1*8d741a5dSApple OSS Distributions #include <mach/mach.h>
2*8d741a5dSApple OSS Distributions #include <stdlib.h>
3*8d741a5dSApple OSS Distributions #include <pthread.h>
4*8d741a5dSApple OSS Distributions #include <unistd.h>
5*8d741a5dSApple OSS Distributions #include <stdio.h>
6*8d741a5dSApple OSS Distributions #include <assert.h>
7*8d741a5dSApple OSS Distributions #include <mach/task.h>
8*8d741a5dSApple OSS Distributions #include <stdbool.h>
9*8d741a5dSApple OSS Distributions #include <mach/mk_timer.h>
10*8d741a5dSApple OSS Distributions #include "cs_helpers.h"
11*8d741a5dSApple OSS Distributions
12*8d741a5dSApple OSS Distributions /*
13*8d741a5dSApple OSS Distributions * DO NOT run this test file by itself.
14*8d741a5dSApple OSS Distributions * This test is meant to be invoked by control_port_options darwintest.
15*8d741a5dSApple OSS Distributions *
16*8d741a5dSApple OSS Distributions * If hard enforcement for pinned control port is on, pinned tests are
17*8d741a5dSApple OSS Distributions * expected to generate fatal EXC_GUARD.
18*8d741a5dSApple OSS Distributions *
19*8d741a5dSApple OSS Distributions * If hard enforcement for immovable control port is on, immovable tests are
20*8d741a5dSApple OSS Distributions * expected to generate fatal EXC_GUARD.
21*8d741a5dSApple OSS Distributions *
22*8d741a5dSApple OSS Distributions * The type of exception raised (if any) is checked on control_port_options side.
23*8d741a5dSApple OSS Distributions */
24*8d741a5dSApple OSS Distributions #define MAX_TEST_NUM 21
25*8d741a5dSApple OSS Distributions
26*8d741a5dSApple OSS Distributions #ifndef MACH64_SEND_ANY
27*8d741a5dSApple OSS Distributions #define MACH64_SEND_ANY 0x0000000800000000ull
28*8d741a5dSApple OSS Distributions #define MACH64_SEND_MQ_CALL 0x0000000400000000ull
29*8d741a5dSApple OSS Distributions #endif
30*8d741a5dSApple OSS Distributions
31*8d741a5dSApple OSS Distributions static int
attempt_send_immovable_port(mach_port_name_t port,mach_msg_type_name_t disp)32*8d741a5dSApple OSS Distributions attempt_send_immovable_port(mach_port_name_t port, mach_msg_type_name_t disp)
33*8d741a5dSApple OSS Distributions {
34*8d741a5dSApple OSS Distributions mach_port_t server;
35*8d741a5dSApple OSS Distributions kern_return_t kr;
36*8d741a5dSApple OSS Distributions kr = mach_port_allocate(mach_task_self(), MACH_PORT_RIGHT_RECEIVE, &server);
37*8d741a5dSApple OSS Distributions assert(kr == 0);
38*8d741a5dSApple OSS Distributions
39*8d741a5dSApple OSS Distributions kr = mach_port_insert_right(mach_task_self(), server, server, MACH_MSG_TYPE_MAKE_SEND);
40*8d741a5dSApple OSS Distributions assert(kr == 0);
41*8d741a5dSApple OSS Distributions
42*8d741a5dSApple OSS Distributions struct {
43*8d741a5dSApple OSS Distributions mach_msg_header_t header;
44*8d741a5dSApple OSS Distributions mach_msg_body_t body;
45*8d741a5dSApple OSS Distributions mach_msg_port_descriptor_t desc;
46*8d741a5dSApple OSS Distributions } msg;
47*8d741a5dSApple OSS Distributions
48*8d741a5dSApple OSS Distributions msg.header.msgh_remote_port = server;
49*8d741a5dSApple OSS Distributions msg.header.msgh_local_port = MACH_PORT_NULL;
50*8d741a5dSApple OSS Distributions msg.header.msgh_bits = MACH_MSGH_BITS(MACH_MSG_TYPE_COPY_SEND, 0) | MACH_MSGH_BITS_COMPLEX;
51*8d741a5dSApple OSS Distributions msg.header.msgh_size = sizeof msg;
52*8d741a5dSApple OSS Distributions
53*8d741a5dSApple OSS Distributions msg.body.msgh_descriptor_count = 1;
54*8d741a5dSApple OSS Distributions
55*8d741a5dSApple OSS Distributions msg.desc.name = port;
56*8d741a5dSApple OSS Distributions msg.desc.disposition = disp;
57*8d741a5dSApple OSS Distributions msg.desc.type = MACH_MSG_PORT_DESCRIPTOR;
58*8d741a5dSApple OSS Distributions
59*8d741a5dSApple OSS Distributions return mach_msg_send(&msg.header);
60*8d741a5dSApple OSS Distributions }
61*8d741a5dSApple OSS Distributions
62*8d741a5dSApple OSS Distributions static void
pinned_test_main_thread_mod_ref(void)63*8d741a5dSApple OSS Distributions pinned_test_main_thread_mod_ref(void)
