/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.88 Revision 1.154
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2006 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.88 2005/09/30 03:30:54 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.154 2006/06/03 18:25:18 solar Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h>
11#include <stdlib.h>
12#include <sys/types.h>
13#include <libgen.h>
14#include <limits.h>
15#define __USE_GNU
16#include <string.h>
17#include <errno.h>
18#include <unistd.h>
19#include <sys/stat.h>
20#include <dirent.h>
21#include <getopt.h>
22#include <assert.h>
23#include "paxelf.h" 10#include "paxinc.h"
24 11
25static const char *rcsid = "$Id: scanelf.c,v 1.88 2005/09/30 03:30:54 vapier Exp $"; 12static const char *rcsid = "$Id: scanelf.c,v 1.154 2006/06/03 18:25:18 solar Exp $";
26#define argv0 "scanelf" 13#define argv0 "scanelf"
27 14
28#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
29 16
17#define do_state(option, flag) \
18 if (islower(option)) { \
19 flags &= ~PF_##flag; \
20 flags |= PF_NO##flag; \
21 } else { \
22 flags &= ~PF_NO##flag; \
23 flags |= PF_##flag; \
24 }
30 25
31 26
32/* prototypes */ 27/* prototypes */
28static int file_matches_list(const char *filename, char **matchlist);
29static int scanelf_elfobj(elfobj *elf);
30static int scanelf_elf(const char *filename, int fd, size_t len);
31static int scanelf_archive(const char *filename, int fd, size_t len);
33static void scanelf_file(const char *filename); 32static void scanelf_file(const char *filename);
34static void scanelf_dir(const char *path); 33static void scanelf_dir(const char *path);
35static void scanelf_ldpath(); 34static void scanelf_ldpath(void);
36static void scanelf_envpath(); 35static void scanelf_envpath(void);
37static void usage(int status); 36static void usage(int status);
37static char **get_split_env(const char *envvar);
38static void parseenv(void);
38static void parseargs(int argc, char *argv[]); 39static void parseargs(int argc, char *argv[]);
39static char *xstrdup(const char *s); 40static char *xstrdup(const char *s);
40static void *xmalloc(size_t size); 41static void *xmalloc(size_t size);
42static void *xrealloc(void *ptr, size_t size);
41static void xstrcat(char **dst, const char *src, size_t *curr_len); 43static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
44#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
42static inline void xchrcat(char **dst, const char append, size_t *curr_len); 45static inline void xchrcat(char **dst, const char append, size_t *curr_len);
43 46
44/* variables to control behavior */ 47/* variables to control behavior */
48static char match_etypes[126] = "";
45static char *ldpaths[256]; 49static char *ldpaths[256];
46static char scan_ldpath = 0; 50static char scan_ldpath = 0;
47static char scan_envpath = 0; 51static char scan_envpath = 0;
48static char scan_symlink = 1; 52static char scan_symlink = 1;
53static char scan_archives = 0;
49static char dir_recurse = 0; 54static char dir_recurse = 0;
50static char dir_crossmount = 1; 55static char dir_crossmount = 1;
51static char show_pax = 0; 56static char show_pax = 0;
52static char show_phdr = 0; 57static char show_phdr = 0;
53static char show_textrel = 0; 58static char show_textrel = 0;
59static char show_textrels = 0; 64static char show_textrels = 0;
60static char show_banner = 1; 65static char show_banner = 1;
61static char be_quiet = 0; 66static char be_quiet = 0;
62static char be_verbose = 0; 67static char be_verbose = 0;
63static char be_wewy_wewy_quiet = 0; 68static char be_wewy_wewy_quiet = 0;
69static char be_semi_verbose = 0;
64static char *find_sym = NULL, *versioned_symname = NULL; 70static char *find_sym = NULL, *versioned_symname = NULL;
65static char *find_lib = NULL; 71static char *find_lib = NULL;
72static char *find_section = NULL;
66static char *out_format = NULL; 73static char *out_format = NULL;
67static char *search_path = NULL; 74static char *search_path = NULL;
75static char fix_elf = 0;
68static char gmatch = 0; 76static char gmatch = 0;
77static char use_ldcache = 0;
78
79static char **qa_textrels = NULL;
80static char **qa_execstack = NULL;
81static char **qa_wx_load = NULL;
82
83int match_bits = 0;
84caddr_t ldcache = 0;
85size_t ldcache_size = 0;
86unsigned long setpax = 0UL;
87
88/* utility funcs */
89static char *xstrdup(const char *s)
90{
91 char *ret = strdup(s);
92 if (!ret) err("Could not strdup(): %s", strerror(errno));
93 return ret;
94}
95static void *xmalloc(size_t size)
96{
97 void *ret = malloc(size);
98 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
99 return ret;
100}
101static void *xrealloc(void *ptr, size_t size)
102{
103 void *ret = realloc(ptr, size);
104 if (!ret) err("Could not realloc() %li bytes", (unsigned long)size);
105 return ret;
106}
107static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
108{
109 size_t new_len;
110
111 new_len = strlen(*dst) + strlen(src);
112 if (*curr_len <= new_len) {
113 *curr_len = new_len + (*curr_len / 2);
114 *dst = realloc(*dst, *curr_len);
115 if (!*dst)
116 err("could not realloc() %li bytes", (unsigned long)*curr_len);
117 }
118
119 if (n)
120 strncat(*dst, src, n);
121 else
122 strcat(*dst, src);
123}
124static inline void xchrcat(char **dst, const char append, size_t *curr_len)
125{
126 static char my_app[2];
127 my_app[0] = append;
128 my_app[1] = '\0';
129 xstrcat(dst, my_app, curr_len);
130}
131
132/* Match filename against entries in matchlist, return TRUE
133 * if the file is listed */
134static int file_matches_list(const char *filename, char **matchlist)
135{
136 char **file;
137 char *match;
138 char buf[__PAX_UTILS_PATH_MAX];
139
140 if (matchlist == NULL)
141 return 0;
142
143 for (file = matchlist; *file != NULL; file++) {
144 if (search_path) {
145 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
146 match = buf;
147 } else {
148 match = *file;
149 }
150 if (fnmatch(match, filename, 0) == 0)
151 return 1;
152 }
153 return 0;
154}
155
69 156
70 157
71/* sub-funcs for scanelf_file() */ 158/* sub-funcs for scanelf_file() */
72static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 159static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab)
73{ 160{
93 } \ 180 } \
94 } 181 }
95 GET_SYMTABS(32) 182 GET_SYMTABS(32)
96 GET_SYMTABS(64) 183 GET_SYMTABS(64)
97} 184}
185
98static char *scanelf_file_pax(elfobj *elf, char *found_pax) 186static char *scanelf_file_pax(elfobj *elf, char *found_pax)
99{ 187{
100 static char *paxflags;
101 static char ret[7]; 188 static char ret[7];
102 unsigned long i, shown; 189 unsigned long i, shown;
103 190
104 if (!show_pax) return NULL; 191 if (!show_pax) return NULL;
105 192
112 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 199 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
113 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 200 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
114 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 201 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
115 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 202 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
116 continue; \ 203 continue; \
117 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 204 if (fix_elf && setpax) { \
205 /* set the paxctl flags */ \
206 ESET(phdr[i].p_flags, setpax); \
207 } \
208 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
118 continue; \ 209 continue; \
119 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 210 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
120 *found_pax = 1; \ 211 *found_pax = 1; \
121 ++shown; \ 212 ++shown; \
122 break; \ 213 break; \
124 } 215 }
125 SHOW_PAX(32) 216 SHOW_PAX(32)
126 SHOW_PAX(64) 217 SHOW_PAX(64)
127 } 218 }
128 219
220
221 if (fix_elf && setpax) {
222 /* set the chpax settings */
223 if (elf->elf_class == ELFCLASS32) {
224 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
225 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
226 } else {
227 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
228 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
229 }
230 }
231
129 /* fall back to EI_PAX if no PT_PAX was found */ 232 /* fall back to EI_PAX if no PT_PAX was found */
130 if (!*ret) { 233 if (!*ret) {
234 static char *paxflags;
131 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 235 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
132 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) { 236 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
133 *found_pax = 1; 237 *found_pax = 1;
134 return paxflags; 238 return (be_wewy_wewy_quiet ? NULL : paxflags);
135 } 239 }
136 strncpy(ret, paxflags, sizeof(ret)); 240 strncpy(ret, paxflags, sizeof(ret));
137 } 241 }
138 242
139 if (be_quiet && !shown) 243 if (be_wewy_wewy_quiet || (be_quiet && !shown))
