sanitizer_coverage_libcdep_new.cpp 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276
  1. //===-- sanitizer_coverage_libcdep_new.cpp --------------------------------===//
  2. //
  3. // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
  4. // See https://llvm.org/LICENSE.txt for license information.
  5. // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
  6. //
  7. //===----------------------------------------------------------------------===//
  8. // Sanitizer Coverage Controller for Trace PC Guard.
  9. #include "sanitizer_platform.h"
  10. #if !SANITIZER_FUCHSIA
  11. #include "sancov_flags.h"
  12. #include "sanitizer_allocator_internal.h"
  13. #include "sanitizer_atomic.h"
  14. #include "sanitizer_common.h"
  15. #include "sanitizer_file.h"
  16. using namespace __sanitizer;
  17. using AddressRange = LoadedModule::AddressRange;
  18. namespace __sancov {
  19. namespace {
  20. static const u64 Magic64 = 0xC0BFFFFFFFFFFF64ULL;
  21. static const u64 Magic32 = 0xC0BFFFFFFFFFFF32ULL;
  22. static const u64 Magic = SANITIZER_WORDSIZE == 64 ? Magic64 : Magic32;
  23. static fd_t OpenFile(const char* path) {
  24. error_t err;
  25. fd_t fd = OpenFile(path, WrOnly, &err);
  26. if (fd == kInvalidFd)
  27. Report("SanitizerCoverage: failed to open %s for writing (reason: %d)\n",
  28. path, err);
  29. return fd;
  30. }
  31. static void GetCoverageFilename(char* path, const char* name,
  32. const char* extension) {
  33. CHECK(name);
  34. internal_snprintf(path, kMaxPathLength, "%s/%s.%zd.%s",
  35. common_flags()->coverage_dir, name, internal_getpid(),
  36. extension);
  37. }
  38. static void WriteModuleCoverage(char* file_path, const char* module_name,
  39. const uptr* pcs, uptr len) {
  40. GetCoverageFilename(file_path, StripModuleName(module_name), "sancov");
  41. fd_t fd = OpenFile(file_path);
  42. WriteToFile(fd, &Magic, sizeof(Magic));
  43. WriteToFile(fd, pcs, len * sizeof(*pcs));
  44. CloseFile(fd);
  45. Printf("SanitizerCoverage: %s: %zd PCs written\n", file_path, len);
  46. }
  47. static void SanitizerDumpCoverage(const uptr* unsorted_pcs, uptr len) {
  48. if (!len) return;
  49. char* file_path = static_cast<char*>(InternalAlloc(kMaxPathLength));
  50. char* module_name = static_cast<char*>(InternalAlloc(kMaxPathLength));
  51. uptr* pcs = static_cast<uptr*>(InternalAlloc(len * sizeof(uptr)));
  52. internal_memcpy(pcs, unsorted_pcs, len * sizeof(uptr));
  53. Sort(pcs, len);
  54. bool module_found = false;
  55. uptr last_base = 0;
  56. uptr module_start_idx = 0;
  57. for (uptr i = 0; i < len; ++i) {
  58. const uptr pc = pcs[i];
  59. if (!pc) continue;
  60. if (!__sanitizer_get_module_and_offset_for_pc(pc, nullptr, 0, &pcs[i])) {
  61. Printf("ERROR: unknown pc 0x%zx (may happen if dlclose is used)\n", pc);
  62. continue;
  63. }
  64. uptr module_base = pc - pcs[i];
  65. if (module_base != last_base || !module_found) {
  66. if (module_found) {
  67. WriteModuleCoverage(file_path, module_name, &pcs[module_start_idx],
  68. i - module_start_idx);
  69. }
  70. last_base = module_base;
  71. module_start_idx = i;
  72. module_found = true;
  73. __sanitizer_get_module_and_offset_for_pc(pc, module_name, kMaxPathLength,
  74. &pcs[i]);
  75. }
  76. }
  77. if (module_found) {
  78. WriteModuleCoverage(file_path, module_name, &pcs[module_start_idx],
  79. len - module_start_idx);
  80. }
  81. InternalFree(file_path);
  82. InternalFree(module_name);
  83. InternalFree(pcs);
  84. }
  85. // Collects trace-pc guard coverage.
  86. // This class relies on zero-initialization.
  87. class TracePcGuardController {
  88. public:
  89. void Initialize() {
  90. CHECK(!initialized);
  91. initialized = true;
  92. InitializeSancovFlags();
  93. pc_vector.Initialize(0);
  94. }
  95. void InitTracePcGuard(u32* start, u32* end) {
  96. if (!initialized) Initialize();
  97. CHECK(!*start);
  98. CHECK_NE(start, end);
  99. u32 i = pc_vector.size();
  100. for (u32* p = start; p < end; p++) *p = ++i;
  101. pc_vector.resize(i);
  102. }
  103. void TracePcGuard(u32* guard, uptr pc) {
  104. u32 idx = *guard;
  105. if (!idx) return;
  106. // we start indices from 1.
  107. atomic_uintptr_t* pc_ptr =
  108. reinterpret_cast<atomic_uintptr_t*>(&pc_vector[idx - 1]);
  109. if (atomic_load(pc_ptr, memory_order_relaxed) == 0)
  110. atomic_store(pc_ptr, pc, memory_order_relaxed);
  111. }
  112. void Reset() {
  113. internal_memset(&pc_vector[0], 0, sizeof(pc_vector[0]) * pc_vector.size());
  114. }
  115. void Dump() {
  116. if (!initialized || !common_flags()->coverage) return;
  117. __sanitizer_dump_coverage(pc_vector.data(), pc_vector.size());
  118. }
  119. private:
  120. bool initialized;
  121. InternalMmapVectorNoCtor<uptr> pc_vector;
  122. };
  123. static TracePcGuardController pc_guard_controller;
  124. // A basic default implementation of callbacks for
  125. // -fsanitize-coverage=inline-8bit-counters,pc-table.
  126. // Use TOOL_OPTIONS (UBSAN_OPTIONS, etc) to dump the coverage data:
  127. // * cov_8bit_counters_out=PATH to dump the 8bit counters.
  128. // * cov_pcs_out=PATH to dump the pc table.
  129. //
  130. // Most users will still need to define their own callbacks for greater
  131. // flexibility.
  132. namespace SingletonCounterCoverage {
  133. static char *counters_beg, *counters_end;
  134. static const uptr *pcs_beg, *pcs_end;
  135. static void DumpCoverage() {
  136. const char* file_path = common_flags()->cov_8bit_counters_out;
  137. if (file_path && internal_strlen(file_path)) {
  138. fd_t fd = OpenFile(file_path);
  139. FileCloser file_closer(fd);
  140. uptr size = counters_end - counters_beg;
  141. WriteToFile(fd, counters_beg, size);
  142. if (common_flags()->verbosity)
  143. __sanitizer::Printf("cov_8bit_counters_out: written %zd bytes to %s\n",
  144. size, file_path);
  145. }
  146. file_path = common_flags()->cov_pcs_out;
  147. if (file_path && internal_strlen(file_path)) {
  148. fd_t fd = OpenFile(file_path);
  149. FileCloser file_closer(fd);
  150. uptr size = (pcs_end - pcs_beg) * sizeof(uptr);
  151. WriteToFile(fd, pcs_beg, size);
  152. if (common_flags()->verbosity)
  153. __sanitizer::Printf("cov_pcs_out: written %zd bytes to %s\n", size,
  154. file_path);
  155. }
  156. }
  157. static void Cov8bitCountersInit(char* beg, char* end) {
  158. counters_beg = beg;
  159. counters_end = end;
  160. Atexit(DumpCoverage);
  161. }
  162. static void CovPcsInit(const uptr* beg, const uptr* end) {
  163. pcs_beg = beg;
  164. pcs_end = end;
  165. }
  166. } // namespace SingletonCounterCoverage
  167. } // namespace
  168. } // namespace __sancov
  169. namespace __sanitizer {
  170. void InitializeCoverage(bool enabled, const char *dir) {
  171. static bool coverage_enabled = false;
  172. if (coverage_enabled)
  173. return; // May happen if two sanitizer enable coverage in the same process.
  174. coverage_enabled = enabled;
  175. Atexit(__sanitizer_cov_dump);
  176. AddDieCallback(__sanitizer_cov_dump);
  177. }
  178. } // namespace __sanitizer
  179. extern "C" {
  180. SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_dump_coverage(const uptr* pcs,
  181. uptr len) {
  182. return __sancov::SanitizerDumpCoverage(pcs, len);
  183. }
  184. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard, u32* guard) {
  185. if (!*guard) return;
  186. __sancov::pc_guard_controller.TracePcGuard(guard, GET_CALLER_PC() - 1);
  187. }
  188. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard_init,
  189. u32* start, u32* end) {
  190. if (start == end || *start) return;
  191. __sancov::pc_guard_controller.InitTracePcGuard(start, end);
  192. }
  193. SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_dump_trace_pc_guard_coverage() {
  194. __sancov::pc_guard_controller.Dump();
  195. }
  196. SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_cov_dump() {
  197. __sanitizer_dump_trace_pc_guard_coverage();
  198. }
  199. SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_cov_reset() {
  200. __sancov::pc_guard_controller.Reset();
  201. }
  202. // Default implementations (weak).
  203. // Either empty or very simple.
  204. // Most users should redefine them.
  205. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp, void) {}
  206. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp1, void) {}
  207. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp2, void) {}
  208. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp4, void) {}
  209. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp8, void) {}
  210. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp1, void) {}
  211. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp2, void) {}
  212. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp4, void) {}
  213. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp8, void) {}
  214. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_switch, void) {}
  215. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_div4, void) {}
  216. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_div8, void) {}
  217. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_gep, void) {}
  218. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_indir, void) {}
  219. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_8bit_counters_init,
  220. char* start, char* end) {
  221. __sancov::SingletonCounterCoverage::Cov8bitCountersInit(start, end);
  222. }
  223. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_bool_flag_init, void) {}
  224. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_pcs_init, const uptr* beg,
  225. const uptr* end) {
  226. __sancov::SingletonCounterCoverage::CovPcsInit(beg, end);
  227. }
  228. } // extern "C"
  229. // Weak definition for code instrumented with -fsanitize-coverage=stack-depth
  230. // and later linked with code containing a strong definition.
  231. // E.g., -fsanitize=fuzzer-no-link
  232. SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
  233. SANITIZER_TLS_INITIAL_EXEC_ATTRIBUTE uptr __sancov_lowest_stack;
  234. #endif // !SANITIZER_FUCHSIA