/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.88 Revision 1.259
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.88 2005/09/30 03:30:54 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.259 2013/08/14 21:09:57 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.259 2013/08/14 21:09:57 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#define __USE_GNU
16#include <string.h>
17#include <errno.h>
18#include <unistd.h>
19#include <sys/stat.h>
20#include <dirent.h>
21#include <getopt.h>
22#include <assert.h>
23#include "paxelf.h" 13#include "paxinc.h"
24 14
25static const char *rcsid = "$Id: scanelf.c,v 1.88 2005/09/30 03:30:54 vapier Exp $";
26#define argv0 "scanelf"
27
28#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
29
30
31 16
32/* prototypes */ 17/* prototypes */
33static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
34static void scanelf_dir(const char *path);
35static void scanelf_ldpath();
36static void scanelf_envpath();
37static void usage(int status);
38static void parseargs(int argc, char *argv[]);
39static char *xstrdup(const char *s);
40static void *xmalloc(size_t size);
41static void xstrcat(char **dst, const char *src, size_t *curr_len);
42static inline void xchrcat(char **dst, const char append, size_t *curr_len);
43 19
44/* variables to control behavior */ 20/* variables to control behavior */
45static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
46static char scan_ldpath = 0; 23static char scan_ldpath = 0;
47static char scan_envpath = 0; 24static char scan_envpath = 0;
48static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
49static char dir_recurse = 0; 27static char dir_recurse = 0;
50static char dir_crossmount = 1; 28static char dir_crossmount = 1;
51static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
52static char show_phdr = 0; 32static char show_phdr = 0;
53static char show_textrel = 0; 33static char show_textrel = 0;
54static char show_rpath = 0; 34static char show_rpath = 0;
55static char show_needed = 0; 35static char show_needed = 0;
56static char show_interp = 0; 36static char show_interp = 0;
57static char show_bind = 0; 37static char show_bind = 0;
58static char show_soname = 0; 38static char show_soname = 0;
59static char show_textrels = 0; 39static char show_textrels = 0;
60static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
61static char be_quiet = 0; 44static char be_quiet = 0;
62static char be_verbose = 0; 45static char be_verbose = 0;
63static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
64static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
65static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
66static char *out_format = NULL; 55static char *out_format = NULL;
67static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
68static char gmatch = 0; 58static char g_match = 0;
59static char use_ldcache = 0;
60static char use_ldpath = 0;
69 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
70 66
67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
72
73static int has_objdump = 0;
74
75/* find the path to a file by name */
76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
80
81 path = getenv("PATH");
82 if (!path)
83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
71/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
72static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
73{ 125{
74 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
75#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
76 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
77 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
78 /* debug sections */ \ 144 Elf ## B ## _Shdr *estrtab = strtab; \
79 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
80 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 146 Elf ## B ## _Shdr *edynstr = dynstr; \
81 /* runtime sections */ \ 147 \
82 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
83 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
84 if (symtab && dynsym) { \ 152 if (symtab && dynsym) \
85 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
86 } else { \ 154 else \
87 *sym = (void*)(symtab ? symtab : dynsym); \ 155 *sym = symtab ? symtab : dynsym; \
88 } \ 156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
89 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
90 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
91 } else { \ 163 else \
92 *tab = (void*)(strtab ? strtab : dynstr); \ 164 *str = strtab ? strtab : dynstr; \
93 } \
94 } 165 }
95 GET_SYMTABS(32) 166 GET_SYMTABS(32)
96 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
97} 259}
260
98static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
99{ 262{
100 static char *paxflags;
101 static char ret[7]; 263 static char ret[7];
102 unsigned long i, shown; 264 unsigned long i, shown;
103 265
104 if (!show_pax) return NULL; 266 if (!show_pax) return NULL;
105 267
112 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 274 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
113 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 275 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
114 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 276 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
115 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 277 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
116 continue; \ 278 continue; \
117 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 279 if (fix_elf && setpax) { \
280 /* set the paxctl flags */ \
281 ESET(phdr[i].p_flags, setpax); \
282 } \
283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
118 continue; \ 284 continue; \
119 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
120 *found_pax = 1; \ 286 *found_pax = 1; \
121 ++shown; \ 287 ++shown; \
122 break; \ 288 break; \
124 } 290 }
125 SHOW_PAX(32) 291 SHOW_PAX(32)
126 SHOW_PAX(64) 292 SHOW_PAX(64)
127 } 293 }
128 294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
301
129 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
130 if (!*ret) { 303 if (!*ret) {
304 static char *paxflags;
131 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
132 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) { 306 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
133 *found_pax = 1; 307 *found_pax = 1;
134 return paxflags; 308 return (be_wewy_wewy_quiet ? NULL : paxflags);
135 } 309 }
136 strncpy(ret, paxflags, sizeof(ret)); 310 strncpy(ret, paxflags, sizeof(ret));
137 } 311 }
138 312
139 if (be_quiet && !shown) 313 if (be_wewy_wewy_quiet || (be_quiet && !shown))
140 return NULL; 314 return NULL;
315 else
141 return ret; 316 return ret;
142
143} 317}
318
144static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
145{ 320{
146 static char ret[12]; 321 static char ret[12];
147 char *found; 322 char *found;
148 unsigned long i, off, shown, check_flags;
149 unsigned char multi_stack, multi_relro, multi_load; 323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
150 324
151 if (!show_phdr) return NULL; 325 if (!show_phdr) return NULL;
152 326
153 memcpy(ret, "--- --- ---\0", 12); 327 memcpy(ret, "--- --- ---\0", 12);
154 328
155 shown = 0; 329 shown = 0;
156 multi_stack = multi_relro = multi_load = 0; 330 multi_stack = multi_relro = multi_load = 0;
157 331
158 if (elf->phdr) { 332#define NOTE_GNU_STACK ".note.GNU-stack"
159#define SHOW_PHDR(B) \ 333#define SHOW_PHDR(B) \
160 if (elf->elf_class == ELFCLASS ## B) { \ 334 if (elf->elf_class == ELFCLASS ## B) { \
161 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
336 Elf ## B ## _Off offset; \
337 uint32_t flags, check_flags; \
338 if (elf->phdr != NULL) { \
162 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
163 uint32_t flags; \
164 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
165 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
166 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
167 found = found_phdr; \ 346 found = found_phdr; \
168 off = 0; \ 347 offset = 0; \
169 check_flags = PF_X; \ 348 check_flags = PF_X; \
170 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
350 if (multi_relro++) \
171 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
172 found = found_relro; \ 352 found = found_relro; \
173 off = 4; \ 353 offset = 4; \
174 check_flags = PF_X; \ 354 check_flags = PF_X; \
175 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
176 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 356 if (file_matches_list(elf->filename, qa_wx_load)) \
357 continue; \
177 found = found_load; \ 358 found = found_load; \
178 off = 8; \ 359 offset = 8; \
179 check_flags = PF_W|PF_X; \ 360 check_flags = PF_W|PF_X; \
180 } else \ 361 } else \
181 continue; \ 362 continue; \
182 flags = EGET(phdr[i].p_flags); \ 363 flags = EGET(phdr[i].p_flags); \
183 if (be_quiet && ((flags & check_flags) != check_flags)) \ 364 if (be_quiet && ((flags & check_flags) != check_flags)) \
184 continue; \ 365 continue; \
366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
368 ret[3] = ret[7] = '!'; \
369 flags = EGET(phdr[i].p_flags); \
370 } \
185 memcpy(ret+off, gnu_short_stack_flags(flags), 3); \ 371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
186 *found = 1; \ 372 *found = 1; \
187 ++shown; \ 373 ++shown; \
374 } \
375 } else if (elf->shdr != NULL) { \
376 /* no program headers which means this is prob an object file */ \
377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
379 char *str; \
380 if ((void*)strtbl > elf->data_end) \
381 goto skip_this_shdr##B; \
382 /* let's flag -w/+x object files since the final ELF will most likely
383 * need write access to the stack (who doesn't !?). so the combined
384 * output will bring in +w automatically and that's bad.
385 */
386 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
387 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
388 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
389 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
390 str = elf->data + offset; \
391 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
392 if (!strcmp(str, NOTE_GNU_STACK)) { \
393 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
394 flags = EGET(shdr[i].sh_flags); \
395 if (be_quiet && ((flags & check_flags) != check_flags)) \
396 continue; \
397 ++*found_phdr; \
398 shown = 1; \
399 if (flags & SHF_WRITE) ret[0] = 'W'; \
400 if (flags & SHF_ALLOC) ret[1] = 'A'; \
401 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
402 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
403 break; \
404 } \
405 } \
406 skip_this_shdr##B: \
407 if (!multi_stack) { \
408 if (file_matches_list(elf->filename, qa_execstack)) \
409 return NULL; \
410 *found_phdr = 1; \
411 shown = 1; \
412 memcpy(ret, "!WX", 3); \
413 } \
188 } \ 414 } \
189 } 415 }
190 SHOW_PHDR(32) 416 SHOW_PHDR(32)
191 SHOW_PHDR(64) 417 SHOW_PHDR(64)
192 }
193 418
194 if (be_quiet && !shown) 419 if (be_wewy_wewy_quiet || (be_quiet && !shown))
195 return NULL; 420 return NULL;
196 else 421 else
197 return ret; 422 return ret;
198} 423}
424
425/*
426 * See if this ELF contains a DT_TEXTREL tag in any of its
427 * PT_DYNAMIC sections.
428 */
199static char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 429static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
200{ 430{
201 static char ret[] = "TEXTREL"; 431 static const char *ret = "TEXTREL";
202 unsigned long i; 432 unsigned long i;
203 433
204 if (!show_textrel && !show_textrels) return NULL; 434 if (!show_textrel && !show_textrels) return NULL;
435
436 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
205 437
206 if (elf->phdr) { 438 if (elf->phdr) {
207#define SHOW_TEXTREL(B) \ 439#define SHOW_TEXTREL(B) \
208 if (elf->elf_class == ELFCLASS ## B) { \ 440 if (elf->elf_class == ELFCLASS ## B) { \
209 Elf ## B ## _Dyn *dyn; \ 441 Elf ## B ## _Dyn *dyn; \
210 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 442 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
211 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 443 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
212 Elf ## B ## _Off offset; \ 444 Elf ## B ## _Off offset; \
213 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 445 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
214 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 446 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
215 offset = EGET(phdr[i].p_offset); \ 447 offset = EGET(phdr[i].p_offset); \
216 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 448 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
217 dyn = DYN ## B (elf->data + offset); \ 449 dyn = DYN ## B (elf->vdata + offset); \
218 while (EGET(dyn->d_tag) != DT_NULL) { \ 450 while (EGET(dyn->d_tag) != DT_NULL) { \
219 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 451 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
220 *found_textrel = 1; \ 452 *found_textrel = 1; \
221 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 453 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
222 return (be_wewy_wewy_quiet ? NULL : ret); \ 454 return (be_wewy_wewy_quiet ? NULL : ret); \
229 } 461 }
230 462
231 if (be_quiet || be_wewy_wewy_quiet) 463 if (be_quiet || be_wewy_wewy_quiet)
232 return NULL; 464 return NULL;
233 else 465 else
234 return (char *)" - "; 466 return " - ";
235} 467}
468
469/*
470 * Scan the .text section to see if there are any relocations in it.
471 * Should rewrite this to check PT_LOAD sections that are marked
472 * Executable rather than the section named '.text'.
