xref: /xnu-11215.81.4/bsd/kern/code_signing/txm.c (revision d4514f0bc1d3f944c22d92e68b646ac3fb40d452)
1*d4514f0bSApple OSS Distributions /*
2*d4514f0bSApple OSS Distributions  * Copyright (c) 2022 Apple Computer, Inc. All rights reserved.
3*d4514f0bSApple OSS Distributions  *
4*d4514f0bSApple OSS Distributions  * @APPLE_LICENSE_HEADER_START@
5*d4514f0bSApple OSS Distributions  *
6*d4514f0bSApple OSS Distributions  * The contents of this file constitute Original Code as defined in and
7*d4514f0bSApple OSS Distributions  * are subject to the Apple Public Source License Version 1.1 (the
8*d4514f0bSApple OSS Distributions  * "License").  You may not use this file except in compliance with the
9*d4514f0bSApple OSS Distributions  * License.  Please obtain a copy of the License at
10*d4514f0bSApple OSS Distributions  * http://www.apple.com/publicsource and read it before using this file.
11*d4514f0bSApple OSS Distributions  *
12*d4514f0bSApple OSS Distributions  * This Original Code and all software distributed under the License are
13*d4514f0bSApple OSS Distributions  * distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY KIND, EITHER
14*d4514f0bSApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
15*d4514f0bSApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
16*d4514f0bSApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT.  Please see the
17*d4514f0bSApple OSS Distributions  * License for the specific language governing rights and limitations
18*d4514f0bSApple OSS Distributions  * under the License.
19*d4514f0bSApple OSS Distributions  *
20*d4514f0bSApple OSS Distributions  * @APPLE_LICENSE_HEADER_END@
21*d4514f0bSApple OSS Distributions  */
22*d4514f0bSApple OSS Distributions 
23*d4514f0bSApple OSS Distributions #include <stdarg.h>
24*d4514f0bSApple OSS Distributions #include <stdatomic.h>
25*d4514f0bSApple OSS Distributions #include <os/overflow.h>
26*d4514f0bSApple OSS Distributions #include <machine/atomic.h>
27*d4514f0bSApple OSS Distributions #include <mach/vm_param.h>
28*d4514f0bSApple OSS Distributions #include <mach/vm_map.h>
29*d4514f0bSApple OSS Distributions #include <mach/shared_region.h>
30*d4514f0bSApple OSS Distributions #include <vm/vm_kern_xnu.h>
31*d4514f0bSApple OSS Distributions #include <kern/zalloc.h>
32*d4514f0bSApple OSS Distributions #include <kern/kalloc.h>
33*d4514f0bSApple OSS Distributions #include <kern/assert.h>
34*d4514f0bSApple OSS Distributions #include <kern/locks.h>
35*d4514f0bSApple OSS Distributions #include <kern/recount.h>
36*d4514f0bSApple OSS Distributions #include <kern/sched_prim.h>
37*d4514f0bSApple OSS Distributions #include <kern/lock_rw.h>
38*d4514f0bSApple OSS Distributions #include <libkern/libkern.h>
39*d4514f0bSApple OSS Distributions #include <libkern/section_keywords.h>
40*d4514f0bSApple OSS Distributions #include <libkern/coretrust/coretrust.h>
41*d4514f0bSApple OSS Distributions #include <libkern/amfi/amfi.h>
42*d4514f0bSApple OSS Distributions #include <pexpert/pexpert.h>
43*d4514f0bSApple OSS Distributions #include <sys/vm.h>
44*d4514f0bSApple OSS Distributions #include <sys/proc.h>
45*d4514f0bSApple OSS Distributions #include <sys/codesign.h>
46*d4514f0bSApple OSS Distributions #include <sys/code_signing.h>
47*d4514f0bSApple OSS Distributions #include <sys/sysctl.h>
48*d4514f0bSApple OSS Distributions #include <uuid/uuid.h>
49*d4514f0bSApple OSS Distributions #include <IOKit/IOLib.h>
50*d4514f0bSApple OSS Distributions #include <IOKit/IOBSD.h>
51*d4514f0bSApple OSS Distributions 
52*d4514f0bSApple OSS Distributions #if CONFIG_SPTM
53*d4514f0bSApple OSS Distributions /*
54*d4514f0bSApple OSS Distributions  * The TrustedExecutionMonitor environment works in tandem with the SPTM to provide code
55*d4514f0bSApple OSS Distributions  * signing and memory isolation enforcement for data structures critical to ensuring that
56*d4514f0bSApple OSS Distributions  * all code executed on the system is authorized to do so.
57*d4514f0bSApple OSS Distributions  *
58*d4514f0bSApple OSS Distributions  * Unless the data is managed by TXM itself, XNU needs to page-align everything, make the
59*d4514f0bSApple OSS Distributions  * relevant type transfer, and then reference the memory as read-only.
60*d4514f0bSApple OSS Distributions  *
61*d4514f0bSApple OSS Distributions  * TXM enforces concurrency on its side, but through the use of try-locks. Upon a failure
62*d4514f0bSApple OSS Distributions  * in acquiring the lock, TXM will panic. As a result, in order to ensure single-threaded
63*d4514f0bSApple OSS Distributions  * behavior, the kernel also has to take some locks on its side befor calling into TXM.
64*d4514f0bSApple OSS Distributions  */
65*d4514f0bSApple OSS Distributions #include <sys/trusted_execution_monitor.h>
66*d4514f0bSApple OSS Distributions #include <pexpert/arm64/board_config.h>
67*d4514f0bSApple OSS Distributions 
68*d4514f0bSApple OSS Distributions /* Lock group used for all locks within the kernel for TXM */
69*d4514f0bSApple OSS Distributions LCK_GRP_DECLARE(txm_lck_grp, "txm_code_signing_lck_grp");
70*d4514f0bSApple OSS Distributions 
71*d4514f0bSApple OSS Distributions #pragma mark Utilities
72*d4514f0bSApple OSS Distributions 
73*d4514f0bSApple OSS Distributions /* Number of thread stacks is known at build-time */
74*d4514f0bSApple OSS Distributions #define NUM_TXM_THREAD_STACKS (MAX_CPUS)
75*d4514f0bSApple OSS Distributions txm_thread_stack_t thread_stacks[NUM_TXM_THREAD_STACKS] = {0};
76*d4514f0bSApple OSS Distributions 
77*d4514f0bSApple OSS Distributions /* Singly-linked-list head for thread stacks */
78*d4514f0bSApple OSS Distributions SLIST_HEAD(thread_stack_head, _txm_thread_stack) thread_stacks_head =
79*d4514f0bSApple OSS Distributions     SLIST_HEAD_INITIALIZER(thread_stacks_head);
80*d4514f0bSApple OSS Distributions 
81*d4514f0bSApple OSS Distributions static decl_lck_mtx_data(, thread_stacks_lock);
82*d4514f0bSApple OSS Distributions static void *thread_stack_event = NULL;
83*d4514f0bSApple OSS Distributions 
84*d4514f0bSApple OSS Distributions static void
setup_thread_stacks(void)85*d4514f0bSApple OSS Distributions setup_thread_stacks(void)
86*d4514f0bSApple OSS Distributions {
87*d4514f0bSApple OSS Distributions 	extern const sptm_bootstrap_args_xnu_t *SPTMArgs;
88*d4514f0bSApple OSS Distributions 	txm_thread_stack_t *thread_stack = NULL;
89*d4514f0bSApple OSS Distributions 
90*d4514f0bSApple OSS Distributions 	/* Initialize each thread stack and add it to the list */
91*d4514f0bSApple OSS Distributions 	for (uint32_t i = 0; i < NUM_TXM_THREAD_STACKS; i++) {
92*d4514f0bSApple OSS Distributions 		thread_stack = &thread_stacks[i];
93*d4514f0bSApple OSS Distributions 
94*d4514f0bSApple OSS Distributions 		/* Acquire the thread stack virtual mapping */
95*d4514f0bSApple OSS Distributions 		thread_stack->thread_stack_papt = SPTMArgs->txm_thread_stacks[i];
96*d4514f0bSApple OSS Distributions 
97*d4514f0bSApple OSS Distributions 		/* Acquire the thread stack physical page */
98*d4514f0bSApple OSS Distributions 		thread_stack->thread_stack_phys = (uintptr_t)kvtophys_nofail(
99*d4514f0bSApple OSS Distributions 			thread_stack->thread_stack_papt);
100*d4514f0bSApple OSS Distributions 
101*d4514f0bSApple OSS Distributions 		/* Resolve the pointer to the thread stack data */
102*d4514f0bSApple OSS Distributions 		thread_stack->thread_stack_data =
103*d4514f0bSApple OSS Distributions 		    (TXMThreadStack_t*)(thread_stack->thread_stack_papt + (PAGE_SIZE - 1024));
104*d4514f0bSApple OSS Distributions 
105*d4514f0bSApple OSS Distributions 		/* Add thread stack to the list head */
106*d4514f0bSApple OSS Distributions 		SLIST_INSERT_HEAD(&thread_stacks_head, thread_stack, link);
107*d4514f0bSApple OSS Distributions 	}
108*d4514f0bSApple OSS Distributions 
109*d4514f0bSApple OSS Distributions 	/* Initialize the thread stacks lock */
110*d4514f0bSApple OSS Distributions 	lck_mtx_init(&thread_stacks_lock, &txm_lck_grp, 0);
111*d4514f0bSApple OSS Distributions }
112*d4514f0bSApple OSS Distributions 
113*d4514f0bSApple OSS Distributions static txm_thread_stack_t*
acquire_thread_stack(void)114*d4514f0bSApple OSS Distributions acquire_thread_stack(void)
115*d4514f0bSApple OSS Distributions {
116*d4514f0bSApple OSS Distributions 	txm_thread_stack_t *thread_stack = NULL;
117*d4514f0bSApple OSS Distributions 
118*d4514f0bSApple OSS Distributions 	/* Lock the thread stack list */
119*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&thread_stacks_lock);
120*d4514f0bSApple OSS Distributions 
121*d4514f0bSApple OSS Distributions 	while (SLIST_EMPTY(&thread_stacks_head) == true) {
122*d4514f0bSApple OSS Distributions 		lck_mtx_sleep(
123*d4514f0bSApple OSS Distributions 			&thread_stacks_lock,
124*d4514f0bSApple OSS Distributions 			LCK_SLEEP_DEFAULT,
125*d4514f0bSApple OSS Distributions 			&thread_stack_event,
126*d4514f0bSApple OSS Distributions 			THREAD_UNINT);
127*d4514f0bSApple OSS Distributions 	}
128*d4514f0bSApple OSS Distributions 
129*d4514f0bSApple OSS Distributions 	if (SLIST_EMPTY(&thread_stacks_head) == true) {
130*d4514f0bSApple OSS Distributions 		panic("unable to acquire a thread stack for TXM");
131*d4514f0bSApple OSS Distributions 	}
132*d4514f0bSApple OSS Distributions 
133*d4514f0bSApple OSS Distributions 	/* Use the first available thread stack */
134*d4514f0bSApple OSS Distributions 	thread_stack = SLIST_FIRST(&thread_stacks_head);
135*d4514f0bSApple OSS Distributions 
136*d4514f0bSApple OSS Distributions 	/* Remove the thread stack from the list */
137*d4514f0bSApple OSS Distributions 	SLIST_REMOVE_HEAD(&thread_stacks_head, link);
138*d4514f0bSApple OSS Distributions 
139*d4514f0bSApple OSS Distributions 	/* Unlock the thread stack list */
140*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&thread_stacks_lock);
141*d4514f0bSApple OSS Distributions 
142*d4514f0bSApple OSS Distributions 	/* Associate the thread stack with the current thread */
143*d4514f0bSApple OSS Distributions 	thread_associate_txm_thread_stack(thread_stack->thread_stack_phys);
144*d4514f0bSApple OSS Distributions 
145*d4514f0bSApple OSS Distributions 	return thread_stack;
146*d4514f0bSApple OSS Distributions }
147*d4514f0bSApple OSS Distributions 
148*d4514f0bSApple OSS Distributions static void
release_thread_stack(txm_thread_stack_t * thread_stack)149*d4514f0bSApple OSS Distributions release_thread_stack(
150*d4514f0bSApple OSS Distributions 	txm_thread_stack_t* thread_stack)
151*d4514f0bSApple OSS Distributions {
152*d4514f0bSApple OSS Distributions 	/* Remove the TXM thread stack association with the current thread */
153*d4514f0bSApple OSS Distributions 	thread_disassociate_txm_thread_stack(thread_stack->thread_stack_phys);
154*d4514f0bSApple OSS Distributions 
155*d4514f0bSApple OSS Distributions 	/* Lock the thread stack list */
156*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&thread_stacks_lock);
157*d4514f0bSApple OSS Distributions 
158*d4514f0bSApple OSS Distributions 	/* Add the thread stack at the list head */
159*d4514f0bSApple OSS Distributions 	SLIST_INSERT_HEAD(&thread_stacks_head, thread_stack, link);
160*d4514f0bSApple OSS Distributions 
161*d4514f0bSApple OSS Distributions 	/* Unlock the thread stack list */
162*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&thread_stacks_lock);
163*d4514f0bSApple OSS Distributions 
164*d4514f0bSApple OSS Distributions 	/* Wake up any threads waiting to acquire a thread stack */
165*d4514f0bSApple OSS Distributions 	thread_wakeup(&thread_stack_event);
166*d4514f0bSApple OSS Distributions }
167*d4514f0bSApple OSS Distributions 
168*d4514f0bSApple OSS Distributions static kern_return_t
txm_parse_return(TXMReturn_t txm_ret)169*d4514f0bSApple OSS Distributions txm_parse_return(
170*d4514f0bSApple OSS Distributions 	TXMReturn_t txm_ret)
171*d4514f0bSApple OSS Distributions {
172*d4514f0bSApple OSS Distributions 	switch (txm_ret.returnCode) {
173*d4514f0bSApple OSS Distributions 	case kTXMSuccess:
174*d4514f0bSApple OSS Distributions 		return KERN_SUCCESS;
175*d4514f0bSApple OSS Distributions 
176*d4514f0bSApple OSS Distributions 	case kTXMReturnOutOfMemory:
177*d4514f0bSApple OSS Distributions 		return KERN_RESOURCE_SHORTAGE;
178*d4514f0bSApple OSS Distributions 
179*d4514f0bSApple OSS Distributions 	case kTXMReturnNotFound:
180*d4514f0bSApple OSS Distributions 		return KERN_NOT_FOUND;
181*d4514f0bSApple OSS Distributions 
182*d4514f0bSApple OSS Distributions 	case kTXMReturnNotSupported:
183*d4514f0bSApple OSS Distributions 		return KERN_NOT_SUPPORTED;
184*d4514f0bSApple OSS Distributions 
185*d4514f0bSApple OSS Distributions #if kTXMKernelAPIVersion >= 6
186*d4514f0bSApple OSS Distributions 	case kTXMReturnTryAgain:
187*d4514f0bSApple OSS Distributions 		return KERN_OPERATION_TIMED_OUT;
188*d4514f0bSApple OSS Distributions #endif
189*d4514f0bSApple OSS Distributions 
190*d4514f0bSApple OSS Distributions 	default:
191*d4514f0bSApple OSS Distributions 		return KERN_FAILURE;
192*d4514f0bSApple OSS Distributions 	}
193*d4514f0bSApple OSS Distributions }
194*d4514f0bSApple OSS Distributions 
195*d4514f0bSApple OSS Distributions static void
txm_print_return(TXMKernelSelector_t selector,TXMReturn_t txm_ret)196*d4514f0bSApple OSS Distributions txm_print_return(
197*d4514f0bSApple OSS Distributions 	TXMKernelSelector_t selector,
198*d4514f0bSApple OSS Distributions 	TXMReturn_t txm_ret)
199*d4514f0bSApple OSS Distributions {
200*d4514f0bSApple OSS Distributions 	/*
201*d4514f0bSApple OSS Distributions 	 * We specifically use IOLog instead of printf since printf is compiled out on
202*d4514f0bSApple OSS Distributions 	 * RELEASE kernels. We want to ensure that errors from TXM are captured within
203*d4514f0bSApple OSS Distributions 	 * sysdiagnoses from the field.
204*d4514f0bSApple OSS Distributions 	 */
205*d4514f0bSApple OSS Distributions 
206*d4514f0bSApple OSS Distributions 	if (txm_ret.returnCode == kTXMSuccess) {
207*d4514f0bSApple OSS Distributions 		return;
208*d4514f0bSApple OSS Distributions 	} else if (txm_ret.returnCode == kTXMReturnTrustCache) {
209*d4514f0bSApple OSS Distributions 		IOLog("TXM [Error]: TrustCache: selector: %u | 0x%02X | 0x%02X | %u\n",
210*d4514f0bSApple OSS Distributions 		    selector, txm_ret.tcRet.component, txm_ret.tcRet.error, txm_ret.tcRet.uniqueError);
211*d4514f0bSApple OSS Distributions 	} else if (txm_ret.returnCode == kTXMReturnCodeSignature) {
212*d4514f0bSApple OSS Distributions 		IOLog("TXM [Error]: CodeSignature: selector: %u | 0x%02X | 0x%02X | %u\n",
213*d4514f0bSApple OSS Distributions 		    selector, txm_ret.csRet.component, txm_ret.csRet.error, txm_ret.csRet.uniqueError);
214*d4514f0bSApple OSS Distributions 	} else if (txm_ret.returnCode == kTXMReturnCodeErrno) {
215*d4514f0bSApple OSS Distributions 		IOLog("TXM [Error]: Errno: selector: %u | %d\n",
216*d4514f0bSApple OSS Distributions 		    selector, txm_ret.errnoRet);
217*d4514f0bSApple OSS Distributions 	} else {
218*d4514f0bSApple OSS Distributions 		IOLog("TXM [Error]: selector: %u | %u\n",
219*d4514f0bSApple OSS Distributions 		    selector, txm_ret.returnCode);
220*d4514f0bSApple OSS Distributions 	}
221*d4514f0bSApple OSS Distributions }
222*d4514f0bSApple OSS Distributions 
223*d4514f0bSApple OSS Distributions #pragma mark Page Allocation
224*d4514f0bSApple OSS Distributions 
225*d4514f0bSApple OSS Distributions static void
txm_add_page(void)226*d4514f0bSApple OSS Distributions txm_add_page(void)
227*d4514f0bSApple OSS Distributions {
228*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
229*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAddFreeListPage,
230*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
231*d4514f0bSApple OSS Distributions 		.num_input_args = 1
232*d4514f0bSApple OSS Distributions 	};
233*d4514f0bSApple OSS Distributions 
234*d4514f0bSApple OSS Distributions 	/* Allocate a page from the VM -- transfers page to TXM internally */
235*d4514f0bSApple OSS Distributions 	vm_map_address_t phys_addr = pmap_txm_allocate_page();
236*d4514f0bSApple OSS Distributions 
237*d4514f0bSApple OSS Distributions 	/* Add this page to the TXM free list */
238*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, phys_addr);
239*d4514f0bSApple OSS Distributions }
240*d4514f0bSApple OSS Distributions 
241*d4514f0bSApple OSS Distributions #pragma mark Calls
242*d4514f0bSApple OSS Distributions 
243*d4514f0bSApple OSS Distributions static void
txm_kernel_call_registers_setup(txm_call_t * parameters,sptm_call_regs_t * registers,va_list args)244*d4514f0bSApple OSS Distributions txm_kernel_call_registers_setup(
245*d4514f0bSApple OSS Distributions 	txm_call_t *parameters,
246*d4514f0bSApple OSS Distributions 	sptm_call_regs_t *registers,
247*d4514f0bSApple OSS Distributions 	va_list args)
248*d4514f0bSApple OSS Distributions {
249*d4514f0bSApple OSS Distributions 	/*
250*d4514f0bSApple OSS Distributions 	 * We are only ever allowed a maximum of 7 arguments for calling into TXM.
251*d4514f0bSApple OSS Distributions 	 * This is because the SPTM dispatch only sets up registers x0-x7 for the
252*d4514f0bSApple OSS Distributions 	 * call, and x0 is always reserved for passing in a thread stack for TXM
253*d4514f0bSApple OSS Distributions 	 * to operate on.
254*d4514f0bSApple OSS Distributions 	 */
255*d4514f0bSApple OSS Distributions 
256*d4514f0bSApple OSS Distributions 	switch (parameters->num_input_args) {
257*d4514f0bSApple OSS Distributions 	case 7:
258*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
259*d4514f0bSApple OSS Distributions 		registers->x2 = va_arg(args, uintptr_t);
260*d4514f0bSApple OSS Distributions 		registers->x3 = va_arg(args, uintptr_t);
261*d4514f0bSApple OSS Distributions 		registers->x4 = va_arg(args, uintptr_t);
262*d4514f0bSApple OSS Distributions 		registers->x5 = va_arg(args, uintptr_t);
263*d4514f0bSApple OSS Distributions 		registers->x6 = va_arg(args, uintptr_t);
264*d4514f0bSApple OSS Distributions 		registers->x7 = va_arg(args, uintptr_t);
265*d4514f0bSApple OSS Distributions 		break;
266*d4514f0bSApple OSS Distributions 
267*d4514f0bSApple OSS Distributions 	case 6:
268*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
269*d4514f0bSApple OSS Distributions 		registers->x2 = va_arg(args, uintptr_t);
270*d4514f0bSApple OSS Distributions 		registers->x3 = va_arg(args, uintptr_t);
271*d4514f0bSApple OSS Distributions 		registers->x4 = va_arg(args, uintptr_t);
272*d4514f0bSApple OSS Distributions 		registers->x5 = va_arg(args, uintptr_t);
273*d4514f0bSApple OSS Distributions 		registers->x6 = va_arg(args, uintptr_t);
274*d4514f0bSApple OSS Distributions 		break;
275*d4514f0bSApple OSS Distributions 
276*d4514f0bSApple OSS Distributions 	case 5:
277*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
278*d4514f0bSApple OSS Distributions 		registers->x2 = va_arg(args, uintptr_t);
279*d4514f0bSApple OSS Distributions 		registers->x3 = va_arg(args, uintptr_t);
280*d4514f0bSApple OSS Distributions 		registers->x4 = va_arg(args, uintptr_t);
281*d4514f0bSApple OSS Distributions 		registers->x5 = va_arg(args, uintptr_t);
282*d4514f0bSApple OSS Distributions 		break;
283*d4514f0bSApple OSS Distributions 
284*d4514f0bSApple OSS Distributions 	case 4:
285*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
286*d4514f0bSApple OSS Distributions 		registers->x2 = va_arg(args, uintptr_t);
287*d4514f0bSApple OSS Distributions 		registers->x3 = va_arg(args, uintptr_t);
288*d4514f0bSApple OSS Distributions 		registers->x4 = va_arg(args, uintptr_t);
289*d4514f0bSApple OSS Distributions 		break;
290*d4514f0bSApple OSS Distributions 
291*d4514f0bSApple OSS Distributions 	case 3:
292*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
293*d4514f0bSApple OSS Distributions 		registers->x2 = va_arg(args, uintptr_t);
294*d4514f0bSApple OSS Distributions 		registers->x3 = va_arg(args, uintptr_t);
295*d4514f0bSApple OSS Distributions 		break;
296*d4514f0bSApple OSS Distributions 
297*d4514f0bSApple OSS Distributions 	case 2:
298*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
299*d4514f0bSApple OSS Distributions 		registers->x2 = va_arg(args, uintptr_t);
300*d4514f0bSApple OSS Distributions 		break;
301*d4514f0bSApple OSS Distributions 
302*d4514f0bSApple OSS Distributions 	case 1:
303*d4514f0bSApple OSS Distributions 		registers->x1 = va_arg(args, uintptr_t);
304*d4514f0bSApple OSS Distributions 		break;
305*d4514f0bSApple OSS Distributions 
306*d4514f0bSApple OSS Distributions 	case 0:
307*d4514f0bSApple OSS Distributions 		break;
308*d4514f0bSApple OSS Distributions 
309*d4514f0bSApple OSS Distributions 	default:
310*d4514f0bSApple OSS Distributions 		panic("invalid number of arguments to TXM: selector: %u | %u",
311*d4514f0bSApple OSS Distributions 		    parameters->selector, parameters->num_input_args);
312*d4514f0bSApple OSS Distributions 	}
313*d4514f0bSApple OSS Distributions }
314*d4514f0bSApple OSS Distributions 
315*d4514f0bSApple OSS Distributions static TXMReturn_t
txm_kernel_call_internal(txm_call_t * parameters,va_list args)316*d4514f0bSApple OSS Distributions txm_kernel_call_internal(
317*d4514f0bSApple OSS Distributions 	txm_call_t *parameters,
318*d4514f0bSApple OSS Distributions 	va_list args)
319*d4514f0bSApple OSS Distributions {
320*d4514f0bSApple OSS Distributions 	TXMReturn_t txm_ret = (TXMReturn_t){.returnCode = kTXMReturnGeneric};
321*d4514f0bSApple OSS Distributions 	sptm_call_regs_t txm_registers = {0};
322*d4514f0bSApple OSS Distributions 	txm_thread_stack_t *thread_stack = NULL;
323*d4514f0bSApple OSS Distributions 	const TXMThreadStack_t *thread_stack_data = NULL;
324*d4514f0bSApple OSS Distributions 	const TXMSharedContextData_t *shared_context_data = NULL;
325*d4514f0bSApple OSS Distributions 
326*d4514f0bSApple OSS Distributions 	/* Obtain a stack for this call */
327*d4514f0bSApple OSS Distributions 	thread_stack = acquire_thread_stack();
328*d4514f0bSApple OSS Distributions 	thread_stack_data = thread_stack->thread_stack_data;
329*d4514f0bSApple OSS Distributions 	shared_context_data = &thread_stack_data->sharedData;
330*d4514f0bSApple OSS Distributions 
331*d4514f0bSApple OSS Distributions 	/* Setup argument registers */
332*d4514f0bSApple OSS Distributions 	txm_registers.x0 = thread_stack->thread_stack_phys;
333*d4514f0bSApple OSS Distributions 	txm_kernel_call_registers_setup(parameters, &txm_registers, args);
334*d4514f0bSApple OSS Distributions 
335*d4514f0bSApple OSS Distributions 	/* Track resource usage */
336*d4514f0bSApple OSS Distributions 	recount_enter_secure();
337*d4514f0bSApple OSS Distributions 
338*d4514f0bSApple OSS Distributions 	/* Call into TXM */
339*d4514f0bSApple OSS Distributions 	txm_enter(parameters->selector, &txm_registers);
340*d4514f0bSApple OSS Distributions 
341*d4514f0bSApple OSS Distributions 	recount_leave_secure();
342*d4514f0bSApple OSS Distributions 
343*d4514f0bSApple OSS Distributions 	txm_ret = (TXMReturn_t){.rawValue = shared_context_data->txmReturnCode};
344*d4514f0bSApple OSS Distributions 	parameters->txm_ret = txm_ret;
345*d4514f0bSApple OSS Distributions 
346*d4514f0bSApple OSS Distributions 	if (parameters->txm_ret.returnCode == kTXMSuccess) {
347*d4514f0bSApple OSS Distributions 		parameters->num_return_words = shared_context_data->txmNumReturnWords;
348*d4514f0bSApple OSS Distributions 		if (parameters->num_return_words > kTXMStackReturnWords) {
349*d4514f0bSApple OSS Distributions 			panic("received excessive return words from TXM: selector: %u | %llu",
350*d4514f0bSApple OSS Distributions 			    parameters->selector, parameters->num_return_words);
351*d4514f0bSApple OSS Distributions 		}
352*d4514f0bSApple OSS Distributions 
353*d4514f0bSApple OSS Distributions 		for (uint64_t i = 0; i < parameters->num_return_words; i++) {
354*d4514f0bSApple OSS Distributions 			parameters->return_words[i] = shared_context_data->txmReturnWords[i];
355*d4514f0bSApple OSS Distributions 		}
356*d4514f0bSApple OSS Distributions 	}
357*d4514f0bSApple OSS Distributions 
358*d4514f0bSApple OSS Distributions 	/* Release the thread stack as it is no longer needed */
359*d4514f0bSApple OSS Distributions 	release_thread_stack(thread_stack);
360*d4514f0bSApple OSS Distributions 	thread_stack_data = NULL;
361*d4514f0bSApple OSS Distributions 	shared_context_data = NULL;
362*d4514f0bSApple OSS Distributions 
363*d4514f0bSApple OSS Distributions 	return txm_ret;
364*d4514f0bSApple OSS Distributions }
365*d4514f0bSApple OSS Distributions 
366*d4514f0bSApple OSS Distributions kern_return_t
txm_kernel_call(txm_call_t * parameters,...)367*d4514f0bSApple OSS Distributions txm_kernel_call(
368*d4514f0bSApple OSS Distributions 	txm_call_t *parameters, ...)
369*d4514f0bSApple OSS Distributions {
370*d4514f0bSApple OSS Distributions 	TXMReturn_t txm_ret = (TXMReturn_t){.returnCode = kTXMReturnGeneric};
371*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
372*d4514f0bSApple OSS Distributions 	va_list args;
373*d4514f0bSApple OSS Distributions 
374*d4514f0bSApple OSS Distributions 	/* Start the variadic arguments list */
375*d4514f0bSApple OSS Distributions 	va_start(args, parameters);
376*d4514f0bSApple OSS Distributions 
377*d4514f0bSApple OSS Distributions 	do {
378*d4514f0bSApple OSS Distributions 		txm_ret = txm_kernel_call_internal(parameters, args);
379*d4514f0bSApple OSS Distributions 		if (txm_ret.returnCode == kTXMReturnOutOfMemory) {
380*d4514f0bSApple OSS Distributions 			if (parameters->selector == kTXMKernelSelectorAddFreeListPage) {
381*d4514f0bSApple OSS Distributions 				panic("received out-of-memory error when adding a free page to TXM");
382*d4514f0bSApple OSS Distributions 			}
383*d4514f0bSApple OSS Distributions 			txm_add_page();
384*d4514f0bSApple OSS Distributions 		}
385*d4514f0bSApple OSS Distributions 	} while (txm_ret.returnCode == kTXMReturnOutOfMemory);
386*d4514f0bSApple OSS Distributions 
387*d4514f0bSApple OSS Distributions 	/* Clean up the variadic arguments list */
388*d4514f0bSApple OSS Distributions 	va_end(args);
389*d4514f0bSApple OSS Distributions 
390*d4514f0bSApple OSS Distributions 	/* Print all TXM logs from the log buffer */
391*d4514f0bSApple OSS Distributions 	if (parameters->skip_logs == false) {
392*d4514f0bSApple OSS Distributions 		txm_print_logs();
393*d4514f0bSApple OSS Distributions 	}
394*d4514f0bSApple OSS Distributions 
395*d4514f0bSApple OSS Distributions 	/* Print the return code from TXM -- only prints for an error */
396*d4514f0bSApple OSS Distributions 	if (parameters->failure_silent != true) {
397*d4514f0bSApple OSS Distributions 		if (parameters->failure_code_silent != txm_ret.returnCode) {
398*d4514f0bSApple OSS Distributions 			txm_print_return(parameters->selector, txm_ret);
399*d4514f0bSApple OSS Distributions 		}
400*d4514f0bSApple OSS Distributions 	}
401*d4514f0bSApple OSS Distributions 
402*d4514f0bSApple OSS Distributions 	/*
403*d4514f0bSApple OSS Distributions 	 * To ease the process of calling into TXM, and to also reduce the number of
404*d4514f0bSApple OSS Distributions 	 * lines of code for each call site, the txm_call_t offers some properties
405*d4514f0bSApple OSS Distributions 	 * we can enforce over here. Go through these, and panic in case they aren't
406*d4514f0bSApple OSS Distributions 	 * honored.
