exec_elf.c revision 1.19 1 1.19 drochner /* $NetBSD: exec_elf.c,v 1.19 2010/03/22 22:10:10 drochner Exp $ */
2 1.10 ad
3 1.10 ad /*-
4 1.10 ad * Copyright (c) 1994, 2000, 2005 The NetBSD Foundation, Inc.
5 1.10 ad * All rights reserved.
6 1.10 ad *
7 1.10 ad * This code is derived from software contributed to The NetBSD Foundation
8 1.10 ad * by Christos Zoulas.
9 1.10 ad *
10 1.10 ad * Redistribution and use in source and binary forms, with or without
11 1.10 ad * modification, are permitted provided that the following conditions
12 1.10 ad * are met:
13 1.10 ad * 1. Redistributions of source code must retain the above copyright
14 1.10 ad * notice, this list of conditions and the following disclaimer.
15 1.10 ad * 2. Redistributions in binary form must reproduce the above copyright
16 1.10 ad * notice, this list of conditions and the following disclaimer in the
17 1.10 ad * documentation and/or other materials provided with the distribution.
18 1.10 ad *
19 1.10 ad * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
20 1.10 ad * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
21 1.10 ad * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
22 1.10 ad * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
23 1.10 ad * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
24 1.10 ad * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25 1.10 ad * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26 1.10 ad * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
27 1.10 ad * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28 1.10 ad * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
29 1.10 ad * POSSIBILITY OF SUCH DAMAGE.
30 1.10 ad */
31 1.1 fvdl
32 1.1 fvdl /*
33 1.10 ad * Copyright (c) 1996 Christopher G. Demetriou
34 1.1 fvdl * All rights reserved.
35 1.1 fvdl *
36 1.1 fvdl * Redistribution and use in source and binary forms, with or without
37 1.1 fvdl * modification, are permitted provided that the following conditions
38 1.1 fvdl * are met:
39 1.1 fvdl * 1. Redistributions of source code must retain the above copyright
40 1.1 fvdl * notice, this list of conditions and the following disclaimer.
41 1.1 fvdl * 2. Redistributions in binary form must reproduce the above copyright
42 1.1 fvdl * notice, this list of conditions and the following disclaimer in the
43 1.1 fvdl * documentation and/or other materials provided with the distribution.
44 1.1 fvdl * 3. The name of the author may not be used to endorse or promote products
45 1.1 fvdl * derived from this software without specific prior written permission
46 1.1 fvdl *
47 1.1 fvdl * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
48 1.1 fvdl * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
49 1.1 fvdl * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
50 1.1 fvdl * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
51 1.1 fvdl * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
52 1.1 fvdl * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
53 1.1 fvdl * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
54 1.1 fvdl * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
55 1.1 fvdl * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
56 1.1 fvdl * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
57 1.1 fvdl */
58 1.1 fvdl
59 1.10 ad #include <sys/cdefs.h>
60 1.19 drochner __KERNEL_RCSID(1, "$NetBSD: exec_elf.c,v 1.19 2010/03/22 22:10:10 drochner Exp $");
61 1.10 ad
62 1.10 ad #ifdef _KERNEL_OPT
63 1.10 ad #include "opt_pax.h"
64 1.10 ad #endif /* _KERNEL_OPT */
65 1.10 ad
66 1.1 fvdl #include <sys/param.h>
67 1.1 fvdl #include <sys/proc.h>
68 1.1 fvdl #include <sys/malloc.h>
69 1.10 ad #include <sys/kmem.h>
70 1.1 fvdl #include <sys/namei.h>
71 1.1 fvdl #include <sys/vnode.h>
72 1.1 fvdl #include <sys/exec.h>
73 1.1 fvdl #include <sys/exec_elf.h>
74 1.8 christos #include <sys/syscall.h>
75 1.8 christos #include <sys/signalvar.h>
76 1.10 ad #include <sys/mount.h>
77 1.10 ad #include <sys/stat.h>
78 1.10 ad #include <sys/kauth.h>
79 1.10 ad #include <sys/bitops.h>
80 1.10 ad
81 1.10 ad #include <sys/cpu.h>
82 1.10 ad #include <machine/reg.h>
83 1.1 fvdl
84 1.10 ad #include <compat/common/compat_util.h>
85 1.1 fvdl
86 1.10 ad #include <sys/pax.h>
87 1.1 fvdl
88 1.10 ad extern struct emul emul_netbsd;
89 1.1 fvdl
90 1.10 ad #define elf_check_header ELFNAME(check_header)
91 1.10 ad #define elf_copyargs ELFNAME(copyargs)
92 1.10 ad #define elf_load_file ELFNAME(load_file)
93 1.10 ad #define elf_load_psection ELFNAME(load_psection)
94 1.10 ad #define exec_elf_makecmds ELFNAME2(exec,makecmds)
95 1.10 ad #define netbsd_elf_signature ELFNAME2(netbsd,signature)
96 1.10 ad #define netbsd_elf_probe ELFNAME2(netbsd,probe)
97 1.10 ad #define coredump ELFNAMEEND(coredump)
98 1.1 fvdl
99 1.10 ad int elf_load_file(struct lwp *, struct exec_package *, char *,
100 1.10 ad struct exec_vmcmd_set *, u_long *, struct elf_args *, Elf_Addr *);
101 1.10 ad void elf_load_psection(struct exec_vmcmd_set *, struct vnode *,
102 1.10 ad const Elf_Phdr *, Elf_Addr *, u_long *, int *, int);
103 1.6 christos
104 1.10 ad int netbsd_elf_signature(struct lwp *, struct exec_package *, Elf_Ehdr *);
105 1.10 ad int netbsd_elf_probe(struct lwp *, struct exec_package *, void *, char *,
106 1.10 ad vaddr_t *);
107 1.1 fvdl
108 1.10 ad /* round up and down to page boundaries. */
109 1.10 ad #define ELF_ROUND(a, b) (((a) + (b) - 1) & ~((b) - 1))
110 1.10 ad #define ELF_TRUNC(a, b) ((a) & ~((b) - 1))
111 1.1 fvdl
112 1.15 christos /*
113 1.15 christos * Arbitrary limits to avoid DoS for excessive memory allocation.
