2022-09-06 19:14:07 -04:00
|
|
|
|
// Copyright 2014 The Crashpad Authors
|
2014-12-30 14:23:47 -05:00
|
|
|
|
//
|
|
|
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
|
// you may not use this file except in compliance with the License.
|
|
|
|
|
// You may obtain a copy of the License at
|
|
|
|
|
//
|
|
|
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
//
|
|
|
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
|
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
|
// See the License for the specific language governing permissions and
|
|
|
|
|
// limitations under the License.
|
|
|
|
|
|
|
|
|
|
#include "handler/mac/exception_handler_server.h"
|
|
|
|
|
|
2015-12-09 17:36:32 -05:00
|
|
|
|
#include <utility>
|
|
|
|
|
|
2023-08-16 16:30:40 -04:00
|
|
|
|
#include "base/apple/mach_logging.h"
|
2023-11-06 13:34:26 -08:00
|
|
|
|
#include "base/check.h"
|
2014-12-30 14:23:47 -05:00
|
|
|
|
#include "base/logging.h"
|
|
|
|
|
#include "util/mach/composite_mach_message_server.h"
|
|
|
|
|
#include "util/mach/mach_extensions.h"
|
|
|
|
|
#include "util/mach/mach_message.h"
|
|
|
|
|
#include "util/mach/mach_message_server.h"
|
|
|
|
|
#include "util/mach/notify_server.h"
|
|
|
|
|
|
|
|
|
|
namespace crashpad {
|
|
|
|
|
|
|
|
|
|
namespace {
|
|
|
|
|
|
2015-03-12 14:00:38 -04:00
|
|
|
|
class ExceptionHandlerServerRun : public UniversalMachExcServer::Interface,
|
2015-10-30 15:44:40 -04:00
|
|
|
|
public NotifyServer::DefaultInterface {
|
2014-12-30 14:23:47 -05:00
|
|
|
|
public:
|
2015-02-04 18:32:42 -05:00
|
|
|
|
ExceptionHandlerServerRun(
|
|
|
|
|
mach_port_t exception_port,
|
2015-11-09 16:29:25 -05:00
|
|
|
|
mach_port_t notify_port,
|
2015-11-03 19:20:29 -05:00
|
|
|
|
bool launchd,
|
2015-02-04 18:32:42 -05:00
|
|
|
|
UniversalMachExcServer::Interface* exception_interface)
|
2014-12-30 14:23:47 -05:00
|
|
|
|
: UniversalMachExcServer::Interface(),
|
2015-10-30 15:44:40 -04:00
|
|
|
|
NotifyServer::DefaultInterface(),
|
2014-12-30 14:23:47 -05:00
|
|
|
|
mach_exc_server_(this),
|
|
|
|
|
notify_server_(this),
|
|
|
|
|
composite_mach_message_server_(),
|
2015-02-04 18:32:42 -05:00
|
|
|
|
exception_interface_(exception_interface),
|
2014-12-30 14:23:47 -05:00
|
|
|
|
exception_port_(exception_port),
|
2015-11-09 16:29:25 -05:00
|
|
|
|
notify_port_(notify_port),
|
2015-11-03 19:20:29 -05:00
|
|
|
|
running_(true),
|
|
|
|
|
launchd_(launchd) {
|
2014-12-30 14:23:47 -05:00
|
|
|
|
composite_mach_message_server_.AddHandler(&mach_exc_server_);
|
|
|
|
|
composite_mach_message_server_.AddHandler(¬ify_server_);
|
|
|
|
|
}
|
|
|
|
|
|
2021-09-20 12:55:12 -07:00
|
|
|
|
ExceptionHandlerServerRun(const ExceptionHandlerServerRun&) = delete;
|
|
|
|
|
ExceptionHandlerServerRun& operator=(const ExceptionHandlerServerRun&) =
|
|
|
|
|
delete;
|
|
|
|
|
|
2014-12-30 14:23:47 -05:00
|
|
|
|
~ExceptionHandlerServerRun() {
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
void Run() {
|
|
|
|
|
DCHECK(running_);
|
|
|
|
|
|
2015-11-03 19:20:29 -05:00
|
|
|
|
kern_return_t kr;
|
|
|
|
|
if (!launchd_) {
|
|
|
|
|
// Request that a no-senders notification for exception_port_ be sent to
|
|
|
|
|
// notify_port_.
