1*e3723e1fSApple OSS Distributions /*
2*e3723e1fSApple OSS Distributions * Copyright (c) 2000,2008-2009 Apple Inc. All rights reserved.
3*e3723e1fSApple OSS Distributions *
4*e3723e1fSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*e3723e1fSApple OSS Distributions *
6*e3723e1fSApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*e3723e1fSApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*e3723e1fSApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*e3723e1fSApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*e3723e1fSApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*e3723e1fSApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*e3723e1fSApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*e3723e1fSApple OSS Distributions * terms of an Apple operating system software license agreement.
14*e3723e1fSApple OSS Distributions *
15*e3723e1fSApple OSS Distributions * Please obtain a copy of the License at
16*e3723e1fSApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*e3723e1fSApple OSS Distributions *
18*e3723e1fSApple OSS Distributions * The Original Code and all software distributed under the License are
19*e3723e1fSApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*e3723e1fSApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*e3723e1fSApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*e3723e1fSApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*e3723e1fSApple OSS Distributions * Please see the License for the specific language governing rights and
24*e3723e1fSApple OSS Distributions * limitations under the License.
25*e3723e1fSApple OSS Distributions *
26*e3723e1fSApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*e3723e1fSApple OSS Distributions */
28*e3723e1fSApple OSS Distributions /*
29*e3723e1fSApple OSS Distributions * Copyright (c) 1997 Apple Inc.
30*e3723e1fSApple OSS Distributions *
31*e3723e1fSApple OSS Distributions */
32*e3723e1fSApple OSS Distributions #include <libkern/c++/OSMetaClass.h>
33*e3723e1fSApple OSS Distributions #include <libkern/c++/OSKext.h>
34*e3723e1fSApple OSS Distributions #include <libkern/c++/OSLib.h>
35*e3723e1fSApple OSS Distributions #include <libkern/c++/OSSymbol.h>
36*e3723e1fSApple OSS Distributions #include <IOKit/IOKitDebug.h>
37*e3723e1fSApple OSS Distributions
38*e3723e1fSApple OSS Distributions #include <sys/cdefs.h>
39*e3723e1fSApple OSS Distributions #if defined(HAS_APPLE_PAC)
40*e3723e1fSApple OSS Distributions #include <ptrauth.h>
41*e3723e1fSApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x) ((uintptr_t) ptrauth_strip(ptrauth_nop_cast(void *, (x)), ptrauth_key_function_pointer))
42*e3723e1fSApple OSS Distributions #else /* defined(HAS_APPLE_PAC) */
43*e3723e1fSApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x) ((uintptr_t) (x))
44*e3723e1fSApple OSS Distributions #endif /* !defined(HAS_APPLE_PAC) */
45*e3723e1fSApple OSS Distributions
46*e3723e1fSApple OSS Distributions __BEGIN_DECLS
47*e3723e1fSApple OSS Distributions
48*e3723e1fSApple OSS Distributions #include <string.h>
49*e3723e1fSApple OSS Distributions #include <mach/mach_types.h>
50*e3723e1fSApple OSS Distributions #include <libkern/kernel_mach_header.h>
51*e3723e1fSApple OSS Distributions #include <libkern/prelink.h>
52*e3723e1fSApple OSS Distributions #include <stdarg.h>
53*e3723e1fSApple OSS Distributions
54*e3723e1fSApple OSS Distributions #if KASAN
55*e3723e1fSApple OSS Distributions #include <san/kasan.h>
56*e3723e1fSApple OSS Distributions #endif
57*e3723e1fSApple OSS Distributions
58*e3723e1fSApple OSS Distributions #if CONFIG_SPTM
59*e3723e1fSApple OSS Distributions #include <arm64/sptm/sptm.h>
60*e3723e1fSApple OSS Distributions #endif
61*e3723e1fSApple OSS Distributions
62*e3723e1fSApple OSS Distributions #if PRAGMA_MARK
63*e3723e1fSApple OSS Distributions #pragma mark Constants &c.
64*e3723e1fSApple OSS Distributions #endif /* PRAGMA_MARK */
65*e3723e1fSApple OSS Distributions OSKextLogSpec kOSRuntimeLogSpec =
66*e3723e1fSApple OSS Distributions kOSKextLogErrorLevel |
67*e3723e1fSApple OSS Distributions kOSKextLogLoadFlag |
68*e3723e1fSApple OSS Distributions kOSKextLogKextBookkeepingFlag;
69*e3723e1fSApple OSS Distributions
70*e3723e1fSApple OSS Distributions #if PRAGMA_MARK
71*e3723e1fSApple OSS Distributions #pragma mark Logging Bootstrap
72*e3723e1fSApple OSS Distributions #endif /* PRAGMA_MARK */
73*e3723e1fSApple OSS Distributions /*********************************************************************
74*e3723e1fSApple OSS Distributions * kern_os Logging Bootstrap
75*e3723e1fSApple OSS Distributions *
76*e3723e1fSApple OSS Distributions * We can't call in to OSKext until the kernel's C++ environment is up
77*e3723e1fSApple OSS Distributions * and running, so let's mask those references with a check variable.
78*e3723e1fSApple OSS Distributions * We print unconditionally if C++ isn't up, but if that's the case
79*e3723e1fSApple OSS Distributions * we've generally hit a serious error in kernel init!
80*e3723e1fSApple OSS Distributions *********************************************************************/
81*e3723e1fSApple OSS Distributions static bool gKernelCPPInitialized = false;
82*e3723e1fSApple OSS Distributions
83*e3723e1fSApple OSS Distributions #define OSRuntimeLog(kext, flags, format, args ...) \
84*e3723e1fSApple OSS Distributions do { \
85*e3723e1fSApple OSS Distributions if (gKernelCPPInitialized) { \
86*e3723e1fSApple OSS Distributions OSKextLog((kext), (flags), (format), ## args); \
87*e3723e1fSApple OSS Distributions } else { \
88*e3723e1fSApple OSS Distributions printf((format), ## args); \
89*e3723e1fSApple OSS Distributions } \
90*e3723e1fSApple OSS Distributions } while (0)
91*e3723e1fSApple OSS Distributions
92*e3723e1fSApple OSS Distributions #if PRAGMA_MARK
93*e3723e1fSApple OSS Distributions #pragma mark Libkern Init
94*e3723e1fSApple OSS Distributions #endif /* PRAGMA_MARK */
95*e3723e1fSApple OSS Distributions /*********************************************************************
96*e3723e1fSApple OSS Distributions * Libkern Init
97*e3723e1fSApple OSS Distributions *********************************************************************/
98*e3723e1fSApple OSS Distributions
99*e3723e1fSApple OSS Distributions #if __GNUC__ >= 3
100*e3723e1fSApple OSS Distributions void __dead2
__cxa_pure_virtual(void)101*e3723e1fSApple OSS Distributions __cxa_pure_virtual( void )
102*e3723e1fSApple OSS Distributions {
103*e3723e1fSApple OSS Distributions panic("%s", __FUNCTION__);
104*e3723e1fSApple OSS Distributions }
105*e3723e1fSApple OSS Distributions #else
106*e3723e1fSApple OSS Distributions void __dead2
__pure_virtual(void)107*e3723e1fSApple OSS Distributions __pure_virtual( void )
108*e3723e1fSApple OSS Distributions {
109*e3723e1fSApple OSS Distributions panic("%s", __FUNCTION__);
110*e3723e1fSApple OSS Distributions }
111*e3723e1fSApple OSS Distributions #endif
112*e3723e1fSApple OSS Distributions
113*e3723e1fSApple OSS Distributions extern lck_grp_t * IOLockGroup;
114*e3723e1fSApple OSS Distributions extern kmod_info_t g_kernel_kmod_info;
115*e3723e1fSApple OSS Distributions #if CONFIG_SPTM
116*e3723e1fSApple OSS Distributions extern kmod_info_t g_sptm_kmod_info, g_txm_kmod_info;
117*e3723e1fSApple OSS Distributions #endif /* CONFIG_SPTM */
118*e3723e1fSApple OSS Distributions
119*e3723e1fSApple OSS Distributions enum {
120*e3723e1fSApple OSS Distributions kOSSectionNamesDefault = 0,
121*e3723e1fSApple OSS Distributions kOSSectionNamesBuiltinKext = 1,
122*e3723e1fSApple OSS Distributions kOSSectionNamesCount = 2,
123*e3723e1fSApple OSS Distributions };
124*e3723e1fSApple OSS Distributions enum {
125*e3723e1fSApple OSS Distributions kOSSectionNameInitializer = 0,
126*e3723e1fSApple OSS Distributions kOSSectionNameFinalizer = 1,
127*e3723e1fSApple OSS Distributions kOSSectionNameCount = 2
128*e3723e1fSApple OSS Distributions };
129*e3723e1fSApple OSS Distributions
130*e3723e1fSApple OSS Distributions static const char *
131*e3723e1fSApple OSS Distributions gOSStructorSectionNames[kOSSectionNamesCount][kOSSectionNameCount] = {
132*e3723e1fSApple OSS Distributions { SECT_MODINITFUNC, SECT_MODTERMFUNC },
133*e3723e1fSApple OSS Distributions { kBuiltinInitSection, kBuiltinTermSection }
134*e3723e1fSApple OSS Distributions };
135*e3723e1fSApple OSS Distributions
136*e3723e1fSApple OSS Distributions void
OSlibkernInit(void)137*e3723e1fSApple OSS Distributions OSlibkernInit(void)
138*e3723e1fSApple OSS Distributions {
139*e3723e1fSApple OSS Distributions // This must be called before calling OSRuntimeInitializeCPP.
140*e3723e1fSApple OSS Distributions OSMetaClassBase::initialize();
141*e3723e1fSApple OSS Distributions
142*e3723e1fSApple OSS Distributions g_kernel_kmod_info.address = (vm_address_t) &_mh_execute_header;
143*e3723e1fSApple OSS Distributions #if CONFIG_SPTM
144*e3723e1fSApple OSS Distributions g_sptm_kmod_info.address = (vm_offset_t)SPTMArgs->debug_header->image[DEBUG_HEADER_ENTRY_SPTM];
145*e3723e1fSApple OSS Distributions g_txm_kmod_info.address = (vm_offset_t)SPTMArgs->debug_header->image[DEBUG_HEADER_ENTRY_TXM];
146*e3723e1fSApple OSS Distributions #endif /* CONFIG_SPTM */
147*e3723e1fSApple OSS Distributions
148*e3723e1fSApple OSS Distributions if (kOSReturnSuccess != OSRuntimeInitializeCPP(NULL)) {
149*e3723e1fSApple OSS Distributions // &g_kernel_kmod_info, gOSSectionNamesStandard, 0, 0)) {
150*e3723e1fSApple OSS Distributions panic("OSRuntime: C++ runtime failed to initialize.");
151*e3723e1fSApple OSS Distributions }
152*e3723e1fSApple OSS Distributions
153*e3723e1fSApple OSS Distributions gKernelCPPInitialized = true;
154*e3723e1fSApple OSS Distributions
155*e3723e1fSApple OSS Distributions return;
156*e3723e1fSApple OSS Distributions }
157*e3723e1fSApple OSS Distributions
158*e3723e1fSApple OSS Distributions __END_DECLS
159*e3723e1fSApple OSS Distributions
160*e3723e1fSApple OSS Distributions #if PRAGMA_MARK
161*e3723e1fSApple OSS Distributions #pragma mark C++ Runtime Load/Unload
162*e3723e1fSApple OSS Distributions #endif /* PRAGMA_MARK */
163*e3723e1fSApple OSS Distributions /*********************************************************************
164*e3723e1fSApple OSS Distributions * kern_os C++ Runtime Load/Unload
165*e3723e1fSApple OSS Distributions *********************************************************************/
166*e3723e1fSApple OSS Distributions
167*e3723e1fSApple OSS Distributions typedef void (*structor_t)(void);
168*e3723e1fSApple OSS Distributions
169*e3723e1fSApple OSS Distributions static bool
OSRuntimeCallStructorsInSection(OSKext * theKext,kmod_info_t * kmodInfo,void * metaHandle,kernel_segment_command_t * segment,const char * sectionName,uintptr_t textStart,uintptr_t textEnd)170*e3723e1fSApple OSS Distributions OSRuntimeCallStructorsInSection(
171*e3723e1fSApple OSS Distributions OSKext * theKext,
172*e3723e1fSApple OSS Distributions kmod_info_t * kmodInfo,
173*e3723e1fSApple OSS Distributions void * metaHandle,
174*e3723e1fSApple OSS Distributions kernel_segment_command_t * segment,
175*e3723e1fSApple OSS Distributions const char * sectionName,
176*e3723e1fSApple OSS Distributions uintptr_t textStart,
177*e3723e1fSApple OSS Distributions uintptr_t textEnd)
178*e3723e1fSApple OSS Distributions {
179*e3723e1fSApple OSS Distributions kernel_section_t * section;
180*e3723e1fSApple OSS Distributions bool result = TRUE;
181*e3723e1fSApple OSS Distributions
182*e3723e1fSApple OSS Distributions for (section = firstsect(segment);
183*e3723e1fSApple OSS Distributions section != NULL;
184*e3723e1fSApple OSS Distributions section = nextsect(segment, section)) {
185*e3723e1fSApple OSS Distributions if (strncmp(section->sectname, sectionName, sizeof(section->sectname) - 1)) {
186*e3723e1fSApple OSS Distributions continue;
187*e3723e1fSApple OSS Distributions }
188*e3723e1fSApple OSS Distributions if (section->size == 0) {
189*e3723e1fSApple OSS Distributions continue;
190*e3723e1fSApple OSS Distributions }
191*e3723e1fSApple OSS Distributions
192*e3723e1fSApple OSS Distributions structor_t * structors = (structor_t *)section->addr;
193*e3723e1fSApple OSS Distributions if (!structors) {
194*e3723e1fSApple OSS Distributions continue;
195*e3723e1fSApple OSS Distributions }
196*e3723e1fSApple OSS Distributions
197*e3723e1fSApple OSS Distributions structor_t structor;
198*e3723e1fSApple OSS Distributions uintptr_t value;
199*e3723e1fSApple OSS Distributions unsigned long num_structors = section->size / sizeof(structor_t);
200*e3723e1fSApple OSS Distributions unsigned int hit_null_structor = 0;
201*e3723e1fSApple OSS Distributions unsigned long firstIndex = 0;
202*e3723e1fSApple OSS Distributions
203*e3723e1fSApple OSS Distributions if (textStart) {
204*e3723e1fSApple OSS Distributions // bsearch for any in range
205*e3723e1fSApple OSS Distributions unsigned long baseIdx;
206*e3723e1fSApple OSS Distributions unsigned long lim;
207*e3723e1fSApple OSS Distributions firstIndex = num_structors;
208*e3723e1fSApple OSS Distributions for (lim = num_structors, baseIdx = 0; lim; lim >>= 1) {
209*e3723e1fSApple OSS Distributions structor = structors[baseIdx + (lim >> 1)];
210*e3723e1fSApple OSS Distributions if (!structor) {
211*e3723e1fSApple OSS Distributions panic("%s: null structor", kmodInfo->name);
212*e3723e1fSApple OSS Distributions }
213*e3723e1fSApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
214*e3723e1fSApple OSS Distributions if ((value >= textStart) && (value < textEnd)) {
215*e3723e1fSApple OSS Distributions firstIndex = (baseIdx + (lim >> 1));
216*e3723e1fSApple OSS Distributions // scan back for the first in range
217*e3723e1fSApple OSS Distributions for (; firstIndex; firstIndex--) {
218*e3723e1fSApple OSS Distributions structor = structors[firstIndex - 1];
219*e3723e1fSApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
220*e3723e1fSApple OSS Distributions if ((value < textStart) || (value >= textEnd)) {
221*e3723e1fSApple OSS Distributions break;
222*e3723e1fSApple OSS Distributions }
223*e3723e1fSApple OSS Distributions }
224*e3723e1fSApple OSS Distributions break;
225*e3723e1fSApple OSS Distributions }
226*e3723e1fSApple OSS Distributions if (textStart > value) {
227*e3723e1fSApple OSS Distributions // move right
228*e3723e1fSApple OSS Distributions baseIdx += (lim >> 1) + 1;
229*e3723e1fSApple OSS Distributions lim--;
230*e3723e1fSApple OSS Distributions }
231*e3723e1fSApple OSS Distributions // else move left
232*e3723e1fSApple OSS Distributions }
233*e3723e1fSApple OSS Distributions baseIdx = (baseIdx + (lim >> 1));
234*e3723e1fSApple OSS Distributions }
235*e3723e1fSApple OSS Distributions for (;
236*e3723e1fSApple OSS Distributions (firstIndex < num_structors)
237*e3723e1fSApple OSS Distributions && (!metaHandle || OSMetaClass::checkModLoad(metaHandle));
238*e3723e1fSApple OSS Distributions firstIndex++) {
239*e3723e1fSApple OSS Distributions if ((structor = structors[firstIndex])) {
240*e3723e1fSApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
241*e3723e1fSApple OSS Distributions if ((textStart && (value < textStart))
242*e3723e1fSApple OSS Distributions || (textEnd && (value >= textEnd))) {
243*e3723e1fSApple OSS Distributions break;
244*e3723e1fSApple OSS Distributions }
245*e3723e1fSApple OSS Distributions (*structor)();
246*e3723e1fSApple OSS Distributions } else if (!hit_null_structor) {
247*e3723e1fSApple OSS Distributions hit_null_structor = 1;
248*e3723e1fSApple OSS Distributions OSRuntimeLog(theKext, kOSRuntimeLogSpec,
249*e3723e1fSApple OSS Distributions "Null structor in kext %s segment %s!",
250*e3723e1fSApple OSS Distributions kmodInfo->name, section->segname);
251*e3723e1fSApple OSS Distributions }
252*e3723e1fSApple OSS Distributions }
253*e3723e1fSApple OSS Distributions if (metaHandle) {
254*e3723e1fSApple OSS Distributions result = OSMetaClass::checkModLoad(metaHandle);
255*e3723e1fSApple OSS Distributions }
256*e3723e1fSApple OSS Distributions break;
257*e3723e1fSApple OSS Distributions } /* for (section...) */
258*e3723e1fSApple OSS Distributions return result;
259*e3723e1fSApple OSS Distributions }
260*e3723e1fSApple OSS Distributions
261*e3723e1fSApple OSS Distributions /*********************************************************************
262*e3723e1fSApple OSS Distributions *********************************************************************/
263*e3723e1fSApple OSS Distributions kern_return_t
OSRuntimeFinalizeCPP(OSKext * theKext)264*e3723e1fSApple OSS Distributions OSRuntimeFinalizeCPP(
265*e3723e1fSApple OSS Distributions OSKext * theKext)
266*e3723e1fSApple OSS Distributions {
267*e3723e1fSApple OSS Distributions kern_return_t result = KMOD_RETURN_FAILURE;
268*e3723e1fSApple OSS Distributions void * metaHandle = NULL;// do not free
269*e3723e1fSApple OSS Distributions kernel_mach_header_t * header;
270*e3723e1fSApple OSS Distributions kernel_segment_command_t * segment;
271*e3723e1fSApple OSS Distributions kmod_info_t * kmodInfo;
272*e3723e1fSApple OSS Distributions const char ** sectionNames;
273*e3723e1fSApple OSS Distributions uintptr_t textStart;
274*e3723e1fSApple OSS Distributions uintptr_t textEnd;
275*e3723e1fSApple OSS Distributions
276*e3723e1fSApple OSS Distributions textStart = 0;
277*e3723e1fSApple OSS Distributions textEnd = 0;
278*e3723e1fSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
279*e3723e1fSApple OSS Distributions if (theKext) {
280*e3723e1fSApple OSS Distributions if (!theKext->isCPPInitialized()) {
281*e3723e1fSApple OSS Distributions result = KMOD_RETURN_SUCCESS;
282*e3723e1fSApple OSS Distributions goto finish;
283*e3723e1fSApple OSS Distributions }
284*e3723e1fSApple OSS Distributions kmodInfo = theKext->kmod_info;
285*e3723e1fSApple OSS Distributions if (!kmodInfo || !kmodInfo->address) {
286*e3723e1fSApple OSS Distributions result = kOSKextReturnInvalidArgument;
287*e3723e1fSApple OSS Distributions goto finish;
288*e3723e1fSApple OSS Distributions }
289*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
290*e3723e1fSApple OSS Distributions if (theKext->flags.builtin) {
291*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)g_kernel_kmod_info.address;
292*e3723e1fSApple OSS Distributions textStart = kmodInfo->address;
293*e3723e1fSApple OSS Distributions textEnd = textStart + kmodInfo->size;
294*e3723e1fSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
295*e3723e1fSApple OSS Distributions }
296*e3723e1fSApple OSS Distributions } else {
297*e3723e1fSApple OSS Distributions kmodInfo = &g_kernel_kmod_info;
298*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
299*e3723e1fSApple OSS Distributions }
300*e3723e1fSApple OSS Distributions
301*e3723e1fSApple OSS Distributions /* OSKext checks for this condition now, but somebody might call
302*e3723e1fSApple OSS Distributions * this function directly (the symbol is exported....).
303*e3723e1fSApple OSS Distributions */
304*e3723e1fSApple OSS Distributions if (OSMetaClass::modHasInstance(kmodInfo->name)) {
305*e3723e1fSApple OSS Distributions // xxx - Don't log under errors? this is more of an info thing
306*e3723e1fSApple OSS Distributions OSRuntimeLog(theKext, kOSRuntimeLogSpec,
307*e3723e1fSApple OSS Distributions "Can't tear down kext %s C++; classes have instances:",
308*e3723e1fSApple OSS Distributions kmodInfo->name);
309*e3723e1fSApple OSS Distributions OSKext::reportOSMetaClassInstances(kmodInfo->name, kOSRuntimeLogSpec);
310*e3723e1fSApple OSS Distributions result = kOSMetaClassHasInstances;
311*e3723e1fSApple OSS Distributions goto finish;
312*e3723e1fSApple OSS Distributions }
313*e3723e1fSApple OSS Distributions
314*e3723e1fSApple OSS Distributions /* Tell the meta class system that we are starting to unload.
315*e3723e1fSApple OSS Distributions * metaHandle isn't actually needed on the finalize path,
316*e3723e1fSApple OSS Distributions * so we don't check it here, even though OSMetaClass::postModLoad() will
317*e3723e1fSApple OSS Distributions * return a failure (it only does actual work on the init path anyhow).
318*e3723e1fSApple OSS Distributions */
319*e3723e1fSApple OSS Distributions metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
320*e3723e1fSApple OSS Distributions
321*e3723e1fSApple OSS Distributions OSSymbol::checkForPageUnload((void *)kmodInfo->address,
322*e3723e1fSApple OSS Distributions (void *)(kmodInfo->address + kmodInfo->size));
323*e3723e1fSApple OSS Distributions
324*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
325*e3723e1fSApple OSS Distributions segment = firstsegfromheader(header);
326*e3723e1fSApple OSS Distributions
327*e3723e1fSApple OSS Distributions for (segment = firstsegfromheader(header);
328*e3723e1fSApple OSS Distributions segment != NULL;
329*e3723e1fSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
330*e3723e1fSApple OSS Distributions OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
331*e3723e1fSApple OSS Distributions sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
332*e3723e1fSApple OSS Distributions }
333*e3723e1fSApple OSS Distributions
334*e3723e1fSApple OSS Distributions (void)OSMetaClass::postModLoad(metaHandle);
335*e3723e1fSApple OSS Distributions
336*e3723e1fSApple OSS Distributions if (theKext) {
337*e3723e1fSApple OSS Distributions theKext->setCPPInitialized(false);
338*e3723e1fSApple OSS Distributions }
339*e3723e1fSApple OSS Distributions result = KMOD_RETURN_SUCCESS;
340*e3723e1fSApple OSS Distributions finish:
341*e3723e1fSApple OSS Distributions return result;
342*e3723e1fSApple OSS Distributions }
343*e3723e1fSApple OSS Distributions
344*e3723e1fSApple OSS Distributions #if defined(HAS_APPLE_PAC)
345*e3723e1fSApple OSS Distributions #if !KASAN
346*e3723e1fSApple OSS Distributions /*
347*e3723e1fSApple OSS Distributions * Place this function in __KLD,__text on non-kasan builds so it gets unmapped
348*e3723e1fSApple OSS Distributions * after CTRR lockdown.
349*e3723e1fSApple OSS Distributions */
350*e3723e1fSApple OSS Distributions __attribute__((noinline, section("__KLD,__text")))
351*e3723e1fSApple OSS Distributions #endif
352*e3723e1fSApple OSS Distributions static void
OSRuntimeSignStructorsInSegment(kernel_segment_command_t * segment)353*e3723e1fSApple OSS Distributions OSRuntimeSignStructorsInSegment(kernel_segment_command_t *segment)
354*e3723e1fSApple OSS Distributions {
355*e3723e1fSApple OSS Distributions kernel_section_t * section;
356*e3723e1fSApple OSS Distributions structor_t * structors;
357*e3723e1fSApple OSS Distributions volatile structor_t structor;
358*e3723e1fSApple OSS Distributions size_t idx, num_structors;
359*e3723e1fSApple OSS Distributions
360*e3723e1fSApple OSS Distributions for (section = firstsect(segment);
361*e3723e1fSApple OSS Distributions section != NULL;
362*e3723e1fSApple OSS Distributions section = nextsect(segment, section)) {
363*e3723e1fSApple OSS Distributions if ((S_MOD_INIT_FUNC_POINTERS != (SECTION_TYPE & section->flags))
364*e3723e1fSApple OSS Distributions && (S_MOD_TERM_FUNC_POINTERS != (SECTION_TYPE & section->flags))) {
365*e3723e1fSApple OSS Distributions continue;
366*e3723e1fSApple OSS Distributions }
367*e3723e1fSApple OSS Distributions structors = (structor_t *)section->addr;
368*e3723e1fSApple OSS Distributions if (!structors) {
369*e3723e1fSApple OSS Distributions continue;
370*e3723e1fSApple OSS Distributions }
371*e3723e1fSApple OSS Distributions num_structors = section->size / sizeof(structor_t);
372*e3723e1fSApple OSS Distributions for (idx = 0; idx < num_structors; idx++) {
373*e3723e1fSApple OSS Distributions structor = structors[idx];
374*e3723e1fSApple OSS Distributions if (NULL == structor) {
375*e3723e1fSApple OSS Distributions continue;
376*e3723e1fSApple OSS Distributions }
377*e3723e1fSApple OSS Distributions structor = ptrauth_strip(structor, ptrauth_key_function_pointer);
378*e3723e1fSApple OSS Distributions structor = ptrauth_sign_unauthenticated(structor, ptrauth_key_function_pointer, ptrauth_function_pointer_type_discriminator(void (*)(void)));
379*e3723e1fSApple OSS Distributions structors[idx] = structor;
380*e3723e1fSApple OSS Distributions }
381*e3723e1fSApple OSS Distributions } /* for (section...) */
382*e3723e1fSApple OSS Distributions }
383*e3723e1fSApple OSS Distributions #endif
384*e3723e1fSApple OSS Distributions
385*e3723e1fSApple OSS Distributions /*********************************************************************
386*e3723e1fSApple OSS Distributions *********************************************************************/
387*e3723e1fSApple OSS Distributions void
OSRuntimeSignStructors(kernel_mach_header_t * header __unused)388*e3723e1fSApple OSS Distributions OSRuntimeSignStructors(
389*e3723e1fSApple OSS Distributions kernel_mach_header_t * header __unused)
390*e3723e1fSApple OSS Distributions {
391*e3723e1fSApple OSS Distributions #if defined(HAS_APPLE_PAC)
392*e3723e1fSApple OSS Distributions
393*e3723e1fSApple OSS Distributions kernel_segment_command_t * segment;
394*e3723e1fSApple OSS Distributions
395*e3723e1fSApple OSS Distributions for (segment = firstsegfromheader(header);
396*e3723e1fSApple OSS Distributions segment != NULL;
397*e3723e1fSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
398*e3723e1fSApple OSS Distributions OSRuntimeSignStructorsInSegment(segment);
399*e3723e1fSApple OSS Distributions } /* for (segment...) */
400*e3723e1fSApple OSS Distributions #endif /* !defined(XXX) && defined(HAS_APPLE_PAC) */
401*e3723e1fSApple OSS Distributions }
402*e3723e1fSApple OSS Distributions
403*e3723e1fSApple OSS Distributions /*********************************************************************
404*e3723e1fSApple OSS Distributions *********************************************************************/
