/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.96 Revision 1.265
1/* 1/*
2 * Copyright 2003-2005 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.265 2014/03/21 05:33:33 vapier Exp $
5 * 5 *
6 * Copyright 2003-2005 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2005 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10#include <stdio.h> 10static const char rcsid[] = "$Id: scanelf.c,v 1.265 2014/03/21 05:33:33 vapier Exp $";
11#include <stdlib.h> 11const char argv0[] = "scanelf";
12#include <sys/types.h> 12
13#include <libgen.h>
14#include <limits.h>
15#include <string.h>
16#include <errno.h>
17#include <unistd.h>
18#include <sys/stat.h>
19#include <sys/mman.h>
20#include <fcntl.h>
21#include <dirent.h>
22#include <getopt.h>
23#include <assert.h>
24#include "paxinc.h" 13#include "paxinc.h"
25 14
26static const char *rcsid = "$Id: scanelf.c,v 1.96 2005/12/28 22:26:47 solar Exp $";
27#define argv0 "scanelf"
28
29#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
30
31
32 16
33/* prototypes */ 17/* prototypes */
34static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
35static void scanelf_dir(const char *path);
36static void scanelf_ldpath();
37static void scanelf_envpath();
38static void usage(int status);
39static void parseargs(int argc, char *argv[]);
40static char *xstrdup(const char *s);
41static void *xmalloc(size_t size);
42static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
43#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
44static inline void xchrcat(char **dst, const char append, size_t *curr_len);
45 19
46/* variables to control behavior */ 20/* variables to control behavior */
47static char *ldpaths[256]; 21static array_t _match_etypes = array_init_decl, *match_etypes = &_match_etypes;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
48static char scan_ldpath = 0; 23static char scan_ldpath = 0;
49static char scan_envpath = 0; 24static char scan_envpath = 0;
50static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
51static char dir_recurse = 0; 27static char dir_recurse = 0;
52static char dir_crossmount = 1; 28static char dir_crossmount = 1;
53static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
54static char show_phdr = 0; 32static char show_phdr = 0;
55static char show_textrel = 0; 33static char show_textrel = 0;
56static char show_rpath = 0; 34static char show_rpath = 0;
57static char show_needed = 0; 35static char show_needed = 0;
58static char show_interp = 0; 36static char show_interp = 0;
59static char show_bind = 0; 37static char show_bind = 0;
60static char show_soname = 0; 38static char show_soname = 0;
61static char show_textrels = 0; 39static char show_textrels = 0;
62static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
63static char be_quiet = 0; 44static char be_quiet = 0;
64static char be_verbose = 0; 45static char be_verbose = 0;
65static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
66static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
67static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
68static char *out_format = NULL; 55static char *out_format = NULL;
69static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
70static char gmatch = 0; 58static char g_match = 0;
71static char printcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
72 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
73 66
74caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
75size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
76 72
73static const char *objdump;
74
75/* Find the path to a file by name. Note: we do not currently handle the
76 * empty path element correctly (should behave by searching $PWD). */
77static const char *which(const char *fname, const char *envvar)
78{
79 size_t path_len, fname_len;
80 const char *env_path;
81 char *path, *p, *ep;
82
83 p = getenv(envvar);
84 if (p)
85 return p;
86
87 env_path = getenv("PATH");
88 if (!env_path)
89 return NULL;
90
91 /* Create a copy of the $PATH that we can safely modify.
92 * Make it a little bigger so we can append "/fname".
93 * We do this twice -- once for a perm copy, and once for
94 * room at the end of the last element. */
95 path_len = strlen(env_path);
96 fname_len = strlen(fname);
97 path = xmalloc(path_len + (fname_len * 2) + 2 + 2);
98 memcpy(path, env_path, path_len + 1);
99
100 p = path + path_len + 1 + fname_len + 1;
101 *p = '/';
102 memcpy(p + 1, fname, fname_len + 1);
103
104 /* Repoint fname to the copy in the env string as it has
105 * the leading slash which we can include in a single memcpy.
106 * Increase the fname len to include the '/' and '\0'. */
107 fname = p;
108 fname_len += 2;
109
110 p = path;
111 while (p) {
112 ep = strchr(p, ':');
113 /* Append the /foo path to the current element. */
114 if (ep)
115 memcpy(ep, fname, fname_len);
116 else
117 memcpy(path + path_len, fname, fname_len);
118
119 if (access(p, R_OK) != -1)
120 return p;
121
122 p = ep;
123 if (ep) {
124 /* If not the last element, restore the chunk we clobbered. */
125 size_t offset = ep - path;
126 size_t restore = min(path_len - offset, fname_len);
127 memcpy(ep, env_path + offset, restore);
128 ++p;
129 }
130 }
131
132 free(path);
133 return NULL;
134}
135
136static FILE *fopenat_r(int dir_fd, const char *path)
137{
138 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
139 if (fd == -1)
140 return NULL;
141 return fdopen(fd, "re");
142}
143
144static const char *root_rel_path(const char *path)
145{
146 /*
147 * openat() will ignore the dirfd if path starts with
148 * a /, so consume all of that noise
149 *
150 * XXX: we don't handle relative paths like ../ that
151 * break out of the --root option, but for now, just
152 * don't do that :P.
153 */
154 if (root_fd != AT_FDCWD) {
155 while (*path == '/')
156 ++path;
157 if (*path == '\0')
158 path = ".";
159 }
160
161 return path;
162}
163
77/* sub-funcs for scanelf_file() */ 164/* sub-funcs for scanelf_fileat() */
78static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 165static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
79{ 166{
80 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 167 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
168
169 /* debug sections */
170 void *symtab = elf_findsecbyname(elf, ".symtab");
171 void *strtab = elf_findsecbyname(elf, ".strtab");
172 /* runtime sections */
173 void *dynsym = elf_findsecbyname(elf, ".dynsym");
174 void *dynstr = elf_findsecbyname(elf, ".dynstr");
175
176 /*
177 * If the sections are marked NOBITS, then they don't exist, so we just
178 * skip them. This let's us work sanely with splitdebug ELFs (rather
179 * than spewing a lot of "corrupt ELF" messages later on). In malformed
180 * ELFs, the section might be wrongly set to NOBITS, but screw em.
181 */
81#define GET_SYMTABS(B) \ 182#define GET_SYMTABS(B) \
82 if (elf->elf_class == ELFCLASS ## B) { \ 183 if (elf->elf_class == ELFCLASS ## B) { \
83 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 184 Elf ## B ## _Shdr *esymtab = symtab; \
84 /* debug sections */ \ 185 Elf ## B ## _Shdr *estrtab = strtab; \
85 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 186 Elf ## B ## _Shdr *edynsym = dynsym; \
86 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 187 Elf ## B ## _Shdr *edynstr = dynstr; \
87 /* runtime sections */ \ 188 \
88 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 189 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
89 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 190 symtab = NULL; \
191 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
192 dynsym = NULL; \
90 if (symtab && dynsym) { \ 193 if (symtab && dynsym) \
91 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 194 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
92 } else { \ 195 else \
93 *sym = (void*)(symtab ? symtab : dynsym); \ 196 *sym = symtab ? symtab : dynsym; \
94 } \ 197 \
198 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
199 strtab = NULL; \
200 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
201 dynstr = NULL; \
95 if (strtab && dynstr) { \ 202 if (strtab && dynstr) \
96 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 203 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
97 } else { \ 204 else \
98 *tab = (void*)(strtab ? strtab : dynstr); \ 205 *str = strtab ? strtab : dynstr; \
99 } \
100 } 206 }
101 GET_SYMTABS(32) 207 GET_SYMTABS(32)
102 GET_SYMTABS(64) 208 GET_SYMTABS(64)
209
210 if (*sym && *str)
211 return;
212
213 /*
214 * damn, they're really going to make us work for it huh?
215 * reconstruct the section header info out of the dynamic
216 * tags so we can see what symbols this guy uses at runtime.
217 */
218#define GET_SYMTABS_DT(B) \
219 if (elf->elf_class == ELFCLASS ## B) { \
220 size_t i; \
221 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
222 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
223 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
224 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
225 Elf ## B ## _Dyn *dyn; \
226 Elf ## B ## _Off offset; \
227 \
228 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
229 vsym = vstr = vhash = vgnu_hash = 0; \
230 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
231 memset(&str_shdr, 0, sizeof(str_shdr)); \
232 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
233 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
234 continue; \
235 \
236 offset = EGET(phdr[i].p_offset); \
237 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
238 continue; \
239 \
240 dyn = DYN ## B (elf->vdata + offset); \
241 while (EGET(dyn->d_tag) != DT_NULL) { \
242 switch (EGET(dyn->d_tag)) { \
243 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
244 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
245 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
246 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
247 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
248 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
249 } \
250 ++dyn; \
251 } \
252 if (vsym && vstr) \
253 break; \
254 } \
255 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
256 return; \
257 \
258 /* calc offset into the ELF by finding the load addr of the syms */ \
259 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
260 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
261 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
262 offset = EGET(phdr[i].p_offset); \
263 \
264 if (EGET(phdr[i].p_type) != PT_LOAD) \
265 continue; \
266 \
267 if (vhash >= vaddr && vhash < vaddr + filesz) { \
268 /* Scan the hash table to see how many entries we have */ \
269 Elf32_Word max_sym_idx = 0; \
270 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
271 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
272 Elf32_Word nchains = EGET(hashtbl[1]); \
273 Elf32_Word *buckets = &hashtbl[2]; \
274 Elf32_Word *chains = &buckets[nbuckets]; \
275 Elf32_Word sym_idx; \
276 \
277 for (b = 0; b < nbuckets; ++b) { \
278 if (!buckets[b]) \
279 continue; \
280 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
281 if (max_sym_idx < sym_idx) \
282 max_sym_idx = sym_idx; \
283 } \
284 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
285 } \
286 \
287 if (vsym >= vaddr && vsym < vaddr + filesz) { \
288 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
289 *sym = &sym_shdr; \
290 } \
291 \
292 if (vstr >= vaddr && vstr < vaddr + filesz) { \
293 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
294 *str = &str_shdr; \
295 } \
296 } \
297 }
298 GET_SYMTABS_DT(32)
299 GET_SYMTABS_DT(64)
103} 300}
301
104static char *scanelf_file_pax(elfobj *elf, char *found_pax) 302static char *scanelf_file_pax(elfobj *elf, char *found_pax)
105{ 303{
106 static char ret[7]; 304 static char ret[7];
107 unsigned long i, shown; 305 unsigned long i, shown;
108 306
117 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 315 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
118 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 316 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
119 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 317 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
120 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 318 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
121 continue; \ 319 continue; \
122 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 320 if (fix_elf && setpax) { \
321 /* set the paxctl flags */ \
322 ESET(phdr[i].p_flags, setpax); \
323 } \
324 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
123 continue; \ 325 continue; \
124 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 326 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
125 *found_pax = 1; \ 327 *found_pax = 1; \
126 ++shown; \ 328 ++shown; \
127 break; \ 329 break; \
128 } \ 330 } \
129 } 331 }
130 SHOW_PAX(32) 332 SHOW_PAX(32)
131 SHOW_PAX(64) 333 SHOW_PAX(64)
132 } 334 }
335
336 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
337 * was found. This is known to break ELFs on glibc systems,
338 * and mainline PaX has deprecated use of this for a long time.
