13cab2bb3Spatrick //===-- asan_rtl.cpp ------------------------------------------------------===//
23cab2bb3Spatrick //
33cab2bb3Spatrick // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
43cab2bb3Spatrick // See https://llvm.org/LICENSE.txt for license information.
53cab2bb3Spatrick // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
63cab2bb3Spatrick //
73cab2bb3Spatrick //===----------------------------------------------------------------------===//
83cab2bb3Spatrick //
93cab2bb3Spatrick // This file is a part of AddressSanitizer, an address sanity checker.
103cab2bb3Spatrick //
113cab2bb3Spatrick // Main file of the ASan run-time library.
123cab2bb3Spatrick //===----------------------------------------------------------------------===//
133cab2bb3Spatrick
143cab2bb3Spatrick #include "asan_activation.h"
153cab2bb3Spatrick #include "asan_allocator.h"
16d89ec533Spatrick #include "asan_fake_stack.h"
173cab2bb3Spatrick #include "asan_interceptors.h"
183cab2bb3Spatrick #include "asan_interface_internal.h"
193cab2bb3Spatrick #include "asan_internal.h"
203cab2bb3Spatrick #include "asan_mapping.h"
213cab2bb3Spatrick #include "asan_poisoning.h"
223cab2bb3Spatrick #include "asan_report.h"
233cab2bb3Spatrick #include "asan_stack.h"
243cab2bb3Spatrick #include "asan_stats.h"
253cab2bb3Spatrick #include "asan_suppressions.h"
263cab2bb3Spatrick #include "asan_thread.h"
27d89ec533Spatrick #include "lsan/lsan_common.h"
283cab2bb3Spatrick #include "sanitizer_common/sanitizer_atomic.h"
293cab2bb3Spatrick #include "sanitizer_common/sanitizer_flags.h"
30*810390e3Srobert #include "sanitizer_common/sanitizer_interface_internal.h"
313cab2bb3Spatrick #include "sanitizer_common/sanitizer_libc.h"
323cab2bb3Spatrick #include "sanitizer_common/sanitizer_symbolizer.h"
333cab2bb3Spatrick #include "ubsan/ubsan_init.h"
343cab2bb3Spatrick #include "ubsan/ubsan_platform.h"
353cab2bb3Spatrick
363cab2bb3Spatrick uptr __asan_shadow_memory_dynamic_address; // Global interface symbol.
373cab2bb3Spatrick int __asan_option_detect_stack_use_after_return; // Global interface symbol.
383cab2bb3Spatrick uptr *__asan_test_only_reported_buggy_pointer; // Used only for testing asan.
393cab2bb3Spatrick
403cab2bb3Spatrick namespace __asan {
413cab2bb3Spatrick
423cab2bb3Spatrick uptr AsanMappingProfile[kAsanMappingProfileSize];
433cab2bb3Spatrick
AsanDie()443cab2bb3Spatrick static void AsanDie() {
453cab2bb3Spatrick static atomic_uint32_t num_calls;
463cab2bb3Spatrick if (atomic_fetch_add(&num_calls, 1, memory_order_relaxed) != 0) {
473cab2bb3Spatrick // Don't die twice - run a busy loop.
48*810390e3Srobert while (1) {
49*810390e3Srobert internal_sched_yield();
50*810390e3Srobert }
513cab2bb3Spatrick }
52d89ec533Spatrick if (common_flags()->print_module_map >= 1)
53d89ec533Spatrick DumpProcessMap();
54*810390e3Srobert
55*810390e3Srobert WaitForDebugger(flags()->sleep_before_dying, "before dying");
56*810390e3Srobert
573cab2bb3Spatrick if (flags()->unmap_shadow_on_exit) {
583cab2bb3Spatrick if (kMidMemBeg) {
593cab2bb3Spatrick UnmapOrDie((void*)kLowShadowBeg, kMidMemBeg - kLowShadowBeg);
603cab2bb3Spatrick UnmapOrDie((void*)kMidMemEnd, kHighShadowEnd - kMidMemEnd);
613cab2bb3Spatrick } else {
623cab2bb3Spatrick if (kHighShadowEnd)
633cab2bb3Spatrick UnmapOrDie((void*)kLowShadowBeg, kHighShadowEnd - kLowShadowBeg);
643cab2bb3Spatrick }
653cab2bb3Spatrick }
663cab2bb3Spatrick }
673cab2bb3Spatrick
CheckUnwind()68d89ec533Spatrick static void CheckUnwind() {
69d89ec533Spatrick GET_STACK_TRACE(kStackTraceMax, common_flags()->fast_unwind_on_check);
70d89ec533Spatrick stack.Print();
713cab2bb3Spatrick }
723cab2bb3Spatrick
733cab2bb3Spatrick // -------------------------- Globals --------------------- {{{1
743cab2bb3Spatrick int asan_inited;
753cab2bb3Spatrick bool asan_init_is_running;
76*810390e3Srobert bool replace_intrin_cached;
773cab2bb3Spatrick
783cab2bb3Spatrick #if !ASAN_FIXED_MAPPING
793cab2bb3Spatrick uptr kHighMemEnd, kMidMemBeg, kMidMemEnd;
803cab2bb3Spatrick #endif
813cab2bb3Spatrick
823cab2bb3Spatrick // -------------------------- Misc ---------------- {{{1
ShowStatsAndAbort()833cab2bb3Spatrick void ShowStatsAndAbort() {
843cab2bb3Spatrick __asan_print_accumulated_stats();
853cab2bb3Spatrick Die();
863cab2bb3Spatrick }
873cab2bb3Spatrick
88d89ec533Spatrick NOINLINE
ReportGenericErrorWrapper(uptr addr,bool is_write,int size,int exp_arg,bool fatal)89d89ec533Spatrick static void ReportGenericErrorWrapper(uptr addr, bool is_write, int size,
90d89ec533Spatrick int exp_arg, bool fatal) {
91d89ec533Spatrick GET_CALLER_PC_BP_SP;
92d89ec533Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, exp_arg, fatal);
93d89ec533Spatrick }
94d89ec533Spatrick
953cab2bb3Spatrick // --------------- LowLevelAllocateCallbac ---------- {{{1
OnLowLevelAllocate(uptr ptr,uptr size)963cab2bb3Spatrick static void OnLowLevelAllocate(uptr ptr, uptr size) {
973cab2bb3Spatrick PoisonShadow(ptr, size, kAsanInternalHeapMagic);
983cab2bb3Spatrick }
993cab2bb3Spatrick
1003cab2bb3Spatrick // -------------------------- Run-time entry ------------------- {{{1
1013cab2bb3Spatrick // exported functions
1023cab2bb3Spatrick #define ASAN_REPORT_ERROR(type, is_write, size) \
1033cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1043cab2bb3Spatrick void __asan_report_ ## type ## size(uptr addr) { \
1053cab2bb3Spatrick GET_CALLER_PC_BP_SP; \
1063cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, 0, true); \
1073cab2bb3Spatrick } \
1083cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1093cab2bb3Spatrick void __asan_report_exp_ ## type ## size(uptr addr, u32 exp) { \
1103cab2bb3Spatrick GET_CALLER_PC_BP_SP; \
1113cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, exp, true); \
1123cab2bb3Spatrick } \
1133cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1143cab2bb3Spatrick void __asan_report_ ## type ## size ## _noabort(uptr addr) { \
1153cab2bb3Spatrick GET_CALLER_PC_BP_SP; \
1163cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, 0, false); \
1173cab2bb3Spatrick } \
1183cab2bb3Spatrick
1193cab2bb3Spatrick ASAN_REPORT_ERROR(load, false, 1)
1203cab2bb3Spatrick ASAN_REPORT_ERROR(load, false, 2)
1213cab2bb3Spatrick ASAN_REPORT_ERROR(load, false, 4)
1223cab2bb3Spatrick ASAN_REPORT_ERROR(load, false, 8)
1233cab2bb3Spatrick ASAN_REPORT_ERROR(load, false, 16)
1243cab2bb3Spatrick ASAN_REPORT_ERROR(store, true, 1)
1253cab2bb3Spatrick ASAN_REPORT_ERROR(store, true, 2)
1263cab2bb3Spatrick ASAN_REPORT_ERROR(store, true, 4)
1273cab2bb3Spatrick ASAN_REPORT_ERROR(store, true, 8)
1283cab2bb3Spatrick ASAN_REPORT_ERROR(store, true, 16)
1293cab2bb3Spatrick
1303cab2bb3Spatrick #define ASAN_REPORT_ERROR_N(type, is_write) \
1313cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1323cab2bb3Spatrick void __asan_report_ ## type ## _n(uptr addr, uptr size) { \
1333cab2bb3Spatrick GET_CALLER_PC_BP_SP; \
1343cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, 0, true); \
1353cab2bb3Spatrick } \
1363cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1373cab2bb3Spatrick void __asan_report_exp_ ## type ## _n(uptr addr, uptr size, u32 exp) { \
1383cab2bb3Spatrick GET_CALLER_PC_BP_SP; \
1393cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, exp, true); \
1403cab2bb3Spatrick } \
1413cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1423cab2bb3Spatrick void __asan_report_ ## type ## _n_noabort(uptr addr, uptr size) { \
1433cab2bb3Spatrick GET_CALLER_PC_BP_SP; \
1443cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, is_write, size, 0, false); \
1453cab2bb3Spatrick } \
1463cab2bb3Spatrick
ASAN_REPORT_ERROR_N(load,false)1473cab2bb3Spatrick ASAN_REPORT_ERROR_N(load, false)
1483cab2bb3Spatrick ASAN_REPORT_ERROR_N(store, true)
1493cab2bb3Spatrick
1503cab2bb3Spatrick #define ASAN_MEMORY_ACCESS_CALLBACK_BODY(type, is_write, size, exp_arg, fatal) \
1513cab2bb3Spatrick uptr sp = MEM_TO_SHADOW(addr); \
152*810390e3Srobert uptr s = size <= ASAN_SHADOW_GRANULARITY ? *reinterpret_cast<u8 *>(sp) \
1533cab2bb3Spatrick : *reinterpret_cast<u16 *>(sp); \
1543cab2bb3Spatrick if (UNLIKELY(s)) { \
155*810390e3Srobert if (UNLIKELY(size >= ASAN_SHADOW_GRANULARITY || \
156*810390e3Srobert ((s8)((addr & (ASAN_SHADOW_GRANULARITY - 1)) + size - 1)) >= \
1573cab2bb3Spatrick (s8)s)) { \
158d89ec533Spatrick ReportGenericErrorWrapper(addr, is_write, size, exp_arg, fatal); \
1593cab2bb3Spatrick } \
1603cab2bb3Spatrick }
1613cab2bb3Spatrick
1623cab2bb3Spatrick #define ASAN_MEMORY_ACCESS_CALLBACK(type, is_write, size) \
1633cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1643cab2bb3Spatrick void __asan_##type##size(uptr addr) { \
1653cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK_BODY(type, is_write, size, 0, true) \
1663cab2bb3Spatrick } \
1673cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1683cab2bb3Spatrick void __asan_exp_##type##size(uptr addr, u32 exp) { \
