1*4f1223e8SApple OSS Distributions #include <assert.h>
2*4f1223e8SApple OSS Distributions #include <stdio.h>
3*4f1223e8SApple OSS Distributions #include <pthread.h>
4*4f1223e8SApple OSS Distributions #include <signal.h>
5*4f1223e8SApple OSS Distributions #include <unistd.h>
6*4f1223e8SApple OSS Distributions #include <errno.h>
7*4f1223e8SApple OSS Distributions #include <string.h>
8*4f1223e8SApple OSS Distributions #include <sys/wait.h>
9*4f1223e8SApple OSS Distributions #include <sys/types.h>
10*4f1223e8SApple OSS Distributions #include <sys/time.h>
11*4f1223e8SApple OSS Distributions #include <sys/event.h>
12*4f1223e8SApple OSS Distributions #include <sys/ptrace.h>
13*4f1223e8SApple OSS Distributions #include <sys/proc.h>
14*4f1223e8SApple OSS Distributions #include <stdlib.h>
15*4f1223e8SApple OSS Distributions #include <System/sys/codesign.h>
16*4f1223e8SApple OSS Distributions #include <darwintest.h>
17*4f1223e8SApple OSS Distributions
18*4f1223e8SApple OSS Distributions T_GLOBAL_META(T_META_NAMESPACE("xnu.note_exec"),
19*4f1223e8SApple OSS Distributions T_META_RADAR_COMPONENT_NAME("xnu"),
20*4f1223e8SApple OSS Distributions T_META_RADAR_COMPONENT_VERSION("spawn"));
21*4f1223e8SApple OSS Distributions
22*4f1223e8SApple OSS Distributions static int kq;
23*4f1223e8SApple OSS Distributions static int pid;
24*4f1223e8SApple OSS Distributions
25*4f1223e8SApple OSS Distributions static void
do_exec(void)26*4f1223e8SApple OSS Distributions do_exec(void)
27*4f1223e8SApple OSS Distributions {
28*4f1223e8SApple OSS Distributions char echo_arg[50] = "";
29*4f1223e8SApple OSS Distributions
30*4f1223e8SApple OSS Distributions snprintf(echo_arg, sizeof(echo_arg), "Child[%d] says hello after exec", getpid());
31*4f1223e8SApple OSS Distributions
32*4f1223e8SApple OSS Distributions char * new_argv[] = {
33*4f1223e8SApple OSS Distributions "/bin/echo",
34*4f1223e8SApple OSS Distributions echo_arg,
35*4f1223e8SApple OSS Distributions NULL
36*4f1223e8SApple OSS Distributions };
37*4f1223e8SApple OSS Distributions
38*4f1223e8SApple OSS Distributions int ret = execv(new_argv[0], new_argv);
39*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "execv()");
40*4f1223e8SApple OSS Distributions }
41*4f1223e8SApple OSS Distributions
42*4f1223e8SApple OSS Distributions static void *
thread_wait_exec(void * arg __unused)43*4f1223e8SApple OSS Distributions thread_wait_exec(void *arg __unused)
44*4f1223e8SApple OSS Distributions {
45*4f1223e8SApple OSS Distributions int ret;
46*4f1223e8SApple OSS Distributions struct kevent64_s kev;
47*4f1223e8SApple OSS Distributions int csret;
48*4f1223e8SApple OSS Distributions uint32_t status = 0;
49*4f1223e8SApple OSS Distributions
50*4f1223e8SApple OSS Distributions while (1) {
51*4f1223e8SApple OSS Distributions ret = kevent64(kq, NULL, 0, &kev, 1, 0, NULL);
52*4f1223e8SApple OSS Distributions if (ret == -1) {
53*4f1223e8SApple OSS Distributions if (errno == EINTR) {
54*4f1223e8SApple OSS Distributions continue;
55*4f1223e8SApple OSS Distributions }
56*4f1223e8SApple OSS Distributions }
57*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "kevent64()");
58*4f1223e8SApple OSS Distributions break;
59*4f1223e8SApple OSS Distributions }
60*4f1223e8SApple OSS Distributions
61*4f1223e8SApple OSS Distributions /* Try to get the csops of child before we print anything */
62*4f1223e8SApple OSS Distributions csret = csops(pid, CS_OPS_STATUS, &status, sizeof(status));
63*4f1223e8SApple OSS Distributions if (csret != 0) {
64*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Child exited before parent could call csops. The race didn't happen");
65*4f1223e8SApple OSS Distributions return NULL;
66*4f1223e8SApple OSS Distributions }
67*4f1223e8SApple OSS Distributions
68*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_EQ(ret, 1, "kevent64 returned 1 event as expected");
69*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_EQ((int)kev.filter, EVFILT_PROC, "EVFILT_PROC event received");
70*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_EQ((int)kev.udata, pid, "EVFILT_PROC event received for child pid");