64*8d741a5dSApple OSS Distributions {
65*8d741a5dSApple OSS Distributions printf("[Crasher]: Mod refs main thread's self port to 0\n");
66*8d741a5dSApple OSS Distributions mach_port_t thread_self = mach_thread_self();
67*8d741a5dSApple OSS Distributions kern_return_t kr = mach_port_mod_refs(mach_task_self(), thread_self, MACH_PORT_RIGHT_SEND, -2);
68*8d741a5dSApple OSS Distributions
69*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_main_thread_mod_ref] mach_port_mod_refs returned %s \n.", mach_error_string(kr));
70*8d741a5dSApple OSS Distributions }
71*8d741a5dSApple OSS Distributions
72*8d741a5dSApple OSS Distributions static void* _Nullable
pthread_run(void * _Nullable)73*8d741a5dSApple OSS Distributions pthread_run(void *_Nullable)
74*8d741a5dSApple OSS Distributions {
75*8d741a5dSApple OSS Distributions printf("[Crasher]: Deallocate pthread_self\n");
76*8d741a5dSApple OSS Distributions mach_port_t th_self = pthread_mach_thread_np(pthread_self());
77*8d741a5dSApple OSS Distributions kern_return_t kr = mach_port_deallocate(mach_task_self(), th_self);
78*8d741a5dSApple OSS Distributions
79*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_pthread_dealloc] mach_port_deallocate returned %s \n.", mach_error_string(kr));
80*8d741a5dSApple OSS Distributions return NULL;
81*8d741a5dSApple OSS Distributions }
82*8d741a5dSApple OSS Distributions
83*8d741a5dSApple OSS Distributions static void
pinned_test_pthread_dealloc(void)84*8d741a5dSApple OSS Distributions pinned_test_pthread_dealloc(void)
85*8d741a5dSApple OSS Distributions {
86*8d741a5dSApple OSS Distributions printf("[Crasher]: Create a pthread and deallocate its self port\n");
87*8d741a5dSApple OSS Distributions pthread_t thread;
88*8d741a5dSApple OSS Distributions int ret = pthread_create(&thread, NULL, pthread_run, NULL);
89*8d741a5dSApple OSS Distributions assert(ret == 0);
90*8d741a5dSApple OSS Distributions ret = pthread_join(thread, NULL);
91*8d741a5dSApple OSS Distributions assert(ret == 0);
92*8d741a5dSApple OSS Distributions }
93*8d741a5dSApple OSS Distributions
94*8d741a5dSApple OSS Distributions static void
pinned_test_task_self_dealloc(void)95*8d741a5dSApple OSS Distributions pinned_test_task_self_dealloc(void)
96*8d741a5dSApple OSS Distributions {
97*8d741a5dSApple OSS Distributions printf("[Crasher]: Deallocate mach_task_self twice\n");
98*8d741a5dSApple OSS Distributions mach_port_t task_self = mach_task_self();
99*8d741a5dSApple OSS Distributions kern_return_t kr = mach_port_deallocate(task_self, task_self);
100*8d741a5dSApple OSS Distributions assert(kr == 0);
101*8d741a5dSApple OSS Distributions kr = mach_port_deallocate(task_self, task_self);
102*8d741a5dSApple OSS Distributions
103*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_task_self_dealloc] mach_port_deallocate returned %s \n.", mach_error_string(kr));
104*8d741a5dSApple OSS Distributions }
105*8d741a5dSApple OSS Distributions
106*8d741a5dSApple OSS Distributions static void
pinned_test_task_self_mod_ref(void)107*8d741a5dSApple OSS Distributions pinned_test_task_self_mod_ref(void)
108*8d741a5dSApple OSS Distributions {
109*8d741a5dSApple OSS Distributions printf("[Crasher]: Mod refs mach_task_self() to 0\n");
110*8d741a5dSApple OSS Distributions kern_return_t kr = mach_port_mod_refs(mach_task_self(), mach_task_self(), MACH_PORT_RIGHT_SEND, -2);
111*8d741a5dSApple OSS Distributions
112*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_task_self_mod_ref] mach_port_mod_refs returned %s \n.", mach_error_string(kr));
113*8d741a5dSApple OSS Distributions }
114*8d741a5dSApple OSS Distributions
115*8d741a5dSApple OSS Distributions static void
pinned_test_task_threads_mod_ref(void)116*8d741a5dSApple OSS Distributions pinned_test_task_threads_mod_ref(void)
117*8d741a5dSApple OSS Distributions {
118*8d741a5dSApple OSS Distributions printf("[Crasher]: task_threads should return pinned thread ports. Mod refs them to 0\n");
119*8d741a5dSApple OSS Distributions thread_array_t th_list;
120*8d741a5dSApple OSS Distributions mach_msg_type_number_t th_cnt;
121*8d741a5dSApple OSS Distributions kern_return_t kr;
122*8d741a5dSApple OSS Distributions mach_port_t th_kp = mach_thread_self();
123*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), th_kp);
124*8d741a5dSApple OSS Distributions
125*8d741a5dSApple OSS Distributions kr = task_threads(mach_task_self(), &th_list, &th_cnt);
126*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), th_list[0]);
127*8d741a5dSApple OSS Distributions
128*8d741a5dSApple OSS Distributions kr = mach_port_mod_refs(mach_task_self(), th_list[0], MACH_PORT_RIGHT_SEND, -1);
129*8d741a5dSApple OSS Distributions
130*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_task_threads_mod_ref] mach_port_mod_refs returned %s \n.", mach_error_string(kr));
131*8d741a5dSApple OSS Distributions }
132*8d741a5dSApple OSS Distributions
133*8d741a5dSApple OSS Distributions static void
pinned_test_mach_port_destroy(void)134*8d741a5dSApple OSS Distributions pinned_test_mach_port_destroy(void)
135*8d741a5dSApple OSS Distributions {
136*8d741a5dSApple OSS Distributions kern_return_t kr = mach_port_destroy(mach_task_self(), mach_task_self());
137*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_mach_port_destroy] mach_port_destroy returned %s \n.", mach_error_string(kr));
138*8d741a5dSApple OSS Distributions }
139*8d741a5dSApple OSS Distributions
140*8d741a5dSApple OSS Distributions static void
pinned_test_move_send_as_remote_port(void)141*8d741a5dSApple OSS Distributions pinned_test_move_send_as_remote_port(void)
142*8d741a5dSApple OSS Distributions {
143*8d741a5dSApple OSS Distributions struct {
144*8d741a5dSApple OSS Distributions mach_msg_header_t header;
145*8d741a5dSApple OSS Distributions } msg;
146*8d741a5dSApple OSS Distributions
147*8d741a5dSApple OSS Distributions kern_return_t kr = mach_port_deallocate(mach_task_self(), mach_task_self());
148*8d741a5dSApple OSS Distributions assert(kr == 0);
149*8d741a5dSApple OSS Distributions
150*8d741a5dSApple OSS Distributions /*
151*8d741a5dSApple OSS Distributions * We allow move send on remote kobject port but this should trip on pinning on last ref.
152*8d741a5dSApple OSS Distributions * See: IPC_OBJECT_COPYIN_FLAGS_ALLOW_IMMOVABLE_SEND.
153*8d741a5dSApple OSS Distributions */
154*8d741a5dSApple OSS Distributions msg.header.msgh_remote_port = mach_task_self();
155*8d741a5dSApple OSS Distributions msg.header.msgh_local_port = MACH_PORT_NULL;
156*8d741a5dSApple OSS Distributions msg.header.msgh_bits = MACH_MSGH_BITS(MACH_MSG_TYPE_MOVE_SEND, 0);
157*8d741a5dSApple OSS Distributions msg.header.msgh_id = 2000;
158*8d741a5dSApple OSS Distributions msg.header.msgh_size = sizeof msg;
159*8d741a5dSApple OSS Distributions
160*8d741a5dSApple OSS Distributions kr = mach_msg_send(&msg.header);
161*8d741a5dSApple OSS Distributions
162*8d741a5dSApple OSS Distributions printf("[Crasher pinned_test_move_send_as_remote_port] mach_msg_send returned %s \n.", mach_error_string(kr));
163*8d741a5dSApple OSS Distributions }
164*8d741a5dSApple OSS Distributions
165*8d741a5dSApple OSS Distributions static void
immovable_test_move_send_as_remote_port(void)166*8d741a5dSApple OSS Distributions immovable_test_move_send_as_remote_port(void)
167*8d741a5dSApple OSS Distributions {
168*8d741a5dSApple OSS Distributions struct {
169*8d741a5dSApple OSS Distributions mach_msg_header_t header;
170*8d741a5dSApple OSS Distributions } msg;
171*8d741a5dSApple OSS Distributions
172*8d741a5dSApple OSS Distributions /* Local port cannot be immovable. See: ipc_right_copyin_check_reply() */
173*8d741a5dSApple OSS Distributions msg.header.msgh_remote_port = mach_task_self();
174*8d741a5dSApple OSS Distributions msg.header.msgh_local_port = mach_task_self();
175*8d741a5dSApple OSS Distributions msg.header.msgh_bits = MACH_MSGH_BITS(MACH_MSG_TYPE_MOVE_SEND, MACH_MSG_TYPE_MOVE_SEND);
176*8d741a5dSApple OSS Distributions msg.header.msgh_id = 2000;
177*8d741a5dSApple OSS Distributions msg.header.msgh_size = sizeof msg;