405*e3723e1fSApple OSS Distributions void
OSRuntimeSignStructorsInFileset(kernel_mach_header_t * fileset_header __unused)406*e3723e1fSApple OSS Distributions OSRuntimeSignStructorsInFileset(
407*e3723e1fSApple OSS Distributions kernel_mach_header_t * fileset_header __unused)
408*e3723e1fSApple OSS Distributions {
409*e3723e1fSApple OSS Distributions #if defined(HAS_APPLE_PAC)
410*e3723e1fSApple OSS Distributions struct load_command *lc;
411*e3723e1fSApple OSS Distributions
412*e3723e1fSApple OSS Distributions lc = (struct load_command *)((uintptr_t)fileset_header + sizeof(*fileset_header));
413*e3723e1fSApple OSS Distributions for (uint32_t i = 0; i < fileset_header->ncmds; i++,
414*e3723e1fSApple OSS Distributions lc = (struct load_command *)((uintptr_t)lc + lc->cmdsize)) {
415*e3723e1fSApple OSS Distributions if (lc->cmd == LC_FILESET_ENTRY) {
416*e3723e1fSApple OSS Distributions struct fileset_entry_command *fse;
417*e3723e1fSApple OSS Distributions kernel_mach_header_t *mh;
418*e3723e1fSApple OSS Distributions
419*e3723e1fSApple OSS Distributions fse = (struct fileset_entry_command *)(uintptr_t)lc;
420*e3723e1fSApple OSS Distributions mh = (kernel_mach_header_t *)((uintptr_t)fse->vmaddr);
421*e3723e1fSApple OSS Distributions OSRuntimeSignStructors(mh);
422*e3723e1fSApple OSS Distributions } else if (lc->cmd == LC_SEGMENT_64) {
423*e3723e1fSApple OSS Distributions /*
424*e3723e1fSApple OSS Distributions * Slide/adjust all LC_SEGMENT_64 commands in the fileset
425*e3723e1fSApple OSS Distributions * (and any sections in those segments)
426*e3723e1fSApple OSS Distributions */
427*e3723e1fSApple OSS Distributions kernel_segment_command_t *seg;
428*e3723e1fSApple OSS Distributions seg = (kernel_segment_command_t *)(uintptr_t)lc;
429*e3723e1fSApple OSS Distributions OSRuntimeSignStructorsInSegment(seg);
430*e3723e1fSApple OSS Distributions }
431*e3723e1fSApple OSS Distributions }
432*e3723e1fSApple OSS Distributions
433*e3723e1fSApple OSS Distributions #endif /* defined(HAS_APPLE_PAC) */
434*e3723e1fSApple OSS Distributions }
435*e3723e1fSApple OSS Distributions
436*e3723e1fSApple OSS Distributions /*********************************************************************
437*e3723e1fSApple OSS Distributions *********************************************************************/
438*e3723e1fSApple OSS Distributions kern_return_t
OSRuntimeInitializeCPP(OSKext * theKext)439*e3723e1fSApple OSS Distributions OSRuntimeInitializeCPP(
440*e3723e1fSApple OSS Distributions OSKext * theKext)
441*e3723e1fSApple OSS Distributions {
442*e3723e1fSApple OSS Distributions kern_return_t result = KMOD_RETURN_FAILURE;
443*e3723e1fSApple OSS Distributions kernel_mach_header_t * header = NULL;
444*e3723e1fSApple OSS Distributions void * metaHandle = NULL;// do not free
445*e3723e1fSApple OSS Distributions bool load_success = true;
446*e3723e1fSApple OSS Distributions kernel_segment_command_t * segment = NULL;// do not free
447*e3723e1fSApple OSS Distributions kernel_segment_command_t * failure_segment = NULL; // do not free
448*e3723e1fSApple OSS Distributions kmod_info_t * kmodInfo;
449*e3723e1fSApple OSS Distributions const char ** sectionNames;
450*e3723e1fSApple OSS Distributions uintptr_t textStart;
451*e3723e1fSApple OSS Distributions uintptr_t textEnd;
452*e3723e1fSApple OSS Distributions
453*e3723e1fSApple OSS Distributions textStart = 0;
454*e3723e1fSApple OSS Distributions textEnd = 0;
455*e3723e1fSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
456*e3723e1fSApple OSS Distributions if (theKext) {
457*e3723e1fSApple OSS Distributions if (theKext->isCPPInitialized()) {
458*e3723e1fSApple OSS Distributions result = KMOD_RETURN_SUCCESS;
459*e3723e1fSApple OSS Distributions goto finish;
460*e3723e1fSApple OSS Distributions }
461*e3723e1fSApple OSS Distributions
462*e3723e1fSApple OSS Distributions kmodInfo = theKext->kmod_info;
463*e3723e1fSApple OSS Distributions if (!kmodInfo || !kmodInfo->address) {
464*e3723e1fSApple OSS Distributions result = kOSKextReturnInvalidArgument;
465*e3723e1fSApple OSS Distributions goto finish;
466*e3723e1fSApple OSS Distributions }
467*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
468*e3723e1fSApple OSS Distributions
469*e3723e1fSApple OSS Distributions if (theKext->flags.builtin) {
470*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)g_kernel_kmod_info.address;
471*e3723e1fSApple OSS Distributions textStart = kmodInfo->address;
472*e3723e1fSApple OSS Distributions textEnd = textStart + kmodInfo->size;
473*e3723e1fSApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
474*e3723e1fSApple OSS Distributions }
475*e3723e1fSApple OSS Distributions } else {
476*e3723e1fSApple OSS Distributions kmodInfo = &g_kernel_kmod_info;
477*e3723e1fSApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
478*e3723e1fSApple OSS Distributions }
479*e3723e1fSApple OSS Distributions
480*e3723e1fSApple OSS Distributions /* Tell the meta class system that we are starting the load
481*e3723e1fSApple OSS Distributions */
482*e3723e1fSApple OSS Distributions metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
483*e3723e1fSApple OSS Distributions assert(metaHandle);
484*e3723e1fSApple OSS Distributions if (!metaHandle) {
485*e3723e1fSApple OSS Distributions goto finish;
486*e3723e1fSApple OSS Distributions }
487*e3723e1fSApple OSS Distributions
488*e3723e1fSApple OSS Distributions /* NO GOTO PAST HERE. */
489*e3723e1fSApple OSS Distributions
490*e3723e1fSApple OSS Distributions /* Scan the header for all constructor sections, in any
491*e3723e1fSApple OSS Distributions * segment, and invoke the constructors within those sections.
492*e3723e1fSApple OSS Distributions */
493*e3723e1fSApple OSS Distributions for (segment = firstsegfromheader(header);
494*e3723e1fSApple OSS Distributions segment != NULL && load_success;
495*e3723e1fSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
496*e3723e1fSApple OSS Distributions /* Record the current segment in the event of a failure.
497*e3723e1fSApple OSS Distributions */
498*e3723e1fSApple OSS Distributions failure_segment = segment;
499*e3723e1fSApple OSS Distributions load_success = OSRuntimeCallStructorsInSection(
500*e3723e1fSApple OSS Distributions theKext, kmodInfo, metaHandle, segment,
501*e3723e1fSApple OSS Distributions sectionNames[kOSSectionNameInitializer],
502*e3723e1fSApple OSS Distributions textStart, textEnd);
503*e3723e1fSApple OSS Distributions } /* for (segment...) */
504*e3723e1fSApple OSS Distributions
505*e3723e1fSApple OSS Distributions /* We failed so call all of the destructors. We must do this before
506*e3723e1fSApple OSS Distributions * calling OSMetaClass::postModLoad() as the OSMetaClass destructors
507*e3723e1fSApple OSS Distributions * will alter state (in the metaHandle) used by that function.
508*e3723e1fSApple OSS Distributions */
509*e3723e1fSApple OSS Distributions if (!load_success) {
510*e3723e1fSApple OSS Distributions /* Scan the header for all destructor sections, in any
511*e3723e1fSApple OSS Distributions * segment, and invoke the constructors within those sections.
512*e3723e1fSApple OSS Distributions */
513*e3723e1fSApple OSS Distributions for (segment = firstsegfromheader(header);
514*e3723e1fSApple OSS Distributions segment != failure_segment && segment != NULL;
515*e3723e1fSApple OSS Distributions segment = nextsegfromheader(header, segment)) {
516*e3723e1fSApple OSS Distributions OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
517*e3723e1fSApple OSS Distributions sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
518*e3723e1fSApple OSS Distributions } /* for (segment...) */
519*e3723e1fSApple OSS Distributions }
520*e3723e1fSApple OSS Distributions
521*e3723e1fSApple OSS Distributions /* Now, regardless of success so far, do the post-init registration
522*e3723e1fSApple OSS Distributions * and cleanup. If we had to call the unloadCPP function, static
523*e3723e1fSApple OSS Distributions * destructors have removed classes from the stalled list so no
524*e3723e1fSApple OSS Distributions * metaclasses will actually be registered.
525*e3723e1fSApple OSS Distributions */
526*e3723e1fSApple OSS Distributions result = OSMetaClass::postModLoad(metaHandle);
527*e3723e1fSApple OSS Distributions
528*e3723e1fSApple OSS Distributions /* If we've otherwise been fine up to now, but OSMetaClass::postModLoad()
529*e3723e1fSApple OSS Distributions * fails (typically due to a duplicate class), tear down all the C++
530*e3723e1fSApple OSS Distributions * stuff from the kext. This isn't necessary for libkern/OSMetaClass stuff,
531*e3723e1fSApple OSS Distributions * but may be necessary for other C++ code. We ignore the return value
532*e3723e1fSApple OSS Distributions * because it's only a fail when there are existing instances of libkern
533*e3723e1fSApple OSS Distributions * classes, and there had better not be any created on the C++ init path.
534*e3723e1fSApple OSS Distributions */
535*e3723e1fSApple OSS Distributions if (load_success && result != KMOD_RETURN_SUCCESS) {
536*e3723e1fSApple OSS Distributions (void)OSRuntimeFinalizeCPP(theKext); //kmodInfo, sectionNames, textStart, textEnd);
537*e3723e1fSApple OSS Distributions }
538*e3723e1fSApple OSS Distributions
539*e3723e1fSApple OSS Distributions if (theKext && load_success && result == KMOD_RETURN_SUCCESS) {
540*e3723e1fSApple OSS Distributions theKext->setCPPInitialized(true);
541*e3723e1fSApple OSS Distributions }
542*e3723e1fSApple OSS Distributions finish:
543*e3723e1fSApple OSS Distributions return result;
544*e3723e1fSApple OSS Distributions }
545*e3723e1fSApple OSS Distributions
546*e3723e1fSApple OSS Distributions /*********************************************************************
547*e3723e1fSApple OSS Distributions * Unload a kernel segment.
