1 /* $NetBSD: symbol.c,v 1.44 2008/01/14 08:53:42 yamt Exp $ */ 2 3 /* 4 * Copyright 1996 John D. Polstra. 5 * Copyright 1996 Matt Thomas <matt@3am-software.com> 6 * Copyright 2002 Charles M. Hannum <root@ihack.net> 7 * All rights reserved. 8 * 9 * Redistribution and use in source and binary forms, with or without 10 * modification, are permitted provided that the following conditions 11 * are met: 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 2. Redistributions in binary form must reproduce the above copyright 15 * notice, this list of conditions and the following disclaimer in the 16 * documentation and/or other materials provided with the distribution. 17 * 3. All advertising materials mentioning features or use of this software 18 * must display the following acknowledgement: 19 * This product includes software developed by John Polstra. 20 * 4. The name of the author may not be used to endorse or promote products 21 * derived from this software without specific prior written permission. 22 * 23 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 24 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 25 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 26 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 27 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 28 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 29 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 30 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 31 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 32 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 33 */ 34 35 /* 36 * Dynamic linker for ELF. 37 * 38 * John Polstra <jdp@polstra.com>. 39 */ 40 41 #include <sys/cdefs.h> 42 #ifndef lint 43 __RCSID("$NetBSD: symbol.c,v 1.44 2008/01/14 08:53:42 yamt Exp $"); 44 #endif /* not lint */ 45 46 #include <err.h> 47 #include <errno.h> 48 #include <fcntl.h> 49 #include <stdarg.h> 50 #include <stdio.h> 51 #include <stdlib.h> 52 #include <string.h> 53 #include <unistd.h> 54 #include <sys/types.h> 55 #include <sys/mman.h> 56 #include <dirent.h> 57 58 #include "debug.h" 59 #include "rtld.h" 60 61 typedef void (*fptr_t)(void); 62 63 static bool 64 _rtld_is_exported(const Elf_Sym *def) 65 { 66 static const fptr_t _rtld_exports[] = { 67 (fptr_t)dlopen, 68 (fptr_t)dlclose, 69 (fptr_t)dlsym, 70 (fptr_t)dlerror, 71 (fptr_t)dladdr, 72 NULL 73 }; 74 int i; 75 fptr_t value; 76 77 value = (fptr_t)(_rtld_objself.relocbase + def->st_value); 78 for (i = 0; _rtld_exports[i] != NULL; i++) { 79 if (value == _rtld_exports[i]) 80 return true; 81 } 82 return false; 83 } 84 85 /* 86 * Hash function for symbol table lookup. Don't even think about changing 87 * this. It is specified by the System V ABI. 88 */ 89 unsigned long 90 _rtld_elf_hash(const char *name) 91 { 92 const unsigned char *p = (const unsigned char *) name; 93 unsigned long h = 0; 94 unsigned long g; 95 unsigned long c; 96 97 for (; __predict_true((c = *p) != '\0'); p++) { 98 h <<= 4; 99 h += c; 100 if ((g = h & 0xf0000000) != 0) { 101 h ^= g; 102 h ^= g >> 24; 103 } 104 } 105 return (h); 106 } 107 108 const Elf_Sym * 109 _rtld_symlook_list(const char *name, unsigned long hash, const Objlist *objlist, 110 const Obj_Entry **defobj_out, bool in_plt) 111 { 112 const Elf_Sym *symp; 113 const Elf_Sym *def; 114 const Obj_Entry *defobj; 115 const Objlist_Entry *elm; 116 117 def = NULL; 118 defobj = NULL; 119 SIMPLEQ_FOREACH(elm, objlist, link) { 120 rdbg(("search object %p (%s) for %s", elm->obj, elm->obj->path, 121 name)); 122 if ((symp = _rtld_symlook_obj(name, hash, elm->obj, in_plt)) 123 != NULL) { 124 if ((def == NULL) || 125 (ELF_ST_BIND(symp->st_info) != STB_WEAK)) { 126 def = symp; 127 defobj = elm->obj; 128 if (ELF_ST_BIND(def->st_info) != STB_WEAK) 129 break; 130 } 131 } 132 } 133 if (def != NULL) 134 *defobj_out = defobj; 135 return def; 136 } 137 138 /* 139 * Search the symbol table of a single shared object for a symbol of 140 * the given name. Returns a pointer to the symbol, or NULL if no 141 * definition was found. 