xref: /xnu-8792.81.2/osfmk/kern/startup.c (revision 19c3b8c28c31cb8130e034cfb5df6bf9ba342d90)
1 /*
2  * Copyright (c) 2000-2020 Apple Inc. All rights reserved.
3  *
4  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5  *
6  * This file contains Original Code and/or Modifications of Original Code
7  * as defined in and that are subject to the Apple Public Source License
8  * Version 2.0 (the 'License'). You may not use this file except in
9  * compliance with the License. The rights granted to you under the License
10  * may not be used to create, or enable the creation or redistribution of,
11  * unlawful or unlicensed copies of an Apple operating system, or to
12  * circumvent, violate, or enable the circumvention or violation of, any
13  * terms of an Apple operating system software license agreement.
14  *
15  * Please obtain a copy of the License at
16  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17  *
18  * The Original Code and all software distributed under the License are
19  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23  * Please see the License for the specific language governing rights and
24  * limitations under the License.
25  *
26  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27  */
28 /*
29  * @OSF_COPYRIGHT@
30  */
31 /*
32  * Mach Operating System
33  * Copyright (c) 1991,1990,1989,1988 Carnegie Mellon University
34  * All Rights Reserved.
35  *
36  * Permission to use, copy, modify and distribute this software and its
37  * documentation is hereby granted, provided that both the copyright
38  * notice and this permission notice appear in all copies of the
39  * software, derivative works or modified versions, and any portions
40  * thereof, and that both notices appear in supporting documentation.
41  *
42  * CARNEGIE MELLON ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS"
43  * CONDITION.  CARNEGIE MELLON DISCLAIMS ANY LIABILITY OF ANY KIND FOR
44  * ANY DAMAGES WHATSOEVER RESULTING FROM THE USE OF THIS SOFTWARE.
45  *
46  * Carnegie Mellon requests users of this software to return to
47  *
48  *  Software Distribution Coordinator  or  [email protected]
49  *  School of Computer Science
50  *  Carnegie Mellon University
51  *  Pittsburgh PA 15213-3890
52  *
53  * any improvements or extensions that they make and grant Carnegie Mellon
54  * the rights to redistribute these changes.
55  */
56 /*
57  * NOTICE: This file was modified by McAfee Research in 2004 to introduce
58  * support for mandatory and extensible security protections.  This notice
59  * is included in support of clause 2.2 (b) of the Apple Public License,
60  * Version 2.0.
61  */
62 /*
63  */
64 
65 /*
66  *	Mach kernel startup.
67  */
68 
69 #include <debug.h>
70 #include <mach_kdp.h>
71 
72 #include <mach/boolean.h>
73 #include <mach/machine.h>
74 #include <mach/thread_act.h>
75 #include <mach/task_special_ports.h>
76 #include <mach/vm_param.h>
77 #include <kern/assert.h>
78 #include <kern/mach_param.h>
79 #include <kern/misc_protos.h>
80 #include <kern/clock.h>
81 #include <kern/coalition.h>
82 #include <kern/cpu_number.h>
83 #include <kern/cpu_quiesce.h>
84 #include <kern/ledger.h>
85 #include <kern/machine.h>
86 #include <kern/processor.h>
87 #include <kern/restartable.h>
88 #include <kern/sched_prim.h>
89 #include <kern/turnstile.h>
90 #if CONFIG_SCHED_SFI
91 #include <kern/sfi.h>
92 #endif
93 #include <kern/startup.h>
94 #include <kern/task.h>
95 #include <kern/thread.h>
96 #include <kern/timer.h>
97 #if CONFIG_TELEMETRY
98 #include <kern/telemetry.h>
99 #endif
100 #include <kern/zalloc.h>
101 #include <kern/locks.h>
102 #include <kern/debug.h>
103 #if KPERF
104 #include <kperf/kperf.h>
105 #endif /* KPERF */
106 #include <corpses/task_corpse.h>
107 #include <prng/random.h>
108 #include <console/serial_protos.h>
109 #include <vm/vm_kern.h>
110 #include <vm/vm_init.h>
111 #include <vm/vm_map.h>
112 #include <vm/vm_object.h>
113 #include <vm/vm_page.h>
114 #include <vm/vm_pageout.h>
115 #include <vm/vm_shared_region.h>
116 #include <machine/pmap.h>
117 #include <machine/commpage.h>
118 #include <machine/machine_routines.h>
119 #include <libkern/version.h>
120 #include <pexpert/device_tree.h>
121 #include <sys/codesign.h>
122 #include <sys/kdebug.h>
123 #include <sys/random.h>
124 #include <sys/ktrace.h>
125 #include <sys/trust_caches.h>
126 #include <sys/code_signing.h>
127 #include <libkern/section_keywords.h>
128 
129 #include <kern/waitq.h>
130 #include <ipc/ipc_voucher.h>
131 #include <voucher/ipc_pthread_priority_internal.h>
132 #include <mach/host_info.h>
133 #include <pthread/workqueue_internal.h>
134 
135 #if CONFIG_XNUPOST
136 #include <tests/ktest.h>
137 #include <tests/xnupost.h>
138 #endif
139 
140 #if CONFIG_ATM
141 #include <atm/atm_internal.h>
142 #endif
143 
144 #if CONFIG_CSR
145 #include <sys/csr.h>
146 #endif
147 
148 #include <bank/bank_internal.h>
149 
150 #if ALTERNATE_DEBUGGER
151 #include <arm64/alternate_debugger.h>
152 #endif
153 
154 #if MACH_KDP
155 #include <kdp/kdp.h>
156 #endif
157 
158 #if CONFIG_MACF
159 #include <security/mac_mach_internal.h>
160 #if CONFIG_VNGUARD
161 extern void vnguard_policy_init(void);
162 #endif
163 #endif
164 
165 #if KPC
166 #include <kern/kpc.h>
167 #endif
168 
169 #if HYPERVISOR
170 #include <kern/hv_support.h>
171 #endif
172 
173 #if CONFIG_UBSAN_MINIMAL
174 #include <san/ubsan_minimal.h>
175 #endif
176 
177 #include <san/kasan.h>
178 
179 #include <i386/pmCPU.h>
180 static void             kernel_bootstrap_thread(void);
181 
182 static void             load_context(
183 	thread_t        thread);
184 
185 #if CONFIG_ECC_LOGGING
186 #include <kern/ecc.h>
187 #endif
188 
189 #if (defined(__i386__) || defined(__x86_64__)) && CONFIG_VMX
190 #include <i386/vmx/vmx_cpu.h>
191 #endif
192 
193 #if CONFIG_DTRACE
194 extern void dtrace_early_init(void);
195 extern void sdt_early_init(void);
196 #endif
197 
198 // libkern/OSKextLib.cpp
199 extern void OSKextRemoveKextBootstrap(void);
200 
201 void scale_setup(void);
202 extern void bsd_scale_setup(int);
203 extern unsigned int semaphore_max;
204 extern void stackshot_init(void);
205 
206 /*
207  *	Running in virtual memory, on the interrupt stack.
208  */
209 
210 extern struct startup_entry startup_entries[]
211 __SECTION_START_SYM(STARTUP_HOOK_SEGMENT, STARTUP_HOOK_SECTION);
212 
213 extern struct startup_entry startup_entries_end[]
214 __SECTION_END_SYM(STARTUP_HOOK_SEGMENT, STARTUP_HOOK_SECTION);
215 
216 static struct startup_entry *__startup_data startup_entry_cur = startup_entries;
217 
218 SECURITY_READ_ONLY_LATE(startup_subsystem_id_t) startup_phase = STARTUP_SUB_NONE;
219 
220 extern int serverperfmode;
221 
222 TUNABLE(startup_debug_t, startup_debug, "startup_debug", 0);
223 
224 static inline void
kernel_bootstrap_log(const char * message)225 kernel_bootstrap_log(const char *message)
226 {
227 	if ((startup_debug & STARTUP_DEBUG_VERBOSE) &&
228 	    startup_phase >= STARTUP_SUB_KPRINTF) {
229 		kprintf("kernel_bootstrap: %s\n", message);
230 	}
231 	kernel_debug_string_early(message);
232 }
233 
234 static inline void
kernel_bootstrap_thread_log(const char * message)235 kernel_bootstrap_thread_log(const char *message)
236 {
237 	if ((startup_debug & STARTUP_DEBUG_VERBOSE) &&
238 	    startup_phase >= STARTUP_SUB_KPRINTF) {
239 		kprintf("kernel_bootstrap_thread: %s\n", message);
240 	}
241 	kernel_debug_string_early(message);
242 }
243 
244 extern void
245 qsort(void *a, size_t n, size_t es, int (*cmp)(const void *, const void *));
246 
247 __startup_func
248 static int
startup_entry_cmp(const void * e1,const void * e2)249 startup_entry_cmp(const void *e1, const void *e2)
250 {
251 	const struct startup_entry *a = e1;
252 	const struct startup_entry *b = e2;
253 	if (a->subsystem == b->subsystem) {
254 		if (a->rank == b->rank) {
255 			return 0;
256 		}
257 		return a->rank > b->rank ? 1 : -1;
258 	}
259 	return a->subsystem > b->subsystem ? 1 : -1;
260 }
261 
262 __startup_func
263 void
kernel_startup_bootstrap(void)264 kernel_startup_bootstrap(void)
265 {
266 	/*
267 	 * Sort the various STARTUP() entries by subsystem/rank.
