/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.245
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2007 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.245 2012/08/04 06:08:25 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2007 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2007 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.245 2012/08/04 06:08:25 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
67static char *find_lib = NULL; 49static char *find_lib = NULL;
50static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
51static char *find_section = NULL;
52static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 53static char *out_format = NULL;
69static char *search_path = NULL; 54static char *search_path = NULL;
55static char fix_elf = 0;
70static char gmatch = 0; 56static char g_match = 0;
71static char printcache = 0; 57static char use_ldcache = 0;
58static char use_ldpath = 0;
72 59
60static char **qa_textrels = NULL;
61static char **qa_execstack = NULL;
62static char **qa_wx_load = NULL;
63static int root_fd = AT_FDCWD;
73 64
74caddr_t ldcache = 0; 65static int match_bits = 0;
66static unsigned int match_perms = 0;
67static void *ldcache = NULL;
75size_t ldcache_size = 0; 68static size_t ldcache_size = 0;
69static unsigned long setpax = 0UL;
76 70
71static int has_objdump = 0;
72
73/* find the path to a file by name */
74static int bin_in_path(const char *fname)
75{
76 char fullpath[__PAX_UTILS_PATH_MAX];
77 char *path, *p;
78
79 path = getenv("PATH");
80 if (!path)
81 return 0;
82
83 while ((p = strrchr(path, ':')) != NULL) {
84 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
85 *p = 0;
86 if (access(fullpath, R_OK) != -1)
87 return 1;
88 }
89
90 return 0;
91}
92
93static FILE *fopenat_r(int dir_fd, const char *path)
94{
95 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
96 if (fd == -1)
97 return NULL;
98 return fdopen(fd, "re");
99}
100
101static const char *root_rel_path(const char *path)
102{
103 /*
104 * openat() will ignore the dirfd if path starts with
105 * a /, so consume all of that noise
106 *
107 * XXX: we don't handle relative paths like ../ that
108 * break out of the --root option, but for now, just
109 * don't do that :P.
110 */
111 if (root_fd != AT_FDCWD) {
112 while (*path == '/')
113 ++path;
114 if (*path == '\0')
115 path = ".";
116 }
117
118 return path;
119}
120
121/* 1 on failure. 0 otherwise */
122static int rematch(const char *regex, const char *match, int cflags)
123{
124 regex_t preg;
125 int ret;
126
127 if ((match == NULL) || (regex == NULL))
128 return EXIT_FAILURE;
129
130 if ((ret = regcomp(&preg, regex, cflags))) {
131 char err[256];
132
133 if (regerror(ret, &preg, err, sizeof(err)))
134 fprintf(stderr, "regcomp failed: %s", err);
135 else
136 fprintf(stderr, "regcomp failed");
137
138 return EXIT_FAILURE;
139 }
140 ret = regexec(&preg, match, 0, NULL, 0);
141 regfree(&preg);
142
143 return ret;
144}
145
77/* sub-funcs for scanelf_file() */ 146/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 147static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 148{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 149 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
150
151 /* debug sections */
152 void *symtab = elf_findsecbyname(elf, ".symtab");
153 void *strtab = elf_findsecbyname(elf, ".strtab");
154 /* runtime sections */
155 void *dynsym = elf_findsecbyname(elf, ".dynsym");
156 void *dynstr = elf_findsecbyname(elf, ".dynstr");
157
158 /*
159 * If the sections are marked NOBITS, then they don't exist, so we just
160 * skip them. This let's us work sanely with splitdebug ELFs (rather
161 * than spewing a lot of "corrupt ELF" messages later on). In malformed
162 * ELFs, the section might be wrongly set to NOBITS, but screw em.
163 */
81#define GET_SYMTABS(B) \ 164#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 165 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 166 Elf ## B ## _Shdr *esymtab = symtab; \
84 /* debug sections */ \ 167 Elf ## B ## _Shdr *estrtab = strtab; \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 168 Elf ## B ## _Shdr *edynsym = dynsym; \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 169 Elf ## B ## _Shdr *edynstr = dynstr; \
87 /* runtime sections */ \ 170 \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 171 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 172 symtab = NULL; \
173 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
174 dynsym = NULL; \
90 if (symtab && dynsym) { \ 175 if (symtab && dynsym) \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 176 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 177 else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 178 *sym = symtab ? symtab : dynsym; \
94 } \ 179 \
180 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
181 strtab = NULL; \
182 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
183 dynstr = NULL; \
95 if (strtab && dynstr) { \ 184 if (strtab && dynstr) \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 185 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 186 else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 187 *str = strtab ? strtab : dynstr; \
99 } \
100 } 188 }
101 GET_SYMTABS(32) 189 GET_SYMTABS(32)
102 GET_SYMTABS(64) 190 GET_SYMTABS(64)
191
192 if (*sym && *str)
193 return;
194
195 /*
196 * damn, they're really going to make us work for it huh?
197 * reconstruct the section header info out of the dynamic
198 * tags so we can see what symbols this guy uses at runtime.
199 */
200#define GET_SYMTABS_DT(B) \
201 if (elf->elf_class == ELFCLASS ## B) { \
202 size_t i; \
203 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
204 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
205 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
206 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
207 Elf ## B ## _Dyn *dyn; \
208 Elf ## B ## _Off offset; \
209 \
210 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
211 vsym = vstr = vhash = vgnu_hash = 0; \
212 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
213 memset(&str_shdr, 0, sizeof(str_shdr)); \
214 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
215 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
216 continue; \
217 \
218 offset = EGET(phdr[i].p_offset); \
219 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
220 continue; \
221 \
222 dyn = DYN ## B (elf->vdata + offset); \
223 while (EGET(dyn->d_tag) != DT_NULL) { \
224 switch (EGET(dyn->d_tag)) { \
225 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
226 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
227 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
228 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
229 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
230 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
231 } \
232 ++dyn; \
233 } \
234 if (vsym && vstr) \
235 break; \
236 } \
237 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
238 return; \
239 \
240 /* calc offset into the ELF by finding the load addr of the syms */ \
241 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
242 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
243 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
244 offset = EGET(phdr[i].p_offset); \
245 \
246 if (EGET(phdr[i].p_type) != PT_LOAD) \
247 continue; \
248 \
249 if (vhash >= vaddr && vhash < vaddr + filesz) { \
250 /* Scan the hash table to see how many entries we have */ \
251 Elf32_Word max_sym_idx = 0; \
252 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
253 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
254 Elf32_Word nchains = EGET(hashtbl[1]); \
255 Elf32_Word *buckets = &hashtbl[2]; \
256 Elf32_Word *chains = &buckets[nbuckets]; \
257 Elf32_Word sym_idx; \
258 \
259 for (b = 0; b < nbuckets; ++b) { \
260 if (!buckets[b]) \
261 continue; \
262 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
263 if (max_sym_idx < sym_idx) \
264 max_sym_idx = sym_idx; \
265 } \
266 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
267 } \
268 \
269 if (vsym >= vaddr && vsym < vaddr + filesz) { \
270 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
271 *sym = &sym_shdr; \
272 } \
273 \
274 if (vstr >= vaddr && vstr < vaddr + filesz) { \
275 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
276 *str = &str_shdr; \
277 } \
278 } \
279 }
280 GET_SYMTABS_DT(32)
281 GET_SYMTABS_DT(64)
103} 282}
283
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 284static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 285{
106 static char ret[7]; 286 static char ret[7];
107 unsigned long i, shown; 287 unsigned long i, shown;
108 288
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 297 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 298 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 299 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 300 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 301 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 302 if (fix_elf && setpax) { \
303 /* set the paxctl flags */ \
304 ESET(phdr[i].p_flags, setpax); \
305 } \
306 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 307 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 308 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 309 *found_pax = 1; \
126 ++shown; \ 310 ++shown; \
127 break; \ 311 break; \
128 } \ 312 } \
129 } 313 }
130 SHOW_PAX(32) 314 SHOW_PAX(32)
131 SHOW_PAX(64) 315 SHOW_PAX(64)
132 } 316 }
317
318 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
319 * was found. This is known to break ELFs on glibc systems,
320 * and mainline PaX has deprecated use of this for a long time.
321 * We could support changing PT_GNU_STACK, but that doesn't
322 * seem like it's worth the effort. #411919
323 */
133 324
134 /* fall back to EI_PAX if no PT_PAX was found */ 325 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 326 if (!*ret) {
136 static char *paxflags; 327 static char *paxflags;
137 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 328 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
150 341
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 342static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 343{
153 static char ret[12]; 344 static char ret[12];
154 char *found; 345 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 346 unsigned long i, shown, multi_stack, multi_relro, multi_load;
347 int max_pt_load;
157 348
158 if (!show_phdr) return NULL; 349 if (!show_phdr) return NULL;
159 350
160 memcpy(ret, "--- --- ---\0", 12); 351 memcpy(ret, "--- --- ---\0", 12);
161 352
162 shown = 0; 353 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 354 multi_stack = multi_relro = multi_load = 0;
355 max_pt_load = elf_max_pt_load(elf);
164 356
357#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 358#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 359 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 360 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 361 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 362 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 363 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 364 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 365 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 366 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
367 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 368 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
369 if (file_matches_list(elf->filename, qa_execstack)) \
370 continue; \
175 found = found_phdr; \ 371 found = found_phdr; \
176 offset = 0; \ 372 offset = 0; \
177 check_flags = PF_X; \ 373 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 374 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
375 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 376 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 377 found = found_relro; \
181 offset = 4; \ 378 offset = 4; \
182 check_flags = PF_X; \ 379 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 380 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 381 if (EGET(ehdr->e_type) == ET_DYN || EGET(ehdr->e_type) == ET_EXEC) \
382 if (multi_load++ > max_pt_load) \
383 warnf("%s: more than %i PT_LOAD's !?", elf->filename, max_pt_load); \
384 if (file_matches_list(elf->filename, qa_wx_load)) \
385 continue; \
185 found = found_load; \ 386 found = found_load; \
186 offset = 8; \ 387 offset = 8; \
187 check_flags = PF_W|PF_X; \ 388 check_flags = PF_W|PF_X; \
188 } else \ 389 } else \
189 continue; \ 390 continue; \
190 flags = EGET(phdr[i].p_flags); \ 391 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 392 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 393 continue; \
394 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
395 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
396 ret[3] = ret[7] = '!'; \
397 flags = EGET(phdr[i].p_flags); \
398 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 399 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 400 *found = 1; \
195 ++shown; \ 401 ++shown; \
196 } \ 402 } \
197 } else if (elf->shdr != NULL) { \ 403 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 404 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 405 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 406 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
407 char *str; \
408 if ((void*)strtbl > elf->data_end) \
409 goto skip_this_shdr##B; \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 410 check_flags = SHF_WRITE|SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 411 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 412 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 413 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 414 str = elf->data + offset; \
415 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
416 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 417 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 418 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 419 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 420 continue; \
210 ++*found_phdr; \ 421 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 425 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 426 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 427 break; \
217 } \ 428 } \
218 } \ 429 } \
430 skip_this_shdr##B: \
219 if (!multi_stack) { \ 431 if (!multi_stack) { \
432 if (file_matches_list(elf->filename, qa_execstack)) \
433 return NULL; \
220 *found_phdr = 1; \ 434 *found_phdr = 1; \
221 shown = 1; \ 435 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 436 memcpy(ret, "!WX", 3); \
223 } \ 437 } \
224 } \ 438 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 443 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 444 return NULL;
231 else 445 else
232 return ret; 446 return ret;
233} 447}
448
449/*
450 * See if this ELF contains a DT_TEXTREL tag in any of its
451 * PT_DYNAMIC sections.
452 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 453static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 454{
236 static const char *ret = "TEXTREL"; 455 static const char *ret = "TEXTREL";
237 unsigned long i; 456 unsigned long i;
238 457
239 if (!show_textrel && !show_textrels) return NULL; 458 if (!show_textrel && !show_textrels) return NULL;
459
460 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 461
241 if (elf->phdr) { 462 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 463#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 464 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 465 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 466 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 467 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 468 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 469 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 470 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 471 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 472 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 473 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 474 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 475 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 476 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 477 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 478 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 487 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 488 return NULL;
268 else 489 else
269 return " - "; 490 return " - ";
270} 491}
492
493/*
494 * Scan the .text section to see if there are any relocations in it.
495 * Should rewrite this to check PT_LOAD sections that are marked
496 * Executable rather than the section named '.text'.
497 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 498static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 499{
273 unsigned long s, r, rmax; 500 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 501 void *symtab_void, *strtab_void, *text_void;
275 502
296 Elf ## B ## _Rela *rela; \ 523 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 524 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 525 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 526 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 527 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 528 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 529 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 530 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 531 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 532 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 533 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 534 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 535 } else \
309 continue; \ 536 continue; \
310 /* now see if any of the relocs are in the .text */ \ 537 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 538 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 553 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 554 if (be_verbose <= 2) continue; \
328 } else \ 555 } else \
329 *found_textrels = 1; \ 556 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 557 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 558 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
559 if ((void*)sym > elf->data_end) { \
560 warn("%s: corrupt ELF symbol", elf->filename); \
561 continue; \
562 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 563 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 564 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 565 sym += sym_max; \
335 else \ 566 else \
336 sym = NULL; \ 567 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 568 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 569 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 570 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 571 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 572 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 573 else \
343 printf("(memory/fake?)"); \ 574 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 575 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 576 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 577 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 578 func = NULL; \
348 offset_tmp = 0; \ 579 offset_tmp = 0; \
349 while (sym_max--) { \ 580 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 581 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 582 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 583 offset_tmp = EGET(sym->st_value); \
353 } \ 584 } \
354 ++sym; \ 585 ++sym; \
355 } \ 586 } \
356 printf(" in "); \ 587 printf(" in "); \
357 if (func && func->st_name) \ 588 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 589 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
590 if (r_offset > EGET(func->st_size)) \
591 printf("(optimized out: previous %s)", func_name); \
359 else \ 592 else \
360 printf("(NULL: fake?)"); \ 593 printf("%s", func_name); \
594 } else \
595 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 596 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
597 if (be_verbose && has_objdump) { \
598 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
599 char *sysbuf; \
600 size_t syslen; \
601 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
602 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
603 sysbuf = xmalloc(syslen); \
604 if (end_addr < r_offset) \
605 /* not uncommon when things are optimized out */ \
606 end_addr = r_offset + 0x100; \
607 snprintf(sysbuf, syslen, sysfmt, \
608 (unsigned long)offset_tmp, \
609 (unsigned long)end_addr, \
610 elf->filename, \
611 (unsigned long)r_offset); \
612 fflush(stdout); \
613 if (system(sysbuf)) /* don't care */; \
614 fflush(stdout); \
615 free(sysbuf); \
616 } \
362 } \ 617 } \
363 } } 618 } }
364 SHOW_TEXTRELS(32) 619 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 620 SHOW_TEXTRELS(64)
366 } 621 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 623 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 624
370 return NULL; 625 return NULL;
371} 626}
372 627
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 628static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
629{
375 struct stat st; 630 struct stat st;
376 switch (*item) { 631 switch (*item) {
377 case '/': break; 632 case '/': break;
378 case '.': 633 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 634 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 635 break;
636 case ':':
381 case '\0': 637 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 638 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 639 break;
384 case '$': 640 case '$':
385 if (fstat(elf->fd, &st) != -1) 641 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 642 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 643 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 644 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 645 break;
390 default: 646 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 647 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 648 break;
393 } 649 }
394} 650}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 651static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 652{
397 unsigned long i, s; 653 unsigned long i;
398 char *rpath, *runpath, **r; 654 char *rpath, *runpath, **r;
399 void *strtbl_void; 655 void *strtbl_void;
400 656
401 if (!show_rpath) return; 657 if (!show_rpath) return;
402 658
413 Elf ## B ## _Off offset; \ 669 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 670 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 671 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 672 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 673 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 674 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 675 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 676 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 677 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 678 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 679 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 680 if (word == DT_RPATH) { \
425 r = &rpath; \ 681 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 682 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 683 r = &runpath; \
431 } \ 687 } \
432 /* Verify the memory is somewhat sane */ \ 688 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 689 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 690 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 691 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 692 *r = elf->data + offset; \
693 /* cache the length in case we need to nuke this section later on */ \
694 if (fix_elf) \
695 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 696 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 697 if (be_quiet) { \
439 size_t len; \ 698 size_t len; \
