1 //===-- asan_interceptors.cc ----------------------------------------------===// 2 // 3 // This file is distributed under the University of Illinois Open Source 4 // License. See LICENSE.TXT for details. 5 // 6 //===----------------------------------------------------------------------===// 7 // 8 // This file is a part of AddressSanitizer, an address sanity checker. 9 // 10 // Interceptors for operators new and delete. 11 //===----------------------------------------------------------------------===// 12 13 #include "asan_allocator.h" 14 #include "asan_internal.h" 15 #include "asan_malloc_local.h" 16 #include "asan_report.h" 17 #include "asan_stack.h" 18 19 #include "interception/interception.h" 20 21 #include <stddef.h> 22 23 // C++ operators can't have dllexport attributes on Windows. We export them 24 // anyway by passing extra -export flags to the linker, which is exactly that 25 // dllexport would normally do. We need to export them in order to make the 26 // VS2015 dynamic CRT (MD) work. 27 #if SANITIZER_WINDOWS && defined(_MSC_VER) 28 #define CXX_OPERATOR_ATTRIBUTE 29 #define COMMENT_EXPORT(sym) __pragma(comment(linker, "/export:" sym)) 30 #ifdef _WIN64 31 COMMENT_EXPORT("??2@YAPEAX_K@Z") // operator new 32 COMMENT_EXPORT("??2@YAPEAX_KAEBUnothrow_t@std@@@Z") // operator new nothrow 33 COMMENT_EXPORT("??3@YAXPEAX@Z") // operator delete 34 COMMENT_EXPORT("??3@YAXPEAX_K@Z") // sized operator delete 35 COMMENT_EXPORT("??_U@YAPEAX_K@Z") // operator new[] 36 COMMENT_EXPORT("??_V@YAXPEAX@Z") // operator delete[] 37 #else 38 COMMENT_EXPORT("??2@YAPAXI@Z") // operator new 39 COMMENT_EXPORT("??2@YAPAXIABUnothrow_t@std@@@Z") // operator new nothrow 40 COMMENT_EXPORT("??3@YAXPAX@Z") // operator delete 41 COMMENT_EXPORT("??3@YAXPAXI@Z") // sized operator delete 42 COMMENT_EXPORT("??_U@YAPAXI@Z") // operator new[] 43 COMMENT_EXPORT("??_V@YAXPAX@Z") // operator delete[] 44 #endif 45 #undef COMMENT_EXPORT 46 #else 47 #define CXX_OPERATOR_ATTRIBUTE INTERCEPTOR_ATTRIBUTE 48 #endif 49 50 using namespace __asan; // NOLINT 51 52 // FreeBSD prior v9.2 have wrong definition of 'size_t'. 53 // http://svnweb.freebsd.org/base?view=revision&revision=232261 54 #if SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32 55 #include <sys/param.h> 56 #if __FreeBSD_version <= 902001 // v9.2 57 #define size_t unsigned 58 #endif // __FreeBSD_version 59 #endif // SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32 60 61 // This code has issues on OSX. 62 // See https://github.com/google/sanitizers/issues/131. 63 64 // Fake std::nothrow_t and std::align_val_t to avoid including <new>. 65 namespace std { 66 struct nothrow_t {}; 67 enum class align_val_t: size_t {}; 68 } // namespace std 69 70 // TODO(alekseyshl): throw std::bad_alloc instead of dying on OOM. 71 // For local pool allocation, align to SHADOW_GRANULARITY to match asan 72 // allocator behavior. 73 #define OPERATOR_NEW_BODY(type, nothrow) \ 74 if (ALLOCATE_FROM_LOCAL_POOL) {\ 75 void *res = MemalignFromLocalPool(SHADOW_GRANULARITY, size);\ 76 if (!nothrow) CHECK(res);\ 77 return res;\ 78 }\ 79 GET_STACK_TRACE_MALLOC;\ 80 void *res = asan_memalign(0, size, &stack, type);\ 81 if (!nothrow && UNLIKELY(!res)) ReportOutOfMemory(size, &stack);\ 82 return res; 83 #define OPERATOR_NEW_BODY_ALIGN(type, nothrow) \ 84 if (ALLOCATE_FROM_LOCAL_POOL) {\ 85 void *res = MemalignFromLocalPool((uptr)align, size);\ 86 if (!nothrow) CHECK(res);\ 87 return res;\ 88 }\ 89 GET_STACK_TRACE_MALLOC;\ 90 void *res = asan_memalign((uptr)align, size, &stack, type);\ 91 if (!nothrow && UNLIKELY(!res)) ReportOutOfMemory(size, &stack);\ 92 return res; 93 94 // On OS X it's not enough to just provide our own 'operator new' and 95 // 'operator delete' implementations, because they're going to be in the 96 // runtime dylib, and the main executable will depend on both the runtime 97 // dylib and libstdc++, each of those'll have its implementation of new and 98 // delete. 99 // To make sure that C++ allocation/deallocation operators are overridden on 100 // OS X we need to intercept them using their mangled names. 