]>
Commit | Line | Data |
---|---|---|
1c79356b | 1 | /* |
cb323159 | 2 | * Copyright (c) 2000-2019 Apple Inc. All rights reserved. |
5d5c5d0d | 3 | * |
2d21ac55 | 4 | * @APPLE_OSREFERENCE_LICENSE_HEADER_START@ |
0a7de745 | 5 | * |
2d21ac55 A |
6 | * This file contains Original Code and/or Modifications of Original Code |
7 | * as defined in and that are subject to the Apple Public Source License | |
8 | * Version 2.0 (the 'License'). You may not use this file except in | |
9 | * compliance with the License. The rights granted to you under the License | |
10 | * may not be used to create, or enable the creation or redistribution of, | |
11 | * unlawful or unlicensed copies of an Apple operating system, or to | |
12 | * circumvent, violate, or enable the circumvention or violation of, any | |
13 | * terms of an Apple operating system software license agreement. | |
0a7de745 | 14 | * |
2d21ac55 A |
15 | * Please obtain a copy of the License at |
16 | * http://www.opensource.apple.com/apsl/ and read it before using this file. | |
0a7de745 | 17 | * |
2d21ac55 A |
18 | * The Original Code and all software distributed under the License are |
19 | * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER | |
8f6c56a5 A |
20 | * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, |
21 | * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, | |
2d21ac55 A |
22 | * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. |
23 | * Please see the License for the specific language governing rights and | |
24 | * limitations under the License. | |
0a7de745 | 25 | * |
2d21ac55 | 26 | * @APPLE_OSREFERENCE_LICENSE_HEADER_END@ |
0a7de745 | 27 | * |
b0d623f7 | 28 | * |
1c79356b A |
29 | * Copyright (c) 1982, 1986, 1989, 1991, 1992, 1993 |
30 | * The Regents of the University of California. All rights reserved. | |
31 | * (c) UNIX System Laboratories, Inc. | |
32 | * All or some portions of this file are derived from material licensed | |
33 | * to the University of California by American Telephone and Telegraph | |
34 | * Co. or Unix System Laboratories, Inc. and are reproduced herein with | |
35 | * the permission of UNIX System Laboratories, Inc. | |
36 | * | |
37 | * Redistribution and use in source and binary forms, with or without | |
38 | * modification, are permitted provided that the following conditions | |
39 | * are met: | |
40 | * 1. Redistributions of source code must retain the above copyright | |
41 | * notice, this list of conditions and the following disclaimer. | |
42 | * 2. Redistributions in binary form must reproduce the above copyright | |
43 | * notice, this list of conditions and the following disclaimer in the | |
44 | * documentation and/or other materials provided with the distribution. | |
45 | * 3. All advertising materials mentioning features or use of this software | |
46 | * must display the following acknowledgement: | |
47 | * This product includes software developed by the University of | |
48 | * California, Berkeley and its contributors. | |
49 | * 4. Neither the name of the University nor the names of its contributors | |
50 | * may be used to endorse or promote products derived from this software | |
51 | * without specific prior written permission. | |
52 | * | |
53 | * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND | |
54 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | |
55 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE | |
56 | * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE | |
57 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL | |
58 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS | |
59 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) | |
60 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT | |
61 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY | |
62 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | |
63 | * SUCH DAMAGE. | |
64 | * | |
65 | * @(#)init_main.c 8.16 (Berkeley) 5/14/95 | |
66 | */ | |
67 | ||
0a7de745 | 68 | /* |
1c79356b A |
69 | * |
70 | * Mach Operating System | |
71 | * Copyright (c) 1987 Carnegie-Mellon University | |
72 | * All rights reserved. The CMU software License Agreement specifies | |
73 | * the terms and conditions for use and redistribution. | |
74 | */ | |
2d21ac55 A |
75 | /* |
76 | * NOTICE: This file was modified by McAfee Research in 2004 to introduce | |
77 | * support for mandatory and extensible security protections. This notice | |
78 | * is included in support of clause 2.2 (b) of the Apple Public License, | |
79 | * Version 2.0. | |
80 | */ | |
1c79356b A |
81 | |
82 | #include <sys/param.h> | |
83 | #include <sys/filedesc.h> | |
84 | #include <sys/kernel.h> | |
91447636 A |
85 | #include <sys/mount_internal.h> |
86 | #include <sys/proc_internal.h> | |
87 | #include <sys/kauth.h> | |
1c79356b | 88 | #include <sys/systm.h> |
91447636 | 89 | #include <sys/vnode_internal.h> |
1c79356b | 90 | #include <sys/conf.h> |
91447636 | 91 | #include <sys/buf_internal.h> |
1c79356b A |
92 | #include <sys/clist.h> |
93 | #include <sys/user.h> | |
55e303ae A |
94 | #include <sys/time.h> |
95 | #include <sys/systm.h> | |
91447636 | 96 | #include <sys/mman.h> |
cc8bc92a | 97 | #include <sys/kasl.h> |
55e303ae | 98 | |
b0d623f7 | 99 | #include <security/audit/audit.h> |
1c79356b A |
100 | |
101 | #include <sys/malloc.h> | |
102 | #include <sys/dkstat.h> | |
2d21ac55 | 103 | #include <sys/codesign.h> |
1c79356b | 104 | |
91447636 | 105 | #include <kern/startup.h> |
1c79356b A |
106 | #include <kern/thread.h> |
107 | #include <kern/task.h> | |
108 | #include <kern/ast.h> | |
b0d623f7 | 109 | #include <kern/kalloc.h> |
d9a64523 | 110 | #include <kern/ux_handler.h> /* for ux_handler_setup() */ |
1c79356b A |
111 | |
112 | #include <mach/vm_param.h> | |
113 | ||
114 | #include <vm/vm_map.h> | |
115 | #include <vm/vm_kern.h> | |
116 | ||
1c79356b | 117 | #include <sys/reboot.h> |
0a7de745 | 118 | #include <dev/busvar.h> /* for pseudo_inits */ |
1c79356b | 119 | #include <sys/kdebug.h> |
5ba3f43e | 120 | #include <sys/monotonic.h> |
39037602 | 121 | #include <sys/reason.h> |
1c79356b | 122 | |
765c9de3 A |
123 | #include <mach/mach_types.h> |
124 | #include <mach/vm_prot.h> | |
125 | #include <mach/semaphore.h> | |
126 | #include <mach/sync_policy.h> | |
127 | #include <kern/clock.h> | |
128 | #include <mach/kern_return.h> | |
0a7de745 A |
129 | #include <mach/thread_act.h> /* for thread_resume() */ |
130 | #include <sys/ubc_internal.h> /* for ubc_init() */ | |
131 | #include <sys/mcache.h> /* for mcache_init() */ | |
132 | #include <sys/mbuf.h> /* for mbinit() */ | |
133 | #include <sys/event.h> /* for knote_init() */ | |
134 | #include <sys/eventhandler.h> /* for eventhandler_init() */ | |
135 | #include <sys/kern_memorystatus.h> /* for memorystatus_init() */ | |
cb323159 | 136 | #include <sys/kern_memorystatus_freeze.h> /* for memorystatus_freeze_init() */ |
0a7de745 A |
137 | #include <sys/aio_kern.h> /* for aio_init() */ |
138 | #include <sys/semaphore.h> /* for psem_cache_init() */ | |
139 | #include <net/dlil.h> /* for dlil_init() */ | |
140 | #include <net/kpi_protocol.h> /* for proto_kpi_init() */ | |
141 | #include <net/iptap.h> /* for iptap_init() */ | |
142 | #include <sys/pipe.h> /* for pipeinit() */ | |
143 | #include <sys/socketvar.h> /* for socketinit() */ | |
144 | #include <sys/protosw.h> /* for domaininit() */ | |
145 | #include <kern/sched_prim.h> /* for thread_wakeup() */ | |
146 | #include <net/if_ether.h> /* for ether_family_init() */ | |
147 | #include <net/if_gif.h> /* for gif_init() */ | |
148 | #include <vm/vm_protos.h> /* for vnode_pager_bootstrap() */ | |
149 | #include <miscfs/devfs/devfsdefs.h> /* for devfs_kernel_mount() */ | |
