17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * CDDL HEADER START 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 55aefb655Srie * Common Development and Distribution License (the "License"). 65aefb655Srie * You may not use this file except in compliance with the License. 77c478bd9Sstevel@tonic-gate * 87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 117c478bd9Sstevel@tonic-gate * and limitations under the License. 127c478bd9Sstevel@tonic-gate * 137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 187c478bd9Sstevel@tonic-gate * 197c478bd9Sstevel@tonic-gate * CDDL HEADER END 207c478bd9Sstevel@tonic-gate */ 215aefb655Srie 227c478bd9Sstevel@tonic-gate /* 23f441771bSRod Evans * Copyright (c) 2004, 2010, Oracle and/or its affiliates. All rights reserved. 24*38f4bdddSBryan Cantrill * Copyright (c) 2012, Joyent, Inc. All rights reserved. 257c478bd9Sstevel@tonic-gate */ 267257d1b4Sraf 277c478bd9Sstevel@tonic-gate /* 287c478bd9Sstevel@tonic-gate * amd64 machine dependent and ELF file class dependent functions. 297c478bd9Sstevel@tonic-gate * Contains routines for performing function binding and symbol relocations. 307c478bd9Sstevel@tonic-gate */ 317c478bd9Sstevel@tonic-gate 327c478bd9Sstevel@tonic-gate #include <stdio.h> 337c478bd9Sstevel@tonic-gate #include <sys/elf.h> 347c478bd9Sstevel@tonic-gate #include <sys/elf_amd64.h> 357c478bd9Sstevel@tonic-gate #include <sys/mman.h> 367c478bd9Sstevel@tonic-gate #include <dlfcn.h> 377c478bd9Sstevel@tonic-gate #include <synch.h> 387c478bd9Sstevel@tonic-gate #include <string.h> 395aefb655Srie #include <debug.h> 405aefb655Srie #include <reloc.h> 415aefb655Srie #include <conv.h> 427c478bd9Sstevel@tonic-gate #include "_rtld.h" 437c478bd9Sstevel@tonic-gate #include "_audit.h" 447c478bd9Sstevel@tonic-gate #include "_elf.h" 45f441771bSRod Evans #include "_inline_gen.h" 46f441771bSRod Evans #include "_inline_reloc.h" 477c478bd9Sstevel@tonic-gate #include "msg.h" 487c478bd9Sstevel@tonic-gate 497c478bd9Sstevel@tonic-gate extern void elf_rtbndr(Rt_map *, ulong_t, caddr_t); 507c478bd9Sstevel@tonic-gate 517c478bd9Sstevel@tonic-gate int 527c478bd9Sstevel@tonic-gate elf_mach_flags_check(Rej_desc *rej, Ehdr *ehdr) 537c478bd9Sstevel@tonic-gate { 547c478bd9Sstevel@tonic-gate /* 557c478bd9Sstevel@tonic-gate * Check machine type and flags. 567c478bd9Sstevel@tonic-gate */ 577c478bd9Sstevel@tonic-gate if (ehdr->e_flags != 0) { 587c478bd9Sstevel@tonic-gate rej->rej_type = SGS_REJ_BADFLAG; 597c478bd9Sstevel@tonic-gate rej->rej_info = (uint_t)ehdr->e_flags; 607c478bd9Sstevel@tonic-gate return (0); 617c478bd9Sstevel@tonic-gate } 627c478bd9Sstevel@tonic-gate return (1); 637c478bd9Sstevel@tonic-gate } 647c478bd9Sstevel@tonic-gate 657c478bd9Sstevel@tonic-gate void 667c478bd9Sstevel@tonic-gate ldso_plt_init(Rt_map *lmp) 677c478bd9Sstevel@tonic-gate { 687c478bd9Sstevel@tonic-gate /* 697c478bd9Sstevel@tonic-gate * There is no need to analyze ld.so because we don't map in any of 707c478bd9Sstevel@tonic-gate * its dependencies. However we may map these dependencies in later 717c478bd9Sstevel@tonic-gate * (as if ld.so had dlopened them), so initialize the plt and the 727c478bd9Sstevel@tonic-gate * permission information. 737c478bd9Sstevel@tonic-gate */ 747c478bd9Sstevel@tonic-gate if (PLTGOT(lmp)) 7556deab07SRod Evans elf_plt_init((PLTGOT(lmp)), (caddr_t)lmp); 767c478bd9Sstevel@tonic-gate } 777c478bd9Sstevel@tonic-gate 787c478bd9Sstevel@tonic-gate static const uchar_t dyn_plt_template[] = { 797c478bd9Sstevel@tonic-gate /* 0x00 */ 0x55, /* pushq %rbp */ 807c478bd9Sstevel@tonic-gate /* 0x01 */ 0x48, 0x89, 0xe5, /* movq %rsp, %rbp */ 817c478bd9Sstevel@tonic-gate /* 0x04 */ 0x48, 0x83, 0xec, 0x10, /* subq $0x10, %rsp */ 827c478bd9Sstevel@tonic-gate /* 0x08 */ 0x4c, 0x8d, 0x1d, 0x00, /* leaq trace_fields(%rip), %r11 */ 837c478bd9Sstevel@tonic-gate 0x00, 0x00, 0x00, 847c478bd9Sstevel@tonic-gate /* 0x0f */ 0x4c, 0x89, 0x5d, 0xf8, /* movq %r11, -0x8(%rbp) */ 857c478bd9Sstevel@tonic-gate /* 0x13 */ 0x49, 0xbb, 0x00, 0x00, /* movq $elf_plt_trace, %r11 */ 867c478bd9Sstevel@tonic-gate 0x00, 0x00, 0x00, 877c478bd9Sstevel@tonic-gate 0x00, 0x00, 0x00, 887c478bd9Sstevel@tonic-gate /* 0x1d */ 0x41, 0xff, 0xe3 /* jmp *%r11 */ 897c478bd9Sstevel@tonic-gate /* 0x20 */ 907c478bd9Sstevel@tonic-gate }; 917c478bd9Sstevel@tonic-gate 927c478bd9Sstevel@tonic-gate /* 937c478bd9Sstevel@tonic-gate * And the virutal outstanding relocations against the 947c478bd9Sstevel@tonic-gate * above block are: 957c478bd9Sstevel@tonic-gate * 967c478bd9Sstevel@tonic-gate * reloc offset Addend symbol 977c478bd9Sstevel@tonic-gate * R_AMD64_PC32 0x0b -4 trace_fields 987c478bd9Sstevel@tonic-gate * R_AMD64_64 0x15 0 elf_plt_trace 997c478bd9Sstevel@tonic-gate */ 1007c478bd9Sstevel@tonic-gate 1017c478bd9Sstevel@tonic-gate #define TRCREL1OFF 0x0b 1027c478bd9Sstevel@tonic-gate #define TRCREL2OFF 0x15 1037c478bd9Sstevel@tonic-gate 1047c478bd9Sstevel@tonic-gate int dyn_plt_ent_size = sizeof (dyn_plt_template); 1057c478bd9Sstevel@tonic-gate 1067c478bd9Sstevel@tonic-gate /* 1077c478bd9Sstevel@tonic-gate * the dynamic plt entry is: 1087c478bd9Sstevel@tonic-gate * 1097c478bd9Sstevel@tonic-gate * pushq %rbp 1107c478bd9Sstevel@tonic-gate * movq %rsp, %rbp 1117c478bd9Sstevel@tonic-gate * subq $0x10, %rsp 1127c478bd9Sstevel@tonic-gate * leaq trace_fields(%rip), %r11 1137c478bd9Sstevel@tonic-gate * movq %r11, -0x8(%rbp) 1147c478bd9Sstevel@tonic-gate * movq $elf_plt_trace, %r11 1157c478bd9Sstevel@tonic-gate * jmp *%r11 1167c478bd9Sstevel@tonic-gate * dyn_data: 1177c478bd9Sstevel@tonic-gate * .align 8 1187c478bd9Sstevel@tonic-gate * uintptr_t reflmp 1197c478bd9Sstevel@tonic-gate * uintptr_t deflmp 1207c478bd9Sstevel@tonic-gate * uint_t symndx 1217c478bd9Sstevel@tonic-gate * uint_t sb_flags 1227c478bd9Sstevel@tonic-gate * Sym symdef 1237c478bd9Sstevel@tonic-gate */ 1247c478bd9Sstevel@tonic-gate static caddr_t 1257c478bd9Sstevel@tonic-gate elf_plt_trace_write(ulong_t roffset, Rt_map *rlmp, Rt_map *dlmp, Sym *sym, 1267c478bd9Sstevel@tonic-gate uint_t symndx, uint_t pltndx, caddr_t to, uint_t sb_flags, int *fail) 1277c478bd9Sstevel@tonic-gate { 1287c478bd9Sstevel@tonic-gate extern int elf_plt_trace(); 1297c478bd9Sstevel@tonic-gate ulong_t got_entry; 1307c478bd9Sstevel@tonic-gate uchar_t *dyn_plt; 1317c478bd9Sstevel@tonic-gate uintptr_t *dyndata; 1327c478bd9Sstevel@tonic-gate 1337c478bd9Sstevel@tonic-gate /* 1347c478bd9Sstevel@tonic-gate * We only need to add the glue code if there is an auditing 1357c478bd9Sstevel@tonic-gate * library that is interested in this binding. 1367c478bd9Sstevel@tonic-gate */ 1377c478bd9Sstevel@tonic-gate dyn_plt = (uchar_t *)((uintptr_t)AUDINFO(rlmp)->ai_dynplts + 1387c478bd9Sstevel@tonic-gate (pltndx * dyn_plt_ent_size)); 1397c478bd9Sstevel@tonic-gate 1407c478bd9Sstevel@tonic-gate /* 1417c478bd9Sstevel@tonic-gate * Have we initialized this dynamic plt entry yet? If we haven't do it 1427c478bd9Sstevel@tonic-gate * now. Otherwise this function has been called before, but from a 1437c478bd9Sstevel@tonic-gate * different plt (ie. from another shared object). In that case 1447c478bd9Sstevel@tonic-gate * we just set the plt to point to the new dyn_plt. 1457c478bd9Sstevel@tonic-gate */ 1467c478bd9Sstevel@tonic-gate if (*dyn_plt == 0) { 1477c478bd9Sstevel@tonic-gate Sym *symp; 1487c478bd9Sstevel@tonic-gate Xword symvalue; 1495aefb655Srie Lm_list *lml = LIST(rlmp); 1507c478bd9Sstevel@tonic-gate 1517c478bd9Sstevel@tonic-gate (void) memcpy((void *)dyn_plt, dyn_plt_template, 1527c478bd9Sstevel@tonic-gate sizeof (dyn_plt_template)); 1537c478bd9Sstevel@tonic-gate dyndata = (uintptr_t *)((uintptr_t)dyn_plt + 1547c478bd9Sstevel@tonic-gate ROUND(sizeof (dyn_plt_template), M_WORD_ALIGN)); 1557c478bd9Sstevel@tonic-gate 1567c478bd9Sstevel@tonic-gate /* 1577c478bd9Sstevel@tonic-gate * relocate: 1587c478bd9Sstevel@tonic-gate * leaq trace_fields(%rip), %r11 1597c478bd9Sstevel@tonic-gate * R_AMD64_PC32 0x0b -4 trace_fields 1607c478bd9Sstevel@tonic-gate */ 1617c478bd9Sstevel@tonic-gate symvalue = (Xword)((uintptr_t)dyndata - 1627c478bd9Sstevel@tonic-gate (uintptr_t)(&dyn_plt[TRCREL1OFF]) - 4); 163f3324781Sab196087 if (do_reloc_rtld(R_AMD64_PC32, &dyn_plt[TRCREL1OFF], 1645aefb655Srie &symvalue, MSG_ORIG(MSG_SYM_LADYNDATA), 1655aefb655Srie MSG_ORIG(MSG_SPECFIL_DYNPLT), lml) == 0) { 1667c478bd9Sstevel@tonic-gate *fail = 1; 1677c478bd9Sstevel@tonic-gate return (0); 1687c478bd9Sstevel@tonic-gate } 1697c478bd9Sstevel@tonic-gate 1707c478bd9Sstevel@tonic-gate /* 1717c478bd9Sstevel@tonic-gate * relocating: 1727c478bd9Sstevel@tonic-gate * movq $elf_plt_trace, %r11 1737c478bd9Sstevel@tonic-gate * R_AMD64_64 0x15 0 elf_plt_trace 1747c478bd9Sstevel@tonic-gate */ 1757c478bd9Sstevel@tonic-gate symvalue = (Xword)elf_plt_trace; 176f3324781Sab196087 if (do_reloc_rtld(R_AMD64_64, &dyn_plt[TRCREL2OFF], 1775aefb655Srie &symvalue, MSG_ORIG(MSG_SYM_ELFPLTTRACE), 1785aefb655Srie MSG_ORIG(MSG_SPECFIL_DYNPLT), lml) == 0) { 1797c478bd9Sstevel@tonic-gate *fail = 1; 1807c478bd9Sstevel@tonic-gate return (0); 1817c478bd9Sstevel@tonic-gate } 1827c478bd9Sstevel@tonic-gate 1837c478bd9Sstevel@tonic-gate *dyndata++ = (uintptr_t)rlmp; 1847c478bd9Sstevel@tonic-gate *dyndata++ = (uintptr_t)dlmp; 1857c478bd9Sstevel@tonic-gate *dyndata = (uintptr_t)(((uint64_t)sb_flags << 32) | symndx); 1867c478bd9Sstevel@tonic-gate dyndata++; 1877c478bd9Sstevel@tonic-gate symp = (Sym *)dyndata; 1887c478bd9Sstevel@tonic-gate *symp = *sym; 1897c478bd9Sstevel@tonic-gate symp->st_value = (Addr)to; 1907c478bd9Sstevel@tonic-gate } 1917c478bd9Sstevel@tonic-gate 1927c478bd9Sstevel@tonic-gate got_entry = (ulong_t)roffset; 1937c478bd9Sstevel@tonic-gate *(ulong_t *)got_entry = (ulong_t)dyn_plt; 1947c478bd9Sstevel@tonic-gate return ((caddr_t)dyn_plt); 1957c478bd9Sstevel@tonic-gate } 1967c478bd9Sstevel@tonic-gate 1977c478bd9Sstevel@tonic-gate /* 1987c478bd9Sstevel@tonic-gate * Function binding routine - invoked on the first call to a function through 1997c478bd9Sstevel@tonic-gate * the procedure linkage table; 2007c478bd9Sstevel@tonic-gate * passes first through an assembly language interface. 2017c478bd9Sstevel@tonic-gate * 2027c478bd9Sstevel@tonic-gate * Takes the offset into the relocation table of the associated 2037c478bd9Sstevel@tonic-gate * relocation entry and the address of the link map (rt_private_map struct) 2047c478bd9Sstevel@tonic-gate * for the entry. 2057c478bd9Sstevel@tonic-gate * 2067c478bd9Sstevel@tonic-gate * Returns the address of the function referenced after re-writing the PLT 2077c478bd9Sstevel@tonic-gate * entry to invoke the function directly. 2087c478bd9Sstevel@tonic-gate * 2097c478bd9Sstevel@tonic-gate * On error, causes process to terminate with a signal. 2107c478bd9Sstevel@tonic-gate */ 2117c478bd9Sstevel@tonic-gate ulong_t 2127c478bd9Sstevel@tonic-gate elf_bndr(Rt_map *lmp, ulong_t pltndx, caddr_t from) 2137c478bd9Sstevel@tonic-gate { 2147c478bd9Sstevel@tonic-gate Rt_map *nlmp, *llmp; 2157c478bd9Sstevel@tonic-gate ulong_t addr, reloff, symval, rsymndx; 2167c478bd9Sstevel@tonic-gate char *name; 2177c478bd9Sstevel@tonic-gate Rela *rptr; 21860758829Srie Sym *rsym, *nsym; 2195aefb655Srie uint_t binfo, sb_flags = 0, dbg_class; 2207c478bd9Sstevel@tonic-gate Slookup sl; 22108278a5eSRod Evans Sresult sr; 2225aefb655Srie int entry, lmflags; 2235aefb655Srie Lm_list *lml; 2247c478bd9Sstevel@tonic-gate 2257c478bd9Sstevel@tonic-gate /* 2267c478bd9Sstevel@tonic-gate * For compatibility with libthread (TI_VERSION 1) we track the entry 2277c478bd9Sstevel@tonic-gate * value. A zero value indicates we have recursed into ld.so.1 to 2287c478bd9Sstevel@tonic-gate * further process a locking request. Under this recursion we disable 2297c478bd9Sstevel@tonic-gate * tsort and cleanup activities. 