1 //===-- hwasan.cc ---------------------------------------------------------===//
3 // The LLVM Compiler Infrastructure
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
8 //===----------------------------------------------------------------------===//
10 // This file is a part of HWAddressSanitizer.
12 // HWAddressSanitizer runtime.
13 //===----------------------------------------------------------------------===//
16 #include "hwasan_checks.h"
17 #include "hwasan_poisoning.h"
18 #include "hwasan_report.h"
19 #include "hwasan_thread.h"
20 #include "hwasan_thread_list.h"
21 #include "sanitizer_common/sanitizer_atomic.h"
22 #include "sanitizer_common/sanitizer_common.h"
23 #include "sanitizer_common/sanitizer_flag_parser.h"
24 #include "sanitizer_common/sanitizer_flags.h"
25 #include "sanitizer_common/sanitizer_libc.h"
26 #include "sanitizer_common/sanitizer_procmaps.h"
27 #include "sanitizer_common/sanitizer_stackdepot.h"
28 #include "sanitizer_common/sanitizer_stacktrace.h"
29 #include "sanitizer_common/sanitizer_symbolizer.h"
30 #include "ubsan/ubsan_flags.h"
31 #include "ubsan/ubsan_init.h"
33 // ACHTUNG! No system header includes in this file.
35 using namespace __sanitizer;
39 void EnterSymbolizer() {
40 Thread *t = GetCurrentThread();
44 void ExitSymbolizer() {
45 Thread *t = GetCurrentThread();
49 bool IsInSymbolizer() {
50 Thread *t = GetCurrentThread();
51 return t && t->InSymbolizer();
54 static Flags hwasan_flags;
60 int hwasan_inited = 0;
61 int hwasan_shadow_inited = 0;
62 bool hwasan_init_is_running;
64 int hwasan_report_count = 0;
66 void Flags::SetDefaults() {
67 #define HWASAN_FLAG(Type, Name, DefaultValue, Description) Name = DefaultValue;
68 #include "hwasan_flags.inc"
72 static void RegisterHwasanFlags(FlagParser *parser, Flags *f) {
73 #define HWASAN_FLAG(Type, Name, DefaultValue, Description) \
74 RegisterFlag(parser, #Name, Description, &f->Name);
75 #include "hwasan_flags.inc"
79 static void InitializeFlags() {
80 SetCommonFlagsDefaults();
83 cf.CopyFrom(*common_flags());
84 cf.external_symbolizer_path = GetEnv("HWASAN_SYMBOLIZER_PATH");
85 cf.malloc_context_size = 20;
86 cf.handle_ioctl = true;
87 // FIXME: test and enable.
88 cf.check_printf = false;
89 cf.intercept_tls_get_addr = true;
91 // Sigtrap is used in error reporting.
92 cf.handle_sigtrap = kHandleSignalExclusive;
95 // Let platform handle other signals. It is better at reporting them then we
97 cf.handle_segv = kHandleSignalNo;
98 cf.handle_sigbus = kHandleSignalNo;
99 cf.handle_abort = kHandleSignalNo;
100 cf.handle_sigill = kHandleSignalNo;
101 cf.handle_sigfpe = kHandleSignalNo;
103 OverrideCommonFlags(cf);
110 RegisterHwasanFlags(&parser, f);
111 RegisterCommonFlags(&parser);
113 #if HWASAN_CONTAINS_UBSAN
114 __ubsan::Flags *uf = __ubsan::flags();
117 FlagParser ubsan_parser;
118 __ubsan::RegisterUbsanFlags(&ubsan_parser, uf);
119 RegisterCommonFlags(&ubsan_parser);
122 // Override from user-specified string.
123 if (__hwasan_default_options)
124 parser.ParseString(__hwasan_default_options());
125 #if HWASAN_CONTAINS_UBSAN
126 const char *ubsan_default_options = __ubsan::MaybeCallUbsanDefaultOptions();
127 ubsan_parser.ParseString(ubsan_default_options);
130 const char *hwasan_options = GetEnv("HWASAN_OPTIONS");
131 parser.ParseString(hwasan_options);
132 #if HWASAN_CONTAINS_UBSAN
133 ubsan_parser.ParseString(GetEnv("UBSAN_OPTIONS"));
135 VPrintf(1, "HWASAN_OPTIONS: %s\n",
136 hwasan_options ? hwasan_options : "<empty>");
138 InitializeCommonFlags();
140 if (Verbosity()) ReportUnrecognizedFlags();
142 if (common_flags()->help) parser.PrintFlagDescriptions();
145 void GetStackTrace(BufferedStackTrace *stack, uptr max_s, uptr pc, uptr bp,
146 void *context, bool request_fast_unwind) {
147 Thread *t = GetCurrentThread();
149 // the thread is still being created.
