17509ff7cSJens Wiklander // SPDX-License-Identifier: BSD-2-Clause 27509ff7cSJens Wiklander /* 37509ff7cSJens Wiklander * Copyright (c) 2019, Linaro Limited 47509ff7cSJens Wiklander */ 57509ff7cSJens Wiklander 67509ff7cSJens Wiklander #include <assert.h> 77509ff7cSJens Wiklander #include <ctype.h> 87509ff7cSJens Wiklander #include <elf32.h> 97509ff7cSJens Wiklander #include <elf64.h> 107509ff7cSJens Wiklander #include <elf_common.h> 1165137432SJens Wiklander #include <ldelf.h> 127509ff7cSJens Wiklander #include <pta_system.h> 1365137432SJens Wiklander #include <stdio.h> 147509ff7cSJens Wiklander #include <stdlib.h> 157509ff7cSJens Wiklander #include <string_ext.h> 167509ff7cSJens Wiklander #include <string.h> 177509ff7cSJens Wiklander #include <tee_api_types.h> 187509ff7cSJens Wiklander #include <user_ta_header.h> 19*6720dd49SJens Wiklander #include <utee_syscalls.h> 207509ff7cSJens Wiklander 217509ff7cSJens Wiklander #include "sys.h" 227509ff7cSJens Wiklander #include "ta_elf.h" 230242833aSJens Wiklander #include "unwind.h" 247509ff7cSJens Wiklander 2565137432SJens Wiklander static vaddr_t ta_stack; 260242833aSJens Wiklander static vaddr_t ta_stack_size; 2765137432SJens Wiklander 287509ff7cSJens Wiklander struct ta_elf_queue main_elf_queue = TAILQ_HEAD_INITIALIZER(main_elf_queue); 297509ff7cSJens Wiklander 307509ff7cSJens Wiklander static struct ta_elf *queue_elf(const TEE_UUID *uuid) 317509ff7cSJens Wiklander { 327509ff7cSJens Wiklander struct ta_elf *elf = NULL; 337509ff7cSJens Wiklander 347509ff7cSJens Wiklander TAILQ_FOREACH(elf, &main_elf_queue, link) 357509ff7cSJens Wiklander if (!memcmp(uuid, &elf->uuid, sizeof(*uuid))) 367509ff7cSJens Wiklander return NULL; 377509ff7cSJens Wiklander 387509ff7cSJens Wiklander elf = calloc(1, sizeof(*elf)); 397509ff7cSJens Wiklander if (!elf) 407509ff7cSJens Wiklander err(TEE_ERROR_OUT_OF_MEMORY, "calloc"); 417509ff7cSJens Wiklander 427509ff7cSJens Wiklander TAILQ_INIT(&elf->segs); 437509ff7cSJens Wiklander 447509ff7cSJens Wiklander elf->uuid = *uuid; 457509ff7cSJens Wiklander TAILQ_INSERT_TAIL(&main_elf_queue, elf, link); 467509ff7cSJens Wiklander return elf; 477509ff7cSJens Wiklander } 487509ff7cSJens Wiklander 497509ff7cSJens Wiklander static TEE_Result e32_parse_ehdr(struct ta_elf *elf, Elf32_Ehdr *ehdr) 507509ff7cSJens Wiklander { 517509ff7cSJens Wiklander if (ehdr->e_ident[EI_VERSION] != EV_CURRENT || 527509ff7cSJens Wiklander ehdr->e_ident[EI_CLASS] != ELFCLASS32 || 537509ff7cSJens Wiklander ehdr->e_ident[EI_DATA] != ELFDATA2LSB || 547509ff7cSJens Wiklander ehdr->e_ident[EI_OSABI] != ELFOSABI_NONE || 557509ff7cSJens Wiklander ehdr->e_type != ET_DYN || ehdr->e_machine != EM_ARM || 567509ff7cSJens Wiklander (ehdr->e_flags & EF_ARM_ABIMASK) != EF_ARM_ABI_VERSION || 577509ff7cSJens Wiklander #ifndef CFG_WITH_VFP 587509ff7cSJens Wiklander (ehdr->e_flags & EF_ARM_ABI_FLOAT_HARD) || 597509ff7cSJens Wiklander #endif 607509ff7cSJens Wiklander ehdr->e_phentsize != sizeof(Elf32_Phdr) || 617509ff7cSJens Wiklander ehdr->e_shentsize != sizeof(Elf32_Shdr)) 627509ff7cSJens Wiklander return TEE_ERROR_BAD_FORMAT; 637509ff7cSJens Wiklander 647509ff7cSJens Wiklander elf->is_32bit = true; 657509ff7cSJens Wiklander elf->e_entry = ehdr->e_entry; 667509ff7cSJens Wiklander elf->e_phoff = ehdr->e_phoff; 677509ff7cSJens Wiklander elf->e_shoff = ehdr->e_shoff; 687509ff7cSJens Wiklander elf->e_phnum = ehdr->e_phnum; 697509ff7cSJens Wiklander elf->e_shnum = ehdr->e_shnum; 707509ff7cSJens Wiklander elf->e_phentsize = ehdr->e_phentsize; 717509ff7cSJens Wiklander elf->e_shentsize = ehdr->e_shentsize; 727509ff7cSJens Wiklander 737509ff7cSJens Wiklander return TEE_SUCCESS; 747509ff7cSJens Wiklander } 757509ff7cSJens Wiklander 767509ff7cSJens Wiklander #ifdef ARM64 777509ff7cSJens Wiklander static TEE_Result e64_parse_ehdr(struct ta_elf *elf, Elf64_Ehdr *ehdr) 787509ff7cSJens Wiklander { 797509ff7cSJens Wiklander if (ehdr->e_ident[EI_VERSION] != EV_CURRENT || 807509ff7cSJens Wiklander ehdr->e_ident[EI_CLASS] != ELFCLASS64 || 817509ff7cSJens Wiklander ehdr->e_ident[EI_DATA] != ELFDATA2LSB || 827509ff7cSJens Wiklander ehdr->e_ident[EI_OSABI] != ELFOSABI_NONE || 837509ff7cSJens Wiklander ehdr->e_type != ET_DYN || ehdr->e_machine != EM_AARCH64 || 847509ff7cSJens Wiklander ehdr->e_flags || ehdr->e_phentsize != sizeof(Elf64_Phdr) || 857509ff7cSJens Wiklander ehdr->e_shentsize != sizeof(Elf64_Shdr)) 867509ff7cSJens Wiklander return TEE_ERROR_BAD_FORMAT; 877509ff7cSJens Wiklander 887509ff7cSJens Wiklander 897509ff7cSJens Wiklander elf->is_32bit = false; 907509ff7cSJens Wiklander elf->e_entry = ehdr->e_entry; 917509ff7cSJens Wiklander elf->e_phoff = ehdr->e_phoff; 927509ff7cSJens Wiklander elf->e_shoff = ehdr->e_shoff; 937509ff7cSJens Wiklander elf->e_phnum = ehdr->e_phnum; 947509ff7cSJens Wiklander elf->e_shnum = ehdr->e_shnum; 957509ff7cSJens Wiklander elf->e_phentsize = ehdr->e_phentsize; 967509ff7cSJens Wiklander elf->e_shentsize = ehdr->e_shentsize; 977509ff7cSJens Wiklander 987509ff7cSJens Wiklander return TEE_SUCCESS; 997509ff7cSJens Wiklander } 1007509ff7cSJens Wiklander #else /*ARM64*/ 1017509ff7cSJens Wiklander static TEE_Result e64_parse_ehdr(struct ta_elf *elf __unused, 1027509ff7cSJens Wiklander Elf64_Ehdr *ehdr __unused) 1037509ff7cSJens Wiklander { 1047509ff7cSJens Wiklander return TEE_ERROR_NOT_SUPPORTED; 1057509ff7cSJens Wiklander } 1067509ff7cSJens Wiklander #endif /*ARM64*/ 1077509ff7cSJens Wiklander 1087509ff7cSJens Wiklander static void read_dyn(struct ta_elf *elf, vaddr_t addr, 1097509ff7cSJens Wiklander size_t idx, unsigned int *tag, size_t *val) 1107509ff7cSJens Wiklander { 1117509ff7cSJens Wiklander if (elf->is_32bit) { 1127509ff7cSJens Wiklander Elf32_Dyn *dyn = (Elf32_Dyn *)(addr + elf->load_addr); 1137509ff7cSJens Wiklander 1147509ff7cSJens Wiklander *tag = dyn[idx].d_tag; 1157509ff7cSJens Wiklander *val = dyn[idx].d_un.d_val; 1167509ff7cSJens Wiklander } else { 1177509ff7cSJens Wiklander Elf64_Dyn *dyn = (Elf64_Dyn *)(addr + elf->load_addr); 1187509ff7cSJens Wiklander 1197509ff7cSJens Wiklander *tag = dyn[idx].d_tag; 1207509ff7cSJens Wiklander *val = dyn[idx].d_un.d_val; 1217509ff7cSJens Wiklander } 1227509ff7cSJens Wiklander } 1237509ff7cSJens Wiklander 1247509ff7cSJens Wiklander static void e32_save_symtab(struct ta_elf *elf, size_t tab_idx) 1257509ff7cSJens Wiklander { 1267509ff7cSJens Wiklander Elf32_Shdr *shdr = elf->shdr; 1277509ff7cSJens Wiklander size_t str_idx = shdr[tab_idx].sh_link; 1287509ff7cSJens Wiklander 1297509ff7cSJens Wiklander elf->dynsymtab = (void *)(shdr[tab_idx].sh_addr + elf->load_addr); 1307509ff7cSJens Wiklander assert(!