2 * Copyright (c) 1999-2007 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
23 /***********************************************************************
25 * Copyright 1988-1996, NeXT Software, Inc.
28 **********************************************************************/
32 /***********************************************************************
34 **********************************************************************/
36 #include "objc-private.h"
37 #include "objc-loadmethod.h"
38 #include "objc-file.h"
41 /***********************************************************************
43 **********************************************************************/
45 /* Linker metadata symbols */
47 // NSObject was in Foundation/CF on macOS < 10.8.
51 const char __objc_nsobject_class_10_5 = 0;
52 const char __objc_nsobject_class_10_6 = 0;
53 const char __objc_nsobject_class_10_7 = 0;
55 const char __objc_nsobject_metaclass_10_5 = 0;
56 const char __objc_nsobject_metaclass_10_6 = 0;
57 const char __objc_nsobject_metaclass_10_7 = 0;
59 const char __objc_nsobject_isa_10_5 = 0;
60 const char __objc_nsobject_isa_10_6 = 0;
61 const char __objc_nsobject_isa_10_7 = 0;
65 const char __objc_nsobject_class_10_5 = 0;
66 const char __objc_nsobject_class_10_6 = 0;
67 const char __objc_nsobject_class_10_7 = 0;
72 // Settings from environment variables
73 #define OPTION(var, env, help) bool var = false;
84 const option_t Settings[] = {
85 #define OPTION(var, env, help) option_t{&var, #env, help, strlen(#env)},
91 // objc's key for pthread_getspecific
92 #if SUPPORT_DIRECT_THREAD_KEYS
93 #define _objc_pthread_key TLS_DIRECT_KEY
95 static tls_key_t _objc_pthread_key;
99 SEL SEL_cxx_construct = NULL;
100 SEL SEL_cxx_destruct = NULL;
102 struct objc::SafeRanges objc::dataSegmentsRanges;
103 header_info *FirstHeader = 0; // NULL means empty list
104 header_info *LastHeader = 0; // NULL means invalid; recompute it
106 // Set to true on the child side of fork()
107 // if the parent process was multithreaded when fork() was called.
108 bool MultithreadedForkChild = false;
111 /***********************************************************************
112 * objc_noop_imp. Used when we need to install a do-nothing method somewhere.
113 **********************************************************************/
114 id objc_noop_imp(id self, SEL _cmd __unused) {
119 /***********************************************************************
120 * _objc_isDebugBuild. Defined in debug builds only.
121 * Some test code looks for the presence of this symbol.
122 **********************************************************************/
123 #if DEBUG != OBJC_IS_DEBUG_BUILD
124 #error mismatch in debug-ness macros
125 // DEBUG is used in our code. OBJC_IS_DEBUG_BUILD is used in the
126 // header declaration of _objc_isDebugBuild() because that header
127 // is visible to other clients who might have their own DEBUG macro.
130 #if OBJC_IS_DEBUG_BUILD
131 void _objc_isDebugBuild(void) { }
135 /***********************************************************************
136 * objc_getClass. Return the id of the named class. If the class does
137 * not exist, call _objc_classLoader and then objc_classHandler, either of
138 * which may create a new class.
139 * Warning: doesn't work if aClassName is the name of a posed-for class's isa!
140 **********************************************************************/
141 Class objc_getClass(const char *aClassName)
143 if (!aClassName) return Nil;
145 // NO unconnected, YES class handler
146 return look_up_class(aClassName, NO, YES);
150 /***********************************************************************
151 * objc_getRequiredClass.
152 * Same as objc_getClass, but kills the process if the class is not found.
153 * This is used by ZeroLink, where failing to find a class would be a
154 * compile-time link error without ZeroLink.
155 **********************************************************************/
156 Class objc_getRequiredClass(const char *aClassName)
158 Class cls = objc_getClass(aClassName);
159 if (!cls) _objc_fatal("link error: class '%s' not found.", aClassName);
164 /***********************************************************************
165 * objc_lookUpClass. Return the id of the named class.
