/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.235
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2007 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.235 2011/12/13 05:12:14 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.235 2011/12/13 05:12:14 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
67static char *find_lib = NULL; 49static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 53static char *out_format = NULL;
69static char *search_path = NULL; 54static char *search_path = NULL;
55static char fix_elf = 0;
70static char gmatch = 0; 56static char g_match = 0;
71static char printcache = 0; 57static char use_ldcache = 0;
72 58
59static char **qa_textrels = NULL;
60static char **qa_execstack = NULL;
61static char **qa_wx_load = NULL;
62static int root_fd = AT_FDCWD;
73 63
74caddr_t ldcache = 0; 64static int match_bits = 0;
65static unsigned int match_perms = 0;
66static void *ldcache = NULL;
75size_t ldcache_size = 0; 67static size_t ldcache_size = 0;
68static unsigned long setpax = 0UL;
76 69
70static int has_objdump = 0;
71
72/* find the path to a file by name */
73static int bin_in_path(const char *fname)
74{
75 char fullpath[__PAX_UTILS_PATH_MAX];
76 char *path, *p;
77
78 path = getenv("PATH");
79 if (!path)
80 return 0;
81
82 while ((p = strrchr(path, ':')) != NULL) {
83 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
84 *p = 0;
85 if (access(fullpath, R_OK) != -1)
86 return 1;
87 }
88
89 return 0;
90}
91
92static FILE *fopenat_r(int dir_fd, const char *path)
93{
94 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
95 if (fd == -1)
96 return NULL;
97 return fdopen(fd, "re");
98}
99
100static const char *root_rel_path(const char *path)
101{
102 /*
103 * openat() will ignore the dirfd if path starts with
104 * a /, so consume all of that noise
105 *
106 * XXX: we don't handle relative paths like ../ that
107 * break out of the --root option, but for now, just
108 * don't do that :P.
109 */
110 if (root_fd != AT_FDCWD) {
111 while (*path == '/')
112 ++path;
113 if (*path == '\0')
114 path = ".";
115 }
116
117 return path;
118}
119
120/* 1 on failure. 0 otherwise */
121static int rematch(const char *regex, const char *match, int cflags)
122{
123 regex_t preg;
124 int ret;
125
126 if ((match == NULL) || (regex == NULL))
127 return EXIT_FAILURE;
128
129 if ((ret = regcomp(&preg, regex, cflags))) {
130 char err[256];
131
132 if (regerror(ret, &preg, err, sizeof(err)))
133 fprintf(stderr, "regcomp failed: %s", err);
134 else
135 fprintf(stderr, "regcomp failed");
136
137 return EXIT_FAILURE;
138 }
139 ret = regexec(&preg, match, 0, NULL, 0);
140 regfree(&preg);
141
142 return ret;
143}
144
77/* sub-funcs for scanelf_file() */ 145/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 146static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 147{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 148 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
149
150 /* debug sections */
151 void *symtab = elf_findsecbyname(elf, ".symtab");
152 void *strtab = elf_findsecbyname(elf, ".strtab");
153 /* runtime sections */
154 void *dynsym = elf_findsecbyname(elf, ".dynsym");
155 void *dynstr = elf_findsecbyname(elf, ".dynstr");
156
81#define GET_SYMTABS(B) \ 157#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 158 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \
84 /* debug sections */ \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \
87 /* runtime sections */ \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \
90 if (symtab && dynsym) { \ 159 if (symtab && dynsym) { \
160 Elf ## B ## _Shdr *esymtab = symtab; \
161 Elf ## B ## _Shdr *edynsym = dynsym; \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 162 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 163 } else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 164 *sym = symtab ? symtab : dynsym; \
94 } \
95 if (strtab && dynstr) { \ 165 if (strtab && dynstr) { \
166 Elf ## B ## _Shdr *estrtab = strtab; \
167 Elf ## B ## _Shdr *edynstr = dynstr; \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 168 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 169 } else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 170 *str = strtab ? strtab : dynstr; \
99 } \
100 } 171 }
101 GET_SYMTABS(32) 172 GET_SYMTABS(32)
102 GET_SYMTABS(64) 173 GET_SYMTABS(64)
174
175 if (*sym && *str)
176 return;
177
178 /*
179 * damn, they're really going to make us work for it huh?
180 * reconstruct the section header info out of the dynamic
181 * tags so we can see what symbols this guy uses at runtime.
182 */
183#define GET_SYMTABS_DT(B) \
184 if (elf->elf_class == ELFCLASS ## B) { \
185 size_t i; \
186 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
187 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
188 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
189 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
190 Elf ## B ## _Dyn *dyn; \
191 Elf ## B ## _Off offset; \
192 \
193 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
194 vsym = vstr = vhash = vgnu_hash = 0; \
195 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
196 memset(&str_shdr, 0, sizeof(str_shdr)); \
197 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
198 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
199 continue; \
200 \
201 offset = EGET(phdr[i].p_offset); \
202 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
203 continue; \
204 \
205 dyn = DYN ## B (elf->vdata + offset); \
206 while (EGET(dyn->d_tag) != DT_NULL) { \
207 switch (EGET(dyn->d_tag)) { \
208 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
209 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
210 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
211 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
212 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
213 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
214 } \
215 ++dyn; \
216 } \
217 if (vsym && vstr) \
218 break; \
219 } \
220 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
221 return; \
222 \
223 /* calc offset into the ELF by finding the load addr of the syms */ \
224 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
225 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
226 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
227 offset = EGET(phdr[i].p_offset); \
228 \
229 if (EGET(phdr[i].p_type) != PT_LOAD) \
230 continue; \
231 \
232 if (vhash >= vaddr && vhash < vaddr + filesz) { \
233 /* Scan the hash table to see how many entries we have */ \
234 Elf32_Word max_sym_idx = 0; \
235 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
236 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
237 Elf32_Word nchains = EGET(hashtbl[1]); \
238 Elf32_Word *buckets = &hashtbl[2]; \
239 Elf32_Word *chains = &buckets[nbuckets]; \
240 Elf32_Word sym_idx; \
241 \
242 for (b = 0; b < nbuckets; ++b) { \
243 if (!buckets[b]) \
244 continue; \
245 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
246 if (max_sym_idx < sym_idx) \
247 max_sym_idx = sym_idx; \
248 } \
249 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
250 } \
251 \
252 if (vsym >= vaddr && vsym < vaddr + filesz) { \
253 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
254 *sym = &sym_shdr; \
255 } \
256 \
257 if (vstr >= vaddr && vstr < vaddr + filesz) { \
258 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
259 *str = &str_shdr; \
260 } \
261 } \
262 }
263 GET_SYMTABS_DT(32)
264 GET_SYMTABS_DT(64)
103} 265}
266
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 267static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 268{
106 static char ret[7]; 269 static char ret[7];
107 unsigned long i, shown; 270 unsigned long i, shown;
108 271
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 280 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 281 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 282 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 283 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 284 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 285 if (fix_elf && setpax) { \
286 /* set the paxctl flags */ \
287 ESET(phdr[i].p_flags, setpax); \
288 } \
289 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 290 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 291 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 292 *found_pax = 1; \
126 ++shown; \ 293 ++shown; \
127 break; \ 294 break; \
128 } \ 295 } \
129 } 296 }
130 SHOW_PAX(32) 297 SHOW_PAX(32)
131 SHOW_PAX(64) 298 SHOW_PAX(64)
299 }
300
301 if (fix_elf && setpax) {
302 /* set the chpax settings */
303 if (elf->elf_class == ELFCLASS32) {
304 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
305 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
306 } else {
307 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
308 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
309 }
132 } 310 }
133 311
134 /* fall back to EI_PAX if no PT_PAX was found */ 312 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 313 if (!*ret) {
136 static char *paxflags; 314 static char *paxflags;
150 328
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 329static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 330{
153 static char ret[12]; 331 static char ret[12];
154 char *found; 332 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 333 unsigned long i, shown, multi_stack, multi_relro, multi_load;
334 int max_pt_load;
157 335
158 if (!show_phdr) return NULL; 336 if (!show_phdr) return NULL;
159 337
160 memcpy(ret, "--- --- ---\0", 12); 338 memcpy(ret, "--- --- ---\0", 12);
161 339
162 shown = 0; 340 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 341 multi_stack = multi_relro = multi_load = 0;
342 max_pt_load = elf_max_pt_load(elf);
164 343
344#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 345#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 346 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 347 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 348 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 349 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 350 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 351 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 352 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 353 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
354 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 355 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
356 if (file_matches_list(elf->filename, qa_execstack)) \
357 continue; \
175 found = found_phdr; \ 358 found = found_phdr; \
176 offset = 0; \ 359 offset = 0; \
177 check_flags = PF_X; \ 360 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 361 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
362 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 363 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 364 found = found_relro; \
181 offset = 4; \ 365 offset = 4; \
182 check_flags = PF_X; \ 366 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 367 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 368 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
369 if (multi_load++ > max_pt_load) \
370 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
371 if (file_matches_list(elf->filename, qa_wx_load)) \
372 continue; \
185 found = found_load; \ 373 found = found_load; \
186 offset = 8; \ 374 offset = 8; \
187 check_flags = PF_W|PF_X; \ 375 check_flags = PF_W|PF_X; \
188 } else \ 376 } else \
189 continue; \ 377 continue; \
190 flags = EGET(phdr[i].p_flags); \ 378 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 379 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 380 continue; \
381 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
382 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
383 ret[3] = ret[7] = '!'; \
384 flags = EGET(phdr[i].p_flags); \
385 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 386 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 387 *found = 1; \
195 ++shown; \ 388 ++shown; \
196 } \ 389 } \
