1 //===-- hwasan_dynamic_shadow.cc --------------------------------*- C++ -*-===//
3 // The LLVM Compiler Infrastructure
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
8 //===----------------------------------------------------------------------===//
11 /// This file is a part of HWAddressSanitizer. It reserves dynamic shadow memory
12 /// region and handles ifunc resolver case, when necessary.
14 //===----------------------------------------------------------------------===//
16 #include "hwasan_dynamic_shadow.h"
17 #include "hwasan_mapping.h"
18 #include "sanitizer_common/sanitizer_common.h"
19 #include "sanitizer_common/sanitizer_posix.h"
21 // The code in this file needs to run in an unrelocated binary. It should not
22 // access any external symbol, including its own non-hidden globals.
26 static void UnmapFromTo(uptr from, uptr to) {
30 uptr res = internal_munmap(reinterpret_cast<void *>(from), to - from);
31 if (UNLIKELY(internal_iserror(res))) {
32 Report("ERROR: %s failed to unmap 0x%zx (%zd) bytes at address %p\n",
33 SanitizerToolName, to - from, to - from, from);
34 CHECK("unable to unmap" && 0);
38 // Returns an address aligned to 8 pages, such that one page on the left and
39 // shadow_size_bytes bytes on the right of it are mapped r/o.
40 static uptr MapDynamicShadow(uptr shadow_size_bytes) {
41 const uptr granularity = GetMmapGranularity();
42 const uptr alignment = granularity * SHADOW_GRANULARITY;
43 const uptr left_padding = granularity;
44 const uptr shadow_size =
45 RoundUpTo(shadow_size_bytes, granularity);
46 const uptr map_size = shadow_size + left_padding + alignment;
48 const uptr map_start = (uptr)MmapNoAccess(map_size);
49 CHECK_NE(map_start, ~(uptr)0);
51 const uptr shadow_start = RoundUpTo(map_start + left_padding, alignment);
53 UnmapFromTo(map_start, shadow_start - left_padding);
54 UnmapFromTo(shadow_start + shadow_size, map_start + map_size);
59 } // namespace __hwasan
61 #if HWASAN_PREMAP_SHADOW
65 INTERFACE_ATTRIBUTE void __hwasan_shadow();
66 decltype(__hwasan_shadow)* __hwasan_premap_shadow();
72 // Conservative upper limit.
73 static uptr PremapShadowSize() {
74 return RoundUpTo(GetMaxVirtualAddress() >> kShadowScale,
75 GetMmapGranularity());
78 static uptr PremapShadow() {
79 return MapDynamicShadow(PremapShadowSize());
82 static bool IsPremapShadowAvailable() {
83 const uptr shadow = reinterpret_cast<uptr>(&__hwasan_shadow);
84 const uptr resolver = reinterpret_cast<uptr>(&__hwasan_premap_shadow);
85 // shadow == resolver is how Android KitKat and older handles ifunc.
86 // shadow == 0 just in case.
87 return shadow != 0 && shadow != resolver;
90 static uptr FindPremappedShadowStart(uptr shadow_size_bytes) {
91 const uptr granularity = GetMmapGranularity();
92 const uptr shadow_start = reinterpret_cast<uptr>(&__hwasan_shadow);
93 const uptr premap_shadow_size = PremapShadowSize();
94 const uptr shadow_size = RoundUpTo(shadow_size_bytes, granularity);
96 // We may have mapped too much. Release extra memory.
97 UnmapFromTo(shadow_start + shadow_size, shadow_start + premap_shadow_size);
101 } // namespace __hwasan
105 decltype(__hwasan_shadow)* __hwasan_premap_shadow() {
106 // The resolver might be called multiple times. Map the shadow just once.
107 static __sanitizer::uptr shadow = 0;
109 shadow = __hwasan::PremapShadow();
110 return reinterpret_cast<decltype(__hwasan_shadow)*>(shadow);
113 // __hwasan_shadow is a "function" that has the same address as the first byte
114 // of the shadow mapping.
115 INTERFACE_ATTRIBUTE __attribute__((ifunc("__hwasan_premap_shadow")))
116 void __hwasan_shadow();
120 #endif // HWASAN_PREMAP_SHADOW
124 uptr FindDynamicShadowStart(uptr shadow_size_bytes) {
125 #if HWASAN_PREMAP_SHADOW
126 if (IsPremapShadowAvailable())
127 return FindPremappedShadowStart(shadow_size_bytes);
129 return MapDynamicShadow(shadow_size_bytes);
132 } // namespace __hwasan