339 * We could support changing PT_GNU_STACK, but that doesn't
340 * seem like it's worth the effort. #411919
341 */
133 342
134 /* fall back to EI_PAX if no PT_PAX was found */ 343 /* fall back to EI_PAX if no PT_PAX was found */
135 if (!*ret) { 344 if (!*ret) {
136 static char *paxflags; 345 static char *paxflags;
137 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 346 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
150 359
151static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 360static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
152{ 361{
153 static char ret[12]; 362 static char ret[12];
154 char *found; 363 char *found;
155 unsigned long i, shown;
156 unsigned char multi_stack, multi_relro, multi_load; 364 unsigned long i, shown, multi_stack, multi_relro, multi_load;
157 365
158 if (!show_phdr) return NULL; 366 if (!show_phdr) return NULL;
159 367
160 memcpy(ret, "--- --- ---\0", 12); 368 memcpy(ret, "--- --- ---\0", 12);
161 369
162 shown = 0; 370 shown = 0;
163 multi_stack = multi_relro = multi_load = 0; 371 multi_stack = multi_relro = multi_load = 0;
164 372
373#define NOTE_GNU_STACK ".note.GNU-stack"
165#define SHOW_PHDR(B) \ 374#define SHOW_PHDR(B) \
166 if (elf->elf_class == ELFCLASS ## B) { \ 375 if (elf->elf_class == ELFCLASS ## B) { \
167 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 376 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
168 Elf ## B ## _Off offset; \ 377 Elf ## B ## _Off offset; \
169 uint32_t flags, check_flags; \ 378 uint32_t flags, check_flags; \
170 if (elf->phdr != NULL) { \ 379 if (elf->phdr != NULL) { \
171 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 380 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
172 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 381 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
173 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 382 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
383 if (multi_stack++) \
174 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 384 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
385 if (file_matches_list(elf->filename, qa_execstack)) \
386 continue; \
175 found = found_phdr; \ 387 found = found_phdr; \
176 offset = 0; \ 388 offset = 0; \
177 check_flags = PF_X; \ 389 check_flags = PF_X; \
178 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 390 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
391 if (multi_relro++) \
179 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 392 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
180 found = found_relro; \ 393 found = found_relro; \
181 offset = 4; \ 394 offset = 4; \
182 check_flags = PF_X; \ 395 check_flags = PF_X; \
183 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 396 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
184 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 397 if (file_matches_list(elf->filename, qa_wx_load)) \
398 continue; \
185 found = found_load; \ 399 found = found_load; \
186 offset = 8; \ 400 offset = 8; \
187 check_flags = PF_W|PF_X; \ 401 check_flags = PF_W|PF_X; \
188 } else \ 402 } else \
189 continue; \ 403 continue; \
190 flags = EGET(phdr[i].p_flags); \ 404 flags = EGET(phdr[i].p_flags); \
191 if (be_quiet && ((flags & check_flags) != check_flags)) \ 405 if (be_quiet && ((flags & check_flags) != check_flags)) \
192 continue; \ 406 continue; \
407 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
408 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
409 ret[3] = ret[7] = '!'; \
410 flags = EGET(phdr[i].p_flags); \
411 } \
193 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 412 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
194 *found = 1; \ 413 *found = 1; \
195 ++shown; \ 414 ++shown; \
196 } \ 415 } \
197 } else if (elf->shdr != NULL) { \ 416 } else if (elf->shdr != NULL) { \
198 /* no program headers which means this is prob an object file */ \ 417 /* no program headers which means this is prob an object file */ \
199 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 418 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
200 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 419 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
420 char *str; \
421 if ((void*)strtbl > elf->data_end) \
422 goto skip_this_shdr##B; \
423 /* let's flag -w/+x object files since the final ELF will most likely \
424 * need write access to the stack (who doesn't !?). so the combined \
425 * output will bring in +w automatically and that's bad. \
426 */ \
201 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 427 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
202 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 428 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
203 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 429 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
204 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 430 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
205 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 431 str = elf->data + offset; \
432 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
433 if (!strcmp(str, NOTE_GNU_STACK)) { \
206 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 434 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
207 flags = EGET(shdr[i].sh_flags); \ 435 flags = EGET(shdr[i].sh_flags); \
208 if (be_quiet && ((flags & check_flags) != check_flags)) \ 436 if (be_quiet && ((flags & check_flags) != check_flags)) \
209 continue; \ 437 continue; \
210 ++*found_phdr; \ 438 ++*found_phdr; \
214 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 442 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
215 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 443 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
216 break; \ 444 break; \
217 } \ 445 } \
218 } \ 446 } \
447 skip_this_shdr##B: \
219 if (!multi_stack) { \ 448 if (!multi_stack) { \
449 if (file_matches_list(elf->filename, qa_execstack)) \
450 return NULL; \
220 *found_phdr = 1; \ 451 *found_phdr = 1; \
221 shown = 1; \ 452 shown = 1; \
222 memcpy(ret, "!WX", 3); \ 453 memcpy(ret, "!WX", 3); \
223 } \ 454 } \
224 } \ 455 } \
229 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 460 if (be_wewy_wewy_quiet || (be_quiet && !shown))
230 return NULL; 461 return NULL;
231 else 462 else
232 return ret; 463 return ret;
233} 464}
465
466/*
467 * See if this ELF contains a DT_TEXTREL tag in any of its
468 * PT_DYNAMIC sections.
469 */
234static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 470static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
235{ 471{
236 static const char *ret = "TEXTREL"; 472 static const char *ret = "TEXTREL";
237 unsigned long i; 473 unsigned long i;
238 474
239 if (!show_textrel && !show_textrels) return NULL; 475 if (!show_textrel && !show_textrels) return NULL;
476
477 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
240 478
241 if (elf->phdr) { 479 if (elf->phdr) {
242#define SHOW_TEXTREL(B) \ 480#define SHOW_TEXTREL(B) \
243 if (elf->elf_class == ELFCLASS ## B) { \ 481 if (elf->elf_class == ELFCLASS ## B) { \
244 Elf ## B ## _Dyn *dyn; \ 482 Elf ## B ## _Dyn *dyn; \
245 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 483 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
246 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 484 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
247 Elf ## B ## _Off offset; \ 485 Elf ## B ## _Off offset; \
248 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 486 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
249 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 487 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
250 offset = EGET(phdr[i].p_offset); \ 488 offset = EGET(phdr[i].p_offset); \
251 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 489 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
252 dyn = DYN ## B (elf->data + offset); \ 490 dyn = DYN ## B (elf->vdata + offset); \
253 while (EGET(dyn->d_tag) != DT_NULL) { \ 491 while (EGET(dyn->d_tag) != DT_NULL) { \
254 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 492 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
255 *found_textrel = 1; \ 493 *found_textrel = 1; \
256 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 494 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
257 return (be_wewy_wewy_quiet ? NULL : ret); \ 495 return (be_wewy_wewy_quiet ? NULL : ret); \
266 if (be_quiet || be_wewy_wewy_quiet) 504 if (be_quiet || be_wewy_wewy_quiet)
267 return NULL; 505 return NULL;
268 else 506 else
269 return " - "; 507 return " - ";
270} 508}
509
510/*
511 * Scan the .text section to see if there are any relocations in it.
512 * Should rewrite this to check PT_LOAD sections that are marked
513 * Executable rather than the section named '.text'.
514 */
271static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 515static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
272{ 516{
273 unsigned long s, r, rmax; 517 unsigned long s, r, rmax;
274 void *symtab_void, *strtab_void, *text_void; 518 void *symtab_void, *strtab_void, *text_void;
275 519
296 Elf ## B ## _Rela *rela; \ 540 Elf ## B ## _Rela *rela; \
297 /* search the section headers for relocations */ \ 541 /* search the section headers for relocations */ \
298 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 542 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
299 uint32_t sh_type = EGET(shdr[s].sh_type); \ 543 uint32_t sh_type = EGET(shdr[s].sh_type); \
300 if (sh_type == SHT_REL) { \ 544 if (sh_type == SHT_REL) { \
301 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 545 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
302 rela = NULL; \ 546 rela = NULL; \
303 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 547 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
304 } else if (sh_type == SHT_RELA) { \ 548 } else if (sh_type == SHT_RELA) { \
305 rel = NULL; \ 549 rel = NULL; \
306 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 550 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
307 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 551 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
308 } else \ 552 } else \
309 continue; \ 553 continue; \
310 /* now see if any of the relocs are in the .text */ \ 554 /* now see if any of the relocs are in the .text */ \
311 for (r = 0; r < rmax; ++r) { \ 555 for (r = 0; r < rmax; ++r) { \
326 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 570 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
327 if (be_verbose <= 2) continue; \ 571 if (be_verbose <= 2) continue; \
328 } else \ 572 } else \
329 *found_textrels = 1; \ 573 *found_textrels = 1; \
330 /* locate this relocation symbol name */ \ 574 /* locate this relocation symbol name */ \
331 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 575 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
576 if ((void*)sym > elf->data_end) { \
577 warn("%s: corrupt ELF symbol", elf->filename); \
578 continue; \
579 } \
332 sym_max = ELF ## B ## _R_SYM(r_info); \ 580 sym_max = ELF ## B ## _R_SYM(r_info); \
333 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 581 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
334 sym += sym_max; \ 582 sym += sym_max; \
335 else \ 583 else \
336 sym = NULL; \ 584 sym = NULL; \
337 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 585 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
338 /* show the raw details about this reloc */ \ 586 /* show the raw details about this reloc */ \
339 printf(" %s: ", elf->base_filename); \ 587 printf(" %s: ", elf->base_filename); \
340 if (sym && sym->st_name) \ 588 if (sym && sym->st_name) \
341 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 589 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
342 else \ 590 else \
343 printf("(memory/fake?)"); \ 591 printf("(memory/data?)"); \
344 printf(" [0x%lX]", (unsigned long)r_offset); \ 592 printf(" [0x%lX]", (unsigned long)r_offset); \
345 /* now try to find the closest symbol that this rel is probably in */ \ 593 /* now try to find the closest symbol that this rel is probably in */ \
346 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 594 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
347 func = NULL; \ 595 func = NULL; \
348 offset_tmp = 0; \ 596 offset_tmp = 0; \
349 while (sym_max--) { \ 597 while (sym_max--) { \
350 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 598 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
351 func = sym; \ 599 func = sym; \
352 offset_tmp = EGET(sym->st_value); \ 600 offset_tmp = EGET(sym->st_value); \
353 } \ 601 } \
354 ++sym; \ 602 ++sym; \
355 } \ 603 } \
356 printf(" in "); \ 604 printf(" in "); \
357 if (func && func->st_name) \ 605 if (func && func->st_name) { \
358 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 606 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
607 if (r_offset > EGET(func->st_size)) \
608 printf("(optimized out: previous %s)", func_name); \
359 else \ 609 else \
360 printf("(NULL: fake?)"); \ 610 printf("%s", func_name); \
611 } else \
612 printf("(optimized out)"); \
361 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 613 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
614 if (be_verbose && objdump) { \
615 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
616 char *sysbuf; \
617 size_t syslen; \
618 const char sysfmt[] = "%s -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
619 syslen = sizeof(sysfmt) + strlen(objdump) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
620 sysbuf = xmalloc(syslen); \
621 if (end_addr < r_offset) \
622 /* not uncommon when things are optimized out */ \
623 end_addr = r_offset + 0x100; \
624 snprintf(sysbuf, syslen, sysfmt, \
625 objdump, \
626 (unsigned long)offset_tmp, \
627 (unsigned long)end_addr, \
628 elf->filename, \
629 (unsigned long)r_offset); \
630 fflush(stdout); \
631 if (system(sysbuf)) {/* don't care */} \
632 fflush(stdout); \
633 free(sysbuf); \
634 } \
362 } \ 635 } \
363 } } 636 } }
364 SHOW_TEXTRELS(32) 637 SHOW_TEXTRELS(32)
365 SHOW_TEXTRELS(64) 638 SHOW_TEXTRELS(64)
366 } 639 }
368 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 641 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
369 642
370 return NULL; 643 return NULL;
371} 644}
372 645
373static void rpath_security_checks(elfobj *, char *);
374static void rpath_security_checks(elfobj *elf, char *item) { 646static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
647{
375 struct stat st; 648 struct stat st;
376 switch (*item) { 649 switch (*item) {
377 case '/': break; 650 case '/': break;
378 case '.': 651 case '.':
379 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 652 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
380 break; 653 break;
654 case ':':
381 case '\0': 655 case '\0':
382 warnf("Security problem NULL RPATH in %s", elf->filename); 656 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
383 break; 657 break;
384 case '$': 658 case '$':
385 if (fstat(elf->fd, &st) != -1) 659 if (fstat(elf->fd, &st) != -1)
386 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 660 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
387 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 661 warnf("Security problem with %s='%s' in %s with mode set of %o",
388 item, elf->filename, st.st_mode & 07777); 662 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
389 break; 663 break;
390 default: 664 default:
391 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 665 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
392 break; 666 break;
393 } 667 }
394} 668}
395static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 669static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
396{ 670{
397 unsigned long i, s; 671 unsigned long i;
398 char *rpath, *runpath, **r; 672 char *rpath, *runpath, **r;
399 void *strtbl_void; 673 void *strtbl_void;
400 674
401 if (!show_rpath) return; 675 if (!show_rpath) return;
402 676
413 Elf ## B ## _Off offset; \ 687 Elf ## B ## _Off offset; \
414 Elf ## B ## _Xword word; \ 688 Elf ## B ## _Xword word; \
415 /* Scan all the program headers */ \ 689 /* Scan all the program headers */ \
416 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 690 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
417 /* Just scan dynamic headers */ \ 691 /* Just scan dynamic headers */ \
418 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 692 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
419 offset = EGET(phdr[i].p_offset); \ 693 offset = EGET(phdr[i].p_offset); \
420 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 694 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
421 /* Just scan dynamic RPATH/RUNPATH headers */ \ 695 /* Just scan dynamic RPATH/RUNPATH headers */ \
422 dyn = DYN ## B (elf->data + offset); \ 696 dyn = DYN ## B (elf->vdata + offset); \
423 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 697 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
424 if (word == DT_RPATH) { \ 698 if (word == DT_RPATH) { \
425 r = &rpath; \ 699 r = &rpath; \
426 } else if (word == DT_RUNPATH) { \ 700 } else if (word == DT_RUNPATH) { \
427 r = &runpath; \ 701 r = &runpath; \
431 } \ 705 } \
432 /* Verify the memory is somewhat sane */ \ 706 /* Verify the memory is somewhat sane */ \
433 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 707 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
434 if (offset < (Elf ## B ## _Off)elf->len) { \ 708 if (offset < (Elf ## B ## _Off)elf->len) { \
435 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 709 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
436 *r = (char*)(elf->data + offset); \ 710 *r = elf->data + offset; \
711 /* cache the length in case we need to nuke this section later on */ \
712 if (fix_elf) \
713 offset = strlen(*r); \
437 /* If quiet, don't output paths in ld.so.conf */ \ 714 /* If quiet, don't output paths in ld.so.conf */ \
438 if (be_quiet) { \ 715 if (be_quiet) { \
