1 of 18

XNU IPC

CSE 598 – Applied Vulnerability Research

Fall 2024

Adam Doupé�Arizona State University

2 of 18

XNU and POSIX

  • XNU is POSIX-certified compliant
  • This means (among other things) it supports things that you would expect

2

Adam Doupé, CSE 598 Applied Vulnerability Research

3 of 18

POSIX IPC

  • Pipes
    • pipe
  • Message Queues
    • mq_open, mq_send, mq_receive
  • Shared Memory
    • shm_open
  • Semaphores
    • sem_open, sem_post, sem_wait
  • Memory-Mapped files
    • mmap
  • Signals
    • kill, pause
  • Sockets
    • accept, bind, close
  • Fifo

3

Adam Doupé, CSE 598 Applied Vulnerability Research

4 of 18

Mach IPC

  • Directly from the microkernel design goal, efficient message passing mechanism
  • Uni-directional
  • Flexible
    • Inter-process communication
    • Userspace <-> kernel communication
    • Inter-kernel communication
  • Unique functionality

4

Adam Doupé, CSE 598 Applied Vulnerability Research

5 of 18

Mach IPC Concepts

  • ports (no, not TCP/UDP ports)
    • Kernel objects that you can’t touch (similar to file struct)
  • port rights
    • Kernel objects that allow interacting with a port
    • Receive, send, send-once, dead-name
  • port names
    • similar to file fd, int that identifies the port rights within your task (but is meaningless outside)

5

Adam Doupé, CSE 598 Applied Vulnerability Research

6 of 18

Port Rights

  • send
    • Can send messages to the port
    • 0 or more
    • Transitive (can be cloned and sent)
  • send-once
    • Can send one message to the port
    • 0 or more
  • receive
    • Can receive messages sent to the port
    • 1
    • Considered “owner” of the port
  • dead-name
    • Indicates a dead port (receive process dies or is deallocated)

6

Adam Doupé, CSE 598 Applied Vulnerability Research

7 of 18

Passing Port Rights

  • You can pass port rights in a message!
  • When sending a message, you can attach port rights
    • Why would you want to do this?

7

Adam Doupé, CSE 598 Applied Vulnerability Research

8 of 18

Communication

8

Bob

Alice

0. Assume Alice has SEND(B) port right

1. Alice creates a new port, called A

2. Alice sends right SEND(A) to port B using SEND(B)

3. Bob uses RECEIVE(B) right to receive message, and also has SEND(A) right

4. Now what???

Adam Doupé, CSE 598 Applied Vulnerability Research

9 of 18

Communication Issues?

9

Adam Doupé, CSE 598 Applied Vulnerability Research

10 of 18

Bootstrapping

10

Bob

Alice

1. Bob creates port B and has RECEIVE(B) right

3. Alice creates a new port, called A

4. Alice asks bootstrap server for Bob’s port, gets SEND(B)

6. Bob uses RECEIVE(B) right to receive message, and also has SEND(A) right

7. Now what???�How many messages?

2. Bob sends SEND(B) to bootstrap server

5. Alice sends right SEND(A) to port B using SEND(B)

Adam Doupé, CSE 598 Applied Vulnerability Research

11 of 18

Bootstraping Issues?

11

Adam Doupé, CSE 598 Applied Vulnerability Research

12 of 18

Registered Bootstrapping

Bob

Alice

1. Alice creates a new port, called A

2. Alice asks bootstrap server for Bob’s (com.bob) port

9. Bob uses RECEIVE(B) right to receive message, and also has SEND(A) right

4. Bob checks in with bootstrap server

8. Alice sends right SEND(A) to port B using SEND(B)

0. admin says com.bob maps to /bin/bob

3. Bootstrap looks for port for /bin/bob, otherwise runs it, creates B and has RECEIVE(B)

5. Bootstrap keeps SEND(B), sends Bob RECEIVE(B)

6. Bob gets RECEIVE(B) from bootstrap

7. Bootstrap sends SEND(B) to Alice

Adam Doupé, CSE 598 Applied Vulnerability Research

13 of 18

Registered Bootstraping Issues?

13

Adam Doupé, CSE 598 Applied Vulnerability Research

14 of 18

Viewing Ports

  • lsmp (let’s do it!)

14

Adam Doupé, CSE 598 Applied Vulnerability Research

15 of 18

Types of Messages

  • Header
  • Body
  • Trailer (user can’t set)
  • Let’s look at the userspace source
    • mach_msg_descriptor*
    • <mach/message.h>

15

Adam Doupé, CSE 598 Applied Vulnerability Research

16 of 18

Complex Messages

  • Sending port rights
  • Region of memory to share, move, or copy
  • Why might this be useful in exploitation?

16

Adam Doupé, CSE 598 Applied Vulnerability Research

17 of 18

Sending and Receiving Messages

  • mach_msg
  • mach_msg_overwrite
    • Same as mach_msg but can specify a recv buffer (name is weird)
  • Look at headers in <mach/message.h>

17

Adam Doupé, CSE 598 Applied Vulnerability Research

18 of 18

What happens under the hood?

  • Let’s dig into the source!

18

Adam Doupé, CSE 598 Applied Vulnerability Research