/[gentoo-projects]/pax-utils/scanelf.c
Gentoo

Diff of /pax-utils/scanelf.c

Parent Directory Parent Directory | Revision Log Revision Log | View Patch Patch

Revision 1.98 Revision 1.260
1/* 1/*
2 * Copyright 2003-2006 Gentoo Foundation 2 * Copyright 2003-2012 Gentoo Foundation
3 * Distributed under the terms of the GNU General Public License v2 3 * Distributed under the terms of the GNU General Public License v2
4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.98 2006/01/05 03:12:07 vapier Exp $ 4 * $Header: /var/cvsroot/gentoo-projects/pax-utils/Attic/scanelf.c,v 1.260 2014/01/11 00:28:49 vapier Exp $
5 * 5 *
6 * Copyright 2003-2006 Ned Ludd - <solar@gentoo.org> 6 * Copyright 2003-2012 Ned Ludd - <solar@gentoo.org>
7 * Copyright 2004-2006 Mike Frysinger - <vapier@gentoo.org> 7 * Copyright 2004-2012 Mike Frysinger - <vapier@gentoo.org>
8 */ 8 */
9 9
10static const char rcsid[] = "$Id: scanelf.c,v 1.260 2014/01/11 00:28:49 vapier Exp $";
11const char argv0[] = "scanelf";
12
10#include "paxinc.h" 13#include "paxinc.h"
11 14
12static const char *rcsid = "$Id: scanelf.c,v 1.98 2006/01/05 03:12:07 vapier Exp $";
13#define argv0 "scanelf"
14
15#define IS_MODIFIER(c) (c == '%' || c == '#') 15#define IS_MODIFIER(c) (c == '%' || c == '#' || c == '+')
16
17
18 16
19/* prototypes */ 17/* prototypes */
20static void scanelf_file(const char *filename); 18static int file_matches_list(const char *filename, char **matchlist);
21static void scanelf_dir(const char *path);
22static void scanelf_ldpath();
23static void scanelf_envpath();
24static void usage(int status);
25static void parseargs(int argc, char *argv[]);
26static char *xstrdup(const char *s);
27static void *xmalloc(size_t size);
28static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n);
29#define xstrcat(dst,src,curr_len) xstrncat(dst,src,curr_len,0)
30static inline void xchrcat(char **dst, const char append, size_t *curr_len);
31 19
32/* variables to control behavior */ 20/* variables to control behavior */
33static char *ldpaths[256]; 21static char *match_etypes = NULL;
22static array_t _ldpaths = array_init_decl, *ldpaths = &_ldpaths;
34static char scan_ldpath = 0; 23static char scan_ldpath = 0;
35static char scan_envpath = 0; 24static char scan_envpath = 0;
36static char scan_symlink = 1; 25static char scan_symlink = 1;
26static char scan_archives = 0;
37static char dir_recurse = 0; 27static char dir_recurse = 0;
38static char dir_crossmount = 1; 28static char dir_crossmount = 1;
39static char show_pax = 0; 29static char show_pax = 0;
30static char show_perms = 0;
31static char show_size = 0;
40static char show_phdr = 0; 32static char show_phdr = 0;
41static char show_textrel = 0; 33static char show_textrel = 0;
42static char show_rpath = 0; 34static char show_rpath = 0;
43static char show_needed = 0; 35static char show_needed = 0;
44static char show_interp = 0; 36static char show_interp = 0;
45static char show_bind = 0; 37static char show_bind = 0;
46static char show_soname = 0; 38static char show_soname = 0;
47static char show_textrels = 0; 39static char show_textrels = 0;
48static char show_banner = 1; 40static char show_banner = 1;
41static char show_endian = 0;
42static char show_osabi = 0;
43static char show_eabi = 0;
49static char be_quiet = 0; 44static char be_quiet = 0;
50static char be_verbose = 0; 45static char be_verbose = 0;
51static char be_wewy_wewy_quiet = 0; 46static char be_wewy_wewy_quiet = 0;
52static char *find_sym = NULL, *versioned_symname = NULL; 47static char be_semi_verbose = 0;
48static char *find_sym = NULL;
49static array_t _find_sym_arr = array_init_decl, *find_sym_arr = &_find_sym_arr;
50static array_t _find_sym_regex_arr = array_init_decl, *find_sym_regex_arr = &_find_sym_regex_arr;
53static char *find_lib = NULL; 51static char *find_lib = NULL;
52static array_t _find_lib_arr = array_init_decl, *find_lib_arr = &_find_lib_arr;
53static char *find_section = NULL;
54static array_t _find_section_arr = array_init_decl, *find_section_arr = &_find_section_arr;
54static char *out_format = NULL; 55static char *out_format = NULL;
55static char *search_path = NULL; 56static char *search_path = NULL;
57static char fix_elf = 0;
56static char gmatch = 0; 58static char g_match = 0;
57static char printcache = 0; 59static char use_ldcache = 0;
60static char use_ldpath = 0;
58 61
62static char **qa_textrels = NULL;
63static char **qa_execstack = NULL;
64static char **qa_wx_load = NULL;
65static int root_fd = AT_FDCWD;
59 66
60caddr_t ldcache = 0; 67static int match_bits = 0;
68static unsigned int match_perms = 0;
69static void *ldcache = NULL;
61size_t ldcache_size = 0; 70static size_t ldcache_size = 0;
71static unsigned long setpax = 0UL;
62 72
73static int has_objdump = 0;
74
75/* find the path to a file by name */
76static int bin_in_path(const char *fname)
77{
78 char fullpath[__PAX_UTILS_PATH_MAX];
79 char *path, *p;
80
81 path = getenv("PATH");
82 if (!path)
83 return 0;
84
85 while ((p = strrchr(path, ':')) != NULL) {
86 snprintf(fullpath, sizeof(fullpath), "%s/%s", p + 1, fname);
87 *p = 0;
88 if (access(fullpath, R_OK) != -1)
89 return 1;
90 }
91
92 return 0;
93}
94
95static FILE *fopenat_r(int dir_fd, const char *path)
96{
97 int fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
98 if (fd == -1)
99 return NULL;
100 return fdopen(fd, "re");
101}
102
103static const char *root_rel_path(const char *path)
104{
105 /*
106 * openat() will ignore the dirfd if path starts with
107 * a /, so consume all of that noise
108 *
109 * XXX: we don't handle relative paths like ../ that
110 * break out of the --root option, but for now, just
111 * don't do that :P.
112 */
113 if (root_fd != AT_FDCWD) {
114 while (*path == '/')
115 ++path;
116 if (*path == '\0')
117 path = ".";
118 }
119
120 return path;
121}
122
63/* sub-funcs for scanelf_file() */ 123/* sub-funcs for scanelf_fileat() */
64static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **tab) 124static void scanelf_file_get_symtabs(elfobj *elf, void **sym, void **str)
65{ 125{
66 /* find the best SHT_DYNSYM and SHT_STRTAB sections */ 126 /* find the best SHT_DYNSYM and SHT_STRTAB sections */
127
128 /* debug sections */
129 void *symtab = elf_findsecbyname(elf, ".symtab");
130 void *strtab = elf_findsecbyname(elf, ".strtab");
131 /* runtime sections */
132 void *dynsym = elf_findsecbyname(elf, ".dynsym");
133 void *dynstr = elf_findsecbyname(elf, ".dynstr");
134
135 /*
136 * If the sections are marked NOBITS, then they don't exist, so we just
137 * skip them. This let's us work sanely with splitdebug ELFs (rather
138 * than spewing a lot of "corrupt ELF" messages later on). In malformed
139 * ELFs, the section might be wrongly set to NOBITS, but screw em.
140 */
67#define GET_SYMTABS(B) \ 141#define GET_SYMTABS(B) \
68 if (elf->elf_class == ELFCLASS ## B) { \ 142 if (elf->elf_class == ELFCLASS ## B) { \
69 Elf ## B ## _Shdr *symtab, *strtab, *dynsym, *dynstr; \ 143 Elf ## B ## _Shdr *esymtab = symtab; \
70 /* debug sections */ \ 144 Elf ## B ## _Shdr *estrtab = strtab; \
71 symtab = SHDR ## B (elf_findsecbyname(elf, ".symtab")); \ 145 Elf ## B ## _Shdr *edynsym = dynsym; \
72 strtab = SHDR ## B (elf_findsecbyname(elf, ".strtab")); \ 146 Elf ## B ## _Shdr *edynstr = dynstr; \
73 /* runtime sections */ \ 147 \
74 dynsym = SHDR ## B (elf_findsecbyname(elf, ".dynsym")); \ 148 if (symtab && EGET(esymtab->sh_type) == SHT_NOBITS) \
75 dynstr = SHDR ## B (elf_findsecbyname(elf, ".dynstr")); \ 149 symtab = NULL; \
150 if (dynsym && EGET(edynsym->sh_type) == SHT_NOBITS) \
151 dynsym = NULL; \
76 if (symtab && dynsym) { \ 152 if (symtab && dynsym) \
77 *sym = (void*)((EGET(symtab->sh_size) > EGET(dynsym->sh_size)) ? symtab : dynsym); \ 153 *sym = (EGET(esymtab->sh_size) > EGET(edynsym->sh_size)) ? symtab : dynsym; \
78 } else { \ 154 else \
79 *sym = (void*)(symtab ? symtab : dynsym); \ 155 *sym = symtab ? symtab : dynsym; \
80 } \ 156 \
157 if (strtab && EGET(estrtab->sh_type) == SHT_NOBITS) \
158 strtab = NULL; \
159 if (dynstr && EGET(edynstr->sh_type) == SHT_NOBITS) \
160 dynstr = NULL; \
81 if (strtab && dynstr) { \ 161 if (strtab && dynstr) \
82 *tab = (void*)((EGET(strtab->sh_size) > EGET(dynstr->sh_size)) ? strtab : dynstr); \ 162 *str = (EGET(estrtab->sh_size) > EGET(edynstr->sh_size)) ? strtab : dynstr; \
83 } else { \ 163 else \
84 *tab = (void*)(strtab ? strtab : dynstr); \ 164 *str = strtab ? strtab : dynstr; \
85 } \
86 } 165 }
87 GET_SYMTABS(32) 166 GET_SYMTABS(32)
88 GET_SYMTABS(64) 167 GET_SYMTABS(64)
168
169 if (*sym && *str)
170 return;
171
172 /*
173 * damn, they're really going to make us work for it huh?
174 * reconstruct the section header info out of the dynamic
175 * tags so we can see what symbols this guy uses at runtime.
176 */
177#define GET_SYMTABS_DT(B) \
178 if (elf->elf_class == ELFCLASS ## B) { \
179 size_t i; \
180 static Elf ## B ## _Shdr sym_shdr, str_shdr; \
181 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
182 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
183 Elf ## B ## _Addr vsym, vstr, vhash, vgnu_hash; \
184 Elf ## B ## _Dyn *dyn; \
185 Elf ## B ## _Off offset; \
186 \
187 /* lookup symbols used at runtime with DT_SYMTAB / DT_STRTAB */ \
188 vsym = vstr = vhash = vgnu_hash = 0; \
189 memset(&sym_shdr, 0, sizeof(sym_shdr)); \
190 memset(&str_shdr, 0, sizeof(str_shdr)); \
191 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
192 if (EGET(phdr[i].p_type) != PT_DYNAMIC) \
193 continue; \
194 \
195 offset = EGET(phdr[i].p_offset); \
196 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
197 continue; \
198 \
199 dyn = DYN ## B (elf->vdata + offset); \
200 while (EGET(dyn->d_tag) != DT_NULL) { \
201 switch (EGET(dyn->d_tag)) { \
202 case DT_SYMTAB: vsym = EGET(dyn->d_un.d_val); break; \
203 case DT_SYMENT: sym_shdr.sh_entsize = dyn->d_un.d_val; break; \
204 case DT_STRTAB: vstr = EGET(dyn->d_un.d_val); break; \
205 case DT_STRSZ: str_shdr.sh_size = dyn->d_un.d_val; break; \
206 case DT_HASH: vhash = EGET(dyn->d_un.d_val); break; \
207 /*case DT_GNU_HASH: vgnu_hash = EGET(dyn->d_un.d_val); break;*/ \
208 } \
209 ++dyn; \
210 } \
211 if (vsym && vstr) \
212 break; \
213 } \
214 if (!vsym || !vstr || !(vhash || vgnu_hash)) \
215 return; \
216 \
217 /* calc offset into the ELF by finding the load addr of the syms */ \
218 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
219 Elf ## B ## _Addr vaddr = EGET(phdr[i].p_vaddr); \
220 Elf ## B ## _Addr filesz = EGET(phdr[i].p_filesz); \
221 offset = EGET(phdr[i].p_offset); \
222 \
223 if (EGET(phdr[i].p_type) != PT_LOAD) \
224 continue; \
225 \
226 if (vhash >= vaddr && vhash < vaddr + filesz) { \
227 /* Scan the hash table to see how many entries we have */ \
228 Elf32_Word max_sym_idx = 0; \
229 Elf32_Word *hashtbl = elf->vdata + offset + (vhash - vaddr); \
230 Elf32_Word b, nbuckets = EGET(hashtbl[0]); \
231 Elf32_Word nchains = EGET(hashtbl[1]); \
232 Elf32_Word *buckets = &hashtbl[2]; \
233 Elf32_Word *chains = &buckets[nbuckets]; \
234 Elf32_Word sym_idx; \
235 \
236 for (b = 0; b < nbuckets; ++b) { \
237 if (!buckets[b]) \
238 continue; \
239 for (sym_idx = buckets[b]; sym_idx < nchains && sym_idx; sym_idx = chains[sym_idx]) \
240 if (max_sym_idx < sym_idx) \
241 max_sym_idx = sym_idx; \
242 } \
243 ESET(sym_shdr.sh_size, sym_shdr.sh_entsize * max_sym_idx); \
244 } \
245 \
246 if (vsym >= vaddr && vsym < vaddr + filesz) { \
247 ESET(sym_shdr.sh_offset, offset + (vsym - vaddr)); \
248 *sym = &sym_shdr; \
249 } \
250 \
251 if (vstr >= vaddr && vstr < vaddr + filesz) { \
252 ESET(str_shdr.sh_offset, offset + (vstr - vaddr)); \
253 *str = &str_shdr; \
254 } \
255 } \
256 }
257 GET_SYMTABS_DT(32)
258 GET_SYMTABS_DT(64)
89} 259}
260
90static char *scanelf_file_pax(elfobj *elf, char *found_pax) 261static char *scanelf_file_pax(elfobj *elf, char *found_pax)
91{ 262{
92 static char ret[7]; 263 static char ret[7];
93 unsigned long i, shown; 264 unsigned long i, shown;
94 265
103 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 274 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
104 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 275 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
105 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 276 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
106 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \ 277 if (EGET(phdr[i].p_type) != PT_PAX_FLAGS) \
107 continue; \ 278 continue; \
108 if (be_quiet && (EGET(phdr[i].p_flags) == 10240)) \ 279 if (fix_elf && setpax) { \
280 /* set the paxctl flags */ \
281 ESET(phdr[i].p_flags, setpax); \
282 } \
283 if (be_quiet && (EGET(phdr[i].p_flags) == (PF_NOEMUTRAMP | PF_NORANDEXEC))) \
109 continue; \ 284 continue; \
110 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \ 285 memcpy(ret, pax_short_pf_flags(EGET(phdr[i].p_flags)), 6); \
111 *found_pax = 1; \ 286 *found_pax = 1; \
112 ++shown; \ 287 ++shown; \
113 break; \ 288 break; \
114 } \ 289 } \
115 } 290 }
116 SHOW_PAX(32) 291 SHOW_PAX(32)
117 SHOW_PAX(64) 292 SHOW_PAX(64)
118 } 293 }
294
295 /* Note: We do not support setting EI_PAX if not PT_PAX_FLAGS
296 * was found. This is known to break ELFs on glibc systems,
297 * and mainline PaX has deprecated use of this for a long time.
