hwasan.cpp 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766
  1. //===-- hwasan.cpp --------------------------------------------------------===//
  2. //
  3. // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
  4. // See https://llvm.org/LICENSE.txt for license information.
  5. // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
  6. //
  7. //===----------------------------------------------------------------------===//
  8. //
  9. // This file is a part of HWAddressSanitizer.
  10. //
  11. // HWAddressSanitizer runtime.
  12. //===----------------------------------------------------------------------===//
  13. #include "hwasan.h"
  14. #include "hwasan_checks.h"
  15. #include "hwasan_dynamic_shadow.h"
  16. #include "hwasan_globals.h"
  17. #include "hwasan_mapping.h"
  18. #include "hwasan_poisoning.h"
  19. #include "hwasan_report.h"
  20. #include "hwasan_thread.h"
  21. #include "hwasan_thread_list.h"
  22. #include "sanitizer_common/sanitizer_atomic.h"
  23. #include "sanitizer_common/sanitizer_common.h"
  24. #include "sanitizer_common/sanitizer_flag_parser.h"
  25. #include "sanitizer_common/sanitizer_flags.h"
  26. #include "sanitizer_common/sanitizer_interface_internal.h"
  27. #include "sanitizer_common/sanitizer_libc.h"
  28. #include "sanitizer_common/sanitizer_procmaps.h"
  29. #include "sanitizer_common/sanitizer_stackdepot.h"
  30. #include "sanitizer_common/sanitizer_stacktrace.h"
  31. #include "sanitizer_common/sanitizer_symbolizer.h"
  32. #include "ubsan/ubsan_flags.h"
  33. #include "ubsan/ubsan_init.h"
  34. // ACHTUNG! No system header includes in this file.
  35. using namespace __sanitizer;
  36. namespace __hwasan {
  37. static Flags hwasan_flags;
  38. Flags *flags() {
  39. return &hwasan_flags;
  40. }
  41. int hwasan_inited = 0;
  42. int hwasan_instrumentation_inited = 0;
  43. bool hwasan_init_is_running;
  44. int hwasan_report_count = 0;
  45. uptr kLowShadowStart;
  46. uptr kLowShadowEnd;
  47. uptr kHighShadowStart;
  48. uptr kHighShadowEnd;
  49. void Flags::SetDefaults() {
  50. #define HWASAN_FLAG(Type, Name, DefaultValue, Description) Name = DefaultValue;
  51. #include "hwasan_flags.inc"
  52. #undef HWASAN_FLAG
  53. }
  54. static void RegisterHwasanFlags(FlagParser *parser, Flags *f) {
  55. #define HWASAN_FLAG(Type, Name, DefaultValue, Description) \
  56. RegisterFlag(parser, #Name, Description, &f->Name);
  57. #include "hwasan_flags.inc"
  58. #undef HWASAN_FLAG
  59. }
  60. static void InitializeFlags() {
  61. SetCommonFlagsDefaults();
  62. {
  63. CommonFlags cf;
  64. cf.CopyFrom(*common_flags());
  65. cf.external_symbolizer_path = GetEnv("HWASAN_SYMBOLIZER_PATH");
  66. cf.malloc_context_size = 20;
  67. cf.handle_ioctl = true;
  68. // FIXME: test and enable.
  69. cf.check_printf = false;
  70. cf.intercept_tls_get_addr = true;
  71. cf.exitcode = 99;
  72. // 8 shadow pages ~512kB, small enough to cover common stack sizes.
  73. cf.clear_shadow_mmap_threshold = 4096 * (SANITIZER_ANDROID ? 2 : 8);
  74. // Sigtrap is used in error reporting.
  75. cf.handle_sigtrap = kHandleSignalExclusive;
  76. // For now only tested on Linux and Fuchsia. Other plantforms can be turned
  77. // on as they become ready.
  78. constexpr bool can_detect_leaks =
  79. (SANITIZER_LINUX && !SANITIZER_ANDROID) || SANITIZER_FUCHSIA;
  80. cf.detect_leaks = cf.detect_leaks && can_detect_leaks;
  81. #if SANITIZER_ANDROID
  82. // Let platform handle other signals. It is better at reporting them then we
  83. // are.
