xref: /optee_os/ldelf/ta_elf_rel.c (revision bb8cd6f08ea47e3f0d58169846fee0bbae18caae)
17509ff7cSJens Wiklander // SPDX-License-Identifier: BSD-2-Clause
27509ff7cSJens Wiklander /*
37509ff7cSJens Wiklander  * Copyright (c) 2019, Linaro Limited
47509ff7cSJens Wiklander  */
57509ff7cSJens Wiklander 
67509ff7cSJens Wiklander #include <assert.h>
75548a710SJerome Forissier #include <compiler.h>
855e64090SJens Wiklander #include <confine_array_index.h>
97509ff7cSJens Wiklander #include <elf32.h>
107509ff7cSJens Wiklander #include <elf64.h>
117509ff7cSJens Wiklander #include <elf_common.h>
127509ff7cSJens Wiklander #include <string.h>
137509ff7cSJens Wiklander #include <tee_api_types.h>
147509ff7cSJens Wiklander #include <util.h>
157509ff7cSJens Wiklander 
167509ff7cSJens Wiklander #include "sys.h"
177509ff7cSJens Wiklander #include "ta_elf.h"
187509ff7cSJens Wiklander 
199f392760SJerome Forissier static uint32_t elf_hash(const char *name)
209f392760SJerome Forissier {
219f392760SJerome Forissier 	const unsigned char *p = (const unsigned char *)name;
229f392760SJerome Forissier 	uint32_t h = 0;
239f392760SJerome Forissier 	uint32_t g = 0;
249f392760SJerome Forissier 
259f392760SJerome Forissier 	while (*p) {
269f392760SJerome Forissier 		h = (h << 4) + *p++;
279f392760SJerome Forissier 		g = h & 0xf0000000;
289f392760SJerome Forissier 		if (g)
299f392760SJerome Forissier 			h ^= g >> 24;
309f392760SJerome Forissier 		h &= ~g;
319f392760SJerome Forissier 	}
329f392760SJerome Forissier 	return h;
339f392760SJerome Forissier }
349f392760SJerome Forissier 
3597c5ac19SJens Wiklander static bool __resolve_sym(struct ta_elf *elf, unsigned int st_bind,
3697c5ac19SJens Wiklander 			  unsigned int st_type, size_t st_shndx,
3797c5ac19SJens Wiklander 			  size_t st_name, size_t st_value, const char *name,
3897c5ac19SJens Wiklander 			  vaddr_t *val)
397509ff7cSJens Wiklander {
4097c5ac19SJens Wiklander 	if (st_bind != STB_GLOBAL)
417509ff7cSJens Wiklander 		return false;
427509ff7cSJens Wiklander 	if (st_shndx == SHN_UNDEF || st_shndx == SHN_XINDEX)
437509ff7cSJens Wiklander 		return false;
447509ff7cSJens Wiklander 	if (!st_name)
457509ff7cSJens Wiklander 		return false;
467509ff7cSJens Wiklander 	if (st_name > elf->dynstr_size)
4797c5ac19SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Symbol name out of range");
487509ff7cSJens Wiklander 
497509ff7cSJens Wiklander 	if (strcmp(name, elf->dynstr + st_name))
507509ff7cSJens Wiklander 		return false;
517509ff7cSJens Wiklander 
5297c5ac19SJens Wiklander 	if (st_value > (elf->max_addr - elf->load_addr))
5397c5ac19SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Symbol location out of range");
5497c5ac19SJens Wiklander 
5597c5ac19SJens Wiklander 	switch (st_type) {
56*bb8cd6f0SJerome Forissier 	case STT_NOTYPE:
5797c5ac19SJens Wiklander 	case STT_OBJECT:
5897c5ac19SJens Wiklander 	case STT_FUNC:
597509ff7cSJens Wiklander 		*val = st_value + elf->load_addr;
6097c5ac19SJens Wiklander 		break;
6197c5ac19SJens Wiklander 	default:
