1*7c478bd9Sstevel@tonic-gate /*
2*7c478bd9Sstevel@tonic-gate  * CDDL HEADER START
3*7c478bd9Sstevel@tonic-gate  *
4*7c478bd9Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
5*7c478bd9Sstevel@tonic-gate  * Common Development and Distribution License, Version 1.0 only
6*7c478bd9Sstevel@tonic-gate  * (the "License").  You may not use this file except in compliance
7*7c478bd9Sstevel@tonic-gate  * with the License.
8*7c478bd9Sstevel@tonic-gate  *
9*7c478bd9Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
10*7c478bd9Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
11*7c478bd9Sstevel@tonic-gate  * See the License for the specific language governing permissions
12*7c478bd9Sstevel@tonic-gate  * and limitations under the License.
13*7c478bd9Sstevel@tonic-gate  *
14*7c478bd9Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
15*7c478bd9Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
16*7c478bd9Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
17*7c478bd9Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
18*7c478bd9Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
19*7c478bd9Sstevel@tonic-gate  *
20*7c478bd9Sstevel@tonic-gate  * CDDL HEADER END
21*7c478bd9Sstevel@tonic-gate  */
22*7c478bd9Sstevel@tonic-gate /*
23*7c478bd9Sstevel@tonic-gate  * Copyright 2004 Sun Microsystems, Inc.  All rights reserved.
24*7c478bd9Sstevel@tonic-gate  * Use is subject to license terms.
25*7c478bd9Sstevel@tonic-gate  */
26*7c478bd9Sstevel@tonic-gate 
27*7c478bd9Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
28*7c478bd9Sstevel@tonic-gate 
29*7c478bd9Sstevel@tonic-gate 
30*7c478bd9Sstevel@tonic-gate #include	<libelf.h>
31*7c478bd9Sstevel@tonic-gate #include	<sys/regset.h>
32*7c478bd9Sstevel@tonic-gate #include	<rtld_db.h>
33*7c478bd9Sstevel@tonic-gate #include	<_rtld_db.h>
34*7c478bd9Sstevel@tonic-gate #include	<msg.h>
35*7c478bd9Sstevel@tonic-gate #include	<stdio.h>
36*7c478bd9Sstevel@tonic-gate 
37*7c478bd9Sstevel@tonic-gate 
38*7c478bd9Sstevel@tonic-gate typedef	struct {
39*7c478bd9Sstevel@tonic-gate     rd_agent_t	*rlid_rap;
40*7c478bd9Sstevel@tonic-gate     psaddr_t	rlid_pltaddr;
41*7c478bd9Sstevel@tonic-gate     psaddr_t	rlid_gotaddr;
42*7c478bd9Sstevel@tonic-gate     rd_err_e	rlid_ret;
43*7c478bd9Sstevel@tonic-gate } Rli_data;
44*7c478bd9Sstevel@tonic-gate 
45*7c478bd9Sstevel@tonic-gate /*
46*7c478bd9Sstevel@tonic-gate  * Iterator function for rd_loadobj_iter - we are scaning
47*7c478bd9Sstevel@tonic-gate  * each object loaded to try and find the object defining
48*7c478bd9Sstevel@tonic-gate  * the current PLT being traversed - when found we return
49*7c478bd9Sstevel@tonic-gate  * the GOT pointer for that object.
50*7c478bd9Sstevel@tonic-gate  */
51*7c478bd9Sstevel@tonic-gate static int
rli_func(const rd_loadobj_t * rl,void * data)52*7c478bd9Sstevel@tonic-gate rli_func(const rd_loadobj_t *rl, void *data)
53*7c478bd9Sstevel@tonic-gate {
54*7c478bd9Sstevel@tonic-gate 	Ehdr	    ehdr;
55*7c478bd9Sstevel@tonic-gate 	Phdr	    phdr;
56*7c478bd9Sstevel@tonic-gate 	Rli_data    *rli_data;
57*7c478bd9Sstevel@tonic-gate 	ulong_t	    off;
58*7c478bd9Sstevel@tonic-gate 	psaddr_t    baseaddr;
59*7c478bd9Sstevel@tonic-gate 	psaddr_t    pltaddr;
60*7c478bd9Sstevel@tonic-gate 	uint_t	    i;
61*7c478bd9Sstevel@tonic-gate 	uint_t	    found_obj = 0;
62*7c478bd9Sstevel@tonic-gate 	psaddr_t    dynbase = 0;
63*7c478bd9Sstevel@tonic-gate 	rd_agent_t  *rap;
64*7c478bd9Sstevel@tonic-gate 	rd_err_e    rc;
65*7c478bd9Sstevel@tonic-gate 
66*7c478bd9Sstevel@tonic-gate 	rli_data = (Rli_data *)data;
67*7c478bd9Sstevel@tonic-gate 	pltaddr = rli_data->rlid_pltaddr;
68*7c478bd9Sstevel@tonic-gate 	rap = rli_data->rlid_rap;
69*7c478bd9Sstevel@tonic-gate 
70*7c478bd9Sstevel@tonic-gate 	if (ps_pread(rap->rd_psp, rl->rl_base, (char *)&ehdr,
71*7c478bd9Sstevel@tonic-gate 	    sizeof (Ehdr)) != PS_OK) {
72*7c478bd9Sstevel@tonic-gate 		rli_data->rlid_ret = RD_ERR;
73*7c478bd9Sstevel@tonic-gate 		LOG(ps_plog(MSG_ORIG(MSG_DB_READFAIL_X86_1),
74*7c478bd9Sstevel@tonic-gate 		    EC_ADDR(rl->rl_base)));
75*7c478bd9Sstevel@tonic-gate 		return (0);
76*7c478bd9Sstevel@tonic-gate 	}
77*7c478bd9Sstevel@tonic-gate 	if (ehdr.e_type == ET_EXEC)
78*7c478bd9Sstevel@tonic-gate 	    baseaddr = 0;
79*7c478bd9Sstevel@tonic-gate 	else
80*7c478bd9Sstevel@tonic-gate 	    baseaddr = rl->rl_base;
81*7c478bd9Sstevel@tonic-gate 
82*7c478bd9Sstevel@tonic-gate 	off = rl->rl_base + ehdr.e_phoff;
83*7c478bd9Sstevel@tonic-gate 	for (i = 0; i < ehdr.e_phnum; i++) {
84*7c478bd9Sstevel@tonic-gate 		if (ps_pread(rap->rd_psp, off, (char *)&phdr,
85*7c478bd9Sstevel@tonic-gate 		    sizeof (Phdr)) != PS_OK) {
86*7c478bd9Sstevel@tonic-gate 			rli_data->rlid_ret = RD_ERR;
87*7c478bd9Sstevel@tonic-gate 			LOG(ps_plog(MSG_ORIG(MSG_DB_READFAIL_X86_1),
88*7c478bd9Sstevel@tonic-gate 			    EC_ADDR(rl->rl_base)));
89*7c478bd9Sstevel@tonic-gate 			return (0);
90*7c478bd9Sstevel@tonic-gate 		}
91*7c478bd9Sstevel@tonic-gate 		if (phdr.p_type == PT_LOAD) {
92*7c478bd9Sstevel@tonic-gate 			if ((pltaddr >= (phdr.p_vaddr + baseaddr)) &&
93*7c478bd9Sstevel@tonic-gate 			    (pltaddr < (phdr.p_vaddr + baseaddr +
94*7c478bd9Sstevel@tonic-gate 			    phdr.p_memsz))) {
95*7c478bd9Sstevel@tonic-gate 				found_obj = 1;
96*7c478bd9Sstevel@tonic-gate 			}
97*7c478bd9Sstevel@tonic-gate 		} else if (phdr.p_type == PT_DYNAMIC)  {
98*7c478bd9Sstevel@tonic-gate 			dynbase = phdr.p_vaddr + baseaddr;
99*7c478bd9Sstevel@tonic-gate 		}
100*7c478bd9Sstevel@tonic-gate 		off += ehdr.e_phentsize;
101*7c478bd9Sstevel@tonic-gate 
102*7c478bd9Sstevel@tonic-gate 		if (found_obj & dynbase)
103*7c478bd9Sstevel@tonic-gate 			break;
104*7c478bd9Sstevel@tonic-gate 	}
105*7c478bd9Sstevel@tonic-gate 
106*7c478bd9Sstevel@tonic-gate 	if (found_obj) {
107*7c478bd9Sstevel@tonic-gate 		Dyn dynent;
108*7c478bd9Sstevel@tonic-gate 
109*7c478bd9Sstevel@tonic-gate 		if (dynbase == 0) {
110*7c478bd9Sstevel@tonic-gate 			LOG(ps_plog(MSG_ORIG(MSG_DB_NODYN_X86)));
111*7c478bd9Sstevel@tonic-gate 			rli_data->rlid_ret = RD_ERR;
112*7c478bd9Sstevel@tonic-gate 			return (0);
113*7c478bd9Sstevel@tonic-gate 		}
114*7c478bd9Sstevel@tonic-gate 		if ((rc = find_dynamic_ent32(rap, dynbase, DT_PLTGOT,
115*7c478bd9Sstevel@tonic-gate 		    &dynent)) != RD_OK) {
116*7c478bd9Sstevel@tonic-gate 			rli_data->rlid_ret = rc;
117*7c478bd9Sstevel@tonic-gate 			return (0);
118*7c478bd9Sstevel@tonic-gate 		}
119*7c478bd9Sstevel@tonic-gate 		/*
120*7c478bd9Sstevel@tonic-gate 		 * We've found our gotpntr. Return (0) to stop
121*7c478bd9Sstevel@tonic-gate 		 * the 'iteration'.
122*7c478bd9Sstevel@tonic-gate 		 */
123*7c478bd9Sstevel@tonic-gate 		rli_data->rlid_gotaddr = dynent.d_un.d_val + baseaddr;
124*7c478bd9Sstevel@tonic-gate 		return (0);
125*7c478bd9Sstevel@tonic-gate 	}
126*7c478bd9Sstevel@tonic-gate 
127*7c478bd9Sstevel@tonic-gate 	return (1);
128*7c478bd9Sstevel@tonic-gate }
129*7c478bd9Sstevel@tonic-gate 
130*7c478bd9Sstevel@tonic-gate 
131*7c478bd9Sstevel@tonic-gate /*
132*7c478bd9Sstevel@tonic-gate  * On x86, basically, a PLT entry looks like this:
133*7c478bd9Sstevel@tonic-gate  *	8048738:  ff 25 c8 45 05 08   jmp    *0x80545c8	 < OFFSET_INTO_GOT>
134*7c478bd9Sstevel@tonic-gate  *	804873e:  68 20 00 00 00      pushl  $0x20
135*7c478bd9Sstevel@tonic-gate  *	8048743:  e9 70 ff ff ff      jmp    0xffffff70 <80486b8> < &.plt >
136*7c478bd9Sstevel@tonic-gate  *
137*7c478bd9Sstevel@tonic-gate  *  The first time around OFFSET_INTO_GOT contains address of pushl; this forces
138*7c478bd9Sstevel@tonic-gate  *	first time resolution to go thru PLT's first entry (which is a call)
139*7c478bd9Sstevel@tonic-gate  *  The nth time around, the OFFSET_INTO_GOT actually contains the resolved
140*7c478bd9Sstevel@tonic-gate  *	address of the symbol(name), so the jmp is direct  [VT]
141*7c478bd9Sstevel@tonic-gate  *  The only complication is when going from a .so to an a.out or to another
142*7c478bd9Sstevel@tonic-gate  *	.so, we must resolve where the GOT table is for the given object.
143*7c478bd9Sstevel@tonic-gate  */
144*7c478bd9Sstevel@tonic-gate /* ARGSUSED 3 */
145*7c478bd9Sstevel@tonic-gate rd_err_e
plt32_resolution(rd_agent_t * rap,psaddr_t pc,lwpid_t lwpid,psaddr_t pltbase,rd_plt_info_t * rpi)146*7c478bd9Sstevel@tonic-gate plt32_resolution(rd_agent_t *rap, psaddr_t pc, lwpid_t lwpid,
147*7c478bd9Sstevel@tonic-gate 	psaddr_t pltbase, rd_plt_info_t *rpi)
148*7c478bd9Sstevel@tonic-gate {
149*7c478bd9Sstevel@tonic-gate 	unsigned	addr;
150*7c478bd9Sstevel@tonic-gate 	unsigned	ebx;
151*7c478bd9Sstevel@tonic-gate 	psaddr_t	pltoff, pltaddr;
152*7c478bd9Sstevel@tonic-gate 
153*7c478bd9Sstevel@tonic-gate 
154*7c478bd9Sstevel@tonic-gate 	if (rtld_db_version >= RD_VERSION3) {
155*7c478bd9Sstevel@tonic-gate 		rpi->pi_flags = 0;
156*7c478bd9Sstevel@tonic-gate 		rpi->pi_baddr = 0;
157*7c478bd9Sstevel@tonic-gate 	}
158*7c478bd9Sstevel@tonic-gate 
159*7c478bd9Sstevel@tonic-gate 	pltoff = pc - pltbase;
160*7c478bd9Sstevel@tonic-gate 	pltaddr = pltbase +
161*7c478bd9Sstevel@tonic-gate 		((pltoff / M_PLT_ENTSIZE) * M_PLT_ENTSIZE);
162*7c478bd9Sstevel@tonic-gate 	/*
163*7c478bd9Sstevel@tonic-gate 	 * This is the target of the jmp instruction
164*7c478bd9Sstevel@tonic-gate 	 */
165*7c478bd9Sstevel@tonic-gate 	if (ps_pread(rap->rd_psp, pltaddr + 2, (char *)&addr,
166*7c478bd9Sstevel@tonic-gate 	    sizeof (unsigned)) != PS_OK) {
167*7c478bd9Sstevel@tonic-gate 		LOG(ps_plog(MSG_ORIG(MSG_DB_READFAIL_2), EC_ADDR(pltaddr + 2)));
168*7c478bd9Sstevel@tonic-gate 		return (RD_ERR);
169*7c478bd9Sstevel@tonic-gate 	}
170*7c478bd9Sstevel@tonic-gate 
171*7c478bd9Sstevel@tonic-gate 	/*
172*7c478bd9Sstevel@tonic-gate 	 * Is this branch %ebx relative
173*7c478bd9Sstevel@tonic-gate 	 */
174*7c478bd9Sstevel@tonic-gate 	if (ps_pread(rap->rd_psp, pltaddr + 1, (char *)&ebx,
175*7c478bd9Sstevel@tonic-gate 	    sizeof (unsigned)) != PS_OK) {
176*7c478bd9Sstevel@tonic-gate 		LOG(ps_plog(MSG_ORIG(MSG_DB_READFAIL_2), EC_ADDR(pltaddr + 1)));
177*7c478bd9Sstevel@tonic-gate 		return (RD_ERR);
178*7c478bd9Sstevel@tonic-gate 	}
179*7c478bd9Sstevel@tonic-gate 
180*7c478bd9Sstevel@tonic-gate 	/*
181*7c478bd9Sstevel@tonic-gate 	 * If this .plt call is made via a GOT table (pic code), then
182*7c478bd9Sstevel@tonic-gate 	 * in order to resolve the PLT we must determine where the
183*7c478bd9Sstevel@tonic-gate 	 * GOT table is for the object making the call.
184*7c478bd9Sstevel@tonic-gate 	 *
185*7c478bd9Sstevel@tonic-gate 	 * We do this by using the rd_loadobj_iter() logic to scan
186*7c478bd9Sstevel@tonic-gate 	 * all of the objects currently loaded into memory, when we
187*7c478bd9Sstevel@tonic-gate 	 * find one which contains the .PLT table in question - we
188*7c478bd9Sstevel@tonic-gate 	 * find the GOT address for that object.
189*7c478bd9Sstevel@tonic-gate 	 */
190*7c478bd9Sstevel@tonic-gate 	if ((ebx & 0xff) == 0xa3) {
191*7c478bd9Sstevel@tonic-gate 		rd_err_e    rderr;
192*7c478bd9Sstevel@tonic-gate 		Rli_data    rli_data;
193*7c478bd9Sstevel@tonic-gate 
194*7c478bd9Sstevel@tonic-gate 		rli_data.rlid_ret = RD_OK;
195*7c478bd9Sstevel@tonic-gate 		rli_data.rlid_pltaddr = pltaddr;
196*7c478bd9Sstevel@tonic-gate 		rli_data.rlid_rap = rap;
197*7c478bd9Sstevel@tonic-gate 		rli_data.rlid_gotaddr = 0;
198*7c478bd9Sstevel@tonic-gate 		if ((rderr = _rd_loadobj_iter32(rap, rli_func, &rli_data))
199*7c478bd9Sstevel@tonic-gate 		    != RD_OK) {
200*7c478bd9Sstevel@tonic-gate 			return (rderr);
201*7c478bd9Sstevel@tonic-gate 		}
202*7c478bd9Sstevel@tonic-gate 
203*7c478bd9Sstevel@tonic-gate 		if (rli_data.rlid_ret != RD_OK) {
204*7c478bd9Sstevel@tonic-gate 			return (rli_data.rlid_ret);
205*7c478bd9Sstevel@tonic-gate 		}
206*7c478bd9Sstevel@tonic-gate 
207*7c478bd9Sstevel@tonic-gate 		if (rli_data.rlid_gotaddr == 0) {
208*7c478bd9Sstevel@tonic-gate 			LOG(ps_plog(MSG_ORIG(MSG_DB_NOGOT_X86)));
209*7c478bd9Sstevel@tonic-gate 			return (RD_ERR);
210*7c478bd9Sstevel@tonic-gate 		}
211*7c478bd9Sstevel@tonic-gate 		addr += rli_data.rlid_gotaddr;
212*7c478bd9Sstevel@tonic-gate 	}
213*7c478bd9Sstevel@tonic-gate 
214*7c478bd9Sstevel@tonic-gate 	/*
215*7c478bd9Sstevel@tonic-gate 	 * Find out what's pointed to by @OFFSET_INTO_GOT
216*7c478bd9Sstevel@tonic-gate 	 */
217*7c478bd9Sstevel@tonic-gate 	if (ps_pread(rap->rd_psp, addr, (char *)&addr,
218*7c478bd9Sstevel@tonic-gate 	    sizeof (unsigned)) != PS_OK) {
219*7c478bd9Sstevel@tonic-gate 		LOG(ps_plog(MSG_ORIG(MSG_DB_READFAIL_2), EC_ADDR(addr)));
220*7c478bd9Sstevel@tonic-gate 		return (RD_ERR);
221*7c478bd9Sstevel@tonic-gate 	}
222*7c478bd9Sstevel@tonic-gate 	if (addr == (pltaddr + 6)) {
223*7c478bd9Sstevel@tonic-gate 		rd_err_e	rerr;
224*7c478bd9Sstevel@tonic-gate 		/*
225*7c478bd9Sstevel@tonic-gate 		 * If GOT[ind] points to PLT+6 then this is the first
226*7c478bd9Sstevel@tonic-gate 		 * time through this PLT.
227*7c478bd9Sstevel@tonic-gate 		 */
228*7c478bd9Sstevel@tonic-gate 		if ((rerr = rd_binder_exit_addr(rap, MSG_ORIG(MSG_SYM_RTBIND),
229*7c478bd9Sstevel@tonic-gate 		    &(rpi->pi_target))) != RD_OK) {
230*7c478bd9Sstevel@tonic-gate 			return (rerr);
231*7c478bd9Sstevel@tonic-gate 		}
232*7c478bd9Sstevel@tonic-gate 		rpi->pi_skip_method = RD_RESOLVE_TARGET_STEP;
233*7c478bd9Sstevel@tonic-gate 		rpi->pi_nstep = 1;
234*7c478bd9Sstevel@tonic-gate 	} else {
235*7c478bd9Sstevel@tonic-gate 		/*
236*7c478bd9Sstevel@tonic-gate 		 * This is the n'th time through and GOT[ind] points
237*7c478bd9Sstevel@tonic-gate 		 * to the final destination.
238*7c478bd9Sstevel@tonic-gate 		 */
239*7c478bd9Sstevel@tonic-gate 		rpi->pi_skip_method = RD_RESOLVE_STEP;
240*7c478bd9Sstevel@tonic-gate 		rpi->pi_nstep = 1;
241*7c478bd9Sstevel@tonic-gate 		rpi->pi_target = 0;
242*7c478bd9Sstevel@tonic-gate 		if (rtld_db_version >= RD_VERSION3) {
243*7c478bd9Sstevel@tonic-gate 			rpi->pi_flags |= RD_FLG_PI_PLTBOUND;
244*7c478bd9Sstevel@tonic-gate 			rpi->pi_baddr = addr;
245*7c478bd9Sstevel@tonic-gate 		}
246*7c478bd9Sstevel@tonic-gate 	}
247*7c478bd9Sstevel@tonic-gate 
248*7c478bd9Sstevel@tonic-gate 	return (RD_OK);
249*7c478bd9Sstevel@tonic-gate }
250