439 size_t len; \ 716 size_t len; \
440 char *start, *end; \ 717 char *start, *end; \
441 /* note that we only 'chop' off leading known paths. */ \ 718 /* note that we only 'chop' off leading known paths. */ \
442 /* since *r is read-only memory, we can only move the ptr forward. */ \ 719 /* since *r is read-only memory, we can only move the ptr forward. */ \
443 start = *r; \ 720 start = *r; \
444 /* scan each path in : delimited list */ \ 721 /* scan each path in : delimited list */ \
445 while (start) { \ 722 while (start) { \
446 rpath_security_checks(elf, start); \ 723 rpath_security_checks(elf, start, get_elfdtype(word)); \
447 end = strchr(start, ':'); \ 724 end = strchr(start, ':'); \
448 len = (end ? abs(end - start) : strlen(start)); \ 725 len = (end ? abs(end - start) : strlen(start)); \
449 for (s = 0; ldpaths[s]; ++s) { \ 726 if (use_ldcache) { \
727 size_t n; \
728 const char *ldpath; \
729 array_for_each(ldpaths, n, ldpath) \
450 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 730 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
451 *r = (end ? end + 1 : NULL); \ 731 *r = end; \
732 /* corner case ... if RPATH reads "/usr/lib:", we want \
733 * to show ':' rather than '' */ \
734 if (end && end[1] != '\0') \
735 (*r)++; \
452 break; \ 736 break; \
453 } \ 737 } \
454 } \ 738 } \
455 if (!*r || !ldpaths[s] || !end) \ 739 if (!*r || !end) \
456 start = NULL; \ 740 break; \
457 else \ 741 else \
458 start = start + len + 1; \ 742 start = start + len + 1; \
459 } \ 743 } \
460 } \ 744 } \
745 if (*r) { \
746 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
747 /* just nuke it */ \
748 nuke_it##B: \
749 memset(*r, 0x00, offset); \
750 *r = NULL; \
751 ESET(dyn->d_tag, DT_DEBUG); \
752 ESET(dyn->d_un.d_ptr, 0); \
753 } else if (fix_elf) { \
754 /* try to clean "bad" paths */ \
755 size_t len, tmpdir_len; \
756 char *start, *end; \
757 const char *tmpdir; \
758 start = *r; \
759 tmpdir = (getenv("TMPDIR") ? : "."); \
760 tmpdir_len = strlen(tmpdir); \
761 while (1) { \
762 end = strchr(start, ':'); \
763 if (start == end) { \
764 eat_this_path##B: \
765 len = strlen(end); \
766 memmove(start, end+1, len); \
767 start[len-1] = '\0'; \
768 end = start - 1; \
769 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
770 if (!end) { \
771 if (start == *r) \
772 goto nuke_it##B; \
773 *--start = '\0'; \
774 } else \
775 goto eat_this_path##B; \
776 } \
777 if (!end) \
778 break; \
779 start = end + 1; \
780 } \
781 if (**r == '\0') \
782 goto nuke_it##B; \
783 } \
784 if (*r) \
461 if (*r) *found_rpath = 1; \ 785 *found_rpath = 1; \
786 } \
462 } \ 787 } \
463 ++dyn; \ 788 ++dyn; \
464 } \ 789 } \
465 } } 790 } }
466 SHOW_RPATH(32) 791 SHOW_RPATH(32)
484 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 809 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
485 else if (!be_quiet) 810 else if (!be_quiet)
486 xstrcat(ret, " - ", ret_len); 811 xstrcat(ret, " - ", ret_len);
487} 812}
488 813
814/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
489#define LDSO_CACHE_MAGIC "ld.so-" 815#define LDSO_CACHE_MAGIC "ld.so-"
490#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 816#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
491#define LDSO_CACHE_VER "1.7.0" 817#define LDSO_CACHE_VER "1.7.0"
492#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 818#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
819#define FLAG_ANY -1
820#define FLAG_TYPE_MASK 0x00ff
821#define FLAG_LIBC4 0x0000
822#define FLAG_ELF 0x0001
823#define FLAG_ELF_LIBC5 0x0002
824#define FLAG_ELF_LIBC6 0x0003
825#define FLAG_REQUIRED_MASK 0xff00
826#define FLAG_SPARC_LIB64 0x0100
827#define FLAG_IA64_LIB64 0x0200
828#define FLAG_X8664_LIB64 0x0300
829#define FLAG_S390_LIB64 0x0400
830#define FLAG_POWERPC_LIB64 0x0500
831#define FLAG_MIPS64_LIBN32 0x0600
832#define FLAG_MIPS64_LIBN64 0x0700
833#define FLAG_X8664_LIBX32 0x0800
834#define FLAG_ARM_LIBHF 0x0900
835#define FLAG_AARCH64_LIB64 0x0a00
493 836
494static char *lookup_cache_lib(char *); 837#if defined(__GLIBC__) || defined(__UCLIBC__)
838
495static char *lookup_cache_lib(char *fname) 839static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 840{
497 int fd = 0; 841 int fd;
498 char *strs; 842 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 843 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 844 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 845 struct stat st;
502 846
503 typedef struct { 847 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 848 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 849 char version[LDSO_CACHE_VER_LEN];
506 int nlibs; 850 int nlibs;
507 } header_t; 851 } header_t;
852 header_t *header;
508 853
509 typedef struct { 854 typedef struct {
510 int flags; 855 int flags;
511 int sooffset; 856 int sooffset;
512 int liboffset; 857 int liboffset;
513 } libentry_t; 858 } libentry_t;
514
515 header_t *header;
516 libentry_t *libent; 859 libentry_t *libent;
517 860
518 if (fname == NULL) 861 if (fname == NULL)
519 return NULL; 862 return NULL;
520 863
521 if (ldcache == 0) { 864 if (ldcache == NULL) {
522 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) < 0) 865 if (fstatat(root_fd, cachefile, &st, 0))
523 return NULL; 866 return NULL;
524 /* save the cache size for latter unmapping */ 867
868 fd = openat(root_fd, cachefile, O_RDONLY);
869 if (fd == -1)
870 return NULL;
871
872 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 873 ldcache_size = st.st_size;
874 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
875 close(fd);
526 876
527 if ((ldcache = mmap(0, st.st_size, PROT_READ, MAP_SHARED, fd, 0)) == (caddr_t) -1) 877 if (ldcache == MAP_FAILED) {
878 ldcache = NULL;
528 return NULL; 879 return NULL;
880 }
529 881
530 close(fd);
531
532 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 882 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
883 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
884 {
885 munmap(ldcache, ldcache_size);
886 ldcache = NULL;
533 return NULL; 887 return NULL;
534
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 888 }
889 } else
890 header = ldcache;
538 891
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 892 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 893 strs = (char *) &libent[header->nlibs];
542 894
543 for (fd = 0; fd < header->nlibs; fd++) { 895 for (fd = 0; fd < header->nlibs; ++fd) {
896 /* This should be more fine grained, but for now we assume that
897 * diff arches will not be cached together, and we ignore the
898 * the different multilib mips cases.
899 */
900 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
901 continue;
902 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
903 continue;
904
544 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 905 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
545 continue; 906 continue;
907
908 /* Return first hit because that is how the ldso rolls */
546 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 909 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
910 break;
547 } 911 }
912
548 return buf; 913 return buf;
549} 914}
550 915
916#elif defined(__NetBSD__)
917static char *lookup_cache_lib(elfobj *elf, const char *fname)
918{
919 static char buf[__PAX_UTILS_PATH_MAX] = "";
920 static struct stat st;
921 size_t n;
922 char *ldpath;
923
924 array_for_each(ldpath, n, ldpath) {
925 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
926 continue; /* if the pathname is too long, or something went wrong, ignore */
927
928 if (stat(buf, &st) != 0)
929 continue; /* if the lib doesn't exist in *ldpath, look further */
930
931 /* NetBSD doesn't actually do sanity checks, it just loads the file
932 * and if that doesn't work, continues looking in other directories.
933 * This cannot easily be safely emulated, unfortunately. For now,
934 * just assume that if it exists, it's a valid library. */
935
936 return buf;
937 }
938
939 /* not found in any path */
940 return NULL;
941}
942#else
943#ifdef __ELF__
944#warning Cache support not implemented for your target
945#endif
946static char *lookup_cache_lib(elfobj *elf, const char *fname)
947{
948 return NULL;
949}
950#endif
951
952static char *lookup_config_lib(const char *fname)
953{
954 static char buf[__PAX_UTILS_PATH_MAX] = "";
955 const char *ldpath;
956 size_t n;
957
958 array_for_each(ldpaths, n, ldpath) {
959 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
960 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
961 return buf;
962 }
963
964 return NULL;
965}
551 966
552static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 967static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
553{ 968{
554 unsigned long i; 969 unsigned long i;
555 char *needed; 970 char *needed;
556 void *strtbl_void; 971 void *strtbl_void;
557 char *p; 972 char *p;
558 973
974 /*
975 * -n -> op==0 -> print all
976 * -N -> op==1 -> print requested
977 */
559 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 978 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
979 return NULL;
560 980
561 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 981 strtbl_void = elf_findsecbyname(elf, ".dynstr");
562 982
563 if (elf->phdr && strtbl_void) { 983 if (elf->phdr && strtbl_void) {
564#define SHOW_NEEDED(B) \ 984#define SHOW_NEEDED(B) \
566 Elf ## B ## _Dyn *dyn; \ 986 Elf ## B ## _Dyn *dyn; \
567 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 987 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
568 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 988 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
569 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 989 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
570 Elf ## B ## _Off offset; \ 990 Elf ## B ## _Off offset; \
991 size_t matched = 0; \
992 /* Walk all the program headers to find the PT_DYNAMIC */ \
571 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 993 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
572 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 994 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
995 continue; \
573 offset = EGET(phdr[i].p_offset); \ 996 offset = EGET(phdr[i].p_offset); \
574 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 997 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
998 continue; \
999 /* Walk all the dynamic tags to find NEEDED entries */ \
575 dyn = DYN ## B (elf->data + offset); \ 1000 dyn = DYN ## B (elf->vdata + offset); \
576 while (EGET(dyn->d_tag) != DT_NULL) { \ 1001 while (EGET(dyn->d_tag) != DT_NULL) { \
577 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 1002 if (EGET(dyn->d_tag) == DT_NEEDED) { \
578 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1003 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
579 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1004 if (offset >= (Elf ## B ## _Off)elf->len) { \
580 ++dyn; \ 1005 ++dyn; \
581 continue; \ 1006 continue; \
582 } \ 1007 } \
583 needed = (char*)(elf->data + offset); \ 1008 needed = elf->data + offset; \
584 if (op == 0) { \ 1009 if (op == 0) { \
1010 /* -n -> print all entries */ \
585 if (!be_wewy_wewy_quiet) { \ 1011 if (!be_wewy_wewy_quiet) { \
586 if (*found_needed) xchrcat(ret, ',', ret_len); \ 1012 if (*found_needed) xchrcat(ret, ',', ret_len); \
587 if (printcache) \ 1013 if (use_ldpath) { \
588 if ((p = lookup_cache_lib(needed)) != NULL) \ 1014 if ((p = lookup_config_lib(needed)) != NULL) \
589 needed = p; \ 1015 needed = p; \
1016 } else if (use_ldcache) { \
1017 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
1018 needed = p; \
1019 } \
590 xstrcat(ret, needed, ret_len); \ 1020 xstrcat(ret, needed, ret_len); \
591 } \ 1021 } \
592 *found_needed = 1; \ 1022 *found_needed = 1; \
593 } else { \ 1023 } else { \
594 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 1024 /* -N -> print matching entries */ \
1025 size_t n; \
1026 const char *find_lib_name; \
1027 \
1028 array_for_each(find_lib_arr, n, find_lib_name) { \
1029 int invert = 1; \
1030 if (find_lib_name[0] == '!') \
1031 invert = 0, ++find_lib_name; \
1032 if (!strcmp(find_lib_name, needed) == invert) \
1033 ++matched; \
1034 } \
1035 \
1036 if (matched == array_cnt(find_lib_arr)) { \
595 *found_lib = 1; \ 1037 *found_lib = 1; \
596 return (be_wewy_wewy_quiet ? NULL : needed); \ 1038 return (be_wewy_wewy_quiet ? NULL : find_lib); \
597 } \ 1039 } \
598 } \ 1040 } \
599 } \ 1041 } \
600 ++dyn; \ 1042 ++dyn; \
601 } \ 1043 } \
623 *found_interp = 1; \ 1065 *found_interp = 1; \
624 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1066 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
625 } 1067 }
626 SHOW_INTERP(32) 1068 SHOW_INTERP(32)
627 SHOW_INTERP(64) 1069 SHOW_INTERP(64)
1070 } else {
1071 /* Walk all the program headers to find the PT_INTERP */
1072#define SHOW_PT_INTERP(B) \
1073 if (elf->elf_class == ELFCLASS ## B) { \
1074 unsigned long i; \
1075 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1076 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1077 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1078 if (EGET(phdr[i].p_type) != PT_INTERP) \
1079 continue; \
1080 *found_interp = 1; \
1081 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1082 } \
628 } 1083 }
1084 SHOW_PT_INTERP(32)
1085 SHOW_PT_INTERP(64)
1086 }
1087
629 return NULL; 1088 return NULL;
630} 1089}
631static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1090static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
632{ 1091{
633 unsigned long i; 1092 unsigned long i;
634 struct stat s; 1093 struct stat s;
1094 bool dynamic = false;
635 1095
636 if (!show_bind) return NULL; 1096 if (!show_bind) return NULL;
637 if (!elf->phdr) return NULL; 1097 if (!elf->phdr) return NULL;
638 1098
639#define SHOW_BIND(B) \ 1099#define SHOW_BIND(B) \
641 Elf ## B ## _Dyn *dyn; \ 1101 Elf ## B ## _Dyn *dyn; \
642 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1102 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
643 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1103 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
644 Elf ## B ## _Off offset; \ 1104 Elf ## B ## _Off offset; \
645 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1105 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
646 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1106 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1107 dynamic = true; \
647 offset = EGET(phdr[i].p_offset); \ 1108 offset = EGET(phdr[i].p_offset); \
648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1109 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
649 dyn = DYN ## B (elf->data + offset); \ 1110 dyn = DYN ## B (elf->vdata + offset); \
650 while (EGET(dyn->d_tag) != DT_NULL) { \ 1111 while (EGET(dyn->d_tag) != DT_NULL) { \
651 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1112 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
652 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1113 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
653 { \ 1114 { \
654 if (be_quiet) return NULL; \ 1115 if (be_quiet) return NULL; \
662 SHOW_BIND(32) 1123 SHOW_BIND(32)
663 SHOW_BIND(64) 1124 SHOW_BIND(64)
664 1125
665 if (be_wewy_wewy_quiet) return NULL; 1126 if (be_wewy_wewy_quiet) return NULL;
666 1127
1128 /* don't output anything if quiet mode and the ELF is static or not setuid */
667 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1129 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
668 return NULL; 1130 return NULL;
669 } else { 1131 } else {
670 *found_bind = 1; 1132 *found_bind = 1;
671 return (char *) "LAZY"; 1133 return dynamic ? "LAZY" : "STATIC";
672 } 1134 }
673} 1135}
674static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1136static char *scanelf_file_soname(elfobj *elf, char *found_soname)
675{ 1137{
676 unsigned long i; 1138 unsigned long i;
688 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1150 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
689 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1151 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
690 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1152 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
691 Elf ## B ## _Off offset; \ 1153 Elf ## B ## _Off offset; \
692 /* only look for soname in shared objects */ \ 1154 /* only look for soname in shared objects */ \
693 if (ehdr->e_type != ET_DYN) \ 1155 if (EGET(ehdr->e_type) != ET_DYN) \
694 return NULL; \ 1156 return NULL; \
695 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1157 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
696 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1158 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
697 offset = EGET(phdr[i].p_offset); \ 1159 offset = EGET(phdr[i].p_offset); \
698 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1160 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
699 dyn = DYN ## B (elf->data + offset); \ 1161 dyn = DYN ## B (elf->vdata + offset); \
700 while (EGET(dyn->d_tag) != DT_NULL) { \ 1162 while (EGET(dyn->d_tag) != DT_NULL) { \
701 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1163 if (EGET(dyn->d_tag) == DT_SONAME) { \
702 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1164 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
703 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1165 if (offset >= (Elf ## B ## _Off)elf->len) { \
704 ++dyn; \ 1166 ++dyn; \
705 continue; \ 1167 continue; \
706 } \ 1168 } \
707 soname = (char*)(elf->data + offset); \ 1169 soname = elf->data + offset; \
708 *found_soname = 1; \ 1170 *found_soname = 1; \
709 return (be_wewy_wewy_quiet ? NULL : soname); \ 1171 return (be_wewy_wewy_quiet ? NULL : soname); \
710 } \ 1172 } \
711 ++dyn; \ 1173 ++dyn; \
712 } \ 1174 } \
715 SHOW_SONAME(64) 1177 SHOW_SONAME(64)
716 } 1178 }
717 1179
718 return NULL; 1180 return NULL;
719} 1181}
1182
1183/*
1184 * We support the symbol form:
1185 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1186 * If the symbol name is empty, then all symbols are matched.
1187 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1188 * Do not rely on this output format at all.
1189 * Otherwise the symbol name is used to search (either regex or string compare).
1190 * If the first char of the symbol name is a plus ("+"), then only match
1191 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1192 * Putting modifiers in between the percent signs allows for more in depth
1193 * filters. There are groups of modifiers. If you don't specify a member
1194 * of a group, then all types in that group are matched. The current
1195 * groups and their types are:
1196 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1197 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1198 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1199 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1200 * You can search for multiple symbols at once by seperating with a comma (",").
1201 *
1202 * Some examples:
1203 * ELFs with a weak function "foo":
1204 * scanelf -s %wf%foo <ELFs>
1205 * ELFs that define the symbol "main":
1206 * scanelf -s +main <ELFs>
1207 * scanelf -s %d%main <ELFs>
1208 * ELFs that refer to the undefined symbol "brk":
1209 * scanelf -s -brk <ELFs>
1210 * scanelf -s %u%brk <ELFs>
1211 * All global defined objects in an ELF:
1212 * scanelf -s %ogd% <ELF>
1213 */
1214static void
1215scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1216 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1217{
1218 const char *this_sym;
1219 size_t n;
1220
1221 array_for_each(find_sym_arr, n, this_sym) {
1222 bool inc_notype, inc_object, inc_func, inc_file,
1223 inc_local, inc_global, inc_weak,
1224 inc_def, inc_undef, inc_abs, inc_common;
1225
1226 /* symbol selection! */
1227 inc_notype = inc_object = inc_func = inc_file = \
1228 inc_local = inc_global = inc_weak = \
1229 inc_def = inc_undef = inc_abs = inc_common = \
1230 (*this_sym != '%');
1231
1232 /* parse the contents of %...% */
1233 if (!inc_notype) {
1234 while (*(this_sym++)) {
1235 if (*this_sym == '%') {
1236 ++this_sym;
1237 break;
1238 }
1239 switch (*this_sym) {
1240 case 'n': inc_notype = true; break;
1241 case 'o': inc_object = true; break;
1242 case 'f': inc_func = true; break;
1243 case 'F': inc_file = true; break;
1244 case 'l': inc_local = true; break;
1245 case 'g': inc_global = true; break;
1246 case 'w': inc_weak = true; break;
1247 case 'd': inc_def = true; break;
1248 case 'u': inc_undef = true; break;
1249 case 'a': inc_abs = true; break;
1250 case 'c': inc_common = true; break;
1251 default: err("invalid symbol selector '%c'", *this_sym);
1252 }
1253 }
1254
1255 /* If no types are matched, not match all */
1256 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1257 inc_notype = inc_object = inc_func = inc_file = true;
1258 if (!inc_local && !inc_global && !inc_weak)
1259 inc_local = inc_global = inc_weak = true;
1260 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1261 inc_def = inc_undef = inc_abs = inc_common = true;
1262
1263 /* backwards compat for defined/undefined short hand */
1264 } else if (*this_sym == '+') {
1265 inc_undef = false;
1266 ++this_sym;
1267 } else if (*this_sym == '-') {
1268 inc_def = inc_abs = inc_common = false;
1269 ++this_sym;
1270 }
1271
1272 /* filter symbols */
1273 if ((!inc_notype && stt == STT_NOTYPE) || \
1274 (!inc_object && stt == STT_OBJECT) || \
1275 (!inc_func && stt == STT_FUNC ) || \
1276 (!inc_file && stt == STT_FILE ) || \
1277 (!inc_local && stb == STB_LOCAL ) || \
1278 (!inc_global && stb == STB_GLOBAL) || \
1279 (!inc_weak && stb == STB_WEAK ) || \
1280 (!inc_def && shn && shn < SHN_LORESERVE) || \
1281 (!inc_undef && shn == SHN_UNDEF ) || \
1282 (!inc_abs && shn == SHN_ABS ) || \
1283 (!inc_common && shn == SHN_COMMON))
1284 continue;
1285
1286 if (*this_sym == '*') {
1287 /* a "*" symbol gets you debug output */
1288 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1289 ((*found_sym == 0) ? "\n\t" : "\t"),
1290 elf->base_filename,
1291 size,
1292 get_elfstttype(stt),
1293 get_elfstbtype(stb),
1294 get_elfshntype(shn),
1295 symname);
1296 goto matched;
1297
1298 } else {
1299 if (g_match) {
1300 /* regex match the symbol */
1301 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1302 continue;
1303
1304 } else if (*this_sym) {
1305 /* give empty symbols a "pass", else do a normal compare */
1306 const size_t len = strlen(this_sym);
1307 if (!(strncmp(this_sym, symname, len) == 0 &&
1308 /* Accept unversioned symbol names */
1309 (symname[len] == '\0' || symname[len] == '@')))
1310 continue;
1311 }
1312
1313 if (be_semi_verbose) {
1314 char buf[1024];
1315 snprintf(buf, sizeof(buf), "%lX %s %s",
1316 size,
1317 get_elfstttype(stt),
1318 this_sym);
1319 *ret = xstrdup(buf);
1320 } else {
1321 if (*ret) xchrcat(ret, ',', ret_len);
1322 xstrcat(ret, symname, ret_len);
1323 }
1324
1325 goto matched;
1326 }
1327 }
1328
1329 return;
1330
1331 matched:
1332 *found_sym = 1;
1333}
1334
720static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1335static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
721{ 1336{
722 unsigned long i;
723 char *ret; 1337 char *ret;
724 void *symtab_void, *strtab_void; 1338 void *symtab_void, *strtab_void;
725 1339
726 if (!find_sym) return NULL; 1340 if (!find_sym) return NULL;
727 ret = find_sym; 1341 ret = NULL;
728 1342
729 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1343 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
730 1344
731 if (symtab_void && strtab_void) { 1345 if (symtab_void && strtab_void) {
732#define FIND_SYM(B) \ 1346#define FIND_SYM(B) \
733 if (elf->elf_class == ELFCLASS ## B) { \ 1347 if (elf->elf_class == ELFCLASS ## B) { \
734 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1348 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
735 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1349 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
736 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1350 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
737 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1351 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
738 char *symname; \ 1352 char *symname; \
1353 size_t ret_len = 0; \
1354 if (cnt) \
1355 cnt = EGET(symtab->sh_size) / cnt; \
739 for (i = 0; i < cnt; ++i) { \ 1356 for (i = 0; i < cnt; ++i) { \
1357 if ((void*)sym > elf->data_end) { \
1358 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1359 goto break_out; \
1360 } \
740 if (sym->st_name) { \ 1361 if (sym->st_name) { \
1362 /* make sure the symbol name is in acceptable memory range */ \
741 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1363 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
742 if (*find_sym == '*') { \ 1364 if ((void*)symname > elf->data_end) { \
743 printf("%s(%s) %5lX %15s %s\n", \ 1365 warnf("%s: corrupt ELF symbols", elf->filename); \
744 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1366 ++sym; \
745 elf->base_filename, \ 1367 continue; \
746 (unsigned long)sym->st_size, \
747 get_elfstttype(sym->st_info), \
748 symname); \
749 *found_sym = 1; \
750 } else { \
751 char *this_sym, *next_sym; \
752 this_sym = find_sym; \
753 do { \
754 next_sym = strchr(this_sym, ','); \
755 if (next_sym == NULL) \
756 next_sym = this_sym + strlen(this_sym); \
757 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
758 (strcmp(symname, versioned_symname) == 0)) { \
759 ret = this_sym; \
760 (*found_sym)++; \
761 goto break_out; \
762 } \
763 this_sym = next_sym + 1; \
764 } while (*next_sym != '\0'); \
765 } \ 1368 } \
1369 scanelf_match_symname(elf, found_sym, \
1370 &ret, &ret_len, symname, \
1371 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1372 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1373 EGET(sym->st_shndx), \
1374 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1375 EGET(sym->st_size)); \
766 } \ 1376 } \
767 ++sym; \ 1377 ++sym; \
768 } } 1378 } \
1379 }
769 FIND_SYM(32) 1380 FIND_SYM(32)
770 FIND_SYM(64) 1381 FIND_SYM(64)
771 } 1382 }
772 1383
773break_out: 1384break_out:
776 if (*find_sym != '*' && *found_sym) 1387 if (*find_sym != '*' && *found_sym)
777 return ret; 1388 return ret;
778 if (be_quiet) 1389 if (be_quiet)
779 return NULL; 1390 return NULL;
780 else 1391 else
781 return (char *)" - "; 1392 return " - ";
782} 1393}
1394
1395static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1396{
1397 if (!find_section)
1398 return NULL;
1399
1400#define FIND_SECTION(B) \
1401 if (elf->elf_class == ELFCLASS ## B) { \
1402 size_t matched, n; \
1403 int invert; \
1404 const char *section_name; \
1405 Elf ## B ## _Shdr *section; \
1406 \
1407 matched = 0; \
1408 array_for_each(find_section_arr, n, section_name) { \
1409 invert = (*section_name == '!' ? 1 : 0); \
1410 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1411 if ((section == NULL && invert) || (section != NULL && !invert)) \
1412 ++matched; \
1413 } \
1414 \
1415 if (matched == array_cnt(find_section_arr)) \
1416 *found_section = 1; \
1417 }
1418 FIND_SECTION(32)
1419 FIND_SECTION(64)
1420
1421 if (be_wewy_wewy_quiet)
1422 return NULL;
1423
1424 if (*found_section)
1425 return find_section;
1426
1427 if (be_quiet)
1428 return NULL;
1429 else
1430 return " - ";
1431}
1432
783/* scan an elf file and show all the fun stuff */ 1433/* scan an elf file and show all the fun stuff */
784#define prints(str) write(fileno(stdout), str, strlen(str)) 1434#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
785static void scanelf_file(const char *filename) 1435static int scanelf_elfobj(elfobj *elf)
786{ 1436{
787 unsigned long i; 1437 unsigned long i;
788 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1438 char found_pax, found_phdr, found_relro, found_load, found_textrel,
789 found_rpath, found_needed, found_interp, found_bind, found_soname, 1439 found_rpath, found_needed, found_interp, found_bind, found_soname,
790 found_sym, found_lib, found_file, found_textrels; 1440 found_sym, found_lib, found_file, found_textrels, found_section;
791 elfobj *elf;
792 struct stat st;
793 static char *out_buffer = NULL; 1441 static char *out_buffer = NULL;
794 static size_t out_len; 1442 static size_t out_len;
795 1443
796 /* make sure 'filename' exists */
797 if (lstat(filename, &st) == -1) {
798 if (be_verbose > 2) printf("%s: does not exist\n", filename);
799 return;
800 }
801 /* always handle regular files and handle symlinked files if no -y */
802 if (S_ISLNK(st.st_mode)) {
803 if (!scan_symlink) return;
804 stat(filename, &st);
805 }
806 if (!S_ISREG(st.st_mode)) {
807 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
808 return;
809 }
810
811 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1444 found_pax = found_phdr = found_relro = found_load = found_textrel = \
812 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1445 found_rpath = found_needed = found_interp = found_bind = found_soname = \
813 found_sym = found_lib = found_file = found_textrels = 0; 1446 found_sym = found_lib = found_file = found_textrels = found_section = 0;
814 1447
815 /* verify this is real ELF */
816 if ((elf = readelf(filename)) == NULL) {
817 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
818 return;
819 }
820
821 if (be_verbose > 1) 1448 if (be_verbose > 2)
822 printf("%s: scanning file {%s,%s}\n", filename, 1449 printf("%s: scanning file {%s,%s}\n", elf->filename,
823 get_elfeitype(EI_CLASS, elf->elf_class), 1450 get_elfeitype(EI_CLASS, elf->elf_class),
824 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1451 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
825 else if (be_verbose) 1452 else if (be_verbose > 1)
826 printf("%s: scanning file\n", filename); 1453 printf("%s: scanning file\n", elf->filename);
827 1454
828 /* init output buffer */ 1455 /* init output buffer */
829 if (!out_buffer) { 1456 if (!out_buffer) {
830 out_len = sizeof(char) * 80; 1457 out_len = sizeof(char) * 80;
831 out_buffer = (char*)xmalloc(out_len); 1458 out_buffer = xmalloc(out_len);
832 } 1459 }
833 *out_buffer = '\0'; 1460 *out_buffer = '\0';
834 1461
835 /* show the header */ 1462 /* show the header */
836 if (!be_quiet && show_banner) { 1463 if (!be_quiet && show_banner) {
837 for (i = 0; out_format[i]; ++i) { 1464 for (i = 0; out_format[i]; ++i) {
838 if (!IS_MODIFIER(out_format[i])) continue; 1465 if (!IS_MODIFIER(out_format[i])) continue;
839 1466
840 switch (out_format[++i]) { 1467 switch (out_format[++i]) {
1468 case '+': break;
841 case '%': break; 1469 case '%': break;
842 case '#': break; 1470 case '#': break;
843 case 'F': 1471 case 'F':
844 case 'p': 1472 case 'p':
845 case 'f': prints("FILE "); found_file = 1; break; 1473 case 'f': prints("FILE "); found_file = 1; break;
846 case 'o': prints(" TYPE "); break; 1474 case 'o': prints(" TYPE "); break;
847 case 'x': prints(" PAX "); break; 1475 case 'x': prints(" PAX "); break;
848 case 'e': prints("STK/REL/PTL "); break; 1476 case 'e': prints("STK/REL/PTL "); break;
849 case 't': prints("TEXTREL "); break; 1477 case 't': prints("TEXTREL "); break;
850 case 'r': prints("RPATH "); break; 1478 case 'r': prints("RPATH "); break;
1479 case 'M': prints("CLASS "); break;
1480 case 'l':
851 case 'n': prints("NEEDED "); break; 1481 case 'n': prints("NEEDED "); break;
852 case 'i': prints("INTERP "); break; 1482 case 'i': prints("INTERP "); break;
853 case 'b': prints("BIND "); break; 1483 case 'b': prints("BIND "); break;
1484 case 'Z': prints("SIZE "); break;
854 case 'S': prints("SONAME "); break; 1485 case 'S': prints("SONAME "); break;
855 case 's': prints("SYM "); break; 1486 case 's': prints("SYM "); break;
856 case 'N': prints("LIB "); break; 1487 case 'N': prints("LIB "); break;
857 case 'T': prints("TEXTRELS "); break; 1488 case 'T': prints("TEXTRELS "); break;
1489 case 'k': prints("SECTION "); break;
1490 case 'a': prints("ARCH "); break;
1491 case 'I': prints("OSABI "); break;
1492 case 'Y': prints("EABI "); break;
1493 case 'O': prints("PERM "); break;
1494 case 'D': prints("ENDIAN "); break;
858 default: warnf("'%c' has no title ?", out_format[i]); 1495 default: warnf("'%c' has no title ?", out_format[i]);
859 } 1496 }
860 } 1497 }
861 if (!found_file) prints("FILE "); 1498 if (!found_file) prints("FILE ");
862 prints("\n"); 1499 prints("\n");
866 1503
867 /* dump all the good stuff */ 1504 /* dump all the good stuff */
868 for (i = 0; out_format[i]; ++i) { 1505 for (i = 0; out_format[i]; ++i) {
869 const char *out; 1506 const char *out;
870 const char *tmp; 1507 const char *tmp;
871 1508 static char ubuf[sizeof(unsigned long)*2];
872 /* make sure we trim leading spaces in quiet mode */
873 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
874 *out_buffer = '\0';
875
876 if (!IS_MODIFIER(out_format[i])) { 1509 if (!IS_MODIFIER(out_format[i])) {
877 xchrcat(&out_buffer, out_format[i], &out_len); 1510 xchrcat(&out_buffer, out_format[i], &out_len);
878 continue; 1511 continue;
879 } 1512 }
880 1513
881 out = NULL; 1514 out = NULL;
882 be_wewy_wewy_quiet = (out_format[i] == '#'); 1515 be_wewy_wewy_quiet = (out_format[i] == '#');
1516 be_semi_verbose = (out_format[i] == '+');
883 switch (out_format[++i]) { 1517 switch (out_format[++i]) {
1518 case '+':
884 case '%': 1519 case '%':
885 case '#': 1520 case '#':
886 xchrcat(&out_buffer, out_format[i], &out_len); break; 1521 xchrcat(&out_buffer, out_format[i], &out_len); break;
887 case 'F': 1522 case 'F':
888 found_file = 1; 1523 found_file = 1;
889 if (be_wewy_wewy_quiet) break; 1524 if (be_wewy_wewy_quiet) break;
890 xstrcat(&out_buffer, filename, &out_len); 1525 xstrcat(&out_buffer, elf->filename, &out_len);
891 break; 1526 break;
892 case 'p': 1527 case 'p':
893 found_file = 1; 1528 found_file = 1;
894 if (be_wewy_wewy_quiet) break; 1529 if (be_wewy_wewy_quiet) break;
895 tmp = filename; 1530 tmp = elf->filename;
896 if (search_path) { 1531 if (search_path) {
897 ssize_t len_search = strlen(search_path); 1532 ssize_t len_search = strlen(search_path);
898 ssize_t len_file = strlen(filename); 1533 ssize_t len_file = strlen(elf->filename);
899 if (!strncmp(filename, search_path, len_search) && \ 1534 if (!strncmp(elf->filename, search_path, len_search) && \
900 len_file > len_search) 1535 len_file > len_search)
901 tmp += len_search; 1536 tmp += len_search;
902 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1537 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
903 } 1538 }
904 xstrcat(&out_buffer, tmp, &out_len); 1539 xstrcat(&out_buffer, tmp, &out_len);
905 break; 1540 break;
906 case 'f': 1541 case 'f':
907 found_file = 1; 1542 found_file = 1;
908 if (be_wewy_wewy_quiet) break; 1543 if (be_wewy_wewy_quiet) break;
909 tmp = strrchr(filename, '/'); 1544 tmp = strrchr(elf->filename, '/');
910 tmp = (tmp == NULL ? filename : tmp+1); 1545 tmp = (tmp == NULL ? elf->filename : tmp+1);
911 xstrcat(&out_buffer, tmp, &out_len); 1546 xstrcat(&out_buffer, tmp, &out_len);
912 break; 1547 break;
913 case 'o': out = get_elfetype(elf); break; 1548 case 'o': out = get_elfetype(elf); break;
914 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1549 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
915 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1550 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
916 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1551 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
917 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1552 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
918 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1553 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1554 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1555 case 'D': out = get_endian(elf); break;
1556 case 'O': out = strfileperms(elf->filename); break;
919 case 'n': 1557 case 'n':
920 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1558 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
921 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1559 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
922 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1560 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
923 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1561 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
924 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1562 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1563 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1564 case 'a': out = get_elfemtype(elf); break;
1565 case 'I': out = get_elfosabi(elf); break;
1566 case 'Y': out = get_elf_eabi(elf); break;
1567 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
925 default: warnf("'%c' has no scan code?", out_format[i]); 1568 default: warnf("'%c' has no scan code?", out_format[i]);
926 } 1569 }
927 if (out) { 1570 if (out)
928 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
929 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
930 xstrncat(&out_buffer, out, &out_len, (tmp-out));
931 else
932 xstrcat(&out_buffer, out, &out_len); 1571 xstrcat(&out_buffer, out, &out_len);
933 }
934 } 1572 }
935 1573
936#define FOUND_SOMETHING() \ 1574#define FOUND_SOMETHING() \
937 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1575 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
938 found_rpath || found_needed || found_interp || found_bind || \ 1576 found_rpath || found_needed || found_interp || found_bind || \
939 found_soname || found_sym || found_lib || found_textrels) 1577 found_soname || found_sym || found_lib || found_textrels || found_section )
940 1578
941 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1579 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
942 xchrcat(&out_buffer, ' ', &out_len); 1580 xchrcat(&out_buffer, ' ', &out_len);
943 xstrcat(&out_buffer, filename, &out_len); 1581 xstrcat(&out_buffer, elf->filename, &out_len);
944 } 1582 }
945 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1583 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
946 puts(out_buffer); 1584 puts(out_buffer);
947 fflush(stdout); 1585 fflush(stdout);
948 } 1586 }
949 1587
1588 return 0;
1589}
1590
1591/* scan a single elf */
1592static int scanelf_elf(const char *filename, int fd, size_t len)
1593{
1594 int ret = 1;
1595 size_t n;
1596 const char *match_etype;
1597 elfobj *elf;
1598
1599 /* Verify this is a real ELF */
1600 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1601 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1602 return 2;
1603 }
1604
1605 /* Possibly filter based on ELF bitness */
1606 switch (match_bits) {
1607 case 32:
1608 if (elf->elf_class != ELFCLASS32)
1609 goto done;
1610 break;
1611 case 64:
1612 if (elf->elf_class != ELFCLASS64)
1613 goto done;
1614 break;
1615 }
1616
1617 /* Possibly filter based on the ELF's e_type field */
1618 array_for_each(match_etypes, n, match_etype)
1619 if (etype_lookup(match_etype) == get_etype(elf))
1620 goto scanit;
1621 if (array_cnt(match_etypes))
1622 goto done;
1623
1624 scanit:
1625 ret = scanelf_elfobj(elf);
1626
1627 done:
950 unreadelf(elf); 1628 unreadelf(elf);
1629 return ret;
1630}
1631
1632/* scan an archive of elfs */
1633static int scanelf_archive(const char *filename, int fd, size_t len)
1634{
1635 archive_handle *ar;
1636 archive_member *m;
1637 char *ar_buffer;
1638 elfobj *elf;
1639
1640 ar = ar_open_fd(filename, fd);
1641 if (ar == NULL)
1642 return 1;
1643
1644 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1645 while ((m = ar_next(ar)) != NULL) {
1646 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1647 if (cur_pos == -1)
1648 errp("lseek() failed");
1649 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1650 if (elf) {
1651 scanelf_elfobj(elf);
1652 unreadelf(elf);
1653 }
1654 }
1655 munmap(ar_buffer, len);
1656
1657 return 0;
1658}
1659/* scan a file which may be an elf or an archive or some other magical beast */
1660static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1661{
1662 const struct stat *st = st_cache;
1663 struct stat symlink_st;
1664 int fd;
1665
1666 /* always handle regular files and handle symlinked files if no -y */
1667 if (S_ISLNK(st->st_mode)) {
1668 if (!scan_symlink)
1669 return 1;
1670 fstatat(dir_fd, filename, &symlink_st, 0);
1671 st = &symlink_st;
1672 }
1673
1674 if (!S_ISREG(st->st_mode)) {
1675 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1676 return 1;
1677 }
1678
1679 if (match_perms) {
1680 if ((st->st_mode | match_perms) != st->st_mode)
1681 return 1;
1682 }
1683 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1684 if (fd == -1) {
1685 if (fix_elf && errno == ETXTBSY)
1686 warnp("%s: could not fix", filename);
1687 else if (be_verbose > 2)
1688 printf("%s: skipping file: %s\n", filename, strerror(errno));
1689 return 1;
1690 }
1691
1692 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1693 /* if it isn't an ELF, maybe it's an .a archive */
1694 if (scan_archives)
1695 scanelf_archive(filename, fd, st->st_size);
1696
1697 /*
1698 * unreadelf() implicitly closes its fd, so only close it
1699 * when we are returning it in the non-ELF case
1700 */
1701 close(fd);
1702 }
1703
1704 return 0;
951} 1705}
952 1706
953/* scan a directory for ET_EXEC files and print when we find one */ 1707/* scan a directory for ET_EXEC files and print when we find one */
954static void scanelf_dir(const char *path) 1708static int scanelf_dirat(int dir_fd, const char *path)
955{ 1709{
956 register DIR *dir; 1710 register DIR *dir;
957 register struct dirent *dentry; 1711 register struct dirent *dentry;
958 struct stat st_top, st; 1712 struct stat st_top, st;
959 char buf[_POSIX_PATH_MAX]; 1713 char buf[__PAX_UTILS_PATH_MAX], *subpath;
960 size_t pathlen = 0, len = 0; 1714 size_t pathlen = 0, len = 0;
1715 int ret = 0;
1716 int subdir_fd;
961 1717
