xref: /linux/tools/objtool/builtin-check.c (revision 8308fd001927f5bdc37a9c9f9c413baec3fb7bbe)
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  * Copyright (C) 2015-2017 Josh Poimboeuf <jpoimboe@redhat.com>
4  */
5 
6 #include <subcmd/parse-options.h>
7 #include <string.h>
8 #include <stdlib.h>
9 #include <fcntl.h>
10 #include <unistd.h>
11 #include <errno.h>
12 #include <sys/stat.h>
13 #include <sys/sendfile.h>
14 #include <objtool/builtin.h>
15 #include <objtool/objtool.h>
16 #include <objtool/warn.h>
17 
18 #define ORIG_SUFFIX ".orig"
19 
20 int orig_argc;
21 static char **orig_argv;
22 const char *objname;
23 struct opts opts;
24 
25 static const char * const check_usage[] = {
26 	"objtool <actions> [<options>] file.o",
27 	NULL,
28 };
29 
30 static const char * const env_usage[] = {
31 	"OBJTOOL_ARGS=\"<options>\"",
32 	NULL,
33 };
34 
35 static int parse_dump(const struct option *opt, const char *str, int unset)
36 {
37 	if (!str || !strcmp(str, "orc")) {
38 		opts.dump_orc = true;
39 		return 0;
40 	}
41 
42 	return -1;
43 }
44 
45 static int parse_hacks(const struct option *opt, const char *str, int unset)
46 {
47 	bool found = false;
48 
49 	/*
50 	 * Use strstr() as a lazy method of checking for comma-separated
51 	 * options.
52 	 *
53 	 * No string provided == enable all options.
54 	 */
55 
56 	if (!str || strstr(str, "jump_label")) {
57 		opts.hack_jump_label = true;
58 		found = true;
59 	}
60 
61 	if (!str || strstr(str, "noinstr")) {
62 		opts.hack_noinstr = true;
63 		found = true;
64 	}
65 
66 	if (!str || strstr(str, "skylake")) {
67 		opts.hack_skylake = true;
68 		found = true;
69 	}
70 
71 	return found ? 0 : -1;
72 }
73 
74 static const struct option check_options[] = {
75 	OPT_GROUP("Actions:"),
76 	OPT_BOOLEAN(0,		 "checksum", &opts.checksum, "generate per-function checksums"),
77 	OPT_BOOLEAN(0,		 "cfi", &opts.cfi, "annotate kernel control flow integrity (kCFI) function preambles"),
78 	OPT_STRING_OPTARG('d',	 "disas", &opts.disas, "function-pattern", "disassemble functions", "*"),
79 	OPT_CALLBACK_OPTARG('h', "hacks", NULL, NULL, "jump_label,noinstr,skylake", "patch toolchain bugs/limitations", parse_hacks),
80 	OPT_BOOLEAN('i',	 "ibt", &opts.ibt, "validate and annotate IBT"),
81 	OPT_BOOLEAN('m',	 "mcount", &opts.mcount, "annotate mcount/fentry calls for ftrace"),
82 	OPT_BOOLEAN(0,		 "noabs", &opts.noabs, "reject absolute references in allocatable sections"),
83 	OPT_BOOLEAN('n',	 "noinstr", &opts.noinstr, "validate noinstr rules"),
84 	OPT_BOOLEAN(0,		 "orc", &opts.orc, "generate ORC metadata"),
85 	OPT_BOOLEAN('r',	 "retpoline", &opts.retpoline, "validate and annotate retpoline usage"),
86 	OPT_BOOLEAN(0,		 "rethunk", &opts.rethunk, "validate and annotate rethunk usage"),
87 	OPT_BOOLEAN(0,		 "unret", &opts.unret, "validate entry unret placement"),
88 	OPT_INTEGER(0,		 "prefix", &opts.prefix, "generate prefix symbols"),
89 	OPT_BOOLEAN('l',	 "sls", &opts.sls, "validate straight-line-speculation mitigations"),
90 	OPT_BOOLEAN('s',	 "stackval", &opts.stackval, "validate frame pointer rules"),
91 	OPT_BOOLEAN('t',	 "static-call", &opts.static_call, "annotate static calls"),
92 	OPT_BOOLEAN('u',	 "uaccess", &opts.uaccess, "validate uaccess rules for SMAP"),
93 	OPT_CALLBACK_OPTARG(0,	 "dump", NULL, NULL, "orc", "dump metadata", parse_dump),
94 
95 	OPT_GROUP("Options:"),