  84. cf.handle_segv = kHandleSignalNo;
  85. cf.handle_sigbus = kHandleSignalNo;
  86. cf.handle_abort = kHandleSignalNo;
  87. cf.handle_sigill = kHandleSignalNo;
  88. cf.handle_sigfpe = kHandleSignalNo;
  89. #endif
  90. OverrideCommonFlags(cf);
  91. }
  92. Flags *f = flags();
  93. f->SetDefaults();
  94. FlagParser parser;
  95. RegisterHwasanFlags(&parser, f);
  96. RegisterCommonFlags(&parser);
  97. #if CAN_SANITIZE_LEAKS
  98. __lsan::Flags *lf = __lsan::flags();
  99. lf->SetDefaults();
  100. FlagParser lsan_parser;
  101. __lsan::RegisterLsanFlags(&lsan_parser, lf);
  102. RegisterCommonFlags(&lsan_parser);
  103. #endif
  104. #if HWASAN_CONTAINS_UBSAN
  105. __ubsan::Flags *uf = __ubsan::flags();
  106. uf->SetDefaults();
  107. FlagParser ubsan_parser;
  108. __ubsan::RegisterUbsanFlags(&ubsan_parser, uf);
  109. RegisterCommonFlags(&ubsan_parser);
  110. #endif
  111. // Override from user-specified string.
  112. if (__hwasan_default_options)
  113. parser.ParseString(__hwasan_default_options());
  114. #if CAN_SANITIZE_LEAKS
  115. lsan_parser.ParseString(__lsan_default_options());
  116. #endif
  117. #if HWASAN_CONTAINS_UBSAN
  118. const char *ubsan_default_options = __ubsan_default_options();
  119. ubsan_parser.ParseString(ubsan_default_options);
  120. #endif
  121. parser.ParseStringFromEnv("HWASAN_OPTIONS");
  122. #if CAN_SANITIZE_LEAKS
  123. lsan_parser.ParseStringFromEnv("LSAN_OPTIONS");
  124. #endif
  125. #if HWASAN_CONTAINS_UBSAN
  126. ubsan_parser.ParseStringFromEnv("UBSAN_OPTIONS");
  127. #endif
  128. InitializeCommonFlags();
  129. if (Verbosity()) ReportUnrecognizedFlags();
  130. if (common_flags()->help) parser.PrintFlagDescriptions();
  131. // Flag validation:
  132. if (!CAN_SANITIZE_LEAKS && common_flags()->detect_leaks) {
  133. Report("%s: detect_leaks is not supported on this platform.\n",
  134. SanitizerToolName);
  135. Die();
  136. }
  137. }
  138. static void CheckUnwind() {
  139. GET_FATAL_STACK_TRACE_PC_BP(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME());
  140. stack.Print();
  141. }
  142. static void HwasanFormatMemoryUsage(InternalScopedString &s) {
  143. HwasanThreadList &thread_list = hwasanThreadList();
  144. auto thread_stats = thread_list.GetThreadStats();
  145. auto sds = StackDepotGetStats();
  146. AllocatorStatCounters asc;
  147. GetAllocatorStats(asc);
  148. s.AppendF(
  149. "HWASAN pid: %d rss: %zd threads: %zd stacks: %zd"
  150. " thr_aux: %zd stack_depot: %zd uniq_stacks: %zd"
  151. " heap: %zd",
  152. internal_getpid(), GetRSS(), thread_stats.n_live_threads,
  153. thread_stats.total_stack_size,
  154. thread_stats.n_live_threads * thread_list.MemoryUsedPerThread(),
  155. sds.allocated, sds.n_uniq_ids, asc[AllocatorStatMapped]);
  156. }
  157. #if SANITIZER_ANDROID
  158. static constexpr uptr kMemoryUsageBufferSize = 4096;
  159. static char *memory_usage_buffer = nullptr;
  160. static void InitMemoryUsage() {
  161. memory_usage_buffer =
  162. (char *)MmapOrDie(kMemoryUsageBufferSize, "memory usage string");
  163. CHECK(memory_usage_buffer);
  164. memory_usage_buffer[0] = '\0';
  165. DecorateMapping((uptr)memory_usage_buffer, kMemoryUsageBufferSize,
  166. memory_usage_buffer);
  167. }
  168. void UpdateMemoryUsage() {
  169. if (!flags()->export_memory_stats)
  170. return;
  171. if (!memory_usage_buffer)
  172. InitMemoryUsage();
  173. InternalScopedString s;
  174. HwasanFormatMemoryUsage(s);
  175. internal_strncpy(memory_usage_buffer, s.data(), kMemoryUsageBufferSize - 1);
  176. memory_usage_buffer[kMemoryUsageBufferSize - 1] = '\0';
  177. }
  178. #else
  179. void UpdateMemoryUsage() {}
  180. #endif
  181. void HwasanAtExit() {
  182. if (common_flags()->print_module_map)
  183. DumpProcessMap();
  184. if (flags()->print_stats && (flags()->atexit || hwasan_report_count > 0))
  185. ReportStats();
  186. if (hwasan_report_count > 0) {
  187. // ReportAtExitStatistics();
  188. if (common_flags()->exitcode)
  189. internal__exit(common_flags()->exitcode);
  190. }
  191. }
  192. void HandleTagMismatch(AccessInfo ai, uptr pc, uptr frame, void *uc,
  193. uptr *registers_frame) {
  194. InternalMmapVector<BufferedStackTrace> stack_buffer(1);
  195. BufferedStackTrace *stack = stack_buffer.data();
  196. stack->Reset();
  197. stack->Unwind(pc, frame, uc, common_flags()->fast_unwind_on_fatal);
  198. // The second stack frame contains the failure __hwasan_check function, as
  199. // we have a stack frame for the registers saved in __hwasan_tag_mismatch that
  200. // we wish to ignore. This (currently) only occurs on AArch64, as x64
  201. // implementations use SIGTRAP to implement the failure, and thus do not go
  202. // through the stack saver.
  203. if (registers_frame && stack->trace && stack->size > 0) {
  204. stack->trace++;
  205. stack->size--;
  206. }
  207. bool fatal = flags()->halt_on_error || !ai.recover;
  208. ReportTagMismatch(stack, ai.addr, ai.size, ai.is_store, fatal,
  209. registers_frame);
  210. }
  211. void HwasanTagMismatch(uptr addr, uptr pc, uptr frame, uptr access_info,
  212. uptr *registers_frame, size_t outsize) {
  213. __hwasan::AccessInfo ai;
  214. ai.is_store = access_info & 0x10;
  215. ai.is_load = !ai.is_store;
  216. ai.recover = access_info & 0x20;
  217. ai.addr = addr;
  218. if ((access_info & 0xf) == 0xf)
  219. ai.size = outsize;
  220. else
  221. ai.size = 1 << (access_info & 0xf);
  222. HandleTagMismatch(ai, pc, frame, nullptr, registers_frame);
  223. }
  224. Thread *GetCurrentThread() {
  225. uptr *ThreadLongPtr = GetCurrentThreadLongPtr();
  226. if (UNLIKELY(*ThreadLongPtr == 0))
  227. return nullptr;
  228. auto *R = (StackAllocationsRingBuffer *)ThreadLongPtr;
  229. return hwasanThreadList().GetThreadByBufferAddress((uptr)R->Next());
  230. }
  231. } // namespace __hwasan
  232. using namespace __hwasan;
  233. void __sanitizer::BufferedStackTrace::UnwindImpl(
  234. uptr pc, uptr bp, void *context, bool request_fast, u32 max_depth) {
  235. Thread *t = GetCurrentThread();
  236. if (!t) {
  237. // The thread is still being created, or has already been destroyed.
  238. size = 0;
  239. return;
  240. }
  241. Unwind(max_depth, pc, bp, context, t->stack_top(), t->stack_bottom(),
  242. request_fast);
  243. }
  244. static bool InitializeSingleGlobal(const hwasan_global &global) {
  245. uptr full_granule_size = RoundDownTo(global.size(), 16);
  246. TagMemoryAligned(global.addr(), full_granule_size, global.tag());
  247. if (global.size() % 16)
  248. TagMemoryAligned(global.addr() + full_granule_size, 16, global.size() % 16);
  249. return false;
  250. }
  251. static void InitLoadedGlobals() {
  252. // Fuchsia's libc provides a hook (__sanitizer_module_loaded) that runs on
  253. // the startup path which calls into __hwasan_library_loaded on all
  254. // initially loaded modules, so explicitly registering the globals here
  255. // isn't needed.
  256. if constexpr (!SANITIZER_FUCHSIA) {
  257. dl_iterate_phdr(
  258. [](dl_phdr_info *info, size_t /* size */, void * /* data */) -> int {
  259. for (const hwasan_global &global : HwasanGlobalsFor(
  260. info->dlpi_addr, info->dlpi_phdr, info->dlpi_phnum))
  261. InitializeSingleGlobal(global);
  262. return 0;
  263. },
  264. nullptr);
  265. }
  266. }
  267. // Prepare to run instrumented code on the main thread.