166 * If the class does not exist, call _objc_classLoader, which may create
169 * Formerly objc_getClassWithoutWarning ()
170 **********************************************************************/
171 Class objc_lookUpClass(const char *aClassName)
173 if (!aClassName) return Nil;
175 // NO unconnected, NO class handler
176 return look_up_class(aClassName, NO, NO);
180 /***********************************************************************
181 * objc_getMetaClass. Return the id of the meta class the named class.
182 * Warning: doesn't work if aClassName is the name of a posed-for class's isa!
183 **********************************************************************/
184 Class objc_getMetaClass(const char *aClassName)
188 if (!aClassName) return Nil;
190 cls = objc_getClass (aClassName);
193 _objc_inform ("class `%s' not linked into application", aClassName);
200 /***********************************************************************
201 * objc::SafeRanges::find. Find an image data segment that contains address
202 **********************************************************************/
204 objc::SafeRanges::find(uintptr_t ptr, uint32_t &pos)
207 std::sort(ranges, ranges + count, [](const Range &s1, const Range &s2){
208 return s1.start < s2.start;
213 uint32_t l = 0, r = count;
215 uint32_t i = (l + r) / 2;
217 if (ptr < ranges[i].start) {
219 } else if (ptr >= ranges[i].end) {
231 /***********************************************************************
232 * objc::SafeRanges::add. Register a new well known data segment.
233 **********************************************************************/
235 objc::SafeRanges::add(uintptr_t start, uintptr_t end)
238 // Have a typical malloc growth:
239 // - size <= 32: grow by 4
240 // - size <= 64: grow by 8
241 // - size <= 128: grow by 16
243 size += size < 16 ? 4 : 1 << (fls(size) - 3);
244 ranges = (Range *)realloc(ranges, sizeof(Range) * size);
246 ranges[count++] = Range{ start, end };
250 /***********************************************************************
251 * objc::SafeRanges::remove. Remove a previously known data segment.
252 **********************************************************************/
254 objc::SafeRanges::remove(uintptr_t start, uintptr_t end)
258 if (!find(start, pos) || ranges[pos].end != end) {
259 _objc_fatal("Cannot find range %#lx..%#lx", start, end);
262 ranges[pos] = ranges[count];
267 /***********************************************************************
268 * appendHeader. Add a newly-constructed header_info to the list.
269 **********************************************************************/
270 void appendHeader(header_info *hi)
272 // Add the header to the header list.
273 // The header is appended to the list, to preserve the bottom-up order.
277 FirstHeader = LastHeader = hi;
280 // list is not empty, but LastHeader is invalid - recompute it
281 LastHeader = FirstHeader;
282 while (LastHeader->getNext()) LastHeader = LastHeader->getNext();
284 // LastHeader is now valid
285 LastHeader->setNext(hi);
290 if ((hi->mhdr()->flags & MH_DYLIB_IN_CACHE) == 0) {
291 foreach_data_segment(hi->mhdr(), [](const segmentType *seg, intptr_t slide) {
292 uintptr_t start = (uintptr_t)seg->vmaddr + slide;
293 objc::dataSegmentsRanges.add(start, start + seg->vmsize);
300 /***********************************************************************
302 * Remove the given header from the header list.
303 * FirstHeader is updated.
304 * LastHeader is set to NULL. Any code that uses LastHeader must
305 * detect this NULL and recompute LastHeader by traversing the list.
306 **********************************************************************/
307 void removeHeader(header_info *hi)
309 header_info *prev = NULL;
310 header_info *current = NULL;
312 for (current = FirstHeader; current != NULL; current = current->getNext()) {
314 header_info *deadHead = current;
316 // Remove from the linked list.
318 prev->setNext(current->getNext());
320 FirstHeader = current->getNext(); // no prev so removing head
322 // Update LastHeader if necessary.
323 if (LastHeader == deadHead) {
324 LastHeader = NULL; // will be recomputed next time it's used
332 if ((hi->mhdr()->flags & MH_DYLIB_IN_CACHE) == 0) {
333 foreach_data_segment(hi->mhdr(), [](const segmentType *seg, intptr_t slide) {
334 uintptr_t start = (uintptr_t)seg->vmaddr + slide;
335 objc::dataSegmentsRanges.remove(start, start + seg->vmsize);
342 /***********************************************************************
344 * Read environment variables that affect the runtime.
