From patchwork Tue Oct 14 21:42:12 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Matthew Fortune X-Patchwork-Id: 3229 Received: (qmail 18620 invoked by alias); 14 Oct 2014 21:42:19 -0000 Mailing-List: contact libc-alpha-help@sourceware.org; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: libc-alpha-owner@sourceware.org Delivered-To: mailing list libc-alpha@sourceware.org Received: (qmail 18611 invoked by uid 89); 14 Oct 2014 21:42:18 -0000 Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=-2.1 required=5.0 tests=AWL, BAYES_00, SPF_PASS, T_RP_MATCHES_RCVD autolearn=ham version=3.3.2 X-HELO: mailapp01.imgtec.com From: Matthew Fortune To: Roland McGrath CC: "libc-alpha@sourceware.org" , "Joseph Myers (joseph@codesourcery.com)" , Will Newton Subject: RE: Create a hook for inspecting program headers during library load Date: Tue, 14 Oct 2014 21:42:12 +0000 Message-ID: <6D39441BF12EF246A7ABCE6654B0235320F27153@LEMAIL01.le.imgtec.org> References: <6D39441BF12EF246A7ABCE6654B0235320F18A1B@LEMAIL01.le.imgtec.org> <20141001214949.239022C3AAD@topped-with-meat.com> <6D39441BF12EF246A7ABCE6654B0235320F18CA4@LEMAIL01.le.imgtec.org> <20141001230906.9B9852C3AAA@topped-with-meat.com> <6D39441BF12EF246A7ABCE6654B0235320F1971F@LEMAIL01.le.imgtec.org> <6D39441BF12EF246A7ABCE6654B0235320F197DF@LEMAIL01.le.imgtec.org> <6D39441BF12EF246A7ABCE6654B0235320F199DC@LEMAIL01.le.imgtec.org> <20141003183255.153452C3AB6@topped-with-meat.com> In-Reply-To: <20141003183255.153452C3AB6@topped-with-meat.com> MIME-Version: 1.0 Hi Roland, An updated version of this patch is below which should address all of your comments. It took some time as I have been reworking the MIPS implementation and wanted to make sure that didn't impact the definition of the hook. Thanks, Matthew * elf/dl-machine-reject-phdr.h: New file. * elf/dl-load.c: #include that. (open_verify): Call elf_machine_reject_phdr_p and ignore the file if that returned true. --- elf/dl-load.c | 6 ++++++ elf/dl-machine-reject-phdr.h | 34 ++++++++++++++++++++++++++++++++++ 2 files changed, 40 insertions(+) create mode 100644 elf/dl-machine-reject-phdr.h diff --git a/elf/dl-load.c b/elf/dl-load.c index 9dd40e3..ee3c425 100644 --- a/elf/dl-load.c +++ b/elf/dl-load.c @@ -41,6 +41,7 @@ #include #include #include +#include #include @@ -1697,6 +1698,11 @@ open_verify (const char *name, struct filebuf *fbp, struct link_map *loader, } } + if (__glibc_unlikely (elf_machine_reject_phdr_p + (phdr, ehdr->e_phnum, fbp->buf, fbp->len, + loader, fd))) + goto close_and_out; + /* Check .note.ABI-tag if present. */ for (ph = phdr; ph < &phdr[ehdr->e_phnum]; ++ph) if (ph->p_type == PT_NOTE && ph->p_filesz >= 32 && ph->p_align >= 4) diff --git a/elf/dl-machine-reject-phdr.h b/elf/dl-machine-reject-phdr.h new file mode 100644 index 0000000..d110a32 --- /dev/null +++ b/elf/dl-machine-reject-phdr.h @@ -0,0 +1,34 @@ +/* Machine-dependent program header inspection for the ELF loader. + Copyright (C) 2014 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#ifndef _DL_MACHINE_REJECT_PHDR_H +#define _DL_MACHINE_REJECT_PHDR_H 1 + +#include + +/* Return true iff ELF program headers are incompatible with the running + host. */ +static inline bool +elf_machine_reject_phdr_p (const ElfW(Phdr) *phdr, uint_fast16_t phnum, + const char *buf, size_t len, struct link_map *map, + int fd) +{ + return false; +} + +#endif /* dl-machine-reject-phdr.h */