• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2016 The Android Open Source Project
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *  * Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  *  * Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in
12  *    the documentation and/or other materials provided with the
13  *    distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include "linker_main.h"
30 
31 #include <link.h>
32 #include <sys/auxv.h>
33 
34 #include "linker.h"
35 #include "linker_cfi.h"
36 #include "linker_debug.h"
37 #include "linker_debuggerd.h"
38 #include "linker_gdb_support.h"
39 #include "linker_globals.h"
40 #include "linker_phdr.h"
41 #include "linker_relocate.h"
42 #include "linker_relocs.h"
43 #include "linker_tls.h"
44 #include "linker_utils.h"
45 
46 #include "private/bionic_call_ifunc_resolver.h"
47 #include "private/bionic_globals.h"
48 #include "private/bionic_tls.h"
49 #include "private/KernelArgumentBlock.h"
50 
51 #include "android-base/unique_fd.h"
52 #include "android-base/strings.h"
53 #include "android-base/stringprintf.h"
54 
55 #include <async_safe/log.h>
56 #include <bionic/libc_init_common.h>
57 #include <bionic/pthread_internal.h>
58 
59 #include <vector>
60 
61 __LIBC_HIDDEN__ extern "C" void _start();
62 
63 static ElfW(Addr) get_elf_exec_load_bias(const ElfW(Ehdr)* elf);
64 
65 static void get_elf_base_from_phdr(const ElfW(Phdr)* phdr_table, size_t phdr_count,
66                                    ElfW(Addr)* base, ElfW(Addr)* load_bias);
67 
68 static void set_bss_vma_name(soinfo* si);
69 
70 void __libc_init_mte(const void* phdr_start, size_t phdr_count, uintptr_t load_bias,
71                      void* stack_top);
72 
73 // These should be preserved static to avoid emitting
74 // RELATIVE relocations for the part of the code running
75 // before linker links itself.
76 
77 // TODO (dimtiry): remove somain, rename solist to solist_head
78 static soinfo* solist;
79 static soinfo* sonext;
80 static soinfo* somain; // main process, always the one after libdl_info
81 static soinfo* solinker;
82 static soinfo* vdso; // vdso if present
83 
solist_add_soinfo(soinfo * si)84 void solist_add_soinfo(soinfo* si) {
85   sonext->next = si;
86   sonext = si;
87 }
88 
solist_remove_soinfo(soinfo * si)89 bool solist_remove_soinfo(soinfo* si) {
90   soinfo *prev = nullptr, *trav;
91   for (trav = solist; trav != nullptr; trav = trav->next) {
92     if (trav == si) {
93       break;
94     }
95     prev = trav;
96   }
97 
98   if (trav == nullptr) {
99     // si was not in solist
100     PRINT("name \"%s\"@%p is not in solist!", si->get_realpath(), si);
101     return false;
102   }
103 
104   // prev will never be null, because the first entry in solist is
105   // always the static libdl_info.
106   CHECK(prev != nullptr);
107   prev->next = si->next;
108   if (si == sonext) {
109     sonext = prev;
110   }
111 
112   return true;
113 }
114 
solist_get_head()115 soinfo* solist_get_head() {
116   return solist;
117 }
118 
solist_get_somain()119 soinfo* solist_get_somain() {
120   return somain;
121 }
122 
solist_get_vdso()123 soinfo* solist_get_vdso() {
124   return vdso;
125 }
126 
127 bool g_is_ldd;
128 int g_ld_debug_verbosity;
129 
130 static std::vector<std::string> g_ld_preload_names;
131 
132 static std::vector<soinfo*> g_ld_preloads;
133 
parse_path(const char * path,const char * delimiters,std::vector<std::string> * resolved_paths)134 static void parse_path(const char* path, const char* delimiters,
135                        std::vector<std::string>* resolved_paths) {
136   std::vector<std::string> paths;
137   split_path(path, delimiters, &paths);
138   resolve_paths(paths, resolved_paths);
139 }
140 
parse_LD_LIBRARY_PATH(const char * path)141 static void parse_LD_LIBRARY_PATH(const char* path) {
142   std::vector<std::string> ld_libary_paths;
143   parse_path(path, ":", &ld_libary_paths);
144   g_default_namespace.set_ld_library_paths(std::move(ld_libary_paths));
145 }
146 
parse_LD_PRELOAD(const char * path)147 static void parse_LD_PRELOAD(const char* path) {
148   g_ld_preload_names.clear();
149   if (path != nullptr) {
150     // We have historically supported ':' as well as ' ' in LD_PRELOAD.
