xref: /xnu-10002.81.5/tests/test_note_exec.c (revision 5e3eaea39dcf651e66cb99ba7d70e32cc4a99587)
1*5e3eaea3SApple OSS Distributions #include <assert.h>
2*5e3eaea3SApple OSS Distributions #include <stdio.h>
3*5e3eaea3SApple OSS Distributions #include <pthread.h>
4*5e3eaea3SApple OSS Distributions #include <signal.h>
5*5e3eaea3SApple OSS Distributions #include <unistd.h>
6*5e3eaea3SApple OSS Distributions #include <errno.h>
7*5e3eaea3SApple OSS Distributions #include <string.h>
8*5e3eaea3SApple OSS Distributions #include <sys/wait.h>
9*5e3eaea3SApple OSS Distributions #include <sys/types.h>
10*5e3eaea3SApple OSS Distributions #include <sys/time.h>
11*5e3eaea3SApple OSS Distributions #include <sys/event.h>
12*5e3eaea3SApple OSS Distributions #include <sys/ptrace.h>
13*5e3eaea3SApple OSS Distributions #include <sys/proc.h>
14*5e3eaea3SApple OSS Distributions #include <stdlib.h>
15*5e3eaea3SApple OSS Distributions #include <System/sys/codesign.h>
16*5e3eaea3SApple OSS Distributions #include <darwintest.h>
17*5e3eaea3SApple OSS Distributions 
18*5e3eaea3SApple OSS Distributions T_GLOBAL_META(T_META_NAMESPACE("xnu.note_exec"),
19*5e3eaea3SApple OSS Distributions     T_META_RADAR_COMPONENT_NAME("xnu"),
20*5e3eaea3SApple OSS Distributions     T_META_RADAR_COMPONENT_VERSION("spawn"));
21*5e3eaea3SApple OSS Distributions 
22*5e3eaea3SApple OSS Distributions static int kq;
23*5e3eaea3SApple OSS Distributions static int pid;
24*5e3eaea3SApple OSS Distributions 
25*5e3eaea3SApple OSS Distributions static void
do_exec(void)26*5e3eaea3SApple OSS Distributions do_exec(void)
27*5e3eaea3SApple OSS Distributions {
28*5e3eaea3SApple OSS Distributions 	char echo_arg[50] = "";
29*5e3eaea3SApple OSS Distributions 
30*5e3eaea3SApple OSS Distributions 	snprintf(echo_arg, sizeof(echo_arg), "Child[%d] says hello after exec", getpid());
31*5e3eaea3SApple OSS Distributions 
32*5e3eaea3SApple OSS Distributions 	char * new_argv[] = {
33*5e3eaea3SApple OSS Distributions 		"/bin/echo",
34*5e3eaea3SApple OSS Distributions 		echo_arg,
35*5e3eaea3SApple OSS Distributions 		NULL
36*5e3eaea3SApple OSS Distributions 	};
37*5e3eaea3SApple OSS Distributions 
38*5e3eaea3SApple OSS Distributions 	int ret = execv(new_argv[0], new_argv);
39*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "execv()");
40*5e3eaea3SApple OSS Distributions }
41*5e3eaea3SApple OSS Distributions 
42*5e3eaea3SApple OSS Distributions static void *
thread_wait_exec(void * arg __unused)43*5e3eaea3SApple OSS Distributions thread_wait_exec(void *arg __unused)
44*5e3eaea3SApple OSS Distributions {
45*5e3eaea3SApple OSS Distributions 	int ret;
46*5e3eaea3SApple OSS Distributions 	struct kevent64_s kev;
47*5e3eaea3SApple OSS Distributions 	int csret;
48*5e3eaea3SApple OSS Distributions 	uint32_t status = 0;
49*5e3eaea3SApple OSS Distributions 
50*5e3eaea3SApple OSS Distributions 	while (1) {
51*5e3eaea3SApple OSS Distributions 		ret = kevent64(kq, NULL, 0, &kev, 1, 0, NULL);
52*5e3eaea3SApple OSS Distributions 		if (ret == -1) {
53*5e3eaea3SApple OSS Distributions 			if (errno == EINTR) {
54*5e3eaea3SApple OSS Distributions 				continue;
55*5e3eaea3SApple OSS Distributions 			}
56*5e3eaea3SApple OSS Distributions 		}
57*5e3eaea3SApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "kevent64()");
58*5e3eaea3SApple OSS Distributions 		break;
59*5e3eaea3SApple OSS Distributions 	}
60*5e3eaea3SApple OSS Distributions 
61*5e3eaea3SApple OSS Distributions 	/* Try to get the csops of child before we print anything */
62*5e3eaea3SApple OSS Distributions 	csret = csops(pid, CS_OPS_STATUS, &status, sizeof(status));
63*5e3eaea3SApple OSS Distributions 	if (csret != 0) {
64*5e3eaea3SApple OSS Distributions 		T_QUIET; T_LOG("Child exited before parent could call csops. The race didn't happen");
65*5e3eaea3SApple OSS Distributions 		return NULL;
66*5e3eaea3SApple OSS Distributions 	}
67*5e3eaea3SApple OSS Distributions 
68*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_EQ(ret, 1, "kevent64 returned 1 event as expected");
69*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_EQ((int)kev.filter, EVFILT_PROC, "EVFILT_PROC event received");
70*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_EQ((int)kev.udata, pid, "EVFILT_PROC event received for child pid");
