/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.262
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.262 2014/03/20 08:06:01 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.262 2014/03/20 08:06:01 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
67static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 55static char *out_format = NULL;
69static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
70static char gmatch = 0; 58static char g_match = 0;
71static char printcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
72 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
73 66
74caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
75size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
76 72
73static int has_objdump = 0;
74
75/* find the path to a file by name */
76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
80
81 path = getenv("PATH");
82 if (!path)
83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
77/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 125{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
81#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
84 /* debug sections */ \ 144 Elf ## B ## _Shdr *estrtab = strtab; \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 146 Elf ## B ## _Shdr *edynstr = dynstr; \
87 /* runtime sections */ \ 147 \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
90 if (symtab && dynsym) { \ 152 if (symtab && dynsym) \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 154 else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 155 *sym = symtab ? symtab : dynsym; \
94 } \ 156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
95 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 163 else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 164 *str = strtab ? strtab : dynstr; \
99 } \
100 } 165 }
101 GET_SYMTABS(32) 166 GET_SYMTABS(32)
102 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
103} 259}
260
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 262{
106 static char ret[7]; 263 static char ret[7];
107 unsigned long i, shown; 264 unsigned long i, shown;
108 265
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 274 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 275 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 276 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 277 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 278 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 279 if (fix_elf && setpax) { \
280 /* set the paxctl flags */ \
281 ESET(phdr[i].p_flags, setpax); \
282 } \
283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 284 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 286 *found_pax = 1; \
126 ++shown; \ 287 ++shown; \
127 break; \ 288 break; \
128 } \ 289 } \
129 } 290 }
130 SHOW_PAX(32) 291 SHOW_PAX(32)
131 SHOW_PAX(64) 292 SHOW_PAX(64)
132 } 293 }
294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
133 301
134 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 303 if (!*ret) {
136 static char *paxflags; 304 static char *paxflags;
137 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
150 318
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 320{
153 static char ret[12]; 321 static char ret[12];
154 char *found; 322 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
157 324
158 if (!show_phdr) return NULL; 325 if (!show_phdr) return NULL;
159 326
160 memcpy(ret, "--- --- ---\0", 12); 327 memcpy(ret, "--- --- ---\0", 12);
161 328
162 shown = 0; 329 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 330 multi_stack = multi_relro = multi_load = 0;
164 331
332#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 333#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 334 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 336 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 337 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 338 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
175 found = found_phdr; \ 346 found = found_phdr; \
176 offset = 0; \ 347 offset = 0; \
177 check_flags = PF_X; \ 348 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
350 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 352 found = found_relro; \
181 offset = 4; \ 353 offset = 4; \
182 check_flags = PF_X; \ 354 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 356 if (file_matches_list(elf->filename, qa_wx_load)) \
357 continue; \
185 found = found_load; \ 358 found = found_load; \
186 offset = 8; \ 359 offset = 8; \
187 check_flags = PF_W|PF_X; \ 360 check_flags = PF_W|PF_X; \
188 } else \ 361 } else \
189 continue; \ 362 continue; \
190 flags = EGET(phdr[i].p_flags); \ 363 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 364 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 365 continue; \
366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
368 ret[3] = ret[7] = '!'; \
369 flags = EGET(phdr[i].p_flags); \
370 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 372 *found = 1; \
195 ++shown; \ 373 ++shown; \
196 } \ 374 } \
197 } else if (elf->shdr != NULL) { \ 375 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 376 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
379 char *str; \
380 if ((void*)strtbl > elf->data_end) \
381 goto skip_this_shdr##B; \
382 /* let's flag -w/+x object files since the final ELF will most likely \
383 * need write access to the stack (who doesn't !?). so the combined \
384 * output will bring in +w automatically and that's bad. \
385 */ \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 386 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 387 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 388 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 389 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 390 str = elf->data + offset; \
391 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
392 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 393 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 394 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 395 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 396 continue; \
210 ++*found_phdr; \ 397 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 401 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 402 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 403 break; \
217 } \ 404 } \
218 } \ 405 } \
406 skip_this_shdr##B: \
219 if (!multi_stack) { \ 407 if (!multi_stack) { \
408 if (file_matches_list(elf->filename, qa_execstack)) \
409 return NULL; \
220 *found_phdr = 1; \ 410 *found_phdr = 1; \
221 shown = 1; \ 411 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 412 memcpy(ret, "!WX", 3); \
223 } \ 413 } \
224 } \ 414 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 419 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 420 return NULL;
231 else 421 else
232 return ret; 422 return ret;
233} 423}
424
425/*
426 * See if this ELF contains a DT_TEXTREL tag in any of its
427 * PT_DYNAMIC sections.
428 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 429static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 430{
236 static const char *ret = "TEXTREL"; 431 static const char *ret = "TEXTREL";
237 unsigned long i; 432 unsigned long i;
238 433
239 if (!show_textrel && !show_textrels) return NULL; 434 if (!show_textrel && !show_textrels) return NULL;
435
436 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 437
241 if (elf->phdr) { 438 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 439#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 440 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 441 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 442 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 443 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 444 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 445 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 446 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 447 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 448 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 449 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 450 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 451 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 452 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 453 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 454 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 463 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 464 return NULL;
268 else 465 else
269 return " - "; 466 return " - ";
270} 467}
468
469/*
470 * Scan the .text section to see if there are any relocations in it.
471 * Should rewrite this to check PT_LOAD sections that are marked
472 * Executable rather than the section named '.text'.
473 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 474static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 475{
273 unsigned long s, r, rmax; 476 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 477 void *symtab_void, *strtab_void, *text_void;
275 478
296 Elf ## B ## _Rela *rela; \ 499 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 500 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 501 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 502 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 503 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 504 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 505 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 506 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 507 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 508 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 509 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 510 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 511 } else \
309 continue; \ 512 continue; \
310 /* now see if any of the relocs are in the .text */ \ 513 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 514 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 529 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 530 if (be_verbose <= 2) continue; \
328 } else \ 531 } else \
329 *found_textrels = 1; \ 532 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 533 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 534 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
535 if ((void*)sym > elf->data_end) { \
536 warn("%s: corrupt ELF symbol", elf->filename); \
537 continue; \
538 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 539 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 540 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 541 sym += sym_max; \
335 else \ 542 else \
336 sym = NULL; \ 543 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 544 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 545 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 546 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 547 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 548 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 549 else \
343 printf("(memory/fake?)"); \ 550 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 551 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 552 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 553 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 554 func = NULL; \
348 offset_tmp = 0; \ 555 offset_tmp = 0; \
349 while (sym_max--) { \ 556 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 557 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 558 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 559 offset_tmp = EGET(sym->st_value); \
353 } \ 560 } \
354 ++sym; \ 561 ++sym; \
355 } \ 562 } \
356 printf(" in "); \ 563 printf(" in "); \
357 if (func && func->st_name) \ 564 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 565 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
566 if (r_offset > EGET(func->st_size)) \
567 printf("(optimized out: previous %s)", func_name); \
359 else \ 568 else \
360 printf("(NULL: fake?)"); \ 569 printf("%s", func_name); \
570 } else \
571 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 572 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
573 if (be_verbose && has_objdump) { \
574 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
575 char *sysbuf; \
576 size_t syslen; \
577 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
578 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
579 sysbuf = xmalloc(syslen); \
580 if (end_addr < r_offset) \
581 /* not uncommon when things are optimized out */ \
582 end_addr = r_offset + 0x100; \
583 snprintf(sysbuf, syslen, sysfmt, \
584 (unsigned long)offset_tmp, \
585 (unsigned long)end_addr, \
586 elf->filename, \
587 (unsigned long)r_offset); \
588 fflush(stdout); \
589 if (system(sysbuf)) {/* don't care */} \
590 fflush(stdout); \
591 free(sysbuf); \
592 } \
362 } \ 593 } \
363 } } 594 } }
364 SHOW_TEXTRELS(32) 595 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 596 SHOW_TEXTRELS(64)
366 } 597 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 599 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 600
370 return NULL; 601 return NULL;
371} 602}
372 603
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 604static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
605{
375 struct stat st; 606 struct stat st;
376 switch (*item) { 607 switch (*item) {
377 case '/': break; 608 case '/': break;
378 case '.': 609 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 610 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 611 break;
612 case ':':
381 case '\0': 613 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 614 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 615 break;
384 case '$': 616 case '$':
385 if (fstat(elf->fd, &st) != -1) 617 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 618 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 619 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 620 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 621 break;
390 default: 622 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 623 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 624 break;
393 } 625 }
394} 626}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 627static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 628{
397 unsigned long i, s; 629 unsigned long i;
398 char *rpath, *runpath, **r; 630 char *rpath, *runpath, **r;
399 void *strtbl_void; 631 void *strtbl_void;
400 632
401 if (!show_rpath) return; 633 if (!show_rpath) return;
402 634
413 Elf ## B ## _Off offset; \ 645 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 646 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 647 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 648 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 649 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 650 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 651 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 652 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 653 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 654 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 655 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 656 if (word == DT_RPATH) { \
425 r = &rpath; \ 657 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 658 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 659 r = &runpath; \
431 } \ 663 } \
432 /* Verify the memory is somewhat sane */ \ 664 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 665 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 666 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 667 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 668 *r = elf->data + offset; \
669 /* cache the length in case we need to nuke this section later on */ \
670 if (fix_elf) \
671 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 672 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 673 if (be_quiet) { \
439 size_t len; \ 674 size_t len; \
440 char *start, *end; \ 675 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 676 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 677 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 678 start = *r; \
444 /* scan each path in : delimited list */ \ 679 /* scan each path in : delimited list */ \
445 while (start) { \ 680 while (start) { \
446 rpath_security_checks(elf, start); \ 681 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 682 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 683 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 684 if (use_ldcache) { \
685 size_t n; \
686 const char *ldpath; \
687 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 688 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 689 *r = end; \
690 /* corner case ... if RPATH reads "/usr/lib:", we want \
691 * to show ':' rather than '' */ \
692 if (end && end[1] != '\0') \
693 (*r)++; \
452 break; \ 694 break; \
453 } \ 695 } \
454 } \ 696 } \
455 if (!*r || !ldpaths[s] || !end) \ 697 if (!*r || !end) \
456 start = NULL; \ 698 break; \
457 else \ 699 else \
458 start = start + len + 1; \ 700 start = start + len + 1; \
459 } \ 701 } \
460 } \ 702 } \
703 if (*r) { \
704 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
705 /* just nuke it */ \
706 nuke_it##B: \
707 memset(*r, 0x00, offset); \
708 *r = NULL; \
709 ESET(dyn->d_tag, DT_DEBUG); \
710 ESET(dyn->d_un.d_ptr, 0); \
711 } else if (fix_elf) { \
712 /* try to clean "bad" paths */ \
713 size_t len, tmpdir_len; \
714 char *start, *end; \
715 const char *tmpdir; \
716 start = *r; \
717 tmpdir = (getenv("TMPDIR") ? : "."); \
718 tmpdir_len = strlen(tmpdir); \
719 while (1) { \
720 end = strchr(start, ':'); \
721 if (start == end) { \
722 eat_this_path##B: \
723 len = strlen(end); \
724 memmove(start, end+1, len); \
725 start[len-1] = '\0'; \
726 end = start - 1; \
727 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
728 if (!end) { \
729 if (start == *r) \
730 goto nuke_it##B; \
731 *--start = '\0'; \
732 } else \
733 goto eat_this_path##B; \
734 } \
735 if (!end) \
736 break; \
737 start = end + 1; \
738 } \
739 if (**r == '\0') \
740 goto nuke_it##B; \
741 } \
742 if (*r) \
461 if (*r) *found_rpath = 1; \ 743 *found_rpath = 1; \
744 } \
462 } \ 745 } \
463 ++dyn; \ 746 ++dyn; \
464 } \ 747 } \
465 } } 748 } }
466 SHOW_RPATH(32) 749 SHOW_RPATH(32)
484 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 767 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
485 else if (!be_quiet) 768 else if (!be_quiet)
486 xstrcat(ret, " - ", ret_len); 769 xstrcat(ret, " - ", ret_len);
487} 770}
488 771
772/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
489#define LDSO_CACHE_MAGIC "ld.so-" 773#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 774#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 775#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 776#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
777#define FLAG_ANY -1
778#define FLAG_TYPE_MASK 0x00ff
779#define FLAG_LIBC4 0x0000
780#define FLAG_ELF 0x0001
781#define FLAG_ELF_LIBC5 0x0002
782#define FLAG_ELF_LIBC6 0x0003
783#define FLAG_REQUIRED_MASK 0xff00
784#define FLAG_SPARC_LIB64 0x0100
785#define FLAG_IA64_LIB64 0x0200
786#define FLAG_X8664_LIB64 0x0300
787#define FLAG_S390_LIB64 0x0400
788#define FLAG_POWERPC_LIB64 0x0500
789#define FLAG_MIPS64_LIBN32 0x0600
790#define FLAG_MIPS64_LIBN64 0x0700
791#define FLAG_X8664_LIBX32 0x0800
792#define FLAG_ARM_LIBHF 0x0900
793#define FLAG_AARCH64_LIB64 0x0a00
493 794
494static char *lookup_cache_lib(char *); 795#if defined(__GLIBC__) || defined(__UCLIBC__)
796
495static char *lookup_cache_lib(char *fname) 797static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 798{
497 int fd = 0; 799 int fd;
498 char *strs; 800 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 801 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 802 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 803 struct stat st;
502 804
503 typedef struct { 805 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 806 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 807 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 808 int nlibs;
507 } header_t; 809 } header_t;
810 header_t *header;
508 811
509 typedef struct { 812 typedef struct {
510 int flags; 813 int flags;
511 int sooffset; 814 int sooffset;
512 int liboffset; 815 int liboffset;
513 } libentry_t; 816 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 817 libentry_t *libent;
517 818
518 if (fname == NULL) 819 if (fname == NULL)
519 return NULL; 820 return NULL;
520 821
521 if (ldcache == 0) { 822 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 823 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 824 return NULL;
524 /* save the cache size for latter unmapping */ 825
826 fd = openat(root_fd, cachefile, O_RDONLY);
827 if (fd == -1)
828 return NULL;
829
830 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 831 ldcache_size = st.st_size;
832 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
833 close(fd);
526 834
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 835 if (ldcache == MAP_FAILED) {
836 ldcache = NULL;
528 return NULL; 837 return NULL;
838 }
529 839
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 840 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
841 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
842 {
843 munmap(ldcache, ldcache_size);
844 ldcache = NULL;
533 return NULL; 845 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 846 }
847 } else
848 header = ldcache;
538 849
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 850 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 851 strs = (char *) &libent[header->nlibs];
542 852
543 for (fd = 0; fd < header->nlibs; fd++) { 853 for (fd = 0; fd < header->nlibs; ++fd) {
854 /* This should be more fine grained, but for now we assume that
855 * diff arches will not be cached together, and we ignore the
856 * the different multilib mips cases.
857 */
858 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
859 continue;
860 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
861 continue;
862
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 863 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 864 continue;
865
866 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 867 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
868 break;
547 } 869 }
870
548 return buf; 871 return buf;
549} 872}
550 873
874#elif defined(__NetBSD__)
875static char *lookup_cache_lib(elfobj *elf, const char *fname)
876{
877 static char buf[__PAX_UTILS_PATH_MAX] = "";
878 static struct stat st;
879 size_t n;
880 char *ldpath;
881
882 array_for_each(ldpath, n, ldpath) {
883 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
884 continue; /* if the pathname is too long, or something went wrong, ignore */
885
886 if (stat(buf, &st) != 0)
887 continue; /* if the lib doesn't exist in *ldpath, look further */
888
889 /* NetBSD doesn't actually do sanity checks, it just loads the file
890 * and if that doesn't work, continues looking in other directories.
891 * This cannot easily be safely emulated, unfortunately. For now,
892 * just assume that if it exists, it's a valid library. */
893
894 return buf;
895 }
896
897 /* not found in any path */
898 return NULL;
899}
900#else
901#ifdef __ELF__
902#warning Cache support not implemented for your target
903#endif
904static char *lookup_cache_lib(elfobj *elf, const char *fname)
905{
906 return NULL;
907}
908#endif
909
910static char *lookup_config_lib(const char *fname)
911{
912 static char buf[__PAX_UTILS_PATH_MAX] = "";
913 const char *ldpath;
914 size_t n;
915
916 array_for_each(ldpaths, n, ldpath) {
917 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
918 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
919 return buf;
920 }
921
922 return NULL;
923}
551 924
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 925static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 926{
554 unsigned long i; 927 unsigned long i;
555 char *needed; 928 char *needed;
556 void *strtbl_void; 929 void *strtbl_void;
557 char *p; 930 char *p;
558 931
932 /*
933 * -n -> op==0 -> print all
934 * -N -> op==1 -> print requested
935 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 936 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
937 return NULL;
560 938
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 939 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 940
563 if (elf->phdr && strtbl_void) { 941 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 942#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 944 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 945 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 946 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 947 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 948 Elf ## B ## _Off offset; \
949 size_t matched = 0; \
950 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 951 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 952 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
953 continue; \
573 offset = EGET(phdr[i].p_offset); \ 954 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 955 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
956 continue; \
957 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 958 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 959 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 960 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 961 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 962 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 963 ++dyn; \
581 continue; \ 964 continue; \
582 } \ 965 } \
583 needed = (char*)(elf->data + offset); \ 966 needed = elf->data + offset; \
584 if (op == 0) { \ 967 if (op == 0) { \
968 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 969 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 970 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 971 if (use_ldpath) { \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 972 if ((p = lookup_config_lib(needed)) != NULL) \
589 needed = p; \ 973 needed = p; \
974 } else if (use_ldcache) { \
975 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
976 needed = p; \
977 } \
590 xstrcat(ret, needed, ret_len); \ 978 xstrcat(ret, needed, ret_len); \
591 } \ 979 } \
592 *found_needed = 1; \ 980 *found_needed = 1; \
593 } else { \ 981 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 982 /* -N -> print matching entries */ \
983 size_t n; \
984 const char *find_lib_name; \
985 \
986 array_for_each(find_lib_arr, n, find_lib_name) { \
987 int invert = 1; \
988 if (find_lib_name[0] == '!') \
989 invert = 0, ++find_lib_name; \
990 if (!strcmp(find_lib_name, needed) == invert) \
991 ++matched; \
992 } \
993 \
994 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 995 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 996 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 997 } \
598 } \ 998 } \
599 } \ 999 } \
600 ++dyn; \ 1000 ++dyn; \
601 } \ 1001 } \
623 *found_interp = 1; \ 1023 *found_interp = 1; \
624 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1024 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
625 } 1025 }
626 SHOW_INTERP(32) 1026 SHOW_INTERP(32)
627 SHOW_INTERP(64) 1027 SHOW_INTERP(64)
1028 } else {
1029 /* Walk all the program headers to find the PT_INTERP */
1030#define SHOW_PT_INTERP(B) \
1031 if (elf->elf_class == ELFCLASS ## B) { \
1032 unsigned long i; \
1033 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1034 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1035 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1036 if (EGET(phdr[i].p_type) != PT_INTERP) \
1037 continue; \
1038 *found_interp = 1; \
1039 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1040 } \
628 } 1041 }
1042 SHOW_PT_INTERP(32)
1043 SHOW_PT_INTERP(64)
1044 }
1045
629 return NULL; 1046 return NULL;
630} 1047}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1048static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1049{
633 unsigned long i; 1050 unsigned long i;
634 struct stat s; 1051 struct stat s;
1052 bool dynamic = false;
635 1053
636 if (!show_bind) return NULL; 1054 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1055 if (!elf->phdr) return NULL;
638 1056
639#define SHOW_BIND(B) \ 1057#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1059 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1060 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1061 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1062 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1063 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1064 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1065 dynamic = true; \
647 offset = EGET(phdr[i].p_offset); \ 1066 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1067 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1068 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1069 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1070 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1071 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1072 { \
654 if (be_quiet) return NULL; \ 1073 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1081 SHOW_BIND(32)
663 SHOW_BIND(64) 1082 SHOW_BIND(64)
664 1083
665 if (be_wewy_wewy_quiet) return NULL; 1084 if (be_wewy_wewy_quiet) return NULL;
666 1085
1086 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1087 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1088 return NULL;
669 } else { 1089 } else {
670 *found_bind = 1; 1090 *found_bind = 1;
671 return (char *) "LAZY"; 1091 return dynamic ? "LAZY" : "STATIC";
672 } 1092 }
673} 1093}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1094static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1095{
676 unsigned long i; 1096 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1108 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1109 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1110 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1111 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1112 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1113 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1114 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1115 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1116 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1117 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1118 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1119 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1120 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1121 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1122 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1123 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1124 ++dyn; \
705 continue; \ 1125 continue; \
706 } \ 1126 } \
707 soname = (char*)(elf->data + offset); \ 1127 soname = elf->data + offset; \
708 *found_soname = 1; \ 1128 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1129 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1130 } \
711 ++dyn; \ 1131 ++dyn; \
712 } \ 1132 } \
715 SHOW_SONAME(64) 1135 SHOW_SONAME(64)
716 } 1136 }
717 1137
718 return NULL; 1138 return NULL;
719} 1139}
1140
1141/*
1142 * We support the symbol form:
1143 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1144 * If the symbol name is empty, then all symbols are matched.
1145 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1146 * Do not rely on this output format at all.
1147 * Otherwise the symbol name is used to search (either regex or string compare).
1148 * If the first char of the symbol name is a plus ("+"), then only match
1149 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1150 * Putting modifiers in between the percent signs allows for more in depth
1151 * filters. There are groups of modifiers. If you don't specify a member
1152 * of a group, then all types in that group are matched. The current
1153 * groups and their types are:
1154 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1155 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1156 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1157 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1158 * You can search for multiple symbols at once by seperating with a comma (",").
1159 *
1160 * Some examples:
1161 * ELFs with a weak function "foo":
1162 * scanelf -s %wf%foo <ELFs>
1163 * ELFs that define the symbol "main":
1164 * scanelf -s +main <ELFs>
1165 * scanelf -s %d%main <ELFs>
1166 * ELFs that refer to the undefined symbol "brk":
1167 * scanelf -s -brk <ELFs>
1168 * scanelf -s %u%brk <ELFs>
1169 * All global defined objects in an ELF:
1170 * scanelf -s %ogd% <ELF>
1171 */
1172static void
1173scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1174 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1175{
1176 const char *this_sym;
1177 size_t n;
1178
1179 array_for_each(find_sym_arr, n, this_sym) {
1180 bool inc_notype, inc_object, inc_func, inc_file,
1181 inc_local, inc_global, inc_weak,
1182 inc_def, inc_undef, inc_abs, inc_common;
1183
1184 /* symbol selection! */
1185 inc_notype = inc_object = inc_func = inc_file = \
1186 inc_local = inc_global = inc_weak = \
1187 inc_def = inc_undef = inc_abs = inc_common = \
1188 (*this_sym != '%');
1189
1190 /* parse the contents of %...% */
1191 if (!inc_notype) {
1192 while (*(this_sym++)) {
1193 if (*this_sym == '%') {
1194 ++this_sym;
1195 break;
1196 }
1197 switch (*this_sym) {
1198 case 'n': inc_notype = true; break;
1199 case 'o': inc_object = true; break;
1200 case 'f': inc_func = true; break;
1201 case 'F': inc_file = true; break;
1202 case 'l': inc_local = true; break;
1203 case 'g': inc_global = true; break;
1204 case 'w': inc_weak = true; break;
1205 case 'd': inc_def = true; break;
1206 case 'u': inc_undef = true; break;
1207 case 'a': inc_abs = true; break;
1208 case 'c': inc_common = true; break;
1209 default: err("invalid symbol selector '%c'", *this_sym);
1210 }
1211 }
1212
1213 /* If no types are matched, not match all */
1214 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1215 inc_notype = inc_object = inc_func = inc_file = true;
1216 if (!inc_local && !inc_global && !inc_weak)
1217 inc_local = inc_global = inc_weak = true;
1218 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1219 inc_def = inc_undef = inc_abs = inc_common = true;
1220
1221 /* backwards compat for defined/undefined short hand */
1222 } else if (*this_sym == '+') {
1223 inc_undef = false;
1224 ++this_sym;
1225 } else if (*this_sym == '-') {
1226 inc_def = inc_abs = inc_common = false;
1227 ++this_sym;
1228 }
1229
1230 /* filter symbols */
1231 if ((!inc_notype && stt == STT_NOTYPE) || \
1232 (!inc_object && stt == STT_OBJECT) || \
1233 (!inc_func && stt == STT_FUNC ) || \
1234 (!inc_file && stt == STT_FILE ) || \
1235 (!inc_local && stb == STB_LOCAL ) || \
1236 (!inc_global && stb == STB_GLOBAL) || \
1237 (!inc_weak && stb == STB_WEAK ) || \
1238 (!inc_def && shn && shn < SHN_LORESERVE) || \
1239 (!inc_undef && shn == SHN_UNDEF ) || \
1240 (!inc_abs && shn == SHN_ABS ) || \
1241 (!inc_common && shn == SHN_COMMON))
1242 continue;
1243
1244 if (*this_sym == '*') {
1245 /* a "*" symbol gets you debug output */
1246 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1247 ((*found_sym == 0) ? "\n\t" : "\t"),
1248 elf->base_filename,
1249 size,
1250 get_elfstttype(stt),
1251 get_elfstbtype(stb),
1252 get_elfshntype(shn),
1253 symname);
1254 goto matched;
1255
1256 } else {
1257 if (g_match) {
1258 /* regex match the symbol */
1259 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1260 continue;
1261
1262 } else if (*this_sym) {
1263 /* give empty symbols a "pass", else do a normal compare */
1264 const size_t len = strlen(this_sym);
1265 if (!(strncmp(this_sym, symname, len) == 0 &&
1266 /* Accept unversioned symbol names */
1267 (symname[len] == '\0' || symname[len] == '@')))
1268 continue;
1269 }
1270
1271 if (be_semi_verbose) {
1272 char buf[1024];
1273 snprintf(buf, sizeof(buf), "%lX %s %s",
1274 size,
1275 get_elfstttype(stt),
1276 this_sym);
1277 *ret = xstrdup(buf);
1278 } else {
1279 if (*ret) xchrcat(ret, ',', ret_len);
1280 xstrcat(ret, symname, ret_len);
1281 }
1282
1283 goto matched;
1284 }
1285 }
1286
1287 return;
1288
1289 matched:
1290 *found_sym = 1;
1291}
1292
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1293static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1294{
722 unsigned long i;
723 char *ret; 1295 char *ret;
724 void *symtab_void, *strtab_void; 1296 void *symtab_void, *strtab_void;
725 1297
726 if (!find_sym) return NULL; 1298 if (!find_sym) return NULL;
727 ret = find_sym; 1299 ret = NULL;
728 1300
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1301 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1302
731 if (symtab_void && strtab_void) { 1303 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1304#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1305 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1306 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1307 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1308 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1309 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1310 char *symname; \
1311 size_t ret_len = 0; \
1312 if (cnt) \
1313 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1314 for (i = 0; i < cnt; ++i) { \
1315 if ((void*)sym > elf->data_end) { \
1316 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1317 goto break_out; \
1318 } \
740 if (sym->st_name) { \ 1319 if (sym->st_name) { \
1320 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1321 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1322 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1323 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1324 ++sym; \
745 elf->base_filename, \ 1325 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1326 } \
1327 scanelf_match_symname(elf, found_sym, \
1328 &ret, &ret_len, symname, \
1329 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1330 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1331 EGET(sym->st_shndx), \
1332 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1333 EGET(sym->st_size)); \
766 } \ 1334 } \
767 ++sym; \ 1335 ++sym; \
768 } } 1336 } \
1337 }
769 FIND_SYM(32) 1338 FIND_SYM(32)
770 FIND_SYM(64) 1339 FIND_SYM(64)
771 } 1340 }
772 1341
773break_out: 1342break_out:
776 if (*find_sym != '*' && *found_sym) 1345 if (*find_sym != '*' && *found_sym)
777 return ret; 1346 return ret;
778 if (be_quiet) 1347 if (be_quiet)
779 return NULL; 1348 return NULL;
780 else 1349 else
781 return (char *)" - "; 1350 return " - ";
782} 1351}
1352
1353static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1354{
1355 if (!find_section)
1356 return NULL;
1357
1358#define FIND_SECTION(B) \
1359 if (elf->elf_class == ELFCLASS ## B) { \
1360 size_t matched, n; \
1361 int invert; \
1362 const char *section_name; \
1363 Elf ## B ## _Shdr *section; \
1364 \
1365 matched = 0; \
1366 array_for_each(find_section_arr, n, section_name) { \
1367 invert = (*section_name == '!' ? 1 : 0); \
1368 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1369 if ((section == NULL && invert) || (section != NULL && !invert)) \
1370 ++matched; \
1371 } \
1372 \
1373 if (matched == array_cnt(find_section_arr)) \
1374 *found_section = 1; \
1375 }
1376 FIND_SECTION(32)
1377 FIND_SECTION(64)
1378
1379 if (be_wewy_wewy_quiet)
1380 return NULL;
1381
1382 if (*found_section)
1383 return find_section;
1384
1385 if (be_quiet)
1386 return NULL;
1387 else
1388 return " - ";
1389}
1390
783/* scan an elf file and show all the fun stuff */ 1391/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1392#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1393static int scanelf_elfobj(elfobj *elf)
786{ 1394{
787 unsigned long i; 1395 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1396 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1397 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1398 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1399 static char *out_buffer = NULL;
794 static size_t out_len; 1400 static size_t out_len;
795 1401
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1402 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1403 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1404 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1405
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1406 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1407 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1408 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1409 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1410 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1411 printf("%s: scanning file\n", elf->filename);
827 1412
828 /* init output buffer */ 1413 /* init output buffer */
829 if (!out_buffer) { 1414 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1415 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1416 out_buffer = xmalloc(out_len);
832 } 1417 }
833 *out_buffer = '\0'; 1418 *out_buffer = '\0';
834 1419
835 /* show the header */ 1420 /* show the header */
836 if (!be_quiet && show_banner) { 1421 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1422 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1423 if (!IS_MODIFIER(out_format[i])) continue;
839 1424
840 switch (out_format[++i]) { 1425 switch (out_format[++i]) {
1426 case '+': break;
841 case '%': break; 1427 case '%': break;
842 case '#': break; 1428 case '#': break;
843 case 'F': 1429 case 'F':
844 case 'p': 1430 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1431 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1432 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1433 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1434 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1435 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1436 case 'r': prints("RPATH "); break;
1437 case 'M': prints("CLASS "); break;
1438 case 'l':
