1*bbb1b6f9SApple OSS Distributions /*
2*bbb1b6f9SApple OSS Distributions * Copyright (c) 2010 Apple Inc. All rights reserved.
3*bbb1b6f9SApple OSS Distributions *
4*bbb1b6f9SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*bbb1b6f9SApple OSS Distributions *
6*bbb1b6f9SApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*bbb1b6f9SApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*bbb1b6f9SApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*bbb1b6f9SApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*bbb1b6f9SApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*bbb1b6f9SApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*bbb1b6f9SApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*bbb1b6f9SApple OSS Distributions * terms of an Apple operating system software license agreement.
14*bbb1b6f9SApple OSS Distributions *
15*bbb1b6f9SApple OSS Distributions * Please obtain a copy of the License at
16*bbb1b6f9SApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*bbb1b6f9SApple OSS Distributions *
18*bbb1b6f9SApple OSS Distributions * The Original Code and all software distributed under the License are
19*bbb1b6f9SApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*bbb1b6f9SApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*bbb1b6f9SApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*bbb1b6f9SApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*bbb1b6f9SApple OSS Distributions * Please see the License for the specific language governing rights and
24*bbb1b6f9SApple OSS Distributions * limitations under the License.
25*bbb1b6f9SApple OSS Distributions *
26*bbb1b6f9SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*bbb1b6f9SApple OSS Distributions */
28*bbb1b6f9SApple OSS Distributions
29*bbb1b6f9SApple OSS Distributions #include <TargetConditionals.h>
30*bbb1b6f9SApple OSS Distributions #include <stdbool.h>
31*bbb1b6f9SApple OSS Distributions #include <strings.h>
32*bbb1b6f9SApple OSS Distributions #include <unistd.h>
33*bbb1b6f9SApple OSS Distributions #include <mach/vm_page_size.h>
34*bbb1b6f9SApple OSS Distributions #include <spawn_filtering_private.h>
35*bbb1b6f9SApple OSS Distributions #include "_libkernel_init.h"
36*bbb1b6f9SApple OSS Distributions #include "system-version-compat-support.h"
37*bbb1b6f9SApple OSS Distributions
38*bbb1b6f9SApple OSS Distributions extern int mach_init(void);
39*bbb1b6f9SApple OSS Distributions
40*bbb1b6f9SApple OSS Distributions #if SYSTEM_VERSION_COMPAT_ENABLED
41*bbb1b6f9SApple OSS Distributions
42*bbb1b6f9SApple OSS Distributions #include <sys/sysctl.h>
43*bbb1b6f9SApple OSS Distributions
44*bbb1b6f9SApple OSS Distributions extern bool _system_version_compat_check_path_suffix(const char *orig_path);
45*bbb1b6f9SApple OSS Distributions extern int _system_version_compat_open_shim(int opened_fd, int openat_fd, const char *orig_path, int oflag, mode_t mode,
46*bbb1b6f9SApple OSS Distributions int (*close_syscall)(int), int (*open_syscall)(const char *, int, mode_t),
47*bbb1b6f9SApple OSS Distributions int (*openat_syscall)(int, const char *, int, mode_t),
48*bbb1b6f9SApple OSS Distributions int (*fcntl_syscall)(int, int, long));
