dfsan_custom.cpp 93 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488
  1. //===-- dfsan_custom.cpp --------------------------------------------------===//
  2. //
  3. // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
  4. // See https://llvm.org/LICENSE.txt for license information.
  5. // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
  6. //
  7. //===----------------------------------------------------------------------===//
  8. //
  9. // This file is a part of DataFlowSanitizer.
  10. //
  11. // This file defines the custom functions listed in done_abilist.txt.
  12. //===----------------------------------------------------------------------===//
  13. #include <arpa/inet.h>
  14. #include <assert.h>
  15. #include <ctype.h>
  16. #include <dlfcn.h>
  17. #include <link.h>
  18. #include <poll.h>
  19. #include <pthread.h>
  20. #include <pwd.h>
  21. #include <sched.h>
  22. #include <signal.h>
  23. #include <stdarg.h>
  24. #include <stdint.h>
  25. #include <stdio.h>
  26. #include <stdlib.h>
  27. #include <string.h>
  28. #include <sys/epoll.h>
  29. #include <sys/resource.h>
  30. #include <sys/select.h>
  31. #include <sys/socket.h>
  32. #include <sys/stat.h>
  33. #include <sys/time.h>
  34. #include <sys/types.h>
  35. #include <time.h>
  36. #include <unistd.h>
  37. #include "dfsan/dfsan.h"
  38. #include "dfsan/dfsan_chained_origin_depot.h"
  39. #include "dfsan/dfsan_flags.h"
  40. #include "dfsan/dfsan_thread.h"
  41. #include "sanitizer_common/sanitizer_common.h"
  42. #include "sanitizer_common/sanitizer_internal_defs.h"
  43. #include "sanitizer_common/sanitizer_linux.h"
  44. #include "sanitizer_common/sanitizer_stackdepot.h"
  45. using namespace __dfsan;
  46. #define CALL_WEAK_INTERCEPTOR_HOOK(f, ...) \
  47. do { \
  48. if (f) \
  49. f(__VA_ARGS__); \
  50. } while (false)
  51. #define DECLARE_WEAK_INTERCEPTOR_HOOK(f, ...) \
  52. SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE void f(__VA_ARGS__);
  53. // Async-safe, non-reentrant spin lock.
  54. class SignalSpinLocker {
  55. public:
  56. SignalSpinLocker() {
  57. sigset_t all_set;
  58. sigfillset(&all_set);
  59. pthread_sigmask(SIG_SETMASK, &all_set, &saved_thread_mask_);
  60. sigactions_mu.Lock();
  61. }
  62. ~SignalSpinLocker() {
  63. sigactions_mu.Unlock();
  64. pthread_sigmask(SIG_SETMASK, &saved_thread_mask_, nullptr);
  65. }
  66. private:
  67. static StaticSpinMutex sigactions_mu;
  68. sigset_t saved_thread_mask_;
  69. SignalSpinLocker(const SignalSpinLocker &) = delete;
  70. SignalSpinLocker &operator=(const SignalSpinLocker &) = delete;
  71. };
  72. StaticSpinMutex SignalSpinLocker::sigactions_mu;
  73. extern "C" {
  74. SANITIZER_INTERFACE_ATTRIBUTE int
  75. __dfsw_stat(const char *path, struct stat *buf, dfsan_label path_label,
  76. dfsan_label buf_label, dfsan_label *ret_label) {
  77. int ret = stat(path, buf);
  78. if (ret == 0)
  79. dfsan_set_label(0, buf, sizeof(struct stat));
  80. *ret_label = 0;
  81. return ret;
  82. }
  83. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_stat(
  84. const char *path, struct stat *buf, dfsan_label path_label,
  85. dfsan_label buf_label, dfsan_label *ret_label, dfsan_origin path_origin,
  86. dfsan_origin buf_origin, dfsan_origin *ret_origin) {
  87. int ret = __dfsw_stat(path, buf, path_label, buf_label, ret_label);
  88. return ret;
  89. }
  90. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_fstat(int fd, struct stat *buf,
  91. dfsan_label fd_label,
  92. dfsan_label buf_label,
  93. dfsan_label *ret_label) {
  94. int ret = fstat(fd, buf);
  95. if (ret == 0)
  96. dfsan_set_label(0, buf, sizeof(struct stat));
  97. *ret_label = 0;
  98. return ret;
  99. }
  100. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_fstat(
  101. int fd, struct stat *buf, dfsan_label fd_label, dfsan_label buf_label,
  102. dfsan_label *ret_label, dfsan_origin fd_origin, dfsan_origin buf_origin,
  103. dfsan_origin *ret_origin) {
  104. int ret = __dfsw_fstat(fd, buf, fd_label, buf_label, ret_label);
  105. return ret;
  106. }
  107. static char *dfsan_strchr_with_label(const char *s, int c, size_t *bytes_read,
  108. dfsan_label s_label, dfsan_label c_label,
  109. dfsan_label *ret_label) {
  110. char *match_pos = nullptr;
  111. for (size_t i = 0;; ++i) {
  112. if (s[i] == c || s[i] == 0) {
  113. // If s[i] is the \0 at the end of the string, and \0 is not the
  114. // character we are searching for, then return null.
  115. *bytes_read = i + 1;
  116. match_pos = s[i] == 0 && c != 0 ? nullptr : const_cast<char *>(s + i);
  117. break;
  118. }
  119. }
  120. if (flags().strict_data_dependencies)
  121. *ret_label = s_label;
  122. else
  123. *ret_label = dfsan_union(dfsan_read_label(s, *bytes_read),
  124. dfsan_union(s_label, c_label));
  125. return match_pos;
  126. }
  127. SANITIZER_INTERFACE_ATTRIBUTE char *__dfsw_strchr(const char *s, int c,
  128. dfsan_label s_label,
  129. dfsan_label c_label,
  130. dfsan_label *ret_label) {
  131. size_t bytes_read;
  132. return dfsan_strchr_with_label(s, c, &bytes_read, s_label, c_label,
  133. ret_label);
  134. }
  135. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strchr(
  136. const char *s, int c, dfsan_label s_label, dfsan_label c_label,
  137. dfsan_label *ret_label, dfsan_origin s_origin, dfsan_origin c_origin,
  138. dfsan_origin *ret_origin) {
  139. size_t bytes_read;
  140. char *r =
  141. dfsan_strchr_with_label(s, c, &bytes_read, s_label, c_label, ret_label);
  142. if (flags().strict_data_dependencies) {
  143. *ret_origin = s_origin;
  144. } else if (*ret_label) {
  145. dfsan_origin o = dfsan_read_origin_of_first_taint(s, bytes_read);
  146. *ret_origin = o ? o : (s_label ? s_origin : c_origin);
  147. }
  148. return r;
  149. }
  150. SANITIZER_INTERFACE_ATTRIBUTE char *__dfsw_strpbrk(const char *s,
  151. const char *accept,
  152. dfsan_label s_label,
  153. dfsan_label accept_label,
  154. dfsan_label *ret_label) {
  155. const char *ret = strpbrk(s, accept);
  156. if (flags().strict_data_dependencies) {
  157. *ret_label = ret ? s_label : 0;
  158. } else {
  159. size_t s_bytes_read = (ret ? ret - s : strlen(s)) + 1;
  160. *ret_label =
  161. dfsan_union(dfsan_read_label(s, s_bytes_read),
  162. dfsan_union(dfsan_read_label(accept, strlen(accept) + 1),
  163. dfsan_union(s_label, accept_label)));
  164. }
  165. return const_cast<char *>(ret);
  166. }
  167. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strpbrk(
  168. const char *s, const char *accept, dfsan_label s_label,
  169. dfsan_label accept_label, dfsan_label *ret_label, dfsan_origin s_origin,
  170. dfsan_origin accept_origin, dfsan_origin *ret_origin) {
  171. const char *ret = __dfsw_strpbrk(s, accept, s_label, accept_label, ret_label);
  172. if (flags().strict_data_dependencies) {
  173. if (ret)
  174. *ret_origin = s_origin;
  175. } else {
  176. if (*ret_label) {
  177. size_t s_bytes_read = (ret ? ret - s : strlen(s)) + 1;
  178. dfsan_origin o = dfsan_read_origin_of_first_taint(s, s_bytes_read);
  179. if (o) {
  180. *ret_origin = o;
  181. } else {
  182. o = dfsan_read_origin_of_first_taint(accept, strlen(accept) + 1);
  183. *ret_origin = o ? o : (s_label ? s_origin : accept_origin);
  184. }
  185. }
  186. }
  187. return const_cast<char *>(ret);
  188. }
  189. static int dfsan_memcmp_bcmp(const void *s1, const void *s2, size_t n,
  190. size_t *bytes_read) {
  191. const char *cs1 = (const char *) s1, *cs2 = (const char *) s2;
  192. for (size_t i = 0; i != n; ++i) {
  193. if (cs1[i] != cs2[i]) {
  194. *bytes_read = i + 1;
  195. return cs1[i] - cs2[i];
  196. }
  197. }
  198. *bytes_read = n;
  199. return 0;
  200. }
  201. static dfsan_label dfsan_get_memcmp_label(const void *s1, const void *s2,
  202. size_t pos) {
  203. if (flags().strict_data_dependencies)
  204. return 0;
  205. return dfsan_union(dfsan_read_label(s1, pos), dfsan_read_label(s2, pos));
  206. }
  207. static void dfsan_get_memcmp_origin(const void *s1, const void *s2, size_t pos,
  208. dfsan_label *ret_label,
  209. dfsan_origin *ret_origin) {
  210. *ret_label = dfsan_get_memcmp_label(s1, s2, pos);
  211. if (*ret_label == 0)
  212. return;
  213. dfsan_origin o = dfsan_read_origin_of_first_taint(s1, pos);
  214. *ret_origin = o ? o : dfsan_read_origin_of_first_taint(s2, pos);
  215. }
  216. static int dfsan_memcmp_bcmp_label(const void *s1, const void *s2, size_t n,
  217. dfsan_label *ret_label) {
  218. size_t bytes_read;
  219. int r = dfsan_memcmp_bcmp(s1, s2, n, &bytes_read);
  220. *ret_label = dfsan_get_memcmp_label(s1, s2, bytes_read);
  221. return r;
  222. }
  223. static int dfsan_memcmp_bcmp_origin(const void *s1, const void *s2, size_t n,
  224. dfsan_label *ret_label,
  225. dfsan_origin *ret_origin) {
  226. size_t bytes_read;
  227. int r = dfsan_memcmp_bcmp(s1, s2, n, &bytes_read);
  228. dfsan_get_memcmp_origin(s1, s2, bytes_read, ret_label, ret_origin);
  229. return r;
  230. }
  231. DECLARE_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_memcmp, uptr caller_pc,
  232. const void *s1, const void *s2, size_t n,
  233. dfsan_label s1_label, dfsan_label s2_label,
  234. dfsan_label n_label)
  235. DECLARE_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_origin_memcmp, uptr caller_pc,
  236. const void *s1, const void *s2, size_t n,
  237. dfsan_label s1_label, dfsan_label s2_label,
  238. dfsan_label n_label, dfsan_origin s1_origin,
  239. dfsan_origin s2_origin, dfsan_origin n_origin)
  240. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_memcmp(const void *s1, const void *s2,
  241. size_t n, dfsan_label s1_label,
  242. dfsan_label s2_label,
  243. dfsan_label n_label,
  244. dfsan_label *ret_label) {
  245. CALL_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_memcmp, GET_CALLER_PC(), s1, s2, n,
  246. s1_label, s2_label, n_label);
  247. return dfsan_memcmp_bcmp_label(s1, s2, n, ret_label);
  248. }
  249. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_memcmp(
  250. const void *s1, const void *s2, size_t n, dfsan_label s1_label,
  251. dfsan_label s2_label, dfsan_label n_label, dfsan_label *ret_label,
  252. dfsan_origin s1_origin, dfsan_origin s2_origin, dfsan_origin n_origin,
  253. dfsan_origin *ret_origin) {
  254. CALL_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_origin_memcmp, GET_CALLER_PC(), s1,
  255. s2, n, s1_label, s2_label, n_label, s1_origin,
  256. s2_origin, n_origin);
  257. return dfsan_memcmp_bcmp_origin(s1, s2, n, ret_label, ret_origin);
  258. }
  259. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_bcmp(const void *s1, const void *s2,
  260. size_t n, dfsan_label s1_label,
  261. dfsan_label s2_label,
  262. dfsan_label n_label,
  263. dfsan_label *ret_label) {
  264. return dfsan_memcmp_bcmp_label(s1, s2, n, ret_label);
  265. }
  266. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_bcmp(
  267. const void *s1, const void *s2, size_t n, dfsan_label s1_label,
  268. dfsan_label s2_label, dfsan_label n_label, dfsan_label *ret_label,
  269. dfsan_origin s1_origin, dfsan_origin s2_origin, dfsan_origin n_origin,
  270. dfsan_origin *ret_origin) {
  271. return dfsan_memcmp_bcmp_origin(s1, s2, n, ret_label, ret_origin);
  272. }
  273. // When n == 0, compare strings without byte limit.
  274. // When n > 0, compare the first (at most) n bytes of s1 and s2.
  275. static int dfsan_strncmp(const char *s1, const char *s2, size_t n,
  276. size_t *bytes_read) {
  277. for (size_t i = 0;; ++i) {
  278. if (s1[i] != s2[i] || s1[i] == 0 || s2[i] == 0 || (n > 0 && i == n - 1)) {
  279. *bytes_read = i + 1;
  280. return s1[i] - s2[i];
  281. }
  282. }
  283. }
  284. DECLARE_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_strcmp, uptr caller_pc,
  285. const char *s1, const char *s2,
  286. dfsan_label s1_label, dfsan_label s2_label)
  287. DECLARE_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_origin_strcmp, uptr caller_pc,
  288. const char *s1, const char *s2,
  289. dfsan_label s1_label, dfsan_label s2_label,
  290. dfsan_origin s1_origin, dfsan_origin s2_origin)
  291. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_strcmp(const char *s1, const char *s2,
  292. dfsan_label s1_label,
  293. dfsan_label s2_label,
  294. dfsan_label *ret_label) {
  295. CALL_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_strcmp, GET_CALLER_PC(), s1, s2,
  296. s1_label, s2_label);
  297. size_t bytes_read;
  298. int r = dfsan_strncmp(s1, s2, 0, &bytes_read);
  299. *ret_label = dfsan_get_memcmp_label(s1, s2, bytes_read);
  300. return r;
  301. }
  302. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_strcmp(
  303. const char *s1, const char *s2, dfsan_label s1_label, dfsan_label s2_label,
  304. dfsan_label *ret_label, dfsan_origin s1_origin, dfsan_origin s2_origin,
  305. dfsan_origin *ret_origin) {
  306. CALL_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_origin_strcmp, GET_CALLER_PC(), s1,
  307. s2, s1_label, s2_label, s1_origin, s2_origin);
  308. size_t bytes_read;
  309. int r = dfsan_strncmp(s1, s2, 0, &bytes_read);
  310. dfsan_get_memcmp_origin(s1, s2, bytes_read, ret_label, ret_origin);
  311. return r;
  312. }
  313. // When n == 0, compare strings without byte limit.
  314. // When n > 0, compare the first (at most) n bytes of s1 and s2.
  315. static int dfsan_strncasecmp(const char *s1, const char *s2, size_t n,
  316. size_t *bytes_read) {
  317. for (size_t i = 0;; ++i) {
  318. char s1_lower = tolower(s1[i]);
  319. char s2_lower = tolower(s2[i]);
  320. if (s1_lower != s2_lower || s1[i] == 0 || s2[i] == 0 ||
  321. (n > 0 && i == n - 1)) {
  322. *bytes_read = i + 1;
  323. return s1_lower - s2_lower;
  324. }
  325. }
  326. }
  327. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_strcasecmp(const char *s1,
  328. const char *s2,
  329. dfsan_label s1_label,
  330. dfsan_label s2_label,
  331. dfsan_label *ret_label) {
  332. size_t bytes_read;
  333. int r = dfsan_strncasecmp(s1, s2, 0, &bytes_read);
  334. *ret_label = dfsan_get_memcmp_label(s1, s2, bytes_read);
  335. return r;
  336. }
  337. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_strcasecmp(
  338. const char *s1, const char *s2, dfsan_label s1_label, dfsan_label s2_label,
  339. dfsan_label *ret_label, dfsan_origin s1_origin, dfsan_origin s2_origin,
  340. dfsan_origin *ret_origin) {
  341. size_t bytes_read;
  342. int r = dfsan_strncasecmp(s1, s2, 0, &bytes_read);
  343. dfsan_get_memcmp_origin(s1, s2, bytes_read, ret_label, ret_origin);
  344. return r;
  345. }
  346. DECLARE_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_strncmp, uptr caller_pc,
  347. const char *s1, const char *s2, size_t n,
  348. dfsan_label s1_label, dfsan_label s2_label,
  349. dfsan_label n_label)
  350. DECLARE_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_origin_strncmp, uptr caller_pc,
  351. const char *s1, const char *s2, size_t n,
  352. dfsan_label s1_label, dfsan_label s2_label,
  353. dfsan_label n_label, dfsan_origin s1_origin,
  354. dfsan_origin s2_origin, dfsan_origin n_origin)
  355. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_strncmp(const char *s1, const char *s2,
  356. size_t n, dfsan_label s1_label,
  357. dfsan_label s2_label,
  358. dfsan_label n_label,
  359. dfsan_label *ret_label) {
  360. if (n == 0) {
  361. *ret_label = 0;
  362. return 0;
  363. }
  364. CALL_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_strncmp, GET_CALLER_PC(), s1, s2,
  365. n, s1_label, s2_label, n_label);
  366. size_t bytes_read;
  367. int r = dfsan_strncmp(s1, s2, n, &bytes_read);
  368. *ret_label = dfsan_get_memcmp_label(s1, s2, bytes_read);
  369. return r;
  370. }
  371. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_strncmp(
  372. const char *s1, const char *s2, size_t n, dfsan_label s1_label,
  373. dfsan_label s2_label, dfsan_label n_label, dfsan_label *ret_label,
  374. dfsan_origin s1_origin, dfsan_origin s2_origin, dfsan_origin n_origin,
  375. dfsan_origin *ret_origin) {
  376. if (n == 0) {
  377. *ret_label = 0;
  378. return 0;
  379. }
  380. CALL_WEAK_INTERCEPTOR_HOOK(dfsan_weak_hook_origin_strncmp, GET_CALLER_PC(),
  381. s1, s2, n, s1_label, s2_label, n_label, s1_origin,
  382. s2_origin, n_origin);
  383. size_t bytes_read;
  384. int r = dfsan_strncmp(s1, s2, n, &bytes_read);
  385. dfsan_get_memcmp_origin(s1, s2, bytes_read, ret_label, ret_origin);
  386. return r;
  387. }
  388. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_strncasecmp(
  389. const char *s1, const char *s2, size_t n, dfsan_label s1_label,
  390. dfsan_label s2_label, dfsan_label n_label, dfsan_label *ret_label) {
  391. if (n == 0) {
  392. *ret_label = 0;
  393. return 0;
  394. }
  395. size_t bytes_read;
  396. int r = dfsan_strncasecmp(s1, s2, n, &bytes_read);
  397. *ret_label = dfsan_get_memcmp_label(s1, s2, bytes_read);
  398. return r;
  399. }
  400. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_strncasecmp(
  401. const char *s1, const char *s2, size_t n, dfsan_label s1_label,
  402. dfsan_label s2_label, dfsan_label n_label, dfsan_label *ret_label,
  403. dfsan_origin s1_origin, dfsan_origin s2_origin, dfsan_origin n_origin,
  404. dfsan_origin *ret_origin) {
  405. if (n == 0) {
  406. *ret_label = 0;
  407. return 0;
  408. }
  409. size_t bytes_read;
  410. int r = dfsan_strncasecmp(s1, s2, n, &bytes_read);
  411. dfsan_get_memcmp_origin(s1, s2, bytes_read, ret_label, ret_origin);
  412. return r;
  413. }
  414. SANITIZER_INTERFACE_ATTRIBUTE size_t
  415. __dfsw_strlen(const char *s, dfsan_label s_label, dfsan_label *ret_label) {
  416. size_t ret = strlen(s);
  417. if (flags().strict_data_dependencies) {
  418. *ret_label = 0;
  419. } else {
  420. *ret_label = dfsan_read_label(s, ret + 1);
  421. }
  422. return ret;
  423. }
  424. SANITIZER_INTERFACE_ATTRIBUTE size_t __dfso_strlen(const char *s,
  425. dfsan_label s_label,
  426. dfsan_label *ret_label,
  427. dfsan_origin s_origin,
  428. dfsan_origin *ret_origin) {
  429. size_t ret = __dfsw_strlen(s, s_label, ret_label);
  430. if (!flags().strict_data_dependencies)
  431. *ret_origin = dfsan_read_origin_of_first_taint(s, ret + 1);
  432. return ret;
  433. }
  434. static void *dfsan_memmove(void *dest, const void *src, size_t n) {
  435. dfsan_label *sdest = shadow_for(dest);
  436. const dfsan_label *ssrc = shadow_for(src);
  437. internal_memmove((void *)sdest, (const void *)ssrc, n * sizeof(dfsan_label));
  438. return internal_memmove(dest, src, n);
  439. }
  440. static void *dfsan_memmove_with_origin(void *dest, const void *src, size_t n) {
  441. dfsan_mem_origin_transfer(dest, src, n);
  442. return dfsan_memmove(dest, src, n);
  443. }
  444. static void *dfsan_memcpy(void *dest, const void *src, size_t n) {
  445. dfsan_mem_shadow_transfer(dest, src, n);
  446. return internal_memcpy(dest, src, n);
  447. }
  448. static void *dfsan_memcpy_with_origin(void *dest, const void *src, size_t n) {
  449. dfsan_mem_origin_transfer(dest, src, n);
  450. return dfsan_memcpy(dest, src, n);
  451. }
  452. static void dfsan_memset(void *s, int c, dfsan_label c_label, size_t n) {
  453. internal_memset(s, c, n);
  454. dfsan_set_label(c_label, s, n);
  455. }
  456. static void dfsan_memset_with_origin(void *s, int c, dfsan_label c_label,
  457. dfsan_origin c_origin, size_t n) {
  458. internal_memset(s, c, n);
  459. dfsan_set_label_origin(c_label, c_origin, s, n);
  460. }
  461. SANITIZER_INTERFACE_ATTRIBUTE
  462. void *__dfsw_memcpy(void *dest, const void *src, size_t n,
  463. dfsan_label dest_label, dfsan_label src_label,
  464. dfsan_label n_label, dfsan_label *ret_label) {
  465. *ret_label = dest_label;
  466. return dfsan_memcpy(dest, src, n);
  467. }
  468. SANITIZER_INTERFACE_ATTRIBUTE
  469. void *__dfso_memcpy(void *dest, const void *src, size_t n,
  470. dfsan_label dest_label, dfsan_label src_label,
  471. dfsan_label n_label, dfsan_label *ret_label,
  472. dfsan_origin dest_origin, dfsan_origin src_origin,
  473. dfsan_origin n_origin, dfsan_origin *ret_origin) {
  474. *ret_label = dest_label;
  475. *ret_origin = dest_origin;
  476. return dfsan_memcpy_with_origin(dest, src, n);
  477. }
  478. SANITIZER_INTERFACE_ATTRIBUTE
  479. void *__dfsw_memmove(void *dest, const void *src, size_t n,
  480. dfsan_label dest_label, dfsan_label src_label,
  481. dfsan_label n_label, dfsan_label *ret_label) {
  482. *ret_label = dest_label;
  483. return dfsan_memmove(dest, src, n);
  484. }
  485. SANITIZER_INTERFACE_ATTRIBUTE
  486. void *__dfso_memmove(void *dest, const void *src, size_t n,
  487. dfsan_label dest_label, dfsan_label src_label,
  488. dfsan_label n_label, dfsan_label *ret_label,
  489. dfsan_origin dest_origin, dfsan_origin src_origin,
  490. dfsan_origin n_origin, dfsan_origin *ret_origin) {
  491. *ret_label = dest_label;
  492. *ret_origin = dest_origin;
  493. return dfsan_memmove_with_origin(dest, src, n);
  494. }
  495. SANITIZER_INTERFACE_ATTRIBUTE
  496. void *__dfsw_memset(void *s, int c, size_t n,
  497. dfsan_label s_label, dfsan_label c_label,
  498. dfsan_label n_label, dfsan_label *ret_label) {
  499. dfsan_memset(s, c, c_label, n);
  500. *ret_label = s_label;
  501. return s;
  502. }
  503. SANITIZER_INTERFACE_ATTRIBUTE
  504. void *__dfso_memset(void *s, int c, size_t n, dfsan_label s_label,
  505. dfsan_label c_label, dfsan_label n_label,
  506. dfsan_label *ret_label, dfsan_origin s_origin,
  507. dfsan_origin c_origin, dfsan_origin n_origin,
  508. dfsan_origin *ret_origin) {
  509. dfsan_memset_with_origin(s, c, c_label, c_origin, n);
  510. *ret_label = s_label;
  511. *ret_origin = s_origin;
  512. return s;
  513. }
  514. SANITIZER_INTERFACE_ATTRIBUTE char *__dfsw_strcat(char *dest, const char *src,
  515. dfsan_label dest_label,
  516. dfsan_label src_label,
  517. dfsan_label *ret_label) {
  518. size_t dest_len = strlen(dest);
  519. char *ret = strcat(dest, src);
  520. dfsan_mem_shadow_transfer(dest + dest_len, src, strlen(src));
  521. *ret_label = dest_label;
  522. return ret;
  523. }
  524. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strcat(
  525. char *dest, const char *src, dfsan_label dest_label, dfsan_label src_label,
  526. dfsan_label *ret_label, dfsan_origin dest_origin, dfsan_origin src_origin,
  527. dfsan_origin *ret_origin) {
  528. size_t dest_len = strlen(dest);
  529. char *ret = strcat(dest, src);
  530. size_t src_len = strlen(src);
  531. dfsan_mem_origin_transfer(dest + dest_len, src, src_len);
  532. dfsan_mem_shadow_transfer(dest + dest_len, src, src_len);
  533. *ret_label = dest_label;
  534. *ret_origin = dest_origin;
  535. return ret;
  536. }
  537. SANITIZER_INTERFACE_ATTRIBUTE char *
  538. __dfsw_strdup(const char *s, dfsan_label s_label, dfsan_label *ret_label) {
  539. size_t len = strlen(s);
  540. void *p = malloc(len+1);
  541. dfsan_memcpy(p, s, len+1);
  542. *ret_label = 0;
  543. return static_cast<char *>(p);
  544. }
  545. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strdup(const char *s,
  546. dfsan_label s_label,
  547. dfsan_label *ret_label,
  548. dfsan_origin s_origin,
  549. dfsan_origin *ret_origin) {
  550. size_t len = strlen(s);
  551. void *p = malloc(len + 1);
  552. dfsan_memcpy_with_origin(p, s, len + 1);
  553. *ret_label = 0;
  554. return static_cast<char *>(p);
  555. }
  556. SANITIZER_INTERFACE_ATTRIBUTE char *
  557. __dfsw_strncpy(char *s1, const char *s2, size_t n, dfsan_label s1_label,
  558. dfsan_label s2_label, dfsan_label n_label,
  559. dfsan_label *ret_label) {
  560. size_t len = strlen(s2);
  561. if (len < n) {
  562. dfsan_memcpy(s1, s2, len+1);
  563. dfsan_memset(s1+len+1, 0, 0, n-len-1);
  564. } else {
  565. dfsan_memcpy(s1, s2, n);
  566. }
  567. *ret_label = s1_label;
  568. return s1;
  569. }
  570. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strncpy(
  571. char *s1, const char *s2, size_t n, dfsan_label s1_label,
  572. dfsan_label s2_label, dfsan_label n_label, dfsan_label *ret_label,
  573. dfsan_origin s1_origin, dfsan_origin s2_origin, dfsan_origin n_origin,
  574. dfsan_origin *ret_origin) {
  575. size_t len = strlen(s2);
  576. if (len < n) {
  577. dfsan_memcpy_with_origin(s1, s2, len + 1);
  578. dfsan_memset_with_origin(s1 + len + 1, 0, 0, 0, n - len - 1);
  579. } else {
  580. dfsan_memcpy_with_origin(s1, s2, n);
  581. }
  582. *ret_label = s1_label;
  583. *ret_origin = s1_origin;
  584. return s1;
  585. }
  586. SANITIZER_INTERFACE_ATTRIBUTE ssize_t
  587. __dfsw_pread(int fd, void *buf, size_t count, off_t offset,
  588. dfsan_label fd_label, dfsan_label buf_label,
  589. dfsan_label count_label, dfsan_label offset_label,
  590. dfsan_label *ret_label) {
  591. ssize_t ret = pread(fd, buf, count, offset);
  592. if (ret > 0)
  593. dfsan_set_label(0, buf, ret);
  594. *ret_label = 0;
  595. return ret;
  596. }
  597. SANITIZER_INTERFACE_ATTRIBUTE ssize_t __dfso_pread(
  598. int fd, void *buf, size_t count, off_t offset, dfsan_label fd_label,
  599. dfsan_label buf_label, dfsan_label count_label, dfsan_label offset_label,
  600. dfsan_label *ret_label, dfsan_origin fd_origin, dfsan_origin buf_origin,
  601. dfsan_origin count_origin, dfsan_label offset_origin,
  602. dfsan_origin *ret_origin) {
  603. return __dfsw_pread(fd, buf, count, offset, fd_label, buf_label, count_label,
  604. offset_label, ret_label);
  605. }
  606. SANITIZER_INTERFACE_ATTRIBUTE ssize_t
  607. __dfsw_read(int fd, void *buf, size_t count,
  608. dfsan_label fd_label, dfsan_label buf_label,
  609. dfsan_label count_label,
  610. dfsan_label *ret_label) {
  611. ssize_t ret = read(fd, buf, count);
  612. if (ret > 0)
  613. dfsan_set_label(0, buf, ret);
  614. *ret_label = 0;
  615. return ret;
  616. }
  617. SANITIZER_INTERFACE_ATTRIBUTE ssize_t __dfso_read(
  618. int fd, void *buf, size_t count, dfsan_label fd_label,
  619. dfsan_label buf_label, dfsan_label count_label, dfsan_label *ret_label,
  620. dfsan_origin fd_origin, dfsan_origin buf_origin, dfsan_origin count_origin,
  621. dfsan_origin *ret_origin) {
  622. return __dfsw_read(fd, buf, count, fd_label, buf_label, count_label,
  623. ret_label);
  624. }
  625. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_clock_gettime(clockid_t clk_id,
  626. struct timespec *tp,
  627. dfsan_label clk_id_label,
  628. dfsan_label tp_label,
  629. dfsan_label *ret_label) {
  630. int ret = clock_gettime(clk_id, tp);
  631. if (ret == 0)
  632. dfsan_set_label(0, tp, sizeof(struct timespec));
  633. *ret_label = 0;
  634. return ret;
  635. }
  636. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_clock_gettime(
  637. clockid_t clk_id, struct timespec *tp, dfsan_label clk_id_label,
  638. dfsan_label tp_label, dfsan_label *ret_label, dfsan_origin clk_id_origin,
  639. dfsan_origin tp_origin, dfsan_origin *ret_origin) {
  640. return __dfsw_clock_gettime(clk_id, tp, clk_id_label, tp_label, ret_label);
  641. }
  642. static void dfsan_set_zero_label(const void *ptr, uptr size) {
  643. dfsan_set_label(0, const_cast<void *>(ptr), size);
  644. }
  645. // dlopen() ultimately calls mmap() down inside the loader, which generally
  646. // doesn't participate in dynamic symbol resolution. Therefore we won't
  647. // intercept its calls to mmap, and we have to hook it here.
