1*5c2921b0SApple OSS Distributions /*
2*5c2921b0SApple OSS Distributions * Copyright (c) 2000,2008-2009 Apple Inc. All rights reserved.
3*5c2921b0SApple OSS Distributions *
4*5c2921b0SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*5c2921b0SApple OSS Distributions *
6*5c2921b0SApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*5c2921b0SApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*5c2921b0SApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*5c2921b0SApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*5c2921b0SApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*5c2921b0SApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*5c2921b0SApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*5c2921b0SApple OSS Distributions * terms of an Apple operating system software license agreement.
14*5c2921b0SApple OSS Distributions *
15*5c2921b0SApple OSS Distributions * Please obtain a copy of the License at
16*5c2921b0SApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*5c2921b0SApple OSS Distributions *
18*5c2921b0SApple OSS Distributions * The Original Code and all software distributed under the License are
19*5c2921b0SApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*5c2921b0SApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*5c2921b0SApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*5c2921b0SApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*5c2921b0SApple OSS Distributions * Please see the License for the specific language governing rights and
24*5c2921b0SApple OSS Distributions * limitations under the License.
25*5c2921b0SApple OSS Distributions *
26*5c2921b0SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*5c2921b0SApple OSS Distributions */
28*5c2921b0SApple OSS Distributions /*
29*5c2921b0SApple OSS Distributions * Copyright (c) 1997 Apple Inc.
30*5c2921b0SApple OSS Distributions *
31*5c2921b0SApple OSS Distributions */
32*5c2921b0SApple OSS Distributions #include <libkern/c++/OSMetaClass.h>
33*5c2921b0SApple OSS Distributions #include <libkern/c++/OSKext.h>
34*5c2921b0SApple OSS Distributions #include <libkern/c++/OSLib.h>
35*5c2921b0SApple OSS Distributions #include <libkern/c++/OSSymbol.h>
36*5c2921b0SApple OSS Distributions #include <IOKit/IOKitDebug.h>
37*5c2921b0SApple OSS Distributions
38*5c2921b0SApple OSS Distributions #include <sys/cdefs.h>
39*5c2921b0SApple OSS Distributions #if defined(HAS_APPLE_PAC)
40*5c2921b0SApple OSS Distributions #include <ptrauth.h>
41*5c2921b0SApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x) ((uintptr_t) ptrauth_strip(ptrauth_nop_cast(void *, (x)), ptrauth_key_function_pointer))
42*5c2921b0SApple OSS Distributions #else /* defined(HAS_APPLE_PAC) */
43*5c2921b0SApple OSS Distributions #define PTRAUTH_STRIP_STRUCTOR(x) ((uintptr_t) (x))
44*5c2921b0SApple OSS Distributions #endif /* !defined(HAS_APPLE_PAC) */
45*5c2921b0SApple OSS Distributions
46*5c2921b0SApple OSS Distributions __BEGIN_DECLS
47*5c2921b0SApple OSS Distributions
48*5c2921b0SApple OSS Distributions #include <string.h>
49*5c2921b0SApple OSS Distributions #include <mach/mach_types.h>
50*5c2921b0SApple OSS Distributions #include <libkern/kernel_mach_header.h>
51*5c2921b0SApple OSS Distributions #include <libkern/prelink.h>
52*5c2921b0SApple OSS Distributions #include <stdarg.h>
53*5c2921b0SApple OSS Distributions
54*5c2921b0SApple OSS Distributions #if KASAN
55*5c2921b0SApple OSS Distributions #include <san/kasan.h>
56*5c2921b0SApple OSS Distributions #endif
57*5c2921b0SApple OSS Distributions
58*5c2921b0SApple OSS Distributions #if PRAGMA_MARK
59*5c2921b0SApple OSS Distributions #pragma mark Constants &c.
60*5c2921b0SApple OSS Distributions #endif /* PRAGMA_MARK */
61*5c2921b0SApple OSS Distributions OSKextLogSpec kOSRuntimeLogSpec =
62*5c2921b0SApple OSS Distributions kOSKextLogErrorLevel |
63*5c2921b0SApple OSS Distributions kOSKextLogLoadFlag |
64*5c2921b0SApple OSS Distributions kOSKextLogKextBookkeepingFlag;
65*5c2921b0SApple OSS Distributions
66*5c2921b0SApple OSS Distributions #if PRAGMA_MARK
67*5c2921b0SApple OSS Distributions #pragma mark Logging Bootstrap
68*5c2921b0SApple OSS Distributions #endif /* PRAGMA_MARK */
69*5c2921b0SApple OSS Distributions /*********************************************************************
70*5c2921b0SApple OSS Distributions * kern_os Logging Bootstrap
71*5c2921b0SApple OSS Distributions *
72*5c2921b0SApple OSS Distributions * We can't call in to OSKext until the kernel's C++ environment is up
73*5c2921b0SApple OSS Distributions * and running, so let's mask those references with a check variable.
74*5c2921b0SApple OSS Distributions * We print unconditionally if C++ isn't up, but if that's the case
75*5c2921b0SApple OSS Distributions * we've generally hit a serious error in kernel init!
