1*0f4c859eSApple OSS Distributions /*
2*0f4c859eSApple OSS Distributions * Copyright (c) 2023 Apple Computer, Inc. All rights reserved.
3*0f4c859eSApple OSS Distributions *
4*0f4c859eSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*0f4c859eSApple OSS Distributions *
6*0f4c859eSApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*0f4c859eSApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*0f4c859eSApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*0f4c859eSApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*0f4c859eSApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*0f4c859eSApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*0f4c859eSApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*0f4c859eSApple OSS Distributions * terms of an Apple operating system software license agreement.
14*0f4c859eSApple OSS Distributions *
15*0f4c859eSApple OSS Distributions * Please obtain a copy of the License at
16*0f4c859eSApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*0f4c859eSApple OSS Distributions *
18*0f4c859eSApple OSS Distributions * The Original Code and all software distributed under the License are
19*0f4c859eSApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*0f4c859eSApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*0f4c859eSApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*0f4c859eSApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*0f4c859eSApple OSS Distributions * Please see the License for the specific language governing rights and
24*0f4c859eSApple OSS Distributions * limitations under the License.
25*0f4c859eSApple OSS Distributions *
26*0f4c859eSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*0f4c859eSApple OSS Distributions */
28*0f4c859eSApple OSS Distributions
29*0f4c859eSApple OSS Distributions #include <darwintest.h>
30*0f4c859eSApple OSS Distributions #include <stdlib.h>
31*0f4c859eSApple OSS Distributions #include <unistd.h>
32*0f4c859eSApple OSS Distributions #include <mach/exception_types.h>
33*0f4c859eSApple OSS Distributions #include <sys/wait.h>
34*0f4c859eSApple OSS Distributions
35*0f4c859eSApple OSS Distributions #include "exc_helpers.h"
36*0f4c859eSApple OSS Distributions #include "test_utils.h"
37*0f4c859eSApple OSS Distributions
38*0f4c859eSApple OSS Distributions T_GLOBAL_META(
39*0f4c859eSApple OSS Distributions T_META_NAMESPACE("xnu.arm"),
40*0f4c859eSApple OSS Distributions T_META_RADAR_COMPONENT_NAME("xnu"),
41*0f4c859eSApple OSS Distributions T_META_RADAR_COMPONENT_VERSION("arm"),
42*0f4c859eSApple OSS Distributions T_META_OWNER("ghackmann"),
43*0f4c859eSApple OSS Distributions T_META_REQUIRES_SYSCTL_EQ("hw.optional.ptrauth", 1),
44*0f4c859eSApple OSS Distributions T_META_IGNORECRASHES(".*pac_exception_entitlement.*"),
45*0f4c859eSApple OSS Distributions XNU_T_META_SOC_SPECIFIC
46*0f4c859eSApple OSS Distributions );
47*0f4c859eSApple OSS Distributions
48*0f4c859eSApple OSS Distributions #if __arm64e__
49*0f4c859eSApple OSS Distributions static size_t
exception_handler(mach_port_t task __unused,mach_port_t thread __unused,exception_type_t type __unused,mach_exception_data_t codes __unused)50*0f4c859eSApple OSS Distributions exception_handler(mach_port_t task __unused, mach_port_t thread __unused,
51*0f4c859eSApple OSS Distributions exception_type_t type __unused, mach_exception_data_t codes __unused)
52*0f4c859eSApple OSS Distributions {
53*0f4c859eSApple OSS Distributions T_ASSERT_FAIL("kernel ran exception handler instead of terminating process");
54*0f4c859eSApple OSS Distributions }
55*0f4c859eSApple OSS Distributions
56*0f4c859eSApple OSS Distributions /*
57*0f4c859eSApple OSS Distributions * Real-world software should use ptrauth.h when it needs to manually sign or
58*0f4c859eSApple OSS Distributions * auth pointers. But for testing purposes we need clang to emit specific
59*0f4c859eSApple OSS Distributions * ptrauth instructions, so we use inline asm here instead.