473 */
236static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 474static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
237{ 475{
238 unsigned long s, r, rmax; 476 unsigned long s, r, rmax;
239 void *symtab_void, *strtab_void, *text_void; 477 void *symtab_void, *strtab_void, *text_void;
240 478
261 Elf ## B ## _Rela *rela; \ 499 Elf ## B ## _Rela *rela; \
262 /* search the section headers for relocations */ \ 500 /* search the section headers for relocations */ \
263 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 501 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
264 uint32_t sh_type = EGET(shdr[s].sh_type); \ 502 uint32_t sh_type = EGET(shdr[s].sh_type); \
265 if (sh_type == SHT_REL) { \ 503 if (sh_type == SHT_REL) { \
266 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 504 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
267 rela = NULL; \ 505 rela = NULL; \
268 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 506 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
269 } else if (sh_type == SHT_RELA) { \ 507 } else if (sh_type == SHT_RELA) { \
270 rel = NULL; \ 508 rel = NULL; \
271 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 509 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
272 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 510 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
273 } else \ 511 } else \
274 continue; \ 512 continue; \
275 /* now see if any of the relocs are in the .text */ \ 513 /* now see if any of the relocs are in the .text */ \
276 for (r = 0; r < rmax; ++r) { \ 514 for (r = 0; r < rmax; ++r) { \
291 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 529 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
292 if (be_verbose <= 2) continue; \ 530 if (be_verbose <= 2) continue; \
293 } else \ 531 } else \
294 *found_textrels = 1; \ 532 *found_textrels = 1; \
295 /* locate this relocation symbol name */ \ 533 /* locate this relocation symbol name */ \
296 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 534 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
535 if ((void*)sym > elf->data_end) { \
536 warn("%s: corrupt ELF symbol", elf->filename); \
537 continue; \
538 } \
297 sym_max = ELF ## B ## _R_SYM(r_info); \ 539 sym_max = ELF ## B ## _R_SYM(r_info); \
298 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 540 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
299 sym += sym_max; \ 541 sym += sym_max; \
300 else \ 542 else \
301 sym = NULL; \ 543 sym = NULL; \
302 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 544 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
303 /* show the raw details about this reloc */ \ 545 /* show the raw details about this reloc */ \
304 printf(" %s: ", elf->base_filename); \ 546 printf(" %s: ", elf->base_filename); \
305 if (sym && sym->st_name) \ 547 if (sym && sym->st_name) \
306 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 548 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
307 else \ 549 else \
308 printf("(memory/fake?)"); \ 550 printf("(memory/data?)"); \
309 printf(" [0x%lX]", (unsigned long)r_offset); \ 551 printf(" [0x%lX]", (unsigned long)r_offset); \
310 /* now try to find the closest symbol that this rel is probably in */ \ 552 /* now try to find the closest symbol that this rel is probably in */ \
311 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 553 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
312 func = NULL; \ 554 func = NULL; \
313 offset_tmp = 0; \ 555 offset_tmp = 0; \
314 while (sym_max--) { \ 556 while (sym_max--) { \
315 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 557 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
316 func = sym; \ 558 func = sym; \
317 offset_tmp = EGET(sym->st_value); \ 559 offset_tmp = EGET(sym->st_value); \
318 } \ 560 } \
319 ++sym; \ 561 ++sym; \
320 } \ 562 } \
321 printf(" in "); \ 563 printf(" in "); \
322 if (func && func->st_name) \ 564 if (func && func->st_name) { \
323 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 565 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
566 if (r_offset > EGET(func->st_size)) \
567 printf("(optimized out: previous %s)", func_name); \
324 else \ 568 else \
325 printf("(NULL: fake?)"); \ 569 printf("%s", func_name); \
570 } else \
571 printf("(optimized out)"); \
326 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 572 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
573 if (be_verbose && has_objdump) { \
574 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
575 char *sysbuf; \
576 size_t syslen; \
577 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
578 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
579 sysbuf = xmalloc(syslen); \
580 if (end_addr < r_offset) \
581 /* not uncommon when things are optimized out */ \
582 end_addr = r_offset + 0x100; \
583 snprintf(sysbuf, syslen, sysfmt, \
584 (unsigned long)offset_tmp, \
585 (unsigned long)end_addr, \
586 elf->filename, \
587 (unsigned long)r_offset); \
588 fflush(stdout); \
589 if (system(sysbuf)) {/* don't care */} \
590 fflush(stdout); \
591 free(sysbuf); \
592 } \
327 } \ 593 } \
328 } } 594 } }
329 SHOW_TEXTRELS(32) 595 SHOW_TEXTRELS(32)
330 SHOW_TEXTRELS(64) 596 SHOW_TEXTRELS(64)
331 } 597 }
333 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 599 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
334 600
335 return NULL; 601 return NULL;
336} 602}
337 603
338static void rpath_security_checks(elfobj *, char *);
339static void rpath_security_checks(elfobj *elf, char *item) { 604static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
605{
340 struct stat st; 606 struct stat st;
341 switch (*item) { 607 switch (*item) {
608 case '/': break;
342 case 0: 609 case '.':
343 warnf("Security problem NULL RPATH in %s", elf->filename); 610 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
344 break; 611 break;
345 case '/': break; 612 case ':':
613 case '\0':
614 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
615 break;
346 case '$': 616 case '$':
347 if (fstat(elf->fd, &st) != -1) 617 if (fstat(elf->fd, &st) != -1)
348 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 618 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
349 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 619 warnf("Security problem with %s='%s' in %s with mode set of %o",
350 item, elf->filename, st.st_mode & 07777); 620 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
351 break; 621 break;
352 default: 622 default:
353 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 623 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
354 break; 624 break;
355 } 625 }
356} 626}
357static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 627static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
358{ 628{
359 unsigned long i, s; 629 unsigned long i;
360 char *rpath, *runpath, **r; 630 char *rpath, *runpath, **r;
361 void *strtbl_void; 631 void *strtbl_void;
362 632
363 if (!show_rpath) return; 633 if (!show_rpath) return;
364 634
375 Elf ## B ## _Off offset; \ 645 Elf ## B ## _Off offset; \
376 Elf ## B ## _Xword word; \ 646 Elf ## B ## _Xword word; \
377 /* Scan all the program headers */ \ 647 /* Scan all the program headers */ \
378 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 648 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
379 /* Just scan dynamic headers */ \ 649 /* Just scan dynamic headers */ \
380 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 650 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
381 offset = EGET(phdr[i].p_offset); \ 651 offset = EGET(phdr[i].p_offset); \
382 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 652 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
383 /* Just scan dynamic RPATH/RUNPATH headers */ \ 653 /* Just scan dynamic RPATH/RUNPATH headers */ \
384 dyn = DYN ## B (elf->data + offset); \ 654 dyn = DYN ## B (elf->vdata + offset); \
385 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 655 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
386 if (word == DT_RPATH) { \ 656 if (word == DT_RPATH) { \
387 r = &rpath; \ 657 r = &rpath; \
388 } else if (word == DT_RUNPATH) { \ 658 } else if (word == DT_RUNPATH) { \
389 r = &runpath; \ 659 r = &runpath; \
393 } \ 663 } \
394 /* Verify the memory is somewhat sane */ \ 664 /* Verify the memory is somewhat sane */ \
395 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 665 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
396 if (offset < (Elf ## B ## _Off)elf->len) { \ 666 if (offset < (Elf ## B ## _Off)elf->len) { \
397 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 667 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
398 *r = (char*)(elf->data + offset); \ 668 *r = elf->data + offset; \
669 /* cache the length in case we need to nuke this section later on */ \
670 if (fix_elf) \
671 offset = strlen(*r); \
399 /* If quiet, don't output paths in ld.so.conf */ \ 672 /* If quiet, don't output paths in ld.so.conf */ \
400 if (be_quiet) { \ 673 if (be_quiet) { \
401 size_t len; \ 674 size_t len; \
402 char *start, *end; \ 675 char *start, *end; \
403 /* note that we only 'chop' off leading known paths. */ \ 676 /* note that we only 'chop' off leading known paths. */ \
404 /* since *r is read-only memory, we can only move the ptr forward. */ \ 677 /* since *r is read-only memory, we can only move the ptr forward. */ \
405 start = *r; \ 678 start = *r; \
406 /* scan each path in : delimited list */ \ 679 /* scan each path in : delimited list */ \
407 while (start) { \ 680 while (start) { \
408 rpath_security_checks(elf, start); \ 681 rpath_security_checks(elf, start, get_elfdtype(word)); \
409 end = strchr(start, ':'); \ 682 end = strchr(start, ':'); \
410 len = (end ? abs(end - start) : strlen(start)); \ 683 len = (end ? abs(end - start) : strlen(start)); \
411 for (s = 0; ldpaths[s]; ++s) { \ 684 if (use_ldcache) { \
685 size_t n; \
686 const char *ldpath; \
687 array_for_each(ldpaths, n, ldpath) \
412 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 688 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
413 *r = (end ? end + 1 : NULL); \ 689 *r = end; \
690 /* corner case ... if RPATH reads "/usr/lib:", we want \
691 * to show ':' rather than '' */ \
692 if (end && end[1] != '\0') \
693 (*r)++; \
414 break; \ 694 break; \
415 } \ 695 } \
416 } \ 696 } \
417 if (!*r || !ldpaths[s] || !end) \ 697 if (!*r || !end) \
418 start = NULL; \ 698 break; \
419 else \ 699 else \
420 start = start + len + 1; \ 700 start = start + len + 1; \
421 } \ 701 } \
422 } \ 702 } \
703 if (*r) { \
704 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
705 /* just nuke it */ \
706 nuke_it##B: \
707 memset(*r, 0x00, offset); \
708 *r = NULL; \
709 ESET(dyn->d_tag, DT_DEBUG); \
710 ESET(dyn->d_un.d_ptr, 0); \
711 } else if (fix_elf) { \
712 /* try to clean "bad" paths */ \
713 size_t len, tmpdir_len; \
714 char *start, *end; \
715 const char *tmpdir; \
716 start = *r; \
717 tmpdir = (getenv("TMPDIR") ? : "."); \
718 tmpdir_len = strlen(tmpdir); \
719 while (1) { \
720 end = strchr(start, ':'); \
721 if (start == end) { \
722 eat_this_path##B: \
723 len = strlen(end); \
724 memmove(start, end+1, len); \
725 start[len-1] = '\0'; \
726 end = start - 1; \
727 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
728 if (!end) { \
729 if (start == *r) \
730 goto nuke_it##B; \
731 *--start = '\0'; \
732 } else \
733 goto eat_this_path##B; \
734 } \
735 if (!end) \
736 break; \
737 start = end + 1; \
738 } \
739 if (**r == '\0') \
740 goto nuke_it##B; \
741 } \
742 if (*r) \
423 if (*r) *found_rpath = 1; \ 743 *found_rpath = 1; \
744 } \
424 } \ 745 } \
425 ++dyn; \ 746 ++dyn; \
426 } \ 747 } \
427 } } 748 } }
428 SHOW_RPATH(32) 749 SHOW_RPATH(32)
445 } else if (rpath || runpath) 766 } else if (rpath || runpath)
446 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 767 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
447 else if (!be_quiet) 768 else if (!be_quiet)
448 xstrcat(ret, " - ", ret_len); 769 xstrcat(ret, " - ", ret_len);
449} 770}
771
772/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
773#define LDSO_CACHE_MAGIC "ld.so-"
774#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
775#define LDSO_CACHE_VER "1.7.0"
776#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
777#define FLAG_ANY -1
778#define FLAG_TYPE_MASK 0x00ff
779#define FLAG_LIBC4 0x0000
780#define FLAG_ELF 0x0001
781#define FLAG_ELF_LIBC5 0x0002
782#define FLAG_ELF_LIBC6 0x0003
783#define FLAG_REQUIRED_MASK 0xff00
784#define FLAG_SPARC_LIB64 0x0100
785#define FLAG_IA64_LIB64 0x0200
786#define FLAG_X8664_LIB64 0x0300
787#define FLAG_S390_LIB64 0x0400
788#define FLAG_POWERPC_LIB64 0x0500
789#define FLAG_MIPS64_LIBN32 0x0600
790#define FLAG_MIPS64_LIBN64 0x0700
791#define FLAG_X8664_LIBX32 0x0800
792#define FLAG_ARM_LIBHF 0x0900
793#define FLAG_AARCH64_LIB64 0x0a00
794
795#if defined(__GLIBC__) || defined(__UCLIBC__)
796
797static char *lookup_cache_lib(elfobj *elf, const char *fname)
798{
799 int fd;
800 char *strs;
801 static char buf[__PAX_UTILS_PATH_MAX] = "";
802 const char *cachefile = root_rel_path("/etc/ld.so.cache");
803 struct stat st;
804
805 typedef struct {
806 char magic[LDSO_CACHE_MAGIC_LEN];
807 char version[LDSO_CACHE_VER_LEN];
808 int nlibs;
809 } header_t;
810 header_t *header;
811
812 typedef struct {
813 int flags;
814 int sooffset;
815 int liboffset;
816 } libentry_t;
817 libentry_t *libent;
818
819 if (fname == NULL)
820 return NULL;
821
822 if (ldcache == NULL) {
823 if (fstatat(root_fd, cachefile, &st, 0))
824 return NULL;
825
826 fd = openat(root_fd, cachefile, O_RDONLY);
827 if (fd == -1)
828 return NULL;
829
830 /* cache these values so we only map/unmap the cache file once */
831 ldcache_size = st.st_size;
832 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
833 close(fd);
834
835 if (ldcache == MAP_FAILED) {
836 ldcache = NULL;
837 return NULL;
838 }
839
840 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
841 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
842 {
843 munmap(ldcache, ldcache_size);
844 ldcache = NULL;
845 return NULL;
846 }
847 } else
848 header = ldcache;
849
850 libent = ldcache + sizeof(header_t);
851 strs = (char *) &libent[header->nlibs];
852
853 for (fd = 0; fd < header->nlibs; ++fd) {
854 /* This should be more fine grained, but for now we assume that
855 * diff arches will not be cached together, and we ignore the
856 * the different multilib mips cases.
