1 //===-- asan_descriptions.cc ------------------------------------*- C++ -*-===//
3 // The LLVM Compiler Infrastructure
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
8 //===----------------------------------------------------------------------===//
10 // This file is a part of AddressSanitizer, an address sanity checker.
12 // ASan functions for getting information about an address and/or printing it.
13 //===----------------------------------------------------------------------===//
15 #include "asan_descriptions.h"
16 #include "asan_mapping.h"
17 #include "asan_report.h"
18 #include "asan_stack.h"
19 #include "sanitizer_common/sanitizer_stackdepot.h"
23 // Return " (thread_name) " or an empty string if the name is empty.
24 const char *ThreadNameWithParenthesis(AsanThreadContext *t, char buff[],
26 const char *name = t->name;
27 if (name[0] == '\0') return "";
29 internal_strncat(buff, " (", 3);
30 internal_strncat(buff, name, buff_len - 4);
31 internal_strncat(buff, ")", 2);
35 const char *ThreadNameWithParenthesis(u32 tid, char buff[], uptr buff_len) {
36 if (tid == kInvalidTid) return "";
37 asanThreadRegistry().CheckLocked();
38 AsanThreadContext *t = GetThreadContextByTidLocked(tid);
39 return ThreadNameWithParenthesis(t, buff, buff_len);
42 void DescribeThread(AsanThreadContext *context) {
44 asanThreadRegistry().CheckLocked();
45 // No need to announce the main thread.
46 if (context->tid == 0 || context->announced) {
49 context->announced = true;
51 InternalScopedString str(1024);
52 str.append("Thread T%d%s", context->tid,
53 ThreadNameWithParenthesis(context->tid, tname, sizeof(tname)));
54 if (context->parent_tid == kInvalidTid) {
55 str.append(" created by unknown thread\n");
56 Printf("%s", str.data());
60 " created by T%d%s here:\n", context->parent_tid,
61 ThreadNameWithParenthesis(context->parent_tid, tname, sizeof(tname)));
62 Printf("%s", str.data());
63 StackDepotGet(context->stack_id).Print();
64 // Recursively described parent thread if needed.
65 if (flags()->print_full_thread_history) {
66 AsanThreadContext *parent_context =
67 GetThreadContextByTidLocked(context->parent_tid);
68 DescribeThread(parent_context);
72 // Shadow descriptions
73 static bool GetShadowKind(uptr addr, ShadowKind *shadow_kind) {
74 CHECK(!AddrIsInMem(addr));
75 if (AddrIsInShadowGap(addr)) {
76 *shadow_kind = kShadowKindGap;
77 } else if (AddrIsInHighShadow(addr)) {
78 *shadow_kind = kShadowKindHigh;
79 } else if (AddrIsInLowShadow(addr)) {
80 *shadow_kind = kShadowKindLow;
82 CHECK(0 && "Address is not in memory and not in shadow?");
88 bool DescribeAddressIfShadow(uptr addr) {
89 ShadowAddressDescription descr;
90 if (!GetShadowAddressInformation(addr, &descr)) return false;
95 bool GetShadowAddressInformation(uptr addr, ShadowAddressDescription *descr) {
96 if (AddrIsInMem(addr)) return false;
97 ShadowKind shadow_kind;
98 if (!GetShadowKind(addr, &shadow_kind)) return false;
99 if (shadow_kind != kShadowKindGap) descr->shadow_byte = *(u8 *)addr;
101 descr->kind = shadow_kind;
106 static void GetAccessToHeapChunkInformation(ChunkAccess *descr,
107 AsanChunkView chunk, uptr addr,
109 descr->bad_addr = addr;
110 if (chunk.AddrIsAtLeft(addr, access_size, &descr->offset)) {
111 descr->access_type = kAccessTypeLeft;
112 } else if (chunk.AddrIsAtRight(addr, access_size, &descr->offset)) {
113 descr->access_type = kAccessTypeRight;
114 if (descr->offset < 0) {
115 descr->bad_addr -= descr->offset;
