1*33de042dSApple OSS Distributions #include <unistd.h>
2*33de042dSApple OSS Distributions #include <pthread.h>
3*33de042dSApple OSS Distributions #include <errno.h>
4*33de042dSApple OSS Distributions
5*33de042dSApple OSS Distributions #include <sys/event.h>
6*33de042dSApple OSS Distributions #include <mach/mach.h>
7*33de042dSApple OSS Distributions #include <mach/mach_port.h>
8*33de042dSApple OSS Distributions
9*33de042dSApple OSS Distributions #include <Block.h>
10*33de042dSApple OSS Distributions #include <darwintest.h>
11*33de042dSApple OSS Distributions
12*33de042dSApple OSS Distributions T_GLOBAL_META(
13*33de042dSApple OSS Distributions T_META_NAMESPACE("xnu.kevent"),
14*33de042dSApple OSS Distributions T_META_RADAR_COMPONENT_NAME("xnu"),
15*33de042dSApple OSS Distributions T_META_RADAR_COMPONENT_VERSION("kevent"),
16*33de042dSApple OSS Distributions T_META_RUN_CONCURRENTLY(true)
17*33de042dSApple OSS Distributions );
18*33de042dSApple OSS Distributions
19*33de042dSApple OSS Distributions static void
send(mach_port_t send_port)20*33de042dSApple OSS Distributions send(mach_port_t send_port)
21*33de042dSApple OSS Distributions {
22*33de042dSApple OSS Distributions kern_return_t kr = 0;
23*33de042dSApple OSS Distributions mach_msg_base_t msg = {
24*33de042dSApple OSS Distributions .header = {
25*33de042dSApple OSS Distributions .msgh_remote_port = send_port,
26*33de042dSApple OSS Distributions .msgh_bits = MACH_MSGH_BITS_SET(MACH_MSG_TYPE_COPY_SEND,
27*33de042dSApple OSS Distributions 0, MACH_MSG_TYPE_MOVE_SEND, 0),
28*33de042dSApple OSS Distributions .msgh_id = 0x100,
29*33de042dSApple OSS Distributions .msgh_size = sizeof(msg),
30*33de042dSApple OSS Distributions },
31*33de042dSApple OSS Distributions };
32*33de042dSApple OSS Distributions
33*33de042dSApple OSS Distributions kr = mach_msg(&msg.header, MACH_SEND_MSG | MACH_SEND_TIMEOUT,
34*33de042dSApple OSS Distributions msg.header.msgh_size, 0, MACH_PORT_NULL, 10000, 0);
35*33de042dSApple OSS Distributions
36*33de042dSApple OSS Distributions T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "client mach_msg");
37*33de042dSApple OSS Distributions }
38*33de042dSApple OSS Distributions
39*33de042dSApple OSS Distributions static kern_return_t
receive(mach_port_t rcv_port)40*33de042dSApple OSS Distributions receive(mach_port_t rcv_port)
41*33de042dSApple OSS Distributions {
42*33de042dSApple OSS Distributions mach_msg_base_t msg = {
43*33de042dSApple OSS Distributions .header = {
44*33de042dSApple OSS Distributions .msgh_remote_port = MACH_PORT_NULL,
45*33de042dSApple OSS Distributions .msgh_local_port = rcv_port,
46*33de042dSApple OSS Distributions .msgh_size = sizeof(msg),
47*33de042dSApple OSS Distributions },
48*33de042dSApple OSS Distributions };
49*33de042dSApple OSS Distributions
50*33de042dSApple OSS Distributions return mach_msg(&msg.header, MACH_RCV_MSG | MACH_RCV_TIMEOUT,
51*33de042dSApple OSS Distributions 0, msg.header.msgh_size, rcv_port, 5000, 0);
52*33de042dSApple OSS Distributions }
53*33de042dSApple OSS Distributions
54*33de042dSApple OSS Distributions static void
fill_kevent(struct kevent * ke,uint16_t action,mach_port_t mp)55*33de042dSApple OSS Distributions fill_kevent(struct kevent *ke, uint16_t action, mach_port_t mp)
56*33de042dSApple OSS Distributions {
57*33de042dSApple OSS Distributions *ke = (struct kevent){
58*33de042dSApple OSS Distributions .filter = EVFILT_MACHPORT,
59*33de042dSApple OSS Distributions .flags = action,
60*33de042dSApple OSS Distributions .ident = mp,
61*33de042dSApple OSS Distributions };
62*33de042dSApple OSS Distributions }
63*33de042dSApple OSS Distributions
64*33de042dSApple OSS Distributions #define TS(s) (struct timespec){ .tv_sec = s }
65*33de042dSApple OSS Distributions
66*33de042dSApple OSS Distributions static void *
pthread_async_do(void * arg)67*33de042dSApple OSS Distributions pthread_async_do(void *arg)
68*33de042dSApple OSS Distributions {
69*33de042dSApple OSS Distributions void (^block)(void) = arg;
70*33de042dSApple OSS Distributions block();
71*33de042dSApple OSS Distributions Block_release(block);
72*33de042dSApple OSS Distributions pthread_detach(pthread_self());
73*33de042dSApple OSS Distributions return NULL;
74*33de042dSApple OSS Distributions }
75*33de042dSApple OSS Distributions
76*33de042dSApple OSS Distributions static void