548*e3723e1fSApple OSS Distributions *********************************************************************/
549*e3723e1fSApple OSS Distributions
550*e3723e1fSApple OSS Distributions void
OSRuntimeUnloadCPPForSegment(kernel_segment_command_t * segment)551*e3723e1fSApple OSS Distributions OSRuntimeUnloadCPPForSegment(
552*e3723e1fSApple OSS Distributions kernel_segment_command_t * segment)
553*e3723e1fSApple OSS Distributions {
554*e3723e1fSApple OSS Distributions OSRuntimeCallStructorsInSection(NULL, &g_kernel_kmod_info, NULL, segment,
555*e3723e1fSApple OSS Distributions gOSStructorSectionNames[kOSSectionNamesDefault][kOSSectionNameFinalizer], 0, 0);
556*e3723e1fSApple OSS Distributions }
557*e3723e1fSApple OSS Distributions
558*e3723e1fSApple OSS Distributions #if PRAGMA_MARK
559*e3723e1fSApple OSS Distributions #pragma mark C++ Allocators & Deallocators
560*e3723e1fSApple OSS Distributions #endif /* PRAGMA_MARK */
561*e3723e1fSApple OSS Distributions /*********************************************************************
562*e3723e1fSApple OSS Distributions * C++ Allocators & Deallocators
563*e3723e1fSApple OSS Distributions *********************************************************************/
564*e3723e1fSApple OSS Distributions __typed_allocators_ignore_push
565*e3723e1fSApple OSS Distributions
566*e3723e1fSApple OSS Distributions void *
operator new(size_t size)567*e3723e1fSApple OSS Distributions operator new(size_t size)
568*e3723e1fSApple OSS Distributions {
569*e3723e1fSApple OSS Distributions assert(size);
570*e3723e1fSApple OSS Distributions return kheap_alloc(KERN_OS_MALLOC, size,
571*e3723e1fSApple OSS Distributions Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
572*e3723e1fSApple OSS Distributions }
573*e3723e1fSApple OSS Distributions
574*e3723e1fSApple OSS Distributions void
operator delete(void * addr)575*e3723e1fSApple OSS Distributions operator delete(void * addr)
576*e3723e1fSApple OSS Distributions #if __cplusplus >= 201103L
577*e3723e1fSApple OSS Distributions noexcept
578*e3723e1fSApple OSS Distributions #endif
579*e3723e1fSApple OSS Distributions {
580*e3723e1fSApple OSS Distributions kheap_free_addr(KERN_OS_MALLOC, addr);
581*e3723e1fSApple OSS Distributions return;
582*e3723e1fSApple OSS Distributions }
583*e3723e1fSApple OSS Distributions
584*e3723e1fSApple OSS Distributions void *
operator new[](unsigned long size)585*e3723e1fSApple OSS Distributions operator new[](unsigned long size)
586*e3723e1fSApple OSS Distributions {
587*e3723e1fSApple OSS Distributions return kheap_alloc(KERN_OS_MALLOC, size,
588*e3723e1fSApple OSS Distributions Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
589*e3723e1fSApple OSS Distributions }
590*e3723e1fSApple OSS Distributions
591*e3723e1fSApple OSS Distributions void
operator delete[](void * ptr)592*e3723e1fSApple OSS Distributions operator delete[](void * ptr)
593*e3723e1fSApple OSS Distributions #if __cplusplus >= 201103L
594*e3723e1fSApple OSS Distributions noexcept
595*e3723e1fSApple OSS Distributions #endif
596*e3723e1fSApple OSS Distributions {
597*e3723e1fSApple OSS Distributions if (ptr) {
598*e3723e1fSApple OSS Distributions #if KASAN
599*e3723e1fSApple OSS Distributions /*
600*e3723e1fSApple OSS Distributions * Unpoison the C++ array cookie inserted (but not removed) by the
601*e3723e1fSApple OSS Distributions * compiler on new[].
602*e3723e1fSApple OSS Distributions */
603*e3723e1fSApple OSS Distributions kasan_unpoison_cxx_array_cookie(ptr);
604*e3723e1fSApple OSS Distributions #endif
605*e3723e1fSApple OSS Distributions kheap_free_addr(KERN_OS_MALLOC, ptr);
606*e3723e1fSApple OSS Distributions }
607*e3723e1fSApple OSS Distributions return;
608*e3723e1fSApple OSS Distributions }
609*e3723e1fSApple OSS Distributions
610*e3723e1fSApple OSS Distributions #if __cplusplus >= 201103L
611*e3723e1fSApple OSS Distributions
612*e3723e1fSApple OSS Distributions void
operator delete(void * addr,size_t sz)613*e3723e1fSApple OSS Distributions operator delete(void * addr, size_t sz) noexcept
614*e3723e1fSApple OSS Distributions {
615*e3723e1fSApple OSS Distributions kheap_free(KERN_OS_MALLOC, addr, sz);
616*e3723e1fSApple OSS Distributions }
617*e3723e1fSApple OSS Distributions
618*e3723e1fSApple OSS Distributions void
operator delete[](void * addr,size_t sz)619*e3723e1fSApple OSS Distributions operator delete[](void * addr, size_t sz) noexcept
620*e3723e1fSApple OSS Distributions {
621*e3723e1fSApple OSS Distributions if (addr) {
622*e3723e1fSApple OSS Distributions kheap_free(KERN_OS_MALLOC, addr, sz);
623*e3723e1fSApple OSS Distributions }
624*e3723e1fSApple OSS Distributions }
625*e3723e1fSApple OSS Distributions
626*e3723e1fSApple OSS Distributions __typed_allocators_ignore_pop
627*e3723e1fSApple OSS Distributions
628*e3723e1fSApple OSS Distributions #endif /* __cplusplus >= 201103L */
629*e3723e1fSApple OSS Distributions
630*e3723e1fSApple OSS Distributions /* PR-6481964 - The compiler is going to check for size overflows in calls to
631*e3723e1fSApple OSS Distributions * new[], and if there is an overflow, it will call __throw_length_error.
632*e3723e1fSApple OSS Distributions * This is an unrecoverable error by the C++ standard, so we must panic here.
633*e3723e1fSApple OSS Distributions *
634*e3723e1fSApple OSS Distributions * We have to put the function inside the std namespace because of how the
635*e3723e1fSApple OSS Distributions * compiler expects the name to be mangled.
636*e3723e1fSApple OSS Distributions */
637*e3723e1fSApple OSS Distributions namespace std {
638*e3723e1fSApple OSS Distributions void __dead2
__throw_length_error(const char * msg __unused)639*e3723e1fSApple OSS Distributions __throw_length_error(const char *msg __unused)
640*e3723e1fSApple OSS Distributions {
641*e3723e1fSApple OSS Distributions panic("Size of array created by new[] has overflowed");
642*e3723e1fSApple OSS Distributions }
643*e3723e1fSApple OSS Distributions };
644