/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.98 Revision 1.257
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.98 2006/01/05 03:12:07 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.257 2013/04/10 22:27:20 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.257 2013/04/10 22:27:20 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.98 2006/01/05 03:12:07 vapier Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
21static void scanelf_dir(const char *path);
22static void scanelf_ldpath();
23static void scanelf_envpath();
24static void usage(int status);
25static void parseargs(int argc, char *argv[]);
26static char *xstrdup(const char *s);
27static void *xmalloc(size_t size);
28static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
29#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
30static inline void xchrcat(char **dst, const char append, size_t *curr_len);
31 19
32/* variables to control behavior */ 20/* variables to control behavior */
33static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
34static char scan_ldpath = 0; 23static char scan_ldpath = 0;
35static char scan_envpath = 0; 24static char scan_envpath = 0;
36static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
37static char dir_recurse = 0; 27static char dir_recurse = 0;
38static char dir_crossmount = 1; 28static char dir_crossmount = 1;
39static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
40static char show_phdr = 0; 32static char show_phdr = 0;
41static char show_textrel = 0; 33static char show_textrel = 0;
42static char show_rpath = 0; 34static char show_rpath = 0;
43static char show_needed = 0; 35static char show_needed = 0;
44static char show_interp = 0; 36static char show_interp = 0;
45static char show_bind = 0; 37static char show_bind = 0;
46static char show_soname = 0; 38static char show_soname = 0;
47static char show_textrels = 0; 39static char show_textrels = 0;
48static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
49static char be_quiet = 0; 44static char be_quiet = 0;
50static char be_verbose = 0; 45static char be_verbose = 0;
51static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
52static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
53static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
54static char *out_format = NULL; 55static char *out_format = NULL;
55static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
56static char gmatch = 0; 58static char g_match = 0;
57static char printcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
58 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
59 66
60caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
61size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
62 72
73static int has_objdump = 0;
74
75/* find the path to a file by name */
76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
80
81 path = getenv("PATH");
82 if (!path)
83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
63/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
64static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
65{ 125{
66 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
67#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
68 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
69 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
70 /* debug sections */ \ 144 Elf ## B ## _Shdr *estrtab = strtab; \
71 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
72 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 146 Elf ## B ## _Shdr *edynstr = dynstr; \
73 /* runtime sections */ \ 147 \
74 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
75 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
76 if (symtab && dynsym) { \ 152 if (symtab && dynsym) \
77 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
78 } else { \ 154 else \
79 *sym = (void*)(symtab ? symtab : dynsym); \ 155 *sym = symtab ? symtab : dynsym; \
80 } \ 156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
81 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
82 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
83 } else { \ 163 else \
84 *tab = (void*)(strtab ? strtab : dynstr); \ 164 *str = strtab ? strtab : dynstr; \
85 } \
86 } 165 }
87 GET_SYMTABS(32) 166 GET_SYMTABS(32)
88 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
89} 259}
260
90static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
91{ 262{
92 static char ret[7]; 263 static char ret[7];
93 unsigned long i, shown; 264 unsigned long i, shown;
94 265
103 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 274 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
104 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 275 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
105 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 276 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
106 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 277 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
107 continue; \ 278 continue; \
108 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 279 if (fix_elf && setpax) { \
280 /* set the paxctl flags */ \
281 ESET(phdr[i].p_flags, setpax); \
282 } \
283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
109 continue; \ 284 continue; \
110 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
111 *found_pax = 1; \ 286 *found_pax = 1; \
112 ++shown; \ 287 ++shown; \
113 break; \ 288 break; \
114 } \ 289 } \
115 } 290 }
116 SHOW_PAX(32) 291 SHOW_PAX(32)
117 SHOW_PAX(64) 292 SHOW_PAX(64)
118 } 293 }
294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
119 301
120 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
121 if (!*ret) { 303 if (!*ret) {
122 static char *paxflags; 304 static char *paxflags;
123 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
136 318
137static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
138{ 320{
139 static char ret[12]; 321 static char ret[12];
140 char *found; 322 char *found;
141 unsigned long i, shown;
142 unsigned char multi_stack, multi_relro, multi_load; 323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
143 324
144 if (!show_phdr) return NULL; 325 if (!show_phdr) return NULL;
145 326
146 memcpy(ret, "--- --- ---\0", 12); 327 memcpy(ret, "--- --- ---\0", 12);
147 328
148 shown = 0; 329 shown = 0;
149 multi_stack = multi_relro = multi_load = 0; 330 multi_stack = multi_relro = multi_load = 0;
150 331
332#define NOTE_GNU_STACK ".note.GNU-stack"
151#define SHOW_PHDR(B) \ 333#define SHOW_PHDR(B) \
152 if (elf->elf_class == ELFCLASS ## B) { \ 334 if (elf->elf_class == ELFCLASS ## B) { \
153 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
154 Elf ## B ## _Off offset; \ 336 Elf ## B ## _Off offset; \
155 uint32_t flags, check_flags; \ 337 uint32_t flags, check_flags; \
156 if (elf->phdr != NULL) { \ 338 if (elf->phdr != NULL) { \
157 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
158 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
159 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
160 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
161 found = found_phdr; \ 346 found = found_phdr; \
162 offset = 0; \ 347 offset = 0; \
163 check_flags = PF_X; \ 348 check_flags = PF_X; \
164 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
350 if (multi_relro++) \
165 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
166 found = found_relro; \ 352 found = found_relro; \
167 offset = 4; \ 353 offset = 4; \
168 check_flags = PF_X; \ 354 check_flags = PF_X; \
169 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
170 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 356 if (file_matches_list(elf->filename, qa_wx_load)) \
357 continue; \
171 found = found_load; \ 358 found = found_load; \
172 offset = 8; \ 359 offset = 8; \
173 check_flags = PF_W|PF_X; \ 360 check_flags = PF_W|PF_X; \
174 } else \ 361 } else \
175 continue; \ 362 continue; \
176 flags = EGET(phdr[i].p_flags); \ 363 flags = EGET(phdr[i].p_flags); \
177 if (be_quiet && ((flags & check_flags) != check_flags)) \ 364 if (be_quiet && ((flags & check_flags) != check_flags)) \
178 continue; \ 365 continue; \
366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
368 ret[3] = ret[7] = '!'; \
369 flags = EGET(phdr[i].p_flags); \
370 } \
179 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
180 *found = 1; \ 372 *found = 1; \
181 ++shown; \ 373 ++shown; \
182 } \ 374 } \
183 } else if (elf->shdr != NULL) { \ 375 } else if (elf->shdr != NULL) { \
184 /* no program headers which means this is prob an object file */ \ 376 /* no program headers which means this is prob an object file */ \
185 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
186 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
379 char *str; \
380 if ((void*)strtbl > elf->data_end) \
381 goto skip_this_shdr##B; \
187 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 382 check_flags = SHF_WRITE|SHF_EXECINSTR; \
188 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 383 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
189 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 384 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
190 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 385 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
191 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 386 str = elf->data + offset; \
387 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
388 if (!strcmp(str, NOTE_GNU_STACK)) { \
192 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 389 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
193 flags = EGET(shdr[i].sh_flags); \ 390 flags = EGET(shdr[i].sh_flags); \
194 if (be_quiet && ((flags & check_flags) != check_flags)) \ 391 if (be_quiet && ((flags & check_flags) != check_flags)) \
195 continue; \ 392 continue; \
196 ++*found_phdr; \ 393 ++*found_phdr; \
200 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 397 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
201 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 398 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
202 break; \ 399 break; \
203 } \ 400 } \
204 } \ 401 } \
402 skip_this_shdr##B: \
205 if (!multi_stack) { \ 403 if (!multi_stack) { \
404 if (file_matches_list(elf->filename, qa_execstack)) \
405 return NULL; \
206 *found_phdr = 1; \ 406 *found_phdr = 1; \
207 shown = 1; \ 407 shown = 1; \
208 memcpy(ret, "!WX", 3); \ 408 memcpy(ret, "!WX", 3); \
209 } \ 409 } \
210 } \ 410 } \
215 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 415 if (be_wewy_wewy_quiet || (be_quiet && !shown))
216 return NULL; 416 return NULL;
217 else 417 else
218 return ret; 418 return ret;
219} 419}
420
421/*
422 * See if this ELF contains a DT_TEXTREL tag in any of its
423 * PT_DYNAMIC sections.
424 */
220static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 425static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
221{ 426{
222 static const char *ret = "TEXTREL"; 427 static const char *ret = "TEXTREL";
223 unsigned long i; 428 unsigned long i;
224 429
225 if (!show_textrel && !show_textrels) return NULL; 430 if (!show_textrel && !show_textrels) return NULL;
431
432 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
226 433
227 if (elf->phdr) { 434 if (elf->phdr) {
228#define SHOW_TEXTREL(B) \ 435#define SHOW_TEXTREL(B) \
229 if (elf->elf_class == ELFCLASS ## B) { \ 436 if (elf->elf_class == ELFCLASS ## B) { \
230 Elf ## B ## _Dyn *dyn; \ 437 Elf ## B ## _Dyn *dyn; \
231 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 438 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
232 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 439 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
233 Elf ## B ## _Off offset; \ 440 Elf ## B ## _Off offset; \
234 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 441 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
235 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 442 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
236 offset = EGET(phdr[i].p_offset); \ 443 offset = EGET(phdr[i].p_offset); \
237 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 444 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
238 dyn = DYN ## B (elf->data + offset); \ 445 dyn = DYN ## B (elf->vdata + offset); \
239 while (EGET(dyn->d_tag) != DT_NULL) { \ 446 while (EGET(dyn->d_tag) != DT_NULL) { \
240 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 447 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
241 *found_textrel = 1; \ 448 *found_textrel = 1; \
242 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 449 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
243 return (be_wewy_wewy_quiet ? NULL : ret); \ 450 return (be_wewy_wewy_quiet ? NULL : ret); \
252 if (be_quiet || be_wewy_wewy_quiet) 459 if (be_quiet || be_wewy_wewy_quiet)
253 return NULL; 460 return NULL;
254 else 461 else
255 return " - "; 462 return " - ";
256} 463}
464
465/*
466 * Scan the .text section to see if there are any relocations in it.
467 * Should rewrite this to check PT_LOAD sections that are marked
468 * Executable rather than the section named '.text'.