857 */
858 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
859 continue;
860 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
861 continue;
862
863 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
864 continue;
865
866 /* Return first hit because that is how the ldso rolls */
867 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
868 break;
869 }
870
871 return buf;
872}
873
874#elif defined(__NetBSD__)
875static char *lookup_cache_lib(elfobj *elf, const char *fname)
876{
877 static char buf[__PAX_UTILS_PATH_MAX] = "";
878 static struct stat st;
879 size_t n;
880 char *ldpath;
881
882 array_for_each(ldpath, n, ldpath) {
883 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
884 continue; /* if the pathname is too long, or something went wrong, ignore */
885
886 if (stat(buf, &st) != 0)
887 continue; /* if the lib doesn't exist in *ldpath, look further */
888
889 /* NetBSD doesn't actually do sanity checks, it just loads the file
890 * and if that doesn't work, continues looking in other directories.
891 * This cannot easily be safely emulated, unfortunately. For now,
892 * just assume that if it exists, it's a valid library. */
893
894 return buf;
895 }
896
897 /* not found in any path */
898 return NULL;
899}
900#else
901#ifdef __ELF__
902#warning Cache support not implemented for your target
903#endif
904static char *lookup_cache_lib(elfobj *elf, const char *fname)
905{
906 return NULL;
907}
908#endif
909
910static char *lookup_config_lib(const char *fname)
911{
912 static char buf[__PAX_UTILS_PATH_MAX] = "";
913 const char *ldpath;
914 size_t n;
915
916 array_for_each(ldpaths, n, ldpath) {
917 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
918 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
919 return buf;
920 }
921
922 return NULL;
923}
924
450static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 925static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
451{ 926{
452 unsigned long i; 927 unsigned long i;
453 char *needed; 928 char *needed;
454 void *strtbl_void; 929 void *strtbl_void;
930 char *p;
455 931
932 /*
933 * -n -> op==0 -> print all
934 * -N -> op==1 -> print requested
935 */
456 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 936 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
937 return NULL;
457 938
458 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 939 strtbl_void = elf_findsecbyname(elf, ".dynstr");
459 940
460 if (elf->phdr && strtbl_void) { 941 if (elf->phdr && strtbl_void) {
461#define SHOW_NEEDED(B) \ 942#define SHOW_NEEDED(B) \
463 Elf ## B ## _Dyn *dyn; \ 944 Elf ## B ## _Dyn *dyn; \
464 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 945 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
465 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 946 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
466 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 947 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
467 Elf ## B ## _Off offset; \ 948 Elf ## B ## _Off offset; \
949 size_t matched = 0; \
950 /* Walk all the program headers to find the PT_DYNAMIC */ \
468 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 951 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
469 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 952 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
953 continue; \
470 offset = EGET(phdr[i].p_offset); \ 954 offset = EGET(phdr[i].p_offset); \
471 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 955 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
956 continue; \
957 /* Walk all the dynamic tags to find NEEDED entries */ \
472 dyn = DYN ## B (elf->data + offset); \ 958 dyn = DYN ## B (elf->vdata + offset); \
473 while (EGET(dyn->d_tag) != DT_NULL) { \ 959 while (EGET(dyn->d_tag) != DT_NULL) { \
474 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 960 if (EGET(dyn->d_tag) == DT_NEEDED) { \
475 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 961 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
476 if (offset >= (Elf ## B ## _Off)elf->len) { \ 962 if (offset >= (Elf ## B ## _Off)elf->len) { \
477 ++dyn; \ 963 ++dyn; \
478 continue; \ 964 continue; \
479 } \ 965 } \
480 needed = (char*)(elf->data + offset); \ 966 needed = elf->data + offset; \
481 if (op == 0) { \ 967 if (op == 0) { \
968 /* -n -> print all entries */ \
482 if (!be_wewy_wewy_quiet) { \ 969 if (!be_wewy_wewy_quiet) { \
483 if (*found_needed) xchrcat(ret, ',', ret_len); \ 970 if (*found_needed) xchrcat(ret, ',', ret_len); \
971 if (use_ldpath) { \
972 if ((p = lookup_config_lib(needed)) != NULL) \
973 needed = p; \
974 } else if (use_ldcache) { \
975 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
976 needed = p; \
977 } \
484 xstrcat(ret, needed, ret_len); \ 978 xstrcat(ret, needed, ret_len); \
485 } \ 979 } \
486 *found_needed = 1; \ 980 *found_needed = 1; \
487 } else { \ 981 } else { \
488 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 982 /* -N -> print matching entries */ \
983 size_t n; \
984 const char *find_lib_name; \
985 \
986 array_for_each(find_lib_arr, n, find_lib_name) { \
987 int invert = 1; \
988 if (find_lib_name[0] == '!') \
989 invert = 0, ++find_lib_name; \
990 if (!strcmp(find_lib_name, needed) == invert) \
991 ++matched; \
992 } \
993 \
994 if (matched == array_cnt(find_lib_arr)) { \
489 *found_lib = 1; \ 995 *found_lib = 1; \
490 return (be_wewy_wewy_quiet ? NULL : needed); \ 996 return (be_wewy_wewy_quiet ? NULL : find_lib); \
491 } \ 997 } \
492 } \ 998 } \
493 } \ 999 } \
494 ++dyn; \ 1000 ++dyn; \
495 } \ 1001 } \
517 *found_interp = 1; \ 1023 *found_interp = 1; \
518 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1024 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
519 } 1025 }
520 SHOW_INTERP(32) 1026 SHOW_INTERP(32)
521 SHOW_INTERP(64) 1027 SHOW_INTERP(64)
1028 } else {
1029 /* Walk all the program headers to find the PT_INTERP */
1030#define SHOW_PT_INTERP(B) \
1031 if (elf->elf_class == ELFCLASS ## B) { \
1032 unsigned long i; \
1033 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1034 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1035 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1036 if (EGET(phdr[i].p_type) != PT_INTERP) \
1037 continue; \
1038 *found_interp = 1; \
1039 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1040 } \
522 } 1041 }
1042 SHOW_PT_INTERP(32)
1043 SHOW_PT_INTERP(64)
1044 }
1045
523 return NULL; 1046 return NULL;
524} 1047}
525static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1048static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
526{ 1049{
527 unsigned long i; 1050 unsigned long i;
528 struct stat s; 1051 struct stat s;
1052 bool dynamic = false;
529 1053
530 if (!show_bind) return NULL; 1054 if (!show_bind) return NULL;
531 if (!elf->phdr) return NULL; 1055 if (!elf->phdr) return NULL;
532 1056
533#define SHOW_BIND(B) \ 1057#define SHOW_BIND(B) \
535 Elf ## B ## _Dyn *dyn; \ 1059 Elf ## B ## _Dyn *dyn; \
536 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1060 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
537 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1061 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
538 Elf ## B ## _Off offset; \ 1062 Elf ## B ## _Off offset; \
539 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1063 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
540 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1064 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1065 dynamic = true; \
541 offset = EGET(phdr[i].p_offset); \ 1066 offset = EGET(phdr[i].p_offset); \
542 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1067 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
543 dyn = DYN ## B (elf->data + offset); \ 1068 dyn = DYN ## B (elf->vdata + offset); \
544 while (EGET(dyn->d_tag) != DT_NULL) { \ 1069 while (EGET(dyn->d_tag) != DT_NULL) { \
545 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1070 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
546 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1071 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
547 { \ 1072 { \
548 if (be_quiet) return NULL; \ 1073 if (be_quiet) return NULL; \
556 SHOW_BIND(32) 1081 SHOW_BIND(32)
557 SHOW_BIND(64) 1082 SHOW_BIND(64)
558 1083
559 if (be_wewy_wewy_quiet) return NULL; 1084 if (be_wewy_wewy_quiet) return NULL;
560 1085
1086 /* don't output anything if quiet mode and the ELF is static or not setuid */
561 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1087 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
562 return NULL; 1088 return NULL;
563 } else { 1089 } else {
564 *found_bind = 1; 1090 *found_bind = 1;
565 return (char *) "LAZY"; 1091 return dynamic ? "LAZY" : "STATIC";
566 } 1092 }
567} 1093}
568static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1094static char *scanelf_file_soname(elfobj *elf, char *found_soname)
569{ 1095{
570 unsigned long i; 1096 unsigned long i;
582 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1108 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
583 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1109 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
584 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1110 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
585 Elf ## B ## _Off offset; \ 1111 Elf ## B ## _Off offset; \
586 /* only look for soname in shared objects */ \ 1112 /* only look for soname in shared objects */ \
587 if (ehdr->e_type != ET_DYN) \ 1113 if (EGET(ehdr->e_type) != ET_DYN) \
588 return NULL; \ 1114 return NULL; \
589 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1115 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
590 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1116 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
591 offset = EGET(phdr[i].p_offset); \ 1117 offset = EGET(phdr[i].p_offset); \
592 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1118 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
593 dyn = DYN ## B (elf->data + offset); \ 1119 dyn = DYN ## B (elf->vdata + offset); \
594 while (EGET(dyn->d_tag) != DT_NULL) { \ 1120 while (EGET(dyn->d_tag) != DT_NULL) { \
595 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1121 if (EGET(dyn->d_tag) == DT_SONAME) { \
596 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1122 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
597 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1123 if (offset >= (Elf ## B ## _Off)elf->len) { \
598 ++dyn; \ 1124 ++dyn; \
599 continue; \ 1125 continue; \
600 } \ 1126 } \
601 soname = (char*)(elf->data + offset); \ 1127 soname = elf->data + offset; \
602 *found_soname = 1; \ 1128 *found_soname = 1; \
603 return (be_wewy_wewy_quiet ? NULL : soname); \ 1129 return (be_wewy_wewy_quiet ? NULL : soname); \
604 } \ 1130 } \
605 ++dyn; \ 1131 ++dyn; \
606 } \ 1132 } \
609 SHOW_SONAME(64) 1135 SHOW_SONAME(64)
610 } 1136 }
611 1137
612 return NULL; 1138 return NULL;
613} 1139}
1140
1141/*
1142 * We support the symbol form:
1143 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1144 * If the symbol name is empty, then all symbols are matched.
1145 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1146 * Do not rely on this output format at all.
1147 * Otherwise the symbol name is used to search (either regex or string compare).
1148 * If the first char of the symbol name is a plus ("+"), then only match
1149 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1150 * Putting modifiers in between the percent signs allows for more in depth
1151 * filters. There are groups of modifiers. If you don't specify a member
1152 * of a group, then all types in that group are matched. The current
1153 * groups and their types are:
1154 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1155 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1156 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1157 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1158 * You can search for multiple symbols at once by seperating with a comma (",").
