]> git.ipfire.org Git - thirdparty/glibc.git/blame - elf/dl-support.c
elf: Refuse to dlopen PIE objects [BZ #24323]
[thirdparty/glibc.git] / elf / dl-support.c
CommitLineData
266180eb 1/* Support for dynamic linking code in static libc.
04277e02 2 Copyright (C) 1996-2019 Free Software Foundation, Inc.
afd4eb37 3 This file is part of the GNU C Library.
266180eb 4
afd4eb37 5 The GNU C Library is free software; you can redistribute it and/or
41bdb6e2
AJ
6 modify it under the terms of the GNU Lesser General Public
7 License as published by the Free Software Foundation; either
8 version 2.1 of the License, or (at your option) any later version.
266180eb 9
afd4eb37
UD
10 The GNU C Library is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
41bdb6e2 13 Lesser General Public License for more details.
266180eb 14
41bdb6e2 15 You should have received a copy of the GNU Lesser General Public
59ba27a6
PE
16 License along with the GNU C Library; if not, see
17 <http://www.gnu.org/licenses/>. */
266180eb 18
266180eb
RM
19/* This file defines some things that for the dynamic linker are defined in
20 rtld.c and dl-sysdep.c in ways appropriate to bootstrap dynamic linking. */
21
3c720987 22#include <errno.h>
8e17ea58 23#include <libintl.h>
b13927da 24#include <stdlib.h>
0a54e401 25#include <unistd.h>
32b4c839 26#include <sys/param.h>
e054f494 27#include <stdint.h>
a42195db 28#include <ldsodefs.h>
0a54e401 29#include <dl-machine.h>
ec999b8e 30#include <libc-lock.h>
5688da55 31#include <dl-cache.h>
74955460 32#include <dl-librecon.h>
594d423a 33#include <dl-procinfo.h>
74955460 34#include <unsecvars.h>
3b5c1b57 35#include <hp-timing.h>
30950a5f 36#include <stackinfo.h>
b13927da 37
266180eb
RM
38extern char *__progname;
39char **_dl_argv = &__progname; /* This is checked for some error messages. */
40
0a54e401
UD
41/* Name of the architecture. */
42const char *_dl_platform;
43size_t _dl_platformlen;
3c720987 44
62dcee57 45int _dl_debug_mask;
12b5b6b7 46int _dl_lazy;
97fd3a30 47ElfW(Addr) _dl_use_load_bias = -2;
dec126b4 48int _dl_dynamic_weak;
0a54e401 49
b13927da
UD
50/* If nonzero print warnings about problematic situations. */
51int _dl_verbose;
52
3996f34b
UD
53/* We never do profiling. */
54const char *_dl_profile;
53bfdc1c 55const char *_dl_profile_output;
3996f34b 56
fcf70d41
UD
57/* Names of shared object for which the RUNPATHs and RPATHs should be
58 ignored. */
b0a01055 59const char *_dl_inhibit_rpath;
310930c1 60
a3d6fb9b
UD
61/* The map for the object we will profile. */
62struct link_map *_dl_profile_map;
63
c0fb8a56
UD
64/* This is the address of the last stack address ever used. */
65void *__libc_stack_end;
66
f787edde
UD
67/* Path where the binary is found. */
68const char *_dl_origin_path;
69
f53c03c2
UD
70/* Nonzero if runtime lookup should not update the .got/.plt. */
71int _dl_bind_not;
72
f91f1c0f
MR
73/* A dummy link map for the executable, used by dlopen to access the global
74 scope. We don't export any symbols ourselves, so this can be minimal. */
75static struct link_map _dl_main_map =
76 {
77 .l_name = (char *) "",
78 .l_real = &_dl_main_map,
79 .l_ns = LM_ID_BASE,
80 .l_libname = &(struct libname_list) { .name = "", .dont_free = 1 },
81 .l_searchlist =
82 {
83 .r_list = &(struct link_map *) { &_dl_main_map },
84 .r_nlist = 1,
85 },
86 .l_symbolic_searchlist = { .r_list = &(struct link_map *) { NULL } },
87 .l_type = lt_executable,
88 .l_scope_mem = { &_dl_main_map.l_searchlist },
89 .l_scope_max = (sizeof (_dl_main_map.l_scope_mem)
90 / sizeof (_dl_main_map.l_scope_mem[0])),
91 .l_scope = _dl_main_map.l_scope_mem,
92 .l_local_scope = { &_dl_main_map.l_searchlist },
93 .l_used = 1,
94 .l_tls_offset = NO_TLS_OFFSET,
95 .l_serial = 1,
96 };
97
c0f62c56 98/* Namespace information. */
f91f1c0f
MR
99struct link_namespaces _dl_ns[DL_NNS] =
100 {
101 [LM_ID_BASE] =
102 {
103 ._ns_loaded = &_dl_main_map,
104 ._ns_nloaded = 1,
105 ._ns_main_searchlist = &_dl_main_map.l_searchlist,
106 }
107 };
108size_t _dl_nns = 1;
be935610 109
bed12f78 110/* Incremented whenever something may have been added to dl_loaded. */
f91f1c0f 111unsigned long long _dl_load_adds = 1;
bed12f78 112
f91f1c0f
MR
113/* Fake scope of the main application. */
114struct r_scope_elem _dl_initial_searchlist =
115 {
116 .r_list = &(struct link_map *) { &_dl_main_map },
117 .r_nlist = 1,
118 };
be935610 119
ce6e047f 120#ifndef HAVE_INLINED_SYSCALLS
9ad04ff7
UD
121/* Nonzero during startup. */
122int _dl_starting_up = 1;
ce6e047f 123#endif
9ad04ff7 124
965cb60a
UD
125/* Random data provided by the kernel. */
126void *_dl_random;
127
ccdf0cab 128/* Get architecture specific initializer. */
4a306ef1 129#include <dl-procruntime.c>
ccdf0cab
UD
130#include <dl-procinfo.c>
131
adc12574 132void (*_dl_init_static_tls) (struct link_map *) = &_dl_nothread_init_static_tls;
adc12574 133
32b4c839 134size_t _dl_pagesize = EXEC_PAGESIZE;
d6b5d570 135
73d65cc3
SP
136int _dl_inhibit_cache;
137
d6b5d570
UD
138unsigned int _dl_osversion;
139
140/* All known directories in sorted order. */
141struct r_search_path_elem *_dl_all_dirs;
142
143/* All directories after startup. */
144struct r_search_path_elem *_dl_init_all_dirs;
145
146/* The object to be initialized first. */
147struct link_map *_dl_initfirst;
148
5688da55
UD
149/* Descriptor to write debug messages to. */
150int _dl_debug_fd = STDERR_FILENO;
151
152int _dl_correct_cache_id = _DL_CACHE_DEFAULT_ID;
153
c7683a6d 154ElfW(auxv_t) *_dl_auxv;
dc0a0263 155const ElfW(Phdr) *_dl_phdr;
fcda29e2 156size_t _dl_phnum;
ab1d521d 157uint64_t _dl_hwcap __attribute__ ((nocommon));
1ae8bfe0 158uint64_t _dl_hwcap2 __attribute__ ((nocommon));
172ce013 159
95e7cf29
MR
160/* The value of the FPU control word the kernel will preset in hardware. */
161fpu_control_t _dl_fpu_control = _FPU_DEFAULT;
162
ff08fc59 163#if !HAVE_TUNABLES
7bfa311f
RM
164/* This is not initialized to HWCAP_IMPORTANT, matching the definition
165 of _dl_important_hwcaps, below, where no hwcap strings are ever
166 used. This mask is still used to mediate the lookups in the cache
167 file. Since there is no way to set this nonzero (we don't grok the
168 LD_HWCAP_MASK environment variable here), there is no real point in
169 setting _dl_hwcap nonzero below, but we do anyway. */
170uint64_t _dl_hwcap_mask __attribute__ ((nocommon));
ff08fc59 171#endif
7bfa311f 172
30950a5f
RA
173/* Prevailing state of the stack. Generally this includes PF_X, indicating it's
174 * executable but this isn't true for all platforms. */
175ElfW(Word) _dl_stack_flags = DEFAULT_STACK_PERMS;
ecdeaac0
RM
176
177/* If loading a shared object requires that we make the stack executable
178 when it was not, we do it by calling this function.
179 It returns an errno code or zero on success. */
e1d2ae8d 180int (*_dl_make_stack_executable_hook) (void **) = _dl_make_stack_executable;
ecdeaac0
RM
181
182
df94b641
UD
183/* Function in libpthread to wait for termination of lookups. */
184void (*_dl_wait_lookup_done) (void);
185
a5df0318
ST
186#if !THREAD_GSCOPE_IN_TCB
187int _dl_thread_gscope_count;
188#endif
e4eb675d
UD
189struct dl_scope_free_list *_dl_scope_free_list;
190
5e289179
UD
191#ifdef NEED_DL_SYSINFO
192/* Needed for improved syscall handling on at least x86/Linux. */
193uintptr_t _dl_sysinfo = DL_SYSINFO_DEFAULT;
30e32d23 194#endif
7775448e 195#ifdef NEED_DL_SYSINFO_DSO
f866314b
UD
196/* Address of the ELF headers in the vsyscall page. */
197const ElfW(Ehdr) *_dl_sysinfo_dso;
9cee5585
L
198
199struct link_map *_dl_sysinfo_map;
200
201# include "get-dynamic-info.h"
5e289179 202#endif
d0d4f868 203#include "setup-vdso.h"
5e289179 204
cf197e41
UD
205/* During the program run we must not modify the global data of
206 loaded shared object simultanously in two threads. Therefore we
207 protect `_dl_open' and `_dl_close' in dl-close.c.
208
209 This must be a recursive lock since the initializer function of
210 the loaded object might as well require a call to this function.
211 At this time it is not anymore a problem to modify the tables. */
d3c9f895 212__rtld_lock_define_initialized_recursive (, _dl_load_lock)
5a2a1d75
AS
213/* This lock is used to keep __dl_iterate_phdr from inspecting the
214 list of loaded objects while an object is added to or removed from
215 that list. */
216__rtld_lock_define_initialized_recursive (, _dl_load_write_lock)
cf197e41 217
f8f900ec 218
e4a5f77d 219#ifdef HAVE_AUX_VECTOR
d6b5d570 220int _dl_clktck;
0a54e401 221
e4a5f77d 222void
e4a5f77d 223_dl_aux_init (ElfW(auxv_t) *av)
b13927da 224{
be4d8038
UD
225 int seen = 0;
226 uid_t uid = 0;
227 gid_t gid = 0;
228
c7683a6d 229 _dl_auxv = av;
f8f900ec
UD
230 for (; av->a_type != AT_NULL; ++av)
231 switch (av->a_type)
232 {
233 case AT_PAGESZ:
aefc9b8c
RM
234 if (av->a_un.a_val != 0)
235 GLRO(dl_pagesize) = av->a_un.a_val;
f8f900ec 236 break;
f8f900ec 237 case AT_CLKTCK:
afdca0f2 238 GLRO(dl_clktck) = av->a_un.a_val;
f8f900ec 239 break;
fcda29e2 240 case AT_PHDR:
dc0a0263 241 GL(dl_phdr) = (const void *) av->a_un.a_val;
fcda29e2
UD
242 break;
243 case AT_PHNUM:
244 GL(dl_phnum) = av->a_un.a_val;
245 break;
76c5ae00
CES
246 case AT_PLATFORM:
247 GLRO(dl_platform) = (void *) av->a_un.a_val;
248 break;
11bf8ce1 249 case AT_HWCAP:
ab1d521d 250 GLRO(dl_hwcap) = (unsigned long int) av->a_un.a_val;
11bf8ce1 251 break;
1ae8bfe0
RA
252 case AT_HWCAP2:
253 GLRO(dl_hwcap2) = (unsigned long int) av->a_un.a_val;
254 break;
95e7cf29
MR
255 case AT_FPUCW:
256 GLRO(dl_fpu_control) = av->a_un.a_val;
257 break;
5df8349b
UD
258#ifdef NEED_DL_SYSINFO
259 case AT_SYSINFO:
260 GL(dl_sysinfo) = av->a_un.a_val;
261 break;
30e32d23 262#endif
7775448e 263#ifdef NEED_DL_SYSINFO_DSO
30e32d23 264 case AT_SYSINFO_EHDR:
39fb308f 265 GL(dl_sysinfo_dso) = (void *) av->a_un.a_val;
30e32d23 266 break;
5df8349b 267#endif
be4d8038
UD
268 case AT_UID:
269 uid ^= av->a_un.a_val;
270 seen |= 1;
271 break;
272 case AT_EUID:
273 uid ^= av->a_un.a_val;
274 seen |= 2;
275 break;
276 case AT_GID:
277 gid ^= av->a_un.a_val;
278 seen |= 4;
279 break;
280 case AT_EGID:
281 gid ^= av->a_un.a_val;
282 seen |= 8;
283 break;
c801e765
RM
284 case AT_SECURE:
285 seen = -1;
286 __libc_enable_secure = av->a_un.a_val;
287 __libc_enable_secure_decided = 1;
288 break;
965cb60a
UD
289 case AT_RANDOM:
290 _dl_random = (void *) av->a_un.a_val;
291 break;
47dbe62b
RH
292# ifdef DL_PLATFORM_AUXV
293 DL_PLATFORM_AUXV
294# endif
f8f900ec 295 }
be4d8038
UD
296 if (seen == 0xf)
297 {
298 __libc_enable_secure = uid != 0 || gid != 0;
299 __libc_enable_secure_decided = 1;
300 }
e4a5f77d 301}
155fd00c 302#endif
f8f900ec 303
e4a5f77d 304
d417e0ff 305void
d417e0ff 306_dl_non_dynamic_init (void)
e4a5f77d 307{
f91f1c0f 308 _dl_main_map.l_origin = _dl_get_origin ();
0d23a5c1
MR
309 _dl_main_map.l_phdr = GL(dl_phdr);
310 _dl_main_map.l_phnum = GL(dl_phnum);
f91f1c0f 311
f8f900ec 312 _dl_verbose = *(getenv ("LD_WARN") ?: "") == '\0' ? 0 : 1;
e34b0f29 313
9cee5585
L
314 /* Set up the data structures for the system-supplied DSO early,
315 so they can influence _dl_init_paths. */
316 setup_vdso (NULL, NULL);
317
0a54e401
UD
318 /* Initialize the data structures for the search paths for shared
319 objects. */
b4debac9 320 _dl_init_paths (getenv ("LD_LIBRARY_PATH"));
0a54e401 321
bc5fb037
AS
322 /* Remember the last search directory added at startup. */
323 _dl_init_all_dirs = GL(dl_all_dirs);
324
12b5b6b7
UD
325 _dl_lazy = *(getenv ("LD_BIND_NOW") ?: "") == '\0';
326
f53c03c2
UD
327 _dl_bind_not = *(getenv ("LD_BIND_NOT") ?: "") != '\0';
328
dec126b4
UD
329 _dl_dynamic_weak = *(getenv ("LD_DYNAMIC_WEAK") ?: "") == '\0';
330
53bfdc1c
UD
331 _dl_profile_output = getenv ("LD_PROFILE_OUTPUT");
332 if (_dl_profile_output == NULL || _dl_profile_output[0] == '\0')
333 _dl_profile_output
334 = &"/var/tmp\0/var/profile"[__libc_enable_secure ? 9 : 0];
335
74955460
UD
336 if (__libc_enable_secure)
337 {
c4e328a1
UD
338 static const char unsecure_envvars[] =
339 UNSECURE_ENVVARS
74955460
UD
340#ifdef EXTRA_UNSECURE_ENVVARS
341 EXTRA_UNSECURE_ENVVARS
342#endif
c4e328a1
UD
343 ;
344 const char *cp = unsecure_envvars;
74955460 345
c4e328a1
UD
346 while (cp < unsecure_envvars + sizeof (unsecure_envvars))
347 {
348 __unsetenv (cp);
349 cp = (const char *) __rawmemchr (cp, '\0') + 1;
350 }
74955460 351
67e58f39 352#if !HAVE_TUNABLES
74955460 353 if (__access ("/etc/suid-debug", F_OK) != 0)
c4e328a1 354 __unsetenv ("MALLOC_CHECK_");
67e58f39 355#endif
74955460
UD
356 }
357
0a54e401
UD
358#ifdef DL_PLATFORM_INIT
359 DL_PLATFORM_INIT;
360#endif
361
2402cdf3
RM
362#ifdef DL_OSVERSION_INIT
363 DL_OSVERSION_INIT;
364#endif
365
0a54e401
UD
366 /* Now determine the length of the platform string. */
367 if (_dl_platform != NULL)
368 _dl_platformlen = strlen (_dl_platform);
ecdeaac0
RM
369
370 /* Scan for a program header telling us the stack is nonexecutable. */
371 if (_dl_phdr != NULL)
372 for (uint_fast16_t i = 0; i < _dl_phnum; ++i)
373 if (_dl_phdr[i].p_type == PT_GNU_STACK)
374 {
375 _dl_stack_flags = _dl_phdr[i].p_flags;
376 break;
377 }
b13927da 378}
d417e0ff 379
5e289179
UD
380#ifdef DL_SYSINFO_IMPLEMENTATION
381DL_SYSINFO_IMPLEMENTATION
382#endif
9d7a3741
L
383
384#if ENABLE_STATIC_PIE
385/* Since relocation to hidden _dl_main_map causes relocation overflow on
386 aarch64, a function is used to get the address of _dl_main_map. */
387
388struct link_map *
389_dl_get_dl_main_map (void)
390{
391 return &_dl_main_map;
392}
393#endif