xref: /xnu-8020.140.41/libkern/c++/OSRuntime.cpp (revision 27b03b360a988dfd3dfdf34262bb0042026747cc)
1*27b03b36SApple OSS Distributions /*
2*27b03b36SApple OSS Distributions  * Copyright (c) 2000,2008-2009 Apple Inc. All rights reserved.
3*27b03b36SApple OSS Distributions  *
4*27b03b36SApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*27b03b36SApple OSS Distributions  *
6*27b03b36SApple OSS Distributions  * This file contains Original Code and/or Modifications of Original Code
7*27b03b36SApple OSS Distributions  * as defined in and that are subject to the Apple Public Source License
8*27b03b36SApple OSS Distributions  * Version 2.0 (the 'License'). You may not use this file except in
9*27b03b36SApple OSS Distributions  * compliance with the License. The rights granted to you under the License
10*27b03b36SApple OSS Distributions  * may not be used to create, or enable the creation or redistribution of,
11*27b03b36SApple OSS Distributions  * unlawful or unlicensed copies of an Apple operating system, or to
12*27b03b36SApple OSS Distributions  * circumvent, violate, or enable the circumvention or violation of, any
13*27b03b36SApple OSS Distributions  * terms of an Apple operating system software license agreement.
14*27b03b36SApple OSS Distributions  *
15*27b03b36SApple OSS Distributions  * Please obtain a copy of the License at
16*27b03b36SApple OSS Distributions  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*27b03b36SApple OSS Distributions  *
18*27b03b36SApple OSS Distributions  * The Original Code and all software distributed under the License are
19*27b03b36SApple OSS Distributions  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*27b03b36SApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*27b03b36SApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*27b03b36SApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*27b03b36SApple OSS Distributions  * Please see the License for the specific language governing rights and
24*27b03b36SApple OSS Distributions  * limitations under the License.
25*27b03b36SApple OSS Distributions  *
26*27b03b36SApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*27b03b36SApple OSS Distributions  */
28*27b03b36SApple OSS Distributions /*
29*27b03b36SApple OSS Distributions  * Copyright (c) 1997 Apple Inc.
30*27b03b36SApple OSS Distributions  *
31*27b03b36SApple OSS Distributions  */
32*27b03b36SApple OSS Distributions #include <libkern/c++/OSMetaClass.h>
33*27b03b36SApple OSS Distributions #include <libkern/c++/OSKext.h>
34*27b03b36SApple OSS Distributions #include <libkern/c++/OSLib.h>
35*27b03b36SApple OSS Distributions #include <libkern/c++/OSSymbol.h>
36*27b03b36SApple OSS Distributions #include <IOKit/IOKitDebug.h>
37*27b03b36SApple OSS Distributions 
38*27b03b36SApple OSS Distributions #include <sys/cdefs.h>
39*27b03b36SApple OSS Distributions #if defined(HAS_APPLE_PAC)
40*27b03b36SApple OSS Distributions #include <ptrauth.h>
41*27b03b36SApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x)       ((uintptr_t) ptrauth_strip(ptrauth_nop_cast(void *, (x)), ptrauth_key_function_pointer))
42*27b03b36SApple OSS Distributions #else  /* defined(HAS_APPLE_PAC) */
43*27b03b36SApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x)       ((uintptr_t) (x))
44*27b03b36SApple OSS Distributions #endif /* !defined(HAS_APPLE_PAC) */
45*27b03b36SApple OSS Distributions 
46*27b03b36SApple OSS Distributions __BEGIN_DECLS
47*27b03b36SApple OSS Distributions 
48*27b03b36SApple OSS Distributions #include <string.h>
49*27b03b36SApple OSS Distributions #include <mach/mach_types.h>
50*27b03b36SApple OSS Distributions #include <libkern/kernel_mach_header.h>
51*27b03b36SApple OSS Distributions #include <libkern/prelink.h>
52*27b03b36SApple OSS Distributions #include <stdarg.h>
53*27b03b36SApple OSS Distributions 
54*27b03b36SApple OSS Distributions #if KASAN
55*27b03b36SApple OSS Distributions #include <san/kasan.h>
56*27b03b36SApple OSS Distributions #endif
57*27b03b36SApple OSS Distributions 
58*27b03b36SApple OSS Distributions #if PRAGMA_MARK
59*27b03b36SApple OSS Distributions #pragma mark Constants &c.
60*27b03b36SApple OSS Distributions #endif /* PRAGMA_MARK */
61*27b03b36SApple OSS Distributions OSKextLogSpec kOSRuntimeLogSpec =
62*27b03b36SApple OSS Distributions     kOSKextLogErrorLevel |
63*27b03b36SApple OSS Distributions     kOSKextLogLoadFlag |
64*27b03b36SApple OSS Distributions     kOSKextLogKextBookkeepingFlag;
65*27b03b36SApple OSS Distributions 
66*27b03b36SApple OSS Distributions #if PRAGMA_MARK
67*27b03b36SApple OSS Distributions #pragma mark Logging Bootstrap
68*27b03b36SApple OSS Distributions #endif /* PRAGMA_MARK */
69*27b03b36SApple OSS Distributions /*********************************************************************
70*27b03b36SApple OSS Distributions * kern_os Logging Bootstrap
71*27b03b36SApple OSS Distributions *
72*27b03b36SApple OSS Distributions * We can't call in to OSKext until the kernel's C++ environment is up
73*27b03b36SApple OSS Distributions * and running, so let's mask those references with a check variable.
74*27b03b36SApple OSS Distributions * We print unconditionally if C++ isn't up, but if that's the case
75*27b03b36SApple OSS Distributions * we've generally hit a serious error in kernel init!