49*bbb1b6f9SApple OSS Distributions
50*bbb1b6f9SApple OSS Distributions extern bool (*system_version_compat_check_path_suffix)(const char *orig_path);
51*bbb1b6f9SApple OSS Distributions extern int (*system_version_compat_open_shim)(int opened_fd, int openat_fd, const char *orig_path, int oflag, mode_t mode,
52*bbb1b6f9SApple OSS Distributions int (*close_syscall)(int), int (*open_syscall)(const char *, int, mode_t),
53*bbb1b6f9SApple OSS Distributions int (*openat_syscall)(int, const char *, int, mode_t),
54*bbb1b6f9SApple OSS Distributions int (*fcntl_syscall)(int, int, long));
55*bbb1b6f9SApple OSS Distributions
56*bbb1b6f9SApple OSS Distributions extern system_version_compat_mode_t system_version_compat_mode;
57*bbb1b6f9SApple OSS Distributions
58*bbb1b6f9SApple OSS Distributions int __sysctlbyname(const char *name, size_t namelen, void *oldp, size_t *oldlenp, void *newp, size_t newlen);
59*bbb1b6f9SApple OSS Distributions #endif /* SYSTEM_VERSION_COMPAT_ENABLED */
60*bbb1b6f9SApple OSS Distributions
61*bbb1b6f9SApple OSS Distributions #if POSIX_SPAWN_FILTERING_ENABLED
62*bbb1b6f9SApple OSS Distributions struct _posix_spawn_args_desc;
63*bbb1b6f9SApple OSS Distributions extern bool (*posix_spawn_with_filter)(pid_t *pid, const char *fname, char * const *argp,
64*bbb1b6f9SApple OSS Distributions char * const *envp, struct _posix_spawn_args_desc *adp, int *ret);
65*bbb1b6f9SApple OSS Distributions extern bool _posix_spawn_with_filter(pid_t *pid, const char *fname, char * const *argp,
66*bbb1b6f9SApple OSS Distributions char * const *envp, struct _posix_spawn_args_desc *adp, int *ret);
67*bbb1b6f9SApple OSS Distributions extern int (*execve_with_filter)(char *fname, char **argp, char **envp);
68*bbb1b6f9SApple OSS Distributions extern int _execve_with_filter(char *fname, char **argp, char **envp);
69*bbb1b6f9SApple OSS Distributions #endif /* POSIX_SPAWN_FILTERING_ENABLED */
70*bbb1b6f9SApple OSS Distributions
71*bbb1b6f9SApple OSS Distributions #if TARGET_OS_OSX
72*bbb1b6f9SApple OSS Distributions __attribute__((visibility("default")))
73*bbb1b6f9SApple OSS Distributions extern bool _os_xbs_chrooted;
74*bbb1b6f9SApple OSS Distributions bool _os_xbs_chrooted;
75*bbb1b6f9SApple OSS Distributions #endif /* TARGET_OS_OSX */
76*bbb1b6f9SApple OSS Distributions
77*bbb1b6f9SApple OSS Distributions /* dlsym() funcptr is for legacy support in exc_catcher */
78*bbb1b6f9SApple OSS Distributions void* (*LIBKERNEL_FUNCTION_PTRAUTH(_dlsym))(void*, const char*) __attribute__((visibility("hidden")));
79*bbb1b6f9SApple OSS Distributions
80*bbb1b6f9SApple OSS Distributions __attribute__((visibility("hidden")))
81*bbb1b6f9SApple OSS Distributions _libkernel_functions_t _libkernel_functions;
82*bbb1b6f9SApple OSS Distributions
83*bbb1b6f9SApple OSS Distributions
84*bbb1b6f9SApple OSS Distributions void
__libkernel_init(_libkernel_functions_t fns,const char * envp[],const char * apple[],const struct ProgramVars * vars)85*bbb1b6f9SApple OSS Distributions __libkernel_init(_libkernel_functions_t fns,
86*bbb1b6f9SApple OSS Distributions const char *envp[] __attribute__((unused)),
87*bbb1b6f9SApple OSS Distributions const char *apple[] __attribute__((unused)),