345 * Also print environment variable help, if requested.
346 **********************************************************************/
347 void environ_init(void)
350 // All environment variables are silently ignored when setuid or setgid
351 // This includes OBJC_HELP and OBJC_PRINT_OPTIONS themselves.
355 bool PrintHelp = false;
356 bool PrintOptions = false;
357 bool maybeMallocDebugging = false;
359 // Scan environ[] directly instead of calling getenv() a lot.
360 // This optimizes the case where none are set.
361 for (char **p = *_NSGetEnviron(); *p != nil; p++) {
362 if (0 == strncmp(*p, "Malloc", 6) || 0 == strncmp(*p, "DYLD", 4) ||
363 0 == strncmp(*p, "NSZombiesEnabled", 16))
365 maybeMallocDebugging = true;
368 if (0 != strncmp(*p, "OBJC_", 5)) continue;
370 if (0 == strncmp(*p, "OBJC_HELP=", 10)) {
374 if (0 == strncmp(*p, "OBJC_PRINT_OPTIONS=", 19)) {
379 const char *value = strchr(*p, '=');
380 if (!*value) continue;
383 for (size_t i = 0; i < sizeof(Settings)/sizeof(Settings[0]); i++) {
384 const option_t *opt = &Settings[i];
385 if ((size_t)(value - *p) == 1+opt->envlen &&
386 0 == strncmp(*p, opt->env, opt->envlen))
388 *opt->var = (0 == strcmp(value, "YES"));
394 // Special case: enable some autorelease pool debugging
395 // when some malloc debugging is enabled
396 // and OBJC_DEBUG_POOL_ALLOCATION is not set to something other than NO.
397 if (maybeMallocDebugging) {
398 const char *insert = getenv("DYLD_INSERT_LIBRARIES");
399 const char *zombie = getenv("NSZombiesEnabled");
400 const char *pooldebug = getenv("OBJC_DEBUG_POOL_ALLOCATION");
401 if ((getenv("MallocStackLogging")
402 || getenv("MallocStackLoggingNoCompact")
403 || (zombie && (*zombie == 'Y' || *zombie == 'y'))
404 || (insert && strstr(insert, "libgmalloc")))
406 (!pooldebug || 0 == strcmp(pooldebug, "YES")))
408 DebugPoolAllocation = true;
412 // Print OBJC_HELP and OBJC_PRINT_OPTIONS output.
413 if (PrintHelp || PrintOptions) {
415 _objc_inform("Objective-C runtime debugging. Set variable=YES to enable.");
416 _objc_inform("OBJC_HELP: describe available environment variables");
418 _objc_inform("OBJC_HELP is set");
420 _objc_inform("OBJC_PRINT_OPTIONS: list which options are set");
423 _objc_inform("OBJC_PRINT_OPTIONS is set");
426 for (size_t i = 0; i < sizeof(Settings)/sizeof(Settings[0]); i++) {
427 const option_t *opt = &Settings[i];
428 if (PrintHelp) _objc_inform("%s: %s", opt->env, opt->help);
429 if (PrintOptions && *opt->var) _objc_inform("%s is set", opt->env);
435 /***********************************************************************
437 * OBJC_PRINT_REPLACED_METHODS implementation
438 **********************************************************************/
440 logReplacedMethod(const char *className, SEL s,
441 bool isMeta, const char *catName,
442 IMP oldImp, IMP newImp)
444 const char *oldImage = "??";
445 const char *newImage = "??";
447 // Silently ignore +load replacement because category +load is special
448 if (s == @selector(load)) return;
451 // don't know dladdr()/dli_fname equivalent
455 if (dladdr((void*)oldImp, &dl) && dl.dli_fname) oldImage = dl.dli_fname;
456 if (dladdr((void*)newImp, &dl) && dl.dli_fname) newImage = dl.dli_fname;
459 _objc_inform("REPLACED: %c[%s %s] %s%s (IMP was %p (%s), now %p (%s))",
460 isMeta ? '+' : '-', className, sel_getName(s),
461 catName ? "by category " : "", catName ? catName : "",
462 oldImp, oldImage, newImp, newImage);
466 /***********************************************************************
467 * _objc_fetch_pthread_data
468 * Fetch objc's pthread data for this thread.
469 * If the data doesn't exist yet and create is NO, return NULL.
470 * If the data doesn't exist yet and create is YES, allocate and return it.
471 **********************************************************************/
472 _objc_pthread_data *_objc_fetch_pthread_data(bool create)
474 _objc_pthread_data *data;
476 data = (_objc_pthread_data *)tls_get(_objc_pthread_key);
477 if (!data && create) {
478 data = (_objc_pthread_data *)
479 calloc(1, sizeof(_objc_pthread_data));
480 tls_set(_objc_pthread_key, data);
487 /***********************************************************************
488 * _objc_pthread_destroyspecific
489 * Destructor for objc's per-thread data.
490 * arg shouldn't be NULL, but we check anyway.
491 **********************************************************************/
492 extern void _destroyInitializingClassList(struct _objc_initializing_classes *list);
493 void _objc_pthread_destroyspecific(void *arg)
495 _objc_pthread_data *data = (_objc_pthread_data *)arg;
497 _destroyInitializingClassList(data->initializingClasses);
498 _destroySyncCache(data->syncCache);
499 _destroyAltHandlerList(data->handlerList);
500 for (int i = 0; i < (int)countof(data->printableNames); i++) {
501 if (data->printableNames[i]) {
502 free(data->printableNames[i]);
505 free(data->classNameLookups);
507 // add further cleanup here...
516 #if SUPPORT_DIRECT_THREAD_KEYS
517 pthread_key_init_np(TLS_DIRECT_KEY, &_objc_pthread_destroyspecific);
519 _objc_pthread_key = tls_create(&_objc_pthread_destroyspecific);
524 /***********************************************************************
526 * Former library initializer. This function is now merely a placeholder
527 * for external callers. All runtime initialization has now been moved
528 * to map_images() and _objc_init.
529 **********************************************************************/
536 /***********************************************************************
537 * objc_setForwardHandler
538 **********************************************************************/
542 // Default forward handler (nil) goes to forward:: dispatch.
543 void *_objc_forward_handler = nil;
544 void *_objc_forward_stret_handler = nil;
548 // Default forward handler halts the process.
549 __attribute__((noreturn, cold)) void
550 objc_defaultForwardHandler(id self, SEL sel)
552 _objc_fatal("%c[%s %s]: unrecognized selector sent to instance %p "
553 "(no message forward handler is installed)",
554 class_isMetaClass(object_getClass(self)) ? '+' : '-',
555 object_getClassName(self), sel_getName(sel), self);
557 void *_objc_forward_handler = (void*)objc_defaultForwardHandler;
560 struct stret { int i[100]; };
561 __attribute__((noreturn, cold)) struct stret
562 objc_defaultForwardStretHandler(id self, SEL sel)
564 objc_defaultForwardHandler(self, sel);
566 void *_objc_forward_stret_handler = (void*)objc_defaultForwardStretHandler;
571 void objc_setForwardHandler(void *fwd, void *fwd_stret)
573 _objc_forward_handler = fwd;
575 _objc_forward_stret_handler = fwd_stret;
582 extern "C" Class _objc_getOrigClass(const char *name);
585 static BOOL internal_class_getImageName(Class cls, const char **outName)
588 cls = _objc_getOrigClass(cls->demangledName());
590 auto result = dyld_image_path_containing_address(cls);
592 return (result != nil);
596 static ChainedHookFunction<objc_hook_getImageName>
597 GetImageNameHook{internal_class_getImageName};
599 void objc_setHook_getImageName(objc_hook_getImageName newValue,
600 objc_hook_getImageName *outOldValue)
602 GetImageNameHook.set(newValue, outOldValue);
605 const char *class_getImageName(Class cls)
607 if (!cls) return nil;
610 if (GetImageNameHook.get()(cls, &name)) return name;
615 /**********************************************************************
