xref: /xnu-8796.121.2/tests/ldt.c (revision c54f35ca767986246321eb901baf8f5ff7923f6a)
1*c54f35caSApple OSS Distributions /*
2*c54f35caSApple OSS Distributions  * Copyright (c) 2019 Apple Inc. All rights reserved.
3*c54f35caSApple OSS Distributions  *
4*c54f35caSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*c54f35caSApple OSS Distributions  *
6*c54f35caSApple OSS Distributions  * This file contains Original Code and/or Modifications of Original Code
7*c54f35caSApple OSS Distributions  * as defined in and that are subject to the Apple Public Source License
8*c54f35caSApple OSS Distributions  * Version 2.0 (the 'License'). You may not use this file except in
9*c54f35caSApple OSS Distributions  * compliance with the License. The rights granted to you under the License
10*c54f35caSApple OSS Distributions  * may not be used to create, or enable the creation or redistribution of,
11*c54f35caSApple OSS Distributions  * unlawful or unlicensed copies of an Apple operating system, or to
12*c54f35caSApple OSS Distributions  * circumvent, violate, or enable the circumvention or violation of, any
13*c54f35caSApple OSS Distributions  * terms of an Apple operating system software license agreement.
14*c54f35caSApple OSS Distributions  *
15*c54f35caSApple OSS Distributions  * Please obtain a copy of the License at
16*c54f35caSApple OSS Distributions  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*c54f35caSApple OSS Distributions  *
18*c54f35caSApple OSS Distributions  * The Original Code and all software distributed under the License are
19*c54f35caSApple OSS Distributions  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*c54f35caSApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*c54f35caSApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*c54f35caSApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*c54f35caSApple OSS Distributions  * Please see the License for the specific language governing rights and
24*c54f35caSApple OSS Distributions  * limitations under the License.
25*c54f35caSApple OSS Distributions  *
26*c54f35caSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*c54f35caSApple OSS Distributions  */
28*c54f35caSApple OSS Distributions 
29*c54f35caSApple OSS Distributions // #define STANDALONE
30*c54f35caSApple OSS Distributions 
31*c54f35caSApple OSS Distributions #ifndef STANDALONE
32*c54f35caSApple OSS Distributions #include <darwintest.h>
33*c54f35caSApple OSS Distributions #endif
34*c54f35caSApple OSS Distributions #include <architecture/i386/table.h>
35*c54f35caSApple OSS Distributions #include <i386/user_ldt.h>
36*c54f35caSApple OSS Distributions #include <mach/i386/vm_param.h>
37*c54f35caSApple OSS Distributions #include <mach/i386/thread_status.h>
38*c54f35caSApple OSS Distributions #include <mach/mach.h>
39*c54f35caSApple OSS Distributions #include <signal.h>
40*c54f35caSApple OSS Distributions #include <stdio.h>
41*c54f35caSApple OSS Distributions #include <stdlib.h>
42*c54f35caSApple OSS Distributions #include <strings.h>
43*c54f35caSApple OSS Distributions #include <sys/mman.h>
44*c54f35caSApple OSS Distributions #include <sys/types.h>
45*c54f35caSApple OSS Distributions #include <sys/signal.h>
46*c54f35caSApple OSS Distributions #include <sys/sysctl.h>
47*c54f35caSApple OSS Distributions #include <assert.h>
48*c54f35caSApple OSS Distributions #include <errno.h>
49*c54f35caSApple OSS Distributions #include <fcntl.h>
50*c54f35caSApple OSS Distributions #include <pthread.h>
51*c54f35caSApple OSS Distributions #include <unistd.h>
52*c54f35caSApple OSS Distributions #include <ldt_mach_exc.h>
53*c54f35caSApple OSS Distributions 
54*c54f35caSApple OSS Distributions #ifndef STANDALONE
55*c54f35caSApple OSS Distributions T_GLOBAL_META(
56*c54f35caSApple OSS Distributions 	T_META_NAMESPACE("xnu.intel"),
57*c54f35caSApple OSS Distributions 	T_META_RADAR_COMPONENT_NAME("xnu"),
58*c54f35caSApple OSS Distributions 	T_META_RADAR_COMPONENT_VERSION("intel"),
59*c54f35caSApple OSS Distributions 	T_META_OWNER("seth_goldberg"),
60*c54f35caSApple OSS Distributions 	T_META_CHECK_LEAKS(false)
61*c54f35caSApple OSS Distributions 	);
62*c54f35caSApple OSS Distributions #endif
63*c54f35caSApple OSS Distributions 
64*c54f35caSApple OSS Distributions #define COMPAT_MODE_CS_SELECTOR 0x1f
65*c54f35caSApple OSS Distributions #define SYSENTER_SELECTOR 0xb
66*c54f35caSApple OSS Distributions /* #define DEBUG 1 */
67*c54f35caSApple OSS Distributions #define P2ROUNDUP(x, align)     (-(-((long)x) & -((long)align)))
68*c54f35caSApple OSS Distributions #define MSG 2048
69*c54f35caSApple OSS Distributions 
70*c54f35caSApple OSS Distributions #define NORMAL_RUN_TIME  (10)
71*c54f35caSApple OSS Distributions #define TIMEOUT_OVERHEAD (10)
72*c54f35caSApple OSS Distributions 
73*c54f35caSApple OSS Distributions /*
74*c54f35caSApple OSS Distributions  * General theory of operation:
75*c54f35caSApple OSS Distributions  * ----------------------------
76*c54f35caSApple OSS Distributions  * (1) Ensure that all code and data to be accessed from compatibility mode is
77*c54f35caSApple OSS Distributions  *     located in the low 4GiB of virtual address space.
78*c54f35caSApple OSS Distributions  * (2) Allocate required segments via the i386_set_ldt() system call, making
79*c54f35caSApple OSS Distributions  *     sure to set the descriptor type correctly (code vs. data).  Creating
80*c54f35caSApple OSS Distributions  *     64-bit code segments is not allowed (just use the existing 0x2b selector.)
81*c54f35caSApple OSS Distributions  * (3) Once you know which selector is associated with the desired code, use a
82*c54f35caSApple OSS Distributions  *     trampoline (or thunk) to (a) switch to a stack that's located below 4GiB
83*c54f35caSApple OSS Distributions  *     and (b) save ABI-mandated caller-saved state so that if it's trashed by
84*c54f35caSApple OSS Distributions  *     compatibility-mode code, it can be restored before returning to 64-bit
85*c54f35caSApple OSS Distributions  *     mode (if desired), and finally (c) long-jump or long-call (aka far call)
86*c54f35caSApple OSS Distributions  *     to the segment and desired offset (this example uses an offset of 0 for
87*c54f35caSApple OSS Distributions  *     simplicity.)
88*c54f35caSApple OSS Distributions  * (4) Once in compatibility mode, if a framework call or system call is required,
89*c54f35caSApple OSS Distributions  *     the code must trampoline back to 64-bit mode to do so.  System calls from
90*c54f35caSApple OSS Distributions  *     compatibility mode code are not supported and will result in invalid opcode
91*c54f35caSApple OSS Distributions  *     exceptions.  This example includes a simple 64-bit trampoline (which must
92*c54f35caSApple OSS Distributions  *     be located in the low 4GiB of virtual address space, since it's executed
93*c54f35caSApple OSS Distributions  *     by compatibility-mode code.)  Note that since the 64-bit ABI mandates that
94*c54f35caSApple OSS Distributions  *     the stack must be aligned to a 16-byte boundary, the sample trampoline
95*c54f35caSApple OSS Distributions  *     performs that rounding, to simplify compatibility-mode code.  Additionally,
96*c54f35caSApple OSS Distributions  *     since 64-bit native code makes use of thread-local storage, the user-mode
97*c54f35caSApple OSS Distributions  *     GSbase must be restored.  This sample includes two ways to do that-- (a) by
98*c54f35caSApple OSS Distributions  *     calling into a C implementation that associates the thread-local storage
99*c54f35caSApple OSS Distributions  *     pointer with a stack range (which will be unique for each thread.), and
100*c54f35caSApple OSS Distributions  *     (b) by storing the original GSbase in a block of memory installed into
101*c54f35caSApple OSS Distributions  *     GSbase before calling into compatibility-mode code.  A special machdep
102*c54f35caSApple OSS Distributions  *     system call restores GSbase as needed.  Note that the sample trampoline
103*c54f35caSApple OSS Distributions  *     does not save and restore %gs (or most other register state, so that is an
104*c54f35caSApple OSS Distributions  *     area that may be tailored to the application's requirements.)
105*c54f35caSApple OSS Distributions  * (5) Once running in compatibility mode, should synchronous or asynchronous
106*c54f35caSApple OSS Distributions  *     exceptions occur, this sample shows how a mach exception handler (running
107*c54f35caSApple OSS Distributions  *     in a detached thread, handling exceptions for the entire task) can catch
108*c54f35caSApple OSS Distributions  *     such exceptions and manipulate thread state to perform recovery (or not.)
109*c54f35caSApple OSS Distributions  *     Other ways to handle exceptions include installing per-thread exception
110*c54f35caSApple OSS Distributions  *     servers.  Alternatively, BSD signal handlers can be used.  Note that once a
111*c54f35caSApple OSS Distributions  *     process installs a custom LDT, *ALL* future signal deliveries will include
112*c54f35caSApple OSS Distributions  *     ucontext pointers to mcontext structures that include enhanced thread
113*c54f35caSApple OSS Distributions  *     state embedded (e.g. the %ds, %es, %ss, and GSBase registers) [This assumes
114*c54f35caSApple OSS Distributions  *     that the SA_SIGINFO is passed to sigaction(2) when registering handlers].
115*c54f35caSApple OSS Distributions  *     The mcontext size (part of the ucontext) can be used to differentiate between
116*c54f35caSApple OSS Distributions  *     different mcontext flavors (e.g. those with/without full thread state plus
117*c54f35caSApple OSS Distributions  *     x87 FP state, AVX state, or AVX2/3 state).
118*c54f35caSApple OSS Distributions  */
119*c54f35caSApple OSS Distributions 
120*c54f35caSApple OSS Distributions /*
121*c54f35caSApple OSS Distributions  * This test exercises the custom LDT functionality exposed via the i386_{get,set}_ldt
122*c54f35caSApple OSS Distributions  * system calls.
123*c54f35caSApple OSS Distributions  *
124*c54f35caSApple OSS Distributions  * Tests include:
125*c54f35caSApple OSS Distributions  * (1a) Exception handling (due to an exception or another thread sending a signal) while
126*c54f35caSApple OSS Distributions  *      running in compatibility mode;
127*c54f35caSApple OSS Distributions  * (1b) Signal handling while running in compatibility mode;
128*c54f35caSApple OSS Distributions  * (2)  Thunking back to 64-bit mode and executing a framework function (e.g. printf)
129*c54f35caSApple OSS Distributions  * (3)  Ensuring that transitions to compatibility mode and back to 64-bit mode
130*c54f35caSApple OSS Distributions  *      do not negatively impact system calls and framework calls in 64-bit mode
131*c54f35caSApple OSS Distributions  * (4)  Use of thread_get_state / thread_set_state to configure a thread to
132*c54f35caSApple OSS Distributions  *      execute in compatibility mode with the proper LDT code segment (this is
133*c54f35caSApple OSS Distributions  *      effectively what the exception handler does when the passed-in new_state
134*c54f35caSApple OSS Distributions  *      is changed (or what the BSD signal handler return handling does when the
135*c54f35caSApple OSS Distributions  *      mcontext is modified).)
136*c54f35caSApple OSS Distributions  * (5)  Ensure that compatibility mode code cannot make system calls via sysenter or
137*c54f35caSApple OSS Distributions  *      old-style int {0x80..0x82}.
