1 //===-- hwasan.cc -----------------------------------------------------------===//
3 // The LLVM Compiler Infrastructure
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
8 //===----------------------------------------------------------------------===//
10 // This file is a part of HWAddressSanitizer.
12 // HWAddressSanitizer runtime.
13 //===----------------------------------------------------------------------===//
16 #include "hwasan_thread.h"
17 #include "hwasan_poisoning.h"
18 #include "sanitizer_common/sanitizer_atomic.h"
19 #include "sanitizer_common/sanitizer_common.h"
20 #include "sanitizer_common/sanitizer_flags.h"
21 #include "sanitizer_common/sanitizer_flag_parser.h"
22 #include "sanitizer_common/sanitizer_libc.h"
23 #include "sanitizer_common/sanitizer_procmaps.h"
24 #include "sanitizer_common/sanitizer_stacktrace.h"
25 #include "sanitizer_common/sanitizer_symbolizer.h"
26 #include "sanitizer_common/sanitizer_stackdepot.h"
27 #include "ubsan/ubsan_flags.h"
28 #include "ubsan/ubsan_init.h"
30 // ACHTUNG! No system header includes in this file.
32 using namespace __sanitizer;
36 void EnterSymbolizer() {
37 HwasanThread *t = GetCurrentThread();
41 void ExitSymbolizer() {
42 HwasanThread *t = GetCurrentThread();
46 bool IsInSymbolizer() {
47 HwasanThread *t = GetCurrentThread();
48 return t && t->InSymbolizer();
51 static Flags hwasan_flags;
57 int hwasan_inited = 0;
58 bool hwasan_init_is_running;
60 int hwasan_report_count = 0;
62 void Flags::SetDefaults() {
63 #define HWASAN_FLAG(Type, Name, DefaultValue, Description) Name = DefaultValue;
64 #include "hwasan_flags.inc"
68 static void RegisterHwasanFlags(FlagParser *parser, Flags *f) {
69 #define HWASAN_FLAG(Type, Name, DefaultValue, Description) \
70 RegisterFlag(parser, #Name, Description, &f->Name);
71 #include "hwasan_flags.inc"
75 static void InitializeFlags() {
76 SetCommonFlagsDefaults();
79 cf.CopyFrom(*common_flags());
80 cf.external_symbolizer_path = GetEnv("HWASAN_SYMBOLIZER_PATH");
81 cf.malloc_context_size = 20;
82 cf.handle_ioctl = true;
83 // FIXME: test and enable.
84 cf.check_printf = false;
85 cf.intercept_tls_get_addr = true;
87 cf.handle_sigill = kHandleSignalExclusive;
88 OverrideCommonFlags(cf);
95 RegisterHwasanFlags(&parser, f);
96 RegisterCommonFlags(&parser);
98 #if HWASAN_CONTAINS_UBSAN
99 __ubsan::Flags *uf = __ubsan::flags();
102 FlagParser ubsan_parser;
103 __ubsan::RegisterUbsanFlags(&ubsan_parser, uf);
104 RegisterCommonFlags(&ubsan_parser);
107 // Override from user-specified string.
108 if (__hwasan_default_options)
109 parser.ParseString(__hwasan_default_options());
110 #if HWASAN_CONTAINS_UBSAN
111 const char *ubsan_default_options = __ubsan::MaybeCallUbsanDefaultOptions();
112 ubsan_parser.ParseString(ubsan_default_options);
115 const char *hwasan_options = GetEnv("HWASAN_OPTIONS");
116 parser.ParseString(hwasan_options);
117 #if HWASAN_CONTAINS_UBSAN
118 ubsan_parser.ParseString(GetEnv("UBSAN_OPTIONS"));
120 VPrintf(1, "HWASAN_OPTIONS: %s\n", hwasan_options ? hwasan_options : "<empty>");
122 InitializeCommonFlags();
124 if (Verbosity()) ReportUnrecognizedFlags();
126 if (common_flags()->help) parser.PrintFlagDescriptions();
129 void GetStackTrace(BufferedStackTrace *stack, uptr max_s, uptr pc, uptr bp,
130 void *context, bool request_fast_unwind) {
131 HwasanThread *t = GetCurrentThread();
132 if (!t || !StackTrace::WillUseFastUnwind(request_fast_unwind)) {
133 // Block reports from our interceptors during _Unwind_Backtrace.
