/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.88 Revision 1.274
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.88 2005/09/30 03:30:54 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.274 2015/02/22 02:27:39 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.274 2015/02/22 02:27:39 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#define __USE_GNU
16#include <string.h>
17#include <errno.h>
18#include <unistd.h>
19#include <sys/stat.h>
20#include <dirent.h>
21#include <getopt.h>
22#include <assert.h>
23#include "paxelf.h" 13#include "paxinc.h"
24 14
25static const char *rcsid = "$Id: scanelf.c,v 1.88 2005/09/30 03:30:54 vapier Exp $";
26#define argv0 "scanelf"
27
28#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
29
30
31 16
32/* prototypes */ 17/* prototypes */
33static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
34static void scanelf_dir(const char *path);
35static void scanelf_ldpath();
36static void scanelf_envpath();
37static void usage(int status);
38static void parseargs(int argc, char *argv[]);
39static char *xstrdup(const char *s);
40static void *xmalloc(size_t size);
41static void xstrcat(char **dst, const char *src, size_t *curr_len);
42static inline void xchrcat(char **dst, const char append, size_t *curr_len);
43 19
44/* variables to control behavior */ 20/* variables to control behavior */
45static char *ldpaths[256]; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
46static char scan_ldpath = 0; 23static char scan_ldpath = 0;
47static char scan_envpath = 0; 24static char scan_envpath = 0;
48static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
49static char dir_recurse = 0; 27static char dir_recurse = 0;
50static char dir_crossmount = 1; 28static char dir_crossmount = 1;
51static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
52static char show_phdr = 0; 32static char show_phdr = 0;
53static char show_textrel = 0; 33static char show_textrel = 0;
54static char show_rpath = 0; 34static char show_rpath = 0;
55static char show_needed = 0; 35static char show_needed = 0;
56static char show_interp = 0; 36static char show_interp = 0;
57static char show_bind = 0; 37static char show_bind = 0;
58static char show_soname = 0; 38static char show_soname = 0;
59static char show_textrels = 0; 39static char show_textrels = 0;
60static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
61static char be_quiet = 0; 44static char be_quiet = 0;
62static char be_verbose = 0; 45static char be_verbose = 0;
63static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
64static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
65static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
66static char *out_format = NULL; 55static char *out_format = NULL;
67static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
68static char gmatch = 0; 58static char g_match = 0;
59static char use_ldcache = 0;
60static char use_ldpath = 0;
69 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
70 66
67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
72
73static const char *objdump;
74
75/* Find the path to a file by name. Note: we do not currently handle the
76 * empty path element correctly (should behave by searching $PWD). */
77static const char *which(const char *fname, const char *envvar)
78{
79 size_t path_len, fname_len;
80 const char *env_path;
81 char *path, *p, *ep;
82
83 p = getenv(envvar);
84 if (p)
85 return p;
86
87 env_path = getenv("PATH");
88 if (!env_path)
89 return NULL;
90
91 /* Create a copy of the $PATH that we can safely modify.
92 * Make it a little bigger so we can append "/fname".
93 * We do this twice -- once for a perm copy, and once for
94 * room at the end of the last element. */
95 path_len = strlen(env_path);
96 fname_len = strlen(fname);
97 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
98 memcpy(path, env_path, path_len + 1);
99
100 p = path + path_len + 1 + fname_len + 1;
101 *p = '/';
102 memcpy(p + 1, fname, fname_len + 1);
103
104 /* Repoint fname to the copy in the env string as it has
105 * the leading slash which we can include in a single memcpy.
106 * Increase the fname len to include the '/' and '\0'. */
107 fname = p;
108 fname_len += 2;
109
110 p = path;
111 while (p) {
112 ep = strchr(p, ':');
113 /* Append the /foo path to the current element. */
114 if (ep)
115 memcpy(ep, fname, fname_len);
116 else
117 memcpy(path + path_len, fname, fname_len);
118
119 if (access(p, R_OK) != -1)
120 return p;
121
122 p = ep;
123 if (ep) {
124 /* If not the last element, restore the chunk we clobbered. */
125 size_t offset = ep - path;
126 size_t restore = min(path_len - offset, fname_len);
127 memcpy(ep, env_path + offset, restore);
128 ++p;
129 }
130 }
131
132 free(path);
133 return NULL;
134}
135
136static FILE *fopenat_r(int dir_fd, const char *path)
137{
138 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
139 if (fd == -1)
140 return NULL;
141 return fdopen(fd, "re");
142}
143
144static const char *root_rel_path(const char *path)
145{
146 /*
147 * openat() will ignore the dirfd if path starts with
148 * a /, so consume all of that noise
149 *
150 * XXX: we don't handle relative paths like ../ that
151 * break out of the --root option, but for now, just
152 * don't do that :P.
153 */
154 if (root_fd != AT_FDCWD) {
155 while (*path == '/')
156 ++path;
157 if (*path == '\0')
158 path = ".";
159 }
160
161 return path;
162}
163
71/* sub-funcs for scanelf_file() */ 164/* sub-funcs for scanelf_fileat() */
72static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 165static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
73{ 166{
74 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 167 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
168
169 /* debug sections */
170 void *symtab = elf_findsecbyname(elf, ".symtab");
171 void *strtab = elf_findsecbyname(elf, ".strtab");
172 /* runtime sections */
173 void *dynsym = elf_findsecbyname(elf, ".dynsym");
174 void *dynstr = elf_findsecbyname(elf, ".dynstr");
175
176 /*
177 * If the sections are marked NOBITS, then they don't exist, so we just
178 * skip them. This let's us work sanely with splitdebug ELFs (rather
179 * than spewing a lot of "corrupt ELF" messages later on). In malformed
180 * ELFs, the section might be wrongly set to NOBITS, but screw em.
181 *
182 * We need to make sure the debug/runtime sym/str sets are used together
183 * as they are generated in sync. Trying to mix them won't work.
184 */
75#define GET_SYMTABS(B) \ 185#define GET_SYMTABS(B) \
76 if (elf->elf_class == ELFCLASS ## B) { \ 186 if (elf->elf_class == ELFCLASS ## B) { \
77 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 187 Elf ## B ## _Shdr *esymtab = symtab; \
78 /* debug sections */ \ 188 Elf ## B ## _Shdr *estrtab = strtab; \
79 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 189 Elf ## B ## _Shdr *edynsym = dynsym; \
80 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 190 Elf ## B ## _Shdr *edynstr = dynstr; \
81 /* runtime sections */ \ 191 \
82 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 192 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
83 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 193 symtab = NULL; \
84 if (symtab && dynsym) { \ 194 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
85 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 195 dynsym = NULL; \
196 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
197 strtab = NULL; \
198 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
199 dynstr = NULL; \
200 \
201 /* Use the set with more symbols if both exist. */ \
202 if (symtab && dynsym && strtab && dynstr) { \
203 if (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) \
204 goto debug##B; \
205 else \
206 goto runtime##B; \
207 } else if (symtab && strtab) { \
208 debug##B: \
209 *sym = symtab; \
210 *str = strtab; \
211 return; \
212 } else if (dynsym && dynstr) { \
213 runtime##B: \
214 *sym = dynsym; \
215 *str = dynstr; \
216 return; \
86 } else { \ 217 } else { \
87 *sym = (void*)(symtab ? symtab : dynsym); \ 218 *sym = *str = NULL; \
88 } \ 219 } \
89 if (strtab && dynstr) { \
90 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \
91 } else { \
92 *tab = (void*)(strtab ? strtab : dynstr); \
93 } \
94 } 220 }
95 GET_SYMTABS(32) 221 GET_SYMTABS(32)
96 GET_SYMTABS(64) 222 GET_SYMTABS(64)
223
224 if (*sym && *str)
225 return;
226
227 /*
228 * damn, they're really going to make us work for it huh?
229 * reconstruct the section header info out of the dynamic
230 * tags so we can see what symbols this guy uses at runtime.
231 */
232 if (!elf->phdr)
233 return;
234#define GET_SYMTABS_DT(B) \
235 if (elf->elf_class == ELFCLASS ## B) { \
236 size_t i; \
237 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
238 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
239 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
240 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
241 Elf ## B ## _Dyn *dyn; \
242 Elf ## B ## _Off offset; \
243 \
244 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
245 vsym = vstr = vhash = vgnu_hash = 0; \
246 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
247 memset(&str_shdr, 0, sizeof(str_shdr)); \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
250 continue; \
251 \
252 offset = EGET(phdr[i].p_offset); \
253 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
254 continue; \
255 \
256 dyn = DYN ## B (elf->vdata + offset); \
257 while (EGET(dyn->d_tag) != DT_NULL) { \
258 switch (EGET(dyn->d_tag)) { \
259 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
260 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
261 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
262 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
263 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
264 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
265 } \
266 ++dyn; \
267 } \
268 if (vsym && vstr) \
269 break; \
270 } \
271 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
272 return; \
273 \
274 /* calc offset into the ELF by finding the load addr of the syms */ \
275 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
276 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
277 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
278 offset = EGET(phdr[i].p_offset); \
279 \
280 if (EGET(phdr[i].p_type) != PT_LOAD) \
281 continue; \
282 \
283 if (vhash >= vaddr && vhash < vaddr + filesz) { \
284 /* Scan the hash table to see how many entries we have */ \
285 Elf32_Word max_sym_idx = 0; \
286 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
287 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
288 Elf32_Word nchains = EGET(hashtbl[1]); \
289 Elf32_Word *buckets = &hashtbl[2]; \
290 Elf32_Word *chains = &buckets[nbuckets]; \
291 Elf32_Word sym_idx; \
292 \
293 for (b = 0; b < nbuckets; ++b) { \
294 if (!buckets[b]) \
295 continue; \
296 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
297 if (max_sym_idx < sym_idx) \
298 max_sym_idx = sym_idx; \
299 } \
300 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
301 } \
302 \
303 if (vsym >= vaddr && vsym < vaddr + filesz) { \
304 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
305 *sym = &sym_shdr; \
306 } \
307 \
308 if (vstr >= vaddr && vstr < vaddr + filesz) { \
309 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
310 *str = &str_shdr; \
311 } \
312 } \
313 }
314 GET_SYMTABS_DT(32)
315 GET_SYMTABS_DT(64)
97} 316}
317
98static char *scanelf_file_pax(elfobj *elf, char *found_pax) 318static char *scanelf_file_pax(elfobj *elf, char *found_pax)
99{ 319{
100 static char *paxflags;
101 static char ret[7]; 320 static char ret[7];
102 unsigned long i, shown; 321 unsigned long i, shown;
103 322
104 if (!show_pax) return NULL; 323 if (!show_pax) return NULL;
105 324
112 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 331 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
113 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 332 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
114 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 333 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
115 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 334 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
116 continue; \ 335 continue; \
117 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 336 if (fix_elf && setpax) { \
337 /* set the paxctl flags */ \
338 ESET(phdr[i].p_flags, setpax); \
339 } \
340 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
118 continue; \ 341 continue; \
119 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 342 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
120 *found_pax = 1; \ 343 *found_pax = 1; \
121 ++shown; \ 344 ++shown; \
122 break; \ 345 break; \
124 } 347 }
125 SHOW_PAX(32) 348 SHOW_PAX(32)
126 SHOW_PAX(64) 349 SHOW_PAX(64)
127 } 350 }
128 351
352 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
353 * was found. This is known to break ELFs on glibc systems,
354 * and mainline PaX has deprecated use of this for a long time.