(shdr[tab_idx].sh_size % sizeof(Elf32_Sym))); 1317509ff7cSJens Wiklander elf->num_dynsyms = shdr[tab_idx].sh_size / sizeof(Elf32_Sym); 1327509ff7cSJens Wiklander 1337509ff7cSJens Wiklander elf->dynstr = (void *)(shdr[str_idx].sh_addr + elf->load_addr); 1347509ff7cSJens Wiklander elf->dynstr_size = shdr[str_idx].sh_size; 1357509ff7cSJens Wiklander } 1367509ff7cSJens Wiklander 1377509ff7cSJens Wiklander static void e64_save_symtab(struct ta_elf *elf, size_t tab_idx) 1387509ff7cSJens Wiklander { 1397509ff7cSJens Wiklander Elf64_Shdr *shdr = elf->shdr; 1407509ff7cSJens Wiklander size_t str_idx = shdr[tab_idx].sh_link; 1417509ff7cSJens Wiklander 1427509ff7cSJens Wiklander elf->dynsymtab = (void *)(vaddr_t)(shdr[tab_idx].sh_addr + 1437509ff7cSJens Wiklander elf->load_addr); 1447509ff7cSJens Wiklander assert(!(shdr[tab_idx].sh_size % sizeof(Elf64_Sym))); 1457509ff7cSJens Wiklander elf->num_dynsyms = shdr[tab_idx].sh_size / sizeof(Elf64_Sym); 1467509ff7cSJens Wiklander 1477509ff7cSJens Wiklander elf->dynstr = (void *)(vaddr_t)(shdr[str_idx].sh_addr + elf->load_addr); 1487509ff7cSJens Wiklander elf->dynstr_size = shdr[str_idx].sh_size; 1497509ff7cSJens Wiklander } 1507509ff7cSJens Wiklander 1517509ff7cSJens Wiklander static void save_symtab(struct ta_elf *elf) 1527509ff7cSJens Wiklander { 1537509ff7cSJens Wiklander size_t n = 0; 1547509ff7cSJens Wiklander 1557509ff7cSJens Wiklander if (elf->is_32bit) { 1567509ff7cSJens Wiklander Elf32_Shdr *shdr = elf->shdr; 1577509ff7cSJens Wiklander 1587509ff7cSJens Wiklander for (n = 0; n < elf->e_shnum; n++) { 1597509ff7cSJens Wiklander if (shdr[n].sh_type == SHT_DYNSYM) { 1607509ff7cSJens Wiklander e32_save_symtab(elf, n); 1617509ff7cSJens Wiklander break; 1627509ff7cSJens Wiklander } 1637509ff7cSJens Wiklander } 1647509ff7cSJens Wiklander } else { 1657509ff7cSJens Wiklander Elf64_Shdr *shdr = elf->shdr; 1667509ff7cSJens Wiklander 1677509ff7cSJens Wiklander for (n = 0; n < elf->e_shnum; n++) { 1687509ff7cSJens Wiklander if (shdr[n].sh_type == SHT_DYNSYM) { 1697509ff7cSJens Wiklander e64_save_symtab(elf, n); 1707509ff7cSJens Wiklander break; 1717509ff7cSJens Wiklander } 1727509ff7cSJens Wiklander } 1737509ff7cSJens Wiklander 1747509ff7cSJens Wiklander } 1757509ff7cSJens Wiklander } 1767509ff7cSJens Wiklander 1777509ff7cSJens Wiklander static void init_elf(struct ta_elf *elf) 1787509ff7cSJens Wiklander { 1797509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 1807509ff7cSJens Wiklander vaddr_t va = 0; 1817509ff7cSJens Wiklander uint32_t flags = PTA_SYSTEM_MAP_FLAG_SHAREABLE; 1827509ff7cSJens Wiklander 1837509ff7cSJens Wiklander res = sys_open_ta_bin(&elf->uuid, &elf->handle); 1847509ff7cSJens Wiklander if (res) 1857509ff7cSJens Wiklander err(res, "sys_open_ta_bin(%pUl)", (void *)&elf->uuid); 1867509ff7cSJens Wiklander 1877509ff7cSJens Wiklander /* 1887509ff7cSJens Wiklander * Map it read-only executable when we're loading a library where 1897509ff7cSJens Wiklander * the ELF header is included in a load segment. 1907509ff7cSJens Wiklander */ 1917509ff7cSJens Wiklander if (!elf->is_main) 1927509ff7cSJens Wiklander flags |= PTA_SYSTEM_MAP_FLAG_EXECUTABLE; 19388796f89SJens Wiklander res = sys_map_ta_bin(&va, SMALL_PAGE_SIZE, flags, elf->handle, 0, 0, 0); 1947509ff7cSJens Wiklander if (res) 1957509ff7cSJens Wiklander err(res, "sys_map_ta_bin"); 1967509ff7cSJens Wiklander elf->ehdr_addr = va; 1977509ff7cSJens Wiklander if (!elf->is_main) { 1987509ff7cSJens Wiklander elf->load_addr = va; 1997509ff7cSJens Wiklander elf->max_addr = va + SMALL_PAGE_SIZE; 2007509ff7cSJens Wiklander elf->max_offs = SMALL_PAGE_SIZE; 2017509ff7cSJens Wiklander } 2027509ff7cSJens Wiklander 2037509ff7cSJens Wiklander if (!IS_ELF(*(Elf32_Ehdr *)va)) 2047509ff7cSJens Wiklander err(TEE_ERROR_BAD_FORMAT, "TA is not an ELF"); 2057509ff7cSJens Wiklander 2067509ff7cSJens Wiklander res = e32_parse_ehdr(elf, (void *)va); 2077509ff7cSJens Wiklander if (res == TEE_ERROR_BAD_FORMAT) 2087509ff7cSJens Wiklander res = e64_parse_ehdr(elf, (void *)va); 2097509ff7cSJens Wiklander if (res) 2107509ff7cSJens Wiklander err(res, "Cannot parse ELF"); 2117509ff7cSJens Wiklander 2127509ff7cSJens Wiklander if (elf->e_phoff + elf->e_phnum * elf->e_phentsize > SMALL_PAGE_SIZE) 2137509ff7cSJens Wiklander err(TEE_ERROR_NOT_SUPPORTED, "Cannot read program headers"); 2147509ff7cSJens Wiklander 2157509ff7cSJens Wiklander elf->phdr = (void *)(va + elf->e_phoff); 2167509ff7cSJens Wiklander } 2177509ff7cSJens Wiklander 2187509ff7cSJens Wiklander static size_t roundup(size_t v) 2197509ff7cSJens Wiklander { 2207509ff7cSJens Wiklander return ROUNDUP(v, SMALL_PAGE_SIZE); 2217509ff7cSJens Wiklander } 2227509ff7cSJens Wiklander 2237509ff7cSJens Wiklander static size_t rounddown(size_t v) 2247509ff7cSJens Wiklander { 2257509ff7cSJens Wiklander return ROUNDDOWN(v, SMALL_PAGE_SIZE); 2267509ff7cSJens Wiklander } 2277509ff7cSJens Wiklander 2287509ff7cSJens Wiklander static void add_segment(struct ta_elf *elf, size_t offset, size_t vaddr, 2297509ff7cSJens Wiklander size_t filesz, size_t memsz, size_t flags, size_t align) 2307509ff7cSJens Wiklander { 2317509ff7cSJens Wiklander struct segment *seg = calloc(1, sizeof(*seg)); 2327509ff7cSJens Wiklander 2337509ff7cSJens Wiklander if (!seg) 2347509ff7cSJens Wiklander err(TEE_ERROR_OUT_OF_MEMORY, "calloc"); 2357509ff7cSJens Wiklander 2367509ff7cSJens Wiklander seg->offset = offset; 2377509ff7cSJens Wiklander seg->vaddr = vaddr; 2387509ff7cSJens Wiklander seg->filesz = filesz; 2397509ff7cSJens Wiklander seg->memsz = memsz; 2407509ff7cSJens Wiklander seg->flags = flags; 2417509ff7cSJens Wiklander seg->align = align; 2427509ff7cSJens Wiklander 2437509ff7cSJens Wiklander TAILQ_INSERT_TAIL(&elf->segs, seg, link); 2447509ff7cSJens Wiklander } 2457509ff7cSJens Wiklander 2467509ff7cSJens Wiklander static void parse_load_segments(struct ta_elf *elf) 2477509ff7cSJens Wiklander { 2487509ff7cSJens Wiklander size_t n = 0; 2497509ff7cSJens Wiklander 2507509ff7cSJens Wiklander if (elf->is_32bit) { 2517509ff7cSJens Wiklander Elf32_Phdr *phdr = elf->phdr; 2527509ff7cSJens Wiklander 2537509ff7cSJens Wiklander for (n = 0; n < elf->e_phnum; n++) 2540242833aSJens Wiklander if (phdr[n].p_type == PT_LOAD) { 2557509ff7cSJens Wiklander add_segment(elf, phdr[n].p_offset, 2567509ff7cSJens Wiklander phdr[n].p_vaddr, phdr[n].p_filesz, 2577509ff7cSJens Wiklander phdr[n].p_memsz, phdr[n].p_flags, 2587509ff7cSJens Wiklander phdr[n].p_align); 2590242833aSJens Wiklander } else if (phdr[n].p_type == PT_ARM_EXIDX) { 2600242833aSJens Wiklander elf->exidx_start = phdr[n].p_vaddr; 2610242833aSJens Wiklander elf->exidx_size = phdr[n].p_filesz; 2620242833aSJens Wiklander } 2637509ff7cSJens Wiklander } else { 2647509ff7cSJens Wiklander Elf64_Phdr *phdr = elf->phdr; 2657509ff7cSJens Wiklander 2667509ff7cSJens Wiklander for (n = 0; n < elf->e_phnum; n++) 2677509ff7cSJens Wiklander if (phdr[n].p_type == PT_LOAD) 2687509ff7cSJens Wiklander add_segment(elf, phdr[n].p_offset, 2697509ff7cSJens Wiklander phdr[n].p_vaddr, phdr[n].p_filesz, 2707509ff7cSJens Wiklander phdr[n].p_memsz, phdr[n].p_flags, 2717509ff7cSJens Wiklander phdr[n].p_align); 2727509ff7cSJens Wiklander } 2737509ff7cSJens Wiklander } 2747509ff7cSJens Wiklander 2757509ff7cSJens Wiklander static void copy_remapped_to(struct ta_elf *elf, const struct segment *seg) 2767509ff7cSJens Wiklander { 2777509ff7cSJens Wiklander uint8_t *dst = (void *)(seg->vaddr + elf->load_addr); 2787509ff7cSJens Wiklander size_t n = 0; 2797509ff7cSJens Wiklander size_t offs = seg->offset; 2807509ff7cSJens Wiklander size_t num_bytes = seg->filesz; 2817509ff7cSJens Wiklander 2827509ff7cSJens Wiklander if (offs < elf->max_offs) { 2837509ff7cSJens Wiklander n = MIN(elf->max_offs - offs, num_bytes); 2847509ff7cSJens Wiklander memcpy(dst, (void *)(elf->max_addr + offs - elf->max_offs), n); 2857509ff7cSJens Wiklander dst += n; 2867509ff7cSJens Wiklander offs += n; 2877509ff7cSJens Wiklander num_bytes -= n; 2887509ff7cSJens Wiklander } 2897509ff7cSJens Wiklander 2907509ff7cSJens Wiklander if (num_bytes) { 2917509ff7cSJens Wiklander TEE_Result res = sys_copy_from_ta_bin(dst, num_bytes, 2927509ff7cSJens Wiklander elf->handle, offs); 2937509ff7cSJens Wiklander 2947509ff7cSJens Wiklander if (res) 2957509ff7cSJens Wiklander err(res, "sys_copy_from_ta_bin"); 2967509ff7cSJens Wiklander elf->max_offs += offs; 2977509ff7cSJens Wiklander } 2987509ff7cSJens Wiklander } 2997509ff7cSJens Wiklander 3007509ff7cSJens Wiklander static void adjust_segments(struct ta_elf *elf) 3017509ff7cSJens Wiklander { 3027509ff7cSJens Wiklander struct segment *seg = NULL; 3037509ff7cSJens Wiklander struct segment *prev_seg = NULL; 3047509ff7cSJens Wiklander size_t prev_end_addr = 0; 3057509ff7cSJens Wiklander size_t align = 0; 3067509ff7cSJens Wiklander size_t mask = 0; 3077509ff7cSJens Wiklander 3087509ff7cSJens Wiklander /* Sanity check */ 3097509ff7cSJens Wiklander TAILQ_FOREACH(seg, &elf->segs, link) { 3107509ff7cSJens Wiklander size_t dummy __maybe_unused = 0; 3117509ff7cSJens Wiklander 3127509ff7cSJens Wiklander assert(seg->align >= SMALL_PAGE_SIZE); 3137509ff7cSJens Wiklander assert(!ADD_OVERFLOW(seg->vaddr, seg->memsz, &dummy)); 3147509ff7cSJens Wiklander assert(seg->filesz <= seg->memsz); 3157509ff7cSJens Wiklander assert((seg->offset & SMALL_PAGE_MASK) == 3167509ff7cSJens Wiklander (seg->vaddr & SMALL_PAGE_MASK)); 3177509ff7cSJens Wiklander 3187509ff7cSJens Wiklander prev_seg = TAILQ_PREV(seg, segment_head, link); 3197509ff7cSJens Wiklander if (prev_seg) { 3207509ff7cSJens Wiklander assert(seg->vaddr >= prev_seg->vaddr + prev_seg->memsz); 3217509ff7cSJens Wiklander assert(seg->offset >= 3227509ff7cSJens Wiklander prev_seg->offset + prev_seg->filesz); 3237509ff7cSJens Wiklander } 3247509ff7cSJens Wiklander if (!align) 3257509ff7cSJens Wiklander align = seg->align; 3267509ff7cSJens Wiklander assert(align == seg->align); 3277509ff7cSJens Wiklander } 3287509ff7cSJens Wiklander 3297509ff7cSJens Wiklander mask = align - 1; 3307509ff7cSJens Wiklander 3317509ff7cSJens Wiklander seg = TAILQ_FIRST(&elf->segs); 3327509ff7cSJens Wiklander if (seg) 3337509ff7cSJens Wiklander seg = TAILQ_NEXT(seg, link); 3347509ff7cSJens Wiklander while (seg) { 3357509ff7cSJens Wiklander prev_seg = TAILQ_PREV(seg, segment_head, link); 3367509ff7cSJens Wiklander prev_end_addr = prev_seg->vaddr + prev_seg->memsz; 3377509ff7cSJens Wiklander 3387509ff7cSJens Wiklander /* 3397509ff7cSJens Wiklander * This segment may overlap with the last "page" in the 3407509ff7cSJens Wiklander * previous segment in two different ways: 3417509ff7cSJens Wiklander * 1. Virtual address (and offset) overlaps => 3427509ff7cSJens Wiklander * Permissions needs to be merged. The offset must have 3437509ff7cSJens Wiklander * the SMALL_PAGE_MASK bits set as vaddr and offset must 3447509ff7cSJens Wiklander * add up with prevsion segment. 3457509ff7cSJens Wiklander * 3467509ff7cSJens Wiklander * 2. Only offset overlaps => 3477509ff7cSJens Wiklander * The same page in the ELF is mapped at two different 3487509ff7cSJens Wiklander * virtual addresses. As a limitation this segment must 3497509ff7cSJens Wiklander * be mapped as writeable. 3507509ff7cSJens Wiklander */ 3517509ff7cSJens Wiklander 3527509ff7cSJens Wiklander /* Case 1. */ 3537509ff7cSJens Wiklander if (rounddown(seg->vaddr) < prev_end_addr) { 3547509ff7cSJens Wiklander assert((seg->vaddr & mask) == (seg->offset & mask)); 3557509ff7cSJens Wiklander assert(prev_seg->memsz == prev_seg->filesz); 3567509ff7cSJens Wiklander 3577509ff7cSJens Wiklander /* 3587509ff7cSJens Wiklander * Merge the segments and their permissions. 3597509ff7cSJens Wiklander * Note that the may be a small hole between the 3607509ff7cSJens Wiklander * two sections. 3617509ff7cSJens Wiklander */ 3627509ff7cSJens Wiklander prev_seg->filesz = seg->vaddr + seg->filesz - 3637509ff7cSJens Wiklander prev_seg->vaddr; 3647509ff7cSJens Wiklander prev_seg->memsz = seg->vaddr + seg->memsz - 3657509ff7cSJens Wiklander prev_seg->vaddr; 3667509ff7cSJens Wiklander prev_seg->flags |= seg->flags; 3677509ff7cSJens Wiklander 3687509ff7cSJens Wiklander TAILQ_REMOVE(&elf->segs, seg, link); 3697509ff7cSJens Wiklander free(seg); 3707509ff7cSJens Wiklander seg = TAILQ_NEXT(prev_seg, link); 3717509ff7cSJens Wiklander continue; 3727509ff7cSJens Wiklander } 3737509ff7cSJens Wiklander 3747509ff7cSJens Wiklander /* Case 2. */ 3757509ff7cSJens Wiklander if ((seg->offset & mask) && 3767509ff7cSJens Wiklander rounddown(seg->offset) < 3777509ff7cSJens Wiklander (prev_seg->offset + prev_seg->filesz)) { 3787509ff7cSJens Wiklander 3797509ff7cSJens Wiklander assert(seg->flags & PF_W); 3807509ff7cSJens Wiklander seg->remapped_writeable = true; 3817509ff7cSJens Wiklander } 3827509ff7cSJens Wiklander 3837509ff7cSJens Wiklander /* 3847509ff7cSJens Wiklander * No overlap, but we may need to align address, offset and 3857509ff7cSJens Wiklander * size. 3867509ff7cSJens Wiklander */ 3877509ff7cSJens Wiklander seg->filesz += seg->vaddr - rounddown(seg->vaddr); 3887509ff7cSJens Wiklander seg->memsz += seg->vaddr - rounddown(seg->vaddr); 3897509ff7cSJens Wiklander seg->vaddr = rounddown(seg->vaddr); 3907509ff7cSJens Wiklander seg->offset = rounddown(seg->offset); 3917509ff7cSJens Wiklander seg = TAILQ_NEXT(seg, link); 3927509ff7cSJens Wiklander } 3937509ff7cSJens Wiklander 3947509ff7cSJens Wiklander } 3957509ff7cSJens Wiklander 3967509ff7cSJens Wiklander static void populate_segments_legacy(struct ta_elf *elf) 3977509ff7cSJens Wiklander { 3987509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 3997509ff7cSJens Wiklander struct segment *seg = NULL; 4007509ff7cSJens Wiklander vaddr_t va = 0; 4017509ff7cSJens Wiklander 4027509ff7cSJens Wiklander TAILQ_FOREACH(seg, &elf->segs, link) { 4037509ff7cSJens Wiklander struct segment *last_seg = TAILQ_LAST(&elf->segs, segment_head); 4047509ff7cSJens Wiklander size_t pad_end = roundup(last_seg->vaddr + last_seg->memsz - 4057509ff7cSJens Wiklander seg->vaddr - seg->memsz); 4067509ff7cSJens Wiklander size_t num_bytes = roundup(seg->memsz); 4077509ff7cSJens Wiklander 4087509ff7cSJens Wiklander if (!elf->load_addr) 4097509ff7cSJens Wiklander va = 0; 4107509ff7cSJens Wiklander else 4117509ff7cSJens Wiklander va = seg->vaddr + elf->load_addr; 4127509ff7cSJens Wiklander 4137509ff7cSJens Wiklander 4147509ff7cSJens Wiklander if (!