268 	 */
269 	size_t n = startup_entries_end - startup_entries;
270 
271 	if (n == 0) {
272 		panic("Section %s,%s missing",
273 		    STARTUP_HOOK_SEGMENT, STARTUP_HOOK_SECTION);
274 	}
275 	if (((uintptr_t)startup_entries_end - (uintptr_t)startup_entries) %
276 	    sizeof(struct startup_entry)) {
277 		panic("Section %s,%s has invalid size",
278 		    STARTUP_HOOK_SEGMENT, STARTUP_HOOK_SECTION);
279 	}
280 
281 	qsort(startup_entries, n, sizeof(struct startup_entry), startup_entry_cmp);
282 
283 	/*
284 	 * Then initialize all tunables, timeouts, and locks
285 	 */
286 	kernel_startup_initialize_upto(STARTUP_SUB_LOCKS);
287 }
288 
289 __startup_func
290 void
kernel_startup_tunable_init(const struct startup_tunable_spec * spec)291 kernel_startup_tunable_init(const struct startup_tunable_spec *spec)
292 {
293 	if (spec->var_is_str) {
294 		PE_parse_boot_arg_str(spec->name, spec->var_addr, spec->var_len);
295 	} else if (PE_parse_boot_argn(spec->name, spec->var_addr, spec->var_len)) {
296 		if (spec->var_is_bool) {
297 			/* make sure bool's are valued in {0, 1} */
298 			*(bool *)spec->var_addr = *(uint8_t *)spec->var_addr;
299 		}
300 	}
301 }
302 
303 __startup_func
304 void
kernel_startup_tunable_dt_init(const struct startup_tunable_dt_spec * spec)305 kernel_startup_tunable_dt_init(const struct startup_tunable_dt_spec *spec)
306 {
307 	DTEntry base;
308 
309 	if (SecureDTLookupEntry(NULL, spec->dt_base, &base) != kSuccess) {
310 		base = NULL;
311 	}
312 
313 	bool found_in_chosen = false;
314 
315 	if (spec->dt_chosen_override) {
316 		DTEntry chosen, chosen_base;
317 
318 		if (SecureDTLookupEntry(NULL, "chosen", &chosen) != kSuccess) {
319 			chosen = NULL;
320 		}
321 
322 		if (chosen != NULL && SecureDTLookupEntry(chosen, spec->dt_base, &chosen_base) == kSuccess) {
323 			base = chosen_base;
324 			found_in_chosen = true;
325 		}
326 	}
327 
328 	uint64_t const *data;
329 	unsigned int data_size = spec->var_len;
330 
331 	if (base != NULL && SecureDTGetProperty(base, spec->dt_name, (const void **)&data, &data_size) == kSuccess) {
332 		if (data_size != spec->var_len) {
333 			panic("unexpected tunable size %u in DT entry %s/%s/%s",
334 			    data_size, found_in_chosen ? "/chosen" : "", spec->dt_base, spec->dt_name);
335 		}
336 
337 		/* No need to handle bools specially, they are 1 byte integers in the DT. */
338 		memcpy(spec->var_addr, data, spec->var_len);
339 	}
340 
341 	/* boot-arg overrides. */
342 
343 	if (PE_parse_boot_argn(spec->boot_arg_name, spec->var_addr, spec->var_len)) {
344 		if (spec->var_is_bool) {
345 			*(bool *)spec->var_addr = *(uint8_t *)spec->var_addr;
346 		}
347 	}
348 }
349 
350 static void
kernel_startup_log(startup_subsystem_id_t subsystem)351 kernel_startup_log(startup_subsystem_id_t subsystem)
352 {
353 	static const char *names[] = {
354 		[STARTUP_SUB_TUNABLES] = "tunables",
355 		[STARTUP_SUB_TIMEOUTS] = "timeouts",
356 		[STARTUP_SUB_LOCKS] = "locks",
357 		[STARTUP_SUB_KPRINTF] = "kprintf",
358 
359 		[STARTUP_SUB_PMAP_STEAL] = "pmap_steal",
360 		[STARTUP_SUB_KMEM] = "kmem",
361 		[STARTUP_SUB_ZALLOC] = "zalloc",
362 		[STARTUP_SUB_PERCPU] = "percpu",
363 
364 		[STARTUP_SUB_CODESIGNING] = "codesigning",
365 		[STARTUP_SUB_KTRACE] = "ktrace",
366 		[STARTUP_SUB_OSLOG] = "oslog",
367 		[STARTUP_SUB_MACH_IPC] = "mach_ipc",
368 		[STARTUP_SUB_THREAD_CALL] = "thread_call",
369 		[STARTUP_SUB_SYSCTL] = "sysctl",
370 		[STARTUP_SUB_EARLY_BOOT] = "early_boot",
371 
372 		/* LOCKDOWN is special and its value won't fit here. */
373 	};
374 	static startup_subsystem_id_t logged = STARTUP_SUB_NONE;
375 
376 	if (subsystem <= logged) {
377 		return;
378 	}
379 
380 	if (subsystem < sizeof(names) / sizeof(names[0]) && names[subsystem]) {
381 		kernel_bootstrap_log(names[subsystem]);
382 	}
383 	logged = subsystem;
384 }
385 
386 __startup_func
387 void
kernel_startup_initialize_upto(startup_subsystem_id_t upto)388 kernel_startup_initialize_upto(startup_subsystem_id_t upto)
389 {
390 	struct startup_entry *cur = startup_entry_cur;
391 
392 	assert(startup_phase < upto);
393 
394 	while (cur < startup_entries_end && cur->subsystem <= upto) {
395 		if ((startup_debug & STARTUP_DEBUG_VERBOSE) &&
396 		    startup_phase >= STARTUP_SUB_KPRINTF) {
397 			kprintf("%s[%d, rank %d]: %p(%p)\n", __func__,
398 			    cur->subsystem, cur->rank, cur->func, cur->arg);
399 		}
400 		startup_phase = cur->subsystem - 1;
401 		kernel_startup_log(cur->subsystem);
402 		cur->func(cur->arg);
403 		startup_entry_cur = ++cur;
404 	}
405 	kernel_startup_log(upto);
406 
407 	if ((startup_debug & STARTUP_DEBUG_VERBOSE) &&
408 	    upto >= STARTUP_SUB_KPRINTF) {
409 		kprintf("%s: reached phase %d\n", __func__, upto);
410 	}
411 	startup_phase = upto;
412 }
413 
414 void
kernel_bootstrap(void)415 kernel_bootstrap(void)
416 {
417 	kern_return_t   result;
418 	thread_t        thread;
419 	char            namep[16];
420 
421 	printf("%s\n", version); /* log kernel version */
422 
423 	scale_setup();
424 
425 	kernel_bootstrap_log("vm_mem_bootstrap");
426 	vm_mem_bootstrap();
427 
428 	machine_info.memory_size = (uint32_t)mem_size;
429 #if XNU_TARGET_OS_OSX
430 	machine_info.max_mem = max_mem_actual;
431 #else
432 	machine_info.max_mem = max_mem;
433 #endif /* XNU_TARGET_OS_OSX */
434 	machine_info.major_version = version_major;
435 	machine_info.minor_version = version_minor;
436 
437 #if CONFIG_ATM
438 	/* Initialize the Activity Trace Resource Manager. */
439 	kernel_bootstrap_log("atm_init");
440 	atm_init();
441 #endif
442 	kernel_startup_initialize_upto(STARTUP_SUB_OSLOG);
443 
444 #if CONFIG_UBSAN_MINIMAL
445 	kernel_bootstrap_log("UBSan minimal runtime init");
446 	ubsan_minimal_init();
447 #endif
448 
449 #if KASAN
450 	kernel_bootstrap_log("kasan_late_init");
451 	kasan_late_init();
452 #endif
453 
454 #if CONFIG_TELEMETRY
455 	kernel_bootstrap_log("telemetry_init");
456 	telemetry_init();
457 #endif
458 
459 	if (PE_i_can_has_debugger(NULL)) {
460 		if (PE_parse_boot_argn("-show_pointers", &namep, sizeof(namep))) {
461 			doprnt_hide_pointers = FALSE;
462 		}
463 		if (PE_parse_boot_argn("-no_slto_panic", &namep, sizeof(namep))) {
464 			extern boolean_t spinlock_timeout_panic;
465 			spinlock_timeout_panic = FALSE;
466 		}
467 	}
468 
469 	kernel_bootstrap_log("console_init");
470 	console_init();
471 
472 	kernel_bootstrap_log("stackshot_init");
473 	stackshot_init();
474 
475 	kernel_bootstrap_log("sched_init");
476 	sched_init();
477 
478 #if CONFIG_MACF
479 	kernel_bootstrap_log("mac_policy_init");
480 	mac_policy_init();
481 #endif
482 
483 	kernel_startup_initialize_upto(STARTUP_SUB_MACH_IPC);
484 
485 	/*
486 	 * As soon as the virtual memory system is up, we record
487 	 * that this CPU is using the kernel pmap.