355 * We could support changing PT_GNU_STACK, but that doesn't
356 * seem like it's worth the effort. #411919
357 */
358
129 /* fall back to EI_PAX if no PT_PAX was found */ 359 /* fall back to EI_PAX if no PT_PAX was found */
130 if (!*ret) { 360 if (!*ret) {
361 static char *paxflags;
131 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 362 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
132 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) { 363 if (!be_quiet || (be_quiet && EI_PAX_FLAGS(elf))) {
133 *found_pax = 1; 364 *found_pax = 1;
134 return paxflags; 365 return (be_wewy_wewy_quiet ? NULL : paxflags);
135 } 366 }
136 strncpy(ret, paxflags, sizeof(ret)); 367 strncpy(ret, paxflags, sizeof(ret));
137 } 368 }
138 369
139 if (be_quiet && !shown) 370 if (be_wewy_wewy_quiet || (be_quiet && !shown))
140 return NULL; 371 return NULL;
372 else
141 return ret; 373 return ret;
142
143} 374}
375
144static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 376static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
145{ 377{
146 static char ret[12]; 378 static char ret[12];
147 char *found; 379 char *found;
148 unsigned long i, off, shown, check_flags;
149 unsigned char multi_stack, multi_relro, multi_load; 380 unsigned long i, shown, multi_stack, multi_relro, multi_load;
150 381
151 if (!show_phdr) return NULL; 382 if (!show_phdr) return NULL;
152 383
153 memcpy(ret, "--- --- ---\0", 12); 384 memcpy(ret, "--- --- ---\0", 12);
154 385
155 shown = 0; 386 shown = 0;
156 multi_stack = multi_relro = multi_load = 0; 387 multi_stack = multi_relro = multi_load = 0;
157 388
158 if (elf->phdr) { 389#define NOTE_GNU_STACK ".note.GNU-stack"
159#define SHOW_PHDR(B) \ 390#define SHOW_PHDR(B) \
160 if (elf->elf_class == ELFCLASS ## B) { \ 391 if (elf->elf_class == ELFCLASS ## B) { \
161 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 392 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
393 Elf ## B ## _Off offset; \
394 uint32_t flags, check_flags; \
395 if (elf->phdr != NULL) { \
162 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 396 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
163 uint32_t flags; \
164 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 397 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
165 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 398 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
399 if (multi_stack++) \
166 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 400 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
401 if (file_matches_list(elf->filename, qa_execstack)) \
402 continue; \
167 found = found_phdr; \ 403 found = found_phdr; \
168 off = 0; \ 404 offset = 0; \
169 check_flags = PF_X; \ 405 check_flags = PF_X; \
170 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 406 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
407 if (multi_relro++) \
171 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 408 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
172 found = found_relro; \ 409 found = found_relro; \
173 off = 4; \ 410 offset = 4; \
174 check_flags = PF_X; \ 411 check_flags = PF_X; \
175 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 412 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
176 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 413 if (file_matches_list(elf->filename, qa_wx_load)) \
414 continue; \
177 found = found_load; \ 415 found = found_load; \
178 off = 8; \ 416 offset = 8; \
179 check_flags = PF_W|PF_X; \ 417 check_flags = PF_W|PF_X; \
180 } else \ 418 } else \
181 continue; \ 419 continue; \
182 flags = EGET(phdr[i].p_flags); \ 420 flags = EGET(phdr[i].p_flags); \
183 if (be_quiet && ((flags & check_flags) != check_flags)) \ 421 if (be_quiet && ((flags & check_flags) != check_flags)) \
184 continue; \ 422 continue; \
423 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
424 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
425 ret[3] = ret[7] = '!'; \
426 flags = EGET(phdr[i].p_flags); \
427 } \
185 memcpy(ret+off, gnu_short_stack_flags(flags), 3); \ 428 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
186 *found = 1; \ 429 *found = 1; \
187 ++shown; \ 430 ++shown; \
431 } \
432 } else if (elf->shdr != NULL) { \
433 /* no program headers which means this is prob an object file */ \
434 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
435 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
436 if ((void*)strtbl > elf->data_end) \
437 goto skip_this_shdr##B; \
438 /* let's flag -w/+x object files since the final ELF will most likely \
439 * need write access to the stack (who doesn't !?). so the combined \
440 * output will bring in +w automatically and that's bad. \
441 */ \
442 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
443 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
444 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
445 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
446 if (offset >= elf->len - sizeof(NOTE_GNU_STACK)) \
447 continue; \
448 if (!strcmp(elf->data + offset, NOTE_GNU_STACK)) { \
449 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
450 flags = EGET(shdr[i].sh_flags); \
451 if (be_quiet && ((flags & check_flags) != check_flags)) \
452 continue; \
453 ++*found_phdr; \
454 shown = 1; \
455 if (flags & SHF_WRITE) ret[0] = 'W'; \
456 if (flags & SHF_ALLOC) ret[1] = 'A'; \
457 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
458 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
459 break; \
460 } \
461 } \
462 skip_this_shdr##B: \
463 if (!multi_stack) { \
464 if (file_matches_list(elf->filename, qa_execstack)) \
465 return NULL; \
466 *found_phdr = 1; \
467 shown = 1; \
468 memcpy(ret, "!WX", 3); \
469 } \
188 } \ 470 } \
189 } 471 }
190 SHOW_PHDR(32) 472 SHOW_PHDR(32)
191 SHOW_PHDR(64) 473 SHOW_PHDR(64)
192 }
193 474
194 if (be_quiet && !shown) 475 if (be_wewy_wewy_quiet || (be_quiet && !shown))
195 return NULL; 476 return NULL;
196 else 477 else
197 return ret; 478 return ret;
198} 479}
480
481/*
482 * See if this ELF contains a DT_TEXTREL tag in any of its
483 * PT_DYNAMIC sections.
484 */
199static char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 485static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
200{ 486{
201 static char ret[] = "TEXTREL"; 487 static const char *ret = "TEXTREL";
202 unsigned long i; 488 unsigned long i;
203 489
204 if (!show_textrel && !show_textrels) return NULL; 490 if (!show_textrel && !show_textrels) return NULL;
491
492 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
205 493
206 if (elf->phdr) { 494 if (elf->phdr) {
207#define SHOW_TEXTREL(B) \ 495#define SHOW_TEXTREL(B) \
208 if (elf->elf_class == ELFCLASS ## B) { \ 496 if (elf->elf_class == ELFCLASS ## B) { \
209 Elf ## B ## _Dyn *dyn; \ 497 Elf ## B ## _Dyn *dyn; \
210 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 498 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
211 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 499 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
212 Elf ## B ## _Off offset; \ 500 Elf ## B ## _Off offset; \
213 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 501 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
214 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 502 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
215 offset = EGET(phdr[i].p_offset); \ 503 offset = EGET(phdr[i].p_offset); \
216 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 504 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
217 dyn = DYN ## B (elf->data + offset); \ 505 dyn = DYN ## B (elf->vdata + offset); \
218 while (EGET(dyn->d_tag) != DT_NULL) { \ 506 while (EGET(dyn->d_tag) != DT_NULL) { \
219 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 507 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
220 *found_textrel = 1; \ 508 *found_textrel = 1; \
221 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 509 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
222 return (be_wewy_wewy_quiet ? NULL : ret); \ 510 return (be_wewy_wewy_quiet ? NULL : ret); \
229 } 517 }
230 518
231 if (be_quiet || be_wewy_wewy_quiet) 519 if (be_quiet || be_wewy_wewy_quiet)
232 return NULL; 520 return NULL;
233 else 521 else
234 return (char *)" - "; 522 return " - ";
235} 523}
524
525/*
526 * Scan the .text section to see if there are any relocations in it.
527 * Should rewrite this to check PT_LOAD sections that are marked
528 * Executable rather than the section named '.text'.
529 */
236static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 530static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
237{ 531{
238 unsigned long s, r, rmax; 532 unsigned long s, r, rmax;
239 void *symtab_void, *strtab_void, *text_void; 533 void *symtab_void, *strtab_void, *text_void;
240 534
261 Elf ## B ## _Rela *rela; \ 555 Elf ## B ## _Rela *rela; \
262 /* search the section headers for relocations */ \ 556 /* search the section headers for relocations */ \
263 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 557 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
264 uint32_t sh_type = EGET(shdr[s].sh_type); \ 558 uint32_t sh_type = EGET(shdr[s].sh_type); \
265 if (sh_type == SHT_REL) { \ 559 if (sh_type == SHT_REL) { \
266 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 560 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
267 rela = NULL; \ 561 rela = NULL; \
268 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 562 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
269 } else if (sh_type == SHT_RELA) { \ 563 } else if (sh_type == SHT_RELA) { \
270 rel = NULL; \ 564 rel = NULL; \
271 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 565 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
272 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 566 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
273 } else \ 567 } else \
274 continue; \ 568 continue; \
275 /* now see if any of the relocs are in the .text */ \ 569 /* now see if any of the relocs are in the .text */ \
276 for (r = 0; r < rmax; ++r) { \ 570 for (r = 0; r < rmax; ++r) { \
291 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 585 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
292 if (be_verbose <= 2) continue; \ 586 if (be_verbose <= 2) continue; \
293 } else \ 587 } else \
294 *found_textrels = 1; \ 588 *found_textrels = 1; \
295 /* locate this relocation symbol name */ \ 589 /* locate this relocation symbol name */ \
296 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 590 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
591 if ((void*)sym > elf->data_end) { \
592 warn("%s: corrupt ELF symbol", elf->filename); \
593 continue; \
594 } \
297 sym_max = ELF ## B ## _R_SYM(r_info); \ 595 sym_max = ELF ## B ## _R_SYM(r_info); \
298 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 596 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
299 sym += sym_max; \ 597 sym += sym_max; \
300 else \ 598 else \
301 sym = NULL; \ 599 sym = NULL; \
302 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 600 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
303 /* show the raw details about this reloc */ \ 601 /* show the raw details about this reloc */ \
304 printf(" %s: ", elf->base_filename); \ 602 printf(" %s: ", elf->base_filename); \
305 if (sym && sym->st_name) \ 603 if (sym && sym->st_name) \
306 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 604 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
307 else \ 605 else \
308 printf("(memory/fake?)"); \ 606 printf("(memory/data?)"); \
309 printf(" [0x%lX]", (unsigned long)r_offset); \ 607 printf(" [0x%lX]", (unsigned long)r_offset); \
310 /* now try to find the closest symbol that this rel is probably in */ \ 608 /* now try to find the closest symbol that this rel is probably in */ \
311 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 609 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
312 func = NULL; \ 610 func = NULL; \
313 offset_tmp = 0; \ 611 offset_tmp = 0; \
314 while (sym_max--) { \ 612 while (sym_max--) { \
315 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 613 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
316 func = sym; \ 614 func = sym; \
317 offset_tmp = EGET(sym->st_value); \ 615 offset_tmp = EGET(sym->st_value); \
318 } \ 616 } \
319 ++sym; \ 617 ++sym; \
320 } \ 618 } \
321 printf(" in "); \ 619 printf(" in "); \
322 if (func && func->st_name) \ 620 if (func && func->st_name) { \
323 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 621 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
622 if (r_offset > EGET(func->st_size)) \
623 printf("(optimized out: previous %s)", func_name); \
324 else \ 624 else \
325 printf("(NULL: fake?)"); \ 625 printf("%s", func_name); \
626 } else \
627 printf("(optimized out)"); \
326 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 628 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
629 if (be_verbose && objdump) { \
630 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
631 char *sysbuf; \
632 size_t syslen; \
633 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
634 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
635 sysbuf = xmalloc(syslen); \
636 if (end_addr < r_offset) \
637 /* not uncommon when things are optimized out */ \
638 end_addr = r_offset + 0x100; \
639 snprintf(sysbuf, syslen, sysfmt, \
640 objdump, \
641 (unsigned long)offset_tmp, \
642 (unsigned long)end_addr, \
643 elf->filename, \
644 (unsigned long)r_offset); \
645 fflush(stdout); \
646 if (system(sysbuf)) {/* don't care */} \
647 fflush(stdout); \
648 free(sysbuf); \
649 } \
327 } \ 650 } \
328 } } 651 } }
329 SHOW_TEXTRELS(32) 652 SHOW_TEXTRELS(32)
330 SHOW_TEXTRELS(64) 653 SHOW_TEXTRELS(64)
331 } 654 }
333 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 656 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
334 657
335 return NULL; 658 return NULL;
336} 659}
337 660
338static void rpath_security_checks(elfobj *, char *);
339static void rpath_security_checks(elfobj *elf, char *item) { 661static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
662{
340 struct stat st; 663 struct stat st;
341 switch (*item) { 664 switch (*item) {
665 case '/': break;
342 case 0: 666 case '.':
343 warnf("Security problem NULL RPATH in %s", elf->filename); 667 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
344 break; 668 break;
345 case '/': break; 669 case ':':
670 case '\0':
671 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
672 break;
346 case '$': 673 case '$':
347 if (fstat(elf->fd, &st) != -1) 674 if (fstat(elf->fd, &st) != -1)
348 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 675 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
349 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 676 warnf("Security problem with %s='%s' in %s with mode set of %o",
350 item, elf->filename, st.st_mode & 07777); 677 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
351 break; 678 break;
352 default: 679 default:
353 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 680 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
354 break; 681 break;
355 } 682 }
683 if (fix_elf)
684 warnf("Note: RPATH has been automatically fixed, but this should be fixed in the package itself");
356} 685}
357static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 686static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
358{ 687{
359 unsigned long i, s; 688 unsigned long i;
360 char *rpath, *runpath, **r; 689 char *rpath, *runpath, **r;
361 void *strtbl_void; 690 void *strtbl_void;
362 691
363 if (!show_rpath) return; 692 if (!show_rpath) return;
364 693
375 Elf ## B ## _Off offset; \ 704 Elf ## B ## _Off offset; \
376 Elf ## B ## _Xword word; \ 705 Elf ## B ## _Xword word; \
377 /* Scan all the program headers */ \ 706 /* Scan all the program headers */ \
378 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 707 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
379 /* Just scan dynamic headers */ \ 708 /* Just scan dynamic headers */ \
380 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 709 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
381 offset = EGET(phdr[i].p_offset); \ 710 offset = EGET(phdr[i].p_offset); \
382 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 711 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
383 /* Just scan dynamic RPATH/RUNPATH headers */ \ 712 /* Just scan dynamic RPATH/RUNPATH headers */ \
384 dyn = DYN ## B (elf->data + offset); \ 713 dyn = DYN ## B (elf->vdata + offset); \
385 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 714 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
386 if (word == DT_RPATH) { \ 715 if (word == DT_RPATH) { \
387 r = &rpath; \ 716 r = &rpath; \
388 } else if (word == DT_RUNPATH) { \ 717 } else if (word == DT_RUNPATH) { \
389 r = &runpath; \ 718 r = &runpath; \
393 } \ 722 } \
394 /* Verify the memory is somewhat sane */ \ 723 /* Verify the memory is somewhat sane */ \
395 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 724 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
396 if (offset < (Elf ## B ## _Off)elf->len) { \ 725 if (offset < (Elf ## B ## _Off)elf->len) { \
397 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 726 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
398 *r = (char*)(elf->data + offset); \ 727 *r = elf->data + offset; \
728 /* cache the length in case we need to nuke this section later on */ \
729 if (fix_elf) \
730 offset = strlen(*r); \
399 /* If quiet, don't output paths in ld.so.conf */ \ 731 /* If quiet, don't output paths in ld.so.conf */ \
400 if (be_quiet) { \ 732 if (be_quiet) { \
401 size_t len; \ 733 size_t len; \
402 char *start, *end; \ 734 char *start, *end; \
403 /* note that we only 'chop' off leading known paths. */ \ 735 /* note that we only 'chop' off leading known paths. */ \
404 /* since *r is read-only memory, we can only move the ptr forward. */ \ 736 /* since *r is read-only memory, we can only move the ptr forward. */ \
405 start = *r; \ 737 start = *r; \
406 /* scan each path in : delimited list */ \ 738 /* scan each path in : delimited list */ \
407 while (start) { \ 739 while (start) { \
408 rpath_security_checks(elf, start); \ 740 rpath_security_checks(elf, start, get_elfdtype(word)); \
409 end = strchr(start, ':'); \ 741 end = strchr(start, ':'); \
410 len = (end ? abs(end - start) : strlen(start)); \ 742 len = (end ? abs(end - start) : strlen(start)); \
411 for (s = 0; ldpaths[s]; ++s) { \ 743 if (use_ldcache) { \
744 size_t n; \
745 const char *ldpath; \
746 array_for_each(ldpaths, n, ldpath) \
412 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 747 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
413 *r = (end ? end + 1 : NULL); \ 748 *r = end; \
749 /* corner case ... if RPATH reads "/usr/lib:", we want \
750 * to show ':' rather than '' */ \
751 if (end && end[1] != '\0') \
752 (*r)++; \
414 break; \ 753 break; \
415 } \ 754 } \
416 } \ 755 } \
417 if (!*r || !ldpaths[s] || !end) \ 756 if (!*r || !end) \
418 start = NULL; \ 757 break; \
419 else \ 758 else \
420 start = start + len + 1; \ 759 start = start + len + 1; \
421 } \ 760 } \
422 } \ 761 } \
762 if (*r) { \
763 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
764 /* just nuke it */ \
765 nuke_it##B: \
766 memset(*r, 0x00, offset); \
767 *r = NULL; \
768 ESET(dyn->d_tag, DT_DEBUG); \
769 ESET(dyn->d_un.d_ptr, 0); \
770 } else if (fix_elf) { \
771 /* try to clean "bad" paths */ \
772 size_t len, tmpdir_len; \
773 char *start, *end; \
774 const char *tmpdir; \
775 start = *r; \
776 tmpdir = (getenv("TMPDIR") ? : "."); \
777 tmpdir_len = strlen(tmpdir); \
778 while (1) { \
779 end = strchr(start, ':'); \
780 if (start == end) { \
781 eat_this_path##B: \
782 len = strlen(end); \
783 memmove(start, end+1, len); \
784 start[len-1] = '\0'; \
785 end = start - 1; \
786 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
787 if (!end) { \
788 if (start == *r) \
789 goto nuke_it##B; \
790 *--start = '\0'; \
791 } else \
792 goto eat_this_path##B; \
793 } \
794 if (!end) \
795 break; \
796 start = end + 1; \
797 } \
798 if (**r == '\0') \
799 goto nuke_it##B; \
800 } \
801 if (*r) \
423 if (*r) *found_rpath = 1; \ 802 *found_rpath = 1; \
803 } \
424 } \ 804 } \
425 ++dyn; \ 805 ++dyn; \
426 } \ 806 } \
427 } } 807 } }
428 SHOW_RPATH(32) 808 SHOW_RPATH(32)
445 } else if (rpath || runpath) 825 } else if (rpath || runpath)
446 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 826 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
447 else if (!be_quiet) 827 else if (!be_quiet)
448 xstrcat(ret, " - ", ret_len); 828 xstrcat(ret, " - ", ret_len);
449} 829}
830
831/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
832#define LDSO_CACHE_MAGIC "ld.so-"
833#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
834#define LDSO_CACHE_VER "1.7.0"
835#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
836#define FLAG_ANY -1
837#define FLAG_TYPE_MASK 0x00ff
838#define FLAG_LIBC4 0x0000
839#define FLAG_ELF 0x0001
840#define FLAG_ELF_LIBC5 0x0002
841#define FLAG_ELF_LIBC6 0x0003
842#define FLAG_REQUIRED_MASK 0xff00
843#define FLAG_SPARC_LIB64 0x0100
844#define FLAG_IA64_LIB64 0x0200
845#define FLAG_X8664_LIB64 0x0300
846#define FLAG_S390_LIB64 0x0400
847#define FLAG_POWERPC_LIB64 0x0500
848#define FLAG_MIPS64_LIBN32 0x0600
849#define FLAG_MIPS64_LIBN64 0x0700
850#define FLAG_X8664_LIBX32 0x0800
851#define FLAG_ARM_LIBHF 0x0900
852#define FLAG_AARCH64_LIB64 0x0a00
853
854#if defined(__GLIBC__) || defined(__UCLIBC__)
855
856static char *lookup_cache_lib(elfobj *elf, const char *fname)
857{
858 int fd;
859 char *strs;
860 static char buf[__PAX_UTILS_PATH_MAX] = "";
861 const char *cachefile = root_rel_path("/etc/ld.so.cache");
862 struct stat st;
863
864 typedef struct {
865 char magic[LDSO_CACHE_MAGIC_LEN];
866 char version[LDSO_CACHE_VER_LEN];
867 int nlibs;
868 } header_t;
869 header_t *header;
870
871 typedef struct {
872 int flags;
873 int sooffset;
874 int liboffset;
875 } libentry_t;
876 libentry_t *libent;
877
878 if (fname == NULL)
879 return NULL;
880
881 if (ldcache == NULL) {
882 if (fstatat(root_fd, cachefile, &st, 0))
883 return NULL;
884
885 fd = openat(root_fd, cachefile, O_RDONLY);
886 if (fd == -1)
887 return NULL;
888
889 /* cache these values so we only map/unmap the cache file once */
890 ldcache_size = st.st_size;
891 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
892 close(fd);
893
894 if (ldcache == MAP_FAILED) {
895 ldcache = NULL;
896 return NULL;
897 }
898
899 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
900 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
901 {
902 munmap(ldcache, ldcache_size);
903 ldcache = NULL;
904 return NULL;
905 }
906 } else
907 header = ldcache;
908
909 libent = ldcache + sizeof(header_t);
910 strs = (char *) &libent[header->nlibs];
911
912 for (fd = 0; fd < header->nlibs; ++fd) {
913 /* This should be more fine grained, but for now we assume that
914 * diff arches will not be cached together, and we ignore the
915 * the different multilib mips cases.
916 */
917 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
918 continue;
919 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
920 continue;
921
922 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
923 continue;
924
925 /* Return first hit because that is how the ldso rolls */
926 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
927 break;
928 }
929
930 return buf;
931}
932
933#elif defined(__NetBSD__)
934static char *lookup_cache_lib(elfobj *elf, const char *fname)
935{
936 static char buf[__PAX_UTILS_PATH_MAX] = "";
937 static struct stat st;
938 size_t n;
939 char *ldpath;
940
941 array_for_each(ldpath, n, ldpath) {
942 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
943 continue; /* if the pathname is too long, or something went wrong, ignore */
944
945 if (stat(buf, &st) != 0)
946 continue; /* if the lib doesn't exist in *ldpath, look further */
947
948 /* NetBSD doesn't actually do sanity checks, it just loads the file
949 * and if that doesn't work, continues looking in other directories.
950 * This cannot easily be safely emulated, unfortunately. For now,
951 * just assume that if it exists, it's a valid library. */
952
953 return buf;
954 }
955
956 /* not found in any path */
957 return NULL;
958}
959#else
960#ifdef __ELF__
961#warning Cache support not implemented for your target
962#endif
963static char *lookup_cache_lib(elfobj *elf, const char *fname)
964{
965 return NULL;
966}
967#endif
968
969static char *lookup_config_lib(const char *fname)
970{
971 static char buf[__PAX_UTILS_PATH_MAX] = "";
972 const char *ldpath;
973 size_t n;
974
975 array_for_each(ldpaths, n, ldpath) {
976 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
977 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
978 return buf;
979 }
980
981 return NULL;
982}
983
450static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 984static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
451{ 985{
452 unsigned long i; 986 unsigned long i;
453 char *needed; 987 char *needed;
454 void *strtbl_void; 988 void *strtbl_void;
989 char *p;
455 990
991 /*
992 * -n -> op==0 -> print all
993 * -N -> op==1 -> print requested
994 */
456 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 995 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
996 return NULL;
457 997
458 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 998 strtbl_void = elf_findsecbyname(elf, ".dynstr");
459 999
460 if (elf->phdr && strtbl_void) { 1000 if (elf->phdr && strtbl_void) {
461#define SHOW_NEEDED(B) \ 1001#define SHOW_NEEDED(B) \
463 Elf ## B ## _Dyn *dyn; \ 1003 Elf ## B ## _Dyn *dyn; \
464 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1004 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
465 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1005 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
466 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1006 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
467 Elf ## B ## _Off offset; \ 1007 Elf ## B ## _Off offset; \
1008 size_t matched = 0; \
1009 /* Walk all the program headers to find the PT_DYNAMIC */ \
468 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1010 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
469 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1011 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
1012 continue; \
470 offset = EGET(phdr[i].p_offset); \ 1013 offset = EGET(phdr[i].p_offset); \
471 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1014 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
1015 continue; \
1016 /* Walk all the dynamic tags to find NEEDED entries */ \
472 dyn = DYN ## B (elf->data + offset); \ 1017 dyn = DYN ## B (elf->vdata + offset); \
473 while (EGET(dyn->d_tag) != DT_NULL) { \ 1018 while (EGET(dyn->d_tag) != DT_NULL) { \
474 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 1019 if (EGET(dyn->d_tag) == DT_NEEDED) { \
475 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1020 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
