1 /* $NetBSD: map_object.c,v 1.55 2016/06/16 11:34:13 christos Exp $ */ 2 3 /* 4 * Copyright 1996 John D. Polstra. 5 * Copyright 1996 Matt Thomas <matt@3am-software.com> 6 * Copyright 2002 Charles M. Hannum <root@ihack.net> 7 * All rights reserved. 8 * 9 * Redistribution and use in source and binary forms, with or without 10 * modification, are permitted provided that the following conditions 11 * are met: 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 2. Redistributions in binary form must reproduce the above copyright 15 * notice, this list of conditions and the following disclaimer in the 16 * documentation and/or other materials provided with the distribution. 17 * 3. All advertising materials mentioning features or use of this software 18 * must display the following acknowledgement: 19 * This product includes software developed by John Polstra. 20 * 4. The name of the author may not be used to endorse or promote products 21 * derived from this software without specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 24 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 25 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 26 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 27 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 28 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 29 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 30 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 31 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 32 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 33 */ 34 35 #include <sys/cdefs.h> 36 #ifndef lint 37 __RCSID("$NetBSD: map_object.c,v 1.55 2016/06/16 11:34:13 christos Exp $"); 38 #endif /* not lint */ 39 40 #include <errno.h> 41 #include <stddef.h> 42 #include <stdlib.h> 43 #include <string.h> 44 #include <unistd.h> 45 #include <sys/stat.h> 46 #include <sys/types.h> 47 #include <sys/mman.h> 48 49 #include "debug.h" 50 #include "rtld.h" 51 52 static int protflags(int); /* Elf flags -> mmap protection */ 53 54 #define EA_UNDEF (~(Elf_Addr)0) 55 56 /* 57 * Map a shared object into memory. The argument is a file descriptor, 58 * which must be open on the object and positioned at its beginning. 59 * 60 * The return value is a pointer to a newly-allocated Obj_Entry structure 61 * for the shared object. Returns NULL on failure. 62 */ 63 Obj_Entry * 64 _rtld_map_object(const char *path, int fd, const struct stat *sb) 65 { 66 Obj_Entry *obj; 67 Elf_Ehdr *ehdr; 68 Elf_Phdr *phdr; 69 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 70 Elf_Phdr *phtls; 71 #endif 72 size_t phsize; 73 Elf_Phdr *phlimit; 74 Elf_Phdr *segs[2]; 75 int nsegs; 76 caddr_t mapbase = MAP_FAILED; 77 size_t mapsize = 0; 78 int mapflags; 79 Elf_Off base_offset; 80 #ifdef MAP_ALIGNED 81 Elf_Addr base_alignment; 82 #endif 83 Elf_Addr base_vaddr; 84 Elf_Addr base_vlimit; 85 Elf_Addr text_vlimit; 86 int text_flags; 87 caddr_t base_addr; 88 Elf_Off data_offset; 89 Elf_Addr