440 char *start, *end; \ 699 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 700 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 701 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 702 start = *r; \
444 /* scan each path in : delimited list */ \ 703 /* scan each path in : delimited list */ \
445 while (start) { \ 704 while (start) { \
446 rpath_security_checks(elf, start); \ 705 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 706 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 707 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 708 if (use_ldcache) { \
709 size_t n; \
710 const char *ldpath; \
711 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 712 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 713 *r = end; \
714 /* corner case ... if RPATH reads "/usr/lib:", we want \
715 * to show ':' rather than '' */ \
716 if (end && end[1] != '\0') \
717 (*r)++; \
452 break; \ 718 break; \
453 } \ 719 } \
454 } \ 720 } \
455 if (!*r || !ldpaths[s] || !end) \ 721 if (!*r || !end) \
456 start = NULL; \ 722 break; \
457 else \ 723 else \
458 start = start + len + 1; \ 724 start = start + len + 1; \
459 } \ 725 } \
460 } \ 726 } \
727 if (*r) { \
728 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
729 /* just nuke it */ \
730 nuke_it##B: \
731 memset(*r, 0x00, offset); \
732 *r = NULL; \
733 ESET(dyn->d_tag, DT_DEBUG); \
734 ESET(dyn->d_un.d_ptr, 0); \
735 } else if (fix_elf) { \
736 /* try to clean "bad" paths */ \
737 size_t len, tmpdir_len; \
738 char *start, *end; \
739 const char *tmpdir; \
740 start = *r; \
741 tmpdir = (getenv("TMPDIR") ? : "."); \
742 tmpdir_len = strlen(tmpdir); \
743 while (1) { \
744 end = strchr(start, ':'); \
745 if (start == end) { \
746 eat_this_path##B: \
747 len = strlen(end); \
748 memmove(start, end+1, len); \
749 start[len-1] = '\0'; \
750 end = start - 1; \
751 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
752 if (!end) { \
753 if (start == *r) \
754 goto nuke_it##B; \
755 *--start = '\0'; \
756 } else \
757 goto eat_this_path##B; \
758 } \
759 if (!end) \
760 break; \
761 start = end + 1; \
762 } \
763 if (**r == '\0') \
764 goto nuke_it##B; \
765 } \
766 if (*r) \
461 if (*r) *found_rpath = 1; \ 767 *found_rpath = 1; \
768 } \
462 } \ 769 } \
463 ++dyn; \ 770 ++dyn; \
464 } \ 771 } \
465 } } 772 } }
466 SHOW_RPATH(32) 773 SHOW_RPATH(32)
488 795
489#define LDSO_CACHE_MAGIC "ld.so-" 796#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 797#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 798#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 799#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
800#define FLAG_ANY -1
801#define FLAG_TYPE_MASK 0x00ff
802#define FLAG_LIBC4 0x0000
803#define FLAG_ELF 0x0001
804#define FLAG_ELF_LIBC5 0x0002
805#define FLAG_ELF_LIBC6 0x0003
806#define FLAG_REQUIRED_MASK 0xff00
807#define FLAG_SPARC_LIB64 0x0100
808#define FLAG_IA64_LIB64 0x0200
809#define FLAG_X8664_LIB64 0x0300
810#define FLAG_S390_LIB64 0x0400
811#define FLAG_POWERPC_LIB64 0x0500
812#define FLAG_MIPS64_LIBN32 0x0600
813#define FLAG_MIPS64_LIBN64 0x0700
493 814
494static char *lookup_cache_lib(char *); 815#if defined(__GLIBC__) || defined(__UCLIBC__)
816
495static char *lookup_cache_lib(char *fname) 817static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 818{
497 int fd = 0; 819 int fd;
498 char *strs; 820 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 821 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 822 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 823 struct stat st;
502 824
503 typedef struct { 825 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 826 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 827 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 828 int nlibs;
507 } header_t; 829 } header_t;
830 header_t *header;
508 831
509 typedef struct { 832 typedef struct {
510 int flags; 833 int flags;
511 int sooffset; 834 int sooffset;
512 int liboffset; 835 int liboffset;
513 } libentry_t; 836 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 837 libentry_t *libent;
517 838
518 if (fname == NULL) 839 if (fname == NULL)
519 return NULL; 840 return NULL;
520 841
521 if (ldcache == 0) { 842 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 843 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 844 return NULL;
524 /* save the cache size for latter unmapping */ 845
846 fd = openat(root_fd, cachefile, O_RDONLY);
847 if (fd == -1)
848 return NULL;
849
850 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 851 ldcache_size = st.st_size;
852 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
853 close(fd);
526 854
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 855 if (ldcache == MAP_FAILED) {
856 ldcache = NULL;
528 return NULL; 857 return NULL;
858 }
529 859
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 860 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
861 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
862 {
863 munmap(ldcache, ldcache_size);
864 ldcache = NULL;
533 return NULL; 865 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 866 }
867 } else
868 header = ldcache;
538 869
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 870 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 871 strs = (char *) &libent[header->nlibs];
542 872
543 for (fd = 0; fd < header->nlibs; fd++) { 873 for (fd = 0; fd < header->nlibs; ++fd) {
874 /* This should be more fine grained, but for now we assume that
875 * diff arches will not be cached together, and we ignore the
876 * the different multilib mips cases.
877 */
878 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
879 continue;
880 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
881 continue;
882
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 883 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 884 continue;
885
886 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 887 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
888 break;
547 } 889 }
890
548 return buf; 891 return buf;
549} 892}
550 893
894#elif defined(__NetBSD__)
895static char *lookup_cache_lib(elfobj *elf, const char *fname)
896{
897 static char buf[__PAX_UTILS_PATH_MAX] = "";
898 static struct stat st;
899 size_t n;
900 char *ldpath;
901
902 array_for_each(ldpath, n, ldpath) {
903 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
904 continue; /* if the pathname is too long, or something went wrong, ignore */
905
906 if (stat(buf, &st) != 0)
907 continue; /* if the lib doesn't exist in *ldpath, look further */
908
909 /* NetBSD doesn't actually do sanity checks, it just loads the file
910 * and if that doesn't work, continues looking in other directories.
911 * This cannot easily be safely emulated, unfortunately. For now,
912 * just assume that if it exists, it's a valid library. */
913
914 return buf;
915 }
916
917 /* not found in any path */
918 return NULL;
919}
920#else
921#ifdef __ELF__
922#warning Cache support not implemented for your target
923#endif
924static char *lookup_cache_lib(elfobj *elf, const char *fname)
925{
926 return NULL;
927}
928#endif
929
930static char *lookup_config_lib(elfobj *elf, char *fname)
931{
932 static char buf[__PAX_UTILS_PATH_MAX] = "";
933 const char *ldpath;
934 size_t n;
935
936 array_for_each(ldpaths, n, ldpath) {
937 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
938 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
939 return buf;
940 }
941
942 return NULL;
943}
551 944
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 945static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 946{
554 unsigned long i; 947 unsigned long i;
555 char *needed; 948 char *needed;
556 void *strtbl_void; 949 void *strtbl_void;
557 char *p; 950 char *p;
558 951
952 /*
953 * -n -> op==0 -> print all
954 * -N -> op==1 -> print requested
955 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 956 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
957 return NULL;
560 958
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 959 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 960
563 if (elf->phdr && strtbl_void) { 961 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 962#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 964 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 965 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 966 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 967 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 968 Elf ## B ## _Off offset; \
969 size_t matched = 0; \
970 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 971 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 972 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
973 continue; \
573 offset = EGET(phdr[i].p_offset); \ 974 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 975 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
976 continue; \
977 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 978 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 979 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 980 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 981 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 982 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 983 ++dyn; \
581 continue; \ 984 continue; \
582 } \ 985 } \
583 needed = (char*)(elf->data + offset); \ 986 needed = elf->data + offset; \
584 if (op == 0) { \ 987 if (op == 0) { \
988 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 989 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 990 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 991 if (use_ldpath) { \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 992 if ((p = lookup_config_lib(elf, needed)) != NULL) \
589 needed = p; \ 993 needed = p; \
994 } else if (use_ldcache) { \
995 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
996 needed = p; \
997 } \
590 xstrcat(ret, needed, ret_len); \ 998 xstrcat(ret, needed, ret_len); \
591 } \ 999 } \
592 *found_needed = 1; \ 1000 *found_needed = 1; \
593 } else { \ 1001 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1002 /* -N -> print matching entries */ \
1003 size_t n; \
1004 const char *find_lib_name; \
1005 \
1006 array_for_each(find_lib_arr, n, find_lib_name) { \
1007 int invert = 1; \
1008 if (find_lib_name[0] == '!') \
1009 invert = 0, ++find_lib_name; \
1010 if (!strcmp(find_lib_name, needed) == invert) \
1011 ++matched; \
1012 } \
1013 \
1014 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 1015 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 1016 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 1017 } \
598 } \ 1018 } \
599 } \ 1019 } \
600 ++dyn; \ 1020 ++dyn; \
601 } \ 1021 } \
630} 1050}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1051static char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1052{
633 unsigned long i; 1053 unsigned long i;
634 struct stat s; 1054 struct stat s;
1055 char dynamic = 0;
635 1056
636 if (!show_bind) return NULL; 1057 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1058 if (!elf->phdr) return NULL;
638 1059
639#define SHOW_BIND(B) \ 1060#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1062 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1063 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1064 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1065 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1066 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1067 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1068 dynamic = 1; \
647 offset = EGET(phdr[i].p_offset); \ 1069 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1070 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1071 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1072 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1073 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1074 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1075 { \
654 if (be_quiet) return NULL; \ 1076 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1084 SHOW_BIND(32)
663 SHOW_BIND(64) 1085 SHOW_BIND(64)
664 1086
665 if (be_wewy_wewy_quiet) return NULL; 1087 if (be_wewy_wewy_quiet) return NULL;
666 1088
1089 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1090 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1091 return NULL;
669 } else { 1092 } else {
670 *found_bind = 1; 1093 *found_bind = 1;
671 return (char *) "LAZY"; 1094 return (char *)(dynamic ? "LAZY" : "STATIC");
672 } 1095 }
673} 1096}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1097static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1098{
676 unsigned long i; 1099 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1111 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1112 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1113 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1114 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1115 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1116 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1117 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1118 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1119 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1120 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1121 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1122 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1123 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1124 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1125 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1126 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1127 ++dyn; \
705 continue; \ 1128 continue; \
706 } \ 1129 } \
707 soname = (char*)(elf->data + offset); \ 1130 soname = elf->data + offset; \
708 *found_soname = 1; \ 1131 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1132 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1133 } \
711 ++dyn; \ 1134 ++dyn; \
712 } \ 1135 } \
715 SHOW_SONAME(64) 1138 SHOW_SONAME(64)
716 } 1139 }
717 1140
718 return NULL; 1141 return NULL;
719} 1142}
1143
1144/*
1145 * We support the symbol form:
1146 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1147 * If the symbol name is empty, then all symbols are matched.
