1/*	$NetBSD: mdreloc.c,v 1.46 2023/06/04 01:24:57 joerg Exp $	*/
2
3#include <sys/cdefs.h>
4#ifndef lint
5__RCSID("$NetBSD: mdreloc.c,v 1.46 2023/06/04 01:24:57 joerg Exp $");
6#endif /* not lint */
7
8#include <sys/types.h>
9#include <string.h>
10
11#include "debug.h"
12#include "rtld.h"
13
14void _rtld_bind_start(void);
15void _rtld_relocate_nonplt_self(Elf_Dyn *, Elf_Addr);
16caddr_t _rtld_bind(const Obj_Entry *, Elf_Word);
17
18void
19_rtld_setup_pltgot(const Obj_Entry *obj)
20{
21	obj->pltgot[1] = (Elf_Addr) obj;
22	obj->pltgot[2] = (Elf_Addr) &_rtld_bind_start;
23}
24
25void
26_rtld_relocate_nonplt_self(Elf_Dyn *dynp, Elf_Addr relocbase)
27{
28	const Elf_Rel *rel = 0, *rellim;
29	Elf_Addr relsz = 0;
30	Elf_Addr *where;
31
32	for (; dynp->d_tag != DT_NULL; dynp++) {
33		switch (dynp->d_tag) {
34		case DT_REL:
35			rel = (const Elf_Rel *)(relocbase + dynp->d_un.d_ptr);
36			break;
37		case DT_RELSZ:
38			relsz = dynp->d_un.d_val;
39			break;
40		}
41	}
42	rellim = (const Elf_Rel *)((const uint8_t *)rel + relsz);
43	for (; rel < rellim; rel++) {
44		where = (Elf_Addr *)(relocbase + rel->r_offset);
45		*where += (Elf_Addr)relocbase;
46	}
47}
48
49/*
50 * It is possible for the compiler to emit relocations for unaligned data.
51 * We handle this situation with these inlines.
52 */
53#define	RELOC_ALIGNED_P(x) \
54	(((uintptr_t)(x) & (sizeof(void *) - 1)) == 0)
55
56static inline Elf_Addr
57load_ptr(void *where)
58{
59	Elf_Addr res;
60
61	memcpy(&res, where, sizeof(res));
62
63	return (res);
64}
65
66static inline void
67store_ptr(void *where, Elf_Addr val)
68{
69
70	memcpy(where, &val, sizeof(val));
71}
72
73int
74_rtld_relocate_nonplt_objects(Obj_Entry *obj)
75{
76	const Elf_Rel *rel;
77	const Elf_Sym *def = NULL;
78	const Obj_Entry *defobj = NULL;
79	unsigned long last_symnum = ULONG_MAX;
80
81	for (rel = obj->rel; rel < obj->rellim; rel++) {
82		Elf_Addr        *where;
83		Elf_Addr         tmp;
84		unsigned long	 symnum;
85
86		where = (Elf_Addr *)(obj->relocbase + rel->r_offset);
87
88		switch (ELF_R_TYPE(rel->r_info)) {
89		case R_TYPE(PC24):	/* word32 S - P + A */
90		case R_TYPE(ABS32):	/* word32 B + S + A */
91		case R_TYPE(GLOB_DAT):	/* word32 B + S */
92		case R_TYPE(TLS_DTPOFF32):
93		case R_TYPE(TLS_DTPMOD32):
94		case R_TYPE(TLS_TPOFF32):
95			symnum = ELF_R_SYM(rel->r_info);
96			if (last_symnum != symnum) {
97				last_symnum = symnum;
98				def = _rtld_find_symdef(symnum, obj, &defobj,
99				    false);
100				if (def == NULL)
101					return -1;
102			}
103			break;
104
105		default:
106			break;
107		}
108
109		switch (ELF_R_TYPE(rel->r_info)) {
110		case R_TYPE(NONE):
111			break;
112
113#if 1 /* XXX should not occur */
114		case R_TYPE(PC24): {	/* word32 S - P + A */
115			Elf32_Sword addend;
116
117			/*
118			 * Extract addend and sign-extend if needed.
119			 */
120			addend = *where;
121			if (addend & 0x00800000)
122				addend |= 0xff000000;
123			tmp = (Elf_Addr)obj->relocbase + def->st_value
124			    - (Elf_Addr)where + (addend << 2);
125			if ((tmp & 0xfe000000) != 0xfe000000 &&
126			    (tmp & 0xfe000000) != 0) {
127				_rtld_error(
128				"%s: R_ARM_PC24 relocation @ %p to %s failed "
129				"(displacement %ld (%#lx) out of range)",
130				    obj->path, where,
131				    obj->strtab + obj->symtab[
132				        ELF_R_SYM(rel->r_info)].st_name,
133				    (long) tmp, (long) tmp);
134				return -1;
135			}
136			tmp >>= 2;
137			*where = (*where & 0xff000000) | (tmp & 0x00ffffff);
138			rdbg(("PC24 %s in %s --> %p @ %p in %s",
139			    obj->strtab + obj->symtab[ELF_R_SYM(rel->r_info)]
140			    .st_name, obj->path, (void *)*where, where,
141			    defobj->path));
142			break;
143		}
144#endif
145
146		case R_TYPE(ABS32):	/* word32 B + S + A */
147		case R_TYPE(GLOB_DAT):	/* word32 B + S */
148			if (__predict_true(RELOC_ALIGNED_P(where))) {
149				tmp = *where + (Elf_Addr)defobj->relocbase +
150				    def->st_value;
151				/* Set the Thumb bit, if needed.  */
152				if (ELF_ST_TYPE(def->st_info) == STT_ARM_TFUNC)
153				    tmp |= 1;
154				*where = tmp;
155			} else {
156				tmp = load_ptr(where) +
157				    (Elf_Addr)defobj->relocbase +
158				    def->st_value;
159				/* Set the Thumb bit, if needed.  */
160				if (ELF_ST_TYPE(def->st_info) == STT_ARM_TFUNC)
161				    tmp |= 1;
162				store_ptr(where, tmp);
163			}
164			rdbg(("ABS32/GLOB_DAT %s in %s --> %p @ %p in %s",
165			    obj->strtab + obj->symtab[ELF_R_SYM(rel->r_info)]
166			    .st_name, obj->path, (void *)tmp, where,
167			    defobj->path));
168			break;
169
170		case R_TYPE(IRELATIVE):
171			/* IFUNC relocations are handled in _rtld_call_ifunc */
172			if (obj->ifunc_remaining_nonplt == 0)
173				obj->ifunc_remaining_nonplt = obj->rellim - rel;
174			/* FALL-THROUGH */
175
176		case R_TYPE(RELATIVE):	/* word32 B + A */
177			if (__predict_true(RELOC_ALIGNED_P(where))) {
178				tmp = *where + (Elf_Addr)obj->relocbase;
179				*where = tmp;
180			} else {
181				tmp = load_ptr(where) +
182				    (Elf_Addr)obj->relocbase;
183				store_ptr(where, tmp);
184			}
185			rdbg(("RELATIVE in %s --> %p", obj->path,
186			    (void *)tmp));
187			break;
188
189		case R_TYPE(COPY):
190			/*
191			 * These are deferred until all other relocations have
192			 * been done.  All we do here is make sure that the
193			 * COPY relocation is not in a shared library.  They
194			 * are allowed only in executable files.
195			 */
196			if (obj->isdynamic) {
197				_rtld_error(
198			"%s: Unexpected R_COPY relocation in shared library",
199				    obj->path);
200				return -1;
201			}
202			rdbg(("COPY (avoid in main)"));
203			break;
204
205		case R_TYPE(TLS_DTPOFF32):
206			tmp = (Elf_Addr)(def->st_value);
207			if (__predict_true(RELOC_ALIGNED_P(where)))
208				*where = tmp;
209			else
210				store_ptr(where, tmp);
211
212			rdbg(("TLS_DTPOFF32 %s in %s --> %p",
213			    obj->strtab + obj->symtab[ELF_R_SYM(rel->r_info)]
214			    .st_name, obj->path, (void *)tmp));
215
216			break;
217		case R_TYPE(TLS_DTPMOD32):
218			tmp = (Elf_Addr)(defobj->tlsindex);
219			if (__predict_true(RELOC_ALIGNED_P(where)))
220				*where = tmp;
221			else
222				store_ptr(where, tmp);
223
224			rdbg(("TLS_DTPMOD32 %s in %s --> %p",
225			    obj->strtab + obj->symtab[ELF_R_SYM(rel->r_info)]
226			    .st_name, obj->path, (void *)tmp));
227
228			break;
229
230		case R_TYPE(TLS_TPOFF32):
231			if (!defobj->tls_static &&
232			    _rtld_tls_offset_allocate(__UNCONST(defobj)))
233				return -1;
234
235			if (__predict_true(RELOC_ALIGNED_P(where)))
236				tmp = *where;
237			else
238				tmp = load_ptr(where);
239			tmp += (Elf_Addr)def->st_value + defobj->tlsoffset + sizeof(struct tls_tcb);
240			if (__predict_true(RELOC_ALIGNED_P(where)))
241				*where = tmp;
242			else
243				store_ptr(where, tmp);
244			rdbg(("TLS_TPOFF32 %s in %s --> %p",
245			    obj->strtab + obj->symtab[ELF_R_SYM(rel->r_info)]
246			    .st_name, obj->path, (void *)tmp));
247			break;
248
249		default:
250			rdbg(("sym = %lu, type = %lu, offset = %p, "
251			    "contents = %p",
252			    (u_long)ELF_R_SYM(rel->r_info),
253			    (u_long)ELF_R_TYPE(rel->r_info),
254			    (void *)rel->r_offset, (void *)load_ptr(where)));
255			_rtld_error("%s: Unsupported relocation type %ld "
256			    "in non-PLT relocations",
257			    obj->path, (u_long) ELF_R_TYPE(rel->r_info));
258			return -1;
259		}
260	}
261	return 0;
262}
263
264int
265_rtld_relocate_plt_lazy(Obj_Entry *obj)
266{
267	const Elf_Rel *rel;
268
269	for (rel = obj->pltrellim; rel-- > obj->pltrel; ) {
270		Elf_Addr *where = (Elf_Addr *)(obj->relocbase + rel->r_offset);
271
272		assert(ELF_R_TYPE(rel->r_info) == R_TYPE(JUMP_SLOT) ||
273		       ELF_R_TYPE(rel->r_info) == R_TYPE(IRELATIVE));
274
275		if (ELF_R_TYPE(rel->r_info) == R_TYPE(IRELATIVE))
276			obj->ifunc_remaining = obj->pltrellim - rel;
277
278		/* Just relocate the GOT slots pointing into the PLT */
279		*where += (Elf_Addr)obj->relocbase;
280		rdbg(("fixup !main in %s --> %p", obj->path, (void *)*where));
281	}
282
283	return 0;
284}
285
286static int
287_rtld_relocate_plt_object(const Obj_Entry *obj, const Elf_Rel *rel,
288	Elf_Addr *tp)
289{
290	Elf_Addr *where = (Elf_Addr *)(obj->relocbase + rel->r_offset);
291	Elf_Addr new_value;
292	const Elf_Sym  *def;
293	const Obj_Entry *defobj;
294	unsigned long info = rel->r_info;
295
296	assert(ELF_R_TYPE(info) == R_TYPE(JUMP_SLOT));
297
298	def = _rtld_find_plt_symdef(ELF_R_SYM(info), obj, &defobj, tp != NULL);
299	if (__predict_false(def == NULL))
300		return -1;
301	if (__predict_false(def == &_rtld_sym_zero))
302		return 0;
303
304	if (ELF_ST_TYPE(def->st_info) == STT_GNU_IFUNC) {
305		if (tp == NULL)
306			return 0;
307		new_value = _rtld_resolve_ifunc(defobj, def);
308	} else {
309		new_value = (Elf_Addr)(defobj->relocbase + def->st_value);
310	}
311	/* Set the Thumb bit, if needed.  */
312	if (ELF_ST_TYPE(def->st_info) == STT_ARM_TFUNC)
313		new_value |= 1;
314	rdbg(("bind now/fixup in %s --> old=%p new=%p",
315	    defobj->strtab + def->st_name, (void *)*where, (void *)new_value));
316	if (*where != new_value)
317		*where = new_value;
318	if (tp)
319		*tp = new_value;
320
321	return 0;
322}
323
324caddr_t
325_rtld_bind(const Obj_Entry *obj, Elf_Word reloff)
326{
327	const Elf_Rel *rel = (const Elf_Rel *)((const uint8_t *)obj->pltrel + reloff);
328	Elf_Addr new_value = 0;	/* XXX gcc */
329	int err;
330
331	_rtld_shared_enter();
332	err = _rtld_relocate_plt_object(obj, rel, &new_value);
333	if (err)
334		_rtld_die();
335	_rtld_shared_exit();
336
337	return (caddr_t)new_value;
338}
339int
340_rtld_relocate_plt_objects(const Obj_Entry *obj)
341{
342	const Elf_Rel *rel;
343	int err = 0;
344
345	for (rel = obj->pltrel; rel < obj->pltrellim; rel++) {
346		err = _rtld_relocate_plt_object(obj, rel, NULL);
347		if (err)
348			break;
349	}
350
351	return err;
352}
353