488 	 */
489 	kernel_bootstrap_log("PMAP_ACTIVATE_KERNEL");
490 	PMAP_ACTIVATE_KERNEL(master_cpu);
491 
492 	kernel_bootstrap_log("mapping_free_prime");
493 	mapping_free_prime();                                           /* Load up with temporary mapping blocks */
494 
495 	kernel_bootstrap_log("machine_init");
496 	machine_init();
497 
498 	kernel_bootstrap_log("thread_machine_init_template");
499 	thread_machine_init_template();
500 
501 	kernel_bootstrap_log("clock_init");
502 	clock_init();
503 
504 	/*
505 	 *	Initialize the IPC, task, and thread subsystems.
506 	 */
507 #if CONFIG_THREAD_GROUPS
508 	kernel_bootstrap_log("thread_group_init");
509 	thread_group_init();
510 #endif
511 
512 #if CONFIG_COALITIONS
513 	kernel_bootstrap_log("coalitions_init");
514 	coalitions_init();
515 #endif
516 
517 	kernel_bootstrap_log("task_init");
518 	task_init();
519 
520 	kernel_bootstrap_log("thread_init");
521 	thread_init();
522 
523 	kernel_bootstrap_log("restartable_init");
524 	restartable_init();
525 
526 	kernel_bootstrap_log("workq_init");
527 	workq_init();
528 
529 	kernel_bootstrap_log("turnstiles_init");
530 	turnstiles_init();
531 
532 	kernel_bootstrap_log("mach_init_activity_id");
533 	mach_init_activity_id();
534 
535 	/* Initialize the BANK Manager. */
536 	kernel_bootstrap_log("bank_init");
537 	bank_init();
538 
539 #if CONFIG_VOUCHER_DEPRECATED
540 	kernel_bootstrap_log("ipc_pthread_priority_init");
541 	ipc_pthread_priority_init();
542 #endif /* CONFIG_VOUCHER_DEPRECATED */
543 
544 	/* initialize host_statistics */
545 	host_statistics_init();
546 
547 	/* initialize exceptions */
548 	kernel_bootstrap_log("exception_init");
549 	exception_init();
550 
551 #if CONFIG_SCHED_SFI
552 	kernel_bootstrap_log("sfi_init");
553 	sfi_init();
554 #endif
555 
556 	/*
557 	 *	Create a kernel thread to execute the kernel bootstrap.
558 	 */
559 
560 	kernel_bootstrap_log("kernel_thread_create");
561 	result = kernel_thread_create((thread_continue_t)kernel_bootstrap_thread, NULL, MAXPRI_KERNEL, &thread);
562 
563 	if (result != KERN_SUCCESS) {
564 		panic("kernel_bootstrap: result = %08X", result);
565 	}
566 
567 	/* TODO: do a proper thread_start() (without the thread_setrun()) */
568 	thread->state = TH_RUN;
569 	thread->last_made_runnable_time = mach_absolute_time();
570 	thread_set_thread_name(thread, "kernel_bootstrap_thread");
571 
572 	thread_deallocate(thread);
573 
574 	kernel_bootstrap_log("load_context - done");
575 	load_context(thread);
576 	/*NOTREACHED*/
577 }
578 
579 SECURITY_READ_ONLY_LATE(vm_offset_t) vm_kernel_addrperm;
580 SECURITY_READ_ONLY_LATE(vm_offset_t) buf_kernel_addrperm;
581 SECURITY_READ_ONLY_LATE(vm_offset_t) vm_kernel_addrperm_ext;
582 SECURITY_READ_ONLY_LATE(uint64_t) vm_kernel_addrhash_salt;
583 SECURITY_READ_ONLY_LATE(uint64_t) vm_kernel_addrhash_salt_ext;
584 
585 /*
586  * Now running in a thread.  Kick off other services,
587  * invoke user bootstrap, enter pageout loop.
588  */
589 static void
kernel_bootstrap_thread(void)590 kernel_bootstrap_thread(void)
591 {
592 	processor_t processor = current_processor();
593 
594 #if (DEVELOPMENT || DEBUG)
595 	platform_stall_panic_or_spin(PLATFORM_STALL_XNU_LOCATION_KERNEL_BOOTSTRAP);
596 #endif
597 
598 	kernel_bootstrap_thread_log("idle_thread_create");
599 	/*
600 	 * Create the idle processor thread.
601 	 */
602 	idle_thread_create(processor);
603 
604 	/*
605 	 * N.B. Do not stick anything else
606 	 * before this point.
607 	 *
608 	 * Start up the scheduler services.
609 	 */
610 	kernel_bootstrap_thread_log("sched_startup");
611 	sched_startup();
612 
613 	/*
614 	 * Thread lifecycle maintenance (teardown, stack allocation)
615 	 */
616 	kernel_bootstrap_thread_log("thread_daemon_init");
617 	thread_daemon_init();
618 
619 	/*
620 	 * Thread callout service.
621 	 */
622 	kernel_startup_initialize_upto(STARTUP_SUB_THREAD_CALL);
623 
624 	/*
625 	 * Remain on current processor as
626 	 * additional processors come online.
627 	 */
628 	kernel_bootstrap_thread_log("thread_bind");
629 	thread_bind(processor);
630 
631 	/*
632 	 * Kick off memory mapping adjustments.
633 	 */
634 	kernel_bootstrap_thread_log("mapping_adjust");
635 	mapping_adjust();
636 
637 	/*
638 	 *	Create the clock service.
639 	 */
640 	kernel_bootstrap_thread_log("clock_service_create");
641 	clock_service_create();
642 
643 	/*
644 	 *	Create the device service.
645 	 */
646 	device_service_create();
647 
648 	phys_carveout_init();
649 
650 #if MACH_KDP
651 	kernel_bootstrap_log("kdp_init");
652 	kdp_init();
653 #endif
654 
655 #if ALTERNATE_DEBUGGER
656 	alternate_debugger_init();
657 #endif
658 
659 #if HYPERVISOR
660 	kernel_bootstrap_thread_log("hv_support_init");
661 	hv_support_init();
662 #endif
663 
664 #if CONFIG_TELEMETRY
665 	kernel_bootstrap_log("bootprofile_init");
666 	bootprofile_init();
667 #endif
668 
669 	kernel_startup_initialize_upto(STARTUP_SUB_SYSCTL);
670 
671 	/*
672 	 * Initialize the globals used for permuting kernel
673 	 * addresses that may be exported to userland as tokens
674 	 * using VM_KERNEL_ADDRPERM()/VM_KERNEL_ADDRPERM_EXTERNAL().
675 	 * Force the random number to be odd to avoid mapping a non-zero
676 	 * word-aligned address to zero via addition.
677 	 */
678 	vm_kernel_addrperm = (vm_offset_t)(early_random() | 1);
679 	buf_kernel_addrperm = (vm_offset_t)(early_random() | 1);
680 	vm_kernel_addrperm_ext = (vm_offset_t)(early_random() | 1);
681 	vm_kernel_addrhash_salt = early_random();
682 	vm_kernel_addrhash_salt_ext = early_random();
683 
684 #ifdef  IOKIT
685 	kernel_bootstrap_log("PE_init_iokit");
686 	PE_init_iokit();
687 #endif
688 
689 	assert(ml_get_interrupts_enabled() == FALSE);
690 
691 	/*
692 	 * Past this point, kernel subsystems that expect to operate with
693 	 * interrupts or preemption enabled may begin enforcement.
694 	 */
695 	kernel_startup_initialize_upto(STARTUP_SUB_EARLY_BOOT);
696 
697 #if SCHED_HYGIENE_DEBUG
698 	// Reset interrupts masked timeout before we enable interrupts
699 	ml_spin_debug_clear_self();
700 #endif
701 	(void) spllo();         /* Allow interruptions */
702 
703 	/*
704 	 * This will start displaying progress to the user, start as early as possible
705 	 */
706 	initialize_screen(NULL, kPEAcquireScreen);
707 
708 	/*
709 	 *	Initialize the shared region module.
710 	 */
711 	vm_commpage_init();
712 	vm_commpage_text_init();
713 
714 #if CONFIG_MACF
715 	kernel_bootstrap_log("mac_policy_initmach");
716 	mac_policy_initmach();
717 #if CONFIG_VNGUARD
718 	kernel_bootstrap_log("vnguard_policy_init");
719 	vnguard_policy_init();
720 #endif
721 #endif
722 
723 #if CONFIG_DTRACE
724 	kernel_bootstrap_log("dtrace_early_init");
725 	dtrace_early_init();
726 	sdt_early_init();
727 #endif
728 
729 #ifndef BCM2837
730 	kernel_bootstrap_log("code_signing_init");
731 
732 #if CODE_SIGNING_MONITOR
733 	/* Intialize the data for managing provisioning profiles */
734 	initialize_provisioning_profiles();
735 #endif
736 
737 	/* Initialize the runtime for the trust cache interface */
738 	trust_cache_runtime_init();
739 
740 	/* Load the static and engineering trust caches */
741 	load_static_trust_cache();
742 #endif
743 
744 	kernel_startup_initialize_upto(STARTUP_SUB_LOCKDOWN);
745 
746 	/*
747 	 * Get rid of segments used to bootstrap kext loading. This removes
748 	 * the KLD, PRELINK symtab, LINKEDIT, and symtab segments/load commands.
749 	 * Must be done prior to lockdown so that we can free (and possibly relocate)
750 	 * the static KVA mappings used for the jettisoned bootstrap segments.
751 	 */
752 	kernel_bootstrap_log("OSKextRemoveKextBootstrap");
753 	OSKextRemoveKextBootstrap();
754 
755 	/* No changes to kernel text and rodata beyond this point. */
756 	kernel_bootstrap_log("machine_lockdown");
757 	machine_lockdown();
758 
759 #ifdef CONFIG_XNUPOST
760 	kern_return_t result = kernel_list_tests();
761 	result = kernel_do_post();
762 	if (result != KERN_SUCCESS) {
763 		panic("kernel_do_post: Tests failed with result = 0x%08x", result);
764 	}
765 	kernel_bootstrap_log("kernel_do_post - done");
766 #endif /* CONFIG_XNUPOST */
767 
768 #ifdef  IOKIT
769 	kernel_bootstrap_log("PE_lockdown_iokit");
770 	PE_lockdown_iokit();
771 #endif
772 	/*
773 	 * max_cpus must be nailed down by the time PE_lockdown_iokit() finishes,
774 	 * at the latest
775 	 */
776 	vm_set_restrictions(machine_info.max_cpus);
777 
778 
779 #if KPERF
780 	kperf_init_early();
781 #endif
782 
783 	/*
784 	 *	Start the user bootstrap.
785 	 */
786 #ifdef  MACH_BSD
787 	bsd_init();
788 #endif
789 
790 
791 	/*
792 	 * Get rid of pages used for early boot tracing.
793 	 */
794 	kdebug_free_early_buf();
795 
796 	serial_keyboard_init();         /* Start serial keyboard if wanted */
797 
798 	vm_page_init_local_q(machine_info.max_cpus);
799 
800 	thread_bind(PROCESSOR_NULL);
801 
802 	/*
803 	 * Now that all CPUs are available to run threads, this is essentially
804 	 * a background thread. Take this opportunity to initialize and free
805 	 * any remaining vm_pages that were delayed earlier by pmap_startup().
806 	 */
807 	vm_free_delayed_pages();
808 
809 	/*
810 	 *	Become the pageout daemon.
811 	 */
812 	vm_pageout();
813 	/*NOTREACHED*/
814 }
815 
816 /*
817  *	slave_main:
818  *
819  *	Load the first thread to start a processor.
820  *	This path will also be used by the master processor
821  *	after being offlined.
822  */
823 void
slave_main(void * machine_param)824 slave_main(void *machine_param)
825 {
826 	processor_t             processor = current_processor();
827 	thread_t                thread;
828 
829 	/*
830 	 *	Use the idle processor thread if there
831 	 *	is no dedicated start up thread.
832 	 */
833 	if (processor->processor_offlined == true) {
834 		/* Return to the saved processor_offline context */
835 		assert(processor->startup_thread == THREAD_NULL);
836 
837 		thread = processor->idle_thread;
838 		thread->parameter = machine_param;
839 	} else if (processor->startup_thread) {
840 		thread = processor->startup_thread;
841 		processor->startup_thread = THREAD_NULL;
842 	} else {
843 		thread = processor->idle_thread;
844 		thread->continuation = processor_start_thread;
845 		thread->parameter = machine_param;
846 	}
847 
848 	load_context(thread);
849 	/*NOTREACHED*/
850 }
851 
852 /*
853  *	processor_start_thread:
854  *
855  *	First thread to execute on a started processor.
856  *
857  *	Called at splsched.
858  */
859 void
processor_start_thread(void * machine_param,__unused wait_result_t result)860 processor_start_thread(void *machine_param,
861     __unused wait_result_t result)
862 {
863 	processor_t             processor = current_processor();
864 	thread_t                self = current_thread();
865 
866 	slave_machine_init(machine_param);
867 
868 	/*
869 	 *	If running the idle processor thread,
870 	 *	reenter the idle loop, else terminate.
871 	 */
872 	if (self == processor->idle_thread) {
873 		thread_block(idle_thread);
874 	}
875 
876 	thread_terminate(self);
877 	/*NOTREACHED*/
878 }
879 
880 /*
881  *	load_context:
882  *
883  *	Start the first thread on a processor.
884  *	This may be the first thread ever run on a processor, or
885  *	it could be a processor that was previously offlined.
886  */
887 static void __attribute__((noreturn))
load_context(thread_t thread)888 load_context(
889 	thread_t                thread)
890 {
891 	processor_t             processor = current_processor();
892 
893 
894 #define load_context_kprintf(x...) /* kprintf("load_context: " x) */
895 
896 	load_context_kprintf("machine_set_current_thread\n");
897 	machine_set_current_thread(thread);
898 
899 	load_context_kprintf("processor_up\n");
900 
901 	PMAP_ACTIVATE_KERNEL(processor->cpu_id);
902 
903 	/*
904 	 * Acquire a stack if none attached.  The panic
905 	 * should never occur since the thread is expected
906 	 * to have reserved stack.
907 	 */
908 	load_context_kprintf("thread %p, stack %lx, stackptr %lx\n", thread,
909 	    thread->kernel_stack, thread->machine.kstackptr);
910 	if (!thread->kernel_stack) {
911 		load_context_kprintf("stack_alloc_try\n");
912 		if (!stack_alloc_try(thread)) {
913 			panic("load_context");
914 		}
915 	}
916 
917 	/*
918 	 * The idle processor threads are not counted as
919 	 * running for load calculations.
920 	 */
921 	if (!(thread->state & TH_IDLE)) {
922 		SCHED(run_count_incr)(thread);
923 	}
924 
925 	processor->active_thread = thread;
926 	processor_state_update_explicit(processor, thread->sched_pri,
927 	    SFI_CLASS_KERNEL, PSET_SMP, thread_get_perfcontrol_class(thread), THREAD_URGENCY_NONE,
928 	    ((thread->state & TH_IDLE) || (thread->bound_processor != PROCESSOR_NULL)) ? TH_BUCKET_SCHED_MAX : thread->th_sched_bucket);
929 	processor->current_is_bound = thread->bound_processor != PROCESSOR_NULL;
930 	processor->current_is_NO_SMT = false;
931 	processor->current_is_eagerpreempt = false;
932 #if CONFIG_THREAD_GROUPS
933 	processor->current_thread_group = thread_group_get(thread);
934 #endif
935 	processor->starting_pri = thread->sched_pri;
936 	processor->deadline = UINT64_MAX;
937 	thread->last_processor = processor;
938 	processor_up(processor);
939 	struct recount_snap snap = { 0 };
940 	recount_snapshot(&snap);
941 	processor->last_dispatch = snap.rsn_time_mach;
942 	recount_processor_run(&processor->pr_recount, &snap);
943 	recount_update_snap(&snap);
944 
945 	cpu_quiescent_counter_join(processor->last_dispatch);
946 
947 	PMAP_ACTIVATE_USER(thread, processor->cpu_id);
948 
949 	load_context_kprintf("machine_load_context\n");
950 
951 #if KASAN && CONFIG_KERNEL_TBI
952 	__asan_handle_no_return();
953 #endif /* KASAN && CONFIG_KERNEL_TBI */
954 
955 	machine_load_context(thread);
956 	/*NOTREACHED*/
957 }
958 
959 void
scale_setup(void)960 scale_setup(void)
961 {
962 	int scale = 0;
963 #if defined(__LP64__)
964 	typeof(task_max) task_max_base = task_max;
965 
966 	/* Raise limits for servers with >= 16G */
967 	if ((serverperfmode != 0) && ((uint64_t)max_mem_actual >= (uint64_t)(16 * 1024 * 1024 * 1024ULL))) {
968 		scale = (int)((uint64_t)sane_size / (uint64_t)(8 * 1024 * 1024 * 1024ULL));
969 		/* limit to 128 G */
970 		if (scale > 16) {
971 			scale = 16;
972 		}
973 		task_max_base = 2500;
974 		/* Raise limits for machines with >= 3GB */
975 	} else if ((uint64_t)max_mem_actual >= (uint64_t)(3 * 1024 * 1024 * 1024ULL)) {
976 		if ((uint64_t)max_mem_actual < (uint64_t)(8 * 1024 * 1024 * 1024ULL)) {
977 			scale = 2;
978 		} else {
979 			/* limit to 64GB */
980 			scale = MIN(16, (int)((uint64_t)max_mem_actual / (uint64_t)(4 * 1024 * 1024 * 1024ULL)));
981 		}
982 	}
983 
984 	task_max = MAX(task_max, task_max_base * scale);
985 
986 	if (scale != 0) {
987 		task_threadmax = task_max;
988 		thread_max = task_max * 5;
989 	}
990 
991 #endif
992 
993 	bsd_scale_setup(scale);
994 }
995