1148 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1149 * Do not rely on this output format at all.
1150 * Otherwise the symbol name is used to search (either regex or string compare).
1151 * If the first char of the symbol name is a plus ("+"), then only match
1152 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1153 * Putting modifiers in between the percent signs allows for more in depth
1154 * filters. There are groups of modifiers. If you don't specify a member
1155 * of a group, then all types in that group are matched. The current
1156 * groups and their types are:
1157 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1158 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1159 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1160 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1161 * You can search for multiple symbols at once by seperating with a comma (",").
1162 *
1163 * Some examples:
1164 * ELFs with a weak function "foo":
1165 * scanelf -s %wf%foo <ELFs>
1166 * ELFs that define the symbol "main":
1167 * scanelf -s +main <ELFs>
1168 * scanelf -s %d%main <ELFs>
1169 * ELFs that refer to the undefined symbol "brk":
1170 * scanelf -s -brk <ELFs>
1171 * scanelf -s %u%brk <ELFs>
1172 * All global defined objects in an ELF:
1173 * scanelf -s %ogd% <ELF>
1174 */
1175static void
1176scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1177 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1178{
1179 char *this_sym, *next_sym, saved = saved;
1180
1181 /* allow the user to specify a comma delimited list of symbols to search for */
1182 next_sym = NULL;
1183 do {
1184 bool inc_notype, inc_object, inc_func, inc_file,
1185 inc_local, inc_global, inc_weak,
1186 inc_def, inc_undef, inc_abs, inc_common;
1187
1188 if (next_sym) {
1189 next_sym[-1] = saved;
1190 this_sym = next_sym;
1191 } else
1192 this_sym = find_sym;
1193 if ((next_sym = strchr(this_sym, ','))) {
1194 /* make parsing easier by killing the comma temporarily */
1195 saved = *next_sym;
1196 *next_sym = '\0';
1197 next_sym += 1;
1198 }
1199
1200 /* symbol selection! */
1201 inc_notype = inc_object = inc_func = inc_file = \
1202 inc_local = inc_global = inc_weak = \
1203 inc_def = inc_undef = inc_abs = inc_common = \
1204 (*this_sym != '%');
1205
1206 /* parse the contents of %...% */
1207 if (!inc_notype) {
1208 while (*(this_sym++)) {
1209 if (*this_sym == '%') {
1210 ++this_sym;
1211 break;
1212 }
1213 switch (*this_sym) {
1214 case 'n': inc_notype = true; break;
1215 case 'o': inc_object = true; break;
1216 case 'f': inc_func = true; break;
1217 case 'F': inc_file = true; break;
1218 case 'l': inc_local = true; break;
1219 case 'g': inc_global = true; break;
1220 case 'w': inc_weak = true; break;
1221 case 'd': inc_def = true; break;
1222 case 'u': inc_undef = true; break;
1223 case 'a': inc_abs = true; break;
1224 case 'c': inc_common = true; break;
1225 default: err("invalid symbol selector '%c'", *this_sym);
1226 }
1227 }
1228
1229 /* If no types are matched, not match all */
1230 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1231 inc_notype = inc_object = inc_func = inc_file = true;
1232 if (!inc_local && !inc_global && !inc_weak)
1233 inc_local = inc_global = inc_weak = true;
1234 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1235 inc_def = inc_undef = inc_abs = inc_common = true;
1236
1237 /* backwards compat for defined/undefined short hand */
1238 } else if (*this_sym == '+') {
1239 inc_undef = false;
1240 ++this_sym;
1241 } else if (*this_sym == '-') {
1242 inc_def = inc_abs = inc_common = false;
1243 ++this_sym;
1244 }
1245
1246 /* filter symbols */
1247 if ((!inc_notype && stt == STT_NOTYPE) || \
1248 (!inc_object && stt == STT_OBJECT) || \
1249 (!inc_func && stt == STT_FUNC ) || \
1250 (!inc_file && stt == STT_FILE ) || \
1251 (!inc_local && stb == STB_LOCAL ) || \
1252 (!inc_global && stb == STB_GLOBAL) || \
1253 (!inc_weak && stb == STB_WEAK ) || \
1254 (!inc_def && shn && shn < SHN_LORESERVE) || \
1255 (!inc_undef && shn == SHN_UNDEF ) || \
1256 (!inc_abs && shn == SHN_ABS ) || \
1257 (!inc_common && shn == SHN_COMMON))
1258 continue;
1259
1260 if (*this_sym == '*') {
1261 /* a "*" symbol gets you debug output */
1262 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1263 ((*found_sym == 0) ? "\n\t" : "\t"),
1264 elf->base_filename,
1265 size,
1266 get_elfstttype(stt),
1267 get_elfstbtype(stb),
1268 get_elfshntype(shn),
1269 symname);
1270 goto matched;
1271
1272 } else {
1273 if (g_match) {
1274 /* regex match the symbol */
1275 if (rematch(this_sym, symname, REG_EXTENDED) != 0)
1276 continue;
1277
1278 } else if (*this_sym) {
1279 /* give empty symbols a "pass", else do a normal compare */
1280 const size_t len = strlen(this_sym);
1281 if (!(strncmp(this_sym, symname, len) == 0 &&
1282 /* Accept unversioned symbol names */
1283 (symname[len] == '\0' || symname[len] == '@')))
1284 continue;
1285 }
1286
1287 if (be_semi_verbose) {
1288 char buf[1024];
1289 snprintf(buf, sizeof(buf), "%lX %s %s",
1290 size,
1291 get_elfstttype(stt),
1292 this_sym);
1293 *ret = xstrdup(buf);
1294 } else {
1295 if (*ret) xchrcat(ret, ',', ret_len);
1296 xstrcat(ret, symname, ret_len);
1297 }
1298
1299 goto matched;
1300 }
1301 } while (next_sym);
1302
1303 return;
1304
1305 matched:
1306 *found_sym = 1;
1307 if (next_sym)
1308 next_sym[-1] = saved;
1309}
1310
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1311static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1312{
722 unsigned long i;
723 char *ret; 1313 char *ret;
724 void *symtab_void, *strtab_void; 1314 void *symtab_void, *strtab_void;
725 1315
726 if (!find_sym) return NULL; 1316 if (!find_sym) return NULL;
727 ret = find_sym; 1317 ret = NULL;
728 1318
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1319 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1320
731 if (symtab_void && strtab_void) { 1321 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1322#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1323 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1324 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1325 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1326 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1327 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1328 char *symname; \
1329 size_t ret_len = 0; \
1330 if (cnt) \
1331 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1332 for (i = 0; i < cnt; ++i) { \
1333 if ((void*)sym > elf->data_end) { \
1334 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1335 goto break_out; \
1336 } \
740 if (sym->st_name) { \ 1337 if (sym->st_name) { \
1338 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1339 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1340 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1341 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1342 ++sym; \
745 elf->base_filename, \ 1343 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1344 } \
1345 scanelf_match_symname(elf, found_sym, \
1346 &ret, &ret_len, symname, \
1347 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1348 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1349 EGET(sym->st_shndx), \
1350 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1351 EGET(sym->st_size)); \
766 } \ 1352 } \
767 ++sym; \ 1353 ++sym; \
768 } } 1354 } \
1355 }
769 FIND_SYM(32) 1356 FIND_SYM(32)
770 FIND_SYM(64) 1357 FIND_SYM(64)
771 } 1358 }
772 1359
773break_out: 1360break_out:
776 if (*find_sym != '*' && *found_sym) 1363 if (*find_sym != '*' && *found_sym)
777 return ret; 1364 return ret;
778 if (be_quiet) 1365 if (be_quiet)
779 return NULL; 1366 return NULL;
780 else 1367 else
781 return (char *)" - "; 1368 return " - ";
782} 1369}
1370
1371static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1372{
1373 if (!find_section)
1374 return NULL;
1375
1376#define FIND_SECTION(B) \
1377 if (elf->elf_class == ELFCLASS ## B) { \
1378 size_t matched, n; \
1379 int invert; \
1380 const char *section_name; \
1381 Elf ## B ## _Shdr *section; \
1382 \
1383 matched = 0; \
1384 array_for_each(find_section_arr, n, section_name) { \
1385 invert = (*section_name == '!' ? 1 : 0); \
1386 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1387 if ((section == NULL && invert) || (section != NULL && !invert)) \
1388 ++matched; \
1389 } \
1390 \
1391 if (matched == array_cnt(find_section_arr)) \
1392 *found_section = 1; \
1393 }
1394 FIND_SECTION(32)
1395 FIND_SECTION(64)
1396
1397 if (be_wewy_wewy_quiet)
1398 return NULL;
1399
1400 if (*found_section)
1401 return find_section;
1402
1403 if (be_quiet)
1404 return NULL;
1405 else
1406 return " - ";
1407}
1408
783/* scan an elf file and show all the fun stuff */ 1409/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1410#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1411static int scanelf_elfobj(elfobj *elf)
786{ 1412{
787 unsigned long i; 1413 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1414 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1415 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1416 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1417 static char *out_buffer = NULL;
794 static size_t out_len; 1418 static size_t out_len;
795 1419
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1420 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1421 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1422 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1423
