]> git.cameronkatri.com Git - ldid.git/blob - ldid.cpp
Added codehash update-only and entitlement hashing.
[ldid.git] / ldid.cpp
1 /* JocStrap - Java/Objective-C Bootstrap
2 * Copyright (C) 2007 Jay Freeman (saurik)
3 */
4
5 /*
6 * Redistribution and use in source and binary
7 * forms, with or without modification, are permitted
8 * provided that the following conditions are met:
9 *
10 * 1. Redistributions of source code must retain the
11 * above copyright notice, this list of conditions
12 * and the following disclaimer.
13 * 2. Redistributions in binary form must reproduce the
14 * above copyright notice, this list of conditions
15 * and the following disclaimer in the documentation
16 * and/or other materials provided with the
17 * distribution.
18 * 3. The name of the author may not be used to endorse
19 * or promote products derived from this software
20 * without specific prior written permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS''
23 * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING,
24 * BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
25 * MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE
27 * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
28 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
29 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
30 * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
31 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
32 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR
33 * TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
34 * ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF
35 * ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
36 */
37
38 #include "minimal/stdlib.h"
39 #include "minimal/string.h"
40 #include "minimal/mapping.h"
41
42 #include "sha1.h"
43
44 #include <cstring>
45 #include <string>
46 #include <vector>
47
48 #include <sys/wait.h>
49 #include <sys/types.h>
50 #include <sys/stat.h>
51
52 struct fat_header {
53 uint32_t magic;
54 uint32_t nfat_arch;
55 } _packed;
56
57 #define FAT_MAGIC 0xcafebabe
58 #define FAT_CIGAM 0xbebafeca
59
60 struct fat_arch {
61 uint32_t cputype;
62 uint32_t cpusubtype;
63 uint32_t offset;
64 uint32_t size;
65 uint32_t align;
66 } _packed;
67
68 struct mach_header {
69 uint32_t magic;
70 uint32_t cputype;
71 uint32_t cpusubtype;
72 uint32_t filetype;
73 uint32_t ncmds;
74 uint32_t sizeofcmds;
75 uint32_t flags;
76 } _packed;
77
78 #define MH_MAGIC 0xfeedface
79 #define MH_CIGAM 0xcefaedfe
80
81 #define MH_EXECUTE 0x2
82 #define MH_DYLIB 0x6
83 #define MH_BUNDLE 0x8
84 #define MH_DYLIB_STUB 0x9
85
86 struct load_command {
87 uint32_t cmd;
88 uint32_t cmdsize;
89 } _packed;
90
91 #define LC_REQ_DYLD 0x80000000
92
93 #define LC_LOAD_DYLIB 0x0c
94 #define LC_ID_DYLIB 0x0d
95 #define LC_UUID 0x1b
96 #define LC_CODE_SIGNATURE 0x1d
97 #define LC_REEXPORT_DYLIB (0x1f | LC_REQ_DYLD)
98
99 struct dylib {
100 uint32_t name;
101 uint32_t timestamp;
102 uint32_t current_version;
103 uint32_t compatibility_version;
104 } _packed;
105
106 struct dylib_command {
107 uint32_t cmd;
108 uint32_t cmdsize;
109 struct dylib dylib;
110 } _packed;
111
112 struct uuid_command {
113 uint32_t cmd;
114 uint32_t cmdsize;
115 uint8_t uuid[16];
116 } _packed;
117
118 struct linkedit_data_command {
119 uint32_t cmd;
120 uint32_t cmdsize;
121 uint32_t dataoff;
122 uint32_t datasize;
123 } _packed;
124
125 uint16_t Swap_(uint16_t value) {
126 return
127 ((value >> 8) & 0x00ff) |
128 ((value << 8) & 0xff00);
129 }
130