140 return NULL; 244 return NULL;
245 else
141 return ret; 246 return ret;
142
143} 247}
248
144static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 249static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
145{ 250{
146 static char ret[12]; 251 static char ret[12];
147 char *found; 252 char *found;
148 unsigned long i, off, shown, check_flags;
149 unsigned char multi_stack, multi_relro, multi_load; 253 unsigned long i, shown, multi_stack, multi_relro, multi_load;
254 int max_pt_load;
150 255
151 if (!show_phdr) return NULL; 256 if (!show_phdr) return NULL;
152 257
153 memcpy(ret, "--- --- ---\0", 12); 258 memcpy(ret, "--- --- ---\0", 12);
154 259
155 shown = 0; 260 shown = 0;
156 multi_stack = multi_relro = multi_load = 0; 261 multi_stack = multi_relro = multi_load = 0;
262 max_pt_load = elf_max_pt_load(elf);
157 263
158 if (elf->phdr) { 264#define NOTE_GNU_STACK ".note.GNU-stack"
159#define SHOW_PHDR(B) \ 265#define SHOW_PHDR(B) \
160 if (elf->elf_class == ELFCLASS ## B) { \ 266 if (elf->elf_class == ELFCLASS ## B) { \
161 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 267 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
268 Elf ## B ## _Off offset; \
269 uint32_t flags, check_flags; \
270 if (elf->phdr != NULL) { \
162 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 271 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
163 uint32_t flags; \
164 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 272 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
165 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 273 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
274 if (multi_stack++) \
166 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 275 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
276 if (file_matches_list(elf->filename, qa_execstack)) \
277 continue; \
167 found = found_phdr; \ 278 found = found_phdr; \
168 off = 0; \ 279 offset = 0; \
169 check_flags = PF_X; \ 280 check_flags = PF_X; \
170 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 281 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
282 if (multi_relro++) \
171 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 283 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
172 found = found_relro; \ 284 found = found_relro; \
173 off = 4; \ 285 offset = 4; \
174 check_flags = PF_X; \ 286 check_flags = PF_X; \
175 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 287 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
176 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 288 if (ehdr->e_type == ET_DYN || ehdr->e_type == ET_EXEC) \
289 if (multi_load++ > max_pt_load) \
290 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
291 if (file_matches_list(elf->filename, qa_wx_load)) \
292 continue; \
177 found = found_load; \ 293 found = found_load; \
178 off = 8; \ 294 offset = 8; \
179 check_flags = PF_W|PF_X; \ 295 check_flags = PF_W|PF_X; \
180 } else \ 296 } else \
181 continue; \ 297 continue; \
182 flags = EGET(phdr[i].p_flags); \ 298 flags = EGET(phdr[i].p_flags); \
183 if (be_quiet && ((flags & check_flags) != check_flags)) \ 299 if (be_quiet && ((flags & check_flags) != check_flags)) \
184 continue; \ 300 continue; \
301 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
302 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
303 ret[3] = ret[7] = '!'; \
304 flags = EGET(phdr[i].p_flags); \
305 } \
185 memcpy(ret+off, gnu_short_stack_flags(flags), 3); \ 306 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
186 *found = 1; \ 307 *found = 1; \
187 ++shown; \ 308 ++shown; \
309 } \
310 } else if (elf->shdr != NULL) { \
311 /* no program headers which means this is prob an object file */ \
312 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
313 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
314 char *str; \
315 if ((void*)strtbl > (void*)elf->data_end) \
316 goto skip_this_shdr##B; \
317 check_flags = SHF_WRITE|SHF_EXECINSTR; \
318 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
319 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
320 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
321 str = elf->data + offset; \
322 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
323 if (!strcmp(str, NOTE_GNU_STACK)) { \
324 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
325 flags = EGET(shdr[i].sh_flags); \
326 if (be_quiet && ((flags & check_flags) != check_flags)) \
327 continue; \
328 ++*found_phdr; \
329 shown = 1; \
330 if (flags & SHF_WRITE) ret[0] = 'W'; \
331 if (flags & SHF_ALLOC) ret[1] = 'A'; \
332 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
333 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
334 break; \
335 } \
336 } \
337 skip_this_shdr##B: \
338 if (!multi_stack) { \
339 *found_phdr = 1; \
340 shown = 1; \
341 memcpy(ret, "!WX", 3); \
342 } \
188 } \ 343 } \
189 } 344 }
190 SHOW_PHDR(32) 345 SHOW_PHDR(32)
191 SHOW_PHDR(64) 346 SHOW_PHDR(64)
192 }
193 347
194 if (be_quiet && !shown) 348 if (be_wewy_wewy_quiet || (be_quiet && !shown))
195 return NULL; 349 return NULL;
196 else 350 else
197 return ret; 351 return ret;
198} 352}
353
199static char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 354static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
200{ 355{
201 static char ret[] = "TEXTREL"; 356 static const char *ret = "TEXTREL";
202 unsigned long i; 357 unsigned long i;
203 358
204 if (!show_textrel && !show_textrels) return NULL; 359 if (!show_textrel && !show_textrels) return NULL;
360
361 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
205 362
206 if (elf->phdr) { 363 if (elf->phdr) {
207#define SHOW_TEXTREL(B) \ 364#define SHOW_TEXTREL(B) \
208 if (elf->elf_class == ELFCLASS ## B) { \ 365 if (elf->elf_class == ELFCLASS ## B) { \
209 Elf ## B ## _Dyn *dyn; \ 366 Elf ## B ## _Dyn *dyn; \
229 } 386 }
230 387
231 if (be_quiet || be_wewy_wewy_quiet) 388 if (be_quiet || be_wewy_wewy_quiet)
232 return NULL; 389 return NULL;
233 else 390 else
234 return (char *)" - "; 391 return " - ";
235} 392}
236static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 393static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
237{ 394{
238 unsigned long s, r, rmax; 395 unsigned long s, r, rmax;
239 void *symtab_void, *strtab_void, *text_void; 396 void *symtab_void, *strtab_void, *text_void;
292 if (be_verbose <= 2) continue; \ 449 if (be_verbose <= 2) continue; \
293 } else \ 450 } else \
294 *found_textrels = 1; \ 451 *found_textrels = 1; \
295 /* locate this relocation symbol name */ \ 452 /* locate this relocation symbol name */ \
296 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 453 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
454 if ((void*)sym > (void*)elf->data_end) { \
455 warn("%s: corrupt ELF symbol", elf->filename); \
456 continue; \
457 } \
297 sym_max = ELF ## B ## _R_SYM(r_info); \ 458 sym_max = ELF ## B ## _R_SYM(r_info); \
298 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 459 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
299 sym += sym_max; \ 460 sym += sym_max; \
300 else \ 461 else \
301 sym = NULL; \ 462 sym = NULL; \
333 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 494 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
334 495
335 return NULL; 496 return NULL;
336} 497}
337 498
338static void rpath_security_checks(elfobj *, char *); 499static void rpath_security_checks(elfobj *, char *, const char *);
339static void rpath_security_checks(elfobj *elf, char *item) { 500static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
501{
340 struct stat st; 502 struct stat st;
341 switch (*item) { 503 switch (*item) {
342 case 0:
343 warnf("Security problem NULL RPATH in %s", elf->filename);
344 break;
345 case '/': break; 504 case '/': break;
505 case '.':
506 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
507 break;
508 case ':':
509 case '\0':
510 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
511 break;
346 case '$': 512 case '$':
347 if (fstat(elf->fd, &st) != -1) 513 if (fstat(elf->fd, &st) != -1)
348 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 514 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
349 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 515 warnf("Security problem with %s='%s' in %s with mode set of %o",
350 item, elf->filename, st.st_mode & 07777); 516 dt_type, item, elf->filename, st.st_mode & 07777);
351 break; 517 break;
352 default: 518 default:
353 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 519 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
354 break; 520 break;
355 } 521 }
356} 522}
357static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 523static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
358{ 524{
394 /* Verify the memory is somewhat sane */ \ 560 /* Verify the memory is somewhat sane */ \
