1 #include <assert.h>
2 #include <stdio.h>
3 #include <pthread.h>
4 #include <signal.h>
5 #include <unistd.h>
6 #include <errno.h>
7 #include <string.h>
8 #include <sys/wait.h>
9 #include <sys/types.h>
10 #include <sys/time.h>
11 #include <sys/event.h>
12 #include <sys/ptrace.h>
13 #include <sys/proc.h>
14 #include <stdlib.h>
15 #include <System/sys/codesign.h>
16 #include <darwintest.h>
17 #include <sys/reboot.h>
18
19 T_GLOBAL_META(T_META_NAMESPACE("xnu.note_exec"),
20 T_META_RADAR_COMPONENT_NAME("xnu"),
21 T_META_RADAR_COMPONENT_VERSION("spawn"));
22
23
24 #define TIMEOUT 480
25
26 static int kq;
27 static int pid;
28
29 static void
do_exec(void)30 do_exec(void)
31 {
32 char echo_arg[50] = "";
33
34 snprintf(echo_arg, sizeof(echo_arg), "Child[%d] says hello after exec", getpid());
35
36 char * new_argv[] = {
37 "/bin/echo",
38 echo_arg,
39 NULL
40 };
41
42 int ret = execv(new_argv[0], new_argv);
43 T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "execv()");
44 }
45
46 static void *
thread_wait_exec(void * arg __unused)47 thread_wait_exec(void *arg __unused)
48 {
49 int ret;
50 struct kevent64_s kev;
51 int csret;
52 uint32_t status = 0;
53
54 while (1) {
55 ret = kevent64(kq, NULL, 0, &kev, 1, 0, NULL);
56 if (ret == -1) {
57 if (errno == EINTR) {
58 continue;
59 }
60 }
61 T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "kevent64()");
62 break;
63 }
64
65 /* Try to get the csops of child before we print anything */
66 csret = csops(pid, CS_OPS_STATUS, &status, sizeof(status));
67 if (csret != 0) {
68 T_QUIET; T_LOG("Child exited before parent could call csops. The race didn't happen");
69 return NULL;
70 }
71
72 T_QUIET; T_ASSERT_EQ(ret, 1, "kevent64 returned 1 event as expected");
73 T_QUIET; T_ASSERT_EQ((int)kev.filter, EVFILT_PROC, "EVFILT_PROC event received");
74 T_QUIET; T_ASSERT_EQ((int)kev.udata, pid, "EVFILT_PROC event received for child pid");
75 T_QUIET; T_ASSERT_EQ((kev.fflags & NOTE_EXEC), NOTE_EXEC, "NOTE_EXEC event received");
76
77 /* Check that the platform binary bit is set */
78 T_EXPECT_BITS_SET(status, CS_PLATFORM_BINARY, "CS_PLATFORM_BINARY should be set on child");
79
80 return NULL;
81 }
82
83 static void
sigalrm_handler(int sig)84 sigalrm_handler(int sig)
85 {
86 (void)sig;
87 /* Raising additional diagnostic for rdar://146819222 (xnu.note_exec.test_note_exec failed: Test Failed...) */
88 reboot_np(RB_PANIC, "Generating coredump during a fault state");
89 return;
90 }
91
92 static void
run_test(void)93 run_test(void)
94 {
95 struct kevent64_s kev;
96 int ret;
97 int fd[2];
98
99 ret = pipe(fd);
100 T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pipe()");
101 close(fd[0]);
102
103 T_QUIET; T_LOG("Forking child");
104
105 pid = fork();
106
107 if (pid == 0) {
108 char buf[10];
109
110 close(fd[1]);
111 ret = (int)read(fd[0], buf, sizeof(buf));
112 close(fd[0]);
113
114 do_exec();
115 exit(1);
116 }
117
118 T_QUIET; T_LOG("Setting up NOTE_EXEC Handler for child pid %d", pid);
119 kq = kqueue();
120 T_QUIET; T_ASSERT_POSIX_SUCCESS(kq, "kqueue()");
121
122 EV_SET64(&kev, pid, EVFILT_PROC, EV_ADD | EV_ENABLE,
123 NOTE_EXEC, 0, pid, 0, 0);
124 ret = kevent64(kq, &kev, 1, NULL, 0, 0, NULL);
125 T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "kevent64()");
126
127 pthread_t thread;
128 ret = pthread_create(&thread, NULL, thread_wait_exec, NULL);
129 T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_create()");
130
131 T_QUIET; T_LOG("Signalling child to call exec");
132 close(fd[1]);
133
134 T_QUIET; T_LOG("Waiting for child to exit");
135 pid = waitpid(pid, NULL, 0);
136 T_QUIET; T_ASSERT_POSIX_SUCCESS(pid, "waitpid()");
137
138 T_QUIET; T_LOG("Waiting for note exec thread to exit");
139 ret = pthread_join(thread, NULL);
140 T_QUIET; T_ASSERT_POSIX_SUCCESS(ret, "pthread_join()");
141
142 close(kq);
143 }
144
145 T_DECL(test_note_exec, "test NOTE_EXEC race with setting csops") {
146 T_QUIET; T_LOG("Testing race for NOTE_EXEC with csops");
147
148 /* setup SIGALRM handler to panic the kernel in case of a timeout */
149 sig_t sig = signal(SIGALRM, sigalrm_handler);
150
151 alarm(TIMEOUT);
152 for (int i = 0; i < 100; i++) {
153 T_QUIET; T_LOG("Running iteration %d", i);
154 run_test();
155 }
156 alarm(0);
157 T_END;
158 }
159