xref: /xnu-11215.1.10/tests/imm_pinned_control_port.c (revision 8d741a5de7ff4191bf97d57b9f54c2f6d4a15585)
1*8d741a5dSApple OSS Distributions #include <stdio.h>
2*8d741a5dSApple OSS Distributions #include <stdlib.h>
3*8d741a5dSApple OSS Distributions #include <unistd.h>
4*8d741a5dSApple OSS Distributions #include <darwintest.h>
5*8d741a5dSApple OSS Distributions #include <mach/mach.h>
6*8d741a5dSApple OSS Distributions #include <mach/mach_vm.h>
7*8d741a5dSApple OSS Distributions #include <sys/sysctl.h>
8*8d741a5dSApple OSS Distributions #include <spawn.h>
9*8d741a5dSApple OSS Distributions #include <signal.h>
10*8d741a5dSApple OSS Distributions #include <TargetConditionals.h>
11*8d741a5dSApple OSS Distributions #include "excserver_protect.h"
12*8d741a5dSApple OSS Distributions 
13*8d741a5dSApple OSS Distributions #define MAX_ARGV 3
14*8d741a5dSApple OSS Distributions #define EXC_CODE_SHIFT 32
15*8d741a5dSApple OSS Distributions #define EXC_GUARD_TYPE_SHIFT 29
16*8d741a5dSApple OSS Distributions #define MAX_TEST_NUM 21
17*8d741a5dSApple OSS Distributions 
18*8d741a5dSApple OSS Distributions #define TASK_EXC_GUARD_MP_DELIVER 0x10
19*8d741a5dSApple OSS Distributions 
20*8d741a5dSApple OSS Distributions extern char **environ;
21*8d741a5dSApple OSS Distributions static uint64_t exception_code = 0;
22*8d741a5dSApple OSS Distributions static exception_type_t exception_taken = 0;
23*8d741a5dSApple OSS Distributions 
24*8d741a5dSApple OSS Distributions #define IKOT_TASK_CONTROL               2
25*8d741a5dSApple OSS Distributions 
26*8d741a5dSApple OSS Distributions #ifndef kGUARD_EXC_INVALID_OPTIONS
27*8d741a5dSApple OSS Distributions #define kGUARD_EXC_INVALID_OPTIONS 3
28*8d741a5dSApple OSS Distributions #endif
29*8d741a5dSApple OSS Distributions 
30*8d741a5dSApple OSS Distributions /*
31*8d741a5dSApple OSS Distributions  * This test verifies behaviors of immovable/pinned task/thread ports.
32*8d741a5dSApple OSS Distributions  *
33*8d741a5dSApple OSS Distributions  * 1. Compare and verifies port names of mach_{task, thread}_self(),
34*8d741a5dSApple OSS Distributions  * {TASK, THREAD}_KERNEL_PORT, and ports returned from task_threads()
35*8d741a5dSApple OSS Distributions  * and processor_set_tasks().
36*8d741a5dSApple OSS Distributions  * 2. Make sure correct exceptions are raised resulting from moving immovable
37*8d741a5dSApple OSS Distributions  * task/thread control, read and inspect ports.
38*8d741a5dSApple OSS Distributions  * 3. Make sure correct exceptions are raised resulting from deallocating pinned
39*8d741a5dSApple OSS Distributions  * task/thread control ports.