469 */
257static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 470static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
258{ 471{
259 unsigned long s, r, rmax; 472 unsigned long s, r, rmax;
260 void *symtab_void, *strtab_void, *text_void; 473 void *symtab_void, *strtab_void, *text_void;
261 474
282 Elf ## B ## _Rela *rela; \ 495 Elf ## B ## _Rela *rela; \
283 /* search the section headers for relocations */ \ 496 /* search the section headers for relocations */ \
284 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 497 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
285 uint32_t sh_type = EGET(shdr[s].sh_type); \ 498 uint32_t sh_type = EGET(shdr[s].sh_type); \
286 if (sh_type == SHT_REL) { \ 499 if (sh_type == SHT_REL) { \
287 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 500 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
288 rela = NULL; \ 501 rela = NULL; \
289 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 502 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
290 } else if (sh_type == SHT_RELA) { \ 503 } else if (sh_type == SHT_RELA) { \
291 rel = NULL; \ 504 rel = NULL; \
292 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 505 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
293 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 506 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
294 } else \ 507 } else \
295 continue; \ 508 continue; \
296 /* now see if any of the relocs are in the .text */ \ 509 /* now see if any of the relocs are in the .text */ \
297 for (r = 0; r < rmax; ++r) { \ 510 for (r = 0; r < rmax; ++r) { \
312 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 525 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
313 if (be_verbose <= 2) continue; \ 526 if (be_verbose <= 2) continue; \
314 } else \ 527 } else \
315 *found_textrels = 1; \ 528 *found_textrels = 1; \
316 /* locate this relocation symbol name */ \ 529 /* locate this relocation symbol name */ \
317 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 530 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
531 if ((void*)sym > elf->data_end) { \
532 warn("%s: corrupt ELF symbol", elf->filename); \
533 continue; \
534 } \
318 sym_max = ELF ## B ## _R_SYM(r_info); \ 535 sym_max = ELF ## B ## _R_SYM(r_info); \
319 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 536 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
320 sym += sym_max; \ 537 sym += sym_max; \
321 else \ 538 else \
322 sym = NULL; \ 539 sym = NULL; \
323 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 540 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
324 /* show the raw details about this reloc */ \ 541 /* show the raw details about this reloc */ \
325 printf(" %s: ", elf->base_filename); \ 542 printf(" %s: ", elf->base_filename); \
326 if (sym && sym->st_name) \ 543 if (sym && sym->st_name) \
327 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 544 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
328 else \ 545 else \
329 printf("(memory/fake?)"); \ 546 printf("(memory/data?)"); \
330 printf(" [0x%lX]", (unsigned long)r_offset); \ 547 printf(" [0x%lX]", (unsigned long)r_offset); \
331 /* now try to find the closest symbol that this rel is probably in */ \ 548 /* now try to find the closest symbol that this rel is probably in */ \
332 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 549 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
333 func = NULL; \ 550 func = NULL; \
334 offset_tmp = 0; \ 551 offset_tmp = 0; \
335 while (sym_max--) { \ 552 while (sym_max--) { \
336 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 553 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
337 func = sym; \ 554 func = sym; \
338 offset_tmp = EGET(sym->st_value); \ 555 offset_tmp = EGET(sym->st_value); \
339 } \ 556 } \
340 ++sym; \ 557 ++sym; \
341 } \ 558 } \
342 printf(" in "); \ 559 printf(" in "); \
343 if (func && func->st_name) \ 560 if (func && func->st_name) { \
344 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 561 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
562 if (r_offset > EGET(func->st_size)) \
563 printf("(optimized out: previous %s)", func_name); \
345 else \ 564 else \
346 printf("(NULL: fake?)"); \ 565 printf("%s", func_name); \
566 } else \
567 printf("(optimized out)"); \
347 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 568 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
569 if (be_verbose && has_objdump) { \
570 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
571 char *sysbuf; \
572 size_t syslen; \
573 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
574 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
575 sysbuf = xmalloc(syslen); \
576 if (end_addr < r_offset) \
577 /* not uncommon when things are optimized out */ \
578 end_addr = r_offset + 0x100; \
579 snprintf(sysbuf, syslen, sysfmt, \
580 (unsigned long)offset_tmp, \
581 (unsigned long)end_addr, \
582 elf->filename, \
583 (unsigned long)r_offset); \
584 fflush(stdout); \
585 if (system(sysbuf)) {/* don't care */} \
586 fflush(stdout); \
587 free(sysbuf); \
588 } \
348 } \ 589 } \
349 } } 590 } }
350 SHOW_TEXTRELS(32) 591 SHOW_TEXTRELS(32)
351 SHOW_TEXTRELS(64) 592 SHOW_TEXTRELS(64)
352 } 593 }
354 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 595 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
355 596
356 return NULL; 597 return NULL;
357} 598}
358 599
359static void rpath_security_checks(elfobj *, char *);
360static void rpath_security_checks(elfobj *elf, char *item) { 600static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
601{
361 struct stat st; 602 struct stat st;
362 switch (*item) { 603 switch (*item) {
363 case '/': break; 604 case '/': break;
364 case '.': 605 case '.':
365 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 606 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
366 break; 607 break;
608 case ':':
367 case '\0': 609 case '\0':
368 warnf("Security problem NULL RPATH in %s", elf->filename); 610 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
369 break; 611 break;
370 case '$': 612 case '$':
371 if (fstat(elf->fd, &st) != -1) 613 if (fstat(elf->fd, &st) != -1)
372 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 614 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
373 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 615 warnf("Security problem with %s='%s' in %s with mode set of %o",
374 item, elf->filename, st.st_mode & 07777); 616 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
375 break; 617 break;
376 default: 618 default:
377 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 619 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
378 break; 620 break;
379 } 621 }
380} 622}
381static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 623static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
382{ 624{
383 unsigned long i, s; 625 unsigned long i;
384 char *rpath, *runpath, **r; 626 char *rpath, *runpath, **r;
385 void *strtbl_void; 627 void *strtbl_void;
386 628
387 if (!show_rpath) return; 629 if (!show_rpath) return;
388 630
399 Elf ## B ## _Off offset; \ 641 Elf ## B ## _Off offset; \
400 Elf ## B ## _Xword word; \ 642 Elf ## B ## _Xword word; \
401 /* Scan all the program headers */ \ 643 /* Scan all the program headers */ \
402 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 644 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
403 /* Just scan dynamic headers */ \ 645 /* Just scan dynamic headers */ \
404 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 646 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
405 offset = EGET(phdr[i].p_offset); \ 647 offset = EGET(phdr[i].p_offset); \
406 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 648 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
407 /* Just scan dynamic RPATH/RUNPATH headers */ \ 649 /* Just scan dynamic RPATH/RUNPATH headers */ \
408 dyn = DYN ## B (elf->data + offset); \ 650 dyn = DYN ## B (elf->vdata + offset); \
409 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 651 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
410 if (word == DT_RPATH) { \ 652 if (word == DT_RPATH) { \
411 r = &rpath; \ 653 r = &rpath; \
412 } else if (word == DT_RUNPATH) { \ 654 } else if (word == DT_RUNPATH) { \
413 r = &runpath; \ 655 r = &runpath; \
417 } \ 659 } \
418 /* Verify the memory is somewhat sane */ \ 660 /* Verify the memory is somewhat sane */ \
419 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 661 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
420 if (offset < (Elf ## B ## _Off)elf->len) { \ 662 if (offset < (Elf ## B ## _Off)elf->len) { \
421 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 663 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
422 *r = (char*)(elf->data + offset); \ 664 *r = elf->data + offset; \
665 /* cache the length in case we need to nuke this section later on */ \
666 if (fix_elf) \
667 offset = strlen(*r); \
423 /* If quiet, don't output paths in ld.so.conf */ \ 668 /* If quiet, don't output paths in ld.so.conf */ \
424 if (be_quiet) { \ 669 if (be_quiet) { \
425 size_t len; \ 670 size_t len; \
426 char *start, *end; \ 671 char *start, *end; \
427 /* note that we only 'chop' off leading known paths. */ \ 672 /* note that we only 'chop' off leading known paths. */ \
428 /* since *r is read-only memory, we can only move the ptr forward. */ \ 673 /* since *r is read-only memory, we can only move the ptr forward. */ \
429 start = *r; \ 674 start = *r; \
430 /* scan each path in : delimited list */ \ 675 /* scan each path in : delimited list */ \
431 while (start) { \ 676 while (start) { \
432 rpath_security_checks(elf, start); \ 677 rpath_security_checks(elf, start, get_elfdtype(word)); \
433 end = strchr(start, ':'); \ 678 end = strchr(start, ':'); \
434 len = (end ? abs(end - start) : strlen(start)); \ 679 len = (end ? abs(end - start) : strlen(start)); \
435 for (s = 0; ldpaths[s]; ++s) { \ 680 if (use_ldcache) { \
681 size_t n; \
682 const char *ldpath; \
683 array_for_each(ldpaths, n, ldpath) \
436 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 684 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
437 *r = (end ? end + 1 : NULL); \ 685 *r = end; \
686 /* corner case ... if RPATH reads "/usr/lib:", we want \
687 * to show ':' rather than '' */ \
688 if (end && end[1] != '\0') \
689 (*r)++; \
438 break; \ 690 break; \
439 } \ 691 } \
440 } \ 692 } \
441 if (!*r || !ldpaths[s] || !end) \ 693 if (!*r || !end) \
442 start = NULL; \ 694 break; \
443 else \ 695 else \
444 start = start + len + 1; \ 696 start = start + len + 1; \
445 } \ 697 } \
446 } \ 698 } \
699 if (*r) { \
700 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
701 /* just nuke it */ \
702 nuke_it##B: \
703 memset(*r, 0x00, offset); \
704 *r = NULL; \
705 ESET(dyn->d_tag, DT_DEBUG); \
706 ESET(dyn->d_un.d_ptr, 0); \
707 } else if (fix_elf) { \
708 /* try to clean "bad" paths */ \
709 size_t len, tmpdir_len; \
710 char *start, *end; \
711 const char *tmpdir; \
712 start = *r; \
713 tmpdir = (getenv("TMPDIR") ? : "."); \
714 tmpdir_len = strlen(tmpdir); \
715 while (1) { \
716 end = strchr(start, ':'); \
717 if (start == end) { \
718 eat_this_path##B: \
719 len = strlen(end); \
720 memmove(start, end+1, len); \
721 start[len-1] = '\0'; \
722 end = start - 1; \
723 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
724 if (!end) { \
725 if (start == *r) \
726 goto nuke_it##B; \
727 *--start = '\0'; \
728 } else \
729 goto eat_this_path##B; \
730 } \
731 if (!end) \
732 break; \
733 start = end + 1; \
734 } \
735 if (**r == '\0') \
736 goto nuke_it##B; \
737 } \
738 if (*r) \
447 if (*r) *found_rpath = 1; \ 739 *found_rpath = 1; \
740 } \
448 } \ 741 } \
449 ++dyn; \ 742 ++dyn; \
450 } \ 743 } \
451 } } 744 } }
452 SHOW_RPATH(32) 745 SHOW_RPATH(32)
470 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 763 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
471 else if (!be_quiet) 764 else if (!be_quiet)
472 xstrcat(ret, " - ", ret_len); 765 xstrcat(ret, " - ", ret_len);
473} 766}
474 767
768/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
475#define LDSO_CACHE_MAGIC "ld.so-" 769#define LDSO_CACHE_MAGIC "ld.so-"
476#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 770#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
477#define LDSO_CACHE_VER "1.7.0" 771#define LDSO_CACHE_VER "1.7.0"
478#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 772#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
479#define FLAG_ANY -1 773#define FLAG_ANY -1
488#define FLAG_X8664_LIB64 0x0300 782#define FLAG_X8664_LIB64 0x0300
489#define FLAG_S390_LIB64 0x0400 783#define FLAG_S390_LIB64 0x0400
490#define FLAG_POWERPC_LIB64 0x0500 784#define FLAG_POWERPC_LIB64 0x0500
491#define FLAG_MIPS64_LIBN32 0x0600 785#define FLAG_MIPS64_LIBN32 0x0600
492#define FLAG_MIPS64_LIBN64 0x0700 786#define FLAG_MIPS64_LIBN64 0x0700
787#define FLAG_X8664_LIBX32 0x0800
788#define FLAG_ARM_LIBHF 0x0900
789#define FLAG_AARCH64_LIB64 0x0a00
493 790
494static char *lookup_cache_lib(elfobj *, char *); 791#if defined(__GLIBC__) || defined(__UCLIBC__)
792
495static char *lookup_cache_lib(elfobj *elf, char *fname) 793static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 794{
497 int fd = 0; 795 int fd;
498 char *strs; 796 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 797 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 798 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 799 struct stat st;
502 800
503 typedef struct { 801 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 802 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 803 char version[LDSO_CACHE_VER_LEN];
515 libentry_t *libent; 813 libentry_t *libent;
516 814
517 if (fname == NULL) 815 if (fname == NULL)
518 return NULL; 816 return NULL;
519 817
520 if (ldcache == 0) { 818 if (ldcache == NULL) {
521 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 819 if (fstatat(root_fd, cachefile, &st, 0))
820 return NULL;
821
822 fd = openat(root_fd, cachefile, O_RDONLY);
823 if (fd == -1)
522 return NULL; 824 return NULL;
523 825
524 /* cache these values so we only map/unmap the cache file once */ 826 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 827 ldcache_size = st.st_size;
526 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 828 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
527
528 close(fd); 829 close(fd);
529 830
530 if (ldcache == (caddr_t)-1) 831 if (ldcache == MAP_FAILED) {
832 ldcache = NULL;
531 return NULL; 833 return NULL;
834 }
532 835
533 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 836 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
837 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
838 {
839 munmap(ldcache, ldcache_size);
840 ldcache = NULL;
534 return NULL; 841 return NULL;
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 842 }
843 } else
844 header = ldcache;
538 845
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 846 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 847 strs = (char *) &libent[header->nlibs];
542 848
543 for (fd = 0; fd < header->nlibs; fd++) { 849 for (fd = 0; fd < header->nlibs; ++fd) {
544 /* this should be more fine grained, but for now we assume that 850 /* This should be more fine grained, but for now we assume that
545 * diff arches will not be cached together. and we ignore the 851 * diff arches will not be cached together, and we ignore the
546 * the different multilib mips cases. */ 852 * the different multilib mips cases.
853 */
547 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 854 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
548 continue; 855 continue;
549 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 856 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
550 continue; 857 continue;
551 858
552 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 859 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
553 continue; 860 continue;
861
862 /* Return first hit because that is how the ldso rolls */
554 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 863 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
864 break;
555 } 865 }
866
556 return buf; 867 return buf;
557} 868}
558 869
870#elif defined(__NetBSD__)
871static char *lookup_cache_lib(elfobj *elf, const char *fname)
872{
873 static char buf[__PAX_UTILS_PATH_MAX] = "";
874 static struct stat st;
875 size_t n;
876 char *ldpath;
877
878 array_for_each(ldpath, n, ldpath) {
879 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
880 continue; /* if the pathname is too long, or something went wrong, ignore */
881
882 if (stat(buf, &st) != 0)
883 continue; /* if the lib doesn't exist in *ldpath, look further */
884
885 /* NetBSD doesn't actually do sanity checks, it just loads the file
886 * and if that doesn't work, continues looking in other directories.
887 * This cannot easily be safely emulated, unfortunately. For now,
888 * just assume that if it exists, it's a valid library. */
889
890 return buf;
891 }
892
893 /* not found in any path */
894 return NULL;
895}
896#else
897#ifdef __ELF__
898#warning Cache support not implemented for your target
899#endif
900static char *lookup_cache_lib(elfobj *elf, const char *fname)
901{
902 return NULL;
903}
904#endif
905
906static char *lookup_config_lib(const char *fname)
907{
908 static char buf[__PAX_UTILS_PATH_MAX] = "";
909 const char *ldpath;
910 size_t n;
911
912 array_for_each(ldpaths, n, ldpath) {
913 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
914 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
915 return buf;
916 }
917
918 return NULL;
919}
559 920
560static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 921static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
561{ 922{
562 unsigned long i; 923 unsigned long i;
563 char *needed; 924 char *needed;
564 void *strtbl_void; 925 void *strtbl_void;
565 char *p; 926 char *p;
566 927
928 /*
929 * -n -> op==0 -> print all
930 * -N -> op==1 -> print requested
931 */
567 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 932 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
933 return NULL;
568 934
569 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 935 strtbl_void = elf_findsecbyname(elf, ".dynstr");
570 936
571 if (elf->phdr && strtbl_void) { 937 if (elf->phdr && strtbl_void) {
572#define SHOW_NEEDED(B) \ 938#define SHOW_NEEDED(B) \
574 Elf ## B ## _Dyn *dyn; \ 940 Elf ## B ## _Dyn *dyn; \
575 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 941 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
576 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 942 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
577 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 943 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
578 Elf ## B ## _Off offset; \ 944 Elf ## B ## _Off offset; \
945 size_t matched = 0; \
946 /* Walk all the program headers to find the PT_DYNAMIC */ \
579 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 947 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
580 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 948 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
949 continue; \
581 offset = EGET(phdr[i].p_offset); \ 950 offset = EGET(phdr[i].p_offset); \
582 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 951 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
952 continue; \
953 /* Walk all the dynamic tags to find NEEDED entries */ \
583 dyn = DYN ## B (elf->data + offset); \ 954 dyn = DYN ## B (elf->vdata + offset); \
584 while (EGET(dyn->d_tag) != DT_NULL) { \ 955 while (EGET(dyn->d_tag) != DT_NULL) { \
585 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 956 if (EGET(dyn->d_tag) == DT_NEEDED) { \
586 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 957 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
587 if (offset >= (Elf ## B ## _Off)elf->len) { \ 958 if (offset >= (Elf ## B ## _Off)elf->len) { \
588 ++dyn; \ 959 ++dyn; \
589 continue; \ 960 continue; \
590 } \ 961 } \
591 needed = (char*)(elf->data + offset); \ 962 needed = elf->data + offset; \
592 if (op == 0) { \ 963 if (op == 0) { \
964 /* -n -> print all entries */ \
593 if (!be_wewy_wewy_quiet) { \ 965 if (!be_wewy_wewy_quiet) { \
594 if (*found_needed) xchrcat(ret, ',', ret_len); \ 966 if (*found_needed) xchrcat(ret, ',', ret_len); \
595 if (printcache) \ 967 if (use_ldpath) { \
968 if ((p = lookup_config_lib(needed)) != NULL) \
969 needed = p; \
970 } else if (use_ldcache) { \
596 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 971 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
597 needed = p; \ 972 needed = p; \
973 } \
598 xstrcat(ret, needed, ret_len); \ 974 xstrcat(ret, needed, ret_len); \
599 } \ 975 } \
600 *found_needed = 1; \ 976 *found_needed = 1; \
601 } else { \ 977 } else { \
602 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 978 /* -N -> print matching entries */ \
979 size_t n; \
980 const char *find_lib_name; \
981 \
982 array_for_each(find_lib_arr, n, find_lib_name) { \
983 int invert = 1; \
984 if (find_lib_name[0] == '!') \
985 invert = 0, ++find_lib_name; \
986 if (!strcmp(find_lib_name, needed) == invert) \
987 ++matched; \
988 } \
989 \
990 if (matched == array_cnt(find_lib_arr)) { \
603 *found_lib = 1; \ 991 *found_lib = 1; \
604 return (be_wewy_wewy_quiet ? NULL : needed); \ 992 return (be_wewy_wewy_quiet ? NULL : find_lib); \
605 } \ 993 } \
606 } \ 994 } \
607 } \ 995 } \
608 ++dyn; \ 996 ++dyn; \
609 } \ 997 } \
631 *found_interp = 1; \ 1019 *found_interp = 1; \
632 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1020 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
633 } 1021 }
634 SHOW_INTERP(32) 1022 SHOW_INTERP(32)
635 SHOW_INTERP(64) 1023 SHOW_INTERP(64)
1024 } else {
1025 /* Walk all the program headers to find the PT_INTERP */
1026#define SHOW_PT_INTERP(B) \
1027 if (elf->elf_class == ELFCLASS ## B) { \
1028 unsigned long i; \
1029 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1030 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1031 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1032 if (EGET(phdr[i].p_type) != PT_INTERP) \
1033 continue; \
1034 *found_interp = 1; \
1035 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1036 } \
636 } 1037 }
1038 SHOW_PT_INTERP(32)
1039 SHOW_PT_INTERP(64)
1040 }
1041
637 return NULL; 1042 return NULL;
638} 1043}
639static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1044static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
640{ 1045{
641 unsigned long i; 1046 unsigned long i;
642 struct stat s; 1047 struct stat s;
1048 char dynamic = 0;
643 1049
644 if (!show_bind) return NULL; 1050 if (!show_bind) return NULL;
645 if (!elf->phdr) return NULL; 1051 if (!elf->phdr) return NULL;
646 1052
647#define SHOW_BIND(B) \ 1053#define SHOW_BIND(B) \
649 Elf ## B ## _Dyn *dyn; \ 1055 Elf ## B ## _Dyn *dyn; \
650 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1056 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
651 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1057 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
652 Elf ## B ## _Off offset; \ 1058 Elf ## B ## _Off offset; \
653 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1059 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
654 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1060 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1061 dynamic = 1; \
655 offset = EGET(phdr[i].p_offset); \ 1062 offset = EGET(phdr[i].p_offset); \
656 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1063 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
657 dyn = DYN ## B (elf->data + offset); \ 1064 dyn = DYN ## B (elf->vdata + offset); \
658 while (EGET(dyn->d_tag) != DT_NULL) { \ 1065 while (EGET(dyn->d_tag) != DT_NULL) { \
659 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1066 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
660 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1067 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
661 { \ 1068 { \
662 if (be_quiet) return NULL; \ 1069 if (be_quiet) return NULL; \
670 SHOW_BIND(32) 1077 SHOW_BIND(32)
671 SHOW_BIND(64) 1078 SHOW_BIND(64)
672 1079
673 if (be_wewy_wewy_quiet) return NULL; 1080 if (be_wewy_wewy_quiet) return NULL;
674 1081
1082 /* don't output anything if quiet mode and the ELF is static or not setuid */
675 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1083 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
676 return NULL; 1084 return NULL;
677 } else { 1085 } else {
678 *found_bind = 1; 1086 *found_bind = 1;
679 return (char *) "LAZY"; 1087 return dynamic ? "LAZY" : "STATIC";
680 } 1088 }
681} 1089}
682static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1090static char *scanelf_file_soname(elfobj *elf, char *found_soname)
683{ 1091{
684 unsigned long i; 1092 unsigned long i;
696 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1104 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
697 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1105 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
698 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1106 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
699 Elf ## B ## _Off offset; \ 1107 Elf ## B ## _Off offset; \
700 /* only look for soname in shared objects */ \ 1108 /* only look for soname in shared objects */ \
701 if (ehdr->e_type != ET_DYN) \ 1109 if (EGET(ehdr->e_type) != ET_DYN) \
702 return NULL; \ 1110 return NULL; \
703 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1111 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
704 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1112 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
705 offset = EGET(phdr[i].p_offset); \ 1113 offset = EGET(phdr[i].p_offset); \
706 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1114 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
707 dyn = DYN ## B (elf->data + offset); \ 1115 dyn = DYN ## B (elf->vdata + offset); \
708 while (EGET(dyn->d_tag) != DT_NULL) { \ 1116 while (EGET(dyn->d_tag) != DT_NULL) { \
709 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1117 if (EGET(dyn->d_tag) == DT_SONAME) { \
710 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1118 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
711 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1119 if (offset >= (Elf ## B ## _Off)elf->len) { \
712 ++dyn; \ 1120 ++dyn; \
713 continue; \ 1121 continue; \
714 } \ 1122 } \
715 soname = (char*)(elf->data + offset); \ 1123 soname = elf->data + offset; \
716 *found_soname = 1; \ 1124 *found_soname = 1; \
717 return (be_wewy_wewy_quiet ? NULL : soname); \ 1125 return (be_wewy_wewy_quiet ? NULL : soname); \
718 } \ 1126 } \
719 ++dyn; \ 1127 ++dyn; \
720 } \ 1128 } \
723 SHOW_SONAME(64) 1131 SHOW_SONAME(64)
724 } 1132 }
725 1133
726 return NULL; 1134 return NULL;
727} 1135}
1136
1137/*
1138 * We support the symbol form:
1139 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1140 * If the symbol name is empty, then all symbols are matched.
1141 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1142 * Do not rely on this output format at all.
1143 * Otherwise the symbol name is used to search (either regex or string compare).
1144 * If the first char of the symbol name is a plus ("+"), then only match
1145 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1146 * Putting modifiers in between the percent signs allows for more in depth
1147 * filters. There are groups of modifiers. If you don't specify a member
1148 * of a group, then all types in that group are matched. The current
1149 * groups and their types are:
1150 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1151 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1152 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1153 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1154 * You can search for multiple symbols at once by seperating with a comma (",").