298 * We could support changing PT_GNU_STACK, but that doesn't
299 * seem like it's worth the effort. #411919
300 */
119 301
120 /* fall back to EI_PAX if no PT_PAX was found */ 302 /* fall back to EI_PAX if no PT_PAX was found */
121 if (!*ret) { 303 if (!*ret) {
122 static char *paxflags; 304 static char *paxflags;
123 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf)); 305 paxflags = pax_short_hf_flags(EI_PAX_FLAGS(elf));
136 318
137static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load) 319static char *scanelf_file_phdr(elfobj *elf, char *found_phdr, char *found_relro, char *found_load)
138{ 320{
139 static char ret[12]; 321 static char ret[12];
140 char *found; 322 char *found;
141 unsigned long i, shown;
142 unsigned char multi_stack, multi_relro, multi_load; 323 unsigned long i, shown, multi_stack, multi_relro, multi_load;
143 324
144 if (!show_phdr) return NULL; 325 if (!show_phdr) return NULL;
145 326
146 memcpy(ret, "--- --- ---\0", 12); 327 memcpy(ret, "--- --- ---\0", 12);
147 328
148 shown = 0; 329 shown = 0;
149 multi_stack = multi_relro = multi_load = 0; 330 multi_stack = multi_relro = multi_load = 0;
150 331
332#define NOTE_GNU_STACK ".note.GNU-stack"
151#define SHOW_PHDR(B) \ 333#define SHOW_PHDR(B) \
152 if (elf->elf_class == ELFCLASS ## B) { \ 334 if (elf->elf_class == ELFCLASS ## B) { \
153 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 335 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
154 Elf ## B ## _Off offset; \ 336 Elf ## B ## _Off offset; \
155 uint32_t flags, check_flags; \ 337 uint32_t flags, check_flags; \
156 if (elf->phdr != NULL) { \ 338 if (elf->phdr != NULL) { \
157 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 339 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
158 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \ 340 for (i = 0; i < EGET(ehdr->e_phnum); ++i) { \
159 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \ 341 if (EGET(phdr[i].p_type) == PT_GNU_STACK) { \
342 if (multi_stack++) \
160 if (multi_stack++) warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \ 343 warnf("%s: multiple PT_GNU_STACK's !?", elf->filename); \
344 if (file_matches_list(elf->filename, qa_execstack)) \
345 continue; \
161 found = found_phdr; \ 346 found = found_phdr; \
162 offset = 0; \ 347 offset = 0; \
163 check_flags = PF_X; \ 348 check_flags = PF_X; \
164 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \ 349 } else if (EGET(phdr[i].p_type) == PT_GNU_RELRO) { \
350 if (multi_relro++) \
165 if (multi_relro++) warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \ 351 warnf("%s: multiple PT_GNU_RELRO's !?", elf->filename); \
166 found = found_relro; \ 352 found = found_relro; \
167 offset = 4; \ 353 offset = 4; \
168 check_flags = PF_X; \ 354 check_flags = PF_X; \
169 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \ 355 } else if (EGET(phdr[i].p_type) == PT_LOAD) { \
170 if (multi_load++ > 2) warnf("%s: more than 2 PT_LOAD's !?", elf->filename); \ 356 if (file_matches_list(elf->filename, qa_wx_load)) \
357 continue; \
171 found = found_load; \ 358 found = found_load; \
172 offset = 8; \ 359 offset = 8; \
173 check_flags = PF_W|PF_X; \ 360 check_flags = PF_W|PF_X; \
174 } else \ 361 } else \
175 continue; \ 362 continue; \
176 flags = EGET(phdr[i].p_flags); \ 363 flags = EGET(phdr[i].p_flags); \
177 if (be_quiet && ((flags & check_flags) != check_flags)) \ 364 if (be_quiet && ((flags & check_flags) != check_flags)) \
178 continue; \ 365 continue; \
366 if ((EGET(phdr[i].p_type) != PT_LOAD) && (fix_elf && ((flags & PF_X) != flags))) { \
367 ESET(phdr[i].p_flags, flags & (PF_X ^ (size_t)-1)); \
368 ret[3] = ret[7] = '!'; \
369 flags = EGET(phdr[i].p_flags); \
370 } \
179 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \ 371 memcpy(ret+offset, gnu_short_stack_flags(flags), 3); \
180 *found = 1; \ 372 *found = 1; \
181 ++shown; \ 373 ++shown; \
182 } \ 374 } \
183 } else if (elf->shdr != NULL) { \ 375 } else if (elf->shdr != NULL) { \
184 /* no program headers which means this is prob an object file */ \ 376 /* no program headers which means this is prob an object file */ \
185 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \ 377 Elf ## B ## _Shdr *shdr = SHDR ## B (elf->shdr); \
186 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \ 378 Elf ## B ## _Shdr *strtbl = shdr + EGET(ehdr->e_shstrndx); \
379 char *str; \
380 if ((void*)strtbl > elf->data_end) \
381 goto skip_this_shdr##B; \
382 /* let's flag -w/+x object files since the final ELF will most likely \
383 * need write access to the stack (who doesn't !?). so the combined \
384 * output will bring in +w automatically and that's bad. \
385 */ \
187 check_flags = SHF_WRITE|SHF_EXECINSTR; \ 386 check_flags = /*SHF_WRITE|*/SHF_EXECINSTR; \
188 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \ 387 for (i = 0; i < EGET(ehdr->e_shnum); ++i) { \
189 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \ 388 if (EGET(shdr[i].sh_type) != SHT_PROGBITS) continue; \
190 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \ 389 offset = EGET(strtbl->sh_offset) + EGET(shdr[i].sh_name); \
191 if (!strcmp((char*)(elf->data + offset), ".note.GNU-stack")) { \ 390 str = elf->data + offset; \
391 if (str > elf->data + offset + sizeof(NOTE_GNU_STACK)) continue; \
392 if (!strcmp(str, NOTE_GNU_STACK)) { \
192 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \ 393 if (multi_stack++) warnf("%s: multiple .note.GNU-stack's !?", elf->filename); \
193 flags = EGET(shdr[i].sh_flags); \ 394 flags = EGET(shdr[i].sh_flags); \
194 if (be_quiet && ((flags & check_flags) != check_flags)) \ 395 if (be_quiet && ((flags & check_flags) != check_flags)) \
195 continue; \ 396 continue; \
196 ++*found_phdr; \ 397 ++*found_phdr; \
200 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \ 401 if (flags & SHF_EXECINSTR) ret[2] = 'X'; \
201 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \ 402 if (flags & 0xFFFFFFF8) warn("Invalid section flags for GNU-stack"); \
202 break; \ 403 break; \
203 } \ 404 } \
204 } \ 405 } \
406 skip_this_shdr##B: \
205 if (!multi_stack) { \ 407 if (!multi_stack) { \
408 if (file_matches_list(elf->filename, qa_execstack)) \
409 return NULL; \
206 *found_phdr = 1; \ 410 *found_phdr = 1; \
207 shown = 1; \ 411 shown = 1; \
208 memcpy(ret, "!WX", 3); \ 412 memcpy(ret, "!WX", 3); \
209 } \ 413 } \
210 } \ 414 } \
215 if (be_wewy_wewy_quiet || (be_quiet && !shown)) 419 if (be_wewy_wewy_quiet || (be_quiet && !shown))
216 return NULL; 420 return NULL;
217 else 421 else
218 return ret; 422 return ret;
219} 423}
424
425/*
426 * See if this ELF contains a DT_TEXTREL tag in any of its
427 * PT_DYNAMIC sections.
428 */
220static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel) 429static const char *scanelf_file_textrel(elfobj *elf, char *found_textrel)
221{ 430{
222 static const char *ret = "TEXTREL"; 431 static const char *ret = "TEXTREL";
223 unsigned long i; 432 unsigned long i;
224 433
225 if (!show_textrel && !show_textrels) return NULL; 434 if (!show_textrel && !show_textrels) return NULL;
435
436 if (file_matches_list(elf->filename, qa_textrels)) return NULL;
226 437
227 if (elf->phdr) { 438 if (elf->phdr) {
228#define SHOW_TEXTREL(B) \ 439#define SHOW_TEXTREL(B) \
229 if (elf->elf_class == ELFCLASS ## B) { \ 440 if (elf->elf_class == ELFCLASS ## B) { \
230 Elf ## B ## _Dyn *dyn; \ 441 Elf ## B ## _Dyn *dyn; \
231 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 442 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
232 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 443 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
233 Elf ## B ## _Off offset; \ 444 Elf ## B ## _Off offset; \
234 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 445 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
235 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 446 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
236 offset = EGET(phdr[i].p_offset); \ 447 offset = EGET(phdr[i].p_offset); \
237 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 448 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
238 dyn = DYN ## B (elf->data + offset); \ 449 dyn = DYN ## B (elf->vdata + offset); \
239 while (EGET(dyn->d_tag) != DT_NULL) { \ 450 while (EGET(dyn->d_tag) != DT_NULL) { \
240 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \ 451 if (EGET(dyn->d_tag) == DT_TEXTREL) { /*dyn->d_tag != DT_FLAGS)*/ \
241 *found_textrel = 1; \ 452 *found_textrel = 1; \
242 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \ 453 /*if (dyn->d_un.d_val & DF_TEXTREL)*/ \
243 return (be_wewy_wewy_quiet ? NULL : ret); \ 454 return (be_wewy_wewy_quiet ? NULL : ret); \
252 if (be_quiet || be_wewy_wewy_quiet) 463 if (be_quiet || be_wewy_wewy_quiet)
253 return NULL; 464 return NULL;
254 else 465 else
255 return " - "; 466 return " - ";
256} 467}
468
469/*
470 * Scan the .text section to see if there are any relocations in it.
471 * Should rewrite this to check PT_LOAD sections that are marked
472 * Executable rather than the section named '.text'.
473 */
257static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel) 474static char *scanelf_file_textrels(elfobj *elf, char *found_textrels, char *found_textrel)
258{ 475{
259 unsigned long s, r, rmax; 476 unsigned long s, r, rmax;
260 void *symtab_void, *strtab_void, *text_void; 477 void *symtab_void, *strtab_void, *text_void;
261 478
282 Elf ## B ## _Rela *rela; \ 499 Elf ## B ## _Rela *rela; \
283 /* search the section headers for relocations */ \ 500 /* search the section headers for relocations */ \
284 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \ 501 for (s = 0; s < EGET(ehdr->e_shnum); ++s) { \
285 uint32_t sh_type = EGET(shdr[s].sh_type); \ 502 uint32_t sh_type = EGET(shdr[s].sh_type); \
286 if (sh_type == SHT_REL) { \ 503 if (sh_type == SHT_REL) { \
287 rel = REL ## B (elf->data + EGET(shdr[s].sh_offset)); \ 504 rel = REL ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
288 rela = NULL; \ 505 rela = NULL; \
289 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \ 506 rmax = EGET(shdr[s].sh_size) / sizeof(*rel); \
290 } else if (sh_type == SHT_RELA) { \ 507 } else if (sh_type == SHT_RELA) { \
291 rel = NULL; \ 508 rel = NULL; \
292 rela = RELA ## B (elf->data + EGET(shdr[s].sh_offset)); \ 509 rela = RELA ## B (elf->vdata + EGET(shdr[s].sh_offset)); \
293 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \ 510 rmax = EGET(shdr[s].sh_size) / sizeof(*rela); \
294 } else \ 511 } else \
295 continue; \ 512 continue; \
296 /* now see if any of the relocs are in the .text */ \ 513 /* now see if any of the relocs are in the .text */ \
297 for (r = 0; r < rmax; ++r) { \ 514 for (r = 0; r < rmax; ++r) { \
312 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \ 529 if (r_offset < vaddr || r_offset >= vaddr + memsz) { \
313 if (be_verbose <= 2) continue; \ 530 if (be_verbose <= 2) continue; \
314 } else \ 531 } else \
315 *found_textrels = 1; \ 532 *found_textrels = 1; \
316 /* locate this relocation symbol name */ \ 533 /* locate this relocation symbol name */ \
317 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 534 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
535 if ((void*)sym > elf->data_end) { \
536 warn("%s: corrupt ELF symbol", elf->filename); \
537 continue; \
538 } \
318 sym_max = ELF ## B ## _R_SYM(r_info); \ 539 sym_max = ELF ## B ## _R_SYM(r_info); \
319 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \ 540 if (sym_max * EGET(symtab->sh_entsize) < symtab->sh_size) \
320 sym += sym_max; \ 541 sym += sym_max; \
321 else \ 542 else \
322 sym = NULL; \ 543 sym = NULL; \
323 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 544 sym_max = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \
324 /* show the raw details about this reloc */ \ 545 /* show the raw details about this reloc */ \
325 printf(" %s: ", elf->base_filename); \ 546 printf(" %s: ", elf->base_filename); \
326 if (sym && sym->st_name) \ 547 if (sym && sym->st_name) \
327 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name))); \ 548 printf("%s", elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \
328 else \ 549 else \
329 printf("(memory/fake?)"); \ 550 printf("(memory/data?)"); \
330 printf(" [0x%lX]", (unsigned long)r_offset); \ 551 printf(" [0x%lX]", (unsigned long)r_offset); \
331 /* now try to find the closest symbol that this rel is probably in */ \ 552 /* now try to find the closest symbol that this rel is probably in */ \
332 sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 553 sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
333 func = NULL; \ 554 func = NULL; \
334 offset_tmp = 0; \ 555 offset_tmp = 0; \
335 while (sym_max--) { \ 556 while (sym_max--) { \
336 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \ 557 if (EGET(sym->st_value) < r_offset && EGET(sym->st_value) > offset_tmp) { \
337 func = sym; \ 558 func = sym; \
338 offset_tmp = EGET(sym->st_value); \ 559 offset_tmp = EGET(sym->st_value); \
339 } \ 560 } \
340 ++sym; \ 561 ++sym; \
341 } \ 562 } \
342 printf(" in "); \ 563 printf(" in "); \
343 if (func && func->st_name) \ 564 if (func && func->st_name) { \
344 printf("%s", (char*)(elf->data + EGET(strtab->sh_offset) + EGET(func->st_name))); \ 565 const char *func_name = elf->data + EGET(strtab->sh_offset) + EGET(func->st_name); \
566 if (r_offset > EGET(func->st_size)) \
567 printf("(optimized out: previous %s)", func_name); \
345 else \ 568 else \
346 printf("(NULL: fake?)"); \ 569 printf("%s", func_name); \
570 } else \
571 printf("(optimized out)"); \
347 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \ 572 printf(" [0x%lX]\n", (unsigned long)offset_tmp); \
573 if (be_verbose && has_objdump) { \
574 Elf ## B ## _Addr end_addr = offset_tmp + EGET(func->st_size); \
575 char *sysbuf; \
576 size_t syslen; \
577 const char sysfmt[] = "objdump -r -R -d -w -l --start-address=0x%lX --stop-address=0x%lX %s | grep --color -i -C 3 '.*[[:space:]]%lX:[[:space:]]*R_.*'\n"; \
578 syslen = sizeof(sysfmt) + strlen(elf->filename) + 3 * sizeof(unsigned long) + 1; \
579 sysbuf = xmalloc(syslen); \
580 if (end_addr < r_offset) \
581 /* not uncommon when things are optimized out */ \
582 end_addr = r_offset + 0x100; \
583 snprintf(sysbuf, syslen, sysfmt, \
584 (unsigned long)offset_tmp, \
585 (unsigned long)end_addr, \
586 elf->filename, \
587 (unsigned long)r_offset); \
588 fflush(stdout); \
589 if (system(sysbuf)) {/* don't care */} \
590 fflush(stdout); \
591 free(sysbuf); \
592 } \
348 } \ 593 } \
349 } } 594 } }
350 SHOW_TEXTRELS(32) 595 SHOW_TEXTRELS(32)
351 SHOW_TEXTRELS(64) 596 SHOW_TEXTRELS(64)
352 } 597 }
354 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename); 599 warnf("ELF %s has TEXTREL markings but doesnt appear to have any real TEXTREL's !?", elf->filename);
355 600
356 return NULL; 601 return NULL;
357} 602}
358 603
359static void rpath_security_checks(elfobj *, char *);
360static void rpath_security_checks(elfobj *elf, char *item) { 604static void rpath_security_checks(elfobj *elf, char *item, const char *dt_type)
605{
361 struct stat st; 606 struct stat st;
362 switch (*item) { 607 switch (*item) {
363 case '/': break; 608 case '/': break;
364 case '.': 609 case '.':
365 warnf("Security problem with relative RPATH '%s' in %s", item, elf->filename); 610 warnf("Security problem with relative %s '%s' in %s", dt_type, item, elf->filename);
366 break; 611 break;
612 case ':':
367 case '\0': 613 case '\0':
368 warnf("Security problem NULL RPATH in %s", elf->filename); 614 warnf("Security problem NULL %s in %s", dt_type, elf->filename);
369 break; 615 break;
370 case '$': 616 case '$':
371 if (fstat(elf->fd, &st) != -1) 617 if (fstat(elf->fd, &st) != -1)
372 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID)) 618 if ((st.st_mode & S_ISUID) || (st.st_mode & S_ISGID))
373 warnf("Security problem with RPATH='%s' in %s with mode set of %o", 619 warnf("Security problem with %s='%s' in %s with mode set of %o",
374 item, elf->filename, st.st_mode & 07777); 620 dt_type, item, elf->filename, (unsigned int) st.st_mode & 07777);
375 break; 621 break;
376 default: 622 default:
377 warnf("Maybe? sec problem with RPATH='%s' in %s", item, elf->filename); 623 warnf("Maybe? sec problem with %s='%s' in %s", dt_type, item, elf->filename);
378 break; 624 break;
379 } 625 }
380} 626}
381static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len) 627static void scanelf_file_rpath(elfobj *elf, char *found_rpath, char **ret, size_t *ret_len)
382{ 628{
383 unsigned long i, s; 629 unsigned long i;
384 char *rpath, *runpath, **r; 630 char *rpath, *runpath, **r;
385 void *strtbl_void; 631 void *strtbl_void;
386 632
387 if (!show_rpath) return; 633 if (!show_rpath) return;
388 634
399 Elf ## B ## _Off offset; \ 645 Elf ## B ## _Off offset; \
400 Elf ## B ## _Xword word; \ 646 Elf ## B ## _Xword word; \
401 /* Scan all the program headers */ \ 647 /* Scan all the program headers */ \
402 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 648 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
403 /* Just scan dynamic headers */ \ 649 /* Just scan dynamic headers */ \
404 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 650 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
405 offset = EGET(phdr[i].p_offset); \ 651 offset = EGET(phdr[i].p_offset); \
406 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 652 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
407 /* Just scan dynamic RPATH/RUNPATH headers */ \ 653 /* Just scan dynamic RPATH/RUNPATH headers */ \
408 dyn = DYN ## B (elf->data + offset); \ 654 dyn = DYN ## B (elf->vdata + offset); \
409 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \ 655 while ((word=EGET(dyn->d_tag)) != DT_NULL) { \
410 if (word == DT_RPATH) { \ 656 if (word == DT_RPATH) { \
411 r = &rpath; \ 657 r = &rpath; \
412 } else if (word == DT_RUNPATH) { \ 658 } else if (word == DT_RUNPATH) { \
413 r = &runpath; \ 659 r = &runpath; \
417 } \ 663 } \
418 /* Verify the memory is somewhat sane */ \ 664 /* Verify the memory is somewhat sane */ \
419 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 665 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
420 if (offset < (Elf ## B ## _Off)elf->len) { \ 666 if (offset < (Elf ## B ## _Off)elf->len) { \
421 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \ 667 if (*r) warn("ELF has multiple %s's !?", get_elfdtype(word)); \
422 *r = (char*)(elf->data + offset); \ 668 *r = elf->data + offset; \
669 /* cache the length in case we need to nuke this section later on */ \
670 if (fix_elf) \
671 offset = strlen(*r); \
423 /* If quiet, don't output paths in ld.so.conf */ \ 672 /* If quiet, don't output paths in ld.so.conf */ \
424 if (be_quiet) { \ 673 if (be_quiet) { \
425 size_t len; \ 674 size_t len; \
426 char *start, *end; \ 675 char *start, *end; \
427 /* note that we only 'chop' off leading known paths. */ \ 676 /* note that we only 'chop' off leading known paths. */ \
428 /* since *r is read-only memory, we can only move the ptr forward. */ \ 677 /* since *r is read-only memory, we can only move the ptr forward. */ \
429 start = *r; \ 678 start = *r; \
430 /* scan each path in : delimited list */ \ 679 /* scan each path in : delimited list */ \
431 while (start) { \ 680 while (start) { \
432 rpath_security_checks(elf, start); \ 681 rpath_security_checks(elf, start, get_elfdtype(word)); \
433 end = strchr(start, ':'); \ 682 end = strchr(start, ':'); \
434 len = (end ? abs(end - start) : strlen(start)); \ 683 len = (end ? abs(end - start) : strlen(start)); \
435 for (s = 0; ldpaths[s]; ++s) { \ 684 if (use_ldcache) { \
685 size_t n; \
686 const char *ldpath; \
687 array_for_each(ldpaths, n, ldpath) \
436 if (!strncmp(ldpaths[s], start, len) && !ldpaths[s][len]) { \ 688 if (!strncmp(ldpath, start, len) && !ldpath[len]) { \
437 *r = (end ? end + 1 : NULL); \ 689 *r = end; \
690 /* corner case ... if RPATH reads "/usr/lib:", we want \
691 * to show ':' rather than '' */ \
692 if (end && end[1] != '\0') \
693 (*r)++; \
438 break; \ 694 break; \
439 } \ 695 } \
440 } \ 696 } \
441 if (!*r || !ldpaths[s] || !end) \ 697 if (!*r || !end) \
442 start = NULL; \ 698 break; \
443 else \ 699 else \
444 start = start + len + 1; \ 700 start = start + len + 1; \
445 } \ 701 } \
446 } \ 702 } \
703 if (*r) { \
704 if (fix_elf > 2 || (fix_elf && **r == '\0')) { \
705 /* just nuke it */ \
706 nuke_it##B: \
707 memset(*r, 0x00, offset); \
708 *r = NULL; \
709 ESET(dyn->d_tag, DT_DEBUG); \
710 ESET(dyn->d_un.d_ptr, 0); \
711 } else if (fix_elf) { \
712 /* try to clean "bad" paths */ \
713 size_t len, tmpdir_len; \
714 char *start, *end; \
715 const char *tmpdir; \
716 start = *r; \
717 tmpdir = (getenv("TMPDIR") ? : "."); \
718 tmpdir_len = strlen(tmpdir); \
719 while (1) { \
720 end = strchr(start, ':'); \
721 if (start == end) { \
722 eat_this_path##B: \
723 len = strlen(end); \
724 memmove(start, end+1, len); \
725 start[len-1] = '\0'; \
726 end = start - 1; \
727 } else if (tmpdir && !strncmp(start, tmpdir, tmpdir_len)) { \
728 if (!end) { \
729 if (start == *r) \
730 goto nuke_it##B; \
731 *--start = '\0'; \
732 } else \
733 goto eat_this_path##B; \
734 } \
735 if (!end) \
736 break; \
737 start = end + 1; \
738 } \
739 if (**r == '\0') \
740 goto nuke_it##B; \
741 } \
742 if (*r) \
447 if (*r) *found_rpath = 1; \ 743 *found_rpath = 1; \
744 } \
448 } \ 745 } \
449 ++dyn; \ 746 ++dyn; \
450 } \ 747 } \
451 } } 748 } }
452 SHOW_RPATH(32) 749 SHOW_RPATH(32)
470 xstrcat(ret, (runpath ? runpath : rpath), ret_len); 767 xstrcat(ret, (runpath ? runpath : rpath), ret_len);
471 else if (!be_quiet) 768 else if (!be_quiet)
472 xstrcat(ret, " - ", ret_len); 769 xstrcat(ret, " - ", ret_len);
473} 770}
474 771
772/* Defines can be seen in glibc's sysdeps/generic/ldconfig.h */
475#define LDSO_CACHE_MAGIC "ld.so-" 773#define LDSO_CACHE_MAGIC "ld.so-"
476#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1) 774#define LDSO_CACHE_MAGIC_LEN (sizeof LDSO_CACHE_MAGIC -1)
477#define LDSO_CACHE_VER "1.7.0" 775#define LDSO_CACHE_VER "1.7.0"
478#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1) 776#define LDSO_CACHE_VER_LEN (sizeof LDSO_CACHE_VER -1)
479#define FLAG_ANY -1 777#define FLAG_ANY -1
488#define FLAG_X8664_LIB64 0x0300 786#define FLAG_X8664_LIB64 0x0300
489#define FLAG_S390_LIB64 0x0400 787#define FLAG_S390_LIB64 0x0400
490#define FLAG_POWERPC_LIB64 0x0500 788#define FLAG_POWERPC_LIB64 0x0500
491#define FLAG_MIPS64_LIBN32 0x0600 789#define FLAG_MIPS64_LIBN32 0x0600
492#define FLAG_MIPS64_LIBN64 0x0700 790#define FLAG_MIPS64_LIBN64 0x0700
791#define FLAG_X8664_LIBX32 0x0800
792#define FLAG_ARM_LIBHF 0x0900
793#define FLAG_AARCH64_LIB64 0x0a00
493 794
494static char *lookup_cache_lib(elfobj *, char *); 795#if defined(__GLIBC__) || defined(__UCLIBC__)
796
495static char *lookup_cache_lib(elfobj *elf, char *fname) 797static char *lookup_cache_lib(elfobj *elf, const char *fname)
496{ 798{
497 int fd = 0; 799 int fd;
498 char *strs; 800 char *strs;
499 static char buf[_POSIX_PATH_MAX] = ""; 801 static char buf[__PAX_UTILS_PATH_MAX] = "";
500 const char *cachefile = "/etc/ld.so.cache"; 802 const char *cachefile = root_rel_path("/etc/ld.so.cache");
501 struct stat st; 803 struct stat st;
502 804
503 typedef struct { 805 typedef struct {
504 char magic[LDSO_CACHE_MAGIC_LEN]; 806 char magic[LDSO_CACHE_MAGIC_LEN];
505 char version[LDSO_CACHE_VER_LEN]; 807 char version[LDSO_CACHE_VER_LEN];
515 libentry_t *libent; 817 libentry_t *libent;
516 818
517 if (fname == NULL) 819 if (fname == NULL)
518 return NULL; 820 return NULL;
519 821
520 if (ldcache == 0) { 822 if (ldcache == NULL) {
521 if (stat(cachefile, &st) || (fd = open(cachefile, O_RDONLY)) == -1) 823 if (fstatat(root_fd, cachefile, &st, 0))
824 return NULL;
825
826 fd = openat(root_fd, cachefile, O_RDONLY);
827 if (fd == -1)
522 return NULL; 828 return NULL;
523 829
524 /* cache these values so we only map/unmap the cache file once */ 830 /* cache these values so we only map/unmap the cache file once */
525 ldcache_size = st.st_size; 831 ldcache_size = st.st_size;
526 ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0); 832 header = ldcache = mmap(0, ldcache_size, PROT_READ, MAP_SHARED, fd, 0);
527
528 close(fd); 833 close(fd);
529 834
530 if (ldcache == (caddr_t)-1) 835 if (ldcache == MAP_FAILED) {
836 ldcache = NULL;
531 return NULL; 837 return NULL;
838 }
532 839
533 if (memcmp(((header_t *) ldcache)->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN)) 840 if (memcmp(header->magic, LDSO_CACHE_MAGIC, LDSO_CACHE_MAGIC_LEN) ||
841 memcmp(header->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
842 {
843 munmap(ldcache, ldcache_size);
844 ldcache = NULL;
534 return NULL; 845 return NULL;
535 if (memcmp (((header_t *) ldcache)->version, LDSO_CACHE_VER, LDSO_CACHE_VER_LEN))
536 return NULL;
537 } 846 }
847 } else
848 header = ldcache;
538 849
539 header = (header_t *) ldcache;
540 libent = (libentry_t *) (ldcache + sizeof(header_t)); 850 libent = ldcache + sizeof(header_t);
541 strs = (char *) &libent[header->nlibs]; 851 strs = (char *) &libent[header->nlibs];
542 852
543 for (fd = 0; fd < header->nlibs; fd++) { 853 for (fd = 0; fd < header->nlibs; ++fd) {
544 /* this should be more fine grained, but for now we assume that 854 /* This should be more fine grained, but for now we assume that
545 * diff arches will not be cached together. and we ignore the 855 * diff arches will not be cached together, and we ignore the
546 * the different multilib mips cases. */ 856 * the different multilib mips cases.
857 */
547 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK)) 858 if (elf->elf_class == ELFCLASS64 && !(libent[fd].flags & FLAG_REQUIRED_MASK))
548 continue; 859 continue;
549 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK)) 860 if (elf->elf_class == ELFCLASS32 && (libent[fd].flags & FLAG_REQUIRED_MASK))
550 continue; 861 continue;
551 862
552 if (strcmp(fname, strs + libent[fd].sooffset) != 0) 863 if (strcmp(fname, strs + libent[fd].sooffset) != 0)
553 continue; 864 continue;
865
866 /* Return first hit because that is how the ldso rolls */
554 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf)); 867 strncpy(buf, strs + libent[fd].liboffset, sizeof(buf));
868 break;
555 } 869 }
870
556 return buf; 871 return buf;
557} 872}
558 873
874#elif defined(__NetBSD__)
875static char *lookup_cache_lib(elfobj *elf, const char *fname)
876{
877 static char buf[__PAX_UTILS_PATH_MAX] = "";
878 static struct stat st;
879 size_t n;
880 char *ldpath;
881
882 array_for_each(ldpath, n, ldpath) {
883 if ((unsigned) snprintf(buf, sizeof(buf), "%s/%s", ldpath, fname) >= sizeof(buf))
884 continue; /* if the pathname is too long, or something went wrong, ignore */
885
886 if (stat(buf, &st) != 0)
887 continue; /* if the lib doesn't exist in *ldpath, look further */
888
889 /* NetBSD doesn't actually do sanity checks, it just loads the file
890 * and if that doesn't work, continues looking in other directories.
891 * This cannot easily be safely emulated, unfortunately. For now,
892 * just assume that if it exists, it's a valid library. */
893
894 return buf;
895 }
896
897 /* not found in any path */
898 return NULL;
899}
900#else
901#ifdef __ELF__
902#warning Cache support not implemented for your target
903#endif
904static char *lookup_cache_lib(elfobj *elf, const char *fname)
905{
906 return NULL;
907}
908#endif
909
910static char *lookup_config_lib(const char *fname)
911{
912 static char buf[__PAX_UTILS_PATH_MAX] = "";
913 const char *ldpath;
914 size_t n;
915
916 array_for_each(ldpaths, n, ldpath) {
917 snprintf(buf, sizeof(buf), "%s/%s", root_rel_path(ldpath), fname);
918 if (faccessat(root_fd, buf, F_OK, AT_SYMLINK_NOFOLLOW) == 0)
919 return buf;
920 }
921
922 return NULL;
923}
559 924
560static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len) 925static const char *scanelf_file_needed_lib(elfobj *elf, char *found_needed, char *found_lib, int op, char **ret, size_t *ret_len)
561{ 926{
562 unsigned long i; 927 unsigned long i;
563 char *needed; 928 char *needed;
564 void *strtbl_void; 929 void *strtbl_void;
565 char *p; 930 char *p;
566 931
932 /*
933 * -n -> op==0 -> print all
934 * -N -> op==1 -> print requested
935 */
567 if ((op==0 && !show_needed) || (op==1 && !find_lib)) return NULL; 936 if ((op == 0 && !show_needed) || (op == 1 && !find_lib))
937 return NULL;
568 938
569 strtbl_void = elf_findsecbyname(elf, ".dynstr"); 939 strtbl_void = elf_findsecbyname(elf, ".dynstr");
570 940
571 if (elf->phdr && strtbl_void) { 941 if (elf->phdr && strtbl_void) {
572#define SHOW_NEEDED(B) \ 942#define SHOW_NEEDED(B) \
574 Elf ## B ## _Dyn *dyn; \ 944 Elf ## B ## _Dyn *dyn; \
575 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 945 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
576 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 946 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
577 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 947 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
578 Elf ## B ## _Off offset; \ 948 Elf ## B ## _Off offset; \
949 size_t matched = 0; \
950 /* Walk all the program headers to find the PT_DYNAMIC */ \
579 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 951 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
580 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 952 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) \
953 continue; \
581 offset = EGET(phdr[i].p_offset); \ 954 offset = EGET(phdr[i].p_offset); \
582 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 955 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) \
956 continue; \
957 /* Walk all the dynamic tags to find NEEDED entries */ \
583 dyn = DYN ## B (elf->data + offset); \ 958 dyn = DYN ## B (elf->vdata + offset); \
584 while (EGET(dyn->d_tag) != DT_NULL) { \ 959 while (EGET(dyn->d_tag) != DT_NULL) { \
585 if (EGET(dyn->d_tag) == DT_NEEDED) { \ 960 if (EGET(dyn->d_tag) == DT_NEEDED) { \
586 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 961 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
587 if (offset >= (Elf ## B ## _Off)elf->len) { \ 962 if (offset >= (Elf ## B ## _Off)elf->len) { \
588 ++dyn; \ 963 ++dyn; \
589 continue; \ 964 continue; \
590 } \ 965 } \
591 needed = (char*)(elf->data + offset); \ 966 needed = elf->data + offset; \
592 if (op == 0) { \ 967 if (op == 0) { \
968 /* -n -> print all entries */ \
593 if (!be_wewy_wewy_quiet) { \ 969 if (!be_wewy_wewy_quiet) { \
594 if (*found_needed) xchrcat(ret, ',', ret_len); \ 970 if (*found_needed) xchrcat(ret, ',', ret_len); \
595 if (printcache) \ 971 if (use_ldpath) { \
972 if ((p = lookup_config_lib(needed)) != NULL) \
973 needed = p; \
974 } else if (use_ldcache) { \
596 if ((p = lookup_cache_lib(elf, needed)) != NULL) \ 975 if ((p = lookup_cache_lib(elf, needed)) != NULL) \
597 needed = p; \ 976 needed = p; \
977 } \
598 xstrcat(ret, needed, ret_len); \ 978 xstrcat(ret, needed, ret_len); \
599 } \ 979 } \
600 *found_needed = 1; \ 980 *found_needed = 1; \
601 } else { \ 981 } else { \
602 if (!strncmp(find_lib, needed, strlen( !gmatch ? needed : find_lib))) { \ 982 /* -N -> print matching entries */ \
983 size_t n; \
984 const char *find_lib_name; \
985 \
986 array_for_each(find_lib_arr, n, find_lib_name) { \
987 int invert = 1; \
988 if (find_lib_name[0] == '!') \
989 invert = 0, ++find_lib_name; \
990 if (!strcmp(find_lib_name, needed) == invert) \
991 ++matched; \
992 } \
993 \
994 if (matched == array_cnt(find_lib_arr)) { \
603 *found_lib = 1; \ 995 *found_lib = 1; \
604 return (be_wewy_wewy_quiet ? NULL : needed); \ 996 return (be_wewy_wewy_quiet ? NULL : find_lib); \
605 } \ 997 } \
606 } \ 998 } \
607 } \ 999 } \
608 ++dyn; \ 1000 ++dyn; \
609 } \ 1001 } \
631 *found_interp = 1; \ 1023 *found_interp = 1; \
632 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \ 1024 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(strtbl->sh_offset)); \
633 } 1025 }
634 SHOW_INTERP(32) 1026 SHOW_INTERP(32)
635 SHOW_INTERP(64) 1027 SHOW_INTERP(64)
1028 } else {
1029 /* Walk all the program headers to find the PT_INTERP */
1030#define SHOW_PT_INTERP(B) \
1031 if (elf->elf_class == ELFCLASS ## B) { \
1032 unsigned long i; \
1033 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
1034 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
1035 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
1036 if (EGET(phdr[i].p_type) != PT_INTERP) \
1037 continue; \
1038 *found_interp = 1; \
1039 return (be_wewy_wewy_quiet ? NULL : elf->data + EGET(phdr[i].p_offset)); \
1040 } \
636 } 1041 }
1042 SHOW_PT_INTERP(32)
1043 SHOW_PT_INTERP(64)
1044 }
1045
637 return NULL; 1046 return NULL;
638} 1047}
639static char *scanelf_file_bind(elfobj *elf, char *found_bind) 1048static const char *scanelf_file_bind(elfobj *elf, char *found_bind)
640{ 1049{
641 unsigned long i; 1050 unsigned long i;
642 struct stat s; 1051 struct stat s;
1052 bool dynamic = false;
643 1053
644 if (!show_bind) return NULL; 1054 if (!show_bind) return NULL;
645 if (!elf->phdr) return NULL; 1055 if (!elf->phdr) return NULL;
646 1056
647#define SHOW_BIND(B) \ 1057#define SHOW_BIND(B) \
649 Elf ## B ## _Dyn *dyn; \ 1059 Elf ## B ## _Dyn *dyn; \
650 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1060 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
651 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1061 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
652 Elf ## B ## _Off offset; \ 1062 Elf ## B ## _Off offset; \
653 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1063 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
654 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1064 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
1065 dynamic = true; \
655 offset = EGET(phdr[i].p_offset); \ 1066 offset = EGET(phdr[i].p_offset); \
656 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1067 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
657 dyn = DYN ## B (elf->data + offset); \ 1068 dyn = DYN ## B (elf->vdata + offset); \
658 while (EGET(dyn->d_tag) != DT_NULL) { \ 1069 while (EGET(dyn->d_tag) != DT_NULL) { \
659 if (EGET(dyn->d_tag) == DT_BIND_NOW || \ 1070 if (EGET(dyn->d_tag) == DT_BIND_NOW || \
660 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \ 1071 (EGET(dyn->d_tag) == DT_FLAGS && EGET(dyn->d_un.d_val) & DF_BIND_NOW)) \
661 { \ 1072 { \
662 if (be_quiet) return NULL; \ 1073 if (be_quiet) return NULL; \
670 SHOW_BIND(32) 1081 SHOW_BIND(32)
671 SHOW_BIND(64) 1082 SHOW_BIND(64)
672 1083
673 if (be_wewy_wewy_quiet) return NULL; 1084 if (be_wewy_wewy_quiet) return NULL;
674 1085
1086 /* don't output anything if quiet mode and the ELF is static or not setuid */
675 if (be_quiet && !fstat(elf->fd, &s) && !(s.st_mode & S_ISUID || s.st_mode & S_ISGID)) { 1087 if (be_quiet && (!dynamic || (!fstat(elf->fd, &s) && !(s.st_mode & (S_ISUID|S_ISGID))))) {
676 return NULL; 1088 return NULL;
677 } else { 1089 } else {
678 *found_bind = 1; 1090 *found_bind = 1;
679 return (char *) "LAZY"; 1091 return dynamic ? "LAZY" : "STATIC";
680 } 1092 }
681} 1093}
682static char *scanelf_file_soname(elfobj *elf, char *found_soname) 1094static char *scanelf_file_soname(elfobj *elf, char *found_soname)
683{ 1095{
684 unsigned long i; 1096 unsigned long i;
696 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \ 1108 Elf ## B ## _Ehdr *ehdr = EHDR ## B (elf->ehdr); \
697 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \ 1109 Elf ## B ## _Phdr *phdr = PHDR ## B (elf->phdr); \
698 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \ 1110 Elf ## B ## _Shdr *strtbl = SHDR ## B (strtbl_void); \
699 Elf ## B ## _Off offset; \ 1111 Elf ## B ## _Off offset; \
700 /* only look for soname in shared objects */ \ 1112 /* only look for soname in shared objects */ \
701 if (ehdr->e_type != ET_DYN) \ 1113 if (EGET(ehdr->e_type) != ET_DYN) \
702 return NULL; \ 1114 return NULL; \
703 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \ 1115 for (i = 0; i < EGET(ehdr->e_phnum); i++) { \
704 if (EGET(phdr[i].p_type) != PT_DYNAMIC) continue; \ 1116 if (EGET(phdr[i].p_type) != PT_DYNAMIC || EGET(phdr[i].p_filesz) == 0) continue; \
705 offset = EGET(phdr[i].p_offset); \ 1117 offset = EGET(phdr[i].p_offset); \
706 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \ 1118 if (offset >= elf->len - sizeof(Elf ## B ## _Dyn)) continue; \
707 dyn = DYN ## B (elf->data + offset); \ 1119 dyn = DYN ## B (elf->vdata + offset); \
708 while (EGET(dyn->d_tag) != DT_NULL) { \ 1120 while (EGET(dyn->d_tag) != DT_NULL) { \
709 if (EGET(dyn->d_tag) == DT_SONAME) { \ 1121 if (EGET(dyn->d_tag) == DT_SONAME) { \
710 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \ 1122 offset = EGET(strtbl->sh_offset) + EGET(dyn->d_un.d_ptr); \
711 if (offset >= (Elf ## B ## _Off)elf->len) { \ 1123 if (offset >= (Elf ## B ## _Off)elf->len) { \
712 ++dyn; \ 1124 ++dyn; \
713 continue; \ 1125 continue; \
714 } \ 1126 } \
715 soname = (char*)(elf->data + offset); \ 1127 soname = elf->data + offset; \
716 *found_soname = 1; \ 1128 *found_soname = 1; \
717 return (be_wewy_wewy_quiet ? NULL : soname); \ 1129 return (be_wewy_wewy_quiet ? NULL : soname); \
718 } \ 1130 } \
719 ++dyn; \ 1131 ++dyn; \
720 } \ 1132 } \
723 SHOW_SONAME(64) 1135 SHOW_SONAME(64)
724 } 1136 }
725 1137
726 return NULL; 1138 return NULL;
727} 1139}
1140
1141/*
1142 * We support the symbol form:
1143 * [%[modifiers]%][[+-]<symbol name>][,[.....]]
1144 * If the symbol name is empty, then all symbols are matched.
1145 * If the symbol name is a glob ("*"), then all symbols are dumped (debug).
1146 * Do not rely on this output format at all.
1147 * Otherwise the symbol name is used to search (either regex or string compare).
1148 * If the first char of the symbol name is a plus ("+"), then only match
1149 * defined symbols. If it's a minus ("-"), only match undefined symbols.
1150 * Putting modifiers in between the percent signs allows for more in depth
1151 * filters. There are groups of modifiers. If you don't specify a member
1152 * of a group, then all types in that group are matched. The current
1153 * groups and their types are:
1154 * STT group: STT_NOTYPE:n STT_OBJECT:o STT_FUNC:f STT_FILE:F
1155 * STB group: STB_LOCAL:l STB_GLOBAL:g STB_WEAK:w
1156 * SHN group: SHN_UNDEF:u SHN_ABS:a SHN_COMMON:c {defined}:d
1157 * The "defined" value in the SHN group does not correspond to a SHN_xxx define.
1158 * You can search for multiple symbols at once by seperating with a comma (",").
1159 *
1160 * Some examples:
1161 * ELFs with a weak function "foo":
1162 * scanelf -s %wf%foo <ELFs>
1163 * ELFs that define the symbol "main":
1164 * scanelf -s +main <ELFs>
1165 * scanelf -s %d%main <ELFs>
1166 * ELFs that refer to the undefined symbol "brk":
1167 * scanelf -s -brk <ELFs>
1168 * scanelf -s %u%brk <ELFs>
1169 * All global defined objects in an ELF:
1170 * scanelf -s %ogd% <ELF>
1171 */
1172static void
1173scanelf_match_symname(elfobj *elf, char *found_sym, char **ret, size_t *ret_len, const char *symname,
1174 unsigned int stt, unsigned int stb, unsigned int shn, unsigned long size)
1175{
1176 const char *this_sym;
1177 size_t n;
1178
1179 array_for_each(find_sym_arr, n, this_sym) {
1180 bool inc_notype, inc_object, inc_func, inc_file,
1181 inc_local, inc_global, inc_weak,
1182 inc_def, inc_undef, inc_abs, inc_common;
1183
1184 /* symbol selection! */
1185 inc_notype = inc_object = inc_func = inc_file = \
1186 inc_local = inc_global = inc_weak = \
1187 inc_def = inc_undef = inc_abs = inc_common = \
1188 (*this_sym != '%');
1189
1190 /* parse the contents of %...% */
1191 if (!inc_notype) {
1192 while (*(this_sym++)) {
1193 if (*this_sym == '%') {
1194 ++this_sym;
1195 break;
1196 }
1197 switch (*this_sym) {
1198 case 'n': inc_notype = true; break;
1199 case 'o': inc_object = true; break;
1200 case 'f': inc_func = true; break;
1201 case 'F': inc_file = true; break;
1202 case 'l': inc_local = true; break;
1203 case 'g': inc_global = true; break;
1204 case 'w': inc_weak = true; break;
1205 case 'd': inc_def = true; break;
1206 case 'u': inc_undef = true; break;
1207 case 'a': inc_abs = true; break;
1208 case 'c': inc_common = true; break;
1209 default: err("invalid symbol selector '%c'", *this_sym);
1210 }
1211 }
1212
1213 /* If no types are matched, not match all */
1214 if (!inc_notype && !inc_object && !inc_func && !inc_file)
1215 inc_notype = inc_object = inc_func = inc_file = true;
1216 if (!inc_local && !inc_global && !inc_weak)
1217 inc_local = inc_global = inc_weak = true;
1218 if (!inc_def && !inc_undef && !inc_abs && !inc_common)
1219 inc_def = inc_undef = inc_abs = inc_common = true;
1220
1221 /* backwards compat for defined/undefined short hand */
1222 } else if (*this_sym == '+') {
1223 inc_undef = false;
1224 ++this_sym;
1225 } else if (*this_sym == '-') {
1226 inc_def = inc_abs = inc_common = false;
1227 ++this_sym;
1228 }
1229
1230 /* filter symbols */
1231 if ((!inc_notype && stt == STT_NOTYPE) || \
1232 (!inc_object && stt == STT_OBJECT) || \
1233 (!inc_func && stt == STT_FUNC ) || \
1234 (!inc_file && stt == STT_FILE ) || \
1235 (!inc_local && stb == STB_LOCAL ) || \
1236 (!inc_global && stb == STB_GLOBAL) || \
1237 (!inc_weak && stb == STB_WEAK ) || \
1238 (!inc_def && shn && shn < SHN_LORESERVE) || \
1239 (!inc_undef && shn == SHN_UNDEF ) || \
1240 (!inc_abs && shn == SHN_ABS ) || \
1241 (!inc_common && shn == SHN_COMMON))
1242 continue;
1243
1244 if (*this_sym == '*') {
1245 /* a "*" symbol gets you debug output */
1246 printf("%s(%s) %5lX %15s %15s %15s %s\n",
1247 ((*found_sym == 0) ? "\n\t" : "\t"),
1248 elf->base_filename,
1249 size,
1250 get_elfstttype(stt),
1251 get_elfstbtype(stb),
1252 get_elfshntype(shn),
1253 symname);
1254 goto matched;
1255
1256 } else {
1257 if (g_match) {
1258 /* regex match the symbol */
1259 if (regexec(find_sym_regex_arr->eles[n], symname, 0, NULL, 0) == REG_NOMATCH)
1260 continue;
1261
1262 } else if (*this_sym) {
1263 /* give empty symbols a "pass", else do a normal compare */
1264 const size_t len = strlen(this_sym);
1265 if (!(strncmp(this_sym, symname, len) == 0 &&
1266 /* Accept unversioned symbol names */
1267 (symname[len] == '\0' || symname[len] == '@')))
1268 continue;
1269 }
1270
1271 if (be_semi_verbose) {
1272 char buf[1024];
1273 snprintf(buf, sizeof(buf), "%lX %s %s",
1274 size,
1275 get_elfstttype(stt),
1276 this_sym);
1277 *ret = xstrdup(buf);
1278 } else {
1279 if (*ret) xchrcat(ret, ',', ret_len);
1280 xstrcat(ret, symname, ret_len);
1281 }
1282
1283 goto matched;
1284 }
1285 }
1286
1287 return;
1288
1289 matched:
1290 *found_sym = 1;
1291}
1292
728static char *scanelf_file_sym(elfobj *elf, char *found_sym) 1293static const char *scanelf_file_sym(elfobj *elf, char *found_sym)
729{ 1294{
730 unsigned long i;
731 char *ret; 1295 char *ret;
732 void *symtab_void, *strtab_void; 1296 void *symtab_void, *strtab_void;
733 1297
734 if (!find_sym) return NULL; 1298 if (!find_sym) return NULL;
735 ret = find_sym; 1299 ret = NULL;
736 1300
737 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void); 1301 scanelf_file_get_symtabs(elf, &symtab_void, &strtab_void);
738 1302
739 if (symtab_void && strtab_void) { 1303 if (symtab_void && strtab_void) {
740#define FIND_SYM(B) \ 1304#define FIND_SYM(B) \
741 if (elf->elf_class == ELFCLASS ## B) { \ 1305 if (elf->elf_class == ELFCLASS ## B) { \
742 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \ 1306 Elf ## B ## _Shdr *symtab = SHDR ## B (symtab_void); \
743 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \ 1307 Elf ## B ## _Shdr *strtab = SHDR ## B (strtab_void); \
744 Elf ## B ## _Sym *sym = SYM ## B (elf->data + EGET(symtab->sh_offset)); \ 1308 Elf ## B ## _Sym *sym = SYM ## B (elf->vdata + EGET(symtab->sh_offset)); \
745 unsigned long cnt = EGET(symtab->sh_size) / EGET(symtab->sh_entsize); \ 1309 Elf ## B ## _Word i, cnt = EGET(symtab->sh_entsize); \
746 char *symname; \ 1310 char *symname; \
1311 size_t ret_len = 0; \
1312 if (cnt) \
1313 cnt = EGET(symtab->sh_size) / cnt; \
747 for (i = 0; i < cnt; ++i) { \ 1314 for (i = 0; i < cnt; ++i) { \
1315 if ((void*)sym > elf->data_end) { \
1316 warnf("%s: corrupt ELF symbols - aborting", elf->filename); \
1317 goto break_out; \
1318 } \
748 if (sym->st_name) { \ 1319 if (sym->st_name) { \
1320 /* make sure the symbol name is in acceptable memory range */ \
749 symname = (char *)(elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name)); \ 1321 symname = elf->data + EGET(strtab->sh_offset) + EGET(sym->st_name); \
750 if (*find_sym == '*') { \ 1322 if ((void*)symname > elf->data_end) { \
751 printf("%s(%s) %5lX %15s %s\n", \ 1323 warnf("%s: corrupt ELF symbols", elf->filename); \
752 ((*found_sym == 0) ? "\n\t" : "\t"), \ 1324 ++sym; \
753 elf->base_filename, \ 1325 continue; \
754 (unsigned long)sym->st_size, \
755 get_elfstttype(sym->st_info), \
756 symname); \
757 *found_sym = 1; \
758 } else { \
759 char *this_sym, *next_sym; \
760 this_sym = find_sym; \
761 do { \
762 next_sym = strchr(this_sym, ','); \
763 if (next_sym == NULL) \
764 next_sym = this_sym + strlen(this_sym); \
765 if ((strncmp(this_sym, symname, (next_sym-this_sym)) == 0 && symname[next_sym-this_sym] == '\0') || \
766 (strcmp(symname, versioned_symname) == 0)) { \
767 ret = this_sym; \
768 (*found_sym)++; \
769 goto break_out; \
770 } \
771 this_sym = next_sym + 1; \
772 } while (*next_sym != '\0'); \
773 } \ 1326 } \
1327 scanelf_match_symname(elf, found_sym, \
1328 &ret, &ret_len, symname, \
1329 ELF##B##_ST_TYPE(EGET(sym->st_info)), \
1330 ELF##B##_ST_BIND(EGET(sym->st_info)), \
1331 EGET(sym->st_shndx), \
1332 /* st_size can be 64bit, but no one is really that big, so screw em */ \
1333 EGET(sym->st_size)); \
774 } \ 1334 } \
775 ++sym; \ 1335 ++sym; \
776 } } 1336 } \
1337 }
777 FIND_SYM(32) 1338 FIND_SYM(32)
778 FIND_SYM(64) 1339 FIND_SYM(64)
779 } 1340 }
780 1341
781break_out: 1342break_out:
784 if (*find_sym != '*' && *found_sym) 1345 if (*find_sym != '*' && *found_sym)
785 return ret; 1346 return ret;
786 if (be_quiet) 1347 if (be_quiet)
787 return NULL; 1348 return NULL;
788 else 1349 else
789 return (char *)" - "; 1350 return " - ";
790} 1351}
1352
1353static const char *scanelf_file_sections(elfobj *elf, char *found_section)
1354{
1355 if (!find_section)
1356 return NULL;
1357
1358#define FIND_SECTION(B) \
1359 if (elf->elf_class == ELFCLASS ## B) { \
1360 size_t matched, n; \
1361 int invert; \
1362 const char *section_name; \
1363 Elf ## B ## _Shdr *section; \
1364 \
1365 matched = 0; \
1366 array_for_each(find_section_arr, n, section_name) { \
1367 invert = (*section_name == '!' ? 1 : 0); \
1368 section = SHDR ## B (elf_findsecbyname(elf, section_name + invert)); \
1369 if ((section == NULL && invert) || (section != NULL && !invert)) \
1370 ++matched; \
1371 } \
1372 \
1373 if (matched == array_cnt(find_section_arr)) \
1374 *found_section = 1; \
1375 }
1376 FIND_SECTION(32)
1377 FIND_SECTION(64)
1378
1379 if (be_wewy_wewy_quiet)
1380 return NULL;
1381
1382 if (*found_section)
1383 return find_section;
1384
1385 if (be_quiet)
1386 return NULL;
1387 else
1388 return " - ";
1389}
1390
791/* scan an elf file and show all the fun stuff */ 1391/* scan an elf file and show all the fun stuff */
792#define prints(str) write(fileno(stdout), str, strlen(str)) 1392#define prints(str) ({ ssize_t ret = write(fileno(stdout), str, strlen(str)); ret; })
793static void scanelf_file(const char *filename) 1393static int scanelf_elfobj(elfobj *elf)
794{ 1394{
795 unsigned long i; 1395 unsigned long i;
796 char found_pax, found_phdr, found_relro, found_load, found_textrel, 1396 char found_pax, found_phdr, found_relro, found_load, found_textrel,
797 found_rpath, found_needed, found_interp, found_bind, found_soname, 1397 found_rpath, found_needed, found_interp, found_bind, found_soname,
798 found_sym, found_lib, found_file, found_textrels; 1398 found_sym, found_lib, found_file, found_textrels, found_section;
799 elfobj *elf;
800 struct stat st;
801 static char *out_buffer = NULL; 1399 static char *out_buffer = NULL;
802 static size_t out_len; 1400 static size_t out_len;
803 1401
804 /* make sure 'filename' exists */
805 if (lstat(filename, &st) == -1) {
806 if (be_verbose > 2) printf("%s: does not exist\n", filename);
807 return;
808 }
809 /* always handle regular files and handle symlinked files if no -y */
810 if (S_ISLNK(st.st_mode)) {
811 if (!scan_symlink) return;
812 stat(filename, &st);
813 }
814 if (!S_ISREG(st.st_mode)) {
815 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
816 return;
817 }
818
819 found_pax = found_phdr = found_relro = found_load = found_textrel = \ 1402 found_pax = found_phdr = found_relro = found_load = found_textrel = \
820 found_rpath = found_needed = found_interp = found_bind = found_soname = \ 1403 found_rpath = found_needed = found_interp = found_bind = found_soname = \
821 found_sym = found_lib = found_file = found_textrels = 0; 1404 found_sym = found_lib = found_file = found_textrels = found_section = 0;
822 1405
823 /* verify this is real ELF */
824 if ((elf = readelf(filename)) == NULL) {
825 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
826 return;
827 }
828
829 if (be_verbose > 1) 1406 if (be_verbose > 2)
830 printf("%s: scanning file {%s,%s}\n", filename, 1407 printf("%s: scanning file {%s,%s}\n", elf->filename,
831 get_elfeitype(EI_CLASS, elf->elf_class), 1408 get_elfeitype(EI_CLASS, elf->elf_class),
832 get_elfeitype(EI_DATA, elf->data[EI_DATA])); 1409 get_elfeitype(EI_DATA, elf->data[EI_DATA]));
833 else if (be_verbose) 1410 else if (be_verbose > 1)
834 printf("%s: scanning file\n", filename); 1411 printf("%s: scanning file\n", elf->filename);
835 1412
836 /* init output buffer */ 1413 /* init output buffer */
837 if (!out_buffer) { 1414 if (!out_buffer) {
838 out_len = sizeof(char) * 80; 1415 out_len = sizeof(char) * 80;
839 out_buffer = (char*)xmalloc(out_len); 1416 out_buffer = xmalloc(out_len);
840 } 1417 }
841 *out_buffer = '\0'; 1418 *out_buffer = '\0';
842 1419
843 /* show the header */ 1420 /* show the header */
844 if (!be_quiet && show_banner) { 1421 if (!be_quiet && show_banner) {
845 for (i = 0; out_format[i]; ++i) { 1422 for (i = 0; out_format[i]; ++i) {
846 if (!IS_MODIFIER(out_format[i])) continue; 1423 if (!IS_MODIFIER(out_format[i])) continue;
847 1424
848 switch (out_format[++i]) { 1425 switch (out_format[++i]) {
1426 case '+': break;
849 case '%': break; 1427 case '%': break;
850 case '#': break; 1428 case '#': break;
851 case 'F': 1429 case 'F':
852 case 'p': 1430 case 'p':
853 case 'f': prints("FILE "); found_file = 1; break; 1431 case 'f': prints("FILE "); found_file = 1; break;
854 case 'o': prints(" TYPE "); break; 1432 case 'o': prints(" TYPE "); break;
855 case 'x': prints(" PAX "); break; 1433 case 'x': prints(" PAX "); break;
856 case 'e': prints("STK/REL/PTL "); break; 1434 case 'e': prints("STK/REL/PTL "); break;
857 case 't': prints("TEXTREL "); break; 1435 case 't': prints("TEXTREL "); break;
858 case 'r': prints("RPATH "); break; 1436 case 'r': prints("RPATH "); break;
1437 case 'M': prints("CLASS "); break;
1438 case 'l':
859 case 'n': prints("NEEDED "); break; 1439 case 'n': prints("NEEDED "); break;
860 case 'i': prints("INTERP "); break; 1440 case 'i': prints("INTERP "); break;
861 case 'b': prints("BIND "); break; 1441 case 'b': prints("BIND "); break;
1442 case 'Z': prints("SIZE "); break;
862 case 'S': prints("SONAME "); break; 1443 case 'S': prints("SONAME "); break;
863 case 's': prints("SYM "); break; 1444 case 's': prints("SYM "); break;
864 case 'N': prints("LIB "); break; 1445 case 'N': prints("LIB "); break;
865 case 'T': prints("TEXTRELS "); break; 1446 case 'T': prints("TEXTRELS "); break;
1447 case 'k': prints("SECTION "); break;
1448 case 'a': prints("ARCH "); break;
1449 case 'I': prints("OSABI "); break;
1450 case 'Y': prints("EABI "); break;
1451 case 'O': prints("PERM "); break;
1452 case 'D': prints("ENDIAN "); break;
866 default: warnf("'%c' has no title ?", out_format[i]); 1453 default: warnf("'%c' has no title ?", out_format[i]);
867 } 1454 }
868 } 1455 }
869 if (!found_file) prints("FILE "); 1456 if (!found_file) prints("FILE ");
870 prints("\n"); 1457 prints("\n");
874 1461
875 /* dump all the good stuff */ 1462 /* dump all the good stuff */
876 for (i = 0; out_format[i]; ++i) { 1463 for (i = 0; out_format[i]; ++i) {
877 const char *out; 1464 const char *out;
878 const char *tmp; 1465 const char *tmp;
879 1466 static char ubuf[sizeof(unsigned long)*2];
880 /* make sure we trim leading spaces in quiet mode */
881 if (be_quiet && *out_buffer == ' ' && !out_buffer[1])
882 *out_buffer = '\0';
883
884 if (!IS_MODIFIER(out_format[i])) { 1467 if (!IS_MODIFIER(out_format[i])) {
885 xchrcat(&out_buffer, out_format[i], &out_len); 1468 xchrcat(&out_buffer, out_format[i], &out_len);
886 continue; 1469 continue;
887 } 1470 }
888 1471
889 out = NULL; 1472 out = NULL;
890 be_wewy_wewy_quiet = (out_format[i] == '#'); 1473 be_wewy_wewy_quiet = (out_format[i] == '#');
1474 be_semi_verbose = (out_format[i] == '+');
891 switch (out_format[++i]) { 1475 switch (out_format[++i]) {
1476 case '+':
892 case '%': 1477 case '%':
893 case '#': 1478 case '#':
894 xchrcat(&out_buffer, out_format[i], &out_len); break; 1479 xchrcat(&out_buffer, out_format[i], &out_len); break;
895 case 'F': 1480 case 'F':
896 found_file = 1; 1481 found_file = 1;
897 if (be_wewy_wewy_quiet) break; 1482 if (be_wewy_wewy_quiet) break;
898 xstrcat(&out_buffer, filename, &out_len); 1483 xstrcat(&out_buffer, elf->filename, &out_len);
899 break; 1484 break;
900 case 'p': 1485 case 'p':
901 found_file = 1; 1486 found_file = 1;
902 if (be_wewy_wewy_quiet) break; 1487 if (be_wewy_wewy_quiet) break;
903 tmp = filename; 1488 tmp = elf->filename;
904 if (search_path) { 1489 if (search_path) {
905 ssize_t len_search = strlen(search_path); 1490 ssize_t len_search = strlen(search_path);
906 ssize_t len_file = strlen(filename); 1491 ssize_t len_file = strlen(elf->filename);
907 if (!strncmp(filename, search_path, len_search) && \ 1492 if (!strncmp(elf->filename, search_path, len_search) && \
908 len_file > len_search) 1493 len_file > len_search)
909 tmp += len_search; 1494 tmp += len_search;
910 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++; 1495 if (*tmp == '/' && search_path[len_search-1] == '/') tmp++;
911 } 1496 }
912 xstrcat(&out_buffer, tmp, &out_len); 1497 xstrcat(&out_buffer, tmp, &out_len);
913 break; 1498 break;
914 case 'f': 1499 case 'f':
915 found_file = 1; 1500 found_file = 1;
916 if (be_wewy_wewy_quiet) break; 1501 if (be_wewy_wewy_quiet) break;
917 tmp = strrchr(filename, '/'); 1502 tmp = strrchr(elf->filename, '/');
918 tmp = (tmp == NULL ? filename : tmp+1); 1503 tmp = (tmp == NULL ? elf->filename : tmp+1);
919 xstrcat(&out_buffer, tmp, &out_len); 1504 xstrcat(&out_buffer, tmp, &out_len);
920 break; 1505 break;
921 case 'o': out = get_elfetype(elf); break; 1506 case 'o': out = get_elfetype(elf); break;
922 case 'x': out = scanelf_file_pax(elf, &found_pax); break; 1507 case 'x': out = scanelf_file_pax(elf, &found_pax); break;
923 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break; 1508 case 'e': out = scanelf_file_phdr(elf, &found_phdr, &found_relro, &found_load); break;
924 case 't': out = scanelf_file_textrel(elf, &found_textrel); break; 1509 case 't': out = scanelf_file_textrel(elf, &found_textrel); break;
925 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break; 1510 case 'T': out = scanelf_file_textrels(elf, &found_textrels, &found_textrel); break;
926 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break; 1511 case 'r': scanelf_file_rpath(elf, &found_rpath, &out_buffer, &out_len); break;
1512 case 'M': out = get_elfeitype(EI_CLASS, elf->data[EI_CLASS]); break;
1513 case 'D': out = get_endian(elf); break;
1514 case 'O': out = strfileperms(elf->filename); break;
927 case 'n': 1515 case 'n':
928 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break; 1516 case 'N': out = scanelf_file_needed_lib(elf, &found_needed, &found_lib, (out_format[i]=='N'), &out_buffer, &out_len); break;
929 case 'i': out = scanelf_file_interp(elf, &found_interp); break; 1517 case 'i': out = scanelf_file_interp(elf, &found_interp); break;
930 case 'b': out = scanelf_file_bind(elf, &found_bind); break; 1518 case 'b': out = scanelf_file_bind(elf, &found_bind); break;
931 case 'S': out = scanelf_file_soname(elf, &found_soname); break; 1519 case 'S': out = scanelf_file_soname(elf, &found_soname); break;
932 case 's': out = scanelf_file_sym(elf, &found_sym); break; 1520 case 's': out = scanelf_file_sym(elf, &found_sym); break;
1521 case 'k': out = scanelf_file_sections(elf, &found_section); break;
1522 case 'a': out = get_elfemtype(elf); break;
1523 case 'I': out = get_elfosabi(elf); break;
1524 case 'Y': out = get_elf_eabi(elf); break;
1525 case 'Z': snprintf(ubuf, sizeof(ubuf), "%lu", (unsigned long)elf->len); out = ubuf; break;;
933 default: warnf("'%c' has no scan code?", out_format[i]); 1526 default: warnf("'%c' has no scan code?", out_format[i]);
934 } 1527 }
935 if (out) { 1528 if (out)
936 /* hack for comma delimited output like `scanelf -s sym1,sym2,sym3` */
937 if (out_format[i] == 's' && (tmp=strchr(out,',')) != NULL)
938 xstrncat(&out_buffer, out, &out_len, (tmp-out));
939 else
940 xstrcat(&out_buffer, out, &out_len); 1529 xstrcat(&out_buffer, out, &out_len);
941 }
942 } 1530 }
943 1531
944#define FOUND_SOMETHING() \ 1532#define FOUND_SOMETHING() \
945 (found_pax || found_phdr || found_relro || found_load || found_textrel || \ 1533 (found_pax || found_phdr || found_relro || found_load || found_textrel || \
946 found_rpath || found_needed || found_interp || found_bind || \ 1534 found_rpath || found_needed || found_interp || found_bind || \
947 found_soname || found_sym || found_lib || found_textrels) 1535 found_soname || found_sym || found_lib || found_textrels || found_section )
948 1536
949 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) { 1537 if (!found_file && (!be_quiet || (be_quiet && FOUND_SOMETHING()))) {
950 xchrcat(&out_buffer, ' ', &out_len); 1538 xchrcat(&out_buffer, ' ', &out_len);
951 xstrcat(&out_buffer, filename, &out_len); 1539 xstrcat(&out_buffer, elf->filename, &out_len);
952 } 1540 }
953 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) { 1541 if (!be_quiet || (be_quiet && FOUND_SOMETHING())) {
954 puts(out_buffer); 1542 puts(out_buffer);
955 fflush(stdout); 1543 fflush(stdout);
956 } 1544 }
957 1545
1546 return 0;
1547}
1548
1549/* scan a single elf */
1550static int scanelf_elf(const char *filename, int fd, size_t len)
1551{
1552 int ret = 1;
1553 elfobj *elf;
1554
1555 /* verify this is real ELF */
1556 if ((elf = _readelf_fd(filename, fd, len, !fix_elf)) == NULL) {
1557 if (be_verbose > 2) printf("%s: not an ELF\n", filename);
1558 return 2;
1559 }
1560 switch (match_bits) {
1561 case 32:
1562 if (elf->elf_class != ELFCLASS32)
1563 goto label_done;
1564 break;
1565 case 64:
1566 if (elf->elf_class != ELFCLASS64)
1567 goto label_done;
1568 break;
1569 default: break;
1570 }
1571 if (match_etypes) {
1572 char sbuf[126];
1573 strncpy(sbuf, match_etypes, sizeof(sbuf));
1574 if (strchr(match_etypes, ',') != NULL) {
1575 char *p;
1576 while ((p = strrchr(sbuf, ',')) != NULL) {
1577 *p = 0;
1578 if (etype_lookup(p+1) == get_etype(elf))
1579 goto label_ret;
1580 }
1581 }
1582 if (etype_lookup(sbuf) != get_etype(elf))
1583 goto label_done;
1584 }
1585
1586label_ret:
1587 ret = scanelf_elfobj(elf);
1588
1589label_done:
958 unreadelf(elf); 1590 unreadelf(elf);
1591 return ret;
1592}
1593
1594/* scan an archive of elfs */
1595static int scanelf_archive(const char *filename, int fd, size_t len)
1596{
1597 archive_handle *ar;
1598 archive_member *m;
1599 char *ar_buffer;
1600 elfobj *elf;
1601
1602 ar = ar_open_fd(filename, fd);
1603 if (ar == NULL)
1604 return 1;
1605
1606 ar_buffer = mmap(0, len, PROT_READ | (fix_elf ? PROT_WRITE : 0), (fix_elf ? MAP_SHARED : MAP_PRIVATE), fd, 0);
1607 while ((m = ar_next(ar)) != NULL) {
1608 off_t cur_pos = lseek(fd, 0, SEEK_CUR);
1609 if (cur_pos == -1)
1610 errp("lseek() failed");
1611 elf = readelf_buffer(m->name, ar_buffer + cur_pos, m->size);
1612 if (elf) {
1613 scanelf_elfobj(elf);
1614 unreadelf(elf);
1615 }
1616 }
1617 munmap(ar_buffer, len);
1618
1619 return 0;
1620}
1621/* scan a file which may be an elf or an archive or some other magical beast */
1622static int scanelf_fileat(int dir_fd, const char *filename, const struct stat *st_cache)
1623{
1624 const struct stat *st = st_cache;
1625 struct stat symlink_st;
1626 int fd;
1627
1628 /* always handle regular files and handle symlinked files if no -y */
1629 if (S_ISLNK(st->st_mode)) {
1630 if (!scan_symlink)
1631 return 1;
1632 fstatat(dir_fd, filename, &symlink_st, 0);
1633 st = &symlink_st;
1634 }
1635
1636 if (!S_ISREG(st->st_mode)) {
1637 if (be_verbose > 2) printf("%s: skipping non-file\n", filename);
1638 return 1;
1639 }
1640
1641 if (match_perms) {
1642 if ((st->st_mode | match_perms) != st->st_mode)
1643 return 1;
1644 }
1645 fd = openat(dir_fd, filename, (fix_elf ? O_RDWR : O_RDONLY) | O_CLOEXEC);
1646 if (fd == -1) {
1647 if (fix_elf && errno == ETXTBSY)
1648 warnp("%s: could not fix", filename);
1649 else if (be_verbose > 2)
1650 printf("%s: skipping file: %s\n", filename, strerror(errno));
1651 return 1;
1652 }
1653
1654 if (scanelf_elf(filename, fd, st->st_size) == 2) {
1655 /* if it isn't an ELF, maybe it's an .a archive */
1656 if (scan_archives)
1657 scanelf_archive(filename, fd, st->st_size);
1658
1659 /*
1660 * unreadelf() implicitly closes its fd, so only close it
1661 * when we are returning it in the non-ELF case
1662 */
1663 close(fd);
1664 }
1665
1666 return 0;
959} 1667}
960 1668
961/* scan a directory for ET_EXEC files and print when we find one */ 1669/* scan a directory for ET_EXEC files and print when we find one */
962static void scanelf_dir(const char *path) 1670static int scanelf_dirat(int dir_fd, const char *path)
963{ 1671{
964 register DIR *dir; 1672 register DIR *dir;
965 register struct dirent *dentry; 1673 register struct dirent *dentry;
966 struct stat st_top, st; 1674 struct stat st_top, st;
967 char buf[_POSIX_PATH_MAX]; 1675 char buf[__PAX_UTILS_PATH_MAX], *subpath;
968 size_t pathlen = 0, len = 0; 1676 size_t pathlen = 0, len = 0;
1677 int ret = 0;
1678 int subdir_fd;
969 1679
970 /* make sure path exists */ 1680 /* make sure path exists */
971 if (lstat(path, &st_top) == -1) { 1681 if (fstatat(dir_fd, path, &st_top, AT_SYMLINK_NOFOLLOW) == -1) {
972 if (be_verbose > 2) printf("%s: does not exist\n", path); 1682 if (be_verbose > 2) printf("%s: does not exist\n", path);
973 return; 1683 return 1;
974 } 1684 }
975 1685
976 /* ok, if it isn't a directory, assume we can open it */ 1686 /* ok, if it isn't a directory, assume we can open it */
977 if (!S_ISDIR(st_top.st_mode)) { 1687 if (!S_ISDIR(st_top.st_mode))
978 scanelf_file(path); 1688 return scanelf_fileat(dir_fd, path, &st_top);
979 return;
980 }
981 1689
982 /* now scan the dir looking for fun stuff */ 1690 /* now scan the dir looking for fun stuff */
983 if ((dir = opendir(path)) == NULL) { 1691 subdir_fd = openat(dir_fd, path, O_RDONLY|O_CLOEXEC);
984 warnf("could not opendir %s: %s", path, strerror(errno)); 1692 if (subdir_fd == -1)
1693 dir = NULL;
1694 else
1695 dir = fdopendir(subdir_fd);
1696 if (dir == NULL) {
1697 if (subdir_fd != -1)
1698 close(subdir_fd);
1699 else if (be_verbose > 2)
1700 printf("%s: skipping dir: %s\n", path, strerror(errno));
985 return; 1701 return 1;
986 } 1702 }
987 if (be_verbose) printf("%s: scanning dir\n", path); 1703 if (be_verbose > 1) printf("%s: scanning dir\n", path);
988 1704
989 pathlen = strlen(path); 1705 subpath = stpcpy(buf, path);
1706 if (subpath[-1] != '/')
1707 *subpath++ = '/';
1708 pathlen = subpath - buf;
990 while ((dentry = readdir(dir))) { 1709 while ((dentry = readdir(dir))) {
991 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, "..")) 1710 if (!strcmp(dentry->d_name, ".") || !strcmp(dentry->d_name, ".."))
992 continue; 1711 continue;
993 len = (pathlen + 1 + strlen(dentry->d_name) + 1); 1712
994 if (len >= sizeof(buf)) { 1713 if (fstatat(subdir_fd, dentry->d_name, &st, AT_SYMLINK_NOFOLLOW) == -1)
995 warnf("Skipping '%s': len > sizeof(buf); %lu > %lu\n", path,
996 (unsigned long)len, (unsigned long)sizeof(buf));
997 continue; 1714 continue;
1715
1716 len = strlen(dentry->d_name);
1717 if (len + pathlen + 1 >= sizeof(buf)) {
1718 warnf("Skipping '%s%s': len > sizeof(buf); %zu > %zu\n",
1719 path, dentry->d_name, len + pathlen + 1, sizeof(buf));
1720 continue;
998 } 1721 }
999 sprintf(buf, "%s/%s", path, dentry->d_name); 1722 memcpy(subpath, dentry->d_name, len);
1000 if (lstat(buf, &st) != -1) { 1723 subpath[len] = '\0';
1724
1001 if (S_ISREG(st.st_mode)) 1725 if (S_ISREG(st.st_mode))
1002 scanelf_file(buf); 1726 ret = scanelf_fileat(dir_fd, buf, &st);
1003 else if (dir_recurse && S_ISDIR(st.st_mode)) { 1727 else if (dir_recurse && S_ISDIR(st.st_mode)) {
1004 if (dir_crossmount || (st_top.st_dev == st.st_dev)) 1728 if (dir_crossmount || (st_top.st_dev == st.st_dev))
1005 scanelf_dir(buf); 1729 ret = scanelf_dirat(dir_fd, buf);
1006 }
1007 } 1730 }
1008 } 1731 }
1009 closedir(dir); 1732 closedir(dir);
1010}
1011 1733
1734 return ret;
1735}
1736static int scanelf_dir(const char *path)
1737{
1738 return scanelf_dirat(root_fd, root_rel_path(path));
1739}
1740
1012static int scanelf_from_file(char *filename) 1741static int scanelf_from_file(const char *filename)
1013{ 1742{
1014 FILE *fp = NULL; 1743 FILE *fp;
1015 char *p; 1744 char *p, *path;
1016 char path[_POSIX_PATH_MAX]; 1745 size_t len;
1746 int ret;
1017 1747
1018 if (((strcmp(filename, "-")) == 0) && (ttyname(0) == NULL)) 1748 if (strcmp(filename, "-") == 0)
1019 fp = stdin; 1749 fp = stdin;
1020 else if ((fp = fopen(filename, "r")) == NULL) 1750 else if ((fp = fopen(filename, "r")) == NULL)
1021 return 1; 1751 return 1;
1022 1752
1023 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1753 path = NULL;
1754 len = 0;
1755 ret = 0;
1756 while (getline(&path, &len, fp) != -1) {
1024 if ((p = strchr(path, '\n')) != NULL) 1757 if ((p = strchr(path, '\n')) != NULL)
1025 *p = 0; 1758 *p = 0;
1026 search_path = path; 1759 search_path = path;
1027 scanelf_dir(path); 1760 ret = scanelf_dir(path);
1028 } 1761 }
1762 free(path);
1763
1029 if (fp != stdin) 1764 if (fp != stdin)
1030 fclose(fp); 1765 fclose(fp);
1766
1031 return 0; 1767 return ret;
1032} 1768}
1033 1769
1034static void load_ld_so_conf() 1770#if defined(__GLIBC__) || defined(__UCLIBC__) || defined(__NetBSD__)
1771
1772static int _load_ld_cache_config(const char *fname)
1035{ 1773{
1036 FILE *fp = NULL; 1774 FILE *fp = NULL;
1037 char *p; 1775 char *p, *path;
1038 char path[_POSIX_PATH_MAX]; 1776 size_t len;
1039 int i = 0; 1777 int curr_fd = -1;
1040 1778
1041 if ((fp = fopen("/etc/ld.so.conf", "r")) == NULL) 1779 fp = fopenat_r(root_fd, root_rel_path(fname));
1780 if (fp == NULL)
1042 return; 1781 return -1;
1043 1782
1044 while ((fgets(path, _POSIX_PATH_MAX, fp)) != NULL) { 1783 path = NULL;
1045 if (*path != '/') 1784 len = 0;
1046 continue; 1785 while (getline(&path, &len, fp) != -1) {
1047
1048 if ((p = strrchr(path, '\r')) != NULL) 1786 if ((p = strrchr(path, '\r')) != NULL)
1049 *p = 0; 1787 *p = 0;
1050 if ((p = strchr(path, '\n')) != NULL) 1788 if ((p = strchr(path, '\n')) != NULL)
1051 *p = 0; 1789 *p = 0;
1052 1790
1053 ldpaths[i++] = xstrdup(path); 1791 /* recursive includes of the same file will make this segfault. */
1792 if ((memcmp(path, "include", 7) == 0) && isblank(path[7])) {
1793 glob_t gl;
1794 size_t x;
1795 const char *gpath;
1054 1796
1055 if (i + 1 == sizeof(ldpaths) / sizeof(*ldpaths)) 1797 /* re-use existing path buffer ... need to be creative */
1056 break; 1798 if (path[8] != '/')
1799 gpath = memcpy(path + 3, "/etc/", 5);
1800 else
1801 gpath = path + 8;
1802 if (root_fd != AT_FDCWD) {
1803 if (curr_fd == -1) {
1804 curr_fd = open(".", O_RDONLY|O_CLOEXEC);
1805 if (fchdir(root_fd))
1806 errp("unable to change to root dir");
1807 }
1808 gpath = root_rel_path(gpath);
1809 }
1810
1811 if (glob(gpath, 0, NULL, &gl) == 0) {
1812 for (x = 0; x < gl.gl_pathc; ++x) {
1813 /* try to avoid direct loops */
1814 if (strcmp(gl.gl_pathv[x], fname) == 0)
1815 continue;
1816 _load_ld_cache_config(gl.gl_pathv[x]);
1817 }
1818 globfree(&gl);
1819 }
1820
1821 /* failed globs are ignored by glibc */
1822 continue;
1057 } 1823 }
1058 ldpaths[i] = NULL; 1824
1825 if (*path != '/')
1826 continue;
1827
1828 xarraypush_str(ldpaths, path);
1829 }
1830 free(path);
1059 1831
1060 fclose(fp); 1832 fclose(fp);
1833
1834 if (curr_fd != -1) {
1835 if (fchdir(curr_fd))
1836 {/* don't care */}
1837 close(curr_fd);
1838 }
1839
1840 return 0;
1841}
1842
1843#elif defined(__FreeBSD__) || defined(__DragonFly__)
1844
1845static int _load_ld_cache_config(const char *fname)
1846{
1847 FILE *fp = NULL;
1848 char *b = NULL, *p;
1849 struct elfhints_hdr hdr;
1850
1851 fp = fopenat_r(root_fd, root_rel_path(fname));
1852 if (fp == NULL)
1853 return -1;
1854
1855 if (fread(&hdr, 1, sizeof(hdr), fp) != sizeof(hdr) ||
1856 hdr.magic != ELFHINTS_MAGIC || hdr.version != 1 ||
1857 fseek(fp, hdr.strtab + hdr.dirlist, SEEK_SET) == -1)
1858 {
1859 fclose(fp);
1860 return -1;
1861 }
1862
1863 b = xmalloc(hdr.dirlistlen + 1);
1864 if (fread(b, 1, hdr.dirlistlen+1, fp) != hdr.dirlistlen+1) {
1865 fclose(fp);
1866 free(b);
1867 return -1;
1868 }
1869
1870 while ((p = strsep(&b, ":"))) {
1871 if (*p == '\0')
1872 continue;
1873 xarraypush_str(ldpaths, p);
1874 }
1875
1876 free(b);
1877 fclose(fp);
1878 return 0;
1879}
1880
1881#else
1882#ifdef __ELF__
1883#warning Cache config support not implemented for your target
1884#endif
1885static int _load_ld_cache_config(const char *fname)
1886{
1887 return 0;
1888}
1889#endif
1890
1891static void load_ld_cache_config(const char *fname)
1892{
1893 bool scan_l, scan_ul, scan_ull;
1894 size_t n;
1895 const char *ldpath;
1896
1897 _load_ld_cache_config(fname);
1898
1899 scan_l = scan_ul = scan_ull = false;
1900 if (array_cnt(ldpaths)) {
1901 array_for_each(ldpaths, n, ldpath) {
1902 if (!scan_l && !strcmp(ldpath, "/lib")) scan_l = true;
1903 if (!scan_ul && !strcmp(ldpath, "/usr/lib")) scan_ul = true;
1904 if (!scan_ull && !strcmp(ldpath, "/usr/local/lib")) scan_ull = true;
1905 }
1906 }
1907
1908 if (!scan_l) xarraypush_str(ldpaths, "/lib");
1909 if (!scan_ul) xarraypush_str(ldpaths, "/usr/lib");
1910 if (!scan_ull) xarraypush_str(ldpaths, "/usr/local/lib");
1061} 1911}
1062 1912
1063/* scan /etc/ld.so.conf for paths */ 1913/* scan /etc/ld.so.conf for paths */
1064static void scanelf_ldpath() 1914static void scanelf_ldpath(void)
1065{ 1915{
1066 char scan_l, scan_ul, scan_ull; 1916 size_t n;
1067 int i = 0; 1917 const char *ldpath;
1068 1918
1069 if (!ldpaths[0]) 1919 array_for_each(ldpaths, n, ldpath)
1070 err("Unable to load any paths from ld.so.conf");
1071
1072 scan_l = scan_ul = scan_ull = 0;
1073
1074 while (ldpaths[i]) {
1075 if (!scan_l && !strcmp(ldpaths[i], "/lib")) scan_l = 1;
1076 if (!scan_ul && !strcmp(ldpaths[i], "/usr/lib")) scan_ul = 1;
1077 if (!scan_ull && !strcmp(ldpaths[i], "/usr/local/lib")) scan_ull = 1;
1078 scanelf_dir(ldpaths[i]); 1920 scanelf_dir(ldpath);
1079 ++i;
1080 }
1081
1082 if (!scan_l) scanelf_dir("/lib");
1083 if (!scan_ul) scanelf_dir("/usr/lib");
1084 if (!scan_ull) scanelf_dir("/usr/local/lib");
1085} 1921}
1086 1922
1087/* scan env PATH for paths */ 1923/* scan env PATH for paths */
1088static void scanelf_envpath() 1924static void scanelf_envpath(void)
1089{ 1925{
1090 char *path, *p; 1926 char *path, *p;
1091 1927
1092 path = getenv("PATH"); 1928 path = getenv("PATH");
1093 if (!path) 1929 if (!path)
1100 } 1936 }
1101 1937
1102 free(path); 1938 free(path);
1103} 1939}
1104 1940
1105 1941/* usage / invocation handling functions */ /* Free Flags: c d j u w G H J K P Q U W */
1106/* usage / invocation handling functions */
1107#define PARSE_FLAGS "plRmyxetrnLibSs:gN:TaqvF:f:o:BhV" 1942#define PARSE_FLAGS "plRmyAXz:xetrnLibSs:k:gN:TaqvF:f:o:E:M:DIYO:ZCBhV"
1108#define a_argument required_argument 1943#define a_argument required_argument
1109static struct option const long_opts[] = { 1944static struct option const long_opts[] = {
1110 {"path", no_argument, NULL, 'p'}, 1945 {"path", no_argument, NULL, 'p'},
1111 {"ldpath", no_argument, NULL, 'l'}, 1946 {"ldpath", no_argument, NULL, 'l'},
1947 {"use-ldpath",no_argument, NULL, 129},
1948 {"root", a_argument, NULL, 128},
1112 {"recursive", no_argument, NULL, 'R'}, 1949 {"recursive", no_argument, NULL, 'R'},
1113 {"mount", no_argument, NULL, 'm'}, 1950 {"mount", no_argument, NULL, 'm'},
1114 {"symlink", no_argument, NULL, 'y'}, 1951 {"symlink", no_argument, NULL, 'y'},
1952 {"archives", no_argument, NULL, 'A'},
1953 {"ldcache", no_argument, NULL, 'L'},
1954 {"fix", no_argument, NULL, 'X'},
1955 {"setpax", a_argument, NULL, 'z'},
1115 {"pax", no_argument, NULL, 'x'}, 1956 {"pax", no_argument, NULL, 'x'},
1116 {"header", no_argument, NULL, 'e'}, 1957 {"header", no_argument, NULL, 'e'},
1117 {"textrel", no_argument, NULL, 't'}, 1958 {"textrel", no_argument, NULL, 't'},
1118 {"rpath", no_argument, NULL, 'r'}, 1959 {"rpath", no_argument, NULL, 'r'},
1119 {"needed", no_argument, NULL, 'n'}, 1960 {"needed", no_argument, NULL, 'n'},
1120 {"ldcache", no_argument, NULL, 'L'},
1121 {"interp", no_argument, NULL, 'i'}, 1961 {"interp", no_argument, NULL, 'i'},
1122 {"bind", no_argument, NULL, 'b'}, 1962 {"bind", no_argument, NULL, 'b'},
1123 {"soname", no_argument, NULL, 'S'}, 1963 {"soname", no_argument, NULL, 'S'},
1124 {"symbol", a_argument, NULL, 's'}, 1964 {"symbol", a_argument, NULL, 's'},
1965 {"section", a_argument, NULL, 'k'},
1125 {"lib", a_argument, NULL, 'N'}, 1966 {"lib", a_argument, NULL, 'N'},
1126 {"gmatch", no_argument, NULL, 'g'}, 1967 {"gmatch", no_argument, NULL, 'g'},
1127 {"textrels", no_argument, NULL, 'T'}, 1968 {"textrels", no_argument, NULL, 'T'},
1969 {"etype", a_argument, NULL, 'E'},
1970 {"bits", a_argument, NULL, 'M'},
1971 {"endian", no_argument, NULL, 'D'},
1972 {"osabi", no_argument, NULL, 'I'},
1973 {"eabi", no_argument, NULL, 'Y'},
1974 {"perms", a_argument, NULL, 'O'},
1975 {"size", no_argument, NULL, 'Z'},
1128 {"all", no_argument, NULL, 'a'}, 1976 {"all", no_argument, NULL, 'a'},
1129 {"quiet", no_argument, NULL, 'q'}, 1977 {"quiet", no_argument, NULL, 'q'},
1130 {"verbose", no_argument, NULL, 'v'}, 1978 {"verbose", no_argument, NULL, 'v'},
1131 {"format", a_argument, NULL, 'F'}, 1979 {"format", a_argument, NULL, 'F'},
1132 {"from", a_argument, NULL, 'f'}, 1980 {"from", a_argument, NULL, 'f'},
1133 {"file", a_argument, NULL, 'o'}, 1981 {"file", a_argument, NULL, 'o'},
1982 {"nocolor", no_argument, NULL, 'C'},
1134 {"nobanner", no_argument, NULL, 'B'}, 1983 {"nobanner", no_argument, NULL, 'B'},
1135 {"help", no_argument, NULL, 'h'}, 1984 {"help", no_argument, NULL, 'h'},
1136 {"version", no_argument, NULL, 'V'}, 1985 {"version", no_argument, NULL, 'V'},
1137 {NULL, no_argument, NULL, 0x0} 1986 {NULL, no_argument, NULL, 0x0}
1138}; 1987};
1139 1988
1140static const char *opts_help[] = { 1989static const char * const opts_help[] = {
1141 "Scan all directories in PATH environment", 1990 "Scan all directories in PATH environment",
1142 "Scan all directories in /etc/ld.so.conf", 1991 "Scan all directories in /etc/ld.so.conf",
1992 "Use ld.so.conf to show full path (use with -r/-n)",
1993 "Root directory (use with -l or -p)",
1143 "Scan directories recursively", 1994 "Scan directories recursively",
1144 "Don't recursively cross mount points", 1995 "Don't recursively cross mount points",
1145 "Don't scan symlinks\n", 1996 "Don't scan symlinks",
1997 "Scan archives (.a files)",
1998 "Utilize ld.so.cache to show full path (use with -r/-n)",
1999 "Try and 'fix' bad things (use with -r/-e)",
2000 "Sets EI_PAX/PT_PAX_FLAGS to <arg> (use with -Xx)\n",
1146 "Print PaX markings", 2001 "Print PaX markings",
1147 "Print GNU_STACK/PT_LOAD markings", 2002 "Print GNU_STACK/PT_LOAD markings",
1148 "Print TEXTREL information", 2003 "Print TEXTREL information",
1149 "Print RPATH information", 2004 "Print RPATH information",
1150 "Print NEEDED information", 2005 "Print NEEDED information",
1151 "Resolve NEEDED information (use with -n)",
1152 "Print INTERP information", 2006 "Print INTERP information",
1153 "Print BIND information", 2007 "Print BIND information",
1154 "Print SONAME information", 2008 "Print SONAME information",
1155 "Find a specified symbol", 2009 "Find a specified symbol",
2010 "Find a specified section",
1156 "Find a specified library", 2011 "Find a specified library",
1157 "Use strncmp to match libraries. (use with -N)", 2012 "Use regex rather than string compare (with -s); specify twice for case insensitive",
1158 "Locate cause of TEXTREL", 2013 "Locate cause of TEXTREL",
1159 "Print all scanned info (-x -e -t -r -b)\n", 2014 "Print only ELF files matching etype ET_DYN,ET_EXEC ...",
2015 "Print only ELF files matching numeric bits",
2016 "Print Endianness",
2017 "Print OSABI",
2018 "Print EABI (EM_ARM Only)",
2019 "Print only ELF files matching octal permissions",
2020 "Print ELF file size",
2021 "Print all useful/simple info\n",
1160 "Only output 'bad' things", 2022 "Only output 'bad' things",
1161 "Be verbose (can be specified more than once)", 2023 "Be verbose (can be specified more than once)",
1162 "Use specified format for output", 2024 "Use specified format for output",
1163 "Read input stream from a filename", 2025 "Read input stream from a filename",
1164 "Write output stream to a filename", 2026 "Write output stream to a filename",
2027 "Don't emit color in output",
1165 "Don't display the header", 2028 "Don't display the header",
1166 "Print this help and exit", 2029 "Print this help and exit",
1167 "Print version and exit", 2030 "Print version and exit",
1168 NULL 2031 NULL
1169}; 2032};
1170 2033
1171/* display usage and exit */ 2034/* display usage and exit */
1172static void usage(int status) 2035static void usage(int status)
1173{ 2036{
1174 unsigned long i; 2037 const char a_arg[] = "<arg>";
2038 size_t a_arg_len = strlen(a_arg) + 2;
2039 size_t i;
2040 int optlen;
1175 printf("* Scan ELF binaries for stuff\n\n" 2041 printf("* Scan ELF binaries for stuff\n\n"
1176 "Usage: %s [options] <dir1/file1> [dir2 dirN fileN ...]\n\n", argv0); 2042 "Usage: %s [options] <dir1/file1> [dir2 dirN file2 fileN ...]\n\n", argv0);
1177 printf("Options: -[%s]\n", PARSE_FLAGS); 2043 printf("Options: -[%s]\n", PARSE_FLAGS);
2044
2045 /* prescan the --long opt length to auto-align */
2046 optlen = 0;
1178 for (i = 0; long_opts[i].name; ++i) 2047 for (i = 0; long_opts[i].name; ++i) {
2048 int l = strlen(long_opts[i].name);
2049 if (long_opts[i].has_arg == a_argument)
2050 l += a_arg_len;
2051 optlen = max(l, optlen);
2052 }
2053
2054 for (i = 0; long_opts[i].name; ++i) {
2055 /* first output the short flag if it has one */
2056 if (long_opts[i].val > '~')
2057 printf(" ");
2058 else
2059 printf(" -%c, ", long_opts[i].val);
2060
2061 /* then the long flag */
1179 if (long_opts[i].has_arg == no_argument) 2062 if (long_opts[i].has_arg == no_argument)
1180 printf(" -%c, --%-13s* %s\n", long_opts[i].val, 2063 printf("--%-*s", optlen, long_opts[i].name);
1181 long_opts[i].name, opts_help[i]);
1182 else 2064 else
1183 printf(" -%c, --%-6s <arg> * %s\n", long_opts[i].val, 2065 printf("--%s %s %*s", long_opts[i].name, a_arg,
1184 long_opts[i].name, opts_help[i]); 2066 (int)(optlen - strlen(long_opts[i].name) - a_arg_len), "");
1185 2067
1186 if (status != EXIT_SUCCESS) 2068 /* finally the help text */
1187 exit(status); 2069 printf("* %s\n", opts_help[i]);
2070 }
1188 2071
1189 puts("\nThe format modifiers for the -F option are:"); 2072 puts("\nFor more information, see the scanelf(1) manpage");
1190 puts(" F Filename \tx PaX Flags \te STACK/RELRO");
1191 puts(" t TEXTREL \tr RPATH \tn NEEDED");
1192 puts(" i INTERP \tb BIND \ts symbol");
1193 puts(" N library \to Type \tT TEXTRELs");
1194 puts(" S SONAME");
1195 puts(" p filename (with search path removed)");
1196 puts(" f filename (short name/basename)");
1197 puts("Prefix each modifier with '%' (verbose) or '#' (silent)");
1198
1199 exit(status); 2073 exit(status);
1200} 2074}
1201 2075
1202/* parse command line arguments and preform needed actions */ 2076/* parse command line arguments and preform needed actions */
2077#define do_pax_state(option, flag) \
2078 if (islower(option)) { \
2079 flags &= ~PF_##flag; \
2080 flags |= PF_NO##flag; \
2081 } else { \
2082 flags &= ~PF_NO##flag; \
2083 flags |= PF_##flag; \
2084 }
1203static void parseargs(int argc, char *argv[]) 2085static int parseargs(int argc, char *argv[])
1204{ 2086{
1205 int i; 2087 int i;
1206 char *from_file = NULL; 2088 const char *from_file = NULL;
2089 int ret = 0;
2090 char load_cache_config = 0;
1207 2091
1208 opterr = 0; 2092 opterr = 0;
1209 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) { 2093 while ((i=getopt_long(argc, argv, PARSE_FLAGS, long_opts, NULL)) != -1) {
1210 switch (i) { 2094 switch (i) {
1211 2095
1215 VERSION, __FILE__, __DATE__, rcsid, argv0); 2099 VERSION, __FILE__, __DATE__, rcsid, argv0);
1216 exit(EXIT_SUCCESS); 2100 exit(EXIT_SUCCESS);
1217 break; 2101 break;
1218 case 'h': usage(EXIT_SUCCESS); break; 2102 case 'h': usage(EXIT_SUCCESS); break;
1219 case 'f': 2103 case 'f':
1220 if (from_file) err("Don't specify -f twice"); 2104 if (from_file) warn("You prob don't want to specify -f twice");
1221 from_file = xstrdup(optarg); 2105 from_file = optarg;
2106 break;
2107 case 'E':
2108 match_etypes = optarg;
2109 break;
2110 case 'M':
2111 match_bits = atoi(optarg);
2112 if (match_bits == 0) {
2113 if (strcmp(optarg, "ELFCLASS32") == 0)
2114 match_bits = 32;
2115 if (strcmp(optarg, "ELFCLASS64") == 0)
2116 match_bits = 64;
2117 }
2118 break;
2119 case 'O':
2120 if (sscanf(optarg, "%o", &match_perms) == -1)
2121 match_bits = 0;
1222 break; 2122 break;
1223 case 'o': { 2123 case 'o': {
1224 FILE *fp = NULL;
1225 if ((fp = freopen(optarg, "w", stdout)) == NULL) 2124 if (freopen(optarg, "w", stdout) == NULL)
1226 err("Could not open output stream '%s': %s", optarg, strerror(errno)); 2125 errp("Could not freopen(%s)", optarg);
1227 SET_STDOUT(fp);
1228 break; 2126 break;
1229 } 2127 }
1230 2128 case 'k':
2129 xarraypush_str(find_section_arr, optarg);
2130 break;
1231 case 's': { 2131 case 's': {
1232 if (find_sym) warn("You prob don't want to specify -s twice"); 2132 /* historically, this was comma delimited */
1233 find_sym = optarg; 2133 char *this_sym = strtok(optarg, ",");
1234 versioned_symname = (char*)xmalloc(sizeof(char) * (strlen(find_sym)+1+1)); 2134 if (!this_sym) /* edge case: -s '' */
1235 sprintf(versioned_symname, "%s@", find_sym); 2135 xarraypush_str(find_sym_arr, "");
2136 while (this_sym) {
2137 xarraypush_str(find_sym_arr, this_sym);
2138 this_sym = strtok(NULL, ",");
2139 }
1236 break; 2140 break;
1237 } 2141 }
1238 case 'N': { 2142 case 'N':
1239 if (find_lib) warn("You prob don't want to specify -N twice"); 2143 xarraypush_str(find_lib_arr, optarg);
1240 find_lib = optarg;
1241 break; 2144 break;
1242 }
1243
1244 case 'F': { 2145 case 'F': {
1245 if (out_format) warn("You prob don't want to specify -F twice"); 2146 if (out_format) warn("You prob don't want to specify -F twice");
1246 out_format = optarg; 2147 out_format = optarg;
1247 break; 2148 break;
1248 } 2149 }
2150 case 'z': {
2151 unsigned long flags = (PF_NOEMUTRAMP | PF_NORANDEXEC);
2152 size_t x;
1249 2153
1250 case 'g': gmatch = 1; /* break; any reason we dont breal; here ? */ 2154 for (x = 0; x < strlen(optarg); x++) {
1251 case 'L': printcache = 1; break; 2155 switch (optarg[x]) {
2156 case 'p':
2157 case 'P':
2158 do_pax_state(optarg[x], PAGEEXEC);
2159 break;
2160 case 's':
2161 case 'S':
2162 do_pax_state(optarg[x], SEGMEXEC);
2163 break;
2164 case 'm':
2165 case 'M':
2166 do_pax_state(optarg[x], MPROTECT);
2167 break;
2168 case 'e':
2169 case 'E':
2170 do_pax_state(optarg[x], EMUTRAMP);
2171 break;
2172 case 'r':
2173 case 'R':
2174 do_pax_state(optarg[x], RANDMMAP);
2175 break;
2176 case 'x':
2177 case 'X':
2178 do_pax_state(optarg[x], RANDEXEC);
2179 break;
2180 default:
2181 break;
2182 }
2183 }
2184 if (!(((flags & PF_PAGEEXEC) && (flags & PF_NOPAGEEXEC)) ||