|
|
|
|
|
mach_port_t previous;
|
|
|
|
|
kr = mach_port_request_notification(mach_task_self(),
|
|
|
|
|
exception_port_,
|
|
|
|
|
MACH_NOTIFY_NO_SENDERS,
|
|
|
|
|
0,
|
2015-11-09 16:29:25 -05:00
|
|
|
|
notify_port_,
|
2015-11-03 19:20:29 -05:00
|
|
|
|
MACH_MSG_TYPE_MAKE_SEND_ONCE,
|
|
|
|
|
&previous);
|
|
|
|
|
MACH_CHECK(kr == KERN_SUCCESS, kr) << "mach_port_request_notification";
|
2023-08-16 16:30:40 -04:00
|
|
|
|
base::apple::ScopedMachSendRight previous_owner(previous);
|
2014-12-30 14:23:47 -05:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// A single CompositeMachMessageServer will dispatch both exception messages
|
|
|
|
|
// and the no-senders notification. Put both receive rights into a port set.
|
|
|
|
|
//
|
|
|
|
|
// A single receive right can’t be used because the notification request
|
|
|
|
|
// requires a send-once right, which would prevent the no-senders condition
|
|
|
|
|
// from ever existing. Using distinct receive rights also allows the handler
|
|
|
|
|
// methods to ensure that the messages they process were sent by a holder of
|
|
|
|
|
// the proper send right.
|
2023-08-16 16:30:40 -04:00
|
|
|
|
base::apple::ScopedMachPortSet server_port_set(
|
2014-12-30 14:23:47 -05:00
|
|
|
|
NewMachPort(MACH_PORT_RIGHT_PORT_SET));
|
2015-11-03 19:20:29 -05:00
|
|
|
|
CHECK(server_port_set.is_valid());
|
2014-12-30 14:23:47 -05:00
|
|
|
|
|
|
|
|
|
kr = mach_port_insert_member(
|
2015-10-20 11:03:25 -04:00
|
|
|
|
mach_task_self(), exception_port_, server_port_set.get());
|
2014-12-30 14:23:47 -05:00
|
|
|
|
MACH_CHECK(kr == KERN_SUCCESS, kr) << "mach_port_insert_member";
|
|
|
|
|
|
|
|
|
|
kr = mach_port_insert_member(
|
2015-11-09 16:29:25 -05:00
|
|
|
|
mach_task_self(), notify_port_, server_port_set.get());
|
2014-12-30 14:23:47 -05:00
|
|
|
|
MACH_CHECK(kr == KERN_SUCCESS, kr) << "mach_port_insert_member";
|
|
|
|
|
|
|
|
|
|
// Run the server in kOneShot mode so that running_ can be reevaluated after
|
|
|
|
|
// each message. Receipt of a valid no-senders notification causes it to be
|
|
|
|
|
// set to false.
|
|
|
|
|
while (running_) {
|
|
|
|
|
// This will result in a call to CatchMachException() or
|
|
|
|
|
// DoMachNotifyNoSenders() as appropriate.
|
|
|
|
|
mach_msg_return_t mr =
|
|
|
|
|
MachMessageServer::Run(&composite_mach_message_server_,
|
2015-10-20 11:03:25 -04:00
|
|
|
|
server_port_set.get(),
|
2015-03-12 14:00:38 -04:00
|
|
|
|
kMachMessageReceiveAuditTrailer,
|
2014-12-30 14:23:47 -05:00
|
|
|
|
MachMessageServer::kOneShot,
|
|
|
|
|
MachMessageServer::kReceiveLargeIgnore,
|
|
|
|
|
kMachMessageTimeoutWaitIndefinitely);
|
2017-04-17 17:03:57 -04:00
|
|
|
|
|
|
|
|
|
// MACH_SEND_INVALID_DEST occurs when attempting to reply to a dead name.
|
|
|
|
|
// This can happen if a mach_exc or exc client disappears before a reply
|
|
|
|
|
// can be sent to it. That’s unusal for kernel-generated requests, but can
|
|
|
|
|
// easily happen if a task sends its own exception request (as
|
|
|
|
|
// SimulateCrash() does) and dies before the reply is sent.