  648. SANITIZER_INTERFACE_ATTRIBUTE void *
  649. __dfsw_dlopen(const char *filename, int flag, dfsan_label filename_label,
  650. dfsan_label flag_label, dfsan_label *ret_label) {
  651. void *handle = dlopen(filename, flag);
  652. link_map *map = GET_LINK_MAP_BY_DLOPEN_HANDLE(handle);
  653. if (map)
  654. ForEachMappedRegion(map, dfsan_set_zero_label);
  655. *ret_label = 0;
  656. return handle;
  657. }
  658. SANITIZER_INTERFACE_ATTRIBUTE void *__dfso_dlopen(
  659. const char *filename, int flag, dfsan_label filename_label,
  660. dfsan_label flag_label, dfsan_label *ret_label,
  661. dfsan_origin filename_origin, dfsan_origin flag_origin,
  662. dfsan_origin *ret_origin) {
  663. return __dfsw_dlopen(filename, flag, filename_label, flag_label, ret_label);
  664. }
  665. static void *DFsanThreadStartFunc(void *arg) {
  666. DFsanThread *t = (DFsanThread *)arg;
  667. SetCurrentThread(t);
  668. t->Init();
  669. SetSigProcMask(&t->starting_sigset_, nullptr);
  670. return t->ThreadStart();
  671. }
  672. static int dfsan_pthread_create(pthread_t *thread, const pthread_attr_t *attr,
  673. void *start_routine, void *arg,
  674. dfsan_label *ret_label,
  675. bool track_origins = false) {
  676. pthread_attr_t myattr;
  677. if (!attr) {
  678. pthread_attr_init(&myattr);
  679. attr = &myattr;
  680. }
  681. // Ensure that the thread stack is large enough to hold all TLS data.
  682. AdjustStackSize((void *)(const_cast<pthread_attr_t *>(attr)));
  683. DFsanThread *t =
  684. DFsanThread::Create((thread_callback_t)start_routine, arg, track_origins);
  685. ScopedBlockSignals block(&t->starting_sigset_);
  686. int res = pthread_create(thread, attr, DFsanThreadStartFunc, t);
  687. if (attr == &myattr)
  688. pthread_attr_destroy(&myattr);
  689. *ret_label = 0;
  690. return res;
  691. }
  692. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_pthread_create(
  693. pthread_t *thread, const pthread_attr_t *attr, void *start_routine,
  694. void *arg, dfsan_label thread_label, dfsan_label attr_label,
  695. dfsan_label start_routine_label, dfsan_label arg_label,
  696. dfsan_label *ret_label) {
  697. return dfsan_pthread_create(thread, attr, start_routine, arg, ret_label);
  698. }
  699. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_pthread_create(
  700. pthread_t *thread, const pthread_attr_t *attr, void *start_routine,
  701. void *arg, dfsan_label thread_label, dfsan_label attr_label,
  702. dfsan_label start_routine_label, dfsan_label arg_label,
  703. dfsan_label *ret_label, dfsan_origin thread_origin,
  704. dfsan_origin attr_origin, dfsan_origin start_routine_origin,
  705. dfsan_origin arg_origin, dfsan_origin *ret_origin) {
  706. return dfsan_pthread_create(thread, attr, start_routine, arg, ret_label,
  707. true);
  708. }
  709. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_pthread_join(pthread_t thread,
  710. void **retval,
  711. dfsan_label thread_label,
  712. dfsan_label retval_label,
  713. dfsan_label *ret_label) {
  714. int ret = pthread_join(thread, retval);
  715. if (ret == 0 && retval)
  716. dfsan_set_label(0, retval, sizeof(*retval));
  717. *ret_label = 0;
  718. return ret;
  719. }
  720. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_pthread_join(
  721. pthread_t thread, void **retval, dfsan_label thread_label,
  722. dfsan_label retval_label, dfsan_label *ret_label,
  723. dfsan_origin thread_origin, dfsan_origin retval_origin,
  724. dfsan_origin *ret_origin) {
  725. return __dfsw_pthread_join(thread, retval, thread_label, retval_label,
  726. ret_label);
  727. }
  728. struct dl_iterate_phdr_info {
  729. int (*callback)(struct dl_phdr_info *info, size_t size, void *data);
  730. void *data;
  731. };
  732. int dl_iterate_phdr_cb(struct dl_phdr_info *info, size_t size, void *data) {
  733. dl_iterate_phdr_info *dipi = (dl_iterate_phdr_info *)data;
  734. dfsan_set_label(0, *info);
  735. dfsan_set_label(0, const_cast<char *>(info->dlpi_name),
  736. strlen(info->dlpi_name) + 1);
  737. dfsan_set_label(
  738. 0, const_cast<char *>(reinterpret_cast<const char *>(info->dlpi_phdr)),
  739. sizeof(*info->dlpi_phdr) * info->dlpi_phnum);
  740. dfsan_clear_thread_local_state();
  741. return dipi->callback(info, size, dipi->data);
  742. }
  743. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_dl_iterate_phdr(
  744. int (*callback)(struct dl_phdr_info *info, size_t size, void *data),
  745. void *data, dfsan_label callback_label, dfsan_label data_label,
  746. dfsan_label *ret_label) {
  747. dl_iterate_phdr_info dipi = {callback, data};
  748. *ret_label = 0;
  749. return dl_iterate_phdr(dl_iterate_phdr_cb, &dipi);
  750. }
  751. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_dl_iterate_phdr(
  752. int (*callback)(struct dl_phdr_info *info, size_t size, void *data),
  753. void *data, dfsan_label callback_label, dfsan_label data_label,
  754. dfsan_label *ret_label, dfsan_origin callback_origin,
  755. dfsan_origin data_origin, dfsan_origin *ret_origin) {
  756. dl_iterate_phdr_info dipi = {callback, data};
  757. *ret_label = 0;
  758. return dl_iterate_phdr(dl_iterate_phdr_cb, &dipi);
  759. }
  760. // This function is only available for glibc 2.27 or newer. Mark it weak so
  761. // linking succeeds with older glibcs.
  762. SANITIZER_WEAK_ATTRIBUTE void _dl_get_tls_static_info(size_t *sizep,
  763. size_t *alignp);
  764. SANITIZER_INTERFACE_ATTRIBUTE void __dfsw__dl_get_tls_static_info(
  765. size_t *sizep, size_t *alignp, dfsan_label sizep_label,
  766. dfsan_label alignp_label) {
  767. assert(_dl_get_tls_static_info);
  768. _dl_get_tls_static_info(sizep, alignp);
  769. dfsan_set_label(0, sizep, sizeof(*sizep));
  770. dfsan_set_label(0, alignp, sizeof(*alignp));
  771. }
  772. SANITIZER_INTERFACE_ATTRIBUTE void __dfso__dl_get_tls_static_info(
  773. size_t *sizep, size_t *alignp, dfsan_label sizep_label,
  774. dfsan_label alignp_label, dfsan_origin sizep_origin,
  775. dfsan_origin alignp_origin) {
  776. __dfsw__dl_get_tls_static_info(sizep, alignp, sizep_label, alignp_label);
  777. }
  778. SANITIZER_INTERFACE_ATTRIBUTE
  779. char *__dfsw_ctime_r(const time_t *timep, char *buf, dfsan_label timep_label,
  780. dfsan_label buf_label, dfsan_label *ret_label) {
  781. char *ret = ctime_r(timep, buf);
  782. if (ret) {
  783. dfsan_set_label(dfsan_read_label(timep, sizeof(time_t)), buf,
  784. strlen(buf) + 1);
  785. *ret_label = buf_label;
  786. } else {
  787. *ret_label = 0;
  788. }
  789. return ret;
  790. }
  791. SANITIZER_INTERFACE_ATTRIBUTE
  792. char *__dfso_ctime_r(const time_t *timep, char *buf, dfsan_label timep_label,
  793. dfsan_label buf_label, dfsan_label *ret_label,
  794. dfsan_origin timep_origin, dfsan_origin buf_origin,
  795. dfsan_origin *ret_origin) {
  796. char *ret = ctime_r(timep, buf);
  797. if (ret) {
  798. dfsan_set_label_origin(
  799. dfsan_read_label(timep, sizeof(time_t)),
  800. dfsan_read_origin_of_first_taint(timep, sizeof(time_t)), buf,
  801. strlen(buf) + 1);
  802. *ret_label = buf_label;
  803. *ret_origin = buf_origin;
  804. } else {
  805. *ret_label = 0;
  806. }
  807. return ret;
  808. }
  809. SANITIZER_INTERFACE_ATTRIBUTE
  810. char *__dfsw_fgets(char *s, int size, FILE *stream, dfsan_label s_label,
  811. dfsan_label size_label, dfsan_label stream_label,
  812. dfsan_label *ret_label) {
  813. char *ret = fgets(s, size, stream);
  814. if (ret) {
  815. dfsan_set_label(0, ret, strlen(ret) + 1);
  816. *ret_label = s_label;
  817. } else {
  818. *ret_label = 0;
  819. }
  820. return ret;
  821. }
  822. SANITIZER_INTERFACE_ATTRIBUTE
  823. char *__dfso_fgets(char *s, int size, FILE *stream, dfsan_label s_label,
  824. dfsan_label size_label, dfsan_label stream_label,
  825. dfsan_label *ret_label, dfsan_origin s_origin,
  826. dfsan_origin size_origin, dfsan_origin stream_origin,
  827. dfsan_origin *ret_origin) {
  828. char *ret = __dfsw_fgets(s, size, stream, s_label, size_label, stream_label,
  829. ret_label);
  830. if (ret)
  831. *ret_origin = s_origin;
  832. return ret;
  833. }
  834. SANITIZER_INTERFACE_ATTRIBUTE
  835. char *__dfsw_getcwd(char *buf, size_t size, dfsan_label buf_label,
  836. dfsan_label size_label, dfsan_label *ret_label) {
  837. char *ret = getcwd(buf, size);
  838. if (ret) {
  839. dfsan_set_label(0, ret, strlen(ret) + 1);
  840. *ret_label = buf_label;
  841. } else {
  842. *ret_label = 0;
  843. }
  844. return ret;
  845. }
  846. SANITIZER_INTERFACE_ATTRIBUTE
  847. char *__dfso_getcwd(char *buf, size_t size, dfsan_label buf_label,
  848. dfsan_label size_label, dfsan_label *ret_label,
  849. dfsan_origin buf_origin, dfsan_origin size_origin,
  850. dfsan_origin *ret_origin) {
  851. char *ret = __dfsw_getcwd(buf, size, buf_label, size_label, ret_label);
  852. if (ret)
  853. *ret_origin = buf_origin;
  854. return ret;
  855. }
  856. SANITIZER_INTERFACE_ATTRIBUTE
  857. char *__dfsw_get_current_dir_name(dfsan_label *ret_label) {
  858. char *ret = get_current_dir_name();
  859. if (ret)
  860. dfsan_set_label(0, ret, strlen(ret) + 1);
  861. *ret_label = 0;
  862. return ret;
  863. }
  864. SANITIZER_INTERFACE_ATTRIBUTE
  865. char *__dfso_get_current_dir_name(dfsan_label *ret_label,
  866. dfsan_origin *ret_origin) {
  867. return __dfsw_get_current_dir_name(ret_label);
  868. }
  869. // This function is only available for glibc 2.25 or newer. Mark it weak so
  870. // linking succeeds with older glibcs.
  871. SANITIZER_WEAK_ATTRIBUTE int getentropy(void *buffer, size_t length);
  872. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_getentropy(void *buffer, size_t length,
  873. dfsan_label buffer_label,
  874. dfsan_label length_label,
  875. dfsan_label *ret_label) {
  876. int ret = getentropy(buffer, length);
  877. if (ret == 0) {
  878. dfsan_set_label(0, buffer, length);
  879. }
  880. *ret_label = 0;
  881. return ret;
  882. }
  883. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_getentropy(void *buffer, size_t length,
  884. dfsan_label buffer_label,
  885. dfsan_label length_label,
  886. dfsan_label *ret_label,
  887. dfsan_origin buffer_origin,
  888. dfsan_origin length_origin,
  889. dfsan_origin *ret_origin) {
  890. return __dfsw_getentropy(buffer, length, buffer_label, length_label,
  891. ret_label);
  892. }
  893. SANITIZER_INTERFACE_ATTRIBUTE
  894. int __dfsw_gethostname(char *name, size_t len, dfsan_label name_label,
  895. dfsan_label len_label, dfsan_label *ret_label) {
  896. int ret = gethostname(name, len);
  897. if (ret == 0) {
  898. dfsan_set_label(0, name, strlen(name) + 1);
  899. }
  900. *ret_label = 0;
  901. return ret;
  902. }
  903. SANITIZER_INTERFACE_ATTRIBUTE
  904. int __dfso_gethostname(char *name, size_t len, dfsan_label name_label,
  905. dfsan_label len_label, dfsan_label *ret_label,
  906. dfsan_origin name_origin, dfsan_origin len_origin,
  907. dfsan_label *ret_origin) {
  908. return __dfsw_gethostname(name, len, name_label, len_label, ret_label);
  909. }
  910. SANITIZER_INTERFACE_ATTRIBUTE
  911. int __dfsw_getrlimit(int resource, struct rlimit *rlim,
  912. dfsan_label resource_label, dfsan_label rlim_label,
  913. dfsan_label *ret_label) {
  914. int ret = getrlimit(resource, rlim);
  915. if (ret == 0) {
  916. dfsan_set_label(0, rlim, sizeof(struct rlimit));
  917. }
  918. *ret_label = 0;
  919. return ret;
  920. }
  921. SANITIZER_INTERFACE_ATTRIBUTE
  922. int __dfso_getrlimit(int resource, struct rlimit *rlim,
  923. dfsan_label resource_label, dfsan_label rlim_label,
  924. dfsan_label *ret_label, dfsan_origin resource_origin,
  925. dfsan_origin rlim_origin, dfsan_origin *ret_origin) {
  926. return __dfsw_getrlimit(resource, rlim, resource_label, rlim_label,
  927. ret_label);
  928. }
  929. SANITIZER_INTERFACE_ATTRIBUTE
  930. int __dfsw_getrusage(int who, struct rusage *usage, dfsan_label who_label,
  931. dfsan_label usage_label, dfsan_label *ret_label) {
  932. int ret = getrusage(who, usage);
  933. if (ret == 0) {
  934. dfsan_set_label(0, usage, sizeof(struct rusage));
  935. }
  936. *ret_label = 0;
  937. return ret;
  938. }
  939. SANITIZER_INTERFACE_ATTRIBUTE
  940. int __dfso_getrusage(int who, struct rusage *usage, dfsan_label who_label,
  941. dfsan_label usage_label, dfsan_label *ret_label,
  942. dfsan_origin who_origin, dfsan_origin usage_origin,
  943. dfsan_label *ret_origin) {
  944. return __dfsw_getrusage(who, usage, who_label, usage_label, ret_label);
  945. }
  946. SANITIZER_INTERFACE_ATTRIBUTE
  947. char *__dfsw_strcpy(char *dest, const char *src, dfsan_label dst_label,
  948. dfsan_label src_label, dfsan_label *ret_label) {
  949. char *ret = strcpy(dest, src);
  950. if (ret) {
  951. dfsan_mem_shadow_transfer(dest, src, strlen(src) + 1);
  952. }
  953. *ret_label = dst_label;
  954. return ret;
  955. }
  956. SANITIZER_INTERFACE_ATTRIBUTE
  957. char *__dfso_strcpy(char *dest, const char *src, dfsan_label dst_label,
  958. dfsan_label src_label, dfsan_label *ret_label,
  959. dfsan_origin dst_origin, dfsan_origin src_origin,
  960. dfsan_origin *ret_origin) {
  961. char *ret = strcpy(dest, src);
  962. if (ret) {
  963. size_t str_len = strlen(src) + 1;
  964. dfsan_mem_origin_transfer(dest, src, str_len);
  965. dfsan_mem_shadow_transfer(dest, src, str_len);
  966. }
  967. *ret_label = dst_label;
  968. *ret_origin = dst_origin;
  969. return ret;
  970. }
  971. static long int dfsan_strtol(const char *nptr, char **endptr, int base,
  972. char **tmp_endptr) {
  973. assert(tmp_endptr);
  974. long int ret = strtol(nptr, tmp_endptr, base);
  975. if (endptr)
  976. *endptr = *tmp_endptr;
  977. return ret;
  978. }
  979. static void dfsan_strtolong_label(const char *nptr, const char *tmp_endptr,
  980. dfsan_label base_label,
  981. dfsan_label *ret_label) {
  982. if (tmp_endptr > nptr) {
  983. // If *tmp_endptr is '\0' include its label as well.
  984. *ret_label = dfsan_union(
  985. base_label,
  986. dfsan_read_label(nptr, tmp_endptr - nptr + (*tmp_endptr ? 0 : 1)));
  987. } else {
  988. *ret_label = 0;
  989. }
  990. }
  991. static void dfsan_strtolong_origin(const char *nptr, const char *tmp_endptr,
  992. dfsan_label base_label,
  993. dfsan_label *ret_label,
  994. dfsan_origin base_origin,
  995. dfsan_origin *ret_origin) {
  996. if (tmp_endptr > nptr) {
  997. // When multiple inputs are tainted, we propagate one of its origins.
  998. // Because checking if base_label is tainted does not need additional
  999. // computation, we prefer to propagating base_origin.
  1000. *ret_origin = base_label
  1001. ? base_origin
  1002. : dfsan_read_origin_of_first_taint(
  1003. nptr, tmp_endptr - nptr + (*tmp_endptr ? 0 : 1));
  1004. }
  1005. }
  1006. SANITIZER_INTERFACE_ATTRIBUTE
  1007. long int __dfsw_strtol(const char *nptr, char **endptr, int base,
  1008. dfsan_label nptr_label, dfsan_label endptr_label,
  1009. dfsan_label base_label, dfsan_label *ret_label) {
  1010. char *tmp_endptr;
  1011. long int ret = dfsan_strtol(nptr, endptr, base, &tmp_endptr);
  1012. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1013. return ret;
  1014. }
  1015. SANITIZER_INTERFACE_ATTRIBUTE
  1016. long int __dfso_strtol(const char *nptr, char **endptr, int base,
  1017. dfsan_label nptr_label, dfsan_label endptr_label,
  1018. dfsan_label base_label, dfsan_label *ret_label,
  1019. dfsan_origin nptr_origin, dfsan_origin endptr_origin,
  1020. dfsan_origin base_origin, dfsan_origin *ret_origin) {
  1021. char *tmp_endptr;
  1022. long int ret = dfsan_strtol(nptr, endptr, base, &tmp_endptr);
  1023. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1024. dfsan_strtolong_origin(nptr, tmp_endptr, base_label, ret_label, base_origin,
  1025. ret_origin);
  1026. return ret;
  1027. }
  1028. static double dfsan_strtod(const char *nptr, char **endptr, char **tmp_endptr) {
  1029. assert(tmp_endptr);
  1030. double ret = strtod(nptr, tmp_endptr);
  1031. if (endptr)
  1032. *endptr = *tmp_endptr;
  1033. return ret;
  1034. }
  1035. static void dfsan_strtod_label(const char *nptr, const char *tmp_endptr,
  1036. dfsan_label *ret_label) {
  1037. if (tmp_endptr > nptr) {
  1038. // If *tmp_endptr is '\0' include its label as well.
  1039. *ret_label = dfsan_read_label(
  1040. nptr,
  1041. tmp_endptr - nptr + (*tmp_endptr ? 0 : 1));
  1042. } else {
  1043. *ret_label = 0;
  1044. }
  1045. }
  1046. SANITIZER_INTERFACE_ATTRIBUTE
  1047. double __dfsw_strtod(const char *nptr, char **endptr, dfsan_label nptr_label,
  1048. dfsan_label endptr_label, dfsan_label *ret_label) {
  1049. char *tmp_endptr;
  1050. double ret = dfsan_strtod(nptr, endptr, &tmp_endptr);
  1051. dfsan_strtod_label(nptr, tmp_endptr, ret_label);
  1052. return ret;
  1053. }
  1054. SANITIZER_INTERFACE_ATTRIBUTE
  1055. double __dfso_strtod(const char *nptr, char **endptr, dfsan_label nptr_label,
  1056. dfsan_label endptr_label, dfsan_label *ret_label,
  1057. dfsan_origin nptr_origin, dfsan_origin endptr_origin,
  1058. dfsan_origin *ret_origin) {
  1059. char *tmp_endptr;
  1060. double ret = dfsan_strtod(nptr, endptr, &tmp_endptr);
  1061. dfsan_strtod_label(nptr, tmp_endptr, ret_label);
  1062. if (tmp_endptr > nptr) {
  1063. // If *tmp_endptr is '\0' include its label as well.
