Loading...
libsa/bootstrap.cpp xnu-4570.71.2 xnu-1504.7.4
--- xnu/xnu-4570.71.2/libsa/bootstrap.cpp
+++ xnu/xnu-1504.7.4/libsa/bootstrap.cpp
@@ -1,5 +1,5 @@
 /*
- * Copyright (c) 2000-2012 Apple Inc. All rights reserved.
+ * Copyright (c) 2000 Apple Inc. All rights reserved.
  *
  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
  * 
@@ -29,10 +29,6 @@
 #include <mach/kmod.h>
 #include <libkern/kernel_mach_header.h>
 #include <libkern/prelink.h>
-
-#if CONFIG_EMBEDDED
-extern uuid_t kernelcache_uuid;
-#endif
 }
 
 #include <libkern/version.h>
@@ -40,13 +36,9 @@
 #include <libkern/OSKextLibPrivate.h>
 #include <libkern/c++/OSKext.h>
 #include <IOKit/IOLib.h>
-#include <IOKit/IOService.h>
+#include <IOKit/IORegistryEntry.h>
 #include <IOKit/IODeviceTreeSupport.h>
 #include <IOKit/IOCatalogue.h>
-
-#if __x86_64__
-#define KASLR_KEXT_DEBUG 0
-#endif
 
 #if PRAGMA_MARK
 #pragma mark Bootstrap Declarations
@@ -73,11 +65,6 @@
 
 static void bootstrapRecordStartupExtensions(void);
 static void bootstrapLoadSecurityExtensions(void);
-
-
-#if NO_KEXTD
-extern "C" bool IORamDiskBSDRoot(void);
-#endif
 
 #if PRAGMA_MARK
 #pragma mark Macros
@@ -112,27 +99,21 @@
    "com.apple.driver.AppleNMI",
    "com.apple.iokit.IOSystemManagementFamily",
    "com.apple.iokit.ApplePlatformFamily",
+   
+#if defined(__ppc__) || defined(__i386__) || defined(__arm__)
+   /* These ones are not supported on x86_64 or any newer platforms.
+    * They must be version 7.9.9; check by "com.apple.kernel.", with
+    * the trailing period; "com.apple.kernel" always represents the
+    * current kernel version.
+    */
+    "com.apple.kernel.6.0",
+    "com.apple.kernel.bsd",
+    "com.apple.kernel.iokit",
+    "com.apple.kernel.libkern",
+    "com.apple.kernel.mach",
+#endif
+
    NULL
-};
-
-static int __whereIsAddr(vm_offset_t theAddr, unsigned long * segSizes, vm_offset_t *segAddrs, int segCount );
-
-#define PLK_SEGMENTS 12
-
-static const char * plk_segNames[] = {
-    "__TEXT",
-    "__TEXT_EXEC",
-    "__DATA",
-    "__DATA_CONST",
-    "__LINKEDIT",
-    "__PRELINK_TEXT",
-    "__PLK_TEXT_EXEC",
-    "__PRELINK_DATA",
-    "__PLK_DATA_CONST",
-    "__PLK_LLVM_COV",
-    "__PLK_LINKEDIT",
-    "__PRELINK_INFO",
-    NULL
 };
 
 #if PRAGMA_MARK
@@ -155,9 +136,11 @@
     void readPrelinkedExtensions(
         kernel_section_t * prelinkInfoSect);
     void readBooterExtensions(void);
+    OSReturn readMkextExtensions(
+        OSString * deviceTreeName,
+        OSData   * deviceTreeData);
     
     OSReturn loadKernelComponentKexts(void);
-    void     loadKernelExternalComponents(void);
     void     readBuiltinPersonalities(void);
 
     void     loadSecurityExtensions(void);
@@ -180,6 +163,7 @@
     }
     record_startup_extensions_function = &bootstrapRecordStartupExtensions;
     load_security_extensions_function = &bootstrapLoadSecurityExtensions;
+    OSKext::initialize();
 }
 
 /*********************************************************************
@@ -191,8 +175,6 @@
     if (this != &sBootstrapObject) {
         panic("Attempt to access bootstrap segment.");
     }
-
-
     record_startup_extensions_function = 0;
     load_security_extensions_function = 0;
 }
@@ -223,17 +205,11 @@
     }
 
     loadKernelComponentKexts();
-    loadKernelExternalComponents();
     readBuiltinPersonalities();
     OSKext::sendAllKextPersonalitiesToCatalog();
 
     return;
 }
-
-typedef struct kaslrPackedOffsets {
-    uint32_t 	count;              /* number of offsets */
-    uint32_t 	offsetsArray[];     /* offsets to slide */
-} kaslrPackedOffsets;
 
 /*********************************************************************
 *********************************************************************/
@@ -242,14 +218,16 @@
     kernel_section_t * prelinkInfoSect)
 {
     OSArray                   * infoDictArray           = NULL;  // do not release
+    OSArray                   * personalitiesArray      = NULL;  // do not release
     OSObject                  * parsedXML       = NULL;  // must release
     OSDictionary              * prelinkInfoDict         = NULL;  // do not release
     OSString                  * errorString             = NULL;  // must release
     OSKext                    * theKernel               = NULL;  // must release
-#if CONFIG_EMBEDDED
-    OSData                    * kernelcacheUUID         = NULL;  // do not release
+
+#if CONFIG_KXLD
+    kernel_section_t          * kernelLinkStateSection  = NULL;  // see code
 #endif
-
+    kernel_segment_command_t  * prelinkLinkStateSegment = NULL;  // see code
     kernel_segment_command_t  * prelinkTextSegment      = NULL;  // see code
     kernel_segment_command_t  * prelinkInfoSegment      = NULL;  // see code
 
@@ -257,8 +235,13 @@
     * going to fail the boot, so these won't be cleaned up on error.
     */
     void                      * prelinkData             = NULL;  // see code
+    void                      * prelinkCopy             = NULL;  // see code
     vm_size_t                   prelinkLength           = 0;
-
+#if !__LP64__ && !defined(__arm__)
+    vm_map_offset_t             prelinkDataMapOffset    = 0;
+#endif
+
+    kern_return_t               mem_result              = KERN_SUCCESS;
 
     OSDictionary              * infoDict                = NULL;  // do not release
 
@@ -266,20 +249,63 @@
     OSNumber                  * prelinkCountObj         = NULL;  // must release
 
     u_int                       i = 0;
-#if NO_KEXTD
-    bool                        ramDiskBoot;
-    bool                        developerDevice;
-    bool                        dontLoad;
-#endif
-    OSData                     * kaslrOffsets = NULL;
-    unsigned long               plk_segSizes[PLK_SEGMENTS];
-    vm_offset_t                 plk_segAddrs[PLK_SEGMENTS];
 
     OSKextLog(/* kext */ NULL,
         kOSKextLogProgressLevel |
         kOSKextLogDirectoryScanFlag | kOSKextLogArchiveFlag,
         "Starting from prelinked kernel.");
 
+   /*****
+    * Wrap the kernel link state in-place in an OSData.
+    * This is unnecessary (and the link state may not be present) if the kernel
+    * does not have kxld support because this information is only used for
+    * runtime linking.
+    */
+#if CONFIG_KXLD
+    kernelLinkStateSection = getsectbyname(kPrelinkLinkStateSegment,
+        kPrelinkKernelLinkStateSection);
+    if (!kernelLinkStateSection) {
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogErrorLevel |
+            kOSKextLogArchiveFlag,
+            "Can't find prelinked kernel link state.");
+        goto finish;
+    }
+
+    theKernel = OSKext::lookupKextWithIdentifier(kOSKextKernelIdentifier);
+    if (!theKernel) {
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogErrorLevel |
+            kOSKextLogArchiveFlag,
+            "Can't find kernel kext object in prelinked kernel.");
+        goto finish;
+    }
+
+    prelinkData = (void *) kernelLinkStateSection->addr;
+    prelinkLength = kernelLinkStateSection->size;
+
+    mem_result = kmem_alloc_pageable(kernel_map,
+        (vm_offset_t *) &prelinkCopy, prelinkLength);
+    if (mem_result != KERN_SUCCESS) {
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogErrorLevel |
+            kOSKextLogGeneralFlag | kOSKextLogArchiveFlag,
+            "Can't copy prelinked kernel link state.");
+        goto finish;
+    }
+    memcpy(prelinkCopy, prelinkData, prelinkLength);
+
+    theKernel->linkState = OSData::withBytesNoCopy(prelinkCopy, prelinkLength);
+    if (!theKernel->linkState) {
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogErrorLevel |
+            kOSKextLogGeneralFlag | kOSKextLogArchiveFlag,
+            "Can't create prelinked kernel link state wrapper.");
+        goto finish;
+    }
+    theKernel->linkState->setDeallocFunction(osdata_kmem_free);
+#endif
+
     prelinkTextSegment = getsegbyname(kPrelinkTextSegment);
     if (!prelinkTextSegment) {
         OSKextLog(/* kext */ NULL,
@@ -289,60 +315,67 @@
         goto finish;
     }
 