178*8d741a5dSApple OSS Distributions
179*8d741a5dSApple OSS Distributions kern_return_t kr = mach_msg_send(&msg.header);
180*8d741a5dSApple OSS Distributions
181*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_move_send_as_remote_port] mach_msg_send returned %s \n.", mach_error_string(kr));
182*8d741a5dSApple OSS Distributions }
183*8d741a5dSApple OSS Distributions
184*8d741a5dSApple OSS Distributions static void
immovable_test_move_send_task_self(void)185*8d741a5dSApple OSS Distributions immovable_test_move_send_task_self(void)
186*8d741a5dSApple OSS Distributions {
187*8d741a5dSApple OSS Distributions kern_return_t kr;
188*8d741a5dSApple OSS Distributions printf("[Crasher]: Move send mach_task_self_\n");
189*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(mach_task_self(), MACH_MSG_TYPE_MOVE_SEND);
190*8d741a5dSApple OSS Distributions
191*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_move_send_task_self] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
192*8d741a5dSApple OSS Distributions }
193*8d741a5dSApple OSS Distributions
194*8d741a5dSApple OSS Distributions static void
immovable_test_copy_send_task_self(void)195*8d741a5dSApple OSS Distributions immovable_test_copy_send_task_self(void)
196*8d741a5dSApple OSS Distributions {
197*8d741a5dSApple OSS Distributions kern_return_t kr;
198*8d741a5dSApple OSS Distributions printf("[Crasher]: Copy send mach_task_self_\n");
199*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(mach_task_self(), MACH_MSG_TYPE_COPY_SEND);
200*8d741a5dSApple OSS Distributions
201*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_copy_send_task_self] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
202*8d741a5dSApple OSS Distributions }
203*8d741a5dSApple OSS Distributions
204*8d741a5dSApple OSS Distributions static void
immovable_test_move_send_thread_self(void)205*8d741a5dSApple OSS Distributions immovable_test_move_send_thread_self(void)
206*8d741a5dSApple OSS Distributions {
207*8d741a5dSApple OSS Distributions kern_return_t kr;
208*8d741a5dSApple OSS Distributions printf("[Crasher]: Move send main thread's self port\n");
209*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(mach_thread_self(), MACH_MSG_TYPE_MOVE_SEND);
210*8d741a5dSApple OSS Distributions
211*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_move_send_thread_self] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
212*8d741a5dSApple OSS Distributions }
213*8d741a5dSApple OSS Distributions
214*8d741a5dSApple OSS Distributions static void
immovable_test_copy_send_thread_self(void)215*8d741a5dSApple OSS Distributions immovable_test_copy_send_thread_self(void)
216*8d741a5dSApple OSS Distributions {
217*8d741a5dSApple OSS Distributions kern_return_t kr;
218*8d741a5dSApple OSS Distributions mach_port_t port;
219*8d741a5dSApple OSS Distributions printf("[Crasher]: Copy send main thread's self port\n");
220*8d741a5dSApple OSS Distributions port = mach_thread_self();
221*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(port, MACH_MSG_TYPE_COPY_SEND);
222*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_copy_send_thread_self] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
223*8d741a5dSApple OSS Distributions
224*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), port);
225*8d741a5dSApple OSS Distributions }
226*8d741a5dSApple OSS Distributions
227*8d741a5dSApple OSS Distributions static void
immovable_test_copy_send_task_read(void)228*8d741a5dSApple OSS Distributions immovable_test_copy_send_task_read(void)
229*8d741a5dSApple OSS Distributions {
230*8d741a5dSApple OSS Distributions kern_return_t kr;
231*8d741a5dSApple OSS Distributions mach_port_t port;
232*8d741a5dSApple OSS Distributions printf("[Crasher]: Copy send task read port\n");
233*8d741a5dSApple OSS Distributions kr = task_get_special_port(mach_task_self(), TASK_READ_PORT, &port);
234*8d741a5dSApple OSS Distributions assert(kr == 0);
235*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(port, MACH_MSG_TYPE_COPY_SEND);
236*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_copy_send_task_read] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
237*8d741a5dSApple OSS Distributions
238*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), port);
239*8d741a5dSApple OSS Distributions }
240*8d741a5dSApple OSS Distributions
241*8d741a5dSApple OSS Distributions static void
immovable_test_copy_send_task_inspect(void)242*8d741a5dSApple OSS Distributions immovable_test_copy_send_task_inspect(void)
243*8d741a5dSApple OSS Distributions {
244*8d741a5dSApple OSS Distributions kern_return_t kr;
245*8d741a5dSApple OSS Distributions mach_port_t port;
246*8d741a5dSApple OSS Distributions printf("[Crasher]: Move send task inspect port\n");
247*8d741a5dSApple OSS Distributions kr = task_get_special_port(mach_task_self(), TASK_INSPECT_PORT, &port);
248*8d741a5dSApple OSS Distributions assert(kr == 0);
249*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(port, MACH_MSG_TYPE_MOVE_SEND);
250*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_copy_send_task_inspect] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
251*8d741a5dSApple OSS Distributions }
252*8d741a5dSApple OSS Distributions
253*8d741a5dSApple OSS Distributions static void
immovable_test_move_send_thread_inspect(void)254*8d741a5dSApple OSS Distributions immovable_test_move_send_thread_inspect(void)
255*8d741a5dSApple OSS Distributions {
256*8d741a5dSApple OSS Distributions kern_return_t kr;
257*8d741a5dSApple OSS Distributions mach_port_t port;
258*8d741a5dSApple OSS Distributions mach_port_t th_port = mach_thread_self();
259*8d741a5dSApple OSS Distributions
260*8d741a5dSApple OSS Distributions printf("[Crasher]: Move send thread inspect port\n");
261*8d741a5dSApple OSS Distributions kr = thread_get_special_port(th_port, THREAD_INSPECT_PORT, &port);
262*8d741a5dSApple OSS Distributions assert(kr == 0);
263*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(port, MACH_MSG_TYPE_MOVE_SEND);
264*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_move_send_thread_inspect] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
265*8d741a5dSApple OSS Distributions
266*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), th_port);
267*8d741a5dSApple OSS Distributions }
268*8d741a5dSApple OSS Distributions
269*8d741a5dSApple OSS Distributions static void
immovable_test_move_send_raw_thread(void)270*8d741a5dSApple OSS Distributions immovable_test_move_send_raw_thread(void)
271*8d741a5dSApple OSS Distributions {
272*8d741a5dSApple OSS Distributions kern_return_t kr;
273*8d741a5dSApple OSS Distributions mach_port_t port;
274*8d741a5dSApple OSS Distributions
275*8d741a5dSApple OSS Distributions kr = thread_create(mach_task_self(), &port);
276*8d741a5dSApple OSS Distributions assert(kr == 0);
277*8d741a5dSApple OSS Distributions kr = mach_port_deallocate(mach_task_self(), port); /* not pinned, should not crash */
278*8d741a5dSApple OSS Distributions
279*8d741a5dSApple OSS Distributions kr = thread_create(mach_task_self(), &port);
280*8d741a5dSApple OSS Distributions assert(kr == 0);
281*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(port, MACH_MSG_TYPE_MOVE_SEND); /* immovable, should crash here */
282*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_move_send_raw_thread] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
283*8d741a5dSApple OSS Distributions
284*8d741a5dSApple OSS Distributions kr = thread_terminate(port);
285*8d741a5dSApple OSS Distributions assert(kr == 0);
286*8d741a5dSApple OSS Distributions }
287*8d741a5dSApple OSS Distributions
288*8d741a5dSApple OSS Distributions static void
immovable_test_copy_send_thread_read(void)289*8d741a5dSApple OSS Distributions immovable_test_copy_send_thread_read(void)
290*8d741a5dSApple OSS Distributions {
291*8d741a5dSApple OSS Distributions kern_return_t kr;
292*8d741a5dSApple OSS Distributions mach_port_t port;
293*8d741a5dSApple OSS Distributions mach_port_t th_port = mach_thread_self();
294*8d741a5dSApple OSS Distributions
295*8d741a5dSApple OSS Distributions printf("[Crasher]: Copy send thread read port\n");
296*8d741a5dSApple OSS Distributions kr = thread_get_special_port(th_port, THREAD_READ_PORT, &port);
297*8d741a5dSApple OSS Distributions assert(kr == 0);
298*8d741a5dSApple OSS Distributions kr = attempt_send_immovable_port(port, MACH_MSG_TYPE_COPY_SEND);
299*8d741a5dSApple OSS Distributions printf("[Crasher immovable_test_copy_send_thread_read] attempt_send_immovable_port returned %s \n.", mach_error_string(kr));
300*8d741a5dSApple OSS Distributions
301*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), port);
302*8d741a5dSApple OSS Distributions mach_port_deallocate(mach_task_self(), th_port);
303*8d741a5dSApple OSS Distributions }
304*8d741a5dSApple OSS Distributions
305*8d741a5dSApple OSS Distributions static void
cfi_test_no_bit_set(void)306*8d741a5dSApple OSS Distributions cfi_test_no_bit_set(void)
307*8d741a5dSApple OSS Distributions {
308*8d741a5dSApple OSS Distributions printf("[Crasher]: Try sending mach_msg2() without setting CFI bits\n");
309*8d741a5dSApple OSS Distributions
310*8d741a5dSApple OSS Distributions mach_msg_header_t header;
311*8d741a5dSApple OSS Distributions kern_return_t kr;
312*8d741a5dSApple OSS Distributions
313*8d741a5dSApple OSS Distributions header.msgh_local_port = MACH_PORT_NULL;
314*8d741a5dSApple OSS Distributions header.msgh_remote_port = mach_task_self();
315*8d741a5dSApple OSS Distributions header.msgh_id = 3409;
316*8d741a5dSApple OSS Distributions header.msgh_bits = MACH_MSGH_BITS_SET(MACH_MSG_TYPE_COPY_SEND, 0, 0, 0);
317*8d741a5dSApple OSS Distributions header.msgh_size = sizeof(header);
318*8d741a5dSApple OSS Distributions
319*8d741a5dSApple OSS Distributions kr = mach_msg2(&header, MACH64_SEND_MSG, header, header.msgh_size, 0, MACH_PORT_NULL,
320*8d741a5dSApple OSS Distributions 0, MACH_MSG_PRIORITY_UNSPECIFIED);
321*8d741a5dSApple OSS Distributions /* crash */
322*8d741a5dSApple OSS Distributions printf("[Crasher cfi_test_no_bit_set]: mach_msg2() returned %d\n", kr);
323*8d741a5dSApple OSS Distributions }
324*8d741a5dSApple OSS Distributions
325*8d741a5dSApple OSS Distributions static void
cfi_test_two_bits_set(void)326*8d741a5dSApple OSS Distributions cfi_test_two_bits_set(void)
327*8d741a5dSApple OSS Distributions {
328*8d741a5dSApple OSS Distributions printf("[Crasher]: Try sending mach_msg2() but setting 2 CFI bits\n");
329*8d741a5dSApple OSS Distributions
330*8d741a5dSApple OSS Distributions mach_msg_header_t header;
331*8d741a5dSApple OSS Distributions kern_return_t kr;
332*8d741a5dSApple OSS Distributions
333*8d741a5dSApple OSS Distributions header.msgh_local_port = MACH_PORT_NULL;
334*8d741a5dSApple OSS Distributions header.msgh_remote_port = mach_task_self();
335*8d741a5dSApple OSS Distributions header.msgh_id = 3409;
336*8d741a5dSApple OSS Distributions header.msgh_bits = MACH_MSGH_BITS_SET(MACH_MSG_TYPE_COPY_SEND, 0, 0, 0);
337*8d741a5dSApple OSS Distributions header.msgh_size = sizeof(header);
338*8d741a5dSApple OSS Distributions
339*8d741a5dSApple OSS Distributions kr = mach_msg2(&header, MACH64_SEND_MSG | MACH64_SEND_ANY | MACH64_SEND_KOBJECT_CALL,
340*8d741a5dSApple OSS Distributions header, header.msgh_size, 0, MACH_PORT_NULL,
341*8d741a5dSApple OSS Distributions 0, MACH_MSG_PRIORITY_UNSPECIFIED);
342*8d741a5dSApple OSS Distributions /* crash */
343*8d741a5dSApple OSS Distributions printf("[Crasher cfi_test_two_bits_set]: mach_msg2() returned %d\n", kr);
344*8d741a5dSApple OSS Distributions }
345*8d741a5dSApple OSS Distributions
346*8d741a5dSApple OSS Distributions static void
cfi_test_msg_to_timer_port(void)347*8d741a5dSApple OSS Distributions cfi_test_msg_to_timer_port(void)
348*8d741a5dSApple OSS Distributions {
349*8d741a5dSApple OSS Distributions printf("[Crasher]: Try sending mach_msg2() to timer port\n");
350*8d741a5dSApple OSS Distributions
351*8d741a5dSApple OSS Distributions mach_port_t timer = MACH_PORT_NULL;
352*8d741a5dSApple OSS Distributions struct oversize_msg {
353*8d741a5dSApple OSS Distributions mach_msg_header_t header;
354*8d741a5dSApple OSS Distributions char data[2048];
355*8d741a5dSApple OSS Distributions } msg;
356*8d741a5dSApple OSS Distributions
357*8d741a5dSApple OSS Distributions kern_return_t kr;
358*8d741a5dSApple OSS Distributions natural_t kotype;
359*8d741a5dSApple OSS Distributions mach_vm_address_t addr;
360*8d741a5dSApple OSS Distributions
361*8d741a5dSApple OSS Distributions #define IKOT_TIMER 8
362*8d741a5dSApple OSS Distributions timer = mk_timer_create();
363*8d741a5dSApple OSS Distributions assert(timer != MACH_PORT_NULL);
364*8d741a5dSApple OSS Distributions
365*8d741a5dSApple OSS Distributions /* Make sure it's a kobject port */
366*8d741a5dSApple OSS Distributions kr = mach_port_kobject(mach_task_self(), timer, &kotype, &addr);
367*8d741a5dSApple OSS Distributions assert(kr == KERN_SUCCESS);
368*8d741a5dSApple OSS Distributions assert(kotype == IKOT_TIMER);
369*8d741a5dSApple OSS Distributions
370*8d741a5dSApple OSS Distributions msg.header.msgh_local_port = MACH_PORT_NULL;
371*8d741a5dSApple OSS Distributions msg.header.msgh_remote_port = timer;
372*8d741a5dSApple OSS Distributions msg.header.msgh_bits = MACH_MSGH_BITS_SET(MACH_MSG_TYPE_MAKE_SEND, 0, 0, 0);
373*8d741a5dSApple OSS Distributions msg.header.msgh_size = sizeof(msg);
374*8d741a5dSApple OSS Distributions
375*8d741a5dSApple OSS Distributions /* Timer port must use MACH64_SEND_MQ_CALL */
376*8d741a5dSApple OSS Distributions kr = mach_msg2(&msg, MACH64_SEND_MSG | MACH64_SEND_MQ_CALL,
377*8d741a5dSApple OSS Distributions msg.header, msg.header.msgh_size, 0, MACH_PORT_NULL,
378*8d741a5dSApple OSS Distributions 0, MACH_MSG_PRIORITY_UNSPECIFIED);
379*8d741a5dSApple OSS Distributions assert(kr == KERN_SUCCESS);
380*8d741a5dSApple OSS Distributions printf("Message sent to timer port successfully\n");
381*8d741a5dSApple OSS Distributions
382*8d741a5dSApple OSS Distributions /* Using MACH64_SEND_KOBJECT_CALL should crash */
383*8d741a5dSApple OSS Distributions kr = mach_msg2(&msg, MACH64_SEND_MSG | MACH64_SEND_KOBJECT_CALL,
384*8d741a5dSApple OSS Distributions msg.header, msg.header.msgh_size, 0, MACH_PORT_NULL,
385*8d741a5dSApple OSS Distributions 0, MACH_MSG_PRIORITY_UNSPECIFIED);
386*8d741a5dSApple OSS Distributions /* crash */
387*8d741a5dSApple OSS Distributions printf("[Crasher cfi_test_timer_port]: mach_msg2() returned %d\n", kr);
388*8d741a5dSApple OSS Distributions }
389*8d741a5dSApple OSS Distributions
390*8d741a5dSApple OSS Distributions static void
cfi_test_wrong_bit_set(void)391*8d741a5dSApple OSS Distributions cfi_test_wrong_bit_set(void)
392*8d741a5dSApple OSS Distributions {
393*8d741a5dSApple OSS Distributions printf("[Crasher]: Try sending mach_msg2() but setting wrong CFI bits\n");
394*8d741a5dSApple OSS Distributions
395*8d741a5dSApple OSS Distributions mach_msg_header_t header;
396*8d741a5dSApple OSS Distributions kern_return_t kr;
397*8d741a5dSApple OSS Distributions
398*8d741a5dSApple OSS Distributions header.msgh_local_port = MACH_PORT_NULL;
399*8d741a5dSApple OSS Distributions header.msgh_remote_port = mach_task_self();
400*8d741a5dSApple OSS Distributions header.msgh_id = 3409;
401*8d741a5dSApple OSS Distributions header.msgh_bits = MACH_MSGH_BITS_SET(MACH_MSG_TYPE_COPY_SEND, 0, 0, 0);
402*8d741a5dSApple OSS Distributions header.msgh_size = sizeof(header);
403*8d741a5dSApple OSS Distributions
404*8d741a5dSApple OSS Distributions /* Using MACH64_SEND_MQ_CALL but destination is a kobject port */
405*8d741a5dSApple OSS Distributions kr = mach_msg2(&header, MACH64_SEND_MSG | MACH64_SEND_MQ_CALL,
406*8d741a5dSApple OSS Distributions header, header.msgh_size, 0, MACH_PORT_NULL,
407*8d741a5dSApple OSS Distributions 0, MACH_MSG_PRIORITY_UNSPECIFIED);
408*8d741a5dSApple OSS Distributions /* crash */
409*8d741a5dSApple OSS Distributions printf("[Crasher cfi_test_wrong_bit_set]: mach_msg2() returned %d\n", kr);
410*8d741a5dSApple OSS Distributions }
