1 // SPDX-License-Identifier: GPL-2.0-or-later 2 /* 3 * Copyright (C) 2015-2017 Josh Poimboeuf <jpoimboe@redhat.com> 4 */ 5 6 #include <subcmd/parse-options.h> 7 #include <string.h> 8 #include <stdlib.h> 9 #include <fcntl.h> 10 #include <unistd.h> 11 #include <errno.h> 12 #include <sys/stat.h> 13 #include <sys/sendfile.h> 14 #include <objtool/builtin.h> 15 #include <objtool/objtool.h> 16 #include <objtool/warn.h> 17 18 #define ORIG_SUFFIX ".orig" 19 20 int orig_argc; 21 static char **orig_argv; 22 const char *objname; 23 struct opts opts; 24 25 static const char * const check_usage[] = { 26 "objtool <actions> [<options>] file.o", 27 NULL, 28 }; 29 30 static const char * const env_usage[] = { 31 "OBJTOOL_ARGS=\"<options>\"", 32 NULL, 33 }; 34 35 static int parse_dump(const struct option *opt, const char *str, int unset) 36 { 37 if (!str || !strcmp(str, "orc")) { 38 opts.dump_orc = true; 39 return 0; 40 } 41 42 return -1; 43 } 44 45 static int parse_hacks(const struct option *opt, const char *str, int unset) 46 { 47 bool found = false; 48 49 /* 50 * Use strstr() as a lazy method of checking for comma-separated 51 * options. 52 * 53 * No string provided == enable all options. 54 */ 55 56 if (!str || strstr(str, "jump_label")) { 57 opts.hack_jump_label = true; 58 found = true; 59 } 60 61 if (!str || strstr(str, "noinstr")) { 62 opts.hack_noinstr = true; 63 found = true; 64 } 65 66 if (!str || strstr(str, "skylake")) { 67 opts.hack_skylake = true; 68 found = true; 69 } 70 71 return found ? 0 : -1; 72 } 73 74 static const struct option check_options[] = { 75 OPT_GROUP("Actions:"), 76 OPT_BOOLEAN(0, "checksum", &opts.checksum, "generate per-function checksums"), 77 OPT_BOOLEAN(0, "cfi", &opts.cfi, "annotate kernel control flow integrity (kCFI) function preambles"), 78 OPT_STRING_OPTARG('d', "disas", &opts.disas, "function-pattern", "disassemble functions", "*"), 79 OPT_CALLBACK_OPTARG('h', "hacks", NULL, NULL, "jump_label,noinstr,skylake", "patch toolchain bugs/limitations", parse_hacks), 80 OPT_BOOLEAN('i', "ibt", &opts.ibt, "validate and annotate IBT"), 81 OPT_BOOLEAN('m', "mcount", &opts.mcount, "annotate mcount/fentry calls for ftrace"), 82 OPT_BOOLEAN(0, "noabs", &opts.noabs, "reject absolute references in allocatable sections"), 83 OPT_BOOLEAN('n', "noinstr", &opts.noinstr, "validate noinstr rules"), 84 OPT_BOOLEAN(0, "orc", &opts.orc, "generate ORC metadata"), 85 OPT_BOOLEAN('r', "retpoline", &opts.retpoline, "validate and annotate retpoline usage"), 86 OPT_BOOLEAN(0, "rethunk", &opts.rethunk, "validate and annotate rethunk usage"), 87 OPT_BOOLEAN(0, "unret", &opts.unret, "validate entry unret placement"), 88 OPT_INTEGER(0, "prefix", &opts.prefix, "generate prefix symbols"), 89 OPT_BOOLEAN('l', "sls", &opts.sls, "validate straight-line-speculation mitigations"), 90 OPT_BOOLEAN('s', "stackval", &opts.stackval, "validate frame pointer rules"), 91 OPT_BOOLEAN('t', "static-call", &opts.static_call, "annotate static calls"), 92 OPT_BOOLEAN('u', "uaccess", &opts.uaccess, "validate uaccess rules for SMAP"), 93 OPT_CALLBACK_OPTARG(0, "dump", NULL, NULL, "orc", "dump metadata", parse_dump), 94 95 OPT_GROUP("Options:"), 