/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.252
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.252 2012/11/18 07:39:45 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.252 2012/11/18 07:39:45 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
67static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 55static char *out_format = NULL;
69static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
70static char gmatch = 0; 58static char g_match = 0;
71static char printcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
72 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
73 66
74caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
75size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
76 72
73static int has_objdump = 0;
74
75/* find the path to a file by name */
76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
80
81 path = getenv("PATH");
82 if (!path)
83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
77/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 125{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
81#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
84 /* debug sections */ \ 144 Elf ## B ## _Shdr *estrtab = strtab; \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 146 Elf ## B ## _Shdr *edynstr = dynstr; \
87 /* runtime sections */ \ 147 \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
90 if (symtab && dynsym) { \ 152 if (symtab && dynsym) \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 154 else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 155 *sym = symtab ? symtab : dynsym; \
94 } \ 156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
95 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 163 else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 164 *str = strtab ? strtab : dynstr; \
99 } \
100 } 165 }
101 GET_SYMTABS(32) 166 GET_SYMTABS(32)
102 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
103} 259}
260
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 262{
106 static char ret[7]; 263 static char ret[7];
107 unsigned long i, shown; 264 unsigned long i, shown;
108 265
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 274 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 275 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 276 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 277 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 278 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 279 if (fix_elf && setpax) { \
280 /* set the paxctl flags */ \
281 ESET(phdr[i].p_flags, setpax); \
282 } \
283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 284 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 286 *found_pax = 1; \
126 ++shown; \ 287 ++shown; \
127 break; \ 288 break; \
128 } \ 289 } \
129 } 290 }
130 SHOW_PAX(32) 291 SHOW_PAX(32)
131 SHOW_PAX(64) 292 SHOW_PAX(64)
132 } 293 }
294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
133 301
134 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 303 if (!*ret) {
136 static char *paxflags; 304 static char *paxflags;
137 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
150 318
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 320{
153 static char ret[12]; 321 static char ret[12];
154 char *found; 322 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
157 324
158 if (!show_phdr) return NULL; 325 if (!show_phdr) return NULL;
159 326
160 memcpy(ret, "--- --- ---\0", 12); 327 memcpy(ret, "--- --- ---\0", 12);
161 328
162 shown = 0; 329 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 330 multi_stack = multi_relro = multi_load = 0;
164 331
332#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 333#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 334 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 336 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 337 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 338 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
175 found = found_phdr; \ 346 found = found_phdr; \
176 offset = 0; \ 347 offset = 0; \
177 check_flags = PF_X; \ 348 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
350 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 352 found = found_relro; \
181 offset = 4; \ 353 offset = 4; \
182 check_flags = PF_X; \ 354 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 356 if (file_matches_list(elf->filename, qa_wx_load)) \
357 continue; \
185 found = found_load; \ 358 found = found_load; \
186 offset = 8; \ 359 offset = 8; \
187 check_flags = PF_W|PF_X; \ 360 check_flags = PF_W|PF_X; \
188 } else \ 361 } else \
189 continue; \ 362 continue; \
190 flags = EGET(phdr[i].p_flags); \ 363 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 364 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 365 continue; \
366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
368 ret[3] = ret[7] = '!'; \
369 flags = EGET(phdr[i].p_flags); \
370 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 372 *found = 1; \
195 ++shown; \ 373 ++shown; \
196 } \ 374 } \
197 } else if (elf->shdr != NULL) { \ 375 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 376 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
379 char *str; \
380 if ((void*)strtbl > elf->data_end) \
381 goto skip_this_shdr##B; \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 382 check_flags = SHF_WRITE|SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 383 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 384 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 385 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 386 str = elf->data + offset; \
387 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
388 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 389 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 390 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 391 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 392 continue; \
210 ++*found_phdr; \ 393 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 397 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 398 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 399 break; \
217 } \ 400 } \
218 } \ 401 } \
402 skip_this_shdr##B: \
219 if (!multi_stack) { \ 403 if (!multi_stack) { \
404 if (file_matches_list(elf->filename, qa_execstack)) \
405 return NULL; \
220 *found_phdr = 1; \ 406 *found_phdr = 1; \
221 shown = 1; \ 407 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 408 memcpy(ret, "!WX", 3); \
223 } \ 409 } \
224 } \ 410 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 415 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 416 return NULL;
231 else 417 else
232 return ret; 418 return ret;
233} 419}
420
421/*
422 * See if this ELF contains a DT_TEXTREL tag in any of its
423 * PT_DYNAMIC sections.
424 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 425static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 426{
236 static const char *ret = "TEXTREL"; 427 static const char *ret = "TEXTREL";
237 unsigned long i; 428 unsigned long i;
238 429
239 if (!show_textrel && !show_textrels) return NULL; 430 if (!show_textrel && !show_textrels) return NULL;
431
432 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 433
241 if (elf->phdr) { 434 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 435#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 436 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 437 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 438 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 439 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 440 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 441 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 442 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 443 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 444 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 445 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 446 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 447 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 448 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 449 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 450 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 459 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 460 return NULL;
268 else 461 else
269 return " - "; 462 return " - ";
270} 463}
464
465/*
466 * Scan the .text section to see if there are any relocations in it.
467 * Should rewrite this to check PT_LOAD sections that are marked
468 * Executable rather than the section named '.text'.
469 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 470static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 471{
273 unsigned long s, r, rmax; 472 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 473 void *symtab_void, *strtab_void, *text_void;
275 474
296 Elf ## B ## _Rela *rela; \ 495 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 496 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 497 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 498 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 499 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 500 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 501 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 502 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 503 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 504 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 505 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 506 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 507 } else \
309 continue; \ 508 continue; \
310 /* now see if any of the relocs are in the .text */ \ 509 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 510 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 525 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 526 if (be_verbose <= 2) continue; \
328 } else \ 527 } else \
329 *found_textrels = 1; \ 528 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 529 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 530 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
531 if ((void*)sym > elf->data_end) { \
532 warn("%s: corrupt ELF symbol", elf->filename); \
533 continue; \
534 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 535 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 536 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 537 sym += sym_max; \
335 else \ 538 else \
336 sym = NULL; \ 539 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 540 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 541 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 542 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 543 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 544 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 545 else \
343 printf("(memory/fake?)"); \ 546 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 547 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 548 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 549 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 550 func = NULL; \
348 offset_tmp = 0; \ 551 offset_tmp = 0; \
349 while (sym_max--) { \ 552 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 553 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 554 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 555 offset_tmp = EGET(sym->st_value); \
353 } \ 556 } \
354 ++sym; \ 557 ++sym; \
355 } \ 558 } \
356 printf(" in "); \ 559 printf(" in "); \
357 if (func && func->st_name) \ 560 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 561 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
562 if (r_offset > EGET(func->st_size)) \
563 printf("(optimized out: previous %s)", func_name); \
359 else \ 564 else \
360 printf("(NULL: fake?)"); \ 565 printf("%s", func_name); \
566 } else \
567 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 568 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
569 if (be_verbose && has_objdump) { \
570 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
571 char *sysbuf; \
572 size_t syslen; \
573 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
574 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
575 sysbuf = xmalloc(syslen); \
576 if (end_addr < r_offset) \
577 /* not uncommon when things are optimized out */ \
578 end_addr = r_offset + 0x100; \
579 snprintf(sysbuf, syslen, sysfmt, \
580 (unsigned long)offset_tmp, \
581 (unsigned long)end_addr, \
582 elf->filename, \
583 (unsigned long)r_offset); \
584 fflush(stdout); \
585 if (system(sysbuf)) /* don't care */; \
586 fflush(stdout); \
587 free(sysbuf); \
588 } \
362 } \ 589 } \
363 } } 590 } }
364 SHOW_TEXTRELS(32) 591 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 592 SHOW_TEXTRELS(64)
366 } 593 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 595 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 596
370 return NULL; 597 return NULL;
371} 598}
372 599
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 600static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
601{
375 struct stat st; 602 struct stat st;
376 switch (*item) { 603 switch (*item) {
377 case '/': break; 604 case '/': break;
378 case '.': 605 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 606 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 607 break;
608 case ':':
381 case '\0': 609 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 610 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 611 break;
384 case '$': 612 case '$':
385 if (fstat(elf->fd, &st) != -1) 613 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 614 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 615 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 616 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 617 break;
390 default: 618 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 619 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 620 break;
393 } 621 }
394} 622}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 623static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 624{
397 unsigned long i, s; 625 unsigned long i;
398 char *rpath, *runpath, **r; 626 char *rpath, *runpath, **r;
399 void *strtbl_void; 627 void *strtbl_void;
400 628
401 if (!show_rpath) return; 629 if (!show_rpath) return;
402 630
413 Elf ## B ## _Off offset; \ 641 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 642 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 643 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 644 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 645 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 646 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 647 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 649 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 650 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 651 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 652 if (word == DT_RPATH) { \
425 r = &rpath; \ 653 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 654 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 655 r = &runpath; \
431 } \ 659 } \
432 /* Verify the memory is somewhat sane */ \ 660 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 661 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 662 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 663 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 664 *r = elf->data + offset; \
665 /* cache the length in case we need to nuke this section later on */ \
666 if (fix_elf) \
667 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 668 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 669 if (be_quiet) { \
439 size_t len; \ 670 size_t len; \
440 char *start, *end; \ 671 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 672 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 673 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 674 start = *r; \
444 /* scan each path in : delimited list */ \ 675 /* scan each path in : delimited list */ \
445 while (start) { \ 676 while (start) { \
446 rpath_security_checks(elf, start); \ 677 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 678 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 679 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 680 if (use_ldcache) { \
681 size_t n; \
682 const char *ldpath; \
683 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 684 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 685 *r = end; \
686 /* corner case ... if RPATH reads "/usr/lib:", we want \
687 * to show ':' rather than '' */ \
688 if (end && end[1] != '\0') \
689 (*r)++; \
452 break; \ 690 break; \
453 } \ 691 } \
454 } \ 692 } \
455 if (!*r || !ldpaths[s] || !end) \ 693 if (!*r || !end) \
456 start = NULL; \ 694 break; \
457 else \ 695 else \
458 start = start + len + 1; \ 696 start = start + len + 1; \
459 } \ 697 } \
460 } \ 698 } \
699 if (*r) { \
700 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
701 /* just nuke it */ \
702 nuke_it##B: \
703 memset(*r, 0x00, offset); \
704 *r = NULL; \
705 ESET(dyn->d_tag, DT_DEBUG); \
706 ESET(dyn->d_un.d_ptr, 0); \
707 } else if (fix_elf) { \
708 /* try to clean "bad" paths */ \
709 size_t len, tmpdir_len; \
710 char *start, *end; \
711 const char *tmpdir; \
712 start = *r; \
713 tmpdir = (getenv("TMPDIR") ? : "."); \
714 tmpdir_len = strlen(tmpdir); \
715 while (1) { \
716 end = strchr(start, ':'); \
717 if (start == end) { \
718 eat_this_path##B: \
719 len = strlen(end); \
720 memmove(start, end+1, len); \
721 start[len-1] = '\0'; \
722 end = start - 1; \
723 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
724 if (!end) { \
725 if (start == *r) \
726 goto nuke_it##B; \
727 *--start = '\0'; \
728 } else \
729 goto eat_this_path##B; \
730 } \
731 if (!end) \
732 break; \
733 start = end + 1; \
734 } \
735 if (**r == '\0') \
736 goto nuke_it##B; \
737 } \
738 if (*r) \
461 if (*r) *found_rpath = 1; \ 739 *found_rpath = 1; \
740 } \
462 } \ 741 } \
463 ++dyn; \ 742 ++dyn; \
464 } \ 743 } \
465 } } 744 } }
466 SHOW_RPATH(32) 745 SHOW_RPATH(32)
488 767
489#define LDSO_CACHE_MAGIC "ld.so-" 768#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 769#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 770#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 771#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
772#define FLAG_ANY -1
773#define FLAG_TYPE_MASK 0x00ff
774#define FLAG_LIBC4 0x0000
775#define FLAG_ELF 0x0001
776#define FLAG_ELF_LIBC5 0x0002
777#define FLAG_ELF_LIBC6 0x0003
778#define FLAG_REQUIRED_MASK 0xff00
779#define FLAG_SPARC_LIB64 0x0100
780#define FLAG_IA64_LIB64 0x0200
781#define FLAG_X8664_LIB64 0x0300
782#define FLAG_S390_LIB64 0x0400
783#define FLAG_POWERPC_LIB64 0x0500
784#define FLAG_MIPS64_LIBN32 0x0600
785#define FLAG_MIPS64_LIBN64 0x0700
493 786
494static char *lookup_cache_lib(char *); 787#if defined(__GLIBC__) || defined(__UCLIBC__)
788
495static char *lookup_cache_lib(char *fname) 789static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 790{
497 int fd = 0; 791 int fd;
498 char *strs; 792 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 793 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 794 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 795 struct stat st;
502 796
503 typedef struct { 797 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 798 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 799 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 800 int nlibs;
507 } header_t; 801 } header_t;
802 header_t *header;
508 803
509 typedef struct { 804 typedef struct {
510 int flags; 805 int flags;
511 int sooffset; 806 int sooffset;
512 int liboffset; 807 int liboffset;
513 } libentry_t; 808 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 809 libentry_t *libent;
517 810
518 if (fname == NULL) 811 if (fname == NULL)
519 return NULL; 812 return NULL;
520 813
521 if (ldcache == 0) { 814 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 815 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 816 return NULL;
524 /* save the cache size for latter unmapping */ 817
818 fd = openat(root_fd, cachefile, O_RDONLY);
819 if (fd == -1)
820 return NULL;
821
822 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 823 ldcache_size = st.st_size;
824 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
825 close(fd);
526 826
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 827 if (ldcache == MAP_FAILED) {
828 ldcache = NULL;
528 return NULL; 829 return NULL;
830 }
529 831
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 832 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
833 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
834 {
835 munmap(ldcache, ldcache_size);
836 ldcache = NULL;
533 return NULL; 837 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 838 }
839 } else
840 header = ldcache;
538 841
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 842 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 843 strs = (char *) &libent[header->nlibs];
542 844
543 for (fd = 0; fd < header->nlibs; fd++) { 845 for (fd = 0; fd < header->nlibs; ++fd) {
846 /* This should be more fine grained, but for now we assume that
847 * diff arches will not be cached together, and we ignore the
848 * the different multilib mips cases.
849 */
850 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
851 continue;
852 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
853 continue;
854
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 855 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 856 continue;
857
858 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 859 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
860 break;
547 } 861 }
862
548 return buf; 863 return buf;
549} 864}
550 865
866#elif defined(__NetBSD__)
867static char *lookup_cache_lib(elfobj *elf, const char *fname)
868{
869 static char buf[__PAX_UTILS_PATH_MAX] = "";
870 static struct stat st;
871 size_t n;
872 char *ldpath;
873
874 array_for_each(ldpath, n, ldpath) {
875 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
876 continue; /* if the pathname is too long, or something went wrong, ignore */
877
878 if (stat(buf, &st) != 0)
879 continue; /* if the lib doesn't exist in *ldpath, look further */
880
881 /* NetBSD doesn't actually do sanity checks, it just loads the file
882 * and if that doesn't work, continues looking in other directories.
883 * This cannot easily be safely emulated, unfortunately. For now,
884 * just assume that if it exists, it's a valid library. */
885
886 return buf;
887 }
888
889 /* not found in any path */
890 return NULL;
891}
892#else
893#ifdef __ELF__
894#warning Cache support not implemented for your target
895#endif
896static char *lookup_cache_lib(elfobj *elf, const char *fname)
897{
898 return NULL;
899}
900#endif
901
902static char *lookup_config_lib(elfobj *elf, char *fname)
903{
904 static char buf[__PAX_UTILS_PATH_MAX] = "";
905 const char *ldpath;
906 size_t n;
907
908 array_for_each(ldpaths, n, ldpath) {
909 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
910 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
911 return buf;
912 }
913
914 return NULL;
915}
551 916
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 917static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 918{
554 unsigned long i; 919 unsigned long i;
555 char *needed; 920 char *needed;
556 void *strtbl_void; 921 void *strtbl_void;
557 char *p; 922 char *p;
558 923
924 /*
925 * -n -> op==0 -> print all
926 * -N -> op==1 -> print requested
927 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 928 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
929 return NULL;
560 930
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 931 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 932
563 if (elf->phdr && strtbl_void) { 933 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 934#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 936 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 937 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 938 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 939 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 940 Elf ## B ## _Off offset; \
941 size_t matched = 0; \
942 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 943 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 944 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
945 continue; \
573 offset = EGET(phdr[i].p_offset); \ 946 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 947 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
948 continue; \
949 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 950 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 951 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 952 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 953 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 954 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 955 ++dyn; \
581 continue; \ 956 continue; \
582 } \ 957 } \
583 needed = (char*)(elf->data + offset); \ 958 needed = elf->data + offset; \
584 if (op == 0) { \ 959 if (op == 0) { \
960 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 961 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 962 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 963 if (use_ldpath) { \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 964 if ((p = lookup_config_lib(elf, needed)) != NULL) \
589 needed = p; \ 965 needed = p; \
966 } else if (use_ldcache) { \
967 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
968 needed = p; \
969 } \
590 xstrcat(ret, needed, ret_len); \ 970 xstrcat(ret, needed, ret_len); \
591 } \ 971 } \
592 *found_needed = 1; \ 972 *found_needed = 1; \
593 } else { \ 973 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 974 /* -N -> print matching entries */ \
975 size_t n; \
976 const char *find_lib_name; \
977 \
978 array_for_each(find_lib_arr, n, find_lib_name) { \
979 int invert = 1; \
980 if (find_lib_name[0] == '!') \
981 invert = 0, ++find_lib_name; \
982 if (!strcmp(find_lib_name, needed) == invert) \
983 ++matched; \
984 } \
985 \
986 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 987 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 988 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 989 } \
598 } \ 990 } \
599 } \ 991 } \
600 ++dyn; \ 992 ++dyn; \
601 } \ 993 } \
623 *found_interp = 1; \ 1015 *found_interp = 1; \
624 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1016 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
625 } 1017 }
626 SHOW_INTERP(32) 1018 SHOW_INTERP(32)
627 SHOW_INTERP(64) 1019 SHOW_INTERP(64)
1020 } else {
1021 /* Walk all the program headers to find the PT_INTERP */
1022#define SHOW_PT_INTERP(B) \
1023 if (elf->elf_class == ELFCLASS ## B) { \
1024 unsigned long i; \
1025 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1026 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1027 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1028 if (EGET(phdr[i].p_type) != PT_INTERP) \
1029 continue; \
1030 *found_interp = 1; \
1031 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1032 } \
628 } 1033 }
1034 SHOW_PT_INTERP(32)
1035 SHOW_PT_INTERP(64)
1036 }
1037
629 return NULL; 1038 return NULL;
630} 1039}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1040static char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1041{
633 unsigned long i; 1042 unsigned long i;
634 struct stat s; 1043 struct stat s;
1044 char dynamic = 0;
635 1045
636 if (!show_bind) return NULL; 1046 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1047 if (!elf->phdr) return NULL;
638 1048
639#define SHOW_BIND(B) \ 1049#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1051 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1052 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1053 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1054 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1055 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1056 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1057 dynamic = 1; \
647 offset = EGET(phdr[i].p_offset); \ 1058 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1059 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1060 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1061 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1062 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1063 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1064 { \
654 if (be_quiet) return NULL; \ 1065 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1073 SHOW_BIND(32)
663 SHOW_BIND(64) 1074 SHOW_BIND(64)
664 1075
665 if (be_wewy_wewy_quiet) return NULL; 1076 if (be_wewy_wewy_quiet) return NULL;
666 1077
1078 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1079 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1080 return NULL;
669 } else { 1081 } else {
670 *found_bind = 1; 1082 *found_bind = 1;
671 return (char *) "LAZY"; 1083 return (char *)(dynamic ? "LAZY" : "STATIC");
672 } 1084 }
673} 1085}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1086static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1087{
676 unsigned long i; 1088 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1100 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1101 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1102 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1103 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1104 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1105 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1106 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1107 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1108 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1109 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1110 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1111 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1112 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1113 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1114 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1115 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1116 ++dyn; \
705 continue; \ 1117 continue; \
706 } \ 1118 } \
707 soname = (char*)(elf->data + offset); \ 1119 soname = elf->data + offset; \
708 *found_soname = 1; \ 1120 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1121 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1122 } \
711 ++dyn; \ 1123 ++dyn; \
712 } \ 1124 } \
715 SHOW_SONAME(64) 1127 SHOW_SONAME(64)
716 } 1128 }
717 1129
718 return NULL; 1130 return NULL;
719} 1131}
1132
1133/*
1134 * We support the symbol form:
1135 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1136 * If the symbol name is empty, then all symbols are matched.
1137 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1138 * Do not rely on this output format at all.
1139 * Otherwise the symbol name is used to search (either regex or string compare).
1140 * If the first char of the symbol name is a plus ("+"), then only match
1141 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1142 * Putting modifiers in between the percent signs allows for more in depth
1143 * filters. There are groups of modifiers. If you don't specify a member
1144 * of a group, then all types in that group are matched. The current
1145 * groups and their types are:
1146 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1147 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1148 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1149 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1150 * You can search for multiple symbols at once by seperating with a comma (",").