118 } else if (chunk.AddrIsInside(addr, access_size, &descr->offset)) {
119 descr->access_type = kAccessTypeInside;
121 descr->access_type = kAccessTypeUnknown;
123 descr->chunk_begin = chunk.Beg();
124 descr->chunk_size = chunk.UsedSize();
125 descr->alloc_type = chunk.GetAllocType();
128 static void PrintHeapChunkAccess(uptr addr, const ChunkAccess &descr) {
130 InternalScopedString str(4096);
131 str.append("%s", d.Location());
132 switch (descr.access_type) {
133 case kAccessTypeLeft:
134 str.append("%p is located %zd bytes to the left of",
135 (void *)descr.bad_addr, descr.offset);
137 case kAccessTypeRight:
138 str.append("%p is located %zd bytes to the right of",
139 (void *)descr.bad_addr, descr.offset);
141 case kAccessTypeInside:
142 str.append("%p is located %zd bytes inside of", (void *)descr.bad_addr,
145 case kAccessTypeUnknown:
147 "%p is located somewhere around (this is AddressSanitizer bug!)",
148 (void *)descr.bad_addr);
150 str.append(" %zu-byte region [%p,%p)\n", descr.chunk_size,
151 (void *)descr.chunk_begin,
152 (void *)(descr.chunk_begin + descr.chunk_size));
153 str.append("%s", d.EndLocation());
154 Printf("%s", str.data());
157 bool GetHeapAddressInformation(uptr addr, uptr access_size,
158 HeapAddressDescription *descr) {
159 AsanChunkView chunk = FindHeapChunkByAddress(addr);
160 if (!chunk.IsValid()) {
164 GetAccessToHeapChunkInformation(&descr->chunk_access, chunk, addr,
166 CHECK_NE(chunk.AllocTid(), kInvalidTid);
167 descr->alloc_tid = chunk.AllocTid();
168 descr->alloc_stack_id = chunk.GetAllocStackId();
169 descr->free_tid = chunk.FreeTid();
170 if (descr->free_tid != kInvalidTid)
171 descr->free_stack_id = chunk.GetFreeStackId();
175 static StackTrace GetStackTraceFromId(u32 id) {
177 StackTrace res = StackDepotGet(id);
182 bool DescribeAddressIfHeap(uptr addr, uptr access_size) {
183 HeapAddressDescription descr;
184 if (!GetHeapAddressInformation(addr, access_size, &descr)) {
186 "AddressSanitizer can not describe address in more detail "
187 "(wild memory access suspected).\n");
194 // Stack descriptions
195 bool GetStackAddressInformation(uptr addr, uptr access_size,
196 StackAddressDescription *descr) {
197 AsanThread *t = FindThreadByStackAddress(addr);
198 if (!t) return false;
201 descr->tid = t->tid();
202 // Try to fetch precise stack frame for this access.
203 AsanThread::StackFrameAccess access;
204 if (!t->GetStackFrameAccessByAddr(addr, &access)) {
205 descr->frame_descr = nullptr;
209 descr->offset = access.offset;
210 descr->access_size = access_size;
211 descr->frame_pc = access.frame_pc;
212 descr->frame_descr = access.frame_descr;
214 #if SANITIZER_PPC64V1
215 // On PowerPC64 ELFv1, the address of a function actually points to a
216 // three-doubleword data structure with the first field containing
217 // the address of the function's code.
218 descr->frame_pc = *reinterpret_cast<uptr *>(descr->frame_pc);
220 descr->frame_pc += 16;
225 static void PrintAccessAndVarIntersection(const StackVarDescr &var, uptr addr,
226 uptr access_size, uptr prev_var_end,
228 uptr var_end = var.beg + var.size;
229 uptr addr_end = addr + access_size;
230 const char *pos_descr = nullptr;
231 // If the variable [var.beg, var_end) is the nearest variable to the
232 // current memory access, indicate it in the log.
233 if (addr >= var.beg) {
234 if (addr_end <= var_end)
235 pos_descr = "is inside"; // May happen if this is a use-after-return.
236 else if (addr < var_end)
237 pos_descr = "partially overflows";
238 else if (addr_end <= next_var_beg &&
239 next_var_beg - addr_end >= addr - var_end)
240 pos_descr = "overflows";
242 if (addr_end > var.beg)
243 pos_descr = "partially underflows";
244 else if (addr >= prev_var_end && addr - prev_var_end >= var.beg - addr_end)
245 pos_descr = "underflows";
247 InternalScopedString str(1024);
248 str.append(" [%zd, %zd)", var.beg, var_end);
249 // Render variable name.
251 for (uptr i = 0; i < var.name_len; ++i) {
252 str.append("%c", var.name_pos[i]);
256 str.append(" (line %d)", var.line);
260 // FIXME: we may want to also print the size of the access here,
261 // but in case of accesses generated by memset it may be confusing.
262 str.append("%s <== Memory access at offset %zd %s this variable%s\n",
263 d.Location(), addr, pos_descr, d.EndLocation());
267 Printf("%s", str.data());
270 bool DescribeAddressIfStack(uptr addr, uptr access_size) {
271 StackAddressDescription descr;
272 if (!GetStackAddressInformation(addr, access_size, &descr)) return false;
277 // Global descriptions
278 static void DescribeAddressRelativeToGlobal(uptr addr, uptr access_size,
279 const __asan_global &g) {
280 InternalScopedString str(4096);
282 str.append("%s", d.Location());
284 str.append("%p is located %zd bytes to the left", (void *)addr,
286 } else if (addr + access_size > g.beg + g.size) {
287 if (addr < g.beg + g.size) addr = g.beg + g.size;
288 str.append("%p is located %zd bytes to the right", (void *)addr,
289 addr - (g.beg + g.size));
292 str.append("%p is located %zd bytes inside", (void *)addr, addr - g.beg);
294 str.append(" of global variable '%s' defined in '",
295 MaybeDemangleGlobalName(g.name));
296 PrintGlobalLocation(&str, g);
297 str.append("' (0x%zx) of size %zu\n", g.beg, g.size);
298 str.append("%s", d.EndLocation());
299 PrintGlobalNameIfASCII(&str, g);
300 Printf("%s", str.data());
303 bool GetGlobalAddressInformation(uptr addr, uptr access_size,
304 GlobalAddressDescription *descr) {
306 int globals_num = GetGlobalsForAddress(addr, descr->globals, descr->reg_sites,
307 ARRAY_SIZE(descr->globals));
308 descr->size = globals_num;
309 descr->access_size = access_size;
310 return globals_num != 0;
313 bool DescribeAddressIfGlobal(uptr addr, uptr access_size,
314 const char *bug_type) {
315 GlobalAddressDescription descr;
316 if (!GetGlobalAddressInformation(addr, access_size, &descr)) return false;
318 descr.Print(bug_type);
322 void ShadowAddressDescription::Print() const {
323 Printf("Address %p is located in the %s area.\n", addr, ShadowNames[kind]);
326 void GlobalAddressDescription::Print(const char *bug_type) const {
327 for (int i = 0; i < size; i++) {
328 DescribeAddressRelativeToGlobal(addr, access_size, globals[i]);
330 0 == internal_strcmp(bug_type, "initialization-order-fiasco") &&
332 Printf(" registered at:\n");
333 StackDepotGet(reg_sites[i]).Print();
338 void StackAddressDescription::Print() const {
341 Printf("%s", d.Location());
342 Printf("Address %p is located in stack of thread T%d%s", addr, tid,
343 ThreadNameWithParenthesis(tid, tname, sizeof(tname)));
346 Printf("%s\n", d.EndLocation());
349 Printf(" at offset %zu in frame%s\n", offset, d.EndLocation());
351 // Now we print the frame where the alloca has happened.
352 // We print this frame as a stack trace with one element.
353 // The symbolizer may print more than one frame if inlining was involved.
354 // The frame numbers may be different than those in the stack trace printed
355 // previously. That's unfortunate, but I have no better solution,
356 // especially given that the alloca may be from entirely different place
357 // (e.g. use-after-scope, or different thread's stack).
358 Printf("%s", d.EndLocation());
359 StackTrace alloca_stack(&frame_pc, 1);
360 alloca_stack.Print();
362 InternalMmapVector<StackVarDescr> vars(16);
363 if (!ParseFrameDescription(frame_descr, &vars)) {
365 "AddressSanitizer can't parse the stack frame "
366 "descriptor: |%s|\n",
368 // 'addr' is a stack address, so return true even if we can't parse frame
371 uptr n_objects = vars.size();
372 // Report the number of stack objects.
373 Printf(" This frame has %zu object(s):\n", n_objects);
375 // Report all objects in this frame.
376 for (uptr i = 0; i < n_objects; i++) {
377 uptr prev_var_end = i ? vars[i - 1].beg + vars[i - 1].size : 0;
378 uptr next_var_beg = i + 1 < n_objects ? vars[i + 1].beg : ~(0UL);
379 PrintAccessAndVarIntersection(vars[i], offset, access_size, prev_var_end,
383 "HINT: this may be a false positive if your program uses "
384 "some custom stack unwind mechanism or swapcontext\n");
385 if (SANITIZER_WINDOWS)
386 Printf(" (longjmp, SEH and C++ exceptions *are* supported)\n");
388 Printf(" (longjmp and C++ exceptions *are* supported)\n");
390 DescribeThread(GetThreadContextByTidLocked(tid));
393 void HeapAddressDescription::Print() const {
394 PrintHeapChunkAccess(addr, chunk_access);
396 asanThreadRegistry().CheckLocked();
397 AsanThreadContext *alloc_thread = GetThreadContextByTidLocked(alloc_tid);
398 StackTrace alloc_stack = GetStackTraceFromId(alloc_stack_id);
402 AsanThreadContext *free_thread = nullptr;
403 if (free_tid != kInvalidTid) {
404 free_thread = GetThreadContextByTidLocked(free_tid);
405 Printf("%sfreed by thread T%d%s here:%s\n", d.Allocation(),
407 ThreadNameWithParenthesis(free_thread, tname, sizeof(tname)),
409 StackTrace free_stack = GetStackTraceFromId(free_stack_id);
411 Printf("%spreviously allocated by thread T%d%s here:%s\n", d.Allocation(),
413 ThreadNameWithParenthesis(alloc_thread, tname, sizeof(tname)),
416 Printf("%sallocated by thread T%d%s here:%s\n", d.Allocation(),
418 ThreadNameWithParenthesis(alloc_thread, tname, sizeof(tname)),
422 DescribeThread(GetCurrentThread());
423 if (free_thread) DescribeThread(free_thread);
424 DescribeThread(alloc_thread);
427 AddressDescription::AddressDescription(uptr addr, uptr access_size,
428 bool shouldLockThreadRegistry) {
429 if (GetShadowAddressInformation(addr, &data.shadow)) {
430 data.kind = kAddressKindShadow;
433 if (GetHeapAddressInformation(addr, access_size, &data.heap)) {
434 data.kind = kAddressKindHeap;
438 bool isStackMemory = false;
439 if (shouldLockThreadRegistry) {
440 ThreadRegistryLock l(&asanThreadRegistry());
441 isStackMemory = GetStackAddressInformation(addr, access_size, &data.stack);
443 isStackMemory = GetStackAddressInformation(addr, access_size, &data.stack);
446 data.kind = kAddressKindStack;
450 if (GetGlobalAddressInformation(addr, access_size, &data.global)) {
451 data.kind = kAddressKindGlobal;
454 data.kind = kAddressKindWild;
458 void PrintAddressDescription(uptr addr, uptr access_size,
459 const char *bug_type) {
460 ShadowAddressDescription shadow_descr;
461 if (GetShadowAddressInformation(addr, &shadow_descr)) {
462 shadow_descr.Print();
466 GlobalAddressDescription global_descr;
467 if (GetGlobalAddressInformation(addr, access_size, &global_descr)) {
468 global_descr.Print(bug_type);
472 StackAddressDescription stack_descr;
473 if (GetStackAddressInformation(addr, access_size, &stack_descr)) {
478 HeapAddressDescription heap_descr;
479 if (GetHeapAddressInformation(addr, access_size, &heap_descr)) {
484 // We exhausted our possibilities. Bail out.
486 "AddressSanitizer can not describe address in more detail "
487 "(wild memory access suspected).\n");
489 } // namespace __asan