134 SymbolizerScope sym_scope;
135 return stack->Unwind(max_s, pc, bp, context, 0, 0, request_fast_unwind);
137 stack->Unwind(max_s, pc, bp, context, t->stack_top(), t->stack_bottom(),
138 request_fast_unwind);
141 void PrintWarning(uptr pc, uptr bp) {
142 GET_FATAL_STACK_TRACE_PC_BP(pc, bp);
143 ReportInvalidAccess(&stack, 0);
146 } // namespace __hwasan
150 using namespace __hwasan;
152 void __hwasan_init() {
153 CHECK(!hwasan_init_is_running);
154 if (hwasan_inited) return;
155 hwasan_init_is_running = 1;
156 SanitizerToolName = "HWAddressSanitizer";
163 __sanitizer_set_report_path(common_flags()->log_path);
165 InitializeInterceptors();
166 InstallDeadlySignalHandlers(HwasanOnDeadlySignal);
167 InstallAtExitHandler(); // Needs __cxa_atexit interceptor.
169 DisableCoreDumperIfNecessary();
171 Printf("FATAL: HWAddressSanitizer can not mmap the shadow memory.\n");
172 Printf("FATAL: Make sure to compile with -fPIE and to link with -pie.\n");
173 Printf("FATAL: Disabling ASLR is known to cause this error.\n");
174 Printf("FATAL: If running under GDB, try "
175 "'set disable-randomization off'.\n");
180 Symbolizer::GetOrInit()->AddHooks(EnterSymbolizer, ExitSymbolizer);
182 InitializeCoverage(common_flags()->coverage, common_flags()->coverage_dir);
184 HwasanTSDInit(HwasanTSDDtor);
186 HwasanAllocatorInit();
188 HwasanThread *main_thread = HwasanThread::Create(nullptr, nullptr);
189 SetCurrentThread(main_thread);
190 main_thread->ThreadStart();
192 #if HWASAN_CONTAINS_UBSAN
193 __ubsan::InitAsPlugin();
196 VPrintf(1, "HWAddressSanitizer init done\n");
198 hwasan_init_is_running = 0;
202 void __hwasan_print_shadow(const void *x, uptr size) {
204 Printf("FIXME: __hwasan_print_shadow unimplemented\n");
207 sptr __hwasan_test_shadow(const void *p, uptr sz) {
210 tag_t ptr_tag = GetTagFromPointer((uptr)p);
213 uptr ptr_raw = GetAddressFromPointer((uptr)p);
214 uptr shadow_first = MEM_TO_SHADOW(ptr_raw);
215 uptr shadow_last = MEM_TO_SHADOW(ptr_raw + sz - 1);
216 for (uptr s = shadow_first; s <= shadow_last; ++s)
217 if (*(tag_t*)s != ptr_tag)
218 return SHADOW_TO_MEM(s) - ptr_raw;
222 u16 __sanitizer_unaligned_load16(const uu16 *p) {
225 u32 __sanitizer_unaligned_load32(const uu32 *p) {
228 u64 __sanitizer_unaligned_load64(const uu64 *p) {
231 void __sanitizer_unaligned_store16(uu16 *p, u16 x) {
234 void __sanitizer_unaligned_store32(uu32 *p, u32 x) {
237 void __sanitizer_unaligned_store64(uu64 *p, u64 x) {
242 __attribute__((always_inline))
243 static void SigIll() {
244 #if defined(__aarch64__)
245 asm("hlt %0\n\t" ::"n"(X));
246 #elif defined(__x86_64__) || defined(__i386__)
249 // FIXME: not always sigill.
