94084c
commit c1cb2deeca1a85c6fc5bd41b90816d48a95bc434
94084c
Author: Florian Weimer <fweimer@redhat.com>
94084c
Date:   Sun Dec 5 11:28:34 2021 +0100
94084c
94084c
    elf: execve statically linked programs instead of crashing [BZ #28648]
94084c
    
94084c
    Programs without dynamic dependencies and without a program
94084c
    interpreter are now run via execve.
94084c
    
94084c
    Previously, the dynamic linker either crashed while attempting to
94084c
    read a non-existing dynamic segment (looking for DT_AUDIT/DT_DEPAUDIT
94084c
    data), or the self-relocated in the static PIE executable crashed
94084c
    because the outer dynamic linker had already applied RELRO protection.
94084c
    
94084c
    <dl-execve.h> is needed because execve is not available in the
94084c
    dynamic loader on Hurd.
94084c
    
94084c
    Reviewed-by: H.J. Lu <hjl.tools@gmail.com>
94084c
94084c
Conflicts:
94084c
	elf/Makefile
94084c
	  (usual test differences)
94084c
	elf/rtld.c
94084c
	  (missing ld.so self-relocation cleanup downstream)
94084c
94084c
diff --git a/elf/Makefile b/elf/Makefile
94084c
index 118d579c42c38110..7696aa1324919a80 100644
94084c
--- a/elf/Makefile
94084c
+++ b/elf/Makefile
94084c
@@ -224,7 +224,8 @@ tests += restest1 preloadtest loadfail multiload origtest resolvfail \
94084c
 	 tst-tls-ie tst-tls-ie-dlmopen argv0test \
94084c
 	 tst-glibc-hwcaps tst-glibc-hwcaps-prepend tst-glibc-hwcaps-mask \
94084c
 	 tst-tls20 tst-tls21 tst-dlmopen-dlerror tst-dlmopen-gethostbyname \
94084c
-	 tst-dl-is_dso tst-ro-dynamic
94084c
+	 tst-dl-is_dso tst-ro-dynamic \
94084c
+	 tst-rtld-run-static \
94084c
 #	 reldep9
94084c
 tests-internal += loadtest unload unload2 circleload1 \
94084c
 	 neededtest neededtest2 neededtest3 neededtest4 \
94084c
@@ -1914,3 +1915,5 @@ $(objpfx)tst-ro-dynamic-mod.so: $(objpfx)tst-ro-dynamic-mod.os \
94084c
 	$(LINK.o) -nostdlib -nostartfiles -shared -o $@ \
94084c
 		-Wl,--script=tst-ro-dynamic-mod.map \
94084c
 		$(objpfx)tst-ro-dynamic-mod.os
94084c
+
94084c
+$(objpfx)tst-rtld-run-static.out: $(objpfx)/ldconfig
94084c
diff --git a/elf/rtld.c b/elf/rtld.c
94084c
index d83ac1bdc40a6081..6b0d6107801b2f44 100644
94084c
--- a/elf/rtld.c
94084c
+++ b/elf/rtld.c
94084c
@@ -50,6 +50,7 @@
94084c
 #include <dl-main.h>
94084c
 #include <gnu/lib-names.h>
94084c
 #include <dl-tunables.h>
94084c
+#include <dl-execve.h>
94084c
 
94084c
 #include <assert.h>
94084c
 
94084c
@@ -1106,6 +1107,45 @@ load_audit_modules (struct link_map *main_map, struct audit_list *audit_list)
94084c
     }
94084c
 }
94084c
 
94084c
+/* Check if the executable is not actualy dynamically linked, and
94084c
+   invoke it directly in that case.  */
94084c
+static void
94084c
+rtld_chain_load (struct link_map *main_map, char *argv0)
94084c
+{
94084c
+  /* The dynamic loader run against itself.  */
94084c
+  const char *rtld_soname
94084c
+    = ((const char *) D_PTR (&GL(dl_rtld_map), l_info[DT_STRTAB])
94084c
+       + GL(dl_rtld_map).l_info[DT_SONAME]->d_un.d_val);
94084c
+  if (main_map->l_info[DT_SONAME] != NULL
94084c
+      && strcmp (rtld_soname,
94084c
+		 ((const char *) D_PTR (main_map, l_info[DT_STRTAB])
94084c
+		  + main_map->l_info[DT_SONAME]->d_un.d_val)) == 0)
94084c
+    _dl_fatal_printf ("%s: loader cannot load itself\n", rtld_soname);
94084c
+
94084c
+  /* With DT_NEEDED dependencies, the executable is dynamically
94084c
+     linked.  */
94084c
+  if (__glibc_unlikely (main_map->l_info[DT_NEEDED] != NULL))
94084c
+    return;
94084c
+
94084c
+  /* If the executable has program interpreter, it is dynamically
94084c
+     linked.  */
94084c
+  for (size_t i = 0; i < main_map->l_phnum; ++i)
94084c
+    if (main_map->l_phdr[i].p_type == PT_INTERP)
94084c
+      return;
94084c
+
94084c
+  const char *pathname = _dl_argv[0];
94084c
+  if (argv0 != NULL)
94084c
+    _dl_argv[0] = argv0;
94084c
+  int errcode = __rtld_execve (pathname, _dl_argv, _environ);
94084c
+  const char *errname = strerrorname_np (errcode);
94084c
+  if (errname != NULL)
94084c
+    _dl_fatal_printf("%s: cannot execute %s: %s\n",
94084c
+		     rtld_soname, pathname, errname);
94084c
+  else
94084c
+    _dl_fatal_printf("%s: cannot execute %s: %d\n",
94084c
+		     rtld_soname, pathname, errno);
94084c
+}
94084c
+
94084c
 static void
94084c
 dl_main (const ElfW(Phdr) *phdr,
94084c
 	 ElfW(Word) phnum,
94084c
@@ -1374,14 +1414,8 @@ dl_main (const ElfW(Phdr) *phdr,
94084c
       /* Now the map for the main executable is available.  */
94084c
       main_map = GL(dl_ns)[LM_ID_BASE]._ns_loaded;
94084c
 
94084c
-      if (__glibc_likely (state.mode == rtld_mode_normal)
94084c
-	  && GL(dl_rtld_map).l_info[DT_SONAME] != NULL
94084c
-	  && main_map->l_info[DT_SONAME] != NULL
94084c
-	  && strcmp ((const char *) D_PTR (&GL(dl_rtld_map), l_info[DT_STRTAB])
94084c
-		     + GL(dl_rtld_map).l_info[DT_SONAME]->d_un.d_val,
94084c
-		     (const char *) D_PTR (main_map, l_info[DT_STRTAB])
94084c
-		     + main_map->l_info[DT_SONAME]->d_un.d_val) == 0)
94084c
-	_dl_fatal_printf ("loader cannot load itself\n");
94084c
+      if (__glibc_likely (state.mode == rtld_mode_normal))
94084c
+	rtld_chain_load (main_map, argv0);
94084c
 
94084c
       phdr = main_map->l_phdr;
94084c
       phnum = main_map->l_phnum;
94084c
diff --git a/elf/tst-rtld-run-static.c b/elf/tst-rtld-run-static.c
94084c
new file mode 100644
94084c
index 0000000000000000..7281093504b675c4
94084c
--- /dev/null
94084c
+++ b/elf/tst-rtld-run-static.c
94084c
@@ -0,0 +1,62 @@
94084c
+/* Test running statically linked programs using ld.so.
94084c
+   Copyright (C) 2021 Free Software Foundation, Inc.
94084c
+   This file is part of the GNU C Library.
94084c
+
94084c
+   The GNU C Library is free software; you can redistribute it and/or
94084c
+   modify it under the terms of the GNU Lesser General Public
94084c
+   License as published by the Free Software Foundation; either
94084c
+   version 2.1 of the License, or (at your option) any later version.
94084c
+
94084c
+   The GNU C Library is distributed in the hope that it will be useful,
94084c
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
94084c
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
94084c
+   Lesser General Public License for more details.
94084c
+
94084c
+   You should have received a copy of the GNU Lesser General Public
94084c
+   License along with the GNU C Library; if not, see
94084c
+   <https://www.gnu.org/licenses/>.  */
94084c
+
94084c
+#include <support/check.h>
94084c
+#include <support/support.h>
94084c
+#include <support/capture_subprocess.h>
94084c
+#include <string.h>
94084c
+#include <stdlib.h>
94084c
+
94084c
+static int
94084c
+do_test (void)
94084c
+{
94084c
+  char *ldconfig_path = xasprintf ("%s/elf/ldconfig", support_objdir_root);
94084c
+
94084c
+  {
94084c
+    char *argv[] = { (char *) "ld.so", ldconfig_path, (char *) "--help", NULL };
94084c
+    struct support_capture_subprocess cap
94084c
+      = support_capture_subprogram (support_objdir_elf_ldso, argv);
94084c
+    support_capture_subprocess_check (&cap, "no --argv0", 0, sc_allow_stdout);
94084c
+    puts ("info: output without --argv0:");
94084c
+    puts (cap.out.buffer);
94084c
+    TEST_VERIFY (strstr (cap.out.buffer, "Usage: ldconfig [OPTION...]\n")
94084c
+                 == cap.out.buffer);
94084c
+    support_capture_subprocess_free (&cap);
94084c
+  }
94084c
+
94084c
+  {
94084c
+    char *argv[] =
94084c
+      {
94084c
+        (char *) "ld.so", (char *) "--argv0", (char *) "ldconfig-argv0",
94084c
+        ldconfig_path, (char *) "--help", NULL
94084c
+      };
94084c
+    struct support_capture_subprocess cap
94084c
+      = support_capture_subprogram (support_objdir_elf_ldso, argv);
94084c
+    support_capture_subprocess_check (&cap, "with --argv0", 0, sc_allow_stdout);
94084c
+    puts ("info: output with --argv0:");
94084c
+    puts (cap.out.buffer);
94084c
+    TEST_VERIFY (strstr (cap.out.buffer, "Usage: ldconfig-argv0 [OPTION...]\n")
94084c
+                 == cap.out.buffer);
94084c
+    support_capture_subprocess_free (&cap);
94084c
+  }
94084c
+
94084c
+  free (ldconfig_path);
94084c
+  return 0;
94084c
+}
94084c
+
94084c
+#include <support/test-driver.c>
94084c
diff --git a/sysdeps/generic/dl-execve.h b/sysdeps/generic/dl-execve.h
94084c
new file mode 100644
94084c
index 0000000000000000..5fd097df69e1770c
94084c
--- /dev/null
94084c
+++ b/sysdeps/generic/dl-execve.h
94084c
@@ -0,0 +1,25 @@
94084c
+/* execve for the dynamic linker.  Generic stub version.
94084c
+   Copyright (C) 2021 Free Software Foundation, Inc.
94084c
+   This file is part of the GNU C Library.
94084c
+
94084c
+   The GNU C Library is free software; you can redistribute it and/or
94084c
+   modify it under the terms of the GNU Lesser General Public
94084c
+   License as published by the Free Software Foundation; either
94084c
+   version 2.1 of the License, or (at your option) any later version.
94084c
+
94084c
+   The GNU C Library is distributed in the hope that it will be useful,
94084c
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
94084c
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
94084c
+   Lesser General Public License for more details.
94084c
+
94084c
+   You should have received a copy of the GNU Lesser General Public
94084c
+   License along with the GNU C Library; if not, see
94084c
+   <https://www.gnu.org/licenses/>.  */
94084c
+
94084c
+#include <errno.h>
94084c
+
94084c
+static int
94084c
+__rtld_execve (const char *path, char *const *argv, char *const *envp)
94084c
+{
94084c
+  return ENOSYS;
94084c
+}
94084c
diff --git a/sysdeps/unix/sysv/linux/dl-execve.h b/sysdeps/unix/sysv/linux/dl-execve.h
94084c
new file mode 100644
94084c
index 0000000000000000..ead3e1c28da34363
94084c
--- /dev/null
94084c
+++ b/sysdeps/unix/sysv/linux/dl-execve.h
94084c
@@ -0,0 +1,25 @@
94084c
+/* execve for the dynamic linker.  Linux version.
94084c
+   Copyright (C) 2021 Free Software Foundation, Inc.
94084c
+   This file is part of the GNU C Library.
94084c
+
94084c
+   The GNU C Library is free software; you can redistribute it and/or
94084c
+   modify it under the terms of the GNU Lesser General Public
94084c
+   License as published by the Free Software Foundation; either
94084c
+   version 2.1 of the License, or (at your option) any later version.
94084c
+
94084c
+   The GNU C Library is distributed in the hope that it will be useful,
94084c
+   but WITHOUT ANY WARRANTY; without even the implied warranty of
94084c
+   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
94084c
+   Lesser General Public License for more details.
94084c
+
94084c
+   You should have received a copy of the GNU Lesser General Public
94084c
+   License along with the GNU C Library; if not, see
94084c
+   <https://www.gnu.org/licenses/>.  */
94084c
+
94084c
+#include <errno.h>
94084c
+
94084c
+static inline int
94084c
+__rtld_execve (const char *path, char *const *argv, char *const *envp)
94084c
+{
94084c
+  return -INTERNAL_SYSCALL_CALL (execve, path, argv, envp);
94084c
+}