88*bbb1b6f9SApple OSS Distributions const struct ProgramVars *vars __attribute__((unused)))
89*bbb1b6f9SApple OSS Distributions {
90*bbb1b6f9SApple OSS Distributions _libkernel_functions = fns;
91*bbb1b6f9SApple OSS Distributions if (fns->dlsym) {
92*bbb1b6f9SApple OSS Distributions _dlsym = fns->dlsym;
93*bbb1b6f9SApple OSS Distributions }
94*bbb1b6f9SApple OSS Distributions mach_init();
95*bbb1b6f9SApple OSS Distributions #if TARGET_OS_OSX
96*bbb1b6f9SApple OSS Distributions for (size_t i = 0; envp[i]; i++) {
97*bbb1b6f9SApple OSS Distributions
98*bbb1b6f9SApple OSS Distributions #if defined(__i386__) || defined(__x86_64__)
99*bbb1b6f9SApple OSS Distributions const char *VM_KERNEL_PAGE_SHIFT_ENV = "VM_KERNEL_PAGE_SIZE_4K=1";
100*bbb1b6f9SApple OSS Distributions if (vm_kernel_page_shift != 12 && strcmp(VM_KERNEL_PAGE_SHIFT_ENV, envp[i]) == 0) {
101*bbb1b6f9SApple OSS Distributions vm_kernel_page_shift = 12;
102*bbb1b6f9SApple OSS Distributions vm_kernel_page_size = 1 << vm_kernel_page_shift;
103*bbb1b6f9SApple OSS Distributions vm_kernel_page_mask = vm_kernel_page_size - 1;
104*bbb1b6f9SApple OSS Distributions }
105*bbb1b6f9SApple OSS Distributions #endif /* defined(__i386__) || defined(__x86_64__) */
106*bbb1b6f9SApple OSS Distributions }
107*bbb1b6f9SApple OSS Distributions #endif /* TARGET_OS_OSX */
108*bbb1b6f9SApple OSS Distributions }
109*bbb1b6f9SApple OSS Distributions
110*bbb1b6f9SApple OSS Distributions void
__libkernel_init_late(_libkernel_late_init_config_t config)111*bbb1b6f9SApple OSS Distributions __libkernel_init_late(_libkernel_late_init_config_t config)
112*bbb1b6f9SApple OSS Distributions {
113*bbb1b6f9SApple OSS Distributions if (config->version >= 1) {
114*bbb1b6f9SApple OSS Distributions #if SYSTEM_VERSION_COMPAT_ENABLED
115*bbb1b6f9SApple OSS Distributions #if SYSTEM_VERSION_COMPAT_HAS_MODE_MACOSX
116*bbb1b6f9SApple OSS Distributions if (config->enable_system_version_compat) {
117*bbb1b6f9SApple OSS Distributions /* enable the version compatibility shim for this process (macOS only) */
118*bbb1b6f9SApple OSS Distributions
119*bbb1b6f9SApple OSS Distributions /* first hook up the shims we reference from open{at}() */
120*bbb1b6f9SApple OSS Distributions system_version_compat_check_path_suffix = _system_version_compat_check_path_suffix;
121*bbb1b6f9SApple OSS Distributions system_version_compat_open_shim = _system_version_compat_open_shim;
122*bbb1b6f9SApple OSS Distributions
123*bbb1b6f9SApple OSS Distributions system_version_compat_mode = SYSTEM_VERSION_COMPAT_MODE_MACOSX;
124*bbb1b6f9SApple OSS Distributions
125*bbb1b6f9SApple OSS Distributions #if SYSTEM_VERSION_COMPAT_NEEDS_SYSCTL
126*bbb1b6f9SApple OSS Distributions /*
127*bbb1b6f9SApple OSS Distributions * tell the kernel the shim is enabled for this process so it can shim any
128*bbb1b6f9SApple OSS Distributions * necessary sysctls
129*bbb1b6f9SApple OSS Distributions */
130*bbb1b6f9SApple OSS Distributions int enable = 1;
131*bbb1b6f9SApple OSS Distributions __sysctlbyname("kern.system_version_compat", strlen("kern.system_version_compat"),
132*bbb1b6f9SApple OSS Distributions NULL, NULL, &enable, sizeof(enable));
133*bbb1b6f9SApple OSS Distributions #endif /* SYSTEM_VERSION_COMPAT_NEEDS_SYSCTL */
134*bbb1b6f9SApple OSS Distributions }
135*bbb1b6f9SApple OSS Distributions #endif /* SYSTEM_VERSION_COMPAT_HAS_MODE_MACOSX */
136*bbb1b6f9SApple OSS Distributions #if SYSTEM_VERSION_COMPAT_HAS_MODE_IOS
137*bbb1b6f9SApple OSS Distributions if (!config->enable_system_version_compat &&
138*bbb1b6f9SApple OSS Distributions (config->version >= 2) && config->enable_ios_version_compat) {
139*bbb1b6f9SApple OSS Distributions /* enable the iOS ProductVersion compatibility shim for this process */
140*bbb1b6f9SApple OSS Distributions
141*bbb1b6f9SApple OSS Distributions /* first hook up the shims we reference from open{at}() */
142*bbb1b6f9SApple OSS Distributions system_version_compat_check_path_suffix = _system_version_compat_check_path_suffix;
143*bbb1b6f9SApple OSS Distributions system_version_compat_open_shim = _system_version_compat_open_shim;
144*bbb1b6f9SApple OSS Distributions
145*bbb1b6f9SApple OSS Distributions system_version_compat_mode = SYSTEM_VERSION_COMPAT_MODE_IOS;
146*bbb1b6f9SApple OSS Distributions
147*bbb1b6f9SApple OSS Distributions /*
148*bbb1b6f9SApple OSS Distributions * We don't currently shim any sysctls for iOS apps running on macOS so we
149*bbb1b6f9SApple OSS Distributions * don't need to inform the kernel that this app has the SystemVersion shim enabled.
150*bbb1b6f9SApple OSS Distributions */
151*bbb1b6f9SApple OSS Distributions }
152*bbb1b6f9SApple OSS Distributions #endif /* SYSTEM_VERSION_COMPAT_HAS_MODE_IOS */
153*bbb1b6f9SApple OSS Distributions #endif /* SYSTEM_VERSION_COMPAT_ENABLED */
154*bbb1b6f9SApple OSS Distributions
155*bbb1b6f9SApple OSS Distributions #if POSIX_SPAWN_FILTERING_ENABLED
156*bbb1b6f9SApple OSS Distributions if ((config->version >= 3) && config->enable_posix_spawn_filtering) {
157*bbb1b6f9SApple OSS Distributions posix_spawn_with_filter = _posix_spawn_with_filter;
158*bbb1b6f9SApple OSS Distributions execve_with_filter = _execve_with_filter;
159*bbb1b6f9SApple OSS Distributions }
160*bbb1b6f9SApple OSS Distributions #endif /* POSIX_SPAWN_FILTERING_ENABLED */
161*bbb1b6f9SApple OSS Distributions }
162*bbb1b6f9SApple OSS Distributions }
163*bbb1b6f9SApple OSS Distributions
164*bbb1b6f9SApple OSS Distributions void
__libkernel_init_after_boot_tasks(_libkernel_init_after_boot_tasks_config_t config)165*bbb1b6f9SApple OSS Distributions __libkernel_init_after_boot_tasks(
166*bbb1b6f9SApple OSS Distributions _libkernel_init_after_boot_tasks_config_t config)
167*bbb1b6f9SApple OSS Distributions {
168*bbb1b6f9SApple OSS Distributions if (config->version >= 1) {
169*bbb1b6f9SApple OSS Distributions #if POSIX_SPAWN_FILTERING_ENABLED
170*bbb1b6f9SApple OSS Distributions if (config->enable_posix_spawn_filtering) {
171*bbb1b6f9SApple OSS Distributions posix_spawn_with_filter = _posix_spawn_with_filter;
172*bbb1b6f9SApple OSS Distributions execve_with_filter = _execve_with_filter;
173*bbb1b6f9SApple OSS Distributions }
174*bbb1b6f9SApple OSS Distributions #endif /* POSIX_SPAWN_FILTERING_ENABLED */
175*bbb1b6f9SApple OSS Distributions }
176*bbb1b6f9SApple OSS Distributions }
177