From 9a8faad50f56d748fcd1498c170797c67bb53217 Mon Sep 17 00:00:00 2001 From: Mark Rowe Date: Wed, 22 Oct 2025 19:52:19 -0700 Subject: [KernelCache] Set segment permissions based on how XNU initially maps them XNU maps kernel cache segments in with different permissions than the load commands indicate. For instance, `__DATA_CONST` is initially mapped as read-write before later being re-mapped as read-only. Treating it as read-only results in analysis falsely assuming that global variables cannot change. To work around this we maintain a mapping from segment name to initial permissions (i.e., most lax permissions) and favor them over permissions derived from the segment load command. Section semantics are also derived from the segment's permissions when the segment is present in the mapping. The mapping is based on the initial permissions established by `arm_vm_prot_init` within the XNU source. --- view/kernelcache/core/Utility.h | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) (limited to 'view/kernelcache/core/Utility.h') diff --git a/view/kernelcache/core/Utility.h b/view/kernelcache/core/Utility.h index 5664fd9b..6d0bf0a0 100644 --- a/view/kernelcache/core/Utility.h +++ b/view/kernelcache/core/Utility.h @@ -25,7 +25,13 @@ inline int CountTrailingZeros(uint64_t value) } #endif -BNSegmentFlag SegmentFlagsFromMachOProtections(int initProt, int maxProt); +namespace BinaryNinja { + struct segment_command_64; + struct section_64; +} + +uint32_t SegmentFlagsForSegment(const BinaryNinja::segment_command_64& segment); +uint32_t SectionSemanticsForSection(const BinaryNinja::section_64& section); int64_t readSLEB128(const uint8_t*& current, const uint8_t* end); -- cgit v1.3.1