2019-08-01 02:51:27 +08:00
|
|
|
//===-- sanitizer_common_libcdep.cpp --------------------------------------===//
|
2013-05-18 00:17:19 +08:00
|
|
|
//
|
2019-01-19 16:50:56 +08:00
|
|
|
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
|
|
|
|
// See https://llvm.org/LICENSE.txt for license information.
|
|
|
|
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
|
2013-05-18 00:17:19 +08:00
|
|
|
//
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
//
|
|
|
|
// This file is shared between AddressSanitizer and ThreadSanitizer
|
|
|
|
// run-time libraries.
|
|
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
|
2016-09-15 06:00:58 +08:00
|
|
|
#include "sanitizer_allocator_interface.h"
|
[sanitizer] Split Symbolizer/StackTraces from core RTSanitizerCommon
Summary:
Host symbolizer & stacktraces related code in their own RT:
`RTSanitizerCommonSymbolizer`, which is "libcdep" by nature. Symbolizer &
stacktraces specific code that used to live in common files is moved to a new
file `sanitizer_symbolizer_report.cc` as is.
The purpose of this is the enforce a separation between code that relies on
symbolization and code that doesn't. This saves the inclusion of spurious code
due to the interface functions with default visibility, and the extra data
associated.
The following sanitizers makefiles were modified & tested locally:
- dfsan: doesn't require the new symbolizer RT
- esan: requires it
- hwasan: requires it
- lsan: requires it
- msan: requires it
- safestack: doesn't require it
- xray: doesn't require it
- tsan: requires it
- ubsan: requires it
- ubsan_minimal: doesn't require it
- scudo: requires it (but not for Fuchsia that has a minimal runtime)
This was tested locally on Linux, Android, Fuchsia.
Reviewers: alekseyshl, eugenis, dberris, kubamracek, vitalybuka, dvyukov, mcgrathr
Reviewed By: alekseyshl, vitalybuka
Subscribers: srhines, kubamracek, mgorny, krytarowski, delcypher, llvm-commits, #sanitizers
Differential Revision: https://reviews.llvm.org/D45457
llvm-svn: 330131
2018-04-17 00:32:19 +08:00
|
|
|
#include "sanitizer_common.h"
|
2014-02-26 17:06:59 +08:00
|
|
|
#include "sanitizer_flags.h"
|
2017-09-13 14:24:59 +08:00
|
|
|
#include "sanitizer_procmaps.h"
|
2013-05-18 00:17:19 +08:00
|
|
|
|
2015-04-09 01:08:24 +08:00
|
|
|
|
2013-05-18 00:17:19 +08:00
|
|
|
namespace __sanitizer {
|
|
|
|
|
2015-01-07 07:53:32 +08:00
|
|
|
static void (*SoftRssLimitExceededCallback)(bool exceeded);
|
|
|
|
void SetSoftRssLimitExceededCallback(void (*Callback)(bool exceeded)) {
|
|
|
|
CHECK_EQ(SoftRssLimitExceededCallback, nullptr);
|
|
|
|
SoftRssLimitExceededCallback = Callback;
|
|
|
|
}
|
|
|
|
|
2018-12-29 08:32:07 +08:00
|
|
|
#if (SANITIZER_LINUX || SANITIZER_NETBSD) && !SANITIZER_GO
|
2018-04-10 22:41:40 +08:00
|
|
|
// Weak default implementation for when sanitizer_stackdepot is not linked in.
|
|
|
|
SANITIZER_WEAK_ATTRIBUTE StackDepotStats *StackDepotGetStats() {
|
|
|
|
return nullptr;
|
|
|
|
}
|
|
|
|
|
2020-01-24 05:01:08 +08:00
|
|
|
void *BackgroundThread(void *arg) {
|
2018-04-10 22:41:40 +08:00
|
|
|
const uptr hard_rss_limit_mb = common_flags()->hard_rss_limit_mb;
|
|
|
|
const uptr soft_rss_limit_mb = common_flags()->soft_rss_limit_mb;
|
|
|
|
const bool heap_profile = common_flags()->heap_profile;
|
2014-12-17 03:13:01 +08:00
|
|
|
uptr prev_reported_rss = 0;
|
|
|
|
uptr prev_reported_stack_depot_size = 0;
|
2015-01-07 07:53:32 +08:00
|
|
|
bool reached_soft_rss_limit = false;
|
2016-09-15 06:00:58 +08:00
|
|
|
uptr rss_during_last_reported_profile = 0;
|
2014-12-17 03:13:01 +08:00
|
|
|
while (true) {
|
|
|
|
SleepForMillis(100);
|
2018-04-10 22:41:40 +08:00
|
|
|
const uptr current_rss_mb = GetRSS() >> 20;
|
2015-01-20 21:21:20 +08:00
|
|
|
if (Verbosity()) {
|
2014-12-17 03:13:01 +08:00
|
|
|
// If RSS has grown 10% since last time, print some information.