data_vaddr; 90 Elf_Addr data_vlimit; 91 int data_flags; 92 caddr_t data_addr; 93 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 94 Elf_Addr tls_vaddr = 0; /* Noise GCC */ 95 #endif 96 Elf_Addr phdr_vaddr; 97 size_t phdr_memsz; 98 caddr_t gap_addr; 99 size_t gap_size; 100 int i; 101 #ifdef RTLD_LOADER 102 Elf_Addr clear_vaddr; 103 caddr_t clear_addr; 104 size_t nclear; 105 #endif 106 #ifdef GNU_RELRO 107 Elf_Addr relro_page; 108 size_t relro_size; 109 #endif 110 111 if (sb != NULL && sb->st_size < (off_t)sizeof (Elf_Ehdr)) { 112 _rtld_error("%s: not ELF file (too short)", path); 113 return NULL; 114 } 115 116 obj = _rtld_obj_new(); 117 obj->path = xstrdup(path); 118 obj->pathlen = strlen(path); 119 if (sb != NULL) { 120 obj->dev = sb->st_dev; 121 obj->ino = sb->st_ino; 122 } 123 124 ehdr = mmap(NULL, _rtld_pagesz, PROT_READ, MAP_FILE | MAP_SHARED, fd, 125 (off_t)0); 126 obj->ehdr = ehdr; 127 if (ehdr == MAP_FAILED) { 128 _rtld_error("%s: read error: %s", path, xstrerror(errno)); 129 goto bad; 130 } 131 /* Make sure the file is valid */ 132 if (memcmp(ELFMAG, ehdr->e_ident, SELFMAG) != 0) { 133 _rtld_error("%s: not ELF file (magic number bad)", path); 134 goto bad; 135 } 136 if (ehdr->e_ident[EI_CLASS] != ELFCLASS) { 137 _rtld_error("%s: invalid ELF class %x; expected %x", path, 138 ehdr->e_ident[EI_CLASS], ELFCLASS); 139 goto bad; 140 } 141 /* Elf_e_ident includes class */ 142 if (ehdr->e_ident[EI_VERSION] != EV_CURRENT || 143 ehdr->e_version != EV_CURRENT || 144 ehdr->e_ident[EI_DATA] != ELFDEFNNAME(MACHDEP_ENDIANNESS)) { 145 _rtld_error("%s: unsupported file version", path); 146 goto bad; 147 } 148 if (ehdr->e_type != ET_EXEC && ehdr->e_type != ET_DYN) { 149 _rtld_error("%s: unsupported file type", path); 150 goto bad; 151 } 152 switch (ehdr->e_machine) { 153 ELFDEFNNAME(MACHDEP_ID_CASES) 154 default: 155 _rtld_error("%s: unsupported machine", path); 156 goto bad; 157 } 158 159 /* 160 * We rely on the program header being in the first page. This is 161 * not strictly required by the ABI specification, but it seems to 162 * always true in practice. And, it simplifies things considerably. 163 */ 164 assert(ehdr->e_phentsize == sizeof(Elf_Phdr)); 165 assert(ehdr->e_phoff + ehdr->e_phnum * sizeof(Elf_Phdr) <= 166 _rtld_pagesz); 167 168 /* 169 * Scan the program header entries, and save key information. 170 * 171 * We rely on there being exactly two load segments, text and data, 172 * in that order. 173 */ 174 phdr = (Elf_Phdr *) ((caddr_t)ehdr + ehdr->e_phoff); 175 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 176 phtls = NULL; 177 #endif 178 phsize = ehdr->e_phnum * sizeof(phdr[0]); 179 obj->phdr = NULL; 180 #ifdef GNU_RELRO 181 relro_page = 0; 182 relro_size = 0; 183 #endif 184 phdr_vaddr = EA_UNDEF; 185 phdr_memsz = 0; 186 phlimit = phdr + ehdr->e_phnum; 187 nsegs = 0; 188 while (phdr < phlimit) { 189 switch (phdr->p_type) { 190 case PT_INTERP: 191 obj->interp = (void *)(uintptr_t)phdr->p_vaddr; 192 