40*8d741a5dSApple OSS Distributions  * 4. Make sure immovable ports cannot be stashed:
41*8d741a5dSApple OSS Distributions  * rdar://70585367 (Disallow immovable port stashing with *_set_special_port() and mach_port_register())
42*8d741a5dSApple OSS Distributions  */
43*8d741a5dSApple OSS Distributions T_GLOBAL_META(
44*8d741a5dSApple OSS Distributions 	T_META_NAMESPACE("xnu.ipc"),
45*8d741a5dSApple OSS Distributions 	T_META_RADAR_COMPONENT_NAME("xnu"),
46*8d741a5dSApple OSS Distributions 	T_META_RADAR_COMPONENT_VERSION("IPC"),
47*8d741a5dSApple OSS Distributions 	T_META_RUN_CONCURRENTLY(TRUE));
48*8d741a5dSApple OSS Distributions 
49*8d741a5dSApple OSS Distributions static uint64_t soft_exception_code[] = {
50*8d741a5dSApple OSS Distributions 	EXC_GUARD, // Soft crash delivered as EXC_CORPSE_NOTIFY
51*8d741a5dSApple OSS Distributions 	EXC_GUARD,
52*8d741a5dSApple OSS Distributions 	EXC_GUARD,
53*8d741a5dSApple OSS Distributions 	EXC_GUARD,
54*8d741a5dSApple OSS Distributions 	EXC_GUARD,
55*8d741a5dSApple OSS Distributions 	EXC_GUARD,
56*8d741a5dSApple OSS Distributions 	EXC_GUARD,
57*8d741a5dSApple OSS Distributions 
58*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
59*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
60*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
61*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
62*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
63*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
64*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
65*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
66*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
67*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
68*8d741a5dSApple OSS Distributions 
69*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
70*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
71*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
72*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
73*8d741a5dSApple OSS Distributions };
74*8d741a5dSApple OSS Distributions 
75*8d741a5dSApple OSS Distributions static uint64_t hard_exception_code[] = {
76*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
77*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
78*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
79*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
80*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
81*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
82*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_MOD_REFS,
83*8d741a5dSApple OSS Distributions 
84*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
85*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
86*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
87*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
88*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
89*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
90*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
91*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
92*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
93*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_IMMOVABLE,
94*8d741a5dSApple OSS Distributions 
95*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
96*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
97*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
98*8d741a5dSApple OSS Distributions 	(GUARD_TYPE_MACH_PORT << EXC_GUARD_TYPE_SHIFT) | kGUARD_EXC_INVALID_OPTIONS,
99*8d741a5dSApple OSS Distributions };
100*8d741a5dSApple OSS Distributions 
101*8d741a5dSApple OSS Distributions kern_return_t
catch_mach_exception_raise_state(mach_port_t exception_port,exception_type_t exception,const mach_exception_data_t code,mach_msg_type_number_t code_count,int * flavor,const thread_state_t old_state,mach_msg_type_number_t old_state_count,thread_state_t new_state,mach_msg_type_number_t * new_state_count)102*8d741a5dSApple OSS Distributions catch_mach_exception_raise_state(mach_port_t exception_port,
103*8d741a5dSApple OSS Distributions     exception_type_t exception,
104*8d741a5dSApple OSS Distributions     const mach_exception_data_t code,
105*8d741a5dSApple OSS Distributions     mach_msg_type_number_t code_count,
106*8d741a5dSApple OSS Distributions     int * flavor,
107*8d741a5dSApple OSS Distributions     const thread_state_t old_state,
108*8d741a5dSApple OSS Distributions     mach_msg_type_number_t old_state_count,
109*8d741a5dSApple OSS Distributions     thread_state_t new_state,
110*8d741a5dSApple OSS Distributions     mach_msg_type_number_t * new_state_count)
111*8d741a5dSApple OSS Distributions {
112*8d741a5dSApple OSS Distributions #pragma unused(exception_port, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
113*8d741a5dSApple OSS Distributions 	T_FAIL("Unsupported catch_mach_exception_raise_state");
114*8d741a5dSApple OSS Distributions 	return KERN_NOT_SUPPORTED;
115*8d741a5dSApple OSS Distributions }
116*8d741a5dSApple OSS Distributions 
117*8d741a5dSApple OSS Distributions kern_return_t
catch_mach_exception_raise_identity_protected(mach_port_t exception_port,uint64_t thread_id,mach_port_t task_id_token,exception_type_t exception,mach_exception_data_t codes,mach_msg_type_number_t codeCnt)118*8d741a5dSApple OSS Distributions catch_mach_exception_raise_identity_protected(
119*8d741a5dSApple OSS Distributions 	mach_port_t               exception_port,
120*8d741a5dSApple OSS Distributions 	uint64_t                  thread_id,
121*8d741a5dSApple OSS Distributions 	mach_port_t               task_id_token,
122*8d741a5dSApple OSS Distributions 	exception_type_t          exception,
123*8d741a5dSApple OSS Distributions 	mach_exception_data_t     codes,
124*8d741a5dSApple OSS Distributions 	mach_msg_type_number_t    codeCnt)
125*8d741a5dSApple OSS Distributions {
126*8d741a5dSApple OSS Distributions #pragma unused(exception_port, codeCnt)
127*8d741a5dSApple OSS Distributions 	task_t task;
128*8d741a5dSApple OSS Distributions 	pid_t pid;
129*8d741a5dSApple OSS Distributions 	kern_return_t kr = task_identity_token_get_task_port(task_id_token, TASK_FLAVOR_READ, &task);
130*8d741a5dSApple OSS Distributions 	T_ASSERT_MACH_SUCCESS(kr, "task_identity_token_get_task_port");
131*8d741a5dSApple OSS Distributions 	kr = pid_for_task(task, &pid);
132*8d741a5dSApple OSS Distributions 	T_ASSERT_MACH_SUCCESS(kr, "pid_for_task");
133*8d741a5dSApple OSS Distributions 	T_LOG("Crashing child pid: %d, continuing...\n", pid);
134*8d741a5dSApple OSS Distributions 
135*8d741a5dSApple OSS Distributions 	kr = mach_port_deallocate(mach_task_self(), task);
136*8d741a5dSApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kr, "mach_port_deallocate");
137*8d741a5dSApple OSS Distributions 
138*8d741a5dSApple OSS Distributions 	T_ASSERT_GT_UINT(codeCnt, 0, "CodeCnt");
139*8d741a5dSApple OSS Distributions 	T_LOG("Caught exception type: %d code: 0x%llx", exception, (uint64_t)codes[0]);
140*8d741a5dSApple OSS Distributions 	if (exception == EXC_GUARD || exception == EXC_CORPSE_NOTIFY) {
141*8d741a5dSApple OSS Distributions 		exception_taken = exception;
142*8d741a5dSApple OSS Distributions 		exception_code = (uint64_t)codes[0];
143*8d741a5dSApple OSS Distributions 	} else {
144*8d741a5dSApple OSS Distributions 		T_FAIL("Unexpected exception");
145*8d741a5dSApple OSS Distributions 	}
146*8d741a5dSApple OSS Distributions 	return KERN_SUCCESS;
147*8d741a5dSApple OSS Distributions }
148*8d741a5dSApple OSS Distributions 
149*8d741a5dSApple OSS Distributions kern_return_t
catch_mach_exception_raise_state_identity(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t code_count,int * flavor,thread_state_t old_state,mach_msg_type_number_t old_state_count,thread_state_t new_state,mach_msg_type_number_t * new_state_count)150*8d741a5dSApple OSS Distributions catch_mach_exception_raise_state_identity(mach_port_t exception_port,
151*8d741a5dSApple OSS Distributions     mach_port_t thread,
152*8d741a5dSApple OSS Distributions     mach_port_t task,
153*8d741a5dSApple OSS Distributions     exception_type_t exception,
154*8d741a5dSApple OSS Distributions     mach_exception_data_t code,
155*8d741a5dSApple OSS Distributions     mach_msg_type_number_t code_count,
156*8d741a5dSApple OSS Distributions     int * flavor,
157*8d741a5dSApple OSS Distributions     thread_state_t old_state,
158*8d741a5dSApple OSS Distributions     mach_msg_type_number_t old_state_count,
159*8d741a5dSApple OSS Distributions     thread_state_t new_state,
160*8d741a5dSApple OSS Distributions     mach_msg_type_number_t * new_state_count)
161*8d741a5dSApple OSS Distributions {
162*8d741a5dSApple OSS Distributions #pragma unused(exception_port, thread, task, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
163*8d741a5dSApple OSS Distributions 	T_FAIL("Unsupported catch_mach_exception_raise_state_identity");
164*8d741a5dSApple OSS Distributions 	return KERN_NOT_SUPPORTED;
165*8d741a5dSApple OSS Distributions }
166*8d741a5dSApple OSS Distributions 
167*8d741a5dSApple OSS Distributions kern_return_t
catch_mach_exception_raise(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t code_count)168*8d741a5dSApple OSS Distributions catch_mach_exception_raise(mach_port_t exception_port,
169*8d741a5dSApple OSS Distributions     mach_port_t thread,
170*8d741a5dSApple OSS Distributions     mach_port_t task,
171*8d741a5dSApple OSS Distributions     exception_type_t exception,
172*8d741a5dSApple OSS Distributions     mach_exception_data_t code,
173*8d741a5dSApple OSS Distributions     mach_msg_type_number_t code_count)
174*8d741a5dSApple OSS Distributions {
175*8d741a5dSApple OSS Distributions #pragma unused(exception_port, thread, task, exception, code, code_count, flavor, old_state, old_state_count, new_state, new_state_count)
176*8d741a5dSApple OSS Distributions 	T_FAIL("Unsupported catch_mach_exception_raise_state_identity");
177*8d741a5dSApple OSS Distributions 	return KERN_NOT_SUPPORTED;
178*8d741a5dSApple OSS Distributions }
179*8d741a5dSApple OSS Distributions 
180*8d741a5dSApple OSS Distributions static void *
exception_server_thread(void * arg)181*8d741a5dSApple OSS Distributions exception_server_thread(void *arg)
182*8d741a5dSApple OSS Distributions {
183*8d741a5dSApple OSS Distributions 	kern_return_t kr;
184*8d741a5dSApple OSS Distributions 	mach_port_t exc_port = *(mach_port_t *)arg;
185*8d741a5dSApple OSS Distributions 
186*8d741a5dSApple OSS Distributions 	/* Handle exceptions on exc_port */
187*8d741a5dSApple OSS Distributions 	kr = mach_msg_server_once(mach_exc_server, 4096, exc_port, 0);
188*8d741a5dSApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kr, "mach_msg_server_once");
189*8d741a5dSApple OSS Distributions 
190*8d741a5dSApple OSS Distributions 	return NULL;
191*8d741a5dSApple OSS Distributions }
192*8d741a5dSApple OSS Distributions 
193*8d741a5dSApple OSS Distributions static mach_port_t
alloc_exception_port(void)194*8d741a5dSApple OSS Distributions alloc_exception_port(void)
195*8d741a5dSApple OSS Distributions {
196*8d741a5dSApple OSS Distributions 	kern_return_t kret;
197*8d741a5dSApple OSS Distributions 	mach_port_t exc_port = MACH_PORT_NULL;
198*8d741a5dSApple OSS Distributions 	mach_port_t task = mach_task_self();
199*8d741a5dSApple OSS Distributions 
200*8d741a5dSApple OSS Distributions 	kret = mach_port_allocate(task, MACH_PORT_RIGHT_RECEIVE, &exc_port);
201*8d741a5dSApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kret, "mach_port_allocate exc_port");
202*8d741a5dSApple OSS Distributions 
203*8d741a5dSApple OSS Distributions 	kret = mach_port_insert_right(task, exc_port, exc_port, MACH_MSG_TYPE_MAKE_SEND);
204*8d741a5dSApple OSS Distributions 	T_QUIET; T_EXPECT_MACH_SUCCESS(kret, "mach_port_insert_right exc_port");
205*8d741a5dSApple OSS Distributions 
206*8d741a5dSApple OSS Distributions 	return exc_port;
207*8d741a5dSApple OSS Distributions }
208*8d741a5dSApple OSS Distributions 
209*8d741a5dSApple OSS Distributions static void
test_immovable_port_stashing(void)210*8d741a5dSApple OSS Distributions test_immovable_port_stashing(void)
211*8d741a5dSApple OSS Distributions {
212*8d741a5dSApple OSS Distributions 	kern_return_t kr;
213*8d741a5dSApple OSS Distributions 	mach_port_t port;
214*8d741a5dSApple OSS Distributions 
215*8d741a5dSApple OSS Distributions 	kr = task_set_special_port(mach_task_self(), TASK_BOOTSTRAP_PORT, mach_task_self());
216*8d741a5dSApple OSS Distributions 	T_EXPECT_EQ(kr, KERN_INVALID_RIGHT, "should disallow task_set_special_port() with immovable port");
217*8d741a5dSApple OSS Distributions 
218*8d741a5dSApple OSS Distributions 	kr = thread_set_special_port(mach_thread_self(), THREAD_KERNEL_PORT, mach_thread_self());