(seg->flags & PF_R)) 4157509ff7cSJens Wiklander err(TEE_ERROR_NOT_SUPPORTED, 4167509ff7cSJens Wiklander "Segment must be readable"); 4177509ff7cSJens Wiklander 4187509ff7cSJens Wiklander res = sys_map_zi(num_bytes, 0, &va, 0, pad_end); 4197509ff7cSJens Wiklander if (res) 4207509ff7cSJens Wiklander err(res, "sys_map_zi"); 4217509ff7cSJens Wiklander res = sys_copy_from_ta_bin((void *)va, seg->filesz, 4227509ff7cSJens Wiklander elf->handle, seg->offset); 4237509ff7cSJens Wiklander if (res) 4247509ff7cSJens Wiklander err(res, "sys_copy_from_ta_bin"); 4257509ff7cSJens Wiklander 4267509ff7cSJens Wiklander if (!elf->load_addr) 4277509ff7cSJens Wiklander elf->load_addr = va; 4287509ff7cSJens Wiklander elf->max_addr = va + num_bytes; 4297509ff7cSJens Wiklander elf->max_offs = seg->offset + seg->filesz; 4307509ff7cSJens Wiklander } 4317509ff7cSJens Wiklander } 4327509ff7cSJens Wiklander 433*6720dd49SJens Wiklander static size_t get_pad_begin(void) 434*6720dd49SJens Wiklander { 435*6720dd49SJens Wiklander #ifdef CFG_TA_ASLR 436*6720dd49SJens Wiklander size_t min = CFG_TA_ASLR_MIN_OFFSET_PAGES; 437*6720dd49SJens Wiklander size_t max = CFG_TA_ASLR_MAX_OFFSET_PAGES; 438*6720dd49SJens Wiklander TEE_Result res = TEE_SUCCESS; 439*6720dd49SJens Wiklander uint32_t rnd32 = 0; 440*6720dd49SJens Wiklander size_t rnd = 0; 441*6720dd49SJens Wiklander 442*6720dd49SJens Wiklander COMPILE_TIME_ASSERT(CFG_TA_ASLR_MIN_OFFSET_PAGES < 443*6720dd49SJens Wiklander CFG_TA_ASLR_MAX_OFFSET_PAGES); 444*6720dd49SJens Wiklander if (max > min) { 445*6720dd49SJens Wiklander res = utee_cryp_random_number_generate(&rnd32, sizeof(rnd32)); 446*6720dd49SJens Wiklander if (res) { 447*6720dd49SJens Wiklander DMSG("Random read failed: %#"PRIx32, res); 448*6720dd49SJens Wiklander return min * SMALL_PAGE_SIZE; 449*6720dd49SJens Wiklander } 450*6720dd49SJens Wiklander rnd = rnd32 % (max - min); 451*6720dd49SJens Wiklander } 452*6720dd49SJens Wiklander 453*6720dd49SJens Wiklander return (min + rnd) * SMALL_PAGE_SIZE; 454*6720dd49SJens Wiklander #else /*!CFG_TA_ASLR*/ 455*6720dd49SJens Wiklander return 0; 456*6720dd49SJens Wiklander #endif /*!CFG_TA_ASLR*/ 457*6720dd49SJens Wiklander } 458*6720dd49SJens Wiklander 4597509ff7cSJens Wiklander static void populate_segments(struct ta_elf *elf) 4607509ff7cSJens Wiklander { 4617509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 4627509ff7cSJens Wiklander struct segment *seg = NULL; 4637509ff7cSJens Wiklander vaddr_t va = 0; 464*6720dd49SJens Wiklander size_t pad_begin = 0; 4657509ff7cSJens Wiklander 4667509ff7cSJens Wiklander TAILQ_FOREACH(seg, &elf->segs, link) { 4677509ff7cSJens Wiklander struct segment *last_seg = TAILQ_LAST(&elf->segs, segment_head); 4687509ff7cSJens Wiklander size_t pad_end = roundup(last_seg->vaddr + last_seg->memsz - 4697509ff7cSJens Wiklander seg->vaddr - seg->memsz); 4707509ff7cSJens Wiklander 4717509ff7cSJens Wiklander if (seg->remapped_writeable) { 4727509ff7cSJens Wiklander size_t num_bytes = roundup(seg->vaddr + seg->memsz) - 4737509ff7cSJens Wiklander rounddown(seg->vaddr); 4747509ff7cSJens Wiklander 4757509ff7cSJens Wiklander assert(elf->load_addr); 4767509ff7cSJens Wiklander va = rounddown(elf->load_addr + seg->vaddr); 4777509ff7cSJens Wiklander assert(va >= elf->max_addr); 4787509ff7cSJens Wiklander res = sys_map_zi(num_bytes, 0, &va, 0, pad_end); 4797509ff7cSJens Wiklander if (res) 4807509ff7cSJens Wiklander err(res, "sys_map_zi"); 4817509ff7cSJens Wiklander 4827509ff7cSJens Wiklander copy_remapped_to(elf, seg); 4837509ff7cSJens Wiklander elf->max_addr = va + num_bytes; 4847509ff7cSJens Wiklander } else { 4857509ff7cSJens Wiklander uint32_t flags = 0; 4867509ff7cSJens Wiklander size_t filesz = seg->filesz; 4877509ff7cSJens Wiklander size_t memsz = seg->memsz; 4887509ff7cSJens Wiklander size_t offset = seg->offset; 4897509ff7cSJens Wiklander size_t vaddr = seg->vaddr; 4907509ff7cSJens Wiklander 4917509ff7cSJens Wiklander if (offset < elf->max_offs) { 4927509ff7cSJens Wiklander /* 4937509ff7cSJens Wiklander * We're in a load segment which overlaps 4947509ff7cSJens Wiklander * with (or is covered by) the first page 4957509ff7cSJens Wiklander * of a shared library. 4967509ff7cSJens Wiklander */ 4977509ff7cSJens Wiklander if (vaddr + filesz < SMALL_PAGE_SIZE) { 4987509ff7cSJens Wiklander size_t num_bytes = 0; 4997509ff7cSJens Wiklander 5007509ff7cSJens Wiklander /* 5017509ff7cSJens Wiklander * If this segment is completely 5027509ff7cSJens Wiklander * covered, take next. 5037509ff7cSJens Wiklander */ 5047509ff7cSJens Wiklander if (vaddr + memsz <= SMALL_PAGE_SIZE) 5057509ff7cSJens Wiklander continue; 5067509ff7cSJens Wiklander 5077509ff7cSJens Wiklander /* 5087509ff7cSJens Wiklander * All data of the segment is 5097509ff7cSJens Wiklander * loaded, but we need to zero 5107509ff7cSJens Wiklander * extend it. 5117509ff7cSJens Wiklander */ 5127509ff7cSJens Wiklander va = elf->max_addr; 5137509ff7cSJens Wiklander num_bytes = roundup(vaddr + memsz) - 5147509ff7cSJens Wiklander roundup(vaddr) - 5157509ff7cSJens Wiklander SMALL_PAGE_SIZE; 5167509ff7cSJens Wiklander assert(num_bytes); 5177509ff7cSJens Wiklander res = sys_map_zi(num_bytes, 0, &va, 0, 5187509ff7cSJens Wiklander 0); 5197509ff7cSJens Wiklander if (res) 5207509ff7cSJens Wiklander err(res, "sys_map_zi"); 5217509ff7cSJens Wiklander elf->max_addr = roundup(va + num_bytes); 5227509ff7cSJens Wiklander continue; 5237509ff7cSJens Wiklander } 5247509ff7cSJens Wiklander 5257509ff7cSJens Wiklander /* Partial overlap, remove the first page. */ 5267509ff7cSJens Wiklander vaddr += SMALL_PAGE_SIZE; 5277509ff7cSJens Wiklander filesz -= SMALL_PAGE_SIZE; 5287509ff7cSJens Wiklander memsz -= SMALL_PAGE_SIZE; 5297509ff7cSJens Wiklander offset += SMALL_PAGE_SIZE; 5307509ff7cSJens Wiklander } 5317509ff7cSJens Wiklander 532*6720dd49SJens Wiklander if (!elf->load_addr) { 5337509ff7cSJens Wiklander va = 0; 534*6720dd49SJens Wiklander pad_begin = get_pad_begin(); 535*6720dd49SJens Wiklander /* 536*6720dd49SJens Wiklander * If mapping with pad_begin fails we'll 537*6720dd49SJens Wiklander * retry without pad_begin, effectively 538*6720dd49SJens Wiklander * disabling ASLR for the current ELF file. 539*6720dd49SJens Wiklander */ 540*6720dd49SJens Wiklander } else { 5417509ff7cSJens Wiklander va = vaddr + elf->load_addr; 542*6720dd49SJens Wiklander pad_begin = 0; 543*6720dd49SJens Wiklander } 5447509ff7cSJens Wiklander 5457509ff7cSJens Wiklander if (seg->flags & PF_W) 5467509ff7cSJens Wiklander flags |= PTA_SYSTEM_MAP_FLAG_WRITEABLE; 5477509ff7cSJens Wiklander else 5487509ff7cSJens Wiklander flags |= PTA_SYSTEM_MAP_FLAG_SHAREABLE; 5497509ff7cSJens Wiklander if (seg->flags & PF_X) 5507509ff7cSJens Wiklander flags |= PTA_SYSTEM_MAP_FLAG_EXECUTABLE; 5517509ff7cSJens Wiklander if (!