dynlink.c 27.3 KB
Newer Older
1
#define _GNU_SOURCE
R
Rich Felker 已提交
2 3 4 5 6 7 8 9 10 11 12 13 14 15
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <stdint.h>
#include <elf.h>
#include <sys/mman.h>
#include <limits.h>
#include <stdint.h>
#include <fcntl.h>
#include <sys/stat.h>
#include <errno.h>
#include <limits.h>
#include <elf.h>
R
Rich Felker 已提交
16
#include <setjmp.h>
17
#include <pthread.h>
R
Rich Felker 已提交
18
#include <ctype.h>
19
#include <dlfcn.h>
20 21 22
#include "pthread_impl.h"
#include "libc.h"
#undef libc
R
Rich Felker 已提交
23

R
Rich Felker 已提交
24
static int errflag;
25
static char errbuf[128];
R
Rich Felker 已提交
26

27
#ifdef SHARED
R
Rich Felker 已提交
28

R
Rich Felker 已提交
29 30 31 32 33 34 35 36 37 38 39 40 41 42
#if ULONG_MAX == 0xffffffff
typedef Elf32_Ehdr Ehdr;
typedef Elf32_Phdr Phdr;
typedef Elf32_Sym Sym;
#define R_TYPE(x) ((x)&255)
#define R_SYM(x) ((x)>>8)
#else
typedef Elf64_Ehdr Ehdr;
typedef Elf64_Phdr Phdr;
typedef Elf64_Sym Sym;
#define R_TYPE(x) ((x)&0xffffffff)
#define R_SYM(x) ((x)>>32)
#endif

43 44 45 46 47 48 49 50 51 52 53 54
struct debug {
	int ver;
	void *head;
	void (*bp)(void);
	int state;
	void *base;
};

struct dso {
	unsigned char *base;
	char *name;
	size_t *dynv;
R
Rich Felker 已提交
55
	struct dso *next, *prev;
56

R
Rich Felker 已提交
57 58
	int refcnt;
	Sym *syms;
59
	uint32_t *hashtab;
60
	uint32_t *ghashtab;
R
Rich Felker 已提交
61 62 63 64 65
	char *strings;
	unsigned char *map;
	size_t map_len;
	dev_t dev;
	ino_t ino;
66
	signed char global;
67 68
	char relocated;
	char constructed;
69
	struct dso **deps;
70
	void *tls_image;
71
	size_t tls_len, tls_size, tls_align, tls_id, tls_offset;
72
	char *shortname;
R
Rich Felker 已提交
73
	char buf[];
R
Rich Felker 已提交
74 75
};

76 77 78 79 80
struct symdef {
	Sym *sym;
	struct dso *dso;
};

81 82
#include "reloc.h"

83
void __init_ssp(size_t *);
84
void *__install_initial_tls(void *);
85

R
Rich Felker 已提交
86
static struct dso *head, *tail, *libc;
87
static char *env_path, *sys_path, *r_path;
88
static int ssp_used;
R
Rich Felker 已提交
89
static int runtime;
90
static int ldd_mode;
91
static int ldso_fail;
R
Rich Felker 已提交
92
static jmp_buf rtld_fail;
93
static pthread_rwlock_t lock;
94
static struct debug debug;
95
static size_t *auxv;
96
static size_t tls_cnt, tls_size;
97 98

struct debug *_dl_debug_addr = &debug;
R
Rich Felker 已提交
99

R
Rich Felker 已提交
100
#define AUX_CNT 24
R
Rich Felker 已提交
101 102 103 104 105 106 107 108 109 110 111
#define DYN_CNT 34

static void decode_vec(size_t *v, size_t *a, size_t cnt)
{
	memset(a, 0, cnt*sizeof(size_t));
	for (; v[0]; v+=2) if (v[0]<cnt) {
		a[0] |= 1ULL<<v[0];
		a[v[0]] = v[1];
	}
}

112 113 114 115 116 117 118 119 120
static int search_vec(size_t *v, size_t *r, size_t key)
{
	for (; v[0]!=key; v+=2)
		if (!v[0]) return 0;
	*r = v[1];
	return 1;
}

static uint32_t sysv_hash(const char *s0)
R
Rich Felker 已提交
121
{
122
	const unsigned char *s = (void *)s0;
R
Rich Felker 已提交
123 124 125 126 127 128 129 130
	uint_fast32_t h = 0;
	while (*s) {
		h = 16*h + *s++;
		h ^= h>>24 & 0xf0;
	}
	return h & 0xfffffff;
}

131 132 133 134 135 136 137 138 139 140
static uint32_t gnu_hash(const char *s0)
{
	const unsigned char *s = (void *)s0;
	uint_fast32_t h = 5381;
	for (; *s; s++)
		h = h*33 + *s;
	return h;
}

static Sym *sysv_lookup(const char *s, uint32_t h, struct dso *dso)
R
Rich Felker 已提交
141 142
{
	size_t i;
R
Rich Felker 已提交
143 144 145
	Sym *syms = dso->syms;
	uint32_t *hashtab = dso->hashtab;
	char *strings = dso->strings;
R
Rich Felker 已提交
146 147 148 149 150 151 152
	for (i=hashtab[2+h%hashtab[0]]; i; i=hashtab[2+hashtab[0]+i]) {
		if (!strcmp(s, strings+syms[i].st_name))
			return syms+i;
	}
	return 0;
}

153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179
static Sym *gnu_lookup(const char *s, uint32_t h1, struct dso *dso)
{
	Sym *sym;
	char *strings;
	uint32_t *hashtab = dso->ghashtab;
	uint32_t nbuckets = hashtab[0];
	uint32_t *buckets = hashtab + 4 + hashtab[2]*(sizeof(size_t)/4);
	uint32_t h2;
	uint32_t *hashval;
	uint32_t n = buckets[h1 % nbuckets];

	if (!n) return 0;

	strings = dso->strings;
	sym = dso->syms + n;
	hashval = buckets + nbuckets + (n - hashtab[1]);

	for (h1 |= 1; ; sym++) {
		h2 = *hashval++;
		if ((h1 == (h2|1)) && !strcmp(s, strings + sym->st_name))
			return sym;
		if (h2 & 1) break;
	}

	return 0;
}

180
#define OK_TYPES (1<<STT_NOTYPE | 1<<STT_OBJECT | 1<<STT_FUNC | 1<<STT_COMMON | 1<<STT_TLS)
181
#define OK_BINDS (1<<STB_GLOBAL | 1<<STB_WEAK)
R
Rich Felker 已提交
182

183
static struct symdef find_sym(struct dso *dso, const char *s, int need_def)
R
Rich Felker 已提交
184
{
185
	uint32_t h = 0, gh = 0;
186
	struct symdef def = {0};
187 188 189 190 191 192 193
	if (dso->ghashtab) {
		gh = gnu_hash(s);
		if (gh == 0x1f4039c9 && !strcmp(s, "__stack_chk_fail")) ssp_used = 1;
	} else {
		h = sysv_hash(s);
		if (h == 0x595a4cc && !strcmp(s, "__stack_chk_fail")) ssp_used = 1;
	}
R
Rich Felker 已提交
194
	for (; dso; dso=dso->next) {
195 196
		Sym *sym;
		if (!dso->global) continue;
197 198 199 200 201 202 203
		if (dso->ghashtab) {
			if (!gh) gh = gnu_hash(s);
			sym = gnu_lookup(s, gh, dso);
		} else {
			if (!h) h = sysv_hash(s);
			sym = sysv_lookup(s, h, dso);
		}
R
Rich Felker 已提交
204
		if (sym && (!need_def || sym->st_shndx) && sym->st_value
205 206
		 && (1<<(sym->st_info&0xf) & OK_TYPES)
		 && (1<<(sym->st_info>>4) & OK_BINDS)) {
207 208 209
			if (def.sym && sym->st_info>>4 == STB_WEAK) continue;
			def.sym = sym;
			def.dso = dso;
210 211
			if (sym->st_info>>4 == STB_GLOBAL) break;
		}
R
Rich Felker 已提交
212
	}
213
	return def;
R
Rich Felker 已提交
214 215
}

216
static void do_relocs(struct dso *dso, size_t *rel, size_t rel_size, size_t stride)
R
Rich Felker 已提交
217
{
218 219 220
	unsigned char *base = dso->base;
	Sym *syms = dso->syms;
	char *strings = dso->strings;
R
Rich Felker 已提交
221 222 223 224 225
	Sym *sym;
	const char *name;
	void *ctx;
	int type;
	int sym_index;
226
	struct symdef def;
R
Rich Felker 已提交
227 228 229 230 231 232 233

	for (; rel_size; rel+=stride, rel_size-=stride*sizeof(size_t)) {
		type = R_TYPE(rel[1]);
		sym_index = R_SYM(rel[1]);
		if (sym_index) {
			sym = syms + sym_index;
			name = strings + sym->st_name;
234
			ctx = IS_COPY(type) ? head->next : head;
235 236
			def = find_sym(ctx, name, IS_PLT(type));
			if (!def.sym && sym->st_info>>4 != STB_WEAK) {
237 238
				snprintf(errbuf, sizeof errbuf,
					"Error relocating %s: %s: symbol not found",
239
					dso->name, name);
R
Rich Felker 已提交
240
				if (runtime) longjmp(rtld_fail, 1);
241
				dprintf(2, "%s\n", errbuf);
242 243
				ldso_fail = 1;
				continue;
R
Rich Felker 已提交
244
			}
245
		} else {
246 247 248
			sym = 0;
			def.sym = 0;
			def.dso = 0;
R
Rich Felker 已提交
249
		}
250 251 252
		do_single_reloc(dso, base, (void *)(base + rel[0]), type,
			stride>2 ? rel[2] : 0, sym, sym?sym->st_size:0, def,
			def.sym?(size_t)(def.dso->base+def.sym->st_value):0);
R
Rich Felker 已提交
253 254 255
	}
}

256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286
/* A huge hack: to make up for the wastefulness of shared libraries
 * needing at least a page of dirty memory even if they have no global
 * data, we reclaim the gaps at the beginning and end of writable maps
 * and "donate" them to the heap by setting up minimal malloc
 * structures and then freeing them. */

static void reclaim(unsigned char *base, size_t start, size_t end)
{
	size_t *a, *z;
	start = start + 6*sizeof(size_t)-1 & -4*sizeof(size_t);
	end = (end & -4*sizeof(size_t)) - 2*sizeof(size_t);
	if (start>end || end-start < 4*sizeof(size_t)) return;
	a = (size_t *)(base + start);
	z = (size_t *)(base + end);
	a[-2] = 1;
	a[-1] = z[0] = end-start + 2*sizeof(size_t) | 1;
	z[1] = 1;
	free(a);
}

static void reclaim_gaps(unsigned char *base, Phdr *ph, size_t phent, size_t phcnt)
{
	for (; phcnt--; ph=(void *)((char *)ph+phent)) {
		if (ph->p_type!=PT_LOAD) continue;
		if ((ph->p_flags&(PF_R|PF_W))!=(PF_R|PF_W)) continue;
		reclaim(base, ph->p_vaddr & -PAGE_SIZE, ph->p_vaddr);
		reclaim(base, ph->p_vaddr+ph->p_memsz,
			ph->p_vaddr+ph->p_memsz+PAGE_SIZE-1 & -PAGE_SIZE);
	}
}

287
static void *map_library(int fd, struct dso *dso)
R
Rich Felker 已提交
288
{
289
	Ehdr buf[(896+sizeof(Ehdr))/sizeof(Ehdr)];
R
Rich Felker 已提交
290 291 292 293 294 295 296 297 298
	size_t phsize;
	size_t addr_min=SIZE_MAX, addr_max=0, map_len;
	size_t this_min, this_max;
	off_t off_start;
	Ehdr *eh;
	Phdr *ph;
	unsigned prot;
	unsigned char *map, *base;
	size_t dyn;
299
	size_t tls_image=0;
R
Rich Felker 已提交
300 301 302 303
	size_t i;

	ssize_t l = read(fd, buf, sizeof buf);
	if (l<sizeof *eh) return 0;
304
	eh = buf;
R
Rich Felker 已提交
305 306 307
	phsize = eh->e_phentsize * eh->e_phnum;
	if (phsize + sizeof *eh > l) return 0;
	if (eh->e_phoff + phsize > l) {
308
		l = pread(fd, buf+1, phsize, eh->e_phoff);
R
Rich Felker 已提交
309 310 311 312 313 314 315
		if (l != phsize) return 0;
		eh->e_phoff = sizeof *eh;
	}
	ph = (void *)((char *)buf + eh->e_phoff);
	for (i=eh->e_phnum; i; i--, ph=(void *)((char *)ph+eh->e_phentsize)) {
		if (ph->p_type == PT_DYNAMIC)
			dyn = ph->p_vaddr;
316 317 318 319 320 321
		if (ph->p_type == PT_TLS) {
			tls_image = ph->p_vaddr;
			dso->tls_align = ph->p_align;
			dso->tls_len = ph->p_filesz;
			dso->tls_size = ph->p_memsz;
		}
R
Rich Felker 已提交
322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343
		if (ph->p_type != PT_LOAD) continue;
		if (ph->p_vaddr < addr_min) {
			addr_min = ph->p_vaddr;
			off_start = ph->p_offset;
			prot = (((ph->p_flags&PF_R) ? PROT_READ : 0) |
				((ph->p_flags&PF_W) ? PROT_WRITE: 0) |
				((ph->p_flags&PF_X) ? PROT_EXEC : 0));
		}
		if (ph->p_vaddr+ph->p_memsz > addr_max) {
			addr_max = ph->p_vaddr+ph->p_memsz;
		}
	}
	if (!dyn) return 0;
	addr_max += PAGE_SIZE-1;
	addr_max &= -PAGE_SIZE;
	addr_min &= -PAGE_SIZE;
	off_start &= -PAGE_SIZE;
	map_len = addr_max - addr_min + off_start;
	/* The first time, we map too much, possibly even more than
	 * the length of the file. This is okay because we will not
	 * use the invalid part; we just need to reserve the right
	 * amount of virtual address space to map over later. */
344
	map = mmap((void *)addr_min, map_len, prot, MAP_PRIVATE, fd, off_start);
R
Rich Felker 已提交
345 346 347 348 349 350 351 352 353 354 355 356 357
	if (map==MAP_FAILED) return 0;
	base = map - addr_min;
	ph = (void *)((char *)buf + eh->e_phoff);
	for (i=eh->e_phnum; i; i--, ph=(void *)((char *)ph+eh->e_phentsize)) {
		if (ph->p_type != PT_LOAD) continue;
		/* Reuse the existing mapping for the lowest-address LOAD */
		if ((ph->p_vaddr & -PAGE_SIZE) == addr_min) continue;
		this_min = ph->p_vaddr & -PAGE_SIZE;
		this_max = ph->p_vaddr+ph->p_memsz+PAGE_SIZE-1 & -PAGE_SIZE;
		off_start = ph->p_offset & -PAGE_SIZE;
		prot = (((ph->p_flags&PF_R) ? PROT_READ : 0) |
			((ph->p_flags&PF_W) ? PROT_WRITE: 0) |
			((ph->p_flags&PF_X) ? PROT_EXEC : 0));
358 359
		if (mmap(base+this_min, this_max-this_min, prot, MAP_PRIVATE|MAP_FIXED, fd, off_start) == MAP_FAILED)
			goto error;
R
Rich Felker 已提交
360 361 362 363
		if (ph->p_memsz > ph->p_filesz) {
			size_t brk = (size_t)base+ph->p_vaddr+ph->p_filesz;
			size_t pgbrk = brk+PAGE_SIZE-1 & -PAGE_SIZE;
			memset((void *)brk, 0, pgbrk-brk & PAGE_SIZE-1);
364 365
			if (pgbrk-(size_t)base < this_max && mmap((void *)pgbrk, (size_t)base+this_max-pgbrk, prot, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) == MAP_FAILED)
				goto error;
R
Rich Felker 已提交
366 367
		}
	}
R
Rich Felker 已提交
368 369
	for (i=0; ((size_t *)(base+dyn))[i]; i+=2)
		if (((size_t *)(base+dyn))[i]==DT_TEXTREL) {
370 371
			if (mprotect(map, map_len, PROT_READ|PROT_WRITE|PROT_EXEC) < 0)
				goto error;
R
Rich Felker 已提交
372 373
			break;
		}
374 375
	if (!runtime) reclaim_gaps(base, (void *)((char *)buf + eh->e_phoff),
		eh->e_phentsize, eh->e_phnum);
376 377 378 379 380
	dso->map = map;
	dso->map_len = map_len;
	dso->base = base;
	dso->dynv = (void *)(base+dyn);
	if (dso->tls_size) dso->tls_image = (void *)(base+tls_image);
R
Rich Felker 已提交
381
	return map;
382 383 384
error:
	munmap(map, map_len);
	return 0;
R
Rich Felker 已提交
385 386
}

387
static int path_open(const char *name, const char *search, char *buf, size_t buf_size)
388
{
389
	const char *s=search, *z;
390
	int l, fd;
391 392 393
	for (;;) {
		while (*s==':') s++;
		if (!*s) return -1;
394 395
		z = strchr(s, ':');
		l = z ? z-s : strlen(s);
396
		snprintf(buf, buf_size, "%.*s/%s", l, s, name);
397
		if ((fd = open(buf, O_RDONLY|O_CLOEXEC))>=0) return fd;
398
		s += l;
399 400 401
	}
}

402 403 404 405 406 407
static void decode_dyn(struct dso *p)
{
	size_t dyn[DYN_CNT] = {0};
	decode_vec(p->dynv, dyn, DYN_CNT);
	p->syms = (void *)(p->base + dyn[DT_SYMTAB]);
	p->strings = (void *)(p->base + dyn[DT_STRTAB]);
408 409 410 411
	if (dyn[0]&(1<<DT_HASH))
		p->hashtab = (void *)(p->base + dyn[DT_HASH]);
	if (search_vec(p->dynv, dyn, DT_GNU_HASH))
		p->ghashtab = (void *)(p->base + *dyn);
412 413
}

R
Rich Felker 已提交
414 415
static struct dso *load_library(const char *name)
{
416
	char buf[2*NAME_MAX+2];
417
	const char *pathname;
R
Rich Felker 已提交
418 419
	unsigned char *base, *map;
	size_t dyno, map_len;
420
	struct dso *p, temp_dso = {0};
R
Rich Felker 已提交
421 422 423 424 425 426 427 428 429 430 431 432 433 434 435
	int fd;
	struct stat st;

	/* Catch and block attempts to reload the implementation itself */
	if (name[0]=='l' && name[1]=='i' && name[2]=='b') {
		static const char *rp, reserved[] =
			"c\0pthread\0rt\0m\0dl\0util\0xnet\0";
		char *z = strchr(name, '.');
		if (z) {
			size_t l = z-name;
			for (rp=reserved; *rp && memcmp(name+3, rp, l-3); rp+=strlen(rp)+1);
			if (*rp) {
				if (!libc->prev) {
					tail->next = libc;
					libc->prev = tail;
436
					tail = libc->next ? libc->next : libc;
R
Rich Felker 已提交
437 438 439 440 441
				}
				return libc;
			}
		}
	}
442
	if (strchr(name, '/')) {
443
		pathname = name;
444
		fd = open(name, O_RDONLY|O_CLOEXEC);
R
Rich Felker 已提交
445
	} else {
446 447 448 449 450 451 452
		/* Search for the name to see if it's already loaded */
		for (p=head->next; p; p=p->next) {
			if (p->shortname && !strcmp(p->shortname, name)) {
				p->refcnt++;
				return p;
			}
		}
453
		if (strlen(name) > NAME_MAX) return 0;
454
		fd = -1;
455 456
		if (r_path) fd = path_open(name, r_path, buf, sizeof buf);
		if (fd < 0 && env_path) fd = path_open(name, env_path, buf, sizeof buf);
457 458
		if (fd < 0) {
			if (!sys_path) {
459
				FILE *f = fopen(ETC_LDSO_PATH, "rbe");
460 461 462 463 464 465
				if (f) {
					if (getline(&sys_path, (size_t[1]){0}, f) > 0)
						sys_path[strlen(sys_path)-1]=0;
					fclose(f);
				}
			}
466 467
			if (sys_path) fd = path_open(name, sys_path, buf, sizeof buf);
			else fd = path_open(name, "/lib:/usr/local/lib:/usr/lib", buf, sizeof buf);
R
Rich Felker 已提交
468
		}
469
		pathname = buf;
R
Rich Felker 已提交
470 471 472 473 474 475 476 477
	}
	if (fd < 0) return 0;
	if (fstat(fd, &st) < 0) {
		close(fd);
		return 0;
	}
	for (p=head->next; p; p=p->next) {
		if (p->dev == st.st_dev && p->ino == st.st_ino) {
478 479 480 481
			/* If this library was previously loaded with a
			 * pathname but a search found the same inode,
			 * setup its shortname so it can be found by name. */
			if (!p->shortname) p->shortname = strrchr(p->name, '/')+1;
R
Rich Felker 已提交
482 483 484 485 486
			close(fd);
			p->refcnt++;
			return p;
		}
	}
487
	map = map_library(fd, &temp_dso);
R
Rich Felker 已提交
488 489
	close(fd);
	if (!map) return 0;
490
	p = malloc(sizeof *p + strlen(pathname) + 1);
R
Rich Felker 已提交
491 492 493 494
	if (!p) {
		munmap(map, map_len);
		return 0;
	}
495
	memcpy(p, &temp_dso, sizeof temp_dso);
496
	decode_dyn(p);
497 498 499 500 501
	if (p->tls_image) {
		p->tls_id = ++tls_cnt;
		tls_size += p->tls_size + p->tls_align + 8*sizeof(size_t) - 1
			& -4*sizeof(size_t);
	}
R
Rich Felker 已提交
502 503 504
	p->dev = st.st_dev;
	p->ino = st.st_ino;
	p->refcnt = 1;
R
Rich Felker 已提交
505
	p->name = p->buf;
506 507 508
	strcpy(p->name, pathname);
	/* Add a shortname only if name arg was not an explicit pathname. */
	if (pathname != name) p->shortname = strrchr(p->name, '/')+1;
R
Rich Felker 已提交
509 510 511 512 513

	tail->next = p;
	p->prev = tail;
	tail = p;

514
	if (ldd_mode) dprintf(1, "\t%s => %s (%p)\n", name, pathname, base);
515

R
Rich Felker 已提交
516 517 518 519 520
	return p;
}

static void load_deps(struct dso *p)
{
521 522
	size_t i, ndeps=0;
	struct dso ***deps = &p->deps, **tmp, *dep;
R
Rich Felker 已提交
523
	for (; p; p=p->next) {
524 525 526 527
		for (i=0; p->dynv[i]; i+=2) {
			if (p->dynv[i] != DT_RPATH) continue;
			r_path = (void *)(p->strings + p->dynv[i+1]);
		}
R
Rich Felker 已提交
528 529
		for (i=0; p->dynv[i]; i+=2) {
			if (p->dynv[i] != DT_NEEDED) continue;
530 531
			dep = load_library(p->strings + p->dynv[i+1]);
			if (!dep) {
532 533
				snprintf(errbuf, sizeof errbuf,
					"Error loading shared library %s: %m (needed by %s)",
R
Rich Felker 已提交
534
					p->strings + p->dynv[i+1], p->name);
535 536
				if (runtime) longjmp(rtld_fail, 1);
				dprintf(2, "%s\n", errbuf);
537 538
				ldso_fail = 1;
				continue;
R
Rich Felker 已提交
539
			}
540 541 542 543 544 545 546
			if (runtime) {
				tmp = realloc(*deps, sizeof(*tmp)*(ndeps+2));
				if (!tmp) longjmp(rtld_fail, 1);
				tmp[ndeps++] = dep;
				tmp[ndeps] = 0;
				*deps = tmp;
			}
R
Rich Felker 已提交
547
		}
548
		r_path = 0;
R
Rich Felker 已提交
549 550 551
	}
}

R
Rich Felker 已提交
552 553 554 555 556 557 558 559 560 561 562 563 564 565
static void load_preload(char *s)
{
	int tmp;
	char *z;
	for (z=s; *z; s=z) {
		for (   ; *s && isspace(*s); s++);
		for (z=s; *z && !isspace(*z); z++);
		tmp = *z;
		*z = 0;
		load_library(s);
		*z = tmp;
	}
}

566 567 568 569 570
static void make_global(struct dso *p)
{
	for (; p; p=p->next) p->global = 1;
}

R
Rich Felker 已提交
571 572 573 574 575 576
static void reloc_all(struct dso *p)
{
	size_t dyn[DYN_CNT] = {0};
	for (; p; p=p->next) {
		if (p->relocated) continue;
		decode_vec(p->dynv, dyn, DYN_CNT);
R
Rich Felker 已提交
577 578 579
#ifdef NEED_ARCH_RELOCS
		do_arch_relocs(p, head);
#endif
580 581 582 583
		do_relocs(p, (void *)(p->base+dyn[DT_JMPREL]), dyn[DT_PLTRELSZ],
			2+(dyn[DT_PLTREL]==DT_RELA));
		do_relocs(p, (void *)(p->base+dyn[DT_REL]), dyn[DT_RELSZ], 2);
		do_relocs(p, (void *)(p->base+dyn[DT_RELA]), dyn[DT_RELASZ], 3);
584
		p->relocated = 1;
R
Rich Felker 已提交
585 586 587
	}
}

588 589 590 591 592
static void free_all(struct dso *p)
{
	struct dso *n;
	while (p) {
		n = p->next;
593
		if (p->map && p!=libc && p!=head) free(p);
594 595 596 597
		p = n;
	}
}

598 599 600 601 602 603 604 605
static size_t find_dyn(Phdr *ph, size_t cnt, size_t stride)
{
	for (; cnt--; ph = (void *)((char *)ph + stride))
		if (ph->p_type == PT_DYNAMIC)
			return ph->p_vaddr;
	return 0;
}

606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621
static void find_map_range(Phdr *ph, size_t cnt, size_t stride, struct dso *p)
{
	size_t min_addr = -1, max_addr = 0;
	for (; cnt--; ph = (void *)((char *)ph + stride)) {
		if (ph->p_type != PT_LOAD) continue;
		if (ph->p_vaddr < min_addr)
			min_addr = ph->p_vaddr;
		if (ph->p_vaddr+ph->p_memsz > max_addr)
			max_addr = ph->p_vaddr+ph->p_memsz;
	}
	min_addr &= -PAGE_SIZE;
	max_addr = (max_addr + PAGE_SIZE-1) & -PAGE_SIZE;
	p->map = p->base + min_addr;
	p->map_len = max_addr - min_addr;
}

622 623 624 625 626 627 628 629 630 631 632 633 634 635
static void do_init_fini(struct dso *p)
{
	size_t dyn[DYN_CNT] = {0};
	for (; p; p=p->prev) {
		if (p->constructed) return;
		decode_vec(p->dynv, dyn, DYN_CNT);
		if (dyn[0] & (1<<DT_FINI))
			atexit((void (*)(void))(p->base + dyn[DT_FINI]));
		if (dyn[0] & (1<<DT_INIT))
			((void (*)(void))(p->base + dyn[DT_INIT]))();
		p->constructed = 1;
	}
}

636 637 638 639
void _dl_debug_state(void)
{
}

640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658
void *__copy_tls(unsigned char *mem, size_t cnt)
{
	struct dso *p;
	void **dtv = (void *)mem;
	dtv[0] = (void *)cnt;
	mem = (void *)(dtv + cnt + 1);
	for (p=tail; p; p=p->prev) {
		if (p->tls_id-1 >= cnt) continue;
		mem += -p->tls_len & (4*sizeof(size_t)-1);
		mem += ((uintptr_t)p->tls_image - (uintptr_t)mem)
			& (p->tls_align-1);
		dtv[p->tls_id] = mem;
		memcpy(mem, p->tls_image, p->tls_len);
		mem += p->tls_size;
	}
	((pthread_t)mem)->dtv = dtv;
	return mem;
}

659 660 661 662 663 664 665 666 667 668
void *__tls_get_addr(size_t *p)
{
	pthread_t self = __pthread_self();
	if ((size_t)self->dtv[0] < p[0]) {
		// FIXME: obtain new DTV and TLS from the DSO
		a_crash();
	}
	return (char *)self->dtv[p[0]] + p[1];
}

669
void *__dynlink(int argc, char **argv)
R
Rich Felker 已提交
670
{
671
	size_t aux[AUX_CNT] = {0};
R
Rich Felker 已提交
672 673
	size_t i;
	Phdr *phdr;
674
	Ehdr *ehdr;
675
	static struct dso builtin_dsos[3];
R
Rich Felker 已提交
676 677
	struct dso *const app = builtin_dsos+0;
	struct dso *const lib = builtin_dsos+1;
678
	struct dso *const vdso = builtin_dsos+2;
R
Rich Felker 已提交
679
	char *env_preload=0;
R
Rich Felker 已提交
680
	size_t vdso_base;
R
Rich Felker 已提交
681 682

	/* Find aux vector just past environ[] */
683 684 685
	for (i=argc+1; argv[i]; i++)
		if (!memcmp(argv[i], "LD_LIBRARY_PATH=", 16))
			env_path = argv[i]+16;
R
Rich Felker 已提交
686 687
		else if (!memcmp(argv[i], "LD_PRELOAD=", 11))
			env_preload = argv[i]+11;
R
Rich Felker 已提交
688 689 690 691
	auxv = (void *)(argv+i+1);

	decode_vec(auxv, aux, AUX_CNT);

692 693
	/* Only trust user/env if kernel says we're not suid/sgid */
	if ((aux[0]&0x7800)!=0x7800 || aux[AT_UID]!=aux[AT_EUID]
R
Rich Felker 已提交
694
	  || aux[AT_GID]!=aux[AT_EGID] || aux[AT_SECURE]) {
695
		env_path = 0;
R
Rich Felker 已提交
696
		env_preload = 0;
697 698
	}

699 700 701 702 703 704 705 706 707
	/* If the dynamic linker was invoked as a program itself, AT_BASE
	 * will not be set. In that case, we assume the base address is
	 * the start of the page containing the PHDRs; I don't know any
	 * better approach... */
	if (!aux[AT_BASE]) {
		aux[AT_BASE] = aux[AT_PHDR] & -PAGE_SIZE;
		aux[AT_PHDR] = aux[AT_PHENT] = aux[AT_PHNUM] = 0;
	}

708 709 710
	/* The dynamic linker load address is passed by the kernel
	 * in the AUX vector, so this is easy. */
	lib->base = (void *)aux[AT_BASE];
711
	lib->name = lib->shortname = "libc.so";
712 713
	lib->global = 1;
	ehdr = (void *)lib->base;
714 715
	find_map_range((void *)(aux[AT_BASE]+ehdr->e_phoff),
		ehdr->e_phnum, ehdr->e_phentsize, lib);
716 717 718 719 720
	lib->dynv = (void *)(lib->base + find_dyn(
		(void *)(aux[AT_BASE]+ehdr->e_phoff),
		ehdr->e_phnum, ehdr->e_phentsize));
	decode_dyn(lib);

721
	if (aux[AT_PHDR]) {
722
		size_t interp_off = 0;
723
		size_t tls_image = 0;
724 725 726 727 728
		/* Find load address of the main program, via AT_PHDR vs PT_PHDR. */
		phdr = (void *)aux[AT_PHDR];
		for (i=aux[AT_PHNUM]; i; i--, phdr=(void *)((char *)phdr + aux[AT_PHENT])) {
			if (phdr->p_type == PT_PHDR)
				app->base = (void *)(aux[AT_PHDR] - phdr->p_vaddr);
729 730
			else if (phdr->p_type == PT_INTERP)
				interp_off = (size_t)phdr->p_vaddr;
731 732 733 734 735 736
			else if (phdr->p_type == PT_TLS) {
				tls_image = phdr->p_vaddr;
				app->tls_len = phdr->p_filesz;
				app->tls_size = phdr->p_memsz;
				app->tls_align = phdr->p_align;
			}
737
		}
738
		if (app->tls_size) app->tls_image = (char *)app->base + tls_image;
739
		if (interp_off) lib->name = (char *)app->base + interp_off;
740
		app->name = argv[0];
741 742
		app->dynv = (void *)(app->base + find_dyn(
			(void *)aux[AT_PHDR], aux[AT_PHNUM], aux[AT_PHENT]));
743 744
		find_map_range((void *)aux[AT_PHDR],
			aux[AT_PHNUM], aux[AT_PHENT], app);
745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763
	} else {
		int fd;
		char *ldname = argv[0];
		size_t dyno, l = strlen(ldname);
		if (l >= 3 && !strcmp(ldname+l-3, "ldd")) ldd_mode = 1;
		*argv++ = (void *)-1;
		if (argv[0] && !strcmp(argv[0], "--")) *argv++ = (void *)-1;
		if (!argv[0]) {
			dprintf(2, "musl libc/dynamic program loader\n");
			dprintf(2, "usage: %s pathname%s\n", ldname,
				ldd_mode ? "" : " [args]");
			_exit(1);
		}
		fd = open(argv[0], O_RDONLY);
		if (fd < 0) {
			dprintf(2, "%s: cannot load %s: %s\n", ldname, argv[0], strerror(errno));
			_exit(1);
		}
		runtime = 1;
764
		ehdr = (void *)map_library(fd, app);
765 766 767 768 769 770
		if (!ehdr) {
			dprintf(2, "%s: %s: Not a valid dynamic program\n", ldname, argv[0]);
			_exit(1);
		}
		runtime = 0;
		close(fd);
771
		lib->name = ldname;
772
		app->name = argv[0];
773
		aux[AT_ENTRY] = ehdr->e_entry;
774
	}
775 776 777 778 779
	if (app->tls_size) {
		app->tls_id = ++tls_cnt;
		tls_size += app->tls_size+app->tls_align + 8*sizeof(size_t)-1
			& -4*sizeof(size_t);
	}
780
	app->global = 1;
781
	app->constructed = 1;
782 783 784
	decode_dyn(app);

	/* Attach to vdso, if provided by the kernel */
R
Rich Felker 已提交
785
	if (search_vec(auxv, &vdso_base, AT_SYSINFO_EHDR)) {
786 787 788 789 790 791 792 793
		ehdr = (void *)vdso_base;
		phdr = (void *)(vdso_base + ehdr->e_phoff);
		for (i=ehdr->e_phnum; i; i--, phdr=(void *)((char *)phdr + ehdr->e_phentsize)) {
			if (phdr->p_type == PT_DYNAMIC)
				vdso->dynv = (void *)(vdso_base + phdr->p_offset);
			if (phdr->p_type == PT_LOAD)
				vdso->base = (void *)(vdso_base - phdr->p_vaddr + phdr->p_offset);
		}
794
		vdso->name = vdso->shortname = "linux-gate.so.1";
795
		vdso->global = 1;
796
		decode_dyn(vdso);
797 798 799 800
		vdso->prev = lib;
		lib->next = vdso;
	}

801 802 803 804 805 806 807 808 809
	/* Initial dso chain consists only of the app. We temporarily
	 * append the dynamic linker/libc so we can relocate it, then
	 * restore the initial chain in preparation for loading third
	 * party libraries (preload/needed). */
	head = tail = app;
	libc = lib;
	app->next = lib;
	reloc_all(lib);
	app->next = 0;
R
Rich Felker 已提交
810

811
	/* PAST THIS POINT, ALL LIBC INTERFACES ARE FULLY USABLE. */
R
Rich Felker 已提交
812

813
	/* Donate unused parts of app and library mapping to malloc */
R
Rich Felker 已提交
814 815 816
	reclaim_gaps(app->base, (void *)aux[AT_PHDR], aux[AT_PHENT], aux[AT_PHNUM]);
	ehdr = (void *)lib->base;
	reclaim_gaps(lib->base, (void *)(lib->base+ehdr->e_phoff),
817 818
		ehdr->e_phentsize, ehdr->e_phnum);

819
	/* Load preload/needed libraries, add their symbols to the global
820 821 822
	 * namespace, and perform all remaining relocations. The main
	 * program must be relocated LAST since it may contain copy
	 * relocations which depend on libraries' relocations. */
R
Rich Felker 已提交
823
	if (env_preload) load_preload(env_preload);
824 825
	load_deps(app);
	make_global(app);
826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850

	/* Make an initial pass setting up TLS before performing relocs.
	 * This provides the TP-based offset of each DSO's TLS for
	 * use in TP-relative relocations. After relocations, we need
	 * to copy the TLS images again in case they had relocs. */
	tls_size += sizeof(struct pthread) + 4*sizeof(size_t);
	__libc.tls_size = tls_size;
	__libc.tls_cnt = tls_cnt;
	if (tls_cnt) {
		struct dso *p;
		void *mem = mmap(0, __libc.tls_size, PROT_READ|PROT_WRITE,
			MAP_ANONYMOUS|MAP_PRIVATE, -1, 0);
		if (mem==MAP_FAILED ||
		    !__install_initial_tls(__copy_tls(mem, tls_cnt))) {
			dprintf(2, "%s: Error getting %zu bytes thread-local storage: %m\n",
				argv[0], tls_size);
			_exit(127);
		}
		for (p=head; p; p=p->next) {
			if (!p->tls_id) continue;
			p->tls_offset = (char *)__pthread_self()
				- (char *)__pthread_self()->dtv[p->tls_id];
		}
	}

851
	reloc_all(app->next);
852 853
	reloc_all(app);

854 855 856 857
	/* The initial DTV is located at the base of the memory
	 * allocated for TLS. Repeat copying TLS to pick up relocs. */
	if (tls_cnt) __copy_tls((void *)__pthread_self()->dtv, tls_cnt);

858
	if (ldso_fail) _exit(127);
859 860
	if (ldd_mode) _exit(0);

861 862 863 864
	/* Switch to runtime mode: any further failures in the dynamic
	 * linker are a reportable failure rather than a fatal startup
	 * error. If the dynamic loader (dlopen) will not be used, free
	 * all memory used by the dynamic linker. */
R
Rich Felker 已提交
865
	runtime = 1;
866

867
#ifndef DYNAMIC_IS_RO
868 869 870
	for (i=0; app->dynv[i]; i+=2)
		if (app->dynv[i]==DT_DEBUG)
			app->dynv[i+1] = (size_t)&debug;
871
#endif
872 873 874 875 876 877 878
	debug.ver = 1;
	debug.bp = _dl_debug_state;
	debug.head = head;
	debug.base = lib->base;
	debug.state = 0;
	_dl_debug_state();

879 880
	if (ssp_used) __init_ssp(auxv);

881 882
	do_init_fini(tail);

R
Rich Felker 已提交
883 884 885
	errno = 0;
	return (void *)aux[AT_ENTRY];
}
886 887 888

void *dlopen(const char *file, int mode)
{
889
	struct dso *volatile p, *orig_tail = tail, *next;
890
	size_t i;
891
	int cs;
892 893 894

	if (!file) return head;

895
	pthread_setcancelstate(PTHREAD_CANCEL_DISABLE, &cs);
896 897 898 899
	pthread_rwlock_wrlock(&lock);

	if (setjmp(rtld_fail)) {
		/* Clean up anything new that was (partially) loaded */
900 901 902
		if (p->deps) for (i=0; p->deps[i]; i++)
			if (p->deps[i]->global < 0)
				p->deps[i]->global = 0;
903 904 905 906 907 908 909 910
		for (p=orig_tail->next; p; p=next) {
			next = p->next;
			munmap(p->map, p->map_len);
			free(p->deps);
			free(p);
		}
		tail = orig_tail;
		tail->next = 0;
911
		p = 0;
912 913
		errflag = 1;
		goto end;
R
Rich Felker 已提交
914 915 916
	} else p = load_library(file);

	if (!p) {
917 918
		snprintf(errbuf, sizeof errbuf,
			"Error loading shared library %s: %m", file);
R
Rich Felker 已提交
919
		errflag = 1;
920
		goto end;
921 922 923 924 925
	}