1155 *
1156 * Some examples:
1157 * ELFs with a weak function "foo":
1158 * scanelf -s %wf%foo <ELFs>
1159 * ELFs that define the symbol "main":
1160 * scanelf -s +main <ELFs>
1161 * scanelf -s %d%main <ELFs>
1162 * ELFs that refer to the undefined symbol "brk":
1163 * scanelf -s -brk <ELFs>
1164 * scanelf -s %u%brk <ELFs>
1165 * All global defined objects in an ELF:
1166 * scanelf -s %ogd% <ELF>
1167 */
1168static void
1169scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1170 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1171{
1172 const char *this_sym;
1173 size_t n;
1174
1175 array_for_each(find_sym_arr, n, this_sym) {
1176 bool inc_notype, inc_object, inc_func, inc_file,
1177 inc_local, inc_global, inc_weak,
1178 inc_def, inc_undef, inc_abs, inc_common;
1179
1180 /* symbol selection! */
1181 inc_notype = inc_object = inc_func = inc_file = \
1182 inc_local = inc_global = inc_weak = \
1183 inc_def = inc_undef = inc_abs = inc_common = \
1184 (*this_sym != '%');
1185
1186 /* parse the contents of %...% */
1187 if (!inc_notype) {
1188 while (*(this_sym++)) {
1189 if (*this_sym == '%') {
1190 ++this_sym;
1191 break;
1192 }
1193 switch (*this_sym) {
1194 case 'n': inc_notype = true; break;
1195 case 'o': inc_object = true; break;
1196 case 'f': inc_func = true; break;
1197 case 'F': inc_file = true; break;
1198 case 'l': inc_local = true; break;
1199 case 'g': inc_global = true; break;
1200 case 'w': inc_weak = true; break;
1201 case 'd': inc_def = true; break;
1202 case 'u': inc_undef = true; break;
1203 case 'a': inc_abs = true; break;
1204 case 'c': inc_common = true; break;
1205 default: err("invalid symbol selector '%c'", *this_sym);
1206 }
1207 }
1208
1209 /* If no types are matched, not match all */
1210 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1211 inc_notype = inc_object = inc_func = inc_file = true;
1212 if (!inc_local && !inc_global && !inc_weak)
1213 inc_local = inc_global = inc_weak = true;
1214 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1215 inc_def = inc_undef = inc_abs = inc_common = true;
1216
1217 /* backwards compat for defined/undefined short hand */
1218 } else if (*this_sym == '+') {
1219 inc_undef = false;
1220 ++this_sym;
1221 } else if (*this_sym == '-') {
1222 inc_def = inc_abs = inc_common = false;
1223 ++this_sym;
1224 }
1225
1226 /* filter symbols */
1227 if ((!inc_notype && stt == STT_NOTYPE) || \
1228 (!inc_object && stt == STT_OBJECT) || \
1229 (!inc_func && stt == STT_FUNC ) || \
1230 (!inc_file && stt == STT_FILE ) || \
1231 (!inc_local && stb == STB_LOCAL ) || \
1232 (!inc_global && stb == STB_GLOBAL) || \
1233 (!inc_weak && stb == STB_WEAK ) || \
1234 (!inc_def && shn && shn < SHN_LORESERVE) || \
1235 (!inc_undef && shn == SHN_UNDEF ) || \
1236 (!inc_abs && shn == SHN_ABS ) || \
1237 (!inc_common && shn == SHN_COMMON))
1238 continue;
1239
1240 if (*this_sym == '*') {
1241 /* a "*" symbol gets you debug output */
1242 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1243 ((*found_sym == 0) ? "\n\t" : "\t"),
1244 elf->base_filename,
1245 size,
1246 get_elfstttype(stt),
1247 get_elfstbtype(stb),
1248 get_elfshntype(shn),
1249 symname);
1250 goto matched;
1251
1252 } else {
1253 if (g_match) {
1254 /* regex match the symbol */
1255 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1256 continue;
1257
1258 } else if (*this_sym) {
1259 /* give empty symbols a "pass", else do a normal compare */
1260 const size_t len = strlen(this_sym);
1261 if (!(strncmp(this_sym, symname, len) == 0 &&
1262 /* Accept unversioned symbol names */
1263 (symname[len] == '\0' || symname[len] == '@')))
1264 continue;
1265 }
1266
1267 if (be_semi_verbose) {
1268 char buf[1024];
1269 snprintf(buf, sizeof(buf), "%lX %s %s",
1270 size,
1271 get_elfstttype(stt),
1272 this_sym);
1273 *ret = xstrdup(buf);
1274 } else {
1275 if (*ret) xchrcat(ret, ',', ret_len);
1276 xstrcat(ret, symname, ret_len);
1277 }
1278
1279 goto matched;
1280 }
1281 }
1282
1283 return;
1284
1285 matched:
1286 *found_sym = 1;
1287}
1288
728static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1289static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
729{ 1290{
730 unsigned long i;
731 char *ret; 1291 char *ret;
732 void *symtab_void, *strtab_void; 1292 void *symtab_void, *strtab_void;
733 1293
734 if (!find_sym) return NULL; 1294 if (!find_sym) return NULL;
735 ret = find_sym; 1295 ret = NULL;
736 1296
737 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1297 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
738 1298
739 if (symtab_void && strtab_void) { 1299 if (symtab_void && strtab_void) {
740#define FIND_SYM(B) \ 1300#define FIND_SYM(B) \
741 if (elf->elf_class == ELFCLASS ## B) { \ 1301 if (elf->elf_class == ELFCLASS ## B) { \
742 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1302 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
743 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1303 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
744 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1304 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
745 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1305 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
746 char *symname; \ 1306 char *symname; \
1307 size_t ret_len = 0; \
1308 if (cnt) \
1309 cnt = EGET(symtab->sh_size) / cnt; \
747 for (i = 0; i < cnt; ++i) { \ 1310 for (i = 0; i < cnt; ++i) { \
1311 if ((void*)sym > elf->data_end) { \
1312 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1313 goto break_out; \
1314 } \
748 if (sym->st_name) { \ 1315 if (sym->st_name) { \
1316 /* make sure the symbol name is in acceptable memory range */ \
749 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1317 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
750 if (*find_sym == '*') { \ 1318 if ((void*)symname > elf->data_end) { \
751 printf("%s(%s) %5lX %15s %s\n", \ 1319 warnf("%s: corrupt ELF symbols", elf->filename); \
752 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1320 ++sym; \
753 elf->base_filename, \ 1321 continue; \
754 (unsigned long)sym->st_size, \
755 get_elfstttype(sym->st_info), \
756 symname); \
757 *found_sym = 1; \
758 } else { \
759 char *this_sym, *next_sym; \
760 this_sym = find_sym; \
761 do { \
762 next_sym = strchr(this_sym, ','); \
763 if (next_sym == NULL) \
764 next_sym = this_sym + strlen(this_sym); \
765 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
766 (strcmp(symname, versioned_symname) == 0)) { \
767 ret = this_sym; \
768 (*found_sym)++; \
769 goto break_out; \
770 } \
771 this_sym = next_sym + 1; \
772 } while (*next_sym != '\0'); \
773 } \ 1322 } \
1323 scanelf_match_symname(elf, found_sym, \
1324 &ret, &ret_len, symname, \
1325 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1326 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1327 EGET(sym->st_shndx), \
1328 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1329 EGET(sym->st_size)); \
774 } \ 1330 } \
775 ++sym; \ 1331 ++sym; \
776 } } 1332 } \
1333 }
777 FIND_SYM(32) 1334 FIND_SYM(32)
778 FIND_SYM(64) 1335 FIND_SYM(64)
779 } 1336 }
780 1337
781break_out: 1338break_out:
784 if (*find_sym != '*' && *found_sym) 1341 if (*find_sym != '*' && *found_sym)
785 return ret; 1342 return ret;
786 if (be_quiet) 1343 if (be_quiet)
787 return NULL; 1344 return NULL;
788 else 1345 else
789 return (char *)" - "; 1346 return " - ";
790} 1347}
1348
1349static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1350{
1351 if (!find_section)
1352 return NULL;
1353
1354#define FIND_SECTION(B) \
1355 if (elf->elf_class == ELFCLASS ## B) { \
1356 size_t matched, n; \
1357 int invert; \
1358 const char *section_name; \
1359 Elf ## B ## _Shdr *section; \
1360 \
1361 matched = 0; \
1362 array_for_each(find_section_arr, n, section_name) { \
1363 invert = (*section_name == '!' ? 1 : 0); \
1364 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1365 if ((section == NULL && invert) || (section != NULL && !invert)) \
1366 ++matched; \
1367 } \
1368 \
1369 if (matched == array_cnt(find_section_arr)) \
1370 *found_section = 1; \
1371 }
1372 FIND_SECTION(32)
1373 FIND_SECTION(64)
1374
1375 if (be_wewy_wewy_quiet)
1376 return NULL;
1377
1378 if (*found_section)
1379 return find_section;
1380
1381 if (be_quiet)
1382 return NULL;
1383 else
1384 return " - ";
1385}
1386
791/* scan an elf file and show all the fun stuff */ 1387/* scan an elf file and show all the fun stuff */
792#define prints(str) write(fileno(stdout), str, strlen(str)) 1388#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
793static void scanelf_file(const char *filename) 1389static int scanelf_elfobj(elfobj *elf)
794{ 1390{
795 unsigned long i; 1391 unsigned long i;
796 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1392 char found_pax, found_phdr, found_relro, found_load, found_textrel,
797 found_rpath, found_needed, found_interp, found_bind, found_soname, 1393 found_rpath, found_needed, found_interp, found_bind, found_soname,
798 found_sym, found_lib, found_file, found_textrels; 1394 found_sym, found_lib, found_file, found_textrels, found_section;
799 elfobj *elf;
800 struct stat st;
801 static char *out_buffer = NULL; 1395 static char *out_buffer = NULL;
802 static size_t out_len; 1396 static size_t out_len;
803 1397
804 /* make sure 'filename' exists */
805 if (lstat(filename, &st) == -1) {
806 if (be_verbose > 2) printf("%s: does not exist\n", filename);
807 return;
808 }
809 /* always handle regular files and handle symlinked files if no -y */
810 if (S_ISLNK(st.st_mode)) {
811 if (!scan_symlink) return;
812 stat(filename, &st);
813 }
814 if (!S_ISREG(st.st_mode)) {
815 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
816 return;
817 }
818
819 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1398 found_pax = found_phdr = found_relro = found_load = found_textrel = \
820 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1399 found_rpath = found_needed = found_interp = found_bind = found_soname = \
821 found_sym = found_lib = found_file = found_textrels = 0; 1400 found_sym = found_lib = found_file = found_textrels = found_section = 0;
822 1401
823 /* verify this is real ELF */
824 if ((elf = readelf(filename)) == NULL) {
825 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
826 return;
827 }
828
829 if (be_verbose > 1) 1402 if (be_verbose > 2)
830 printf("%s: scanning file {%s,%s}\n", filename, 1403 printf("%s: scanning file {%s,%s}\n", elf->filename,
831 get_elfeitype(EI_CLASS, elf->elf_class), 1404 get_elfeitype(EI_CLASS, elf->elf_class),
832 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1405 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
833 else if (be_verbose) 1406 else if (be_verbose > 1)
834 printf("%s: scanning file\n", filename); 1407 printf("%s: scanning file\n", elf->filename);
835 1408
836 /* init output buffer */ 1409 /* init output buffer */
837 if (!out_buffer) { 1410 if (!out_buffer) {
838 out_len = sizeof(char) * 80; 1411 out_len = sizeof(char) * 80;
839 out_buffer = (char*)xmalloc(out_len); 1412 out_buffer = xmalloc(out_len);
840 } 1413 }
841 *out_buffer = '\0'; 1414 *out_buffer = '\0';
842 1415
843 /* show the header */ 1416 /* show the header */
844 if (!be_quiet && show_banner) { 1417 if (!be_quiet && show_banner) {
845 for (i = 0; out_format[i]; ++i) { 1418 for (i = 0; out_format[i]; ++i) {
846 if (!IS_MODIFIER(out_format[i])) continue; 1419 if (!IS_MODIFIER(out_format[i])) continue;
847 1420
848 switch (out_format[++i]) { 1421 switch (out_format[++i]) {
1422 case '+': break;
849 case '%': break; 1423 case '%': break;
850 case '#': break; 1424 case '#': break;
851 case 'F': 1425 case 'F':
852 case 'p': 1426 case 'p':