76*5c2921b0SApple OSS Distributions *********************************************************************/
77*5c2921b0SApple OSS Distributions static bool gKernelCPPInitialized = false;
78*5c2921b0SApple OSS Distributions
79*5c2921b0SApple OSS Distributions #define OSRuntimeLog(kext, flags, format, args ...) \
80*5c2921b0SApple OSS Distributions do { \
81*5c2921b0SApple OSS Distributions if (gKernelCPPInitialized) { \
82*5c2921b0SApple OSS Distributions OSKextLog((kext), (flags), (format), ## args); \
83*5c2921b0SApple OSS Distributions } else { \
84*5c2921b0SApple OSS Distributions printf((format), ## args); \
85*5c2921b0SApple OSS Distributions } \
86*5c2921b0SApple OSS Distributions } while (0)
87*5c2921b0SApple OSS Distributions
88*5c2921b0SApple OSS Distributions #if PRAGMA_MARK
89*5c2921b0SApple OSS Distributions #pragma mark Libkern Init
90*5c2921b0SApple OSS Distributions #endif /* PRAGMA_MARK */
91*5c2921b0SApple OSS Distributions /*********************************************************************
92*5c2921b0SApple OSS Distributions * Libkern Init
93*5c2921b0SApple OSS Distributions *********************************************************************/
94*5c2921b0SApple OSS Distributions
95*5c2921b0SApple OSS Distributions #if __GNUC__ >= 3
96*5c2921b0SApple OSS Distributions void __dead2
__cxa_pure_virtual(void)97*5c2921b0SApple OSS Distributions __cxa_pure_virtual( void )
98*5c2921b0SApple OSS Distributions {
99*5c2921b0SApple OSS Distributions panic("%s", __FUNCTION__);
100*5c2921b0SApple OSS Distributions }
101*5c2921b0SApple OSS Distributions #else
102*5c2921b0SApple OSS Distributions void __dead2
__pure_virtual(void)103*5c2921b0SApple OSS Distributions __pure_virtual( void )
104*5c2921b0SApple OSS Distributions {
105*5c2921b0SApple OSS Distributions panic("%s", __FUNCTION__);
106*5c2921b0SApple OSS Distributions }
107*5c2921b0SApple OSS Distributions #endif
108*5c2921b0SApple OSS Distributions
109*5c2921b0SApple OSS Distributions extern lck_grp_t * IOLockGroup;
110*5c2921b0SApple OSS Distributions extern kmod_info_t g_kernel_kmod_info;
111*5c2921b0SApple OSS Distributions
112*5c2921b0SApple OSS Distributions enum {
113*5c2921b0SApple OSS Distributions kOSSectionNamesDefault = 0,
114*5c2921b0SApple OSS Distributions kOSSectionNamesBuiltinKext = 1,
115*5c2921b0SApple OSS Distributions kOSSectionNamesCount = 2,
116*5c2921b0SApple OSS Distributions };
117*5c2921b0SApple OSS Distributions enum {
118*5c2921b0SApple OSS Distributions kOSSectionNameInitializer = 0,
119*5c2921b0SApple OSS Distributions kOSSectionNameFinalizer = 1,
120*5c2921b0SApple OSS Distributions kOSSectionNameCount = 2
121*5c2921b0SApple OSS Distributions };
122*5c2921b0SApple OSS Distributions
123*5c2921b0SApple OSS Distributions static const char *
124*5c2921b0SApple OSS Distributions gOSStructorSectionNames[kOSSectionNamesCount][kOSSectionNameCount] = {
125*5c2921b0SApple OSS Distributions { SECT_MODINITFUNC, SECT_MODTERMFUNC },
126*5c2921b0SApple OSS Distributions { kBuiltinInitSection, kBuiltinTermSection }
127*5c2921b0SApple OSS Distributions };
128*5c2921b0SApple OSS Distributions
129*5c2921b0SApple OSS Distributions void
OSlibkernInit(void)130*5c2921b0SApple OSS Distributions OSlibkernInit(void)
131*5c2921b0SApple OSS Distributions {
132*5c2921b0SApple OSS Distributions // This must be called before calling OSRuntimeInitializeCPP.
133*5c2921b0SApple OSS Distributions OSMetaClassBase::initialize();
134*5c2921b0SApple OSS Distributions
135*5c2921b0SApple OSS Distributions g_kernel_kmod_info.address = (vm_address_t) &_mh_execute_header;
136*5c2921b0SApple OSS Distributions if (kOSReturnSuccess != OSRuntimeInitializeCPP(NULL)) {
137*5c2921b0SApple OSS Distributions // &g_kernel_kmod_info, gOSSectionNamesStandard, 0, 0)) {
138*5c2921b0SApple OSS Distributions panic("OSRuntime: C++ runtime failed to initialize.");
139*5c2921b0SApple OSS Distributions }
140*5c2921b0SApple OSS Distributions
141*5c2921b0SApple OSS Distributions gKernelCPPInitialized = true;
142*5c2921b0SApple OSS Distributions
143*5c2921b0SApple OSS Distributions return;
144*5c2921b0SApple OSS Distributions }
145*5c2921b0SApple OSS Distributions
146*5c2921b0SApple OSS Distributions __END_DECLS
147*5c2921b0SApple OSS Distributions
148*5c2921b0SApple OSS Distributions #if PRAGMA_MARK
149*5c2921b0SApple OSS Distributions #pragma mark C++ Runtime Load/Unload
150*5c2921b0SApple OSS Distributions #endif /* PRAGMA_MARK */
151*5c2921b0SApple OSS Distributions /*********************************************************************
152*5c2921b0SApple OSS Distributions * kern_os C++ Runtime Load/Unload
153*5c2921b0SApple OSS Distributions *********************************************************************/
154*5c2921b0SApple OSS Distributions
155*5c2921b0SApple OSS Distributions typedef void (*structor_t)(void);
156*5c2921b0SApple OSS Distributions
157*5c2921b0SApple OSS Distributions static bool
OSRuntimeCallStructorsInSection(OSKext * theKext,kmod_info_t * kmodInfo,void * metaHandle,kernel_segment_command_t * segment,const char * sectionName,uintptr_t textStart,uintptr_t textEnd)158*5c2921b0SApple OSS Distributions OSRuntimeCallStructorsInSection(
159*5c2921b0SApple OSS Distributions OSKext * theKext,
160*5c2921b0SApple OSS Distributions kmod_info_t * kmodInfo,
161*5c2921b0SApple OSS Distributions void * metaHandle,
162*5c2921b0SApple OSS Distributions kernel_segment_command_t * segment,
163*5c2921b0SApple OSS Distributions const char * sectionName,
164*5c2921b0SApple OSS Distributions uintptr_t textStart,
165*5c2921b0SApple OSS Distributions uintptr_t textEnd)
166*5c2921b0SApple OSS Distributions {
167*5c2921b0SApple OSS Distributions kernel_section_t * section;
168*5c2921b0SApple OSS Distributions bool result = TRUE;
169*5c2921b0SApple OSS Distributions
170*5c2921b0SApple OSS Distributions for (section = firstsect(segment);
171*5c2921b0SApple OSS Distributions section != NULL;
172*5c2921b0SApple OSS Distributions section = nextsect(segment, section)) {
173*5c2921b0SApple OSS Distributions if (strncmp(section->sectname, sectionName, sizeof(section->sectname) - 1)) {
174*5c2921b0SApple OSS Distributions continue;
175*5c2921b0SApple OSS Distributions }
176*5c2921b0SApple OSS Distributions if (section->size == 0) {
177*5c2921b0SApple OSS Distributions continue;
178*5c2921b0SApple OSS Distributions }
179*5c2921b0SApple OSS Distributions
180*5c2921b0SApple OSS Distributions structor_t * structors = (structor_t *)section->addr;
181*5c2921b0SApple OSS Distributions if (!structors) {
182*5c2921b0SApple OSS Distributions continue;
183*5c2921b0SApple OSS Distributions }
184*5c2921b0SApple OSS Distributions
185*5c2921b0SApple OSS Distributions structor_t structor;
186*5c2921b0SApple OSS Distributions uintptr_t value;
187*5c2921b0SApple OSS Distributions unsigned long num_structors = section->size / sizeof(structor_t);
188*5c2921b0SApple OSS Distributions unsigned int hit_null_structor = 0;
189*5c2921b0SApple OSS Distributions unsigned long firstIndex = 0;
190*5c2921b0SApple OSS Distributions
191*5c2921b0SApple OSS Distributions if (textStart) {
192*5c2921b0SApple OSS Distributions // bsearch for any in range
193*5c2921b0SApple OSS Distributions unsigned long baseIdx;
194*5c2921b0SApple OSS Distributions unsigned long lim;
195*5c2921b0SApple OSS Distributions firstIndex = num_structors;
196*5c2921b0SApple OSS Distributions for (lim = num_structors, baseIdx = 0; lim; lim >>= 1) {
197*5c2921b0SApple OSS Distributions structor = structors[baseIdx + (lim >> 1)];
198*5c2921b0SApple OSS Distributions if (!structor) {
199*5c2921b0SApple OSS Distributions panic("%s: null structor", kmodInfo->name);
200*5c2921b0SApple OSS Distributions }
201*5c2921b0SApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
202*5c2921b0SApple OSS Distributions if ((value >= textStart) && (value < textEnd)) {
203*5c2921b0SApple OSS Distributions firstIndex = (baseIdx + (lim >> 1));
204*5c2921b0SApple OSS Distributions // scan back for the first in range
205*5c2921b0SApple OSS Distributions for (; firstIndex; firstIndex--) {
206*5c2921b0SApple OSS Distributions structor = structors[firstIndex - 1];
207*5c2921b0SApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
208*5c2921b0SApple OSS Distributions if ((value < textStart) || (value >= textEnd)) {
209*5c2921b0SApple OSS Distributions break;
210*5c2921b0SApple OSS Distributions }
211*5c2921b0SApple OSS Distributions }
212*5c2921b0SApple OSS Distributions break;
213*5c2921b0SApple OSS Distributions }
214*5c2921b0SApple OSS Distributions if (textStart > value) {
215*5c2921b0SApple OSS Distributions // move right
216*5c2921b0SApple OSS Distributions baseIdx += (lim >> 1) + 1;
217*5c2921b0SApple OSS Distributions lim--;
218*5c2921b0SApple OSS Distributions }
219*5c2921b0SApple OSS Distributions // else move left
220*5c2921b0SApple OSS Distributions }
221*5c2921b0SApple OSS Distributions baseIdx = (baseIdx + (lim >> 1));
222*5c2921b0SApple OSS Distributions }
223*5c2921b0SApple OSS Distributions for (;
224*5c2921b0SApple OSS Distributions (firstIndex < num_structors)
225*5c2921b0SApple OSS Distributions && (!metaHandle || OSMetaClass::checkModLoad(metaHandle));
226*5c2921b0SApple OSS Distributions firstIndex++) {
227*5c2921b0SApple OSS Distributions if ((structor = structors[firstIndex])) {
228*5c2921b0SApple OSS Distributions value = PTRAUTH_STRIP_STRUCTOR(structor);
229*5c2921b0SApple OSS Distributions if ((textStart && (value < textStart))
230*5c2921b0SApple OSS Distributions || (textEnd && (value >= textEnd))) {
231*5c2921b0SApple OSS Distributions break;
232*5c2921b0SApple OSS Distributions }
233*5c2921b0SApple OSS Distributions (*structor)();
234*5c2921b0SApple OSS Distributions } else if (!hit_null_structor) {
235*5c2921b0SApple OSS Distributions hit_null_structor = 1;
236*5c2921b0SApple OSS Distributions OSRuntimeLog(theKext, kOSRuntimeLogSpec,
237*5c2921b0SApple OSS Distributions "Null structor in kext %s segment %s!",
238*5c2921b0SApple OSS Distributions kmodInfo->name, section->segname);
239*5c2921b0SApple OSS Distributions }
240*5c2921b0SApple OSS Distributions }
241*5c2921b0SApple OSS Distributions if (metaHandle) {
242*5c2921b0SApple OSS Distributions result = OSMetaClass::checkModLoad(metaHandle);
243*5c2921b0SApple OSS Distributions }
244*5c2921b0SApple OSS Distributions break;
245*5c2921b0SApple OSS Distributions } /* for (section...) */
246*5c2921b0SApple OSS Distributions return result;
247*5c2921b0SApple OSS Distributions }
248*5c2921b0SApple OSS Distributions
249*5c2921b0SApple OSS Distributions /*********************************************************************
250*5c2921b0SApple OSS Distributions *********************************************************************/
251*5c2921b0SApple OSS Distributions kern_return_t
OSRuntimeFinalizeCPP(OSKext * theKext)252*5c2921b0SApple OSS Distributions OSRuntimeFinalizeCPP(
253*5c2921b0SApple OSS Distributions OSKext * theKext)
254*5c2921b0SApple OSS Distributions {
255*5c2921b0SApple OSS Distributions kern_return_t result = KMOD_RETURN_FAILURE;
256*5c2921b0SApple OSS Distributions void * metaHandle = NULL;// do not free
257*5c2921b0SApple OSS Distributions kernel_mach_header_t * header;
258*5c2921b0SApple OSS Distributions kernel_segment_command_t * segment;
259*5c2921b0SApple OSS Distributions kmod_info_t * kmodInfo;
260*5c2921b0SApple OSS Distributions const char ** sectionNames;
261*5c2921b0SApple OSS Distributions uintptr_t textStart;
262*5c2921b0SApple OSS Distributions uintptr_t textEnd;
263*5c2921b0SApple OSS Distributions
264*5c2921b0SApple OSS Distributions textStart = 0;
265*5c2921b0SApple OSS Distributions textEnd = 0;
266*5c2921b0SApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
267*5c2921b0SApple OSS Distributions if (theKext) {
268*5c2921b0SApple OSS Distributions if (!theKext->isCPPInitialized()) {
269*5c2921b0SApple OSS Distributions result = KMOD_RETURN_SUCCESS;
270*5c2921b0SApple OSS Distributions goto finish;
271*5c2921b0SApple OSS Distributions }
272*5c2921b0SApple OSS Distributions kmodInfo = theKext->kmod_info;
273*5c2921b0SApple OSS Distributions if (!kmodInfo || !kmodInfo->address) {
274*5c2921b0SApple OSS Distributions result = kOSKextReturnInvalidArgument;
275*5c2921b0SApple OSS Distributions goto finish;
276*5c2921b0SApple OSS Distributions }
277*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
278*5c2921b0SApple OSS Distributions if (theKext->flags.builtin) {
279*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)g_kernel_kmod_info.address;
280*5c2921b0SApple OSS Distributions textStart = kmodInfo->address;
281*5c2921b0SApple OSS Distributions textEnd = textStart + kmodInfo->size;
282*5c2921b0SApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
283*5c2921b0SApple OSS Distributions }
284*5c2921b0SApple OSS Distributions } else {
285*5c2921b0SApple OSS Distributions kmodInfo = &g_kernel_kmod_info;
286*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
287*5c2921b0SApple OSS Distributions }
288*5c2921b0SApple OSS Distributions
289*5c2921b0SApple OSS Distributions /* OSKext checks for this condition now, but somebody might call
290*5c2921b0SApple OSS Distributions * this function directly (the symbol is exported....).
291*5c2921b0SApple OSS Distributions */
292*5c2921b0SApple OSS Distributions if (OSMetaClass::modHasInstance(kmodInfo->name)) {
293*5c2921b0SApple OSS Distributions // xxx - Don't log under errors? this is more of an info thing
294*5c2921b0SApple OSS Distributions OSRuntimeLog(theKext, kOSRuntimeLogSpec,
295*5c2921b0SApple OSS Distributions "Can't tear down kext %s C++; classes have instances:",
296*5c2921b0SApple OSS Distributions kmodInfo->name);
297*5c2921b0SApple OSS Distributions OSKext::reportOSMetaClassInstances(kmodInfo->name, kOSRuntimeLogSpec);
298*5c2921b0SApple OSS Distributions result = kOSMetaClassHasInstances;
299*5c2921b0SApple OSS Distributions goto finish;
300*5c2921b0SApple OSS Distributions }
301*5c2921b0SApple OSS Distributions
302*5c2921b0SApple OSS Distributions /* Tell the meta class system that we are starting to unload.
303*5c2921b0SApple OSS Distributions * metaHandle isn't actually needed on the finalize path,
304*5c2921b0SApple OSS Distributions * so we don't check it here, even though OSMetaClass::postModLoad() will
305*5c2921b0SApple OSS Distributions * return a failure (it only does actual work on the init path anyhow).
306*5c2921b0SApple OSS Distributions */
307*5c2921b0SApple OSS Distributions metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
308*5c2921b0SApple OSS Distributions
309*5c2921b0SApple OSS Distributions OSSymbol::checkForPageUnload((void *)kmodInfo->address,
310*5c2921b0SApple OSS Distributions (void *)(kmodInfo->address + kmodInfo->size));
311*5c2921b0SApple OSS Distributions
312*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
313*5c2921b0SApple OSS Distributions segment = firstsegfromheader(header);
314*5c2921b0SApple OSS Distributions
315*5c2921b0SApple OSS Distributions for (segment = firstsegfromheader(header);
316*5c2921b0SApple OSS Distributions segment != NULL;
317*5c2921b0SApple OSS Distributions segment = nextsegfromheader(header, segment)) {
318*5c2921b0SApple OSS Distributions OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
319*5c2921b0SApple OSS Distributions sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
320*5c2921b0SApple OSS Distributions }
321*5c2921b0SApple OSS Distributions
322*5c2921b0SApple OSS Distributions (void)OSMetaClass::postModLoad(metaHandle);
323*5c2921b0SApple OSS Distributions
324*5c2921b0SApple OSS Distributions if (theKext) {
325*5c2921b0SApple OSS Distributions theKext->setCPPInitialized(false);
326*5c2921b0SApple OSS Distributions }
327*5c2921b0SApple OSS Distributions result = KMOD_RETURN_SUCCESS;
328*5c2921b0SApple OSS Distributions finish:
329*5c2921b0SApple OSS Distributions return result;
330*5c2921b0SApple OSS Distributions }
331*5c2921b0SApple OSS Distributions
332*5c2921b0SApple OSS Distributions #if defined(HAS_APPLE_PAC)
333*5c2921b0SApple OSS Distributions #if !KASAN
334*5c2921b0SApple OSS Distributions /*
335*5c2921b0SApple OSS Distributions * Place this function in __KLD,__text on non-kasan builds so it gets unmapped
336*5c2921b0SApple OSS Distributions * after CTRR lockdown.