	/* First load handling */
	if (!p->deps) {
		load_deps(p);
R
Rich Felker 已提交
926
		if (p->deps) for (i=0; p->deps[i]; i++)
927 928 929
			if (!p->deps[i]->global)
				p->deps[i]->global = -1;
		if (!p->global) p->global = -1;
930
		reloc_all(p);
R
Rich Felker 已提交
931
		if (p->deps) for (i=0; p->deps[i]; i++)
932 933 934
			if (p->deps[i]->global < 0)
				p->deps[i]->global = 0;
		if (p->global < 0) p->global = 0;
935 936 937
	}

	if (mode & RTLD_GLOBAL) {
R
Rich Felker 已提交
938
		if (p->deps) for (i=0; p->deps[i]; i++)
939 940 941 942
			p->deps[i]->global = 1;
		p->global = 1;
	}

943 944
	if (ssp_used) __init_ssp(auxv);

945 946
	_dl_debug_state();

947
	do_init_fini(tail);
948
end:
949
	pthread_rwlock_unlock(&lock);
950
	pthread_setcancelstate(cs, 0);
951 952 953
	return p;
}

R
Rich Felker 已提交
954
static void *do_dlsym(struct dso *p, const char *s, void *ra)
955 956
{
	size_t i;
957
	uint32_t h = 0, gh = 0;
958
	Sym *sym;
959 960 961 962 963 964 965 966
	if (p == head || p == RTLD_DEFAULT || p == RTLD_NEXT) {
		if (p == RTLD_NEXT) {
			for (p=head; p && (unsigned char *)ra-p->map>p->map_len; p=p->next);
			if (!p) p=head;
		}
		struct symdef def = find_sym(p->next, s, 0);
		if (!def.sym) goto failed;
		return def.dso->base + def.sym->st_value;
R
Rich Felker 已提交
967
	}
968 969 970 971 972 973 974
	if (p->ghashtab) {
		gh = gnu_hash(s);
		sym = gnu_lookup(s, gh, p);
	} else {
		h = sysv_hash(s);
		sym = sysv_lookup(s, h, p);
	}
975 976 977
	if (sym && sym->st_value && (1<<(sym->st_info&0xf) & OK_TYPES))
		return p->base + sym->st_value;
	if (p->deps) for (i=0; p->deps[i]; i++) {
978 979
		if (p->deps[i]->ghashtab) {
			if (!gh) gh = gnu_hash(s);
980
			sym = gnu_lookup(s, gh, p->deps[i]);
981 982 983 984
		} else {
			if (!h) h = sysv_hash(s);
			sym = sysv_lookup(s, h, p->deps[i]);
		}
985 986 987
		if (sym && sym->st_value && (1<<(sym->st_info&0xf) & OK_TYPES))
			return p->deps[i]->base + sym->st_value;
	}
988
failed:
R
Rich Felker 已提交
989
	errflag = 1;
990
	snprintf(errbuf, sizeof errbuf, "Symbol not found: %s", s);
991 992 993
	return 0;
}

994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054
int __dladdr(void *addr, Dl_info *info)
{
	struct dso *p;
	Sym *sym;
	uint32_t nsym;
	char *strings;
	size_t i;
	void *best = 0;
	char *bestname;

	pthread_rwlock_rdlock(&lock);
	for (p=head; p && (unsigned char *)addr-p->map>p->map_len; p=p->next);
	pthread_rwlock_unlock(&lock);

	if (!p) return 0;

	sym = p->syms;
	strings = p->strings;
	if (p->hashtab) {
		nsym = p->hashtab[1];
	} else {
		uint32_t *buckets;
		uint32_t *hashval;
		buckets = p->ghashtab + 4 + (p->ghashtab[2]*sizeof(size_t)/4);
		sym += p->ghashtab[1];
		for (i = 0; i < p->ghashtab[0]; i++) {
			if (buckets[i] > nsym)
				nsym = buckets[i];
		}
		if (nsym) {
			nsym -= p->ghashtab[1];
			hashval = buckets + p->ghashtab[0] + nsym;
			do nsym++;
			while (!(*hashval++ & 1));
		}
	}

	for (; nsym; nsym--, sym++) {
		if (sym->st_shndx && sym->st_value
		 && (1<<(sym->st_info&0xf) & OK_TYPES)
		 && (1<<(sym->st_info>>4) & OK_BINDS)) {
			void *symaddr = p->base + sym->st_value;
			if (symaddr > addr || symaddr < best)
				continue;
			best = symaddr;
			bestname = strings + sym->st_name;
			if (addr == symaddr)
				break;
		}
	}

	if (!best) return 0;

	info->dli_fname = p->name;
	info->dli_fbase = p->base;
	info->dli_sname = bestname;
	info->dli_saddr = best;

	return 1;
}

1055
void *__dlsym(void *restrict p, const char *restrict s, void *restrict ra)
1056 1057 1058
{
	void *res;
	pthread_rwlock_rdlock(&lock);
R
Rich Felker 已提交
1059
	res = do_dlsym(p, s, ra);
1060 1061 1062
	pthread_rwlock_unlock(&lock);
	return res;
}
1063 1064 1065 1066 1067
#else
void *dlopen(const char *file, int mode)
{
	return 0;
}
1068
void *__dlsym(void *restrict p, const char *restrict s, void *restrict ra)
1069 1070 1071
{
	return 0;
}
1072 1073 1074 1075
int __dladdr (void *addr, Dl_info *info)
{
	return 0;
}
1076
#endif
1077 1078 1079

char *dlerror()
{
R
Rich Felker 已提交
1080 1081
	if (!errflag) return 0;
	errflag = 0;
1082
	return errbuf;
1083 1084 1085 1086 1087 1088
}

int dlclose(void *p)
{
	return 0;
}