138*c54f35caSApple OSS Distributions  * (6)  Negative testing to ensure errors are returned if the consumer tries
139*c54f35caSApple OSS Distributions  *      to set a disallowed segment type / Long flag. [TBD]
140*c54f35caSApple OSS Distributions  */
141*c54f35caSApple OSS Distributions 
142*c54f35caSApple OSS Distributions /*
143*c54f35caSApple OSS Distributions  * Note that these addresses are not necessarily available due to ASLR, so
144*c54f35caSApple OSS Distributions  * a robust implementation should determine the proper range to use via
145*c54f35caSApple OSS Distributions  * another means.
146*c54f35caSApple OSS Distributions  */
147*c54f35caSApple OSS Distributions #ifndef STANDALONE
148*c54f35caSApple OSS Distributions /* libdarwintest needs LOTs of stack */
149*c54f35caSApple OSS Distributions #endif
150*c54f35caSApple OSS Distributions #define FIXED_STACK_SIZE (PAGE_SIZE * 16)
151*c54f35caSApple OSS Distributions #define FIXED_TRAMP_MAXLEN (PAGE_SIZE * 8)
152*c54f35caSApple OSS Distributions 
153*c54f35caSApple OSS Distributions #pragma pack(1)
154*c54f35caSApple OSS Distributions typedef struct {
155*c54f35caSApple OSS Distributions 	uint64_t off;
156*c54f35caSApple OSS Distributions 	uint16_t seg;
157*c54f35caSApple OSS Distributions } far_call_t;
158*c54f35caSApple OSS Distributions #pragma pack()
159*c54f35caSApple OSS Distributions 
160*c54f35caSApple OSS Distributions typedef struct {
161*c54f35caSApple OSS Distributions 	uint64_t stack_base;
162*c54f35caSApple OSS Distributions 	uint64_t stack_limit;
163*c54f35caSApple OSS Distributions 	uint64_t GSbase;
164*c54f35caSApple OSS Distributions } stackaddr_to_gsbase_t;
165*c54f35caSApple OSS Distributions 
166*c54f35caSApple OSS Distributions typedef struct thread_arg {
167*c54f35caSApple OSS Distributions 	pthread_mutex_t         mutex;
168*c54f35caSApple OSS Distributions 	pthread_cond_t          condvar;
169*c54f35caSApple OSS Distributions 	volatile boolean_t      done;
170*c54f35caSApple OSS Distributions 	uint32_t                compat_stackaddr;       /* Compatibility mode stack address */
171*c54f35caSApple OSS Distributions } thread_arg_t;
172*c54f35caSApple OSS Distributions 
173*c54f35caSApple OSS Distributions typedef struct custom_tsd {
174*c54f35caSApple OSS Distributions 	struct custom_tsd *     this_tsd_base;
175*c54f35caSApple OSS Distributions 	uint64_t                orig_tsd_base;
176*c54f35caSApple OSS Distributions } custom_tsd_t;
177*c54f35caSApple OSS Distributions 
178*c54f35caSApple OSS Distributions typedef uint64_t (*compat_tramp_t)(far_call_t *fcp, void *lowmemstk, uint64_t arg_for_32bit,
179*c54f35caSApple OSS Distributions     uint64_t callback, uint64_t absolute_addr_of_thunk64);
180*c54f35caSApple OSS Distributions 
181*c54f35caSApple OSS Distributions #define GS_RELATIVE volatile __attribute__((address_space(256)))
182*c54f35caSApple OSS Distributions static custom_tsd_t GS_RELATIVE *mytsd = (custom_tsd_t GS_RELATIVE *)0;
183*c54f35caSApple OSS Distributions 
184*c54f35caSApple OSS Distributions static far_call_t input_desc = { .seg = COMPAT_MODE_CS_SELECTOR, .off = 0 };
185*c54f35caSApple OSS Distributions static uint64_t stackAddr = 0;
186*c54f35caSApple OSS Distributions static compat_tramp_t thunkit = NULL;
187*c54f35caSApple OSS Distributions static uint64_t thunk64_addr;
188*c54f35caSApple OSS Distributions /* stack2gs[0] is initialized in map_lowmem_stack() */
189*c54f35caSApple OSS Distributions static stackaddr_to_gsbase_t stack2gs[] = { { 0 } };
190*c54f35caSApple OSS Distributions 
191*c54f35caSApple OSS Distributions extern int compat_mode_trampoline(far_call_t *, void *, uint64_t);
192*c54f35caSApple OSS Distributions extern void long_mode_trampoline(void);
193*c54f35caSApple OSS Distributions extern boolean_t mach_exc_server(mach_msg_header_t *InHeadP, mach_msg_header_t *OutHeadP);
194*c54f35caSApple OSS Distributions 
195*c54f35caSApple OSS Distributions extern void code_32(void);
196*c54f35caSApple OSS Distributions 
197*c54f35caSApple OSS Distributions kern_return_t catch_mach_exception_raise_state_identity(mach_port_t exception_port,
198*c54f35caSApple OSS Distributions     mach_port_t thread,
199*c54f35caSApple OSS Distributions     mach_port_t task,
200*c54f35caSApple OSS Distributions     exception_type_t exception,
201*c54f35caSApple OSS Distributions     mach_exception_data_t code,
202*c54f35caSApple OSS Distributions     mach_msg_type_number_t code_count,
203*c54f35caSApple OSS Distributions     int * flavor,
204*c54f35caSApple OSS Distributions     thread_state_t old_state,
205*c54f35caSApple OSS Distributions     mach_msg_type_number_t old_state_count,
206*c54f35caSApple OSS Distributions     thread_state_t new_state,
207*c54f35caSApple OSS Distributions     mach_msg_type_number_t * new_state_count);
208*c54f35caSApple OSS Distributions 
209*c54f35caSApple OSS Distributions kern_return_t
210*c54f35caSApple OSS Distributions catch_mach_exception_raise_state(mach_port_t exception_port,
211*c54f35caSApple OSS Distributions     exception_type_t exception,
212*c54f35caSApple OSS Distributions     const mach_exception_data_t code,
213*c54f35caSApple OSS Distributions     mach_msg_type_number_t codeCnt,
214*c54f35caSApple OSS Distributions     int *flavor,
215*c54f35caSApple OSS Distributions     const thread_state_t old_state,
216*c54f35caSApple OSS Distributions     mach_msg_type_number_t old_stateCnt,
217*c54f35caSApple OSS Distributions     thread_state_t new_state,
218*c54f35caSApple OSS Distributions     mach_msg_type_number_t *new_stateCnt);
219*c54f35caSApple OSS Distributions 
220*c54f35caSApple OSS Distributions kern_return_t
221*c54f35caSApple OSS Distributions catch_mach_exception_raise(mach_port_t exception_port,
222*c54f35caSApple OSS Distributions     mach_port_t thread,
223*c54f35caSApple OSS Distributions     mach_port_t task,
224*c54f35caSApple OSS Distributions     exception_type_t exception,
225*c54f35caSApple OSS Distributions     mach_exception_data_t code,
226*c54f35caSApple OSS Distributions     mach_msg_type_number_t codeCnt,
227*c54f35caSApple OSS Distributions     int *flavor,
228*c54f35caSApple OSS Distributions     thread_state_t old_state,
229*c54f35caSApple OSS Distributions     mach_msg_type_number_t old_stateCnt,
230*c54f35caSApple OSS Distributions     thread_state_t new_state,
231*c54f35caSApple OSS Distributions     mach_msg_type_number_t *new_stateCnt);
232*c54f35caSApple OSS Distributions 
233*c54f35caSApple OSS Distributions extern void _thread_set_tsd_base(uint64_t);
234*c54f35caSApple OSS Distributions static uint64_t stack_range_to_GSbase(uint64_t stackptr, uint64_t GSbase);
235*c54f35caSApple OSS Distributions void restore_gsbase(uint64_t stackptr);
236*c54f35caSApple OSS Distributions 
237*c54f35caSApple OSS Distributions static uint64_t
get_gsbase(void)238*c54f35caSApple OSS Distributions get_gsbase(void)
239*c54f35caSApple OSS Distributions {
240*c54f35caSApple OSS Distributions 	struct thread_identifier_info tiinfo;
241*c54f35caSApple OSS Distributions 	unsigned int info_count = THREAD_IDENTIFIER_INFO_COUNT;
242*c54f35caSApple OSS Distributions 	kern_return_t kr;
243*c54f35caSApple OSS Distributions 
244*c54f35caSApple OSS Distributions 	if ((kr = thread_info(mach_thread_self(), THREAD_IDENTIFIER_INFO,
245*c54f35caSApple OSS Distributions 	    (thread_info_t) &tiinfo, &info_count)) != KERN_SUCCESS) {
246*c54f35caSApple OSS Distributions 		fprintf(stderr, "Could not get tsd base address.  This will not end well.\n");
247*c54f35caSApple OSS Distributions 		return 0;
248*c54f35caSApple OSS Distributions 	}
249*c54f35caSApple OSS Distributions 
250*c54f35caSApple OSS Distributions 	return (uint64_t)tiinfo.thread_handle;
251*c54f35caSApple OSS Distributions }
252*c54f35caSApple OSS Distributions 
253*c54f35caSApple OSS Distributions void
restore_gsbase(uint64_t stackptr)254*c54f35caSApple OSS Distributions restore_gsbase(uint64_t stackptr)
255*c54f35caSApple OSS Distributions {
256*c54f35caSApple OSS Distributions 	/* Restore GSbase so tsd is accessible in long mode */
257*c54f35caSApple OSS Distributions 	uint64_t orig_GSbase = stack_range_to_GSbase(stackptr, 0);
258*c54f35caSApple OSS Distributions 
259*c54f35caSApple OSS Distributions 	assert(orig_GSbase != 0);
260*c54f35caSApple OSS Distributions 	_thread_set_tsd_base(orig_GSbase);
261*c54f35caSApple OSS Distributions }
262*c54f35caSApple OSS Distributions 
263*c54f35caSApple OSS Distributions /*
264*c54f35caSApple OSS Distributions  * Though we've directed all exceptions through the catch_mach_exception_raise_state_identity
265*c54f35caSApple OSS Distributions  * entry point, we still must provide these two other entry points, otherwise a linker error
266*c54f35caSApple OSS Distributions  * will occur.