197 } else if (elf->shdr != NULL) { \ 390 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 391 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 392 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 393 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
394 char *str; \
395 if ((void*)strtbl > elf->data_end) \
396 goto skip_this_shdr##B; \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 397 check_flags = SHF_WRITE|SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 398 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 399 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 400 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 401 str = elf->data + offset; \
402 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
403 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 404 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 405 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 406 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 407 continue; \
210 ++*found_phdr; \ 408 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 412 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 413 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 414 break; \
217 } \ 415 } \
218 } \ 416 } \
417 skip_this_shdr##B: \
219 if (!multi_stack) { \ 418 if (!multi_stack) { \
419 if (file_matches_list(elf->filename, qa_execstack)) \
420 return NULL; \
220 *found_phdr = 1; \ 421 *found_phdr = 1; \
221 shown = 1; \ 422 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 423 memcpy(ret, "!WX", 3); \
223 } \ 424 } \
224 } \ 425 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 430 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 431 return NULL;
231 else 432 else
232 return ret; 433 return ret;
233} 434}
435
436/*
437 * See if this ELF contains a DT_TEXTREL tag in any of its
438 * PT_DYNAMIC sections.
439 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 440static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 441{
236 static const char *ret = "TEXTREL"; 442 static const char *ret = "TEXTREL";
237 unsigned long i; 443 unsigned long i;
238 444
239 if (!show_textrel && !show_textrels) return NULL; 445 if (!show_textrel && !show_textrels) return NULL;
446
447 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 448
241 if (elf->phdr) { 449 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 450#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 451 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 452 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 453 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 454 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 455 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 456 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 457 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 458 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 459 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 460 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 461 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 462 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 463 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 464 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 465 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 474 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 475 return NULL;
268 else 476 else
269 return " - "; 477 return " - ";
270} 478}
479
480/*
481 * Scan the .text section to see if there are any relocations in it.
482 * Should rewrite this to check PT_LOAD sections that are marked
483 * Executable rather than the section named '.text'.
484 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 485static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 486{
273 unsigned long s, r, rmax; 487 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 488 void *symtab_void, *strtab_void, *text_void;
275 489
296 Elf ## B ## _Rela *rela; \ 510 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 511 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 512 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 513 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 514 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 515 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 516 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 517 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 518 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 519 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 520 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 521 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 522 } else \
309 continue; \ 523 continue; \
310 /* now see if any of the relocs are in the .text */ \ 524 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 525 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 540 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 541 if (be_verbose <= 2) continue; \
328 } else \ 542 } else \
329 *found_textrels = 1; \ 543 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 544 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 545 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
546 if ((void*)sym > elf->data_end) { \
547 warn("%s: corrupt ELF symbol", elf->filename); \
548 continue; \
549 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 550 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 551 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 552 sym += sym_max; \
335 else \ 553 else \
336 sym = NULL; \ 554 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 555 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 556 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 557 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 558 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 559 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 560 else \
343 printf("(memory/fake?)"); \ 561 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 562 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 563 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 564 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 565 func = NULL; \
348 offset_tmp = 0; \ 566 offset_tmp = 0; \
349 while (sym_max--) { \ 567 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 568 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 569 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 570 offset_tmp = EGET(sym->st_value); \
353 } \ 571 } \
354 ++sym; \ 572 ++sym; \
355 } \ 573 } \
356 printf(" in "); \ 574 printf(" in "); \
357 if (func && func->st_name) \ 575 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 576 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
577 if (r_offset > EGET(func->st_size)) \
578 printf("(optimized out: previous %s)", func_name); \
359 else \ 579 else \
360 printf("(NULL: fake?)"); \ 580 printf("%s", func_name); \
581 } else \
582 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 583 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
584 if (be_verbose && has_objdump) { \
585 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
586 char *sysbuf; \
587 size_t syslen; \
588 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
589 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
590 sysbuf = xmalloc(syslen); \
591 if (end_addr < r_offset) \
592 /* not uncommon when things are optimized out */ \
593 end_addr = r_offset + 0x100; \
594 snprintf(sysbuf, syslen, sysfmt, \
595 (unsigned long)offset_tmp, \
596 (unsigned long)end_addr, \
597 elf->filename, \
598 (unsigned long)r_offset); \
599 fflush(stdout); \
600 if (system(sysbuf)) /* don't care */; \
601 fflush(stdout); \
602 free(sysbuf); \
603 } \
362 } \ 604 } \
363 } } 605 } }
364 SHOW_TEXTRELS(32) 606 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 607 SHOW_TEXTRELS(64)
366 } 608 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 610 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 611
370 return NULL; 612 return NULL;
371} 613}
372 614
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 615static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
616{
375 struct stat st; 617 struct stat st;
376 switch (*item) { 618 switch (*item) {
377 case '/': break; 619 case '/': break;
378 case '.': 620 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 621 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 622 break;
623 case ':':
381 case '\0': 624 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 625 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 626 break;
384 case '$': 627 case '$':
385 if (fstat(elf->fd, &st) != -1) 628 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 629 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 630 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 631 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 632 break;
390 default: 633 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 634 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 635 break;
393 } 636 }
394} 637}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 638static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 639{
397 unsigned long i, s; 640 unsigned long i;
398 char *rpath, *runpath, **r; 641 char *rpath, *runpath, **r;
399 void *strtbl_void; 642 void *strtbl_void;
400 643
401 if (!show_rpath) return; 644 if (!show_rpath) return;
402 645
413 Elf ## B ## _Off offset; \ 656 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 657 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 658 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 659 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 660 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 661 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 662 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 663 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 664 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 665 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 666 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 667 if (word == DT_RPATH) { \
425 r = &rpath; \ 668 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 669 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 670 r = &runpath; \
431 } \ 674 } \
432 /* Verify the memory is somewhat sane */ \ 675 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 676 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 677 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 678 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 679 *r = elf->data + offset; \
680 /* cache the length in case we need to nuke this section later on */ \
681 if (fix_elf) \
682 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 683 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 684 if (be_quiet) { \
439 size_t len; \ 685 size_t len; \
440 char *start, *end; \ 686 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 687 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 688 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 689 start = *r; \
444 /* scan each path in : delimited list */ \ 690 /* scan each path in : delimited list */ \
445 while (start) { \ 691 while (start) { \
446 rpath_security_checks(elf, start); \ 692 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 693 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 694 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 695 if (use_ldcache) { \
696 size_t n; \
697 const char *ldpath; \
698 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 699 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 700 *r = end; \
701 /* corner case ... if RPATH reads "/usr/lib:", we want \
702 * to show ':' rather than '' */ \
703 if (end && end[1] != '\0') \
704 (*r)++; \
452 break; \ 705 break; \
453 } \ 706 } \
454 } \ 707 } \
455 if (!*r || !ldpaths[s] || !end) \ 708 if (!*r || !end) \
456 start = NULL; \ 709 break; \
457 else \ 710 else \
458 start = start + len + 1; \ 711 start = start + len + 1; \
459 } \ 712 } \
460 } \ 713 } \
714 if (*r) { \
715 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
716 /* just nuke it */ \
717 nuke_it##B: \
718 memset(*r, 0x00, offset); \
719 *r = NULL; \
720 ESET(dyn->d_tag, DT_DEBUG); \
721 ESET(dyn->d_un.d_ptr, 0); \
722 } else if (fix_elf) { \