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1424 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1425 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1426 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1427 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1428 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1429 printf("%s: scanning file\n", elf->filename);
827 1430
828 /* init output buffer */ 1431 /* init output buffer */
829 if (!out_buffer) { 1432 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1433 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1434 out_buffer = xmalloc(out_len);
832 } 1435 }
833 *out_buffer = '\0'; 1436 *out_buffer = '\0';
834 1437
835 /* show the header */ 1438 /* show the header */
836 if (!be_quiet && show_banner) { 1439 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1440 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1441 if (!IS_MODIFIER(out_format[i])) continue;
839 1442
840 switch (out_format[++i]) { 1443 switch (out_format[++i]) {
1444 case '+': break;
841 case '%': break; 1445 case '%': break;
842 case '#': break; 1446 case '#': break;
843 case 'F': 1447 case 'F':
844 case 'p': 1448 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1449 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1450 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1451 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1452 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1453 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1454 case 'r': prints("RPATH "); break;
1455 case 'M': prints("CLASS "); break;
1456 case 'l':
851 case 'n': prints("NEEDED "); break; 1457 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1458 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1459 case 'b': prints("BIND "); break;
1460 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1461 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1462 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1463 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1464 case 'T': prints("TEXTRELS "); break;
1465 case 'k': prints("SECTION "); break;
1466 case 'a': prints("ARCH "); break;
1467 case 'I': prints("OSABI "); break;
1468 case 'Y': prints("EABI "); break;
1469 case 'O': prints("PERM "); break;
1470 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1471 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1472 }
860 } 1473 }
861 if (!found_file) prints("FILE "); 1474 if (!found_file) prints("FILE ");
862 prints("\n"); 1475 prints("\n");
866 1479
867 /* dump all the good stuff */ 1480 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1481 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1482 const char *out;
870 const char *tmp; 1483 const char *tmp;
871 1484 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1485 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1486 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1487 continue;
879 } 1488 }
880 1489
881 out = NULL; 1490 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1491 be_wewy_wewy_quiet = (out_format[i] == '#');
1492 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1493 switch (out_format[++i]) {
1494 case '+':
884 case '%': 1495 case '%':
885 case '#': 1496 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1497 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1498 case 'F':
888 found_file = 1; 1499 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1500 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1501 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1502 break;
892 case 'p': 1503 case 'p':
893 found_file = 1; 1504 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1505 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1506 tmp = elf->filename;
896 if (search_path) { 1507 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1508 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1509 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1510 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1511 len_file > len_search)
901 tmp += len_search; 1512 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1513 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1514 }
904 xstrcat(&out_buffer, tmp, &out_len); 1515 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1516 break;
906 case 'f': 1517 case 'f':
907 found_file = 1; 1518 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1519 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1520 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1521 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1522 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1523 break;
913 case 'o': out = get_elfetype(elf); break; 1524 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1525 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1526 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1527 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1528 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1529 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1530 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1531 case 'D': out = get_endian(elf); break;
1532 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1533 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1534 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1535 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1536 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1537 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1538 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1539 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1540 case 'a': out = get_elfemtype(elf); break;
1541 case 'I': out = get_elfosabi(elf); break;
1542 case 'Y': out = get_elf_eabi(elf); break;
1543 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1544 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1545 }
927 if (out) { 1546 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1547 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1548 }
935 1549
936#define FOUND_SOMETHING() \ 1550#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1551 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1552 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1553 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1554
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1555 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1556 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1557 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1558 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1559 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1560 puts(out_buffer);
947 fflush(stdout); 1561 fflush(stdout);
948 } 1562 }
949 1563
1564 return 0;
1565}
1566
1567/* scan a single elf */
1568static int scanelf_elf(const char *filename, int fd, size_t len)
1569{
1570 int ret = 1;
1571 elfobj *elf;
1572
1573 /* verify this is real ELF */
1574 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1575 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1576 return 2;
1577 }
1578 switch (match_bits) {
1579 case 32:
1580 if (elf->elf_class != ELFCLASS32)
1581 goto label_done;
1582 break;
1583 case 64:
1584 if (elf->elf_class != ELFCLASS64)
1585 goto label_done;
1586 break;
1587 default: break;
1588 }
1589 if (match_etypes) {
1590 char sbuf[126];
1591 strncpy(sbuf, match_etypes, sizeof(sbuf));
1592 if (strchr(match_etypes, ',') != NULL) {
1593 char *p;
1594 while ((p = strrchr(sbuf, ',')) != NULL) {
1595 *p = 0;
1596 if (etype_lookup(p+1) == get_etype(elf))
1597 goto label_ret;
1598 }
1599 }
1600 if (etype_lookup(sbuf) != get_etype(elf))
1601 goto label_done;
1602 }
1603
1604label_ret:
1605 ret = scanelf_elfobj(elf);
1606
1607label_done:
950 unreadelf(elf); 1608 unreadelf(elf);
1609 return ret;
1610}
1611
1612/* scan an archive of elfs */
1613static int scanelf_archive(const char *filename, int fd, size_t len)
1614{
1615 archive_handle *ar;
1616 archive_member *m;
1617 char *ar_buffer;
1618 elfobj *elf;
1619
1620 ar = ar_open_fd(filename, fd);
1621 if (ar == NULL)
1622 return 1;
1623
1624 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1625 while ((m = ar_next(ar)) != NULL) {
1626 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1627 if (cur_pos == -1)
1628 errp("lseek() failed");
1629 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1630 if (elf) {
1631 scanelf_elfobj(elf);
1632 unreadelf(elf);
1633 }
1634 }
1635 munmap(ar_buffer, len);
1636
1637 return 0;
1638}
1639/* scan a file which may be an elf or an archive or some other magical beast */
1640static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1641{
1642 const struct stat *st = st_cache;
1643 struct stat symlink_st;
1644 int fd;
1645
1646 /* always handle regular files and handle symlinked files if no -y */
1647 if (S_ISLNK(st->st_mode)) {
1648 if (!scan_symlink)
1649 return 1;
1650 fstatat(dir_fd, filename, &symlink_st, 0);
1651 st = &symlink_st;
1652 }
1653
1654 if (!S_ISREG(st->st_mode)) {
1655 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1656 return 1;
1657 }
1658
1659 if (match_perms) {
1660 if ((st->st_mode | match_perms) != st->st_mode)
1661 return 1;
1662 }
1663 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1664 if (fd == -1) {
1665 if (fix_elf && errno == ETXTBSY)
1666 warnp("%s: could not fix", filename);
1667 else if (be_verbose > 2)
1668 printf("%s: skipping file: %s\n", filename, strerror(errno));
1669 return 1;
1670 }
1671
1672 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1673 /* if it isn't an ELF, maybe it's an .a archive */
1674 if (scan_archives)
1675 scanelf_archive(filename, fd, st->st_size);
1676
1677 /*
1678 * unreadelf() implicitly closes its fd, so only close it
1679 * when we are returning it in the non-ELF case
1680 */
1681 close(fd);
1682 }
1683
1684 return 0;
951} 1685}
952 1686
953/* scan a directory for ET_EXEC files and print when we find one */ 1687/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1688static int scanelf_dirat(int dir_fd, const char *path)
955{ 1689{
956 register DIR *dir; 1690 register DIR *dir;
957 register struct dirent *dentry; 1691 register struct dirent *dentry;
958 struct stat st_top, st; 1692 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1693 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1694 size_t pathlen = 0, len = 0;
1695 int ret = 0;
1696 int subdir_fd;
961 1697
962 /* make sure path exists */ 1698 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1699 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1700 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1701 return 1;
966 } 1702 }
967 1703
968 /* ok, if it isn't a directory, assume we can open it */ 1704 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1705 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1706 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1707
974 /* now scan the dir looking for fun stuff */ 1708 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1709 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1710 if (subdir_fd == -1)
1711 dir = NULL;
1712 else
1713 dir = fdopendir(subdir_fd);
1714 if (dir == NULL) {
1715 if (subdir_fd != -1)
1716 close(subdir_fd);
1717 warnfp("could not opendir(%s)", path);
977 return; 1718 return 1;
978 } 1719 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1720 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1721
981 pathlen = strlen(path); 1722 subpath = stpcpy(buf, path);
1723 if (subpath[-1] != '/')
1724 *subpath++ = '/';
1725 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1726 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1727 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1728 continue;
1729
1730 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1731 continue;
1732
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1733 len = strlen(dentry->d_name);
986 if (len >= sizeof(buf)) { 1734 if (len + pathlen + 1 >= sizeof(buf)) {
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1735 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
988 (unsigned long)len, (unsigned long)sizeof(buf)); 1736 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
989 continue; 1737 continue;
990 } 1738 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1739 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1740 subpath[len] = '\0';
1741
993 if (S_ISREG(st.st_mode)) 1742 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1743 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1744 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1745 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1746 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1747 }
1000 } 1748 }
1001 closedir(dir); 1749 closedir(dir);
1002}
1003 1750
1751 return ret;
1752}
1753static int scanelf_dir(const char *path)
1754{
1755 return scanelf_dirat(root_fd, root_rel_path(path));
1756}
1757
1004static int scanelf_from_file(char *filename) 1758static int scanelf_from_file(const char *filename)
1005{ 1759{
1006 FILE *fp = NULL; 1760 FILE *fp;
1007 char *p; 1761 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1762 size_t len;
1763 int ret;
1009 1764
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1765 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1766 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1767 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1768 return 1;
1014 1769
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1770 path = NULL;
1771 len = 0;
1772 ret = 0;
1773 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1774 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1775 *p = 0;
1018 search_path = path; 1776 search_path = path;
1019 scanelf_dir(path); 1777 ret = scanelf_dir(path);
1020 } 1778 }
1779 free(path);
1780
1021 if (fp != stdin) 1781 if (fp != stdin)
1022 fclose(fp); 1782 fclose(fp);
1783
1023 return 0; 1784 return ret;
1024} 1785}
1025 1786
1026static void load_ld_so_conf() 1787#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1788
1789static int _load_ld_cache_config(const char *fname)
1027{ 1790{
1028 FILE *fp = NULL; 1791 FILE *fp = NULL;
1029 char *p; 1792 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1793 size_t len;
1031 int i = 0; 1794 int curr_fd = -1;
1032 1795
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1796 fp = fopenat_r(root_fd, root_rel_path(fname));
1797 if (fp == NULL)
1034 return; 1798 return -1;
1035 1799
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1800 path = NULL;
1037 if (*path != '/') 1801 len = 0;
1038 continue; 1802 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1803 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1804 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1805 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1806 *p = 0;
1044 1807
1045 ldpaths[i++] = xstrdup(path); 1808 /* recursive includes of the same file will make this segfault. */
1809 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1810 glob_t gl;
1811 size_t x;
1812 const char *gpath;
1046 1813
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1814 /* re-use existing path buffer ... need to be creative */
1048 break; 1815 if (path[8] != '/')
1816 gpath = memcpy(path + 3, "/etc/", 5);
1817 else
1818 gpath = path + 8;
1819 if (root_fd != AT_FDCWD) {
1820 if (curr_fd == -1) {
1821 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1822 if (fchdir(root_fd))
1823 errp("unable to change to root dir");
1824 }
1825 gpath = root_rel_path(gpath);
1826 }
1827
1828 if (glob(gpath, 0, NULL, &gl) == 0) {
1829 for (x = 0; x < gl.gl_pathc; ++x) {
1830 /* try to avoid direct loops */
1831 if (strcmp(gl.gl_pathv[x], fname) == 0)
1832 continue;
1833 _load_ld_cache_config(gl.gl_pathv[x]);
1834 }
1835 globfree(&gl);
1836 }
1837
1838 /* failed globs are ignored by glibc */
1839 continue;
1049 } 1840 }
1050 ldpaths[i] = NULL; 1841
1842 if (*path != '/')
1843 continue;
1844
1845 xarraypush_str(ldpaths, path);
1846 }
1847 free(path);
1051 1848
1052 fclose(fp); 1849 fclose(fp);
1850
1851 if (curr_fd != -1) {
1852 if (fchdir(curr_fd))
1853 /* don't care */;
1854 close(curr_fd);
1855 }
1856
1857 return 0;
1858}
1859
1860#elif defined(__FreeBSD__) || defined(__DragonFly__)
1861
1862static int _load_ld_cache_config(const char *fname)
1863{
1864 FILE *fp = NULL;
1865 char *b = NULL, *p;
1866 struct elfhints_hdr hdr;
1867
1868 fp = fopenat_r(root_fd, root_rel_path(fname));
1869 if (fp == NULL)
1870 return -1;
1871
1872 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1873 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1874 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1875 {
1876 fclose(fp);
1877 return -1;
1878 }
1879
1880 b = xmalloc(hdr.dirlistlen + 1);
1881 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1882 fclose(fp);
1883 free(b);
1884 return -1;
1885 }
1886
1887 while ((p = strsep(&b, ":"))) {
1888 if (*p == '\0')
1889 continue;
1890 xarraypush_str(ldpaths, p);
1891 }
1892
1893 free(b);
1894 fclose(fp);
1895 return 0;
1896}
1897
1898#else
1899#ifdef __ELF__
1900#warning Cache config support not implemented for your target
1901#endif
1902static int _load_ld_cache_config(const char *fname)
1903{
1904 return 0;
1905}
1906#endif
1907
1908static void load_ld_cache_config(const char *fname)
1909{
1910 bool scan_l, scan_ul, scan_ull;
1911 size_t n;
1912 const char *ldpath;
1913
1914 _load_ld_cache_config(fname);
1915
1916 scan_l = scan_ul = scan_ull = false;
1917 if (array_cnt(ldpaths)) {
1918 array_for_each(ldpaths, n, ldpath) {
1919 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1920 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1921 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1922 }
1923 }
1924
1925 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1926 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1927 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1053} 1928}
1054 1929
1055/* scan /etc/ld.so.conf for paths */ 1930/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1931static void scanelf_ldpath(void)
1057{ 1932{
1058 char scan_l, scan_ul, scan_ull; 1933 size_t n;
1059 int i = 0; 1934 const char *ldpath;
1060 1935
1061 if (!ldpaths[0]) 1936 array_for_each(ldpaths, n, ldpath)
1062 err("Unable to load any paths from ld.so.conf");
1063
1064 scan_l = scan_ul = scan_ull = 0;
1065
1066 while (ldpaths[i]) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1937 scanelf_dir(ldpath);
1071 ++i;
1072 }
1073
1074 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1938}
1078 1939
1079/* scan env PATH for paths */ 1940/* scan env PATH for paths */
1080static void scanelf_envpath() 1941static void scanelf_envpath(void)
1081{ 1942{
1082 char *path, *p; 1943 char *path, *p;
1083 1944
1084 path = getenv("PATH"); 1945 path = getenv("PATH");
1085 if (!path) 1946 if (!path)
1092 } 1953 }
1093 1954
1094 free(path); 1955 free(path);
1095} 1956}
1096 1957
1097 1958/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1959#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1960#define a_argument required_argument
1101static struct option const long_opts[] = { 1961static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1962 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1963 {"ldpath", no_argument, NULL, 'l'},
1964 {"use-ldpath",no_argument, NULL, 129},
1965 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1966 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1967 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1968 {"symlink", no_argument, NULL, 'y'},
1969 {"archives", no_argument, NULL, 'A'},
1970 {"ldcache", no_argument, NULL, 'L'},
1971 {"fix", no_argument, NULL, 'X'},
1972 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1973 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1974 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1975 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1976 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1977 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1978 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1979 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1980 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 1981 {"symbol", a_argument, NULL, 's'},
1982 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 1983 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 1984 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 1985 {"textrels", no_argument, NULL, 'T'},
1986 {"etype", a_argument, NULL, 'E'},
1987 {"bits", a_argument, NULL, 'M'},
1988 {"endian", no_argument, NULL, 'D'},
1989 {"osabi", no_argument, NULL, 'I'},
1990 {"eabi", no_argument, NULL, 'Y'},
1991 {"perms", a_argument, NULL, 'O'},
1992 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 1993 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 1994 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 1995 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 1996 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 1997 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 1998 {"file", a_argument, NULL, 'o'},
1999 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 2000 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 2001 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 2002 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 2003 {NULL, no_argument, NULL, 0x0}
1130}; 2004};
1131 2005
1132static const char *opts_help[] = { 2006static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 2007 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 2008 "Scan all directories in /etc/ld.so.conf",
2009 "Use ld.so.conf to show full path (use with -r/-n)",
2010 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 2011 "Scan directories recursively",
1136 "Don't recursively cross mount points", 2012 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 2013 "Don't scan symlinks",
2014 "Scan archives (.a files)",
2015 "Utilize ld.so.cache to show full path (use with -r/-n)",
2016 "Try and 'fix' bad things (use with -r/-e)",
2017 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 2018 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 2019 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 2020 "Print TEXTREL information",
1141 "Print RPATH information", 2021 "Print RPATH information",
1142 "Print NEEDED information", 2022 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 2023 "Print INTERP information",
1145 "Print BIND information", 2024 "Print BIND information",
1146 "Print SONAME information", 2025 "Print SONAME information",
1147 "Find a specified symbol", 2026 "Find a specified symbol",
2027 "Find a specified section",
1148 "Find a specified library", 2028 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 2029 "Use regex matching rather than string compare (use with -s)",
1150 "Locate cause of TEXTREL", 2030 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 2031 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2032 "Print only ELF files matching numeric bits",
2033 "Print Endianness",
2034 "Print OSABI",
2035 "Print EABI (EM_ARM Only)",
2036 "Print only ELF files matching octal permissions",
2037 "Print ELF file size",
2038 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 2039 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 2040 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 2041 "Use specified format for output",
1155 "Read input stream from a filename", 2042 "Read input stream from a filename",
1156 "Write output stream to a filename", 2043 "Write output stream to a filename",
2044 "Don't emit color in output",
1157 "Don't display the header", 2045 "Don't display the header",
1158 "Print this help and exit", 2046 "Print this help and exit",
1159 "Print version and exit", 2047 "Print version and exit",
1160 NULL 2048 NULL
1161}; 2049};
1163/* display usage and exit */ 2051/* display usage and exit */
1164static void usage(int status) 2052static void usage(int status)
1165{ 2053{
1166 unsigned long i; 2054 unsigned long i;
1167 printf("* Scan ELF binaries for stuff\n\n" 2055 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2056 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2057 printf("Options: -[%s]\n", PARSE_FLAGS);
1170 for (i = 0; long_opts[i].name; ++i) 2058 for (i = 0; long_opts[i].name; ++i) {
2059 /* first output the short flag if it has one */
2060 if (long_opts[i].val > '~')
2061 printf(" ");
2062 else
2063 printf(" -%c, ", long_opts[i].val);
2064
2065 /* then the long flag */
1171 if (long_opts[i].has_arg == no_argument) 2066 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2067 printf("--%-14s", long_opts[i].name);
1173 long_opts[i].name, opts_help[i]);
1174 else 2068 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2069 printf("--%-7s <arg> ", long_opts[i].name);
1176 long_opts[i].name, opts_help[i]);
1177 2070
1178 if (status != EXIT_SUCCESS) 2071 /* finally the help text */
1179 exit(status); 2072 printf("* %s\n", opts_help[i]);
2073 }
1180 2074
1181 puts("\nThe format modifiers for the -F option are:"); 2075 puts("\nFor more information, see the scanelf(1) manpage");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2076 exit(status);
1192} 2077}
1193 2078
1194/* parse command line arguments and preform needed actions */ 2079/* parse command line arguments and preform needed actions */
2080#define do_pax_state(option, flag) \
2081 if (islower(option)) { \
2082 flags &= ~PF_##flag; \
2083 flags |= PF_NO##flag; \
2084 } else { \
2085 flags &= ~PF_NO##flag; \
2086 flags |= PF_##flag; \
2087 }
1195static void parseargs(int argc, char *argv[]) 2088static int parseargs(int argc, char *argv[])
1196{ 2089{
1197 int i; 2090 int i;
1198 char *from_file = NULL; 2091 const char *from_file = NULL;
2092 int ret = 0;
2093 char load_cache_config = 0;
1199 2094
1200 opterr = 0; 2095 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2096 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2097 switch (i) {
1203 2098
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2102 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2103 exit(EXIT_SUCCESS);
1209 break; 2104 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2105 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2106 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2107 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2108 from_file = optarg;
2109 break;
2110 case 'E':
2111 match_etypes = optarg;
2112 break;
2113 case 'M':
2114 match_bits = atoi(optarg);
2115 if (match_bits == 0) {
2116 if (strcmp(optarg, "ELFCLASS32") == 0)
2117 match_bits = 32;
2118 if (strcmp(optarg, "ELFCLASS64") == 0)
2119 match_bits = 64;
2120 }
2121 break;
2122 case 'O':
2123 if (sscanf(optarg, "%o", &match_perms) == -1)
2124 match_bits = 0;
1214 break; 2125 break;
1215 case 'o': { 2126 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2127 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2128 errp("Could not freopen(%s)", optarg);
1219 SET_STDOUT(fp);
1220 break; 2129 break;
1221 } 2130 }
1222 2131 case 'k':
2132 xarraypush_str(find_section_arr, optarg);
2133 break;
1223 case 's': { 2134 case 's': {
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2135 if (find_sym) warn("You prob don't want to specify -s twice");
1225 find_sym = optarg; 2136 find_sym = optarg;
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1227 sprintf(versioned_symname, "%s@", find_sym);
1228 break; 2137 break;
1229 } 2138 }
1230 case 'N': { 2139 case 'N':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2140 xarraypush_str(find_lib_arr, optarg);
1232 find_lib = optarg;
1233 break; 2141 break;
1234 }
1235
1236 case 'F': { 2142 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2143 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2144 out_format = optarg;
1239 break; 2145 break;
1240 } 2146 }
2147 case 'z': {
2148 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2149 size_t x;
1241 2150
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2151 for (x = 0; x < strlen(optarg); x++) {
2152 switch (optarg[x]) {
2153 case 'p':
2154 case 'P':
2155 do_pax_state(optarg[x], PAGEEXEC);
2156 break;
2157 case 's':
2158 case 'S':
2159 do_pax_state(optarg[x], SEGMEXEC);
2160 break;
2161 case 'm':
2162 case 'M':
2163 do_pax_state(optarg[x], MPROTECT);
2164 break;
2165 case 'e':
2166 case 'E':
2167 do_pax_state(optarg[x], EMUTRAMP);
2168 break;
2169 case 'r':
2170 case 'R':
2171 do_pax_state(optarg[x], RANDMMAP);
2172 break;
2173 case 'x':
2174 case 'X':
2175 do_pax_state(optarg[x], RANDEXEC);
2176 break;
2177 default:
2178 break;
2179 }
2180 }
2181 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2182 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2183 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2184 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2185 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2186 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2187 setpax = flags;
2188 break;
2189 }
2190 case 'Z': show_size = 1; break;
1243 case 'L': printcache = 1; break; 2191 case 'g': g_match = 1; break;
2192 case 'L': load_cache_config = use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2193 case 'y': scan_symlink = 0; break;
2194 case 'A': scan_archives = 1; break;
2195 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2196 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2197 case 'l': load_cache_config = scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2198 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2199 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2200 case 'm': dir_crossmount = 0; break;
2201 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2202 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2203 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2204 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2205 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2206 case 'n': show_needed = 1; break;
1256 case 'b': show_bind = 1; break; 2208 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2209 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2210 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2211 case 'q': be_quiet = 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2212 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2213 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2214 case 'D': show_endian = 1; break;
2215 case 'I': show_osabi = 1; break;
2216 case 'Y': show_eabi = 1; break;
2217 case 128:
2218 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2219 if (root_fd == -1)
2220 err("Could not open root: %s", optarg);
2221 break;
2222 case 129: load_cache_config = use_ldpath = 1; break;
1263 case ':': 2223 case ':':
1264 err("Option missing parameter\n"); 2224 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2225 case '?':
1266 err("Unknown option\n"); 2226 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2227 default:
1268 err("Unhandled option '%c'", i); 2228 err("Unhandled option '%c'; please report this", i);
1269 } 2229 }
1270 } 2230 }
1271 2231 if (show_textrels && be_verbose)
2232 has_objdump = bin_in_path("objdump");
2233 /* flatten arrays for display */
2234 if (array_cnt(find_lib_arr))
2235 find_lib = array_flatten_str(find_lib_arr);
2236 if (array_cnt(find_section_arr))
2237 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2238 /* let the format option override all other options */
1273 if (out_format) { 2239 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2240 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2241 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2242 show_textrels = show_perms = show_endian = show_size = \
2243 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2244 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2245 if (!IS_MODIFIER(out_format[i])) continue;
1279 2246
1280 switch (out_format[++i]) { 2247 switch (out_format[++i]) {
2248 case '+': break;
1281 case '%': break; 2249 case '%': break;
1282 case '#': break; 2250 case '#': break;
1283 case 'F': break; 2251 case 'F': break;
1284 case 'p': break; 2252 case 'p': break;
1285 case 'f': break; 2253 case 'f': break;
2254 case 'k': break;
1286 case 's': break; 2255 case 's': break;
1287 case 'N': break; 2256 case 'N': break;
1288 case 'o': break; 2257 case 'o': break;
2258 case 'a': break;
2259 case 'M': break;
2260 case 'Z': show_size = 1; break;
2261 case 'D': show_endian = 1; break;
2262 case 'I': show_osabi = 1; break;
2263 case 'Y': show_eabi = 1; break;
2264 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2265 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2266 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2267 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2268 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2269 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2270 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2271 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2272 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2273 case 'T': show_textrels = 1; break;
1298 default: 2274 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2275 err("invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2276 out_format[i], i+1);
1301 } 2277 }
1302 } 2278 }
1303 2279
1304 /* construct our default format */ 2280 /* construct our default format */
1305 } else { 2281 } else {
1306 size_t fmt_len = 30; 2282 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2283 out_format = xmalloc(sizeof(char) * fmt_len);
2284 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2285 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2286 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2287 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2288 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2289 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2290 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2291 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2292 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2293 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2294 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2295 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2296 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2297 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2298 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2299 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2300 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2301 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2302 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2303 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2304 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2305 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2306
1324 /* now lets actually do the scanning */ 2307 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2308 if (load_cache_config)
1326 load_ld_so_conf(); 2309 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2310 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2311 if (scan_envpath) scanelf_envpath();
2312 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2313 from_file = "-";
1329 if (from_file) { 2314 if (from_file) {
1330 scanelf_from_file(from_file); 2315 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2316 from_file = *argv;
1333 } 2317 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2318 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2319 err("Nothing to scan !?");
1336 while (optind < argc) { 2320 while (optind < argc) {
1337 search_path = argv[optind++]; 2321 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2322 ret = scanelf_dir(search_path);
1339 } 2323 }
1340 2324
1341 /* clean up */ 2325 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2326 xarrayfree(ldpaths);
2327 xarrayfree(find_lib_arr);
2328 xarrayfree(find_section_arr);
2329 free(find_lib);
2330 free(find_section);
1345 2331
1346 if (ldcache != 0) 2332 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2333 munmap(ldcache, ldcache_size);
1348}
1349
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2334 return ret;
1358} 2335}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2336
1369 new_len = strlen(*dst) + strlen(src); 2337static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2338{
1384 static char my_app[2]; 2339 const char *delims = " \t\n";
1385 my_app[0] = append; 2340 char **envvals = NULL;
1386 my_app[1] = '\0'; 2341 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2342 int nentry;
1388}
1389 2343
2344 if ((env = getenv(envvar)) == NULL)
2345 return NULL;
1390 2346
2347 env = xstrdup(env);
2348 if (env == NULL)
2349 return NULL;
2350
2351 s = strtok(env, delims);
2352 if (s == NULL) {
2353 free(env);
2354 return NULL;
2355 }
2356
2357 nentry = 0;
2358 while (s != NULL) {
2359 ++nentry;
2360 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2361 envvals[nentry-1] = s;
2362 s = strtok(NULL, delims);
2363 }
2364 envvals[nentry] = NULL;
2365
2366 /* don't want to free(env) as it contains the memory that backs
2367 * the envvals array of strings */
2368 return envvals;
2369}
2370
2371static void parseenv(void)
2372{
2373 color_init(false);
2374 qa_textrels = get_split_env("QA_TEXTRELS");
2375 qa_execstack = get_split_env("QA_EXECSTACK");
2376 qa_wx_load = get_split_env("QA_WX_LOAD");
2377}
2378
2379#ifdef __PAX_UTILS_CLEANUP
2380static void cleanup(void)
2381{
2382 free(out_format);
2383 free(qa_textrels);
2384 free(qa_execstack);
2385 free(qa_wx_load);
2386}
2387#endif
1391 2388
1392int main(int argc, char *argv[]) 2389int main(int argc, char *argv[])
1393{ 2390{
2391 int ret;
1394 if (argc < 2) 2392 if (argc < 2)
1395 usage(EXIT_FAILURE); 2393 usage(EXIT_FAILURE);
2394 parseenv();
1396 parseargs(argc, argv); 2395 ret = parseargs(argc, argv);
1397 fclose(stdout); 2396 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2397#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2398 cleanup();
2399 warn("The calls to add/delete heap should be off:\n"
2400 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2401 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2402#endif
1401 return EXIT_SUCCESS; 2403 return ret;
1402} 2404}
2405
2406/* Match filename against entries in matchlist, return TRUE
2407 * if the file is listed */
2408static int file_matches_list(const char *filename, char **matchlist)
2409{
2410 char **file;
2411 char *match;
2412 char buf[__PAX_UTILS_PATH_MAX];
2413
2414 if (matchlist == NULL)
2415 return 0;
2416
2417 for (file = matchlist; *file != NULL; file++) {
2418 if (search_path) {
2419 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2420 match = buf;
2421 } else {
2422 match = *file;
2423 }
2424 if (fnmatch(match, filename, 0) == 0)
2425 return 1;
2426 }
2427 return 0;
2428}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.245

  ViewVC Help
Powered by ViewVC 1.1.20