dynlink.c 38.9 KB
Newer Older
1
#define _GNU_SOURCE
R
Rich Felker 已提交
2 3 4 5 6 7 8 9 10 11 12
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <stdint.h>
#include <elf.h>
#include <sys/mman.h>
#include <limits.h>
#include <fcntl.h>
#include <sys/stat.h>
#include <errno.h>
R
Rich Felker 已提交
13
#include <link.h>
R
Rich Felker 已提交
14
#include <setjmp.h>
15
#include <pthread.h>
R
Rich Felker 已提交
16
#include <ctype.h>
17
#include <dlfcn.h>
18 19
#include "pthread_impl.h"
#include "libc.h"
R
Rich Felker 已提交
20

R
Rich Felker 已提交
21
static int errflag;
22
static char errbuf[128];
R
Rich Felker 已提交
23

24
#ifdef SHARED
R
Rich Felker 已提交
25

R
Rich Felker 已提交
26 27 28 29 30 31 32 33 34 35 36 37 38 39
#if ULONG_MAX == 0xffffffff
typedef Elf32_Ehdr Ehdr;
typedef Elf32_Phdr Phdr;
typedef Elf32_Sym Sym;
#define R_TYPE(x) ((x)&255)
#define R_SYM(x) ((x)>>8)
#else
typedef Elf64_Ehdr Ehdr;
typedef Elf64_Phdr Phdr;
typedef Elf64_Sym Sym;
#define R_TYPE(x) ((x)&0xffffffff)
#define R_SYM(x) ((x)>>32)
#endif

R
Rich Felker 已提交
40 41 42
#define MAXP2(a,b) (-(-(a)&-(b)))
#define ALIGN(x,y) ((x)+(y)-1 & -(y))

43 44 45 46 47 48 49 50 51 52 53 54
struct debug {
	int ver;
	void *head;
	void (*bp)(void);
	int state;
	void *base;
};

struct dso {
	unsigned char *base;
	char *name;
	size_t *dynv;
R
Rich Felker 已提交
55
	struct dso *next, *prev;
56

R
Rich Felker 已提交
57 58
	Phdr *phdr;
	int phnum;
59
	size_t phentsize;
R
Rich Felker 已提交
60 61
	int refcnt;
	Sym *syms;
62
	uint32_t *hashtab;
63
	uint32_t *ghashtab;
64
	int16_t *versym;
R
Rich Felker 已提交
65 66 67 68 69
	char *strings;
	unsigned char *map;
	size_t map_len;
	dev_t dev;
	ino_t ino;
70
	signed char global;
71 72
	char relocated;
	char constructed;
73
	char kernel_mapped;
74
	struct dso **deps, *needed_by;
75
	char *rpath_orig, *rpath;
76
	void *tls_image;
77
	size_t tls_len, tls_size, tls_align, tls_id, tls_offset;
T
Timo Teräs 已提交
78
	size_t relro_start, relro_end;
79 80 81
	void **new_dtv;
	unsigned char *new_tls;
	int new_dtv_idx, new_tls_idx;
82
	struct dso *fini_next;
83
	char *shortname;
R
Rich Felker 已提交
84
	char buf[];
R
Rich Felker 已提交
85 86
};

87 88 89 90 91
struct symdef {
	Sym *sym;
	struct dso *dso;
};

92 93
#include "reloc.h"

94
void __init_ssp(size_t *);
95
int __init_tp(void *);
96
void __init_libc(char **, char *);
97

98 99
const char *__libc_get_version(void);

100
static struct dso *head, *tail, *ldso, *fini_head;
101
static char *env_path, *sys_path;
R
Rich Felker 已提交
102
static unsigned long long gencnt;
103
static int ssp_used;
R
Rich Felker 已提交
104
static int runtime;
105
static int ldd_mode;
106
static int ldso_fail;
107
static int noload;
108
static jmp_buf *rtld_fail;
109
static pthread_rwlock_t lock;
110
static struct debug debug;
111
static size_t tls_cnt, tls_offset, tls_align = 4*sizeof(size_t);
112
static pthread_mutex_t init_fini_lock = { ._m_type = PTHREAD_MUTEX_RECURSIVE };
113
static long long builtin_tls[(sizeof(struct pthread) + 64)/sizeof(long long)];
114 115

struct debug *_dl_debug_addr = &debug;
R
Rich Felker 已提交
116

117
#define AUX_CNT 38
R
Rich Felker 已提交
118 119 120 121 122 123 124 125 126 127 128
#define DYN_CNT 34

static void decode_vec(size_t *v, size_t *a, size_t cnt)
{
	memset(a, 0, cnt*sizeof(size_t));
	for (; v[0]; v+=2) if (v[0]<cnt) {
		a[0] |= 1ULL<<v[0];
		a[v[0]] = v[1];
	}
}

129 130 131 132 133 134 135 136 137
static int search_vec(size_t *v, size_t *r, size_t key)
{
	for (; v[0]!=key; v+=2)
		if (!v[0]) return 0;
	*r = v[1];
	return 1;
}

static uint32_t sysv_hash(const char *s0)
R
Rich Felker 已提交
138
{
139
	const unsigned char *s = (void *)s0;
R
Rich Felker 已提交
140 141 142 143 144 145 146 147
	uint_fast32_t h = 0;
	while (*s) {
		h = 16*h + *s++;
		h ^= h>>24 & 0xf0;
	}
	return h & 0xfffffff;
}

148 149 150 151 152 153 154 155 156 157
static uint32_t gnu_hash(const char *s0)
{
	const unsigned char *s = (void *)s0;
	uint_fast32_t h = 5381;
	for (; *s; s++)
		h = h*33 + *s;
	return h;
}

static Sym *sysv_lookup(const char *s, uint32_t h, struct dso *dso)
R
Rich Felker 已提交
158 159
{
	size_t i;
R
Rich Felker 已提交
160 161 162
	Sym *syms = dso->syms;
	uint32_t *hashtab = dso->hashtab;
	char *strings = dso->strings;
R
Rich Felker 已提交
163
	for (i=hashtab[2+h%hashtab[0]]; i; i=hashtab[2+hashtab[0]+i]) {
164 165
		if ((!dso->versym || dso->versym[i] >= 0)
		    && (!strcmp(s, strings+syms[i].st_name)))
R
Rich Felker 已提交
166 167 168 169 170
			return syms+i;
	}
	return 0;
}

171 172
static Sym *gnu_lookup(const char *s, uint32_t h1, struct dso *dso)
{
173 174
	Sym *syms = dso->syms;
	char *strings = dso->strings;
175 176 177 178 179
	uint32_t *hashtab = dso->ghashtab;
	uint32_t nbuckets = hashtab[0];
	uint32_t *buckets = hashtab + 4 + hashtab[2]*(sizeof(size_t)/4);
	uint32_t h2;
	uint32_t *hashval;
180
	uint32_t i = buckets[h1 % nbuckets];
181

182
	if (!i) return 0;
183

184
	hashval = buckets + nbuckets + (i - hashtab[1]);
185

186
	for (h1 |= 1; ; i++) {
187
		h2 = *hashval++;
188 189 190
		if ((!dso->versym || dso->versym[i] >= 0)
		    && (h1 == (h2|1)) && !strcmp(s, strings + syms[i].st_name))
			return syms+i;
191 192 193 194 195 196
		if (h2 & 1) break;
	}

	return 0;
}

197
#define OK_TYPES (1<<STT_NOTYPE | 1<<STT_OBJECT | 1<<STT_FUNC | 1<<STT_COMMON | 1<<STT_TLS)
198
#define OK_BINDS (1<<STB_GLOBAL | 1<<STB_WEAK | 1<<STB_GNU_UNIQUE)
R
Rich Felker 已提交
199

200
static struct symdef find_sym(struct dso *dso, const char *s, int need_def)
R
Rich Felker 已提交
201
{
202
	uint32_t h = 0, gh = 0;
203
	struct symdef def = {0};
204 205 206 207 208 209 210
	if (dso->ghashtab) {
		gh = gnu_hash(s);
		if (gh == 0x1f4039c9 && !strcmp(s, "__stack_chk_fail")) ssp_used = 1;
	} else {
		h = sysv_hash(s);
		if (h == 0x595a4cc && !strcmp(s, "__stack_chk_fail")) ssp_used = 1;
	}
R
Rich Felker 已提交
211
	for (; dso; dso=dso->next) {
212 213
		Sym *sym;
		if (!dso->global) continue;
214 215 216 217 218 219 220
		if (dso->ghashtab) {
			if (!gh) gh = gnu_hash(s);
			sym = gnu_lookup(s, gh, dso);
		} else {
			if (!h) h = sysv_hash(s);
			sym = sysv_lookup(s, h, dso);
		}
221 222 223 224 225 226 227 228 229 230 231 232 233 234
		if (!sym) continue;
		if (!sym->st_shndx)
			if (need_def || (sym->st_info&0xf) == STT_TLS)
				continue;
		if (!sym->st_value)
			if ((sym->st_info&0xf) != STT_TLS)
				continue;
		if (!(1<<(sym->st_info&0xf) & OK_TYPES)) continue;
		if (!(1<<(sym->st_info>>4) & OK_BINDS)) continue;

		if (def.sym && sym->st_info>>4 == STB_WEAK) continue;
		def.sym = sym;
		def.dso = dso;
		if (sym->st_info>>4 == STB_GLOBAL) break;
R
Rich Felker 已提交
235
	}
236
	return def;
R
Rich Felker 已提交
237 238
}

239
static void do_relocs(struct dso *dso, size_t *rel, size_t rel_size, size_t stride)
R
Rich Felker 已提交
240
{
241 242 243
	unsigned char *base = dso->base;
	Sym *syms = dso->syms;
	char *strings = dso->strings;
R
Rich Felker 已提交
244 245 246 247 248
	Sym *sym;
	const char *name;
	void *ctx;
	int type;
	int sym_index;
249
	struct symdef def;
R
Rich Felker 已提交
250 251 252 253 254 255 256

	for (; rel_size; rel+=stride, rel_size-=stride*sizeof(size_t)) {
		type = R_TYPE(rel[1]);
		sym_index = R_SYM(rel[1]);
		if (sym_index) {
			sym = syms + sym_index;
			name = strings + sym->st_name;
257
			ctx = IS_COPY(type) ? head->next : head;
258
			def = find_sym(ctx, name, IS_PLT(type));
259 260
			if (!def.sym && (sym->st_shndx != SHN_UNDEF
			    || sym->st_info>>4 != STB_WEAK)) {
261 262
				snprintf(errbuf, sizeof errbuf,
					"Error relocating %s: %s: symbol not found",
263
					dso->name, name);
264
				if (runtime) longjmp(*rtld_fail, 1);
265
				dprintf(2, "%s\n", errbuf);
266 267
				ldso_fail = 1;
				continue;
R
Rich Felker 已提交
268
			}
269
		} else {
270 271 272
			sym = 0;
			def.sym = 0;
			def.dso = 0;
R
Rich Felker 已提交
273
		}
274 275 276
		do_single_reloc(dso, base, (void *)(base + rel[0]), type,
			stride>2 ? rel[2] : 0, sym, sym?sym->st_size:0, def,
			def.sym?(size_t)(def.dso->base+def.sym->st_value):0);
R
Rich Felker 已提交
277 278 279
	}
}

280 281 282 283 284 285
/* A huge hack: to make up for the wastefulness of shared libraries
 * needing at least a page of dirty memory even if they have no global
 * data, we reclaim the gaps at the beginning and end of writable maps
 * and "donate" them to the heap by setting up minimal malloc
 * structures and then freeing them. */

T
Timo Teräs 已提交
286
static void reclaim(struct dso *dso, size_t start, size_t end)
287 288
{
	size_t *a, *z;
T
Timo Teräs 已提交
289 290
	if (start >= dso->relro_start && start < dso->relro_end) start = dso->relro_end;
	if (end   >= dso->relro_start && end   < dso->relro_end) end = dso->relro_start;
291 292 293
	start = start + 6*sizeof(size_t)-1 & -4*sizeof(size_t);
	end = (end & -4*sizeof(size_t)) - 2*sizeof(size_t);
	if (start>end || end-start < 4*sizeof(size_t)) return;
T
Timo Teräs 已提交
294 295
	a = (size_t *)(dso->base + start);
	z = (size_t *)(dso->base + end);
296 297 298 299 300 301
	a[-2] = 1;
	a[-1] = z[0] = end-start + 2*sizeof(size_t) | 1;
	z[1] = 1;
	free(a);
}

302
static void reclaim_gaps(struct dso *dso)
303
{
304 305
	Phdr *ph = dso->phdr;
	size_t phcnt = dso->phnum;
306

307
	for (; phcnt--; ph=(void *)((char *)ph+dso->phentsize)) {
308 309
		if (ph->p_type!=PT_LOAD) continue;
		if ((ph->p_flags&(PF_R|PF_W))!=(PF_R|PF_W)) continue;
T
Timo Teräs 已提交
310 311
		reclaim(dso, ph->p_vaddr & -PAGE_SIZE, ph->p_vaddr);
		reclaim(dso, ph->p_vaddr+ph->p_memsz,
312 313 314 315
			ph->p_vaddr+ph->p_memsz+PAGE_SIZE-1 & -PAGE_SIZE);
	}
}

316
static void *map_library(int fd, struct dso *dso)
R
Rich Felker 已提交
317
{
318
	Ehdr buf[(896+sizeof(Ehdr))/sizeof(Ehdr)];
319
	void *allocated_buf=0;
R
Rich Felker 已提交
320 321 322 323 324
	size_t phsize;
	size_t addr_min=SIZE_MAX, addr_max=0, map_len;
	size_t this_min, this_max;
	off_t off_start;
	Ehdr *eh;
325
	Phdr *ph, *ph0;
R
Rich Felker 已提交
326
	unsigned prot;
327
	unsigned char *map=MAP_FAILED, *base;
328
	size_t dyn=0;
329
	size_t tls_image=0;
R
Rich Felker 已提交
330 331 332
	size_t i;

