nuttx/libs/libc/elf/elf_remove.c
Marco Casaroli dcd93b0f67
Some checks are pending
Build Documentation / build-html (push) Waiting to run
MemBrowse Memory Report / changes-filter (push) Waiting to run
MemBrowse Memory Report / load-targets (push) Waiting to run
MemBrowse Memory Report / identical (push) Blocked by required conditions
MemBrowse Memory Report / analyze (push) Blocked by required conditions
libs/libc/elf: Load the libraries a module names in DT_NEEDED.
A module that names a shared library in DT_NEEDED now gets it loaded and
its imports bound against it, rather than being refused.

libelf_insert() does the loading, which is what dlopen() calls anyway: the
library lands in the module registry like anything else, its exports come
back through libelf_getsymbol() -- the same call dlsym() uses -- and a
library named by two modules is loaded once.  A bare name is looked for
along LD_LIBRARY_PATH, where dlopen() looks for it.  Undefined symbols
resolve against the globally registered symbols first, then the modules
this one depends on, then the table exec() supplied.  Nothing here calls
into dlfcn, because this loader is also the kernel's module loader, which
has none.

Each library becomes one of the module's dependencies[], and the dependency
holds it in place of the reference libelf_insert() took.  So a library
loaded only for DT_NEEDED is kept by the modules that depend on it, and
libelf_undepend() unloads it with the last of them; one that dlopen() or
insmod also opened stays until that reference goes too.
CONFIG_LIBC_ELF_MAXDEPEND bounds how many libraries a module may name,
which is what it already meant.

Six things had to be fixed to make it work, none of which a build shows.

reldata was a file-scope global.  Loading a library from inside
libelf_relocatedyn() makes that function reentrant, so the nested load
overwrote the outer one's relocation offsets and the module resumed binding
with the library's DT_REL.  It is now per call.

A cross-object call needs the callee's data base, not the caller's.  A
symbol resolved from an FDPIC library comes back as a descriptor, and
R_ARM_FUNCDESC_VALUE was treating it as a code address and pairing it with
the importing module's GOT.  It now copies both words, so the library runs
with its own.

An object with no imports has no PLT and so no DT_PLTGOT, but it still has
a GOT and still has to be entered with it.  Without the fallback its
descriptors carried a data base of zero and the library read its globals
through a null pointer.

R_ARM_FUNCDESC, a pointer to a descriptor, wrapped a library's descriptor
in a second one.  It now stores the library's descriptor as it is.

The flag that says a resolved value is a descriptor was set only for an
import and never cleared, so the next relocation against a symbol of the
module itself took that symbol for a descriptor too.  It is cleared there.

libelf_symname() was static, and reading a DT_NEEDED name needs it.

A module with DT_NEEDED is refused where CONFIG_LIBC_ELF_MAXDEPEND is zero,
since that is where the dependency logic is compiled out.

A DT_NEEDED library is one shared instance, its data included, because the
loader returns the object already in the registry.  A module started with
exec() is different: that path loads the module afresh each time, so two
running instances have separate data while sharing one copy of the text.

Built for mps3-an547:picostest with CONFIG_FDPIC both ways.  Run on
mps2-an500:xipfs under QEMU: fdpicxip solib loads libcounter.so by name out
of DT_NEEDED, two instances share one pinned copy of its text, and the
library is unloaded, and its pin given back, when the second one exits.  A
library also opened with dlopen() stays loaded after its DT_NEEDED user
exits, and dlclose() unloads it.

With CONFIG_ARCH_ADDRENV the program runs in its own address space, which
a library libelf_insert() loads cannot reach, so DT_NEEDED is refused
there as before.

Assisted-by: Claude Code:claude-opus-5-5
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
2026-10-06 17:48:49 -03:00

