]> git.saurik.com Git - ldid.git/blob - ldid.cpp
b58198845e85b7c6bb597de995e9eeb0a63ae59b
[ldid.git] / ldid.cpp
1 /* JocStrap - Java/Objective-C Bootstrap
2 * Copyright (C) 2007 Jay Freeman (saurik)
3 */
4
5 /*
6 * Redistribution and use in source and binary
7 * forms, with or without modification, are permitted
8 * provided that the following conditions are met:
9 *
10 * 1. Redistributions of source code must retain the
11 * above copyright notice, this list of conditions
12 * and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the
14 * above copyright notice, this list of conditions
15 * and the following disclaimer in the documentation
16 * and/or other materials provided with the
17 * distribution.
18 * 3. The name of the author may not be used to endorse
19 * or promote products derived from this software
20 * without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS''
23 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING,
24 * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
25 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE
27 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
28 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
29 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
30 * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
31 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
32 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR
33 * TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
34 * ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
35 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
36 */
37
38 #include "minimal/stdlib.h"
39 #include "minimal/string.h"
40 #include "minimal/mapping.h"
41
42 #include "sha1.h"
43
44 #include <cstring>
45 #include <string>
46 #include <vector>
47
48 #include <sys/wait.h>
49 #include <sys/types.h>
50 #include <sys/stat.h>
51
52 struct fat_header {
53 uint32_t magic;
54 uint32_t nfat_arch;
55 } _packed;
56
57 #define FAT_MAGIC 0xcafebabe
58 #define FAT_CIGAM 0xbebafeca
59
60 struct fat_arch {
61 uint32_t cputype;
62 uint32_t cpusubtype;
63 uint32_t offset;
64 uint32_t size;
65 uint32_t align;
66 } _packed;
67
68 struct mach_header {
69 uint32_t magic;
70 uint32_t cputype;
71 uint32_t cpusubtype;
72 uint32_t filetype;
73 uint32_t ncmds;
74 uint32_t sizeofcmds;
75 uint32_t flags;
76 } _packed;
77
78 #define MH_MAGIC 0xfeedface
79 #define MH_CIGAM 0xcefaedfe
80
81 #define MH_EXECUTE 0x2
82 #define MH_DYLIB 0x6
83 #define MH_BUNDLE 0x8
84 #define MH_DYLIB_STUB 0x9
85
86 struct load_command {
87 uint32_t cmd;
88 uint32_t cmdsize;
89 } _packed;
90
91 #define LC_REQ_DYLD 0x80000000
92
93 #define LC_LOAD_DYLIB 0x0c
94 #define LC_ID_DYLIB 0x0d
95 #define LC_UUID 0x1b
96 #define LC_CODE_SIGNATURE 0x1d
97 #define LC_REEXPORT_DYLIB (0x1f | LC_REQ_DYLD)
98
99 struct dylib {
100 uint32_t name;
101 uint32_t timestamp;
102 uint32_t current_version;
103 uint32_t compatibility_version;
104 } _packed;
105
106 struct dylib_command {
107 uint32_t cmd;
108 uint32_t cmdsize;
109 struct dylib dylib;
110 } _packed;
111
112 struct uuid_command {
113 uint32_t cmd;
114 uint32_t cmdsize;
115 uint8_t uuid[16];
116 } _packed;
117
118 struct linkedit_data_command {
119 uint32_t cmd;
120 uint32_t cmdsize;
121 uint32_t dataoff;
122 uint32_t datasize;
123 } _packed;
124
125 uint16_t Swap_(uint16_t value) {
126 return
127 ((value >> 8) & 0x00ff) |
128 ((value << 8) & 0xff00);
129 }
130
131 uint32_t Swap_(uint32_t value) {
132 value = ((value >> 8) & 0x00ff00ff) |
133 ((value << 8) & 0xff00ff00);
134 value = ((value >> 16) & 0x0000ffff) |
135 ((value << 16) & 0xffff0000);
136 return value;
137 }
138
139 int16_t Swap_(int16_t value) {
140 return Swap_(static_cast<uint16_t>(value));
141 }
142
143 int32_t Swap_(int32_t value) {
144 return Swap_(static_cast<uint32_t>(value));
145 }
146
147 uint16_t Swap(uint16_t value) {
148 return true ? Swap_(value) : value;
149 }
150
151 uint32_t Swap(uint32_t value) {
152 return true ? Swap_(value) : value;
153 }
154
155 int16_t Swap(int16_t value) {
156 return Swap(static_cast<uint16_t>(value));
157 }
158
159 int32_t Swap(int32_t value) {
160 return Swap(static_cast<uint32_t>(value));
161 }
162
163 class Framework {
164 private:
165 void *base_;
166 size_t size_;
167 mach_header *mach_header_;
168 bool swapped_;
169
170 public:
171 uint16_t Swap(uint16_t value) const {
172 return swapped_ ? Swap_(value) : value;
173 }
174
175 uint32_t Swap(uint32_t value) const {
176 return swapped_ ? Swap_(value) : value;
177 }
178
179 int16_t Swap(int16_t value) const {
180 return Swap(static_cast<uint16_t>(value));
181 }
182
183 int32_t Swap(int32_t value) const {
184 return Swap(static_cast<uint32_t>(value));
185 }
186
187 Framework(const char *framework_path) :
188 swapped_(false)
189 {
190 base_ = map(framework_path, 0, _not(size_t), &size_, false);
191 fat_header *fat_header = reinterpret_cast<struct fat_header *>(base_);
192
193 if (Swap(fat_header->magic) == FAT_CIGAM) {
194 swapped_ = !swapped_;
195 goto fat;
196 } else if (Swap(fat_header->magic) != FAT_MAGIC)
197 mach_header_ = (mach_header *) base_;
198 else fat: {
199 size_t fat_narch = Swap(fat_header->nfat_arch);
200 fat_arch *fat_arch = reinterpret_cast<struct fat_arch *>(fat_header + 1);
201 size_t arch;
202 for (arch = 0; arch != fat_narch; ++arch) {
203 uint32_t arch_offset = Swap(fat_arch->offset);
204 mach_header_ = (mach_header *) ((uint8_t *) base_ + arch_offset);
205 goto found;
206 ++fat_arch;
207 }
208
209 _assert(false);
210 }
211
212 found:
213 if (Swap(mach_header_->magic) == MH_CIGAM)
214 swapped_ = !swapped_;
215 else _assert(Swap(mach_header_->magic) == MH_MAGIC);
216
217 _assert(
218 Swap(mach_header_->filetype) == MH_EXECUTE ||
219 Swap(mach_header_->filetype) == MH_DYLIB ||
220 Swap(mach_header_->filetype) == MH_BUNDLE
221 );
222 }
223
224 struct mach_header *operator ->() const {
225 return mach_header_;
226 }
227
228 void *GetBase() {
229 return base_;
230 }
231
232 size_t GetSize() {
233 return size_;
234 }
235
236 std::vector<struct load_command *> GetLoadCommands() {
237 std::vector<struct load_command *> load_commands;
238
239 struct load_command *load_command = reinterpret_cast<struct load_command *>(mach_header_ + 1);
240 for (uint32_t cmd = 0; cmd != Swap(mach_header_->ncmds); ++cmd) {
241 load_commands.push_back(load_command);
242 load_command = (struct load_command *) ((uint8_t *) load_command + Swap(load_command->cmdsize));
243 }
244
245 return load_commands;
246 }
247 };
248
249 #define CSMAGIC_CODEDIRECTORY 0xfade0c02
250 #define CSMAGIC_EMBEDDED_SIGNATURE 0xfade0cc0
251 #define CSMAGIC_ENTITLEMENTS 0xfade7171
252
253 #define CSSLOT_CODEDIRECTORY 0
254 #define CSSLOT_REQUIREMENTS 2
255 #define CSSLOT_ENTITLEMENTS 5
256
257 struct BlobIndex {
258 uint32_t type;
259 uint32_t offset;
260 } _packed;
261
262 struct Blob {
263 uint32_t magic;
264 uint32_t length;
265 } _packed;
266
267 struct SuperBlob {
268 struct Blob blob;
269 uint32_t count;
270 struct BlobIndex index[];
271 } _packed;
272
273 struct CodeDirectory {
274 struct Blob blob;
275 uint32_t version;
276 uint32_t flags;
277 uint32_t hashOffset;
278 uint32_t identOffset;
279 uint32_t nSpecialSlots;
280 uint32_t nCodeSlots;
281 uint32_t codeLimit;
282 uint8_t hashSize;
283 uint8_t hashType;
284 uint8_t spare1;
285 uint8_t pageSize;
286 uint32_t spare2;
287 } _packed;
288
289 extern "C" uint32_t hash(uint8_t *k, uint32_t length, uint32_t initval);
290
291 #define CODESIGN_ALLOCATE "arm-apple-darwin9-codesign_allocate"
292
293 void sha1(uint8_t *hash, uint8_t *data, size_t size) {
294 SHA1Context context;
295 SHA1Reset(&context);
296 SHA1Input(&context, data, size);
297 SHA1Result(&context, hash);
298 }
299
300 int main(int argc, const char *argv[]) {
301 bool flag_R(false);
302 bool flag_t(false);
303 bool flag_p(false);
304 bool flag_u(false);
305
306 bool flag_T(false);
307
308 bool flag_S(false);
309 bool flag_s(false);
310
311 bool timeh(false);
312 uint32_t timev(0);
313
314 const void *xmld(NULL);
315 size_t xmls(0);
316
317 std::vector<std::string> files;
318
319 if (argc == 1) {
320 fprintf(stderr, "usage: %s -S[entitlements.xml] <binary>\n", argv[0]);
321 fprintf(stderr, " %s -S cat\n", argv[0]);
322 fprintf(stderr, " %s -Stfp.xml gdb\n", argv[0]);
323 exit(0);
324 }
325
326 for (int argi(1); argi != argc; ++argi)
327 if (argv[argi][0] != '-')
328 files.push_back(argv[argi]);
329 else switch (argv[argi][1]) {
330 case 'R': flag_R = true; break;
331 case 't': flag_t = true; break;
332 case 'u': flag_u = true; break;
333 case 'p': flag_p = true; break;
334
335 case 's':
336 _assert(!flag_S);
337 flag_s = true;
338 break;
339
340 case 'S':
341 _assert(!flag_s);
342 flag_S = true;
343 if (argv[argi][2] != '\0') {
344 const char *xml = argv[argi] + 2;
345 xmld = map(xml, 0, _not(size_t), &xmls, true);
346 }
347 break;
348
349 case 'T': {
350 flag_T = true;
351 if (argv[argi][2] == '-')
352 timeh = true;
353 else {
354 char *arge;
355 timev = strtoul(argv[argi] + 2, &arge, 0);
356 _assert(arge == argv[argi] + strlen(argv[argi]));
357 }
358 } break;
359
360 default:
361 goto usage;
362 break;
363 }
364
365 if (files.empty()) usage: {
366 exit(0);
367 }
368
369 size_t filei(0), filee(0);
370 _foreach (file, files) try {
371 const char *path(file->c_str());
372 const char *base = strrchr(path, '/');
373 char *temp(NULL), *dir;
374 mode_t mode = 0;
375
376 if (base != NULL)
377 dir = strndup_(path, base++ - path + 1);
378 else {
379 dir = strdup("");
380 base = path;
381 }
382
383 if (flag_S) {
384 asprintf(&temp, "%s.%s.cs", dir, base);
385 const char *allocate = getenv("CODESIGN_ALLOCATE");
386 if (allocate == NULL)
387 allocate = "codesign_allocate";
388
389 size_t size = _not(size_t);
390 const char *arch; {
391 Framework framework(path);
392 _foreach (load_command, framework.GetLoadCommands()) {
393 uint32_t cmd(framework.Swap((*load_command)->cmd));
394 if (cmd == LC_CODE_SIGNATURE) {
395 struct linkedit_data_command *signature = reinterpret_cast<struct linkedit_data_command *>(*load_command);
396 size = framework.Swap(signature->dataoff);
397 _assert(size < framework.GetSize());
398 break;
399 }
400 }
401
402 if (size == _not(size_t))
403 size = framework.GetSize();
404
405 switch (framework->cputype) {
406 case 12: switch (framework->cpusubtype) {
407 case 0: arch = "arm"; break;
408 case 6: arch = "armv6"; break;
409 default: arch = NULL; break;
410 } break;
411
412 default: arch = NULL; break;
413 }
414 }
415
416 _assert(arch != NULL);
417
418 pid_t pid = fork();
419 _syscall(pid);
420 if (pid == 0) {
421 char *ssize;
422 asprintf(&ssize, "%u", (sizeof(struct SuperBlob) + 2 * sizeof(struct BlobIndex) + sizeof(struct CodeDirectory) + strlen(base) + 1 + ((xmld == NULL ? CSSLOT_REQUIREMENTS : CSSLOT_ENTITLEMENTS) + (size + 0x1000 - 1) / 0x1000) * 0x14 + 0xc + (xmld == NULL ? 0 : 0x10 + xmls) + 15) / 16 * 16);
423 //printf("%s -i %s -a %s %s -o %s\n", allocate, path, arch, ssize, temp);
424 execlp(allocate, allocate, "-i", path, "-a", arch, ssize, "-o", temp, NULL);
425 _assert(false);
426 }
427
428 int status;
429 _syscall(waitpid(pid, &status, 0));
430 _assert(WIFEXITED(status));
431 _assert(WEXITSTATUS(status) == 0);
432 }
433
434 Framework framework(temp == NULL ? path : temp);
435 struct linkedit_data_command *signature(NULL);
436
437 if (flag_p)
438 printf("path%zu='%s'\n", filei, file->c_str());
439
440 _foreach (load_command, framework.GetLoadCommands()) {
441 uint32_t cmd(framework.Swap((*load_command)->cmd));
442
443 if (flag_R && cmd == LC_REEXPORT_DYLIB)
444 (*load_command)->cmd = framework.Swap(LC_LOAD_DYLIB);
445 else if (cmd == LC_CODE_SIGNATURE)
446 signature = reinterpret_cast<struct linkedit_data_command *>(*load_command);
447 else if (cmd == LC_UUID) {
448 volatile struct uuid_command *uuid_command(reinterpret_cast<struct uuid_command *>(*load_command));
449
450 if (flag_u) {
451 printf("uuid%zu=%.2x%.2x%.2x%.2x-%.2x%.2x-%.2x%.2x-%.2x%.2x-%.2x%.2x%.2x%.2x%.2x%.2x\n", filei,
452 uuid_command->uuid[ 0], uuid_command->uuid[ 1], uuid_command->uuid[ 2], uuid_command->uuid[ 3],
453 uuid_command->uuid[ 4], uuid_command->uuid[ 5], uuid_command->uuid[ 6], uuid_command->uuid[ 7],
454 uuid_command->uuid[ 8], uuid_command->uuid[ 9], uuid_command->uuid[10], uuid_command->uuid[11],
455 uuid_command->uuid[12], uuid_command->uuid[13], uuid_command->uuid[14], uuid_command->uuid[15]
456 );
457 }
458 } else if (cmd == LC_ID_DYLIB) {
459 volatile struct dylib_command *dylib_command(reinterpret_cast<struct dylib_command *>(*load_command));
460
461 if (flag_t)
462 printf("time%zu=0x%.8x\n", filei, framework.Swap(dylib_command->dylib.timestamp));
463
464 if (flag_T) {
465 uint32_t timed;
466
467 if (!timeh)
468 timed = timev;
469 else {
470 dylib_command->dylib.timestamp = 0;
471 timed = hash(reinterpret_cast<uint8_t *>(framework.GetBase()), framework.GetSize(), timev);
472 }
473
474 dylib_command->dylib.timestamp = framework.Swap(timed);
475 }
476 }
477 }
478
479 if (flag_s) {
480 _assert(signature != NULL);
481
482 uint32_t data = framework.Swap(signature->dataoff);
483 uint32_t size = framework.Swap(signature->datasize);
484
485 uint8_t *top = reinterpret_cast<uint8_t *>(framework.GetBase());
486 uint8_t *blob = top + data;
487 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
488
489 for (size_t index(0); index != Swap(super->count); ++index)
490 if (Swap(super->index[index].type) == CSSLOT_CODEDIRECTORY) {
491 uint32_t begin = Swap(super->index[index].offset);
492 struct CodeDirectory *directory = reinterpret_cast<struct CodeDirectory *>(blob + begin);
493
494 uint8_t (*hashes)[20] = reinterpret_cast<uint8_t (*)[20]>(blob + begin + Swap(directory->hashOffset));
495 uint32_t pages = Swap(directory->nCodeSlots);
496
497 if (pages != 1)
498 for (size_t i = 0; i != pages - 1; ++i)
499 sha1(hashes[i], top + 0x1000 * i, 0x1000);
500 if (pages != 0)
501 sha1(hashes[pages - 1], top + 0x1000 * (pages - 1), ((data - 1) % 0x1000) + 1);
502 }
503 }
504
505 if (flag_S) {
506 _assert(signature != NULL);
507
508 uint32_t data = framework.Swap(signature->dataoff);
509 uint32_t size = framework.Swap(signature->datasize);
510
511 uint8_t *top = reinterpret_cast<uint8_t *>(framework.GetBase());
512 uint8_t *blob = top + data;
513 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
514 super->blob.magic = Swap(CSMAGIC_EMBEDDED_SIGNATURE);
515
516 uint32_t count = xmld == NULL ? 2 : 3;
517 uint32_t offset = sizeof(struct SuperBlob) + count * sizeof(struct BlobIndex);
518
519 super->index[0].type = Swap(CSSLOT_CODEDIRECTORY);
520 super->index[0].offset = Swap(offset);
521
522 uint32_t begin = offset;
523 struct CodeDirectory *directory = reinterpret_cast<struct CodeDirectory *>(blob + begin);
524 offset += sizeof(struct CodeDirectory);
525
526 directory->blob.magic = Swap(CSMAGIC_CODEDIRECTORY);
527 directory->version = Swap(0x00020001);
528 directory->flags = Swap(0);
529 directory->codeLimit = Swap(data);
530 directory->hashSize = 0x14;
531 directory->hashType = 0x01;
532 directory->spare1 = 0x00;
533 directory->pageSize = 0x0c;
534 directory->spare2 = Swap(0);
535
536 directory->identOffset = Swap(offset - begin);
537 strcpy(reinterpret_cast<char *>(blob + offset), base);
538 offset += strlen(base) + 1;
539
540 uint32_t special = xmld == NULL ? CSSLOT_REQUIREMENTS : CSSLOT_ENTITLEMENTS;
541 directory->nSpecialSlots = Swap(special);
542
543 uint8_t (*hashes)[20] = reinterpret_cast<uint8_t (*)[20]>(blob + offset);
544 memset(hashes, 0, sizeof(*hashes) * special);
545
546 offset += sizeof(*hashes) * special;
547 hashes += special;
548
549 uint32_t pages = (data + 0x1000 - 1) / 0x1000;
550 directory->nCodeSlots = Swap(pages);
551
552 if (pages != 1)
553 for (size_t i = 0; i != pages - 1; ++i)
554 sha1(hashes[i], top + 0x1000 * i, 0x1000);
555 if (pages != 0)
556 sha1(hashes[pages - 1], top + 0x1000 * (pages - 1), ((data - 1) % 0x1000) + 1);
557
558 directory->hashOffset = Swap(offset - begin);
559 offset += sizeof(*hashes) * pages;
560 directory->blob.length = Swap(offset - begin);
561
562 super->index[1].type = Swap(CSSLOT_REQUIREMENTS);
563 super->index[1].offset = Swap(offset);
564
565 memcpy(blob + offset, "\xfa\xde\x0c\x01\x00\x00\x00\x0c\x00\x00\x00\x00", 0xc);
566 offset += 0xc;
567
568 if (xmld != NULL) {
569 super->index[2].type = Swap(CSSLOT_ENTITLEMENTS);
570 super->index[2].offset = Swap(offset);
571
572 uint32_t begin = offset;
573 struct Blob *entitlements = reinterpret_cast<struct Blob *>(blob + begin);
574 offset += sizeof(struct Blob);
575
576 memcpy(blob + offset, xmld, xmls);
577 offset += xmls;
578
579 entitlements->magic = Swap(CSMAGIC_ENTITLEMENTS);
580 entitlements->length = Swap(offset - begin);
581 }
582
583 for (size_t index(0); index != count; ++index) {
584 uint32_t type = Swap(super->index[index].type);
585 if (type != 0 && type <= special) {
586 uint32_t offset = Swap(super->index[index].offset);
587 struct Blob *local = (struct Blob *) (blob + offset);
588 sha1((uint8_t *) (hashes - type), (uint8_t *) local, Swap(local->length));
589 }
590 }
591
592 super->count = Swap(count);
593 super->blob.length = Swap(offset);
594
595 if (offset > size) {
596 fprintf(stderr, "offset (%zu) > size (%zu)\n", offset, size);
597 _assert(false);
598 } //else fprintf(stderr, "offset (%zu) <= size (%zu)\n", offset, size);
599
600 memset(blob + offset, 0, size - offset);
601 }
602
603 if (temp) {
604 struct stat info;
605 _syscall(stat(path, &info));
606 _syscall(chown(temp, info.st_uid, info.st_gid));
607 _syscall(chmod(temp, info.st_mode));
608 _syscall(unlink(path));
609 _syscall(rename(temp, path));
610 free(temp);
611 }
612
613 free(dir);
614 ++filei;
615 } catch (const char *) {
616 ++filee;
617 ++filei;
618 }
619
620 return filee;
621 }