1 //===-- asan_interceptors.cpp ---------------------------------------------===//
2 //
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6 //
7 //===----------------------------------------------------------------------===//
8 //
9 // This file is a part of AddressSanitizer, an address sanity checker.
10 //
11 // Interceptors for operators new and delete.
12 //===----------------------------------------------------------------------===//
13
14 #include <stddef.h>
15
16 #include "asan_allocator.h"
17 #include "asan_internal.h"
18 #include "asan_report.h"
19 #include "asan_stack.h"
20 #include "interception/interception.h"
21
22 // C++ operators can't have dllexport attributes on Windows. We export them
23 // anyway by passing extra -export flags to the linker, which is exactly that
24 // dllexport would normally do. We need to export them in order to make the
25 // VS2015 dynamic CRT (MD) work.
26 #if SANITIZER_WINDOWS && defined(_MSC_VER)
27 #define CXX_OPERATOR_ATTRIBUTE
28 #define COMMENT_EXPORT(sym) __pragma(comment(linker, "/export:" sym))
29 #ifdef _WIN64
30 COMMENT_EXPORT("??2@YAPEAX_K@Z") // operator new
31 COMMENT_EXPORT("??2@YAPEAX_KAEBUnothrow_t@std@@@Z") // operator new nothrow
32 COMMENT_EXPORT("??3@YAXPEAX@Z") // operator delete
33 COMMENT_EXPORT("??3@YAXPEAX_K@Z") // sized operator delete
34 COMMENT_EXPORT("??_U@YAPEAX_K@Z") // operator new[]
35 COMMENT_EXPORT("??_V@YAXPEAX@Z") // operator delete[]
36 #else
37 COMMENT_EXPORT("??2@YAPAXI@Z") // operator new
38 COMMENT_EXPORT("??2@YAPAXIABUnothrow_t@std@@@Z") // operator new nothrow
39 COMMENT_EXPORT("??3@YAXPAX@Z") // operator delete
40 COMMENT_EXPORT("??3@YAXPAXI@Z") // sized operator delete
41 COMMENT_EXPORT("??_U@YAPAXI@Z") // operator new[]
42 COMMENT_EXPORT("??_V@YAXPAX@Z") // operator delete[]
43 #endif
44 #undef COMMENT_EXPORT
45 #else
46 #define CXX_OPERATOR_ATTRIBUTE INTERCEPTOR_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
47 #endif
48
49 using namespace __asan;
50
51 // This code has issues on OSX.
52 // See https://github.com/google/sanitizers/issues/131.
53
54 // Fake std::nothrow_t and std::align_val_t to avoid including <new>.
55 namespace std {
56 struct nothrow_t {};
57 enum class align_val_t: size_t {};
58 } // namespace std
59
60 // TODO(alekseyshl): throw std::bad_alloc instead of dying on OOM.
61 // For local pool allocation, align to SHADOW_GRANULARITY to match asan
62 // allocator behavior.
63 #define OPERATOR_NEW_BODY(type, nothrow) \
64 GET_STACK_TRACE_MALLOC; \
65 void *res = asan_memalign(0, size, &stack, type); \
66 if (!nothrow && UNLIKELY(!res)) \
67 ReportOutOfMemory(size, &stack); \
68 return res;
69 #define OPERATOR_NEW_BODY_ALIGN(type, nothrow) \
70 GET_STACK_TRACE_MALLOC; \
71 void *res = asan_memalign((uptr)align, size, &stack, type); \
72 if (!nothrow && UNLIKELY(!res)) \
73 ReportOutOfMemory(size, &stack); \
74 return res;
75
76 // On OS X it's not enough to just provide our own 'operator new' and
77 // 'operator delete' implementations, because they're going to be in the
78 // runtime dylib, and the main executable will depend on both the runtime
79 // dylib and libstdc++, each of those'll have its implementation of new and
80 // delete.
81 // To make sure that C++ allocation/deallocation operators are overridden on
82 // OS X we need to intercept them using their mangled names.