	ssize_t l = read(fd, buf, sizeof buf);
333
	eh = buf;
334 335 336
	if (l<0) return 0;
	if (l<sizeof *eh || (eh->e_type != ET_DYN && eh->e_type != ET_EXEC))
		goto noexec;
R
Rich Felker 已提交
337
	phsize = eh->e_phentsize * eh->e_phnum;
338 339 340 341 342 343 344 345
	if (phsize > sizeof buf - sizeof *eh) {
		allocated_buf = malloc(phsize);
		if (!allocated_buf) return 0;
		l = pread(fd, allocated_buf, phsize, eh->e_phoff);
		if (l < 0) goto error;
		if (l != phsize) goto noexec;
		ph = ph0 = allocated_buf;
	} else if (eh->e_phoff + phsize > l) {
346
		l = pread(fd, buf+1, phsize, eh->e_phoff);
347 348
		if (l < 0) goto error;
		if (l != phsize) goto noexec;
349 350 351
		ph = ph0 = (void *)(buf + 1);
	} else {
		ph = ph0 = (void *)((char *)buf + eh->e_phoff);
R
Rich Felker 已提交
352 353
	}
	for (i=eh->e_phnum; i; i--, ph=(void *)((char *)ph+eh->e_phentsize)) {
354
		if (ph->p_type == PT_DYNAMIC) {
R
Rich Felker 已提交
355
			dyn = ph->p_vaddr;
356
		} else if (ph->p_type == PT_TLS) {
357 358 359 360
			tls_image = ph->p_vaddr;
			dso->tls_align = ph->p_align;
			dso->tls_len = ph->p_filesz;
			dso->tls_size = ph->p_memsz;
T
Timo Teräs 已提交
361 362 363
		} else if (ph->p_type == PT_GNU_RELRO) {
			dso->relro_start = ph->p_vaddr & -PAGE_SIZE;
			dso->relro_end = (ph->p_vaddr + ph->p_memsz) & -PAGE_SIZE;
364
		}
R
Rich Felker 已提交
365 366 367 368 369 370 371 372 373 374 375 376
		if (ph->p_type != PT_LOAD) continue;
		if (ph->p_vaddr < addr_min) {
			addr_min = ph->p_vaddr;
			off_start = ph->p_offset;
			prot = (((ph->p_flags&PF_R) ? PROT_READ : 0) |
				((ph->p_flags&PF_W) ? PROT_WRITE: 0) |
				((ph->p_flags&PF_X) ? PROT_EXEC : 0));
		}
		if (ph->p_vaddr+ph->p_memsz > addr_max) {
			addr_max = ph->p_vaddr+ph->p_memsz;
		}
	}
377
	if (!dyn) goto noexec;
R
Rich Felker 已提交
378 379 380 381 382 383 384 385 386
	addr_max += PAGE_SIZE-1;
	addr_max &= -PAGE_SIZE;
	addr_min &= -PAGE_SIZE;
	off_start &= -PAGE_SIZE;
	map_len = addr_max - addr_min + off_start;
	/* The first time, we map too much, possibly even more than
	 * the length of the file. This is okay because we will not
	 * use the invalid part; we just need to reserve the right
	 * amount of virtual address space to map over later. */
387
	map = mmap((void *)addr_min, map_len, prot, MAP_PRIVATE, fd, off_start);
388
	if (map==MAP_FAILED) goto error;
389 390 391 392 393 394
	/* If the loaded file is not relocatable and the requested address is
	 * not available, then the load operation must fail. */
	if (eh->e_type != ET_DYN && addr_min && map!=(void *)addr_min) {
		errno = EBUSY;
		goto error;
	}
R
Rich Felker 已提交
395
	base = map - addr_min;
396 397 398
	dso->phdr = 0;
	dso->phnum = 0;
	for (ph=ph0, i=eh->e_phnum; i; i--, ph=(void *)((char *)ph+eh->e_phentsize)) {
R
Rich Felker 已提交
399
		if (ph->p_type != PT_LOAD) continue;
400 401 402 403 404 405 406
		/* Check if the programs headers are in this load segment, and
		 * if so, record the address for use by dl_iterate_phdr. */
		if (!dso->phdr && eh->e_phoff >= ph->p_offset
		    && eh->e_phoff+phsize <= ph->p_offset+ph->p_filesz) {
			dso->phdr = (void *)(base + ph->p_vaddr
				+ (eh->e_phoff-ph->p_offset));
			dso->phnum = eh->e_phnum;
407
			dso->phentsize = eh->e_phentsize;
408
		}
R
Rich Felker 已提交
409 410 411 412 413 414 415 416
		/* Reuse the existing mapping for the lowest-address LOAD */
		if ((ph->p_vaddr & -PAGE_SIZE) == addr_min) continue;
		this_min = ph->p_vaddr & -PAGE_SIZE;
		this_max = ph->p_vaddr+ph->p_memsz+PAGE_SIZE-1 & -PAGE_SIZE;
		off_start = ph->p_offset & -PAGE_SIZE;
		prot = (((ph->p_flags&PF_R) ? PROT_READ : 0) |
			((ph->p_flags&PF_W) ? PROT_WRITE: 0) |
			((ph->p_flags&PF_X) ? PROT_EXEC : 0));
417 418
		if (mmap(base+this_min, this_max-this_min, prot, MAP_PRIVATE|MAP_FIXED, fd, off_start) == MAP_FAILED)
			goto error;
R
Rich Felker 已提交
419 420 421 422
		if (ph->p_memsz > ph->p_filesz) {
			size_t brk = (size_t)base+ph->p_vaddr+ph->p_filesz;
			size_t pgbrk = brk+PAGE_SIZE-1 & -PAGE_SIZE;
			memset((void *)brk, 0, pgbrk-brk & PAGE_SIZE-1);
423 424
			if (pgbrk-(size_t)base < this_max && mmap((void *)pgbrk, (size_t)base+this_max-pgbrk, prot, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) == MAP_FAILED)
				goto error;
R
Rich Felker 已提交
425 426
		}
	}
R
Rich Felker 已提交
427 428
	for (i=0; ((size_t *)(base+dyn))[i]; i+=2)
		if (((size_t *)(base+dyn))[i]==DT_TEXTREL) {
429 430
			if (mprotect(map, map_len, PROT_READ|PROT_WRITE|PROT_EXEC) < 0)
				goto error;
R
Rich Felker 已提交
431 432
			break;
		}
433 434 435 436 437
	dso->map = map;
	dso->map_len = map_len;
	dso->base = base;
	dso->dynv = (void *)(base+dyn);
	if (dso->tls_size) dso->tls_image = (void *)(base+tls_image);
438
	if (!runtime) reclaim_gaps(dso);
439
	free(allocated_buf);
R
Rich Felker 已提交
440
	return map;
441 442
noexec:
	errno = ENOEXEC;
443
error:
444 445
	if (map!=MAP_FAILED) munmap(map, map_len);
	free(allocated_buf);
446
	return 0;
R
Rich Felker 已提交
447 448
}

449
static int path_open(const char *name, const char *s, char *buf, size_t buf_size)
450
{
451 452
	size_t l;
	int fd;
453
	for (;;) {
454 455 456 457 458
		s += strspn(s, ":\n");
		l = strcspn(s, ":\n");
		if (l-1 >= INT_MAX) return -1;
		if (snprintf(buf, buf_size, "%.*s/%s", (int)l, s, name) >= buf_size)
			continue;
459
		if ((fd = open(buf, O_RDONLY|O_CLOEXEC))>=0) return fd;
460
		s += l;
461 462 463
	}
}

464 465 466 467 468 469 470 471 472 473 474 475 476
static int fixup_rpath(struct dso *p, char *buf, size_t buf_size)
{
	size_t n, l;
	const char *s, *t, *origin;
	char *d;
	if (p->rpath) return 0;
	if (!p->rpath_orig) return -1;
	if (!strchr(p->rpath_orig, '$')) {
		p->rpath = p->rpath_orig;
		return 0;
	}
	n = 0;
	s = p->rpath_orig;
R
Rich Felker 已提交
477 478 479
	while ((t=strchr(s, '$'))) {
		if (strncmp(t, "$ORIGIN", 7) && strncmp(t, "${ORIGIN}", 9))
			return -1;
480 481 482 483 484 485 486 487 488 489 490 491 492 493
		s = t+1;
		n++;
	}
	if (n > SSIZE_MAX/PATH_MAX) return -1;

	if (p->kernel_mapped) {
		/* $ORIGIN searches cannot be performed for the main program
		 * when it is suid/sgid/AT_SECURE. This is because the
		 * pathname is under the control of the caller of execve.
		 * For libraries, however, $ORIGIN can be processed safely
		 * since the library's pathname came from a trusted source
		 * (either system paths or a call to dlopen). */
		if (libc.secure)
			return -1;
R
Rich Felker 已提交
494 495
		l = readlink("/proc/self/exe", buf, buf_size);
		if (l >= buf_size)
496
			return -1;
R
Rich Felker 已提交
497
		buf[l] = 0;
498 499 500 501 502 503 504 505 506 507 508
		origin = buf;
	} else {
		origin = p->name;
	}
	t = strrchr(origin, '/');
	l = t ? t-origin : 0;
	p->rpath = malloc(strlen(p->rpath_orig) + n*l + 1);
	if (!p->rpath) return -1;

	d = p->rpath;
	s = p->rpath_orig;
R
Rich Felker 已提交
509
	while ((t=strchr(s, '$'))) {
510 511 512 513
		memcpy(d, s, t-s);
		d += t-s;
		memcpy(d, origin, l);
		d += l;
R
Rich Felker 已提交
514 515
		/* It was determined previously that the '$' is followed
		 * either by "ORIGIN" or "{ORIGIN}". */
516 517 518 519 520 521
		s = t + 7 + 2*(t[1]=='{');
	}
	strcpy(d, s);
	return 0;
}

522 523 524 525 526 527
static void decode_dyn(struct dso *p)
{
	size_t dyn[DYN_CNT] = {0};
	decode_vec(p->dynv, dyn, DYN_CNT);
	p->syms = (void *)(p->base + dyn[DT_SYMTAB]);
	p->strings = (void *)(p->base + dyn[DT_STRTAB]);
528 529
	if (dyn[0]&(1<<DT_HASH))
		p->hashtab = (void *)(p->base + dyn[DT_HASH]);
530
	if (dyn[0]&(1<<DT_RPATH))
531
		p->rpath_orig = (void *)(p->strings + dyn[DT_RPATH]);
532 533
	if (search_vec(p->dynv, dyn, DT_GNU_HASH))
		p->ghashtab = (void *)(p->base + *dyn);
534 535
	if (search_vec(p->dynv, dyn, DT_VERSYM))
		p->versym = (void *)(p->base + *dyn);
536 537
}

538
static struct dso *load_library(const char *name, struct dso *needed_by)
R
Rich Felker 已提交
539
{
540
	char buf[2*NAME_MAX+2];
541
	const char *pathname;
542
	unsigned char *map;
543
	struct dso *p, temp_dso = {0};
R
Rich Felker 已提交
544 545
	int fd;
	struct stat st;
546 547
	size_t alloc_size;
	int n_th = 0;
548
	int is_self = 0;
R
Rich Felker 已提交
549 550 551 552 553 554 555 556