407*d4514f0bSApple OSS Distributions 	 *
408*d4514f0bSApple OSS Distributions 	 * NOTE: We check for "<" instead of "!=" for the number of return words we
409*d4514f0bSApple OSS Distributions 	 * get back from TXM since this helps in forward development. If the kernel
410*d4514f0bSApple OSS Distributions 	 * and TXM are proceeding at different project cadences, we do not want to
411*d4514f0bSApple OSS Distributions 	 * gate adding more return words from TXM on the kernel first adopting the
412*d4514f0bSApple OSS Distributions 	 * new number of return words.
413*d4514f0bSApple OSS Distributions 	 */
414*d4514f0bSApple OSS Distributions 	ret = txm_parse_return(txm_ret);
415*d4514f0bSApple OSS Distributions 
416*d4514f0bSApple OSS Distributions 	if (parameters->failure_fatal && (ret != KERN_SUCCESS)) {
417*d4514f0bSApple OSS Distributions 		panic("received fatal error for a selector from TXM: selector: %u | 0x%0llX",
418*d4514f0bSApple OSS Distributions 		    parameters->selector, txm_ret.rawValue);
419*d4514f0bSApple OSS Distributions 	} else if (parameters->num_return_words < parameters->num_output_args) {
420*d4514f0bSApple OSS Distributions 		/* Only panic if return was a success */
421*d4514f0bSApple OSS Distributions 		if (ret == KERN_SUCCESS) {
422*d4514f0bSApple OSS Distributions 			panic("received fewer than expected return words from TXM: selector: %u | %llu",
423*d4514f0bSApple OSS Distributions 			    parameters->selector, parameters->num_return_words);
424*d4514f0bSApple OSS Distributions 		}
425*d4514f0bSApple OSS Distributions 	}
426*d4514f0bSApple OSS Distributions 
427*d4514f0bSApple OSS Distributions 	return ret;
428*d4514f0bSApple OSS Distributions }
429*d4514f0bSApple OSS Distributions 
430*d4514f0bSApple OSS Distributions void
txm_transfer_region(vm_address_t addr,vm_size_t size)431*d4514f0bSApple OSS Distributions txm_transfer_region(
432*d4514f0bSApple OSS Distributions 	vm_address_t addr,
433*d4514f0bSApple OSS Distributions 	vm_size_t size)
434*d4514f0bSApple OSS Distributions {
435*d4514f0bSApple OSS Distributions 	vm_address_t addr_end = 0;
436*d4514f0bSApple OSS Distributions 	vm_size_t size_aligned = round_page(size);
437*d4514f0bSApple OSS Distributions 
438*d4514f0bSApple OSS Distributions 	if ((addr & PAGE_MASK) != 0) {
439*d4514f0bSApple OSS Distributions 		panic("attempted to transfer non-page-aligned memory to TXM: %p", (void*)addr);
440*d4514f0bSApple OSS Distributions 	} else if (os_add_overflow(addr, size_aligned, &addr_end)) {
441*d4514f0bSApple OSS Distributions 		panic("overflow on range to be transferred to TXM: %p | %lu",
442*d4514f0bSApple OSS Distributions 		    (void*)addr, size);
443*d4514f0bSApple OSS Distributions 	}
444*d4514f0bSApple OSS Distributions 
445*d4514f0bSApple OSS Distributions 	/* Make the memory read-only first (transfer will panic otherwise) */
446*d4514f0bSApple OSS Distributions 	vm_protect(kernel_map, addr, size_aligned, false, VM_PROT_READ);
447*d4514f0bSApple OSS Distributions 
448*d4514f0bSApple OSS Distributions 	/* Transfer each physical page to be TXM_DEFAULT */
449*d4514f0bSApple OSS Distributions 	for (vm_address_t page = addr; page < addr_end; page += PAGE_SIZE) {
450*d4514f0bSApple OSS Distributions 		pmap_txm_transfer_page(page);
451*d4514f0bSApple OSS Distributions 	}
452*d4514f0bSApple OSS Distributions }
453*d4514f0bSApple OSS Distributions 
454*d4514f0bSApple OSS Distributions void
txm_reclaim_region(vm_address_t addr,vm_size_t size)455*d4514f0bSApple OSS Distributions txm_reclaim_region(
456*d4514f0bSApple OSS Distributions 	vm_address_t addr,
457*d4514f0bSApple OSS Distributions 	vm_size_t size)
458*d4514f0bSApple OSS Distributions {
459*d4514f0bSApple OSS Distributions 	vm_address_t addr_end = 0;
460*d4514f0bSApple OSS Distributions 	vm_size_t size_aligned = round_page(size);
461*d4514f0bSApple OSS Distributions 
462*d4514f0bSApple OSS Distributions 	if ((addr & PAGE_MASK) != 0) {
463*d4514f0bSApple OSS Distributions 		panic("attempted to reclaim non-page-aligned memory from TXM: %p", (void*)addr);
464*d4514f0bSApple OSS Distributions 	} else if (os_add_overflow(addr, size_aligned, &addr_end)) {
465*d4514f0bSApple OSS Distributions 		panic("overflow on range to be reclaimed from TXM: %p | %lu",
466*d4514f0bSApple OSS Distributions 		    (void*)addr, size);
467*d4514f0bSApple OSS Distributions 	}
468*d4514f0bSApple OSS Distributions 
469*d4514f0bSApple OSS Distributions 	/*
470*d4514f0bSApple OSS Distributions 	 * We can only reclaim once TXM has transferred the memory range back to the
471*d4514f0bSApple OSS Distributions 	 * kernel. Hence, we simply try and switch permissions to read-write. If TXM
472*d4514f0bSApple OSS Distributions 	 * hasn't transferred pages, this then should panic.
473*d4514f0bSApple OSS Distributions 	 */
474*d4514f0bSApple OSS Distributions 	vm_protect(kernel_map, addr, size_aligned, false, VM_PROT_READ | VM_PROT_WRITE);
475*d4514f0bSApple OSS Distributions }
476*d4514f0bSApple OSS Distributions 
477*d4514f0bSApple OSS Distributions static SECURITY_READ_ONLY_LATE(const char*) txm_log_page = NULL;
478*d4514f0bSApple OSS Distributions static SECURITY_READ_ONLY_LATE(const uint32_t*) txm_log_head = NULL;
479*d4514f0bSApple OSS Distributions static SECURITY_READ_ONLY_LATE(const uint32_t*) txm_log_sync = NULL;
480*d4514f0bSApple OSS Distributions 
481*d4514f0bSApple OSS Distributions static decl_lck_mtx_data(, log_lock);
482*d4514f0bSApple OSS Distributions static uint32_t log_head = 0;
483*d4514f0bSApple OSS Distributions 
484*d4514f0bSApple OSS Distributions void
txm_print_logs(void)485*d4514f0bSApple OSS Distributions txm_print_logs(void)
486*d4514f0bSApple OSS Distributions {
487*d4514f0bSApple OSS Distributions 	uint32_t start_index = 0;
488*d4514f0bSApple OSS Distributions 	uint32_t end_index = 0;
489*d4514f0bSApple OSS Distributions 
490*d4514f0bSApple OSS Distributions 	/*
491*d4514f0bSApple OSS Distributions 	 * The design here is very simple. TXM keeps adding slots to its circular buffer
492*d4514f0bSApple OSS Distributions 	 * and the kernel attempts to read each one and print it, maintaining its own head
493*d4514f0bSApple OSS Distributions 	 * for the log.
494*d4514f0bSApple OSS Distributions 	 *
495*d4514f0bSApple OSS Distributions 	 * This design is by nature lazy. TXM doesn't know or care if the kernel has gone
496*d4514f0bSApple OSS Distributions 	 * through and printed any of the logs, so it'll just keep writing into its buffer
497*d4514f0bSApple OSS Distributions 	 * and then circle around when it becomes full.
498*d4514f0bSApple OSS Distributions 	 *
499*d4514f0bSApple OSS Distributions 	 * This is fine most of the time since there are a decent amount of slots in the
500*d4514f0bSApple OSS Distributions 	 * log buffer. We mostly have an issue when TXM is adding so many logs so quickly
501*d4514f0bSApple OSS Distributions 	 * such that it wraps around and starts overwriting logs which haven't been seen
502*d4514f0bSApple OSS Distributions 	 * by the kernel. If this were to happen, TXM's log head may circle around the
503*d4514f0bSApple OSS Distributions 	 * head maintained by the kernel, causing a lot of logs to be missed, since the
504*d4514f0bSApple OSS Distributions 	 * kernel only attempts the number of logs in-between the two heads.
505*d4514f0bSApple OSS Distributions 	 *
506*d4514f0bSApple OSS Distributions 	 * The fix for that is complicated, and until we see an actual impact, we're going
507*d4514f0bSApple OSS Distributions 	 * to keep the simpler design in place.
508*d4514f0bSApple OSS Distributions 	 */
509*d4514f0bSApple OSS Distributions 
510*d4514f0bSApple OSS Distributions 	/* Return if the logging hasn't been setup yet */
511*d4514f0bSApple OSS Distributions 	if (txm_log_sync == NULL) {
512*d4514f0bSApple OSS Distributions 		return;
513*d4514f0bSApple OSS Distributions 	}
514*d4514f0bSApple OSS Distributions 
515*d4514f0bSApple OSS Distributions 	/*
516*d4514f0bSApple OSS Distributions 	 * Holding the log lock and printing can cause lots of issues since printing can
517*d4514f0bSApple OSS Distributions 	 * be rather slow. While we make it a point to keep the logging buffer quiet, some
518*d4514f0bSApple OSS Distributions 	 * actions (such as loading trust caches) are still very chatty.
519*d4514f0bSApple OSS Distributions 	 *
520*d4514f0bSApple OSS Distributions 	 * As a result, we optimize this routine to ensure that the lock itself isn't held
521*d4514f0bSApple OSS Distributions 	 * for very long. All we need to do within the critical section is calculate the
522*d4514f0bSApple OSS Distributions 	 * starting and ending index of the log buffer. The actual printing doesn't need
523*d4514f0bSApple OSS Distributions 	 * to be done with the lock held.
524*d4514f0bSApple OSS Distributions 	 */
525*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&log_lock);
526*d4514f0bSApple OSS Distributions 
527*d4514f0bSApple OSS Distributions 	start_index = log_head;
528*d4514f0bSApple OSS Distributions 	end_index = os_atomic_load(txm_log_head, relaxed) % kTXMLogSlots;
529*d4514f0bSApple OSS Distributions 
530*d4514f0bSApple OSS Distributions 	/* Update the log head with the new index */
531*d4514f0bSApple OSS Distributions 	log_head = end_index;
532*d4514f0bSApple OSS Distributions 
533*d4514f0bSApple OSS Distributions 	/* Release the log lock */
534*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&log_lock);
535*d4514f0bSApple OSS Distributions 
536*d4514f0bSApple OSS Distributions 	if (start_index != end_index) {
537*d4514f0bSApple OSS Distributions 		/* Use load acquire here to sync up with all writes to the buffer */
538*d4514f0bSApple OSS Distributions 		os_atomic_load(txm_log_sync, acquire);
539*d4514f0bSApple OSS Distributions 
540*d4514f0bSApple OSS Distributions 		while (start_index != end_index) {
541*d4514f0bSApple OSS Distributions 			const char *slot = txm_log_page + (start_index * kTXMLogSlotSize);
542*d4514f0bSApple OSS Distributions 
543*d4514f0bSApple OSS Distributions 			/* We add newlines after each log statement since TXM does not */
544*d4514f0bSApple OSS Distributions 			printf("%s\n", slot);
545*d4514f0bSApple OSS Distributions 
546*d4514f0bSApple OSS Distributions 			start_index = (start_index + 1) % kTXMLogSlots;
547*d4514f0bSApple OSS Distributions 		}
548*d4514f0bSApple OSS Distributions 	}
549*d4514f0bSApple OSS Distributions }
550*d4514f0bSApple OSS Distributions 
551*d4514f0bSApple OSS Distributions #pragma mark Initialization
552*d4514f0bSApple OSS Distributions 
553*d4514f0bSApple OSS Distributions SECURITY_READ_ONLY_LATE(const TXMReadOnlyData_t*) txm_ro_data = NULL;
554*d4514f0bSApple OSS Distributions SECURITY_READ_ONLY_LATE(const TXMStatistics_t*) txm_stats = NULL;
555*d4514f0bSApple OSS Distributions SECURITY_READ_ONLY_LATE(const CSConfig_t*) txm_cs_config = NULL;
556*d4514f0bSApple OSS Distributions SECURITY_READ_ONLY_LATE(CSRestrictedModeState_t*) txm_restricted_mode_state = NULL;
557*d4514f0bSApple OSS Distributions 
558*d4514f0bSApple OSS Distributions SECURITY_READ_ONLY_LATE(bool*) developer_mode_enabled = NULL;
559*d4514f0bSApple OSS Distributions static SECURITY_READ_ONLY_LATE(bool) code_signing_enabled = true;
560*d4514f0bSApple OSS Distributions static SECURITY_READ_ONLY_LATE(uint32_t) managed_signature_size = 0;
561*d4514f0bSApple OSS Distributions 
562*d4514f0bSApple OSS Distributions static decl_lck_mtx_data(, compilation_service_lock);
563*d4514f0bSApple OSS Distributions static decl_lck_mtx_data(, unregister_sync_lock);
564*d4514f0bSApple OSS Distributions 
565*d4514f0bSApple OSS Distributions static void
get_logging_info(void)566*d4514f0bSApple OSS Distributions get_logging_info(void)
567*d4514f0bSApple OSS Distributions {
568*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
569*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorGetLogInfo,
570*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
571*d4514f0bSApple OSS Distributions 		.num_output_args = 3
572*d4514f0bSApple OSS Distributions 	};
573*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call);
574*d4514f0bSApple OSS Distributions 
575*d4514f0bSApple OSS Distributions 	txm_log_page = (const char*)txm_call.return_words[0];
576*d4514f0bSApple OSS Distributions 	txm_log_head = (const uint32_t*)txm_call.return_words[1];
577*d4514f0bSApple OSS Distributions 	txm_log_sync = (const uint32_t*)txm_call.return_words[2];
578*d4514f0bSApple OSS Distributions }
579*d4514f0bSApple OSS Distributions 
580*d4514f0bSApple OSS Distributions static void
get_code_signing_info(void)581*d4514f0bSApple OSS Distributions get_code_signing_info(void)
582*d4514f0bSApple OSS Distributions {
583*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
584*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorGetCodeSigningInfo,
585*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
586*d4514f0bSApple OSS Distributions 		.num_output_args = 6
587*d4514f0bSApple OSS Distributions 	};
588*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call);
589*d4514f0bSApple OSS Distributions 
590*d4514f0bSApple OSS Distributions 	/*
591*d4514f0bSApple OSS Distributions 	 * Not using txm_call.return_words[0] for now. This was previously the
592*d4514f0bSApple OSS Distributions 	 * code_signing_enabled field, but we've since switched to acquiring that
593*d4514f0bSApple OSS Distributions 	 * value from TXM's read-only data.
594*d4514f0bSApple OSS Distributions 	 *
595*d4514f0bSApple OSS Distributions 	 * Not using txm_call.return_words[4] for now. This was previously the
596*d4514f0bSApple OSS Distributions 	 * txm_cs_config field, but we've since switched to acquiring that value
597*d4514f0bSApple OSS Distributions 	 * from TXM's read-only data.