395 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 561 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
396 if (offset < (Elf ## B ## _Off)elf->len) { \ 562 if (offset < (Elf ## B ## _Off)elf->len) { \
397 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 563 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
398 *r = (char*)(elf->data + offset); \ 564 *r = (char*)(elf->data + offset); \
565 /* cache the length in case we need to nuke this section later on */ \
566 if (fix_elf) \
567 offset = strlen(*r); \
399 /* If quiet, don't output paths in ld.so.conf */ \ 568 /* If quiet, don't output paths in ld.so.conf */ \
400 if (be_quiet) { \ 569 if (be_quiet) { \
401 size_t len; \ 570 size_t len; \
402 char *start, *end; \ 571 char *start, *end; \
403 /* note that we only 'chop' off leading known paths. */ \ 572 /* note that we only 'chop' off leading known paths. */ \
404 /* since *r is read-only memory, we can only move the ptr forward. */ \ 573 /* since *r is read-only memory, we can only move the ptr forward. */ \
405 start = *r; \ 574 start = *r; \
406 /* scan each path in : delimited list */ \ 575 /* scan each path in : delimited list */ \
407 while (start) { \ 576 while (start) { \
408 rpath_security_checks(elf, start); \ 577 rpath_security_checks(elf, start, get_elfdtype(word)); \
409 end = strchr(start, ':'); \ 578 end = strchr(start, ':'); \
410 len = (end ? abs(end - start) : strlen(start)); \ 579 len = (end ? abs(end - start) : strlen(start)); \
580 if (use_ldcache) \
411 for (s = 0; ldpaths[s]; ++s) { \ 581 for (s = 0; ldpaths[s]; ++s) \
412 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 582 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \
413 *r = (end ? end + 1 : NULL); \ 583 *r = end; \
584 /* corner case ... if RPATH reads "/usr/lib:", we want \
585 * to show ':' rather than '' */ \
586 if (end && end[1] != '\0') \
587 (*r)++; \
414 break; \ 588 break; \
415 } \ 589 } \
416 } \
417 if (!*r || !ldpaths[s] || !end) \ 590 if (!*r || !end) \
418 start = NULL; \ 591 break; \
419 else \ 592 else \
420 start = start + len + 1; \ 593 start = start + len + 1; \
421 } \ 594 } \
422 } \ 595 } \
596 if (*r) { \
597 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
598 /* just nuke it */ \
599 nuke_it##B: \
600 memset(*r, 0x00, offset); \
601 *r = NULL; \
602 ESET(dyn->d_tag, DT_DEBUG); \
603 ESET(dyn->d_un.d_ptr, 0); \
604 } else if (fix_elf) { \
605 /* try to clean "bad" paths */ \
606 size_t len, tmpdir_len; \
607 char *start, *end; \
608 const char *tmpdir; \
609 start = *r; \
610 tmpdir = (getenv("TMPDIR") ? : "."); \
611 tmpdir_len = strlen(tmpdir); \
612 while (1) { \
613 end = strchr(start, ':'); \
614 if (start == end) { \
615 eat_this_path##B: \
616 len = strlen(end); \
617 memmove(start, end+1, len); \
618 start[len-1] = '\0'; \
619 end = start - 1; \
620 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
621 if (!end) { \
622 if (start == *r) \
623 goto nuke_it##B; \
624 *--start = '\0'; \
625 } else \
626 goto eat_this_path##B; \
627 } \
628 if (!end) \
629 break; \
630 start = end + 1; \
631 } \
632 if (**r == '\0') \
633 goto nuke_it##B; \
634 } \
635 if (*r) \
423 if (*r) *found_rpath = 1; \ 636 *found_rpath = 1; \
637 } \
424 } \ 638 } \
425 ++dyn; \ 639 ++dyn; \
426 } \ 640 } \
427 } } 641 } }
428 SHOW_RPATH(32) 642 SHOW_RPATH(32)
445 } else if (rpath || runpath) 659 } else if (rpath || runpath)
446 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 660 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
447 else if (!be_quiet) 661 else if (!be_quiet)
448 xstrcat(ret, " - ", ret_len); 662 xstrcat(ret, " - ", ret_len);
449} 663}
664
665#define LDSO_CACHE_MAGIC "ld.so-"
666#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
667#define LDSO_CACHE_VER "1.7.0"
668#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
669#define FLAG_ANY -1
670#define FLAG_TYPE_MASK 0x00ff
671#define FLAG_LIBC4 0x0000
672#define FLAG_ELF 0x0001
673#define FLAG_ELF_LIBC5 0x0002
674#define FLAG_ELF_LIBC6 0x0003
675#define FLAG_REQUIRED_MASK 0xff00
676#define FLAG_SPARC_LIB64 0x0100
677#define FLAG_IA64_LIB64 0x0200
678#define FLAG_X8664_LIB64 0x0300
679#define FLAG_S390_LIB64 0x0400
680#define FLAG_POWERPC_LIB64 0x0500
681#define FLAG_MIPS64_LIBN32 0x0600
682#define FLAG_MIPS64_LIBN64 0x0700
683
684static char *lookup_cache_lib(elfobj *, char *);
685
686#if defined(__GLIBC__) || defined(__UCLIBC__)
687
688static char *lookup_cache_lib(elfobj *elf, char *fname)
689{
690 int fd = 0;
691 char *strs;
692 static char buf[__PAX_UTILS_PATH_MAX] = "";
693 const char *cachefile = "/etc/ld.so.cache";
694 struct stat st;
695
696 typedef struct {
697 char magic[LDSO_CACHE_MAGIC_LEN];
698 char version[LDSO_CACHE_VER_LEN];
699 int nlibs;
700 } header_t;
701 header_t *header;
702
703 typedef struct {
704 int flags;
705 int sooffset;
706 int liboffset;
707 } libentry_t;
708 libentry_t *libent;
709
710 if (fname == NULL)
711 return NULL;
712
713 if (ldcache == 0) {
714 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1)
715 return NULL;
716
717 /* cache these values so we only map/unmap the cache file once */
718 ldcache_size = st.st_size;
719 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
720
721 close(fd);
722
723 if (ldcache == (caddr_t)-1) {
724 ldcache = 0;
725 return NULL;
726 }
727
728 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN))
729 return NULL;
730 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
731 return NULL;
732 }
733
734 header = (header_t *) ldcache;
735 libent = (libentry_t *) (ldcache + sizeof(header_t));
736 strs = (char *) &libent[header->nlibs];
737
738 for (fd = 0; fd < header->nlibs; fd++) {
739 /* this should be more fine grained, but for now we assume that
740 * diff arches will not be cached together. and we ignore the
741 * the different multilib mips cases. */
742 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
743 continue;
744 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
745 continue;
746
747 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
748 continue;
749 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
750 }
751 return buf;
752}
753#elif defined(__NetBSD__)
754static char *lookup_cache_lib(elfobj *elf, char *fname)
755{
756 static char buf[__PAX_UTILS_PATH_MAX] = "";
757 static struct stat st;
758
759 char **ldpath;
760 for (ldpath = ldpaths; *ldpath != NULL; ldpath++) {
761 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", *ldpath, fname) >= sizeof(buf))
762 continue; /* if the pathname is too long, or something went wrong, ignore */
763
764 if (stat(buf, &st) != 0)
765 continue; /* if the lib doesn't exist in *ldpath, look further */
766
767 /* NetBSD doesn't actually do sanity checks, it just loads the file
768 * and if that doesn't work, continues looking in other directories.
769 * This cannot easily be safely emulated, unfortunately. For now,
770 * just assume that if it exists, it's a valid library. */
771
772 return buf;
773 }
774
775 /* not found in any path */
776 return NULL;
777}
778#else
779#warning Cache support not implemented for your target
780static char *lookup_cache_lib(elfobj *elf, char *fname)
781{
782 return NULL;
783}
784#endif
785
450static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 786static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
451{ 787{
452 unsigned long i; 788 unsigned long i;
453 char *needed; 789 char *needed;
454 void *strtbl_void; 790 void *strtbl_void;
791 char *p;
455 792
456 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 793 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL;
457 794
458 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 795 strtbl_void = elf_findsecbyname(elf, ".dynstr");
459 796
479 } \ 816 } \
480 needed = (char*)(elf->data + offset); \ 817 needed = (char*)(elf->data + offset); \
481 if (op == 0) { \ 818 if (op == 0) { \
482 if (!be_wewy_wewy_quiet) { \ 819 if (!be_wewy_wewy_quiet) { \
483 if (*found_needed) xchrcat(ret, ',', ret_len); \ 820 if (*found_needed) xchrcat(ret, ',', ret_len); \
821 if (use_ldcache) \
822 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
823 needed = p; \
484 xstrcat(ret, needed, ret_len); \ 824 xstrcat(ret, needed, ret_len); \
485 } \ 825 } \
486 *found_needed = 1; \ 826 *found_needed = 1; \
487 } else { \ 827 } else { \
488 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 828 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \
524} 864}
525static char *scanelf_file_bind(elfobj *elf, char *found_bind) 865static char *scanelf_file_bind(elfobj *elf, char *found_bind)
526{ 866{
527 unsigned long i; 867 unsigned long i;
528 struct stat s; 868 struct stat s;
869 char dynamic = 0;
529 870
530 if (!show_bind) return NULL; 871 if (!show_bind) return NULL;
531 if (!elf->phdr) return NULL; 872 if (!elf->phdr) return NULL;