114 1.15 christos */
115 1.15 christos #define MAXPHNUM 128
116 1.15 christos #define MAXSHNUM 32768
117 1.15 christos #define MAXNOTESIZE 1024
118 1.1 fvdl
119 1.10 ad static void
120 1.16 christos elf_placedynexec(struct lwp *l, struct exec_package *epp, Elf_Ehdr *eh,
121 1.10 ad Elf_Phdr *ph)
122 1.10 ad {
123 1.19 drochner Elf_Addr align, offset;
124 1.19 drochner int i;
125 1.19 drochner
126 1.19 drochner for (align = i = 0; i < eh->e_phnum; i++)
127 1.19 drochner if (ph[i].p_type == PT_LOAD && ph[i].p_align > align)
128 1.19 drochner align = ph[i].p_align;
129 1.10 ad
130 1.16 christos #ifdef PAX_ASLR
131 1.15 christos if (pax_aslr_active(l)) {
132 1.15 christos size_t pax_align, l2, delta;
133 1.15 christos uint32_t r;
134 1.10 ad
135 1.19 drochner pax_align = align;
136 1.10 ad
137 1.15 christos r = arc4random();
138 1.8 christos
139 1.15 christos if (pax_align == 0)
140 1.15 christos pax_align = PGSHIFT;
141 1.15 christos l2 = ilog2(pax_align);
142 1.15 christos delta = PAX_ASLR_DELTA(r, l2, PAX_ASLR_DELTA_EXEC_LEN);
143 1.16 christos offset = ELF_TRUNC(delta, pax_align) + PAGE_SIZE;
144 1.17 christos #ifdef PAX_ASLR_DEBUG
145 1.18 christos uprintf("r=0x%x l2=0x%zx PGSHIFT=0x%x Delta=0x%zx\n", r, l2,
146 1.18 christos PGSHIFT, delta);
147 1.16 christos uprintf("pax offset=0x%zx entry=0x%llx\n",
148 1.17 christos offset, (unsigned long long)eh->e_entry);
149 1.17 christos #endif /* PAX_ASLR_DEBUG */
150 1.15 christos } else
151 1.16 christos #endif /* PAX_ASLR */
152 1.19 drochner offset = MAX(align, PAGE_SIZE);
153 1.10 ad
154 1.10 ad for (i = 0; i < eh->e_phnum; i++)
155 1.18 christos ph[i].p_vaddr += offset;
156 1.16 christos eh->e_entry += offset;
157 1.10 ad }
158 1.8 christos
159 1.8 christos /*
160 1.1 fvdl * Copy arguments onto the stack in the normal way, but add some
161 1.1 fvdl * extra information in case of dynamic binding.
162 1.1 fvdl */
163 1.10 ad int
164 1.10 ad elf_copyargs(struct lwp *l, struct exec_package *pack,
165 1.10 ad struct ps_strings *arginfo, char **stackp, void *argp)
166 1.1 fvdl {
167 1.10 ad size_t len, vlen;
168 1.10 ad AuxInfo ai[ELF_AUX_ENTRIES], *a, *execname;
169 1.1 fvdl struct elf_args *ap;
170 1.10 ad int error;
171 1.1 fvdl
172 1.10 ad if ((error = copyargs(l, pack, arginfo, stackp, argp)) != 0)
173 1.10 ad return error;
174 1.10 ad
175 1.10 ad a = ai;
176 1.10 ad execname = NULL;
177 1.1 fvdl
178 1.1 fvdl /*
179 1.1 fvdl * Push extra arguments on the stack needed by dynamically
180 1.1 fvdl * linked binaries
181 1.1 fvdl */
182 1.10 ad if ((ap = (struct elf_args *)pack->ep_emul_arg)) {
183 1.10 ad struct vattr *vap = pack->ep_vap;
184 1.10 ad
185 1.10 ad a->a_type = AT_PHDR;
186 1.10 ad a->a_v = ap->arg_phaddr;
187 1.10 ad a++;
188 1.10 ad
189 1.10 ad a->a_type = AT_PHENT;
190 1.10 ad a->a_v = ap->arg_phentsize;
191 1.10 ad a++;
192 1.10 ad
193 1.10 ad a->a_type = AT_PHNUM;
194 1.10 ad a->a_v = ap->arg_phnum;
195 1.10 ad a++;
196 1.1 fvdl
197 1.10 ad a->a_type = AT_PAGESZ;
198 1.10 ad a->a_v = PAGE_SIZE;
199 1.1 fvdl a++;
200 1.1 fvdl
201 1.10 ad a->a_type = AT_BASE;
202 1.10 ad a->a_v = ap->arg_interp;
203 1.1 fvdl a++;
204 1.1 fvdl
205 1.10 ad a->a_type = AT_FLAGS;
206 1.10 ad a->a_v = 0;
207 1.1 fvdl a++;
208 1.1 fvdl
209 1.10 ad a->a_type = AT_ENTRY;
210 1.10 ad a->a_v = ap->arg_entry;
211 1.1 fvdl a++;
212 1.1 fvdl
213 1.10 ad a->a_type = AT_EUID;
214 1.10 ad if (vap->va_mode & S_ISUID)
215 1.10 ad a->a_v = vap->va_uid;
216 1.10 ad else
217 1.10 ad a->a_v = kauth_cred_geteuid(l->l_cred);
218 1.1 fvdl a++;
219 1.1 fvdl
220 1.10 ad a->a_type = AT_RUID;
221 1.10 ad a->a_v = kauth_cred_getuid(l->l_cred);
222 1.1 fvdl a++;
223 1.1 fvdl
224 1.10 ad a->a_type = AT_EGID;
225 1.10 ad if (vap->va_mode & S_ISGID)
226 1.10 ad a->a_v = vap->va_gid;
227 1.10 ad else
228 1.10 ad a->a_v = kauth_cred_getegid(l->l_cred);
229 1.1 fvdl a++;
230 1.1 fvdl
231 1.10 ad a->a_type = AT_RGID;
232 1.10 ad a->a_v = kauth_cred_getgid(l->l_cred);
233 1.1 fvdl a++;
234 1.1 fvdl
235 1.10 ad if (pack->ep_path) {
236 1.10 ad execname = a;
237 1.10 ad a->a_type = AT_SUN_EXECNAME;
238 1.10 ad a++;
239 1.10 ad }
240 1.10 ad
241 1.10 ad free(ap, M_TEMP);
242 1.10 ad pack->ep_emul_arg = NULL;
243 1.1 fvdl }
244 1.10 ad
245 1.10 ad a->a_type = AT_NULL;
246 1.10 ad a->a_v = 0;
247 1.10 ad a++;
248 1.10 ad
249 1.10 ad vlen = (a - ai) * sizeof(AuxInfo);
250 1.10 ad
251 1.10 ad if (execname) {
252 1.10 ad char *path = pack->ep_path;
253 1.10 ad execname->a_v = (uintptr_t)(*stackp + vlen);
254 1.10 ad len = strlen(path) + 1;
255 1.10 ad if ((error = copyout(path, (*stackp + vlen), len)) != 0)
256 1.10 ad return error;
257 1.10 ad len = ALIGN(len);
258 1.10 ad } else
259 1.10 ad len = 0;
260 1.10 ad
261 1.10 ad if ((error = copyout(ai, *stackp, vlen)) != 0)
262 1.10 ad return error;
263 1.10 ad *stackp += vlen + len;
264 1.10 ad
265 1.10 ad return 0;
266 1.1 fvdl }
267 1.1 fvdl
268 1.1 fvdl /*
269 1.1 fvdl * elf_check_header():
270 1.1 fvdl *
271 1.1 fvdl * Check header for validity; return 0 of ok ENOEXEC if error
272 1.1 fvdl */
273 1.1 fvdl int
274 1.10 ad elf_check_header(Elf_Ehdr *eh, int type)
275 1.1 fvdl {
276 1.3 thorpej
277 1.10 ad if (memcmp(eh->e_ident, ELFMAG, SELFMAG) != 0 ||
278 1.10 ad eh->e_ident[EI_CLASS] != ELFCLASS)
279 1.1 fvdl return ENOEXEC;
280 1.1 fvdl
281 1.1 fvdl switch (eh->e_machine) {
282 1.10 ad
283 1.10 ad ELFDEFNNAME(MACHDEP_ID_CASES)
284 1.1 fvdl
285 1.1 fvdl default:
286 1.1 fvdl return ENOEXEC;
287 1.1 fvdl }
288 1.1 fvdl
289 1.10 ad if (ELF_EHDR_FLAGS_OK(eh) == 0)
290 1.10 ad return ENOEXEC;
291 1.10 ad
292 1.1 fvdl if (eh->e_type != type)
293 1.1 fvdl return ENOEXEC;
294 1.1 fvdl
295 1.15 christos if (eh->e_shnum > MAXSHNUM || eh->e_phnum > MAXPHNUM)
296 1.10 ad return ENOEXEC;
297 1.10 ad
298 1.1 fvdl return 0;
299 1.1 fvdl }
300 1.1 fvdl
301 1.1 fvdl /*
302 1.1 fvdl * elf_load_psection():
303 1.10 ad *
304 1.1 fvdl * Load a psection at the appropriate address
305 1.1 fvdl */
306 1.10 ad void
307 1.10 ad elf_load_psection(struct exec_vmcmd_set *vcset, struct vnode *vp,
308 1.10 ad const Elf_Phdr *ph, Elf_Addr *addr, u_long *size, int *prot, int flags)
309 1.1 fvdl {
310 1.10 ad u_long msize, psize, rm, rf;
311 1.1 fvdl long diff, offset;
312 1.1 fvdl
313 1.1 fvdl /*
314 1.10 ad * If the user specified an address, then we load there.
315 1.10 ad */
316 1.10 ad if (*addr == ELFDEFNNAME(NO_ADDR))
317 1.10 ad *addr = ph->p_vaddr;
318 1.10 ad
319 1.10 ad if (ph->p_align > 1) {
320 1.10 ad /*
321 1.10 ad * Make sure we are virtually aligned as we are supposed to be.
322 1.10 ad */
323 1.10 ad diff = ph->p_vaddr - ELF_TRUNC(ph->p_vaddr, ph->p_align);
324 1.10 ad KASSERT(*addr - diff == ELF_TRUNC(*addr, ph->p_align));
325 1.10 ad /*
326 1.10 ad * But make sure to not map any pages before the start of the
327 1.10 ad * psection by limiting the difference to within a page.
328 1.10 ad */
329 1.10 ad diff &= PAGE_MASK;
330 1.10 ad } else
331 1.10 ad diff = 0;
332 1.1 fvdl
333 1.10 ad *prot |= (ph->p_flags & PF_R) ? VM_PROT_READ : 0;
334 1.10 ad *prot |= (ph->p_flags & PF_W) ? VM_PROT_WRITE : 0;
335 1.10 ad *prot |= (ph->p_flags & PF_X) ? VM_PROT_EXECUTE : 0;
336 1.1 fvdl
337 1.10 ad /*
338 1.10 ad * Adjust everything so it all starts on a page boundary.
339 1.10 ad */
340 1.10 ad *addr -= diff;
341 1.1 fvdl offset = ph->p_offset - diff;
342 1.1 fvdl *size = ph->p_filesz + diff;
343 1.1 fvdl msize = ph->p_memsz + diff;
344 1.1 fvdl
345 1.10 ad if (ph->p_align >= PAGE_SIZE) {
346 1.10 ad if ((ph->p_flags & PF_W) != 0) {
347 1.10 ad /*
348 1.10 ad * Because the pagedvn pager can't handle zero fill
349 1.10 ad * of the last data page if it's not page aligned we
350 1.10 ad * map the last page readvn.
351 1.10 ad */
352 1.10 ad psize = trunc_page(*size);
353 1.10 ad } else {
354 1.10 ad psize = round_page(*size);
355 1.10 ad }
356 1.10 ad } else {
357 1.10 ad psize = *size;
358 1.10 ad }
359 1.10 ad
360 1.10 ad if (psize > 0) {
361 1.10 ad NEW_VMCMD2(vcset, ph->p_align < PAGE_SIZE ?
362 1.10 ad vmcmd_map_readvn : vmcmd_map_pagedvn, psize, *addr, vp,
363 1.10 ad offset, *prot, flags);
364 1.10 ad flags &= VMCMD_RELATIVE;
365 1.10 ad }
366 1.10 ad if (psize < *size) {
367 1.10 ad NEW_VMCMD2(vcset, vmcmd_map_readvn, *size - psize,
368 1.10 ad *addr + psize, vp, offset + psize, *prot, flags);
369 1.10 ad }
370 1.1 fvdl
371 1.1 fvdl /*
372 1.10 ad * Check if we need to extend the size of the segment (does
373 1.10 ad * bss extend page the next page boundary)?
374 1.10 ad */
375 1.1 fvdl rm = round_page(*addr + msize);
376 1.1 fvdl rf = round_page(*addr + *size);
377 1.1 fvdl
378 1.1 fvdl if (rm != rf) {
379 1.10 ad NEW_VMCMD2(vcset, vmcmd_map_zero, rm - rf, rf, NULLVP,
380 1.10 ad 0, *prot, flags & VMCMD_RELATIVE);
381 1.1 fvdl *size = msize;
382 1.1 fvdl }
383 1.1 fvdl }
384 1.1 fvdl
385 1.1 fvdl /*
386 1.1 fvdl * elf_load_file():
387 1.1 fvdl *
388 1.1 fvdl * Load a file (interpreter/library) pointed to by path
389 1.1 fvdl * [stolen from coff_load_shlib()]. Made slightly generic
390 1.1 fvdl * so it might be used externally.
391 1.1 fvdl */
392 1.1 fvdl int
393 1.10 ad elf_load_file(struct lwp *l, struct exec_package *epp, char *path,
394 1.10 ad struct exec_vmcmd_set *vcset, u_long *entryoff, struct elf_args *ap,
395 1.10 ad Elf_Addr *last)
396 1.1 fvdl {
397 1.1 fvdl int error, i;
398 1.10 ad struct vnode *vp;
399 1.10 ad struct vattr attr;
400 1.10 ad Elf_Ehdr eh;
401 1.10 ad Elf_Phdr *ph = NULL;
402 1.10 ad const Elf_Phdr *ph0;
403 1.10 ad const Elf_Phdr *base_ph;
404 1.10 ad const Elf_Phdr *last_ph;
405 1.1 fvdl u_long phsize;
406 1.10 ad Elf_Addr addr = *last;
407 1.10 ad struct proc *p;
408 1.10 ad
409 1.10 ad p = l->l_proc;
410 1.10 ad
411 1.10 ad /*
412 1.10 ad * 1. open file
413 1.10 ad * 2. read filehdr
414 1.10 ad * 3. map text, data, and bss out of it using VM_*
415 1.10 ad */
416 1.10 ad vp = epp->ep_interp;
417 1.10 ad if (vp == NULL) {
418 1.10 ad error = emul_find_interp(l, epp, path);
419 1.10 ad if (error != 0)
420 1.10 ad return error;
421 1.10 ad vp = epp->ep_interp;
422 1.10 ad }
423 1.10 ad /* We'll tidy this ourselves - otherwise we have locking issues */
424 1.10 ad epp->ep_interp = NULL;
425 1.10 ad vn_lock(vp, LK_EXCLUSIVE | LK_RETRY);
426 1.1 fvdl
427 1.1 fvdl /*
428 1.10 ad * Similarly, if it's not marked as executable, or it's not a regular
429 1.10 ad * file, we don't allow it to be used.
430 1.10 ad */
431 1.10 ad if (vp->v_type != VREG) {
432 1.10 ad error = EACCES;
433 1.10 ad goto badunlock;
434 1.10 ad }
435 1.10 ad if ((error = VOP_ACCESS(vp, VEXEC, l->l_cred)) != 0)
436 1.10 ad goto badunlock;
437 1.10 ad
438 1.10 ad /* get attributes */
439 1.10 ad if ((error = VOP_GETATTR(vp, &attr, l->l_cred)) != 0)
440 1.10 ad goto badunlock;
441 1.10 ad
442 1.10 ad /*
443 1.10 ad * Check mount point. Though we're not trying to exec this binary,
444 1.10 ad * we will be executing code from it, so if the mount point
445 1.10 ad * disallows execution or set-id-ness, we punt or kill the set-id.
446 1.10 ad */
447 1.10 ad if (vp->v_mount->mnt_flag & MNT_NOEXEC) {
448 1.10 ad error = EACCES;
449 1.10 ad goto badunlock;
450 1.1 fvdl }
451 1.10 ad if (vp->v_mount->mnt_flag & MNT_NOSUID)
452 1.10 ad epp->ep_vap->va_mode &= ~(S_ISUID | S_ISGID);
453 1.10 ad
454 1.10 ad #ifdef notyet /* XXX cgd 960926 */
455 1.10 ad XXX cgd 960926: (maybe) VOP_OPEN it (and VOP_CLOSE in copyargs?)
456 1.10 ad #endif
457 1.10 ad
458 1.10 ad error = vn_marktext(vp);
459 1.10 ad if (error)
460 1.10 ad goto badunlock;
461 1.10 ad
462 1.10 ad VOP_UNLOCK(vp, 0);
463 1.10 ad
464 1.10 ad if ((error = exec_read_from(l, vp, 0, &eh, sizeof(eh))) != 0)
465 1.10 ad goto bad;
466 1.10 ad
467 1.10 ad if ((error = elf_check_header(&eh, ET_DYN)) != 0)
468 1.1 fvdl goto bad;
469 1.1 fvdl
470 1.10 ad if (eh.e_phnum > MAXPHNUM || eh.e_phnum == 0) {
471 1.10 ad error = ENOEXEC;
472 1.1 fvdl goto bad;
473 1.10 ad }
474 1.1 fvdl
475 1.10 ad phsize = eh.e_phnum * sizeof(Elf_Phdr);
476 1.10 ad ph = kmem_alloc(phsize, KM_SLEEP);
477 1.1 fvdl
478 1.10 ad if ((error = exec_read_from(l, vp, eh.e_phoff, ph, phsize)) != 0)
479 1.1 fvdl goto bad;
480 1.1 fvdl
481 1.10 ad #ifdef ELF_INTERP_NON_RELOCATABLE
482 1.10 ad /*
483 1.10 ad * Evil hack: Only MIPS should be non-relocatable, and the
484 1.10 ad * psections should have a high address (typically 0x5ffe0000).
485 1.10 ad * If it's now relocatable, it should be linked at 0 and the
486 1.10 ad * psections should have zeros in the upper part of the address.
487 1.10 ad * Otherwise, force the load at the linked address.
488 1.10 ad */
489 1.10 ad if (*last == ELF_LINK_ADDR && (ph->p_vaddr & 0xffff0000) == 0)
490 1.10 ad *last = ELFDEFNNAME(NO_ADDR);
491 1.10 ad #endif
492 1.10 ad
493 1.10 ad /*
494 1.10 ad * If no position to load the interpreter was set by a probe
495 1.10 ad * function, pick the same address that a non-fixed mmap(0, ..)
496 1.10 ad * would (i.e. something safely out of the way).
497 1.10 ad */
498 1.10 ad if (*last == ELFDEFNNAME(NO_ADDR)) {
499 1.10 ad u_long limit = 0;
500 1.10 ad /*
501 1.10 ad * Find the start and ending addresses of the psections to
502 1.10 ad * be loaded. This will give us the size.
503 1.10 ad */
504 1.10 ad for (i = 0, ph0 = ph, base_ph = NULL; i < eh.e_phnum;
505 1.10 ad i++, ph0++) {
506 1.10 ad if (ph0->p_type == PT_LOAD) {
507 1.10 ad u_long psize = ph0->p_vaddr + ph0->p_memsz;
508 1.10 ad if (base_ph == NULL)
509 1.10 ad base_ph = ph0;
510 1.10 ad if (psize > limit)
511 1.10 ad limit = psize;
512 1.10 ad }
513 1.10 ad }
514 1.10 ad
515 1.10 ad if (base_ph == NULL) {
516 1.10 ad error = ENOEXEC;
517 1.10 ad goto bad;
518 1.10 ad }
519 1.10 ad
520 1.10 ad /*
521 1.10 ad * Now compute the size and load address.
522 1.10 ad */
523 1.10 ad addr = (*epp->ep_esch->es_emul->e_vm_default_addr)(p,
524 1.10 ad epp->ep_daddr,
525 1.10 ad round_page(limit) - trunc_page(base_ph->p_vaddr));
526 1.10 ad } else
527 1.10 ad addr = *last; /* may be ELF_LINK_ADDR */
528 1.10 ad
529 1.1 fvdl /*
530 1.10 ad * Load all the necessary sections
531 1.10 ad */
532 1.10 ad for (i = 0, ph0 = ph, base_ph = NULL, last_ph = NULL;
533 1.10 ad i < eh.e_phnum; i++, ph0++) {
534 1.10 ad switch (ph0->p_type) {
535 1.10 ad case PT_LOAD: {
536 1.10 ad u_long size;
537 1.10 ad int prot = 0;
538 1.10 ad int flags;
539 1.10 ad
540 1.10 ad if (base_ph == NULL) {
541 1.10 ad /*
542 1.10 ad * First encountered psection is always the
543 1.10 ad * base psection. Make sure it's aligned
544 1.10 ad * properly (align down for topdown and align
545 1.10 ad * upwards for not topdown).
546 1.10 ad */
547 1.10 ad base_ph = ph0;
548 1.10 ad flags = VMCMD_BASE;
549 1.10 ad if (addr == ELF_LINK_ADDR)
550 1.10 ad addr = ph0->p_vaddr;
551 1.10 ad if (p->p_vmspace->vm_map.flags & VM_MAP_TOPDOWN)
552 1.10 ad addr = ELF_TRUNC(addr, ph0->p_align);
553 1.10 ad else
554 1.10 ad addr = ELF_ROUND(addr, ph0->p_align);
555 1.10 ad } else {
556 1.10 ad u_long limit = round_page(last_ph->p_vaddr
557 1.10 ad + last_ph->p_memsz);
558 1.10 ad u_long base = trunc_page(ph0->p_vaddr);
559 1.10 ad
560 1.10 ad /*
561 1.10 ad * If there is a gap in between the psections,
562 1.10 ad * map it as inaccessible so nothing else
563 1.10 ad * mmap'ed will be placed there.
564 1.10 ad */
565 1.10 ad if (limit != base) {
566 1.10 ad NEW_VMCMD2(vcset, vmcmd_map_zero,
567 1.10 ad base - limit,
568 1.10 ad limit - base_ph->p_vaddr, NULLVP,
569 1.10 ad 0, VM_PROT_NONE, VMCMD_RELATIVE);
570 1.10 ad }
571 1.1 fvdl
572 1.10 ad addr = ph0->p_vaddr - base_ph->p_vaddr;
573 1.10 ad flags = VMCMD_RELATIVE;
574 1.10 ad }
575 1.10 ad last_ph = ph0;
576 1.10 ad elf_load_psection(vcset, vp, &ph[i], &addr,
577 1.10 ad &size, &prot, flags);
578 1.10 ad /*
579 1.10 ad * If entry is within this psection then this
580 1.10 ad * must contain the .text section. *entryoff is
581 1.10 ad * relative to the base psection.
582 1.10 ad */
583 1.10 ad if (eh.e_entry >= ph0->p_vaddr &&
584 1.10 ad eh.e_entry < (ph0->p_vaddr + size)) {
585 1.10 ad *entryoff = eh.e_entry - base_ph->p_vaddr;
586 1.1 fvdl }
587 1.1 fvdl addr += size;
588 1.1 fvdl break;
589 1.10 ad }
590 1.1 fvdl
591 1.10 ad case PT_DYNAMIC:
592 1.10 ad case PT_PHDR:
593 1.10 ad break;
594 1.10 ad
595 1.10 ad case PT_NOTE:
596 1.1 fvdl break;
597 1.1 fvdl
598 1.1 fvdl default:
599 1.1 fvdl break;
600 1.1 fvdl }
601 1.1 fvdl }
602 1.1 fvdl
603 1.10 ad kmem_free(ph, phsize);
604 1.10 ad /*
605 1.10 ad * This value is ignored if TOPDOWN.
606 1.10 ad */
607 1.10 ad *last = addr;
608 1.10 ad vrele(vp);
609 1.10 ad return 0;
610 1.10 ad
611 1.10 ad badunlock:
612 1.10 ad VOP_UNLOCK(vp, 0);
613 1.10 ad
614 1.1 fvdl bad:
615 1.1 fvdl if (ph != NULL)
616 1.10 ad kmem_free(ph, phsize);
617 1.10 ad #ifdef notyet /* XXX cgd 960926 */
618 1.10 ad (maybe) VOP_CLOSE it
619 1.10 ad #endif
620 1.10 ad vrele(vp);
621 1.1 fvdl return error;
622 1.1 fvdl }
623 1.1 fvdl
624 1.1 fvdl /*
625 1.1 fvdl * exec_elf_makecmds(): Prepare an Elf binary's exec package
626 1.1 fvdl *
627 1.1 fvdl * First, set of the various offsets/lengths in the exec package.
628 1.1 fvdl *
629 1.1 fvdl * Then, mark the text image busy (so it can be demand paged) or error
630 1.1 fvdl * out if this is not possible. Finally, set up vmcmds for the
631 1.1 fvdl * text, data, bss, and stack segments.
632 1.1 fvdl */
633 1.1 fvdl int
634 1.10 ad exec_elf_makecmds(struct lwp *l, struct exec_package *epp)
635 1.10 ad {
636 1.10 ad Elf_Ehdr *eh = epp->ep_hdr;
637 1.10 ad Elf_Phdr *ph, *pp;
638 1.10 ad Elf_Addr phdr = 0, pos = 0;
639 1.10 ad int error, i, nload;
640 1.10 ad char *interp = NULL;
641 1.10 ad u_long phsize;
642 1.1 fvdl struct proc *p;
643 1.10 ad bool is_dyn;
644 1.1 fvdl
645 1.10 ad if (epp->ep_hdrvalid < sizeof(Elf_Ehdr))
646 1.1 fvdl return ENOEXEC;
647 1.1 fvdl
648 1.10 ad is_dyn = elf_check_header(eh, ET_DYN) == 0;
649 1.10 ad /*
650 1.10 ad * XXX allow for executing shared objects. It seems silly
651 1.10 ad * but other ELF-based systems allow it as well.
652 1.10 ad */
653 1.10 ad if (elf_check_header(eh, ET_EXEC) != 0 && !is_dyn)
654 1.1 fvdl return ENOEXEC;
655 1.1 fvdl
656 1.10 ad if (eh->e_phnum > MAXPHNUM || eh->e_phnum == 0)
657 1.10 ad return ENOEXEC;
658 1.10 ad
659 1.10 ad error = vn_marktext(epp->ep_vp);
660 1.10 ad if (error)
661 1.10 ad return error;
662 1.10 ad
663 1.1 fvdl /*
664 1.10 ad * Allocate space to hold all the program headers, and read them
665 1.10 ad * from the file
666 1.10 ad */
667 1.10 ad p = l->l_proc;
668 1.10 ad phsize = eh->e_phnum * sizeof(Elf_Phdr);
669 1.10 ad ph = kmem_alloc(phsize, KM_SLEEP);
670 1.1 fvdl
671 1.10 ad if ((error = exec_read_from(l, epp->ep_vp, eh->e_phoff, ph, phsize)) !=
672 1.10 ad 0)
673 1.1 fvdl goto bad;
674 1.1 fvdl
675 1.10 ad epp->ep_taddr = epp->ep_tsize = ELFDEFNNAME(NO_ADDR);
676 1.10 ad epp->ep_daddr = epp->ep_dsize = ELFDEFNNAME(NO_ADDR);
677 1.1 fvdl
678 1.1 fvdl for (i = 0; i < eh->e_phnum; i++) {
679 1.1 fvdl pp = &ph[i];
680 1.10 ad if (pp->p_type == PT_INTERP) {
681 1.10 ad if (pp->p_filesz >= MAXPATHLEN) {
682 1.10 ad error = ENOEXEC;
683 1.1 fvdl goto bad;
684 1.10 ad }
685 1.10 ad interp = PNBUF_GET();
686 1.10 ad interp[0] = '\0';
687 1.10 ad if ((error = exec_read_from(l, epp->ep_vp,
688 1.10 ad pp->p_offset, interp, pp->p_filesz)) != 0)
689 1.1 fvdl goto bad;
690 1.1 fvdl break;
691 1.1 fvdl }
692 1.1 fvdl }
693 1.1 fvdl
694 1.1 fvdl /*
695 1.1 fvdl * On the same architecture, we may be emulating different systems.
696 1.10 ad * See which one will accept this executable.
697 1.1 fvdl *
698 1.1 fvdl * Probe functions would normally see if the interpreter (if any)
699 1.1 fvdl * exists. Emulation packages may possibly replace the interpreter in
700 1.10 ad * interp[] with a changed path (/emul/xxx/<path>).
701 1.1 fvdl */
702 1.10 ad pos = ELFDEFNNAME(NO_ADDR);
703 1.10 ad if (epp->ep_esch->u.elf_probe_func) {
704 1.10 ad vaddr_t startp = (vaddr_t)pos;
705 1.1 fvdl
706 1.10 ad error = (*epp->ep_esch->u.elf_probe_func)(l, epp, eh, interp,
707 1.10 ad &startp);
708 1.1 fvdl if (error)
709 1.1 fvdl goto bad;
710 1.10 ad pos = (Elf_Addr)startp;
711 1.1 fvdl }
712 1.1 fvdl
713 1.10 ad #if defined(PAX_MPROTECT) || defined(PAX_SEGVGUARD) || defined(PAX_ASLR)
714 1.10 ad p->p_pax = epp->ep_pax_flags;
715 1.10 ad #endif /* PAX_MPROTECT || PAX_SEGVGUARD || PAX_ASLR */
716 1.10 ad
717 1.13 drochner if (is_dyn)
718 1.16 christos elf_placedynexec(l, epp, eh, ph);
719 1.10 ad
720 1.1 fvdl /*
721 1.10 ad * Load all the necessary sections
722 1.10 ad */
723 1.4 fvdl for (i = nload = 0; i < eh->e_phnum; i++) {
724 1.10 ad Elf_Addr addr = ELFDEFNNAME(NO_ADDR);
725 1.10 ad u_long size = 0;
726 1.1 fvdl int prot = 0;
727 1.1 fvdl
728 1.1 fvdl pp = &ph[i];
729 1.1 fvdl
730 1.1 fvdl switch (ph[i].p_type) {
731 1.10 ad case PT_LOAD:
732 1.4 fvdl /*
733 1.4 fvdl * XXX
734 1.4 fvdl * Can handle only 2 sections: text and data
735 1.4 fvdl */
736 1.10 ad if (nload++ == 2) {
737 1.10 ad error = ENOEXEC;
738 1.4 fvdl goto bad;
739 1.10 ad }
740 1.1 fvdl elf_load_psection(&epp->ep_vmcmds, epp->ep_vp,
741 1.10 ad &ph[i], &addr, &size, &prot, VMCMD_FIXED);
742 1.10 ad
743 1.4 fvdl /*
744 1.4 fvdl * Decide whether it's text or data by looking
745 1.4 fvdl * at the entry point.
746 1.4 fvdl */
747 1.10 ad if (eh->e_entry >= addr &&
748 1.10 ad eh->e_entry < (addr + size)) {
749 1.4 fvdl epp->ep_taddr = addr;
750 1.4 fvdl epp->ep_tsize = size;
751 1.10 ad if (epp->ep_daddr == ELFDEFNNAME(NO_ADDR)) {
752 1.10 ad epp->ep_daddr = addr;
753 1.10 ad epp->ep_dsize = size;
754 1.10 ad }
755 1.4 fvdl } else {
756 1.4 fvdl epp->ep_daddr = addr;
757 1.4 fvdl epp->ep_dsize = size;
758 1.4 fvdl }
759 1.1 fvdl break;
760 1.1 fvdl
761 1.10 ad case PT_SHLIB:
762 1.10 ad /* SCO has these sections. */
763 1.10 ad case PT_INTERP:
764 1.10 ad /* Already did this one. */
765 1.10 ad case PT_DYNAMIC:
766 1.10 ad break;
767 1.10 ad case PT_NOTE:
768 1.1 fvdl break;
769 1.10 ad case PT_PHDR:
770 1.4 fvdl /* Note address of program headers (in text segment) */
771 1.4 fvdl phdr = pp->p_vaddr;
772 1.7 christos break;
773 1.4 fvdl
774 1.1 fvdl default:
775 1.1 fvdl /*
776 1.10 ad * Not fatal; we don't need to understand everything.
777 1.1 fvdl */
778 1.1 fvdl break;
779 1.1 fvdl }
780 1.1 fvdl }
781 1.5 fvdl
782 1.5 fvdl /*
783 1.10 ad * Check if we found a dynamically linked binary and arrange to load
784 1.10 ad * its interpreter
785 1.5 fvdl */
786 1.10 ad if (interp) {
787 1.1 fvdl struct elf_args *ap;
788 1.10 ad int j = epp->ep_vmcmds.evs_used;
789 1.10 ad u_long interp_offset;
790 1.1 fvdl
791 1.11 cegger ap = (struct elf_args *)malloc(sizeof(struct elf_args),
792 1.10 ad M_TEMP, M_WAITOK);
793 1.10 ad if ((error = elf_load_file(l, epp, interp,
794 1.10 ad &epp->ep_vmcmds, &interp_offset, ap, &pos)) != 0) {
795 1.11 cegger free(ap, M_TEMP);
796 1.1 fvdl goto bad;
797 1.1 fvdl }
798 1.10 ad ap->arg_interp = epp->ep_vmcmds.evs_cmds[j].ev_addr;
799 1.10 ad epp->ep_entry = ap->arg_interp + interp_offset;
800 1.4 fvdl ap->arg_phaddr = phdr;
801 1.1 fvdl
802 1.1 fvdl ap->arg_phentsize = eh->e_phentsize;
803 1.1 fvdl ap->arg_phnum = eh->e_phnum;
804 1.1 fvdl ap->arg_entry = eh->e_entry;
805 1.1 fvdl
806 1.1 fvdl epp->ep_emul_arg = ap;
807 1.10 ad
808 1.10 ad PNBUF_PUT(interp);
809 1.1 fvdl } else
810 1.1 fvdl epp->ep_entry = eh->e_entry;
811 1.1 fvdl
812 1.8 christos #ifdef ELF_MAP_PAGE_ZERO
813 1.8 christos /* Dell SVR4 maps page zero, yeuch! */
814 1.10 ad NEW_VMCMD(&epp->ep_vmcmds, vmcmd_map_readvn, PAGE_SIZE, 0,
815 1.10 ad epp->ep_vp, 0, VM_PROT_READ);
816 1.8 christos #endif
817 1.10 ad kmem_free(ph, phsize);
818 1.10 ad return (*epp->ep_esch->es_setup_stack)(l, epp);
819 1.1 fvdl
820 1.1 fvdl bad:
821 1.10 ad if (interp)
822 1.10 ad PNBUF_PUT(interp);
823 1.10 ad kmem_free(ph, phsize);
824 1.1 fvdl kill_vmcmds(&epp->ep_vmcmds);
825 1.10 ad return error;
826 1.10 ad }
827 1.10 ad
828 1.10 ad int
829 1.10 ad netbsd_elf_signature(struct lwp *l, struct exec_package *epp,
830 1.10 ad Elf_Ehdr *eh)
831 1.10 ad {
832 1.10 ad size_t i;
833 1.15 christos Elf_Shdr *sh;
834 1.15 christos Elf_Nhdr *np;
835 1.15 christos size_t shsize;
836 1.10 ad int error;
837 1.10 ad int isnetbsd = 0;
838 1.10 ad char *ndata;
839 1.10 ad
840 1.10 ad epp->ep_pax_flags = 0;
841 1.15 christos if (eh->e_shnum > MAXSHNUM || eh->e_shnum == 0)
842 1.10 ad return ENOEXEC;
843 1.10 ad
844 1.15 christos shsize = eh->e_shnum * sizeof(Elf_Shdr);
845 1.15 christos sh = kmem_alloc(shsize, KM_SLEEP);
846 1.15 christos error = exec_read_from(l, epp->ep_vp, eh->e_shoff, sh, shsize);
847 1.10 ad if (error)
848 1.10 ad goto out;
849 1.10 ad
850 1.15 christos np = kmem_alloc(MAXNOTESIZE, KM_SLEEP);
851 1.15 christos for (i = 0; i < eh->e_shnum; i++) {
852 1.15 christos Elf_Shdr *shp = &sh[i];
853 1.15 christos
854 1.15 christos if (shp->sh_type != SHT_NOTE ||
855 1.15 christos shp->sh_size > MAXNOTESIZE ||
856 1.15 christos shp->sh_size < sizeof(Elf_Nhdr) + ELF_NOTE_NETBSD_NAMESZ)
857 1.10 ad continue;
858 1.10 ad
859 1.15 christos error = exec_read_from(l, epp->ep_vp, shp->sh_offset, np,
860 1.15 christos shp->sh_size);
861 1.10 ad if (error)
862 1.15 christos continue;
863 1.10 ad
864 1.10 ad ndata = (char *)(np + 1);
865 1.10 ad switch (np->n_type) {
866 1.10 ad case ELF_NOTE_TYPE_NETBSD_TAG:
867 1.10 ad if (np->n_namesz != ELF_NOTE_NETBSD_NAMESZ ||
868 1.10 ad np->n_descsz != ELF_NOTE_NETBSD_DESCSZ ||
869 1.10 ad memcmp(ndata, ELF_NOTE_NETBSD_NAME,
870 1.10 ad ELF_NOTE_NETBSD_NAMESZ))
871 1.15 christos goto bad;
872 1.10 ad isnetbsd = 1;
873 1.10 ad break;
874 1.10 ad
875 1.10 ad case ELF_NOTE_TYPE_PAX_TAG:
876 1.10 ad if (np->n_namesz != ELF_NOTE_PAX_NAMESZ ||
877 1.10 ad np->n_descsz != ELF_NOTE_PAX_DESCSZ ||
878 1.10 ad memcmp(ndata, ELF_NOTE_PAX_NAME,
879 1.15 christos ELF_NOTE_PAX_NAMESZ)) {
880 1.15 christos bad:
881 1.15 christos #ifdef DIAGNOSTIC
882 1.15 christos printf("%s: bad tag %d: "
883 1.15 christos "[%d %d, %d %d, %*.*s %*.*s]\n",
884 1.15 christos epp->ep_name,
885 1.18 christos np->n_type,
886 1.15 christos np->n_namesz, ELF_NOTE_PAX_NAMESZ,
887 1.15 christos np->n_descsz, ELF_NOTE_PAX_DESCSZ,
888 1.15 christos ELF_NOTE_PAX_NAMESZ,
889 1.15 christos ELF_NOTE_PAX_NAMESZ,
890 1.15 christos ndata,
891 1.15 christos ELF_NOTE_PAX_NAMESZ,
892 1.15 christos ELF_NOTE_PAX_NAMESZ,
893 1.15 christos ELF_NOTE_PAX_NAME);
894 1.15 christos #endif
895 1.15 christos continue;
896 1.15 christos }
897 1.10 ad (void)memcpy(&epp->ep_pax_flags,
898 1.10 ad ndata + ELF_NOTE_PAX_NAMESZ,
899 1.10 ad sizeof(epp->ep_pax_flags));
900 1.10 ad break;
901 1.10 ad
902 1.10 ad default:
903 1.15 christos #ifdef DIAGNOSTIC
904 1.15 christos printf("%s: unknown note type %d\n", epp->ep_name,
905 1.15 christos np->n_type);
906 1.15 christos #endif
907 1.10 ad break;
908 1.10 ad }
909 1.10 ad }
910 1.15 christos kmem_free(np, MAXNOTESIZE);
911 1.10 ad
912 1.10 ad error = isnetbsd ? 0 : ENOEXEC;
913 1.10 ad out:
914 1.15 christos kmem_free(sh, shsize);
915 1.10 ad return error;
916 1.10 ad }
917 1.10 ad
918 1.10 ad int
919 1.10 ad netbsd_elf_probe(struct lwp *l, struct exec_package *epp, void *eh, char *itp,
920 1.10 ad vaddr_t *pos)
921 1.10 ad {
922 1.10 ad int error;
923 1.10 ad
924 1.10 ad if ((error = netbsd_elf_signature(l, epp, eh)) != 0)
925 1.10 ad return error;
926 1.12 matt #ifdef ELF_MD_PROBE_FUNC
927 1.12 matt if ((error = ELF_MD_PROBE_FUNC(l, epp, eh, itp, pos)) != 0)
928 1.12 matt return error;
929 1.12 matt #elif defined(ELF_INTERP_NON_RELOCATABLE)
930 1.10 ad *pos = ELF_LINK_ADDR;
931 1.10 ad #endif
932 1.10 ad return 0;
933 1.1 fvdl }
934