 171
96 if (be_verbose > 1) 172 /*
97 printf("%s: {%s,%s} scanning file\n", filename, 173 * damn, they're really going to make us work for it huh?
98 get_elfeitype(elf, EI_CLASS, elf->elf_class), 174 * reconstruct the section header info out of the dynamic
99 get_elfeitype(elf, EI_DATA, elf->data[EI_DATA])); 175 * tags so we can see what symbols this guy uses at runtime.
100 else if (be_verbose) 176 */
101 printf("%s: scanning file\n", filename); 177#define GET_SYMTABS_DT(B) \
102
103 /* show the header */
104 if (!be_quiet && show_banner) {
105 printf(" TYPE ");
106 if (show_pax) printf(" PAX ");
107 if (show_stack) printf("STK/REL ");
108 if (show_textrel) printf("TEXTREL ");
109 if (show_rpath) printf("RPATH ");
110 if (show_needed) printf("NEEDED ");
111 printf(" FILE\n");
112 show_banner = 0;
113 }
114
115 /* dump all the good stuff */
116 if (!be_quiet)
117 printf("%-7s ", get_elfetype(elf));
118
119 if (show_pax) {
120 char *paxflags = pax_short_hf_flags(PAX_FLAGS(elf));
121 if (!be_quiet || (be_quiet && strncmp(paxflags, "PeMRxS", 6))) {
122 found_pax = 1;
123 printf("%s ", pax_short_hf_flags(PAX_FLAGS(elf)));
124 }
125 }
126
127 /* stack fun */
128 if (show_stack) {
129#define SHOW_STACK(B) \
130 if (elf->elf_class == ELFCLASS ## B) { \ 178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
131 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
259}
260
261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
262{
263 static char ret[7];
264 unsigned long i, shown;
265
266 if (!show_pax) return NULL;
267
268 shown = 0;
269 memset(&ret, 0, sizeof(ret));
270
271 if (elf->phdr) {
272#define SHOW_PAX(B) \
273 if (elf->elf_class == ELFCLASS ## B) { \
274 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
275 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
276 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
277 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
278 continue; \
279 if (fix_elf && setpax) { \
280 /* set the paxctl flags */ \
281 ESET(phdr[i].p_flags, setpax); \
282 } \
283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
284 continue; \
285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
286 *found_pax = 1; \
287 ++shown; \
288 break; \
289 } \
290 }
291 SHOW_PAX(32)
292 SHOW_PAX(64)
293 }
294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
301
302 /* fall back to EI_PAX if no PT_PAX was found */
303 if (!*ret) {
304 static char *paxflags;
305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
306 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
307 *found_pax = 1;
308 return (be_wewy_wewy_quiet ? NULL : paxflags);
309 }
310 strncpy(ret, paxflags, sizeof(ret));
311 }
312
313 if (be_wewy_wewy_quiet || (be_quiet && !shown))
314 return NULL;
315 else
316 return ret;
317}
318
319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
320{
321 static char ret[12];
322 char *found;
323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
324
325 if (!show_phdr) return NULL;
326
327 memcpy(ret, "--- --- ---\0", 12);
328
329 shown = 0;
330 multi_stack = multi_relro = multi_load = 0;
331
332#define NOTE_GNU_STACK ".note.GNU-stack"
333#define SHOW_PHDR(B) \
334 if (elf->elf_class == ELFCLASS ## B) { \
335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
336 Elf ## B ## _Off offset; \
337 uint32_t flags, check_flags; \
338 if (elf->phdr != NULL) { \
132 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
133 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
134 if (EGET(phdr[i].p_type) != PT_GNU_STACK && \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
346 found = found_phdr; \
347 offset = 0; \
348 check_flags = PF_X; \
135 EGET(phdr[i].p_type) != PT_GNU_RELRO) continue; \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
136 if (be_quiet && !(EGET(phdr[i].p_flags) & PF_X)) \ 350 if (multi_relro++) \
351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
352 found = found_relro; \
353 offset = 4; \
354 check_flags = PF_X; \
355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
356 if (file_matches_list(elf->filename, qa_wx_load)) \
357 continue; \
358 found = found_load; \
359 offset = 8; \
360 check_flags = PF_W|PF_X; \
361 } else \
137 continue; \ 362 continue; \
138 if (EGET(phdr[i].p_type) == PT_GNU_STACK) \ 363 flags = EGET(phdr[i].p_flags); \
364 if (be_quiet && ((flags & check_flags) != check_flags)) \
365 continue; \
366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
368 ret[3] = ret[7] = '!'; \
369 flags = EGET(phdr[i].p_flags); \
370 } \
371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
139 found_stack = 1; \ 372 *found = 1; \
140 if (EGET(phdr[i].p_type) == PT_GNU_RELRO) \ 373 ++shown; \
141 found_relro = 1; \
142 printf("%s ", gnu_short_stack_flags(EGET(phdr[i].p_flags))); \
143 } \ 374 } \
375 } else if (elf->shdr != NULL) { \
376 /* no program headers which means this is prob an object file */ \
377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
379 char *str; \
380 if ((void*)strtbl > elf->data_end) \
381 goto skip_this_shdr##B; \
382 check_flags = SHF_WRITE|SHF_EXECINSTR; \
383 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
384 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
385 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
386 str = elf->data + offset; \
387 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
388 if (!strcmp(str, NOTE_GNU_STACK)) { \
389 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
390 flags = EGET(shdr[i].sh_flags); \
391 if (be_quiet && ((flags & check_flags) != check_flags)) \
392 continue; \
393 ++*found_phdr; \
394 shown = 1; \
395 if (flags & SHF_WRITE) ret[0] = 'W'; \
396 if (flags & SHF_ALLOC) ret[1] = 'A'; \
397 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
398 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
399 break; \
400 } \
401 } \
402 skip_this_shdr##B: \
403 if (!multi_stack) { \
404 if (file_matches_list(elf->filename, qa_execstack)) \
405 return NULL; \
406 *found_phdr = 1; \
407 shown = 1; \
408 memcpy(ret, "!WX", 3); \
409 } \
410 } \
144 } 411 }
145 SHOW_STACK(32) 412 SHOW_PHDR(32)
146 SHOW_STACK(64) 413 SHOW_PHDR(64)
147 if (!be_quiet && !found_stack) printf("--- ");
148 if (!be_quiet && !found_relro) printf("--- ");
149 }
150 414
151 /* textrel fun */ 415 if (be_wewy_wewy_quiet || (be_quiet && !shown))
152 if (show_textrel) { 416 return NULL;
417 else
418 return ret;
419}
420
421/*
422 * See if this ELF contains a DT_TEXTREL tag in any of its
423 * PT_DYNAMIC sections.
424 */
425static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
426{
427 static const char *ret = "TEXTREL";
428 unsigned long i;
429
430 if (!show_textrel && !show_textrels) return NULL;
431
432 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
433
434 if (elf->phdr) {
153#define SHOW_TEXTREL(B) \ 435#define SHOW_TEXTREL(B) \
154 if (elf->elf_class == ELFCLASS ## B) { \ 436 if (elf->elf_class == ELFCLASS ## B) { \
155 Elf ## B ## _Dyn *dyn; \ 437 Elf ## B ## _Dyn *dyn; \
156 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 438 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
157 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 439 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
440 Elf ## B ## _Off offset; \
158 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 441 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
159 if (phdr[i].p_type != PT_DYNAMIC) continue; \ 442 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
443 offset = EGET(phdr[i].p_offset); \
444 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
160 dyn = DYN ## B (elf->data + EGET(phdr[i].p_offset)); \ 445 dyn = DYN ## B (elf->vdata + offset); \
161 while (EGET(dyn->d_tag) != DT_NULL) { \ 446 while (EGET(dyn->d_tag) != DT_NULL) { \
162 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 447 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
163 found_textrel = 1; \ 448 *found_textrel = 1; \
164 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 449 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
165 printf("TEXTREL "); \ 450 return (be_wewy_wewy_quiet ? NULL : ret); \
451 } \
452 ++dyn; \
453 } \
454 } }
455 SHOW_TEXTREL(32)
456 SHOW_TEXTREL(64)
457 }
458
459 if (be_quiet || be_wewy_wewy_quiet)
460 return NULL;
461 else
462 return " - ";
463}
464
465/*
466 * Scan the .text section to see if there are any relocations in it.
467 * Should rewrite this to check PT_LOAD sections that are marked
468 * Executable rather than the section named '.text'.