267*c54f35caSApple OSS Distributions  */
268*c54f35caSApple OSS Distributions kern_return_t
catch_mach_exception_raise(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t codeCnt,int * flavor,thread_state_t old_state,mach_msg_type_number_t old_stateCnt,thread_state_t new_state,mach_msg_type_number_t * new_stateCnt)269*c54f35caSApple OSS Distributions catch_mach_exception_raise(mach_port_t exception_port,
270*c54f35caSApple OSS Distributions     mach_port_t thread,
271*c54f35caSApple OSS Distributions     mach_port_t task,
272*c54f35caSApple OSS Distributions     exception_type_t exception,
273*c54f35caSApple OSS Distributions     mach_exception_data_t code,
274*c54f35caSApple OSS Distributions     mach_msg_type_number_t codeCnt,
275*c54f35caSApple OSS Distributions     int *flavor,
276*c54f35caSApple OSS Distributions     thread_state_t old_state,
277*c54f35caSApple OSS Distributions     mach_msg_type_number_t old_stateCnt,
278*c54f35caSApple OSS Distributions     thread_state_t new_state,
279*c54f35caSApple OSS Distributions     mach_msg_type_number_t *new_stateCnt)
280*c54f35caSApple OSS Distributions {
281*c54f35caSApple OSS Distributions #pragma unused(exception_port, thread, task, exception, code, codeCnt, flavor, old_state, old_stateCnt, new_state, new_stateCnt)
282*c54f35caSApple OSS Distributions 	fprintf(stderr, "Unexpected exception handler called: %s\n", __func__);
283*c54f35caSApple OSS Distributions 	return KERN_FAILURE;
284*c54f35caSApple OSS Distributions }
285*c54f35caSApple OSS Distributions 
286*c54f35caSApple OSS Distributions kern_return_t
catch_mach_exception_raise_state(mach_port_t exception_port,exception_type_t exception,const mach_exception_data_t code,mach_msg_type_number_t codeCnt,int * flavor,const thread_state_t old_state,mach_msg_type_number_t old_stateCnt,thread_state_t new_state,mach_msg_type_number_t * new_stateCnt)287*c54f35caSApple OSS Distributions catch_mach_exception_raise_state(mach_port_t exception_port,
288*c54f35caSApple OSS Distributions     exception_type_t exception,
289*c54f35caSApple OSS Distributions     const mach_exception_data_t code,
290*c54f35caSApple OSS Distributions     mach_msg_type_number_t codeCnt,
291*c54f35caSApple OSS Distributions     int *flavor,
292*c54f35caSApple OSS Distributions     const thread_state_t old_state,
293*c54f35caSApple OSS Distributions     mach_msg_type_number_t old_stateCnt,
294*c54f35caSApple OSS Distributions     thread_state_t new_state,
295*c54f35caSApple OSS Distributions     mach_msg_type_number_t *new_stateCnt)
296*c54f35caSApple OSS Distributions {
297*c54f35caSApple OSS Distributions #pragma unused(exception_port, exception, code, codeCnt, flavor, old_state, old_stateCnt, new_state, new_stateCnt)
298*c54f35caSApple OSS Distributions 	fprintf(stderr, "Unexpected exception handler called: %s\n", __func__);
299*c54f35caSApple OSS Distributions 	return KERN_FAILURE;
300*c54f35caSApple OSS Distributions }
301*c54f35caSApple OSS Distributions 
302*c54f35caSApple OSS Distributions static void
handle_arithmetic_exception(_STRUCT_X86_THREAD_FULL_STATE64 * xtfs64,uint64_t * ip_skip_countp)303*c54f35caSApple OSS Distributions handle_arithmetic_exception(_STRUCT_X86_THREAD_FULL_STATE64 *xtfs64, uint64_t *ip_skip_countp)
304*c54f35caSApple OSS Distributions {
305*c54f35caSApple OSS Distributions 	fprintf(stderr, "Caught divide-error exception\n");
306*c54f35caSApple OSS Distributions 	fprintf(stderr, "cs=0x%x rip=0x%x gs=0x%x ss=0x%x rsp=0x%llx\n",
307*c54f35caSApple OSS Distributions 	    (unsigned)xtfs64->__ss64.__cs,
308*c54f35caSApple OSS Distributions 	    (unsigned)xtfs64->__ss64.__rip, (unsigned)xtfs64->__ss64.__gs,
309*c54f35caSApple OSS Distributions 	    (unsigned)xtfs64->__ss, xtfs64->__ss64.__rsp);
310*c54f35caSApple OSS Distributions 	*ip_skip_countp = 2;
311*c54f35caSApple OSS Distributions }
312*c54f35caSApple OSS Distributions 
313*c54f35caSApple OSS Distributions static void
handle_badinsn_exception(_STRUCT_X86_THREAD_FULL_STATE64 * xtfs64,uint64_t __unused * ip_skip_countp)314*c54f35caSApple OSS Distributions handle_badinsn_exception(_STRUCT_X86_THREAD_FULL_STATE64 *xtfs64, uint64_t __unused *ip_skip_countp)
315*c54f35caSApple OSS Distributions {
316*c54f35caSApple OSS Distributions 	extern void first_invalid_opcode(void);
317*c54f35caSApple OSS Distributions 	extern void last_invalid_opcode(void);
318*c54f35caSApple OSS Distributions 
319*c54f35caSApple OSS Distributions 	uint64_t start_addr = ((uintptr_t)first_invalid_opcode - (uintptr_t)code_32);
320*c54f35caSApple OSS Distributions 	uint64_t end_addr = ((uintptr_t)last_invalid_opcode - (uintptr_t)code_32);
321*c54f35caSApple OSS Distributions 
322*c54f35caSApple OSS Distributions 	fprintf(stderr, "Caught invalid opcode exception\n");
323*c54f35caSApple OSS Distributions 	fprintf(stderr, "cs=%x rip=%x gs=%x ss=0x%x rsp=0x%llx | handling between 0x%llx and 0x%llx\n",
324*c54f35caSApple OSS Distributions 	    (unsigned)xtfs64->__ss64.__cs,
325*c54f35caSApple OSS Distributions 	    (unsigned)xtfs64->__ss64.__rip, (unsigned)xtfs64->__ss64.__gs,
326*c54f35caSApple OSS Distributions 	    (unsigned)xtfs64->__ss, xtfs64->__ss64.__rsp,
327*c54f35caSApple OSS Distributions 	    start_addr, end_addr);
328*c54f35caSApple OSS Distributions 
329*c54f35caSApple OSS Distributions 	/*
330*c54f35caSApple OSS Distributions 	 * We expect to handle 4 invalid opcode exceptions:
331*c54f35caSApple OSS Distributions 	 * (1) sysenter
332*c54f35caSApple OSS Distributions 	 * (2) int $0x80
333*c54f35caSApple OSS Distributions 	 * (3) int $0x81
334*c54f35caSApple OSS Distributions 	 * (4) int $0x82
335*c54f35caSApple OSS Distributions 	 * (Note that due to the way the invalid opcode indication was implemented,
336*c54f35caSApple OSS Distributions 	 * %rip is already set to the next instruction.)
337*c54f35caSApple OSS Distributions 	 */
338*c54f35caSApple OSS Distributions 	if (xtfs64->__ss64.__rip >= start_addr && xtfs64->__ss64.__rip <= end_addr) {
339*c54f35caSApple OSS Distributions 		/*
340*c54f35caSApple OSS Distributions 		 * On return from the failed sysenter, %cs is changed to the
341*c54f35caSApple OSS Distributions 		 * sysenter code selector and %ss is set to 0x23, so switch them
342*c54f35caSApple OSS Distributions 		 * back to sane values.
343*c54f35caSApple OSS Distributions 		 */
344*c54f35caSApple OSS Distributions 		if ((unsigned)xtfs64->__ss64.__cs == SYSENTER_SELECTOR) {
345*c54f35caSApple OSS Distributions 			xtfs64->__ss64.__cs = COMPAT_MODE_CS_SELECTOR;
346*c54f35caSApple OSS Distributions 			xtfs64->__ss = 0x23; /* XXX */
347*c54f35caSApple OSS Distributions 		}
348*c54f35caSApple OSS Distributions 	}
349*c54f35caSApple OSS Distributions }
350*c54f35caSApple OSS Distributions 
351*c54f35caSApple OSS Distributions kern_return_t
catch_mach_exception_raise_state_identity(mach_port_t exception_port,mach_port_t thread,mach_port_t task,exception_type_t exception,mach_exception_data_t code,mach_msg_type_number_t codeCnt,int * flavor,thread_state_t old_state,mach_msg_type_number_t old_stateCnt,thread_state_t new_state,mach_msg_type_number_t * new_stateCnt)352*c54f35caSApple OSS Distributions catch_mach_exception_raise_state_identity(mach_port_t exception_port,
353*c54f35caSApple OSS Distributions     mach_port_t thread,
354*c54f35caSApple OSS Distributions     mach_port_t task,
355*c54f35caSApple OSS Distributions     exception_type_t exception,
356*c54f35caSApple OSS Distributions     mach_exception_data_t code,
357*c54f35caSApple OSS Distributions     mach_msg_type_number_t codeCnt,
358*c54f35caSApple OSS Distributions     int * flavor,
359*c54f35caSApple OSS Distributions     thread_state_t old_state,
360*c54f35caSApple OSS Distributions     mach_msg_type_number_t old_stateCnt,
361*c54f35caSApple OSS Distributions     thread_state_t new_state,
362*c54f35caSApple OSS Distributions     mach_msg_type_number_t * new_stateCnt)
363*c54f35caSApple OSS Distributions {
364*c54f35caSApple OSS Distributions #pragma unused(exception_port, thread, task)
365*c54f35caSApple OSS Distributions 
366*c54f35caSApple OSS Distributions 	_STRUCT_X86_THREAD_FULL_STATE64 *xtfs64 = (_STRUCT_X86_THREAD_FULL_STATE64 *)(void *)old_state;
367*c54f35caSApple OSS Distributions 	_STRUCT_X86_THREAD_FULL_STATE64 *new_xtfs64 = (_STRUCT_X86_THREAD_FULL_STATE64 *)(void *)new_state;
368*c54f35caSApple OSS Distributions 	uint64_t rip_skip_count = 0;
369*c54f35caSApple OSS Distributions 
370*c54f35caSApple OSS Distributions 	/*
371*c54f35caSApple OSS Distributions 	 * Check the exception code and thread state.
372*c54f35caSApple OSS Distributions 	 * If we were executing 32-bit code (or 64-bit code on behalf of
373*c54f35caSApple OSS Distributions 	 * 32-bit code), we could update the thread state to effectively longjmp
374*c54f35caSApple OSS Distributions 	 * back to a safe location where the victim thread can recover.
375*c54f35caSApple OSS Distributions 	 * Then again, we could return KERN_NOT_SUPPORTED and allow the process
376*c54f35caSApple OSS Distributions 	 * to be nuked.
377*c54f35caSApple OSS Distributions 	 */
378*c54f35caSApple OSS Distributions 
379*c54f35caSApple OSS Distributions 	switch (exception) {
380*c54f35caSApple OSS Distributions 	case EXC_ARITHMETIC:
381*c54f35caSApple OSS Distributions 		if (codeCnt >= 1 && code[0] == EXC_I386_DIV) {
382*c54f35caSApple OSS Distributions 			handle_arithmetic_exception(xtfs64, &rip_skip_count);
383*c54f35caSApple OSS Distributions 		}
384*c54f35caSApple OSS Distributions 		break;
385*c54f35caSApple OSS Distributions 
386*c54f35caSApple OSS Distributions 	case EXC_BAD_INSTRUCTION:
387*c54f35caSApple OSS Distributions 	{
388*c54f35caSApple OSS Distributions 		if (codeCnt >= 1 && code[0] == EXC_I386_INVOP) {
389*c54f35caSApple OSS Distributions 			handle_badinsn_exception(xtfs64, &rip_skip_count);
390*c54f35caSApple OSS Distributions 		}
391*c54f35caSApple OSS Distributions 		break;
392*c54f35caSApple OSS Distributions 	}
393*c54f35caSApple OSS Distributions 
394*c54f35caSApple OSS Distributions 	default:
395*c54f35caSApple OSS Distributions 		fprintf(stderr, "Unsupported catch_mach_exception_raise_state_identity: code 0x%llx sub 0x%llx\n",
396*c54f35caSApple OSS Distributions 		    code[0], codeCnt > 1 ? code[1] : 0LL);
397*c54f35caSApple OSS Distributions 		fprintf(stderr, "flavor=%d %%cs=0x%x %%rip=0x%llx\n", *flavor, (unsigned)xtfs64->__ss64.__cs,
398*c54f35caSApple OSS Distributions 		    xtfs64->__ss64.__rip);
399*c54f35caSApple OSS Distributions 	}
400*c54f35caSApple OSS Distributions 
401*c54f35caSApple OSS Distributions 	/*
402*c54f35caSApple OSS Distributions 	 * If this exception happened in compatibility mode,
403*c54f35caSApple OSS Distributions 	 * assume it was the intentional division-by-zero and set the
404*c54f35caSApple OSS Distributions 	 * new state's cs register to just after the div instruction
405*c54f35caSApple OSS Distributions 	 * to enable the thread to resume.
