xref: /xnu-10002.41.9/tests/reply_port_defense.c (revision 699cd48037512bf4380799317ca44ca453c82f57)
1*699cd480SApple OSS Distributions #include <stdio.h>
2*699cd480SApple OSS Distributions #include <stdlib.h>
3*699cd480SApple OSS Distributions #include <unistd.h>
4*699cd480SApple OSS Distributions #include <darwintest.h>
5*699cd480SApple OSS Distributions #include <spawn.h>
6*699cd480SApple OSS Distributions #include <mach/mach.h>
7*699cd480SApple OSS Distributions #include <sys/sysctl.h>
8*699cd480SApple OSS Distributions #include <excserver.h>
9*699cd480SApple OSS Distributions #include <signal.h>
10*699cd480SApple OSS Distributions #include "../osfmk/ipc/ipc_init.h"
11*699cd480SApple OSS Distributions #include "../osfmk/mach/port.h"
12*699cd480SApple OSS Distributions #include "../osfmk/kern/exc_guard.h"
13*699cd480SApple OSS Distributions 
14*699cd480SApple OSS Distributions #define MAX_TEST_NUM 5
15*699cd480SApple OSS Distributions #define MAX_ARGV 3
16*699cd480SApple OSS Distributions 
17*699cd480SApple OSS Distributions extern char **environ;
18*699cd480SApple OSS Distributions static mach_exception_data_type_t received_exception_code = 0;
19*699cd480SApple OSS Distributions static mach_exception_data_type_t expected_exception_code = 0;
20*699cd480SApple OSS Distributions static exception_type_t exception_taken = 0;
21*699cd480SApple OSS Distributions 
22*699cd480SApple OSS Distributions /*
23*699cd480SApple OSS Distributions  * This test infrastructure is inspired from imm_pinned_control_port.c.
24*699cd480SApple OSS Distributions  * It verifies no reply port security semantics are violated.
25*699cd480SApple OSS Distributions  *
26*699cd480SApple OSS Distributions  * 1. The rcv right of the port would be marked immovable.
27*699cd480SApple OSS Distributions  */
28*699cd480SApple OSS Distributions T_GLOBAL_META(
29*699cd480SApple OSS Distributions 	T_META_NAMESPACE("xnu.ipc"),
30*699cd480SApple OSS Distributions 	T_META_RADAR_COMPONENT_NAME("xnu"),
31*699cd480SApple OSS Distributions 	T_META_RADAR_COMPONENT_VERSION("IPC"),
32*699cd480SApple OSS Distributions 	T_META_RUN_CONCURRENTLY(TRUE));
33*699cd480SApple OSS Distributions 
34*699cd480SApple OSS Distributions static mach_port_t
alloc_exception_port(void)35*699cd480SApple OSS Distributions alloc_exception_port(void)
36*699cd480SApple OSS Distributions {
37*699cd480SApple OSS Distributions 	kern_return_t kret;
38*699cd480SApple OSS Distributions 	mach_port_t exc_port = MACH_PORT_NULL;
39*699cd480SApple OSS Distributions 	mach_port_t task = mach_task_self();
40*699cd480SApple OSS Distributions 
41*699cd480SApple OSS Distributions 	kret = mach_port_allocate(task, MACH_PORT_RIGHT_RECEIVE, &exc_port);
42*699cd480SApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kret, "mach_port_allocate exc_port");
43*699cd480SApple OSS Distributions 
44*699cd480SApple OSS Distributions 	kret = mach_port_insert_right(task, exc_port, exc_port, MACH_MSG_TYPE_MAKE_SEND);
45*699cd480SApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kret, "mach_port_insert_right exc_port");
46*699cd480SApple OSS Distributions 
47*699cd480SApple OSS Distributions 	return exc_port;
48*699cd480SApple OSS Distributions }
49*699cd480SApple OSS Distributions 
50*699cd480SApple OSS Distributions kern_return_t
catch_mach_exception_raise_state(mach_port_t exception_port,exception_type_t exception,const mach_exception_data_t code,mach_msg_type_number_t code_count,int * flavor,const thread_state_t old_state,mach_msg_type_number_t old_state_count,thread_state_t new_state,mach_msg_type_number_t * new_state_count)51*699cd480SApple OSS Distributions catch_mach_exception_raise_state(mach_port_t exception_port,
52*699cd480SApple OSS Distributions     exception_type_t exception,
53*699cd480SApple OSS Distributions     const mach_exception_data_t code,