598*d4514f0bSApple OSS Distributions 	 */
599*d4514f0bSApple OSS Distributions 
600*d4514f0bSApple OSS Distributions 	developer_mode_enabled = (bool*)txm_call.return_words[1];
601*d4514f0bSApple OSS Distributions 	txm_stats = (TXMStatistics_t*)txm_call.return_words[2];
602*d4514f0bSApple OSS Distributions 	managed_signature_size = (uint32_t)txm_call.return_words[3];
603*d4514f0bSApple OSS Distributions 	txm_ro_data = (TXMReadOnlyData_t*)txm_call.return_words[5];
604*d4514f0bSApple OSS Distributions 
605*d4514f0bSApple OSS Distributions 	/* Set code_signing_disabled based on read-only data */
606*d4514f0bSApple OSS Distributions 	code_signing_enabled = txm_ro_data->codeSigningDisabled == false;
607*d4514f0bSApple OSS Distributions 
608*d4514f0bSApple OSS Distributions 	/* Set txm_cs_config based on read-only data */
609*d4514f0bSApple OSS Distributions 	txm_cs_config = &txm_ro_data->CSConfiguration;
610*d4514f0bSApple OSS Distributions 
611*d4514f0bSApple OSS Distributions 	/* Only setup when REM is supported on the platform */
612*d4514f0bSApple OSS Distributions 	if (txm_cs_config->systemPolicy->featureSet.restrictedExecutionMode == true) {
613*d4514f0bSApple OSS Distributions 		txm_restricted_mode_state = txm_ro_data->restrictedModeState;
614*d4514f0bSApple OSS Distributions 	}
615*d4514f0bSApple OSS Distributions }
616*d4514f0bSApple OSS Distributions 
617*d4514f0bSApple OSS Distributions static void
set_shared_region_base_address(void)618*d4514f0bSApple OSS Distributions set_shared_region_base_address(void)
619*d4514f0bSApple OSS Distributions {
620*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
621*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorSetSharedRegionBaseAddress,
622*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
623*d4514f0bSApple OSS Distributions 		.num_input_args = 2,
624*d4514f0bSApple OSS Distributions 	};
625*d4514f0bSApple OSS Distributions 
626*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call,
627*d4514f0bSApple OSS Distributions 	    SHARED_REGION_BASE,
628*d4514f0bSApple OSS Distributions 	    SHARED_REGION_SIZE);
629*d4514f0bSApple OSS Distributions }
630*d4514f0bSApple OSS Distributions 
631*d4514f0bSApple OSS Distributions void
code_signing_init(void)632*d4514f0bSApple OSS Distributions code_signing_init(void)
633*d4514f0bSApple OSS Distributions {
634*d4514f0bSApple OSS Distributions #if kTXMKernelAPIVersion >= 6
635*d4514f0bSApple OSS Distributions 	printf("libTXM_KernelVersion: %u\n", libTrustedExecutionMonitor_KernelVersion);
636*d4514f0bSApple OSS Distributions 	printf("libTXM_Image4Version: %u\n", libTrustedExecutionMonitor_Image4Version);
637*d4514f0bSApple OSS Distributions #endif
638*d4514f0bSApple OSS Distributions 
639*d4514f0bSApple OSS Distributions 	/* Setup the thread stacks used by TXM */
640*d4514f0bSApple OSS Distributions 	setup_thread_stacks();
641*d4514f0bSApple OSS Distributions 
642*d4514f0bSApple OSS Distributions 	/* Setup the logging lock */
643*d4514f0bSApple OSS Distributions 	lck_mtx_init(&log_lock, &txm_lck_grp, 0);
644*d4514f0bSApple OSS Distributions 
645*d4514f0bSApple OSS Distributions 	/* Setup TXM logging information */
646*d4514f0bSApple OSS Distributions 	get_logging_info();
647*d4514f0bSApple OSS Distributions 
648*d4514f0bSApple OSS Distributions 	/* Setup code signing configuration */
649*d4514f0bSApple OSS Distributions 	get_code_signing_info();
650*d4514f0bSApple OSS Distributions 
651*d4514f0bSApple OSS Distributions 	/* Setup all the other locks we need */
652*d4514f0bSApple OSS Distributions 	lck_mtx_init(&compilation_service_lock, &txm_lck_grp, 0);
653*d4514f0bSApple OSS Distributions 	lck_mtx_init(&unregister_sync_lock, &txm_lck_grp, 0);
654*d4514f0bSApple OSS Distributions 
655*d4514f0bSApple OSS Distributions 	/*
656*d4514f0bSApple OSS Distributions 	 * We need to let TXM know what the shared region base address is going
657*d4514f0bSApple OSS Distributions 	 * to be for this boot.
658*d4514f0bSApple OSS Distributions 	 */
659*d4514f0bSApple OSS Distributions 	set_shared_region_base_address();
660*d4514f0bSApple OSS Distributions 
661*d4514f0bSApple OSS Distributions 	/* Require signed code when monitor is enabled */
662*d4514f0bSApple OSS Distributions 	if (code_signing_enabled == true) {
663*d4514f0bSApple OSS Distributions 		cs_debug_fail_on_unsigned_code = 1;
664*d4514f0bSApple OSS Distributions 	}
665*d4514f0bSApple OSS Distributions }
666*d4514f0bSApple OSS Distributions 
667*d4514f0bSApple OSS Distributions void
txm_enter_lockdown_mode(void)668*d4514f0bSApple OSS Distributions txm_enter_lockdown_mode(void)
669*d4514f0bSApple OSS Distributions {
670*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
671*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorEnterLockdownMode,
672*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
673*d4514f0bSApple OSS Distributions 	};
674*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call);
675*d4514f0bSApple OSS Distributions }
676*d4514f0bSApple OSS Distributions 
677*d4514f0bSApple OSS Distributions kern_return_t
txm_secure_channel_shared_page(uint64_t * secure_channel_phys,size_t * secure_channel_size)678*d4514f0bSApple OSS Distributions txm_secure_channel_shared_page(
679*d4514f0bSApple OSS Distributions 	uint64_t *secure_channel_phys,
680*d4514f0bSApple OSS Distributions 	size_t *secure_channel_size)
681*d4514f0bSApple OSS Distributions {
682*d4514f0bSApple OSS Distributions #if kTXMKernelAPIVersion >= 5
683*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
684*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorGetSecureChannelAddr,
685*d4514f0bSApple OSS Distributions 		.num_output_args = 2
686*d4514f0bSApple OSS Distributions 	};
687*d4514f0bSApple OSS Distributions 
688*d4514f0bSApple OSS Distributions 	kern_return_t ret = txm_kernel_call(&txm_call);
689*d4514f0bSApple OSS Distributions 	if (ret == KERN_NOT_SUPPORTED) {
690*d4514f0bSApple OSS Distributions 		return ret;
691*d4514f0bSApple OSS Distributions 	} else if (ret != KERN_SUCCESS) {
692*d4514f0bSApple OSS Distributions 		panic("unexpected failure for TXM secure channel: %d", ret);
693*d4514f0bSApple OSS Distributions 	}
694*d4514f0bSApple OSS Distributions 
695*d4514f0bSApple OSS Distributions 	/* Return the physical address */
696*d4514f0bSApple OSS Distributions 	if (secure_channel_phys != NULL) {
697*d4514f0bSApple OSS Distributions 		*secure_channel_phys = txm_call.return_words[0];
698*d4514f0bSApple OSS Distributions 	}
699*d4514f0bSApple OSS Distributions 
700*d4514f0bSApple OSS Distributions 	/* Return the size */
701*d4514f0bSApple OSS Distributions 	if (secure_channel_size != NULL) {
702*d4514f0bSApple OSS Distributions 		*secure_channel_size = txm_call.return_words[1];
703*d4514f0bSApple OSS Distributions 	}
704*d4514f0bSApple OSS Distributions 
705*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
706*d4514f0bSApple OSS Distributions #else
707*d4514f0bSApple OSS Distributions 	(void)secure_channel_phys;
708*d4514f0bSApple OSS Distributions 	(void)secure_channel_size;
709*d4514f0bSApple OSS Distributions 	return KERN_NOT_SUPPORTED;
710*d4514f0bSApple OSS Distributions #endif
711*d4514f0bSApple OSS Distributions }
712*d4514f0bSApple OSS Distributions 
713*d4514f0bSApple OSS Distributions #pragma mark Developer Mode
714*d4514f0bSApple OSS Distributions 
715*d4514f0bSApple OSS Distributions void
txm_toggle_developer_mode(bool state)716*d4514f0bSApple OSS Distributions txm_toggle_developer_mode(bool state)
717*d4514f0bSApple OSS Distributions {
718*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
719*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorDeveloperModeToggle,
720*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
721*d4514f0bSApple OSS Distributions 		.num_input_args = 1
722*d4514f0bSApple OSS Distributions 	};
723*d4514f0bSApple OSS Distributions 
724*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, state);
725*d4514f0bSApple OSS Distributions }
726*d4514f0bSApple OSS Distributions 
727*d4514f0bSApple OSS Distributions #pragma mark Restricted Execution Mode
728*d4514f0bSApple OSS Distributions 
729*d4514f0bSApple OSS Distributions kern_return_t
txm_rem_enable(void)730*d4514f0bSApple OSS Distributions txm_rem_enable(void)
731*d4514f0bSApple OSS Distributions {
732*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
733*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorEnableRestrictedMode
734*d4514f0bSApple OSS Distributions 	};
735*d4514f0bSApple OSS Distributions 	return txm_kernel_call(&txm_call);
736*d4514f0bSApple OSS Distributions }
737*d4514f0bSApple OSS Distributions 
738*d4514f0bSApple OSS Distributions kern_return_t
txm_rem_state(void)739*d4514f0bSApple OSS Distributions txm_rem_state(void)
740*d4514f0bSApple OSS Distributions {
741*d4514f0bSApple OSS Distributions 	if (txm_restricted_mode_state == NULL) {
742*d4514f0bSApple OSS Distributions 		return KERN_NOT_SUPPORTED;
743*d4514f0bSApple OSS Distributions 	}
744*d4514f0bSApple OSS Distributions 
745*d4514f0bSApple OSS Distributions 	CSReturn_t cs_ret = restrictedModeStatus(txm_restricted_mode_state);
746*d4514f0bSApple OSS Distributions 	if (cs_ret.error == kCSReturnSuccess) {
747*d4514f0bSApple OSS Distributions 		return KERN_SUCCESS;
748*d4514f0bSApple OSS Distributions 	}
749*d4514f0bSApple OSS Distributions 	return KERN_DENIED;
750*d4514f0bSApple OSS Distributions }
751*d4514f0bSApple OSS Distributions 
752*d4514f0bSApple OSS Distributions #pragma mark Device State
753*d4514f0bSApple OSS Distributions 
754*d4514f0bSApple OSS Distributions void
txm_update_device_state(void)755*d4514f0bSApple OSS Distributions txm_update_device_state(void)
756*d4514f0bSApple OSS Distributions {
757*d4514f0bSApple OSS Distributions #if kTXMKernelAPIVersion >= 6
758*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
759*d4514f0bSApple OSS Distributions 		.selector = kTXMSelectorUpdateDeviceState,
760*d4514f0bSApple OSS Distributions 		.failure_fatal = true
761*d4514f0bSApple OSS Distributions 	};
762*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call);
763*d4514f0bSApple OSS Distributions #endif
764*d4514f0bSApple OSS Distributions }
765*d4514f0bSApple OSS Distributions 
766*d4514f0bSApple OSS Distributions void
txm_complete_security_boot_mode(__unused uint32_t security_boot_mode)767*d4514f0bSApple OSS Distributions txm_complete_security_boot_mode(
768*d4514f0bSApple OSS Distributions 	__unused uint32_t security_boot_mode)
769*d4514f0bSApple OSS Distributions {
770*d4514f0bSApple OSS Distributions #if kTXMKernelAPIVersion >= 6
771*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
772*d4514f0bSApple OSS Distributions 		.selector = kTXMSelectorCompleteSecurityBootMode,
773*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
774*d4514f0bSApple OSS Distributions 		.failure_fatal = true
775*d4514f0bSApple OSS Distributions 	};
776*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, security_boot_mode);
777*d4514f0bSApple OSS Distributions #endif
778*d4514f0bSApple OSS Distributions }
779*d4514f0bSApple OSS Distributions 
780*d4514f0bSApple OSS Distributions #pragma mark Code Signing and Provisioning Profiles
781*d4514f0bSApple OSS Distributions 
782*d4514f0bSApple OSS Distributions bool
txm_code_signing_enabled(void)783*d4514f0bSApple OSS Distributions txm_code_signing_enabled(void)
784*d4514f0bSApple OSS Distributions {
785*d4514f0bSApple OSS Distributions 	return code_signing_enabled;
786*d4514f0bSApple OSS Distributions }
787*d4514f0bSApple OSS Distributions 
788*d4514f0bSApple OSS Distributions vm_size_t
txm_managed_code_signature_size(void)789*d4514f0bSApple OSS Distributions txm_managed_code_signature_size(void)
790*d4514f0bSApple OSS Distributions {
791*d4514f0bSApple OSS Distributions 	return managed_signature_size;
792*d4514f0bSApple OSS Distributions }
793*d4514f0bSApple OSS Distributions 
794*d4514f0bSApple OSS Distributions kern_return_t
txm_register_provisioning_profile(const void * profile_blob,const size_t profile_blob_size,void ** profile_obj)795*d4514f0bSApple OSS Distributions txm_register_provisioning_profile(
796*d4514f0bSApple OSS Distributions 	const void *profile_blob,
797*d4514f0bSApple OSS Distributions 	const size_t profile_blob_size,
798*d4514f0bSApple OSS Distributions 	void **profile_obj)
799*d4514f0bSApple OSS Distributions {
800*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
801*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorRegisterProvisioningProfile,
802*d4514f0bSApple OSS Distributions 		.num_input_args = 2,
803*d4514f0bSApple OSS Distributions 		.num_output_args = 1
804*d4514f0bSApple OSS Distributions 	};
805*d4514f0bSApple OSS Distributions 	vm_address_t payload_addr = 0;
806*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
807*d4514f0bSApple OSS Distributions 
808*d4514f0bSApple OSS Distributions 	/* We need to allocate page-wise in order to transfer the range to TXM */
809*d4514f0bSApple OSS Distributions 	ret = kmem_alloc(kernel_map, &payload_addr, profile_blob_size,
810*d4514f0bSApple OSS Distributions 	    KMA_KOBJECT | KMA_DATA, VM_KERN_MEMORY_SECURITY);
811*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
812*d4514f0bSApple OSS Distributions 		printf("unable to allocate memory for profile payload: %d\n", ret);
813*d4514f0bSApple OSS Distributions 		goto exit;
814*d4514f0bSApple OSS Distributions 	}
815*d4514f0bSApple OSS Distributions 
816*d4514f0bSApple OSS Distributions 	/* Copy the contents into the allocation */
817*d4514f0bSApple OSS Distributions 	memcpy((void*)payload_addr, profile_blob, profile_blob_size);
818*d4514f0bSApple OSS Distributions 
819*d4514f0bSApple OSS Distributions 	/* Transfer the memory range to TXM */
820*d4514f0bSApple OSS Distributions 	txm_transfer_region(payload_addr, profile_blob_size);
821*d4514f0bSApple OSS Distributions 
822*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, payload_addr, profile_blob_size);
823*d4514f0bSApple OSS Distributions 	if (ret == KERN_SUCCESS) {
824*d4514f0bSApple OSS Distributions 		*profile_obj = (void*)txm_call.return_words[0];
825*d4514f0bSApple OSS Distributions 	}
826*d4514f0bSApple OSS Distributions 
827*d4514f0bSApple OSS Distributions exit:
828*d4514f0bSApple OSS Distributions 	if ((ret != KERN_SUCCESS) && (payload_addr != 0)) {
829*d4514f0bSApple OSS Distributions 		/* Reclaim this memory range */
830*d4514f0bSApple OSS Distributions 		txm_reclaim_region(payload_addr, profile_blob_size);
831*d4514f0bSApple OSS Distributions 
832*d4514f0bSApple OSS Distributions 		/* Free the memory range */
833*d4514f0bSApple OSS Distributions 		kmem_free(kernel_map, payload_addr, profile_blob_size);
834*d4514f0bSApple OSS Distributions 		payload_addr = 0;
835*d4514f0bSApple OSS Distributions 	}
836*d4514f0bSApple OSS Distributions 
837*d4514f0bSApple OSS Distributions 	return ret;
838*d4514f0bSApple OSS Distributions }
839*d4514f0bSApple OSS Distributions 
840*d4514f0bSApple OSS Distributions kern_return_t
txm_trust_provisioning_profile(__unused void * profile_obj,__unused const void * sig_data,__unused size_t sig_size)841*d4514f0bSApple OSS Distributions txm_trust_provisioning_profile(
842*d4514f0bSApple OSS Distributions 	__unused void *profile_obj,
843*d4514f0bSApple OSS Distributions 	__unused const void *sig_data,
844*d4514f0bSApple OSS Distributions 	__unused size_t sig_size)
845*d4514f0bSApple OSS Distributions {
846*d4514f0bSApple OSS Distributions #if kTXMKernelAPIVersion >= 7
847*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
848*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorTrustProvisioningProfile,
849*d4514f0bSApple OSS Distributions 		.num_input_args = 3
850*d4514f0bSApple OSS Distributions 	};
851*d4514f0bSApple OSS Distributions 
852*d4514f0bSApple OSS Distributions 	return txm_kernel_call(&txm_call, profile_obj, sig_data, sig_size);
853*d4514f0bSApple OSS Distributions #else
854*d4514f0bSApple OSS Distributions 	/* The TXM selector hasn't yet landed */
855*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
856*d4514f0bSApple OSS Distributions #endif
857*d4514f0bSApple OSS Distributions }
858*d4514f0bSApple OSS Distributions 
859*d4514f0bSApple OSS Distributions kern_return_t
txm_unregister_provisioning_profile(void * profile_obj)860*d4514f0bSApple OSS Distributions txm_unregister_provisioning_profile(
861*d4514f0bSApple OSS Distributions 	void *profile_obj)
862*d4514f0bSApple OSS Distributions {
863*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
864*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorUnregisterProvisioningProfile,
865*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
866*d4514f0bSApple OSS Distributions 		.num_output_args = 2
867*d4514f0bSApple OSS Distributions 	};
868*d4514f0bSApple OSS Distributions 	vm_address_t profile_addr = 0;
869*d4514f0bSApple OSS Distributions 	vm_size_t profile_size = 0;
870*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
871*d4514f0bSApple OSS Distributions 
872*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, profile_obj);
873*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
874*d4514f0bSApple OSS Distributions 		return ret;
875*d4514f0bSApple OSS Distributions 	}
876*d4514f0bSApple OSS Distributions 
877*d4514f0bSApple OSS Distributions 	profile_addr = txm_call.return_words[0];
878*d4514f0bSApple OSS Distributions 	profile_size = txm_call.return_words[1];
879*d4514f0bSApple OSS Distributions 
880*d4514f0bSApple OSS Distributions 	/* Reclaim this memory range */
881*d4514f0bSApple OSS Distributions 	txm_reclaim_region(profile_addr, profile_size);
882*d4514f0bSApple OSS Distributions 
883*d4514f0bSApple OSS Distributions 	/* Free the memory range */
884*d4514f0bSApple OSS Distributions 	kmem_free(kernel_map, profile_addr, profile_size);
885*d4514f0bSApple OSS Distributions 
886*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
887*d4514f0bSApple OSS Distributions }
888*d4514f0bSApple OSS Distributions 
889*d4514f0bSApple OSS Distributions kern_return_t
txm_associate_provisioning_profile(void * sig_obj,void * profile_obj)890*d4514f0bSApple OSS Distributions txm_associate_provisioning_profile(
891*d4514f0bSApple OSS Distributions 	void *sig_obj,
892*d4514f0bSApple OSS Distributions 	void *profile_obj)
893*d4514f0bSApple OSS Distributions {
894*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
895*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAssociateProvisioningProfile,
896*d4514f0bSApple OSS Distributions 		.num_input_args = 2,
897*d4514f0bSApple OSS Distributions 	};
898*d4514f0bSApple OSS Distributions 
899*d4514f0bSApple OSS Distributions 	return txm_kernel_call(&txm_call, sig_obj, profile_obj);
900*d4514f0bSApple OSS Distributions }
901*d4514f0bSApple OSS Distributions 
902*d4514f0bSApple OSS Distributions kern_return_t
txm_disassociate_provisioning_profile(void * sig_obj)903*d4514f0bSApple OSS Distributions txm_disassociate_provisioning_profile(
904*d4514f0bSApple OSS Distributions 	void *sig_obj)
905*d4514f0bSApple OSS Distributions {
906*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
907*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorDisassociateProvisioningProfile,
908*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
909*d4514f0bSApple OSS Distributions 	};
910*d4514f0bSApple OSS Distributions 
911*d4514f0bSApple OSS Distributions 	/*
912*d4514f0bSApple OSS Distributions 	 * Take the unregistration sync lock.
913*d4514f0bSApple OSS Distributions 	 * For more information: rdar://99205627.
914*d4514f0bSApple OSS Distributions 	 */
915*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&unregister_sync_lock);
916*d4514f0bSApple OSS Distributions 
917*d4514f0bSApple OSS Distributions 	/* Disassociate the profile from the signature */
918*d4514f0bSApple OSS Distributions 	kern_return_t ret = txm_kernel_call(&txm_call, sig_obj);
919*d4514f0bSApple OSS Distributions 
920*d4514f0bSApple OSS Distributions 	/* Release the unregistration sync lock */
921*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&unregister_sync_lock);
922*d4514f0bSApple OSS Distributions 
923*d4514f0bSApple OSS Distributions 	return ret;
924*d4514f0bSApple OSS Distributions }
925*d4514f0bSApple OSS Distributions 
926*d4514f0bSApple OSS Distributions void
txm_set_compilation_service_cdhash(const uint8_t cdhash[CS_CDHASH_LEN])927*d4514f0bSApple OSS Distributions txm_set_compilation_service_cdhash(
928*d4514f0bSApple OSS Distributions 	const uint8_t cdhash[CS_CDHASH_LEN])
929*d4514f0bSApple OSS Distributions {
930*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
931*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAuthorizeCompilationServiceCDHash,
932*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
933*d4514f0bSApple OSS Distributions 	};
934*d4514f0bSApple OSS Distributions 
935*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&compilation_service_lock);
936*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, cdhash);
937*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&compilation_service_lock);
938*d4514f0bSApple OSS Distributions }
939*d4514f0bSApple OSS Distributions 
940*d4514f0bSApple OSS Distributions bool
txm_match_compilation_service_cdhash(const uint8_t cdhash[CS_CDHASH_LEN])941*d4514f0bSApple OSS Distributions txm_match_compilation_service_cdhash(
942*d4514f0bSApple OSS Distributions 	const uint8_t cdhash[CS_CDHASH_LEN])
943*d4514f0bSApple OSS Distributions {
944*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
945*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorMatchCompilationServiceCDHash,
946*d4514f0bSApple OSS Distributions 		.failure_silent = true,
947*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
948*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
949*d4514f0bSApple OSS Distributions 	};
950*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
951*d4514f0bSApple OSS Distributions 
952*d4514f0bSApple OSS Distributions 	/* Be safe and take the lock (avoid thread collisions) */
953*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&compilation_service_lock);
954*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, cdhash);
955*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&compilation_service_lock);
956*d4514f0bSApple OSS Distributions 
957*d4514f0bSApple OSS Distributions 	if (ret == KERN_SUCCESS) {
958*d4514f0bSApple OSS Distributions 		return true;
959*d4514f0bSApple OSS Distributions 	}
960*d4514f0bSApple OSS Distributions 	return false;
961*d4514f0bSApple OSS Distributions }
962*d4514f0bSApple OSS Distributions 
963*d4514f0bSApple OSS Distributions void
txm_set_local_signing_public_key(const uint8_t public_key[XNU_LOCAL_SIGNING_KEY_SIZE])964*d4514f0bSApple OSS Distributions txm_set_local_signing_public_key(
965*d4514f0bSApple OSS Distributions 	const uint8_t public_key[XNU_LOCAL_SIGNING_KEY_SIZE])
966*d4514f0bSApple OSS Distributions {
967*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
968*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorSetLocalSigningPublicKey,
969*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
970*d4514f0bSApple OSS Distributions 	};
971*d4514f0bSApple OSS Distributions 
972*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, public_key);
973*d4514f0bSApple OSS Distributions }
974*d4514f0bSApple OSS Distributions 
975*d4514f0bSApple OSS Distributions uint8_t*
txm_get_local_signing_public_key(void)976*d4514f0bSApple OSS Distributions txm_get_local_signing_public_key(void)
977*d4514f0bSApple OSS Distributions {
978*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
979*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorGetLocalSigningPublicKey,
980*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
981*d4514f0bSApple OSS Distributions 	};
982*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
983*d4514f0bSApple OSS Distributions 
984*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call);
985*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
986*d4514f0bSApple OSS Distributions 		return NULL;
987*d4514f0bSApple OSS Distributions 	}
988*d4514f0bSApple OSS Distributions 
989*d4514f0bSApple OSS Distributions 	return (uint8_t*)txm_call.return_words[0];
990*d4514f0bSApple OSS Distributions }
991*d4514f0bSApple OSS Distributions 
992*d4514f0bSApple OSS Distributions void
txm_unrestrict_local_signing_cdhash(const uint8_t cdhash[CS_CDHASH_LEN])993*d4514f0bSApple OSS Distributions txm_unrestrict_local_signing_cdhash(
994*d4514f0bSApple OSS Distributions 	const uint8_t cdhash[CS_CDHASH_LEN])
995*d4514f0bSApple OSS Distributions {
996*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
997*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAuthorizeLocalSigningCDHash,
998*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
999*d4514f0bSApple OSS Distributions 	};
1000*d4514f0bSApple OSS Distributions 
1001*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, cdhash);
1002*d4514f0bSApple OSS Distributions }
1003*d4514f0bSApple OSS Distributions 
1004*d4514f0bSApple OSS Distributions kern_return_t
txm_register_code_signature(const vm_address_t signature_addr,const vm_size_t signature_size,const vm_offset_t code_directory_offset,const char * signature_path,void ** sig_obj,vm_address_t * txm_signature_addr)1005*d4514f0bSApple OSS Distributions txm_register_code_signature(
1006*d4514f0bSApple OSS Distributions 	const vm_address_t signature_addr,
1007*d4514f0bSApple OSS Distributions 	const vm_size_t signature_size,
1008*d4514f0bSApple OSS Distributions 	const vm_offset_t code_directory_offset,
1009*d4514f0bSApple OSS Distributions 	const char *signature_path,
1010*d4514f0bSApple OSS Distributions 	void **sig_obj,
1011*d4514f0bSApple OSS Distributions 	vm_address_t *txm_signature_addr)
1012*d4514f0bSApple OSS Distributions {
1013*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1014*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorRegisterCodeSignature,
1015*d4514f0bSApple OSS Distributions 		.num_input_args = 3,
1016*d4514f0bSApple OSS Distributions 		.num_output_args = 2,
1017*d4514f0bSApple OSS Distributions 	};
1018*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1019*d4514f0bSApple OSS Distributions 
1020*d4514f0bSApple OSS Distributions 	/*
1021*d4514f0bSApple OSS Distributions 	 * TXM performs more exhaustive validation of the code signature and figures
1022*d4514f0bSApple OSS Distributions 	 * out the best code directory to use on its own. As a result, this offset here
1023*d4514f0bSApple OSS Distributions 	 * is not used.
1024*d4514f0bSApple OSS Distributions 	 */
1025*d4514f0bSApple OSS Distributions 	(void)code_directory_offset;
1026*d4514f0bSApple OSS Distributions 
1027*d4514f0bSApple OSS Distributions 	/*
1028*d4514f0bSApple OSS Distributions 	 * If the signature is large enough to not fit within TXM's managed signature
1029*d4514f0bSApple OSS Distributions 	 * size, then we need to transfer it over so it is owned by TXM.
1030*d4514f0bSApple OSS Distributions 	 */
1031*d4514f0bSApple OSS Distributions 	if (signature_size > txm_managed_code_signature_size()) {
1032*d4514f0bSApple OSS Distributions 		txm_transfer_region(signature_addr, signature_size);
1033*d4514f0bSApple OSS Distributions 	}
1034*d4514f0bSApple OSS Distributions 
1035*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(
1036*d4514f0bSApple OSS Distributions 		&txm_call,
1037*d4514f0bSApple OSS Distributions 		signature_addr,
1038*d4514f0bSApple OSS Distributions 		signature_size,
1039*d4514f0bSApple OSS Distributions 		signature_path);
1040*d4514f0bSApple OSS Distributions 
1041*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
1042*d4514f0bSApple OSS Distributions 		goto exit;
1043*d4514f0bSApple OSS Distributions 	}
1044*d4514f0bSApple OSS Distributions 
1045*d4514f0bSApple OSS Distributions 	*sig_obj = (void*)txm_call.return_words[0];
1046*d4514f0bSApple OSS Distributions 	*txm_signature_addr = txm_call.return_words[1];
1047*d4514f0bSApple OSS Distributions 
1048*d4514f0bSApple OSS Distributions exit:
1049*d4514f0bSApple OSS Distributions 	if ((ret != KERN_SUCCESS) && (signature_size > txm_managed_code_signature_size())) {
1050*d4514f0bSApple OSS Distributions 		txm_reclaim_region(signature_addr, signature_size);
1051*d4514f0bSApple OSS Distributions 	}
1052*d4514f0bSApple OSS Distributions 
1053*d4514f0bSApple OSS Distributions 	return ret;
1054*d4514f0bSApple OSS Distributions }
1055*d4514f0bSApple OSS Distributions 
1056*d4514f0bSApple OSS Distributions kern_return_t
txm_unregister_code_signature(void * sig_obj)1057*d4514f0bSApple OSS Distributions txm_unregister_code_signature(
1058*d4514f0bSApple OSS Distributions 	void *sig_obj)
1059*d4514f0bSApple OSS Distributions {
1060*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1061*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorUnregisterCodeSignature,
1062*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1063*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1064*d4514f0bSApple OSS Distributions 		.num_output_args = 2,
1065*d4514f0bSApple OSS Distributions 	};
1066*d4514f0bSApple OSS Distributions 	TXMCodeSignature_t *cs_obj = sig_obj;
1067*d4514f0bSApple OSS Distributions 	vm_address_t signature_addr = 0;
1068*d4514f0bSApple OSS Distributions 	vm_size_t signature_size = 0;
1069*d4514f0bSApple OSS Distributions 	bool txm_managed = false;
1070*d4514f0bSApple OSS Distributions 
1071*d4514f0bSApple OSS Distributions 	/* Check if the signature memory is TXM managed */
1072*d4514f0bSApple OSS Distributions 	txm_managed = cs_obj->sptmType != TXM_BULK_DATA;
1073*d4514f0bSApple OSS Distributions 
1074*d4514f0bSApple OSS Distributions 	/*
1075*d4514f0bSApple OSS Distributions 	 * Take the unregistration sync lock.
1076*d4514f0bSApple OSS Distributions 	 * For more information: rdar://99205627.