|
|
|
|
|
MACH_CHECK(mr == MACH_MSG_SUCCESS || mr == MACH_SEND_INVALID_DEST, mr)
|
|
|
|
|
<< "MachMessageServer::Run";
|
2014-12-30 14:23:47 -05:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// UniversalMachExcServer::Interface:
|
|
|
|
|
|
|
|
|
|
kern_return_t CatchMachException(exception_behavior_t behavior,
|
|
|
|
|
exception_handler_t exception_port,
|
|
|
|
|
thread_t thread,
|
|
|
|
|
task_t task,
|
|
|
|
|
exception_type_t exception,
|
|
|
|
|
const mach_exception_data_type_t* code,
|
|
|
|
|
mach_msg_type_number_t code_count,
|
|
|
|
|
thread_state_flavor_t* flavor,
|
2015-04-02 15:28:28 -04:00
|
|
|
|
ConstThreadState old_state,
|
2014-12-30 14:23:47 -05:00
|
|
|
|
mach_msg_type_number_t old_state_count,
|
|
|
|
|
thread_state_t new_state,
|
|
|
|
|
mach_msg_type_number_t* new_state_count,
|
|
|
|
|
const mach_msg_trailer_t* trailer,
|
|
|
|
|
bool* destroy_complex_request) override {
|
|
|
|
|
if (exception_port != exception_port_) {
|
|
|
|
|
LOG(WARNING) << "exception port mismatch";
|
2015-10-29 18:09:03 -04:00
|
|
|
|
return KERN_FAILURE;
|
2014-12-30 14:23:47 -05:00
|
|
|
|
}
|
|
|
|
|
|
2015-02-04 18:32:42 -05:00
|
|
|
|
return exception_interface_->CatchMachException(behavior,
|
|
|
|
|
exception_port,
|
|
|
|
|
thread,
|
|
|
|
|
task,
|
|
|
|
|
exception,
|
|
|
|
|
code,
|
|
|
|
|
code_count,
|
|
|
|
|
flavor,
|
|
|
|
|
old_state,
|
|
|
|
|
old_state_count,
|
|
|
|
|
new_state,
|
|
|
|
|
new_state_count,
|
|
|
|
|
trailer,
|
|
|
|
|
destroy_complex_request);
|
2014-12-30 14:23:47 -05:00
|
|
|
|
}
|
|
|
|
|
|
2015-10-30 15:44:40 -04:00
|
|
|
|
// NotifyServer::DefaultInterface:
|
2014-12-30 14:23:47 -05:00
|
|
|
|
|
|
|
|
|
kern_return_t DoMachNotifyNoSenders(
|
|
|
|
|
notify_port_t notify,
|
|
|
|
|
mach_port_mscount_t mscount,
|
|
|
|
|
const mach_msg_trailer_t* trailer) override {
|
|
|
|
|
if (notify != notify_port_) {
|
|
|
|
|
// The message was received as part of a port set. This check ensures that
|
|
|
|
|
// only the authorized sender of the no-senders notification is able to
|
|
|
|
|
// stop the exception server. Otherwise, a malicious client would be able
|
|
|
|
|
// to craft and send a no-senders notification via its exception port, and
|
|
|
|
|
// cause the handler to stop processing exceptions and exit.