723 /* try to clean "bad" paths */ \
724 size_t len, tmpdir_len; \
725 char *start, *end; \
726 const char *tmpdir; \
727 start = *r; \
728 tmpdir = (getenv("TMPDIR") ? : "."); \
729 tmpdir_len = strlen(tmpdir); \
730 while (1) { \
731 end = strchr(start, ':'); \
732 if (start == end) { \
733 eat_this_path##B: \
734 len = strlen(end); \
735 memmove(start, end+1, len); \
736 start[len-1] = '\0'; \
737 end = start - 1; \
738 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
739 if (!end) { \
740 if (start == *r) \
741 goto nuke_it##B; \
742 *--start = '\0'; \
743 } else \
744 goto eat_this_path##B; \
745 } \
746 if (!end) \
747 break; \
748 start = end + 1; \
749 } \
750 if (**r == '\0') \
751 goto nuke_it##B; \
752 } \
753 if (*r) \
461 if (*r) *found_rpath = 1; \ 754 *found_rpath = 1; \
755 } \
462 } \ 756 } \
463 ++dyn; \ 757 ++dyn; \
464 } \ 758 } \
465 } } 759 } }
466 SHOW_RPATH(32) 760 SHOW_RPATH(32)
488 782
489#define LDSO_CACHE_MAGIC "ld.so-" 783#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 784#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 785#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 786#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
787#define FLAG_ANY -1
788#define FLAG_TYPE_MASK 0x00ff
789#define FLAG_LIBC4 0x0000
790#define FLAG_ELF 0x0001
791#define FLAG_ELF_LIBC5 0x0002
792#define FLAG_ELF_LIBC6 0x0003
793#define FLAG_REQUIRED_MASK 0xff00
794#define FLAG_SPARC_LIB64 0x0100
795#define FLAG_IA64_LIB64 0x0200
796#define FLAG_X8664_LIB64 0x0300
797#define FLAG_S390_LIB64 0x0400
798#define FLAG_POWERPC_LIB64 0x0500
799#define FLAG_MIPS64_LIBN32 0x0600
800#define FLAG_MIPS64_LIBN64 0x0700
493 801
494static char *lookup_cache_lib(char *); 802#if defined(__GLIBC__) || defined(__UCLIBC__)
803
495static char *lookup_cache_lib(char *fname) 804static char *lookup_cache_lib(elfobj *elf, char *fname)
496{ 805{
497 int fd = 0; 806 int fd;
498 char *strs; 807 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 808 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 809 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 810 struct stat st;
502 811
503 typedef struct { 812 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 813 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 814 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 815 int nlibs;
507 } header_t; 816 } header_t;
817 header_t *header;
508 818
509 typedef struct { 819 typedef struct {
510 int flags; 820 int flags;
511 int sooffset; 821 int sooffset;
512 int liboffset; 822 int liboffset;
513 } libentry_t; 823 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 824 libentry_t *libent;
517 825
518 if (fname == NULL) 826 if (fname == NULL)
519 return NULL; 827 return NULL;
520 828
521 if (ldcache == 0) { 829 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 830 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 831 return NULL;
524 /* save the cache size for latter unmapping */ 832
833 fd = openat(root_fd, cachefile, O_RDONLY);
834 if (fd == -1)
835 return NULL;
836
837 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 838 ldcache_size = st.st_size;
839 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
840 close(fd);
526 841
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 842 if (ldcache == MAP_FAILED) {
843 ldcache = NULL;
528 return NULL; 844 return NULL;
845 }
529 846
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 847 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
848 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
849 {
850 munmap(ldcache, ldcache_size);
851 ldcache = NULL;
533 return NULL; 852 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 853 }
854 } else
855 header = ldcache;
538 856
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 857 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 858 strs = (char *) &libent[header->nlibs];
542 859
543 for (fd = 0; fd < header->nlibs; fd++) { 860 for (fd = 0; fd < header->nlibs; ++fd) {
861 /* This should be more fine grained, but for now we assume that
862 * diff arches will not be cached together, and we ignore the
863 * the different multilib mips cases.
864 */
865 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
866 continue;
867 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
868 continue;
869
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 870 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 871 continue;
872
873 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 874 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
875 break;
547 } 876 }
877
548 return buf; 878 return buf;
549} 879}
550 880
881#elif defined(__NetBSD__)
882static char *lookup_cache_lib(elfobj *elf, char *fname)
883{
884 static char buf[__PAX_UTILS_PATH_MAX] = "";
885 static struct stat st;
886 size_t n;
887 char *ldpath;
888
889 array_for_each(ldpath, n, ldpath) {
890 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
891 continue; /* if the pathname is too long, or something went wrong, ignore */
892
893 if (stat(buf, &st) != 0)
894 continue; /* if the lib doesn't exist in *ldpath, look further */
895
896 /* NetBSD doesn't actually do sanity checks, it just loads the file
897 * and if that doesn't work, continues looking in other directories.
898 * This cannot easily be safely emulated, unfortunately. For now,
899 * just assume that if it exists, it's a valid library. */
900
901 return buf;
902 }
903
904 /* not found in any path */
905 return NULL;
906}
907#else
908#ifdef __ELF__
909#warning Cache support not implemented for your target
910#endif
911static char *lookup_cache_lib(elfobj *elf, char *fname)
912{
913 return NULL;
914}
915#endif
551 916
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 917static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 918{
554 unsigned long i; 919 unsigned long i;
555 char *needed; 920 char *needed;
556 void *strtbl_void; 921 void *strtbl_void;
557 char *p; 922 char *p;
558 923
924 /*
925 * -n -> op==0 -> print all
926 * -N -> op==1 -> print requested
927 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 928 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
929 return NULL;
560 930
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 931 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 932
563 if (elf->phdr && strtbl_void) { 933 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 934#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 936 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 937 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 938 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 939 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 940 Elf ## B ## _Off offset; \
941 size_t matched = 0; \
942 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 943 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 944 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
945 continue; \
573 offset = EGET(phdr[i].p_offset); \ 946 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 947 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
948 continue; \
949 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 950 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 951 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 952 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 953 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 954 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 955 ++dyn; \
581 continue; \ 956 continue; \
582 } \ 957 } \
583 needed = (char*)(elf->data + offset); \ 958 needed = elf->data + offset; \
584 if (op == 0) { \ 959 if (op == 0) { \
960 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 961 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 962 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 963 if (use_ldcache) \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 964 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
589 needed = p; \ 965 needed = p; \
590 xstrcat(ret, needed, ret_len); \ 966 xstrcat(ret, needed, ret_len); \
591 } \ 967 } \
592 *found_needed = 1; \ 968 *found_needed = 1; \
593 } else { \ 969 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 970 /* -N -> print matching entries */ \
971 size_t n; \
972 const char *find_lib_name; \
973 \
974 array_for_each(find_lib_arr, n, find_lib_name) \
975 if (!strcmp(find_lib_name, needed)) \
976 ++matched; \
977 \
978 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 979 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 980 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 981 } \
598 } \ 982 } \
599 } \ 983 } \
600 ++dyn; \ 984 ++dyn; \
601 } \ 985 } \
630} 1014}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1015static char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1016{
633 unsigned long i; 1017 unsigned long i;
634 struct stat s; 1018 struct stat s;
1019 char dynamic = 0;
635 1020
636 if (!show_bind) return NULL; 1021 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1022 if (!elf->phdr) return NULL;
638 1023
639#define SHOW_BIND(B) \ 1024#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1026 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1027 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1028 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1029 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1030 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1031 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1032 dynamic = 1; \
647 offset = EGET(phdr[i].p_offset); \ 1033 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1034 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1035 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1036 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1037 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1038 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1039 { \
654 if (be_quiet) return NULL; \ 1040 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1048 SHOW_BIND(32)
663 SHOW_BIND(64) 1049 SHOW_BIND(64)
664 1050
665 if (be_wewy_wewy_quiet) return NULL; 1051 if (be_wewy_wewy_quiet) return NULL;
666 1052
1053 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1054 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1055 return NULL;
669 } else { 1056 } else {
670 *found_bind = 1; 1057 *found_bind = 1;
671 return (char *) "LAZY"; 1058 return (char *)(dynamic ? "LAZY" : "STATIC");
672 } 1059 }
673} 1060}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1061static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1062{
676 unsigned long i; 1063 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1075 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1076 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1077 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1078 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1079 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1080 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1081 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1082 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1083 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1084 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1085 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1086 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1087 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1088 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1089 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1090 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1091 ++dyn; \
705 continue; \ 1092 continue; \
706 } \ 1093 } \
707 soname = (char*)(elf->data + offset); \ 1094 soname = elf->data + offset; \
708 *found_soname = 1; \ 1095 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1096 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1097 } \
711 ++dyn; \ 1098 ++dyn; \
712 } \ 1099 } \
715 SHOW_SONAME(64) 1102 SHOW_SONAME(64)
716 } 1103 }
717 1104
718 return NULL; 1105 return NULL;
719} 1106}
1107
1108/*
1109 * We support the symbol form:
1110 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1111 * If the symbol name is empty, then all symbols are matched.