  1064. *ret_origin = dfsan_read_origin_of_first_taint(
  1065. nptr, tmp_endptr - nptr + (*tmp_endptr ? 0 : 1));
  1066. } else {
  1067. *ret_origin = 0;
  1068. }
  1069. return ret;
  1070. }
  1071. static long long int dfsan_strtoll(const char *nptr, char **endptr, int base,
  1072. char **tmp_endptr) {
  1073. assert(tmp_endptr);
  1074. long long int ret = strtoll(nptr, tmp_endptr, base);
  1075. if (endptr)
  1076. *endptr = *tmp_endptr;
  1077. return ret;
  1078. }
  1079. SANITIZER_INTERFACE_ATTRIBUTE
  1080. long long int __dfsw_strtoll(const char *nptr, char **endptr, int base,
  1081. dfsan_label nptr_label, dfsan_label endptr_label,
  1082. dfsan_label base_label, dfsan_label *ret_label) {
  1083. char *tmp_endptr;
  1084. long long int ret = dfsan_strtoll(nptr, endptr, base, &tmp_endptr);
  1085. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1086. return ret;
  1087. }
  1088. SANITIZER_INTERFACE_ATTRIBUTE
  1089. long long int __dfso_strtoll(const char *nptr, char **endptr, int base,
  1090. dfsan_label nptr_label, dfsan_label endptr_label,
  1091. dfsan_label base_label, dfsan_label *ret_label,
  1092. dfsan_origin nptr_origin,
  1093. dfsan_origin endptr_origin,
  1094. dfsan_origin base_origin,
  1095. dfsan_origin *ret_origin) {
  1096. char *tmp_endptr;
  1097. long long int ret = dfsan_strtoll(nptr, endptr, base, &tmp_endptr);
  1098. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1099. dfsan_strtolong_origin(nptr, tmp_endptr, base_label, ret_label, base_origin,
  1100. ret_origin);
  1101. return ret;
  1102. }
  1103. static unsigned long int dfsan_strtoul(const char *nptr, char **endptr,
  1104. int base, char **tmp_endptr) {
  1105. assert(tmp_endptr);
  1106. unsigned long int ret = strtoul(nptr, tmp_endptr, base);
  1107. if (endptr)
  1108. *endptr = *tmp_endptr;
  1109. return ret;
  1110. }
  1111. SANITIZER_INTERFACE_ATTRIBUTE
  1112. unsigned long int __dfsw_strtoul(const char *nptr, char **endptr, int base,
  1113. dfsan_label nptr_label, dfsan_label endptr_label,
  1114. dfsan_label base_label, dfsan_label *ret_label) {
  1115. char *tmp_endptr;
  1116. unsigned long int ret = dfsan_strtoul(nptr, endptr, base, &tmp_endptr);
  1117. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1118. return ret;
  1119. }
  1120. SANITIZER_INTERFACE_ATTRIBUTE
  1121. unsigned long int __dfso_strtoul(
  1122. const char *nptr, char **endptr, int base, dfsan_label nptr_label,
  1123. dfsan_label endptr_label, dfsan_label base_label, dfsan_label *ret_label,
  1124. dfsan_origin nptr_origin, dfsan_origin endptr_origin,
  1125. dfsan_origin base_origin, dfsan_origin *ret_origin) {
  1126. char *tmp_endptr;
  1127. unsigned long int ret = dfsan_strtoul(nptr, endptr, base, &tmp_endptr);
  1128. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1129. dfsan_strtolong_origin(nptr, tmp_endptr, base_label, ret_label, base_origin,
  1130. ret_origin);
  1131. return ret;
  1132. }
  1133. static long long unsigned int dfsan_strtoull(const char *nptr, char **endptr,
  1134. int base, char **tmp_endptr) {
  1135. assert(tmp_endptr);
  1136. long long unsigned int ret = strtoull(nptr, tmp_endptr, base);
  1137. if (endptr)
  1138. *endptr = *tmp_endptr;
  1139. return ret;
  1140. }
  1141. SANITIZER_INTERFACE_ATTRIBUTE
  1142. long long unsigned int __dfsw_strtoull(const char *nptr, char **endptr,
  1143. int base, dfsan_label nptr_label,
  1144. dfsan_label endptr_label,
  1145. dfsan_label base_label,
  1146. dfsan_label *ret_label) {
  1147. char *tmp_endptr;
  1148. long long unsigned int ret = dfsan_strtoull(nptr, endptr, base, &tmp_endptr);
  1149. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1150. return ret;
  1151. }
  1152. SANITIZER_INTERFACE_ATTRIBUTE
  1153. long long unsigned int __dfso_strtoull(
  1154. const char *nptr, char **endptr, int base, dfsan_label nptr_label,
  1155. dfsan_label endptr_label, dfsan_label base_label, dfsan_label *ret_label,
  1156. dfsan_origin nptr_origin, dfsan_origin endptr_origin,
  1157. dfsan_origin base_origin, dfsan_origin *ret_origin) {
  1158. char *tmp_endptr;
  1159. long long unsigned int ret = dfsan_strtoull(nptr, endptr, base, &tmp_endptr);
  1160. dfsan_strtolong_label(nptr, tmp_endptr, base_label, ret_label);
  1161. dfsan_strtolong_origin(nptr, tmp_endptr, base_label, ret_label, base_origin,
  1162. ret_origin);
  1163. return ret;
  1164. }
  1165. SANITIZER_INTERFACE_ATTRIBUTE
  1166. time_t __dfsw_time(time_t *t, dfsan_label t_label, dfsan_label *ret_label) {
  1167. time_t ret = time(t);
  1168. if (ret != (time_t) -1 && t) {
  1169. dfsan_set_label(0, t, sizeof(time_t));
  1170. }
  1171. *ret_label = 0;
  1172. return ret;
  1173. }
  1174. SANITIZER_INTERFACE_ATTRIBUTE
  1175. time_t __dfso_time(time_t *t, dfsan_label t_label, dfsan_label *ret_label,
  1176. dfsan_origin t_origin, dfsan_origin *ret_origin) {
  1177. return __dfsw_time(t, t_label, ret_label);
  1178. }
  1179. SANITIZER_INTERFACE_ATTRIBUTE
  1180. int __dfsw_inet_pton(int af, const char *src, void *dst, dfsan_label af_label,
  1181. dfsan_label src_label, dfsan_label dst_label,
  1182. dfsan_label *ret_label) {
  1183. int ret = inet_pton(af, src, dst);
  1184. if (ret == 1) {
  1185. dfsan_set_label(dfsan_read_label(src, strlen(src) + 1), dst,
  1186. af == AF_INET ? sizeof(struct in_addr) : sizeof(in6_addr));
  1187. }
  1188. *ret_label = 0;
  1189. return ret;
  1190. }
  1191. SANITIZER_INTERFACE_ATTRIBUTE
  1192. int __dfso_inet_pton(int af, const char *src, void *dst, dfsan_label af_label,
  1193. dfsan_label src_label, dfsan_label dst_label,
  1194. dfsan_label *ret_label, dfsan_origin af_origin,
  1195. dfsan_origin src_origin, dfsan_origin dst_origin,
  1196. dfsan_origin *ret_origin) {
  1197. int ret = inet_pton(af, src, dst);
  1198. if (ret == 1) {
  1199. int src_len = strlen(src) + 1;
  1200. dfsan_set_label_origin(
  1201. dfsan_read_label(src, src_len),
  1202. dfsan_read_origin_of_first_taint(src, src_len), dst,
  1203. af == AF_INET ? sizeof(struct in_addr) : sizeof(in6_addr));
  1204. }
  1205. *ret_label = 0;
  1206. return ret;
  1207. }
  1208. SANITIZER_INTERFACE_ATTRIBUTE
  1209. struct tm *__dfsw_localtime_r(const time_t *timep, struct tm *result,
  1210. dfsan_label timep_label, dfsan_label result_label,
  1211. dfsan_label *ret_label) {
  1212. struct tm *ret = localtime_r(timep, result);
  1213. if (ret) {
  1214. dfsan_set_label(dfsan_read_label(timep, sizeof(time_t)), result,
  1215. sizeof(struct tm));
  1216. *ret_label = result_label;
  1217. } else {
  1218. *ret_label = 0;
  1219. }
  1220. return ret;
  1221. }
  1222. SANITIZER_INTERFACE_ATTRIBUTE
  1223. struct tm *__dfso_localtime_r(const time_t *timep, struct tm *result,
  1224. dfsan_label timep_label, dfsan_label result_label,
  1225. dfsan_label *ret_label, dfsan_origin timep_origin,
  1226. dfsan_origin result_origin,
  1227. dfsan_origin *ret_origin) {
  1228. struct tm *ret = localtime_r(timep, result);
  1229. if (ret) {
  1230. dfsan_set_label_origin(
  1231. dfsan_read_label(timep, sizeof(time_t)),
  1232. dfsan_read_origin_of_first_taint(timep, sizeof(time_t)), result,
  1233. sizeof(struct tm));
  1234. *ret_label = result_label;
  1235. *ret_origin = result_origin;
  1236. } else {
  1237. *ret_label = 0;
  1238. }
  1239. return ret;
  1240. }
  1241. SANITIZER_INTERFACE_ATTRIBUTE
  1242. int __dfsw_getpwuid_r(id_t uid, struct passwd *pwd,
  1243. char *buf, size_t buflen, struct passwd **result,
  1244. dfsan_label uid_label, dfsan_label pwd_label,
  1245. dfsan_label buf_label, dfsan_label buflen_label,
  1246. dfsan_label result_label, dfsan_label *ret_label) {
  1247. // Store the data in pwd, the strings referenced from pwd in buf, and the
  1248. // address of pwd in *result. On failure, NULL is stored in *result.
  1249. int ret = getpwuid_r(uid, pwd, buf, buflen, result);
  1250. if (ret == 0) {
  1251. dfsan_set_label(0, pwd, sizeof(struct passwd));
  1252. dfsan_set_label(0, buf, strlen(buf) + 1);
  1253. }
  1254. *ret_label = 0;
  1255. dfsan_set_label(0, result, sizeof(struct passwd*));
  1256. return ret;
  1257. }
  1258. SANITIZER_INTERFACE_ATTRIBUTE
  1259. int __dfso_getpwuid_r(id_t uid, struct passwd *pwd, char *buf, size_t buflen,
  1260. struct passwd **result, dfsan_label uid_label,
  1261. dfsan_label pwd_label, dfsan_label buf_label,
  1262. dfsan_label buflen_label, dfsan_label result_label,
  1263. dfsan_label *ret_label, dfsan_origin uid_origin,
  1264. dfsan_origin pwd_origin, dfsan_origin buf_origin,
  1265. dfsan_origin buflen_origin, dfsan_origin result_origin,
  1266. dfsan_origin *ret_origin) {
  1267. return __dfsw_getpwuid_r(uid, pwd, buf, buflen, result, uid_label, pwd_label,
  1268. buf_label, buflen_label, result_label, ret_label);
  1269. }
  1270. SANITIZER_INTERFACE_ATTRIBUTE
  1271. int __dfsw_epoll_wait(int epfd, struct epoll_event *events, int maxevents,
  1272. int timeout, dfsan_label epfd_label,
  1273. dfsan_label events_label, dfsan_label maxevents_label,
  1274. dfsan_label timeout_label, dfsan_label *ret_label) {
  1275. int ret = epoll_wait(epfd, events, maxevents, timeout);
  1276. if (ret > 0)
  1277. dfsan_set_label(0, events, ret * sizeof(*events));
  1278. *ret_label = 0;
  1279. return ret;
  1280. }
  1281. SANITIZER_INTERFACE_ATTRIBUTE
  1282. int __dfso_epoll_wait(int epfd, struct epoll_event *events, int maxevents,
  1283. int timeout, dfsan_label epfd_label,
  1284. dfsan_label events_label, dfsan_label maxevents_label,
  1285. dfsan_label timeout_label, dfsan_label *ret_label,
  1286. dfsan_origin epfd_origin, dfsan_origin events_origin,
  1287. dfsan_origin maxevents_origin,
  1288. dfsan_origin timeout_origin, dfsan_origin *ret_origin) {
  1289. return __dfsw_epoll_wait(epfd, events, maxevents, timeout, epfd_label,
  1290. events_label, maxevents_label, timeout_label,
  1291. ret_label);
  1292. }
  1293. SANITIZER_INTERFACE_ATTRIBUTE
  1294. int __dfsw_poll(struct pollfd *fds, nfds_t nfds, int timeout,
  1295. dfsan_label dfs_label, dfsan_label nfds_label,
  1296. dfsan_label timeout_label, dfsan_label *ret_label) {
  1297. int ret = poll(fds, nfds, timeout);
  1298. if (ret >= 0) {
  1299. for (; nfds > 0; --nfds) {
  1300. dfsan_set_label(0, &fds[nfds - 1].revents, sizeof(fds[nfds - 1].revents));
  1301. }
  1302. }
  1303. *ret_label = 0;
  1304. return ret;
  1305. }
  1306. SANITIZER_INTERFACE_ATTRIBUTE
  1307. int __dfso_poll(struct pollfd *fds, nfds_t nfds, int timeout,
  1308. dfsan_label dfs_label, dfsan_label nfds_label,
  1309. dfsan_label timeout_label, dfsan_label *ret_label,
  1310. dfsan_origin dfs_origin, dfsan_origin nfds_origin,
  1311. dfsan_origin timeout_origin, dfsan_origin *ret_origin) {
  1312. return __dfsw_poll(fds, nfds, timeout, dfs_label, nfds_label, timeout_label,
  1313. ret_label);
  1314. }
  1315. SANITIZER_INTERFACE_ATTRIBUTE
  1316. int __dfsw_select(int nfds, fd_set *readfds, fd_set *writefds,
  1317. fd_set *exceptfds, struct timeval *timeout,
  1318. dfsan_label nfds_label, dfsan_label readfds_label,
  1319. dfsan_label writefds_label, dfsan_label exceptfds_label,
  1320. dfsan_label timeout_label, dfsan_label *ret_label) {
  1321. int ret = select(nfds, readfds, writefds, exceptfds, timeout);
  1322. // Clear everything (also on error) since their content is either set or
  1323. // undefined.
  1324. if (readfds) {
  1325. dfsan_set_label(0, readfds, sizeof(fd_set));
  1326. }
  1327. if (writefds) {
  1328. dfsan_set_label(0, writefds, sizeof(fd_set));
  1329. }
  1330. if (exceptfds) {
  1331. dfsan_set_label(0, exceptfds, sizeof(fd_set));
  1332. }
  1333. dfsan_set_label(0, timeout, sizeof(struct timeval));
  1334. *ret_label = 0;
  1335. return ret;
  1336. }
  1337. SANITIZER_INTERFACE_ATTRIBUTE
  1338. int __dfso_select(int nfds, fd_set *readfds, fd_set *writefds,
  1339. fd_set *exceptfds, struct timeval *timeout,
  1340. dfsan_label nfds_label, dfsan_label readfds_label,
  1341. dfsan_label writefds_label, dfsan_label exceptfds_label,
  1342. dfsan_label timeout_label, dfsan_label *ret_label,
  1343. dfsan_origin nfds_origin, dfsan_origin readfds_origin,
  1344. dfsan_origin writefds_origin, dfsan_origin exceptfds_origin,
  1345. dfsan_origin timeout_origin, dfsan_origin *ret_origin) {
  1346. return __dfsw_select(nfds, readfds, writefds, exceptfds, timeout, nfds_label,
  1347. readfds_label, writefds_label, exceptfds_label,
  1348. timeout_label, ret_label);
  1349. }
  1350. SANITIZER_INTERFACE_ATTRIBUTE
  1351. int __dfsw_sched_getaffinity(pid_t pid, size_t cpusetsize, cpu_set_t *mask,
  1352. dfsan_label pid_label,
  1353. dfsan_label cpusetsize_label,
  1354. dfsan_label mask_label, dfsan_label *ret_label) {
  1355. int ret = sched_getaffinity(pid, cpusetsize, mask);
  1356. if (ret == 0) {
  1357. dfsan_set_label(0, mask, cpusetsize);
  1358. }
  1359. *ret_label = 0;
  1360. return ret;
  1361. }
  1362. SANITIZER_INTERFACE_ATTRIBUTE
  1363. int __dfso_sched_getaffinity(pid_t pid, size_t cpusetsize, cpu_set_t *mask,
  1364. dfsan_label pid_label,
  1365. dfsan_label cpusetsize_label,
  1366. dfsan_label mask_label, dfsan_label *ret_label,
  1367. dfsan_origin pid_origin,
  1368. dfsan_origin cpusetsize_origin,
  1369. dfsan_origin mask_origin,
  1370. dfsan_origin *ret_origin) {
  1371. return __dfsw_sched_getaffinity(pid, cpusetsize, mask, pid_label,
  1372. cpusetsize_label, mask_label, ret_label);
  1373. }
  1374. SANITIZER_INTERFACE_ATTRIBUTE
  1375. int __dfsw_sigemptyset(sigset_t *set, dfsan_label set_label,
  1376. dfsan_label *ret_label) {
  1377. int ret = sigemptyset(set);
  1378. dfsan_set_label(0, set, sizeof(sigset_t));
  1379. *ret_label = 0;
  1380. return ret;
  1381. }
  1382. SANITIZER_INTERFACE_ATTRIBUTE
  1383. int __dfso_sigemptyset(sigset_t *set, dfsan_label set_label,
  1384. dfsan_label *ret_label, dfsan_origin set_origin,
  1385. dfsan_origin *ret_origin) {
  1386. return __dfsw_sigemptyset(set, set_label, ret_label);
  1387. }
  1388. class SignalHandlerScope {
  1389. public:
  1390. SignalHandlerScope() {
  1391. if (DFsanThread *t = GetCurrentThread())
  1392. t->EnterSignalHandler();
  1393. }
  1394. ~SignalHandlerScope() {
  1395. if (DFsanThread *t = GetCurrentThread())
  1396. t->LeaveSignalHandler();
  1397. }
  1398. };
  1399. // Clear DFSan runtime TLS state at the end of a scope.
  1400. //
  1401. // Implementation must be async-signal-safe and use small data size, because
  1402. // instances of this class may live on the signal handler stack.
  1403. //
  1404. // DFSan uses TLS to pass metadata of arguments and return values. When an
  1405. // instrumented function accesses the TLS, if a signal callback happens, and the
  1406. // callback calls other instrumented functions with updating the same TLS, the
  1407. // TLS is in an inconsistent state after the callback ends. This may cause
  1408. // either under-tainting or over-tainting.
  1409. //
  1410. // The current implementation simply resets TLS at restore. This prevents from
  1411. // over-tainting. Although under-tainting may still happen, a taint flow can be
  1412. // found eventually if we run a DFSan-instrumented program multiple times. The
  1413. // alternative option is saving the entire TLS. However the TLS storage takes
  1414. // 2k bytes, and signal calls could be nested. So it does not seem worth.
  1415. class ScopedClearThreadLocalState {
  1416. public:
  1417. ScopedClearThreadLocalState() {}
  1418. ~ScopedClearThreadLocalState() { dfsan_clear_thread_local_state(); }
  1419. };
  1420. // SignalSpinLocker::sigactions_mu guarantees atomicity of sigaction() calls.
  1421. const int kMaxSignals = 1024;
  1422. static atomic_uintptr_t sigactions[kMaxSignals];
  1423. static void SignalHandler(int signo) {
  1424. SignalHandlerScope signal_handler_scope;
  1425. ScopedClearThreadLocalState scoped_clear_tls;
  1426. // Clear shadows for all inputs provided by system.
  1427. dfsan_clear_arg_tls(0, sizeof(dfsan_label));
  1428. typedef void (*signal_cb)(int x);
  1429. signal_cb cb =
  1430. (signal_cb)atomic_load(&sigactions[signo], memory_order_relaxed);
  1431. cb(signo);
  1432. }
  1433. static void SignalAction(int signo, siginfo_t *si, void *uc) {
  1434. SignalHandlerScope signal_handler_scope;
  1435. ScopedClearThreadLocalState scoped_clear_tls;
  1436. // Clear shadows for all inputs provided by system. Similar to SignalHandler.
  1437. dfsan_clear_arg_tls(0, 3 * sizeof(dfsan_label));
  1438. dfsan_set_label(0, si, sizeof(*si));
  1439. dfsan_set_label(0, uc, sizeof(ucontext_t));
  1440. typedef void (*sigaction_cb)(int, siginfo_t *, void *);
  1441. sigaction_cb cb =
  1442. (sigaction_cb)atomic_load(&sigactions[signo], memory_order_relaxed);
  1443. cb(signo, si, uc);
  1444. }
  1445. SANITIZER_INTERFACE_ATTRIBUTE
  1446. int __dfsw_sigaction(int signum, const struct sigaction *act,
  1447. struct sigaction *oldact, dfsan_label signum_label,
  1448. dfsan_label act_label, dfsan_label oldact_label,
  1449. dfsan_label *ret_label) {
  1450. CHECK_LT(signum, kMaxSignals);
  1451. SignalSpinLocker lock;
  1452. uptr old_cb = atomic_load(&sigactions[signum], memory_order_relaxed);
  1453. struct sigaction new_act;
  1454. struct sigaction *pnew_act = act ? &new_act : nullptr;
  1455. if (act) {
  1456. internal_memcpy(pnew_act, act, sizeof(struct sigaction));
  1457. if (pnew_act->sa_flags & SA_SIGINFO) {
  1458. uptr cb = (uptr)(pnew_act->sa_sigaction);
  1459. if (cb != (uptr)SIG_IGN && cb != (uptr)SIG_DFL) {
  1460. atomic_store(&sigactions[signum], cb, memory_order_relaxed);
  1461. pnew_act->sa_sigaction = SignalAction;
  1462. }
  1463. } else {
  1464. uptr cb = (uptr)(pnew_act->sa_handler);
  1465. if (cb != (uptr)SIG_IGN && cb != (uptr)SIG_DFL) {
  1466. atomic_store(&sigactions[signum], cb, memory_order_relaxed);
  1467. pnew_act->sa_handler = SignalHandler;
  1468. }
  1469. }
  1470. }
  1471. int ret = sigaction(signum, pnew_act, oldact);
  1472. if (ret == 0 && oldact) {
  1473. if (oldact->sa_flags & SA_SIGINFO) {
  1474. if (oldact->sa_sigaction == SignalAction)
  1475. oldact->sa_sigaction = (decltype(oldact->sa_sigaction))old_cb;
  1476. } else {
  1477. if (oldact->sa_handler == SignalHandler)
  1478. oldact->sa_handler = (decltype(oldact->sa_handler))old_cb;
  1479. }
  1480. }
  1481. if (oldact) {
  1482. dfsan_set_label(0, oldact, sizeof(struct sigaction));
  1483. }
  1484. *ret_label = 0;
  1485. return ret;
  1486. }
  1487. SANITIZER_INTERFACE_ATTRIBUTE
  1488. int __dfso_sigaction(int signum, const struct sigaction *act,
  1489. struct sigaction *oldact, dfsan_label signum_label,
  1490. dfsan_label act_label, dfsan_label oldact_label,
  1491. dfsan_label *ret_label, dfsan_origin signum_origin,
  1492. dfsan_origin act_origin, dfsan_origin oldact_origin,
  1493. dfsan_origin *ret_origin) {
  1494. return __dfsw_sigaction(signum, act, oldact, signum_label, act_label,
  1495. oldact_label, ret_label);
  1496. }
  1497. static sighandler_t dfsan_signal(int signum, sighandler_t handler,
  1498. dfsan_label *ret_label) {
  1499. CHECK_LT(signum, kMaxSignals);
  1500. SignalSpinLocker lock;
  1501. uptr old_cb = atomic_load(&sigactions[signum], memory_order_relaxed);
  1502. if (handler != SIG_IGN && handler != SIG_DFL) {
  1503. atomic_store(&sigactions[signum], (uptr)handler, memory_order_relaxed);
  1504. handler = &SignalHandler;
  1505. }
  1506. sighandler_t ret = signal(signum, handler);
  1507. if (ret == SignalHandler)
  1508. ret = (sighandler_t)old_cb;
  1509. *ret_label = 0;
  1510. return ret;
  1511. }
  1512. SANITIZER_INTERFACE_ATTRIBUTE
  1513. sighandler_t __dfsw_signal(int signum, sighandler_t handler,
  1514. dfsan_label signum_label, dfsan_label handler_label,
  1515. dfsan_label *ret_label) {
  1516. return dfsan_signal(signum, handler, ret_label);
  1517. }
  1518. SANITIZER_INTERFACE_ATTRIBUTE
  1519. sighandler_t __dfso_signal(int signum, sighandler_t handler,
  1520. dfsan_label signum_label, dfsan_label handler_label,
  1521. dfsan_label *ret_label, dfsan_origin signum_origin,
  1522. dfsan_origin handler_origin,
  1523. dfsan_origin *ret_origin) {
  1524. return dfsan_signal(signum, handler, ret_label);
  1525. }
  1526. SANITIZER_INTERFACE_ATTRIBUTE
  1527. int __dfsw_sigaltstack(const stack_t *ss, stack_t *old_ss, dfsan_label ss_label,
  1528. dfsan_label old_ss_label, dfsan_label *ret_label) {
  1529. int ret = sigaltstack(ss, old_ss);
  1530. if (ret != -1 && old_ss)
  1531. dfsan_set_label(0, old_ss, sizeof(*old_ss));
  1532. *ret_label = 0;
  1533. return ret;
  1534. }
  1535. SANITIZER_INTERFACE_ATTRIBUTE
  1536. int __dfso_sigaltstack(const stack_t *ss, stack_t *old_ss, dfsan_label ss_label,
  1537. dfsan_label old_ss_label, dfsan_label *ret_label,
  1538. dfsan_origin ss_origin, dfsan_origin old_ss_origin,
  1539. dfsan_origin *ret_origin) {
  1540. return __dfsw_sigaltstack(ss, old_ss, ss_label, old_ss_label, ret_label);
  1541. }
  1542. SANITIZER_INTERFACE_ATTRIBUTE
  1543. int __dfsw_gettimeofday(struct timeval *tv, struct timezone *tz,
  1544. dfsan_label tv_label, dfsan_label tz_label,
  1545. dfsan_label *ret_label) {
  1546. int ret = gettimeofday(tv, tz);
  1547. if (tv) {
  1548. dfsan_set_label(0, tv, sizeof(struct timeval));
  1549. }
  1550. if (tz) {
  1551. dfsan_set_label(0, tz, sizeof(struct timezone));
  1552. }
  1553. *ret_label = 0;
  1554. return ret;
  1555. }
  1556. SANITIZER_INTERFACE_ATTRIBUTE
  1557. int __dfso_gettimeofday(struct timeval *tv, struct timezone *tz,
  1558. dfsan_label tv_label, dfsan_label tz_label,
  1559. dfsan_label *ret_label, dfsan_origin tv_origin,
  1560. dfsan_origin tz_origin, dfsan_origin *ret_origin) {
  1561. return __dfsw_gettimeofday(tv, tz, tv_label, tz_label, ret_label);
  1562. }
  1563. SANITIZER_INTERFACE_ATTRIBUTE void *__dfsw_memchr(void *s, int c, size_t n,
  1564. dfsan_label s_label,
  1565. dfsan_label c_label,
  1566. dfsan_label n_label,
  1567. dfsan_label *ret_label) {
  1568. void *ret = memchr(s, c, n);
  1569. if (flags().strict_data_dependencies) {
  1570. *ret_label = ret ? s_label : 0;
  1571. } else {
  1572. size_t len =
  1573. ret ? reinterpret_cast<char *>(ret) - reinterpret_cast<char *>(s) + 1
  1574. : n;
  1575. *ret_label =
  1576. dfsan_union(dfsan_read_label(s, len), dfsan_union(s_label, c_label));
  1577. }
  1578. return ret;
  1579. }
  1580. SANITIZER_INTERFACE_ATTRIBUTE void *__dfso_memchr(
  1581. void *s, int c, size_t n, dfsan_label s_label, dfsan_label c_label,
  1582. dfsan_label n_label, dfsan_label *ret_label, dfsan_origin s_origin,
  1583. dfsan_origin c_origin, dfsan_origin n_origin, dfsan_origin *ret_origin) {
  1584. void *ret = __dfsw_memchr(s, c, n, s_label, c_label, n_label, ret_label);
  1585. if (flags().strict_data_dependencies) {
  1586. if (ret)
  1587. *ret_origin = s_origin;
  1588. } else {
  1589. size_t len =
  1590. ret ? reinterpret_cast<char *>(ret) - reinterpret_cast<char *>(s) + 1
  1591. : n;
  1592. dfsan_origin o = dfsan_read_origin_of_first_taint(s, len);
  1593. *ret_origin = o ? o : (s_label ? s_origin : c_origin);
  1594. }
  1595. return ret;
  1596. }
  1597. SANITIZER_INTERFACE_ATTRIBUTE char *__dfsw_strrchr(char *s, int c,
  1598. dfsan_label s_label,
  1599. dfsan_label c_label,
  1600. dfsan_label *ret_label) {
  1601. char *ret = strrchr(s, c);
  1602. if (flags().strict_data_dependencies) {
  1603. *ret_label = ret ? s_label : 0;
  1604. } else {
  1605. *ret_label =
  1606. dfsan_union(dfsan_read_label(s, strlen(s) + 1),
  1607. dfsan_union(s_label, c_label));
  1608. }
  1609. return ret;
  1610. }
  1611. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strrchr(
  1612. char *s, int c, dfsan_label s_label, dfsan_label c_label,
  1613. dfsan_label *ret_label, dfsan_origin s_origin, dfsan_origin c_origin,
  1614. dfsan_origin *ret_origin) {
  1615. char *ret = __dfsw_strrchr(s, c, s_label, c_label, ret_label);
  1616. if (flags().strict_data_dependencies) {
  1617. if (ret)
  1618. *ret_origin = s_origin;
  1619. } else {
  1620. size_t s_len = strlen(s) + 1;
  1621. dfsan_origin o = dfsan_read_origin_of_first_taint(s, s_len);
  1622. *ret_origin = o ? o : (s_label ? s_origin : c_origin);
  1623. }
  1624. return ret;
  1625. }
  1626. SANITIZER_INTERFACE_ATTRIBUTE char *__dfsw_strstr(char *haystack, char *needle,
  1627. dfsan_label haystack_label,
  1628. dfsan_label needle_label,
  1629. dfsan_label *ret_label) {
  1630. char *ret = strstr(haystack, needle);
  1631. if (flags().strict_data_dependencies) {
  1632. *ret_label = ret ? haystack_label : 0;
  1633. } else {
  1634. size_t len = ret ? ret + strlen(needle) - haystack : strlen(haystack) + 1;
  1635. *ret_label =
  1636. dfsan_union(dfsan_read_label(haystack, len),
  1637. dfsan_union(dfsan_read_label(needle, strlen(needle) + 1),
  1638. dfsan_union(haystack_label, needle_label)));
  1639. }
  1640. return ret;
  1641. }
  1642. SANITIZER_INTERFACE_ATTRIBUTE char *__dfso_strstr(char *haystack, char *needle,
  1643. dfsan_label haystack_label,
  1644. dfsan_label needle_label,
  1645. dfsan_label *ret_label,
  1646. dfsan_origin haystack_origin,
  1647. dfsan_origin needle_origin,
  1648. dfsan_origin *ret_origin) {
  1649. char *ret =
  1650. __dfsw_strstr(haystack, needle, haystack_label, needle_label, ret_label);
  1651. if (flags().strict_data_dependencies) {
  1652. if (ret)
  1653. *ret_origin = haystack_origin;
  1654. } else {
  1655. size_t needle_len = strlen(needle);
  1656. size_t len = ret ? ret + needle_len - haystack : strlen(haystack) + 1;
  1657. dfsan_origin o = dfsan_read_origin_of_first_taint(haystack, len);
  1658. if (o) {
  1659. *ret_origin = o;
  1660. } else {
  1661. o = dfsan_read_origin_of_first_taint(needle, needle_len + 1);
  1662. *ret_origin = o ? o : (haystack_label ? haystack_origin : needle_origin);
  1663. }
  1664. }
  1665. return ret;
  1666. }
  1667. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_nanosleep(const struct timespec *req,
  1668. struct timespec *rem,
  1669. dfsan_label req_label,
  1670. dfsan_label rem_label,
  1671. dfsan_label *ret_label) {
  1672. int ret = nanosleep(req, rem);
  1673. *ret_label = 0;
  1674. if (ret == -1) {
  1675. // Interrupted by a signal, rem is filled with the remaining time.
  1676. dfsan_set_label(0, rem, sizeof(struct timespec));
  1677. }
  1678. return ret;
  1679. }
  1680. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_nanosleep(
  1681. const struct timespec *req, struct timespec *rem, dfsan_label req_label,
  1682. dfsan_label rem_label, dfsan_label *ret_label, dfsan_origin req_origin,
  1683. dfsan_origin rem_origin, dfsan_origin *ret_origin) {
  1684. return __dfsw_nanosleep(req, rem, req_label, rem_label, ret_label);
  1685. }
  1686. static void clear_msghdr_labels(size_t bytes_written, struct msghdr *msg) {
  1687. dfsan_set_label(0, msg, sizeof(*msg));
  1688. dfsan_set_label(0, msg->msg_name, msg->msg_namelen);
  1689. dfsan_set_label(0, msg->msg_control, msg->msg_controllen);
  1690. for (size_t i = 0; bytes_written > 0; ++i) {
  1691. assert(i < msg->msg_iovlen);
  1692. struct iovec *iov = &msg->msg_iov[i];
  1693. size_t iov_written =
  1694. bytes_written < iov->iov_len ? bytes_written : iov->iov_len;
  1695. dfsan_set_label(0, iov->iov_base, iov_written);
  1696. bytes_written -= iov_written;
  1697. }
  1698. }
  1699. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_recvmmsg(
  1700. int sockfd, struct mmsghdr *msgvec, unsigned int vlen, int flags,
  1701. struct timespec *timeout, dfsan_label sockfd_label,
  1702. dfsan_label msgvec_label, dfsan_label vlen_label, dfsan_label flags_label,
  1703. dfsan_label timeout_label, dfsan_label *ret_label) {
  1704. int ret = recvmmsg(sockfd, msgvec, vlen, flags, timeout);
  1705. for (int i = 0; i < ret; ++i) {
  1706. dfsan_set_label(0, &msgvec[i].msg_len, sizeof(msgvec[i].msg_len));
  1707. clear_msghdr_labels(msgvec[i].msg_len, &msgvec[i].msg_hdr);
  1708. }
  1709. *ret_label = 0;
  1710. return ret;
  1711. }
  1712. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_recvmmsg(
  1713. int sockfd, struct mmsghdr *msgvec, unsigned int vlen, int flags,
  1714. struct timespec *timeout, dfsan_label sockfd_label,
  1715. dfsan_label msgvec_label, dfsan_label vlen_label, dfsan_label flags_label,
  1716. dfsan_label timeout_label, dfsan_label *ret_label,
  1717. dfsan_origin sockfd_origin, dfsan_origin msgvec_origin,
  1718. dfsan_origin vlen_origin, dfsan_origin flags_origin,
  1719. dfsan_origin timeout_origin, dfsan_origin *ret_origin) {
  1720. return __dfsw_recvmmsg(sockfd, msgvec, vlen, flags, timeout, sockfd_label,
  1721. msgvec_label, vlen_label, flags_label, timeout_label,
  1722. ret_label);
  1723. }
  1724. SANITIZER_INTERFACE_ATTRIBUTE ssize_t __dfsw_recvmsg(
  1725. int sockfd, struct msghdr *msg, int flags, dfsan_label sockfd_label,
  1726. dfsan_label msg_label, dfsan_label flags_label, dfsan_label *ret_label) {
  1727. ssize_t ret = recvmsg(sockfd, msg, flags);
  1728. if (ret >= 0)
  1729. clear_msghdr_labels(ret, msg);
  1730. *ret_label = 0;
  1731. return ret;
  1732. }
  1733. SANITIZER_INTERFACE_ATTRIBUTE ssize_t __dfso_recvmsg(
  1734. int sockfd, struct msghdr *msg, int flags, dfsan_label sockfd_label,
  1735. dfsan_label msg_label, dfsan_label flags_label, dfsan_label *ret_label,
  1736. dfsan_origin sockfd_origin, dfsan_origin msg_origin,
  1737. dfsan_origin flags_origin, dfsan_origin *ret_origin) {
  1738. return __dfsw_recvmsg(sockfd, msg, flags, sockfd_label, msg_label,
  1739. flags_label, ret_label);
  1740. }
  1741. SANITIZER_INTERFACE_ATTRIBUTE int
  1742. __dfsw_socketpair(int domain, int type, int protocol, int sv[2],
  1743. dfsan_label domain_label, dfsan_label type_label,
  1744. dfsan_label protocol_label, dfsan_label sv_label,
  1745. dfsan_label *ret_label) {
  1746. int ret = socketpair(domain, type, protocol, sv);
  1747. *ret_label = 0;
  1748. if (ret == 0) {
  1749. dfsan_set_label(0, sv, sizeof(*sv) * 2);
  1750. }
  1751. return ret;
  1752. }
  1753. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_socketpair(
  1754. int domain, int type, int protocol, int sv[2], dfsan_label domain_label,
  1755. dfsan_label type_label, dfsan_label protocol_label, dfsan_label sv_label,
  1756. dfsan_label *ret_label, dfsan_origin domain_origin,
  1757. dfsan_origin type_origin, dfsan_origin protocol_origin,
  1758. dfsan_origin sv_origin, dfsan_origin *ret_origin) {
  1759. return __dfsw_socketpair(domain, type, protocol, sv, domain_label, type_label,
  1760. protocol_label, sv_label, ret_label);
  1761. }
  1762. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_getsockopt(
  1763. int sockfd, int level, int optname, void *optval, socklen_t *optlen,
  1764. dfsan_label sockfd_label, dfsan_label level_label,
  1765. dfsan_label optname_label, dfsan_label optval_label,
  1766. dfsan_label optlen_label, dfsan_label *ret_label) {
  1767. int ret = getsockopt(sockfd, level, optname, optval, optlen);
  1768. if (ret != -1 && optval && optlen) {
  1769. dfsan_set_label(0, optlen, sizeof(*optlen));
  1770. dfsan_set_label(0, optval, *optlen);
  1771. }
  1772. *ret_label = 0;
  1773. return ret;
  1774. }
  1775. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_getsockopt(
  1776. int sockfd, int level, int optname, void *optval, socklen_t *optlen,
  1777. dfsan_label sockfd_label, dfsan_label level_label,
  1778. dfsan_label optname_label, dfsan_label optval_label,
  1779. dfsan_label optlen_label, dfsan_label *ret_label,
  1780. dfsan_origin sockfd_origin, dfsan_origin level_origin,
  1781. dfsan_origin optname_origin, dfsan_origin optval_origin,
  1782. dfsan_origin optlen_origin, dfsan_origin *ret_origin) {
  1783. return __dfsw_getsockopt(sockfd, level, optname, optval, optlen, sockfd_label,
  1784. level_label, optname_label, optval_label,
  1785. optlen_label, ret_label);
  1786. }
  1787. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_getsockname(
  1788. int sockfd, struct sockaddr *addr, socklen_t *addrlen,
  1789. dfsan_label sockfd_label, dfsan_label addr_label, dfsan_label addrlen_label,
  1790. dfsan_label *ret_label) {
  1791. socklen_t origlen = addrlen ? *addrlen : 0;
  1792. int ret = getsockname(sockfd, addr, addrlen);
  1793. if (ret != -1 && addr && addrlen) {
  1794. socklen_t written_bytes = origlen < *addrlen ? origlen : *addrlen;
  1795. dfsan_set_label(0, addrlen, sizeof(*addrlen));
  1796. dfsan_set_label(0, addr, written_bytes);
  1797. }
  1798. *ret_label = 0;
  1799. return ret;
  1800. }
  1801. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_getsockname(
  1802. int sockfd, struct sockaddr *addr, socklen_t *addrlen,
  1803. dfsan_label sockfd_label, dfsan_label addr_label, dfsan_label addrlen_label,
  1804. dfsan_label *ret_label, dfsan_origin sockfd_origin,
  1805. dfsan_origin addr_origin, dfsan_origin addrlen_origin,
  1806. dfsan_origin *ret_origin) {
  1807. return __dfsw_getsockname(sockfd, addr, addrlen, sockfd_label, addr_label,
  1808. addrlen_label, ret_label);
  1809. }
  1810. SANITIZER_INTERFACE_ATTRIBUTE int __dfsw_getpeername(
  1811. int sockfd, struct sockaddr *addr, socklen_t *addrlen,
  1812. dfsan_label sockfd_label, dfsan_label addr_label, dfsan_label addrlen_label,
  1813. dfsan_label *ret_label) {
  1814. socklen_t origlen = addrlen ? *addrlen : 0;
  1815. int ret = getpeername(sockfd, addr, addrlen);
  1816. if (ret != -1 && addr && addrlen) {
  1817. socklen_t written_bytes = origlen < *addrlen ? origlen : *addrlen;
  1818. dfsan_set_label(0, addrlen, sizeof(*addrlen));
  1819. dfsan_set_label(0, addr, written_bytes);
  1820. }
  1821. *ret_label = 0;
  1822. return ret;
  1823. }
  1824. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_getpeername(
  1825. int sockfd, struct sockaddr *addr, socklen_t *addrlen,
  1826. dfsan_label sockfd_label, dfsan_label addr_label, dfsan_label addrlen_label,
  1827. dfsan_label *ret_label, dfsan_origin sockfd_origin,
  1828. dfsan_origin addr_origin, dfsan_origin addrlen_origin,
  1829. dfsan_origin *ret_origin) {
  1830. return __dfsw_getpeername(sockfd, addr, addrlen, sockfd_label, addr_label,
  1831. addrlen_label, ret_label);
  1832. }
  1833. // Type of the function passed to dfsan_set_write_callback.
  1834. typedef void (*write_dfsan_callback_t)(int fd, const void *buf, ssize_t count);
  1835. // Calls to dfsan_set_write_callback() set the values in this struct.
  1836. // Calls to the custom version of write() read (and invoke) them.
  1837. static struct {
  1838. write_dfsan_callback_t write_callback = nullptr;
  1839. } write_callback_info;
  1840. SANITIZER_INTERFACE_ATTRIBUTE void __dfsw_dfsan_set_write_callback(
  1841. write_dfsan_callback_t write_callback, dfsan_label write_callback_label,
  1842. dfsan_label *ret_label) {
  1843. write_callback_info.write_callback = write_callback;
  1844. }
  1845. SANITIZER_INTERFACE_ATTRIBUTE void __dfso_dfsan_set_write_callback(
  1846. write_dfsan_callback_t write_callback, dfsan_label write_callback_label,
  1847. dfsan_label *ret_label, dfsan_origin write_callback_origin,
  1848. dfsan_origin *ret_origin) {
  1849. write_callback_info.write_callback = write_callback;
  1850. }
  1851. static inline void setup_tls_args_for_write_callback(
  1852. dfsan_label fd_label, dfsan_label buf_label, dfsan_label count_label,
  1853. bool origins, dfsan_origin fd_origin, dfsan_origin buf_origin,
  1854. dfsan_origin count_origin) {
  1855. // The callback code will expect argument shadow labels in the args TLS,
  1856. // and origin labels in the origin args TLS.
  1857. // Previously this was done by a trampoline, but we want to remove this:
  1858. // https://github.com/llvm/llvm-project/issues/54172
  1859. //
  1860. // Instead, this code is manually setting up the args TLS data.
  1861. //
  1862. // The offsets used need to correspond with the instrumentation code,
  1863. // see llvm/lib/Transforms/Instrumentation/DataFlowSanitizer.cpp
  1864. // DFSanFunction::getShadowForTLSArgument.
  1865. // https://github.com/llvm/llvm-project/blob/0acc9e4b5edd8b39ff3d4c6d0e17f02007671c4e/llvm/lib/Transforms/Instrumentation/DataFlowSanitizer.cpp#L1684
  1866. // https://github.com/llvm/llvm-project/blob/0acc9e4b5edd8b39ff3d4c6d0e17f02007671c4e/llvm/lib/Transforms/Instrumentation/DataFlowSanitizer.cpp#L125
  1867. //
  1868. // Here the arguments are all primitives, but it can be more complex
  1869. // to compute offsets for array/aggregate type arguments.
  1870. //
  1871. // TODO(browneee): Consider a builtin to improve maintainabliity.
  1872. // With a builtin, we would provide the argument labels via builtin,
  1873. // and the builtin would reuse parts of the instrumentation code to ensure
  1874. // that this code and the instrumentation can never be out of sync.
  1875. // Note: Currently DFSan instrumentation does not run on this code, so
  1876. // the builtin may need to be handled outside DFSan instrumentation.
  1877. dfsan_set_arg_tls(0, fd_label);
  1878. dfsan_set_arg_tls(1, buf_label);
  1879. dfsan_set_arg_tls(2, count_label);
  1880. if (origins) {
  1881. dfsan_set_arg_origin_tls(0, fd_origin);
  1882. dfsan_set_arg_origin_tls(1, buf_origin);
  1883. dfsan_set_arg_origin_tls(2, count_origin);
  1884. }
  1885. }
  1886. SANITIZER_INTERFACE_ATTRIBUTE int
  1887. __dfsw_write(int fd, const void *buf, size_t count,
  1888. dfsan_label fd_label, dfsan_label buf_label,
  1889. dfsan_label count_label, dfsan_label *ret_label) {
  1890. if (write_callback_info.write_callback) {
  1891. setup_tls_args_for_write_callback(fd_label, buf_label, count_label, false,
  1892. 0, 0, 0);
  1893. write_callback_info.write_callback(fd, buf, count);
  1894. }
  1895. *ret_label = 0;
  1896. return write(fd, buf, count);
  1897. }
  1898. SANITIZER_INTERFACE_ATTRIBUTE int __dfso_write(
  1899. int fd, const void *buf, size_t count, dfsan_label fd_label,
  1900. dfsan_label buf_label, dfsan_label count_label, dfsan_label *ret_label,
  1901. dfsan_origin fd_origin, dfsan_origin buf_origin, dfsan_origin count_origin,
  1902. dfsan_origin *ret_origin) {
  1903. if (write_callback_info.write_callback) {
  1904. setup_tls_args_for_write_callback(fd_label, buf_label, count_label, true,
  1905. fd_origin, buf_origin, count_origin);
  1906. write_callback_info.write_callback(fd, buf, count);
  1907. }
  1908. *ret_label = 0;
  1909. return write(fd, buf, count);
  1910. }
  1911. } // namespace __dfsan
  1912. // Type used to extract a dfsan_label with va_arg()
  1913. typedef int dfsan_label_va;
  1914. // Formats a chunk either a constant string or a single format directive (e.g.,
  1915. // '%.3f').
  1916. struct Formatter {
  1917. Formatter(char *str_, const char *fmt_, size_t size_)
  1918. : str(str_), str_off(0), size(size_), fmt_start(fmt_), fmt_cur(fmt_),
  1919. width(-1) {}
  1920. int format() {
  1921. char *tmp_fmt = build_format_string();
  1922. int retval =
  1923. snprintf(str + str_off, str_off < size ? size - str_off : 0, tmp_fmt,
  1924. 0 /* used only to avoid warnings */);
  1925. free(tmp_fmt);
  1926. return retval;
  1927. }
  1928. template <typename T> int format(T arg) {
  1929. char *tmp_fmt = build_format_string();
  1930. int retval;
  1931. if (width >= 0) {
  1932. retval = snprintf(str + str_off, str_off < size ? size - str_off : 0,
  1933. tmp_fmt, width, arg);
  1934. } else {
  1935. retval = snprintf(str + str_off, str_off < size ? size - str_off : 0,
  1936. tmp_fmt, arg);
  1937. }
  1938. free(tmp_fmt);
  1939. return retval;
  1940. }
  1941. char *build_format_string() {
  1942. size_t fmt_size = fmt_cur - fmt_start + 1;
  1943. char *new_fmt = (char *)malloc(fmt_size + 1);
  1944. assert(new_fmt);
  1945. internal_memcpy(new_fmt, fmt_start, fmt_size);
  1946. new_fmt[fmt_size] = '\0';
  1947. return new_fmt;
  1948. }
  1949. char *str_cur() { return str + str_off; }
  1950. size_t num_written_bytes(int retval) {
  1951. if (retval < 0) {
  1952. return 0;
  1953. }
  1954. size_t num_avail = str_off < size ? size - str_off : 0;
  1955. if (num_avail == 0) {
  1956. return 0;
  1957. }
  1958. size_t num_written = retval;
  1959. // A return value of {v,}snprintf of size or more means that the output was
  1960. // truncated.
  1961. if (num_written >= num_avail) {
  1962. num_written -= num_avail;
  1963. }
  1964. return num_written;
  1965. }
  1966. char *str;
  1967. size_t str_off;
  1968. size_t size;
  1969. const char *fmt_start;
  1970. const char *fmt_cur;
  1971. int width;
  1972. };
  1973. // Formats the input and propagates the input labels to the output. The output
  1974. // is stored in 'str'. 'size' bounds the number of output bytes. 'format' and
  1975. // 'ap' are the format string and the list of arguments for formatting. Returns
  1976. // the return value vsnprintf would return.
  1977. //
  1978. // The function tokenizes the format string in chunks representing either a
  1979. // constant string or a single format directive (e.g., '%.3f') and formats each
  1980. // chunk independently into the output string. This approach allows to figure
  1981. // out which bytes of the output string depends on which argument and thus to
  1982. // propagate labels more precisely.
  1983. //
  1984. // WARNING: This implementation does not support conversion specifiers with
  1985. // positional arguments.
  1986. static int format_buffer(char *str, size_t size, const char *fmt,
  1987. dfsan_label *va_labels, dfsan_label *ret_label,
  1988. dfsan_origin *va_origins, dfsan_origin *ret_origin,
  1989. va_list ap) {
  1990. Formatter formatter(str, fmt, size);
  1991. while (*formatter.fmt_cur) {
  1992. formatter.fmt_start = formatter.fmt_cur;
  1993. formatter.width = -1;
  1994. int retval = 0;
  1995. if (*formatter.fmt_cur != '%') {
  1996. // Ordinary character. Consume all the characters until a '%' or the end
  1997. // of the string.
  1998. for (; *(formatter.fmt_cur + 1) && *(formatter.fmt_cur + 1) != '%';
  1999. ++formatter.fmt_cur) {}
  2000. retval = formatter.format();
  2001. dfsan_set_label(0, formatter.str_cur(),
  2002. formatter.num_written_bytes(retval));
  2003. } else {
  2004. // Conversion directive. Consume all the characters until a conversion
  2005. // specifier or the end of the string.
  2006. bool end_fmt = false;
  2007. for (; *formatter.fmt_cur && !end_fmt; ) {
  2008. switch (*++formatter.fmt_cur) {
  2009. case 'd':
  2010. case 'i':
  2011. case 'o':
  2012. case 'u':
  2013. case 'x':
  2014. case 'X':
  2015. switch (*(formatter.fmt_cur - 1)) {
  2016. case 'h':
  2017. // Also covers the 'hh' case (since the size of the arg is still
  2018. // an int).
  2019. retval = formatter.format(va_arg(ap, int));
  2020. break;
  2021. case 'l':
  2022. if (formatter.fmt_cur - formatter.fmt_start >= 2 &&
  2023. *(formatter.fmt_cur - 2) == 'l') {
  2024. retval = formatter.format(va_arg(ap, long long int));
  2025. } else {
  2026. retval = formatter.format(va_arg(ap, long int));
  2027. }
  2028. break;
  2029. case 'q':
  2030. retval = formatter.format(va_arg(ap, long long int));
  2031. break;
  2032. case 'j':
  2033. retval = formatter.format(va_arg(ap, intmax_t));
  2034. break;
  2035. case 'z':
  2036. case 't':
  2037. retval = formatter.format(va_arg(ap, size_t));
  2038. break;
  2039. default:
  2040. retval = formatter.format(va_arg(ap, int));
  2041. }
  2042. if (va_origins == nullptr)
  2043. dfsan_set_label(*va_labels++, formatter.str_cur(),
  2044. formatter.num_written_bytes(retval));
  2045. else
  2046. dfsan_set_label_origin(*va_labels++, *va_origins++,
  2047. formatter.str_cur(),
  2048. formatter.num_written_bytes(retval));
  2049. end_fmt = true;
  2050. break;
  2051. case 'a':
  2052. case 'A':
  2053. case 'e':
  2054. case 'E':
  2055. case 'f':
  2056. case 'F':
  2057. case 'g':
  2058. case 'G':
  2059. if (*(formatter.fmt_cur - 1) == 'L') {
  2060. retval = formatter.format(va_arg(ap, long double));
  2061. } else {
  2062. retval = formatter.format(va_arg(ap, double));
  2063. }
  2064. if (va_origins == nullptr)
  2065. dfsan_set_label(*va_labels++, formatter.str_cur(),
  2066. formatter.num_written_bytes(retval));
  2067. else
  2068. dfsan_set_label_origin(*va_labels++, *va_origins++,
  2069. formatter.str_cur(),
  2070. formatter.num_written_bytes(retval));
  2071. end_fmt = true;
  2072. break;
  2073. case 'c':
  2074. retval = formatter.format(va_arg(ap, int));
  2075. if (va_origins == nullptr)
  2076. dfsan_set_label(*va_labels++, formatter.str_cur(),
  2077. formatter.num_written_bytes(retval));
  2078. else
  2079. dfsan_set_label_origin(*va_labels++, *va_origins++,
  2080. formatter.str_cur(),
  2081. formatter.num_written_bytes(retval));
  2082. end_fmt = true;
  2083. break;
  2084. case 's': {
  2085. char *arg = va_arg(ap, char *);
  2086. retval = formatter.format(arg);
  2087. if (va_origins) {
  2088. va_origins++;
  2089. dfsan_mem_origin_transfer(formatter.str_cur(), arg,
  2090. formatter.num_written_bytes(retval));
  2091. }
  2092. va_labels++;
  2093. dfsan_mem_shadow_transfer(formatter.str_cur(), arg,
  2094. formatter.num_written_bytes(retval));
  2095. end_fmt = true;
  2096. break;
  2097. }
  2098. case 'p':
  2099. retval = formatter.format(va_arg(ap, void *));
  2100. if (va_origins == nullptr)
  2101. dfsan_set_label(*va_labels++, formatter.str_cur(),
  2102. formatter.num_written_bytes(retval));
  2103. else
  2104. dfsan_set_label_origin(*va_labels++, *va_origins++,
  2105. formatter.str_cur(),
  2106. formatter.num_written_bytes(retval));
  2107. end_fmt = true;
  2108. break;
  2109. case 'n': {
  2110. int *ptr = va_arg(ap, int *);
  2111. *ptr = (int)formatter.str_off;
  2112. va_labels++;
  2113. if (va_origins)
  2114. va_origins++;
  2115. dfsan_set_label(0, ptr, sizeof(ptr));
  2116. end_fmt = true;
  2117. break;
  2118. }
  2119. case '%':
  2120. retval = formatter.format();
  2121. dfsan_set_label(0, formatter.str_cur(),
  2122. formatter.num_written_bytes(retval));
  2123. end_fmt = true;
  2124. break;
  2125. case '*':
  2126. formatter.width = va_arg(ap, int);
  2127. va_labels++;
  2128. if (va_origins)
  2129. va_origins++;
  2130. break;
  2131. default:
  2132. break;
  2133. }
  2134. }
  2135. }
  2136. if (retval < 0) {
  2137. return retval;
  2138. }
  2139. formatter.fmt_cur++;
  2140. formatter.str_off += retval;
  2141. }
  2142. *ret_label = 0;
  2143. if (ret_origin)
  2144. *ret_origin = 0;
  2145. // Number of bytes written in total.
  2146. return formatter.str_off;
  2147. }
  2148. extern "C" {
  2149. SANITIZER_INTERFACE_ATTRIBUTE
  2150. int __dfsw_sprintf(char *str, const char *format, dfsan_label str_label,
  2151. dfsan_label format_label, dfsan_label *va_labels,
  2152. dfsan_label *ret_label, ...) {
  2153. va_list ap;
  2154. va_start(ap, ret_label);
  2155. int ret = format_buffer(str, ~0ul, format, va_labels, ret_label, nullptr,
  2156. nullptr, ap);
  2157. va_end(ap);
  2158. return ret;
  2159. }
  2160. SANITIZER_INTERFACE_ATTRIBUTE
  2161. int __dfso_sprintf(char *str, const char *format, dfsan_label str_label,
  2162. dfsan_label format_label, dfsan_label *va_labels,
  2163. dfsan_label *ret_label, dfsan_origin str_origin,
  2164. dfsan_origin format_origin, dfsan_origin *va_origins,
  2165. dfsan_origin *ret_origin, ...) {
  2166. va_list ap;
  2167. va_start(ap, ret_origin);
  2168. int ret = format_buffer(str, ~0ul, format, va_labels, ret_label, va_origins,
  2169. ret_origin, ap);
  2170. va_end(ap);
  2171. return ret;
  2172. }
  2173. SANITIZER_INTERFACE_ATTRIBUTE
  2174. int __dfsw_snprintf(char *str, size_t size, const char *format,
  2175. dfsan_label str_label, dfsan_label size_label,
  2176. dfsan_label format_label, dfsan_label *va_labels,
  2177. dfsan_label *ret_label, ...) {
  2178. va_list ap;
  2179. va_start(ap, ret_label);
  2180. int ret = format_buffer(str, size, format, va_labels, ret_label, nullptr,
  2181. nullptr, ap);
  2182. va_end(ap);
  2183. return ret;
  2184. }
  2185. SANITIZER_INTERFACE_ATTRIBUTE
  2186. int __dfso_snprintf(char *str, size_t size, const char *format,
  2187. dfsan_label str_label, dfsan_label size_label,
  2188. dfsan_label format_label, dfsan_label *va_labels,
  2189. dfsan_label *ret_label, dfsan_origin str_origin,
  2190. dfsan_origin size_origin, dfsan_origin format_origin,
  2191. dfsan_origin *va_origins, dfsan_origin *ret_origin, ...) {
  2192. va_list ap;
  2193. va_start(ap, ret_origin);
  2194. int ret = format_buffer(str, size, format, va_labels, ret_label, va_origins,
  2195. ret_origin, ap);
  2196. va_end(ap);
  2197. return ret;
  2198. }
  2199. static void BeforeFork() {
  2200. StackDepotLockAll();
  2201. GetChainedOriginDepot()->LockAll();
  2202. }
  2203. static void AfterFork() {
  2204. GetChainedOriginDepot()->UnlockAll();
  2205. StackDepotUnlockAll();
  2206. }
  2207. SANITIZER_INTERFACE_ATTRIBUTE
  2208. pid_t __dfsw_fork(dfsan_label *ret_label) {
  2209. pid_t pid = fork();
  2210. *ret_label = 0;
  2211. return pid;
  2212. }
  2213. SANITIZER_INTERFACE_ATTRIBUTE
  2214. pid_t __dfso_fork(dfsan_label *ret_label, dfsan_origin *ret_origin) {
  2215. BeforeFork();
  2216. pid_t pid = __dfsw_fork(ret_label);
  2217. AfterFork();
  2218. return pid;
  2219. }
  2220. // Default empty implementations (weak). Users should redefine them.
  2221. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard, u32 *) {}
  2222. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard_init, u32 *,
  2223. u32 *) {}
  2224. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_pcs_init, const uptr *beg,
  2225. const uptr *end) {}
  2226. SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_indir, void) {}
  2227. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_cmp, void) {}
  2228. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_cmp1, void) {}
  2229. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_cmp2, void) {}
  2230. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_cmp4, void) {}
  2231. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_cmp8, void) {}
  2232. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_const_cmp1,
  2233. void) {}
  2234. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_const_cmp2,
  2235. void) {}
  2236. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_const_cmp4,
  2237. void) {}
  2238. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_const_cmp8,
  2239. void) {}
  2240. SANITIZER_INTERFACE_WEAK_DEF(void, __dfsw___sanitizer_cov_trace_switch, void) {}
  2241. } // extern "C"