aboutsummaryrefslogtreecommitdiffhomepage
path: root/index.html
diff options
context:
space:
mode:
authorjohannst <johannst@users.noreply.github.com>2020-03-17 22:48:49 +0000
committerjohannst <johannst@users.noreply.github.com>2020-03-17 22:48:49 +0000
commit2a064a9d1bbb8de6ce489b685cce026eee167cd2 (patch)
tree123cdb825636f0bfe98ef152ace16eb8b3ae2647 /index.html
parent21e8db012f8c46f75e43a40da3f3e2676363c291 (diff)
downloadnotes-2a064a9d1bbb8de6ce489b685cce026eee167cd2.tar.gz
notes-2a064a9d1bbb8de6ce489b685cce026eee167cd2.zip
deploy: fb719f52b73920fb18c7f3080ebb1fc73300be49
Diffstat (limited to 'index.html')
-rw-r--r--index.html177
1 files changed, 94 insertions, 83 deletions
diff --git a/index.html b/index.html
index 425ada7..16c39ba 100644
--- a/index.html
+++ b/index.html
@@ -81,7 +81,7 @@
<nav id="sidebar" class="sidebar" aria-label="Table of contents">
<div id="sidebar-scrollbox" class="sidebar-scrollbox">
- <ol class="chapter"><li class="expanded "><a href="ld.so.html"><strong aria-hidden="true">1.</strong> ld.so</a></li><li class="expanded "><a href="git.html"><strong aria-hidden="true">2.</strong> git</a></li><li class="expanded "><a href="gdb.html"><strong aria-hidden="true">3.</strong> gdb</a></li><li class="expanded "><a href="radare2.html"><strong aria-hidden="true">4.</strong> radare2</a></li><li class="expanded "><a href="emacs.html"><strong aria-hidden="true">5.</strong> emacs</a></li><li class="expanded "><a href="fish.html"><strong aria-hidden="true">6.</strong> fish</a></li><li class="expanded "><a href="strace.html"><strong aria-hidden="true">7.</strong> strace</a></li><li class="expanded "><a href="lsof.html"><strong aria-hidden="true">8.</strong> lsof</a></li><li class="expanded "><a href="pidstat.html"><strong aria-hidden="true">9.</strong> pidstat</a></li><li class="expanded "><a href="time.html"><strong aria-hidden="true">10.</strong> time</a></li><li class="expanded "><a href="pmap.html"><strong aria-hidden="true">11.</strong> pmap</a></li><li class="expanded "><a href="pstack.html"><strong aria-hidden="true">12.</strong> pstack</a></li><li class="expanded "><a href="perf.html"><strong aria-hidden="true">13.</strong> perf</a></li><li class="expanded "><a href="oprofile.html"><strong aria-hidden="true">14.</strong> OProfile</a></li><li class="expanded "><a href="od.html"><strong aria-hidden="true">15.</strong> od</a></li><li class="expanded "><a href="xxd.html"><strong aria-hidden="true">16.</strong> xxd</a></li><li class="expanded "><a href="readelf.html"><strong aria-hidden="true">17.</strong> readelf</a></li><li class="expanded "><a href="objdump.html"><strong aria-hidden="true">18.</strong> objdump</a></li><li class="expanded "><a href="nm.html"><strong aria-hidden="true">19.</strong> nm</a></li><li class="expanded "><a href="c++filt.html"><strong aria-hidden="true">20.</strong> c++filt</a></li></ol>
+ <ol class="chapter"><li class="expanded "><a href="ld.so.html"><strong aria-hidden="true">1.</strong> ld.so</a></li><li class="expanded "><a href="git.html"><strong aria-hidden="true">2.</strong> git</a></li><li class="expanded "><a href="awk.html"><strong aria-hidden="true">3.</strong> awk</a></li><li class="expanded "><a href="gdb.html"><strong aria-hidden="true">4.</strong> gdb</a></li><li class="expanded "><a href="radare2.html"><strong aria-hidden="true">5.</strong> radare2</a></li><li class="expanded "><a href="emacs.html"><strong aria-hidden="true">6.</strong> emacs</a></li><li class="expanded "><a href="fish.html"><strong aria-hidden="true">7.</strong> fish</a></li><li class="expanded "><a href="strace.html"><strong aria-hidden="true">8.</strong> strace</a></li><li class="expanded "><a href="lsof.html"><strong aria-hidden="true">9.</strong> lsof</a></li><li class="expanded "><a href="pidstat.html"><strong aria-hidden="true">10.</strong> pidstat</a></li><li class="expanded "><a href="time.html"><strong aria-hidden="true">11.</strong> time</a></li><li class="expanded "><a href="pgrep.html"><strong aria-hidden="true">12.</strong> pgrep</a></li><li class="expanded "><a href="pstack.html"><strong aria-hidden="true">13.