476 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1021 if (offset >= (Elf ## B ## _Off)elf->len) { \
477 ++dyn; \ 1022 ++dyn; \
478 continue; \ 1023 continue; \
479 } \ 1024 } \
480 needed = (char*)(elf->data + offset); \ 1025 needed = elf->data + offset; \
481 if (op == 0) { \ 1026 if (op == 0) { \
1027 /* -n -> print all entries */ \
482 if (!be_wewy_wewy_quiet) { \ 1028 if (!be_wewy_wewy_quiet) { \
483 if (*found_needed) xchrcat(ret, ',', ret_len); \ 1029 if (*found_needed) xchrcat(ret, ',', ret_len); \
1030 if (use_ldpath) { \
1031 if ((p = lookup_config_lib(needed)) != NULL) \
1032 needed = p; \
1033 } else if (use_ldcache) { \
1034 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
1035 needed = p; \
1036 } \
484 xstrcat(ret, needed, ret_len); \ 1037 xstrcat(ret, needed, ret_len); \
485 } \ 1038 } \
486 *found_needed = 1; \ 1039 *found_needed = 1; \
487 } else { \ 1040 } else { \
488 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1041 /* -N -> print matching entries */ \
1042 size_t n; \
1043 const char *find_lib_name; \
1044 \
1045 array_for_each(find_lib_arr, n, find_lib_name) { \
1046 int invert = 1; \
1047 if (find_lib_name[0] == '!') \
1048 invert = 0, ++find_lib_name; \
1049 if (!strcmp(find_lib_name, needed) == invert) \
1050 ++matched; \
1051 } \
1052 \
1053 if (matched == array_cnt(find_lib_arr)) { \
489 *found_lib = 1; \ 1054 *found_lib = 1; \
490 return (be_wewy_wewy_quiet ? NULL : needed); \ 1055 return (be_wewy_wewy_quiet ? NULL : find_lib); \
491 } \ 1056 } \
492 } \ 1057 } \
493 } \ 1058 } \
494 ++dyn; \ 1059 ++dyn; \
495 } \ 1060 } \
502 1067
503 return NULL; 1068 return NULL;
504} 1069}
505static char *scanelf_file_interp(elfobj *elf, char *found_interp) 1070static char *scanelf_file_interp(elfobj *elf, char *found_interp)
506{ 1071{
507 void *strtbl_void; 1072 uint64_t offset = 0;
508 1073
509 if (!show_interp) return NULL; 1074 if (!show_interp) return NULL;
510 1075
1076 if (elf->phdr) {
1077 /* Walk all the program headers to find the PT_INTERP */
1078#define SHOW_PT_INTERP(B) \
1079 if (elf->elf_class == ELFCLASS ## B) { \
1080 size_t i; \
1081 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1082 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1083 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
1084 if (EGET(phdr[i].p_type) == PT_INTERP) { \
1085 offset = EGET(phdr[i].p_offset); \
1086 break; \
1087 } \
1088 } \
1089 }
1090 SHOW_PT_INTERP(32)
1091 SHOW_PT_INTERP(64)
1092 } else if (elf->shdr) {
1093 /* Use the section headers to find it */
511 strtbl_void = elf_findsecbyname(elf, ".interp"); 1094 void *strtbl_void = elf_findsecbyname(elf, ".interp");
512 1095
513 if (strtbl_void) {
514#define SHOW_INTERP(B) \ 1096#define SHOW_INTERP(B) \
515 if (elf->elf_class == ELFCLASS ## B) { \ 1097 if (elf->elf_class == ELFCLASS ## B) { \
516 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1098 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
517 *found_interp = 1; \ 1099 offset = EGET(strtbl->sh_offset); \
518 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
519 } 1100 }
1101 if (strtbl_void) {
520 SHOW_INTERP(32) 1102 SHOW_INTERP(32)
521 SHOW_INTERP(64) 1103 SHOW_INTERP(64)
522 } 1104 }
1105 }
1106
1107 /* Validate the pointer even if we don't use it in output */
1108 if (offset && offset <= (uint64_t)elf->len) {
1109 char *interp = elf->data + offset;
1110
1111 /* If it isn't a C pointer, it's garbage */
1112 if (memchr(interp, 0, elf->len - offset)) {
1113 *found_interp = 1;
1114 if (!be_wewy_wewy_quiet)
1115 return interp;
1116 }
1117 }
1118
523 return NULL; 1119 return NULL;
524} 1120}
525static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1121static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
526{ 1122{
527 unsigned long i; 1123 unsigned long i;
528 struct stat s; 1124 struct stat s;
1125 bool dynamic = false;
529 1126
530 if (!show_bind) return NULL; 1127 if (!show_bind) return NULL;
531 if (!elf->phdr) return NULL; 1128 if (!elf->phdr) return NULL;
532 1129
533#define SHOW_BIND(B) \ 1130#define SHOW_BIND(B) \
535 Elf ## B ## _Dyn *dyn; \ 1132 Elf ## B ## _Dyn *dyn; \
536 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1133 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
537 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1134 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
538 Elf ## B ## _Off offset; \ 1135 Elf ## B ## _Off offset; \
539 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1136 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
540 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1137 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1138 dynamic = true; \
541 offset = EGET(phdr[i].p_offset); \ 1139 offset = EGET(phdr[i].p_offset); \
542 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1140 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
543 dyn = DYN ## B (elf->data + offset); \ 1141 dyn = DYN ## B (elf->vdata + offset); \
544 while (EGET(dyn->d_tag) != DT_NULL) { \ 1142 while (EGET(dyn->d_tag) != DT_NULL) { \
545 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1143 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
546 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1144 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
547 { \ 1145 { \
548 if (be_quiet) return NULL; \ 1146 if (be_quiet) return NULL; \
556 SHOW_BIND(32) 1154 SHOW_BIND(32)
557 SHOW_BIND(64) 1155 SHOW_BIND(64)
558 1156
559 if (be_wewy_wewy_quiet) return NULL; 1157 if (be_wewy_wewy_quiet) return NULL;
560 1158
1159 /* don't output anything if quiet mode and the ELF is static or not setuid */
561 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1160 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
562 return NULL; 1161 return NULL;
563 } else { 1162 } else {
564 *found_bind = 1; 1163 *found_bind = 1;
565 return (char *) "LAZY"; 1164 return dynamic ? "LAZY" : "STATIC";
566 } 1165 }
567} 1166}
568static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1167static char *scanelf_file_soname(elfobj *elf, char *found_soname)
569{ 1168{
570 unsigned long i; 1169 unsigned long i;
582 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
583 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
584 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1183 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
585 Elf ## B ## _Off offset; \ 1184 Elf ## B ## _Off offset; \
586 /* only look for soname in shared objects */ \ 1185 /* only look for soname in shared objects */ \
587 if (ehdr->e_type != ET_DYN) \ 1186 if (EGET(ehdr->e_type) != ET_DYN) \
588 return NULL; \ 1187 return NULL; \
589 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1188 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
590 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1189 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
591 offset = EGET(phdr[i].p_offset); \ 1190 offset = EGET(phdr[i].p_offset); \
592 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1191 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
593 dyn = DYN ## B (elf->data + offset); \ 1192 dyn = DYN ## B (elf->vdata + offset); \
594 while (EGET(dyn->d_tag) != DT_NULL) { \ 1193 while (EGET(dyn->d_tag) != DT_NULL) { \
595 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1194 if (EGET(dyn->d_tag) == DT_SONAME) { \
596 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1195 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
597 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1196 if (offset >= (Elf ## B ## _Off)elf->len) { \
598 ++dyn; \ 1197 ++dyn; \
599 continue; \ 1198 continue; \
600 } \ 1199 } \
601 soname = (char*)(elf->data + offset); \ 1200 soname = elf->data + offset; \
602 *found_soname = 1; \ 1201 *found_soname = 1; \
603 return (be_wewy_wewy_quiet ? NULL : soname); \ 1202 return (be_wewy_wewy_quiet ? NULL : soname); \
604 } \ 1203 } \
605 ++dyn; \ 1204 ++dyn; \
606 } \ 1205 } \
609 SHOW_SONAME(64) 1208 SHOW_SONAME(64)
610 } 1209 }
611 1210
612 return NULL; 1211 return NULL;
613} 1212}
1213
1214/*
1215 * We support the symbol form:
1216 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1217 * If the symbol name is empty, then all symbols are matched.
1218 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1219 * Do not rely on this output format at all.
1220 * Otherwise the symbol name is used to search (either regex or string compare).
1221 * If the first char of the symbol name is a plus ("+"), then only match
1222 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1223 * Putting modifiers in between the percent signs allows for more in depth
1224 * filters. There are groups of modifiers. If you don't specify a member
1225 * of a group, then all types in that group are matched. The current
1226 * groups and their types are:
1227 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1228 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1229 * STV group: STV_DEFAULT:p STV_INTERNAL:i STV_HIDDEN:h STV_PROTECTED:P
1230 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1231 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1232 * You can search for multiple symbols at once by seperating with a comma (",").
1233 *
1234 * Some examples:
1235 * ELFs with a weak function "foo":
1236 * scanelf -s %wf%foo <ELFs>
1237 * ELFs that define the symbol "main":
1238 * scanelf -s +main <ELFs>
1239 * scanelf -s %d%main <ELFs>
1240 * ELFs that refer to the undefined symbol "brk":
1241 * scanelf -s -brk <ELFs>
1242 * scanelf -s %u%brk <ELFs>
1243 * All global defined objects in an ELF:
1244 * scanelf -s %ogd% <ELF>
1245 */
1246static void
1247scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1248 unsigned int stt, unsigned int stb, unsigned int stv, unsigned int shn, unsigned long size)
1249{
1250 const char *this_sym;
1251 size_t n;
1252
1253 array_for_each(find_sym_arr, n, this_sym) {
1254 bool inc_notype, inc_object, inc_func, inc_file,
1255 inc_local, inc_global, inc_weak,
1256 inc_visdef, inc_intern, inc_hidden, inc_prot,
1257 inc_def, inc_undef, inc_abs, inc_common;
1258
1259 /* symbol selection! */
1260 inc_notype = inc_object = inc_func = inc_file =
1261 inc_local = inc_global = inc_weak =
1262 inc_visdef = inc_intern = inc_hidden = inc_prot =
1263 inc_def = inc_undef = inc_abs = inc_common =
1264 (*this_sym != '%');
1265
1266 /* parse the contents of %...% */
1267 if (!inc_notype) {
1268 while (*(this_sym++)) {
1269 if (*this_sym == '%') {
1270 ++this_sym;
1271 break;
1272 }
1273 switch (*this_sym) {
1274 case 'n': inc_notype = true; break;
1275 case 'o': inc_object = true; break;
1276 case 'f': inc_func = true; break;
1277 case 'F': inc_file = true; break;
1278 case 'l': inc_local = true; break;
1279 case 'g': inc_global = true; break;
1280 case 'w': inc_weak = true; break;
1281 case 'p': inc_visdef = true; break;
1282 case 'i': inc_intern = true; break;
1283 case 'h': inc_hidden = true; break;
1284 case 'P': inc_prot = true; break;
1285 case 'd': inc_def = true; break;
1286 case 'u': inc_undef = true; break;
1287 case 'a': inc_abs = true; break;
1288 case 'c': inc_common = true; break;
1289 default: err("invalid symbol selector '%c'", *this_sym);
1290 }
1291 }
1292
1293 /* If no types are matched, not match all */
1294 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1295 inc_notype = inc_object = inc_func = inc_file = true;
1296 if (!inc_local && !inc_global && !inc_weak)
1297 inc_local = inc_global = inc_weak = true;
1298 if (!inc_visdef && !inc_intern && !inc_hidden && !inc_prot)
1299 inc_visdef = inc_intern = inc_hidden = inc_prot = true;
1300 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1301 inc_def = inc_undef = inc_abs = inc_common = true;
1302
1303 /* backwards compat for defined/undefined short hand */
1304 } else if (*this_sym == '+') {
1305 inc_undef = false;
1306 ++this_sym;
1307 } else if (*this_sym == '-') {
1308 inc_def = inc_abs = inc_common = false;
1309 ++this_sym;
1310 }
1311
1312 /* filter symbols */
1313 if ((!inc_notype && stt == STT_NOTYPE ) || \
1314 (!inc_object && stt == STT_OBJECT ) || \
1315 (!inc_func && stt == STT_FUNC ) || \
1316 (!inc_file && stt == STT_FILE ) || \
1317 (!inc_local && stb == STB_LOCAL ) || \
1318 (!inc_global && stb == STB_GLOBAL ) || \
1319 (!inc_weak && stb == STB_WEAK ) || \
1320 (!inc_visdef && stv == STV_DEFAULT ) || \
1321 (!inc_intern && stv == STV_INTERNAL ) || \
1322 (!inc_hidden && stv == STV_HIDDEN ) || \
1323 (!inc_prot && stv == STV_PROTECTED) || \
1324 (!inc_def && shn && shn < SHN_LORESERVE) || \
1325 (!inc_undef && shn == SHN_UNDEF ) || \
1326 (!inc_abs && shn == SHN_ABS ) || \
1327 (!inc_common && shn == SHN_COMMON ))
1328 continue;
1329
1330 if (*this_sym == '*') {
1331 /* a "*" symbol gets you debug output */
1332 printf("%s(%s) %5lX %-15s %-15s %-15s %-15s %s\n",
1333 ((*found_sym == 0) ? "\n\t" : "\t"),
1334 elf->base_filename,
1335 size,
1336 get_elfstttype(stt),
1337 get_elfstbtype(stb),
1338 get_elfstvtype(stv),
1339 get_elfshntype(shn),
1340 symname);
1341 goto matched;
1342
1343 } else {
1344 if (g_match) {
1345 /* regex match the symbol */
1346 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1347 continue;
1348
1349 } else if (*this_sym) {
1350 /* give empty symbols a "pass", else do a normal compare */
1351 const size_t len = strlen(this_sym);
1352 if (!(strncmp(this_sym, symname, len) == 0 &&
1353 /* Accept unversioned symbol names */
1354 (symname[len] == '\0' || symname[len] == '@')))
1355 continue;
1356 }
1357
1358 if (be_semi_verbose) {
1359 char buf[1024];
1360 snprintf(buf, sizeof(buf), "%lX %s %s",
1361 size,
1362 get_elfstttype(stt),
1363 this_sym);
1364 *ret = xstrdup(buf);
1365 } else {
1366 if (*ret) xchrcat(ret, ',', ret_len);
1367 xstrcat(ret, symname, ret_len);
1368 }
1369
1370 goto matched;
1371 }
1372 }
1373
1374 return;
1375
1376 matched:
1377 *found_sym = 1;
1378}
1379
614static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1380static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
615{ 1381{
616 unsigned long i; 1382 char *ret;
617 void *symtab_void, *strtab_void; 1383 void *symtab_void, *strtab_void;
618 1384
619 if (!find_sym) return NULL; 1385 if (!find_sym) return NULL;
1386 ret = NULL;
620 1387
621 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1388 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
622 1389
623 if (symtab_void && strtab_void) { 1390 if (symtab_void && strtab_void) {
624#define FIND_SYM(B) \ 1391#define FIND_SYM(B) \
625 if (elf->elf_class == ELFCLASS ## B) { \ 1392 if (elf->elf_class == ELFCLASS ## B) { \
626 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1393 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
627 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1394 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
628 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1395 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
629 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1396 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
630 char *symname; \ 1397 char *symname; \
1398 size_t ret_len = 0; \
1399 if (cnt) \
1400 cnt = EGET(symtab->sh_size) / cnt; \
631 for (i = 0; i < cnt; ++i) { \ 1401 for (i = 0; i < cnt; ++i) { \
1402 if ((void*)sym > elf->data_end) { \
1403 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1404 goto break_out; \
1405 } \
632 if (sym->st_name) { \ 1406 if (sym->st_name) { \
1407 /* make sure the symbol name is in acceptable memory range */ \
633 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1408 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
634 if (*find_sym == '*') { \ 1409 if ((void*)symname > elf->data_end) { \
635 printf("%s(%s) %5lX %15s %s\n", \ 1410 warnf("%s: corrupt ELF symbols", elf->filename); \
636 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1411 ++sym; \
637 elf->base_filename, \ 1412 continue; \
638 (long)sym->st_size, \ 1413 } \
639 (char *)get_elfstttype(sym->st_info), \ 1414 scanelf_match_symname(elf, found_sym, \
640 symname); \ 1415 &ret, &ret_len, symname, \
641 *found_sym = 1; \ 1416 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
642 } else if ((strcmp(find_sym, symname) == 0) || \ 1417 ELF##B##_ST_BIND(EGET(sym->st_info)), \
643 (strcmp(symname, versioned_symname) == 0)) \ 1418 ELF##B##_ST_VISIBILITY(EGET(sym->st_other)), \
644 (*found_sym)++; \ 1419 EGET(sym->st_shndx), \
1420 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1421 EGET(sym->st_size)); \
645 } \ 1422 } \
646 ++sym; \ 1423 ++sym; \
647 } } 1424 } \
1425 }
648 FIND_SYM(32) 1426 FIND_SYM(32)
649 FIND_SYM(64) 1427 FIND_SYM(64)
650 } 1428 }
651 1429
1430break_out:
652 if (be_wewy_wewy_quiet) return NULL; 1431 if (be_wewy_wewy_quiet) return NULL;
653 1432
654 if (*find_sym != '*' && *found_sym) 1433 if (*find_sym != '*' && *found_sym)
655 return find_sym; 1434 return ret;
656 if (be_quiet) 1435 if (be_quiet)
657 return NULL; 1436 return NULL;
658 else 1437 else
659 return (char *)" - "; 1438 return " - ";
660} 1439}
1440
1441static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1442{
1443 if (!find_section)
1444 return NULL;
1445
1446#define FIND_SECTION(B) \
1447 if (elf->elf_class == ELFCLASS ## B) { \
1448 size_t matched, n; \
1449 int invert; \
1450 const char *section_name; \
1451 Elf ## B ## _Shdr *section; \
1452 \
1453 matched = 0; \
1454 array_for_each(find_section_arr, n, section_name) { \
1455 invert = (*section_name == '!' ? 1 : 0); \
1456 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1457 if ((section == NULL && invert) || (section != NULL && !invert)) \
1458 ++matched; \
1459 } \
1460 \
1461 if (matched == array_cnt(find_section_arr)) \
1462 *found_section = 1; \
1463 }
1464 FIND_SECTION(32)
1465 FIND_SECTION(64)
1466
1467 if (be_wewy_wewy_quiet)
1468 return NULL;
1469
1470 if (*found_section)
1471 return find_section;
1472
1473 if (be_quiet)
1474 return NULL;
1475 else
1476 return " - ";
1477}
1478
661/* scan an elf file and show all the fun stuff */ 1479/* scan an elf file and show all the fun stuff */
662#define prints(str) write(fileno(stdout), str, strlen(str)) 1480#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
663static void scanelf_file(const char *filename) 1481static int scanelf_elfobj(elfobj *elf)
664{ 1482{
665 unsigned long i; 1483 unsigned long i;
666 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1484 char found_pax, found_phdr, found_relro, found_load, found_textrel,
667 found_rpath, found_needed, found_interp, found_bind, found_soname, 1485 found_rpath, found_needed, found_interp, found_bind, found_soname,
668 found_sym, found_lib, found_file, found_textrels; 1486 found_sym, found_lib, found_file, found_textrels, found_section;
669 elfobj *elf;
670 struct stat st;
671 static char *out_buffer = NULL; 1487 static char *out_buffer = NULL;
672 static size_t out_len; 1488 static size_t out_len;
673 1489
674 /* make sure 'filename' exists */
675 if (lstat(filename, &st) == -1) {
676 if (be_verbose > 2) printf("%s: does not exist\n", filename);
677 return;
678 }
679 /* always handle regular files and handle symlinked files if no -y */
680 if (S_ISLNK(st.st_mode)) {
681 if (!scan_symlink) return;
682 stat(filename, &st);
683 }
684 if (!S_ISREG(st.st_mode)) {
685 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
686 return;
687 }
688
689 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1490 found_pax = found_phdr = found_relro = found_load = found_textrel = \
690 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1491 found_rpath = found_needed = found_interp = found_bind = found_soname = \
691 found_sym = found_lib = found_file = found_textrels = 0; 1492 found_sym = found_lib = found_file = found_textrels = found_section = 0;
692 1493
693 /* verify this is real ELF */
694 if ((elf = readelf(filename)) == NULL) {
695 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
696 return;
697 }
698
699 if (be_verbose > 1) 1494 if (be_verbose > 2)
700 printf("%s: scanning file {%s,%s}\n", filename, 1495 printf("%s: scanning file {%s,%s}\n", elf->filename,
701 get_elfeitype(EI_CLASS, elf->elf_class), 1496 get_elfeitype(EI_CLASS, elf->elf_class),
702 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1497 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
703 else if (be_verbose) 1498 else if (be_verbose > 1)
704 printf("%s: scanning file\n", filename); 1499 printf("%s: scanning file\n", elf->filename);
705 1500
706 /* init output buffer */ 1501 /* init output buffer */
707 if (!out_buffer) { 1502 if (!out_buffer) {
708 out_len = sizeof(char) * 80; 1503 out_len = sizeof(char) * 80;
709 out_buffer = (char*)xmalloc(out_len); 1504 out_buffer = xmalloc(out_len);
710 } 1505 }
711 *out_buffer = '\0'; 1506 *out_buffer = '\0';
712 1507
713 /* show the header */ 1508 /* show the header */
714 if (!be_quiet && show_banner) { 1509 if (!be_quiet && show_banner) {
715 for (i = 0; out_format[i]; ++i) { 1510 for (i = 0; out_format[i]; ++i) {
716 if (!IS_MODIFIER(out_format[i])) continue; 1511 if (!IS_MODIFIER(out_format[i])) continue;
717 1512
718 switch (out_format[++i]) { 1513 switch (out_format[++i]) {
1514 case '+': break;
719 case '%': break; 1515 case '%': break;
720 case '#': break; 1516 case '#': break;
721 case 'F': 1517 case 'F':
722 case 'p': 1518 case 'p':
723 case 'f': prints("FILE "); found_file = 1; break; 1519 case 'f': prints("FILE "); found_file = 1; break;
724 case 'o': prints(" TYPE "); break; 1520 case 'o': prints(" TYPE "); break;
725 case 'x': prints(" PAX "); break; 1521 case 'x': prints(" PAX "); break;
726 case 'e': prints("STK/REL/PTL "); break; 1522 case 'e': prints("STK/REL/PTL "); break;
727 case 't': prints("TEXTREL "); break; 1523 case 't': prints("TEXTREL "); break;
728 case 'r': prints("RPATH "); break; 1524 case 'r': prints("RPATH "); break;
1525 case 'M': prints("CLASS "); break;
1526 case 'l':
729 case 'n': prints("NEEDED "); break; 1527 case 'n': prints("NEEDED "); break;
730 case 'i': prints("INTERP "); break; 1528 case 'i': prints("INTERP "); break;
731 case 'b': prints("BIND "); break; 1529 case 'b': prints("BIND "); break;
1530 case 'Z': prints("SIZE "); break;
732 case 'S': prints("SONAME "); break; 1531 case 'S': prints("SONAME "); break;
733 case 's': prints("SYM "); break; 1532 case 's': prints("SYM "); break;
734 case 'N': prints("LIB "); break; 1533 case 'N': prints("LIB "); break;
735 case 'T': prints("TEXTRELS "); break; 1534 case 'T': prints("TEXTRELS "); break;
1535 case 'k': prints("SECTION "); break;
1536 case 'a': prints("ARCH "); break;
1537 case 'I': prints("OSABI "); break;
1538 case 'Y': prints("EABI "); break;
1539 case 'O': prints("PERM "); break;
1540 case 'D': prints("ENDIAN "); break;
736 default: warnf("'%c' has no title ?", out_format[i]); 1541 default: warnf("'%c' has no title ?", out_format[i]);
737 } 1542 }
738 } 1543 }
739 if (!found_file) prints("FILE "); 1544 if (!found_file) prints("FILE ");
740 prints("\n"); 1545 prints("\n");
744 1549
745 /* dump all the good stuff */ 1550 /* dump all the good stuff */
746 for (i = 0; out_format[i]; ++i) { 1551 for (i = 0; out_format[i]; ++i) {
747 const char *out; 1552 const char *out;
748 const char *tmp; 1553 const char *tmp;
749 1554 static char ubuf[sizeof(unsigned long)*2];
750 /* make sure we trim leading spaces in quiet mode */
751 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
752 *out_buffer = '\0';
753
754 if (!IS_MODIFIER(out_format[i])) { 1555 if (!IS_MODIFIER(out_format[i])) {
755 xchrcat(&out_buffer, out_format[i], &out_len); 1556 xchrcat(&out_buffer, out_format[i], &out_len);
756 continue; 1557 continue;
757 } 1558 }
758 1559
759 out = NULL; 1560 out = NULL;
760 be_wewy_wewy_quiet = (out_format[i] == '#'); 1561 be_wewy_wewy_quiet = (out_format[i] == '#');
1562 be_semi_verbose = (out_format[i] == '+');
761 switch (out_format[++i]) { 1563 switch (out_format[++i]) {
1564 case '+':
762 case '%': 1565 case '%':
763 case '#': 1566 case '#':
764 xchrcat(&out_buffer, out_format[i], &out_len); break; 1567 xchrcat(&out_buffer, out_format[i], &out_len); break;
765 case 'F': 1568 case 'F':
766 found_file = 1; 1569 found_file = 1;
767 if (be_wewy_wewy_quiet) break; 1570 if (be_wewy_wewy_quiet) break;
768 xstrcat(&out_buffer, filename, &out_len); 1571 xstrcat(&out_buffer, elf->filename, &out_len);
769 break; 1572 break;
770 case 'p': 1573 case 'p':
771 found_file = 1; 1574 found_file = 1;
772 if (be_wewy_wewy_quiet) break; 1575 if (be_wewy_wewy_quiet) break;
773 tmp = filename; 1576 tmp = elf->filename;
774 if (search_path) { 1577 if (search_path) {
775 ssize_t len_search = strlen(search_path); 1578 ssize_t len_search = strlen(search_path);
776 ssize_t len_file = strlen(filename); 1579 ssize_t len_file = strlen(elf->filename);
777 if (!strncmp(filename, search_path, len_search) && \ 1580 if (!strncmp(elf->filename, search_path, len_search) && \
778 len_file > len_search) 1581 len_file > len_search)
779 tmp += len_search; 1582 tmp += len_search;
780 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1583 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
781 } 1584 }
782 xstrcat(&out_buffer, tmp, &out_len); 1585 xstrcat(&out_buffer, tmp, &out_len);
783 break; 1586 break;
784 case 'f': 1587 case 'f':
785 found_file = 1; 1588 found_file = 1;
786 if (be_wewy_wewy_quiet) break; 1589 if (be_wewy_wewy_quiet) break;
787 tmp = strrchr(filename, '/'); 1590 tmp = strrchr(elf->filename, '/');
788 tmp = (tmp == NULL ? filename : tmp+1); 1591 tmp = (tmp == NULL ? elf->filename : tmp+1);
789 xstrcat(&out_buffer, tmp, &out_len); 1592 xstrcat(&out_buffer, tmp, &out_len);
790 break; 1593 break;
791 case 'o': out = get_elfetype(elf); break; 1594 case 'o': out = get_elfetype(elf); break;
792 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1595 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
793 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1596 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
794 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1597 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
795 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1598 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
796 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1599 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1600 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1601 case 'D': out = get_endian(elf); break;
1602 case 'O': out = strfileperms(elf->filename); break;
797 case 'n': 1603 case 'n':
798 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1604 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
799 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1605 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
800 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1606 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
801 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1607 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
802 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1608 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1609 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1610 case 'a': out = get_elfemtype(elf); break;