2307c478bd9Sstevel@tonic-gate */ 2318cd45542Sraf entry = enter(0); 2327c478bd9Sstevel@tonic-gate 2335aefb655Srie lml = LIST(lmp); 2345aefb655Srie if ((lmflags = lml->lm_flags) & LML_FLG_RTLDLM) { 2355aefb655Srie dbg_class = dbg_desc->d_class; 2365aefb655Srie dbg_desc->d_class = 0; 2377c478bd9Sstevel@tonic-gate } 2387c478bd9Sstevel@tonic-gate 2397c478bd9Sstevel@tonic-gate /* 2407c478bd9Sstevel@tonic-gate * Perform some basic sanity checks. If we didn't get a load map or 2417c478bd9Sstevel@tonic-gate * the relocation offset is invalid then its possible someone has walked 2427c478bd9Sstevel@tonic-gate * over the .got entries or jumped to plt0 out of the blue. 2437c478bd9Sstevel@tonic-gate */ 2447c478bd9Sstevel@tonic-gate if ((!lmp) && (pltndx <= 2457c478bd9Sstevel@tonic-gate (ulong_t)PLTRELSZ(lmp) / (ulong_t)RELENT(lmp))) { 246de777a60Sab196087 Conv_inv_buf_t inv_buf; 247de777a60Sab196087 2485aefb655Srie eprintf(lml, ERR_FATAL, MSG_INTL(MSG_REL_PLTREF), 249de777a60Sab196087 conv_reloc_amd64_type(R_AMD64_JUMP_SLOT, 0, &inv_buf), 2505aefb655Srie EC_NATPTR(lmp), EC_XWORD(pltndx), EC_NATPTR(from)); 2515aefb655Srie rtldexit(lml, 1); 2527c478bd9Sstevel@tonic-gate } 2537c478bd9Sstevel@tonic-gate reloff = pltndx * (ulong_t)RELENT(lmp); 2547c478bd9Sstevel@tonic-gate 2557c478bd9Sstevel@tonic-gate /* 2567c478bd9Sstevel@tonic-gate * Use relocation entry to get symbol table entry and symbol name. 2577c478bd9Sstevel@tonic-gate */ 2587c478bd9Sstevel@tonic-gate addr = (ulong_t)JMPREL(lmp); 2597c478bd9Sstevel@tonic-gate rptr = (Rela *)(addr + reloff); 2607c478bd9Sstevel@tonic-gate rsymndx = ELF_R_SYM(rptr->r_info); 26160758829Srie rsym = (Sym *)((ulong_t)SYMTAB(lmp) + (rsymndx * SYMENT(lmp))); 26260758829Srie name = (char *)(STRTAB(lmp) + rsym->st_name); 2637c478bd9Sstevel@tonic-gate 2647c478bd9Sstevel@tonic-gate /* 2657c478bd9Sstevel@tonic-gate * Determine the last link-map of this list, this'll be the starting 2667c478bd9Sstevel@tonic-gate * point for any tsort() processing. 2677c478bd9Sstevel@tonic-gate */ 2685aefb655Srie llmp = lml->lm_tail; 2697c478bd9Sstevel@tonic-gate 2707c478bd9Sstevel@tonic-gate /* 27108278a5eSRod Evans * Find definition for symbol. Initialize the symbol lookup, and 27208278a5eSRod Evans * symbol result, data structures. 2737c478bd9Sstevel@tonic-gate */ 27475e7992aSrie SLOOKUP_INIT(sl, name, lmp, lml->lm_head, ld_entry_cnt, 0, 27575e7992aSrie rsymndx, rsym, 0, LKUP_DEFT); 27608278a5eSRod Evans SRESULT_INIT(sr, name); 2777c478bd9Sstevel@tonic-gate 27808278a5eSRod Evans if (lookup_sym(&sl, &sr, &binfo, NULL) == 0) { 2795aefb655Srie eprintf(lml, ERR_FATAL, MSG_INTL(MSG_REL_NOSYM), NAME(lmp), 2807c478bd9Sstevel@tonic-gate demangle(name)); 2815aefb655Srie rtldexit(lml, 1); 2827c478bd9Sstevel@tonic-gate } 2837c478bd9Sstevel@tonic-gate 28408278a5eSRod Evans name = (char *)sr.sr_name; 28508278a5eSRod Evans nlmp = sr.sr_dmap; 28608278a5eSRod Evans nsym = sr.sr_sym; 28708278a5eSRod Evans 2887c478bd9Sstevel@tonic-gate symval = nsym->st_value; 28908278a5eSRod Evans 2907c478bd9Sstevel@tonic-gate if (!(FLAGS(nlmp) & FLG_RT_FIXED) && 2917c478bd9Sstevel@tonic-gate (nsym->st_shndx != SHN_ABS)) 2927c478bd9Sstevel@tonic-gate symval += ADDR(nlmp); 2937c478bd9Sstevel@tonic-gate if ((lmp != nlmp) && ((FLAGS1(nlmp) & FL1_RT_NOINIFIN) == 0)) { 2947c478bd9Sstevel@tonic-gate /* 2957c478bd9Sstevel@tonic-gate * Record that this new link map is now bound to the caller. 2967c478bd9Sstevel@tonic-gate */ 2977c478bd9Sstevel@tonic-gate if (bind_one(lmp, nlmp, BND_REFER) == 0) 2985aefb655Srie rtldexit(lml, 1); 2997c478bd9Sstevel@tonic-gate } 3007c478bd9Sstevel@tonic-gate 301*38f4bdddSBryan Cantrill if ((lml->lm_tflags | AFLAGS(lmp) | AFLAGS(nlmp)) & 302*38f4bdddSBryan Cantrill LML_TFLG_AUD_SYMBIND) { 3037c478bd9Sstevel@tonic-gate uint_t symndx = (((uintptr_t)nsym - 3047c478bd9Sstevel@tonic-gate (uintptr_t)SYMTAB(nlmp)) / SYMENT(nlmp)); 3057c478bd9Sstevel@tonic-gate symval = audit_symbind(lmp, nlmp, nsym, symndx, symval, 3067c478bd9Sstevel@tonic-gate &sb_flags); 3077c478bd9Sstevel@tonic-gate } 3087c478bd9Sstevel@tonic-gate 3097c478bd9Sstevel@tonic-gate if (!(rtld_flags & RT_FL_NOBIND)) { 3107c478bd9Sstevel@tonic-gate addr = rptr->r_offset; 3117c478bd9Sstevel@tonic-gate if (!(FLAGS(lmp) & FLG_RT_FIXED)) 3127c478bd9Sstevel@tonic-gate addr += ADDR(lmp); 31356deab07SRod Evans if (((lml->lm_tflags | AFLAGS(lmp)) & 3147c478bd9Sstevel@tonic-gate (LML_TFLG_AUD_PLTENTER | LML_TFLG_AUD_PLTEXIT)) && 3157c478bd9Sstevel@tonic-gate AUDINFO(lmp)->ai_dynplts) { 3167c478bd9Sstevel@tonic-gate int fail = 0; 3177c478bd9Sstevel@tonic-gate uint_t pltndx = reloff / sizeof (Rela); 3187c478bd9Sstevel@tonic-gate uint_t symndx = (((uintptr_t)nsym - 3197247f888Srie (uintptr_t)SYMTAB(nlmp)) / SYMENT(nlmp)); 3207c478bd9Sstevel@tonic-gate 3217c478bd9Sstevel@tonic-gate symval = (ulong_t)elf_plt_trace_write(addr, lmp, nlmp, 3227c478bd9Sstevel@tonic-gate nsym, symndx, pltndx, (caddr_t)symval, sb_flags, 3237c478bd9Sstevel@tonic-gate &fail); 3247c478bd9Sstevel@tonic-gate if (fail) 3255aefb655Srie rtldexit(lml, 1); 3267c478bd9Sstevel@tonic-gate } else { 3277c478bd9Sstevel@tonic-gate /* 3287c478bd9Sstevel@tonic-gate * Write standard PLT entry to jump directly 3297c478bd9Sstevel@tonic-gate * to newly bound function. 3307c478bd9Sstevel@tonic-gate */ 3317c478bd9Sstevel@tonic-gate *(ulong_t *)addr = symval; 3327c478bd9Sstevel@tonic-gate } 3337c478bd9Sstevel@tonic-gate } 3347c478bd9Sstevel@tonic-gate 3357c478bd9Sstevel@tonic-gate /* 3367c478bd9Sstevel@tonic-gate * Print binding information and rebuild PLT entry. 3377c478bd9Sstevel@tonic-gate */ 3385aefb655Srie DBG_CALL(Dbg_bind_global(lmp, (Addr)from, (Off)(from - ADDR(lmp)), 33956deab07SRod Evans (Xword)(reloff / sizeof (Rela)), PLT_T_FULL, nlmp, (Addr)symval, 34056deab07SRod Evans nsym->st_value, name, binfo)); 3417c478bd9Sstevel@tonic-gate 3427c478bd9Sstevel@tonic-gate /* 3437c478bd9Sstevel@tonic-gate * Complete any processing for newly loaded objects. Note we don't 3447c478bd9Sstevel@tonic-gate * know exactly where any new objects are loaded (we know the object 3457c478bd9Sstevel@tonic-gate * that supplied the symbol, but others may have been loaded lazily as 3467c478bd9Sstevel@tonic-gate * we searched for the symbol), so sorting starts from the last 3477c478bd9Sstevel@tonic-gate * link-map know on entry to this routine. 3487c478bd9Sstevel@tonic-gate */ 3497c478bd9Sstevel@tonic-gate if (entry) 3507247f888Srie load_completion(llmp); 3517c478bd9Sstevel@tonic-gate 3527c478bd9Sstevel@tonic-gate /* 3537c478bd9Sstevel@tonic-gate * Some operations like dldump() or dlopen()'ing a relocatable object 3547c478bd9Sstevel@tonic-gate * result in objects being loaded on rtld's link-map, make sure these 3557c478bd9Sstevel@tonic-gate * objects are initialized also. 3567c478bd9Sstevel@tonic-gate */ 35756deab07SRod Evans if ((LIST(nlmp)->lm_flags & LML_FLG_RTLDLM) && LIST(nlmp)->lm_init) 3587247f888Srie load_completion(nlmp); 3597c478bd9Sstevel@tonic-gate 3607c478bd9Sstevel@tonic-gate /* 3617c478bd9Sstevel@tonic-gate * Make sure the object to which we've bound has had it's .init fired. 3627c478bd9Sstevel@tonic-gate * Cleanup before return to user code. 3637c478bd9Sstevel@tonic-gate */ 3647c478bd9Sstevel@tonic-gate if (entry) { 3657c478bd9Sstevel@tonic-gate is_dep_init(nlmp, lmp); 3668cd45542Sraf leave(lml, 0); 3677c478bd9Sstevel@tonic-gate } 3687c478bd9Sstevel@tonic-gate 3697c478bd9Sstevel@tonic-gate if (lmflags & LML_FLG_RTLDLM) 3705aefb655Srie dbg_desc->d_class = dbg_class; 3717c478bd9Sstevel@tonic-gate 3727c478bd9Sstevel@tonic-gate return (symval); 3737c478bd9Sstevel@tonic-gate } 3747c478bd9Sstevel@tonic-gate 3757c478bd9Sstevel@tonic-gate /* 3767c478bd9Sstevel@tonic-gate * Read and process the relocations for one link object, we assume all 3777c478bd9Sstevel@tonic-gate * relocation sections for loadable segments are stored contiguously in 3787c478bd9Sstevel@tonic-gate * the file. 3797c478bd9Sstevel@tonic-gate */ 3807c478bd9Sstevel@tonic-gate int 38156deab07SRod Evans elf_reloc(Rt_map *lmp, uint_t plt, int *in_nfavl, APlist **textrel) 3827c478bd9Sstevel@tonic-gate { 3837c478bd9Sstevel@tonic-gate ulong_t relbgn, relend, relsiz, basebgn; 3847c478bd9Sstevel@tonic-gate ulong_t pltbgn, pltend, _pltbgn, _pltend; 38556deab07SRod Evans ulong_t roffset, rsymndx, psymndx = 0; 38656deab07SRod Evans ulong_t dsymndx; 3877c478bd9Sstevel@tonic-gate uchar_t rtype; 3887c478bd9Sstevel@tonic-gate long reladd, value, pvalue; 3897c478bd9Sstevel@tonic-gate Sym *symref, *psymref, *symdef, *psymdef; 390f441771bSRod Evans Syminfo *sip; 3917c478bd9Sstevel@tonic-gate char *name, *pname; 3927c478bd9Sstevel@tonic-gate Rt_map *_lmp, *plmp; 39356deab07SRod Evans int ret = 1, noplt = 0; 3947c478bd9Sstevel@tonic-gate int relacount = RELACOUNT(lmp), plthint = 0; 3957c478bd9Sstevel@tonic-gate Rela *rel; 3967c478bd9Sstevel@tonic-gate uint_t binfo, pbinfo; 397cce0e03bSab196087 APlist *bound = NULL; 3987c478bd9Sstevel@tonic-gate 3997c478bd9Sstevel@tonic-gate /* 4007c478bd9Sstevel@tonic-gate * Although only necessary for lazy binding, initialize the first 4017c478bd9Sstevel@tonic-gate * global offset entry to go to elf_rtbndr(). dbx(1) seems 4027c478bd9Sstevel@tonic-gate * to find this useful. 4037c478bd9Sstevel@tonic-gate */ 4047c478bd9Sstevel@tonic-gate if ((plt == 0) && PLTGOT(lmp)) { 40556deab07SRod Evans mmapobj_result_t *mpp; 40656deab07SRod Evans 40756deab07SRod Evans /* 40856deab07SRod Evans * Make sure the segment is writable. 40956deab07SRod Evans */ 41056deab07SRod Evans if ((((mpp = 41156deab07SRod Evans find_segment((caddr_t)PLTGOT(lmp), lmp)) != NULL) && 41256deab07SRod Evans ((mpp->mr_prot & PROT_WRITE) == 0)) && 41356deab07SRod Evans ((set_prot(lmp, mpp, 1) == 0) || 41456deab07SRod Evans (aplist_append(textrel, mpp, AL_CNT_TEXTREL) == NULL))) 4157c478bd9Sstevel@tonic-gate return (0); 41656deab07SRod Evans 41756deab07SRod Evans elf_plt_init(PLTGOT(lmp), (caddr_t)lmp); 4187c478bd9Sstevel@tonic-gate } 4197c478bd9Sstevel@tonic-gate 4207c478bd9Sstevel@tonic-gate /* 4217c478bd9Sstevel@tonic-gate * Initialize the plt start and end addresses. 4227c478bd9Sstevel@tonic-gate */ 4237c478bd9Sstevel@tonic-gate if ((pltbgn = (ulong_t)JMPREL(lmp)) != 0) 4247c478bd9Sstevel@tonic-gate pltend = pltbgn + (ulong_t)(PLTRELSZ(lmp)); 4257c478bd9Sstevel@tonic-gate 4267c478bd9Sstevel@tonic-gate relsiz = (ulong_t)(RELENT(lmp)); 4277c478bd9Sstevel@tonic-gate basebgn = ADDR(lmp); 4287c478bd9Sstevel@tonic-gate 4297c478bd9Sstevel@tonic-gate if (PLTRELSZ(lmp)) 4307c478bd9Sstevel@tonic-gate plthint = PLTRELSZ(lmp) / relsiz; 4317c478bd9Sstevel@tonic-gate 4327c478bd9Sstevel@tonic-gate /* 4337c478bd9Sstevel@tonic-gate * If we've been called upon to promote an RTLD_LAZY object to an 4347c478bd9Sstevel@tonic-gate * RTLD_NOW then we're only interested in scaning the .plt table. 4357c478bd9Sstevel@tonic-gate * An uninitialized .plt is the case where the associated got entry 4367c478bd9Sstevel@tonic-gate * points back to the plt itself. Determine the range of the real .plt 4377c478bd9Sstevel@tonic-gate * entries using the _PROCEDURE_LINKAGE_TABLE_ symbol. 4387c478bd9Sstevel@tonic-gate */ 4397c478bd9Sstevel@tonic-gate if (plt) { 4407c478bd9Sstevel@tonic-gate Slookup sl; 44108278a5eSRod Evans Sresult sr; 4427c478bd9Sstevel@tonic-gate 4437c478bd9Sstevel@tonic-gate relbgn = pltbgn; 4447c478bd9Sstevel@tonic-gate relend = pltend; 4457c478bd9Sstevel@tonic-gate if (!relbgn || (relbgn == relend)) 4467c478bd9Sstevel@tonic-gate return (1); 4477c478bd9Sstevel@tonic-gate 44875e7992aSrie /* 44908278a5eSRod Evans * Initialize the symbol lookup, and symbol result, data 45008278a5eSRod Evans * structures. 45175e7992aSrie */ 45275e7992aSrie SLOOKUP_INIT(sl, MSG_ORIG(MSG_SYM_PLT), lmp, lmp, ld_entry_cnt, 45375e7992aSrie elf_hash(MSG_ORIG(MSG_SYM_PLT)), 0, 0, 0, LKUP_DEFT); 45408278a5eSRod Evans SRESULT_INIT(sr, MSG_ORIG(MSG_SYM_PLT)); 4557c478bd9Sstevel@tonic-gate 45608278a5eSRod Evans if (elf_find_sym(&sl, &sr, &binfo, NULL) == 0) 4577c478bd9Sstevel@tonic-gate return (1); 4587c478bd9Sstevel@tonic-gate 45908278a5eSRod Evans symdef = sr.sr_sym; 4607c478bd9Sstevel@tonic-gate _pltbgn = symdef->st_value; 4617c478bd9Sstevel@tonic-gate if (!(FLAGS(lmp) & FLG_RT_FIXED) && 4627c478bd9Sstevel@tonic-gate (symdef->st_shndx != SHN_ABS)) 4637c478bd9Sstevel@tonic-gate _pltbgn += basebgn; 4647c478bd9Sstevel@tonic-gate _pltend = _pltbgn + (((PLTRELSZ(lmp) / relsiz)) * 4657c478bd9Sstevel@tonic-gate M_PLT_ENTSIZE) + M_PLT_RESERVSZ; 4667c478bd9Sstevel@tonic-gate 4677c478bd9Sstevel@tonic-gate } else { 4687c478bd9Sstevel@tonic-gate /* 4697c478bd9Sstevel@tonic-gate * The relocation sections appear to the run-time linker as a 4707c478bd9Sstevel@tonic-gate * single table. Determine the address of the beginning and end 4717c478bd9Sstevel@tonic-gate * of this table. There are two different interpretations of 4727c478bd9Sstevel@tonic-gate * the ABI at this point: 4737c478bd9Sstevel@tonic-gate * 4747c478bd9Sstevel@tonic-gate * o The REL table and its associated RELSZ indicate the 4757c478bd9Sstevel@tonic-gate * concatenation of *all* relocation sections (this is the 4767c478bd9Sstevel@tonic-gate * model our link-editor constructs). 4777c478bd9Sstevel@tonic-gate * 4787c478bd9Sstevel@tonic-gate * o The REL table and its associated RELSZ indicate the 4797c478bd9Sstevel@tonic-gate * concatenation of all *but* the .plt relocations. These 4807c478bd9Sstevel@tonic-gate * relocations are specified individually by the JMPREL and 4817c478bd9Sstevel@tonic-gate * PLTRELSZ entries. 4827c478bd9Sstevel@tonic-gate * 4837c478bd9Sstevel@tonic-gate * Determine from our knowledege of the relocation range and 4847c478bd9Sstevel@tonic-gate * .plt range, the range of the total relocation table. Note 4857c478bd9Sstevel@tonic-gate * that one other ABI assumption seems to be that the .plt 4867c478bd9Sstevel@tonic-gate * relocations always follow any other relocations, the 4877c478bd9Sstevel@tonic-gate * following range checking drops that assumption. 4887c478bd9Sstevel@tonic-gate */ 4897c478bd9Sstevel@tonic-gate relbgn = (ulong_t)(REL(lmp)); 4907c478bd9Sstevel@tonic-gate relend = relbgn + (ulong_t)(RELSZ(lmp)); 4917c478bd9Sstevel@tonic-gate if (pltbgn) { 4927c478bd9Sstevel@tonic-gate if (!relbgn || (relbgn > pltbgn)) 4937c478bd9Sstevel@tonic-gate relbgn = pltbgn; 4947c478bd9Sstevel@tonic-gate if (!relbgn || (relend < pltend)) 4957c478bd9Sstevel@tonic-gate relend = pltend; 4967c478bd9Sstevel@tonic-gate } 4977c478bd9Sstevel@tonic-gate } 4987c478bd9Sstevel@tonic-gate if (!relbgn || (relbgn == relend)) { 4995aefb655Srie DBG_CALL(Dbg_reloc_run(lmp, 0, plt, DBG_REL_NONE)); 5007c478bd9Sstevel@tonic-gate return (1); 5017c478bd9Sstevel@tonic-gate } 5025aefb655Srie DBG_CALL(Dbg_reloc_run(lmp, M_REL_SHT_TYPE, plt, DBG_REL_START)); 5037c478bd9Sstevel@tonic-gate 5047c478bd9Sstevel@tonic-gate /* 5057c478bd9Sstevel@tonic-gate * If we're processing a dynamic executable in lazy mode there is no 5067c478bd9Sstevel@tonic-gate * need to scan the .rel.plt table, however if we're processing a shared 5077c478bd9Sstevel@tonic-gate * object in lazy mode the .got addresses associated to each .plt must 5087c478bd9Sstevel@tonic-gate * be relocated to reflect the location of the shared object. 5097c478bd9Sstevel@tonic-gate */ 5107c478bd9Sstevel@tonic-gate if (pltbgn && ((MODE(lmp) & RTLD_NOW) == 0) && 5117c478bd9Sstevel@tonic-gate (FLAGS(lmp) & FLG_RT_FIXED)) 5127c478bd9Sstevel@tonic-gate noplt = 1; 5137c478bd9Sstevel@tonic-gate 514f441771bSRod Evans sip = SYMINFO(lmp); 5157c478bd9Sstevel@tonic-gate /* 5167c478bd9Sstevel@tonic-gate * Loop through relocations. 5177c478bd9Sstevel@tonic-gate */ 5187c478bd9Sstevel@tonic-gate while (relbgn < relend) { 51956deab07SRod Evans mmapobj_result_t *mpp; 5207c478bd9Sstevel@tonic-gate uint_t sb_flags = 0; 5217c478bd9Sstevel@tonic-gate 522ba2be530Sab196087 rtype = ELF_R_TYPE(((Rela *)relbgn)->r_info, M_MACH); 5237c478bd9Sstevel@tonic-gate 5247c478bd9Sstevel@tonic-gate /* 5257c478bd9Sstevel@tonic-gate * If this is a RELATIVE relocation in a shared object (the 5267c478bd9Sstevel@tonic-gate * common case), and if we are not debugging, then jump into a 52756deab07SRod Evans * tighter relocation loop (elf_reloc_relative). 5287c478bd9Sstevel@tonic-gate */ 5297c478bd9Sstevel@tonic-gate if ((rtype == R_AMD64_RELATIVE) && 5305aefb655Srie ((FLAGS(lmp) & FLG_RT_FIXED) == 0) && (DBG_ENABLED == 0)) { 5317c478bd9Sstevel@tonic-gate if (relacount) { 53256deab07SRod Evans relbgn = elf_reloc_relative_count(relbgn, 533f441771bSRod Evans relacount, relsiz, basebgn, lmp, 534f441771bSRod Evans textrel, 0); 5357c478bd9Sstevel@tonic-gate relacount = 0; 5367c478bd9Sstevel@tonic-gate } else { 5377c478bd9Sstevel@tonic-gate relbgn = elf_reloc_relative(relbgn, relend, 538f441771bSRod Evans relsiz, basebgn, lmp, textrel, 0); 5397c478bd9Sstevel@tonic-gate } 5407c478bd9Sstevel@tonic-gate if (relbgn >= relend) 5417c478bd9Sstevel@tonic-gate break; 542ba2be530Sab196087 rtype = ELF_R_TYPE(((Rela *)relbgn)->r_info, M_MACH); 5437c478bd9Sstevel@tonic-gate } 5447c478bd9Sstevel@tonic-gate 5457c478bd9Sstevel@tonic-gate roffset = ((Rela *)relbgn)->r_offset; 5467c478bd9Sstevel@tonic-gate 5477c478bd9Sstevel@tonic-gate /* 5487c478bd9Sstevel@tonic-gate * If this is a shared object, add the base address to offset. 5497c478bd9Sstevel@tonic-gate */ 5507c478bd9Sstevel@tonic-gate if (!(FLAGS(lmp) & FLG_RT_FIXED)) { 5517c478bd9Sstevel@tonic-gate /* 5527c478bd9Sstevel@tonic-gate * If we're processing lazy bindings, we have to step 5537c478bd9Sstevel@tonic-gate * through the plt entries and add the base address 5547c478bd9Sstevel@tonic-gate * to the corresponding got entry. 5557c478bd9Sstevel@tonic-gate */ 5567c478bd9Sstevel@tonic-gate if (plthint && (plt == 0) && 5577c478bd9Sstevel@tonic-gate (rtype == R_AMD64_JUMP_SLOT) && 5587c478bd9Sstevel@tonic-gate ((MODE(lmp) & RTLD_NOW) == 0)) { 559f441771bSRod Evans relbgn = elf_reloc_relative_count(relbgn, 560f441771bSRod Evans plthint, relsiz, basebgn, lmp, textrel, 1); 561f441771bSRod Evans plthint = 0; 5627c478bd9Sstevel@tonic-gate continue; 5637c478bd9Sstevel@tonic-gate } 5647c478bd9Sstevel@tonic-gate roffset += basebgn; 5657c478bd9Sstevel@tonic-gate } 5667c478bd9Sstevel@tonic-gate 5677c478bd9Sstevel@tonic-gate reladd = (long)(((Rela *)relbgn)->r_addend); 5687c478bd9Sstevel@tonic-gate rsymndx = ELF_R_SYM(((Rela *)relbgn)->r_info); 5697c478bd9Sstevel@tonic-gate rel = (Rela *)relbgn; 5707c478bd9Sstevel@tonic-gate relbgn += relsiz; 5717c478bd9Sstevel@tonic-gate 5727c478bd9Sstevel@tonic-gate /* 5737c478bd9Sstevel@tonic-gate * Optimizations. 5747c478bd9Sstevel@tonic-gate */ 5757c478bd9Sstevel@tonic-gate if (rtype == R_AMD64_NONE) 5767c478bd9Sstevel@tonic-gate continue; 5777c478bd9Sstevel@tonic-gate if (noplt && ((ulong_t)rel >= pltbgn) && 5787c478bd9Sstevel@tonic-gate ((ulong_t)rel < pltend)) { 5797c478bd9Sstevel@tonic-gate relbgn = pltend; 5807c478bd9Sstevel@tonic-gate continue; 5817c478bd9Sstevel@tonic-gate } 5827c478bd9Sstevel@tonic-gate 5837c478bd9Sstevel@tonic-gate /* 58456deab07SRod Evans * If we're promoting plts, determine if this one has already 58556deab07SRod Evans * been written. 58656deab07SRod Evans */ 58756deab07SRod Evans if (plt && ((*(ulong_t *)roffset < _pltbgn) || 58856deab07SRod Evans (*(ulong_t *)roffset > _pltend))) 58956deab07SRod Evans continue; 59056deab07SRod Evans 59156deab07SRod Evans /* 5927c478bd9Sstevel@tonic-gate * If this relocation is not against part of the image 5937c478bd9Sstevel@tonic-gate * mapped into memory we skip it. 5947c478bd9Sstevel@tonic-gate */ 59556deab07SRod Evans if ((mpp = find_segment((caddr_t)roffset, lmp)) == NULL) { 5967c478bd9Sstevel@tonic-gate elf_reloc_bad(lmp, (void *)rel, rtype, roffset, 5977c478bd9Sstevel@tonic-gate rsymndx); 5987c478bd9Sstevel@tonic-gate continue; 5997c478bd9Sstevel@tonic-gate } 6007c478bd9Sstevel@tonic-gate 6017c478bd9Sstevel@tonic-gate binfo = 0; 6027c478bd9Sstevel@tonic-gate /* 6037c478bd9Sstevel@tonic-gate * If a symbol index is specified then get the symbol table 6047c478bd9Sstevel@tonic-gate * entry, locate the symbol definition, and determine its 6057c478bd9Sstevel@tonic-gate * address. 6067c478bd9Sstevel@tonic-gate */ 6077c478bd9Sstevel@tonic-gate if (rsymndx) { 6087c478bd9Sstevel@tonic-gate /* 609f441771bSRod Evans * If a Syminfo section is provided, determine if this 610f441771bSRod Evans * symbol is deferred, and if so, skip this relocation. 611f441771bSRod Evans */ 612f441771bSRod Evans if (sip && is_sym_deferred((ulong_t)rel, basebgn, lmp, 613f441771bSRod Evans textrel, sip, rsymndx)) 614f441771bSRod Evans continue; 615f441771bSRod Evans 616f441771bSRod Evans /* 6177c478bd9Sstevel@tonic-gate * Get the local symbol table entry. 6187c478bd9Sstevel@tonic-gate */ 6197c478bd9Sstevel@tonic-gate symref = (Sym *)((ulong_t)SYMTAB(lmp) + 6207c478bd9Sstevel@tonic-gate (rsymndx * SYMENT(lmp))); 6217c478bd9Sstevel@tonic-gate 6227c478bd9Sstevel@tonic-gate /* 6237c478bd9Sstevel@tonic-gate * If this is a local symbol, just use the base address. 6247c478bd9Sstevel@tonic-gate * (we should have no local relocations in the 6257c478bd9Sstevel@tonic-gate * executable). 6267c478bd9Sstevel@tonic-gate */ 6277c478bd9Sstevel@tonic-gate if (ELF_ST_BIND(symref->st_info) == STB_LOCAL) { 6287c478bd9Sstevel@tonic-gate value = basebgn; 62908278a5eSRod Evans name = NULL; 6307c478bd9Sstevel@tonic-gate 6317c478bd9Sstevel@tonic-gate /* 632d326b23bSrie * Special case TLS relocations. 6337c478bd9Sstevel@tonic-gate */ 634d326b23bSrie if (rtype == R_AMD64_DTPMOD64) { 635d326b23bSrie /* 636d326b23bSrie * Use the TLS modid. 637d326b23bSrie */ 6387c478bd9Sstevel@tonic-gate value = TLSMODID(lmp); 639d326b23bSrie 640d326b23bSrie } else if ((rtype == R_AMD64_TPOFF64) || 641d326b23bSrie (rtype == R_AMD64_TPOFF32)) { 642d326b23bSrie if ((value = elf_static_tls(lmp, symref, 643d326b23bSrie rel, rtype, 0, roffset, 0)) == 0) { 644d326b23bSrie ret = 0; 645d326b23bSrie break; 646d326b23bSrie } 647d326b23bSrie } 6487c478bd9Sstevel@tonic-gate } else { 6497c478bd9Sstevel@tonic-gate /* 6507c478bd9Sstevel@tonic-gate * If the symbol index is equal to the previous 6517c478bd9Sstevel@tonic-gate * symbol index relocation we processed then 6527c478bd9Sstevel@tonic-gate * reuse the previous values. (Note that there 6537c478bd9Sstevel@tonic-gate * have been cases where a relocation exists 6547c478bd9Sstevel@tonic-gate * against a copy relocation symbol, our ld(1) 6557c478bd9Sstevel@tonic-gate * should optimize this away, but make sure we 6567c478bd9Sstevel@tonic-gate * don't use the same symbol information should 6577c478bd9Sstevel@tonic-gate * this case exist). 6587c478bd9Sstevel@tonic-gate */ 6597c478bd9Sstevel@tonic-gate if ((rsymndx == psymndx) && 6607c478bd9Sstevel@tonic-gate (rtype != R_AMD64_COPY)) { 6617c478bd9Sstevel@tonic-gate /* LINTED */ 6627c478bd9Sstevel@tonic-gate if (psymdef == 0) { 6635aefb655Srie DBG_CALL(Dbg_bind_weak(lmp, 6645aefb655Srie (Addr)roffset, (Addr) 6657c478bd9Sstevel@tonic-gate (roffset - basebgn), name)); 6667c478bd9Sstevel@tonic-gate continue; 6677c478bd9Sstevel@tonic-gate } 6687c478bd9Sstevel@tonic-gate /* LINTED */ 6697c478bd9Sstevel@tonic-gate value = pvalue; 6707c478bd9Sstevel@tonic-gate /* LINTED */ 6717c478bd9Sstevel@tonic-gate name = pname; 6727c478bd9Sstevel@tonic-gate /* LINTED */ 6737c478bd9Sstevel@tonic-gate symdef = psymdef; 6747c478bd9Sstevel@tonic-gate /* LINTED */ 6757c478bd9Sstevel@tonic-gate symref = psymref; 6767c478bd9Sstevel@tonic-gate /* LINTED */ 6777c478bd9Sstevel@tonic-gate _lmp = plmp; 6787c478bd9Sstevel@tonic-gate /* LINTED */ 6797c478bd9Sstevel@tonic-gate binfo = pbinfo; 6807c478bd9Sstevel@tonic-gate 6817c478bd9Sstevel@tonic-gate if ((LIST(_lmp)->lm_tflags | 68256deab07SRod Evans AFLAGS(_lmp)) & 6837c478bd9Sstevel@tonic-gate LML_TFLG_AUD_SYMBIND) { 6847c478bd9Sstevel@tonic-gate value = audit_symbind(lmp, _lmp, 6857c478bd9Sstevel@tonic-gate /* LINTED */ 6867c478bd9Sstevel@tonic-gate symdef, dsymndx, value, 6877c478bd9Sstevel@tonic-gate &sb_flags); 6887c478bd9Sstevel@tonic-gate } 6897c478bd9Sstevel@tonic-gate } else { 6907c478bd9Sstevel@tonic-gate Slookup sl; 69108278a5eSRod Evans Sresult sr; 6927c478bd9Sstevel@tonic-gate 6937c478bd9Sstevel@tonic-gate /* 6947c478bd9Sstevel@tonic-gate * Lookup the symbol definition. 69508278a5eSRod Evans * Initialize the symbol lookup, and 69608278a5eSRod Evans * symbol result, data structure. 6977c478bd9Sstevel@tonic-gate */ 6987c478bd9Sstevel@tonic-gate name = (char *)(STRTAB(lmp) + 6997c478bd9Sstevel@tonic-gate symref->st_name); 7007c478bd9Sstevel@tonic-gate 70175e7992aSrie SLOOKUP_INIT(sl, name, lmp, 0, 70275e7992aSrie ld_entry_cnt, 0, rsymndx, symref, 70375e7992aSrie rtype, LKUP_STDRELOC); 70408278a5eSRod Evans SRESULT_INIT(sr, name); 70508278a5eSRod Evans symdef = NULL; 7067c478bd9Sstevel@tonic-gate 70708278a5eSRod Evans if (lookup_sym(&sl, &sr, &binfo, 70808278a5eSRod Evans in_nfavl)) { 70908278a5eSRod Evans name = (char *)sr.sr_name; 71008278a5eSRod Evans _lmp = sr.sr_dmap; 71108278a5eSRod Evans symdef = sr.sr_sym; 71208278a5eSRod Evans } 7137c478bd9Sstevel@tonic-gate 7147c478bd9Sstevel@tonic-gate /* 7157c478bd9Sstevel@tonic-gate * If the symbol is not found and the 7167c478bd9Sstevel@tonic-gate * reference was not to a weak symbol, 7177c478bd9Sstevel@tonic-gate * report an error. Weak references 7187c478bd9Sstevel@tonic-gate * may be unresolved. 7197c478bd9Sstevel@tonic-gate */ 7207247f888Srie /* BEGIN CSTYLED */ 7217c478bd9Sstevel@tonic-gate if (symdef == 0) { 72260758829Srie if (sl.sl_bind != STB_WEAK) { 723dae2dfb7Srie if (elf_reloc_error(lmp, name, 724dae2dfb7Srie rel, binfo)) 7257c478bd9Sstevel@tonic-gate continue; 726dae2dfb7Srie 7277c478bd9Sstevel@tonic-gate ret = 0; 7287c478bd9Sstevel@tonic-gate break; 729dae2dfb7Srie 7307c478bd9Sstevel@tonic-gate } else { 7317c478bd9Sstevel@tonic-gate psymndx = rsymndx; 7327c478bd9Sstevel@tonic-gate psymdef = 0; 7337c478bd9Sstevel@tonic-gate 7345aefb655Srie DBG_CALL(Dbg_bind_weak(lmp, 7355aefb655Srie (Addr)roffset, (Addr) 7367c478bd9Sstevel@tonic-gate (roffset - basebgn), name)); 7377c478bd9Sstevel@tonic-gate continue; 7387c478bd9Sstevel@tonic-gate } 7397c478bd9Sstevel@tonic-gate } 7407247f888Srie /* END CSTYLED */ 7417c478bd9Sstevel@tonic-gate 7427c478bd9Sstevel@tonic-gate /* 7437c478bd9Sstevel@tonic-gate * If symbol was found in an object 7447c478bd9Sstevel@tonic-gate * other than the referencing object 7457c478bd9Sstevel@tonic-gate * then record the binding. 7467c478bd9Sstevel@tonic-gate */ 7477c478bd9Sstevel@tonic-gate if ((lmp != _lmp) && ((FLAGS1(_lmp) & 7487c478bd9Sstevel@tonic-gate FL1_RT_NOINIFIN) == 0)) { 749cce0e03bSab196087 if (aplist_test(&bound, _lmp, 7507c478bd9Sstevel@tonic-gate AL_CNT_RELBIND) == 0) { 7517c478bd9Sstevel@tonic-gate ret = 0; 7527c478bd9Sstevel@tonic-gate break; 7537c478bd9Sstevel@tonic-gate } 7547c478bd9Sstevel@tonic-gate } 7557c478bd9Sstevel@tonic-gate 7567c478bd9Sstevel@tonic-gate /* 7577c478bd9Sstevel@tonic-gate * Calculate the location of definition; 7587c478bd9Sstevel@tonic-gate * symbol value plus base address of 7597c478bd9Sstevel@tonic-gate * containing shared object. 7607c478bd9Sstevel@tonic-gate */ 7612926dd2eSrie if (IS_SIZE(rtype)) 7622926dd2eSrie value = symdef->st_size; 7632926dd2eSrie else 7647c478bd9Sstevel@tonic-gate value = symdef->st_value; 7652926dd2eSrie 7667c478bd9Sstevel@tonic-gate if (!(FLAGS(_lmp) & FLG_RT_FIXED) && 7672926dd2eSrie !(IS_SIZE(rtype)) && 7687c478bd9Sstevel@tonic-gate (symdef->st_shndx != SHN_ABS) && 7697c478bd9Sstevel@tonic-gate (ELF_ST_TYPE(symdef->st_info) != 7707c478bd9Sstevel@tonic-gate STT_TLS)) 7717c478bd9Sstevel@tonic-gate value += ADDR(_lmp); 7727c478bd9Sstevel@tonic-gate 7737c478bd9Sstevel@tonic-gate /* 7747c478bd9Sstevel@tonic-gate * Retain this symbol index and the 7757c478bd9Sstevel@tonic-gate * value in case it can be used for the 7767c478bd9Sstevel@tonic-gate * subsequent relocations. 7777c478bd9Sstevel@tonic-gate */ 7787c478bd9Sstevel@tonic-gate if (rtype != R_AMD64_COPY) { 7797c478bd9Sstevel@tonic-gate psymndx = rsymndx; 7807c478bd9Sstevel@tonic-gate pvalue = value; 7817c478bd9Sstevel@tonic-gate pname = name; 7827c478bd9Sstevel@tonic-gate psymdef = symdef; 7837c478bd9Sstevel@tonic-gate psymref = symref; 7847c478bd9Sstevel@tonic-gate plmp = _lmp; 7857c478bd9Sstevel@tonic-gate pbinfo = binfo; 7867c478bd9Sstevel@tonic-gate } 7877c478bd9Sstevel@tonic-gate if ((LIST(_lmp)->lm_tflags | 78856deab07SRod Evans AFLAGS(_lmp)) & 7897c478bd9Sstevel@tonic-gate LML_TFLG_AUD_SYMBIND) { 7907c478bd9Sstevel@tonic-gate dsymndx = (((uintptr_t)symdef - 7917c478bd9Sstevel@tonic-gate (uintptr_t)SYMTAB(_lmp)) / 7927c478bd9Sstevel@tonic-gate SYMENT(_lmp)); 7937c478bd9Sstevel@tonic-gate value = audit_symbind(lmp, _lmp, 7947c478bd9Sstevel@tonic-gate symdef, dsymndx, value, 7957c478bd9Sstevel@tonic-gate &sb_flags); 7967c478bd9Sstevel@tonic-gate } 7977c478bd9Sstevel@tonic-gate } 7987c478bd9Sstevel@tonic-gate 7997c478bd9Sstevel@tonic-gate /* 8007c478bd9Sstevel@tonic-gate * If relocation is PC-relative, subtract 8017c478bd9Sstevel@tonic-gate * offset address. 8027c478bd9Sstevel@tonic-gate */ 8037c478bd9Sstevel@tonic-gate if (IS_PC_RELATIVE(rtype)) 8047c478bd9Sstevel@tonic-gate value -= roffset; 8057c478bd9Sstevel@tonic-gate 8067c478bd9Sstevel@tonic-gate /* 807d326b23bSrie * Special case TLS relocations. 8087c478bd9Sstevel@tonic-gate */ 809d326b23bSrie if (rtype == R_AMD64_DTPMOD64) { 810d326b23bSrie /* 811d326b23bSrie * Relocation value is the TLS modid. 812d326b23bSrie */ 8137c478bd9Sstevel@tonic-gate value = TLSMODID(_lmp); 814d326b23bSrie 815d326b23bSrie } else if ((rtype == R_AMD64_TPOFF64) || 816d326b23bSrie (rtype == R_AMD64_TPOFF32)) { 817d326b23bSrie if ((value = elf_static_tls(_lmp, 818d326b23bSrie symdef, rel, rtype, name, roffset, 819d326b23bSrie value)) == 0) { 820d326b23bSrie ret = 0; 821d326b23bSrie break; 822d326b23bSrie } 823d326b23bSrie } 8247c478bd9Sstevel@tonic-gate } 8257c478bd9Sstevel@tonic-gate } else { 8267c478bd9Sstevel@tonic-gate /* 827d326b23bSrie * Special cases. 8287c478bd9Sstevel@tonic-gate */ 829d326b23bSrie if (rtype == R_AMD64_DTPMOD64) { 830d326b23bSrie /* 831d326b23bSrie * TLS relocation value is the TLS modid. 832d326b23bSrie */ 8337c478bd9Sstevel@tonic-gate value = TLSMODID(lmp); 834d326b23bSrie } else 8357c478bd9Sstevel@tonic-gate value = basebgn; 83608278a5eSRod Evans 83708278a5eSRod Evans name = NULL; 8387c478bd9Sstevel@tonic-gate } 8397c478bd9Sstevel@tonic-gate 840d326b23bSrie DBG_CALL(Dbg_reloc_in(LIST(lmp), ELF_DBG_RTLD, M_MACH, 841e23c41c9SAli Bahrami M_REL_SHT_TYPE, rel, NULL, 0, name)); 842d326b23bSrie 8437c478bd9Sstevel@tonic-gate /* 84456deab07SRod Evans * Make sure the segment is writable. 8457c478bd9Sstevel@tonic-gate */ 84656deab07SRod Evans if (((mpp->mr_prot & PROT_WRITE) == 0) && 84756deab07SRod Evans ((set_prot(lmp, mpp, 1) == 0) || 84856deab07SRod Evans (aplist_append(textrel, mpp, AL_CNT_TEXTREL) == NULL))) { 8497c478bd9Sstevel@tonic-gate ret = 0; 8507c478bd9Sstevel@tonic-gate break; 8517c478bd9Sstevel@tonic-gate } 8527c478bd9Sstevel@tonic-gate 8537c478bd9Sstevel@tonic-gate /* 8547c478bd9Sstevel@tonic-gate * Call relocation routine to perform required relocation. 8557c478bd9Sstevel@tonic-gate */ 8567c478bd9Sstevel@tonic-gate switch (rtype) { 8577c478bd9Sstevel@tonic-gate case R_AMD64_COPY: 8587c478bd9Sstevel@tonic-gate if (elf_copy_reloc(name, symref, lmp, (void *)roffset, 8597c478bd9Sstevel@tonic-gate symdef, _lmp, (const void *)value) == 0) 8607c478bd9Sstevel@tonic-gate ret = 0; 8617c478bd9Sstevel@tonic-gate break; 8627c478bd9Sstevel@tonic-gate case R_AMD64_JUMP_SLOT: 86356deab07SRod Evans if (((LIST(lmp)->lm_tflags | AFLAGS(lmp)) & 8647c478bd9Sstevel@tonic-gate (LML_TFLG_AUD_PLTENTER | LML_TFLG_AUD_PLTEXIT)) && 8657c478bd9Sstevel@tonic-gate AUDINFO(lmp)->ai_dynplts) { 8667c478bd9Sstevel@tonic-gate int fail = 0; 8677c478bd9Sstevel@tonic-gate int pltndx = (((ulong_t)rel - 8687c478bd9Sstevel@tonic-gate (uintptr_t)JMPREL(lmp)) / relsiz); 8697c478bd9Sstevel@tonic-gate int symndx = (((uintptr_t)symdef - 8707247f888Srie (uintptr_t)SYMTAB(_lmp)) / SYMENT(_lmp)); 8717c478bd9Sstevel@tonic-gate 8727c478bd9Sstevel@tonic-gate (void) elf_plt_trace_write(roffset, lmp, _lmp, 8737c478bd9Sstevel@tonic-gate symdef, symndx, pltndx, (caddr_t)value, 8747c478bd9Sstevel@tonic-gate sb_flags, &fail); 8757c478bd9Sstevel@tonic-gate if (fail) 8767c478bd9Sstevel@tonic-gate ret = 0; 8777c478bd9Sstevel@tonic-gate } else { 8787c478bd9Sstevel@tonic-gate /* 8797c478bd9Sstevel@tonic-gate * Write standard PLT entry to jump directly 8807c478bd9Sstevel@tonic-gate * to newly bound function. 8817c478bd9Sstevel@tonic-gate */ 8825aefb655Srie DBG_CALL(Dbg_reloc_apply_val(LIST(lmp), 8835aefb655Srie ELF_DBG_RTLD, (Xword)roffset, 8847c478bd9Sstevel@tonic-gate (Xword)value)); 8857c478bd9Sstevel@tonic-gate *(ulong_t *)roffset = value; 8867c478bd9Sstevel@tonic-gate } 8877c478bd9Sstevel@tonic-gate break; 8887c478bd9Sstevel@tonic-gate default: 8897c478bd9Sstevel@tonic-gate value += reladd; 8907c478bd9Sstevel@tonic-gate /* 8917c478bd9Sstevel@tonic-gate * Write the relocation out. 8927c478bd9Sstevel@tonic-gate */ 893f3324781Sab196087 if (do_reloc_rtld(rtype, (uchar_t *)roffset, 8945aefb655Srie (Xword *)&value, name, NAME(lmp), LIST(lmp)) == 0) 8957c478bd9Sstevel@tonic-gate ret = 0; 8967c478bd9Sstevel@tonic-gate 8975aefb655Srie DBG_CALL(Dbg_reloc_apply_val(LIST(lmp), ELF_DBG_RTLD, 8985aefb655Srie (Xword)roffset, (Xword)value)); 8997c478bd9Sstevel@tonic-gate } 9007c478bd9Sstevel@tonic-gate 9017c478bd9Sstevel@tonic-gate if ((ret == 0) && 9027c478bd9Sstevel@tonic-gate ((LIST(lmp)->lm_flags & LML_FLG_TRC_WARN) == 0)) 9037c478bd9Sstevel@tonic-gate break; 9047c478bd9Sstevel@tonic-gate 9057c478bd9Sstevel@tonic-gate if (binfo) { 9065aefb655Srie DBG_CALL(Dbg_bind_global(lmp, (Addr)roffset, 9075aefb655Srie (Off)(roffset - basebgn), (Xword)(-1), PLT_T_FULL, 9085aefb655Srie _lmp, (Addr)value, symdef->st_value, name, binfo)); 9097c478bd9Sstevel@tonic-gate } 9107c478bd9Sstevel@tonic-gate } 9117c478bd9Sstevel@tonic-gate 91256deab07SRod Evans return (relocate_finish(lmp, bound, ret)); 9137c478bd9Sstevel@tonic-gate } 9147c478bd9Sstevel@tonic-gate 9157c478bd9Sstevel@tonic-gate /* 9167c478bd9Sstevel@tonic-gate * Initialize the first few got entries so that function calls go to 9177c478bd9Sstevel@tonic-gate * elf_rtbndr: 9187c478bd9Sstevel@tonic-gate * 9197c478bd9Sstevel@tonic-gate * GOT[GOT_XLINKMAP] = the address of the link map 9207c478bd9Sstevel@tonic-gate * GOT[GOT_XRTLD] = the address of rtbinder 9217c478bd9Sstevel@tonic-gate */ 9227c478bd9Sstevel@tonic-gate void 9237c478bd9Sstevel@tonic-gate elf_plt_init(void *got, caddr_t l) 9247c478bd9Sstevel@tonic-gate { 9257c478bd9Sstevel@tonic-gate uint64_t *_got; 9267c478bd9Sstevel@tonic-gate /* LINTED */ 9277c478bd9Sstevel@tonic-gate Rt_map *lmp = (Rt_map *)l; 9287c478bd9Sstevel@tonic-gate 9297c478bd9Sstevel@tonic-gate _got = (uint64_t *)got + M_GOT_XLINKMAP; 9307c478bd9Sstevel@tonic-gate *_got = (uint64_t)lmp; 9317c478bd9Sstevel@tonic-gate _got = (uint64_t *)got + M_GOT_XRTLD; 9327c478bd9Sstevel@tonic-gate *_got = (uint64_t)elf_rtbndr; 9337c478bd9Sstevel@tonic-gate } 9347c478bd9Sstevel@tonic-gate 9357c478bd9Sstevel@tonic-gate /* 9367c478bd9Sstevel@tonic-gate * Plt writing interface to allow debugging initialization to be generic. 9377c478bd9Sstevel@tonic-gate */ 9387c478bd9Sstevel@tonic-gate Pltbindtype 9397c478bd9Sstevel@tonic-gate /* ARGSUSED1 */ 9407c478bd9Sstevel@tonic-gate elf_plt_write(uintptr_t addr, uintptr_t vaddr, void *rptr, uintptr_t symval, 9417c478bd9Sstevel@tonic-gate Xword pltndx) 9427c478bd9Sstevel@tonic-gate { 9437c478bd9Sstevel@tonic-gate Rela *rel = (Rela*)rptr; 9447c478bd9Sstevel@tonic-gate uintptr_t pltaddr; 9457c478bd9Sstevel@tonic-gate 9467c478bd9Sstevel@tonic-gate pltaddr = addr + rel->r_offset; 9477c478bd9Sstevel@tonic-gate *(ulong_t *)pltaddr = (ulong_t)symval + rel->r_addend; 9487c478bd9Sstevel@tonic-gate DBG_CALL(pltcntfull++); 9497c478bd9Sstevel@tonic-gate return (PLT_T_FULL); 9507c478bd9Sstevel@tonic-gate } 9517c478bd9Sstevel@tonic-gate 9527c478bd9Sstevel@tonic-gate /* 9537c478bd9Sstevel@tonic-gate * Provide a machine specific interface to the conversion routine. By calling 9547c478bd9Sstevel@tonic-gate * the machine specific version, rather than the generic version, we insure that 9557c478bd9Sstevel@tonic-gate * the data tables/strings for all known machine versions aren't dragged into 9567c478bd9Sstevel@tonic-gate * ld.so.1. 9577c478bd9Sstevel@tonic-gate */ 9587c478bd9Sstevel@tonic-gate const char * 9595aefb655Srie _conv_reloc_type(uint_t rel) 9607c478bd9Sstevel@tonic-gate { 961de777a60Sab196087 static Conv_inv_buf_t inv_buf; 962de777a60Sab196087 963de777a60Sab196087 return (conv_reloc_amd64_type(rel, 0, &inv_buf)); 9647c478bd9Sstevel@tonic-gate } 965