</strong> pstack</a></li><li class="expanded "><a href="pstack.html"><strong aria-hidden="true">14.</strong> pstack</a></li><li class="expanded "><a href="perf.html"><strong aria-hidden="true">15.</strong> perf</a></li><li class="expanded "><a href="oprofile.html"><strong aria-hidden="true">16.</strong> OProfile</a></li><li class="expanded "><a href="od.html"><strong aria-hidden="true">17.</strong> od</a></li><li class="expanded "><a href="xxd.html"><strong aria-hidden="true">18.</strong> xxd</a></li><li class="expanded "><a href="readelf.html"><strong aria-hidden="true">19.</strong> readelf</a></li><li class="expanded "><a href="objdump.html"><strong aria-hidden="true">20.</strong> objdump</a></li><li class="expanded "><a href="nm.html"><strong aria-hidden="true">21.</strong> nm</a></li><li class="expanded "><a href="c++filt.html"><strong aria-hidden="true">22.</strong> c++filt</a></li></ol>
</div>
<div id="sidebar-resize-handle" class="sidebar-resize-handle"></div>
</nav>
@@ -149,16 +149,18 @@
<div id="content" class="content">
<main>
<h1><a class="header" href="#ldso8" id="ldso8">ld.so(8)</a></h1>
-<h2><a class="header" href="#environment-variables" id="environment-variables">Environment variables</a></h2>
+<h2><a class="header" href="#environment-variables" id="environment-variables">Environment Variables</a></h2>
<pre><code class="language-console"> LD_PRELOAD=&lt;l_so&gt; colon separated list of libso's to be pre loaded
- LD_DEBUG=&lt;opts&gt; comman separated list of debug options
+ LD_DEBUG=&lt;opts&gt; comma separated list of debug options
=help list available options
=libs show library search path
=files processing of input files
=symbols show search path for symbol lookup
=bindings show against which definition a symbol is bound
</code></pre>
-<h2><a class="header" href="#ld_preload-load--init-order" id="ld_preload-load--init-order">LD_PRELOAD load &amp; init order</a></h2>
+<h2><a class="header" href="#ld_preload-initialization-order-and-link-map" id="ld_preload-initialization-order-and-link-map">LD_PRELOAD: Initialization Order and Link Map</a></h2>
+<p>Libraries specified in <code>LD_PRELOAD</code> are loaded from <code>left-to-right</code> but
+initialized from <code>right-to-left</code>.</p>
<pre><code class="language-markdown"> &gt; ldd ./main
&gt;&gt; libc.so.6 =&gt; /usr/lib/libc.so.6
@@ -167,87 +169,96 @@
preloaded in this order
&lt;--
initialized in this order
-
- - preload order determines the order libs are inserted into the link map
-
- - resulting link map:
- +------+ +------+ +------+ +------+
- | main | -&gt; | liba | -&gt; | libb | -&gt; | libc |
- +------+ +------+ +------+ +------+
-
- - see preload and init order in action
- &gt; LD_DEBUG=files LD_PRELOAD=liba.so:libb.so ./main
- # load order (-&gt; determines link map)
- &gt;&gt; file=liba.so [0]; generating link map
- &gt;&gt; file=libb.so [0]; generating link map
- &gt;&gt; file=libc.so.6 [0]; generating link map
-
- # init order
- &gt;&gt; calling init: /usr/lib/libc.so.6
- &gt;&gt; calling init: &lt;path&gt;/libb.so
- &gt;&gt; calling init: &lt;path&gt;/liba.so
- &gt;&gt; initialize program: ./main
-
- - see the symbol lookup in action and therefore the link map order
- &gt; LD_DEBUG=symbols,bindings LD_PRELOAD=liba.so:libb.so ./main
- &gt;&gt; symbol=memcpy; lookup in file=./main [0]
- &gt;&gt; symbol=memcpy; lookup in file=&lt;path&gt;/liba.so [0]
- &gt;&gt; symbol=memcpy; lookup in file=&lt;path&gt;/libb.so [0]
- &gt;&gt; symbol=memcpy; lookup in file=/usr/lib/libc.so.6 [0]
- &gt;&gt; binding file ./main [0] to /usr/lib/libc.so.6 [0]: normal symbol
- `memcpy' [GLIBC_2.14]
</code></pre>
-<h2><a class="header" href="#dynamic-linking-x86_64" id="dynamic-linking-x86_64">dynamic linking (x86_64)</a></h2>
-<pre><code class="language-makrdown"> - dynamic linking basically works via one indirect jump. It uses a
- combination of function trampolines (.plt) and a function pointer table
- (.got.plt). On the first call the trampoline sets up some metadata and
- then jumps to the ld.so runtime resolve function, which in turn patches
- the table with the correct function pointer.
- .plt ....... contains function trampolines, usually located in code
- segment (rx permission)
- .got.plt ... hold the function pointer table
-
- - following r2 dump shows this
- - [0x00401030] indirect jump for 'puts' using function pointer in
- _GLOBAL_OFFSET_TABLE_[3]
- - initially points to instruction behind 'puts' trampoline [0x00401036]
- - this pushes relocation index and then jumps to the first trampoline
- [0x00401020]
- - the first trampoline jumps to _GLOBAL_OFFSET_TABLE_[2] which will be
- filled at program startup by the ld.so with its resolve function
- - the resolve function fixes the relocation referenced by the
- relocation index pushed by the 'puts' trampoline
- - the relocation entry tells the resolve function which symbol to
- search for and where to put the function pointer
- &gt; readelf -r &lt;main&gt;
- &gt;&gt; Relocation section '.rela.plt' at offset 0x4b8 contains 1 entry:
- &gt;&gt; Offset Info Type Sym. Value Sym. Name + Addend
- &gt;&gt; 000000404018 000200000007 R_X86_64_JUMP_SLO 0000000000000000 puts@GLIBC_2.2.5 + 0
- - offset points to _GLOBAL_OFFSET_TABLE_[3]
-
- [0x00401040]&gt; pd 4 @ section..got.plt
- ;-- section..got.plt:
- ;-- .got.plt: ; [22] -rw- section size 32 named .got.plt
- ;-- _GLOBAL_OFFSET_TABLE_:
- 0x00404000 .qword 0x0000000000403e10 ; section..dynamic ; obj._DYNAMIC
- 0x00404008 .qword 0x0000000000000000
- ; CODE XREF from section..plt @ +0x6
- 0x00404010 .qword 0x0000000000000000
- ;-- reloc.puts:
- ; CODE XREF from sym.imp.puts @ 0x401030
- 0x00404018 .qword 0x0000000000401036 ; RELOC 64 puts
-
- [0x00401040]&gt; pd 6 @ section..plt
- ;-- section..plt:
- ;-- .plt: ; [12] -r-x section size 32 named .plt
- ┌─&gt; 0x00401020 ff35e22f0000 push qword [0x00404008]
- ╎ 0x00401026 ff25e42f0000 jmp qword [0x00404010]
- ╎ 0x0040102c 0f1f4000 nop dword [rax]
- ┌ 6: int sym.imp.puts (const char *s);
- └ ╎ 0x00401030 ff25e22f0000 jmp qword [reloc.puts]
- ╎ 0x00401036 6800000000 push 0
- └─&lt; 0x0040103b e9e0ffffff jmp sym..plt
+<p>The preload order determines:</p>
+<ul>
+<li>the order libraries are inserted into the <code>link map</code></li>
+<li>the initialization order for libraries</li>
+</ul>
+<p>For the example listed above the resulting <code>link map</code> will look like the
+following:</p>
+<pre><code class="language-makrdown"> +------+ +------+ +------+ +------+
+ | main | -&gt; | liba | -&gt; | libb | -&gt; | libc |
+ +------+ +------+ +------+ +------+
+</code></pre>
+<p>This can be seen when running with <code>LD_DEBUG=files</code>:</p>
+<pre><code class="language-makrdown"> &gt; LD_DEBUG=files LD_PRELOAD=liba.so:libb.so ./main
+ # load order (-&gt; determines link map)
+ &gt;&gt; file=liba.so [0]; generating link map
+ &gt;&gt; file=libb.so [0]; generating link map
+ &gt;&gt; file=libc.so.6 [0]; generating link map
+
+ # init order
+ &gt;&gt; calling init: /usr/lib/libc.so.6
+ &gt;&gt; calling init: &lt;path&gt;/libb.so
+ &gt;&gt; calling init: &lt;path&gt;/liba.so
+ &gt;&gt; initialize program: ./main
+</code></pre>
+<p>To verify the <code>link map</code> order we let <code>ld.so</code> resolve the <code>memcpy(3)</code> libc
+symbol (used in <em>main</em>) dynamically, while enabling <code>LD_DEBUG=symbols,bindings</code>
+to see the resolving in action.</p>
+<pre><code class="language-makrdown"> &gt; LD_DEBUG=symbols,bindings LD_PRELOAD=liba.so:libb.so ./main
+ &gt;&gt; symbol=memcpy; lookup in file=./main [0]
+ &gt;&gt; symbol=memcpy; lookup in file=&lt;path&gt;/liba.so [0]
+ &gt;&gt; symbol=memcpy; lookup in file=&lt;path&gt;/libb.so [0]
+ &gt;&gt; symbol=memcpy; lookup in file=/usr/lib/libc.so.6 [0]
+ &gt;&gt; binding file ./main [0] to /usr/lib/libc.so.6 [0]: normal symbol `memcpy' [GLIBC_2.14]
+</code></pre>
+<h2><a class="header" href="#dynamic-linking-x86_64" id="dynamic-linking-x86_64">Dynamic Linking (x86_64)</a></h2>
+<p>Dynamic linking basically works via one indirect jump. It uses a combination of
+function trampolines (<code>.plt</code> section) and a function pointer table (<code>.got.plt</code>
+section).
+On the first call the trampoline sets up some metadata and then jumps to the
+<code>ld.so</code> runtime resolve function, which in turn patches the table with the
+correct function pointer.</p>
+<pre><code class="language-makrdown"> .plt ....... procedure linkage table, contains function trampolines, usually
+ located in code segment (rx permission)
+ .got.plt ... global offset table for .plt, holds the function pointer table
+</code></pre>
+<p>Using <code>radare2</code> we can analyze this in more detail:</p>
+<pre><code class="language-makrdown"> [0x00401040]&gt; pd 4 @ section..got.plt
+ ;-- section..got.plt:
+ ;-- .got.plt: ; [22] -rw- section size 32 named .got.plt
+ ;-- _GLOBAL_OFFSET_TABLE_:
+ [0] 0x00404000 .qword 0x0000000000403e10 ; section..dynamic
+ [1] 0x00404008 .qword 0x0000000000000000
+ ; CODE XREF from section..plt @ +0x6
+ [2] 0x00404010 .qword 0x0000000000000000
+ ;-- reloc.puts:
+ ; CODE XREF from sym.imp.puts @ 0x401030
+ [3] 0x00404018 .qword 0x0000000000401036 ; RELOC 64 puts
+
+ [0x00401040]&gt; pd 6 @ section..plt
+ ;-- section..plt:
+ ;-- .plt: ; [12] -r-x section size 32 named .plt
+ ┌─&gt; 0x00401020 ff35e22f0000 push qword [0x00404008]
+ ╎ 0x00401026 ff25e42f0000 jmp qword [0x00404010]
+ ╎ 0x0040102c 0f1f4000 nop dword [rax]
+ ┌ 6: int sym.imp.puts (const char *s);
+ └ ╎ 0x00401030 ff25e22f0000 jmp qword [reloc.puts]
+ ╎ 0x00401036 6800000000 push 0
+ └─&lt; 0x0040103b e9e0ffffff jmp sym..plt
+</code></pre>
+<ul>
+<li>At address <code>0x00401030</code> in the <code>.plt</code> section we see the indirect jump for
+<code>puts</code> using the function pointer in <code>_GLOBAL_OFFSET_TABLE_[3] (GOT)</code>.</li>
+<li><code>GOT[3]</code> initially points to instruction after the <code>puts</code> trampoline
+<code>0x00401036</code>.</li>
+<li>This pushes the relocation index <code>0</code> and then jumps to the first trampoline
+<code>0x00401020</code>.</li>
+<li>The first trampoline jumps to <code>GOT[2]</code> which will be filled at program
+startup by the <code>ld.so</code> with its resolve function.</li>
+<li>The <code>ld.so</code> resolve function fixes the relocation referenced by the
+relocation index pushed by the <code>puts</code> trampoline.</li>
+<li>The relocation entry at index <code>0</code> tells the resolve function which symbol to
+search for and where to put the function pointer:
+<pre><code class="language-makrdown"> &gt; readelf -r &lt;main&gt;
+ &gt;&gt; Relocation section '.rela.plt' at offset 0x4b8 contains 1 entry:
+ &gt;&gt; Offset Info Type Sym. Value Sym. Name + Addend
+ &gt;&gt; 000000404018 000200000007 R_X86_64_JUMP_SLO 0000000000000000 puts@GLIBC_2.2.5 + 0
</code></pre>
+As we can see the offset from relocation at index <code>0</code> points to <code>GOT[3]</code>.</li>
+</ul>
</main>