Skip to content
Mach trap#-31

svc · mach trap -31

mach_msg_trap

Legacy single-buffer entry point that sends and/or receives a Mach message through the kernel.

Prototype

kern_return_t mach_msg_trap(/* 7 args */);

Returns: kern_return_t

Version history

XNU tagmacOS#
xnu-344macOS 10.2 Jaguar-30
xnu-517macOS 10.3 Panther-30
xnu-792macOS 10.4 Tiger-31
xnu-1228macOS 10.5 Leopard-31
xnu-1456.1.26macOS 10.6 Snow Leopard-31
xnu-1699.24.8macOS 10.7 Lion-31
xnu-2050.18.24macOS 10.8 Mountain Lion-31
xnu-2422.115.4macOS 10.9 Mavericks-31
xnu-2782.40.9macOS 10.10 Yosemite-31
xnu-3247.1.106macOS 10.11 El Capitan-31
xnu-3789.1.32macOS 10.12 Sierra-31
xnu-4570.1.46macOS 10.13 High Sierra-31
xnu-4903.221.2macOS 10.14 Mojave-31
xnu-6153.11.26macOS 10.15 Catalina-31
xnu-7195.50.7.100.1macOS 11.0 Big Sur-31
xnu-8019.41.5macOS 12.0 Monterey-31
xnu-8792.41.9macOS 13.0 Ventura-31
xnu-10002.1.13macOS 14.0 Sonoma-31
xnu-11215.1.10macOS 15.0 Sequoia-31
xnu-11417.101.15macOS 15.4 Sequoia-31
xnu-12377.1.9macOS 26.0 Tahoe-31
xnu-10002.41.9-31
xnu-10002.61.3-31
xnu-10002.81.5-31
xnu-10063.101.15-31
xnu-10063.121.3-31
xnu-10063.141.1-31
xnu-11215.41.3-31
xnu-11215.61.5-31
xnu-11215.81.4-31
xnu-11417.121.6-31
xnu-11417.140.69-31
xnu-1228.0.2-31
xnu-1228.12.14-31
xnu-1228.15.4-31
xnu-1228.3.13-31
xnu-1228.5.18-31
xnu-1228.5.20-31
xnu-1228.7.58-31
xnu-1228.9.59-31
xnu-12377.101.15-31
xnu-12377.41.6-31
xnu-12377.61.12-31
xnu-12377.81.4-31
xnu-1486.2.11-31
xnu-1504.15.3-31
xnu-1504.3.12-31
xnu-1504.7.4-31
xnu-1504.9.17-31
xnu-1504.9.26-31
xnu-1504.9.37-31
xnu-1699.22.73-31
xnu-1699.22.81-31
xnu-1699.24.23-31
xnu-1699.26.8-31
xnu-1699.32.7-31
xnu-2050.22.13-31
xnu-2050.24.15-31
xnu-2050.48.11-31
xnu-2050.7.9-31
xnu-2050.9.2-31
xnu-2422.1.72-31
xnu-2422.100.13-31
xnu-2422.110.17-31
xnu-2422.90.20-31
xnu-2782.1.97-31
xnu-2782.10.72-31
xnu-2782.20.48-31
xnu-2782.30.5-31
xnu-3247.10.11-31
xnu-3248.20.55-31
xnu-3248.30.4-31
xnu-3248.40.184-31
xnu-3248.50.21-31
xnu-3248.60.10-31
xnu-344.12.2-30
xnu-344.2-30
xnu-344.21.73-30
xnu-344.21.74-30
xnu-344.23-30
xnu-344.26-30
xnu-344.32-30
xnu-344.34-30
xnu-344.49-30
xnu-3789.21.4-31
xnu-3789.31.2-31
xnu-3789.41.3-31
xnu-3789.51.2-31
xnu-3789.60.24-31
xnu-3789.70.16-31
xnu-4570.20.62-31
xnu-4570.31.3-31
xnu-4570.41.2-31
xnu-4570.51.1-31
xnu-4570.61.1-31
xnu-4570.71.2-31
xnu-4903.231.4-31
xnu-4903.241.1-31
xnu-4903.270.47-31
xnu-517.11.1-30
xnu-517.12.7-30
xnu-517.3.15-30
xnu-517.3.7-30
xnu-517.7.21-30
xnu-517.7.7-30
xnu-517.9.4-30
xnu-517.9.5-30
xnu-6153.101.6-31
xnu-6153.121.1-31
xnu-6153.141.1-31
xnu-6153.41.3-31
xnu-6153.61.1-31
xnu-6153.81.5-31
xnu-7195.101.1-31
xnu-7195.121.3-31
xnu-7195.141.2-31
xnu-7195.60.75-31
xnu-7195.81.3-31
xnu-792.1.5-31
xnu-792.10.96-31
xnu-792.12.6-31
xnu-792.13.8-31
xnu-792.17.14-31
xnu-792.18.15-31
xnu-792.2.4-31
xnu-792.21.3-31
xnu-792.22.5-31
xnu-792.24.17-31
xnu-792.25.20-31
xnu-792.6.22-31
xnu-792.6.56-31
xnu-792.6.61-31
xnu-792.6.70-31
xnu-792.6.76-31
xnu-8019.61.5-31
xnu-8019.80.24-31
xnu-8020.101.4-31
xnu-8020.121.3-31
xnu-8020.140.41-31
xnu-8792.61.2-31
xnu-8792.81.2-31
xnu-8796.101.5-31
xnu-8796.121.2-31
xnu-8796.141.3-31

Examples

C — send-then-receive RPC pattern

mach_msg_header_t *hdr = (mach_msg_header_t *)buf;
hdr->msgh_bits = MACH_MSGH_BITS(MACH_MSG_TYPE_COPY_SEND,
                                MACH_MSG_TYPE_MAKE_SEND_ONCE);
hdr->msgh_remote_port = remote;
hdr->msgh_local_port  = mach_reply_port();
hdr->msgh_size = sizeof(*hdr);
hdr->msgh_id   = 1000;

kern_return_t kr = mach_msg(hdr,
    MACH_SEND_MSG | MACH_RCV_MSG,
    hdr->msgh_size, sizeof(buf),
    hdr->msgh_local_port, MACH_MSG_TIMEOUT_NONE, MACH_PORT_NULL);

Notes

mach_msg_trap is the original Mach IPC primitive: a single mach_msg_header_t-prefixed buffer is handed to the kernel, which copies it to the destination port's queue and optionally blocks waiting for a reply on a receive right. The MACH_SEND_MSG / MACH_RCV_MSG option bits select send, receive, or the combined send-then-receive RPC pattern used by MIG stubs. On macOS 12+ the libsyscall shim normally routes through mach_msg2_trap, which packs the descriptor metadata into registers; mach_msg_trap remains available for older binaries and direct callers. Almost every userspace-to-userspace and userspace-to-kernel call on macOS — POSIX, BSD shims aside — ultimately bottoms out here.

Detection

Mach IPC is opaque to Endpoint Security — there is no ES event for arbitrary mach_msg traffic. The DTrace mach_trap provider (mach_trap::mach_msg:entry) is the practical observation point, along with kdebug DBG_MACH_IPC traces and the lldb 'log enable lldb mach-ipc' family. Volume is extreme (millions per second on a busy system), so meaningful detection requires filtering on destination port name or message ID.

Related APIs

mach_msg2_trapmach_msg_overwrite_trapmach_reply_portmach_port_allocatemig_get_reply_port