1693cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK_BODY(type, is_write, size, exp, true) \
1703cab2bb3Spatrick } \
1713cab2bb3Spatrick extern "C" NOINLINE INTERFACE_ATTRIBUTE \
1723cab2bb3Spatrick void __asan_##type##size ## _noabort(uptr addr) { \
1733cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK_BODY(type, is_write, size, 0, false) \
1743cab2bb3Spatrick } \
1753cab2bb3Spatrick
1763cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(load, false, 1)
1773cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(load, false, 2)
1783cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(load, false, 4)
1793cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(load, false, 8)
1803cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(load, false, 16)
1813cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(store, true, 1)
1823cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(store, true, 2)
1833cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(store, true, 4)
1843cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(store, true, 8)
1853cab2bb3Spatrick ASAN_MEMORY_ACCESS_CALLBACK(store, true, 16)
1863cab2bb3Spatrick
1873cab2bb3Spatrick extern "C"
1883cab2bb3Spatrick NOINLINE INTERFACE_ATTRIBUTE
1893cab2bb3Spatrick void __asan_loadN(uptr addr, uptr size) {
190*810390e3Srobert if ((addr = __asan_region_is_poisoned(addr, size))) {
1913cab2bb3Spatrick GET_CALLER_PC_BP_SP;
1923cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, false, size, 0, true);
1933cab2bb3Spatrick }
1943cab2bb3Spatrick }
1953cab2bb3Spatrick
1963cab2bb3Spatrick extern "C"
1973cab2bb3Spatrick NOINLINE INTERFACE_ATTRIBUTE
__asan_exp_loadN(uptr addr,uptr size,u32 exp)1983cab2bb3Spatrick void __asan_exp_loadN(uptr addr, uptr size, u32 exp) {
199*810390e3Srobert if ((addr = __asan_region_is_poisoned(addr, size))) {
2003cab2bb3Spatrick GET_CALLER_PC_BP_SP;
2013cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, false, size, exp, true);
2023cab2bb3Spatrick }
2033cab2bb3Spatrick }
2043cab2bb3Spatrick
2053cab2bb3Spatrick extern "C"
2063cab2bb3Spatrick NOINLINE INTERFACE_ATTRIBUTE
__asan_loadN_noabort(uptr addr,uptr size)2073cab2bb3Spatrick void __asan_loadN_noabort(uptr addr, uptr size) {
208*810390e3Srobert if ((addr = __asan_region_is_poisoned(addr, size))) {
2093cab2bb3Spatrick GET_CALLER_PC_BP_SP;
2103cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, false, size, 0, false);
2113cab2bb3Spatrick }
2123cab2bb3Spatrick }
2133cab2bb3Spatrick
2143cab2bb3Spatrick extern "C"
2153cab2bb3Spatrick NOINLINE INTERFACE_ATTRIBUTE
__asan_storeN(uptr addr,uptr size)2163cab2bb3Spatrick void __asan_storeN(uptr addr, uptr size) {
217*810390e3Srobert if ((addr = __asan_region_is_poisoned(addr, size))) {
2183cab2bb3Spatrick GET_CALLER_PC_BP_SP;
2193cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, true, size, 0, true);
2203cab2bb3Spatrick }
2213cab2bb3Spatrick }
2223cab2bb3Spatrick
2233cab2bb3Spatrick extern "C"
2243cab2bb3Spatrick NOINLINE INTERFACE_ATTRIBUTE
__asan_exp_storeN(uptr addr,uptr size,u32 exp)2253cab2bb3Spatrick void __asan_exp_storeN(uptr addr, uptr size, u32 exp) {
226*810390e3Srobert if ((addr = __asan_region_is_poisoned(addr, size))) {
2273cab2bb3Spatrick GET_CALLER_PC_BP_SP;
2283cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, true, size, exp, true);
2293cab2bb3Spatrick }
2303cab2bb3Spatrick }
2313cab2bb3Spatrick
2323cab2bb3Spatrick extern "C"
2333cab2bb3Spatrick NOINLINE INTERFACE_ATTRIBUTE
__asan_storeN_noabort(uptr addr,uptr size)2343cab2bb3Spatrick void __asan_storeN_noabort(uptr addr, uptr size) {
235*810390e3Srobert if ((addr = __asan_region_is_poisoned(addr, size))) {
2363cab2bb3Spatrick GET_CALLER_PC_BP_SP;
2373cab2bb3Spatrick ReportGenericError(pc, bp, sp, addr, true, size, 0, false);
2383cab2bb3Spatrick }
2393cab2bb3Spatrick }
2403cab2bb3Spatrick
2413cab2bb3Spatrick // Force the linker to keep the symbols for various ASan interface functions.
2423cab2bb3Spatrick // We want to keep those in the executable in order to let the instrumented
2433cab2bb3Spatrick // dynamic libraries access the symbol even if it is not used by the executable
2443cab2bb3Spatrick // itself. This should help if the build system is removing dead code at link
2453cab2bb3Spatrick // time.
force_interface_symbols()2463cab2bb3Spatrick static NOINLINE void force_interface_symbols() {
2473cab2bb3Spatrick volatile int fake_condition = 0; // prevent dead condition elimination.
2483cab2bb3Spatrick // __asan_report_* functions are noreturn, so we need a switch to prevent
2493cab2bb3Spatrick // the compiler from removing any of them.
2503cab2bb3Spatrick // clang-format off
2513cab2bb3Spatrick switch (fake_condition) {
2523cab2bb3Spatrick case 1: __asan_report_load1(0); break;
2533cab2bb3Spatrick case 2: __asan_report_load2(0); break;
2543cab2bb3Spatrick case 3: __asan_report_load4(0); break;
2553cab2bb3Spatrick case 4: __asan_report_load8(0); break;
2563cab2bb3Spatrick case 5: __asan_report_load16(0); break;
2573cab2bb3Spatrick case 6: __asan_report_load_n(0, 0); break;
2583cab2bb3Spatrick case 7: __asan_report_store1(0); break;
2593cab2bb3Spatrick case 8: __asan_report_store2(0); break;
2603cab2bb3Spatrick case 9: __asan_report_store4(0); break;
2613cab2bb3Spatrick case 10: __asan_report_store8(0); break;
2623cab2bb3Spatrick case 11: __asan_report_store16(0); break;
2633cab2bb3Spatrick case 12: __asan_report_store_n(0, 0); break;
2643cab2bb3Spatrick case 13: __asan_report_exp_load1(0, 0); break;
2653cab2bb3Spatrick case 14: __asan_report_exp_load2(0, 0); break;
2663cab2bb3Spatrick case 15: __asan_report_exp_load4(0, 0); break;
2673cab2bb3Spatrick case 16: __asan_report_exp_load8(0, 0); break;
2683cab2bb3Spatrick case 17: __asan_report_exp_load16(0, 0); break;
2693cab2bb3Spatrick case 18: __asan_report_exp_load_n(0, 0, 0); break;
2703cab2bb3Spatrick case 19: __asan_report_exp_store1(0, 0); break;
2713cab2bb3Spatrick case 20: __asan_report_exp_store2(0, 0); break;
2723cab2bb3Spatrick case 21: __asan_report_exp_store4(0, 0); break;
2733cab2bb3Spatrick case 22: __asan_report_exp_store8(0, 0); break;
2743cab2bb3Spatrick case 23: __asan_report_exp_store16(0, 0); break;
2753cab2bb3Spatrick case 24: __asan_report_exp_store_n(0, 0, 0); break;
2763cab2bb3Spatrick case 25: __asan_register_globals(nullptr, 0); break;
2773cab2bb3Spatrick case 26: __asan_unregister_globals(nullptr, 0); break;
2783cab2bb3Spatrick case 27: __asan_set_death_callback(nullptr); break;
2793cab2bb3Spatrick case 28: __asan_set_error_report_callback(nullptr); break;
2803cab2bb3Spatrick case 29: __asan_handle_no_return(); break;
2813cab2bb3Spatrick case 30: __asan_address_is_poisoned(nullptr); break;
2823cab2bb3Spatrick case 31: __asan_poison_memory_region(nullptr, 0); break;
2833cab2bb3Spatrick case 32: __asan_unpoison_memory_region(nullptr, 0); break;
2843cab2bb3Spatrick case 34: __asan_before_dynamic_init(nullptr); break;
2853cab2bb3Spatrick case 35: __asan_after_dynamic_init(); break;
2863cab2bb3Spatrick case 36: __asan_poison_stack_memory(0, 0); break;
2873cab2bb3Spatrick case 37: __asan_unpoison_stack_memory(0, 0); break;
2883cab2bb3Spatrick case 38: __asan_region_is_poisoned(0, 0); break;
2893cab2bb3Spatrick case 39: __asan_describe_address(0); break;
2903cab2bb3Spatrick case 40: __asan_set_shadow_00(0, 0); break;
291*810390e3Srobert case 41: __asan_set_shadow_01(0, 0); break;
292*810390e3Srobert case 42: __asan_set_shadow_02(0, 0); break;
293*810390e3Srobert case 43: __asan_set_shadow_03(0, 0); break;
294*810390e3Srobert case 44: __asan_set_shadow_04(0, 0); break;
295*810390e3Srobert case 45: __asan_set_shadow_05(0, 0); break;
296*810390e3Srobert case 46: __asan_set_shadow_06(0, 0); break;
297*810390e3Srobert case 47: __asan_set_shadow_07(0, 0); break;
298*810390e3Srobert case 48: __asan_set_shadow_f1(0, 0); break;
299*810390e3Srobert case 49: __asan_set_shadow_f2(0, 0); break;
300*810390e3Srobert case 50: __asan_set_shadow_f3(0, 0); break;
301*810390e3Srobert case 51: __asan_set_shadow_f5(0, 0); break;
302*810390e3Srobert case 52: __asan_set_shadow_f8(0, 0); break;
3033cab2bb3Spatrick }
3043cab2bb3Spatrick // clang-format on
3053cab2bb3Spatrick }
3063cab2bb3Spatrick
asan_atexit()3073cab2bb3Spatrick static void asan_atexit() {
3083cab2bb3Spatrick Printf("AddressSanitizer exit stats:\n");
3093cab2bb3Spatrick __asan_print_accumulated_stats();
3103cab2bb3Spatrick // Print AsanMappingProfile.
3113cab2bb3Spatrick for (uptr i = 0; i < kAsanMappingProfileSize; i++) {
3123cab2bb3Spatrick if (AsanMappingProfile[i] == 0) continue;
3133cab2bb3Spatrick Printf("asan_mapping.h:%zd -- %zd\n", i, AsanMappingProfile[i]);
3143cab2bb3Spatrick }
3153cab2bb3Spatrick }
3163cab2bb3Spatrick
InitializeHighMemEnd()3173cab2bb3Spatrick static void InitializeHighMemEnd() {
3183cab2bb3Spatrick #if !ASAN_FIXED_MAPPING
3193cab2bb3Spatrick kHighMemEnd = GetMaxUserVirtualAddress();
3203cab2bb3Spatrick // Increase kHighMemEnd to make sure it's properly
3213cab2bb3Spatrick // aligned together with kHighMemBeg:
322*810390e3Srobert kHighMemEnd |= (GetMmapGranularity() << ASAN_SHADOW_SCALE) - 1;
3233cab2bb3Spatrick #endif // !ASAN_FIXED_MAPPING
3243cab2bb3Spatrick CHECK_EQ((kHighMemBeg % GetMmapGranularity()), 0);
3253cab2bb3Spatrick }
3263cab2bb3Spatrick
PrintAddressSpaceLayout()3273cab2bb3Spatrick void PrintAddressSpaceLayout() {
3283cab2bb3Spatrick if (kHighMemBeg) {
3293cab2bb3Spatrick Printf("|| `[%p, %p]` || HighMem ||\n",
3303cab2bb3Spatrick (void*)kHighMemBeg, (void*)kHighMemEnd);
3313cab2bb3Spatrick Printf("|| `[%p, %p]` || HighShadow ||\n",
3323cab2bb3Spatrick (void*)kHighShadowBeg, (void*)kHighShadowEnd);
3333cab2bb3Spatrick }
3343cab2bb3Spatrick if (kMidMemBeg) {
3353cab2bb3Spatrick Printf("|| `[%p, %p]` || ShadowGap3 ||\n",
3363cab2bb3Spatrick (void*)kShadowGap3Beg, (void*)kShadowGap3End);
3373cab2bb3Spatrick Printf("|| `[%p, %p]` || MidMem ||\n",
3383cab2bb3Spatrick (void*)kMidMemBeg, (void*)kMidMemEnd);
3393cab2bb3Spatrick Printf("|| `[%p, %p]` || ShadowGap2 ||\n",
3403cab2bb3Spatrick (void*)kShadowGap2Beg, (void*)kShadowGap2End);
3413cab2bb3Spatrick Printf("|| `[%p, %p]` || MidShadow ||\n",
3423cab2bb3Spatrick (void*)kMidShadowBeg, (void*)kMidShadowEnd);
3433cab2bb3Spatrick }
3443cab2bb3Spatrick Printf("|| `[%p, %p]` || ShadowGap ||\n",
3453cab2bb3Spatrick (void*)kShadowGapBeg, (void*)kShadowGapEnd);
3463cab2bb3Spatrick if (kLowShadowBeg) {
3473cab2bb3Spatrick Printf("|| `[%p, %p]` || LowShadow ||\n",
3483cab2bb3Spatrick (void*)kLowShadowBeg, (void*)kLowShadowEnd);
3493cab2bb3Spatrick Printf("|| `[%p, %p]` || LowMem ||\n",
3503cab2bb3Spatrick (void*)kLowMemBeg, (void*)kLowMemEnd);
3513cab2bb3Spatrick }
3523cab2bb3Spatrick Printf("MemToShadow(shadow): %p %p",
3533cab2bb3Spatrick (void*)MEM_TO_SHADOW(kLowShadowBeg),
3543cab2bb3Spatrick (void*)MEM_TO_SHADOW(kLowShadowEnd));
3553cab2bb3Spatrick if (kHighMemBeg) {
3563cab2bb3Spatrick Printf(" %p %p",
3573cab2bb3Spatrick (void*)MEM_TO_SHADOW(kHighShadowBeg),
3583cab2bb3Spatrick (void*)MEM_TO_SHADOW(kHighShadowEnd));
3593cab2bb3Spatrick }
3603cab2bb3Spatrick if (kMidMemBeg) {
3613cab2bb3Spatrick Printf(" %p %p",
3623cab2bb3Spatrick (void*)MEM_TO_SHADOW(kMidShadowBeg),
3633cab2bb3Spatrick (void*)MEM_TO_SHADOW(kMidShadowEnd));
3643cab2bb3Spatrick }
3653cab2bb3Spatrick Printf("\n");
3663cab2bb3Spatrick Printf("redzone=%zu\n", (uptr)flags()->redzone);
3673cab2bb3Spatrick Printf("max_redzone=%zu\n", (uptr)flags()->max_redzone);
3683cab2bb3Spatrick Printf("quarantine_size_mb=%zuM\n", (uptr)flags()->quarantine_size_mb);
3693cab2bb3Spatrick Printf("thread_local_quarantine_size_kb=%zuK\n",
3703cab2bb3Spatrick (uptr)flags()->thread_local_quarantine_size_kb);
3713cab2bb3Spatrick Printf("malloc_context_size=%zu\n",
3723cab2bb3Spatrick (uptr)common_flags()->malloc_context_size);
3733cab2bb3Spatrick
374*810390e3Srobert Printf("SHADOW_SCALE: %d\n", (int)ASAN_SHADOW_SCALE);
375*810390e3Srobert Printf("SHADOW_GRANULARITY: %d\n", (int)ASAN_SHADOW_GRANULARITY);
376*810390e3Srobert Printf("SHADOW_OFFSET: 0x%zx\n", (uptr)ASAN_SHADOW_OFFSET);
377*810390e3Srobert CHECK(ASAN_SHADOW_SCALE >= 3 && ASAN_SHADOW_SCALE <= 7);
3783cab2bb3Spatrick if (kMidMemBeg)
3793cab2bb3Spatrick CHECK(kMidShadowBeg > kLowShadowEnd &&
3803cab2bb3Spatrick kMidMemBeg > kMidShadowEnd &&
3813cab2bb3Spatrick kHighShadowBeg > kMidMemEnd);
3823cab2bb3Spatrick }
3833cab2bb3Spatrick
AsanInitInternal()3843cab2bb3Spatrick static void AsanInitInternal() {
3853cab2bb3Spatrick if (LIKELY(asan_inited)) return;
3863cab2bb3Spatrick SanitizerToolName = "AddressSanitizer";
3873cab2bb3Spatrick CHECK(!asan_init_is_running && "ASan init calls itself!");
3883cab2bb3Spatrick asan_init_is_running = true;
3893cab2bb3Spatrick
3903cab2bb3Spatrick CacheBinaryName();
3913cab2bb3Spatrick
3923cab2bb3Spatrick // Initialize flags. This must be done early, because most of the
3933cab2bb3Spatrick // initialization steps look at flags().
3943cab2bb3Spatrick InitializeFlags();
3953cab2bb3Spatrick
396*810390e3Srobert WaitForDebugger(flags()->sleep_before_init, "before init");
397*810390e3Srobert
3983cab2bb3Spatrick // Stop performing init at this point if we are being loaded via
3993cab2bb3Spatrick // dlopen() and the platform supports it.
4003cab2bb3Spatrick if (SANITIZER_SUPPORTS_INIT_FOR_DLOPEN && UNLIKELY(HandleDlopenInit())) {
4013cab2bb3Spatrick asan_init_is_running = false;
4023cab2bb3Spatrick VReport(1, "AddressSanitizer init is being performed for dlopen().\n");
4033cab2bb3Spatrick return;
4043cab2bb3Spatrick }
4053cab2bb3Spatrick
4063cab2bb3Spatrick AsanCheckIncompatibleRT();
4073cab2bb3Spatrick AsanCheckDynamicRTPrereqs();
4083cab2bb3Spatrick AvoidCVE_2016_2143();
4093cab2bb3Spatrick
4103cab2bb3Spatrick SetCanPoisonMemory(flags()->poison_heap);
4113cab2bb3Spatrick SetMallocContextSize(common_flags()->malloc_context_size);
4123cab2bb3Spatrick
4133cab2bb3Spatrick InitializePlatformExceptionHandlers();
4143cab2bb3Spatrick
4153cab2bb3Spatrick InitializeHighMemEnd();
4163cab2bb3Spatrick
4173cab2bb3Spatrick // Make sure we are not statically linked.
4183cab2bb3Spatrick AsanDoesNotSupportStaticLinkage();
4193cab2bb3Spatrick
4203cab2bb3Spatrick // Install tool-specific callbacks in sanitizer_common.
4213cab2bb3Spatrick AddDieCallback(AsanDie);
422d89ec533Spatrick SetCheckUnwindCallback(CheckUnwind);
4233cab2bb3Spatrick SetPrintfAndReportCallback(AppendToErrorMessageBuffer);
4243cab2bb3Spatrick
4253cab2bb3Spatrick __sanitizer_set_report_path(common_flags()->log_path);
4263cab2bb3Spatrick
4273cab2bb3Spatrick __asan_option_detect_stack_use_after_return =
4283cab2bb3Spatrick flags()->detect_stack_use_after_return;
4293cab2bb3Spatrick
4303cab2bb3Spatrick __sanitizer::InitializePlatformEarly();
4313cab2bb3Spatrick
4323cab2bb3Spatrick // Setup internal allocator callback.
433*810390e3Srobert SetLowLevelAllocateMinAlignment(ASAN_SHADOW_GRANULARITY);
4343cab2bb3Spatrick SetLowLevelAllocateCallback(OnLowLevelAllocate);
4353cab2bb3Spatrick
4363cab2bb3Spatrick InitializeAsanInterceptors();
4373cab2bb3Spatrick CheckASLR();
4383cab2bb3Spatrick
4393cab2bb3Spatrick // Enable system log ("adb logcat") on Android.
4403cab2bb3Spatrick // Doing this before interceptors are initialized crashes in:
4413cab2bb3Spatrick // AsanInitInternal -> android_log_write -> __interceptor_strcmp
4423cab2bb3Spatrick AndroidLogInit();
4433cab2bb3Spatrick
4443cab2bb3Spatrick ReplaceSystemMalloc();
4453cab2bb3Spatrick
4463cab2bb3Spatrick DisableCoreDumperIfNecessary();
4473cab2bb3Spatrick
4483cab2bb3Spatrick InitializeShadowMemory();
4493cab2bb3Spatrick
4503cab2bb3Spatrick AsanTSDInit(PlatformTSDDtor);
4513cab2bb3Spatrick InstallDeadlySignalHandlers(AsanOnDeadlySignal);
4523cab2bb3Spatrick
4533cab2bb3Spatrick AllocatorOptions allocator_options;
4543cab2bb3Spatrick allocator_options.SetFrom(flags(), common_flags());
4553cab2bb3Spatrick InitializeAllocator(allocator_options);
4563cab2bb3Spatrick
457*810390e3Srobert if (SANITIZER_START_BACKGROUND_THREAD_IN_ASAN_INTERNAL)
4583cab2bb3Spatrick MaybeStartBackgroudThread();
4593cab2bb3Spatrick
4603cab2bb3Spatrick // On Linux AsanThread::ThreadStart() calls malloc() that's why asan_inited
4613cab2bb3Spatrick // should be set to 1 prior to initializing the threads.
462*810390e3Srobert replace_intrin_cached = flags()->replace_intrin;
4633cab2bb3Spatrick asan_inited = 1;
4643cab2bb3Spatrick asan_init_is_running = false;
4653cab2bb3Spatrick
4663cab2bb3Spatrick if (flags()->atexit)
4673cab2bb3Spatrick Atexit(asan_atexit);
4683cab2bb3Spatrick
4693cab2bb3Spatrick InitializeCoverage(common_flags()->coverage, common_flags()->coverage_dir);
4703cab2bb3Spatrick
4713cab2bb3Spatrick // Now that ASan runtime is (mostly) initialized, deactivate it if
4723cab2bb3Spatrick // necessary, so that it can be re-activated when requested.
4733cab2bb3Spatrick if (flags()->start_deactivated)
4743cab2bb3Spatrick AsanDeactivate();
4753cab2bb3Spatrick
4763cab2bb3Spatrick // interceptors
4773cab2bb3Spatrick InitTlsSize();
4783cab2bb3Spatrick
4793cab2bb3Spatrick // Create main thread.
4803cab2bb3Spatrick AsanThread *main_thread = CreateMainThread();
4813cab2bb3Spatrick CHECK_EQ(0, main_thread->tid());
4823cab2bb3Spatrick force_interface_symbols(); // no-op.
4833cab2bb3Spatrick SanitizerInitializeUnwinder();
4843cab2bb3Spatrick
4853cab2bb3Spatrick if (CAN_SANITIZE_LEAKS) {
4863cab2bb3Spatrick __lsan::InitCommonLsan();
487*810390e3Srobert InstallAtExitCheckLeaks();
4883cab2bb3Spatrick }
4893cab2bb3Spatrick
4903cab2bb3Spatrick #if CAN_SANITIZE_UB
4913cab2bb3Spatrick __ubsan::InitAsPlugin();
4923cab2bb3Spatrick #endif
4933cab2bb3Spatrick
4943cab2bb3Spatrick InitializeSuppressions();
4953cab2bb3Spatrick
4963cab2bb3Spatrick if (CAN_SANITIZE_LEAKS) {
4973cab2bb3Spatrick // LateInitialize() calls dlsym, which can allocate an error string buffer
4983cab2bb3Spatrick // in the TLS. Let's ignore the allocation to avoid reporting a leak.
4993cab2bb3Spatrick __lsan::ScopedInterceptorDisabler disabler;
5003cab2bb3Spatrick Symbolizer::LateInitialize();
5013cab2bb3Spatrick } else {
5023cab2bb3Spatrick Symbolizer::LateInitialize();
5033cab2bb3Spatrick }
5043cab2bb3Spatrick
5053cab2bb3Spatrick VReport(1, "AddressSanitizer Init done\n");
5063cab2bb3Spatrick
507*810390e3Srobert WaitForDebugger(flags()->sleep_after_init, "after init");
5083cab2bb3Spatrick }
5093cab2bb3Spatrick
5103cab2bb3Spatrick // Initialize as requested from some part of ASan runtime library (interceptors,
5113cab2bb3Spatrick // allocator, etc).
AsanInitFromRtl()5123cab2bb3Spatrick void AsanInitFromRtl() {
5133cab2bb3Spatrick AsanInitInternal();
5143cab2bb3Spatrick }
5153cab2bb3Spatrick
5163cab2bb3Spatrick #if ASAN_DYNAMIC
5173cab2bb3Spatrick // Initialize runtime in case it's LD_PRELOAD-ed into unsanitized executable
5183cab2bb3Spatrick // (and thus normal initializers from .preinit_array or modules haven't run).
5193cab2bb3Spatrick
5203cab2bb3Spatrick class AsanInitializer {
5213cab2bb3Spatrick public:
AsanInitializer()5223cab2bb3Spatrick AsanInitializer() {
5233cab2bb3Spatrick AsanInitFromRtl();
5243cab2bb3Spatrick }
5253cab2bb3Spatrick };
5263cab2bb3Spatrick
5273cab2bb3Spatrick static AsanInitializer asan_initializer;
5283cab2bb3Spatrick #endif // ASAN_DYNAMIC
5293cab2bb3Spatrick
UnpoisonStack(uptr bottom,uptr top,const char * type)5301f9cb04fSpatrick void UnpoisonStack(uptr bottom, uptr top, const char *type) {
5311f9cb04fSpatrick static const uptr kMaxExpectedCleanupSize = 64 << 20; // 64M
5321f9cb04fSpatrick if (top - bottom > kMaxExpectedCleanupSize) {
5331f9cb04fSpatrick static bool reported_warning = false;
5341f9cb04fSpatrick if (reported_warning)
5353cab2bb3Spatrick return;
5361f9cb04fSpatrick reported_warning = true;
5371f9cb04fSpatrick Report(
5381f9cb04fSpatrick "WARNING: ASan is ignoring requested __asan_handle_no_return: "
5391f9cb04fSpatrick "stack type: %s top: %p; bottom %p; size: %p (%zd)\n"
5401f9cb04fSpatrick "False positive error reports may follow\n"
5411f9cb04fSpatrick "For details see "
5421f9cb04fSpatrick "https://github.com/google/sanitizers/issues/189\n",
543*810390e3Srobert type, (void *)top, (void *)bottom, (void *)(top - bottom),
544*810390e3Srobert top - bottom);
5451f9cb04fSpatrick return;
5461f9cb04fSpatrick }
547*810390e3Srobert PoisonShadow(bottom, RoundUpTo(top - bottom, ASAN_SHADOW_GRANULARITY), 0);
5481f9cb04fSpatrick }
5493cab2bb3Spatrick
UnpoisonDefaultStack()5501f9cb04fSpatrick static void UnpoisonDefaultStack() {
5511f9cb04fSpatrick uptr bottom, top;
5521f9cb04fSpatrick
5531f9cb04fSpatrick if (AsanThread *curr_thread = GetCurrentThread()) {
5543cab2bb3Spatrick int local_stack;
5551f9cb04fSpatrick const uptr page_size = GetPageSizeCached();
5563cab2bb3Spatrick top = curr_thread->stack_top();
5571f9cb04fSpatrick bottom = ((uptr)&local_stack - page_size) & ~(page_size - 1);
5583cab2bb3Spatrick } else {
5593cab2bb3Spatrick CHECK(!SANITIZER_FUCHSIA);
5603cab2bb3Spatrick // If we haven't seen this thread, try asking the OS for stack bounds.
5613cab2bb3Spatrick uptr tls_addr, tls_size, stack_size;
5623cab2bb3Spatrick GetThreadStackAndTls(/*main=*/false, &bottom, &stack_size, &tls_addr,
5633cab2bb3Spatrick &tls_size);
5643cab2bb3Spatrick top = bottom + stack_size;
5653cab2bb3Spatrick }
5661f9cb04fSpatrick
5671f9cb04fSpatrick UnpoisonStack(bottom, top, "default");
5683cab2bb3Spatrick }
5691f9cb04fSpatrick
UnpoisonFakeStack()5701f9cb04fSpatrick static void UnpoisonFakeStack() {
5711f9cb04fSpatrick AsanThread *curr_thread = GetCurrentThread();
572d89ec533Spatrick if (!curr_thread)
573d89ec533Spatrick return;
574d89ec533Spatrick FakeStack *stack = curr_thread->get_fake_stack();
575d89ec533Spatrick if (!stack)
576d89ec533Spatrick return;
577d89ec533Spatrick stack->HandleNoReturn();
5783cab2bb3Spatrick }
5793cab2bb3Spatrick
5801f9cb04fSpatrick } // namespace __asan
5811f9cb04fSpatrick
5821f9cb04fSpatrick // ---------------------- Interface ---------------- {{{1
5831f9cb04fSpatrick using namespace __asan;
5841f9cb04fSpatrick
__asan_handle_no_return()5851f9cb04fSpatrick void NOINLINE __asan_handle_no_return() {
5861f9cb04fSpatrick if (asan_init_is_running)
5871f9cb04fSpatrick return;
5881f9cb04fSpatrick
5891f9cb04fSpatrick if (!PlatformUnpoisonStacks())
5901f9cb04fSpatrick UnpoisonDefaultStack();
5911f9cb04fSpatrick
5921f9cb04fSpatrick UnpoisonFakeStack();
5931f9cb04fSpatrick }
5941f9cb04fSpatrick
__asan_extra_spill_area()5953cab2bb3Spatrick extern "C" void *__asan_extra_spill_area() {
5963cab2bb3Spatrick AsanThread *t = GetCurrentThread();
5973cab2bb3Spatrick CHECK(t);
5983cab2bb3Spatrick return t->extra_spill_area();
5993cab2bb3Spatrick }
6003cab2bb3Spatrick
__asan_handle_vfork(void * sp)6013cab2bb3Spatrick void __asan_handle_vfork(void *sp) {
6023cab2bb3Spatrick AsanThread *t = GetCurrentThread();
6033cab2bb3Spatrick CHECK(t);
6043cab2bb3Spatrick uptr bottom = t->stack_bottom();
6053cab2bb3Spatrick PoisonShadow(bottom, (uptr)sp - bottom, 0);
6063cab2bb3Spatrick }
6073cab2bb3Spatrick
__asan_set_death_callback(void (* callback)(void))6083cab2bb3Spatrick void NOINLINE __asan_set_death_callback(void (*callback)(void)) {
6093cab2bb3Spatrick SetUserDieCallback(callback);
6103cab2bb3Spatrick }
6113cab2bb3Spatrick
6123cab2bb3Spatrick // Initialize as requested from instrumented application code.
6133cab2bb3Spatrick // We use this call as a trigger to wake up ASan from deactivated state.
__asan_init()6143cab2bb3Spatrick void __asan_init() {
6153cab2bb3Spatrick AsanActivate();
6163cab2bb3Spatrick AsanInitInternal();
6173cab2bb3Spatrick }
6183cab2bb3Spatrick
__asan_version_mismatch_check()6193cab2bb3Spatrick void __asan_version_mismatch_check() {
6203cab2bb3Spatrick // Do nothing.
6213cab2bb3Spatrick }
622