1112 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1113 * Do not rely on this output format at all.
1114 * Otherwise the symbol name is used to search (either regex or string compare).
1115 * If the first char of the symbol name is a plus ("+"), then only match
1116 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1117 * Putting modifiers in between the percent signs allows for more in depth
1118 * filters. There are groups of modifiers. If you don't specify a member
1119 * of a group, then all types in that group are matched. The current
1120 * groups and their types are:
1121 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f SST_FILE:F
1122 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1123 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1124 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1125 * You can search for multiple symbols at once by seperating with a comma (",").
1126 *
1127 * Some examples:
1128 * ELFs with a weak function "foo":
1129 * scanelf -s %wf%foo <ELFs>
1130 * ELFs that define the symbol "main":
1131 * scanelf -s +main <ELFs>
1132 * scanelf -s %d%main <ELFs>
1133 * ELFs that refer to the undefined symbol "brk":
1134 * scanelf -s -brk <ELFs>
1135 * scanelf -s %u%brk <ELFs>
1136 * All global defined objects in an ELF:
1137 * scanelf -s %ogd% <ELF>
1138 */
1139static void
1140scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1141 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1142{
1143 char *this_sym, *next_sym, saved = saved;
1144
1145 /* allow the user to specify a comma delimited list of symbols to search for */
1146 next_sym = NULL;
1147 do {
1148 bool inc_notype, inc_object, inc_func, inc_file,
1149 inc_local, inc_global, inc_weak,
1150 inc_def, inc_undef, inc_abs, inc_common;
1151
1152 if (next_sym) {
1153 next_sym[-1] = saved;
1154 this_sym = next_sym;
1155 } else
1156 this_sym = find_sym;
1157 if ((next_sym = strchr(this_sym, ','))) {
1158 /* make parsing easier by killing the comma temporarily */
1159 saved = *next_sym;
1160 *next_sym = '\0';
1161 next_sym += 1;
1162 }
1163
1164 /* symbol selection! */
1165 inc_notype = inc_object = inc_func = inc_file = \
1166 inc_local = inc_global = inc_weak = \
1167 inc_def = inc_undef = inc_abs = inc_common = \
1168 (*this_sym != '%');
1169
1170 /* parse the contents of %...% */
1171 if (!inc_notype) {
1172 while (*(this_sym++)) {
1173 if (*this_sym == '%') {
1174 ++this_sym;
1175 break;
1176 }
1177 switch (*this_sym) {
1178 case 'n': inc_notype = true; break;
1179 case 'o': inc_object = true; break;
1180 case 'f': inc_func = true; break;
1181 case 'F': inc_file = true; break;
1182 case 'l': inc_local = true; break;
1183 case 'g': inc_global = true; break;
1184 case 'w': inc_weak = true; break;
1185 case 'd': inc_def = true; break;
1186 case 'u': inc_undef = true; break;
1187 case 'a': inc_abs = true; break;
1188 case 'c': inc_common = true; break;
1189 default: err("invalid symbol selector '%c'", *this_sym);
1190 }
1191 }
1192
1193 /* If no types are matched, not match all */
1194 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1195 inc_notype = inc_object = inc_func = inc_file = true;
1196 if (!inc_local && !inc_global && !inc_weak)
1197 inc_local = inc_global = inc_weak = true;
1198 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1199 inc_def = inc_undef = inc_abs = inc_common = true;
1200
1201 /* backwards compat for defined/undefined short hand */
1202 } else if (*this_sym == '+') {
1203 inc_undef = false;
1204 ++this_sym;
1205 } else if (*this_sym == '-') {
1206 inc_def = inc_abs = inc_common = false;
1207 ++this_sym;
1208 }
1209
1210 /* filter symbols */
1211 if ((!inc_notype && stt == STT_NOTYPE) || \
1212 (!inc_object && stt == STT_OBJECT) || \
1213 (!inc_func && stt == STT_FUNC ) || \
1214 (!inc_file && stt == STT_FILE ) || \
1215 (!inc_local && stb == STB_LOCAL ) || \
1216 (!inc_global && stb == STB_GLOBAL) || \
1217 (!inc_weak && stb == STB_WEAK ) || \
1218 (!inc_def && shn && shn < SHN_LORESERVE) || \
1219 (!inc_undef && shn == SHN_UNDEF ) || \
1220 (!inc_abs && shn == SHN_ABS ) || \
1221 (!inc_common && shn == SHN_COMMON))
1222 continue;
1223
1224 if (*this_sym == '*') {
1225 /* a "*" symbol gets you debug output */
1226 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1227 ((*found_sym == 0) ? "\n\t" : "\t"),
1228 elf->base_filename,
1229 size,
1230 get_elfstttype(stt),
1231 get_elfstbtype(stb),
1232 get_elfshntype(shn),
1233 symname);
1234 goto matched;
1235
1236 } else {
1237 if (g_match) {
1238 /* regex match the symbol */
1239 if (rematch(this_sym, symname, REG_EXTENDED) != 0)
1240 continue;
1241
1242 } else if (*this_sym) {
1243 /* give empty symbols a "pass", else do a normal compare */
1244 const size_t len = strlen(this_sym);
1245 if (!(strncmp(this_sym, symname, len) == 0 &&
1246 /* Accept unversioned symbol names */
1247 (symname[len] == '\0' || symname[len] == '@')))
1248 continue;
1249 }
1250
1251 if (be_semi_verbose) {
1252 char buf[1024];
1253 snprintf(buf, sizeof(buf), "%lX %s %s",
1254 size,
1255 get_elfstttype(stt),
1256 this_sym);
1257 *ret = xstrdup(buf);
1258 } else {
1259 if (*ret) xchrcat(ret, ',', ret_len);
1260 xstrcat(ret, symname, ret_len);
1261 }
1262
1263 goto matched;
1264 }
1265 } while (next_sym);
1266
1267 return;
1268
1269 matched:
1270 *found_sym = 1;
1271 if (next_sym)
1272 next_sym[-1] = saved;
1273}
1274
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1275static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1276{
722 unsigned long i;
723 char *ret; 1277 char *ret;
724 void *symtab_void, *strtab_void; 1278 void *symtab_void, *strtab_void;
725 1279
726 if (!find_sym) return NULL; 1280 if (!find_sym) return NULL;
727 ret = find_sym; 1281 ret = NULL;
728 1282
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1283 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1284
731 if (symtab_void && strtab_void) { 1285 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1286#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1287 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1288 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1289 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1290 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1291 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1292 char *symname; \
1293 size_t ret_len = 0; \
1294 if (cnt) \
1295 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1296 for (i = 0; i < cnt; ++i) { \
1297 if ((void*)sym > elf->data_end) { \
1298 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1299 goto break_out; \
1300 } \
740 if (sym->st_name) { \ 1301 if (sym->st_name) { \
1302 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1303 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1304 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1305 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1306 ++sym; \
745 elf->base_filename, \ 1307 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1308 } \
1309 scanelf_match_symname(elf, found_sym, \
1310 &ret, &ret_len, symname, \
1311 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1312 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1313 EGET(sym->st_shndx), \
1314 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1315 EGET(sym->st_size)); \
766 } \ 1316 } \
767 ++sym; \ 1317 ++sym; \
768 } } 1318 } \
1319 }
769 FIND_SYM(32) 1320 FIND_SYM(32)
770 FIND_SYM(64) 1321 FIND_SYM(64)
771 } 1322 }
772 1323
773break_out: 1324break_out:
776 if (*find_sym != '*' && *found_sym) 1327 if (*find_sym != '*' && *found_sym)
777 return ret; 1328 return ret;
778 if (be_quiet) 1329 if (be_quiet)
779 return NULL; 1330 return NULL;
780 else 1331 else
781 return (char *)" - "; 1332 return " - ";
782} 1333}
1334
1335static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1336{
1337 if (!find_section)
1338 return NULL;
1339
1340#define FIND_SECTION(B) \
1341 if (elf->elf_class == ELFCLASS ## B) { \
1342 size_t matched, n; \
1343 int invert; \
1344 const char *section_name; \
1345 Elf ## B ## _Shdr *section; \
1346 \
1347 matched = 0; \
1348 array_for_each(find_section_arr, n, section_name) { \
1349 invert = (*section_name == '!' ? 1 : 0); \
1350 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1351 if ((section == NULL && invert) || (section != NULL && !invert)) \
1352 ++matched; \
1353 } \
1354 \
1355 if (matched == array_cnt(find_section_arr)) \
1356 *found_section = 1; \
1357 }
1358 FIND_SECTION(32)
1359 FIND_SECTION(64)
1360
1361 if (be_wewy_wewy_quiet)
1362 return NULL;
1363
1364 if (*found_section)
1365 return find_section;
1366
1367 if (be_quiet)
1368 return NULL;
1369 else
1370 return " - ";
1371}
1372
783/* scan an elf file and show all the fun stuff */ 1373/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1374#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1375static int scanelf_elfobj(elfobj *elf)
786{ 1376{
787 unsigned long i; 1377 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1378 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1379 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1380 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1381 static char *out_buffer = NULL;
794 static size_t out_len; 1382 static size_t out_len;
795 1383
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1384 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1385 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1386 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1387