76*27b03b36SApple OSS Distributions *********************************************************************/
77*27b03b36SApple OSS Distributions static bool gKernelCPPInitialized = false;
78*27b03b36SApple OSS Distributions 
79*27b03b36SApple OSS Distributions #define OSRuntimeLog(kext, flags, format, args ...)            \
80*27b03b36SApple OSS Distributions     do {                                                      \
81*27b03b36SApple OSS Distributions 	if (gKernelCPPInitialized) {                          \
82*27b03b36SApple OSS Distributions 	    OSKextLog((kext), (flags), (format), ## args);  \
83*27b03b36SApple OSS Distributions 	} else {                                              \
84*27b03b36SApple OSS Distributions 	    printf((format), ## args);                        \
85*27b03b36SApple OSS Distributions 	}                                                     \
86*27b03b36SApple OSS Distributions     } while (0)
87*27b03b36SApple OSS Distributions 
88*27b03b36SApple OSS Distributions #if PRAGMA_MARK
89*27b03b36SApple OSS Distributions #pragma mark Libkern Init
90*27b03b36SApple OSS Distributions #endif /* PRAGMA_MARK */
91*27b03b36SApple OSS Distributions /*********************************************************************
92*27b03b36SApple OSS Distributions * Libkern Init
93*27b03b36SApple OSS Distributions *********************************************************************/
94*27b03b36SApple OSS Distributions 
95*27b03b36SApple OSS Distributions #if __GNUC__ >= 3
96*27b03b36SApple OSS Distributions void __dead2
__cxa_pure_virtual(void)97*27b03b36SApple OSS Distributions __cxa_pure_virtual( void )
98*27b03b36SApple OSS Distributions {
99*27b03b36SApple OSS Distributions 	panic("%s", __FUNCTION__);
100*27b03b36SApple OSS Distributions }
101*27b03b36SApple OSS Distributions #else
102*27b03b36SApple OSS Distributions void __dead2
__pure_virtual(void)103*27b03b36SApple OSS Distributions __pure_virtual( void )
104*27b03b36SApple OSS Distributions {
105*27b03b36SApple OSS Distributions 	panic("%s", __FUNCTION__);
106*27b03b36SApple OSS Distributions }
107*27b03b36SApple OSS Distributions #endif
108*27b03b36SApple OSS Distributions 
109*27b03b36SApple OSS Distributions extern lck_grp_t * IOLockGroup;
110*27b03b36SApple OSS Distributions extern kmod_info_t g_kernel_kmod_info;
111*27b03b36SApple OSS Distributions 
112*27b03b36SApple OSS Distributions enum {
113*27b03b36SApple OSS Distributions 	kOSSectionNamesDefault     = 0,
114*27b03b36SApple OSS Distributions 	kOSSectionNamesBuiltinKext = 1,
115*27b03b36SApple OSS Distributions 	kOSSectionNamesCount       = 2,
116*27b03b36SApple OSS Distributions };
117*27b03b36SApple OSS Distributions enum {
118*27b03b36SApple OSS Distributions 	kOSSectionNameInitializer = 0,
119*27b03b36SApple OSS Distributions 	kOSSectionNameFinalizer   = 1,
120*27b03b36SApple OSS Distributions 	kOSSectionNameCount       = 2
121*27b03b36SApple OSS Distributions };
122*27b03b36SApple OSS Distributions 
123*27b03b36SApple OSS Distributions static const char *
124*27b03b36SApple OSS Distributions     gOSStructorSectionNames[kOSSectionNamesCount][kOSSectionNameCount] = {
125*27b03b36SApple OSS Distributions 	{ SECT_MODINITFUNC, SECT_MODTERMFUNC },
126*27b03b36SApple OSS Distributions 	{ kBuiltinInitSection, kBuiltinTermSection }
127*27b03b36SApple OSS Distributions };
128*27b03b36SApple OSS Distributions 
129*27b03b36SApple OSS Distributions void
OSlibkernInit(void)130*27b03b36SApple OSS Distributions OSlibkernInit(void)
131*27b03b36SApple OSS Distributions {
132*27b03b36SApple OSS Distributions 	// This must be called before calling OSRuntimeInitializeCPP.
133*27b03b36SApple OSS Distributions 	OSMetaClassBase::initialize();
134*27b03b36SApple OSS Distributions 
135*27b03b36SApple OSS Distributions 	g_kernel_kmod_info.address = (vm_address_t) &_mh_execute_header;
136*27b03b36SApple OSS Distributions 	if (kOSReturnSuccess != OSRuntimeInitializeCPP(NULL)) {
137*27b03b36SApple OSS Distributions 		// &g_kernel_kmod_info, gOSSectionNamesStandard, 0, 0)) {
138*27b03b36SApple OSS Distributions 		panic("OSRuntime: C++ runtime failed to initialize.");
139*27b03b36SApple OSS Distributions 	}
140*27b03b36SApple OSS Distributions 
141*27b03b36SApple OSS Distributions 	gKernelCPPInitialized = true;
142*27b03b36SApple OSS Distributions 
143*27b03b36SApple OSS Distributions 	return;
144*27b03b36SApple OSS Distributions }
145*27b03b36SApple OSS Distributions 
146*27b03b36SApple OSS Distributions __END_DECLS
147*27b03b36SApple OSS Distributions 
148*27b03b36SApple OSS Distributions #if PRAGMA_MARK
149*27b03b36SApple OSS Distributions #pragma mark C++ Runtime Load/Unload
150*27b03b36SApple OSS Distributions #endif /* PRAGMA_MARK */
151*27b03b36SApple OSS Distributions /*********************************************************************
152*27b03b36SApple OSS Distributions * kern_os C++ Runtime Load/Unload
153*27b03b36SApple OSS Distributions *********************************************************************/
154*27b03b36SApple OSS Distributions 
155*27b03b36SApple OSS Distributions typedef void (*structor_t)(void);
156*27b03b36SApple OSS Distributions 