1611 case 'I': out = get_elfosabi(elf); break;
1612 case 'Y': out = get_elf_eabi(elf); break;
1613 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
803 default: warnf("'%c' has no scan code?", out_format[i]); 1614 default: warnf("'%c' has no scan code?", out_format[i]);
804 } 1615 }
1616 if (out)
805 if (out) xstrcat(&out_buffer, out, &out_len); 1617 xstrcat(&out_buffer, out, &out_len);
806 } 1618 }
807 1619
808#define FOUND_SOMETHING() \ 1620#define FOUND_SOMETHING() \
809 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1621 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
810 found_rpath || found_needed || found_interp || found_bind || \ 1622 found_rpath || found_needed || found_interp || found_bind || \
811 found_soname || found_sym || found_lib || found_textrels) 1623 found_soname || found_sym || found_lib || found_textrels || found_section )
812 1624
813 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1625 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
814 xchrcat(&out_buffer, ' ', &out_len); 1626 xchrcat(&out_buffer, ' ', &out_len);
815 xstrcat(&out_buffer, filename, &out_len); 1627 xstrcat(&out_buffer, elf->filename, &out_len);
816 } 1628 }
817 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1629 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
818 puts(out_buffer); 1630 puts(out_buffer);
819 fflush(stdout); 1631 fflush(stdout);
820 } 1632 }
821 1633
1634 return 0;
1635}
1636
1637/* scan a single elf */
1638static int scanelf_elf(const char *filename, int fd, size_t len)
1639{
1640 int ret = 1;
1641 size_t n;
1642 const char *match_etype;
1643 elfobj *elf;
1644
1645 /* Verify this is a real ELF */
1646 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1647 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1648 return 2;
1649 }
1650
1651 /* Possibly filter based on ELF bitness */
1652 switch (match_bits) {
1653 case 32:
1654 if (elf->elf_class != ELFCLASS32)
1655 goto done;
1656 break;
1657 case 64:
1658 if (elf->elf_class != ELFCLASS64)
1659 goto done;
1660 break;
1661 }
1662
1663 /* Possibly filter based on the ELF's e_type field */
1664 array_for_each(match_etypes, n, match_etype)
1665 if (etype_lookup(match_etype) == get_etype(elf))
1666 goto scanit;
1667 if (array_cnt(match_etypes))
1668 goto done;
1669
1670 scanit:
1671 ret = scanelf_elfobj(elf);
1672
1673 done:
822 unreadelf(elf); 1674 unreadelf(elf);
1675 return ret;
1676}
1677
1678/* scan an archive of elfs */
1679static int scanelf_archive(const char *filename, int fd, size_t len)
1680{
1681 archive_handle *ar;
1682 archive_member *m;
1683 char *ar_buffer;
1684 elfobj *elf;
1685
1686 ar = ar_open_fd(filename, fd);
1687 if (ar == NULL)
1688 return 1;
1689
1690 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1691 while ((m = ar_next(ar)) != NULL) {
1692 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1693 if (cur_pos == -1)
1694 errp("lseek() failed");
1695 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1696 if (elf) {
1697 scanelf_elfobj(elf);
1698 unreadelf(elf);
1699 }
1700 }
1701 munmap(ar_buffer, len);
1702
1703 return 0;
1704}
1705/* scan a file which may be an elf or an archive or some other magical beast */
1706static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1707{
1708 const struct stat *st = st_cache;
1709 struct stat symlink_st;
1710 int fd;
1711
1712 /* always handle regular files and handle symlinked files if no -y */
1713 if (S_ISLNK(st->st_mode)) {
1714 if (!scan_symlink)
1715 return 1;
1716 fstatat(dir_fd, filename, &symlink_st, 0);
1717 st = &symlink_st;
1718 }
1719
1720 if (!S_ISREG(st->st_mode)) {
1721 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1722 return 1;
1723 }
1724
1725 if (match_perms) {
1726 if ((st->st_mode | match_perms) != st->st_mode)
1727 return 1;
1728 }
1729 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1730 if (fd == -1) {
1731 if (fix_elf && errno == ETXTBSY)
1732 warnp("%s: could not fix", filename);
1733 else if (be_verbose > 2)
1734 printf("%s: skipping file: %s\n", filename, strerror(errno));
1735 return 1;
1736 }
1737
1738 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1739 /* if it isn't an ELF, maybe it's an .a archive */
1740 if (scan_archives)
1741 scanelf_archive(filename, fd, st->st_size);
1742
1743 /*
1744 * unreadelf() implicitly closes its fd, so only close it
1745 * when we are returning it in the non-ELF case
1746 */
1747 close(fd);
1748 }
1749
1750 return 0;
823} 1751}
824 1752
825/* scan a directory for ET_EXEC files and print when we find one */ 1753/* scan a directory for ET_EXEC files and print when we find one */
826static void scanelf_dir(const char *path) 1754static int scanelf_dirat(int dir_fd, const char *path)
827{ 1755{
828 register DIR *dir; 1756 register DIR *dir;
829 register struct dirent *dentry; 1757 register struct dirent *dentry;
830 struct stat st_top, st; 1758 struct stat st_top, st;
831 char buf[_POSIX_PATH_MAX]; 1759 char buf[__PAX_UTILS_PATH_MAX], *subpath;
832 size_t pathlen = 0, len = 0; 1760 size_t pathlen = 0, len = 0;
1761 int ret = 0;
1762 int subdir_fd;
833 1763
834 /* make sure path exists */ 1764 /* make sure path exists */
835 if (lstat(path, &st_top) == -1) { 1765 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
836 if (be_verbose > 2) printf("%s: does not exist\n", path); 1766 if (be_verbose > 2) printf("%s: does not exist\n", path);
837 return; 1767 return 1;
838 } 1768 }
839 1769
840 /* ok, if it isn't a directory, assume we can open it */ 1770 /* ok, if it isn't a directory, assume we can open it */
841 if (!S_ISDIR(st_top.st_mode)) { 1771 if (!S_ISDIR(st_top.st_mode))
842 scanelf_file(path); 1772 return scanelf_fileat(dir_fd, path, &st_top);
843 return;
844 }
845 1773
846 /* now scan the dir looking for fun stuff */ 1774 /* now scan the dir looking for fun stuff */
847 if ((dir = opendir(path)) == NULL) { 1775 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
848 warnf("could not opendir %s: %s", path, strerror(errno)); 1776 if (subdir_fd == -1)
1777 dir = NULL;
1778 else
1779 dir = fdopendir(subdir_fd);
1780 if (dir == NULL) {
1781 if (subdir_fd != -1)
1782 close(subdir_fd);
1783 else if (be_verbose > 2)
1784 printf("%s: skipping dir: %s\n", path, strerror(errno));
849 return; 1785 return 1;
850 } 1786 }
851 if (be_verbose) printf("%s: scanning dir\n", path); 1787 if (be_verbose > 1) printf("%s: scanning dir\n", path);
852 1788
853 pathlen = strlen(path); 1789 subpath = stpcpy(buf, path);
1790 if (subpath[-1] != '/')
1791 *subpath++ = '/';
1792 pathlen = subpath - buf;
854 while ((dentry = readdir(dir))) { 1793 while ((dentry = readdir(dir))) {
855 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1794 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
856 continue; 1795 continue;
1796
1797 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1798 continue;
1799
857 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1800 len = strlen(dentry->d_name);
858 if (len >= sizeof(buf)) { 1801 if (len + pathlen + 1 >= sizeof(buf)) {
859 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1802 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
860 (unsigned long)len, (unsigned long)sizeof(buf)); 1803 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
861 continue; 1804 continue;
862 } 1805 }
863 sprintf(buf, "%s/%s", path, dentry->d_name); 1806 memcpy(subpath, dentry->d_name, len);
864 if (lstat(buf, &st) != -1) { 1807 subpath[len] = '\0';
1808
865 if (S_ISREG(st.st_mode)) 1809 if (S_ISREG(st.st_mode))
866 scanelf_file(buf); 1810 ret = scanelf_fileat(dir_fd, buf, &st);
867 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1811 else if (dir_recurse && S_ISDIR(st.st_mode)) {
868 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1812 if (dir_crossmount || (st_top.st_dev == st.st_dev))
869 scanelf_dir(buf); 1813 ret = scanelf_dirat(dir_fd, buf);
870 }
871 } 1814 }
872 } 1815 }
873 closedir(dir); 1816 closedir(dir);
874}
875 1817
1818 return ret;
1819}
1820static int scanelf_dir(const char *path)
1821{
1822 return scanelf_dirat(root_fd, root_rel_path(path));
1823}
1824
876static int scanelf_from_file(char *filename) 1825static int scanelf_from_file(const char *filename)
877{ 1826{
878 FILE *fp = NULL; 1827 FILE *fp;
879 char *p; 1828 char *p, *path;
880 char path[_POSIX_PATH_MAX]; 1829 size_t len;
1830 int ret;
881 1831
882 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1832 if (strcmp(filename, "-") == 0)
883 fp = stdin; 1833 fp = stdin;
884 else if ((fp = fopen(filename, "r")) == NULL) 1834 else if ((fp = fopen(filename, "r")) == NULL)
885 return 1; 1835 return 1;
886 1836
887 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1837 path = NULL;
1838 len = 0;
1839 ret = 0;
1840 while (getline(&path, &len, fp) != -1) {
888 if ((p = strchr(path, '\n')) != NULL) 1841 if ((p = strchr(path, '\n')) != NULL)
889 *p = 0; 1842 *p = 0;
890 search_path = path; 1843 search_path = path;
891 scanelf_dir(path); 1844 ret = scanelf_dir(path);
892 } 1845 }
1846 free(path);
1847
893 if (fp != stdin) 1848 if (fp != stdin)
894 fclose(fp); 1849 fclose(fp);
1850
895 return 0; 1851 return ret;
896} 1852}
897 1853
898static void load_ld_so_conf() 1854#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1855
1856static int _load_ld_cache_config(const char *fname)
899{ 1857{
900 FILE *fp = NULL; 1858 FILE *fp = NULL;
901 char *p; 1859 char *p, *path;
902 char path[_POSIX_PATH_MAX]; 1860 size_t len;
903 int i = 0; 1861 int curr_fd = -1;
904 1862
905 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1863 fp = fopenat_r(root_fd, root_rel_path(fname));
1864 if (fp == NULL)
906 return; 1865 return -1;
907 1866
908 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1867 path = NULL;
909 if (*path != '/') 1868 len = 0;
910 continue; 1869 while (getline(&path, &len, fp) != -1) {
911
912 if ((p = strrchr(path, '\r')) != NULL) 1870 if ((p = strrchr(path, '\r')) != NULL)
913 *p = 0; 1871 *p = 0;
914 if ((p = strchr(path, '\n')) != NULL) 1872 if ((p = strchr(path, '\n')) != NULL)
915 *p = 0; 1873 *p = 0;
916 1874
917 ldpaths[i++] = xstrdup(path); 1875 /* recursive includes of the same file will make this segfault. */
1876 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1877 glob_t gl;
1878 size_t x;
1879 const char *gpath;
918 1880
919 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1881 /* re-use existing path buffer ... need to be creative */
920 break; 1882 if (path[8] != '/')
1883 gpath = memcpy(path + 3, "/etc/", 5);
1884 else
1885 gpath = path + 8;
1886 if (root_fd != AT_FDCWD) {
1887 if (curr_fd == -1) {
1888 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1889 if (fchdir(root_fd))
1890 errp("unable to change to root dir");
1891 }
1892 gpath = root_rel_path(gpath);
1893 }
1894
1895 if (glob(gpath, 0, NULL, &gl) == 0) {
1896 for (x = 0; x < gl.gl_pathc; ++x) {
1897 /* try to avoid direct loops */
1898 if (strcmp(gl.gl_pathv[x], fname) == 0)
1899 continue;
1900 _load_ld_cache_config(gl.gl_pathv[x]);
1901 }
1902 globfree(&gl);
1903 }
1904
1905 /* failed globs are ignored by glibc */
1906 continue;
921 } 1907 }
922 ldpaths[i] = NULL; 1908
1909 if (*path != '/')
1910 continue;
1911
1912 xarraypush_str(ldpaths, path);
1913 }
1914 free(path);
923 1915
924 fclose(fp); 1916 fclose(fp);
1917
1918 if (curr_fd != -1) {
1919 if (fchdir(curr_fd))
1920 {/* don't care */}
1921 close(curr_fd);
1922 }
1923
1924 return 0;
1925}
1926
1927#elif defined(__FreeBSD__) || defined(__DragonFly__)
1928
1929static int _load_ld_cache_config(const char *fname)
1930{
1931 FILE *fp = NULL;
1932 char *b = NULL, *p;
1933 struct elfhints_hdr hdr;
1934
1935 fp = fopenat_r(root_fd, root_rel_path(fname));
1936 if (fp == NULL)
1937 return -1;
1938
1939 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1940 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1941 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1942 {
1943 fclose(fp);
1944 return -1;
1945 }
1946
1947 b = xmalloc(hdr.dirlistlen + 1);
1948 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1949 fclose(fp);
1950 free(b);
1951 return -1;
1952 }
1953
1954 while ((p = strsep(&b, ":"))) {
1955 if (*p == '\0')
1956 continue;
1957 xarraypush_str(ldpaths, p);
1958 }
1959
1960 free(b);
1961 fclose(fp);
1962 return 0;
1963}
1964
1965#else
1966#ifdef __ELF__
1967#warning Cache config support not implemented for your target
1968#endif
1969static int _load_ld_cache_config(const char *fname)
1970{
1971 return 0;
1972}
1973#endif
1974
1975static void load_ld_cache_config(const char *fname)
1976{
1977 bool scan_l, scan_ul, scan_ull;
1978 size_t n;
1979 const char *ldpath;
1980
1981 _load_ld_cache_config(fname);
1982
1983 scan_l = scan_ul = scan_ull = false;
1984 array_for_each(ldpaths, n, ldpath) {
1985 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1986 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1987 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1988 }
1989
1990 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1991 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1992 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
925} 1993}
926 1994
927/* scan /etc/ld.so.conf for paths */ 1995/* scan /etc/ld.so.conf for paths */
928static void scanelf_ldpath() 1996static void scanelf_ldpath(void)
929{ 1997{
930 char scan_l, scan_ul, scan_ull; 1998 size_t n;
931 int i = 0; 1999 const char *ldpath;
932 2000
933 if (!ldpaths[0]) 2001 array_for_each(ldpaths, n, ldpath)
934 err("Unable to load any paths from ld.so.conf");
935
936 scan_l = scan_ul = scan_ull = 0;
937
938 while (ldpaths[i]) {