54*699cd480SApple OSS Distributions     mach_msg_type_number_t code_count,
55*699cd480SApple OSS Distributions     int * flavor,
56*699cd480SApple OSS Distributions     const thread_state_t old_state,
57*699cd480SApple OSS Distributions     mach_msg_type_number_t old_state_count,
58*699cd480SApple OSS Distributions     thread_state_t new_state,
59*699cd480SApple OSS Distributions     mach_msg_type_number_t * new_state_count)
60*699cd480SApple OSS Distributions {
61*699cd480SApple OSS Distributions #pragma unused(exception_port, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
62*699cd480SApple OSS Distributions 	T_FAIL("Unsupported catch_mach_exception_raise_state");
63*699cd480SApple OSS Distributions 	return KERN_NOT_SUPPORTED;
64*699cd480SApple OSS Distributions }
65*699cd480SApple OSS Distributions 
66*699cd480SApple OSS Distributions kern_return_t
catch_mach_exception_raise_state_identity(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t code_count,int * flavor,thread_state_t old_state,mach_msg_type_number_t old_state_count,thread_state_t new_state,mach_msg_type_number_t * new_state_count)67*699cd480SApple OSS Distributions catch_mach_exception_raise_state_identity(mach_port_t exception_port,
68*699cd480SApple OSS Distributions     mach_port_t thread,
69*699cd480SApple OSS Distributions     mach_port_t task,
70*699cd480SApple OSS Distributions     exception_type_t exception,
71*699cd480SApple OSS Distributions     mach_exception_data_t code,
72*699cd480SApple OSS Distributions     mach_msg_type_number_t code_count,
73*699cd480SApple OSS Distributions     int * flavor,
74*699cd480SApple OSS Distributions     thread_state_t old_state,
75*699cd480SApple OSS Distributions     mach_msg_type_number_t old_state_count,
76*699cd480SApple OSS Distributions     thread_state_t new_state,
77*699cd480SApple OSS Distributions     mach_msg_type_number_t * new_state_count)
78*699cd480SApple OSS Distributions {
79*699cd480SApple OSS Distributions #pragma unused(exception_port, thread, task, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
80*699cd480SApple OSS Distributions 	T_FAIL("Unsupported catch_mach_exception_raise_state_identity");
81*699cd480SApple OSS Distributions 	return KERN_NOT_SUPPORTED;
82*699cd480SApple OSS Distributions }
83*699cd480SApple OSS Distributions 
84*699cd480SApple OSS Distributions kern_return_t
catch_mach_exception_raise(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t code_count)85*699cd480SApple OSS Distributions catch_mach_exception_raise(mach_port_t exception_port,
86*699cd480SApple OSS Distributions     mach_port_t thread,
87*699cd480SApple OSS Distributions     mach_port_t task,
88*699cd480SApple OSS Distributions     exception_type_t exception,
89*699cd480SApple OSS Distributions     mach_exception_data_t code,
90*699cd480SApple OSS Distributions     mach_msg_type_number_t code_count)
91*699cd480SApple OSS Distributions {
92*699cd480SApple OSS Distributions #pragma unused(exception_port, code_count)
93*699cd480SApple OSS Distributions 	kern_return_t kr;
94*699cd480SApple OSS Distributions 
95*699cd480SApple OSS Distributions 	kr = mach_port_deallocate(mach_task_self(), thread);
96*699cd480SApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kr, "mach_port_deallocate");
97*699cd480SApple OSS Distributions 	kr = mach_port_deallocate(mach_task_self(), task);
98*699cd480SApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kr, "mach_port_deallocate");
99*699cd480SApple OSS Distributions 
100*699cd480SApple OSS Distributions 	T_LOG("Caught exception type: %d code: 0x%llx", exception, *code);
101*699cd480SApple OSS Distributions 	exception_taken = exception;
102*699cd480SApple OSS Distributions 	if (exception == EXC_GUARD) {
