/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.243
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2007 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.243 2012/04/29 05:41:14 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.243 2012/04/29 05:41:14 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
67static char *find_lib = NULL; 49static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 53static char *out_format = NULL;
69static char *search_path = NULL; 54static char *search_path = NULL;
55static char fix_elf = 0;
70static char gmatch = 0; 56static char g_match = 0;
71static char printcache = 0; 57static char use_ldcache = 0;
58static char use_ldpath = 0;
72 59
60static char **qa_textrels = NULL;
61static char **qa_execstack = NULL;
62static char **qa_wx_load = NULL;
63static int root_fd = AT_FDCWD;
73 64
74caddr_t ldcache = 0; 65static int match_bits = 0;
66static unsigned int match_perms = 0;
67static void *ldcache = NULL;
75size_t ldcache_size = 0; 68static size_t ldcache_size = 0;
69static unsigned long setpax = 0UL;
76 70
71static int has_objdump = 0;
72
73/* find the path to a file by name */
74static int bin_in_path(const char *fname)
75{
76 char fullpath[__PAX_UTILS_PATH_MAX];
77 char *path, *p;
78
79 path = getenv("PATH");
80 if (!path)
81 return 0;
82
83 while ((p = strrchr(path, ':')) != NULL) {
84 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
85 *p = 0;
86 if (access(fullpath, R_OK) != -1)
87 return 1;
88 }
89
90 return 0;
91}
92
93static FILE *fopenat_r(int dir_fd, const char *path)
94{
95 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
96 if (fd == -1)
97 return NULL;
98 return fdopen(fd, "re");
99}
100
101static const char *root_rel_path(const char *path)
102{
103 /*
104 * openat() will ignore the dirfd if path starts with
105 * a /, so consume all of that noise
106 *
107 * XXX: we don't handle relative paths like ../ that
108 * break out of the --root option, but for now, just
109 * don't do that :P.
110 */
111 if (root_fd != AT_FDCWD) {
112 while (*path == '/')
113 ++path;
114 if (*path == '\0')
115 path = ".";
116 }
117
118 return path;
119}
120
121/* 1 on failure. 0 otherwise */
122static int rematch(const char *regex, const char *match, int cflags)
123{
124 regex_t preg;
125 int ret;
126
127 if ((match == NULL) || (regex == NULL))
128 return EXIT_FAILURE;
129
130 if ((ret = regcomp(&preg, regex, cflags))) {
131 char err[256];
132
133 if (regerror(ret, &preg, err, sizeof(err)))
134 fprintf(stderr, "regcomp failed: %s", err);
135 else
136 fprintf(stderr, "regcomp failed");
137
138 return EXIT_FAILURE;
139 }
140 ret = regexec(&preg, match, 0, NULL, 0);
141 regfree(&preg);
142
143 return ret;
144}
145
77/* sub-funcs for scanelf_file() */ 146/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 147static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 148{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 149 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
150
151 /* debug sections */
152 void *symtab = elf_findsecbyname(elf, ".symtab");
153 void *strtab = elf_findsecbyname(elf, ".strtab");
154 /* runtime sections */
155 void *dynsym = elf_findsecbyname(elf, ".dynsym");
156 void *dynstr = elf_findsecbyname(elf, ".dynstr");
157
81#define GET_SYMTABS(B) \ 158#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 159 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \
84 /* debug sections */ \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \
87 /* runtime sections */ \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \
90 if (symtab && dynsym) { \ 160 if (symtab && dynsym) { \
161 Elf ## B ## _Shdr *esymtab = symtab; \
162 Elf ## B ## _Shdr *edynsym = dynsym; \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 163 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 164 } else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 165 *sym = symtab ? symtab : dynsym; \
94 } \
95 if (strtab && dynstr) { \ 166 if (strtab && dynstr) { \
167 Elf ## B ## _Shdr *estrtab = strtab; \
168 Elf ## B ## _Shdr *edynstr = dynstr; \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 169 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 170 } else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 171 *str = strtab ? strtab : dynstr; \
99 } \
100 } 172 }
101 GET_SYMTABS(32) 173 GET_SYMTABS(32)
102 GET_SYMTABS(64) 174 GET_SYMTABS(64)
175
176 if (*sym && *str)
177 return;
178
179 /*
180 * damn, they're really going to make us work for it huh?
181 * reconstruct the section header info out of the dynamic
182 * tags so we can see what symbols this guy uses at runtime.
183 */
184#define GET_SYMTABS_DT(B) \
185 if (elf->elf_class == ELFCLASS ## B) { \
186 size_t i; \
187 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
188 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
189 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
190 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
191 Elf ## B ## _Dyn *dyn; \
192 Elf ## B ## _Off offset; \
193 \
194 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
195 vsym = vstr = vhash = vgnu_hash = 0; \
196 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
197 memset(&str_shdr, 0, sizeof(str_shdr)); \
198 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
199 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
200 continue; \
201 \
202 offset = EGET(phdr[i].p_offset); \
203 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
204 continue; \
205 \
206 dyn = DYN ## B (elf->vdata + offset); \
207 while (EGET(dyn->d_tag) != DT_NULL) { \
208 switch (EGET(dyn->d_tag)) { \
209 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
210 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
211 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
212 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
213 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
214 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
215 } \
216 ++dyn; \
217 } \
218 if (vsym && vstr) \
219 break; \
220 } \
221 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
222 return; \
223 \
224 /* calc offset into the ELF by finding the load addr of the syms */ \
225 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
226 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
227 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
228 offset = EGET(phdr[i].p_offset); \
229 \
230 if (EGET(phdr[i].p_type) != PT_LOAD) \
231 continue; \
232 \
233 if (vhash >= vaddr && vhash < vaddr + filesz) { \
234 /* Scan the hash table to see how many entries we have */ \
235 Elf32_Word max_sym_idx = 0; \
236 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
237 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
238 Elf32_Word nchains = EGET(hashtbl[1]); \
239 Elf32_Word *buckets = &hashtbl[2]; \
240 Elf32_Word *chains = &buckets[nbuckets]; \
241 Elf32_Word sym_idx; \
242 \
243 for (b = 0; b < nbuckets; ++b) { \
244 if (!buckets[b]) \
245 continue; \
246 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
247 if (max_sym_idx < sym_idx) \
248 max_sym_idx = sym_idx; \
249 } \
250 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
251 } \
252 \
253 if (vsym >= vaddr && vsym < vaddr + filesz) { \
254 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
255 *sym = &sym_shdr; \
256 } \
257 \
258 if (vstr >= vaddr && vstr < vaddr + filesz) { \
259 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
260 *str = &str_shdr; \
261 } \
262 } \
263 }
264 GET_SYMTABS_DT(32)
265 GET_SYMTABS_DT(64)
103} 266}
267
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 268static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 269{
106 static char ret[7]; 270 static char ret[7];
107 unsigned long i, shown; 271 unsigned long i, shown;
108 272
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 281 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 282 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 283 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 284 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 285 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 286 if (fix_elf && setpax) { \
287 /* set the paxctl flags */ \
288 ESET(phdr[i].p_flags, setpax); \
289 } \
290 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 291 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 292 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 293 *found_pax = 1; \
126 ++shown; \ 294 ++shown; \
127 break; \ 295 break; \
128 } \ 296 } \
129 } 297 }
130 SHOW_PAX(32) 298 SHOW_PAX(32)
131 SHOW_PAX(64) 299 SHOW_PAX(64)
132 } 300 }
301
302 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
303 * was found. This is known to break ELFs on glibc systems,
304 * and mainline PaX has deprecated use of this for a long time.
305 * We could support changing PT_GNU_STACK, but that doesn't
306 * seem like it's worth the effort. #411919
307 */
133 308
134 /* fall back to EI_PAX if no PT_PAX was found */ 309 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 310 if (!*ret) {
136 static char *paxflags; 311 static char *paxflags;
137 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 312 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
150 325
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 326static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 327{
153 static char ret[12]; 328 static char ret[12];
154 char *found; 329 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 330 unsigned long i, shown, multi_stack, multi_relro, multi_load;
331 int max_pt_load;
157 332
158 if (!show_phdr) return NULL; 333 if (!show_phdr) return NULL;
159 334
160 memcpy(ret, "--- --- ---\0", 12); 335 memcpy(ret, "--- --- ---\0", 12);
161 336
162 shown = 0; 337 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 338 multi_stack = multi_relro = multi_load = 0;
339 max_pt_load = elf_max_pt_load(elf);
164 340
341#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 342#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 343 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 344 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 345 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 346 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 347 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 348 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 349 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 350 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
351 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 352 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
353 if (file_matches_list(elf->filename, qa_execstack)) \
354 continue; \
175 found = found_phdr; \ 355 found = found_phdr; \
176 offset = 0; \ 356 offset = 0; \
177 check_flags = PF_X; \ 357 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 358 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
359 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 360 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 361 found = found_relro; \
181 offset = 4; \ 362 offset = 4; \
182 check_flags = PF_X; \ 363 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 364 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 365 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
366 if (multi_load++ > max_pt_load) \
367 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
368 if (file_matches_list(elf->filename, qa_wx_load)) \
369 continue; \
185 found = found_load; \ 370 found = found_load; \
186 offset = 8; \ 371 offset = 8; \
187 check_flags = PF_W|PF_X; \ 372 check_flags = PF_W|PF_X; \
188 } else \ 373 } else \
189 continue; \ 374 continue; \
190 flags = EGET(phdr[i].p_flags); \ 375 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 376 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 377 continue; \
378 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
379 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
380 ret[3] = ret[7] = '!'; \
381 flags = EGET(phdr[i].p_flags); \
382 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 383 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 384 *found = 1; \
195 ++shown; \ 385 ++shown; \
196 } \ 386 } \
197 } else if (elf->shdr != NULL) { \ 387 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 388 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 389 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 390 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
391 char *str; \
392 if ((void*)strtbl > elf->data_end) \
393 goto skip_this_shdr##B; \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 394 check_flags = SHF_WRITE|SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 395 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 396 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 397 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 398 str = elf->data + offset; \
399 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
400 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 401 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 402 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 403 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 404 continue; \
210 ++*found_phdr; \ 405 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 409 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 410 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 411 break; \
217 } \ 412 } \
218 } \ 413 } \
414 skip_this_shdr##B: \
219 if (!multi_stack) { \ 415 if (!multi_stack) { \
416 if (file_matches_list(elf->filename, qa_execstack)) \
417 return NULL; \
220 *found_phdr = 1; \ 418 *found_phdr = 1; \
221 shown = 1; \ 419 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 420 memcpy(ret, "!WX", 3); \
223 } \ 421 } \
224 } \ 422 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 427 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 428 return NULL;
231 else 429 else
232 return ret; 430 return ret;
233} 431}
432
433/*
434 * See if this ELF contains a DT_TEXTREL tag in any of its
435 * PT_DYNAMIC sections.
436 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 437static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 438{
236 static const char *ret = "TEXTREL"; 439 static const char *ret = "TEXTREL";
237 unsigned long i; 440 unsigned long i;
238 441
239 if (!show_textrel && !show_textrels) return NULL; 442 if (!show_textrel && !show_textrels) return NULL;
443
444 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 445
241 if (elf->phdr) { 446 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 447#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 448 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 449 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 450 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 451 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 452 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 453 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 454 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 455 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 456 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 457 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 458 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 459 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 460 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 461 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 462 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 471 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 472 return NULL;
268 else 473 else
269 return " - "; 474 return " - ";
270} 475}
476
477/*
478 * Scan the .text section to see if there are any relocations in it.
479 * Should rewrite this to check PT_LOAD sections that are marked
480 * Executable rather than the section named '.text'.
481 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 482static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 483{
273 unsigned long s, r, rmax; 484 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 485 void *symtab_void, *strtab_void, *text_void;
275 486
296 Elf ## B ## _Rela *rela; \ 507 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 508 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 509 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 510 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 511 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 512 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 513 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 514 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 515 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 516 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 517 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 518 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 519 } else \
309 continue; \ 520 continue; \
310 /* now see if any of the relocs are in the .text */ \ 521 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 522 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 537 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 538 if (be_verbose <= 2) continue; \
328 } else \ 539 } else \
329 *found_textrels = 1; \ 540 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 541 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 542 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
543 if ((void*)sym > elf->data_end) { \
544 warn("%s: corrupt ELF symbol", elf->filename); \
545 continue; \
546 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 547 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 548 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 549 sym += sym_max; \
335 else \ 550 else \
336 sym = NULL; \ 551 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 552 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 553 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 554 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 555 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 556 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 557 else \
343 printf("(memory/fake?)"); \ 558 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 559 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 560 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 561 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 562 func = NULL; \
348 offset_tmp = 0; \ 563 offset_tmp = 0; \
349 while (sym_max--) { \ 564 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 565 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 566 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 567 offset_tmp = EGET(sym->st_value); \
353 } \ 568 } \
354 ++sym; \ 569 ++sym; \
355 } \ 570 } \
356 printf(" in "); \ 571 printf(" in "); \
357 if (func && func->st_name) \ 572 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 573 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
574 if (r_offset > EGET(func->st_size)) \
575 printf("(optimized out: previous %s)", func_name); \
359 else \ 576 else \
360 printf("(NULL: fake?)"); \ 577 printf("%s", func_name); \
578 } else \
579 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 580 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
581 if (be_verbose && has_objdump) { \
582 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
583 char *sysbuf; \
584 size_t syslen; \
585 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
586 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
587 sysbuf = xmalloc(syslen); \
588 if (end_addr < r_offset) \
589 /* not uncommon when things are optimized out */ \
590 end_addr = r_offset + 0x100; \
591 snprintf(sysbuf, syslen, sysfmt, \
592 (unsigned long)offset_tmp, \
593 (unsigned long)end_addr, \
594 elf->filename, \
595 (unsigned long)r_offset); \
596 fflush(stdout); \
597 if (system(sysbuf)) /* don't care */; \
598 fflush(stdout); \
599 free(sysbuf); \
600 } \
362 } \ 601 } \
363 } } 602 } }
364 SHOW_TEXTRELS(32) 603 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 604 SHOW_TEXTRELS(64)
366 } 605 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 607 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 608
370 return NULL; 609 return NULL;
371} 610}
372 611
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 612static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
613{
375 struct stat st; 614 struct stat st;
376 switch (*item) { 615 switch (*item) {
377 case '/': break; 616 case '/': break;
378 case '.': 617 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 618 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 619 break;
620 case ':':
381 case '\0': 621 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 622 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 623 break;
384 case '$': 624 case '$':
385 if (fstat(elf->fd, &st) != -1) 625 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 626 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 627 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 628 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 629 break;
390 default: 630 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 631 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 632 break;
393 } 633 }
394} 634}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 635static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 636{
397 unsigned long i, s; 637 unsigned long i;
398 char *rpath, *runpath, **r; 638 char *rpath, *runpath, **r;
399 void *strtbl_void; 639 void *strtbl_void;
400 640
401 if (!show_rpath) return; 641 if (!show_rpath) return;
402 642
413 Elf ## B ## _Off offset; \ 653 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 654 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 655 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 656 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 657 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 658 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 659 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 660 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 661 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 662 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 663 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 664 if (word == DT_RPATH) { \
425 r = &rpath; \ 665 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 666 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 667 r = &runpath; \
431 } \ 671 } \
432 /* Verify the memory is somewhat sane */ \ 672 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 673 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 674 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 675 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 676 *r = elf->data + offset; \
677 /* cache the length in case we need to nuke this section later on */ \
678 if (fix_elf) \
679 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 680 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 681 if (be_quiet) { \
439 size_t len; \ 682 size_t len; \