  268. static void InitInstrumentation() {
  269. if (hwasan_instrumentation_inited) return;
  270. InitializeOsSupport();
  271. if (!InitShadow()) {
  272. Printf("FATAL: HWAddressSanitizer cannot mmap the shadow memory.\n");
  273. DumpProcessMap();
  274. Die();
  275. }
  276. InitThreads();
  277. hwasan_instrumentation_inited = 1;
  278. }
  279. // Interface.
  280. uptr __hwasan_shadow_memory_dynamic_address; // Global interface symbol.
  281. // This function was used by the old frame descriptor mechanism. We keep it
  282. // around to avoid breaking ABI.
  283. void __hwasan_init_frames(uptr beg, uptr end) {}
  284. void __hwasan_init_static() {
  285. InitShadowGOT();
  286. InitInstrumentation();
  287. // In the non-static code path we call dl_iterate_phdr here. But at this point
  288. // libc might not have been initialized enough for dl_iterate_phdr to work.
  289. // Fortunately, since this is a statically linked executable we can use the
  290. // linker-defined symbol __ehdr_start to find the only relevant set of phdrs.
  291. extern ElfW(Ehdr) __ehdr_start;
  292. for (const hwasan_global &global : HwasanGlobalsFor(
  293. /* base */ 0,
  294. reinterpret_cast<const ElfW(Phdr) *>(
  295. reinterpret_cast<const char *>(&__ehdr_start) +
  296. __ehdr_start.e_phoff),
  297. __ehdr_start.e_phnum))
  298. InitializeSingleGlobal(global);
  299. }
  300. __attribute__((constructor(0))) void __hwasan_init() {
  301. CHECK(!hwasan_init_is_running);
  302. if (hwasan_inited) return;
  303. hwasan_init_is_running = 1;
  304. SanitizerToolName = "HWAddressSanitizer";
  305. InitTlsSize();
  306. CacheBinaryName();
  307. InitializeFlags();
  308. // Install tool-specific callbacks in sanitizer_common.
  309. SetCheckUnwindCallback(CheckUnwind);
  310. __sanitizer_set_report_path(common_flags()->log_path);
  311. AndroidTestTlsSlot();
  312. DisableCoreDumperIfNecessary();
  313. InitInstrumentation();
  314. InitLoadedGlobals();
  315. // Needs to be called here because flags()->random_tags might not have been
  316. // initialized when InitInstrumentation() was called.
  317. GetCurrentThread()->EnsureRandomStateInited();
  318. SetPrintfAndReportCallback(AppendToErrorMessageBuffer);
  319. // This may call libc -> needs initialized shadow.
  320. AndroidLogInit();
  321. InitializeInterceptors();
  322. InstallDeadlySignalHandlers(HwasanOnDeadlySignal);
  323. InstallAtExitHandler(); // Needs __cxa_atexit interceptor.
  324. InitializeCoverage(common_flags()->coverage, common_flags()->coverage_dir);
  325. HwasanTSDInit();
  326. HwasanTSDThreadInit();
  327. HwasanAllocatorInit();
  328. HwasanInstallAtForkHandler();
  329. if (CAN_SANITIZE_LEAKS) {
  330. __lsan::InitCommonLsan();
  331. InstallAtExitCheckLeaks();
  332. }
  333. #if HWASAN_CONTAINS_UBSAN
  334. __ubsan::InitAsPlugin();
  335. #endif
  336. if (CAN_SANITIZE_LEAKS && common_flags()->detect_leaks) {
  337. __lsan::ScopedInterceptorDisabler disabler;
  338. Symbolizer::LateInitialize();
  339. }
  340. VPrintf(1, "HWAddressSanitizer init done\n");
  341. hwasan_init_is_running = 0;
  342. hwasan_inited = 1;
  343. }
  344. void __hwasan_library_loaded(ElfW(Addr) base, const ElfW(Phdr) * phdr,
  345. ElfW(Half) phnum) {
  346. for (const hwasan_global &global : HwasanGlobalsFor(base, phdr, phnum))
  347. InitializeSingleGlobal(global);
  348. }
  349. void __hwasan_library_unloaded(ElfW(Addr) base, const ElfW(Phdr) * phdr,
  350. ElfW(Half) phnum) {