dbg(("%s: PT_INTERP %p", obj->path, obj->interp)); 193 break; 194 195 case PT_LOAD: 196 if (nsegs < 2) 197 segs[nsegs] = phdr; 198 ++nsegs; 199 200 dbg(("%s: %s %p phsize %" PRImemsz, obj->path, "PT_LOAD", 201 (void *)(uintptr_t)phdr->p_vaddr, phdr->p_memsz)); 202 break; 203 204 case PT_PHDR: 205 phdr_vaddr = phdr->p_vaddr; 206 phdr_memsz = phdr->p_memsz; 207 dbg(("%s: %s %p phsize %" PRImemsz, obj->path, "PT_PHDR", 208 (void *)(uintptr_t)phdr->p_vaddr, phdr->p_memsz)); 209 break; 210 211 #ifdef GNU_RELRO 212 case PT_GNU_RELRO: 213 relro_page = phdr->p_vaddr; 214 relro_size = phdr->p_memsz; 215 break; 216 #endif 217 218 case PT_DYNAMIC: 219 obj->dynamic = (void *)(uintptr_t)phdr->p_vaddr; 220 dbg(("%s: %s %p phsize %" PRImemsz, obj->path, "PT_DYNAMIC", 221 (void *)(uintptr_t)phdr->p_vaddr, phdr->p_memsz)); 222 break; 223 224 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 225 case PT_TLS: 226 phtls = phdr; 227 dbg(("%s: %s %p phsize %" PRImemsz, obj->path, "PT_TLS", 228 (void *)(uintptr_t)phdr->p_vaddr, phdr->p_memsz)); 229 break; 230 #endif 231 #ifdef __ARM_EABI__ 232 case PT_ARM_EXIDX: 233 obj->exidx_start = (void *)(uintptr_t)phdr->p_vaddr; 234 obj->exidx_sz = phdr->p_memsz; 235 break; 236 #endif 237 } 238 239 ++phdr; 240 } 241 phdr = (Elf_Phdr *) ((caddr_t)ehdr + ehdr->e_phoff); 242 obj->entry = (void *)(uintptr_t)ehdr->e_entry; 243 if (!obj->dynamic) { 244 _rtld_error("%s: not dynamically linked", path); 245 goto bad; 246 } 247 if (nsegs != 2) { 248 _rtld_error("%s: wrong number of segments (%d != 2)", path, 249 nsegs); 250 goto bad; 251 } 252 253 /* 254 * Map the entire address space of the object as a file 255 * region to stake out our contiguous region and establish a 256 * base for relocation. We use a file mapping so that 257 * the kernel will give us whatever alignment is appropriate 258 * for the platform we're running on. 259 * 260 * We map it using the text protection, map the data segment 261 * into the right place, then map an anon segment for the bss 262 * and unmap the gaps left by padding to alignment. 263 */ 264 265 #ifdef MAP_ALIGNED 266 base_alignment = segs[0]->p_align; 267 #endif 268 base_offset = round_down(segs[0]->p_offset); 269 base_vaddr = round_down(segs[0]->p_vaddr); 270 base_vlimit = round_up(segs[1]->p_vaddr + segs[1]->p_memsz); 271 text_vlimit = round_up(segs[0]->p_vaddr + segs[0]->p_memsz); 272 text_flags = protflags(segs[0]->p_flags); 273 data_offset = round_down(segs[1]->p_offset); 274 data_vaddr = round_down(segs[1]->p_vaddr); 275 data_vlimit = round_up(segs[1]->p_vaddr + segs[1]->p_filesz); 276 data_flags = protflags(segs[1]->p_flags); 277 #ifdef RTLD_LOADER 278 clear_vaddr = segs[1]->p_vaddr + segs[1]->p_filesz; 279 #endif 280 281 obj->textsize = text_vlimit - base_vaddr; 282 obj->vaddrbase = base_vaddr; 283 obj->isdynamic = ehdr->e_type == ET_DYN; 284 285 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 286 if (phtls != NULL) { 287 ++_rtld_tls_dtv_generation; 288 obj->tlsindex = ++_rtld_tls_max_index; 289 obj->tlssize = phtls->p_memsz; 290 obj->tlsalign = phtls->p_align; 291 obj->tlsinitsize = phtls->p_filesz; 292 tls_vaddr = phtls->p_vaddr; 293 } 294 #endif 295 296 obj->phdr_loaded = false; 297 for (i = 0; i < nsegs; i++) { 298 if (phdr_vaddr != EA_UNDEF && 299 segs[i]->p_vaddr <= phdr_vaddr && 300 segs[i]->p_memsz >= phdr_memsz) { 301 obj->phdr_loaded = true; 302 break; 303 } 304 if (segs[i]->p_offset <= ehdr->e_phoff && 305 segs[i]->p_memsz >= phsize) { 306 phdr_vaddr = segs[i]->p_vaddr + ehdr->e_phoff; 307 phdr_memsz = phsize; 308 obj->phdr_loaded = true; 309 break; 310 } 311 } 312 if (obj->phdr_loaded) { 313 obj->phdr = (void *)(uintptr_t)phdr_vaddr; 314 obj->phsize = phdr_memsz; 315 } else { 316 Elf_Phdr *buf; 317 buf = xmalloc(phsize); 318 if (buf == NULL) { 319 _rtld_error("%s: cannot allocate program header", path); 320 goto bad; 321 } 322 memcpy(buf, phdr, phsize); 323 obj->phdr = buf; 324 obj->phsize = phsize; 325 } 326 dbg(("%s: phdr %p phsize %zu (%s)", obj->path, obj->phdr, obj->phsize, 327 obj->phdr_loaded ? "loaded" : "allocated")); 328 329 /* Unmap header if it overlaps the first load section. */ 330 if (base_offset < _rtld_pagesz) { 331 munmap(ehdr, _rtld_pagesz); 332 obj->ehdr = MAP_FAILED; 333 } 334 335 /* 336 * Calculate log2 of the base section alignment. 337 */ 338 mapflags = 0; 339 #ifdef MAP_ALIGNED 340 if (base_alignment > _rtld_pagesz) { 341 unsigned int log2 = 0; 342 for (; base_alignment > 1; base_alignment >>= 1) 343 log2++; 344 mapflags = MAP_ALIGNED(log2); 345 } 346 #endif 347 348 #ifdef RTLD_LOADER 349 base_addr = obj->isdynamic ? NULL : (caddr_t)base_vaddr; 350 #else 351 base_addr = NULL; 352 #endif 353 mapsize = base_vlimit - base_vaddr; 354 mapbase = mmap(base_addr, mapsize, text_flags, 355 mapflags | MAP_FILE | MAP_PRIVATE, fd, base_offset); 356 if (mapbase == MAP_FAILED) { 357 _rtld_error("mmap of entire address space failed: %s", 358 xstrerror(errno)); 359 goto bad; 360 } 361 362 /* Overlay the data segment onto the proper region. */ 363 data_addr = mapbase + (data_vaddr - base_vaddr); 364 if (mmap(data_addr, data_vlimit - data_vaddr, data_flags, 365 MAP_FILE | MAP_PRIVATE | MAP_FIXED, fd, data_offset) == 366 MAP_FAILED) { 367 _rtld_error("mmap of data failed: %s", xstrerror(errno)); 368 goto bad; 369 } 370 371 /* Overlay the bss segment onto the proper region. */ 372 if (mmap(mapbase + data_vlimit - base_vaddr, base_vlimit - data_vlimit, 373 data_flags, MAP_ANON | MAP_PRIVATE | MAP_FIXED, -1, 0) == 374 MAP_FAILED) { 375 _rtld_error("mmap of bss failed: %s", xstrerror(errno)); 376 goto bad; 377 } 378 379 /* Unmap the gap between the text and data. */ 380 gap_addr = mapbase + round_up(text_vlimit - base_vaddr); 381 gap_size = data_addr - gap_addr; 382 if (gap_size != 0 && mprotect(gap_addr, gap_size, PROT_NONE) == -1) { 383 _rtld_error("mprotect of text -> data gap failed: %s", 384 xstrerror(errno)); 385 goto bad; 386 } 387 388 #ifdef RTLD_LOADER 389 /* Clear any BSS in the last page of the data segment. */ 390 clear_addr = mapbase + (clear_vaddr - base_vaddr); 391 if ((nclear = data_vlimit - clear_vaddr) > 0) 392 memset(clear_addr, 0, nclear); 393 394 /* Non-file portion of BSS mapped above. */ 395 #endif 396 397 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 398 if (phtls != NULL) 399 obj->tlsinit = mapbase + tls_vaddr; 400 #endif 401 402 obj->mapbase = mapbase; 403 obj->mapsize = mapsize; 404 obj->relocbase = mapbase - base_vaddr; 405 406 #ifdef GNU_RELRO 407 obj->relro_page = obj->relocbase + round_down(relro_page); 408 obj->relro_size = round_up(relro_size); 409 #endif 410 411 if (obj->dynamic) 412 obj->dynamic = (void *)(obj->relocbase + (Elf_Addr)(uintptr_t)obj->dynamic); 413 if (obj->entry) 414 obj->entry = (void *)(obj->relocbase + (Elf_Addr)(uintptr_t)obj->entry); 415 if (obj->interp) 416 obj->interp = (void *)(obj->relocbase + (Elf_Addr)(uintptr_t)obj->interp); 417 if (obj->phdr_loaded) 418 obj->phdr = (void *)(obj->relocbase + (Elf_Addr)(uintptr_t)obj->phdr); 419 #ifdef __ARM_EABI__ 420 if (obj->exidx_start) 421 obj->exidx_start = (void *)(obj->relocbase + (Elf_Addr)(uintptr_t)obj->exidx_start); 422 #endif 423 424 return obj; 425 426 bad: 427 if (obj->ehdr != MAP_FAILED) 428 munmap(obj->ehdr, _rtld_pagesz); 429 if (mapbase != MAP_FAILED) 430 munmap(mapbase, mapsize); 431 _rtld_obj_free(obj); 432 return NULL; 433 } 434 435 void 436 _rtld_obj_free(Obj_Entry *obj) 437 { 438 Objlist_Entry *elm; 439 Name_Entry *entry; 440 441 #if defined(__HAVE_TLS_VARIANT_I) || defined(__HAVE_TLS_VARIANT_II) 442 if (obj->tls_done) 443 _rtld_tls_offset_free(obj); 444 #endif 445 xfree(obj->path); 446 while (obj->needed != NULL) { 447 Needed_Entry *needed = obj->needed; 448 obj->needed = needed->next; 449 xfree(needed); 450 } 451 while ((entry = SIMPLEQ_FIRST(&obj->names)) != NULL) { 452 SIMPLEQ_REMOVE_HEAD(&obj->names, link); 453 xfree(entry); 454 } 455 while ((elm = SIMPLEQ_FIRST(&obj->dldags)) != NULL) { 456 SIMPLEQ_REMOVE_HEAD(&obj->dldags, link); 457 xfree(elm); 458 } 459 while ((elm = SIMPLEQ_FIRST(&obj->dagmembers)) != NULL) { 460 SIMPLEQ_REMOVE_HEAD(&obj->dagmembers, link); 461 xfree(elm); 462 } 463 if (!obj->phdr_loaded) 464 xfree((void *)(uintptr_t)obj->phdr); 465 #ifdef COMBRELOC 466 _rtld_combreloc_reset(obj); 467 #endif 468 xfree(obj); 469 } 470 471 Obj_Entry * 472 _rtld_obj_new(void) 473 { 474 Obj_Entry *obj; 475 476 obj = CNEW(Obj_Entry); 477 SIMPLEQ_INIT(&obj->names); 478 SIMPLEQ_INIT(&obj->dldags); 479 SIMPLEQ_INIT(&obj->dagmembers); 480 return obj; 481 } 482 483 /* 484 * Given a set of ELF protection flags, return the corresponding protection 485 * flags for MMAP. 486 */ 487 static int 488 protflags(int elfflags) 489 { 490 int prot = 0; 491 492 if (elfflags & PF_R) 493 prot |= PROT_READ; 494 #ifdef RTLD_LOADER 495 if (elfflags & PF_W) 496 prot |= PROT_WRITE; 497 #endif 498 if (elfflags & PF_X) 499 prot |= PROT_EXEC; 500 return prot; 501 } 502