440 char *start, *end; \ 683 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 684 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 685 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 686 start = *r; \
444 /* scan each path in : delimited list */ \ 687 /* scan each path in : delimited list */ \
445 while (start) { \ 688 while (start) { \
446 rpath_security_checks(elf, start); \ 689 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 690 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 691 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 692 if (use_ldcache) { \
693 size_t n; \
694 const char *ldpath; \
695 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 696 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 697 *r = end; \
698 /* corner case ... if RPATH reads "/usr/lib:", we want \
699 * to show ':' rather than '' */ \
700 if (end && end[1] != '\0') \
701 (*r)++; \
452 break; \ 702 break; \
453 } \ 703 } \
454 } \ 704 } \
455 if (!*r || !ldpaths[s] || !end) \ 705 if (!*r || !end) \
456 start = NULL; \ 706 break; \
457 else \ 707 else \
458 start = start + len + 1; \ 708 start = start + len + 1; \
459 } \ 709 } \
460 } \ 710 } \
711 if (*r) { \
712 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
713 /* just nuke it */ \
714 nuke_it##B: \
715 memset(*r, 0x00, offset); \
716 *r = NULL; \
717 ESET(dyn->d_tag, DT_DEBUG); \
718 ESET(dyn->d_un.d_ptr, 0); \
719 } else if (fix_elf) { \
720 /* try to clean "bad" paths */ \
721 size_t len, tmpdir_len; \
722 char *start, *end; \
723 const char *tmpdir; \
724 start = *r; \
725 tmpdir = (getenv("TMPDIR") ? : "."); \
726 tmpdir_len = strlen(tmpdir); \
727 while (1) { \
728 end = strchr(start, ':'); \
729 if (start == end) { \
730 eat_this_path##B: \
731 len = strlen(end); \
732 memmove(start, end+1, len); \
733 start[len-1] = '\0'; \
734 end = start - 1; \
735 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
736 if (!end) { \
737 if (start == *r) \
738 goto nuke_it##B; \
739 *--start = '\0'; \
740 } else \
741 goto eat_this_path##B; \
742 } \
743 if (!end) \
744 break; \
745 start = end + 1; \
746 } \
747 if (**r == '\0') \
748 goto nuke_it##B; \
749 } \
750 if (*r) \
461 if (*r) *found_rpath = 1; \ 751 *found_rpath = 1; \
752 } \
462 } \ 753 } \
463 ++dyn; \ 754 ++dyn; \
464 } \ 755 } \
465 } } 756 } }
466 SHOW_RPATH(32) 757 SHOW_RPATH(32)
488 779
489#define LDSO_CACHE_MAGIC "ld.so-" 780#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 781#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 782#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 783#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
784#define FLAG_ANY -1
785#define FLAG_TYPE_MASK 0x00ff
786#define FLAG_LIBC4 0x0000
787#define FLAG_ELF 0x0001
788#define FLAG_ELF_LIBC5 0x0002
789#define FLAG_ELF_LIBC6 0x0003
790#define FLAG_REQUIRED_MASK 0xff00
791#define FLAG_SPARC_LIB64 0x0100
792#define FLAG_IA64_LIB64 0x0200
793#define FLAG_X8664_LIB64 0x0300
794#define FLAG_S390_LIB64 0x0400
795#define FLAG_POWERPC_LIB64 0x0500
796#define FLAG_MIPS64_LIBN32 0x0600
797#define FLAG_MIPS64_LIBN64 0x0700
493 798
494static char *lookup_cache_lib(char *); 799#if defined(__GLIBC__) || defined(__UCLIBC__)
800
495static char *lookup_cache_lib(char *fname) 801static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 802{
497 int fd = 0; 803 int fd;
498 char *strs; 804 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 805 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 806 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 807 struct stat st;
502 808
503 typedef struct { 809 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 810 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 811 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 812 int nlibs;
507 } header_t; 813 } header_t;
814 header_t *header;
508 815
509 typedef struct { 816 typedef struct {
510 int flags; 817 int flags;
511 int sooffset; 818 int sooffset;
512 int liboffset; 819 int liboffset;
513 } libentry_t; 820 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 821 libentry_t *libent;
517 822
518 if (fname == NULL) 823 if (fname == NULL)
519 return NULL; 824 return NULL;
520 825
521 if (ldcache == 0) { 826 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 827 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 828 return NULL;
524 /* save the cache size for latter unmapping */ 829
830 fd = openat(root_fd, cachefile, O_RDONLY);
831 if (fd == -1)
832 return NULL;
833
834 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 835 ldcache_size = st.st_size;
836 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
837 close(fd);
526 838
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 839 if (ldcache == MAP_FAILED) {
840 ldcache = NULL;
528 return NULL; 841 return NULL;
842 }
529 843
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 844 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
845 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
846 {
847 munmap(ldcache, ldcache_size);
848 ldcache = NULL;
533 return NULL; 849 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 850 }
851 } else
852 header = ldcache;
538 853
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 854 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 855 strs = (char *) &libent[header->nlibs];
542 856
543 for (fd = 0; fd < header->nlibs; fd++) { 857 for (fd = 0; fd < header->nlibs; ++fd) {
858 /* This should be more fine grained, but for now we assume that
859 * diff arches will not be cached together, and we ignore the
860 * the different multilib mips cases.
861 */
862 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
863 continue;
864 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
865 continue;
866
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 867 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 868 continue;
869
870 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 871 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
872 break;
547 } 873 }
874
548 return buf; 875 return buf;
549} 876}
550 877
878#elif defined(__NetBSD__)
879static char *lookup_cache_lib(elfobj *elf, const char *fname)
880{
881 static char buf[__PAX_UTILS_PATH_MAX] = "";
882 static struct stat st;
883 size_t n;
884 char *ldpath;
885
886 array_for_each(ldpath, n, ldpath) {
887 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
888 continue; /* if the pathname is too long, or something went wrong, ignore */
889
890 if (stat(buf, &st) != 0)
891 continue; /* if the lib doesn't exist in *ldpath, look further */
892
893 /* NetBSD doesn't actually do sanity checks, it just loads the file
894 * and if that doesn't work, continues looking in other directories.
895 * This cannot easily be safely emulated, unfortunately. For now,
896 * just assume that if it exists, it's a valid library. */
897
898 return buf;
899 }
900
901 /* not found in any path */
902 return NULL;
903}
904#else
905#ifdef __ELF__
906#warning Cache support not implemented for your target
907#endif
908static char *lookup_cache_lib(elfobj *elf, const char *fname)
909{
910 return NULL;
911}
912#endif
913
914static char *lookup_config_lib(elfobj *elf, char *fname)
915{
916 static char buf[__PAX_UTILS_PATH_MAX] = "";
917 const char *ldpath;
918 size_t n;
919
920 array_for_each(ldpaths, n, ldpath) {
921 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
922 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
923 return buf;
924 }
925
926 return NULL;
927}
551 928
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 929static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 930{
554 unsigned long i; 931 unsigned long i;
555 char *needed; 932 char *needed;
556 void *strtbl_void; 933 void *strtbl_void;
557 char *p; 934 char *p;
558 935
936 /*
937 * -n -> op==0 -> print all
938 * -N -> op==1 -> print requested
939 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 940 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
941 return NULL;
560 942
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 943 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 944
563 if (elf->phdr && strtbl_void) { 945 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 946#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 948 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 949 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 950 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 951 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 952 Elf ## B ## _Off offset; \
953 size_t matched = 0; \
954 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 955 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 956 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
957 continue; \
573 offset = EGET(phdr[i].p_offset); \ 958 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 959 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
960 continue; \
961 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 962 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 963 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 964 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 965 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 966 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 967 ++dyn; \
581 continue; \ 968 continue; \
582 } \ 969 } \
583 needed = (char*)(elf->data + offset); \ 970 needed = elf->data + offset; \
584 if (op == 0) { \ 971 if (op == 0) { \
972 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 973 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 974 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 975 if (use_ldpath) { \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 976 if ((p = lookup_config_lib(elf, needed)) != NULL) \
589 needed = p; \ 977 needed = p; \
978 } else if (use_ldcache) { \
979 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
980 needed = p; \
981 } \
590 xstrcat(ret, needed, ret_len); \ 982 xstrcat(ret, needed, ret_len); \
591 } \ 983 } \
592 *found_needed = 1; \ 984 *found_needed = 1; \
593 } else { \ 985 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 986 /* -N -> print matching entries */ \
987 size_t n; \
988 const char *find_lib_name; \
989 \
990 array_for_each(find_lib_arr, n, find_lib_name) { \
991 int invert = 1; \
992 if (find_lib_name[0] == '!') \
993 invert = 0, ++find_lib_name; \
994 if (!strcmp(find_lib_name, needed) == invert) \
995 ++matched; \
996 } \
997 \
998 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 999 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 1000 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 1001 } \
598 } \ 1002 } \
599 } \ 1003 } \
600 ++dyn; \ 1004 ++dyn; \
601 } \ 1005 } \
630} 1034}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1035static char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1036{
633 unsigned long i; 1037 unsigned long i;
634 struct stat s; 1038 struct stat s;
1039 char dynamic = 0;
635 1040
636 if (!show_bind) return NULL; 1041 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1042 if (!elf->phdr) return NULL;
638 1043
639#define SHOW_BIND(B) \ 1044#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1046 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1047 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1048 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1049 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1050 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1051 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1052 dynamic = 1; \
647 offset = EGET(phdr[i].p_offset); \ 1053 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1054 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1055 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1056 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1057 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1058 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1059 { \
654 if (be_quiet) return NULL; \ 1060 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1068 SHOW_BIND(32)
663 SHOW_BIND(64) 1069 SHOW_BIND(64)
664 1070
665 if (be_wewy_wewy_quiet) return NULL; 1071 if (be_wewy_wewy_quiet) return NULL;
666 1072
1073 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1074 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1075 return NULL;
669 } else { 1076 } else {
670 *found_bind = 1; 1077 *found_bind = 1;
671 return (char *) "LAZY"; 1078 return (char *)(dynamic ? "LAZY" : "STATIC");
672 } 1079 }
673} 1080}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1081static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1082{
676 unsigned long i; 1083 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1095 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1096 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1097 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1098 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1099 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1100 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1101 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1102 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1103 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1104 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1105 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1106 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1107 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1108 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1109 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1110 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1111 ++dyn; \
705 continue; \ 1112 continue; \
706 } \ 1113 } \
707 soname = (char*)(elf->data + offset); \ 1114 soname = elf->data + offset; \
708 *found_soname = 1; \ 1115 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1116 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1117 } \
711 ++dyn; \ 1118 ++dyn; \
712 } \ 1119 } \
715 SHOW_SONAME(64) 1122 SHOW_SONAME(64)
716 } 1123 }
717 1124
718 return NULL; 1125 return NULL;
719} 1126}
1127
1128/*
1129 * We support the symbol form:
1130 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1131 * If the symbol name is empty, then all symbols are matched.
1132 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1133 * Do not rely on this output format at all.
1134 * Otherwise the symbol name is used to search (either regex or string compare).
1135 * If the first char of the symbol name is a plus ("+"), then only match
1136 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1137 * Putting modifiers in between the percent signs allows for more in depth
1138 * filters. There are groups of modifiers. If you don't specify a member
1139 * of a group, then all types in that group are matched. The current
1140 * groups and their types are:
1141 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1142 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1143 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1144 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1145 * You can search for multiple symbols at once by seperating with a comma (",").
1146 *
1147 * Some examples:
1148 * ELFs with a weak function "foo":
1149 * scanelf -s %wf%foo <ELFs>
1150 * ELFs that define the symbol "main":
1151 * scanelf -s +main <ELFs>
1152 * scanelf -s %d%main <ELFs>
1153 * ELFs that refer to the undefined symbol "brk":
1154 * scanelf -s -brk <ELFs>
1155 * scanelf -s %u%brk <ELFs>
1156 * All global defined objects in an ELF:
1157 * scanelf -s %ogd% <ELF>
1158 */
1159static void
1160scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1161 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1162{
1163 char *this_sym, *next_sym, saved = saved;
1164
1165 /* allow the user to specify a comma delimited list of symbols to search for */
1166 next_sym = NULL;
1167 do {
1168 bool inc_notype, inc_object, inc_func, inc_file,
1169 inc_local, inc_global, inc_weak,
1170 inc_def, inc_undef, inc_abs, inc_common;
1171
1172 if (next_sym) {
1173 next_sym[-1] = saved;
1174 this_sym = next_sym;
1175 } else
1176 this_sym = find_sym;
1177 if ((next_sym = strchr(this_sym, ','))) {
1178 /* make parsing easier by killing the comma temporarily */
1179 saved = *next_sym;
1180 *next_sym = '\0';
1181 next_sym += 1;
1182 }
1183
1184 /* symbol selection! */
1185 inc_notype = inc_object = inc_func = inc_file = \
1186 inc_local = inc_global = inc_weak = \
1187 inc_def = inc_undef = inc_abs = inc_common = \
1188 (*this_sym != '%');
1189
1190 /* parse the contents of %...% */
1191 if (!inc_notype) {
1192 while (*(this_sym++)) {
1193 if (*this_sym == '%') {
1194 ++this_sym;
1195 break;
1196 }
1197 switch (*this_sym) {
1198 case 'n': inc_notype = true; break;
1199 case 'o': inc_object = true; break;
1200 case 'f': inc_func = true; break;
1201 case 'F': inc_file = true; break;
1202 case 'l': inc_local = true; break;
1203 case 'g': inc_global = true; break;
1204 case 'w': inc_weak = true; break;
1205 case 'd': inc_def = true; break;
1206 case 'u': inc_undef = true; break;
1207 case 'a': inc_abs = true; break;
1208 case 'c': inc_common = true; break;
1209 default: err("invalid symbol selector '%c'", *this_sym);
1210 }
1211 }
1212
1213 /* If no types are matched, not match all */
1214 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1215 inc_notype = inc_object = inc_func = inc_file = true;
1216 if (!inc_local && !inc_global && !inc_weak)
1217 inc_local = inc_global = inc_weak = true;
1218 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1219 inc_def = inc_undef = inc_abs = inc_common = true;
1220
1221 /* backwards compat for defined/undefined short hand */
1222 } else if (*this_sym == '+') {
1223 inc_undef = false;
1224 ++this_sym;
1225 } else if (*this_sym == '-') {
1226 inc_def = inc_abs = inc_common = false;
1227 ++this_sym;
1228 }
1229
1230 /* filter symbols */
1231 if ((!inc_notype && stt == STT_NOTYPE) || \
1232 (!inc_object && stt == STT_OBJECT) || \
1233 (!inc_func && stt == STT_FUNC ) || \
1234 (!inc_file && stt == STT_FILE ) || \
1235 (!inc_local && stb == STB_LOCAL ) || \
1236 (!inc_global && stb == STB_GLOBAL) || \
1237 (!inc_weak && stb == STB_WEAK ) || \
1238 (!inc_def && shn && shn < SHN_LORESERVE) || \
1239 (!inc_undef && shn == SHN_UNDEF ) || \
1240 (!inc_abs && shn == SHN_ABS ) || \
1241 (!inc_common && shn == SHN_COMMON))
1242 continue;
1243
1244 if (*this_sym == '*') {
1245 /* a "*" symbol gets you debug output */
1246 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1247 ((*found_sym == 0) ? "\n\t" : "\t"),
1248 elf->base_filename,
1249 size,
1250 get_elfstttype(stt),
1251 get_elfstbtype(stb),
1252 get_elfshntype(shn),
1253 symname);
1254 goto matched;
1255
1256 } else {
1257 if (g_match) {
1258 /* regex match the symbol */
1259 if (rematch(this_sym, symname, REG_EXTENDED) != 0)
1260 continue;
1261
1262 } else if (*this_sym) {
1263 /* give empty symbols a "pass", else do a normal compare */
1264 const size_t len = strlen(this_sym);
1265 if (!(strncmp(this_sym, symname, len) == 0 &&
1266 /* Accept unversioned symbol names */
1267 (symname[len] == '\0' || symname[len] == '@')))
1268 continue;
1269 }
1270
1271 if (be_semi_verbose) {
1272 char buf[1024];
1273 snprintf(buf, sizeof(buf), "%lX %s %s",
1274 size,
1275 get_elfstttype(stt),
1276 this_sym);
1277 *ret = xstrdup(buf);
1278 } else {
1279 if (*ret) xchrcat(ret, ',', ret_len);
1280 xstrcat(ret, symname, ret_len);
1281 }
1282
1283 goto matched;
1284 }
1285 } while (next_sym);
1286
1287 return;
1288
1289 matched:
1290 *found_sym = 1;
1291 if (next_sym)
1292 next_sym[-1] = saved;
1293}
1294
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1295static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1296{
722 unsigned long i;
723 char *ret; 1297 char *ret;
724 void *symtab_void, *strtab_void; 1298 void *symtab_void, *strtab_void;
725 1299
726 if (!find_sym) return NULL; 1300 if (!find_sym) return NULL;
727 ret = find_sym; 1301 ret = NULL;
728 1302
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1303 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1304
731 if (symtab_void && strtab_void) { 1305 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1306#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1307 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1308 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1309 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1310 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1311 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1312 char *symname; \
1313 size_t ret_len = 0; \
1314 if (cnt) \
1315 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1316 for (i = 0; i < cnt; ++i) { \
1317 if ((void*)sym > elf->data_end) { \
1318 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1319 goto break_out; \
1320 } \
740 if (sym->st_name) { \ 1321 if (sym->st_name) { \
1322 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1323 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1324 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1325 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1326 ++sym; \
745 elf->base_filename, \ 1327 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1328 } \
1329 scanelf_match_symname(elf, found_sym, \
1330 &ret, &ret_len, symname, \
1331 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1332 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1333 EGET(sym->st_shndx), \
1334 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1335 EGET(sym->st_size)); \
766 } \ 1336 } \
767 ++sym; \ 1337 ++sym; \
768 } } 1338 } \
1339 }
769 FIND_SYM(32) 1340 FIND_SYM(32)
770 FIND_SYM(64) 1341 FIND_SYM(64)
771 } 1342 }
772 1343
773break_out: 1344break_out:
776 if (*find_sym != '*' && *found_sym) 1347 if (*find_sym != '*' && *found_sym)
777 return ret; 1348 return ret;
778 if (be_quiet) 1349 if (be_quiet)
779 return NULL; 1350 return NULL;
780 else 1351 else
781 return (char *)" - "; 1352 return " - ";
782} 1353}
1354
1355static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1356{
1357 if (!find_section)
1358 return NULL;
1359
1360#define FIND_SECTION(B) \
1361 if (elf->elf_class == ELFCLASS ## B) { \
1362 size_t matched, n; \
1363 int invert; \
1364 const char *section_name; \
1365 Elf ## B ## _Shdr *section; \
1366 \
1367 matched = 0; \
1368 array_for_each(find_section_arr, n, section_name) { \
1369 invert = (*section_name == '!' ? 1 : 0); \
1370 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1371 if ((section == NULL && invert) || (section != NULL && !invert)) \
1372 ++matched; \
1373 } \
1374 \
1375 if (matched == array_cnt(find_section_arr)) \
1376 *found_section = 1; \
1377 }
1378 FIND_SECTION(32)
1379 FIND_SECTION(64)
1380
1381 if (be_wewy_wewy_quiet)
1382 return NULL;
1383
1384 if (*found_section)
1385 return find_section;
1386
1387 if (be_quiet)
1388 return NULL;
1389 else
1390 return " - ";
1391}
1392
783/* scan an elf file and show all the fun stuff */ 1393/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1394#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1395static int scanelf_elfobj(elfobj *elf)
786{ 1396{
787 unsigned long i; 1397 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1398 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1399 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1400 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1401 static char *out_buffer = NULL;
794 static size_t out_len; 1402 static size_t out_len;
795 1403
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1404 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1405 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1406 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1407
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1408 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1409 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1410 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1411 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1412 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1413 printf("%s: scanning file\n", elf->filename);
827 1414
828 /* init output buffer */ 1415 /* init output buffer */
829 if (!out_buffer) { 1416 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1417 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1418 out_buffer = xmalloc(out_len);
832 } 1419 }
833 *out_buffer = '\0'; 1420 *out_buffer = '\0';
834 1421
835 /* show the header */ 1422 /* show the header */
836 if (!be_quiet && show_banner) { 1423 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1424 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1425 if (!IS_MODIFIER(out_format[i])) continue;
839 1426
840 switch (out_format[++i]) { 1427 switch (out_format[++i]) {
1428 case '+': break;
841 case '%': break; 1429 case '%': break;
842 case '#': break; 1430 case '#': break;
843 case 'F': 1431 case 'F':
844 case 'p': 1432 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1433 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1434 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1435 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1436 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1437 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1438 case 'r': prints("RPATH "); break;
1439 case 'M': prints("CLASS "); break;
1440 case 'l':
851 case 'n': prints("NEEDED "); break; 1441 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1442 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1443 case 'b': prints("BIND "); break;
1444 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1445 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1446 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1447 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1448 case 'T': prints("TEXTRELS "); break;
1449 case 'k': prints("SECTION "); break;
1450 case 'a': prints("ARCH "); break;
1451 case 'I': prints("OSABI "); break;
1452 case 'Y': prints("EABI "); break;
1453 case 'O': prints("PERM "); break;
1454 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1455 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1456 }
860 } 1457 }
861 if (!found_file) prints("FILE "); 1458 if (!found_file) prints("FILE ");
862 prints("\n"); 1459 prints("\n");
866 1463
867 /* dump all the good stuff */ 1464 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1465 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1466 const char *out;
870 const char *tmp; 1467 const char *tmp;
871 1468 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1469 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1470 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1471 continue;
879 } 1472 }
880 1473
881 out = NULL; 1474 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1475 be_wewy_wewy_quiet = (out_format[i] == '#');
1476 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1477 switch (out_format[++i]) {
1478 case '+':
884 case '%': 1479 case '%':
885 case '#': 1480 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1481 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1482 case 'F':
888 found_file = 1; 1483 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1484 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1485 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1486 break;
892 case 'p': 1487 case 'p':
893 found_file = 1; 1488 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1489 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1490 tmp = elf->filename;
896 if (search_path) { 1491 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1492 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1493 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1494 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1495 len_file > len_search)
901 tmp += len_search; 1496 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1497 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1498 }
904 xstrcat(&out_buffer, tmp, &out_len); 1499 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1500 break;
906 case 'f': 1501 case 'f':
907 found_file = 1; 1502 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1503 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1504 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1505 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1506 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1507 break;
913 case 'o': out = get_elfetype(elf); break; 1508 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1509 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1510 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1511 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1512 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1513 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1514 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1515 case 'D': out = get_endian(elf); break;
1516 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1517 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1518 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1519 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1520 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1521 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1522 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1523 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1524 case 'a': out = get_elfemtype(elf); break;
1525 case 'I': out = get_elfosabi(elf); break;
1526 case 'Y': out = get_elf_eabi(elf); break;
1527 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1528 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1529 }
927 if (out) { 1530 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1531 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1532 }
935 1533
936#define FOUND_SOMETHING() \ 1534#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1535 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1536 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1537 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1538
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1539 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1540 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1541 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1542 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1543 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1544 puts(out_buffer);
947 fflush(stdout); 1545 fflush(stdout);
948 } 1546 }
949 1547
1548 return 0;
1549}
1550
1551/* scan a single elf */
1552static int scanelf_elf(const char *filename, int fd, size_t len)
1553{
1554 int ret = 1;
1555 elfobj *elf;
1556
1557 /* verify this is real ELF */
1558 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1559 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1560 return 2;
1561 }
1562 switch (match_bits) {
1563 case 32:
1564 if (elf->elf_class != ELFCLASS32)
1565 goto label_done;
1566 break;
1567 case 64:
1568 if (elf->elf_class != ELFCLASS64)
1569 goto label_done;
1570 break;
1571 default: break;
1572 }
1573 if (match_etypes) {
1574 char sbuf[126];
1575 strncpy(sbuf, match_etypes, sizeof(sbuf));
1576 if (strchr(match_etypes, ',') != NULL) {
1577 char *p;
1578 while ((p = strrchr(sbuf, ',')) != NULL) {
1579 *p = 0;
1580 if (etype_lookup(p+1) == get_etype(elf))
1581 goto label_ret;
1582 }
1583 }
1584 if (etype_lookup(sbuf) != get_etype(elf))
1585 goto label_done;
1586 }
1587
1588label_ret:
1589 ret = scanelf_elfobj(elf);
1590
1591label_done:
950 unreadelf(elf); 1592 unreadelf(elf);
1593 return ret;
1594}
1595
1596/* scan an archive of elfs */
1597static int scanelf_archive(const char *filename, int fd, size_t len)
1598{
1599 archive_handle *ar;
1600 archive_member *m;
1601 char *ar_buffer;
1602 elfobj *elf;
1603
1604 ar = ar_open_fd(filename, fd);
1605 if (ar == NULL)
1606 return 1;
1607
1608 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1609 while ((m = ar_next(ar)) != NULL) {
1610 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1611 if (cur_pos == -1)
1612 errp("lseek() failed");
1613 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1614 if (elf) {
1615 scanelf_elfobj(elf);
1616 unreadelf(elf);
1617 }
1618 }
1619 munmap(ar_buffer, len);
1620
1621 return 0;
1622}
1623/* scan a file which may be an elf or an archive or some other magical beast */
1624static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1625{
1626 const struct stat *st = st_cache;
1627 struct stat symlink_st;
1628 int fd;
1629
1630 /* always handle regular files and handle symlinked files if no -y */
1631 if (S_ISLNK(st->st_mode)) {
1632 if (!scan_symlink)
1633 return 1;
1634 fstatat(dir_fd, filename, &symlink_st, 0);
1635 st = &symlink_st;
1636 }
1637
1638 if (!S_ISREG(st->st_mode)) {
1639 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1640 return 1;
1641 }
1642
1643 if (match_perms) {
1644 if ((st->st_mode | match_perms) != st->st_mode)
1645 return 1;
1646 }
1647 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1648 if (fd == -1)
1649 return 1;
1650
1651 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1652 /* if it isn't an ELF, maybe it's an .a archive */
1653 if (scan_archives)
1654 scanelf_archive(filename, fd, st->st_size);
1655
1656 /*
1657 * unreadelf() implicitly closes its fd, so only close it
1658 * when we are returning it in the non-ELF case
1659 */
1660 close(fd);
1661 }
1662
1663 return 0;
951} 1664}
952 1665
953/* scan a directory for ET_EXEC files and print when we find one */ 1666/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1667static int scanelf_dirat(int dir_fd, const char *path)
955{ 1668{
956 register DIR *dir; 1669 register DIR *dir;
957 register struct dirent *dentry; 1670 register struct dirent *dentry;
958 struct stat st_top, st; 1671 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1672 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1673 size_t pathlen = 0, len = 0;
1674 int ret = 0;
1675 int subdir_fd;
961 1676
962 /* make sure path exists */ 1677 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1678 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1679 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1680 return 1;
966 } 1681 }
967 1682
968 /* ok, if it isn't a directory, assume we can open it */ 1683 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1684 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1685 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1686
974 /* now scan the dir looking for fun stuff */ 1687 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1688 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1689 if (subdir_fd == -1)
1690 dir = NULL;
1691 else
1692 dir = fdopendir(subdir_fd);
1693 if (dir == NULL) {
1694 if (subdir_fd != -1)
1695 close(subdir_fd);
1696 warnfp("could not opendir(%s)", path);
977 return; 1697 return 1;
978 } 1698 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1699 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1700
981 pathlen = strlen(path); 1701 subpath = stpcpy(buf, path);
1702 if (subpath[-1] != '/')
1703 *subpath++ = '/';
1704 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1705 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1706 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1707 continue;
1708
1709 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1710 continue;
1711
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1712 len = strlen(dentry->d_name);
986 if (len >= sizeof(buf)) { 1713 if (len + pathlen + 1 >= sizeof(buf)) {
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1714 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
988 (unsigned long)len, (unsigned long)sizeof(buf)); 1715 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
989 continue; 1716 continue;
990 } 1717 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1718 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1719 subpath[len] = '\0';
1720
993 if (S_ISREG(st.st_mode)) 1721 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1722 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1723 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1724 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1725 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1726 }
1000 } 1727 }
1001 closedir(dir); 1728 closedir(dir);
1002}
1003 1729
1730 return ret;
1731}
1732static int scanelf_dir(const char *path)
1733{
1734 return scanelf_dirat(root_fd, root_rel_path(path));
1735}
1736
1004static int scanelf_from_file(char *filename) 1737static int scanelf_from_file(const char *filename)
1005{ 1738{
1006 FILE *fp = NULL; 1739 FILE *fp;
1007 char *p; 1740 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1741 size_t len;
1742 int ret;
1009 1743
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1744 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1745 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1746 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1747 return 1;
1014 1748
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1749 path = NULL;
1750 len = 0;
1751 ret = 0;
1752 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1753 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1754 *p = 0;
1018 search_path = path; 1755 search_path = path;
1019 scanelf_dir(path); 1756 ret = scanelf_dir(path);
1020 } 1757 }
1758 free(path);
1759
1021 if (fp != stdin) 1760 if (fp != stdin)
1022 fclose(fp); 1761 fclose(fp);
1762
1023 return 0; 1763 return ret;
1024} 1764}
1025 1765
1026static void load_ld_so_conf() 1766#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1767
1768static int _load_ld_cache_config(const char *fname)
1027{ 1769{
1028 FILE *fp = NULL; 1770 FILE *fp = NULL;
1029 char *p; 1771 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1772 size_t len;
1031 int i = 0; 1773 int curr_fd = -1;
1032 1774
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1775 fp = fopenat_r(root_fd, root_rel_path(fname));
1776 if (fp == NULL)
1034 return; 1777 return -1;
1035 1778
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1779 path = NULL;
1037 if (*path != '/') 1780 len = 0;
1038 continue; 1781 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1782 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1783 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1784 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1785 *p = 0;
1044 1786
1045 ldpaths[i++] = xstrdup(path); 1787 /* recursive includes of the same file will make this segfault. */
1788 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1789 glob_t gl;
1790 size_t x;
1791 const char *gpath;
1046 1792
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1793 /* re-use existing path buffer ... need to be creative */
1048 break; 1794 if (path[8] != '/')
1795 gpath = memcpy(path + 3, "/etc/", 5);
1796 else
1797 gpath = path + 8;
1798 if (root_fd != AT_FDCWD) {
1799 if (curr_fd == -1) {
1800 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1801 if (fchdir(root_fd))
1802 errp("unable to change to root dir");
1803 }
1804 gpath = root_rel_path(gpath);
1805 }
1806
1807 if (glob(gpath, 0, NULL, &gl) == 0) {
1808 for (x = 0; x < gl.gl_pathc; ++x) {
1809 /* try to avoid direct loops */
1810 if (strcmp(gl.gl_pathv[x], fname) == 0)
1811 continue;
1812 _load_ld_cache_config(gl.gl_pathv[x]);
1813 }
1814 globfree(&gl);
1815 }
1816
1817 /* failed globs are ignored by glibc */
1818 continue;
1049 } 1819 }
1050 ldpaths[i] = NULL; 1820
1821 if (*path != '/')
1822 continue;
1823
1824 xarraypush_str(ldpaths, path);
1825 }
1826 free(path);
1051 1827
1052 fclose(fp); 1828 fclose(fp);
1829
1830 if (curr_fd != -1) {
1831 if (fchdir(curr_fd))
1832 /* don't care */;
1833 close(curr_fd);
1834 }
1835
1836 return 0;
1837}
1838
1839#elif defined(__FreeBSD__) || defined(__DragonFly__)
1840
1841static int _load_ld_cache_config(const char *fname)
1842{
1843 FILE *fp = NULL;
1844 char *b = NULL, *p;
1845 struct elfhints_hdr hdr;
1846
1847 fp = fopenat_r(root_fd, root_rel_path(fname));
1848 if (fp == NULL)
1849 return -1;
1850
1851 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1852 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1853 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1854 {
1855 fclose(fp);
1856 return -1;
1857 }
1858
1859 b = xmalloc(hdr.dirlistlen + 1);
1860 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1861 fclose(fp);
1862 free(b);
1863 return -1;
1864 }
1865
1866 while ((p = strsep(&b, ":"))) {
1867 if (*p == '\0')
1868 continue;
1869 xarraypush_str(ldpaths, p);
1870 }
1871
1872 free(b);
1873 fclose(fp);
1874 return 0;
1875}
1876
1877#else
1878#ifdef __ELF__
1879#warning Cache config support not implemented for your target
1880#endif
1881static int _load_ld_cache_config(const char *fname)
1882{
1883 return 0;
1884}
1885#endif
1886
1887static void load_ld_cache_config(const char *fname)
1888{
1889 bool scan_l, scan_ul, scan_ull;
1890 size_t n;
1891 const char *ldpath;
1892
1893 _load_ld_cache_config(fname);
1894
1895 scan_l = scan_ul = scan_ull = false;
1896 if (array_cnt(ldpaths)) {
1897 array_for_each(ldpaths, n, ldpath) {
1898 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1899 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1900 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1901 }
1902 }
1903
1904 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1905 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1906 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1053} 1907}
1054 1908
1055/* scan /etc/ld.so.conf for paths */ 1909/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1910static void scanelf_ldpath(void)
1057{ 1911{
1058 char scan_l, scan_ul, scan_ull; 1912 size_t n;
1059 int i = 0; 1913 const char *ldpath;
1060 1914
1061 if (!ldpaths[0]) 1915 array_for_each(ldpaths, n, ldpath)
1062 err("Unable to load any paths from ld.so.conf");
1063
1064 scan_l = scan_ul = scan_ull = 0;
1065
1066 while (ldpaths[i]) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1916 scanelf_dir(ldpath);
1071 ++i;
1072 }
1073
1074 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1917}
1078 1918
1079/* scan env PATH for paths */ 1919/* scan env PATH for paths */
1080static void scanelf_envpath() 1920static void scanelf_envpath(void)
1081{ 1921{
1082 char *path, *p; 1922 char *path, *p;
1083 1923
1084 path = getenv("PATH"); 1924 path = getenv("PATH");
1085 if (!path) 1925 if (!path)
1092 } 1932 }
1093 1933
1094 free(path); 1934 free(path);
1095} 1935}
1096 1936
1097 1937/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1938#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1939#define a_argument required_argument
1101static struct option const long_opts[] = { 1940static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1941 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1942 {"ldpath", no_argument, NULL, 'l'},
1943 {"use-ldpath",no_argument, NULL, 129},
1944 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1945 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1946 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1947 {"symlink", no_argument, NULL, 'y'},
1948 {"archives", no_argument, NULL, 'A'},