6297c5ac19SJens Wiklander 		err(TEE_ERROR_NOT_SUPPORTED, "Symbol type not supported");
6397c5ac19SJens Wiklander 	}
6497c5ac19SJens Wiklander 
657509ff7cSJens Wiklander 	return true;
667509ff7cSJens Wiklander }
677509ff7cSJens Wiklander 
68ebef121cSJerome Forissier static TEE_Result resolve_sym_helper(uint32_t hash, const char *name,
69ebef121cSJerome Forissier 				     vaddr_t *val, struct ta_elf *elf)
707509ff7cSJens Wiklander {
719f392760SJerome Forissier 	/*
729f392760SJerome Forissier 	 * Using uint32_t here for convenience because both Elf64_Word
739f392760SJerome Forissier 	 * and Elf32_Word are 32-bit types
749f392760SJerome Forissier 	 */
759f392760SJerome Forissier 	uint32_t *hashtab = elf->hashtab;
769f392760SJerome Forissier 	uint32_t nbuckets = hashtab[0];
779f392760SJerome Forissier 	uint32_t nchains = hashtab[1];
789f392760SJerome Forissier 	uint32_t *bucket = &hashtab[2];
799f392760SJerome Forissier 	uint32_t *chain = &bucket[nbuckets];
80ebef121cSJerome Forissier 	size_t n = 0;
819f392760SJerome Forissier 
827509ff7cSJens Wiklander 	if (elf->is_32bit) {
837509ff7cSJens Wiklander 		Elf32_Sym *sym = elf->dynsymtab;
847509ff7cSJens Wiklander 
859f392760SJerome Forissier 		for (n = bucket[hash % nbuckets]; n; n = chain[n]) {
868dbe2cbdSJens Wiklander 			if (n >= nchains || n >= elf->num_dynsyms)
875c0860dbSJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
885c0860dbSJens Wiklander 				    "Index out of range");
8955e64090SJens Wiklander 			/*
9055e64090SJens Wiklander 			 * We're loading values from sym[] which later
9155e64090SJens Wiklander 			 * will be used to load something.
9255e64090SJens Wiklander 			 * => Spectre V1 pattern, need to cap the index
9355e64090SJens Wiklander 			 * against speculation.
9455e64090SJens Wiklander 			 */
9555e64090SJens Wiklander 			n = confine_array_index(n, elf->num_dynsyms);
967509ff7cSJens Wiklander 			if (__resolve_sym(elf,
977509ff7cSJens Wiklander 					  ELF32_ST_BIND(sym[n].st_info),
9897c5ac19SJens Wiklander 					  ELF32_ST_TYPE(sym[n].st_info),
997509ff7cSJens Wiklander 					  sym[n].st_shndx,
1007509ff7cSJens Wiklander 					  sym[n].st_name,
1017509ff7cSJens Wiklander 					  sym[n].st_value, name, val))
102c86f218cSJens Wiklander 				return TEE_SUCCESS;
1037509ff7cSJens Wiklander 		}
1047509ff7cSJens Wiklander 	} else {
1057509ff7cSJens Wiklander 		Elf64_Sym *sym = elf->dynsymtab;
1067509ff7cSJens Wiklander 
1079f392760SJerome Forissier 		for (n = bucket[hash % nbuckets]; n; n = chain[n]) {
1088dbe2cbdSJens Wiklander 			if (n >= nchains || n >= elf->num_dynsyms)
1095c0860dbSJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
1105c0860dbSJens Wiklander 				    "Index out of range");
11155e64090SJens Wiklander 			/*
11255e64090SJens Wiklander 			 * We're loading values from sym[] which later
11355e64090SJens Wiklander 			 * will be used to load something.
11455e64090SJens Wiklander 			 * => Spectre V1 pattern, need to cap the index
11555e64090SJens Wiklander 			 * against speculation.