411*8d741a5dSApple OSS Distributions
412*8d741a5dSApple OSS Distributions int
main(int argc,char * argv[])413*8d741a5dSApple OSS Distributions main(int argc, char *argv[])
414*8d741a5dSApple OSS Distributions {
415*8d741a5dSApple OSS Distributions void (*tests[MAX_TEST_NUM])(void) = {
416*8d741a5dSApple OSS Distributions pinned_test_main_thread_mod_ref,
417*8d741a5dSApple OSS Distributions pinned_test_pthread_dealloc,
418*8d741a5dSApple OSS Distributions pinned_test_task_self_dealloc,
419*8d741a5dSApple OSS Distributions pinned_test_task_self_mod_ref,
420*8d741a5dSApple OSS Distributions pinned_test_task_threads_mod_ref,
421*8d741a5dSApple OSS Distributions pinned_test_mach_port_destroy,
422*8d741a5dSApple OSS Distributions pinned_test_move_send_as_remote_port,
423*8d741a5dSApple OSS Distributions
424*8d741a5dSApple OSS Distributions immovable_test_move_send_task_self,
425*8d741a5dSApple OSS Distributions immovable_test_copy_send_task_self,
426*8d741a5dSApple OSS Distributions immovable_test_move_send_thread_self,
427*8d741a5dSApple OSS Distributions immovable_test_copy_send_thread_self,
428*8d741a5dSApple OSS Distributions immovable_test_copy_send_task_read,
429*8d741a5dSApple OSS Distributions immovable_test_copy_send_task_inspect,
430*8d741a5dSApple OSS Distributions immovable_test_move_send_thread_inspect,
431*8d741a5dSApple OSS Distributions immovable_test_copy_send_thread_read,
432*8d741a5dSApple OSS Distributions immovable_test_move_send_as_remote_port,
433*8d741a5dSApple OSS Distributions immovable_test_move_send_raw_thread,
434*8d741a5dSApple OSS Distributions
435*8d741a5dSApple OSS Distributions cfi_test_no_bit_set,
436*8d741a5dSApple OSS Distributions cfi_test_two_bits_set,
437*8d741a5dSApple OSS Distributions cfi_test_wrong_bit_set,
438*8d741a5dSApple OSS Distributions cfi_test_msg_to_timer_port,
439*8d741a5dSApple OSS Distributions };
440*8d741a5dSApple OSS Distributions printf("[Crasher]: My Pid: %d\n", getpid());
441*8d741a5dSApple OSS Distributions
442*8d741a5dSApple OSS Distributions if (argc < 2) {
443*8d741a5dSApple OSS Distributions printf("[Crasher]: Specify a test to run.");
444*8d741a5dSApple OSS Distributions exit(-1);
445*8d741a5dSApple OSS Distributions }
446*8d741a5dSApple OSS Distributions
447*8d741a5dSApple OSS Distributions bool third_party_hardened = !strcmp(argv[0], "imm_pinned_control_port_crasher_3P_hardened");
448*8d741a5dSApple OSS Distributions if (third_party_hardened) {
449*8d741a5dSApple OSS Distributions // Ensure that we can set this crasher as a non-platform binary
450*8d741a5dSApple OSS Distributions if (remove_platform_binary() != 0) {
451*8d741a5dSApple OSS Distributions /*
452*8d741a5dSApple OSS Distributions * CS_OPS_CLEARPLATFORM always fail on release build, and it can also
453*8d741a5dSApple OSS Distributions * fail depending on global/mac policies of the BATS container (ref: csops_internal).
454*8d741a5dSApple OSS Distributions * Skip instead of failing the test.
455*8d741a5dSApple OSS Distributions */
456*8d741a5dSApple OSS Distributions printf("Failed to remove platform binary, skipping test\n");
457*8d741a5dSApple OSS Distributions exit(0);
458*8d741a5dSApple OSS Distributions }
459*8d741a5dSApple OSS Distributions }
460*8d741a5dSApple OSS Distributions
461*8d741a5dSApple OSS Distributions int test_num = atoi(argv[1]);
462*8d741a5dSApple OSS Distributions
463*8d741a5dSApple OSS Distributions
464*8d741a5dSApple OSS Distributions if (test_num >= 0 && test_num < MAX_TEST_NUM) {
465*8d741a5dSApple OSS Distributions printf("[Crasher]: Running test num %d\n", test_num);
466*8d741a5dSApple OSS Distributions (*tests[test_num])();
467*8d741a5dSApple OSS Distributions } else {
468*8d741a5dSApple OSS Distributions printf("[Crasher]: Invalid test num: %d. Exiting...\n", test_num);
469*8d741a5dSApple OSS Distributions exit(-1);
470*8d741a5dSApple OSS Distributions }
471*8d741a5dSApple OSS Distributions
472*8d741a5dSApple OSS Distributions exit(0);
473*8d741a5dSApple OSS Distributions }
474