60*0f4c859eSApple OSS Distributions *
61*0f4c859eSApple OSS Distributions * Likewise clang would normally combine the "naked" auth and brk testcases as
62*0f4c859eSApple OSS Distributions * part of a sequence like:
63*0f4c859eSApple OSS Distributions *
64*0f4c859eSApple OSS Distributions * output = auth(...);
65*0f4c859eSApple OSS Distributions * if (output is poisoned) {
66*0f4c859eSApple OSS Distributions * brk(PTRAUTH_FAILURE_COMMENT);
67*0f4c859eSApple OSS Distributions * }
68*0f4c859eSApple OSS Distributions *
69*0f4c859eSApple OSS Distributions * On auth failure, CPUs that implement FEAT_FPAC will trap immediately at the
70*0f4c859eSApple OSS Distributions * auth instruction, and CPUs without FEAT_FPAC will trap at the later brk
71*0f4c859eSApple OSS Distributions * instruction. But again, for testing purposes we want these to be two
72*0f4c859eSApple OSS Distributions * discrete cases. (On FPAC-enabled CPUs, the kernel should treat *both* traps
73*0f4c859eSApple OSS Distributions * as ptrauth failure, even if we don't expect the latter to be reachable in
74*0f4c859eSApple OSS Distributions * real-world software.)
75*0f4c859eSApple OSS Distributions */
76*0f4c859eSApple OSS Distributions
77*0f4c859eSApple OSS Distributions static void
naked_auth(void)78*0f4c859eSApple OSS Distributions naked_auth(void)
79*0f4c859eSApple OSS Distributions {
80*0f4c859eSApple OSS Distributions asm volatile (
81*0f4c859eSApple OSS Distributions "mov x0, #0" "\n"
82*0f4c859eSApple OSS Distributions "paciza x0" "\n"
83*0f4c859eSApple OSS Distributions "eor x0, x0, (1 << 63)" "\n"
84*0f4c859eSApple OSS Distributions "autiza x0"
85*0f4c859eSApple OSS Distributions :
86*0f4c859eSApple OSS Distributions :
87*0f4c859eSApple OSS Distributions : "x0"
88*0f4c859eSApple OSS Distributions );
89*0f4c859eSApple OSS Distributions }
90*0f4c859eSApple OSS Distributions
91*0f4c859eSApple OSS Distributions static void
ptrauth_brk(void)92*0f4c859eSApple OSS Distributions ptrauth_brk(void)
93*0f4c859eSApple OSS Distributions {
94*0f4c859eSApple OSS Distributions asm volatile ("brk 0xc470");
95*0f4c859eSApple OSS Distributions }
96*0f4c859eSApple OSS Distributions
97*0f4c859eSApple OSS Distributions static void
combined_branch_auth(void)98*0f4c859eSApple OSS Distributions combined_branch_auth(void)
99*0f4c859eSApple OSS Distributions {
100*0f4c859eSApple OSS Distributions asm volatile (
101*0f4c859eSApple OSS Distributions "adr x0, 1f" "\n"
102*0f4c859eSApple OSS Distributions "paciza x0" "\n"
103*0f4c859eSApple OSS Distributions "eor x0, x0, (1 << 63)" "\n"
104*0f4c859eSApple OSS Distributions "braaz x0" "\n"
105*0f4c859eSApple OSS Distributions "1:"
106*0f4c859eSApple OSS Distributions :
107*0f4c859eSApple OSS Distributions :
108*0f4c859eSApple OSS Distributions : "x0"
109*0f4c859eSApple OSS Distributions );
110*0f4c859eSApple OSS Distributions }
111*0f4c859eSApple OSS Distributions
112*0f4c859eSApple OSS Distributions static void
combined_load_auth(void)113*0f4c859eSApple OSS Distributions combined_load_auth(void)
114*0f4c859eSApple OSS Distributions {
115*0f4c859eSApple OSS Distributions asm volatile (
116*0f4c859eSApple OSS Distributions "mov x0, sp" "\n"
117*0f4c859eSApple OSS Distributions "pacdza x0" "\n"
118*0f4c859eSApple OSS Distributions "eor x0, x0, (1 << 63)" "\n"
119*0f4c859eSApple OSS Distributions "ldraa x0, [x0]" "\n"
120*0f4c859eSApple OSS Distributions :
121*0f4c859eSApple OSS Distributions :
122*0f4c859eSApple OSS Distributions : "x0"
123*0f4c859eSApple OSS Distributions );
124*0f4c859eSApple OSS Distributions }
125*0f4c859eSApple OSS Distributions
126*0f4c859eSApple OSS Distributions static void
run_pac_exception_test(void (* ptrauth_failure_fn)(void))127*0f4c859eSApple OSS Distributions run_pac_exception_test(void (*ptrauth_failure_fn)(void))
128*0f4c859eSApple OSS Distributions {
129*0f4c859eSApple OSS Distributions pid_t pid = fork();
130*0f4c859eSApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(pid, "fork");
131*0f4c859eSApple OSS Distributions
132*0f4c859eSApple OSS Distributions if (pid == 0) {
133*0f4c859eSApple OSS Distributions mach_port_t exc_port = create_exception_port(EXC_MASK_BAD_ACCESS | EXC_MASK_BREAKPOINT);
134*0f4c859eSApple OSS Distributions run_exception_handler(exc_port, exception_handler);
135*0f4c859eSApple OSS Distributions
136*0f4c859eSApple OSS Distributions ptrauth_failure_fn();
137*0f4c859eSApple OSS Distributions /* ptrauth_failure_fn() should have raised an uncatchable exception */
138*0f4c859eSApple OSS Distributions T_FAIL("child ran to completion");
139*0f4c859eSApple OSS Distributions } else {
140*0f4c859eSApple OSS Distributions int status;
141*0f4c859eSApple OSS Distributions int err = waitpid(pid, &status, 0);
142*0f4c859eSApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(err, "waitpid");
143*0f4c859eSApple OSS Distributions
144*0f4c859eSApple OSS Distributions T_EXPECT_TRUE(WIFSIGNALED(status), "child terminated due to signal");
145*0f4c859eSApple OSS Distributions T_EXPECT_EQ(SIGKILL, WTERMSIG(status), "child terminated due to SIGKILL");
146*0f4c859eSApple OSS Distributions }
147*0f4c859eSApple OSS Distributions }
148*0f4c859eSApple OSS Distributions #endif
149*0f4c859eSApple OSS Distributions
150*0f4c859eSApple OSS Distributions T_DECL(pac_exception_naked_auth,
151*0f4c859eSApple OSS Distributions "Test the com.apple.private.pac.exception entitlement (naked auth failure)",
152*0f4c859eSApple OSS Distributions T_META_REQUIRES_SYSCTL_EQ("hw.optional.arm.FEAT_FPAC", 1))
153*0f4c859eSApple OSS Distributions {
154*0f4c859eSApple OSS Distributions #if __arm64e__
155*0f4c859eSApple OSS Distributions run_pac_exception_test(naked_auth);
156*0f4c859eSApple OSS Distributions #else
157*0f4c859eSApple OSS Distributions T_SKIP("Running on non-arm64e target, skipping...");
158*0f4c859eSApple OSS Distributions #endif
159*0f4c859eSApple OSS Distributions }
160*0f4c859eSApple OSS Distributions
161*0f4c859eSApple OSS Distributions
162*0f4c859eSApple OSS Distributions T_DECL(pac_exception_ptrauth_brk,
163*0f4c859eSApple OSS Distributions "Test the com.apple.private.pac.exception entitlement (brk with comment indicating ptrauth failure)")
164*0f4c859eSApple OSS Distributions {
165*0f4c859eSApple OSS Distributions #if __arm64e__
166*0f4c859eSApple OSS Distributions run_pac_exception_test(ptrauth_brk);
167*0f4c859eSApple OSS Distributions #else
168*0f4c859eSApple OSS Distributions T_SKIP("Running on non-arm64e target, skipping...");
169*0f4c859eSApple OSS Distributions #endif
170*0f4c859eSApple OSS Distributions }
171*0f4c859eSApple OSS Distributions
172*0f4c859eSApple OSS Distributions T_DECL(pac_exception_combined_branch_auth,
173*0f4c859eSApple OSS Distributions "Test the com.apple.private.pac.exception entitlement (combined branch + auth failure)")
174*0f4c859eSApple OSS Distributions {
175*0f4c859eSApple OSS Distributions #if __arm64e__
176*0f4c859eSApple OSS Distributions run_pac_exception_test(combined_branch_auth);
177*0f4c859eSApple OSS Distributions #else
178*0f4c859eSApple OSS Distributions T_SKIP("Running on non-arm64e target, skipping...");
179*0f4c859eSApple OSS Distributions #endif
180*0f4c859eSApple OSS Distributions }
181*0f4c859eSApple OSS Distributions
182*0f4c859eSApple OSS Distributions T_DECL(pac_exception_combined_load_auth,
183*0f4c859eSApple OSS Distributions "Test the com.apple.private.pac.exception entitlement (combined branch + auth failure)")
184*0f4c859eSApple OSS Distributions {
185*0f4c859eSApple OSS Distributions #if __arm64e__
186*0f4c859eSApple OSS Distributions run_pac_exception_test(combined_load_auth);
187*0f4c859eSApple OSS Distributions #else
188*0f4c859eSApple OSS Distributions T_SKIP("Running on non-arm64e target, skipping...");
189*0f4c859eSApple OSS Distributions #endif
190*0f4c859eSApple OSS Distributions }
191