962 /* make sure path exists */ 1718 /* make sure path exists */
963 if (lstat(path, &st_top) == -1) { 1719 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
964 if (be_verbose > 2) printf("%s: does not exist\n", path); 1720 if (be_verbose > 2) printf("%s: does not exist\n", path);
965 return; 1721 return 1;
966 } 1722 }
967 1723
968 /* ok, if it isn't a directory, assume we can open it */ 1724 /* ok, if it isn't a directory, assume we can open it */
969 if (!S_ISDIR(st_top.st_mode)) { 1725 if (!S_ISDIR(st_top.st_mode))
970 scanelf_file(path); 1726 return scanelf_fileat(dir_fd, path, &st_top);
971 return;
972 }
973 1727
974 /* now scan the dir looking for fun stuff */ 1728 /* now scan the dir looking for fun stuff */
975 if ((dir = opendir(path)) == NULL) { 1729 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
976 warnf("could not opendir %s: %s", path, strerror(errno)); 1730 if (subdir_fd == -1)
1731 dir = NULL;
1732 else
1733 dir = fdopendir(subdir_fd);
1734 if (dir == NULL) {
1735 if (subdir_fd != -1)
1736 close(subdir_fd);
1737 else if (be_verbose > 2)
1738 printf("%s: skipping dir: %s\n", path, strerror(errno));
977 return; 1739 return 1;
978 } 1740 }
979 if (be_verbose) printf("%s: scanning dir\n", path); 1741 if (be_verbose > 1) printf("%s: scanning dir\n", path);
980 1742
981 pathlen = strlen(path); 1743 subpath = stpcpy(buf, path);
1744 if (subpath[-1] != '/')
1745 *subpath++ = '/';
1746 pathlen = subpath - buf;
982 while ((dentry = readdir(dir))) { 1747 while ((dentry = readdir(dir))) {
983 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1748 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
984 continue; 1749 continue;
1750
1751 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
1752 continue;
1753
985 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1754 len = strlen(dentry->d_name);
986 if (len >= sizeof(buf)) { 1755 if (len + pathlen + 1 >= sizeof(buf)) {
987 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path, 1756 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
988 (unsigned long)len, (unsigned long)sizeof(buf)); 1757 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
989 continue; 1758 continue;
990 } 1759 }
991 sprintf(buf, "%s/%s", path, dentry->d_name); 1760 memcpy(subpath, dentry->d_name, len);
992 if (lstat(buf, &st) != -1) { 1761 subpath[len] = '\0';
1762
993 if (S_ISREG(st.st_mode)) 1763 if (S_ISREG(st.st_mode))
994 scanelf_file(buf); 1764 ret = scanelf_fileat(dir_fd, buf, &st);
995 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1765 else if (dir_recurse && S_ISDIR(st.st_mode)) {
996 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1766 if (dir_crossmount || (st_top.st_dev == st.st_dev))
997 scanelf_dir(buf); 1767 ret = scanelf_dirat(dir_fd, buf);
998 }
999 } 1768 }
1000 } 1769 }
1001 closedir(dir); 1770 closedir(dir);
1002}
1003 1771
1772 return ret;
1773}
1774static int scanelf_dir(const char *path)
1775{
1776 return scanelf_dirat(root_fd, root_rel_path(path));
1777}
1778
1004static int scanelf_from_file(char *filename) 1779static int scanelf_from_file(const char *filename)
1005{ 1780{
1006 FILE *fp = NULL; 1781 FILE *fp;
1007 char *p; 1782 char *p, *path;
1008 char path[_POSIX_PATH_MAX]; 1783 size_t len;
1784 int ret;
1009 1785
1010 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1786 if (strcmp(filename, "-") == 0)
1011 fp = stdin; 1787 fp = stdin;
1012 else if ((fp = fopen(filename, "r")) == NULL) 1788 else if ((fp = fopen(filename, "r")) == NULL)
1013 return 1; 1789 return 1;
1014 1790
1015 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1791 path = NULL;
1792 len = 0;
1793 ret = 0;
1794 while (getline(&path, &len, fp) != -1) {
1016 if ((p = strchr(path, '\n')) != NULL) 1795 if ((p = strchr(path, '\n')) != NULL)
1017 *p = 0; 1796 *p = 0;
1018 search_path = path; 1797 search_path = path;
1019 scanelf_dir(path); 1798 ret = scanelf_dir(path);
1020 } 1799 }
1800 free(path);
1801
1021 if (fp != stdin) 1802 if (fp != stdin)
1022 fclose(fp); 1803 fclose(fp);
1804
1023 return 0; 1805 return ret;
1024} 1806}
1025 1807
1026static void load_ld_so_conf() 1808#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1809
1810static int _load_ld_cache_config(const char *fname)
1027{ 1811{
1028 FILE *fp = NULL; 1812 FILE *fp = NULL;
1029 char *p; 1813 char *p, *path;
1030 char path[_POSIX_PATH_MAX]; 1814 size_t len;
1031 int i = 0; 1815 int curr_fd = -1;
1032 1816
1033 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1817 fp = fopenat_r(root_fd, root_rel_path(fname));
1818 if (fp == NULL)
1034 return; 1819 return -1;
1035 1820
1036 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1821 path = NULL;
1037 if (*path != '/') 1822 len = 0;
1038 continue; 1823 while (getline(&path, &len, fp) != -1) {
1039
1040 if ((p = strrchr(path, '\r')) != NULL) 1824 if ((p = strrchr(path, '\r')) != NULL)
1041 *p = 0; 1825 *p = 0;
1042 if ((p = strchr(path, '\n')) != NULL) 1826 if ((p = strchr(path, '\n')) != NULL)
1043 *p = 0; 1827 *p = 0;
1044 1828
1045 ldpaths[i++] = xstrdup(path); 1829 /* recursive includes of the same file will make this segfault. */
1830 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1831 glob_t gl;
1832 size_t x;
1833 const char *gpath;
1046 1834
1047 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1835 /* re-use existing path buffer ... need to be creative */
1048 break; 1836 if (path[8] != '/')
1837 gpath = memcpy(path + 3, "/etc/", 5);
1838 else
1839 gpath = path + 8;
1840 if (root_fd != AT_FDCWD) {
1841 if (curr_fd == -1) {
1842 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1843 if (fchdir(root_fd))
1844 errp("unable to change to root dir");
1845 }
1846 gpath = root_rel_path(gpath);
1847 }
1848
1849 if (glob(gpath, 0, NULL, &gl) == 0) {
1850 for (x = 0; x < gl.gl_pathc; ++x) {
1851 /* try to avoid direct loops */
1852 if (strcmp(gl.gl_pathv[x], fname) == 0)
1853 continue;
1854 _load_ld_cache_config(gl.gl_pathv[x]);
1855 }
1856 globfree(&gl);
1857 }
1858
1859 /* failed globs are ignored by glibc */
1860 continue;
1049 } 1861 }
1050 ldpaths[i] = NULL; 1862
1863 if (*path != '/')
1864 continue;
1865
1866 xarraypush_str(ldpaths, path);
1867 }
1868 free(path);
1051 1869
1052 fclose(fp); 1870 fclose(fp);
1871
1872 if (curr_fd != -1) {
1873 if (fchdir(curr_fd))
1874 {/* don't care */}
1875 close(curr_fd);
1876 }
1877
1878 return 0;
1879}
1880
1881#elif defined(__FreeBSD__) || defined(__DragonFly__)
1882
1883static int _load_ld_cache_config(const char *fname)
1884{
1885 FILE *fp = NULL;
1886 char *b = NULL, *p;
1887 struct elfhints_hdr hdr;
1888
1889 fp = fopenat_r(root_fd, root_rel_path(fname));
1890 if (fp == NULL)
1891 return -1;
1892
1893 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1894 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1895 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1896 {
1897 fclose(fp);
1898 return -1;
1899 }
1900
1901 b = xmalloc(hdr.dirlistlen + 1);
1902 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1903 fclose(fp);
1904 free(b);
1905 return -1;
1906 }
1907
1908 while ((p = strsep(&b, ":"))) {
1909 if (*p == '\0')
1910 continue;
1911 xarraypush_str(ldpaths, p);
1912 }
1913
1914 free(b);
1915 fclose(fp);
1916 return 0;
1917}
1918
1919#else
1920#ifdef __ELF__
1921#warning Cache config support not implemented for your target
1922#endif
1923static int _load_ld_cache_config(const char *fname)
1924{
1925 return 0;
1926}
1927#endif
1928
1929static void load_ld_cache_config(const char *fname)
1930{
1931 bool scan_l, scan_ul, scan_ull;
1932 size_t n;
1933 const char *ldpath;
1934
1935 _load_ld_cache_config(fname);
1936
1937 scan_l = scan_ul = scan_ull = false;
1938 array_for_each(ldpaths, n, ldpath) {
1939 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1940 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1941 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1942 }
1943
1944 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1945 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1946 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1053} 1947}
1054 1948
1055/* scan /etc/ld.so.conf for paths */ 1949/* scan /etc/ld.so.conf for paths */
1056static void scanelf_ldpath() 1950static void scanelf_ldpath(void)
1057{ 1951{
1058 char scan_l, scan_ul, scan_ull; 1952 size_t n;
1059 int i = 0; 1953 const char *ldpath;
1060 1954
1061 if (!ldpaths[0]) 1955 array_for_each(ldpaths, n, ldpath)
1062 err("Unable to load any paths from ld.so.conf");
1063
1064 scan_l = scan_ul = scan_ull = 0;
1065
1066 while (ldpaths[i]) {
1067 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1068 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1069 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1070 scanelf_dir(ldpaths[i]); 1956 scanelf_dir(ldpath);
1071 ++i;
1072 }
1073
1074 if (!scan_l) scanelf_dir("/lib");
1075 if (!scan_ul) scanelf_dir("/usr/lib");
1076 if (!scan_ull) scanelf_dir("/usr/local/lib");
1077} 1957}
1078 1958
1079/* scan env PATH for paths */ 1959/* scan env PATH for paths */
1080static void scanelf_envpath() 1960static void scanelf_envpath(void)
1081{ 1961{
1082 char *path, *p; 1962 char *path, *p;
1083 1963
1084 path = getenv("PATH"); 1964 path = getenv("PATH");
1085 if (!path) 1965 if (!path)
1092 } 1972 }
1093 1973
1094 free(path); 1974 free(path);
1095} 1975}
1096 1976
1097 1977/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1098/* usage / invocation handling functions */
1099#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1978#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1100#define a_argument required_argument 1979#define a_argument required_argument
1101static struct option const long_opts[] = { 1980static struct option const long_opts[] = {
1102 {"path", no_argument, NULL, 'p'}, 1981 {"path", no_argument, NULL, 'p'},
1103 {"ldpath", no_argument, NULL, 'l'}, 1982 {"ldpath", no_argument, NULL, 'l'},
1983 {"use-ldpath",no_argument, NULL, 129},
1984 {"root", a_argument, NULL, 128},
1104 {"recursive", no_argument, NULL, 'R'}, 1985 {"recursive", no_argument, NULL, 'R'},
1105 {"mount", no_argument, NULL, 'm'}, 1986 {"mount", no_argument, NULL, 'm'},
1106 {"symlink", no_argument, NULL, 'y'}, 1987 {"symlink", no_argument, NULL, 'y'},
1988 {"archives", no_argument, NULL, 'A'},
1989 {"ldcache", no_argument, NULL, 'L'},
1990 {"fix", no_argument, NULL, 'X'},
1991 {"setpax", a_argument, NULL, 'z'},
1107 {"pax", no_argument, NULL, 'x'}, 1992 {"pax", no_argument, NULL, 'x'},
1108 {"header", no_argument, NULL, 'e'}, 1993 {"header", no_argument, NULL, 'e'},
1109 {"textrel", no_argument, NULL, 't'}, 1994 {"textrel", no_argument, NULL, 't'},
1110 {"rpath", no_argument, NULL, 'r'}, 1995 {"rpath", no_argument, NULL, 'r'},
1111 {"needed", no_argument, NULL, 'n'}, 1996 {"needed", no_argument, NULL, 'n'},
1112 {"ldcache", no_argument, NULL, 'L'},
1113 {"interp", no_argument, NULL, 'i'}, 1997 {"interp", no_argument, NULL, 'i'},
1114 {"bind", no_argument, NULL, 'b'}, 1998 {"bind", no_argument, NULL, 'b'},
1115 {"soname", no_argument, NULL, 'S'}, 1999 {"soname", no_argument, NULL, 'S'},
1116 {"symbol", a_argument, NULL, 's'}, 2000 {"symbol", a_argument, NULL, 's'},
2001 {"section", a_argument, NULL, 'k'},
1117 {"lib", a_argument, NULL, 'N'}, 2002 {"lib", a_argument, NULL, 'N'},
1118 {"gmatch", no_argument, NULL, 'g'}, 2003 {"gmatch", no_argument, NULL, 'g'},
1119 {"textrels", no_argument, NULL, 'T'}, 2004 {"textrels", no_argument, NULL, 'T'},
2005 {"etype", a_argument, NULL, 'E'},
2006 {"bits", a_argument, NULL, 'M'},
2007 {"endian", no_argument, NULL, 'D'},
2008 {"osabi", no_argument, NULL, 'I'},
2009 {"eabi", no_argument, NULL, 'Y'},
2010 {"perms", a_argument, NULL, 'O'},
2011 {"size", no_argument, NULL, 'Z'},
1120 {"all", no_argument, NULL, 'a'}, 2012 {"all", no_argument, NULL, 'a'},
1121 {"quiet", no_argument, NULL, 'q'}, 2013 {"quiet", no_argument, NULL, 'q'},
1122 {"verbose", no_argument, NULL, 'v'}, 2014 {"verbose", no_argument, NULL, 'v'},
1123 {"format", a_argument, NULL, 'F'}, 2015 {"format", a_argument, NULL, 'F'},
1124 {"from", a_argument, NULL, 'f'}, 2016 {"from", a_argument, NULL, 'f'},
1125 {"file", a_argument, NULL, 'o'}, 2017 {"file", a_argument, NULL, 'o'},
2018 {"nocolor", no_argument, NULL, 'C'},
1126 {"nobanner", no_argument, NULL, 'B'}, 2019 {"nobanner", no_argument, NULL, 'B'},
1127 {"help", no_argument, NULL, 'h'}, 2020 {"help", no_argument, NULL, 'h'},
1128 {"version", no_argument, NULL, 'V'}, 2021 {"version", no_argument, NULL, 'V'},
1129 {NULL, no_argument, NULL, 0x0} 2022 {NULL, no_argument, NULL, 0x0}
1130}; 2023};
1131 2024
1132static const char *opts_help[] = { 2025static const char * const opts_help[] = {
1133 "Scan all directories in PATH environment", 2026 "Scan all directories in PATH environment",
1134 "Scan all directories in /etc/ld.so.conf", 2027 "Scan all directories in /etc/ld.so.conf",
2028 "Use ld.so.conf to show full path (use with -r/-n)",
2029 "Root directory (use with -l or -p)",
1135 "Scan directories recursively", 2030 "Scan directories recursively",
1136 "Don't recursively cross mount points", 2031 "Don't recursively cross mount points",
1137 "Don't scan symlinks\n", 2032 "Don't scan symlinks",
2033 "Scan archives (.a files)",
2034 "Utilize ld.so.cache to show full path (use with -r/-n)",
2035 "Try and 'fix' bad things (use with -r/-e)",
2036 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1138 "Print PaX markings", 2037 "Print PaX markings",
1139 "Print GNU_STACK/PT_LOAD markings", 2038 "Print GNU_STACK/PT_LOAD markings",
1140 "Print TEXTREL information", 2039 "Print TEXTREL information",
1141 "Print RPATH information", 2040 "Print RPATH information",
1142 "Print NEEDED information", 2041 "Print NEEDED information",
1143 "Resolve NEEDED information (use with -n)",
1144 "Print INTERP information", 2042 "Print INTERP information",
1145 "Print BIND information", 2043 "Print BIND information",
1146 "Print SONAME information", 2044 "Print SONAME information",
1147 "Find a specified symbol", 2045 "Find a specified symbol",
2046 "Find a specified section",
1148 "Find a specified library", 2047 "Find a specified library",
1149 "Use strncmp to match libraries. (use with -N)", 2048 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1150 "Locate cause of TEXTREL", 2049 "Locate cause of TEXTREL",
1151 "Print all scanned info (-x -e -t -r -b)\n", 2050 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2051 "Print only ELF files matching numeric bits",
2052 "Print Endianness",
2053 "Print OSABI",
2054 "Print EABI (EM_ARM Only)",
2055 "Print only ELF files matching octal permissions",
2056 "Print ELF file size",
2057 "Print all useful/simple info\n",
1152 "Only output 'bad' things", 2058 "Only output 'bad' things",
1153 "Be verbose (can be specified more than once)", 2059 "Be verbose (can be specified more than once)",
1154 "Use specified format for output", 2060 "Use specified format for output",
1155 "Read input stream from a filename", 2061 "Read input stream from a filename",
1156 "Write output stream to a filename", 2062 "Write output stream to a filename",
2063 "Don't emit color in output",
1157 "Don't display the header", 2064 "Don't display the header",
1158 "Print this help and exit", 2065 "Print this help and exit",
1159 "Print version and exit", 2066 "Print version and exit",
1160 NULL 2067 NULL
1161}; 2068};
1162 2069
1163/* display usage and exit */ 2070/* display usage and exit */
1164static void usage(int status) 2071static void usage(int status)
1165{ 2072{
1166 unsigned long i; 2073 const char a_arg[] = "<arg>";
2074 size_t a_arg_len = strlen(a_arg) + 2;
2075 size_t i;
2076 int optlen;
1167 printf("* Scan ELF binaries for stuff\n\n" 2077 printf("* Scan ELF binaries for stuff\n\n"
1168 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2078 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1169 printf("Options: -[%s]\n", PARSE_FLAGS); 2079 printf("Options: -[%s]\n", PARSE_FLAGS);
2080
2081 /* prescan the --long opt length to auto-align */
2082 optlen = 0;
1170 for (i = 0; long_opts[i].name; ++i) 2083 for (i = 0; long_opts[i].name; ++i) {
2084 int l = strlen(long_opts[i].name);
2085 if (long_opts[i].has_arg == a_argument)
2086 l += a_arg_len;
2087 optlen = max(l, optlen);
2088 }
2089
2090 for (i = 0; long_opts[i].name; ++i) {
2091 /* first output the short flag if it has one */
2092 if (long_opts[i].val > '~')
2093 printf(" ");
2094 else
2095 printf(" -%c, ", long_opts[i].val);
2096
2097 /* then the long flag */
1171 if (long_opts[i].has_arg == no_argument) 2098 if (long_opts[i].has_arg == no_argument)
1172 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2099 printf("--%-*s", optlen, long_opts[i].name);
1173 long_opts[i].name, opts_help[i]);
1174 else 2100 else
1175 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2101 printf("--%s %s %*s", long_opts[i].name, a_arg,
1176 long_opts[i].name, opts_help[i]); 2102 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1177 2103
1178 if (status != EXIT_SUCCESS) 2104 /* finally the help text */
1179 exit(status); 2105 printf("* %s\n", opts_help[i]);
2106 }
1180 2107
1181 puts("\nThe format modifiers for the -F option are:"); 2108 puts("\nFor more information, see the scanelf(1) manpage");
1182 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1183 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1184 puts(" i INTERP \tb BIND \ts symbol");
1185 puts(" N library \to Type \tT TEXTRELs");
1186 puts(" S SONAME");
1187 puts(" p filename (with search path removed)");
1188 puts(" f filename (short name/basename)");
1189 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1190
1191 exit(status); 2109 exit(status);
1192} 2110}
1193 2111
1194/* parse command line arguments and preform needed actions */ 2112/* parse command line arguments and preform needed actions */
2113#define do_pax_state(option, flag) \
2114 if (islower(option)) { \
2115 flags &= ~PF_##flag; \
2116 flags |= PF_NO##flag; \
2117 } else { \
2118 flags &= ~PF_NO##flag; \
2119 flags |= PF_##flag; \
2120 }
2121static void parse_delimited(array_t *arr, char *arg, const char *delim)
2122{
2123 char *ele = strtok(arg, delim);
2124 if (!ele) /* edge case: -s '' */
2125 xarraypush_str(arr, "");
2126 while (ele) {
2127 xarraypush_str(arr, ele);
2128 ele = strtok(NULL, delim);
2129 }
2130}
1195static void parseargs(int argc, char *argv[]) 2131static int parseargs(int argc, char *argv[])
1196{ 2132{
1197 int i; 2133 int i;
1198 char *from_file = NULL; 2134 const char *from_file = NULL;
2135 int ret = 0;
2136 char load_cache_config = 0;
1199 2137
1200 opterr = 0; 2138 opterr = 0;
1201 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2139 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1202 switch (i) { 2140 switch (i) {
1203 2141
1207 VERSION, __FILE__, __DATE__, rcsid, argv0); 2145 VERSION, __FILE__, __DATE__, rcsid, argv0);
1208 exit(EXIT_SUCCESS); 2146 exit(EXIT_SUCCESS);
1209 break; 2147 break;
1210 case 'h': usage(EXIT_SUCCESS); break; 2148 case 'h': usage(EXIT_SUCCESS); break;
1211 case 'f': 2149 case 'f':
1212 if (from_file) err("Don't specify -f twice"); 2150 if (from_file) warn("You prob don't want to specify -f twice");
1213 from_file = xstrdup(optarg); 2151 from_file = optarg;
2152 break;
2153 case 'E':
2154 /* historically, this was comma delimited */
2155 parse_delimited(match_etypes, optarg, ",");
2156 break;
2157 case 'M':
2158 match_bits = atoi(optarg);
2159 if (match_bits == 0) {
2160 if (strcmp(optarg, "ELFCLASS32") == 0)
2161 match_bits = 32;
2162 if (strcmp(optarg, "ELFCLASS64") == 0)
2163 match_bits = 64;
2164 }
2165 break;
2166 case 'O':
2167 if (sscanf(optarg, "%o", &match_perms) == -1)
2168 match_bits = 0;
1214 break; 2169 break;
1215 case 'o': { 2170 case 'o': {
1216 FILE *fp = NULL;
1217 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2171 if (freopen(optarg, "w", stdout) == NULL)
1218 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2172 errp("Could not freopen(%s)", optarg);
1219 SET_STDOUT(fp);
1220 break; 2173 break;
1221 } 2174 }
1222
1223 case 's': { 2175 case 'k':
1224 if (find_sym) warn("You prob don't want to specify -s twice"); 2176 xarraypush_str(find_section_arr, optarg);
1225 find_sym = optarg;
1226 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1));
1227 sprintf(versioned_symname, "%s@", find_sym);
1228 break; 2177 break;
1229 }
1230 case 'N': { 2178 case 's':
1231 if (find_lib) warn("You prob don't want to specify -N twice"); 2179 /* historically, this was comma delimited */
1232 find_lib = optarg; 2180 parse_delimited(find_sym_arr, optarg, ",");
1233 break; 2181 break;
1234 } 2182 case 'N':
1235 2183 xarraypush_str(find_lib_arr, optarg);
2184 break;
1236 case 'F': { 2185 case 'F': {
1237 if (out_format) warn("You prob don't want to specify -F twice"); 2186 if (out_format) warn("You prob don't want to specify -F twice");
1238 out_format = optarg; 2187 out_format = optarg;
1239 break; 2188 break;
1240 } 2189 }
2190 case 'z': {
2191 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2192 size_t x;
1241 2193
1242 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2194 for (x = 0; x < strlen(optarg); x++) {
1243 case 'L': printcache = 1; break; 2195 switch (optarg[x]) {
2196 case 'p':
2197 case 'P':
2198 do_pax_state(optarg[x], PAGEEXEC);
2199 break;
2200 case 's':
2201 case 'S':
2202 do_pax_state(optarg[x], SEGMEXEC);
2203 break;
2204 case 'm':
2205 case 'M':
2206 do_pax_state(optarg[x], MPROTECT);
2207 break;
2208 case 'e':
2209 case 'E':
2210 do_pax_state(optarg[x], EMUTRAMP);
2211 break;
2212 case 'r':
2213 case 'R':
2214 do_pax_state(optarg[x], RANDMMAP);
2215 break;
2216 case 'x':
2217 case 'X':
2218 do_pax_state(optarg[x], RANDEXEC);
2219 break;
2220 default:
2221 break;
2222 }
2223 }
2224 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2225 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2226 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2227 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2228 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2229 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2230 setpax = flags;
2231 break;
2232 }
2233 case 'Z': show_size = 1; break;
2234 case 'g': ++g_match; break;
2235 case 'L': load_cache_config = use_ldcache = 1; break;
1244 case 'y': scan_symlink = 0; break; 2236 case 'y': scan_symlink = 0; break;
2237 case 'A': scan_archives = 1; break;
2238 case 'C': color_init(true); break;
1245 case 'B': show_banner = 0; break; 2239 case 'B': show_banner = 0; break;
1246 case 'l': scan_ldpath = 1; break; 2240 case 'l': load_cache_config = scan_ldpath = 1; break;
1247 case 'p': scan_envpath = 1; break; 2241 case 'p': scan_envpath = 1; break;
1248 case 'R': dir_recurse = 1; break; 2242 case 'R': dir_recurse = 1; break;
1249 case 'm': dir_crossmount = 0; break; 2243 case 'm': dir_crossmount = 0; break;
2244 case 'X': ++fix_elf; break;
1250 case 'x': show_pax = 1; break; 2245 case 'x': show_pax = 1; break;
1251 case 'e': show_phdr = 1; break; 2246 case 'e': show_phdr = 1; break;
1252 case 't': show_textrel = 1; break; 2247 case 't': show_textrel = 1; break;
1253 case 'r': show_rpath = 1; break; 2248 case 'r': show_rpath = 1; break;
1254 case 'n': show_needed = 1; break; 2249 case 'n': show_needed = 1; break;
1255 case 'i': show_interp = 1; break; 2250 case 'i': show_interp = 1; break;
1256 case 'b': show_bind = 1; break; 2251 case 'b': show_bind = 1; break;
1257 case 'S': show_soname = 1; break; 2252 case 'S': show_soname = 1; break;
1258 case 'T': show_textrels = 1; break; 2253 case 'T': show_textrels = 1; break;
1259 case 'q': be_quiet = 1; break; 2254 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1260 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2255 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1261 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2256 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1262 2257 case 'D': show_endian = 1; break;