2185 ((flags & PF_SEGMEXEC) && (flags & PF_NOSEGMEXEC)) ||
2186 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP)) ||
2187 ((flags & PF_RANDEXEC) && (flags & PF_NORANDEXEC)) ||
2188 ((flags & PF_EMUTRAMP) && (flags & PF_NOEMUTRAMP)) ||
2189 ((flags & PF_RANDMMAP) && (flags & PF_NORANDMMAP))))
2190 setpax = flags;
2191 break;
2192 }
2193 case 'Z': show_size = 1; break;
2194 case 'g': ++g_match; break;
2195 case 'L': load_cache_config = use_ldcache = 1; break;
1252 case 'y': scan_symlink = 0; break; 2196 case 'y': scan_symlink = 0; break;
2197 case 'A': scan_archives = 1; break;
2198 case 'C': color_init(true); break;
1253 case 'B': show_banner = 0; break; 2199 case 'B': show_banner = 0; break;
1254 case 'l': scan_ldpath = 1; break; 2200 case 'l': load_cache_config = scan_ldpath = 1; break;
1255 case 'p': scan_envpath = 1; break; 2201 case 'p': scan_envpath = 1; break;
1256 case 'R': dir_recurse = 1; break; 2202 case 'R': dir_recurse = 1; break;
1257 case 'm': dir_crossmount = 0; break; 2203 case 'm': dir_crossmount = 0; break;
2204 case 'X': ++fix_elf; break;
1258 case 'x': show_pax = 1; break; 2205 case 'x': show_pax = 1; break;
1259 case 'e': show_phdr = 1; break; 2206 case 'e': show_phdr = 1; break;
1260 case 't': show_textrel = 1; break; 2207 case 't': show_textrel = 1; break;
1261 case 'r': show_rpath = 1; break; 2208 case 'r': show_rpath = 1; break;
1262 case 'n': show_needed = 1; break; 2209 case 'n': show_needed = 1; break;
1263 case 'i': show_interp = 1; break; 2210 case 'i': show_interp = 1; break;
1264 case 'b': show_bind = 1; break; 2211 case 'b': show_bind = 1; break;
1265 case 'S': show_soname = 1; break; 2212 case 'S': show_soname = 1; break;
1266 case 'T': show_textrels = 1; break; 2213 case 'T': show_textrels = 1; break;
1267 case 'q': be_quiet = 1; break; 2214 case 'q': be_quiet = min(be_quiet, 20) + 1; break;
1268 case 'v': be_verbose = (be_verbose % 20) + 1; break; 2215 case 'v': be_verbose = min(be_verbose, 20) + 1; break;
1269 case 'a': show_pax = show_phdr = show_textrel = show_rpath = show_bind = 1; break; 2216 case 'a': show_perms = show_pax = show_phdr = show_textrel = show_rpath = show_bind = show_endian = 1; break;
1270 2217 case 'D': show_endian = 1; break;
2218 case 'I': show_osabi = 1; break;
2219 case 'Y': show_eabi = 1; break;
2220 case 128:
2221 root_fd = open(optarg, O_RDONLY|O_CLOEXEC);
2222 if (root_fd == -1)
2223 err("Could not open root: %s", optarg);
2224 break;
2225 case 129: load_cache_config = use_ldpath = 1; break;
1271 case ':': 2226 case ':':
1272 err("Option missing parameter\n"); 2227 err("Option '%c' is missing parameter", optopt);
1273 case '?': 2228 case '?':
1274 err("Unknown option\n"); 2229 err("Unknown option '%c' or argument missing", optopt);
1275 default: 2230 default:
1276 err("Unhandled option '%c'", i); 2231 err("Unhandled option '%c'; please report this", i);
2232 }
2233 }
2234 if (show_textrels && be_verbose)
2235 has_objdump = bin_in_path("objdump");
2236 /* precompile all the regexes */
2237 if (g_match) {
2238 regex_t preg;
2239 const char *this_sym;
2240 size_t n;
2241 int flags = REG_EXTENDED | REG_NOSUB | (g_match > 1 ? REG_ICASE : 0);
2242
2243 array_for_each(find_sym_arr, n, this_sym) {
2244 /* see scanelf_match_symname for logic info */
2245 switch (this_sym[0]) {
2246 case '%':
2247 while (*(this_sym++))
2248 if (*this_sym == '%') {
2249 ++this_sym;
2250 break;
2251 }
2252 break;
2253 case '+':
2254 case '-':
2255 ++this_sym;
2256 break;
1277 } 2257 }
2258 if (*this_sym == '*')
2259 ++this_sym;
2260
2261 ret = regcomp(&preg, this_sym, flags);
2262 if (ret) {
2263 char err[256];
2264 regerror(ret, &preg, err, sizeof(err));
2265 err("regcomp of %s failed: %s", this_sym, err);
2266 }
2267 xarraypush(find_sym_regex_arr, &preg, sizeof(preg));
1278 } 2268 }
1279 2269 }
2270 /* flatten arrays for display */
2271 if (array_cnt(find_sym_arr))
2272 find_sym = array_flatten_str(find_sym_arr);
2273 if (array_cnt(find_lib_arr))
2274 find_lib = array_flatten_str(find_lib_arr);
2275 if (array_cnt(find_section_arr))
2276 find_section = array_flatten_str(find_section_arr);
1280 /* let the format option override all other options */ 2277 /* let the format option override all other options */
1281 if (out_format) { 2278 if (out_format) {
1282 show_pax = show_phdr = show_textrel = show_rpath = \ 2279 show_pax = show_phdr = show_textrel = show_rpath = \
1283 show_needed = show_interp = show_bind = show_soname = \ 2280 show_needed = show_interp = show_bind = show_soname = \
1284 show_textrels = 0; 2281 show_textrels = show_perms = show_endian = show_size = \
2282 show_osabi = show_eabi = 0;
1285 for (i = 0; out_format[i]; ++i) { 2283 for (i = 0; out_format[i]; ++i) {
1286 if (!IS_MODIFIER(out_format[i])) continue; 2284 if (!IS_MODIFIER(out_format[i])) continue;
1287 2285
1288 switch (out_format[++i]) { 2286 switch (out_format[++i]) {
2287 case '+': break;
1289 case '%': break; 2288 case '%': break;
1290 case '#': break; 2289 case '#': break;
1291 case 'F': break; 2290 case 'F': break;
1292 case 'p': break; 2291 case 'p': break;
1293 case 'f': break; 2292 case 'f': break;
2293 case 'k': break;
1294 case 's': break; 2294 case 's': break;
1295 case 'N': break; 2295 case 'N': break;
1296 case 'o': break; 2296 case 'o': break;
2297 case 'a': break;
2298 case 'M': break;
2299 case 'Z': show_size = 1; break;
2300 case 'D': show_endian = 1; break;
2301 case 'I': show_osabi = 1; break;
2302 case 'Y': show_eabi = 1; break;
2303 case 'O': show_perms = 1; break;
1297 case 'x': show_pax = 1; break; 2304 case 'x': show_pax = 1; break;
1298 case 'e': show_phdr = 1; break; 2305 case 'e': show_phdr = 1; break;
1299 case 't': show_textrel = 1; break; 2306 case 't': show_textrel = 1; break;
1300 case 'r': show_rpath = 1; break; 2307 case 'r': show_rpath = 1; break;
1301 case 'n': show_needed = 1; break; 2308 case 'n': show_needed = 1; break;
1302 case 'i': show_interp = 1; break; 2309 case 'i': show_interp = 1; break;
1303 case 'b': show_bind = 1; break; 2310 case 'b': show_bind = 1; break;
1304 case 'S': show_soname = 1; break; 2311 case 'S': show_soname = 1; break;
1305 case 'T': show_textrels = 1; break; 2312 case 'T': show_textrels = 1; break;
1306 default: 2313 default:
1307 err("Invalid format specifier '%c' (byte %i)", 2314 err("invalid format specifier '%c' (byte %i)",
1308 out_format[i], i+1); 2315 out_format[i], i+1);
1309 } 2316 }
1310 } 2317 }
1311 2318
1312 /* construct our default format */ 2319 /* construct our default format */
1313 } else { 2320 } else {
1314 size_t fmt_len = 30; 2321 size_t fmt_len = 30;
1315 out_format = (char*)xmalloc(sizeof(char) * fmt_len); 2322 out_format = xmalloc(sizeof(char) * fmt_len);
2323 *out_format = '\0';
1316 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len); 2324 if (!be_quiet) xstrcat(&out_format, "%o ", &fmt_len);
1317 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len); 2325 if (show_pax) xstrcat(&out_format, "%x ", &fmt_len);
2326 if (show_perms) xstrcat(&out_format, "%O ", &fmt_len);
2327 if (show_size) xstrcat(&out_format, "%Z ", &fmt_len);
2328 if (show_endian) xstrcat(&out_format, "%D ", &fmt_len);
2329 if (show_osabi) xstrcat(&out_format, "%I ", &fmt_len);
2330 if (show_eabi) xstrcat(&out_format, "%Y ", &fmt_len);
1318 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len); 2331 if (show_phdr) xstrcat(&out_format, "%e ", &fmt_len);
1319 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len); 2332 if (show_textrel) xstrcat(&out_format, "%t ", &fmt_len);
1320 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len); 2333 if (show_rpath) xstrcat(&out_format, "%r ", &fmt_len);
1321 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len); 2334 if (show_needed) xstrcat(&out_format, "%n ", &fmt_len);
1322 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len); 2335 if (show_interp) xstrcat(&out_format, "%i ", &fmt_len);
1323 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len); 2336 if (show_bind) xstrcat(&out_format, "%b ", &fmt_len);
1324 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len); 2337 if (show_soname) xstrcat(&out_format, "%S ", &fmt_len);
1325 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len); 2338 if (show_textrels) xstrcat(&out_format, "%T ", &fmt_len);
1326 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len); 2339 if (find_sym) xstrcat(&out_format, "%s ", &fmt_len);
2340 if (find_section) xstrcat(&out_format, "%k ", &fmt_len);
1327 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len); 2341 if (find_lib) xstrcat(&out_format, "%N ", &fmt_len);
1328 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len); 2342 if (!be_quiet) xstrcat(&out_format, "%F ", &fmt_len);
1329 } 2343 }
1330 if (be_verbose > 2) printf("Format: %s\n", out_format); 2344 if (be_verbose > 2) printf("Format: %s\n", out_format);
1331 2345
1332 /* now lets actually do the scanning */ 2346 /* now lets actually do the scanning */
1333 if (scan_ldpath || (show_rpath && be_quiet)) 2347 if (load_cache_config)
1334 load_ld_so_conf(); 2348 load_ld_cache_config(__PAX_UTILS_DEFAULT_LD_CACHE_CONFIG);
1335 if (scan_ldpath) scanelf_ldpath(); 2349 if (scan_ldpath) scanelf_ldpath();
1336 if (scan_envpath) scanelf_envpath(); 2350 if (scan_envpath) scanelf_envpath();
2351 if (!from_file && optind == argc && ttyname(0) == NULL && !scan_ldpath && !scan_envpath)
2352 from_file = "-";
1337 if (from_file) { 2353 if (from_file) {
1338 scanelf_from_file(from_file); 2354 scanelf_from_file(from_file);
1339 free(from_file);
1340 from_file = *argv; 2355 from_file = *argv;
1341 } 2356 }
1342 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file) 2357 if (optind == argc && !scan_ldpath && !scan_envpath && !from_file)
1343 err("Nothing to scan !?"); 2358 err("Nothing to scan !?");
1344 while (optind < argc) { 2359 while (optind < argc) {
1345 search_path = argv[optind++]; 2360 search_path = argv[optind++];
1346 scanelf_dir(search_path); 2361 ret = scanelf_dir(search_path);
1347 } 2362 }
1348 2363
2364#ifdef __PAX_UTILS_CLEANUP
1349 /* clean up */ 2365 /* clean up */
1350 if (versioned_symname) free(versioned_symname);
1351 for (i = 0; ldpaths[i]; ++i)
1352 free(ldpaths[i]); 2366 xarrayfree(ldpaths);
2367 xarrayfree(find_sym_arr);
2368 xarrayfree(find_lib_arr);
2369 xarrayfree(find_section_arr);
2370 free(find_sym);
2371 free(find_lib);
2372 free(find_section);
2373 {
2374 size_t n;
2375 regex_t *preg;
2376 array_for_each(find_sym_regex_arr, n, preg)
2377 regfree(preg);
2378 xarrayfree(find_sym_regex_arr);
2379 }
1353 2380
1354 if (ldcache != 0) 2381 if (ldcache != 0)
1355 munmap(ldcache, ldcache_size); 2382 munmap(ldcache, ldcache_size);
1356} 2383#endif
1357 2384
1358
1359
1360/* utility funcs */
1361static char *xstrdup(const char *s)
1362{
1363 char *ret = strdup(s);
1364 if (!ret) err("Could not strdup(): %s", strerror(errno));
1365 return ret; 2385 return ret;
1366} 2386}
1367static void *xmalloc(size_t size)
1368{
1369 void *ret = malloc(size);
1370 if (!ret) err("Could not malloc() %li bytes", (unsigned long)size);
1371 return ret;
1372}
1373static void xstrncat(char **dst, const char *src, size_t *curr_len, size_t n)
1374{
1375 size_t new_len;
1376 2387
1377 new_len = strlen(*dst) + strlen(src); 2388static char **get_split_env(const char *envvar)
1378 if (*curr_len <= new_len) {
1379 *curr_len = new_len + (*curr_len / 2);
1380 *dst = realloc(*dst, *curr_len);
1381 if (!*dst)
1382 err("could not realloc() %li bytes", (unsigned long)*curr_len);
1383 }
1384
1385 if (n)
1386 strncat(*dst, src, n);
1387 else
1388 strcat(*dst, src);
1389}
1390static inline void xchrcat(char **dst, const char append, size_t *curr_len)
1391{ 2389{
1392 static char my_app[2]; 2390 const char *delims = " \t\n";
1393 my_app[0] = append; 2391 char **envvals = NULL;
1394 my_app[1] = '\0'; 2392 char *env, *s;
1395 xstrcat(dst, my_app, curr_len); 2393 int nentry;
1396}
1397 2394
2395 if ((env = getenv(envvar)) == NULL)
2396 return NULL;
1398 2397
2398 env = xstrdup(env);
2399 if (env == NULL)
2400 return NULL;
2401
2402 s = strtok(env, delims);
2403 if (s == NULL) {
2404 free(env);
2405 return NULL;
2406 }
2407
2408 nentry = 0;
2409 while (s != NULL) {
2410 ++nentry;
2411 envvals = xrealloc(envvals, sizeof(*envvals) * (nentry+1));
2412 envvals[nentry-1] = s;
2413 s = strtok(NULL, delims);
2414 }
2415 envvals[nentry] = NULL;
2416
2417 /* don't want to free(env) as it contains the memory that backs
2418 * the envvals array of strings */
2419 return envvals;
2420}
2421
2422static void parseenv(void)
2423{
2424 color_init(false);
2425 qa_textrels = get_split_env("QA_TEXTRELS");
2426 qa_execstack = get_split_env("QA_EXECSTACK");
2427 qa_wx_load = get_split_env("QA_WX_LOAD");
2428}
2429
2430#ifdef __PAX_UTILS_CLEANUP
2431static void cleanup(void)
2432{
2433 free(out_format);
2434 free(qa_textrels);
2435 free(qa_execstack);
2436 free(qa_wx_load);
2437}
2438#endif
1399 2439
1400int main(int argc, char *argv[]) 2440int main(int argc, char *argv[])
1401{ 2441{
2442 int ret;
1402 if (argc < 2) 2443 if (argc < 2)
1403 usage(EXIT_FAILURE); 2444 usage(EXIT_FAILURE);
2445 parseenv();
1404 parseargs(argc, argv); 2446 ret = parseargs(argc, argv);
1405 fclose(stdout); 2447 fclose(stdout);
1406#ifdef __BOUNDS_CHECKING_ON 2448#ifdef __PAX_UTILS_CLEANUP
1407 warn("The calls to add/delete heap should be off by 1 due to the out_buffer not being freed in scanelf_file()"); 2449 cleanup();
2450 warn("The calls to add/delete heap should be off:\n"
2451 "\t- 1 due to the out_buffer not being freed in scanelf_fileat()\n"
2452 "\t- 1 per QA_TEXTRELS/QA_EXECSTACK/QA_WX_LOAD");
1408#endif 2453#endif
1409 return EXIT_SUCCESS; 2454 return ret;
1410} 2455}
2456
2457/* Match filename against entries in matchlist, return TRUE
2458 * if the file is listed */
2459static int file_matches_list(const char *filename, char **matchlist)
2460{
2461 char **file;
2462 char *match;
2463 char buf[__PAX_UTILS_PATH_MAX];
2464
2465 if (matchlist == NULL)
2466 return 0;
2467
2468 for (file = matchlist; *file != NULL; file++) {
2469 if (search_path) {
2470 snprintf(buf, sizeof(buf), "%s%s", search_path, *file);
2471 match = buf;
2472 } else {
2473 match = *file;
2474 }
2475 if (fnmatch(match, filename, 0) == 0)
2476 return 1;
2477 }
2478 return 0;
2479}

Legend:
Removed from v.1.98  
changed lines
  Added in v.1.260

  ViewVC Help
Powered by ViewVC 1.1.20