11655e64090SJens Wiklander 			 */
11755e64090SJens Wiklander 			n = confine_array_index(n, elf->num_dynsyms);
1187509ff7cSJens Wiklander 			if (__resolve_sym(elf,
1197509ff7cSJens Wiklander 					  ELF64_ST_BIND(sym[n].st_info),
12097c5ac19SJens Wiklander 					  ELF64_ST_TYPE(sym[n].st_info),
1217509ff7cSJens Wiklander 					  sym[n].st_shndx,
1227509ff7cSJens Wiklander 					  sym[n].st_name,
1237509ff7cSJens Wiklander 					  sym[n].st_value, name, val))
124c86f218cSJens Wiklander 				return TEE_SUCCESS;
1257509ff7cSJens Wiklander 		}
1267509ff7cSJens Wiklander 	}
127ebef121cSJerome Forissier 
128ebef121cSJerome Forissier 	return TEE_ERROR_ITEM_NOT_FOUND;
1297509ff7cSJens Wiklander }
130c86f218cSJens Wiklander 
131ebef121cSJerome Forissier TEE_Result ta_elf_resolve_sym(const char *name, vaddr_t *val,
132ebef121cSJerome Forissier 			      struct ta_elf *elf)
133ebef121cSJerome Forissier {
134ebef121cSJerome Forissier 	uint32_t hash = elf_hash(name);
135ebef121cSJerome Forissier 
136ebef121cSJerome Forissier 	if (elf)
137ebef121cSJerome Forissier 		return resolve_sym_helper(hash, name, val, elf);
138ebef121cSJerome Forissier 
139ebef121cSJerome Forissier 	TAILQ_FOREACH(elf, &main_elf_queue, link)
140ebef121cSJerome Forissier 		if (!resolve_sym_helper(hash, name, val, elf))
141ebef121cSJerome Forissier 			return TEE_SUCCESS;
142ebef121cSJerome Forissier 
143c86f218cSJens Wiklander 	return TEE_ERROR_ITEM_NOT_FOUND;
144c86f218cSJens Wiklander }
145c86f218cSJens Wiklander 
146c86f218cSJens Wiklander static void resolve_sym(const char *name, vaddr_t *val)
147c86f218cSJens Wiklander {
148ebef121cSJerome Forissier 	TEE_Result res = ta_elf_resolve_sym(name, val, NULL);
149c86f218cSJens Wiklander 
150c86f218cSJens Wiklander 	if (res)
151c86f218cSJens Wiklander 		err(res, "Symbol %s not found", name);
1527509ff7cSJens Wiklander }
1537509ff7cSJens Wiklander 
1547509ff7cSJens Wiklander static void e32_process_dyn_rel(const Elf32_Sym *sym_tab, size_t num_syms,
1557509ff7cSJens Wiklander 				const char *str_tab, size_t str_tab_size,
1567509ff7cSJens Wiklander 				Elf32_Rel *rel, Elf32_Addr *where)
1577509ff7cSJens Wiklander {
1587509ff7cSJens Wiklander 	size_t sym_idx = 0;
1597509ff7cSJens Wiklander 	const char *name = NULL;
1607509ff7cSJens Wiklander 	vaddr_t val = 0;
1617509ff7cSJens Wiklander 	size_t name_idx = 0;
1627509ff7cSJens Wiklander 
1637509ff7cSJens Wiklander 	sym_idx = ELF32_R_SYM(rel->r_info);
164447354c6SJens Wiklander 	if (sym_idx >= num_syms)
165e97bbbb2SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Symbol index out of range");
16655e64090SJens Wiklander 	sym_idx = confine_array_index(sym_idx, num_syms);
1677509ff7cSJens Wiklander 
1687509ff7cSJens Wiklander 	name_idx = sym_tab[sym_idx].st_name;
169447354c6SJens Wiklander 	if (name_idx >= str_tab_size)
170e97bbbb2SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Name index out of range");
1717509ff7cSJens Wiklander 	name = str_tab + name_idx;
1727509ff7cSJens Wiklander 
1737509ff7cSJens Wiklander 	resolve_sym(name, &val);
1747509ff7cSJens Wiklander 	*where = val;
1757509ff7cSJens Wiklander }
1767509ff7cSJens Wiklander 