151     g_ld_preload_names = android::base::Split(path, " :");
152     g_ld_preload_names.erase(std::remove_if(g_ld_preload_names.begin(), g_ld_preload_names.end(),
153                                             [](const std::string& s) { return s.empty(); }),
154                              g_ld_preload_names.end());
155   }
156 }
157 
158 // An empty list of soinfos
159 static soinfo_list_t g_empty_list;
160 
add_vdso()161 static void add_vdso() {
162   ElfW(Ehdr)* ehdr_vdso = reinterpret_cast<ElfW(Ehdr)*>(getauxval(AT_SYSINFO_EHDR));
163   if (ehdr_vdso == nullptr) {
164     return;
165   }
166 
167   soinfo* si = soinfo_alloc(&g_default_namespace, "[vdso]", nullptr, 0, 0);
168 
169   si->phdr = reinterpret_cast<ElfW(Phdr)*>(reinterpret_cast<char*>(ehdr_vdso) + ehdr_vdso->e_phoff);
170   si->phnum = ehdr_vdso->e_phnum;
171   si->base = reinterpret_cast<ElfW(Addr)>(ehdr_vdso);
172   si->size = phdr_table_get_load_size(si->phdr, si->phnum);
173   si->load_bias = get_elf_exec_load_bias(ehdr_vdso);
174 
175   si->prelink_image();
176   si->link_image(SymbolLookupList(si), si, nullptr, nullptr);
177   // prevents accidental unloads...
178   si->set_dt_flags_1(si->get_dt_flags_1() | DF_1_NODELETE);
179   si->set_linked();
180   si->call_constructors();
181 
182   vdso = si;
183 }
184 
185 // Initializes an soinfo's link_map_head field using other fields from the
186 // soinfo (phdr, phnum, load_bias). The soinfo's realpath must not change after
187 // this function is called.
init_link_map_head(soinfo & info)188 static void init_link_map_head(soinfo& info) {
189   auto& map = info.link_map_head;
190   map.l_addr = info.load_bias;
191   map.l_name = const_cast<char*>(info.get_realpath());
192   phdr_table_get_dynamic_section(info.phdr, info.phnum, info.load_bias, &map.l_ld, nullptr);
193 }
194 
195 extern "C" int __system_properties_init(void);
196 
197 struct ExecutableInfo {
198   std::string path;
199   struct stat file_stat;
200   const ElfW(Phdr)* phdr;
201   size_t phdr_count;
202   ElfW(Addr) entry_point;
203 };
204 
get_executable_info(const char * arg_path)205 static ExecutableInfo get_executable_info(const char* arg_path) {
206   ExecutableInfo result = {};
207   char const* exe_path = "/proc/self/exe";
208 
209   // Stat "/proc/self/exe" instead of executable_path because
210   // the executable could be unlinked by this point and it should
211   // not cause a crash (see http://b/31084669)
212   if (TEMP_FAILURE_RETRY(stat(exe_path, &result.file_stat) == -1)) {
213     // Fallback to argv[0] for the case where /proc isn't available
214     if (TEMP_FAILURE_RETRY(stat(arg_path, &result.file_stat) == -1)) {
215       async_safe_fatal("unable to stat either \"/proc/self/exe\" or \"%s\": %s",
216           arg_path, strerror(errno));
217     }
218     exe_path = arg_path;
219   }
220 
221   // Path might be a symlink
222   char sym_path[PATH_MAX];
223   ssize_t sym_path_len = readlink(exe_path, sym_path, sizeof(sym_path));
224   if (sym_path_len > 0 && sym_path_len < static_cast<ssize_t>(sizeof(sym_path))) {
225     result.path = std::string(sym_path, sym_path_len);
226   } else {
227     result.path = std::string(exe_path, strlen(exe_path));
228   }
229 
230   result.phdr = reinterpret_cast<const ElfW(Phdr)*>(getauxval(AT_PHDR));
231   result.phdr_count = getauxval(AT_PHNUM);
232   result.entry_point = getauxval(AT_ENTRY);
233   return result;
234 }
235 
236 #if defined(__LP64__)
237 static char kFallbackLinkerPath[] = "/system/bin/linker64";
238 #else
239 static char kFallbackLinkerPath[] = "/system/bin/linker";
240 #endif
241 
242 __printflike(1, 2)
__linker_error(const char * fmt,...)243 static void __linker_error(const char* fmt, ...) {
244   va_list ap;
245 
246   va_start(ap, fmt);
247   async_safe_format_fd_va_list(STDERR_FILENO, fmt, ap);
248   va_end(ap);
249 
250   va_start(ap, fmt);
251   async_safe_format_log_va_list(ANDROID_LOG_FATAL, "linker", fmt, ap);
252   va_end(ap);
253 
254   _exit(EXIT_FAILURE);
255 }
256 
__linker_cannot_link(const char * argv0)257 static void __linker_cannot_link(const char* argv0) {
258   __linker_error("CANNOT LINK EXECUTABLE \"%s\": %s\n",
259                  argv0,
260                  linker_get_error_buffer());
261 }
262 
263 // Load an executable. Normally the kernel has already loaded the executable when the linker
264 // starts. The linker can be invoked directly on an executable, though, and then the linker must
265 // load it. This function doesn't load dependencies or resolve relocations.