1159 *
1160 * Some examples:
1161 * ELFs with a weak function "foo":
1162 * scanelf -s %wf%foo <ELFs>
1163 * ELFs that define the symbol "main":
1164 * scanelf -s +main <ELFs>
1165 * scanelf -s %d%main <ELFs>
1166 * ELFs that refer to the undefined symbol "brk":
1167 * scanelf -s -brk <ELFs>
1168 * scanelf -s %u%brk <ELFs>
1169 * All global defined objects in an ELF:
1170 * scanelf -s %ogd% <ELF>
1171 */
1172static void
1173scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1174 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1175{
1176 const char *this_sym;
1177 size_t n;
1178
1179 array_for_each(find_sym_arr, n, this_sym) {
1180 bool inc_notype, inc_object, inc_func, inc_file,
1181 inc_local, inc_global, inc_weak,
1182 inc_def, inc_undef, inc_abs, inc_common;
1183
1184 /* symbol selection! */
1185 inc_notype = inc_object = inc_func = inc_file = \
1186 inc_local = inc_global = inc_weak = \
1187 inc_def = inc_undef = inc_abs = inc_common = \
1188 (*this_sym != '%');
1189
1190 /* parse the contents of %...% */
1191 if (!inc_notype) {
1192 while (*(this_sym++)) {
1193 if (*this_sym == '%') {
1194 ++this_sym;
1195 break;
1196 }
1197 switch (*this_sym) {
1198 case 'n': inc_notype = true; break;
1199 case 'o': inc_object = true; break;
1200 case 'f': inc_func = true; break;
1201 case 'F': inc_file = true; break;
1202 case 'l': inc_local = true; break;
1203 case 'g': inc_global = true; break;
1204 case 'w': inc_weak = true; break;
1205 case 'd': inc_def = true; break;
1206 case 'u': inc_undef = true; break;
1207 case 'a': inc_abs = true; break;
1208 case 'c': inc_common = true; break;
1209 default: err("invalid symbol selector '%c'", *this_sym);
1210 }
1211 }
1212
1213 /* If no types are matched, not match all */
1214 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1215 inc_notype = inc_object = inc_func = inc_file = true;
1216 if (!inc_local && !inc_global && !inc_weak)
1217 inc_local = inc_global = inc_weak = true;
1218 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1219 inc_def = inc_undef = inc_abs = inc_common = true;
1220
1221 /* backwards compat for defined/undefined short hand */
1222 } else if (*this_sym == '+') {
1223 inc_undef = false;
1224 ++this_sym;
1225 } else if (*this_sym == '-') {
1226 inc_def = inc_abs = inc_common = false;
1227 ++this_sym;
1228 }
1229
1230 /* filter symbols */
1231 if ((!inc_notype && stt == STT_NOTYPE) || \
1232 (!inc_object && stt == STT_OBJECT) || \
1233 (!inc_func && stt == STT_FUNC ) || \
1234 (!inc_file && stt == STT_FILE ) || \
1235 (!inc_local && stb == STB_LOCAL ) || \
1236 (!inc_global && stb == STB_GLOBAL) || \
1237 (!inc_weak && stb == STB_WEAK ) || \
1238 (!inc_def && shn && shn < SHN_LORESERVE) || \
1239 (!inc_undef && shn == SHN_UNDEF ) || \
1240 (!inc_abs && shn == SHN_ABS ) || \
1241 (!inc_common && shn == SHN_COMMON))
1242 continue;
1243
1244 if (*this_sym == '*') {
1245 /* a "*" symbol gets you debug output */
1246 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1247 ((*found_sym == 0) ? "\n\t" : "\t"),
1248 elf->base_filename,
1249 size,
1250 get_elfstttype(stt),
1251 get_elfstbtype(stb),
1252 get_elfshntype(shn),
1253 symname);
1254 goto matched;
1255
1256 } else {
1257 if (g_match) {
1258 /* regex match the symbol */
1259 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1260 continue;
1261
1262 } else if (*this_sym) {
1263 /* give empty symbols a "pass", else do a normal compare */
1264 const size_t len = strlen(this_sym);
1265 if (!(strncmp(this_sym, symname, len) == 0 &&
1266 /* Accept unversioned symbol names */
1267 (symname[len] == '\0' || symname[len] == '@')))
1268 continue;
1269 }
1270
1271 if (be_semi_verbose) {
1272 char buf[1024];
1273 snprintf(buf, sizeof(buf), "%lX %s %s",
1274 size,
1275 get_elfstttype(stt),
1276 this_sym);
1277 *ret = xstrdup(buf);
1278 } else {
1279 if (*ret) xchrcat(ret, ',', ret_len);
1280 xstrcat(ret, symname, ret_len);
1281 }
1282
1283 goto matched;
1284 }
1285 }
1286
1287 return;
1288
1289 matched:
1290 *found_sym = 1;
1291}
1292
614static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1293static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
615{ 1294{
616 unsigned long i; 1295 char *ret;
617 void *symtab_void, *strtab_void; 1296 void *symtab_void, *strtab_void;
618 1297
619 if (!find_sym) return NULL; 1298 if (!find_sym) return NULL;
1299 ret = NULL;
620 1300
621 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1301 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
622 1302
623 if (symtab_void && strtab_void) { 1303 if (symtab_void && strtab_void) {
624#define FIND_SYM(B) \ 1304#define FIND_SYM(B) \
625 if (elf->elf_class == ELFCLASS ## B) { \ 1305 if (elf->elf_class == ELFCLASS ## B) { \
626 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1306 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
627 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1307 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
628 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1308 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
629 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1309 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
630 char *symname; \ 1310 char *symname; \
1311 size_t ret_len = 0; \
1312 if (cnt) \
1313 cnt = EGET(symtab->sh_size) / cnt; \
631 for (i = 0; i < cnt; ++i) { \ 1314 for (i = 0; i < cnt; ++i) { \
1315 if ((void*)sym > elf->data_end) { \
1316 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1317 goto break_out; \
1318 } \
632 if (sym->st_name) { \ 1319 if (sym->st_name) { \
1320 /* make sure the symbol name is in acceptable memory range */ \
633 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1321 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
634 if (*find_sym == '*') { \ 1322 if ((void*)symname > elf->data_end) { \
635 printf("%s(%s) %5lX %15s %s\n", \ 1323 warnf("%s: corrupt ELF symbols", elf->filename); \
636 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1324 ++sym; \
637 elf->base_filename, \ 1325 continue; \
638 (long)sym->st_size, \ 1326 } \
639 (char *)get_elfstttype(sym->st_info), \ 1327 scanelf_match_symname(elf, found_sym, \
640 symname); \ 1328 &ret, &ret_len, symname, \
641 *found_sym = 1; \ 1329 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
642 } else if ((strcmp(find_sym, symname) == 0) || \ 1330 ELF##B##_ST_BIND(EGET(sym->st_info)), \
643 (strcmp(symname, versioned_symname) == 0)) \ 1331 EGET(sym->st_shndx), \
644 (*found_sym)++; \ 1332 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1333 EGET(sym->st_size)); \
645 } \ 1334 } \
646 ++sym; \ 1335 ++sym; \
647 } } 1336 } \
1337 }
648 FIND_SYM(32) 1338 FIND_SYM(32)
649 FIND_SYM(64) 1339 FIND_SYM(64)
650 } 1340 }
651 1341
1342break_out:
652 if (be_wewy_wewy_quiet) return NULL; 1343 if (be_wewy_wewy_quiet) return NULL;
653 1344
654 if (*find_sym != '*' && *found_sym) 1345 if (*find_sym != '*' && *found_sym)
655 return find_sym; 1346 return ret;
656 if (be_quiet) 1347 if (be_quiet)
657 return NULL; 1348 return NULL;
658 else 1349 else
659 return (char *)" - "; 1350 return " - ";
660} 1351}
1352
1353static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1354{
1355 if (!find_section)
1356 return NULL;
1357
1358#define FIND_SECTION(B) \
1359 if (elf->elf_class == ELFCLASS ## B) { \
1360 size_t matched, n; \
1361 int invert; \
1362 const char *section_name; \
1363 Elf ## B ## _Shdr *section; \
1364 \
1365 matched = 0; \
1366 array_for_each(find_section_arr, n, section_name) { \
1367 invert = (*section_name == '!' ? 1 : 0); \
1368 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1369 if ((section == NULL && invert) || (section != NULL && !invert)) \
1370 ++matched; \
1371 } \
1372 \
1373 if (matched == array_cnt(find_section_arr)) \
1374 *found_section = 1; \
1375 }
1376 FIND_SECTION(32)
1377 FIND_SECTION(64)
1378
1379 if (be_wewy_wewy_quiet)
1380 return NULL;
1381
1382 if (*found_section)
1383 return find_section;
1384
1385 if (be_quiet)
1386 return NULL;
1387 else
1388 return " - ";
1389}
1390
661/* scan an elf file and show all the fun stuff */ 1391/* scan an elf file and show all the fun stuff */
662#define prints(str) write(fileno(stdout), str, strlen(str)) 1392#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
663static void scanelf_file(const char *filename) 1393static int scanelf_elfobj(elfobj *elf)
664{ 1394{
665 unsigned long i; 1395 unsigned long i;
666 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1396 char found_pax, found_phdr, found_relro, found_load, found_textrel,
667 found_rpath, found_needed, found_interp, found_bind, found_soname, 1397 found_rpath, found_needed, found_interp, found_bind, found_soname,
668 found_sym, found_lib, found_file, found_textrels; 1398 found_sym, found_lib, found_file, found_textrels, found_section;
669 elfobj *elf;
670 struct stat st;
671 static char *out_buffer = NULL; 1399 static char *out_buffer = NULL;
672 static size_t out_len; 1400 static size_t out_len;
673 1401
674 /* make sure 'filename' exists */
675 if (lstat(filename, &st) == -1) {
676 if (be_verbose > 2) printf("%s: does not exist\n", filename);
677 return;
678 }
679 /* always handle regular files and handle symlinked files if no -y */
680 if (S_ISLNK(st.st_mode)) {
681 if (!scan_symlink) return;
682 stat(filename, &st);
683 }
684 if (!S_ISREG(st.st_mode)) {
685 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
686 return;
687 }
688
689 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1402 found_pax = found_phdr = found_relro = found_load = found_textrel = \
690 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1403 found_rpath = found_needed = found_interp = found_bind = found_soname = \
691 found_sym = found_lib = found_file = found_textrels = 0; 1404 found_sym = found_lib = found_file = found_textrels = found_section = 0;
692 1405
693 /* verify this is real ELF */
694 if ((elf = readelf(filename)) == NULL) {
695 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
696 return;
697 }
698
699 if (be_verbose > 1) 1406 if (be_verbose > 2)
700 printf("%s: scanning file {%s,%s}\n", filename, 1407 printf("%s: scanning file {%s,%s}\n", elf->filename,
701 get_elfeitype(EI_CLASS, elf->elf_class), 1408 get_elfeitype(EI_CLASS, elf->elf_class),
702 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1409 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
703 else if (be_verbose) 1410 else if (be_verbose > 1)
704 printf("%s: scanning file\n", filename); 1411 printf("%s: scanning file\n", elf->filename);
705 1412
706 /* init output buffer */ 1413 /* init output buffer */
707 if (!out_buffer) { 1414 if (!out_buffer) {
708 out_len = sizeof(char) * 80; 1415 out_len = sizeof(char) * 80;
709 out_buffer = (char*)xmalloc(out_len); 1416 out_buffer = xmalloc(out_len);
710 } 1417 }
711 *out_buffer = '\0'; 1418 *out_buffer = '\0';
712 1419
713 /* show the header */ 1420 /* show the header */
714 if (!be_quiet && show_banner) { 1421 if (!be_quiet && show_banner) {
715 for (i = 0; out_format[i]; ++i) { 1422 for (i = 0; out_format[i]; ++i) {
716 if (!IS_MODIFIER(out_format[i])) continue; 1423 if (!IS_MODIFIER(out_format[i])) continue;
717 1424
718 switch (out_format[++i]) { 1425 switch (out_format[++i]) {
1426 case '+': break;
719 case '%': break; 1427 case '%': break;
720 case '#': break; 1428 case '#': break;
721 case 'F': 1429 case 'F':
722 case 'p': 1430 case 'p':
723 case 'f': prints("FILE "); found_file = 1; break; 1431 case 'f': prints("FILE "); found_file = 1; break;
724 case 'o': prints(" TYPE "); break; 1432 case 'o': prints(" TYPE "); break;