1777509ff7cSJens Wiklander static void e32_relocate(struct ta_elf *elf, unsigned int rel_sidx)
1787509ff7cSJens Wiklander {
1797509ff7cSJens Wiklander 	Elf32_Shdr *shdr = elf->shdr;
1807509ff7cSJens Wiklander 	Elf32_Rel *rel = NULL;
1817509ff7cSJens Wiklander 	Elf32_Rel *rel_end = NULL;
1827509ff7cSJens Wiklander 	size_t sym_tab_idx = 0;
1837509ff7cSJens Wiklander 	Elf32_Sym *sym_tab = NULL;
1847509ff7cSJens Wiklander 	size_t num_syms = 0;
1857509ff7cSJens Wiklander 	size_t sh_end = 0;
1867509ff7cSJens Wiklander 	const char *str_tab = NULL;
1877509ff7cSJens Wiklander 	size_t str_tab_size = 0;
1887509ff7cSJens Wiklander 
1897509ff7cSJens Wiklander 	assert(shdr[rel_sidx].sh_type == SHT_REL);
1907509ff7cSJens Wiklander 
1917509ff7cSJens Wiklander 	assert(shdr[rel_sidx].sh_entsize == sizeof(Elf32_Rel));
1927509ff7cSJens Wiklander 
1937509ff7cSJens Wiklander 	sym_tab_idx = shdr[rel_sidx].sh_link;
1947509ff7cSJens Wiklander 	if (sym_tab_idx) {
1957509ff7cSJens Wiklander 		size_t str_tab_idx = 0;
1967509ff7cSJens Wiklander 
197447354c6SJens Wiklander 		if (sym_tab_idx >= elf->e_shnum)
198dcf64f87SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "SYMTAB index out of range");
19955e64090SJens Wiklander 		sym_tab_idx = confine_array_index(sym_tab_idx, elf->e_shnum);
2007509ff7cSJens Wiklander 
2017509ff7cSJens Wiklander 		assert(shdr[sym_tab_idx].sh_entsize == sizeof(Elf32_Sym));
2027509ff7cSJens Wiklander 
2037509ff7cSJens Wiklander 		/* Check the address is inside ELF memory */
2047509ff7cSJens Wiklander 		if (ADD_OVERFLOW(shdr[sym_tab_idx].sh_addr,
2057509ff7cSJens Wiklander 				 shdr[sym_tab_idx].sh_size, &sh_end))
206e97bbbb2SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "Overflow");
207447354c6SJens Wiklander 		if (sh_end >= (elf->max_addr - elf->load_addr))
208dcf64f87SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "SYMTAB out of range");
2097509ff7cSJens Wiklander 
2107509ff7cSJens Wiklander 		sym_tab = (Elf32_Sym *)(elf->load_addr +
2117509ff7cSJens Wiklander 					shdr[sym_tab_idx].sh_addr);
2127509ff7cSJens Wiklander 
2137509ff7cSJens Wiklander 		num_syms = shdr[sym_tab_idx].sh_size / sizeof(Elf32_Sym);
2147509ff7cSJens Wiklander 
2157509ff7cSJens Wiklander 		str_tab_idx = shdr[sym_tab_idx].sh_link;
2167509ff7cSJens Wiklander 		if (str_tab_idx) {
21755e64090SJens Wiklander 			if (str_tab_idx >= elf->e_shnum)
218e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
219dcf64f87SJens Wiklander 				    "STRTAB index out of range");
22055e64090SJens Wiklander 			str_tab_idx = confine_array_index(str_tab_idx,
22155e64090SJens Wiklander 							  elf->e_shnum);
22255e64090SJens Wiklander 
2237509ff7cSJens Wiklander 			/* Check the address is inside ELF memory */
2247509ff7cSJens Wiklander 			if (ADD_OVERFLOW(shdr[str_tab_idx].sh_addr,
2257509ff7cSJens Wiklander 					 shdr[str_tab_idx].sh_size, &sh_end))
226e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT, "Overflow");
227447354c6SJens Wiklander 			if (sh_end >= (elf->max_addr - elf->load_addr))
228e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
229dcf64f87SJens Wiklander 				    "STRTAB out of range");
2307509ff7cSJens Wiklander 