406*c54f35caSApple OSS Distributions 	 */
407*c54f35caSApple OSS Distributions 	if ((unsigned)xtfs64->__ss64.__cs == COMPAT_MODE_CS_SELECTOR) {
408*c54f35caSApple OSS Distributions 		*new_stateCnt = old_stateCnt;
409*c54f35caSApple OSS Distributions 		*new_xtfs64 = *xtfs64;
410*c54f35caSApple OSS Distributions 		new_xtfs64->__ss64.__rip += rip_skip_count;
411*c54f35caSApple OSS Distributions 		fprintf(stderr, "new cs=0x%x rip=0x%llx\n", (unsigned)new_xtfs64->__ss64.__cs,
412*c54f35caSApple OSS Distributions 		    new_xtfs64->__ss64.__rip);
413*c54f35caSApple OSS Distributions 		return KERN_SUCCESS;
414*c54f35caSApple OSS Distributions 	} else {
415*c54f35caSApple OSS Distributions 		return KERN_NOT_SUPPORTED;
416*c54f35caSApple OSS Distributions 	}
417*c54f35caSApple OSS Distributions }
418*c54f35caSApple OSS Distributions 
419*c54f35caSApple OSS Distributions static void *
handle_exceptions(void * arg)420*c54f35caSApple OSS Distributions handle_exceptions(void *arg)
421*c54f35caSApple OSS Distributions {
422*c54f35caSApple OSS Distributions 	mach_port_t ePort = (mach_port_t)arg;
423*c54f35caSApple OSS Distributions 	kern_return_t kret;
424*c54f35caSApple OSS Distributions 
425*c54f35caSApple OSS Distributions 	kret = mach_msg_server(mach_exc_server, MACH_MSG_SIZE_RELIABLE, ePort, 0);
426*c54f35caSApple OSS Distributions 	if (kret != KERN_SUCCESS) {
427*c54f35caSApple OSS Distributions 		fprintf(stderr, "mach_msg_server: %s (%d)", mach_error_string(kret), kret);
428*c54f35caSApple OSS Distributions 	}
429*c54f35caSApple OSS Distributions 
430*c54f35caSApple OSS Distributions 	return NULL;
431*c54f35caSApple OSS Distributions }
432*c54f35caSApple OSS Distributions 
433*c54f35caSApple OSS Distributions static void
init_task_exception_server(void)434*c54f35caSApple OSS Distributions init_task_exception_server(void)
435*c54f35caSApple OSS Distributions {
436*c54f35caSApple OSS Distributions 	kern_return_t kr;
437*c54f35caSApple OSS Distributions 	task_t me = mach_task_self();
438*c54f35caSApple OSS Distributions 	pthread_t handler_thread;
439*c54f35caSApple OSS Distributions 	pthread_attr_t  attr;
440*c54f35caSApple OSS Distributions 	mach_port_t ePort;
441*c54f35caSApple OSS Distributions 
442*c54f35caSApple OSS Distributions 	kr = mach_port_allocate(me, MACH_PORT_RIGHT_RECEIVE, &ePort);
443*c54f35caSApple OSS Distributions 	if (kr != KERN_SUCCESS) {
444*c54f35caSApple OSS Distributions 		fprintf(stderr, "allocate receive right: %d\n", kr);
445*c54f35caSApple OSS Distributions 		return;
446*c54f35caSApple OSS Distributions 	}
447*c54f35caSApple OSS Distributions 
448*c54f35caSApple OSS Distributions 	kr = mach_port_insert_right(me, ePort, ePort, MACH_MSG_TYPE_MAKE_SEND);
449*c54f35caSApple OSS Distributions 	if (kr != KERN_SUCCESS) {
450*c54f35caSApple OSS Distributions 		fprintf(stderr, "insert right into port=[%d]: %d\n", ePort, kr);
451*c54f35caSApple OSS Distributions 		return;
452*c54f35caSApple OSS Distributions 	}
453*c54f35caSApple OSS Distributions 
454*c54f35caSApple OSS Distributions 	kr = task_set_exception_ports(me, EXC_MASK_BAD_INSTRUCTION | EXC_MASK_ARITHMETIC, ePort,
455*c54f35caSApple OSS Distributions 	    (exception_behavior_t)(EXCEPTION_STATE_IDENTITY | MACH_EXCEPTION_CODES), x86_THREAD_FULL_STATE64);
456*c54f35caSApple OSS Distributions 	if (kr != KERN_SUCCESS) {
457*c54f35caSApple OSS Distributions 		fprintf(stderr, "abort: error setting task exception ports on task=[%d], handler=[%d]: %d\n", me, ePort, kr);
458*c54f35caSApple OSS Distributions 		exit(1);
459*c54f35caSApple OSS Distributions 	}
460*c54f35caSApple OSS Distributions 
461*c54f35caSApple OSS Distributions 	pthread_attr_init(&attr);
462*c54f35caSApple OSS Distributions 	pthread_attr_setdetachstate(&attr, PTHREAD_CREATE_DETACHED);
463*c54f35caSApple OSS Distributions 
464*c54f35caSApple OSS Distributions 	if (pthread_create(&handler_thread, &attr, handle_exceptions, (void *)(uintptr_t)ePort) != 0) {
465*c54f35caSApple OSS Distributions 		perror("pthread create error");
466*c54f35caSApple OSS Distributions 		return;
467*c54f35caSApple OSS Distributions 	}
468*c54f35caSApple OSS Distributions 
469*c54f35caSApple OSS Distributions 	pthread_attr_destroy(&attr);
470*c54f35caSApple OSS Distributions }
471*c54f35caSApple OSS Distributions 
472*c54f35caSApple OSS Distributions static union ldt_entry *descs = 0;
473*c54f35caSApple OSS Distributions static uint64_t idx;
474*c54f35caSApple OSS Distributions static int saw_ud2 = 0;
475*c54f35caSApple OSS Distributions static boolean_t ENV_set_ldt_in_sighandler = FALSE;
476*c54f35caSApple OSS Distributions 
477*c54f35caSApple OSS Distributions static void
signal_handler(int signo,siginfo_t * sinfop,void * ucontext)478*c54f35caSApple OSS Distributions signal_handler(int signo, siginfo_t *sinfop, void *ucontext)
479*c54f35caSApple OSS Distributions {
480*c54f35caSApple OSS Distributions 	uint64_t rip_skip_count = 0;
481*c54f35caSApple OSS Distributions 	ucontext_t *uctxp = (ucontext_t *)ucontext;
482*c54f35caSApple OSS Distributions 	union {
483*c54f35caSApple OSS Distributions 		_STRUCT_MCONTEXT_AVX512_64 *avx512_basep;
484*c54f35caSApple OSS Distributions 		_STRUCT_MCONTEXT_AVX512_64_FULL *avx512_fullp;
485*c54f35caSApple OSS Distributions 		_STRUCT_MCONTEXT_AVX64 *avx64_basep;
486*c54f35caSApple OSS Distributions 		_STRUCT_MCONTEXT_AVX64_FULL *avx64_fullp;
487*c54f35caSApple OSS Distributions 		_STRUCT_MCONTEXT64 *fp_basep;
488*c54f35caSApple OSS Distributions 		_STRUCT_MCONTEXT64_FULL *fp_fullp;
489*c54f35caSApple OSS Distributions 	} mctx;
490*c54f35caSApple OSS Distributions 
491*c54f35caSApple OSS Distributions 	mctx.fp_fullp = (_STRUCT_MCONTEXT64_FULL *)uctxp->uc_mcontext;
492*c54f35caSApple OSS Distributions 
493*c54f35caSApple OSS Distributions 	/*
494*c54f35caSApple OSS Distributions 	 * Note that GSbase must be restored before calling into any frameworks
495*c54f35caSApple OSS Distributions 	 * that might access anything %gs-relative (e.g. TSD) if the signal
496*c54f35caSApple OSS Distributions 	 * handler was triggered while the thread was running with a non-default
497*c54f35caSApple OSS Distributions 	 * (system-established) GSbase.
498*c54f35caSApple OSS Distributions 	 */
499*c54f35caSApple OSS Distributions 
500*c54f35caSApple OSS Distributions 	if ((signo != SIGFPE && signo != SIGILL) || sinfop->si_signo != signo) {
501*c54f35caSApple OSS Distributions #ifndef STANDALONE
502*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Unexpected signal %d\n", signo);
503*c54f35caSApple OSS Distributions #else
504*c54f35caSApple OSS Distributions 		restore_gsbase(mctx.fp_fullp->__ss.__ss64.__rsp);
505*c54f35caSApple OSS Distributions 		fprintf(stderr, "Not handling signal %d\n", signo);
506*c54f35caSApple OSS Distributions 		abort();
507*c54f35caSApple OSS Distributions #endif
508*c54f35caSApple OSS Distributions 	}
509*c54f35caSApple OSS Distributions 
510*c54f35caSApple OSS Distributions 	if (uctxp->uc_mcsize == sizeof(_STRUCT_MCONTEXT_AVX512_64) ||
511*c54f35caSApple OSS Distributions 	    uctxp->uc_mcsize == sizeof(_STRUCT_MCONTEXT_AVX64) ||
512*c54f35caSApple OSS Distributions 	    uctxp->uc_mcsize == sizeof(_STRUCT_MCONTEXT64)) {
513*c54f35caSApple OSS Distributions 		_STRUCT_X86_THREAD_STATE64 *ss64 = &mctx.fp_basep->__ss;
514*c54f35caSApple OSS Distributions 
515*c54f35caSApple OSS Distributions 		/*
516*c54f35caSApple OSS Distributions 		 * The following block is an illustration of what NOT to do.
517*c54f35caSApple OSS Distributions 		 * Configuring an LDT for the first time in a signal handler
518*c54f35caSApple OSS Distributions 		 * will likely cause the process to crash.
519*c54f35caSApple OSS Distributions 		 */
520*c54f35caSApple OSS Distributions 		if (ENV_set_ldt_in_sighandler == TRUE && !saw_ud2) {
521*c54f35caSApple OSS Distributions 			/* Set the LDT: */
522*c54f35caSApple OSS Distributions 			int cnt = i386_set_ldt((int)idx, &descs[idx], 1);
523*c54f35caSApple OSS Distributions 			if (cnt != (int)idx) {
524*c54f35caSApple OSS Distributions #ifdef DEBUG
525*c54f35caSApple OSS Distributions 				fprintf(stderr, "i386_set_ldt unexpectedly returned %d (errno = %s)\n", cnt, strerror(errno));
526*c54f35caSApple OSS Distributions #endif
527*c54f35caSApple OSS Distributions #ifndef STANDALONE
528*c54f35caSApple OSS Distributions 				T_LOG("i386_set_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
529*c54f35caSApple OSS Distributions 				T_ASSERT_FAIL("i386_set_ldt failure");
530*c54f35caSApple OSS Distributions #else
531*c54f35caSApple OSS Distributions 				exit(1);
532*c54f35caSApple OSS Distributions #endif
533*c54f35caSApple OSS Distributions 			}
534*c54f35caSApple OSS Distributions #ifdef DEBUG
535*c54f35caSApple OSS Distributions 			printf("i386_set_ldt returned %d\n", cnt);
536*c54f35caSApple OSS Distributions #endif
537*c54f35caSApple OSS Distributions 			ss64->__rip += 2;       /* ud2 is 2 bytes */
538*c54f35caSApple OSS Distributions 
539*c54f35caSApple OSS Distributions 			saw_ud2 = 1;
540*c54f35caSApple OSS Distributions 
541*c54f35caSApple OSS Distributions 			/*
542*c54f35caSApple OSS Distributions 			 * When we return here, the sigreturn processing code will try to copy a FULL
543*c54f35caSApple OSS Distributions 			 * thread context from the signal stack, which will likely cause the resumed
544*c54f35caSApple OSS Distributions 			 * thread to fault and be terminated.
545*c54f35caSApple OSS Distributions 			 */
546*c54f35caSApple OSS Distributions 			return;
547*c54f35caSApple OSS Distributions 		}
548*c54f35caSApple OSS Distributions 
549*c54f35caSApple OSS Distributions 		restore_gsbase(ss64->__rsp);
550*c54f35caSApple OSS Distributions 
551*c54f35caSApple OSS Distributions 		/*
552*c54f35caSApple OSS Distributions 		 * If we're in this block, either we are dispatching a signal received
553*c54f35caSApple OSS Distributions 		 * before we installed a custom LDT or we are on a kernel without
554*c54f35caSApple OSS Distributions 		 * BSD-signalling-sending-full-thread-state support.  It's likely the latter case.