1151 *
1152 * Some examples:
1153 * ELFs with a weak function "foo":
1154 * scanelf -s %wf%foo <ELFs>
1155 * ELFs that define the symbol "main":
1156 * scanelf -s +main <ELFs>
1157 * scanelf -s %d%main <ELFs>
1158 * ELFs that refer to the undefined symbol "brk":
1159 * scanelf -s -brk <ELFs>
1160 * scanelf -s %u%brk <ELFs>
1161 * All global defined objects in an ELF:
1162 * scanelf -s %ogd% <ELF>
1163 */
1164static void
1165scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1166 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1167{
1168 const char *this_sym;
1169 size_t n;
1170
1171 array_for_each(find_sym_arr, n, this_sym) {
1172 bool inc_notype, inc_object, inc_func, inc_file,
1173 inc_local, inc_global, inc_weak,
1174 inc_def, inc_undef, inc_abs, inc_common;
1175
1176 /* symbol selection! */
1177 inc_notype = inc_object = inc_func = inc_file = \
1178 inc_local = inc_global = inc_weak = \
1179 inc_def = inc_undef = inc_abs = inc_common = \
1180 (*this_sym != '%');
1181
1182 /* parse the contents of %...% */
1183 if (!inc_notype) {
1184 while (*(this_sym++)) {
1185 if (*this_sym == '%') {
1186 ++this_sym;
1187 break;
1188 }
1189 switch (*this_sym) {
1190 case 'n': inc_notype = true; break;
1191 case 'o': inc_object = true; break;
1192 case 'f': inc_func = true; break;
1193 case 'F': inc_file = true; break;
1194 case 'l': inc_local = true; break;
1195 case 'g': inc_global = true; break;
1196 case 'w': inc_weak = true; break;
1197 case 'd': inc_def = true; break;
1198 case 'u': inc_undef = true; break;
1199 case 'a': inc_abs = true; break;
1200 case 'c': inc_common = true; break;
1201 default: err("invalid symbol selector '%c'", *this_sym);
1202 }
1203 }
1204
1205 /* If no types are matched, not match all */
1206 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1207 inc_notype = inc_object = inc_func = inc_file = true;
1208 if (!inc_local && !inc_global && !inc_weak)
1209 inc_local = inc_global = inc_weak = true;
1210 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1211 inc_def = inc_undef = inc_abs = inc_common = true;
1212
1213 /* backwards compat for defined/undefined short hand */
1214 } else if (*this_sym == '+') {
1215 inc_undef = false;
1216 ++this_sym;
1217 } else if (*this_sym == '-') {
1218 inc_def = inc_abs = inc_common = false;
1219 ++this_sym;
1220 }
1221
1222 /* filter symbols */
1223 if ((!inc_notype && stt == STT_NOTYPE) || \
1224 (!inc_object && stt == STT_OBJECT) || \
1225 (!inc_func && stt == STT_FUNC ) || \
1226 (!inc_file && stt == STT_FILE ) || \
1227 (!inc_local && stb == STB_LOCAL ) || \
1228 (!inc_global && stb == STB_GLOBAL) || \
1229 (!inc_weak && stb == STB_WEAK ) || \
1230 (!inc_def && shn && shn < SHN_LORESERVE) || \
1231 (!inc_undef && shn == SHN_UNDEF ) || \
1232 (!inc_abs && shn == SHN_ABS ) || \
1233 (!inc_common && shn == SHN_COMMON))
1234 continue;
1235
1236 if (*this_sym == '*') {
1237 /* a "*" symbol gets you debug output */
1238 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1239 ((*found_sym == 0) ? "\n\t" : "\t"),
1240 elf->base_filename,
1241 size,
1242 get_elfstttype(stt),
1243 get_elfstbtype(stb),
1244 get_elfshntype(shn),
1245 symname);
1246 goto matched;
1247
1248 } else {
1249 if (g_match) {
1250 /* regex match the symbol */
1251 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1252 continue;
1253
1254 } else if (*this_sym) {
1255 /* give empty symbols a "pass", else do a normal compare */
1256 const size_t len = strlen(this_sym);
1257 if (!(strncmp(this_sym, symname, len) == 0 &&
1258 /* Accept unversioned symbol names */
1259 (symname[len] == '\0' || symname[len] == '@')))
1260 continue;
1261 }
1262
1263 if (be_semi_verbose) {
1264 char buf[1024];
1265 snprintf(buf, sizeof(buf), "%lX %s %s",
1266 size,
1267 get_elfstttype(stt),
1268 this_sym);
1269 *ret = xstrdup(buf);
1270 } else {
1271 if (*ret) xchrcat(ret, ',', ret_len);
1272 xstrcat(ret, symname, ret_len);
1273 }
1274
1275 goto matched;
1276 }
1277 }
1278
1279 return;
1280
1281 matched:
1282 *found_sym = 1;
1283}
1284
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1285static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1286{
722 unsigned long i;
723 char *ret; 1287 char *ret;
724 void *symtab_void, *strtab_void; 1288 void *symtab_void, *strtab_void;
725 1289
726 if (!find_sym) return NULL; 1290 if (!find_sym) return NULL;
727 ret = find_sym; 1291 ret = NULL;
728 1292
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1293 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1294
731 if (symtab_void && strtab_void) { 1295 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1296#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1297 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1298 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1299 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1300 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1301 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1302 char *symname; \
1303 size_t ret_len = 0; \
1304 if (cnt) \
1305 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1306 for (i = 0; i < cnt; ++i) { \
1307 if ((void*)sym > elf->data_end) { \
1308 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1309 goto break_out; \
1310 } \
740 if (sym->st_name) { \ 1311 if (sym->st_name) { \
1312 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1313 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1314 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1315 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1316 ++sym; \
745 elf->base_filename, \ 1317 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1318 } \
1319 scanelf_match_symname(elf, found_sym, \
1320 &ret, &ret_len, symname, \
1321 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1322 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1323 EGET(sym->st_shndx), \
1324 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1325 EGET(sym->st_size)); \
766 } \ 1326 } \
767 ++sym; \ 1327 ++sym; \
768 } } 1328 } \
1329 }
769 FIND_SYM(32) 1330 FIND_SYM(32)
770 FIND_SYM(64) 1331 FIND_SYM(64)
771 } 1332 }
772 1333
773break_out: 1334break_out:
776 if (*find_sym != '*' && *found_sym) 1337 if (*find_sym != '*' && *found_sym)
777 return ret; 1338 return ret;
778 if (be_quiet) 1339 if (be_quiet)
779 return NULL; 1340 return NULL;
780 else 1341 else
781 return (char *)" - "; 1342 return " - ";
782} 1343}
1344
1345static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1346{
1347 if (!find_section)
1348 return NULL;
1349
1350#define FIND_SECTION(B) \
1351 if (elf->elf_class == ELFCLASS ## B) { \
1352 size_t matched, n; \
1353 int invert; \
1354 const char *section_name; \
1355 Elf ## B ## _Shdr *section; \
1356 \
1357 matched = 0; \
1358 array_for_each(find_section_arr, n, section_name) { \
1359 invert = (*section_name == '!' ? 1 : 0); \
1360 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1361 if ((section == NULL && invert) || (section != NULL && !invert)) \
1362 ++matched; \
1363 } \
1364 \
1365 if (matched == array_cnt(find_section_arr)) \
1366 *found_section = 1; \
1367 }
1368 FIND_SECTION(32)
1369 FIND_SECTION(64)
1370
1371 if (be_wewy_wewy_quiet)
1372 return NULL;
1373
1374 if (*found_section)
1375 return find_section;
1376
1377 if (be_quiet)
1378 return NULL;
1379 else
1380 return " - ";
1381}
1382
783/* scan an elf file and show all the fun stuff */ 1383/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1384#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1385static int scanelf_elfobj(elfobj *elf)
786{ 1386{
787 unsigned long i; 1387 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1388 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1389 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1390 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1391 static char *out_buffer = NULL;
794 static size_t out_len; 1392 static size_t out_len;
795 1393
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1394 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1395 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1396 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1397
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1398 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1399 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1400 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1401 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1402 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1403 printf("%s: scanning file\n", elf->filename);
827 1404
828 /* init output buffer */ 1405 /* init output buffer */
829 if (!out_buffer) { 1406 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1407 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1408 out_buffer = xmalloc(out_len);
832 } 1409 }
833 *out_buffer = '\0'; 1410 *out_buffer = '\0';
834 1411
835 /* show the header */ 1412 /* show the header */
836 if (!be_quiet && show_banner) { 1413 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1414 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1415 if (!IS_MODIFIER(out_format[i])) continue;
839 1416
840 switch (out_format[++i]) { 1417 switch (out_format[++i]) {
1418 case '+': break;
841 case '%': break; 1419 case '%': break;
842 case '#': break; 1420 case '#': break;
843 case 'F': 1421 case 'F':
844 case 'p': 1422 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1423 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1424 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1425 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1426 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1427 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1428 case 'r': prints("RPATH "); break;
1429 case 'M': prints("CLASS "); break;
1430 case 'l':
851 case 'n': prints("NEEDED "); break; 1431 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1432 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1433 case 'b': prints("BIND "); break;
1434 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1435 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1436 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1437 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1438 case 'T': prints("TEXTRELS "); break;
1439 case 'k': prints("SECTION "); break;
1440 case 'a': prints("ARCH "); break;
1441 case 'I': prints("OSABI "); break;
1442 case 'Y': prints("EABI "); break;
1443 case 'O': prints("PERM "); break;
1444 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1445 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1446 }
860 } 1447 }
861 if (!found_file) prints("FILE "); 1448 if (!found_file) prints("FILE ");
862 prints("\n"); 1449 prints("\n");
866 1453
867 /* dump all the good stuff */ 1454 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1455 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1456 const char *out;
870 const char *tmp; 1457 const char *tmp;
871 1458 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1459 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1460 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1461 continue;
879 } 1462 }
880 1463
881 out = NULL; 1464 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1465 be_wewy_wewy_quiet = (out_format[i] == '#');
1466 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1467 switch (out_format[++i]) {
1468 case '+':
884 case '%': 1469 case '%':
885 case '#': 1470 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1471 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1472 case 'F':
888 found_file = 1; 1473 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1474 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1475 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1476 break;
892 case 'p': 1477 case 'p':
893 found_file = 1; 1478 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1479 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1480 tmp = elf->filename;
896 if (search_path) { 1481 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1482 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1483 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1484 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1485 len_file > len_search)
901 tmp += len_search; 1486 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1487 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1488 }
904 xstrcat(&out_buffer, tmp, &out_len); 1489 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1490 break;
906 case 'f': 1491 case 'f':
907 found_file = 1; 1492 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1493 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1494 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1495 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1496 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1497 break;
913 case 'o': out = get_elfetype(elf); break; 1498 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1499 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1500 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1501 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1502 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1503 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1504 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1505 case 'D': out = get_endian(elf); break;
1506 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1507 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1508 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1509 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1510 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1511 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1512 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1513 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1514 case 'a': out = get_elfemtype(elf); break;
1515 case 'I': out = get_elfosabi(elf); break;
1516 case 'Y': out = get_elf_eabi(elf); break;
1517 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1518 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1519 }
927 if (out) { 1520 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1521 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1522 }
935 1523
936#define FOUND_SOMETHING() \ 1524#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1525 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1526 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1527 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1528
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1529 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1530 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1531 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1532 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1533 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1534 puts(out_buffer);
947 fflush(stdout); 1535 fflush(stdout);
948 } 1536 }
949 1537
1538 return 0;
1539}
1540
1541/* scan a single elf */
1542static int scanelf_elf(const char *filename, int fd, size_t len)
1543{
1544 int ret = 1;
1545 elfobj *elf;
1546
1547 /* verify this is real ELF */
1548 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1549 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1550 return 2;
1551 }
1552 switch (match_bits) {
1553 case 32:
1554 if (elf->elf_class != ELFCLASS32)
1555 goto label_done;
1556 break;
1557 case 64:
1558 if (elf->elf_class != ELFCLASS64)
1559 goto label_done;
1560 break;
1561 default: break;
1562 }
1563 if (match_etypes) {
1564 char sbuf[126];
1565 strncpy(sbuf, match_etypes, sizeof(sbuf));
1566 if (strchr(match_etypes, ',') != NULL) {
1567 char *p;
1568 while ((p = strrchr(sbuf, ',')) != NULL) {
1569 *p = 0;
1570 if (etype_lookup(p+1) == get_etype(elf))
1571 goto label_ret;
1572 }
1573 }
1574 if (etype_lookup(sbuf) != get_etype(elf))
1575 goto label_done;
1576 }
1577
1578label_ret:
1579 ret = scanelf_elfobj(elf);
1580
1581label_done:
950 unreadelf(elf); 1582 unreadelf(elf);
1583 return ret;
1584}
1585
1586/* scan an archive of elfs */
1587static int scanelf_archive(const char *filename, int fd, size_t len)
1588{
1589 archive_handle *ar;
1590 archive_member *m;
1591 char *ar_buffer;
1592 elfobj *elf;
1593
1594 ar = ar_open_fd(filename, fd);
1595 if (ar == NULL)
1596 return 1;
1597
1598 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1599 while ((m = ar_next(ar)) != NULL) {
1600 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1601 if (cur_pos == -1)
1602 errp("lseek() failed");
1603 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1604 if (elf) {
1605 scanelf_elfobj(elf);
1606 unreadelf(elf);
1607 }
1608 }
1609 munmap(ar_buffer, len);
1610
1611 return 0;
1612}
1613/* scan a file which may be an elf or an archive or some other magical beast */
1614static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1615{
1616 const struct stat *st = st_cache;
1617 struct stat symlink_st;
1618 int fd;
1619
1620 /* always handle regular files and handle symlinked files if no -y */
1621 if (S_ISLNK(st->st_mode)) {
1622 if (!scan_symlink)
1623 return 1;
1624 fstatat(dir_fd, filename, &symlink_st, 0);
1625 st = &symlink_st;
1626 }
1627
1628 if (!S_ISREG(st->st_mode)) {
1629 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1630 return 1;
1631 }
1632
1633 if (match_perms) {
1634 if ((st->st_mode | match_perms) != st->st_mode)
1635 return 1;
1636 }
1637 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1638 if (fd == -1) {
1639 if (fix_elf && errno == ETXTBSY)
1640 warnp("%s: could not fix", filename);
1641 else if (be_verbose > 2)
1642 printf("%s: skipping file: %s\n", filename, strerror(errno));
1643 return 1;
1644 }
1645
1646 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1647 /* if it isn't an ELF, maybe it's an .a archive */
1648 if (scan_archives)
1649 scanelf_archive(filename, fd, st->st_size);
1650
1651 /*
1652 * unreadelf() implicitly closes its fd, so only close it
1653 * when we are returning it in the non-ELF case
1654 */
1655 close(fd);
1656 }
1657
1658 return 0;
951} 1659}
952 1660
953/* scan a directory for ET_EXEC files and print when we find one */ 1661/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1662static int scanelf_dirat(int dir_fd, const char *path)
955{ 1663{
956 register DIR *dir; 1664 register DIR *dir;
957 register struct dirent *dentry; 1665 register struct dirent *dentry;
958 struct stat st_top, st; 1666 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1667 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1668 size_t pathlen = 0, len = 0;
1669 int ret = 0;
1670 int subdir_fd;
961 1671
962 /* make sure path exists */ 1672 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1673 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1674 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1675 return 1;
966 } 1676 }
967 1677
968 /* ok, if it isn't a directory, assume we can open it */ 1678 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1679 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1680 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1681
974 /* now scan the dir looking for fun stuff */ 1682 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1683 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1684 if (subdir_fd == -1)
1685 dir = NULL;
1686 else
1687 dir = fdopendir(subdir_fd);
1688 if (dir == NULL) {