2317509ff7cSJens Wiklander 			str_tab = (const char *)(elf->load_addr +
2327509ff7cSJens Wiklander 						 shdr[str_tab_idx].sh_addr);
2337509ff7cSJens Wiklander 			str_tab_size = shdr[str_tab_idx].sh_size;
2347509ff7cSJens Wiklander 		}
2357509ff7cSJens Wiklander 	}
2367509ff7cSJens Wiklander 
2377509ff7cSJens Wiklander 	/* Check the address is inside TA memory */
238447354c6SJens Wiklander 	if (ADD_OVERFLOW(shdr[rel_sidx].sh_addr,
239447354c6SJens Wiklander 			 shdr[rel_sidx].sh_size, &sh_end))
240e97bbbb2SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Overflow");
241447354c6SJens Wiklander 	if (sh_end >= (elf->max_addr - elf->load_addr))
242dcf64f87SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, ".rel.*/REL out of range");
2437509ff7cSJens Wiklander 	rel = (Elf32_Rel *)(elf->load_addr + shdr[rel_sidx].sh_addr);
2447509ff7cSJens Wiklander 
2457509ff7cSJens Wiklander 	rel_end = rel + shdr[rel_sidx].sh_size / sizeof(Elf32_Rel);
2467509ff7cSJens Wiklander 	for (; rel < rel_end; rel++) {
2477509ff7cSJens Wiklander 		Elf32_Addr *where = NULL;
2487509ff7cSJens Wiklander 		size_t sym_idx = 0;
2497509ff7cSJens Wiklander 
2507509ff7cSJens Wiklander 		/* Check the address is inside TA memory */
251447354c6SJens Wiklander 		if (rel->r_offset >= (elf->max_addr - elf->load_addr))
252e97bbbb2SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT,
253447354c6SJens Wiklander 			    "Relocation offset out of range");
2547509ff7cSJens Wiklander 		where = (Elf32_Addr *)(elf->load_addr + rel->r_offset);
2557509ff7cSJens Wiklander 
2567509ff7cSJens Wiklander 		switch (ELF32_R_TYPE(rel->r_info)) {
2577509ff7cSJens Wiklander 		case R_ARM_ABS32:
2587509ff7cSJens Wiklander 			sym_idx = ELF32_R_SYM(rel->r_info);
259447354c6SJens Wiklander 			if (sym_idx >= num_syms)
260e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
261447354c6SJens Wiklander 				    "Symbol index out of range");
2627509ff7cSJens Wiklander 			if (sym_tab[sym_idx].st_shndx == SHN_UNDEF) {
2637509ff7cSJens Wiklander 				/* Symbol is external */
2647509ff7cSJens Wiklander 				e32_process_dyn_rel(sym_tab, num_syms, str_tab,
2657509ff7cSJens Wiklander 						    str_tab_size, rel, where);
2667509ff7cSJens Wiklander 			} else {
2677509ff7cSJens Wiklander 				*where += elf->load_addr +
2687509ff7cSJens Wiklander 					  sym_tab[sym_idx].st_value;
2697509ff7cSJens Wiklander 			}
2707509ff7cSJens Wiklander 			break;
2717509ff7cSJens Wiklander 		case R_ARM_REL32:
2727509ff7cSJens Wiklander 			sym_idx = ELF32_R_SYM(rel->r_info);
273447354c6SJens Wiklander 			if (sym_idx >= num_syms)
274e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
275447354c6SJens Wiklander 				    "Symbol index out of range");
2767509ff7cSJens Wiklander 			*where += sym_tab[sym_idx].st_value - rel->r_offset;
2777509ff7cSJens Wiklander 			break;
2787509ff7cSJens Wiklander 		case R_ARM_RELATIVE:
2797509ff7cSJens Wiklander 			*where += elf->load_addr;
2807509ff7cSJens Wiklander 			break;
2817509ff7cSJens Wiklander 		case R_ARM_GLOB_DAT:
2827509ff7cSJens Wiklander 		case R_ARM_JUMP_SLOT:
2837509ff7cSJens Wiklander 			e32_process_dyn_rel(sym_tab, num_syms, str_tab,