load_executable(const char * orig_path)266 static ExecutableInfo load_executable(const char* orig_path) {
267   ExecutableInfo result = {};
268 
269   if (orig_path[0] != '/') {
270     __linker_error("error: expected absolute path: \"%s\"\n", orig_path);
271   }
272 
273   off64_t file_offset;
274   android::base::unique_fd fd(open_executable(orig_path, &file_offset, &result.path));
275   if (fd.get() == -1) {
276     __linker_error("error: unable to open file \"%s\"\n", orig_path);
277   }
278 
279   if (TEMP_FAILURE_RETRY(fstat(fd.get(), &result.file_stat)) == -1) {
280     __linker_error("error: unable to stat \"%s\": %s\n", result.path.c_str(), strerror(errno));
281   }
282 
283   ElfReader elf_reader;
284   if (!elf_reader.Read(result.path.c_str(), fd.get(), file_offset, result.file_stat.st_size)) {
285     __linker_error("error: %s\n", linker_get_error_buffer());
286   }
287   address_space_params address_space;
288   if (!elf_reader.Load(&address_space)) {
289     __linker_error("error: %s\n", linker_get_error_buffer());
290   }
291 
292   result.phdr = elf_reader.loaded_phdr();
293   result.phdr_count = elf_reader.phdr_count();
294   result.entry_point = elf_reader.entry_point();
295   return result;
296 }
297 
platform_properties_init()298 static void platform_properties_init() {
299 #if defined(__aarch64__)
300   const unsigned long hwcap2 = getauxval(AT_HWCAP2);
301   g_platform_properties.bti_supported = (hwcap2 & HWCAP2_BTI) != 0;
302 #endif
303 }
304 
linker_main(KernelArgumentBlock & args,const char * exe_to_load)305 static ElfW(Addr) linker_main(KernelArgumentBlock& args, const char* exe_to_load) {
306   ProtectedDataGuard guard;
307 
308 #if TIMING
309   struct timeval t0, t1;
310   gettimeofday(&t0, 0);
311 #endif
312 
313   // Sanitize the environment.
314   __libc_init_AT_SECURE(args.envp);
315 
316   // Initialize system properties
317   __system_properties_init(); // may use 'environ'
318 
319   // Initialize platform properties.
320   platform_properties_init();
321 
322   // Register the debuggerd signal handler.
323   linker_debuggerd_init();
324 
325   g_linker_logger.ResetState();
326 
327   // Get a few environment variables.
328   const char* LD_DEBUG = getenv("LD_DEBUG");
329   if (LD_DEBUG != nullptr) {
330     g_ld_debug_verbosity = atoi(LD_DEBUG);
331   }
332 
333 #if defined(__LP64__)
334   INFO("[ Android dynamic linker (64-bit) ]");
335 #else
336   INFO("[ Android dynamic linker (32-bit) ]");
337 #endif
338 
339   // These should have been sanitized by __libc_init_AT_SECURE, but the test
340   // doesn't cost us anything.
341   const char* ldpath_env = nullptr;
342   const char* ldpreload_env = nullptr;
343   if (!getauxval(AT_SECURE)) {
344     ldpath_env = getenv("LD_LIBRARY_PATH");
345     if (ldpath_env != nullptr) {
346       INFO("[ LD_LIBRARY_PATH set to \"%s\" ]", ldpath_env);
347     }
348     ldpreload_env = getenv("LD_PRELOAD");
349     if (ldpreload_env != nullptr) {
350       INFO("[ LD_PRELOAD set to \"%s\" ]", ldpreload_env);
351     }
352   }
353 
354   const ExecutableInfo exe_info = exe_to_load ? load_executable(exe_to_load) :
355                                                 get_executable_info(args.argv[0]);
356 
357   INFO("[ Linking executable \"%s\" ]", exe_info.path.c_str());
358 
359   // Initialize the main exe's soinfo.
360   soinfo* si = soinfo_alloc(&g_default_namespace,
361                             exe_info.path.c_str(), &exe_info.file_stat,
362                             0, RTLD_GLOBAL);
363   somain = si;
364   si->phdr = exe_info.phdr;
365   si->phnum = exe_info.phdr_count;
366   get_elf_base_from_phdr(si->phdr, si->phnum, &si->base, &si->load_bias);
367   si->size = phdr_table_get_load_size(si->phdr, si->phnum);
368   si->dynamic = nullptr;
369   si->set_main_executable();
370   init_link_map_head(*si);
371 
372   set_bss_vma_name(si);
373 
374   // Use the executable's PT_INTERP string as the solinker filename in the
375   // dynamic linker's module list. gdb reads both PT_INTERP and the module list,
376   // and if the paths for the linker are different, gdb will report that the
377   // PT_INTERP linker path was unloaded once the module list is initialized.
378   // There are three situations to handle:
379   //  - the APEX linker (/system/bin/linker[64] -> /apex/.../linker[64])
380   //  - the ASAN linker (/system/bin/linker_asan[64] -> /apex/.../linker[64])
381   //  - the bootstrap linker (/system/bin/bootstrap/linker[64])
382   const char *interp = phdr_table_get_interpreter_name(somain->phdr, somain->phnum,
383                                                        somain->load_bias);
384   if (interp == nullptr) {
385     // This case can happen if the linker attempts to execute itself
386     // (e.g. "linker64 /system/bin/linker64").
387     interp = kFallbackLinkerPath;
388   }
389   solinker->set_realpath(interp);
390   init_link_map_head(*solinker);
391 
392 #if defined(__aarch64__)
393   if (exe_to_load == nullptr) {
394     // Kernel does not add PROT_BTI to executable pages of the loaded ELF.
395     // Apply appropriate protections here if it is needed.
396     auto note_gnu_property = GnuPropertySection(somain);
397     if (note_gnu_property.IsBTICompatible() &&
398         (phdr_table_protect_segments(somain->phdr, somain->phnum, somain->load_bias,
399                                      &note_gnu_property) < 0)) {
400       __linker_error("error: can't protect segments for \"%s\": %s", exe_info.path.c_str(),
401                      strerror(errno));
402     }
403   }
404 
405   __libc_init_mte(somain->phdr, somain->phnum, somain->load_bias, args.argv);
406 #endif
407 
408   // Register the main executable and the linker upfront to have
409   // gdb aware of them before loading the rest of the dependency
410   // tree.
411   //
412   // gdb expects the linker to be in the debug shared object list.
413   // Without this, gdb has trouble locating the linker's ".text"
414   // and ".plt" sections. Gdb could also potentially use this to
415   // relocate the offset of our exported 'rtld_db_dlactivity' symbol.
416   //
417   insert_link_map_into_debug_map(&si->link_map_head);
418   insert_link_map_into_debug_map(&solinker->link_map_head);
419 
420   add_vdso();
421 
422   ElfW(Ehdr)* elf_hdr = reinterpret_cast<ElfW(Ehdr)*>(si->base);
423 
424   // We haven't supported non-PIE since Lollipop for security reasons.
425   if (elf_hdr->e_type != ET_DYN) {
426     // We don't use async_safe_fatal here because we don't want a tombstone:
427     // even after several years we still find ourselves on app compatibility
428     // investigations because some app's trying to launch an executable that
429     // hasn't worked in at least three years, and we've "helpfully" dropped a
430     // tombstone for them. The tombstone never provided any detail relevant to
431     // fixing the problem anyway, and the utility of drawing extra attention
432     // to the problem is non-existent at this late date.
433     async_safe_format_fd(STDERR_FILENO,
434                          "\"%s\": error: Android 5.0 and later only support "
435                          "position-independent executables (-fPIE).\n",
436                          g_argv[0]);
437     _exit(EXIT_FAILURE);
438   }
439 
440   // Use LD_LIBRARY_PATH and LD_PRELOAD (but only if we aren't setuid/setgid).
441   parse_LD_LIBRARY_PATH(ldpath_env);
442   parse_LD_PRELOAD(ldpreload_env);
443 
444   std::vector<android_namespace_t*> namespaces = init_default_namespaces(exe_info.path.c_str());
445 
446   if (!si->prelink_image()) __linker_cannot_link(g_argv[0]);
447 
448   // add somain to global group
449   si->set_dt_flags_1(si->get_dt_flags_1() | DF_1_GLOBAL);
450   // ... and add it to all other linked namespaces
451   for (auto linked_ns : namespaces) {
452     if (linked_ns != &g_default_namespace) {
453       linked_ns->add_soinfo(somain);
454       somain->add_secondary_namespace(linked_ns);
455     }
456   }
457 
458   linker_setup_exe_static_tls(g_argv[0]);
459 
460   // Load ld_preloads and dependencies.
461   std::vector<const char*> needed_library_name_list;
462   size_t ld_preloads_count = 0;
463 
464   for (const auto& ld_preload_name : g_ld_preload_names) {
465     needed_library_name_list.push_back(ld_preload_name.c_str());
466     ++ld_preloads_count;
467   }
468 
469   for_each_dt_needed(si, [&](const char* name) {
470     needed_library_name_list.push_back(name);
471   });
472 
473   const char** needed_library_names = &needed_library_name_list[0];
474   size_t needed_libraries_count = needed_library_name_list.size();
475 
476   if (needed_libraries_count > 0 &&
477       !find_libraries(&g_default_namespace,
478                       si,
479                       needed_library_names,
480                       needed_libraries_count,
481                       nullptr,
482                       &g_ld_preloads,
483                       ld_preloads_count,
484                       RTLD_GLOBAL,
485                       nullptr,
486                       true /* add_as_children */,
487                       &namespaces)) {
488     __linker_cannot_link(g_argv[0]);
489   } else if (needed_libraries_count == 0) {
490     if (!si->link_image(SymbolLookupList(si), si, nullptr, nullptr)) {
491       __linker_cannot_link(g_argv[0]);
492     }
493     si->increment_ref_count();
494   }
495 
496   linker_finalize_static_tls();
497   __libc_init_main_thread_final();
498 
499   if (!get_cfi_shadow()->InitialLinkDone(solist)) __linker_cannot_link(g_argv[0]);
500 
501   si->call_pre_init_constructors();
502   si->call_constructors();
503 
504 #if TIMING
505   gettimeofday(&t1, nullptr);
506   PRINT("LINKER TIME: %s: %d microseconds", g_argv[0],
507         static_cast<int>(((static_cast<long long>(t1.tv_sec) * 1000000LL) +
508                           static_cast<long long>(t1.tv_usec)) -
509                          ((static_cast<long long>(t0.tv_sec) * 1000000LL) +
510                           static_cast<long long>(t0.tv_usec))));
511 #endif
512 #if STATS
513   print_linker_stats();
514 #endif
515 #if TIMING || STATS
516   fflush(stdout);
517 #endif
518 
519   // We are about to hand control over to the executable loaded.  We don't want
520   // to leave dirty pages behind unnecessarily.
521   purge_unused_memory();
522 
523   ElfW(Addr) entry = exe_info.entry_point;
524   TRACE("[ Ready to execute \"%s\" @ %p ]", si->get_realpath(), reinterpret_cast<void*>(entry));
525   return entry;
526 }
527 
528 /* Compute the load-bias of an existing executable. This shall only
529  * be used to compute the load bias of an executable or shared library
530  * that was loaded by the kernel itself.
531  *
532  * Input:
533  *    elf    -> address of ELF header, assumed to be at the start of the file.
534  * Return:
535  *    load bias, i.e. add the value of any p_vaddr in the file to get
536  *    the corresponding address in memory.
537  */
get_elf_exec_load_bias(const ElfW (Ehdr)* elf)538 static ElfW(Addr) get_elf_exec_load_bias(const ElfW(Ehdr)* elf) {
539   ElfW(Addr) offset = elf->e_phoff;
540   const ElfW(Phdr)* phdr_table =
541       reinterpret_cast<const ElfW(Phdr)*>(reinterpret_cast<uintptr_t>(elf) + offset);
542   const ElfW(Phdr)* phdr_end = phdr_table + elf->e_phnum;
543 
544   for (const ElfW(Phdr)* phdr = phdr_table; phdr < phdr_end; phdr++) {
545     if (phdr->p_type == PT_LOAD) {
546       return reinterpret_cast<ElfW(Addr)>(elf) + phdr->p_offset - phdr->p_vaddr;
547     }
548   }
549   return 0;
550 }
551 
552 /* Find the load bias and base address of an executable or shared object loaded
553  * by the kernel. The ELF file's PHDR table must have a PT_PHDR entry.
554  *
555  * A VDSO doesn't have a PT_PHDR entry in its PHDR table.
556  */
get_elf_base_from_phdr(const ElfW (Phdr)* phdr_table,size_t phdr_count,ElfW (Addr)* base,ElfW (Addr)* load_bias)557 static void get_elf_base_from_phdr(const ElfW(Phdr)* phdr_table, size_t phdr_count,
558                                    ElfW(Addr)* base, ElfW(Addr)* load_bias) {
559   for (size_t i = 0; i < phdr_count; ++i) {
560     if (phdr_table[i].p_type == PT_PHDR) {
561       *load_bias = reinterpret_cast<ElfW(Addr)>(phdr_table) - phdr_table[i].p_vaddr;
562       *base = reinterpret_cast<ElfW(Addr)>(phdr_table) - phdr_table[i].p_offset;
563       return;
564     }
565   }
566   async_safe_fatal("Could not find a PHDR: broken executable?");
567 }
568 
569 /*
570  * Set anonymous VMA name for .bss section.  For DSOs loaded by the linker, this
571  * is done by ElfReader.  This function is here for DSOs loaded by the kernel,
572  * namely the linker itself and the main executable.
573  */
set_bss_vma_name(soinfo * si)574 static void set_bss_vma_name(soinfo* si) {
575   for (size_t i = 0; i < si->phnum; ++i) {
576     auto phdr = &si->phdr[i];
577 
578     if (phdr->p_type != PT_LOAD) {
579       continue;
580     }
581 
582     ElfW(Addr) seg_start = phdr->p_vaddr + si->load_bias;
583     ElfW(Addr) seg_page_end = PAGE_END(seg_start + phdr->p_memsz);
584     ElfW(Addr) seg_file_end = PAGE_END(seg_start + phdr->p_filesz);
585 
586     if (seg_page_end > seg_file_end) {
587       prctl(PR_SET_VMA, PR_SET_VMA_ANON_NAME,
588             reinterpret_cast<void*>(seg_file_end), seg_page_end - seg_file_end,
589             ".bss");
590     }
591   }
592 }
593 
594 #if defined(USE_RELA)
595 using RelType = ElfW(Rela);
596 const unsigned kRelTag = DT_RELA;
597 const unsigned kRelSzTag = DT_RELASZ;
598 #else
599 using RelType = ElfW(Rel);
600 const unsigned kRelTag = DT_REL;
601 const unsigned kRelSzTag = DT_RELSZ;
602 #endif
603 
604 extern __LIBC_HIDDEN__ ElfW(Ehdr) __ehdr_start;
605 
call_ifunc_resolvers_for_section(RelType * begin,RelType * end)606 static void call_ifunc_resolvers_for_section(RelType* begin, RelType* end) {
607   auto ehdr = reinterpret_cast<ElfW(Addr)>(&__ehdr_start);
608   for (RelType *r = begin; r != end; ++r) {
609     if (ELFW(R_TYPE)(r->r_info) != R_GENERIC_IRELATIVE) {
610       continue;
611     }
612     ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(ehdr + r->r_offset);
613 #if defined(USE_RELA)
614     ElfW(Addr) resolver = ehdr + r->r_addend;
615 #else
616     ElfW(Addr) resolver = ehdr + *offset;
617 #endif
618     *offset = __bionic_call_ifunc_resolver(resolver);
619   }
620 }
621 
call_ifunc_resolvers()622 static void call_ifunc_resolvers() {
623   // Find the IRELATIVE relocations using the DT_JMPREL and DT_PLTRELSZ, or DT_RELA? and DT_RELA?SZ
624   // dynamic tags.
625   auto ehdr = reinterpret_cast<ElfW(Addr)>(&__ehdr_start);
626   auto* phdr = reinterpret_cast<ElfW(Phdr)*>(ehdr + __ehdr_start.e_phoff);
627   for (size_t i = 0; i != __ehdr_start.e_phnum; ++i) {
628     if (phdr[i].p_type != PT_DYNAMIC) {
629       continue;
630     }
631     auto *dyn = reinterpret_cast<ElfW(Dyn)*>(ehdr + phdr[i].p_vaddr);
632     ElfW(Addr) pltrel = 0, pltrelsz = 0, rel = 0, relsz = 0;
633     for (size_t j = 0, size = phdr[i].p_filesz / sizeof(ElfW(Dyn)); j != size; ++j) {
634       if (dyn[j].d_tag == DT_JMPREL) {
635         pltrel = dyn[j].d_un.d_ptr;
636       } else if (dyn[j].d_tag == DT_PLTRELSZ) {
637         pltrelsz = dyn[j].d_un.d_ptr;
638       } else if (dyn[j].d_tag == kRelTag) {
639         rel = dyn[j].d_un.d_ptr;
640       } else if (dyn[j].d_tag == kRelSzTag) {
641         relsz = dyn[j].d_un.d_ptr;
642       }
643     }
644     if (pltrel && pltrelsz) {
645       call_ifunc_resolvers_for_section(reinterpret_cast<RelType*>(ehdr + pltrel),
646                                        reinterpret_cast<RelType*>(ehdr + pltrel + pltrelsz));
647     }
648     if (rel && relsz) {
649       call_ifunc_resolvers_for_section(reinterpret_cast<RelType*>(ehdr + rel),
650                                        reinterpret_cast<RelType*>(ehdr + rel + relsz));
651     }
652   }
653 }
654 
655 // Usable before ifunc resolvers have been called. This function is compiled with -ffreestanding.
linker_memclr(void * dst,size_t cnt)656 static void linker_memclr(void* dst, size_t cnt) {
657   for (size_t i = 0; i < cnt; ++i) {
658     reinterpret_cast<char*>(dst)[i] = '\0';
659   }
660 }
661 
662 // Detect an attempt to run the linker on itself. e.g.:
663 //   /system/bin/linker64 /system/bin/linker64
664 // Use priority-1 to run this constructor before other constructors.
detect_self_exec()665 __attribute__((constructor(1))) static void detect_self_exec() {
666   // Normally, the linker initializes the auxv global before calling its
667   // constructors. If the linker loads itself, though, the first loader calls
668   // the second loader's constructors before calling __linker_init.
669   if (__libc_shared_globals()->auxv != nullptr) {
670     return;
671   }
672 #if defined(__i386__)
673   // We don't have access to the auxv struct from here, so use the int 0x80
674   // fallback.
675   __libc_sysinfo = reinterpret_cast<void*>(__libc_int0x80);
676 #endif
677   __linker_error("error: linker cannot load itself\n");
678 }
679 
680 static ElfW(Addr) __attribute__((noinline))
681 __linker_init_post_relocation(KernelArgumentBlock& args, soinfo& linker_so);
682 
683 /*
684  * This is the entry point for the linker, called from begin.S. This
685  * method is responsible for fixing the linker's own relocations, and
686  * then calling __linker_init_post_relocation().
687  *
688  * Because this method is called before the linker has fixed it's own
689  * relocations, any attempt to reference an extern variable, extern
690  * function, or other GOT reference will generate a segfault.
691  */
__linker_init(void * raw_args)692 extern "C" ElfW(Addr) __linker_init(void* raw_args) {
693   // Initialize TLS early so system calls and errno work.
694   KernelArgumentBlock args(raw_args);
695   bionic_tcb temp_tcb __attribute__((uninitialized));
696   linker_memclr(&temp_tcb, sizeof(temp_tcb));
697   __libc_init_main_thread_early(args, &temp_tcb);
698 
699   // When the linker is run by itself (rather than as an interpreter for
700   // another program), AT_BASE is 0.
701   ElfW(Addr) linker_addr = getauxval(AT_BASE);
702   if (linker_addr == 0) {
703     // The AT_PHDR and AT_PHNUM aux values describe this linker instance, so use
704     // the phdr to find the linker's base address.
705     ElfW(Addr) load_bias;
706     get_elf_base_from_phdr(
707       reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)), getauxval(AT_PHNUM),
708       &linker_addr, &load_bias);
709   }
710 
711   ElfW(Ehdr)* elf_hdr = reinterpret_cast<ElfW(Ehdr)*>(linker_addr);
712   ElfW(Phdr)* phdr = reinterpret_cast<ElfW(Phdr)*>(linker_addr + elf_hdr->e_phoff);
713 
714   // string.h functions must not be used prior to calling the linker's ifunc resolvers.
715   call_ifunc_resolvers();
716 
717   soinfo tmp_linker_so(nullptr, nullptr, nullptr, 0, 0);
718 
719   tmp_linker_so.base = linker_addr;
720   tmp_linker_so.size = phdr_table_get_load_size(phdr, elf_hdr->e_phnum);
721   tmp_linker_so.load_bias = get_elf_exec_load_bias(elf_hdr);
722   tmp_linker_so.dynamic = nullptr;
723   tmp_linker_so.phdr = phdr;
724   tmp_linker_so.phnum = elf_hdr->e_phnum;
725   tmp_linker_so.set_linker_flag();
726 
727   // Prelink the linker so we can access linker globals.
728   if (!tmp_linker_so.prelink_image()) __linker_cannot_link(args.argv[0]);
729   if (!tmp_linker_so.link_image(SymbolLookupList(&tmp_linker_so), &tmp_linker_so, nullptr, nullptr)) __linker_cannot_link(args.argv[0]);
730 
731   return __linker_init_post_relocation(args, tmp_linker_so);
732 }
733 
734 /*
735  * This code is called after the linker has linked itself and fixed its own
736  * GOT. It is safe to make references to externs and other non-local data at
737  * this point. The compiler sometimes moves GOT references earlier in a
738  * function, so avoid inlining this function (http://b/80503879).
739  */
740 static ElfW(Addr) __attribute__((noinline))
__linker_init_post_relocation(KernelArgumentBlock & args,soinfo & tmp_linker_so)741 __linker_init_post_relocation(KernelArgumentBlock& args, soinfo& tmp_linker_so) {
742   // Finish initializing the main thread.
743   __libc_init_main_thread_late();
744 
745   // We didn't protect the linker's RELRO pages in link_image because we
746   // couldn't make system calls on x86 at that point, but we can now...
747   if (!tmp_linker_so.protect_relro()) __linker_cannot_link(args.argv[0]);
748 
749   // And we can set VMA name for the bss section now
750   set_bss_vma_name(&tmp_linker_so);
751 
752   // Initialize the linker's static libc's globals
753   __libc_init_globals();
754 
755   // Initialize the linker's own global variables
756   tmp_linker_so.call_constructors();
757 
758   // Setting the linker soinfo's soname can allocate heap memory, so delay it until here.
759   for (const ElfW(Dyn)* d = tmp_linker_so.dynamic; d->d_tag != DT_NULL; ++d) {
760     if (d->d_tag == DT_SONAME) {
761       tmp_linker_so.set_soname(tmp_linker_so.get_string(d->d_un.d_val));
762     }
763   }
764 
765   // When the linker is run directly rather than acting as PT_INTERP, parse
766   // arguments and determine the executable to load. When it's instead acting
767   // as PT_INTERP, AT_ENTRY will refer to the loaded executable rather than the
768   // linker's _start.
769   const char* exe_to_load = nullptr;
770   if (getauxval(AT_ENTRY) == reinterpret_cast<uintptr_t>(&_start)) {
771     if (args.argc == 3 && !strcmp(args.argv[1], "--list")) {
772       // We're being asked to behave like ldd(1).
773       g_is_ldd = true;
774       exe_to_load = args.argv[2];
775     } else if (args.argc <= 1 || !strcmp(args.argv[1], "--help")) {
776       async_safe_format_fd(STDOUT_FILENO,
777          "Usage: %s [--list] PROGRAM [ARGS-FOR-PROGRAM...]\n"
778          "       %s [--list] path.zip!/PROGRAM [ARGS-FOR-PROGRAM...]\n"
779          "\n"
780          "A helper program for linking dynamic executables. Typically, the kernel loads\n"
781          "this program because it's the PT_INTERP of a dynamic executable.\n"
782          "\n"
783          "This program can also be run directly to load and run a dynamic executable. The\n"
784          "executable can be inside a zip file if it's stored uncompressed and at a\n"
785          "page-aligned offset.\n"
786          "\n"
787          "The --list option gives behavior equivalent to ldd(1) on other systems.\n",
788          args.argv[0], args.argv[0]);
789       _exit(EXIT_SUCCESS);
790     } else {
791       exe_to_load = args.argv[1];
792       __libc_shared_globals()->initial_linker_arg_count = 1;
793     }
794   }
795 
796   // store argc/argv/envp to use them for calling constructors
797   g_argc = args.argc - __libc_shared_globals()->initial_linker_arg_count;
798   g_argv = args.argv + __libc_shared_globals()->initial_linker_arg_count;
799   g_envp = args.envp;
800   __libc_shared_globals()->init_progname = g_argv[0];
801 
802   // Initialize static variables. Note that in order to
803   // get correct libdl_info we need to call constructors
804   // before get_libdl_info().
805   sonext = solist = solinker = get_libdl_info(tmp_linker_so);
806   g_default_namespace.add_soinfo(solinker);
807 
808   ElfW(Addr) start_address = linker_main(args, exe_to_load);
809 
810   if (g_is_ldd) _exit(EXIT_SUCCESS);
811 
812   INFO("[ Jumping to _start (%p)... ]", reinterpret_cast<void*>(start_address));
813 
814   // Return the address that the calling assembly stub should jump to.
815   return start_address;
816 }
817