853 case 'f': prints("FILE "); found_file = 1; break; 1427 case 'f': prints("FILE "); found_file = 1; break;
854 case 'o': prints(" TYPE "); break; 1428 case 'o': prints(" TYPE "); break;
855 case 'x': prints(" PAX "); break; 1429 case 'x': prints(" PAX "); break;
856 case 'e': prints("STK/REL/PTL "); break; 1430 case 'e': prints("STK/REL/PTL "); break;
857 case 't': prints("TEXTREL "); break; 1431 case 't': prints("TEXTREL "); break;
858 case 'r': prints("RPATH "); break; 1432 case 'r': prints("RPATH "); break;
1433 case 'M': prints("CLASS "); break;
1434 case 'l':
859 case 'n': prints("NEEDED "); break; 1435 case 'n': prints("NEEDED "); break;
860 case 'i': prints("INTERP "); break; 1436 case 'i': prints("INTERP "); break;
861 case 'b': prints("BIND "); break; 1437 case 'b': prints("BIND "); break;
1438 case 'Z': prints("SIZE "); break;
862 case 'S': prints("SONAME "); break; 1439 case 'S': prints("SONAME "); break;
863 case 's': prints("SYM "); break; 1440 case 's': prints("SYM "); break;
864 case 'N': prints("LIB "); break; 1441 case 'N': prints("LIB "); break;
865 case 'T': prints("TEXTRELS "); break; 1442 case 'T': prints("TEXTRELS "); break;
1443 case 'k': prints("SECTION "); break;
1444 case 'a': prints("ARCH "); break;
1445 case 'I': prints("OSABI "); break;
1446 case 'Y': prints("EABI "); break;
1447 case 'O': prints("PERM "); break;
1448 case 'D': prints("ENDIAN "); break;
866 default: warnf("'%c' has no title ?", out_format[i]); 1449 default: warnf("'%c' has no title ?", out_format[i]);
867 } 1450 }
868 } 1451 }
869 if (!found_file) prints("FILE "); 1452 if (!found_file) prints("FILE ");
870 prints("\n"); 1453 prints("\n");
874 1457
875 /* dump all the good stuff */ 1458 /* dump all the good stuff */
876 for (i = 0; out_format[i]; ++i) { 1459 for (i = 0; out_format[i]; ++i) {
877 const char *out; 1460 const char *out;
878 const char *tmp; 1461 const char *tmp;
879 1462 static char ubuf[sizeof(unsigned long)*2];
880 /* make sure we trim leading spaces in quiet mode */
881 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
882 *out_buffer = '\0';
883
884 if (!IS_MODIFIER(out_format[i])) { 1463 if (!IS_MODIFIER(out_format[i])) {
885 xchrcat(&out_buffer, out_format[i], &out_len); 1464 xchrcat(&out_buffer, out_format[i], &out_len);
886 continue; 1465 continue;
887 } 1466 }
888 1467
889 out = NULL; 1468 out = NULL;
890 be_wewy_wewy_quiet = (out_format[i] == '#'); 1469 be_wewy_wewy_quiet = (out_format[i] == '#');
1470 be_semi_verbose = (out_format[i] == '+');
891 switch (out_format[++i]) { 1471 switch (out_format[++i]) {
1472 case '+':
892 case '%': 1473 case '%':
893 case '#': 1474 case '#':
894 xchrcat(&out_buffer, out_format[i], &out_len); break; 1475 xchrcat(&out_buffer, out_format[i], &out_len); break;
895 case 'F': 1476 case 'F':
896 found_file = 1; 1477 found_file = 1;
897 if (be_wewy_wewy_quiet) break; 1478 if (be_wewy_wewy_quiet) break;
898 xstrcat(&out_buffer, filename, &out_len); 1479 xstrcat(&out_buffer, elf->filename, &out_len);
899 break; 1480 break;
900 case 'p': 1481 case 'p':
901 found_file = 1; 1482 found_file = 1;
902 if (be_wewy_wewy_quiet) break; 1483 if (be_wewy_wewy_quiet) break;
903 tmp = filename; 1484 tmp = elf->filename;
904 if (search_path) { 1485 if (search_path) {
905 ssize_t len_search = strlen(search_path); 1486 ssize_t len_search = strlen(search_path);
906 ssize_t len_file = strlen(filename); 1487 ssize_t len_file = strlen(elf->filename);
907 if (!strncmp(filename, search_path, len_search) && \ 1488 if (!strncmp(elf->filename, search_path, len_search) && \
908 len_file > len_search) 1489 len_file > len_search)
909 tmp += len_search; 1490 tmp += len_search;
910 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1491 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
911 } 1492 }
912 xstrcat(&out_buffer, tmp, &out_len); 1493 xstrcat(&out_buffer, tmp, &out_len);
913 break; 1494 break;
914 case 'f': 1495 case 'f':
915 found_file = 1; 1496 found_file = 1;
916 if (be_wewy_wewy_quiet) break; 1497 if (be_wewy_wewy_quiet) break;
917 tmp = strrchr(filename, '/'); 1498 tmp = strrchr(elf->filename, '/');
918 tmp = (tmp == NULL ? filename : tmp+1); 1499 tmp = (tmp == NULL ? elf->filename : tmp+1);
919 xstrcat(&out_buffer, tmp, &out_len); 1500 xstrcat(&out_buffer, tmp, &out_len);
920 break; 1501 break;
921 case 'o': out = get_elfetype(elf); break; 1502 case 'o': out = get_elfetype(elf); break;
922 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1503 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
923 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1504 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
924 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1505 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
925 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1506 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
926 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1507 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1508 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1509 case 'D': out = get_endian(elf); break;
1510 case 'O': out = strfileperms(elf->filename); break;
927 case 'n': 1511 case 'n':
928 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1512 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
929 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1513 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
930 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1514 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
931 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1515 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
932 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1516 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1517 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1518 case 'a': out = get_elfemtype(elf); break;
1519 case 'I': out = get_elfosabi(elf); break;
1520 case 'Y': out = get_elf_eabi(elf); break;
1521 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
933 default: warnf("'%c' has no scan code?", out_format[i]); 1522 default: warnf("'%c' has no scan code?", out_format[i]);
934 } 1523 }
935 if (out) { 1524 if (out)
936 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
937 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
938 xstrncat(&out_buffer, out, &out_len, (tmp-out));
939 else
940 xstrcat(&out_buffer, out, &out_len); 1525 xstrcat(&out_buffer, out, &out_len);
941 }
942 } 1526 }
943 1527
944#define FOUND_SOMETHING() \ 1528#define FOUND_SOMETHING() \
945 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1529 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
946 found_rpath || found_needed || found_interp || found_bind || \ 1530 found_rpath || found_needed || found_interp || found_bind || \
947 found_soname || found_sym || found_lib || found_textrels) 1531 found_soname || found_sym || found_lib || found_textrels || found_section )
948 1532
949 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1533 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
950 xchrcat(&out_buffer, ' ', &out_len); 1534 xchrcat(&out_buffer, ' ', &out_len);
951 xstrcat(&out_buffer, filename, &out_len); 1535 xstrcat(&out_buffer, elf->filename, &out_len);
952 } 1536 }
953 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1537 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
954 puts(out_buffer); 1538 puts(out_buffer);
955 fflush(stdout); 1539 fflush(stdout);
956 } 1540 }
957 1541
1542 return 0;
1543}
1544
1545/* scan a single elf */
1546static int scanelf_elf(const char *filename, int fd, size_t len)
1547{
1548 int ret = 1;
1549 elfobj *elf;
1550
1551 /* verify this is real ELF */
1552 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1553 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1554 return 2;
1555 }
1556 switch (match_bits) {
1557 case 32:
1558 if (elf->elf_class != ELFCLASS32)
1559 goto label_done;
1560 break;
1561 case 64:
1562 if (elf->elf_class != ELFCLASS64)
1563 goto label_done;
1564 break;
1565 default: break;
1566 }
1567 if (match_etypes) {
1568 char sbuf[126];
1569 strncpy(sbuf, match_etypes, sizeof(sbuf));
1570 if (strchr(match_etypes, ',') != NULL) {
1571 char *p;
1572 while ((p = strrchr(sbuf, ',')) != NULL) {
1573 *p = 0;
1574 if (etype_lookup(p+1) == get_etype(elf))
1575 goto label_ret;
1576 }
1577 }
1578 if (etype_lookup(sbuf) != get_etype(elf))
1579 goto label_done;
1580 }
1581
1582label_ret:
1583 ret = scanelf_elfobj(elf);
1584
1585label_done:
958 unreadelf(elf); 1586 unreadelf(elf);
1587 return ret;
1588}
1589
1590/* scan an archive of elfs */
1591static int scanelf_archive(const char *filename, int fd, size_t len)
1592{
1593 archive_handle *ar;
1594 archive_member *m;
1595 char *ar_buffer;
1596 elfobj *elf;
1597
1598 ar = ar_open_fd(filename, fd);
1599 if (ar == NULL)
1600 return 1;
1601
1602 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1603 while ((m = ar_next(ar)) != NULL) {
1604 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1605 if (cur_pos == -1)
1606 errp("lseek() failed");
1607 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1608 if (elf) {
1609 scanelf_elfobj(elf);
1610 unreadelf(elf);
1611 }
1612 }
1613 munmap(ar_buffer, len);
1614
1615 return 0;
1616}
1617/* scan a file which may be an elf or an archive or some other magical beast */
1618static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1619{
1620 const struct stat *st = st_cache;
1621 struct stat symlink_st;
1622 int fd;
1623
1624 /* always handle regular files and handle symlinked files if no -y */
1625 if (S_ISLNK(st->st_mode)) {
1626 if (!scan_symlink)
1627 return 1;
1628 fstatat(dir_fd, filename, &symlink_st, 0);
1629 st = &symlink_st;
1630 }
1631
1632 if (!S_ISREG(st->st_mode)) {
1633 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1634 return 1;
1635 }
1636
1637 if (match_perms) {
1638 if ((st->st_mode | match_perms) != st->st_mode)
1639 return 1;
1640 }
1641 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1642 if (fd == -1) {
1643 if (fix_elf && errno == ETXTBSY)
1644 warnp("%s: could not fix", filename);
1645 else if (be_verbose > 2)
1646 printf("%s: skipping file: %s\n", filename, strerror(errno));
1647 return 1;
1648 }
1649
1650 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1651 /* if it isn't an ELF, maybe it's an .a archive */
1652 if (scan_archives)
1653 scanelf_archive(filename, fd, st->st_size);
1654
1655 /*
1656 * unreadelf() implicitly closes its fd, so only close it
1657 * when we are returning it in the non-ELF case
1658 */
1659 close(fd);
1660 }
1661
1662 return 0;
959} 1663}
960 1664
961/* scan a directory for ET_EXEC files and print when we find one */ 1665/* scan a directory for ET_EXEC files and print when we find one */
962static void scanelf_dir(const char *path) 1666static int scanelf_dirat(int dir_fd, const char *path)
963{ 1667{
964 register DIR *dir; 1668 register DIR *dir;
965 register struct dirent *dentry; 1669 register struct dirent *dentry;
966 struct stat st_top, st; 1670 struct stat st_top, st;
967 char buf[_POSIX_PATH_MAX]; 1671 char buf[__PAX_UTILS_PATH_MAX], *subpath;
968 size_t pathlen = 0, len = 0; 1672 size_t pathlen = 0, len = 0;
1673 int ret = 0;
1674 int subdir_fd;
969 1675
970 /* make sure path exists */ 1676 /* make sure path exists */
971 if (lstat(path, &st_top) == -1) { 1677 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
972 if (be_verbose > 2) printf("%s: does not exist\n", path); 1678 if (be_verbose > 2) printf("%s: does not exist\n", path);
973 return; 1679 return 1;
974 } 1680 }
975 1681
976 /* ok, if it isn't a directory, assume we can open it */ 1682 /* ok, if it isn't a directory, assume we can open it */
977 if (!S_ISDIR(st_top.st_mode)) { 1683 if (!S_ISDIR(st_top.st_mode))
978 scanelf_file(path); 1684 return scanelf_fileat(dir_fd, path, &st_top);
979 return;
980 }
981 1685
982 /* now scan the dir looking for fun stuff */ 1686 /* now scan the dir looking for fun stuff */
983 if ((dir = opendir(path)) == NULL) { 1687 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
984 warnf("could not opendir %s: %s", path, strerror(errno)); 1688 if (subdir_fd == -1)
1689 dir = NULL;
1690 else
1691 dir = fdopendir(subdir_fd);
1692 if (dir == NULL) {
1693 if (subdir_fd != -1)
1694 close(subdir_fd);
1695 else if (be_verbose > 2)
1696 printf("%s: skipping dir: %s\n", path, strerror(errno));
985 return; 1697 return 1;
986 } 1698 }
987 if (be_verbose) printf("%s: scanning dir\n", path); 1699 if (be_verbose > 1) printf("%s: scanning dir\n", path);
988 1700
989 pathlen = strlen(path); 1701 subpath = stpcpy(buf, path);
1702 if (subpath[-1] != '/')
1703 *subpath++ = '/';
1704 pathlen = subpath - buf;
990 while ((dentry = readdir(dir))) { 1705 while ((dentry = readdir(dir))) {
991 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1706 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
992 continue; 1707 continue;
993 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1708
994 if (len >= sizeof(buf)) { 1709 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
995 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
996 (unsigned long)len, (unsigned long)sizeof(buf));
997 continue; 1710 continue;
1711
1712 len = strlen(dentry->d_name);
1713 if (len + pathlen + 1 >= sizeof(buf)) {
1714 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1715 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1716 continue;
998 } 1717 }
999 sprintf(buf, "%s/%s", path, dentry->d_name); 1718 memcpy(subpath, dentry->d_name, len);
1000 if (lstat(buf, &st) != -1) { 1719 subpath[len] = '\0';
1720
1001 if (S_ISREG(st.st_mode)) 1721 if (S_ISREG(st.st_mode))
1002 scanelf_file(buf); 1722 ret = scanelf_fileat(dir_fd, buf, &st);
1003 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1723 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1004 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1724 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1005 scanelf_dir(buf); 1725 ret = scanelf_dirat(dir_fd, buf);
1006 }
1007 } 1726 }
1008 } 1727 }
1009 closedir(dir); 1728 closedir(dir);
1010}
1011 1729
1730 return ret;
1731}
1732static int scanelf_dir(const char *path)
1733{
1734 return scanelf_dirat(root_fd, root_rel_path(path));
1735}
1736
1012static int scanelf_from_file(char *filename) 1737static int scanelf_from_file(const char *filename)
1013{ 1738{
1014 FILE *fp = NULL; 1739 FILE *fp;
1015 char *p; 1740 char *p, *path;
1016 char path[_POSIX_PATH_MAX]; 1741 size_t len;
1742 int ret;
1017 1743
1018 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1744 if (strcmp(filename, "-") == 0)
1019 fp = stdin; 1745 fp = stdin;
1020 else if ((fp = fopen(filename, "r")) == NULL) 1746 else if ((fp = fopen(filename, "r")) == NULL)
1021 return 1; 1747 return 1;
1022 1748
1023 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1749 path = NULL;
1750 len = 0;
1751 ret = 0;
1752 while (getline(&path, &len, fp) != -1) {
1024 if ((p = strchr(path, '\n')) != NULL) 1753 if ((p = strchr(path, '\n')) != NULL)
1025 *p = 0; 1754 *p = 0;
1026 search_path = path; 1755 search_path = path;
1027 scanelf_dir(path); 1756 ret = scanelf_dir(path);
1028 } 1757 }
1758 free(path);
1759
1029 if (fp != stdin) 1760 if (fp != stdin)
1030 fclose(fp); 1761 fclose(fp);
1762
1031 return 0; 1763 return ret;
1032} 1764}
1033 1765
1034static void load_ld_so_conf() 1766#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1767
1768static int _load_ld_cache_config(const char *fname)
1035{ 1769{
1036 FILE *fp = NULL; 1770 FILE *fp = NULL;
1037 char *p; 1771 char *p, *path;
1038 char path[_POSIX_PATH_MAX]; 1772 size_t len;
1039 int i = 0; 1773 int curr_fd = -1;
1040 1774
1041 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1775 fp = fopenat_r(root_fd, root_rel_path(fname));
1776 if (fp == NULL)
1042 return; 1777 return -1;
1043 1778
1044 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1779 path = NULL;
1045 if (*path != '/') 1780 len = 0;
1046 continue; 1781 while (getline(&path, &len, fp) != -1) {
1047
1048 if ((p = strrchr(path, '\r')) != NULL) 1782 if ((p = strrchr(path, '\r')) != NULL)
1049 *p = 0; 1783 *p = 0;
1050 if ((p = strchr(path, '\n')) != NULL) 1784 if ((p = strchr(path, '\n')) != NULL)
1051 *p = 0; 1785 *p = 0;
1052 1786
1053 ldpaths[i++] = xstrdup(path); 1787 /* recursive includes of the same file will make this segfault. */
1788 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1789 glob_t gl;
1790 size_t x;
1791 const char *gpath;
1054 1792
1055 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1793 /* re-use existing path buffer ... need to be creative */
1056 break; 1794 if (path[8] != '/')
1795 gpath = memcpy(path + 3, "/etc/", 5);
1796 else
1797 gpath = path + 8;
1798 if (root_fd != AT_FDCWD) {
1799 if (curr_fd == -1) {
1800 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1801 if (fchdir(root_fd))
1802 errp("unable to change to root dir");
1803 }
1804 gpath = root_rel_path(gpath);
1805 }
1806
1807 if (glob(gpath, 0, NULL, &gl) == 0) {
1808 for (x = 0; x < gl.gl_pathc; ++x) {
1809 /* try to avoid direct loops */
1810 if (strcmp(gl.gl_pathv[x], fname) == 0)
1811 continue;
1812 _load_ld_cache_config(gl.gl_pathv[x]);
1813 }
1814 globfree(&gl);
1815 }
1816
1817 /* failed globs are ignored by glibc */
1818 continue;
1057 } 1819 }
1058 ldpaths[i] = NULL; 1820
1821 if (*path != '/')
1822 continue;
1823
1824 xarraypush_str(ldpaths, path);
1825 }
1826 free(path);
1059 1827
1060 fclose(fp); 1828 fclose(fp);
1829
1830 if (curr_fd != -1) {
1831 if (fchdir(curr_fd))
1832 {/* don't care */}
1833 close(curr_fd);
1834 }
1835
1836 return 0;
1837}
1838
1839#elif defined(__FreeBSD__) || defined(__DragonFly__)
1840
1841static int _load_ld_cache_config(const char *fname)
1842{
1843 FILE *fp = NULL;
1844 char *b = NULL, *p;
1845 struct elfhints_hdr hdr;
1846
1847 fp = fopenat_r(root_fd, root_rel_path(fname));
1848 if (fp == NULL)
1849 return -1;
1850
1851 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1852 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1853 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1854 {
1855 fclose(fp);
1856 return -1;
1857 }
1858
1859 b = xmalloc(hdr.dirlistlen + 1);
1860 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1861 fclose(fp);
1862 free(b);
1863 return -1;
1864 }
1865
1866 while ((p = strsep(&b, ":"))) {
1867 if (*p == '\0')
1868 continue;
1869 xarraypush_str(ldpaths, p);
1870 }
1871
1872 free(b);
1873 fclose(fp);
1874 return 0;
1875}
1876
1877#else
1878#ifdef __ELF__
1879#warning Cache config support not implemented for your target
1880#endif
1881static int _load_ld_cache_config(const char *fname)
1882{
1883 return 0;
1884}
1885#endif
1886
1887static void load_ld_cache_config(const char *fname)
1888{
1889 bool scan_l, scan_ul, scan_ull;
1890 size_t n;
1891 const char *ldpath;
1892
1893 _load_ld_cache_config(fname);
1894
1895 scan_l = scan_ul = scan_ull = false;
1896 if (array_cnt(ldpaths)) {
1897 array_for_each(ldpaths, n, ldpath) {
1898 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1899 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1900 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1901 }
1902 }
1903
1904 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1905 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1906 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1061} 1907}
1062 1908
1063/* scan /etc/ld.so.conf for paths */ 1909/* scan /etc/ld.so.conf for paths */
1064static void scanelf_ldpath() 1910static void scanelf_ldpath(void)
1065{ 1911{
1066 char scan_l, scan_ul, scan_ull; 1912 size_t n;
1067 int i = 0; 1913 const char *ldpath;
1068 1914
1069 if (!ldpaths[0]) 1915 array_for_each(ldpaths, n, ldpath)
1070 err("Unable to load any paths from ld.so.conf");
1071
1072 scan_l = scan_ul = scan_ull = 0;
1073
1074 while (ldpaths[i]) {
1075 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1076 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1077 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1078 scanelf_dir(ldpaths[i]); 1916 scanelf_dir(ldpath);
1079 ++i;
1080 }
1081
1082 if (!scan_l) scanelf_dir("/lib");
1083 if (!scan_ul) scanelf_dir("/usr/lib");
1084 if (!scan_ull) scanelf_dir("/usr/local/lib");
1085} 1917}
1086 1918
1087/* scan env PATH for paths */ 1919/* scan env PATH for paths */
1088static void scanelf_envpath() 1920static void scanelf_envpath(void)
1089{ 1921{
1090 char *path, *p; 1922 char *path, *p;
1091 1923
1092 path = getenv("PATH"); 1924 path = getenv("PATH");
1093 if (!path) 1925 if (!path)
1100 } 1932 }
1101 1933
1102 free(path); 1934 free(path);
1103} 1935}
1104 1936
1105 1937/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1106/* usage / invocation handling functions */
1107#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1938#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1108#define a_argument required_argument 1939#define a_argument required_argument
1109static struct option const long_opts[] = { 1940static struct option const long_opts[] = {
1110 {"path", no_argument, NULL, 'p'}, 1941 {"path", no_argument, NULL, 'p'},
1111 {"ldpath", no_argument, NULL, 'l'}, 1942 {"ldpath", no_argument, NULL, 'l'},
1943 {"use-ldpath",no_argument, NULL, 129},
1944 {"root", a_argument, NULL, 128},
1112 {"recursive", no_argument, NULL, 'R'}, 1945 {"recursive", no_argument, NULL, 'R'},
1113 {"mount", no_argument, NULL, 'm'}, 1946 {"mount", no_argument, NULL, 'm'},
1114 {"symlink", no_argument, NULL, 'y'}, 1947 {"symlink", no_argument, NULL, 'y'},
1948 {"archives", no_argument, NULL, 'A'},
1949 {"ldcache", no_argument, NULL, 'L'},
1950 {"fix", no_argument, NULL, 'X'},
1951 {"setpax", a_argument, NULL, 'z'},
1115 {"pax", no_argument, NULL, 'x'}, 1952 {"pax", no_argument, NULL, 'x'},
1116 {"header", no_argument, NULL, 'e'}, 1953 {"header", no_argument, NULL, 'e'},
1117 {"textrel", no_argument, NULL, 't'}, 1954 {"textrel", no_argument, NULL, 't'},
1118 {"rpath", no_argument, NULL, 'r'}, 1955 {"rpath", no_argument, NULL, 'r'},
1119 {"needed", no_argument, NULL, 'n'}, 1956 {"needed", no_argument, NULL, 'n'},
1120 {"ldcache", no_argument, NULL, 'L'},
1121 {"interp", no_argument, NULL, 'i'}, 1957 {"interp", no_argument, NULL, 'i'},
1122 {"bind", no_argument, NULL, 'b'}, 1958 {"bind", no_argument, NULL, 'b'},
1123 {"soname", no_argument, NULL, 'S'}, 1959 {"soname", no_argument, NULL, 'S'},
1124 {"symbol", a_argument, NULL, 's'}, 1960 {"symbol", a_argument, NULL, 's'},
1961 {"section", a_argument, NULL, 'k'},
1125 {"lib", a_argument, NULL, 'N'}, 1962 {"lib", a_argument, NULL, 'N'},
1126 {"gmatch", no_argument, NULL, 'g'}, 1963 {"gmatch", no_argument, NULL, 'g'},
1127 {"textrels", no_argument, NULL, 'T'}, 1964 {"textrels", no_argument, NULL, 'T'},
1965 {"etype", a_argument, NULL, 'E'},
1966 {"bits", a_argument, NULL, 'M'},
1967 {"endian", no_argument, NULL, 'D'},
1968 {"osabi", no_argument, NULL, 'I'},
1969 {"eabi", no_argument, NULL, 'Y'},
1970 {"perms", a_argument, NULL, 'O'},
1971 {"size", no_argument, NULL, 'Z'},
1128 {"all", no_argument, NULL, 'a'}, 1972 {"all", no_argument, NULL, 'a'},
1129 {"quiet", no_argument, NULL, 'q'}, 1973 {"quiet", no_argument, NULL, 'q'},
1130 {"verbose", no_argument, NULL, 'v'}, 1974 {"verbose", no_argument, NULL, 'v'},
1131 {"format", a_argument, NULL, 'F'}, 1975 {"format", a_argument, NULL, 'F'},
1132 {"from", a_argument, NULL, 'f'}, 1976 {"from", a_argument, NULL, 'f'},
1133 {"file", a_argument, NULL, 'o'}, 1977 {"file", a_argument, NULL, 'o'},
