]> git.saurik.com Git - apple/security.git/blob - supd/main.m
Security-59754.41.1.tar.gz
[apple/security.git] / supd / main.m
1 /*
2 * Copyright (c) 2017 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 */
23
24 #include <TargetConditionals.h>
25 #import <Foundation/NSError_Private.h>
26 #import <dirhelper_priv.h>
27
28 #if TARGET_OS_OSX
29 #include <sandbox.h>
30 #include <notify.h>
31 #include <pwd.h>
32 #endif
33
34 #if TARGET_OS_SIMULATOR
35
36 int main(int argc, char** argv)
37 {
38 return 0;
39 }
40
41 #else
42
43 #import <Foundation/Foundation.h>
44 #import "supd.h"
45 #include "debugging.h"
46 #import <Foundation/NSXPCConnection_Private.h>
47 #include <xpc/private.h>
48
49 @interface ServiceDelegate : NSObject <NSXPCListenerDelegate>
50 @end
51
52 @implementation ServiceDelegate
53
54 - (BOOL)listener:(NSXPCListener *)listener shouldAcceptNewConnection:(NSXPCConnection *)newConnection {
55 NSNumber *num = [newConnection valueForEntitlement:@"com.apple.private.securityuploadd"];
56 if (![num isKindOfClass:[NSNumber class]] || ![num boolValue]) {
57 secerror("xpc: Client (pid: %d) doesn't have entitlement", [newConnection processIdentifier]);
58 return NO;
59 } else {
60 secinfo("xpc", "Client (pid: %d) properly entitled, let's go", [newConnection processIdentifier]);
61 }
62
63 newConnection.exportedInterface = [NSXPCInterface interfaceWithProtocol:@protocol(supdProtocol)];
64 supd *exportedObject = [supd instance];
65 newConnection.exportedObject = exportedObject;
66 [newConnection resume];
67 return YES;
68 }
69
70 @end
71
72 static void securityuploadd_sandbox(void)
73 {
74 #if TARGET_OS_OSX
75 // Enter the sandbox on macOS
76 char homeDir[PATH_MAX] = {};
77 struct passwd* pwd = getpwuid(getuid());
78 if (pwd == NULL) {
79 secerror("Failed to get home directory for user: %d", errno);
80 exit(EXIT_FAILURE);
81 }
82
83 if (realpath(pwd->pw_dir, homeDir) == NULL) {
84 strlcpy(homeDir, pwd->pw_dir, sizeof(homeDir));
85 }
86
87 const char *sandbox_params[] = {
88 "HOME", homeDir,
89 NULL
90 };
91
92 char *sberror = NULL;
93 secerror("initializing securityuploadd sandbox with HOME=%s", homeDir);
94 if (sandbox_init_with_parameters("com.apple.securityuploadd", SANDBOX_NAMED, sandbox_params, &sberror) != 0) {
95 secerror("Failed to enter securityuploadd sandbox: %{public}s", sberror);
96 exit(EXIT_FAILURE);
97 }
98 #endif
99 }
100
101 int main(int argc, const char *argv[])
102 {
103 secnotice("lifecycle", "supd lives!");
104 [NSError _setFileNameLocalizationEnabled:NO];
105 securityuploadd_sandbox();
106
107 ServiceDelegate *delegate = [ServiceDelegate new];
108
109 // kick the singleton so it can register its xpc activity handler
110 [supd instantiate];
111
112 NSXPCListener *listener = [[NSXPCListener alloc] initWithMachServiceName:@"com.apple.securityuploadd"];
113 listener.delegate = delegate;
114
115 // We're always launched in response to client activity and don't want to sit around idle.
116 dispatch_after(dispatch_time(DISPATCH_TIME_NOW, 5ull * NSEC_PER_SEC), dispatch_get_global_queue(DISPATCH_QUEUE_PRIORITY_DEFAULT, 0), ^{
117 secnotice("lifecycle", "will exit when clean");
118 xpc_transaction_exit_clean();
119 });
120
121 [listener resume];
122 [[NSRunLoop currentRunLoop] run];
123 return 0;
124 }
125
126 #endif // !TARGET_OS_SIMULATOR