2 * Copyright (c) 2013, Stacey D. Son
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27 #include <sys/cdefs.h>
28 __FBSDID("$FreeBSD$");
30 #include <sys/param.h>
31 #include <sys/ctype.h>
33 #include <sys/systm.h>
34 #include <sys/sysproto.h>
36 #include <sys/imgact.h>
37 #include <sys/imgact_binmisc.h>
38 #include <sys/kernel.h>
39 #include <sys/libkern.h>
41 #include <sys/malloc.h>
42 #include <sys/mutex.h>
43 #include <sys/sysctl.h>
46 * Miscellaneous binary interpreter image activator.
48 * If the given target executable's header matches 'xbe_magic' field in the
49 * 'interpreter_list' then it will use the user-level interpreter specified in
50 * the 'xbe_interpreter' field to execute the binary. The 'xbe_magic' field may
51 * be adjusted to a given offset using the value in the 'xbe_moffset' field
52 * and bits of the header may be masked using the 'xbe_mask' field. The
53 * 'interpreter_list' entries are managed using sysctl(3) as described in the
54 * <sys/imgact_binmisc.h> file.
58 * Node of the interpreter list.
60 typedef struct imgact_binmisc_entry {
66 uint8_t *ibe_interpreter;
67 uint32_t ibe_interp_argcnt;
68 uint32_t ibe_interp_length;
70 SLIST_ENTRY(imgact_binmisc_entry) link;
71 } imgact_binmisc_entry_t;
76 #define IBC_ADD 1 /* Add given entry. */
77 #define IBC_REMOVE 2 /* Remove entry for a given name. */
78 #define IBC_DISABLE 3 /* Disable entry for a given name. */
79 #define IBC_ENABLE 4 /* Enable entry for a given name. */
80 #define IBC_LOOKUP 5 /* Lookup and return entry for given name. */
81 #define IBC_LIST 6 /* Get a snapshot of the interpretor list. */
84 * Interpreter string macros.
86 * They all start with '#' followed by a single letter:
88 #define ISM_POUND '#' /* "##" is the escape sequence for single #. */
89 #define ISM_OLD_ARGV0 'a' /* "#a" is replaced with the old argv0. */
91 MALLOC_DEFINE(M_BINMISC, KMOD_NAME, "misc binary image activator");
93 /* The interpreter list. */
94 static SLIST_HEAD(, imgact_binmisc_entry) interpreter_list =
95 SLIST_HEAD_INITIALIZER(interpreter_list);
97 static int interp_list_entry_count = 0;
99 static struct mtx interp_list_mtx;
101 int imgact_binmisc_exec(struct image_params *imgp);
105 * Populate the entry with the information about the interpreter.
108 imgact_binmisc_populate_interp(char *str, imgact_binmisc_entry_t *ibe)
110 uint32_t len = 0, argc = 1;
111 char t[IBE_INTERP_LEN_MAX];
117 * Normalize interpreter string. Replace white space between args with
121 while (*sp != '\0') {
122 if (*sp == ' ' || *sp == '\t') {
123 if (++len > IBE_INTERP_LEN_MAX)
127 while (*sp == ' ' || *sp == '\t')
138 ibe->ibe_interpreter = malloc(len, M_BINMISC, M_WAITOK|M_ZERO);
140 /* Populate all the ibe fields for the interpreter. */
141 memcpy(ibe->ibe_interpreter, t, len);
142 ibe->ibe_interp_argcnt = argc;
143 ibe->ibe_interp_length = len;
147 * Allocate memory and populate a new entry for the interpreter table.
149 static imgact_binmisc_entry_t *
150 imgact_binmisc_new_entry(ximgact_binmisc_entry_t *xbe)
152 imgact_binmisc_entry_t *ibe = NULL;
153 size_t namesz = min(strlen(xbe->xbe_name) + 1, IBE_NAME_MAX);
155 mtx_assert(&interp_list_mtx, MA_NOTOWNED);
157 ibe = malloc(sizeof(*ibe), M_BINMISC, M_WAITOK|M_ZERO);
159 ibe->ibe_name = malloc(namesz, M_BINMISC, M_WAITOK|M_ZERO);
160 strlcpy(ibe->ibe_name, xbe->xbe_name, namesz);
162 imgact_binmisc_populate_interp(xbe->xbe_interpreter, ibe);
164 ibe->ibe_magic = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO);
165 memcpy(ibe->ibe_magic, xbe->xbe_magic, xbe->xbe_msize);
167 ibe->ibe_mask = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO);
168 memcpy(ibe->ibe_mask, xbe->xbe_mask, xbe->xbe_msize);
170 ibe->ibe_moffset = xbe->xbe_moffset;
171 ibe->ibe_msize = xbe->xbe_msize;
172 ibe->ibe_flags = xbe->xbe_flags;
178 * Free the allocated memory for a given list item.
181 imgact_binmisc_destroy_entry(imgact_binmisc_entry_t *ibe)
186 free(ibe->ibe_magic, M_BINMISC);
188 free(ibe->ibe_mask, M_BINMISC);
189 if (ibe->ibe_interpreter)
190 free(ibe->ibe_interpreter, M_BINMISC);
192 free(ibe->ibe_name, M_BINMISC);
194 free(ibe, M_BINMISC);
198 * Find the interpreter in the list by the given name. Return NULL if not
201 static imgact_binmisc_entry_t *
202 imgact_binmisc_find_entry(char *name)
204 imgact_binmisc_entry_t *ibe;
206 mtx_assert(&interp_list_mtx, MA_OWNED);
208 SLIST_FOREACH(ibe, &interpreter_list, link) {
209 if (strncmp(name, ibe->ibe_name, IBE_NAME_MAX) == 0)
217 * Add the given interpreter if it doesn't already exist. Return EEXIST
218 * if the name already exist in the interpreter list.
221 imgact_binmisc_add_entry(ximgact_binmisc_entry_t *xbe)
223 imgact_binmisc_entry_t *ibe;
226 if (xbe->xbe_msize > IBE_MAGIC_MAX)
229 for(p = xbe->xbe_name; *p != 0; p++)
230 if (!isascii((int)*p))
233 for(p = xbe->xbe_interpreter; *p != 0; p++)
234 if (!isascii((int)*p))
237 /* Make sure we don't have any invalid #'s. */
238 p = xbe->xbe_interpreter;
258 /* Anything besides the above is invalid. */
263 mtx_lock(&interp_list_mtx);
264 if (imgact_binmisc_find_entry(xbe->xbe_name) != NULL) {
265 mtx_unlock(&interp_list_mtx);
268 mtx_unlock(&interp_list_mtx);
270 ibe = imgact_binmisc_new_entry(xbe);
274 mtx_lock(&interp_list_mtx);
275 SLIST_INSERT_HEAD(&interpreter_list, ibe, link);
276 interp_list_entry_count++;
277 mtx_unlock(&interp_list_mtx);
283 * Remove the interpreter in the list with the given name. Return ENOENT
287 imgact_binmisc_remove_entry(char *name)
289 imgact_binmisc_entry_t *ibe;
291 mtx_lock(&interp_list_mtx);
292 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
293 mtx_unlock(&interp_list_mtx);
296 SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry, link);
297 interp_list_entry_count--;
298 mtx_unlock(&interp_list_mtx);
300 imgact_binmisc_destroy_entry(ibe);
306 * Disable the interpreter in the list with the given name. Return ENOENT
310 imgact_binmisc_disable_entry(char *name)
312 imgact_binmisc_entry_t *ibe;
314 mtx_lock(&interp_list_mtx);
315 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
316 mtx_unlock(&interp_list_mtx);
320 ibe->ibe_flags &= ~IBF_ENABLED;
321 mtx_unlock(&interp_list_mtx);
327 * Enable the interpreter in the list with the given name. Return ENOENT
331 imgact_binmisc_enable_entry(char *name)
333 imgact_binmisc_entry_t *ibe;
335 mtx_lock(&interp_list_mtx);
336 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
337 mtx_unlock(&interp_list_mtx);
341 ibe->ibe_flags |= IBF_ENABLED;
342 mtx_unlock(&interp_list_mtx);
348 imgact_binmisc_populate_xbe(ximgact_binmisc_entry_t *xbe,
349 imgact_binmisc_entry_t *ibe)
353 mtx_assert(&interp_list_mtx, MA_OWNED);
355 bzero(xbe, sizeof(*xbe));
356 strlcpy(xbe->xbe_name, ibe->ibe_name, IBE_NAME_MAX);
358 /* Copy interpreter string. Replace NULL breaks with space. */
359 memcpy(xbe->xbe_interpreter, ibe->ibe_interpreter,
360 ibe->ibe_interp_length);
361 for(i = 0; i < (ibe->ibe_interp_length - 1); i++)
362 if (xbe->xbe_interpreter[i] == '\0')
363 xbe->xbe_interpreter[i] = ' ';
365 memcpy(xbe->xbe_magic, ibe->ibe_magic, ibe->ibe_msize);
366 memcpy(xbe->xbe_mask, ibe->ibe_mask, ibe->ibe_msize);
367 xbe->xbe_version = IBE_VERSION;
368 xbe->xbe_flags = ibe->ibe_flags;
369 xbe->xbe_moffset = ibe->ibe_moffset;
370 xbe->xbe_msize = ibe->ibe_msize;
376 * Retrieve the interpreter with the give name and populate the
377 * ximgact_binmisc_entry structure. Return ENOENT if not found.
380 imgact_binmisc_lookup_entry(char *name, ximgact_binmisc_entry_t *xbe)
382 imgact_binmisc_entry_t *ibe;
385 mtx_lock(&interp_list_mtx);
386 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
387 mtx_unlock(&interp_list_mtx);
391 error = imgact_binmisc_populate_xbe(xbe, ibe);
392 mtx_unlock(&interp_list_mtx);
398 * Get a snapshot of all the interpreter entries in the list.
401 imgact_binmisc_get_all_entries(struct sysctl_req *req)
403 ximgact_binmisc_entry_t *xbe, *xbep;
404 imgact_binmisc_entry_t *ibe;
405 int error = 0, count;
407 mtx_lock(&interp_list_mtx);
408 count = interp_list_entry_count;
409 /* Don't block in malloc() while holding lock. */
410 xbe = malloc(sizeof(*xbe) * count, M_BINMISC, M_NOWAIT|M_ZERO);
412 mtx_unlock(&interp_list_mtx);
417 SLIST_FOREACH(ibe, &interpreter_list, link) {
418 error = imgact_binmisc_populate_xbe(xbep++, ibe);
422 mtx_unlock(&interp_list_mtx);
425 error = SYSCTL_OUT(req, xbe, sizeof(*xbe) * count);
427 free(xbe, M_BINMISC);
432 * sysctl() handler for munipulating interpretor table.
433 * Not MP safe (locked by sysctl).
436 sysctl_kern_binmisc(SYSCTL_HANDLER_ARGS)
438 ximgact_binmisc_entry_t xbe;
443 /* Add an entry. Limited to IBE_MAX_ENTRIES. */
444 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
447 if (IBE_VERSION != xbe.xbe_version)
449 if (interp_list_entry_count == IBE_MAX_ENTRIES)
451 error = imgact_binmisc_add_entry(&xbe);
455 /* Remove an entry. */
456 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
459 if (IBE_VERSION != xbe.xbe_version)
461 error = imgact_binmisc_remove_entry(xbe.xbe_name);
465 /* Disable an entry. */
466 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
469 if (IBE_VERSION != xbe.xbe_version)
471 error = imgact_binmisc_disable_entry(xbe.xbe_name);
475 /* Enable an entry. */
476 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
479 if (IBE_VERSION != xbe.xbe_version)
481 error = imgact_binmisc_enable_entry(xbe.xbe_name);
485 /* Lookup an entry. */
486 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
489 if (IBE_VERSION != xbe.xbe_version)
491 error = imgact_binmisc_lookup_entry(xbe.xbe_name, &xbe);
493 error = SYSCTL_OUT(req, &xbe, sizeof(xbe));
497 /* Return a snapshot of the interpretor list. */
500 /* No pointer then just return the list size. */
501 error = SYSCTL_OUT(req, 0, interp_list_entry_count *
502 sizeof(ximgact_binmisc_entry_t));
508 error = imgact_binmisc_get_all_entries(req);
518 SYSCTL_NODE(_kern, OID_AUTO, binmisc, CTLFLAG_RW, 0,
519 "Image activator for miscellaneous binaries");
521 SYSCTL_PROC(_kern_binmisc, OID_AUTO, add,
522 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ADD,
523 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
524 "Add an activator entry");
526 SYSCTL_PROC(_kern_binmisc, OID_AUTO, remove,
527 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_REMOVE,
528 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
529 "Remove an activator entry");
531 SYSCTL_PROC(_kern_binmisc, OID_AUTO, disable,
532 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_DISABLE,
533 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
534 "Disable an activator entry");
536 SYSCTL_PROC(_kern_binmisc, OID_AUTO, enable,
537 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ENABLE,
538 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
539 "Enable an activator entry");
541 SYSCTL_PROC(_kern_binmisc, OID_AUTO, lookup,
542 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RW|CTLFLAG_ANYBODY, NULL, IBC_LOOKUP,
543 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
544 "Lookup an activator entry");
546 SYSCTL_PROC(_kern_binmisc, OID_AUTO, list,
547 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RD|CTLFLAG_ANYBODY, NULL, IBC_LIST,
548 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
549 "Get snapshot of all the activator entries");
551 static imgact_binmisc_entry_t *
552 imgact_binmisc_find_interpreter(const char *image_header)
554 imgact_binmisc_entry_t *ibe;
559 mtx_assert(&interp_list_mtx, MA_OWNED);
561 SLIST_FOREACH(ibe, &interpreter_list, link) {
562 if (!(IBF_ENABLED & ibe->ibe_flags))
565 p = image_header + ibe->ibe_moffset;
567 if (IBF_USE_MASK & ibe->ibe_flags) {
568 /* Compare using mask. */
569 for (i = 0; i < sz; i++)
570 if ((*p++ ^ ibe->ibe_magic[i]) &
574 for (i = 0; i < sz; i++)
575 if (*p++ ^ ibe->ibe_magic[i])
578 if (i == ibe->ibe_msize)
585 imgact_binmisc_exec(struct image_params *imgp)
587 const char *image_header = imgp->image_header;
588 const char *fname = NULL;
591 imgact_binmisc_entry_t *ibe;
595 /* Do we have an interpreter for the given image header? */
596 mtx_lock(&interp_list_mtx);
597 if ((ibe = imgact_binmisc_find_interpreter(image_header)) == NULL) {
598 mtx_unlock(&interp_list_mtx);
602 /* No interpreter nesting allowed. */
603 if (imgp->interpreted & IMGACT_BINMISC) {
604 mtx_unlock(&interp_list_mtx);
608 imgp->interpreted |= IMGACT_BINMISC;
610 if (imgp->args->fname != NULL) {
611 fname = imgp->args->fname;
614 /* Use the fdescfs(5) path for fexecve(2). */
615 sname = sbuf_new_auto();
616 sbuf_printf(sname, "/dev/fd/%d", imgp->args->fd);
618 fname = sbuf_data(sname);
623 * We need to "push" the interpreter in the arg[] list. To do this,
624 * we first shift all the other values in the `begin_argv' area to
625 * provide the exact amount of room for the values added. Set up
626 * `offset' as the number of bytes to be added to the `begin_argv'
629 offset = ibe->ibe_interp_length;
631 /* Adjust the offset for #'s. */
632 s = ibe->ibe_interpreter;
641 /* "##" -> "#": reduce offset by one. */
646 /* "#a" -> (old argv0): increase offset to fit fname */
647 offset += strlen(fname) - 2;
651 /* Hmm... This shouldn't happen. */
652 mtx_unlock(&interp_list_mtx);
653 printf("%s: Unknown macro #%c sequence in "
654 "interpreter string\n", KMOD_NAME, *(s + 1));
661 /* Check to make sure we won't overrun the stringspace. */
662 if (offset > imgp->args->stringspace) {
663 mtx_unlock(&interp_list_mtx);
668 /* Make room for the interpreter */
669 bcopy(imgp->args->begin_argv, imgp->args->begin_argv + offset,
670 imgp->args->endp - imgp->args->begin_argv);
672 /* Adjust everything by the offset. */
673 imgp->args->begin_envv += offset;
674 imgp->args->endp += offset;
675 imgp->args->stringspace -= offset;
677 /* Add the new argument(s) in the count. */
678 imgp->args->argc += ibe->ibe_interp_argcnt;
681 * The original arg[] list has been shifted appropriately. Copy in
682 * the interpreter path.
684 s = ibe->ibe_interpreter;
685 d = imgp->args->begin_argv;
689 /* Handle "#" in interpreter string. */
693 /* "##": Replace with a single '#' */
698 /* "#a": Replace with old arg0 (fname). */
699 if ((l = strlen(fname)) != 0) {
706 /* Shouldn't happen but skip it if it does. */
712 /* Replace space with NUL to seperate arguments. */
723 mtx_unlock(&interp_list_mtx);
726 imgp->interpreter_name = imgp->args->begin_argv;
736 imgact_binmisc_init(void *arg)
739 mtx_init(&interp_list_mtx, KMOD_NAME, NULL, MTX_DEF);
743 imgact_binmisc_fini(void *arg)
745 imgact_binmisc_entry_t *ibe, *ibe_tmp;
747 /* Free all the interpreters. */
748 mtx_lock(&interp_list_mtx);
749 SLIST_FOREACH_SAFE(ibe, &interpreter_list, link, ibe_tmp) {
750 SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry,
752 imgact_binmisc_destroy_entry(ibe);
754 mtx_unlock(&interp_list_mtx);
756 mtx_destroy(&interp_list_mtx);
759 SYSINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_init, 0);
760 SYSUNINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_fini, 0);
763 * Tell kern_execve.c about it, with a little help from the linker.
765 static struct execsw imgact_binmisc_execsw = { imgact_binmisc_exec, KMOD_NAME };
766 EXEC_SET(imgact_binmisc, imgact_binmisc_execsw);