71*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_EQ((kev.fflags & NOTE_EXEC), NOTE_EXEC, "NOTE_EXEC event received");
72*5e3eaea3SApple OSS Distributions 
73*5e3eaea3SApple OSS Distributions 	/* Check that the platform binary bit is set */
74*5e3eaea3SApple OSS Distributions 	T_EXPECT_BITS_SET(status, CS_PLATFORM_BINARY, "CS_PLATFORM_BINARY should be set on child");
75*5e3eaea3SApple OSS Distributions 
76*5e3eaea3SApple OSS Distributions 	return NULL;
77*5e3eaea3SApple OSS Distributions }
78*5e3eaea3SApple OSS Distributions 
79*5e3eaea3SApple OSS Distributions static void
run_test(void)80*5e3eaea3SApple OSS Distributions run_test(void)
81*5e3eaea3SApple OSS Distributions {
82*5e3eaea3SApple OSS Distributions 	struct kevent64_s kev;
83*5e3eaea3SApple OSS Distributions 	int ret;
84*5e3eaea3SApple OSS Distributions 	int fd[2];
85*5e3eaea3SApple OSS Distributions 
86*5e3eaea3SApple OSS Distributions 	ret = pipe(fd);
87*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pipe()");
88*5e3eaea3SApple OSS Distributions 	close(fd[0]);
89*5e3eaea3SApple OSS Distributions 
90*5e3eaea3SApple OSS Distributions 	T_QUIET; T_LOG("Forking child");
91*5e3eaea3SApple OSS Distributions 
92*5e3eaea3SApple OSS Distributions 	pid = fork();
93*5e3eaea3SApple OSS Distributions 
94*5e3eaea3SApple OSS Distributions 	if (pid == 0) {
95*5e3eaea3SApple OSS Distributions 		char buf[10];
96*5e3eaea3SApple OSS Distributions 
97*5e3eaea3SApple OSS Distributions 		close(fd[1]);
98*5e3eaea3SApple OSS Distributions 		ret = (int)read(fd[0], buf, sizeof(buf));
99*5e3eaea3SApple OSS Distributions 		close(fd[0]);
100*5e3eaea3SApple OSS Distributions 
101*5e3eaea3SApple OSS Distributions 		do_exec();
102*5e3eaea3SApple OSS Distributions 		exit(1);
103*5e3eaea3SApple OSS Distributions 	}
104*5e3eaea3SApple OSS Distributions 
105*5e3eaea3SApple OSS Distributions 	T_QUIET; T_LOG("Setting up NOTE_EXEC Handler for child pid %d", pid);
106*5e3eaea3SApple OSS Distributions 	kq = kqueue();
107*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(kq, "kqueue()");
108*5e3eaea3SApple OSS Distributions 
109*5e3eaea3SApple OSS Distributions 	EV_SET64(&kev, pid, EVFILT_PROC, EV_ADD | EV_ENABLE,
110*5e3eaea3SApple OSS Distributions 	    NOTE_EXEC, 0, pid, 0, 0);
111*5e3eaea3SApple OSS Distributions 	ret = kevent64(kq, &kev, 1, NULL, 0, 0, NULL);
112*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "kevent64()");
113*5e3eaea3SApple OSS Distributions 
114*5e3eaea3SApple OSS Distributions 	pthread_t thread;
115*5e3eaea3SApple OSS Distributions 	ret = pthread_create(&thread, NULL, thread_wait_exec, NULL);
116*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_create()");
117*5e3eaea3SApple OSS Distributions 
118*5e3eaea3SApple OSS Distributions 	T_QUIET; T_LOG("Signalling child to call exec");
119*5e3eaea3SApple OSS Distributions 	close(fd[1]);
120*5e3eaea3SApple OSS Distributions 
121*5e3eaea3SApple OSS Distributions 	T_QUIET; T_LOG("Waiting for child to exit");
122*5e3eaea3SApple OSS Distributions 	pid = waitpid(pid, NULL, 0);
123*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(pid, "waitpid()");
124*5e3eaea3SApple OSS Distributions 
125*5e3eaea3SApple OSS Distributions 	T_QUIET; T_LOG("Waiting for note exec thread to exit");
126*5e3eaea3SApple OSS Distributions 	ret = pthread_join(thread, NULL);
127*5e3eaea3SApple OSS Distributions 	T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_join()");
128*5e3eaea3SApple OSS Distributions 
129*5e3eaea3SApple OSS Distributions 	close(kq);
130*5e3eaea3SApple OSS Distributions }
131*5e3eaea3SApple OSS Distributions 
132*5e3eaea3SApple OSS Distributions T_DECL(test_note_exec, "test NOTE_EXEC race with setting csops") {
133*5e3eaea3SApple OSS Distributions 	T_QUIET; T_LOG("Testing race for NOTE_EXEC with csops");
134*5e3eaea3SApple OSS Distributions 
135*5e3eaea3SApple OSS Distributions 	for (int i = 0; i < 100; i++) {
136*5e3eaea3SApple OSS Distributions 		T_QUIET; T_LOG("Running iteration %d", i);
137*5e3eaea3SApple OSS Distributions 		run_test();
138*5e3eaea3SApple OSS Distributions 	}
139*5e3eaea3SApple OSS Distributions 	T_END;
140*5e3eaea3SApple OSS Distributions }
141