77*33de042dSApple OSS Distributions pthread_async(void (^block)(void))
78*33de042dSApple OSS Distributions {
79*33de042dSApple OSS Distributions pthread_t th;
80*33de042dSApple OSS Distributions int rc;
81*33de042dSApple OSS Distributions
82*33de042dSApple OSS Distributions rc = pthread_create(&th, NULL, pthread_async_do, Block_copy(block));
83*33de042dSApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(rc, "pthread_create");
84*33de042dSApple OSS Distributions }
85*33de042dSApple OSS Distributions
86*33de042dSApple OSS Distributions T_DECL(kqueue_machport, "basic EVFILT_MACHPORT tests", T_META_TAG_VM_PREFERRED)
87*33de042dSApple OSS Distributions {
88*33de042dSApple OSS Distributions mach_port_options_t opts = {
89*33de042dSApple OSS Distributions .flags = MPO_INSERT_SEND_RIGHT,
90*33de042dSApple OSS Distributions };
91*33de042dSApple OSS Distributions mach_port_t mp, pset;
92*33de042dSApple OSS Distributions kern_return_t kr;
93*33de042dSApple OSS Distributions struct kevent ke[2];
94*33de042dSApple OSS Distributions int kq, rc;
95*33de042dSApple OSS Distributions
96*33de042dSApple OSS Distributions kr = mach_port_construct(mach_task_self(), &opts, 0, &mp);
97*33de042dSApple OSS Distributions T_EXPECT_MACH_SUCCESS(kr, "mach_port_construct()");
98*33de042dSApple OSS Distributions
99*33de042dSApple OSS Distributions kr = mach_port_allocate(mach_task_self(), MACH_PORT_RIGHT_PORT_SET, &pset);
100*33de042dSApple OSS Distributions T_EXPECT_MACH_SUCCESS(kr, "mach_port_allocate(PSET)");
101*33de042dSApple OSS Distributions
102*33de042dSApple OSS Distributions kr = mach_port_move_member(mach_task_self(), mp, pset);
103*33de042dSApple OSS Distributions T_EXPECT_MACH_SUCCESS(kr, "mach_port_move_member(PORT, PSET)");
104*33de042dSApple OSS Distributions
105*33de042dSApple OSS Distributions kq = kqueue();
106*33de042dSApple OSS Distributions T_EXPECT_POSIX_SUCCESS(kq, "kqueue()");
107*33de042dSApple OSS Distributions
108*33de042dSApple OSS Distributions /*
109*33de042dSApple OSS Distributions * Fired when attached
110*33de042dSApple OSS Distributions */
111*33de042dSApple OSS Distributions send(mp);
112*33de042dSApple OSS Distributions
113*33de042dSApple OSS Distributions fill_kevent(&ke[0], EV_ADD, mp);
114*33de042dSApple OSS Distributions fill_kevent(&ke[1], EV_ADD, pset);
115*33de042dSApple OSS Distributions rc = kevent(kq, ke, 2, NULL, 0, &TS(5));
116*33de042dSApple OSS Distributions T_EXPECT_POSIX_SUCCESS(rc, "kevent(registration)");
117*33de042dSApple OSS Distributions
118*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(5));
119*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 2, "kevent(fired at attach time)");
120*33de042dSApple OSS Distributions
121*33de042dSApple OSS Distributions receive(mp);
122*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(1));
123*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 0, "no event");
124*33de042dSApple OSS Distributions
125*33de042dSApple OSS Distributions /*
126*33de042dSApple OSS Distributions * Fired after being attached, before wait
127*33de042dSApple OSS Distributions */
128*33de042dSApple OSS Distributions send(mp);
129*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(5));
130*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 2, "kevent(fired after attach time, before wait)");
131*33de042dSApple OSS Distributions
132*33de042dSApple OSS Distributions receive(mp);
133*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(1));
134*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 0, "no event");
135*33de042dSApple OSS Distributions
136*33de042dSApple OSS Distributions /*
137*33de042dSApple OSS Distributions * Fired after being attached, after wait
138*33de042dSApple OSS Distributions */
139*33de042dSApple OSS Distributions pthread_async(^{
140*33de042dSApple OSS Distributions sleep(1);
141*33de042dSApple OSS Distributions send(mp);
142*33de042dSApple OSS Distributions });
143*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(5));
144*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 2, "kevent(fired after attach time, after wait)");
145*33de042dSApple OSS Distributions
146*33de042dSApple OSS Distributions receive(mp);
147*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(1));
148*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 0, "no event");
149*33de042dSApple OSS Distributions
150*33de042dSApple OSS Distributions /* Make sure destroying ports wakes you up */
