1*0f4c859eSApple OSS Distributions /*
2*0f4c859eSApple OSS Distributions * Copyright (c) 2000,2008-2009 Apple Inc. All rights reserved.
3*0f4c859eSApple OSS Distributions *
4*0f4c859eSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*0f4c859eSApple OSS Distributions *
6*0f4c859eSApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*0f4c859eSApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*0f4c859eSApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*0f4c859eSApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*0f4c859eSApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*0f4c859eSApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*0f4c859eSApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*0f4c859eSApple OSS Distributions * terms of an Apple operating system software license agreement.
14*0f4c859eSApple OSS Distributions *
15*0f4c859eSApple OSS Distributions * Please obtain a copy of the License at
16*0f4c859eSApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*0f4c859eSApple OSS Distributions *
18*0f4c859eSApple OSS Distributions * The Original Code and all software distributed under the License are
19*0f4c859eSApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*0f4c859eSApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*0f4c859eSApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*0f4c859eSApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*0f4c859eSApple OSS Distributions * Please see the License for the specific language governing rights and
24*0f4c859eSApple OSS Distributions * limitations under the License.
25*0f4c859eSApple OSS Distributions *
26*0f4c859eSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*0f4c859eSApple OSS Distributions */
28*0f4c859eSApple OSS Distributions /*
29*0f4c859eSApple OSS Distributions * Copyright (c) 1997 Apple Inc.
30*0f4c859eSApple OSS Distributions *
31*0f4c859eSApple OSS Distributions */
32*0f4c859eSApple OSS Distributions #include <libkern/c++/OSMetaClass.h>
33*0f4c859eSApple OSS Distributions #include <libkern/c++/OSKext.h>
34*0f4c859eSApple OSS Distributions #include <libkern/c++/OSLib.h>
35*0f4c859eSApple OSS Distributions #include <libkern/c++/OSSymbol.h>
36*0f4c859eSApple OSS Distributions #include <IOKit/IOKitDebug.h>
37*0f4c859eSApple OSS Distributions
38*0f4c859eSApple OSS Distributions #include <sys/cdefs.h>
39*0f4c859eSApple OSS Distributions #if defined(HAS_APPLE_PAC)
40*0f4c859eSApple OSS Distributions #include <ptrauth.h>
41*0f4c859eSApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x) ((uintptr_t) ptrauth_strip(ptrauth_nop_cast(void *, (x)), ptrauth_key_function_pointer))
42*0f4c859eSApple OSS Distributions #else /* defined(HAS_APPLE_PAC) */
43*0f4c859eSApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x) ((uintptr_t) (x))
44*0f4c859eSApple OSS Distributions #endif /* !defined(HAS_APPLE_PAC) */
45*0f4c859eSApple OSS Distributions
46*0f4c859eSApple OSS Distributions __BEGIN_DECLS
47*0f4c859eSApple OSS Distributions
48*0f4c859eSApple OSS Distributions #include <string.h>
49*0f4c859eSApple OSS Distributions #include <mach/mach_types.h>
50*0f4c859eSApple OSS Distributions #include <libkern/kernel_mach_header.h>
51*0f4c859eSApple OSS Distributions #include <libkern/prelink.h>
52*0f4c859eSApple OSS Distributions #include <stdarg.h>
53*0f4c859eSApple OSS Distributions
54*0f4c859eSApple OSS Distributions #if KASAN
55*0f4c859eSApple OSS Distributions #include <san/kasan.h>
56*0f4c859eSApple OSS Distributions #endif
57*0f4c859eSApple OSS Distributions
58*0f4c859eSApple OSS Distributions
59*0f4c859eSApple OSS Distributions #if PRAGMA_MARK
60*0f4c859eSApple OSS Distributions #pragma mark Constants &c.
61*0f4c859eSApple OSS Distributions #endif /* PRAGMA_MARK */
62*0f4c859eSApple OSS Distributions OSKextLogSpec kOSRuntimeLogSpec =
63*0f4c859eSApple OSS Distributions kOSKextLogErrorLevel |
64*0f4c859eSApple OSS Distributions kOSKextLogLoadFlag |
65*0f4c859eSApple OSS Distributions kOSKextLogKextBookkeepingFlag;
66*0f4c859eSApple OSS Distributions
67*0f4c859eSApple OSS Distributions #if PRAGMA_MARK
68*0f4c859eSApple OSS Distributions #pragma mark Logging Bootstrap
69*0f4c859eSApple OSS Distributions #endif /* PRAGMA_MARK */
70*0f4c859eSApple OSS Distributions /*********************************************************************
71*0f4c859eSApple OSS Distributions * kern_os Logging Bootstrap
72*0f4c859eSApple OSS Distributions *
73*0f4c859eSApple OSS Distributions * We can't call in to OSKext until the kernel's C++ environment is up
74*0f4c859eSApple OSS Distributions * and running, so let's mask those references with a check variable.
75*0f4c859eSApple OSS Distributions * We print unconditionally if C++ isn't up, but if that's the case
76*0f4c859eSApple OSS Distributions * we've generally hit a serious error in kernel init!
