VirtualBox

source: vbox/trunk/src/VBox/HostDrivers/Support/darwin/SUPR3HardenedMain-darwin.cpp@ 87030

最後變更 在這個檔案從87030是 87030,由 vboxsync 提交於 4 年 前

Forward port r141521, r141567, r141568, r141588, r141589, r141590, r141592, r141593, r141594, r141595 and r141652 from 6.1 (Fixes for BigSur with SIP disabled, bugref:9836)

  • 屬性 svn:eol-style 設為 native
  • 屬性 svn:keywords 設為 Author Date Id Revision
檔案大小: 9.5 KB
 
1/* $Id: SUPR3HardenedMain-darwin.cpp 87030 2020-12-02 10:46:49Z vboxsync $ */
2/** @file
3 * VirtualBox Support Library - Hardened main(), posix bits.
4 */
5
6/*
7 * Copyright (C) 2017-2020 Oracle Corporation
8 *
9 * This file is part of VirtualBox Open Source Edition (OSE), as
10 * available from http://www.alldomusa.eu.org. This file is free software;
11 * you can redistribute it and/or modify it under the terms of the GNU
12 * General Public License (GPL) as published by the Free Software
13 * Foundation, in version 2 as it comes in the "COPYING" file of the
14 * VirtualBox OSE distribution. VirtualBox OSE is distributed in the
15 * hope that it will be useful, but WITHOUT ANY WARRANTY of any kind.
16 *
17 * The contents of this file may alternatively be used under the terms
18 * of the Common Development and Distribution License Version 1.0
19 * (CDDL) only, as it comes in the "COPYING.CDDL" file of the
20 * VirtualBox OSE distribution, in which case the provisions of the
21 * CDDL are applicable instead of those of the GPL.
22 *
23 * You may elect to license modified versions of this file under the
24 * terms and conditions of either the GPL or the CDDL or both.
25 */
26
27
28/*********************************************************************************************************************************
29* Header Files *
30*********************************************************************************************************************************/
31#include <VBox/err.h>
32#include <VBox/sup.h>
33
34#include <iprt/path.h>
35#include <iprt/string.h>
36
37#include <dlfcn.h>
38#include <sys/mman.h>
39#include <errno.h>
40#include <sys/sysctl.h> /* sysctlbyname() */
41#include <stdio.h>
42#include <stdint.h>
43#include <mach-o/dyld.h>
44
45#include "SUPLibInternal.h"
46
47
48/*********************************************************************************************************************************
49* Defined Constants And Macros *
50*********************************************************************************************************************************/
51
52
53/*********************************************************************************************************************************
54* Structures and Typedefs *
55*********************************************************************************************************************************/
56
57/**
58 * Interpose table entry.
59 */
60typedef struct DYLDINTERPOSE
61{
62 /** The symbol address to replace with. */
63 const void *pvReplacement;
64 /** The replaced symbol address. */
65 const void *pvReplacee;
66} DYLDINTERPOSE;
67/** Pointer to an interposer table entry. */
68typedef DYLDINTERPOSE *PDYLDINTERPOSE;
69/** Pointer to a const interposer table entry. */
70typedef const DYLDINTERPOSE *PCDYLDINTERPOSE;
71
72/** @sa dyld_dynamic_interpose(). */
73typedef const mach_header * FNDYLDDYNAMICINTERPOSE(const struct mach_header* mh, PCDYLDINTERPOSE paSym, size_t cSyms);
74typedef FNDYLDDYNAMICINTERPOSE *PFNDYLDDYNAMICINTERPOSE;
75
76/** @sa dlopen(). */
77typedef void *FNDLOPEN(const char *path, int mode);
78typedef FNDLOPEN *PFNDLOPEN;
79
80
81/*********************************************************************************************************************************
82* Internal Functions *
83*********************************************************************************************************************************/
84
85extern "C" void _dyld_register_func_for_add_image(void (*func)(const struct mach_header* mh, intptr_t vmaddr_slide));
86
87static void * supR3HardenedDarwinDlopenInterpose(const char *path, int mode);
88
89
90/*********************************************************************************************************************************
91* Global Variables *
92*********************************************************************************************************************************/
93/** Flag whether macOS 11.x (BigSur) was detected. */
94static bool g_fMacOs11 = false;
95/** Resolved dyld_dynamic_interpose() value. */
96static PFNDYLDDYNAMICINTERPOSE g_pfnDyldDynamicInterpose = NULL;
97/** Pointer to the real dlopen() function used from the interposer when verification succeeded. */
98static PFNDLOPEN g_pfnDlopenReal = NULL;
99/**
100 * The interposer table.
101 */
102static const DYLDINTERPOSE g_aInterposers[] =
103{
104 { (const void *)(uintptr_t)&supR3HardenedDarwinDlopenInterpose, (const void *)(uintptr_t)&dlopen }
