1 /*
2  * Copyright (C) 2007 The Android Open Source Project
3  *
4  * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *      http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16 
17 #include "linker.h"
18 #include "linker_dlwarning.h"
19 
20 #include <pthread.h>
21 #include <stdio.h>
22 #include <stdlib.h>
23 #include <string.h>
24 #include <android/api-level.h>
25 
26 #include <bionic/pthread_internal.h>
27 #include "private/bionic_tls.h"
28 #include "private/ScopedPthreadMutexLocker.h"
29 #include "private/ThreadLocalBuffer.h"
30 
31 /* This file hijacks the symbols stubbed out in libdl.so. */
32 
33 static pthread_mutex_t g_dl_mutex = PTHREAD_RECURSIVE_MUTEX_INITIALIZER_NP;
34 
__bionic_set_dlerror(char * new_value)35 static const char* __bionic_set_dlerror(char* new_value) {
36   char** dlerror_slot = &reinterpret_cast<char**>(__get_tls())[TLS_SLOT_DLERROR];
37 
38   const char* old_value = *dlerror_slot;
39   *dlerror_slot = new_value;
40   return old_value;
41 }
42 
__bionic_format_dlerror(const char * msg,const char * detail)43 static void __bionic_format_dlerror(const char* msg, const char* detail) {
44   char* buffer = __get_thread()->dlerror_buffer;
45   strlcpy(buffer, msg, __BIONIC_DLERROR_BUFFER_SIZE);
46   if (detail != nullptr) {
47     strlcat(buffer, ": ", __BIONIC_DLERROR_BUFFER_SIZE);
48     strlcat(buffer, detail, __BIONIC_DLERROR_BUFFER_SIZE);
49   }
50 
51   __bionic_set_dlerror(buffer);
52 }
53 
dlerror()54 const char* dlerror() {
55   const char* old_value = __bionic_set_dlerror(nullptr);
56   return old_value;
57 }
58 
android_get_LD_LIBRARY_PATH(char * buffer,size_t buffer_size)59 void android_get_LD_LIBRARY_PATH(char* buffer, size_t buffer_size) {
60   ScopedPthreadMutexLocker locker(&g_dl_mutex);
61   do_android_get_LD_LIBRARY_PATH(buffer, buffer_size);
62 }
63 
android_update_LD_LIBRARY_PATH(const char * ld_library_path)64 void android_update_LD_LIBRARY_PATH(const char* ld_library_path) {
65   ScopedPthreadMutexLocker locker(&g_dl_mutex);
66   do_android_update_LD_LIBRARY_PATH(ld_library_path);
67 }
68 
dlopen_ext(const char * filename,int flags,const android_dlextinfo * extinfo,void * caller_addr)69 static void* dlopen_ext(const char* filename, int flags,
70                         const android_dlextinfo* extinfo, void* caller_addr) {
71   ScopedPthreadMutexLocker locker(&g_dl_mutex);
72   void* result = do_dlopen(filename, flags, extinfo, caller_addr);
73   if (result == nullptr) {
74     __bionic_format_dlerror("dlopen failed", linker_get_error_buffer());
75     return nullptr;
76   }
77   return result;
78 }
79 
android_dlopen_ext(const char * filename,int flags,const android_dlextinfo * extinfo)80 void* android_dlopen_ext(const char* filename, int flags, const android_dlextinfo* extinfo) {
81   void* caller_addr = __builtin_return_address(0);
82   return dlopen_ext(filename, flags, extinfo, caller_addr);
83 }
84 
dlopen(const char * filename,int flags)85 void* dlopen(const char* filename, int flags) {
86   void* caller_addr = __builtin_return_address(0);
87   return dlopen_ext(filename, flags, nullptr, caller_addr);
88 }
89 
dlsym_impl(void * handle,const char * symbol,const char * version,void * caller_addr)90 void* dlsym_impl(void* handle, const char* symbol, const char* version, void* caller_addr) {
91   ScopedPthreadMutexLocker locker(&g_dl_mutex);
92   void* result;
93   if (!do_dlsym(handle, symbol, version, caller_addr, &result)) {
94     __bionic_format_dlerror(linker_get_error_buffer(), nullptr);
95     return nullptr;
96   }
97 
98   return result;
99 }
100 
dlsym(void * handle,const char * symbol)101 void* dlsym(void* handle, const char* symbol) {
102   void* caller_addr = __builtin_return_address(0);
103   return dlsym_impl(handle, symbol, nullptr, caller_addr);
104 }
105 
dlvsym(void * handle,const char * symbol,const char * version)106 void* dlvsym(void* handle, const char* symbol, const char* version) {
107   void* caller_addr = __builtin_return_address(0);
108   return dlsym_impl(handle, symbol, version, caller_addr);
109 }
110 
dladdr(const void * addr,Dl_info * info)111 int dladdr(const void* addr, Dl_info* info) {
112   ScopedPthreadMutexLocker locker(&g_dl_mutex);
113   return do_dladdr(addr, info);
114 }
115 
dlclose(void * handle)116 int dlclose(void* handle) {
117   ScopedPthreadMutexLocker locker(&g_dl_mutex);
118   int result = do_dlclose(handle);
119   if (result != 0) {
120     __bionic_format_dlerror("dlclose failed", linker_get_error_buffer());
121   }
122   return result;
123 }
124 
dl_iterate_phdr(int (* cb)(dl_phdr_info * info,size_t size,void * data),void * data)125 int dl_iterate_phdr(int (*cb)(dl_phdr_info* info, size_t size, void* data), void* data) {
126   ScopedPthreadMutexLocker locker(&g_dl_mutex);
127   return do_dl_iterate_phdr(cb, data);
128 }
129 
android_set_application_target_sdk_version(uint32_t target)130 void android_set_application_target_sdk_version(uint32_t target) {
131   // lock to avoid modification in the middle of dlopen.
132   ScopedPthreadMutexLocker locker(&g_dl_mutex);
133   set_application_target_sdk_version(target);
134 }
135 
android_get_application_target_sdk_version()136 uint32_t android_get_application_target_sdk_version() {
137   return get_application_target_sdk_version();
138 }
139 
android_dlwarning(void * obj,void (* f)(void *,const char *))140 void android_dlwarning(void* obj, void (*f)(void*, const char*)) {
141   ScopedPthreadMutexLocker locker(&g_dl_mutex);
142   get_dlwarning(obj, f);
143 }
144 
android_init_namespaces(const char * public_ns_sonames,const char * anon_ns_library_path)145 bool android_init_namespaces(const char* public_ns_sonames,
146                              const char* anon_ns_library_path) {
147   ScopedPthreadMutexLocker locker(&g_dl_mutex);
148   bool success = init_namespaces(public_ns_sonames, anon_ns_library_path);
149   if (!success) {
150     __bionic_format_dlerror("android_init_namespaces failed", linker_get_error_buffer());
151   }
152 
153   return success;
154 }
155 
android_create_namespace(const char * name,const char * ld_library_path,const char * default_library_path,uint64_t type,const char * permitted_when_isolated_path,android_namespace_t * parent_namespace)156 android_namespace_t* android_create_namespace(const char* name,
157                                               const char* ld_library_path,
158                                               const char* default_library_path,
159                                               uint64_t type,
160                                               const char* permitted_when_isolated_path,
161                                               android_namespace_t* parent_namespace) {
162   void* caller_addr = __builtin_return_address(0);
163   ScopedPthreadMutexLocker locker(&g_dl_mutex);
164 
165   android_namespace_t* result = create_namespace(caller_addr,
166                                                  name,
167                                                  ld_library_path,
168                                                  default_library_path,
169                                                  type,
170                                                  permitted_when_isolated_path,
171                                                  parent_namespace);
172 
173   if (result == nullptr) {
174     __bionic_format_dlerror("android_create_namespace failed", linker_get_error_buffer());
175   }
176 
177   return result;
178 }
179 
180 // name_offset: starting index of the name in libdl_info.strtab
181 #define ELF32_SYM_INITIALIZER(name_offset, value, shndx) \
182     { name_offset, \
183       reinterpret_cast<Elf32_Addr>(value), \
184       /* st_size */ 0, \
185       (shndx == 0) ? 0 : (STB_GLOBAL << 4), \
186       /* st_other */ 0, \
187       shndx, \
188     }
189 
190 #define ELF64_SYM_INITIALIZER(name_offset, value, shndx) \
191     { name_offset, \
192       (shndx == 0) ? 0 : (STB_GLOBAL << 4), \
193       /* st_other */ 0, \
194       shndx, \
195       reinterpret_cast<Elf64_Addr>(value), \
196       /* st_size */ 0, \
197     }
198 
199 static const char ANDROID_LIBDL_STRTAB[] =
200   // 0000000 00011111 111112 22222222 2333333 3333444444444455555555556666666 6667777777777888888888899999 99999
201   // 0123456 78901234 567890 12345678 9012345 6789012345678901234567890123456 7890123456789012345678901234 56789
202     "dlopen\0dlclose\0dlsym\0dlerror\0dladdr\0android_update_LD_LIBRARY_PATH\0android_get_LD_LIBRARY_PATH\0dl_it"
203   // 00000000001 1111111112222222222 3333333333444444444455555555556666666666777 777777788888888889999999999
204   // 01234567890 1234567890123456789 0123456789012345678901234567890123456789012 345678901234567890123456789
205     "erate_phdr\0android_dlopen_ext\0android_set_application_target_sdk_version\0android_get_application_tar"
206   // 0000000000111111 111122222222223333333333 4444444444555555555566666 6666677 777777778888888888
207   // 0123456789012345 678901234567890123456789 0123456789012345678901234 5678901 234567890123456789
208     "get_sdk_version\0android_init_namespaces\0android_create_namespace\0dlvsym\0android_dlwarning\0"
209 #if defined(__arm__)
210   // 290
211     "dl_unwind_find_exidx\0"
212 #endif
213     ;
214 
215 static ElfW(Sym) g_libdl_symtab[] = {
216   // Total length of libdl_info.strtab, including trailing 0.
217   // This is actually the STH_UNDEF entry. Technically, it's
218   // supposed to have st_name == 0, but instead, it points to an index
219   // in the strtab with a \0 to make iterating through the symtab easier.
220   ELFW(SYM_INITIALIZER)(sizeof(ANDROID_LIBDL_STRTAB) - 1, nullptr, 0),
221   ELFW(SYM_INITIALIZER)(  0, &dlopen, 1),
222   ELFW(SYM_INITIALIZER)(  7, &dlclose, 1),
223   ELFW(SYM_INITIALIZER)( 15, &dlsym, 1),
224   ELFW(SYM_INITIALIZER)( 21, &dlerror, 1),
225   ELFW(SYM_INITIALIZER)( 29, &dladdr, 1),
226   ELFW(SYM_INITIALIZER)( 36, &android_update_LD_LIBRARY_PATH, 1),
227   ELFW(SYM_INITIALIZER)( 67, &android_get_LD_LIBRARY_PATH, 1),
228   ELFW(SYM_INITIALIZER)( 95, &dl_iterate_phdr, 1),
229   ELFW(SYM_INITIALIZER)(111, &android_dlopen_ext, 1),
230   ELFW(SYM_INITIALIZER)(130, &android_set_application_target_sdk_version, 1),
231   ELFW(SYM_INITIALIZER)(173, &android_get_application_target_sdk_version, 1),
232   ELFW(SYM_INITIALIZER)(216, &android_init_namespaces, 1),
233   ELFW(SYM_INITIALIZER)(240, &android_create_namespace, 1),
234   ELFW(SYM_INITIALIZER)(265, &dlvsym, 1),
235   ELFW(SYM_INITIALIZER)(272, &android_dlwarning, 1),
236 #if defined(__arm__)
237   ELFW(SYM_INITIALIZER)(290, &dl_unwind_find_exidx, 1),
238 #endif
239 };
240 
241 // Fake out a hash table with a single bucket.
242 //
243 // A search of the hash table will look through g_libdl_symtab starting with index 1, then
244 // use g_libdl_chains to find the next index to look at. g_libdl_chains should be set up to
245 // walk through every element in g_libdl_symtab, and then end with 0 (sentinel value).
246 //
247 // That is, g_libdl_chains should look like { 0, 2, 3, ... N, 0 } where N is the number
248 // of actual symbols, or nelems(g_libdl_symtab)-1 (since the first element of g_libdl_symtab is not
249 // a real symbol). (See soinfo_elf_lookup().)
250 //
251 // Note that adding any new symbols here requires stubbing them out in libdl.
252 static unsigned g_libdl_buckets[1] = { 1 };
253 #if defined(__arm__)
254 static unsigned g_libdl_chains[] = { 0, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 0 };
255 #else
256 static unsigned g_libdl_chains[] = { 0, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 0 };
257 #endif
258 
259 static uint8_t __libdl_info_buf[sizeof(soinfo)] __attribute__((aligned(8)));
260 static soinfo* __libdl_info = nullptr;
261 
262 extern android_namespace_t g_default_namespace;
263 
264 // This is used by the dynamic linker. Every process gets these symbols for free.
get_libdl_info()265 soinfo* get_libdl_info() {
266   if (__libdl_info == nullptr) {
267     __libdl_info = new (__libdl_info_buf) soinfo(&g_default_namespace, "libdl.so", nullptr, 0, RTLD_GLOBAL);
268     __libdl_info->flags_ |= FLAG_LINKED;
269     __libdl_info->strtab_ = ANDROID_LIBDL_STRTAB;
270     __libdl_info->symtab_ = g_libdl_symtab;
271     __libdl_info->nbucket_ = sizeof(g_libdl_buckets)/sizeof(unsigned);
272     __libdl_info->nchain_ = sizeof(g_libdl_chains)/sizeof(unsigned);
273     __libdl_info->bucket_ = g_libdl_buckets;
274     __libdl_info->chain_ = g_libdl_chains;
275     __libdl_info->ref_count_ = 1;
276     __libdl_info->strtab_size_ = sizeof(ANDROID_LIBDL_STRTAB);
277     __libdl_info->local_group_root_ = __libdl_info;
278     __libdl_info->soname_ = "libdl.so";
279     __libdl_info->target_sdk_version_ = __ANDROID_API__;
280     __libdl_info->generate_handle();
281 #if defined(__work_around_b_24465209__)
282     strlcpy(__libdl_info->old_name_, __libdl_info->soname_, sizeof(__libdl_info->old_name_));
283 #endif
284   }
285 
286   return __libdl_info;
287 }
288