1689 if (subdir_fd != -1)
1690 close(subdir_fd);
1691 warnfp("could not opendir(%s)", path);
977 return; 1692 return 1;
978 } 1693 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1694 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1695
981 pathlen = strlen(path); 1696 subpath = stpcpy(buf, path);
1697 if (subpath[-1] != '/')
1698 *subpath++ = '/';
1699 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1700 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1701 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1702 continue;
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1703
986 if (len >= sizeof(buf)) { 1704 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
988 (unsigned long)len, (unsigned long)sizeof(buf));
989 continue; 1705 continue;
1706
1707 len = strlen(dentry->d_name);
1708 if (len + pathlen + 1 >= sizeof(buf)) {
1709 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1710 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1711 continue;
990 } 1712 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1713 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1714 subpath[len] = '\0';
1715
993 if (S_ISREG(st.st_mode)) 1716 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1717 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1718 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1719 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1720 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1721 }
1000 } 1722 }
1001 closedir(dir); 1723 closedir(dir);
1002}
1003 1724
1725 return ret;
1726}
1727static int scanelf_dir(const char *path)
1728{
1729 return scanelf_dirat(root_fd, root_rel_path(path));
1730}
1731
1004static int scanelf_from_file(char *filename) 1732static int scanelf_from_file(const char *filename)
1005{ 1733{
1006 FILE *fp = NULL; 1734 FILE *fp;
1007 char *p; 1735 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1736 size_t len;
1737 int ret;
1009 1738
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1739 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1740 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1741 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1742 return 1;
1014 1743
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1744 path = NULL;
1745 len = 0;
1746 ret = 0;
1747 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1748 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1749 *p = 0;
1018 search_path = path; 1750 search_path = path;
1019 scanelf_dir(path); 1751 ret = scanelf_dir(path);
1020 } 1752 }
1753 free(path);
1754
1021 if (fp != stdin) 1755 if (fp != stdin)
1022 fclose(fp); 1756 fclose(fp);
1757
1023 return 0; 1758 return ret;
1024} 1759}
1025 1760
1026static void load_ld_so_conf() 1761#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1762
1763static int _load_ld_cache_config(const char *fname)
1027{ 1764{
1028 FILE *fp = NULL; 1765 FILE *fp = NULL;
1029 char *p; 1766 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1767 size_t len;
1031 int i = 0; 1768 int curr_fd = -1;
1032 1769
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1770 fp = fopenat_r(root_fd, root_rel_path(fname));
1771 if (fp == NULL)
1034 return; 1772 return -1;
1035 1773
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1774 path = NULL;
1037 if (*path != '/') 1775 len = 0;
1038 continue; 1776 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1777 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1778 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1779 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1780 *p = 0;
1044 1781
1045 ldpaths[i++] = xstrdup(path); 1782 /* recursive includes of the same file will make this segfault. */
1783 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1784 glob_t gl;
1785 size_t x;
1786 const char *gpath;
1046 1787
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1788 /* re-use existing path buffer ... need to be creative */
1048 break; 1789 if (path[8] != '/')
1790 gpath = memcpy(path + 3, "/etc/", 5);
1791 else
1792 gpath = path + 8;
1793 if (root_fd != AT_FDCWD) {
1794 if (curr_fd == -1) {
1795 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1796 if (fchdir(root_fd))
1797 errp("unable to change to root dir");
1798 }
1799 gpath = root_rel_path(gpath);
1800 }
1801
1802 if (glob(gpath, 0, NULL, &gl) == 0) {
1803 for (x = 0; x < gl.gl_pathc; ++x) {
1804 /* try to avoid direct loops */
1805 if (strcmp(gl.gl_pathv[x], fname) == 0)
1806 continue;
1807 _load_ld_cache_config(gl.gl_pathv[x]);
1808 }
1809 globfree(&gl);
1810 }
1811
1812 /* failed globs are ignored by glibc */
1813 continue;
1049 } 1814 }
1050 ldpaths[i] = NULL; 1815
1816 if (*path != '/')
1817 continue;
1818
1819 xarraypush_str(ldpaths, path);
1820 }
1821 free(path);
1051 1822
1052 fclose(fp); 1823 fclose(fp);
1824
1825 if (curr_fd != -1) {
1826 if (fchdir(curr_fd))
1827 /* don't care */;
1828 close(curr_fd);
1829 }
1830
1831 return 0;
1832}
1833
1834#elif defined(__FreeBSD__) || defined(__DragonFly__)
1835
1836static int _load_ld_cache_config(const char *fname)
1837{
1838 FILE *fp = NULL;
1839 char *b = NULL, *p;
1840 struct elfhints_hdr hdr;
1841
1842 fp = fopenat_r(root_fd, root_rel_path(fname));
1843 if (fp == NULL)
1844 return -1;
1845
1846 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1847 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1848 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1849 {
1850 fclose(fp);
1851 return -1;
1852 }
1853
1854 b = xmalloc(hdr.dirlistlen + 1);
1855 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1856 fclose(fp);
1857 free(b);
1858 return -1;
1859 }
1860
1861 while ((p = strsep(&b, ":"))) {
1862 if (*p == '\0')
1863 continue;
1864 xarraypush_str(ldpaths, p);
1865 }
1866
1867 free(b);
1868 fclose(fp);
1869 return 0;
1870}
1871
1872#else
1873#ifdef __ELF__
1874#warning Cache config support not implemented for your target
1875#endif
1876static int _load_ld_cache_config(const char *fname)
1877{
1878 return 0;
1879}
1880#endif
1881
1882static void load_ld_cache_config(const char *fname)
1883{
1884 bool scan_l, scan_ul, scan_ull;
1885 size_t n;
1886 const char *ldpath;
1887
1888 _load_ld_cache_config(fname);
1889
1890 scan_l = scan_ul = scan_ull = false;
1891 if (array_cnt(ldpaths)) {
1892 array_for_each(ldpaths, n, ldpath) {
1893 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1894 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1895 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1896 }
1897 }
1898
1899 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1900 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1901 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1053} 1902}
1054 1903
1055/* scan /etc/ld.so.conf for paths */ 1904/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1905static void scanelf_ldpath(void)
1057{ 1906{
1058 char scan_l, scan_ul, scan_ull; 1907 size_t n;
1059 int i = 0; 1908 const char *ldpath;
1060 1909
1061 if (!ldpaths[0]) 1910 array_for_each(ldpaths, n, ldpath)
1062 err("Unable to load any paths from ld.so.conf");
1063
1064 scan_l = scan_ul = scan_ull = 0;
1065
1066 while (ldpaths[i]) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1911 scanelf_dir(ldpath);
1071 ++i;
1072 }
1073
1074 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1912}
1078 1913
1079/* scan env PATH for paths */ 1914/* scan env PATH for paths */
1080static void scanelf_envpath() 1915static void scanelf_envpath(void)
1081{ 1916{
1082 char *path, *p; 1917 char *path, *p;
1083 1918
1084 path = getenv("PATH"); 1919 path = getenv("PATH");
1085 if (!path) 1920 if (!path)
1092 } 1927 }
1093 1928
1094 free(path); 1929 free(path);
1095} 1930}
1096 1931
1097 1932/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1933#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1934#define a_argument required_argument
1101static struct option const long_opts[] = { 1935static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1936 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1937 {"ldpath", no_argument, NULL, 'l'},
1938 {"use-ldpath",no_argument, NULL, 129},
1939 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1940 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1941 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1942 {"symlink", no_argument, NULL, 'y'},
1943 {"archives", no_argument, NULL, 'A'},
1944 {"ldcache", no_argument, NULL, 'L'},
1945 {"fix", no_argument, NULL, 'X'},
1946 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1947 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1948 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1949 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1950 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1951 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1952 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1953 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1954 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 1955 {"symbol", a_argument, NULL, 's'},
1956 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 1957 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 1958 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 1959 {"textrels", no_argument, NULL, 'T'},
1960 {"etype", a_argument, NULL, 'E'},
1961 {"bits", a_argument, NULL, 'M'},
1962 {"endian", no_argument, NULL, 'D'},
1963 {"osabi", no_argument, NULL, 'I'},
1964 {"eabi", no_argument, NULL, 'Y'},
1965 {"perms", a_argument, NULL, 'O'},
1966 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 1967 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 1968 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 1969 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 1970 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 1971 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 1972 {"file", a_argument, NULL, 'o'},
1973 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 1974 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 1975 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 1976 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 1977 {NULL, no_argument, NULL, 0x0}
1130}; 1978};
1131 1979
1132static const char *opts_help[] = { 1980static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 1981 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 1982 "Scan all directories in /etc/ld.so.conf",
1983 "Use ld.so.conf to show full path (use with -r/-n)",
1984 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 1985 "Scan directories recursively",
1136 "Don't recursively cross mount points", 1986 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 1987 "Don't scan symlinks",
1988 "Scan archives (.a files)",
1989 "Utilize ld.so.cache to show full path (use with -r/-n)",
1990 "Try and 'fix' bad things (use with -r/-e)",
1991 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 1992 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 1993 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 1994 "Print TEXTREL information",
1141 "Print RPATH information", 1995 "Print RPATH information",
1142 "Print NEEDED information", 1996 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 1997 "Print INTERP information",
1145 "Print BIND information", 1998 "Print BIND information",
1146 "Print SONAME information", 1999 "Print SONAME information",
1147 "Find a specified symbol", 2000 "Find a specified symbol",
2001 "Find a specified section",
1148 "Find a specified library", 2002 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 2003 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1150 "Locate cause of TEXTREL", 2004 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 2005 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2006 "Print only ELF files matching numeric bits",
2007 "Print Endianness",
2008 "Print OSABI",
2009 "Print EABI (EM_ARM Only)",
2010 "Print only ELF files matching octal permissions",
2011 "Print ELF file size",
2012 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 2013 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 2014 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 2015 "Use specified format for output",
1155 "Read input stream from a filename", 2016 "Read input stream from a filename",
1156 "Write output stream to a filename", 2017 "Write output stream to a filename",
2018 "Don't emit color in output",
1157 "Don't display the header", 2019 "Don't display the header",
1158 "Print this help and exit", 2020 "Print this help and exit",
1159 "Print version and exit", 2021 "Print version and exit",
1160 NULL 2022 NULL
1161}; 2023};
1163/* display usage and exit */ 2025/* display usage and exit */
1164static void usage(int status) 2026static void usage(int status)
1165{ 2027{
1166 unsigned long i; 2028 unsigned long i;
1167 printf("* Scan ELF binaries for stuff\n\n" 2029 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2030 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2031 printf("Options: -[%s]\n", PARSE_FLAGS);
1170 for (i = 0; long_opts[i].name; ++i) 2032 for (i = 0; long_opts[i].name; ++i) {
2033 /* first output the short flag if it has one */
2034 if (long_opts[i].val > '~')
2035 printf(" ");
2036 else
2037 printf(" -%c, ", long_opts[i].val);
2038
2039 /* then the long flag */
1171 if (long_opts[i].has_arg == no_argument) 2040 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2041 printf("--%-14s", long_opts[i].name);
1173 long_opts[i].name, opts_help[i]);
1174 else 2042 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2043 printf("--%-7s <arg> ", long_opts[i].name);
1176 long_opts[i].name, opts_help[i]);
1177 2044
1178 if (status != EXIT_SUCCESS) 2045 /* finally the help text */
1179 exit(status); 2046 printf("* %s\n", opts_help[i]);
2047 }
1180 2048
1181 puts("\nThe format modifiers for the -F option are:"); 2049 puts("\nFor more information, see the scanelf(1) manpage");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2050 exit(status);
1192} 2051}
1193 2052
1194/* parse command line arguments and preform needed actions */ 2053/* parse command line arguments and preform needed actions */
2054#define do_pax_state(option, flag) \
2055 if (islower(option)) { \
2056 flags &= ~PF_##flag; \
2057 flags |= PF_NO##flag; \
2058 } else { \
2059 flags &= ~PF_NO##flag; \
2060 flags |= PF_##flag; \
2061 }
1195static void parseargs(int argc, char *argv[]) 2062static int parseargs(int argc, char *argv[])
1196{ 2063{
1197 int i; 2064 int i;
1198 char *from_file = NULL; 2065 const char *from_file = NULL;
2066 int ret = 0;
2067 char load_cache_config = 0;
1199 2068
1200 opterr = 0; 2069 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2070 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2071 switch (i) {
1203 2072
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2076 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2077 exit(EXIT_SUCCESS);
1209 break; 2078 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2079 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2080 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2081 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2082 from_file = optarg;
2083 break;
2084 case 'E':
2085 match_etypes = optarg;
2086 break;
2087 case 'M':
2088 match_bits = atoi(optarg);
2089 if (match_bits == 0) {
2090 if (strcmp(optarg, "ELFCLASS32") == 0)
2091 match_bits = 32;
2092 if (strcmp(optarg, "ELFCLASS64") == 0)
2093 match_bits = 64;
2094 }
2095 break;
2096 case 'O':
2097 if (sscanf(optarg, "%o", &match_perms) == -1)
2098 match_bits = 0;
1214 break; 2099 break;
1215 case 'o': { 2100 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2101 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2102 errp("Could not freopen(%s)", optarg);
1219 SET_STDOUT(fp);
1220 break; 2103 break;
1221 } 2104 }
1222 2105 case 'k':
2106 xarraypush_str(find_section_arr, optarg);
2107 break;
1223 case 's': { 2108 case 's': {
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2109 /* historically, this was comma delimited */
1225 find_sym = optarg; 2110 char *this_sym = strtok(optarg, ",");
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1)); 2111 if (!this_sym) /* edge case: -s '' */
1227 sprintf(versioned_symname, "%s@", find_sym); 2112 xarraypush_str(find_sym_arr, "");
2113 while (this_sym) {
2114 xarraypush_str(find_sym_arr, this_sym);
2115 this_sym = strtok(NULL, ",");
2116 }
1228 break; 2117 break;
1229 } 2118 }
1230 case 'N': { 2119 case 'N':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2120 xarraypush_str(find_lib_arr, optarg);
1232 find_lib = optarg;
1233 break; 2121 break;
1234 }
1235
1236 case 'F': { 2122 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2123 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2124 out_format = optarg;
1239 break; 2125 break;
1240 } 2126 }
2127 case 'z': {
2128 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2129 size_t x;
1241 2130
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2131 for (x = 0; x < strlen(optarg); x++) {
1243 case 'L': printcache = 1; break; 2132 switch (optarg[x]) {
2133 case 'p':
2134 case 'P':
2135 do_pax_state(optarg[x], PAGEEXEC);
2136 break;
2137 case 's':
2138 case 'S':
2139 do_pax_state(optarg[x], SEGMEXEC);
2140 break;
2141 case 'm':
2142 case 'M':
2143 do_pax_state(optarg[x], MPROTECT);
2144 break;
2145 case 'e':
2146 case 'E':
2147 do_pax_state(optarg[x], EMUTRAMP);
2148 break;
2149 case 'r':
2150 case 'R':
2151 do_pax_state(optarg[x], RANDMMAP);
2152 break;
2153 case 'x':
2154 case 'X':
2155 do_pax_state(optarg[x], RANDEXEC);
2156 break;
2157 default:
2158 break;
2159 }
2160 }
2161 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2162 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2163 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2164 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2165 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2166 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2167 setpax = flags;
2168 break;
2169 }
2170 case 'Z': show_size = 1; break;
2171 case 'g': ++g_match; break;
2172 case 'L': load_cache_config = use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2173 case 'y': scan_symlink = 0; break;
2174 case 'A': scan_archives = 1; break;
2175 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2176 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2177 case 'l': load_cache_config = scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2178 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2179 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2180 case 'm': dir_crossmount = 0; break;
2181 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2182 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2183 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2184 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2185 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2186 case 'n': show_needed = 1; break;
1256 case 'b': show_bind = 1; break; 2188 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2189 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2190 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2191 case 'q': be_quiet = 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2192 case 'v': be_verbose = (be_verbose % 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2193 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2194 case 'D': show_endian = 1; break;
2195 case 'I': show_osabi = 1; break;
2196 case 'Y': show_eabi = 1; break;
2197 case 128:
2198 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2199 if (root_fd == -1)
2200 err("Could not open root: %s", optarg);
2201 break;
2202 case 129: load_cache_config = use_ldpath = 1; break;
1263 case ':': 2203 case ':':
1264 err("Option missing parameter\n"); 2204 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2205 case '?':
1266 err("Unknown option\n"); 2206 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2207 default:
1268 err("Unhandled option '%c'", i); 2208 err("Unhandled option '%c'; please report this", i);
2209 }
2210 }
2211 if (show_textrels && be_verbose)
2212 has_objdump = bin_in_path("objdump");
2213 /* precompile all the regexes */
2214 if (g_match) {
2215 regex_t preg;
2216 const char *this_sym;
2217 size_t n;
2218 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2219
2220 array_for_each(find_sym_arr, n, this_sym) {
2221 /* see scanelf_match_symname for logic info */
2222 switch (this_sym[0]) {
2223 case '%':
2224 while (*(this_sym++))
2225 if (*this_sym == '%') {
2226 ++this_sym;
2227 break;
2228 }
2229 break;
2230 case '+':
2231 case '-':
2232 ++this_sym;
2233 break;
1269 } 2234 }
2235 if (*this_sym == '*')
2236 ++this_sym;
2237
2238 ret = regcomp(&preg, this_sym, flags);
2239 if (ret) {
2240 char err[256];
2241 regerror(ret, &preg, err, sizeof(err));
2242 err("regcomp of %s failed: %s", this_sym, err);
2243 }
2244 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
1270 } 2245 }
1271 2246 }
2247 /* flatten arrays for display */
2248 if (array_cnt(find_sym_arr))
2249 find_sym = array_flatten_str(find_sym_arr);
2250 if (array_cnt(find_lib_arr))
2251 find_lib = array_flatten_str(find_lib_arr);
2252 if (array_cnt(find_section_arr))
2253 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2254 /* let the format option override all other options */
1273 if (out_format) { 2255 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2256 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2257 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2258 show_textrels = show_perms = show_endian = show_size = \
2259 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2260 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2261 if (!IS_MODIFIER(out_format[i])) continue;
1279 2262
1280 switch (out_format[++i]) { 2263 switch (out_format[++i]) {
2264 case '+': break;
1281 case '%': break; 2265 case '%': break;
1282 case '#': break; 2266 case '#': break;
1283 case 'F': break; 2267 case 'F': break;
1284 case 'p': break; 2268 case 'p': break;
1285 case 'f': break; 2269 case 'f': break;
2270 case 'k': break;
1286 case 's': break; 2271 case 's': break;
1287 case 'N': break; 2272 case 'N': break;
1288 case 'o': break; 2273 case 'o': break;
2274 case 'a': break;
2275 case 'M': break;
2276 case 'Z': show_size = 1; break;
2277 case 'D': show_endian = 1; break;
2278 case 'I': show_osabi = 1; break;
2279 case 'Y': show_eabi = 1; break;
2280 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2281 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2282 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2283 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2284 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2285 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2286 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2287 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2288 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2289 case 'T': show_textrels = 1; break;
1298 default: 2290 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2291 err("invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2292 out_format[i], i+1);
1301 } 2293 }
1302 } 2294 }
1303 2295
1304 /* construct our default format */ 2296 /* construct our default format */
1305 } else { 2297 } else {
1306 size_t fmt_len = 30; 2298 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2299 out_format = xmalloc(sizeof(char) * fmt_len);
2300 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2301 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2302 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2303 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2304 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2305 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2306 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2307 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2308 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2309 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2310 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2311 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2312 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2313 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2314 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2315 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2316 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2317 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2318 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2319 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2320 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2321 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2322
1324 /* now lets actually do the scanning */ 2323 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2324 if (load_cache_config)
1326 load_ld_so_conf(); 2325 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2326 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2327 if (scan_envpath) scanelf_envpath();
2328 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2329 from_file = "-";
1329 if (from_file) { 2330 if (from_file) {
1330 scanelf_from_file(from_file); 2331 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2332 from_file = *argv;
1333 } 2333 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2335 err("Nothing to scan !?");
1336 while (optind < argc) { 2336 while (optind < argc) {
1337 search_path = argv[optind++]; 2337 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2338 ret = scanelf_dir(search_path);
1339 } 2339 }
1340 2340
2341#ifdef __PAX_UTILS_CLEANUP
1341 /* clean up */ 2342 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2343 xarrayfree(ldpaths);
2344 xarrayfree(find_sym_arr);
2345 xarrayfree(find_lib_arr);
2346 xarrayfree(find_section_arr);
2347 free(find_sym);
2348 free(find_lib);
2349 free(find_section);
2350 {
2351 size_t n;
2352 regex_t *preg;
2353 array_for_each(find_sym_regex_arr, n, preg)
2354 regfree(preg);
2355 xarrayfree(find_sym_regex_arr);
2356 }
1345 2357
1346 if (ldcache != 0) 2358 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2359 munmap(ldcache, ldcache_size);
1348} 2360#endif
1349 2361
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2362 return ret;
1358} 2363}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2364
1369 new_len = strlen(*dst) + strlen(src); 2365static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2366{
1384 static char my_app[2]; 2367 const char *delims = " \t\n";
1385 my_app[0] = append; 2368 char **envvals = NULL;
1386 my_app[1] = '\0'; 2369 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2370 int nentry;
1388}
1389 2371
2372 if ((env = getenv(envvar)) == NULL)
2373 return NULL;
1390 2374
2375 env = xstrdup(env);
2376 if (env == NULL)
2377 return NULL;
2378
2379 s = strtok(env, delims);
2380 if (s == NULL) {
2381 free(env);
2382 return NULL;
2383 }
2384
2385 nentry = 0;
2386 while (s != NULL) {
2387 ++nentry;
2388 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2389 envvals[nentry-1] = s;
2390 s = strtok(NULL, delims);
2391 }
2392 envvals[nentry] = NULL;
2393
2394 /* don't want to free(env) as it contains the memory that backs
2395 * the envvals array of strings */
2396 return envvals;
2397}
2398
2399static void parseenv(void)
2400{
2401 color_init(false);
2402 qa_textrels = get_split_env("QA_TEXTRELS");
2403 qa_execstack = get_split_env("QA_EXECSTACK");
2404 qa_wx_load = get_split_env("QA_WX_LOAD");
2405}
2406
2407#ifdef __PAX_UTILS_CLEANUP
2408static void cleanup(void)
2409{
2410 free(out_format);
2411 free(qa_textrels);
2412 free(qa_execstack);
2413 free(qa_wx_load);
2414}
2415#endif
1391 2416
1392int main(int argc, char *argv[]) 2417int main(int argc, char *argv[])
1393{ 2418{
2419 int ret;
1394 if (argc < 2) 2420 if (argc < 2)
1395 usage(EXIT_FAILURE); 2421 usage(EXIT_FAILURE);
2422 parseenv();
1396 parseargs(argc, argv); 2423 ret = parseargs(argc, argv);
1397 fclose(stdout); 2424 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2425#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2426 cleanup();
2427 warn("The calls to add/delete heap should be off:\n"
2428 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2429 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2430#endif
1401 return EXIT_SUCCESS; 2431 return ret;
1402} 2432}
2433
2434/* Match filename against entries in matchlist, return TRUE
2435 * if the file is listed */
2436static int file_matches_list(const char *filename, char **matchlist)
2437{
2438 char **file;
2439 char *match;
2440 char buf[__PAX_UTILS_PATH_MAX];
2441
2442 if (matchlist == NULL)
2443 return 0;
2444
2445 for (file = matchlist; *file != NULL; file++) {
2446 if (search_path) {
2447 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2448 match = buf;
2449 } else {
2450 match = *file;
2451 }
2452 if (fnmatch(match, filename, 0) == 0)
2453 return 1;
2454 }
2455 return 0;
2456}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.252

  ViewVC Help
Powered by ViewVC 1.1.20