2847509ff7cSJens Wiklander 					    str_tab_size, rel, where);
2857509ff7cSJens Wiklander 			break;
2867509ff7cSJens Wiklander 		default:
2877509ff7cSJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "Unknown relocation type %d",
2887509ff7cSJens Wiklander 			     ELF32_R_TYPE(rel->r_info));
2897509ff7cSJens Wiklander 		}
2907509ff7cSJens Wiklander 	}
2917509ff7cSJens Wiklander }
2927509ff7cSJens Wiklander 
2937509ff7cSJens Wiklander #ifdef ARM64
2947509ff7cSJens Wiklander static void e64_process_dyn_rela(const Elf64_Sym *sym_tab, size_t num_syms,
2957509ff7cSJens Wiklander 				 const char *str_tab, size_t str_tab_size,
2967509ff7cSJens Wiklander 				 Elf64_Rela *rela, Elf64_Addr *where)
2977509ff7cSJens Wiklander {
2987509ff7cSJens Wiklander 	size_t sym_idx = 0;
2997509ff7cSJens Wiklander 	const char *name = NULL;
3007509ff7cSJens Wiklander 	uintptr_t val = 0;
3017509ff7cSJens Wiklander 	size_t name_idx = 0;
3027509ff7cSJens Wiklander 
3037509ff7cSJens Wiklander 	sym_idx = ELF64_R_SYM(rela->r_info);
304447354c6SJens Wiklander 	if (sym_idx >= num_syms)
305e97bbbb2SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Symbol index out of range");
30655e64090SJens Wiklander 	sym_idx = confine_array_index(sym_idx, num_syms);
3077509ff7cSJens Wiklander 
3087509ff7cSJens Wiklander 	name_idx = sym_tab[sym_idx].st_name;
309447354c6SJens Wiklander 	if (name_idx >= str_tab_size)
310e97bbbb2SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Name index out of range");
3117509ff7cSJens Wiklander 	name = str_tab + name_idx;
3127509ff7cSJens Wiklander 
3137509ff7cSJens Wiklander 	resolve_sym(name, &val);
3147509ff7cSJens Wiklander 	*where = val;
3157509ff7cSJens Wiklander }
3167509ff7cSJens Wiklander 
3177509ff7cSJens Wiklander static void e64_relocate(struct ta_elf *elf, unsigned int rel_sidx)
3187509ff7cSJens Wiklander {
3197509ff7cSJens Wiklander 	Elf64_Shdr *shdr = elf->shdr;
3207509ff7cSJens Wiklander 	Elf64_Rela *rela = NULL;
3217509ff7cSJens Wiklander 	Elf64_Rela *rela_end = NULL;
3227509ff7cSJens Wiklander 	size_t sym_tab_idx = 0;
3237509ff7cSJens Wiklander 	Elf64_Sym *sym_tab = NULL;
3247509ff7cSJens Wiklander 	size_t num_syms = 0;
3257509ff7cSJens Wiklander 	size_t sh_end = 0;
3267509ff7cSJens Wiklander 	const char *str_tab = NULL;
3277509ff7cSJens Wiklander 	size_t str_tab_size = 0;
3287509ff7cSJens Wiklander 
3297509ff7cSJens Wiklander 	assert(shdr[rel_sidx].sh_type == SHT_RELA);
3307509ff7cSJens Wiklander 
3317509ff7cSJens Wiklander 	assert(shdr[rel_sidx].sh_entsize == sizeof(Elf64_Rela));
3327509ff7cSJens Wiklander 
3337509ff7cSJens Wiklander 	sym_tab_idx = shdr[rel_sidx].sh_link;
3347509ff7cSJens Wiklander 	if (sym_tab_idx) {
3357509ff7cSJens Wiklander 		size_t str_tab_idx = 0;
3367509ff7cSJens Wiklander 
337447354c6SJens Wiklander 		if (sym_tab_idx >= elf->e_shnum)
338dcf64f87SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "SYMTAB index out of range");
33955e64090SJens Wiklander 		sym_tab_idx = confine_array_index(sym_tab_idx, elf->e_shnum);
3407509ff7cSJens Wiklander 
3417509ff7cSJens Wiklander 		assert(shdr[sym_tab_idx].sh_entsize == sizeof(Elf64_Sym));
3427509ff7cSJens Wiklander 
3437509ff7cSJens Wiklander 		/* Check the address is inside TA memory */
3447509ff7cSJens Wiklander 		if (ADD_OVERFLOW(shdr[sym_tab_idx].sh_addr,
3457509ff7cSJens Wiklander 				 shdr[sym_tab_idx].sh_size, &sh_end))
346e97bbbb2SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "Overflow");
347447354c6SJens Wiklander 		if (sh_end >= (elf->max_addr - elf->load_addr))
348dcf64f87SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "SYMTAB out of range");
3497509ff7cSJens Wiklander 
3507509ff7cSJens Wiklander 		sym_tab = (Elf64_Sym *)(elf->load_addr +
3517509ff7cSJens Wiklander 					shdr[sym_tab_idx].sh_addr);
3527509ff7cSJens Wiklander 
3537509ff7cSJens Wiklander 		num_syms = shdr[sym_tab_idx].sh_size / sizeof(Elf64_Sym);
3547509ff7cSJens Wiklander 
3557509ff7cSJens Wiklander 		str_tab_idx = shdr[sym_tab_idx].sh_link;
3567509ff7cSJens Wiklander 		if (str_tab_idx) {
35755e64090SJens Wiklander 			if (str_tab_idx >= elf->e_shnum)
358e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
359dcf64f87SJens Wiklander 				    "STRTAB index out of range");
36055e64090SJens Wiklander 			str_tab_idx = confine_array_index(str_tab_idx,
36155e64090SJens Wiklander 							  elf->e_shnum);
36255e64090SJens Wiklander 
3637509ff7cSJens Wiklander 			/* Check the address is inside ELF memory */
3647509ff7cSJens Wiklander 			if (ADD_OVERFLOW(shdr[str_tab_idx].sh_addr,
3657509ff7cSJens Wiklander 					 shdr[str_tab_idx].sh_size, &sh_end))
366e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT, "Overflow");
367447354c6SJens Wiklander 			if (sh_end >= (elf->max_addr - elf->load_addr))
368e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
369dcf64f87SJens Wiklander 				    "STRTAB out of range");
3707509ff7cSJens Wiklander 
3717509ff7cSJens Wiklander 			str_tab = (const char *)(elf->load_addr +
3727509ff7cSJens Wiklander 						 shdr[str_tab_idx].sh_addr);
3737509ff7cSJens Wiklander 			str_tab_size = shdr[str_tab_idx].sh_size;
3747509ff7cSJens Wiklander 		}
3757509ff7cSJens Wiklander 	}
3767509ff7cSJens Wiklander 
3777509ff7cSJens Wiklander 	/* Check the address is inside TA memory */
378447354c6SJens Wiklander 	if (ADD_OVERFLOW(shdr[rel_sidx].sh_addr,
379447354c6SJens Wiklander 			 shdr[rel_sidx].sh_size, &sh_end))
380e97bbbb2SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, "Overflow");
381447354c6SJens Wiklander 	if (sh_end >= (elf->max_addr - elf->load_addr))
382dcf64f87SJens Wiklander 		err(TEE_ERROR_BAD_FORMAT, ".rel.*/REL out of range");
3837509ff7cSJens Wiklander 	rela = (Elf64_Rela *)(elf->load_addr + shdr[rel_sidx].sh_addr);
3847509ff7cSJens Wiklander 
3857509ff7cSJens Wiklander 	rela_end = rela + shdr[rel_sidx].sh_size / sizeof(Elf64_Rela);
3867509ff7cSJens Wiklander 	for (; rela < rela_end; rela++) {
3877509ff7cSJens Wiklander 		Elf64_Addr *where = NULL;
3887509ff7cSJens Wiklander 		size_t sym_idx = 0;
3897509ff7cSJens Wiklander 
3907509ff7cSJens Wiklander 		/* Check the address is inside TA memory */
391447354c6SJens Wiklander 		if (rela->r_offset >= (elf->max_addr - elf->load_addr))
392e97bbbb2SJens Wiklander 			err(TEE_ERROR_BAD_FORMAT,
393447354c6SJens Wiklander 			    "Relocation offset out of range");
3947509ff7cSJens Wiklander 
3957509ff7cSJens Wiklander 		where = (Elf64_Addr *)(elf->load_addr + rela->r_offset);
3967509ff7cSJens Wiklander 
3977509ff7cSJens Wiklander 		switch (ELF64_R_TYPE(rela->r_info)) {
3987509ff7cSJens Wiklander 		case R_AARCH64_ABS64:
3997509ff7cSJens Wiklander 			sym_idx = ELF64_R_SYM(rela->r_info);
400447354c6SJens Wiklander 			if (sym_idx >= num_syms)
401e97bbbb2SJens Wiklander 				err(TEE_ERROR_BAD_FORMAT,
402447354c6SJens Wiklander 				    "Symbol index out of range");
40355e64090SJens Wiklander 			sym_idx = confine_array_index(sym_idx, num_syms);
4047509ff7cSJens Wiklander 			if (sym_tab[sym_idx].st_shndx == SHN_UNDEF) {
4057509ff7cSJens Wiklander 				/* Symbol is external */
4067509ff7cSJens Wiklander 				e64_process_dyn_rela(sym_tab, num_syms, str_tab,
4077509ff7cSJens Wiklander 						     str_tab_size, rela, where);
4087509ff7cSJens Wiklander 			} else {
4097509ff7cSJens Wiklander 				*where = rela->r_addend + elf->load_addr +
4107509ff7cSJens Wiklander 					 sym_tab[sym_idx].st_value;
4117509ff7cSJens Wiklander 			}
4127509ff7cSJens Wiklander 			break;
4137509ff7cSJens Wiklander 		case R_AARCH64_RELATIVE:
4147509ff7cSJens Wiklander 			*where = rela->r_addend + elf->load_addr;
4157509ff7cSJens Wiklander 			break;
4167509ff7cSJens Wiklander 		case R_AARCH64_GLOB_DAT:
4177509ff7cSJens Wiklander 		case R_AARCH64_JUMP_SLOT:
4187509ff7cSJens Wiklander 			e64_process_dyn_rela(sym_tab, num_syms, str_tab,
4197509ff7cSJens Wiklander 					     str_tab_size, rela, where);
4207509ff7cSJens Wiklander 			break;
4217509ff7cSJens Wiklander 		default:
4227509ff7cSJens Wiklander 			err(TEE_ERROR_BAD_FORMAT, "Unknown relocation type %zd",
4237509ff7cSJens Wiklander 			     ELF64_R_TYPE(rela->r_info));
4247509ff7cSJens Wiklander 		}
4257509ff7cSJens Wiklander 	}
4267509ff7cSJens Wiklander }
4277509ff7cSJens Wiklander #else /*ARM64*/
4285548a710SJerome Forissier static void __noreturn e64_relocate(struct ta_elf *elf __unused,
4297509ff7cSJens Wiklander 				    unsigned int rel_sidx __unused)
4307509ff7cSJens Wiklander {
4317509ff7cSJens Wiklander 	err(TEE_ERROR_NOT_SUPPORTED, "arm64 not supported");
4327509ff7cSJens Wiklander }
4337509ff7cSJens Wiklander #endif /*ARM64*/
4347509ff7cSJens Wiklander 
4357509ff7cSJens Wiklander void ta_elf_relocate(struct ta_elf *elf)
4367509ff7cSJens Wiklander {
4377509ff7cSJens Wiklander 	size_t n = 0;
4387509ff7cSJens Wiklander 
4397509ff7cSJens Wiklander 	if (elf->is_32bit) {
4407509ff7cSJens Wiklander 		Elf32_Shdr *shdr = elf->shdr;
4417509ff7cSJens Wiklander 
4427509ff7cSJens Wiklander 		for (n = 0; n < elf->e_shnum; n++)
4437509ff7cSJens Wiklander 			if (shdr[n].sh_type == SHT_REL)
4447509ff7cSJens Wiklander 				e32_relocate(elf, n);
4457509ff7cSJens Wiklander 	} else {
4467509ff7cSJens Wiklander 		Elf64_Shdr *shdr = elf->shdr;
4477509ff7cSJens Wiklander 
4487509ff7cSJens Wiklander 		for (n = 0; n < elf->e_shnum; n++)
4497509ff7cSJens Wiklander 			if (shdr[n].sh_type == SHT_RELA)
4507509ff7cSJens Wiklander 				e64_relocate(elf, n);
4517509ff7cSJens Wiklander 
4527509ff7cSJens Wiklander 	}
4537509ff7cSJens Wiklander }
454