103*699cd480SApple OSS Distributions 		received_exception_code = EXC_GUARD_DECODE_GUARD_FLAVOR( *((uint64_t *)code));
104*699cd480SApple OSS Distributions 	} else if (exception == EXC_CORPSE_NOTIFY) {
105*699cd480SApple OSS Distributions 		received_exception_code = *code;
106*699cd480SApple OSS Distributions 	} else {
107*699cd480SApple OSS Distributions 		T_FAIL("Unexpected exception");
108*699cd480SApple OSS Distributions 	}
109*699cd480SApple OSS Distributions 	return KERN_SUCCESS;
110*699cd480SApple OSS Distributions }
111*699cd480SApple OSS Distributions 
112*699cd480SApple OSS Distributions static void *
exception_server_thread(void * arg)113*699cd480SApple OSS Distributions exception_server_thread(void *arg)
114*699cd480SApple OSS Distributions {
115*699cd480SApple OSS Distributions 	kern_return_t kr;
116*699cd480SApple OSS Distributions 	mach_port_t exc_port = *(mach_port_t *)arg;
117*699cd480SApple OSS Distributions 
118*699cd480SApple OSS Distributions 	/* Handle exceptions on exc_port */
119*699cd480SApple OSS Distributions 	kr = mach_msg_server_once(mach_exc_server, 4096, exc_port, 0);
120*699cd480SApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kr, "mach_msg_server_once");
121*699cd480SApple OSS Distributions 
122*699cd480SApple OSS Distributions 	return NULL;
123*699cd480SApple OSS Distributions }
124*699cd480SApple OSS Distributions 
125*699cd480SApple OSS Distributions T_DECL(reply_port_defense, "Test reply port semantics violations", T_META_IGNORECRASHES(".*reply_port_defense_client.*"), T_META_CHECK_LEAKS(false))
126*699cd480SApple OSS Distributions {
127*699cd480SApple OSS Distributions 	int ret = 0;
128*699cd480SApple OSS Distributions 
129*699cd480SApple OSS Distributions 	uint32_t task_exc_guard = 0;
130*699cd480SApple OSS Distributions 	size_t te_size = sizeof(&task_exc_guard);
131*699cd480SApple OSS Distributions 
132*699cd480SApple OSS Distributions 	char *test_prog_name = "./reply_port_defense_client";
133*699cd480SApple OSS Distributions 	char *child_args[MAX_ARGV];
134*699cd480SApple OSS Distributions 	pid_t client_pid = 0;
135*699cd480SApple OSS Distributions 	posix_spawnattr_t attrs;
136*699cd480SApple OSS Distributions 	bool triggers_exception;
137*699cd480SApple OSS Distributions 
138*699cd480SApple OSS Distributions 	pthread_t s_exc_thread;
139*699cd480SApple OSS Distributions 	mach_port_t exc_port;
140*699cd480SApple OSS Distributions 
141*699cd480SApple OSS Distributions 	T_LOG("Check if task_exc_guard exception has been enabled\n");
142*699cd480SApple OSS Distributions 	ret = sysctlbyname("kern.task_exc_guard_default", &task_exc_guard, &te_size, NULL, 0);
143*699cd480SApple OSS Distributions 	T_ASSERT_EQ(ret, 0, "sysctlbyname");
144*699cd480SApple OSS Distributions 
145*699cd480SApple OSS Distributions 	if (!(task_exc_guard & TASK_EXC_GUARD_MP_DELIVER)) {
146*699cd480SApple OSS Distributions 		T_SKIP("task_exc_guard exception is not enabled");
147*699cd480SApple OSS Distributions 	}
148*699cd480SApple OSS Distributions 
149*699cd480SApple OSS Distributions 	for (int i = 0; i < MAX_TEST_NUM; i++) {
150*699cd480SApple OSS Distributions 		received_exception_code = 0;
151*699cd480SApple OSS Distributions 		triggers_exception = true;
152*699cd480SApple OSS Distributions 		exc_port = alloc_exception_port();
153*699cd480SApple OSS Distributions 		T_QUIET; T_ASSERT_NE(exc_port, MACH_PORT_NULL, "Create a new exception port");
154*699cd480SApple OSS Distributions 
155*699cd480SApple OSS Distributions 		if (i == 4) {
156*699cd480SApple OSS Distributions 			triggers_exception = false;
157*699cd480SApple OSS Distributions 		}
158*699cd480SApple OSS Distributions 
159*699cd480SApple OSS Distributions 		/* Create exception serving thread */
160*699cd480SApple OSS Distributions 		ret = pthread_create(&s_exc_thread, NULL, exception_server_thread, &exc_port);
161*699cd480SApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_create exception_server_thread");
162*699cd480SApple OSS Distributions 
163*699cd480SApple OSS Distributions 		/* Initialize posix_spawn attributes */
164*699cd480SApple OSS Distributions 		posix_spawnattr_init(&attrs);
165*699cd480SApple OSS Distributions 
166*699cd480SApple OSS Distributions 		int err = posix_spawnattr_setexceptionports_np(&attrs, EXC_MASK_GUARD | EXC_MASK_CORPSE_NOTIFY, exc_port,
167*699cd480SApple OSS Distributions 		    (exception_behavior_t) (EXCEPTION_DEFAULT | MACH_EXCEPTION_CODES), 0);
168*699cd480SApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(err, "posix_spawnattr_setflags");
169*699cd480SApple OSS Distributions 
170*699cd480SApple OSS Distributions 		child_args[0] = test_prog_name;
171*699cd480SApple OSS Distributions 		char test_num[10];
172*699cd480SApple OSS Distributions 		sprintf(test_num, "%d", i);
173*699cd480SApple OSS Distributions 		child_args[1] = test_num;
174*699cd480SApple OSS Distributions 		child_args[2] = NULL;
175*699cd480SApple OSS Distributions 
176*699cd480SApple OSS Distributions 		T_LOG("========== Spawning new child ==========");
177*699cd480SApple OSS Distributions 		err = posix_spawn(&client_pid, child_args[0], NULL, &attrs, &child_args[0], environ);
178*699cd480SApple OSS Distributions 		T_ASSERT_POSIX_SUCCESS(err, "posix_spawn reply_port_defense_client = %d", client_pid);
179*699cd480SApple OSS Distributions 
180*699cd480SApple OSS Distributions 		int child_status;
181*699cd480SApple OSS Distributions 		/* Wait for child and check for exception */
182*699cd480SApple OSS Distributions 		if (-1 == waitpid(-1, &child_status, 0)) {
183*699cd480SApple OSS Distributions 			T_FAIL("%s waitpid: child", strerror(errno));
184*699cd480SApple OSS Distributions 		}
185*699cd480SApple OSS Distributions 		if (WIFEXITED(child_status) && WEXITSTATUS(child_status)) {
186*699cd480SApple OSS Distributions 			T_FAIL("Child exited with status = 0x%x", child_status);
187*699cd480SApple OSS Distributions 			T_END;
188*699cd480SApple OSS Distributions 		}
189*699cd480SApple OSS Distributions 		sleep(1);
190*699cd480SApple OSS Distributions 		kill(1, SIGKILL);
191*699cd480SApple OSS Distributions 		if (triggers_exception) {
192*699cd480SApple OSS Distributions 			ret = pthread_join(s_exc_thread, NULL);
193*699cd480SApple OSS Distributions 			T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_join");
194*699cd480SApple OSS Distributions 		}
195*699cd480SApple OSS Distributions 
196*699cd480SApple OSS Distributions 		mach_port_deallocate(mach_task_self(), exc_port);
197*699cd480SApple OSS Distributions 
198*699cd480SApple OSS Distributions 		if (i == 0) { /* The first test is setup as moving immovable receive right of a reply port. */
199*699cd480SApple OSS Distributions 			expected_exception_code = (mach_exception_data_type_t)kGUARD_EXC_IMMOVABLE;
200*699cd480SApple OSS Distributions 		} else if (!triggers_exception) {
201*699cd480SApple OSS Distributions 			expected_exception_code = 0;
202*699cd480SApple OSS Distributions 		} else {
203*699cd480SApple OSS Distributions 			expected_exception_code = (mach_exception_data_type_t)kGUARD_EXC_INVALID_RIGHT;
204*699cd480SApple OSS Distributions 		}
205*699cd480SApple OSS Distributions 
206*699cd480SApple OSS Distributions 		T_LOG("Exception code: Received code = 0x%llx Expected code = 0x%llx", received_exception_code, expected_exception_code);
207*699cd480SApple OSS Distributions 		T_EXPECT_EQ(received_exception_code, expected_exception_code, "Exception code: Received == Expected");
208*699cd480SApple OSS Distributions 	}
209*699cd480SApple OSS Distributions 
210*699cd480SApple OSS Distributions 	T_END;
211*699cd480SApple OSS Distributions }
212