2258 case 'I': show_osabi = 1; break;
2259 case 'Y': show_eabi = 1; break;
2260 case 128:
2261 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2262 if (root_fd == -1)
2263 err("Could not open root: %s", optarg);
2264 break;
2265 case 129: load_cache_config = use_ldpath = 1; break;
1263 case ':': 2266 case ':':
1264 err("Option missing parameter\n"); 2267 err("Option '%c' is missing parameter", optopt);
1265 case '?': 2268 case '?':
1266 err("Unknown option\n"); 2269 err("Unknown option '%c' or argument missing", optopt);
1267 default: 2270 default:
1268 err("Unhandled option '%c'", i); 2271 err("Unhandled option '%c'; please report this", i);
1269 } 2272 }
1270 } 2273 }
2274 if (show_textrels && be_verbose)
2275 objdump = which("objdump", "OBJDUMP");
2276 /* precompile all the regexes */
2277 if (g_match) {
2278 regex_t preg;
2279 const char *this_sym;
2280 size_t n;
2281 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
1271 2282
2283 array_for_each(find_sym_arr, n, this_sym) {
2284 /* see scanelf_match_symname for logic info */
2285 switch (this_sym[0]) {
2286 case '%':
2287 while (*(this_sym++))
2288 if (*this_sym == '%') {
2289 ++this_sym;
2290 break;
2291 }
2292 break;
2293 case '+':
2294 case '-':
2295 ++this_sym;
2296 break;
2297 }
2298 if (*this_sym == '*')
2299 ++this_sym;
2300
2301 ret = regcomp(&preg, this_sym, flags);
2302 if (ret) {
2303 char err[256];
2304 regerror(ret, &preg, err, sizeof(err));
2305 err("regcomp of %s failed: %s", this_sym, err);
2306 }
2307 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
2308 }
2309 }
2310 /* flatten arrays for display */
2311 find_sym = array_flatten_str(find_sym_arr);
2312 find_lib = array_flatten_str(find_lib_arr);
2313 find_section = array_flatten_str(find_section_arr);
1272 /* let the format option override all other options */ 2314 /* let the format option override all other options */
1273 if (out_format) { 2315 if (out_format) {
1274 show_pax = show_phdr = show_textrel = show_rpath = \ 2316 show_pax = show_phdr = show_textrel = show_rpath = \
1275 show_needed = show_interp = show_bind = show_soname = \ 2317 show_needed = show_interp = show_bind = show_soname = \
1276 show_textrels = 0; 2318 show_textrels = show_perms = show_endian = show_size = \
2319 show_osabi = show_eabi = 0;
1277 for (i = 0; out_format[i]; ++i) { 2320 for (i = 0; out_format[i]; ++i) {
1278 if (!IS_MODIFIER(out_format[i])) continue; 2321 if (!IS_MODIFIER(out_format[i])) continue;
1279 2322
1280 switch (out_format[++i]) { 2323 switch (out_format[++i]) {
2324 case '+': break;
1281 case '%': break; 2325 case '%': break;
1282 case '#': break; 2326 case '#': break;
1283 case 'F': break; 2327 case 'F': break;
1284 case 'p': break; 2328 case 'p': break;
1285 case 'f': break; 2329 case 'f': break;
2330 case 'k': break;
1286 case 's': break; 2331 case 's': break;
1287 case 'N': break; 2332 case 'N': break;
1288 case 'o': break; 2333 case 'o': break;
2334 case 'a': break;
2335 case 'M': break;
2336 case 'Z': show_size = 1; break;
2337 case 'D': show_endian = 1; break;
2338 case 'I': show_osabi = 1; break;
2339 case 'Y': show_eabi = 1; break;
2340 case 'O': show_perms = 1; break;
1289 case 'x': show_pax = 1; break; 2341 case 'x': show_pax = 1; break;
1290 case 'e': show_phdr = 1; break; 2342 case 'e': show_phdr = 1; break;
1291 case 't': show_textrel = 1; break; 2343 case 't': show_textrel = 1; break;
1292 case 'r': show_rpath = 1; break; 2344 case 'r': show_rpath = 1; break;
1293 case 'n': show_needed = 1; break; 2345 case 'n': show_needed = 1; break;
1294 case 'i': show_interp = 1; break; 2346 case 'i': show_interp = 1; break;
1295 case 'b': show_bind = 1; break; 2347 case 'b': show_bind = 1; break;
1296 case 'S': show_soname = 1; break; 2348 case 'S': show_soname = 1; break;
1297 case 'T': show_textrels = 1; break; 2349 case 'T': show_textrels = 1; break;
1298 default: 2350 default:
1299 err("Invalid format specifier '%c' (byte %i)", 2351 err("invalid format specifier '%c' (byte %i)",
1300 out_format[i], i+1); 2352 out_format[i], i+1);
1301 } 2353 }
1302 } 2354 }
1303 2355
1304 /* construct our default format */ 2356 /* construct our default format */
1305 } else { 2357 } else {
1306 size_t fmt_len = 30; 2358 size_t fmt_len = 30;
1307 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2359 out_format = xmalloc(sizeof(char) * fmt_len);
2360 *out_format = '\0';
1308 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2361 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1309 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2362 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2363 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2364 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2365 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2366 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2367 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1310 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2368 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1311 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2369 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1312 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2370 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1313 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2371 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1314 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2372 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1315 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2373 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1316 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2374 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1317 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2375 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1318 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2376 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2377 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1319 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2378 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1320 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2379 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1321 } 2380 }
1322 if (be_verbose > 2) printf("Format: %s\n", out_format); 2381 if (be_verbose > 2) printf("Format: %s\n", out_format);
1323 2382
1324 /* now lets actually do the scanning */ 2383 /* now lets actually do the scanning */
1325 if (scan_ldpath || (show_rpath && be_quiet)) 2384 if (load_cache_config)
1326 load_ld_so_conf(); 2385 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1327 if (scan_ldpath) scanelf_ldpath(); 2386 if (scan_ldpath) scanelf_ldpath();
1328 if (scan_envpath) scanelf_envpath(); 2387 if (scan_envpath) scanelf_envpath();
2388 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2389 from_file = "-";
1329 if (from_file) { 2390 if (from_file) {
1330 scanelf_from_file(from_file); 2391 scanelf_from_file(from_file);
1331 free(from_file);
1332 from_file = *argv; 2392 from_file = *argv;
1333 } 2393 }
1334 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2394 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1335 err("Nothing to scan !?"); 2395 err("Nothing to scan !?");
1336 while (optind < argc) { 2396 while (optind < argc) {
1337 search_path = argv[optind++]; 2397 search_path = argv[optind++];
1338 scanelf_dir(search_path); 2398 ret = scanelf_dir(search_path);
1339 } 2399 }
1340 2400
2401#ifdef __PAX_UTILS_CLEANUP
1341 /* clean up */ 2402 /* clean up */
1342 if (versioned_symname) free(versioned_symname);
1343 for (i = 0; ldpaths[i]; ++i)
1344 free(ldpaths[i]); 2403 xarrayfree(ldpaths);
2404 xarrayfree(find_sym_arr);
2405 xarrayfree(find_lib_arr);
2406 xarrayfree(find_section_arr);
2407 free(find_sym);
2408 free(find_lib);
2409 free(find_section);
2410 {
2411 size_t n;
2412 regex_t *preg;
2413 array_for_each(find_sym_regex_arr, n, preg)
2414 regfree(preg);
2415 xarrayfree(find_sym_regex_arr);
2416 }
1345 2417
1346 if (ldcache != 0) 2418 if (ldcache != 0)
1347 munmap(ldcache, ldcache_size); 2419 munmap(ldcache, ldcache_size);
1348} 2420#endif
1349 2421
1350
1351
1352/* utility funcs */
1353static char *xstrdup(const char *s)
1354{
1355 char *ret = strdup(s);
1356 if (!ret) err("Could not strdup(): %s", strerror(errno));
1357 return ret; 2422 return ret;
1358} 2423}
1359static void *xmalloc(size_t size)
1360{
1361 void *ret = malloc(size);
1362 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1363 return ret;
1364}
1365static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1366{
1367 size_t new_len;
1368 2424
1369 new_len = strlen(*dst) + strlen(src); 2425static char **get_split_env(const char *envvar)
1370 if (*curr_len <= new_len) {
1371 *curr_len = new_len + (*curr_len / 2);
1372 *dst = realloc(*dst, *curr_len);
1373 if (!*dst)
1374 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1375 }
1376
1377 if (n)
1378 strncat(*dst, src, n);
1379 else
1380 strcat(*dst, src);
1381}
1382static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1383{ 2426{
1384 static char my_app[2]; 2427 const char *delims = " \t\n";
1385 my_app[0] = append; 2428 char **envvals = NULL;
1386 my_app[1] = '\0'; 2429 char *env, *s;
1387 xstrcat(dst, my_app, curr_len); 2430 int nentry;
1388}
1389 2431
2432 if ((env = getenv(envvar)) == NULL)
2433 return NULL;
1390 2434
2435 env = xstrdup(env);
2436 if (env == NULL)
2437 return NULL;
2438
2439 s = strtok(env, delims);
2440 if (s == NULL) {
2441 free(env);
2442 return NULL;
2443 }
2444
2445 nentry = 0;
2446 while (s != NULL) {
2447 ++nentry;
2448 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2449 envvals[nentry-1] = s;
2450 s = strtok(NULL, delims);
2451 }
2452 envvals[nentry] = NULL;
2453
2454 /* don't want to free(env) as it contains the memory that backs
2455 * the envvals array of strings */
2456 return envvals;
2457}
2458
2459static void parseenv(void)
2460{
2461 color_init(false);
2462 qa_textrels = get_split_env("QA_TEXTRELS");
2463 qa_execstack = get_split_env("QA_EXECSTACK");
2464 qa_wx_load = get_split_env("QA_WX_LOAD");
2465}
2466
2467#ifdef __PAX_UTILS_CLEANUP
2468static void cleanup(void)
2469{
2470 free(out_format);
2471 free(qa_textrels);
2472 free(qa_execstack);
2473 free(qa_wx_load);
2474}
2475#endif
1391 2476
1392int main(int argc, char *argv[]) 2477int main(int argc, char *argv[])
1393{ 2478{
2479 int ret;
1394 if (argc < 2) 2480 if (argc < 2)
1395 usage(EXIT_FAILURE); 2481 usage(EXIT_FAILURE);
2482 parseenv();
1396 parseargs(argc, argv); 2483 ret = parseargs(argc, argv);
1397 fclose(stdout); 2484 fclose(stdout);
1398#ifdef __BOUNDS_CHECKING_ON 2485#ifdef __PAX_UTILS_CLEANUP
1399 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2486 cleanup();
2487 warn("The calls to add/delete heap should be off:\n"
2488 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2489 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1400#endif 2490#endif
1401 return EXIT_SUCCESS; 2491 return ret;
1402} 2492}
2493
2494/* Match filename against entries in matchlist, return TRUE
2495 * if the file is listed */
2496static int file_matches_list(const char *filename, char **matchlist)
2497{
2498 char **file;
2499 char *match;
2500 char buf[__PAX_UTILS_PATH_MAX];
2501
2502 if (matchlist == NULL)
2503 return 0;
2504
2505 for (file = matchlist; *file != NULL; file++) {
2506 if (search_path) {
2507 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2508 match = buf;
2509 } else {
2510 match = *file;
2511 }
2512 if (fnmatch(match, filename, 0) == 0)
2513 return 1;
2514 }
2515 return 0;
2516}

Legend:
Removed from v.1.96  
changed lines
  Added in v.1.265

  ViewVC Help
Powered by ViewVC 1.1.20