153 if (!StackTrace::WillUseFastUnwind(request_fast_unwind)) {
154 // Block reports from our interceptors during _Unwind_Backtrace.
155 SymbolizerScope sym_scope;
156 return stack->Unwind(max_s, pc, bp, context, 0, 0, request_fast_unwind);
158 stack->Unwind(max_s, pc, bp, context, t->stack_top(), t->stack_bottom(),
159 request_fast_unwind);
162 static void HWAsanCheckFailed(const char *file, int line, const char *cond,
164 Report("HWAddressSanitizer CHECK failed: %s:%d \"%s\" (0x%zx, 0x%zx)\n", file,
165 line, cond, (uptr)v1, (uptr)v2);
166 PRINT_CURRENT_STACK_CHECK();
170 static constexpr uptr kMemoryUsageBufferSize = 4096;
172 static void HwasanFormatMemoryUsage(InternalScopedString &s) {
173 HwasanThreadList &thread_list = hwasanThreadList();
174 auto thread_stats = thread_list.GetThreadStats();
175 auto *sds = StackDepotGetStats();
176 AllocatorStatCounters asc;
177 GetAllocatorStats(asc);
179 "HWASAN pid: %d rss: %zd threads: %zd stacks: %zd"
180 " thr_aux: %zd stack_depot: %zd uniq_stacks: %zd"
182 internal_getpid(), GetRSS(), thread_stats.n_live_threads,
183 thread_stats.total_stack_size,
184 thread_stats.n_live_threads * thread_list.MemoryUsedPerThread(),
185 sds->allocated, sds->n_uniq_ids, asc[AllocatorStatMapped]);
188 #if SANITIZER_ANDROID
189 static char *memory_usage_buffer = nullptr;
191 #define PR_SET_VMA 0x53564d41
192 #define PR_SET_VMA_ANON_NAME 0
194 static void InitMemoryUsage() {
195 memory_usage_buffer =
196 (char *)MmapOrDie(kMemoryUsageBufferSize, "memory usage string");
197 CHECK(memory_usage_buffer);
198 memory_usage_buffer[0] = '\0';
199 CHECK(internal_prctl(PR_SET_VMA, PR_SET_VMA_ANON_NAME,
200 (uptr)memory_usage_buffer, kMemoryUsageBufferSize,
201 (uptr)memory_usage_buffer) == 0);
204 void UpdateMemoryUsage() {
205 if (!flags()->export_memory_stats)
207 if (!memory_usage_buffer)
209 InternalScopedString s(kMemoryUsageBufferSize);
210 HwasanFormatMemoryUsage(s);
211 internal_strncpy(memory_usage_buffer, s.data(), kMemoryUsageBufferSize - 1);
212 memory_usage_buffer[kMemoryUsageBufferSize - 1] = '\0';
215 void UpdateMemoryUsage() {}
218 struct FrameDescription {
223 struct FrameDescriptionArray {
224 FrameDescription *beg, *end;
227 static InternalMmapVectorNoCtor<FrameDescriptionArray> AllFrames;
229 void InitFrameDescriptors(uptr b, uptr e) {
230 FrameDescription *beg = reinterpret_cast<FrameDescription *>(b);
231 FrameDescription *end = reinterpret_cast<FrameDescription *>(e);
234 AllFrames.push_back({beg, end});
236 for (FrameDescription *frame_descr = beg; frame_descr < end; frame_descr++)
237 Printf("Frame: %p %s\n", frame_descr->PC, frame_descr->Descr);
240 const char *GetStackFrameDescr(uptr pc) {
241 for (uptr i = 0, n = AllFrames.size(); i < n; i++)
242 for (auto p = AllFrames[i].beg; p < AllFrames[i].end; p++)
248 } // namespace __hwasan
252 using namespace __hwasan;
254 uptr __hwasan_shadow_memory_dynamic_address; // Global interface symbol.
256 void __hwasan_shadow_init() {
257 if (hwasan_shadow_inited) return;
259 Printf("FATAL: HWAddressSanitizer cannot mmap the shadow memory.\n");
263 hwasan_shadow_inited = 1;
266 void __hwasan_init_frames(uptr beg, uptr end) {
267 InitFrameDescriptors(beg, end);
270 void __hwasan_init() {
271 CHECK(!hwasan_init_is_running);
272 if (hwasan_inited) return;
273 hwasan_init_is_running = 1;
274 SanitizerToolName = "HWAddressSanitizer";
281 // Install tool-specific callbacks in sanitizer_common.
282 SetCheckFailedCallback(HWAsanCheckFailed);
284 __sanitizer_set_report_path(common_flags()->log_path);
286 AndroidTestTlsSlot();
288 DisableCoreDumperIfNecessary();
290 __hwasan_shadow_init();
293 hwasanThreadList().CreateCurrentThread();
297 SetPrintfAndReportCallback(AppendToErrorMessageBuffer);
298 // This may call libc -> needs initialized shadow.
301 InitializeInterceptors();
302 InstallDeadlySignalHandlers(HwasanOnDeadlySignal);
303 InstallAtExitHandler(); // Needs __cxa_atexit interceptor.
305 Symbolizer::GetOrInit()->AddHooks(EnterSymbolizer, ExitSymbolizer);
307 InitializeCoverage(common_flags()->coverage, common_flags()->coverage_dir);
310 HwasanTSDThreadInit();
312 HwasanAllocatorInit();
314 #if HWASAN_CONTAINS_UBSAN
315 __ubsan::InitAsPlugin();
318 VPrintf(1, "HWAddressSanitizer init done\n");
320 hwasan_init_is_running = 0;
324 void __hwasan_print_shadow(const void *p, uptr sz) {
325 uptr ptr_raw = UntagAddr(reinterpret_cast<uptr>(p));
326 uptr shadow_first = MemToShadow(ptr_raw);
327 uptr shadow_last = MemToShadow(ptr_raw + sz - 1);
328 Printf("HWASan shadow map for %zx .. %zx (pointer tag %x)\n", ptr_raw,
329 ptr_raw + sz, GetTagFromPointer((uptr)p));
330 for (uptr s = shadow_first; s <= shadow_last; ++s)
331 Printf(" %zx: %x\n", ShadowToMem(s), *(tag_t *)s);
334 sptr __hwasan_test_shadow(const void *p, uptr sz) {
337 tag_t ptr_tag = GetTagFromPointer((uptr)p);
340 uptr ptr_raw = UntagAddr(reinterpret_cast<uptr>(p));
341 uptr shadow_first = MemToShadow(ptr_raw);
342 uptr shadow_last = MemToShadow(ptr_raw + sz - 1);
343 for (uptr s = shadow_first; s <= shadow_last; ++s)
344 if (*(tag_t*)s != ptr_tag)
345 return ShadowToMem(s) - ptr_raw;
349 u16 __sanitizer_unaligned_load16(const uu16 *p) {
352 u32 __sanitizer_unaligned_load32(const uu32 *p) {
355 u64 __sanitizer_unaligned_load64(const uu64 *p) {
358 void __sanitizer_unaligned_store16(uu16 *p, u16 x) {
361 void __sanitizer_unaligned_store32(uu32 *p, u32 x) {
364 void __sanitizer_unaligned_store64(uu64 *p, u64 x) {
368 void __hwasan_loadN(uptr p, uptr sz) {
369 CheckAddressSized<ErrorAction::Abort, AccessType::Load>(p, sz);
371 void __hwasan_load1(uptr p) {
372 CheckAddress<ErrorAction::Abort, AccessType::Load, 0>(p);
374 void __hwasan_load2(uptr p) {
375 CheckAddress<ErrorAction::Abort, AccessType::Load, 1>(p);
377 void __hwasan_load4(uptr p) {
378 CheckAddress<ErrorAction::Abort, AccessType::Load, 2>(p);
380 void __hwasan_load8(uptr p) {
381 CheckAddress<ErrorAction::Abort, AccessType::Load, 3>(p);
383 void __hwasan_load16(uptr p) {
384 CheckAddress<ErrorAction::Abort, AccessType::Load, 4>(p);
387 void __hwasan_loadN_noabort(uptr p, uptr sz) {
388 CheckAddressSized<ErrorAction::Recover, AccessType::Load>(p, sz);