616 * Fast Enumeration Support
617 **********************************************************************/
619 static void (*enumerationMutationHandler)(id);
621 /**********************************************************************
622 * objc_enumerationMutation
623 * called by compiler when a mutation is detected during foreach iteration
624 **********************************************************************/
625 void objc_enumerationMutation(id object) {
626 if (enumerationMutationHandler == nil) {
627 _objc_fatal("mutation detected during 'for(... in ...)' enumeration of object %p.", (void*)object);
629 (*enumerationMutationHandler)(object);
633 /**********************************************************************
634 * objc_setEnumerationMutationHandler
635 * an entry point to customize mutation error handing
636 **********************************************************************/
637 void objc_setEnumerationMutationHandler(void (*handler)(id)) {
638 enumerationMutationHandler = handler;
642 /**********************************************************************
643 * Associative Reference Support
644 **********************************************************************/
647 objc_getAssociatedObject(id object, const void *key)
649 return _object_get_associative_reference(object, key);
653 _base_objc_setAssociatedObject(id object, const void *key, id value, objc_AssociationPolicy policy)
655 _object_set_associative_reference(object, key, value, policy);
658 static ChainedHookFunction<objc_hook_setAssociatedObject> SetAssocHook{_base_objc_setAssociatedObject};
661 objc_setHook_setAssociatedObject(objc_hook_setAssociatedObject _Nonnull newValue,
662 objc_hook_setAssociatedObject _Nullable * _Nonnull outOldValue) {
663 SetAssocHook.set(newValue, outOldValue);
667 objc_setAssociatedObject(id object, const void *key, id value, objc_AssociationPolicy policy)
669 SetAssocHook.get()(object, key, value, policy);
673 void objc_removeAssociatedObjects(id object)
675 if (object && object->hasAssociatedObjects()) {
676 _object_remove_assocations(object);
682 #if SUPPORT_GC_COMPAT
684 #include <mach-o/fat.h>
686 // GC preflight for an app executable.
694 // Overloaded template wrappers around clang's overflow-checked arithmetic.
696 template <typename T> bool uadd_overflow(T x, T y, T* sum);
697 template <typename T> bool usub_overflow(T x, T y, T* diff);
698 template <typename T> bool umul_overflow(T x, T y, T* prod);
700 template <typename T> bool sadd_overflow(T x, T y, T* sum);
701 template <typename T> bool ssub_overflow(T x, T y, T* diff);
702 template <typename T> bool smul_overflow(T x, T y, T* prod);
704 template <> bool uadd_overflow(unsigned x, unsigned y, unsigned* sum) { return __builtin_uadd_overflow(x, y, sum); }
705 template <> bool uadd_overflow(unsigned long x, unsigned long y, unsigned long* sum) { return __builtin_uaddl_overflow(x, y, sum); }
706 template <> bool uadd_overflow(unsigned long long x, unsigned long long y, unsigned long long* sum) { return __builtin_uaddll_overflow(x, y, sum); }
708 template <> bool usub_overflow(unsigned x, unsigned y, unsigned* diff) { return __builtin_usub_overflow(x, y, diff); }
709 template <> bool usub_overflow(unsigned long x, unsigned long y, unsigned long* diff) { return __builtin_usubl_overflow(x, y, diff); }
710 template <> bool usub_overflow(unsigned long long x, unsigned long long y, unsigned long long* diff) { return __builtin_usubll_overflow(x, y, diff); }
712 template <> bool umul_overflow(unsigned x, unsigned y, unsigned* prod) { return __builtin_umul_overflow(x, y, prod); }
713 template <> bool umul_overflow(unsigned long x, unsigned long y, unsigned long* prod) { return __builtin_umull_overflow(x, y, prod); }
