17509ff7cSJens Wiklander // SPDX-License-Identifier: BSD-2-Clause 27509ff7cSJens Wiklander /* 37509ff7cSJens Wiklander * Copyright (c) 2019, Linaro Limited 47509ff7cSJens Wiklander */ 57509ff7cSJens Wiklander 67509ff7cSJens Wiklander #include <assert.h> 75548a710SJerome Forissier #include <compiler.h> 855e64090SJens Wiklander #include <confine_array_index.h> 97509ff7cSJens Wiklander #include <elf32.h> 107509ff7cSJens Wiklander #include <elf64.h> 117509ff7cSJens Wiklander #include <elf_common.h> 127509ff7cSJens Wiklander #include <string.h> 137509ff7cSJens Wiklander #include <tee_api_types.h> 147509ff7cSJens Wiklander #include <util.h> 157509ff7cSJens Wiklander 167509ff7cSJens Wiklander #include "sys.h" 177509ff7cSJens Wiklander #include "ta_elf.h" 187509ff7cSJens Wiklander 199f392760SJerome Forissier static uint32_t elf_hash(const char *name) 209f392760SJerome Forissier { 219f392760SJerome Forissier const unsigned char *p = (const unsigned char *)name; 229f392760SJerome Forissier uint32_t h = 0; 239f392760SJerome Forissier uint32_t g = 0; 249f392760SJerome Forissier 259f392760SJerome Forissier while (*p) { 269f392760SJerome Forissier h = (h << 4) + *p++; 279f392760SJerome Forissier g = h & 0xf0000000; 289f392760SJerome Forissier if (g) 299f392760SJerome Forissier h ^= g >> 24; 309f392760SJerome Forissier h &= ~g; 319f392760SJerome Forissier } 329f392760SJerome Forissier return h; 339f392760SJerome Forissier } 349f392760SJerome Forissier 3597c5ac19SJens Wiklander static bool __resolve_sym(struct ta_elf *elf, unsigned int st_bind, 3697c5ac19SJens Wiklander unsigned int st_type, size_t st_shndx, 3797c5ac19SJens Wiklander size_t st_name, size_t st_value, const char *name, 3897c5ac19SJens Wiklander vaddr_t *val) 397509ff7cSJens Wiklander { 4097c5ac19SJens Wiklander if (st_bind != STB_GLOBAL) 417509ff7cSJens Wiklander return false; 427509ff7cSJens Wiklander if (st_shndx == SHN_UNDEF || st_shndx == SHN_XINDEX) 437509ff7cSJens Wiklander return false; 447509ff7cSJens Wiklander if (!st_name) 457509ff7cSJens Wiklander return false; 467509ff7cSJens Wiklander if (st_name > elf->dynstr_size) 4797c5ac19SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Symbol name out of range"); 487509ff7cSJens Wiklander 497509ff7cSJens Wiklander if (strcmp(name, elf->dynstr + st_name)) 507509ff7cSJens Wiklander return false; 517509ff7cSJens Wiklander 5297c5ac19SJens Wiklander if (st_value > (elf->max_addr - elf->load_addr)) 5397c5ac19SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Symbol location out of range"); 5497c5ac19SJens Wiklander 5597c5ac19SJens Wiklander switch (st_type) { 56*bb8cd6f0SJerome Forissier case STT_NOTYPE: 5797c5ac19SJens Wiklander case STT_OBJECT: 5897c5ac19SJens Wiklander case STT_FUNC: 597509ff7cSJens Wiklander *val = st_value + elf->load_addr; 6097c5ac19SJens Wiklander break; 6197c5ac19SJens Wiklander default: 6297c5ac19SJens Wiklander err(TEE_ERROR_NOT_SUPPORTED, "Symbol type not supported"); 6397c5ac19SJens Wiklander } 6497c5ac19SJens Wiklander 657509ff7cSJens Wiklander return true; 667509ff7cSJens Wiklander } 677509ff7cSJens Wiklander 68ebef121cSJerome Forissier static TEE_Result resolve_sym_helper(uint32_t hash, const char *name, 69ebef121cSJerome Forissier vaddr_t *val, struct ta_elf *elf) 707509ff7cSJens Wiklander { 719f392760SJerome Forissier /* 729f392760SJerome Forissier * Using uint32_t here for convenience because both Elf64_Word 739f392760SJerome Forissier * and Elf32_Word are 32-bit types 749f392760SJerome Forissier */ 759f392760SJerome Forissier uint32_t *hashtab = elf->hashtab; 769f392760SJerome Forissier uint32_t nbuckets = hashtab[0]; 779f392760SJerome Forissier uint32_t nchains = hashtab[1]; 789f392760SJerome Forissier uint32_t *bucket = &hashtab[2]; 799f392760SJerome Forissier uint32_t *chain = &bucket[nbuckets]; 80ebef121cSJerome Forissier size_t n = 0; 819f392760SJerome Forissier 827509ff7cSJens Wiklander if (elf->is_32bit) { 837509ff7cSJens Wiklander Elf32_Sym *sym = elf->dynsymtab; 847509ff7cSJens Wiklander 859f392760SJerome Forissier for (n = bucket[hash % nbuckets]; n; n = chain[n]) { 868dbe2cbdSJens Wiklander if (n >= nchains || n >= elf->num_dynsyms) 875c0860dbSJens Wiklander err(TEE_ERROR_BAD_FORMAT, 885c0860dbSJens Wiklander "Index out of range"); 8955e64090SJens Wiklander /* 9055e64090SJens Wiklander * We're loading values from sym[] which later 9155e64090SJens Wiklander * will be used to load something. 9255e64090SJens Wiklander * => Spectre V1 pattern, need to cap the index 9355e64090SJens Wiklander * against speculation. 9455e64090SJens Wiklander */ 9555e64090SJens Wiklander n = confine_array_index(n, elf->num_dynsyms); 967509ff7cSJens Wiklander if (__resolve_sym(elf, 977509ff7cSJens Wiklander ELF32_ST_BIND(sym[n].st_info), 9897c5ac19SJens Wiklander ELF32_ST_TYPE(sym[n].st_info), 997509ff7cSJens Wiklander sym[n].st_shndx, 1007509ff7cSJens Wiklander sym[n].st_name, 1017509ff7cSJens Wiklander sym[n].st_value, name, val)) 102c86f218cSJens Wiklander return TEE_SUCCESS; 1037509ff7cSJens Wiklander } 1047509ff7cSJens Wiklander } else { 1057509ff7cSJens Wiklander Elf64_Sym *sym = elf->dynsymtab; 1067509ff7cSJens Wiklander 1079f392760SJerome Forissier for (n = bucket[hash % nbuckets]; n; n = chain[n]) { 1088dbe2cbdSJens Wiklander if (n >= nchains || n >= elf->num_dynsyms) 1095c0860dbSJens Wiklander err(TEE_ERROR_BAD_FORMAT, 1105c0860dbSJens Wiklander "Index out of range"); 11155e64090SJens Wiklander /* 11255e64090SJens Wiklander * We're loading values from sym[] which later 11355e64090SJens Wiklander * will be used to load something. 11455e64090SJens Wiklander * => Spectre V1 pattern, need to cap the index 11555e64090SJens Wiklander * against speculation. 