131 uint32_t Swap_(uint32_t value) {
132 value = ((value >> 8) & 0x00ff00ff) |
133 ((value << 8) & 0xff00ff00);
134 value = ((value >> 16) & 0x0000ffff) |
135 ((value << 16) & 0xffff0000);
136 return value;
137 }
138
139 int16_t Swap_(int16_t value) {
140 return Swap_(static_cast<uint16_t>(value));
141 }
142
143 int32_t Swap_(int32_t value) {
144 return Swap_(static_cast<uint32_t>(value));
145 }
146
147 uint16_t Swap(uint16_t value) {
148 return true ? Swap_(value) : value;
149 }
150
151 uint32_t Swap(uint32_t value) {
152 return true ? Swap_(value) : value;
153 }
154
155 int16_t Swap(int16_t value) {
156 return Swap(static_cast<uint16_t>(value));
157 }
158
159 int32_t Swap(int32_t value) {
160 return Swap(static_cast<uint32_t>(value));
161 }
162
163 class Framework {
164 private:
165 void *base_;
166 size_t size_;
167 mach_header *mach_header_;
168 bool swapped_;
169
170 public:
171 uint16_t Swap(uint16_t value) const {
172 return swapped_ ? Swap_(value) : value;
173 }
174
175 uint32_t Swap(uint32_t value) const {
176 return swapped_ ? Swap_(value) : value;
177 }
178
179 int16_t Swap(int16_t value) const {
180 return Swap(static_cast<uint16_t>(value));
181 }
182
183 int32_t Swap(int32_t value) const {
184 return Swap(static_cast<uint32_t>(value));
185 }
186
187 Framework(const char *framework_path) :
188 swapped_(false)
189 {
190 base_ = map(framework_path, 0, _not(size_t), &size_, false);
191 fat_header *fat_header = reinterpret_cast<struct fat_header *>(base_);
192
193 if (Swap(fat_header->magic) == FAT_CIGAM) {
194 swapped_ = !swapped_;
195 goto fat;
196 } else if (Swap(fat_header->magic) != FAT_MAGIC)
197 mach_header_ = (mach_header *) base_;
198 else fat: {
199 size_t fat_narch = Swap(fat_header->nfat_arch);
200 fat_arch *fat_arch = reinterpret_cast<struct fat_arch *>(fat_header + 1);
201 size_t arch;
202 for (arch = 0; arch != fat_narch; ++arch) {
203 uint32_t arch_offset = Swap(fat_arch->offset);
204 mach_header_ = (mach_header *) ((uint8_t *) base_ + arch_offset);
205 goto found;
206 ++fat_arch;
207 }
208
209 _assert(false);
210 }
211
212 found:
213 if (Swap(mach_header_->magic) == MH_CIGAM)
214 swapped_ = !swapped_;
215 else _assert(Swap(mach_header_->magic) == MH_MAGIC);
216
217 _assert(
218 Swap(mach_header_->filetype) == MH_EXECUTE ||
219 Swap(mach_header_->filetype) == MH_DYLIB ||
220 Swap(mach_header_->filetype) == MH_BUNDLE
221 );
222 }
223
224 struct mach_header *operator ->() const {
225 return mach_header_;
226 }
227
228 void *GetBase() {
229 return base_;
230 }
231
232 size_t GetSize() {
233 return size_;
234 }
235
236 std::vector<struct load_command *> GetLoadCommands() {
237 std::vector<struct load_command *> load_commands;
238
239 struct load_command *load_command = reinterpret_cast<struct load_command *>(mach_header_ + 1);
240 for (uint32_t cmd = 0; cmd != Swap(mach_header_->ncmds); ++cmd) {
241 load_commands.push_back(load_command);
242 load_command = (struct load_command *) ((uint8_t *) load_command + Swap(load_command->cmdsize));
243 }
244
245 return load_commands;
246 }
247 };
248
249 #define CSMAGIC_CODEDIRECTORY 0xfade0c02
250 #define CSMAGIC_EMBEDDED_SIGNATURE 0xfade0cc0
251 #define CSMAGIC_ENTITLEMENTS 0xfade7171
252
253 #define CSSLOT_CODEDIRECTORY 0
254 #define CSSLOT_REQUIREMENTS 2
255 #define CSSLOT_ENTITLEMENTS 5
256
257 struct BlobIndex {
258 uint32_t type;
259 uint32_t offset;
260 } _packed;
261
262 struct Blob {
263 uint32_t magic;
264 uint32_t length;
265 } _packed;
266
267 struct SuperBlob {
268 struct Blob blob;
269 uint32_t count;
270 struct BlobIndex index[];
271 } _packed;
272
273 struct CodeDirectory {
274 struct Blob blob;
275 uint32_t version;
276 uint32_t flags;
277 uint32_t hashOffset;
278 uint32_t identOffset;
279 uint32_t nSpecialSlots;
280 uint32_t nCodeSlots;
281 uint32_t codeLimit;
282 uint8_t hashSize;
283 uint8_t hashType;
284 uint8_t spare1;
285 uint8_t pageSize;
286 uint32_t spare2;
287 } _packed;
288
289 extern "C" uint32_t hash(uint8_t *k, uint32_t length, uint32_t initval);
290
291 #define CODESIGN_ALLOCATE "arm-apple-darwin9-codesign_allocate"
292
293 void sha1(uint8_t *hash, uint8_t *data, size_t size) {
294 SHA1Context context;
295 SHA1Reset(&context);
296 SHA1Input(&context, data, size);
297 SHA1Result(&context, hash);
298 }
299
300 int main(int argc, const char *argv[]) {
301 bool flag_R(false);
302 bool flag_t(false);
303 bool flag_p(false);
304 bool flag_u(false);
305
306 bool flag_T(false);
307
308 bool flag_S(false);
309 bool flag_s(false);
310
311 bool timeh(false);
312 uint32_t timev(0);
313
314 const void *xmld(NULL);
315 size_t xmls(0);
316
317 std::vector<std::string> files;
318
319 _assert(argc != 0);
320 for (int argi(1); argi != argc; ++argi)
321 if (argv[argi][0] != '-')
322 files.push_back(argv[argi]);
323 else switch (argv[argi][1]) {
324 case 'R': flag_R = true; break;
325 case 't': flag_t = true; break;
326 case 'u': flag_u = true; break;
327 case 'p': flag_p = true; break;
328
329 case 's':
330 _assert(!flag_S);
331 flag_s = true;
332 break;
333
334 case 'S':
335 _assert(!flag_s);
336 flag_S = true;
337 if (argv[argi][2] != '\0') {
338 const char *xml = argv[argi] + 2;
339 xmld = map(xml, 0, _not(size_t), &xmls, true);
340 }
341 break;
342
343 case 'T': {
344 flag_T = true;
345 if (argv[argi][2] == '-')
346 timeh = true;
347 else {
348 char *arge;
349 timev = strtoul(argv[argi] + 2, &arge, 0);
350 _assert(arge == argv[argi] + strlen(argv[argi]));
351 }
352 } break;
353
354 default:
355 goto usage;
356 break;
357 }
358
359 if (files.empty()) usage: {
360 exit(0);
361 }
362
363 size_t filei(0), filee(0);
364 _foreach (file, files) try {
365 const char *path(file->c_str());
366 const char *base = strrchr(path, '/');
367 char *temp(NULL), *dir;
368 mode_t mode = 0;
369
370 if (base != NULL)
371 dir = strndup_(path, base++ - path + 1);
372 else {
373 dir = strdup("");
374 base = path;
375 }
376
377 if (flag_S) {
378 asprintf(&temp, "%s.%s.cs", dir, base);
379 const char *allocate = getenv("CODESIGN_ALLOCATE");
380 if (allocate == NULL)
381 allocate = "codesign_allocate";
382
383 size_t size = _not(size_t);
384 const char *arch; {
385 Framework framework(path);
386 _foreach (load_command, framework.GetLoadCommands()) {
387 uint32_t cmd(framework.Swap((*load_command)->cmd));
388 if (cmd == LC_CODE_SIGNATURE) {
389 struct linkedit_data_command *signature = reinterpret_cast<struct linkedit_data_command *>(*load_command);
390 size = framework.Swap(signature->dataoff);
391 _assert(size < framework.GetSize());
392 break;
393 }
394 }
395
396 if (size == _not(size_t))
397 size = framework.GetSize();
398
399 switch (framework->cputype) {
400 case 12: switch (framework->cpusubtype) {
401 case 0: arch = "arm"; break;
402 case 6: arch = "armv6"; break;
403 default: arch = NULL; break;
404 } break;
405
406 default: arch = NULL; break;
407 }
408 }
409
410 _assert(arch != NULL);
411
412 pid_t pid = fork();
413 _syscall(pid);
414 if (pid == 0) {
415 char *ssize;
416 asprintf(&ssize, "%u", (sizeof(struct SuperBlob) + 2 * sizeof(struct BlobIndex) + sizeof(struct CodeDirectory) + strlen(base) + 1 + ((xmld == NULL ? CSSLOT_REQUIREMENTS : CSSLOT_ENTITLEMENTS) + (size + 0x1000 - 1) / 0x1000) * 0x14 + 0xc + (xmld == NULL ? 0 : 0x10 + xmls) + 15) / 16 * 16);
417 //printf("%s -i %s -a %s %s -o %s\n", allocate, path, arch, ssize, temp);
418 execlp(allocate, allocate, "-i", path, "-a", arch, ssize, "-o", temp, NULL);
419 _assert(false);
420 }
421
422 int status;
423 _syscall(waitpid(pid, &status, 0));
424 _assert(WIFEXITED(status));
425 _assert(WEXITSTATUS(status) == 0);
426 }
427
428 Framework framework(temp == NULL ? path : temp);
429 struct linkedit_data_command *signature(NULL);
430
431 if (flag_p)
432 printf("path%zu='%s'\n", filei, file->c_str());
433
434 _foreach (load_command, framework.GetLoadCommands()) {
435 uint32_t cmd(framework.Swap((*load_command)->cmd));
436
437 if (flag_R && cmd == LC_REEXPORT_DYLIB)
438 (*load_command)->cmd = framework.Swap(LC_LOAD_DYLIB);
439 else if (cmd == LC_CODE_SIGNATURE)
440 signature = reinterpret_cast<struct linkedit_data_command *>(*load_command);
441 else if (cmd == LC_UUID) {
442 volatile struct uuid_command *uuid_command(reinterpret_cast<struct uuid_command *>(*load_command));
443
444 if (flag_u) {
445 printf("uuid%zu=%.2x%.2x%.2x%.2x-%.2x%.2x-%.2x%.2x-%.2x%.2x-%.2x%.2x%.2x%.2x%.2x%.2x\n", filei,
446 uuid_command->uuid[ 0], uuid_command->uuid[ 1], uuid_command->uuid[ 2], uuid_command->uuid[ 3],
447 uuid_command->uuid[ 4], uuid_command->uuid[ 5], uuid_command->uuid[ 6], uuid_command->uuid[ 7],
448 uuid_command->uuid[ 8], uuid_command->uuid[ 9], uuid_command->uuid[10], uuid_command->uuid[11],
449 uuid_command->uuid[12], uuid_command->uuid[13], uuid_command->uuid[14], uuid_command->uuid[15]
450 );
451 }
452 } else if (cmd == LC_ID_DYLIB) {
453 volatile struct dylib_command *dylib_command(reinterpret_cast<struct dylib_command *>(*load_command));
454
455 if (flag_t)
456 printf("time%zu=0x%.8x\n", filei, framework.Swap(dylib_command->dylib.timestamp));
457
458 if (flag_T) {
459 uint32_t timed;
460
461 if (!timeh)
462 timed = timev;
463 else {
464 dylib_command->dylib.timestamp = 0;
465 timed = hash(reinterpret_cast<uint8_t *>(framework.GetBase()), framework.GetSize(), timev);
466 }
467
468 dylib_command->dylib.timestamp = framework.Swap(timed);
469 }
470 }
471 }
472
473 if (flag_s) {
474 _assert(signature != NULL);
475
476 uint32_t data = framework.Swap(signature->dataoff);
477 uint32_t size = framework.Swap(signature->datasize);
478
479 uint8_t *top = reinterpret_cast<uint8_t *>(framework.GetBase());
480 uint8_t *blob = top + data;
481 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
482
483 for (size_t index(0); index != Swap(super->count); ++index)
484 if (Swap(super->index[index].type) == CSSLOT_CODEDIRECTORY) {
485 uint32_t begin = Swap(super->index[index].offset);
486 struct CodeDirectory *directory = reinterpret_cast<struct CodeDirectory *>(blob + begin);
487
488 uint8_t (*hashes)[20] = reinterpret_cast<uint8_t (*)[20]>(blob + begin + Swap(directory->hashOffset));
489 uint32_t pages = Swap(directory->nCodeSlots);
490
491 if (pages != 1)
492 for (size_t i = 0; i != pages - 1; ++i)
493 sha1(hashes[i], top + 0x1000 * i, 0x1000);
494 if (pages != 0)
495 sha1(hashes[pages - 1], top + 0x1000 * (pages - 1), data % 0x1000);
496 }
497 }
498
499 if (flag_S) {
500 _assert(signature != NULL);
501
502 uint32_t data = framework.Swap(signature->dataoff);
503 uint32_t size = framework.Swap(signature->datasize);
504
505 uint8_t *top = reinterpret_cast<uint8_t *>(framework.GetBase());
506 uint8_t *blob = top + data;
507 struct SuperBlob *super = reinterpret_cast<struct SuperBlob *>(blob);
508 super->blob.magic = Swap(CSMAGIC_EMBEDDED_SIGNATURE);
509
510 uint32_t count = xmld == NULL ? 2 : 3;
511 uint32_t offset = sizeof(struct SuperBlob) + count * sizeof(struct BlobIndex);
512
513 super->index[0].type = Swap(CSSLOT_CODEDIRECTORY);
514 super->index[0].offset = Swap(offset);
515
516 uint32_t begin = offset;
517 struct CodeDirectory *directory = reinterpret_cast<struct CodeDirectory *>(blob + begin);
518 offset += sizeof(struct CodeDirectory);
519
520 directory->blob.magic = Swap(CSMAGIC_CODEDIRECTORY);
521 directory->version = Swap(0x00020001);
522 directory->flags = Swap(0);
523 directory->codeLimit = Swap(data);
524 directory->hashSize = 0x14;
525 directory->hashType = 0x01;
526 directory->spare1 = 0x00;
527 directory->pageSize = 0x0c;
528 directory->spare2 = Swap(0);
529
530 directory->identOffset = Swap(offset - begin);
531 strcpy(reinterpret_cast<char *>(blob + offset), base);
532 offset += strlen(base) + 1;
533
534 uint32_t special = xmld == NULL ? CSSLOT_REQUIREMENTS : CSSLOT_ENTITLEMENTS;
535 directory->nSpecialSlots = Swap(special);
536
537 uint8_t (*hashes)[20] = reinterpret_cast<uint8_t (*)[20]>(blob + offset);
538 memset(hashes, 0, sizeof(*hashes) * special);
539
540 offset += sizeof(*hashes) * special;
541 hashes += special;
542
543 uint32_t pages = (data + 0x1000 - 1) / 0x1000;
544 directory->nCodeSlots = Swap(pages);
545
546 if (pages != 1)
547 for (size_t i = 0; i != pages - 1; ++i)
548 sha1(hashes[i], top + 0x1000 * i, 0x1000);
549 if (pages != 0)
550 sha1(hashes[pages - 1], top + 0x1000 * (pages - 1), data % 0x1000);
551
552 directory->hashOffset = Swap(offset - begin);
553 offset += sizeof(*hashes) * pages;
554 directory->blob.length = Swap(offset - begin);
555
556 super->index[1].type = Swap(CSSLOT_REQUIREMENTS);
557 super->index[1].offset = Swap(offset);
558
559 memcpy(blob + offset, "\xfa\xde\x0c\x01\x00\x00\x00\x0c\x00\x00\x00\x00", 0xc);
560 offset += 0xc;
561
562 if (xmld != NULL) {
563 super->index[2].type = Swap(CSSLOT_ENTITLEMENTS);
564 super->index[2].offset = Swap(offset);
565
566 uint32_t begin = offset;
567 struct Blob *entitlements = reinterpret_cast<struct Blob *>(blob + begin);
568 offset += sizeof(struct Blob);
569
570 memcpy(blob + offset, xmld, xmls);
571 offset += xmls;
572
573 entitlements->magic = Swap(CSMAGIC_ENTITLEMENTS);
574 entitlements->length = Swap(offset - begin);
575 }
576
577 for (size_t index(0); index != count; ++index) {
578 uint32_t type = Swap(super->index[index].type);
579 if (type != 0 && type <= special) {
580 uint32_t offset = Swap(super->index[index].offset);
581 struct Blob *local = (struct Blob *) (blob + offset);
582 sha1((uint8_t *) (hashes - type), (uint8_t *) local, Swap(local->length));
583 }
584 }
585
586 super->count = Swap(count);
587 super->blob.length = Swap(offset);
588
589 if (offset > size) {
590 fprintf(stderr, "offset (%zu) > size (%zu)\n", offset, size);
591 _assert(false);
592 } //else fprintf(stderr, "offset (%zu) <= size (%zu)\n", offset, size);
593
594 memset(blob + offset, 0, size - offset);
595 }
596
597 if (temp) {
598 struct stat info;
599 _syscall(stat(path, &info));
600 _syscall(chown(temp, info.st_uid, info.st_gid));
601 _syscall(chmod(temp, info.st_mode));
602 _syscall(unlink(path));
603 _syscall(rename(temp, path));
604 free(temp);
605 }
606
607 free(dir);
608 ++filei;
609 } catch (const char *) {
610 ++filee;
611 ++filei;
612 }
613
614 return filee;
615 }