555*c54f35caSApple OSS Distributions 		 */
556*c54f35caSApple OSS Distributions #ifndef STANDALONE
557*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("This system doesn't support BSD signals with full thread state.");
558*c54f35caSApple OSS Distributions #else
559*c54f35caSApple OSS Distributions 		fprintf(stderr, "This system doesn't support BSD signals with full thread state.  Aborting.\n");
560*c54f35caSApple OSS Distributions 		abort();
561*c54f35caSApple OSS Distributions #endif
562*c54f35caSApple OSS Distributions 	} else if (uctxp->uc_mcsize == sizeof(_STRUCT_MCONTEXT_AVX512_64_FULL) ||
563*c54f35caSApple OSS Distributions 	    uctxp->uc_mcsize == sizeof(_STRUCT_MCONTEXT_AVX64_FULL) ||
564*c54f35caSApple OSS Distributions 	    uctxp->uc_mcsize == sizeof(_STRUCT_MCONTEXT64_FULL)) {
565*c54f35caSApple OSS Distributions 		_STRUCT_X86_THREAD_FULL_STATE64 *ss64 = &mctx.fp_fullp->__ss;
566*c54f35caSApple OSS Distributions 
567*c54f35caSApple OSS Distributions 		/*
568*c54f35caSApple OSS Distributions 		 * Since we're handing this signal on the same thread, we may need to
569*c54f35caSApple OSS Distributions 		 * restore GSbase.
570*c54f35caSApple OSS Distributions 		 */
571*c54f35caSApple OSS Distributions 		uint64_t orig_gsbase = stack_range_to_GSbase(ss64->__ss64.__rsp, 0);
572*c54f35caSApple OSS Distributions 		if (orig_gsbase != 0 && orig_gsbase != ss64->__gsbase) {
573*c54f35caSApple OSS Distributions 			restore_gsbase(ss64->__ss64.__rsp);
574*c54f35caSApple OSS Distributions 		}
575*c54f35caSApple OSS Distributions 
576*c54f35caSApple OSS Distributions 		if (signo == SIGFPE) {
577*c54f35caSApple OSS Distributions 			handle_arithmetic_exception(ss64, &rip_skip_count);
578*c54f35caSApple OSS Distributions 		} else if (signo == SIGILL) {
579*c54f35caSApple OSS Distributions 			handle_badinsn_exception(ss64, &rip_skip_count);
580*c54f35caSApple OSS Distributions 		}
581*c54f35caSApple OSS Distributions 
582*c54f35caSApple OSS Distributions 		/*
583*c54f35caSApple OSS Distributions 		 * If this exception happened in compatibility mode,
584*c54f35caSApple OSS Distributions 		 * assume it was the intentional division-by-zero and set the
585*c54f35caSApple OSS Distributions 		 * new state's cs register to just after the div instruction
586*c54f35caSApple OSS Distributions 		 * to enable the thread to resume.
587*c54f35caSApple OSS Distributions 		 */
588*c54f35caSApple OSS Distributions 		if ((unsigned)ss64->__ss64.__cs == COMPAT_MODE_CS_SELECTOR) {
589*c54f35caSApple OSS Distributions 			ss64->__ss64.__rip += rip_skip_count;
590*c54f35caSApple OSS Distributions 			fprintf(stderr, "new cs=0x%x rip=0x%llx\n", (unsigned)ss64->__ss64.__cs,
591*c54f35caSApple OSS Distributions 			    ss64->__ss64.__rip);
592*c54f35caSApple OSS Distributions 		}
593*c54f35caSApple OSS Distributions 	} else {
594*c54f35caSApple OSS Distributions 		_STRUCT_X86_THREAD_STATE64 *ss64 = &mctx.fp_basep->__ss;
595*c54f35caSApple OSS Distributions 
596*c54f35caSApple OSS Distributions 		restore_gsbase(ss64->__rsp);
597*c54f35caSApple OSS Distributions #ifndef STANDALONE
598*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Unknown mcontext size %lu: Aborting.", uctxp->uc_mcsize);
599*c54f35caSApple OSS Distributions #else
600*c54f35caSApple OSS Distributions 		fprintf(stderr, "Unknown mcontext size %lu: Aborting.\n", uctxp->uc_mcsize);
601*c54f35caSApple OSS Distributions 		abort();
602*c54f35caSApple OSS Distributions #endif
603*c54f35caSApple OSS Distributions 	}
604*c54f35caSApple OSS Distributions }
605*c54f35caSApple OSS Distributions 
606*c54f35caSApple OSS Distributions static void
setup_signal_handling(void)607*c54f35caSApple OSS Distributions setup_signal_handling(void)
608*c54f35caSApple OSS Distributions {
609*c54f35caSApple OSS Distributions 	int rv;
610*c54f35caSApple OSS Distributions 
611*c54f35caSApple OSS Distributions 	struct sigaction sa = {
612*c54f35caSApple OSS Distributions 		.__sigaction_u = { .__sa_sigaction = signal_handler },
613*c54f35caSApple OSS Distributions 		.sa_flags = SA_SIGINFO
614*c54f35caSApple OSS Distributions 	};
615*c54f35caSApple OSS Distributions 
616*c54f35caSApple OSS Distributions 	sigfillset(&sa.sa_mask);
617*c54f35caSApple OSS Distributions 
618*c54f35caSApple OSS Distributions 	rv = sigaction(SIGFPE, &sa, NULL);
619*c54f35caSApple OSS Distributions 	if (rv != 0) {
620*c54f35caSApple OSS Distributions #ifndef STANDALONE
621*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Failed to configure SIGFPE signal handler\n");
622*c54f35caSApple OSS Distributions #else
623*c54f35caSApple OSS Distributions 		fprintf(stderr, "Failed to configure SIGFPE signal handler\n");
624*c54f35caSApple OSS Distributions 		abort();
625*c54f35caSApple OSS Distributions #endif
626*c54f35caSApple OSS Distributions 	}
627*c54f35caSApple OSS Distributions 
628*c54f35caSApple OSS Distributions 	rv = sigaction(SIGILL, &sa, NULL);
629*c54f35caSApple OSS Distributions 	if (rv != 0) {
630*c54f35caSApple OSS Distributions #ifndef STANDALONE
631*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Failed to configure SIGILL signal handler\n");
632*c54f35caSApple OSS Distributions #else
633*c54f35caSApple OSS Distributions 		fprintf(stderr, "Failed to configure SIGILL signal handler\n");
634*c54f35caSApple OSS Distributions 		abort();
635*c54f35caSApple OSS Distributions #endif
636*c54f35caSApple OSS Distributions 	}
637*c54f35caSApple OSS Distributions }
638*c54f35caSApple OSS Distributions 
639*c54f35caSApple OSS Distributions static void
teardown_signal_handling(void)640*c54f35caSApple OSS Distributions teardown_signal_handling(void)
641*c54f35caSApple OSS Distributions {
642*c54f35caSApple OSS Distributions 	if (signal(SIGFPE, SIG_DFL) == SIG_ERR) {
643*c54f35caSApple OSS Distributions #ifndef STANDALONE
644*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Error resetting SIGFPE signal disposition\n");
645*c54f35caSApple OSS Distributions #else
646*c54f35caSApple OSS Distributions 		fprintf(stderr, "Error resetting SIGFPE signal disposition\n");
647*c54f35caSApple OSS Distributions 		abort();
648*c54f35caSApple OSS Distributions #endif
649*c54f35caSApple OSS Distributions 	}
650*c54f35caSApple OSS Distributions 
651*c54f35caSApple OSS Distributions 	if (signal(SIGILL, SIG_DFL) == SIG_ERR) {
652*c54f35caSApple OSS Distributions #ifndef STANDALONE
653*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Error resetting SIGILL signal disposition\n");
654*c54f35caSApple OSS Distributions #else
655*c54f35caSApple OSS Distributions 		fprintf(stderr, "Error resetting SIGILL signal disposition\n");
656*c54f35caSApple OSS Distributions 		abort();
657*c54f35caSApple OSS Distributions #endif
658*c54f35caSApple OSS Distributions 	}
659*c54f35caSApple OSS Distributions }
660*c54f35caSApple OSS Distributions 
661*c54f35caSApple OSS Distributions #ifdef DEBUG
662*c54f35caSApple OSS Distributions static void
dump_desc(union ldt_entry * entp)663*c54f35caSApple OSS Distributions dump_desc(union ldt_entry *entp)
664*c54f35caSApple OSS Distributions {
665*c54f35caSApple OSS Distributions 	printf("base %p lim %p type 0x%x dpl %x present %x opsz %x granular %x\n",
666*c54f35caSApple OSS Distributions 	    (void *)(uintptr_t)(entp->code.base00 + (entp->code.base16 << 16) + (entp->code.base24 << 24)),
667*c54f35caSApple OSS Distributions 	    (void *)(uintptr_t)(entp->code.limit00 + (entp->code.limit16 << 16)),
668*c54f35caSApple OSS Distributions 	    entp->code.type,
669*c54f35caSApple OSS Distributions 	    entp->code.dpl,
670*c54f35caSApple OSS Distributions 	    entp->code.present,
671*c54f35caSApple OSS Distributions 	    entp->code.opsz,
672*c54f35caSApple OSS Distributions 	    entp->code.granular);
673*c54f35caSApple OSS Distributions }
674*c54f35caSApple OSS Distributions #endif
675*c54f35caSApple OSS Distributions 
676*c54f35caSApple OSS Distributions static int
map_lowmem_stack(void ** lowmemstk)677*c54f35caSApple OSS Distributions map_lowmem_stack(void **lowmemstk)
678*c54f35caSApple OSS Distributions {
679*c54f35caSApple OSS Distributions 	void *addr;
680*c54f35caSApple OSS Distributions 	int err;
681*c54f35caSApple OSS Distributions 
682*c54f35caSApple OSS Distributions 	if ((addr = mmap(0, FIXED_STACK_SIZE + PAGE_SIZE, PROT_READ | PROT_WRITE,
683*c54f35caSApple OSS Distributions 	    MAP_32BIT | MAP_PRIVATE | MAP_ANON, -1, 0)) == MAP_FAILED) {
684*c54f35caSApple OSS Distributions 		return errno;
685*c54f35caSApple OSS Distributions 	}
686*c54f35caSApple OSS Distributions 
687*c54f35caSApple OSS Distributions 	if ((uintptr_t)addr > 0xFFFFF000ULL) {
688*c54f35caSApple OSS Distributions 		/* Error: This kernel does not support MAP_32BIT or there's a bug. */
689*c54f35caSApple OSS Distributions #ifndef STANDALONE
690*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("%s: failed to map a 32-bit-accessible stack", __func__);
691*c54f35caSApple OSS Distributions #else
692*c54f35caSApple OSS Distributions 		fprintf(stderr, "This kernel returned a virtual address > 4G (%p) despite MAP_32BIT.  Aborting.\n", addr);
693*c54f35caSApple OSS Distributions 		exit(1);
694*c54f35caSApple OSS Distributions #endif
695*c54f35caSApple OSS Distributions 	}
696*c54f35caSApple OSS Distributions 
697*c54f35caSApple OSS Distributions 	/* Enforce one page of redzone at the bottom of the stack */
698*c54f35caSApple OSS Distributions 	if (mprotect(addr, PAGE_SIZE, PROT_NONE) < 0) {
699*c54f35caSApple OSS Distributions 		err = errno;
700*c54f35caSApple OSS Distributions 		(void) munmap(addr, FIXED_STACK_SIZE + PAGE_SIZE);
701*c54f35caSApple OSS Distributions 		return err;
702*c54f35caSApple OSS Distributions 	}
703*c54f35caSApple OSS Distributions 
704*c54f35caSApple OSS Distributions 	if (lowmemstk) {
705*c54f35caSApple OSS Distributions 		stack2gs[0].stack_base = (uintptr_t)addr + PAGE_SIZE;
706*c54f35caSApple OSS Distributions 		stack2gs[0].stack_limit = stack2gs[0].stack_base + FIXED_STACK_SIZE;
707*c54f35caSApple OSS Distributions 		*lowmemstk = (void *)((uintptr_t)addr + PAGE_SIZE);