77*0f4c859eSApple OSS Distributions *********************************************************************/
78*0f4c859eSApple OSS Distributions static bool gKernelCPPInitialized = false;
79*0f4c859eSApple OSS Distributions
80*0f4c859eSApple OSS Distributions #define OSRuntimeLog(kext, flags, format, args ...) \
81*0f4c859eSApple OSS Distributions do { \
82*0f4c859eSApple OSS Distributions if (gKernelCPPInitialized) { \
83*0f4c859eSApple OSS Distributions OSKextLog((kext), (flags), (format), ## args); \
84*0f4c859eSApple OSS Distributions } else { \
85*0f4c859eSApple OSS Distributions printf((format), ## args); \
86*0f4c859eSApple OSS Distributions } \
87*0f4c859eSApple OSS Distributions } while (0)
88*0f4c859eSApple OSS Distributions
89*0f4c859eSApple OSS Distributions #if PRAGMA_MARK
90*0f4c859eSApple OSS Distributions #pragma mark Libkern Init
91*0f4c859eSApple OSS Distributions #endif /* PRAGMA_MARK */
92*0f4c859eSApple OSS Distributions /*********************************************************************
93*0f4c859eSApple OSS Distributions * Libkern Init
94*0f4c859eSApple OSS Distributions *********************************************************************/
95*0f4c859eSApple OSS Distributions
96*0f4c859eSApple OSS Distributions #if __GNUC__ >= 3
97*0f4c859eSApple OSS Distributions void __dead2
__cxa_pure_virtual(void)98*0f4c859eSApple OSS Distributions __cxa_pure_virtual( void )
99*0f4c859eSApple OSS Distributions {
100*0f4c859eSApple OSS Distributions panic("%s", __FUNCTION__);
101*0f4c859eSApple OSS Distributions }
102*0f4c859eSApple OSS Distributions #else
103*0f4c859eSApple OSS Distributions void __dead2
__pure_virtual(void)104*0f4c859eSApple OSS Distributions __pure_virtual( void )
105*0f4c859eSApple OSS Distributions {
106*0f4c859eSApple OSS Distributions panic("%s", __FUNCTION__);
107*0f4c859eSApple OSS Distributions }
108*0f4c859eSApple OSS Distributions #endif
109*0f4c859eSApple OSS Distributions
110*0f4c859eSApple OSS Distributions extern lck_grp_t * IOLockGroup;
111*0f4c859eSApple OSS Distributions extern kmod_info_t g_kernel_kmod_info;
112*0f4c859eSApple OSS Distributions
113*0f4c859eSApple OSS Distributions enum {
114*0f4c859eSApple OSS Distributions kOSSectionNamesDefault = 0,
115*0f4c859eSApple OSS Distributions kOSSectionNamesBuiltinKext = 1,
116*0f4c859eSApple OSS Distributions kOSSectionNamesCount = 2,
117*0f4c859eSApple OSS Distributions };
118*0f4c859eSApple OSS Distributions enum {
119*0f4c859eSApple OSS Distributions kOSSectionNameInitializer = 0,
120*0f4c859eSApple OSS Distributions kOSSectionNameFinalizer = 1,
121*0f4c859eSApple OSS Distributions kOSSectionNameCount = 2
122*0f4c859eSApple OSS Distributions };
123*0f4c859eSApple OSS Distributions
124*0f4c859eSApple OSS Distributions static const char *
125*0f4c859eSApple OSS Distributions gOSStructorSectionNames[kOSSectionNamesCount][kOSSectionNameCount] = {
126*0f4c859eSApple OSS Distributions { SECT_MODINITFUNC, SECT_MODTERMFUNC },
127*0f4c859eSApple OSS Distributions { kBuiltinInitSection, kBuiltinTermSection }
128*0f4c859eSApple OSS Distributions };
129*0f4c859eSApple OSS Distributions
130*0f4c859eSApple OSS Distributions void
OSlibkernInit(void)131*0f4c859eSApple OSS Distributions OSlibkernInit(void)
132*0f4c859eSApple OSS Distributions {
133*0f4c859eSApple OSS Distributions // This must be called before calling OSRuntimeInitializeCPP.
134*0f4c859eSApple OSS Distributions OSMetaClassBase::initialize();
135*0f4c859eSApple OSS Distributions
136*0f4c859eSApple OSS Distributions g_kernel_kmod_info.address = (vm_address_t) &_mh_execute_header;
137*0f4c859eSApple OSS Distributions
138*0f4c859eSApple OSS Distributions if (kOSReturnSuccess != OSRuntimeInitializeCPP(NULL)) {
139*0f4c859eSApple OSS Distributions // &g_kernel_kmod_info, gOSSectionNamesStandard, 0, 0)) {
140*0f4c859eSApple OSS Distributions panic("OSRuntime: C++ runtime failed to initialize.");
141*0f4c859eSApple OSS Distributions }
142*0f4c859eSApple OSS Distributions
143*0f4c859eSApple OSS Distributions gKernelCPPInitialized = true;
144*0f4c859eSApple OSS Distributions
145*0f4c859eSApple OSS Distributions return;
146*0f4c859eSApple OSS Distributions }
147*0f4c859eSApple OSS Distributions
148*0f4c859eSApple OSS Distributions __END_DECLS
149*0f4c859eSApple OSS Distributions
150*0f4c859eSApple OSS Distributions #if PRAGMA_MARK
151*0f4c859eSApple OSS Distributions #pragma mark C++ Runtime Load/Unload
152*0f4c859eSApple OSS Distributions #endif /* PRAGMA_MARK */
153*0f4c859eSApple OSS Distributions /*********************************************************************
154*0f4c859eSApple OSS Distributions * kern_os C++ Runtime Load/Unload
155*0f4c859eSApple OSS Distributions *********************************************************************/
156*0f4c859eSApple OSS Distributions
157*0f4c859eSApple OSS Distributions typedef void (*structor_t)(void);
158*0f4c859eSApple OSS Distributions
159*0f4c859eSApple OSS Distributions static bool
OSRuntimeCallStructorsInSection(OSKext * theKext,kmod_info_t * kmodInfo,void * metaHandle,kernel_segment_command_t * segment,const char * sectionName,uintptr_t textStart,uintptr_t textEnd)160*0f4c859eSApple OSS Distributions OSRuntimeCallStructorsInSection(
161*0f4c859eSApple OSS Distributions OSKext * theKext,
162*0f4c859eSApple OSS Distributions kmod_info_t * kmodInfo,
163*0f4c859eSApple OSS Distributions void * metaHandle,
164*0f4c859eSApple OSS Distributions kernel_segment_command_t * segment,
165*0f4c859eSApple OSS Distributions const char * sectionName,
166*0f4c859eSApple OSS Distributions uintptr_t textStart,
167*0f4c859eSApple OSS Distributions uintptr_t textEnd)
168*0f4c859eSApple OSS Distributions {
169*0f4c859eSApple OSS Distributions kernel_section_t * section;
170*0f4c859eSApple OSS Distributions bool result = TRUE;
171*0f4c859eSApple OSS Distributions
172*0f4c859eSApple OSS Distributions for (section = firstsect(segment);
173*0f4c859eSApple OSS Distributions section != NULL;
174*0f4c859eSApple OSS Distributions section = nextsect(segment, section)) {
175*0f4c859eSApple OSS Distributions if (strncmp(section->sectname, sectionName, sizeof(section->sectname) - 1)) {
176*0f4c859eSApple OSS Distributions continue;
177*0f4c859eSApple OSS Distributions }
178*0f4c859eSApple OSS Distributions if (section->size == 0) {
179*0f4c859eSApple OSS Distributions continue;
180*0f4c859eSApple OSS Distributions }
181*0f4c859eSApple OSS Distributions
182*0f4c859eSApple OSS Distributions structor_t * structors = (structor_t *)section->addr;
183*0f4c859eSApple OSS Distributions if (!structors) {
184*0f4c859eSApple OSS Distributions continue;
185*0f4c859eSApple OSS Distributions }
186*0f4c859eSApple OSS Distributions
187*0f4c859eSApple OSS Distributions structor_t structor;
188*0f4c859eSApple OSS Distributions uintptr_t value;
189*0f4c859eSApple OSS Distributions unsigned long num_structors = section->size / sizeof(structor_t);
190*0f4c859eSApple OSS Distributions unsigned int hit_null_structor = 0;
191*0f4c859eSApple OSS Distributions unsigned long firstIndex = 0;
192*0f4c859eSApple OSS Distributions
193*0f4c859eSApple OSS Distributions if (textStart) {
194*0f4c859eSApple OSS Distributions // bsearch for any in range
195*0f4c859eSApple OSS Distributions unsigned long baseIdx;
196*0f4c859eSApple OSS Distributions unsigned long lim;
197*0f4c859eSApple OSS Distributions firstIndex = num_structors;
198*0f4c859eSApple OSS Distributions for (lim = num_structors, baseIdx = 0; lim; lim >>= 1) {
199*0f4c859eSApple OSS Distributions structor = structors[baseIdx + (lim >> 1)];
200*0f4c859eSApple OSS Distributions if (!structor) {
201*0f4c859eSApple OSS Distributions panic("%s: null structor", kmodInfo->name);
202*0f4c859eSApple OSS Distributions }
203*0f4c859eSApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
204*0f4c859eSApple OSS Distributions if ((value >= textStart) && (value < textEnd)) {
205*0f4c859eSApple OSS Distributions firstIndex = (baseIdx + (lim >> 1));
206*0f4c859eSApple OSS Distributions // scan back for the first in range
207*0f4c859eSApple OSS Distributions for (; firstIndex; firstIndex--) {
208*0f4c859eSApple OSS Distributions structor = structors[firstIndex - 1];
209*0f4c859eSApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
210*0f4c859eSApple OSS Distributions if ((value < textStart) || (value >= textEnd)) {
211*0f4c859eSApple OSS Distributions break;
212*0f4c859eSApple OSS Distributions }
213*0f4c859eSApple OSS Distributions }
214*0f4c859eSApple OSS Distributions break;
215*0f4c859eSApple OSS Distributions }
216*0f4c859eSApple OSS Distributions if (textStart > value) {
217*0f4c859eSApple OSS Distributions // move right
218*0f4c859eSApple OSS Distributions baseIdx += (lim >> 1) + 1;
219*0f4c859eSApple OSS Distributions lim--;
220*0f4c859eSApple OSS Distributions }
221*0f4c859eSApple OSS Distributions // else move left
222*0f4c859eSApple OSS Distributions }
223*0f4c859eSApple OSS Distributions baseIdx = (baseIdx + (lim >> 1));
224*0f4c859eSApple OSS Distributions }
225*0f4c859eSApple OSS Distributions for (;
226*0f4c859eSApple OSS Distributions (firstIndex < num_structors)
227*0f4c859eSApple OSS Distributions && (!metaHandle || OSMetaClass::checkModLoad(metaHandle));
228*0f4c859eSApple OSS Distributions firstIndex++) {
229*0f4c859eSApple OSS Distributions if ((structor = structors[firstIndex])) {
230*0f4c859eSApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
231*0f4c859eSApple OSS Distributions if ((textStart && (value < textStart))
232*0f4c859eSApple OSS Distributions || (textEnd && (value >= textEnd))) {
233*0f4c859eSApple OSS Distributions break;
234*0f4c859eSApple OSS Distributions }
235*0f4c859eSApple OSS Distributions (*structor)();
236*0f4c859eSApple OSS Distributions } else if (!hit_null_structor) {
237*0f4c859eSApple OSS Distributions hit_null_structor = 1;
238*0f4c859eSApple OSS Distributions OSRuntimeLog(theKext, kOSRuntimeLogSpec,
239*0f4c859eSApple OSS Distributions "Null structor in kext %s segment %s!",
240*0f4c859eSApple OSS Distributions kmodInfo->name, section->segname);
241*0f4c859eSApple OSS Distributions }
242*0f4c859eSApple OSS Distributions }
243*0f4c859eSApple OSS Distributions if (metaHandle) {
244*0f4c859eSApple OSS Distributions result = OSMetaClass::checkModLoad(metaHandle);
245*0f4c859eSApple OSS Distributions }
246*0f4c859eSApple OSS Distributions break;
247*0f4c859eSApple OSS Distributions } /* for (section...) */
248*0f4c859eSApple OSS Distributions return result;
249*0f4c859eSApple OSS Distributions }
250*0f4c859eSApple OSS Distributions
251*0f4c859eSApple OSS Distributions /*********************************************************************
252*0f4c859eSApple OSS Distributions *********************************************************************/
253*0f4c859eSApple OSS Distributions kern_return_t
OSRuntimeFinalizeCPP(OSKext * theKext)254*0f4c859eSApple OSS Distributions OSRuntimeFinalizeCPP(
255*0f4c859eSApple OSS Distributions OSKext * theKext)
256*0f4c859eSApple OSS Distributions {
257*0f4c859eSApple OSS Distributions kern_return_t result = KMOD_RETURN_FAILURE;
258*0f4c859eSApple OSS Distributions void * metaHandle = NULL;// do not free
259*0f4c859eSApple OSS Distributions kernel_mach_header_t * header;
260*0f4c859eSApple OSS Distributions kernel_segment_command_t * segment;
261*0f4c859eSApple OSS Distributions kmod_info_t * kmodInfo;
262*0f4c859eSApple OSS Distributions const char ** sectionNames;
263*0f4c859eSApple OSS Distributions uintptr_t textStart;
264*0f4c859eSApple OSS Distributions uintptr_t textEnd;
265*0f4c859eSApple OSS Distributions
266*0f4c859eSApple OSS Distributions textStart = 0;
267*0f4c859eSApple OSS Distributions textEnd = 0;
268*0f4c859eSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
269*0f4c859eSApple OSS Distributions if (theKext) {
270*0f4c859eSApple OSS Distributions if (!theKext->isCPPInitialized()) {
271*0f4c859eSApple OSS Distributions result = KMOD_RETURN_SUCCESS;
272*0f4c859eSApple OSS Distributions goto finish;
273*0f4c859eSApple OSS Distributions }
274*0f4c859eSApple OSS Distributions kmodInfo = theKext->kmod_info;
275*0f4c859eSApple OSS Distributions if (!kmodInfo || !kmodInfo->address) {
276*0f4c859eSApple OSS Distributions result = kOSKextReturnInvalidArgument;
277*0f4c859eSApple OSS Distributions goto finish;
278*0f4c859eSApple OSS Distributions }
279*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
280*0f4c859eSApple OSS Distributions if (theKext->flags.builtin) {
281*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)g_kernel_kmod_info.address;
282*0f4c859eSApple OSS Distributions textStart = kmodInfo->address;
283*0f4c859eSApple OSS Distributions textEnd = textStart + kmodInfo->size;
284*0f4c859eSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
285*0f4c859eSApple OSS Distributions }
286*0f4c859eSApple OSS Distributions } else {
287*0f4c859eSApple OSS Distributions kmodInfo = &g_kernel_kmod_info;
288*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
289*0f4c859eSApple OSS Distributions }
290*0f4c859eSApple OSS Distributions
291*0f4c859eSApple OSS Distributions /* OSKext checks for this condition now, but somebody might call
292*0f4c859eSApple OSS Distributions * this function directly (the symbol is exported....).
293*0f4c859eSApple OSS Distributions */
294*0f4c859eSApple OSS Distributions if (OSMetaClass::modHasInstance(kmodInfo->name)) {
295*0f4c859eSApple OSS Distributions // xxx - Don't log under errors? this is more of an info thing
296*0f4c859eSApple OSS Distributions OSRuntimeLog(theKext, kOSRuntimeLogSpec,
297*0f4c859eSApple OSS Distributions "Can't tear down kext %s C++; classes have instances:",
298*0f4c859eSApple OSS Distributions kmodInfo->name);
299*0f4c859eSApple OSS Distributions OSKext::reportOSMetaClassInstances(kmodInfo->name, kOSRuntimeLogSpec);
300*0f4c859eSApple OSS Distributions result = kOSMetaClassHasInstances;
301*0f4c859eSApple OSS Distributions goto finish;
302*0f4c859eSApple OSS Distributions }
303*0f4c859eSApple OSS Distributions
304*0f4c859eSApple OSS Distributions /* Tell the meta class system that we are starting to unload.
305*0f4c859eSApple OSS Distributions * metaHandle isn't actually needed on the finalize path,
306*0f4c859eSApple OSS Distributions * so we don't check it here, even though OSMetaClass::postModLoad() will
307*0f4c859eSApple OSS Distributions * return a failure (it only does actual work on the init path anyhow).
308*0f4c859eSApple OSS Distributions */
309*0f4c859eSApple OSS Distributions metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
310*0f4c859eSApple OSS Distributions
311*0f4c859eSApple OSS Distributions OSSymbol::checkForPageUnload((void *)kmodInfo->address,
312*0f4c859eSApple OSS Distributions (void *)(kmodInfo->address + kmodInfo->size));
313*0f4c859eSApple OSS Distributions
314*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
315*0f4c859eSApple OSS Distributions segment = firstsegfromheader(header);
316*0f4c859eSApple OSS Distributions
317*0f4c859eSApple OSS Distributions for (segment = firstsegfromheader(header);
318*0f4c859eSApple OSS Distributions segment != NULL;
319*0f4c859eSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
320*0f4c859eSApple OSS Distributions OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
321*0f4c859eSApple OSS Distributions sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
322*0f4c859eSApple OSS Distributions }
323*0f4c859eSApple OSS Distributions
324*0f4c859eSApple OSS Distributions (void)OSMetaClass::postModLoad(metaHandle);
325*0f4c859eSApple OSS Distributions
326*0f4c859eSApple OSS Distributions if (theKext) {
327*0f4c859eSApple OSS Distributions theKext->setCPPInitialized(false);
328*0f4c859eSApple OSS Distributions }
329*0f4c859eSApple OSS Distributions result = KMOD_RETURN_SUCCESS;
330*0f4c859eSApple OSS Distributions finish:
331*0f4c859eSApple OSS Distributions return result;
332*0f4c859eSApple OSS Distributions }
333*0f4c859eSApple OSS Distributions
334*0f4c859eSApple OSS Distributions #if defined(HAS_APPLE_PAC)
335*0f4c859eSApple OSS Distributions #if !KASAN
336*0f4c859eSApple OSS Distributions /*
337*0f4c859eSApple OSS Distributions * Place this function in __KLD,__text on non-kasan builds so it gets unmapped
338*0f4c859eSApple OSS Distributions * after CTRR lockdown.