|
|
|
|
if (prev_reported_rss * 11 / 10 < current_rss_mb) {
|
|
|
|
Printf("%s: RSS: %zdMb\n", SanitizerToolName, current_rss_mb);
|
|
|
|
prev_reported_rss = current_rss_mb;
|
|
|
|
}
|
2018-04-10 03:18:50 +08:00
|
|
|
// If stack depot has grown 10% since last time, print it too.
|
|
|
|
StackDepotStats *stack_depot_stats = StackDepotGetStats();
|
2018-04-10 22:41:40 +08:00
|
|
|
if (stack_depot_stats) {
|
|
|
|
if (prev_reported_stack_depot_size * 11 / 10 <
|
|
|
|
stack_depot_stats->allocated) {
|
|
|
|
Printf("%s: StackDepot: %zd ids; %zdM allocated\n",
|
|
|
|
SanitizerToolName,
|
|
|
|
stack_depot_stats->n_uniq_ids,
|
|
|
|
stack_depot_stats->allocated >> 20);
|
|
|
|
prev_reported_stack_depot_size = stack_depot_stats->allocated;
|
|
|
|
}
|
2014-12-17 03:13:01 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
// Check RSS against the limit.
|
|
|
|
if (hard_rss_limit_mb && hard_rss_limit_mb < current_rss_mb) {
|
|
|
|
Report("%s: hard rss limit exhausted (%zdMb vs %zdMb)\n",
|
|
|
|
SanitizerToolName, hard_rss_limit_mb, current_rss_mb);
|
|
|
|
DumpProcessMap();
|
|
|
|
Die();
|
|
|
|
}
|
2015-01-07 07:53:32 +08:00
|
|
|
if (soft_rss_limit_mb) {
|
|
|
|
if (soft_rss_limit_mb < current_rss_mb && !reached_soft_rss_limit) {
|
|
|
|
reached_soft_rss_limit = true;
|
|
|
|
Report("%s: soft rss limit exhausted (%zdMb vs %zdMb)\n",
|
|
|
|
SanitizerToolName, soft_rss_limit_mb, current_rss_mb);
|
|
|
|
if (SoftRssLimitExceededCallback)
|
|
|
|
SoftRssLimitExceededCallback(true);
|
|
|
|
} else if (soft_rss_limit_mb >= current_rss_mb &&
|
|
|
|
reached_soft_rss_limit) {
|
|
|
|
reached_soft_rss_limit = false;
|
|
|
|
if (SoftRssLimitExceededCallback)
|
|
|
|
SoftRssLimitExceededCallback(false);
|
|
|
|
}
|
|
|
|
}
|
2016-09-15 10:11:07 +08:00
|
|
|
if (heap_profile &&
|
2016-09-15 06:00:58 +08:00
|
|
|
current_rss_mb > rss_during_last_reported_profile * 1.1) {
|
|
|
|
Printf("\n\nHEAP PROFILE at RSS %zdMb\n", current_rss_mb);
|
2017-03-16 07:27:14 +08:00
|
|
|
__sanitizer_print_memory_profile(90, 20);
|
2016-09-15 06:00:58 +08:00
|
|
|
rss_during_last_reported_profile = current_rss_mb;
|
|
|
|
}
|
2014-12-17 03:13:01 +08:00
|
|
|
}
|
|
|
|
}
|
2016-10-28 22:16:13 +08:00
|
|
|
#endif
|
2014-12-17 03:13:01 +08:00
|
|
|
|
2015-11-21 02:42:01 +08:00
|
|
|
void WriteToSyslog(const char *msg) {
|
|
|
|
InternalScopedString msg_copy(kErrorMessageBufferSize);
|
|
|
|
msg_copy.append("%s", msg);
|
|
|
|
char *p = msg_copy.data();
|
Reapply: [asan] On OS X, log reports to syslog and os_trace
When ASan currently detects a bug, by default it will only print out the text
of the report to stderr. This patch changes this behavior and writes the full
text of the report to syslog before we terminate the process. It also calls
os_trace (Activity Tracing available on OS X and iOS) with a message saying
that the report is available in syslog. This is useful, because this message
will be shown in the crash log.