1949 {"ldcache", no_argument, NULL, 'L'},
1950 {"fix", no_argument, NULL, 'X'},
1951 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1952 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1953 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1954 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1955 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1956 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1957 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1958 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1959 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 1960 {"symbol", a_argument, NULL, 's'},
1961 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 1962 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 1963 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 1964 {"textrels", no_argument, NULL, 'T'},
1965 {"etype", a_argument, NULL, 'E'},
1966 {"bits", a_argument, NULL, 'M'},
1967 {"endian", no_argument, NULL, 'D'},
1968 {"osabi", no_argument, NULL, 'I'},
1969 {"eabi", no_argument, NULL, 'Y'},
1970 {"perms", a_argument, NULL, 'O'},
1971 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 1972 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 1973 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 1974 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 1975 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 1976 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 1977 {"file", a_argument, NULL, 'o'},
1978 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 1979 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 1980 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 1981 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 1982 {NULL, no_argument, NULL, 0x0}
1130}; 1983};
1131 1984
1132static const char *opts_help[] = { 1985static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 1986 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 1987 "Scan all directories in /etc/ld.so.conf",
1988 "Use ld.so.conf to show full path (use with -r/-n)",
1989 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 1990 "Scan directories recursively",
1136 "Don't recursively cross mount points", 1991 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 1992 "Don't scan symlinks",
1993 "Scan archives (.a files)",
1994 "Utilize ld.so.cache to show full path (use with -r/-n)",
1995 "Try and 'fix' bad things (use with -r/-e)",
1996 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 1997 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 1998 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 1999 "Print TEXTREL information",
1141 "Print RPATH information", 2000 "Print RPATH information",
1142 "Print NEEDED information", 2001 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 2002 "Print INTERP information",
1145 "Print BIND information", 2003 "Print BIND information",
1146 "Print SONAME information", 2004 "Print SONAME information",
1147 "Find a specified symbol", 2005 "Find a specified symbol",
2006 "Find a specified section",
1148 "Find a specified library", 2007 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 2008 "Use regex matching rather than string compare (use with -s)",
1150 "Locate cause of TEXTREL", 2009 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 2010 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2011 "Print only ELF files matching numeric bits",
2012 "Print Endianness",
2013 "Print OSABI",
2014 "Print EABI (EM_ARM Only)",
2015 "Print only ELF files matching octal permissions",
2016 "Print ELF file size",
2017 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 2018 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 2019 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 2020 "Use specified format for output",
1155 "Read input stream from a filename", 2021 "Read input stream from a filename",
1156 "Write output stream to a filename", 2022 "Write output stream to a filename",
2023 "Don't emit color in output",
1157 "Don't display the header", 2024 "Don't display the header",
1158 "Print this help and exit", 2025 "Print this help and exit",
1159 "Print version and exit", 2026 "Print version and exit",
1160 NULL 2027 NULL
1161}; 2028};
1163/* display usage and exit */ 2030/* display usage and exit */
1164static void usage(int status) 2031static void usage(int status)
1165{ 2032{
1166 unsigned long i; 2033 unsigned long i;
1167 printf("* Scan ELF binaries for stuff\n\n" 2034 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2035 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2036 printf("Options: -[%s]\n", PARSE_FLAGS);
1170 for (i = 0; long_opts[i].name; ++i) 2037 for (i = 0; long_opts[i].name; ++i) {
2038 /* first output the short flag if it has one */
2039 if (long_opts[i].val > '~')
2040 printf(" ");
2041 else
2042 printf(" -%c, ", long_opts[i].val);
2043
2044 /* then the long flag */
1171 if (long_opts[i].has_arg == no_argument) 2045 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2046 printf("--%-14s", long_opts[i].name);
1173 long_opts[i].name, opts_help[i]);
1174 else 2047 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2048 printf("--%-7s <arg> ", long_opts[i].name);
1176 long_opts[i].name, opts_help[i]);
1177 2049
1178 if (status != EXIT_SUCCESS) 2050 /* finally the help text */
1179 exit(status); 2051 printf("* %s\n", opts_help[i]);
2052 }
1180 2053
1181 puts("\nThe format modifiers for the -F option are:"); 2054 puts("\nFor more information, see the scanelf(1) manpage");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2055 exit(status);
1192} 2056}
1193 2057
1194/* parse command line arguments and preform needed actions */ 2058/* parse command line arguments and preform needed actions */
2059#define do_pax_state(option, flag) \
2060 if (islower(option)) { \
2061 flags &= ~PF_##flag; \
2062 flags |= PF_NO##flag; \
2063 } else { \
2064 flags &= ~PF_NO##flag; \
2065 flags |= PF_##flag; \
2066 }
1195static void parseargs(int argc, char *argv[]) 2067static int parseargs(int argc, char *argv[])
1196{ 2068{
1197 int i; 2069 int i;
1198 char *from_file = NULL; 2070 const char *from_file = NULL;
2071 int ret = 0;
2072 char load_cache_config = 0;
1199 2073
1200 opterr = 0; 2074 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2075 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2076 switch (i) {
1203 2077
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2081 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2082 exit(EXIT_SUCCESS);
1209 break; 2083 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2084 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2085 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2086 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2087 from_file = optarg;
2088 break;
2089 case 'E':
2090 match_etypes = optarg;
2091 break;
2092 case 'M':
2093 match_bits = atoi(optarg);
2094 if (match_bits == 0) {
2095 if (strcmp(optarg, "ELFCLASS32") == 0)
2096 match_bits = 32;
2097 if (strcmp(optarg, "ELFCLASS64") == 0)
2098 match_bits = 64;
2099 }
2100 break;
2101 case 'O':
2102 if (sscanf(optarg, "%o", &match_perms) == -1)
2103 match_bits = 0;
1214 break; 2104 break;
1215 case 'o': { 2105 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2106 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2107 errp("Could not freopen(%s)", optarg);
1219 SET_STDOUT(fp);
1220 break; 2108 break;
1221 } 2109 }
1222 2110 case 'k':
2111 xarraypush_str(find_section_arr, optarg);
2112 break;
1223 case 's': { 2113 case 's': {
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2114 if (find_sym) warn("You prob don't want to specify -s twice");
1225 find_sym = optarg; 2115 find_sym = optarg;
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1227 sprintf(versioned_symname, "%s@", find_sym);
1228 break; 2116 break;
1229 } 2117 }
1230 case 'N': { 2118 case 'N':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2119 xarraypush_str(find_lib_arr, optarg);
1232 find_lib = optarg;
1233 break; 2120 break;
1234 }
1235
1236 case 'F': { 2121 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2122 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2123 out_format = optarg;
1239 break; 2124 break;
1240 } 2125 }
2126 case 'z': {
2127 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2128 size_t x;
1241 2129
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2130 for (x = 0; x < strlen(optarg); x++) {
2131 switch (optarg[x]) {
2132 case 'p':
2133 case 'P':
2134 do_pax_state(optarg[x], PAGEEXEC);
2135 break;
2136 case 's':
2137 case 'S':
2138 do_pax_state(optarg[x], SEGMEXEC);
2139 break;
2140 case 'm':
2141 case 'M':
2142 do_pax_state(optarg[x], MPROTECT);
2143 break;
2144 case 'e':
2145 case 'E':
2146 do_pax_state(optarg[x], EMUTRAMP);
2147 break;
2148 case 'r':
2149 case 'R':
2150 do_pax_state(optarg[x], RANDMMAP);
2151 break;
2152 case 'x':
2153 case 'X':
2154 do_pax_state(optarg[x], RANDEXEC);
2155 break;
2156 default:
2157 break;
2158 }
2159 }
2160 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2161 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2162 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2163 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2164 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2165 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2166 setpax = flags;
2167 break;
2168 }
2169 case 'Z': show_size = 1; break;
1243 case 'L': printcache = 1; break; 2170 case 'g': g_match = 1; break;
2171 case 'L': load_cache_config = use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2172 case 'y': scan_symlink = 0; break;
2173 case 'A': scan_archives = 1; break;