96 OPT_BOOLEAN(0, "backtrace", &opts.backtrace, "unwind on error"), 97 OPT_BOOLEAN(0, "backup", &opts.backup, "create backup (.orig) file on warning/error"), 98 OPT_STRING(0, "debug-checksum", &opts.debug_checksum, "funcs", "enable checksum debug output"), 99 OPT_BOOLEAN(0, "dry-run", &opts.dryrun, "don't write modifications"), 100 OPT_BOOLEAN(0, "link", &opts.link, "object is a linked object"), 101 OPT_BOOLEAN(0, "module", &opts.module, "object is part of a kernel module"), 102 OPT_BOOLEAN(0, "mnop", &opts.mnop, "nop out mcount call sites"), 103 OPT_BOOLEAN(0, "no-unreachable", &opts.no_unreachable, "skip 'unreachable instruction' warnings"), 104 OPT_STRING('o', "output", &opts.output, "file", "output file name"), 105 OPT_BOOLEAN(0, "sec-address", &opts.sec_address, "print section addresses in warnings"), 106 OPT_BOOLEAN(0, "stats", &opts.stats, "print statistics"), 107 OPT_STRING(0, "trace", &opts.trace, "func", "trace function validation"), 108 OPT_BOOLEAN('v', "verbose", &opts.verbose, "verbose warnings"), 109 OPT_BOOLEAN(0, "werror", &opts.werror, "return error on warnings"), 110 111 OPT_END(), 112 }; 113 114 int cmd_parse_options(int argc, const char **argv, const char * const usage[]) 115 { 116 const char *envv[16] = { }; 117 char *env; 118 int envc; 119 120 env = getenv("OBJTOOL_ARGS"); 121 if (env) { 122 envv[0] = "OBJTOOL_ARGS"; 123 for (envc = 1; envc < ARRAY_SIZE(envv); ) { 124 envv[envc++] = env; 125 env = strchr(env, ' '); 126 if (!env) 127 break; 128 *env = '\0'; 129 env++; 130 } 131 132 parse_options(envc, envv, check_options, env_usage, 0); 133 } 134 135 env = getenv("OBJTOOL_VERBOSE"); 136 if (env && !strcmp(env, "1")) 137 opts.verbose = true; 138 139 argc = parse_options(argc, argv, check_options, usage, 0); 140 if (argc != 1) 141 usage_with_options(usage, check_options); 142 return argc; 143 } 144 145 static bool opts_valid(void) 146 { 147 if (opts.mnop && !opts.mcount) { 148 ERROR("--mnop requires --mcount"); 149 return false; 150 } 151 152 if (opts.noinstr && !opts.link) { 153 ERROR("--noinstr requires --link"); 154 return false; 155 } 156 157 if (opts.ibt && !opts.link) { 158 ERROR("--ibt requires --link"); 159 return false; 160 } 161 162 if (opts.unret && !opts.link) { 163 ERROR("--unret requires --link"); 164 return false; 165 } 166 167 #ifndef BUILD_KLP 168 if (opts.checksum) { 169 ERROR("--checksum not supported; install xxhash-devel/libxxhash-dev (version >= 0.8) and recompile"); 170 return false; 171 } 172 #endif 173 174 if (opts.debug_checksum && !opts.checksum) { 175 ERROR("--debug-checksum requires --checksum"); 176 return false; 177 } 178 179 if (opts.checksum || 180 opts.disas || 181 opts.hack_jump_label || 182 opts.hack_noinstr || 183 opts.ibt || 184 opts.mcount || 185 opts.noabs || 186 opts.noinstr || 187 opts.orc || 188 opts.retpoline || 189 opts.rethunk || 190 opts.sls || 191 opts.stackval || 192 opts.static_call || 193 opts.uaccess) { 194 if (opts.dump_orc) { 195 ERROR("--dump can't be combined with other actions"); 196 return false; 197 } 198 199 return true; 200 } 201 202 if (opts.dump_orc) 203 return true; 204 205 ERROR("At least one action required"); 206 return false; 207 } 208 209 static int copy_file(const char *src, const char *dst) 210 { 211 size_t to_copy, copied; 212 int dst_fd, src_fd; 213 struct stat stat; 214 off_t offset = 0; 215 216 src_fd = open(src, O_RDONLY); 217 if (src_fd == -1) { 218 ERROR("can't open %s for reading: %s", src, strerror(errno)); 219 return 1; 220 } 221 222 dst_fd = open(dst, O_WRONLY | O_CREAT | O_TRUNC, 0400); 223 if (dst_fd == -1) { 224 ERROR("can't open %s for writing: %s", dst, strerror(errno)); 225 return 1; 226 } 227 228 if (fstat(src_fd, &stat) == -1) { 229 ERROR_GLIBC("fstat"); 230 return 1; 231 } 232 233 if (fchmod(dst_fd, stat.st_mode) == -1) { 234 ERROR_GLIBC("fchmod"); 235 return 1; 236 } 237 238 for (to_copy = stat.st_size; to_copy > 0; to_copy -= copied) { 239 copied = sendfile(dst_fd, src_fd, &offset, to_copy); 240 if (copied == -1) { 241 ERROR_GLIBC("sendfile"); 242 return 1; 243 } 244 } 245 246 close(dst_fd); 247 close(src_fd); 248 return 0; 249 } 250 251 static void save_argv(int argc, const char **argv) 252 { 253 orig_argv = calloc(argc, sizeof(char *)); 254 if (!orig_argv) { 255 ERROR_GLIBC("calloc"); 256 exit(1); 257 } 258 259 for (int i = 0; i < argc; i++) { 260 orig_argv[i] = strdup(argv[i]); 261 if (!orig_argv[i]) { 262 ERROR_GLIBC("strdup(%s)", argv[i]); 263 exit(1); 264 } 265 } 266 } 267 268 int make_backup(void) 269 { 270 char *backup; 271 272 /* 273 * Make a backup before kbuild deletes the file so the error 274 * can be recreated without recompiling or relinking. 275 */ 276 backup = malloc(strlen(objname) + strlen(ORIG_SUFFIX) + 1); 277 if (!backup) { 278 ERROR_GLIBC("malloc"); 279 return 1; 280 } 281 282 strcpy(backup, objname); 283 strcat(backup, ORIG_SUFFIX); 284 if (copy_file(objname, backup)) 285 return 1; 286 287 /* 288 * Print the cmdline args to make it easier to recreate. 289 */ 290 291 fprintf(stderr, "%s", orig_argv[0]); 292 293 for (int i = 1; i < orig_argc; i++) { 294 char *arg = orig_argv[i]; 295 296 /* Modify the printed args to use the backup */ 297 if (!opts.output && !strcmp(arg, objname)) 298 fprintf(stderr, " %s -o %s", backup, objname); 299 else 300 fprintf(stderr, " %s", arg); 301 } 302 303 fprintf(stderr, "\n"); 304 return 0; 305 } 306 307 int objtool_run(int argc, const char **argv) 308 { 309 struct objtool_file *file; 310 int ret = 0; 311 312 orig_argc = argc; 313 save_argv(argc, argv); 314 315 cmd_parse_options(argc, argv, check_usage); 316 317 if (!opts_valid()) 318 return 1; 319 320 objname = argv[0]; 321 322 if (opts.dump_orc) 323 return orc_dump(objname); 324 325 if (!opts.dryrun && opts.output) { 326 /* copy original .o file to output file */ 327 if (copy_file(objname, opts.output)) 328 return 1; 329 330 /* from here on, work directly on the output file */ 331 objname = opts.output; 332 } 333 334 file = objtool_open_read(objname); 335 if (!file) 336 return 1; 337 338 if (!opts.link && has_multiple_files(file->elf)) { 339 ERROR("Linked object requires --link"); 340 return 1; 341 } 342 343 ret = check(file); 344 if (ret) 345 return ret; 346 347 if (!opts.dryrun && file->elf->changed && elf_write(file->elf)) 348 return 1; 349 350 return elf_close(file->elf); 351 } 352