96 	OPT_BOOLEAN(0,		 "backtrace", &opts.backtrace, "unwind on error"),
97 	OPT_BOOLEAN(0,		 "backup", &opts.backup, "create backup (.orig) file on warning/error"),
98 	OPT_STRING(0,		 "debug-checksum", &opts.debug_checksum,  "funcs", "enable checksum debug output"),
99 	OPT_BOOLEAN(0,		 "dry-run", &opts.dryrun, "don't write modifications"),
100 	OPT_BOOLEAN(0,		 "link", &opts.link, "object is a linked object"),
101 	OPT_BOOLEAN(0,		 "module", &opts.module, "object is part of a kernel module"),
102 	OPT_BOOLEAN(0,		 "mnop", &opts.mnop, "nop out mcount call sites"),
103 	OPT_BOOLEAN(0,		 "no-unreachable", &opts.no_unreachable, "skip 'unreachable instruction' warnings"),
104 	OPT_STRING('o',		 "output", &opts.output, "file", "output file name"),
105 	OPT_BOOLEAN(0,		 "sec-address", &opts.sec_address, "print section addresses in warnings"),
106 	OPT_BOOLEAN(0,		 "stats", &opts.stats, "print statistics"),
107 	OPT_STRING(0,		 "trace", &opts.trace, "func", "trace function validation"),
108 	OPT_BOOLEAN('v',	 "verbose", &opts.verbose, "verbose warnings"),
109 	OPT_BOOLEAN(0,		 "werror", &opts.werror, "return error on warnings"),
110 
111 	OPT_END(),
112 };
113 
114 int cmd_parse_options(int argc, const char **argv, const char * const usage[])
115 {
116 	const char *envv[16] = { };
117 	char *env;
118 	int envc;
119 
120 	env = getenv("OBJTOOL_ARGS");
121 	if (env) {
122 		envv[0] = "OBJTOOL_ARGS";
123 		for (envc = 1; envc < ARRAY_SIZE(envv); ) {
124 			envv[envc++] = env;
125 			env = strchr(env, ' ');
126 			if (!env)
127 				break;
128 			*env = '\0';
129 			env++;
130 		}
131 
132 		parse_options(envc, envv, check_options, env_usage, 0);
133 	}
134 
135 	env = getenv("OBJTOOL_VERBOSE");
136 	if (env && !strcmp(env, "1"))
137 		opts.verbose = true;
138 
139 	argc = parse_options(argc, argv, check_options, usage, 0);
140 	if (argc != 1)
141 		usage_with_options(usage, check_options);
142 	return argc;
143 }
144 
145 static bool opts_valid(void)
146 {
147 	if (opts.mnop && !opts.mcount) {
148 		ERROR("--mnop requires --mcount");
149 		return false;
150 	}
151 
152 	if (opts.noinstr && !opts.link) {
153 		ERROR("--noinstr requires --link");
154 		return false;
155 	}
156 
157 	if (opts.ibt && !opts.link) {
158 		ERROR("--ibt requires --link");
159 		return false;
160 	}
161 
162 	if (opts.unret && !opts.link) {
163 		ERROR("--unret requires --link");
164 		return false;
165 	}
166 
167 #ifndef BUILD_KLP
168 	if (opts.checksum) {
169 		ERROR("--checksum not supported; install xxhash-devel/libxxhash-dev (version >= 0.8) and recompile");
170 		return false;
171 	}
172 #endif
173 
174 	if (opts.debug_checksum && !opts.checksum) {
175 		ERROR("--debug-checksum requires --checksum");
176 		return false;
177 	}
178 
179 	if (opts.checksum		||
180 	    opts.disas			||
181 	    opts.hack_jump_label	||
182 	    opts.hack_noinstr		||
183 	    opts.ibt			||
184 	    opts.mcount			||
185 	    opts.noabs			||
186 	    opts.noinstr		||
187 	    opts.orc			||
188 	    opts.retpoline		||
189 	    opts.rethunk		||
190 	    opts.sls			||
191 	    opts.stackval		||
192 	    opts.static_call		||
193 	    opts.uaccess) {
194 		if (opts.dump_orc) {
195 			ERROR("--dump can't be combined with other actions");
196 			return false;
197 		}
198 
199 		return true;
200 	}
201 
202 	if (opts.dump_orc)
203 		return true;
204 
205 	ERROR("At least one action required");
206 	return false;
207 }
208 
209 static int copy_file(const char *src, const char *dst)
210 {
211 	size_t to_copy, copied;
212 	int dst_fd, src_fd;
213 	struct stat stat;
214 	off_t offset = 0;
215 
216 	src_fd = open(src, O_RDONLY);
217 	if (src_fd == -1) {
218 		ERROR("can't open %s for reading: %s", src, strerror(errno));
219 		return 1;
220 	}
221 
222 	dst_fd = open(dst, O_WRONLY | O_CREAT | O_TRUNC, 0400);
223 	if (dst_fd == -1) {
224 		ERROR("can't open %s for writing: %s", dst, strerror(errno));
225 		return 1;
226 	}
227 
228 	if (fstat(src_fd, &stat) == -1) {
229 		ERROR_GLIBC("fstat");
230 		return 1;
231 	}
232 
233 	if (fchmod(dst_fd, stat.st_mode) == -1) {
234 		ERROR_GLIBC("fchmod");
235 		return 1;
236 	}
237 
238 	for (to_copy = stat.st_size; to_copy > 0; to_copy -= copied) {
239 		copied = sendfile(dst_fd, src_fd, &offset, to_copy);
240 		if (copied == -1) {
241 			ERROR_GLIBC("sendfile");
242 			return 1;
243 		}
244 	}
245 
246 	close(dst_fd);
247 	close(src_fd);
248 	return 0;
249 }
250 
251 static void save_argv(int argc, const char **argv)
252 {
253 	orig_argv = calloc(argc, sizeof(char *));
254 	if (!orig_argv) {
255 		ERROR_GLIBC("calloc");
256 		exit(1);
257 	}
258 
259 	for (int i = 0; i < argc; i++) {
260 		orig_argv[i] = strdup(argv[i]);
261 		if (!orig_argv[i]) {
262 			ERROR_GLIBC("strdup(%s)", argv[i]);
263 			exit(1);
264 		}
265 	}
266 }
267 
268 int make_backup(void)
269 {
270 	char *backup;
271 
272 	/*
273 	 * Make a backup before kbuild deletes the file so the error
274 	 * can be recreated without recompiling or relinking.
275 	 */
276 	backup = malloc(strlen(objname) + strlen(ORIG_SUFFIX) + 1);
277 	if (!backup) {
278 		ERROR_GLIBC("malloc");
279 		return 1;
280 	}
281 
282 	strcpy(backup, objname);
283 	strcat(backup, ORIG_SUFFIX);
284 	if (copy_file(objname, backup))
285 		return 1;
286 
287 	/*
288 	 * Print the cmdline args to make it easier to recreate.
289 	 */
290 
291 	fprintf(stderr, "%s", orig_argv[0]);
292 
293 	for (int i = 1; i < orig_argc; i++) {
294 		char *arg = orig_argv[i];
295 
296 		/* Modify the printed args to use the backup */
297 		if (!opts.output && !strcmp(arg, objname))
298 			fprintf(stderr, " %s -o %s", backup, objname);
299 		else
300 			fprintf(stderr, " %s", arg);
301 	}
302 
303 	fprintf(stderr, "\n");
304 	return 0;
305 }
306 
307 int objtool_run(int argc, const char **argv)
308 {
309 	struct objtool_file *file;
310 	int ret = 0;
311 
312 	orig_argc = argc;
313 	save_argv(argc, argv);
314 
315 	cmd_parse_options(argc, argv, check_usage);
316 
317 	if (!opts_valid())
318 		return 1;
319 
320 	objname = argv[0];
321 
322 	if (opts.dump_orc)
323 		return orc_dump(objname);
324 
325 	if (!opts.dryrun && opts.output) {
326 		/* copy original .o file to output file */
327 		if (copy_file(objname, opts.output))
328 			return 1;
329 
330 		/* from here on, work directly on the output file */
331 		objname = opts.output;
332 	}
333 
334 	file = objtool_open_read(objname);
335 	if (!file)
336 		return 1;
337 
338 	if (!opts.link && has_multiple_files(file->elf)) {
339 		ERROR("Linked object requires --link");
340 		return 1;
341 	}
342 
343 	ret = check(file);
344 	if (ret)
345 		return ret;
346 
347 	if (!opts.dryrun && file->elf->changed && elf_write(file->elf))
348 		return 1;
349 
350 	return elf_close(file->elf);
351 }
352