105};
106
107
108/**
109 * dlopen() interposer which verifies that the path to be loaded meets the criteria for hardened builds.
110 *
111 * @sa dlopen() man page.
112 */
113static void * supR3HardenedDarwinDlopenInterpose(const char *path, int mode)
114{
115 /*
116 * Giving NULL as the filename indicates opening the main program which is fine
117 * We are already loaded and executing after all.
118 *
119 * Filenames without any path component (whether absolute or relative) are allowed
120 * unconditionally too as the loader will only search the default paths configured by root.
121 */
122 if ( path
123 && strchr(path, '/') != NULL)
124 {
125 int rc = VINF_SUCCESS;
126
127 /*
128 * Starting with macOS 11.0 (BigSur) system provided libraries
129 * under /System/Libraries are not stored on the filesystem anymore
130 * but in a dynamic linker cache. The integrity of the linker cache
131 * is maintained by the system and dyld. Our verification code fails because
132 * it can't find the file.
133 * The obvious solution is to exclude paths starting with /System/Libraries
134 * when we run on BigSur. Other paths are still subject to verification.
135 */
136 if ( !g_fMacOs11
137 || strncmp(path, RT_STR_TUPLE("/System/Library")))
138 rc = supR3HardenedVerifyFileFollowSymlinks(path, RTHCUINTPTR_MAX, true /* fMaybe3rdParty */,
139 NULL /* pErrInfo */);
140 if (RT_FAILURE(rc))
141 return NULL;
142 }
143
144 return g_pfnDlopenReal(path, mode);
145}
146
147
148/**
149 * Callback to get notified of new images being loaded to be able to apply our dlopn() interposer.
150 *
151 * @returns nothing.
152 * @param mh Pointer to the mach header of the loaded image.
153 * @param vmaddr_slide The slide value for ASLR.
154 */
155static DECLCALLBACK(void) supR3HardenedDarwinAddImage(const struct mach_header* mh, intptr_t vmaddr_slide)
156{
157 RT_NOREF(vmaddr_slide);
158
159 g_pfnDyldDynamicInterpose((const struct mach_header*)mh, &g_aInterposers[0], RT_ELEMENTS(g_aInterposers));
160}
161
162
163/**
164 * Hardening initialization for macOS hosts.
165 *
166 * @returns nothing.
167 *
168 * @note Doesn't return on error.
169 */
170DECLHIDDEN(void) supR3HardenedDarwinInit(void)
171{
172 /*
173 * Check whether we are running on macOS BigSur by checking kern.osproductversion
174 * available since some point in 2018.
175 */
176 char szVers[256]; RT_ZERO(szVers);
177 size_t cbVers = sizeof(szVers);
178 int rc = sysctlbyname("kern.osproductversion", &szVers[0], &cbVers, NULL, 0);
179 if ( !rc
180 && !memcmp(&szVers[0], RT_STR_TUPLE("10.16")))
181 g_fMacOs11 = true;
182
183 /* Saved to call real dlopen() later on, as we will interpose dlopen() from the main binary in the next step as well. */
184 g_pfnDlopenReal = (PFNDLOPEN)dlsym(RTLD_DEFAULT, "dlopen");
185 g_pfnDyldDynamicInterpose = (PFNDYLDDYNAMICINTERPOSE)dlsym(RTLD_DEFAULT, "dyld_dynamic_interpose");
186 if (!g_pfnDyldDynamicInterpose)
187 supR3HardenedFatalMsg("supR3HardenedDarwinInit", kSupInitOp_Integrity, VERR_SYMBOL_NOT_FOUND,
188 "Failed to find dyld_dynamic_interpose()");
189
190 /*
191 * The following will causes our add image notification to be called for all images loaded so far.
192 * The callback will set up the interposer.
193 */
194 _dyld_register_func_for_add_image(supR3HardenedDarwinAddImage);
195}
196
197
198
199/*
200 * assert.cpp
201 *
202 * ASSUMES working DECLHIDDEN or there will be symbol confusion!
203 */
204
205RTDATADECL(char) g_szRTAssertMsg1[1024];
206RTDATADECL(char) g_szRTAssertMsg2[4096];
207RTDATADECL(const char * volatile) g_pszRTAssertExpr;
208RTDATADECL(const char * volatile) g_pszRTAssertFile;
209RTDATADECL(uint32_t volatile) g_u32RTAssertLine;
210RTDATADECL(const char * volatile) g_pszRTAssertFunction;
211
212RTDECL(bool) RTAssertMayPanic(void)
213{
214 return true;
215}
216
217
218RTDECL(void) RTAssertMsg1(const char *pszExpr, unsigned uLine, const char *pszFile, const char *pszFunction)
219{
220 /*
221 * Fill in the globals.
222 */
223 g_pszRTAssertExpr = pszExpr;
224 g_pszRTAssertFile = pszFile;
225 g_pszRTAssertFunction = pszFunction;
226 g_u32RTAssertLine = uLine;
227 snprintf(g_szRTAssertMsg1, sizeof(g_szRTAssertMsg1),
228 "\n!!Assertion Failed!!\n"
229 "Expression: %s\n"
230 "Location : %s(%u) %s\n",
231 pszExpr, pszFile, uLine, pszFunction);
232}
233
234
235RTDECL(void) RTAssertMsg2V(const char *pszFormat, va_list va)
236{
237 vsnprintf(g_szRTAssertMsg2, sizeof(g_szRTAssertMsg2), pszFormat, va);
238 if (g_enmSupR3HardenedMainState < SUPR3HARDENEDMAINSTATE_CALLED_TRUSTED_MAIN)
239 supR3HardenedFatalMsg(g_pszRTAssertExpr, kSupInitOp_Misc, VERR_INTERNAL_ERROR,
240 "%s%s", g_szRTAssertMsg1, g_szRTAssertMsg2);
241 else
242 supR3HardenedError(VERR_INTERNAL_ERROR, false/*fFatal*/, "%s%s", g_szRTAssertMsg1, g_szRTAssertMsg2);
243}
244
注意: 瀏覽 TracBrowser 來幫助您使用儲存庫瀏覽器

© 2025 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette