|
|
d5c145 |
diff -rup a/ltrace-elf.c b/ltrace-elf.c
|
|
|
d5c145 |
--- a/ltrace-elf.c 2019-02-28 17:32:49.873659818 -0500
|
|
|
d5c145 |
+++ b/ltrace-elf.c 2019-02-28 17:36:32.426779439 -0500
|
|
|
d5c145 |
@@ -639,7 +639,21 @@ ltelf_read_elf(struct ltelf *lte, const
|
|
|
d5c145 |
}
|
|
|
d5c145 |
} else if (shdr.sh_type == SHT_PROGBITS
|
|
|
d5c145 |
|| shdr.sh_type == SHT_NOBITS) {
|
|
|
d5c145 |
- if (strcmp(name, ".plt") == 0) {
|
|
|
d5c145 |
+ if (strcmp(name, ".plt") == 0
|
|
|
d5c145 |
+ && lte->second_plt_seen == 0) {
|
|
|
d5c145 |
+ lte->plt_addr = shdr.sh_addr;
|
|
|
d5c145 |
+ lte->plt_size = shdr.sh_size;
|
|
|
d5c145 |
+ lte->plt_data = elf_loaddata(scn, &shdr);
|
|
|
d5c145 |
+ if (lte->plt_data == NULL)
|
|
|
d5c145 |
+ fprintf(stderr,
|
|
|
d5c145 |
+ "Can't load .plt data\n");
|
|
|
d5c145 |
+ lte->plt_flags = shdr.sh_flags;
|
|
|
d5c145 |
+ }
|
|
|
d5c145 |
+ /* An Intel CET binary has two PLTs; the
|
|
|
d5c145 |
+ initial PLTGOT points to the second
|
|
|
d5c145 |
+ one. */
|
|
|
d5c145 |
+ else if (strcmp(name, ".plt.sec") == 0) {
|
|
|
d5c145 |
+ lte->second_plt_seen = 1;
|
|
|
d5c145 |
lte->plt_addr = shdr.sh_addr;
|
|
|
d5c145 |
lte->plt_size = shdr.sh_size;
|
|
|
d5c145 |
lte->plt_data = elf_loaddata(scn, &shdr);
|
|
|
d5c145 |
diff -rup a/ltrace-elf.h b/ltrace-elf.h
|
|
|
d5c145 |
--- a/ltrace-elf.h 2019-02-28 17:32:49.874660328 -0500
|
|
|
d5c145 |
+++ b/ltrace-elf.h 2019-02-28 17:36:32.428779868 -0500
|
|
|
d5c145 |
@@ -45,6 +45,7 @@ struct ltelf {
|
|
|
d5c145 |
Elf_Data *dynsym;
|
|
|
d5c145 |
size_t dynsym_count;
|
|
|
d5c145 |
const char *dynstr;
|
|
|
d5c145 |
+ int second_plt_seen;
|
|
|
d5c145 |
GElf_Addr plt_addr;
|
|
|
d5c145 |
GElf_Word plt_flags;
|
|
|
d5c145 |
size_t plt_size;
|
|
|
d5c145 |
diff -rup a/sysdeps/linux-gnu/x86/plt.c b/sysdeps/linux-gnu/x86/plt.c
|
|
|
d5c145 |
--- a/sysdeps/linux-gnu/x86/plt.c 2019-02-28 17:32:49.991720041 -0500
|
|
|
d5c145 |
+++ b/sysdeps/linux-gnu/x86/plt.c 2019-02-28 17:36:32.429780083 -0500
|
|
|
d5c145 |
@@ -28,18 +28,18 @@
|
|
|
d5c145 |
#include "trace.h"
|
|
|
d5c145 |
|
|
|
d5c145 |
static GElf_Addr
|
|
|
d5c145 |
-x86_plt_offset(uint32_t i)
|
|
|
d5c145 |
+x86_plt_offset(struct ltelf *lte, uint32_t i)
|
|
|
d5c145 |
{
|
|
|
d5c145 |
/* Skip the first PLT entry, which contains a stub to call the
|
|
|
d5c145 |
* resolver. */
|
|
|
d5c145 |
- return (i + 1) * 16;
|
|
|
d5c145 |
+ return (i + (lte->second_plt_seen ? 0 : 1)) * 16;
|
|
|
d5c145 |
}
|
|
|
d5c145 |
|
|
|
d5c145 |
GElf_Addr
|
|
|
d5c145 |
arch_plt_sym_val(struct ltelf *lte, size_t ndx, GElf_Rela *rela)
|
|
|
d5c145 |
{
|
|
|
d5c145 |
uint32_t i = *VECT_ELEMENT(<e->arch.plt_map, uint32_t, ndx);
|
|
|
d5c145 |
- return x86_plt_offset(i) + lte->plt_addr;
|
|
|
d5c145 |
+ return x86_plt_offset(lte, i) + lte->plt_addr;
|
|
|
d5c145 |
}
|
|
|
d5c145 |
|
|
|
d5c145 |
void *
|
|
|
d5c145 |
@@ -116,6 +116,13 @@ arch_elf_init(struct ltelf *lte, struct
|
|
|
d5c145 |
* 400426: 68 00 00 00 00 pushq $0x0
|
|
|
d5c145 |
* 40042b: e9 e0 ff ff ff jmpq 400410 <_init+0x18>
|
|
|
d5c145 |
*
|
|
|
d5c145 |
+ * For CET binaries it is the following:
|
|
|
d5c145 |
+ *
|
|
|
d5c145 |
+ * 13d0: f3 0f 1e fa endbr64
|
|
|
d5c145 |
+ * 13d4: 68 27 00 00 00 pushq $0x27 <-- index
|
|
|
d5c145 |
+ * 13d9: f2 e9 71 fd ff ff bnd jmpq 1150 <.plt>
|
|
|
d5c145 |
+ * 13df: 90 nop
|
|
|
d5c145 |
+ *
|
|
|
d5c145 |
* On i386, the argument to push is an offset of relocation to
|
|
|
d5c145 |
* use. The first PLT slot has an offset of 0x0, the second
|
|
|
d5c145 |
* 0x8, etc. On x86_64, it's directly the index that we are
|
|
|
d5c145 |
@@ -128,11 +135,33 @@ arch_elf_init(struct ltelf *lte, struct
|
|
|
d5c145 |
unsigned int i, sz = vect_size(<e->plt_relocs);
|
|
|
d5c145 |
for (i = 0; i < sz; ++i) {
|
|
|
d5c145 |
|
|
|
d5c145 |
- GElf_Addr offset = x86_plt_offset(i);
|
|
|
d5c145 |
+ GElf_Addr offset = x86_plt_offset(lte, i);
|
|
|
d5c145 |
+ uint32_t reloc_arg;
|
|
|
d5c145 |
|
|
|
d5c145 |
uint8_t byte;
|
|
|
d5c145 |
- if (elf_read_next_u8(lte->plt_data, &offset, &byte) < 0
|
|
|
d5c145 |
- || byte != 0xff
|
|
|
d5c145 |
+ if (elf_read_next_u8(lte->plt_data, &offset, &byte) < 0)
|
|
|
d5c145 |
+ continue;
|
|
|
d5c145 |
+
|
|
|
d5c145 |
+
|
|
|
d5c145 |
+ if (byte == 0xf3
|
|
|
d5c145 |
+ && elf_read_next_u8(lte->plt_data, &offset, &byte) >= 0
|
|
|
d5c145 |
+ && byte == 0x0f
|
|
|
d5c145 |
+ && elf_read_next_u8(lte->plt_data, &offset, &byte) >= 0
|
|
|
d5c145 |
+ && byte == 0x1e
|
|
|
d5c145 |
+ && elf_read_next_u8(lte->plt_data, &offset, &byte) >= 0
|
|
|
d5c145 |
+ && byte == 0xfa
|
|
|
d5c145 |
+ && elf_read_next_u8(lte->plt_data, &offset, &byte) >= 0
|
|
|
d5c145 |
+ && byte == 0x68
|
|
|
d5c145 |
+ && elf_read_next_u32(lte->plt_data,
|
|
|
d5c145 |
+ &offset, &reloc_arg) >= 0)
|
|
|
d5c145 |
+ {
|
|
|
d5c145 |
+ /* CET */
|
|
|
d5c145 |
+ fprintf(stderr, "%d: reloc_arg is %lx\n", i, (long)reloc_arg);
|
|
|
d5c145 |
+ *VECT_ELEMENT(<e->arch.plt_map, unsigned int, reloc_arg) = i;
|
|
|
d5c145 |
+ continue;
|
|
|
d5c145 |
+ }
|
|
|
d5c145 |
+
|
|
|
d5c145 |
+ if (byte != 0xff
|
|
|
d5c145 |
|| elf_read_next_u8(lte->plt_data, &offset, &byte) < 0
|
|
|
d5c145 |
|| (byte != 0xa3 && byte != 0x25))
|
|
|
d5c145 |
continue;
|
|
|
d5c145 |
@@ -140,7 +169,6 @@ arch_elf_init(struct ltelf *lte, struct
|
|
|
d5c145 |
/* Skip immediate argument in the instruction. */
|
|
|
d5c145 |
offset += 4;
|
|
|
d5c145 |
|
|
|
d5c145 |
- uint32_t reloc_arg;
|
|
|
d5c145 |
if (elf_read_next_u8(lte->plt_data, &offset, &byte) < 0
|
|
|
d5c145 |
|| byte != 0x68
|
|
|
d5c145 |
|| elf_read_next_u32(lte->plt_data,
|