1 //===-- hwasan_dynamic_shadow.cc --------------------------------*- C++ -*-===//
3 // The LLVM Compiler Infrastructure
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
8 //===----------------------------------------------------------------------===//
11 /// This file is a part of HWAddressSanitizer. It reserves dynamic shadow memory
12 /// region and handles ifunc resolver case, when necessary.
14 //===----------------------------------------------------------------------===//
17 #include "hwasan_dynamic_shadow.h"
18 #include "hwasan_mapping.h"
19 #include "sanitizer_common/sanitizer_common.h"
20 #include "sanitizer_common/sanitizer_posix.h"
22 // The code in this file needs to run in an unrelocated binary. It should not
23 // access any external symbol, including its own non-hidden globals.
27 static void UnmapFromTo(uptr from, uptr to) {
31 uptr res = internal_munmap(reinterpret_cast<void *>(from), to - from);
32 if (UNLIKELY(internal_iserror(res))) {
33 Report("ERROR: %s failed to unmap 0x%zx (%zd) bytes at address %p\n",
34 SanitizerToolName, to - from, to - from, from);
35 CHECK("unable to unmap" && 0);
39 // Returns an address aligned to kShadowBaseAlignment, such that
40 // 2**kShadowBaseAlingment on the left and shadow_size_bytes bytes on the right
41 // of it are mapped no access.
42 static uptr MapDynamicShadow(uptr shadow_size_bytes) {
43 const uptr granularity = GetMmapGranularity();
44 const uptr min_alignment = granularity << kShadowScale;
45 const uptr alignment = 1ULL << kShadowBaseAlignment;
46 CHECK_GE(alignment, min_alignment);
48 const uptr left_padding = 1ULL << kShadowBaseAlignment;
49 const uptr shadow_size =
50 RoundUpTo(shadow_size_bytes, granularity);
51 const uptr map_size = shadow_size + left_padding + alignment;
53 const uptr map_start = (uptr)MmapNoAccess(map_size);
54 CHECK_NE(map_start, ~(uptr)0);
56 const uptr shadow_start = RoundUpTo(map_start + left_padding, alignment);
58 UnmapFromTo(map_start, shadow_start - left_padding);
59 UnmapFromTo(shadow_start + shadow_size, map_start + map_size);
64 } // namespace __hwasan
69 INTERFACE_ATTRIBUTE void __hwasan_shadow();
70 decltype(__hwasan_shadow)* __hwasan_premap_shadow();
76 // Conservative upper limit.
77 static uptr PremapShadowSize() {
78 return RoundUpTo(GetMaxVirtualAddress() >> kShadowScale,
79 GetMmapGranularity());
82 static uptr PremapShadow() {
83 return MapDynamicShadow(PremapShadowSize());
86 static bool IsPremapShadowAvailable() {
87 const uptr shadow = reinterpret_cast<uptr>(&__hwasan_shadow);
88 const uptr resolver = reinterpret_cast<uptr>(&__hwasan_premap_shadow);
89 // shadow == resolver is how Android KitKat and older handles ifunc.
90 // shadow == 0 just in case.
91 return shadow != 0 && shadow != resolver;
94 static uptr FindPremappedShadowStart(uptr shadow_size_bytes) {
95 const uptr granularity = GetMmapGranularity();
96 const uptr shadow_start = reinterpret_cast<uptr>(&__hwasan_shadow);
97 const uptr premap_shadow_size = PremapShadowSize();
98 const uptr shadow_size = RoundUpTo(shadow_size_bytes, granularity);
100 // We may have mapped too much. Release extra memory.
101 UnmapFromTo(shadow_start + shadow_size, shadow_start + premap_shadow_size);
105 } // namespace __hwasan
109 decltype(__hwasan_shadow)* __hwasan_premap_shadow() {
110 // The resolver might be called multiple times. Map the shadow just once.
111 static __sanitizer::uptr shadow = 0;
113 shadow = __hwasan::PremapShadow();
114 return reinterpret_cast<decltype(__hwasan_shadow)*>(shadow);
117 // __hwasan_shadow is a "function" that has the same address as the first byte
118 // of the shadow mapping.
119 INTERFACE_ATTRIBUTE __attribute__((ifunc("__hwasan_premap_shadow")))
120 void __hwasan_shadow();
126 uptr FindDynamicShadowStart(uptr shadow_size_bytes) {
127 if (IsPremapShadowAvailable())
128 return FindPremappedShadowStart(shadow_size_bytes);
129 return MapDynamicShadow(shadow_size_bytes);
132 } // namespace __hwasan
136 uptr FindDynamicShadowStart(uptr shadow_size_bytes) {
137 return MapDynamicShadow(shadow_size_bytes);
140 } // namespace __hwasan
142 #endif // SANITIZER_ANDROID