(seg->flags & PF_R)) 5527509ff7cSJens Wiklander err(TEE_ERROR_NOT_SUPPORTED, 5537509ff7cSJens Wiklander "Segment must be readable"); 5547509ff7cSJens Wiklander if (flags & PTA_SYSTEM_MAP_FLAG_WRITEABLE) { 555*6720dd49SJens Wiklander res = sys_map_zi(memsz, 0, &va, pad_begin, 556*6720dd49SJens Wiklander pad_end); 557*6720dd49SJens Wiklander if (pad_begin && res == TEE_ERROR_OUT_OF_MEMORY) 558*6720dd49SJens Wiklander res = sys_map_zi(memsz, 0, &va, 0, 559*6720dd49SJens Wiklander pad_end); 5607509ff7cSJens Wiklander if (res) 5617509ff7cSJens Wiklander err(res, "sys_map_zi"); 5627509ff7cSJens Wiklander res = sys_copy_from_ta_bin((void *)va, filesz, 5637509ff7cSJens Wiklander elf->handle, offset); 5647509ff7cSJens Wiklander if (res) 5657509ff7cSJens Wiklander err(res, "sys_copy_from_ta_bin"); 5667509ff7cSJens Wiklander } else { 5677509ff7cSJens Wiklander res = sys_map_ta_bin(&va, filesz, flags, 5687509ff7cSJens Wiklander elf->handle, offset, 569*6720dd49SJens Wiklander pad_begin, pad_end); 570*6720dd49SJens Wiklander if (pad_begin && res == TEE_ERROR_OUT_OF_MEMORY) 571*6720dd49SJens Wiklander res = sys_map_ta_bin(&va, filesz, flags, 572*6720dd49SJens Wiklander elf->handle, 573*6720dd49SJens Wiklander offset, 0, 574*6720dd49SJens Wiklander pad_end); 5757509ff7cSJens Wiklander if (res) 5767509ff7cSJens Wiklander err(res, "sys_map_ta_bin"); 5777509ff7cSJens Wiklander } 5787509ff7cSJens Wiklander 5797509ff7cSJens Wiklander if (!elf->load_addr) 5807509ff7cSJens Wiklander elf->load_addr = va; 5817509ff7cSJens Wiklander elf->max_addr = roundup(va + filesz); 5827509ff7cSJens Wiklander elf->max_offs += filesz; 5837509ff7cSJens Wiklander } 5847509ff7cSJens Wiklander } 5857509ff7cSJens Wiklander } 5867509ff7cSJens Wiklander 5877509ff7cSJens Wiklander static void map_segments(struct ta_elf *elf) 5887509ff7cSJens Wiklander { 58988796f89SJens Wiklander TEE_Result res = TEE_SUCCESS; 59088796f89SJens Wiklander 5917509ff7cSJens Wiklander parse_load_segments(elf); 5927509ff7cSJens Wiklander adjust_segments(elf); 59388796f89SJens Wiklander if (TAILQ_FIRST(&elf->segs)->offset < SMALL_PAGE_SIZE) { 59488796f89SJens Wiklander vaddr_t va = 0; 59588796f89SJens Wiklander size_t sz = elf->max_addr - elf->load_addr; 59688796f89SJens Wiklander struct segment *seg = TAILQ_LAST(&elf->segs, segment_head); 597*6720dd49SJens Wiklander size_t pad_begin = get_pad_begin(); 59888796f89SJens Wiklander 59988796f89SJens Wiklander /* 60088796f89SJens Wiklander * We're loading a library, if not other parts of the code 60188796f89SJens Wiklander * need to be updated too. 60288796f89SJens Wiklander */ 60388796f89SJens Wiklander assert(!elf->is_main); 60488796f89SJens Wiklander 60588796f89SJens Wiklander /* 60688796f89SJens Wiklander * Now that we know how much virtual memory is needed move 60788796f89SJens Wiklander * the already mapped part to a location which can 60888796f89SJens Wiklander * accommodate us. 60988796f89SJens Wiklander */ 610*6720dd49SJens Wiklander res = sys_remap(elf->load_addr, &va, sz, pad_begin, 611*6720dd49SJens Wiklander roundup(seg->vaddr + seg->memsz)); 612*6720dd49SJens Wiklander if (res == TEE_ERROR_OUT_OF_MEMORY) 61388796f89SJens Wiklander res = sys_remap(elf->load_addr, &va, sz, 0, 61488796f89SJens Wiklander roundup(seg->vaddr + seg->memsz)); 61588796f89SJens Wiklander if (res) 61688796f89SJens Wiklander err(res, "sys_remap"); 61788796f89SJens Wiklander elf->ehdr_addr = va; 61888796f89SJens Wiklander elf->load_addr = va; 61988796f89SJens Wiklander elf->max_addr = va + sz; 62088796f89SJens Wiklander elf->phdr = (void *)(va + elf->e_phoff); 62188796f89SJens Wiklander } 6227509ff7cSJens Wiklander if (elf->is_legacy) 6237509ff7cSJens Wiklander populate_segments_legacy(elf); 6247509ff7cSJens Wiklander else 6257509ff7cSJens Wiklander populate_segments(elf); 6267509ff7cSJens Wiklander } 6277509ff7cSJens Wiklander 6287509ff7cSJens Wiklander static int hex(char c) 6297509ff7cSJens Wiklander { 6307509ff7cSJens Wiklander char lc = tolower(c); 6317509ff7cSJens Wiklander 6327509ff7cSJens Wiklander if (isdigit(lc)) 6337509ff7cSJens Wiklander return lc - '0'; 6347509ff7cSJens Wiklander if (isxdigit(lc)) 6357509ff7cSJens Wiklander return lc - 'a' + 10; 6367509ff7cSJens Wiklander return -1; 6377509ff7cSJens Wiklander } 6387509ff7cSJens Wiklander 6397509ff7cSJens Wiklander static uint32_t parse_hex(const char *s, size_t nchars, uint32_t *res) 6407509ff7cSJens Wiklander { 6417509ff7cSJens Wiklander uint32_t v = 0; 6427509ff7cSJens Wiklander size_t n; 6437509ff7cSJens Wiklander int c; 6447509ff7cSJens Wiklander 6457509ff7cSJens Wiklander for (n = 0; n < nchars; n++) { 6467509ff7cSJens Wiklander c = hex(s[n]); 6477509ff7cSJens Wiklander if (c == (char)-1) { 6487509ff7cSJens Wiklander *res = TEE_ERROR_BAD_FORMAT; 6497509ff7cSJens Wiklander goto out; 6507509ff7cSJens Wiklander } 6517509ff7cSJens Wiklander v = (v << 4) + c; 6527509ff7cSJens Wiklander } 6537509ff7cSJens Wiklander *res = TEE_SUCCESS; 6547509ff7cSJens Wiklander out: 6557509ff7cSJens Wiklander return v; 6567509ff7cSJens Wiklander } 6577509ff7cSJens Wiklander 6587509ff7cSJens Wiklander /* 6597509ff7cSJens Wiklander * Convert a UUID string @s into a TEE_UUID @uuid 6607509ff7cSJens Wiklander * Expected format for @s is: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx 6617509ff7cSJens Wiklander * 'x' being any hexadecimal digit (0-9a-fA-F) 6627509ff7cSJens Wiklander */ 6637509ff7cSJens Wiklander static TEE_Result parse_uuid(const char *s, TEE_UUID *uuid) 6647509ff7cSJens Wiklander { 6657509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 6667509ff7cSJens Wiklander TEE_UUID u = { 0 }; 6677509ff7cSJens Wiklander const char *p = s; 6687509ff7cSJens Wiklander size_t i; 6697509ff7cSJens Wiklander 6707509ff7cSJens Wiklander if (strlen(p) != 36) 6717509ff7cSJens Wiklander return TEE_ERROR_BAD_FORMAT; 6727509ff7cSJens