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1388 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1389 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1390 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1391 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1392 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1393 printf("%s: scanning file\n", elf->filename);
827 1394
828 /* init output buffer */ 1395 /* init output buffer */
829 if (!out_buffer) { 1396 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1397 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1398 out_buffer = xmalloc(out_len);
832 } 1399 }
833 *out_buffer = '\0'; 1400 *out_buffer = '\0';
834 1401
835 /* show the header */ 1402 /* show the header */
836 if (!be_quiet && show_banner) { 1403 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1404 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1405 if (!IS_MODIFIER(out_format[i])) continue;
839 1406
840 switch (out_format[++i]) { 1407 switch (out_format[++i]) {
1408 case '+': break;
841 case '%': break; 1409 case '%': break;
842 case '#': break; 1410 case '#': break;
843 case 'F': 1411 case 'F':
844 case 'p': 1412 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1413 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1414 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1415 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1416 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1417 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1418 case 'r': prints("RPATH "); break;
1419 case 'M': prints("CLASS "); break;
851 case 'n': prints("NEEDED "); break; 1420 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1421 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1422 case 'b': prints("BIND "); break;
1423 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1424 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1425 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1426 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1427 case 'T': prints("TEXTRELS "); break;
1428 case 'k': prints("SECTION "); break;
1429 case 'a': prints("ARCH "); break;
1430 case 'I': prints("OSABI "); break;
1431 case 'Y': prints("EABI "); break;
1432 case 'O': prints("PERM "); break;
1433 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1434 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1435 }
860 } 1436 }
861 if (!found_file) prints("FILE "); 1437 if (!found_file) prints("FILE ");
862 prints("\n"); 1438 prints("\n");
866 1442
867 /* dump all the good stuff */ 1443 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1444 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1445 const char *out;
870 const char *tmp; 1446 const char *tmp;
871 1447 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1448 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1449 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1450 continue;
879 } 1451 }
880 1452
881 out = NULL; 1453 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1454 be_wewy_wewy_quiet = (out_format[i] == '#');
1455 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1456 switch (out_format[++i]) {
1457 case '+':
884 case '%': 1458 case '%':
885 case '#': 1459 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1460 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1461 case 'F':
888 found_file = 1; 1462 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1463 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1464 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1465 break;
892 case 'p': 1466 case 'p':
893 found_file = 1; 1467 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1468 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1469 tmp = elf->filename;
896 if (search_path) { 1470 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1471 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1472 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1473 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1474 len_file > len_search)
901 tmp += len_search; 1475 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1476 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1477 }
904 xstrcat(&out_buffer, tmp, &out_len); 1478 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1479 break;
906 case 'f': 1480 case 'f':
907 found_file = 1; 1481 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1482 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1483 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1484 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1485 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1486 break;
913 case 'o': out = get_elfetype(elf); break; 1487 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1488 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1489 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1490 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1491 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1492 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1493 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1494 case 'D': out = get_endian(elf); break;
1495 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1496 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1497 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1498 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1499 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1500 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1501 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1502 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1503 case 'a': out = get_elfemtype(elf); break;
1504 case 'I': out = get_elfosabi(elf); break;
1505 case 'Y': out = get_elf_eabi(elf); break;
1506 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1507 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1508 }
927 if (out) { 1509 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1510 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1511 }
935 1512
936#define FOUND_SOMETHING() \ 1513#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1514 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1515 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1516 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1517
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1518 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1519 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1520 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1521 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1522 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1523 puts(out_buffer);
947 fflush(stdout); 1524 fflush(stdout);
948 } 1525 }
949 1526
1527 return 0;
1528}
1529
1530/* scan a single elf */
1531static int scanelf_elf(const char *filename, int fd, size_t len)
1532{
1533 int ret = 1;
1534 elfobj *elf;
1535
1536 /* verify this is real ELF */
1537 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1538 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1539 return 2;
1540 }
1541 switch (match_bits) {
1542 case 32:
1543 if (elf->elf_class != ELFCLASS32)
1544 goto label_done;
1545 break;
1546 case 64:
1547 if (elf->elf_class != ELFCLASS64)
1548 goto label_done;
1549 break;
1550 default: break;
1551 }
1552 if (match_etypes) {
1553 char sbuf[126];
1554 strncpy(sbuf, match_etypes, sizeof(sbuf));
1555 if (strchr(match_etypes, ',') != NULL) {
1556 char *p;
1557 while ((p = strrchr(sbuf, ',')) != NULL) {
1558 *p = 0;
1559 if (etype_lookup(p+1) == get_etype(elf))
1560 goto label_ret;
1561 }
1562 }
1563 if (etype_lookup(sbuf) != get_etype(elf))
1564 goto label_done;
1565 }
1566
1567label_ret:
1568 ret = scanelf_elfobj(elf);
1569
1570label_done:
950 unreadelf(elf); 1571 unreadelf(elf);
1572 return ret;
1573}
1574
1575/* scan an archive of elfs */
1576static int scanelf_archive(const char *filename, int fd, size_t len)
1577{
1578 archive_handle *ar;
1579 archive_member *m;
1580 char *ar_buffer;
1581 elfobj *elf;
1582
1583 ar = ar_open_fd(filename, fd);
1584 if (ar == NULL)
1585 return 1;
1586
1587 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1588 while ((m = ar_next(ar)) != NULL) {
1589 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1590 if (cur_pos == -1)
1591 errp("lseek() failed");
1592 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1593 if (elf) {
1594 scanelf_elfobj(elf);
1595 unreadelf(elf);
1596 }
1597 }
1598 munmap(ar_buffer, len);
1599
1600 return 0;
1601}
1602/* scan a file which may be an elf or an archive or some other magical beast */
1603static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1604{
1605 const struct stat *st = st_cache;
1606 struct stat symlink_st;
1607 int fd;
1608
1609 /* always handle regular files and handle symlinked files if no -y */
1610 if (S_ISLNK(st->st_mode)) {
1611 if (!scan_symlink)
1612 return 1;
1613 fstatat(dir_fd, filename, &symlink_st, 0);
1614 st = &symlink_st;
1615 }
1616
1617 if (!S_ISREG(st->st_mode)) {
1618 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1619 return 1;
1620 }
1621
1622 if (match_perms) {
1623 if ((st->st_mode | match_perms) != st->st_mode)
1624 return 1;
1625 }
1626 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1627 if (fd == -1)
1628 return 1;
1629
1630 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1631 /* if it isn't an ELF, maybe it's an .a archive */
1632 if (scan_archives)
1633 scanelf_archive(filename, fd, st->st_size);
1634
1635 /*
1636 * unreadelf() implicitly closes its fd, so only close it
1637 * when we are returning it in the non-ELF case
1638 */
1639 close(fd);
1640 }
1641
1642 return 0;
951} 1643}
952 1644
953/* scan a directory for ET_EXEC files and print when we find one */ 1645/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1646static int scanelf_dirat(int dir_fd, const char *path)
955{ 1647{
956 register DIR *dir; 1648 register DIR *dir;
957 register struct dirent *dentry; 1649 register struct dirent *dentry;
958 struct stat st_top, st; 1650 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1651 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1652 size_t pathlen = 0, len = 0;
1653 int ret = 0;
1654 int subdir_fd;
961 1655
962 /* make sure path exists */ 1656 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1657 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1658 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1659 return 1;
966 } 1660 }
967 1661
968 /* ok, if it isn't a directory, assume we can open it */ 1662 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1663 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1664 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1665
974 /* now scan the dir looking for fun stuff */ 1666 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1667 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
1668 if (subdir_fd == -1)
1669 dir = NULL;
1670 else
1671 dir = fdopendir(subdir_fd);
1672 if (dir == NULL) {
1673 if (subdir_fd != -1)
1674 close(subdir_fd);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1675 warnf("could not opendir %s: %s", path, strerror(errno));
977 return; 1676 return 1;
978 } 1677 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1678 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1679
981 pathlen = strlen(path); 1680 subpath = stpcpy(buf, path);
1681 *subpath++ = '/';
1682 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1683 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1684 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1685 continue;
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1686
986 if (len >= sizeof(buf)) { 1687 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
988 (unsigned long)len, (unsigned long)sizeof(buf));
989 continue; 1688 continue;
1689
1690 len = strlen(dentry->d_name);
1691 if (len + pathlen + 1 >= sizeof(buf)) {
1692 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1693 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1694 continue;
990 } 1695 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1696 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1697 subpath[len] = '\0';
1698
993 if (S_ISREG(st.st_mode)) 1699 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1700 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1701 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1702 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1703 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1704 }
1000 } 1705 }
1001 closedir(dir); 1706 closedir(dir);
1002}
1003 1707
1708 return ret;
1709}
1710static int scanelf_dir(const char *path)
1711{
1712 return scanelf_dirat(root_fd, root_rel_path(path));
1713}
1714
1004static int scanelf_from_file(char *filename) 1715static int scanelf_from_file(const char *filename)
1005{ 1716{
1006 FILE *fp = NULL; 1717 FILE *fp;
1007 char *p; 1718 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1719 size_t len;
1720 int ret;
1009 1721
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1722 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1723 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1724 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1725 return 1;
1014 1726
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1727 path = NULL;
1728 len = 0;
1729 ret = 0;
1730 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1731 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1732 *p = 0;
1018 search_path = path; 1733 search_path = path;
1019 scanelf_dir(path); 1734 ret = scanelf_dir(path);
1020 } 1735 }
1736 free(path);
1737
1021 if (fp != stdin) 1738 if (fp != stdin)
1022 fclose(fp); 1739 fclose(fp);
1740
1023 return 0; 1741 return ret;
1024} 1742}
1025 1743
1026static void load_ld_so_conf() 1744#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1745
1746static int load_ld_cache_config(int i, const char *fname)
1027{ 1747{
1028 FILE *fp = NULL; 1748 FILE *fp = NULL;
1029 char *p; 1749 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1750 size_t len;
1031 int i = 0; 1751 int curr_fd = -1;
1032 1752
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1753 fp = fopenat_r(root_fd, root_rel_path(fname));
1754 if (fp == NULL)
1034 return; 1755 return i;
1035 1756
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1757 path = NULL;
1037 if (*path != '/') 1758 len = 0;
1038 continue; 1759 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1760 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1761 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1762 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1763 *p = 0;
1044 1764
1045 ldpaths[i++] = xstrdup(path); 1765 /* recursive includes of the same file will make this segfault. */
1766 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1767 glob_t gl;
1768 size_t x;
1769 const char *gpath;
1046 1770
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1771 /* re-use existing path buffer ... need to be creative */
1048 break; 1772 if (path[8] != '/')
1773 gpath = memcpy(path + 3, "/etc/", 5);
1774 else
1775 gpath = path + 8;
1776 if (root_fd != AT_FDCWD) {
1777 if (curr_fd == -1) {
1778 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1779 if (fchdir(root_fd))
1780 errp("unable to change to root dir");
1781 }
1782 gpath = root_rel_path(gpath);
1783 }
1784
1785 if (glob(gpath, 0, NULL, &gl) == 0) {
1786 for (x = 0; x < gl.gl_pathc; ++x) {
1787 /* try to avoid direct loops */
1788 if (strcmp(gl.gl_pathv[x], fname) == 0)
1789 continue;
1790 i = load_ld_cache_config(i, gl.gl_pathv[x]);
1791 }
1792 globfree(&gl);
1793 }
1794
1795 /* failed globs are ignored by glibc */
1796 continue;
1049 } 1797 }
1050 ldpaths[i] = NULL; 1798
1799 if (*path != '/')
1800 continue;
1801
1802 xarraypush_str(ldpaths, path);
1803 }
1804 free(path);
1051 1805
1052 fclose(fp); 1806 fclose(fp);
1807
1808 if (curr_fd != -1) {
1809 if (fchdir(curr_fd))
1810 /* don't care */;
1811 close(curr_fd);
1812 }
1813
1814 return i;
1053} 1815}
1816
1817#elif defined(__FreeBSD__) || defined(__DragonFly__)
1818
1819static int load_ld_cache_config(int i, const char *fname)
1820{
1821 FILE *fp = NULL;
1822 char *b = NULL, *p;
1823 struct elfhints_hdr hdr;
1824
1825 fp = fopenat_r(root_fd, root_rel_path(fname));
1826 if (fp == NULL)
1827 return i;
1828
1829 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1830 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1831 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1832 {
1833 fclose(fp);
1834 return i;
1835 }
1836
1837 b = xmalloc(hdr.dirlistlen + 1);
1838 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1839 fclose(fp);
1840 free(b);
1841 return i;
1842 }
1843
1844 while ((p = strsep(&b, ":"))) {
1845 if (*p == '\0')
1846 continue;
1847 xarraypush_str(ldpaths, p);
1848 }
1849
1850 free(b);
1851 fclose(fp);
1852 return i;
1853}
1854
1855#else
1856#ifdef __ELF__
1857#warning Cache config support not implemented for your target
1858#endif
1859static int load_ld_cache_config(int i, const char *fname)
1860{
1861 return 0;
1862}
1863#endif
1054 1864
1055/* scan /etc/ld.so.conf for paths */ 1865/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1866static void scanelf_ldpath(void)
1057{ 1867{
1058 char scan_l, scan_ul, scan_ull; 1868 char scan_l, scan_ul, scan_ull;
1869 size_t n;
1870 const char *ldpath;
1059 int i = 0; 1871 int i = 0;
1060 1872
1061 if (!ldpaths[0]) 1873 if (array_cnt(ldpaths) == 0)
1062 err("Unable to load any paths from ld.so.conf"); 1874 err("Unable to load any paths from ld.so.conf");
1063 1875
1064 scan_l = scan_ul = scan_ull = 0; 1876 scan_l = scan_ul = scan_ull = 0;
1065 1877
1066 while (ldpaths[i]) { 1878 array_for_each(ldpaths, n, ldpath) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1; 1879 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1; 1880 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1; 1881 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1882 scanelf_dir(ldpath);
1071 ++i; 1883 ++i;
1072 } 1884 }
1073 1885
1074 if (!scan_l) scanelf_dir("/lib"); 1886 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib"); 1887 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib"); 1888 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1889}
1078 1890
1079/* scan env PATH for paths */ 1891/* scan env PATH for paths */
1080static void scanelf_envpath() 1892static void scanelf_envpath(void)
1081{ 1893{
1082 char *path, *p; 1894 char *path, *p;
1083 1895
1084 path = getenv("PATH"); 1896 path = getenv("PATH");
1085 if (!path) 1897 if (!path)
1092 } 1904 }
1093 1905
1094 free(path); 1906 free(path);
1095} 1907}
1096 1908
1097 1909/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1910#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1911#define a_argument required_argument
1101static struct option const long_opts[] = { 1912static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1913 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1914 {"ldpath", no_argument, NULL, 'l'},
1915 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1916 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1917 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1918 {"symlink", no_argument, NULL, 'y'},
1919 {"archives", no_argument, NULL, 'A'},
1920 {"ldcache", no_argument, NULL, 'L'},
1921 {"fix", no_argument, NULL, 'X'},
1922 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1923 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1924 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1925 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1926 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1927 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1928 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1929 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1930 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 1931 {"symbol", a_argument, NULL, 's'},
1932 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 1933 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 1934 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 1935 {"textrels", no_argument, NULL, 'T'},
1936 {"etype", a_argument, NULL, 'E'},
1937 {"bits", a_argument, NULL, 'M'},
1938 {"endian", no_argument, NULL, 'D'},
1939 {"osabi", no_argument, NULL, 'I'},
1940 {"eabi", no_argument, NULL, 'Y'},
1941 {"perms", a_argument, NULL, 'O'},
1942 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 1943 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 1944 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 1945 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 1946 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 1947 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 1948 {"file", a_argument, NULL, 'o'},
1949 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 1950 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 1951 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 1952 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 1953 {NULL, no_argument, NULL, 0x0}
1130}; 1954};
1131 1955
1132static const char *opts_help[] = { 1956static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 1957 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 1958 "Scan all directories in /etc/ld.so.conf",
1959 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 1960 "Scan directories recursively",
1136 "Don't recursively cross mount points", 1961 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 1962 "Don't scan symlinks",
1963 "Scan archives (.a files)",
1964 "Utilize ld.so.cache information (use with -r/-n)",
1965 "Try and 'fix' bad things (use with -r/-e)",
1966 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 1967 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 1968 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 1969 "Print TEXTREL information",
1141 "Print RPATH information", 1970 "Print RPATH information",
1142 "Print NEEDED information", 1971 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 1972 "Print INTERP information",
1145 "Print BIND information", 1973 "Print BIND information",
1146 "Print SONAME information", 1974 "Print SONAME information",
1147 "Find a specified symbol", 1975 "Find a specified symbol",
1976 "Find a specified section",
1148 "Find a specified library", 1977 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 1978 "Use regex matching rather than string compare (use with -s)",
1150 "Locate cause of TEXTREL", 1979 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 1980 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
1981 "Print only ELF files matching numeric bits",
1982 "Print Endianness",
1983 "Print OSABI",
1984 "Print EABI (EM_ARM Only)",
1985 "Print only ELF files matching octal permissions",
1986 "Print ELF file size",
1987 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 1988 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 1989 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 1990 "Use specified format for output",
1155 "Read input stream from a filename", 1991 "Read input stream from a filename",
1156 "Write output stream to a filename", 1992 "Write output stream to a filename",
1993 "Don't emit color in output",
1157 "Don't display the header", 1994 "Don't display the header",
1158 "Print this help and exit", 1995 "Print this help and exit",
1159 "Print version and exit", 1996 "Print version and exit",
1160 NULL 1997 NULL
1161}; 1998};
1163/* display usage and exit */ 2000/* display usage and exit */
1164static void usage(int status) 2001static void usage(int status)
1165{ 2002{
1166 unsigned long i; 2003 unsigned long i;
1167 printf("* Scan ELF binaries for stuff\n\n" 2004 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2005 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2006 printf("Options: -[%s]\n", PARSE_FLAGS);
1170 for (i = 0; long_opts[i].name; ++i) 2007 for (i = 0; long_opts[i].name; ++i)
1171 if (long_opts[i].has_arg == no_argument) 2008 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2009 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
2010 long_opts[i].name, opts_help[i]);
2011 else if (long_opts[i].val > '~')
2012 printf(" --%-7s <arg> * %s\n",
1173 long_opts[i].name, opts_help[i]); 2013 long_opts[i].name, opts_help[i]);
1174 else 2014 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2015 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
1176 long_opts[i].name, opts_help[i]); 2016 long_opts[i].name, opts_help[i]);
1177 2017
1178 if (status != EXIT_SUCCESS) 2018 puts("\nFor more information, see the scanelf(1) manpage");
1179 exit(status);
1180
1181 puts("\nThe format modifiers for the -F option are:");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2019 exit(status);
1192} 2020}
1193 2021
1194/* parse command line arguments and preform needed actions */ 2022/* parse command line arguments and preform needed actions */
2023#define do_pax_state(option, flag) \
2024 if (islower(option)) { \
2025 flags &= ~PF_##flag; \
2026 flags |= PF_NO##flag; \
2027 } else { \
2028 flags &= ~PF_NO##flag; \
2029 flags |= PF_##flag; \
2030 }
1195static void parseargs(int argc, char *argv[]) 2031static int parseargs(int argc, char *argv[])
1196{ 2032{
1197 int i; 2033 int i;
1198 char *from_file = NULL; 2034 const char *from_file = NULL;
2035 int ret = 0;
1199 2036
1200 opterr = 0; 2037 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2038 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2039 switch (i) {
1203 2040
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2044 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2045 exit(EXIT_SUCCESS);
1209 break; 2046 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2047 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2048 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2049 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2050 from_file = optarg;
2051 break;
2052 case 'E':
2053 match_etypes = optarg;
2054 break;
2055 case 'M':
2056 match_bits = atoi(optarg);
2057 if (match_bits == 0) {
2058 if (strcmp(optarg, "ELFCLASS32") == 0)
2059 match_bits = 32;
2060 if (strcmp(optarg, "ELFCLASS64") == 0)
2061 match_bits = 64;
2062 }
2063 break;
2064 case 'O':
2065 if (sscanf(optarg, "%o", &match_perms) == -1)
2066 match_bits = 0;
1214 break; 2067 break;
1215 case 'o': { 2068 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2069 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2070 err("Could not open output stream '%s': %s", optarg, strerror(errno));
1219 SET_STDOUT(fp);
1220 break; 2071 break;
1221 } 2072 }
1222 2073 case 'k':
2074 xarraypush_str(find_section_arr, optarg);
2075 break;
1223 case 's': { 2076 case 's': {
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2077 if (find_sym) warn("You prob don't want to specify -s twice");
1225 find_sym = optarg; 2078 find_sym = optarg;
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1227 sprintf(versioned_symname, "%s@", find_sym);
1228 break; 2079 break;
1229 } 2080 }
1230 case 'N': { 2081 case 'N':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2082 xarraypush_str(find_lib_arr, optarg);
1232 find_lib = optarg;
1233 break; 2083 break;
1234 }
1235
1236 case 'F': { 2084 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2085 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2086 out_format = optarg;
1239 break; 2087 break;
1240 } 2088 }
2089 case 'z': {
2090 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2091 size_t x;
1241 2092
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2093 for (x = 0; x < strlen(optarg); x++) {
2094 switch (optarg[x]) {
2095 case 'p':
2096 case 'P':
2097 do_pax_state(optarg[x], PAGEEXEC);
2098 break;
2099 case 's':
2100 case 'S':
2101 do_pax_state(optarg[x], SEGMEXEC);
2102 break;
2103 case 'm':
2104 case 'M':
2105 do_pax_state(optarg[x], MPROTECT);
2106 break;
2107 case 'e':
2108 case 'E':
2109 do_pax_state(optarg[x], EMUTRAMP);
2110 break;
2111 case 'r':
2112 case 'R':
2113 do_pax_state(optarg[x], RANDMMAP);
2114 break;
2115 case 'x':
2116 case 'X':
2117 do_pax_state(optarg[x], RANDEXEC);
2118 break;
2119 default:
2120 break;
2121 }
2122 }
2123 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2124 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2125 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2126 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2127 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2128 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2129 setpax = flags;
2130 break;
2131 }
2132 case 'Z': show_size = 1; break;
2133 case 'g': g_match = 1; break;
1243 case 'L': printcache = 1; break; 2134 case 'L': use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2135 case 'y': scan_symlink = 0; break;
2136 case 'A': scan_archives = 1; break;
2137 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2138 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2139 case 'l': scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2140 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2141 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2142 case 'm': dir_crossmount = 0; break;
2143 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2144 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2145 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2146 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2147 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2148 case 'n': show_needed = 1; break;
1256 case 'b': show_bind = 1; break; 2150 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2151 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2152 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2153 case 'q': be_quiet = 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2154 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2155 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2156 case 'D': show_endian = 1; break;
2157 case 'I': show_osabi = 1; break;
2158 case 'Y': show_eabi = 1; break;
2159 case 128:
2160 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2161 if (root_fd == -1)
2162 err("Could not open root: %s", optarg);
2163 break;
1263 case ':': 2164 case ':':
1264 err("Option missing parameter\n"); 2165 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2166 case '?':
1266 err("Unknown option\n"); 2167 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2168 default:
1268 err("Unhandled option '%c'", i); 2169 err("Unhandled option '%c'; please report this", i);
1269 }
1270 } 2170 }
1271 2171 }
2172 if (show_textrels && be_verbose)
2173 has_objdump = bin_in_path("objdump");
2174 /* flatten arrays for display */
2175 if (array_cnt(find_lib_arr))
2176 find_lib = array_flatten_str(find_lib_arr);
2177 if (array_cnt(find_section_arr))
2178 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2179 /* let the format option override all other options */
1273 if (out_format) { 2180 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2181 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2182 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2183 show_textrels = show_perms = show_endian = show_size = \
2184 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2185 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2186 if (!IS_MODIFIER(out_format[i])) continue;
1279 2187
1280 switch (out_format[++i]) { 2188 switch (out_format[++i]) {
2189 case '+': break;
1281 case '%': break; 2190 case '%': break;
1282 case '#': break; 2191 case '#': break;
1283 case 'F': break; 2192 case 'F': break;
1284 case 'p': break; 2193 case 'p': break;
1285 case 'f': break; 2194 case 'f': break;
2195 case 'k': break;
1286 case 's': break; 2196 case 's': break;
1287 case 'N': break; 2197 case 'N': break;
1288 case 'o': break; 2198 case 'o': break;
2199 case 'a': break;
2200 case 'M': break;
2201 case 'Z': show_size = 1; break;
2202 case 'D': show_endian = 1; break;
2203 case 'I': show_osabi = 1; break;
2204 case 'Y': show_eabi = 1; break;
2205 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2206 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2207 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2208 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2209 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2210 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2211 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2212 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2213 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2214 case 'T': show_textrels = 1; break;
1298 default: 2215 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2216 err("Invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2217 out_format[i], i+1);
1301 } 2218 }
1302 } 2219 }
1303 2220
1304 /* construct our default format */ 2221 /* construct our default format */
1305 } else { 2222 } else {
1306 size_t fmt_len = 30; 2223 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2224 out_format = xmalloc(sizeof(char) * fmt_len);
2225 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2226 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2227 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2228 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2229 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2230 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2231 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2232 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2233 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2234 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2235 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2236 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2237 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2238 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2239 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2240 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2241 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2242 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2243 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2244 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2245 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2246 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2247
1324 /* now lets actually do the scanning */ 2248 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2249 if (scan_ldpath || use_ldcache)
1326 load_ld_so_conf(); 2250 load_ld_cache_config(0, __PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2251 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2252 if (scan_envpath) scanelf_envpath();
2253 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2254 from_file = "-";
1329 if (from_file) { 2255 if (from_file) {
1330 scanelf_from_file(from_file); 2256 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2257 from_file = *argv;
1333 } 2258 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2259 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2260 err("Nothing to scan !?");
1336 while (optind < argc) { 2261 while (optind < argc) {
1337 search_path = argv[optind++]; 2262 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2263 ret = scanelf_dir(search_path);
1339 } 2264 }
1340 2265
1341 /* clean up */ 2266 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2267 xarrayfree(ldpaths);
2268 xarrayfree(find_lib_arr);
2269 xarrayfree(find_section_arr);
2270 free(find_lib);
2271 free(find_section);
1345 2272
1346 if (ldcache != 0) 2273 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2274 munmap(ldcache, ldcache_size);
1348}
1349
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2275 return ret;
1358} 2276}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2277
1369 new_len = strlen(*dst) + strlen(src); 2278static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2279{
1384 static char my_app[2]; 2280 const char *delims = " \t\n";
1385 my_app[0] = append; 2281 char **envvals = NULL;
1386 my_app[1] = '\0'; 2282 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2283 int nentry;
1388}
1389 2284
2285 if ((env = getenv(envvar)) == NULL)
2286 return NULL;
1390 2287
2288 env = xstrdup(env);
2289 if (env == NULL)
2290 return NULL;
2291
2292 s = strtok(env, delims);
2293 if (s == NULL) {
2294 free(env);
2295 return NULL;
2296 }
2297
2298 nentry = 0;
2299 while (s != NULL) {
2300 ++nentry;
2301 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2302 envvals[nentry-1] = s;
2303 s = strtok(NULL, delims);
2304 }
2305 envvals[nentry] = NULL;
2306
2307 /* don't want to free(env) as it contains the memory that backs
2308 * the envvals array of strings */
2309 return envvals;
2310}
2311
2312static void parseenv(void)
2313{
2314 color_init(false);
2315 qa_textrels = get_split_env("QA_TEXTRELS");
2316 qa_execstack = get_split_env("QA_EXECSTACK");
2317 qa_wx_load = get_split_env("QA_WX_LOAD");
2318}
2319
2320#ifdef __PAX_UTILS_CLEANUP
2321static void cleanup(void)
2322{
2323 free(out_format);
2324 free(qa_textrels);
2325 free(qa_execstack);
2326 free(qa_wx_load);
2327}
2328#endif
1391 2329
1392int main(int argc, char *argv[]) 2330int main(int argc, char *argv[])
1393{ 2331{
2332 int ret;
1394 if (argc < 2) 2333 if (argc < 2)
1395 usage(EXIT_FAILURE); 2334 usage(EXIT_FAILURE);
2335 parseenv();
1396 parseargs(argc, argv); 2336 ret = parseargs(argc, argv);
1397 fclose(stdout); 2337 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2338#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2339 cleanup();
2340 warn("The calls to add/delete heap should be off:\n"
2341 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2342 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2343#endif
1401 return EXIT_SUCCESS; 2344 return ret;
1402} 2345}
2346
2347/* Match filename against entries in matchlist, return TRUE
2348 * if the file is listed */
2349static int file_matches_list(const char *filename, char **matchlist)
2350{
2351 char **file;
2352 char *match;
2353 char buf[__PAX_UTILS_PATH_MAX];
2354
2355 if (matchlist == NULL)
2356 return 0;
2357
2358 for (file = matchlist; *file != NULL; file++) {
2359 if (search_path) {
2360 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2361 match = buf;
2362 } else {
2363 match = *file;
2364 }
2365 if (fnmatch(match, filename, 0) == 0)
2366 return 1;
2367 }
2368 return 0;
2369}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.235

  ViewVC Help
Powered by ViewVC 1.1.20