1 /* JocStrap - Java/Objective-C Bootstrap
2 * Copyright (C) 2007 Jay Freeman (saurik)
6 * Redistribution and use in source and binary
7 * forms, with or without modification, are permitted
8 * provided that the following conditions are met:
10 * 1. Redistributions of source code must retain the
11 * above copyright notice, this list of conditions
12 * and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the
14 * above copyright notice, this list of conditions
15 * and the following disclaimer in the documentation
16 * and/or other materials provided with the
18 * 3. The name of the author may not be used to endorse
19 * or promote products derived from this software
20 * without specific prior written permission.
22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS''
23 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING,
24 * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
25 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE
27 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
28 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
29 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
30 * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
31 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
32 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR
33 * TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
34 * ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
35 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
38 #include "minimal/stdlib.h"
39 #include "minimal/string.h"
40 #include "minimal/mapping.h"
49 #include <sys/types.h>
57 #define FAT_MAGIC 0xcafebabe
58 #define FAT_CIGAM 0xbebafeca
78 #define MH_MAGIC 0xfeedface
79 #define MH_CIGAM 0xcefaedfe
81 #define MH_EXECUTE 0x2
84 #define MH_DYLIB_STUB 0x9
91 #define LC_REQ_DYLD 0x80000000
93 #define LC_LOAD_DYLIB 0x0c
94 #define LC_ID_DYLIB 0x0d
96 #define LC_CODE_SIGNATURE 0x1d
97 #define LC_REEXPORT_DYLIB (0x1f | LC_REQ_DYLD)
102 uint32_t current_version
;
103 uint32_t compatibility_version
;
106 struct dylib_command
{
112 struct uuid_command
{
118 struct linkedit_data_command
{
125 uint16_t Swap_(uint16_t value
) {
127 ((value
>> 8) & 0x00ff) |
128 ((value
<< 8) & 0xff00);
131 uint32_t Swap_(uint32_t value
) {
132 value
= ((value
>> 8) & 0x00ff00ff) |
133 ((value
<< 8) & 0xff00ff00);
134 value
= ((value
>> 16) & 0x0000ffff) |
135 ((value
<< 16) & 0xffff0000);
139 int16_t Swap_(int16_t value
) {
140 return Swap_(static_cast<uint16_t>(value
));
143 int32_t Swap_(int32_t value
) {
144 return Swap_(static_cast<uint32_t>(value
));
147 uint16_t Swap(uint16_t value
) {
148 return true ? Swap_(value
) : value
;
151 uint32_t Swap(uint32_t value
) {
152 return true ? Swap_(value
) : value
;
155 int16_t Swap(int16_t value
) {
156 return Swap(static_cast<uint16_t>(value
));
159 int32_t Swap(int32_t value
) {
160 return Swap(static_cast<uint32_t>(value
));
167 mach_header
*mach_header_
;
171 uint16_t Swap(uint16_t value
) const {
172 return swapped_
? Swap_(value
) : value
;
175 uint32_t Swap(uint32_t value
) const {
176 return swapped_
? Swap_(value
) : value
;
179 int16_t Swap(int16_t value
) const {
180 return Swap(static_cast<uint16_t>(value
));
183 int32_t Swap(int32_t value
) const {
184 return Swap(static_cast<uint32_t>(value
));
187 Framework(const char *framework_path
) :
190 base_
= map(framework_path
, 0, _not(size_t), &size_
, false);
191 fat_header
*fat_header
= reinterpret_cast<struct fat_header
*>(base_
);
193 if (Swap(fat_header
->magic