Wiklander if (p[8] != '-' || p[13] != '-' || p[18] != '-' || p[23] != '-') 6737509ff7cSJens Wiklander return TEE_ERROR_BAD_FORMAT; 6747509ff7cSJens Wiklander 6757509ff7cSJens Wiklander u.timeLow = parse_hex(p, 8, &res); 6767509ff7cSJens Wiklander if (res) 6777509ff7cSJens Wiklander goto out; 6787509ff7cSJens Wiklander p += 9; 6797509ff7cSJens Wiklander u.timeMid = parse_hex(p, 4, &res); 6807509ff7cSJens Wiklander if (res) 6817509ff7cSJens Wiklander goto out; 6827509ff7cSJens Wiklander p += 5; 6837509ff7cSJens Wiklander u.timeHiAndVersion = parse_hex(p, 4, &res); 6847509ff7cSJens Wiklander if (res) 6857509ff7cSJens Wiklander goto out; 6867509ff7cSJens Wiklander p += 5; 6877509ff7cSJens Wiklander for (i = 0; i < 8; i++) { 6887509ff7cSJens Wiklander u.clockSeqAndNode[i] = parse_hex(p, 2, &res); 6897509ff7cSJens Wiklander if (res) 6907509ff7cSJens Wiklander goto out; 6917509ff7cSJens Wiklander if (i == 1) 6927509ff7cSJens Wiklander p += 3; 6937509ff7cSJens Wiklander else 6947509ff7cSJens Wiklander p += 2; 6957509ff7cSJens Wiklander } 6967509ff7cSJens Wiklander *uuid = u; 6977509ff7cSJens Wiklander out: 6987509ff7cSJens Wiklander return res; 6997509ff7cSJens Wiklander } 7007509ff7cSJens Wiklander 7017509ff7cSJens Wiklander static void add_deps_from_segment(struct ta_elf *elf, unsigned int type, 7027509ff7cSJens Wiklander vaddr_t addr, size_t memsz) 7037509ff7cSJens Wiklander { 7047509ff7cSJens Wiklander size_t dyn_entsize = 0; 7057509ff7cSJens Wiklander size_t num_dyns = 0; 7067509ff7cSJens Wiklander size_t n = 0; 7077509ff7cSJens Wiklander unsigned int tag = 0; 7087509ff7cSJens Wiklander size_t val = 0; 7097509ff7cSJens Wiklander TEE_UUID uuid = { }; 7107509ff7cSJens Wiklander char *str_tab = NULL; 7117509ff7cSJens Wiklander 7127509ff7cSJens Wiklander if (type != PT_DYNAMIC) 7137509ff7cSJens Wiklander return; 7147509ff7cSJens Wiklander 7157509ff7cSJens Wiklander if (elf->is_32bit) 7167509ff7cSJens Wiklander dyn_entsize = sizeof(Elf32_Dyn); 7177509ff7cSJens Wiklander else 7187509ff7cSJens Wiklander dyn_entsize = sizeof(Elf64_Dyn); 7197509ff7cSJens Wiklander 7207509ff7cSJens Wiklander assert(!(memsz % dyn_entsize)); 7217509ff7cSJens Wiklander num_dyns = memsz / dyn_entsize; 7227509ff7cSJens Wiklander 7237509ff7cSJens Wiklander for (n = 0; n < num_dyns; n++) { 7247509ff7cSJens Wiklander read_dyn(elf, addr, n, &tag, &val); 7257509ff7cSJens Wiklander if (tag == DT_STRTAB) { 7267509ff7cSJens Wiklander str_tab = (char *)(val + elf->load_addr); 7277509ff7cSJens Wiklander break; 7287509ff7cSJens Wiklander } 7297509ff7cSJens Wiklander } 7307509ff7cSJens Wiklander 7317509ff7cSJens Wiklander for (n = 0; n < num_dyns; n++) { 7327509ff7cSJens Wiklander read_dyn(elf, addr, n, &tag, &val); 7337509ff7cSJens Wiklander if (tag != DT_NEEDED) 7347509ff7cSJens Wiklander continue; 7357509ff7cSJens Wiklander parse_uuid(str_tab + val, &uuid); 7367509ff7cSJens Wiklander queue_elf(&uuid); 7377509ff7cSJens Wiklander } 7387509ff7cSJens Wiklander } 7397509ff7cSJens Wiklander 7407509ff7cSJens Wiklander static void add_dependencies(struct ta_elf *elf) 7417509ff7cSJens Wiklander { 7427509ff7cSJens Wiklander size_t n = 0; 7437509ff7cSJens Wiklander 7447509ff7cSJens Wiklander if (elf->is_32bit) { 7457509ff7cSJens Wiklander Elf32_Phdr *phdr = elf->phdr; 7467509ff7cSJens Wiklander 7477509ff7cSJens Wiklander for (n = 0; n < elf->e_phnum; n++) 7487509ff7cSJens Wiklander add_deps_from_segment(elf, phdr[n].p_type, 7497509ff7cSJens Wiklander phdr[n].p_vaddr, phdr[n].p_memsz); 7507509ff7cSJens Wiklander } else { 7517509ff7cSJens Wiklander Elf64_Phdr *phdr = elf->phdr; 7527509ff7cSJens Wiklander 7537509ff7cSJens Wiklander for (n = 0; n < elf->e_phnum; n++) 7547509ff7cSJens Wiklander add_deps_from_segment(elf, phdr[n].p_type, 7557509ff7cSJens Wiklander phdr[n].p_vaddr, phdr[n].p_memsz); 7567509ff7cSJens Wiklander } 7577509ff7cSJens Wiklander } 7587509ff7cSJens Wiklander 7597509ff7cSJens Wiklander static void copy_section_headers(struct ta_elf *elf) 7607509ff7cSJens Wiklander { 7617509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 7627509ff7cSJens Wiklander size_t sz = elf->e_shnum * elf->e_shentsize; 7637509ff7cSJens Wiklander size_t offs = 0; 7647509ff7cSJens Wiklander 7657509ff7cSJens Wiklander elf->shdr = malloc(sz); 7667509ff7cSJens Wiklander if (!elf->shdr) 7677509ff7cSJens Wiklander err(TEE_ERROR_OUT_OF_MEMORY, "malloc"); 7687509ff7cSJens Wiklander 7697509ff7cSJens Wiklander /* 7707509ff7cSJens Wiklander * We're assuming that section headers comes after the load segments, 7717509ff7cSJens Wiklander * but if it's a very small dynamically linked library the section 7727509ff7cSJens Wiklander * headers can still end up (partially?) in the first mapped page. 7737509ff7cSJens Wiklander */ 7747509ff7cSJens Wiklander if (elf->e_shoff < SMALL_PAGE_SIZE) { 7757509ff7cSJens Wiklander assert(!elf->is_main); 7767509ff7cSJens Wiklander offs = MIN(SMALL_PAGE_SIZE - elf->e_shoff, sz); 7777509ff7cSJens Wiklander memcpy(elf->shdr, (void *)(elf->load_addr + elf->e_shoff), 7787509ff7cSJens Wiklander offs); 7797509ff7cSJens Wiklander } 7807509ff7cSJens Wiklander 7817509ff7cSJens Wiklander if (offs < sz) { 7827509ff7cSJens Wiklander res = sys_copy_from_ta_bin((uint8_t *)elf->shdr + offs, 7837509ff7cSJens Wiklander sz - offs, elf->handle, 7847509ff7cSJens Wiklander elf->e_shoff + offs); 7857509ff7cSJens Wiklander if (res) 7867509ff7cSJens Wiklander err(res, "sys_copy_from_ta_bin"); 7877509ff7cSJens Wiklander } 7887509ff7cSJens Wiklander } 7897509ff7cSJens Wiklander 7907509ff7cSJens Wiklander static void close_handle(struct ta_elf *elf) 7917509ff7cSJens Wiklander { 7927509ff7cSJens Wiklander TEE_Result res = sys_close_ta_bin(elf->handle); 7937509ff7cSJens Wiklander 7947509ff7cSJens Wiklander if (res) 7957509ff7cSJens Wiklander err(res, "sys_close_ta_bin"); 7967509ff7cSJens Wiklander elf->handle = -1; 7977509ff7cSJens Wiklander } 7987509ff7cSJens Wiklander 7997509ff7cSJens Wiklander void ta_elf_load_main(const TEE_UUID *uuid, uint32_t *is_32bit, 8007509ff7cSJens Wiklander uint64_t *entry, uint64_t *sp, uint32_t *ta_flags) 8017509ff7cSJens Wiklander { 8027509ff7cSJens Wiklander struct ta_elf *elf = queue_elf(uuid); 8037509ff7cSJens Wiklander struct ta_head *head; 8047509ff7cSJens Wiklander vaddr_t va = 0; 8057509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 8067509ff7cSJens Wiklander 8077509ff7cSJens Wiklander assert(elf); 8087509ff7cSJens Wiklander elf->is_main = true; 8097509ff7cSJens Wiklander 8107509ff7cSJens Wiklander init_elf(elf); 8117509ff7cSJens Wiklander 8127509ff7cSJens Wiklander /* 8137509ff7cSJens Wiklander * Legacy TAs doesn't set entry point, instead it's set in ta_head. 8147509ff7cSJens Wiklander * If entry point isn't set explicitly, set to the start of the 8157509ff7cSJens Wiklander * first executable section by the linker. Since ta_head also 8167509ff7cSJens Wiklander * always comes first in legacy TA it means that the entry point 8177509ff7cSJens Wiklander * will be set to 0x20. 8187509ff7cSJens Wiklander * 8197509ff7cSJens Wiklander * NB, everything before the commit a73b5878c89d ("Replace 8207509ff7cSJens Wiklander * ta_head.entry with elf entry") is considered legacy TAs for 8217509ff7cSJens Wiklander * ldelf. 8227509ff7cSJens Wiklander */ 8237509ff7cSJens Wiklander if (elf->e_entry == sizeof(*head)) 8247509ff7cSJens Wiklander elf->is_legacy = true; 8257509ff7cSJens Wiklander 8267509ff7cSJens Wiklander map_segments(elf); 8277509ff7cSJens Wiklander add_dependencies(elf); 8287509ff7cSJens Wiklander copy_section_headers(elf); 8297509ff7cSJens Wiklander save_symtab(elf); 8307509ff7cSJens Wiklander close_handle(elf); 8317509ff7cSJens Wiklander 8327509ff7cSJens Wiklander head = (struct ta_head *)elf->load_addr; 8337509ff7cSJens Wiklander 8347509ff7cSJens Wiklander *is_32bit = elf->is_32bit; 8357509ff7cSJens Wiklander if (elf->is_legacy) { 8367509ff7cSJens Wiklander assert(head->depr_entry != UINT64_MAX); 8377509ff7cSJens Wiklander *entry = head->depr_entry + elf->load_addr; 8387509ff7cSJens Wiklander } else { 8397509ff7cSJens Wiklander assert(head->depr_entry == UINT64_MAX); 8407509ff7cSJens Wiklander *entry = elf->e_entry + elf->load_addr; 8417509ff7cSJens Wiklander } 8427509ff7cSJens Wiklander 8437509ff7cSJens Wiklander res = sys_map_zi(head->stack_size, 0, &va, 0, 0); 8447509ff7cSJens Wiklander if (res) 8457509ff7cSJens Wiklander err(res, "sys_map_zi stack"); 8467509ff7cSJens Wiklander 8477509ff7cSJens Wiklander if (head->flags & ~TA_FLAGS_MASK) 8487509ff7cSJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Invalid TA flags(s) %#"PRIx32, 8497509ff7cSJens Wiklander head->flags & ~TA_FLAGS_MASK); 8507509ff7cSJens Wiklander 8517509ff7cSJens Wiklander *ta_flags = head->flags; 8527509ff7cSJens Wiklander *sp = va + head->stack_size; 85365137432SJens Wiklander ta_stack = va; 8540242833aSJens Wiklander ta_stack_size = head->stack_size; 8557509ff7cSJens Wiklander } 8567509ff7cSJens Wiklander 8577509ff7cSJens Wiklander void ta_elf_load_dependency(struct ta_elf *elf, bool is_32bit) 8587509ff7cSJens Wiklander { 8597509ff7cSJens Wiklander if (elf->is_main) 8607509ff7cSJens Wiklander return; 8617509ff7cSJens Wiklander 8627509ff7cSJens Wiklander init_elf(elf); 8637509ff7cSJens Wiklander if (elf->is_32bit != is_32bit) 8647509ff7cSJens Wiklander err(TEE_ERROR_BAD_FORMAT, "ELF %pUl is %sbit (expected %sbit)", 8657509ff7cSJens Wiklander (void *)&elf->uuid, elf->is_32bit ? "32" : "64", 8667509ff7cSJens Wiklander is_32bit ? "32" : "64"); 8677509ff7cSJens Wiklander 8687509ff7cSJens Wiklander map_segments(elf); 8697509ff7cSJens Wiklander add_dependencies(elf); 8707509ff7cSJens Wiklander copy_section_headers(elf); 8717509ff7cSJens Wiklander save_symtab(elf); 8727509ff7cSJens Wiklander close_handle(elf); 8737509ff7cSJens Wiklander } 8747509ff7cSJens Wiklander 8757509ff7cSJens Wiklander void ta_elf_finalize_mappings(struct ta_elf *elf) 8767509ff7cSJens Wiklander { 8777509ff7cSJens Wiklander TEE_Result res = TEE_SUCCESS; 8787509ff7cSJens Wiklander struct segment *seg = NULL; 8797509ff7cSJens Wiklander 8807509ff7cSJens Wiklander if (!elf->is_legacy) 8817509ff7cSJens Wiklander return; 8827509ff7cSJens Wiklander 8837509ff7cSJens Wiklander TAILQ_FOREACH(seg, &elf->segs, link) { 8847509ff7cSJens Wiklander vaddr_t va = elf->load_addr + seg->vaddr; 8857509ff7cSJens Wiklander uint32_t flags = 0; 8867509ff7cSJens Wiklander 8877509ff7cSJens Wiklander if (seg->flags & PF_W) 8887509ff7cSJens Wiklander flags |= PTA_SYSTEM_MAP_FLAG_WRITEABLE; 8897509ff7cSJens Wiklander if (seg->flags & PF_X) 8907509ff7cSJens Wiklander flags |= PTA_SYSTEM_MAP_FLAG_EXECUTABLE; 8917509ff7cSJens Wiklander 8927509ff7cSJens Wiklander res = sys_set_prot(va, seg->memsz, flags); 8937509ff7cSJens Wiklander if (res) 8947509ff7cSJens Wiklander err(res, "sys_set_prot"); 8957509ff7cSJens Wiklander } 8967509ff7cSJens Wiklander } 89765137432SJens Wiklander 89865137432SJens Wiklander static void print_seg(size_t idx __maybe_unused, int elf_idx __maybe_unused, 89965137432SJens Wiklander vaddr_t va __maybe_unused, paddr_t pa __maybe_unused, 90065137432SJens Wiklander size_t sz __maybe_unused, uint32_t flags) 90165137432SJens Wiklander { 90265137432SJens Wiklander int width __maybe_unused = 8; 90365137432SJens Wiklander char desc[14] __maybe_unused = ""; 90465137432SJens Wiklander char flags_str[] __maybe_unused = "----"; 90565137432SJens Wiklander 90665137432SJens Wiklander if (elf_idx > -1) { 90765137432SJens Wiklander snprintf(desc, sizeof(desc), " [%d]", elf_idx); 90865137432SJens Wiklander } else { 90965137432SJens Wiklander if (flags & DUMP_MAP_EPHEM) 91065137432SJens Wiklander snprintf(desc, sizeof(desc), " (param)"); 91165137432SJens Wiklander if (flags & DUMP_MAP_LDELF) 91265137432SJens Wiklander snprintf(desc, sizeof(desc), " (ldelf)"); 91365137432SJens Wiklander if (va == ta_stack) 91465137432SJens Wiklander snprintf(desc, sizeof(desc), " (stack)"); 91565137432SJens Wiklander } 91665137432SJens Wiklander 91765137432SJens Wiklander if (flags & DUMP_MAP_READ) 91865137432SJens Wiklander flags_str[0] = 'r'; 91965137432SJens Wiklander if (flags & DUMP_MAP_WRITE) 92065137432SJens Wiklander flags_str[1] = 'w'; 92165137432SJens Wiklander if (flags & DUMP_MAP_EXEC) 92265137432SJens Wiklander flags_str[2] = 'x'; 92365137432SJens Wiklander if (flags & DUMP_MAP_SECURE) 92465137432SJens Wiklander flags_str[3] = 's'; 92565137432SJens Wiklander 92665137432SJens Wiklander EMSG_RAW("region %2zu: va 0x%0*"PRIxVA" pa 0x%0*"PRIxPA" size 0x%06zx flags %s%s", 92765137432SJens Wiklander idx, width, va, width, pa, sz, flags_str, desc); 92865137432SJens Wiklander } 92965137432SJens Wiklander 930*6720dd49SJens Wiklander static bool get_next_in_order(struct ta_elf_queue *elf_queue, 931*6720dd49SJens Wiklander struct ta_elf **elf, struct segment **seg, 932*6720dd49SJens Wiklander size_t *elf_idx) 933*6720dd49SJens Wiklander { 934*6720dd49SJens Wiklander struct ta_elf *e = NULL; 935*6720dd49SJens Wiklander struct segment *s = NULL; 936*6720dd49SJens Wiklander size_t idx = 0; 937*6720dd49SJens Wiklander vaddr_t va = 0; 938*6720dd49SJens Wiklander struct ta_elf *e2 = NULL; 939*6720dd49SJens Wiklander size_t i2 = 0; 940*6720dd49SJens Wiklander 941*6720dd49SJens Wiklander assert(elf && seg && elf_idx); 942*6720dd49SJens Wiklander e = *elf; 943*6720dd49SJens Wiklander s = *seg; 944*6720dd49SJens Wiklander assert((e == NULL && s == NULL) || (e != NULL && s != NULL)); 945*6720dd49SJens Wiklander 946*6720dd49SJens Wiklander if (s) { 947*6720dd49SJens Wiklander s = TAILQ_NEXT(s, link); 948*6720dd49SJens Wiklander if (s) { 949*6720dd49SJens Wiklander *seg = s; 950*6720dd49SJens Wiklander return true; 951*6720dd49SJens Wiklander } 952*6720dd49SJens Wiklander } 953*6720dd49SJens Wiklander 954*6720dd49SJens Wiklander if (e) 955*6720dd49SJens Wiklander va = e->load_addr; 956*6720dd49SJens Wiklander 957*6720dd49SJens Wiklander /* Find the ELF with next load address */ 958*6720dd49SJens Wiklander e = NULL; 959*6720dd49SJens Wiklander TAILQ_FOREACH(e2, elf_queue, link) { 960*6720dd49SJens Wiklander if (e2->load_addr > va) { 961*6720dd49SJens Wiklander if (!e || e2->load_addr < e->load_addr) { 962*6720dd49SJens Wiklander e = e2; 963*6720dd49SJens Wiklander idx = i2; 964*6720dd49SJens Wiklander } 965*6720dd49SJens Wiklander } 966*6720dd49SJens Wiklander i2++; 967*6720dd49SJens Wiklander } 968*6720dd49SJens Wiklander if (!e) 969*6720dd49SJens Wiklander return false; 970*6720dd49SJens Wiklander 971*6720dd49SJens Wiklander *elf = e; 972*6720dd49SJens Wiklander *seg = TAILQ_FIRST(&e->segs); 973*6720dd49SJens Wiklander *elf_idx = idx; 974*6720dd49SJens Wiklander return true; 975*6720dd49SJens Wiklander } 976*6720dd49SJens Wiklander 97765137432SJens Wiklander void ta_elf_print_mappings(struct ta_elf_queue *elf_queue, size_t num_maps, 97865137432SJens Wiklander struct dump_map *maps, vaddr_t mpool_base) 97965137432SJens Wiklander { 98065137432SJens Wiklander struct segment *seg = NULL; 98165137432SJens Wiklander struct ta_elf *elf = NULL; 98265137432SJens Wiklander size_t elf_idx = 0; 98365137432SJens Wiklander size_t idx = 0; 98465137432SJens Wiklander size_t map_idx = 0; 98565137432SJens Wiklander 98665137432SJens Wiklander /* 98765137432SJens Wiklander * Loop over all segments and maps, printing virtual address in 98865137432SJens Wiklander * order. Segment has priority if the virtual address is present 98965137432SJens Wiklander * in both map and segment. 99065137432SJens Wiklander */ 991*6720dd49SJens Wiklander get_next_in_order(elf_queue, &elf, &seg, &elf_idx); 99265137432SJens Wiklander while (true) { 99365137432SJens Wiklander vaddr_t va = -1; 99465137432SJens Wiklander size_t sz = 0; 99565137432SJens Wiklander uint32_t flags = DUMP_MAP_SECURE; 99665137432SJens Wiklander size_t offs = 0; 99765137432SJens Wiklander 99865137432SJens Wiklander if (seg) { 99965137432SJens Wiklander va = rounddown(seg->vaddr + elf->load_addr); 100065137432SJens Wiklander sz = roundup(seg->vaddr + seg->memsz) - 100165137432SJens Wiklander rounddown(seg->vaddr); 100265137432SJens Wiklander } 100365137432SJens Wiklander 100465137432SJens Wiklander while (map_idx < num_maps && maps[map_idx].va <= va) { 100565137432SJens Wiklander uint32_t f = 0; 100665137432SJens Wiklander 100765137432SJens Wiklander /* If there's a match, it should be the same map */ 100865137432SJens Wiklander if (maps[map_idx].va == va) { 100965137432SJens Wiklander /* 101065137432SJens Wiklander * In shared libraries the first page is 101165137432SJens Wiklander * mapped separately with the rest of that 101265137432SJens Wiklander * segment following back to back in a 101365137432SJens Wiklander * separate entry. 101465137432SJens Wiklander */ 101565137432SJens Wiklander if (map_idx + 1 < num_maps && 101665137432SJens Wiklander maps[map_idx].sz == SMALL_PAGE_SIZE) { 101765137432SJens Wiklander vaddr_t next_va = maps[map_idx].va + 101865137432SJens Wiklander maps[map_idx].sz; 101965137432SJens Wiklander size_t comb_sz = maps[map_idx].sz + 102065137432SJens Wiklander maps[map_idx + 1].sz; 102165137432SJens Wiklander 102265137432SJens Wiklander if (next_va == maps[map_idx + 1].va && 102365137432SJens Wiklander comb_sz == sz && 102465137432SJens Wiklander maps[map_idx].flags == 102565137432SJens Wiklander maps[map_idx + 1].flags) { 102665137432SJens Wiklander /* Skip this and next entry */ 102765137432SJens Wiklander map_idx += 2; 102865137432SJens Wiklander continue; 102965137432SJens Wiklander } 103065137432SJens Wiklander } 103165137432SJens Wiklander assert(maps[map_idx].sz == sz); 103265137432SJens Wiklander } else if (maps[map_idx].va < va) { 103365137432SJens Wiklander if (maps[map_idx].va == mpool_base) 103465137432SJens Wiklander f |= DUMP_MAP_LDELF; 103565137432SJens Wiklander print_seg(idx, -1, maps[map_idx].va, 103665137432SJens Wiklander maps[map_idx].pa, maps[map_idx].sz, 103765137432SJens Wiklander maps[map_idx].flags | f); 103865137432SJens Wiklander idx++; 103965137432SJens Wiklander } 104065137432SJens Wiklander map_idx++; 104165137432SJens Wiklander } 104265137432SJens Wiklander 104365137432SJens Wiklander if (!seg) 104465137432SJens Wiklander break; 104565137432SJens Wiklander 104665137432SJens Wiklander offs = rounddown(seg->offset); 104765137432SJens Wiklander if (seg->flags & PF_R) 104865137432SJens Wiklander flags |= DUMP_MAP_READ; 104965137432SJens Wiklander if (seg->flags & PF_W) 105065137432SJens Wiklander flags |= DUMP_MAP_WRITE; 105165137432SJens Wiklander if (seg->flags & PF_X) 105265137432SJens Wiklander flags |= DUMP_MAP_EXEC; 105365137432SJens Wiklander 105465137432SJens Wiklander print_seg(idx, elf_idx, va, offs, sz, flags); 105565137432SJens Wiklander idx++; 105665137432SJens Wiklander 1057*6720dd49SJens Wiklander if (!get_next_in_order(elf_queue, &elf, &seg, &elf_idx)) 1058*6720dd49SJens Wiklander seg = NULL; 105965137432SJens Wiklander } 106065137432SJens Wiklander 106165137432SJens Wiklander elf_idx = 0; 106265137432SJens Wiklander TAILQ_FOREACH(elf, elf_queue, link) { 106365137432SJens Wiklander EMSG_RAW(" [%zu] %pUl @ 0x%0*" PRIxVA, 106465137432SJens Wiklander elf_idx, (void *)&elf->uuid, 8, elf->load_addr); 106565137432SJens Wiklander elf_idx++; 106665137432SJens Wiklander } 106765137432SJens Wiklander } 10680242833aSJens Wiklander 10690242833aSJens Wiklander #ifdef CFG_UNWIND 10700242833aSJens Wiklander void ta_elf_stack_trace_a32(uint32_t regs[16]) 10710242833aSJens Wiklander { 10720242833aSJens Wiklander struct unwind_state_arm32 state = { }; 10730242833aSJens Wiklander 10740242833aSJens Wiklander memcpy(state.registers, regs, sizeof(state.registers)); 10750242833aSJens Wiklander print_stack_arm32(&state, ta_stack, ta_stack_size); 10760242833aSJens Wiklander } 10770242833aSJens Wiklander 10780242833aSJens Wiklander void ta_elf_stack_trace_a64(uint64_t fp, uint64_t sp, uint64_t pc) 10790242833aSJens Wiklander { 10800242833aSJens Wiklander struct unwind_state_arm64 state = { .fp = fp, .sp = sp, .pc = pc }; 10810242833aSJens Wiklander 10820242833aSJens Wiklander print_stack_arm64(&state, ta_stack, ta_stack_size); 10830242833aSJens Wiklander } 10840242833aSJens Wiklander #endif 1085