469 */
470static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
471{
472 unsigned long s, r, rmax;
473 void *symtab_void, *strtab_void, *text_void;
474
475 if (!show_textrels) return NULL;
476
477 /* don't search for TEXTREL's if the ELF doesn't have any */
478 if (!*found_textrel) scanelf_file_textrel(elf, found_textrel);
479 if (!*found_textrel) return NULL;
480
481 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
482 text_void = elf_findsecbyname(elf, ".text");
483
484 if (symtab_void && strtab_void && text_void && elf->shdr) {
485#define SHOW_TEXTRELS(B) \
486 if (elf->elf_class == ELFCLASS ## B) { \
487 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
488 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
489 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
490 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
491 Elf ## B ## _Shdr *text = SHDR ## B (text_void); \
492 Elf ## B ## _Addr vaddr = EGET(text->sh_addr); \
493 uint ## B ## _t memsz = EGET(text->sh_size); \
494 Elf ## B ## _Rel *rel; \
495 Elf ## B ## _Rela *rela; \
496 /* search the section headers for relocations */ \
497 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
498 uint32_t sh_type = EGET(shdr[s].sh_type); \
499 if (sh_type == SHT_REL) { \
500 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
501 rela = NULL; \
502 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
503 } else if (sh_type == SHT_RELA) { \
504 rel = NULL; \
505 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
506 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
507 } else \
508 continue; \
509 /* now see if any of the relocs are in the .text */ \
510 for (r = 0; r < rmax; ++r) { \
511 unsigned long sym_max; \
512 Elf ## B ## _Addr offset_tmp; \
513 Elf ## B ## _Sym *func; \
514 Elf ## B ## _Sym *sym; \
515 Elf ## B ## _Addr r_offset; \
516 uint ## B ## _t r_info; \
517 if (sh_type == SHT_REL) { \
518 r_offset = EGET(rel[r].r_offset); \
519 r_info = EGET(rel[r].r_info); \
520 } else { \
521 r_offset = EGET(rela[r].r_offset); \
522 r_info = EGET(rela[r].r_info); \
523 } \
524 /* make sure this relocation is inside of the .text */ \
525 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
526 if (be_verbose <= 2) continue; \
527 } else \
528 *found_textrels = 1; \
529 /* locate this relocation symbol name */ \
530 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
531 if ((void*)sym > elf->data_end) { \
532 warn("%s: corrupt ELF symbol", elf->filename); \
533 continue; \
534 } \
535 sym_max = ELF ## B ## _R_SYM(r_info); \
536 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
537 sym += sym_max; \
538 else \
539 sym = NULL; \
540 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
541 /* show the raw details about this reloc */ \
542 printf(" %s: ", elf->base_filename); \
543 if (sym && sym->st_name) \
544 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
545 else \
546 printf("(memory/data?)"); \
547 printf(" [0x%lX]", (unsigned long)r_offset); \
548 /* now try to find the closest symbol that this rel is probably in */ \
549 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
550 func = NULL; \
551 offset_tmp = 0; \
552 while (sym_max--) { \
553 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
554 func = sym; \
555 offset_tmp = EGET(sym->st_value); \
166 } \ 556 } \
167 ++dyn; \ 557 ++sym; \
168 } \ 558 } \
559 printf(" in "); \
560 if (func && func->st_name) { \
561 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
562 if (r_offset > EGET(func->st_size)) \
563 printf("(optimized out: previous %s)", func_name); \
564 else \
565 printf("%s", func_name); \
566 } else \
567 printf("(optimized out)"); \
568 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
569 if (be_verbose && has_objdump) { \
570 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
571 char *sysbuf; \
572 size_t syslen; \
573 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
574 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
575 sysbuf = xmalloc(syslen); \
576 if (end_addr < r_offset) \
577 /* not uncommon when things are optimized out */ \
578 end_addr = r_offset + 0x100; \
579 snprintf(sysbuf, syslen, sysfmt, \
580 (unsigned long)offset_tmp, \
581 (unsigned long)end_addr, \
582 elf->filename, \
583 (unsigned long)r_offset); \
584 fflush(stdout); \
585 if (system(sysbuf)) /* don't care */; \
586 fflush(stdout); \
587 free(sysbuf); \
588 } \
589 } \
169 } } 590 } }
170 SHOW_TEXTREL(32) 591 SHOW_TEXTRELS(32)
171 SHOW_TEXTREL(64) 592 SHOW_TEXTRELS(64)
172 if (!be_quiet && !found_textrel) printf("------- ");
173 } 593 }
594 if (!*found_textrels)
595 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
174 596
175 /* rpath fun */ 597 return NULL;
176 /* TODO: if be_quiet, only output RPATH's which aren't in /etc/ld.so.conf */ 598}
177 if (show_rpath) { 599
600static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
601{
602 struct stat st;
603 switch (*item) {
604 case '/': break;
605 case '.':
606 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
607 break;
608 case ':':
609 case '\0':
610 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
611 break;
612 case '$':
613 if (fstat(elf->fd, &st) != -1)
614 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
615 warnf("Security problem with %s='%s' in %s with mode set of %o",
616 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
617 break;
618 default:
619 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
620 break;
621 }
622}
623static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
624{
625 unsigned long i;
178 char *rpath, *runpath; 626 char *rpath, *runpath, **r;
627 void *strtbl_void;
628
629 if (!show_rpath) return;
630
179 void *strtbl_void = elf_findsecbyname(elf, ".dynstr"); 631 strtbl_void = elf_findsecbyname(elf, ".dynstr");
180 rpath = runpath = NULL; 632 rpath = runpath = NULL;
181 633
182 if (strtbl_void) { 634 if (elf->phdr && strtbl_void) {
183#define SHOW_RPATH(B) \ 635#define SHOW_RPATH(B) \
184 if (elf->elf_class == ELFCLASS ## B) { \ 636 if (elf->elf_class == ELFCLASS ## B) { \
185 Elf ## B ## _Dyn *dyn; \ 637 Elf ## B ## _Dyn *dyn; \
186 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 638 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
187 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 639 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
188 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 640 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
641 Elf ## B ## _Off offset; \
642 Elf ## B ## _Xword word; \
643 /* Scan all the program headers */ \
189 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 644 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
645 /* Just scan dynamic headers */ \
190 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 646 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
647 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 /* Just scan dynamic RPATH/RUNPATH headers */ \
191 dyn = DYN ## B (elf->data + EGET(phdr[i].p_offset)); \ 650 dyn = DYN ## B (elf->vdata + offset); \
192 while (EGET(dyn->d_tag) != DT_NULL) { \ 651 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
193 if (EGET(dyn->d_tag) == DT_RPATH) { \ 652 if (word == DT_RPATH) { \
653 r = &rpath; \
654 } else if (word == DT_RUNPATH) { \
655 r = &runpath; \
656 } else { \
657 ++dyn; \
658 continue; \
659 } \
660 /* Verify the memory is somewhat sane */ \
194 rpath = elf->data + EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 661 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
662 if (offset < (Elf ## B ## _Off)elf->len) { \
663 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
664 *r = elf->data + offset; \
665 /* cache the length in case we need to nuke this section later on */ \
666 if (fix_elf) \
667 offset = strlen(*r); \
668 /* If quiet, don't output paths in ld.so.conf */ \
669 if (be_quiet) { \
670 size_t len; \
671 char *start, *end; \
672 /* note that we only 'chop' off leading known paths. */ \
673 /* since *r is read-only memory, we can only move the ptr forward. */ \
674 start = *r; \
675 /* scan each path in : delimited list */ \
676 while (start) { \
677 rpath_security_checks(elf, start, get_elfdtype(word)); \
678 end = strchr(start, ':'); \
679 len = (end ? abs(end - start) : strlen(start)); \
680 if (use_ldcache) { \
681 size_t n; \
682 const char *ldpath; \
683 array_for_each(ldpaths, n, ldpath) \
684 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
685 *r = end; \
686 /* corner case ... if RPATH reads "/usr/lib:", we want \
687 * to show ':' rather than '' */ \
688 if (end && end[1] != '\0') \
689 (*r)++; \
690 break; \
691 } \
692 } \
693 if (!*r || !end) \
694 break; \
695 else \
696 start = start + len + 1; \
697 } \
698 } \
699 if (*r) { \
700 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
701 /* just nuke it */ \
702 nuke_it##B: \
703 memset(*r, 0x00, offset); \
704 *r = NULL; \
705 ESET(dyn->d_tag, DT_DEBUG); \
706 ESET(dyn->d_un.d_ptr, 0); \
707 } else if (fix_elf) { \
708 /* try to clean "bad" paths */ \
709 size_t len, tmpdir_len; \
710 char *start, *end; \
711 const char *tmpdir; \
712 start = *r; \
713 tmpdir = (getenv("TMPDIR") ? : "."); \
714 tmpdir_len = strlen(tmpdir); \
715 while (1) { \
716 end = strchr(start, ':'); \
717 if (start == end) { \
718 eat_this_path##B: \
719 len = strlen(end); \
720 memmove(start, end+1, len); \
721 start[len-1] = '\0'; \
722 end = start - 1; \
723 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
724 if (!end) { \
725 if (start == *r) \
726 goto nuke_it##B; \
727 *--start = '\0'; \
728 } else \
729 goto eat_this_path##B; \
730 } \
731 if (!end) \
732 break; \
733 start = end + 1; \
734 } \
735 if (**r == '\0') \
736 goto nuke_it##B; \
737 } \
738 if (*r) \
195 found_rpath = 1; \ 739 *found_rpath = 1; \
196 } else if (EGET(dyn->d_tag) == DT_RUNPATH) { \ 740 } \
197 runpath = elf->data + EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
198 found_rpath = 1; \
199 } \ 741 } \
200 ++dyn; \ 742 ++dyn; \
201 } \ 743 } \
202 } } 744 } }
203 SHOW_RPATH(32) 745 SHOW_RPATH(32)
204 SHOW_RPATH(64) 746 SHOW_RPATH(64)
205 } 747 }
748
749 if (be_wewy_wewy_quiet) return;
750
206 if (rpath && runpath) { 751 if (rpath && runpath) {
207 if (!strcmp(rpath, runpath)) 752 if (!strcmp(rpath, runpath)) {
208 printf("%-5s ", runpath); 753 xstrcat(ret, runpath, ret_len);
209 else { 754 } else {
210 fprintf(stderr, "%s's RPATH [%s] != RUNPATH [%s]\n", filename, rpath, runpath); 755 fprintf(stderr, "RPATH [%s] != RUNPATH [%s]\n", rpath, runpath);
211 printf("{%s,%s} ", rpath, runpath); 756 xchrcat(ret, '{', ret_len);
757 xstrcat(ret, rpath, ret_len);
758 xchrcat(ret, ',', ret_len);
759 xstrcat(ret, runpath, ret_len);
760 xchrcat(ret, '}', ret_len);
212 } 761 }
213 } else if (rpath || runpath) 762 } else if (rpath || runpath)
214 printf("%-5s ", (runpath ? runpath : rpath)); 763 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
215 else if (!be_quiet && !found_rpath) 764 else if (!be_quiet)
216 printf(" - "); 765 xstrcat(ret, " - ", ret_len);
766}
767
768/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
769#define LDSO_CACHE_MAGIC "ld.so-"
770#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
771#define LDSO_CACHE_VER "1.7.0"
772#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
773#define FLAG_ANY -1
774#define FLAG_TYPE_MASK 0x00ff
775#define FLAG_LIBC4 0x0000
776#define FLAG_ELF 0x0001
777#define FLAG_ELF_LIBC5 0x0002
778#define FLAG_ELF_LIBC6 0x0003
779#define FLAG_REQUIRED_MASK 0xff00
780#define FLAG_SPARC_LIB64 0x0100
781#define FLAG_IA64_LIB64 0x0200
782#define FLAG_X8664_LIB64 0x0300
783#define FLAG_S390_LIB64 0x0400
784#define FLAG_POWERPC_LIB64 0x0500
785#define FLAG_MIPS64_LIBN32 0x0600
786#define FLAG_MIPS64_LIBN64 0x0700
787#define FLAG_X8664_LIBX32 0x0800
788#define FLAG_ARM_LIBHF 0x0900
789#define FLAG_AARCH64_LIB64 0x0a00
790
791#if defined(__GLIBC__) || defined(__UCLIBC__)
792
793static char *lookup_cache_lib(elfobj *elf, const char *fname)
794{
795 int fd;
796 char *strs;
797 static char buf[__PAX_UTILS_PATH_MAX] = "";
798 const char *cachefile = root_rel_path("/etc/ld.so.cache");
799 struct stat st;
800
801 typedef struct {
802 char magic[LDSO_CACHE_MAGIC_LEN];
803 char version[LDSO_CACHE_VER_LEN];
804 int nlibs;
805 } header_t;
806 header_t *header;
807
808 typedef struct {
809 int flags;
810 int sooffset;
811 int liboffset;
812 } libentry_t;
813 libentry_t *libent;
814
815 if (fname == NULL)
816 return NULL;
817
818 if (ldcache == NULL) {
819 if (fstatat(root_fd, cachefile, &st, 0))
820 return NULL;
821
822 fd = openat(root_fd, cachefile, O_RDONLY);
823 if (fd == -1)
824 return NULL;
825
826 /* cache these values so we only map/unmap the cache file once */
827 ldcache_size = st.st_size;
828 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
829 close(fd);
830
831 if (ldcache == MAP_FAILED) {
832 ldcache = NULL;
833 return NULL;
217 } 834 }
218 835
219 /* print out all the NEEDED entries */ 836 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
220 if (show_needed) { 837 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
838 {
839 munmap(ldcache, ldcache_size);
840 ldcache = NULL;
841 return NULL;
842 }
843 } else
844 header = ldcache;
845
846 libent = ldcache + sizeof(header_t);
847 strs = (char *) &libent[header->nlibs];
848
849 for (fd = 0; fd < header->nlibs; ++fd) {
850 /* This should be more fine grained, but for now we assume that
851 * diff arches will not be cached together, and we ignore the
852 * the different multilib mips cases.
853 */
854 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
855 continue;
856 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
857 continue;
858
859 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
860 continue;
861
862 /* Return first hit because that is how the ldso rolls */
863 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
864 break;
865 }
866
867 return buf;
868}
869
870#elif defined(__NetBSD__)
871static char *lookup_cache_lib(elfobj *elf, const char *fname)
872{
873 static char buf[__PAX_UTILS_PATH_MAX] = "";
874 static struct stat st;
875 size_t n;
876 char *ldpath;
877
878 array_for_each(ldpath, n, ldpath) {
879 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
880 continue; /* if the pathname is too long, or something went wrong, ignore */
881
882 if (stat(buf, &st) != 0)
883 continue; /* if the lib doesn't exist in *ldpath, look further */
884
885 /* NetBSD doesn't actually do sanity checks, it just loads the file
886 * and if that doesn't work, continues looking in other directories.
887 * This cannot easily be safely emulated, unfortunately. For now,
888 * just assume that if it exists, it's a valid library. */
889
890 return buf;
891 }
892
893 /* not found in any path */
894 return NULL;
895}
896#else
897#ifdef __ELF__
898#warning Cache support not implemented for your target
899#endif
900static char *lookup_cache_lib(elfobj *elf, const char *fname)
901{
902 return NULL;
903}
904#endif
905
906static char *lookup_config_lib(elfobj *elf, char *fname)
907{
908 static char buf[__PAX_UTILS_PATH_MAX] = "";
909 const char *ldpath;
910 size_t n;
911
912 array_for_each(ldpaths, n, ldpath) {
913 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
914 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
915 return buf;
916 }
917
918 return NULL;
919}
920
921static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
922{
923 unsigned long i;
221 char *needed; 924 char *needed;
925 void *strtbl_void;
926 char *p;
927
928 /*
929 * -n -> op==0 -> print all
930 * -N -> op==1 -> print requested
931 */
932 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
933 return NULL;
934
222 void *strtbl_void = elf_findsecbyname(elf, ".dynstr"); 935 strtbl_void = elf_findsecbyname(elf, ".dynstr");
223 936
224 if (strtbl_void) { 937 if (elf->phdr && strtbl_void) {
225#define SHOW_NEEDED(B) \ 938#define SHOW_NEEDED(B) \
226 if (elf->elf_class == ELFCLASS ## B) { \ 939 if (elf->elf_class == ELFCLASS ## B) { \
227 Elf ## B ## _Dyn *dyn; \ 940 Elf ## B ## _Dyn *dyn; \
228 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 941 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
229 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 942 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
230 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 943 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
944 Elf ## B ## _Off offset; \
945 size_t matched = 0; \
946 /* Walk all the program headers to find the PT_DYNAMIC */ \
231 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 947 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
232 if (be_verbose && EGET(phdr[i].p_type) == PT_INTERP) { \ 948 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
233 dyn = DYN ## B (elf->data + EGET(phdr[i].p_offset)); \ 949 continue; \
234 printf("%s\n", elf->data + EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr)); \ 950 offset = EGET(phdr[i].p_offset); \
235 exit(0); \ 951 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
236 } \ 952 continue; \
237 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 953 /* Walk all the dynamic tags to find NEEDED entries */ \
238 dyn = DYN ## B (elf->data + EGET(phdr[i].p_offset)); \ 954 dyn = DYN ## B (elf->vdata + offset); \
239 while (EGET(dyn->d_tag) != DT_NULL) { \ 955 while (EGET(dyn->d_tag) != DT_NULL) { \
240 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 956 if (EGET(dyn->d_tag) == DT_NEEDED) { \
241 needed = elf->data + EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 957 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
242 if (found_needed) printf(","); \ 958 if (offset >= (Elf ## B ## _Off)elf->len) { \
243 printf("%s", needed); \ 959 ++dyn; \
960 continue; \
961 } \
962 needed = elf->data + offset; \
963 if (op == 0) { \
964 /* -n -> print all entries */ \
965 if (!be_wewy_wewy_quiet) { \
966 if (*found_needed) xchrcat(ret, ',', ret_len); \
967 if (use_ldpath) { \
968 if ((p = lookup_config_lib(elf, needed)) != NULL) \
969 needed = p; \
970 } else if (use_ldcache) { \
971 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
972 needed = p; \
973 } \
974 xstrcat(ret, needed, ret_len); \
975 } \
244 found_needed = 1; \ 976 *found_needed = 1; \
977 } else { \
978 /* -N -> print matching entries */ \
979 size_t n; \
980 const char *find_lib_name; \
981 \
982 array_for_each(find_lib_arr, n, find_lib_name) { \
983 int invert = 1; \
984 if (find_lib_name[0] == '!') \
985 invert = 0, ++find_lib_name; \
986 if (!strcmp(find_lib_name, needed) == invert) \
987 ++matched; \
988 } \
989 \
990 if (matched == array_cnt(find_lib_arr)) { \
991 *found_lib = 1; \
992 return (be_wewy_wewy_quiet ? NULL : find_lib); \
993 } \
994 } \
245 } \ 995 } \
246 ++dyn; \ 996 ++dyn; \
247 } \ 997 } \
248 } } 998 } }
249 SHOW_NEEDED(32) 999 SHOW_NEEDED(32)
250 SHOW_NEEDED(64) 1000 SHOW_NEEDED(64)
1001 if (op == 0 && !*found_needed && be_verbose)
1002 warn("ELF lacks DT_NEEDED sections: %s", elf->filename);
1003 }
1004
1005 return NULL;
1006}
1007static char *scanelf_file_interp(elfobj *elf, char *found_interp)
1008{
1009 void *strtbl_void;
1010
1011 if (!show_interp) return NULL;
1012
1013 strtbl_void = elf_findsecbyname(elf, ".interp");
1014
1015 if (strtbl_void) {
1016#define SHOW_INTERP(B) \
1017 if (elf->elf_class == ELFCLASS ## B) { \
1018 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
1019 *found_interp = 1; \
1020 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
1021 }
1022 SHOW_INTERP(32)
1023 SHOW_INTERP(64)
1024 } else {
1025 /* Walk all the program headers to find the PT_INTERP */
1026#define SHOW_PT_INTERP(B) \
1027 if (elf->elf_class == ELFCLASS ## B) { \
1028 unsigned long i; \
1029 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1030 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1031 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1032 if (EGET(phdr[i].p_type) != PT_INTERP) \
1033 continue; \
1034 *found_interp = 1; \
1035 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1036 } \
1037 }
1038 SHOW_PT_INTERP(32)
1039 SHOW_PT_INTERP(64)
1040 }
1041
1042 return NULL;
1043}
1044static char *scanelf_file_bind(elfobj *elf, char *found_bind)
1045{
1046 unsigned long i;
1047 struct stat s;
1048 char dynamic = 0;
1049
1050 if (!show_bind) return NULL;
1051 if (!elf->phdr) return NULL;
1052
1053#define SHOW_BIND(B) \
1054 if (elf->elf_class == ELFCLASS ## B) { \
1055 Elf ## B ## _Dyn *dyn; \
1056 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1057 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1058 Elf ## B ## _Off offset; \
1059 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1060 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1061 dynamic = 1; \
1062 offset = EGET(phdr[i].p_offset); \
1063 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
1064 dyn = DYN ## B (elf->vdata + offset); \
1065 while (EGET(dyn->d_tag) != DT_NULL) { \
1066 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
1067 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
1068 { \
1069 if (be_quiet) return NULL; \
1070 *found_bind = 1; \
1071 return (char *)(be_wewy_wewy_quiet ? NULL : "NOW"); \
1072 } \
1073 ++dyn; \
1074 } \
1075 } \
1076 }
1077 SHOW_BIND(32)
1078 SHOW_BIND(64)
1079
1080 if (be_wewy_wewy_quiet) return NULL;
1081
1082 /* don't output anything if quiet mode and the ELF is static or not setuid */
1083 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
1084 return NULL;
1085 } else {
1086 *found_bind = 1;
1087 return (char *)(dynamic ? "LAZY" : "STATIC");
1088 }
1089}
1090static char *scanelf_file_soname(elfobj *elf, char *found_soname)
1091{
1092 unsigned long i;
1093 char *soname;
1094 void *strtbl_void;
1095
1096 if (!show_soname) return NULL;
1097
1098 strtbl_void = elf_findsecbyname(elf, ".dynstr");
1099
1100 if (elf->phdr && strtbl_void) {
1101#define SHOW_SONAME(B) \
1102 if (elf->elf_class == ELFCLASS ## B) { \
1103 Elf ## B ## _Dyn *dyn; \
1104 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1105 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1106 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
1107 Elf ## B ## _Off offset; \
1108 /* only look for soname in shared objects */ \
1109 if (EGET(ehdr->e_type) != ET_DYN) \
1110 return NULL; \
1111 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1112 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1113 offset = EGET(phdr[i].p_offset); \
1114 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
1115 dyn = DYN ## B (elf->vdata + offset); \
1116 while (EGET(dyn->d_tag) != DT_NULL) { \
1117 if (EGET(dyn->d_tag) == DT_SONAME) { \
1118 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
1119 if (offset >= (Elf ## B ## _Off)elf->len) { \
1120 ++dyn; \
1121 continue; \
1122 } \
1123 soname = elf->data + offset; \
1124 *found_soname = 1; \
1125 return (be_wewy_wewy_quiet ? NULL : soname); \
1126 } \
1127 ++dyn; \
1128 } \
1129 } }
1130 SHOW_SONAME(32)
1131 SHOW_SONAME(64)
1132 }
1133
1134 return NULL;
1135}
1136
1137/*
1138 * We support the symbol form:
1139 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1140 * If the symbol name is empty, then all symbols are matched.
1141 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1142 * Do not rely on this output format at all.
1143 * Otherwise the symbol name is used to search (either regex or string compare).
1144 * If the first char of the symbol name is a plus ("+"), then only match
1145 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1146 * Putting modifiers in between the percent signs allows for more in depth
1147 * filters. There are groups of modifiers. If you don't specify a member
1148 * of a group, then all types in that group are matched. The current
1149 * groups and their types are:
1150 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1151 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1152 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1153 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1154 * You can search for multiple symbols at once by seperating with a comma (",").
1155 *
1156 * Some examples:
1157 * ELFs with a weak function "foo":
1158 * scanelf -s %wf%foo <ELFs>
1159 * ELFs that define the symbol "main":
1160 * scanelf -s +main <ELFs>
1161 * scanelf -s %d%main <ELFs>
1162 * ELFs that refer to the undefined symbol "brk":
1163 * scanelf -s -brk <ELFs>
1164 * scanelf -s %u%brk <ELFs>
1165 * All global defined objects in an ELF:
1166 * scanelf -s %ogd% <ELF>
1167 */
1168static void
1169scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1170 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1171{
1172 const char *this_sym;
1173 size_t n;
1174
1175 array_for_each(find_sym_arr, n, this_sym) {
1176 bool inc_notype, inc_object, inc_func, inc_file,
1177 inc_local, inc_global, inc_weak,
1178 inc_def, inc_undef, inc_abs, inc_common;
1179
1180 /* symbol selection! */
1181 inc_notype = inc_object = inc_func = inc_file = \
1182 inc_local = inc_global = inc_weak = \
1183 inc_def = inc_undef = inc_abs = inc_common = \
1184 (*this_sym != '%');
1185
1186 /* parse the contents of %...% */
1187 if (!inc_notype) {
1188 while (*(this_sym++)) {
1189 if (*this_sym == '%') {
1190 ++this_sym;
1191 break;
1192 }
1193 switch (*this_sym) {
1194 case 'n': inc_notype = true; break;
1195 case 'o': inc_object = true; break;
1196 case 'f': inc_func = true; break;
1197 case 'F': inc_file = true; break;
1198 case 'l': inc_local = true; break;
1199 case 'g': inc_global = true; break;
1200 case 'w': inc_weak = true; break;
1201 case 'd': inc_def = true; break;
1202 case 'u': inc_undef = true; break;
1203 case 'a': inc_abs = true; break;
1204 case 'c': inc_common = true; break;
1205 default: err("invalid symbol selector '%c'", *this_sym);
1206 }
251 } 1207 }
252 if (!be_quiet && !found_needed) 1208
253 printf(" - "); 1209 /* If no types are matched, not match all */
254 else if (found_needed) 1210 if (!inc_notype && !inc_object && !inc_func && !inc_file)
255 printf(" "); 1211 inc_notype = inc_object = inc_func = inc_file = true;
1212 if (!inc_local && !inc_global && !inc_weak)
1213 inc_local = inc_global = inc_weak = true;
1214 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1215 inc_def = inc_undef = inc_abs = inc_common = true;
1216
1217 /* backwards compat for defined/undefined short hand */
1218 } else if (*this_sym == '+') {
1219 inc_undef = false;
1220 ++this_sym;
1221 } else if (*this_sym == '-') {
1222 inc_def = inc_abs = inc_common = false;
1223 ++this_sym;
256 } 1224 }
257 1225
258 /* search the symbol table for a specified symbol */ 1226 /* filter symbols */
259 if (find_sym) { 1227 if ((!inc_notype && stt == STT_NOTYPE) || \
1228 (!inc_object && stt == STT_OBJECT) || \
1229 (!inc_func && stt == STT_FUNC ) || \
1230 (!inc_file && stt == STT_FILE ) || \
1231 (!inc_local && stb == STB_LOCAL ) || \
1232 (!inc_global && stb == STB_GLOBAL) || \
1233 (!inc_weak && stb == STB_WEAK ) || \
1234 (!inc_def && shn && shn < SHN_LORESERVE) || \
1235 (!inc_undef && shn == SHN_UNDEF ) || \
1236 (!inc_abs && shn == SHN_ABS ) || \
1237 (!inc_common && shn == SHN_COMMON))
1238 continue;
1239
1240 if (*this_sym == '*') {
1241 /* a "*" symbol gets you debug output */
1242 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1243 ((*found_sym == 0) ? "\n\t" : "\t"),
1244 elf->base_filename,
1245 size,
1246 get_elfstttype(stt),
1247 get_elfstbtype(stb),
1248 get_elfshntype(shn),
1249 symname);
1250 goto matched;
1251
1252 } else {
1253 if (g_match) {
1254 /* regex match the symbol */
1255 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1256 continue;
1257
1258 } else if (*this_sym) {
1259 /* give empty symbols a "pass", else do a normal compare */
1260 const size_t len = strlen(this_sym);
1261 if (!(strncmp(this_sym, symname, len) == 0 &&
1262 /* Accept unversioned symbol names */
1263 (symname[len] == '\0' || symname[len] == '@')))
1264 continue;
1265 }
1266
1267 if (be_semi_verbose) {
1268 char buf[1024];
1269 snprintf(buf, sizeof(buf), "%lX %s %s",
1270 size,
1271 get_elfstttype(stt),
1272 this_sym);
1273 *ret = xstrdup(buf);
1274 } else {
1275 if (*ret) xchrcat(ret, ',', ret_len);
1276 xstrcat(ret, symname, ret_len);
1277 }
1278
1279 goto matched;
1280 }
1281 }
1282
1283 return;
1284
1285 matched:
1286 *found_sym = 1;
1287}
1288
1289static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
1290{
1291 char *ret;
260 void *symtab_void, *strtab_void; 1292 void *symtab_void, *strtab_void;
261 char *versioned_symname;
262 size_t len;
263 1293
264 len = strlen(find_sym) + 1; 1294 if (!find_sym) return NULL;
265 versioned_symname = (char *)malloc(sizeof(char) * (len+1)); 1295 ret = NULL;
266 if (!versioned_symname) {
267 warnf("Could not malloc() mem for sym scan");
268 return;
269 }
270 sprintf(versioned_symname, "%s@", find_sym);
271 1296
272 symtab_void = elf_findsecbyname(elf, ".symtab"); 1297 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
273 strtab_void = elf_findsecbyname(elf, ".strtab");
274 1298
275 if (symtab_void && strtab_void) { 1299 if (symtab_void && strtab_void) {
276#define FIND_SYM(B) \ 1300#define FIND_SYM(B) \
277 if (elf->elf_class == ELFCLASS ## B) { \ 1301 if (elf->elf_class == ELFCLASS ## B) { \
278 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1302 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
279 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1303 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
280 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1304 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
281 int cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1305 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
282 char *symname; \ 1306 char *symname; \
1307 size_t ret_len = 0; \
1308 if (cnt) \
1309 cnt = EGET(symtab->sh_size) / cnt; \
283 for (i = 0; i < cnt; ++i) { \ 1310 for (i = 0; i < cnt; ++i) { \
1311 if ((void*)sym > elf->data_end) { \
1312 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1313 goto break_out; \
1314 } \
284 if (sym->st_name) { \ 1315 if (sym->st_name) { \
1316 /* make sure the symbol name is in acceptable memory range */ \
285 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1317 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
286 if (*find_sym == '*') { \ 1318 if ((void*)symname > elf->data_end) { \
287 printf("%s(%s) %5lX %15s %s\n", \ 1319 warnf("%s: corrupt ELF symbols", elf->filename); \
288 ((found_sym == 0) ? "\n\t" : "\t"), \ 1320 ++sym; \
289 (char *)basename(filename), \ 1321 continue; \
290 (long)sym->st_size, \ 1322 } \
291 (char *)get_elfstttype(sym->st_info), \ 1323 scanelf_match_symname(elf, found_sym, \
292 symname); \ 1324 &ret, &ret_len, symname, \
293 found_sym = 1; \ 1325 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
294 } else if ((strcmp(find_sym, symname) == 0) || \ 1326 ELF##B##_ST_BIND(EGET(sym->st_info)), \
295 (strncmp(symname, versioned_symname, len) == 0)) \ 1327 EGET(sym->st_shndx), \
296 found_sym++; \ 1328 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1329 EGET(sym->st_size)); \
297 } \ 1330 } \
298 ++sym; \ 1331 ++sym; \
299 } } 1332 } \
1333 }
300 FIND_SYM(32) 1334 FIND_SYM(32)
301 FIND_SYM(64) 1335 FIND_SYM(64)
1336 }
1337
1338break_out:
1339 if (be_wewy_wewy_quiet) return NULL;
1340
1341 if (*find_sym != '*' && *found_sym)
1342 return ret;
1343 if (be_quiet)
1344 return NULL;
1345 else
1346 return " - ";
1347}
1348
1349static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1350{
1351 if (!find_section)
1352 return NULL;
1353
1354#define FIND_SECTION(B) \
1355 if (elf->elf_class == ELFCLASS ## B) { \
1356 size_t matched, n; \
1357 int invert; \
1358 const char *section_name; \
1359 Elf ## B ## _Shdr *section; \
1360 \
1361 matched = 0; \
1362 array_for_each(find_section_arr, n, section_name) { \
1363 invert = (*section_name == '!' ? 1 : 0); \
1364 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1365 if ((section == NULL && invert) || (section != NULL && !invert)) \
1366 ++matched; \
1367 } \
1368 \
1369 if (matched == array_cnt(find_section_arr)) \
1370 *found_section = 1; \
1371 }
1372 FIND_SECTION(32)
1373 FIND_SECTION(64)
1374
1375 if (be_wewy_wewy_quiet)
1376 return NULL;
1377
1378 if (*found_section)
1379 return find_section;
1380
1381 if (be_quiet)
1382 return NULL;
1383 else
1384 return " - ";
1385}
1386
1387/* scan an elf file and show all the fun stuff */
1388#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
1389static int scanelf_elfobj(elfobj *elf)
1390{
1391 unsigned long i;
1392 char found_pax, found_phdr, found_relro, found_load, found_textrel,
1393 found_rpath, found_needed, found_interp, found_bind, found_soname,
1394 found_sym, found_lib, found_file, found_textrels, found_section;
1395 static char *out_buffer = NULL;
1396 static size_t out_len;
1397