339*0f4c859eSApple OSS Distributions */
340*0f4c859eSApple OSS Distributions __attribute__((noinline, section("__KLD,__text")))
341*0f4c859eSApple OSS Distributions #endif
342*0f4c859eSApple OSS Distributions static void
OSRuntimeSignStructorsInSegment(kernel_segment_command_t * segment)343*0f4c859eSApple OSS Distributions OSRuntimeSignStructorsInSegment(kernel_segment_command_t *segment)
344*0f4c859eSApple OSS Distributions {
345*0f4c859eSApple OSS Distributions kernel_section_t * section;
346*0f4c859eSApple OSS Distributions structor_t * structors;
347*0f4c859eSApple OSS Distributions volatile structor_t structor;
348*0f4c859eSApple OSS Distributions size_t idx, num_structors;
349*0f4c859eSApple OSS Distributions
350*0f4c859eSApple OSS Distributions for (section = firstsect(segment);
351*0f4c859eSApple OSS Distributions section != NULL;
352*0f4c859eSApple OSS Distributions section = nextsect(segment, section)) {
353*0f4c859eSApple OSS Distributions if ((S_MOD_INIT_FUNC_POINTERS != (SECTION_TYPE & section->flags))
354*0f4c859eSApple OSS Distributions && (S_MOD_TERM_FUNC_POINTERS != (SECTION_TYPE & section->flags))) {
355*0f4c859eSApple OSS Distributions continue;
356*0f4c859eSApple OSS Distributions }
357*0f4c859eSApple OSS Distributions structors = (structor_t *)section->addr;
358*0f4c859eSApple OSS Distributions if (!structors) {
359*0f4c859eSApple OSS Distributions continue;
360*0f4c859eSApple OSS Distributions }
361*0f4c859eSApple OSS Distributions num_structors = section->size / sizeof(structor_t);
362*0f4c859eSApple OSS Distributions for (idx = 0; idx < num_structors; idx++) {
363*0f4c859eSApple OSS Distributions structor = structors[idx];
364*0f4c859eSApple OSS Distributions if (NULL == structor) {
365*0f4c859eSApple OSS Distributions continue;
366*0f4c859eSApple OSS Distributions }
367*0f4c859eSApple OSS Distributions structor = ptrauth_strip(structor, ptrauth_key_function_pointer);
368*0f4c859eSApple OSS Distributions structor = ptrauth_sign_unauthenticated(structor, ptrauth_key_function_pointer, ptrauth_function_pointer_type_discriminator(void (*)(void)));
369*0f4c859eSApple OSS Distributions structors[idx] = structor;
370*0f4c859eSApple OSS Distributions }
371*0f4c859eSApple OSS Distributions } /* for (section...) */
372*0f4c859eSApple OSS Distributions }
373*0f4c859eSApple OSS Distributions #endif
374*0f4c859eSApple OSS Distributions
375*0f4c859eSApple OSS Distributions /*********************************************************************
376*0f4c859eSApple OSS Distributions *********************************************************************/
377*0f4c859eSApple OSS Distributions void
OSRuntimeSignStructors(kernel_mach_header_t * header __unused)378*0f4c859eSApple OSS Distributions OSRuntimeSignStructors(
379*0f4c859eSApple OSS Distributions kernel_mach_header_t * header __unused)
380*0f4c859eSApple OSS Distributions {
381*0f4c859eSApple OSS Distributions #if defined(HAS_APPLE_PAC)
382*0f4c859eSApple OSS Distributions
383*0f4c859eSApple OSS Distributions kernel_segment_command_t * segment;
384*0f4c859eSApple OSS Distributions
385*0f4c859eSApple OSS Distributions for (segment = firstsegfromheader(header);
386*0f4c859eSApple OSS Distributions segment != NULL;
387*0f4c859eSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
388*0f4c859eSApple OSS Distributions OSRuntimeSignStructorsInSegment(segment);
389*0f4c859eSApple OSS Distributions } /* for (segment...) */
390*0f4c859eSApple OSS Distributions #endif /* !defined(XXX) && defined(HAS_APPLE_PAC) */
391*0f4c859eSApple OSS Distributions }
392*0f4c859eSApple OSS Distributions
393*0f4c859eSApple OSS Distributions /*********************************************************************
394*0f4c859eSApple OSS Distributions *********************************************************************/
395*0f4c859eSApple OSS Distributions void
OSRuntimeSignStructorsInFileset(kernel_mach_header_t * fileset_header __unused)396*0f4c859eSApple OSS Distributions OSRuntimeSignStructorsInFileset(
397*0f4c859eSApple OSS Distributions kernel_mach_header_t * fileset_header __unused)
398*0f4c859eSApple OSS Distributions {
399*0f4c859eSApple OSS Distributions #if defined(HAS_APPLE_PAC)
400*0f4c859eSApple OSS Distributions struct load_command *lc;
401*0f4c859eSApple OSS Distributions
402*0f4c859eSApple OSS Distributions lc = (struct load_command *)((uintptr_t)fileset_header + sizeof(*fileset_header));
403*0f4c859eSApple OSS Distributions for (uint32_t i = 0; i < fileset_header->ncmds; i++,
404*0f4c859eSApple OSS Distributions lc = (struct load_command *)((uintptr_t)lc + lc->cmdsize)) {
405*0f4c859eSApple OSS Distributions if (lc->cmd == LC_FILESET_ENTRY) {
406*0f4c859eSApple OSS Distributions struct fileset_entry_command *fse;
