exec_elf32.c revision 1.60
11.60Smycroft/* $NetBSD: exec_elf32.c,v 1.60 2000/12/11 05:29:02 mycroft Exp $ */ 21.36Schristos 31.36Schristos/*- 41.60Smycroft * Copyright (c) 1994, 2000 The NetBSD Foundation, Inc. 51.36Schristos * All rights reserved. 61.36Schristos * 71.36Schristos * This code is derived from software contributed to The NetBSD Foundation 81.36Schristos * by Christos Zoulas. 91.36Schristos * 101.36Schristos * Redistribution and use in source and binary forms, with or without 111.36Schristos * modification, are permitted provided that the following conditions 121.36Schristos * are met: 131.36Schristos * 1. Redistributions of source code must retain the above copyright 141.36Schristos * notice, this list of conditions and the following disclaimer. 151.36Schristos * 2. Redistributions in binary form must reproduce the above copyright 161.36Schristos * notice, this list of conditions and the following disclaimer in the 171.36Schristos * documentation and/or other materials provided with the distribution. 181.36Schristos * 3. All advertising materials mentioning features or use of this software 191.36Schristos * must display the following acknowledgement: 201.37Schristos * This product includes software developed by the NetBSD 211.37Schristos * Foundation, Inc. and its contributors. 221.36Schristos * 4. Neither the name of The NetBSD Foundation nor the names of its 231.36Schristos * contributors may be used to endorse or promote products derived 241.36Schristos * from this software without specific prior written permission. 251.36Schristos * 261.36Schristos * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS 271.36Schristos * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED 281.36Schristos * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 291.36Schristos * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS 301.36Schristos * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 311.36Schristos * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 321.36Schristos * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 331.36Schristos * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 341.36Schristos * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 351.36Schristos * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 361.36Schristos * POSSIBILITY OF SUCH DAMAGE. 371.36Schristos */ 381.1Sfvdl 391.1Sfvdl/* 401.9Scgd * Copyright (c) 1996 Christopher G. Demetriou 411.1Sfvdl * All rights reserved. 421.1Sfvdl * 431.1Sfvdl * Redistribution and use in source and binary forms, with or without 441.1Sfvdl * modification, are permitted provided that the following conditions 451.1Sfvdl * are met: 461.1Sfvdl * 1. Redistributions of source code must retain the above copyright 471.1Sfvdl * notice, this list of conditions and the following disclaimer. 481.1Sfvdl * 2. Redistributions in binary form must reproduce the above copyright 491.1Sfvdl * notice, this list of conditions and the following disclaimer in the 501.1Sfvdl * documentation and/or other materials provided with the distribution. 511.1Sfvdl * 3. The name of the author may not be used to endorse or promote products 521.1Sfvdl * derived from this software without specific prior written permission 531.1Sfvdl * 541.1Sfvdl * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 551.1Sfvdl * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 561.1Sfvdl * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 571.1Sfvdl * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 581.1Sfvdl * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 591.1Sfvdl * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 601.1Sfvdl * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 611.1Sfvdl * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 621.1Sfvdl * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 631.1Sfvdl * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 641.1Sfvdl */ 651.1Sfvdl 661.9Scgd/* If not included by exec_elf64.c, ELFSIZE won't be defined. */ 671.9Scgd#ifndef ELFSIZE 681.9Scgd#define ELFSIZE 32 691.9Scgd#endif 701.30Sthorpej 711.1Sfvdl#include <sys/param.h> 721.1Sfvdl#include <sys/proc.h> 731.1Sfvdl#include <sys/malloc.h> 741.1Sfvdl#include <sys/namei.h> 751.1Sfvdl#include <sys/vnode.h> 761.1Sfvdl#include <sys/exec.h> 771.1Sfvdl#include <sys/exec_elf.h> 781.8Schristos#include <sys/syscall.h> 791.8Schristos#include <sys/signalvar.h> 801.14Scgd#include <sys/mount.h> 811.14Scgd#include <sys/stat.h> 821.1Sfvdl 831.58Sjdolecek#include <machine/cpu.h> 841.58Sjdolecek#include <machine/reg.h> 851.57Sthorpej 861.58Sjdolecekextern const struct emul emul_netbsd; 871.42Schristos 881.54Sthorpejint ELFNAME(check_header)(Elf_Ehdr *, int); 891.54Sthorpejint ELFNAME(load_file)(struct proc *, struct exec_package *, char *, 901.54Sthorpej struct exec_vmcmd_set *, u_long *, struct elf_args *, Elf_Addr *); 911.54Sthorpejvoid ELFNAME(load_psection)(struct exec_vmcmd_set *, struct vnode *, 921.54Sthorpej const Elf_Phdr *, Elf_Addr *, u_long *, int *, int); 931.54Sthorpej 941.59Smrgint ELFNAME2(netbsd,signature)(struct proc *, struct exec_package *, 951.54Sthorpej Elf_Ehdr *); 961.58Sjdolecekint ELFNAME2(netbsd,probe)(struct proc *, struct exec_package *, 971.58Sjdolecek void *, char *, vaddr_t *); 981.8Schristos 991.18Scgd/* round up and down to page boundaries. */ 1001.18Scgd#define ELF_ROUND(a, b) (((a) + (b) - 1) & ~((b) - 1)) 1011.18Scgd#define ELF_TRUNC(a, b) ((a) & ~((b) - 1)) 1021.8Schristos 1031.8Schristos/* 1041.1Sfvdl * Copy arguments onto the stack in the normal way, but add some 1051.1Sfvdl * extra information in case of dynamic binding. 1061.1Sfvdl */ 1071.1Sfvdlvoid * 1081.54SthorpejELFNAME(copyargs)(struct exec_package *pack, struct ps_strings *arginfo, 1091.54Sthorpej void *stack, void *argp) 1101.1Sfvdl{ 1111.1Sfvdl size_t len; 1121.4Sfvdl AuxInfo ai[ELF_AUX_ENTRIES], *a; 1131.1Sfvdl struct elf_args *ap; 1141.1Sfvdl 1151.4Sfvdl stack = copyargs(pack, arginfo, stack, argp); 1161.4Sfvdl if (!stack) 1171.1Sfvdl return NULL; 1181.1Sfvdl 1191.22Scgd a = ai; 1201.22Scgd 1211.1Sfvdl /* 1221.1Sfvdl * Push extra arguments on the stack needed by dynamically 1231.1Sfvdl * linked binaries 1241.1Sfvdl */ 1251.17Scgd if ((ap = (struct elf_args *)pack->ep_emul_arg)) { 1261.1Sfvdl 1271.46Skleink a->a_type = AT_PHDR; 1281.46Skleink a->a_v = ap->arg_phaddr; 1291.1Sfvdl a++; 1301.1Sfvdl 1311.46Skleink a->a_type = AT_PHENT; 1321.46Skleink a->a_v = ap->arg_phentsize; 1331.1Sfvdl a++; 1341.1Sfvdl 1351.46Skleink a->a_type = AT_PHNUM; 1361.46Skleink a->a_v = ap->arg_phnum; 1371.1Sfvdl a++; 1381.1Sfvdl 1391.46Skleink a->a_type = AT_PAGESZ; 1401.57Sthorpej a->a_v = PAGE_SIZE; 1411.1Sfvdl a++; 1421.1Sfvdl 1431.46Skleink a->a_type = AT_BASE; 1441.46Skleink a->a_v = ap->arg_interp; 1451.1Sfvdl a++; 1461.1Sfvdl 1471.46Skleink a->a_type = AT_FLAGS; 1481.46Skleink a->a_v = 0; 1491.1Sfvdl a++; 1501.1Sfvdl 1511.46Skleink a->a_type = AT_ENTRY; 1521.46Skleink a->a_v = ap->arg_entry; 1531.1Sfvdl a++; 1541.1Sfvdl 1551.17Scgd free((char *)ap, M_TEMP); 1561.9Scgd pack->ep_emul_arg = NULL; 1571.1Sfvdl } 1581.22Scgd 1591.46Skleink a->a_type = AT_NULL; 1601.46Skleink a->a_v = 0; 1611.22Scgd a++; 1621.22Scgd 1631.34Sperry len = (a - ai) * sizeof(AuxInfo); 1641.22Scgd if (copyout(ai, stack, len)) 1651.22Scgd return NULL; 1661.43Skleink stack = (caddr_t)stack + len; 1671.22Scgd 1681.4Sfvdl return stack; 1691.1Sfvdl} 1701.1Sfvdl 1711.1Sfvdl/* 1721.1Sfvdl * elf_check_header(): 1731.1Sfvdl * 1741.1Sfvdl * Check header for validity; return 0 of ok ENOEXEC if error 1751.1Sfvdl */ 1761.17Scgdint 1771.54SthorpejELFNAME(check_header)(Elf_Ehdr *eh, int type) 1781.1Sfvdl{ 1791.3Sthorpej 1801.46Skleink if (memcmp(eh->e_ident, ELFMAG, SELFMAG) != 0 || 1811.46Skleink eh->e_ident[EI_CLASS] != ELFCLASS) 1821.52Skleink return ENOEXEC; 1831.1Sfvdl 1841.1Sfvdl switch (eh->e_machine) { 1851.9Scgd 1861.10Scgd ELFDEFNNAME(MACHDEP_ID_CASES) 1871.1Sfvdl 1881.1Sfvdl default: 1891.1Sfvdl return ENOEXEC; 1901.1Sfvdl } 1911.1Sfvdl 1921.1Sfvdl if (eh->e_type != type) 1931.1Sfvdl return ENOEXEC; 1941.1Sfvdl 1951.1Sfvdl return 0; 1961.1Sfvdl} 1971.1Sfvdl 1981.1Sfvdl/* 1991.1Sfvdl * elf_load_psection(): 2001.17Scgd * 2011.1Sfvdl * Load a psection at the appropriate address 2021.1Sfvdl */ 2031.17Scgdvoid 2041.54SthorpejELFNAME(load_psection)(struct exec_vmcmd_set *vcset, struct vnode *vp, 2051.54Sthorpej const Elf_Phdr *ph, Elf_Addr *addr, u_long *size, int *prot, int flags) 2061.1Sfvdl{ 2071.8Schristos u_long uaddr, msize, psize, rm, rf; 2081.1Sfvdl long diff, offset; 2091.1Sfvdl 2101.1Sfvdl /* 2111.17Scgd * If the user specified an address, then we load there. 2121.17Scgd */ 2131.9Scgd if (*addr != ELFDEFNNAME(NO_ADDR)) { 2141.1Sfvdl if (ph->p_align > 1) { 2151.53Smatt *addr = ELF_TRUNC(*addr, ph->p_align); 2161.18Scgd uaddr = ELF_TRUNC(ph->p_vaddr, ph->p_align); 2171.1Sfvdl } else 2181.1Sfvdl uaddr = ph->p_vaddr; 2191.1Sfvdl diff = ph->p_vaddr - uaddr; 2201.1Sfvdl } else { 2211.1Sfvdl *addr = uaddr = ph->p_vaddr; 2221.1Sfvdl if (ph->p_align > 1) 2231.18Scgd *addr = ELF_TRUNC(uaddr, ph->p_align); 2241.1Sfvdl diff = uaddr - *addr; 2251.1Sfvdl } 2261.1Sfvdl 2271.46Skleink *prot |= (ph->p_flags & PF_R) ? VM_PROT_READ : 0; 2281.46Skleink *prot |= (ph->p_flags & PF_W) ? VM_PROT_WRITE : 0; 2291.46Skleink *prot |= (ph->p_flags & PF_X) ? VM_PROT_EXECUTE : 0; 2301.1Sfvdl 2311.1Sfvdl offset = ph->p_offset - diff; 2321.1Sfvdl *size = ph->p_filesz + diff; 2331.1Sfvdl msize = ph->p_memsz + diff; 2341.8Schristos psize = round_page(*size); 2351.1Sfvdl 2361.46Skleink if ((ph->p_flags & PF_W) != 0) { 2371.8Schristos /* 2381.8Schristos * Because the pagedvn pager can't handle zero fill of the last 2391.8Schristos * data page if it's not page aligned we map the last page 2401.8Schristos * readvn. 