|
|
|
|
|
LOG(WARNING) << "notify port mismatch";
|
2015-10-29 18:09:03 -04:00
|
|
|
|
return KERN_FAILURE;
|
2014-12-30 14:23:47 -05:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
running_ = false;
|
|
|
|
|
|
|
|
|
|
return KERN_SUCCESS;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
private:
|
|
|
|
|
UniversalMachExcServer mach_exc_server_;
|
|
|
|
|
NotifyServer notify_server_;
|
|
|
|
|
CompositeMachMessageServer composite_mach_message_server_;
|
2015-02-04 18:32:42 -05:00
|
|
|
|
UniversalMachExcServer::Interface* exception_interface_; // weak
|
2014-12-30 14:23:47 -05:00
|
|
|
|
mach_port_t exception_port_; // weak
|
2015-11-09 16:29:25 -05:00
|
|
|
|
mach_port_t notify_port_; // weak
|
2014-12-30 14:23:47 -05:00
|
|
|
|
bool running_;
|
2015-11-03 19:20:29 -05:00
|
|
|
|
bool launchd_;
|
2014-12-30 14:23:47 -05:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
} // namespace
|
|
|
|
|
|
2015-10-29 18:09:03 -04:00
|
|
|
|
ExceptionHandlerServer::ExceptionHandlerServer(
|
2023-08-16 16:30:40 -04:00
|
|
|
|
base::apple::ScopedMachReceiveRight receive_port,
|
2015-11-03 19:20:29 -05:00
|
|
|
|
bool launchd)
|
2015-12-09 17:36:32 -05:00
|
|
|
|
: receive_port_(std::move(receive_port)),
|
2015-11-09 16:29:25 -05:00
|
|
|
|
notify_port_(NewMachPort(MACH_PORT_RIGHT_RECEIVE)),
|
2015-11-03 19:20:29 -05:00
|
|
|
|
launchd_(launchd) {
|
2015-10-20 11:03:25 -04:00
|
|
|
|
CHECK(receive_port_.is_valid());
|
2015-11-09 16:29:25 -05:00
|
|
|
|
CHECK(notify_port_.is_valid());
|
2014-12-30 14:23:47 -05:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
ExceptionHandlerServer::~ExceptionHandlerServer() {
|
|
|
|
|
}
|
|
|
|
|
|
2015-02-04 18:32:42 -05:00
|
|
|
|
void ExceptionHandlerServer::Run(
|
|
|
|
|
UniversalMachExcServer::Interface* exception_interface) {
|
2015-11-03 19:20:29 -05:00
|
|
|
|
ExceptionHandlerServerRun run(
|
2015-11-09 16:29:25 -05:00
|
|
|
|
receive_port_.get(), notify_port_.get(), launchd_, exception_interface);
|
2014-12-30 14:23:47 -05:00
|
|
|
|
run.Run();
|
|
|
|
|
}
|
|
|
|
|
|
2015-11-09 16:29:25 -05:00
|
|
|
|
void ExceptionHandlerServer::Stop() {
|
|
|
|
|
// Cause the exception handler server to stop running by sending it a
|
|
|
|
|
// synthesized no-senders notification.
|
|
|
|
|
//
|
|
|
|
|
// mach_no_senders_notification_t defines the receive side of this structure,
|
|
|
|
|
// with a trailer element that’s undesirable for the send side.
|
|
|
|
|
struct {
|
|
|
|
|
mach_msg_header_t header;
|
|
|
|
|
NDR_record_t ndr;
|
|
|
|
|
mach_msg_type_number_t mscount;
|
|
|
|
|
} no_senders_notification = {};
|
|
|
|
|
no_senders_notification.header.msgh_bits =
|
|
|
|
|
MACH_MSGH_BITS(MACH_MSG_TYPE_MAKE_SEND_ONCE, 0);
|
|
|
|
|
no_senders_notification.header.msgh_size = sizeof(no_senders_notification);
|
|
|
|
|
no_senders_notification.header.msgh_remote_port = notify_port_.get();
|
|
|
|
|
no_senders_notification.header.msgh_local_port = MACH_PORT_NULL;
|
|
|
|
|
no_senders_notification.header.msgh_id = MACH_NOTIFY_NO_SENDERS;
|
|
|
|
|
no_senders_notification.ndr = NDR_record;
|
|
|
|
|
no_senders_notification.mscount = 0;
|
|
|
|
|
|
|
|
|
|
kern_return_t kr = mach_msg(&no_senders_notification.header,
|
|
|
|
|
MACH_SEND_MSG,
|
|
|
|
|
sizeof(no_senders_notification),
|
|
|
|
|
0,
|
|
|
|
|
MACH_PORT_NULL,
|
|
|
|
|
MACH_MSG_TIMEOUT_NONE,
|
|
|
|
|
MACH_PORT_NULL);
|
|
|
|
|
MACH_CHECK(kr == KERN_SUCCESS, kr) << "mach_msg";
|
|
|
|
|
}
|
|
|
|
|
|
2014-12-30 14:23:47 -05:00
|
|
|
|
} // namespace crashpad
|