83 #if !SANITIZER_APPLE
84 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size)85 void *operator new(size_t size)
86 { OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/); }
87 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size)88 void *operator new[](size_t size)
89 { OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/); }
90 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size,std::nothrow_t const &)91 void *operator new(size_t size, std::nothrow_t const&)
92 { OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/); }
93 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size,std::nothrow_t const &)94 void *operator new[](size_t size, std::nothrow_t const&)
95 { OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/); }
96 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size,std::align_val_t align)97 void *operator new(size_t size, std::align_val_t align)
98 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, false /*nothrow*/); }
99 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size,std::align_val_t align)100 void *operator new[](size_t size, std::align_val_t align)
101 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, false /*nothrow*/); }
102 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size,std::align_val_t align,std::nothrow_t const &)103 void *operator new(size_t size, std::align_val_t align, std::nothrow_t const&)
104 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, true /*nothrow*/); }
105 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size,std::align_val_t align,std::nothrow_t const &)106 void *operator new[](size_t size, std::align_val_t align, std::nothrow_t const&)
107 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, true /*nothrow*/); }
108
109 #else // SANITIZER_APPLE
INTERCEPTOR(void *,_Znwm,size_t size)110 INTERCEPTOR(void *, _Znwm, size_t size) {
111 OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/);
112 }
INTERCEPTOR(void *,_Znam,size_t size)113 INTERCEPTOR(void *, _Znam, size_t size) {
114 OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/);
115 }
INTERCEPTOR(void *,_ZnwmRKSt9nothrow_t,size_t size,std::nothrow_t const &)116 INTERCEPTOR(void *, _ZnwmRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
117 OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/);
118 }
INTERCEPTOR(void *,_ZnamRKSt9nothrow_t,size_t size,std::nothrow_t const &)119 INTERCEPTOR(void *, _ZnamRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
120 OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/);
121 }
122 #endif // !SANITIZER_APPLE
123
124 #define OPERATOR_DELETE_BODY(type) \
125 GET_STACK_TRACE_FREE; \
126 asan_delete(ptr, 0, 0, &stack, type);
127
128 #define OPERATOR_DELETE_BODY_SIZE(type) \
129 GET_STACK_TRACE_FREE; \
130 asan_delete(ptr, size, 0, &stack, type);
131
132 #define OPERATOR_DELETE_BODY_ALIGN(type) \
133 GET_STACK_TRACE_FREE; \
134 asan_delete(ptr, 0, static_cast<uptr>(align), &stack, type);
135
136 #define OPERATOR_DELETE_BODY_SIZE_ALIGN(type) \
137 GET_STACK_TRACE_FREE; \
138 asan_delete(ptr, size, static_cast<uptr>(align), &stack, type);
139
140 #if !SANITIZER_APPLE
141 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr)142 void operator delete(void *ptr) NOEXCEPT
143 { OPERATOR_DELETE_BODY(FROM_NEW); }
144 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr)145 void operator delete[](void *ptr) NOEXCEPT
146 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
147 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,std::nothrow_t const &)148 void operator delete(void *ptr, std::nothrow_t const&)
149 { OPERATOR_DELETE_BODY(FROM_NEW); }
150 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,std::nothrow_t const &)151 void operator delete[](void *ptr, std::nothrow_t const&)
152 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
153 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,size_t size)154 void operator delete(void *ptr, size_t size) NOEXCEPT
155 { OPERATOR_DELETE_BODY_SIZE(FROM_NEW); }
156 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,size_t size)157 void operator delete[](void *ptr, size_t size) NOEXCEPT
158 { OPERATOR_DELETE_BODY_SIZE(FROM_NEW_BR); }
159 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,std::align_val_t align)160 void operator delete(void *ptr, std::align_val_t align) NOEXCEPT
161 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); }
162 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,std::align_val_t align)163 void operator delete[](void *ptr, std::align_val_t align) NOEXCEPT
164 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); }
165 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,std::align_val_t align,std::nothrow_t const &)166 void operator delete(void *ptr, std::align_val_t align, std::nothrow_t const&)
167 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); }
168 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,std::align_val_t align,std::nothrow_t const &)169 void operator delete[](void *ptr, std::align_val_t align, std::nothrow_t const&)
170 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); }
171 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,size_t size,std::align_val_t align)172 void operator delete(void *ptr, size_t size, std::align_val_t align) NOEXCEPT
173 { OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW); }
174 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,size_t size,std::align_val_t align)175 void operator delete[](void *ptr, size_t size, std::align_val_t align) NOEXCEPT
176 { OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW_BR); }
177
178 #else // SANITIZER_APPLE
INTERCEPTOR(void,_ZdlPv,void * ptr)179 INTERCEPTOR(void, _ZdlPv, void *ptr)
180 { OPERATOR_DELETE_BODY(FROM_NEW); }
INTERCEPTOR(void,_ZdaPv,void * ptr)181 INTERCEPTOR(void, _ZdaPv, void *ptr)
182 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
INTERCEPTOR(void,_ZdlPvRKSt9nothrow_t,void * ptr,std::nothrow_t const &)183 INTERCEPTOR(void, _ZdlPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&)
184 { OPERATOR_DELETE_BODY(FROM_NEW); }
INTERCEPTOR(void,_ZdaPvRKSt9nothrow_t,void * ptr,std::nothrow_t const &)185 INTERCEPTOR(void, _ZdaPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&)
186 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
187 #endif // !SANITIZER_APPLE
188