From patchwork Thu Oct 2 15:02:21 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Matthew Fortune X-Patchwork-Id: 3067 Received: (qmail 22219 invoked by alias); 2 Oct 2014 15:02:29 -0000 Mailing-List: contact libc-alpha-help@sourceware.org; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: libc-alpha-owner@sourceware.org Delivered-To: mailing list libc-alpha@sourceware.org Received: (qmail 22208 invoked by uid 89); 2 Oct 2014 15:02:28 -0000 Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=-2.6 required=5.0 tests=AWL, BAYES_00, RP_MATCHES_RCVD, SPF_PASS autolearn=ham version=3.3.2 X-HELO: mailapp01.imgtec.com From: Matthew Fortune To: Roland McGrath CC: "libc-alpha@sourceware.org" , "Joseph Myers (joseph@codesourcery.com)" Subject: RE: Create a hook for inspecting program headers during library load Date: Thu, 2 Oct 2014 15:02:21 +0000 Message-ID: <6D39441BF12EF246A7ABCE6654B0235320F1971F@LEMAIL01.le.imgtec.org> References: <6D39441BF12EF246A7ABCE6654B0235320F18A1B@LEMAIL01.le.imgtec.org> <20141001214949.239022C3AAD@topped-with-meat.com> <6D39441BF12EF246A7ABCE6654B0235320F18CA4@LEMAIL01.le.imgtec.org> <20141001230906.9B9852C3AAA@topped-with-meat.com> In-Reply-To: <20141001230906.9B9852C3AAA@topped-with-meat.com> MIME-Version: 1.0 Patch updated below. Though I did remember Joseph steering me away from an ifdef based interface while reworking this: https://sourceware.org/ml/libc-alpha/2014-05/msg00045.html Does this seem more appropriate? Tested for x86_64-linux-gnu. Thanks, Matthew * elf/dl-load.c (dl-load-stubs.h): Include. (open_verify): Add hook for phdr check. * elf/dl-load-stubs.h: New file. --- elf/dl-load-stubs.h | 32 ++++++++++++++++++++++++++++++++ elf/dl-load.c | 6 ++++++ 2 files changed, 38 insertions(+) create mode 100644 elf/dl-load-stubs.h diff --git a/elf/dl-load-stubs.h b/elf/dl-load-stubs.h new file mode 100644 index 0000000..8eb671d --- /dev/null +++ b/elf/dl-load-stubs.h @@ -0,0 +1,32 @@ +/* Stub implementations for loader functions. + Copyright (C) 2014 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +/* Provide a default implementation of elf_machine_reject_phdr_p if a port + has not provided its own. */ + +#ifndef ELF_MACHINE_REJECT_PHDR_P +/* Return true iff ELF program headers are incompatible with the running + host. */ +static inline bool +elf_machine_reject_phdr_p (const ElfW(Phdr) *phdr, uint_fast16_t phnum, + const char *buf, size_t len, int fd, + struct link_map *map) +{ + return false; +} +#endif diff --git a/elf/dl-load.c b/elf/dl-load.c index 016a99c..aff3506 100644 --- a/elf/dl-load.c +++ b/elf/dl-load.c @@ -31,6 +31,7 @@ #include #include #include "dynamic-link.h" +#include "dl-load-stubs.h" #include #include #include @@ -1697,6 +1698,11 @@ open_verify (const char *name, struct filebuf *fbp, struct link_map *loader, } } + if (__glibc_unlikely ( + elf_machine_reject_phdr_p (phdr, ehdr->e_phnum, fbp->buf, fbp->len, + fd, loader))) + goto close_and_out; + /* Check .note.ABI-tag if present. */ for (ph = phdr; ph < &phdr[ehdr->e_phnum]; ++ph) if (ph->p_type == PT_NOTE && ph->p_filesz >= 32 && ph->p_align >= 4)