xref: /trueos/lib/liblaunch/libbootstrap.c (revision f2f653d61580d6639d1a7f839ad31ea61de7e4db)
1 /*
2  * Copyright (c) 1999-2005 Apple Computer, Inc. All rights reserved.
3  *
4  * @APPLE_APACHE_LICENSE_HEADER_START@
5  *
6  * Licensed under the Apache License, Version 2.0 (the "License");
7  * you may not use this file except in compliance with the License.
8  * You may obtain a copy of the License at
9  *
10  *     http://www.apache.org/licenses/LICENSE-2.0
11  *
12  * Unless required by applicable law or agreed to in writing, software
13  * distributed under the License is distributed on an "AS IS" BASIS,
14  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15  * See the License for the specific language governing permissions and
16  * limitations under the License.
17  *
18  * @APPLE_APACHE_LICENSE_HEADER_END@
19  */
20 
21 #include "config.h"
22 #include "launch.h"
23 #include "launch_priv.h"
24 #include "launch_internal.h"
25 #include "bootstrap.h"
26 #include "bootstrap_priv.h"
27 #include "vproc.h"
28 #include "vproc_priv.h"
29 
30 #include <mach/mach.h>
31 #include <mach/mach_port.h>
32 #include <sys/types.h>
33 #include <sys/syslog.h>
34 #include <sys/stat.h>
35 #include <pthread.h>
36 #include <stdlib.h>
37 
38 
39 #include "job.h"
40 
41 void
bootstrap_init(void)42 bootstrap_init(void)
43 {
44 	kern_return_t kr = task_get_special_port(task_self_trap(), TASK_BOOTSTRAP_PORT, &bootstrap_port);
45 	if (kr != KERN_SUCCESS) {
46 		abort();
47 	}
48 }
49 
50 kern_return_t
bootstrap_create_server(mach_port_t bp,cmd_t server_cmd,uid_t server_uid,boolean_t on_demand,mach_port_t * server_port)51 bootstrap_create_server(mach_port_t bp, cmd_t server_cmd, uid_t server_uid, boolean_t on_demand, mach_port_t *server_port)
52 {
53 	kern_return_t kr;
54 
55 	kr = vproc_mig_create_server(bp, server_cmd, server_uid, on_demand, server_port);
56 
57 	if (kr == VPROC_ERR_TRY_PER_USER) {
58 		mach_port_t puc;
59 
60 		if (vproc_mig_lookup_per_user_context(bp, 0, &puc) == 0) {
61 			kr = vproc_mig_create_server(puc, server_cmd, server_uid, on_demand, server_port);
62 			mach_port_deallocate(mach_task_self(), puc);
63 		}
64 	}
65 
66 	return kr;
67 }
68 
69 kern_return_t
bootstrap_subset(mach_port_t bp,mach_port_t requestor_port,mach_port_t * subset_port)70 bootstrap_subset(mach_port_t bp, mach_port_t requestor_port, mach_port_t *subset_port)
71 {
72 	return vproc_mig_subset(bp, requestor_port, subset_port);
73 }
74 
75 kern_return_t
bootstrap_unprivileged(mach_port_t bp,mach_port_t * unpriv_port)76 bootstrap_unprivileged(mach_port_t bp, mach_port_t *unpriv_port)
77 {
78 	kern_return_t kr;
79 
80 	*unpriv_port = MACH_PORT_NULL;
81 
82 	kr = mach_port_mod_refs(mach_task_self(), bp, MACH_PORT_RIGHT_SEND, 1);
83 
84 	if (kr == KERN_SUCCESS) {
85 		*unpriv_port = bp;
86 	}
87 
88 	return kr;
89 }
90 
91 kern_return_t
bootstrap_parent(mach_port_t bp,mach_port_t * parent_port)92 bootstrap_parent(mach_port_t bp, mach_port_t *parent_port)
93 {
94 	return vproc_mig_parent(bp, parent_port);
95 }
96 
97 kern_return_t
bootstrap_register(mach_port_t bp,name_t service_name,mach_port_t sp)98 bootstrap_register(mach_port_t bp, name_t service_name, mach_port_t sp)
99 {
100 	return bootstrap_register2(bp, service_name, sp, 0);
101 }
102 
103 kern_return_t
bootstrap_register2(mach_port_t bp,name_t service_name,mach_port_t sp,uint64_t flags)104 bootstrap_register2(mach_port_t bp, name_t service_name, mach_port_t sp, uint64_t flags)
105 {
106 	kern_return_t kr = vproc_mig_register2(bp, service_name, sp, flags);
107 
108 	if (kr == VPROC_ERR_TRY_PER_USER) {
109 		mach_port_t puc;
110 
111 		if (vproc_mig_lookup_per_user_context(bp, 0, &puc) == 0) {
112 			kr = vproc_mig_register2(puc, service_name, sp, flags);
113 			mach_port_deallocate(mach_task_self(), puc);
114 		}
115 	}
116 
117 	return kr;
118 }
119 
120 kern_return_t
bootstrap_create_service(mach_port_t bp,name_t service_name,mach_port_t * sp)121 bootstrap_create_service(mach_port_t bp, name_t service_name, mach_port_t *sp)
122 {
123 	kern_return_t kr;
124 
125 	if ((kr = bootstrap_check_in(bp, service_name, sp))) {
126 		return kr;
127 	}
128 
129 	if ((kr = mach_port_mod_refs(mach_task_self(), *sp, MACH_PORT_RIGHT_RECEIVE, -1))) {
130 		return kr;
131 	}
132 
133 	return bootstrap_look_up(bp, service_name, sp);
134 }
135 
136 kern_return_t
bootstrap_check_in(mach_port_t bp,const name_t service_name,mach_port_t * sp)137 bootstrap_check_in(mach_port_t bp, const name_t service_name, mach_port_t *sp)
138 {
139 	uuid_t junk;
140 	(void)bzero(junk, sizeof(junk));
141 	return vproc_mig_check_in2(bp, (char *)service_name, sp, junk, 0);
142 }
143 
144 kern_return_t
bootstrap_check_in2(mach_port_t bp,const name_t service_name,mach_port_t * sp,uint64_t flags)145 bootstrap_check_in2(mach_port_t bp, const name_t service_name, mach_port_t *sp, uint64_t flags)
146 {
147 	uuid_t junk;
148 	(void)bzero(junk, sizeof(junk));
149 	return vproc_mig_check_in2(bp, (char *)service_name, sp, junk, flags);
150 }
151 
152 kern_return_t
bootstrap_look_up_per_user(mach_port_t bp,const name_t service_name,uid_t target_user,mach_port_t * sp)153 bootstrap_look_up_per_user(mach_port_t bp, const name_t service_name, uid_t target_user, mach_port_t *sp)
154 {
155 	audit_token_t au_tok;
156 	kern_return_t kr;
157 	mach_port_t puc;
158 
159 	/* See rdar://problem/4890134. */
160 
161 	if ((kr = vproc_mig_lookup_per_user_context(bp, target_user, &puc)) != 0) {
162 		return kr;
163 	}
164 
165 	if (!service_name) {
166 		*sp = puc;
167 	} else {
168 		uuid_t junk;
169 		kr = vproc_mig_look_up2(puc, (char *)service_name, sp, &au_tok, 0, junk, 0);
170 		mach_port_deallocate(mach_task_self(), puc);
171 	}
172 
173 	return kr;
174 }
175 
176 kern_return_t
bootstrap_lookup_children(mach_port_t bp,mach_port_array_t * children,name_array_t * names,bootstrap_property_array_t * properties,mach_msg_type_number_t * n_children)177 bootstrap_lookup_children(mach_port_t bp, mach_port_array_t *children, name_array_t *names, bootstrap_property_array_t *properties, mach_msg_type_number_t *n_children)
178 {
179 	mach_msg_type_number_t junk = 0;
180 	return vproc_mig_lookup_children(bp, children, &junk, names, n_children, properties, &junk);
181 }
182 
183 kern_return_t
bootstrap_look_up(mach_port_t bp,const name_t service_name,mach_port_t * sp)184 bootstrap_look_up(mach_port_t bp, const name_t service_name, mach_port_t *sp)
185 {
186 	return bootstrap_look_up2(bp, service_name, sp, 0, 0);
187 }
188 
189 kern_return_t
bootstrap_look_up2(mach_port_t bp,const name_t service_name,mach_port_t * sp,pid_t target_pid,uint64_t flags)190 bootstrap_look_up2(mach_port_t bp, const name_t service_name, mach_port_t *sp, pid_t target_pid, uint64_t flags)
191 {
192 	uuid_t instance_id;
193 	return bootstrap_look_up3(bp, service_name, sp, target_pid, instance_id, flags);
194 }
195 
196 kern_return_t
bootstrap_look_up3(mach_port_t bp,const name_t service_name,mach_port_t * sp,pid_t target_pid,const uuid_t instance_id,uint64_t flags)197 bootstrap_look_up3(mach_port_t bp, const name_t service_name, mach_port_t *sp, pid_t target_pid, const uuid_t instance_id, uint64_t flags)
198 {
199 	audit_token_t au_tok;
200 	bool privileged_server_lookup = flags & BOOTSTRAP_PRIVILEGED_SERVER;
201 	kern_return_t kr = 0;
202 	mach_port_t puc;
203 
204 	// We have to cast instance_id here because the MIG-generated method
205 	// doesn't expect a const parameter.
206 	if ((kr = vproc_mig_look_up2(bp, (char *)service_name, sp, &au_tok, target_pid, (unsigned char*)instance_id, flags)) != VPROC_ERR_TRY_PER_USER) {
207 		goto out;
208 	}
209 
210 	if ((kr = vproc_mig_lookup_per_user_context(bp, 0, &puc)) != 0) {
211 		goto out;
212 	}
213 
214 	kr = vproc_mig_look_up2(puc, (char *)service_name, sp, &au_tok, target_pid, (unsigned char*)instance_id, flags);
215 	mach_port_deallocate(mach_task_self(), puc);
216 
217 out:
218 	if ((kr == 0) && privileged_server_lookup) {
219 		uid_t server_euid;
220 
221 		/*
222 		 * The audit token magic is dependent on the per-user launchd
223 		 * forwarding MIG requests to the root launchd when it cannot
224 		 * find the answer locally.
225 		 */
226 
227 		/* This API should be in Libsystem, but is not */
228 		//audit_token_to_au32(au_tok, NULL, &server_euid, NULL, NULL, NULL, NULL, NULL, NULL);
229 
230 		server_euid = au_tok.val[1];
231 
232 		if (server_euid) {
233 			mach_port_deallocate(mach_task_self(), *sp);
234 			*sp = MACH_PORT_NULL;
235 			kr = BOOTSTRAP_NOT_PRIVILEGED;
236 		}
237 	}
238 
239 	return kr;
240 }
241 
242 kern_return_t
bootstrap_check_in3(mach_port_t bp,const name_t service_name,mach_port_t * sp,uuid_t instance_id,uint64_t flags)243 bootstrap_check_in3(mach_port_t bp, const name_t service_name, mach_port_t *sp, uuid_t instance_id, uint64_t flags)
244 {
245 	return vproc_mig_check_in2(bp, (char *)service_name, sp, instance_id, flags);
246 }
247 
248 kern_return_t
bootstrap_get_root(mach_port_t bp,mach_port_t * root)249 bootstrap_get_root(mach_port_t bp, mach_port_t *root)
250 {
251 	return vproc_mig_get_root_bootstrap(bp, root);
252 }
253 
254 kern_return_t
bootstrap_status(mach_port_t bp,name_t service_name,bootstrap_status_t * service_active)255 bootstrap_status(mach_port_t bp, name_t service_name, bootstrap_status_t *service_active)
256 {
257 	kern_return_t kr;
258 	mach_port_t p;
259 
260 	if ((kr = bootstrap_look_up(bp, service_name, &p))) {
261 		return kr;
262 	}
263 
264 	mach_port_deallocate(mach_task_self(), p);
265 	*service_active = BOOTSTRAP_STATUS_ACTIVE;
266 
267 	if (bootstrap_check_in(bp, service_name, &p) == BOOTSTRAP_SUCCESS) {
268 		mach_port_mod_refs(mach_task_self(), p, MACH_PORT_RIGHT_RECEIVE, -1);
269 		*service_active = BOOTSTRAP_STATUS_ON_DEMAND;
270 	}
271 
272 	return BOOTSTRAP_SUCCESS;
273 }
274 
275 kern_return_t
bootstrap_info(mach_port_t bp,name_array_t * service_names,mach_msg_type_number_t * service_namesCnt,name_array_t * service_jobs,mach_msg_type_number_t * service_jobsCnt,bootstrap_status_array_t * service_active,mach_msg_type_number_t * service_activeCnt,uint64_t flags)276 bootstrap_info(mach_port_t bp,
277 			   name_array_t *service_names, mach_msg_type_number_t *service_namesCnt,
278 			   name_array_t *service_jobs, mach_msg_type_number_t *service_jobsCnt,
279 			   bootstrap_status_array_t *service_active, mach_msg_type_number_t *service_activeCnt,
280 			   uint64_t flags)
281 {
282 	return vproc_mig_info(bp, service_names, service_namesCnt, service_jobs, service_jobsCnt, service_active, service_activeCnt, flags);
283 }
284 
285 const char *
bootstrap_strerror(kern_return_t r)286 bootstrap_strerror(kern_return_t r)
287 {
288 	switch (r) {
289 	case BOOTSTRAP_SUCCESS:
290 		return "Success";
291 	case BOOTSTRAP_NOT_PRIVILEGED:
292 		return "Permission denied";
293 	case BOOTSTRAP_NAME_IN_USE:
294 	case BOOTSTRAP_SERVICE_ACTIVE:
295 		return "Service name already exists";
296 	case BOOTSTRAP_UNKNOWN_SERVICE:
297 		return "Unknown service name";
298 	case BOOTSTRAP_BAD_COUNT:
299 		return "Too many lookups were requested in one request";
300 	case BOOTSTRAP_NO_MEMORY:
301 		return "Out of memory";
302 	default:
303 		return mach_error_string(r);
304 	}
305 }
306