252 // __builtin_unreachable();
255 enum class ErrorAction { Abort, Recover };
256 enum class AccessType { Load, Store };
258 template <ErrorAction EA, AccessType AT, unsigned LogSize>
259 __attribute__((always_inline, nodebug)) static void CheckAddress(uptr p) {
260 tag_t ptr_tag = GetTagFromPointer(p);
261 uptr ptr_raw = p & ~kAddressTagMask;
262 tag_t mem_tag = *(tag_t *)MEM_TO_SHADOW(ptr_raw);
263 if (UNLIKELY(ptr_tag != mem_tag)) {
264 SigIll<0x100 + 0x20 * (EA == ErrorAction::Recover) +
265 0x10 * (AT == AccessType::Store) + LogSize>();
266 if (EA == ErrorAction::Abort) __builtin_unreachable();
270 template <ErrorAction EA, AccessType AT>
271 __attribute__((always_inline, nodebug)) static void CheckAddressSized(uptr p,
274 tag_t ptr_tag = GetTagFromPointer(p);
275 uptr ptr_raw = p & ~kAddressTagMask;
276 tag_t *shadow_first = (tag_t *)MEM_TO_SHADOW(ptr_raw);
277 tag_t *shadow_last = (tag_t *)MEM_TO_SHADOW(ptr_raw + sz - 1);
278 for (tag_t *t = shadow_first; t <= shadow_last; ++t)
279 if (UNLIKELY(ptr_tag != *t)) {
280 SigIll<0x100 + 0x20 * (EA == ErrorAction::Recover) +
281 0x10 * (AT == AccessType::Store) + 0xf>();
282 if (EA == ErrorAction::Abort) __builtin_unreachable();
286 void __hwasan_load(uptr p, uptr sz) {
287 CheckAddressSized<ErrorAction::Abort, AccessType::Load>(p, sz);
289 void __hwasan_load1(uptr p) {
290 CheckAddress<ErrorAction::Abort, AccessType::Load, 0>(p);
292 void __hwasan_load2(uptr p) {
293 CheckAddress<ErrorAction::Abort, AccessType::Load, 1>(p);
295 void __hwasan_load4(uptr p) {
296 CheckAddress<ErrorAction::Abort, AccessType::Load, 2>(p);
298 void __hwasan_load8(uptr p) {
299 CheckAddress<ErrorAction::Abort, AccessType::Load, 3>(p);
301 void __hwasan_load16(uptr p) {
302 CheckAddress<ErrorAction::Abort, AccessType::Load, 4>(p);
305 void __hwasan_load_noabort(uptr p, uptr sz) {
306 CheckAddressSized<ErrorAction::Recover, AccessType::Load>(p, sz);
308 void __hwasan_load1_noabort(uptr p) {
309 CheckAddress<ErrorAction::Recover, AccessType::Load, 0>(p);
311 void __hwasan_load2_noabort(uptr p) {
312 CheckAddress<ErrorAction::Recover, AccessType::Load, 1>(p);
314 void __hwasan_load4_noabort(uptr p) {
315 CheckAddress<ErrorAction::Recover, AccessType::Load, 2>(p);
317 void __hwasan_load8_noabort(uptr p) {
318 CheckAddress<ErrorAction::Recover, AccessType::Load, 3>(p);
320 void __hwasan_load16_noabort(uptr p) {
321 CheckAddress<ErrorAction::Recover, AccessType::Load, 4>(p);
324 void __hwasan_store(uptr p, uptr sz) {
325 CheckAddressSized<ErrorAction::Abort, AccessType::Store>(p, sz);
327 void __hwasan_store1(uptr p) {
328 CheckAddress<ErrorAction::Abort, AccessType::Store, 0>(p);
330 void __hwasan_store2(uptr p) {
331 CheckAddress<ErrorAction::Abort, AccessType::Store, 1>(p);
333 void __hwasan_store4(uptr p) {
334 CheckAddress<ErrorAction::Abort, AccessType::Store, 2>(p);
336 void __hwasan_store8(uptr p) {
337 CheckAddress<ErrorAction::Abort, AccessType::Store, 3>(p);
339 void __hwasan_store16(uptr p) {
340 CheckAddress<ErrorAction::Abort, AccessType::Store, 4>(p);
343 void __hwasan_store_noabort(uptr p, uptr sz) {
344 CheckAddressSized<ErrorAction::Recover, AccessType::Store>(p, sz);
346 void __hwasan_store1_noabort(uptr p) {
347 CheckAddress<ErrorAction::Recover, AccessType::Store, 0>(p);
349 void __hwasan_store2_noabort(uptr p) {
350 CheckAddress<ErrorAction::Recover, AccessType::Store, 1>(p);
352 void __hwasan_store4_noabort(uptr p) {
353 CheckAddress<ErrorAction::Recover, AccessType::Store, 2>(p);
355 void __hwasan_store8_noabort(uptr p) {
356 CheckAddress<ErrorAction::Recover, AccessType::Store, 3>(p);
358 void __hwasan_store16_noabort(uptr p) {
359 CheckAddress<ErrorAction::Recover, AccessType::Store, 4>(p);
362 #if !SANITIZER_SUPPORTS_WEAK_HOOKS
364 SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
365 const char* __hwasan_default_options() { return ""; }
370 SANITIZER_INTERFACE_ATTRIBUTE
371 void __sanitizer_print_stack_trace() {
372 GET_FATAL_STACK_TRACE_PC_BP(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME());