1 /*
2 * Copyright (C) 2008 The Android Open Source Project
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * * Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * * Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in
12 * the documentation and/or other materials provided with the
13 * distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19 * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22 * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25 * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 */
28
29 #include <android/api-level.h>
30 #include <elf.h>
31 #include <errno.h>
32 #include <malloc.h>
33 #include <signal.h>
34 #include <stddef.h>
35 #include <stdint.h>
36 #include <stdio.h>
37 #include <stdlib.h>
38 #include <sys/auxv.h>
39 #include <sys/mman.h>
40
41 #include "async_safe/log.h"
42 #include "heap_tagging.h"
43 #include "libc_init_common.h"
44 #include "platform/bionic/macros.h"
45 #include "platform/bionic/mte.h"
46 #include "platform/bionic/page.h"
47 #include "platform/bionic/reserved_signals.h"
48 #include "private/KernelArgumentBlock.h"
49 #include "private/bionic_asm.h"
50 #include "private/bionic_asm_note.h"
51 #include "private/bionic_call_ifunc_resolver.h"
52 #include "private/bionic_elf_tls.h"
53 #include "private/bionic_globals.h"
54 #include "private/bionic_tls.h"
55 #include "private/elf_note.h"
56 #include "pthread_internal.h"
57 #include "sys/system_properties.h"
58 #include "sysprop_helpers.h"
59
60 #if __has_feature(hwaddress_sanitizer)
61 #include <sanitizer/hwasan_interface.h>
62 #endif
63
64 // Leave the variable uninitialized for the sake of the dynamic loader, which
65 // links in this file. The loader will initialize this variable before
66 // relocating itself.
67 #if defined(__i386__)
68 __LIBC_HIDDEN__ void* __libc_sysinfo;
69 #endif
70
71 extern "C" int __cxa_atexit(void (*)(void *), void *, void *);
72 extern "C" const char* __gnu_basename(const char* path);
73
call_array(init_func_t ** list,size_t count,int argc,char * argv[],char * envp[])74 static void call_array(init_func_t** list, size_t count, int argc, char* argv[], char* envp[]) {
75 while (count-- > 0) {
76 init_func_t* function = *list++;
77 (*function)(argc, argv, envp);
78 }
79 }
80
call_fini_array(void * arg)81 static void call_fini_array(void* arg) {
82 structors_array_t* structors = reinterpret_cast<structors_array_t*>(arg);
83 fini_func_t** array = structors->fini_array;
84 size_t count = structors->fini_array_count;
85 // Now call each destructor in reverse order.
86 while (count-- > 0) {
87 fini_func_t* function = array[count];
88 (*function)();
89 }
90 }
91
92 #if defined(__arm__) || defined(__i386__) // Legacy architectures used REL...
93 extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rel) __rel_iplt_start[], __rel_iplt_end[];
94
call_ifunc_resolvers()95 static void call_ifunc_resolvers() {
96 for (ElfW(Rel)* r = __rel_iplt_start; r != __rel_iplt_end; ++r) {
97 ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
98 ElfW(Addr) resolver = *offset;
99 *offset = __bionic_call_ifunc_resolver(resolver);
100 }
101 }
102 #else // ...but modern architectures use RELA instead.
103 extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rela) __rela_iplt_start[], __rela_iplt_end[];
104
call_ifunc_resolvers()105 static void call_ifunc_resolvers() {
106 for (ElfW(Rela)* r = __rela_iplt_start; r != __rela_iplt_end; ++r) {
107 ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
108 ElfW(Addr) resolver = r->r_addend;
109 *offset = __bionic_call_ifunc_resolver(resolver);
110 }
111 }
112 #endif
113
apply_gnu_relro()114 static void apply_gnu_relro() {
115 ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
116 unsigned long int phdr_ct = getauxval(AT_PHNUM);
117
118 for (ElfW(Phdr)* phdr = phdr_start; phdr < (phdr_start + phdr_ct); phdr++) {
119 if (phdr->p_type != PT_GNU_RELRO) {
120 continue;
121 }
122
123 ElfW(Addr) seg_page_start = page_start(phdr->p_vaddr);
124 ElfW(Addr) seg_page_end = page_end(phdr->p_vaddr + phdr->p_memsz);
125
126 // Check return value here? What do we do if we fail?
127 mprotect(reinterpret_cast<void*>(seg_page_start), seg_page_end - seg_page_start, PROT_READ);
128 }
129 }
130
layout_static_tls(KernelArgumentBlock & args)131 static void layout_static_tls(KernelArgumentBlock& args) {
132 StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout;
133 layout.reserve_bionic_tls();
134
135 const char* progname = args.argv[0];
136 ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
137 size_t phdr_ct = getauxval(AT_PHNUM);
138
139 static TlsModule mod;
140 TlsModules& modules = __libc_shared_globals()->tls_modules;
141 if (__bionic_get_tls_segment(phdr_start, phdr_ct, 0, &mod.segment)) {
142 if (!__bionic_check_tls_align(mod.segment.aligned_size.align.value)) {
143 async_safe_fatal("error: TLS segment alignment in \"%s\" is not a power of 2: %zu\n",
144 progname, mod.segment.aligned_size.align.value);
145 }
146 mod.static_offset = layout.reserve_exe_segment_and_tcb(&mod.segment, progname);
147 mod.first_generation = kTlsGenerationFirst;
148
149 modules.module_count = 1;
150 modules.static_module_count = 1;
151 modules.module_table = &mod;
152 } else {
153 layout.reserve_exe_segment_and_tcb(nullptr, progname);
154 }
155 // Enable the fast path in __tls_get_addr.
156 __libc_tls_generation_copy = modules.generation;
157
158 layout.finish_layout();
159 }
__libc_init_profiling_handlers()160 void __libc_init_profiling_handlers() {
161 // The dynamic variant of this function is more interesting, but this
162 // at least ensures that static binaries aren't killed by the kernel's
163 // default disposition for these two real-time signals that would have
164 // handlers installed if this was a dynamic binary.
165 signal(BIONIC_SIGNAL_PROFILER, SIG_IGN);
166 signal(BIONIC_SIGNAL_ART_PROFILER, SIG_IGN);
167 }
168
__real_libc_init(KernelArgumentBlock & args,void * raw_args,void (* onexit)(void)__unused,int (* slingshot)(int,char **,char **),structors_array_t const * const structors,bionic_tcb * temp_tcb)169 __attribute__((no_sanitize("memtag"))) __noreturn static void __real_libc_init(
170 KernelArgumentBlock& args, void* raw_args, void (*onexit)(void) __unused,
171 int (*slingshot)(int, char**, char**), structors_array_t const* const structors,
172 bionic_tcb* temp_tcb) {
173 BIONIC_STOP_UNWIND;
174
175 __libc_init_main_thread_early(args, temp_tcb);
176 __libc_init_main_thread_late();
177 __libc_init_globals();
178 __libc_shared_globals()->init_progname = args.argv[0];
179 __libc_init_AT_SECURE(args.envp);
180 layout_static_tls(args);
181 __libc_init_main_thread_final();
182 __libc_init_common();
183 __libc_init_mte(/*memtag_dynamic_entries=*/nullptr,
184 reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)), getauxval(AT_PHNUM),
185 /*load_bias = */ 0);
186 __libc_init_mte_stack(/*stack_top = */ raw_args);
187 __libc_init_scudo();
188 __libc_init_profiling_handlers();
189 __libc_init_fork_handler();
190
191 call_ifunc_resolvers();
192 apply_gnu_relro();
193
194 // Several Linux ABIs don't pass the onexit pointer, and the ones that
195 // do never use it. Therefore, we ignore it.
196
197 call_array(structors->preinit_array, structors->preinit_array_count, args.argc, args.argv,
198 args.envp);
199 call_array(structors->init_array, structors->init_array_count, args.argc, args.argv, args.envp);
200
201 // The executable may have its own destructors listed in its .fini_array
202 // so we need to ensure that these are called when the program exits
203 // normally.
204 if (structors->fini_array_count > 0) {
205 __cxa_atexit(call_fini_array, const_cast<structors_array_t*>(structors), nullptr);
206 }
207
208 __libc_init_mte_late();
209
210 exit(slingshot(args.argc, args.argv, args.envp));
211 }
212
213 extern "C" void __hwasan_init_static();
214
215 // This __libc_init() is only used for static executables, and is called from crtbegin.c.
216 //
217 // The 'structors' parameter contains pointers to various initializer
218 // arrays that must be run before the program's 'main' routine is launched.
__libc_init(void * raw_args,void (* onexit)(void)__unused,int (* slingshot)(int,char **,char **),structors_array_t const * const structors)219 __attribute__((no_sanitize("hwaddress", "memtag"))) __noreturn void __libc_init(
220 void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
221 structors_array_t const* const structors) {
222 // We _really_ don't want the compiler to call memset() here,
223 // but it's done so before for riscv64 (http://b/365618934),
224 // so we have to force it to behave.
225 bionic_tcb temp_tcb __attribute__((uninitialized));
226 __builtin_memset_inline(&temp_tcb, 0, sizeof(temp_tcb));
227
228 KernelArgumentBlock args(raw_args);
229 #if __has_feature(hwaddress_sanitizer)
230 // Install main thread TLS early. It will be initialized later in __libc_init_main_thread. For now
231 // all we need is access to TLS_SLOT_SANITIZER and read auxval for the page size.
232 __set_tls(&temp_tcb.tls_slot(0));
233 __libc_shared_globals()->auxv = args.auxv;
234 // Initialize HWASan enough to run instrumented code. This sets up TLS_SLOT_SANITIZER, among other
235 // things.
236 __hwasan_init_static();
237 // We are ready to run HWASan-instrumented code, proceed with libc initialization...
238 #endif
239
240 __real_libc_init(args, raw_args, onexit, slingshot, structors, &temp_tcb);
241 }
242
243 static int g_target_sdk_version{__ANDROID_API__};
244
android_get_application_target_sdk_version()245 extern "C" int android_get_application_target_sdk_version() {
246 return g_target_sdk_version;
247 }
248
android_set_application_target_sdk_version(int target)249 extern "C" void android_set_application_target_sdk_version(int target) {
250 g_target_sdk_version = target;
251 __libc_set_target_sdk_version(target);
252 }
253
254 // This function is called in the dynamic linker before ifunc resolvers have run, so this file is
255 // compiled with -ffreestanding to avoid implicit string.h function calls. (It shouldn't strictly
256 // be necessary, though.)
__libc_shared_globals()257 __LIBC_HIDDEN__ libc_shared_globals* __libc_shared_globals() {
258 BIONIC_USED_BEFORE_LINKER_RELOCATES static libc_shared_globals globals;
259 return &globals;
260 }
261