219*8d741a5dSApple OSS Distributions 	T_EXPECT_EQ(kr, KERN_INVALID_RIGHT, "should disallow task_set_special_port() with immovable port");
220*8d741a5dSApple OSS Distributions 
221*8d741a5dSApple OSS Distributions 	mach_port_t stash[1] = {mach_task_self()};
222*8d741a5dSApple OSS Distributions 	kr = mach_ports_register(mach_task_self(), stash, 1);
223*8d741a5dSApple OSS Distributions 	T_EXPECT_EQ(kr, KERN_INVALID_RIGHT, "should disallow mach_ports_register() with immovable port");
224*8d741a5dSApple OSS Distributions 
225*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(mach_port_allocate(mach_task_self(), MACH_PORT_RIGHT_RECEIVE, &port), "mach_port_allocate");
226*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(mach_port_insert_right(mach_task_self(), port, port, MACH_MSG_TYPE_MAKE_SEND), "mach_port_insert_right");
227*8d741a5dSApple OSS Distributions 
228*8d741a5dSApple OSS Distributions 	stash[0] = port;
229*8d741a5dSApple OSS Distributions 	kr = mach_ports_register(mach_task_self(), stash, 1);
230*8d741a5dSApple OSS Distributions 	T_EXPECT_MACH_SUCCESS(kr, "mach_ports_register() should succeed with movable port");
231*8d741a5dSApple OSS Distributions }
232*8d741a5dSApple OSS Distributions 
233*8d741a5dSApple OSS Distributions static void
test_task_thread_port_values(void)234*8d741a5dSApple OSS Distributions test_task_thread_port_values(void)
235*8d741a5dSApple OSS Distributions {
236*8d741a5dSApple OSS Distributions 	T_LOG("Compare various task/thread control port values\n");
237*8d741a5dSApple OSS Distributions 	kern_return_t kr;
238*8d741a5dSApple OSS Distributions 	mach_port_t port, th_self;
239*8d741a5dSApple OSS Distributions 	thread_array_t threadList;
240*8d741a5dSApple OSS Distributions 	mach_msg_type_number_t threadCount = 0;
241*8d741a5dSApple OSS Distributions 	boolean_t found_self = false;
242*8d741a5dSApple OSS Distributions 	processor_set_name_array_t psets;
243*8d741a5dSApple OSS Distributions 	processor_set_t        pset_priv;
244*8d741a5dSApple OSS Distributions 	task_array_t taskList;
245*8d741a5dSApple OSS Distributions 	mach_msg_type_number_t pcnt = 0, tcnt = 0;
246*8d741a5dSApple OSS Distributions 	mach_port_t host = mach_host_self();
247*8d741a5dSApple OSS Distributions 
248*8d741a5dSApple OSS Distributions 	/* Compare with task/thread_get_special_port() */
249*8d741a5dSApple OSS Distributions 	kr = task_get_special_port(mach_task_self(), TASK_KERNEL_PORT, &port);
250*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "task_get_special_port() - TASK_KERNEL_PORT");
251*8d741a5dSApple OSS Distributions 	T_EXPECT_NE(port, mach_task_self(), "TASK_KERNEL_PORT should not match mach_task_self()");
252*8d741a5dSApple OSS Distributions 	mach_port_deallocate(mach_task_self(), port);
253*8d741a5dSApple OSS Distributions 
254*8d741a5dSApple OSS Distributions 	kr = task_for_pid(mach_task_self(), getpid(), &port);
255*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "task_for_pid()");
256*8d741a5dSApple OSS Distributions 	T_EXPECT_EQ(port, mach_task_self(), "task_for_pid(self) should match mach_task_self()");
257*8d741a5dSApple OSS Distributions 	mach_port_deallocate(mach_task_self(), port);
258*8d741a5dSApple OSS Distributions 
259*8d741a5dSApple OSS Distributions 	th_self = mach_thread_self();
260*8d741a5dSApple OSS Distributions 	kr = thread_get_special_port(th_self, THREAD_KERNEL_PORT, &port);
261*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "thread_get_special_port() - THREAD_KERNEL_PORT");
262*8d741a5dSApple OSS Distributions 	T_EXPECT_NE(port, th_self, "THREAD_KERNEL_PORT should not match mach_thread_self()");
263*8d741a5dSApple OSS Distributions 	mach_port_deallocate(mach_task_self(), port);
264*8d741a5dSApple OSS Distributions 
265*8d741a5dSApple OSS Distributions 	/* Make sure task_threads() return immovable thread ports */
266*8d741a5dSApple OSS Distributions 	kr = task_threads(mach_task_self(), &threadList, &threadCount);
267*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "task_threads()");
268*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_GE(threadCount, 1, "should have at least 1 thread");
269*8d741a5dSApple OSS Distributions 
270*8d741a5dSApple OSS Distributions 	for (size_t i = 0; i < threadCount; i++) {
271*8d741a5dSApple OSS Distributions 		if (th_self == threadList[i]) { /* th_self is immovable */
272*8d741a5dSApple OSS Distributions 			found_self = true;
273*8d741a5dSApple OSS Distributions 			break;
274*8d741a5dSApple OSS Distributions 		}
275*8d741a5dSApple OSS Distributions 	}
276*8d741a5dSApple OSS Distributions 
277*8d741a5dSApple OSS Distributions 	T_EXPECT_TRUE(found_self, "task_threads() should return immovable thread self");
278*8d741a5dSApple OSS Distributions 
279*8d741a5dSApple OSS Distributions 	for (size_t i = 0; i < threadCount; i++) {
280*8d741a5dSApple OSS Distributions 		mach_port_deallocate(mach_task_self(), threadList[i]);
281*8d741a5dSApple OSS Distributions 	}
282*8d741a5dSApple OSS Distributions 
283*8d741a5dSApple OSS Distributions 	if (threadCount > 0) {
284*8d741a5dSApple OSS Distributions 		mach_vm_deallocate(mach_task_self(),
285*8d741a5dSApple OSS Distributions 		    (mach_vm_address_t)threadList,
286*8d741a5dSApple OSS Distributions 		    threadCount * sizeof(mach_port_t));
287*8d741a5dSApple OSS Distributions 	}
288*8d741a5dSApple OSS Distributions 
289*8d741a5dSApple OSS Distributions 	mach_port_deallocate(mach_task_self(), th_self);
290*8d741a5dSApple OSS Distributions 
291*8d741a5dSApple OSS Distributions 	/* Make sure processor_set_tasks() return immovable task self */
292*8d741a5dSApple OSS Distributions 	kr = host_processor_sets(host, &psets, &pcnt);
293*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "host_processor_sets");
294*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_GE(pcnt, 1, "should have at least 1 processor set");
295*8d741a5dSApple OSS Distributions 
296*8d741a5dSApple OSS Distributions 	kr = host_processor_set_priv(host, psets[0], &pset_priv);
297*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "host_processor_set_priv");
298*8d741a5dSApple OSS Distributions 	for (size_t i = 0; i < pcnt; i++) {
299*8d741a5dSApple OSS Distributions 		mach_port_deallocate(mach_task_self(), psets[i]);
300*8d741a5dSApple OSS Distributions 	}
301*8d741a5dSApple OSS Distributions 	mach_port_deallocate(mach_task_self(), host);
302*8d741a5dSApple OSS Distributions 	vm_deallocate(mach_task_self(), (vm_address_t)psets, (vm_size_t)pcnt * sizeof(mach_port_t));
303*8d741a5dSApple OSS Distributions 
304*8d741a5dSApple OSS Distributions 	kr = processor_set_tasks_with_flavor(pset_priv, TASK_FLAVOR_CONTROL, &taskList, &tcnt);
305*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "processor_set_tasks_with_flavor");
306*8d741a5dSApple OSS Distributions 	T_QUIET; T_ASSERT_GE(tcnt, 1, "should have at least 1 task");
307*8d741a5dSApple OSS Distributions 	mach_port_deallocate(mach_task_self(), pset_priv);
308*8d741a5dSApple OSS Distributions 
309*8d741a5dSApple OSS Distributions 	found_self = false;
310*8d741a5dSApple OSS Distributions 	for (size_t i = 0; i < tcnt; i++) {
311*8d741a5dSApple OSS Distributions 		if (taskList[i] == mach_task_self()) {
312*8d741a5dSApple OSS Distributions 			found_self = true;
313*8d741a5dSApple OSS Distributions 			break;
314*8d741a5dSApple OSS Distributions 		}
315*8d741a5dSApple OSS Distributions 	}
316*8d741a5dSApple OSS Distributions 
317*8d741a5dSApple OSS Distributions 	T_EXPECT_TRUE(found_self, " processor_set_tasks() should return immovable task self");
318*8d741a5dSApple OSS Distributions 
319*8d741a5dSApple OSS Distributions 	for (size_t i = 0; i < tcnt; i++) {
320*8d741a5dSApple OSS Distributions 		mach_port_deallocate(mach_task_self(), taskList[i]);
321*8d741a5dSApple OSS Distributions 	}
322*8d741a5dSApple OSS Distributions 
323*8d741a5dSApple OSS Distributions 	if (tcnt > 0) {
324*8d741a5dSApple OSS Distributions 		mach_vm_deallocate(mach_task_self(),
325*8d741a5dSApple OSS Distributions 		    (mach_vm_address_t)taskList,
326*8d741a5dSApple OSS Distributions 		    tcnt * sizeof(mach_port_t));
327*8d741a5dSApple OSS Distributions 	}
328*8d741a5dSApple OSS Distributions }
329*8d741a5dSApple OSS Distributions 
330*8d741a5dSApple OSS Distributions static void
test_imm_pinned_control_port(const char * test_prog_name)331*8d741a5dSApple OSS Distributions test_imm_pinned_control_port(const char *test_prog_name)
332*8d741a5dSApple OSS Distributions {
333*8d741a5dSApple OSS Distributions 	uint32_t task_exc_guard = 0;
334*8d741a5dSApple OSS Distributions 	size_t te_size = sizeof(&task_exc_guard);
335*8d741a5dSApple OSS Distributions 	posix_spawnattr_t       attrs;
336*8d741a5dSApple OSS Distributions 	char *child_args[MAX_ARGV];
337*8d741a5dSApple OSS Distributions 	pid_t client_pid = 0;
338*8d741a5dSApple OSS Distributions 	uint32_t opts = 0;
339*8d741a5dSApple OSS Distributions 	uint64_t *test_exception_code;
340*8d741a5dSApple OSS Distributions 	size_t size = sizeof(&opts);
341*8d741a5dSApple OSS Distributions 	mach_port_t exc_port;
342*8d741a5dSApple OSS Distributions 	pthread_t s_exc_thread;
343*8d741a5dSApple OSS Distributions 	uint64_t exc_id;
344*8d741a5dSApple OSS Distributions 
345*8d741a5dSApple OSS Distributions 	T_LOG("Check if task_exc_guard exception has been enabled\n");
346*8d741a5dSApple OSS Distributions 	int ret = sysctlbyname("kern.task_exc_guard_default", &task_exc_guard, &te_size, NULL, 0);
347*8d741a5dSApple OSS Distributions 	T_ASSERT_EQ(ret, 0, "sysctlbyname");
348*8d741a5dSApple OSS Distributions 
349*8d741a5dSApple OSS Distributions 	if (!(task_exc_guard & TASK_EXC_GUARD_MP_DELIVER)) {
350*8d741a5dSApple OSS Distributions 		T_SKIP("task_exc_guard exception is not enabled");
351*8d741a5dSApple OSS Distributions 	}
352*8d741a5dSApple OSS Distributions 
353*8d741a5dSApple OSS Distributions 	T_LOG("Check if immovable control port has been enabled\n");
354*8d741a5dSApple OSS Distributions 	ret = sysctlbyname("kern.ipc_control_port_options", &opts, &size, NULL, 0);
355*8d741a5dSApple OSS Distributions 
356*8d741a5dSApple OSS Distributions 	if (!ret && (opts & 0x8) != 0x8) {
357*8d741a5dSApple OSS Distributions 		T_SKIP("hard immovable control port isn't enabled");
358*8d741a5dSApple OSS Distributions 	}
359*8d741a5dSApple OSS Distributions 
360*8d741a5dSApple OSS Distributions 	if (!ret && (opts & 0x2)) {
361*8d741a5dSApple OSS Distributions 		T_LOG("Hard pinning enforcement is on.");
362*8d741a5dSApple OSS Distributions 		test_exception_code = hard_exception_code;
363*8d741a5dSApple OSS Distributions 	} else {
364*8d741a5dSApple OSS Distributions 		T_LOG("Hard pinning enforcement is off.");
365*8d741a5dSApple OSS Distributions 		test_exception_code = soft_exception_code;
366*8d741a5dSApple OSS Distributions 	}
367*8d741a5dSApple OSS Distributions 
368*8d741a5dSApple OSS Distributions 
369*8d741a5dSApple OSS Distributions 	/* first, try out comparing various task/thread ports */
370*8d741a5dSApple OSS Distributions 	test_task_thread_port_values();
371*8d741a5dSApple OSS Distributions 
372*8d741a5dSApple OSS Distributions 	/* try stashing immovable ports: rdar://70585367 */
373*8d741a5dSApple OSS Distributions 	test_immovable_port_stashing();
374*8d741a5dSApple OSS Distributions 
375*8d741a5dSApple OSS Distributions 	/* spawn a child and see if EXC_GUARD are correctly generated */
376*8d741a5dSApple OSS Distributions 	for (int i = 0; i < MAX_TEST_NUM; i++) {
377*8d741a5dSApple OSS Distributions 		/* Create the exception port for the child */
378*8d741a5dSApple OSS Distributions 		exc_port = alloc_exception_port();
379*8d741a5dSApple OSS Distributions 		T_QUIET; T_ASSERT_NE(exc_port, MACH_PORT_NULL, "Create a new exception port");
380*8d741a5dSApple OSS Distributions 
381*8d741a5dSApple OSS Distributions 		/* Create exception serving thread */
382*8d741a5dSApple OSS Distributions 		ret = pthread_create(&s_exc_thread, NULL, exception_server_thread, &exc_port);
383*8d741a5dSApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_create exception_server_thread");
384*8d741a5dSApple OSS Distributions 
385*8d741a5dSApple OSS Distributions 		/* Initialize posix_spawn attributes */
386*8d741a5dSApple OSS Distributions 		posix_spawnattr_init(&attrs);
387*8d741a5dSApple OSS Distributions 
388*8d741a5dSApple OSS Distributions 		int err = posix_spawnattr_setexceptionports_np(&attrs, EXC_MASK_GUARD | EXC_MASK_CORPSE_NOTIFY, exc_port,
389*8d741a5dSApple OSS Distributions 		    (exception_behavior_t) (EXCEPTION_IDENTITY_PROTECTED | MACH_EXCEPTION_CODES), 0);
390*8d741a5dSApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(err, "posix_spawnattr_setflags");
391*8d741a5dSApple OSS Distributions 
392*8d741a5dSApple OSS Distributions 		child_args[0] = test_prog_name;