390 void __hwasan_load1_noabort(uptr p) {
391 CheckAddress<ErrorAction::Recover, AccessType::Load, 0>(p);
393 void __hwasan_load2_noabort(uptr p) {
394 CheckAddress<ErrorAction::Recover, AccessType::Load, 1>(p);
396 void __hwasan_load4_noabort(uptr p) {
397 CheckAddress<ErrorAction::Recover, AccessType::Load, 2>(p);
399 void __hwasan_load8_noabort(uptr p) {
400 CheckAddress<ErrorAction::Recover, AccessType::Load, 3>(p);
402 void __hwasan_load16_noabort(uptr p) {
403 CheckAddress<ErrorAction::Recover, AccessType::Load, 4>(p);
406 void __hwasan_storeN(uptr p, uptr sz) {
407 CheckAddressSized<ErrorAction::Abort, AccessType::Store>(p, sz);
409 void __hwasan_store1(uptr p) {
410 CheckAddress<ErrorAction::Abort, AccessType::Store, 0>(p);
412 void __hwasan_store2(uptr p) {
413 CheckAddress<ErrorAction::Abort, AccessType::Store, 1>(p);
415 void __hwasan_store4(uptr p) {
416 CheckAddress<ErrorAction::Abort, AccessType::Store, 2>(p);
418 void __hwasan_store8(uptr p) {
419 CheckAddress<ErrorAction::Abort, AccessType::Store, 3>(p);
421 void __hwasan_store16(uptr p) {
422 CheckAddress<ErrorAction::Abort, AccessType::Store, 4>(p);
425 void __hwasan_storeN_noabort(uptr p, uptr sz) {
426 CheckAddressSized<ErrorAction::Recover, AccessType::Store>(p, sz);
428 void __hwasan_store1_noabort(uptr p) {
429 CheckAddress<ErrorAction::Recover, AccessType::Store, 0>(p);
431 void __hwasan_store2_noabort(uptr p) {
432 CheckAddress<ErrorAction::Recover, AccessType::Store, 1>(p);
434 void __hwasan_store4_noabort(uptr p) {
435 CheckAddress<ErrorAction::Recover, AccessType::Store, 2>(p);
437 void __hwasan_store8_noabort(uptr p) {
438 CheckAddress<ErrorAction::Recover, AccessType::Store, 3>(p);
440 void __hwasan_store16_noabort(uptr p) {
441 CheckAddress<ErrorAction::Recover, AccessType::Store, 4>(p);
444 void __hwasan_tag_memory(uptr p, u8 tag, uptr sz) {
445 TagMemoryAligned(p, sz, tag);
448 uptr __hwasan_tag_pointer(uptr p, u8 tag) {
449 return AddTagToPointer(p, tag);
452 void __hwasan_handle_longjmp(const void *sp_dst) {
453 uptr dst = (uptr)sp_dst;
454 // HWASan does not support tagged SP.
455 CHECK(GetTagFromPointer(dst) == 0);
457 uptr sp = (uptr)__builtin_frame_address(0);
458 static const uptr kMaxExpectedCleanupSize = 64 << 20; // 64M
459 if (dst < sp || dst - sp > kMaxExpectedCleanupSize) {
461 "WARNING: HWASan is ignoring requested __hwasan_handle_longjmp: "
462 "stack top: %p; target %p; distance: %p (%zd)\n"
463 "False positive error reports may follow\n",
464 (void *)sp, (void *)dst, dst - sp);
467 TagMemory(sp, dst - sp, 0);
470 void __hwasan_print_memory_usage() {
471 InternalScopedString s(kMemoryUsageBufferSize);
472 HwasanFormatMemoryUsage(s);
473 Printf("%s\n", s.data());
476 static const u8 kFallbackTag = 0xBB;
478 u8 __hwasan_generate_tag() {
479 Thread *t = GetCurrentThread();
480 if (!t) return kFallbackTag;
481 return t->GenerateRandomTag();
484 #if !SANITIZER_SUPPORTS_WEAK_HOOKS
486 SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
487 const char* __hwasan_default_options() { return ""; }
492 SANITIZER_INTERFACE_ATTRIBUTE
493 void __sanitizer_print_stack_trace() {
494 GET_FATAL_STACK_TRACE_PC_BP(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME());