2 * Copyright (c) 2013-16, Stacey D. Son
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
14 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27 #include <sys/cdefs.h>
28 __FBSDID("$FreeBSD$");
30 #include <sys/param.h>
31 #include <sys/ctype.h>
33 #include <sys/imgact.h>
34 #include <sys/imgact_binmisc.h>
35 #include <sys/kernel.h>
37 #include <sys/malloc.h>
38 #include <sys/mutex.h>
40 #include <sys/sysctl.h>
43 #include <machine/atomic.h>
46 * Miscellaneous binary interpreter image activator.
48 * If the given target executable's header matches 'xbe_magic' field in the
49 * 'interpreter_list' then it will use the user-level interpreter specified in
50 * the 'xbe_interpreter' field to execute the binary. The 'xbe_magic' field may
51 * be adjusted to a given offset using the value in the 'xbe_moffset' field
52 * and bits of the header may be masked using the 'xbe_mask' field. The
53 * 'interpreter_list' entries are managed using sysctl(3) as described in the
54 * <sys/imgact_binmisc.h> file.
58 * Node of the interpreter list.
60 typedef struct imgact_binmisc_entry {
61 SLIST_ENTRY(imgact_binmisc_entry) link;
65 uint8_t *ibe_interpreter;
66 ssize_t ibe_interp_offset;
67 uint32_t ibe_interp_argcnt;
68 uint32_t ibe_interp_length;
69 uint32_t ibe_argv0_cnt;
73 } imgact_binmisc_entry_t;
78 #define IBC_ADD 1 /* Add given entry. */
79 #define IBC_REMOVE 2 /* Remove entry for a given name. */
80 #define IBC_DISABLE 3 /* Disable entry for a given name. */
81 #define IBC_ENABLE 4 /* Enable entry for a given name. */
82 #define IBC_LOOKUP 5 /* Lookup and return entry for given name. */
83 #define IBC_LIST 6 /* Get a snapshot of the interpretor list. */
86 * Interpreter string macros.
88 * They all start with '#' followed by a single letter:
90 #define ISM_POUND '#' /* "##" is the escape sequence for single #. */
91 #define ISM_OLD_ARGV0 'a' /* "#a" is replaced with the old argv0. */
93 MALLOC_DEFINE(M_BINMISC, KMOD_NAME, "misc binary image activator");
95 /* The interpreter list. */
96 static SLIST_HEAD(, imgact_binmisc_entry) interpreter_list =
97 SLIST_HEAD_INITIALIZER(interpreter_list);
99 static int interp_list_entry_count;
101 static struct sx interp_list_sx;
103 #define INTERP_LIST_WLOCK() sx_xlock(&interp_list_sx)
104 #define INTERP_LIST_RLOCK() sx_slock(&interp_list_sx)
105 #define INTERP_LIST_WUNLOCK() sx_xunlock(&interp_list_sx)
106 #define INTERP_LIST_RUNLOCK() sx_sunlock(&interp_list_sx)
108 #define INTERP_LIST_LOCK_INIT() sx_init(&interp_list_sx, KMOD_NAME)
109 #define INTERP_LIST_LOCK_DESTROY() sx_destroy(&interp_list_sx)
111 #define INTERP_LIST_ASSERT_LOCKED() sx_assert(&interp_list_sx, SA_LOCKED)
114 * Populate the entry with the information about the interpreter.
117 imgact_binmisc_populate_interp(char *str, imgact_binmisc_entry_t *ibe)
119 uint32_t len = 0, argc = 1;
120 char t[IBE_INTERP_LEN_MAX];
123 memset(t, 0, sizeof(t));
126 * Normalize interpreter string. Replace white space between args with
130 while (*sp != '\0') {
131 if (*sp == ' ' || *sp == '\t') {
132 if (++len >= IBE_INTERP_LEN_MAX)
136 while (*sp == ' ' || *sp == '\t')
147 ibe->ibe_interpreter = malloc(len, M_BINMISC, M_WAITOK|M_ZERO);
149 /* Populate all the ibe fields for the interpreter. */
150 memcpy(ibe->ibe_interpreter, t, len);
151 ibe->ibe_interp_argcnt = argc;
152 ibe->ibe_interp_length = len;
156 * Allocate memory and populate a new entry for the interpreter table.
158 static imgact_binmisc_entry_t *
159 imgact_binmisc_new_entry(ximgact_binmisc_entry_t *xbe, ssize_t interp_offset,
162 imgact_binmisc_entry_t *ibe = NULL;
163 size_t namesz = min(strlen(xbe->xbe_name) + 1, IBE_NAME_MAX);
165 ibe = malloc(sizeof(*ibe), M_BINMISC, M_WAITOK|M_ZERO);
167 ibe->ibe_name = malloc(namesz, M_BINMISC, M_WAITOK|M_ZERO);
168 strlcpy(ibe->ibe_name, xbe->xbe_name, namesz);
170 imgact_binmisc_populate_interp(xbe->xbe_interpreter, ibe);
172 ibe->ibe_magic = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO);
173 memcpy(ibe->ibe_magic, xbe->xbe_magic, xbe->xbe_msize);
175 ibe->ibe_mask = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO);
176 memcpy(ibe->ibe_mask, xbe->xbe_mask, xbe->xbe_msize);
178 ibe->ibe_moffset = xbe->xbe_moffset;
179 ibe->ibe_msize = xbe->xbe_msize;
180 ibe->ibe_flags = xbe->xbe_flags;
181 ibe->ibe_interp_offset = interp_offset;
182 ibe->ibe_argv0_cnt = argv0_cnt;
187 * Free the allocated memory for a given list item.
190 imgact_binmisc_destroy_entry(imgact_binmisc_entry_t *ibe)
195 free(ibe->ibe_magic, M_BINMISC);
197 free(ibe->ibe_mask, M_BINMISC);
198 if (ibe->ibe_interpreter)
199 free(ibe->ibe_interpreter, M_BINMISC);
201 free(ibe->ibe_name, M_BINMISC);
203 free(ibe, M_BINMISC);
207 * Find the interpreter in the list by the given name. Return NULL if not
210 static imgact_binmisc_entry_t *
211 imgact_binmisc_find_entry(char *name)
213 imgact_binmisc_entry_t *ibe;
215 INTERP_LIST_ASSERT_LOCKED();
217 SLIST_FOREACH(ibe, &interpreter_list, link) {
218 if (strncmp(name, ibe->ibe_name, IBE_NAME_MAX) == 0)
226 * Add the given interpreter if it doesn't already exist. Return EEXIST
227 * if the name already exist in the interpreter list.
230 imgact_binmisc_add_entry(ximgact_binmisc_entry_t *xbe)
232 imgact_binmisc_entry_t *ibe;
234 ssize_t interp_offset;
237 if (xbe->xbe_msize > IBE_MAGIC_MAX)
239 if (xbe->xbe_moffset + xbe->xbe_msize > IBE_MATCH_MAX)
242 for(cnt = 0, p = xbe->xbe_name; *p != 0; cnt++, p++)
243 if (cnt >= IBE_NAME_MAX || !isascii((int)*p))
246 for(cnt = 0, p = xbe->xbe_interpreter; *p != 0; cnt++, p++)
247 if (cnt >= IBE_INTERP_LEN_MAX || !isascii((int)*p))
250 /* Make sure we don't have any invalid #'s. */
251 p = xbe->xbe_interpreter;
254 while ((p = strchr(p, '#')) != NULL) {
269 /* Anything besides the above is invalid. */
275 if (imgact_binmisc_find_entry(xbe->xbe_name) != NULL) {
276 INTERP_LIST_WUNLOCK();
280 /* Preallocate a new entry. */
281 ibe = imgact_binmisc_new_entry(xbe, interp_offset, argv0_cnt);
283 SLIST_INSERT_HEAD(&interpreter_list, ibe, link);
284 interp_list_entry_count++;
285 INTERP_LIST_WUNLOCK();
291 * Remove the interpreter in the list with the given name. Return ENOENT
295 imgact_binmisc_remove_entry(char *name)
297 imgact_binmisc_entry_t *ibe;
300 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
301 INTERP_LIST_WUNLOCK();
304 SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry, link);
305 interp_list_entry_count--;
306 INTERP_LIST_WUNLOCK();
308 imgact_binmisc_destroy_entry(ibe);
314 * Disable the interpreter in the list with the given name. Return ENOENT
318 imgact_binmisc_disable_entry(char *name)
320 imgact_binmisc_entry_t *ibe;
323 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
324 INTERP_LIST_WUNLOCK();
328 ibe->ibe_flags &= ~IBF_ENABLED;
329 INTERP_LIST_WUNLOCK();
335 * Enable the interpreter in the list with the given name. Return ENOENT
339 imgact_binmisc_enable_entry(char *name)
341 imgact_binmisc_entry_t *ibe;
344 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
345 INTERP_LIST_WUNLOCK();
349 ibe->ibe_flags |= IBF_ENABLED;
350 INTERP_LIST_WUNLOCK();
356 imgact_binmisc_populate_xbe(ximgact_binmisc_entry_t *xbe,
357 imgact_binmisc_entry_t *ibe)
361 INTERP_LIST_ASSERT_LOCKED();
362 memset(xbe, 0, sizeof(*xbe));
363 strlcpy(xbe->xbe_name, ibe->ibe_name, IBE_NAME_MAX);
365 /* Copy interpreter string. Replace NULL breaks with space. */
366 memcpy(xbe->xbe_interpreter, ibe->ibe_interpreter,
367 ibe->ibe_interp_length);
368 for(i = 0; i < (ibe->ibe_interp_length - 1); i++)
369 if (xbe->xbe_interpreter[i] == '\0')
370 xbe->xbe_interpreter[i] = ' ';
372 memcpy(xbe->xbe_magic, ibe->ibe_magic, ibe->ibe_msize);
373 memcpy(xbe->xbe_mask, ibe->ibe_mask, ibe->ibe_msize);
374 xbe->xbe_version = IBE_VERSION;
375 xbe->xbe_flags = ibe->ibe_flags;
376 xbe->xbe_moffset = ibe->ibe_moffset;
377 xbe->xbe_msize = ibe->ibe_msize;
383 * Retrieve the interpreter with the give name and populate the
384 * ximgact_binmisc_entry structure. Return ENOENT if not found.
387 imgact_binmisc_lookup_entry(char *name, ximgact_binmisc_entry_t *xbe)
389 imgact_binmisc_entry_t *ibe;
393 if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
394 INTERP_LIST_RUNLOCK();
398 error = imgact_binmisc_populate_xbe(xbe, ibe);
399 INTERP_LIST_RUNLOCK();
405 * Get a snapshot of all the interpreter entries in the list.
408 imgact_binmisc_get_all_entries(struct sysctl_req *req)
410 ximgact_binmisc_entry_t *xbe, *xbep;
411 imgact_binmisc_entry_t *ibe;
412 int error = 0, count;
415 count = interp_list_entry_count;
416 xbe = malloc(sizeof(*xbe) * count, M_BINMISC, M_WAITOK|M_ZERO);
419 SLIST_FOREACH(ibe, &interpreter_list, link) {
420 error = imgact_binmisc_populate_xbe(xbep++, ibe);
424 INTERP_LIST_RUNLOCK();
427 error = SYSCTL_OUT(req, xbe, sizeof(*xbe) * count);
429 free(xbe, M_BINMISC);
434 * sysctl() handler for munipulating interpretor table.
435 * Not MP safe (locked by sysctl).
438 sysctl_kern_binmisc(SYSCTL_HANDLER_ARGS)
440 ximgact_binmisc_entry_t xbe;
445 /* Add an entry. Limited to IBE_MAX_ENTRIES. */
446 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
449 if (IBE_VERSION != xbe.xbe_version)
451 if ((xbe.xbe_flags & ~IBF_VALID_UFLAGS) != 0)
453 if (interp_list_entry_count == IBE_MAX_ENTRIES)
455 error = imgact_binmisc_add_entry(&xbe);
459 /* Remove an entry. */
460 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
463 if (IBE_VERSION != xbe.xbe_version)
465 error = imgact_binmisc_remove_entry(xbe.xbe_name);
469 /* Disable an entry. */
470 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
473 if (IBE_VERSION != xbe.xbe_version)
475 error = imgact_binmisc_disable_entry(xbe.xbe_name);
479 /* Enable an entry. */
480 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
483 if (IBE_VERSION != xbe.xbe_version)
485 error = imgact_binmisc_enable_entry(xbe.xbe_name);
489 /* Lookup an entry. */
490 error = SYSCTL_IN(req, &xbe, sizeof(xbe));
493 if (IBE_VERSION != xbe.xbe_version)
495 error = imgact_binmisc_lookup_entry(xbe.xbe_name, &xbe);
497 error = SYSCTL_OUT(req, &xbe, sizeof(xbe));
501 /* Return a snapshot of the interpretor list. */
504 /* No pointer then just return the list size. */
505 error = SYSCTL_OUT(req, 0, interp_list_entry_count *
506 sizeof(ximgact_binmisc_entry_t));
512 error = imgact_binmisc_get_all_entries(req);
522 SYSCTL_NODE(_kern, OID_AUTO, binmisc, CTLFLAG_RW | CTLFLAG_MPSAFE, 0,
523 "Image activator for miscellaneous binaries");
525 SYSCTL_PROC(_kern_binmisc, OID_AUTO, add,
526 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ADD,
527 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
528 "Add an activator entry");
530 SYSCTL_PROC(_kern_binmisc, OID_AUTO, remove,
531 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_REMOVE,
532 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
533 "Remove an activator entry");
535 SYSCTL_PROC(_kern_binmisc, OID_AUTO, disable,
536 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_DISABLE,
537 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
538 "Disable an activator entry");
540 SYSCTL_PROC(_kern_binmisc, OID_AUTO, enable,
541 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ENABLE,
542 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
543 "Enable an activator entry");
545 SYSCTL_PROC(_kern_binmisc, OID_AUTO, lookup,
546 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RW|CTLFLAG_ANYBODY, NULL, IBC_LOOKUP,
547 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
548 "Lookup an activator entry");
550 SYSCTL_PROC(_kern_binmisc, OID_AUTO, list,
551 CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RD|CTLFLAG_ANYBODY, NULL, IBC_LIST,
552 sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
553 "Get snapshot of all the activator entries");
555 static imgact_binmisc_entry_t *
556 imgact_binmisc_find_interpreter(const char *image_header)
558 imgact_binmisc_entry_t *ibe;
563 INTERP_LIST_ASSERT_LOCKED();
565 SLIST_FOREACH(ibe, &interpreter_list, link) {
566 if (!(IBF_ENABLED & ibe->ibe_flags))
569 p = image_header + ibe->ibe_moffset;
571 if (IBF_USE_MASK & ibe->ibe_flags) {
572 /* Compare using mask. */
573 for (i = 0; i < sz; i++)
574 if ((*p++ ^ ibe->ibe_magic[i]) &
578 for (i = 0; i < sz; i++)
579 if (*p++ ^ ibe->ibe_magic[i])
582 if (i == ibe->ibe_msize)
589 imgact_binmisc_exec(struct image_params *imgp)
591 const char *image_header = imgp->image_header;
592 const char *fname = NULL;
597 size_t namelen, offset;
598 imgact_binmisc_entry_t *ibe;
604 /* Do we have an interpreter for the given image header? */
606 if ((ibe = imgact_binmisc_find_interpreter(image_header)) == NULL) {
611 /* No interpreter nesting allowed. */
612 if (imgp->interpreted & IMGACT_BINMISC) {
617 imgp->interpreted |= IMGACT_BINMISC;
620 * Don't bother with the overhead of putting fname together if we're not
623 if (ibe->ibe_argv0_cnt != 0) {
624 if (imgp->args->fname != NULL) {
625 fname = imgp->args->fname;
627 /* Use the fdescfs(5) path for fexecve(2). */
628 sname = sbuf_new_auto();
629 sbuf_printf(sname, "/dev/fd/%d", imgp->args->fd);
631 fname = sbuf_data(sname);
634 namelen = strlen(fname);
638 * We need to "push" the interpreter in the arg[] list. To do this,
639 * we first shift all the other values in the `begin_argv' area to
640 * provide the exact amount of room for the values added. Set up
641 * `offset' as the number of bytes to be added to the `begin_argv'
642 * area. ibe_interp_offset is the fixed offset from macros present in
643 * the interpreter string.
645 offset = ibe->ibe_interp_length + ibe->ibe_interp_offset;
647 /* Variable offset to be added from macros to the interpreter string. */
648 MPASS(ibe->ibe_argv0_cnt == 0 || namelen > 0);
649 offset += ibe->ibe_argv0_cnt * (namelen - 2);
651 /* Make room for the interpreter */
652 error = exec_args_adjust_args(imgp->args, 0, offset);
657 /* Add the new argument(s) in the count. */
658 imgp->args->argc += ibe->ibe_interp_argcnt;
661 * The original arg[] list has been shifted appropriately. Copy in
662 * the interpreter path.
664 s = ibe->ibe_interpreter;
665 d = imgp->args->begin_argv;
669 /* Handle "#" in interpreter string. */
673 /* "##": Replace with a single '#' */
677 /* "#a": Replace with old arg0 (fname). */
678 MPASS(ibe->ibe_argv0_cnt >= ++argv0_cnt);
679 memcpy(d, fname, namelen);
683 __assert_unreachable();
687 /* Replace space with NUL to separate arguments. */
698 /* Catch ibe->ibe_argv0_cnt counting more #a than we did. */
699 MPASS(ibe->ibe_argv0_cnt == argv0_cnt);
700 imgp->interpreter_name = imgp->args->begin_argv;
703 INTERP_LIST_RUNLOCK();
710 imgact_binmisc_init(void *arg)
713 INTERP_LIST_LOCK_INIT();
717 imgact_binmisc_fini(void *arg)
719 imgact_binmisc_entry_t *ibe, *ibe_tmp;
721 /* Free all the interpreters. */
723 SLIST_FOREACH_SAFE(ibe, &interpreter_list, link, ibe_tmp) {
724 SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry,
726 imgact_binmisc_destroy_entry(ibe);
728 INTERP_LIST_WUNLOCK();
730 INTERP_LIST_LOCK_DESTROY();
733 SYSINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_init,
735 SYSUNINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_fini,
739 * Tell kern_execve.c about it, with a little help from the linker.
741 static struct execsw imgact_binmisc_execsw = {
742 .ex_imgact = imgact_binmisc_exec,
745 EXEC_SET(imgact_binmisc, imgact_binmisc_execsw);