939 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
940 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
941 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
942 scanelf_dir(ldpaths[i]); 2002 scanelf_dir(ldpath);
943 ++i;
944 }
945
946 if (!scan_l) scanelf_dir("/lib");
947 if (!scan_ul) scanelf_dir("/usr/lib");
948 if (!scan_ull) scanelf_dir("/usr/local/lib");
949} 2003}
950 2004
951/* scan env PATH for paths */ 2005/* scan env PATH for paths */
952static void scanelf_envpath() 2006static void scanelf_envpath(void)
953{ 2007{
954 char *path, *p; 2008 char *path, *p;
955 2009
956 path = getenv("PATH"); 2010 path = getenv("PATH");
957 if (!path) 2011 if (!path)
964 } 2018 }
965 2019
966 free(path); 2020 free(path);
967} 2021}
968 2022
969 2023/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
970
971/* usage / invocation handling functions */
972#define PARSE_FLAGS "plRmyxetrnibSs:gN:TaqvF:f:o:BhV" 2024#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
973#define a_argument required_argument 2025#define a_argument required_argument
974static struct option const long_opts[] = { 2026static struct option const long_opts[] = {
975 {"path", no_argument, NULL, 'p'}, 2027 {"path", no_argument, NULL, 'p'},
976 {"ldpath", no_argument, NULL, 'l'}, 2028 {"ldpath", no_argument, NULL, 'l'},
2029 {"use-ldpath",no_argument, NULL, 129},
2030 {"root", a_argument, NULL, 128},
977 {"recursive", no_argument, NULL, 'R'}, 2031 {"recursive", no_argument, NULL, 'R'},
978 {"mount", no_argument, NULL, 'm'}, 2032 {"mount", no_argument, NULL, 'm'},
979 {"symlink", no_argument, NULL, 'y'}, 2033 {"symlink", no_argument, NULL, 'y'},
2034 {"archives", no_argument, NULL, 'A'},
2035 {"ldcache", no_argument, NULL, 'L'},
2036 {"fix", no_argument, NULL, 'X'},
2037 {"setpax", a_argument, NULL, 'z'},
980 {"pax", no_argument, NULL, 'x'}, 2038 {"pax", no_argument, NULL, 'x'},
981 {"header", no_argument, NULL, 'e'}, 2039 {"header", no_argument, NULL, 'e'},
982 {"textrel", no_argument, NULL, 't'}, 2040 {"textrel", no_argument, NULL, 't'},
983 {"rpath", no_argument, NULL, 'r'}, 2041 {"rpath", no_argument, NULL, 'r'},
984 {"needed", no_argument, NULL, 'n'}, 2042 {"needed", no_argument, NULL, 'n'},
985 {"interp", no_argument, NULL, 'i'}, 2043 {"interp", no_argument, NULL, 'i'},
986 {"bind", no_argument, NULL, 'b'}, 2044 {"bind", no_argument, NULL, 'b'},
987 {"soname", no_argument, NULL, 'S'}, 2045 {"soname", no_argument, NULL, 'S'},
988 {"symbol", a_argument, NULL, 's'}, 2046 {"symbol", a_argument, NULL, 's'},
2047 {"section", a_argument, NULL, 'k'},
989 {"lib", a_argument, NULL, 'N'}, 2048 {"lib", a_argument, NULL, 'N'},
990 {"gmatch", no_argument, NULL, 'g'}, 2049 {"gmatch", no_argument, NULL, 'g'},
991 {"textrels", no_argument, NULL, 'T'}, 2050 {"textrels", no_argument, NULL, 'T'},
2051 {"etype", a_argument, NULL, 'E'},
2052 {"bits", a_argument, NULL, 'M'},
2053 {"endian", no_argument, NULL, 'D'},
2054 {"osabi", no_argument, NULL, 'I'},
2055 {"eabi", no_argument, NULL, 'Y'},
2056 {"perms", a_argument, NULL, 'O'},
2057 {"size", no_argument, NULL, 'Z'},
992 {"all", no_argument, NULL, 'a'}, 2058 {"all", no_argument, NULL, 'a'},
993 {"quiet", no_argument, NULL, 'q'}, 2059 {"quiet", no_argument, NULL, 'q'},
994 {"verbose", no_argument, NULL, 'v'}, 2060 {"verbose", no_argument, NULL, 'v'},
995 {"format", a_argument, NULL, 'F'}, 2061 {"format", a_argument, NULL, 'F'},
996 {"from", a_argument, NULL, 'f'}, 2062 {"from", a_argument, NULL, 'f'},
997 {"file", a_argument, NULL, 'o'}, 2063 {"file", a_argument, NULL, 'o'},
2064 {"nocolor", no_argument, NULL, 'C'},
998 {"nobanner", no_argument, NULL, 'B'}, 2065 {"nobanner", no_argument, NULL, 'B'},
999 {"help", no_argument, NULL, 'h'}, 2066 {"help", no_argument, NULL, 'h'},
1000 {"version", no_argument, NULL, 'V'}, 2067 {"version", no_argument, NULL, 'V'},
1001 {NULL, no_argument, NULL, 0x0} 2068 {NULL, no_argument, NULL, 0x0}
1002}; 2069};
1003 2070
1004static const char *opts_help[] = { 2071static const char * const opts_help[] = {
1005 "Scan all directories in PATH environment", 2072 "Scan all directories in PATH environment",
1006 "Scan all directories in /etc/ld.so.conf", 2073 "Scan all directories in /etc/ld.so.conf",
2074 "Use ld.so.conf to show full path (use with -r/-n)",
2075 "Root directory (use with -l or -p)",
1007 "Scan directories recursively", 2076 "Scan directories recursively",
1008 "Don't recursively cross mount points", 2077 "Don't recursively cross mount points",
1009 "Don't scan symlinks\n", 2078 "Don't scan symlinks",
2079 "Scan archives (.a files)",
2080 "Utilize ld.so.cache to show full path (use with -r/-n)",
2081 "Try and 'fix' bad things (use with -r/-e)",
2082 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1010 "Print PaX markings", 2083 "Print PaX markings",
1011 "Print GNU_STACK/PT_LOAD markings", 2084 "Print GNU_STACK/PT_LOAD markings",
1012 "Print TEXTREL information", 2085 "Print TEXTREL information",
1013 "Print RPATH information", 2086 "Print RPATH information",
1014 "Print NEEDED information", 2087 "Print NEEDED information",
1015 "Print INTERP information", 2088 "Print INTERP information",
1016 "Print BIND information", 2089 "Print BIND information",
1017 "Print SONAME information", 2090 "Print SONAME information",
1018 "Find a specified symbol", 2091 "Find a specified symbol",
2092 "Find a specified section",
1019 "Find a specified library", 2093 "Find a specified library",
1020 "Use strncmp to match libraries. (use with -N)", 2094 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1021 "Locate cause of TEXTREL", 2095 "Locate cause of TEXTREL",
1022 "Print all scanned info (-x -e -t -r -b)\n", 2096 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2097 "Print only ELF files matching numeric bits",
2098 "Print Endianness",
2099 "Print OSABI",
2100 "Print EABI (EM_ARM Only)",
2101 "Print only ELF files matching octal permissions",
2102 "Print ELF file size",
2103 "Print all useful/simple info\n",
1023 "Only output 'bad' things", 2104 "Only output 'bad' things",
1024 "Be verbose (can be specified more than once)", 2105 "Be verbose (can be specified more than once)",
1025 "Use specified format for output", 2106 "Use specified format for output",
1026 "Read input stream from a filename", 2107 "Read input stream from a filename",
1027 "Write output stream to a filename", 2108 "Write output stream to a filename",
2109 "Don't emit color in output",
1028 "Don't display the header", 2110 "Don't display the header",
1029 "Print this help and exit", 2111 "Print this help and exit",
1030 "Print version and exit", 2112 "Print version and exit",
1031 NULL 2113 NULL
1032}; 2114};
1033 2115
1034/* display usage and exit */ 2116/* display usage and exit */
1035static void usage(int status) 2117static void usage(int status)
1036{ 2118{
1037 unsigned long i; 2119 const char a_arg[] = "<arg>";
2120 size_t a_arg_len = strlen(a_arg) + 2;
2121 size_t i;
2122 int optlen;
1038 printf("* Scan ELF binaries for stuff\n\n" 2123 printf("* Scan ELF binaries for stuff\n\n"
1039 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2124 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1040 printf("Options: -[%s]\n", PARSE_FLAGS); 2125 printf("Options: -[%s]\n", PARSE_FLAGS);
2126
2127 /* prescan the --long opt length to auto-align */
2128 optlen = 0;
1041 for (i = 0; long_opts[i].name; ++i) 2129 for (i = 0; long_opts[i].name; ++i) {
2130 int l = strlen(long_opts[i].name);
2131 if (long_opts[i].has_arg == a_argument)
2132 l += a_arg_len;
2133 optlen = max(l, optlen);
2134 }
2135
2136 for (i = 0; long_opts[i].name; ++i) {
2137 /* first output the short flag if it has one */
2138 if (long_opts[i].val > '~')
2139 printf(" ");
2140 else
2141 printf(" -%c, ", long_opts[i].val);
2142
2143 /* then the long flag */
1042 if (long_opts[i].has_arg == no_argument) 2144 if (long_opts[i].has_arg == no_argument)
1043 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2145 printf("--%-*s", optlen, long_opts[i].name);
1044 long_opts[i].name, opts_help[i]);
1045 else 2146 else
1046 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2147 printf("--%s %s %*s", long_opts[i].name, a_arg,
1047 long_opts[i].name, opts_help[i]); 2148 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1048 2149
1049 if (status != EXIT_SUCCESS) 2150 /* finally the help text */
1050 exit(status); 2151 printf("* %s\n", opts_help[i]);
2152 }
1051 2153
1052 puts("\nThe format modifiers for the -F option are:"); 2154 puts("\nFor more information, see the scanelf(1) manpage");
1053 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1054 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1055 puts(" i INTERP \tb BIND \ts symbol");
1056 puts(" N library \to Type \tT TEXTRELs");
1057 puts(" S SONAME");
1058 puts(" p filename (with search path removed)");
1059 puts(" f filename (short name/basename)");
1060 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1061
1062 exit(status); 2155 exit(status);
1063} 2156}
1064 2157
1065/* parse command line arguments and preform needed actions */ 2158/* parse command line arguments and preform needed actions */
2159#define do_pax_state(option, flag) \
2160 if (islower(option)) { \
2161 flags &= ~PF_##flag; \
2162 flags |= PF_NO##flag; \
2163 } else { \
2164 flags &= ~PF_NO##flag; \
2165 flags |= PF_##flag; \
2166 }
2167static void parse_delimited(array_t *arr, char *arg, const char *delim)
2168{
2169 char *ele = strtok(arg, delim);
2170 if (!ele) /* edge case: -s '' */
2171 xarraypush_str(arr, "");
2172 while (ele) {
2173 xarraypush_str(arr, ele);
2174 ele = strtok(NULL, delim);
2175 }
2176}
1066static void parseargs(int argc, char *argv[]) 2177static int parseargs(int argc, char *argv[])
1067{ 2178{
1068 int i; 2179 int i;
1069 char *from_file = NULL; 2180 const char *from_file = NULL;
2181 int ret = 0;
2182 char load_cache_config = 0;
1070 2183
1071 opterr = 0; 2184 opterr = 0;
1072 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2185 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1073 switch (i) { 2186 switch (i) {
1074 2187
1075 case 'V': 2188 case 'V':
1076 printf("pax-utils-%s: %s compiled %s\n%s\n" 2189 printf("pax-utils-%s: %s\n%s\n"
1077 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n", 2190 "%s written for Gentoo by <solar and vapier @ gentoo.org>\n",
1078 VERSION, __FILE__, __DATE__, rcsid, argv0); 2191 VERSION, __FILE__, rcsid, argv0);
1079 exit(EXIT_SUCCESS); 2192 exit(EXIT_SUCCESS);
1080 break; 2193 break;
1081 case 'h': usage(EXIT_SUCCESS); break; 2194 case 'h': usage(EXIT_SUCCESS); break;
1082 case 'f': 2195 case 'f':
1083 if (from_file) err("Don't specify -f twice"); 2196 if (from_file) warn("You prob don't want to specify -f twice");
1084 from_file = xstrdup(optarg); 2197 from_file = optarg;
2198 break;
2199 case 'E':
2200 /* historically, this was comma delimited */
2201 parse_delimited(match_etypes, optarg, ",");
2202 break;
2203 case 'M':
2204 match_bits = atoi(optarg);
2205 if (match_bits == 0) {
2206 if (strcmp(optarg, "ELFCLASS32") == 0)
2207 match_bits = 32;
2208 if (strcmp(optarg, "ELFCLASS64") == 0)
2209 match_bits = 64;
2210 }
2211 break;
2212 case 'O':
2213 if (sscanf(optarg, "%o", &match_perms) == -1)
2214 match_bits = 0;
1085 break; 2215 break;
1086 case 'o': { 2216 case 'o': {
1087 FILE *fp = NULL;
1088 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2217 if (freopen(optarg, "w", stdout) == NULL)
1089 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2218 errp("Could not freopen(%s)", optarg);
1090 SET_STDOUT(fp);
1091 break; 2219 break;
1092 } 2220 }
1093 2221 case 'k':
2222 xarraypush_str(find_section_arr, optarg);
2223 break;
2224 case 's':
2225 /* historically, this was comma delimited */
2226 parse_delimited(find_sym_arr, optarg, ",");
2227 break;
2228 case 'N':
2229 xarraypush_str(find_lib_arr, optarg);
2230 break;
1094 case 's': { 2231 case 'F': {
1095 size_t len; 2232 if (out_format) warn("You prob don't want to specify -F twice");
1096 if (find_sym) err("Don't specify -s twice"); 2233 out_format = optarg;
1097 find_sym = xstrdup(optarg);
1098 len = strlen(find_sym) + 1;
1099 versioned_symname = (char*)xmalloc(sizeof(char) * (len+1));
1100 sprintf(versioned_symname, "%s@", find_sym);
1101 break; 2234 break;
1102 } 2235 }
1103 case 'N': { 2236 case 'z': {
1104 if (find_lib) err("Don't specify -N twice"); 2237 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
1105 find_lib = xstrdup(optarg); 2238 size_t x;
2239
2240 for (x = 0; x < strlen(optarg); x++) {
2241 switch (optarg[x]) {
2242 case 'p':
2243 case 'P':
2244 do_pax_state(optarg[x], PAGEEXEC);
2245 break;
2246 case 's':
2247 case 'S':
2248 do_pax_state(optarg[x], SEGMEXEC);
2249 break;
2250 case 'm':
2251 case 'M':
2252 do_pax_state(optarg[x], MPROTECT);
2253 break;
2254 case 'e':
2255 case 'E':
2256 do_pax_state(optarg[x], EMUTRAMP);
2257 break;
2258 case 'r':
2259 case 'R':
2260 do_pax_state(optarg[x], RANDMMAP);
2261 break;
2262 case 'x':
2263 case 'X':
2264 do_pax_state(optarg[x], RANDEXEC);
2265 break;
2266 default:
2267 break;
2268 }
2269 }
2270 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2271 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2272 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2273 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2274 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2275 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2276 setpax = flags;
1106 break; 2277 break;
1107 } 2278 }
1108 2279 case 'Z': show_size = 1; break;
1109 case 'F': { 2280 case 'g': ++g_match; break;
1110 if (out_format) err("Don't specify -F twice"); 2281 case 'L': load_cache_config = use_ldcache = 1; break;
1111 out_format = xstrdup(optarg);
1112 break;
1113 }
1114
1115 case 'g': gmatch = 1;
1116 case 'y': scan_symlink = 0; break; 2282 case 'y': scan_symlink = 0; break;
2283 case 'A': scan_archives = 1; break;
2284 case 'C': color_init(true); break;
1117 case 'B': show_banner = 0; break; 2285 case 'B': show_banner = 0; break;
1118 case 'l': scan_ldpath = 1; break; 2286 case 'l': load_cache_config = scan_ldpath = 1; break;
1119 case 'p': scan_envpath = 1; break; 2287 case 'p': scan_envpath = 1; break;
1120 case 'R': dir_recurse = 1; break; 2288 case 'R': dir_recurse = 1; break;
1121 case 'm': dir_crossmount = 0; break; 2289 case 'm': dir_crossmount = 0; break;
2290 case 'X': ++fix_elf; break;
1122 case 'x': show_pax = 1; break; 2291 case 'x': show_pax = 1; break;
1123 case 'e': show_phdr = 1; break; 2292 case 'e': show_phdr = 1; break;
1124 case 't': show_textrel = 1; break; 2293 case 't': show_textrel = 1; break;
1125 case 'r': show_rpath = 1; break; 2294 case 'r': show_rpath = 1; break;
1126 case 'n': show_needed = 1; break; 2295 case 'n': show_needed = 1; break;
1127 case 'i': show_interp = 1; break; 2296 case 'i': show_interp = 1; break;
1128 case 'b': show_bind = 1; break; 2297 case 'b': show_bind = 1; break;
1129 case 'S': show_soname = 1; break; 2298 case 'S': show_soname = 1; break;
1130 case 'T': show_textrels = 1; break; 2299 case 'T': show_textrels = 1; break;
1131 case 'q': be_quiet = 1; break; 2300 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1132 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2301 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1133 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2302 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1134 2303 case 'D': show_endian = 1; break;
2304 case 'I': show_osabi = 1; break;
2305 case 'Y': show_eabi = 1; break;
2306 case 128:
2307 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2308 if (root_fd == -1)
2309 err("Could not open root: %s", optarg);
2310 break;
2311 case 129: load_cache_config = use_ldpath = 1; break;
1135 case ':': 2312 case ':':
1136 err("Option missing parameter\n"); 2313 err("Option '%c' is missing parameter", optopt);
1137 case '?': 2314 case '?':
1138 err("Unknown option\n"); 2315 err("Unknown option '%c' or argument missing", optopt);
1139 default: 2316 default:
1140 err("Unhandled option '%c'", i); 2317 err("Unhandled option '%c'; please report this", i);
1141 } 2318 }
1142 } 2319 }
2320 if (show_textrels && be_verbose)
2321 objdump = which("objdump", "OBJDUMP");
2322 /* precompile all the regexes */
2323 if (g_match) {
2324 regex_t preg;
2325 const char *this_sym;
2326 size_t n;
2327 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1143 2328
2329 array_for_each(find_sym_arr, n, this_sym) {
2330 /* see scanelf_match_symname for logic info */
2331 switch (this_sym[0]) {
2332 case '%':
2333 while (*(this_sym++))
2334 if (*this_sym == '%') {
2335 ++this_sym;
2336 break;
2337 }
2338 break;
2339 case '+':
2340 case '-':
2341 ++this_sym;
2342 break;
2343 }
2344 if (*this_sym == '*')
2345 ++this_sym;
2346
2347 ret = regcomp(&preg, this_sym, flags);
2348 if (ret) {
2349 char err[256];
2350 regerror(ret, &preg, err, sizeof(err));
2351 err("regcomp of %s failed: %s", this_sym, err);
2352 }
2353 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2354 }
2355 }
2356 /* flatten arrays for display */
2357 find_sym = array_flatten_str(find_sym_arr);
2358 find_lib = array_flatten_str(find_lib_arr);
2359 find_section = array_flatten_str(find_section_arr);
1144 /* let the format option override all other options */ 2360 /* let the format option override all other options */
1145 if (out_format) { 2361 if (out_format) {
1146 show_pax = show_phdr = show_textrel = show_rpath = \ 2362 show_pax = show_phdr = show_textrel = show_rpath = \
1147 show_needed = show_interp = show_bind = show_soname = \ 2363 show_needed = show_interp = show_bind = show_soname = \
1148 show_textrels = 0; 2364 show_textrels = show_perms = show_endian = show_size = \
2365 show_osabi = show_eabi = 0;
1149 for (i = 0; out_format[i]; ++i) { 2366 for (i = 0; out_format[i]; ++i) {
1150 if (!IS_MODIFIER(out_format[i])) continue; 2367 if (!IS_MODIFIER(out_format[i])) continue;
1151 2368
1152 switch (out_format[++i]) { 2369 switch (out_format[++i]) {
2370 case '+': break;
1153 case '%': break; 2371 case '%': break;
1154 case '#': break; 2372 case '#': break;
1155 case 'F': break; 2373 case 'F': break;
1156 case 'p': break; 2374 case 'p': break;
1157 case 'f': break; 2375 case 'f': break;
2376 case 'k': break;
1158 case 's': break; 2377 case 's': break;
1159 case 'N': break; 2378 case 'N': break;
1160 case 'o': break; 2379 case 'o': break;
2380 case 'a': break;
2381 case 'M': break;
2382 case 'Z': show_size = 1; break;
2383 case 'D': show_endian = 1; break;
2384 case 'I': show_osabi = 1; break;
2385 case 'Y': show_eabi = 1; break;
2386 case 'O': show_perms = 1; break;
1161 case 'x': show_pax = 1; break; 2387 case 'x': show_pax = 1; break;
1162 case 'e': show_phdr = 1; break; 2388 case 'e': show_phdr = 1; break;
1163 case 't': show_textrel = 1; break; 2389 case 't': show_textrel = 1; break;
1164 case 'r': show_rpath = 1; break; 2390 case 'r': show_rpath = 1; break;
1165 case 'n': show_needed = 1; break; 2391 case 'n': show_needed = 1; break;
1166 case 'i': show_interp = 1; break; 2392 case 'i': show_interp = 1; break;
1167 case 'b': show_bind = 1; break; 2393 case 'b': show_bind = 1; break;
1168 case 'S': show_soname = 1; break; 2394 case 'S': show_soname = 1; break;
1169 case 'T': show_textrels = 1; break; 2395 case 'T': show_textrels = 1; break;
1170 default: 2396 default:
1171 err("Invalid format specifier '%c' (byte %i)", 2397 err("invalid format specifier '%c' (byte %i)",
1172 out_format[i], i+1); 2398 out_format[i], i+1);
1173 } 2399 }
1174 } 2400 }
1175 2401
1176 /* construct our default format */ 2402 /* construct our default format */
1177 } else { 2403 } else {
1178 size_t fmt_len = 30; 2404 size_t fmt_len = 30;
1179 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2405 out_format = xmalloc(sizeof(char) * fmt_len);
2406 *out_format = '\0';
1180 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2407 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1181 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2408 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2409 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2410 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2411 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2412 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2413 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1182 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2414 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1183 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2415 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1184 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2416 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1185 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2417 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1186 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2418 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1187 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2419 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1188 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2420 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1189 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2421 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1190 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2422 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2423 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1191 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2424 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1192 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2425 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1193 } 2426 }
1194 if (be_verbose > 2) printf("Format: %s\n", out_format); 2427 if (be_verbose > 2) printf("Format: %s\n", out_format);
1195 2428
1196 /* now lets actually do the scanning */ 2429 /* now lets actually do the scanning */
1197 if (scan_ldpath || (show_rpath && be_quiet)) 2430 if (load_cache_config)
1198 load_ld_so_conf(); 2431 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1199 if (scan_ldpath) scanelf_ldpath(); 2432 if (scan_ldpath) scanelf_ldpath();
1200 if (scan_envpath) scanelf_envpath(); 2433 if (scan_envpath) scanelf_envpath();
2434 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2435 from_file = "-";
1201 if (from_file) { 2436 if (from_file) {
1202 scanelf_from_file(from_file); 2437 scanelf_from_file(from_file);
1203 free(from_file);
1204 from_file = *argv; 2438 from_file = *argv;
1205 } 2439 }
1206 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2440 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1207 err("Nothing to scan !?"); 2441 err("Nothing to scan !?");
1208 while (optind < argc) { 2442 while (optind < argc) {
1209 search_path = argv[optind++]; 2443 search_path = argv[optind++];
1210 scanelf_dir(search_path); 2444 ret = scanelf_dir(search_path);
1211 } 2445 }
1212 2446
2447#ifdef __PAX_UTILS_CLEANUP
1213 /* clean up */ 2448 /* clean up */
1214 if (find_sym) { 2449 xarrayfree(ldpaths);
2450 xarrayfree(find_sym_arr);
2451 xarrayfree(find_lib_arr);
2452 xarrayfree(find_section_arr);
1215 free(find_sym); 2453 free(find_sym);
1216 free(versioned_symname); 2454 free(find_lib);
2455 free(find_section);
2456 {
2457 size_t n;
2458 regex_t *preg;
2459 array_for_each(find_sym_regex_arr, n, preg)
2460 regfree(preg);
2461 xarrayfree(find_sym_regex_arr);
1217 } 2462 }
1218 if (find_lib) free(find_lib);
1219 if (out_format) free(out_format);
1220 for (i = 0; ldpaths[i]; ++i)
1221 free(ldpaths[i]);
1222}
1223 2463
2464 if (ldcache != 0)
2465 munmap(ldcache, ldcache_size);
2466#endif
1224 2467
1225
1226/* utility funcs */
1227static char *xstrdup(const char *s)
1228{
1229 char *ret = strdup(s);
1230 if (!ret) err("Could not strdup(): %s", strerror(errno));
1231 return ret; 2468 return ret;
1232} 2469}
1233 2470
1234static void *xmalloc(size_t size) 2471static char **get_split_env(const char *envvar)
1235{ 2472{
1236 void *ret = malloc(size); 2473 const char *delims = " \t\n";
1237 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size); 2474 char **envvals = NULL;
1238 return ret; 2475 char *env, *s;
1239} 2476 int nentry;
1240 2477
1241static void xstrcat(char **dst, const char *src, size_t *curr_len) 2478 if ((env = getenv(envvar)) == NULL)
1242{ 2479 return NULL;
1243 size_t new_len;
1244 2480
1245 new_len = strlen(*dst) + strlen(src); 2481 env = xstrdup(env);
1246 if (*curr_len <= new_len) { 2482 if (env == NULL)
1247 *curr_len = new_len + (*curr_len / 2); 2483 return NULL;
1248 *dst = realloc(*dst, *curr_len);
1249 if (!*dst)
1250 err("could not realloc %li bytes", (unsigned long)*curr_len);
1251 }
1252 2484
1253 strcat(*dst, src); 2485 s = strtok(env, delims);
1254} 2486 if (s == NULL) {
2487 free(env);
2488 return NULL;
2489 }
1255 2490
1256static inline void xchrcat(char **dst, const char append, size_t *curr_len) 2491 nentry = 0;
1257{ 2492 while (s != NULL) {
1258 static char my_app[2]; 2493 ++nentry;
1259 my_app[0] = append; 2494 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
1260 my_app[1] = '\0'; 2495 envvals[nentry-1] = s;
1261 xstrcat(dst, my_app, curr_len); 2496 s = strtok(NULL, delims);
1262} 2497 }
2498 envvals[nentry] = NULL;
1263 2499
2500 /* don't want to free(env) as it contains the memory that backs
2501 * the envvals array of strings */
2502 return envvals;
2503}
1264 2504
2505static void parseenv(void)
2506{
2507 color_init(false);
2508 qa_textrels = get_split_env("QA_TEXTRELS");
2509 qa_execstack = get_split_env("QA_EXECSTACK");
2510 qa_wx_load = get_split_env("QA_WX_LOAD");
2511}
2512
2513#ifdef __PAX_UTILS_CLEANUP
2514static void cleanup(void)
2515{
2516 free(out_format);
2517 free(qa_textrels);
2518 free(qa_execstack);
2519 free(qa_wx_load);
2520}
2521#endif
1265 2522
1266int main(int argc, char *argv[]) 2523int main(int argc, char *argv[])
1267{ 2524{
2525 int ret;
1268 if (argc < 2) 2526 if (argc < 2)
1269 usage(EXIT_FAILURE); 2527 usage(EXIT_FAILURE);
2528 parseenv();
1270 parseargs(argc, argv); 2529 ret = parseargs(argc, argv);
1271 fclose(stdout); 2530 fclose(stdout);
1272#ifdef __BOUNDS_CHECKING_ON 2531#ifdef __PAX_UTILS_CLEANUP
1273 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2532 cleanup();
2533 warn("The calls to add/delete heap should be off:\n"
2534 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2535 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1274#endif 2536#endif
1275 return EXIT_SUCCESS; 2537 return ret;
1276} 2538}
2539
2540/* Match filename against entries in matchlist, return TRUE
2541 * if the file is listed */
2542static int file_matches_list(const char *filename, char **matchlist)
2543{
2544 char **file;
2545 char *match;
2546 char buf[__PAX_UTILS_PATH_MAX];
2547
2548 if (matchlist == NULL)
2549 return 0;
2550
2551 for (file = matchlist; *file != NULL; file++) {
2552 if (search_path) {
2553 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2554 match = buf;
2555 } else {
2556 match = *file;
2557 }
2558 if (fnmatch(match, filename, 0) == 0)
2559 return 1;
2560 }
2561 return 0;
2562}

Legend:
Removed from v.1.88  
changed lines
  Added in v.1.274

  ViewVC Help
Powered by ViewVC 1.1.20