851 case 'n': prints("NEEDED "); break; 1439 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1440 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1441 case 'b': prints("BIND "); break;
1442 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1443 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1444 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1445 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1446 case 'T': prints("TEXTRELS "); break;
1447 case 'k': prints("SECTION "); break;
1448 case 'a': prints("ARCH "); break;
1449 case 'I': prints("OSABI "); break;
1450 case 'Y': prints("EABI "); break;
1451 case 'O': prints("PERM "); break;
1452 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1453 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1454 }
860 } 1455 }
861 if (!found_file) prints("FILE "); 1456 if (!found_file) prints("FILE ");
862 prints("\n"); 1457 prints("\n");
866 1461
867 /* dump all the good stuff */ 1462 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1463 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1464 const char *out;
870 const char *tmp; 1465 const char *tmp;
871 1466 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1467 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1468 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1469 continue;
879 } 1470 }
880 1471
881 out = NULL; 1472 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1473 be_wewy_wewy_quiet = (out_format[i] == '#');
1474 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1475 switch (out_format[++i]) {
1476 case '+':
884 case '%': 1477 case '%':
885 case '#': 1478 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1479 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1480 case 'F':
888 found_file = 1; 1481 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1482 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1483 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1484 break;
892 case 'p': 1485 case 'p':
893 found_file = 1; 1486 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1487 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1488 tmp = elf->filename;
896 if (search_path) { 1489 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1490 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1491 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1492 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1493 len_file > len_search)
901 tmp += len_search; 1494 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1495 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1496 }
904 xstrcat(&out_buffer, tmp, &out_len); 1497 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1498 break;
906 case 'f': 1499 case 'f':
907 found_file = 1; 1500 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1501 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1502 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1503 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1504 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1505 break;
913 case 'o': out = get_elfetype(elf); break; 1506 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1507 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1508 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1509 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1510 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1511 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1512 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1513 case 'D': out = get_endian(elf); break;
1514 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1515 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1516 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1517 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1518 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1519 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1520 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1521 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1522 case 'a': out = get_elfemtype(elf); break;
1523 case 'I': out = get_elfosabi(elf); break;
1524 case 'Y': out = get_elf_eabi(elf); break;
1525 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1526 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1527 }
927 if (out) { 1528 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1529 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1530 }
935 1531
936#define FOUND_SOMETHING() \ 1532#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1533 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1534 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1535 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1536
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1537 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1538 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1539 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1540 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1541 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1542 puts(out_buffer);
947 fflush(stdout); 1543 fflush(stdout);
948 } 1544 }
949 1545
1546 return 0;
1547}
1548
1549/* scan a single elf */
1550static int scanelf_elf(const char *filename, int fd, size_t len)
1551{
1552 int ret = 1;
1553 size_t n;
1554 const char *match_etype;
1555 elfobj *elf;
1556
1557 /* verify this is real ELF */
1558 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1559 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1560 return 2;
1561 }
1562 switch (match_bits) {
1563 case 32:
1564 if (elf->elf_class != ELFCLASS32)
1565 goto label_done;
1566 break;
1567 case 64:
1568 if (elf->elf_class != ELFCLASS64)
1569 goto label_done;
1570 break;
1571 default: break;
1572 }
1573
1574 array_for_each(match_etypes, n, match_etype)
1575 if (etype_lookup(match_etype) == get_etype(elf))
1576 goto label_ret;
1577 if (array_cnt(match_etypes))
1578 goto label_done;
1579
1580label_ret:
1581 ret = scanelf_elfobj(elf);
1582
1583label_done:
950 unreadelf(elf); 1584 unreadelf(elf);
1585 return ret;
1586}
1587
1588/* scan an archive of elfs */
1589static int scanelf_archive(const char *filename, int fd, size_t len)
1590{
1591 archive_handle *ar;
1592 archive_member *m;
1593 char *ar_buffer;
1594 elfobj *elf;
1595
1596 ar = ar_open_fd(filename, fd);
1597 if (ar == NULL)
1598 return 1;
1599
1600 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1601 while ((m = ar_next(ar)) != NULL) {
1602 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1603 if (cur_pos == -1)
1604 errp("lseek() failed");
1605 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1606 if (elf) {
1607 scanelf_elfobj(elf);
1608 unreadelf(elf);
1609 }
1610 }
1611 munmap(ar_buffer, len);
1612
1613 return 0;
1614}
1615/* scan a file which may be an elf or an archive or some other magical beast */
1616static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1617{
1618 const struct stat *st = st_cache;
1619 struct stat symlink_st;
1620 int fd;
1621
1622 /* always handle regular files and handle symlinked files if no -y */
1623 if (S_ISLNK(st->st_mode)) {
1624 if (!scan_symlink)
1625 return 1;
1626 fstatat(dir_fd, filename, &symlink_st, 0);
1627 st = &symlink_st;
1628 }
1629
1630 if (!S_ISREG(st->st_mode)) {
1631 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1632 return 1;
1633 }
1634
1635 if (match_perms) {
1636 if ((st->st_mode | match_perms) != st->st_mode)
1637 return 1;
1638 }
1639 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1640 if (fd == -1) {
1641 if (fix_elf && errno == ETXTBSY)
1642 warnp("%s: could not fix", filename);
1643 else if (be_verbose > 2)
1644 printf("%s: skipping file: %s\n", filename, strerror(errno));
1645 return 1;
1646 }
1647
1648 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1649 /* if it isn't an ELF, maybe it's an .a archive */
1650 if (scan_archives)
1651 scanelf_archive(filename, fd, st->st_size);
1652
1653 /*
1654 * unreadelf() implicitly closes its fd, so only close it
1655 * when we are returning it in the non-ELF case
1656 */
1657 close(fd);
1658 }
1659
1660 return 0;
951} 1661}
952 1662
953/* scan a directory for ET_EXEC files and print when we find one */ 1663/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1664static int scanelf_dirat(int dir_fd, const char *path)
955{ 1665{
956 register DIR *dir; 1666 register DIR *dir;
957 register struct dirent *dentry; 1667 register struct dirent *dentry;
958 struct stat st_top, st; 1668 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1669 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1670 size_t pathlen = 0, len = 0;
1671 int ret = 0;
1672 int subdir_fd;
961 1673
962 /* make sure path exists */ 1674 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1675 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1676 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1677 return 1;
966 } 1678 }
967 1679
968 /* ok, if it isn't a directory, assume we can open it */ 1680 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1681 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1682 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1683
974 /* now scan the dir looking for fun stuff */ 1684 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1685 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1686 if (subdir_fd == -1)
1687 dir = NULL;
1688 else
1689 dir = fdopendir(subdir_fd);
1690 if (dir == NULL) {
1691 if (subdir_fd != -1)
1692 close(subdir_fd);
1693 else if (be_verbose > 2)
1694 printf("%s: skipping dir: %s\n", path, strerror(errno));
977 return; 1695 return 1;
978 } 1696 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1697 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1698
981 pathlen = strlen(path); 1699 subpath = stpcpy(buf, path);
1700 if (subpath[-1] != '/')
1701 *subpath++ = '/';
1702 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1703 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1704 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1705 continue;
1706
1707 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1708 continue;
1709
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1710 len = strlen(dentry->d_name);
986 if (len >= sizeof(buf)) { 1711 if (len + pathlen + 1 >= sizeof(buf)) {
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1712 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
988 (unsigned long)len, (unsigned long)sizeof(buf)); 1713 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
989 continue; 1714 continue;
990 } 1715 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1716 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1717 subpath[len] = '\0';
1718
993 if (S_ISREG(st.st_mode)) 1719 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1720 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1721 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1722 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1723 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1724 }
1000 } 1725 }
1001 closedir(dir); 1726 closedir(dir);
1002}
1003 1727
1728 return ret;
1729}
1730static int scanelf_dir(const char *path)
1731{
1732 return scanelf_dirat(root_fd, root_rel_path(path));
1733}
1734
1004static int scanelf_from_file(char *filename) 1735static int scanelf_from_file(const char *filename)
1005{ 1736{
1006 FILE *fp = NULL; 1737 FILE *fp;
1007 char *p; 1738 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1739 size_t len;
1740 int ret;
1009 1741
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1742 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1743 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1744 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1745 return 1;
1014 1746
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1747 path = NULL;
1748 len = 0;
1749 ret = 0;
1750 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1751 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1752 *p = 0;
1018 search_path = path; 1753 search_path = path;
1019 scanelf_dir(path); 1754 ret = scanelf_dir(path);
1020 } 1755 }
1756 free(path);
1757
1021 if (fp != stdin) 1758 if (fp != stdin)
1022 fclose(fp); 1759 fclose(fp);
1760
1023 return 0; 1761 return ret;
1024} 1762}
1025 1763
1026static void load_ld_so_conf() 1764#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1765
1766static int _load_ld_cache_config(const char *fname)
1027{ 1767{
1028 FILE *fp = NULL; 1768 FILE *fp = NULL;
1029 char *p; 1769 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1770 size_t len;
1031 int i = 0; 1771 int curr_fd = -1;
1032 1772
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1773 fp = fopenat_r(root_fd, root_rel_path(fname));
1774 if (fp == NULL)
1034 return; 1775 return -1;
1035 1776
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1777 path = NULL;
1037 if (*path != '/') 1778 len = 0;
1038 continue; 1779 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1780 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1781 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1782 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1783 *p = 0;
1044 1784
1045 ldpaths[i++] = xstrdup(path); 1785 /* recursive includes of the same file will make this segfault. */
1786 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1787 glob_t gl;
1788 size_t x;
1789 const char *gpath;
1046 1790
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1791 /* re-use existing path buffer ... need to be creative */
1048 break; 1792 if (path[8] != '/')
1793 gpath = memcpy(path + 3, "/etc/", 5);
1794 else
1795 gpath = path + 8;
1796 if (root_fd != AT_FDCWD) {
1797 if (curr_fd == -1) {
1798 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1799 if (fchdir(root_fd))
1800 errp("unable to change to root dir");
1801 }
1802 gpath = root_rel_path(gpath);
1803 }
1804
1805 if (glob(gpath, 0, NULL, &gl) == 0) {
1806 for (x = 0; x < gl.gl_pathc; ++x) {
1807 /* try to avoid direct loops */
1808 if (strcmp(gl.gl_pathv[x], fname) == 0)
1809 continue;
1810 _load_ld_cache_config(gl.gl_pathv[x]);
1811 }
1812 globfree(&gl);
1813 }
1814
1815 /* failed globs are ignored by glibc */
1816 continue;
1049 } 1817 }
1050 ldpaths[i] = NULL; 1818
1819 if (*path != '/')
1820 continue;
1821
1822 xarraypush_str(ldpaths, path);
1823 }
1824 free(path);
1051 1825
1052 fclose(fp); 1826 fclose(fp);
1827
1828 if (curr_fd != -1) {
1829 if (fchdir(curr_fd))
1830 {/* don't care */}
1831 close(curr_fd);
1832 }
1833
1834 return 0;
1835}
1836
1837#elif defined(__FreeBSD__) || defined(__DragonFly__)
1838
1839static int _load_ld_cache_config(const char *fname)
1840{
1841 FILE *fp = NULL;
1842 char *b = NULL, *p;
1843 struct elfhints_hdr hdr;
1844
1845 fp = fopenat_r(root_fd, root_rel_path(fname));
1846 if (fp == NULL)
1847 return -1;
1848
1849 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1850 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1851 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1852 {
1853 fclose(fp);
1854 return -1;
1855 }
1856
1857 b = xmalloc(hdr.dirlistlen + 1);
1858 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1859 fclose(fp);
1860 free(b);
1861 return -1;
1862 }
1863
1864 while ((p = strsep(&b, ":"))) {
1865 if (*p == '\0')
1866 continue;
1867 xarraypush_str(ldpaths, p);
1868 }
1869
1870 free(b);
1871 fclose(fp);
1872 return 0;
1873}
1874
1875#else
1876#ifdef __ELF__
1877#warning Cache config support not implemented for your target
1878#endif
1879static int _load_ld_cache_config(const char *fname)
1880{
1881 return 0;
1882}
1883#endif
1884
1885static void load_ld_cache_config(const char *fname)
1886{
1887 bool scan_l, scan_ul, scan_ull;
1888 size_t n;
1889 const char *ldpath;
1890
1891 _load_ld_cache_config(fname);
1892
1893 scan_l = scan_ul = scan_ull = false;
1894 array_for_each(ldpaths, n, ldpath) {
1895 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1896 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1897 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1898 }
1899
1900 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1901 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1902 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1053} 1903}
1054 1904
1055/* scan /etc/ld.so.conf for paths */ 1905/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1906static void scanelf_ldpath(void)
1057{ 1907{
1058 char scan_l, scan_ul, scan_ull; 1908 size_t n;
1059 int i = 0; 1909 const char *ldpath;
1060 1910
1061 if (!ldpaths[0]) 1911 array_for_each(ldpaths, n, ldpath)
1062 err("Unable to load any paths from ld.so.conf");
1063
1064 scan_l = scan_ul = scan_ull = 0;
1065
1066 while (ldpaths[i]) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1912 scanelf_dir(ldpath);
1071 ++i;
1072 }
1073
1074 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1913}
1078 1914
1079/* scan env PATH for paths */ 1915/* scan env PATH for paths */
1080static void scanelf_envpath() 1916static void scanelf_envpath(void)
1081{ 1917{
1082 char *path, *p; 1918 char *path, *p;
1083 1919
1084 path = getenv("PATH"); 1920 path = getenv("PATH");
1085 if (!path) 1921 if (!path)
1092 } 1928 }
1093 1929
1094 free(path); 1930 free(path);
1095} 1931}
1096 1932
1097 1933/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1934#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1935#define a_argument required_argument
1101static struct option const long_opts[] = { 1936static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1937 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1938 {"ldpath", no_argument, NULL, 'l'},
1939 {"use-ldpath",no_argument, NULL, 129},
1940 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1941 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1942 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1943 {"symlink", no_argument, NULL, 'y'},
1944 {"archives", no_argument, NULL, 'A'},
1945 {"ldcache", no_argument, NULL, 'L'},
1946 {"fix", no_argument, NULL, 'X'},
1947 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1948 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1949 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1950 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1951 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1952 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1953 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1954 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1955 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 1956 {"symbol", a_argument, NULL, 's'},
1957 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 1958 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 1959 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 1960 {"textrels", no_argument, NULL, 'T'},
1961 {"etype", a_argument, NULL, 'E'},
1962 {"bits", a_argument, NULL, 'M'},
1963 {"endian", no_argument, NULL, 'D'},
1964 {"osabi", no_argument, NULL, 'I'},
1965 {"eabi", no_argument, NULL, 'Y'},
1966 {"perms", a_argument, NULL, 'O'},
1967 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 1968 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 1969 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 1970 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 1971 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 1972 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 1973 {"file", a_argument, NULL, 'o'},
1974 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 1975 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 1976 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 1977 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 1978 {NULL, no_argument, NULL, 0x0}