725 case 'x': prints(" PAX "); break; 1433 case 'x': prints(" PAX "); break;
726 case 'e': prints("STK/REL/PTL "); break; 1434 case 'e': prints("STK/REL/PTL "); break;
727 case 't': prints("TEXTREL "); break; 1435 case 't': prints("TEXTREL "); break;
728 case 'r': prints("RPATH "); break; 1436 case 'r': prints("RPATH "); break;
1437 case 'M': prints("CLASS "); break;
1438 case 'l':
729 case 'n': prints("NEEDED "); break; 1439 case 'n': prints("NEEDED "); break;
730 case 'i': prints("INTERP "); break; 1440 case 'i': prints("INTERP "); break;
731 case 'b': prints("BIND "); break; 1441 case 'b': prints("BIND "); break;
1442 case 'Z': prints("SIZE "); break;
732 case 'S': prints("SONAME "); break; 1443 case 'S': prints("SONAME "); break;
733 case 's': prints("SYM "); break; 1444 case 's': prints("SYM "); break;
734 case 'N': prints("LIB "); break; 1445 case 'N': prints("LIB "); break;
735 case 'T': prints("TEXTRELS "); break; 1446 case 'T': prints("TEXTRELS "); break;
1447 case 'k': prints("SECTION "); break;
1448 case 'a': prints("ARCH "); break;
1449 case 'I': prints("OSABI "); break;
1450 case 'Y': prints("EABI "); break;
1451 case 'O': prints("PERM "); break;
1452 case 'D': prints("ENDIAN "); break;
736 default: warnf("'%c' has no title ?", out_format[i]); 1453 default: warnf("'%c' has no title ?", out_format[i]);
737 } 1454 }
738 } 1455 }
739 if (!found_file) prints("FILE "); 1456 if (!found_file) prints("FILE ");
740 prints("\n"); 1457 prints("\n");
744 1461
745 /* dump all the good stuff */ 1462 /* dump all the good stuff */
746 for (i = 0; out_format[i]; ++i) { 1463 for (i = 0; out_format[i]; ++i) {
747 const char *out; 1464 const char *out;
748 const char *tmp; 1465 const char *tmp;
749 1466 static char ubuf[sizeof(unsigned long)*2];
750 /* make sure we trim leading spaces in quiet mode */
751 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
752 *out_buffer = '\0';
753
754 if (!IS_MODIFIER(out_format[i])) { 1467 if (!IS_MODIFIER(out_format[i])) {
755 xchrcat(&out_buffer, out_format[i], &out_len); 1468 xchrcat(&out_buffer, out_format[i], &out_len);
756 continue; 1469 continue;
757 } 1470 }
758 1471
759 out = NULL; 1472 out = NULL;
760 be_wewy_wewy_quiet = (out_format[i] == '#'); 1473 be_wewy_wewy_quiet = (out_format[i] == '#');
1474 be_semi_verbose = (out_format[i] == '+');
761 switch (out_format[++i]) { 1475 switch (out_format[++i]) {
1476 case '+':
762 case '%': 1477 case '%':
763 case '#': 1478 case '#':
764 xchrcat(&out_buffer, out_format[i], &out_len); break; 1479 xchrcat(&out_buffer, out_format[i], &out_len); break;
765 case 'F': 1480 case 'F':
766 found_file = 1; 1481 found_file = 1;
767 if (be_wewy_wewy_quiet) break; 1482 if (be_wewy_wewy_quiet) break;
768 xstrcat(&out_buffer, filename, &out_len); 1483 xstrcat(&out_buffer, elf->filename, &out_len);
769 break; 1484 break;
770 case 'p': 1485 case 'p':
771 found_file = 1; 1486 found_file = 1;
772 if (be_wewy_wewy_quiet) break; 1487 if (be_wewy_wewy_quiet) break;
773 tmp = filename; 1488 tmp = elf->filename;
774 if (search_path) { 1489 if (search_path) {
775 ssize_t len_search = strlen(search_path); 1490 ssize_t len_search = strlen(search_path);
776 ssize_t len_file = strlen(filename); 1491 ssize_t len_file = strlen(elf->filename);
777 if (!strncmp(filename, search_path, len_search) && \ 1492 if (!strncmp(elf->filename, search_path, len_search) && \
778 len_file > len_search) 1493 len_file > len_search)
779 tmp += len_search; 1494 tmp += len_search;
780 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1495 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
781 } 1496 }
782 xstrcat(&out_buffer, tmp, &out_len); 1497 xstrcat(&out_buffer, tmp, &out_len);
783 break; 1498 break;
784 case 'f': 1499 case 'f':
785 found_file = 1; 1500 found_file = 1;
786 if (be_wewy_wewy_quiet) break; 1501 if (be_wewy_wewy_quiet) break;
787 tmp = strrchr(filename, '/'); 1502 tmp = strrchr(elf->filename, '/');
788 tmp = (tmp == NULL ? filename : tmp+1); 1503 tmp = (tmp == NULL ? elf->filename : tmp+1);
789 xstrcat(&out_buffer, tmp, &out_len); 1504 xstrcat(&out_buffer, tmp, &out_len);
790 break; 1505 break;
791 case 'o': out = get_elfetype(elf); break; 1506 case 'o': out = get_elfetype(elf); break;
792 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1507 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
793 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1508 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
794 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1509 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
795 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1510 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
796 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1511 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1512 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1513 case 'D': out = get_endian(elf); break;
1514 case 'O': out = strfileperms(elf->filename); break;
797 case 'n': 1515 case 'n':
798 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1516 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
799 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1517 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
800 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1518 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
801 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1519 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
802 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1520 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1521 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1522 case 'a': out = get_elfemtype(elf); break;
1523 case 'I': out = get_elfosabi(elf); break;
1524 case 'Y': out = get_elf_eabi(elf); break;
1525 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
803 default: warnf("'%c' has no scan code?", out_format[i]); 1526 default: warnf("'%c' has no scan code?", out_format[i]);
804 } 1527 }
1528 if (out)
805 if (out) xstrcat(&out_buffer, out, &out_len); 1529 xstrcat(&out_buffer, out, &out_len);
806 } 1530 }
807 1531
808#define FOUND_SOMETHING() \ 1532#define FOUND_SOMETHING() \
809 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1533 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
810 found_rpath || found_needed || found_interp || found_bind || \ 1534 found_rpath || found_needed || found_interp || found_bind || \
811 found_soname || found_sym || found_lib || found_textrels) 1535 found_soname || found_sym || found_lib || found_textrels || found_section )
812 1536
813 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1537 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
814 xchrcat(&out_buffer, ' ', &out_len); 1538 xchrcat(&out_buffer, ' ', &out_len);
815 xstrcat(&out_buffer, filename, &out_len); 1539 xstrcat(&out_buffer, elf->filename, &out_len);
816 } 1540 }
817 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1541 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
818 puts(out_buffer); 1542 puts(out_buffer);
819 fflush(stdout); 1543 fflush(stdout);
820 } 1544 }
821 1545
1546 return 0;
1547}
1548
1549/* scan a single elf */
1550static int scanelf_elf(const char *filename, int fd, size_t len)
1551{
1552 int ret = 1;
1553 elfobj *elf;
1554
1555 /* verify this is real ELF */
1556 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1557 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1558 return 2;
1559 }
1560 switch (match_bits) {
1561 case 32:
1562 if (elf->elf_class != ELFCLASS32)
1563 goto label_done;
1564 break;
1565 case 64:
1566 if (elf->elf_class != ELFCLASS64)
1567 goto label_done;
1568 break;
1569 default: break;
1570 }
1571 if (match_etypes) {
1572 char sbuf[126];
1573 strncpy(sbuf, match_etypes, sizeof(sbuf));
1574 if (strchr(match_etypes, ',') != NULL) {
1575 char *p;
1576 while ((p = strrchr(sbuf, ',')) != NULL) {
1577 *p = 0;
1578 if (etype_lookup(p+1) == get_etype(elf))
1579 goto label_ret;
1580 }
1581 }
1582 if (etype_lookup(sbuf) != get_etype(elf))
1583 goto label_done;
1584 }
1585
1586label_ret:
1587 ret = scanelf_elfobj(elf);
1588
1589label_done:
822 unreadelf(elf); 1590 unreadelf(elf);
1591 return ret;
1592}
1593
1594/* scan an archive of elfs */
1595static int scanelf_archive(const char *filename, int fd, size_t len)
1596{
1597 archive_handle *ar;
1598 archive_member *m;
1599 char *ar_buffer;
1600 elfobj *elf;
1601
1602 ar = ar_open_fd(filename, fd);
1603 if (ar == NULL)
1604 return 1;
1605
1606 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1607 while ((m = ar_next(ar)) != NULL) {
1608 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1609 if (cur_pos == -1)
1610 errp("lseek() failed");
1611 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1612 if (elf) {
1613 scanelf_elfobj(elf);
1614 unreadelf(elf);
1615 }
1616 }
1617 munmap(ar_buffer, len);
1618
1619 return 0;
1620}
1621/* scan a file which may be an elf or an archive or some other magical beast */
1622static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1623{
1624 const struct stat *st = st_cache;
1625 struct stat symlink_st;
1626 int fd;
1627
1628 /* always handle regular files and handle symlinked files if no -y */
1629 if (S_ISLNK(st->st_mode)) {
1630 if (!scan_symlink)
1631 return 1;
1632 fstatat(dir_fd, filename, &symlink_st, 0);
1633 st = &symlink_st;
1634 }
1635
1636 if (!S_ISREG(st->st_mode)) {
1637 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1638 return 1;
1639 }
1640
1641 if (match_perms) {
1642 if ((st->st_mode | match_perms) != st->st_mode)
1643 return 1;
1644 }
1645 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1646 if (fd == -1) {
1647 if (fix_elf && errno == ETXTBSY)
1648 warnp("%s: could not fix", filename);
1649 else if (be_verbose > 2)
1650 printf("%s: skipping file: %s\n", filename, strerror(errno));
1651 return 1;
1652 }
1653
1654 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1655 /* if it isn't an ELF, maybe it's an .a archive */
1656 if (scan_archives)
1657 scanelf_archive(filename, fd, st->st_size);
1658
1659 /*
1660 * unreadelf() implicitly closes its fd, so only close it
1661 * when we are returning it in the non-ELF case
1662 */
1663 close(fd);
1664 }
1665
1666 return 0;
823} 1667}
824 1668
825/* scan a directory for ET_EXEC files and print when we find one */ 1669/* scan a directory for ET_EXEC files and print when we find one */
826static void scanelf_dir(const char *path) 1670static int scanelf_dirat(int dir_fd, const char *path)
827{ 1671{
828 register DIR *dir; 1672 register DIR *dir;
829 register struct dirent *dentry; 1673 register struct dirent *dentry;
830 struct stat st_top, st; 1674 struct stat st_top, st;
831 char buf[_POSIX_PATH_MAX]; 1675 char buf[__PAX_UTILS_PATH_MAX], *subpath;
832 size_t pathlen = 0, len = 0; 1676 size_t pathlen = 0, len = 0;
1677 int ret = 0;
1678 int subdir_fd;
833 1679
834 /* make sure path exists */ 1680 /* make sure path exists */
835 if (lstat(path, &st_top) == -1) { 1681 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
836 if (be_verbose > 2) printf("%s: does not exist\n", path); 1682 if (be_verbose > 2) printf("%s: does not exist\n", path);
837 return; 1683 return 1;
838 } 1684 }
839 1685
840 /* ok, if it isn't a directory, assume we can open it */ 1686 /* ok, if it isn't a directory, assume we can open it */
841 if (!S_ISDIR(st_top.st_mode)) { 1687 if (!S_ISDIR(st_top.st_mode))
842 scanelf_file(path); 1688 return scanelf_fileat(dir_fd, path, &st_top);
843 return;
844 }
845 1689
846 /* now scan the dir looking for fun stuff */ 1690 /* now scan the dir looking for fun stuff */