714 template <> bool umul_overflow(unsigned long long x, unsigned long long y, unsigned long long* prod) { return __builtin_umulll_overflow(x, y, prod); }
716 template <> bool sadd_overflow(signed x, signed y, signed* sum) { return __builtin_sadd_overflow(x, y, sum); }
717 template <> bool sadd_overflow(signed long x, signed long y, signed long* sum) { return __builtin_saddl_overflow(x, y, sum); }
718 template <> bool sadd_overflow(signed long long x, signed long long y, signed long long* sum) { return __builtin_saddll_overflow(x, y, sum); }
720 template <> bool ssub_overflow(signed x, signed y, signed* diff) { return __builtin_ssub_overflow(x, y, diff); }
721 template <> bool ssub_overflow(signed long x, signed long y, signed long* diff) { return __builtin_ssubl_overflow(x, y, diff); }
722 template <> bool ssub_overflow(signed long long x, signed long long y, signed long long* diff) { return __builtin_ssubll_overflow(x, y, diff); }
724 template <> bool smul_overflow(signed x, signed y, signed* prod) { return __builtin_smul_overflow(x, y, prod); }
725 template <> bool smul_overflow(signed long x, signed long y, signed long* prod) { return __builtin_smull_overflow(x, y, prod); }
726 template <> bool smul_overflow(signed long long x, signed long long y, signed long long* prod) { return __builtin_smulll_overflow(x, y, prod); }
729 // Range-checking subview of a file.
732 uint64_t sliceOffset;
736 FileSlice() : fd(-1), sliceOffset(0), sliceSize(0) { }
738 FileSlice(int newfd, uint64_t newOffset, uint64_t newSize)
739 : fd(newfd) , sliceOffset(newOffset) , sliceSize(newSize) { }
741 // Read bytes from this slice.
742 // Returns YES if all bytes were read successfully.
743 bool pread(void *buf, uint64_t readSize, uint64_t readOffset = 0) {
745 if (uadd_overflow(readOffset, readSize, &readEnd)) return NO;
746 if (readEnd > sliceSize) return NO;
748 uint64_t preadOffset;
749 if (uadd_overflow(sliceOffset, readOffset, &preadOffset)) return NO;
751 int64_t readed = ::pread(fd, buf, (size_t)readSize, preadOffset);
752 if (readed < 0 || (uint64_t)readed != readSize) return NO;
756 // Create a new slice that is a subset of this slice.
757 // Returnes YES if successful.
758 bool slice(uint64_t newOffset, uint64_t newSize, FileSlice& result) {
759 // fixme arithmetic overflow
761 if (uadd_overflow(newOffset, newSize, &newEnd)) return NO;
762 if (newEnd > sliceSize) return NO;
764 if (uadd_overflow(sliceOffset, newOffset, &result.sliceOffset)) {
767 result.sliceSize = newSize;
772 // Shorten this slice in place by removing a range from the start.
773 bool advance(uint64_t distance) {
774 if (distance > sliceSize) return NO;
775 if (uadd_overflow(sliceOffset, distance, &sliceOffset)) return NO;
776 if (usub_overflow(sliceSize, distance, &sliceSize)) return NO;
782 // Arch32 and Arch64 are used to specialize sliceRequiresGC()
783 // to interrogate old-ABI i386 and new-ABI x86_64 files.
786 using mh_t = struct mach_header;
787 using segment_command_t = struct segment_command;
788 using section_t = struct section;
790 enum : cpu_type_t { cputype = CPU_TYPE_X86 };
791 enum : int { segment_cmd = LC_SEGMENT };
793 static bool isObjCSegment(const char *segname) {
794 return segnameEquals(segname, "__OBJC");
797 static bool isImageInfoSection(const char *sectname) {
798 return sectnameEquals(sectname, "__image_info");
801 static bool countClasses(FileSlice file, section_t& sect,
802 int& classCount, int& classrefCount)
804 if (sectnameEquals(sect.sectname, "__cls_refs")) {
805 classrefCount += sect.size / 4;
807 else if (sectnameEquals(sect.sectname, "__module_info")) {
811 uint32_t name; // not bound
812 uint32_t symtab; // not bound
814 size_t mod_count = sect.size / sizeof(module_t);
815 if (mod_count == 0) {
816 // no classes defined
817 } else if (mod_count > 1) {
818 // AppleScriptObjC apps only have one module.
