1 of 15

XNU IOKit

CSE 598 – Applied Vulnerability Research

Fall 2024

Adam Doupé�Arizona State University

2 of 15

Talking to the Kernel

  • We’ve already seen
    • System Calls
    • Mach Traps
    • Mach IPC (ports)
  • Other ways
    • BSD device drivers
    • IOKit

2

Adam Doupé, CSE 598 Applied Vulnerability Research

3 of 15

BSD Device Drivers

  • Similar to what you’ve already experienced on Linux
  • Different types
    • Character
    • Block
    • Network
  • https://github.com/apple-oss-distributions/SMBClient/tree/main/kernel
  • tty driver

3

Adam Doupé, CSE 598 Applied Vulnerability Research

4 of 15

BSD Device Drivers

  • open
  • ioctl
  • close

4

Adam Doupé, CSE 598 Applied Vulnerability Research

5 of 15

IOKit

  • Introduced in Mac OS X
  • Completely different interaction model for drivers: object-oriented
  • Limited C++
    • No exceptions
    • No multiple inheritance
    • No templates
    • No RTTI

5

Adam Doupé, CSE 598 Applied Vulnerability Research

6 of 15

IOKit.framework

  • Under the hood, everything is done over Mach IPC to IO Master Port
  • IOKit.framework is user-space code to talk to kernel IOKit objects
    • Uses MIG over Mach IPC under the hood

6

Adam Doupé, CSE 598 Applied Vulnerability Research

7 of 15

IORegistry

  • Registry that keeps track of IOKit objects, properties, and relations
  • IORegistryExplorer.app
    • Additional Tools for Xcode
  • ioreg

7

Adam Doupé, CSE 598 Applied Vulnerability Research

8 of 15

IOKit and libkern

  • IOKit relies on libkern for runtime services
  • OSObject
    • OSBoolean
    • OSCollection
    • OSData
    • OSString
  • Look at source…

8

Adam Doupé, CSE 598 Applied Vulnerability Research

9 of 15

IOKit Classes

  • IORegistryEntry
  • IOService
  • IO*MemoryDescriptor
  • IO*MemoryCursor
  • IOWorkLoop
  • IOCommand

9

Adam Doupé, CSE 598 Applied Vulnerability Research

10 of 15

IOService Driver Lifecycle

10

Figure by Jonathan Levin, *OS Internals, Volume II, Kernel Mode

Adam Doupé, CSE 598 Applied Vulnerability Research

11 of 15

Talking to User Space: IOUserClient

  • Let driver communicate with userspace
    • Get/set driver properties
    • Notifications
    • Mapped memory
    • External Traps
    • External Methods
  • IOUserClient is free to support any of these

11

Adam Doupé, CSE 598 Applied Vulnerability Research

12 of 15

IOUserClient Lifecycle

  • From IOKitLib.h
  • IOServiceOpen()
  • Notifications
    • IOConnectSetNotificationPort
  • Map Memory
    • IOConnectMapMemory64
    • IOConnectUnmapMemory64
  • External Traps
    • IOConnectTrap0, IOConnectTrap1,…
  • External Methods
    • IOConnectCallMethod
  • IOServiceClose()

12

Adam Doupé, CSE 598 Applied Vulnerability Research

13 of 15

IOUserClient External Methods

  • IOConnectCallMethod
  • IOUserClient must specify
    • Number of arguments
    • Direction of argument: input/output
    • Type of each argument: scalar or struct

13

Adam Doupé, CSE 598 Applied Vulnerability Research

14 of 15

IOUserClient External Methods

  • Two ways IOUserClient can handle
    • Override ::externalMethod, select method, then call super::externalMethod
    • Override ::getTargetAndMethodForIndex
  • IOUserClient responsible for marshaling data from userspace to driver
    • IOExternalMethodArguments function
      • target
      • reference
      • struct IOExternalMethodArguments

14

Adam Doupé, CSE 598 Applied Vulnerability Research

15 of 15

IOExternalMethodArguments

  • Scalar input/output passed in
    • scalarInput
    • scalarInputCount
  • Structure input/output passed in
    • structureInput
    • structureInputSize
  • Large structure input/output passed in
    • structureInputDescriptor
  • Let’s look at the code!

15

Adam Doupé, CSE 598 Applied Vulnerability Research