Loading...
src/dyldAPIs.cpp dyld-551.4 dyld-635.2
--- dyld/dyld-551.4/src/dyldAPIs.cpp
+++ dyld/dyld-635.2/src/dyldAPIs.cpp
@@ -55,9 +55,35 @@
 #include "dyld.h"
 #include "dyldLibSystemInterface.h"
 #include "DyldSharedCache.h"
+#include "MachOFile.h"
 
 #undef _POSIX_C_SOURCE
 #include "dlfcn.h"
+
+#if __has_feature(ptrauth_calls)
+  #include <ptrauth.h>
+#endif
+
+#ifndef CPU_SUBTYPE_ARM64_E
+	#define CPU_SUBTYPE_ARM64_E    2
+#endif
+
+// relocation_info.r_length field has value 3 for 64-bit executables and value 2 for 32-bit executables
+#if __LP64__
+#define RELOC_SIZE 3
+#define LC_SEGMENT_COMMAND		LC_SEGMENT_64
+#define LC_ROUTINES_COMMAND		LC_ROUTINES_64
+struct macho_segment_command	: public segment_command_64  {};
+struct macho_section			: public section_64  {};
+struct macho_routines_command	: public routines_command_64  {};
+#else
+#define RELOC_SIZE 2
+#define LC_SEGMENT_COMMAND		LC_SEGMENT
+#define LC_ROUTINES_COMMAND		LC_ROUTINES
+struct macho_segment_command	: public segment_command {};
+struct macho_section			: public section  {};
+struct macho_routines_command	: public routines_command  {};
+#endif
 
 
 // this was in dyld_priv.h but it is no longer exported
@@ -75,6 +101,16 @@
 extern const char* allImagesIndexedPath(uint32_t index);
 
 extern "C" int _dyld_func_lookup(const char* name, void** address);
+
+extern "C" void* dlopen_internal(const char* path, int mode, void* callerAddress);
+extern "C" bool  dlopen_preflight_internal(const char* path, void* callerAddress);
+extern "C" void* dlsym_internal(void* handle, const char* symbolName, void* callerAddress);
+
+extern "C" void* dlopen_compat(const char* path, int mode);
+extern "C" bool  dlopen_preflight_compat(const char* path);
+extern "C" void* dlsym_compat(void* handle, const char* symbolName);
+
+
 
 // deprecated APIs are still availble on Mac OS X, but not on iPhone OS
 #if __IPHONE_OS_VERSION_MIN_REQUIRED	
@@ -136,9 +172,12 @@
     {"__dyld_dladdr",									(void*)dladdr },
     {"__dyld_dlclose",									(void*)dlclose },
     {"__dyld_dlerror",									(void*)dlerror },
-    {"__dyld_dlopen",									(void*)dlopen },
-    {"__dyld_dlsym",									(void*)dlsym },
-    {"__dyld_dlopen_preflight",							(void*)dlopen_preflight },
+    {"__dyld_dlopen_internal",							(void*)dlopen_internal },
+    {"__dyld_dlsym_internal",							(void*)dlsym_internal },
+    {"__dyld_dlopen_preflight_internal",				(void*)dlopen_preflight_internal },
+    {"__dyld_dlopen",									(void*)dlopen_compat },
+    {"__dyld_dlsym",									(void*)dlsym_compat },
+    {"__dyld_dlopen_preflight",							(void*)dlopen_preflight_compat },
 	{"__dyld_image_count",								(void*)_dyld_image_count },
     {"__dyld_get_image_header",							(void*)_dyld_get_image_header },
     {"__dyld_get_image_vmaddr_slide",					(void*)_dyld_get_image_vmaddr_slide },
@@ -167,7 +206,8 @@
     {"__dyld_objc_notify_register",						(void*)_dyld_objc_notify_register },
     {"__dyld_get_shared_cache_uuid",					(void*)_dyld_get_shared_cache_uuid },
     {"__dyld_get_shared_cache_range",					(void*)_dyld_get_shared_cache_range },
-
+    {"__dyld_images_for_addresses",						(void*)_dyld_images_for_addresses },
+    {"__dyld_register_for_image_loads",					(void*)_dyld_register_for_image_loads },
 
 	// deprecated
 #if DEPRECATED_APIS_SUPPORTED
@@ -257,6 +297,7 @@
 	const void*		imageBaseAddress;	// not used with OFI created from files
 	size_t			imageLength;		// not used with OFI created from files
 };
+typedef __NSObjectFileImage*  NSObjectFileImage;
 
 
 VECTOR_NEVER_DESTRUCTED(NSObjectFileImage);
@@ -347,10 +388,27 @@
 	return allImagesIndexedPath(image_index);
 }
 
+static const void *stripPointer(const void *ptr) {
+#if __has_feature(ptrauth_calls)
+	return __builtin_ptrauth_strip(ptr, ptrauth_key_asia);
+#else
+	return ptr;
+#endif
+}
+
+static void *stripPointer(void *ptr) {
+#if __has_feature(ptrauth_calls)
+	return __builtin_ptrauth_strip(ptr, ptrauth_key_asia);
+#else
+	return ptr;
+#endif
+}
+
 const struct mach_header * dyld_image_header_containing_address(const void* address)
 {
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%p)\n", __func__, address);
+	address = stripPointer(address);
 #if SUPPORT_ACCELERATE_TABLES
 	const mach_header* mh;
 	const char* path;
@@ -550,6 +608,7 @@
 		context.mustBeBundle		= false;
 		context.mustBeDylib			= true;
 		context.canBePIE			= false;
+		context.enforceIOSMac		= false;
 		context.origin				= callerImage != NULL ? callerImage->getPath() : NULL; // caller's image's path
 		context.rpath				= &callersRPaths; 	// rpaths from caller and main executable
 
@@ -743,6 +802,7 @@
 {
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%p)\n", __func__, address);
+	address = stripPointer(address);
 	dyld::clearErrorMessage();
 	ImageLoader* image = dyld::findImageContainingAddress(address);
 	if ( image != NULL ) {
@@ -793,6 +853,7 @@
 		context.mustBeBundle		= true;
 		context.mustBeDylib			= false;
 		context.canBePIE			= false;
+		context.enforceIOSMac		= false;
 		context.origin				= callerImage != NULL ? callerImage->getPath() : NULL; // caller's image's path
 		context.rpath				= NULL; // support not yet implemented
 
@@ -1299,7 +1360,7 @@
 }
 
 
-bool dlopen_preflight(const char* path)
+bool dlopen_preflight_internal(const char* path, void* callerAddress)
 {
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%s)\n", __func__, path);
@@ -1344,7 +1405,6 @@
 	bool result = false;
 	std::vector<const char*> rpathsFromCallerImage;
 	try {
-		void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 		ImageLoader* callerImage = dyld::findImageContainingAddress(callerAddress);
 		// for dlopen, use rpath from caller image and from main executable
 		if ( callerImage != NULL )
@@ -1365,6 +1425,7 @@
 		context.mustBeBundle	= false;
 		context.mustBeDylib		= false;
 		context.canBePIE		= true;
+		context.enforceIOSMac	= false;
 		context.origin			= callerImage != NULL ? callerImage->getPath() : NULL; // caller's image's path
 		context.rpath			= &callersRPaths;	// rpaths from caller and main executable
 
@@ -1410,14 +1471,13 @@
 }
 #endif
 
-void* dlopen(const char* path, int mode)
+void* dlopen_internal(const char* path, int mode, void* callerAddress)
 {
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%s, 0x%08X)\n", __func__, ((path==NULL) ? "NULL" : path), mode);
 
 #if SUPPORT_ACCELERATE_TABLES
 	if ( dyld::gLogAppAPIs ) {
-		void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 		const char* shortName;
 		if ( callerIsNonOSApp(callerAddress, &shortName) ) {
 			dyld::log("%s: %s(%s, 0x%08X)\n", shortName, __func__, ((path==NULL) ? "NULL" : path), mode);
@@ -1481,7 +1541,6 @@
 	std::vector<const char*> rpathsFromCallerImage;
 	ImageLoader::RPathChain callersRPaths(NULL, &rpathsFromCallerImage);
 	try {
-		void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 		ImageLoader* callerImage = dyld::findImageContainingAddress(callerAddress);
 		if ( (mode & RTLD_NOLOAD) == 0 ) {
 			// for dlopen, use rpath from caller image and from main executable
@@ -1501,6 +1560,7 @@
 		context.mustBeBundle	= false;
 		context.mustBeDylib		= false;
 		context.canBePIE		= true;
+		context.enforceIOSMac	= false;
 		context.origin			= callerImage != NULL ? callerImage->getPath() : NULL; // caller's image's path
 		context.rpath			= &callersRPaths;				// rpaths from caller and main executable
 
@@ -1527,7 +1587,12 @@
 				bool alreadyLinked = image->isLinked();
 				bool forceLazysBound = ( (mode & RTLD_NOW) != 0 );
 				dyld::link(image, forceLazysBound, false, callersRPaths, cacheIndex);
-				if ( ! alreadyLinked ) {
+				if ( alreadyLinked ) {
+					// upgrade
+					if ( ((mode & RTLD_LOCAL) == 0) && image->hasHiddenExports() )
+						image->setHideExports(false);
+				}
+				else {
 					// only hide exports if image is not already in use
 					if ( (mode & RTLD_LOCAL) != 0 )
 						image->setHideExports(true);
@@ -1603,8 +1668,6 @@
 	return result;
 }
 
-
-
 int dlclose(void* handle)
 {
 	if ( dyld::gLogAPIs )
@@ -1615,7 +1678,14 @@
 		return 0;
 	if ( handle == RTLD_DEFAULT )
 		return 0;
-	
+
+#if SUPPORT_ACCELERATE_TABLES
+	if ( dyld::isCacheHandle(handle) ) {
+		dlerrorClear();
+		return 0;
+	}
+#endif
+
 	ImageLoader* image = (ImageLoader*)(((uintptr_t)handle) & (-4));	// clear mode bits
 	if ( dyld::validImage(image) ) {
 		dlerrorClear();
@@ -1641,6 +1711,12 @@
 {
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%p, %p)\n", __func__, address, info);
+
+	// <rdar://problem/42171466> calling dladdr(xx,NULL) crashes
+	if ( info == NULL )
+		return 0; // failure
+
+	address = stripPointer(address);
 
 	CRSetCrashLogMessage("dyld: in dladdr()");
 #if SUPPORT_ACCELERATE_TABLES
@@ -1709,14 +1785,13 @@
 	return NULL;
 }
 
-void* dlsym(void* handle, const char* symbolName)
+void* dlsym_internal(void* handle, const char* symbolName, void* callerAddress)
 {
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%p, %s)\n", __func__, handle, symbolName);
 
 #if SUPPORT_ACCELERATE_TABLES
 	if ( dyld::gLogAppAPIs ) {
-		void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 		const char* shortName;
 		if ( callerIsNonOSApp(callerAddress, &shortName) ) {
 			dyld::log("%s: %s(%p, %s)\n", shortName, __func__, handle, symbolName);
@@ -1742,6 +1817,20 @@
 		if ( dyld::flatFindExportedSymbol(underscoredName, &sym, &image) ) {
 			CRSetCrashLogMessage(NULL);
 			result = (void*)image->getExportedSymbolAddress(sym, dyld::gLinkContext, NULL, false, underscoredName);
+#if __has_feature(ptrauth_calls)
+			// Sign the pointer if it points to a function
+			// Note we only do this if the main executable is arm64e as otherwise we
+			// may end up calling containsAddress on the accelerator tables.
+			if ( result && (dyld::gLinkContext.mainExecutable->machHeader()->cpusubtype == CPU_SUBTYPE_ARM64_E) ) {
+				const ImageLoader* symbolImage = image;
+				if (!symbolImage->containsAddress(result)) {
+					symbolImage = dyld::findImageContainingAddress(result);
+				}
+				const macho_section *sect = symbolImage ? symbolImage->findSection(result) : NULL;
+				if ( sect && ((sect->flags & S_ATTR_PURE_INSTRUCTIONS) || (sect->flags & S_ATTR_SOME_INSTRUCTIONS)) )
+					result = __builtin_ptrauth_sign_unauthenticated(result, ptrauth_key_asia, 0);
+			}
+#endif
 			if ( dyld::gLogAPIs )
 				dyld::log("  %s(RTLD_DEFAULT, %s) ==> %p\n", __func__, symbolName, result);
 			return result;
@@ -1762,6 +1851,20 @@
 		if ( sym != NULL ) {
 			CRSetCrashLogMessage(NULL);
 			result = (void*)image->getExportedSymbolAddress(sym, dyld::gLinkContext, NULL, false, underscoredName);
+#if __has_feature(ptrauth_calls)
+			// Sign the pointer if it points to a function
+			// Note we only do this if the main executable is arm64e as otherwise we
+			// may end up calling containsAddress on the accelerator tables.
+			if ( result && (dyld::gLinkContext.mainExecutable->machHeader()->cpusubtype == CPU_SUBTYPE_ARM64_E) ) {
+				const ImageLoader* symbolImage = image;
+				if (!symbolImage->containsAddress(result)) {
+					symbolImage = dyld::findImageContainingAddress(result);
+				}
+				const macho_section *sect = symbolImage ? symbolImage->findSection(result) : NULL;
+				if ( sect && ((sect->flags & S_ATTR_PURE_INSTRUCTIONS) || (sect->flags & S_ATTR_SOME_INSTRUCTIONS)) )
+					result = __builtin_ptrauth_sign_unauthenticated(result, ptrauth_key_asia, 0);
+			}
+#endif
 			if ( dyld::gLogAPIs )
 				dyld::log("  %s(RTLD_MAIN_ONLY, %s) ==> %p\n", __func__, symbolName, result);
 			return result;
@@ -1777,7 +1880,6 @@
 	
 	// magic "search what I would see" handle
 	else if ( handle == RTLD_NEXT ) {
-		void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 #if SUPPORT_ACCELERATE_TABLES
 		const mach_header* mh;
 		const char* path;
@@ -1795,6 +1897,20 @@
 		if ( sym != NULL ) {
 			CRSetCrashLogMessage(NULL);
 			result = (void*)image->getExportedSymbolAddress(sym, dyld::gLinkContext , callerImage, false, underscoredName);
+#if __has_feature(ptrauth_calls)
+			// Sign the pointer if it points to a function
+			// Note we only do this if the main executable is arm64e as otherwise we
+			// may end up calling containsAddress on the accelerator tables.
+			if ( result && (dyld::gLinkContext.mainExecutable->machHeader()->cpusubtype == CPU_SUBTYPE_ARM64_E) ) {
+				const ImageLoader* symbolImage = image;
+				if (!symbolImage->containsAddress(result)) {
+					symbolImage = dyld::findImageContainingAddress(result);
+				}
+				const macho_section *sect = symbolImage ? symbolImage->findSection(result) : NULL;
+				if ( sect && ((sect->flags & S_ATTR_PURE_INSTRUCTIONS) || (sect->flags & S_ATTR_SOME_INSTRUCTIONS)) )
+					result = __builtin_ptrauth_sign_unauthenticated(result, ptrauth_key_asia, 0);
+			}
+#endif
 			if ( dyld::gLogAPIs )
 				dyld::log("  %s(RTLD_NEXT, %s) ==> %p\n", __func__, symbolName, result);
 			return result;
@@ -1809,7 +1925,6 @@
 	}
 	// magic "search me, then what I would see" handle
 	else if ( handle == RTLD_SELF ) {
-		void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 #if SUPPORT_ACCELERATE_TABLES
 		const mach_header* mh;
 		const char* path;
@@ -1827,6 +1942,20 @@
 		if ( sym != NULL ) {
 			CRSetCrashLogMessage(NULL);
 			result = (void*)image->getExportedSymbolAddress(sym, dyld::gLinkContext, callerImage, false, underscoredName);
+#if __has_feature(ptrauth_calls)
+			// Sign the pointer if it points to a function
+			// Note we only do this if the main executable is arm64e as otherwise we
+			// may end up calling containsAddress on the accelerator tables.
+			if ( result && (dyld::gLinkContext.mainExecutable->machHeader()->cpusubtype == CPU_SUBTYPE_ARM64_E) ) {
+				const ImageLoader* symbolImage = image;
+				if (!symbolImage->containsAddress(result)) {
+					symbolImage = dyld::findImageContainingAddress(result);
+				}
+				const macho_section *sect = symbolImage ? symbolImage->findSection(result) : NULL;
+				if ( sect && ((sect->flags & S_ATTR_PURE_INSTRUCTIONS) || (sect->flags & S_ATTR_SOME_INSTRUCTIONS)) )
+					result = __builtin_ptrauth_sign_unauthenticated(result, ptrauth_key_asia, 0);
+			}
+#endif
 			if ( dyld::gLogAPIs )
 				dyld::log("  %s(RTLD_SELF, %s) ==> %p\n", __func__, symbolName, result);
 			return result;
@@ -1861,10 +1990,23 @@
 			ImageLoader* callerImage = NULL;
 			if ( sDynamicInterposing ) {
 				// only take time to look up caller, if dynamic interposing in use
-				void* callerAddress = __builtin_return_address(1); // note layers: 1: real client, 0: libSystem glue
 				callerImage = dyld::findImageContainingAddress(callerAddress);
 			}
 			result = (void*)image->getExportedSymbolAddress(sym, dyld::gLinkContext, callerImage, false, underscoredName);
+#if __has_feature(ptrauth_calls)
+			// Sign the pointer if it points to a function
+			// Note we only do this if the main executable is arm64e as otherwise we
+			// may end up calling containsAddress on the accelerator tables.
+			if ( result && (dyld::gLinkContext.mainExecutable->machHeader()->cpusubtype == CPU_SUBTYPE_ARM64_E) ) {
+				const ImageLoader* symbolImage = image;
+				if (!symbolImage->containsAddress(result)) {
+					symbolImage = dyld::findImageContainingAddress(result);
+				}
+				const macho_section *sect = symbolImage ? symbolImage->findSection(result) : NULL;
+				if ( sect && ((sect->flags & S_ATTR_PURE_INSTRUCTIONS) || (sect->flags & S_ATTR_SOME_INSTRUCTIONS)) )
+					result = __builtin_ptrauth_sign_unauthenticated(result, ptrauth_key_asia, 0);
+			}
+#endif
 			if ( dyld::gLogAPIs )
 				dyld::log("  %s(%p, %s) ==> %p\n", __func__, handle, symbolName, result);
 			return result;
@@ -1882,11 +2024,25 @@
 	return NULL;
 }
 
-
-
-
-
-
+// Note this is only here to support ___pthread_abort in libpthread.a
+void* dlsym(void* handle, const char* symbolName) {
+	return dlsym_internal(handle, symbolName, __builtin_return_address(1));
+}
+
+
+// <rdar://problem/40352925> *_compat functions are for old binaries that have __dyld section and use it to bypass libdyld.dylib
+void* dlopen_compat(const char* path, int mode)
+{
+	return dlopen_internal(path, mode, (void*)dyld::mainExecutable()->machHeader());
+}
+bool  dlopen_preflight_compat(const char* path)
+{
+	return dlopen_preflight_internal(path, (void*)dyld::mainExecutable()->machHeader());
+}
+void* dlsym_compat(void* handle, const char* symbolName)
+{
+	return dlsym_internal(handle, symbolName, (void*)dyld::mainExecutable()->machHeader());
+}
 
 
 
@@ -1902,6 +2058,8 @@
 {
 	//if ( dyld::gLogAPIs )
 	//	dyld::log("%s(%p, %p)\n", __func__, addr, info);
+
+	addr = stripPointer(addr);
 	
 #if SUPPORT_ACCELERATE_TABLES
 	if ( dyld::findUnwindSections(addr, info) )
@@ -1922,6 +2080,8 @@
 	if ( dyld::gLogAPIs )
 		dyld::log("%s(%p)\n", __func__, address);
 
+    address = (void*)stripPointer(address);
+    
 #if SUPPORT_ACCELERATE_TABLES
 	const mach_header* mh;
 	const char* path;
@@ -2030,5 +2190,38 @@
 	return nullptr;
 }
 
-
-
+void _dyld_images_for_addresses(unsigned count, const void* addresses[], struct dyld_image_uuid_offset infos[])
+{
+	for (unsigned i=0; i < count; ++i) {
+        const void* addr = addresses[i];
+		addr = stripPointer(addr);
+        bzero(&infos[i], sizeof(dyld_image_uuid_offset));
+#if SUPPORT_ACCELERATE_TABLES
+		const mach_header* 	mh;
+		const char* 		path;
+		if ( dyld::addressInCache(addr, &mh, &path) ) {
+			infos[i].image         = mh;
+			infos[i].offsetInImage = (uintptr_t)addr - (uintptr_t)mh;
+			((dyld3::MachOFile*)mh)->getUuid(infos[i].uuid);
+			break;
+		}
+#endif
+		ImageLoader* image = dyld::findImageContainingAddress(addr);
+        if ( image != nullptr ) {
+            infos[i].image         = image->machHeader();
+            infos[i].offsetInImage = (uintptr_t)addr - (uintptr_t)(image->machHeader());
+            image->getUUID(infos[i].uuid);
+        }
+    }
+}
+
+void _dyld_register_for_image_loads(void (*func)(const mach_header* mh, const char* path, bool unloadable))
+{
+	if ( dyld::gLogAPIs )
+		dyld::log("%s(%p)\n", __func__, (void *)func);
+	dyld::registerLoadCallback(func);
+}
+
+
+
+