393*8d741a5dSApple OSS Distributions 		char test_num[10];
394*8d741a5dSApple OSS Distributions 		sprintf(test_num, "%d", i);
395*8d741a5dSApple OSS Distributions 		child_args[1] = test_num;
396*8d741a5dSApple OSS Distributions 		child_args[2] = NULL;
397*8d741a5dSApple OSS Distributions 
398*8d741a5dSApple OSS Distributions 		T_LOG("========== Spawning new child ==========");
399*8d741a5dSApple OSS Distributions 		err = posix_spawn(&client_pid, child_args[0], NULL, &attrs, &child_args[0], environ);
400*8d741a5dSApple OSS Distributions 		T_ASSERT_POSIX_SUCCESS(err, "posix_spawn control_port_options_client = %d test_num = %d", client_pid, i);
401*8d741a5dSApple OSS Distributions 
402*8d741a5dSApple OSS Distributions 		/* try extracting child task port: rdar://71744817
403*8d741a5dSApple OSS Distributions 		 * Moved to tests/extract_right_soft_fail.c
404*8d741a5dSApple OSS Distributions 		 */
405*8d741a5dSApple OSS Distributions 		// test_extract_immovable_task_port(client_pid);
406*8d741a5dSApple OSS Distributions 
407*8d741a5dSApple OSS Distributions 		int child_status;
408*8d741a5dSApple OSS Distributions 		/* Wait for child and check for exception */
409*8d741a5dSApple OSS Distributions 		if (-1 == waitpid(-1, &child_status, 0)) {
410*8d741a5dSApple OSS Distributions 			T_FAIL("waitpid: child mia");
411*8d741a5dSApple OSS Distributions 		}
412*8d741a5dSApple OSS Distributions 
413*8d741a5dSApple OSS Distributions 		if (WIFEXITED(child_status)) {
414*8d741a5dSApple OSS Distributions 			if (WEXITSTATUS(child_status)) {
415*8d741a5dSApple OSS Distributions 				T_FAIL("Child exited with status = %x", child_status); T_END;
416*8d741a5dSApple OSS Distributions 			} else {
417*8d741a5dSApple OSS Distributions 				/* Skipping test because CS_OPS_CLEARPLATFORM is not supported in the current BATS container */
418*8d741a5dSApple OSS Distributions 				T_SKIP("Failed to remove platform binary");
419*8d741a5dSApple OSS Distributions 			}
420*8d741a5dSApple OSS Distributions 		}
421*8d741a5dSApple OSS Distributions 
422*8d741a5dSApple OSS Distributions 		sleep(1);
423*8d741a5dSApple OSS Distributions 		kill(1, SIGKILL);
424*8d741a5dSApple OSS Distributions 
425*8d741a5dSApple OSS Distributions 		ret = pthread_join(s_exc_thread, NULL);
426*8d741a5dSApple OSS Distributions 		T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_join");
427*8d741a5dSApple OSS Distributions 
428*8d741a5dSApple OSS Distributions 		if (exception_taken == EXC_GUARD) {
429*8d741a5dSApple OSS Distributions 			exc_id = exception_code >> EXC_CODE_SHIFT;
430*8d741a5dSApple OSS Distributions 		} else {
431*8d741a5dSApple OSS Distributions 			exc_id = exception_code;
432*8d741a5dSApple OSS Distributions 		}
433*8d741a5dSApple OSS Distributions 
434*8d741a5dSApple OSS Distributions 		T_LOG("Exception code: Received code = 0x%llx Expected code = 0x%llx", exc_id, test_exception_code[i]);
435*8d741a5dSApple OSS Distributions 		T_EXPECT_EQ(exc_id, test_exception_code[i], "Exception code: Received == Expected");
436*8d741a5dSApple OSS Distributions 	}
437*8d741a5dSApple OSS Distributions }
438*8d741a5dSApple OSS Distributions 
439*8d741a5dSApple OSS Distributions T_DECL(imm_pinned_control_port_hardened, "Test pinned & immovable task and thread control ports for hardened runtime binary",
440*8d741a5dSApple OSS Distributions     T_META_IGNORECRASHES(".*pinned_rights_child.*"),
441*8d741a5dSApple OSS Distributions     T_META_CHECK_LEAKS(false))
442*8d741a5dSApple OSS Distributions {
443*8d741a5dSApple OSS Distributions 	test_imm_pinned_control_port("imm_pinned_control_port_crasher_3P_hardened");
444*8d741a5dSApple OSS Distributions }
445*8d741a5dSApple OSS Distributions 
446*8d741a5dSApple OSS Distributions T_DECL(imm_pinned_control_port, "Test pinned & immovable task and thread control ports for first party binary",
447*8d741a5dSApple OSS Distributions     T_META_IGNORECRASHES(".*pinned_rights_child.*"),
448*8d741a5dSApple OSS Distributions     T_META_CHECK_LEAKS(false),
449*8d741a5dSApple OSS Distributions     T_META_TAG_VM_PREFERRED)
450*8d741a5dSApple OSS Distributions {
451*8d741a5dSApple OSS Distributions 	test_imm_pinned_control_port("imm_pinned_control_port_crasher");
452*8d741a5dSApple OSS Distributions }
453