exec_elf.c revision 1.16 1 1.16 christos /* $NetBSD: exec_elf.c,v 1.16 2010/03/20 01:45:30 christos Exp $ */
2 1.10 ad
3 1.10 ad /*-
4 1.10 ad * Copyright (c) 1994, 2000, 2005 The NetBSD Foundation, Inc.
5 1.10 ad * All rights reserved.
6 1.10 ad *
7 1.10 ad * This code is derived from software contributed to The NetBSD Foundation
8 1.10 ad * by Christos Zoulas.
9 1.10 ad *
10 1.10 ad * Redistribution and use in source and binary forms, with or without
11 1.10 ad * modification, are permitted provided that the following conditions
12 1.10 ad * are met:
13 1.10 ad * 1. Redistributions of source code must retain the above copyright
14 1.10 ad * notice, this list of conditions and the following disclaimer.
15 1.10 ad * 2. Redistributions in binary form must reproduce the above copyright
16 1.10 ad * notice, this list of conditions and the following disclaimer in the
17 1.10 ad * documentation and/or other materials provided with the distribution.
18 1.10 ad *
19 1.10 ad * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20 1.10 ad * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21 1.10 ad * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22 1.10 ad * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23 1.10 ad * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24 1.10 ad * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25 1.10 ad * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26 1.10 ad * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27 1.10 ad * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28 1.10 ad * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29 1.10 ad * POSSIBILITY OF SUCH DAMAGE.
30 1.10 ad */
31 1.1 fvdl
32 1.1 fvdl /*
33 1.10 ad * Copyright (c) 1996 Christopher G. Demetriou
34 1.1 fvdl * All rights reserved.
35 1.1 fvdl *
36 1.1 fvdl * Redistribution and use in source and binary forms, with or without
37 1.1 fvdl * modification, are permitted provided that the following conditions
38 1.1 fvdl * are met:
39 1.1 fvdl * 1. Redistributions of source code must retain the above copyright
40 1.1 fvdl * notice, this list of conditions and the following disclaimer.
41 1.1 fvdl * 2. Redistributions in binary form must reproduce the above copyright
42 1.1 fvdl * notice, this list of conditions and the following disclaimer in the
43 1.1 fvdl * documentation and/or other materials provided with the distribution.
44 1.1 fvdl * 3. The name of the author may not be used to endorse or promote products
45 1.1 fvdl * derived from this software without specific prior written permission
46 1.1 fvdl *
47 1.1 fvdl * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
48 1.1 fvdl * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
49 1.1 fvdl * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
50 1.1 fvdl * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
51 1.1 fvdl * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
52 1.1 fvdl * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
53 1.1 fvdl * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
54 1.1 fvdl * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
55 1.1 fvdl * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
56 1.1 fvdl * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
57 1.1 fvdl */
58 1.1 fvdl
59 1.10 ad #include <sys/cdefs.h>
60 1.16 christos __KERNEL_RCSID(1, "$NetBSD: exec_elf.c,v 1.16 2010/03/20 01:45:30 christos Exp $");
61 1.10 ad
62 1.10 ad #ifdef _KERNEL_OPT
63 1.10 ad #include "opt_pax.h"
64 1.10 ad #endif /* _KERNEL_OPT */
65 1.10 ad
66 1.1 fvdl #include <sys/param.h>
67 1.1 fvdl #include <sys/proc.h>
68 1.1 fvdl #include <sys/malloc.h>
69 1.10 ad #include <sys/kmem.h>
70 1.1 fvdl #include <sys/namei.h>
71 1.1 fvdl #include <sys/vnode.h>
72 1.1 fvdl #include <sys/exec.h>
73 1.1 fvdl #include <sys/exec_elf.h>
74 1.8 christos #include <sys/syscall.h>
75 1.8 christos #include <sys/signalvar.h>
76 1.10 ad #include <sys/mount.h>
77 1.10 ad #include <sys/stat.h>
78 1.10 ad #include <sys/kauth.h>
79 1.10 ad #include <sys/bitops.h>
80 1.10 ad
81 1.10 ad #include <sys/cpu.h>
82 1.10 ad #include <machine/reg.h>
83 1.1 fvdl
84 1.10 ad #include <compat/common/compat_util.h>
85 1.1 fvdl
86 1.10 ad #include <sys/pax.h>
87 1.1 fvdl
88 1.10 ad extern struct emul emul_netbsd;
89 1.1 fvdl
90 1.10 ad #define elf_check_header ELFNAME(check_header)
91 1.10 ad #define elf_copyargs ELFNAME(copyargs)
92 1.10 ad #define elf_load_file ELFNAME(load_file)
93 1.10 ad #define elf_load_psection ELFNAME(load_psection)
94 1.10 ad #define exec_elf_makecmds ELFNAME2(exec,makecmds)
95 1.10 ad #define netbsd_elf_signature ELFNAME2(netbsd,signature)
96 1.10 ad #define netbsd_elf_probe ELFNAME2(netbsd,probe)
97 1.10 ad #define coredump ELFNAMEEND(coredump)
98 1.1 fvdl
99 1.10 ad int elf_load_file(struct lwp *, struct exec_package *, char *,
100 1.10 ad struct exec_vmcmd_set *, u_long *, struct elf_args *, Elf_Addr *);
101 1.10 ad void elf_load_psection(struct exec_vmcmd_set *, struct vnode *,
102 1.10 ad const Elf_Phdr *, Elf_Addr *, u_long *, int *, int);
103 1.6 christos
104 1.10 ad int netbsd_elf_signature(struct lwp *, struct exec_package *, Elf_Ehdr *);
105 1.10 ad int netbsd_elf_probe(struct lwp *, struct exec_package *, void *, char *,
106 1.10 ad vaddr_t *);
107 1.1 fvdl
108 1.10 ad /* round up and down to page boundaries. */
109 1.10 ad #define ELF_ROUND(a, b) (((a) + (b) - 1) & ~((b) - 1))
110 1.10 ad #define ELF_TRUNC(a, b) ((a) & ~((b) - 1))
111 1.1 fvdl
112 1.15 christos /*
113 1.15 christos * Arbitrary limits to avoid DoS for excessive memory allocation.
114 1.15 christos */
115 1.15 christos #define MAXPHNUM 128
116 1.15 christos #define MAXSHNUM 32768
117 1.15 christos #define MAXNOTESIZE 1024
118 1.1 fvdl
119 1.1 fvdl /*
120 1.10 ad * We don't move this code in kern_pax.c because it is compiled twice.
121 1.8 christos */
122 1.10 ad static void
123 1.16 christos elf_placedynexec(struct lwp *l, struct exec_package *epp, Elf_Ehdr *eh,
124 1.10 ad Elf_Phdr *ph)
125 1.10 ad {
126 1.16 christos size_t offset, i;
127 1.10 ad
128 1.16 christos #ifdef PAX_ASLR
129 1.15 christos if (pax_aslr_active(l)) {
130 1.15 christos size_t pax_align, l2, delta;
131 1.15 christos uint32_t r;
132 1.10 ad
133 1.15 christos /*
134 1.15 christos * find align XXX: not all sections might have the same
135 1.15 christos * alignment
136 1.15 christos */
137 1.15 christos for (pax_align = i = 0; i < eh->e_phnum; i++)
138 1.15 christos if (ph[i].p_type == PT_LOAD) {
139 1.15 christos pax_align = ph[i].p_align;
140 1.15 christos break;
141 1.15 christos }
142 1.10 ad
143 1.15 christos r = arc4random();
144 1.8 christos
145 1.15 christos if (pax_align == 0)
146 1.15 christos pax_align = PGSHIFT;
147 1.15 christos l2 = ilog2(pax_align);
148 1.15 christos delta = PAX_ASLR_DELTA(r, l2, PAX_ASLR_DELTA_EXEC_LEN);
149 1.15 christos uprintf("r=0x%x a=0x%x p=0x%x Delta=0x%lx\n", r, l2, PGSHIFT,
150 1.15 christos delta);
151 1.16 christos offset = ELF_TRUNC(delta, pax_align) + PAGE_SIZE;
152 1.16 christos uprintf("pax offset=0x%zx entry=0x%llx\n",
153 1.16 christos pax_offset, (unsigned long long)eh->e_entry);
154 1.15 christos } else
155 1.16 christos #endif /* PAX_ASLR */
156 1.16 christos offset = PAGE_SIZE;
157 1.10 ad
158 1.10 ad for (i = 0; i < eh->e_phnum; i++)
159 1.10 ad ph[i].p_vaddr += pax_offset;
160 1.16 christos eh->e_entry += offset;
161 1.10 ad }
162 1.8 christos
163 1.8 christos /*
164 1.1 fvdl * Copy arguments onto the stack in the normal way, but add some
165 1.1 fvdl * extra information in case of dynamic binding.
166 1.1 fvdl */
167 1.10 ad int
168 1.10 ad elf_copyargs(struct lwp *l, struct exec_package *pack,
169 1.10 ad struct ps_strings *arginfo, char **stackp, void *argp)
170 1.1 fvdl {
171 1.10 ad size_t len, vlen;
172 1.10 ad AuxInfo ai[ELF_AUX_ENTRIES], *a, *execname;
173 1.1 fvdl struct elf_args *ap;
174 1.10 ad int error;
175 1.1 fvdl
176 1.10 ad if ((error = copyargs(l, pack, arginfo, stackp, argp)) != 0)
177 1.10 ad return error;
178 1.10 ad
179 1.10 ad a = ai;
180 1.10 ad execname = NULL;
181 1.1 fvdl
182 1.1 fvdl /*
183 1.1 fvdl * Push extra arguments on the stack needed by dynamically
184 1.1 fvdl * linked binaries
185 1.1 fvdl */
186 1.10 ad if ((ap = (struct elf_args *)pack->ep_emul_arg)) {
187 1.10 ad struct vattr *vap = pack->ep_vap;
188 1.10 ad
189 1.10 ad a->a_type = AT_PHDR;
190 1.10 ad a->a_v = ap->arg_phaddr;
191 1.10 ad a++;
192 1.10 ad
193 1.10 ad a->a_type = AT_PHENT;
194 1.10 ad a->a_v = ap->arg_phentsize;
195 1.10 ad a++;
196 1.10 ad
197 1.10 ad a->a_type = AT_PHNUM;
198 1.10 ad a->a_v = ap->arg_phnum;
199 1.10 ad a++;
200 1.1 fvdl
201 1.10 ad a->a_type = AT_PAGESZ;
202 1.10 ad a->a_v = PAGE_SIZE;
203 1.1 fvdl a++;
204 1.1 fvdl
205 1.10 ad a->a_type = AT_BASE;
206 1.10 ad a->a_v = ap->arg_interp;
207 1.1 fvdl a++;
208 1.1 fvdl
209 1.10 ad a->a_type = AT_FLAGS;
210 1.10 ad a->a_v = 0;
211 1.1 fvdl a++;
212 1.1 fvdl
213 1.10 ad a->a_type = AT_ENTRY;
214 1.10 ad a->a_v = ap->arg_entry;
215 1.1 fvdl a++;
216 1.1 fvdl
217 1.10 ad a->a_type = AT_EUID;
218 1.10 ad if (vap->va_mode & S_ISUID)
219 1.10 ad a->a_v = vap->va_uid;
220 1.10 ad else
221 1.10 ad a->a_v = kauth_cred_geteuid(l->l_cred);
222 1.1 fvdl a++;
223 1.1 fvdl
224 1.10 ad a->a_type = AT_RUID;
225 1.10 ad a->a_v = kauth_cred_getuid(l->l_cred);
226 1.1 fvdl a++;
227 1.1 fvdl
228 1.10 ad a->a_type = AT_EGID;
229 1.10 ad if (vap->va_mode & S_ISGID)
230 1.10 ad a->a_v = vap->va_gid;
231 1.10 ad else
232 1.10 ad a->a_v = kauth_cred_getegid(l->l_cred);
233 1.1 fvdl a++;
234 1.1 fvdl
235 1.10 ad a->a_type = AT_RGID;
236 1.10 ad a->a_v = kauth_cred_getgid(l->l_cred);
237 1.1 fvdl a++;
238 1.1 fvdl
239 1.10 ad if (pack->ep_path) {
240 1.10 ad execname = a;
241 1.10 ad a->a_type = AT_SUN_EXECNAME;
242 1.10 ad a++;
243 1.10 ad }
244 1.10 ad
245 1.10 ad free(ap, M_TEMP);
246 1.10 ad pack->ep_emul_arg = NULL;
247 1.1 fvdl }
248 1.10 ad
249 1.10 ad a->a_type = AT_NULL;
250 1.10 ad a->a_v = 0;
251 1.10 ad a++;
252 1.10 ad
253 1.10 ad vlen = (a - ai) * sizeof(AuxInfo);
254 1.10 ad
255 1.10 ad if (execname) {
256 1.10 ad char *path = pack->ep_path;
257 1.10 ad execname->a_v = (uintptr_t)(*stackp + vlen);
258 1.10 ad len = strlen(path) + 1;
259 1.10 ad if ((error = copyout(path, (*stackp + vlen), len)) != 0)
260 1.10 ad return error;
261 1.10 ad len = ALIGN(len);
262 1.10 ad } else
263 1.10 ad len = 0;
264 1.10 ad
265 1.10 ad if ((error = copyout(ai, *stackp, vlen)) != 0)
266 1.10 ad return error;
267 1.10 ad *stackp += vlen + len;
268 1.10 ad
269 1.10 ad return 0;
270 1.1 fvdl }
271 1.1 fvdl
272 1.1 fvdl /*
273 1.1 fvdl * elf_check_header():
274 1.1 fvdl *
275 1.1 fvdl * Check header for validity; return 0 of ok ENOEXEC if error
276 1.1 fvdl */
277 1.1 fvdl int
278 1.10 ad elf_check_header(Elf_Ehdr *eh, int type)
279 1.1 fvdl {
280 1.3 thorpej
281 1.10 ad if (memcmp(eh->e_ident, ELFMAG, SELFMAG) != 0 ||
282 1.10 ad eh->e_ident[EI_CLASS] != ELFCLASS)
283 1.1 fvdl return ENOEXEC;
284 1.1 fvdl
285 1.1 fvdl switch (eh->e_machine) {
286 1.10 ad
287 1.10 ad ELFDEFNNAME(MACHDEP_ID_CASES)
288 1.1 fvdl
289 1.1 fvdl default:
290 1.1 fvdl return ENOEXEC;
291 1.1 fvdl }
292 1.1 fvdl
293 1.10 ad if (ELF_EHDR_FLAGS_OK(eh) == 0)
294 1.10 ad return ENOEXEC;
295 1.10 ad
296 1.1 fvdl if (eh->e_type != type)
297 1.1 fvdl return ENOEXEC;
298 1.1 fvdl
299 1.15 christos if (eh->e_shnum > MAXSHNUM || eh->e_phnum > MAXPHNUM)
300 1.10 ad return ENOEXEC;
301 1.10 ad
302 1.1 fvdl return 0;
303 1.1 fvdl }
304 1.1 fvdl
305 1.1 fvdl /*
306 1.1 fvdl * elf_load_psection():
307 1.10 ad *
308 1.1 fvdl * Load a psection at the appropriate address
309 1.1 fvdl */
310 1.10 ad void
311 1.10 ad elf_load_psection(struct exec_vmcmd_set *vcset, struct vnode *vp,
312 1.10 ad const Elf_Phdr *ph, Elf_Addr *addr, u_long *size, int *prot, int flags)
313 1.1 fvdl {
314 1.10 ad u_long msize, psize, rm, rf;
315 1.1 fvdl long diff, offset;
316 1.1 fvdl
317 1.1 fvdl /*
318 1.10 ad * If the user specified an address, then we load there.
319 1.10 ad */
320 1.10 ad if (*addr == ELFDEFNNAME(NO_ADDR))
321 1.10 ad *addr = ph->p_vaddr;
322 1.10 ad
323 1.10 ad if (ph->p_align > 1) {
324 1.10 ad /*
325 1.10 ad * Make sure we are virtually aligned as we are supposed to be.
326 1.10 ad */
327 1.10 ad diff = ph->p_vaddr - ELF_TRUNC(ph->p_vaddr, ph->p_align);
328 1.10 ad KASSERT(*addr - diff == ELF_TRUNC(*addr, ph->p_align));
329 1.10 ad /*
330 1.10 ad * But make sure to not map any pages before the start of the
331 1.10 ad * psection by limiting the difference to within a page.
332 1.10 ad */
333 1.10 ad diff &= PAGE_MASK;
334 1.10 ad } else
335 1.10 ad diff = 0;
336 1.1 fvdl
337 1.10 ad *prot |= (ph->p_flags & PF_R) ? VM_PROT_READ : 0;
338 1.10 ad *prot |= (ph->p_flags & PF_W) ? VM_PROT_WRITE : 0;
339 1.10 ad *prot |= (ph->p_flags & PF_X) ? VM_PROT_EXECUTE : 0;
340 1.1 fvdl
341 1.10 ad /*
342 1.10 ad * Adjust everything so it all starts on a page boundary.
343 1.10 ad */
344 1.10 ad *addr -= diff;
345 1.1 fvdl offset = ph->p_offset - diff;
346 1.1 fvdl *size = ph->p_filesz + diff;
347 1.1 fvdl msize = ph->p_memsz + diff;
348 1.1 fvdl
349 1.10 ad if (ph->p_align >= PAGE_SIZE) {
350 1.10 ad if ((ph->p_flags & PF_W) != 0) {
351 1.10 ad /*
352 1.10 ad * Because the pagedvn pager can't handle zero fill
353 1.10 ad * of the last data page if it's not page aligned we
354 1.10 ad * map the last page readvn.