	/* Catch and block attempts to reload the implementation itself */
	if (name[0]=='l' && name[1]=='i' && name[2]=='b') {
		static const char *rp, reserved[] =
			"c\0pthread\0rt\0m\0dl\0util\0xnet\0";
		char *z = strchr(name, '.');
		if (z) {
			size_t l = z-name;
557
			for (rp=reserved; *rp && strncmp(name+3, rp, l-3); rp+=strlen(rp)+1);
R
Rich Felker 已提交
558
			if (*rp) {
559 560 561 562 563 564 565 566 567 568 569 570
				if (ldd_mode) {
					/* Track which names have been resolved
					 * and only report each one once. */
					static unsigned reported;
					unsigned mask = 1U<<(rp-reserved);
					if (!(reported & mask)) {
						reported |= mask;
						dprintf(1, "\t%s => %s (%p)\n",
							name, ldso->name,
							ldso->base);
					}
				}
571
				is_self = 1;
R
Rich Felker 已提交
572 573 574
			}
		}
	}
575 576 577 578 579 580 581 582 583
	if (!strcmp(name, ldso->name)) is_self = 1;
	if (is_self) {
		if (!ldso->prev) {
			tail->next = ldso;
			ldso->prev = tail;
			tail = ldso->next ? ldso->next : ldso;
		}
		return ldso;
	}
584
	if (strchr(name, '/')) {
585
		pathname = name;
586
		fd = open(name, O_RDONLY|O_CLOEXEC);
R
Rich Felker 已提交
587
	} else {
588 589 590 591 592 593 594
		/* Search for the name to see if it's already loaded */
		for (p=head->next; p; p=p->next) {
			if (p->shortname && !strcmp(p->shortname, name)) {
				p->refcnt++;
				return p;
			}
		}
595
		if (strlen(name) > NAME_MAX) return 0;
596
		fd = -1;
597
		if (env_path) fd = path_open(name, env_path, buf, sizeof buf);
598
		for (p=needed_by; fd < 0 && p; p=p->needed_by)
599
			if (!fixup_rpath(p, buf, sizeof buf))
600
				fd = path_open(name, p->rpath, buf, sizeof buf);
601 602
		if (fd < 0) {
			if (!sys_path) {
603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622
				char *prefix = 0;
				size_t prefix_len;
				if (ldso->name[0]=='/') {
					char *s, *t, *z;
					for (s=t=z=ldso->name; *s; s++)
						if (*s=='/') z=t, t=s;
					prefix_len = z-ldso->name;
					if (prefix_len < PATH_MAX)
						prefix = ldso->name;
				}
				if (!prefix) {
					prefix = "";
					prefix_len = 0;
				}
				char etc_ldso_path[prefix_len + 1
					+ sizeof "/etc/ld-musl-" LDSO_ARCH ".path"];
				snprintf(etc_ldso_path, sizeof etc_ldso_path,
					"%.*s/etc/ld-musl-" LDSO_ARCH ".path",
					(int)prefix_len, prefix);
				FILE *f = fopen(etc_ldso_path, "rbe");
623
				if (f) {
624
					if (getdelim(&sys_path, (size_t[1]){0}, 0, f) <= 0) {
625
						free(sys_path);
626
						sys_path = "";
627
					}
628
					fclose(f);
629 630
				} else if (errno != ENOENT) {
					sys_path = "";
631 632
				}
			}
633 634
			if (!sys_path) sys_path = "/lib:/usr/local/lib:/usr/lib";
			fd = path_open(name, sys_path, buf, sizeof buf);
R
Rich Felker 已提交
635
		}
636
		pathname = buf;
R
Rich Felker 已提交
637 638 639 640 641 642 643 644
	}
	if (fd < 0) return 0;
	if (fstat(fd, &st) < 0) {
		close(fd);
		return 0;
	}
	for (p=head->next; p; p=p->next) {
		if (p->dev == st.st_dev && p->ino == st.st_ino) {
645 646 647
			/* If this library was previously loaded with a
			 * pathname but a search found the same inode,
			 * setup its shortname so it can be found by name. */
648 649
			if (!p->shortname && pathname != name)
				p->shortname = strrchr(p->name, '/')+1;
R
Rich Felker 已提交
650 651 652 653 654
			close(fd);
			p->refcnt++;
			return p;
		}
	}
655
	map = noload ? 0 : map_library(fd, &temp_dso);
R
Rich Felker 已提交
656 657
	close(fd);
	if (!map) return 0;
658 659 660 661 662 663 664 665 666 667

	/* Allocate storage for the new DSO. When there is TLS, this
	 * storage must include a reservation for all pre-existing
	 * threads to obtain copies of both the new TLS, and an
	 * extended DTV capable of storing an additional slot for
	 * the newly-loaded DSO. */
	alloc_size = sizeof *p + strlen(pathname) + 1;
	if (runtime && temp_dso.tls_image) {
		size_t per_th = temp_dso.tls_size + temp_dso.tls_align
			+ sizeof(void *) * (tls_cnt+3);
668
		n_th = libc.threads_minus_1 + 1;
669 670 671 672
		if (n_th > SSIZE_MAX / per_th) alloc_size = SIZE_MAX;
		else alloc_size += n_th * per_th;
	}
	p = calloc(1, alloc_size);
R
Rich Felker 已提交
673
	if (!p) {
674
		munmap(map, temp_dso.map_len);
R
Rich Felker 已提交
675 676
		return 0;
	}
677
	memcpy(p, &temp_dso, sizeof temp_dso);
678
	decode_dyn(p);
R
Rich Felker 已提交
679 680 681
	p->dev = st.st_dev;
	p->ino = st.st_ino;
	p->refcnt = 1;
682
	p->needed_by = needed_by;
R
Rich Felker 已提交
683
	p->name = p->buf;
684 685 686
	strcpy(p->name, pathname);
	/* Add a shortname only if name arg was not an explicit pathname. */
	if (pathname != name) p->shortname = strrchr(p->name, '/')+1;
687
	if (p->tls_image) {
688
		if (runtime && !libc.has_thread_pointer) {
689
			munmap(map, p->map_len);
690
			free(p);
691
			errno = ENOSYS;
692 693
			return 0;
		}
694
		p->tls_id = ++tls_cnt;
R
Rich Felker 已提交
695
		tls_align = MAXP2(tls_align, p->tls_align);
696 697 698 699 700
#ifdef TLS_ABOVE_TP
		p->tls_offset = tls_offset + ( (tls_align-1) &
			-(tls_offset + (uintptr_t)p->tls_image) );
		tls_offset += p->tls_size;
#else
R
Rich Felker 已提交
701 702 703 704
		tls_offset += p->tls_size + p->tls_align - 1;
		tls_offset -= (tls_offset + (uintptr_t)p->tls_image)
			& (p->tls_align-1);
		p->tls_offset = tls_offset;
705
#endif
706 707 708 709
		p->new_dtv = (void *)(-sizeof(size_t) &
			(uintptr_t)(p->name+strlen(p->name)+sizeof(size_t)));
		p->new_tls = (void *)(p->new_dtv + n_th*(tls_cnt+1));
	}
R
Rich Felker 已提交
710 711 712 713 714

	tail->next = p;
	p->prev = tail;
	tail = p;

715
	if (ldd_mode) dprintf(1, "\t%s => %s (%p)\n", name, pathname, p->base);
716

R
Rich Felker 已提交
717 718 719 720 721
	return p;
}

static void load_deps(struct dso *p)
{
722 723
	size_t i, ndeps=0;
	struct dso ***deps = &p->deps, **tmp, *dep;
R
Rich Felker 已提交
724 725 726
	for (; p; p=p->next) {
		for (i=0; p->dynv[i]; i+=2) {
			if (p->dynv[i] != DT_NEEDED) continue;
727
			dep = load_library(p->strings + p->dynv[i+1], p);
728
			if (!dep) {
729 730
				snprintf(errbuf, sizeof errbuf,
					"Error loading shared library %s: %m (needed by %s)",
R
Rich Felker 已提交
731
					p->strings + p->dynv[i+1], p->name);
732
				if (runtime) longjmp(*rtld_fail, 1);
733
				dprintf(2, "%s\n", errbuf);
734 735
				ldso_fail = 1;
				continue;
R
Rich Felker 已提交
736
			}
737 738
			if (runtime) {
				tmp = realloc(*deps, sizeof(*tmp)*(ndeps+2));
739
				if (!tmp) longjmp(*rtld_fail, 1);
740 741 742 743
				tmp[ndeps++] = dep;
				tmp[ndeps] = 0;
				*deps = tmp;
			}
R
Rich Felker 已提交
744 745 746 747
		}
	}
}

R
Rich Felker 已提交
748 749 750 751 752 753 754 755 756
static void load_preload(char *s)
{
	int tmp;
	char *z;
	for (z=s; *z; s=z) {
		for (   ; *s && isspace(*s); s++);
		for (z=s; *z && !isspace(*z); z++);
		tmp = *z;
		*z = 0;
757
		load_library(s, 0);
R
Rich Felker 已提交
758 759 760 761
		*z = tmp;
	}
}

762 763 764 765 766
static void make_global(struct dso *p)
{
	for (; p; p=p->next) p->global = 1;
}

R
Rich Felker 已提交
767 768 769 770 771 772
static void reloc_all(struct dso *p)
{
	size_t dyn[DYN_CNT] = {0};
	for (; p; p=p->next) {
		if (p->relocated) continue;
		decode_vec(p->dynv, dyn, DYN_CNT);
R
Rich Felker 已提交
773 774 775
#ifdef NEED_ARCH_RELOCS
		do_arch_relocs(p, head);
#endif
776 777 778 779
		do_relocs(p, (void *)(p->base+dyn[DT_JMPREL]), dyn[DT_PLTRELSZ],
			2+(dyn[DT_PLTREL]==DT_RELA));
		do_relocs(p, (void *)(p->base+dyn[DT_REL]), dyn[DT_RELSZ], 2);
		do_relocs(p, (void *)(p->base+dyn[DT_RELA]), dyn[DT_RELASZ], 3);
T
Timo Teräs 已提交
780 781 782 783

		if (p->relro_start != p->relro_end &&
		    mprotect(p->base+p->relro_start, p->relro_end-p->relro_start, PROT_READ) < 0) {
			snprintf(errbuf, sizeof errbuf,
784
				"Error relocating %s: RELRO protection failed: %m",
T
Timo Teräs 已提交
785 786 787 788 789 790
				p->name);
			if (runtime) longjmp(*rtld_fail, 1);
			dprintf(2, "%s\n", errbuf);
			ldso_fail = 1;
		}

791
		p->relocated = 1;
R
Rich Felker 已提交
792 793 794
	}
}

795
static void kernel_mapped_dso(struct dso *p)
796
{
797 798 799 800 801 802
	size_t min_addr = -1, max_addr = 0, cnt;
	Phdr *ph = p->phdr;
	for (cnt = p->phnum; cnt--; ph = (void *)((char *)ph + p->phentsize)) {
		if (ph->p_type == PT_DYNAMIC) {
			p->dynv = (void *)(p->base + ph->p_vaddr);
		} else if (ph->p_type == PT_GNU_RELRO) {
T
Timo Teräs 已提交
803 804 805
			p->relro_start = ph->p_vaddr & -PAGE_SIZE;
			p->relro_end = (ph->p_vaddr + ph->p_memsz) & -PAGE_SIZE;
		}
806 807 808 809 810 811 812 813 814 815
		if (ph->p_type != PT_LOAD) continue;
		if (ph->p_vaddr < min_addr)
			min_addr = ph->p_vaddr;
		if (ph->p_vaddr+ph->p_memsz > max_addr)
			max_addr = ph->p_vaddr+ph->p_memsz;
	}
	min_addr &= -PAGE_SIZE;
	max_addr = (max_addr + PAGE_SIZE-1) & -PAGE_SIZE;
	p->map = p->base + min_addr;
	p->map_len = max_addr - min_addr;
816
	p->kernel_mapped = 1;
817 818
}

819 820 821 822 823 824 825
static void do_fini()
{
	struct dso *p;
	size_t dyn[DYN_CNT] = {0};
	for (p=fini_head; p; p=p->fini_next) {
		if (!p->constructed) continue;
		decode_vec(p->dynv, dyn, DYN_CNT);
826 827
		if (dyn[0] & (1<<DT_FINI_ARRAY)) {
			size_t n = dyn[DT_FINI_ARRAYSZ]/sizeof(size_t);
828 829
			size_t *fn = (size_t *)(p->base + dyn[DT_FINI_ARRAY])+n;
			while (n--) ((void (*)(void))*--fn)();
830
		}
831
#ifndef NO_LEGACY_INITFINI
832
		if ((dyn[0] & (1<<DT_FINI)) && dyn[DT_FINI])
833
			((void (*)(void))(p->base + dyn[DT_FINI]))();
834
#endif
835 836 837
	}
}

838 839 840
static void do_init_fini(struct dso *p)
{
	size_t dyn[DYN_CNT] = {0};
841
	int need_locking = libc.threads_minus_1;
842 843 844 845
	/* Allow recursive calls that arise when a library calls
	 * dlopen from one of its constructors, but block any
	 * other threads until all ctors have finished. */
	if (need_locking) pthread_mutex_lock(&init_fini_lock);
846
	for (; p; p=p->prev) {
847 848
		if (p->constructed) continue;
		p->constructed = 1;
849
		decode_vec(p->dynv, dyn, DYN_CNT);
850
		if (dyn[0] & ((1<<DT_FINI) | (1<<DT_FINI_ARRAY))) {
851 852 853
			p->fini_next = fini_head;
			fini_head = p;
		}
854
#ifndef NO_LEGACY_INITFINI
855
		if ((dyn[0] & (1<<DT_INIT)) && dyn[DT_INIT])
856
			((void (*)(void))(p->base + dyn[DT_INIT]))();
857
#endif
858 859 860 861 862
		if (dyn[0] & (1<<DT_INIT_ARRAY)) {
			size_t n = dyn[DT_INIT_ARRAYSZ]/sizeof(size_t);
			size_t *fn = (void *)(p->base + dyn[DT_INIT_ARRAY]);
			while (n--) ((void (*)(void))*fn++)();
		}
863 864 865 866
		if (!need_locking && libc.threads_minus_1) {
			need_locking = 1;
			pthread_mutex_lock(&init_fini_lock);
		}
867
	}
868
	if (need_locking) pthread_mutex_unlock(&init_fini_lock);
869 870
}

871 872 873 874
void _dl_debug_state(void)
{
}

875 876 877 878 879 880 881 882 883 884 885 886 887
void __reset_tls()
{
	pthread_t self = __pthread_self();
	struct dso *p;
	for (p=head; p; p=p->next) {
		if (!p->tls_id || !self->dtv[p->tls_id]) continue;
		memcpy(self->dtv[p->tls_id], p->tls_image, p->tls_len);
		memset((char *)self->dtv[p->tls_id]+p->tls_len, 0,
			p->tls_size - p->tls_len);
		if (p->tls_id == (size_t)self->dtv[0]) break;
	}
}

888
void *__copy_tls(unsigned char *mem)
889
{
R
Rich Felker 已提交
890
	pthread_t td;
891
	struct dso *p;
R
Rich Felker 已提交
892

893
	void **dtv = (void *)mem;
894
	dtv[0] = (void *)tls_cnt;
895 896 897 898 899
	if (!tls_cnt) {
		td = (void *)(dtv+1);
		td->dtv = dtv;
		return td;
	}
R
Rich Felker 已提交
900

901 902 903 904 905 906 907 908 909 910 911 912
#ifdef TLS_ABOVE_TP
	mem += sizeof(void *) * (tls_cnt+1);
	mem += -((uintptr_t)mem + sizeof(struct pthread)) & (tls_align-1);
	td = (pthread_t)mem;
	mem += sizeof(struct pthread);

	for (p=head; p; p=p->next) {
		if (!p->tls_id) continue;
		dtv[p->tls_id] = mem + p->tls_offset;
		memcpy(dtv[p->tls_id], p->tls_image, p->tls_len);
	}
#else
913
	mem += libc.tls_size - sizeof(struct pthread);
R
Rich Felker 已提交
914 915 916 917
	mem -= (uintptr_t)mem & (tls_align-1);
	td = (pthread_t)mem;

	for (p=head; p; p=p->next) {
918
		if (!p->tls_id) continue;
R
Rich Felker 已提交
919 920
		dtv[p->tls_id] = mem - p->tls_offset;
		memcpy(dtv[p->tls_id], p->tls_image, p->tls_len);
921
	}
922
#endif
R
Rich Felker 已提交
923 924
	td->dtv = dtv;
	return td;
925 926
}

927
void *__tls_get_addr(size_t *v)
928 929
{
	pthread_t self = __pthread_self();
930
	if (v[0]<=(size_t)self->dtv[0] && self->dtv[v[0]])
931 932 933 934
		return (char *)self->dtv[v[0]]+v[1];

	/* Block signals to make accessing new TLS async-signal-safe */
	sigset_t set;
935
	pthread_sigmask(SIG_BLOCK, SIGALL_SET, &set);
936
	if (v[0]<=(size_t)self->dtv[0] && self->dtv[v[0]]) {
937 938 939 940 941 942 943 944 945 946 947 948
		pthread_sigmask(SIG_SETMASK, &set, 0);
		return (char *)self->dtv[v[0]]+v[1];
	}

	/* This is safe without any locks held because, if the caller
	 * is able to request the Nth entry of the DTV, the DSO list
	 * must be valid at least that far out and it was synchronized
	 * at program startup or by an already-completed call to dlopen. */
	struct dso *p;
	for (p=head; p->tls_id != v[0]; p=p->next);

	/* Get new DTV space from new DSO if needed */
949
	if (v[0] > (size_t)self->dtv[0]) {
950 951
		void **newdtv = p->new_dtv +
			(v[0]+1)*sizeof(void *)*a_fetch_add(&p->new_dtv_idx,1);
952
		memcpy(newdtv, self->dtv,
953 954 955
			((size_t)self->dtv[0]+1) * sizeof(void *));
		newdtv[0] = (void *)v[0];
		self->dtv = newdtv;
956
	}
957 958 959 960 961 962

	/* Get new TLS memory from new DSO */
	unsigned char *mem = p->new_tls +
		(p->tls_size + p->tls_align) * a_fetch_add(&p->new_tls_idx,1);
	mem += ((uintptr_t)p->tls_image - (uintptr_t)mem) & (p->tls_align-1);
	self->dtv[v[0]] = mem;
R
Rich Felker 已提交
963
	memcpy(mem, p->tls_image, p->tls_len);
964 965
	pthread_sigmask(SIG_SETMASK, &set, 0);
	return mem + v[1];
966 967
}

R
Rich Felker 已提交
968 969
static void update_tls_size()
{
970 971 972 973 974 975
	libc.tls_size = ALIGN(
		(1+tls_cnt) * sizeof(void *) +
		tls_offset +
		sizeof(struct pthread) +
		tls_align * 2,
	tls_align);
R
Rich Felker 已提交
976 977
}

978
void *__dynlink(int argc, char **argv)
R
Rich Felker 已提交
979
{
980
	size_t aux[AUX_CNT] = {0};
R
Rich Felker 已提交
981 982
	size_t i;
	Phdr *phdr;
983
	Ehdr *ehdr;
984
	static struct dso builtin_dsos[3];
R
Rich Felker 已提交
985 986
	struct dso *const app = builtin_dsos+0;
	struct dso *const lib = builtin_dsos+1;
987
	struct dso *const vdso = builtin_dsos+2;
R
Rich Felker 已提交
988
	char *env_preload=0;
R
Rich Felker 已提交
989
	size_t vdso_base;
990
	size_t *auxv;
991
	char **envp = argv+argc+1;
992
	void *initial_tls;
R
Rich Felker 已提交
993 994

	/* Find aux vector just past environ[] */
995 996 997
	for (i=argc+1; argv[i]; i++)
		if (!memcmp(argv[i], "LD_LIBRARY_PATH=", 16))
			env_path = argv[i]+16;
R
Rich Felker 已提交
998 999
		else if (!memcmp(argv[i], "LD_PRELOAD=", 11))
			env_preload = argv[i]+11;
R
Rich Felker 已提交
1000 1001 1002 1003
	auxv = (void *)(argv+i+1);

	decode_vec(auxv, aux, AUX_CNT);

1004 1005
	/* Only trust user/env if kernel says we're not suid/sgid */
	if ((aux[0]&0x7800)!=0x7800 || aux[AT_UID]!=aux[AT_EUID]
R
Rich Felker 已提交
1006
	  || aux[AT_GID]!=aux[AT_EGID] || aux[AT_SECURE]) {
1007
		env_path = 0;
R
Rich Felker 已提交
1008
		env_preload = 0;
1009
		libc.secure = 1;
1010
	}
1011
	libc.page_size = aux[AT_PAGESZ];
1012

1013 1014 1015 1016 1017 1018 1019 1020 1021
	/* If the dynamic linker was invoked as a program itself, AT_BASE
	 * will not be set. In that case, we assume the base address is
	 * the start of the page containing the PHDRs; I don't know any
	 * better approach... */
	if (!aux[AT_BASE]) {
		aux[AT_BASE] = aux[AT_PHDR] & -PAGE_SIZE;
		aux[AT_PHDR] = aux[AT_PHENT] = aux[AT_PHNUM] = 0;
	}

1022 1023 1024
	/* The dynamic linker load address is passed by the kernel
	 * in the AUX vector, so this is easy. */
	lib->base = (void *)aux[AT_BASE];
1025
	lib->name = lib->shortname = "libc.so";
1026 1027
	lib->global = 1;
	ehdr = (void *)lib->base;
R
Rich Felker 已提交
1028 1029
	lib->phnum = ehdr->e_phnum;
	lib->phdr = (void *)(aux[AT_BASE]+ehdr->e_phoff);
1030 1031
	lib->phentsize = ehdr->e_phentsize;
	kernel_mapped_dso(lib);
1032 1033
	decode_dyn(lib);

1034
	if (aux[AT_PHDR]) {
1035
		size_t interp_off = 0;
1036
		size_t tls_image = 0;
1037
		/* Find load address of the main program, via AT_PHDR vs PT_PHDR. */
R
Rich Felker 已提交
1038 1039
		app->phdr = phdr = (void *)aux[AT_PHDR];
		app->phnum = aux[AT_PHNUM];
1040
		app->phentsize = aux[AT_PHENT];
1041 1042 1043
		for (i=aux[AT_PHNUM]; i; i--, phdr=(void *)((char *)phdr + aux[AT_PHENT])) {
			if (phdr->p_type == PT_PHDR)
				app->base = (void *)(aux[AT_PHDR] - phdr->p_vaddr);
1044 1045
			else if (phdr->p_type == PT_INTERP)
				interp_off = (size_t)phdr->p_vaddr;
1046 1047 1048 1049 1050 1051
			else if (phdr->p_type == PT_TLS) {
				tls_image = phdr->p_vaddr;
				app->tls_len = phdr->p_filesz;
				app->tls_size = phdr->p_memsz;
				app->tls_align = phdr->p_align;
			}
1052
		}
1053
		if (app->tls_size) app->tls_image = (char *)app->base + tls_image;
1054
		if (interp_off) lib->name = (char *)app->base + interp_off;
1055 1056 1057 1058 1059
		if ((aux[0] & (1UL<<AT_EXECFN))
		    && strncmp((char *)aux[AT_EXECFN], "/proc/", 6))
			app->name = (char *)aux[AT_EXECFN];
		else
			app->name = argv[0];
1060
		kernel_mapped_dso(app);
1061 1062 1063
	} else {
		int fd;
		char *ldname = argv[0];
R
Rich Felker 已提交
1064
		size_t l = strlen(ldname);
1065 1066 1067 1068
		if (l >= 3 && !strcmp(ldname+l-3, "ldd")) ldd_mode = 1;
		*argv++ = (void *)-1;
		if (argv[0] && !strcmp(argv[0], "--")) *argv++ = (void *)-1;
		if (!argv[0]) {
1069 1070 1071 1072 1073
			dprintf(2, "musl libc\n"
				"Version %s\n"
				"Dynamic Program Loader\n"
				"Usage: %s [--] pathname%s\n",
				__libc_get_version(), ldname,
1074 1075 1076 1077 1078 1079 1080 1081 1082
				ldd_mode ? "" : " [args]");
			_exit(1);
		}
		fd = open(argv[0], O_RDONLY);
		if (fd < 0) {
			dprintf(2, "%s: cannot load %s: %s\n", ldname, argv[0], strerror(errno));
			_exit(1);
		}
		runtime = 1;
1083
		ehdr = (void *)map_library(fd, app);
1084 1085 1086 1087 1088 1089
		if (!ehdr) {
			dprintf(2, "%s: %s: Not a valid dynamic program\n", ldname, argv[0]);
			_exit(1);
		}
		runtime = 0;
		close(fd);
1090
		lib->name = ldname;
1091
		app->name = argv[0];
1092
		aux[AT_ENTRY] = (size_t)app->base + ehdr->e_entry;
1093 1094 1095 1096 1097 1098 1099 1100 1101 1102
		/* Find the name that would have been used for the dynamic
		 * linker had ldd not taken its place. */
		if (ldd_mode) {
			for (i=0; i<app->phnum; i++) {
				if (app->phdr[i].p_type == PT_INTERP)
					lib->name = (void *)(app->base
						+ app->phdr[i].p_vaddr);
			}
			dprintf(1, "\t%s (%p)\n", lib->name, lib->base);
		}
1103
	}
1104
	if (app->tls_size) {
R
Rich Felker 已提交
1105
		app->tls_id = tls_cnt = 1;
1106 1107 1108 1109 1110 1111
#ifdef TLS_ABOVE_TP
		app->tls_offset = 0;
		tls_offset = app->tls_size
			+ ( -((uintptr_t)app->tls_image + app->tls_size)
			& (app->tls_align-1) );
#else
1112 1113 1114
		tls_offset = app->tls_offset = app->tls_size
			+ ( -((uintptr_t)app->tls_image + app->tls_size)
			& (app->tls_align-1) );
1115
#endif
R
Rich Felker 已提交
1116
		tls_align = MAXP2(tls_align, app->tls_align);
1117
	}
1118 1119 1120 1121
	app->global = 1;
	decode_dyn(app);

	/* Attach to vdso, if provided by the kernel */
R
Rich Felker 已提交
1122
	if (search_vec(auxv, &vdso_base, AT_SYSINFO_EHDR)) {
1123
		ehdr = (void *)vdso_base;
R
Rich Felker 已提交
1124 1125
		vdso->phdr = phdr = (void *)(vdso_base + ehdr->e_phoff);
		vdso->phnum = ehdr->e_phnum;
1126
		vdso->phentsize = ehdr->e_phentsize;
1127 1128 1129 1130 1131 1132
		for (i=ehdr->e_phnum; i; i--, phdr=(void *)((char *)phdr + ehdr->e_phentsize)) {
			if (phdr->p_type == PT_DYNAMIC)
				vdso->dynv = (void *)(vdso_base + phdr->p_offset);
			if (phdr->p_type == PT_LOAD)
				vdso->base = (void *)(vdso_base - phdr->p_vaddr + phdr->p_offset);
		}
1133 1134
		vdso->name = "";
		vdso->shortname = "linux-gate.so.1";
1135
		vdso->global = 1;
1136
		decode_dyn(vdso);
1137 1138 1139 1140
		vdso->prev = lib;
		lib->next = vdso;
	}

1141 1142 1143 1144 1145
	/* Initial dso chain consists only of the app. We temporarily
	 * append the dynamic linker/libc so we can relocate it, then
	 * restore the initial chain in preparation for loading third
	 * party libraries (preload/needed). */
	head = tail = app;
1146
	ldso = lib;
1147 1148 1149
	app->next = lib;
	reloc_all(lib);
	app->next = 0;
R
Rich Felker 已提交
1150

1151
	/* PAST THIS POINT, ALL LIBC INTERFACES ARE FULLY USABLE. */
R
Rich Felker 已提交
1152

1153
	/* Donate unused parts of app and library mapping to malloc */
1154 1155
	reclaim_gaps(app);
	reclaim_gaps(lib);
1156

1157
	/* Load preload/needed libraries, add their symbols to the global
1158 1159 1160
	 * namespace, and perform all remaining relocations. The main
	 * program must be relocated LAST since it may contain copy
	 * relocations which depend on libraries' relocations. */
R
Rich Felker 已提交
1161
	if (env_preload) load_preload(env_preload);
1162 1163
	load_deps(app);
	make_global(app);
1164

T
Timo Teräs 已提交
1165 1166 1167 1168 1169 1170
#ifndef DYNAMIC_IS_RO
	for (i=0; app->dynv[i]; i+=2)
		if (app->dynv[i]==DT_DEBUG)
			app->dynv[i+1] = (size_t)&debug;
#endif

R
Rich Felker 已提交
1171 1172 1173 1174
	reloc_all(app->next);
	reloc_all(app);

	update_tls_size();
1175 1176 1177
	if (libc.tls_size > sizeof builtin_tls) {
		initial_tls = calloc(libc.tls_size, 1);
		if (!initial_tls) {
1178
			dprintf(2, "%s: Error getting %zu bytes thread-local storage: %m\n",
1179
				argv[0], libc.tls_size);
1180 1181
			_exit(127);
		}
1182 1183 1184 1185 1186 1187
	} else {
		initial_tls = builtin_tls;
	}
	if (__init_tp(__copy_tls(initial_tls)) < 0 && tls_cnt) {
		dprintf(2, "%s: Thread-local storage not supported by kernel.\n", argv[0]);
		_exit(127);
1188 1189
	}

1190
	if (ldso_fail) _exit(127);
1191 1192
	if (ldd_mode) _exit(0);

1193 1194 1195 1196
	/* Switch to runtime mode: any further failures in the dynamic
	 * linker are a reportable failure rather than a fatal startup
	 * error. If the dynamic loader (dlopen) will not be used, free
	 * all memory used by the dynamic linker. */
R
Rich Felker 已提交
1197
	runtime = 1;
1198

1199 1200 1201 1202 1203 1204 1205
	debug.ver = 1;
	debug.bp = _dl_debug_state;
	debug.head = head;
	debug.base = lib->base;
	debug.state = 0;
	_dl_debug_state();

1206
	if (ssp_used) __init_ssp((void *)aux[AT_RANDOM]);
1207
	__init_libc(envp, argv[0]);
1208
	atexit(do_fini);
1209
	errno = 0;
1210
	do_init_fini(tail);
1211 1212

	return (void *)aux[AT_ENTRY];
1213 1214
}

1215 1216
void *dlopen(const char *file, int mode)
{
R
Rich Felker 已提交
1217
	struct dso *volatile p, *orig_tail, *next;
R
Rich Felker 已提交
1218
	size_t orig_tls_cnt, orig_tls_offset, orig_tls_align;
1219
	size_t i;
1220
	int cs;
1221
	jmp_buf jb;
1222 1223 1224

	if (!file) return head;

1225
	pthread_setcancelstate(PTHREAD_CANCEL_DISABLE, &cs);
1226
	pthread_rwlock_wrlock(&lock);
1227
	__inhibit_ptc();
1228

1229 1230
	p = 0;
	orig_tls_cnt = tls_cnt;
R
Rich Felker 已提交
1231 1232
	orig_tls_offset = tls_offset;
	orig_tls_align = tls_align;
R
Rich Felker 已提交
1233
	orig_tail = tail;
1234
	noload = mode & RTLD_NOLOAD;
R
Rich Felker 已提交
1235

1236 1237
	rtld_fail = &jb;
	if (setjmp(*rtld_fail)) {
1238
		/* Clean up anything new that was (partially) loaded */
1239
		if (p && p->deps) for (i=0; p->deps[i]; i++)
1240 1241
			if (p->deps[i]->global < 0)
				p->deps[i]->global = 0;
1242 1243 1244 1245 1246 1247
		for (p=orig_tail->next; p; p=next) {
			next = p->next;
			munmap(p->map, p->map_len);
			free(p->deps);
			free(p);
		}
1248
		tls_cnt = orig_tls_cnt;
R
Rich Felker 已提交
1249 1250
		tls_offset = orig_tls_offset;
		tls_align = orig_tls_align;
1251 1252
		tail = orig_tail;
		tail->next = 0;
1253
		p = 0;
1254 1255
		errflag = 1;
		goto end;
1256
	} else p = load_library(file, head);
R
Rich Felker 已提交
1257 1258

	if (!p) {
1259 1260 1261 1262
		snprintf(errbuf, sizeof errbuf, noload ?
			"Library %s is not already loaded" :
			"Error loading shared library %s: %m",
			file);
R
Rich Felker 已提交
1263
		errflag = 1;
1264
		goto end;
1265 1266 1267 1268 1269
	}