819 // Disqualify this app by setting classCount to non-zero.
820 // We don't actually need an accurate count.
822 } else if (mod_count == 1) {
823 FileSlice moduleSlice;
824 if (!file.slice(sect.offset, sect.size, moduleSlice)) return NO;
826 if (!moduleSlice.pread(&module, sizeof(module))) return NO;
828 // AppleScriptObjC apps only have a module with no symtab.
829 // Disqualify this app by setting classCount to non-zero.
830 // We don't actually need an accurate count.
842 using mh_t = struct mach_header_64;
843 using segment_command_t = struct segment_command_64;
844 using section_t = struct section_64;
846 enum : cpu_type_t { cputype = CPU_TYPE_X86_64 };
847 enum : int { segment_cmd = LC_SEGMENT_64 };
849 static bool isObjCSegment(const char *segname) {
851 segnameEquals(segname, "__DATA") ||
852 segnameEquals(segname, "__DATA_CONST") ||
853 segnameEquals(segname, "__DATA_DIRTY");
856 static bool isImageInfoSection(const char *sectname) {
857 return sectnameEquals(sectname, "__objc_imageinfo");
860 static bool countClasses(FileSlice, section_t& sect,
861 int& classCount, int& classrefCount)
863 if (sectnameEquals(sect.sectname, "__objc_classlist")) {
864 classCount += sect.size / 8;
866 else if (sectnameEquals(sect.sectname, "__objc_classrefs")) {
867 classrefCount += sect.size / 8;
874 #define SANE_HEADER_SIZE (32*1024)
876 template <typename Arch>
877 static int sliceRequiresGC(typename Arch::mh_t mh, FileSlice file)
879 // We assume there is only one arch per pointer size that can support GC.
881 if (mh.cputype != Arch::cputype) return 0;
883 // We only check the main executable.
884 if (mh.filetype != MH_EXECUTE) return 0;
886 // Look for ObjC segment.
887 // Look for AppleScriptObjC linkage.
889 if (!file.slice(sizeof(mh), mh.sizeofcmds, cmds)) return Error;
891 // Exception: Some AppleScriptObjC apps built for GC can run without GC.
892 // 1. executable defines no classes
893 // 2. executable references NSBundle only
894 // 3. executable links to AppleScriptObjC.framework
895 // Note that shouldRejectGCApp() also knows about this.
897 bool linksToAppleScriptObjC = NO;
899 int classrefCount = 0;
901 // Disallow abusively-large executables that could hang this checker.
902 // dyld performs similar checks (MAX_MACH_O_HEADER_AND_LOAD_COMMANDS_SIZE)
903 if (mh.sizeofcmds > SANE_HEADER_SIZE) return Error;
904 if (mh.ncmds > mh.sizeofcmds / sizeof(struct load_command)) return Error;
906 for (uint32_t cmdindex = 0; cmdindex < mh.ncmds; cmdindex++) {
907 struct load_command lc;
908 if (!cmds.pread(&lc, sizeof(lc))) return Error;
910 // Disallow abusively-small load commands that could hang this checker.
911 // dyld performs a similar check.
912 if (lc.cmdsize < sizeof(lc)) return Error;
914 if (lc.cmd == LC_LOAD_DYLIB || lc.cmd == LC_LOAD_UPWARD_DYLIB ||
915 lc.cmd == LC_LOAD_WEAK_DYLIB || lc.cmd == LC_REEXPORT_DYLIB)
917 // Look for AppleScriptObjC linkage.
