]> git.saurik.com Git - ldid.git/blob - ldid.cpp
064846933baffc0542b98120fbf22c2a4a227740
[ldid.git] / ldid.cpp
1 /* ldid - (Mach-O) Link-Loader Identity Editor
2 * Copyright (C) 2007-2012 Jay Freeman (saurik)
3 */
4
5 /* GNU Affero General Public License, Version 3 {{{ */
6 /*
7 * This program is free software: you can redistribute it and/or modify
8 * it under the terms of the GNU Affero General Public License as published by
9 * the Free Software Foundation, either version 3 of the License, or
10 * (at your option) any later version.
11
12 * This program is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 * GNU Affero General Public License for more details.
16
17 * You should have received a copy of the GNU Affero General Public License
18 * along with this program. If not, see <http://www.gnu.org/licenses/>.
19 **/
20 /* }}} */
21
22 #include "minimal/stdlib.h"
23
24 #include <cstring>
25 #include <string>
26 #include <vector>
27
28 #include <dlfcn.h>
29 #include <fcntl.h>
30
31 #include <sys/mman.h>
32 #include <sys/stat.h>
33
34 #include <openssl/sha.h>
35
36 #include <plist/plist.h>
37
38 struct fat_header {
39 uint32_t magic;
40 uint32_t nfat_arch;
41 } _packed;
42
43 #define FAT_MAGIC 0xcafebabe
44 #define FAT_CIGAM 0xbebafeca
45
46 struct fat_arch {
47 uint32_t cputype;
48 uint32_t cpusubtype;
49 uint32_t offset;
50 uint32_t size;
51 uint32_t align;
52 } _packed;
53
54 struct mach_header {
55 uint32_t magic;
56 uint32_t cputype;
57 uint32_t cpusubtype;
58 uint32_t filetype;
59 uint32_t ncmds;
60 uint32_t sizeofcmds;
61 uint32_t flags;
62 } _packed;
63
64 #define MH_MAGIC 0xfeedface
65 #define MH_CIGAM 0xcefaedfe
66
67 #define MH_MAGIC_64 0xfeedfacf
68 #define MH_CIGAM_64 0xcffaedfe
69
70 #define MH_DYLDLINK 0x4
71
72 #define MH_OBJECT 0x1
73 #define MH_EXECUTE 0x2
74 #define MH_DYLIB 0x6
75 #define MH_BUNDLE 0x8
76 #define MH_DYLIB_STUB 0x9
77
78 struct load_command {
79 uint32_t cmd;
80 uint32_t cmdsize;
81 } _packed;
82
83 #define LC_REQ_DYLD uint32_t(0x80000000)
84
85 #define LC_SEGMENT uint32_t(0x01)
86 #define LC_SYMTAB uint32_t(0x02)
87 #define LC_DYSYMTAB uint32_t(0x0b)
88 #define LC_LOAD_DYLIB uint32_t(0x0c)
89 #define LC_ID_DYLIB uint32_t(0x0d)
90 #define LC_SEGMENT_64 uint32_t(0x19)
91 #define LC_UUID uint32_t(0x1b)
92 #define LC_CODE_SIGNATURE uint32_t(0x1d)
93 #define LC_SEGMENT_SPLIT_INFO uint32_t(0x1e)
94 #define LC_REEXPORT_DYLIB uint32_t(0x1f | LC_REQ_DYLD)
95 #define LC_ENCRYPTION_INFO uint32_t(0x21)
96 #define LC_DYLD_INFO uint32_t(0x22)
97 #define LC_DYLD_INFO_ONLY uint32_t(0x22 | LC_REQ_DYLD)
98
99 struct dylib {
100 uint32_t name;
101 uint32_t timestamp;
102 uint32_t current_version;
103 uint32_t compatibility_version;
104 } _packed;
105
106 struct dylib_command {
107 uint32_t cmd;
108 uint32_t cmdsize;
109 struct dylib dylib;
110 } _packed;
111
112 struct uuid_command {
113 uint32_t cmd;
114 uint32_t cmdsize;
115 uint8_t uuid[16];
116 } _packed;
117
118 struct symtab_command {
119 uint32_t cmd;
120 uint32_t cmdsize;
121 uint32_t symoff;
122 uint32_t nsyms;
123 uint32_t stroff;
124 uint32_t strsize;
125 } _packed;
126
127 struct dyld_info_command {
128 uint32_t cmd;
129 uint32_t cmdsize;
130 uint32_t rebase_off;
131 uint32_t rebase_size;
132 uint32_t bind_off;
133 uint32_t bind_size;
134 uint32_t weak_bind_off;
135 uint32_t weak_bind_size;
136 uint32_t lazy_bind_off;
137 uint32_t lazy_bind_size;
138 uint32_t export_off;
139 uint32_t export_size;
140 } _packed;
141
142 struct dysymtab_command {
143 uint32_t cmd;
144 uint32_t cmdsize;
145 uint32_t ilocalsym;
146 uint32_t nlocalsym;
147 uint32_t iextdefsym;
148 uint32_t nextdefsym;
149 uint32_t iundefsym;
150 uint32_t nundefsym;
151 uint32_t tocoff;
152 uint32_t ntoc;
153 uint32_t modtaboff;
154 uint32_t nmodtab;
155 uint32_t extrefsymoff;
156 uint32_t nextrefsyms;
157 uint32_t indirectsymoff;
158 uint32_t nindirectsyms;
159 uint32_t extreloff;
160 uint32_t nextrel;
161 uint32_t locreloff;
162 uint32_t nlocrel;
163 } _packed;
164
165 struct dylib_table_of_contents {
166 uint32_t symbol_index;
167 uint32_t module_index;
168 } _packed;
169
170 struct dylib_module {
171 uint32_t module_name;
172 uint32_t iextdefsym;
173 uint32_t nextdefsym;
174 uint32_t irefsym;
175 uint32_t nrefsym;
176 uint32_t ilocalsym;
177 uint32_t nlocalsym;
178 uint32_t iextrel;
179 uint32_t nextrel;
180 uint32_t iinit_iterm;
181 uint32_t ninit_nterm;
182 uint32_t objc_module_info_addr;
183 uint32_t objc_module_info_size;
184 } _packed;
185
186 struct dylib_reference {
187 uint32_t isym:24;
188 uint32_t flags:8;
189 } _packed;
190
191 struct relocation_info {
192 int32_t r_address;
193 uint32_t r_symbolnum:24;
194 uint32_t r_pcrel:1;
195 uint32_t r_length:2;
196 uint32_t r_extern:1;
197 uint32_t r_type:4;
198 } _packed;
199
200 struct nlist {
201 union {
202 char *n_name;
203 int32_t n_strx;
204 } n_un;
205
206 uint8_t n_type;
207 uint8_t n_sect;
208 uint8_t n_desc;
209 uint32_t n_value;
210 } _packed;
211
212 struct segment_command {
213 uint32_t cmd;
214 uint32_t cmdsize;
215 char segname[16];
216 uint32_t vmaddr;
217 uint32_t vmsize;
218 uint32_t fileoff;
219 uint32_t filesize;
220 uint32_t maxprot;
221 uint32_t initprot;
222 uint32_t nsects;
223 uint32_t flags;
224 } _packed;
225
226 struct segment_command_64 {
227 uint32_t cmd;
228 uint32_t cmdsize;
229 char segname[16];
230 uint64_t vmaddr;
231 uint64_t vmsize;
232 uint64_t fileoff;
233 uint64_t filesize;
234 uint32_t maxprot;
235 uint32_t initprot;
236 uint32_t nsects;
237 uint32_t flags;
238 } _packed;
239
240 struct section {
241 char sectname[16];
242 char segname[16];
243 uint32_t addr;
244 uint32_t size;
245 uint32_t offset;
246 uint32_t align;
247 uint32_t reloff;
248 uint32_t nreloc;
249 uint32_t flags;
250 uint32_t reserved1;
251 uint32_t reserved2;
252 } _packed;
253
254 struct section_64 {
255 char sectname[16];
256 char segname[16];
257 uint64_t addr;
258 uint64_t size;
259 uint32_t offset;
260 uint32_t align;
261 uint32_t reloff;
262 uint32_t nreloc;
263 uint32_t flags;
264 uint32_t reserved1;
265 uint32_t reserved2;
266 } _packed;
267
268 struct linkedit_data_command {
269 uint32_t cmd;
270 uint32_t cmdsize;
271 uint32_t dataoff;
272 uint32_t datasize;
273 } _packed;
274
275 struct encryption_info_command {
276 uint32_t cmd;
277 uint32_t cmdsize;
278 uint32_t cryptoff;
279 uint32_t cryptsize;
280 uint32_t cryptid;
281 } _packed;
282
283 #define BIND_OPCODE_MASK 0xf0
284 #define BIND_IMMEDIATE_MASK 0x0f
285 #define BIND_OPCODE_DONE 0x00
286 #define BIND_OPCODE_SET_DYLIB_ORDINAL_IMM 0x10
287 #define BIND_OPCODE_SET_DYLIB_ORDINAL_ULEB 0x20
288 #define BIND_OPCODE_SET_DYLIB_SPECIAL_IMM 0x30
289 #define BIND_OPCODE_SET_SYMBOL_TRAILING_FLAGS_IMM 0x40
290 #define BIND_OPCODE_SET_TYPE_IMM 0x50
291 #define BIND_OPCODE_SET_ADDEND_SLEB 0x60
292 #define BIND_OPCODE_SET_SEGMENT_AND_OFFSET_ULEB 0x70
293 #define BIND_OPCODE_ADD_ADDR_ULEB 0x80
294 #define BIND_OPCODE_DO_BIND 0x90
295 #define BIND_OPCODE_DO_BIND_ADD_ADDR_ULEB 0xa0
296 #define BIND_OPCODE_DO_BIND_ADD_ADDR_IMM_SCALED 0xb0
297 #define BIND_OPCODE_DO_BIND_ULEB_TIMES_SKIPPING_ULEB 0xc0
298
299 template <typename Type_>
300 Type_ Align(Type_ value, size_t align) {
301 value += align - 1;
302 value /= align;
303 value *= align;
304 return value;
305 }
306
307 uint16_t Swap_(uint16_t value) {
308 return
309 ((value >> 8) & 0x00ff) |
310 ((value << 8) & 0xff00);
311 }
312
313 uint32_t Swap_(uint32_t value) {
314 value = ((value >> 8) & 0x00ff00ff) |
315 ((value << 8) & 0xff00ff00);
316 value = ((value >> 16) & 0x0000ffff) |
317 ((value << 16) & 0xffff0000);
318 return value;
319 }
320
321 uint64_t Swap_(uint64_t value) {
322 value = (value & 0x00000000ffffffff) << 32 | (value & 0xffffffff00000000) >> 32;
323 value = (value & 0x0000ffff0000ffff) << 16 | (value & 0xffff0000ffff0000) >> 16;
324 value = (value & 0x00ff00ff00ff00ff) << 8 | (value & 0xff00ff00ff00ff00) >> 8;
325 return value;
326 }
327
328 int16_t Swap_(int16_t value) {
329 return Swap_(static_cast<uint16_t>(value));
330 }
331
332 int32_t Swap_(int32_t value) {
333 return Swap_(static_cast<uint32_t>(value));
334 }
335
336 int64_t Swap_(int64_t value) {
337 return Swap_(static_cast<uint64_t>(value));
338 }
339
340 bool little_(true);
341
342 uint16_t Swap(uint16_t value) {
343 return little_ ? Swap_(value) : value;
344 }
345
346 uint32_t Swap(uint32_t value) {
347 return little_ ? Swap_(value) : value;
348 }
349
350 uint64_t Swap(uint64_t value) {
351 return little_ ? Swap_(value) : value;
352 }
353
354 int16_t Swap(int16_t value) {
355 return Swap(static_cast<uint16_t>(value));
356 }
357
358 int32_t Swap(int32_t value) {
359 return Swap(static_cast<uint32_t>(value));
360 }
361
362 int64_t Swap(int64_t value) {
363 return Swap(static_cast<uint64_t>(value));
364 }
365
366 template <typename Target_>
367 class Pointer;
368
369 class Data {
370 private:
371 void *base_;
372 size_t size_;
373
374 protected:
375 bool swapped_;
376
377 public:
378 Data(void *base, size_t size) :
379 base_(base),
380 size_(size),
381 swapped_(false)
382 {
383 }
384
385 uint16_t Swap(uint16_t value) const {
386 return swapped_ ? Swap_(value) : value;
387 }
388
389 uint32_t Swap(uint32_t value) const {
390 return swapped_ ? Swap_(value) : value;
391 }
392
393 uint64_t Swap(uint64_t value) const {
394 return swapped_ ? Swap_(value) : value;
395 }
396
397 int16_t Swap(int16_t value) const {
398 return Swap(static_cast<uint16_t>(value));
399 }
400
401 int32_t Swap(int32_t value) const {
402 return Swap(static_cast<uint32_t>(value));
403 }
404
405 int64_t Swap(int64_t value) const {
406 return Swap(static_cast<uint64_t>(value));
407 }
408
409 void *GetBase() const {
410 return base_;
411 }
412
413 size_t GetSize() const {
414 return size_;
415 }
416 };
417
418 class MachHeader :
419 public Data
420 {
421 private:
422 bool bits64_;
423
424 struct mach_header *mach_header_;
425 struct load_command *load_command_;
426
427 public:
428 MachHeader(void *base, size_t size) :
429 Data(base, size)
430 {
431 mach_header_ = (mach_header *) base;
432
433 switch (Swap(mach_header_->magic)) {
434 case MH_CIGAM:
435 swapped_ = !swapped_;
436 case MH_MAGIC:
437 bits64_ = false;
438 break;
439
440 case MH_CIGAM_64:
441 swapped_ = !swapped_;
442 case MH_MAGIC_64:
443 bits64_ = true;
444 break;
445
446 default:
447 _assert(false);
448 }
449
450 void *post = mach_header_ + 1;
451 if (bits64_)
452 post = (uint32_t *) post + 1;
453 load_command_ = (struct load_command *) post;
454
455 _assert(
456 Swap(mach_header_->filetype) == MH_EXECUTE ||
457 Swap(mach_header_->filetype) == MH_DYLIB ||
458 Swap(mach_header_->filetype) == MH_BUNDLE
459 );
460 }
461
462 struct mach_header *operator ->() const {
463 return mach_header_;
464 }
465
466 operator struct mach_header *() const {
467 return mach_header_;
468 }
469
470 uint32_t GetCPUType() const {
471 return Swap(mach_header_->cputype);
472 }
473
474 uint32_t GetCPUSubtype() const {
475 return Swap(mach_header_->cpusubtype) & 0xff;
476 }
477
478 struct load_command *GetLoadCommand() const {
479 return load_command_;
480 }
481
482 std::vector<struct load_command *> GetLoadCommands() const {
483 std::vector<struct load_command *> load_commands;
484
485 struct load_command *load_command = load_command_;
486 for (uint32_t cmd = 0; cmd != Swap(mach_header_->ncmds); ++cmd) {
487 load_commands.push_back(load_command);
488 load_command = (struct load_command *) ((uint8_t *) load_command + Swap(load_command->cmdsize));
489 }
490
491 return load_commands;
492 }
493
494 std::vector<segment_command *> GetSegments(const char *segment_name) const {
495 std::vector<struct segment_command *> segment_commands;
496
497 _foreach (load_command, GetLoadCommands()) {
498 if (Swap(load_command->cmd) == LC_SEGMENT) {
499 segment_command *segment_command = reinterpret_cast<struct segment_command *>(load_command);
500 if (strncmp(segment_command->segname, segment_name, 16) == 0)
501 segment_commands.push_back(segment_command);
502 }
503 }
504
505 return segment_commands;
506 }
507
508 std::vector<segment_command_64 *> GetSegments64(const char *segment_name) const {
509 std::vector<struct segment_command_64 *> segment_commands;
510
511 _foreach (load_command, GetLoadCommands()) {
512 if (Swap(load_command->cmd) == LC_SEGMENT_64) {
513 segment_command_64 *segment_command = reinterpret_cast<struct segment_command_64 *>(load_command);
514 if (strncmp(segment_command->segname, segment_name, 16) == 0)
515 segment_commands.push_back(segment_command);
516 }
517 }
518
519 return segment_commands;
520 }
521
522 std::vector<section *> GetSections(const char *segment_name, const char *section_name) const {
523 std::vector<section *> sections;
524
525 _foreach (segment, GetSegments(segment_name)) {
526 section *section = (struct section *) (segment + 1);
527
528 uint32_t sect;
529 for (sect = 0; sect != Swap(segment->nsects); ++sect) {
530 if (strncmp(section->sectname, section_name, 16) == 0)
531 sections.push_back(section);
532 ++section;
533 }
534 }
535
536 return sections;
537 }
538
539 template <typename Target_>
540 Pointer<Target_> GetPointer(uint32_t address, const char *segment_name = NULL) const {
541 load_command *load_command = (struct load_command *) (mach_header_ + 1);
542 uint32_t cmd;
543
544 for (cmd = 0; cmd != Swap(mach_header_->ncmds); ++cmd) {
545 if (Swap(load_command->cmd) == LC_SEGMENT) {
546 segment_command *segment_command = (struct segment_command *) load_command;
547 if (segment_name != NULL && strncmp(segment_command->segname, segment_name, 16) != 0)
548 goto next_command;
549
550 section *sections = (struct section *) (segment_command + 1);
551
552 uint32_t sect;
553 for (sect = 0; sect != Swap(segment_command->nsects); ++sect) {
554 section *section = &sections[sect];
555 //printf("%s %u %p %p %u\n", segment_command->segname, sect, address, section->addr, section->size);
556 if (address >= Swap(section->addr) && address < Swap(section->addr) + Swap(section->size)) {
557 //printf("0x%.8x %s\n", address, segment_command->segname);
558 return Pointer<Target_>(this, reinterpret_cast<Target_ *>(address - Swap(section->addr) + Swap(section->offset) + (char *) mach_header_));
559 }
560 }
561 }
562
563 next_command:
564 load_command = (struct load_command *) ((char *) load_command + Swap(load_command->cmdsize));
565 }
566
567 return Pointer<Target_>(this);
568 }
569
570 template <typename Target_>
571 Pointer<Target_> GetOffset(uint32_t offset) {
572 return Pointer<Target_>(this, reinterpret_cast<Target_ *>(offset + (uint8_t *) mach_header_));
573 }
574 };
575
576 class FatMachHeader :
577 public MachHeader
578 {
579 private:
580 fat_arch *fat_arch_;
581
582 public:
583 FatMachHeader(void *base, size_t size, fat_arch *fat_arch) :
584 MachHeader(base, size),
585 fat_arch_(fat_arch)
586 {
587 }
588
589 fat_arch *GetFatArch() const {
590 return fat_arch_;
591 }
592 };
593
594 class FatHeader :
595 public Data
596 {
597 private:
598 fat_header *fat_header_;
599 std::vector<FatMachHeader> mach_headers_;
600
601 public:
602 FatHeader(void *base, size_t size) :
603 Data(base, size)
604 {
605 fat_header_ = reinterpret_cast<struct fat_header *>(base);
606
607 if (Swap(fat_header_->magic) == FAT_CIGAM) {
608 swapped_ = !swapped_;
609 goto fat;
610 } else if (Swap(fat_header_->magic) != FAT_MAGIC) {
611 fat_header_ = NULL;
612 mach_headers_.push_back(FatMachHeader(base, size, NULL));
613 } else fat: {
614 size_t fat_narch = Swap(fat_header_->nfat_arch);
615 fat_arch *fat_arch = reinterpret_cast<struct fat_arch *>(fat_header_ + 1);
616 size_t arch;
617 for (arch = 0; arch != fat_narch; ++arch) {
618 uint32_t arch_offset = Swap(fat_arch->offset);
619 uint32_t arch_size = Swap(fat_arch->size);
620 mach_headers_.push_back(FatMachHeader((uint8_t *) base + arch_offset, arch_size, fat_arch));
621 ++fat_arch;
622 }
623 }
624 }
625
626 std::vector<FatMachHeader> &GetMachHeaders() {
627 return mach_headers_;
628 }
629
630 bool IsFat() const {
631 return fat_header_ != NULL;
632 }
633
634 struct fat_header *operator ->() const {
635 return fat_header_;
636 }
637
638 operator struct fat_header *() const {
639 return fat_header_;
640 }
641 };
642
643 template <typename Target_>
644 class Pointer {
645 private:
646 const MachHeader *framework_;
647 const Target_ *pointer_;
648
649 public:
650 Pointer(const MachHeader *framework = NULL, const Target_ *pointer = NULL) :
651 framework_(framework),
652 pointer_(pointer)
653 {
654 }
655
656 operator const Target_ *() const {
657 return pointer_;
658 }
659
660 const Target_ *operator ->() const {
661 return pointer_;
662 }
663
664 Pointer<Target_> &operator ++() {
665 ++pointer_;
666 return *this;
667 }
668
669 template <typename Value_>
670 Value_ Swap(Value_ value) {
671 return framework_->Swap(value);
672 }
673 };
674
675 #define CSMAGIC_CODEDIRECTORY uint32_t(0xfade0c02)
676 #define CSMAGIC_EMBEDDED_SIGNATURE uint32_t(0xfade0cc0)
677 #define CSMAGIC_ENTITLEMENTS uint32_t(0xfade7171)
678
679 #define CSSLOT_CODEDIRECTORY uint32_t(0)
680 #define CSSLOT_REQUIREMENTS uint32_t(2)
681 #define CSSLOT_ENTITLEMENTS uint32_t(5)
682
683 struct BlobIndex {
684 uint32_t type;
685 uint32_t offset;
686 } _packed;
687
688 struct Blob {
689 uint32_t magic;
690 uint32_t length;
691 } _packed;
692
693 struct SuperBlob {
694 struct Blob blob;
695 uint32_t count;
696 struct BlobIndex index[];
697 } _packed;
698
699 struct CodeDirectory {
700 struct Blob blob;
701 uint32_t version;
702 uint32_t flags;
703 uint32_t hashOffset;
704 uint32_t identOffset;
705 uint32_t nSpecialSlots;
706 uint32_t nCodeSlots;
707 uint32_t codeLimit;
708 uint8_t hashSize;
709 uint8_t hashType;
710 uint8_t spare1;
711 uint8_t pageSize;
712 uint32_t spare2;
713 } _packed;
714
715 extern "C" uint32_t hash(uint8_t *k, uint32_t length, uint32_t initval);
716
717 void sha1(uint8_t *hash, uint8_t *data, size_t size) {
718 SHA1(data, size, hash);
719 }
720
721 struct CodesignAllocation {
722 FatMachHeader mach_header_;
723 uint32_t offset_;
724 uint32_t size_;
725 uint32_t alloc_;
726 uint32_t align_;
727
728 CodesignAllocation(FatMachHeader mach_header, size_t offset, size_t size, size_t alloc, size_t align) :
729 mach_header_(mach_header),
730 offset_(offset),
731 size_(size),
732 alloc_(alloc),
733 align_(align)
734 {
735 }
736 };
737
738 class File {
739 private:
740 int file_;
741
742 public:
743 File() :
744 file_(-1)
745 {
746 }
747
748 ~File() {
749 if (file_ != -1)
750 _syscall(close(file_));
751 }
752
753 void open(const char *path, int flags) {
754 _assert(file_ == -1);
755 _syscall(file_ = ::open(path, flags));
756 }
757
758 int file() const {
759 return file_;
760 }
761 };
762
763 class Map {
764 private:
765 File file_;
766 void *data_;
767 size_t size_;
768
769 void clear() {
770 if (data_ == NULL)
771 return;
772 _syscall(munmap(data_, size_));
773 data_ = NULL;
774 size_ = 0;
775 }
776
777 public:
778 Map() :
779 data_(NULL),
780 size_(0)
781 {
782 }
783
784 Map(const char *path, int oflag, int pflag, int mflag) :
785 Map()
786 {
787 open(path, oflag, pflag, mflag);
788 }
789
790 Map(const char *path, bool edit) :
791 Map()
792 {
793 open(path, edit);
794 }
795
796 ~Map() {
797 clear();
798 }
799
800 void open(const char *path, int oflag, int pflag, int mflag) {
801 clear();
802
803 file_.open(path, oflag);
804 int file(file_.file());
805
806 struct stat stat;
807 _syscall(fstat(file, &stat));
808 size_ = stat.st_size;
809
810 _syscall(data_ = mmap(NULL, size_, pflag, mflag, file, 0));
811 }
812
813 void open(const char *path, bool edit) {
814 if (edit)
815 open(path, O_RDWR, PROT_READ | PROT_WRITE, MAP_SHARED);
816 else
817 open(path, O_RDONLY, PROT_READ, MAP_PRIVATE);
818 }
819
820 void *data() const {
821 return data_;
822 }
823
824 size_t size() const {
825 return size_;
826 }
827 };
828
829 int main(int argc, const char *argv[]) {
830 union {
831 uint16_t word;
832 uint8_t byte[2];
833 } endian = {1};
834
835 little_ = endian.byte[0];
836
837 bool flag_r(false);
838 bool flag_e(false);
839
840 bool flag_T(false);
841
842 bool flag_S(false);
843 bool flag_s(false);
844
845 bool flag_D(false);
846
847 bool flag_A(false);
848 bool flag_a(false);
849
850 uint32_t flag_CPUType(_not(uint32_t));
851 uint32_t flag_CPUSubtype(_not(uint32_t));
852
853 const char *flag_I(NULL);
854
855 bool timeh(false);
856 uint32_t timev(0);
857
858 Map xmlm;
859 const void *xmld(NULL);
860 size_t xmls(0);
861
862 std::vector<std::string> files;
863
864 if (argc == 1) {
865 fprintf(stderr, "usage: %s -S[entitlements.xml] <binary>\n", argv[0]);
866 fprintf(stderr, " %s -e MobileSafari\n", argv[0]);
867 fprintf(stderr, " %s -S cat\n", argv[0]);
868 fprintf(stderr, " %s -Stfp.xml gdb\n", argv[0]);
869 exit(0);
870 }
871
872 for (int argi(1); argi != argc; ++argi)
873 if (argv[argi][0] != '-')
874 files.push_back(argv[argi]);
875 else switch (argv[argi][1]) {
876 case 'r': flag_r = true; break;
877 case 'e': flag_e = true; break;
878
879 case 'D': flag_D = true; break;
880
881 case 'a': flag_a = true; break;
882
883 case 'A':
884 flag_A = true;
885 if (argv[argi][2] != '\0') {
886 const char *cpu = argv[argi] + 2;
887 const char *colon = strchr(cpu, ':');
888 _assert(colon != NULL);
889 char *arge;
890 flag_CPUType = strtoul(cpu, &arge, 0);
891 _assert(arge == colon);
892 flag_CPUSubtype = strtoul(colon + 1, &arge, 0);
893 _assert(arge == argv[argi] + strlen(argv[argi]));
894 }
895 break;
896
897 case 's':
898 _assert(!flag_S);
899 flag_s = true;
900 break;
901
902 case 'S':
903 _assert(!flag_s);
904 flag_S = true;
905 if (argv[argi][2] != '\0') {
906 const char *xml = argv[argi] + 2;
907 xmlm.open(xml, O_RDONLY, PROT_READ, MAP_PRIVATE);
908 xmld = xmlm.data();
909 xmls = xmlm.size();
910 }
911 break;
912
913 case 'T': {
914 flag_T = true;
915 if (argv[argi][2] == '-')
916 timeh = true;
917 else {
918 char *arge;
919 timev = strtoul(argv[argi] + 2, &arge, 0);
920 _assert(arge == argv[argi] + strlen(argv[argi]));
921 }
922 } break;
923
924 case 'I': {
925 flag_I = argv[argi] + 2;
926 } break;
927
928 default:
929 goto usage;
930 break;
931 }
932
933 if (files.empty()) usage: {
934 exit(0);
935 }
936
937 size_t filei(0), filee(0);
938 _foreach (file, files) try {
939 const char *path(file.c_str());
940 const char *base = strrchr(path, '/');
941
942 std::string dir;
943 if (base != NULL)
944 dir.assign(path, base++ - path + 1);
945 else
946 base = path;
947
948 const char *name(flag_I ?: base);
949 char *temp(NULL);
950
951 if (flag_S || flag_r) {
952 Map input(path, O_RDONLY, PROT_READ | PROT_WRITE, MAP_PRIVATE);
953 FatHeader source(input.data(), input.size());
954
955 size_t offset(0);
956 if (source.IsFat())
957 offset += sizeof(fat_header) + sizeof(fat_arch) * source.Swap(source->nfat_arch);
958
959 std::vector<CodesignAllocation> allocations;
960 _foreach (mach_header, source.GetMachHeaders()) {
961 struct linkedit_data_command *signature(NULL);
962 struct symtab_command *symtab(NULL);
963
964 _foreach (load_command, mach_header.GetLoadCommands()) {
965 uint32_t cmd(mach_header.Swap(load_command->cmd));
966 if (false);
967 else if (cmd == LC_CODE_SIGNATURE)
968 signature = reinterpret_cast<struct linkedit_data_command *>(load_command);
969 else if (cmd == LC_SYMTAB)
970 symtab = reinterpret_cast<struct symtab_command *>(load_command);
971 }
972
973 size_t size;
974 if (signature == NULL)
975 size = mach_header.GetSize();
976 else {
977 size = mach_header.Swap(signature->dataoff);
978 _assert(size <= mach_header.GetSize());
979 }
980
981 if (symtab != NULL) {
982 auto end(mach_header.Swap(symtab->stroff) + mach_header.Swap(symtab->strsize));
983 _assert(end <= size);
984 _assert(end >= size - 0x10);
985 size = end;
986 }
987
988 size_t alloc(0);
989 if (!flag_r) {
990 alloc += sizeof(struct SuperBlob);
991 uint32_t special(0);
992
993 special = std::max(special, CSSLOT_CODEDIRECTORY);
994 alloc += sizeof(struct BlobIndex);
995 alloc += sizeof(struct CodeDirectory);
996 alloc += strlen(name) + 1;
997
998 special = std::max(special, CSSLOT_REQUIREMENTS);
999 alloc += sizeof(struct BlobIndex);
1000 alloc += 0xc;
1001
1002 if (xmld != NULL) {
1003 special = std::max(special, CSSLOT_ENTITLEMENTS);
1004 alloc += sizeof(struct BlobIndex);
1005 alloc += sizeof(struct Blob);
1006 alloc += xmls;
1007 }
1008
1009 size_t normal((size + 0x1000 - 1) / 0x1000);
1010 alloc = Align(alloc + (special + normal) * 0x14, 16);
1011 }
1012
1013 auto *fat_arch(mach_header.GetFatArch());
1014 uint32_t align(fat_arch == NULL ? 0 : source.Swap(fat_arch->align));
1015 offset = Align(offset, 1 << align);
1016
1017 allocations.push_back(CodesignAllocation(mach_header, offset, size, alloc, align));
1018 offset += size + alloc;
1019 offset = Align(offset, 16);
1020 }
1021
1022 asprintf(&temp, "%s.%s.cs", dir.c_str(), base);
1023 fclose(fopen(temp, "w+"));
1024 _syscall(truncate(temp, offset));
1025
1026 Map output(temp, O_RDWR, PROT_READ | PROT_WRITE, MAP_SHARED);
1027 _assert(output.size() == offset);
1028 void *file(output.data());
1029 memset(file, 0, offset);
1030
1031 fat_arch *fat_arch;
1032 if (!source.IsFat())
1033 fat_arch = NULL;
1034 else {
1035 auto *fat_header(reinterpret_cast<struct fat_header *>(file));
1036 fat_header->magic = Swap(FAT_MAGIC);
1037 fat_header->nfat_arch = Swap(source.Swap(source->nfat_arch));
1038 fat_arch = reinterpret_cast<struct fat_arch *>(fat_header + 1);
1039 }
1040
1041 _foreach (allocation, allocations) {
1042 auto &source(allocation.mach_header_);
1043
1044 uint32_t align(allocation.size_);
1045 if (allocation.alloc_ != 0)
1046 align = Align(align, 0x10);
1047
1048 if (fat_arch != NULL) {
1049 fat_arch->cputype = Swap(source->cputype);
1050 fat_arch->cpusubtype = Swap(source->cpusubtype);
1051 fat_arch->offset = Swap(allocation.offset_);
1052 fat_arch->size = Swap(align + allocation.alloc_);
1053 fat_arch->align = Swap(allocation.align_);
1054 ++fat_arch;
1055 }
1056
1057 void *target(reinterpret_cast<uint8_t *>(file) + allocation.offset_);
1058 memcpy(target, source, allocation.size_);
1059 MachHeader mach_header(target, align + allocation.alloc_);
1060
1061 struct linkedit_data_command *signature(NULL);
1062 _foreach (load_command, mach_header.GetLoadCommands()) {
1063 uint32_t cmd(mach_header.Swap(load_command->cmd));
1064 if (cmd != LC_CODE_SIGNATURE)
1065 continue;
1066 signature = reinterpret_cast<struct linkedit_data_command *>(load_command);
1067 break;
1068 }
1069
1070 if (flag_r && signature != NULL) {
1071 auto before(reinterpret_cast<uint8_t *>(mach_header.GetLoadCommand()));
1072 auto after(reinterpret_cast<uint8_t *>(signature));
1073 auto next(mach_header.Swap(signature->cmdsize));
1074 auto total(mach_header.Swap(mach_header->sizeofcmds));
1075 memmove(signature, after + next, before + total - after - next);
1076 memset(before + total - next, 0, next);
1077 mach_header->ncmds = mach_header.Swap(mach_header.Swap(mach_header->ncmds) - 1);
1078 mach_header->sizeofcmds = mach_header.Swap(total - next);
1079 signature = NULL;
1080 }
1081
1082 if (flag_S) {
1083 if (signature == NULL) {
1084 signature = reinterpret_cast<struct linkedit_data_command *>(reinterpret_cast<uint8_t *>(mach_header.GetLoadCommand()) + mach_header.Swap(mach_header->sizeofcmds));
1085 signature->cmd = mach_header.Swap(LC_CODE_SIGNATURE);
1086 signature->cmdsize = mach_header.Swap(uint32_t(sizeof(*signature)));
1087 mach_header->ncmds = mach_header.Swap(mach_header.Swap(mach_header->ncmds) + 1);
1088 mach_header->sizeofcmds = mach_header.Swap(mach_header.Swap(mach_header->sizeofcmds) + uint32_t(sizeof(*signature)));
1089 }
1090
1091 signature->dataoff = mach_header.Swap(align);
1092 signature->datasize = mach_header.Swap(allocation.alloc_);
1093 }
1094
1095 _foreach (segment, mach_header.GetSegments("__LINKEDIT")) {
1096 size_t size(mach_header.Swap(align + allocation.alloc_ - mach_header.Swap(segment->fileoff)));
1097 segment->filesize = size;
1098 segment->vmsize = Align(size, 0x1000);
1099 }
1100
1101 _foreach (segment, mach_header.GetSegments64("__LINKEDIT")) {
1102 size_t size(mach_header.Swap(align + allocation.alloc_ - mach_header.Swap(segment->fileoff)));
1103 segment->filesize = size;
1104 segment->vmsize = Align(size, 0x1000);
1105 }
1106 }
1107 }
1108
1109 Map mapping(temp ?: path, flag_T || flag_s || flag_S);
1110 FatHeader fat_header(mapping.data(), mapping.size());
1111
1112 _foreach (mach_header, fat_header.GetMachHeaders()) {
1113 struct linkedit_data_command *signature(NULL);
1114 struct encryption_info_command *encryption(NULL);
1115
1116 if (flag_A) {
1117 if (mach_header.GetCPUType() != flag_CPUType)
1118 continue;
1119 if (mach_header.GetCPUSubtype() != flag_CPUSubtype)
1120 continue;
1121 }
1122
1123 if (flag_a)
1124 printf("cpu=0x%x:0x%x\n", mach_header.GetCPUType(), mach_header.GetCPUSubtype());
1125
1126 _foreach (load_command, mach_header.GetLoadCommands()) {
1127 uint32_t cmd(mach_header.Swap(load_command->cmd));
1128
1129 if (false);
1130 else if (cmd == LC_CODE_SIGNATURE)
1131 signature = reinterpret_cast<struct linkedit_data_command *>(load_command);
1132 else if (cmd == LC_ENCRYPTION_INFO)
1133 encryption = reinterpret_cast<struct encryption_info_command *>(load_command);
1134 else if (cmd == LC_ID_DYLIB) {
1135 volatile struct dylib_command *dylib_command(reinterpret_cast<struct dylib_command *>(load_command));
1136
1137 if (flag_T) {
1138 uint32_t timed;
1139
1140 if (!timeh)
1141 timed = timev;
1142 else {
1143 dylib_command->dylib.timestamp = 0;
1144 timed = hash(reinterpret_cast<uint8_t *>(mach_header.GetBase()), mach_header.GetSize(), timev);
1145 }
1146
1147 dylib_command->dylib.timestamp = mach_header.Swap(timed);
1148 }
1149 }
1150 }
1151
1152 if (flag_D) {
1153 _assert(encryption != NULL);
1154 encryption->cryptid = mach_header.Swap(0);
1155 }
1156
1157 if (flag_e) {
1158 _assert(signature != NULL);
1159
1160 uint32_t data = mach_header.Swap(signature->dataoff);
1161
1162 uint8_t *top = reinterpret_cast<uint8_t *>(mach_header.GetBase());
1163 uint8_t *blob = top + data;
1164 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
1165
1166 for (size_t index(0); index != Swap(super->count); ++index)
1167 if (Swap(super->index[index].type) == CSSLOT_ENTITLEMENTS) {
1168 uint32_t begin = Swap(super->index[index].offset);
1169 struct Blob *entitlements = reinterpret_cast<struct Blob *>(blob + begin);
1170 fwrite(entitlements + 1, 1, Swap(entitlements->length) - sizeof(struct Blob), stdout);
1171 }
1172 }
1173
1174 if (flag_s) {
1175 _assert(signature != NULL);
1176
1177 uint32_t data = mach_header.Swap(signature->dataoff);
1178
1179 uint8_t *top = reinterpret_cast<uint8_t *>(mach_header.GetBase());
1180 uint8_t *blob = top + data;
1181 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
1182
1183 for (size_t index(0); index != Swap(super->count); ++index)
1184 if (Swap(super->index[index].type) == CSSLOT_CODEDIRECTORY) {
1185 uint32_t begin = Swap(super->index[index].offset);
1186 struct CodeDirectory *directory = reinterpret_cast<struct CodeDirectory *>(blob + begin);
1187
1188 uint8_t (*hashes)[20] = reinterpret_cast<uint8_t (*)[20]>(blob + begin + Swap(directory->hashOffset));
1189 uint32_t pages = Swap(directory->nCodeSlots);
1190
1191 if (pages != 1)
1192 for (size_t i = 0; i != pages - 1; ++i)
1193 sha1(hashes[i], top + 0x1000 * i, 0x1000);
1194 if (pages != 0)
1195 sha1(hashes[pages - 1], top + 0x1000 * (pages - 1), ((data - 1) % 0x1000) + 1);
1196 }
1197 }
1198
1199 if (flag_S) {
1200 _assert(signature != NULL);
1201
1202 uint32_t data = mach_header.Swap(signature->dataoff);
1203 uint32_t size = mach_header.Swap(signature->datasize);
1204
1205 uint8_t *top = reinterpret_cast<uint8_t *>(mach_header.GetBase());
1206 uint8_t *blob = top + data;
1207 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
1208 super->blob.magic = Swap(CSMAGIC_EMBEDDED_SIGNATURE);
1209
1210 uint32_t count = xmld == NULL ? 2 : 3;
1211 uint32_t offset = sizeof(struct SuperBlob) + count * sizeof(struct BlobIndex);
1212
1213 super->index[0].type = Swap(CSSLOT_CODEDIRECTORY);
1214 super->index[0].offset = Swap(offset);
1215
1216 uint32_t begin = offset;
1217 struct CodeDirectory *directory = reinterpret_cast<struct CodeDirectory *>(blob + begin);
1218 offset += sizeof(struct CodeDirectory);
1219
1220 directory->blob.magic = Swap(CSMAGIC_CODEDIRECTORY);
1221 directory->version = Swap(uint32_t(0x00020001));
1222 directory->flags = Swap(uint32_t(0));
1223 directory->codeLimit = Swap(data);
1224 directory->hashSize = 0x14;
1225 directory->hashType = 0x01;
1226 directory->spare1 = 0x00;
1227 directory->pageSize = 0x0c;
1228 directory->spare2 = Swap(uint32_t(0));
1229
1230 directory->identOffset = Swap(offset - begin);
1231 strcpy(reinterpret_cast<char *>(blob + offset), name);
1232 offset += strlen(name) + 1;
1233
1234 uint32_t special = xmld == NULL ? CSSLOT_REQUIREMENTS : CSSLOT_ENTITLEMENTS;
1235 directory->nSpecialSlots = Swap(special);
1236
1237 uint8_t (*hashes)[20] = reinterpret_cast<uint8_t (*)[20]>(blob + offset);
1238 memset(hashes, 0, sizeof(*hashes) * special);
1239
1240 offset += sizeof(*hashes) * special;
1241 hashes += special;
1242
1243 uint32_t pages = (data + 0x1000 - 1) / 0x1000;
1244 directory->nCodeSlots = Swap(pages);
1245
1246 if (pages != 1)
1247 for (size_t i = 0; i != pages - 1; ++i)
1248 sha1(hashes[i], top + 0x1000 * i, 0x1000);
1249 if (pages != 0)
1250 sha1(hashes[pages - 1], top + 0x1000 * (pages - 1), ((data - 1) % 0x1000) + 1);
1251
1252 directory->hashOffset = Swap(offset - begin);
1253 offset += sizeof(*hashes) * pages;
1254 directory->blob.length = Swap(offset - begin);
1255
1256 super->index[1].type = Swap(CSSLOT_REQUIREMENTS);
1257 super->index[1].offset = Swap(offset);
1258
1259 memcpy(blob + offset, "\xfa\xde\x0c\x01\x00\x00\x00\x0c\x00\x00\x00\x00", 0xc);
1260 offset += 0xc;
1261
1262 if (xmld != NULL) {
1263 super->index[2].type = Swap(CSSLOT_ENTITLEMENTS);
1264 super->index[2].offset = Swap(offset);
1265
1266 uint32_t begin = offset;
1267 struct Blob *entitlements = reinterpret_cast<struct Blob *>(blob + begin);
1268 offset += sizeof(struct Blob);
1269
1270 memcpy(blob + offset, xmld, xmls);
1271 offset += xmls;
1272
1273 entitlements->magic = Swap(CSMAGIC_ENTITLEMENTS);
1274 entitlements->length = Swap(offset - begin);
1275 }
1276
1277 for (size_t index(0); index != count; ++index) {
1278 uint32_t type = Swap(super->index[index].type);
1279 if (type != 0 && type <= special) {
1280 uint32_t offset = Swap(super->index[index].offset);
1281 struct Blob *local = (struct Blob *) (blob + offset);
1282 sha1((uint8_t *) (hashes - type), (uint8_t *) local, Swap(local->length));
1283 }
1284 }
1285
1286 super->count = Swap(count);
1287 super->blob.length = Swap(offset);
1288
1289 if (offset > size) {
1290 fprintf(stderr, "offset (%u) > size (%u)\n", offset, size);
1291 _assert(false);
1292 } //else fprintf(stderr, "offset (%zu) <= size (%zu)\n", offset, size);
1293
1294 memset(blob + offset, 0, size - offset);
1295 }
1296 }
1297
1298 if (temp != NULL) {
1299 struct stat info;
1300 _syscall(stat(path, &info));
1301 _syscall(chown(temp, info.st_uid, info.st_gid));
1302 _syscall(chmod(temp, info.st_mode));
1303 _syscall(unlink(path));
1304 _syscall(rename(temp, path));
1305 free(temp);
1306 }
1307
1308 ++filei;
1309 } catch (const char *) {
1310 ++filee;
1311 ++filei;
1312 }
1313
1314 return filee;
1315 }