1 ; Bold - Import by hash for linux/amd64 (elf64-x86-64)
2 ; © 2009 Amand "alrj" Tihon
3 ; kate: syntax Intel x86 (NASM);
5 ; alrj's x86_64 version of the import by hash method by parapete, las, leblane.
6 ; See the wonderful thread at http://www.pouet.net/topic.php?which=5392 to
7 ; learn everything about import by hash on Linux.
10 ; yasm -f elf64 -o bold_ibh-x86_64.o bold_ibh-x86_64.asm
11 ; (or replace yasm by nasm)
20 extern _dt_debug ; defined by bold linker
21 extern _bold__functions_hash ; in .data, generated by bold
22 extern _bold__functions_pointers ; in .bss, generated by bold
23 extern _bold__functions_count ; immediate 32 bits
24 extern main ; must be declared when using this
34 mov rbx, [_dt_debug] ; rbx points to r_debug
35 mov rbx, [rbx + 8] ; rbx points to link_map
36 mov rbx, [rbx + 24] ; skip the first two link_map entries
39 mov esi, _bold__functions_hash ; Implicitly zero-extended
40 mov edi, _bold__functions_pointers ; ditto
41 mov ecx, _bold__functions_count
43 ; Load all the symbols
45 lodsd ; Load symbol hash in eax
50 mov r15d, eax ; Save function hash
51 mov r13, rbx ; copy link_map's pseudo-head
53 ; Iterate over libraries found in link_map
55 mov rdx, [r13 + 16] ; link_map->l_ld
57 ; Find the interesting entries in the DYNAMIC table.
59 xor eax, eax ; enough because hash was 32 bits
61 mov al, DT_HASH ; DT_HASH == 4
65 inc al ; DT_STRTAB == 5
69 inc al ; DT_SYMTAB == 6
79 ; All DYNAMIC entries have been read.
80 mov ecx, [r9 + 4] ; nchain, number of exported symbols
82 ; Iterate over the symbols in the library (symtab entries).
84 ; Find the symbol name in strtab
85 mov esi, [r11] ; st_name, offset in strtab
86 add rsi, r10 ; pointer to symbol name
91 .hash_loop: ; over each char
92 imul edx, edx, byte 0x21
99 cmp edx, r15d ; Compare with stored hash
101 add r11, 24 ; Next symtab entry
104 ; Symbol was not found in this library
105 mov r13, [r13 + 24] ; Next link_map entry
108 mov rax, [r11 + 8] ; st_value, offset of the symbol
109 add rax, [r13] ; add link_map->l_addr
114 stosq ; Store function pointer
118 ; When all is resolved, call main()