  351. for (; phnum != 0; ++phdr, --phnum)
  352. if (phdr->p_type == PT_LOAD)
  353. TagMemory(base + phdr->p_vaddr, phdr->p_memsz, 0);
  354. }
  355. void __hwasan_print_shadow(const void *p, uptr sz) {
  356. uptr ptr_raw = UntagAddr(reinterpret_cast<uptr>(p));
  357. uptr shadow_first = MemToShadow(ptr_raw);
  358. uptr shadow_last = MemToShadow(ptr_raw + sz - 1);
  359. Printf("HWASan shadow map for %zx .. %zx (pointer tag %x)\n", ptr_raw,
  360. ptr_raw + sz, GetTagFromPointer((uptr)p));
  361. for (uptr s = shadow_first; s <= shadow_last; ++s) {
  362. tag_t mem_tag = *reinterpret_cast<tag_t *>(s);
  363. uptr granule_addr = ShadowToMem(s);
  364. if (mem_tag && mem_tag < kShadowAlignment)
  365. Printf(" %zx: %02x(%02x)\n", granule_addr, mem_tag,
  366. *reinterpret_cast<tag_t *>(granule_addr + kShadowAlignment - 1));
  367. else
  368. Printf(" %zx: %02x\n", granule_addr, mem_tag);
  369. }
  370. }
  371. sptr __hwasan_test_shadow(const void *p, uptr sz) {
  372. if (sz == 0)
  373. return -1;
  374. uptr ptr = reinterpret_cast<uptr>(p);
  375. tag_t ptr_tag = GetTagFromPointer(ptr);
  376. uptr ptr_raw = UntagAddr(ptr);
  377. uptr shadow_first = MemToShadow(ptr_raw);
  378. uptr shadow_last = MemToShadow(ptr_raw + sz);
  379. for (uptr s = shadow_first; s < shadow_last; ++s) {
  380. if (UNLIKELY(*(tag_t *)s != ptr_tag)) {
  381. uptr short_size =
  382. ShortTagSize(*(tag_t *)s, AddTagToPointer(ShadowToMem(s), ptr_tag));
  383. sptr offset = ShadowToMem(s) - ptr_raw + short_size;
  384. return offset < 0 ? 0 : offset;
  385. }
  386. }
  387. uptr end = ptr + sz;
  388. uptr tail_sz = end & (kShadowAlignment - 1);
  389. if (!tail_sz)
  390. return -1;
  391. uptr short_size =
  392. ShortTagSize(*(tag_t *)shadow_last, end & ~(kShadowAlignment - 1));
  393. if (LIKELY(tail_sz <= short_size))
  394. return -1;
  395. sptr offset = sz - tail_sz + short_size;
  396. return offset < 0 ? 0 : offset;
  397. }
  398. u16 __sanitizer_unaligned_load16(const uu16 *p) {
  399. return *p;
  400. }
  401. u32 __sanitizer_unaligned_load32(const uu32 *p) {
  402. return *p;
  403. }
  404. u64 __sanitizer_unaligned_load64(const uu64 *p) {
  405. return *p;
  406. }
  407. void __sanitizer_unaligned_store16(uu16 *p, u16 x) {
  408. *p = x;
  409. }
  410. void __sanitizer_unaligned_store32(uu32 *p, u32 x) {
  411. *p = x;
  412. }
  413. void __sanitizer_unaligned_store64(uu64 *p, u64 x) {
  414. *p = x;
  415. }
  416. void __hwasan_loadN(uptr p, uptr sz) {
  417. CheckAddressSized<ErrorAction::Abort, AccessType::Load>(p, sz);
  418. }
  419. void __hwasan_load1(uptr p) {
  420. CheckAddress<ErrorAction::Abort, AccessType::Load, 0>(p);
  421. }
  422. void __hwasan_load2(uptr p) {
  423. CheckAddress<ErrorAction::Abort, AccessType::Load, 1>(p);
  424. }
  425. void __hwasan_load4(uptr p) {
  426. CheckAddress<ErrorAction::Abort, AccessType::Load, 2>(p);
  427. }
  428. void __hwasan_load8(uptr p) {
  429. CheckAddress<ErrorAction::Abort, AccessType::Load, 3>(p);
  430. }
  431. void __hwasan_load16(uptr p) {
  432. CheckAddress<ErrorAction::Abort, AccessType::Load, 4>(p);
  433. }
  434. void __hwasan_loadN_noabort(uptr p, uptr sz) {
  435. CheckAddressSized<ErrorAction::Recover, AccessType::Load>(p, sz);
  436. }
  437. void __hwasan_load1_noabort(uptr p) {
  438. CheckAddress<ErrorAction::Recover, AccessType::Load, 0>(p);
  439. }
  440. void __hwasan_load2_noabort(uptr p) {
  441. CheckAddress<ErrorAction::Recover, AccessType::Load, 1>(p);
  442. }
  443. void __hwasan_load4_noabort(uptr p) {
  444. CheckAddress<ErrorAction::Recover, AccessType::Load, 2>(p);
  445. }
  446. void __hwasan_load8_noabort(uptr p) {
  447. CheckAddress<ErrorAction::Recover, AccessType::Load, 3>(p);
  448. }
  449. void __hwasan_load16_noabort(uptr p) {
  450. CheckAddress<ErrorAction::Recover, AccessType::Load, 4>(p);
  451. }
  452. void __hwasan_loadN_match_all(uptr p, uptr sz, u8 match_all_tag) {
  453. if (GetTagFromPointer(p) != match_all_tag)
  454. CheckAddressSized<ErrorAction::Abort, AccessType::Load>(p, sz);
  455. }
  456. void __hwasan_load1_match_all(uptr p, u8 match_all_tag) {
  457. if (GetTagFromPointer(p) != match_all_tag)
  458. CheckAddress<ErrorAction::Abort, AccessType::Load, 0>(p);
  459. }
  460. void __hwasan_load2_match_all(uptr p, u8 match_all_tag) {
  461. if (GetTagFromPointer(p) != match_all_tag)
  462. CheckAddress<ErrorAction::Abort, AccessType::Load, 1>(p);
  463. }
  464. void __hwasan_load4_match_all(uptr p, u8 match_all_tag) {
  465. if (GetTagFromPointer(p) != match_all_tag)
  466. CheckAddress<ErrorAction::Abort, AccessType::Load, 2>(p);
  467. }
  468. void __hwasan_load8_match_all(uptr p, u8 match_all_tag) {
  469. if (GetTagFromPointer(p) != match_all_tag)
  470. CheckAddress<ErrorAction::Abort, AccessType::Load, 3>(p);
  471. }
  472. void __hwasan_load16_match_all(uptr p, u8 match_all_tag) {
  473. if (GetTagFromPointer(p) != match_all_tag)
  474. CheckAddress<ErrorAction::Abort, AccessType::Load, 4>(p);
  475. }
  476. void __hwasan_loadN_match_all_noabort(uptr p, uptr sz, u8 match_all_tag) {
  477. if (GetTagFromPointer(p) != match_all_tag)
  478. CheckAddressSized<ErrorAction::Recover, AccessType::Load>(p, sz);
  479. }
  480. void __hwasan_load1_match_all_noabort(uptr p, u8 match_all_tag) {
  481. if (GetTagFromPointer(p) != match_all_tag)
  482. CheckAddress<ErrorAction::Recover, AccessType::Load, 0>(p);
  483. }
  484. void __hwasan_load2_match_all_noabort(uptr p, u8 match_all_tag) {
  485. if (GetTagFromPointer(p) != match_all_tag)
  486. CheckAddress<ErrorAction::Recover, AccessType::Load, 1>(p);
  487. }
  488. void __hwasan_load4_match_all_noabort(uptr p, u8 match_all_tag) {
  489. if (GetTagFromPointer(p) != match_all_tag)
  490. CheckAddress<ErrorAction::Recover, AccessType::Load, 2>(p);
  491. }
  492. void __hwasan_load8_match_all_noabort(uptr p, u8 match_all_tag) {
  493. if (GetTagFromPointer(p) != match_all_tag)
  494. CheckAddress<ErrorAction::Recover, AccessType::Load, 3>(p);
  495. }
  496. void __hwasan_load16_match_all_noabort(uptr p, u8 match_all_tag) {
  497. if (GetTagFromPointer(p) != match_all_tag)
  498. CheckAddress<ErrorAction::Recover, AccessType::Load, 4>(p);
  499. }
  500. void __hwasan_storeN(uptr p, uptr sz) {
  501. CheckAddressSized<ErrorAction::Abort, AccessType::Store>(p, sz);
  502. }
  503. void __hwasan_store1(uptr p) {
  504. CheckAddress<ErrorAction::Abort, AccessType::Store, 0>(p);
  505. }
  506. void __hwasan_store2(uptr p) {
  507. CheckAddress<ErrorAction::Abort, AccessType::Store, 1>(p);
  508. }
  509. void __hwasan_store4(uptr p) {
  510. CheckAddress<ErrorAction::Abort, AccessType::Store, 2>(p);
  511. }
  512. void __hwasan_store8(uptr p) {
  513. CheckAddress<ErrorAction::Abort, AccessType::Store, 3>(p);
  514. }
  515. void __hwasan_store16(uptr p) {
  516. CheckAddress<ErrorAction::Abort, AccessType::Store, 4>(p);
  517. }
  518. void __hwasan_storeN_noabort(uptr p, uptr sz) {
  519. CheckAddressSized<ErrorAction::Recover, AccessType::Store>(p, sz);
  520. }
  521. void __hwasan_store1_noabort(uptr p) {
  522. CheckAddress<ErrorAction::Recover, AccessType::Store, 0>(p);
  523. }
  524. void __hwasan_store2_noabort(uptr p) {
  525. CheckAddress<ErrorAction::Recover, AccessType::Store, 1>(p);
  526. }
  527. void __hwasan_store4_noabort(uptr p) {
  528. CheckAddress<ErrorAction::Recover, AccessType::Store, 2>(p);
  529. }
  530. void __hwasan_store8_noabort(uptr p) {
  531. CheckAddress<ErrorAction::Recover, AccessType::Store, 3>(p);
  532. }
  533. void __hwasan_store16_noabort(uptr p) {
  534. CheckAddress<ErrorAction::Recover, AccessType::Store, 4>(p);
  535. }
  536. void __hwasan_storeN_match_all(uptr p, uptr sz, u8 match_all_tag) {
  537. if (GetTagFromPointer(p) != match_all_tag)
  538. CheckAddressSized<ErrorAction::Abort, AccessType::Store>(p, sz);
  539. }
  540. void __hwasan_store1_match_all(uptr p, u8 match_all_tag) {
  541. if (GetTagFromPointer(p) != match_all_tag)
  542. CheckAddress<ErrorAction::Abort, AccessType::Store, 0>(p);
  543. }
  544. void __hwasan_store2_match_all(uptr p, u8 match_all_tag) {
  545. if (GetTagFromPointer(p) != match_all_tag)
  546. CheckAddress<ErrorAction::Abort, AccessType::Store, 1>(p);
  547. }
  548. void __hwasan_store4_match_all(uptr p, u8 match_all_tag) {
  549. if (GetTagFromPointer(p) != match_all_tag)
  550. CheckAddress<ErrorAction::Abort, AccessType::Store, 2>(p);
  551. }
  552. void __hwasan_store8_match_all(uptr p, u8 match_all_tag) {
  553. if (GetTagFromPointer(p) != match_all_tag)
  554. CheckAddress<ErrorAction::Abort, AccessType::Store, 3>(p);
  555. }
  556. void __hwasan_store16_match_all(uptr p, u8 match_all_tag) {
  557. if (GetTagFromPointer(p) != match_all_tag)
  558. CheckAddress<ErrorAction::Abort, AccessType::Store, 4>(p);
  559. }
  560. void __hwasan_storeN_match_all_noabort(uptr p, uptr sz, u8 match_all_tag) {
  561. if (GetTagFromPointer(p) != match_all_tag)
  562. CheckAddressSized<ErrorAction::Recover, AccessType::Store>(p, sz);
  563. }
  564. void __hwasan_store1_match_all_noabort(uptr p, u8 match_all_tag) {
  565. if (GetTagFromPointer(p) != match_all_tag)
  566. CheckAddress<ErrorAction::Recover, AccessType::Store, 0>(p);
  567. }
  568. void __hwasan_store2_match_all_noabort(uptr p, u8 match_all_tag) {
  569. if (GetTagFromPointer(p) != match_all_tag)
  570. CheckAddress<ErrorAction::Recover, AccessType::Store, 1>(p);
  571. }
  572. void __hwasan_store4_match_all_noabort(uptr p, u8 match_all_tag) {
  573. if (GetTagFromPointer(p) != match_all_tag)
  574. CheckAddress<ErrorAction::Recover, AccessType::Store, 2>(p);
  575. }
  576. void __hwasan_store8_match_all_noabort(uptr p, u8 match_all_tag) {
  577. if (GetTagFromPointer(p) != match_all_tag)
  578. CheckAddress<ErrorAction::Recover, AccessType::Store, 3>(p);
  579. }
  580. void __hwasan_store16_match_all_noabort(uptr p, u8 match_all_tag) {
  581. if (GetTagFromPointer(p) != match_all_tag)
  582. CheckAddress<ErrorAction::Recover, AccessType::Store, 4>(p);
  583. }
  584. void __hwasan_tag_memory(uptr p, u8 tag, uptr sz) {
  585. TagMemoryAligned(UntagAddr(p), sz, tag);
  586. }
  587. uptr __hwasan_tag_pointer(uptr p, u8 tag) {
  588. return AddTagToPointer(p, tag);
  589. }
  590. u8 __hwasan_get_tag_from_pointer(uptr p) { return GetTagFromPointer(p); }
  591. void __hwasan_handle_longjmp(const void *sp_dst) {
  592. uptr dst = (uptr)sp_dst;
  593. // HWASan does not support tagged SP.
  594. CHECK_EQ(GetTagFromPointer(dst), 0);
  595. uptr sp = (uptr)__builtin_frame_address(0);
  596. static const uptr kMaxExpectedCleanupSize = 64 << 20; // 64M
  597. if (dst < sp || dst - sp > kMaxExpectedCleanupSize) {
  598. Report(
  599. "WARNING: HWASan is ignoring requested __hwasan_handle_longjmp: "
  600. "stack top: %p; target %p; distance: %p (%zd)\n"
  601. "False positive error reports may follow\n",
  602. (void *)sp, (void *)dst, dst - sp);
  603. return;
  604. }
  605. TagMemory(sp, dst - sp, 0);
  606. }
  607. void __hwasan_handle_vfork(const void *sp_dst) {
  608. uptr sp = (uptr)sp_dst;
  609. Thread *t = GetCurrentThread();
  610. CHECK(t);
  611. uptr top = t->stack_top();
  612. uptr bottom = t->stack_bottom();
  613. if (top == 0 || bottom == 0 || sp < bottom || sp >= top) {
  614. Report(
  615. "WARNING: HWASan is ignoring requested __hwasan_handle_vfork: "
  616. "stack top: %zx; current %zx; bottom: %zx \n"
  617. "False positive error reports may follow\n",
  618. top, sp, bottom);
  619. return;
  620. }
  621. TagMemory(bottom, sp - bottom, 0);
  622. }
  623. extern "C" void *__hwasan_extra_spill_area() {
  624. Thread *t = GetCurrentThread();
  625. return &t->vfork_spill();
  626. }
  627. void __hwasan_print_memory_usage() {
  628. InternalScopedString s;
  629. HwasanFormatMemoryUsage(s);
  630. Printf("%s\n", s.data());
  631. }
  632. static const u8 kFallbackTag = 0xBB & kTagMask;
  633. u8 __hwasan_generate_tag() {
  634. Thread *t = GetCurrentThread();
  635. if (!t) return kFallbackTag;
  636. return t->GenerateRandomTag();
  637. }
  638. void __hwasan_add_frame_record(u64 frame_record_info) {
  639. Thread *t = GetCurrentThread();
  640. if (t)
  641. t->stack_allocations()->push(frame_record_info);
  642. }
  643. #if !SANITIZER_SUPPORTS_WEAK_HOOKS
  644. extern "C" {
  645. SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
  646. const char* __hwasan_default_options() { return ""; }
  647. } // extern "C"
  648. #endif
  649. extern "C" {
  650. SANITIZER_INTERFACE_ATTRIBUTE
  651. void __sanitizer_print_stack_trace() {
  652. GET_FATAL_STACK_TRACE_PC_BP(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME());
  653. stack.Print();
  654. }
  655. // Entry point for interoperability between __hwasan_tag_mismatch (ASM) and the
  656. // rest of the mismatch handling code (C++).
  657. void __hwasan_tag_mismatch4(uptr addr, uptr access_info, uptr *registers_frame,
  658. size_t outsize) {
  659. __hwasan::HwasanTagMismatch(addr, (uptr)__builtin_return_address(0),
  660. (uptr)__builtin_frame_address(0), access_info,
  661. registers_frame, outsize);
  662. }
  663. } // extern "C"