For this to work, the patch makes sure we store the full report into
error_message_buffer unconditionally, and it also strips out ANSI escape
sequences from the report (they are used when producing colored reports).
I've initially tried to log to syslog during printing, which is done on Android
right now. The advantage is that if we crash during error reporting or the
produced error does not go through ScopedInErrorReport, we would still get a
(partial) message in the syslog. However, that solution is very problematic on
OS X. One issue is that the logging routine uses GCD, which may spawn a new
thread on its behalf. In many cases, the reporting logic locks threadRegistry,
which leads to deadlocks.
Reviewed at http://reviews.llvm.org/D13452
(In addition, add sanitizer_common_libcdep.cc to buildgo.sh to avoid
build failures on Linux.)
llvm-svn: 253688
2015-11-21 02:41:44 +08:00
|
|
|
char *q;
|
|
|
|
|
|
|
|
// Print one line at a time.
|
|
|
|
// syslog, at least on Android, has an implicit message length limit.
|
2018-10-13 06:07:54 +08:00
|
|
|
while ((q = internal_strchr(p, '\n'))) {
|
|
|
|
*q = '\0';
|
|
|
|
WriteOneLineToSyslog(p);
|
|
|
|
p = q + 1;
|
|
|
|
}
|
|
|
|
// Print remaining characters, if there are any.
|
|
|
|
// Note that this will add an extra newline at the end.
|
|
|
|
// FIXME: buffer extra output. This would need a thread-local buffer, which
|
|
|
|
// on Android requires plugging into the tools (ex. ASan's) Thread class.
|
|
|
|
if (*p)
|
Reapply: [asan] On OS X, log reports to syslog and os_trace
When ASan currently detects a bug, by default it will only print out the text
of the report to stderr. This patch changes this behavior and writes the full
text of the report to syslog before we terminate the process. It also calls
os_trace (Activity Tracing available on OS X and iOS) with a message saying
that the report is available in syslog. This is useful, because this message
will be shown in the crash log.
For this to work, the patch makes sure we store the full report into
error_message_buffer unconditionally, and it also strips out ANSI escape
sequences from the report (they are used when producing colored reports).
I've initially tried to log to syslog during printing, which is done on Android
right now. The advantage is that if we crash during error reporting or the
produced error does not go through ScopedInErrorReport, we would still get a
(partial) message in the syslog. However, that solution is very problematic on
OS X. One issue is that the logging routine uses GCD, which may spawn a new
thread on its behalf. In many cases, the reporting logic locks threadRegistry,
which leads to deadlocks.
Reviewed at http://reviews.llvm.org/D13452
(In addition, add sanitizer_common_libcdep.cc to buildgo.sh to avoid
build failures on Linux.)
llvm-svn: 253688
2015-11-21 02:41:44 +08:00
|
|
|
WriteOneLineToSyslog(p);
|
|
|
|
}
|
|
|
|
|
2014-12-17 03:13:01 +08:00
|
|
|
void MaybeStartBackgroudThread() {
|
2018-12-29 08:32:07 +08:00
|
|
|
#if (SANITIZER_LINUX || SANITIZER_NETBSD) && \
|
Reapply: [asan] On OS X, log reports to syslog and os_trace
When ASan currently detects a bug, by default it will only print out the text
of the report to stderr. This patch changes this behavior and writes the full
text of the report to syslog before we terminate the process. It also calls
os_trace (Activity Tracing available on OS X and iOS) with a message saying
that the report is available in syslog. This is useful, because this message
will be shown in the crash log.
For this to work, the patch makes sure we store the full report into
error_message_buffer unconditionally, and it also strips out ANSI escape
sequences from the report (they are used when producing colored reports).
I've initially tried to log to syslog during printing, which is done on Android
right now. The advantage is that if we crash during error reporting or the
produced error does not go through ScopedInErrorReport, we would still get a
(partial) message in the syslog. However, that solution is very problematic on
OS X. One issue is that the logging routine uses GCD, which may spawn a new
thread on its behalf. In many cases, the reporting logic locks threadRegistry,
which leads to deadlocks.
Reviewed at http://reviews.llvm.org/D13452
(In addition, add sanitizer_common_libcdep.cc to buildgo.sh to avoid
build failures on Linux.)
llvm-svn: 253688
2015-11-21 02:41:44 +08:00
|
|
|
!SANITIZER_GO // Need to implement/test on other platforms.
|
2015-01-07 07:53:32 +08:00
|
|
|
// Start the background thread if one of the rss limits is given.
|
|
|
|
if (!common_flags()->hard_rss_limit_mb &&
|
2016-08-27 07:58:42 +08:00
|
|
|
!common_flags()->soft_rss_limit_mb &&
|
2016-09-15 06:00:58 +08:00
|
|
|
!common_flags()->heap_profile) return;
|
2015-02-18 05:57:42 +08:00
|
|
|
if (!&real_pthread_create) return; // Can't spawn the thread anyway.
|
2014-12-17 03:13:01 +08:00
|
|
|
internal_start_thread(BackgroundThread, nullptr);
|
2015-04-02 22:48:08 +08:00
|
|
|
#endif
|
2014-12-17 03:13:01 +08:00
|
|
|
}
|
|
|
|
|
2018-04-04 02:07:22 +08:00
|
|
|
static void (*sandboxing_callback)();
|
|
|
|
void SetSandboxingCallback(void (*f)()) {
|
|
|
|
sandboxing_callback = f;
|
|
|
|
}
|
|
|
|
|
2020-05-09 07:32:33 +08:00
|
|
|
uptr ReservedAddressRange::InitAligned(uptr size, uptr align,
|
|
|
|
const char *name) {
|
|
|
|
CHECK(IsPowerOfTwo(align));
|
|
|
|
if (align <= GetPageSizeCached())
|
|
|
|
return Init(size, name);
|
|
|
|
uptr start = Init(size + align, name);
|
|
|
|
start += align - (start & (align - 1));
|
|
|
|
return start;
|
|
|
|
}
|
|
|
|
|
2020-07-18 05:48:28 +08:00
|
|
|
#if !SANITIZER_FUCHSIA && !SANITIZER_RTEMS
|
|
|
|
|
[compiler-rt][asan][hwasan] Refactor shadow setup into sanitizer_common (NFCI)
Summary:
This refactors some common support related to shadow memory setup from
asan and hwasan into sanitizer_common. This should not only reduce code
duplication but also make these facilities available for new compiler-rt
uses (e.g. heap profiling).
In most cases the separate copies of the code were either identical, or
at least functionally identical. A few notes:
In ProtectGap, the asan version checked the address against an upper
bound (kZeroBaseMaxShadowStart, which is (2^18). I have created a copy
of kZeroBaseMaxShadowStart in hwasan_mapping.h, with the same value, as
it isn't clear why that code should not do the same check. If it
shouldn't, I can remove this and guard this check so that it only
happens for asan.
In asan's InitializeShadowMemory, in the dynamic shadow case it was
setting __asan_shadow_memory_dynamic_address to 0 (which then sets both
macro SHADOW_OFFSET as well as macro kLowShadowBeg to 0) before calling
FindDynamicShadowStart(). AFAICT this is only needed because
FindDynamicShadowStart utilizes kHighShadowEnd to
get the shadow size, and kHighShadowEnd is a macro invoking
MEM_TO_SHADOW(kHighMemEnd) which in turn invokes:
(((kHighMemEnd) >> SHADOW_SCALE) + (SHADOW_OFFSET))
I.e. it computes the shadow space needed by kHighMemEnd (the shift), and
adds the offset. Since we only want the shadow space here, the earlier
setting of SHADOW_OFFSET to 0 via __asan_shadow_memory_dynamic_address
accomplishes this. In the hwasan version, it simply gets the shadow
space via "MemToShadowSize(kHighMemEnd)", where MemToShadowSize just
does the shift. I've simplified the asan handling to do the same
thing, and therefore was able to remove the setting of the SHADOW_OFFSET
via __asan_shadow_memory_dynamic_address to 0.
Reviewers: vitalybuka, kcc, eugenis
Subscribers: dberris, #sanitizers, llvm-commits, davidxl
Tags: #sanitizers
Differential Revision: https://reviews.llvm.org/D83247
2020-07-07 02:05:12 +08:00
|
|
|
// Reserve memory range [beg, end].
|
|
|
|
// We need to use inclusive range because end+1 may not be representable.
|
|
|
|
void ReserveShadowMemoryRange(uptr beg, uptr end, const char *name,
|
|
|
|
bool madvise_shadow) {
|
|
|
|
CHECK_EQ((beg % GetMmapGranularity()), 0);
|
|
|
|
CHECK_EQ(((end + 1) % GetMmapGranularity()), 0);
|
|
|
|
uptr size = end - beg + 1;
|
|
|
|
DecreaseTotalMmap(size); // Don't count the shadow against mmap_limit_mb.
|
|
|
|
if (madvise_shadow ? !MmapFixedSuperNoReserve(beg, size, name)
|
|
|
|
: !MmapFixedNoReserve(beg, size, name)) {
|
|
|
|
Report(
|
|
|
|
"ReserveShadowMemoryRange failed while trying to map 0x%zx bytes. "
|
|
|
|
"Perhaps you're using ulimit -v\n",
|
|
|
|
size);
|
|
|
|
Abort();
|
|
|
|
}
|
|
|
|
if (madvise_shadow && common_flags()->use_madv_dontdump)
|
|
|
|
DontDumpShadowMemory(beg, size);
|
|
|
|
}
|
|
|
|
|
|
|
|
void ProtectGap(uptr addr, uptr size, uptr zero_base_shadow_start,
|
|
|
|
uptr zero_base_max_shadow_start) {
|
|
|
|
if (!size)
|
|
|
|
return;
|
|
|
|
void *res = MmapFixedNoAccess(addr, size, "shadow gap");
|
|
|
|
if (addr == (uptr)res)
|
|
|
|
return;
|
|
|
|
// A few pages at the start of the address space can not be protected.
|
|
|
|
// But we really want to protect as much as possible, to prevent this memory
|
|
|
|
// being returned as a result of a non-FIXED mmap().
|
|
|
|
if (addr == zero_base_shadow_start) {
|
|
|
|
uptr step = GetMmapGranularity();
|
|
|
|
while (size > step && addr < zero_base_max_shadow_start) {
|
|
|
|
addr += step;
|
|
|
|
size -= step;
|
|
|
|
void *res = MmapFixedNoAccess(addr, size, "shadow gap");
|
|
|
|
if (addr == (uptr)res)
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
Report(
|
|
|
|
"ERROR: Failed to protect the shadow gap. "
|
|
|
|
"%s cannot proceed correctly. ABORTING.\n",
|
|
|
|
SanitizerToolName);
|
|
|
|
DumpProcessMap();
|
|
|
|
Die();
|
|
|
|
}
|
|
|
|
|
2020-07-18 05:48:28 +08:00
|
|
|
#endif // !SANITIZER_FUCHSIA && !SANITIZER_RTEMS
|
|
|
|
|
2013-05-18 00:17:19 +08:00
|
|
|
} // namespace __sanitizer
|
2014-05-27 20:37:52 +08:00
|
|
|
|
2017-02-01 04:23:14 +08:00
|
|
|
SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_sandbox_on_notify,
|
|
|
|
__sanitizer_sandbox_arguments *args) {
|
2018-04-04 02:07:22 +08:00
|
|
|
__sanitizer::PlatformPrepareForSandboxing(args);
|
2016-09-16 05:02:18 +08:00
|
|
|
if (__sanitizer::sandboxing_callback)
|
|
|
|
__sanitizer::sandboxing_callback();
|
2014-05-27 20:37:52 +08:00
|
|
|
}
|