1 /*
2  * Copyright (C) 2008 The Android Open Source Project
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *  * Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  *  * Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in
12  *    the documentation and/or other materials provided with the
13  *    distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include <android/api-level.h>
30 #include <errno.h>
31 #include <fcntl.h>
32 #include <inttypes.h>
33 #include <pthread.h>
34 #include <stdio.h>
35 #include <stdlib.h>
36 #include <string.h>
37 #include <sys/mman.h>
38 #include <sys/param.h>
39 #include <sys/vfs.h>
40 #include <unistd.h>
41 
42 #include <new>
43 #include <string>
44 #include <unordered_map>
45 #include <vector>
46 
47 #include <android-base/properties.h>
48 #include <android-base/scopeguard.h>
49 #include <async_safe/log.h>
50 #include <bionic/pthread_internal.h>
51 
52 // Private C library headers.
53 
54 #include "linker.h"
55 #include "linker_block_allocator.h"
56 #include "linker_cfi.h"
57 #include "linker_config.h"
58 #include "linker_gdb_support.h"
59 #include "linker_globals.h"
60 #include "linker_debug.h"
61 #include "linker_dlwarning.h"
62 #include "linker_main.h"
63 #include "linker_namespaces.h"
64 #include "linker_sleb128.h"
65 #include "linker_phdr.h"
66 #include "linker_relocate.h"
67 #include "linker_tls.h"
68 #include "linker_translate_path.h"
69 #include "linker_utils.h"
70 
71 #include "private/bionic_call_ifunc_resolver.h"
72 #include "private/bionic_globals.h"
73 #include "android-base/macros.h"
74 #include "android-base/strings.h"
75 #include "android-base/stringprintf.h"
76 #include "ziparchive/zip_archive.h"
77 
78 static std::unordered_map<void*, size_t> g_dso_handle_counters;
79 
80 static bool g_anonymous_namespace_set = false;
81 static android_namespace_t* g_anonymous_namespace = &g_default_namespace;
82 static std::unordered_map<std::string, android_namespace_t*> g_exported_namespaces;
83 
84 static LinkerTypeAllocator<soinfo> g_soinfo_allocator;
85 static LinkerTypeAllocator<LinkedListEntry<soinfo>> g_soinfo_links_allocator;
86 
87 static LinkerTypeAllocator<android_namespace_t> g_namespace_allocator;
88 static LinkerTypeAllocator<LinkedListEntry<android_namespace_t>> g_namespace_list_allocator;
89 
90 static uint64_t g_module_load_counter = 0;
91 static uint64_t g_module_unload_counter = 0;
92 
93 static const char* const kLdConfigArchFilePath = "/system/etc/ld.config." ABI_STRING ".txt";
94 
95 static const char* const kLdConfigFilePath = "/system/etc/ld.config.txt";
96 static const char* const kLdConfigVndkLiteFilePath = "/system/etc/ld.config.vndk_lite.txt";
97 
98 static const char* const kLdGeneratedConfigFilePath = "/linkerconfig/ld.config.txt";
99 
100 #if defined(__LP64__)
101 static const char* const kSystemLibDir        = "/system/lib64";
102 static const char* const kOdmLibDir           = "/odm/lib64";
103 static const char* const kVendorLibDir        = "/vendor/lib64";
104 static const char* const kAsanSystemLibDir    = "/data/asan/system/lib64";
105 static const char* const kAsanOdmLibDir       = "/data/asan/odm/lib64";
106 static const char* const kAsanVendorLibDir    = "/data/asan/vendor/lib64";
107 #else
108 static const char* const kSystemLibDir        = "/system/lib";
109 static const char* const kOdmLibDir           = "/odm/lib";
110 static const char* const kVendorLibDir        = "/vendor/lib";
111 static const char* const kAsanSystemLibDir    = "/data/asan/system/lib";
112 static const char* const kAsanOdmLibDir       = "/data/asan/odm/lib";
113 static const char* const kAsanVendorLibDir    = "/data/asan/vendor/lib";
114 #endif
115 
116 static const char* const kAsanLibDirPrefix = "/data/asan";
117 
118 static const char* const kDefaultLdPaths[] = {
119   kSystemLibDir,
120   kOdmLibDir,
121   kVendorLibDir,
122   nullptr
123 };
124 
125 static const char* const kAsanDefaultLdPaths[] = {
126   kAsanSystemLibDir,
127   kSystemLibDir,
128   kAsanOdmLibDir,
129   kOdmLibDir,
130   kAsanVendorLibDir,
131   kVendorLibDir,
132   nullptr
133 };
134 
135 // Is ASAN enabled?
136 static bool g_is_asan = false;
137 
138 static CFIShadowWriter g_cfi_shadow;
139 
get_cfi_shadow()140 CFIShadowWriter* get_cfi_shadow() {
141   return &g_cfi_shadow;
142 }
143 
is_system_library(const std::string & realpath)144 static bool is_system_library(const std::string& realpath) {
145   for (const auto& dir : g_default_namespace.get_default_library_paths()) {
146     if (file_is_in_dir(realpath, dir)) {
147       return true;
148     }
149   }
150   return false;
151 }
152 
153 // Checks if the file exists and not a directory.
file_exists(const char * path)154 static bool file_exists(const char* path) {
155   struct stat s;
156 
157   if (stat(path, &s) != 0) {
158     return false;
159   }
160 
161   return S_ISREG(s.st_mode);
162 }
163 
resolve_soname(const std::string & name)164 static std::string resolve_soname(const std::string& name) {
165   // We assume that soname equals to basename here
166 
167   // TODO(dimitry): consider having honest absolute-path -> soname resolution
168   // note that since we might end up refusing to load this library because
169   // it is not in shared libs list we need to get the soname without actually loading
170   // the library.
171   //
172   // On the other hand there are several places where we already assume that
173   // soname == basename in particular for any not-loaded library mentioned
174   // in DT_NEEDED list.
175   return basename(name.c_str());
176 }
177 
maybe_accessible_via_namespace_links(android_namespace_t * ns,const char * name)178 static bool maybe_accessible_via_namespace_links(android_namespace_t* ns, const char* name) {
179   std::string soname = resolve_soname(name);
180   for (auto& ns_link : ns->linked_namespaces()) {
181     if (ns_link.is_accessible(soname.c_str())) {
182       return true;
183     }
184   }
185 
186   return false;
187 }
188 
189 // TODO(dimitry): The grey-list is a workaround for http://b/26394120 ---
190 // gradually remove libraries from this list until it is gone.
is_greylisted(android_namespace_t * ns,const char * name,const soinfo * needed_by)191 static bool is_greylisted(android_namespace_t* ns, const char* name, const soinfo* needed_by) {
192   static const char* const kLibraryGreyList[] = {
193     "libandroid_runtime.so",
194     "libbinder.so",
195     "libcrypto.so",
196     "libcutils.so",
197     "libexpat.so",
198     "libgui.so",
199     "libmedia.so",
200     "libnativehelper.so",
201     "libssl.so",
202     "libstagefright.so",
203     "libsqlite.so",
204     "libui.so",
205     "libutils.so",
206     nullptr
207   };
208 
209   // If you're targeting N, you don't get the greylist.
210   if (get_application_target_sdk_version() >= 24) {
211     return false;
212   }
213 
214   // if the library needed by a system library - implicitly assume it
215   // is greylisted unless it is in the list of shared libraries for one or
216   // more linked namespaces
217   if (needed_by != nullptr && is_system_library(needed_by->get_realpath())) {
218     return !maybe_accessible_via_namespace_links(ns, name);
219   }
220 
221   // if this is an absolute path - make sure it points to /system/lib(64)
222   if (name[0] == '/' && dirname(name) == kSystemLibDir) {
223     // and reduce the path to basename
224     name = basename(name);
225   }
226 
227   for (size_t i = 0; kLibraryGreyList[i] != nullptr; ++i) {
228     if (strcmp(name, kLibraryGreyList[i]) == 0) {
229       return true;
230     }
231   }
232 
233   return false;
234 }
235 // END OF WORKAROUND
236 
237 static std::vector<std::string> g_ld_preload_names;
238 
notify_gdb_of_load(soinfo * info)239 static void notify_gdb_of_load(soinfo* info) {
240   if (info->is_linker() || info->is_main_executable()) {
241     // gdb already knows about the linker and the main executable.
242     return;
243   }
244 
245   link_map* map = &(info->link_map_head);
246 
247   map->l_addr = info->load_bias;
248   // link_map l_name field is not const.
249   map->l_name = const_cast<char*>(info->get_realpath());
250   map->l_ld = info->dynamic;
251 
252   CHECK(map->l_name != nullptr);
253   CHECK(map->l_name[0] != '\0');
254 
255   notify_gdb_of_load(map);
256 }
257 
notify_gdb_of_unload(soinfo * info)258 static void notify_gdb_of_unload(soinfo* info) {
259   notify_gdb_of_unload(&(info->link_map_head));
260 }
261 
alloc()262 LinkedListEntry<soinfo>* SoinfoListAllocator::alloc() {
263   return g_soinfo_links_allocator.alloc();
264 }
265 
free(LinkedListEntry<soinfo> * entry)266 void SoinfoListAllocator::free(LinkedListEntry<soinfo>* entry) {
267   g_soinfo_links_allocator.free(entry);
268 }
269 
alloc()270 LinkedListEntry<android_namespace_t>* NamespaceListAllocator::alloc() {
271   return g_namespace_list_allocator.alloc();
272 }
273 
free(LinkedListEntry<android_namespace_t> * entry)274 void NamespaceListAllocator::free(LinkedListEntry<android_namespace_t>* entry) {
275   g_namespace_list_allocator.free(entry);
276 }
277 
soinfo_alloc(android_namespace_t * ns,const char * name,const struct stat * file_stat,off64_t file_offset,uint32_t rtld_flags)278 soinfo* soinfo_alloc(android_namespace_t* ns, const char* name,
279                      const struct stat* file_stat, off64_t file_offset,
280                      uint32_t rtld_flags) {
281   if (strlen(name) >= PATH_MAX) {
282     async_safe_fatal("library name \"%s\" too long", name);
283   }
284 
285   TRACE("name %s: allocating soinfo for ns=%p", name, ns);
286 
287   soinfo* si = new (g_soinfo_allocator.alloc()) soinfo(ns, name, file_stat,
288                                                        file_offset, rtld_flags);
289 
290   solist_add_soinfo(si);
291 
292   si->generate_handle();
293   ns->add_soinfo(si);
294 
295   TRACE("name %s: allocated soinfo @ %p", name, si);
296   return si;
297 }
298 
soinfo_free(soinfo * si)299 static void soinfo_free(soinfo* si) {
300   if (si == nullptr) {
301     return;
302   }
303 
304   if (si->base != 0 && si->size != 0) {
305     if (!si->is_mapped_by_caller()) {
306       munmap(reinterpret_cast<void*>(si->base), si->size);
307     } else {
308       // remap the region as PROT_NONE, MAP_ANONYMOUS | MAP_NORESERVE
309       mmap(reinterpret_cast<void*>(si->base), si->size, PROT_NONE,
310            MAP_FIXED | MAP_PRIVATE | MAP_ANONYMOUS | MAP_NORESERVE, -1, 0);
311     }
312   }
313 
314   if (si->has_min_version(6) && si->get_gap_size()) {
315     munmap(reinterpret_cast<void*>(si->get_gap_start()), si->get_gap_size());
316   }
317 
318   TRACE("name %s: freeing soinfo @ %p", si->get_realpath(), si);
319 
320   if (!solist_remove_soinfo(si)) {
321     async_safe_fatal("soinfo=%p is not in soinfo_list (double unload?)", si);
322   }
323 
324   // clear links to/from si
325   si->remove_all_links();
326 
327   si->~soinfo();
328   g_soinfo_allocator.free(si);
329 }
330 
parse_path(const char * path,const char * delimiters,std::vector<std::string> * resolved_paths)331 static void parse_path(const char* path, const char* delimiters,
332                        std::vector<std::string>* resolved_paths) {
333   std::vector<std::string> paths;
334   split_path(path, delimiters, &paths);
335   resolve_paths(paths, resolved_paths);
336 }
337 
parse_LD_LIBRARY_PATH(const char * path)338 static void parse_LD_LIBRARY_PATH(const char* path) {
339   std::vector<std::string> ld_libary_paths;
340   parse_path(path, ":", &ld_libary_paths);
341   g_default_namespace.set_ld_library_paths(std::move(ld_libary_paths));
342 }
343 
realpath_fd(int fd,std::string * realpath)344 static bool realpath_fd(int fd, std::string* realpath) {
345   // proc_self_fd needs to be large enough to hold "/proc/self/fd/" plus an
346   // integer, plus the NULL terminator.
347   char proc_self_fd[32];
348   // We want to statically allocate this large buffer so that we don't grow
349   // the stack by too much.
350   static char buf[PATH_MAX];
351 
352   async_safe_format_buffer(proc_self_fd, sizeof(proc_self_fd), "/proc/self/fd/%d", fd);
353   auto length = readlink(proc_self_fd, buf, sizeof(buf));
354   if (length == -1) {
355     if (!is_first_stage_init()) {
356       PRINT("readlink(\"%s\") failed: %s [fd=%d]", proc_self_fd, strerror(errno), fd);
357     }
358     return false;
359   }
360 
361   realpath->assign(buf, length);
362   return true;
363 }
364 
365 // Returns the address of the current thread's copy of a TLS module. If the current thread doesn't
366 // have a copy yet, allocate one on-demand if should_alloc is true, and return nullptr otherwise.
get_tls_block_for_this_thread(const soinfo_tls * si_tls,bool should_alloc)367 static inline void* get_tls_block_for_this_thread(const soinfo_tls* si_tls, bool should_alloc) {
368   const TlsModule& tls_mod = get_tls_module(si_tls->module_id);
369   if (tls_mod.static_offset != SIZE_MAX) {
370     const StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout;
371     char* static_tls = reinterpret_cast<char*>(__get_bionic_tcb()) - layout.offset_bionic_tcb();
372     return static_tls + tls_mod.static_offset;
373   } else if (should_alloc) {
374     const TlsIndex ti { si_tls->module_id, 0 };
375     return TLS_GET_ADDR(&ti);
376   } else {
377     TlsDtv* dtv = __get_tcb_dtv(__get_bionic_tcb());
378     if (dtv->generation < tls_mod.first_generation) return nullptr;
379     return dtv->modules[__tls_module_id_to_idx(si_tls->module_id)];
380   }
381 }
382 
383 #if defined(__arm__)
384 
385 // For a given PC, find the .so that it belongs to.
386 // Returns the base address of the .ARM.exidx section
387 // for that .so, and the number of 8-byte entries
388 // in that section (via *pcount).
389 //
390 // Intended to be called by libc's __gnu_Unwind_Find_exidx().
do_dl_unwind_find_exidx(_Unwind_Ptr pc,int * pcount)391 _Unwind_Ptr do_dl_unwind_find_exidx(_Unwind_Ptr pc, int* pcount) {
392   if (soinfo* si = find_containing_library(reinterpret_cast<void*>(pc))) {
393     *pcount = si->ARM_exidx_count;
394     return reinterpret_cast<_Unwind_Ptr>(si->ARM_exidx);
395   }
396   *pcount = 0;
397   return 0;
398 }
399 
400 #endif
401 
402 // Here, we only have to provide a callback to iterate across all the
403 // loaded libraries. gcc_eh does the rest.
do_dl_iterate_phdr(int (* cb)(dl_phdr_info * info,size_t size,void * data),void * data)404 int do_dl_iterate_phdr(int (*cb)(dl_phdr_info* info, size_t size, void* data), void* data) {
405   int rv = 0;
406   for (soinfo* si = solist_get_head(); si != nullptr; si = si->next) {
407     dl_phdr_info dl_info;
408     dl_info.dlpi_addr = si->link_map_head.l_addr;
409     dl_info.dlpi_name = si->link_map_head.l_name;
410     dl_info.dlpi_phdr = si->phdr;
411     dl_info.dlpi_phnum = si->phnum;
412     dl_info.dlpi_adds = g_module_load_counter;
413     dl_info.dlpi_subs = g_module_unload_counter;
414     if (soinfo_tls* tls_module = si->get_tls()) {
415       dl_info.dlpi_tls_modid = tls_module->module_id;
416       dl_info.dlpi_tls_data = get_tls_block_for_this_thread(tls_module, /*should_alloc=*/false);
417     } else {
418       dl_info.dlpi_tls_modid = 0;
419       dl_info.dlpi_tls_data = nullptr;
420     }
421 
422     rv = cb(&dl_info, sizeof(dl_phdr_info), data);
423     if (rv != 0) {
424       break;
425     }
426   }
427   return rv;
428 }
429 
ProtectedDataGuard()430 ProtectedDataGuard::ProtectedDataGuard() {
431   if (ref_count_++ == 0) {
432     protect_data(PROT_READ | PROT_WRITE);
433   }
434 
435   if (ref_count_ == 0) { // overflow
436     async_safe_fatal("Too many nested calls to dlopen()");
437   }
438 }
439 
~ProtectedDataGuard()440 ProtectedDataGuard::~ProtectedDataGuard() {
441   if (--ref_count_ == 0) {
442     protect_data(PROT_READ);
443   }
444 }
445 
protect_data(int protection)446 void ProtectedDataGuard::protect_data(int protection) {
447   g_soinfo_allocator.protect_all(protection);
448   g_soinfo_links_allocator.protect_all(protection);
449   g_namespace_allocator.protect_all(protection);
450   g_namespace_list_allocator.protect_all(protection);
451 }
452 
453 size_t ProtectedDataGuard::ref_count_ = 0;
454 
455 // Each size has it's own allocator.
456 template<size_t size>
457 class SizeBasedAllocator {
458  public:
alloc()459   static void* alloc() {
460     return allocator_.alloc();
461   }
462 
free(void * ptr)463   static void free(void* ptr) {
464     allocator_.free(ptr);
465   }
466 
purge()467   static void purge() {
468     allocator_.purge();
469   }
470 
471  private:
472   static LinkerBlockAllocator allocator_;
473 };
474 
475 template<size_t size>
476 LinkerBlockAllocator SizeBasedAllocator<size>::allocator_(size);
477 
478 template<typename T>
479 class TypeBasedAllocator {
480  public:
alloc()481   static T* alloc() {
482     return reinterpret_cast<T*>(SizeBasedAllocator<sizeof(T)>::alloc());
483   }
484 
free(T * ptr)485   static void free(T* ptr) {
486     SizeBasedAllocator<sizeof(T)>::free(ptr);
487   }
488 
purge()489   static void purge() {
490     SizeBasedAllocator<sizeof(T)>::purge();
491   }
492 };
493 
494 class LoadTask {
495  public:
496   struct deleter_t {
operator ()LoadTask::deleter_t497     void operator()(LoadTask* t) {
498       t->~LoadTask();
499       TypeBasedAllocator<LoadTask>::free(t);
500     }
501   };
502 
503   static deleter_t deleter;
504 
505   // needed_by is NULL iff dlopen is called from memory that isn't part of any known soinfo.
create(const char * _Nonnull name,soinfo * _Nullable needed_by,android_namespace_t * _Nonnull start_from,std::unordered_map<const soinfo *,ElfReader> * _Nonnull readers_map)506   static LoadTask* create(const char* _Nonnull name, soinfo* _Nullable needed_by,
507                           android_namespace_t* _Nonnull start_from,
508                           std::unordered_map<const soinfo*, ElfReader>* _Nonnull readers_map) {
509     LoadTask* ptr = TypeBasedAllocator<LoadTask>::alloc();
510     return new (ptr) LoadTask(name, needed_by, start_from, readers_map);
511   }
512 
get_name() const513   const char* get_name() const {
514     return name_;
515   }
516 
get_needed_by() const517   soinfo* get_needed_by() const {
518     return needed_by_;
519   }
520 
get_soinfo() const521   soinfo* get_soinfo() const {
522     return si_;
523   }
524 
set_soinfo(soinfo * si)525   void set_soinfo(soinfo* si) {
526     si_ = si;
527   }
528 
get_file_offset() const529   off64_t get_file_offset() const {
530     return file_offset_;
531   }
532 
set_file_offset(off64_t offset)533   void set_file_offset(off64_t offset) {
534     file_offset_ = offset;
535   }
536 
get_fd() const537   int get_fd() const {
538     return fd_;
539   }
540 
set_fd(int fd,bool assume_ownership)541   void set_fd(int fd, bool assume_ownership) {
542     if (fd_ != -1 && close_fd_) {
543       close(fd_);
544     }
545     fd_ = fd;
546     close_fd_ = assume_ownership;
547   }
548 
get_extinfo() const549   const android_dlextinfo* get_extinfo() const {
550     return extinfo_;
551   }
552 
set_extinfo(const android_dlextinfo * extinfo)553   void set_extinfo(const android_dlextinfo* extinfo) {
554     extinfo_ = extinfo;
555   }
556 
is_dt_needed() const557   bool is_dt_needed() const {
558     return is_dt_needed_;
559   }
560 
set_dt_needed(bool is_dt_needed)561   void set_dt_needed(bool is_dt_needed) {
562     is_dt_needed_ = is_dt_needed;
563   }
564 
565   // returns the namespace from where we need to start loading this.
get_start_from() const566   const android_namespace_t* get_start_from() const {
567     return start_from_;
568   }
569 
remove_cached_elf_reader()570   void remove_cached_elf_reader() {
571     CHECK(si_ != nullptr);
572     (*elf_readers_map_).erase(si_);
573   }
574 
get_elf_reader() const575   const ElfReader& get_elf_reader() const {
576     CHECK(si_ != nullptr);
577     return (*elf_readers_map_)[si_];
578   }
579 
get_elf_reader()580   ElfReader& get_elf_reader() {
581     CHECK(si_ != nullptr);
582     return (*elf_readers_map_)[si_];
583   }
584 
get_readers_map()585   std::unordered_map<const soinfo*, ElfReader>* get_readers_map() {
586     return elf_readers_map_;
587   }
588 
read(const char * realpath,off64_t file_size)589   bool read(const char* realpath, off64_t file_size) {
590     ElfReader& elf_reader = get_elf_reader();
591     return elf_reader.Read(realpath, fd_, file_offset_, file_size);
592   }
593 
load(address_space_params * address_space)594   bool load(address_space_params* address_space) {
595     ElfReader& elf_reader = get_elf_reader();
596     if (!elf_reader.Load(address_space)) {
597       return false;
598     }
599 
600     si_->base = elf_reader.load_start();
601     si_->size = elf_reader.load_size();
602     si_->set_mapped_by_caller(elf_reader.is_mapped_by_caller());
603     si_->load_bias = elf_reader.load_bias();
604     si_->phnum = elf_reader.phdr_count();
605     si_->phdr = elf_reader.loaded_phdr();
606     si_->set_gap_start(elf_reader.gap_start());
607     si_->set_gap_size(elf_reader.gap_size());
608 
609     return true;
610   }
611 
612  private:
LoadTask(const char * name,soinfo * needed_by,android_namespace_t * start_from,std::unordered_map<const soinfo *,ElfReader> * readers_map)613   LoadTask(const char* name,
614            soinfo* needed_by,
615            android_namespace_t* start_from,
616            std::unordered_map<const soinfo*, ElfReader>* readers_map)
617     : name_(name), needed_by_(needed_by), si_(nullptr),
618       fd_(-1), close_fd_(false), file_offset_(0), elf_readers_map_(readers_map),
619       is_dt_needed_(false), start_from_(start_from) {}
620 
~LoadTask()621   ~LoadTask() {
622     if (fd_ != -1 && close_fd_) {
623       close(fd_);
624     }
625   }
626 
627   const char* name_;
628   soinfo* needed_by_;
629   soinfo* si_;
630   const android_dlextinfo* extinfo_;
631   int fd_;
632   bool close_fd_;
633   off64_t file_offset_;
634   std::unordered_map<const soinfo*, ElfReader>* elf_readers_map_;
635   // TODO(dimitry): needed by workaround for http://b/26394120 (the grey-list)
636   bool is_dt_needed_;
637   // END OF WORKAROUND
638   const android_namespace_t* const start_from_;
639 
640   DISALLOW_IMPLICIT_CONSTRUCTORS(LoadTask);
641 };
642 
643 LoadTask::deleter_t LoadTask::deleter;
644 
645 template <typename T>
646 using linked_list_t = LinkedList<T, TypeBasedAllocator<LinkedListEntry<T>>>;
647 
648 typedef linked_list_t<soinfo> SoinfoLinkedList;
649 typedef linked_list_t<const char> StringLinkedList;
650 typedef std::vector<LoadTask*> LoadTaskList;
651 
652 enum walk_action_result_t : uint32_t {
653   kWalkStop = 0,
654   kWalkContinue = 1,
655   kWalkSkip = 2
656 };
657 
658 // This function walks down the tree of soinfo dependencies
659 // in breadth-first order and
660 //   * calls action(soinfo* si) for each node, and
661 //   * terminates walk if action returns kWalkStop
662 //   * skips children of the node if action
663 //     return kWalkSkip
664 //
665 // walk_dependencies_tree returns false if walk was terminated
666 // by the action and true otherwise.
667 template<typename F>
walk_dependencies_tree(soinfo * root_soinfo,F action)668 static bool walk_dependencies_tree(soinfo* root_soinfo, F action) {
669   SoinfoLinkedList visit_list;
670   SoinfoLinkedList visited;
671 
672   visit_list.push_back(root_soinfo);
673 
674   soinfo* si;
675   while ((si = visit_list.pop_front()) != nullptr) {
676     if (visited.contains(si)) {
677       continue;
678     }
679 
680     walk_action_result_t result = action(si);
681 
682     if (result == kWalkStop) {
683       return false;
684     }
685 
686     visited.push_back(si);
687 
688     if (result != kWalkSkip) {
689       si->get_children().for_each([&](soinfo* child) {
690         visit_list.push_back(child);
691       });
692     }
693   }
694 
695   return true;
696 }
697 
698 
ElfW(Sym)699 static const ElfW(Sym)* dlsym_handle_lookup_impl(android_namespace_t* ns,
700                                                  soinfo* root,
701                                                  soinfo* skip_until,
702                                                  soinfo** found,
703                                                  SymbolName& symbol_name,
704                                                  const version_info* vi) {
705   const ElfW(Sym)* result = nullptr;
706   bool skip_lookup = skip_until != nullptr;
707 
708   walk_dependencies_tree(root, [&](soinfo* current_soinfo) {
709     if (skip_lookup) {
710       skip_lookup = current_soinfo != skip_until;
711       return kWalkContinue;
712     }
713 
714     if (!ns->is_accessible(current_soinfo)) {
715       return kWalkSkip;
716     }
717 
718     result = current_soinfo->find_symbol_by_name(symbol_name, vi);
719     if (result != nullptr) {
720       *found = current_soinfo;
721       return kWalkStop;
722     }
723 
724     return kWalkContinue;
725   });
726 
727   return result;
728 }
729 
730 /* This is used by dlsym(3) to performs a global symbol lookup. If the
731    start value is null (for RTLD_DEFAULT), the search starts at the
732    beginning of the global solist. Otherwise the search starts at the
733    specified soinfo (for RTLD_NEXT).
734  */
ElfW(Sym)735 static const ElfW(Sym)* dlsym_linear_lookup(android_namespace_t* ns,
736                                             const char* name,
737                                             const version_info* vi,
738                                             soinfo** found,
739                                             soinfo* caller,
740                                             void* handle) {
741   SymbolName symbol_name(name);
742 
743   auto& soinfo_list = ns->soinfo_list();
744   auto start = soinfo_list.begin();
745 
746   if (handle == RTLD_NEXT) {
747     if (caller == nullptr) {
748       return nullptr;
749     } else {
750       auto it = soinfo_list.find(caller);
751       CHECK (it != soinfo_list.end());
752       start = ++it;
753     }
754   }
755 
756   const ElfW(Sym)* s = nullptr;
757   for (auto it = start, end = soinfo_list.end(); it != end; ++it) {
758     soinfo* si = *it;
759     // Do not skip RTLD_LOCAL libraries in dlsym(RTLD_DEFAULT, ...)
760     // if the library is opened by application with target api level < M.
761     // See http://b/21565766
762     if ((si->get_rtld_flags() & RTLD_GLOBAL) == 0 && si->get_target_sdk_version() >= 23) {
763       continue;
764     }
765 
766     s = si->find_symbol_by_name(symbol_name, vi);
767     if (s != nullptr) {
768       *found = si;
769       break;
770     }
771   }
772 
773   // If not found - use dlsym_handle_lookup_impl for caller's local_group
774   if (s == nullptr && caller != nullptr) {
775     soinfo* local_group_root = caller->get_local_group_root();
776 
777     return dlsym_handle_lookup_impl(local_group_root->get_primary_namespace(),
778                                     local_group_root,
779                                     (handle == RTLD_NEXT) ? caller : nullptr,
780                                     found,
781                                     symbol_name,
782                                     vi);
783   }
784 
785   if (s != nullptr) {
786     TRACE_TYPE(LOOKUP, "%s s->st_value = %p, found->base = %p",
787                name, reinterpret_cast<void*>(s->st_value), reinterpret_cast<void*>((*found)->base));
788   }
789 
790   return s;
791 }
792 
793 // This is used by dlsym(3).  It performs symbol lookup only within the
794 // specified soinfo object and its dependencies in breadth first order.
ElfW(Sym)795 static const ElfW(Sym)* dlsym_handle_lookup(soinfo* si,
796                                             soinfo** found,
797                                             const char* name,
798                                             const version_info* vi) {
799   // According to man dlopen(3) and posix docs in the case when si is handle
800   // of the main executable we need to search not only in the executable and its
801   // dependencies but also in all libraries loaded with RTLD_GLOBAL.
802   //
803   // Since RTLD_GLOBAL is always set for the main executable and all dt_needed shared
804   // libraries and they are loaded in breath-first (correct) order we can just execute
805   // dlsym(RTLD_DEFAULT, ...); instead of doing two stage lookup.
806   if (si == solist_get_somain()) {
807     return dlsym_linear_lookup(&g_default_namespace, name, vi, found, nullptr, RTLD_DEFAULT);
808   }
809 
810   SymbolName symbol_name(name);
811   // note that the namespace is not the namespace associated with caller_addr
812   // we use ns associated with root si intentionally here. Using caller_ns
813   // causes problems when user uses dlopen_ext to open a library in the separate
814   // namespace and then calls dlsym() on the handle.
815   return dlsym_handle_lookup_impl(si->get_primary_namespace(), si, nullptr, found, symbol_name, vi);
816 }
817 
find_containing_library(const void * p)818 soinfo* find_containing_library(const void* p) {
819   // Addresses within a library may be tagged if they point to globals. Untag
820   // them so that the bounds check succeeds.
821   ElfW(Addr) address = reinterpret_cast<ElfW(Addr)>(untag_address(p));
822   for (soinfo* si = solist_get_head(); si != nullptr; si = si->next) {
823     if (address < si->base || address - si->base >= si->size) {
824       continue;
825     }
826     ElfW(Addr) vaddr = address - si->load_bias;
827     for (size_t i = 0; i != si->phnum; ++i) {
828       const ElfW(Phdr)* phdr = &si->phdr[i];
829       if (phdr->p_type != PT_LOAD) {
830         continue;
831       }
832       if (vaddr >= phdr->p_vaddr && vaddr < phdr->p_vaddr + phdr->p_memsz) {
833         return si;
834       }
835     }
836   }
837   return nullptr;
838 }
839 
840 class ZipArchiveCache {
841  public:
ZipArchiveCache()842   ZipArchiveCache() {}
843   ~ZipArchiveCache();
844 
845   bool get_or_open(const char* zip_path, ZipArchiveHandle* handle);
846  private:
847   DISALLOW_COPY_AND_ASSIGN(ZipArchiveCache);
848 
849   std::unordered_map<std::string, ZipArchiveHandle> cache_;
850 };
851 
get_or_open(const char * zip_path,ZipArchiveHandle * handle)852 bool ZipArchiveCache::get_or_open(const char* zip_path, ZipArchiveHandle* handle) {
853   std::string key(zip_path);
854 
855   auto it = cache_.find(key);
856   if (it != cache_.end()) {
857     *handle = it->second;
858     return true;
859   }
860 
861   int fd = TEMP_FAILURE_RETRY(open(zip_path, O_RDONLY | O_CLOEXEC));
862   if (fd == -1) {
863     return false;
864   }
865 
866   if (OpenArchiveFd(fd, "", handle) != 0) {
867     // invalid zip-file (?)
868     CloseArchive(*handle);
869     return false;
870   }
871 
872   cache_[key] = *handle;
873   return true;
874 }
875 
~ZipArchiveCache()876 ZipArchiveCache::~ZipArchiveCache() {
877   for (const auto& it : cache_) {
878     CloseArchive(it.second);
879   }
880 }
881 
open_library_in_zipfile(ZipArchiveCache * zip_archive_cache,const char * const input_path,off64_t * file_offset,std::string * realpath)882 static int open_library_in_zipfile(ZipArchiveCache* zip_archive_cache,
883                                    const char* const input_path,
884                                    off64_t* file_offset, std::string* realpath) {
885   std::string normalized_path;
886   if (!normalize_path(input_path, &normalized_path)) {
887     return -1;
888   }
889 
890   const char* const path = normalized_path.c_str();
891   TRACE("Trying zip file open from path \"%s\" -> normalized \"%s\"", input_path, path);
892 
893   // Treat an '!/' separator inside a path as the separator between the name
894   // of the zip file on disk and the subdirectory to search within it.
895   // For example, if path is "foo.zip!/bar/bas/x.so", then we search for
896   // "bar/bas/x.so" within "foo.zip".
897   const char* const separator = strstr(path, kZipFileSeparator);
898   if (separator == nullptr) {
899     return -1;
900   }
901 
902   char buf[512];
903   if (strlcpy(buf, path, sizeof(buf)) >= sizeof(buf)) {
904     PRINT("Warning: ignoring very long library path: %s", path);
905     return -1;
906   }
907 
908   buf[separator - path] = '\0';
909 
910   const char* zip_path = buf;
911   const char* file_path = &buf[separator - path + 2];
912   int fd = TEMP_FAILURE_RETRY(open(zip_path, O_RDONLY | O_CLOEXEC));
913   if (fd == -1) {
914     return -1;
915   }
916 
917   ZipArchiveHandle handle;
918   if (!zip_archive_cache->get_or_open(zip_path, &handle)) {
919     // invalid zip-file (?)
920     close(fd);
921     return -1;
922   }
923 
924   ZipEntry entry;
925 
926   if (FindEntry(handle, file_path, &entry) != 0) {
927     // Entry was not found.
928     close(fd);
929     return -1;
930   }
931 
932   // Check if it is properly stored
933   if (entry.method != kCompressStored || (entry.offset % PAGE_SIZE) != 0) {
934     close(fd);
935     return -1;
936   }
937 
938   *file_offset = entry.offset;
939 
940   if (realpath_fd(fd, realpath)) {
941     *realpath += separator;
942   } else {
943     if (!is_first_stage_init()) {
944       PRINT("warning: unable to get realpath for the library \"%s\". Will use given path.",
945             normalized_path.c_str());
946     }
947     *realpath = normalized_path;
948   }
949 
950   return fd;
951 }
952 
format_path(char * buf,size_t buf_size,const char * path,const char * name)953 static bool format_path(char* buf, size_t buf_size, const char* path, const char* name) {
954   int n = async_safe_format_buffer(buf, buf_size, "%s/%s", path, name);
955   if (n < 0 || n >= static_cast<int>(buf_size)) {
956     PRINT("Warning: ignoring very long library path: %s/%s", path, name);
957     return false;
958   }
959 
960   return true;
961 }
962 
open_library_at_path(ZipArchiveCache * zip_archive_cache,const char * path,off64_t * file_offset,std::string * realpath)963 static int open_library_at_path(ZipArchiveCache* zip_archive_cache,
964                                 const char* path, off64_t* file_offset,
965                                 std::string* realpath) {
966   int fd = -1;
967   if (strstr(path, kZipFileSeparator) != nullptr) {
968     fd = open_library_in_zipfile(zip_archive_cache, path, file_offset, realpath);
969   }
970 
971   if (fd == -1) {
972     fd = TEMP_FAILURE_RETRY(open(path, O_RDONLY | O_CLOEXEC));
973     if (fd != -1) {
974       *file_offset = 0;
975       if (!realpath_fd(fd, realpath)) {
976         if (!is_first_stage_init()) {
977           PRINT("warning: unable to get realpath for the library \"%s\". Will use given path.",
978                 path);
979         }
980         *realpath = path;
981       }
982     }
983   }
984 
985   return fd;
986 }
987 
open_library_on_paths(ZipArchiveCache * zip_archive_cache,const char * name,off64_t * file_offset,const std::vector<std::string> & paths,std::string * realpath)988 static int open_library_on_paths(ZipArchiveCache* zip_archive_cache,
989                                  const char* name, off64_t* file_offset,
990                                  const std::vector<std::string>& paths,
991                                  std::string* realpath) {
992   for (const auto& path : paths) {
993     char buf[512];
994     if (!format_path(buf, sizeof(buf), path.c_str(), name)) {
995       continue;
996     }
997 
998     int fd = open_library_at_path(zip_archive_cache, buf, file_offset, realpath);
999     if (fd != -1) {
1000       return fd;
1001     }
1002   }
1003 
1004   return -1;
1005 }
1006 
open_library(android_namespace_t * ns,ZipArchiveCache * zip_archive_cache,const char * name,soinfo * needed_by,off64_t * file_offset,std::string * realpath)1007 static int open_library(android_namespace_t* ns,
1008                         ZipArchiveCache* zip_archive_cache,
1009                         const char* name, soinfo *needed_by,
1010                         off64_t* file_offset, std::string* realpath) {
1011   TRACE("[ opening %s from namespace %s ]", name, ns->get_name());
1012 
1013   // If the name contains a slash, we should attempt to open it directly and not search the paths.
1014   if (strchr(name, '/') != nullptr) {
1015     return open_library_at_path(zip_archive_cache, name, file_offset, realpath);
1016   }
1017 
1018   // LD_LIBRARY_PATH has the highest priority. We don't have to check accessibility when searching
1019   // the namespace's path lists, because anything found on a namespace path list should always be
1020   // accessible.
1021   int fd = open_library_on_paths(zip_archive_cache, name, file_offset, ns->get_ld_library_paths(), realpath);
1022 
1023   // Try the DT_RUNPATH, and verify that the library is accessible.
1024   if (fd == -1 && needed_by != nullptr) {
1025     fd = open_library_on_paths(zip_archive_cache, name, file_offset, needed_by->get_dt_runpath(), realpath);
1026     if (fd != -1 && !ns->is_accessible(*realpath)) {
1027       close(fd);
1028       fd = -1;
1029     }
1030   }
1031 
1032   // Finally search the namespace's main search path list.
1033   if (fd == -1) {
1034     fd = open_library_on_paths(zip_archive_cache, name, file_offset, ns->get_default_library_paths(), realpath);
1035   }
1036 
1037   return fd;
1038 }
1039 
open_executable(const char * path,off64_t * file_offset,std::string * realpath)1040 int open_executable(const char* path, off64_t* file_offset, std::string* realpath) {
1041   ZipArchiveCache zip_archive_cache;
1042   return open_library_at_path(&zip_archive_cache, path, file_offset, realpath);
1043 }
1044 
fix_dt_needed(const char * dt_needed,const char * sopath __unused)1045 const char* fix_dt_needed(const char* dt_needed, const char* sopath __unused) {
1046 #if !defined(__LP64__)
1047   // Work around incorrect DT_NEEDED entries for old apps: http://b/21364029
1048   int app_target_api_level = get_application_target_sdk_version();
1049   if (app_target_api_level < 23) {
1050     const char* bname = basename(dt_needed);
1051     if (bname != dt_needed) {
1052       DL_WARN_documented_change(23,
1053                                 "invalid-dt_needed-entries-enforced-for-api-level-23",
1054                                 "library \"%s\" has invalid DT_NEEDED entry \"%s\"",
1055                                 sopath, dt_needed, app_target_api_level);
1056       add_dlwarning(sopath, "invalid DT_NEEDED entry",  dt_needed);
1057     }
1058 
1059     return bname;
1060   }
1061 #endif
1062   return dt_needed;
1063 }
1064 
1065 template<typename F>
for_each_dt_needed(const ElfReader & elf_reader,F action)1066 static void for_each_dt_needed(const ElfReader& elf_reader, F action) {
1067   for (const ElfW(Dyn)* d = elf_reader.dynamic(); d->d_tag != DT_NULL; ++d) {
1068     if (d->d_tag == DT_NEEDED) {
1069       action(fix_dt_needed(elf_reader.get_string(d->d_un.d_val), elf_reader.name()));
1070     }
1071   }
1072 }
1073 
find_loaded_library_by_inode(android_namespace_t * ns,const struct stat & file_stat,off64_t file_offset,bool search_linked_namespaces,soinfo ** candidate)1074 static bool find_loaded_library_by_inode(android_namespace_t* ns,
1075                                          const struct stat& file_stat,
1076                                          off64_t file_offset,
1077                                          bool search_linked_namespaces,
1078                                          soinfo** candidate) {
1079   if (file_stat.st_dev == 0 || file_stat.st_ino == 0) {
1080     *candidate = nullptr;
1081     return false;
1082   }
1083 
1084   auto predicate = [&](soinfo* si) {
1085     return si->get_st_ino() == file_stat.st_ino &&
1086            si->get_st_dev() == file_stat.st_dev &&
1087            si->get_file_offset() == file_offset;
1088   };
1089 
1090   *candidate = ns->soinfo_list().find_if(predicate);
1091 
1092   if (*candidate == nullptr && search_linked_namespaces) {
1093     for (auto& link : ns->linked_namespaces()) {
1094       android_namespace_t* linked_ns = link.linked_namespace();
1095       soinfo* si = linked_ns->soinfo_list().find_if(predicate);
1096 
1097       if (si != nullptr && link.is_accessible(si->get_soname())) {
1098         *candidate = si;
1099         return true;
1100       }
1101     }
1102   }
1103 
1104   return *candidate != nullptr;
1105 }
1106 
find_loaded_library_by_realpath(android_namespace_t * ns,const char * realpath,bool search_linked_namespaces,soinfo ** candidate)1107 static bool find_loaded_library_by_realpath(android_namespace_t* ns, const char* realpath,
1108                                             bool search_linked_namespaces, soinfo** candidate) {
1109   auto predicate = [&](soinfo* si) { return strcmp(realpath, si->get_realpath()) == 0; };
1110 
1111   *candidate = ns->soinfo_list().find_if(predicate);
1112 
1113   if (*candidate == nullptr && search_linked_namespaces) {
1114     for (auto& link : ns->linked_namespaces()) {
1115       android_namespace_t* linked_ns = link.linked_namespace();
1116       soinfo* si = linked_ns->soinfo_list().find_if(predicate);
1117 
1118       if (si != nullptr && link.is_accessible(si->get_soname())) {
1119         *candidate = si;
1120         return true;
1121       }
1122     }
1123   }
1124 
1125   return *candidate != nullptr;
1126 }
1127 
load_library(android_namespace_t * ns,LoadTask * task,LoadTaskList * load_tasks,int rtld_flags,const std::string & realpath,bool search_linked_namespaces)1128 static bool load_library(android_namespace_t* ns,
1129                          LoadTask* task,
1130                          LoadTaskList* load_tasks,
1131                          int rtld_flags,
1132                          const std::string& realpath,
1133                          bool search_linked_namespaces) {
1134   off64_t file_offset = task->get_file_offset();
1135   const char* name = task->get_name();
1136   const android_dlextinfo* extinfo = task->get_extinfo();
1137 
1138   LD_LOG(kLogDlopen,
1139          "load_library(ns=%s, task=%s, flags=0x%x, realpath=%s, search_linked_namespaces=%d)",
1140          ns->get_name(), name, rtld_flags, realpath.c_str(), search_linked_namespaces);
1141 
1142   if ((file_offset % PAGE_SIZE) != 0) {
1143     DL_OPEN_ERR("file offset for the library \"%s\" is not page-aligned: %" PRId64, name, file_offset);
1144     return false;
1145   }
1146   if (file_offset < 0) {
1147     DL_OPEN_ERR("file offset for the library \"%s\" is negative: %" PRId64, name, file_offset);
1148     return false;
1149   }
1150 
1151   struct stat file_stat;
1152   if (TEMP_FAILURE_RETRY(fstat(task->get_fd(), &file_stat)) != 0) {
1153     DL_OPEN_ERR("unable to stat file for the library \"%s\": %s", name, strerror(errno));
1154     return false;
1155   }
1156   if (file_offset >= file_stat.st_size) {
1157     DL_OPEN_ERR("file offset for the library \"%s\" >= file size: %" PRId64 " >= %" PRId64,
1158         name, file_offset, file_stat.st_size);
1159     return false;
1160   }
1161 
1162   // Check for symlink and other situations where
1163   // file can have different names, unless ANDROID_DLEXT_FORCE_LOAD is set
1164   if (extinfo == nullptr || (extinfo->flags & ANDROID_DLEXT_FORCE_LOAD) == 0) {
1165     soinfo* si = nullptr;
1166     if (find_loaded_library_by_inode(ns, file_stat, file_offset, search_linked_namespaces, &si)) {
1167       LD_LOG(kLogDlopen,
1168              "load_library(ns=%s, task=%s): Already loaded under different name/path \"%s\" - "
1169              "will return existing soinfo",
1170              ns->get_name(), name, si->get_realpath());
1171       task->set_soinfo(si);
1172       return true;
1173     }
1174   }
1175 
1176   if ((rtld_flags & RTLD_NOLOAD) != 0) {
1177     DL_OPEN_ERR("library \"%s\" wasn't loaded and RTLD_NOLOAD prevented it", name);
1178     return false;
1179   }
1180 
1181   struct statfs fs_stat;
1182   if (TEMP_FAILURE_RETRY(fstatfs(task->get_fd(), &fs_stat)) != 0) {
1183     DL_OPEN_ERR("unable to fstatfs file for the library \"%s\": %s", name, strerror(errno));
1184     return false;
1185   }
1186 
1187   // do not check accessibility using realpath if fd is located on tmpfs
1188   // this enables use of memfd_create() for apps
1189   if ((fs_stat.f_type != TMPFS_MAGIC) && (!ns->is_accessible(realpath))) {
1190     // TODO(dimitry): workaround for http://b/26394120 - the grey-list
1191 
1192     // TODO(dimitry) before O release: add a namespace attribute to have this enabled
1193     // only for classloader-namespaces
1194     const soinfo* needed_by = task->is_dt_needed() ? task->get_needed_by() : nullptr;
1195     if (is_greylisted(ns, name, needed_by)) {
1196       // print warning only if needed by non-system library
1197       if (needed_by == nullptr || !is_system_library(needed_by->get_realpath())) {
1198         const soinfo* needed_or_dlopened_by = task->get_needed_by();
1199         const char* sopath = needed_or_dlopened_by == nullptr ? "(unknown)" :
1200                                                       needed_or_dlopened_by->get_realpath();
1201         DL_WARN_documented_change(24,
1202                                   "private-api-enforced-for-api-level-24",
1203                                   "library \"%s\" (\"%s\") needed or dlopened by \"%s\" "
1204                                   "is not accessible by namespace \"%s\"",
1205                                   name, realpath.c_str(), sopath, ns->get_name());
1206         add_dlwarning(sopath, "unauthorized access to",  name);
1207       }
1208     } else {
1209       // do not load libraries if they are not accessible for the specified namespace.
1210       const char* needed_or_dlopened_by = task->get_needed_by() == nullptr ?
1211                                           "(unknown)" :
1212                                           task->get_needed_by()->get_realpath();
1213 
1214       DL_OPEN_ERR("library \"%s\" needed or dlopened by \"%s\" is not accessible for the namespace \"%s\"",
1215              name, needed_or_dlopened_by, ns->get_name());
1216 
1217       // do not print this if a library is in the list of shared libraries for linked namespaces
1218       if (!maybe_accessible_via_namespace_links(ns, name)) {
1219         PRINT("library \"%s\" (\"%s\") needed or dlopened by \"%s\" is not accessible for the"
1220               " namespace: [name=\"%s\", ld_library_paths=\"%s\", default_library_paths=\"%s\","
1221               " permitted_paths=\"%s\"]",
1222               name, realpath.c_str(),
1223               needed_or_dlopened_by,
1224               ns->get_name(),
1225               android::base::Join(ns->get_ld_library_paths(), ':').c_str(),
1226               android::base::Join(ns->get_default_library_paths(), ':').c_str(),
1227               android::base::Join(ns->get_permitted_paths(), ':').c_str());
1228       }
1229       return false;
1230     }
1231   }
1232 
1233   soinfo* si = soinfo_alloc(ns, realpath.c_str(), &file_stat, file_offset, rtld_flags);
1234 
1235   task->set_soinfo(si);
1236 
1237   // Read the ELF header and some of the segments.
1238   if (!task->read(realpath.c_str(), file_stat.st_size)) {
1239     task->remove_cached_elf_reader();
1240     task->set_soinfo(nullptr);
1241     soinfo_free(si);
1242     return false;
1243   }
1244 
1245   // find and set DT_RUNPATH and dt_soname
1246   // Note that these field values are temporary and are
1247   // going to be overwritten on soinfo::prelink_image
1248   // with values from PT_LOAD segments.
1249   const ElfReader& elf_reader = task->get_elf_reader();
1250   for (const ElfW(Dyn)* d = elf_reader.dynamic(); d->d_tag != DT_NULL; ++d) {
1251     if (d->d_tag == DT_RUNPATH) {
1252       si->set_dt_runpath(elf_reader.get_string(d->d_un.d_val));
1253     }
1254     if (d->d_tag == DT_SONAME) {
1255       si->set_soname(elf_reader.get_string(d->d_un.d_val));
1256     }
1257   }
1258 
1259 #if !defined(__ANDROID__)
1260   // Bionic on the host currently uses some Android prebuilts, which don't set
1261   // DT_RUNPATH with any relative paths, so they can't find their dependencies.
1262   // b/118058804
1263   if (si->get_dt_runpath().empty()) {
1264     si->set_dt_runpath("$ORIGIN/../lib64:$ORIGIN/lib64");
1265   }
1266 #endif
1267 
1268   for_each_dt_needed(task->get_elf_reader(), [&](const char* name) {
1269     LD_LOG(kLogDlopen, "load_library(ns=%s, task=%s): Adding DT_NEEDED task: %s",
1270            ns->get_name(), task->get_name(), name);
1271     load_tasks->push_back(LoadTask::create(name, si, ns, task->get_readers_map()));
1272   });
1273 
1274   return true;
1275 }
1276 
load_library(android_namespace_t * ns,LoadTask * task,ZipArchiveCache * zip_archive_cache,LoadTaskList * load_tasks,int rtld_flags,bool search_linked_namespaces)1277 static bool load_library(android_namespace_t* ns,
1278                          LoadTask* task,
1279                          ZipArchiveCache* zip_archive_cache,
1280                          LoadTaskList* load_tasks,
1281                          int rtld_flags,
1282                          bool search_linked_namespaces) {
1283   const char* name = task->get_name();
1284   soinfo* needed_by = task->get_needed_by();
1285   const android_dlextinfo* extinfo = task->get_extinfo();
1286 
1287   if (extinfo != nullptr && (extinfo->flags & ANDROID_DLEXT_USE_LIBRARY_FD) != 0) {
1288     off64_t file_offset = 0;
1289     if ((extinfo->flags & ANDROID_DLEXT_USE_LIBRARY_FD_OFFSET) != 0) {
1290       file_offset = extinfo->library_fd_offset;
1291     }
1292 
1293     std::string realpath;
1294     if (!realpath_fd(extinfo->library_fd, &realpath)) {
1295       if (!is_first_stage_init()) {
1296         PRINT(
1297             "warning: unable to get realpath for the library \"%s\" by extinfo->library_fd. "
1298             "Will use given name.",
1299             name);
1300       }
1301       realpath = name;
1302     }
1303 
1304     task->set_fd(extinfo->library_fd, false);
1305     task->set_file_offset(file_offset);
1306     return load_library(ns, task, load_tasks, rtld_flags, realpath, search_linked_namespaces);
1307   }
1308 
1309   LD_LOG(kLogDlopen,
1310          "load_library(ns=%s, task=%s, flags=0x%x, search_linked_namespaces=%d): calling "
1311          "open_library",
1312          ns->get_name(), name, rtld_flags, search_linked_namespaces);
1313 
1314   // Open the file.
1315   off64_t file_offset;
1316   std::string realpath;
1317   int fd = open_library(ns, zip_archive_cache, name, needed_by, &file_offset, &realpath);
1318   if (fd == -1) {
1319     if (task->is_dt_needed()) {
1320       if (needed_by->is_main_executable()) {
1321         DL_OPEN_ERR("library \"%s\" not found: needed by main executable", name);
1322       } else {
1323         DL_OPEN_ERR("library \"%s\" not found: needed by %s in namespace %s", name,
1324                     needed_by->get_realpath(), task->get_start_from()->get_name());
1325       }
1326     } else {
1327       DL_OPEN_ERR("library \"%s\" not found", name);
1328     }
1329     return false;
1330   }
1331 
1332   task->set_fd(fd, true);
1333   task->set_file_offset(file_offset);
1334 
1335   return load_library(ns, task, load_tasks, rtld_flags, realpath, search_linked_namespaces);
1336 }
1337 
find_loaded_library_by_soname(android_namespace_t * ns,const char * name,soinfo ** candidate)1338 static bool find_loaded_library_by_soname(android_namespace_t* ns,
1339                                           const char* name,
1340                                           soinfo** candidate) {
1341   return !ns->soinfo_list().visit([&](soinfo* si) {
1342     const char* soname = si->get_soname();
1343     if (soname != nullptr && (strcmp(name, soname) == 0)) {
1344       *candidate = si;
1345       return false;
1346     }
1347 
1348     return true;
1349   });
1350 }
1351 
1352 // Returns true if library was found and false otherwise
find_loaded_library_by_soname(android_namespace_t * ns,const char * name,bool search_linked_namespaces,soinfo ** candidate)1353 static bool find_loaded_library_by_soname(android_namespace_t* ns,
1354                                          const char* name,
1355                                          bool search_linked_namespaces,
1356                                          soinfo** candidate) {
1357   *candidate = nullptr;
1358 
1359   // Ignore filename with path.
1360   if (strchr(name, '/') != nullptr) {
1361     return false;
1362   }
1363 
1364   bool found = find_loaded_library_by_soname(ns, name, candidate);
1365 
1366   if (!found && search_linked_namespaces) {
1367     // if a library was not found - look into linked namespaces
1368     for (auto& link : ns->linked_namespaces()) {
1369       if (!link.is_accessible(name)) {
1370         continue;
1371       }
1372 
1373       android_namespace_t* linked_ns = link.linked_namespace();
1374 
1375       if (find_loaded_library_by_soname(linked_ns, name, candidate)) {
1376         return true;
1377       }
1378     }
1379   }
1380 
1381   return found;
1382 }
1383 
find_library_in_linked_namespace(const android_namespace_link_t & namespace_link,LoadTask * task)1384 static bool find_library_in_linked_namespace(const android_namespace_link_t& namespace_link,
1385                                              LoadTask* task) {
1386   android_namespace_t* ns = namespace_link.linked_namespace();
1387 
1388   soinfo* candidate;
1389   bool loaded = false;
1390 
1391   std::string soname;
1392   if (find_loaded_library_by_soname(ns, task->get_name(), false, &candidate)) {
1393     loaded = true;
1394     soname = candidate->get_soname();
1395   } else {
1396     soname = resolve_soname(task->get_name());
1397   }
1398 
1399   if (!namespace_link.is_accessible(soname.c_str())) {
1400     // the library is not accessible via namespace_link
1401     LD_LOG(kLogDlopen,
1402            "find_library_in_linked_namespace(ns=%s, task=%s): Not accessible (soname=%s)",
1403            ns->get_name(), task->get_name(), soname.c_str());
1404     return false;
1405   }
1406 
1407   // if library is already loaded - return it
1408   if (loaded) {
1409     LD_LOG(kLogDlopen, "find_library_in_linked_namespace(ns=%s, task=%s): Already loaded",
1410            ns->get_name(), task->get_name());
1411     task->set_soinfo(candidate);
1412     return true;
1413   }
1414 
1415   // returning true with empty soinfo means that the library is okay to be
1416   // loaded in the namespace but has not yet been loaded there before.
1417   LD_LOG(kLogDlopen, "find_library_in_linked_namespace(ns=%s, task=%s): Ok to load", ns->get_name(),
1418          task->get_name());
1419   task->set_soinfo(nullptr);
1420   return true;
1421 }
1422 
find_library_internal(android_namespace_t * ns,LoadTask * task,ZipArchiveCache * zip_archive_cache,LoadTaskList * load_tasks,int rtld_flags)1423 static bool find_library_internal(android_namespace_t* ns,
1424                                   LoadTask* task,
1425                                   ZipArchiveCache* zip_archive_cache,
1426                                   LoadTaskList* load_tasks,
1427                                   int rtld_flags) {
1428   soinfo* candidate;
1429 
1430   if (find_loaded_library_by_soname(ns, task->get_name(), true /* search_linked_namespaces */,
1431                                     &candidate)) {
1432     LD_LOG(kLogDlopen,
1433            "find_library_internal(ns=%s, task=%s): Already loaded (by soname): %s",
1434            ns->get_name(), task->get_name(), candidate->get_realpath());
1435     task->set_soinfo(candidate);
1436     return true;
1437   }
1438 
1439   // Library might still be loaded, the accurate detection
1440   // of this fact is done by load_library.
1441   TRACE("[ \"%s\" find_loaded_library_by_soname failed (*candidate=%s@%p). Trying harder... ]",
1442         task->get_name(), candidate == nullptr ? "n/a" : candidate->get_realpath(), candidate);
1443 
1444   if (load_library(ns, task, zip_archive_cache, load_tasks, rtld_flags,
1445                    true /* search_linked_namespaces */)) {
1446     return true;
1447   }
1448 
1449   // TODO(dimitry): workaround for http://b/26394120 (the grey-list)
1450   if (ns->is_greylist_enabled() && is_greylisted(ns, task->get_name(), task->get_needed_by())) {
1451     // For the libs in the greylist, switch to the default namespace and then
1452     // try the load again from there. The library could be loaded from the
1453     // default namespace or from another namespace (e.g. runtime) that is linked
1454     // from the default namespace.
1455     LD_LOG(kLogDlopen,
1456            "find_library_internal(ns=%s, task=%s): Greylisted library - trying namespace %s",
1457            ns->get_name(), task->get_name(), g_default_namespace.get_name());
1458     ns = &g_default_namespace;
1459     if (load_library(ns, task, zip_archive_cache, load_tasks, rtld_flags,
1460                      true /* search_linked_namespaces */)) {
1461       return true;
1462     }
1463   }
1464   // END OF WORKAROUND
1465 
1466   // if a library was not found - look into linked namespaces
1467   // preserve current dlerror in the case it fails.
1468   DlErrorRestorer dlerror_restorer;
1469   LD_LOG(kLogDlopen, "find_library_internal(ns=%s, task=%s): Trying %zu linked namespaces",
1470          ns->get_name(), task->get_name(), ns->linked_namespaces().size());
1471   for (auto& linked_namespace : ns->linked_namespaces()) {
1472     if (find_library_in_linked_namespace(linked_namespace, task)) {
1473       // Library is already loaded.
1474       if (task->get_soinfo() != nullptr) {
1475         // n.b. This code path runs when find_library_in_linked_namespace found an already-loaded
1476         // library by soname. That should only be possible with a greylist lookup, where we switch
1477         // the namespace, because otherwise, find_library_in_linked_namespace is duplicating the
1478         // soname scan done in this function's first call to find_loaded_library_by_soname.
1479         return true;
1480       }
1481 
1482       if (load_library(linked_namespace.linked_namespace(), task, zip_archive_cache, load_tasks,
1483                        rtld_flags, false /* search_linked_namespaces */)) {
1484         LD_LOG(kLogDlopen, "find_library_internal(ns=%s, task=%s): Found in linked namespace %s",
1485                ns->get_name(), task->get_name(), linked_namespace.linked_namespace()->get_name());
1486         return true;
1487       }
1488     }
1489   }
1490 
1491   return false;
1492 }
1493 
1494 static void soinfo_unload(soinfo* si);
1495 
shuffle(std::vector<LoadTask * > * v)1496 static void shuffle(std::vector<LoadTask*>* v) {
1497   if (is_first_stage_init()) {
1498     // arc4random* is not available in first stage init because /dev/random
1499     // hasn't yet been created.
1500     return;
1501   }
1502   for (size_t i = 0, size = v->size(); i < size; ++i) {
1503     size_t n = size - i;
1504     size_t r = arc4random_uniform(n);
1505     std::swap((*v)[n-1], (*v)[r]);
1506   }
1507 }
1508 
1509 // add_as_children - add first-level loaded libraries (i.e. library_names[], but
1510 // not their transitive dependencies) as children of the start_with library.
1511 // This is false when find_libraries is called for dlopen(), when newly loaded
1512 // libraries must form a disjoint tree.
find_libraries(android_namespace_t * ns,soinfo * start_with,const char * const library_names[],size_t library_names_count,soinfo * soinfos[],std::vector<soinfo * > * ld_preloads,size_t ld_preloads_count,int rtld_flags,const android_dlextinfo * extinfo,bool add_as_children,std::vector<android_namespace_t * > * namespaces)1513 bool find_libraries(android_namespace_t* ns,
1514                     soinfo* start_with,
1515                     const char* const library_names[],
1516                     size_t library_names_count,
1517                     soinfo* soinfos[],
1518                     std::vector<soinfo*>* ld_preloads,
1519                     size_t ld_preloads_count,
1520                     int rtld_flags,
1521                     const android_dlextinfo* extinfo,
1522                     bool add_as_children,
1523                     std::vector<android_namespace_t*>* namespaces) {
1524   // Step 0: prepare.
1525   std::unordered_map<const soinfo*, ElfReader> readers_map;
1526   LoadTaskList load_tasks;
1527 
1528   for (size_t i = 0; i < library_names_count; ++i) {
1529     const char* name = library_names[i];
1530     load_tasks.push_back(LoadTask::create(name, start_with, ns, &readers_map));
1531   }
1532 
1533   // If soinfos array is null allocate one on stack.
1534   // The array is needed in case of failure; for example
1535   // when library_names[] = {libone.so, libtwo.so} and libone.so
1536   // is loaded correctly but libtwo.so failed for some reason.
1537   // In this case libone.so should be unloaded on return.
1538   // See also implementation of failure_guard below.
1539 
1540   if (soinfos == nullptr) {
1541     size_t soinfos_size = sizeof(soinfo*)*library_names_count;
1542     soinfos = reinterpret_cast<soinfo**>(alloca(soinfos_size));
1543     memset(soinfos, 0, soinfos_size);
1544   }
1545 
1546   // list of libraries to link - see step 2.
1547   size_t soinfos_count = 0;
1548 
1549   auto scope_guard = android::base::make_scope_guard([&]() {
1550     for (LoadTask* t : load_tasks) {
1551       LoadTask::deleter(t);
1552     }
1553   });
1554 
1555   ZipArchiveCache zip_archive_cache;
1556 
1557   // Step 1: expand the list of load_tasks to include
1558   // all DT_NEEDED libraries (do not load them just yet)
1559   for (size_t i = 0; i<load_tasks.size(); ++i) {
1560     LoadTask* task = load_tasks[i];
1561     soinfo* needed_by = task->get_needed_by();
1562 
1563     bool is_dt_needed = needed_by != nullptr && (needed_by != start_with || add_as_children);
1564     task->set_extinfo(is_dt_needed ? nullptr : extinfo);
1565     task->set_dt_needed(is_dt_needed);
1566 
1567     LD_LOG(kLogDlopen, "find_libraries(ns=%s): task=%s, is_dt_needed=%d", ns->get_name(),
1568            task->get_name(), is_dt_needed);
1569 
1570     // Note: start from the namespace that is stored in the LoadTask. This namespace
1571     // is different from the current namespace when the LoadTask is for a transitive
1572     // dependency and the lib that created the LoadTask is not found in the
1573     // current namespace but in one of the linked namespace.
1574     if (!find_library_internal(const_cast<android_namespace_t*>(task->get_start_from()),
1575                                task,
1576                                &zip_archive_cache,
1577                                &load_tasks,
1578                                rtld_flags)) {
1579       return false;
1580     }
1581 
1582     soinfo* si = task->get_soinfo();
1583 
1584     if (is_dt_needed) {
1585       needed_by->add_child(si);
1586     }
1587 
1588     // When ld_preloads is not null, the first
1589     // ld_preloads_count libs are in fact ld_preloads.
1590     if (ld_preloads != nullptr && soinfos_count < ld_preloads_count) {
1591       ld_preloads->push_back(si);
1592     }
1593 
1594     if (soinfos_count < library_names_count) {
1595       soinfos[soinfos_count++] = si;
1596     }
1597   }
1598 
1599   // Step 2: Load libraries in random order (see b/24047022)
1600   LoadTaskList load_list;
1601   for (auto&& task : load_tasks) {
1602     soinfo* si = task->get_soinfo();
1603     auto pred = [&](const LoadTask* t) {
1604       return t->get_soinfo() == si;
1605     };
1606 
1607     if (!si->is_linked() &&
1608         std::find_if(load_list.begin(), load_list.end(), pred) == load_list.end() ) {
1609       load_list.push_back(task);
1610     }
1611   }
1612   bool reserved_address_recursive = false;
1613   if (extinfo) {
1614     reserved_address_recursive = extinfo->flags & ANDROID_DLEXT_RESERVED_ADDRESS_RECURSIVE;
1615   }
1616   if (!reserved_address_recursive) {
1617     // Shuffle the load order in the normal case, but not if we are loading all
1618     // the libraries to a reserved address range.
1619     shuffle(&load_list);
1620   }
1621 
1622   // Set up address space parameters.
1623   address_space_params extinfo_params, default_params;
1624   size_t relro_fd_offset = 0;
1625   if (extinfo) {
1626     if (extinfo->flags & ANDROID_DLEXT_RESERVED_ADDRESS) {
1627       extinfo_params.start_addr = extinfo->reserved_addr;
1628       extinfo_params.reserved_size = extinfo->reserved_size;
1629       extinfo_params.must_use_address = true;
1630     } else if (extinfo->flags & ANDROID_DLEXT_RESERVED_ADDRESS_HINT) {
1631       extinfo_params.start_addr = extinfo->reserved_addr;
1632       extinfo_params.reserved_size = extinfo->reserved_size;
1633     }
1634   }
1635 
1636   for (auto&& task : load_list) {
1637     address_space_params* address_space =
1638         (reserved_address_recursive || !task->is_dt_needed()) ? &extinfo_params : &default_params;
1639     if (!task->load(address_space)) {
1640       return false;
1641     }
1642   }
1643 
1644   // Step 3: pre-link all DT_NEEDED libraries in breadth first order.
1645   for (auto&& task : load_tasks) {
1646     soinfo* si = task->get_soinfo();
1647     if (!si->is_linked() && !si->prelink_image()) {
1648       return false;
1649     }
1650     register_soinfo_tls(si);
1651   }
1652 
1653   // Step 4: Construct the global group. Note: DF_1_GLOBAL bit of a library is
1654   // determined at step 3.
1655 
1656   // Step 4-1: DF_1_GLOBAL bit is force set for LD_PRELOADed libs because they
1657   // must be added to the global group
1658   if (ld_preloads != nullptr) {
1659     for (auto&& si : *ld_preloads) {
1660       si->set_dt_flags_1(si->get_dt_flags_1() | DF_1_GLOBAL);
1661     }
1662   }
1663 
1664   // Step 4-2: Gather all DF_1_GLOBAL libs which were newly loaded during this
1665   // run. These will be the new member of the global group
1666   soinfo_list_t new_global_group_members;
1667   for (auto&& task : load_tasks) {
1668     soinfo* si = task->get_soinfo();
1669     if (!si->is_linked() && (si->get_dt_flags_1() & DF_1_GLOBAL) != 0) {
1670       new_global_group_members.push_back(si);
1671     }
1672   }
1673 
1674   // Step 4-3: Add the new global group members to all the linked namespaces
1675   if (namespaces != nullptr) {
1676     for (auto linked_ns : *namespaces) {
1677       for (auto si : new_global_group_members) {
1678         if (si->get_primary_namespace() != linked_ns) {
1679           linked_ns->add_soinfo(si);
1680           si->add_secondary_namespace(linked_ns);
1681         }
1682       }
1683     }
1684   }
1685 
1686   // Step 5: Collect roots of local_groups.
1687   // Whenever needed_by->si link crosses a namespace boundary it forms its own local_group.
1688   // Here we collect new roots to link them separately later on. Note that we need to avoid
1689   // collecting duplicates. Also the order is important. They need to be linked in the same
1690   // BFS order we link individual libraries.
1691   std::vector<soinfo*> local_group_roots;
1692   if (start_with != nullptr && add_as_children) {
1693     local_group_roots.push_back(start_with);
1694   } else {
1695     CHECK(soinfos_count == 1);
1696     local_group_roots.push_back(soinfos[0]);
1697   }
1698 
1699   for (auto&& task : load_tasks) {
1700     soinfo* si = task->get_soinfo();
1701     soinfo* needed_by = task->get_needed_by();
1702     bool is_dt_needed = needed_by != nullptr && (needed_by != start_with || add_as_children);
1703     android_namespace_t* needed_by_ns =
1704         is_dt_needed ? needed_by->get_primary_namespace() : ns;
1705 
1706     if (!si->is_linked() && si->get_primary_namespace() != needed_by_ns) {
1707       auto it = std::find(local_group_roots.begin(), local_group_roots.end(), si);
1708       LD_LOG(kLogDlopen,
1709              "Crossing namespace boundary (si=%s@%p, si_ns=%s@%p, needed_by=%s@%p, ns=%s@%p, needed_by_ns=%s@%p) adding to local_group_roots: %s",
1710              si->get_realpath(),
1711              si,
1712              si->get_primary_namespace()->get_name(),
1713              si->get_primary_namespace(),
1714              needed_by == nullptr ? "(nullptr)" : needed_by->get_realpath(),
1715              needed_by,
1716              ns->get_name(),
1717              ns,
1718              needed_by_ns->get_name(),
1719              needed_by_ns,
1720              it == local_group_roots.end() ? "yes" : "no");
1721 
1722       if (it == local_group_roots.end()) {
1723         local_group_roots.push_back(si);
1724       }
1725     }
1726   }
1727 
1728   // Step 6: Link all local groups
1729   for (auto root : local_group_roots) {
1730     soinfo_list_t local_group;
1731     android_namespace_t* local_group_ns = root->get_primary_namespace();
1732 
1733     walk_dependencies_tree(root,
1734       [&] (soinfo* si) {
1735         if (local_group_ns->is_accessible(si)) {
1736           local_group.push_back(si);
1737           return kWalkContinue;
1738         } else {
1739           return kWalkSkip;
1740         }
1741       });
1742 
1743     soinfo_list_t global_group = local_group_ns->get_global_group();
1744     SymbolLookupList lookup_list(global_group, local_group);
1745     soinfo* local_group_root = local_group.front();
1746 
1747     bool linked = local_group.visit([&](soinfo* si) {
1748       // Even though local group may contain accessible soinfos from other namespaces
1749       // we should avoid linking them (because if they are not linked -> they
1750       // are in the local_group_roots and will be linked later).
1751       if (!si->is_linked() && si->get_primary_namespace() == local_group_ns) {
1752         const android_dlextinfo* link_extinfo = nullptr;
1753         if (si == soinfos[0] || reserved_address_recursive) {
1754           // Only forward extinfo for the first library unless the recursive
1755           // flag is set.
1756           link_extinfo = extinfo;
1757         }
1758         if (__libc_shared_globals()->load_hook) {
1759           __libc_shared_globals()->load_hook(si->load_bias, si->phdr, si->phnum);
1760         }
1761         lookup_list.set_dt_symbolic_lib(si->has_DT_SYMBOLIC ? si : nullptr);
1762         if (!si->link_image(lookup_list, local_group_root, link_extinfo, &relro_fd_offset) ||
1763             !get_cfi_shadow()->AfterLoad(si, solist_get_head())) {
1764           return false;
1765         }
1766       }
1767 
1768       return true;
1769     });
1770 
1771     if (!linked) {
1772       return false;
1773     }
1774   }
1775 
1776   // Step 7: Mark all load_tasks as linked and increment refcounts
1777   // for references between load_groups (at this point it does not matter if
1778   // referenced load_groups were loaded by previous dlopen or as part of this
1779   // one on step 6)
1780   if (start_with != nullptr && add_as_children) {
1781     start_with->set_linked();
1782   }
1783 
1784   for (auto&& task : load_tasks) {
1785     soinfo* si = task->get_soinfo();
1786     si->set_linked();
1787   }
1788 
1789   for (auto&& task : load_tasks) {
1790     soinfo* si = task->get_soinfo();
1791     soinfo* needed_by = task->get_needed_by();
1792     if (needed_by != nullptr &&
1793         needed_by != start_with &&
1794         needed_by->get_local_group_root() != si->get_local_group_root()) {
1795       si->increment_ref_count();
1796     }
1797   }
1798 
1799 
1800   return true;
1801 }
1802 
find_library(android_namespace_t * ns,const char * name,int rtld_flags,const android_dlextinfo * extinfo,soinfo * needed_by)1803 static soinfo* find_library(android_namespace_t* ns,
1804                             const char* name, int rtld_flags,
1805                             const android_dlextinfo* extinfo,
1806                             soinfo* needed_by) {
1807   soinfo* si = nullptr;
1808 
1809   if (name == nullptr) {
1810     si = solist_get_somain();
1811   } else if (!find_libraries(ns,
1812                              needed_by,
1813                              &name,
1814                              1,
1815                              &si,
1816                              nullptr,
1817                              0,
1818                              rtld_flags,
1819                              extinfo,
1820                              false /* add_as_children */)) {
1821     if (si != nullptr) {
1822       soinfo_unload(si);
1823     }
1824     return nullptr;
1825   }
1826 
1827   si->increment_ref_count();
1828 
1829   return si;
1830 }
1831 
soinfo_unload_impl(soinfo * root)1832 static void soinfo_unload_impl(soinfo* root) {
1833   ScopedTrace trace((std::string("unload ") + root->get_realpath()).c_str());
1834   bool is_linked = root->is_linked();
1835 
1836   if (!root->can_unload()) {
1837     LD_LOG(kLogDlopen,
1838            "... dlclose(root=\"%s\"@%p) ... not unloading - the load group is flagged with NODELETE",
1839            root->get_realpath(),
1840            root);
1841     return;
1842   }
1843 
1844 
1845   soinfo_list_t unload_list;
1846   unload_list.push_back(root);
1847 
1848   soinfo_list_t local_unload_list;
1849   soinfo_list_t external_unload_list;
1850   soinfo* si = nullptr;
1851 
1852   while ((si = unload_list.pop_front()) != nullptr) {
1853     if (local_unload_list.contains(si)) {
1854       continue;
1855     }
1856 
1857     local_unload_list.push_back(si);
1858 
1859     if (si->has_min_version(0)) {
1860       soinfo* child = nullptr;
1861       while ((child = si->get_children().pop_front()) != nullptr) {
1862         TRACE("%s@%p needs to unload %s@%p", si->get_realpath(), si,
1863             child->get_realpath(), child);
1864 
1865         child->get_parents().remove(si);
1866 
1867         if (local_unload_list.contains(child)) {
1868           continue;
1869         } else if (child->is_linked() && child->get_local_group_root() != root) {
1870           external_unload_list.push_back(child);
1871         } else if (child->get_parents().empty()) {
1872           unload_list.push_back(child);
1873         }
1874       }
1875     } else {
1876       async_safe_fatal("soinfo for \"%s\"@%p has no version", si->get_realpath(), si);
1877     }
1878   }
1879 
1880   local_unload_list.for_each([](soinfo* si) {
1881     LD_LOG(kLogDlopen,
1882            "... dlclose: calling destructors for \"%s\"@%p ... ",
1883            si->get_realpath(),
1884            si);
1885     si->call_destructors();
1886     LD_LOG(kLogDlopen,
1887            "... dlclose: calling destructors for \"%s\"@%p ... done",
1888            si->get_realpath(),
1889            si);
1890   });
1891 
1892   while ((si = local_unload_list.pop_front()) != nullptr) {
1893     LD_LOG(kLogDlopen,
1894            "... dlclose: unloading \"%s\"@%p ...",
1895            si->get_realpath(),
1896            si);
1897     ++g_module_unload_counter;
1898     notify_gdb_of_unload(si);
1899     unregister_soinfo_tls(si);
1900     if (__libc_shared_globals()->unload_hook) {
1901       __libc_shared_globals()->unload_hook(si->load_bias, si->phdr, si->phnum);
1902     }
1903     get_cfi_shadow()->BeforeUnload(si);
1904     soinfo_free(si);
1905   }
1906 
1907   if (is_linked) {
1908     while ((si = external_unload_list.pop_front()) != nullptr) {
1909       LD_LOG(kLogDlopen,
1910              "... dlclose: unloading external reference \"%s\"@%p ...",
1911              si->get_realpath(),
1912              si);
1913       soinfo_unload(si);
1914     }
1915   } else {
1916       LD_LOG(kLogDlopen,
1917              "... dlclose: unload_si was not linked - not unloading external references ...");
1918   }
1919 }
1920 
soinfo_unload(soinfo * unload_si)1921 static void soinfo_unload(soinfo* unload_si) {
1922   // Note that the library can be loaded but not linked;
1923   // in which case there is no root but we still need
1924   // to walk the tree and unload soinfos involved.
1925   //
1926   // This happens on unsuccessful dlopen, when one of
1927   // the DT_NEEDED libraries could not be linked/found.
1928   bool is_linked = unload_si->is_linked();
1929   soinfo* root = is_linked ? unload_si->get_local_group_root() : unload_si;
1930 
1931   LD_LOG(kLogDlopen,
1932          "... dlclose(realpath=\"%s\"@%p) ... load group root is \"%s\"@%p",
1933          unload_si->get_realpath(),
1934          unload_si,
1935          root->get_realpath(),
1936          root);
1937 
1938 
1939   size_t ref_count = is_linked ? root->decrement_ref_count() : 0;
1940   if (ref_count > 0) {
1941     LD_LOG(kLogDlopen,
1942            "... dlclose(root=\"%s\"@%p) ... not unloading - decrementing ref_count to %zd",
1943            root->get_realpath(),
1944            root,
1945            ref_count);
1946     return;
1947   }
1948 
1949   soinfo_unload_impl(root);
1950 }
1951 
increment_dso_handle_reference_counter(void * dso_handle)1952 void increment_dso_handle_reference_counter(void* dso_handle) {
1953   if (dso_handle == nullptr) {
1954     return;
1955   }
1956 
1957   auto it = g_dso_handle_counters.find(dso_handle);
1958   if (it != g_dso_handle_counters.end()) {
1959     CHECK(++it->second != 0);
1960   } else {
1961     soinfo* si = find_containing_library(dso_handle);
1962     if (si != nullptr) {
1963       ProtectedDataGuard guard;
1964       si->increment_ref_count();
1965     } else {
1966       async_safe_fatal(
1967           "increment_dso_handle_reference_counter: Couldn't find soinfo by dso_handle=%p",
1968           dso_handle);
1969     }
1970     g_dso_handle_counters[dso_handle] = 1U;
1971   }
1972 }
1973 
decrement_dso_handle_reference_counter(void * dso_handle)1974 void decrement_dso_handle_reference_counter(void* dso_handle) {
1975   if (dso_handle == nullptr) {
1976     return;
1977   }
1978 
1979   auto it = g_dso_handle_counters.find(dso_handle);
1980   CHECK(it != g_dso_handle_counters.end());
1981   CHECK(it->second != 0);
1982 
1983   if (--it->second == 0) {
1984     soinfo* si = find_containing_library(dso_handle);
1985     if (si != nullptr) {
1986       ProtectedDataGuard guard;
1987       soinfo_unload(si);
1988     } else {
1989       async_safe_fatal(
1990           "decrement_dso_handle_reference_counter: Couldn't find soinfo by dso_handle=%p",
1991           dso_handle);
1992     }
1993     g_dso_handle_counters.erase(it);
1994   }
1995 }
1996 
symbol_display_name(const char * sym_name,const char * sym_ver)1997 static std::string symbol_display_name(const char* sym_name, const char* sym_ver) {
1998   if (sym_ver == nullptr) {
1999     return sym_name;
2000   }
2001 
2002   return std::string(sym_name) + ", version " + sym_ver;
2003 }
2004 
get_caller_namespace(soinfo * caller)2005 static android_namespace_t* get_caller_namespace(soinfo* caller) {
2006   return caller != nullptr ? caller->get_primary_namespace() : g_anonymous_namespace;
2007 }
2008 
do_android_get_LD_LIBRARY_PATH(char * buffer,size_t buffer_size)2009 void do_android_get_LD_LIBRARY_PATH(char* buffer, size_t buffer_size) {
2010   // Use basic string manipulation calls to avoid snprintf.
2011   // snprintf indirectly calls pthread_getspecific to get the size of a buffer.
2012   // When debug malloc is enabled, this call returns 0. This in turn causes
2013   // snprintf to do nothing, which causes libraries to fail to load.
2014   // See b/17302493 for further details.
2015   // Once the above bug is fixed, this code can be modified to use
2016   // snprintf again.
2017   const auto& default_ld_paths = g_default_namespace.get_default_library_paths();
2018 
2019   size_t required_size = 0;
2020   for (const auto& path : default_ld_paths) {
2021     required_size += path.size() + 1;
2022   }
2023 
2024   if (buffer_size < required_size) {
2025     async_safe_fatal("android_get_LD_LIBRARY_PATH failed, buffer too small: "
2026                      "buffer len %zu, required len %zu", buffer_size, required_size);
2027   }
2028 
2029   char* end = buffer;
2030   for (size_t i = 0; i < default_ld_paths.size(); ++i) {
2031     if (i > 0) *end++ = ':';
2032     end = stpcpy(end, default_ld_paths[i].c_str());
2033   }
2034 }
2035 
do_android_update_LD_LIBRARY_PATH(const char * ld_library_path)2036 void do_android_update_LD_LIBRARY_PATH(const char* ld_library_path) {
2037   parse_LD_LIBRARY_PATH(ld_library_path);
2038 }
2039 
android_dlextinfo_to_string(const android_dlextinfo * info)2040 static std::string android_dlextinfo_to_string(const android_dlextinfo* info) {
2041   if (info == nullptr) {
2042     return "(null)";
2043   }
2044 
2045   return android::base::StringPrintf("[flags=0x%" PRIx64 ","
2046                                      " reserved_addr=%p,"
2047                                      " reserved_size=0x%zx,"
2048                                      " relro_fd=%d,"
2049                                      " library_fd=%d,"
2050                                      " library_fd_offset=0x%" PRIx64 ","
2051                                      " library_namespace=%s@%p]",
2052                                      info->flags,
2053                                      info->reserved_addr,
2054                                      info->reserved_size,
2055                                      info->relro_fd,
2056                                      info->library_fd,
2057                                      info->library_fd_offset,
2058                                      (info->flags & ANDROID_DLEXT_USE_NAMESPACE) != 0 ?
2059                                         (info->library_namespace != nullptr ?
2060                                           info->library_namespace->get_name() : "(null)") : "(n/a)",
2061                                      (info->flags & ANDROID_DLEXT_USE_NAMESPACE) != 0 ?
2062                                         info->library_namespace : nullptr);
2063 }
2064 
do_dlopen(const char * name,int flags,const android_dlextinfo * extinfo,const void * caller_addr)2065 void* do_dlopen(const char* name, int flags,
2066                 const android_dlextinfo* extinfo,
2067                 const void* caller_addr) {
2068   std::string trace_prefix = std::string("dlopen: ") + (name == nullptr ? "(nullptr)" : name);
2069   ScopedTrace trace(trace_prefix.c_str());
2070   ScopedTrace loading_trace((trace_prefix + " - loading and linking").c_str());
2071   soinfo* const caller = find_containing_library(caller_addr);
2072   android_namespace_t* ns = get_caller_namespace(caller);
2073 
2074   LD_LOG(kLogDlopen,
2075          "dlopen(name=\"%s\", flags=0x%x, extinfo=%s, caller=\"%s\", caller_ns=%s@%p, targetSdkVersion=%i) ...",
2076          name,
2077          flags,
2078          android_dlextinfo_to_string(extinfo).c_str(),
2079          caller == nullptr ? "(null)" : caller->get_realpath(),
2080          ns == nullptr ? "(null)" : ns->get_name(),
2081          ns,
2082          get_application_target_sdk_version());
2083 
2084   auto purge_guard = android::base::make_scope_guard([&]() { purge_unused_memory(); });
2085 
2086   auto failure_guard = android::base::make_scope_guard(
2087       [&]() { LD_LOG(kLogDlopen, "... dlopen failed: %s", linker_get_error_buffer()); });
2088 
2089   if ((flags & ~(RTLD_NOW|RTLD_LAZY|RTLD_LOCAL|RTLD_GLOBAL|RTLD_NODELETE|RTLD_NOLOAD)) != 0) {
2090     DL_OPEN_ERR("invalid flags to dlopen: %x", flags);
2091     return nullptr;
2092   }
2093 
2094   if (extinfo != nullptr) {
2095     if ((extinfo->flags & ~(ANDROID_DLEXT_VALID_FLAG_BITS)) != 0) {
2096       DL_OPEN_ERR("invalid extended flags to android_dlopen_ext: 0x%" PRIx64, extinfo->flags);
2097       return nullptr;
2098     }
2099 
2100     if ((extinfo->flags & ANDROID_DLEXT_USE_LIBRARY_FD) == 0 &&
2101         (extinfo->flags & ANDROID_DLEXT_USE_LIBRARY_FD_OFFSET) != 0) {
2102       DL_OPEN_ERR("invalid extended flag combination (ANDROID_DLEXT_USE_LIBRARY_FD_OFFSET without "
2103           "ANDROID_DLEXT_USE_LIBRARY_FD): 0x%" PRIx64, extinfo->flags);
2104       return nullptr;
2105     }
2106 
2107     if ((extinfo->flags & ANDROID_DLEXT_USE_NAMESPACE) != 0) {
2108       if (extinfo->library_namespace == nullptr) {
2109         DL_OPEN_ERR("ANDROID_DLEXT_USE_NAMESPACE is set but extinfo->library_namespace is null");
2110         return nullptr;
2111       }
2112       ns = extinfo->library_namespace;
2113     }
2114   }
2115 
2116   // Workaround for dlopen(/system/lib/<soname>) when .so is in /apex. http://b/121248172
2117   // The workaround works only when targetSdkVersion < Q.
2118   std::string name_to_apex;
2119   if (translateSystemPathToApexPath(name, &name_to_apex)) {
2120     const char* new_name = name_to_apex.c_str();
2121     LD_LOG(kLogDlopen, "dlopen considering translation from %s to APEX path %s",
2122            name,
2123            new_name);
2124     // Some APEXs could be optionally disabled. Only translate the path
2125     // when the old file is absent and the new file exists.
2126     // TODO(b/124218500): Re-enable it once app compat issue is resolved
2127     /*
2128     if (file_exists(name)) {
2129       LD_LOG(kLogDlopen, "dlopen %s exists, not translating", name);
2130     } else
2131     */
2132     if (!file_exists(new_name)) {
2133       LD_LOG(kLogDlopen, "dlopen %s does not exist, not translating",
2134              new_name);
2135     } else {
2136       LD_LOG(kLogDlopen, "dlopen translation accepted: using %s", new_name);
2137       name = new_name;
2138     }
2139   }
2140   // End Workaround for dlopen(/system/lib/<soname>) when .so is in /apex.
2141 
2142   std::string asan_name_holder;
2143 
2144   const char* translated_name = name;
2145   if (g_is_asan && translated_name != nullptr && translated_name[0] == '/') {
2146     char original_path[PATH_MAX];
2147     if (realpath(name, original_path) != nullptr) {
2148       asan_name_holder = std::string(kAsanLibDirPrefix) + original_path;
2149       if (file_exists(asan_name_holder.c_str())) {
2150         soinfo* si = nullptr;
2151         if (find_loaded_library_by_realpath(ns, original_path, true, &si)) {
2152           PRINT("linker_asan dlopen NOT translating \"%s\" -> \"%s\": library already loaded", name,
2153                 asan_name_holder.c_str());
2154         } else {
2155           PRINT("linker_asan dlopen translating \"%s\" -> \"%s\"", name, translated_name);
2156           translated_name = asan_name_holder.c_str();
2157         }
2158       }
2159     }
2160   }
2161 
2162   ProtectedDataGuard guard;
2163   soinfo* si = find_library(ns, translated_name, flags, extinfo, caller);
2164   loading_trace.End();
2165 
2166   if (si != nullptr) {
2167     void* handle = si->to_handle();
2168     LD_LOG(kLogDlopen,
2169            "... dlopen calling constructors: realpath=\"%s\", soname=\"%s\", handle=%p",
2170            si->get_realpath(), si->get_soname(), handle);
2171     si->call_constructors();
2172     failure_guard.Disable();
2173     LD_LOG(kLogDlopen,
2174            "... dlopen successful: realpath=\"%s\", soname=\"%s\", handle=%p",
2175            si->get_realpath(), si->get_soname(), handle);
2176     return handle;
2177   }
2178 
2179   return nullptr;
2180 }
2181 
do_dladdr(const void * addr,Dl_info * info)2182 int do_dladdr(const void* addr, Dl_info* info) {
2183   // Determine if this address can be found in any library currently mapped.
2184   soinfo* si = find_containing_library(addr);
2185   if (si == nullptr) {
2186     return 0;
2187   }
2188 
2189   memset(info, 0, sizeof(Dl_info));
2190 
2191   info->dli_fname = si->get_realpath();
2192   // Address at which the shared object is loaded.
2193   info->dli_fbase = reinterpret_cast<void*>(si->base);
2194 
2195   // Determine if any symbol in the library contains the specified address.
2196   ElfW(Sym)* sym = si->find_symbol_by_address(addr);
2197   if (sym != nullptr) {
2198     info->dli_sname = si->get_string(sym->st_name);
2199     info->dli_saddr = reinterpret_cast<void*>(si->resolve_symbol_address(sym));
2200   }
2201 
2202   return 1;
2203 }
2204 
soinfo_from_handle(void * handle)2205 static soinfo* soinfo_from_handle(void* handle) {
2206   if ((reinterpret_cast<uintptr_t>(handle) & 1) != 0) {
2207     auto it = g_soinfo_handles_map.find(reinterpret_cast<uintptr_t>(handle));
2208     if (it == g_soinfo_handles_map.end()) {
2209       return nullptr;
2210     } else {
2211       return it->second;
2212     }
2213   }
2214 
2215   return static_cast<soinfo*>(handle);
2216 }
2217 
do_dlsym(void * handle,const char * sym_name,const char * sym_ver,const void * caller_addr,void ** symbol)2218 bool do_dlsym(void* handle,
2219               const char* sym_name,
2220               const char* sym_ver,
2221               const void* caller_addr,
2222               void** symbol) {
2223   ScopedTrace trace("dlsym");
2224 #if !defined(__LP64__)
2225   if (handle == nullptr) {
2226     DL_SYM_ERR("dlsym failed: library handle is null");
2227     return false;
2228   }
2229 #endif
2230 
2231   soinfo* found = nullptr;
2232   const ElfW(Sym)* sym = nullptr;
2233   soinfo* caller = find_containing_library(caller_addr);
2234   android_namespace_t* ns = get_caller_namespace(caller);
2235   soinfo* si = nullptr;
2236   if (handle != RTLD_DEFAULT && handle != RTLD_NEXT) {
2237     si = soinfo_from_handle(handle);
2238   }
2239 
2240   LD_LOG(kLogDlsym,
2241          "dlsym(handle=%p(\"%s\"), sym_name=\"%s\", sym_ver=\"%s\", caller=\"%s\", caller_ns=%s@%p) ...",
2242          handle,
2243          si != nullptr ? si->get_realpath() : "n/a",
2244          sym_name,
2245          sym_ver,
2246          caller == nullptr ? "(null)" : caller->get_realpath(),
2247          ns == nullptr ? "(null)" : ns->get_name(),
2248          ns);
2249 
2250   auto failure_guard = android::base::make_scope_guard(
2251       [&]() { LD_LOG(kLogDlsym, "... dlsym failed: %s", linker_get_error_buffer()); });
2252 
2253   if (sym_name == nullptr) {
2254     DL_SYM_ERR("dlsym failed: symbol name is null");
2255     return false;
2256   }
2257 
2258   version_info vi_instance;
2259   version_info* vi = nullptr;
2260 
2261   if (sym_ver != nullptr) {
2262     vi_instance.name = sym_ver;
2263     vi_instance.elf_hash = calculate_elf_hash(sym_ver);
2264     vi = &vi_instance;
2265   }
2266 
2267   if (handle == RTLD_DEFAULT || handle == RTLD_NEXT) {
2268     sym = dlsym_linear_lookup(ns, sym_name, vi, &found, caller, handle);
2269   } else {
2270     if (si == nullptr) {
2271       DL_SYM_ERR("dlsym failed: invalid handle: %p", handle);
2272       return false;
2273     }
2274     sym = dlsym_handle_lookup(si, &found, sym_name, vi);
2275   }
2276 
2277   if (sym != nullptr) {
2278     uint32_t bind = ELF_ST_BIND(sym->st_info);
2279     uint32_t type = ELF_ST_TYPE(sym->st_info);
2280 
2281     if ((bind == STB_GLOBAL || bind == STB_WEAK) && sym->st_shndx != 0) {
2282       if (type == STT_TLS) {
2283         // For a TLS symbol, dlsym returns the address of the current thread's
2284         // copy of the symbol.
2285         const soinfo_tls* tls_module = found->get_tls();
2286         if (tls_module == nullptr) {
2287           DL_SYM_ERR("TLS symbol \"%s\" in solib \"%s\" with no TLS segment",
2288                      sym_name, found->get_realpath());
2289           return false;
2290         }
2291         void* tls_block = get_tls_block_for_this_thread(tls_module, /*should_alloc=*/true);
2292         *symbol = static_cast<char*>(tls_block) + sym->st_value;
2293       } else {
2294         *symbol = reinterpret_cast<void*>(found->resolve_symbol_address(sym));
2295       }
2296       failure_guard.Disable();
2297       LD_LOG(kLogDlsym,
2298              "... dlsym successful: sym_name=\"%s\", sym_ver=\"%s\", found in=\"%s\", address=%p",
2299              sym_name, sym_ver, found->get_soname(), *symbol);
2300       return true;
2301     }
2302 
2303     DL_SYM_ERR("symbol \"%s\" found but not global", symbol_display_name(sym_name, sym_ver).c_str());
2304     return false;
2305   }
2306 
2307   DL_SYM_ERR("undefined symbol: %s", symbol_display_name(sym_name, sym_ver).c_str());
2308   return false;
2309 }
2310 
do_dlclose(void * handle)2311 int do_dlclose(void* handle) {
2312   ScopedTrace trace("dlclose");
2313   ProtectedDataGuard guard;
2314   soinfo* si = soinfo_from_handle(handle);
2315   if (si == nullptr) {
2316     DL_OPEN_ERR("invalid handle: %p", handle);
2317     return -1;
2318   }
2319 
2320   LD_LOG(kLogDlopen,
2321          "dlclose(handle=%p, realpath=\"%s\"@%p) ...",
2322          handle,
2323          si->get_realpath(),
2324          si);
2325   soinfo_unload(si);
2326   LD_LOG(kLogDlopen,
2327          "dlclose(handle=%p) ... done",
2328          handle);
2329   return 0;
2330 }
2331 
2332 // Make ns as the anonymous namespace that is a namespace used when
2333 // we fail to determine the caller address (e.g., call from mono-jited code)
2334 // Since there can be multiple anonymous namespace in a process, subsequent
2335 // call to this function causes an error.
set_anonymous_namespace(android_namespace_t * ns)2336 static bool set_anonymous_namespace(android_namespace_t* ns) {
2337   if (!g_anonymous_namespace_set && ns != nullptr) {
2338     CHECK(ns->is_also_used_as_anonymous());
2339     g_anonymous_namespace = ns;
2340     g_anonymous_namespace_set = true;
2341     return true;
2342   }
2343   return false;
2344 }
2345 
2346 // TODO(b/130388701) remove this. Currently, this is used only for testing
2347 // where we don't have classloader namespace.
init_anonymous_namespace(const char * shared_lib_sonames,const char * library_search_path)2348 bool init_anonymous_namespace(const char* shared_lib_sonames, const char* library_search_path) {
2349   ProtectedDataGuard guard;
2350 
2351   // Test-only feature: we need to change the anonymous namespace multiple times
2352   // while the test is running.
2353   g_anonymous_namespace_set = false;
2354 
2355   // create anonymous namespace
2356   // When the caller is nullptr - create_namespace will take global group
2357   // from the anonymous namespace, which is fine because anonymous namespace
2358   // is still pointing to the default one.
2359   android_namespace_t* anon_ns =
2360       create_namespace(nullptr,
2361                        "(anonymous)",
2362                        nullptr,
2363                        library_search_path,
2364                        ANDROID_NAMESPACE_TYPE_ISOLATED |
2365                        ANDROID_NAMESPACE_TYPE_ALSO_USED_AS_ANONYMOUS,
2366                        nullptr,
2367                        &g_default_namespace);
2368 
2369   CHECK(anon_ns != nullptr);
2370 
2371   if (!link_namespaces(anon_ns, &g_default_namespace, shared_lib_sonames)) {
2372     // TODO: delete anon_ns
2373     return false;
2374   }
2375 
2376   return true;
2377 }
2378 
add_soinfos_to_namespace(const soinfo_list_t & soinfos,android_namespace_t * ns)2379 static void add_soinfos_to_namespace(const soinfo_list_t& soinfos, android_namespace_t* ns) {
2380   ns->add_soinfos(soinfos);
2381   for (auto si : soinfos) {
2382     si->add_secondary_namespace(ns);
2383   }
2384 }
2385 
fix_lib_paths(std::vector<std::string> paths)2386 std::vector<std::string> fix_lib_paths(std::vector<std::string> paths) {
2387   // For the bootstrap linker, insert /system/${LIB}/bootstrap in front of /system/${LIB} in any
2388   // namespace search path. The bootstrap linker should prefer to use the bootstrap bionic libraries
2389   // (e.g. libc.so).
2390 #if !defined(__ANDROID_APEX__)
2391   for (size_t i = 0; i < paths.size(); ++i) {
2392     if (paths[i] == kSystemLibDir) {
2393       paths.insert(paths.begin() + i, std::string(kSystemLibDir) + "/bootstrap");
2394       ++i;
2395     }
2396   }
2397 #endif
2398   return paths;
2399 }
2400 
create_namespace(const void * caller_addr,const char * name,const char * ld_library_path,const char * default_library_path,uint64_t type,const char * permitted_when_isolated_path,android_namespace_t * parent_namespace)2401 android_namespace_t* create_namespace(const void* caller_addr,
2402                                       const char* name,
2403                                       const char* ld_library_path,
2404                                       const char* default_library_path,
2405                                       uint64_t type,
2406                                       const char* permitted_when_isolated_path,
2407                                       android_namespace_t* parent_namespace) {
2408   if (parent_namespace == nullptr) {
2409     // if parent_namespace is nullptr -> set it to the caller namespace
2410     soinfo* caller_soinfo = find_containing_library(caller_addr);
2411 
2412     parent_namespace = caller_soinfo != nullptr ?
2413                        caller_soinfo->get_primary_namespace() :
2414                        g_anonymous_namespace;
2415   }
2416 
2417   ProtectedDataGuard guard;
2418   std::vector<std::string> ld_library_paths;
2419   std::vector<std::string> default_library_paths;
2420   std::vector<std::string> permitted_paths;
2421 
2422   parse_path(ld_library_path, ":", &ld_library_paths);
2423   parse_path(default_library_path, ":", &default_library_paths);
2424   parse_path(permitted_when_isolated_path, ":", &permitted_paths);
2425 
2426   android_namespace_t* ns = new (g_namespace_allocator.alloc()) android_namespace_t();
2427   ns->set_name(name);
2428   ns->set_isolated((type & ANDROID_NAMESPACE_TYPE_ISOLATED) != 0);
2429   ns->set_greylist_enabled((type & ANDROID_NAMESPACE_TYPE_GREYLIST_ENABLED) != 0);
2430   ns->set_also_used_as_anonymous((type & ANDROID_NAMESPACE_TYPE_ALSO_USED_AS_ANONYMOUS) != 0);
2431 
2432   if ((type & ANDROID_NAMESPACE_TYPE_SHARED) != 0) {
2433     // append parent namespace paths.
2434     std::copy(parent_namespace->get_ld_library_paths().begin(),
2435               parent_namespace->get_ld_library_paths().end(),
2436               back_inserter(ld_library_paths));
2437 
2438     std::copy(parent_namespace->get_default_library_paths().begin(),
2439               parent_namespace->get_default_library_paths().end(),
2440               back_inserter(default_library_paths));
2441 
2442     std::copy(parent_namespace->get_permitted_paths().begin(),
2443               parent_namespace->get_permitted_paths().end(),
2444               back_inserter(permitted_paths));
2445 
2446     // If shared - clone the parent namespace
2447     add_soinfos_to_namespace(parent_namespace->soinfo_list(), ns);
2448     // and copy parent namespace links
2449     for (auto& link : parent_namespace->linked_namespaces()) {
2450       ns->add_linked_namespace(link.linked_namespace(), link.shared_lib_sonames(),
2451                                link.allow_all_shared_libs());
2452     }
2453   } else {
2454     // If not shared - copy only the shared group
2455     add_soinfos_to_namespace(parent_namespace->get_shared_group(), ns);
2456   }
2457 
2458   ns->set_ld_library_paths(std::move(ld_library_paths));
2459   ns->set_default_library_paths(std::move(default_library_paths));
2460   ns->set_permitted_paths(std::move(permitted_paths));
2461 
2462   if (ns->is_also_used_as_anonymous() && !set_anonymous_namespace(ns)) {
2463     DL_ERR("failed to set namespace: [name=\"%s\", ld_library_path=\"%s\", default_library_paths=\"%s\""
2464            " permitted_paths=\"%s\"] as the anonymous namespace",
2465            ns->get_name(),
2466            android::base::Join(ns->get_ld_library_paths(), ':').c_str(),
2467            android::base::Join(ns->get_default_library_paths(), ':').c_str(),
2468            android::base::Join(ns->get_permitted_paths(), ':').c_str());
2469     return nullptr;
2470   }
2471 
2472   return ns;
2473 }
2474 
link_namespaces(android_namespace_t * namespace_from,android_namespace_t * namespace_to,const char * shared_lib_sonames)2475 bool link_namespaces(android_namespace_t* namespace_from,
2476                      android_namespace_t* namespace_to,
2477                      const char* shared_lib_sonames) {
2478   if (namespace_to == nullptr) {
2479     namespace_to = &g_default_namespace;
2480   }
2481 
2482   if (namespace_from == nullptr) {
2483     DL_ERR("error linking namespaces: namespace_from is null.");
2484     return false;
2485   }
2486 
2487   if (shared_lib_sonames == nullptr || shared_lib_sonames[0] == '\0') {
2488     DL_ERR("error linking namespaces \"%s\"->\"%s\": the list of shared libraries is empty.",
2489            namespace_from->get_name(), namespace_to->get_name());
2490     return false;
2491   }
2492 
2493   auto sonames = android::base::Split(shared_lib_sonames, ":");
2494   std::unordered_set<std::string> sonames_set(sonames.begin(), sonames.end());
2495 
2496   ProtectedDataGuard guard;
2497   namespace_from->add_linked_namespace(namespace_to, sonames_set, false);
2498 
2499   return true;
2500 }
2501 
link_namespaces_all_libs(android_namespace_t * namespace_from,android_namespace_t * namespace_to)2502 bool link_namespaces_all_libs(android_namespace_t* namespace_from,
2503                               android_namespace_t* namespace_to) {
2504   if (namespace_from == nullptr) {
2505     DL_ERR("error linking namespaces: namespace_from is null.");
2506     return false;
2507   }
2508 
2509   if (namespace_to == nullptr) {
2510     DL_ERR("error linking namespaces: namespace_to is null.");
2511     return false;
2512   }
2513 
2514   ProtectedDataGuard guard;
2515   namespace_from->add_linked_namespace(namespace_to, std::unordered_set<std::string>(), true);
2516 
2517   return true;
2518 }
2519 
call_ifunc_resolver(ElfW (Addr)resolver_addr)2520 ElfW(Addr) call_ifunc_resolver(ElfW(Addr) resolver_addr) {
2521   if (g_is_ldd) return 0;
2522 
2523   ElfW(Addr) ifunc_addr = __bionic_call_ifunc_resolver(resolver_addr);
2524   TRACE_TYPE(RELO, "Called ifunc_resolver@%p. The result is %p",
2525       reinterpret_cast<void *>(resolver_addr), reinterpret_cast<void*>(ifunc_addr));
2526 
2527   return ifunc_addr;
2528 }
2529 
get_version_info(ElfW (Versym)source_symver) const2530 const version_info* VersionTracker::get_version_info(ElfW(Versym) source_symver) const {
2531   if (source_symver < 2 ||
2532       source_symver >= version_infos.size() ||
2533       version_infos[source_symver].name == nullptr) {
2534     return nullptr;
2535   }
2536 
2537   return &version_infos[source_symver];
2538 }
2539 
add_version_info(size_t source_index,ElfW (Word)elf_hash,const char * ver_name,const soinfo * target_si)2540 void VersionTracker::add_version_info(size_t source_index,
2541                                       ElfW(Word) elf_hash,
2542                                       const char* ver_name,
2543                                       const soinfo* target_si) {
2544   if (source_index >= version_infos.size()) {
2545     version_infos.resize(source_index+1);
2546   }
2547 
2548   version_infos[source_index].elf_hash = elf_hash;
2549   version_infos[source_index].name = ver_name;
2550   version_infos[source_index].target_si = target_si;
2551 }
2552 
init_verneed(const soinfo * si_from)2553 bool VersionTracker::init_verneed(const soinfo* si_from) {
2554   uintptr_t verneed_ptr = si_from->get_verneed_ptr();
2555 
2556   if (verneed_ptr == 0) {
2557     return true;
2558   }
2559 
2560   size_t verneed_cnt = si_from->get_verneed_cnt();
2561 
2562   for (size_t i = 0, offset = 0; i<verneed_cnt; ++i) {
2563     const ElfW(Verneed)* verneed = reinterpret_cast<ElfW(Verneed)*>(verneed_ptr + offset);
2564     size_t vernaux_offset = offset + verneed->vn_aux;
2565     offset += verneed->vn_next;
2566 
2567     if (verneed->vn_version != 1) {
2568       DL_ERR("unsupported verneed[%zd] vn_version: %d (expected 1)", i, verneed->vn_version);
2569       return false;
2570     }
2571 
2572     const char* target_soname = si_from->get_string(verneed->vn_file);
2573     // find it in dependencies
2574     soinfo* target_si = si_from->get_children().find_if([&](const soinfo* si) {
2575       return si->get_soname() != nullptr && strcmp(si->get_soname(), target_soname) == 0;
2576     });
2577 
2578     if (target_si == nullptr) {
2579       DL_ERR("cannot find \"%s\" from verneed[%zd] in DT_NEEDED list for \"%s\"",
2580           target_soname, i, si_from->get_realpath());
2581       return false;
2582     }
2583 
2584     for (size_t j = 0; j<verneed->vn_cnt; ++j) {
2585       const ElfW(Vernaux)* vernaux = reinterpret_cast<ElfW(Vernaux)*>(verneed_ptr + vernaux_offset);
2586       vernaux_offset += vernaux->vna_next;
2587 
2588       const ElfW(Word) elf_hash = vernaux->vna_hash;
2589       const char* ver_name = si_from->get_string(vernaux->vna_name);
2590       ElfW(Half) source_index = vernaux->vna_other;
2591 
2592       add_version_info(source_index, elf_hash, ver_name, target_si);
2593     }
2594   }
2595 
2596   return true;
2597 }
2598 
2599 template <typename F>
for_each_verdef(const soinfo * si,F functor)2600 static bool for_each_verdef(const soinfo* si, F functor) {
2601   if (!si->has_min_version(2)) {
2602     return true;
2603   }
2604 
2605   uintptr_t verdef_ptr = si->get_verdef_ptr();
2606   if (verdef_ptr == 0) {
2607     return true;
2608   }
2609 
2610   size_t offset = 0;
2611 
2612   size_t verdef_cnt = si->get_verdef_cnt();
2613   for (size_t i = 0; i<verdef_cnt; ++i) {
2614     const ElfW(Verdef)* verdef = reinterpret_cast<ElfW(Verdef)*>(verdef_ptr + offset);
2615     size_t verdaux_offset = offset + verdef->vd_aux;
2616     offset += verdef->vd_next;
2617 
2618     if (verdef->vd_version != 1) {
2619       DL_ERR("unsupported verdef[%zd] vd_version: %d (expected 1) library: %s",
2620           i, verdef->vd_version, si->get_realpath());
2621       return false;
2622     }
2623 
2624     if ((verdef->vd_flags & VER_FLG_BASE) != 0) {
2625       // "this is the version of the file itself.  It must not be used for
2626       //  matching a symbol. It can be used to match references."
2627       //
2628       // http://www.akkadia.org/drepper/symbol-versioning
2629       continue;
2630     }
2631 
2632     if (verdef->vd_cnt == 0) {
2633       DL_ERR("invalid verdef[%zd] vd_cnt == 0 (version without a name)", i);
2634       return false;
2635     }
2636 
2637     const ElfW(Verdaux)* verdaux = reinterpret_cast<ElfW(Verdaux)*>(verdef_ptr + verdaux_offset);
2638 
2639     if (functor(i, verdef, verdaux) == true) {
2640       break;
2641     }
2642   }
2643 
2644   return true;
2645 }
2646 
find_verdef_version_index(const soinfo * si,const version_info * vi)2647 ElfW(Versym) find_verdef_version_index(const soinfo* si, const version_info* vi) {
2648   if (vi == nullptr) {
2649     return kVersymNotNeeded;
2650   }
2651 
2652   ElfW(Versym) result = kVersymGlobal;
2653 
2654   if (!for_each_verdef(si,
2655     [&](size_t, const ElfW(Verdef)* verdef, const ElfW(Verdaux)* verdaux) {
2656       if (verdef->vd_hash == vi->elf_hash &&
2657           strcmp(vi->name, si->get_string(verdaux->vda_name)) == 0) {
2658         result = verdef->vd_ndx;
2659         return true;
2660       }
2661 
2662       return false;
2663     }
2664   )) {
2665     // verdef should have already been validated in prelink_image.
2666     async_safe_fatal("invalid verdef after prelinking: %s, %s",
2667                      si->get_realpath(), linker_get_error_buffer());
2668   }
2669 
2670   return result;
2671 }
2672 
2673 // Validate the library's verdef section. On error, returns false and invokes DL_ERR.
validate_verdef_section(const soinfo * si)2674 bool validate_verdef_section(const soinfo* si) {
2675   return for_each_verdef(si,
2676     [&](size_t, const ElfW(Verdef)*, const ElfW(Verdaux)*) {
2677       return false;
2678     });
2679 }
2680 
init_verdef(const soinfo * si_from)2681 bool VersionTracker::init_verdef(const soinfo* si_from) {
2682   return for_each_verdef(si_from,
2683     [&](size_t, const ElfW(Verdef)* verdef, const ElfW(Verdaux)* verdaux) {
2684       add_version_info(verdef->vd_ndx, verdef->vd_hash,
2685           si_from->get_string(verdaux->vda_name), si_from);
2686       return false;
2687     }
2688   );
2689 }
2690 
init(const soinfo * si_from)2691 bool VersionTracker::init(const soinfo* si_from) {
2692   if (!si_from->has_min_version(2)) {
2693     return true;
2694   }
2695 
2696   return init_verneed(si_from) && init_verdef(si_from);
2697 }
2698 
2699 // TODO (dimitry): Methods below need to be moved out of soinfo
2700 // and in more isolated file in order minimize dependencies on
2701 // unnecessary object in the linker binary. Consider making them
2702 // independent from soinfo (?).
lookup_version_info(const VersionTracker & version_tracker,ElfW (Word)sym,const char * sym_name,const version_info ** vi)2703 bool soinfo::lookup_version_info(const VersionTracker& version_tracker, ElfW(Word) sym,
2704                                  const char* sym_name, const version_info** vi) {
2705   const ElfW(Versym)* sym_ver_ptr = get_versym(sym);
2706   ElfW(Versym) sym_ver = sym_ver_ptr == nullptr ? 0 : *sym_ver_ptr;
2707 
2708   if (sym_ver != VER_NDX_LOCAL && sym_ver != VER_NDX_GLOBAL) {
2709     *vi = version_tracker.get_version_info(sym_ver);
2710 
2711     if (*vi == nullptr) {
2712       DL_ERR("cannot find verneed/verdef for version index=%d "
2713           "referenced by symbol \"%s\" at \"%s\"", sym_ver, sym_name, get_realpath());
2714       return false;
2715     }
2716   } else {
2717     // there is no version info
2718     *vi = nullptr;
2719   }
2720 
2721   return true;
2722 }
2723 
apply_relr_reloc(ElfW (Addr)offset)2724 void soinfo::apply_relr_reloc(ElfW(Addr) offset) {
2725   ElfW(Addr) address = offset + load_bias;
2726   *reinterpret_cast<ElfW(Addr)*>(address) += load_bias;
2727 }
2728 
2729 // Process relocations in SHT_RELR section (experimental).
2730 // Details of the encoding are described in this post:
2731 //   https://groups.google.com/d/msg/generic-abi/bX460iggiKg/Pi9aSwwABgAJ
relocate_relr()2732 bool soinfo::relocate_relr() {
2733   ElfW(Relr)* begin = relr_;
2734   ElfW(Relr)* end = relr_ + relr_count_;
2735   constexpr size_t wordsize = sizeof(ElfW(Addr));
2736 
2737   ElfW(Addr) base = 0;
2738   for (ElfW(Relr)* current = begin; current < end; ++current) {
2739     ElfW(Relr) entry = *current;
2740     ElfW(Addr) offset;
2741 
2742     if ((entry&1) == 0) {
2743       // Even entry: encodes the offset for next relocation.
2744       offset = static_cast<ElfW(Addr)>(entry);
2745       apply_relr_reloc(offset);
2746       // Set base offset for subsequent bitmap entries.
2747       base = offset + wordsize;
2748       continue;
2749     }
2750 
2751     // Odd entry: encodes bitmap for relocations starting at base.
2752     offset = base;
2753     while (entry != 0) {
2754       entry >>= 1;
2755       if ((entry&1) != 0) {
2756         apply_relr_reloc(offset);
2757       }
2758       offset += wordsize;
2759     }
2760 
2761     // Advance base offset by 63 words for 64-bit platforms,
2762     // or 31 words for 32-bit platforms.
2763     base += (8*wordsize - 1) * wordsize;
2764   }
2765   return true;
2766 }
2767 
2768 // An empty list of soinfos
2769 static soinfo_list_t g_empty_list;
2770 
prelink_image()2771 bool soinfo::prelink_image() {
2772   if (flags_ & FLAG_PRELINKED) return true;
2773   /* Extract dynamic section */
2774   ElfW(Word) dynamic_flags = 0;
2775   phdr_table_get_dynamic_section(phdr, phnum, load_bias, &dynamic, &dynamic_flags);
2776 
2777   /* We can't log anything until the linker is relocated */
2778   bool relocating_linker = (flags_ & FLAG_LINKER) != 0;
2779   if (!relocating_linker) {
2780     INFO("[ Linking \"%s\" ]", get_realpath());
2781     DEBUG("si->base = %p si->flags = 0x%08x", reinterpret_cast<void*>(base), flags_);
2782   }
2783 
2784   if (dynamic == nullptr) {
2785     if (!relocating_linker) {
2786       DL_ERR("missing PT_DYNAMIC in \"%s\"", get_realpath());
2787     }
2788     return false;
2789   } else {
2790     if (!relocating_linker) {
2791       DEBUG("dynamic = %p", dynamic);
2792     }
2793   }
2794 
2795 #if defined(__arm__)
2796   (void) phdr_table_get_arm_exidx(phdr, phnum, load_bias,
2797                                   &ARM_exidx, &ARM_exidx_count);
2798 #endif
2799 
2800   TlsSegment tls_segment;
2801   if (__bionic_get_tls_segment(phdr, phnum, load_bias, &tls_segment)) {
2802     if (!__bionic_check_tls_alignment(&tls_segment.alignment)) {
2803       if (!relocating_linker) {
2804         DL_ERR("TLS segment alignment in \"%s\" is not a power of 2: %zu",
2805                get_realpath(), tls_segment.alignment);
2806       }
2807       return false;
2808     }
2809     tls_ = std::make_unique<soinfo_tls>();
2810     tls_->segment = tls_segment;
2811   }
2812 
2813   // Extract useful information from dynamic section.
2814   // Note that: "Except for the DT_NULL element at the end of the array,
2815   // and the relative order of DT_NEEDED elements, entries may appear in any order."
2816   //
2817   // source: http://www.sco.com/developers/gabi/1998-04-29/ch5.dynamic.html
2818   uint32_t needed_count = 0;
2819   for (ElfW(Dyn)* d = dynamic; d->d_tag != DT_NULL; ++d) {
2820     DEBUG("d = %p, d[0](tag) = %p d[1](val) = %p",
2821           d, reinterpret_cast<void*>(d->d_tag), reinterpret_cast<void*>(d->d_un.d_val));
2822     switch (d->d_tag) {
2823       case DT_SONAME:
2824         // this is parsed after we have strtab initialized (see below).
2825         break;
2826 
2827       case DT_HASH:
2828         nbucket_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr)[0];
2829         nchain_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr)[1];
2830         bucket_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr + 8);
2831         chain_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr + 8 + nbucket_ * 4);
2832         break;
2833 
2834       case DT_GNU_HASH:
2835         gnu_nbucket_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr)[0];
2836         // skip symndx
2837         gnu_maskwords_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr)[2];
2838         gnu_shift2_ = reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr)[3];
2839 
2840         gnu_bloom_filter_ = reinterpret_cast<ElfW(Addr)*>(load_bias + d->d_un.d_ptr + 16);
2841         gnu_bucket_ = reinterpret_cast<uint32_t*>(gnu_bloom_filter_ + gnu_maskwords_);
2842         // amend chain for symndx = header[1]
2843         gnu_chain_ = gnu_bucket_ + gnu_nbucket_ -
2844             reinterpret_cast<uint32_t*>(load_bias + d->d_un.d_ptr)[1];
2845 
2846         if (!powerof2(gnu_maskwords_)) {
2847           DL_ERR("invalid maskwords for gnu_hash = 0x%x, in \"%s\" expecting power to two",
2848               gnu_maskwords_, get_realpath());
2849           return false;
2850         }
2851         --gnu_maskwords_;
2852 
2853         flags_ |= FLAG_GNU_HASH;
2854         break;
2855 
2856       case DT_STRTAB:
2857         strtab_ = reinterpret_cast<const char*>(load_bias + d->d_un.d_ptr);
2858         break;
2859 
2860       case DT_STRSZ:
2861         strtab_size_ = d->d_un.d_val;
2862         break;
2863 
2864       case DT_SYMTAB:
2865         symtab_ = reinterpret_cast<ElfW(Sym)*>(load_bias + d->d_un.d_ptr);
2866         break;
2867 
2868       case DT_SYMENT:
2869         if (d->d_un.d_val != sizeof(ElfW(Sym))) {
2870           DL_ERR("invalid DT_SYMENT: %zd in \"%s\"",
2871               static_cast<size_t>(d->d_un.d_val), get_realpath());
2872           return false;
2873         }
2874         break;
2875 
2876       case DT_PLTREL:
2877 #if defined(USE_RELA)
2878         if (d->d_un.d_val != DT_RELA) {
2879           DL_ERR("unsupported DT_PLTREL in \"%s\"; expected DT_RELA", get_realpath());
2880           return false;
2881         }
2882 #else
2883         if (d->d_un.d_val != DT_REL) {
2884           DL_ERR("unsupported DT_PLTREL in \"%s\"; expected DT_REL", get_realpath());
2885           return false;
2886         }
2887 #endif
2888         break;
2889 
2890       case DT_JMPREL:
2891 #if defined(USE_RELA)
2892         plt_rela_ = reinterpret_cast<ElfW(Rela)*>(load_bias + d->d_un.d_ptr);
2893 #else
2894         plt_rel_ = reinterpret_cast<ElfW(Rel)*>(load_bias + d->d_un.d_ptr);
2895 #endif
2896         break;
2897 
2898       case DT_PLTRELSZ:
2899 #if defined(USE_RELA)
2900         plt_rela_count_ = d->d_un.d_val / sizeof(ElfW(Rela));
2901 #else
2902         plt_rel_count_ = d->d_un.d_val / sizeof(ElfW(Rel));
2903 #endif
2904         break;
2905 
2906       case DT_PLTGOT:
2907         // Ignored (because RTLD_LAZY is not supported).
2908         break;
2909 
2910       case DT_DEBUG:
2911         // Set the DT_DEBUG entry to the address of _r_debug for GDB
2912         // if the dynamic table is writable
2913         if ((dynamic_flags & PF_W) != 0) {
2914           d->d_un.d_val = reinterpret_cast<uintptr_t>(&_r_debug);
2915         }
2916         break;
2917 #if defined(USE_RELA)
2918       case DT_RELA:
2919         rela_ = reinterpret_cast<ElfW(Rela)*>(load_bias + d->d_un.d_ptr);
2920         break;
2921 
2922       case DT_RELASZ:
2923         rela_count_ = d->d_un.d_val / sizeof(ElfW(Rela));
2924         break;
2925 
2926       case DT_ANDROID_RELA:
2927         android_relocs_ = reinterpret_cast<uint8_t*>(load_bias + d->d_un.d_ptr);
2928         break;
2929 
2930       case DT_ANDROID_RELASZ:
2931         android_relocs_size_ = d->d_un.d_val;
2932         break;
2933 
2934       case DT_ANDROID_REL:
2935         DL_ERR("unsupported DT_ANDROID_REL in \"%s\"", get_realpath());
2936         return false;
2937 
2938       case DT_ANDROID_RELSZ:
2939         DL_ERR("unsupported DT_ANDROID_RELSZ in \"%s\"", get_realpath());
2940         return false;
2941 
2942       case DT_RELAENT:
2943         if (d->d_un.d_val != sizeof(ElfW(Rela))) {
2944           DL_ERR("invalid DT_RELAENT: %zd", static_cast<size_t>(d->d_un.d_val));
2945           return false;
2946         }
2947         break;
2948 
2949       // Ignored (see DT_RELCOUNT comments for details).
2950       case DT_RELACOUNT:
2951         break;
2952 
2953       case DT_REL:
2954         DL_ERR("unsupported DT_REL in \"%s\"", get_realpath());
2955         return false;
2956 
2957       case DT_RELSZ:
2958         DL_ERR("unsupported DT_RELSZ in \"%s\"", get_realpath());
2959         return false;
2960 
2961 #else
2962       case DT_REL:
2963         rel_ = reinterpret_cast<ElfW(Rel)*>(load_bias + d->d_un.d_ptr);
2964         break;
2965 
2966       case DT_RELSZ:
2967         rel_count_ = d->d_un.d_val / sizeof(ElfW(Rel));
2968         break;
2969 
2970       case DT_RELENT:
2971         if (d->d_un.d_val != sizeof(ElfW(Rel))) {
2972           DL_ERR("invalid DT_RELENT: %zd", static_cast<size_t>(d->d_un.d_val));
2973           return false;
2974         }
2975         break;
2976 
2977       case DT_ANDROID_REL:
2978         android_relocs_ = reinterpret_cast<uint8_t*>(load_bias + d->d_un.d_ptr);
2979         break;
2980 
2981       case DT_ANDROID_RELSZ:
2982         android_relocs_size_ = d->d_un.d_val;
2983         break;
2984 
2985       case DT_ANDROID_RELA:
2986         DL_ERR("unsupported DT_ANDROID_RELA in \"%s\"", get_realpath());
2987         return false;
2988 
2989       case DT_ANDROID_RELASZ:
2990         DL_ERR("unsupported DT_ANDROID_RELASZ in \"%s\"", get_realpath());
2991         return false;
2992 
2993       // "Indicates that all RELATIVE relocations have been concatenated together,
2994       // and specifies the RELATIVE relocation count."
2995       //
2996       // TODO: Spec also mentions that this can be used to optimize relocation process;
2997       // Not currently used by bionic linker - ignored.
2998       case DT_RELCOUNT:
2999         break;
3000 
3001       case DT_RELA:
3002         DL_ERR("unsupported DT_RELA in \"%s\"", get_realpath());
3003         return false;
3004 
3005       case DT_RELASZ:
3006         DL_ERR("unsupported DT_RELASZ in \"%s\"", get_realpath());
3007         return false;
3008 
3009 #endif
3010       case DT_RELR:
3011       case DT_ANDROID_RELR:
3012         relr_ = reinterpret_cast<ElfW(Relr)*>(load_bias + d->d_un.d_ptr);
3013         break;
3014 
3015       case DT_RELRSZ:
3016       case DT_ANDROID_RELRSZ:
3017         relr_count_ = d->d_un.d_val / sizeof(ElfW(Relr));
3018         break;
3019 
3020       case DT_RELRENT:
3021       case DT_ANDROID_RELRENT:
3022         if (d->d_un.d_val != sizeof(ElfW(Relr))) {
3023           DL_ERR("invalid DT_RELRENT: %zd", static_cast<size_t>(d->d_un.d_val));
3024           return false;
3025         }
3026         break;
3027 
3028       // Ignored (see DT_RELCOUNT comments for details).
3029       // There is no DT_RELRCOUNT specifically because it would only be ignored.
3030       case DT_ANDROID_RELRCOUNT:
3031         break;
3032 
3033       case DT_INIT:
3034         init_func_ = reinterpret_cast<linker_ctor_function_t>(load_bias + d->d_un.d_ptr);
3035         DEBUG("%s constructors (DT_INIT) found at %p", get_realpath(), init_func_);
3036         break;
3037 
3038       case DT_FINI:
3039         fini_func_ = reinterpret_cast<linker_dtor_function_t>(load_bias + d->d_un.d_ptr);
3040         DEBUG("%s destructors (DT_FINI) found at %p", get_realpath(), fini_func_);
3041         break;
3042 
3043       case DT_INIT_ARRAY:
3044         init_array_ = reinterpret_cast<linker_ctor_function_t*>(load_bias + d->d_un.d_ptr);
3045         DEBUG("%s constructors (DT_INIT_ARRAY) found at %p", get_realpath(), init_array_);
3046         break;
3047 
3048       case DT_INIT_ARRAYSZ:
3049         init_array_count_ = static_cast<uint32_t>(d->d_un.d_val) / sizeof(ElfW(Addr));
3050         break;
3051 
3052       case DT_FINI_ARRAY:
3053         fini_array_ = reinterpret_cast<linker_dtor_function_t*>(load_bias + d->d_un.d_ptr);
3054         DEBUG("%s destructors (DT_FINI_ARRAY) found at %p", get_realpath(), fini_array_);
3055         break;
3056 
3057       case DT_FINI_ARRAYSZ:
3058         fini_array_count_ = static_cast<uint32_t>(d->d_un.d_val) / sizeof(ElfW(Addr));
3059         break;
3060 
3061       case DT_PREINIT_ARRAY:
3062         preinit_array_ = reinterpret_cast<linker_ctor_function_t*>(load_bias + d->d_un.d_ptr);
3063         DEBUG("%s constructors (DT_PREINIT_ARRAY) found at %p", get_realpath(), preinit_array_);
3064         break;
3065 
3066       case DT_PREINIT_ARRAYSZ:
3067         preinit_array_count_ = static_cast<uint32_t>(d->d_un.d_val) / sizeof(ElfW(Addr));
3068         break;
3069 
3070       case DT_TEXTREL:
3071 #if defined(__LP64__)
3072         DL_ERR("\"%s\" has text relocations", get_realpath());
3073         return false;
3074 #else
3075         has_text_relocations = true;
3076         break;
3077 #endif
3078 
3079       case DT_SYMBOLIC:
3080         has_DT_SYMBOLIC = true;
3081         break;
3082 
3083       case DT_NEEDED:
3084         ++needed_count;
3085         break;
3086 
3087       case DT_FLAGS:
3088         if (d->d_un.d_val & DF_TEXTREL) {
3089 #if defined(__LP64__)
3090           DL_ERR("\"%s\" has text relocations", get_realpath());
3091           return false;
3092 #else
3093           has_text_relocations = true;
3094 #endif
3095         }
3096         if (d->d_un.d_val & DF_SYMBOLIC) {
3097           has_DT_SYMBOLIC = true;
3098         }
3099         break;
3100 
3101       case DT_FLAGS_1:
3102         set_dt_flags_1(d->d_un.d_val);
3103 
3104         if ((d->d_un.d_val & ~SUPPORTED_DT_FLAGS_1) != 0) {
3105           DL_WARN("Warning: \"%s\" has unsupported flags DT_FLAGS_1=%p "
3106                   "(ignoring unsupported flags)",
3107                   get_realpath(), reinterpret_cast<void*>(d->d_un.d_val));
3108         }
3109         break;
3110 
3111       // Ignored: "Its use has been superseded by the DF_BIND_NOW flag"
3112       case DT_BIND_NOW:
3113         break;
3114 
3115       case DT_VERSYM:
3116         versym_ = reinterpret_cast<ElfW(Versym)*>(load_bias + d->d_un.d_ptr);
3117         break;
3118 
3119       case DT_VERDEF:
3120         verdef_ptr_ = load_bias + d->d_un.d_ptr;
3121         break;
3122       case DT_VERDEFNUM:
3123         verdef_cnt_ = d->d_un.d_val;
3124         break;
3125 
3126       case DT_VERNEED:
3127         verneed_ptr_ = load_bias + d->d_un.d_ptr;
3128         break;
3129 
3130       case DT_VERNEEDNUM:
3131         verneed_cnt_ = d->d_un.d_val;
3132         break;
3133 
3134       case DT_RUNPATH:
3135         // this is parsed after we have strtab initialized (see below).
3136         break;
3137 
3138       case DT_TLSDESC_GOT:
3139       case DT_TLSDESC_PLT:
3140         // These DT entries are used for lazy TLSDESC relocations. Bionic
3141         // resolves everything eagerly, so these can be ignored.
3142         break;
3143 
3144       default:
3145         if (!relocating_linker) {
3146           const char* tag_name;
3147           if (d->d_tag == DT_RPATH) {
3148             tag_name = "DT_RPATH";
3149           } else if (d->d_tag == DT_ENCODING) {
3150             tag_name = "DT_ENCODING";
3151           } else if (d->d_tag >= DT_LOOS && d->d_tag <= DT_HIOS) {
3152             tag_name = "unknown OS-specific";
3153           } else if (d->d_tag >= DT_LOPROC && d->d_tag <= DT_HIPROC) {
3154             tag_name = "unknown processor-specific";
3155           } else {
3156             tag_name = "unknown";
3157           }
3158           DL_WARN("Warning: \"%s\" unused DT entry: %s (type %p arg %p) (ignoring)",
3159                   get_realpath(),
3160                   tag_name,
3161                   reinterpret_cast<void*>(d->d_tag),
3162                   reinterpret_cast<void*>(d->d_un.d_val));
3163         }
3164         break;
3165     }
3166   }
3167 
3168   DEBUG("si->base = %p, si->strtab = %p, si->symtab = %p",
3169         reinterpret_cast<void*>(base), strtab_, symtab_);
3170 
3171   // Validity checks.
3172   if (relocating_linker && needed_count != 0) {
3173     DL_ERR("linker cannot have DT_NEEDED dependencies on other libraries");
3174     return false;
3175   }
3176   if (nbucket_ == 0 && gnu_nbucket_ == 0) {
3177     DL_ERR("empty/missing DT_HASH/DT_GNU_HASH in \"%s\" "
3178         "(new hash type from the future?)", get_realpath());
3179     return false;
3180   }
3181   if (strtab_ == nullptr) {
3182     DL_ERR("empty/missing DT_STRTAB in \"%s\"", get_realpath());
3183     return false;
3184   }
3185   if (symtab_ == nullptr) {
3186     DL_ERR("empty/missing DT_SYMTAB in \"%s\"", get_realpath());
3187     return false;
3188   }
3189 
3190   // second pass - parse entries relying on strtab
3191   for (ElfW(Dyn)* d = dynamic; d->d_tag != DT_NULL; ++d) {
3192     switch (d->d_tag) {
3193       case DT_SONAME:
3194         set_soname(get_string(d->d_un.d_val));
3195         break;
3196       case DT_RUNPATH:
3197         set_dt_runpath(get_string(d->d_un.d_val));
3198         break;
3199     }
3200   }
3201 
3202   // Before M release linker was using basename in place of soname.
3203   // In the case when dt_soname is absent some apps stop working
3204   // because they can't find dt_needed library by soname.
3205   // This workaround should keep them working. (Applies only
3206   // for apps targeting sdk version < M.) Make an exception for
3207   // the main executable and linker; they do not need to have dt_soname.
3208   // TODO: >= O the linker doesn't need this workaround.
3209   if (soname_ == nullptr &&
3210       this != solist_get_somain() &&
3211       (flags_ & FLAG_LINKER) == 0 &&
3212       get_application_target_sdk_version() < 23) {
3213     soname_ = basename(realpath_.c_str());
3214     DL_WARN_documented_change(23,
3215                               "missing-soname-enforced-for-api-level-23",
3216                               "\"%s\" has no DT_SONAME (will use %s instead)",
3217                               get_realpath(), soname_);
3218 
3219     // Don't call add_dlwarning because a missing DT_SONAME isn't important enough to show in the UI
3220   }
3221 
3222   // Validate each library's verdef section once, so we don't have to validate
3223   // it each time we look up a symbol with a version.
3224   if (!validate_verdef_section(this)) return false;
3225 
3226   flags_ |= FLAG_PRELINKED;
3227   return true;
3228 }
3229 
link_image(const SymbolLookupList & lookup_list,soinfo * local_group_root,const android_dlextinfo * extinfo,size_t * relro_fd_offset)3230 bool soinfo::link_image(const SymbolLookupList& lookup_list, soinfo* local_group_root,
3231                         const android_dlextinfo* extinfo, size_t* relro_fd_offset) {
3232   if (is_image_linked()) {
3233     // already linked.
3234     return true;
3235   }
3236 
3237   if (g_is_ldd && !is_main_executable()) {
3238     async_safe_format_fd(STDOUT_FILENO, "\t%s => %s (%p)\n", get_soname(),
3239                          get_realpath(), reinterpret_cast<void*>(base));
3240   }
3241 
3242   local_group_root_ = local_group_root;
3243   if (local_group_root_ == nullptr) {
3244     local_group_root_ = this;
3245   }
3246 
3247   if ((flags_ & FLAG_LINKER) == 0 && local_group_root_ == this) {
3248     target_sdk_version_ = get_application_target_sdk_version();
3249   }
3250 
3251 #if !defined(__LP64__)
3252   if (has_text_relocations) {
3253     // Fail if app is targeting M or above.
3254     int app_target_api_level = get_application_target_sdk_version();
3255     if (app_target_api_level >= 23) {
3256       DL_ERR_AND_LOG("\"%s\" has text relocations (%s#Text-Relocations-Enforced-for-API-level-23)",
3257                      get_realpath(), kBionicChangesUrl);
3258       return false;
3259     }
3260     // Make segments writable to allow text relocations to work properly. We will later call
3261     // phdr_table_protect_segments() after all of them are applied.
3262     DL_WARN_documented_change(23,
3263                               "Text-Relocations-Enforced-for-API-level-23",
3264                               "\"%s\" has text relocations",
3265                               get_realpath());
3266     add_dlwarning(get_realpath(), "text relocations");
3267     if (phdr_table_unprotect_segments(phdr, phnum, load_bias) < 0) {
3268       DL_ERR("can't unprotect loadable segments for \"%s\": %s", get_realpath(), strerror(errno));
3269       return false;
3270     }
3271   }
3272 #endif
3273 
3274   if (!relocate(lookup_list)) {
3275     return false;
3276   }
3277 
3278   DEBUG("[ finished linking %s ]", get_realpath());
3279 
3280 #if !defined(__LP64__)
3281   if (has_text_relocations) {
3282     // All relocations are done, we can protect our segments back to read-only.
3283     if (phdr_table_protect_segments(phdr, phnum, load_bias) < 0) {
3284       DL_ERR("can't protect segments for \"%s\": %s",
3285              get_realpath(), strerror(errno));
3286       return false;
3287     }
3288   }
3289 #endif
3290 
3291   // We can also turn on GNU RELRO protection if we're not linking the dynamic linker
3292   // itself --- it can't make system calls yet, and will have to call protect_relro later.
3293   if (!is_linker() && !protect_relro()) {
3294     return false;
3295   }
3296 
3297   /* Handle serializing/sharing the RELRO segment */
3298   if (extinfo && (extinfo->flags & ANDROID_DLEXT_WRITE_RELRO)) {
3299     if (phdr_table_serialize_gnu_relro(phdr, phnum, load_bias,
3300                                        extinfo->relro_fd, relro_fd_offset) < 0) {
3301       DL_ERR("failed serializing GNU RELRO section for \"%s\": %s",
3302              get_realpath(), strerror(errno));
3303       return false;
3304     }
3305   } else if (extinfo && (extinfo->flags & ANDROID_DLEXT_USE_RELRO)) {
3306     if (phdr_table_map_gnu_relro(phdr, phnum, load_bias,
3307                                  extinfo->relro_fd, relro_fd_offset) < 0) {
3308       DL_ERR("failed mapping GNU RELRO section for \"%s\": %s",
3309              get_realpath(), strerror(errno));
3310       return false;
3311     }
3312   }
3313 
3314   ++g_module_load_counter;
3315   notify_gdb_of_load(this);
3316   set_image_linked();
3317   return true;
3318 }
3319 
protect_relro()3320 bool soinfo::protect_relro() {
3321   if (phdr_table_protect_gnu_relro(phdr, phnum, load_bias) < 0) {
3322     DL_ERR("can't enable GNU RELRO protection for \"%s\": %s",
3323            get_realpath(), strerror(errno));
3324     return false;
3325   }
3326   return true;
3327 }
3328 
init_default_namespace_no_config(bool is_asan)3329 static std::vector<android_namespace_t*> init_default_namespace_no_config(bool is_asan) {
3330   g_default_namespace.set_isolated(false);
3331   auto default_ld_paths = is_asan ? kAsanDefaultLdPaths : kDefaultLdPaths;
3332 
3333   char real_path[PATH_MAX];
3334   std::vector<std::string> ld_default_paths;
3335   for (size_t i = 0; default_ld_paths[i] != nullptr; ++i) {
3336     if (realpath(default_ld_paths[i], real_path) != nullptr) {
3337       ld_default_paths.push_back(real_path);
3338     } else {
3339       ld_default_paths.push_back(default_ld_paths[i]);
3340     }
3341   }
3342 
3343   g_default_namespace.set_default_library_paths(std::move(ld_default_paths));
3344 
3345   std::vector<android_namespace_t*> namespaces;
3346   namespaces.push_back(&g_default_namespace);
3347   return namespaces;
3348 }
3349 
3350 // Given an `executable_path` starting with "/apex/<name>/bin/, return
3351 // "/linkerconfig/<name>/ld.config.txt" (or "/apex/<name>/etc/ld.config.txt", if
3352 // the former does not exist).
get_ld_config_file_apex_path(const char * executable_path)3353 static std::string get_ld_config_file_apex_path(const char* executable_path) {
3354   std::vector<std::string> paths = android::base::Split(executable_path, "/");
3355   if (paths.size() >= 5 && paths[1] == "apex" && paths[3] == "bin") {
3356     // Check auto-generated ld.config.txt first
3357     std::string generated_apex_config = "/linkerconfig/" + paths[2] + "/ld.config.txt";
3358     if (file_exists(generated_apex_config.c_str())) {
3359       return generated_apex_config;
3360     }
3361 
3362     return std::string("/apex/") + paths[2] + "/etc/ld.config.txt";
3363   }
3364   return "";
3365 }
3366 
get_ld_config_file_vndk_path()3367 static std::string get_ld_config_file_vndk_path() {
3368   if (android::base::GetBoolProperty("ro.vndk.lite", false)) {
3369     return kLdConfigVndkLiteFilePath;
3370   }
3371 
3372   std::string ld_config_file_vndk = kLdConfigFilePath;
3373   size_t insert_pos = ld_config_file_vndk.find_last_of('.');
3374   if (insert_pos == std::string::npos) {
3375     insert_pos = ld_config_file_vndk.length();
3376   }
3377   ld_config_file_vndk.insert(insert_pos, Config::get_vndk_version_string('.'));
3378   return ld_config_file_vndk;
3379 }
3380 
is_linker_config_expected(const char * executable_path)3381 bool is_linker_config_expected(const char* executable_path) {
3382   // Do not raise message from a host environment which is expected to miss generated linker
3383   // configuration.
3384 #if !defined(__ANDROID__)
3385   return false;
3386 #endif
3387 
3388   if (strcmp(executable_path, "/system/bin/init") == 0) {
3389     // Generated linker configuration can be missed from processes executed
3390     // with init binary
3391     return false;
3392   }
3393 
3394   return true;
3395 }
3396 
get_ld_config_file_path(const char * executable_path)3397 static std::string get_ld_config_file_path(const char* executable_path) {
3398 #ifdef USE_LD_CONFIG_FILE
3399   // This is a debugging/testing only feature. Must not be available on
3400   // production builds.
3401   const char* ld_config_file_env = getenv("LD_CONFIG_FILE");
3402   if (ld_config_file_env != nullptr && file_exists(ld_config_file_env)) {
3403     return ld_config_file_env;
3404   }
3405 #endif
3406 
3407   std::string path = get_ld_config_file_apex_path(executable_path);
3408   if (!path.empty()) {
3409     if (file_exists(path.c_str())) {
3410       return path;
3411     }
3412     DL_WARN("Warning: couldn't read config file \"%s\" for \"%s\"",
3413             path.c_str(), executable_path);
3414   }
3415 
3416   path = kLdConfigArchFilePath;
3417   if (file_exists(path.c_str())) {
3418     return path;
3419   }
3420 
3421   if (file_exists(kLdGeneratedConfigFilePath)) {
3422     return kLdGeneratedConfigFilePath;
3423   }
3424 
3425   if (is_linker_config_expected(executable_path)) {
3426     DL_WARN("Warning: failed to find generated linker configuration from \"%s\"",
3427             kLdGeneratedConfigFilePath);
3428   }
3429 
3430   path = get_ld_config_file_vndk_path();
3431   if (file_exists(path.c_str())) {
3432     return path;
3433   }
3434 
3435   return kLdConfigFilePath;
3436 }
3437 
init_default_namespaces(const char * executable_path)3438 std::vector<android_namespace_t*> init_default_namespaces(const char* executable_path) {
3439   g_default_namespace.set_name("(default)");
3440 
3441   soinfo* somain = solist_get_somain();
3442 
3443   const char *interp = phdr_table_get_interpreter_name(somain->phdr, somain->phnum,
3444                                                        somain->load_bias);
3445   const char* bname = (interp != nullptr) ? basename(interp) : nullptr;
3446 
3447   g_is_asan = bname != nullptr &&
3448               (strcmp(bname, "linker_asan") == 0 ||
3449                strcmp(bname, "linker_asan64") == 0);
3450 
3451   const Config* config = nullptr;
3452 
3453   std::string error_msg;
3454 
3455   std::string ld_config_file_path = get_ld_config_file_path(executable_path);
3456 
3457   INFO("[ Reading linker config \"%s\" ]", ld_config_file_path.c_str());
3458   if (!Config::read_binary_config(ld_config_file_path.c_str(),
3459                                   executable_path,
3460                                   g_is_asan,
3461                                   &config,
3462                                   &error_msg)) {
3463     if (!error_msg.empty()) {
3464       DL_WARN("Warning: couldn't read \"%s\" for \"%s\" (using default configuration instead): %s",
3465               ld_config_file_path.c_str(),
3466               executable_path,
3467               error_msg.c_str());
3468     }
3469     config = nullptr;
3470   }
3471 
3472   if (config == nullptr) {
3473     return init_default_namespace_no_config(g_is_asan);
3474   }
3475 
3476   const auto& namespace_configs = config->namespace_configs();
3477   std::unordered_map<std::string, android_namespace_t*> namespaces;
3478 
3479   // 1. Initialize default namespace
3480   const NamespaceConfig* default_ns_config = config->default_namespace_config();
3481 
3482   g_default_namespace.set_isolated(default_ns_config->isolated());
3483   g_default_namespace.set_default_library_paths(default_ns_config->search_paths());
3484   g_default_namespace.set_permitted_paths(default_ns_config->permitted_paths());
3485 
3486   namespaces[default_ns_config->name()] = &g_default_namespace;
3487   if (default_ns_config->visible()) {
3488     g_exported_namespaces[default_ns_config->name()] = &g_default_namespace;
3489   }
3490 
3491   // 2. Initialize other namespaces
3492 
3493   for (auto& ns_config : namespace_configs) {
3494     if (namespaces.find(ns_config->name()) != namespaces.end()) {
3495       continue;
3496     }
3497 
3498     android_namespace_t* ns = new (g_namespace_allocator.alloc()) android_namespace_t();
3499     ns->set_name(ns_config->name());
3500     ns->set_isolated(ns_config->isolated());
3501     ns->set_default_library_paths(ns_config->search_paths());
3502     ns->set_permitted_paths(ns_config->permitted_paths());
3503     ns->set_whitelisted_libs(ns_config->whitelisted_libs());
3504 
3505     namespaces[ns_config->name()] = ns;
3506     if (ns_config->visible()) {
3507       g_exported_namespaces[ns_config->name()] = ns;
3508     }
3509   }
3510 
3511   // 3. Establish links between namespaces
3512   for (auto& ns_config : namespace_configs) {
3513     auto it_from = namespaces.find(ns_config->name());
3514     CHECK(it_from != namespaces.end());
3515     android_namespace_t* namespace_from = it_from->second;
3516     for (const NamespaceLinkConfig& ns_link : ns_config->links()) {
3517       auto it_to = namespaces.find(ns_link.ns_name());
3518       CHECK(it_to != namespaces.end());
3519       android_namespace_t* namespace_to = it_to->second;
3520       if (ns_link.allow_all_shared_libs()) {
3521         link_namespaces_all_libs(namespace_from, namespace_to);
3522       } else {
3523         link_namespaces(namespace_from, namespace_to, ns_link.shared_libs().c_str());
3524       }
3525     }
3526   }
3527   // we can no longer rely on the fact that libdl.so is part of default namespace
3528   // this is why we want to add ld-android.so to all namespaces from ld.config.txt
3529   soinfo* ld_android_so = solist_get_head();
3530 
3531   // we also need vdso to be available for all namespaces (if present)
3532   soinfo* vdso = solist_get_vdso();
3533   for (auto it : namespaces) {
3534     if (it.second != &g_default_namespace) {
3535       it.second->add_soinfo(ld_android_so);
3536       if (vdso != nullptr) {
3537         it.second->add_soinfo(vdso);
3538       }
3539       // somain and ld_preloads are added to these namespaces after LD_PRELOAD libs are linked
3540     }
3541   }
3542 
3543   set_application_target_sdk_version(config->target_sdk_version());
3544 
3545   std::vector<android_namespace_t*> created_namespaces;
3546   created_namespaces.reserve(namespaces.size());
3547   for (const auto& kv : namespaces) {
3548     created_namespaces.push_back(kv.second);
3549   }
3550   return created_namespaces;
3551 }
3552 
3553 // This function finds a namespace exported in ld.config.txt by its name.
3554 // A namespace can be exported by setting .visible property to true.
get_exported_namespace(const char * name)3555 android_namespace_t* get_exported_namespace(const char* name) {
3556   if (name == nullptr) {
3557     return nullptr;
3558   }
3559   auto it = g_exported_namespaces.find(std::string(name));
3560   if (it == g_exported_namespaces.end()) {
3561     return nullptr;
3562   }
3563   return it->second;
3564 }
3565 
purge_unused_memory()3566 void purge_unused_memory() {
3567   // For now, we only purge the memory used by LoadTask because we know those
3568   // are temporary objects.
3569   //
3570   // Purging other LinkerBlockAllocator hardly yields much because they hold
3571   // information about namespaces and opened libraries, which are not freed
3572   // when the control leaves the linker.
3573   //
3574   // Purging BionicAllocator may give us a few dirty pages back, but those pages
3575   // would be already zeroed out, so they compress easily in ZRAM.  Therefore,
3576   // it is not worth munmap()'ing those pages.
3577   TypeBasedAllocator<LoadTask>::purge();
3578 }
3579