151*33de042dSApple OSS Distributions pthread_async(^{
152*33de042dSApple OSS Distributions sleep(1);
153*33de042dSApple OSS Distributions T_EXPECT_MACH_SUCCESS(mach_port_destruct(mach_task_self(), mp, -1, 0),
154*33de042dSApple OSS Distributions "mach_port_destruct");
155*33de042dSApple OSS Distributions });
156*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(5));
157*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 1, "kevent(port-destroyed)");
158*33de042dSApple OSS Distributions T_EXPECT_EQ(ke[0].ident, (uintptr_t)mp, "event was for the port");
159*33de042dSApple OSS Distributions
160*33de042dSApple OSS Distributions pthread_async(^{
161*33de042dSApple OSS Distributions sleep(1);
162*33de042dSApple OSS Distributions T_EXPECT_MACH_SUCCESS(mach_port_mod_refs(mach_task_self(), pset,
163*33de042dSApple OSS Distributions MACH_PORT_RIGHT_PORT_SET, -1), "destroy pset");
164*33de042dSApple OSS Distributions });
165*33de042dSApple OSS Distributions rc = kevent(kq, NULL, 0, ke, 2, &TS(5));
166*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 1, "kevent(port-destroyed)");
167*33de042dSApple OSS Distributions T_EXPECT_EQ(ke[0].ident, (uintptr_t)pset, "event was for the pset");
168*33de042dSApple OSS Distributions }
169*33de042dSApple OSS Distributions
170*33de042dSApple OSS Distributions static int
kevent_attach_event(mach_port_t port,uint16_t flags,uint32_t fflags,int * error)171*33de042dSApple OSS Distributions kevent_attach_event(mach_port_t port, uint16_t flags, uint32_t fflags, int *error)
172*33de042dSApple OSS Distributions {
173*33de042dSApple OSS Distributions int rc;
174*33de042dSApple OSS Distributions
175*33de042dSApple OSS Distributions struct kevent_qos_s kev = {
176*33de042dSApple OSS Distributions .ident = port,
177*33de042dSApple OSS Distributions .filter = EVFILT_MACHPORT,
178*33de042dSApple OSS Distributions .flags = flags,
179*33de042dSApple OSS Distributions .qos = 0xA00,
180*33de042dSApple OSS Distributions .udata = 0x6666666666666666,
181*33de042dSApple OSS Distributions .fflags = fflags,
182*33de042dSApple OSS Distributions };
183*33de042dSApple OSS Distributions
184*33de042dSApple OSS Distributions struct kevent_qos_s kev_err = {};
185*33de042dSApple OSS Distributions
186*33de042dSApple OSS Distributions rc = kevent_id(0x88888887, &kev, 1, &kev_err, 1, NULL, NULL,
187*33de042dSApple OSS Distributions KEVENT_FLAG_WORKLOOP | KEVENT_FLAG_ERROR_EVENTS);
188*33de042dSApple OSS Distributions
189*33de042dSApple OSS Distributions *error = (int)kev_err.data;
190*33de042dSApple OSS Distributions return rc;
191*33de042dSApple OSS Distributions }
192*33de042dSApple OSS Distributions
193*33de042dSApple OSS Distributions /* rdar://95680295 (Turnstile Use-after-Free in XNU) */
194*33de042dSApple OSS Distributions T_DECL(kqueue_machport_no_toggle_flags, "don't allow turnstile flags to be toggled for EVFILT_MACHPORT", T_META_TAG_VM_PREFERRED)
195*33de042dSApple OSS Distributions {
196*33de042dSApple OSS Distributions kern_return_t kr;
197*33de042dSApple OSS Distributions int rc, error = 0;
198*33de042dSApple OSS Distributions mach_port_t port = MACH_PORT_NULL;
199*33de042dSApple OSS Distributions
200*33de042dSApple OSS Distributions kr = mach_port_allocate(mach_task_self(), MACH_PORT_RIGHT_RECEIVE, &port);
201*33de042dSApple OSS Distributions T_EXPECT_MACH_SUCCESS(kr, "mach_port_allocate()");
202*33de042dSApple OSS Distributions
203*33de042dSApple OSS Distributions rc = kevent_attach_event(port, EV_ADD | EV_ENABLE | EV_DISPATCH, 0, &error);
204*33de042dSApple OSS Distributions T_EXPECT_EQ(rc, 0, "kevent attach event");
205*33de042dSApple OSS Distributions
206*33de042dSApple OSS Distributions rc = kevent_attach_event(port, 0, MACH_RCV_MSG, &error);
207*33de042dSApple OSS Distributions T_QUIET; T_EXPECT_EQ_INT(rc, 1, "registration failed");
208*33de042dSApple OSS Distributions T_EXPECT_EQ_INT(error, EINVAL, "cannot modify filter flag MACH_RCV_MSG");
209*33de042dSApple OSS Distributions
210*33de042dSApple OSS Distributions rc = kevent_attach_event(port, 0, MACH_RCV_SYNC_PEEK, &error);
211*33de042dSApple OSS Distributions T_QUIET; T_EXPECT_EQ_INT(rc, 1, "registration failed");
212*33de042dSApple OSS Distributions T_EXPECT_EQ_INT(error, EINVAL, "cannot modify filter flag MACH_RCV_SYNC_PEEK");
213*33de042dSApple OSS Distributions }
214