532 873
533#define SHOW_BIND(B) \ 874#define SHOW_BIND(B) \
536 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 877 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
537 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 878 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
538 Elf ## B ## _Off offset; \ 879 Elf ## B ## _Off offset; \
539 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 880 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
540 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 881 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \
882 dynamic = 1; \
541 offset = EGET(phdr[i].p_offset); \ 883 offset = EGET(phdr[i].p_offset); \
542 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 884 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
543 dyn = DYN ## B (elf->data + offset); \ 885 dyn = DYN ## B (elf->data + offset); \
544 while (EGET(dyn->d_tag) != DT_NULL) { \ 886 while (EGET(dyn->d_tag) != DT_NULL) { \
545 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 887 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
560 902
561 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 903 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) {
562 return NULL; 904 return NULL;
563 } else { 905 } else {
564 *found_bind = 1; 906 *found_bind = 1;
565 return (char *) "LAZY"; 907 return (char *) (dynamic ? "LAZY" : "STATIC");
566 } 908 }
567} 909}
568static char *scanelf_file_soname(elfobj *elf, char *found_soname) 910static char *scanelf_file_soname(elfobj *elf, char *found_soname)
569{ 911{
570 unsigned long i; 912 unsigned long i;
612 return NULL; 954 return NULL;
613} 955}
614static char *scanelf_file_sym(elfobj *elf, char *found_sym) 956static char *scanelf_file_sym(elfobj *elf, char *found_sym)
615{ 957{
616 unsigned long i; 958 unsigned long i;
959 char *ret;
617 void *symtab_void, *strtab_void; 960 void *symtab_void, *strtab_void;
618 961
619 if (!find_sym) return NULL; 962 if (!find_sym) return NULL;
963 ret = find_sym;
620 964
621 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 965 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
622 966
623 if (symtab_void && strtab_void) { 967 if (symtab_void && strtab_void) {
624#define FIND_SYM(B) \ 968#define FIND_SYM(B) \
625 if (elf->elf_class == ELFCLASS ## B) { \ 969 if (elf->elf_class == ELFCLASS ## B) { \
626 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 970 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
627 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 971 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
628 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 972 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \
629 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 973 unsigned long cnt = EGET(symtab->sh_entsize); \
630 char *symname; \ 974 char *symname; \
975 if (cnt) \
976 cnt = EGET(symtab->sh_size) / cnt; \
631 for (i = 0; i < cnt; ++i) { \ 977 for (i = 0; i < cnt; ++i) { \
632 if (sym->st_name) { \ 978 if (sym->st_name) { \
979 /* make sure the symbol name is in acceptable memory range */ \
633 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 980 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
981 if ((void*)symname > (void*)elf->data_end) { \
982 warnf("%s: corrupt ELF symbols", elf->filename); \
983 ++sym; \
984 continue; \
985 } \
986 /* debug display ... show all symbols and some extra info */ \
634 if (*find_sym == '*') { \ 987 if (*ret == '*') { \
635 printf("%s(%s) %5lX %15s %s\n", \ 988 printf("%s(%s) %5lX %15s %s\n", \
636 ((*found_sym == 0) ? "\n\t" : "\t"), \ 989 ((*found_sym == 0) ? "\n\t" : "\t"), \
637 elf->base_filename, \ 990 elf->base_filename, \
638 (long)sym->st_size, \ 991 (unsigned long)sym->st_size, \
639 (char *)get_elfstttype(sym->st_info), \ 992 get_elfstttype(sym->st_info), \
640 symname); \ 993 symname); \
641 *found_sym = 1; \ 994 *found_sym = 1; \
642 } else if ((strcmp(find_sym, symname) == 0) || \ 995 } else { \
643 (strcmp(symname, versioned_symname) == 0)) \ 996 /* allow the user to specify a comma delimited list of symbols to search for */ \
997 char *this_sym, *next_sym; \
998 this_sym = ret; \
999 do { \
1000 next_sym = strchr(this_sym, ','); \
1001 if (next_sym == NULL) \
1002 next_sym = this_sym + strlen(this_sym); \
1003 /* do we want a defined symbol ? */ \
1004 if (*this_sym == '+') { \
1005 if (sym->st_shndx == SHN_UNDEF) \
1006 goto skip_this_sym##B; \
1007 ++this_sym; \
1008 /* do we want an undefined symbol ? */ \
1009 } else if (*this_sym == '-') { \
1010 if (sym->st_shndx != SHN_UNDEF) \
1011 goto skip_this_sym##B; \
1012 ++this_sym; \
1013 } \
1014 /* ok, lets compare the name now */ \
1015 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
1016 (strncmp(symname, versioned_symname, strlen(versioned_symname)) == 0)) { \
1017 if (be_semi_verbose) { \
1018 char buf[126]; \
1019 snprintf(buf, sizeof(buf), "%lX %s %s", \
1020 (unsigned long)sym->st_size, get_elfstttype(sym->st_info), this_sym); \
1021 ret = buf; \
1022 } else \
1023 ret = this_sym; \
644 (*found_sym)++; \ 1024 (*found_sym)++; \
1025 goto break_out; \
1026 } \
1027 skip_this_sym##B: this_sym = next_sym + 1; \
1028 } while (*next_sym != '\0'); \
1029 } \
645 } \ 1030 } \
646 ++sym; \ 1031 ++sym; \
647 } } 1032 } }
648 FIND_SYM(32) 1033 FIND_SYM(32)
649 FIND_SYM(64) 1034 FIND_SYM(64)
650 } 1035 }
651 1036
1037break_out:
652 if (be_wewy_wewy_quiet) return NULL; 1038 if (be_wewy_wewy_quiet) return NULL;
653 1039
654 if (*find_sym != '*' && *found_sym) 1040 if (*find_sym != '*' && *found_sym)
655 return find_sym; 1041 return ret;
656 if (be_quiet) 1042 if (be_quiet)
657 return NULL; 1043 return NULL;
658 else 1044 else
659 return (char *)" - "; 1045 return (char *)" - ";
660} 1046}
1047
1048
1049static char *scanelf_file_sections(elfobj *elf, char *found_section)
1050{
1051 if (!find_section)
1052 return NULL;
1053
1054#define FIND_SECTION(B) \
1055 if (elf->elf_class == ELFCLASS ## B) { \
1056 int invert; \
1057 Elf ## B ## _Shdr *section; \
1058 invert = (*find_section == '!' ? 1 : 0); \
1059 section = SHDR ## B (elf_findsecbyname(elf, find_section+invert)); \
1060 if ((section == NULL && invert) || (section != NULL && !invert)) \
1061 *found_section = 1; \
1062 }
1063 FIND_SECTION(32)
1064 FIND_SECTION(64)
1065
1066 if (be_wewy_wewy_quiet)
1067 return NULL;
1068
1069 if (*found_section)
1070 return find_section;
1071
1072 if (be_quiet)
1073 return NULL;
1074 else
1075 return (char *)" - ";
1076}
1077
661/* scan an elf file and show all the fun stuff */ 1078/* scan an elf file and show all the fun stuff */
662#define prints(str) write(fileno(stdout), str, strlen(str)) 1079#define prints(str) write(fileno(stdout), str, strlen(str))
663static void scanelf_file(const char *filename) 1080static int scanelf_elfobj(elfobj *elf)
664{ 1081{
665 unsigned long i; 1082 unsigned long i;
666 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1083 char found_pax, found_phdr, found_relro, found_load, found_textrel,
667 found_rpath, found_needed, found_interp, found_bind, found_soname, 1084 found_rpath, found_needed, found_interp, found_bind, found_soname,
668 found_sym, found_lib, found_file, found_textrels; 1085 found_sym, found_lib, found_file, found_textrels, found_section;
669 elfobj *elf;
670 struct stat st;
671 static char *out_buffer = NULL; 1086 static char *out_buffer = NULL;
672 static size_t out_len; 1087 static size_t out_len;
673 1088
674 /* make sure 'filename' exists */
675 if (lstat(filename, &st) == -1) {
676 if (be_verbose > 2) printf("%s: does not exist\n", filename);
677 return;
678 }
679 /* always handle regular files and handle symlinked files if no -y */
680 if (S_ISLNK(st.st_mode)) {
681 if (!scan_symlink) return;
682 stat(filename, &st);
683 }
684 if (!S_ISREG(st.st_mode)) {
685 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
686 return;
687 }
688
689 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1089 found_pax = found_phdr = found_relro = found_load = found_textrel = \
690 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1090 found_rpath = found_needed = found_interp = found_bind = found_soname = \
691 found_sym = found_lib = found_file = found_textrels = 0; 1091 found_sym = found_lib = found_file = found_textrels = found_section = 0;
692 1092
693 /* verify this is real ELF */
694 if ((elf = readelf(filename)) == NULL) {
695 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
696 return;
697 }
698
699 if (be_verbose > 1) 1093 if (be_verbose > 2)
700 printf("%s: scanning file {%s,%s}\n", filename, 1094 printf("%s: scanning file {%s,%s}\n", elf->filename,
701 get_elfeitype(EI_CLASS, elf->elf_class), 1095 get_elfeitype(EI_CLASS, elf->elf_class),
702 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1096 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
703 else if (be_verbose) 1097 else if (be_verbose > 1)
704 printf("%s: scanning file\n", filename); 1098 printf("%s: scanning file\n", elf->filename);
705 1099
706 /* init output buffer */ 1100 /* init output buffer */
707 if (!out_buffer) { 1101 if (!out_buffer) {
708 out_len = sizeof(char) * 80; 1102 out_len = sizeof(char) * 80;
709 out_buffer = (char*)xmalloc(out_len); 1103 out_buffer = (char*)xmalloc(out_len);
714 if (!be_quiet && show_banner) { 1108 if (!be_quiet && show_banner) {
715 for (i = 0; out_format[i]; ++i) { 1109 for (i = 0; out_format[i]; ++i) {
716 if (!IS_MODIFIER(out_format[i])) continue; 1110 if (!IS_MODIFIER(out_format[i])) continue;
717 1111
718 switch (out_format[++i]) { 1112 switch (out_format[++i]) {
1113 case '+': break;
719 case '%': break; 1114 case '%': break;
720 case '#': break; 1115 case '#': break;
721 case 'F': 1116 case 'F':
722 case 'p': 1117 case 'p':
723 case 'f': prints("FILE "); found_file = 1; break; 1118 case 'f': prints("FILE "); found_file = 1; break;
731 case 'b': prints("BIND "); break; 1126 case 'b': prints("BIND "); break;
732 case 'S': prints("SONAME "); break; 1127 case 'S': prints("SONAME "); break;
733 case 's': prints("SYM "); break; 1128 case 's': prints("SYM "); break;
734 case 'N': prints("LIB "); break; 1129 case 'N': prints("LIB "); break;
735 case 'T': prints("TEXTRELS "); break; 1130 case 'T': prints("TEXTRELS "); break;
1131 case 'k': prints("SECTION "); break;
736 default: warnf("'%c' has no title ?", out_format[i]); 1132 default: warnf("'%c' has no title ?", out_format[i]);
737 } 1133 }
738 } 1134 }
739 if (!found_file) prints("FILE "); 1135 if (!found_file) prints("FILE ");
740 prints("\n"); 1136 prints("\n");
745 /* dump all the good stuff */ 1141 /* dump all the good stuff */
746 for (i = 0; out_format[i]; ++i) { 1142 for (i = 0; out_format[i]; ++i) {
747 const char *out; 1143 const char *out;
748 const char *tmp; 1144 const char *tmp;
749 1145
750 /* make sure we trim leading spaces in quiet mode */
751 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
752 *out_buffer = '\0';
753
754 if (!IS_MODIFIER(out_format[i])) { 1146 if (!IS_MODIFIER(out_format[i])) {
755 xchrcat(&out_buffer, out_format[i], &out_len); 1147 xchrcat(&out_buffer, out_format[i], &out_len);
756 continue; 1148 continue;
757 } 1149 }
758 1150
759 out = NULL; 1151 out = NULL;
760 be_wewy_wewy_quiet = (out_format[i] == '#'); 1152 be_wewy_wewy_quiet = (out_format[i] == '#');
1153 be_semi_verbose = (out_format[i] == '+');
761 switch (out_format[++i]) { 1154 switch (out_format[++i]) {
1155 case '+':
762 case '%': 1156 case '%':
763 case '#': 1157 case '#':
764 xchrcat(&out_buffer, out_format[i], &out_len); break; 1158 xchrcat(&out_buffer, out_format[i], &out_len); break;
765 case 'F': 1159 case 'F':
766 found_file = 1; 1160 found_file = 1;
767 if (be_wewy_wewy_quiet) break; 1161 if (be_wewy_wewy_quiet) break;
768 xstrcat(&out_buffer, filename, &out_len); 1162 xstrcat(&out_buffer, elf->filename, &out_len);
769 break; 1163 break;
770 case 'p': 1164 case 'p':
771 found_file = 1; 1165 found_file = 1;
772 if (be_wewy_wewy_quiet) break; 1166 if (be_wewy_wewy_quiet) break;
773 tmp = filename; 1167 tmp = elf->filename;
774 if (search_path) { 1168 if (search_path) {
775 ssize_t len_search = strlen(search_path); 1169 ssize_t len_search = strlen(search_path);
776 ssize_t len_file = strlen(filename); 1170 ssize_t len_file = strlen(elf->filename);
777 if (!strncmp(filename, search_path, len_search) && \ 1171 if (!strncmp(elf->filename, search_path, len_search) && \
778 len_file > len_search) 1172 len_file > len_search)
779 tmp += len_search; 1173 tmp += len_search;
780 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1174 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
781 } 1175 }
782 xstrcat(&out_buffer, tmp, &out_len); 1176 xstrcat(&out_buffer, tmp, &out_len);
783 break; 1177 break;
784 case 'f': 1178 case 'f':
785 found_file = 1; 1179 found_file = 1;
786 if (be_wewy_wewy_quiet) break; 1180 if (be_wewy_wewy_quiet) break;
787 tmp = strrchr(filename, '/'); 1181 tmp = strrchr(elf->filename, '/');
788 tmp = (tmp == NULL ? filename : tmp+1); 1182 tmp = (tmp == NULL ? elf->filename : tmp+1);
789 xstrcat(&out_buffer, tmp, &out_len); 1183 xstrcat(&out_buffer, tmp, &out_len);
790 break; 1184 break;
791 case 'o': out = get_elfetype(elf); break; 1185 case 'o': out = get_elfetype(elf); break;
792 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1186 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
793 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1187 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
798 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1192 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
799 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1193 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
800 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1194 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
801 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1195 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
802 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1196 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1197 case 'k': out = scanelf_file_sections(elf, &found_section); break;
803 default: warnf("'%c' has no scan code?", out_format[i]); 1198 default: warnf("'%c' has no scan code?", out_format[i]);
804 } 1199 }
1200 if (out) {
1201 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
1202 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
1203 xstrncat(&out_buffer, out, &out_len, (tmp-out));
1204 else
805 if (out) xstrcat(&out_buffer, out, &out_len); 1205 xstrcat(&out_buffer, out, &out_len);
1206 }
806 } 1207 }
807 1208
808#define FOUND_SOMETHING() \ 1209#define FOUND_SOMETHING() \
809 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1210 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
810 found_rpath || found_needed || found_interp || found_bind || \ 1211 found_rpath || found_needed || found_interp || found_bind || \
811 found_soname || found_sym || found_lib || found_textrels) 1212 found_soname || found_sym || found_lib || found_textrels || found_section )
812 1213
813 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1214 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
814 xchrcat(&out_buffer, ' ', &out_len); 1215 xchrcat(&out_buffer, ' ', &out_len);
815 xstrcat(&out_buffer, filename, &out_len); 1216 xstrcat(&out_buffer, elf->filename, &out_len);
816 } 1217 }
817 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1218 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
818 puts(out_buffer); 1219 puts(out_buffer);
819 fflush(stdout); 1220 fflush(stdout);
820 } 1221 }
821 1222
1223 return 0;
1224}
1225
1226/* scan a single elf */
1227static int scanelf_elf(const char *filename, int fd, size_t len)
1228{
1229 int ret = 1;
1230 elfobj *elf;
1231
1232 /* verify this is real ELF */
1233 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1234 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1235 return ret;
1236 }
1237 switch (match_bits) {
1238 case 32:
1239 if (elf->elf_class != ELFCLASS32)
1240 goto label_done;
1241 break;
1242 case 64:
1243 if (elf->elf_class != ELFCLASS64)
1244 goto label_done;
1245 break;
1246 default: break;
1247 }
1248 if (strlen(match_etypes)) {
1249 char sbuf[126];
1250 strncpy(sbuf, match_etypes, sizeof(sbuf));
1251 if (strchr(match_etypes, ',') != NULL) {
1252 char *p;
1253 while((p = strrchr(sbuf, ',')) != NULL) {
1254 *p = 0;
1255 if (etype_lookup(p+1) == get_etype(elf))
1256 goto label_ret;
1257 }
1258 }
1259 if (etype_lookup(sbuf) != get_etype(elf))
1260 goto label_done;
1261 }
1262
1263label_ret:
1264 ret = scanelf_elfobj(elf);
1265
1266label_done:
822 unreadelf(elf); 1267 unreadelf(elf);
1268 return ret;
1269}
1270
1271/* scan an archive of elfs */
1272static int scanelf_archive(const char *filename, int fd, size_t len)
1273{
1274 archive_handle *ar;
1275 archive_member *m;
1276 char *ar_buffer;
1277 elfobj *elf;
1278
1279 ar = ar_open_fd(filename, fd);
1280 if (ar == NULL)
1281 return 1;
1282
1283 ar_buffer = (char*)mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1284 while ((m=ar_next(ar)) != NULL) {
1285 elf = readelf_buffer(m->name, ar_buffer+lseek(fd,0,SEEK_CUR), m->size);
1286 if (elf) {
1287 scanelf_elfobj(elf);
1288 unreadelf(elf);
1289 }
1290 }
1291 munmap(ar_buffer, len);
1292
1293 return 0;
1294}
1295/* scan a file which may be an elf or an archive or some other magical beast */
1296static void scanelf_file(const char *filename)
1297{
1298 struct stat st;
1299 int fd;
1300
1301 /* make sure 'filename' exists */
1302 if (lstat(filename, &st) == -1) {
1303 if (be_verbose > 2) printf("%s: does not exist\n", filename);
1304 return;
1305 }
1306
1307 /* always handle regular files and handle symlinked files if no -y */
1308 if (S_ISLNK(st.st_mode)) {
1309 if (!scan_symlink) return;
1310 stat(filename, &st);
1311 }
1312 if (!S_ISREG(st.st_mode)) {
1313 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1314 return;
1315 }
1316
1317 if ((fd=open(filename, (fix_elf ? O_RDWR : O_RDONLY))) == -1)
1318 return;
1319
1320 if (scanelf_elf(filename, fd, st.st_size) == 1 && scan_archives)
1321 /* if it isn't an ELF, maybe it's an .a archive */
1322 scanelf_archive(filename, fd, st.st_size);
1323
1324 close(fd);
823} 1325}
824 1326
825/* scan a directory for ET_EXEC files and print when we find one */ 1327/* scan a directory for ET_EXEC files and print when we find one */
826static void scanelf_dir(const char *path) 1328static void scanelf_dir(const char *path)
827{ 1329{
828 register DIR *dir; 1330 register DIR *dir;
829 register struct dirent *dentry; 1331 register struct dirent *dentry;
830 struct stat st_top, st; 1332 struct stat st_top, st;
831 char buf[_POSIX_PATH_MAX]; 1333 char buf[__PAX_UTILS_PATH_MAX];
832 size_t pathlen = 0, len = 0; 1334 size_t pathlen = 0, len = 0;
833 1335
834 /* make sure path exists */ 1336 /* make sure path exists */
835 if (lstat(path, &st_top) == -1) { 1337 if (lstat(path, &st_top) == -1) {
836 if (be_verbose > 2) printf("%s: does not exist\n", path); 1338 if (be_verbose > 2) printf("%s: does not exist\n", path);
846 /* now scan the dir looking for fun stuff */ 1348 /* now scan the dir looking for fun stuff */
847 if ((dir = opendir(path)) == NULL) { 1349 if ((dir = opendir(path)) == NULL) {
848 warnf("could not opendir %s: %s", path, strerror(errno)); 1350 warnf("could not opendir %s: %s", path, strerror(errno));
849 return; 1351 return;
850 } 1352 }
851 if (be_verbose) printf("%s: scanning dir\n", path); 1353 if (be_verbose > 1) printf("%s: scanning dir\n", path);
852 1354
853 pathlen = strlen(path); 1355 pathlen = strlen(path);
854 while ((dentry = readdir(dir))) { 1356 while ((dentry = readdir(dir))) {
855 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1357 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
856 continue; 1358 continue;
858 if (len >= sizeof(buf)) { 1360 if (len >= sizeof(buf)) {
859 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1361 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
860 (unsigned long)len, (unsigned long)sizeof(buf)); 1362 (unsigned long)len, (unsigned long)sizeof(buf));
861 continue; 1363 continue;
862 } 1364 }
863 sprintf(buf, "%s/%s", path, dentry->d_name); 1365 snprintf(buf, sizeof(buf), "%s%s%s", path, (path[pathlen-1] == '/') ? "" : "/", dentry->d_name);
864 if (lstat(buf, &st) != -1) { 1366 if (lstat(buf, &st) != -1) {
865 if (S_ISREG(st.st_mode)) 1367 if (S_ISREG(st.st_mode))
866 scanelf_file(buf); 1368 scanelf_file(buf);
867 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1369 else if (dir_recurse && S_ISDIR(st.st_mode)) {
868 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1370 if (dir_crossmount || (st_top.st_dev == st.st_dev))
871 } 1373 }
872 } 1374 }
873 closedir(dir); 1375 closedir(dir);
874} 1376}
875 1377
876static int scanelf_from_file(char *filename) 1378static int scanelf_from_file(const char *filename)
877{ 1379{
878 FILE *fp = NULL; 1380 FILE *fp = NULL;
879 char *p; 1381 char *p;
880 char path[_POSIX_PATH_MAX]; 1382 char path[__PAX_UTILS_PATH_MAX];
881 1383
882 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1384 if (strcmp(filename, "-") == 0)
883 fp = stdin; 1385 fp = stdin;
884 else if ((fp = fopen(filename, "r")) == NULL) 1386 else if ((fp = fopen(filename, "r")) == NULL)
885 return 1; 1387 return 1;
886 1388
887 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1389 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
888 if ((p = strchr(path, '\n')) != NULL) 1390 if ((p = strchr(path, '\n')) != NULL)
889 *p = 0; 1391 *p = 0;
890 search_path = path; 1392 search_path = path;
891 scanelf_dir(path); 1393 scanelf_dir(path);
892 } 1394 }
893 if (fp != stdin) 1395 if (fp != stdin)
894 fclose(fp); 1396 fclose(fp);
895 return 0; 1397 return 0;
896} 1398}
897 1399
898static void load_ld_so_conf() 1400#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1401
1402static int load_ld_cache_config(int i, const char *fname)
899{ 1403{
900 FILE *fp = NULL; 1404 FILE *fp = NULL;
901 char *p; 1405 char *p;
902 char path[_POSIX_PATH_MAX]; 1406 char path[__PAX_UTILS_PATH_MAX];
903 int i = 0;
904 1407
905 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1408 if (i + 1 == ARRAY_SIZE(ldpaths))
906 return; 1409 return i;
907 1410
1411 if ((fp = fopen(fname, "r")) == NULL)
1412 return i;
1413
908 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1414 while ((fgets(path, __PAX_UTILS_PATH_MAX, fp)) != NULL) {
909 if (*path != '/')
910 continue;
911
912 if ((p = strrchr(path, '\r')) != NULL) 1415 if ((p = strrchr(path, '\r')) != NULL)
913 *p = 0; 1416 *p = 0;
914 if ((p = strchr(path, '\n')) != NULL) 1417 if ((p = strchr(path, '\n')) != NULL)
915 *p = 0; 1418 *p = 0;
1419#ifdef __linux__
1420 // recursive includes of the same file will make this segfault.
1421 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1422 glob64_t gl;
1423 size_t x;
1424 char gpath[__PAX_UTILS_PATH_MAX];
1425
1426 memset(gpath, 0, sizeof(gpath));
1427
1428 if (path[8] != '/')
1429 snprintf(gpath, sizeof(gpath), "/etc/%s", &path[8]);
1430 else
1431 strncpy(gpath, &path[8], sizeof(gpath));
1432
1433 if ((glob64(gpath, 0, NULL, &gl)) == 0) {
1434 for (x = 0; x < gl.gl_pathc; ++x) {
1435 /* try to avoid direct loops */
1436 if (strcmp(gl.gl_pathv[x], fname) == 0)
1437 continue;
1438 i = load_ld_cache_config(i, gl.gl_pathv[x]);
1439 if (i + 1 >= ARRAY_SIZE(ldpaths)) {
1440 globfree64(&gl);
1441 return i;
1442 }
1443 }
1444 globfree64 (&gl);
1445 continue;
1446 } else
1447 abort();
1448 }
1449#endif
1450 if (*path != '/')
1451 continue;
916 1452
917 ldpaths[i++] = xstrdup(path); 1453 ldpaths[i++] = xstrdup(path);
918 1454
919 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1455 if (i + 1 == ARRAY_SIZE(ldpaths))
920 break; 1456 break;
921 } 1457 }
922 ldpaths[i] = NULL; 1458 ldpaths[i] = NULL;
923 1459
924 fclose(fp); 1460 fclose(fp);
1461 return i;
925} 1462}
1463
1464#elif defined(__FreeBSD__) || (__DragonFly__)
1465
1466static int load_ld_cache_config(int i, const char *fname)
1467{
1468 FILE *fp = NULL;
1469 char *b = NULL, *p;
1470 struct elfhints_hdr hdr;
1471
1472 if (i + 1 == ARRAY_SIZE(ldpaths))
1473 return i;
1474
1475 if ((fp = fopen(fname, "r")) == NULL)
1476 return i;
1477
1478 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1479 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1480 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1481 {
1482 fclose(fp);
1483 return i;
1484 }
1485
1486 b = (char*)malloc(hdr.dirlistlen+1);
1487 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1488 fclose(fp);
1489 free(b);
1490 return i;
1491 }
1492
1493 while ((p = strsep(&b, ":"))) {
1494 if (*p == '\0') continue;
1495 ldpaths[i++] = xstrdup(p);
1496
1497 if (i + 1 == ARRAY_SIZE(ldpaths))
1498 break;
1499 }
1500 ldpaths[i] = NULL;
1501
1502 free(b);
1503 fclose(fp);
1504 return i;
1505}
1506
1507#else
1508
1509#warning Cache config support not implemented for your target
1510static int load_ld_cache_config(int i, const char *fname)
1511{
1512 memset(ldpaths, 0x00, sizeof(ldpaths));
1513}
1514
1515#endif
926 1516
927/* scan /etc/ld.so.conf for paths */ 1517/* scan /etc/ld.so.conf for paths */
928static void scanelf_ldpath() 1518static void scanelf_ldpath()
929{ 1519{
930 char scan_l, scan_ul, scan_ull; 1520 char scan_l, scan_ul, scan_ull;
964 } 1554 }
965 1555
966 free(path); 1556 free(path);
967} 1557}
968 1558
969
970
971/* usage / invocation handling functions */ 1559/* usage / invocation handling functions */
972#define PARSE_FLAGS "plRmyxetrnibSs:gN:TaqvF:f:o:BhV" 1560#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:BhV"
973#define a_argument required_argument 1561#define a_argument required_argument
974static struct option const long_opts[] = { 1562static struct option const long_opts[] = {
975 {"path", no_argument, NULL, 'p'}, 1563 {"path", no_argument, NULL, 'p'},
976 {"ldpath", no_argument, NULL, 'l'}, 1564 {"ldpath", no_argument, NULL, 'l'},
977 {"recursive", no_argument, NULL, 'R'}, 1565 {"recursive", no_argument, NULL, 'R'},
978 {"mount", no_argument, NULL, 'm'}, 1566 {"mount", no_argument, NULL, 'm'},
979 {"symlink", no_argument, NULL, 'y'}, 1567 {"symlink", no_argument, NULL, 'y'},
1568 {"archives", no_argument, NULL, 'A'},
1569 {"ldcache", no_argument, NULL, 'L'},
1570 {"fix", no_argument, NULL, 'X'},
1571 {"setpax", a_argument, NULL, 'z'},
980 {"pax", no_argument, NULL, 'x'}, 1572 {"pax", no_argument, NULL, 'x'},
981 {"header", no_argument, NULL, 'e'}, 1573 {"header", no_argument, NULL, 'e'},
982 {"textrel", no_argument, NULL, 't'}, 1574 {"textrel", no_argument, NULL, 't'},
983 {"rpath", no_argument, NULL, 'r'}, 1575 {"rpath", no_argument, NULL, 'r'},
984 {"needed", no_argument, NULL, 'n'}, 1576 {"needed", no_argument, NULL, 'n'},
985 {"interp", no_argument, NULL, 'i'}, 1577 {"interp", no_argument, NULL, 'i'},
986 {"bind", no_argument, NULL, 'b'}, 1578 {"bind", no_argument, NULL, 'b'},
987 {"soname", no_argument, NULL, 'S'}, 1579 {"soname", no_argument, NULL, 'S'},
988 {"symbol", a_argument, NULL, 's'}, 1580 {"symbol", a_argument, NULL, 's'},
1581 {"section", a_argument, NULL, 'k'},
989 {"lib", a_argument, NULL, 'N'}, 1582 {"lib", a_argument, NULL, 'N'},
990 {"gmatch", no_argument, NULL, 'g'}, 1583 {"gmatch", no_argument, NULL, 'g'},
991 {"textrels", no_argument, NULL, 'T'}, 1584 {"textrels", no_argument, NULL, 'T'},
1585 {"etype", a_argument, NULL, 'E'},
1586 {"bits", a_argument, NULL, 'M'},
992 {"all", no_argument, NULL, 'a'}, 1587 {"all", no_argument, NULL, 'a'},
993 {"quiet", no_argument, NULL, 'q'}, 1588 {"quiet", no_argument, NULL, 'q'},
994 {"verbose", no_argument, NULL, 'v'}, 1589 {"verbose", no_argument, NULL, 'v'},
995 {"format", a_argument, NULL, 'F'}, 1590 {"format", a_argument, NULL, 'F'},
996 {"from", a_argument, NULL, 'f'}, 1591 {"from", a_argument, NULL, 'f'},
1004static const char *opts_help[] = { 1599static const char *opts_help[] = {
1005 "Scan all directories in PATH environment", 1600 "Scan all directories in PATH environment",
1006 "Scan all directories in /etc/ld.so.conf", 1601 "Scan all directories in /etc/ld.so.conf",
1007 "Scan directories recursively", 1602 "Scan directories recursively",
1008 "Don't recursively cross mount points", 1603 "Don't recursively cross mount points",
1009 "Don't scan symlinks\n", 1604 "Don't scan symlinks",
1605 "Scan archives (.a files)",
1606 "Utilize ld.so.cache information (use with -r/-n)",
1607 "Try and 'fix' bad things (use with -r/-e)",
1608 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1010 "Print PaX markings", 1609 "Print PaX markings",
1011 "Print GNU_STACK/PT_LOAD markings", 1610 "Print GNU_STACK/PT_LOAD markings",
1012 "Print TEXTREL information", 1611 "Print TEXTREL information",
1013 "Print RPATH information", 1612 "Print RPATH information",
1014 "Print NEEDED information", 1613 "Print NEEDED information",
1015 "Print INTERP information", 1614 "Print INTERP information",
1016 "Print BIND information", 1615 "Print BIND information",
1017 "Print SONAME information", 1616 "Print SONAME information",
1018 "Find a specified symbol", 1617 "Find a specified symbol",
1618 "Find a specified section",
1019 "Find a specified library", 1619 "Find a specified library",
1020 "Use strncmp to match libraries. (use with -N)", 1620 "Use strncmp to match libraries. (use with -N)",
1021 "Locate cause of TEXTREL", 1621 "Locate cause of TEXTREL",
1622 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1623 "Print only ELF files matching numeric bits",
1022 "Print all scanned info (-x -e -t -r -b)\n", 1624 "Print all scanned info (-x -e -t -r -b)\n",
1023 "Only output 'bad' things", 1625 "Only output 'bad' things",
1024 "Be verbose (can be specified more than once)", 1626 "Be verbose (can be specified more than once)",
1025 "Use specified format for output", 1627 "Use specified format for output",
1026 "Read input stream from a filename", 1628 "Read input stream from a filename",
1034/* display usage and exit */ 1636/* display usage and exit */
1035static void usage(int status) 1637static void usage(int status)
1036{ 1638{
1037 unsigned long i; 1639 unsigned long i;
1038 printf("* Scan ELF binaries for stuff\n\n" 1640 printf("* Scan ELF binaries for stuff\n\n"
1039 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 1641 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1040 printf("Options: -[%s]\n", PARSE_FLAGS); 1642 printf("Options: -[%s]\n", PARSE_FLAGS);
1041 for (i = 0; long_opts[i].name; ++i) 1643 for (i = 0; long_opts[i].name; ++i)
1042 if (long_opts[i].has_arg == no_argument) 1644 if (long_opts[i].has_arg == no_argument)
1043 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 1645 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
1044 long_opts[i].name, opts_help[i]); 1646 long_opts[i].name, opts_help[i]);
1045 else 1647 else
1046 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 1648 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
1047 long_opts[i].name, opts_help[i]); 1649 long_opts[i].name, opts_help[i]);
1048 1650
1049 if (status != EXIT_SUCCESS) 1651 if (status != EXIT_SUCCESS)
1050 exit(status); 1652 exit(status);
1051 1653
1052 puts("\nThe format modifiers for the -F option are:"); 1654 puts("\nThe format modifiers for the -F option are:");
1053 puts(" F Filename \tx PaX Flags \te STACK/RELRO"); 1655 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1054 puts(" t TEXTREL \tr RPATH \tn NEEDED"); 1656 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1055 puts(" i INTERP \tb BIND \ts symbol"); 1657 puts(" i INTERP \tb BIND \ts symbol");
1056 puts(" N library \to Type \tT TEXTRELs"); 1658 puts(" N library \to Type \tT TEXTRELs");
1057 puts(" S SONAME"); 1659 puts(" S SONAME \tk section");
1058 puts(" p filename (with search path removed)"); 1660 puts(" p filename (with search path removed)");
1059 puts(" f filename (short name/basename)"); 1661 puts(" f filename (short name/basename)");
1060 puts("Prefix each modifier with '%' (verbose) or '#' (silent)"); 1662 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1061 1663
1664 puts("\nELF Etypes:");
1665 print_etypes(stdout);
1666
1062 exit(status); 1667 exit(status);
1063} 1668}
1064 1669
1065/* parse command line arguments and preform needed actions */ 1670/* parse command line arguments and preform needed actions */
1066static void parseargs(int argc, char *argv[]) 1671static void parseargs(int argc, char *argv[])
1067{ 1672{
1068 int i; 1673 int i;
1069 char *from_file = NULL; 1674 const char *from_file = NULL;
1070 1675
1071 opterr = 0; 1676 opterr = 0;
1072 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 1677 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1073 switch (i) { 1678 switch (i) {
1074 1679
1078 VERSION, __FILE__, __DATE__, rcsid, argv0); 1683 VERSION, __FILE__, __DATE__, rcsid, argv0);
1079 exit(EXIT_SUCCESS); 1684 exit(EXIT_SUCCESS);
1080 break; 1685 break;
1081 case 'h': usage(EXIT_SUCCESS); break; 1686 case 'h': usage(EXIT_SUCCESS); break;
1082 case 'f': 1687 case 'f':
1083 if (from_file) err("Don't specify -f twice"); 1688 if (from_file) warn("You prob don't want to specify -f twice");
1084 from_file = xstrdup(optarg); 1689 from_file = optarg;
1690 break;
1691 case 'E':
1692 strncpy(match_etypes, optarg, sizeof(match_etypes));
1693 break;
1694 case 'M':
1695 match_bits = atoi(optarg);
1085 break; 1696 break;
1086 case 'o': { 1697 case 'o': {
1087 FILE *fp = NULL;
1088 if ((fp = freopen(optarg, "w", stdout)) == NULL) 1698 if (freopen(optarg, "w", stdout) == NULL)
1089 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 1699 err("Could not open output stream '%s': %s", optarg, strerror(errno));
1090 SET_STDOUT(fp);
1091 break; 1700 break;
1092 } 1701 }
1093 1702 case 'k':
1703 if (find_section) warn("You prob don't want to specify -k twice");
1704 find_section = optarg;
1705 break;
1094 case 's': { 1706 case 's': {
1095 size_t len;
1096 if (find_sym) err("Don't specify -s twice"); 1707 if (find_sym) warn("You prob don't want to specify -s twice");
1097 find_sym = xstrdup(optarg); 1708 find_sym = optarg;
1098 len = strlen(find_sym) + 1;
1099 versioned_symname = (char*)xmalloc(sizeof(char) * (len+1)); 1709 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1100 sprintf(versioned_symname, "%s@", find_sym); 1710 sprintf(versioned_symname, "%s@", find_sym);
1101 break; 1711 break;
1102 } 1712 }
1103 case 'N': { 1713 case 'N': {
1104 if (find_lib) err("Don't specify -N twice"); 1714 if (find_lib) warn("You prob don't want to specify -N twice");
1105 find_lib = xstrdup(optarg); 1715 find_lib = optarg;
1106 break; 1716 break;
1107 } 1717 }
1108 1718
1109 case 'F': { 1719 case 'F': {
1110 if (out_format) err("Don't specify -F twice"); 1720 if (out_format) warn("You prob don't want to specify -F twice");
1111 out_format = xstrdup(optarg); 1721 out_format = optarg;
1722 break;
1723 }
1724 case 'z': {
1725 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1726 size_t x;
1727
1728 for (x = 0 ; x < strlen(optarg); x++) {
1729 switch(optarg[x]) {
1730 case 'p':
1731 case 'P':
1732 do_state(optarg[x], PAGEEXEC);
1112 break; 1733 break;
1734 case 's':
1735 case 'S':
1736 do_state(optarg[x], SEGMEXEC);
1737 break;
1738 case 'm':
1739 case 'M':
1740 do_state(optarg[x], MPROTECT);
1741 break;
1742 case 'e':
1743 case 'E':
1744 do_state(optarg[x], EMUTRAMP);
1745 break;
1746 case 'r':
