xref: /xnu-10002.61.3/tests/hw_breakpoint_step_arm64.c (revision 0f4c859e951fba394238ab619495c4e1d54d0f34)
1 #ifdef T_NAMESPACE
2 #undef T_NAMESPACE
3 #endif
4 
5 #include <mach/arm/thread_status.h>
6 #include <mach/mach_traps.h>
7 #include <mach-o/dyld.h>
8 #include <mach/mach.h>
9 #include <mach/task.h>
10 
11 #include <darwintest.h>
12 #include <dispatch/dispatch.h>
13 #include <stdlib.h>
14 
15 #include <signal.h>
16 #include <spawn.h>
17 #include <spawn_private.h>
18 #include <stdatomic.h>
19 
20 #include <excserver.h>
21 #include <sys/syslimits.h>
22 
23 #define SYNC_TIMEOUT dispatch_time(DISPATCH_TIME_NOW, 10 * NSEC_PER_SEC)
24 
25 static dispatch_semaphore_t sync_sema;
26 static _Atomic bool after_kill;
27 
28 kern_return_t
catch_mach_exception_raise(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t code_count)29 catch_mach_exception_raise(mach_port_t exception_port,
30     mach_port_t thread,
31     mach_port_t task,
32     exception_type_t exception,
33     mach_exception_data_t code,
34     mach_msg_type_number_t code_count)
35 {
36 #pragma unused(exception_port, thread, task, code, code_count)
37 	if (exception == EXC_BREAKPOINT || (exception == EXC_CRASH && atomic_load_explicit(&after_kill,
38 	    memory_order_seq_cst))) {
39 		T_LOG("Received exception %d", exception);
40 		dispatch_semaphore_signal(sync_sema);
41 		return KERN_SUCCESS;
42 	}
43 
44 	T_FAIL("invalid exception type: %d", exception);
45 
46 	return KERN_FAILURE;
47 }
48 
49 kern_return_t
catch_mach_exception_raise_state(mach_port_t exception_port,exception_type_t exception,const mach_exception_data_t code,mach_msg_type_number_t code_count,int * flavor,const thread_state_t old_state,mach_msg_type_number_t old_state_count,thread_state_t new_state,mach_msg_type_number_t * new_state_count)50 catch_mach_exception_raise_state(mach_port_t exception_port,
51     exception_type_t exception,
52     const mach_exception_data_t code,
53     mach_msg_type_number_t code_count,
54     int * flavor,
55     const thread_state_t old_state,
56     mach_msg_type_number_t old_state_count,
57     thread_state_t new_state,
58     mach_msg_type_number_t * new_state_count)
59 {
60 #pragma unused(exception_port, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
61 	T_FAIL("Unsupported catch_mach_exception_raise_state");
62 	return KERN_NOT_SUPPORTED;
63 }
64 
65 kern_return_t
catch_mach_exception_raise_state_identity(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t code_count,int * flavor,thread_state_t old_state,mach_msg_type_number_t old_state_count,thread_state_t new_state,mach_msg_type_number_t * new_state_count)66 catch_mach_exception_raise_state_identity(mach_port_t exception_port,
67     mach_port_t thread,
68     mach_port_t task,
69     exception_type_t exception,
70     mach_exception_data_t code,
71     mach_msg_type_number_t code_count,
72     int * flavor,
73     thread_state_t old_state,
74     mach_msg_type_number_t old_state_count,
75     thread_state_t new_state,
76     mach_msg_type_number_t * new_state_count)
77 {
78 #pragma unused(exception_port, thread, task, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
79 	T_FAIL("Unsupported catch_mach_exception_raise_state_identity");
80 	return KERN_NOT_SUPPORTED;
81 }
82 
83 static void *
exc_handler(void * arg)84 exc_handler(void * arg)
85 {
86 #pragma unused(arg)
87 	kern_return_t kret;
88 	mach_port_t exception_port;
89 
90 	kret = mach_port_allocate(mach_task_self(), MACH_PORT_RIGHT_RECEIVE, &exception_port);
91 	if (kret != KERN_SUCCESS) {
92 		T_FAIL("mach_port_allocate: %s (%d)", mach_error_string(kret), kret);
93 	}
94 
95 	kret = mach_port_insert_right(mach_task_self(), exception_port, exception_port, MACH_MSG_TYPE_MAKE_SEND);
96 	if (kret != KERN_SUCCESS) {
97 		T_FAIL("mach_port_insert_right: %s (%d)", mach_error_string(kret), kret);
98 	}
99 
100 	kret = task_set_exception_ports(mach_task_self(), EXC_MASK_CRASH | EXC_MASK_BREAKPOINT, exception_port,
101 	    (exception_behavior_t)(EXCEPTION_DEFAULT | MACH_EXCEPTION_CODES), 0);
102 	if (kret != KERN_SUCCESS) {
103 		T_FAIL("task_set_exception_ports: %s (%d)", mach_error_string(kret), kret);
104 	}
105 
106 	dispatch_semaphore_signal(sync_sema);
107 
108 	kret = mach_msg_server(mach_exc_server, MACH_MSG_SIZE_RELIABLE, exception_port, 0);
109 	if (kret != KERN_SUCCESS) {
110 		T_FAIL("mach_msg_server: %s (%d)", mach_error_string(kret), kret);
111 	}
112 
113 	return NULL;
114 }
115 
116 T_HELPER_DECL(hw_breakpoint_helper, "hw_breakpoint_helper")
117 {
118 	while (1) {
119 		sleep(1);
120 	}
121 }
122 
123 // Single instruction step
124 // (SS bit in the MDSCR_EL1 register)
125 #define SS_ENABLE ((uint32_t)(1u))
126 
127 static void
step_thread(mach_port_name_t task,thread_t thread)128 step_thread(mach_port_name_t task, thread_t thread)
129 {
130 	kern_return_t kr;
131 
132 	arm_debug_state64_t dbg;
133 	mach_msg_type_number_t count = ARM_DEBUG_STATE64_COUNT;
134 
135 	kr = thread_get_state(thread, ARM_DEBUG_STATE64,
136 	    (thread_state_t)&dbg, &count);
137 	T_ASSERT_MACH_SUCCESS(kr, "get debug state for target thread");
138 
139 	dbg.__mdscr_el1 |= SS_ENABLE;
140 
141 	kr = thread_set_state(thread, ARM_DEBUG_STATE64,
142 	    (thread_state_t)&dbg, count);
143 	T_ASSERT_MACH_SUCCESS(kr, "set debug state for target thread");
144 
145 	kr = task_resume(task);
146 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "resume target task");
147 
148 	long err = dispatch_semaphore_wait(sync_sema, SYNC_TIMEOUT);
149 	T_QUIET; T_ASSERT_EQ(err, 0L, "dispatch_semaphore_wait timeout");
150 }
151 
152 T_DECL(hw_breakpoint_step, "Ensures that a process can be single-stepped using thread_set_state / ARM_DEBUG_STATE64", T_META_ASROOT(true),
153     T_META_OWNER("Samuel Lepetit <[email protected]>"))
154 {
155 	kern_return_t kr;
156 	pthread_t handle_thread;
157 	sync_sema = dispatch_semaphore_create(0);
158 
159 	T_ASSERT_POSIX_ZERO(pthread_create(&handle_thread, NULL, exc_handler, NULL), "pthread_create");
160 	long err = dispatch_semaphore_wait(sync_sema, SYNC_TIMEOUT);
161 	T_QUIET; T_ASSERT_EQ(err, 0L, "dispatch_semaphore_wait timeout");
162 
163 	pid_t pid;
164 	char path[PATH_MAX];
165 	uint32_t path_size = sizeof(path);
166 
167 	T_QUIET; T_ASSERT_POSIX_ZERO(_NSGetExecutablePath(path, &path_size), "_NSGetExecutablePath");
168 
169 	char *args[] = { path, "-n", "hw_breakpoint_helper", NULL };
170 	T_EXPECT_POSIX_ZERO(posix_spawn(&pid, args[0], NULL, NULL, args, NULL), "posix_spawn helper");
171 
172 	mach_port_name_t task;
173 	kr = task_for_pid(mach_task_self(), pid, &task);
174 	T_ASSERT_TRUE(kr == KERN_SUCCESS, "task_for_pid");
175 
176 	kr = task_suspend(task);
177 	T_QUIET; T_ASSERT_TRUE(kr == KERN_SUCCESS, "task_suspend");
178 
179 	thread_array_t threads = NULL;
180 	mach_msg_type_number_t thread_count;
181 	kr = task_threads(task, &threads, &thread_count);
182 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "task_threads");
183 
184 	step_thread(task, threads[0]);
185 
186 	kr = task_suspend(task);
187 	T_QUIET; T_ASSERT_TRUE(kr == KERN_SUCCESS, "task_suspend");
188 
189 	step_thread(task, threads[0]);
190 
191 	atomic_store_explicit(&after_kill, 1, memory_order_seq_cst);
192 	T_ASSERT_POSIX_ZERO(kill(pid, SIGKILL), "kill target process");
193 }
194