1398 found_pax = found_phdr = found_relro = found_load = found_textrel = \
1399 found_rpath = found_needed = found_interp = found_bind = found_soname = \
1400 found_sym = found_lib = found_file = found_textrels = found_section = 0;
1401
1402 if (be_verbose > 2)
1403 printf("%s: scanning file {%s,%s}\n", elf->filename,
1404 get_elfeitype(EI_CLASS, elf->elf_class),
1405 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
1406 else if (be_verbose > 1)
1407 printf("%s: scanning file\n", elf->filename);
1408
1409 /* init output buffer */
1410 if (!out_buffer) {
1411 out_len = sizeof(char) * 80;
1412 out_buffer = xmalloc(out_len);
1413 }
1414 *out_buffer = '\0';
1415
1416 /* show the header */
1417 if (!be_quiet && show_banner) {
1418 for (i = 0; out_format[i]; ++i) {
1419 if (!IS_MODIFIER(out_format[i])) continue;
1420
1421 switch (out_format[++i]) {
1422 case '+': break;
1423 case '%': break;
1424 case '#': break;
1425 case 'F':
1426 case 'p':
1427 case 'f': prints("FILE "); found_file = 1; break;
1428 case 'o': prints(" TYPE "); break;
1429 case 'x': prints(" PAX "); break;
1430 case 'e': prints("STK/REL/PTL "); break;
1431 case 't': prints("TEXTREL "); break;
1432 case 'r': prints("RPATH "); break;
1433 case 'M': prints("CLASS "); break;
1434 case 'l':
1435 case 'n': prints("NEEDED "); break;
1436 case 'i': prints("INTERP "); break;
1437 case 'b': prints("BIND "); break;
1438 case 'Z': prints("SIZE "); break;
1439 case 'S': prints("SONAME "); break;
1440 case 's': prints("SYM "); break;
1441 case 'N': prints("LIB "); break;
1442 case 'T': prints("TEXTRELS "); break;
1443 case 'k': prints("SECTION "); break;
1444 case 'a': prints("ARCH "); break;
1445 case 'I': prints("OSABI "); break;
1446 case 'Y': prints("EABI "); break;
1447 case 'O': prints("PERM "); break;
1448 case 'D': prints("ENDIAN "); break;
1449 default: warnf("'%c' has no title ?", out_format[i]);
302 } 1450 }
303 free(versioned_symname); 1451 }
304 if (*find_sym != '*') { 1452 if (!found_file) prints("FILE ");
305 if (found_sym) 1453 prints("\n");
306 printf(" %s ", find_sym); 1454 found_file = 0;
307 else if (!be_quiet) 1455 show_banner = 0;
308 printf(" - "); 1456 }
1457
1458 /* dump all the good stuff */
1459 for (i = 0; out_format[i]; ++i) {
1460 const char *out;
1461 const char *tmp;
1462 static char ubuf[sizeof(unsigned long)*2];
1463 if (!IS_MODIFIER(out_format[i])) {
1464 xchrcat(&out_buffer, out_format[i], &out_len);
1465 continue;
1466 }
1467
1468 out = NULL;
1469 be_wewy_wewy_quiet = (out_format[i] == '#');
1470 be_semi_verbose = (out_format[i] == '+');
1471 switch (out_format[++i]) {
1472 case '+':
1473 case '%':
1474 case '#':
1475 xchrcat(&out_buffer, out_format[i], &out_len); break;
1476 case 'F':
1477 found_file = 1;
1478 if (be_wewy_wewy_quiet) break;
1479 xstrcat(&out_buffer, elf->filename, &out_len);
1480 break;
1481 case 'p':
1482 found_file = 1;
1483 if (be_wewy_wewy_quiet) break;
1484 tmp = elf->filename;
1485 if (search_path) {
1486 ssize_t len_search = strlen(search_path);
1487 ssize_t len_file = strlen(elf->filename);
1488 if (!strncmp(elf->filename, search_path, len_search) && \
1489 len_file > len_search)
1490 tmp += len_search;
1491 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
309 } 1492 }
1493 xstrcat(&out_buffer, tmp, &out_len);
1494 break;
1495 case 'f':
1496 found_file = 1;
1497 if (be_wewy_wewy_quiet) break;
1498 tmp = strrchr(elf->filename, '/');
1499 tmp = (tmp == NULL ? elf->filename : tmp+1);
1500 xstrcat(&out_buffer, tmp, &out_len);
1501 break;
1502 case 'o': out = get_elfetype(elf); break;
1503 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
1504 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
1505 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
1506 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
1507 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1508 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1509 case 'D': out = get_endian(elf); break;
1510 case 'O': out = strfileperms(elf->filename); break;
1511 case 'n':
1512 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
1513 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
1514 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
1515 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
1516 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1517 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1518 case 'a': out = get_elfemtype(elf); break;
1519 case 'I': out = get_elfosabi(elf); break;
1520 case 'Y': out = get_elf_eabi(elf); break;
1521 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
1522 default: warnf("'%c' has no scan code?", out_format[i]);
310 } 1523 }
1524 if (out)
1525 xstrcat(&out_buffer, out, &out_len);
1526 }
311 1527
312 if (!be_quiet || found_pax || found_stack || found_textrel || \ 1528#define FOUND_SOMETHING() \
313 found_rpath || found_needed || found_sym) 1529 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
314 printf("%s\n", filename); 1530 found_rpath || found_needed || found_interp || found_bind || \
1531 found_soname || found_sym || found_lib || found_textrels || found_section )
315 1532
1533 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
1534 xchrcat(&out_buffer, ' ', &out_len);
1535 xstrcat(&out_buffer, elf->filename, &out_len);
1536 }
1537 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
1538 puts(out_buffer);
1539 fflush(stdout);
1540 }
1541
1542 return 0;
1543}
1544
1545/* scan a single elf */
1546static int scanelf_elf(const char *filename, int fd, size_t len)
1547{
1548 int ret = 1;
1549 elfobj *elf;
1550
1551 /* verify this is real ELF */
1552 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1553 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1554 return 2;
1555 }
1556 switch (match_bits) {
1557 case 32:
1558 if (elf->elf_class != ELFCLASS32)
1559 goto label_done;
1560 break;
1561 case 64:
1562 if (elf->elf_class != ELFCLASS64)
1563 goto label_done;
1564 break;
1565 default: break;
1566 }
1567 if (match_etypes) {
1568 char sbuf[126];
1569 strncpy(sbuf, match_etypes, sizeof(sbuf));
1570 if (strchr(match_etypes, ',') != NULL) {
1571 char *p;
1572 while ((p = strrchr(sbuf, ',')) != NULL) {
1573 *p = 0;
1574 if (etype_lookup(p+1) == get_etype(elf))
1575 goto label_ret;
1576 }
1577 }
1578 if (etype_lookup(sbuf) != get_etype(elf))
1579 goto label_done;
1580 }
1581
1582label_ret:
1583 ret = scanelf_elfobj(elf);
1584
1585label_done:
316 unreadelf(elf); 1586 unreadelf(elf);
1587 return ret;
1588}
1589
1590/* scan an archive of elfs */
1591static int scanelf_archive(const char *filename, int fd, size_t len)
1592{
1593 archive_handle *ar;
1594 archive_member *m;
1595 char *ar_buffer;
1596 elfobj *elf;
1597
1598 ar = ar_open_fd(filename, fd);
1599 if (ar == NULL)
1600 return 1;
1601
1602 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1603 while ((m = ar_next(ar)) != NULL) {
1604 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1605 if (cur_pos == -1)
1606 errp("lseek() failed");
1607 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1608 if (elf) {
1609 scanelf_elfobj(elf);
1610 unreadelf(elf);
1611 }
1612 }
1613 munmap(ar_buffer, len);
1614
1615 return 0;
1616}
1617/* scan a file which may be an elf or an archive or some other magical beast */
1618static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1619{
1620 const struct stat *st = st_cache;
1621 struct stat symlink_st;
1622 int fd;
1623
1624 /* always handle regular files and handle symlinked files if no -y */
1625 if (S_ISLNK(st->st_mode)) {
1626 if (!scan_symlink)
1627 return 1;
1628 fstatat(dir_fd, filename, &symlink_st, 0);
1629 st = &symlink_st;
1630 }
1631
1632 if (!S_ISREG(st->st_mode)) {
1633 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1634 return 1;
1635 }
1636
1637 if (match_perms) {
1638 if ((st->st_mode | match_perms) != st->st_mode)
1639 return 1;
1640 }
1641 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1642 if (fd == -1) {
1643 if (fix_elf && errno == ETXTBSY)
1644 warnp("%s: could not fix", filename);
1645 else if (be_verbose > 2)
1646 printf("%s: skipping file: %s\n", filename, strerror(errno));
1647 return 1;
1648 }
1649
1650 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1651 /* if it isn't an ELF, maybe it's an .a archive */
1652 if (scan_archives)
1653 scanelf_archive(filename, fd, st->st_size);
1654
1655 /*
1656 * unreadelf() implicitly closes its fd, so only close it
1657 * when we are returning it in the non-ELF case
1658 */
1659 close(fd);
1660 }
1661
1662 return 0;
317} 1663}
318 1664
319/* scan a directory for ET_EXEC files and print when we find one */ 1665/* scan a directory for ET_EXEC files and print when we find one */
320static void scanelf_dir(const char *path) 1666static int scanelf_dirat(int dir_fd, const char *path)
321{ 1667{
322 register DIR *dir; 1668 register DIR *dir;
323 register struct dirent *dentry; 1669 register struct dirent *dentry;
324 struct stat st_top, st; 1670 struct stat st_top, st;
325 char buf[_POSIX_PATH_MAX]; 1671 char buf[__PAX_UTILS_PATH_MAX], *subpath;
326 size_t pathlen = 0, len = 0; 1672 size_t pathlen = 0, len = 0;
1673 int ret = 0;
1674 int subdir_fd;
327 1675
328 /* make sure path exists */ 1676 /* make sure path exists */
329 if (lstat(path, &st_top) == -1) 1677 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
1678 if (be_verbose > 2) printf("%s: does not exist\n", path);
330 return; 1679 return 1;
1680 }
331 1681
332 /* ok, if it isn't a directory, assume we can open it */ 1682 /* ok, if it isn't a directory, assume we can open it */
333 if (!S_ISDIR(st_top.st_mode)) { 1683 if (!S_ISDIR(st_top.st_mode))
334 scanelf_file(path); 1684 return scanelf_fileat(dir_fd, path, &st_top);
335 return;
336 }
337 1685
338 /* now scan the dir looking for fun stuff */ 1686 /* now scan the dir looking for fun stuff */
339 if ((dir = opendir(path)) == NULL) { 1687 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
340 warnf("could not opendir %s: %s", path, strerror(errno)); 1688 if (subdir_fd == -1)
1689 dir = NULL;
1690 else
1691 dir = fdopendir(subdir_fd);
1692 if (dir == NULL) {
1693 if (subdir_fd != -1)
1694 close(subdir_fd);
1695 warnfp("could not opendir(%s)", path);
341 return; 1696 return 1;
342 } 1697 }
343 if (be_verbose) printf("%s: scanning dir\n", path); 1698 if (be_verbose > 1) printf("%s: scanning dir\n", path);
344 1699
345 pathlen = strlen(path); 1700 subpath = stpcpy(buf, path);
1701 if (subpath[-1] != '/')
1702 *subpath++ = '/';
1703 pathlen = subpath - buf;
346 while ((dentry = readdir(dir))) { 1704 while ((dentry = readdir(dir))) {
347 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1705 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
348 continue; 1706 continue;
349 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1707
350 if (len >= sizeof(buf)) { 1708 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
351 warnf("Skipping '%s': len > sizeof(buf); %d > %d\n", path, (int)len, (int)sizeof(buf));
352 continue; 1709 continue;
1710
1711 len = strlen(dentry->d_name);
1712 if (len + pathlen + 1 >= sizeof(buf)) {
1713 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1714 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1715 continue;
353 } 1716 }
354 sprintf(buf, "%s/%s", path, dentry->d_name); 1717 memcpy(subpath, dentry->d_name, len);
355 if (lstat(buf, &st) != -1) { 1718 subpath[len] = '\0';
1719
356 if (S_ISREG(st.st_mode)) 1720 if (S_ISREG(st.st_mode))
357 scanelf_file(buf); 1721 ret = scanelf_fileat(dir_fd, buf, &st);
358 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1722 else if (dir_recurse && S_ISDIR(st.st_mode)) {
359 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1723 if (dir_crossmount || (st_top.st_dev == st.st_dev))
360 scanelf_dir(buf); 1724 ret = scanelf_dirat(dir_fd, buf);
1725 }
1726 }
1727 closedir(dir);
1728
1729 return ret;
1730}
1731static int scanelf_dir(const char *path)
1732{
1733 return scanelf_dirat(root_fd, root_rel_path(path));
1734}
1735
1736static int scanelf_from_file(const char *filename)
1737{
1738 FILE *fp;
1739 char *p, *path;
1740 size_t len;
1741 int ret;
1742
1743 if (strcmp(filename, "-") == 0)
1744 fp = stdin;
1745 else if ((fp = fopen(filename, "r")) == NULL)
1746 return 1;
1747
1748 path = NULL;
1749 len = 0;
1750 ret = 0;
1751 while (getline(&path, &len, fp) != -1) {
1752 if ((p = strchr(path, '\n')) != NULL)
1753 *p = 0;
1754 search_path = path;
1755 ret = scanelf_dir(path);
1756 }
1757 free(path);
1758
1759 if (fp != stdin)
1760 fclose(fp);
1761
1762 return ret;
1763}
1764
1765#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1766
1767static int _load_ld_cache_config(const char *fname)
1768{
1769 FILE *fp = NULL;
1770 char *p, *path;
1771 size_t len;
1772 int curr_fd = -1;
1773
1774 fp = fopenat_r(root_fd, root_rel_path(fname));
1775 if (fp == NULL)
1776 return -1;
1777
1778 path = NULL;
1779 len = 0;
1780 while (getline(&path, &len, fp) != -1) {
1781 if ((p = strrchr(path, '\r')) != NULL)
1782 *p = 0;
1783 if ((p = strchr(path, '\n')) != NULL)
1784 *p = 0;
1785
1786 /* recursive includes of the same file will make this segfault. */
1787 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1788 glob_t gl;
1789 size_t x;
1790 const char *gpath;
1791
1792 /* re-use existing path buffer ... need to be creative */
1793 if (path[8] != '/')
1794 gpath = memcpy(path + 3, "/etc/", 5);
1795 else
1796 gpath = path + 8;
1797 if (root_fd != AT_FDCWD) {
1798 if (curr_fd == -1) {
1799 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1800 if (fchdir(root_fd))
1801 errp("unable to change to root dir");
1802 }
1803 gpath = root_rel_path(gpath);
361 } 1804 }
1805
1806 if (glob(gpath, 0, NULL, &gl) == 0) {
1807 for (x = 0; x < gl.gl_pathc; ++x) {
1808 /* try to avoid direct loops */
1809 if (strcmp(gl.gl_pathv[x], fname) == 0)
1810 continue;
1811 _load_ld_cache_config(gl.gl_pathv[x]);
1812 }
1813 globfree(&gl);
362 } 1814 }
1815
1816 /* failed globs are ignored by glibc */
1817 continue;
363 } 1818 }
364 closedir(dir); 1819
1820 if (*path != '/')
1821 continue;
1822
1823 xarraypush_str(ldpaths, path);
1824 }
1825 free(path);
1826
1827 fclose(fp);
1828
1829 if (curr_fd != -1) {
1830 if (fchdir(curr_fd))
1831 /* don't care */;
1832 close(curr_fd);
1833 }
1834
1835 return 0;
1836}
1837
1838#elif defined(__FreeBSD__) || defined(__DragonFly__)
1839
1840static int _load_ld_cache_config(const char *fname)
1841{
1842 FILE *fp = NULL;
1843 char *b = NULL, *p;
1844 struct elfhints_hdr hdr;
1845
1846 fp = fopenat_r(root_fd, root_rel_path(fname));
1847 if (fp == NULL)
1848 return -1;
1849
1850 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1851 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1852 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1853 {
1854 fclose(fp);
1855 return -1;
1856 }
1857
1858 b = xmalloc(hdr.dirlistlen + 1);
1859 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1860 fclose(fp);
1861 free(b);
1862 return -1;
1863 }
1864
1865 while ((p = strsep(&b, ":"))) {
1866 if (*p == '\0')
1867 continue;
1868 xarraypush_str(ldpaths, p);
1869 }
1870
1871 free(b);
1872 fclose(fp);
1873 return 0;
1874}
1875
1876#else
1877#ifdef __ELF__
1878#warning Cache config support not implemented for your target
1879#endif
1880static int _load_ld_cache_config(const char *fname)
1881{
1882 return 0;
1883}
1884#endif
1885
1886static void load_ld_cache_config(const char *fname)
1887{
1888 bool scan_l, scan_ul, scan_ull;
1889 size_t n;
1890 const char *ldpath;
1891
1892 _load_ld_cache_config(fname);
1893
1894 scan_l = scan_ul = scan_ull = false;
1895 if (array_cnt(ldpaths)) {
1896 array_for_each(ldpaths, n, ldpath) {
1897 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1898 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1899 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1900 }
1901 }
1902
1903 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1904 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1905 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
365} 1906}
366 1907
367/* scan /etc/ld.so.conf for paths */ 1908/* scan /etc/ld.so.conf for paths */
368static void scanelf_ldpath() 1909static void scanelf_ldpath(void)
369{ 1910{
370 char scan_l, scan_ul, scan_ull; 1911 size_t n;
371 char *path, *p; 1912 const char *ldpath;
372 FILE *fp;
373 1913
374 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1914 array_for_each(ldpaths, n, ldpath)
375 err("Unable to open ld.so.conf: %s", strerror(errno));
376
377 scan_l = scan_ul = scan_ull = 0;
378
379 if ((path = malloc(_POSIX_PATH_MAX)) == NULL) {
380 warn("Can not malloc() memory for ldpath scanning");
381 return;
382 }
383 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL)
384 if (*path == '/') {
385 if ((p = strrchr(path, '\r')) != NULL)
386 *p = 0;
387 if ((p = strrchr(path, '\n')) != NULL)
388 *p = 0;
389 if (!scan_l && !strcmp(path, "/lib")) scan_l = 1;
390 if (!scan_ul && !strcmp(path, "/usr/lib")) scan_ul = 1;
391 if (!scan_ull && !strcmp(path, "/usr/local/lib")) scan_ull = 1;
392 scanelf_dir(path); 1915 scanelf_dir(ldpath);
393 }
394 free(path);
395 fclose(fp);
396
397 if (!scan_l) scanelf_dir("/lib");
398 if (!scan_ul) scanelf_dir("/usr/lib");
399 if (!scan_ull) scanelf_dir("/usr/local/lib");
400} 1916}
401 1917
402/* scan env PATH for paths */ 1918/* scan env PATH for paths */
403static void scanelf_envpath() 1919static void scanelf_envpath(void)
404{ 1920{
405 char *path, *p; 1921 char *path, *p;
406 1922
407 path = getenv("PATH"); 1923 path = getenv("PATH");
408 if (!path) 1924 if (!path)
409 err("PATH is not set in your env !"); 1925 err("PATH is not set in your env !");
410 1926 path = xstrdup(path);
411 if ((path = strdup(path)) == NULL)
412 err("strdup failed: %s", strerror(errno));
413 1927
414 while ((p = strrchr(path, ':')) != NULL) { 1928 while ((p = strrchr(path, ':')) != NULL) {
415 scanelf_dir(p + 1); 1929 scanelf_dir(p + 1);
416 *p = 0; 1930 *p = 0;
417 } 1931 }
418 1932
419 free(path); 1933 free(path);
420} 1934}
421 1935
422 1936/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
423 1937#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
424/* usage / invocation handling functions */
425#define PARSE_FLAGS "plRmxetrns:aqvo:BhV"
426#define a_argument required_argument 1938#define a_argument required_argument
427static struct option const long_opts[] = { 1939static struct option const long_opts[] = {
428 {"path", no_argument, NULL, 'p'}, 1940 {"path", no_argument, NULL, 'p'},
429 {"ldpath", no_argument, NULL, 'l'}, 1941 {"ldpath", no_argument, NULL, 'l'},
1942 {"use-ldpath",no_argument, NULL, 129},
1943 {"root", a_argument, NULL, 128},
430 {"recursive", no_argument, NULL, 'R'}, 1944 {"recursive", no_argument, NULL, 'R'},
431 {"mount", no_argument, NULL, 'm'}, 1945 {"mount", no_argument, NULL, 'm'},
1946 {"symlink", no_argument, NULL, 'y'},
1947 {"archives", no_argument, NULL, 'A'},
1948 {"ldcache", no_argument, NULL, 'L'},
1949 {"fix", no_argument, NULL, 'X'},
1950 {"setpax", a_argument, NULL, 'z'},
432 {"pax", no_argument, NULL, 'x'}, 1951 {"pax", no_argument, NULL, 'x'},
433 {"header", no_argument, NULL, 'e'}, 1952 {"header", no_argument, NULL, 'e'},
434 {"textrel", no_argument, NULL, 't'}, 1953 {"textrel", no_argument, NULL, 't'},
435 {"rpath", no_argument, NULL, 'r'}, 1954 {"rpath", no_argument, NULL, 'r'},
436 {"needed", no_argument, NULL, 'n'}, 1955 {"needed", no_argument, NULL, 'n'},
1956 {"interp", no_argument, NULL, 'i'},
1957 {"bind", no_argument, NULL, 'b'},
1958 {"soname", no_argument, NULL, 'S'},
437 {"symbol", a_argument, NULL, 's'}, 1959 {"symbol", a_argument, NULL, 's'},
1960 {"section", a_argument, NULL, 'k'},
1961 {"lib", a_argument, NULL, 'N'},
1962 {"gmatch", no_argument, NULL, 'g'},
1963 {"textrels", no_argument, NULL, 'T'},
1964 {"etype", a_argument, NULL, 'E'},
1965 {"bits", a_argument, NULL, 'M'},
1966 {"endian", no_argument, NULL, 'D'},
1967 {"osabi", no_argument, NULL, 'I'},
1968 {"eabi", no_argument, NULL, 'Y'},
1969 {"perms", a_argument, NULL, 'O'},
1970 {"size", no_argument, NULL, 'Z'},
438 {"all", no_argument, NULL, 'a'}, 1971 {"all", no_argument, NULL, 'a'},
439 {"quiet", no_argument, NULL, 'q'}, 1972 {"quiet", no_argument, NULL, 'q'},
440 {"verbose", no_argument, NULL, 'v'}, 1973 {"verbose", no_argument, NULL, 'v'},
1974 {"format", a_argument, NULL, 'F'},
1975 {"from", a_argument, NULL, 'f'},
441 {"file", a_argument, NULL, 'o'}, 1976 {"file", a_argument, NULL, 'o'},
1977 {"nocolor", no_argument, NULL, 'C'},
442 {"nobanner", no_argument, NULL, 'B'}, 1978 {"nobanner", no_argument, NULL, 'B'},
443 {"help", no_argument, NULL, 'h'}, 1979 {"help", no_argument, NULL, 'h'},
444 {"version", no_argument, NULL, 'V'}, 1980 {"version", no_argument, NULL, 'V'},
445 {NULL, no_argument, NULL, 0x0} 1981 {NULL, no_argument, NULL, 0x0}
446}; 1982};
1983
447static char *opts_help[] = { 1984static const char * const opts_help[] = {
448 "Scan all directories in PATH environment", 1985 "Scan all directories in PATH environment",
449 "Scan all directories in /etc/ld.so.conf", 1986 "Scan all directories in /etc/ld.so.conf",
1987 "Use ld.so.conf to show full path (use with -r/-n)",
1988 "Root directory (use with -l or -p)",
450 "Scan directories recursively", 1989 "Scan directories recursively",
451 "Don't recursively cross mount points\n", 1990 "Don't recursively cross mount points",
1991 "Don't scan symlinks",
1992 "Scan archives (.a files)",
1993 "Utilize ld.so.cache to show full path (use with -r/-n)",
1994 "Try and 'fix' bad things (use with -r/-e)",
1995 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
452 "Print PaX markings", 1996 "Print PaX markings",
453 "Print GNU_STACK markings", 1997 "Print GNU_STACK/PT_LOAD markings",
454 "Print TEXTREL information", 1998 "Print TEXTREL information",
455 "Print RPATH information", 1999 "Print RPATH information",
456 "Print NEEDED information", 2000 "Print NEEDED information",
2001 "Print INTERP information",
2002 "Print BIND information",
2003 "Print SONAME information",
457 "Find a specified symbol", 2004 "Find a specified symbol",
458 "Print all scanned info (-x -e -t -r)\n", 2005 "Find a specified section",
2006 "Find a specified library",
2007 "Use regex rather than string compare (with -s); specify twice for case insensitive",
2008 "Locate cause of TEXTREL",
2009 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2010 "Print only ELF files matching numeric bits",
2011 "Print Endianness",
2012 "Print OSABI",
2013 "Print EABI (EM_ARM Only)",
2014 "Print only ELF files matching octal permissions",
2015 "Print ELF file size",
2016 "Print all useful/simple info\n",
459 "Only output 'bad' things", 2017 "Only output 'bad' things",
460 "Be verbose (can be specified more than once)", 2018 "Be verbose (can be specified more than once)",
2019 "Use specified format for output",
2020 "Read input stream from a filename",
461 "Write output stream to a filename", 2021 "Write output stream to a filename",
2022 "Don't emit color in output",
462 "Don't display the header", 2023 "Don't display the header",
463 "Print this help and exit", 2024 "Print this help and exit",
464 "Print version and exit", 2025 "Print version and exit",
465 NULL 2026 NULL
466}; 2027};
467 2028
468/* display usage and exit */ 2029/* display usage and exit */
469static void usage(int status) 2030static void usage(int status)
470{ 2031{
2032 unsigned long i;
2033 printf("* Scan ELF binaries for stuff\n\n"
2034 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
2035 printf("Options: -[%s]\n", PARSE_FLAGS);
2036 for (i = 0; long_opts[i].name; ++i) {
2037 /* first output the short flag if it has one */
2038 if (long_opts[i].val > '~')
2039 printf(" ");
2040 else
2041 printf(" -%c, ", long_opts[i].val);
2042
2043 /* then the long flag */
2044 if (long_opts[i].has_arg == no_argument)
2045 printf("--%-14s", long_opts[i].name);
2046 else
2047 printf("--%-7s <arg> ", long_opts[i].name);
2048
2049 /* finally the help text */
2050 printf("* %s\n", opts_help[i]);
2051 }
2052
2053 puts("\nFor more information, see the scanelf(1) manpage");
2054 exit(status);
2055}
2056
2057/* parse command line arguments and preform needed actions */
2058#define do_pax_state(option, flag) \
2059 if (islower(option)) { \
2060 flags &= ~PF_##flag; \
2061 flags |= PF_NO##flag; \
2062 } else { \
2063 flags &= ~PF_NO##flag; \
2064 flags |= PF_##flag; \
2065 }
2066static int parseargs(int argc, char *argv[])
2067{
471 int i; 2068 int i;
472 printf(" Scan ELF binaries for stuff\n" 2069 const char *from_file = NULL;
473 "Usage: %s [options] <dir1> [dir2 dirN ...]\n\n", argv0); 2070 int ret = 0;
474 printf("Options:\n"); 2071 char load_cache_config = 0;
475 for (i = 0; long_opts[i].name; ++i)
476 if (long_opts[i].has_arg == no_argument)
477 printf(" -%c, --%-13s %s\n", long_opts[i].val,
478 long_opts[i].name, opts_help[i]);
479 else
480 printf(" -%c, --%-6s <arg> %s\n", long_opts[i].val,
481 long_opts[i].name, opts_help[i]);
482 exit(status);
483}
484
485/* parse command line arguments and preform needed actions */
486static void parseargs(int argc, char *argv[])
487{
488 int flag;
489 2072
490 opterr = 0; 2073 opterr = 0;
491 while ((flag=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2074 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
492 switch (flag) { 2075 switch (i) {
493 2076
494 case 'V': /* version info */ 2077 case 'V':
495 printf("%s compiled %s\n%s\n" 2078 printf("pax-utils-%s: %s compiled %s\n%s\n"
496 "%s written for Gentoo Linux by <solar and vapier @ gentoo.org>\n", 2079 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
497 __FILE__, __DATE__, rcsid, argv0); 2080 VERSION, __FILE__, __DATE__, rcsid, argv0);
498 exit(EXIT_SUCCESS); 2081 exit(EXIT_SUCCESS);
499 break; 2082 break;
500 case 'h': usage(EXIT_SUCCESS); break; 2083 case 'h': usage(EXIT_SUCCESS); break;
501 2084 case 'f':
2085 if (from_file) warn("You prob don't want to specify -f twice");
2086 from_file = optarg;
2087 break;
2088 case 'E':
2089 match_etypes = optarg;
2090 break;
2091 case 'M':
2092 match_bits = atoi(optarg);
2093 if (match_bits == 0) {
2094 if (strcmp(optarg, "ELFCLASS32") == 0)
2095 match_bits = 32;
2096 if (strcmp(optarg, "ELFCLASS64") == 0)
2097 match_bits = 64;
2098 }
2099 break;
2100 case 'O':
2101 if (sscanf(optarg, "%o", &match_perms) == -1)
2102 match_bits = 0;
2103 break;
502 case 'o': { 2104 case 'o': {
503 FILE *fp = NULL;
504 fp = freopen(optarg, "w", stdout); 2105 if (freopen(optarg, "w", stdout) == NULL)
505 if (fp == NULL) 2106 errp("Could not freopen(%s)", optarg);
506 err("Could not open output stream '%s': %s", optarg, strerror(errno));
507 stdout = fp;
508 break; 2107 break;
509 } 2108 }
2109 case 'k':
2110 xarraypush_str(find_section_arr, optarg);
2111 break;
2112 case 's': {
2113 /* historically, this was comma delimited */
2114 char *this_sym = strtok(optarg, ",");
2115 if (!this_sym) /* edge case: -s '' */
2116 xarraypush_str(find_sym_arr, "");
2117 while (this_sym) {
2118 xarraypush_str(find_sym_arr, this_sym);
2119 this_sym = strtok(NULL, ",");
2120 }
2121 break;
2122 }
2123 case 'N':
2124 xarraypush_str(find_lib_arr, optarg);
2125 break;
2126 case 'F': {
2127 if (out_format) warn("You prob don't want to specify -F twice");
2128 out_format = optarg;
2129 break;
2130 }
2131 case 'z': {
2132 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2133 size_t x;
510 2134
511 case 's': find_sym = strdup(optarg); break; 2135 for (x = 0; x < strlen(optarg); x++) {
512 2136 switch (optarg[x]) {
2137 case 'p':
2138 case 'P':
2139 do_pax_state(optarg[x], PAGEEXEC);
2140 break;
2141 case 's':
2142 case 'S':
2143 do_pax_state(optarg[x], SEGMEXEC);
2144 break;
2145 case 'm':
2146 case 'M':
2147 do_pax_state(optarg[x], MPROTECT);
2148 break;
2149 case 'e':
2150 case 'E':
2151 do_pax_state(optarg[x], EMUTRAMP);
2152 break;
2153 case 'r':
2154 case 'R':
2155 do_pax_state(optarg[x], RANDMMAP);
2156 break;
2157 case 'x':
2158 case 'X':
2159 do_pax_state(optarg[x], RANDEXEC);
2160 break;
2161 default:
2162 break;
2163 }
2164 }
2165 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2166 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2167 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2168 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2169 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2170 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2171 setpax = flags;
2172 break;
2173 }
2174 case 'Z': show_size = 1; break;
2175 case 'g': ++g_match; break;
2176 case 'L': load_cache_config = use_ldcache = 1; break;
2177 case 'y': scan_symlink = 0; break;
2178 case 'A': scan_archives = 1; break;
2179 case 'C': color_init(true); break;
513 case 'B': show_banner = 0; break; 2180 case 'B': show_banner = 0; break;
514 case 'l': scan_ldpath = 1; break; 2181 case 'l': load_cache_config = scan_ldpath = 1; break;
515 case 'p': scan_envpath = 1; break; 2182 case 'p': scan_envpath = 1; break;