2174 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2175 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2176 case 'l': load_cache_config = scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2177 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2178 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2179 case 'm': dir_crossmount = 0; break;
2180 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2181 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2182 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2183 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2184 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2185 case 'n': show_needed = 1; break;
1256 case 'b': show_bind = 1; break; 2187 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2188 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2189 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2190 case 'q': be_quiet = 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2191 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2192 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2193 case 'D': show_endian = 1; break;
2194 case 'I': show_osabi = 1; break;
2195 case 'Y': show_eabi = 1; break;
2196 case 128:
2197 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2198 if (root_fd == -1)
2199 err("Could not open root: %s", optarg);
2200 break;
2201 case 129: load_cache_config = use_ldpath = 1; break;
1263 case ':': 2202 case ':':
1264 err("Option missing parameter\n"); 2203 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2204 case '?':
1266 err("Unknown option\n"); 2205 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2206 default:
1268 err("Unhandled option '%c'", i); 2207 err("Unhandled option '%c'; please report this", i);
1269 } 2208 }
1270 } 2209 }
1271 2210 if (show_textrels && be_verbose)
2211 has_objdump = bin_in_path("objdump");
2212 /* flatten arrays for display */
2213 if (array_cnt(find_lib_arr))
2214 find_lib = array_flatten_str(find_lib_arr);
2215 if (array_cnt(find_section_arr))
2216 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2217 /* let the format option override all other options */
1273 if (out_format) { 2218 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2219 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2220 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2221 show_textrels = show_perms = show_endian = show_size = \
2222 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2223 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2224 if (!IS_MODIFIER(out_format[i])) continue;
1279 2225
1280 switch (out_format[++i]) { 2226 switch (out_format[++i]) {
2227 case '+': break;
1281 case '%': break; 2228 case '%': break;
1282 case '#': break; 2229 case '#': break;
1283 case 'F': break; 2230 case 'F': break;
1284 case 'p': break; 2231 case 'p': break;
1285 case 'f': break; 2232 case 'f': break;
2233 case 'k': break;
1286 case 's': break; 2234 case 's': break;
1287 case 'N': break; 2235 case 'N': break;
1288 case 'o': break; 2236 case 'o': break;
2237 case 'a': break;
2238 case 'M': break;
2239 case 'Z': show_size = 1; break;
2240 case 'D': show_endian = 1; break;
2241 case 'I': show_osabi = 1; break;
2242 case 'Y': show_eabi = 1; break;
2243 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2244 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2245 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2246 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2247 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2248 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2249 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2250 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2251 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2252 case 'T': show_textrels = 1; break;
1298 default: 2253 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2254 err("invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2255 out_format[i], i+1);
1301 } 2256 }
1302 } 2257 }
1303 2258
1304 /* construct our default format */ 2259 /* construct our default format */
1305 } else { 2260 } else {
1306 size_t fmt_len = 30; 2261 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2262 out_format = xmalloc(sizeof(char) * fmt_len);
2263 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2264 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2265 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2266 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2267 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2268 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2269 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2270 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2271 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2272 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2273 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2274 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2275 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2276 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2277 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2278 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2279 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2280 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2281 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2282 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2283 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2284 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2285
1324 /* now lets actually do the scanning */ 2286 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2287 if (load_cache_config)
1326 load_ld_so_conf(); 2288 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2289 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2290 if (scan_envpath) scanelf_envpath();
2291 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2292 from_file = "-";
1329 if (from_file) { 2293 if (from_file) {
1330 scanelf_from_file(from_file); 2294 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2295 from_file = *argv;
1333 } 2296 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2297 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2298 err("Nothing to scan !?");
1336 while (optind < argc) { 2299 while (optind < argc) {
1337 search_path = argv[optind++]; 2300 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2301 ret = scanelf_dir(search_path);
1339 } 2302 }
1340 2303
1341 /* clean up */ 2304 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2305 xarrayfree(ldpaths);
2306 xarrayfree(find_lib_arr);
2307 xarrayfree(find_section_arr);
2308 free(find_lib);
2309 free(find_section);
1345 2310
1346 if (ldcache != 0) 2311 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2312 munmap(ldcache, ldcache_size);
1348}
1349
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2313 return ret;
1358} 2314}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2315
1369 new_len = strlen(*dst) + strlen(src); 2316static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2317{
1384 static char my_app[2]; 2318 const char *delims = " \t\n";
1385 my_app[0] = append; 2319 char **envvals = NULL;
1386 my_app[1] = '\0'; 2320 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2321 int nentry;
1388}
1389 2322
2323 if ((env = getenv(envvar)) == NULL)
2324 return NULL;
1390 2325
2326 env = xstrdup(env);
2327 if (env == NULL)
2328 return NULL;
2329
2330 s = strtok(env, delims);
2331 if (s == NULL) {
2332 free(env);
2333 return NULL;
2334 }
2335
2336 nentry = 0;
2337 while (s != NULL) {
2338 ++nentry;
2339 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2340 envvals[nentry-1] = s;
2341 s = strtok(NULL, delims);
2342 }
2343 envvals[nentry] = NULL;
2344
2345 /* don't want to free(env) as it contains the memory that backs
2346 * the envvals array of strings */
2347 return envvals;
2348}
2349
2350static void parseenv(void)
2351{
2352 color_init(false);
2353 qa_textrels = get_split_env("QA_TEXTRELS");
2354 qa_execstack = get_split_env("QA_EXECSTACK");
2355 qa_wx_load = get_split_env("QA_WX_LOAD");
2356}
2357
2358#ifdef __PAX_UTILS_CLEANUP
2359static void cleanup(void)
2360{
2361 free(out_format);
2362 free(qa_textrels);
2363 free(qa_execstack);
2364 free(qa_wx_load);
2365}
2366#endif
1391 2367
1392int main(int argc, char *argv[]) 2368int main(int argc, char *argv[])
1393{ 2369{
2370 int ret;
1394 if (argc < 2) 2371 if (argc < 2)
1395 usage(EXIT_FAILURE); 2372 usage(EXIT_FAILURE);
2373 parseenv();
1396 parseargs(argc, argv); 2374 ret = parseargs(argc, argv);
1397 fclose(stdout); 2375 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2376#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2377 cleanup();
2378 warn("The calls to add/delete heap should be off:\n"
2379 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2380 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2381#endif
1401 return EXIT_SUCCESS; 2382 return ret;
1402} 2383}
2384
2385/* Match filename against entries in matchlist, return TRUE
2386 * if the file is listed */
2387static int file_matches_list(const char *filename, char **matchlist)
2388{
2389 char **file;
2390 char *match;
2391 char buf[__PAX_UTILS_PATH_MAX];
2392
2393 if (matchlist == NULL)
2394 return 0;
2395
2396 for (file = matchlist; *file != NULL; file++) {
2397 if (search_path) {
2398 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2399 match = buf;
2400 } else {
2401 match = *file;
2402 }
2403 if (fnmatch(match, filename, 0) == 0)
2404 return 1;
2405 }
2406 return 0;
2407}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.243

  ViewVC Help
Powered by ViewVC 1.1.20