11655e64090SJens Wiklander */ 11755e64090SJens Wiklander n = confine_array_index(n, elf->num_dynsyms); 1187509ff7cSJens Wiklander if (__resolve_sym(elf, 1197509ff7cSJens Wiklander ELF64_ST_BIND(sym[n].st_info), 12097c5ac19SJens Wiklander ELF64_ST_TYPE(sym[n].st_info), 1217509ff7cSJens Wiklander sym[n].st_shndx, 1227509ff7cSJens Wiklander sym[n].st_name, 1237509ff7cSJens Wiklander sym[n].st_value, name, val)) 124c86f218cSJens Wiklander return TEE_SUCCESS; 1257509ff7cSJens Wiklander } 1267509ff7cSJens Wiklander } 127ebef121cSJerome Forissier 128ebef121cSJerome Forissier return TEE_ERROR_ITEM_NOT_FOUND; 1297509ff7cSJens Wiklander } 130c86f218cSJens Wiklander 131ebef121cSJerome Forissier TEE_Result ta_elf_resolve_sym(const char *name, vaddr_t *val, 132ebef121cSJerome Forissier struct ta_elf *elf) 133ebef121cSJerome Forissier { 134ebef121cSJerome Forissier uint32_t hash = elf_hash(name); 135ebef121cSJerome Forissier 136ebef121cSJerome Forissier if (elf) 137ebef121cSJerome Forissier return resolve_sym_helper(hash, name, val, elf); 138ebef121cSJerome Forissier 139ebef121cSJerome Forissier TAILQ_FOREACH(elf, &main_elf_queue, link) 140ebef121cSJerome Forissier if (!resolve_sym_helper(hash, name, val, elf)) 141ebef121cSJerome Forissier return TEE_SUCCESS; 142ebef121cSJerome Forissier 143c86f218cSJens Wiklander return TEE_ERROR_ITEM_NOT_FOUND; 144c86f218cSJens Wiklander } 145c86f218cSJens Wiklander 146c86f218cSJens Wiklander static void resolve_sym(const char *name, vaddr_t *val) 147c86f218cSJens Wiklander { 148ebef121cSJerome Forissier TEE_Result res = ta_elf_resolve_sym(name, val, NULL); 149c86f218cSJens Wiklander 150c86f218cSJens Wiklander if (res) 151c86f218cSJens Wiklander err(res, "Symbol %s not found", name); 1527509ff7cSJens Wiklander } 1537509ff7cSJens Wiklander 1547509ff7cSJens Wiklander static void e32_process_dyn_rel(const Elf32_Sym *sym_tab, size_t num_syms, 1557509ff7cSJens Wiklander const char *str_tab, size_t str_tab_size, 1567509ff7cSJens Wiklander Elf32_Rel *rel, Elf32_Addr *where) 1577509ff7cSJens Wiklander { 1587509ff7cSJens Wiklander size_t sym_idx = 0; 1597509ff7cSJens Wiklander const char *name = NULL; 1607509ff7cSJens Wiklander vaddr_t val = 0; 1617509ff7cSJens Wiklander size_t name_idx = 0; 1627509ff7cSJens Wiklander 1637509ff7cSJens Wiklander sym_idx = ELF32_R_SYM(rel->r_info); 164447354c6SJens Wiklander if (sym_idx >= num_syms) 165e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Symbol index out of range"); 16655e64090SJens Wiklander sym_idx = confine_array_index(sym_idx, num_syms); 1677509ff7cSJens Wiklander 1687509ff7cSJens Wiklander name_idx = sym_tab[sym_idx].st_name; 169447354c6SJens Wiklander if (name_idx >= str_tab_size) 170e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Name index out of range"); 1717509ff7cSJens Wiklander name = str_tab + name_idx; 1727509ff7cSJens Wiklander 1737509ff7cSJens Wiklander resolve_sym(name, &val); 1747509ff7cSJens Wiklander *where = val; 1757509ff7cSJens Wiklander } 1767509ff7cSJens Wiklander 1777509ff7cSJens Wiklander static void e32_relocate(struct ta_elf *elf, unsigned int rel_sidx) 1787509ff7cSJens Wiklander { 1797509ff7cSJens Wiklander Elf32_Shdr *shdr = elf->shdr; 1807509ff7cSJens Wiklander