	/* First load handling */
	if (!p->deps) {
		load_deps(p);
R
Rich Felker 已提交
1270
		if (p->deps) for (i=0; p->deps[i]; i++)
1271 1272 1273
			if (!p->deps[i]->global)
				p->deps[i]->global = -1;
		if (!p->global) p->global = -1;
1274
		reloc_all(p);
R
Rich Felker 已提交
1275
		if (p->deps) for (i=0; p->deps[i]; i++)
1276 1277 1278
			if (p->deps[i]->global < 0)
				p->deps[i]->global = 0;
		if (p->global < 0) p->global = 0;
1279 1280 1281
	}

	if (mode & RTLD_GLOBAL) {
R
Rich Felker 已提交
1282
		if (p->deps) for (i=0; p->deps[i]; i++)
1283 1284 1285 1286
			p->deps[i]->global = 1;
		p->global = 1;
	}

R
Rich Felker 已提交
1287
	update_tls_size();
1288

1289
	if (ssp_used) __init_ssp(libc.auxv);
1290

1291
	_dl_debug_state();
1292
	orig_tail = tail;
1293
end:
1294
	__release_ptc();
R
Rich Felker 已提交
1295
	if (p) gencnt++;
1296
	pthread_rwlock_unlock(&lock);
1297
	if (p) do_init_fini(orig_tail);
1298
	pthread_setcancelstate(cs, 0);
1299 1300 1301
	return p;
}

1302
static int invalid_dso_handle(void *h)
1303 1304 1305 1306 1307 1308 1309 1310
{
	struct dso *p;
	for (p=head; p; p=p->next) if (h==p) return 0;
	snprintf(errbuf, sizeof errbuf, "Invalid library handle %p", (void *)h);
	errflag = 1;
	return 1;
}

R
Rich Felker 已提交
1311
static void *do_dlsym(struct dso *p, const char *s, void *ra)
1312 1313
{
	size_t i;
1314
	uint32_t h = 0, gh = 0;
1315
	Sym *sym;
1316
	if (p == head || p == RTLD_DEFAULT || p == RTLD_NEXT) {
1317 1318 1319
		if (p == RTLD_DEFAULT) {
			p = head;
		} else if (p == RTLD_NEXT) {
1320 1321
			for (p=head; p && (unsigned char *)ra-p->map>p->map_len; p=p->next);
			if (!p) p=head;
1322
			p = p->next;
1323
		}
1324
		struct symdef def = find_sym(p, s, 0);
1325
		if (!def.sym) goto failed;
1326 1327
		if ((def.sym->st_info&0xf) == STT_TLS)
			return __tls_get_addr((size_t []){def.dso->tls_id, def.sym->st_value});
1328
		return def.dso->base + def.sym->st_value;
R
Rich Felker 已提交
1329
	}
1330 1331
	if (p != RTLD_DEFAULT && p != RTLD_NEXT && invalid_dso_handle(p))
		return 0;
1332 1333 1334 1335 1336 1337 1338
	if (p->ghashtab) {
		gh = gnu_hash(s);
		sym = gnu_lookup(s, gh, p);
	} else {
		h = sysv_hash(s);
		sym = sysv_lookup(s, h, p);
	}
1339 1340
	if (sym && (sym->st_info&0xf) == STT_TLS)
		return __tls_get_addr((size_t []){p->tls_id, sym->st_value});
1341 1342 1343
	if (sym && sym->st_value && (1<<(sym->st_info&0xf) & OK_TYPES))
		return p->base + sym->st_value;
	if (p->deps) for (i=0; p->deps[i]; i++) {
1344 1345
		if (p->deps[i]->ghashtab) {
			if (!gh) gh = gnu_hash(s);
1346
			sym = gnu_lookup(s, gh, p->deps[i]);
1347 1348 1349 1350
		} else {
			if (!h) h = sysv_hash(s);
			sym = sysv_lookup(s, h, p->deps[i]);
		}
1351 1352
		if (sym && (sym->st_info&0xf) == STT_TLS)
			return __tls_get_addr((size_t []){p->deps[i]->tls_id, sym->st_value});
1353 1354 1355
		if (sym && sym->st_value && (1<<(sym->st_info&0xf) & OK_TYPES))
			return p->deps[i]->base + sym->st_value;
	}
1356
failed:
R
Rich Felker 已提交
1357
	errflag = 1;
1358
	snprintf(errbuf, sizeof errbuf, "Symbol not found: %s", s);
1359 1360 1361
	return 0;
}

1362
int __dladdr(const void *addr, Dl_info *info)
1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386
{
	struct dso *p;
	Sym *sym;
	uint32_t nsym;
	char *strings;
	size_t i;
	void *best = 0;
	char *bestname;

	pthread_rwlock_rdlock(&lock);
	for (p=head; p && (unsigned char *)addr-p->map>p->map_len; p=p->next);
	pthread_rwlock_unlock(&lock);

	if (!p) return 0;

	sym = p->syms;
	strings = p->strings;
	if (p->hashtab) {
		nsym = p->hashtab[1];
	} else {
		uint32_t *buckets;
		uint32_t *hashval;
		buckets = p->ghashtab + 4 + (p->ghashtab[2]*sizeof(size_t)/4);
		sym += p->ghashtab[1];
R
Rich Felker 已提交
1387
		for (i = nsym = 0; i < p->ghashtab[0]; i++) {
1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399
			if (buckets[i] > nsym)
				nsym = buckets[i];
		}
		if (nsym) {
			nsym -= p->ghashtab[1];
			hashval = buckets + p->ghashtab[0] + nsym;
			do nsym++;
			while (!(*hashval++ & 1));
		}
	}

	for (; nsym; nsym--, sym++) {
1400
		if (sym->st_value
1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422
		 && (1<<(sym->st_info&0xf) & OK_TYPES)
		 && (1<<(sym->st_info>>4) & OK_BINDS)) {
			void *symaddr = p->base + sym->st_value;
			if (symaddr > addr || symaddr < best)
				continue;
			best = symaddr;
			bestname = strings + sym->st_name;
			if (addr == symaddr)
				break;
		}
	}

	if (!best) return 0;

	info->dli_fname = p->name;
	info->dli_fbase = p->base;
	info->dli_sname = bestname;
	info->dli_saddr = best;

	return 1;
}

1423
void *__dlsym(void *restrict p, const char *restrict s, void *restrict ra)
1424 1425 1426
{
	void *res;
	pthread_rwlock_rdlock(&lock);
R
Rich Felker 已提交
1427
	res = do_dlsym(p, s, ra);
1428 1429 1430
	pthread_rwlock_unlock(&lock);
	return res;
}
R
Rich Felker 已提交
1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456

int dl_iterate_phdr(int(*callback)(struct dl_phdr_info *info, size_t size, void *data), void *data)
{
	struct dso *current;
	struct dl_phdr_info info;
	int ret = 0;
	for(current = head; current;) {
		info.dlpi_addr      = (uintptr_t)current->base;
		info.dlpi_name      = current->name;
		info.dlpi_phdr      = current->phdr;
		info.dlpi_phnum     = current->phnum;
		info.dlpi_adds      = gencnt;
		info.dlpi_subs      = 0;
		info.dlpi_tls_modid = current->tls_id;
		info.dlpi_tls_data  = current->tls_image;

		ret = (callback)(&info, sizeof (info), data);

		if (ret != 0) break;

		pthread_rwlock_rdlock(&lock);
		current = current->next;
		pthread_rwlock_unlock(&lock);
	}
	return ret;
}
1457
#else
1458
static int invalid_dso_handle(void *h)
1459 1460 1461 1462 1463
{
	snprintf(errbuf, sizeof errbuf, "Invalid library handle %p", (void *)h);
	errflag = 1;
	return 1;
}
1464 1465 1466 1467
void *dlopen(const char *file, int mode)
{
	return 0;
}
1468
void *__dlsym(void *restrict p, const char *restrict s, void *restrict ra)
1469 1470 1471
{
	return 0;
}
1472
int __dladdr (const void *addr, Dl_info *info)
1473 1474 1475
{
	return 0;
}
1476
#endif
1477

R
Rich Felker 已提交
1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489
int __dlinfo(void *dso, int req, void *res)
{
	if (invalid_dso_handle(dso)) return -1;
	if (req != RTLD_DI_LINKMAP) {
		snprintf(errbuf, sizeof errbuf, "Unsupported request %d", req);
		errflag = 1;
		return -1;
	}
	*(struct link_map **)res = dso;
	return 0;
}

1490 1491
char *dlerror()
{
R
Rich Felker 已提交
1492 1493
	if (!errflag) return 0;
	errflag = 0;
1494
	return errbuf;
1495 1496 1497 1498
}

int dlclose(void *p)
{
1499
	return invalid_dso_handle(p);
1500
}