918 FileSlice dylibSlice;
919 if (!cmds.slice(0, lc.cmdsize, dylibSlice)) return Error;
920 struct dylib_command dylib;
921 if (!dylibSlice.pread(&dylib, sizeof(dylib))) return Error;
923 const char *asoFramework =
924 "/System/Library/Frameworks/AppleScriptObjC.framework"
925 "/Versions/A/AppleScriptObjC";
926 size_t asoLen = strlen(asoFramework);
929 if (dylibSlice.slice(dylib.dylib.name.offset, asoLen, nameSlice)) {
931 if (!nameSlice.pread(name, asoLen)) return Error;
932 if (0 == memcmp(name, asoFramework, asoLen)) {
933 linksToAppleScriptObjC = YES;
937 else if (lc.cmd == Arch::segment_cmd) {
938 typename Arch::segment_command_t seg;
939 if (!cmds.pread(&seg, sizeof(seg))) return Error;
941 if (Arch::isObjCSegment(seg.segname)) {
943 // Look for image info section.
944 // Look for class implementations and class references.
946 if (!cmds.slice(0, seg.cmdsize, sections)) return Error;
947 if (!sections.advance(sizeof(seg))) return Error;
949 for (uint32_t segindex = 0; segindex < seg.nsects; segindex++) {
950 typename Arch::section_t sect;
951 if (!sections.pread(§, sizeof(sect))) return Error;
952 if (!Arch::isObjCSegment(sect.segname)) return Error;
954 if (!Arch::countClasses(file, sect,
955 classCount, classrefCount))
960 if ((sect.flags & SECTION_TYPE) == S_REGULAR &&
961 Arch::isImageInfoSection(sect.sectname))
963 // ObjC image info section.
964 // Check its contents.
966 if (!file.slice(sect.offset, sect.size, section)) {
969 // The subset of objc_image_info that was in use for GC.
974 if (!section.pread(&ii, sizeof(ii))) return Error;
975 if (ii.flags & (1<<1)) {
977 // Don't return yet because we need to
978 // check the AppleScriptObjC exception.
983 if (!sections.advance(sizeof(sect))) return Error;
988 if (!cmds.advance(lc.cmdsize)) return Error;
995 else if (linksToAppleScriptObjC && classCount == 0 && classrefCount == 1) {
996 // Has GC bit but falls under the AppleScriptObjC exception.
1000 // Has GC bit and is not AppleScriptObjC.
1006 static int sliceRequiresGC(FileSlice file)
1008 // Read mach-o header.
1009 struct mach_header_64 mh;
1010 if (!file.pread(&mh, sizeof(mh))) return Error;
1012 // Check header magic. We assume only host-endian slices can support GC.
1015 return sliceRequiresGC<Arch32>(*(struct mach_header *)&mh, file);
1017 return sliceRequiresGC<Arch64>(mh, file);
1024 // Returns 1 if any slice requires GC.
1025 // Returns 0 if no slice requires GC.
1026 // Returns -1 on any I/O or file format error.
1027 int objc_appRequiresGC(int fd)
1030 if (fstat(fd, &st) < 0) return Error;
1032 FileSlice file(fd, 0, st.st_size);
1034 // Read fat header, if any.
1035 struct fat_header fh;
1037 if (! file.pread(&fh, sizeof(fh))) return Error;
1041 if (OSSwapBigToHostInt32(fh.magic) == FAT_MAGIC) {
1044 size_t nfat_arch = OSSwapBigToHostInt32(fh.nfat_arch);
1045 // Disallow abusively-large files that could hang this checker.
1046 if (nfat_arch > SANE_HEADER_SIZE/sizeof(struct fat_arch)) return Error;
1049 if (umul_overflow(nfat_arch, sizeof(struct fat_arch), &fat_size)) {
1054 if (!file.slice(sizeof(fh), fat_size, archlist)) return Error;
1057 for (size_t i = 0; i < nfat_arch; i++) {
1059 if (!archlist.pread(&fa, sizeof(fa))) return Error;
1060 if (!archlist.advance(sizeof(fa))) return Error;
1063 if (!file.slice(OSSwapBigToHostInt32(fa.offset),
1064 OSSwapBigToHostInt32(fa.size), thin))
1068 switch (sliceRequiresGC(thin)) {
1069 case WithoutGC: break; // no change
1070 case WithGC: if (result != Error) result = WithGC; break;
1071 case Error: result = Error; break;
1076 // Thin header or not a header.
1077 result = sliceRequiresGC(file);
1083 // SUPPORT_GC_COMPAT