71*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_EQ((kev.fflags & NOTE_EXEC), NOTE_EXEC, "NOTE_EXEC event received");
72*4f1223e8SApple OSS Distributions
73*4f1223e8SApple OSS Distributions /* Check that the platform binary bit is set */
74*4f1223e8SApple OSS Distributions T_EXPECT_BITS_SET(status, CS_PLATFORM_BINARY, "CS_PLATFORM_BINARY should be set on child");
75*4f1223e8SApple OSS Distributions
76*4f1223e8SApple OSS Distributions return NULL;
77*4f1223e8SApple OSS Distributions }
78*4f1223e8SApple OSS Distributions
79*4f1223e8SApple OSS Distributions static void
run_test(void)80*4f1223e8SApple OSS Distributions run_test(void)
81*4f1223e8SApple OSS Distributions {
82*4f1223e8SApple OSS Distributions struct kevent64_s kev;
83*4f1223e8SApple OSS Distributions int ret;
84*4f1223e8SApple OSS Distributions int fd[2];
85*4f1223e8SApple OSS Distributions
86*4f1223e8SApple OSS Distributions ret = pipe(fd);
87*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pipe()");
88*4f1223e8SApple OSS Distributions close(fd[0]);
89*4f1223e8SApple OSS Distributions
90*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Forking child");
91*4f1223e8SApple OSS Distributions
92*4f1223e8SApple OSS Distributions pid = fork();
93*4f1223e8SApple OSS Distributions
94*4f1223e8SApple OSS Distributions if (pid == 0) {
95*4f1223e8SApple OSS Distributions char buf[10];
96*4f1223e8SApple OSS Distributions
97*4f1223e8SApple OSS Distributions close(fd[1]);
98*4f1223e8SApple OSS Distributions ret = (int)read(fd[0], buf, sizeof(buf));
99*4f1223e8SApple OSS Distributions close(fd[0]);
100*4f1223e8SApple OSS Distributions
101*4f1223e8SApple OSS Distributions do_exec();
102*4f1223e8SApple OSS Distributions exit(1);
103*4f1223e8SApple OSS Distributions }
104*4f1223e8SApple OSS Distributions
105*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Setting up NOTE_EXEC Handler for child pid %d", pid);
106*4f1223e8SApple OSS Distributions kq = kqueue();
107*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(kq, "kqueue()");
108*4f1223e8SApple OSS Distributions
109*4f1223e8SApple OSS Distributions EV_SET64(&kev, pid, EVFILT_PROC, EV_ADD | EV_ENABLE,
110*4f1223e8SApple OSS Distributions NOTE_EXEC, 0, pid, 0, 0);
111*4f1223e8SApple OSS Distributions ret = kevent64(kq, &kev, 1, NULL, 0, 0, NULL);
112*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "kevent64()");
113*4f1223e8SApple OSS Distributions
114*4f1223e8SApple OSS Distributions pthread_t thread;
115*4f1223e8SApple OSS Distributions ret = pthread_create(&thread, NULL, thread_wait_exec, NULL);
116*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_create()");
117*4f1223e8SApple OSS Distributions
118*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Signalling child to call exec");
119*4f1223e8SApple OSS Distributions close(fd[1]);
120*4f1223e8SApple OSS Distributions
121*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Waiting for child to exit");
122*4f1223e8SApple OSS Distributions pid = waitpid(pid, NULL, 0);
123*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(pid, "waitpid()");
124*4f1223e8SApple OSS Distributions
125*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Waiting for note exec thread to exit");
126*4f1223e8SApple OSS Distributions ret = pthread_join(thread, NULL);
127*4f1223e8SApple OSS Distributions T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_join()");
128*4f1223e8SApple OSS Distributions
129*4f1223e8SApple OSS Distributions close(kq);
130*4f1223e8SApple OSS Distributions }
131*4f1223e8SApple OSS Distributions
132*4f1223e8SApple OSS Distributions T_DECL(test_note_exec, "test NOTE_EXEC race with setting csops") {
133*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Testing race for NOTE_EXEC with csops");
134*4f1223e8SApple OSS Distributions
135*4f1223e8SApple OSS Distributions for (int i = 0; i < 100; i++) {
136*4f1223e8SApple OSS Distributions T_QUIET; T_LOG("Running iteration %d", i);
137*4f1223e8SApple OSS Distributions run_test();
138*4f1223e8SApple OSS Distributions }
139*4f1223e8SApple OSS Distributions T_END;
140*4f1223e8SApple OSS Distributions }
141