291 lines
7.8 KiB
C

/****************************************************************************
* libs/libc/elf/elf_remove.c
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <assert.h>
#include <nuttx/debug.h>
#include <errno.h>
#include <nuttx/arch.h>
#include <nuttx/fdpic.h>
#include <nuttx/lib/lib.h>
#include <nuttx/lib/elf.h>
#include "elf/elf.h"
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: libelf_uninit
*
* Description:
* Uninitialize module resources. Gives up everything the module holds,
* the DT_NEEDED libraries included, so the caller must hold the last
* reference.
*
****************************************************************************/
int libelf_uninit(FAR struct module_s *modp)
{
FAR void (**array)(void);
int ret = OK;
int i;
#if CONFIG_LIBC_ELF_MAXDEPEND > 0
/* Refuse to remove any module that other modules may depend upon. */
if (modp->dependents > 0)
{
berr("ERROR: Module has dependents: %d\n", modp->dependents);
return -EBUSY;
}
#endif
/* Is there an uninitializer? Like the constructors, an FDPIC object's
* destructors reach its globals through its own data base, which the
* unloading thread does not carry.
*/
array = (FAR void (**)(void))modp->finiarr;
for (i = 0; i < modp->nfini; i++)
{
fdpic_call(0, array[i], modp->gotbase);
}
if (modp->modinfo.uninitializer != NULL)
{
/* Try to uninitialize the module */
ret = modp->modinfo.uninitializer(modp->modinfo.arg);
/* Did the module successfully uninitialize? */
if (ret < 0)
{
berr("ERROR: Failed to uninitialize the module: %d\n", ret);
return ret;
}
/* Nullify so that the uninitializer cannot be called again */
modp->modinfo.uninitializer = NULL;
modp->modinfo.arg = NULL;
}
/* Free the symbol table that the module exports. It is built for
* every loaded module, whether or not it has an uninitializer.
*/
libelf_freesymtab(modp);
modp->modinfo.exports = NULL;
modp->modinfo.nexports = 0;
#ifdef HAVE_LIBC_ELF_PIN
/* Give the pin back before the text goes out of use. This does nothing if
* the loader took no pin.
*/
libelf_pinrelease(&modp->pinfile);
#endif
/* Release resources held by the module */
if (modp->textalloc != NULL || modp->dataalloc != NULL)
{
/* Free the module memory and nullify so that the memory cannot
* be freed again
*
* NOTE: For dynamic shared objects there is only a single
* allocation: the text/data were allocated in one operation
*/
if (!modp->dynamic)
{
#ifdef CONFIG_ARCH_USE_SEPARATED_SECTION
for (i = 0; i < modp->nsect && modp->sectalloc[i] != NULL; i++)
{
# ifdef CONFIG_ARCH_USE_TEXT_HEAP
if (up_textheap_heapmember(modp->sectalloc[i]))
{
up_textheap_free(modp->sectalloc[i]);
continue;
}
# endif
# ifdef CONFIG_ARCH_USE_DATA_HEAP
if (up_dataheap_heapmember(modp->sectalloc[i]))
{
up_dataheap_free(modp->sectalloc[i]);
continue;
}
# endif
lib_free(modp->sectalloc[i]);
}
lib_free(modp->sectalloc);
modp->sectalloc = NULL;
modp->nsect = 0;
#else
if (modp->xipbase == 0)
{
# if defined(CONFIG_ARCH_USE_TEXT_HEAP)
up_textheap_free((FAR void *)modp->textalloc);
# else
lib_free((FAR void *)modp->textalloc);
# endif
}
# if defined(CONFIG_ARCH_USE_DATA_HEAP)
up_dataheap_free((FAR void *)modp->dataalloc);
# else
lib_free((FAR void *)modp->dataalloc);
# endif
#endif
}
else if (modp->gotbase != 0)
{
/* An FDPIC object, which placed its two segments separately. Free
* each one. If the text stayed on the media, it was never
* allocated, thus leave it.
*/
if (modp->xipbase == 0)
{
#ifdef CONFIG_ARCH_USE_TEXT_HEAP
up_textheap_free((FAR void *)modp->textalloc);
#else
lib_free((FAR void *)modp->textalloc);
#endif
}
#ifdef CONFIG_ARCH_USE_DATA_HEAP
up_dataheap_free((FAR void *)modp->dataalloc);
#else
lib_free((FAR void *)modp->dataalloc);
#endif
}
else
{
lib_free((FAR void *)modp->textalloc);
}
modp->textalloc = NULL;
modp->dataalloc = NULL;
#if defined(CONFIG_FS_PROCFS) && !defined(CONFIG_FS_PROCFS_EXCLUDE_MODULE)
modp->textsize = 0;
modp->datasize = 0;
#endif
}
#if CONFIG_LIBC_ELF_MAXDEPEND > 0
/* Eliminate any dependencies that this module has on other modules */
libelf_undepend(modp);
#endif
return ret;
}
/****************************************************************************
* Name: libelf_remove
*
* Description:
* Remove a previously installed module from memory.
*
* Input Parameters:
* handle - The module handler previously returned by libelf_insert().
*
* Returned Value:
* Zero (OK) on success. On any failure, -1 (ERROR) is returned the
* errno value is set appropriately.
*
****************************************************************************/
int libelf_remove(FAR void *handle)
{
FAR struct module_s *modp = (FAR struct module_s *)handle;
int ret;
DEBUGASSERT(modp != NULL);
/* Get exclusive access to the module registry */
libelf_registry_lock();
/* Verify that the module is in the registry */
ret = libelf_registry_verify(modp);
if (ret < 0)
{
berr("ERROR: Failed to verify module: %d\n", ret);
goto errout_with_lock;
}
/* Give back a reference. The module goes only when the last one does,
* so an rmmod() cannot pull a module out from under a dlopen(), or from
* under a module that names it in DT_NEEDED.
*/
if (modp->nopen > 1)
{
modp->nopen--;
libelf_registry_unlock();
return OK;
}
modp->nopen = 0;
ret = libelf_uninit(modp);
if (ret < 0)
{
berr("ERROR: Failed to uninitialize module %d\n", ret);
goto errout_with_lock;
}
/* Remove the module from the registry */
ret = libelf_registry_del(modp);
if (ret < 0)
{
berr("ERROR: Failed to remove the module from the registry: %d\n",
ret);
goto errout_with_lock;
}
libelf_registry_unlock();
/* And free the registry entry */
lib_free(modp);
return ret;
errout_with_lock:
libelf_registry_unlock();
set_errno(-ret);
return ERROR;
}