847 if ((dir = opendir(path)) == NULL) { 1691 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
848 warnf("could not opendir %s: %s", path, strerror(errno)); 1692 if (subdir_fd == -1)
1693 dir = NULL;
1694 else
1695 dir = fdopendir(subdir_fd);
1696 if (dir == NULL) {
1697 if (subdir_fd != -1)
1698 close(subdir_fd);
1699 else if (be_verbose > 2)
1700 printf("%s: skipping dir: %s\n", path, strerror(errno));
849 return; 1701 return 1;
850 } 1702 }
851 if (be_verbose) printf("%s: scanning dir\n", path); 1703 if (be_verbose > 1) printf("%s: scanning dir\n", path);
852 1704
853 pathlen = strlen(path); 1705 subpath = stpcpy(buf, path);
1706 if (subpath[-1] != '/')
1707 *subpath++ = '/';
1708 pathlen = subpath - buf;
854 while ((dentry = readdir(dir))) { 1709 while ((dentry = readdir(dir))) {
855 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1710 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
856 continue; 1711 continue;
857 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1712
858 if (len >= sizeof(buf)) { 1713 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
859 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
860 (unsigned long)len, (unsigned long)sizeof(buf));
861 continue; 1714 continue;
1715
1716 len = strlen(dentry->d_name);
1717 if (len + pathlen + 1 >= sizeof(buf)) {
1718 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1719 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1720 continue;
862 } 1721 }
863 sprintf(buf, "%s/%s", path, dentry->d_name); 1722 memcpy(subpath, dentry->d_name, len);
864 if (lstat(buf, &st) != -1) { 1723 subpath[len] = '\0';
1724
865 if (S_ISREG(st.st_mode)) 1725 if (S_ISREG(st.st_mode))
866 scanelf_file(buf); 1726 ret = scanelf_fileat(dir_fd, buf, &st);
867 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1727 else if (dir_recurse && S_ISDIR(st.st_mode)) {
868 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1728 if (dir_crossmount || (st_top.st_dev == st.st_dev))
869 scanelf_dir(buf); 1729 ret = scanelf_dirat(dir_fd, buf);
870 }
871 } 1730 }
872 } 1731 }
873 closedir(dir); 1732 closedir(dir);
874}
875 1733
1734 return ret;
1735}
1736static int scanelf_dir(const char *path)
1737{
1738 return scanelf_dirat(root_fd, root_rel_path(path));
1739}
1740
876static int scanelf_from_file(char *filename) 1741static int scanelf_from_file(const char *filename)
877{ 1742{
878 FILE *fp = NULL; 1743 FILE *fp;
879 char *p; 1744 char *p, *path;
880 char path[_POSIX_PATH_MAX]; 1745 size_t len;
1746 int ret;
881 1747
882 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1748 if (strcmp(filename, "-") == 0)
883 fp = stdin; 1749 fp = stdin;
884 else if ((fp = fopen(filename, "r")) == NULL) 1750 else if ((fp = fopen(filename, "r")) == NULL)
885 return 1; 1751 return 1;
886 1752
887 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1753 path = NULL;
1754 len = 0;
1755 ret = 0;
1756 while (getline(&path, &len, fp) != -1) {
888 if ((p = strchr(path, '\n')) != NULL) 1757 if ((p = strchr(path, '\n')) != NULL)
889 *p = 0; 1758 *p = 0;
890 search_path = path; 1759 search_path = path;
891 scanelf_dir(path); 1760 ret = scanelf_dir(path);
892 } 1761 }
1762 free(path);
1763
893 if (fp != stdin) 1764 if (fp != stdin)
894 fclose(fp); 1765 fclose(fp);
1766
895 return 0; 1767 return ret;
896} 1768}
897 1769
898static void load_ld_so_conf() 1770#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1771
1772static int _load_ld_cache_config(const char *fname)
899{ 1773{
900 FILE *fp = NULL; 1774 FILE *fp = NULL;
901 char *p; 1775 char *p, *path;
902 char path[_POSIX_PATH_MAX]; 1776 size_t len;
903 int i = 0; 1777 int curr_fd = -1;
904 1778
905 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1779 fp = fopenat_r(root_fd, root_rel_path(fname));
1780 if (fp == NULL)
906 return; 1781 return -1;
907 1782
908 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1783 path = NULL;
909 if (*path != '/') 1784 len = 0;
910 continue; 1785 while (getline(&path, &len, fp) != -1) {
911
912 if ((p = strrchr(path, '\r')) != NULL) 1786 if ((p = strrchr(path, '\r')) != NULL)
913 *p = 0; 1787 *p = 0;
914 if ((p = strchr(path, '\n')) != NULL) 1788 if ((p = strchr(path, '\n')) != NULL)
915 *p = 0; 1789 *p = 0;
916 1790
917 ldpaths[i++] = xstrdup(path); 1791 /* recursive includes of the same file will make this segfault. */
1792 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1793 glob_t gl;
1794 size_t x;
1795 const char *gpath;
918 1796
919 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1797 /* re-use existing path buffer ... need to be creative */
920 break; 1798 if (path[8] != '/')
1799 gpath = memcpy(path + 3, "/etc/", 5);
1800 else
1801 gpath = path + 8;
1802 if (root_fd != AT_FDCWD) {
1803 if (curr_fd == -1) {
1804 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1805 if (fchdir(root_fd))
1806 errp("unable to change to root dir");
1807 }
1808 gpath = root_rel_path(gpath);
1809 }
1810
1811 if (glob(gpath, 0, NULL, &gl) == 0) {
1812 for (x = 0; x < gl.gl_pathc; ++x) {
1813 /* try to avoid direct loops */
1814 if (strcmp(gl.gl_pathv[x], fname) == 0)
1815 continue;
1816 _load_ld_cache_config(gl.gl_pathv[x]);
1817 }
1818 globfree(&gl);
1819 }
1820
1821 /* failed globs are ignored by glibc */
1822 continue;
921 } 1823 }
922 ldpaths[i] = NULL; 1824
1825 if (*path != '/')
1826 continue;
1827
1828 xarraypush_str(ldpaths, path);
1829 }
1830 free(path);
923 1831
924 fclose(fp); 1832 fclose(fp);
1833
1834 if (curr_fd != -1) {
1835 if (fchdir(curr_fd))
1836 {/* don't care */}
1837 close(curr_fd);
1838 }
1839
1840 return 0;
1841}
1842
1843#elif defined(__FreeBSD__) || defined(__DragonFly__)
1844
1845static int _load_ld_cache_config(const char *fname)
1846{
1847 FILE *fp = NULL;
1848 char *b = NULL, *p;
1849 struct elfhints_hdr hdr;
1850
1851 fp = fopenat_r(root_fd, root_rel_path(fname));
1852 if (fp == NULL)
1853 return -1;
1854
1855 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1856 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1857 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1858 {
1859 fclose(fp);
1860 return -1;
1861 }
1862
1863 b = xmalloc(hdr.dirlistlen + 1);
1864 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1865 fclose(fp);
1866 free(b);
1867 return -1;
1868 }
1869
1870 while ((p = strsep(&b, ":"))) {
1871 if (*p == '\0')
1872 continue;
1873 xarraypush_str(ldpaths, p);
1874 }
1875
1876 free(b);
1877 fclose(fp);
1878 return 0;
1879}
1880
1881#else
1882#ifdef __ELF__
1883#warning Cache config support not implemented for your target
1884#endif
1885static int _load_ld_cache_config(const char *fname)
1886{
1887 return 0;
1888}
1889#endif
1890
1891static void load_ld_cache_config(const char *fname)
1892{
1893 bool scan_l, scan_ul, scan_ull;
1894 size_t n;
1895 const char *ldpath;
1896
1897 _load_ld_cache_config(fname);
1898
1899 scan_l = scan_ul = scan_ull = false;
1900 if (array_cnt(ldpaths)) {
1901 array_for_each(ldpaths, n, ldpath) {
1902 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1903 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1904 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1905 }
1906 }
1907
1908 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1909 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1910 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
925} 1911}
926 1912
927/* scan /etc/ld.so.conf for paths */ 1913/* scan /etc/ld.so.conf for paths */
928static void scanelf_ldpath() 1914static void scanelf_ldpath(void)
929{ 1915{
930 char scan_l, scan_ul, scan_ull; 1916 size_t n;
931 int i = 0; 1917 const char *ldpath;
932 1918
933 if (!ldpaths[0]) 1919 array_for_each(ldpaths, n, ldpath)
934 err("Unable to load any paths from ld.so.conf");
935
936 scan_l = scan_ul = scan_ull = 0;
937
938 while (ldpaths[i]) {
939 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
940 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
941 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
942 scanelf_dir(ldpaths[i]); 1920 scanelf_dir(ldpath);
943 ++i;
944 }
945
946 if (!scan_l) scanelf_dir("/lib");
947 if (!scan_ul) scanelf_dir("/usr/lib");
948 if (!scan_ull) scanelf_dir("/usr/local/lib");
949} 1921}
950 1922
951/* scan env PATH for paths */ 1923/* scan env PATH for paths */
952static void scanelf_envpath() 1924static void scanelf_envpath(void)
953{ 1925{
954 char *path, *p; 1926 char *path, *p;
955 1927
956 path = getenv("PATH"); 1928 path = getenv("PATH");
957 if (!path) 1929 if (!path)
964 } 1936 }
965 1937
966 free(path); 1938 free(path);
967} 1939}
968 1940
969 1941/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
970
971/* usage / invocation handling functions */
972#define PARSE_FLAGS "plRmyxetrnibSs:gN:TaqvF:f:o:BhV" 1942#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
973#define a_argument required_argument 1943#define a_argument required_argument
974static struct option const long_opts[] = { 1944static struct option const long_opts[] = {
975 {"path", no_argument, NULL, 'p'}, 1945 {"path", no_argument, NULL, 'p'},
976 {"ldpath", no_argument, NULL, 'l'}, 1946 {"ldpath", no_argument, NULL, 'l'},
1947 {"use-ldpath",no_argument, NULL, 129},
1948 {"root", a_argument, NULL, 128},
977 {"recursive", no_argument, NULL, 'R'}, 1949 {"recursive", no_argument, NULL, 'R'},
978 {"mount", no_argument, NULL, 'm'}, 1950 {"mount", no_argument, NULL, 'm'},
979 {"symlink", no_argument, NULL, 'y'}, 1951 {"symlink", no_argument, NULL, 'y'},
1952 {"archives", no_argument, NULL, 'A'},
1953 {"ldcache", no_argument, NULL, 'L'},
1954 {"fix", no_argument, NULL, 'X'},
1955 {"setpax", a_argument, NULL, 'z'},
980 {"pax", no_argument, NULL, 'x'}, 1956 {"pax", no_argument, NULL, 'x'},
981 {"header", no_argument, NULL, 'e'}, 1957 {"header", no_argument, NULL, 'e'},
982 {"textrel", no_argument, NULL, 't'}, 1958 {"textrel", no_argument, NULL, 't'},
983 {"rpath", no_argument, NULL, 'r'}, 1959 {"rpath", no_argument, NULL, 'r'},
984 {"needed", no_argument, NULL, 'n'}, 1960 {"needed", no_argument, NULL, 'n'},
985 {"interp", no_argument, NULL, 'i'}, 1961 {"interp", no_argument, NULL, 'i'},
986 {"bind", no_argument, NULL, 'b'}, 1962 {"bind", no_argument, NULL, 'b'},
987 {"soname", no_argument, NULL, 'S'}, 1963 {"soname", no_argument, NULL, 'S'},
988 {"symbol", a_argument, NULL, 's'}, 1964 {"symbol", a_argument, NULL, 's'},
1965 {"section", a_argument, NULL, 'k'},
989 {"lib", a_argument, NULL, 'N'}, 1966 {"lib", a_argument, NULL, 'N'},
990 {"gmatch", no_argument, NULL, 'g'}, 1967 {"gmatch", no_argument, NULL, 'g'},
991 {"textrels", no_argument, NULL, 'T'}, 1968 {"textrels", no_argument, NULL, 'T'},
1969 {"etype", a_argument, NULL, 'E'},
1970 {"bits", a_argument, NULL, 'M'},
1971 {"endian", no_argument, NULL, 'D'},
1972 {"osabi", no_argument, NULL, 'I'},
1973 {"eabi", no_argument, NULL, 'Y'},
1974 {"perms", a_argument, NULL, 'O'},
1975 {"size", no_argument, NULL, 'Z'},
992 {"all", no_argument, NULL, 'a'}, 1976 {"all", no_argument, NULL, 'a'},
993 {"quiet", no_argument, NULL, 'q'}, 1977 {"quiet", no_argument, NULL, 'q'},
994 {"verbose", no_argument, NULL, 'v'}, 1978 {"verbose", no_argument, NULL, 'v'},
995 {"format", a_argument, NULL, 'F'}, 1979 {"format", a_argument, NULL, 'F'},
996 {"from", a_argument, NULL, 'f'}, 1980 {"from", a_argument, NULL, 'f'},
997 {"file", a_argument, NULL, 'o'}, 1981 {"file", a_argument, NULL, 'o'},
1982 {"nocolor", no_argument, NULL, 'C'},
998 {"nobanner", no_argument, NULL, 'B'}, 1983 {"nobanner", no_argument, NULL, 'B'},
999 {"help", no_argument, NULL, 'h'}, 1984 {"help", no_argument, NULL, 'h'},