1747 case 'R':
1748 do_state(optarg[x], RANDMMAP);
1749 break;
1750 case 'x':
1751 case 'X':
1752 do_state(optarg[x], RANDEXEC);
1753 break;
1754 default:
1755 break;
1756 }
1113 } 1757 }
1114 1758 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
1759 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
1760 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
1761 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
1762 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
1763 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
1764 setpax = flags;
1765 break;
1766 }
1115 case 'g': gmatch = 1; 1767 case 'g': gmatch = 1; break;
1768 case 'L': use_ldcache = 1; break;
1116 case 'y': scan_symlink = 0; break; 1769 case 'y': scan_symlink = 0; break;
1770 case 'A': scan_archives = 1; break;
1117 case 'B': show_banner = 0; break; 1771 case 'B': show_banner = 0; break;
1118 case 'l': scan_ldpath = 1; break; 1772 case 'l': scan_ldpath = 1; break;
1119 case 'p': scan_envpath = 1; break; 1773 case 'p': scan_envpath = 1; break;
1120 case 'R': dir_recurse = 1; break; 1774 case 'R': dir_recurse = 1; break;
1121 case 'm': dir_crossmount = 0; break; 1775 case 'm': dir_crossmount = 0; break;
1776 case 'X': ++fix_elf; break;
1122 case 'x': show_pax = 1; break; 1777 case 'x': show_pax = 1; break;
1123 case 'e': show_phdr = 1; break; 1778 case 'e': show_phdr = 1; break;
1124 case 't': show_textrel = 1; break; 1779 case 't': show_textrel = 1; break;
1125 case 'r': show_rpath = 1; break; 1780 case 'r': show_rpath = 1; break;
1126 case 'n': show_needed = 1; break; 1781 case 'n': show_needed = 1; break;
1131 case 'q': be_quiet = 1; break; 1786 case 'q': be_quiet = 1; break;
1132 case 'v': be_verbose = (be_verbose % 20) + 1; break; 1787 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1133 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 1788 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break;
1134 1789
1135 case ':': 1790 case ':':
1136 err("Option missing parameter\n"); 1791 err("Option '%c' is missing parameter", optopt);
1137 case '?': 1792 case '?':
1138 err("Unknown option\n"); 1793 err("Unknown option '%c' or argument missing", optopt);
1139 default: 1794 default:
1140 err("Unhandled option '%c'", i); 1795 err("Unhandled option '%c'; please report this", i);
1141 } 1796 }
1142 } 1797 }
1143 1798
1144 /* let the format option override all other options */ 1799 /* let the format option override all other options */
1145 if (out_format) { 1800 if (out_format) {
1148 show_textrels = 0; 1803 show_textrels = 0;
1149 for (i = 0; out_format[i]; ++i) { 1804 for (i = 0; out_format[i]; ++i) {
1150 if (!IS_MODIFIER(out_format[i])) continue; 1805 if (!IS_MODIFIER(out_format[i])) continue;
1151 1806
1152 switch (out_format[++i]) { 1807 switch (out_format[++i]) {
1808 case '+': break;
1153 case '%': break; 1809 case '%': break;
1154 case '#': break; 1810 case '#': break;
1155 case 'F': break; 1811 case 'F': break;
1156 case 'p': break; 1812 case 'p': break;
1157 case 'f': break; 1813 case 'f': break;
1814 case 'k': break;
1158 case 's': break; 1815 case 's': break;
1159 case 'N': break; 1816 case 'N': break;
1160 case 'o': break; 1817 case 'o': break;
1161 case 'x': show_pax = 1; break; 1818 case 'x': show_pax = 1; break;
1162 case 'e': show_phdr = 1; break; 1819 case 'e': show_phdr = 1; break;
1186 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 1843 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1187 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 1844 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1188 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 1845 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1189 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 1846 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1190 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 1847 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
1848 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1191 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 1849 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1192 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 1850 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1193 } 1851 }
1194 if (be_verbose > 2) printf("Format: %s\n", out_format); 1852 if (be_verbose > 2) printf("Format: %s\n", out_format);
1195 1853
1196 /* now lets actually do the scanning */ 1854 /* now lets actually do the scanning */
1197 if (scan_ldpath || (show_rpath && be_quiet)) 1855 if (scan_ldpath || use_ldcache)
1198 load_ld_so_conf(); 1856 load_ld_cache_config(0, __PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1199 if (scan_ldpath) scanelf_ldpath(); 1857 if (scan_ldpath) scanelf_ldpath();
1200 if (scan_envpath) scanelf_envpath(); 1858 if (scan_envpath) scanelf_envpath();
1859 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
1860 from_file = "-";
1201 if (from_file) { 1861 if (from_file) {
1202 scanelf_from_file(from_file); 1862 scanelf_from_file(from_file);
1203 free(from_file);
1204 from_file = *argv; 1863 from_file = *argv;
1205 } 1864 }
1206 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 1865 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1207 err("Nothing to scan !?"); 1866 err("Nothing to scan !?");
1208 while (optind < argc) { 1867 while (optind < argc) {
1209 search_path = argv[optind++]; 1868 search_path = argv[optind++];
1210 scanelf_dir(search_path); 1869 scanelf_dir(search_path);
1211 } 1870 }
1212 1871
1213 /* clean up */ 1872 /* clean up */
1214 if (find_sym) {
1215 free(find_sym);
1216 free(versioned_symname); 1873 free(versioned_symname);
1217 }
1218 if (find_lib) free(find_lib);
1219 if (out_format) free(out_format);
1220 for (i = 0; ldpaths[i]; ++i) 1874 for (i = 0; ldpaths[i]; ++i)
1221 free(ldpaths[i]); 1875 free(ldpaths[i]);
1222}
1223 1876
1224 1877 if (ldcache != 0)
1225 1878 munmap(ldcache, ldcache_size);
1226/* utility funcs */
1227static char *xstrdup(const char *s)
1228{
1229 char *ret = strdup(s);
1230 if (!ret) err("Could not strdup(): %s", strerror(errno));
1231 return ret;
1232} 1879}
1233 1880
1234static void *xmalloc(size_t size) 1881static char **get_split_env(const char *envvar)
1235{ 1882{
1236 void *ret = malloc(size); 1883 const char *delims = " \t\n";
1237 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size); 1884 char **envvals = NULL;
1238 return ret; 1885 char *env, *s;
1239} 1886 int nentry;
1240 1887
1241static void xstrcat(char **dst, const char *src, size_t *curr_len) 1888 if ((env = getenv(envvar)) == NULL)
1242{ 1889 return NULL;
1243 size_t new_len;
1244 1890
1245 new_len = strlen(*dst) + strlen(src); 1891 env = xstrdup(env);
1246 if (*curr_len <= new_len) { 1892 if (env == NULL)
1247 *curr_len = new_len + (*curr_len / 2); 1893 return NULL;
1248 *dst = realloc(*dst, *curr_len);
1249 if (!*dst)
1250 err("could not realloc %li bytes", (unsigned long)*curr_len);
1251 }
1252 1894
1253 strcat(*dst, src); 1895 s = strtok(env, delims);
1254} 1896 if (s == NULL) {
1897 free(env);
1898 return NULL;
1899 }
1255 1900
1256static inline void xchrcat(char **dst, const char append, size_t *curr_len) 1901 nentry = 0;
1257{ 1902 while (s != NULL) {
1258 static char my_app[2]; 1903 ++nentry;
1259 my_app[0] = append; 1904 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
1260 my_app[1] = '\0'; 1905 envvals[nentry-1] = s;
1261 xstrcat(dst, my_app, curr_len); 1906 s = strtok(NULL, delims);
1907 }
1908 envvals[nentry] = NULL;
1909
1910 /* don't want to free(env) as it contains the memory that backs
1911 * the envvals array of strings */
1912 return envvals;
1262} 1913}
1914static void parseenv()
1915{
1916 qa_textrels = get_split_env("QA_TEXTRELS");
1917 qa_execstack = get_split_env("QA_EXECSTACK");
1918 qa_wx_load = get_split_env("QA_WX_LOAD");
1919}
1920#ifdef __PAX_UTILS_CLEANUP
1921static void cleanup()
1922{
1923 free(out_format);
1924 free(qa_textrels);
1925 free(qa_execstack);
1926 free(qa_wx_load);
1927}
1928#endif
1263 1929
1264 1930
1265 1931
1266int main(int argc, char *argv[]) 1932int main(int argc, char *argv[])
1267{ 1933{
1268 if (argc < 2) 1934 if (argc < 2)
1269 usage(EXIT_FAILURE); 1935 usage(EXIT_FAILURE);
1936 parseenv();
1270 parseargs(argc, argv); 1937 parseargs(argc, argv);
1271 fclose(stdout); 1938 fclose(stdout);
1272#ifdef __BOUNDS_CHECKING_ON 1939#ifdef __PAX_UTILS_CLEANUP
1273 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 1940 cleanup();
1941 warn("The calls to add/delete heap should be off:\n"
1942 "\t- 1 due to the out_buffer not being freed in scanelf_file()\n"
1943 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1274#endif 1944#endif
1275 return EXIT_SUCCESS; 1945 return EXIT_SUCCESS;
1276} 1946}

Legend:
Removed from v.1.88  
changed lines
  Added in v.1.154

  ViewVC Help
Powered by ViewVC 1.1.20