1130}; 1979};
1131 1980
1132static const char *opts_help[] = { 1981static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 1982 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 1983 "Scan all directories in /etc/ld.so.conf",
1984 "Use ld.so.conf to show full path (use with -r/-n)",
1985 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 1986 "Scan directories recursively",
1136 "Don't recursively cross mount points", 1987 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 1988 "Don't scan symlinks",
1989 "Scan archives (.a files)",
1990 "Utilize ld.so.cache to show full path (use with -r/-n)",
1991 "Try and 'fix' bad things (use with -r/-e)",
1992 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 1993 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 1994 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 1995 "Print TEXTREL information",
1141 "Print RPATH information", 1996 "Print RPATH information",
1142 "Print NEEDED information", 1997 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 1998 "Print INTERP information",
1145 "Print BIND information", 1999 "Print BIND information",
1146 "Print SONAME information", 2000 "Print SONAME information",
1147 "Find a specified symbol", 2001 "Find a specified symbol",
2002 "Find a specified section",
1148 "Find a specified library", 2003 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 2004 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1150 "Locate cause of TEXTREL", 2005 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 2006 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2007 "Print only ELF files matching numeric bits",
2008 "Print Endianness",
2009 "Print OSABI",
2010 "Print EABI (EM_ARM Only)",
2011 "Print only ELF files matching octal permissions",
2012 "Print ELF file size",
2013 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 2014 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 2015 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 2016 "Use specified format for output",
1155 "Read input stream from a filename", 2017 "Read input stream from a filename",
1156 "Write output stream to a filename", 2018 "Write output stream to a filename",
2019 "Don't emit color in output",
1157 "Don't display the header", 2020 "Don't display the header",
1158 "Print this help and exit", 2021 "Print this help and exit",
1159 "Print version and exit", 2022 "Print version and exit",
1160 NULL 2023 NULL
1161}; 2024};
1162 2025
1163/* display usage and exit */ 2026/* display usage and exit */
1164static void usage(int status) 2027static void usage(int status)
1165{ 2028{
1166 unsigned long i; 2029 const char a_arg[] = "<arg>";
2030 size_t a_arg_len = strlen(a_arg) + 2;
2031 size_t i;
2032 int optlen;
1167 printf("* Scan ELF binaries for stuff\n\n" 2033 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2034 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2035 printf("Options: -[%s]\n", PARSE_FLAGS);
2036
2037 /* prescan the --long opt length to auto-align */
2038 optlen = 0;
1170 for (i = 0; long_opts[i].name; ++i) 2039 for (i = 0; long_opts[i].name; ++i) {
2040 int l = strlen(long_opts[i].name);
2041 if (long_opts[i].has_arg == a_argument)
2042 l += a_arg_len;
2043 optlen = max(l, optlen);
2044 }
2045
2046 for (i = 0; long_opts[i].name; ++i) {
2047 /* first output the short flag if it has one */
2048 if (long_opts[i].val > '~')
2049 printf(" ");
2050 else
2051 printf(" -%c, ", long_opts[i].val);
2052
2053 /* then the long flag */
1171 if (long_opts[i].has_arg == no_argument) 2054 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2055 printf("--%-*s", optlen, long_opts[i].name);
1173 long_opts[i].name, opts_help[i]);
1174 else 2056 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2057 printf("--%s %s %*s", long_opts[i].name, a_arg,
1176 long_opts[i].name, opts_help[i]); 2058 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1177 2059
1178 if (status != EXIT_SUCCESS) 2060 /* finally the help text */
1179 exit(status); 2061 printf("* %s\n", opts_help[i]);
2062 }
1180 2063
1181 puts("\nThe format modifiers for the -F option are:"); 2064 puts("\nFor more information, see the scanelf(1) manpage");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2065 exit(status);
1192} 2066}
1193 2067
1194/* parse command line arguments and preform needed actions */ 2068/* parse command line arguments and preform needed actions */
2069#define do_pax_state(option, flag) \
2070 if (islower(option)) { \
2071 flags &= ~PF_##flag; \
2072 flags |= PF_NO##flag; \
2073 } else { \
2074 flags &= ~PF_NO##flag; \
2075 flags |= PF_##flag; \
2076 }
2077static void parse_delimited(array_t *arr, char *arg, const char *delim)
2078{
2079 char *ele = strtok(arg, delim);
2080 if (!ele) /* edge case: -s '' */
2081 xarraypush_str(arr, "");
2082 while (ele) {
2083 xarraypush_str(arr, ele);
2084 ele = strtok(NULL, delim);
2085 }
2086}
1195static void parseargs(int argc, char *argv[]) 2087static int parseargs(int argc, char *argv[])
1196{ 2088{
1197 int i; 2089 int i;
1198 char *from_file = NULL; 2090 const char *from_file = NULL;
2091 int ret = 0;
2092 char load_cache_config = 0;
1199 2093
1200 opterr = 0; 2094 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2095 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2096 switch (i) {
1203 2097
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2101 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2102 exit(EXIT_SUCCESS);
1209 break; 2103 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2104 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2105 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2106 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2107 from_file = optarg;
2108 break;
2109 case 'E':
2110 /* historically, this was comma delimited */
2111 parse_delimited(match_etypes, optarg, ",");
2112 break;
2113 case 'M':
2114 match_bits = atoi(optarg);
2115 if (match_bits == 0) {
2116 if (strcmp(optarg, "ELFCLASS32") == 0)
2117 match_bits = 32;
2118 if (strcmp(optarg, "ELFCLASS64") == 0)
2119 match_bits = 64;
2120 }
2121 break;
2122 case 'O':
2123 if (sscanf(optarg, "%o", &match_perms) == -1)
2124 match_bits = 0;
1214 break; 2125 break;
1215 case 'o': { 2126 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2127 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2128 errp("Could not freopen(%s)", optarg);
1219 SET_STDOUT(fp);
1220 break; 2129 break;
1221 } 2130 }
1222
1223 case 's': { 2131 case 'k':
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2132 xarraypush_str(find_section_arr, optarg);
1225 find_sym = optarg;
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1227 sprintf(versioned_symname, "%s@", find_sym);
1228 break; 2133 break;
1229 }
1230 case 'N': { 2134 case 's':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2135 /* historically, this was comma delimited */
1232 find_lib = optarg; 2136 parse_delimited(find_sym_arr, optarg, ",");
1233 break; 2137 break;
1234 } 2138 case 'N':
1235 2139 xarraypush_str(find_lib_arr, optarg);
2140 break;
1236 case 'F': { 2141 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2142 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2143 out_format = optarg;
1239 break; 2144 break;
1240 } 2145 }
2146 case 'z': {
2147 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2148 size_t x;
1241 2149
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2150 for (x = 0; x < strlen(optarg); x++) {
1243 case 'L': printcache = 1; break; 2151 switch (optarg[x]) {
2152 case 'p':
2153 case 'P':
2154 do_pax_state(optarg[x], PAGEEXEC);
2155 break;
2156 case 's':
2157 case 'S':
2158 do_pax_state(optarg[x], SEGMEXEC);
2159 break;
2160 case 'm':
2161 case 'M':
2162 do_pax_state(optarg[x], MPROTECT);
2163 break;
2164 case 'e':
2165 case 'E':
2166 do_pax_state(optarg[x], EMUTRAMP);
2167 break;
2168 case 'r':
2169 case 'R':
2170 do_pax_state(optarg[x], RANDMMAP);
2171 break;
2172 case 'x':
2173 case 'X':
2174 do_pax_state(optarg[x], RANDEXEC);
2175 break;
2176 default:
2177 break;
2178 }
2179 }
2180 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2181 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2182 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2183 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2184 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2185 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2186 setpax = flags;
2187 break;
2188 }
2189 case 'Z': show_size = 1; break;
2190 case 'g': ++g_match; break;
2191 case 'L': load_cache_config = use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2192 case 'y': scan_symlink = 0; break;
2193 case 'A': scan_archives = 1; break;
2194 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2195 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2196 case 'l': load_cache_config = scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2197 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2198 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2199 case 'm': dir_crossmount = 0; break;
2200 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2201 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2202 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2203 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2204 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2205 case 'n': show_needed = 1; break;
1255 case 'i': show_interp = 1; break; 2206 case 'i': show_interp = 1; break;
1256 case 'b': show_bind = 1; break; 2207 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2208 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2209 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2210 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2211 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2212 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2213 case 'D': show_endian = 1; break;
2214 case 'I': show_osabi = 1; break;
2215 case 'Y': show_eabi = 1; break;
2216 case 128:
2217 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2218 if (root_fd == -1)
2219 err("Could not open root: %s", optarg);
2220 break;
2221 case 129: load_cache_config = use_ldpath = 1; break;
1263 case ':': 2222 case ':':
1264 err("Option missing parameter\n"); 2223 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2224 case '?':
1266 err("Unknown option\n"); 2225 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2226 default:
1268 err("Unhandled option '%c'", i); 2227 err("Unhandled option '%c'; please report this", i);
1269 } 2228 }
1270 } 2229 }
2230 if (show_textrels && be_verbose)
2231 has_objdump = bin_in_path("objdump");
2232 /* precompile all the regexes */
2233 if (g_match) {
2234 regex_t preg;
2235 const char *this_sym;
2236 size_t n;
2237 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1271 2238
2239 array_for_each(find_sym_arr, n, this_sym) {
2240 /* see scanelf_match_symname for logic info */
2241 switch (this_sym[0]) {
2242 case '%':
2243 while (*(this_sym++))
2244 if (*this_sym == '%') {
2245 ++this_sym;
2246 break;
2247 }
2248 break;
2249 case '+':
2250 case '-':
2251 ++this_sym;
2252 break;
2253 }
2254 if (*this_sym == '*')
2255 ++this_sym;
2256
2257 ret = regcomp(&preg, this_sym, flags);
2258 if (ret) {
2259 char err[256];
2260 regerror(ret, &preg, err, sizeof(err));
2261 err("regcomp of %s failed: %s", this_sym, err);
2262 }
2263 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2264 }
2265 }
2266 /* flatten arrays for display */
2267 find_sym = array_flatten_str(find_sym_arr);
2268 find_lib = array_flatten_str(find_lib_arr);
2269 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2270 /* let the format option override all other options */
1273 if (out_format) { 2271 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2272 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2273 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2274 show_textrels = show_perms = show_endian = show_size = \
2275 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2276 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2277 if (!IS_MODIFIER(out_format[i])) continue;
1279 2278
1280 switch (out_format[++i]) { 2279 switch (out_format[++i]) {
2280 case '+': break;
1281 case '%': break; 2281 case '%': break;
1282 case '#': break; 2282 case '#': break;
1283 case 'F': break; 2283 case 'F': break;
1284 case 'p': break; 2284 case 'p': break;
1285 case 'f': break; 2285 case 'f': break;
2286 case 'k': break;
1286 case 's': break; 2287 case 's': break;
1287 case 'N': break; 2288 case 'N': break;
1288 case 'o': break; 2289 case 'o': break;
2290 case 'a': break;
2291 case 'M': break;
2292 case 'Z': show_size = 1; break;
2293 case 'D': show_endian = 1; break;
2294 case 'I': show_osabi = 1; break;
2295 case 'Y': show_eabi = 1; break;
2296 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2297 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2298 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2299 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2300 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2301 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2302 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2303 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2304 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2305 case 'T': show_textrels = 1; break;
1298 default: 2306 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2307 err("invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2308 out_format[i], i+1);
1301 } 2309 }
1302 } 2310 }
1303 2311
1304 /* construct our default format */ 2312 /* construct our default format */
1305 } else { 2313 } else {
1306 size_t fmt_len = 30; 2314 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2315 out_format = xmalloc(sizeof(char) * fmt_len);
2316 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2317 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2318 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2319 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2320 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2321 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2322 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2323 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2324 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2325 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2326 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2327 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2328 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2329 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2330 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2331 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2332 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2333 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2334 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2335 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2336 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2337 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2338
1324 /* now lets actually do the scanning */ 2339 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2340 if (load_cache_config)
1326 load_ld_so_conf(); 2341 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2342 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2343 if (scan_envpath) scanelf_envpath();
2344 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2345 from_file = "-";
1329 if (from_file) { 2346 if (from_file) {
1330 scanelf_from_file(from_file); 2347 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2348 from_file = *argv;
1333 } 2349 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2350 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2351 err("Nothing to scan !?");
1336 while (optind < argc) { 2352 while (optind < argc) {
1337 search_path = argv[optind++]; 2353 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2354 ret = scanelf_dir(search_path);
1339 } 2355 }
1340 2356
2357#ifdef __PAX_UTILS_CLEANUP
1341 /* clean up */ 2358 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2359 xarrayfree(ldpaths);
2360 xarrayfree(find_sym_arr);
2361 xarrayfree(find_lib_arr);
2362 xarrayfree(find_section_arr);
2363 free(find_sym);
2364 free(find_lib);
2365 free(find_section);
2366 {
2367 size_t n;
2368 regex_t *preg;
2369 array_for_each(find_sym_regex_arr, n, preg)
2370 regfree(preg);
2371 xarrayfree(find_sym_regex_arr);
2372 }
1345 2373
1346 if (ldcache != 0) 2374 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2375 munmap(ldcache, ldcache_size);
1348} 2376#endif
1349 2377
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2378 return ret;
1358} 2379}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2380
1369 new_len = strlen(*dst) + strlen(src); 2381static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2382{
1384 static char my_app[2]; 2383 const char *delims = " \t\n";
1385 my_app[0] = append; 2384 char **envvals = NULL;
1386 my_app[1] = '\0'; 2385 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2386 int nentry;
1388}
1389 2387
2388 if ((env = getenv(envvar)) == NULL)
2389 return NULL;
1390 2390
2391 env = xstrdup(env);
2392 if (env == NULL)
2393 return NULL;
2394
2395 s = strtok(env, delims);
2396 if (s == NULL) {
2397 free(env);
2398 return NULL;
2399 }
2400
2401 nentry = 0;
2402 while (s != NULL) {
2403 ++nentry;
2404 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2405 envvals[nentry-1] = s;
2406 s = strtok(NULL, delims);
2407 }
2408 envvals[nentry] = NULL;
2409
2410 /* don't want to free(env) as it contains the memory that backs
2411 * the envvals array of strings */
2412 return envvals;
2413}
2414
2415static void parseenv(void)
2416{
2417 color_init(false);
2418 qa_textrels = get_split_env("QA_TEXTRELS");
2419 qa_execstack = get_split_env("QA_EXECSTACK");
2420 qa_wx_load = get_split_env("QA_WX_LOAD");
2421}
2422
2423#ifdef __PAX_UTILS_CLEANUP
2424static void cleanup(void)
2425{
2426 free(out_format);
2427 free(qa_textrels);
2428 free(qa_execstack);
2429 free(qa_wx_load);
2430}
2431#endif
1391 2432
1392int main(int argc, char *argv[]) 2433int main(int argc, char *argv[])
1393{ 2434{
2435 int ret;
1394 if (argc < 2) 2436 if (argc < 2)
1395 usage(EXIT_FAILURE); 2437 usage(EXIT_FAILURE);
2438 parseenv();
1396 parseargs(argc, argv); 2439 ret = parseargs(argc, argv);
1397 fclose(stdout); 2440 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2441#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2442 cleanup();
2443 warn("The calls to add/delete heap should be off:\n"
2444 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2445 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2446#endif
1401 return EXIT_SUCCESS; 2447 return ret;
1402} 2448}
2449
2450/* Match filename against entries in matchlist, return TRUE
2451 * if the file is listed */
2452static int file_matches_list(const char *filename, char **matchlist)
2453{
2454 char **file;
2455 char *match;
2456 char buf[__PAX_UTILS_PATH_MAX];
2457
2458 if (matchlist == NULL)
2459 return 0;
2460
2461 for (file = matchlist; *file != NULL; file++) {
2462 if (search_path) {
2463 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2464 match = buf;
2465 } else {
2466 match = *file;
2467 }
2468 if (fnmatch(match, filename, 0) == 0)
2469 return 1;
2470 }
2471 return 0;
2472}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.262

  ViewVC Help
Powered by ViewVC 1.1.20