1 /*
2  * Copyright (C) 2008 The Android Open Source Project
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *  * Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  *  * Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in
12  *    the documentation and/or other materials provided with the
13  *    distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include <android/api-level.h>
30 #include <elf.h>
31 #include <errno.h>
32 #include <stddef.h>
33 #include <stdint.h>
34 #include <stdio.h>
35 #include <stdlib.h>
36 #include <sys/auxv.h>
37 #include <sys/mman.h>
38 
39 #include "libc_init_common.h"
40 #include "pthread_internal.h"
41 
42 #include "platform/bionic/page.h"
43 #include "private/bionic_call_ifunc_resolver.h"
44 #include "private/bionic_elf_tls.h"
45 #include "private/bionic_globals.h"
46 #include "platform/bionic/macros.h"
47 #include "private/bionic_tls.h"
48 #include "private/KernelArgumentBlock.h"
49 
50 #if __has_feature(hwaddress_sanitizer)
51 #include <sanitizer/hwasan_interface.h>
52 #endif
53 
54 // Leave the variable uninitialized for the sake of the dynamic loader, which
55 // links in this file. The loader will initialize this variable before
56 // relocating itself.
57 #if defined(__i386__)
58 __LIBC_HIDDEN__ void* __libc_sysinfo;
59 #endif
60 
61 extern "C" int __cxa_atexit(void (*)(void *), void *, void *);
62 
call_array(void (** list)())63 static void call_array(void(**list)()) {
64   // First element is -1, list is null-terminated
65   while (*++list) {
66     (*list)();
67   }
68 }
69 
70 #if defined(__aarch64__) || defined(__x86_64__)
71 extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rela) __rela_iplt_start[], __rela_iplt_end[];
72 
call_ifunc_resolvers()73 static void call_ifunc_resolvers() {
74   if (__rela_iplt_start == nullptr || __rela_iplt_end == nullptr) {
75     // These symbols are not emitted by gold. Gold has code to do so, but for
76     // whatever reason it is not being run. In these cases ifuncs cannot be
77     // resolved, so we do not support using ifuncs in static executables linked
78     // with gold.
79     //
80     // Since they are weak, they will be non-null when linked with bfd/lld and
81     // null when linked with gold.
82     return;
83   }
84 
85   for (ElfW(Rela) *r = __rela_iplt_start; r != __rela_iplt_end; ++r) {
86     ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
87     ElfW(Addr) resolver = r->r_addend;
88     *offset = __bionic_call_ifunc_resolver(resolver);
89   }
90 }
91 #else
92 extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rel) __rel_iplt_start[], __rel_iplt_end[];
93 
call_ifunc_resolvers()94 static void call_ifunc_resolvers() {
95   if (__rel_iplt_start == nullptr || __rel_iplt_end == nullptr) {
96     // These symbols are not emitted by gold. Gold has code to do so, but for
97     // whatever reason it is not being run. In these cases ifuncs cannot be
98     // resolved, so we do not support using ifuncs in static executables linked
99     // with gold.
100     //
101     // Since they are weak, they will be non-null when linked with bfd/lld and
102     // null when linked with gold.
103     return;
104   }
105 
106   for (ElfW(Rel) *r = __rel_iplt_start; r != __rel_iplt_end; ++r) {
107     ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
108     ElfW(Addr) resolver = *offset;
109     *offset = __bionic_call_ifunc_resolver(resolver);
110   }
111 }
112 #endif
113 
apply_gnu_relro()114 static void apply_gnu_relro() {
115   ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
116   unsigned long int phdr_ct = getauxval(AT_PHNUM);
117 
118   for (ElfW(Phdr)* phdr = phdr_start; phdr < (phdr_start + phdr_ct); phdr++) {
119     if (phdr->p_type != PT_GNU_RELRO) {
120       continue;
121     }
122 
123     ElfW(Addr) seg_page_start = PAGE_START(phdr->p_vaddr);
124     ElfW(Addr) seg_page_end = PAGE_END(phdr->p_vaddr + phdr->p_memsz);
125 
126     // Check return value here? What do we do if we fail?
127     mprotect(reinterpret_cast<void*>(seg_page_start), seg_page_end - seg_page_start, PROT_READ);
128   }
129 }
130 
layout_static_tls(KernelArgumentBlock & args)131 static void layout_static_tls(KernelArgumentBlock& args) {
132   StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout;
133   layout.reserve_bionic_tls();
134 
135   const char* progname = args.argv[0];
136   ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
137   size_t phdr_ct = getauxval(AT_PHNUM);
138 
139   static TlsModule mod;
140   TlsModules& modules = __libc_shared_globals()->tls_modules;
141   if (__bionic_get_tls_segment(phdr_start, phdr_ct, 0, &mod.segment)) {
142     if (!__bionic_check_tls_alignment(&mod.segment.alignment)) {
143       async_safe_fatal("error: TLS segment alignment in \"%s\" is not a power of 2: %zu\n",
144                        progname, mod.segment.alignment);
145     }
146     mod.static_offset = layout.reserve_exe_segment_and_tcb(&mod.segment, progname);
147     mod.first_generation = kTlsGenerationFirst;
148 
149     modules.module_count = 1;
150     modules.module_table = &mod;
151   } else {
152     layout.reserve_exe_segment_and_tcb(nullptr, progname);
153   }
154   // Enable the fast path in __tls_get_addr.
155   __libc_tls_generation_copy = modules.generation;
156 
157   layout.finish_layout();
158 }
159 
__real_libc_init(void * raw_args,void (* onexit)(void)__unused,int (* slingshot)(int,char **,char **),structors_array_t const * const structors,bionic_tcb * temp_tcb)160 __noreturn static void __real_libc_init(void *raw_args,
161                                         void (*onexit)(void) __unused,
162                                         int (*slingshot)(int, char**, char**),
163                                         structors_array_t const * const structors,
164                                         bionic_tcb* temp_tcb) {
165   BIONIC_STOP_UNWIND;
166 
167   // Initialize TLS early so system calls and errno work.
168   KernelArgumentBlock args(raw_args);
169   __libc_init_main_thread_early(args, temp_tcb);
170   __libc_init_main_thread_late();
171   __libc_init_globals();
172   __libc_shared_globals()->init_progname = args.argv[0];
173   __libc_init_AT_SECURE(args.envp);
174   layout_static_tls(args);
175   __libc_init_main_thread_final();
176   __libc_init_common();
177   __libc_init_fork_handler();
178 
179   call_ifunc_resolvers();
180   apply_gnu_relro();
181 
182   // Several Linux ABIs don't pass the onexit pointer, and the ones that
183   // do never use it.  Therefore, we ignore it.
184 
185   call_array(structors->preinit_array);
186   call_array(structors->init_array);
187 
188   // The executable may have its own destructors listed in its .fini_array
189   // so we need to ensure that these are called when the program exits
190   // normally.
191   if (structors->fini_array != nullptr) {
192     __cxa_atexit(__libc_fini,structors->fini_array,nullptr);
193   }
194 
195   exit(slingshot(args.argc, args.argv, args.envp));
196 }
197 
198 extern "C" void __hwasan_init_static();
199 
200 // This __libc_init() is only used for static executables, and is called from crtbegin.c.
201 //
202 // The 'structors' parameter contains pointers to various initializer
203 // arrays that must be run before the program's 'main' routine is launched.
204 __attribute__((no_sanitize("hwaddress")))
__libc_init(void * raw_args,void (* onexit)(void)__unused,int (* slingshot)(int,char **,char **),structors_array_t const * const structors)205 __noreturn void __libc_init(void* raw_args,
206                             void (*onexit)(void) __unused,
207                             int (*slingshot)(int, char**, char**),
208                             structors_array_t const * const structors) {
209   bionic_tcb temp_tcb = {};
210 #if __has_feature(hwaddress_sanitizer)
211   // Install main thread TLS early. It will be initialized later in __libc_init_main_thread. For now
212   // all we need is access to TLS_SLOT_SANITIZER.
213   __set_tls(&temp_tcb.tls_slot(0));
214   // Initialize HWASan enough to run instrumented code. This sets up TLS_SLOT_SANITIZER, among other
215   // things.
216   __hwasan_init_static();
217   // We are ready to run HWASan-instrumented code, proceed with libc initialization...
218 #endif
219   __real_libc_init(raw_args, onexit, slingshot, structors, &temp_tcb);
220 }
221 
222 static int g_target_sdk_version{__ANDROID_API__};
223 
android_get_application_target_sdk_version()224 extern "C" int android_get_application_target_sdk_version() {
225   return g_target_sdk_version;
226 }
227 
android_set_application_target_sdk_version(int target)228 extern "C" void android_set_application_target_sdk_version(int target) {
229   g_target_sdk_version = target;
230 }
231 
232 // This function is called in the dynamic linker before ifunc resolvers have run, so this file is
233 // compiled with -ffreestanding to avoid implicit string.h function calls. (It shouldn't strictly
234 // be necessary, though.)
__libc_shared_globals()235 __LIBC_HIDDEN__ libc_shared_globals* __libc_shared_globals() {
236   static libc_shared_globals globals;
237   return &globals;
238 }
239