) == FAT_CIGAM
) {
194 swapped_
= !swapped_
;
196 } else if (Swap(fat_header
->magic
) != FAT_MAGIC
)
197 mach_header_
= (mach_header
*) base_
;
199 size_t fat_narch
= Swap(fat_header
->nfat_arch
);
200 fat_arch
*fat_arch
= reinterpret_cast<struct fat_arch
*>(fat_header
+ 1);
202 for (arch
= 0; arch
!= fat_narch
; ++arch
) {
203 uint32_t arch_offset
= Swap(fat_arch
->offset
);
204 mach_header_
= (mach_header
*) ((uint8_t *) base_
+ arch_offset
);
213 if (Swap(mach_header_
->magic
) == MH_CIGAM
)
214 swapped_
= !swapped_
;
215 else _assert(Swap(mach_header_
->magic
) == MH_MAGIC
);
218 Swap(mach_header_
->filetype
) == MH_EXECUTE
||
219 Swap(mach_header_
->filetype
) == MH_DYLIB
||
220 Swap(mach_header_
->filetype
) == MH_BUNDLE
224 struct mach_header
*operator ->() const {
236 std::vector
<struct load_command
*> GetLoadCommands() {
237 std::vector
<struct load_command
*> load_commands
;
239 struct load_command
*load_command
= reinterpret_cast<struct load_command
*>(mach_header_
+ 1);
240 for (uint32_t cmd
= 0; cmd
!= Swap(mach_header_
->ncmds
); ++cmd
) {
241 load_commands
.push_back(load_command
);
242 load_command
= (struct load_command
*) ((uint8_t *) load_command
+ Swap(load_command
->cmdsize
));
245 return load_commands
;
249 #define CSMAGIC_CODEDIRECTORY 0xfade0c02
250 #define CSMAGIC_EMBEDDED_SIGNATURE 0xfade0cc0
251 #define CSMAGIC_ENTITLEMENTS 0xfade7171
253 #define CSSLOT_CODEDIRECTORY 0
254 #define CSSLOT_REQUIREMENTS 2
255 #define CSSLOT_ENTITLEMENTS 5
270 struct BlobIndex index
[];
273 struct CodeDirectory
{
278 uint32_t identOffset
;
279 uint32_t nSpecialSlots
;
289 extern "C" uint32_t hash(uint8_t *k
, uint32_t length
, uint32_t initval
);
291 #define CODESIGN_ALLOCATE "arm-apple-darwin9-codesign_allocate"
293 void sha1(uint8_t *hash
, uint8_t *data
, size_t size
) {
296 SHA1Input(&context
, data
, size
);
297 SHA1Result(&context
, hash
);
300 int main(int argc
, const char *argv
[]) {
314 const void *xmld(NULL
);
317 std::vector
<std::string
> files
;
320 fprintf(stderr
, "usage: %s -S[entitlements.xml] <binary>\n", argv
[0]);
321 fprintf(stderr
, " %s -S cat\n", argv
[0]);
322 fprintf(stderr
, " %s -Stfp.xml gdb\n", argv
[0]);
326 for (int argi(1); argi
!= argc
; ++argi
)
327 if (argv
[argi
][0] != '-')
328 files
.push_back(argv
[argi
]);
329 else switch (argv
[argi
][1]) {
330 case 'R': flag_R
= true; break;
331 case 't': flag_t
= true; break;
332 case 'u': flag_u
= true; break;
333 case 'p': flag_p
= true; break;
343 if (argv
[argi
][2] != '\0') {
344 const char *xml
= argv
[argi
] + 2;
345 xmld
= map(xml
, 0, _not(size_t), &xmls
, true);
351 if (argv
[argi
][2] == '-')
355 timev
= strtoul(argv
[argi
] + 2, &arge
, 0);
356 _assert(arge
== argv
[argi
] + strlen(argv
[argi
]));
365 if (files
.empty()) usage
: {
369 size_t filei(0), filee(0);
370 _foreach (file
, files
) try {
371 const char *path(file
->c_str());
372 const char *base
= strrchr(path
, '/');
373 char *temp(NULL
), *dir
;
377 dir
= strndup_(path
, base
++ - path
+ 1);
384 asprintf(&temp
, "%s.%s.cs", dir
, base
);
385 const char *allocate
= getenv("CODESIGN_ALLOCATE");
386 if (allocate
== NULL
)
387 allocate
= "codesign_allocate";
389 size_t size
= _not(size_t);
391 Framework
framework(path
);
392 _foreach (load_command
, framework
.GetLoadCommands()) {
393 uint32_t cmd(framework
.Swap((*load_command
)->cmd
));
394 if (cmd
== LC_CODE_SIGNATURE
) {
395 struct linkedit_data_command
*signature
= reinterpret_cast<struct linkedit_data_command
*>(*load_command
);
396 size
= framework
.Swap(signature
->dataoff
);
397 _assert(size
< framework
.GetSize());
402 if (size
== _not(size_t))
403 size
= framework
.GetSize();
405 switch (framework
->cputype
) {
406 case 12: switch (framework
->cpusubtype
) {
407 case 0: arch
= "arm"; break;
408 case 6: arch
= "armv6"; break;
409 default: arch
= NULL
; break;
412 default: arch
= NULL
; break;
416 _assert(arch
!= NULL
);
422 asprintf(&ssize
, "%u", (sizeof(struct SuperBlob
) + 2 * sizeof(struct BlobIndex
) + sizeof(struct CodeDirectory
) + strlen(base
) + 1 + ((xmld
== NULL
? CSSLOT_REQUIREMENTS
: CSSLOT_ENTITLEMENTS
) + (size
+ 0x1000 - 1) / 0x1000) * 0x14 + 0xc + (xmld
== NULL
? 0 : 0x10 + xmls
) + 15) / 16 * 16);
423 //printf("%s -i %s -a %s %s -o %s\n", allocate, path, arch, ssize, temp);
424 execlp(allocate
, allocate
, "-i", path
, "-a", arch
, ssize
, "-o", temp
, NULL
);
429 _syscall(waitpid(pid
, &status
, 0));
430 _assert(WIFEXITED(status
));
431 _assert(WEXITSTATUS(status
) == 0);
434 Framework
framework(temp
== NULL
? path
: temp
);
435 struct linkedit_data_command
*signature(NULL
);
438 printf("path%zu='%s'\n", filei
, file
->c_str());
440 _foreach (load_command
, framework
.GetLoadCommands()) {
441 uint32_t cmd(framework
.Swap((*load_command
)->cmd
));
443 if (flag_R
&& cmd
== LC_REEXPORT_DYLIB
)
444 (*load_command
)->cmd
= framework
.Swap(LC_LOAD_DYLIB
);
445 else if (cmd
== LC_CODE_SIGNATURE
)
446 signature
= reinterpret_cast<struct linkedit_data_command
*>(*load_command
);
447 else if (cmd
== LC_UUID
) {
448 volatile struct uuid_command
*uuid_command(reinterpret_cast<struct uuid_command
*>(*load_command
));
451 printf("uuid%zu=%.2x%.2x%.2x%.2x-%.2x%.2x-%.2x%.2x-%.2x%.2x-%.2x%.2x%.2x%.2x%.2x%.2x\n", filei
,
452 uuid_command
->uuid
[ 0], uuid_command
->uuid
[ 1], uuid_command
->uuid
[ 2], uuid_command
->uuid
[ 3],
453 uuid_command
->uuid
[ 4], uuid_command
->uuid
[ 5], uuid_command
->uuid
[ 6], uuid_command
->uuid
[ 7],
454 uuid_command
->uuid
[ 8], uuid_command
->uuid
[ 9], uuid_command
->uuid
[10], uuid_command
->uuid
[11],
455 uuid_command
->uuid
[12], uuid_command
->uuid
[13], uuid_command
->uuid
[14], uuid_command
->uuid
[15]
458 } else if (cmd
== LC_ID_DYLIB
) {
459 volatile struct dylib_command
*dylib_command(reinterpret_cast<struct dylib_command
*>(*load_command
));
462 printf("time%zu=0x%.8x\n", filei
, framework
.Swap(dylib_command
->dylib
.timestamp
));
470 dylib_command
->dylib
.timestamp
= 0;
471 timed
= hash(reinterpret_cast<uint8_t *>(framework
.GetBase()), framework
.GetSize(), timev
);
474 dylib_command
->dylib
.timestamp
= framework
.Swap(timed
);
480 _assert(signature
!= NULL
);
482 uint32_t data
= framework
.Swap(signature
->dataoff
);
483 uint32_t size
= framework
.Swap(signature
->datasize
);
485 uint8_t *top
= reinterpret_cast<uint8_t *>(framework
.GetBase());
486 uint8_t *blob
= top
+ data
;
487 struct SuperBlob
*super
= reinterpret_cast<struct SuperBlob
*>(blob
);
489 for (size_t index(0); index
!= Swap(super
->count
); ++index
)
490 if (Swap(super
->index
[index
].type
) == CSSLOT_CODEDIRECTORY
) {
491 uint32_t begin
= Swap(super
->index
[index
].offset
);
492 struct CodeDirectory
*directory
= reinterpret_cast<struct CodeDirectory
*>(blob
+ begin
);
494 uint8_t (*hashes
)[20] = reinterpret_cast<uint8_t (*)[20]>(blob
+ begin
+ Swap(directory
->hashOffset
));
495 uint32_t pages
= Swap(directory
->nCodeSlots
);
498 for (size_t i
= 0; i
!= pages
- 1; ++i
)
499 sha1(hashes
[i
], top
+ 0x1000 * i
, 0x1000);
501 sha1(hashes
[pages
- 1], top
+ 0x1000 * (pages
- 1), ((data
- 1) % 0x1000) + 1);
506 _assert(signature
!= NULL
);
508 uint32_t data
= framework
.Swap(signature
->dataoff
);
509 uint32_t size
= framework
.Swap(signature
->datasize
);
511 uint8_t *top
= reinterpret_cast<uint8_t *>(framework
.GetBase());
512 uint8_t *blob
= top
+ data
;
513 struct SuperBlob
*super
= reinterpret_cast<struct SuperBlob
*>(blob
);
514 super
->blob
.magic
= Swap(CSMAGIC_EMBEDDED_SIGNATURE
);
516 uint32_t count
= xmld
== NULL
? 2 : 3;
517 uint32_t offset
= sizeof(struct SuperBlob
) + count
* sizeof(struct BlobIndex
);
519 super
->index
[0].type
= Swap(CSSLOT_CODEDIRECTORY
);
520 super
->index
[0].offset
= Swap(offset
);
522 uint32_t begin
= offset
;
523 struct CodeDirectory
*directory
= reinterpret_cast<struct CodeDirectory
*>(blob
+ begin
);
524 offset
+= sizeof(struct CodeDirectory
);
526 directory
->blob
.magic
= Swap(CSMAGIC_CODEDIRECTORY
);
527 directory
->version
= Swap(0x00020001);
528 directory
->flags
= Swap(0);
529 directory
->codeLimit
= Swap(data
);
530 directory
->hashSize
= 0x14;
531 directory
->hashType
= 0x01;
532 directory
->spare1
= 0x00;
533 directory
->pageSize
= 0x0c;
534 directory
->spare2
= Swap(0);
536 directory
->identOffset
= Swap(offset
- begin
);
537 strcpy(reinterpret_cast<char *>(blob
+ offset
), base
);
538 offset
+= strlen(base
) + 1;
540 uint32_t special
= xmld
== NULL
? CSSLOT_REQUIREMENTS
: CSSLOT_ENTITLEMENTS
;
541 directory
->nSpecialSlots
= Swap(special
);
543 uint8_t (*hashes
)[20] = reinterpret_cast<uint8_t (*)[20]>(blob
+ offset
);
544 memset(hashes
, 0, sizeof(*hashes
) * special
);
546 offset
+= sizeof(*hashes
) * special
;
549 uint32_t pages
= (data
+ 0x1000 - 1) / 0x1000;
550 directory
->nCodeSlots
= Swap(pages
);
553 for (size_t i
= 0; i
!= pages
- 1; ++i
)
554 sha1(hashes
[i
], top
+ 0x1000 * i
, 0x1000);
556 sha1(hashes
[pages
- 1], top
+ 0x1000 * (pages
- 1), ((data
- 1) % 0x1000) + 1);
558 directory
->hashOffset
= Swap(offset
- begin
);
559 offset
+= sizeof(*hashes
) * pages
;
560 directory
->blob
.length
= Swap(offset
- begin
);
562 super
->index
[1].type
= Swap(CSSLOT_REQUIREMENTS
);
563 super
->index
[1].offset
= Swap(offset
);
565 memcpy(blob
+ offset
, "\xfa\xde\x0c\x01\x00\x00\x00\x0c\x00\x00\x00\x00", 0xc);
569 super
->index
[2].type
= Swap(CSSLOT_ENTITLEMENTS
);
570 super
->index
[2].offset
= Swap(offset
);
572 uint32_t begin
= offset
;
573 struct Blob
*entitlements
= reinterpret_cast<struct Blob
*>(blob
+ begin
);
574 offset
+= sizeof(struct Blob
);
576 memcpy(blob
+ offset
, xmld
, xmls
);
579 entitlements
->magic
= Swap(CSMAGIC_ENTITLEMENTS
);
580 entitlements
->length
= Swap(offset
- begin
);
583 for (size_t index(0); index
!= count
; ++index
) {
584 uint32_t type
= Swap(super
->index
[index
].type
);
585 if (type
!= 0 && type
<= special
) {
586 uint32_t offset
= Swap(super
->index
[index
].offset
);
587 struct Blob
*local
= (struct Blob
*) (blob
+ offset
);
588 sha1((uint8_t *) (hashes
- type
), (uint8_t *) local
, Swap(local
->length
));
592 super
->count
= Swap(count
);
593 super
->blob
.length
= Swap(offset
);
596 fprintf(stderr
, "offset (%zu) > size (%zu)\n", offset
, size
);
598 } //else fprintf(stderr, "offset (%zu) <= size (%zu)\n", offset, size);
600 memset(blob
+ offset
, 0, size
- offset
);
605 _syscall(stat(path
, &info
));
606 _syscall(chown(temp
, info
.st_uid
, info
.st_gid
));
607 _syscall(chmod(temp
, info
.st_mode
));
608 _syscall(unlink(path
));
609 _syscall(rename(temp
, path
));
615 } catch (const char *) {