Elf32_Rel *rel = NULL; 1817509ff7cSJens Wiklander Elf32_Rel *rel_end = NULL; 1827509ff7cSJens Wiklander size_t sym_tab_idx = 0; 1837509ff7cSJens Wiklander Elf32_Sym *sym_tab = NULL; 1847509ff7cSJens Wiklander size_t num_syms = 0; 1857509ff7cSJens Wiklander size_t sh_end = 0; 1867509ff7cSJens Wiklander const char *str_tab = NULL; 1877509ff7cSJens Wiklander size_t str_tab_size = 0; 1887509ff7cSJens Wiklander 1897509ff7cSJens Wiklander assert(shdr[rel_sidx].sh_type == SHT_REL); 1907509ff7cSJens Wiklander 1917509ff7cSJens Wiklander assert(shdr[rel_sidx].sh_entsize == sizeof(Elf32_Rel)); 1927509ff7cSJens Wiklander 1937509ff7cSJens Wiklander sym_tab_idx = shdr[rel_sidx].sh_link; 1947509ff7cSJens Wiklander if (sym_tab_idx) { 1957509ff7cSJens Wiklander size_t str_tab_idx = 0; 1967509ff7cSJens Wiklander 197447354c6SJens Wiklander if (sym_tab_idx >= elf->e_shnum) 198dcf64f87SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "SYMTAB index out of range"); 19955e64090SJens Wiklander sym_tab_idx = confine_array_index(sym_tab_idx, elf->e_shnum); 2007509ff7cSJens Wiklander 2017509ff7cSJens Wiklander assert(shdr[sym_tab_idx].sh_entsize == sizeof(Elf32_Sym)); 2027509ff7cSJens Wiklander 2037509ff7cSJens Wiklander /* Check the address is inside ELF memory */ 2047509ff7cSJens Wiklander if (ADD_OVERFLOW(shdr[sym_tab_idx].sh_addr, 2057509ff7cSJens Wiklander shdr[sym_tab_idx].sh_size, &sh_end)) 206e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Overflow"); 207447354c6SJens Wiklander if (sh_end >= (elf->max_addr - elf->load_addr)) 208dcf64f87SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "SYMTAB out of range"); 2097509ff7cSJens Wiklander 2107509ff7cSJens Wiklander sym_tab = (Elf32_Sym *)(elf->load_addr + 2117509ff7cSJens Wiklander shdr[sym_tab_idx].sh_addr); 2127509ff7cSJens Wiklander 2137509ff7cSJens Wiklander num_syms = shdr[sym_tab_idx].sh_size / sizeof(Elf32_Sym); 2147509ff7cSJens Wiklander 2157509ff7cSJens Wiklander str_tab_idx = shdr[sym_tab_idx].sh_link; 2167509ff7cSJens Wiklander if (str_tab_idx) { 21755e64090SJens Wiklander if (str_tab_idx >= elf->e_shnum) 218e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 219dcf64f87SJens Wiklander "STRTAB index out of range"); 22055e64090SJens Wiklander str_tab_idx = confine_array_index(str_tab_idx, 22155e64090SJens Wiklander elf->e_shnum); 22255e64090SJens Wiklander 2237509ff7cSJens Wiklander /* Check the address is inside ELF memory */ 2247509ff7cSJens Wiklander if (ADD_OVERFLOW(shdr[str_tab_idx].sh_addr, 2257509ff7cSJens Wiklander shdr[str_tab_idx].sh_size, &sh_end)) 226e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Overflow"); 227447354c6SJens Wiklander if (sh_end >= (elf->max_addr - elf->load_addr)) 228e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 229dcf64f87SJens Wiklander "STRTAB out of range"); 2307509ff7cSJens Wiklander 2317509ff7cSJens Wiklander str_tab = (const char *)(elf->load_addr + 2327509ff7cSJens Wiklander shdr[str_tab_idx].sh_addr); 2337509ff7cSJens Wiklander str_tab_size = shdr[str_tab_idx].sh_size; 2347509ff7cSJens Wiklander } 2357509ff7cSJens Wiklander } 2367509ff7cSJens Wiklander 2377509ff7cSJens Wiklander /* Check the address is inside TA memory */ 238447354c6SJens Wiklander if (ADD_OVERFLOW(shdr[rel_sidx].sh_addr, 239447354c6SJens Wiklander shdr[rel_sidx].sh_size, &sh_end)) 240e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Overflow"); 241447354c6SJens Wiklander if (sh_end >= (elf->max_addr - elf->load_addr)) 242dcf64f87SJens Wiklander err(TEE_ERROR_BAD_FORMAT, ".rel.*/REL out of range"); 2437509ff7cSJens Wiklander rel = (Elf32_Rel *)(elf->load_addr + shdr[rel_sidx].sh_addr); 2447509ff7cSJens Wiklander 2457509ff7cSJens Wiklander rel_end = rel + shdr[rel_sidx].sh_size / sizeof(Elf32_Rel); 2467509ff7cSJens Wiklander for (; rel < rel_end; rel++) { 2477509ff7cSJens Wiklander Elf32_Addr *where = NULL; 2487509ff7cSJens Wiklander size_t sym_idx = 0; 2497509ff7cSJens Wiklander 2507509ff7cSJens Wiklander /* Check the address is inside TA memory */ 251447354c6SJens Wiklander if (rel->r_offset >= (elf->max_addr - elf->load_addr)) 252e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 253447354c6SJens Wiklander "Relocation offset out of range"); 2547509ff7cSJens Wiklander where = (Elf32_Addr *)(elf->load_addr + rel->r_offset); 2557509ff7cSJens Wiklander 2567509ff7cSJens Wiklander switch (ELF32_R_TYPE(rel->r_info)) { 2577509ff7cSJens Wiklander case R_ARM_ABS32: 2587509ff7cSJens Wiklander sym_idx = ELF32_R_SYM(rel->r_info); 259447354c6SJens Wiklander if (sym_idx >= num_syms) 260e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 261447354c6SJens Wiklander "Symbol index out of range"); 2627509ff7cSJens Wiklander if (sym_tab[sym_idx].st_shndx == SHN_UNDEF) { 2637509ff7cSJens Wiklander /* Symbol is external */ 2647509ff7cSJens Wiklander e32_process_dyn_rel(sym_tab, num_syms, str_tab, 2657509ff7cSJens Wiklander str_tab_size, rel, where); 2667509ff7cSJens Wiklander } else { 2677509ff7cSJens Wiklander *where += elf->load_addr + 2687509ff7cSJens Wiklander sym_tab[sym_idx].st_value; 2697509ff7cSJens Wiklander } 2707509ff7cSJens Wiklander break; 2717509ff7cSJens Wiklander case R_ARM_REL32: 2727509ff7cSJens Wiklander sym_idx = ELF32_R_SYM(rel->r_info); 273447354c6SJens Wiklander if (sym_idx >= num_syms) 274e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 275447354c6SJens Wiklander "Symbol index out of range"); 2767509ff7cSJens Wiklander *where += sym_tab[sym_idx].st_value - rel->r_offset; 2777509ff7cSJens Wiklander break; 2787509ff7cSJens Wiklander case R_ARM_RELATIVE: 2797509ff7cSJens Wiklander *where += elf->load_addr; 2807509ff7cSJens Wiklander break; 2817509ff7cSJens Wiklander case R_ARM_GLOB_DAT: 2827509ff7cSJens Wiklander case R_ARM_JUMP_SLOT: 2837509ff7cSJens Wiklander e32_process_dyn_rel(sym_tab, num_syms, str_tab, 2847509ff7cSJens Wiklander str_tab_size, rel, where); 2857509ff7cSJens Wiklander break; 2867509ff7cSJens Wiklander default: 2877509ff7cSJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Unknown relocation type %d", 2887509ff7cSJens Wiklander ELF32_R_TYPE(rel->r_info)); 2897509ff7cSJens Wiklander } 2907509ff7cSJens Wiklander } 2917509ff7cSJens Wiklander } 2927509ff7cSJens Wiklander 2937509ff7cSJens Wiklander #ifdef ARM64 2947509ff7cSJens Wiklander static void e64_process_dyn_rela(const Elf64_Sym *sym_tab, size_t num_syms, 2957509ff7cSJens Wiklander const char *str_tab, size_t str_tab_size, 2967509ff7cSJens Wiklander Elf64_Rela *rela, Elf64_Addr *where) 2977509ff7cSJens Wiklander { 2987509ff7cSJens Wiklander size_t sym_idx = 0; 2997509ff7cSJens Wiklander const char *name = NULL; 3007509ff7cSJens Wiklander uintptr_t val = 0; 3017509ff7cSJens Wiklander size_t name_idx = 0; 3027509ff7cSJens Wiklander 3037509ff7cSJens Wiklander sym_idx = ELF64_R_SYM(rela->r_info); 304447354c6SJens Wiklander if (sym_idx >= num_syms) 305e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Symbol index out of range"); 30655e64090SJens Wiklander sym_idx = confine_array_index(sym_idx, num_syms); 3077509ff7cSJens Wiklander 3087509ff7cSJens Wiklander name_idx = sym_tab[sym_idx].st_name; 309447354c6SJens Wiklander if (name_idx >= str_tab_size) 310e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Name index out of range"); 3117509ff7cSJens Wiklander name = str_tab + name_idx; 3127509ff7cSJens Wiklander 3137509ff7cSJens Wiklander resolve_sym(name, &val); 3147509ff7cSJens Wiklander *where = val; 3157509ff7cSJens Wiklander } 3167509ff7cSJens Wiklander 3177509ff7cSJens Wiklander static void e64_relocate(struct ta_elf *elf, unsigned int rel_sidx) 3187509ff7cSJens Wiklander { 3197509ff7cSJens Wiklander Elf64_Shdr *shdr = elf->shdr; 3207509ff7cSJens Wiklander Elf64_Rela *rela = NULL; 3217509ff7cSJens Wiklander Elf64_Rela *rela_end = NULL; 3227509ff7cSJens Wiklander size_t sym_tab_idx = 0; 3237509ff7cSJens Wiklander Elf64_Sym *sym_tab = NULL; 3247509ff7cSJens Wiklander size_t num_syms = 0; 3257509ff7cSJens Wiklander size_t sh_end = 0; 3267509ff7cSJens Wiklander const char *str_tab = NULL; 3277509ff7cSJens Wiklander size_t str_tab_size = 0; 3287509ff7cSJens Wiklander 3297509ff7cSJens Wiklander assert(shdr[rel_sidx].sh_type == SHT_RELA); 3307509ff7cSJens Wiklander 3317509ff7cSJens Wiklander assert(shdr[rel_sidx].sh_entsize == sizeof(Elf64_Rela)); 3327509ff7cSJens Wiklander 3337509ff7cSJens Wiklander sym_tab_idx = shdr[rel_sidx].sh_link; 3347509ff7cSJens Wiklander if (sym_tab_idx) { 3357509ff7cSJens Wiklander size_t str_tab_idx = 0; 3367509ff7cSJens Wiklander 337447354c6SJens Wiklander if (sym_tab_idx >= elf->e_shnum) 338dcf64f87SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "SYMTAB index out of range"); 33955e64090SJens Wiklander sym_tab_idx = confine_array_index(sym_tab_idx, elf->e_shnum); 3407509ff7cSJens Wiklander 3417509ff7cSJens Wiklander assert(shdr[sym_tab_idx].sh_entsize == sizeof(Elf64_Sym)); 3427509ff7cSJens Wiklander 3437509ff7cSJens Wiklander /* Check the address is inside TA memory */ 3447509ff7cSJens Wiklander if (ADD_OVERFLOW(shdr[sym_tab_idx].sh_addr, 3457509ff7cSJens Wiklander shdr[sym_tab_idx].sh_size, &sh_end)) 346e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Overflow"); 347447354c6SJens Wiklander if (sh_end >= (elf->max_addr - elf->load_addr)) 348dcf64f87SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "SYMTAB out of range"); 3497509ff7cSJens Wiklander 3507509ff7cSJens Wiklander sym_tab = (Elf64_Sym *)(elf->load_addr + 3517509ff7cSJens Wiklander shdr[sym_tab_idx].sh_addr); 3527509ff7cSJens Wiklander 3537509ff7cSJens Wiklander num_syms = shdr[sym_tab_idx].sh_size / sizeof(Elf64_Sym); 3547509ff7cSJens Wiklander 3557509ff7cSJens Wiklander str_tab_idx = shdr[sym_tab_idx].sh_link; 3567509ff7cSJens Wiklander if (str_tab_idx) { 35755e64090SJens Wiklander if (str_tab_idx >= elf->e_shnum) 358e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 359dcf64f87SJens Wiklander "STRTAB index out of range"); 36055e64090SJens Wiklander str_tab_idx = confine_array_index(str_tab_idx, 36155e64090SJens Wiklander elf->e_shnum); 36255e64090SJens Wiklander 3637509ff7cSJens Wiklander /* Check the address is inside ELF memory */ 3647509ff7cSJens Wiklander if (ADD_OVERFLOW(shdr[str_tab_idx].sh_addr, 3657509ff7cSJens Wiklander shdr[str_tab_idx].sh_size, &sh_end)) 366e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Overflow"); 367447354c6SJens Wiklander if (sh_end >= (elf->max_addr - elf->load_addr)) 368e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 369dcf64f87SJens Wiklander "STRTAB out of range"); 3707509ff7cSJens Wiklander 3717509ff7cSJens Wiklander str_tab = (const char *)(elf->load_addr + 3727509ff7cSJens Wiklander shdr[str_tab_idx].sh_addr); 3737509ff7cSJens Wiklander str_tab_size = shdr[str_tab_idx].sh_size; 3747509ff7cSJens Wiklander } 3757509ff7cSJens Wiklander } 3767509ff7cSJens Wiklander 3777509ff7cSJens Wiklander /* Check the address is inside TA memory */ 378447354c6SJens Wiklander if (ADD_OVERFLOW(shdr[rel_sidx].sh_addr, 379447354c6SJens Wiklander shdr[rel_sidx].sh_size, &sh_end)) 380e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Overflow"); 381447354c6SJens Wiklander if (sh_end >= (elf->max_addr - elf->load_addr)) 382dcf64f87SJens Wiklander err(TEE_ERROR_BAD_FORMAT, ".rel.*/REL out of range"); 3837509ff7cSJens Wiklander rela = (Elf64_Rela *)(elf->load_addr + shdr[rel_sidx].sh_addr); 3847509ff7cSJens Wiklander 3857509ff7cSJens Wiklander rela_end = rela + shdr[rel_sidx].sh_size / sizeof(Elf64_Rela); 3867509ff7cSJens Wiklander for (; rela < rela_end; rela++) { 3877509ff7cSJens Wiklander Elf64_Addr *where = NULL; 3887509ff7cSJens Wiklander size_t sym_idx = 0; 3897509ff7cSJens Wiklander 3907509ff7cSJens Wiklander /* Check the address is inside TA memory */ 391447354c6SJens Wiklander if (rela->r_offset >= (elf->max_addr - elf->load_addr)) 392e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 393447354c6SJens Wiklander "Relocation offset out of range"); 3947509ff7cSJens Wiklander 3957509ff7cSJens Wiklander where = (Elf64_Addr *)(elf->load_addr + rela->r_offset); 3967509ff7cSJens Wiklander 3977509ff7cSJens Wiklander switch (ELF64_R_TYPE(rela->r_info)) { 3987509ff7cSJens Wiklander case R_AARCH64_ABS64: 3997509ff7cSJens Wiklander sym_idx = ELF64_R_SYM(rela->r_info); 400447354c6SJens Wiklander if (sym_idx >= num_syms) 401e97bbbb2SJens Wiklander err(TEE_ERROR_BAD_FORMAT, 402447354c6SJens Wiklander "Symbol index out of range"); 40355e64090SJens Wiklander sym_idx = confine_array_index(sym_idx, num_syms); 4047509ff7cSJens Wiklander if (sym_tab[sym_idx].st_shndx == SHN_UNDEF) { 4057509ff7cSJens Wiklander /* Symbol is external */ 4067509ff7cSJens Wiklander e64_process_dyn_rela(sym_tab, num_syms, str_tab, 4077509ff7cSJens Wiklander str_tab_size, rela, where); 4087509ff7cSJens Wiklander } else { 4097509ff7cSJens Wiklander *where = rela->r_addend + elf->load_addr + 4107509ff7cSJens Wiklander sym_tab[sym_idx].st_value; 4117509ff7cSJens Wiklander } 4127509ff7cSJens Wiklander break; 4137509ff7cSJens Wiklander case R_AARCH64_RELATIVE: 4147509ff7cSJens Wiklander *where = rela->r_addend + elf->load_addr; 4157509ff7cSJens Wiklander break; 4167509ff7cSJens Wiklander case R_AARCH64_GLOB_DAT: 4177509ff7cSJens Wiklander case R_AARCH64_JUMP_SLOT: 4187509ff7cSJens Wiklander e64_process_dyn_rela(sym_tab, num_syms, str_tab, 4197509ff7cSJens Wiklander str_tab_size, rela, where); 4207509ff7cSJens Wiklander break; 4217509ff7cSJens Wiklander default: 4227509ff7cSJens Wiklander err(TEE_ERROR_BAD_FORMAT, "Unknown relocation type %zd", 4237509ff7cSJens Wiklander ELF64_R_TYPE(rela->r_info)); 4247509ff7cSJens Wiklander } 4257509ff7cSJens Wiklander } 4267509ff7cSJens Wiklander } 4277509ff7cSJens Wiklander #else /*ARM64*/ 4285548a710SJerome Forissier static void __noreturn e64_relocate(struct ta_elf *elf __unused, 4297509ff7cSJens Wiklander unsigned int rel_sidx __unused) 4307509ff7cSJens Wiklander { 4317509ff7cSJens Wiklander err(TEE_ERROR_NOT_SUPPORTED, "arm64 not supported"); 4327509ff7cSJens Wiklander } 4337509ff7cSJens Wiklander #endif /*ARM64*/ 4347509ff7cSJens Wiklander 4357509ff7cSJens Wiklander void ta_elf_relocate(struct ta_elf *elf) 4367509ff7cSJens Wiklander { 4377509ff7cSJens Wiklander size_t n = 0; 4387509ff7cSJens Wiklander 4397509ff7cSJens Wiklander if (elf->is_32bit) { 4407509ff7cSJens Wiklander Elf32_Shdr *shdr = elf->shdr; 4417509ff7cSJens Wiklander 4427509ff7cSJens Wiklander for (n = 0; n < elf->e_shnum; n++) 4437509ff7cSJens Wiklander if (shdr[n].sh_type == SHT_REL) 4447509ff7cSJens Wiklander e32_relocate(elf, n); 4457509ff7cSJens Wiklander } else { 4467509ff7cSJens Wiklander Elf64_Shdr *shdr = elf->shdr; 4477509ff7cSJens Wiklander 4487509ff7cSJens Wiklander for (n = 0; n < elf->e_shnum; n++) 4497509ff7cSJens Wiklander if (shdr[n].sh_type == SHT_RELA) 4507509ff7cSJens Wiklander e64_relocate(elf, n); 4517509ff7cSJens Wiklander 4527509ff7cSJens Wiklander } 4537509ff7cSJens Wiklander } 454