/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.240
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2007 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.240 2012/01/23 23:48:54 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.240 2012/01/23 23:48:54 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
67static char *find_lib = NULL; 49static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 53static char *out_format = NULL;
69static char *search_path = NULL; 54static char *search_path = NULL;
55static char fix_elf = 0;
70static char gmatch = 0; 56static char g_match = 0;
71static char printcache = 0; 57static char use_ldcache = 0;
58static char use_ldpath = 0;
72 59
60static char **qa_textrels = NULL;
61static char **qa_execstack = NULL;
62static char **qa_wx_load = NULL;
63static int root_fd = AT_FDCWD;
73 64
74caddr_t ldcache = 0; 65static int match_bits = 0;
66static unsigned int match_perms = 0;
67static void *ldcache = NULL;
75size_t ldcache_size = 0; 68static size_t ldcache_size = 0;
69static unsigned long setpax = 0UL;
76 70
71static int has_objdump = 0;
72
73/* find the path to a file by name */
74static int bin_in_path(const char *fname)
75{
76 char fullpath[__PAX_UTILS_PATH_MAX];
77 char *path, *p;
78
79 path = getenv("PATH");
80 if (!path)
81 return 0;
82
83 while ((p = strrchr(path, ':')) != NULL) {
84 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
85 *p = 0;
86 if (access(fullpath, R_OK) != -1)
87 return 1;
88 }
89
90 return 0;
91}
92
93static FILE *fopenat_r(int dir_fd, const char *path)
94{
95 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
96 if (fd == -1)
97 return NULL;
98 return fdopen(fd, "re");
99}
100
101static const char *root_rel_path(const char *path)
102{
103 /*
104 * openat() will ignore the dirfd if path starts with
105 * a /, so consume all of that noise
106 *
107 * XXX: we don't handle relative paths like ../ that
108 * break out of the --root option, but for now, just
109 * don't do that :P.
110 */
111 if (root_fd != AT_FDCWD) {
112 while (*path == '/')
113 ++path;
114 if (*path == '\0')
115 path = ".";
116 }
117
118 return path;
119}
120
121/* 1 on failure. 0 otherwise */
122static int rematch(const char *regex, const char *match, int cflags)
123{
124 regex_t preg;
125 int ret;
126
127 if ((match == NULL) || (regex == NULL))
128 return EXIT_FAILURE;
129
130 if ((ret = regcomp(&preg, regex, cflags))) {
131 char err[256];
132
133 if (regerror(ret, &preg, err, sizeof(err)))
134 fprintf(stderr, "regcomp failed: %s", err);
135 else
136 fprintf(stderr, "regcomp failed");
137
138 return EXIT_FAILURE;
139 }
140 ret = regexec(&preg, match, 0, NULL, 0);
141 regfree(&preg);
142
143 return ret;
144}
145
77/* sub-funcs for scanelf_file() */ 146/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 147static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 148{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 149 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
150
151 /* debug sections */
152 void *symtab = elf_findsecbyname(elf, ".symtab");
153 void *strtab = elf_findsecbyname(elf, ".strtab");
154 /* runtime sections */
155 void *dynsym = elf_findsecbyname(elf, ".dynsym");
156 void *dynstr = elf_findsecbyname(elf, ".dynstr");
157
81#define GET_SYMTABS(B) \ 158#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 159 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \
84 /* debug sections */ \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \
87 /* runtime sections */ \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \
90 if (symtab && dynsym) { \ 160 if (symtab && dynsym) { \
161 Elf ## B ## _Shdr *esymtab = symtab; \
162 Elf ## B ## _Shdr *edynsym = dynsym; \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 163 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 164 } else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 165 *sym = symtab ? symtab : dynsym; \
94 } \
95 if (strtab && dynstr) { \ 166 if (strtab && dynstr) { \
167 Elf ## B ## _Shdr *estrtab = strtab; \
168 Elf ## B ## _Shdr *edynstr = dynstr; \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 169 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 170 } else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 171 *str = strtab ? strtab : dynstr; \
99 } \
100 } 172 }
101 GET_SYMTABS(32) 173 GET_SYMTABS(32)
102 GET_SYMTABS(64) 174 GET_SYMTABS(64)
175
176 if (*sym && *str)
177 return;
178
179 /*
180 * damn, they're really going to make us work for it huh?
181 * reconstruct the section header info out of the dynamic
182 * tags so we can see what symbols this guy uses at runtime.
183 */
184#define GET_SYMTABS_DT(B) \
185 if (elf->elf_class == ELFCLASS ## B) { \
186 size_t i; \
187 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
188 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
189 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
190 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
191 Elf ## B ## _Dyn *dyn; \
192 Elf ## B ## _Off offset; \
193 \
194 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
195 vsym = vstr = vhash = vgnu_hash = 0; \
196 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
197 memset(&str_shdr, 0, sizeof(str_shdr)); \
198 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
199 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
200 continue; \
201 \
202 offset = EGET(phdr[i].p_offset); \
203 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
204 continue; \
205 \
206 dyn = DYN ## B (elf->vdata + offset); \
207 while (EGET(dyn->d_tag) != DT_NULL) { \
208 switch (EGET(dyn->d_tag)) { \
209 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
210 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
211 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
212 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
213 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
214 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
215 } \
216 ++dyn; \
217 } \
218 if (vsym && vstr) \
219 break; \
220 } \
221 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
222 return; \
223 \
224 /* calc offset into the ELF by finding the load addr of the syms */ \
225 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
226 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
227 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
228 offset = EGET(phdr[i].p_offset); \
229 \
230 if (EGET(phdr[i].p_type) != PT_LOAD) \
231 continue; \
232 \
233 if (vhash >= vaddr && vhash < vaddr + filesz) { \
234 /* Scan the hash table to see how many entries we have */ \
235 Elf32_Word max_sym_idx = 0; \
236 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
237 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
238 Elf32_Word nchains = EGET(hashtbl[1]); \
239 Elf32_Word *buckets = &hashtbl[2]; \
240 Elf32_Word *chains = &buckets[nbuckets]; \
241 Elf32_Word sym_idx; \
242 \
243 for (b = 0; b < nbuckets; ++b) { \
244 if (!buckets[b]) \
245 continue; \
246 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
247 if (max_sym_idx < sym_idx) \
248 max_sym_idx = sym_idx; \
249 } \
250 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
251 } \
252 \
253 if (vsym >= vaddr && vsym < vaddr + filesz) { \
254 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
255 *sym = &sym_shdr; \
256 } \
257 \
258 if (vstr >= vaddr && vstr < vaddr + filesz) { \
259 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
260 *str = &str_shdr; \
261 } \
262 } \
263 }
264 GET_SYMTABS_DT(32)
265 GET_SYMTABS_DT(64)
103} 266}
267
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 268static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 269{
106 static char ret[7]; 270 static char ret[7];
107 unsigned long i, shown; 271 unsigned long i, shown;
108 272
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 281 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 282 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 283 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 284 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 285 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 286 if (fix_elf && setpax) { \
287 /* set the paxctl flags */ \
288 ESET(phdr[i].p_flags, setpax); \
289 } \
290 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 291 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 292 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 293 *found_pax = 1; \
126 ++shown; \ 294 ++shown; \
127 break; \ 295 break; \
128 } \ 296 } \
129 } 297 }
130 SHOW_PAX(32) 298 SHOW_PAX(32)
131 SHOW_PAX(64) 299 SHOW_PAX(64)
300 }
301
302 if (fix_elf && setpax) {
303 /* set the chpax settings */
304 if (elf->elf_class == ELFCLASS32) {
305 if (EHDR32(elf->ehdr)->e_type == ET_DYN || EHDR32(elf->ehdr)->e_type == ET_EXEC)
306 ESET(EHDR32(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
307 } else {
308 if (EHDR64(elf->ehdr)->e_type == ET_DYN || EHDR64(elf->ehdr)->e_type == ET_EXEC)
309 ESET(EHDR64(elf->ehdr)->e_ident[EI_PAX], pax_pf2hf_flags(setpax));
310 }
132 } 311 }
133 312
134 /* fall back to EI_PAX if no PT_PAX was found */ 313 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 314 if (!*ret) {
136 static char *paxflags; 315 static char *paxflags;
150 329
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 330static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 331{
153 static char ret[12]; 332 static char ret[12];
154 char *found; 333 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 334 unsigned long i, shown, multi_stack, multi_relro, multi_load;
335 int max_pt_load;
157 336
158 if (!show_phdr) return NULL; 337 if (!show_phdr) return NULL;
159 338
160 memcpy(ret, "--- --- ---\0", 12); 339 memcpy(ret, "--- --- ---\0", 12);
161 340
162 shown = 0; 341 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 342 multi_stack = multi_relro = multi_load = 0;
343 max_pt_load = elf_max_pt_load(elf);
164 344
345#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 346#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 347 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 348 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 349 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 350 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 351 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 352 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 353 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 354 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
355 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 356 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
357 if (file_matches_list(elf->filename, qa_execstack)) \
358 continue; \
175 found = found_phdr; \ 359 found = found_phdr; \
176 offset = 0; \ 360 offset = 0; \
177 check_flags = PF_X; \ 361 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 362 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
363 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 364 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 365 found = found_relro; \
181 offset = 4; \ 366 offset = 4; \
182 check_flags = PF_X; \ 367 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 368 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 369 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
370 if (multi_load++ > max_pt_load) \
371 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
372 if (file_matches_list(elf->filename, qa_wx_load)) \
373 continue; \
185 found = found_load; \ 374 found = found_load; \
186 offset = 8; \ 375 offset = 8; \
187 check_flags = PF_W|PF_X; \ 376 check_flags = PF_W|PF_X; \
188 } else \ 377 } else \
189 continue; \ 378 continue; \
190 flags = EGET(phdr[i].p_flags); \ 379 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 380 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 381 continue; \
382 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
383 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
384 ret[3] = ret[7] = '!'; \
385 flags = EGET(phdr[i].p_flags); \
386 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 387 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 388 *found = 1; \
195 ++shown; \ 389 ++shown; \
196 } \ 390 } \
197 } else if (elf->shdr != NULL) { \ 391 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 392 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 393 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 394 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
395 char *str; \
396 if ((void*)strtbl > elf->data_end) \
397 goto skip_this_shdr##B; \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 398 check_flags = SHF_WRITE|SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 399 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 400 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 401 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 402 str = elf->data + offset; \
403 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
404 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 405 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 406 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 407 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 408 continue; \
210 ++*found_phdr; \ 409 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 413 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 414 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 415 break; \
217 } \ 416 } \
218 } \ 417 } \
418 skip_this_shdr##B: \
219 if (!multi_stack) { \ 419 if (!multi_stack) { \
420 if (file_matches_list(elf->filename, qa_execstack)) \
421 return NULL; \
220 *found_phdr = 1; \ 422 *found_phdr = 1; \
221 shown = 1; \ 423 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 424 memcpy(ret, "!WX", 3); \
223 } \ 425 } \
224 } \ 426 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 431 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 432 return NULL;
231 else 433 else
232 return ret; 434 return ret;
233} 435}
436
437/*
438 * See if this ELF contains a DT_TEXTREL tag in any of its
439 * PT_DYNAMIC sections.
440 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 441static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 442{
236 static const char *ret = "TEXTREL"; 443 static const char *ret = "TEXTREL";
237 unsigned long i; 444 unsigned long i;
238 445
239 if (!show_textrel && !show_textrels) return NULL; 446 if (!show_textrel && !show_textrels) return NULL;
447
448 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 449
241 if (elf->phdr) { 450 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 451#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 452 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 453 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 454 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 455 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 456 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 457 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 458 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 459 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 460 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 461 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 462 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 463 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 464 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 465 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 466 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 475 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 476 return NULL;
268 else 477 else
269 return " - "; 478 return " - ";
270} 479}
480
481/*
482 * Scan the .text section to see if there are any relocations in it.
483 * Should rewrite this to check PT_LOAD sections that are marked
484 * Executable rather than the section named '.text'.
485 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 486static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 487{
273 unsigned long s, r, rmax; 488 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 489 void *symtab_void, *strtab_void, *text_void;
275 490
296 Elf ## B ## _Rela *rela; \ 511 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 512 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 513 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 514 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 515 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 516 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 517 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 518 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 519 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 520 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 521 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 522 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 523 } else \
309 continue; \ 524 continue; \
310 /* now see if any of the relocs are in the .text */ \ 525 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 526 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 541 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 542 if (be_verbose <= 2) continue; \
328 } else \ 543 } else \
329 *found_textrels = 1; \ 544 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 545 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 546 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
547 if ((void*)sym > elf->data_end) { \
548 warn("%s: corrupt ELF symbol", elf->filename); \
549 continue; \
550 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 551 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 552 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 553 sym += sym_max; \
335 else \ 554 else \
336 sym = NULL; \ 555 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 556 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 557 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 558 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 559 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 560 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 561 else \
343 printf("(memory/fake?)"); \ 562 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 563 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 564 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 565 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 566 func = NULL; \
348 offset_tmp = 0; \ 567 offset_tmp = 0; \
349 while (sym_max--) { \ 568 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 569 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 570 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 571 offset_tmp = EGET(sym->st_value); \
353 } \ 572 } \
354 ++sym; \ 573 ++sym; \
355 } \ 574 } \
356 printf(" in "); \ 575 printf(" in "); \
357 if (func && func->st_name) \ 576 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 577 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
578 if (r_offset > EGET(func->st_size)) \
579 printf("(optimized out: previous %s)", func_name); \
359 else \ 580 else \
360 printf("(NULL: fake?)"); \ 581 printf("%s", func_name); \
582 } else \
583 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 584 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
585 if (be_verbose && has_objdump) { \
586 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
587 char *sysbuf; \
588 size_t syslen; \
589 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
590 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
591 sysbuf = xmalloc(syslen); \
592 if (end_addr < r_offset) \
593 /* not uncommon when things are optimized out */ \
594 end_addr = r_offset + 0x100; \
595 snprintf(sysbuf, syslen, sysfmt, \
596 (unsigned long)offset_tmp, \
597 (unsigned long)end_addr, \
598 elf->filename, \
599 (unsigned long)r_offset); \
600 fflush(stdout); \
601 if (system(sysbuf)) /* don't care */; \
602 fflush(stdout); \
603 free(sysbuf); \
604 } \
362 } \ 605 } \
363 } } 606 } }
364 SHOW_TEXTRELS(32) 607 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 608 SHOW_TEXTRELS(64)
366 } 609 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 611 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 612
370 return NULL; 613 return NULL;
371} 614}
372 615
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 616static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
617{
375 struct stat st; 618 struct stat st;
376 switch (*item) { 619 switch (*item) {
377 case '/': break; 620 case '/': break;
378 case '.': 621 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 622 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 623 break;
624 case ':':
381 case '\0': 625 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 626 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 627 break;
384 case '$': 628 case '$':
385 if (fstat(elf->fd, &st) != -1) 629 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 630 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 631 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 632 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 633 break;
390 default: 634 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 635 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 636 break;
393 } 637 }
394} 638}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 639static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 640{
397 unsigned long i, s; 641 unsigned long i;
398 char *rpath, *runpath, **r; 642 char *rpath, *runpath, **r;
399 void *strtbl_void; 643 void *strtbl_void;
400 644
401 if (!show_rpath) return; 645 if (!show_rpath) return;
402 646
413 Elf ## B ## _Off offset; \ 657 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 658 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 659 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 660 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 661 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 662 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 663 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 664 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 665 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 666 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 667 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 668 if (word == DT_RPATH) { \
425 r = &rpath; \ 669 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 670 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 671 r = &runpath; \
431 } \ 675 } \
432 /* Verify the memory is somewhat sane */ \ 676 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 677 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 678 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 679 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 680 *r = elf->data + offset; \
681 /* cache the length in case we need to nuke this section later on */ \
682 if (fix_elf) \
683 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 684 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 685 if (be_quiet) { \
439 size_t len; \ 686 size_t len; \
440 char *start, *end; \ 687 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 688 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 689 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 690 start = *r; \
444 /* scan each path in : delimited list */ \ 691 /* scan each path in : delimited list */ \
445 while (start) { \ 692 while (start) { \
446 rpath_security_checks(elf, start); \ 693 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 694 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 695 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 696 if (use_ldcache) { \
697 size_t n; \
698 const char *ldpath; \
699 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 700 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 701 *r = end; \
702 /* corner case ... if RPATH reads "/usr/lib:", we want \
703 * to show ':' rather than '' */ \
704 if (end && end[1] != '\0') \
705 (*r)++; \
452 break; \ 706 break; \
453 } \ 707 } \
454 } \ 708 } \
455 if (!*r || !ldpaths[s] || !end) \ 709 if (!*r || !end) \
456 start = NULL; \ 710 break; \
457 else \ 711 else \
458 start = start + len + 1; \ 712 start = start + len + 1; \
459 } \ 713 } \
460 } \ 714 } \
715 if (*r) { \
716 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
717 /* just nuke it */ \
718 nuke_it##B: \
719 memset(*r, 0x00, offset); \
720 *r = NULL; \
721 ESET(dyn->d_tag, DT_DEBUG); \
722 ESET(dyn->d_un.d_ptr, 0); \
723 } else if (fix_elf) { \
724 /* try to clean "bad" paths */ \
725 size_t len, tmpdir_len; \
726 char *start, *end; \
727 const char *tmpdir; \
728 start = *r; \
729 tmpdir = (getenv("TMPDIR") ? : "."); \
730 tmpdir_len = strlen(tmpdir); \
731 while (1) { \
732 end = strchr(start, ':'); \
733 if (start == end) { \
734 eat_this_path##B: \
735 len = strlen(end); \
736 memmove(start, end+1, len); \
737 start[len-1] = '\0'; \
738 end = start - 1; \
739 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
740 if (!end) { \
741 if (start == *r) \
742 goto nuke_it##B; \
743 *--start = '\0'; \
744 } else \
745 goto eat_this_path##B; \
746 } \
747 if (!end) \
748 break; \
749 start = end + 1; \
750 } \
751 if (**r == '\0') \
752 goto nuke_it##B; \
753 } \
754 if (*r) \
461 if (*r) *found_rpath = 1; \ 755 *found_rpath = 1; \
756 } \
462 } \ 757 } \
463 ++dyn; \ 758 ++dyn; \
464 } \ 759 } \
465 } } 760 } }
466 SHOW_RPATH(32) 761 SHOW_RPATH(32)
488 783
489#define LDSO_CACHE_MAGIC "ld.so-" 784#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 785#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 786#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 787#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
788#define FLAG_ANY -1
789#define FLAG_TYPE_MASK 0x00ff
790#define FLAG_LIBC4 0x0000
791#define FLAG_ELF 0x0001
792#define FLAG_ELF_LIBC5 0x0002
793#define FLAG_ELF_LIBC6 0x0003
794#define FLAG_REQUIRED_MASK 0xff00
795#define FLAG_SPARC_LIB64 0x0100
796#define FLAG_IA64_LIB64 0x0200
797#define FLAG_X8664_LIB64 0x0300
798#define FLAG_S390_LIB64 0x0400
799#define FLAG_POWERPC_LIB64 0x0500
800#define FLAG_MIPS64_LIBN32 0x0600
801#define FLAG_MIPS64_LIBN64 0x0700
493 802
494static char *lookup_cache_lib(char *); 803#if defined(__GLIBC__) || defined(__UCLIBC__)
804
495static char *lookup_cache_lib(char *fname) 805static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 806{
497 int fd = 0; 807 int fd;
498 char *strs; 808 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 809 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 810 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 811 struct stat st;
502 812
503 typedef struct { 813 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 814 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 815 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 816 int nlibs;
507 } header_t; 817 } header_t;
818 header_t *header;
508 819
509 typedef struct { 820 typedef struct {
510 int flags; 821 int flags;
511 int sooffset; 822 int sooffset;
512 int liboffset; 823 int liboffset;
513 } libentry_t; 824 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 825 libentry_t *libent;
517 826
518 if (fname == NULL) 827 if (fname == NULL)
519 return NULL; 828 return NULL;
520 829
521 if (ldcache == 0) { 830 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 831 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 832 return NULL;
524 /* save the cache size for latter unmapping */ 833
834 fd = openat(root_fd, cachefile, O_RDONLY);
835 if (fd == -1)
836 return NULL;
837
838 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 839 ldcache_size = st.st_size;
840 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
841 close(fd);
526 842
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 843 if (ldcache == MAP_FAILED) {
844 ldcache = NULL;
528 return NULL; 845 return NULL;
846 }
529 847
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 848 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
849 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
850 {
851 munmap(ldcache, ldcache_size);
852 ldcache = NULL;
533 return NULL; 853 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 854 }
855 } else
856 header = ldcache;
538 857
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 858 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 859 strs = (char *) &libent[header->nlibs];
542 860
543 for (fd = 0; fd < header->nlibs; fd++) { 861 for (fd = 0; fd < header->nlibs; ++fd) {
862 /* This should be more fine grained, but for now we assume that
863 * diff arches will not be cached together, and we ignore the
864 * the different multilib mips cases.
865 */
866 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
867 continue;
868 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
869 continue;
870
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 871 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 872 continue;
873
874 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 875 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
876 break;
547 } 877 }
878
548 return buf; 879 return buf;
549} 880}
550 881
882#elif defined(__NetBSD__)
883static char *lookup_cache_lib(elfobj *elf, const char *fname)
884{
885 static char buf[__PAX_UTILS_PATH_MAX] = "";
886 static struct stat st;
887 size_t n;
888 char *ldpath;
889
890 array_for_each(ldpath, n, ldpath) {
891 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
892 continue; /* if the pathname is too long, or something went wrong, ignore */
893
894 if (stat(buf, &st) != 0)
895 continue; /* if the lib doesn't exist in *ldpath, look further */
896
897 /* NetBSD doesn't actually do sanity checks, it just loads the file
898 * and if that doesn't work, continues looking in other directories.
899 * This cannot easily be safely emulated, unfortunately. For now,
900 * just assume that if it exists, it's a valid library. */
901
902 return buf;
903 }
904
905 /* not found in any path */
906 return NULL;
907}
908#else
909#ifdef __ELF__
910#warning Cache support not implemented for your target
911#endif
912static char *lookup_cache_lib(elfobj *elf, const char *fname)
913{
914 return NULL;
915}
916#endif
917
918static char *lookup_config_lib(elfobj *elf, char *fname)
919{
920 static char buf[__PAX_UTILS_PATH_MAX] = "";
921 const char *ldpath;
922 size_t n;
923
924 array_for_each(ldpaths, n, ldpath) {
925 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
926 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
927 return buf;
928 }
929
930 return NULL;
931}
551 932
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 933static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 934{
554 unsigned long i; 935 unsigned long i;
555 char *needed; 936 char *needed;
556 void *strtbl_void; 937 void *strtbl_void;
557 char *p; 938 char *p;
558 939
940 /*
941 * -n -> op==0 -> print all
942 * -N -> op==1 -> print requested
943 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 944 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
945 return NULL;
560 946
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 947 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 948
563 if (elf->phdr && strtbl_void) { 949 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 950#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 952 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 953 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 954 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 955 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 956 Elf ## B ## _Off offset; \
957 size_t matched = 0; \
958 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 959 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 960 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
961 continue; \
573 offset = EGET(phdr[i].p_offset); \ 962 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 963 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
964 continue; \
965 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 966 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 967 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 968 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 969 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 970 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 971 ++dyn; \
581 continue; \ 972 continue; \
582 } \ 973 } \
583 needed = (char*)(elf->data + offset); \ 974 needed = elf->data + offset; \
584 if (op == 0) { \ 975 if (op == 0) { \
976 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 977 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 978 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 979 if (use_ldpath) { \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 980 if ((p = lookup_config_lib(elf, needed)) != NULL) \
589 needed = p; \ 981 needed = p; \
982 } else if (use_ldcache) { \
983 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
984 needed = p; \
985 } \
590 xstrcat(ret, needed, ret_len); \ 986 xstrcat(ret, needed, ret_len); \
591 } \ 987 } \
592 *found_needed = 1; \ 988 *found_needed = 1; \
593 } else { \ 989 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 990 /* -N -> print matching entries */ \
991 size_t n; \
992 const char *find_lib_name; \
993 \
994 array_for_each(find_lib_arr, n, find_lib_name) { \
995 int invert = 1; \
996 if (find_lib_name[0] == '!') \
997 invert = 0, ++find_lib_name; \
998 if (!strcmp(find_lib_name, needed) == invert) \
999 ++matched; \
1000 } \
1001 \
1002 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 1003 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 1004 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 1005 } \
598 } \ 1006 } \
599 } \ 1007 } \
600 ++dyn; \ 1008 ++dyn; \
601 } \ 1009 } \
630} 1038}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1039static char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1040{
633 unsigned long i; 1041 unsigned long i;
634 struct stat s; 1042 struct stat s;
1043 char dynamic = 0;
635 1044
636 if (!show_bind) return NULL; 1045 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1046 if (!elf->phdr) return NULL;
638 1047
639#define SHOW_BIND(B) \ 1048#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1050 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1051 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1052 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1053 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1054 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1055 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1056 dynamic = 1; \
647 offset = EGET(phdr[i].p_offset); \ 1057 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1058 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1059 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1060 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1061 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1062 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1063 { \
654 if (be_quiet) return NULL; \ 1064 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1072 SHOW_BIND(32)
663 SHOW_BIND(64) 1073 SHOW_BIND(64)
664 1074
665 if (be_wewy_wewy_quiet) return NULL; 1075 if (be_wewy_wewy_quiet) return NULL;
666 1076
1077 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1078 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1079 return NULL;
669 } else { 1080 } else {
670 *found_bind = 1; 1081 *found_bind = 1;
671 return (char *) "LAZY"; 1082 return (char *)(dynamic ? "LAZY" : "STATIC");
672 } 1083 }
673} 1084}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1085static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1086{
676 unsigned long i; 1087 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1099 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1100 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1101 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1102 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1103 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1104 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1105 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1106 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1107 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1108 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1109 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1110 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1111 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1112 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1113 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1114 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1115 ++dyn; \
705 continue; \ 1116 continue; \
706 } \ 1117 } \
707 soname = (char*)(elf->data + offset); \ 1118 soname = elf->data + offset; \
708 *found_soname = 1; \ 1119 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1120 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1121 } \
711 ++dyn; \ 1122 ++dyn; \
712 } \ 1123 } \
715 SHOW_SONAME(64) 1126 SHOW_SONAME(64)
716 } 1127 }
717 1128
718 return NULL; 1129 return NULL;
719} 1130}
1131
1132/*
1133 * We support the symbol form:
1134 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1135 * If the symbol name is empty, then all symbols are matched.