101 #if !SANITIZER_MAC 102 CXX_OPERATOR_ATTRIBUTE 103 void *operator new(size_t size) 104 { OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/); } 105 CXX_OPERATOR_ATTRIBUTE 106 void *operator new[](size_t size) 107 { OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/); } 108 CXX_OPERATOR_ATTRIBUTE 109 void *operator new(size_t size, std::nothrow_t const&) 110 { OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/); } 111 CXX_OPERATOR_ATTRIBUTE 112 void *operator new[](size_t size, std::nothrow_t const&) 113 { OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/); } 114 CXX_OPERATOR_ATTRIBUTE 115 void *operator new(size_t size, std::align_val_t align) 116 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, false /*nothrow*/); } 117 CXX_OPERATOR_ATTRIBUTE 118 void *operator new[](size_t size, std::align_val_t align) 119 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, false /*nothrow*/); } 120 CXX_OPERATOR_ATTRIBUTE 121 void *operator new(size_t size, std::align_val_t align, std::nothrow_t const&) 122 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, true /*nothrow*/); } 123 CXX_OPERATOR_ATTRIBUTE 124 void *operator new[](size_t size, std::align_val_t align, std::nothrow_t const&) 125 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, true /*nothrow*/); } 126 127 #else // SANITIZER_MAC 128 INTERCEPTOR(void *, _Znwm, size_t size) { 129 OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/); 130 } 131 INTERCEPTOR(void *, _Znam, size_t size) { 132 OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/); 133 } 134 INTERCEPTOR(void *, _ZnwmRKSt9nothrow_t, size_t size, std::nothrow_t const&) { 135 OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/); 136 } 137 INTERCEPTOR(void *, _ZnamRKSt9nothrow_t, size_t size, std::nothrow_t const&) { 138 OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/); 139 } 140 #endif // !SANITIZER_MAC 141 142 #define OPERATOR_DELETE_BODY(type) \ 143 if (IS_FROM_LOCAL_POOL(ptr)) return;\ 144 GET_STACK_TRACE_FREE;\ 145 asan_delete(ptr, 0, 0, &stack, type); 146 147 #define OPERATOR_DELETE_BODY_SIZE(type) \ 148 if (IS_FROM_LOCAL_POOL(ptr)) return;\ 149 GET_STACK_TRACE_FREE;\ 150 asan_delete(ptr, size, 0, &stack, type); 151 152 #define OPERATOR_DELETE_BODY_ALIGN(type) \ 153 if (IS_FROM_LOCAL_POOL(ptr)) return;\ 154 GET_STACK_TRACE_FREE;\ 155 asan_delete(ptr, 0, static_cast<uptr>(align), &stack, type); 156 157 #define OPERATOR_DELETE_BODY_SIZE_ALIGN(type) \ 158 if (IS_FROM_LOCAL_POOL(ptr)) return;\ 159 GET_STACK_TRACE_FREE;\ 160 asan_delete(ptr, size, static_cast<uptr>(align), &stack, type); 161 162 #if !SANITIZER_MAC 163 CXX_OPERATOR_ATTRIBUTE 164 void operator delete(void *ptr) NOEXCEPT 165 { OPERATOR_DELETE_BODY(FROM_NEW); } 166 CXX_OPERATOR_ATTRIBUTE 167 void operator delete[](void *ptr) NOEXCEPT 168 { OPERATOR_DELETE_BODY(FROM_NEW_BR); } 169 CXX_OPERATOR_ATTRIBUTE 170 void operator delete(void *ptr, std::nothrow_t const&) 171 { OPERATOR_DELETE_BODY(FROM_NEW); } 172 CXX_OPERATOR_ATTRIBUTE 173 void operator delete[](void *ptr, std::nothrow_t const&) 174 { OPERATOR_DELETE_BODY(FROM_NEW_BR); } 175 CXX_OPERATOR_ATTRIBUTE 176 void operator delete(void *ptr, size_t size) NOEXCEPT 177 { OPERATOR_DELETE_BODY_SIZE(FROM_NEW); } 178 CXX_OPERATOR_ATTRIBUTE 179 void operator delete[](void *ptr, size_t size) NOEXCEPT 180 { OPERATOR_DELETE_BODY_SIZE(FROM_NEW_BR); } 181 CXX_OPERATOR_ATTRIBUTE 182 void operator delete(void *ptr, std::align_val_t align) NOEXCEPT 183 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); } 184 CXX_OPERATOR_ATTRIBUTE 185 void operator delete[](void *ptr, std::align_val_t align) NOEXCEPT 186 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); } 187 CXX_OPERATOR_ATTRIBUTE 188 void operator delete(void *ptr, std::align_val_t align, std::nothrow_t const&) 189 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); } 190 CXX_OPERATOR_ATTRIBUTE 191 void operator delete[](void *ptr, std::align_val_t align, std::nothrow_t const&) 192 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); } 193 CXX_OPERATOR_ATTRIBUTE 194 void operator delete(void *ptr, size_t size, std::align_val_t align) NOEXCEPT 195 { OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW); } 196 CXX_OPERATOR_ATTRIBUTE 197 void operator delete[](void *ptr, size_t size, std::align_val_t align) NOEXCEPT 198 { OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW_BR); } 199 200 #else // SANITIZER_MAC 201 INTERCEPTOR(void, _ZdlPv, void *ptr) 202 { OPERATOR_DELETE_BODY(FROM_NEW); } 203 INTERCEPTOR(void, _ZdaPv, void *ptr) 204 { OPERATOR_DELETE_BODY(FROM_NEW_BR); } 205 INTERCEPTOR(void, _ZdlPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&) 206 { OPERATOR_DELETE_BODY(FROM_NEW); } 207 INTERCEPTOR(void, _ZdaPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&) 208 { OPERATOR_DELETE_BODY(FROM_NEW_BR); } 209 #endif // !SANITIZER_MAC 210