150 | #include <vm/vm_kern.h> /* for kmem_suballoc() */ | |
151 | #include <sys/semaphore.h> /* for psem_lock_init() */ | |
152 | #include <sys/msgbuf.h> /* for log_setsize() */ | |
153 | #include <sys/tty.h> /* for tty_init() */ | |
154 | #include <sys/proc_uuid_policy.h> /* proc_uuid_policy_init() */ | |
155 | #include <netinet/flow_divert.h> /* flow_divert_init() */ | |
156 | #include <net/content_filter.h> /* for cfil_init() */ | |
157 | #include <net/necp.h> /* for necp_init() */ | |
158 | #include <net/network_agent.h> /* for netagent_init() */ | |
159 | #include <net/packet_mangler.h> /* for pkt_mnglr_init() */ | |
160 | #include <net/if_utun.h> /* for utun_register_control() */ | |
161 | #include <net/if_ipsec.h> /* for ipsec_register_control() */ | |
162 | #include <net/net_str_id.h> /* for net_str_id_init() */ | |
163 | #include <net/netsrc.h> /* for netsrc_init() */ | |
164 | #include <net/ntstat.h> /* for nstat_init() */ | |
165 | #include <netinet/tcp_cc.h> /* for tcp_cc_init() */ | |
166 | #include <netinet/mptcp_var.h> /* for mptcp_control_register() */ | |
167 | #include <net/nwk_wq.h> /* for nwk_wq_init */ | |
cb323159 | 168 | #include <net/restricted_in_port.h> /* for restricted_in_port_init() */ |
0a7de745 A |
169 | #include <kern/assert.h> /* for assert() */ |
170 | #include <sys/kern_overrides.h> /* for init_system_override() */ | |
94ff46dc | 171 | #include <sys/lockf.h> /* for lf_init() */ |
9bccf70c | 172 | |
91447636 A |
173 | #include <net/init.h> |
174 | ||
2d21ac55 A |
175 | #if CONFIG_MACF |
176 | #include <security/mac_framework.h> | |
0a7de745 A |
177 | #include <security/mac_internal.h> /* mac_init_bsd() */ |
178 | #include <security/mac_mach_internal.h> /* mac_update_task_label() */ | |
2d21ac55 A |
179 | #endif |
180 | ||
0c530ab8 A |
181 | #include <machine/exec.h> |
182 | ||
cb323159 | 183 | #if CONFIG_NETBOOT |
6d2010ae A |
184 | #include <sys/netboot.h> |
185 | #endif | |
186 | ||
2d21ac55 A |
187 | #if CONFIG_IMAGEBOOT |
188 | #include <sys/imageboot.h> | |
189 | #endif | |
190 | ||
b0d623f7 A |
191 | #if PFLOG |
192 | #include <net/if_pflog.h> | |
193 | #endif | |
194 | ||
39037602 | 195 | |
2d21ac55 | 196 | #include <pexpert/pexpert.h> |
6d2010ae | 197 | #include <machine/pal_routines.h> |
13f56ec4 | 198 | #include <console/video_console.h> |
2d21ac55 | 199 | |
d9a64523 A |
200 | #if CONFIG_XNUPOST |
201 | #include <tests/xnupost.h> | |
202 | #endif | |
3e170ce0 | 203 | |
0a7de745 A |
204 | void * get_user_regs(thread_t); /* XXX kludge for <machine/thread.h> */ |
205 | void IOKitInitializeTime(void); /* XXX */ | |
206 | void IOSleep(unsigned int); /* XXX */ | |
207 | void loopattach(void); /* XXX */ | |
1c79356b | 208 | |
b0d623f7 | 209 | const char copyright[] = |
0a7de745 A |
210 | "Copyright (c) 1982, 1986, 1989, 1991, 1993\n\t" |
211 | "The Regents of the University of California. " | |
212 | "All rights reserved.\n\n"; | |
1c79356b | 213 | |
1c79356b | 214 | /* Components of the first process -- never freed. */ |
0a7de745 A |
215 | struct proc proc0; |
216 | struct session session0; | |
217 | struct pgrp pgrp0; | |
218 | struct filedesc filedesc0; | |
219 | struct plimit limit0; | |
220 | struct pstats pstats0; | |
221 | struct sigacts sigacts0; | |
2d21ac55 A |
222 | proc_t kernproc; |
223 | proc_t initproc; | |
1c79356b | 224 | |
1c79356b A |
225 | long tk_cancc; |
226 | long tk_nin; | |
227 | long tk_nout; | |
228 | long tk_rawcc; | |
229 | ||
91447636 | 230 | int lock_trace = 0; |
1c79356b A |
231 | /* Global variables to make pstat happy. We do swapping differently */ |
232 | int nswdev, nswap; | |
233 | int nswapmap; | |
234 | void *swapmap; | |
235 | struct swdevt swdevt[1]; | |
236 | ||
0a7de745 A |
237 | dev_t rootdev; /* device of the root */ |
238 | dev_t dumpdev; /* device to take dumps on */ | |
239 | long dumplo; /* offset into dumpdev */ | |
240 | long hostid; | |
241 | char hostname[MAXHOSTNAMELEN]; | |
cb323159 A |
242 | lck_mtx_t hostname_lock; |
243 | lck_grp_t *hostname_lck_grp; | |
0a7de745 | 244 | char domainname[MAXDOMNAMELEN]; |
cb323159 | 245 | lck_mtx_t domainname_lock; |
1c79356b | 246 | |
5ba3f43e | 247 | char rootdevice[DEVMAXNAMESIZE]; |
1c79356b | 248 | |
2d21ac55 | 249 | #if KMEMSTATS |
0a7de745 | 250 | struct kmemstats kmemstats[M_LAST]; |
1c79356b A |
251 | #endif |
252 | ||
0a7de745 | 253 | struct vnode *rootvp; |
cb323159 | 254 | int boothowto; |
3e170ce0 | 255 | int minimalboot = 0; |
5ba3f43e A |
256 | #if CONFIG_EMBEDDED |
257 | int darkboot = 0; | |
258 | #endif | |
3e170ce0 | 259 | |
cb323159 A |
260 | #if __arm64__ |
261 | int legacy_footprint_entitlement_mode = LEGACY_FOOTPRINT_ENTITLEMENT_IGNORE; | |
262 | #endif /* __arm64__ */ | |
263 | ||
3e170ce0 A |
264 | #if PROC_REF_DEBUG |
265 | __private_extern__ int proc_ref_tracking_disabled = 0; /* disable panics on leaked proc refs across syscall boundary */ | |
266 | #endif | |
1c79356b | 267 | |
39037602 A |
268 | #if OS_REASON_DEBUG |
269 | __private_extern__ int os_reason_debug_disabled = 0; /* disable asserts for when we fail to allocate OS reasons */ | |
270 | #endif | |
271 | ||
cf7d32b8 | 272 | extern kern_return_t IOFindBSDRoot(char *, unsigned int, dev_t *, u_int32_t *); |
2d21ac55 A |
273 | extern void IOSecureBSDRoot(const char * rootName); |
274 | extern kern_return_t IOKitBSDInit(void ); | |
275 | extern void kminit(void); | |
2d21ac55 A |
276 | extern void file_lock_init(void); |
277 | extern void kmeminit(void); | |
278 | extern void bsd_bufferinit(void); | |
39037602 | 279 | extern void oslog_setsize(int size); |
316670eb | 280 | extern void throttle_init(void); |
fe8ab488 | 281 | extern void acct_init(void); |
2d21ac55 | 282 | |
cb323159 A |
283 | #if CONFIG_LOCKERBOOT |
284 | #define LOCKER_PROTOBOOT_MOUNT "/protoboot" | |
285 | ||
286 | const char kernel_protoboot_mount[] = LOCKER_PROTOBOOT_MOUNT; | |
287 | extern int mount_locker_protoboot(const char *fsname, const char *mntpoint, | |
288 | const char *pbdevpath); | |
289 | #endif | |
290 | ||
6d2010ae | 291 | extern int serverperfmode; |
2d21ac55 | 292 | extern int ncl; |
cb323159 A |
293 | #if DEVELOPMENT || DEBUG |
294 | extern int syscallfilter_disable; | |
295 | #endif // DEVELOPMENT || DEBUG | |
2d21ac55 | 296 | |
0a7de745 A |
297 | vm_map_t bsd_pageable_map; |
298 | vm_map_t mb_map; | |
b0d623f7 | 299 | |
6d2010ae A |
300 | static int bsd_simul_execs; |
301 | static int bsd_pageable_map_size; | |
302 | __private_extern__ int execargs_cache_size = 0; | |
303 | __private_extern__ int execargs_free_count = 0; | |
b0d623f7 A |
304 | __private_extern__ vm_offset_t * execargs_cache = NULL; |
305 | ||
39236c6e | 306 | void bsd_exec_setup(int); |
b0d623f7 | 307 | |
cb323159 A |
308 | __private_extern__ int bootarg_execfailurereports = 0; |
309 | ||
a39ff7e2 | 310 | #if __x86_64__ |
cb323159 | 311 | __private_extern__ int bootarg_no32exec = 1; |
a39ff7e2 | 312 | #endif |
6d2010ae A |
313 | __private_extern__ int bootarg_vnode_cache_defeat = 0; |
314 | ||
3e170ce0 A |
315 | #if CONFIG_JETSAM && (DEVELOPMENT || DEBUG) |
316 | __private_extern__ int bootarg_no_vnode_jetsam = 0; | |
317 | #endif /* CONFIG_JETSAM && (DEVELOPMENT || DEBUG) */ | |
318 | ||
94ff46dc A |
319 | __private_extern__ int bootarg_no_vnode_drain = 0; |
320 | ||
6d2010ae A |
321 | /* |
322 | * Prevent kernel-based ASLR from being used, for testing. | |
323 | */ | |
324 | #if DEVELOPMENT || DEBUG | |
325 | __private_extern__ int bootarg_disable_aslr = 0; | |
326 | #endif | |
1c79356b | 327 | |
39037602 A |
328 | /* |
329 | * Allow an alternate dyld to be used for testing. | |
330 | */ | |
331 | ||
332 | #if DEVELOPMENT || DEBUG | |
333 | char dyld_alt_path[MAXPATHLEN]; | |
334 | int use_alt_dyld = 0; | |
cb323159 | 335 | extern uint64_t dyld_flags; |
39037602 A |
336 | #endif |
337 | ||
0a7de745 | 338 | int cmask = CMASK; |
0c530ab8 | 339 | extern int customnbuf; |
1c79356b | 340 | |
39236c6e A |
341 | kern_return_t bsd_autoconf(void); |
342 | void bsd_utaskbootstrap(void); | |
2d21ac55 A |
343 | |
344 | static void parse_bsd_args(void); | |
fe8ab488 A |
345 | #if CONFIG_DEV_KMEM |
346 | extern void dev_kmem_init(void); | |
347 | #endif | |
9bccf70c | 348 | extern void time_zone_slock_init(void); |
3e170ce0 | 349 | extern void select_waitq_init(void); |
2d21ac55 | 350 | static void process_name(const char *, proc_t); |
91447636 A |
351 | |
352 | static void setconf(void); | |
1c79356b | 353 | |
2d21ac55 | 354 | #if SYSV_SHM |
91447636 | 355 | extern void sysv_shm_lock_init(void); |
2d21ac55 A |
356 | #endif |
357 | #if SYSV_SEM | |
91447636 | 358 | extern void sysv_sem_lock_init(void); |
2d21ac55 A |
359 | #endif |
360 | #if SYSV_MSG | |
91447636 | 361 | extern void sysv_msg_lock_init(void); |
2d21ac55 | 362 | #endif |
0c530ab8 | 363 | |
39037602 A |
364 | extern void ulock_initialize(void); |
365 | ||
6d2010ae A |
366 | #if CONFIG_MACF |
367 | #if defined (__i386__) || defined (__x86_64__) | |
368 | /* MACF policy_check configuration flags; see policy_check.c for details */ | |
369 | int policy_check_flags = 0; | |
2d21ac55 | 370 | |
6d2010ae A |
371 | extern int check_policy_init(int); |
372 | #endif | |
0a7de745 | 373 | #endif /* CONFIG_MACF */ |
2d21ac55 | 374 | |
b0d623f7 A |
375 | /* If we are using CONFIG_DTRACE */ |
376 | #if CONFIG_DTRACE | |
0a7de745 | 377 | extern void dtrace_postinit(void); |
b0d623f7 A |
378 | #endif |
379 | ||
1c79356b A |
380 | /* |
381 | * Initialization code. | |
382 | * Called from cold start routine as | |
383 | * soon as a stack and segmentation | |
384 | * have been established. | |
385 | * Functions: | |
1c79356b A |
386 | * turn on clock |
387 | * hand craft 0th process | |
388 | * call all initialization routines | |
55e303ae | 389 | * hand craft 1st user process |
1c79356b A |
390 | */ |
391 | ||
392 | /* | |
393 | * Sets the name for the given task. | |
394 | */ | |
91447636 | 395 | static void |
2d21ac55 | 396 | process_name(const char *s, proc_t p) |
1c79356b | 397 | { |
0a7de745 A |
398 | strlcpy(p->p_comm, s, sizeof(p->p_comm)); |
399 | strlcpy(p->p_name, s, sizeof(p->p_name)); | |
1c79356b A |
400 | } |
401 | ||
1c79356b A |
402 | /* To allow these values to be patched, they're globals here */ |
403 | #include <machine/vmparam.h> | |
cb323159 A |
404 | struct rlimit vm_initial_limit_stack = { .rlim_cur = DFLSSIZ, .rlim_max = MAXSSIZ - PAGE_MAX_SIZE }; |
405 | struct rlimit vm_initial_limit_data = { .rlim_cur = DFLDSIZ, .rlim_max = MAXDSIZ }; | |
406 | struct rlimit vm_initial_limit_core = { .rlim_cur = DFLCSIZ, .rlim_max = MAXCSIZ }; | |
1c79356b | 407 | |
0a7de745 A |
408 | extern thread_t cloneproc(task_t, coalition_t, proc_t, int, int); |
409 | extern int (*mountroot)(void); | |
1c79356b | 410 | |
91447636 | 411 | lck_grp_t * proc_lck_grp; |
b0d623f7 A |
412 | lck_grp_t * proc_slock_grp; |
413 | lck_grp_t * proc_fdmlock_grp; | |
5ba3f43e A |
414 | lck_grp_t * proc_kqhashlock_grp; |
415 | lck_grp_t * proc_knhashlock_grp; | |
4bd07ac2 | 416 | lck_grp_t * proc_ucred_mlock_grp; |
b0d623f7 | 417 | lck_grp_t * proc_mlock_grp; |
bca245ac | 418 | lck_grp_t * proc_dirslock_grp; |
91447636 A |
419 | lck_grp_attr_t * proc_lck_grp_attr; |
420 | lck_attr_t * proc_lck_attr; | |
2d21ac55 A |
421 | lck_mtx_t * proc_list_mlock; |
422 | lck_mtx_t * proc_klist_mlock; | |
91447636 | 423 | |
d9a64523 A |
424 | #if CONFIG_XNUPOST |
425 | lck_grp_t * sysctl_debug_test_stackshot_owner_grp; | |
426 | lck_mtx_t * sysctl_debug_test_stackshot_owner_init_mtx; | |
427 | #endif /* !CONFIG_XNUPOST */ | |
813fb2f6 | 428 | |
b0d623f7 A |
429 | extern lck_mtx_t * execargs_cache_lock; |
430 | ||
9bccf70c A |
431 | /* hook called after root is mounted XXX temporary hack */ |
432 | void (*mountroot_post_hook)(void); | |
b0d623f7 | 433 | void (*unmountroot_pre_hook)(void); |
1c79356b | 434 | |
39037602 A |
435 | /* |
436 | * This function is called before IOKit initialization, so that globals | |
437 | * like the sysctl tree are initialized before kernel extensions | |
438 | * are started (since they may want to register sysctls | |
439 | */ | |
440 | void | |
441 | bsd_early_init(void) | |
442 | { | |
443 | sysctl_early_init(); | |
444 | } | |
445 | ||
91447636 A |
446 | /* |
447 | * This function is called very early on in the Mach startup, from the | |
448 | * function start_kernel_threads() in osfmk/kern/startup.c. It's called | |
449 | * in the context of the current (startup) task using a call to the | |
450 | * function kernel_thread_create() to jump into start_kernel_threads(). | |
451 | * Internally, kernel_thread_create() calls thread_create_internal(), | |
452 | * which calls uthread_alloc(). The function of uthread_alloc() is | |
453 | * normally to allocate a uthread structure, and fill out the uu_sigmask, | |
2d21ac55 A |
454 | * uu_context fields. It skips filling these out in the case of the "task" |
455 | * being "kernel_task", because the order of operation is inverted. To | |
456 | * account for that, we need to manually fill in at least the contents | |
457 | * of the uu_context.vc_ucred field so that the uthread structure can be | |
458 | * used like any other. | |
91447636 | 459 | */ |
316670eb | 460 | |
1c79356b | 461 | void |
2d21ac55 | 462 | bsd_init(void) |
1c79356b | 463 | { |
91447636 | 464 | struct uthread *ut; |
2d21ac55 | 465 | unsigned int i; |
91447636 | 466 | struct vfs_context context; |
0a7de745 | 467 | kern_return_t ret; |
91447636 | 468 | struct ucred temp_cred; |
6d2010ae | 469 | struct posix_cred temp_pcred; |
cb323159 | 470 | #if CONFIG_NETBOOT || CONFIG_IMAGEBOOT |
6d2010ae A |
471 | boolean_t netboot = FALSE; |
472 | #endif | |
cb323159 A |
473 | #if CONFIG_LOCKERBOOT |
474 | vnode_t pbvn = NULLVP; | |
475 | mount_t pbmnt = NULL; | |
476 | char *pbdevp = NULL; | |
477 | char pbdevpath[64]; | |
478 | char pbfsname[MFSNAMELEN]; | |
479 | char *slash_dev = NULL; | |
480 | #endif | |
2d21ac55 | 481 | |
cb323159 A |
482 | #define DEBUG_BSDINIT 0 |
483 | ||
484 | #if DEBUG_BSDINIT | |
485 | #define bsd_init_kprintf(x, ...) kprintf("bsd_init: " x, ## __VA_ARGS__) | |
486 | #else | |
487 | #define bsd_init_kprintf(x, ...) | |
488 | #endif | |
1c79356b | 489 | |
316670eb A |
490 | throttle_init(); |
491 | ||
1c79356b | 492 | printf(copyright); |
0a7de745 | 493 | |
2d21ac55 | 494 | bsd_init_kprintf("calling kmeminit\n"); |
1c79356b | 495 | kmeminit(); |
0a7de745 | 496 | |
2d21ac55 | 497 | bsd_init_kprintf("calling parse_bsd_args\n"); |
1c79356b A |
498 | parse_bsd_args(); |
499 | ||
fe8ab488 A |
500 | #if CONFIG_DEV_KMEM |
501 | bsd_init_kprintf("calling dev_kmem_init\n"); | |
502 | dev_kmem_init(); | |
503 | #endif | |
504 | ||
91447636 | 505 | /* Initialize kauth subsystem before instancing the first credential */ |
2d21ac55 | 506 | bsd_init_kprintf("calling kauth_init\n"); |
91447636 A |
507 | kauth_init(); |
508 | ||
509 | /* Initialize process and pgrp structures. */ | |
2d21ac55 | 510 | bsd_init_kprintf("calling procinit\n"); |
1c79356b A |
511 | procinit(); |
512 | ||
b0d623f7 A |
513 | /* Initialize the ttys (MUST be before kminit()/bsd_autoconf()!)*/ |
514 | tty_init(); | |
1c79356b | 515 | |
0a7de745 | 516 | kernproc = &proc0; /* implicitly bzero'ed */ |
1c79356b A |
517 | |
518 | /* kernel_task->proc = kernproc; */ | |
0a7de745 | 519 | set_bsdtask_info(kernel_task, (void *)kernproc); |
1c79356b A |
520 | |
521 | /* give kernproc a name */ | |
2d21ac55 | 522 | bsd_init_kprintf("calling process_name\n"); |
b0d623f7 | 523 | process_name("kernel_task", kernproc); |
91447636 | 524 | |
91447636 | 525 | /* allocate proc lock group attribute and group */ |
2d21ac55 | 526 | bsd_init_kprintf("calling lck_grp_attr_alloc_init\n"); |
0a7de745 | 527 | proc_lck_grp_attr = lck_grp_attr_alloc_init(); |
91447636 | 528 | |
0a7de745 | 529 | proc_lck_grp = lck_grp_alloc_init("proc", proc_lck_grp_attr); |
5ba3f43e | 530 | |
0a7de745 A |
531 | proc_slock_grp = lck_grp_alloc_init("proc-slock", proc_lck_grp_attr); |
532 | proc_ucred_mlock_grp = lck_grp_alloc_init("proc-ucred-mlock", proc_lck_grp_attr); | |
533 | proc_mlock_grp = lck_grp_alloc_init("proc-mlock", proc_lck_grp_attr); | |
534 | proc_fdmlock_grp = lck_grp_alloc_init("proc-fdmlock", proc_lck_grp_attr); | |
535 | proc_kqhashlock_grp = lck_grp_alloc_init("proc-kqhashlock", proc_lck_grp_attr); | |
536 | proc_knhashlock_grp = lck_grp_alloc_init("proc-knhashlock", proc_lck_grp_attr); | |
bca245ac | 537 | proc_dirslock_grp = lck_grp_alloc_init("proc-dirslock", proc_lck_grp_attr); |
d9a64523 A |
538 | #if CONFIG_XNUPOST |
539 | sysctl_debug_test_stackshot_owner_grp = lck_grp_alloc_init("test-stackshot-owner-grp", LCK_GRP_ATTR_NULL); | |
540 | sysctl_debug_test_stackshot_owner_init_mtx = lck_mtx_alloc_init( | |
0a7de745 A |
541 | sysctl_debug_test_stackshot_owner_grp, |
542 | LCK_ATTR_NULL); | |
d9a64523 | 543 | #endif /* !CONFIG_XNUPOST */ |
91447636 A |
544 | /* Allocate proc lock attribute */ |
545 | proc_lck_attr = lck_attr_alloc_init(); | |
91447636 | 546 | |
b0d623f7 A |
547 | proc_list_mlock = lck_mtx_alloc_init(proc_mlock_grp, proc_lck_attr); |
548 | proc_klist_mlock = lck_mtx_alloc_init(proc_mlock_grp, proc_lck_attr); | |
549 | lck_mtx_init(&kernproc->p_mlock, proc_mlock_grp, proc_lck_attr); | |
550 | lck_mtx_init(&kernproc->p_fdmlock, proc_fdmlock_grp, proc_lck_attr); | |
4bd07ac2 | 551 | lck_mtx_init(&kernproc->p_ucred_mlock, proc_ucred_mlock_grp, proc_lck_attr); |
b0d623f7 | 552 | lck_spin_init(&kernproc->p_slock, proc_slock_grp, proc_lck_attr); |
bca245ac | 553 | lck_rw_init(&kernproc->p_dirs_lock, proc_dirslock_grp, proc_lck_attr); |
1c79356b | 554 | |
6d2010ae | 555 | assert(bsd_simul_execs != 0); |
b0d623f7 A |
556 | execargs_cache_lock = lck_mtx_alloc_init(proc_lck_grp, proc_lck_attr); |
557 | execargs_cache_size = bsd_simul_execs; | |
558 | execargs_free_count = bsd_simul_execs; | |
559 | execargs_cache = (vm_offset_t *)kalloc(bsd_simul_execs * sizeof(vm_offset_t)); | |
560 | bzero(execargs_cache, bsd_simul_execs * sizeof(vm_offset_t)); | |
0a7de745 A |
561 | |
562 | if (current_task() != kernel_task) { | |
9bccf70c | 563 | printf("bsd_init: We have a problem, " |
0a7de745 A |
564 | "current task is not kernel task\n"); |
565 | } | |
566 | ||
2d21ac55 | 567 | bsd_init_kprintf("calling get_bsdthread_info\n"); |
91447636 A |
568 | ut = (uthread_t)get_bsdthread_info(current_thread()); |
569 | ||
2d21ac55 A |
570 | #if CONFIG_MACF |
571 | /* | |
572 | * Initialize the MAC Framework | |
573 | */ | |
574 | mac_policy_initbsd(); | |
6d2010ae A |
575 | |
576 | #if defined (__i386__) || defined (__x86_64__) | |
577 | /* | |
578 | * We currently only support this on i386/x86_64, as that is the | |
579 | * only lock code we have instrumented so far. | |
580 | */ | |
581 | check_policy_init(policy_check_flags); | |
582 | #endif | |
2d21ac55 A |
583 | #endif /* MAC */ |
584 | ||
39037602 A |
585 | ulock_initialize(); |
586 | ||
cb323159 A |
587 | hostname_lck_grp = lck_grp_alloc_init("hostname", LCK_GRP_ATTR_NULL); |
588 | lck_mtx_init(&hostname_lock, hostname_lck_grp, LCK_ATTR_NULL); | |
589 | lck_mtx_init(&domainname_lock, hostname_lck_grp, LCK_ATTR_NULL); | |
590 | ||
1c79356b A |
591 | /* |
592 | * Create process 0. | |
593 | */ | |
2d21ac55 | 594 | proc_list_lock(); |
b0d623f7 A |
595 | LIST_INSERT_HEAD(&allproc, kernproc, p_list); |
596 | kernproc->p_pgrp = &pgrp0; | |
1c79356b A |
597 | LIST_INSERT_HEAD(PGRPHASH(0), &pgrp0, pg_hash); |
598 | LIST_INIT(&pgrp0.pg_members); | |
b0d623f7 | 599 | lck_mtx_init(&pgrp0.pg_mlock, proc_mlock_grp, proc_lck_attr); |
2d21ac55 | 600 | /* There is no other bsd thread this point and is safe without pgrp lock */ |
b0d623f7 A |
601 | LIST_INSERT_HEAD(&pgrp0.pg_members, kernproc, p_pglist); |
602 | kernproc->p_listflag |= P_LIST_INPGRP; | |
603 | kernproc->p_pgrpid = 0; | |
6d2010ae | 604 | kernproc->p_uniqueid = 0; |
1c79356b A |
605 | |
606 | pgrp0.pg_session = &session0; | |
2d21ac55 A |
607 | pgrp0.pg_membercnt = 1; |
608 | ||
1c79356b | 609 | session0.s_count = 1; |
b0d623f7 | 610 | session0.s_leader = kernproc; |
2d21ac55 | 611 | session0.s_listflags = 0; |
b0d623f7 | 612 | lck_mtx_init(&session0.s_mlock, proc_mlock_grp, proc_lck_attr); |
2d21ac55 A |
613 | LIST_INSERT_HEAD(SESSHASH(0), &session0, s_hash); |
614 | proc_list_unlock(); | |
615 | ||
490019cf A |
616 | #if CONFIG_PERSONAS |
617 | kernproc->p_persona = NULL; | |
618 | #endif | |
619 | ||
b0d623f7 | 620 | kernproc->task = kernel_task; |
0a7de745 | 621 | |
b0d623f7 A |
622 | kernproc->p_stat = SRUN; |
623 | kernproc->p_flag = P_SYSTEM; | |
6d2010ae A |
624 | kernproc->p_lflag = 0; |
625 | kernproc->p_ladvflag = 0; | |
39037602 A |
626 | |
627 | #if defined(__LP64__) | |
628 | kernproc->p_flag |= P_LP64; | |
629 | #endif | |
630 | ||
6d2010ae | 631 | #if DEVELOPMENT || DEBUG |
0a7de745 | 632 | if (bootarg_disable_aslr) { |
6d2010ae | 633 | kernproc->p_flag |= P_DISABLE_ASLR; |
0a7de745 | 634 | } |
6d2010ae A |
635 | #endif |
636 | ||
b0d623f7 A |
637 | kernproc->p_nice = NZERO; |
638 | kernproc->p_pptr = kernproc; | |
2d21ac55 | 639 | |
b0d623f7 A |
640 | TAILQ_INIT(&kernproc->p_uthlist); |
641 | TAILQ_INSERT_TAIL(&kernproc->p_uthlist, ut, uu_list); | |
0a7de745 | 642 | |
b0d623f7 A |
643 | kernproc->sigwait = FALSE; |
644 | kernproc->sigwait_thread = THREAD_NULL; | |
645 | kernproc->exit_thread = THREAD_NULL; | |
646 | kernproc->p_csflags = CS_VALID; | |
1c79356b | 647 | |
91447636 A |
648 | /* |
649 | * Create credential. This also Initializes the audit information. | |
91447636 | 650 | */ |
2d21ac55 | 651 | bsd_init_kprintf("calling bzero\n"); |
91447636 | 652 | bzero(&temp_cred, sizeof(temp_cred)); |
6d2010ae A |
653 | bzero(&temp_pcred, sizeof(temp_pcred)); |
654 | temp_pcred.cr_ngroups = 1; | |
39236c6e A |
655 | /* kern_proc, shouldn't call up to DS for group membership */ |
656 | temp_pcred.cr_flags = CRF_NOMEMBERD; | |
6d2010ae | 657 | temp_cred.cr_audit.as_aia_p = audit_default_aia_p; |
0a7de745 | 658 | |
2d21ac55 | 659 | bsd_init_kprintf("calling kauth_cred_create\n"); |
6d2010ae A |
660 | /* |
661 | * We have to label the temp cred before we create from it to | |
662 | * properly set cr_ngroups, or the create will fail. | |
663 | */ | |
664 | posix_cred_label(&temp_cred, &temp_pcred); | |
0a7de745 | 665 | kernproc->p_ucred = kauth_cred_create(&temp_cred); |
91447636 | 666 | |
6d2010ae A |
667 | /* update cred on proc */ |
668 | PROC_UPDATE_CREDS_ONPROC(kernproc); | |
669 | ||
91447636 | 670 | /* give the (already exisiting) initial thread a reference on it */ |
2d21ac55 | 671 | bsd_init_kprintf("calling kauth_cred_ref\n"); |
b0d623f7 A |
672 | kauth_cred_ref(kernproc->p_ucred); |
673 | ut->uu_context.vc_ucred = kernproc->p_ucred; | |
2d21ac55 A |
674 | ut->uu_context.vc_thread = current_thread(); |
675 | ||
b0d623f7 A |
676 | TAILQ_INIT(&kernproc->p_aio_activeq); |
677 | TAILQ_INIT(&kernproc->p_aio_doneq); | |
678 | kernproc->p_aio_total_count = 0; | |
679 | kernproc->p_aio_active_count = 0; | |
55e303ae | 680 | |
2d21ac55 | 681 | bsd_init_kprintf("calling file_lock_init\n"); |
91447636 | 682 | file_lock_init(); |
1c79356b | 683 | |
2d21ac55 | 684 | #if CONFIG_MACF |
b0d623f7 | 685 | mac_cred_label_associate_kernel(kernproc->p_ucred); |
2d21ac55 A |
686 | #endif |
687 | ||
1c79356b | 688 | /* Create the file descriptor table. */ |
b0d623f7 | 689 | kernproc->p_fd = &filedesc0; |
1c79356b | 690 | filedesc0.fd_cmask = cmask; |
cb323159 | 691 | filedesc0.fd_knlistsize = 0; |
55e303ae A |
692 | filedesc0.fd_knlist = NULL; |
693 | filedesc0.fd_knhash = NULL; | |
694 | filedesc0.fd_knhashmask = 0; | |
5ba3f43e A |
695 | lck_mtx_init(&filedesc0.fd_kqhashlock, proc_kqhashlock_grp, proc_lck_attr); |
696 | lck_mtx_init(&filedesc0.fd_knhashlock, proc_knhashlock_grp, proc_lck_attr); | |
1c79356b A |
697 | |
698 | /* Create the limits structures. */ | |
b0d623f7 | 699 | kernproc->p_limit = &limit0; |
0a7de745 A |
700 | for (i = 0; i < sizeof(kernproc->p_rlimit) / sizeof(kernproc->p_rlimit[0]); i++) { |
701 | limit0.pl_rlimit[i].rlim_cur = | |
702 | limit0.pl_rlimit[i].rlim_max = RLIM_INFINITY; | |
703 | } | |
1c79356b | 704 | limit0.pl_rlimit[RLIMIT_NOFILE].rlim_cur = NOFILE; |
0c530ab8 | 705 | limit0.pl_rlimit[RLIMIT_NPROC].rlim_cur = maxprocperuid; |
55e303ae | 706 | limit0.pl_rlimit[RLIMIT_NPROC].rlim_max = maxproc; |
1c79356b A |
707 | limit0.pl_rlimit[RLIMIT_STACK] = vm_initial_limit_stack; |
708 | limit0.pl_rlimit[RLIMIT_DATA] = vm_initial_limit_data; | |
709 | limit0.pl_rlimit[RLIMIT_CORE] = vm_initial_limit_core; | |
2d21ac55 | 710 | limit0.pl_refcnt = 1; |
1c79356b | 711 | |
b0d623f7 A |
712 | kernproc->p_stats = &pstats0; |
713 | kernproc->p_sigacts = &sigacts0; | |
1c79356b A |
714 | |
715 | /* | |
fe8ab488 | 716 | * Charge root for one process: launchd. |
1c79356b | 717 | */ |
2d21ac55 | 718 | bsd_init_kprintf("calling chgproccnt\n"); |
1c79356b A |
719 | (void)chgproccnt(0, 1); |
720 | ||
1c79356b A |
721 | /* |
722 | * Allocate a kernel submap for pageable memory | |
765c9de3 | 723 | * for temporary copying (execve()). |
1c79356b A |
724 | */ |
725 | { | |
0a7de745 | 726 | vm_offset_t minimum; |
1c79356b | 727 | |
2d21ac55 | 728 | bsd_init_kprintf("calling kmem_suballoc\n"); |
6d2010ae | 729 | assert(bsd_pageable_map_size != 0); |
1c79356b | 730 | ret = kmem_suballoc(kernel_map, |
0a7de745 A |
731 | &minimum, |
732 | (vm_size_t)bsd_pageable_map_size, | |
733 | TRUE, | |
734 | VM_FLAGS_ANYWHERE, | |
735 | VM_MAP_KERNEL_FLAGS_NONE, | |
736 | VM_KERN_MEMORY_BSD, | |
737 | &bsd_pageable_map); | |
738 | if (ret != KERN_SUCCESS) { | |
9bccf70c | 739 | panic("bsd_init: Failed to allocate bsd pageable map"); |
0a7de745 | 740 | } |
765c9de3 A |
741 | } |
742 | ||
cc8bc92a A |
743 | bsd_init_kprintf("calling fpxlog_init\n"); |
744 | fpxlog_init(); | |
745 | ||
91447636 A |
746 | /* |
747 | * Initialize buffers and hash links for buffers | |
748 | * | |
749 | * SIDE EFFECT: Starts a thread for bcleanbuf_thread(), so must | |
750 | * happen after a credential has been associated with | |
751 | * the kernel task. | |
752 | */ | |
2d21ac55 | 753 | bsd_init_kprintf("calling bsd_bufferinit\n"); |
91447636 A |
754 | bsd_bufferinit(); |
755 | ||
1c79356b | 756 | /* |
0b4e3aa0 A |
757 | * Initialize the calendar. |
758 | */ | |
4a3eedf9 | 759 | bsd_init_kprintf("calling IOKitInitializeTime\n"); |
2d21ac55 A |
760 | IOKitInitializeTime(); |
761 | ||
2d21ac55 | 762 | bsd_init_kprintf("calling ubc_init\n"); |
1c79356b A |
763 | ubc_init(); |
764 | ||
765 | /* Initialize the file systems. */ | |
2d21ac55 | 766 | bsd_init_kprintf("calling vfsinit\n"); |
1c79356b A |
767 | vfsinit(); |
768 | ||
94ff46dc A |
769 | /* Initialize file locks. */ |
770 | bsd_init_kprintf("calling lf_init\n"); | |
771 | lf_init(); | |
772 | ||
39236c6e A |
773 | #if CONFIG_PROC_UUID_POLICY |
774 | /* Initial proc_uuid_policy subsystem */ | |
775 | bsd_init_kprintf("calling proc_uuid_policy_init()\n"); | |
776 | proc_uuid_policy_init(); | |
777 | #endif | |
778 | ||
2d21ac55 A |
779 | #if SOCKETS |
780 | /* Initialize per-CPU cache allocator */ | |
781 | mcache_init(); | |
782 | ||
1c79356b | 783 | /* Initialize mbuf's. */ |
2d21ac55 | 784 | bsd_init_kprintf("calling mbinit\n"); |
1c79356b | 785 | mbinit(); |
b0d623f7 | 786 | net_str_id_init(); /* for mbuf tags */ |
cb323159 | 787 | restricted_in_port_init(); |
2d21ac55 | 788 | #endif /* SOCKETS */ |
1c79356b | 789 | |
55e303ae A |
790 | /* |
791 | * Initializes security event auditing. | |
792 | * XXX: Should/could this occur later? | |
793 | */ | |
b0d623f7 | 794 | #if CONFIG_AUDIT |
2d21ac55 | 795 | bsd_init_kprintf("calling audit_init\n"); |
0a7de745 | 796 | audit_init(); |
2d21ac55 | 797 | #endif |
55e303ae A |
798 | |
799 | /* Initialize kqueues */ | |
2d21ac55 | 800 | bsd_init_kprintf("calling knote_init\n"); |
55e303ae A |
801 | knote_init(); |
802 | ||
5ba3f43e A |
803 | /* Initialize event handler */ |
804 | bsd_init_kprintf("calling eventhandler_init\n"); | |
805 | eventhandler_init(); | |
806 | ||
55e303ae | 807 | /* Initialize for async IO */ |
2d21ac55 | 808 | bsd_init_kprintf("calling aio_init\n"); |
55e303ae A |
809 | aio_init(); |
810 | ||
91447636 | 811 | /* Initialize pipes */ |
2d21ac55 | 812 | bsd_init_kprintf("calling pipeinit\n"); |
91447636 A |
813 | pipeinit(); |
814 | ||
815 | /* Initialize SysV shm subsystem locks; the subsystem proper is | |
816 | * initialized through a sysctl. | |
817 | */ | |
2d21ac55 A |
818 | #if SYSV_SHM |
819 | bsd_init_kprintf("calling sysv_shm_lock_init\n"); | |
91447636 | 820 | sysv_shm_lock_init(); |
2d21ac55 A |
821 | #endif |
822 | #if SYSV_SEM | |
823 | bsd_init_kprintf("calling sysv_sem_lock_init\n"); | |
91447636 | 824 | sysv_sem_lock_init(); |
2d21ac55 A |
825 | #endif |
826 | #if SYSV_MSG | |
827 | bsd_init_kprintf("sysv_msg_lock_init\n"); | |
91447636 | 828 | sysv_msg_lock_init(); |
2d21ac55 A |
829 | #endif |
830 | bsd_init_kprintf("calling pshm_lock_init\n"); | |
91447636 | 831 | pshm_lock_init(); |
2d21ac55 | 832 | bsd_init_kprintf("calling psem_lock_init\n"); |
91447636 A |
833 | psem_lock_init(); |
834 | ||
2d21ac55 | 835 | pthread_init(); |
9bccf70c | 836 | /* POSIX Shm and Sem */ |
2d21ac55 | 837 | bsd_init_kprintf("calling pshm_cache_init\n"); |
9bccf70c | 838 | pshm_cache_init(); |
2d21ac55 | 839 | bsd_init_kprintf("calling psem_cache_init\n"); |
9bccf70c | 840 | psem_cache_init(); |
2d21ac55 | 841 | bsd_init_kprintf("calling time_zone_slock_init\n"); |
9bccf70c | 842 | time_zone_slock_init(); |
3e170ce0 A |
843 | bsd_init_kprintf("calling select_waitq_init\n"); |
844 | select_waitq_init(); | |
1c79356b | 845 | |
1c79356b A |
846 | /* |
847 | * Initialize protocols. Block reception of incoming packets | |
848 | * until everything is ready. | |
849 | */ | |
2d21ac55 | 850 | #if NETWORKING |
5ba3f43e A |
851 | bsd_init_kprintf("calling nwk_wq_init\n"); |
852 | nwk_wq_init(); | |
2d21ac55 | 853 | bsd_init_kprintf("calling dlil_init\n"); |
1c79356b | 854 | dlil_init(); |
2d21ac55 | 855 | bsd_init_kprintf("calling proto_kpi_init\n"); |
91447636 | 856 | proto_kpi_init(); |
2d21ac55 A |
857 | #endif /* NETWORKING */ |
858 | #if SOCKETS | |
859 | bsd_init_kprintf("calling socketinit\n"); | |
1c79356b | 860 | socketinit(); |
2d21ac55 | 861 | bsd_init_kprintf("calling domaininit\n"); |
1c79356b | 862 | domaininit(); |
316670eb | 863 | iptap_init(); |
39236c6e A |
864 | #if FLOW_DIVERT |
865 | flow_divert_init(); | |
0a7de745 | 866 | #endif /* FLOW_DIVERT */ |
2d21ac55 | 867 | #endif /* SOCKETS */ |
b0d623f7 A |
868 | kernproc->p_fd->fd_cdir = NULL; |
869 | kernproc->p_fd->fd_rdir = NULL; | |
1c79356b | 870 | |
6d2010ae | 871 | #if CONFIG_FREEZE |
316670eb A |
872 | #ifndef CONFIG_MEMORYSTATUS |
873 | #error "CONFIG_FREEZE defined without matching CONFIG_MEMORYSTATUS" | |
874 | #endif | |
875 | /* Initialise background freezing */ | |
876 | bsd_init_kprintf("calling memorystatus_freeze_init\n"); | |
877 | memorystatus_freeze_init(); | |
6d2010ae A |
878 | #endif |
879 | ||
316670eb | 880 | #if CONFIG_MEMORYSTATUS |
d1ecb069 | 881 | /* Initialize kernel memory status notifications */ |
316670eb A |
882 | bsd_init_kprintf("calling memorystatus_init\n"); |
883 | memorystatus_init(); | |
884 | #endif /* CONFIG_MEMORYSTATUS */ | |
d1ecb069 | 885 | |
fe8ab488 A |
886 | bsd_init_kprintf("calling acct_init\n"); |
887 | acct_init(); | |
888 | ||
39037602 | 889 | bsd_init_kprintf("calling sysctl_mib_init\n"); |
cb323159 | 890 | sysctl_mib_init(); |
39037602 | 891 | |
2d21ac55 | 892 | bsd_init_kprintf("calling bsd_autoconf\n"); |
1c79356b A |
893 | bsd_autoconf(); |
894 | ||
39037602 A |
895 | bsd_init_kprintf("calling os_reason_init\n"); |
896 | os_reason_init(); | |
897 | ||
2d21ac55 | 898 | #if CONFIG_DTRACE |
2d21ac55 A |
899 | dtrace_postinit(); |
900 | #endif | |
901 | ||
1c79356b A |
902 | /* |
903 | * We attach the loopback interface *way* down here to ensure | |
904 | * it happens after autoconf(), otherwise it becomes the | |
905 | * "primary" interface. | |
906 | */ | |
907 | #include <loop.h> | |
908 | #if NLOOP > 0 | |
2d21ac55 | 909 | bsd_init_kprintf("calling loopattach\n"); |
0a7de745 | 910 | loopattach(); /* XXX */ |
1c79356b | 911 | #endif |
39236c6e A |
912 | #if NGIF |
913 | /* Initialize gif interface (after lo0) */ | |
914 | gif_init(); | |
915 | #endif | |
b0d623f7 A |
916 | |
917 | #if PFLOG | |
918 | /* Initialize packet filter log interface */ | |
919 | pfloginit(); | |
920 | #endif /* PFLOG */ | |
921 | ||
2d21ac55 A |
922 | #if NETHER > 0 |
923 | /* Register the built-in dlil ethernet interface family */ | |
924 | bsd_init_kprintf("calling ether_family_init\n"); | |
9bccf70c | 925 | ether_family_init(); |
2d21ac55 | 926 | #endif /* ETHER */ |
1c79356b | 927 | |
2d21ac55 | 928 | #if NETWORKING |
91447636 | 929 | /* Call any kext code that wants to run just after network init */ |
2d21ac55 | 930 | bsd_init_kprintf("calling net_init_run\n"); |
91447636 | 931 | net_init_run(); |
0a7de745 | 932 | |
fe8ab488 A |
933 | #if CONTENT_FILTER |
934 | cfil_init(); | |
935 | #endif | |
936 | ||
937 | #if PACKET_MANGLER | |
938 | pkt_mnglr_init(); | |
0a7de745 | 939 | #endif |
fe8ab488 A |
940 | |
941 | #if NECP | |
942 | /* Initialize Network Extension Control Policies */ | |
943 | necp_init(); | |
944 | #endif | |
3e170ce0 A |
945 | |
946 | netagent_init(); | |
947 | ||
b0d623f7 A |
948 | /* register user tunnel kernel control handler */ |
949 | utun_register_control(); | |
39236c6e A |
950 | #if IPSEC |
951 | ipsec_register_control(); | |
952 | #endif /* IPSEC */ | |
316670eb A |
953 | netsrc_init(); |
954 | nstat_init(); | |
fe8ab488 | 955 | tcp_cc_init(); |
3e170ce0 A |
956 | #if MPTCP |
957 | mptcp_control_register(); | |
958 | #endif /* MPTCP */ | |
2d21ac55 | 959 | #endif /* NETWORKING */ |
91447636 | 960 | |
2d21ac55 | 961 | bsd_init_kprintf("calling vnode_pager_bootstrap\n"); |
1c79356b | 962 | vnode_pager_bootstrap(); |
91447636 | 963 | |
2d21ac55 | 964 | bsd_init_kprintf("calling inittodr\n"); |
91447636 | 965 | inittodr(0); |
1c79356b A |
966 | |
967 | /* Mount the root file system. */ | |
0a7de745 | 968 | while (TRUE) { |
1c79356b A |
969 | int err; |
970 | ||
2d21ac55 | 971 | bsd_init_kprintf("calling setconf\n"); |
1c79356b | 972 | setconf(); |
cb323159 | 973 | #if CONFIG_NETBOOT |
6d2010ae A |
974 | netboot = (mountroot == netboot_mountroot); |
975 | #endif | |
9bccf70c | 976 | |
2d21ac55 | 977 | bsd_init_kprintf("vfs_mountroot\n"); |
0a7de745 | 978 | if (0 == (err = vfs_mountroot())) { |
1c79356b | 979 | break; |
0a7de745 | 980 | } |
2d21ac55 | 981 | rootdevice[0] = '\0'; |
cb323159 | 982 | #if CONFIG_NETBOOT |
6d2010ae | 983 | if (netboot) { |
b0d623f7 A |
984 | PE_display_icon( 0, "noroot"); /* XXX a netboot-specific icon would be nicer */ |
985 | vc_progress_set(FALSE, 0); | |
0a7de745 | 986 | for (i = 1; 1; i *= 2) { |
b0d623f7 | 987 | printf("bsd_init: failed to mount network root, error %d, %s\n", |
0a7de745 | 988 | err, PE_boot_args()); |
b0d623f7 | 989 | printf("We are hanging here...\n"); |
0a7de745 | 990 | IOSleep(i * 60 * 1000); |
b0d623f7 A |
991 | } |
992 | /*NOTREACHED*/ | |
9bccf70c | 993 | } |
91447636 | 994 | #endif |
1c79356b A |
995 | printf("cannot mount root, errno = %d\n", err); |
996 | boothowto |= RB_ASKNAME; | |
997 | } | |
998 | ||
2d21ac55 A |
999 | IOSecureBSDRoot(rootdevice); |
1000 | ||
1001 | context.vc_thread = current_thread(); | |
b0d623f7 | 1002 | context.vc_ucred = kernproc->p_ucred; |
91447636 | 1003 | mountlist.tqh_first->mnt_flag |= MNT_ROOTFS; |
1c79356b | 1004 | |
2d21ac55 | 1005 | bsd_init_kprintf("calling VFS_ROOT\n"); |
1c79356b | 1006 | /* Get the vnode for '/'. Set fdp->fd_fd.fd_cdir to reference it. */ |
0a7de745 | 1007 | if (VFS_ROOT(mountlist.tqh_first, &rootvnode, &context)) { |
2d21ac55 | 1008 | panic("bsd_init: cannot find root vnode: %s", PE_boot_args()); |
0a7de745 | 1009 | } |
91447636 A |
1010 | rootvnode->v_flag |= VROOT; |
1011 | (void)vnode_ref(rootvnode); | |
1012 | (void)vnode_put(rootvnode); | |
fa4905b1 | 1013 | filedesc0.fd_cdir = rootvnode; |
9bccf70c | 1014 | |
cb323159 | 1015 | #if CONFIG_NETBOOT |
6d2010ae | 1016 | if (netboot) { |
9bccf70c | 1017 | int err; |
6d2010ae A |
1018 | |
1019 | netboot = TRUE; | |
9bccf70c | 1020 | /* post mount setup */ |
2d21ac55 | 1021 | if ((err = netboot_setup()) != 0) { |
b0d623f7 A |
1022 | PE_display_icon( 0, "noroot"); /* XXX a netboot-specific icon would be nicer */ |
1023 | vc_progress_set(FALSE, 0); | |
0a7de745 | 1024 | for (i = 1; 1; i *= 2) { |
b0d623f7 | 1025 | printf("bsd_init: NetBoot could not find root, error %d: %s\n", |
0a7de745 | 1026 | err, PE_boot_args()); |
b0d623f7 | 1027 | printf("We are hanging here...\n"); |
0a7de745 | 1028 | IOSleep(i * 60 * 1000); |
b0d623f7 A |
1029 | } |
1030 | /*NOTREACHED*/ | |
9bccf70c A |
1031 | } |
1032 | } | |
91447636 | 1033 | #endif |
0a7de745 | 1034 | |
1c79356b | 1035 | |
2d21ac55 | 1036 | #if CONFIG_IMAGEBOOT |
cb323159 A |
1037 | #if CONFIG_LOCKERBOOT |
1038 | /* | |
1039 | * Stash the protoboot vnode, mount, filesystem name, and device name for | |
1040 | * later use. Note that the mount-from name may not have the "/dev/" | |
1041 | * component, so we must sniff out this condition and add it as needed. | |
1042 | */ | |
1043 | pbvn = rootvnode; | |
1044 | pbmnt = pbvn->v_mount; | |
1045 | pbdevp = vfs_statfs(pbmnt)->f_mntfromname; | |
1046 | slash_dev = strnstr(pbdevp, "/dev/", strlen(pbdevp)); | |
1047 | if (slash_dev) { | |
1048 | /* | |
1049 | * If the old root is a snapshot mount, it will have the form: | |
1050 | * | |
1051 | * com.apple.os.update-<boot manifest hash>@<dev node path> | |
1052 | * | |
1053 | * So we just search the mntfromname for any occurrence of "/dev/" and | |
1054 | * grab that as the device path. The image boot code needs a dev node to | |
1055 | * do the re-mount, so we cannot directly mount the snapshot as the | |
1056 | * protoboot volume currently. | |
1057 | */ | |
1058 | strlcpy(pbdevpath, slash_dev, sizeof(pbdevpath)); | |
1059 | } else { | |
1060 | snprintf(pbdevpath, sizeof(pbdevpath), "/dev/%s", pbdevp); | |
1061 | } | |
1062 | ||
1063 | bsd_init_kprintf("protoboot mount-from: %s\n", pbdevp); | |
1064 | bsd_init_kprintf("protoboot dev path: %s\n", pbdevpath); | |
1065 | ||
1066 | strlcpy(pbfsname, pbmnt->mnt_vtable->vfc_name, sizeof(pbfsname)); | |
1067 | #endif | |
2d21ac55 A |
1068 | /* |
1069 | * See if a system disk image is present. If so, mount it and | |
1070 | * switch the root vnode to point to it | |
0a7de745 | 1071 | */ |
cb323159 A |
1072 | imageboot_type_t imageboot_type = imageboot_needed(); |
1073 | if (netboot == FALSE && imageboot_type) { | |
0a7de745 | 1074 | /* |
6d2010ae A |
1075 | * An image was found. No turning back: we're booted |
1076 | * with a kernel from the disk image. | |
1077 | */ | |
cb323159 A |
1078 | bsd_init_kprintf("doing image boot: type = %d\n", imageboot_type); |
1079 | imageboot_setup(imageboot_type); | |
2d21ac55 | 1080 | } |
cb323159 A |
1081 | |
1082 | #if CONFIG_LOCKERBOOT | |
1083 | if (imageboot_type == IMAGEBOOT_LOCKER) { | |
1084 | bsd_init_kprintf("booting from locker\n"); | |
1085 | if (vnode_tag(rootvnode) != VT_LOCKERFS) { | |
1086 | panic("root filesystem not a locker: fsname = %s", | |
1087 | rootvnode->v_mount->mnt_vtable->vfc_name); | |
1088 | } | |
1089 | } | |
1090 | #endif /* CONFIG_LOCKERBOOT */ | |
2d21ac55 | 1091 | #endif /* CONFIG_IMAGEBOOT */ |
0a7de745 | 1092 | |
b0d623f7 | 1093 | /* set initial time; all other resource data is already zero'ed */ |
39236c6e | 1094 | microtime_with_abstime(&kernproc->p_start, &kernproc->p_stats->ps_start); |
1c79356b | 1095 | |
9bccf70c | 1096 | #if DEVFS |
1c79356b | 1097 | { |
0a7de745 | 1098 | char mounthere[] = "/dev"; /* !const because of internal casting */ |
2d21ac55 | 1099 | |
0a7de745 A |
1100 | bsd_init_kprintf("calling devfs_kernel_mount\n"); |
1101 | devfs_kernel_mount(mounthere); | |
1c79356b | 1102 | } |
55e303ae | 1103 | #endif /* DEVFS */ |
3e170ce0 | 1104 | |
cb323159 A |
1105 | if (vfs_mount_rosv_data()) { |
1106 | panic("failed to mount data volume!"); | |
1107 | } | |
1108 | ||
1109 | if (vfs_mount_vm()) { | |
1110 | printf("failed to mount vm volume!"); | |
1111 | } | |
1112 | ||
1113 | #if CONFIG_LOCKERBOOT | |
1114 | /* | |
1115 | * We need to wait until devfs is up before remounting the protoboot volume | |
1116 | * within the locker so that it can have a real devfs vnode backing it. | |
1117 | */ | |
1118 | if (imageboot_type == IMAGEBOOT_LOCKER) { | |
1119 | bsd_init_kprintf("re-mounting protoboot volume\n"); | |
1120 | int error = mount_locker_protoboot(pbfsname, LOCKER_PROTOBOOT_MOUNT, | |
1121 | pbdevpath); | |
1122 | if (error) { | |
1123 | panic("failed to mount protoboot volume: dev path = %s, error = %d", | |
1124 | pbdevpath, error); | |
1125 | } | |
1126 | } | |
1127 | #endif /* CONFIG_LOCKERBOOT */ | |
1128 | ||
1c79356b | 1129 | /* Initialize signal state for process 0. */ |
2d21ac55 | 1130 | bsd_init_kprintf("calling siginit\n"); |
b0d623f7 | 1131 | siginit(kernproc); |
1c79356b | 1132 | |
2d21ac55 | 1133 | bsd_init_kprintf("calling bsd_utaskbootstrap\n"); |
1c79356b A |
1134 | bsd_utaskbootstrap(); |
1135 | ||
6d2010ae A |
1136 | pal_kernel_announce(); |
1137 | ||
2d21ac55 A |
1138 | bsd_init_kprintf("calling mountroot_post_hook\n"); |
1139 | ||
9bccf70c | 1140 | /* invoke post-root-mount hook */ |
0a7de745 | 1141 | if (mountroot_post_hook != NULL) { |
9bccf70c | 1142 | mountroot_post_hook(); |
0a7de745 | 1143 | } |
2d21ac55 A |
1144 | |
1145 | #if 0 /* not yet */ | |
5ba3f43e | 1146 | consider_zone_gc(FALSE); |
2d21ac55 | 1147 | #endif |
b0d623f7 | 1148 | |
d9a64523 A |
1149 | /* Initialize System Override call */ |
1150 | init_system_override(); | |
0a7de745 | 1151 | |
2d21ac55 | 1152 | bsd_init_kprintf("done\n"); |
1c79356b A |
1153 | } |
1154 | ||
1155 | void | |
9bccf70c | 1156 | bsdinit_task(void) |
1c79356b | 1157 | { |
2d21ac55 | 1158 | proc_t p = current_proc(); |
1c79356b | 1159 | |
91447636 | 1160 | process_name("init", p); |
1c79356b | 1161 | |
d9a64523 A |
1162 | /* Set up exception-to-signal reflection */ |
1163 | ux_handler_setup(); | |
1c79356b | 1164 | |
2d21ac55 A |
1165 | #if CONFIG_MACF |
1166 | mac_cred_label_associate_user(p->p_ucred); | |
2d21ac55 | 1167 | #endif |
813fb2f6 | 1168 | |
0a7de745 | 1169 | vm_init_before_launchd(); |
5ba3f43e | 1170 | |
d9a64523 A |
1171 | #if CONFIG_XNUPOST |
1172 | int result = bsd_list_tests(); | |
1173 | result = bsd_do_post(); | |
1174 | if (result != 0) { | |
1175 | panic("bsd_do_post: Tests failed with result = 0x%08x\n", result); | |
1176 | } | |
1177 | #endif | |
5ba3f43e A |
1178 | |
1179 | bsd_init_kprintf("bsd_do_post - done"); | |
813fb2f6 | 1180 | |
1c79356b | 1181 | load_init_program(p); |
91447636 | 1182 | lock_trace = 1; |
1c79356b A |
1183 | } |
1184 | ||
2d21ac55 A |
1185 | kern_return_t |
1186 | bsd_autoconf(void) | |
9bccf70c | 1187 | { |
2d21ac55 | 1188 | kprintf("bsd_autoconf: calling kminit\n"); |
1c79356b A |
1189 | kminit(); |
1190 | ||
0a7de745 | 1191 | /* |
1c79356b A |
1192 | * Early startup for bsd pseudodevices. |
1193 | */ | |
1194 | { | |
0a7de745 A |
1195 | struct pseudo_init *pi; |
1196 | ||
1197 | for (pi = pseudo_inits; pi->ps_func; pi++) { | |
1198 | (*pi->ps_func)(pi->ps_count); | |
1199 | } | |
1c79356b A |
1200 | } |
1201 | ||
0a7de745 | 1202 | return IOKitBSDInit(); |
1c79356b A |
1203 | } |
1204 | ||
1205 | ||
55e303ae | 1206 | #include <sys/disklabel.h> /* for MAXPARTITIONS */ |
1c79356b | 1207 | |
91447636 A |
1208 | static void |
1209 | setconf(void) | |
0a7de745 A |
1210 | { |
1211 | u_int32_t flags; | |
1212 | kern_return_t err; | |
1c79356b | 1213 | |
cf7d32b8 | 1214 | err = IOFindBSDRoot(rootdevice, sizeof(rootdevice), &rootdev, &flags); |
0a7de745 | 1215 | if (err) { |
1c79356b | 1216 | printf("setconf: IOFindBSDRoot returned an error (%d);" |
0a7de745 | 1217 | "setting rootdevice to 'sd0a'.\n", err); /* XXX DEBUG TEMP */ |
1c79356b | 1218 | rootdev = makedev( 6, 0 ); |
2d21ac55 | 1219 | strlcpy(rootdevice, "sd0a", sizeof(rootdevice)); |
1c79356b A |
1220 | flags = 0; |
1221 | } | |
1222 | ||
cb323159 | 1223 | #if CONFIG_NETBOOT |
0a7de745 | 1224 | if (flags & 1) { |
9bccf70c A |
1225 | /* network device */ |
1226 | mountroot = netboot_mountroot; | |
1c79356b | 1227 | } else { |
91447636 | 1228 | #endif |
0a7de745 A |
1229 | /* otherwise have vfs determine root filesystem */ |
1230 | mountroot = NULL; | |
cb323159 | 1231 | #if CONFIG_NETBOOT |
0a7de745 | 1232 | } |
91447636 | 1233 | #endif |
1c79356b A |
1234 | } |
1235 | ||
2d21ac55 A |
1236 | void |
1237 | bsd_utaskbootstrap(void) | |
1c79356b | 1238 | { |
2d21ac55 | 1239 | thread_t thread; |
9bccf70c | 1240 | struct uthread *ut; |
1c79356b | 1241 | |
b0d623f7 A |
1242 | /* |
1243 | * Clone the bootstrap process from the kernel process, without | |
1244 | * inheriting either task characteristics or memory from the kernel; | |
1245 | */ | |
fe8ab488 | 1246 | thread = cloneproc(TASK_NULL, COALITION_NULL, kernproc, FALSE, TRUE); |
b0d623f7 | 1247 | |
2d21ac55 | 1248 | /* Hold the reference as it will be dropped during shutdown */ |
0a7de745 | 1249 | initproc = proc_find(1); |
2d21ac55 | 1250 | #if __PROC_INTERNAL_DEBUG |
0a7de745 | 1251 | if (initproc == PROC_NULL) { |
2d21ac55 | 1252 | panic("bsd_utaskbootstrap: initproc not set\n"); |
0a7de745 | 1253 | } |
2d21ac55 | 1254 | #endif |
b0d623f7 A |
1255 | /* |
1256 | * Since we aren't going back out the normal way to our parent, | |
1257 | * we have to drop the transition locks explicitly. | |
1258 | */ | |
1259 | proc_signalend(initproc, 0); | |
1260 | proc_transend(initproc, 0); | |
9bccf70c | 1261 | |
2d21ac55 | 1262 | ut = (struct uthread *)get_bsdthread_info(thread); |
9bccf70c | 1263 | ut->uu_sigmask = 0; |
2d21ac55 | 1264 | act_set_astbsd(thread); |
cb323159 | 1265 | task_clear_return_wait(get_threadtask(thread), TCRW_CLEAR_ALL_WAIT); |
1c79356b A |
1266 | } |
1267 | ||
2d21ac55 A |
1268 | static void |
1269 | parse_bsd_args(void) | |
1c79356b | 1270 | { |
cb323159 | 1271 | char namep[48]; |
2d21ac55 | 1272 | int msgbuf; |
1c79356b | 1273 | |
0a7de745 | 1274 | if (PE_parse_boot_argn("-s", namep, sizeof(namep))) { |
1c79356b | 1275 | boothowto |= RB_SINGLE; |
0a7de745 | 1276 | } |
55e303ae | 1277 | |
0a7de745 | 1278 | if (PE_parse_boot_argn("-x", namep, sizeof(namep))) { /* safe boot */ |
2d21ac55 | 1279 | boothowto |= RB_SAFEBOOT; |
0a7de745 | 1280 | } |
1c79356b | 1281 | |
3e170ce0 A |
1282 | if (PE_parse_boot_argn("-minimalboot", namep, sizeof(namep))) { |
1283 | /* | |
1284 | * -minimalboot indicates that we want userspace to be bootstrapped to a | |
1285 | * minimal environment. What constitutes minimal is up to the bootstrap | |
1286 | * process. | |
1287 | */ | |
1288 | minimalboot = 1; | |
1289 | } | |
1290 | ||
a39ff7e2 | 1291 | #if __x86_64__ |
cb323159 A |
1292 | int no32exec; |
1293 | ||
a39ff7e2 | 1294 | /* disable 32 bit grading */ |
cb323159 A |
1295 | if (PE_parse_boot_argn("no32exec", &no32exec, sizeof(no32exec))) { |
1296 | bootarg_no32exec = !!no32exec; | |
0a7de745 | 1297 | } |
a39ff7e2 | 1298 | #endif |
fe8ab488 | 1299 | |
cb323159 A |
1300 | int execfailure_crashreports; |
1301 | /* enable crash reports on various exec failures */ | |
1302 | if (PE_parse_boot_argn("execfailurecrashes", &execfailure_crashreports, sizeof(execfailure_crashreports))) { | |
1303 | bootarg_execfailurereports = !!execfailure_crashreports; | |
1304 | } | |
1305 | ||
6d2010ae | 1306 | /* disable vnode_cache_is_authorized() by setting vnode_cache_defeat */ |
0a7de745 | 1307 | if (PE_parse_boot_argn("-vnode_cache_defeat", namep, sizeof(namep))) { |
6d2010ae | 1308 | bootarg_vnode_cache_defeat = 1; |
0a7de745 | 1309 | } |
6d2010ae A |
1310 | |
1311 | #if DEVELOPMENT || DEBUG | |
0a7de745 | 1312 | if (PE_parse_boot_argn("-disable_aslr", namep, sizeof(namep))) { |
6d2010ae | 1313 | bootarg_disable_aslr = 1; |
0a7de745 | 1314 | } |
6d2010ae A |
1315 | #endif |
1316 | ||
0a7de745 | 1317 | PE_parse_boot_argn("ncl", &ncl, sizeof(ncl)); |
b0d623f7 | 1318 | if (PE_parse_boot_argn("nbuf", &max_nbuf_headers, |
0a7de745 | 1319 | sizeof(max_nbuf_headers))) { |
0c530ab8 | 1320 | customnbuf = 1; |
2d21ac55 | 1321 | } |
6d2010ae A |
1322 | |
1323 | #if CONFIG_MACF | |
1324 | #if defined (__i386__) || defined (__x86_64__) | |
0a7de745 | 1325 | PE_parse_boot_argn("policy_check", &policy_check_flags, sizeof(policy_check_flags)); |
6d2010ae | 1326 | #endif |
0a7de745 | 1327 | #endif /* CONFIG_MACF */ |
1c79356b | 1328 | |
0a7de745 | 1329 | if (PE_parse_boot_argn("msgbuf", &msgbuf, sizeof(msgbuf))) { |
2d21ac55 | 1330 | log_setsize(msgbuf); |
39037602 | 1331 | oslog_setsize(msgbuf); |
2d21ac55 | 1332 | } |
6d2010ae A |
1333 | |
1334 | if (PE_parse_boot_argn("-novfscache", namep, sizeof(namep))) { | |
1335 | nc_disabled = 1; | |
1336 | } | |
3e170ce0 A |
1337 | |
1338 | #if CONFIG_JETSAM && (DEVELOPMENT || DEBUG) | |
0a7de745 A |
1339 | if (PE_parse_boot_argn("-no_vnode_jetsam", namep, sizeof(namep))) { |
1340 | bootarg_no_vnode_jetsam = 1; | |
1341 | } | |
3e170ce0 A |
1342 | #endif /* CONFIG_JETSAM && (DEVELOPMENT || DEBUG) */ |
1343 | ||
94ff46dc A |
1344 | if (PE_parse_boot_argn("-no_vnode_drain", namep, sizeof(namep))) { |
1345 | bootarg_no_vnode_drain = 1; | |
1346 | } | |
3e170ce0 | 1347 | |
5ba3f43e A |
1348 | #if CONFIG_EMBEDDED |
1349 | /* | |
1350 | * The darkboot flag is specified by the bootloader and is stored in | |
1351 | * boot_args->bootFlags. This flag is available starting revision 2. | |
1352 | */ | |
1353 | boot_args *args = (boot_args *) PE_state.bootArgs; | |
1354 | if ((args != NULL) && (args->Revision >= kBootArgsRevision2)) { | |
1355 | darkboot = (args->bootFlags & kBootFlagsDarkBoot) ? 1 : 0; | |
1356 | } else { | |
1357 | darkboot = 0; | |
1358 | } | |
1359 | #endif | |
3e170ce0 A |
1360 | |
1361 | #if PROC_REF_DEBUG | |
1362 | if (PE_parse_boot_argn("-disable_procref_tracking", namep, sizeof(namep))) { | |
1363 | proc_ref_tracking_disabled = 1; | |
1364 | } | |
1365 | #endif | |
1366 | ||
39037602 A |
1367 | #if OS_REASON_DEBUG |
1368 | if (PE_parse_boot_argn("-disable_osreason_debug", namep, sizeof(namep))) { | |
1369 | os_reason_debug_disabled = 1; | |
1370 | } | |
1371 | #endif | |
1372 | ||
3e170ce0 | 1373 | PE_parse_boot_argn("sigrestrict", &sigrestrict_arg, sizeof(sigrestrict_arg)); |
39037602 | 1374 | |
0a7de745 | 1375 | #if DEVELOPMENT || DEBUG |
39037602 A |
1376 | if (PE_parse_boot_argn("-no_sigsys", namep, sizeof(namep))) { |
1377 | send_sigsys = false; | |
1378 | } | |
39037602 | 1379 | |
39037602 | 1380 | if (PE_parse_boot_argn("alt-dyld", dyld_alt_path, sizeof(dyld_alt_path))) { |
0a7de745 A |
1381 | if (strlen(dyld_alt_path) > 0) { |
1382 | use_alt_dyld = 1; | |
1383 | } | |
39037602 | 1384 | } |
cb323159 A |
1385 | PE_parse_boot_argn("dyld_flags", &dyld_flags, sizeof(dyld_flags)); |
1386 | ||
1387 | if (PE_parse_boot_argn("-disable_syscallfilter", &namep, sizeof(namep))) { | |
1388 | syscallfilter_disable = 1; | |
1389 | } | |
1390 | ||
1391 | #if __arm64__ | |
1392 | if (PE_parse_boot_argn("legacy_footprint_entitlement_mode", &legacy_footprint_entitlement_mode, sizeof(legacy_footprint_entitlement_mode))) { | |
1393 | /* | |
1394 | * legacy_footprint_entitlement_mode specifies the behavior we want associated | |
1395 | * with the entitlement. The supported modes are: | |
1396 | * | |
1397 | * LEGACY_FOOTPRINT_ENTITLEMENT_IGNORE: | |
1398 | * Indicates that we want every process to have the memory accounting | |
1399 | * that is available in iOS 12.0 and beyond. | |
1400 | * | |
1401 | * LEGACY_FOOTPRINT_ENTITLEMENT_IOS11_ACCT: | |
1402 | * Indicates that for every process that has the 'legacy footprint entitlement', | |
1403 | * we want to give it the old iOS 11.0 accounting behavior which accounted some | |
1404 | * of the process's memory to the kernel. | |
1405 | * | |
1406 | * LEGACY_FOOTPRINT_ENTITLEMENT_LIMIT_INCREASE: | |
1407 | * Indicates that for every process that has the 'legacy footprint entitlement', | |
1408 | * we want it to have a higher memory limit which will help them acclimate to the | |
1409 | * iOS 12.0 (& beyond) accounting behavior that does the right accounting. | |
1410 | * The bonus added to the system-wide task limit to calculate this higher memory limit | |
1411 | * is available in legacy_footprint_bonus_mb. | |
1412 | */ | |
1413 | ||
1414 | if (legacy_footprint_entitlement_mode < LEGACY_FOOTPRINT_ENTITLEMENT_IGNORE || | |
1415 | legacy_footprint_entitlement_mode > LEGACY_FOOTPRINT_ENTITLEMENT_LIMIT_INCREASE) { | |
1416 | legacy_footprint_entitlement_mode = LEGACY_FOOTPRINT_ENTITLEMENT_LIMIT_INCREASE; | |
1417 | } | |
1418 | } | |
1419 | #endif /* __arm64__ */ | |
1420 | #endif /* DEVELOPMENT || DEBUG */ | |
1c79356b A |
1421 | } |
1422 | ||
b0d623f7 A |
1423 | void |
1424 | bsd_exec_setup(int scale) | |
1425 | { | |
b0d623f7 | 1426 | switch (scale) { |
0a7de745 A |
1427 | case 0: |
1428 | case 1: | |
1429 | bsd_simul_execs = BSD_SIMUL_EXECS; | |
1430 | break; | |
1431 | case 2: | |
1432 | case 3: | |
1433 | bsd_simul_execs = 65; | |
1434 | break; | |
1435 | case 4: | |
1436 | case 5: | |
1437 | bsd_simul_execs = 129; | |
1438 | break; | |
1439 | case 6: | |
1440 | case 7: | |
1441 | bsd_simul_execs = 257; | |
1442 | break; | |
1443 | default: | |
1444 | bsd_simul_execs = 513; | |
1445 | break; | |
b0d623f7 | 1446 | } |
6d2010ae | 1447 | bsd_pageable_map_size = (bsd_simul_execs * BSD_PAGEABLE_SIZE_PER_EXEC); |
b0d623f7 A |
1448 | } |
1449 | ||
cb323159 | 1450 | #if !CONFIG_NETBOOT |
0a7de745 | 1451 | int |
6d2010ae A |
1452 | netboot_root(void); |
1453 | ||
0a7de745 | 1454 | int |
91447636 | 1455 | netboot_root(void) |
1c79356b | 1456 | { |
0a7de745 | 1457 | return 0; |
1c79356b | 1458 | } |
91447636 | 1459 | #endif |