355 1.10 ad */
356 1.10 ad psize = trunc_page(*size);
357 1.10 ad } else {
358 1.10 ad psize = round_page(*size);
359 1.10 ad }
360 1.10 ad } else {
361 1.10 ad psize = *size;
362 1.10 ad }
363 1.10 ad
364 1.10 ad if (psize > 0) {
365 1.10 ad NEW_VMCMD2(vcset, ph->p_align < PAGE_SIZE ?
366 1.10 ad vmcmd_map_readvn : vmcmd_map_pagedvn, psize, *addr, vp,
367 1.10 ad offset, *prot, flags);
368 1.10 ad flags &= VMCMD_RELATIVE;
369 1.10 ad }
370 1.10 ad if (psize < *size) {
371 1.10 ad NEW_VMCMD2(vcset, vmcmd_map_readvn, *size - psize,
372 1.10 ad *addr + psize, vp, offset + psize, *prot, flags);
373 1.10 ad }
374 1.1 fvdl
375 1.1 fvdl /*
376 1.10 ad * Check if we need to extend the size of the segment (does
377 1.10 ad * bss extend page the next page boundary)?
378 1.10 ad */
379 1.1 fvdl rm = round_page(*addr + msize);
380 1.1 fvdl rf = round_page(*addr + *size);
381 1.1 fvdl
382 1.1 fvdl if (rm != rf) {
383 1.10 ad NEW_VMCMD2(vcset, vmcmd_map_zero, rm - rf, rf, NULLVP,
384 1.10 ad 0, *prot, flags & VMCMD_RELATIVE);
385 1.1 fvdl *size = msize;
386 1.1 fvdl }
387 1.1 fvdl }
388 1.1 fvdl
389 1.1 fvdl /*
390 1.1 fvdl * elf_load_file():
391 1.1 fvdl *
392 1.1 fvdl * Load a file (interpreter/library) pointed to by path
393 1.1 fvdl * [stolen from coff_load_shlib()]. Made slightly generic
394 1.1 fvdl * so it might be used externally.
395 1.1 fvdl */
396 1.1 fvdl int
397 1.10 ad elf_load_file(struct lwp *l, struct exec_package *epp, char *path,
398 1.10 ad struct exec_vmcmd_set *vcset, u_long *entryoff, struct elf_args *ap,
399 1.10 ad Elf_Addr *last)
400 1.1 fvdl {
401 1.1 fvdl int error, i;
402 1.10 ad struct vnode *vp;
403 1.10 ad struct vattr attr;
404 1.10 ad Elf_Ehdr eh;
405 1.10 ad Elf_Phdr *ph = NULL;
406 1.10 ad const Elf_Phdr *ph0;
407 1.10 ad const Elf_Phdr *base_ph;
408 1.10 ad const Elf_Phdr *last_ph;
409 1.1 fvdl u_long phsize;
410 1.10 ad Elf_Addr addr = *last;
411 1.10 ad struct proc *p;
412 1.10 ad
413 1.10 ad p = l->l_proc;
414 1.10 ad
415 1.10 ad /*
416 1.10 ad * 1. open file
417 1.10 ad * 2. read filehdr
418 1.10 ad * 3. map text, data, and bss out of it using VM_*
419 1.10 ad */
420 1.10 ad vp = epp->ep_interp;
421 1.10 ad if (vp == NULL) {
422 1.10 ad error = emul_find_interp(l, epp, path);
423 1.10 ad if (error != 0)
424 1.10 ad return error;
425 1.10 ad vp = epp->ep_interp;
426 1.10 ad }
427 1.10 ad /* We'll tidy this ourselves - otherwise we have locking issues */
428 1.10 ad epp->ep_interp = NULL;
429 1.10 ad vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
430 1.1 fvdl
431 1.1 fvdl /*
432 1.10 ad * Similarly, if it's not marked as executable, or it's not a regular
433 1.10 ad * file, we don't allow it to be used.
434 1.10 ad */
435 1.10 ad if (vp->v_type != VREG) {
436 1.10 ad error = EACCES;
437 1.10 ad goto badunlock;
438 1.10 ad }
439 1.10 ad if ((error = VOP_ACCESS(vp, VEXEC, l->l_cred)) != 0)
440 1.10 ad goto badunlock;
441 1.10 ad
442 1.10 ad /* get attributes */
443 1.10 ad if ((error = VOP_GETATTR(vp, &attr, l->l_cred)) != 0)
444 1.10 ad goto badunlock;
445 1.10 ad
446 1.10 ad /*
447 1.10 ad * Check mount point. Though we're not trying to exec this binary,
448 1.10 ad * we will be executing code from it, so if the mount point
449 1.10 ad * disallows execution or set-id-ness, we punt or kill the set-id.
450 1.10 ad */
451 1.10 ad if (vp->v_mount->mnt_flag & MNT_NOEXEC) {
452 1.10 ad error = EACCES;
453 1.10 ad goto badunlock;
454 1.1 fvdl }
455 1.10 ad if (vp->v_mount->mnt_flag & MNT_NOSUID)
456 1.10 ad epp->ep_vap->va_mode &= ~(S_ISUID | S_ISGID);
457 1.10 ad
458 1.10 ad #ifdef notyet /* XXX cgd 960926 */
459 1.10 ad XXX cgd 960926: (maybe) VOP_OPEN it (and VOP_CLOSE in copyargs?)
460 1.10 ad #endif
461 1.10 ad
462 1.10 ad error = vn_marktext(vp);
463 1.10 ad if (error)
464 1.10 ad goto badunlock;
465 1.10 ad
466 1.10 ad VOP_UNLOCK(vp, 0);
467 1.10 ad
468 1.10 ad if ((error = exec_read_from(l, vp, 0, &eh, sizeof(eh))) != 0)
469 1.10 ad goto bad;
470 1.10 ad
471 1.10 ad if ((error = elf_check_header(&eh, ET_DYN)) != 0)
472 1.1 fvdl goto bad;
473 1.1 fvdl
474 1.10 ad if (eh.e_phnum > MAXPHNUM || eh.e_phnum == 0) {
475 1.10 ad error = ENOEXEC;
476 1.1 fvdl goto bad;
477 1.10 ad }
478 1.1 fvdl
479 1.10 ad phsize = eh.e_phnum * sizeof(Elf_Phdr);
480 1.10 ad ph = kmem_alloc(phsize, KM_SLEEP);
481 1.1 fvdl
482 1.10 ad if ((error = exec_read_from(l, vp, eh.e_phoff, ph, phsize)) != 0)
483 1.1 fvdl goto bad;
484 1.1 fvdl
485 1.10 ad #ifdef ELF_INTERP_NON_RELOCATABLE
486 1.10 ad /*
487 1.10 ad * Evil hack: Only MIPS should be non-relocatable, and the
488 1.10 ad * psections should have a high address (typically 0x5ffe0000).
489 1.10 ad * If it's now relocatable, it should be linked at 0 and the
490 1.10 ad * psections should have zeros in the upper part of the address.
491 1.10 ad * Otherwise, force the load at the linked address.
492 1.10 ad */
493 1.10 ad if (*last == ELF_LINK_ADDR && (ph->p_vaddr & 0xffff0000) == 0)
494 1.10 ad *last = ELFDEFNNAME(NO_ADDR);
495 1.10 ad #endif
496 1.10 ad
497 1.10 ad /*
498 1.10 ad * If no position to load the interpreter was set by a probe
499 1.10 ad * function, pick the same address that a non-fixed mmap(0, ..)
500 1.10 ad * would (i.e. something safely out of the way).
501 1.10 ad */
502 1.10 ad if (*last == ELFDEFNNAME(NO_ADDR)) {
503 1.10 ad u_long limit = 0;
504 1.10 ad /*
505 1.10 ad * Find the start and ending addresses of the psections to
506 1.10 ad * be loaded. This will give us the size.
507 1.10 ad */
508 1.10 ad for (i = 0, ph0 = ph, base_ph = NULL; i < eh.e_phnum;
509 1.10 ad i++, ph0++) {
510 1.10 ad if (ph0->p_type == PT_LOAD) {
511 1.10 ad u_long psize = ph0->p_vaddr + ph0->p_memsz;
512 1.10 ad if (base_ph == NULL)
513 1.10 ad base_ph = ph0;
514 1.10 ad if (psize > limit)
515 1.10 ad limit = psize;
516 1.10 ad }
517 1.10 ad }
518 1.10 ad
519 1.10 ad if (base_ph == NULL) {
520 1.10 ad error = ENOEXEC;
521 1.10 ad goto bad;
522 1.10 ad }
523 1.10 ad
524 1.10 ad /*
525 1.10 ad * Now compute the size and load address.
526 1.10 ad */
527 1.10 ad addr = (*epp->ep_esch->es_emul->e_vm_default_addr)(p,
528 1.10 ad epp->ep_daddr,
529 1.10 ad round_page(limit) - trunc_page(base_ph->p_vaddr));
530 1.10 ad } else
531 1.10 ad addr = *last; /* may be ELF_LINK_ADDR */
532 1.10 ad
533 1.1 fvdl /*
534 1.10 ad * Load all the necessary sections
535 1.10 ad */
536 1.10 ad for (i = 0, ph0 = ph, base_ph = NULL, last_ph = NULL;
537 1.10 ad i < eh.e_phnum; i++, ph0++) {
538 1.10 ad switch (ph0->p_type) {
539 1.10 ad case PT_LOAD: {
540 1.10 ad u_long size;
541 1.10 ad int prot = 0;
542 1.10 ad int flags;
543 1.10 ad
544 1.10 ad if (base_ph == NULL) {
545 1.10 ad /*
546 1.10 ad * First encountered psection is always the
547 1.10 ad * base psection. Make sure it's aligned
548 1.10 ad * properly (align down for topdown and align
549 1.10 ad * upwards for not topdown).
550 1.10 ad */
551 1.10 ad base_ph = ph0;
552 1.10 ad flags = VMCMD_BASE;
553 1.10 ad if (addr == ELF_LINK_ADDR)
554 1.10 ad addr = ph0->p_vaddr;
555 1.10 ad if (p->p_vmspace->vm_map.flags & VM_MAP_TOPDOWN)
556 1.10 ad addr = ELF_TRUNC(addr, ph0->p_align);
557 1.10 ad else
558 1.10 ad addr = ELF_ROUND(addr, ph0->p_align);
559 1.10 ad } else {
560 1.10 ad u_long limit = round_page(last_ph->p_vaddr
561 1.10 ad + last_ph->p_memsz);
562 1.10 ad u_long base = trunc_page(ph0->p_vaddr);
563 1.10 ad
564 1.10 ad /*
565 1.10 ad * If there is a gap in between the psections,
566 1.10 ad * map it as inaccessible so nothing else
567 1.10 ad * mmap'ed will be placed there.
568 1.10 ad */
569 1.10 ad if (limit != base) {
570 1.10 ad NEW_VMCMD2(vcset, vmcmd_map_zero,
571 1.10 ad base - limit,
572 1.10 ad limit - base_ph->p_vaddr, NULLVP,
573 1.10 ad 0, VM_PROT_NONE, VMCMD_RELATIVE);
574 1.10 ad }
575 1.1 fvdl
576 1.10 ad addr = ph0->p_vaddr - base_ph->p_vaddr;
577 1.10 ad flags = VMCMD_RELATIVE;
578 1.10 ad }
579 1.10 ad last_ph = ph0;
580 1.10 ad elf_load_psection(vcset, vp, &ph[i], &addr,
581 1.10 ad &size, &prot, flags);
582 1.10 ad /*
583 1.10 ad * If entry is within this psection then this
584 1.10 ad * must contain the .text section. *entryoff is
585 1.10 ad * relative to the base psection.
586 1.10 ad */
587 1.10 ad if (eh.e_entry >= ph0->p_vaddr &&
588 1.10 ad eh.e_entry < (ph0->p_vaddr + size)) {
589 1.10 ad *entryoff = eh.e_entry - base_ph->p_vaddr;
590 1.1 fvdl }
591 1.1 fvdl addr += size;
592 1.1 fvdl break;
593 1.10 ad }
594 1.1 fvdl
595 1.10 ad case PT_DYNAMIC:
596 1.10 ad case PT_PHDR:
597 1.10 ad break;
598 1.10 ad
599 1.10 ad case PT_NOTE:
600 1.1 fvdl break;
601 1.1 fvdl
602 1.1 fvdl default:
603 1.1 fvdl break;
604 1.1 fvdl }
605 1.1 fvdl }
606 1.1 fvdl
607 1.10 ad kmem_free(ph, phsize);
608 1.10 ad /*
609 1.10 ad * This value is ignored if TOPDOWN.
610 1.10 ad */
611 1.10 ad *last = addr;
612 1.10 ad vrele(vp);
613 1.10 ad return 0;
614 1.10 ad
615 1.10 ad badunlock:
616 1.10 ad VOP_UNLOCK(vp, 0);
617 1.10 ad
618 1.1 fvdl bad:
619 1.1 fvdl if (ph != NULL)
620 1.10 ad kmem_free(ph, phsize);
621 1.10 ad #ifdef notyet /* XXX cgd 960926 */
622 1.10 ad (maybe) VOP_CLOSE it
623 1.10 ad #endif
624 1.10 ad vrele(vp);
625 1.1 fvdl return error;
626 1.1 fvdl }
627 1.1 fvdl
628 1.1 fvdl /*
629 1.1 fvdl * exec_elf_makecmds(): Prepare an Elf binary's exec package
630 1.1 fvdl *
631 1.1 fvdl * First, set of the various offsets/lengths in the exec package.
632 1.1 fvdl *
633 1.1 fvdl * Then, mark the text image busy (so it can be demand paged) or error
634 1.1 fvdl * out if this is not possible. Finally, set up vmcmds for the
635 1.1 fvdl * text, data, bss, and stack segments.
636 1.1 fvdl */
637 1.1 fvdl int
638 1.10 ad exec_elf_makecmds(struct lwp *l, struct exec_package *epp)
639 1.10 ad {
640 1.10 ad Elf_Ehdr *eh = epp->ep_hdr;
641 1.10 ad Elf_Phdr *ph, *pp;
642 1.10 ad Elf_Addr phdr = 0, pos = 0;
643 1.10 ad int error, i, nload;
644 1.10 ad char *interp = NULL;
645 1.10 ad u_long phsize;
646 1.1 fvdl struct proc *p;
647 1.10 ad bool is_dyn;
648 1.1 fvdl
649 1.10 ad if (epp->ep_hdrvalid < sizeof(Elf_Ehdr))
650 1.1 fvdl return ENOEXEC;
651 1.1 fvdl
652 1.10 ad is_dyn = elf_check_header(eh, ET_DYN) == 0;
653 1.10 ad /*
654 1.10 ad * XXX allow for executing shared objects. It seems silly
655 1.10 ad * but other ELF-based systems allow it as well.
656 1.10 ad */
657 1.10 ad if (elf_check_header(eh, ET_EXEC) != 0 && !is_dyn)
658 1.1 fvdl return ENOEXEC;
659 1.1 fvdl
660 1.10 ad if (eh->e_phnum > MAXPHNUM || eh->e_phnum == 0)
661 1.10 ad return ENOEXEC;
662 1.10 ad
663 1.10 ad error = vn_marktext(epp->ep_vp);
664 1.10 ad if (error)
665 1.10 ad return error;
666 1.10 ad
667 1.1 fvdl /*
668 1.10 ad * Allocate space to hold all the program headers, and read them
669 1.10 ad * from the file
670 1.10 ad */
671 1.10 ad p = l->l_proc;
672 1.10 ad phsize = eh->e_phnum * sizeof(Elf_Phdr);
673 1.10 ad ph = kmem_alloc(phsize, KM_SLEEP);
674 1.1 fvdl
675 1.10 ad if ((error = exec_read_from(l, epp->ep_vp, eh->e_phoff, ph, phsize)) !=
676 1.10 ad 0)
677 1.1 fvdl goto bad;
678 1.1 fvdl
679 1.10 ad epp->ep_taddr = epp->ep_tsize = ELFDEFNNAME(NO_ADDR);
680 1.10 ad epp->ep_daddr = epp->ep_dsize = ELFDEFNNAME(NO_ADDR);
681 1.1 fvdl
682 1.1 fvdl for (i = 0; i < eh->e_phnum; i++) {
683 1.1 fvdl pp = &ph[i];
684 1.10 ad if (pp->p_type == PT_INTERP) {
685 1.10 ad if (pp->p_filesz >= MAXPATHLEN) {
686 1.10 ad error = ENOEXEC;
687 1.1 fvdl goto bad;
688 1.10 ad }
689 1.10 ad interp = PNBUF_GET();
690 1.10 ad interp[0] = '\0';
691 1.10 ad if ((error = exec_read_from(l, epp->ep_vp,
692 1.10 ad pp->p_offset, interp, pp->p_filesz)) != 0)
693 1.1 fvdl goto bad;
694 1.1 fvdl break;
695 1.1 fvdl }
696 1.1 fvdl }
697 1.1 fvdl
698 1.1 fvdl /*
699 1.1 fvdl * On the same architecture, we may be emulating different systems.
700 1.10 ad * See which one will accept this executable.
701 1.1 fvdl *
702 1.1 fvdl * Probe functions would normally see if the interpreter (if any)
703 1.1 fvdl * exists. Emulation packages may possibly replace the interpreter in
704 1.10 ad * interp[] with a changed path (/emul/xxx/<path>).
705 1.1 fvdl */
706 1.10 ad pos = ELFDEFNNAME(NO_ADDR);
707 1.10 ad if (epp->ep_esch->u.elf_probe_func) {
708 1.10 ad vaddr_t startp = (vaddr_t)pos;
709 1.1 fvdl
710 1.10 ad error = (*epp->ep_esch->u.elf_probe_func)(l, epp, eh, interp,
711 1.10 ad &startp);
712 1.1 fvdl if (error)
713 1.1 fvdl goto bad;
714 1.10 ad pos = (Elf_Addr)startp;
715 1.1 fvdl }
716 1.1 fvdl
717 1.10 ad #if defined(PAX_MPROTECT) || defined(PAX_SEGVGUARD) || defined(PAX_ASLR)
718 1.10 ad p->p_pax = epp->ep_pax_flags;
719 1.10 ad #endif /* PAX_MPROTECT || PAX_SEGVGUARD || PAX_ASLR */
720 1.10 ad
721 1.13 drochner if (is_dyn)
722 1.16 christos elf_placedynexec(l, epp, eh, ph);
723 1.10 ad
724 1.1 fvdl /*
725 1.10 ad * Load all the necessary sections
726 1.10 ad */
727 1.4 fvdl for (i = nload = 0; i < eh->e_phnum; i++) {
728 1.10 ad Elf_Addr addr = ELFDEFNNAME(NO_ADDR);
729 1.10 ad u_long size = 0;
730 1.1 fvdl int prot = 0;
731 1.1 fvdl
732 1.1 fvdl pp = &ph[i];
733 1.1 fvdl
734 1.1 fvdl switch (ph[i].p_type) {
735 1.10 ad case PT_LOAD:
736 1.4 fvdl /*
737 1.4 fvdl * XXX
738 1.4 fvdl * Can handle only 2 sections: text and data
739 1.4 fvdl */
740 1.10 ad if (nload++ == 2) {
741 1.10 ad error = ENOEXEC;
742 1.4 fvdl goto bad;
743 1.10 ad }
744 1.1 fvdl elf_load_psection(&epp->ep_vmcmds, epp->ep_vp,
745 1.10 ad &ph[i], &addr, &size, &prot, VMCMD_FIXED);
746 1.10 ad
747 1.4 fvdl /*
748 1.4 fvdl * Decide whether it's text or data by looking
749 1.4 fvdl * at the entry point.
750 1.4 fvdl */
751 1.10 ad if (eh->e_entry >= addr &&
752 1.10 ad eh->e_entry < (addr + size)) {
753 1.4 fvdl epp->ep_taddr = addr;
754 1.4 fvdl epp->ep_tsize = size;
755 1.10 ad if (epp->ep_daddr == ELFDEFNNAME(NO_ADDR)) {
756 1.10 ad epp->ep_daddr = addr;
757 1.10 ad epp->ep_dsize = size;
758 1.10 ad }
759 1.4 fvdl } else {
760 1.4 fvdl epp->ep_daddr = addr;
761 1.4 fvdl epp->ep_dsize = size;
762 1.4 fvdl }
763 1.1 fvdl break;
764 1.1 fvdl
765 1.10 ad case PT_SHLIB:
766 1.10 ad /* SCO has these sections. */
767 1.10 ad case PT_INTERP:
768 1.10 ad /* Already did this one. */
769 1.10 ad case PT_DYNAMIC:
770 1.10 ad break;
771 1.10 ad case PT_NOTE:
772 1.1 fvdl break;
773 1.10 ad case PT_PHDR:
774 1.4 fvdl /* Note address of program headers (in text segment) */
775 1.4 fvdl phdr = pp->p_vaddr;
776 1.7 christos break;
777 1.4 fvdl
778 1.1 fvdl default:
779 1.1 fvdl /*
780 1.10 ad * Not fatal; we don't need to understand everything.
781 1.1 fvdl */
782 1.1 fvdl break;
783 1.1 fvdl }
784 1.1 fvdl }
785 1.5 fvdl
786 1.5 fvdl /*
787 1.10 ad * Check if we found a dynamically linked binary and arrange to load
788 1.10 ad * its interpreter
789 1.5 fvdl */
790 1.10 ad if (interp) {
791 1.1 fvdl struct elf_args *ap;
792 1.10 ad int j = epp->ep_vmcmds.evs_used;
793 1.10 ad u_long interp_offset;
794 1.1 fvdl
795 1.11 cegger ap = (struct elf_args *)malloc(sizeof(struct elf_args),
796 1.10 ad M_TEMP, M_WAITOK);
797 1.10 ad if ((error = elf_load_file(l, epp, interp,
798 1.10 ad &epp->ep_vmcmds, &interp_offset, ap, &pos)) != 0) {
799 1.11 cegger free(ap, M_TEMP);
800 1.1 fvdl goto bad;
801 1.1 fvdl }
802 1.10 ad ap->arg_interp = epp->ep_vmcmds.evs_cmds[j].ev_addr;
803 1.10 ad epp->ep_entry = ap->arg_interp + interp_offset;
804 1.4 fvdl ap->arg_phaddr = phdr;
805 1.1 fvdl
806 1.1 fvdl ap->arg_phentsize = eh->e_phentsize;
807 1.1 fvdl ap->arg_phnum = eh->e_phnum;
808 1.1 fvdl ap->arg_entry = eh->e_entry;
809 1.1 fvdl
810 1.1 fvdl epp->ep_emul_arg = ap;
811 1.10 ad
812 1.10 ad PNBUF_PUT(interp);
813 1.1 fvdl } else
814 1.1 fvdl epp->ep_entry = eh->e_entry;
815 1.1 fvdl
816 1.8 christos #ifdef ELF_MAP_PAGE_ZERO
817 1.8 christos /* Dell SVR4 maps page zero, yeuch! */
818 1.10 ad NEW_VMCMD(&epp->ep_vmcmds, vmcmd_map_readvn, PAGE_SIZE, 0,
819 1.10 ad epp->ep_vp, 0, VM_PROT_READ);
820 1.8 christos #endif
821 1.10 ad kmem_free(ph, phsize);
822 1.10 ad return (*epp->ep_esch->es_setup_stack)(l, epp);
823 1.1 fvdl
824 1.1 fvdl bad:
825 1.10 ad if (interp)
826 1.10 ad PNBUF_PUT(interp);
827 1.10 ad kmem_free(ph, phsize);
828 1.1 fvdl kill_vmcmds(&epp->ep_vmcmds);
829 1.10 ad return error;
830 1.10 ad }
831 1.10 ad
832 1.10 ad int
833 1.10 ad netbsd_elf_signature(struct lwp *l, struct exec_package *epp,
834 1.10 ad Elf_Ehdr *eh)
835 1.10 ad {
836 1.10 ad size_t i;
837 1.15 christos Elf_Shdr *sh;
838 1.15 christos Elf_Nhdr *np;
839 1.15 christos size_t shsize;
840 1.10 ad int error;
841 1.10 ad int isnetbsd = 0;
842 1.10 ad char *ndata;
843 1.10 ad
844 1.10 ad epp->ep_pax_flags = 0;
845 1.15 christos if (eh->e_shnum > MAXSHNUM || eh->e_shnum == 0)
846 1.10 ad return ENOEXEC;
847 1.10 ad
848 1.15 christos shsize = eh->e_shnum * sizeof(Elf_Shdr);
849 1.15 christos sh = kmem_alloc(shsize, KM_SLEEP);
850 1.15 christos error = exec_read_from(l, epp->ep_vp, eh->e_shoff, sh, shsize);
851 1.10 ad if (error)
852 1.10 ad goto out;
853 1.10 ad
854 1.15 christos np = kmem_alloc(MAXNOTESIZE, KM_SLEEP);
855 1.15 christos for (i = 0; i < eh->e_shnum; i++) {
856 1.15 christos Elf_Shdr *shp = &sh[i];
857 1.15 christos
858 1.15 christos if (shp->sh_type != SHT_NOTE ||
859 1.15 christos shp->sh_size > MAXNOTESIZE ||
860 1.15 christos shp->sh_size < sizeof(Elf_Nhdr) + ELF_NOTE_NETBSD_NAMESZ)
861 1.10 ad continue;
862 1.10 ad
863 1.15 christos error = exec_read_from(l, epp->ep_vp, shp->sh_offset, np,
864 1.15 christos shp->sh_size);
865 1.10 ad if (error)
866 1.15 christos continue;
867 1.10 ad
868 1.10 ad ndata = (char *)(np + 1);
869 1.10 ad switch (np->n_type) {
870 1.10 ad case ELF_NOTE_TYPE_NETBSD_TAG:
871 1.10 ad if (np->n_namesz != ELF_NOTE_NETBSD_NAMESZ ||
872 1.10 ad np->n_descsz != ELF_NOTE_NETBSD_DESCSZ ||
873 1.10 ad memcmp(ndata, ELF_NOTE_NETBSD_NAME,
874 1.10 ad ELF_NOTE_NETBSD_NAMESZ))
875 1.15 christos goto bad;
876 1.10 ad isnetbsd = 1;
877 1.10 ad break;
878 1.10 ad
879 1.10 ad case ELF_NOTE_TYPE_PAX_TAG:
880 1.10 ad if (np->n_namesz != ELF_NOTE_PAX_NAMESZ ||
881 1.10 ad np->n_descsz != ELF_NOTE_PAX_DESCSZ ||
882 1.10 ad memcmp(ndata, ELF_NOTE_PAX_NAME,
883 1.15 christos ELF_NOTE_PAX_NAMESZ)) {
884 1.15 christos bad:
885 1.15 christos #ifdef DIAGNOSTIC
886 1.15 christos printf("%s: bad tag %d: "
887 1.15 christos "[%d %d, %d %d, %*.*s %*.*s]\n",
888 1.15 christos epp->ep_name,
889 1.15 christos np->n_type
890 1.15 christos np->n_namesz, ELF_NOTE_PAX_NAMESZ,
891 1.15 christos np->n_descsz, ELF_NOTE_PAX_DESCSZ,
892 1.15 christos ELF_NOTE_PAX_NAMESZ,
893 1.15 christos ELF_NOTE_PAX_NAMESZ,
894 1.15 christos ndata,
895 1.15 christos ELF_NOTE_PAX_NAMESZ,
896 1.15 christos ELF_NOTE_PAX_NAMESZ,
897 1.15 christos ELF_NOTE_PAX_NAME);
898 1.15 christos #endif
899 1.15 christos continue;
900 1.15 christos }
901 1.10 ad (void)memcpy(&epp->ep_pax_flags,
902 1.10 ad ndata + ELF_NOTE_PAX_NAMESZ,
903 1.10 ad sizeof(epp->ep_pax_flags));
904 1.10 ad break;
905 1.10 ad
906 1.10 ad default:
907 1.15 christos #ifdef DIAGNOSTIC
908 1.15 christos printf("%s: unknown note type %d\n", epp->ep_name,
909 1.15 christos np->n_type);
910 1.15 christos #endif
911 1.10 ad break;
912 1.10 ad }
913 1.10 ad }
914 1.15 christos kmem_free(np, MAXNOTESIZE);
915 1.10 ad
916 1.10 ad error = isnetbsd ? 0 : ENOEXEC;
917 1.10 ad out:
918 1.15 christos kmem_free(sh, shsize);
919 1.10 ad return error;
920 1.10 ad }
921 1.10 ad
922 1.10 ad int
923 1.10 ad netbsd_elf_probe(struct lwp *l, struct exec_package *epp, void *eh, char *itp,
924 1.10 ad vaddr_t *pos)
925 1.10 ad {
926 1.10 ad int error;
927 1.10 ad
928 1.10 ad if ((error = netbsd_elf_signature(l, epp, eh)) != 0)
929 1.10 ad return error;
930 1.12 matt #ifdef ELF_MD_PROBE_FUNC
931 1.12 matt if ((error = ELF_MD_PROBE_FUNC(l, epp, eh, itp, pos)) != 0)
932 1.12 matt return error;
933 1.12 matt #elif defined(ELF_INTERP_NON_RELOCATABLE)
934 1.10 ad *pos = ELF_LINK_ADDR;
935 1.10 ad #endif
936 1.10 ad return 0;
937 1.1 fvdl }
938