157*27b03b36SApple OSS Distributions static bool
OSRuntimeCallStructorsInSection(OSKext * theKext,kmod_info_t * kmodInfo,void * metaHandle,kernel_segment_command_t * segment,const char * sectionName,uintptr_t textStart,uintptr_t textEnd)158*27b03b36SApple OSS Distributions OSRuntimeCallStructorsInSection(
159*27b03b36SApple OSS Distributions 	OSKext                   * theKext,
160*27b03b36SApple OSS Distributions 	kmod_info_t              * kmodInfo,
161*27b03b36SApple OSS Distributions 	void                     * metaHandle,
162*27b03b36SApple OSS Distributions 	kernel_segment_command_t * segment,
163*27b03b36SApple OSS Distributions 	const char               * sectionName,
164*27b03b36SApple OSS Distributions 	uintptr_t                  textStart,
165*27b03b36SApple OSS Distributions 	uintptr_t                  textEnd)
166*27b03b36SApple OSS Distributions {
167*27b03b36SApple OSS Distributions 	kernel_section_t * section;
168*27b03b36SApple OSS Distributions 	bool result = TRUE;
169*27b03b36SApple OSS Distributions 
170*27b03b36SApple OSS Distributions 	for (section = firstsect(segment);
171*27b03b36SApple OSS Distributions 	    section != NULL;
172*27b03b36SApple OSS Distributions 	    section = nextsect(segment, section)) {
173*27b03b36SApple OSS Distributions 		if (strncmp(section->sectname, sectionName, sizeof(section->sectname) - 1)) {
174*27b03b36SApple OSS Distributions 			continue;
175*27b03b36SApple OSS Distributions 		}
176*27b03b36SApple OSS Distributions 		if (section->size == 0) {
177*27b03b36SApple OSS Distributions 			continue;
178*27b03b36SApple OSS Distributions 		}
179*27b03b36SApple OSS Distributions 
180*27b03b36SApple OSS Distributions 		structor_t * structors = (structor_t *)section->addr;
181*27b03b36SApple OSS Distributions 		if (!structors) {
182*27b03b36SApple OSS Distributions 			continue;
183*27b03b36SApple OSS Distributions 		}
184*27b03b36SApple OSS Distributions 
185*27b03b36SApple OSS Distributions 		structor_t structor;
186*27b03b36SApple OSS Distributions 		uintptr_t value;
187*27b03b36SApple OSS Distributions 		unsigned long num_structors = section->size / sizeof(structor_t);
188*27b03b36SApple OSS Distributions 		unsigned int hit_null_structor = 0;
189*27b03b36SApple OSS Distributions 		unsigned long firstIndex = 0;
190*27b03b36SApple OSS Distributions 
191*27b03b36SApple OSS Distributions 		if (textStart) {
192*27b03b36SApple OSS Distributions 			// bsearch for any in range
193*27b03b36SApple OSS Distributions 			unsigned long baseIdx;
194*27b03b36SApple OSS Distributions 			unsigned long lim;
195*27b03b36SApple OSS Distributions 			firstIndex = num_structors;
196*27b03b36SApple OSS Distributions 			for (lim = num_structors, baseIdx = 0; lim; lim >>= 1) {
197*27b03b36SApple OSS Distributions 				structor = structors[baseIdx + (lim >> 1)];
198*27b03b36SApple OSS Distributions 				if (!structor) {
199*27b03b36SApple OSS Distributions 					panic("%s: null structor", kmodInfo->name);
200*27b03b36SApple OSS Distributions 				}
201*27b03b36SApple OSS Distributions 				value = PTRAUTH_STRIP_STRUCTOR(structor);
202*27b03b36SApple OSS Distributions 				if ((value >= textStart) && (value < textEnd)) {
203*27b03b36SApple OSS Distributions 					firstIndex = (baseIdx + (lim >> 1));
204*27b03b36SApple OSS Distributions 					// scan back for the first in range
205*27b03b36SApple OSS Distributions 					for (; firstIndex; firstIndex--) {
206*27b03b36SApple OSS Distributions 						structor = structors[firstIndex - 1];
207*27b03b36SApple OSS Distributions 						value = PTRAUTH_STRIP_STRUCTOR(structor);
208*27b03b36SApple OSS Distributions 						if ((value < textStart) || (value >= textEnd)) {
209*27b03b36SApple OSS Distributions 							break;
210*27b03b36SApple OSS Distributions 						}
211*27b03b36SApple OSS Distributions 					}
212*27b03b36SApple OSS Distributions 					break;
213*27b03b36SApple OSS Distributions 				}
214*27b03b36SApple OSS Distributions 				if (textStart > value) {
215*27b03b36SApple OSS Distributions 					// move right
216*27b03b36SApple OSS Distributions 					baseIdx += (lim >> 1) + 1;
217*27b03b36SApple OSS Distributions 					lim--;
218*27b03b36SApple OSS Distributions 				}
219*27b03b36SApple OSS Distributions 				// else move left
220*27b03b36SApple OSS Distributions 			}
221*27b03b36SApple OSS Distributions 			baseIdx = (baseIdx + (lim >> 1));
222*27b03b36SApple OSS Distributions 		}
223*27b03b36SApple OSS Distributions 		for (;
224*27b03b36SApple OSS Distributions 		    (firstIndex < num_structors)
225*27b03b36SApple OSS Distributions 		    && (!metaHandle || OSMetaClass::checkModLoad(metaHandle));
226*27b03b36SApple OSS Distributions 		    firstIndex++) {
227*27b03b36SApple OSS Distributions 			if ((structor = structors[firstIndex])) {
228*27b03b36SApple OSS Distributions 				value = PTRAUTH_STRIP_STRUCTOR(structor);
229*27b03b36SApple OSS Distributions 				if ((textStart && (value < textStart))
230*27b03b36SApple OSS Distributions 				    || (textEnd && (value >= textEnd))) {
231*27b03b36SApple OSS Distributions 					break;
232*27b03b36SApple OSS Distributions 				}
233*27b03b36SApple OSS Distributions 				(*structor)();
234*27b03b36SApple OSS Distributions 			} else if (!hit_null_structor) {
235*27b03b36SApple OSS Distributions 				hit_null_structor = 1;
236*27b03b36SApple OSS Distributions 				OSRuntimeLog(theKext, kOSRuntimeLogSpec,
237*27b03b36SApple OSS Distributions 				    "Null structor in kext %s segment %s!",
238*27b03b36SApple OSS Distributions 				    kmodInfo->name, section->segname);
239*27b03b36SApple OSS Distributions 			}
240*27b03b36SApple OSS Distributions 		}
241*27b03b36SApple OSS Distributions 		if (metaHandle) {
242*27b03b36SApple OSS Distributions 			result = OSMetaClass::checkModLoad(metaHandle);
243*27b03b36SApple OSS Distributions 		}
244*27b03b36SApple OSS Distributions 		break;
245*27b03b36SApple OSS Distributions 	} /* for (section...) */
246*27b03b36SApple OSS Distributions 	return result;
247*27b03b36SApple OSS Distributions }
248*27b03b36SApple OSS Distributions 
249*27b03b36SApple OSS Distributions /*********************************************************************
250*27b03b36SApple OSS Distributions *********************************************************************/
251*27b03b36SApple OSS Distributions kern_return_t
OSRuntimeFinalizeCPP(OSKext * theKext)252*27b03b36SApple OSS Distributions OSRuntimeFinalizeCPP(
253*27b03b36SApple OSS Distributions 	OSKext                   * theKext)
254*27b03b36SApple OSS Distributions {
255*27b03b36SApple OSS Distributions 	kern_return_t              result = KMOD_RETURN_FAILURE;
256*27b03b36SApple OSS Distributions 	void                     * metaHandle = NULL;// do not free
257*27b03b36SApple OSS Distributions 	kernel_mach_header_t     * header;
258*27b03b36SApple OSS Distributions 	kernel_segment_command_t * segment;
259*27b03b36SApple OSS Distributions 	kmod_info_t              * kmodInfo;
260*27b03b36SApple OSS Distributions 	const char              ** sectionNames;
261*27b03b36SApple OSS Distributions 	uintptr_t                  textStart;
262*27b03b36SApple OSS Distributions 	uintptr_t                  textEnd;
263*27b03b36SApple OSS Distributions 
264*27b03b36SApple OSS Distributions 	textStart    = 0;
265*27b03b36SApple OSS Distributions 	textEnd      = 0;
266*27b03b36SApple OSS Distributions 	sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
267*27b03b36SApple OSS Distributions 	if (theKext) {
268*27b03b36SApple OSS Distributions 		if (!theKext->isCPPInitialized()) {
269*27b03b36SApple OSS Distributions 			result = KMOD_RETURN_SUCCESS;
270*27b03b36SApple OSS Distributions 			goto finish;
271*27b03b36SApple OSS Distributions 		}
272*27b03b36SApple OSS Distributions 		kmodInfo = theKext->kmod_info;
273*27b03b36SApple OSS Distributions 		if (!kmodInfo || !kmodInfo->address) {
274*27b03b36SApple OSS Distributions 			result = kOSKextReturnInvalidArgument;
275*27b03b36SApple OSS Distributions 			goto finish;
276*27b03b36SApple OSS Distributions 		}
277*27b03b36SApple OSS Distributions 		header = (kernel_mach_header_t *)kmodInfo->address;
278*27b03b36SApple OSS Distributions 		if (theKext->flags.builtin) {
279*27b03b36SApple OSS Distributions 			header       = (kernel_mach_header_t *)g_kernel_kmod_info.address;
280*27b03b36SApple OSS Distributions 			textStart    = kmodInfo->address;
281*27b03b36SApple OSS Distributions 			textEnd      = textStart + kmodInfo->size;
282*27b03b36SApple OSS Distributions 			sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
283*27b03b36SApple OSS Distributions 		}
284*27b03b36SApple OSS Distributions 	} else {
285*27b03b36SApple OSS Distributions 		kmodInfo = &g_kernel_kmod_info;
286*27b03b36SApple OSS Distributions 		header   = (kernel_mach_header_t *)kmodInfo->address;
287*27b03b36SApple OSS Distributions 	}
288*27b03b36SApple OSS Distributions 
289*27b03b36SApple OSS Distributions 	/* OSKext checks for this condition now, but somebody might call
290*27b03b36SApple OSS Distributions 	 * this function directly (the symbol is exported....).
291*27b03b36SApple OSS Distributions 	 */
292*27b03b36SApple OSS Distributions 	if (OSMetaClass::modHasInstance(kmodInfo->name)) {
293*27b03b36SApple OSS Distributions 		// xxx - Don't log under errors? this is more of an info thing
294*27b03b36SApple OSS Distributions 		OSRuntimeLog(theKext, kOSRuntimeLogSpec,
295*27b03b36SApple OSS Distributions 		    "Can't tear down kext %s C++; classes have instances:",
296*27b03b36SApple OSS Distributions 		    kmodInfo->name);
297*27b03b36SApple OSS Distributions 		OSKext::reportOSMetaClassInstances(kmodInfo->name, kOSRuntimeLogSpec);
298*27b03b36SApple OSS Distributions 		result = kOSMetaClassHasInstances;
299*27b03b36SApple OSS Distributions 		goto finish;
300*27b03b36SApple OSS Distributions 	}
301*27b03b36SApple OSS Distributions 
302*27b03b36SApple OSS Distributions 	/* Tell the meta class system that we are starting to unload.
303*27b03b36SApple OSS Distributions 	 * metaHandle isn't actually needed on the finalize path,
304*27b03b36SApple OSS Distributions 	 * so we don't check it here, even though OSMetaClass::postModLoad() will
305*27b03b36SApple OSS Distributions 	 * return a failure (it only does actual work on the init path anyhow).
306*27b03b36SApple OSS Distributions 	 */
307*27b03b36SApple OSS Distributions 	metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
308*27b03b36SApple OSS Distributions 
309*27b03b36SApple OSS Distributions 	OSSymbol::checkForPageUnload((void *)kmodInfo->address,
310*27b03b36SApple OSS Distributions 	    (void *)(kmodInfo->address + kmodInfo->size));
311*27b03b36SApple OSS Distributions 
312*27b03b36SApple OSS Distributions 	header = (kernel_mach_header_t *)kmodInfo->address;
313*27b03b36SApple OSS Distributions 	segment = firstsegfromheader(header);
314*27b03b36SApple OSS Distributions 
315*27b03b36SApple OSS Distributions 	for (segment = firstsegfromheader(header);
316*27b03b36SApple OSS Distributions 	    segment != NULL;
317*27b03b36SApple OSS Distributions 	    segment = nextsegfromheader(header, segment)) {
318*27b03b36SApple OSS Distributions 		OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
319*27b03b36SApple OSS Distributions 		    sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
320*27b03b36SApple OSS Distributions 	}
321*27b03b36SApple OSS Distributions 
322*27b03b36SApple OSS Distributions 	(void)OSMetaClass::postModLoad(metaHandle);
323*27b03b36SApple OSS Distributions 
324*27b03b36SApple OSS Distributions 	if (theKext) {
325*27b03b36SApple OSS Distributions 		theKext->setCPPInitialized(false);
326*27b03b36SApple OSS Distributions 	}
327*27b03b36SApple OSS Distributions 	result = KMOD_RETURN_SUCCESS;
328*27b03b36SApple OSS Distributions finish:
329*27b03b36SApple OSS Distributions 	return result;
330*27b03b36SApple OSS Distributions }
331*27b03b36SApple OSS Distributions 
332*27b03b36SApple OSS Distributions #if defined(HAS_APPLE_PAC)
333*27b03b36SApple OSS Distributions #if !KASAN
334*27b03b36SApple OSS Distributions /*
335*27b03b36SApple OSS Distributions  * Place this function in __KLD,__text on non-kasan builds so it gets unmapped
336*27b03b36SApple OSS Distributions  * after CTRR lockdown.
337*27b03b36SApple OSS Distributions  */
338*27b03b36SApple OSS Distributions __attribute__((noinline, section("__KLD,__text")))
339*27b03b36SApple OSS Distributions #endif
340*27b03b36SApple OSS Distributions static void
OSRuntimeSignStructorsInSegment(kernel_segment_command_t * segment)341*27b03b36SApple OSS Distributions OSRuntimeSignStructorsInSegment(kernel_segment_command_t *segment)
342*27b03b36SApple OSS Distributions {
343*27b03b36SApple OSS Distributions 	kernel_section_t         * section;
344*27b03b36SApple OSS Distributions 	structor_t               * structors;
345*27b03b36SApple OSS Distributions 	volatile structor_t                 structor;
346*27b03b36SApple OSS Distributions 	size_t                     idx, num_structors;
347*27b03b36SApple OSS Distributions 
348*27b03b36SApple OSS Distributions 	for (section = firstsect(segment);
349*27b03b36SApple OSS Distributions 	    section != NULL;
350*27b03b36SApple OSS Distributions 	    section = nextsect(segment, section)) {
351*27b03b36SApple OSS Distributions 		if ((S_MOD_INIT_FUNC_POINTERS != (SECTION_TYPE & section->flags))
352*27b03b36SApple OSS Distributions 		    && (S_MOD_TERM_FUNC_POINTERS != (SECTION_TYPE & section->flags))) {
353*27b03b36SApple OSS Distributions 			continue;
354*27b03b36SApple OSS Distributions 		}
355*27b03b36SApple OSS Distributions 		structors = (structor_t *)section->addr;
356*27b03b36SApple OSS Distributions 		if (!structors) {
357*27b03b36SApple OSS Distributions 			continue;
358*27b03b36SApple OSS Distributions 		}
359*27b03b36SApple OSS Distributions 		num_structors = section->size / sizeof(structor_t);
360*27b03b36SApple OSS Distributions 		for (idx = 0; idx < num_structors; idx++) {
361*27b03b36SApple OSS Distributions 			structor = structors[idx];
362*27b03b36SApple OSS Distributions 			if (NULL == structor) {
363*27b03b36SApple OSS Distributions 				continue;
364*27b03b36SApple OSS Distributions 			}
365*27b03b36SApple OSS Distributions 			structor = ptrauth_strip(structor, ptrauth_key_function_pointer);
366*27b03b36SApple OSS Distributions 			structor = ptrauth_sign_unauthenticated(structor, ptrauth_key_function_pointer, ptrauth_function_pointer_type_discriminator(void (*)(void)));
367*27b03b36SApple OSS Distributions 			structors[idx] = structor;
368*27b03b36SApple OSS Distributions 		}
369*27b03b36SApple OSS Distributions 	} /* for (section...) */
370*27b03b36SApple OSS Distributions }
371*27b03b36SApple OSS Distributions #endif
372*27b03b36SApple OSS Distributions 
373*27b03b36SApple OSS Distributions /*********************************************************************
374*27b03b36SApple OSS Distributions *********************************************************************/
375*27b03b36SApple OSS Distributions void
OSRuntimeSignStructors(kernel_mach_header_t * header __unused)376*27b03b36SApple OSS Distributions OSRuntimeSignStructors(
377*27b03b36SApple OSS Distributions 	kernel_mach_header_t * header __unused)
378*27b03b36SApple OSS Distributions {
379*27b03b36SApple OSS Distributions #if defined(HAS_APPLE_PAC)
380*27b03b36SApple OSS Distributions 
381*27b03b36SApple OSS Distributions 	kernel_segment_command_t * segment;
382*27b03b36SApple OSS Distributions 
383*27b03b36SApple OSS Distributions 	for (segment = firstsegfromheader(header);
384*27b03b36SApple OSS Distributions 	    segment != NULL;
385*27b03b36SApple OSS Distributions 	    segment = nextsegfromheader(header, segment)) {
386*27b03b36SApple OSS Distributions 		OSRuntimeSignStructorsInSegment(segment);
387*27b03b36SApple OSS Distributions 	} /* for (segment...) */
388*27b03b36SApple OSS Distributions #endif /* !defined(XXX) && defined(HAS_APPLE_PAC) */
389*27b03b36SApple OSS Distributions }
390*27b03b36SApple OSS Distributions 
391*27b03b36SApple OSS Distributions /*********************************************************************
392*27b03b36SApple OSS Distributions *********************************************************************/
393*27b03b36SApple OSS Distributions void
OSRuntimeSignStructorsInFileset(kernel_mach_header_t * fileset_header __unused)394*27b03b36SApple OSS Distributions OSRuntimeSignStructorsInFileset(
395*27b03b36SApple OSS Distributions 	kernel_mach_header_t * fileset_header __unused)
396*27b03b36SApple OSS Distributions {
397*27b03b36SApple OSS Distributions #if defined(HAS_APPLE_PAC)
398*27b03b36SApple OSS Distributions 	struct load_command *lc;
399*27b03b36SApple OSS Distributions 
400*27b03b36SApple OSS Distributions 	lc = (struct load_command *)((uintptr_t)fileset_header + sizeof(*fileset_header));
401*27b03b36SApple OSS Distributions 	for (uint32_t i = 0; i < fileset_header->ncmds; i++,
402*27b03b36SApple OSS Distributions 	    lc = (struct load_command *)((uintptr_t)lc + lc->cmdsize)) {
403*27b03b36SApple OSS Distributions 		if (lc->cmd == LC_FILESET_ENTRY) {
404*27b03b36SApple OSS Distributions 			struct fileset_entry_command *fse;
405*27b03b36SApple OSS Distributions 			kernel_mach_header_t *mh;
406*27b03b36SApple OSS Distributions 
407*27b03b36SApple OSS Distributions 			fse = (struct fileset_entry_command *)(uintptr_t)lc;
408*27b03b36SApple OSS Distributions 			mh = (kernel_mach_header_t *)((uintptr_t)fse->vmaddr);
409*27b03b36SApple OSS Distributions 			OSRuntimeSignStructors(mh);
410*27b03b36SApple OSS Distributions 		} else if (lc->cmd == LC_SEGMENT_64) {
411*27b03b36SApple OSS Distributions 			/*
412*27b03b36SApple OSS Distributions 			 * Slide/adjust all LC_SEGMENT_64 commands in the fileset
413*27b03b36SApple OSS Distributions 			 * (and any sections in those segments)
414*27b03b36SApple OSS Distributions 			 */
415*27b03b36SApple OSS Distributions 			kernel_segment_command_t *seg;
416*27b03b36SApple OSS Distributions 			seg = (kernel_segment_command_t *)(uintptr_t)lc;
417*27b03b36SApple OSS Distributions 			OSRuntimeSignStructorsInSegment(seg);
418*27b03b36SApple OSS Distributions 		}
419*27b03b36SApple OSS Distributions 	}
420*27b03b36SApple OSS Distributions 
421*27b03b36SApple OSS Distributions #endif /* defined(HAS_APPLE_PAC) */
422*27b03b36SApple OSS Distributions }
423*27b03b36SApple OSS Distributions 
424*27b03b36SApple OSS Distributions /*********************************************************************
425*27b03b36SApple OSS Distributions *********************************************************************/
426*27b03b36SApple OSS Distributions kern_return_t
OSRuntimeInitializeCPP(OSKext * theKext)427*27b03b36SApple OSS Distributions OSRuntimeInitializeCPP(
428*27b03b36SApple OSS Distributions 	OSKext                   * theKext)
429*27b03b36SApple OSS Distributions {
430*27b03b36SApple OSS Distributions 	kern_return_t              result          = KMOD_RETURN_FAILURE;
431*27b03b36SApple OSS Distributions 	kernel_mach_header_t     * header          = NULL;
432*27b03b36SApple OSS Distributions 	void                     * metaHandle      = NULL;// do not free
433*27b03b36SApple OSS Distributions 	bool                       load_success    = true;
434*27b03b36SApple OSS Distributions 	kernel_segment_command_t * segment         = NULL;// do not free
435*27b03b36SApple OSS Distributions 	kernel_segment_command_t * failure_segment = NULL; // do not free
436*27b03b36SApple OSS Distributions 	kmod_info_t             *  kmodInfo;
437*27b03b36SApple OSS Distributions 	const char              ** sectionNames;
438*27b03b36SApple OSS Distributions 	uintptr_t                  textStart;
439*27b03b36SApple OSS Distributions 	uintptr_t                  textEnd;
440*27b03b36SApple OSS Distributions 
441*27b03b36SApple OSS Distributions 	textStart    = 0;
442*27b03b36SApple OSS Distributions 	textEnd      = 0;
443*27b03b36SApple OSS Distributions 	sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
444*27b03b36SApple OSS Distributions 	if (theKext) {
445*27b03b36SApple OSS Distributions 		if (theKext->isCPPInitialized()) {
446*27b03b36SApple OSS Distributions 			result = KMOD_RETURN_SUCCESS;
447*27b03b36SApple OSS Distributions 			goto finish;
448*27b03b36SApple OSS Distributions 		}
449*27b03b36SApple OSS Distributions 
450*27b03b36SApple OSS Distributions 		kmodInfo = theKext->kmod_info;
451*27b03b36SApple OSS Distributions 		if (!kmodInfo || !kmodInfo->address) {
452*27b03b36SApple OSS Distributions 			result = kOSKextReturnInvalidArgument;
453*27b03b36SApple OSS Distributions 			goto finish;
454*27b03b36SApple OSS Distributions 		}
455*27b03b36SApple OSS Distributions 		header = (kernel_mach_header_t *)kmodInfo->address;
456*27b03b36SApple OSS Distributions 
457*27b03b36SApple OSS Distributions 		if (theKext->flags.builtin) {
458*27b03b36SApple OSS Distributions 			header       = (kernel_mach_header_t *)g_kernel_kmod_info.address;
459*27b03b36SApple OSS Distributions 			textStart    = kmodInfo->address;
460*27b03b36SApple OSS Distributions 			textEnd      = textStart + kmodInfo->size;
461*27b03b36SApple OSS Distributions 			sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
462*27b03b36SApple OSS Distributions 		}
463*27b03b36SApple OSS Distributions 	} else {
464*27b03b36SApple OSS Distributions 		kmodInfo = &g_kernel_kmod_info;
465*27b03b36SApple OSS Distributions 		header   = (kernel_mach_header_t *)kmodInfo->address;
466*27b03b36SApple OSS Distributions 	}
467*27b03b36SApple OSS Distributions 
468*27b03b36SApple OSS Distributions 	/* Tell the meta class system that we are starting the load
469*27b03b36SApple OSS Distributions 	 */
470*27b03b36SApple OSS Distributions 	metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
471*27b03b36SApple OSS Distributions 	assert(metaHandle);
472*27b03b36SApple OSS Distributions 	if (!metaHandle) {
473*27b03b36SApple OSS Distributions 		goto finish;
474*27b03b36SApple OSS Distributions 	}
475*27b03b36SApple OSS Distributions 
476*27b03b36SApple OSS Distributions 	/* NO GOTO PAST HERE. */
477*27b03b36SApple OSS Distributions 
478*27b03b36SApple OSS Distributions 	/* Scan the header for all constructor sections, in any
479*27b03b36SApple OSS Distributions 	 * segment, and invoke the constructors within those sections.
480*27b03b36SApple OSS Distributions 	 */
481*27b03b36SApple OSS Distributions 	for (segment = firstsegfromheader(header);
482*27b03b36SApple OSS Distributions 	    segment != NULL && load_success;
483*27b03b36SApple OSS Distributions 	    segment = nextsegfromheader(header, segment)) {
484*27b03b36SApple OSS Distributions 		/* Record the current segment in the event of a failure.
485*27b03b36SApple OSS Distributions 		 */
486*27b03b36SApple OSS Distributions 		failure_segment = segment;
487*27b03b36SApple OSS Distributions 		load_success = OSRuntimeCallStructorsInSection(
488*27b03b36SApple OSS Distributions 			theKext, kmodInfo, metaHandle, segment,
489*27b03b36SApple OSS Distributions 			sectionNames[kOSSectionNameInitializer],
490*27b03b36SApple OSS Distributions 			textStart, textEnd);
491*27b03b36SApple OSS Distributions 	} /* for (segment...) */
492*27b03b36SApple OSS Distributions 
493*27b03b36SApple OSS Distributions 	/* We failed so call all of the destructors. We must do this before
494*27b03b36SApple OSS Distributions 	 * calling OSMetaClass::postModLoad() as the OSMetaClass destructors
495*27b03b36SApple OSS Distributions 	 * will alter state (in the metaHandle) used by that function.
496*27b03b36SApple OSS Distributions 	 */
497*27b03b36SApple OSS Distributions 	if (!load_success) {
498*27b03b36SApple OSS Distributions 		/* Scan the header for all destructor sections, in any
499*27b03b36SApple OSS Distributions 		 * segment, and invoke the constructors within those sections.
500*27b03b36SApple OSS Distributions 		 */
501*27b03b36SApple OSS Distributions 		for (segment = firstsegfromheader(header);
502*27b03b36SApple OSS Distributions 		    segment != failure_segment && segment != NULL;
503*27b03b36SApple OSS Distributions 		    segment = nextsegfromheader(header, segment)) {
504*27b03b36SApple OSS Distributions 			OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
505*27b03b36SApple OSS Distributions 			    sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
506*27b03b36SApple OSS Distributions 		} /* for (segment...) */
507*27b03b36SApple OSS Distributions 	}
508*27b03b36SApple OSS Distributions 
509*27b03b36SApple OSS Distributions 	/* Now, regardless of success so far, do the post-init registration
510*27b03b36SApple OSS Distributions 	 * and cleanup. If we had to call the unloadCPP function, static
511*27b03b36SApple OSS Distributions 	 * destructors have removed classes from the stalled list so no
512*27b03b36SApple OSS Distributions 	 * metaclasses will actually be registered.
513*27b03b36SApple OSS Distributions 	 */
514*27b03b36SApple OSS Distributions 	result = OSMetaClass::postModLoad(metaHandle);
515*27b03b36SApple OSS Distributions 
516*27b03b36SApple OSS Distributions 	/* If we've otherwise been fine up to now, but OSMetaClass::postModLoad()
517*27b03b36SApple OSS Distributions 	 * fails (typically due to a duplicate class), tear down all the C++
518*27b03b36SApple OSS Distributions 	 * stuff from the kext. This isn't necessary for libkern/OSMetaClass stuff,
519*27b03b36SApple OSS Distributions 	 * but may be necessary for other C++ code. We ignore the return value
520*27b03b36SApple OSS Distributions 	 * because it's only a fail when there are existing instances of libkern
521*27b03b36SApple OSS Distributions 	 * classes, and there had better not be any created on the C++ init path.
522*27b03b36SApple OSS Distributions 	 */
523*27b03b36SApple OSS Distributions 	if (load_success && result != KMOD_RETURN_SUCCESS) {
524*27b03b36SApple OSS Distributions 		(void)OSRuntimeFinalizeCPP(theKext); //kmodInfo, sectionNames, textStart, textEnd);
525*27b03b36SApple OSS Distributions 	}
526*27b03b36SApple OSS Distributions 
527*27b03b36SApple OSS Distributions 	if (theKext && load_success && result == KMOD_RETURN_SUCCESS) {
528*27b03b36SApple OSS Distributions 		theKext->setCPPInitialized(true);
529*27b03b36SApple OSS Distributions 	}
530*27b03b36SApple OSS Distributions finish:
531*27b03b36SApple OSS Distributions 	return result;
532*27b03b36SApple OSS Distributions }
533*27b03b36SApple OSS Distributions 
534*27b03b36SApple OSS Distributions /*********************************************************************
535*27b03b36SApple OSS Distributions *   Unload a kernel segment.
536*27b03b36SApple OSS Distributions *********************************************************************/
537*27b03b36SApple OSS Distributions 
538*27b03b36SApple OSS Distributions void
OSRuntimeUnloadCPPForSegment(kernel_segment_command_t * segment)539*27b03b36SApple OSS Distributions OSRuntimeUnloadCPPForSegment(
540*27b03b36SApple OSS Distributions 	kernel_segment_command_t * segment)
541*27b03b36SApple OSS Distributions {
542*27b03b36SApple OSS Distributions 	OSRuntimeCallStructorsInSection(NULL, &g_kernel_kmod_info, NULL, segment,
543*27b03b36SApple OSS Distributions 	    gOSStructorSectionNames[kOSSectionNamesDefault][kOSSectionNameFinalizer], 0, 0);
544*27b03b36SApple OSS Distributions }
545*27b03b36SApple OSS Distributions 
546*27b03b36SApple OSS Distributions #if PRAGMA_MARK
547*27b03b36SApple OSS Distributions #pragma mark C++ Allocators & Deallocators
548*27b03b36SApple OSS Distributions #endif /* PRAGMA_MARK */
549*27b03b36SApple OSS Distributions /*********************************************************************
550*27b03b36SApple OSS Distributions * C++ Allocators & Deallocators
551*27b03b36SApple OSS Distributions *********************************************************************/
552*27b03b36SApple OSS Distributions void *
operator new(size_t size)553*27b03b36SApple OSS Distributions operator new(size_t size)
554*27b03b36SApple OSS Distributions {
555*27b03b36SApple OSS Distributions 	assert(size);
556*27b03b36SApple OSS Distributions 	return kheap_alloc(KERN_OS_MALLOC, size,
557*27b03b36SApple OSS Distributions 	           Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
558*27b03b36SApple OSS Distributions }
559*27b03b36SApple OSS Distributions 
560*27b03b36SApple OSS Distributions void
operator delete(void * addr)561*27b03b36SApple OSS Distributions operator delete(void * addr)
562*27b03b36SApple OSS Distributions #if __cplusplus >= 201103L
563*27b03b36SApple OSS Distributions noexcept
564*27b03b36SApple OSS Distributions #endif
565*27b03b36SApple OSS Distributions {
566*27b03b36SApple OSS Distributions 	kheap_free_addr(KERN_OS_MALLOC, addr);
567*27b03b36SApple OSS Distributions 	return;
568*27b03b36SApple OSS Distributions }
569*27b03b36SApple OSS Distributions 
570*27b03b36SApple OSS Distributions void *
operator new[](unsigned long size)571*27b03b36SApple OSS Distributions operator new[](unsigned long size)
572*27b03b36SApple OSS Distributions {
573*27b03b36SApple OSS Distributions 	return kheap_alloc(KERN_OS_MALLOC, size,
574*27b03b36SApple OSS Distributions 	           Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
575*27b03b36SApple OSS Distributions }
576*27b03b36SApple OSS Distributions 
577*27b03b36SApple OSS Distributions void
operator delete[](void * ptr)578*27b03b36SApple OSS Distributions operator delete[](void * ptr)
579*27b03b36SApple OSS Distributions #if __cplusplus >= 201103L
580*27b03b36SApple OSS Distributions noexcept
581*27b03b36SApple OSS Distributions #endif
582*27b03b36SApple OSS Distributions {
583*27b03b36SApple OSS Distributions 	if (ptr) {
584*27b03b36SApple OSS Distributions #if KASAN
585*27b03b36SApple OSS Distributions 		/*
586*27b03b36SApple OSS Distributions 		 * Unpoison the C++ array cookie inserted (but not removed) by the
587*27b03b36SApple OSS Distributions 		 * compiler on new[].
588*27b03b36SApple OSS Distributions 		 */
589*27b03b36SApple OSS Distributions 		kasan_unpoison_cxx_array_cookie(ptr);
590*27b03b36SApple OSS Distributions #endif
591*27b03b36SApple OSS Distributions 		kheap_free_addr(KERN_OS_MALLOC, ptr);
592*27b03b36SApple OSS Distributions 	}
593*27b03b36SApple OSS Distributions 	return;
594*27b03b36SApple OSS Distributions }
595*27b03b36SApple OSS Distributions 
596*27b03b36SApple OSS Distributions #if __cplusplus >= 201103L
597*27b03b36SApple OSS Distributions 
598*27b03b36SApple OSS Distributions void
operator delete(void * addr,size_t sz)599*27b03b36SApple OSS Distributions operator delete(void * addr, size_t sz) noexcept
600*27b03b36SApple OSS Distributions {
601*27b03b36SApple OSS Distributions 	kheap_free(KERN_OS_MALLOC, addr, sz);
602*27b03b36SApple OSS Distributions }
603*27b03b36SApple OSS Distributions 
604*27b03b36SApple OSS Distributions void
operator delete[](void * addr,size_t sz)605*27b03b36SApple OSS Distributions operator delete[](void * addr, size_t sz) noexcept
606*27b03b36SApple OSS Distributions {
607*27b03b36SApple OSS Distributions 	if (addr) {
608*27b03b36SApple OSS Distributions 		kheap_free(KERN_OS_MALLOC, addr, sz);
609*27b03b36SApple OSS Distributions 	}
610*27b03b36SApple OSS Distributions }
611*27b03b36SApple OSS Distributions 
612*27b03b36SApple OSS Distributions #endif /* __cplusplus >= 201103L */
613*27b03b36SApple OSS Distributions 
614*27b03b36SApple OSS Distributions /* PR-6481964 - The compiler is going to check for size overflows in calls to
615*27b03b36SApple OSS Distributions  * new[], and if there is an overflow, it will call __throw_length_error.
616*27b03b36SApple OSS Distributions  * This is an unrecoverable error by the C++ standard, so we must panic here.
617*27b03b36SApple OSS Distributions  *
618*27b03b36SApple OSS Distributions  * We have to put the function inside the std namespace because of how the
619*27b03b36SApple OSS Distributions  * compiler expects the name to be mangled.
620*27b03b36SApple OSS Distributions  */
621*27b03b36SApple OSS Distributions namespace std {
622*27b03b36SApple OSS Distributions void __dead2
__throw_length_error(const char * msg __unused)623*27b03b36SApple OSS Distributions __throw_length_error(const char *msg __unused)
624*27b03b36SApple OSS Distributions {
625*27b03b36SApple OSS Distributions 	panic("Size of array created by new[] has overflowed");
626*27b03b36SApple OSS Distributions }
627*27b03b36SApple OSS Distributions };
628