1*043036a2SApple OSS Distributions /* 2*043036a2SApple OSS Distributions * Copyright (c) 2025 Apple Inc. All rights reserved. 3*043036a2SApple OSS Distributions * 4*043036a2SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@ 5*043036a2SApple OSS Distributions * 6*043036a2SApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code 7*043036a2SApple OSS Distributions * as defined in and that are subject to the Apple Public Source License 8*043036a2SApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in 9*043036a2SApple OSS Distributions * compliance with the License. The rights granted to you under the License 10*043036a2SApple OSS Distributions * may not be used to create, or enable the creation or redistribution of, 11*043036a2SApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to 12*043036a2SApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any 13*043036a2SApple OSS Distributions * terms of an Apple operating system software license agreement. 14*043036a2SApple OSS Distributions * 15*043036a2SApple OSS Distributions * Please obtain a copy of the License at 16*043036a2SApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file. 17*043036a2SApple OSS Distributions * 18*043036a2SApple OSS Distributions * The Original Code and all software distributed under the License are 19*043036a2SApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER 20*043036a2SApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, 21*043036a2SApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, 22*043036a2SApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. 23*043036a2SApple OSS Distributions * Please see the License for the specific language governing rights and 24*043036a2SApple OSS Distributions * limitations under the License. 25*043036a2SApple OSS Distributions * 26*043036a2SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@ 27*043036a2SApple OSS Distributions */ 28*043036a2SApple OSS Distributions 29*043036a2SApple OSS Distributions #include "exc_guard_helper.h" 30*043036a2SApple OSS Distributions #include <darwintest.h> 31*043036a2SApple OSS Distributions #include <mach/mach.h> 32*043036a2SApple OSS Distributions #include <mach/mach_vm.h> 33*043036a2SApple OSS Distributions #include <mach/task_info.h> 34*043036a2SApple OSS Distributions #include <kern/exc_guard.h> 35*043036a2SApple OSS Distributions #include <mach/vm_statistics.h> 36*043036a2SApple OSS Distributions #include "test_utils.h" 37*043036a2SApple OSS Distributions 38*043036a2SApple OSS Distributions T_GLOBAL_META( 39*043036a2SApple OSS Distributions T_META_NAMESPACE("xnu.vm.guard_objects_telemetry"), 40*043036a2SApple OSS Distributions T_META_RADAR_COMPONENT_NAME("xnu"), 41*043036a2SApple OSS Distributions T_META_RADAR_COMPONENT_VERSION("VM")); 42*043036a2SApple OSS Distributions 43*043036a2SApple OSS Distributions #ifndef kGUARD_EXC_LARGE_ALLOCATION_TELEMETRY 44*043036a2SApple OSS Distributions #define kGUARD_EXC_LARGE_ALLOCATION_TELEMETRY (13) 45*043036a2SApple OSS Distributions #endif 46*043036a2SApple OSS Distributions 47*043036a2SApple OSS Distributions /* 48*043036a2SApple OSS Distributions * This test is signed with com.apple.security.hardened-process.guard-objects, 49*043036a2SApple OSS Distributions * so it will run with guard objects enabled. 50*043036a2SApple OSS Distributions */ 51*043036a2SApple OSS Distributions T_DECL(test_allocation_denied_under_guard_objects, 52*043036a2SApple OSS Distributions "Ensure simulated crash occurs when violating guard objects allocation limit", 53*043036a2SApple OSS Distributions T_META_ENABLED(!TARGET_OS_OSX)) { 54*043036a2SApple OSS Distributions exc_guard_helper_info_t exc_info; 55*043036a2SApple OSS Distributions 56*043036a2SApple OSS Distributions exc_guard_helper_init(); 57*043036a2SApple OSS Distributions enable_exc_guard_of_type(GUARD_TYPE_VIRT_MEMORY); 58*043036a2SApple OSS Distributions 59*043036a2SApple OSS Distributions bool caught_exception = block_raised_exc_guard_of_type(GUARD_TYPE_VIRT_MEMORY, &exc_info, ^{ 60*043036a2SApple OSS Distributions kern_return_t kr; 61*043036a2SApple OSS Distributions mach_vm_address_t addr; 62*043036a2SApple OSS Distributions mach_vm_size_t limit = (1 << 30); 63*043036a2SApple OSS Distributions mach_vm_size_t size = limit + PAGE_SIZE; 64*043036a2SApple OSS Distributions 65*043036a2SApple OSS Distributions /* 66*043036a2SApple OSS Distributions * Only the first iteration should generate an exception. 67*043036a2SApple OSS Distributions */ 68*043036a2SApple OSS Distributions for (int i = 0; i < 4; i++) { 69*043036a2SApple OSS Distributions addr = 0; 70*043036a2SApple OSS Distributions 71*043036a2SApple OSS Distributions kr = mach_vm_allocate(mach_task_self(), &addr, size, VM_FLAGS_ANYWHERE); 72*043036a2SApple OSS Distributions T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "mach_vm_allocate"); 73*043036a2SApple OSS Distributions 74*043036a2SApple OSS Distributions kr = mach_vm_deallocate(mach_task_self(), addr, size); 75*043036a2SApple OSS Distributions T_QUIET; T_ASSERT_MACH_SUCCESS(kr, "mach_vm_deallocate"); 76*043036a2SApple OSS Distributions } 77*043036a2SApple OSS Distributions }); 78*043036a2SApple OSS Distributions 79*043036a2SApple OSS Distributions T_QUIET; T_ASSERT_TRUE(caught_exception, "guard exception received for large allocation"); 80*043036a2SApple OSS Distributions T_QUIET; T_ASSERT_EQ(exc_info.catch_count, 1, "only a single exception should be received"); 81*043036a2SApple OSS Distributions T_QUIET; T_ASSERT_EQ(exc_info.guard_type, GUARD_TYPE_VIRT_MEMORY, "exception should be type GUARD_TYPE_VIRT_MEMORY"); 82*043036a2SApple OSS Distributions T_QUIET; T_ASSERT_EQ(exc_info.guard_flavor, kGUARD_EXC_LARGE_ALLOCATION_TELEMETRY, "exception should be flavor kGUARD_EXC_LARGE_ALLOCATION_TELEMETRY"); 83*043036a2SApple OSS Distributions 84*043036a2SApple OSS Distributions T_PASS("Successfully raised a single guard exception of the expected type"); 85*043036a2SApple OSS Distributions } 86