1136 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1137 * Do not rely on this output format at all.
1138 * Otherwise the symbol name is used to search (either regex or string compare).
1139 * If the first char of the symbol name is a plus ("+"), then only match
1140 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1141 * Putting modifiers in between the percent signs allows for more in depth
1142 * filters. There are groups of modifiers. If you don't specify a member
1143 * of a group, then all types in that group are matched. The current
1144 * groups and their types are:
1145 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1146 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1147 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1148 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1149 * You can search for multiple symbols at once by seperating with a comma (",").
1150 *
1151 * Some examples:
1152 * ELFs with a weak function "foo":
1153 * scanelf -s %wf%foo <ELFs>
1154 * ELFs that define the symbol "main":
1155 * scanelf -s +main <ELFs>
1156 * scanelf -s %d%main <ELFs>
1157 * ELFs that refer to the undefined symbol "brk":
1158 * scanelf -s -brk <ELFs>
1159 * scanelf -s %u%brk <ELFs>
1160 * All global defined objects in an ELF:
1161 * scanelf -s %ogd% <ELF>
1162 */
1163static void
1164scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1165 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1166{
1167 char *this_sym, *next_sym, saved = saved;
1168
1169 /* allow the user to specify a comma delimited list of symbols to search for */
1170 next_sym = NULL;
1171 do {
1172 bool inc_notype, inc_object, inc_func, inc_file,
1173 inc_local, inc_global, inc_weak,
1174 inc_def, inc_undef, inc_abs, inc_common;
1175
1176 if (next_sym) {
1177 next_sym[-1] = saved;
1178 this_sym = next_sym;
1179 } else
1180 this_sym = find_sym;
1181 if ((next_sym = strchr(this_sym, ','))) {
1182 /* make parsing easier by killing the comma temporarily */
1183 saved = *next_sym;
1184 *next_sym = '\0';
1185 next_sym += 1;
1186 }
1187
1188 /* symbol selection! */
1189 inc_notype = inc_object = inc_func = inc_file = \
1190 inc_local = inc_global = inc_weak = \
1191 inc_def = inc_undef = inc_abs = inc_common = \
1192 (*this_sym != '%');
1193
1194 /* parse the contents of %...% */
1195 if (!inc_notype) {
1196 while (*(this_sym++)) {
1197 if (*this_sym == '%') {
1198 ++this_sym;
1199 break;
1200 }
1201 switch (*this_sym) {
1202 case 'n': inc_notype = true; break;
1203 case 'o': inc_object = true; break;
1204 case 'f': inc_func = true; break;
1205 case 'F': inc_file = true; break;
1206 case 'l': inc_local = true; break;
1207 case 'g': inc_global = true; break;
1208 case 'w': inc_weak = true; break;
1209 case 'd': inc_def = true; break;
1210 case 'u': inc_undef = true; break;
1211 case 'a': inc_abs = true; break;
1212 case 'c': inc_common = true; break;
1213 default: err("invalid symbol selector '%c'", *this_sym);
1214 }
1215 }
1216
1217 /* If no types are matched, not match all */
1218 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1219 inc_notype = inc_object = inc_func = inc_file = true;
1220 if (!inc_local && !inc_global && !inc_weak)
1221 inc_local = inc_global = inc_weak = true;
1222 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1223 inc_def = inc_undef = inc_abs = inc_common = true;
1224
1225 /* backwards compat for defined/undefined short hand */
1226 } else if (*this_sym == '+') {
1227 inc_undef = false;
1228 ++this_sym;
1229 } else if (*this_sym == '-') {
1230 inc_def = inc_abs = inc_common = false;
1231 ++this_sym;
1232 }
1233
1234 /* filter symbols */
1235 if ((!inc_notype && stt == STT_NOTYPE) || \
1236 (!inc_object && stt == STT_OBJECT) || \
1237 (!inc_func && stt == STT_FUNC ) || \
1238 (!inc_file && stt == STT_FILE ) || \
1239 (!inc_local && stb == STB_LOCAL ) || \
1240 (!inc_global && stb == STB_GLOBAL) || \
1241 (!inc_weak && stb == STB_WEAK ) || \
1242 (!inc_def && shn && shn < SHN_LORESERVE) || \
1243 (!inc_undef && shn == SHN_UNDEF ) || \
1244 (!inc_abs && shn == SHN_ABS ) || \
1245 (!inc_common && shn == SHN_COMMON))
1246 continue;
1247
1248 if (*this_sym == '*') {
1249 /* a "*" symbol gets you debug output */
1250 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1251 ((*found_sym == 0) ? "\n\t" : "\t"),
1252 elf->base_filename,
1253 size,
1254 get_elfstttype(stt),
1255 get_elfstbtype(stb),
1256 get_elfshntype(shn),
1257 symname);
1258 goto matched;
1259
1260 } else {
1261 if (g_match) {
1262 /* regex match the symbol */
1263 if (rematch(this_sym, symname, REG_EXTENDED) != 0)
1264 continue;
1265
1266 } else if (*this_sym) {
1267 /* give empty symbols a "pass", else do a normal compare */
1268 const size_t len = strlen(this_sym);
1269 if (!(strncmp(this_sym, symname, len) == 0 &&
1270 /* Accept unversioned symbol names */
1271 (symname[len] == '\0' || symname[len] == '@')))
1272 continue;
1273 }
1274
1275 if (be_semi_verbose) {
1276 char buf[1024];
1277 snprintf(buf, sizeof(buf), "%lX %s %s",
1278 size,
1279 get_elfstttype(stt),
1280 this_sym);
1281 *ret = xstrdup(buf);
1282 } else {
1283 if (*ret) xchrcat(ret, ',', ret_len);
1284 xstrcat(ret, symname, ret_len);
1285 }
1286
1287 goto matched;
1288 }
1289 } while (next_sym);
1290
1291 return;
1292
1293 matched:
1294 *found_sym = 1;
1295 if (next_sym)
1296 next_sym[-1] = saved;
1297}
1298
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1299static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1300{
722 unsigned long i;
723 char *ret; 1301 char *ret;
724 void *symtab_void, *strtab_void; 1302 void *symtab_void, *strtab_void;
725 1303
726 if (!find_sym) return NULL; 1304 if (!find_sym) return NULL;
727 ret = find_sym; 1305 ret = NULL;
728 1306
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1307 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1308
731 if (symtab_void && strtab_void) { 1309 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1310#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1311 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1312 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1313 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1314 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1315 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1316 char *symname; \
1317 size_t ret_len = 0; \
1318 if (cnt) \
1319 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1320 for (i = 0; i < cnt; ++i) { \
1321 if ((void*)sym > elf->data_end) { \
1322 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1323 goto break_out; \
1324 } \
740 if (sym->st_name) { \ 1325 if (sym->st_name) { \
1326 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1327 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1328 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1329 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1330 ++sym; \
745 elf->base_filename, \ 1331 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1332 } \
1333 scanelf_match_symname(elf, found_sym, \
1334 &ret, &ret_len, symname, \
1335 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1336 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1337 EGET(sym->st_shndx), \
1338 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1339 EGET(sym->st_size)); \
766 } \ 1340 } \
767 ++sym; \ 1341 ++sym; \
768 } } 1342 } \
1343 }
769 FIND_SYM(32) 1344 FIND_SYM(32)
770 FIND_SYM(64) 1345 FIND_SYM(64)
771 } 1346 }
772 1347
773break_out: 1348break_out:
776 if (*find_sym != '*' && *found_sym) 1351 if (*find_sym != '*' && *found_sym)
777 return ret; 1352 return ret;
778 if (be_quiet) 1353 if (be_quiet)
779 return NULL; 1354 return NULL;
780 else 1355 else
781 return (char *)" - "; 1356 return " - ";
782} 1357}
1358
1359static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1360{
1361 if (!find_section)
1362 return NULL;
1363
1364#define FIND_SECTION(B) \
1365 if (elf->elf_class == ELFCLASS ## B) { \
1366 size_t matched, n; \
1367 int invert; \
1368 const char *section_name; \
1369 Elf ## B ## _Shdr *section; \
1370 \
1371 matched = 0; \
1372 array_for_each(find_section_arr, n, section_name) { \
1373 invert = (*section_name == '!' ? 1 : 0); \
1374 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1375 if ((section == NULL && invert) || (section != NULL && !invert)) \
1376 ++matched; \
1377 } \
1378 \
1379 if (matched == array_cnt(find_section_arr)) \
1380 *found_section = 1; \
1381 }
1382 FIND_SECTION(32)
1383 FIND_SECTION(64)
1384
1385 if (be_wewy_wewy_quiet)
1386 return NULL;
1387
1388 if (*found_section)
1389 return find_section;
1390
1391 if (be_quiet)
1392 return NULL;
1393 else
1394 return " - ";
1395}
1396
783/* scan an elf file and show all the fun stuff */ 1397/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1398#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1399static int scanelf_elfobj(elfobj *elf)
786{ 1400{
787 unsigned long i; 1401 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1402 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1403 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1404 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1405 static char *out_buffer = NULL;
794 static size_t out_len; 1406 static size_t out_len;
795 1407
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1408 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1409 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1410 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1411
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1412 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1413 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1414 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1415 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1416 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1417 printf("%s: scanning file\n", elf->filename);
827 1418
828 /* init output buffer */ 1419 /* init output buffer */
829 if (!out_buffer) { 1420 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1421 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1422 out_buffer = xmalloc(out_len);
832 } 1423 }
833 *out_buffer = '\0'; 1424 *out_buffer = '\0';
834 1425
835 /* show the header */ 1426 /* show the header */
836 if (!be_quiet && show_banner) { 1427 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1428 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1429 if (!IS_MODIFIER(out_format[i])) continue;
839 1430
840 switch (out_format[++i]) { 1431 switch (out_format[++i]) {
1432 case '+': break;
841 case '%': break; 1433 case '%': break;
842 case '#': break; 1434 case '#': break;
843 case 'F': 1435 case 'F':
844 case 'p': 1436 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1437 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1438 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1439 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1440 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1441 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1442 case 'r': prints("RPATH "); break;
1443 case 'M': prints("CLASS "); break;
1444 case 'l':
851 case 'n': prints("NEEDED "); break; 1445 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1446 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1447 case 'b': prints("BIND "); break;
1448 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1449 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1450 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1451 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1452 case 'T': prints("TEXTRELS "); break;
1453 case 'k': prints("SECTION "); break;
1454 case 'a': prints("ARCH "); break;
1455 case 'I': prints("OSABI "); break;
1456 case 'Y': prints("EABI "); break;
1457 case 'O': prints("PERM "); break;
1458 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1459 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1460 }
860 } 1461 }
861 if (!found_file) prints("FILE "); 1462 if (!found_file) prints("FILE ");
862 prints("\n"); 1463 prints("\n");
866 1467
867 /* dump all the good stuff */ 1468 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1469 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1470 const char *out;
870 const char *tmp; 1471 const char *tmp;
871 1472 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1473 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1474 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1475 continue;
879 } 1476 }
880 1477
881 out = NULL; 1478 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1479 be_wewy_wewy_quiet = (out_format[i] == '#');
1480 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1481 switch (out_format[++i]) {
1482 case '+':
884 case '%': 1483 case '%':
885 case '#': 1484 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1485 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1486 case 'F':
888 found_file = 1; 1487 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1488 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1489 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1490 break;
892 case 'p': 1491 case 'p':
893 found_file = 1; 1492 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1493 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1494 tmp = elf->filename;
896 if (search_path) { 1495 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1496 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1497 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1498 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1499 len_file > len_search)
901 tmp += len_search; 1500 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1501 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1502 }
904 xstrcat(&out_buffer, tmp, &out_len); 1503 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1504 break;
906 case 'f': 1505 case 'f':
907 found_file = 1; 1506 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1507 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1508 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1509 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1510 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1511 break;
913 case 'o': out = get_elfetype(elf); break; 1512 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1513 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1514 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1515 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1516 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1517 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1518 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1519 case 'D': out = get_endian(elf); break;
1520 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1521 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1522 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1523 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1524 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1525 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1526 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1527 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1528 case 'a': out = get_elfemtype(elf); break;
1529 case 'I': out = get_elfosabi(elf); break;
1530 case 'Y': out = get_elf_eabi(elf); break;
1531 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1532 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1533 }
927 if (out) { 1534 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1535 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1536 }
935 1537
936#define FOUND_SOMETHING() \ 1538#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1539 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1540 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1541 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1542
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1543 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1544 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1545 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1546 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1547 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1548 puts(out_buffer);
947 fflush(stdout); 1549 fflush(stdout);
948 } 1550 }
949 1551
1552 return 0;
1553}
1554
1555/* scan a single elf */
1556static int scanelf_elf(const char *filename, int fd, size_t len)
1557{
1558 int ret = 1;
1559 elfobj *elf;
1560
1561 /* verify this is real ELF */
1562 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1563 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1564 return 2;
1565 }
1566 switch (match_bits) {
1567 case 32:
1568 if (elf->elf_class != ELFCLASS32)
1569 goto label_done;
1570 break;
1571 case 64:
1572 if (elf->elf_class != ELFCLASS64)
1573 goto label_done;
1574 break;
1575 default: break;
1576 }
1577 if (match_etypes) {
1578 char sbuf[126];
1579 strncpy(sbuf, match_etypes, sizeof(sbuf));
1580 if (strchr(match_etypes, ',') != NULL) {
1581 char *p;
1582 while ((p = strrchr(sbuf, ',')) != NULL) {
1583 *p = 0;
1584 if (etype_lookup(p+1) == get_etype(elf))
1585 goto label_ret;
1586 }
1587 }
1588 if (etype_lookup(sbuf) != get_etype(elf))
1589 goto label_done;
1590 }
1591
1592label_ret:
1593 ret = scanelf_elfobj(elf);
1594
1595label_done:
950 unreadelf(elf); 1596 unreadelf(elf);
1597 return ret;
1598}
1599
1600/* scan an archive of elfs */
1601static int scanelf_archive(const char *filename, int fd, size_t len)
1602{
1603 archive_handle *ar;
1604 archive_member *m;
1605 char *ar_buffer;
1606 elfobj *elf;
1607
1608 ar = ar_open_fd(filename, fd);
1609 if (ar == NULL)
1610 return 1;
1611
1612 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1613 while ((m = ar_next(ar)) != NULL) {
1614 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1615 if (cur_pos == -1)
1616 errp("lseek() failed");
1617 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1618 if (elf) {
1619 scanelf_elfobj(elf);
1620 unreadelf(elf);
1621 }
1622 }
1623 munmap(ar_buffer, len);
1624
1625 return 0;
1626}
1627/* scan a file which may be an elf or an archive or some other magical beast */
1628static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1629{
1630 const struct stat *st = st_cache;
1631 struct stat symlink_st;
1632 int fd;
1633
1634 /* always handle regular files and handle symlinked files if no -y */
1635 if (S_ISLNK(st->st_mode)) {
1636 if (!scan_symlink)
1637 return 1;
1638 fstatat(dir_fd, filename, &symlink_st, 0);
1639 st = &symlink_st;
1640 }
1641
1642 if (!S_ISREG(st->st_mode)) {
1643 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1644 return 1;
1645 }
1646
1647 if (match_perms) {
1648 if ((st->st_mode | match_perms) != st->st_mode)
1649 return 1;
1650 }
1651 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1652 if (fd == -1)
1653 return 1;
1654
1655 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1656 /* if it isn't an ELF, maybe it's an .a archive */
1657 if (scan_archives)
1658 scanelf_archive(filename, fd, st->st_size);
1659
1660 /*
1661 * unreadelf() implicitly closes its fd, so only close it
1662 * when we are returning it in the non-ELF case
1663 */
1664 close(fd);
1665 }
1666
1667 return 0;
951} 1668}
952 1669
953/* scan a directory for ET_EXEC files and print when we find one */ 1670/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1671static int scanelf_dirat(int dir_fd, const char *path)
955{ 1672{
956 register DIR *dir; 1673 register DIR *dir;
957 register struct dirent *dentry; 1674 register struct dirent *dentry;
958 struct stat st_top, st; 1675 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1676 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1677 size_t pathlen = 0, len = 0;
1678 int ret = 0;
1679 int subdir_fd;
961 1680
962 /* make sure path exists */ 1681 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1682 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1683 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1684 return 1;
966 } 1685 }
967 1686
968 /* ok, if it isn't a directory, assume we can open it */ 1687 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1688 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1689 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1690
974 /* now scan the dir looking for fun stuff */ 1691 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1692 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1693 if (subdir_fd == -1)
1694 dir = NULL;
1695 else
1696 dir = fdopendir(subdir_fd);
1697 if (dir == NULL) {
1698 if (subdir_fd != -1)
1699 close(subdir_fd);
1700 warnfp("could not opendir(%s)", path);
977 return; 1701 return 1;
978 } 1702 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1703 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1704
981 pathlen = strlen(path); 1705 subpath = stpcpy(buf, path);
1706 *subpath++ = '/';
1707 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1708 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1709 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1710 continue;
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1711
986 if (len >= sizeof(buf)) { 1712 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
988 (unsigned long)len, (unsigned long)sizeof(buf));
989 continue; 1713 continue;
1714
1715 len = strlen(dentry->d_name);
1716 if (len + pathlen + 1 >= sizeof(buf)) {
1717 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1718 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1719 continue;
990 } 1720 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1721 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1722 subpath[len] = '\0';
1723
993 if (S_ISREG(st.st_mode)) 1724 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1725 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1726 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1727 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1728 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1729 }
1000 } 1730 }
1001 closedir(dir); 1731 closedir(dir);
1002}
1003 1732
1733 return ret;
1734}
1735static int scanelf_dir(const char *path)
1736{
1737 return scanelf_dirat(root_fd, root_rel_path(path));
1738}
1739
1004static int scanelf_from_file(char *filename) 1740static int scanelf_from_file(const char *filename)
1005{ 1741{
1006 FILE *fp = NULL; 1742 FILE *fp;
1007 char *p; 1743 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1744 size_t len;
1745 int ret;
1009 1746
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1747 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1748 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1749 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1750 return 1;
1014 1751
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1752 path = NULL;
1753 len = 0;
1754 ret = 0;
1755 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1756 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1757 *p = 0;
1018 search_path = path; 1758 search_path = path;
1019 scanelf_dir(path); 1759 ret = scanelf_dir(path);
1020 } 1760 }
1761 free(path);
1762
1021 if (fp != stdin) 1763 if (fp != stdin)
1022 fclose(fp); 1764 fclose(fp);
1765
1023 return 0; 1766 return ret;
1024} 1767}
1025 1768
1026static void load_ld_so_conf() 1769#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1770
1771static int _load_ld_cache_config(const char *fname)
1027{ 1772{
1028 FILE *fp = NULL; 1773 FILE *fp = NULL;
1029 char *p; 1774 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1775 size_t len;
1031 int i = 0; 1776 int curr_fd = -1;
1032 1777
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1778 fp = fopenat_r(root_fd, root_rel_path(fname));
1779 if (fp == NULL)
1034 return; 1780 return -1;
1035 1781
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1782 path = NULL;
1037 if (*path != '/') 1783 len = 0;
1038 continue; 1784 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1785 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1786 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1787 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1788 *p = 0;
1044 1789
1045 ldpaths[i++] = xstrdup(path); 1790 /* recursive includes of the same file will make this segfault. */
1791 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1792 glob_t gl;
1793 size_t x;
1794 const char *gpath;
1046 1795
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1796 /* re-use existing path buffer ... need to be creative */
1048 break; 1797 if (path[8] != '/')
1798 gpath = memcpy(path + 3, "/etc/", 5);
1799 else
1800 gpath = path + 8;
1801 if (root_fd != AT_FDCWD) {
1802 if (curr_fd == -1) {
1803 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1804 if (fchdir(root_fd))
1805 errp("unable to change to root dir");
1806 }
1807 gpath = root_rel_path(gpath);
1808 }
1809
1810 if (glob(gpath, 0, NULL, &gl) == 0) {
1811 for (x = 0; x < gl.gl_pathc; ++x) {
1812 /* try to avoid direct loops */
1813 if (strcmp(gl.gl_pathv[x], fname) == 0)
1814 continue;
1815 _load_ld_cache_config(gl.gl_pathv[x]);
1816 }
1817 globfree(&gl);
1818 }
1819
1820 /* failed globs are ignored by glibc */
1821 continue;
1049 } 1822 }
1050 ldpaths[i] = NULL; 1823
1824 if (*path != '/')
1825 continue;
1826
1827 xarraypush_str(ldpaths, path);
1828 }
1829 free(path);
1051 1830
1052 fclose(fp); 1831 fclose(fp);
1832
1833 if (curr_fd != -1) {
1834 if (fchdir(curr_fd))
1835 /* don't care */;
1836 close(curr_fd);
1837 }
1838
1839 return 0;
1840}
1841
1842#elif defined(__FreeBSD__) || defined(__DragonFly__)
1843
1844static int _load_ld_cache_config(const char *fname)
1845{
1846 FILE *fp = NULL;
1847 char *b = NULL, *p;
1848 struct elfhints_hdr hdr;
1849
1850 fp = fopenat_r(root_fd, root_rel_path(fname));
1851 if (fp == NULL)
1852 return -1;
1853
1854 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1855 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1856 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1857 {
1858 fclose(fp);
1859 return -1;
1860 }
1861
1862 b = xmalloc(hdr.dirlistlen + 1);
1863 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1864 fclose(fp);
1865 free(b);
1866 return -1;
1867 }
1868
1869 while ((p = strsep(&b, ":"))) {
1870 if (*p == '\0')
1871 continue;
1872 xarraypush_str(ldpaths, p);
1873 }
1874
1875 free(b);
1876 fclose(fp);
1877 return 0;
1878}
1879
1880#else
1881#ifdef __ELF__
1882#warning Cache config support not implemented for your target
1883#endif
1884static int _load_ld_cache_config(const char *fname)
1885{
1886 return 0;
1887}
1888#endif
1889
1890static void load_ld_cache_config(const char *fname)
1891{
1892 bool scan_l, scan_ul, scan_ull;
1893 size_t n;
1894 const char *ldpath;
1895
1896 _load_ld_cache_config(fname);
1897
1898 scan_l = scan_ul = scan_ull = false;
1899 if (array_cnt(ldpaths)) {
1900 array_for_each(ldpaths, n, ldpath) {
1901 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1902 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1903 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1904 }
1905 }
1906
1907 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1908 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1909 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1053} 1910}
1054 1911
1055/* scan /etc/ld.so.conf for paths */ 1912/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1913static void scanelf_ldpath(void)
1057{ 1914{
1058 char scan_l, scan_ul, scan_ull; 1915 size_t n;
1059 int i = 0; 1916 const char *ldpath;
1060 1917
1061 if (!ldpaths[0]) 1918 array_for_each(ldpaths, n, ldpath)
1062 err("Unable to load any paths from ld.so.conf");
1063
1064 scan_l = scan_ul = scan_ull = 0;
1065
1066 while (ldpaths[i]) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1919 scanelf_dir(ldpath);
1071 ++i;
1072 }
1073
1074 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1920}
1078 1921
1079/* scan env PATH for paths */ 1922/* scan env PATH for paths */
1080static void scanelf_envpath() 1923static void scanelf_envpath(void)
1081{ 1924{
1082 char *path, *p; 1925 char *path, *p;
1083 1926
1084 path = getenv("PATH"); 1927 path = getenv("PATH");
1085 if (!path) 1928 if (!path)
1092 } 1935 }
1093 1936
1094 free(path); 1937 free(path);
1095} 1938}
1096 1939
1097 1940/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1941#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1942#define a_argument required_argument
1101static struct option const long_opts[] = { 1943static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1944 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1945 {"ldpath", no_argument, NULL, 'l'},
1946 {"use-ldpath",no_argument, NULL, 129},
1947 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1948 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1949 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1950 {"symlink", no_argument, NULL, 'y'},
1951 {"archives", no_argument, NULL, 'A'},
1952 {"ldcache", no_argument, NULL, 'L'},
1953 {"fix", no_argument, NULL, 'X'},
1954 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1955 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1956 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1957 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1958 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1959 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1960 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1961 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1962 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 1963 {"symbol", a_argument, NULL, 's'},
1964 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 1965 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 1966 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 1967 {"textrels", no_argument, NULL, 'T'},
1968 {"etype", a_argument, NULL, 'E'},
1969 {"bits", a_argument, NULL, 'M'},
1970 {"endian", no_argument, NULL, 'D'},
1971 {"osabi", no_argument, NULL, 'I'},
1972 {"eabi", no_argument, NULL, 'Y'},
1973 {"perms", a_argument, NULL, 'O'},
1974 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 1975 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 1976 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 1977 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 1978 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 1979 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 1980 {"file", a_argument, NULL, 'o'},
1981 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 1982 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 1983 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 1984 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 1985 {NULL, no_argument, NULL, 0x0}
1130}; 1986};
1131 1987
1132static const char *opts_help[] = { 1988static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 1989 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 1990 "Scan all directories in /etc/ld.so.conf",
1991 "Use ld.so.conf to show full path (use with -r/-n)",
1992 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 1993 "Scan directories recursively",
1136 "Don't recursively cross mount points", 1994 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 1995 "Don't scan symlinks",
1996 "Scan archives (.a files)",
1997 "Utilize ld.so.cache to show full path (use with -r/-n)",
1998 "Try and 'fix' bad things (use with -r/-e)",
1999 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 2000 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 2001 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 2002 "Print TEXTREL information",
1141 "Print RPATH information", 2003 "Print RPATH information",
1142 "Print NEEDED information", 2004 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 2005 "Print INTERP information",
1145 "Print BIND information", 2006 "Print BIND information",
1146 "Print SONAME information", 2007 "Print SONAME information",
1147 "Find a specified symbol", 2008 "Find a specified symbol",
2009 "Find a specified section",
1148 "Find a specified library", 2010 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 2011 "Use regex matching rather than string compare (use with -s)",
1150 "Locate cause of TEXTREL", 2012 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 2013 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2014 "Print only ELF files matching numeric bits",
2015 "Print Endianness",
2016 "Print OSABI",
2017 "Print EABI (EM_ARM Only)",
2018 "Print only ELF files matching octal permissions",
2019 "Print ELF file size",
2020 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 2021 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 2022 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 2023 "Use specified format for output",
1155 "Read input stream from a filename", 2024 "Read input stream from a filename",
1156 "Write output stream to a filename", 2025 "Write output stream to a filename",
2026 "Don't emit color in output",
1157 "Don't display the header", 2027 "Don't display the header",
1158 "Print this help and exit", 2028 "Print this help and exit",
1159 "Print version and exit", 2029 "Print version and exit",
1160 NULL 2030 NULL
1161}; 2031};
1163/* display usage and exit */ 2033/* display usage and exit */
1164static void usage(int status) 2034static void usage(int status)
1165{ 2035{
1166 unsigned long i; 2036 unsigned long i;
1167 printf("* Scan ELF binaries for stuff\n\n" 2037 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2038 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2039 printf("Options: -[%s]\n", PARSE_FLAGS);
1170 for (i = 0; long_opts[i].name; ++i) 2040 for (i = 0; long_opts[i].name; ++i)
1171 if (long_opts[i].has_arg == no_argument) 2041 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2042 printf(" -%c, --%-14s* %s\n", long_opts[i].val,
2043 long_opts[i].name, opts_help[i]);
2044 else if (long_opts[i].val > '~')
2045 printf(" --%-7s <arg> * %s\n",
1173 long_opts[i].name, opts_help[i]); 2046 long_opts[i].name, opts_help[i]);
1174 else 2047 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2048 printf(" -%c, --%-7s <arg> * %s\n", long_opts[i].val,
1176 long_opts[i].name, opts_help[i]); 2049 long_opts[i].name, opts_help[i]);
1177 2050
1178 if (status != EXIT_SUCCESS) 2051 puts("\nFor more information, see the scanelf(1) manpage");
1179 exit(status);
1180
1181 puts("\nThe format modifiers for the -F option are:");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2052 exit(status);
1192} 2053}
1193 2054
1194/* parse command line arguments and preform needed actions */ 2055/* parse command line arguments and preform needed actions */
2056#define do_pax_state(option, flag) \
2057 if (islower(option)) { \
2058 flags &= ~PF_##flag; \
2059 flags |= PF_NO##flag; \
2060 } else { \
2061 flags &= ~PF_NO##flag; \
2062 flags |= PF_##flag; \
2063 }
1195static void parseargs(int argc, char *argv[]) 2064static int parseargs(int argc, char *argv[])
1196{ 2065{
1197 int i; 2066 int i;
1198 char *from_file = NULL; 2067 const char *from_file = NULL;
2068 int ret = 0;
2069 char load_cache_config = 0;
1199 2070
1200 opterr = 0; 2071 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2072 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2073 switch (i) {
1203 2074
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2078 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2079 exit(EXIT_SUCCESS);
1209 break; 2080 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2081 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2082 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2083 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2084 from_file = optarg;
2085 break;
2086 case 'E':
2087 match_etypes = optarg;
2088 break;
2089 case 'M':
2090 match_bits = atoi(optarg);
2091 if (match_bits == 0) {
2092 if (strcmp(optarg, "ELFCLASS32") == 0)
2093 match_bits = 32;
2094 if (strcmp(optarg, "ELFCLASS64") == 0)
2095 match_bits = 64;
2096 }
2097 break;
2098 case 'O':
2099 if (sscanf(optarg, "%o", &match_perms) == -1)
2100 match_bits = 0;
1214 break; 2101 break;
1215 case 'o': { 2102 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2103 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2104 errp("Could not freopen(%s)", optarg);
1219 SET_STDOUT(fp);
1220 break; 2105 break;
1221 } 2106 }
1222 2107 case 'k':
2108 xarraypush_str(find_section_arr, optarg);
2109 break;
1223 case 's': { 2110 case 's': {
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2111 if (find_sym) warn("You prob don't want to specify -s twice");
1225 find_sym = optarg; 2112 find_sym = optarg;
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1227 sprintf(versioned_symname, "%s@", find_sym);
1228 break; 2113 break;
1229 } 2114 }
1230 case 'N': { 2115 case 'N':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2116 xarraypush_str(find_lib_arr, optarg);
1232 find_lib = optarg;
1233 break; 2117 break;
1234 }
1235
1236 case 'F': { 2118 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2119 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2120 out_format = optarg;
1239 break; 2121 break;
1240 } 2122 }
2123 case 'z': {
2124 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2125 size_t x;
1241 2126
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2127 for (x = 0; x < strlen(optarg); x++) {
2128 switch (optarg[x]) {
2129 case 'p':
2130 case 'P':
2131 do_pax_state(optarg[x], PAGEEXEC);
2132 break;
2133 case 's':
2134 case 'S':
2135 do_pax_state(optarg[x], SEGMEXEC);
2136 break;
2137 case 'm':
2138 case 'M':
2139 do_pax_state(optarg[x], MPROTECT);
2140 break;
2141 case 'e':
2142 case 'E':
2143 do_pax_state(optarg[x], EMUTRAMP);
2144 break;
2145 case 'r':
2146 case 'R':
2147 do_pax_state(optarg[x], RANDMMAP);
2148 break;
2149 case 'x':
2150 case 'X':
2151 do_pax_state(optarg[x], RANDEXEC);
2152 break;
2153 default:
2154 break;
2155 }
2156 }
2157 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2158 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2159 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2160 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2161 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2162 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2163 setpax = flags;
2164 break;
2165 }
2166 case 'Z': show_size = 1; break;
1243 case 'L': printcache = 1; break; 2167 case 'g': g_match = 1; break;
2168 case 'L': load_cache_config = use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2169 case 'y': scan_symlink = 0; break;
2170 case 'A': scan_archives = 1; break;
2171 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2172 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2173 case 'l': load_cache_config = scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2174 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2175 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2176 case 'm': dir_crossmount = 0; break;
2177 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2178 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2179 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2180 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2181 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2182 case 'n': show_needed = 1; break;
1256 case 'b': show_bind = 1; break; 2184 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2185 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2186 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2187 case 'q': be_quiet = 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2188 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2189 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2190 case 'D': show_endian = 1; break;
2191 case 'I': show_osabi = 1; break;
2192 case 'Y': show_eabi = 1; break;
2193 case 128:
2194 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2195 if (root_fd == -1)
2196 err("Could not open root: %s", optarg);
2197 break;
2198 case 129: load_cache_config = use_ldpath = 1; break;
1263 case ':': 2199 case ':':
1264 err("Option missing parameter\n"); 2200 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2201 case '?':
1266 err("Unknown option\n"); 2202 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2203 default:
1268 err("Unhandled option '%c'", i); 2204 err("Unhandled option '%c'; please report this", i);
1269 }
1270 } 2205 }
1271 2206 }
2207 if (show_textrels && be_verbose)
2208 has_objdump = bin_in_path("objdump");
2209 /* flatten arrays for display */
2210 if (array_cnt(find_lib_arr))
2211 find_lib = array_flatten_str(find_lib_arr);
2212 if (array_cnt(find_section_arr))
2213 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2214 /* let the format option override all other options */
1273 if (out_format) { 2215 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2216 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2217 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2218 show_textrels = show_perms = show_endian = show_size = \
2219 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2220 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2221 if (!IS_MODIFIER(out_format[i])) continue;
1279 2222
1280 switch (out_format[++i]) { 2223 switch (out_format[++i]) {
2224 case '+': break;
1281 case '%': break; 2225 case '%': break;
1282 case '#': break; 2226 case '#': break;
1283 case 'F': break; 2227 case 'F': break;
1284 case 'p': break; 2228 case 'p': break;
1285 case 'f': break; 2229 case 'f': break;
2230 case 'k': break;
1286 case 's': break; 2231 case 's': break;
1287 case 'N': break; 2232 case 'N': break;
1288 case 'o': break; 2233 case 'o': break;
2234 case 'a': break;
2235 case 'M': break;
2236 case 'Z': show_size = 1; break;
2237 case 'D': show_endian = 1; break;
2238 case 'I': show_osabi = 1; break;
2239 case 'Y': show_eabi = 1; break;
2240 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2241 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2242 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2243 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2244 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2245 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2246 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2247 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2248 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2249 case 'T': show_textrels = 1; break;
1298 default: 2250 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2251 err("invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2252 out_format[i], i+1);
1301 } 2253 }
1302 } 2254 }
1303 2255
1304 /* construct our default format */ 2256 /* construct our default format */
1305 } else { 2257 } else {
1306 size_t fmt_len = 30; 2258 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2259 out_format = xmalloc(sizeof(char) * fmt_len);
2260 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2261 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2262 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2263 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2264 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2265 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2266 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2267 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2268 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2269 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2270 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2271 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2272 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2273 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2274 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2275 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2276 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2277 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2278 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2279 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2280 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2281 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2282
1324 /* now lets actually do the scanning */ 2283 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2284 if (load_cache_config)
1326 load_ld_so_conf(); 2285 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2286 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2287 if (scan_envpath) scanelf_envpath();
2288 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2289 from_file = "-";
1329 if (from_file) { 2290 if (from_file) {
1330 scanelf_from_file(from_file); 2291 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2292 from_file = *argv;
1333 } 2293 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2294 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2295 err("Nothing to scan !?");
1336 while (optind < argc) { 2296 while (optind < argc) {
1337 search_path = argv[optind++]; 2297 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2298 ret = scanelf_dir(search_path);
1339 } 2299 }
1340 2300
1341 /* clean up */ 2301 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2302 xarrayfree(ldpaths);
2303 xarrayfree(find_lib_arr);
2304 xarrayfree(find_section_arr);
2305 free(find_lib);
2306 free(find_section);
1345 2307
1346 if (ldcache != 0) 2308 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2309 munmap(ldcache, ldcache_size);
1348}
1349
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2310 return ret;
1358} 2311}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2312
1369 new_len = strlen(*dst) + strlen(src); 2313static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2314{
1384 static char my_app[2]; 2315 const char *delims = " \t\n";
1385 my_app[0] = append; 2316 char **envvals = NULL;
1386 my_app[1] = '\0'; 2317 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2318 int nentry;
1388}
1389 2319
2320 if ((env = getenv(envvar)) == NULL)
2321 return NULL;
1390 2322
2323 env = xstrdup(env);
2324 if (env == NULL)
2325 return NULL;
2326
2327 s = strtok(env, delims);
2328 if (s == NULL) {
2329 free(env);
2330 return NULL;
2331 }
2332
2333 nentry = 0;
2334 while (s != NULL) {
2335 ++nentry;
2336 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2337 envvals[nentry-1] = s;
2338 s = strtok(NULL, delims);
2339 }
2340 envvals[nentry] = NULL;
2341
2342 /* don't want to free(env) as it contains the memory that backs
2343 * the envvals array of strings */
2344 return envvals;
2345}
2346
2347static void parseenv(void)
2348{
2349 color_init(false);
2350 qa_textrels = get_split_env("QA_TEXTRELS");
2351 qa_execstack = get_split_env("QA_EXECSTACK");
2352 qa_wx_load = get_split_env("QA_WX_LOAD");
2353}
2354
2355#ifdef __PAX_UTILS_CLEANUP
2356static void cleanup(void)
2357{
2358 free(out_format);
2359 free(qa_textrels);
2360 free(qa_execstack);
2361 free(qa_wx_load);
2362}
2363#endif
1391 2364
1392int main(int argc, char *argv[]) 2365int main(int argc, char *argv[])
1393{ 2366{
2367 int ret;
1394 if (argc < 2) 2368 if (argc < 2)
1395 usage(EXIT_FAILURE); 2369 usage(EXIT_FAILURE);
2370 parseenv();
1396 parseargs(argc, argv); 2371 ret = parseargs(argc, argv);
1397 fclose(stdout); 2372 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2373#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2374 cleanup();
2375 warn("The calls to add/delete heap should be off:\n"
2376 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2377 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2378#endif
1401 return EXIT_SUCCESS; 2379 return ret;
1402} 2380}
2381
2382/* Match filename against entries in matchlist, return TRUE
2383 * if the file is listed */
2384static int file_matches_list(const char *filename, char **matchlist)
2385{
2386 char **file;
2387 char *match;
2388 char buf[__PAX_UTILS_PATH_MAX];
2389
2390 if (matchlist == NULL)
2391 return 0;
2392
2393 for (file = matchlist; *file != NULL; file++) {
2394 if (search_path) {
2395 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2396 match = buf;
2397 } else {
2398 match = *file;
2399 }
2400 if (fnmatch(match, filename, 0) == 0)
2401 return 1;
2402 }
2403 return 0;
2404}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.240

  ViewVC Help
Powered by ViewVC 1.1.20