1978 {"nocolor", no_argument, NULL, 'C'},
1134 {"nobanner", no_argument, NULL, 'B'}, 1979 {"nobanner", no_argument, NULL, 'B'},
1135 {"help", no_argument, NULL, 'h'}, 1980 {"help", no_argument, NULL, 'h'},
1136 {"version", no_argument, NULL, 'V'}, 1981 {"version", no_argument, NULL, 'V'},
1137 {NULL, no_argument, NULL, 0x0} 1982 {NULL, no_argument, NULL, 0x0}
1138}; 1983};
1139 1984
1140static const char *opts_help[] = { 1985static const char * const opts_help[] = {
1141 "Scan all directories in PATH environment", 1986 "Scan all directories in PATH environment",
1142 "Scan all directories in /etc/ld.so.conf", 1987 "Scan all directories in /etc/ld.so.conf",
1988 "Use ld.so.conf to show full path (use with -r/-n)",
1989 "Root directory (use with -l or -p)",
1143 "Scan directories recursively", 1990 "Scan directories recursively",
1144 "Don't recursively cross mount points", 1991 "Don't recursively cross mount points",
1145 "Don't scan symlinks\n", 1992 "Don't scan symlinks",
1993 "Scan archives (.a files)",
1994 "Utilize ld.so.cache to show full path (use with -r/-n)",
1995 "Try and 'fix' bad things (use with -r/-e)",
1996 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1146 "Print PaX markings", 1997 "Print PaX markings",
1147 "Print GNU_STACK/PT_LOAD markings", 1998 "Print GNU_STACK/PT_LOAD markings",
1148 "Print TEXTREL information", 1999 "Print TEXTREL information",
1149 "Print RPATH information", 2000 "Print RPATH information",
1150 "Print NEEDED information", 2001 "Print NEEDED information",
1151 "Resolve NEEDED information (use with -n)",
1152 "Print INTERP information", 2002 "Print INTERP information",
1153 "Print BIND information", 2003 "Print BIND information",
1154 "Print SONAME information", 2004 "Print SONAME information",
1155 "Find a specified symbol", 2005 "Find a specified symbol",
2006 "Find a specified section",
1156 "Find a specified library", 2007 "Find a specified library",
1157 "Use strncmp to match libraries. (use with -N)", 2008 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1158 "Locate cause of TEXTREL", 2009 "Locate cause of TEXTREL",
1159 "Print all scanned info (-x -e -t -r -b)\n", 2010 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2011 "Print only ELF files matching numeric bits",
2012 "Print Endianness",
2013 "Print OSABI",
2014 "Print EABI (EM_ARM Only)",
2015 "Print only ELF files matching octal permissions",
2016 "Print ELF file size",
2017 "Print all useful/simple info\n",
1160 "Only output 'bad' things", 2018 "Only output 'bad' things",
1161 "Be verbose (can be specified more than once)", 2019 "Be verbose (can be specified more than once)",
1162 "Use specified format for output", 2020 "Use specified format for output",
1163 "Read input stream from a filename", 2021 "Read input stream from a filename",
1164 "Write output stream to a filename", 2022 "Write output stream to a filename",
2023 "Don't emit color in output",
1165 "Don't display the header", 2024 "Don't display the header",
1166 "Print this help and exit", 2025 "Print this help and exit",
1167 "Print version and exit", 2026 "Print version and exit",
1168 NULL 2027 NULL
1169}; 2028};
1170 2029
1171/* display usage and exit */ 2030/* display usage and exit */
1172static void usage(int status) 2031static void usage(int status)
1173{ 2032{
1174 unsigned long i; 2033 const char a_arg[] = "<arg>";
2034 size_t a_arg_len = strlen(a_arg) + 2;
2035 size_t i;
2036 int optlen;
1175 printf("* Scan ELF binaries for stuff\n\n" 2037 printf("* Scan ELF binaries for stuff\n\n"
1176 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2038 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1177 printf("Options: -[%s]\n", PARSE_FLAGS); 2039 printf("Options: -[%s]\n", PARSE_FLAGS);
2040
2041 /* prescan the --long opt length to auto-align */
2042 optlen = 0;
1178 for (i = 0; long_opts[i].name; ++i) 2043 for (i = 0; long_opts[i].name; ++i) {
2044 int l = strlen(long_opts[i].name);
2045 if (long_opts[i].has_arg == a_argument)
2046 l += a_arg_len;
2047 optlen = max(l, optlen);
2048 }
2049
2050 for (i = 0; long_opts[i].name; ++i) {
2051 /* first output the short flag if it has one */
2052 if (long_opts[i].val > '~')
2053 printf(" ");
2054 else
2055 printf(" -%c, ", long_opts[i].val);
2056
2057 /* then the long flag */
1179 if (long_opts[i].has_arg == no_argument) 2058 if (long_opts[i].has_arg == no_argument)
1180 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2059 printf("--%-*s", optlen, long_opts[i].name);
1181 long_opts[i].name, opts_help[i]);
1182 else 2060 else
1183 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2061 printf("--%s %s %*s", long_opts[i].name, a_arg,
1184 long_opts[i].name, opts_help[i]); 2062 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1185 2063
1186 if (status != EXIT_SUCCESS) 2064 /* finally the help text */
1187 exit(status); 2065 printf("* %s\n", opts_help[i]);
2066 }
1188 2067
1189 puts("\nThe format modifiers for the -F option are:"); 2068 puts("\nFor more information, see the scanelf(1) manpage");
1190 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1191 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1192 puts(" i INTERP \tb BIND \ts symbol");
1193 puts(" N library \to Type \tT TEXTRELs");
1194 puts(" S SONAME");
1195 puts(" p filename (with search path removed)");
1196 puts(" f filename (short name/basename)");
1197 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1198
1199 exit(status); 2069 exit(status);
1200} 2070}
1201 2071
1202/* parse command line arguments and preform needed actions */ 2072/* parse command line arguments and preform needed actions */
2073#define do_pax_state(option, flag) \
2074 if (islower(option)) { \
2075 flags &= ~PF_##flag; \
2076 flags |= PF_NO##flag; \
2077 } else { \
2078 flags &= ~PF_NO##flag; \
2079 flags |= PF_##flag; \
2080 }
1203static void parseargs(int argc, char *argv[]) 2081static int parseargs(int argc, char *argv[])
1204{ 2082{
1205 int i; 2083 int i;
1206 char *from_file = NULL; 2084 const char *from_file = NULL;
2085 int ret = 0;
2086 char load_cache_config = 0;
1207 2087
1208 opterr = 0; 2088 opterr = 0;
1209 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2089 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1210 switch (i) { 2090 switch (i) {
1211 2091
1215 VERSION, __FILE__, __DATE__, rcsid, argv0); 2095 VERSION, __FILE__, __DATE__, rcsid, argv0);
1216 exit(EXIT_SUCCESS); 2096 exit(EXIT_SUCCESS);
1217 break; 2097 break;
1218 case 'h': usage(EXIT_SUCCESS); break; 2098 case 'h': usage(EXIT_SUCCESS); break;
1219 case 'f': 2099 case 'f':
1220 if (from_file) err("Don't specify -f twice"); 2100 if (from_file) warn("You prob don't want to specify -f twice");
1221 from_file = xstrdup(optarg); 2101 from_file = optarg;
2102 break;
2103 case 'E':
2104 match_etypes = optarg;
2105 break;
2106 case 'M':
2107 match_bits = atoi(optarg);
2108 if (match_bits == 0) {
2109 if (strcmp(optarg, "ELFCLASS32") == 0)
2110 match_bits = 32;
2111 if (strcmp(optarg, "ELFCLASS64") == 0)
2112 match_bits = 64;
2113 }
2114 break;
2115 case 'O':
2116 if (sscanf(optarg, "%o", &match_perms) == -1)
2117 match_bits = 0;
1222 break; 2118 break;
1223 case 'o': { 2119 case 'o': {
1224 FILE *fp = NULL;
1225 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2120 if (freopen(optarg, "w", stdout) == NULL)
1226 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2121 errp("Could not freopen(%s)", optarg);
1227 SET_STDOUT(fp);
1228 break; 2122 break;
1229 } 2123 }
1230 2124 case 'k':
2125 xarraypush_str(find_section_arr, optarg);
2126 break;
1231 case 's': { 2127 case 's': {
1232 if (find_sym) warn("You prob don't want to specify -s twice"); 2128 /* historically, this was comma delimited */
1233 find_sym = optarg; 2129 char *this_sym = strtok(optarg, ",");
1234 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1)); 2130 if (!this_sym) /* edge case: -s '' */
1235 sprintf(versioned_symname, "%s@", find_sym); 2131 xarraypush_str(find_sym_arr, "");
2132 while (this_sym) {
2133 xarraypush_str(find_sym_arr, this_sym);
2134 this_sym = strtok(NULL, ",");
2135 }
1236 break; 2136 break;
1237 } 2137 }
1238 case 'N': { 2138 case 'N':
1239 if (find_lib) warn("You prob don't want to specify -N twice"); 2139 xarraypush_str(find_lib_arr, optarg);
1240 find_lib = optarg;
1241 break; 2140 break;
1242 }
1243
1244 case 'F': { 2141 case 'F': {
1245 if (out_format) warn("You prob don't want to specify -F twice"); 2142 if (out_format) warn("You prob don't want to specify -F twice");
1246 out_format = optarg; 2143 out_format = optarg;
1247 break; 2144 break;
1248 } 2145 }
2146 case 'z': {
2147 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2148 size_t x;
1249 2149
1250 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2150 for (x = 0; x < strlen(optarg); x++) {
1251 case 'L': printcache = 1; break; 2151 switch (optarg[x]) {
2152 case 'p':
2153 case 'P':
2154 do_pax_state(optarg[x], PAGEEXEC);
2155 break;
2156 case 's':
2157 case 'S':
2158 do_pax_state(optarg[x], SEGMEXEC);
2159 break;
2160 case 'm':
2161 case 'M':
2162 do_pax_state(optarg[x], MPROTECT);
2163 break;
2164 case 'e':
2165 case 'E':
2166 do_pax_state(optarg[x], EMUTRAMP);
2167 break;
2168 case 'r':
2169 case 'R':
2170 do_pax_state(optarg[x], RANDMMAP);
2171 break;
2172 case 'x':
2173 case 'X':
2174 do_pax_state(optarg[x], RANDEXEC);
2175 break;
2176 default:
2177 break;
2178 }
2179 }
2180 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2181 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2182 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2183 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2184 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2185 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2186 setpax = flags;
2187 break;
2188 }
2189 case 'Z': show_size = 1; break;
2190 case 'g': ++g_match; break;
2191 case 'L': load_cache_config = use_ldcache = 1; break;
1252 case 'y': scan_symlink = 0; break; 2192 case 'y': scan_symlink = 0; break;
2193 case 'A': scan_archives = 1; break;
2194 case 'C': color_init(true); break;
1253 case 'B': show_banner = 0; break; 2195 case 'B': show_banner = 0; break;
1254 case 'l': scan_ldpath = 1; break; 2196 case 'l': load_cache_config = scan_ldpath = 1; break;
1255 case 'p': scan_envpath = 1; break; 2197 case 'p': scan_envpath = 1; break;
1256 case 'R': dir_recurse = 1; break; 2198 case 'R': dir_recurse = 1; break;
1257 case 'm': dir_crossmount = 0; break; 2199 case 'm': dir_crossmount = 0; break;
2200 case 'X': ++fix_elf; break;
1258 case 'x': show_pax = 1; break; 2201 case 'x': show_pax = 1; break;
1259 case 'e': show_phdr = 1; break; 2202 case 'e': show_phdr = 1; break;
1260 case 't': show_textrel = 1; break; 2203 case 't': show_textrel = 1; break;
1261 case 'r': show_rpath = 1; break; 2204 case 'r': show_rpath = 1; break;
1262 case 'n': show_needed = 1; break; 2205 case 'n': show_needed = 1; break;
1263 case 'i': show_interp = 1; break; 2206 case 'i': show_interp = 1; break;
1264 case 'b': show_bind = 1; break; 2207 case 'b': show_bind = 1; break;
1265 case 'S': show_soname = 1; break; 2208 case 'S': show_soname = 1; break;
1266 case 'T': show_textrels = 1; break; 2209 case 'T': show_textrels = 1; break;
1267 case 'q': be_quiet = 1; break; 2210 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1268 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2211 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1269 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2212 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1270 2213 case 'D': show_endian = 1; break;
2214 case 'I': show_osabi = 1; break;
2215 case 'Y': show_eabi = 1; break;
2216 case 128:
2217 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2218 if (root_fd == -1)
2219 err("Could not open root: %s", optarg);
2220 break;
2221 case 129: load_cache_config = use_ldpath = 1; break;
1271 case ':': 2222 case ':':
1272 err("Option missing parameter\n"); 2223 err("Option '%c' is missing parameter", optopt);
1273 case '?': 2224 case '?':
1274 err("Unknown option\n"); 2225 err("Unknown option '%c' or argument missing", optopt);
1275 default: 2226 default:
1276 err("Unhandled option '%c'", i); 2227 err("Unhandled option '%c'; please report this", i);
2228 }
2229 }
2230 if (show_textrels && be_verbose)
2231 has_objdump = bin_in_path("objdump");
2232 /* precompile all the regexes */
2233 if (g_match) {
2234 regex_t preg;
2235 const char *this_sym;
2236 size_t n;
2237 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2238
2239 array_for_each(find_sym_arr, n, this_sym) {
2240 /* see scanelf_match_symname for logic info */
2241 switch (this_sym[0]) {
2242 case '%':
2243 while (*(this_sym++))
2244 if (*this_sym == '%') {
2245 ++this_sym;
2246 break;
2247 }
2248 break;
2249 case '+':
2250 case '-':
2251 ++this_sym;
2252 break;
1277 } 2253 }
2254 if (*this_sym == '*')
2255 ++this_sym;
2256
2257 ret = regcomp(&preg, this_sym, flags);
2258 if (ret) {
2259 char err[256];
2260 regerror(ret, &preg, err, sizeof(err));
2261 err("regcomp of %s failed: %s", this_sym, err);
2262 }
2263 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
1278 } 2264 }
1279 2265 }
2266 /* flatten arrays for display */
2267 if (array_cnt(find_sym_arr))
2268 find_sym = array_flatten_str(find_sym_arr);
2269 if (array_cnt(find_lib_arr))
2270 find_lib = array_flatten_str(find_lib_arr);
2271 if (array_cnt(find_section_arr))
2272 find_section = array_flatten_str(find_section_arr);
1280 /* let the format option override all other options */ 2273 /* let the format option override all other options */
1281 if (out_format) { 2274 if (out_format) {
1282 show_pax = show_phdr = show_textrel = show_rpath = \ 2275 show_pax = show_phdr = show_textrel = show_rpath = \
1283 show_needed = show_interp = show_bind = show_soname = \ 2276 show_needed = show_interp = show_bind = show_soname = \
1284 show_textrels = 0; 2277 show_textrels = show_perms = show_endian = show_size = \
2278 show_osabi = show_eabi = 0;
1285 for (i = 0; out_format[i]; ++i) { 2279 for (i = 0; out_format[i]; ++i) {
1286 if (!IS_MODIFIER(out_format[i])) continue; 2280 if (!IS_MODIFIER(out_format[i])) continue;
1287 2281
1288 switch (out_format[++i]) { 2282 switch (out_format[++i]) {
2283 case '+': break;
1289 case '%': break; 2284 case '%': break;
1290 case '#': break; 2285 case '#': break;
1291 case 'F': break; 2286 case 'F': break;
1292 case 'p': break; 2287 case 'p': break;
1293 case 'f': break; 2288 case 'f': break;
2289 case 'k': break;
1294 case 's': break; 2290 case 's': break;
1295 case 'N': break; 2291 case 'N': break;
1296 case 'o': break; 2292 case 'o': break;
2293 case 'a': break;
2294 case 'M': break;
2295 case 'Z': show_size = 1; break;
2296 case 'D': show_endian = 1; break;
2297 case 'I': show_osabi = 1; break;
2298 case 'Y': show_eabi = 1; break;
2299 case 'O': show_perms = 1; break;
1297 case 'x': show_pax = 1; break; 2300 case 'x': show_pax = 1; break;
1298 case 'e': show_phdr = 1; break; 2301 case 'e': show_phdr = 1; break;
1299 case 't': show_textrel = 1; break; 2302 case 't': show_textrel = 1; break;
1300 case 'r': show_rpath = 1; break; 2303 case 'r': show_rpath = 1; break;
1301 case 'n': show_needed = 1; break; 2304 case 'n': show_needed = 1; break;
1302 case 'i': show_interp = 1; break; 2305 case 'i': show_interp = 1; break;
1303 case 'b': show_bind = 1; break; 2306 case 'b': show_bind = 1; break;
1304 case 'S': show_soname = 1; break; 2307 case 'S': show_soname = 1; break;
1305 case 'T': show_textrels = 1; break; 2308 case 'T': show_textrels = 1; break;
1306 default: 2309 default:
1307 err("Invalid format specifier '%c' (byte %i)", 2310 err("invalid format specifier '%c' (byte %i)",
1308 out_format[i], i+1); 2311 out_format[i], i+1);
1309 } 2312 }
1310 } 2313 }
1311 2314
1312 /* construct our default format */ 2315 /* construct our default format */
1313 } else { 2316 } else {
1314 size_t fmt_len = 30; 2317 size_t fmt_len = 30;
1315 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2318 out_format = xmalloc(sizeof(char) * fmt_len);
2319 *out_format = '\0';
1316 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2320 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1317 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2321 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2322 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2323 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2324 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2325 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2326 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1318 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2327 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1319 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2328 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1320 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2329 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1321 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2330 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1322 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2331 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1323 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2332 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1324 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2333 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1325 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2334 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1326 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2335 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2336 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1327 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2337 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1328 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2338 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1329 } 2339 }
1330 if (be_verbose > 2) printf("Format: %s\n", out_format); 2340 if (be_verbose > 2) printf("Format: %s\n", out_format);
1331 2341
1332 /* now lets actually do the scanning */ 2342 /* now lets actually do the scanning */
1333 if (scan_ldpath || (show_rpath && be_quiet)) 2343 if (load_cache_config)
1334 load_ld_so_conf(); 2344 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1335 if (scan_ldpath) scanelf_ldpath(); 2345 if (scan_ldpath) scanelf_ldpath();
1336 if (scan_envpath) scanelf_envpath(); 2346 if (scan_envpath) scanelf_envpath();
2347 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2348 from_file = "-";
1337 if (from_file) { 2349 if (from_file) {
1338 scanelf_from_file(from_file); 2350 scanelf_from_file(from_file);
1339 free(from_file);
1340 from_file = *argv; 2351 from_file = *argv;
1341 } 2352 }
1342 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2353 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1343 err("Nothing to scan !?"); 2354 err("Nothing to scan !?");
1344 while (optind < argc) { 2355 while (optind < argc) {
1345 search_path = argv[optind++]; 2356 search_path = argv[optind++];
1346 scanelf_dir(search_path); 2357 ret = scanelf_dir(search_path);
1347 } 2358 }
1348 2359
2360#ifdef __PAX_UTILS_CLEANUP
1349 /* clean up */ 2361 /* clean up */
1350 if (versioned_symname) free(versioned_symname);
1351 for (i = 0; ldpaths[i]; ++i)
1352 free(ldpaths[i]); 2362 xarrayfree(ldpaths);
2363 xarrayfree(find_sym_arr);
2364 xarrayfree(find_lib_arr);
2365 xarrayfree(find_section_arr);
2366 free(find_sym);
2367 free(find_lib);
2368 free(find_section);
2369 {
2370 size_t n;
2371 regex_t *preg;
2372 array_for_each(find_sym_regex_arr, n, preg)
2373 regfree(preg);
2374 xarrayfree(find_sym_regex_arr);
2375 }
1353 2376
1354 if (ldcache != 0) 2377 if (ldcache != 0)
1355 munmap(ldcache, ldcache_size); 2378 munmap(ldcache, ldcache_size);
1356} 2379#endif
1357 2380
1358
1359
1360/* utility funcs */
1361static char *xstrdup(const char *s)
1362{
1363 char *ret = strdup(s);
1364 if (!ret) err("Could not strdup(): %s", strerror(errno));
1365 return ret; 2381 return ret;
1366} 2382}
1367static void *xmalloc(size_t size)
1368{
1369 void *ret = malloc(size);
1370 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1371 return ret;
1372}
1373static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1374{
1375 size_t new_len;
1376 2383
1377 new_len = strlen(*dst) + strlen(src); 2384static char **get_split_env(const char *envvar)
1378 if (*curr_len <= new_len) {
1379 *curr_len = new_len + (*curr_len / 2);
1380 *dst = realloc(*dst, *curr_len);
1381 if (!*dst)
1382 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1383 }
1384
1385 if (n)
1386 strncat(*dst, src, n);
1387 else
1388 strcat(*dst, src);
1389}
1390static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1391{ 2385{
1392 static char my_app[2]; 2386 const char *delims = " \t\n";
1393 my_app[0] = append; 2387 char **envvals = NULL;
1394 my_app[1] = '\0'; 2388 char *env, *s;
1395 xstrcat(dst, my_app, curr_len); 2389 int nentry;
1396}
1397 2390
2391 if ((env = getenv(envvar)) == NULL)
2392 return NULL;
1398 2393
2394 env = xstrdup(env);
2395 if (env == NULL)
2396 return NULL;
2397
2398 s = strtok(env, delims);
2399 if (s == NULL) {
2400 free(env);
2401 return NULL;
2402 }
2403
2404 nentry = 0;
2405 while (s != NULL) {
2406 ++nentry;
2407 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2408 envvals[nentry-1] = s;
2409 s = strtok(NULL, delims);
2410 }
2411 envvals[nentry] = NULL;
2412
2413 /* don't want to free(env) as it contains the memory that backs
2414 * the envvals array of strings */
2415 return envvals;
2416}
2417
2418static void parseenv(void)
2419{
2420 color_init(false);
2421 qa_textrels = get_split_env("QA_TEXTRELS");
2422 qa_execstack = get_split_env("QA_EXECSTACK");
2423 qa_wx_load = get_split_env("QA_WX_LOAD");
2424}
2425
2426#ifdef __PAX_UTILS_CLEANUP
2427static void cleanup(void)
2428{
2429 free(out_format);
2430 free(qa_textrels);
2431 free(qa_execstack);
2432 free(qa_wx_load);
2433}
2434#endif
1399 2435
1400int main(int argc, char *argv[]) 2436int main(int argc, char *argv[])
1401{ 2437{
2438 int ret;
1402 if (argc < 2) 2439 if (argc < 2)
1403 usage(EXIT_FAILURE); 2440 usage(EXIT_FAILURE);
2441 parseenv();
1404 parseargs(argc, argv); 2442 ret = parseargs(argc, argv);
1405 fclose(stdout); 2443 fclose(stdout);
1406#ifdef __BOUNDS_CHECKING_ON 2444#ifdef __PAX_UTILS_CLEANUP
1407 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2445 cleanup();
2446 warn("The calls to add/delete heap should be off:\n"
2447 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2448 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1408#endif 2449#endif
1409 return EXIT_SUCCESS; 2450 return ret;
1410} 2451}
2452
2453/* Match filename against entries in matchlist, return TRUE
2454 * if the file is listed */
2455static int file_matches_list(const char *filename, char **matchlist)
2456{
2457 char **file;
2458 char *match;
2459 char buf[__PAX_UTILS_PATH_MAX];
2460
2461 if (matchlist == NULL)
2462 return 0;
2463
2464 for (file = matchlist; *file != NULL; file++) {
2465 if (search_path) {
2466 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2467 match = buf;
2468 } else {
2469 match = *file;
2470 }
2471 if (fnmatch(match, filename, 0) == 0)
2472 return 1;
2473 }
2474 return 0;
2475}

Legend:
Removed from v.1.98  
changed lines
  Added in v.1.257

  ViewVC Help
Powered by ViewVC 1.1.20