516 case 'R': dir_recurse = 1; break; 2183 case 'R': dir_recurse = 1; break;
517 case 'm': dir_crossmount = 0; break; 2184 case 'm': dir_crossmount = 0; break;
2185 case 'X': ++fix_elf; break;
518 case 'x': show_pax = 1; break; 2186 case 'x': show_pax = 1; break;
519 case 'e': show_stack = 1; break; 2187 case 'e': show_phdr = 1; break;
520 case 't': show_textrel = 1; break; 2188 case 't': show_textrel = 1; break;
521 case 'r': show_rpath = 1; break; 2189 case 'r': show_rpath = 1; break;
522 case 'n': show_needed = 1; break; 2190 case 'n': show_needed = 1; break;
2191 case 'i': show_interp = 1; break;
523 case 'q': be_quiet = 1; break; 2192 case 'b': show_bind = 1; break;
2193 case 'S': show_soname = 1; break;
2194 case 'T': show_textrels = 1; break;
2195 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
524 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2196 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
525 case 'a': show_pax = show_stack = show_textrel = show_needed = show_rpath = 1; break; 2197 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
526 2198 case 'D': show_endian = 1; break;
2199 case 'I': show_osabi = 1; break;
2200 case 'Y': show_eabi = 1; break;
2201 case 128:
2202 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2203 if (root_fd == -1)
2204 err("Could not open root: %s", optarg);
2205 break;
2206 case 129: load_cache_config = use_ldpath = 1; break;
527 case ':': 2207 case ':':
528 warn("Option missing parameter"); 2208 err("Option '%c' is missing parameter", optopt);
529 usage(EXIT_FAILURE);
530 break;
531 case '?': 2209 case '?':
532 warn("Unknown option"); 2210 err("Unknown option '%c' or argument missing", optopt);
533 usage(EXIT_FAILURE);
534 break;
535 default: 2211 default:
536 err("Unhandled option '%c'", flag); 2212 err("Unhandled option '%c'; please report this", i);
2213 }
2214 }
2215 if (show_textrels && be_verbose)
2216 has_objdump = bin_in_path("objdump");
2217 /* precompile all the regexes */
2218 if (g_match) {
2219 regex_t preg;
2220 const char *this_sym;
2221 size_t n;
2222 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2223
2224 array_for_each(find_sym_arr, n, this_sym) {
2225 /* see scanelf_match_symname for logic info */
2226 switch (this_sym[0]) {
2227 case '%':
2228 while (*(this_sym++))
2229 if (*this_sym == '%') {
2230 ++this_sym;
2231 break;
2232 }
537 break; 2233 break;
2234 case '+':
2235 case '-':
2236 ++this_sym;
2237 break;
538 } 2238 }
2239 if (*this_sym == '*')
2240 ++this_sym;
2241
2242 ret = regcomp(&preg, this_sym, flags);
2243 if (ret) {
2244 char err[256];
2245 regerror(ret, &preg, err, sizeof(err));
2246 err("regcomp of %s failed: %s", this_sym, err);
2247 }
2248 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
539 } 2249 }
2250 }
2251 /* flatten arrays for display */
2252 if (array_cnt(find_sym_arr))
2253 find_sym = array_flatten_str(find_sym_arr);
2254 if (array_cnt(find_lib_arr))
2255 find_lib = array_flatten_str(find_lib_arr);
2256 if (array_cnt(find_section_arr))
2257 find_section = array_flatten_str(find_section_arr);
2258 /* let the format option override all other options */
2259 if (out_format) {
2260 show_pax = show_phdr = show_textrel = show_rpath = \
2261 show_needed = show_interp = show_bind = show_soname = \
2262 show_textrels = show_perms = show_endian = show_size = \
2263 show_osabi = show_eabi = 0;
2264 for (i = 0; out_format[i]; ++i) {
2265 if (!IS_MODIFIER(out_format[i])) continue;
540 2266
541 if (be_quiet && be_verbose) 2267 switch (out_format[++i]) {
542 err("You can be quiet or you can be verbose, not both, stupid"); 2268 case '+': break;
2269 case '%': break;
2270 case '#': break;
2271 case 'F': break;
2272 case 'p': break;
2273 case 'f': break;
2274 case 'k': break;
2275 case 's': break;
2276 case 'N': break;
2277 case 'o': break;
2278 case 'a': break;
2279 case 'M': break;
2280 case 'Z': show_size = 1; break;
2281 case 'D': show_endian = 1; break;
2282 case 'I': show_osabi = 1; break;
2283 case 'Y': show_eabi = 1; break;
2284 case 'O': show_perms = 1; break;
2285 case 'x': show_pax = 1; break;
2286 case 'e': show_phdr = 1; break;
2287 case 't': show_textrel = 1; break;
2288 case 'r': show_rpath = 1; break;
2289 case 'n': show_needed = 1; break;
2290 case 'i': show_interp = 1; break;
2291 case 'b': show_bind = 1; break;
2292 case 'S': show_soname = 1; break;
2293 case 'T': show_textrels = 1; break;
2294 default:
2295 err("invalid format specifier '%c' (byte %i)",
2296 out_format[i], i+1);
2297 }
2298 }
543 2299
2300 /* construct our default format */
2301 } else {
2302 size_t fmt_len = 30;
2303 out_format = xmalloc(sizeof(char) * fmt_len);
2304 *out_format = '\0';
2305 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
2306 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2307 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2308 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2309 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2310 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2311 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
2312 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
2313 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
2314 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
2315 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
2316 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
2317 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
2318 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
2319 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
2320 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2321 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
2322 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
2323 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
2324 }
2325 if (be_verbose > 2) printf("Format: %s\n", out_format);
2326
2327 /* now lets actually do the scanning */
2328 if (load_cache_config)
2329 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
544 if (scan_ldpath) scanelf_ldpath(); 2330 if (scan_ldpath) scanelf_ldpath();
545 if (scan_envpath) scanelf_envpath(); 2331 if (scan_envpath) scanelf_envpath();
2332 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2333 from_file = "-";
2334 if (from_file) {
2335 scanelf_from_file(from_file);
2336 from_file = *argv;
2337 }
546 if (optind == argc && !scan_ldpath && !scan_envpath) 2338 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
547 err("Nothing to scan !?"); 2339 err("Nothing to scan !?");
548 while (optind < argc) 2340 while (optind < argc) {
549 scanelf_dir(argv[optind++]); 2341 search_path = argv[optind++];
2342 ret = scanelf_dir(search_path);
2343 }
550 2344
551 if (find_sym) free(find_sym); 2345#ifdef __PAX_UTILS_CLEANUP
552} 2346 /* clean up */
2347 xarrayfree(ldpaths);
2348 xarrayfree(find_sym_arr);
2349 xarrayfree(find_lib_arr);
2350 xarrayfree(find_section_arr);
2351 free(find_sym);
2352 free(find_lib);
2353 free(find_section);
2354 {
2355 size_t n;
2356 regex_t *preg;
2357 array_for_each(find_sym_regex_arr, n, preg)
2358 regfree(preg);
2359 xarrayfree(find_sym_regex_arr);
2360 }
553 2361
2362 if (ldcache != 0)
2363 munmap(ldcache, ldcache_size);
2364#endif
554 2365
2366 return ret;
2367}
2368
2369static char **get_split_env(const char *envvar)
2370{
2371 const char *delims = " \t\n";
2372 char **envvals = NULL;
2373 char *env, *s;
2374 int nentry;
2375
2376 if ((env = getenv(envvar)) == NULL)
2377 return NULL;
2378
2379 env = xstrdup(env);
2380 if (env == NULL)
2381 return NULL;
2382
2383 s = strtok(env, delims);
2384 if (s == NULL) {
2385 free(env);
2386 return NULL;
2387 }
2388
2389 nentry = 0;
2390 while (s != NULL) {
2391 ++nentry;
2392 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2393 envvals[nentry-1] = s;
2394 s = strtok(NULL, delims);
2395 }
2396 envvals[nentry] = NULL;
2397
2398 /* don't want to free(env) as it contains the memory that backs
2399 * the envvals array of strings */
2400 return envvals;
2401}
2402
2403static void parseenv(void)
2404{
2405 color_init(false);
2406 qa_textrels = get_split_env("QA_TEXTRELS");
2407 qa_execstack = get_split_env("QA_EXECSTACK");
2408 qa_wx_load = get_split_env("QA_WX_LOAD");
2409}
2410
2411#ifdef __PAX_UTILS_CLEANUP
2412static void cleanup(void)
2413{
2414 free(out_format);
2415 free(qa_textrels);
2416 free(qa_execstack);
2417 free(qa_wx_load);
2418}
2419#endif
555 2420
556int main(int argc, char *argv[]) 2421int main(int argc, char *argv[])
557{ 2422{
2423 int ret;
558 if (argc < 2) 2424 if (argc < 2)
559 usage(EXIT_FAILURE); 2425 usage(EXIT_FAILURE);
2426 parseenv();
560 parseargs(argc, argv); 2427 ret = parseargs(argc, argv);
561 fclose(stdout); 2428 fclose(stdout);
562 return EXIT_SUCCESS; 2429#ifdef __PAX_UTILS_CLEANUP
2430 cleanup();
2431 warn("The calls to add/delete heap should be off:\n"
2432 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2433 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
2434#endif
2435 return ret;
563} 2436}
2437
2438/* Match filename against entries in matchlist, return TRUE
2439 * if the file is listed */
2440static int file_matches_list(const char *filename, char **matchlist)
2441{
2442 char **file;
2443 char *match;
2444 char buf[__PAX_UTILS_PATH_MAX];
2445
2446 if (matchlist == NULL)
2447 return 0;
2448
2449 for (file = matchlist; *file != NULL; file++) {
2450 if (search_path) {
2451 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2452 match = buf;
2453 } else {
2454 match = *file;
2455 }
2456 if (fnmatch(match, filename, 0) == 0)
2457 return 1;
2458 }
2459 return 0;
2460}

Legend:
Removed from v.1.32  
changed lines
  Added in v.1.254

  ViewVC Help
Powered by ViewVC 1.1.20