about summary refs log tree commit diff
path: root/elf/rtld.c
blob: 032bb8ee87ceef7ed7839aeff37e09ad00a8940c (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
/* Run time dynamic linker.
Copyright (C) 1995, 1996 Free Software Foundation, Inc.
This file is part of the GNU C Library.

The GNU C Library is free software; you can redistribute it and/or
modify it under the terms of the GNU Library General Public License as
published by the Free Software Foundation; either version 2 of the
License, or (at your option) any later version.

The GNU C Library is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Library General Public License for more details.

You should have received a copy of the GNU Library General Public
License along with the GNU C Library; see the file COPYING.LIB.  If
not, write to the Free Software Foundation, Inc., 675 Mass Ave,
Cambridge, MA 02139, USA.  */

#include <link.h>
#include "dynamic-link.h"
#include <stddef.h>
#include <stdlib.h>
#include <unistd.h>
#include "../stdio-common/_itoa.h"


#ifdef RTLD_START
RTLD_START
#else
#error "sysdeps/MACHINE/dl-machine.h fails to define RTLD_START"
#endif

/* System-specific function to do initial startup for the dynamic linker.
   After this, file access calls and getenv must work.  This is responsible
   for setting _dl_secure if we need to be secure (e.g. setuid),
   and for setting _dl_argc and _dl_argv, and then calling _dl_main.  */
extern Elf32_Addr _dl_sysdep_start (void **start_argptr,
				    void (*dl_main) (const Elf32_Phdr *phdr,
						     Elf32_Word phent,
						     Elf32_Addr *user_entry));
extern void _dl_sysdep_start_cleanup (void);

int _dl_secure;
int _dl_argc;
char **_dl_argv;
const char *_dl_rpath;

struct r_debug dl_r_debug;

static void dl_main (const Elf32_Phdr *phdr,
		     Elf32_Word phent,
		     Elf32_Addr *user_entry);

struct link_map _dl_rtld_map;

Elf32_Addr
_dl_start (void *arg)
{
  struct link_map bootstrap_map;

  /* Figure out the run-time load address of the dynamic linker itself.  */
  bootstrap_map.l_addr = elf_machine_load_address ();

  /* Read our own dynamic section and fill in the info array.
     Conveniently, the first element of the GOT contains the
     offset of _DYNAMIC relative to the run-time load address.  */
  bootstrap_map.l_ld = (void *) bootstrap_map.l_addr + *elf_machine_got ();
  elf_get_dynamic_info (bootstrap_map.l_ld, bootstrap_map.l_info);

#ifdef ELF_MACHINE_BEFORE_RTLD_RELOC
  ELF_MACHINE_BEFORE_RTLD_RELOC (bootstrap_map.l_info);
#endif

  /* Relocate ourselves so we can do normal function calls and
     data access using the global offset table.  */

  /* We must initialize `l_type' to make sure it is not `lt_interpreter'.
     That is the type to describe us, but not during bootstrapping--it
     indicates to elf_machine_rel{,a} that we were already relocated during
     bootstrapping, so it must anti-perform each bootstrapping relocation
     before applying the final relocation when ld.so is linked in as
     normal a shared library.  */
  bootstrap_map.l_type = lt_library;
  ELF_DYNAMIC_RELOCATE (&bootstrap_map, 0, NULL);


  /* Now life is sane; we can call functions and access global data.
     Set up to use the operating system facilities, and find out from
     the operating system's program loader where to find the program
     header table in core.  */


  /* Transfer data about ourselves to the permanent link_map structure.  */
  _dl_rtld_map.l_addr = bootstrap_map.l_addr;
  _dl_rtld_map.l_ld = bootstrap_map.l_ld;
  memcpy (_dl_rtld_map.l_info, bootstrap_map.l_info,
	  sizeof _dl_rtld_map.l_info);
  _dl_setup_hash (&_dl_rtld_map);

  /* Cache the DT_RPATH stored in ld.so itself; this will be
     the default search path.  */
  _dl_rpath = (void *) (_dl_rtld_map.l_addr +
			_dl_rtld_map.l_info[DT_STRTAB]->d_un.d_ptr +
			_dl_rtld_map.l_info[DT_RPATH]->d_un.d_val);

  /* Call the OS-dependent function to set up life so we can do things like
     file access.  It will call `dl_main' (below) to do all the real work
     of the dynamic linker, and then unwind our frame and run the user
     entry point on the same stack we entered on.  */
  return _dl_sysdep_start (&arg, &dl_main);
}


/* Now life is peachy; we can do all normal operations.
   On to the real work.  */

void _start (void);

unsigned int _dl_skip_args;	/* Nonzero if we were run directly.  */

static void
dl_main (const Elf32_Phdr *phdr,
	 Elf32_Word phent,
	 Elf32_Addr *user_entry)
{
  const Elf32_Phdr *ph;
  struct link_map *l;
  const char *interpreter_name;
  int lazy;
  int list_only = 0;

  if (*user_entry == (Elf32_Addr) &_start)
    {
      /* Ho ho.  We are not the program interpreter!  We are the program
	 itself!  This means someone ran ld.so as a command.  Well, that
	 might be convenient to do sometimes.  We support it by
	 interpreting the args like this:

	 ld.so PROGRAM ARGS...

	 The first argument is the name of a file containing an ELF
	 executable we will load and run with the following arguments.
	 To simplify life here, PROGRAM is searched for using the
	 normal rules for shared objects, rather than $PATH or anything
	 like that.  We just load it and use its entry point; we don't
	 pay attention to its PT_INTERP command (we are the interpreter
	 ourselves).  This is an easy way to test a new ld.so before
	 installing it.  */
      if (_dl_argc < 2)
	_dl_sysdep_fatal ("\
Usage: ld.so [--list] EXECUTABLE-FILE [ARGS-FOR-PROGRAM...]\n\
You have invoked `ld.so', the helper program for shared library executables.\n\
This program usually lives in the file `/lib/ld.so', and special directives\n\
in executable files using ELF shared libraries tell the system's program\n\
loader to load the helper program from this file.  This helper program loads\n\
the shared libraries needed by the program executable, prepares the program\n\
to run, and runs it.  You may invoke this helper program directly from the\n\
command line to load and run an ELF executable file; this is like executing\n\
that file itself, but always uses this helper program from the file you\n\
specified, instead of the helper program file specified in the executable\n\
file you run.  This is mostly of use for maintainers to test new versions\n\
of this helper program; chances are you did not intend to run this program.\n",
			  NULL);

      interpreter_name = _dl_argv[0];

      if (! strcmp (_dl_argv[1], "--list"))
	{
	  list_only = 1;

	  ++_dl_skip_args;
	  --_dl_argc;
	  ++_dl_argv;
	}

      ++_dl_skip_args;
      --_dl_argc;
      ++_dl_argv;

      l = _dl_map_object (NULL, _dl_argv[0]);
      phdr = l->l_phdr;
      phent = l->l_phnum;
      l->l_name = (char *) "";
      *user_entry = l->l_entry;
    }
  else
    {
      /* Create a link_map for the executable itself.
	 This will be what dlopen on "" returns.  */
      l = _dl_new_object ((char *) "", "", lt_executable);
      l->l_phdr = phdr;
      l->l_phnum = phent;
      interpreter_name = 0;
      l->l_entry = *user_entry;
    }

  if (l != _dl_loaded)
    {
      /* GDB assumes that the first element on the chain is the
	 link_map for the executable itself, and always skips it.
	 Make sure the first one is indeed that one.  */
      l->l_prev->l_next = l->l_next;
      if (l->l_next)
	l->l_next->l_prev = l->l_prev;
      l->l_prev = NULL;
      l->l_next = _dl_loaded;
      _dl_loaded->l_prev = l;
      _dl_loaded = l;
    }

  /* Scan the program header table for the dynamic section.  */
  for (ph = phdr; ph < &phdr[phent]; ++ph)
    switch (ph->p_type)
      {
      case PT_DYNAMIC:
	/* This tells us where to find the dynamic section,
	   which tells us everything we need to do.  */
	l->l_ld = (void *) l->l_addr + ph->p_vaddr;
	break;
      case PT_INTERP:
	/* This "interpreter segment" was used by the program loader to
	   find the program interpreter, which is this program itself, the
	   dynamic linker.  We note what name finds us, so that a future
	   dlopen call or DT_NEEDED entry, for something that wants to link
	   against the dynamic linker as a shared library, will know that
	   the shared object is already loaded.  */
	interpreter_name = (void *) l->l_addr + ph->p_vaddr;
	break;
      }
  assert (interpreter_name);	/* How else did we get here?  */

  /* Extract the contents of the dynamic section for easy access.  */
  elf_get_dynamic_info (l->l_ld, l->l_info);
  if (l->l_info[DT_HASH])
    /* Set up our cache of pointers into the hash table.  */
    _dl_setup_hash (l);

  if (l->l_info[DT_DEBUG])
    /* There is a DT_DEBUG entry in the dynamic section.  Fill it in
       with the run-time address of the r_debug structure, which we
       will set up later to communicate with the debugger.  */
    l->l_info[DT_DEBUG]->d_un.d_ptr = (Elf32_Addr) &dl_r_debug;

  /* Put the link_map for ourselves on the chain so it can be found by
     name.  */
  _dl_rtld_map.l_name = (char *) _dl_rtld_map.l_libname = interpreter_name;
  _dl_rtld_map.l_type = lt_interpreter;
  while (l->l_next)
    l = l->l_next;
  l->l_next = &_dl_rtld_map;
  _dl_rtld_map.l_prev = l;

  /* Load all the libraries specified by DT_NEEDED entries.  */
  _dl_map_object_deps (l);

  /* XXX if kept, move it so l_next list is in dep order because
     it will determine gdb's search order.
     Perhaps do this always, so later dlopen by name finds it?
     XXX But then gdb always considers it present.  */
  if (_dl_rtld_map.l_opencount == 0)
    {
      /* No DT_NEEDED entry referred to the interpreter object itself,
	 so remove it from the list of visible objects.  */
      _dl_rtld_map.l_prev->l_next = _dl_rtld_map.l_next;
      _dl_rtld_map.l_next->l_prev = _dl_rtld_map.l_prev;
    }

  if (list_only)
    {
      /* We were run just to list the shared libraries.  It is
	 important that we do this before real relocation, because the
	 functions we call below for output may no longer work properly
	 after relocation.  */

      int i;

      if (! _dl_loaded->l_info[DT_NEEDED])
	_dl_sysdep_message ("\t", "statically linked\n", NULL);
      else
	for (l = _dl_loaded->l_next; l; l = l->l_next)
	  {
	    char buf[20], *bp;
	    buf[sizeof buf - 1] = '\0';
	    bp = _itoa (l->l_addr, &buf[sizeof buf - 1], 16, 0);
	    while (&buf[sizeof buf - 1] - bp < sizeof l->l_addr * 2)
	      *--bp = '0';
	    _dl_sysdep_message ("\t", l->l_libname, " => ", l->l_name,
				" (0x", bp, ")\n", NULL);
	  }

      for (i = 1; i < _dl_argc; ++i)
	{
	  const Elf32_Sym *ref = NULL;
	  struct link_map *scope[2] ={ _dl_loaded, NULL };
	  Elf32_Addr loadbase
	    = _dl_lookup_symbol (_dl_argv[i], &ref, scope, "argument", 0, 0);
	  char buf[20], *bp;
	  buf[sizeof buf - 1] = '\0';
	  bp = _itoa (ref->st_value, &buf[sizeof buf - 1], 16, 0);
	  while (&buf[sizeof buf - 1] - bp < sizeof loadbase * 2)
	    *--bp = '0';
	  _dl_sysdep_message (_dl_argv[i], " found at 0x", bp, NULL);
	  buf[sizeof buf - 1] = '\0';
	  bp = _itoa (loadbase, &buf[sizeof buf - 1], 16, 0);
	  while (&buf[sizeof buf - 1] - bp < sizeof loadbase * 2)
	    *--bp = '0';
	  _dl_sysdep_message (" in object at 0x", bp, "\n", NULL);
	}

      _exit (0);
    }

  lazy = !_dl_secure && *(getenv ("LD_BIND_NOW") ?: "") == '\0';

  /* Now we have all the objects loaded.  Relocate them all except for
     the dynamic linker itself.  We do this in reverse order so that
     copy relocs of earlier objects overwrite the data written by later
     objects.  We do not re-relocate the dynamic linker itself in this
     loop because that could result in the GOT entries for functions we
     call being changed, and that would break us.  It is safe to
     relocate the dynamic linker out of order because it has no copy
     relocs (we know that because it is self-contained).  */
  l = _dl_loaded;
  while (l->l_next)
    l = l->l_next;
  do
    {
      if (l != &_dl_rtld_map)
	_dl_relocate_object (l, lazy);
      l = l->l_prev;
    } while (l);

  /* Do any necessary cleanups for the startup OS interface code.
     We do these now so that no calls are made after rtld re-relocation
     which might be resolved to different functions than we expect.
     We cannot do this before relocating the other objects because
     _dl_relocate_object might need to call `mprotect' for DT_TEXTREL.  */
  _dl_sysdep_start_cleanup ();

  if (_dl_rtld_map.l_opencount > 0)
    /* There was an explicit ref to the dynamic linker as a shared lib.
       Re-relocate ourselves with user-controlled symbol definitions.  */
    _dl_relocate_object (&_dl_rtld_map, lazy);

  /* Tell the debugger where to find the map of loaded objects.  */
  dl_r_debug.r_version = 1	/* R_DEBUG_VERSION XXX */;
  dl_r_debug.r_ldbase = _dl_rtld_map.l_addr; /* Record our load address.  */
  dl_r_debug.r_map = _dl_loaded;
  dl_r_debug.r_brk = (Elf32_Addr) &_dl_r_debug_state;

  if (_dl_rtld_map.l_info[DT_INIT])
    {
      /* Call the initializer for the compatibility version of the
	 dynamic linker.  There is no additional initialization
	 required for the ABI-compliant dynamic linker.  */

      (*(void (*) (void)) (_dl_rtld_map.l_addr +
			   _dl_rtld_map.l_info[DT_INIT]->d_un.d_ptr)) ();

      /* Clear the field so a future dlopen won't run it again.  */
      _dl_rtld_map.l_info[DT_INIT] = NULL;
    }

  /* Once we return, _dl_sysdep_start will invoke
     the DT_INIT functions and then *USER_ENTRY.  */
}

/* This function exists solely to have a breakpoint set on it by the
   debugger.  */
void
_dl_r_debug_state (void)
{
}