142 * 143 * The symbol's hash value is passed in for efficiency reasons; that 144 * eliminates many recomputations of the hash value. 145 */ 146 const Elf_Sym * 147 _rtld_symlook_obj(const char *name, unsigned long hash, 148 const Obj_Entry *obj, bool in_plt) 149 { 150 unsigned long symnum; 151 152 for (symnum = obj->buckets[hash % obj->nbuckets]; 153 symnum != ELF_SYM_UNDEFINED; 154 symnum = obj->chains[symnum]) { 155 const Elf_Sym *symp; 156 const char *strp; 157 158 assert(symnum < obj->nchains); 159 symp = obj->symtab + symnum; 160 strp = obj->strtab + symp->st_name; 161 rdbg(("check \"%s\" vs \"%s\" in %p", name, strp, obj)); 162 if (name[1] == strp[1] && !strcmp(name, strp)) { 163 if (symp->st_shndx != SHN_UNDEF) 164 return symp; 165 #ifndef __mips__ 166 /* 167 * XXX DANGER WILL ROBINSON! 168 * If we have a function pointer in the executable's 169 * data section, it points to the executable's PLT 170 * slot, and there is NO relocation emitted. To make 171 * the function pointer comparable to function pointers 172 * in shared libraries, we must resolve data references 173 * in the libraries to point to PLT slots in the 174 * executable, if they exist. 175 */ 176 else if (!in_plt && symp->st_value != 0 && 177 ELF_ST_TYPE(symp->st_info) == STT_FUNC) 178 return symp; 179 #endif 180 else 181 return NULL; 182 } 183 } 184 185 return NULL; 186 } 187 188 /* 189 * Given a symbol number in a referencing object, find the corresponding 190 * definition of the symbol. Returns a pointer to the symbol, or NULL if 191 * no definition was found. Returns a pointer to the Obj_Entry of the 192 * defining object via the reference parameter DEFOBJ_OUT. 193 */ 194 const Elf_Sym * 195 _rtld_find_symdef(unsigned long symnum, const Obj_Entry *refobj, 196 const Obj_Entry **defobj_out, bool in_plt) 197 { 198 const Elf_Sym *ref; 199 const Elf_Sym *def; 200 const Obj_Entry *defobj; 201 const char *name; 202 unsigned long hash; 203 204 #ifdef COMBRELOC 205 /* 206 * COMBRELOC combines multiple reloc sections and sorts them to make 207 * dynamic symbol lookup caching possible. 208 * 209 * So if the lookup we are doing is the same as the previous lookup 210 * return the cached results. 211 */ 212 static unsigned long last_symnum; 213 static const Elf_Sym *last_def; 214 static const Obj_Entry *last_refobj; 215 static const Obj_Entry *last_defobj; 216 217 if (symnum == last_symnum && refobj == last_refobj 218 && in_plt == false) { 219 *defobj_out = last_defobj; 220 return last_def; 221 } 222 #endif 223 224 ref = refobj->symtab + symnum; 225 name = refobj->strtab + ref->st_name; 226 227 /* 228 * We don't have to do a full scale lookup if the symbol is local. 229 * We know it will bind to the instance in this load module; to 230 * which we already have a pointer (ie ref). 231 */ 232 if (ELF_ST_BIND(ref->st_info) != STB_LOCAL) { 233 if (ELF_ST_TYPE(ref->st_info) == STT_SECTION) { 234 _rtld_error("%s: Bogus symbol table entry %lu", 235 refobj->path, symnum); 236 } 237 238 hash = _rtld_elf_hash(name); 239 defobj = NULL; 240 def = _rtld_symlook_default(name, hash, refobj, &defobj, in_plt); 241 } else { 242 rdbg(("STB_LOCAL symbol %s in %s", name, refobj->path)); 243 def = ref; 244 defobj = refobj; 245 } 246 247 /* 248 * If we found no definition and the reference is weak, treat the 249 * symbol as having the value zero. 250 */ 251 if (def == NULL && ELF_ST_BIND(ref->st_info) == STB_WEAK) { 252 rdbg((" returning _rtld_sym_zero@_rtld_objmain")); 253 def = &_rtld_sym_zero; 254 defobj = _rtld_objmain; 255 } 256 257 if (def != NULL) { 258 *defobj_out = defobj; 259 #ifdef COMBRELOC 260 if (in_plt == false) { 261 /* 262 * Cache the lookup arguments and results if this was 263 * non-PLT lookup. 264 */ 265 last_symnum = symnum; 266 last_refobj = refobj; 267 last_def = def; 268 last_defobj = defobj; 269 } 270 #endif 271 } else { 272 rdbg(("lookup failed")); 273 _rtld_error("%s: Undefined %ssymbol \"%s\" (symnum = %ld)", 274 refobj->path, in_plt ? "PLT " : "", name, symnum); 275 } 276 return def; 277 } 278 279 /* 280 * Given a symbol name in a referencing object, find the corresponding 281 * definition of the symbol. Returns a pointer to the symbol, or NULL if 282 * no definition was found. Returns a pointer to the Obj_Entry of the 283 * defining object via the reference parameter DEFOBJ_OUT. 284 */ 285 const Elf_Sym * 286 _rtld_symlook_default(const char *name, unsigned long hash, 287 const Obj_Entry *refobj, const Obj_Entry **defobj_out, bool in_plt) 288 { 289 const Elf_Sym *def; 290 const Elf_Sym *symp; 291 const Obj_Entry *obj; 292 const Obj_Entry *defobj; 293 const Objlist_Entry *elm; 294 def = NULL; 295 defobj = NULL; 296 297 /* Look first in the referencing object if linked symbolically. */ 298 if (refobj->symbolic) { 299 rdbg(("search referencing object for %s", name)); 300 symp = _rtld_symlook_obj(name, hash, refobj, in_plt); 301 if (symp != NULL) { 302 def = symp; 303 defobj = refobj; 304 } 305 } 306 307 /* Search all objects loaded at program start up. */ 308 if (def == NULL || ELF_ST_BIND(def->st_info) == STB_WEAK) { 309 rdbg(("search _rtld_list_main for %s", name)); 310 symp = _rtld_symlook_list(name, hash, &_rtld_list_main, &obj, 311 in_plt); 312 if (symp != NULL && 313 (def == NULL || ELF_ST_BIND(symp->st_info) != STB_WEAK)) { 314 def = symp; 315 defobj = obj; 316 } 317 } 318 319 /* Search all RTLD_GLOBAL objects. */ 320 if (def == NULL || ELF_ST_BIND(def->st_info) == STB_WEAK) { 321 rdbg(("search _rtld_list_global for %s", name)); 322 symp = _rtld_symlook_list(name, hash, &_rtld_list_global, 323 &obj, in_plt); 324 if (symp != NULL && 325 (def == NULL || ELF_ST_BIND(symp->st_info) != STB_WEAK)) { 326 def = symp; 327 defobj = obj; 328 } 329 } 330 331 /* Search all dlopened DAGs containing the referencing object. */ 332 SIMPLEQ_FOREACH(elm, &refobj->dldags, link) { 333 if (def != NULL && ELF_ST_BIND(def->st_info) != STB_WEAK) 334 break; 335 rdbg(("search DAG with root %p (%s) for %s", elm->obj, 336 elm->obj->path, name)); 337 symp = _rtld_symlook_list(name, hash, &elm->obj->dagmembers, 338 &obj, in_plt); 339 if (symp != NULL && 340 (def == NULL || ELF_ST_BIND(symp->st_info) != STB_WEAK)) { 341 def = symp; 342 defobj = obj; 343 } 344 } 345 346 /* 347 * Search the dynamic linker itself, and possibly resolve the 348 * symbol from there. This is how the application links to 349 * dynamic linker services such as dlopen. Only the values listed 350 * in the "_rtld_exports" array can be resolved from the dynamic 351 * linker. 352 */ 353 if (def == NULL || ELF_ST_BIND(def->st_info) == STB_WEAK) { 354 rdbg(("Search the dynamic linker itself.")); 355 symp = _rtld_symlook_obj(name, hash, &_rtld_objself, in_plt); 356 if (symp != NULL && _rtld_is_exported(symp)) { 357 def = symp; 358 defobj = &_rtld_objself; 359 } 360 } 361 362 if (def != NULL) 363 *defobj_out = defobj; 364 return def; 365 } 366