708*c54f35caSApple OSS Distributions 	}
709*c54f35caSApple OSS Distributions 
710*c54f35caSApple OSS Distributions 	return 0;
711*c54f35caSApple OSS Distributions }
712*c54f35caSApple OSS Distributions 
713*c54f35caSApple OSS Distributions static int
map_32bit_code_impl(uint8_t * code_src,size_t code_len,void ** codeptr,size_t szlimit)714*c54f35caSApple OSS Distributions map_32bit_code_impl(uint8_t *code_src, size_t code_len, void **codeptr,
715*c54f35caSApple OSS Distributions     size_t szlimit)
716*c54f35caSApple OSS Distributions {
717*c54f35caSApple OSS Distributions 	void *addr;
718*c54f35caSApple OSS Distributions 	size_t sz = (size_t)P2ROUNDUP(code_len, (unsigned)PAGE_SIZE);
719*c54f35caSApple OSS Distributions 
720*c54f35caSApple OSS Distributions 	if (code_len > szlimit) {
721*c54f35caSApple OSS Distributions 		return E2BIG;
722*c54f35caSApple OSS Distributions 	}
723*c54f35caSApple OSS Distributions 
724*c54f35caSApple OSS Distributions #ifdef DEBUG
725*c54f35caSApple OSS Distributions 	printf("size = %lu, szlimit = %u\n", sz, (unsigned)szlimit);
726*c54f35caSApple OSS Distributions #endif
727*c54f35caSApple OSS Distributions 
728*c54f35caSApple OSS Distributions 	if ((addr = mmap(0, sz, PROT_READ | PROT_WRITE | PROT_EXEC,
729*c54f35caSApple OSS Distributions 	    MAP_32BIT | MAP_PRIVATE | MAP_ANON, -1, 0)) == MAP_FAILED) {
730*c54f35caSApple OSS Distributions 		return errno;
731*c54f35caSApple OSS Distributions 	}
732*c54f35caSApple OSS Distributions 
733*c54f35caSApple OSS Distributions 	if ((uintptr_t)addr > 0xFFFFF000ULL) {
734*c54f35caSApple OSS Distributions 		/* Error: This kernel does not support MAP_32BIT or there's a bug. */
735*c54f35caSApple OSS Distributions #ifndef STANDALONE
736*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("%s: failed to map a 32-bit-accessible trampoline", __func__);
737*c54f35caSApple OSS Distributions #else
738*c54f35caSApple OSS Distributions 		fprintf(stderr, "This kernel returned a virtual address > 4G (%p) despite MAP_32BIT.  Aborting.\n", addr);
739*c54f35caSApple OSS Distributions 		exit(1);
740*c54f35caSApple OSS Distributions #endif
741*c54f35caSApple OSS Distributions 	}
742*c54f35caSApple OSS Distributions 
743*c54f35caSApple OSS Distributions #ifdef DEBUG
744*c54f35caSApple OSS Distributions 	printf("Mapping code @%p..%p => %p..%p\n", (void *)code_src,
745*c54f35caSApple OSS Distributions 	    (void *)((uintptr_t)code_src + (unsigned)code_len),
746*c54f35caSApple OSS Distributions 	    addr, (void *)((uintptr_t)addr + (unsigned)code_len));
747*c54f35caSApple OSS Distributions #endif
748*c54f35caSApple OSS Distributions 
749*c54f35caSApple OSS Distributions 	bcopy(code_src, addr, code_len);
750*c54f35caSApple OSS Distributions 
751*c54f35caSApple OSS Distributions 	/* Fill the rest of the page with NOPs */
752*c54f35caSApple OSS Distributions 	if ((sz - code_len) > 0) {
753*c54f35caSApple OSS Distributions 		memset((void *)((uintptr_t)addr + code_len), 0x90, sz - code_len);
754*c54f35caSApple OSS Distributions 	}
755*c54f35caSApple OSS Distributions 
756*c54f35caSApple OSS Distributions 	if (codeptr) {
757*c54f35caSApple OSS Distributions 		*codeptr = addr;
758*c54f35caSApple OSS Distributions 	}
759*c54f35caSApple OSS Distributions 
760*c54f35caSApple OSS Distributions 	return 0;
761*c54f35caSApple OSS Distributions }
762*c54f35caSApple OSS Distributions 
763*c54f35caSApple OSS Distributions static int
map_32bit_trampoline(compat_tramp_t * lowmemtrampp)764*c54f35caSApple OSS Distributions map_32bit_trampoline(compat_tramp_t *lowmemtrampp)
765*c54f35caSApple OSS Distributions {
766*c54f35caSApple OSS Distributions 	extern int compat_mode_trampoline_len;
767*c54f35caSApple OSS Distributions 
768*c54f35caSApple OSS Distributions 	return map_32bit_code_impl((uint8_t *)&compat_mode_trampoline,
769*c54f35caSApple OSS Distributions 	           (size_t)compat_mode_trampoline_len, (void **)lowmemtrampp,
770*c54f35caSApple OSS Distributions 	           FIXED_TRAMP_MAXLEN);
771*c54f35caSApple OSS Distributions }
772*c54f35caSApple OSS Distributions 
773*c54f35caSApple OSS Distributions static uint64_t
stack_range_to_GSbase(uint64_t stackptr,uint64_t GSbase)774*c54f35caSApple OSS Distributions stack_range_to_GSbase(uint64_t stackptr, uint64_t GSbase)
775*c54f35caSApple OSS Distributions {
776*c54f35caSApple OSS Distributions 	unsigned long i;
777*c54f35caSApple OSS Distributions 
778*c54f35caSApple OSS Distributions 	for (i = 0; i < sizeof(stack2gs) / sizeof(stack2gs[0]); i++) {
779*c54f35caSApple OSS Distributions 		if (stackptr >= stack2gs[i].stack_base &&
780*c54f35caSApple OSS Distributions 		    stackptr < stack2gs[i].stack_limit) {
781*c54f35caSApple OSS Distributions 			if (GSbase != 0) {
782*c54f35caSApple OSS Distributions #ifdef DEBUG
783*c54f35caSApple OSS Distributions 				fprintf(stderr, "Updated gsbase for stack at 0x%llx..0x%llx to 0x%llx\n",
784*c54f35caSApple OSS Distributions 				    stack2gs[i].stack_base, stack2gs[i].stack_limit, GSbase);
785*c54f35caSApple OSS Distributions #endif
786*c54f35caSApple OSS Distributions 				stack2gs[i].GSbase = GSbase;
787*c54f35caSApple OSS Distributions 			}
788*c54f35caSApple OSS Distributions 			return stack2gs[i].GSbase;
789*c54f35caSApple OSS Distributions 		}
790*c54f35caSApple OSS Distributions 	}
791*c54f35caSApple OSS Distributions 	return 0;
792*c54f35caSApple OSS Distributions }
793*c54f35caSApple OSS Distributions 
794*c54f35caSApple OSS Distributions static uint64_t
call_compatmode(uint32_t stackaddr,uint64_t compat_arg,uint64_t callback)795*c54f35caSApple OSS Distributions call_compatmode(uint32_t stackaddr, uint64_t compat_arg, uint64_t callback)
796*c54f35caSApple OSS Distributions {
797*c54f35caSApple OSS Distributions 	uint64_t rv;
798*c54f35caSApple OSS Distributions 
799*c54f35caSApple OSS Distributions 	/*
800*c54f35caSApple OSS Distributions 	 * Depending on how this is used, this allocation may need to be
801*c54f35caSApple OSS Distributions 	 * made with an allocator that returns virtual addresses below 4G.
802*c54f35caSApple OSS Distributions 	 */
803*c54f35caSApple OSS Distributions 	custom_tsd_t *new_GSbase = malloc(PAGE_SIZE);
804*c54f35caSApple OSS Distributions 
805*c54f35caSApple OSS Distributions 	/*
806*c54f35caSApple OSS Distributions 	 * Change the GSbase (so things like printf will fail unless GSbase is
807*c54f35caSApple OSS Distributions 	 * restored)
808*c54f35caSApple OSS Distributions 	 */
809*c54f35caSApple OSS Distributions 	if (new_GSbase != NULL) {
810*c54f35caSApple OSS Distributions #ifdef DEBUG
811*c54f35caSApple OSS Distributions 		fprintf(stderr, "Setting new GS base: %p\n", (void *)new_GSbase);
812*c54f35caSApple OSS Distributions #endif
813*c54f35caSApple OSS Distributions 		new_GSbase->this_tsd_base = new_GSbase;
814*c54f35caSApple OSS Distributions 		new_GSbase->orig_tsd_base = get_gsbase();
815*c54f35caSApple OSS Distributions 		_thread_set_tsd_base((uintptr_t)new_GSbase);
816*c54f35caSApple OSS Distributions 	} else {
817*c54f35caSApple OSS Distributions #ifndef STANDALONE
818*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Failed to allocate a page for new GSbase");
819*c54f35caSApple OSS Distributions #else
820*c54f35caSApple OSS Distributions 		fprintf(stderr, "Failed to allocate a page for new GSbase");
821*c54f35caSApple OSS Distributions 		abort();
822*c54f35caSApple OSS Distributions #endif
823*c54f35caSApple OSS Distributions 	}
824*c54f35caSApple OSS Distributions 
825*c54f35caSApple OSS Distributions 	rv = thunkit(&input_desc, (void *)(uintptr_t)stackaddr, compat_arg,
826*c54f35caSApple OSS Distributions 	    callback, thunk64_addr);
827*c54f35caSApple OSS Distributions 
828*c54f35caSApple OSS Distributions 	restore_gsbase(stackaddr);
829*c54f35caSApple OSS Distributions 
830*c54f35caSApple OSS Distributions 	free(new_GSbase);
831*c54f35caSApple OSS Distributions 
832*c54f35caSApple OSS Distributions 	return rv;
833*c54f35caSApple OSS Distributions }
834*c54f35caSApple OSS Distributions 
835*c54f35caSApple OSS Distributions static uint64_t
get_cursp(void)836*c54f35caSApple OSS Distributions get_cursp(void)
837*c54f35caSApple OSS Distributions {
838*c54f35caSApple OSS Distributions 	uint64_t curstk;
839*c54f35caSApple OSS Distributions 	__asm__ __volatile__ ("movq %%rsp, %0" : "=r" (curstk) :: "memory");
840*c54f35caSApple OSS Distributions 	return curstk;
841*c54f35caSApple OSS Distributions }
842*c54f35caSApple OSS Distributions 
843*c54f35caSApple OSS Distributions static void
hello_from_32bit(void)844*c54f35caSApple OSS Distributions hello_from_32bit(void)
845*c54f35caSApple OSS Distributions {
846*c54f35caSApple OSS Distributions 	uint64_t cur_tsd_base = (uint64_t)(uintptr_t)mytsd->this_tsd_base;
847*c54f35caSApple OSS Distributions 	restore_gsbase(get_cursp());
848*c54f35caSApple OSS Distributions 
849*c54f35caSApple OSS Distributions 	printf("Hello on behalf of 32-bit compatibility mode!\n");
850*c54f35caSApple OSS Distributions 
851*c54f35caSApple OSS Distributions 	_thread_set_tsd_base(cur_tsd_base);
852*c54f35caSApple OSS Distributions }
853*c54f35caSApple OSS Distributions 
854*c54f35caSApple OSS Distributions /*
855*c54f35caSApple OSS Distributions  * Thread for executing 32-bit code
856*c54f35caSApple OSS Distributions  */
857*c54f35caSApple OSS Distributions static void *
thread_32bit(void * arg)858*c54f35caSApple OSS Distributions thread_32bit(void *arg)
859*c54f35caSApple OSS Distributions {
860*c54f35caSApple OSS Distributions 	thread_arg_t *targp = (thread_arg_t *)arg;
861*c54f35caSApple OSS Distributions 	uint64_t cthread_self = 0;
862*c54f35caSApple OSS Distributions 
863*c54f35caSApple OSS Distributions 	/* Save the GSbase for context switch back to 64-bit mode */
864*c54f35caSApple OSS Distributions 	cthread_self = get_gsbase();
865*c54f35caSApple OSS Distributions 
866*c54f35caSApple OSS Distributions 	/*
867*c54f35caSApple OSS Distributions 	 * Associate GSbase with the compat-mode stack (which will be used for long mode
868*c54f35caSApple OSS Distributions 	 * thunk calls as well.)
869*c54f35caSApple OSS Distributions 	 */
870*c54f35caSApple OSS Distributions 	(void)stack_range_to_GSbase(targp->compat_stackaddr, cthread_self);
871*c54f35caSApple OSS Distributions 
872*c54f35caSApple OSS Distributions #ifdef DEBUG
873*c54f35caSApple OSS Distributions 	printf("[thread %p] tsd base => %p\n", (void *)pthread_self(), (void *)cthread_self);
874*c54f35caSApple OSS Distributions #endif
875*c54f35caSApple OSS Distributions 
876*c54f35caSApple OSS Distributions 	pthread_mutex_lock(&targp->mutex);
877*c54f35caSApple OSS Distributions 
878*c54f35caSApple OSS Distributions 	do {
879*c54f35caSApple OSS Distributions 		if (targp->done == FALSE) {
880*c54f35caSApple OSS Distributions 			pthread_cond_wait(&targp->condvar, &targp->mutex);
881*c54f35caSApple OSS Distributions 		}
882*c54f35caSApple OSS Distributions 
883*c54f35caSApple OSS Distributions 		/* Finally, execute the test */
884*c54f35caSApple OSS Distributions 		if (call_compatmode(targp->compat_stackaddr, 0,
885*c54f35caSApple OSS Distributions 		    (uint64_t)&hello_from_32bit) == 1) {
886*c54f35caSApple OSS Distributions 			printf("32-bit code test passed\n");
887*c54f35caSApple OSS Distributions 		} else {
888*c54f35caSApple OSS Distributions 			printf("32-bit code test failed\n");
889*c54f35caSApple OSS Distributions 		}
890*c54f35caSApple OSS Distributions 	} while (targp->done == FALSE);
891*c54f35caSApple OSS Distributions 
892*c54f35caSApple OSS Distributions 	pthread_mutex_unlock(&targp->mutex);
893*c54f35caSApple OSS Distributions 
894*c54f35caSApple OSS Distributions 	return 0;
895*c54f35caSApple OSS Distributions }
896*c54f35caSApple OSS Distributions 
897*c54f35caSApple OSS Distributions static void
join_32bit_thread(pthread_t * thridp,thread_arg_t * cmargp)898*c54f35caSApple OSS Distributions join_32bit_thread(pthread_t *thridp, thread_arg_t *cmargp)
899*c54f35caSApple OSS Distributions {
900*c54f35caSApple OSS Distributions 	(void)pthread_mutex_lock(&cmargp->mutex);
901*c54f35caSApple OSS Distributions 	cmargp->done = TRUE;
902*c54f35caSApple OSS Distributions 	(void)pthread_cond_signal(&cmargp->condvar);
903*c54f35caSApple OSS Distributions 	(void)pthread_mutex_unlock(&cmargp->mutex);
904*c54f35caSApple OSS Distributions 	(void)pthread_join(*thridp, NULL);
905*c54f35caSApple OSS Distributions 	*thridp = 0;
906*c54f35caSApple OSS Distributions }
907*c54f35caSApple OSS Distributions 
908*c54f35caSApple OSS Distributions static int
create_worker_thread(thread_arg_t * cmargp,uint32_t stackaddr,pthread_t * cmthreadp)909*c54f35caSApple OSS Distributions create_worker_thread(thread_arg_t *cmargp, uint32_t stackaddr, pthread_t *cmthreadp)
910*c54f35caSApple OSS Distributions {
911*c54f35caSApple OSS Distributions 	*cmargp = (thread_arg_t) { .mutex = PTHREAD_MUTEX_INITIALIZER,
912*c54f35caSApple OSS Distributions 		                   .condvar = PTHREAD_COND_INITIALIZER,
913*c54f35caSApple OSS Distributions 		                   .done = FALSE,
914*c54f35caSApple OSS Distributions 		                   .compat_stackaddr = stackaddr };
915*c54f35caSApple OSS Distributions 
916*c54f35caSApple OSS Distributions 	return pthread_create(cmthreadp, NULL, thread_32bit, cmargp);
917*c54f35caSApple OSS Distributions }
918*c54f35caSApple OSS Distributions 
919*c54f35caSApple OSS Distributions static void
ldt64_test_setup(pthread_t * cmthreadp,thread_arg_t * cmargp,boolean_t setldt_in_sighandler)920*c54f35caSApple OSS Distributions ldt64_test_setup(pthread_t *cmthreadp, thread_arg_t *cmargp, boolean_t setldt_in_sighandler)
921*c54f35caSApple OSS Distributions {
922*c54f35caSApple OSS Distributions 	extern void thunk64(void);
923*c54f35caSApple OSS Distributions 	extern void thunk64_movabs(void);
924*c54f35caSApple OSS Distributions 	int cnt = 0, err;
925*c54f35caSApple OSS Distributions 	void *addr;
926*c54f35caSApple OSS Distributions 	uintptr_t code_addr;
927*c54f35caSApple OSS Distributions 	uintptr_t thunk64_movabs_addr;
928*c54f35caSApple OSS Distributions 
929*c54f35caSApple OSS Distributions 	descs = malloc(sizeof(union ldt_entry) * 256);
930*c54f35caSApple OSS Distributions 	if (descs == 0) {
931*c54f35caSApple OSS Distributions #ifndef STANDALONE
932*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Could not allocate descriptor storage");
933*c54f35caSApple OSS Distributions #else
934*c54f35caSApple OSS Distributions 		fprintf(stderr, "Could not allocate descriptor storage\n");
935*c54f35caSApple OSS Distributions 		abort();
936*c54f35caSApple OSS Distributions #endif
937*c54f35caSApple OSS Distributions 	}
938*c54f35caSApple OSS Distributions 
939*c54f35caSApple OSS Distributions #ifdef DEBUG
940*c54f35caSApple OSS Distributions 	printf("32-bit code is at %p\n", (void *)&code_32);
941*c54f35caSApple OSS Distributions #endif
942*c54f35caSApple OSS Distributions 
943*c54f35caSApple OSS Distributions 	if ((err = map_lowmem_stack(&addr)) != 0) {
944*c54f35caSApple OSS Distributions #ifndef STANDALONE
945*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("failed to mmap lowmem stack: %s", strerror(err));
946*c54f35caSApple OSS Distributions #else
947*c54f35caSApple OSS Distributions 		fprintf(stderr, "Failed to mmap lowmem stack: %s\n", strerror(err));
948*c54f35caSApple OSS Distributions 		exit(1);
949*c54f35caSApple OSS Distributions #endif
950*c54f35caSApple OSS Distributions 	}
951*c54f35caSApple OSS Distributions 
952*c54f35caSApple OSS Distributions 	stackAddr = (uintptr_t)addr + FIXED_STACK_SIZE - 16;
953*c54f35caSApple OSS Distributions #ifdef DEBUG
954*c54f35caSApple OSS Distributions 	printf("lowstack addr = %p\n", (void *)stackAddr);
955*c54f35caSApple OSS Distributions #endif
956*c54f35caSApple OSS Distributions 
957*c54f35caSApple OSS Distributions 	if ((err = map_32bit_trampoline(&thunkit)) != 0) {
958*c54f35caSApple OSS Distributions #ifndef STANDALONE
959*c54f35caSApple OSS Distributions 		T_LOG("Failed to map trampoline into lowmem: %s\n", strerror(err));
960*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Failed to map trampoline into lowmem");
961*c54f35caSApple OSS Distributions #else
962*c54f35caSApple OSS Distributions 		fprintf(stderr, "Failed to map trampoline into lowmem: %s\n", strerror(err));
963*c54f35caSApple OSS Distributions 		exit(1);
964*c54f35caSApple OSS Distributions #endif
965*c54f35caSApple OSS Distributions 	}
966*c54f35caSApple OSS Distributions 
967*c54f35caSApple OSS Distributions 	/*
968*c54f35caSApple OSS Distributions 	 * Store long_mode_trampoline's address into the constant part of the movabs
969*c54f35caSApple OSS Distributions 	 * instruction in thunk64
970*c54f35caSApple OSS Distributions 	 */
971*c54f35caSApple OSS Distributions 	thunk64_movabs_addr = (uintptr_t)thunkit + ((uintptr_t)thunk64_movabs - (uintptr_t)compat_mode_trampoline);
972*c54f35caSApple OSS Distributions 	*((uint64_t *)(thunk64_movabs_addr + 2)) = (uint64_t)&long_mode_trampoline;
973*c54f35caSApple OSS Distributions 
974*c54f35caSApple OSS Distributions 	bzero(descs, sizeof(union ldt_entry) * 256);
975*c54f35caSApple OSS Distributions 
976*c54f35caSApple OSS Distributions 	if ((cnt = i386_get_ldt(0, descs, 1)) <= 0) {
977*c54f35caSApple OSS Distributions #ifndef STANDALONE
978*c54f35caSApple OSS Distributions 		T_LOG("i386_get_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
979*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("i386_get_ldt failure");
980*c54f35caSApple OSS Distributions #else
981*c54f35caSApple OSS Distributions 		fprintf(stderr, "i386_get_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
982*c54f35caSApple OSS Distributions 		exit(1);
983*c54f35caSApple OSS Distributions #endif
984*c54f35caSApple OSS Distributions 	}
985*c54f35caSApple OSS Distributions 
986*c54f35caSApple OSS Distributions #ifdef DEBUG
987*c54f35caSApple OSS Distributions 	printf("i386_get_ldt returned %d\n", cnt);
988*c54f35caSApple OSS Distributions #endif
989*c54f35caSApple OSS Distributions 
990*c54f35caSApple OSS Distributions 	idx = (unsigned)cnt;      /* Put the desired descriptor in the first available slot */
991*c54f35caSApple OSS Distributions 
992*c54f35caSApple OSS Distributions 	/*
993*c54f35caSApple OSS Distributions 	 * code_32's address for the purposes of this descriptor is the base mapped address of
994*c54f35caSApple OSS Distributions 	 * the thunkit function + the offset of code_32 from compat_mode_trampoline.
995*c54f35caSApple OSS Distributions 	 */
996*c54f35caSApple OSS Distributions 	code_addr = (uintptr_t)thunkit + ((uintptr_t)code_32 - (uintptr_t)compat_mode_trampoline);
997*c54f35caSApple OSS Distributions 	thunk64_addr = (uintptr_t)thunkit + ((uintptr_t)thunk64 - (uintptr_t)compat_mode_trampoline);
998*c54f35caSApple OSS Distributions 
999*c54f35caSApple OSS Distributions 	/* Initialize desired descriptor */
1000*c54f35caSApple OSS Distributions 	descs[idx].code.limit00 = (unsigned short)(((code_addr >> 12) + 1) & 0xFFFF);
1001*c54f35caSApple OSS Distributions 	descs[idx].code.limit16 = (unsigned char)((((code_addr >> 12) + 1) >> 16) & 0xF);
1002*c54f35caSApple OSS Distributions 	descs[idx].code.base00 = (unsigned short)((code_addr) & 0xFFFF);
1003*c54f35caSApple OSS Distributions 	descs[idx].code.base16 = (unsigned char)((code_addr >> 16) & 0xFF);
1004*c54f35caSApple OSS Distributions 	descs[idx].code.base24 = (unsigned char)((code_addr >> 24) & 0xFF);
1005*c54f35caSApple OSS Distributions 	descs[idx].code.type = DESC_CODE_READ;
1006*c54f35caSApple OSS Distributions 	descs[idx].code.opsz = DESC_CODE_32B;
1007*c54f35caSApple OSS Distributions 	descs[idx].code.granular = DESC_GRAN_PAGE;
1008*c54f35caSApple OSS Distributions 	descs[idx].code.dpl = 3;
1009*c54f35caSApple OSS Distributions 	descs[idx].code.present = 1;
1010*c54f35caSApple OSS Distributions 
1011*c54f35caSApple OSS Distributions 	if (setldt_in_sighandler == FALSE) {
1012*c54f35caSApple OSS Distributions 		/* Set the LDT: */
1013*c54f35caSApple OSS Distributions 		cnt = i386_set_ldt((int)idx, &descs[idx], 1);
1014*c54f35caSApple OSS Distributions 		if (cnt != (int)idx) {
1015*c54f35caSApple OSS Distributions #ifndef STANDALONE
1016*c54f35caSApple OSS Distributions 			T_LOG("i386_set_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
1017*c54f35caSApple OSS Distributions 			T_ASSERT_FAIL("i386_set_ldt failure");
1018*c54f35caSApple OSS Distributions #else
1019*c54f35caSApple OSS Distributions 			fprintf(stderr, "i386_set_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
1020*c54f35caSApple OSS Distributions 			exit(1);
1021*c54f35caSApple OSS Distributions #endif
1022*c54f35caSApple OSS Distributions 		}
1023*c54f35caSApple OSS Distributions #ifdef DEBUG
1024*c54f35caSApple OSS Distributions 		printf("i386_set_ldt returned %d\n", cnt);
1025*c54f35caSApple OSS Distributions #endif
1026*c54f35caSApple OSS Distributions 	} else {
1027*c54f35caSApple OSS Distributions 		__asm__ __volatile__ ("ud2" ::: "memory");
1028*c54f35caSApple OSS Distributions 	}
1029*c54f35caSApple OSS Distributions 
1030*c54f35caSApple OSS Distributions 
1031*c54f35caSApple OSS Distributions 	/* Read back the LDT to ensure it was set properly */
1032*c54f35caSApple OSS Distributions 	if ((cnt = i386_get_ldt(0, descs, (int)idx)) > 0) {
1033*c54f35caSApple OSS Distributions #ifdef DEBUG
1034*c54f35caSApple OSS Distributions 		for (int i = 0; i < cnt; i++) {
1035*c54f35caSApple OSS Distributions 			dump_desc(&descs[i]);
1036*c54f35caSApple OSS Distributions 		}
1037*c54f35caSApple OSS Distributions #endif
1038*c54f35caSApple OSS Distributions 	} else {
1039*c54f35caSApple OSS Distributions #ifndef STANDALONE
1040*c54f35caSApple OSS Distributions 		T_LOG("i386_get_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
1041*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("i386_get_ldt failure");
1042*c54f35caSApple OSS Distributions #else
1043*c54f35caSApple OSS Distributions 		fprintf(stderr, "i386_get_ldt unexpectedly returned %d (errno: %s)\n", cnt, strerror(errno));
1044*c54f35caSApple OSS Distributions 		exit(1);
1045*c54f35caSApple OSS Distributions #endif
1046*c54f35caSApple OSS Distributions 	}
1047*c54f35caSApple OSS Distributions 
1048*c54f35caSApple OSS Distributions 	free(descs);
1049*c54f35caSApple OSS Distributions 
1050*c54f35caSApple OSS Distributions 	if ((err = create_worker_thread(cmargp, (uint32_t)stackAddr, cmthreadp)) != 0) {
1051*c54f35caSApple OSS Distributions #ifdef DEBUG
1052*c54f35caSApple OSS Distributions 		fprintf(stderr, "Fatal: Could not create thread: %s\n", strerror(err));
1053*c54f35caSApple OSS Distributions #endif
1054*c54f35caSApple OSS Distributions #ifndef STANDALONE
1055*c54f35caSApple OSS Distributions 		T_LOG("Fatal: Could not create thread: %s\n", strerror(err));
1056*c54f35caSApple OSS Distributions 		T_ASSERT_FAIL("Thread creation failure");
1057*c54f35caSApple OSS Distributions #else
1058*c54f35caSApple OSS Distributions 		exit(1);
1059*c54f35caSApple OSS Distributions #endif
1060*c54f35caSApple OSS Distributions 	}
1061*c54f35caSApple OSS Distributions }
1062*c54f35caSApple OSS Distributions 
1063*c54f35caSApple OSS Distributions #ifdef STANDALONE
1064*c54f35caSApple OSS Distributions static void
test_ldt64_with_bsdsig(void)1065*c54f35caSApple OSS Distributions test_ldt64_with_bsdsig(void)
1066*c54f35caSApple OSS Distributions #else
1067*c54f35caSApple OSS Distributions /*
1068*c54f35caSApple OSS Distributions  * Main test declarations
1069*c54f35caSApple OSS Distributions  */
1070*c54f35caSApple OSS Distributions T_DECL(ldt64_with_bsd_sighandling,
1071*c54f35caSApple OSS Distributions     "Ensures that a 64-bit process can create LDT entries and can execute code in "
1072*c54f35caSApple OSS Distributions     "compatibility mode with BSD signal handling",
1073*c54f35caSApple OSS Distributions     T_META_TIMEOUT(NORMAL_RUN_TIME + TIMEOUT_OVERHEAD))
1074*c54f35caSApple OSS Distributions #endif
1075*c54f35caSApple OSS Distributions {
1076*c54f35caSApple OSS Distributions 	pthread_t cmthread;
1077*c54f35caSApple OSS Distributions 	thread_arg_t cmarg;
1078*c54f35caSApple OSS Distributions 
1079*c54f35caSApple OSS Distributions 	int translated = 0;
1080*c54f35caSApple OSS Distributions 	size_t translated_size = sizeof(int);
1081*c54f35caSApple OSS Distributions 
1082*c54f35caSApple OSS Distributions 	sysctlbyname("sysctl.proc_translated", &translated, &translated_size, NULL, 0);
1083*c54f35caSApple OSS Distributions 
1084*c54f35caSApple OSS Distributions 	if (translated) {
1085*c54f35caSApple OSS Distributions 		T_SKIP("Skipping this test because it is translated");
1086*c54f35caSApple OSS Distributions 	}
1087*c54f35caSApple OSS Distributions 
1088*c54f35caSApple OSS Distributions 	setup_signal_handling();
1089*c54f35caSApple OSS Distributions 
1090*c54f35caSApple OSS Distributions #ifndef STANDALONE
1091*c54f35caSApple OSS Distributions 	T_SETUPBEGIN;
1092*c54f35caSApple OSS Distributions #endif
1093*c54f35caSApple OSS Distributions 	ENV_set_ldt_in_sighandler = (getenv("LDT_SET_IN_SIGHANDLER") != NULL) ? TRUE : FALSE;
1094*c54f35caSApple OSS Distributions 	ldt64_test_setup(&cmthread, &cmarg, ENV_set_ldt_in_sighandler);
1095*c54f35caSApple OSS Distributions #ifndef STANDALONE
1096*c54f35caSApple OSS Distributions 	T_SETUPEND;
1097*c54f35caSApple OSS Distributions #endif
1098*c54f35caSApple OSS Distributions 
1099*c54f35caSApple OSS Distributions 	join_32bit_thread(&cmthread, &cmarg);
1100*c54f35caSApple OSS Distributions 
1101*c54f35caSApple OSS Distributions 	teardown_signal_handling();
1102*c54f35caSApple OSS Distributions 
1103*c54f35caSApple OSS Distributions #ifndef STANDALONE
1104*c54f35caSApple OSS Distributions 	T_PASS("Successfully completed ldt64 test with BSD signal handling");
1105*c54f35caSApple OSS Distributions #else
1106*c54f35caSApple OSS Distributions 	fprintf(stderr, "PASSED: ldt64_with_bsd_signal_handling\n");
1107*c54f35caSApple OSS Distributions #endif
1108*c54f35caSApple OSS Distributions }
1109*c54f35caSApple OSS Distributions 
1110*c54f35caSApple OSS Distributions #ifdef STANDALONE
1111*c54f35caSApple OSS Distributions static void
test_ldt64_with_machexc(void)1112*c54f35caSApple OSS Distributions test_ldt64_with_machexc(void)
1113*c54f35caSApple OSS Distributions #else
1114*c54f35caSApple OSS Distributions T_DECL(ldt64_with_mach_exception_handling,
1115*c54f35caSApple OSS Distributions     "Ensures that a 64-bit process can create LDT entries and can execute code in "
1116*c54f35caSApple OSS Distributions     "compatibility mode with Mach exception handling",
1117*c54f35caSApple OSS Distributions     T_META_TIMEOUT(NORMAL_RUN_TIME + TIMEOUT_OVERHEAD))
1118*c54f35caSApple OSS Distributions #endif
1119*c54f35caSApple OSS Distributions {
1120*c54f35caSApple OSS Distributions 	pthread_t cmthread;
1121*c54f35caSApple OSS Distributions 	thread_arg_t cmarg;
1122*c54f35caSApple OSS Distributions 
1123*c54f35caSApple OSS Distributions 	int translated = 0;
1124*c54f35caSApple OSS Distributions 	size_t translated_size = sizeof(int);
1125*c54f35caSApple OSS Distributions 
1126*c54f35caSApple OSS Distributions 	sysctlbyname("sysctl.proc_translated", &translated, &translated_size, NULL, 0);
1127*c54f35caSApple OSS Distributions 
1128*c54f35caSApple OSS Distributions 	if (translated) {
1129*c54f35caSApple OSS Distributions 		T_SKIP("Skipping this test because it is translated");
1130*c54f35caSApple OSS Distributions 	}
1131*c54f35caSApple OSS Distributions 
1132*c54f35caSApple OSS Distributions #ifndef STANDALONE
1133*c54f35caSApple OSS Distributions 	T_SETUPBEGIN;
1134*c54f35caSApple OSS Distributions #endif
1135*c54f35caSApple OSS Distributions 	ldt64_test_setup(&cmthread, &cmarg, FALSE);
1136*c54f35caSApple OSS Distributions #ifndef STANDALONE
1137*c54f35caSApple OSS Distributions 	T_SETUPEND;
1138*c54f35caSApple OSS Distributions #endif
1139*c54f35caSApple OSS Distributions 
1140*c54f35caSApple OSS Distributions 	/* Now repeat with Mach exception handling */
1141*c54f35caSApple OSS Distributions 	init_task_exception_server();
1142*c54f35caSApple OSS Distributions 
1143*c54f35caSApple OSS Distributions 	join_32bit_thread(&cmthread, &cmarg);
1144*c54f35caSApple OSS Distributions 
1145*c54f35caSApple OSS Distributions #ifndef STANDALONE
1146*c54f35caSApple OSS Distributions 	T_PASS("Successfully completed ldt64 test with mach exception handling");
1147*c54f35caSApple OSS Distributions #else
1148*c54f35caSApple OSS Distributions 	fprintf(stderr, "PASSED: ldt64_with_mach_exception_handling\n");
1149*c54f35caSApple OSS Distributions #endif
1150*c54f35caSApple OSS Distributions }
1151*c54f35caSApple OSS Distributions 
1152*c54f35caSApple OSS Distributions #ifdef STANDALONE
1153*c54f35caSApple OSS Distributions int
main(int __unused argc,char ** __unused argv)1154*c54f35caSApple OSS Distributions main(int __unused argc, char ** __unused argv)
1155*c54f35caSApple OSS Distributions {
1156*c54f35caSApple OSS Distributions 	test_ldt64_with_bsdsig();
1157*c54f35caSApple OSS Distributions 	test_ldt64_with_machexc();
1158*c54f35caSApple OSS Distributions }
1159*c54f35caSApple OSS Distributions #endif
1160