Skip to content

Show the real target of REL and RELR relative relocs ##bin - #26937

Merged
trufae merged 1 commit into
radareorg:masterfrom
phix33:reloc-implicit-addend-listing
Oct 9, 2026
Merged

trufae merged 1 commit into
radareorg:masterfrom
phix33:reloc-implicit-addend-listing

Conversation

@phix33

@phix33 phix33 commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator
  • Mark this if you consider it ready to merge
  • I've added tests (optional)
  • I wrote some lines in the book (optional)

Description

A DT_REL or DT_RELR relative reloc keeps its addend in the slot, but ir never reads it, so every such row lists the link base (usually 0) instead of the address the slot points to:

$ r2 -qc 'ir~SET_32' bins/elf/arm-relative-linkbase.so
0x00070220 0x00000220 SET_32 23     0x00040000
0x00070224 0x00000224 SET_32 23     0x00040000
$ r2 -qc 'pxw 8 @ 0x70220' bins/elf/arm-relative-linkbase.so
0x00070220  0x000501bc 0x00070224                        ....$...
  • Read the slot word once, when the reloc table is built, for relative relocs with no explicit addend (REL, RELR, Android packed REL, CREL), and list it as-is like a RELA addend. The RELR patch path now uses the same value instead of re-reading the slot.
  • Android packed REL entries now say their addend is implicit, so i386 bin.relocs.apply=true stops zeroing their slots.
  • ppc32, riscv and nds32 relative rows stop adding the base or subtracting the slot address from the listed addend.

Tests: new aarch64 RELR (non-zero base) and i386 Android-packed fixtures in radare2-testbins#150; the RELR, arm, i386, Android and ppc32 listing cases fail without the fix. Moved goldens list the slot's pointer, and on libexploit.so/ls-toybox those pointers now name reloc.fixup.* flags after the strings they point to.

@trufae
trufae merged commit 4d89496 into radareorg:master Oct 9, 2026
50 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants