xref: /xnu-10002.41.9/tests/pac_exception_entitlement.c (revision 699cd48037512bf4380799317ca44ca453c82f57)
1*699cd480SApple OSS Distributions /*
2*699cd480SApple OSS Distributions  * Copyright (c) 2023 Apple Computer, Inc. All rights reserved.
3*699cd480SApple OSS Distributions  *
4*699cd480SApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*699cd480SApple OSS Distributions  *
6*699cd480SApple OSS Distributions  * This file contains Original Code and/or Modifications of Original Code
7*699cd480SApple OSS Distributions  * as defined in and that are subject to the Apple Public Source License
8*699cd480SApple OSS Distributions  * Version 2.0 (the 'License'). You may not use this file except in
9*699cd480SApple OSS Distributions  * compliance with the License. The rights granted to you under the License
10*699cd480SApple OSS Distributions  * may not be used to create, or enable the creation or redistribution of,
11*699cd480SApple OSS Distributions  * unlawful or unlicensed copies of an Apple operating system, or to
12*699cd480SApple OSS Distributions  * circumvent, violate, or enable the circumvention or violation of, any
13*699cd480SApple OSS Distributions  * terms of an Apple operating system software license agreement.
14*699cd480SApple OSS Distributions  *
15*699cd480SApple OSS Distributions  * Please obtain a copy of the License at
16*699cd480SApple OSS Distributions  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*699cd480SApple OSS Distributions  *
18*699cd480SApple OSS Distributions  * The Original Code and all software distributed under the License are
19*699cd480SApple OSS Distributions  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*699cd480SApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*699cd480SApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*699cd480SApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*699cd480SApple OSS Distributions  * Please see the License for the specific language governing rights and
24*699cd480SApple OSS Distributions  * limitations under the License.
25*699cd480SApple OSS Distributions  *
26*699cd480SApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*699cd480SApple OSS Distributions  */
28*699cd480SApple OSS Distributions 
29*699cd480SApple OSS Distributions #include <darwintest.h>
30*699cd480SApple OSS Distributions #include <stdlib.h>
31*699cd480SApple OSS Distributions #include <unistd.h>
32*699cd480SApple OSS Distributions #include <mach/exception_types.h>
33*699cd480SApple OSS Distributions #include <sys/wait.h>
34*699cd480SApple OSS Distributions 
35*699cd480SApple OSS Distributions #include "exc_helpers.h"
36*699cd480SApple OSS Distributions #include "test_utils.h"
37*699cd480SApple OSS Distributions 
38*699cd480SApple OSS Distributions T_GLOBAL_META(
39*699cd480SApple OSS Distributions 	T_META_NAMESPACE("xnu.arm"),
40*699cd480SApple OSS Distributions 	T_META_RADAR_COMPONENT_NAME("xnu"),
41*699cd480SApple OSS Distributions 	T_META_RADAR_COMPONENT_VERSION("arm"),
42*699cd480SApple OSS Distributions 	T_META_OWNER("ghackmann"),
43*699cd480SApple OSS Distributions 	T_META_REQUIRES_SYSCTL_EQ("hw.optional.ptrauth", 1),
44*699cd480SApple OSS Distributions 	T_META_IGNORECRASHES(".*pac_exception_entitlement.*"),
45*699cd480SApple OSS Distributions 	XNU_T_META_SOC_SPECIFIC
46*699cd480SApple OSS Distributions 	);
47*699cd480SApple OSS Distributions 
48*699cd480SApple OSS Distributions #if __arm64e__
49*699cd480SApple OSS Distributions static size_t
exception_handler(mach_port_t task __unused,mach_port_t thread __unused,exception_type_t type __unused,mach_exception_data_t codes __unused)50*699cd480SApple OSS Distributions exception_handler(mach_port_t task __unused, mach_port_t thread __unused,
51*699cd480SApple OSS Distributions     exception_type_t type __unused, mach_exception_data_t codes __unused)
52*699cd480SApple OSS Distributions {
53*699cd480SApple OSS Distributions 	T_ASSERT_FAIL("kernel ran exception handler instead of terminating process");
54*699cd480SApple OSS Distributions }
55*699cd480SApple OSS Distributions 
56*699cd480SApple OSS Distributions /*
57*699cd480SApple OSS Distributions  * Real-world software should use ptrauth.h when it needs to manually sign or
58*699cd480SApple OSS Distributions  * auth pointers.  But for testing purposes we need clang to emit specific
59*699cd480SApple OSS Distributions  * ptrauth instructions, so we use inline asm here instead.
60*699cd480SApple OSS Distributions  *
61*699cd480SApple OSS Distributions  * Likewise clang would normally combine the "naked" auth and brk testcases as
62*699cd480SApple OSS Distributions  * part of a sequence like:
63*699cd480SApple OSS Distributions  *
64*699cd480SApple OSS Distributions  *     output = auth(...);
65*699cd480SApple OSS Distributions  *     if (output is poisoned) {
66*699cd480SApple OSS Distributions  *         brk(PTRAUTH_FAILURE_COMMENT);
67*699cd480SApple OSS Distributions  *     }
68*699cd480SApple OSS Distributions  *
69*699cd480SApple OSS Distributions  * On auth failure, CPUs that implement FEAT_FPAC will trap immediately at the
70*699cd480SApple OSS Distributions  * auth instruction, and CPUs without FEAT_FPAC will trap at the later brk
71*699cd480SApple OSS Distributions  * instruction.  But again, for testing purposes we want these to be two
72*699cd480SApple OSS Distributions  * discrete cases.  (On FPAC-enabled CPUs, the kernel should treat *both* traps
73*699cd480SApple OSS Distributions  * as ptrauth failure, even if we don't expect the latter to be reachable in
74*699cd480SApple OSS Distributions  * real-world software.)
75*699cd480SApple OSS Distributions  */
76*699cd480SApple OSS Distributions 
77*699cd480SApple OSS Distributions static void
naked_auth(void)78*699cd480SApple OSS Distributions naked_auth(void)
79*699cd480SApple OSS Distributions {
80*699cd480SApple OSS Distributions 	asm volatile (
81*699cd480SApple OSS Distributions                 "mov	x0, #0"                 "\n"
82*699cd480SApple OSS Distributions                 "paciza	x0"                     "\n"
83*699cd480SApple OSS Distributions                 "eor	x0, x0, (1 << 63)"      "\n"
84*699cd480SApple OSS Distributions                 "autiza	x0"
85*699cd480SApple OSS Distributions                 :
86*699cd480SApple OSS Distributions                 :
87*699cd480SApple OSS Distributions                 : "x0"
88*699cd480SApple OSS Distributions         );
89*699cd480SApple OSS Distributions }
90*699cd480SApple OSS Distributions 
91*699cd480SApple OSS Distributions static void
ptrauth_brk(void)92*699cd480SApple OSS Distributions ptrauth_brk(void)
93*699cd480SApple OSS Distributions {
94*699cd480SApple OSS Distributions 	asm volatile ("brk 0xc470");
95*699cd480SApple OSS Distributions }
96*699cd480SApple OSS Distributions 
97*699cd480SApple OSS Distributions static void
combined_branch_auth(void)98*699cd480SApple OSS Distributions combined_branch_auth(void)
99*699cd480SApple OSS Distributions {
100*699cd480SApple OSS Distributions 	asm volatile (
101*699cd480SApple OSS Distributions                 "adr	x0, 1f"                 "\n"
102*699cd480SApple OSS Distributions                 "paciza	x0"                     "\n"
103*699cd480SApple OSS Distributions                 "eor	x0, x0, (1 << 63)"      "\n"
104*699cd480SApple OSS Distributions                 "braaz	x0"                     "\n"
105*699cd480SApple OSS Distributions         "1:"
106*699cd480SApple OSS Distributions                 :
107*699cd480SApple OSS Distributions                 :
108*699cd480SApple OSS Distributions                 : "x0"
109*699cd480SApple OSS Distributions         );
110*699cd480SApple OSS Distributions }
111*699cd480SApple OSS Distributions 
112*699cd480SApple OSS Distributions static void
combined_load_auth(void)113*699cd480SApple OSS Distributions combined_load_auth(void)
114*699cd480SApple OSS Distributions {
115*699cd480SApple OSS Distributions 	asm volatile (
116*699cd480SApple OSS Distributions                 "mov	x0, sp"                 "\n"
117*699cd480SApple OSS Distributions                 "pacdza	x0"                     "\n"
118*699cd480SApple OSS Distributions                 "eor	x0, x0, (1 << 63)"      "\n"
119*699cd480SApple OSS Distributions                 "ldraa	x0, [x0]"               "\n"
120*699cd480SApple OSS Distributions                 :
121*699cd480SApple OSS Distributions                 :
122*699cd480SApple OSS Distributions                 : "x0"
123*699cd480SApple OSS Distributions         );
124*699cd480SApple OSS Distributions }
125*699cd480SApple OSS Distributions 
126*699cd480SApple OSS Distributions static void
run_pac_exception_test(void (* ptrauth_failure_fn)(void))127*699cd480SApple OSS Distributions run_pac_exception_test(void (*ptrauth_failure_fn)(void))
128*699cd480SApple OSS Distributions {
129*699cd480SApple OSS Distributions 	pid_t pid = fork();
130*699cd480SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(pid, "fork");
131*699cd480SApple OSS Distributions 
132*699cd480SApple OSS Distributions 	if (pid == 0) {
133*699cd480SApple OSS Distributions 		mach_port_t exc_port = create_exception_port(EXC_MASK_BAD_ACCESS | EXC_MASK_BREAKPOINT);
134*699cd480SApple OSS Distributions 		run_exception_handler(exc_port, exception_handler);
135*699cd480SApple OSS Distributions 
136*699cd480SApple OSS Distributions 		ptrauth_failure_fn();
137*699cd480SApple OSS Distributions 		/* ptrauth_failure_fn() should have raised an uncatchable exception */
138*699cd480SApple OSS Distributions 		T_FAIL("child ran to completion");
139*699cd480SApple OSS Distributions 	} else {
140*699cd480SApple OSS Distributions 		int status;
141*699cd480SApple OSS Distributions 		int err = waitpid(pid, &status, 0);
142*699cd480SApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(err, "waitpid");
143*699cd480SApple OSS Distributions 
144*699cd480SApple OSS Distributions 		T_EXPECT_TRUE(WIFSIGNALED(status), "child terminated due to signal");
145*699cd480SApple OSS Distributions 		T_EXPECT_EQ(SIGKILL, WTERMSIG(status), "child terminated due to SIGKILL");
146*699cd480SApple OSS Distributions 	}
147*699cd480SApple OSS Distributions }
148*699cd480SApple OSS Distributions #endif
149*699cd480SApple OSS Distributions 
150*699cd480SApple OSS Distributions T_DECL(pac_exception_naked_auth,
151*699cd480SApple OSS Distributions     "Test the com.apple.private.pac.exception entitlement (naked auth failure)",
152*699cd480SApple OSS Distributions     T_META_REQUIRES_SYSCTL_EQ("hw.optional.arm.FEAT_FPAC", 1))
153*699cd480SApple OSS Distributions {
154*699cd480SApple OSS Distributions #if __arm64e__
155*699cd480SApple OSS Distributions 	run_pac_exception_test(naked_auth);
156*699cd480SApple OSS Distributions #else
157*699cd480SApple OSS Distributions 	T_SKIP("Running on non-arm64e target, skipping...");
158*699cd480SApple OSS Distributions #endif
159*699cd480SApple OSS Distributions }
160*699cd480SApple OSS Distributions 
161*699cd480SApple OSS Distributions 
162*699cd480SApple OSS Distributions T_DECL(pac_exception_ptrauth_brk,
163*699cd480SApple OSS Distributions     "Test the com.apple.private.pac.exception entitlement (brk with comment indicating ptrauth failure)")
164*699cd480SApple OSS Distributions {
165*699cd480SApple OSS Distributions #if __arm64e__
166*699cd480SApple OSS Distributions 	run_pac_exception_test(ptrauth_brk);
167*699cd480SApple OSS Distributions #else
168*699cd480SApple OSS Distributions 	T_SKIP("Running on non-arm64e target, skipping...");
169*699cd480SApple OSS Distributions #endif
170*699cd480SApple OSS Distributions }
171*699cd480SApple OSS Distributions 
172*699cd480SApple OSS Distributions T_DECL(pac_exception_combined_branch_auth,
173*699cd480SApple OSS Distributions     "Test the com.apple.private.pac.exception entitlement (combined branch + auth failure)")
174*699cd480SApple OSS Distributions {
175*699cd480SApple OSS Distributions #if __arm64e__
176*699cd480SApple OSS Distributions 	run_pac_exception_test(combined_branch_auth);
177*699cd480SApple OSS Distributions #else
178*699cd480SApple OSS Distributions 	T_SKIP("Running on non-arm64e target, skipping...");
179*699cd480SApple OSS Distributions #endif
180*699cd480SApple OSS Distributions }
181*699cd480SApple OSS Distributions 
182*699cd480SApple OSS Distributions T_DECL(pac_exception_combined_load_auth,
183*699cd480SApple OSS Distributions     "Test the com.apple.private.pac.exception entitlement (combined branch + auth failure)")
184*699cd480SApple OSS Distributions {
185*699cd480SApple OSS Distributions #if __arm64e__
186*699cd480SApple OSS Distributions 	run_pac_exception_test(combined_load_auth);
187*699cd480SApple OSS Distributions #else
188*699cd480SApple OSS Distributions 	T_SKIP("Running on non-arm64e target, skipping...");
189*699cd480SApple OSS Distributions #endif
190*699cd480SApple OSS Distributions }
191