-#if KASLR_KEXT_DEBUG
-    unsigned long   scratchSize;
-    vm_offset_t     scratchAddr;
-    
-    IOLog("kaslr: prelinked kernel address info: \n");
-    
-    scratchAddr = (vm_offset_t) getsegdatafromheader(&_mh_execute_header, "__TEXT", &scratchSize);
-    IOLog("kaslr: start 0x%lx end 0x%lx length %lu for __TEXT \n", 
-          (unsigned long)scratchAddr, 
-          (unsigned long)(scratchAddr + scratchSize),
-          scratchSize);
-    
-    scratchAddr = (vm_offset_t) getsegdatafromheader(&_mh_execute_header, "__DATA", &scratchSize);
-    IOLog("kaslr: start 0x%lx end 0x%lx length %lu for __DATA \n", 
-          (unsigned long)scratchAddr, 
-          (unsigned long)(scratchAddr + scratchSize),
-          scratchSize);
-    
-    scratchAddr = (vm_offset_t) getsegdatafromheader(&_mh_execute_header, "__LINKEDIT", &scratchSize);
-    IOLog("kaslr: start 0x%lx end 0x%lx length %lu for __LINKEDIT \n", 
-          (unsigned long)scratchAddr, 
-          (unsigned long)(scratchAddr + scratchSize),
-          scratchSize);
-    
-    scratchAddr = (vm_offset_t) getsegdatafromheader(&_mh_execute_header, "__KLD", &scratchSize);
-    IOLog("kaslr: start 0x%lx end 0x%lx length %lu for __KLD \n", 
-          (unsigned long)scratchAddr, 
-          (unsigned long)(scratchAddr + scratchSize),
-          scratchSize);
-    
-    scratchAddr = (vm_offset_t) getsegdatafromheader(&_mh_execute_header, "__PRELINK_TEXT", &scratchSize);
-    IOLog("kaslr: start 0x%lx end 0x%lx length %lu for __PRELINK_TEXT \n", 
-          (unsigned long)scratchAddr, 
-          (unsigned long)(scratchAddr + scratchSize),
-          scratchSize);
-    
-    scratchAddr = (vm_offset_t) getsegdatafromheader(&_mh_execute_header, "__PRELINK_INFO", &scratchSize);
-    IOLog("kaslr: start 0x%lx end 0x%lx length %lu for __PRELINK_INFO \n", 
-          (unsigned long)scratchAddr, 
-          (unsigned long)(scratchAddr + scratchSize),
-          scratchSize);
-#endif
-
     prelinkData = (void *) prelinkTextSegment->vmaddr;
     prelinkLength = prelinkTextSegment->vmsize;
 
-    /* build arrays of plk info for later use */
-    const char ** segNamePtr;
-
-    for (segNamePtr = &plk_segNames[0], i = 0; *segNamePtr && i < PLK_SEGMENTS; segNamePtr++, i++) {
-        plk_segSizes[i] = 0;
-        plk_segAddrs[i] = (vm_offset_t)getsegdatafromheader(&_mh_execute_header, *segNamePtr, &plk_segSizes[i]);
-    }
-
+#if !__LP64__
+    /* To enable paging and write/execute protections on the kext
+     * executables, we need to copy them out of the booter-created
+     * memory, reallocate that space with VM, then prelinkCopy them back in.
+     * This isn't necessary on LP64 because kexts have their own VM
+     * region on that architecture model.
+     */
+
+    mem_result = kmem_alloc(kernel_map, (vm_offset_t *)&prelinkCopy,
+        prelinkLength);
+    if (mem_result != KERN_SUCCESS) {
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogErrorLevel |
+            kOSKextLogGeneralFlag | kOSKextLogArchiveFlag,
+            "Can't copy prelinked kexts' text for VM reassign.");
+        goto finish;
+    }
+
+   /* Copy it out.
+    */
+    memcpy(prelinkCopy, prelinkData, prelinkLength);
+    
+   /* Dump the booter memory.
+    */
+    ml_static_mfree((vm_offset_t)prelinkData, prelinkLength);
+
+   /* Set up the VM region.
+    */
+    prelinkDataMapOffset = (vm_map_offset_t)(uintptr_t)prelinkData;
+    mem_result = vm_map_enter_mem_object(
+        kernel_map,
+        &prelinkDataMapOffset,
+        prelinkLength, /* mask */ 0, 
+        VM_FLAGS_FIXED | VM_FLAGS_OVERWRITE, 
+        (ipc_port_t)NULL,
+        (vm_object_offset_t) 0,
+        /* copy */ FALSE,
+        /* cur_protection */ VM_PROT_ALL,
+        /* max_protection */ VM_PROT_ALL,
+        /* inheritance */ VM_INHERIT_DEFAULT);
+    if ((mem_result != KERN_SUCCESS) || 
+        (prelinkTextSegment->vmaddr != prelinkDataMapOffset)) 
+    {
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogErrorLevel |
+            kOSKextLogGeneralFlag | kOSKextLogArchiveFlag,
+            "Can't create kexts' text VM entry at 0x%llx, length 0x%x (error 0x%x).",
+            (unsigned long long) prelinkDataMapOffset, prelinkLength, mem_result);
+        goto finish;
+    }
+    prelinkData = (void *)(uintptr_t)prelinkDataMapOffset;
+
+   /* And copy it back.
+    */
+    memcpy(prelinkData, prelinkCopy, prelinkLength);
+
+    kmem_free(kernel_map, (vm_offset_t)prelinkCopy, prelinkLength);
+#endif /* !__LP64__ */
 
    /* Unserialize the info dictionary from the prelink info section.
     */
@@ -363,30 +396,6 @@
             "Error unserializing prelink plist: %s.", errorCString);
         goto finish;
     }
-
-#if NO_KEXTD
-    /* Check if we should keep developer kexts around.
-     * TODO: Check DeviceTree instead of a boot-arg <rdar://problem/10604201>
-     */
-    developerDevice = true;
-    PE_parse_boot_argn("developer", &developerDevice, sizeof(developerDevice));
-
-    ramDiskBoot = IORamDiskBSDRoot();
-#endif /* NO_KEXTD */
-
-#if CONFIG_EMBEDDED
-    /* Copy in the kernelcache UUID */
-    kernelcacheUUID = OSDynamicCast(OSData,
-        prelinkInfoDict->getObject(kPrelinkInfoKCIDKey));
-    if (!kernelcacheUUID) {
-	bzero(&kernelcache_uuid, sizeof(kernelcache_uuid));
-    } else if (kernelcacheUUID->getLength() != sizeof(kernelcache_uuid)) {
-        panic("kernelcacheUUID length is %d, expected %lu", kernelcacheUUID->getLength(),
-            sizeof(kernelcache_uuid));
-    } else {
-        memcpy((void *)&kernelcache_uuid, (const void *)kernelcacheUUID->getBytesNoCopy(), kernelcacheUUID->getLength());
-    }
-#endif /* CONFIG_EMBEDDED */
 
     infoDictArray = OSDynamicCast(OSArray, 
         prelinkInfoDict->getObject(kPrelinkInfoDictionaryKey));
@@ -395,18 +404,9 @@
             "The prelinked kernel has no kext info dictionaries");
         goto finish;
     }
-    
-    /* kaslrOffsets are available use them to slide local relocations */
-    kaslrOffsets = OSDynamicCast(OSData,
-                                 prelinkInfoDict->getObject(kPrelinkLinkKASLROffsetsKey));
-        
-    /* Create dictionary of excluded kexts
-     */
-#ifndef CONFIG_EMBEDDED
-    OSKext::createExcludeListFromPrelinkInfo(infoDictArray);
-#endif
-    /* Create OSKext objects for each info dictionary. 
-     */
+
+   /* Create OSKext objects for each info dictionary.
+    */
     for (i = 0; i < infoDictArray->getCount(); ++i) {
         infoDict = OSDynamicCast(OSDictionary, infoDictArray->getObject(i));
         if (!infoDict) {
@@ -417,99 +417,27 @@
             continue;
         }
 
-#if NO_KEXTD
-        dontLoad = false;
-
-        /* If we're not on a developer device, skip and free developer kexts.
-         */
-        if (developerDevice == false) {
-            OSBoolean *devOnlyBool = OSDynamicCast(OSBoolean,
-                infoDict->getObject(kOSBundleDeveloperOnlyKey));
-            if (devOnlyBool == kOSBooleanTrue) {
-                dontLoad = true;
-            }
-        }
-
-        /* Skip and free kexts that are only needed when booted from a ram disk.
-         */
-        if (ramDiskBoot == false) {
-            OSBoolean *ramDiskOnlyBool = OSDynamicCast(OSBoolean,
-                infoDict->getObject(kOSBundleRamDiskOnlyKey));
-            if (ramDiskOnlyBool == kOSBooleanTrue) {
-                dontLoad = true;
-            }
-        }
-
-        if (dontLoad == true) {
-            OSString *bundleID = OSDynamicCast(OSString,
-                infoDict->getObject(kCFBundleIdentifierKey));
-            if (bundleID) {
-                OSKextLog(NULL, kOSKextLogWarningLevel | kOSKextLogGeneralFlag,
-                    "Kext %s not loading.", bundleID->getCStringNoCopy());
-            }
-            
-            OSNumber *addressNum = OSDynamicCast(OSNumber,
-                infoDict->getObject(kPrelinkExecutableLoadKey));
-            OSNumber *lengthNum = OSDynamicCast(OSNumber,
-                infoDict->getObject(kPrelinkExecutableSizeKey));
-            if (addressNum && lengthNum) {
-#if __arm__ || __arm64__
-                vm_offset_t data = (vm_offset_t) ((addressNum->unsigned64BitValue()) + vm_kernel_slide);
-                vm_size_t length = (vm_size_t) (lengthNum->unsigned32BitValue());
-                ml_static_mfree(data, length);
-#else
-#error Pick the right way to free prelinked data on this arch
-#endif
-            }
-
-            infoDictArray->removeObject(i--);
-            continue;
-        }
-#endif /* NO_KEXTD */
-
        /* Create the kext for the entry, then release it, because the
         * kext system keeps them around until explicitly removed.
         * Any creation/registration failures are already logged for us.
         */
-        OSKext * newKext = OSKext::withPrelinkedInfoDict(infoDict, (kaslrOffsets ? TRUE : FALSE));
+        OSKext * newKext = OSKext::withPrelinkedInfoDict(infoDict);
         OSSafeReleaseNULL(newKext);
     }
-
-    /* slide kxld relocations */
-    if (kaslrOffsets && vm_kernel_slide > 0) {
-	    int slidKextAddrCount = 0;
-	    int badSlideAddr = 0;
-	    int badSlideTarget = 0;
-
-        const kaslrPackedOffsets * myOffsets = NULL;
-	    myOffsets = (const kaslrPackedOffsets *) kaslrOffsets->getBytesNoCopy();
-
-	    for (uint32_t j = 0; j < myOffsets->count; j++) {
-
-		    uint64_t        slideOffset = (uint64_t) myOffsets->offsetsArray[j];
-		    uintptr_t *     slideAddr = (uintptr_t *) ((uint64_t)prelinkData + slideOffset);
-		    int             slideAddrSegIndex = -1;
-		    int             addrToSlideSegIndex = -1;
-
-		    slideAddrSegIndex = __whereIsAddr( (vm_offset_t)slideAddr, &plk_segSizes[0], &plk_segAddrs[0], PLK_SEGMENTS );
-		    if (slideAddrSegIndex >= 0) {
-			    addrToSlideSegIndex = __whereIsAddr( (vm_offset_t)(*slideAddr + vm_kernel_slide), &plk_segSizes[0], &plk_segAddrs[0], PLK_SEGMENTS );
-			    if (addrToSlideSegIndex < 0) {
-				    badSlideTarget++;
-				    continue;
-			    }
-		    }
-		    else {
-			    badSlideAddr++;
-			    continue;
-		    }
-
-		    slidKextAddrCount++;
-		    *(slideAddr) += vm_kernel_slide;
-	    } // for ...
-
-	    /* All kexts are now slid, set VM protections for them */
-	    OSKext::setAllVMAttributes();
+    
+    /* Get all of the personalities for kexts that were not prelinked and
+     * add them to the catalogue.
+     */
+    personalitiesArray = OSDynamicCast(OSArray,
+        prelinkInfoDict->getObject(kPrelinkPersonalitiesKey));
+    if (!personalitiesArray) {
+        OSKextLog(/* kext */ NULL, kOSKextLogErrorLevel | kOSKextLogArchiveFlag,
+            "The prelinked kernel has no personalities array");
+        goto finish;
+    }
+
+    if (personalitiesArray->getCount()) {
+        gIOCatalogue->addDrivers(personalitiesArray);
     }
 
    /* Store the number of prelinked kexts in the registry so we can tell
@@ -525,21 +453,37 @@
     if (prelinkCountObj) {
         registryRoot->setProperty(kOSPrelinkKextCountKey, prelinkCountObj);
     }
-    
+
+    OSSafeReleaseNULL(prelinkCountObj);
+    prelinkCountObj = OSNumber::withNumber(
+        (unsigned long long)personalitiesArray->getCount(),
+        8 * sizeof(uint32_t));
+    assert(prelinkCountObj);
+    if (prelinkCountObj) {
+        registryRoot->setProperty(kOSPrelinkPersonalityCountKey, prelinkCountObj);
+    }
+
     OSKextLog(/* kext */ NULL,
         kOSKextLogProgressLevel |
         kOSKextLogGeneralFlag | kOSKextLogKextBookkeepingFlag |
         kOSKextLogDirectoryScanFlag | kOSKextLogArchiveFlag,
-        "%u prelinked kexts", 
-        infoDictArray->getCount());
-
-#if CONFIG_KEXT_BASEMENT
-        /* On CONFIG_KEXT_BASEMENT systems, kexts are copied to their own 
-         * special VM region during OSKext init time, so we can free the whole 
-         * segment now.
+        "%u prelinked kexts, and %u additional personalities.", 
+        infoDictArray->getCount(), personalitiesArray->getCount());
+
+#if __LP64__
+        /* On LP64 systems, kexts are copied to their own special VM region
+         * during OSKext init time, so we can free the whole segment now.
          */
         ml_static_mfree((vm_offset_t) prelinkData, prelinkLength);
-#endif /* __x86_64__ */
+#endif /* __LP64__ */
+
+   /* Free the link state segment, kexts have copied out what they need.
+    */
+    prelinkLinkStateSegment = getsegbyname(kPrelinkLinkStateSegment);
+    if (prelinkLinkStateSegment) {
+        ml_static_mfree((vm_offset_t)prelinkLinkStateSegment->vmaddr,
+            (vm_size_t)prelinkLinkStateSegment->vmsize);
+    }
 
    /* Free the prelink info segment, we're done with it.
     */
@@ -550,33 +494,17 @@
     }
 
 finish:
-    OSSafeReleaseNULL(errorString);
-    OSSafeReleaseNULL(parsedXML);
-    OSSafeReleaseNULL(theKernel);
-    OSSafeReleaseNULL(prelinkCountObj);
+    OSSafeRelease(errorString);
+    OSSafeRelease(parsedXML);
+    OSSafeRelease(theKernel);
+    OSSafeRelease(prelinkCountObj);
     return;
 }
 
-static int __whereIsAddr(vm_offset_t theAddr, unsigned long * segSizes, vm_offset_t *segAddrs, int segCount)
-{
-	int i;
-
-	for (i = 0; i < segCount; i++) {
-		vm_offset_t         myAddr = *(segAddrs + i);
-		unsigned long       mySize = *(segSizes + i);
-
-		if (theAddr >= myAddr && theAddr < (myAddr + mySize)) {
-			return i;
-		}
-	}
-
-	return -1;
-}
-
-
 /*********************************************************************
 *********************************************************************/
 #define BOOTER_KEXT_PREFIX   "Driver-"
+#define BOOTER_MKEXT_PREFIX  "DriversPackage-"
 
 typedef struct _DeviceTreeBuffer {
     uint32_t paddr;
@@ -600,7 +528,7 @@
     OSKextLog(/* kext */ NULL,
         kOSKextLogProgressLevel |
         kOSKextLogDirectoryScanFlag | kOSKextLogKextBookkeepingFlag,
-        "Reading startup extensions from booter memory.");
+        "Reading startup extensions/mkexts from booter memory.");
     
     booterMemoryMap = IORegistryEntry::fromPath( "/chosen/memory-map", gIODTPlane);
 
@@ -630,16 +558,10 @@
         goto finish;
     }
 
-    /* Create dictionary of excluded kexts
-     */
-#ifndef CONFIG_EMBEDDED
-    OSKext::createExcludeListFromBooterData(propertyDict, keyIterator);
-#endif
-    keyIterator->reset();
-
     while ( ( deviceTreeName =
         OSDynamicCast(OSString, keyIterator->getNextObject() ))) {
 
+        boolean_t isMkext = FALSE;
         const char * devTreeNameCString = deviceTreeName->getCStringNoCopy();
         OSData * deviceTreeEntry = OSDynamicCast(OSData,
             propertyDict->getObject(deviceTreeName));
@@ -653,10 +575,18 @@
             continue;
         }
 
-        /* Make sure it is a kext */
-        if (strncmp(devTreeNameCString,
-                    BOOTER_KEXT_PREFIX,
-                    CONST_STRLEN(BOOTER_KEXT_PREFIX))) {
+        /* Make sure it is either a kext or an mkext */
+        if (!strncmp(devTreeNameCString, BOOTER_KEXT_PREFIX,
+            CONST_STRLEN(BOOTER_KEXT_PREFIX))) {
+
+            isMkext = FALSE;
+
+        } else if (!strncmp(devTreeNameCString, BOOTER_MKEXT_PREFIX,
+            CONST_STRLEN(BOOTER_MKEXT_PREFIX))) {
+
+            isMkext = TRUE;
+
+        } else {
             continue;
         }
 
@@ -679,7 +609,7 @@
             OSKextLog(/* kext */ NULL,
                 kOSKextLogErrorLevel |
                 kOSKextLogDirectoryScanFlag,
-                "Can't get virtual address for device tree entry %s.",
+                "Can't get virtual address for device tree mkext entry %s.",
                 devTreeNameCString);
             goto finish;
         }
@@ -701,12 +631,16 @@
         }
         booterData->setDeallocFunction(osdata_phys_free);
 
-        /* Create the kext for the entry, then release it, because the
-         * kext system keeps them around until explicitly removed.
-         * Any creation/registration failures are already logged for us.
-         */
-        OSKext * newKext = OSKext::withBooterData(deviceTreeName, booterData);
-        OSSafeReleaseNULL(newKext);
+        if (isMkext) {
+            readMkextExtensions(deviceTreeName, booterData);
+        } else {
+           /* Create the kext for the entry, then release it, because the
+            * kext system keeps them around until explicitly removed.
+            * Any creation/registration failures are already logged for us.
+            */
+            OSKext * newKext = OSKext::withBooterData(deviceTreeName, booterData);
+            OSSafeRelease(newKext);
+        }
 
         booterMemoryMap->removeProperty(deviceTreeName);
 
@@ -714,12 +648,55 @@
 
 finish:
 
-    OSSafeReleaseNULL(booterMemoryMap);
-    OSSafeReleaseNULL(propertyDict);
-    OSSafeReleaseNULL(keyIterator);
-    OSSafeReleaseNULL(booterData);
-    OSSafeReleaseNULL(aKext);
+    OSSafeRelease(booterMemoryMap);
+    OSSafeRelease(propertyDict);
+    OSSafeRelease(keyIterator);
+    OSSafeRelease(booterData);
+    OSSafeRelease(aKext);
     return;
+}
+
+/*********************************************************************
+*********************************************************************/
+OSReturn
+KLDBootstrap::readMkextExtensions(
+    OSString   * deviceTreeName,
+    OSData     * booterData)
+{
+    OSReturn result = kOSReturnError;
+
+    uint32_t          checksum;
+    IORegistryEntry * registryRoot = NULL;  // do not release
+    OSData          * checksumObj  = NULL;   // must release
+
+    OSKextLog(/* kext */ NULL,
+        kOSKextLogStepLevel |
+        kOSKextLogDirectoryScanFlag | kOSKextLogArchiveFlag,
+        "Reading startup mkext archive from device tree entry %s.",
+        deviceTreeName->getCStringNoCopy());
+
+   /* If we successfully read the archive,
+    * then save the mkext's checksum in the IORegistry.
+    * assumes we'll only ever have one mkext to boot
+    */
+    result = OSKext::readMkextArchive(booterData, &checksum);
+    if (result == kOSReturnSuccess) {
+
+        OSKextLog(/* kext */ NULL,
+            kOSKextLogProgressLevel |
+            kOSKextLogArchiveFlag,
+            "Startup mkext archive has checksum 0x%x.", (int)checksum);
+
+        registryRoot = IORegistryEntry::getRegistryRoot();
+        assert(registryRoot);
+        checksumObj = OSData::withBytes((void *)&checksum, sizeof(checksum));
+        assert(checksumObj);
+        if (checksumObj) {
+            registryRoot->setProperty(kOSStartupMkextCRC, checksumObj);
+        }
+    }
+    
+    return result;
 }
 
 /*********************************************************************
@@ -772,7 +749,7 @@
         }
 
         isSecurityKext = OSDynamicCast(OSBoolean,
-            theKext->getPropertyForHostArch(kAppleSecurityExtensionKey));
+            theKext->getPropertyForHostArch("AppleSecurityExtension"));
         if (isSecurityKext && isSecurityKext->isTrue()) {
             OSKextLog(/* kext */ NULL,
                 kOSKextLogStepLevel |
@@ -784,8 +761,8 @@
     }
 
 finish:
-    OSSafeReleaseNULL(keyIterator);
-    OSSafeReleaseNULL(extensionsDict);
+    OSSafeRelease(keyIterator);
+    OSSafeRelease(extensionsDict);
 
     return;
 }
@@ -827,82 +804,8 @@
         }
     }
 
-    OSSafeReleaseNULL(theKext);
+    OSSafeRelease(theKext);
     return result;
-}
-
-/*********************************************************************
-* Ensure that Kernel External Components are loaded early in boot,
-* before other kext personalities get sent to the IOCatalogue. These
-* kexts are treated specially because they may provide the implementation
-* for kernel-vended KPI, so they must register themselves before
-* general purpose IOKit probing begins.
-*********************************************************************/
-
-#define COM_APPLE_KEC  "com.apple.kec."
-
-void
-KLDBootstrap::loadKernelExternalComponents(void)
-{
-    OSDictionary         * extensionsDict = NULL;  // must release
-    OSCollectionIterator * keyIterator    = NULL;  // must release
-    OSString             * bundleID       = NULL;  // don't release
-    OSKext               * theKext        = NULL;  // don't release
-    OSBoolean            * isKernelExternalComponent = NULL;  // don't release
-
-    OSKextLog(/* kext */ NULL,
-        kOSKextLogStepLevel |
-        kOSKextLogLoadFlag,
-        "Loading Kernel External Components.");
-
-    extensionsDict = OSKext::copyKexts();
-    if (!extensionsDict) {
-        return;
-    }
-
-    keyIterator = OSCollectionIterator::withCollection(extensionsDict);
-    if (!keyIterator) {
-        OSKextLog(/* kext */ NULL,
-            kOSKextLogErrorLevel |
-            kOSKextLogGeneralFlag,
-            "Failed to allocate iterator for Kernel External Components.");
-        goto finish;
-    }
-
-    while ((bundleID = OSDynamicCast(OSString, keyIterator->getNextObject()))) {
-
-        const char * bundle_id = bundleID->getCStringNoCopy();
-        
-       /* Skip extensions whose bundle IDs don't start with "com.apple.kec.".
-        */
-        if (!bundle_id ||
-            (strncmp(bundle_id, COM_APPLE_KEC, CONST_STRLEN(COM_APPLE_KEC)) != 0)) {
-
-            continue;
-        }
-
-        theKext = OSDynamicCast(OSKext, extensionsDict->getObject(bundleID));
-        if (!theKext) {
-            continue;
-        }
-
-        isKernelExternalComponent = OSDynamicCast(OSBoolean,
-            theKext->getPropertyForHostArch(kAppleKernelExternalComponentKey));
-        if (isKernelExternalComponent && isKernelExternalComponent->isTrue()) {
-            OSKextLog(/* kext */ NULL,
-                kOSKextLogStepLevel |
-                kOSKextLogLoadFlag,
-                "Loading kernel external component %s.", bundleID->getCStringNoCopy());
-            OSKext::loadKextWithIdentifier(bundleID->getCStringNoCopy(),
-                /* allowDefer */ false);
-        }
-    }
-
-finish:
-    OSSafeReleaseNULL(keyIterator);
-    OSSafeReleaseNULL(extensionsDict);
-
-    return;
 }
 
 /*********************************************************************
@@ -1019,10 +922,10 @@
     gIOCatalogue->addDrivers(allPersonalities, false);
 
 finish:
-    OSSafeReleaseNULL(parsedXML);
-    OSSafeReleaseNULL(allPersonalities);
-    OSSafeReleaseNULL(errorString);
-    OSSafeReleaseNULL(personalitiesIterator);
+    OSSafeRelease(parsedXML);
+    OSSafeRelease(allPersonalities);
+    OSSafeRelease(errorString);
+    OSSafeRelease(personalitiesIterator);
     return;
 }
 
@@ -1043,4 +946,3 @@
     sBootstrapObject.loadSecurityExtensions();
     return;
 }
-