337*5c2921b0SApple OSS Distributions */
338*5c2921b0SApple OSS Distributions __attribute__((noinline, section("__KLD,__text")))
339*5c2921b0SApple OSS Distributions #endif
340*5c2921b0SApple OSS Distributions static void
OSRuntimeSignStructorsInSegment(kernel_segment_command_t * segment)341*5c2921b0SApple OSS Distributions OSRuntimeSignStructorsInSegment(kernel_segment_command_t *segment)
342*5c2921b0SApple OSS Distributions {
343*5c2921b0SApple OSS Distributions kernel_section_t * section;
344*5c2921b0SApple OSS Distributions structor_t * structors;
345*5c2921b0SApple OSS Distributions volatile structor_t structor;
346*5c2921b0SApple OSS Distributions size_t idx, num_structors;
347*5c2921b0SApple OSS Distributions
348*5c2921b0SApple OSS Distributions for (section = firstsect(segment);
349*5c2921b0SApple OSS Distributions section != NULL;
350*5c2921b0SApple OSS Distributions section = nextsect(segment, section)) {
351*5c2921b0SApple OSS Distributions if ((S_MOD_INIT_FUNC_POINTERS != (SECTION_TYPE & section->flags))
352*5c2921b0SApple OSS Distributions && (S_MOD_TERM_FUNC_POINTERS != (SECTION_TYPE & section->flags))) {
353*5c2921b0SApple OSS Distributions continue;
354*5c2921b0SApple OSS Distributions }
355*5c2921b0SApple OSS Distributions structors = (structor_t *)section->addr;
356*5c2921b0SApple OSS Distributions if (!structors) {
357*5c2921b0SApple OSS Distributions continue;
358*5c2921b0SApple OSS Distributions }
359*5c2921b0SApple OSS Distributions num_structors = section->size / sizeof(structor_t);
360*5c2921b0SApple OSS Distributions for (idx = 0; idx < num_structors; idx++) {
361*5c2921b0SApple OSS Distributions structor = structors[idx];
362*5c2921b0SApple OSS Distributions if (NULL == structor) {
363*5c2921b0SApple OSS Distributions continue;
364*5c2921b0SApple OSS Distributions }
365*5c2921b0SApple OSS Distributions structor = ptrauth_strip(structor, ptrauth_key_function_pointer);
366*5c2921b0SApple OSS Distributions structor = ptrauth_sign_unauthenticated(structor, ptrauth_key_function_pointer, ptrauth_function_pointer_type_discriminator(void (*)(void)));
367*5c2921b0SApple OSS Distributions structors[idx] = structor;
368*5c2921b0SApple OSS Distributions }
369*5c2921b0SApple OSS Distributions } /* for (section...) */
370*5c2921b0SApple OSS Distributions }
371*5c2921b0SApple OSS Distributions #endif
372*5c2921b0SApple OSS Distributions
373*5c2921b0SApple OSS Distributions /*********************************************************************
374*5c2921b0SApple OSS Distributions *********************************************************************/
375*5c2921b0SApple OSS Distributions void
OSRuntimeSignStructors(kernel_mach_header_t * header __unused)376*5c2921b0SApple OSS Distributions OSRuntimeSignStructors(
377*5c2921b0SApple OSS Distributions kernel_mach_header_t * header __unused)
378*5c2921b0SApple OSS Distributions {
379*5c2921b0SApple OSS Distributions #if defined(HAS_APPLE_PAC)
380*5c2921b0SApple OSS Distributions
381*5c2921b0SApple OSS Distributions kernel_segment_command_t * segment;
382*5c2921b0SApple OSS Distributions
383*5c2921b0SApple OSS Distributions for (segment = firstsegfromheader(header);
384*5c2921b0SApple OSS Distributions segment != NULL;
385*5c2921b0SApple OSS Distributions segment = nextsegfromheader(header, segment)) {
386*5c2921b0SApple OSS Distributions OSRuntimeSignStructorsInSegment(segment);
387*5c2921b0SApple OSS Distributions } /* for (segment...) */
388*5c2921b0SApple OSS Distributions #endif /* !defined(XXX) && defined(HAS_APPLE_PAC) */
389*5c2921b0SApple OSS Distributions }
390*5c2921b0SApple OSS Distributions
391*5c2921b0SApple OSS Distributions /*********************************************************************
392*5c2921b0SApple OSS Distributions *********************************************************************/
393*5c2921b0SApple OSS Distributions void
OSRuntimeSignStructorsInFileset(kernel_mach_header_t * fileset_header __unused)394*5c2921b0SApple OSS Distributions OSRuntimeSignStructorsInFileset(
395*5c2921b0SApple OSS Distributions kernel_mach_header_t * fileset_header __unused)
396*5c2921b0SApple OSS Distributions {
397*5c2921b0SApple OSS Distributions #if defined(HAS_APPLE_PAC)
398*5c2921b0SApple OSS Distributions struct load_command *lc;
399*5c2921b0SApple OSS Distributions
400*5c2921b0SApple OSS Distributions lc = (struct load_command *)((uintptr_t)fileset_header + sizeof(*fileset_header));
401*5c2921b0SApple OSS Distributions for (uint32_t i = 0; i < fileset_header->ncmds; i++,
402*5c2921b0SApple OSS Distributions lc = (struct load_command *)((uintptr_t)lc + lc->cmdsize)) {
403*5c2921b0SApple OSS Distributions if (lc->cmd == LC_FILESET_ENTRY) {
404*5c2921b0SApple OSS Distributions struct fileset_entry_command *fse;
405*5c2921b0SApple OSS Distributions kernel_mach_header_t *mh;
406*5c2921b0SApple OSS Distributions
407*5c2921b0SApple OSS Distributions fse = (struct fileset_entry_command *)(uintptr_t)lc;
408*5c2921b0SApple OSS Distributions mh = (kernel_mach_header_t *)((uintptr_t)fse->vmaddr);
409*5c2921b0SApple OSS Distributions OSRuntimeSignStructors(mh);
410*5c2921b0SApple OSS Distributions } else if (lc->cmd == LC_SEGMENT_64) {
411*5c2921b0SApple OSS Distributions /*
412*5c2921b0SApple OSS Distributions * Slide/adjust all LC_SEGMENT_64 commands in the fileset
413*5c2921b0SApple OSS Distributions * (and any sections in those segments)
414*5c2921b0SApple OSS Distributions */
415*5c2921b0SApple OSS Distributions kernel_segment_command_t *seg;
416*5c2921b0SApple OSS Distributions seg = (kernel_segment_command_t *)(uintptr_t)lc;
417*5c2921b0SApple OSS Distributions OSRuntimeSignStructorsInSegment(seg);
418*5c2921b0SApple OSS Distributions }
419*5c2921b0SApple OSS Distributions }
420*5c2921b0SApple OSS Distributions
421*5c2921b0SApple OSS Distributions #endif /* defined(HAS_APPLE_PAC) */
422*5c2921b0SApple OSS Distributions }
423*5c2921b0SApple OSS Distributions
424*5c2921b0SApple OSS Distributions /*********************************************************************
425*5c2921b0SApple OSS Distributions *********************************************************************/
426*5c2921b0SApple OSS Distributions kern_return_t
OSRuntimeInitializeCPP(OSKext * theKext)427*5c2921b0SApple OSS Distributions OSRuntimeInitializeCPP(
428*5c2921b0SApple OSS Distributions OSKext * theKext)
429*5c2921b0SApple OSS Distributions {
430*5c2921b0SApple OSS Distributions kern_return_t result = KMOD_RETURN_FAILURE;
431*5c2921b0SApple OSS Distributions kernel_mach_header_t * header = NULL;
432*5c2921b0SApple OSS Distributions void * metaHandle = NULL;// do not free
433*5c2921b0SApple OSS Distributions bool load_success = true;
434*5c2921b0SApple OSS Distributions kernel_segment_command_t * segment = NULL;// do not free
435*5c2921b0SApple OSS Distributions kernel_segment_command_t * failure_segment = NULL; // do not free
436*5c2921b0SApple OSS Distributions kmod_info_t * kmodInfo;
437*5c2921b0SApple OSS Distributions const char ** sectionNames;
438*5c2921b0SApple OSS Distributions uintptr_t textStart;
439*5c2921b0SApple OSS Distributions uintptr_t textEnd;
440*5c2921b0SApple OSS Distributions
441*5c2921b0SApple OSS Distributions textStart = 0;
442*5c2921b0SApple OSS Distributions textEnd = 0;
443*5c2921b0SApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesDefault];
444*5c2921b0SApple OSS Distributions if (theKext) {
445*5c2921b0SApple OSS Distributions if (theKext->isCPPInitialized()) {
446*5c2921b0SApple OSS Distributions result = KMOD_RETURN_SUCCESS;
447*5c2921b0SApple OSS Distributions goto finish;
448*5c2921b0SApple OSS Distributions }
449*5c2921b0SApple OSS Distributions
450*5c2921b0SApple OSS Distributions kmodInfo = theKext->kmod_info;
451*5c2921b0SApple OSS Distributions if (!kmodInfo || !kmodInfo->address) {
452*5c2921b0SApple OSS Distributions result = kOSKextReturnInvalidArgument;
453*5c2921b0SApple OSS Distributions goto finish;
454*5c2921b0SApple OSS Distributions }
455*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
456*5c2921b0SApple OSS Distributions
457*5c2921b0SApple OSS Distributions if (theKext->flags.builtin) {
458*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)g_kernel_kmod_info.address;
459*5c2921b0SApple OSS Distributions textStart = kmodInfo->address;
460*5c2921b0SApple OSS Distributions textEnd = textStart + kmodInfo->size;
461*5c2921b0SApple OSS Distributions sectionNames = gOSStructorSectionNames[kOSSectionNamesBuiltinKext];
462*5c2921b0SApple OSS Distributions }
463*5c2921b0SApple OSS Distributions } else {
464*5c2921b0SApple OSS Distributions kmodInfo = &g_kernel_kmod_info;
465*5c2921b0SApple OSS Distributions header = (kernel_mach_header_t *)kmodInfo->address;
466*5c2921b0SApple OSS Distributions }
467*5c2921b0SApple OSS Distributions
468*5c2921b0SApple OSS Distributions /* Tell the meta class system that we are starting the load
469*5c2921b0SApple OSS Distributions */
470*5c2921b0SApple OSS Distributions metaHandle = OSMetaClass::preModLoad(kmodInfo->name);
471*5c2921b0SApple OSS Distributions assert(metaHandle);
472*5c2921b0SApple OSS Distributions if (!metaHandle) {
473*5c2921b0SApple OSS Distributions goto finish;
474*5c2921b0SApple OSS Distributions }
475*5c2921b0SApple OSS Distributions
476*5c2921b0SApple OSS Distributions /* NO GOTO PAST HERE. */
477*5c2921b0SApple OSS Distributions
478*5c2921b0SApple OSS Distributions /* Scan the header for all constructor sections, in any
479*5c2921b0SApple OSS Distributions * segment, and invoke the constructors within those sections.
480*5c2921b0SApple OSS Distributions */
481*5c2921b0SApple OSS Distributions for (segment = firstsegfromheader(header);
482*5c2921b0SApple OSS Distributions segment != NULL && load_success;
483*5c2921b0SApple OSS Distributions segment = nextsegfromheader(header, segment)) {
484*5c2921b0SApple OSS Distributions /* Record the current segment in the event of a failure.
485*5c2921b0SApple OSS Distributions */
486*5c2921b0SApple OSS Distributions failure_segment = segment;
487*5c2921b0SApple OSS Distributions load_success = OSRuntimeCallStructorsInSection(
488*5c2921b0SApple OSS Distributions theKext, kmodInfo, metaHandle, segment,
489*5c2921b0SApple OSS Distributions sectionNames[kOSSectionNameInitializer],
490*5c2921b0SApple OSS Distributions textStart, textEnd);
491*5c2921b0SApple OSS Distributions } /* for (segment...) */
492*5c2921b0SApple OSS Distributions
493*5c2921b0SApple OSS Distributions /* We failed so call all of the destructors. We must do this before
494*5c2921b0SApple OSS Distributions * calling OSMetaClass::postModLoad() as the OSMetaClass destructors
495*5c2921b0SApple OSS Distributions * will alter state (in the metaHandle) used by that function.
496*5c2921b0SApple OSS Distributions */
497*5c2921b0SApple OSS Distributions if (!load_success) {
498*5c2921b0SApple OSS Distributions /* Scan the header for all destructor sections, in any
499*5c2921b0SApple OSS Distributions * segment, and invoke the constructors within those sections.
500*5c2921b0SApple OSS Distributions */
501*5c2921b0SApple OSS Distributions for (segment = firstsegfromheader(header);
502*5c2921b0SApple OSS Distributions segment != failure_segment && segment != NULL;
503*5c2921b0SApple OSS Distributions segment = nextsegfromheader(header, segment)) {
504*5c2921b0SApple OSS Distributions OSRuntimeCallStructorsInSection(theKext, kmodInfo, NULL, segment,
505*5c2921b0SApple OSS Distributions sectionNames[kOSSectionNameFinalizer], textStart, textEnd);
506*5c2921b0SApple OSS Distributions } /* for (segment...) */
507*5c2921b0SApple OSS Distributions }
508*5c2921b0SApple OSS Distributions
509*5c2921b0SApple OSS Distributions /* Now, regardless of success so far, do the post-init registration
510*5c2921b0SApple OSS Distributions * and cleanup. If we had to call the unloadCPP function, static
511*5c2921b0SApple OSS Distributions * destructors have removed classes from the stalled list so no
512*5c2921b0SApple OSS Distributions * metaclasses will actually be registered.
513*5c2921b0SApple OSS Distributions */
514*5c2921b0SApple OSS Distributions result = OSMetaClass::postModLoad(metaHandle);
515*5c2921b0SApple OSS Distributions
516*5c2921b0SApple OSS Distributions /* If we've otherwise been fine up to now, but OSMetaClass::postModLoad()
517*5c2921b0SApple OSS Distributions * fails (typically due to a duplicate class), tear down all the C++
518*5c2921b0SApple OSS Distributions * stuff from the kext. This isn't necessary for libkern/OSMetaClass stuff,
519*5c2921b0SApple OSS Distributions * but may be necessary for other C++ code. We ignore the return value
520*5c2921b0SApple OSS Distributions * because it's only a fail when there are existing instances of libkern
521*5c2921b0SApple OSS Distributions * classes, and there had better not be any created on the C++ init path.
522*5c2921b0SApple OSS Distributions */
523*5c2921b0SApple OSS Distributions if (load_success && result != KMOD_RETURN_SUCCESS) {
524*5c2921b0SApple OSS Distributions (void)OSRuntimeFinalizeCPP(theKext); //kmodInfo, sectionNames, textStart, textEnd);
525*5c2921b0SApple OSS Distributions }
526*5c2921b0SApple OSS Distributions
527*5c2921b0SApple OSS Distributions if (theKext && load_success && result == KMOD_RETURN_SUCCESS) {
528*5c2921b0SApple OSS Distributions theKext->setCPPInitialized(true);
529*5c2921b0SApple OSS Distributions }
530*5c2921b0SApple OSS Distributions finish:
531*5c2921b0SApple OSS Distributions return result;
532*5c2921b0SApple OSS Distributions }
533*5c2921b0SApple OSS Distributions
534*5c2921b0SApple OSS Distributions /*********************************************************************
535*5c2921b0SApple OSS Distributions * Unload a kernel segment.
536*5c2921b0SApple OSS Distributions *********************************************************************/
537*5c2921b0SApple OSS Distributions
538*5c2921b0SApple OSS Distributions void
OSRuntimeUnloadCPPForSegment(kernel_segment_command_t * segment)539*5c2921b0SApple OSS Distributions OSRuntimeUnloadCPPForSegment(
540*5c2921b0SApple OSS Distributions kernel_segment_command_t * segment)
541*5c2921b0SApple OSS Distributions {
542*5c2921b0SApple OSS Distributions OSRuntimeCallStructorsInSection(NULL, &g_kernel_kmod_info, NULL, segment,
543*5c2921b0SApple OSS Distributions gOSStructorSectionNames[kOSSectionNamesDefault][kOSSectionNameFinalizer], 0, 0);
544*5c2921b0SApple OSS Distributions }
545*5c2921b0SApple OSS Distributions
546*5c2921b0SApple OSS Distributions #if PRAGMA_MARK
547*5c2921b0SApple OSS Distributions #pragma mark C++ Allocators & Deallocators
548*5c2921b0SApple OSS Distributions #endif /* PRAGMA_MARK */
549*5c2921b0SApple OSS Distributions /*********************************************************************
550*5c2921b0SApple OSS Distributions * C++ Allocators & Deallocators
551*5c2921b0SApple OSS Distributions *********************************************************************/
552*5c2921b0SApple OSS Distributions __typed_allocators_ignore_push
553*5c2921b0SApple OSS Distributions
554*5c2921b0SApple OSS Distributions void *
operator new(size_t size)555*5c2921b0SApple OSS Distributions operator new(size_t size)
556*5c2921b0SApple OSS Distributions {
557*5c2921b0SApple OSS Distributions assert(size);
558*5c2921b0SApple OSS Distributions return kheap_alloc(KERN_OS_MALLOC, size,
559*5c2921b0SApple OSS Distributions Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
560*5c2921b0SApple OSS Distributions }
561*5c2921b0SApple OSS Distributions
562*5c2921b0SApple OSS Distributions void
operator delete(void * addr)563*5c2921b0SApple OSS Distributions operator delete(void * addr)
564*5c2921b0SApple OSS Distributions #if __cplusplus >= 201103L
565*5c2921b0SApple OSS Distributions noexcept
566*5c2921b0SApple OSS Distributions #endif
567*5c2921b0SApple OSS Distributions {
568*5c2921b0SApple OSS Distributions kheap_free_addr(KERN_OS_MALLOC, addr);
569*5c2921b0SApple OSS Distributions return;
570*5c2921b0SApple OSS Distributions }
571*5c2921b0SApple OSS Distributions
572*5c2921b0SApple OSS Distributions void *
operator new[](unsigned long size)573*5c2921b0SApple OSS Distributions operator new[](unsigned long size)
574*5c2921b0SApple OSS Distributions {
575*5c2921b0SApple OSS Distributions return kheap_alloc(KERN_OS_MALLOC, size,
576*5c2921b0SApple OSS Distributions Z_VM_TAG_BT(Z_WAITOK_ZERO, VM_KERN_MEMORY_LIBKERN));
577*5c2921b0SApple OSS Distributions }
578*5c2921b0SApple OSS Distributions
579*5c2921b0SApple OSS Distributions void
operator delete[](void * ptr)580*5c2921b0SApple OSS Distributions operator delete[](void * ptr)
581*5c2921b0SApple OSS Distributions #if __cplusplus >= 201103L
582*5c2921b0SApple OSS Distributions noexcept
583*5c2921b0SApple OSS Distributions #endif
584*5c2921b0SApple OSS Distributions {
585*5c2921b0SApple OSS Distributions if (ptr) {
586*5c2921b0SApple OSS Distributions #if KASAN
587*5c2921b0SApple OSS Distributions /*
588*5c2921b0SApple OSS Distributions * Unpoison the C++ array cookie inserted (but not removed) by the
589*5c2921b0SApple OSS Distributions * compiler on new[].
590*5c2921b0SApple OSS Distributions */
591*5c2921b0SApple OSS Distributions kasan_unpoison_cxx_array_cookie(ptr);
592*5c2921b0SApple OSS Distributions #endif
593*5c2921b0SApple OSS Distributions kheap_free_addr(KERN_OS_MALLOC, ptr);
594*5c2921b0SApple OSS Distributions }
595*5c2921b0SApple OSS Distributions return;
596*5c2921b0SApple OSS Distributions }
597*5c2921b0SApple OSS Distributions
598*5c2921b0SApple OSS Distributions #if __cplusplus >= 201103L
599*5c2921b0SApple OSS Distributions
600*5c2921b0SApple OSS Distributions void
operator delete(void * addr,size_t sz)601*5c2921b0SApple OSS Distributions operator delete(void * addr, size_t sz) noexcept
602*5c2921b0SApple OSS Distributions {
603*5c2921b0SApple OSS Distributions kheap_free(KERN_OS_MALLOC, addr, sz);
604*5c2921b0SApple OSS Distributions }
605*5c2921b0SApple OSS Distributions
606*5c2921b0SApple OSS Distributions void
operator delete[](void * addr,size_t sz)607*5c2921b0SApple OSS Distributions operator delete[](void * addr, size_t sz) noexcept
608*5c2921b0SApple OSS Distributions {
609*5c2921b0SApple OSS Distributions if (addr) {
610*5c2921b0SApple OSS Distributions kheap_free(KERN_OS_MALLOC, addr, sz);
611*5c2921b0SApple OSS Distributions }
612*5c2921b0SApple OSS Distributions }
613*5c2921b0SApple OSS Distributions
614*5c2921b0SApple OSS Distributions __typed_allocators_ignore_pop
615*5c2921b0SApple OSS Distributions
616*5c2921b0SApple OSS Distributions #endif /* __cplusplus >= 201103L */
617*5c2921b0SApple OSS Distributions
618*5c2921b0SApple OSS Distributions /* PR-6481964 - The compiler is going to check for size overflows in calls to
619*5c2921b0SApple OSS Distributions * new[], and if there is an overflow, it will call __throw_length_error.
620*5c2921b0SApple OSS Distributions * This is an unrecoverable error by the C++ standard, so we must panic here.
621*5c2921b0SApple OSS Distributions *
622*5c2921b0SApple OSS Distributions * We have to put the function inside the std namespace because of how the
623*5c2921b0SApple OSS Distributions * compiler expects the name to be mangled.
624*5c2921b0SApple OSS Distributions */
625*5c2921b0SApple OSS Distributions namespace std {
626*5c2921b0SApple OSS Distributions void __dead2
__throw_length_error(const char * msg __unused)627*5c2921b0SApple OSS Distributions __throw_length_error(const char *msg __unused)
628*5c2921b0SApple OSS Distributions {
629*5c2921b0SApple OSS Distributions panic("Size of array created by new[] has overflowed");
630*5c2921b0SApple OSS Distributions }
631*5c2921b0SApple OSS Distributions };
632