1077*d4514f0bSApple OSS Distributions 	 */
1078*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&unregister_sync_lock);
1079*d4514f0bSApple OSS Distributions 
1080*d4514f0bSApple OSS Distributions 	/* Unregister the signature from TXM -- cannot fail */
1081*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, sig_obj);
1082*d4514f0bSApple OSS Distributions 
1083*d4514f0bSApple OSS Distributions 	/* Release the unregistration sync lock */
1084*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&unregister_sync_lock);
1085*d4514f0bSApple OSS Distributions 
1086*d4514f0bSApple OSS Distributions 	signature_addr = txm_call.return_words[0];
1087*d4514f0bSApple OSS Distributions 	signature_size = txm_call.return_words[1];
1088*d4514f0bSApple OSS Distributions 
1089*d4514f0bSApple OSS Distributions 	/* Reclaim the memory range in case we need to */
1090*d4514f0bSApple OSS Distributions 	if (txm_managed == false) {
1091*d4514f0bSApple OSS Distributions 		txm_reclaim_region(signature_addr, signature_size);
1092*d4514f0bSApple OSS Distributions 	}
1093*d4514f0bSApple OSS Distributions 
1094*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1095*d4514f0bSApple OSS Distributions }
1096*d4514f0bSApple OSS Distributions 
1097*d4514f0bSApple OSS Distributions kern_return_t
txm_verify_code_signature(void * sig_obj)1098*d4514f0bSApple OSS Distributions txm_verify_code_signature(
1099*d4514f0bSApple OSS Distributions 	void *sig_obj)
1100*d4514f0bSApple OSS Distributions {
1101*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1102*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorValidateCodeSignature,
1103*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1104*d4514f0bSApple OSS Distributions 	};
1105*d4514f0bSApple OSS Distributions 
1106*d4514f0bSApple OSS Distributions 	return txm_kernel_call(&txm_call, sig_obj);
1107*d4514f0bSApple OSS Distributions }
1108*d4514f0bSApple OSS Distributions 
1109*d4514f0bSApple OSS Distributions kern_return_t
txm_reconstitute_code_signature(void * sig_obj,vm_address_t * unneeded_addr,vm_size_t * unneeded_size)1110*d4514f0bSApple OSS Distributions txm_reconstitute_code_signature(
1111*d4514f0bSApple OSS Distributions 	void *sig_obj,
1112*d4514f0bSApple OSS Distributions 	vm_address_t *unneeded_addr,
1113*d4514f0bSApple OSS Distributions 	vm_size_t *unneeded_size)
1114*d4514f0bSApple OSS Distributions {
1115*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1116*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorReconstituteCodeSignature,
1117*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1118*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1119*d4514f0bSApple OSS Distributions 		.num_output_args = 2,
1120*d4514f0bSApple OSS Distributions 	};
1121*d4514f0bSApple OSS Distributions 	vm_address_t return_addr = 0;
1122*d4514f0bSApple OSS Distributions 	vm_size_t return_size = 0;
1123*d4514f0bSApple OSS Distributions 
1124*d4514f0bSApple OSS Distributions 	/* Reconstitute the code signature -- cannot fail */
1125*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, sig_obj);
1126*d4514f0bSApple OSS Distributions 
1127*d4514f0bSApple OSS Distributions 	return_addr = txm_call.return_words[0];
1128*d4514f0bSApple OSS Distributions 	return_size = txm_call.return_words[1];
1129*d4514f0bSApple OSS Distributions 
1130*d4514f0bSApple OSS Distributions 	/* Reclaim the memory region if we need to */
1131*d4514f0bSApple OSS Distributions 	if ((return_addr != 0) && (return_size != 0)) {
1132*d4514f0bSApple OSS Distributions 		txm_reclaim_region(return_addr, return_size);
1133*d4514f0bSApple OSS Distributions 	}
1134*d4514f0bSApple OSS Distributions 
1135*d4514f0bSApple OSS Distributions 	*unneeded_addr = return_addr;
1136*d4514f0bSApple OSS Distributions 	*unneeded_size = return_size;
1137*d4514f0bSApple OSS Distributions 
1138*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1139*d4514f0bSApple OSS Distributions }
1140*d4514f0bSApple OSS Distributions 
1141*d4514f0bSApple OSS Distributions #pragma mark Address Spaces
1142*d4514f0bSApple OSS Distributions 
1143*d4514f0bSApple OSS Distributions kern_return_t
txm_register_address_space(pmap_t pmap,uint16_t addr_space_id,TXMAddressSpaceFlags_t flags)1144*d4514f0bSApple OSS Distributions txm_register_address_space(
1145*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1146*d4514f0bSApple OSS Distributions 	uint16_t addr_space_id,
1147*d4514f0bSApple OSS Distributions 	TXMAddressSpaceFlags_t flags)
1148*d4514f0bSApple OSS Distributions {
1149*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1150*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorRegisterAddressSpace,
1151*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1152*d4514f0bSApple OSS Distributions 		.num_input_args = 2,
1153*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
1154*d4514f0bSApple OSS Distributions 	};
1155*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = NULL;
1156*d4514f0bSApple OSS Distributions 
1157*d4514f0bSApple OSS Distributions 	/* Register the address space -- cannot fail */
1158*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, addr_space_id, flags);
1159*d4514f0bSApple OSS Distributions 
1160*d4514f0bSApple OSS Distributions 	/* Set the address space object within the PMAP */
1161*d4514f0bSApple OSS Distributions 	txm_addr_space = (TXMAddressSpace_t*)txm_call.return_words[0];
1162*d4514f0bSApple OSS Distributions 	pmap_txm_set_addr_space(pmap, txm_addr_space);
1163*d4514f0bSApple OSS Distributions 
1164*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1165*d4514f0bSApple OSS Distributions }
1166*d4514f0bSApple OSS Distributions 
1167*d4514f0bSApple OSS Distributions kern_return_t
txm_unregister_address_space(pmap_t pmap)1168*d4514f0bSApple OSS Distributions txm_unregister_address_space(
1169*d4514f0bSApple OSS Distributions 	pmap_t pmap)
1170*d4514f0bSApple OSS Distributions {
1171*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1172*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorUnregisterAddressSpace,
1173*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1174*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1175*d4514f0bSApple OSS Distributions 	};
1176*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = pmap_txm_addr_space(pmap);
1177*d4514f0bSApple OSS Distributions 
1178*d4514f0bSApple OSS Distributions 	/*
1179*d4514f0bSApple OSS Distributions 	 * Take the unregistration sync lock.
1180*d4514f0bSApple OSS Distributions 	 * For more information: rdar://99205627.
1181*d4514f0bSApple OSS Distributions 	 */
1182*d4514f0bSApple OSS Distributions 	lck_mtx_lock(&unregister_sync_lock);
1183*d4514f0bSApple OSS Distributions 
1184*d4514f0bSApple OSS Distributions 	/* Unregister the address space -- cannot fail */
1185*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, txm_addr_space);
1186*d4514f0bSApple OSS Distributions 
1187*d4514f0bSApple OSS Distributions 	/* Release the unregistration sync lock */
1188*d4514f0bSApple OSS Distributions 	lck_mtx_unlock(&unregister_sync_lock);
1189*d4514f0bSApple OSS Distributions 
1190*d4514f0bSApple OSS Distributions 	/* Remove the address space from the pmap */
1191*d4514f0bSApple OSS Distributions 	pmap_txm_set_addr_space(pmap, NULL);
1192*d4514f0bSApple OSS Distributions 
1193*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1194*d4514f0bSApple OSS Distributions }
1195*d4514f0bSApple OSS Distributions 
1196*d4514f0bSApple OSS Distributions kern_return_t
txm_associate_code_signature(pmap_t pmap,void * sig_obj,const vm_address_t region_addr,const vm_size_t region_size,const vm_offset_t region_offset)1197*d4514f0bSApple OSS Distributions txm_associate_code_signature(
1198*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1199*d4514f0bSApple OSS Distributions 	void *sig_obj,
1200*d4514f0bSApple OSS Distributions 	const vm_address_t region_addr,
1201*d4514f0bSApple OSS Distributions 	const vm_size_t region_size,
1202*d4514f0bSApple OSS Distributions 	const vm_offset_t region_offset)
1203*d4514f0bSApple OSS Distributions {
1204*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1205*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAssociateCodeSignature,
1206*d4514f0bSApple OSS Distributions 		.num_input_args = 5,
1207*d4514f0bSApple OSS Distributions 	};
1208*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = pmap_txm_addr_space(pmap);
1209*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1210*d4514f0bSApple OSS Distributions 
1211*d4514f0bSApple OSS Distributions 	/*
1212*d4514f0bSApple OSS Distributions 	 * Associating a code signature may require exclusive access to the TXM address
1213*d4514f0bSApple OSS Distributions 	 * space lock within TXM.
1214*d4514f0bSApple OSS Distributions 	 */
1215*d4514f0bSApple OSS Distributions 	pmap_txm_acquire_exclusive_lock(pmap);
1216*d4514f0bSApple OSS Distributions 
1217*d4514f0bSApple OSS Distributions 	/*
1218*d4514f0bSApple OSS Distributions 	 * If the address space in question is a nested address space, then all associations
1219*d4514f0bSApple OSS Distributions 	 * need to go into the shared region base range. The VM layer is inconsistent with
1220*d4514f0bSApple OSS Distributions 	 * how it makes associations with TXM vs. how it maps pages into the shared region.
1221*d4514f0bSApple OSS Distributions 	 *
1222*d4514f0bSApple OSS Distributions 	 * For TXM, the associations are made without taking the base range into account,
1223*d4514f0bSApple OSS Distributions 	 * but when mappings are entered into the shared region, the base range is taken
1224*d4514f0bSApple OSS Distributions 	 * into account. To normalize this, we add the base range address here.
1225*d4514f0bSApple OSS Distributions 	 */
1226*d4514f0bSApple OSS Distributions 	vm_address_t adjusted_region_addr = region_addr;
1227*d4514f0bSApple OSS Distributions 	if (txm_addr_space->addrSpaceID.type == kTXMAddressSpaceIDTypeSharedRegion) {
1228*d4514f0bSApple OSS Distributions 		adjusted_region_addr += SHARED_REGION_BASE;
1229*d4514f0bSApple OSS Distributions 	}
1230*d4514f0bSApple OSS Distributions 
1231*d4514f0bSApple OSS Distributions 	/*
1232*d4514f0bSApple OSS Distributions 	 * The VM tries a bunch of weird mappings within launchd for some platform code
1233*d4514f0bSApple OSS Distributions 	 * which isn't mapped contiguously. These mappings don't succeed, but the failure
1234*d4514f0bSApple OSS Distributions 	 * is fairly harmless since everything seems to work. However, since the call to
1235*d4514f0bSApple OSS Distributions 	 * TXM fails, we make a series of logs. Hence, for launchd, we suppress failure
1236*d4514f0bSApple OSS Distributions 	 * logs.
1237*d4514f0bSApple OSS Distributions 	 */
1238*d4514f0bSApple OSS Distributions 	if (txm_addr_space->addrSpaceID.type == kTXMAddressSpaceIDTypeAddressSpace) {
1239*d4514f0bSApple OSS Distributions 		/* TXMTODO: Scope this to launchd better */
1240*d4514f0bSApple OSS Distributions 		txm_call.failure_code_silent = kTXMReturnPlatformCodeMapping;
1241*d4514f0bSApple OSS Distributions 	}
1242*d4514f0bSApple OSS Distributions 
1243*d4514f0bSApple OSS Distributions 	/* Check if the main region has been set on the address space */
1244*d4514f0bSApple OSS Distributions 	bool main_region_set = txm_addr_space->mainRegion != NULL;
1245*d4514f0bSApple OSS Distributions 	bool main_region_set_after = false;
1246*d4514f0bSApple OSS Distributions 
1247*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(
1248*d4514f0bSApple OSS Distributions 		&txm_call,
1249*d4514f0bSApple OSS Distributions 		txm_addr_space,
1250*d4514f0bSApple OSS Distributions 		sig_obj,
1251*d4514f0bSApple OSS Distributions 		adjusted_region_addr,
1252*d4514f0bSApple OSS Distributions 		region_size,
1253*d4514f0bSApple OSS Distributions 		region_offset);
1254*d4514f0bSApple OSS Distributions 
1255*d4514f0bSApple OSS Distributions 	while (ret == KERN_OPERATION_TIMED_OUT) {
1256*d4514f0bSApple OSS Distributions 		/*
1257*d4514f0bSApple OSS Distributions 		 * There is no easy method to sleep in the kernel. This operation has the
1258*d4514f0bSApple OSS Distributions 		 * potential to burn CPU cycles, but that is alright since we don't actually
1259*d4514f0bSApple OSS Distributions 		 * ever expect to enter this case on legitimately operating systems.
1260*d4514f0bSApple OSS Distributions 		 */
1261*d4514f0bSApple OSS Distributions 		ret = txm_kernel_call(
1262*d4514f0bSApple OSS Distributions 			&txm_call,
1263*d4514f0bSApple OSS Distributions 			txm_addr_space,
1264*d4514f0bSApple OSS Distributions 			sig_obj,
1265*d4514f0bSApple OSS Distributions 			adjusted_region_addr,
1266*d4514f0bSApple OSS Distributions 			region_size,
1267*d4514f0bSApple OSS Distributions 			region_offset);
1268*d4514f0bSApple OSS Distributions 	}
1269*d4514f0bSApple OSS Distributions 
1270*d4514f0bSApple OSS Distributions 	/*
1271*d4514f0bSApple OSS Distributions 	 * If the main region wasn't set on the address space before hand, but this new
1272*d4514f0bSApple OSS Distributions 	 * call into TXM was successful and sets the main region, it means this signature
1273*d4514f0bSApple OSS Distributions 	 * object is associated with the main region on the address space. With this, we
1274*d4514f0bSApple OSS Distributions 	 * can now set the appropriate trust level on the PMAP.
1275*d4514f0bSApple OSS Distributions 	 */
1276*d4514f0bSApple OSS Distributions 	if (ret == KERN_SUCCESS) {
1277*d4514f0bSApple OSS Distributions 		main_region_set_after = txm_addr_space->mainRegion != NULL;
1278*d4514f0bSApple OSS Distributions 	}
1279*d4514f0bSApple OSS Distributions 
1280*d4514f0bSApple OSS Distributions 	/* Unlock the TXM address space lock */
1281*d4514f0bSApple OSS Distributions 	pmap_txm_release_exclusive_lock(pmap);
1282*d4514f0bSApple OSS Distributions 
1283*d4514f0bSApple OSS Distributions 	/* Check if we should set the trust level on the PMAP */
1284*d4514f0bSApple OSS Distributions 	if (!main_region_set && main_region_set_after) {
1285*d4514f0bSApple OSS Distributions 		const TXMCodeSignature_t *cs_obj = sig_obj;
1286*d4514f0bSApple OSS Distributions 		const SignatureValidation_t *sig = &cs_obj->sig;
1287*d4514f0bSApple OSS Distributions 
1288*d4514f0bSApple OSS Distributions 		/*
1289*d4514f0bSApple OSS Distributions 		 * This is gross, as we're dereferencing into a private data structure type.
1290*d4514f0bSApple OSS Distributions 		 * There are 2 ways to clean this up in the future:
1291*d4514f0bSApple OSS Distributions 		 * 1. Import libCodeSignature, so we can use "codeSignatureGetTrustLevel".
1292*d4514f0bSApple OSS Distributions 		 * 2. Cache the trust level on the address space within TXM and then use it.
1293*d4514f0bSApple OSS Distributions 		 */
1294*d4514f0bSApple OSS Distributions 		pmap_txm_set_trust_level(pmap, sig->trustLevel);
1295*d4514f0bSApple OSS Distributions 	}
1296*d4514f0bSApple OSS Distributions 
1297*d4514f0bSApple OSS Distributions 	return ret;
1298*d4514f0bSApple OSS Distributions }
1299*d4514f0bSApple OSS Distributions 
1300*d4514f0bSApple OSS Distributions kern_return_t
txm_allow_jit_region(pmap_t pmap)1301*d4514f0bSApple OSS Distributions txm_allow_jit_region(
1302*d4514f0bSApple OSS Distributions 	pmap_t pmap)
1303*d4514f0bSApple OSS Distributions {
1304*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1305*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAllowJITRegion,
1306*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1307*d4514f0bSApple OSS Distributions 	};
1308*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = pmap_txm_addr_space(pmap);
1309*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1310*d4514f0bSApple OSS Distributions 
1311*d4514f0bSApple OSS Distributions 	pmap_txm_acquire_shared_lock(pmap);
1312*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, txm_addr_space);
1313*d4514f0bSApple OSS Distributions 	pmap_txm_release_shared_lock(pmap);
1314*d4514f0bSApple OSS Distributions 
1315*d4514f0bSApple OSS Distributions 	return ret;
1316*d4514f0bSApple OSS Distributions }
1317*d4514f0bSApple OSS Distributions 
1318*d4514f0bSApple OSS Distributions kern_return_t
txm_associate_jit_region(pmap_t pmap,const vm_address_t region_addr,const vm_size_t region_size)1319*d4514f0bSApple OSS Distributions txm_associate_jit_region(
1320*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1321*d4514f0bSApple OSS Distributions 	const vm_address_t region_addr,
1322*d4514f0bSApple OSS Distributions 	const vm_size_t region_size)
1323*d4514f0bSApple OSS Distributions {
1324*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1325*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAssociateJITRegion,
1326*d4514f0bSApple OSS Distributions 		.num_input_args = 3,
1327*d4514f0bSApple OSS Distributions 	};
1328*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = pmap_txm_addr_space(pmap);
1329*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1330*d4514f0bSApple OSS Distributions 
1331*d4514f0bSApple OSS Distributions 	/*
1332*d4514f0bSApple OSS Distributions 	 * Associating a JIT region may require exclusive access to the TXM address
1333*d4514f0bSApple OSS Distributions 	 * space lock within TXM.
1334*d4514f0bSApple OSS Distributions 	 */
1335*d4514f0bSApple OSS Distributions 	pmap_txm_acquire_exclusive_lock(pmap);
1336*d4514f0bSApple OSS Distributions 
1337*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(
1338*d4514f0bSApple OSS Distributions 		&txm_call,
1339*d4514f0bSApple OSS Distributions 		txm_addr_space,
1340*d4514f0bSApple OSS Distributions 		region_addr,
1341*d4514f0bSApple OSS Distributions 		region_size);
1342*d4514f0bSApple OSS Distributions 
1343*d4514f0bSApple OSS Distributions 	/* Unlock the TXM address space lock */
1344*d4514f0bSApple OSS Distributions 	pmap_txm_release_exclusive_lock(pmap);
1345*d4514f0bSApple OSS Distributions 
1346*d4514f0bSApple OSS Distributions 	return ret;
1347*d4514f0bSApple OSS Distributions }
1348*d4514f0bSApple OSS Distributions 
1349*d4514f0bSApple OSS Distributions kern_return_t
txm_address_space_debugged(pmap_t pmap)1350*d4514f0bSApple OSS Distributions txm_address_space_debugged(
1351*d4514f0bSApple OSS Distributions 	pmap_t pmap)
1352*d4514f0bSApple OSS Distributions {
1353*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = pmap_txm_addr_space(pmap);
1354*d4514f0bSApple OSS Distributions 	bool debug_regions_allowed = false;
1355*d4514f0bSApple OSS Distributions 
1356*d4514f0bSApple OSS Distributions 	/*
1357*d4514f0bSApple OSS Distributions 	 * We do not actually need to trap into the monitor for this function for
1358*d4514f0bSApple OSS Distributions 	 * now. It might be a tad bit more secure to actually trap into the monitor
1359*d4514f0bSApple OSS Distributions 	 * as it implicitly verifies all of our pointers, but since this is a simple
1360*d4514f0bSApple OSS Distributions 	 * state check against the address space, the real policy around it lies
1361*d4514f0bSApple OSS Distributions 	 * within the kernel still, in which case entering the monitor doesn't
1362*d4514f0bSApple OSS Distributions 	 * really provide much more security.
1363*d4514f0bSApple OSS Distributions 	 */
1364*d4514f0bSApple OSS Distributions 
1365*d4514f0bSApple OSS Distributions 	pmap_txm_acquire_shared_lock(pmap);
1366*d4514f0bSApple OSS Distributions 	debug_regions_allowed = os_atomic_load(&txm_addr_space->allowsInvalidCode, relaxed);
1367*d4514f0bSApple OSS Distributions 	pmap_txm_release_shared_lock(pmap);
1368*d4514f0bSApple OSS Distributions 
1369*d4514f0bSApple OSS Distributions 	if (debug_regions_allowed == true) {
1370*d4514f0bSApple OSS Distributions 		return KERN_SUCCESS;
1371*d4514f0bSApple OSS Distributions 	}
1372*d4514f0bSApple OSS Distributions 	return KERN_DENIED;
1373*d4514f0bSApple OSS Distributions }
1374*d4514f0bSApple OSS Distributions 
1375*d4514f0bSApple OSS Distributions kern_return_t
txm_associate_debug_region(pmap_t pmap,const vm_address_t region_addr,const vm_size_t region_size)1376*d4514f0bSApple OSS Distributions txm_associate_debug_region(
1377*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1378*d4514f0bSApple OSS Distributions 	const vm_address_t region_addr,
1379*d4514f0bSApple OSS Distributions 	const vm_size_t region_size)
1380*d4514f0bSApple OSS Distributions {
1381*d4514f0bSApple OSS Distributions 	/*
1382*d4514f0bSApple OSS Distributions 	 * This function is an interesting one. There is no need for us to make
1383*d4514f0bSApple OSS Distributions 	 * a call into TXM for this one and instead, all we need to do here is
1384*d4514f0bSApple OSS Distributions 	 * to verify that the TXM address space actually allows debug regions to
1385*d4514f0bSApple OSS Distributions 	 * be mapped in or not.
1386*d4514f0bSApple OSS Distributions 	 */
1387*d4514f0bSApple OSS Distributions 	(void)region_addr;
1388*d4514f0bSApple OSS Distributions 	(void)region_size;
1389*d4514f0bSApple OSS Distributions 
1390*d4514f0bSApple OSS Distributions 	kern_return_t ret = txm_address_space_debugged(pmap);
1391*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
1392*d4514f0bSApple OSS Distributions 		printf("address space does not allow creating debug regions\n");
1393*d4514f0bSApple OSS Distributions 	}
1394*d4514f0bSApple OSS Distributions 
1395*d4514f0bSApple OSS Distributions 	return ret;
1396*d4514f0bSApple OSS Distributions }
1397*d4514f0bSApple OSS Distributions 
1398*d4514f0bSApple OSS Distributions kern_return_t
txm_allow_invalid_code(pmap_t pmap)1399*d4514f0bSApple OSS Distributions txm_allow_invalid_code(
1400*d4514f0bSApple OSS Distributions 	pmap_t pmap)
1401*d4514f0bSApple OSS Distributions {
1402*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1403*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAllowInvalidCode,
1404*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1405*d4514f0bSApple OSS Distributions 	};
1406*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = pmap_txm_addr_space(pmap);
1407*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1408*d4514f0bSApple OSS Distributions 
1409*d4514f0bSApple OSS Distributions 	/*
1410*d4514f0bSApple OSS Distributions 	 * Allowing invalid code may require exclusive access to the TXM address
1411*d4514f0bSApple OSS Distributions 	 * space lock within TXM.
1412*d4514f0bSApple OSS Distributions 	 */
1413*d4514f0bSApple OSS Distributions 
1414*d4514f0bSApple OSS Distributions 	pmap_txm_acquire_exclusive_lock(pmap);
1415*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, txm_addr_space);
1416*d4514f0bSApple OSS Distributions 	pmap_txm_release_exclusive_lock(pmap);
1417*d4514f0bSApple OSS Distributions 
1418*d4514f0bSApple OSS Distributions 	return ret;
1419*d4514f0bSApple OSS Distributions }
1420*d4514f0bSApple OSS Distributions 
1421*d4514f0bSApple OSS Distributions kern_return_t
txm_get_trust_level_kdp(pmap_t pmap,uint32_t * trust_level)1422*d4514f0bSApple OSS Distributions txm_get_trust_level_kdp(
1423*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1424*d4514f0bSApple OSS Distributions 	uint32_t *trust_level)
1425*d4514f0bSApple OSS Distributions {
1426*d4514f0bSApple OSS Distributions 	CSTrust_t txm_trust_level = kCSTrustUntrusted;
1427*d4514f0bSApple OSS Distributions 
1428*d4514f0bSApple OSS Distributions 	kern_return_t ret = pmap_txm_get_trust_level_kdp(pmap, &txm_trust_level);
1429*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
1430*d4514f0bSApple OSS Distributions 		return ret;
1431*d4514f0bSApple OSS Distributions 	}
1432*d4514f0bSApple OSS Distributions 
1433*d4514f0bSApple OSS Distributions 	if (trust_level != NULL) {
1434*d4514f0bSApple OSS Distributions 		*trust_level = txm_trust_level;
1435*d4514f0bSApple OSS Distributions 	}
1436*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1437*d4514f0bSApple OSS Distributions }
1438*d4514f0bSApple OSS Distributions 
1439*d4514f0bSApple OSS Distributions kern_return_t
txm_get_jit_address_range_kdp(pmap_t pmap,uintptr_t * jit_region_start,uintptr_t * jit_region_end)1440*d4514f0bSApple OSS Distributions txm_get_jit_address_range_kdp(
1441*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1442*d4514f0bSApple OSS Distributions 	uintptr_t *jit_region_start,
1443*d4514f0bSApple OSS Distributions 	uintptr_t *jit_region_end)
1444*d4514f0bSApple OSS Distributions {
1445*d4514f0bSApple OSS Distributions 	return pmap_txm_get_jit_address_range_kdp(pmap, jit_region_start, jit_region_end);
1446*d4514f0bSApple OSS Distributions }
1447*d4514f0bSApple OSS Distributions 
1448*d4514f0bSApple OSS Distributions kern_return_t
txm_address_space_exempt(const pmap_t pmap)1449*d4514f0bSApple OSS Distributions txm_address_space_exempt(
1450*d4514f0bSApple OSS Distributions 	const pmap_t pmap)
1451*d4514f0bSApple OSS Distributions {
1452*d4514f0bSApple OSS Distributions 	if (pmap_performs_stage2_translations(pmap) == true) {
1453*d4514f0bSApple OSS Distributions 		return KERN_SUCCESS;
1454*d4514f0bSApple OSS Distributions 	}
1455*d4514f0bSApple OSS Distributions 
1456*d4514f0bSApple OSS Distributions 	return KERN_DENIED;
1457*d4514f0bSApple OSS Distributions }
1458*d4514f0bSApple OSS Distributions 
1459*d4514f0bSApple OSS Distributions kern_return_t
txm_fork_prepare(pmap_t old_pmap,pmap_t new_pmap)1460*d4514f0bSApple OSS Distributions txm_fork_prepare(
1461*d4514f0bSApple OSS Distributions 	pmap_t old_pmap,
1462*d4514f0bSApple OSS Distributions 	pmap_t new_pmap)
1463*d4514f0bSApple OSS Distributions {
1464*d4514f0bSApple OSS Distributions 	/*
1465*d4514f0bSApple OSS Distributions 	 * We'll add support for this as the need for it becomes more important.
1466*d4514f0bSApple OSS Distributions 	 * TXMTODO: Complete this implementation.
1467*d4514f0bSApple OSS Distributions 	 */
1468*d4514f0bSApple OSS Distributions 	(void)old_pmap;
1469*d4514f0bSApple OSS Distributions 	(void)new_pmap;
1470*d4514f0bSApple OSS Distributions 
1471*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1472*d4514f0bSApple OSS Distributions }
1473*d4514f0bSApple OSS Distributions 
1474*d4514f0bSApple OSS Distributions kern_return_t
txm_acquire_signing_identifier(const void * sig_obj,const char ** signing_id)1475*d4514f0bSApple OSS Distributions txm_acquire_signing_identifier(
1476*d4514f0bSApple OSS Distributions 	const void *sig_obj,
1477*d4514f0bSApple OSS Distributions 	const char **signing_id)
1478*d4514f0bSApple OSS Distributions {
1479*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1480*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAcquireSigningIdentifier,
1481*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1482*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
1483*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1484*d4514f0bSApple OSS Distributions 	};
1485*d4514f0bSApple OSS Distributions 
1486*d4514f0bSApple OSS Distributions 	/* Get the signing ID -- should not fail */
1487*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, sig_obj);
1488*d4514f0bSApple OSS Distributions 
1489*d4514f0bSApple OSS Distributions 	if (signing_id != NULL) {
1490*d4514f0bSApple OSS Distributions 		*signing_id = (const char*)txm_call.return_words[0];
1491*d4514f0bSApple OSS Distributions 	}
1492*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1493*d4514f0bSApple OSS Distributions }
1494*d4514f0bSApple OSS Distributions 
1495*d4514f0bSApple OSS Distributions #pragma mark Entitlements
1496*d4514f0bSApple OSS Distributions 
1497*d4514f0bSApple OSS Distributions kern_return_t
txm_associate_kernel_entitlements(void * sig_obj,const void * kernel_entitlements)1498*d4514f0bSApple OSS Distributions txm_associate_kernel_entitlements(
1499*d4514f0bSApple OSS Distributions 	void *sig_obj,
1500*d4514f0bSApple OSS Distributions 	const void *kernel_entitlements)
1501*d4514f0bSApple OSS Distributions {
1502*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1503*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAssociateKernelEntitlements,
1504*d4514f0bSApple OSS Distributions 		.num_input_args = 2,
1505*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1506*d4514f0bSApple OSS Distributions 	};
1507*d4514f0bSApple OSS Distributions 
1508*d4514f0bSApple OSS Distributions 	/* Associate the kernel entitlements -- should not fail */
1509*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, sig_obj, kernel_entitlements);
1510*d4514f0bSApple OSS Distributions 
1511*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1512*d4514f0bSApple OSS Distributions }
1513*d4514f0bSApple OSS Distributions 
1514*d4514f0bSApple OSS Distributions kern_return_t
txm_resolve_kernel_entitlements(pmap_t pmap,const void ** kernel_entitlements)1515*d4514f0bSApple OSS Distributions txm_resolve_kernel_entitlements(
1516*d4514f0bSApple OSS Distributions 	pmap_t pmap,
1517*d4514f0bSApple OSS Distributions 	const void **kernel_entitlements)
1518*d4514f0bSApple OSS Distributions {
1519*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1520*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorResolveKernelEntitlementsAddressSpace,
1521*d4514f0bSApple OSS Distributions 		.skip_logs = true,
1522*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1523*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
1524*d4514f0bSApple OSS Distributions 		.failure_silent = true,
1525*d4514f0bSApple OSS Distributions 	};
1526*d4514f0bSApple OSS Distributions 	TXMAddressSpace_t *txm_addr_space = NULL;
1527*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1528*d4514f0bSApple OSS Distributions 
1529*d4514f0bSApple OSS Distributions 	if (pmap == pmap_txm_kernel_pmap()) {
1530*d4514f0bSApple OSS Distributions 		return KERN_NOT_FOUND;
1531*d4514f0bSApple OSS Distributions 	}
1532*d4514f0bSApple OSS Distributions 	txm_addr_space = pmap_txm_addr_space(pmap);
1533*d4514f0bSApple OSS Distributions 
1534*d4514f0bSApple OSS Distributions 	pmap_txm_acquire_shared_lock(pmap);
1535*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, txm_addr_space);
1536*d4514f0bSApple OSS Distributions 	pmap_txm_release_shared_lock(pmap);
1537*d4514f0bSApple OSS Distributions 
1538*d4514f0bSApple OSS Distributions 	if ((ret == KERN_SUCCESS) && (kernel_entitlements != NULL)) {
1539*d4514f0bSApple OSS Distributions 		*kernel_entitlements = (const void*)txm_call.return_words[0];
1540*d4514f0bSApple OSS Distributions 	}
1541*d4514f0bSApple OSS Distributions 	return ret;
1542*d4514f0bSApple OSS Distributions }
1543*d4514f0bSApple OSS Distributions 
1544*d4514f0bSApple OSS Distributions kern_return_t
txm_accelerate_entitlements(void * sig_obj,CEQueryContext_t * ce_ctx)1545*d4514f0bSApple OSS Distributions txm_accelerate_entitlements(
1546*d4514f0bSApple OSS Distributions 	void *sig_obj,
1547*d4514f0bSApple OSS Distributions 	CEQueryContext_t *ce_ctx)
1548*d4514f0bSApple OSS Distributions {
1549*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1550*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorAccelerateEntitlements,
1551*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1552*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
1553*d4514f0bSApple OSS Distributions 	};
1554*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1555*d4514f0bSApple OSS Distributions 
1556*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, sig_obj);
1557*d4514f0bSApple OSS Distributions 	if ((ret == KERN_SUCCESS) && (ce_ctx != NULL)) {
1558*d4514f0bSApple OSS Distributions 		*ce_ctx = (CEQueryContext_t)txm_call.return_words[0];
1559*d4514f0bSApple OSS Distributions 	}
1560*d4514f0bSApple OSS Distributions 
1561*d4514f0bSApple OSS Distributions 	return ret;
1562*d4514f0bSApple OSS Distributions }
1563*d4514f0bSApple OSS Distributions 
1564*d4514f0bSApple OSS Distributions #pragma mark Image4
1565*d4514f0bSApple OSS Distributions 
1566*d4514f0bSApple OSS Distributions void*
txm_image4_storage_data(__unused size_t * allocated_size)1567*d4514f0bSApple OSS Distributions txm_image4_storage_data(
1568*d4514f0bSApple OSS Distributions 	__unused size_t *allocated_size)
1569*d4514f0bSApple OSS Distributions {
1570*d4514f0bSApple OSS Distributions 	/*
1571*d4514f0bSApple OSS Distributions 	 * AppleImage4 builds a variant of TXM which TXM should link against statically
1572*d4514f0bSApple OSS Distributions 	 * thereby removing the need for the kernel to allocate some data on behalf of
1573*d4514f0bSApple OSS Distributions 	 * the kernel extension.
1574*d4514f0bSApple OSS Distributions 	 */
1575*d4514f0bSApple OSS Distributions 	panic("unsupported AppleImage4 interface");
1576*d4514f0bSApple OSS Distributions }
1577*d4514f0bSApple OSS Distributions 
1578*d4514f0bSApple OSS Distributions void
txm_image4_set_nonce(const img4_nonce_domain_index_t ndi,const img4_nonce_t * nonce)1579*d4514f0bSApple OSS Distributions txm_image4_set_nonce(
1580*d4514f0bSApple OSS Distributions 	const img4_nonce_domain_index_t ndi,
1581*d4514f0bSApple OSS Distributions 	const img4_nonce_t *nonce)
1582*d4514f0bSApple OSS Distributions {
1583*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1584*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4SetNonce,
1585*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1586*d4514f0bSApple OSS Distributions 		.num_input_args = 2,
1587*d4514f0bSApple OSS Distributions 	};
1588*d4514f0bSApple OSS Distributions 
1589*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, ndi, nonce);
1590*d4514f0bSApple OSS Distributions }
1591*d4514f0bSApple OSS Distributions 
1592*d4514f0bSApple OSS Distributions void
txm_image4_roll_nonce(const img4_nonce_domain_index_t ndi)1593*d4514f0bSApple OSS Distributions txm_image4_roll_nonce(
1594*d4514f0bSApple OSS Distributions 	const img4_nonce_domain_index_t ndi)
1595*d4514f0bSApple OSS Distributions {
1596*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1597*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4RollNonce,
1598*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1599*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1600*d4514f0bSApple OSS Distributions 	};
1601*d4514f0bSApple OSS Distributions 
1602*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, ndi);
1603*d4514f0bSApple OSS Distributions }
1604*d4514f0bSApple OSS Distributions 
1605*d4514f0bSApple OSS Distributions errno_t
txm_image4_copy_nonce(const img4_nonce_domain_index_t ndi,img4_nonce_t * nonce_out)1606*d4514f0bSApple OSS Distributions txm_image4_copy_nonce(
1607*d4514f0bSApple OSS Distributions 	const img4_nonce_domain_index_t ndi,
1608*d4514f0bSApple OSS Distributions 	img4_nonce_t *nonce_out)
1609*d4514f0bSApple OSS Distributions {
1610*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1611*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4GetNonce,
1612*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1613*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
1614*d4514f0bSApple OSS Distributions 	};
1615*d4514f0bSApple OSS Distributions 	const img4_nonce_t *nonce = NULL;
1616*d4514f0bSApple OSS Distributions 	TXMReturn_t txm_ret = {0};
1617*d4514f0bSApple OSS Distributions 	kern_return_t ret = KERN_DENIED;
1618*d4514f0bSApple OSS Distributions 
1619*d4514f0bSApple OSS Distributions 	ret = txm_kernel_call(&txm_call, ndi);
1620*d4514f0bSApple OSS Distributions 	if (ret != KERN_SUCCESS) {
1621*d4514f0bSApple OSS Distributions 		txm_ret = txm_call.txm_ret;
1622*d4514f0bSApple OSS Distributions 		if (txm_ret.returnCode != kTXMReturnCodeErrno) {
1623*d4514f0bSApple OSS Distributions 			return EPERM;
1624*d4514f0bSApple OSS Distributions 		}
1625*d4514f0bSApple OSS Distributions 		return txm_ret.errnoRet;
1626*d4514f0bSApple OSS Distributions 	}
1627*d4514f0bSApple OSS Distributions 
1628*d4514f0bSApple OSS Distributions 	/* Acquire a pointer to the nonce from TXM */
1629*d4514f0bSApple OSS Distributions 	nonce = (const img4_nonce_t*)txm_call.return_words[0];
1630*d4514f0bSApple OSS Distributions 
1631*d4514f0bSApple OSS Distributions 	if (nonce_out) {
1632*d4514f0bSApple OSS Distributions 		*nonce_out = *nonce;
1633*d4514f0bSApple OSS Distributions 	}
1634*d4514f0bSApple OSS Distributions 	return 0;
1635*d4514f0bSApple OSS Distributions }
1636*d4514f0bSApple OSS Distributions 
1637*d4514f0bSApple OSS Distributions errno_t
txm_image4_execute_object(img4_runtime_object_spec_index_t obj_spec_index,const img4_buff_t * payload,const img4_buff_t * manifest)1638*d4514f0bSApple OSS Distributions txm_image4_execute_object(
1639*d4514f0bSApple OSS Distributions 	img4_runtime_object_spec_index_t obj_spec_index,
1640*d4514f0bSApple OSS Distributions 	const img4_buff_t *payload,
1641*d4514f0bSApple OSS Distributions 	const img4_buff_t *manifest)
1642*d4514f0bSApple OSS Distributions {
1643*d4514f0bSApple OSS Distributions 	/* Not supported within TXM yet */
1644*d4514f0bSApple OSS Distributions 	(void)obj_spec_index;
1645*d4514f0bSApple OSS Distributions 	(void)payload;
1646*d4514f0bSApple OSS Distributions 	(void)manifest;
1647*d4514f0bSApple OSS Distributions 
1648*d4514f0bSApple OSS Distributions 	printf("image4 object execution isn't supported by TXM\n");
1649*d4514f0bSApple OSS Distributions 	return ENOSYS;
1650*d4514f0bSApple OSS Distributions }
1651*d4514f0bSApple OSS Distributions 
1652*d4514f0bSApple OSS Distributions errno_t
txm_image4_copy_object(img4_runtime_object_spec_index_t obj_spec_index,vm_address_t object_out,size_t * object_length)1653*d4514f0bSApple OSS Distributions txm_image4_copy_object(
1654*d4514f0bSApple OSS Distributions 	img4_runtime_object_spec_index_t obj_spec_index,
1655*d4514f0bSApple OSS Distributions 	vm_address_t object_out,
1656*d4514f0bSApple OSS Distributions 	size_t *object_length)
1657*d4514f0bSApple OSS Distributions {
1658*d4514f0bSApple OSS Distributions 	/* Not supported within TXM yet */
1659*d4514f0bSApple OSS Distributions 	(void)obj_spec_index;
1660*d4514f0bSApple OSS Distributions 	(void)object_out;
1661*d4514f0bSApple OSS Distributions 	(void)object_length;
1662*d4514f0bSApple OSS Distributions 
1663*d4514f0bSApple OSS Distributions 	printf("image4 object copying isn't supported by TXM\n");
1664*d4514f0bSApple OSS Distributions 	return ENOSYS;
1665*d4514f0bSApple OSS Distributions }
1666*d4514f0bSApple OSS Distributions 
1667*d4514f0bSApple OSS Distributions const void*
txm_image4_get_monitor_exports(void)1668*d4514f0bSApple OSS Distributions txm_image4_get_monitor_exports(void)
1669*d4514f0bSApple OSS Distributions {
1670*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1671*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4GetExports,
1672*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1673*d4514f0bSApple OSS Distributions 		.num_output_args = 1,
1674*d4514f0bSApple OSS Distributions 	};
1675*d4514f0bSApple OSS Distributions 
1676*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call);
1677*d4514f0bSApple OSS Distributions 	return (const void*)txm_call.return_words[0];
1678*d4514f0bSApple OSS Distributions }
1679*d4514f0bSApple OSS Distributions 
1680*d4514f0bSApple OSS Distributions errno_t
txm_image4_set_release_type(const char * release_type)1681*d4514f0bSApple OSS Distributions txm_image4_set_release_type(
1682*d4514f0bSApple OSS Distributions 	const char *release_type)
1683*d4514f0bSApple OSS Distributions {
1684*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1685*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4SetReleaseType,
1686*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1687*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1688*d4514f0bSApple OSS Distributions 	};
1689*d4514f0bSApple OSS Distributions 
1690*d4514f0bSApple OSS Distributions 	/* Set the release type -- cannot fail */
1691*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, release_type);
1692*d4514f0bSApple OSS Distributions 
1693*d4514f0bSApple OSS Distributions 	return 0;
1694*d4514f0bSApple OSS Distributions }
1695*d4514f0bSApple OSS Distributions 
1696*d4514f0bSApple OSS Distributions errno_t
txm_image4_set_bnch_shadow(const img4_nonce_domain_index_t ndi)1697*d4514f0bSApple OSS Distributions txm_image4_set_bnch_shadow(
1698*d4514f0bSApple OSS Distributions 	const img4_nonce_domain_index_t ndi)
1699*d4514f0bSApple OSS Distributions {
1700*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1701*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4SetBootNonceShadow,
1702*d4514f0bSApple OSS Distributions 		.failure_fatal = true,
1703*d4514f0bSApple OSS Distributions 		.num_input_args = 1,
1704*d4514f0bSApple OSS Distributions 	};
1705*d4514f0bSApple OSS Distributions 
1706*d4514f0bSApple OSS Distributions 	/* Set the release type -- cannot fail */
1707*d4514f0bSApple OSS Distributions 	txm_kernel_call(&txm_call, ndi);
1708*d4514f0bSApple OSS Distributions 
1709*d4514f0bSApple OSS Distributions 	return 0;
1710*d4514f0bSApple OSS Distributions }
1711*d4514f0bSApple OSS Distributions 
1712*d4514f0bSApple OSS Distributions #pragma mark Image4 - New
1713*d4514f0bSApple OSS Distributions 
1714*d4514f0bSApple OSS Distributions static inline bool
_txm_image4_monitor_trap_supported(image4_cs_trap_t selector)1715*d4514f0bSApple OSS Distributions _txm_image4_monitor_trap_supported(
1716*d4514f0bSApple OSS Distributions 	image4_cs_trap_t selector)
1717*d4514f0bSApple OSS Distributions {
1718*d4514f0bSApple OSS Distributions 	switch (selector) {
1719*d4514f0bSApple OSS Distributions #if kTXMImage4APIVersion >= 1
1720*d4514f0bSApple OSS Distributions 	case IMAGE4_CS_TRAP_KMOD_SET_RELEASE_TYPE:
1721*d4514f0bSApple OSS Distributions 	case IMAGE4_CS_TRAP_NONCE_SET:
1722*d4514f0bSApple OSS Distributions 	case IMAGE4_CS_TRAP_NONCE_ROLL:
1723*d4514f0bSApple OSS Distributions 	case IMAGE4_CS_TRAP_IMAGE_ACTIVATE:
1724*d4514f0bSApple OSS Distributions 		return true;
1725*d4514f0bSApple OSS Distributions #endif
1726*d4514f0bSApple OSS Distributions 
1727*d4514f0bSApple OSS Distributions 	default:
1728*d4514f0bSApple OSS Distributions 		return false;
1729*d4514f0bSApple OSS Distributions 	}
1730*d4514f0bSApple OSS Distributions }
1731*d4514f0bSApple OSS Distributions 
1732*d4514f0bSApple OSS Distributions kern_return_t
txm_image4_transfer_region(image4_cs_trap_t selector,vm_address_t region_addr,vm_size_t region_size)1733*d4514f0bSApple OSS Distributions txm_image4_transfer_region(
1734*d4514f0bSApple OSS Distributions 	image4_cs_trap_t selector,
1735*d4514f0bSApple OSS Distributions 	vm_address_t region_addr,
1736*d4514f0bSApple OSS Distributions 	vm_size_t region_size)
1737*d4514f0bSApple OSS Distributions {
1738*d4514f0bSApple OSS Distributions 	if (_txm_image4_monitor_trap_supported(selector) == true) {
1739*d4514f0bSApple OSS Distributions 		txm_transfer_region(region_addr, region_size);
1740*d4514f0bSApple OSS Distributions 	}
1741*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1742*d4514f0bSApple OSS Distributions }
1743*d4514f0bSApple OSS Distributions 
1744*d4514f0bSApple OSS Distributions kern_return_t
txm_image4_reclaim_region(image4_cs_trap_t selector,vm_address_t region_addr,vm_size_t region_size)1745*d4514f0bSApple OSS Distributions txm_image4_reclaim_region(
1746*d4514f0bSApple OSS Distributions 	image4_cs_trap_t selector,
1747*d4514f0bSApple OSS Distributions 	vm_address_t region_addr,
1748*d4514f0bSApple OSS Distributions 	vm_size_t region_size)
1749*d4514f0bSApple OSS Distributions {
1750*d4514f0bSApple OSS Distributions 	if (_txm_image4_monitor_trap_supported(selector) == true) {
1751*d4514f0bSApple OSS Distributions 		txm_reclaim_region(region_addr, region_size);
1752*d4514f0bSApple OSS Distributions 	}
1753*d4514f0bSApple OSS Distributions 	return KERN_SUCCESS;
1754*d4514f0bSApple OSS Distributions }
1755*d4514f0bSApple OSS Distributions 
1756*d4514f0bSApple OSS Distributions errno_t
txm_image4_monitor_trap(image4_cs_trap_t selector,const void * input_data,size_t input_size)1757*d4514f0bSApple OSS Distributions txm_image4_monitor_trap(
1758*d4514f0bSApple OSS Distributions 	image4_cs_trap_t selector,
1759*d4514f0bSApple OSS Distributions 	const void *input_data,
1760*d4514f0bSApple OSS Distributions 	size_t input_size)
1761*d4514f0bSApple OSS Distributions {
1762*d4514f0bSApple OSS Distributions 	txm_call_t txm_call = {
1763*d4514f0bSApple OSS Distributions 		.selector = kTXMKernelSelectorImage4Dispatch,
1764*d4514f0bSApple OSS Distributions 		.num_input_args = 5,
1765*d4514f0bSApple OSS Distributions 	};
1766*d4514f0bSApple OSS Distributions 
1767*d4514f0bSApple OSS Distributions 	kern_return_t ret = txm_kernel_call(
1768*d4514f0bSApple OSS Distributions 		&txm_call, selector,
1769*d4514f0bSApple OSS Distributions 		input_data, input_size,
1770*d4514f0bSApple OSS Distributions 		NULL, NULL);
1771*d4514f0bSApple OSS Distributions 
1772*d4514f0bSApple OSS Distributions 	/* Return 0 for success */
1773*d4514f0bSApple OSS Distributions 	if (ret == KERN_SUCCESS) {
1774*d4514f0bSApple OSS Distributions 		return 0;
1775*d4514f0bSApple OSS Distributions 	}
1776*d4514f0bSApple OSS Distributions 
1777*d4514f0bSApple OSS Distributions 	/* Check for an errno_t return */
1778*d4514f0bSApple OSS Distributions 	if (txm_call.txm_ret.returnCode == kTXMReturnCodeErrno) {
1779*d4514f0bSApple OSS Distributions 		if (txm_call.txm_ret.errnoRet == 0) {
1780*d4514f0bSApple OSS Distributions 			panic("image4 dispatch: unexpected success errno_t: %llu", selector);
1781*d4514f0bSApple OSS Distributions 		}
1782*d4514f0bSApple OSS Distributions 		return txm_call.txm_ret.errnoRet;
1783*d4514f0bSApple OSS Distributions 	}
1784*d4514f0bSApple OSS Distributions 
1785*d4514f0bSApple OSS Distributions 	/* Return a generic error */
1786*d4514f0bSApple OSS Distributions 	return EPERM;
1787*d4514f0bSApple OSS Distributions }
1788*d4514f0bSApple OSS Distributions 
1789*d4514f0bSApple OSS Distributions 
1790*d4514f0bSApple OSS Distributions #endif /* CONFIG_SPTM */
1791