407*0f4c859eSApple OSS Distributions kernel_mach_header_t *mh;
408*0f4c859eSApple OSS Distributions
409*0f4c859eSApple OSS Distributions fse = (struct fileset_entry_command *)(uintptr_t)lc;
410*0f4c859eSApple OSS Distributions mh = (kernel_mach_header_t *)((uintptr_t)fse->vmaddr);
411*0f4c859eSApple OSS Distributions OSRuntimeSignStructors(mh);
412*0f4c859eSApple OSS Distributions } else if (lc->cmd == LC_SEGMENT_64) {
413*0f4c859eSApple OSS Distributions /*
414*0f4c859eSApple OSS Distributions * Slide/adjust all LC_SEGMENT_64 commands in the fileset
415*0f4c859eSApple OSS Distributions * (and any sections in those segments)
416*0f4c859eSApple OSS Distributions */
417*0f4c859eSApple OSS Distributions kernel_segment_command_t *seg;
418*0f4c859eSApple OSS Distributions seg = (kernel_segment_command_t *)(uintptr_t)lc;
419*0f4c859eSApple OSS Distributions OSRuntimeSignStructorsInSegment(seg);
420*0f4c859eSApple OSS Distributions }
421*0f4c859eSApple OSS Distributions }
422*0f4c859eSApple OSS Distributions
423*0f4c859eSApple OSS Distributions #endif /* defined(HAS_APPLE_PAC) */
424*0f4c859eSApple OSS Distributions }
425*0f4c859eSApple OSS Distributions
426*0f4c859eSApple OSS Distributions /*********************************************************************
427*0f4c859eSApple OSS Distributions *********************************************************************/
428*0f4c859eSApple OSS Distributions kern_return_t
OSRuntimeInitializeCPP(OSKext * theKext)429*0f4c859eSApple OSS Distributions OSRuntimeInitializeCPP(
430*0f4c859eSApple OSS Distributions OSKext * theKext)
431*0f4c859eSApple OSS Distributions {
432*0f4c859eSApple OSS Distributions kern_return_t result = KMOD_RETURN_FAILURE;
433*0f4c859eSApple OSS Distributions kernel_mach_header_t * header = NULL;
434*0f4c859eSApple OSS Distributions void * metaHandle = NULL;// do not free
435*0f4c859eSApple OSS Distributions bool load_success = true;
436*0f4c859eSApple OSS Distributions kernel_segment_command_t * segment = NULL;// do not free
437*0f4c859eSApple OSS Distributions kernel_segment_command_t * failure_segment = NULL; // do not free
438*0f4c859eSApple OSS Distributions kmod_info_t * kmodInfo;
439*0f4c859eSApple OSS Distributions const char ** sectionNames;
440*0f4c859eSApple OSS Distributions uintptr_t textStart;
441*0f4c859eSApple OSS Distributions uintptr_t textEnd;
442*0f4c859eSApple OSS Distributions
443*0f4c859eSApple OSS Distributions textStart = 0;
444*0f4c859eSApple OSS Distributions textEnd = 0;
445*0f4c859eSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
446*0f4c859eSApple OSS Distributions if (theKext) {
447*0f4c859eSApple OSS Distributions if (theKext->isCPPInitialized()) {
448*0f4c859eSApple OSS Distributions result = KMOD_RETURN_SUCCESS;
449*0f4c859eSApple OSS Distributions goto finish;
450*0f4c859eSApple OSS Distributions }
451*0f4c859eSApple OSS Distributions
452*0f4c859eSApple OSS Distributions kmodInfo = theKext->kmod_info;
453*0f4c859eSApple OSS Distributions if (!kmodInfo || !kmodInfo->address) {
454*0f4c859eSApple OSS Distributions result = kOSKextReturnInvalidArgument;
455*0f4c859eSApple OSS Distributions goto finish;
456*0f4c859eSApple OSS Distributions }
457*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
458*0f4c859eSApple OSS Distributions
459*0f4c859eSApple OSS Distributions if (theKext->flags.builtin) {
460*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)g_kernel_kmod_info.address;
461*0f4c859eSApple OSS Distributions textStart = kmodInfo->address;
462*0f4c859eSApple OSS Distributions textEnd = textStart + kmodInfo->size;
463*0f4c859eSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
464*0f4c859eSApple OSS Distributions }
465*0f4c859eSApple OSS Distributions } else {
466*0f4c859eSApple OSS Distributions kmodInfo = &g_kernel_kmod_info;
467*0f4c859eSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
468*0f4c859eSApple OSS Distributions }
469*0f4c859eSApple OSS Distributions
470*0f4c859eSApple OSS Distributions /* Tell the meta class system that we are starting the load
471*0f4c859eSApple OSS Distributions */
472*0f4c859eSApple OSS Distributions metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
473*0f4c859eSApple OSS Distributions assert(metaHandle);
474*0f4c859eSApple OSS Distributions if (!metaHandle) {
475*0f4c859eSApple OSS Distributions goto finish;
476*0f4c859eSApple OSS Distributions }
477*0f4c859eSApple OSS Distributions
478*0f4c859eSApple OSS Distributions /* NO GOTO PAST HERE. */
479*0f4c859eSApple OSS Distributions
480*0f4c859eSApple OSS Distributions /* Scan the header for all constructor sections, in any
481*0f4c859eSApple OSS Distributions * segment, and invoke the constructors within those sections.
482*0f4c859eSApple OSS Distributions */
483*0f4c859eSApple OSS Distributions for (segment = firstsegfromheader(header);
484*0f4c859eSApple OSS Distributions segment != NULL && load_success;
485*0f4c859eSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
486*0f4c859eSApple OSS Distributions /* Record the current segment in the event of a failure.
487*0f4c859eSApple OSS Distributions */
488*0f4c859eSApple OSS Distributions failure_segment = segment;
489*0f4c859eSApple OSS Distributions load_success = OSRuntimeCallStructorsInSection(
490*0f4c859eSApple OSS Distributions theKext, kmodInfo, metaHandle, segment,
491*0f4c859eSApple OSS Distributions sectionNames[kOSSectionNameInitializer],
492*0f4c859eSApple OSS Distributions textStart, textEnd);
493*0f4c859eSApple OSS Distributions } /* for (segment...) */
494*0f4c859eSApple OSS Distributions
495*0f4c859eSApple OSS Distributions /* We failed so call all of the destructors. We must do this before
496*0f4c859eSApple OSS Distributions * calling OSMetaClass::postModLoad() as the OSMetaClass destructors
497*0f4c859eSApple OSS Distributions * will alter state (in the metaHandle) used by that function.
498*0f4c859eSApple OSS Distributions */
499*0f4c859eSApple OSS Distributions if (!load_success) {
500*0f4c859eSApple OSS Distributions /* Scan the header for all destructor sections, in any
501*0f4c859eSApple OSS Distributions * segment, and invoke the constructors within those sections.
502*0f4c859eSApple OSS Distributions */
503*0f4c859eSApple OSS Distributions for (segment = firstsegfromheader(header);
504*0f4c859eSApple OSS Distributions segment != failure_segment && segment != NULL;
505*0f4c859eSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
506*0f4c859eSApple OSS Distributions OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
507*0f4c859eSApple OSS Distributions sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
508*0f4c859eSApple OSS Distributions } /* for (segment...) */
509*0f4c859eSApple OSS Distributions }
510*0f4c859eSApple OSS Distributions
511*0f4c859eSApple OSS Distributions /* Now, regardless of success so far, do the post-init registration
512*0f4c859eSApple OSS Distributions * and cleanup. If we had to call the unloadCPP function, static
513*0f4c859eSApple OSS Distributions * destructors have removed classes from the stalled list so no
514*0f4c859eSApple OSS Distributions * metaclasses will actually be registered.
515*0f4c859eSApple OSS Distributions */
516*0f4c859eSApple OSS Distributions result = OSMetaClass::postModLoad(metaHandle);
517*0f4c859eSApple OSS Distributions
518*0f4c859eSApple OSS Distributions /* If we've otherwise been fine up to now, but OSMetaClass::postModLoad()
519*0f4c859eSApple OSS Distributions * fails (typically due to a duplicate class), tear down all the C++
520*0f4c859eSApple OSS Distributions * stuff from the kext. This isn't necessary for libkern/OSMetaClass stuff,
521*0f4c859eSApple OSS Distributions * but may be necessary for other C++ code. We ignore the return value
522*0f4c859eSApple OSS Distributions * because it's only a fail when there are existing instances of libkern
523*0f4c859eSApple OSS Distributions * classes, and there had better not be any created on the C++ init path.
524*0f4c859eSApple OSS Distributions */
525*0f4c859eSApple OSS Distributions if (load_success && result != KMOD_RETURN_SUCCESS) {
526*0f4c859eSApple OSS Distributions (void)OSRuntimeFinalizeCPP(theKext); //kmodInfo, sectionNames, textStart, textEnd);
527*0f4c859eSApple OSS Distributions }
528*0f4c859eSApple OSS Distributions
529*0f4c859eSApple OSS Distributions if (theKext && load_success && result == KMOD_RETURN_SUCCESS) {
530*0f4c859eSApple OSS Distributions theKext->setCPPInitialized(true);
531*0f4c859eSApple OSS Distributions }
532*0f4c859eSApple OSS Distributions finish:
533*0f4c859eSApple OSS Distributions return result;
534*0f4c859eSApple OSS Distributions }
535*0f4c859eSApple OSS Distributions
536*0f4c859eSApple OSS Distributions /*********************************************************************
537*0f4c859eSApple OSS Distributions * Unload a kernel segment.
538*0f4c859eSApple OSS Distributions *********************************************************************/
539*0f4c859eSApple OSS Distributions
540*0f4c859eSApple OSS Distributions void
OSRuntimeUnloadCPPForSegment(kernel_segment_command_t * segment)541*0f4c859eSApple OSS Distributions OSRuntimeUnloadCPPForSegment(
542*0f4c859eSApple OSS Distributions kernel_segment_command_t * segment)
543*0f4c859eSApple OSS Distributions {
544*0f4c859eSApple OSS Distributions OSRuntimeCallStructorsInSection(NULL, &g_kernel_kmod_info, NULL, segment,
545*0f4c859eSApple OSS Distributions gOSStructorSectionNames[kOSSectionNamesDefault][kOSSectionNameFinalizer], 0, 0);
546*0f4c859eSApple OSS Distributions }
547*0f4c859eSApple OSS Distributions
548*0f4c859eSApple OSS Distributions #if PRAGMA_MARK
549*0f4c859eSApple OSS Distributions #pragma mark C++ Allocators & Deallocators
550*0f4c859eSApple OSS Distributions #endif /* PRAGMA_MARK */
551*0f4c859eSApple OSS Distributions /*********************************************************************
552*0f4c859eSApple OSS Distributions * C++ Allocators & Deallocators
553*0f4c859eSApple OSS Distributions *********************************************************************/
554*0f4c859eSApple OSS Distributions __typed_allocators_ignore_push
555*0f4c859eSApple OSS Distributions
556*0f4c859eSApple OSS Distributions void *
operator new(size_t size)557*0f4c859eSApple OSS Distributions operator new(size_t size)
558*0f4c859eSApple OSS Distributions {
559*0f4c859eSApple OSS Distributions assert(size);
560*0f4c859eSApple OSS Distributions return kheap_alloc(KERN_OS_MALLOC, size,
561*0f4c859eSApple OSS Distributions Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
562*0f4c859eSApple OSS Distributions }
563*0f4c859eSApple OSS Distributions
564*0f4c859eSApple OSS Distributions void
operator delete(void * addr)565*0f4c859eSApple OSS Distributions operator delete(void * addr)
566*0f4c859eSApple OSS Distributions #if __cplusplus >= 201103L
567*0f4c859eSApple OSS Distributions noexcept
568*0f4c859eSApple OSS Distributions #endif
569*0f4c859eSApple OSS Distributions {
570*0f4c859eSApple OSS Distributions kheap_free_addr(KERN_OS_MALLOC, addr);
571*0f4c859eSApple OSS Distributions return;
572*0f4c859eSApple OSS Distributions }
573*0f4c859eSApple OSS Distributions
574*0f4c859eSApple OSS Distributions void *
operator new[](unsigned long size)575*0f4c859eSApple OSS Distributions operator new[](unsigned long size)
576*0f4c859eSApple OSS Distributions {
577*0f4c859eSApple OSS Distributions return kheap_alloc(KERN_OS_MALLOC, size,
578*0f4c859eSApple OSS Distributions Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
579*0f4c859eSApple OSS Distributions }
580*0f4c859eSApple OSS Distributions
581*0f4c859eSApple OSS Distributions void
operator delete[](void * ptr)582*0f4c859eSApple OSS Distributions operator delete[](void * ptr)
583*0f4c859eSApple OSS Distributions #if __cplusplus >= 201103L
584*0f4c859eSApple OSS Distributions noexcept
585*0f4c859eSApple OSS Distributions #endif
586*0f4c859eSApple OSS Distributions {
587*0f4c859eSApple OSS Distributions if (ptr) {
588*0f4c859eSApple OSS Distributions #if KASAN
589*0f4c859eSApple OSS Distributions /*
590*0f4c859eSApple OSS Distributions * Unpoison the C++ array cookie inserted (but not removed) by the
591*0f4c859eSApple OSS Distributions * compiler on new[].
592*0f4c859eSApple OSS Distributions */
593*0f4c859eSApple OSS Distributions kasan_unpoison_cxx_array_cookie(ptr);
594*0f4c859eSApple OSS Distributions #endif
595*0f4c859eSApple OSS Distributions kheap_free_addr(KERN_OS_MALLOC, ptr);
596*0f4c859eSApple OSS Distributions }
597*0f4c859eSApple OSS Distributions return;
598*0f4c859eSApple OSS Distributions }
599*0f4c859eSApple OSS Distributions
600*0f4c859eSApple OSS Distributions #if __cplusplus >= 201103L
601*0f4c859eSApple OSS Distributions
602*0f4c859eSApple OSS Distributions void
operator delete(void * addr,size_t sz)603*0f4c859eSApple OSS Distributions operator delete(void * addr, size_t sz) noexcept
604*0f4c859eSApple OSS Distributions {
605*0f4c859eSApple OSS Distributions kheap_free(KERN_OS_MALLOC, addr, sz);
606*0f4c859eSApple OSS Distributions }
607*0f4c859eSApple OSS Distributions
608*0f4c859eSApple OSS Distributions void
operator delete[](void * addr,size_t sz)609*0f4c859eSApple OSS Distributions operator delete[](void * addr, size_t sz) noexcept
610*0f4c859eSApple OSS Distributions {
611*0f4c859eSApple OSS Distributions if (addr) {
612*0f4c859eSApple OSS Distributions kheap_free(KERN_OS_MALLOC, addr, sz);
613*0f4c859eSApple OSS Distributions }
614*0f4c859eSApple OSS Distributions }
615*0f4c859eSApple OSS Distributions
616*0f4c859eSApple OSS Distributions __typed_allocators_ignore_pop
617*0f4c859eSApple OSS Distributions
618*0f4c859eSApple OSS Distributions #endif /* __cplusplus >= 201103L */
619*0f4c859eSApple OSS Distributions
620*0f4c859eSApple OSS Distributions /* PR-6481964 - The compiler is going to check for size overflows in calls to
621*0f4c859eSApple OSS Distributions * new[], and if there is an overflow, it will call __throw_length_error.
622*0f4c859eSApple OSS Distributions * This is an unrecoverable error by the C++ standard, so we must panic here.
623*0f4c859eSApple OSS Distributions *
624*0f4c859eSApple OSS Distributions * We have to put the function inside the std namespace because of how the
625*0f4c859eSApple OSS Distributions * compiler expects the name to be mangled.
626*0f4c859eSApple OSS Distributions */
627*0f4c859eSApple OSS Distributions namespace std {
628*0f4c859eSApple OSS Distributions void __dead2
__throw_length_error(const char * msg __unused)629*0f4c859eSApple OSS Distributions __throw_length_error(const char *msg __unused)
630*0f4c859eSApple OSS Distributions {
631*0f4c859eSApple OSS Distributions panic("Size of array created by new[] has overflowed");
632*0f4c859eSApple OSS Distributions }
633*0f4c859eSApple OSS Distributions };
634