1000 {"version", no_argument, NULL, 'V'}, 1985 {"version", no_argument, NULL, 'V'},
1001 {NULL, no_argument, NULL, 0x0} 1986 {NULL, no_argument, NULL, 0x0}
1002}; 1987};
1003 1988
1004static const char *opts_help[] = { 1989static const char * const opts_help[] = {
1005 "Scan all directories in PATH environment", 1990 "Scan all directories in PATH environment",
1006 "Scan all directories in /etc/ld.so.conf", 1991 "Scan all directories in /etc/ld.so.conf",
1992 "Use ld.so.conf to show full path (use with -r/-n)",
1993 "Root directory (use with -l or -p)",
1007 "Scan directories recursively", 1994 "Scan directories recursively",
1008 "Don't recursively cross mount points", 1995 "Don't recursively cross mount points",
1009 "Don't scan symlinks\n", 1996 "Don't scan symlinks",
1997 "Scan archives (.a files)",
1998 "Utilize ld.so.cache to show full path (use with -r/-n)",
1999 "Try and 'fix' bad things (use with -r/-e)",
2000 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1010 "Print PaX markings", 2001 "Print PaX markings",
1011 "Print GNU_STACK/PT_LOAD markings", 2002 "Print GNU_STACK/PT_LOAD markings",
1012 "Print TEXTREL information", 2003 "Print TEXTREL information",
1013 "Print RPATH information", 2004 "Print RPATH information",
1014 "Print NEEDED information", 2005 "Print NEEDED information",
1015 "Print INTERP information", 2006 "Print INTERP information",
1016 "Print BIND information", 2007 "Print BIND information",
1017 "Print SONAME information", 2008 "Print SONAME information",
1018 "Find a specified symbol", 2009 "Find a specified symbol",
2010 "Find a specified section",
1019 "Find a specified library", 2011 "Find a specified library",
1020 "Use strncmp to match libraries. (use with -N)", 2012 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1021 "Locate cause of TEXTREL", 2013 "Locate cause of TEXTREL",
1022 "Print all scanned info (-x -e -t -r -b)\n", 2014 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2015 "Print only ELF files matching numeric bits",
2016 "Print Endianness",
2017 "Print OSABI",
2018 "Print EABI (EM_ARM Only)",
2019 "Print only ELF files matching octal permissions",
2020 "Print ELF file size",
2021 "Print all useful/simple info\n",
1023 "Only output 'bad' things", 2022 "Only output 'bad' things",
1024 "Be verbose (can be specified more than once)", 2023 "Be verbose (can be specified more than once)",
1025 "Use specified format for output", 2024 "Use specified format for output",
1026 "Read input stream from a filename", 2025 "Read input stream from a filename",
1027 "Write output stream to a filename", 2026 "Write output stream to a filename",
2027 "Don't emit color in output",
1028 "Don't display the header", 2028 "Don't display the header",
1029 "Print this help and exit", 2029 "Print this help and exit",
1030 "Print version and exit", 2030 "Print version and exit",
1031 NULL 2031 NULL
1032}; 2032};
1033 2033
1034/* display usage and exit */ 2034/* display usage and exit */
1035static void usage(int status) 2035static void usage(int status)
1036{ 2036{
1037 unsigned long i; 2037 const char a_arg[] = "<arg>";
2038 size_t a_arg_len = strlen(a_arg) + 2;
2039 size_t i;
2040 int optlen;
1038 printf("* Scan ELF binaries for stuff\n\n" 2041 printf("* Scan ELF binaries for stuff\n\n"
1039 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2042 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1040 printf("Options: -[%s]\n", PARSE_FLAGS); 2043 printf("Options: -[%s]\n", PARSE_FLAGS);
2044
2045 /* prescan the --long opt length to auto-align */
2046 optlen = 0;
1041 for (i = 0; long_opts[i].name; ++i) 2047 for (i = 0; long_opts[i].name; ++i) {
2048 int l = strlen(long_opts[i].name);
2049 if (long_opts[i].has_arg == a_argument)
2050 l += a_arg_len;
2051 optlen = max(l, optlen);
2052 }
2053
2054 for (i = 0; long_opts[i].name; ++i) {
2055 /* first output the short flag if it has one */
2056 if (long_opts[i].val > '~')
2057 printf(" ");
2058 else
2059 printf(" -%c, ", long_opts[i].val);
2060
2061 /* then the long flag */
1042 if (long_opts[i].has_arg == no_argument) 2062 if (long_opts[i].has_arg == no_argument)
1043 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2063 printf("--%-*s", optlen, long_opts[i].name);
1044 long_opts[i].name, opts_help[i]);
1045 else 2064 else
1046 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2065 printf("--%s %s %*s", long_opts[i].name, a_arg,
1047 long_opts[i].name, opts_help[i]); 2066 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1048 2067
1049 if (status != EXIT_SUCCESS) 2068 /* finally the help text */
1050 exit(status); 2069 printf("* %s\n", opts_help[i]);
2070 }
1051 2071
1052 puts("\nThe format modifiers for the -F option are:"); 2072 puts("\nFor more information, see the scanelf(1) manpage");
1053 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1054 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1055 puts(" i INTERP \tb BIND \ts symbol");
1056 puts(" N library \to Type \tT TEXTRELs");
1057 puts(" S SONAME");
1058 puts(" p filename (with search path removed)");
1059 puts(" f filename (short name/basename)");
1060 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1061
1062 exit(status); 2073 exit(status);
1063} 2074}
1064 2075
1065/* parse command line arguments and preform needed actions */ 2076/* parse command line arguments and preform needed actions */
2077#define do_pax_state(option, flag) \
2078 if (islower(option)) { \
2079 flags &= ~PF_##flag; \
2080 flags |= PF_NO##flag; \
2081 } else { \
2082 flags &= ~PF_NO##flag; \
2083 flags |= PF_##flag; \
2084 }
1066static void parseargs(int argc, char *argv[]) 2085static int parseargs(int argc, char *argv[])
1067{ 2086{
1068 int i; 2087 int i;
1069 char *from_file = NULL; 2088 const char *from_file = NULL;
2089 int ret = 0;
2090 char load_cache_config = 0;
1070 2091
1071 opterr = 0; 2092 opterr = 0;
1072 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2093 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1073 switch (i) { 2094 switch (i) {
1074 2095
1078 VERSION, __FILE__, __DATE__, rcsid, argv0); 2099 VERSION, __FILE__, __DATE__, rcsid, argv0);
1079 exit(EXIT_SUCCESS); 2100 exit(EXIT_SUCCESS);
1080 break; 2101 break;
1081 case 'h': usage(EXIT_SUCCESS); break; 2102 case 'h': usage(EXIT_SUCCESS); break;
1082 case 'f': 2103 case 'f':
1083 if (from_file) err("Don't specify -f twice"); 2104 if (from_file) warn("You prob don't want to specify -f twice");
1084 from_file = xstrdup(optarg); 2105 from_file = optarg;
2106 break;
2107 case 'E':
2108 match_etypes = optarg;
2109 break;
2110 case 'M':
2111 match_bits = atoi(optarg);
2112 if (match_bits == 0) {
2113 if (strcmp(optarg, "ELFCLASS32") == 0)
2114 match_bits = 32;
2115 if (strcmp(optarg, "ELFCLASS64") == 0)
2116 match_bits = 64;
2117 }
2118 break;
2119 case 'O':
2120 if (sscanf(optarg, "%o", &match_perms) == -1)
2121 match_bits = 0;
1085 break; 2122 break;
1086 case 'o': { 2123 case 'o': {
1087 FILE *fp = NULL;
1088 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2124 if (freopen(optarg, "w", stdout) == NULL)
1089 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2125 errp("Could not freopen(%s)", optarg);
1090 SET_STDOUT(fp);
1091 break; 2126 break;
1092 } 2127 }
1093 2128 case 'k':
2129 xarraypush_str(find_section_arr, optarg);
2130 break;
1094 case 's': { 2131 case 's': {
1095 size_t len; 2132 /* historically, this was comma delimited */
1096 if (find_sym) err("Don't specify -s twice"); 2133 char *this_sym = strtok(optarg, ",");
1097 find_sym = xstrdup(optarg); 2134 if (!this_sym) /* edge case: -s '' */
1098 len = strlen(find_sym) + 1; 2135 xarraypush_str(find_sym_arr, "");
1099 versioned_symname = (char*)xmalloc(sizeof(char) * (len+1)); 2136 while (this_sym) {
1100 sprintf(versioned_symname, "%s@", find_sym); 2137 xarraypush_str(find_sym_arr, this_sym);
2138 this_sym = strtok(NULL, ",");
2139 }
1101 break; 2140 break;
1102 } 2141 }
1103 case 'N': { 2142 case 'N':
1104 if (find_lib) err("Don't specify -N twice"); 2143 xarraypush_str(find_lib_arr, optarg);
1105 find_lib = xstrdup(optarg);
1106 break; 2144 break;
1107 }
1108
1109 case 'F': { 2145 case 'F': {
1110 if (out_format) err("Don't specify -F twice"); 2146 if (out_format) warn("You prob don't want to specify -F twice");
1111 out_format = xstrdup(optarg); 2147 out_format = optarg;
1112 break; 2148 break;
1113 } 2149 }
2150 case 'z': {
2151 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2152 size_t x;
1114 2153
1115 case 'g': gmatch = 1; 2154 for (x = 0; x < strlen(optarg); x++) {
2155 switch (optarg[x]) {
2156 case 'p':
2157 case 'P':
2158 do_pax_state(optarg[x], PAGEEXEC);
2159 break;
2160 case 's':
2161 case 'S':
2162 do_pax_state(optarg[x], SEGMEXEC);
2163 break;
2164 case 'm':
2165 case 'M':
2166 do_pax_state(optarg[x], MPROTECT);
2167 break;
2168 case 'e':
2169 case 'E':
2170 do_pax_state(optarg[x], EMUTRAMP);
2171 break;
2172 case 'r':
2173 case 'R':
2174 do_pax_state(optarg[x], RANDMMAP);
2175 break;
2176 case 'x':
2177 case 'X':
2178 do_pax_state(optarg[x], RANDEXEC);
2179 break;
2180 default:
2181 break;
2182 }
2183 }
2184 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2185 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2186 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2187 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2188 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2189 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2190 setpax = flags;
2191 break;
2192 }
2193 case 'Z': show_size = 1; break;
2194 case 'g': ++g_match; break;
2195 case 'L': load_cache_config = use_ldcache = 1; break;
1116 case 'y': scan_symlink = 0; break; 2196 case 'y': scan_symlink = 0; break;
2197 case 'A': scan_archives = 1; break;
2198 case 'C': color_init(true); break;
1117 case 'B': show_banner = 0; break; 2199 case 'B': show_banner = 0; break;
1118 case 'l': scan_ldpath = 1; break; 2200 case 'l': load_cache_config = scan_ldpath = 1; break;
1119 case 'p': scan_envpath = 1; break; 2201 case 'p': scan_envpath = 1; break;
1120 case 'R': dir_recurse = 1; break; 2202 case 'R': dir_recurse = 1; break;
1121 case 'm': dir_crossmount = 0; break; 2203 case 'm': dir_crossmount = 0; break;
2204 case 'X': ++fix_elf; break;
1122 case 'x': show_pax = 1; break; 2205 case 'x': show_pax = 1; break;
1123 case 'e': show_phdr = 1; break; 2206 case 'e': show_phdr = 1; break;
1124 case 't': show_textrel = 1; break; 2207 case 't': show_textrel = 1; break;
1125 case 'r': show_rpath = 1; break; 2208 case 'r': show_rpath = 1; break;
1126 case 'n': show_needed = 1; break; 2209 case 'n': show_needed = 1; break;
1127 case 'i': show_interp = 1; break; 2210 case 'i': show_interp = 1; break;
1128 case 'b': show_bind = 1; break; 2211 case 'b': show_bind = 1; break;
1129 case 'S': show_soname = 1; break; 2212 case 'S': show_soname = 1; break;
1130 case 'T': show_textrels = 1; break; 2213 case 'T': show_textrels = 1; break;
1131 case 'q': be_quiet = 1; break; 2214 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1132 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2215 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1133 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2216 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1134 2217 case 'D': show_endian = 1; break;
2218 case 'I': show_osabi = 1; break;
2219 case 'Y': show_eabi = 1; break;
2220 case 128:
2221 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2222 if (root_fd == -1)
2223 err("Could not open root: %s", optarg);
2224 break;
2225 case 129: load_cache_config = use_ldpath = 1; break;
1135 case ':': 2226 case ':':
1136 err("Option missing parameter\n"); 2227 err("Option '%c' is missing parameter", optopt);
1137 case '?': 2228 case '?':
1138 err("Unknown option\n"); 2229 err("Unknown option '%c' or argument missing", optopt);
1139 default: 2230 default:
1140 err("Unhandled option '%c'", i); 2231 err("Unhandled option '%c'; please report this", i);
2232 }
2233 }
2234 if (show_textrels && be_verbose)
2235 has_objdump = bin_in_path("objdump");
2236 /* precompile all the regexes */
2237 if (g_match) {
2238 regex_t preg;
2239 const char *this_sym;
2240 size_t n;
2241 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2242
2243 array_for_each(find_sym_arr, n, this_sym) {
2244 /* see scanelf_match_symname for logic info */
2245 switch (this_sym[0]) {
2246 case '%':
2247 while (*(this_sym++))
2248 if (*this_sym == '%') {
2249 ++this_sym;
2250 break;
2251 }
2252 break;
2253 case '+':
2254 case '-':
2255 ++this_sym;
2256 break;
1141 } 2257 }
2258 if (*this_sym == '*')
2259 ++this_sym;
2260
2261 ret = regcomp(&preg, this_sym, flags);
2262 if (ret) {
2263 char err[256];
2264 regerror(ret, &preg, err, sizeof(err));
2265 err("regcomp of %s failed: %s", this_sym, err);
2266 }
2267 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
1142 } 2268 }
1143 2269 }
2270 /* flatten arrays for display */
2271 if (array_cnt(find_sym_arr))
2272 find_sym = array_flatten_str(find_sym_arr);
2273 if (array_cnt(find_lib_arr))
2274 find_lib = array_flatten_str(find_lib_arr);
2275 if (array_cnt(find_section_arr))
2276 find_section = array_flatten_str(find_section_arr);
1144 /* let the format option override all other options */ 2277 /* let the format option override all other options */
1145 if (out_format) { 2278 if (out_format) {
1146 show_pax = show_phdr = show_textrel = show_rpath = \ 2279 show_pax = show_phdr = show_textrel = show_rpath = \
1147 show_needed = show_interp = show_bind = show_soname = \ 2280 show_needed = show_interp = show_bind = show_soname = \
1148 show_textrels = 0; 2281 show_textrels = show_perms = show_endian = show_size = \
2282 show_osabi = show_eabi = 0;
1149 for (i = 0; out_format[i]; ++i) { 2283 for (i = 0; out_format[i]; ++i) {
1150 if (!IS_MODIFIER(out_format[i])) continue; 2284 if (!IS_MODIFIER(out_format[i])) continue;
1151 2285
1152 switch (out_format[++i]) { 2286 switch (out_format[++i]) {
2287 case '+': break;
1153 case '%': break; 2288 case '%': break;
1154 case '#': break; 2289 case '#': break;
1155 case 'F': break; 2290 case 'F': break;
1156 case 'p': break; 2291 case 'p': break;
1157 case 'f': break; 2292 case 'f': break;
2293 case 'k': break;
1158 case 's': break; 2294 case 's': break;
1159 case 'N': break; 2295 case 'N': break;
1160 case 'o': break; 2296 case 'o': break;
2297 case 'a': break;
2298 case 'M': break;
2299 case 'Z': show_size = 1; break;
2300 case 'D': show_endian = 1; break;
2301 case 'I': show_osabi = 1; break;
2302 case 'Y': show_eabi = 1; break;
2303 case 'O': show_perms = 1; break;
1161 case 'x': show_pax = 1; break; 2304 case 'x': show_pax = 1; break;
1162 case 'e': show_phdr = 1; break; 2305 case 'e': show_phdr = 1; break;
1163 case 't': show_textrel = 1; break; 2306 case 't': show_textrel = 1; break;
1164 case 'r': show_rpath = 1; break; 2307 case 'r': show_rpath = 1; break;
1165 case 'n': show_needed = 1; break; 2308 case 'n': show_needed = 1; break;
1166 case 'i': show_interp = 1; break; 2309 case 'i': show_interp = 1; break;
1167 case 'b': show_bind = 1; break; 2310 case 'b': show_bind = 1; break;
1168 case 'S': show_soname = 1; break; 2311 case 'S': show_soname = 1; break;
1169 case 'T': show_textrels = 1; break; 2312 case 'T': show_textrels = 1; break;
1170 default: 2313 default:
1171 err("Invalid format specifier '%c' (byte %i)", 2314 err("invalid format specifier '%c' (byte %i)",
1172 out_format[i], i+1); 2315 out_format[i], i+1);
1173 } 2316 }
1174 } 2317 }
1175 2318
1176 /* construct our default format */ 2319 /* construct our default format */
1177 } else { 2320 } else {
1178 size_t fmt_len = 30; 2321 size_t fmt_len = 30;
1179 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2322 out_format = xmalloc(sizeof(char) * fmt_len);
2323 *out_format = '\0';
1180 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2324 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1181 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2325 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2326 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2327 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2328 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2329 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2330 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1182 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2331 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1183 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2332 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1184 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2333 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1185 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2334 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1186 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2335 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1187 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2336 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1188 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2337 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1189 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2338 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1190 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2339 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2340 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1191 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2341 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1192 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2342 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1193 } 2343 }
1194 if (be_verbose > 2) printf("Format: %s\n", out_format); 2344 if (be_verbose > 2) printf("Format: %s\n", out_format);
1195 2345
1196 /* now lets actually do the scanning */ 2346 /* now lets actually do the scanning */
1197 if (scan_ldpath || (show_rpath && be_quiet)) 2347 if (load_cache_config)
1198 load_ld_so_conf(); 2348 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1199 if (scan_ldpath) scanelf_ldpath(); 2349 if (scan_ldpath) scanelf_ldpath();
1200 if (scan_envpath) scanelf_envpath(); 2350 if (scan_envpath) scanelf_envpath();
2351 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2352 from_file = "-";
1201 if (from_file) { 2353 if (from_file) {
1202 scanelf_from_file(from_file); 2354 scanelf_from_file(from_file);
1203 free(from_file);
1204 from_file = *argv; 2355 from_file = *argv;
1205 } 2356 }
1206 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2357 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1207 err("Nothing to scan !?"); 2358 err("Nothing to scan !?");
1208 while (optind < argc) { 2359 while (optind < argc) {
1209 search_path = argv[optind++]; 2360 search_path = argv[optind++];
1210 scanelf_dir(search_path); 2361 ret = scanelf_dir(search_path);
1211 } 2362 }
1212 2363
2364#ifdef __PAX_UTILS_CLEANUP
1213 /* clean up */ 2365 /* clean up */
1214 if (find_sym) { 2366 xarrayfree(ldpaths);
2367 xarrayfree(find_sym_arr);
2368 xarrayfree(find_lib_arr);
2369 xarrayfree(find_section_arr);
1215 free(find_sym); 2370 free(find_sym);
1216 free(versioned_symname); 2371 free(find_lib);
2372 free(find_section);
2373 {
2374 size_t n;
2375 regex_t *preg;
2376 array_for_each(find_sym_regex_arr, n, preg)
2377 regfree(preg);
2378 xarrayfree(find_sym_regex_arr);
1217 } 2379 }
1218 if (find_lib) free(find_lib);
1219 if (out_format) free(out_format);
1220 for (i = 0; ldpaths[i]; ++i)
1221 free(ldpaths[i]);
1222}
1223 2380
2381 if (ldcache != 0)
2382 munmap(ldcache, ldcache_size);
2383#endif
1224 2384
1225
1226/* utility funcs */
1227static char *xstrdup(const char *s)
1228{
1229 char *ret = strdup(s);
1230 if (!ret) err("Could not strdup(): %s", strerror(errno));
1231 return ret; 2385 return ret;
1232} 2386}
1233 2387
1234static void *xmalloc(size_t size) 2388static char **get_split_env(const char *envvar)
1235{ 2389{
1236 void *ret = malloc(size); 2390 const char *delims = " \t\n";
1237 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size); 2391 char **envvals = NULL;
1238 return ret; 2392 char *env, *s;
1239} 2393 int nentry;
1240 2394
1241static void xstrcat(char **dst, const char *src, size_t *curr_len) 2395 if ((env = getenv(envvar)) == NULL)
1242{ 2396 return NULL;
1243 size_t new_len;
1244 2397
1245 new_len = strlen(*dst) + strlen(src); 2398 env = xstrdup(env);
1246 if (*curr_len <= new_len) { 2399 if (env == NULL)
1247 *curr_len = new_len + (*curr_len / 2); 2400 return NULL;
1248 *dst = realloc(*dst, *curr_len);
1249 if (!*dst)
1250 err("could not realloc %li bytes", (unsigned long)*curr_len);
1251 }
1252 2401
1253 strcat(*dst, src); 2402 s = strtok(env, delims);
1254} 2403 if (s == NULL) {
2404 free(env);
2405 return NULL;
2406 }
1255 2407
1256static inline void xchrcat(char **dst, const char append, size_t *curr_len) 2408 nentry = 0;
1257{ 2409 while (s != NULL) {
1258 static char my_app[2]; 2410 ++nentry;
1259 my_app[0] = append; 2411 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
1260 my_app[1] = '\0'; 2412 envvals[nentry-1] = s;
1261 xstrcat(dst, my_app, curr_len); 2413 s = strtok(NULL, delims);
1262} 2414 }
2415 envvals[nentry] = NULL;
1263 2416
2417 /* don't want to free(env) as it contains the memory that backs
2418 * the envvals array of strings */
2419 return envvals;
2420}
1264 2421
2422static void parseenv(void)
2423{
2424 color_init(false);
2425 qa_textrels = get_split_env("QA_TEXTRELS");
2426 qa_execstack = get_split_env("QA_EXECSTACK");
2427 qa_wx_load = get_split_env("QA_WX_LOAD");
2428}
2429
2430#ifdef __PAX_UTILS_CLEANUP
2431static void cleanup(void)
2432{
2433 free(out_format);
2434 free(qa_textrels);
2435 free(qa_execstack);
2436 free(qa_wx_load);
2437}
2438#endif
1265 2439
1266int main(int argc, char *argv[]) 2440int main(int argc, char *argv[])
1267{ 2441{
2442 int ret;
1268 if (argc < 2) 2443 if (argc < 2)
1269 usage(EXIT_FAILURE); 2444 usage(EXIT_FAILURE);
2445 parseenv();
1270 parseargs(argc, argv); 2446 ret = parseargs(argc, argv);
1271 fclose(stdout); 2447 fclose(stdout);
1272#ifdef __BOUNDS_CHECKING_ON 2448#ifdef __PAX_UTILS_CLEANUP
1273 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2449 cleanup();
2450 warn("The calls to add/delete heap should be off:\n"
2451 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2452 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1274#endif 2453#endif
1275 return EXIT_SUCCESS; 2454 return ret;
1276} 2455}
2456
2457/* Match filename against entries in matchlist, return TRUE
2458 * if the file is listed */
2459static int file_matches_list(const char *filename, char **matchlist)
2460{
2461 char **file;
2462 char *match;
2463 char buf[__PAX_UTILS_PATH_MAX];
2464
2465 if (matchlist == NULL)
2466 return 0;
2467
2468 for (file = matchlist; *file != NULL; file++) {
2469 if (search_path) {
2470 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2471 match = buf;
2472 } else {
2473 match = *file;
2474 }
2475 if (fnmatch(match, filename, 0) == 0)
2476 return 1;
2477 }
2478 return 0;
2479}

Legend:
Removed from v.1.88  
changed lines
  Added in v.1.259

  ViewVC Help
Powered by ViewVC 1.1.20