2411.8Schristos */ 2421.8Schristos psize = trunc_page(*size); 2431.53Smatt } 2441.53Smatt if (psize > 0) { 2451.53Smatt NEW_VMCMD2(vcset, vmcmd_map_pagedvn, psize, *addr, vp, 2461.53Smatt offset, *prot, flags); 2471.53Smatt } 2481.53Smatt if (psize < *size) { 2491.53Smatt NEW_VMCMD2(vcset, vmcmd_map_readvn, *size - psize, 2501.53Smatt *addr + psize, vp, offset + psize, *prot, 2511.53Smatt psize > 0 ? flags & VMCMD_RELATIVE : flags); 2521.53Smatt } 2531.1Sfvdl 2541.1Sfvdl /* 2551.17Scgd * Check if we need to extend the size of the segment 2561.17Scgd */ 2571.1Sfvdl rm = round_page(*addr + msize); 2581.1Sfvdl rf = round_page(*addr + *size); 2591.1Sfvdl 2601.1Sfvdl if (rm != rf) { 2611.53Smatt NEW_VMCMD2(vcset, vmcmd_map_zero, rm - rf, rf, NULLVP, 2621.53Smatt 0, *prot, flags & VMCMD_RELATIVE); 2631.1Sfvdl *size = msize; 2641.1Sfvdl } 2651.1Sfvdl} 2661.1Sfvdl 2671.1Sfvdl/* 2681.1Sfvdl * elf_read_from(): 2691.1Sfvdl * 2701.1Sfvdl * Read from vnode into buffer at offset. 2711.1Sfvdl */ 2721.7Schristosint 2731.54SthorpejELFNAME(read_from)(struct proc *p, struct vnode *vp, u_long off, 2741.54Sthorpej caddr_t buf, int size) 2751.1Sfvdl{ 2761.1Sfvdl int error; 2771.33Sthorpej size_t resid; 2781.1Sfvdl 2791.17Scgd if ((error = vn_rdwr(UIO_READ, vp, buf, size, off, UIO_SYSSPACE, 2801.17Scgd 0, p->p_ucred, &resid, p)) != 0) 2811.1Sfvdl return error; 2821.1Sfvdl /* 2831.17Scgd * See if we got all of it 2841.17Scgd */ 2851.1Sfvdl if (resid != 0) 2861.4Sfvdl return ENOEXEC; 2871.1Sfvdl return 0; 2881.1Sfvdl} 2891.1Sfvdl 2901.1Sfvdl/* 2911.1Sfvdl * elf_load_file(): 2921.1Sfvdl * 2931.1Sfvdl * Load a file (interpreter/library) pointed to by path 2941.1Sfvdl * [stolen from coff_load_shlib()]. Made slightly generic 2951.1Sfvdl * so it might be used externally. 2961.1Sfvdl */ 2971.17Scgdint 2981.54SthorpejELFNAME(load_file)(struct proc *p, struct exec_package *epp, char *path, 2991.54Sthorpej struct exec_vmcmd_set *vcset, u_long *entry, struct elf_args *ap, 3001.54Sthorpej Elf_Addr *last) 3011.1Sfvdl{ 3021.1Sfvdl int error, i; 3031.1Sfvdl struct nameidata nd; 3041.14Scgd struct vnode *vp; 3051.14Scgd struct vattr attr; 3061.9Scgd Elf_Ehdr eh; 3071.9Scgd Elf_Phdr *ph = NULL; 3081.53Smatt Elf_Phdr *base_ph = NULL; 3091.1Sfvdl u_long phsize; 3101.1Sfvdl char *bp = NULL; 3111.9Scgd Elf_Addr addr = *last; 3121.1Sfvdl 3131.1Sfvdl bp = path; 3141.1Sfvdl /* 3151.17Scgd * 1. open file 3161.17Scgd * 2. read filehdr 3171.17Scgd * 3. map text, data, and bss out of it using VM_* 3181.17Scgd */ 3191.12Scgd NDINIT(&nd, LOOKUP, FOLLOW | LOCKLEAF, UIO_SYSSPACE, path, p); 3201.12Scgd if ((error = namei(&nd)) != 0) 3211.1Sfvdl return error; 3221.14Scgd vp = nd.ni_vp; 3231.14Scgd 3241.26Smycroft /* 3251.26Smycroft * Similarly, if it's not marked as executable, or it's not a regular 3261.26Smycroft * file, we don't allow it to be used. 3271.26Smycroft */ 3281.14Scgd if (vp->v_type != VREG) { 3291.14Scgd error = EACCES; 3301.14Scgd goto badunlock; 3311.14Scgd } 3321.26Smycroft if ((error = VOP_ACCESS(vp, VEXEC, p->p_ucred, p)) != 0) 3331.26Smycroft goto badunlock; 3341.14Scgd 3351.17Scgd /* get attributes */ 3361.14Scgd if ((error = VOP_GETATTR(vp, &attr, p->p_ucred, p)) != 0) 3371.14Scgd goto badunlock; 3381.14Scgd 3391.14Scgd /* 3401.14Scgd * Check mount point. Though we're not trying to exec this binary, 3411.15Scgd * we will be executing code from it, so if the mount point 3421.15Scgd * disallows execution or set-id-ness, we punt or kill the set-id. 3431.14Scgd */ 3441.14Scgd if (vp->v_mount->mnt_flag & MNT_NOEXEC) { 3451.14Scgd error = EACCES; 3461.14Scgd goto badunlock; 3471.14Scgd } 3481.14Scgd if (vp->v_mount->mnt_flag & MNT_NOSUID) 3491.24Smycroft epp->ep_vap->va_mode &= ~(S_ISUID | S_ISGID); 3501.14Scgd 3511.12Scgd#ifdef notyet /* XXX cgd 960926 */ 3521.12Scgd XXX cgd 960926: (maybe) VOP_OPEN it (and VOP_CLOSE in copyargs?) 3531.12Scgd#endif 3541.28Sfvdl VOP_UNLOCK(vp, 0); 3551.12Scgd 3561.14Scgd if ((error = ELFNAME(read_from)(p, vp, 0, (caddr_t) &eh, 3571.17Scgd sizeof(eh))) != 0) 3581.1Sfvdl goto bad; 3591.1Sfvdl 3601.46Skleink if ((error = ELFNAME(check_header)(&eh, ET_DYN)) != 0) 3611.1Sfvdl goto bad; 3621.1Sfvdl 3631.9Scgd phsize = eh.e_phnum * sizeof(Elf_Phdr); 3641.17Scgd ph = (Elf_Phdr *)malloc(phsize, M_TEMP, M_WAITOK); 3651.1Sfvdl 3661.14Scgd if ((error = ELFNAME(read_from)(p, vp, eh.e_phoff, 3671.9Scgd (caddr_t) ph, phsize)) != 0) 3681.1Sfvdl goto bad; 3691.1Sfvdl 3701.1Sfvdl /* 3711.17Scgd * Load all the necessary sections 3721.17Scgd */ 3731.1Sfvdl for (i = 0; i < eh.e_phnum; i++) { 3741.1Sfvdl u_long size = 0; 3751.1Sfvdl int prot = 0; 3761.53Smatt int flags; 3771.1Sfvdl 3781.1Sfvdl switch (ph[i].p_type) { 3791.46Skleink case PT_LOAD: 3801.53Smatt if (base_ph == NULL) { 3811.53Smatt addr = *last; 3821.53Smatt flags = VMCMD_BASE; 3831.53Smatt } else { 3841.53Smatt addr = ph[i].p_vaddr - base_ph->p_vaddr; 3851.53Smatt flags = VMCMD_RELATIVE; 3861.53Smatt } 3871.14Scgd ELFNAME(load_psection)(vcset, vp, &ph[i], &addr, 3881.53Smatt &size, &prot, flags); 3891.4Sfvdl /* If entry is within this section it must be text */ 3901.4Sfvdl if (eh.e_entry >= ph[i].p_vaddr && 3911.4Sfvdl eh.e_entry < (ph[i].p_vaddr + size)) { 3921.21Sfvdl /* XXX */ 3931.21Sfvdl *entry = addr + eh.e_entry; 3941.21Sfvdl#ifdef mips 3951.21Sfvdl *entry -= ph[i].p_vaddr; 3961.21Sfvdl#endif 3971.1Sfvdl ap->arg_interp = addr; 3981.1Sfvdl } 3991.53Smatt if (base_ph == NULL) 4001.53Smatt base_ph = &ph[i]; 4011.1Sfvdl addr += size; 4021.1Sfvdl break; 4031.1Sfvdl 4041.46Skleink case PT_DYNAMIC: 4051.46Skleink case PT_PHDR: 4061.46Skleink case PT_NOTE: 4071.1Sfvdl break; 4081.1Sfvdl 4091.1Sfvdl default: 4101.1Sfvdl break; 4111.1Sfvdl } 4121.1Sfvdl } 4131.1Sfvdl 4141.17Scgd free((char *)ph, M_TEMP); 4151.12Scgd *last = addr; 4161.14Scgd vrele(vp); 4171.12Scgd return 0; 4181.12Scgd 4191.14Scgdbadunlock: 4201.28Sfvdl VOP_UNLOCK(vp, 0); 4211.14Scgd 4221.1Sfvdlbad: 4231.1Sfvdl if (ph != NULL) 4241.17Scgd free((char *)ph, M_TEMP); 4251.12Scgd#ifdef notyet /* XXX cgd 960926 */ 4261.12Scgd (maybe) VOP_CLOSE it 4271.12Scgd#endif 4281.14Scgd vrele(vp); 4291.1Sfvdl return error; 4301.1Sfvdl} 4311.1Sfvdl 4321.1Sfvdl/* 4331.1Sfvdl * exec_elf_makecmds(): Prepare an Elf binary's exec package 4341.1Sfvdl * 4351.1Sfvdl * First, set of the various offsets/lengths in the exec package. 4361.1Sfvdl * 4371.1Sfvdl * Then, mark the text image busy (so it can be demand paged) or error 4381.1Sfvdl * out if this is not possible. Finally, set up vmcmds for the 4391.1Sfvdl * text, data, bss, and stack segments. 4401.1Sfvdl */ 4411.1Sfvdlint 4421.54SthorpejELFNAME2(exec,makecmds)(struct proc *p, struct exec_package *epp) 4431.1Sfvdl{ 4441.9Scgd Elf_Ehdr *eh = epp->ep_hdr; 4451.9Scgd Elf_Phdr *ph, *pp; 4461.9Scgd Elf_Addr phdr = 0, pos = 0; 4471.58Sjdolecek int error, i, nload; 4481.58Sjdolecek char *interp = NULL; 4491.9Scgd u_long phsize; 4501.1Sfvdl 4511.9Scgd if (epp->ep_hdrvalid < sizeof(Elf_Ehdr)) 4521.1Sfvdl return ENOEXEC; 4531.1Sfvdl 4541.45Sfvdl /* 4551.45Sfvdl * XXX allow for executing shared objects. It seems silly 4561.45Sfvdl * but other ELF-based systems allow it as well. 4571.45Sfvdl */ 4581.46Skleink if (ELFNAME(check_header)(eh, ET_EXEC) != 0 && 4591.46Skleink ELFNAME(check_header)(eh, ET_DYN) != 0) 4601.1Sfvdl return ENOEXEC; 4611.1Sfvdl 4621.1Sfvdl /* 4631.17Scgd * check if vnode is in open for writing, because we want to 4641.17Scgd * demand-page out of it. if it is, don't do it, for various 4651.17Scgd * reasons 4661.17Scgd */ 4671.1Sfvdl if (epp->ep_vp->v_writecount != 0) { 4681.1Sfvdl#ifdef DIAGNOSTIC 4691.1Sfvdl if (epp->ep_vp->v_flag & VTEXT) 4701.1Sfvdl panic("exec: a VTEXT vnode has writecount != 0\n"); 4711.1Sfvdl#endif 4721.1Sfvdl return ETXTBSY; 4731.1Sfvdl } 4741.1Sfvdl /* 4751.17Scgd * Allocate space to hold all the program headers, and read them 4761.17Scgd * from the file 4771.17Scgd */ 4781.9Scgd phsize = eh->e_phnum * sizeof(Elf_Phdr); 4791.17Scgd ph = (Elf_Phdr *)malloc(phsize, M_TEMP, M_WAITOK); 4801.1Sfvdl 4811.9Scgd if ((error = ELFNAME(read_from)(p, epp->ep_vp, eh->e_phoff, 4821.8Schristos (caddr_t) ph, phsize)) != 0) 4831.1Sfvdl goto bad; 4841.1Sfvdl 4851.19Scgd epp->ep_taddr = epp->ep_tsize = ELFDEFNNAME(NO_ADDR); 4861.19Scgd epp->ep_daddr = epp->ep_dsize = ELFDEFNNAME(NO_ADDR); 4871.1Sfvdl 4881.58Sjdolecek MALLOC(interp, char *, MAXPATHLEN, M_TEMP, M_WAITOK); 4891.1Sfvdl interp[0] = '\0'; 4901.1Sfvdl 4911.1Sfvdl for (i = 0; i < eh->e_phnum; i++) { 4921.1Sfvdl pp = &ph[i]; 4931.46Skleink if (pp->p_type == PT_INTERP) { 4941.58Sjdolecek if (pp->p_filesz >= MAXPATHLEN) 4951.1Sfvdl goto bad; 4961.17Scgd if ((error = ELFNAME(read_from)(p, epp->ep_vp, 4971.17Scgd pp->p_offset, (caddr_t) interp, 4981.17Scgd pp->p_filesz)) != 0) 4991.1Sfvdl goto bad; 5001.1Sfvdl break; 5011.1Sfvdl } 5021.1Sfvdl } 5031.1Sfvdl 5041.9Scgd /* 5051.1Sfvdl * On the same architecture, we may be emulating different systems. 5061.1Sfvdl * See which one will accept this executable. This currently only 5071.38Serh * applies to SVR4, and IBCS2 on the i386 and Linux on the i386 5081.38Serh * and the Alpha. 5091.1Sfvdl * 5101.1Sfvdl * Probe functions would normally see if the interpreter (if any) 5111.1Sfvdl * exists. Emulation packages may possibly replace the interpreter in 5121.58Sjdolecek * interp[] with a changed path (/emul/xxx/<path>). 5131.1Sfvdl */ 5141.58Sjdolecek if (!epp->ep_esch->u.elf_probe_func) { 5151.58Sjdolecek pos = ELFDEFNNAME(NO_ADDR); 5161.58Sjdolecek } else { 5171.58Sjdolecek error = (*epp->ep_esch->u.elf_probe_func)(p, epp, eh, interp, 5181.58Sjdolecek (vaddr_t *)&pos); 5191.1Sfvdl if (error) 5201.1Sfvdl goto bad; 5211.1Sfvdl } 5221.1Sfvdl 5231.1Sfvdl /* 5241.17Scgd * Load all the necessary sections 5251.17Scgd */ 5261.4Sfvdl for (i = nload = 0; i < eh->e_phnum; i++) { 5271.9Scgd Elf_Addr addr = ELFDEFNNAME(NO_ADDR); 5281.9Scgd u_long size = 0; 5291.1Sfvdl int prot = 0; 5301.1Sfvdl 5311.1Sfvdl pp = &ph[i]; 5321.1Sfvdl 5331.1Sfvdl switch (ph[i].p_type) { 5341.46Skleink case PT_LOAD: 5351.4Sfvdl /* 5361.4Sfvdl * XXX 5371.4Sfvdl * Can handle only 2 sections: text and data 5381.4Sfvdl */ 5391.4Sfvdl if (nload++ == 2) 5401.4Sfvdl goto bad; 5411.9Scgd ELFNAME(load_psection)(&epp->ep_vmcmds, epp->ep_vp, 5421.53Smatt &ph[i], &addr, &size, &prot, 0); 5431.17Scgd 5441.4Sfvdl /* 5451.4Sfvdl * Decide whether it's text or data by looking 5461.4Sfvdl * at the entry point. 5471.4Sfvdl */ 5481.19Scgd if (eh->e_entry >= addr && 5491.19Scgd eh->e_entry < (addr + size)) { 5501.4Sfvdl epp->ep_taddr = addr; 5511.4Sfvdl epp->ep_tsize = size; 5521.19Scgd if (epp->ep_daddr == ELFDEFNNAME(NO_ADDR)) { 5531.19Scgd epp->ep_daddr = addr; 5541.19Scgd epp->ep_dsize = size; 5551.19Scgd } 5561.4Sfvdl } else { 5571.4Sfvdl epp->ep_daddr = addr; 5581.4Sfvdl epp->ep_dsize = size; 5591.4Sfvdl } 5601.1Sfvdl break; 5611.1Sfvdl 5621.46Skleink case PT_SHLIB: 5631.60Smycroft /* SCO has these sections. */ 5641.46Skleink case PT_INTERP: 5651.60Smycroft /* Already did this one. */ 5661.46Skleink case PT_DYNAMIC: 5671.46Skleink case PT_NOTE: 5681.1Sfvdl break; 5691.1Sfvdl 5701.46Skleink case PT_PHDR: 5711.4Sfvdl /* Note address of program headers (in text segment) */ 5721.4Sfvdl phdr = pp->p_vaddr; 5731.7Schristos break; 5741.4Sfvdl 5751.1Sfvdl default: 5761.1Sfvdl /* 5771.9Scgd * Not fatal; we don't need to understand everything. 5781.1Sfvdl */ 5791.1Sfvdl break; 5801.1Sfvdl } 5811.1Sfvdl } 5821.5Sfvdl 5831.20Sjonathan /* this breaks on, e.g., OpenBSD-compatible mips shared binaries. */ 5841.20Sjonathan#ifndef ELF_INTERP_NON_RELOCATABLE 5851.5Sfvdl /* 5861.5Sfvdl * If no position to load the interpreter was set by a probe 5871.5Sfvdl * function, pick the same address that a non-fixed mmap(0, ..) 5881.5Sfvdl * would (i.e. something safely out of the way). 5891.5Sfvdl */ 5901.21Sfvdl if (pos == ELFDEFNNAME(NO_ADDR)) 5911.5Sfvdl pos = round_page(epp->ep_daddr + MAXDSIZ); 5921.20Sjonathan#endif /* !ELF_INTERP_NON_RELOCATABLE */ 5931.1Sfvdl 5941.1Sfvdl /* 5951.17Scgd * Check if we found a dynamically linked binary and arrange to load 5961.17Scgd * it's interpreter 5971.17Scgd */ 5981.1Sfvdl if (interp[0]) { 5991.1Sfvdl struct elf_args *ap; 6001.1Sfvdl 6011.58Sjdolecek MALLOC(ap, struct elf_args *, sizeof(struct elf_args), 6021.17Scgd M_TEMP, M_WAITOK); 6031.14Scgd if ((error = ELFNAME(load_file)(p, epp, interp, 6041.14Scgd &epp->ep_vmcmds, &epp->ep_entry, ap, &pos)) != 0) { 6051.58Sjdolecek FREE((char *)ap, M_TEMP); 6061.1Sfvdl goto bad; 6071.1Sfvdl } 6081.1Sfvdl pos += phsize; 6091.4Sfvdl ap->arg_phaddr = phdr; 6101.1Sfvdl 6111.1Sfvdl ap->arg_phentsize = eh->e_phentsize; 6121.1Sfvdl ap->arg_phnum = eh->e_phnum; 6131.1Sfvdl ap->arg_entry = eh->e_entry; 6141.1Sfvdl 6151.1Sfvdl epp->ep_emul_arg = ap; 6161.1Sfvdl } else 6171.1Sfvdl epp->ep_entry = eh->e_entry; 6181.1Sfvdl 6191.8Schristos#ifdef ELF_MAP_PAGE_ZERO 6201.8Schristos /* Dell SVR4 maps page zero, yeuch! */ 6211.57Sthorpej NEW_VMCMD(&epp->ep_vmcmds, vmcmd_map_readvn, PAGE_SIZE, 0, 6221.57Sthorpej epp->ep_vp, 0, VM_PROT_READ); 6231.8Schristos#endif 6241.58Sjdolecek FREE(interp, M_TEMP); 6251.17Scgd free((char *)ph, M_TEMP); 6261.48Schs vn_marktext(epp->ep_vp); 6271.9Scgd return exec_elf_setup_stack(p, epp); 6281.1Sfvdl 6291.1Sfvdlbad: 6301.58Sjdolecek if (interp) 6311.58Sjdolecek FREE(interp, M_TEMP); 6321.17Scgd free((char *)ph, M_TEMP); 6331.1Sfvdl kill_vmcmds(&epp->ep_vmcmds); 6341.1Sfvdl return ENOEXEC; 6351.40Schristos} 6361.40Schristos 6371.59Smrgint 6381.54SthorpejELFNAME2(netbsd,signature)(struct proc *p, struct exec_package *epp, 6391.54Sthorpej Elf_Ehdr *eh) 6401.40Schristos{ 6411.40Schristos Elf_Phdr *hph, *ph; 6421.46Skleink Elf_Nhdr *np = NULL; 6431.40Schristos size_t phsize; 6441.40Schristos int error; 6451.40Schristos 6461.40Schristos phsize = eh->e_phnum * sizeof(Elf_Phdr); 6471.40Schristos hph = (Elf_Phdr *)malloc(phsize, M_TEMP, M_WAITOK); 6481.41Schristos if ((error = ELFNAME(read_from)(p, epp->ep_vp, eh->e_phoff, 6491.41Schristos (caddr_t)hph, phsize)) != 0) 6501.40Schristos goto out1; 6511.40Schristos 6521.40Schristos for (ph = hph; ph < &hph[eh->e_phnum]; ph++) { 6531.46Skleink if (ph->p_type != PT_NOTE || 6541.46Skleink ph->p_filesz < sizeof(Elf_Nhdr) + ELF_NOTE_NETBSD_NAMESZ) 6551.40Schristos continue; 6561.40Schristos 6571.46Skleink np = (Elf_Nhdr *)malloc(ph->p_filesz, M_TEMP, M_WAITOK); 6581.40Schristos if ((error = ELFNAME(read_from)(p, epp->ep_vp, ph->p_offset, 6591.40Schristos (caddr_t)np, ph->p_filesz)) != 0) 6601.40Schristos goto out2; 6611.40Schristos 6621.46Skleink if (np->n_type != ELF_NOTE_TYPE_OSVERSION) { 6631.40Schristos free(np, M_TEMP); 6641.40Schristos np = NULL; 6651.40Schristos continue; 6661.40Schristos } 6671.40Schristos 6681.40Schristos /* Check the name and description sizes. */ 6691.46Skleink if (np->n_namesz != ELF_NOTE_NETBSD_NAMESZ || 6701.46Skleink np->n_descsz != ELF_NOTE_NETBSD_DESCSZ) 6711.40Schristos goto out3; 6721.40Schristos 6731.40Schristos /* Is the name "NetBSD\0\0"? */ 6741.40Schristos if (memcmp((np + 1), ELF_NOTE_NETBSD_NAME, 6751.40Schristos ELF_NOTE_NETBSD_NAMESZ)) 6761.40Schristos goto out3; 6771.40Schristos 6781.40Schristos /* XXX: We could check for the specific emulation here */ 6791.40Schristos /* All checks succeeded. */ 6801.40Schristos error = 0; 6811.40Schristos goto out2; 6821.40Schristos } 6831.40Schristos 6841.40Schristosout3: 6851.40Schristos error = ENOEXEC; 6861.40Schristosout2: 6871.40Schristos if (np) 6881.40Schristos free(np, M_TEMP); 6891.40Schristosout1: 6901.40Schristos free(hph, M_TEMP); 6911.40Schristos return error; 6921.40Schristos} 6931.40Schristos 6941.58Sjdolecekint 6951.54SthorpejELFNAME2(netbsd,probe)(struct proc *p, struct exec_package *epp, 6961.58Sjdolecek void *eh, char *itp, vaddr_t *pos) 6971.40Schristos{ 6981.40Schristos int error; 6991.40Schristos 7001.40Schristos if ((error = ELFNAME2(netbsd,signature)(p, epp, eh)) != 0) 7011.40Schristos return error; 7021.41Schristos *pos = ELFDEFNNAME(NO_ADDR); 7031.40Schristos return 0; 7041.1Sfvdl} 705