10b57cec5SDimitry Andric 20b57cec5SDimitry Andric #include "hwasan_thread.h" 30b57cec5SDimitry Andric 4349cc55cSDimitry Andric #include "hwasan.h" 5349cc55cSDimitry Andric #include "hwasan_interface_internal.h" 6349cc55cSDimitry Andric #include "hwasan_mapping.h" 7349cc55cSDimitry Andric #include "hwasan_poisoning.h" 8bdd1243dSDimitry Andric #include "hwasan_thread_list.h" 9349cc55cSDimitry Andric #include "sanitizer_common/sanitizer_atomic.h" 100b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_file.h" 110b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_placement_new.h" 120b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_tls_get_addr.h" 130b57cec5SDimitry Andric 140b57cec5SDimitry Andric namespace __hwasan { 150b57cec5SDimitry Andric 160b57cec5SDimitry Andric static u32 RandomSeed() { 170b57cec5SDimitry Andric u32 seed; 180b57cec5SDimitry Andric do { 190b57cec5SDimitry Andric if (UNLIKELY(!GetRandom(reinterpret_cast<void *>(&seed), sizeof(seed), 200b57cec5SDimitry Andric /*blocking=*/false))) { 210b57cec5SDimitry Andric seed = static_cast<u32>( 220b57cec5SDimitry Andric (NanoTime() >> 12) ^ 230b57cec5SDimitry Andric (reinterpret_cast<uptr>(__builtin_frame_address(0)) >> 4)); 240b57cec5SDimitry Andric } 250b57cec5SDimitry Andric } while (!seed); 260b57cec5SDimitry Andric return seed; 270b57cec5SDimitry Andric } 280b57cec5SDimitry Andric 290b57cec5SDimitry Andric void Thread::InitRandomState() { 300b57cec5SDimitry Andric random_state_ = flags()->random_tags ? RandomSeed() : unique_id_; 31349cc55cSDimitry Andric random_state_inited_ = true; 320b57cec5SDimitry Andric 330b57cec5SDimitry Andric // Push a random number of zeros onto the ring buffer so that the first stack 340b57cec5SDimitry Andric // tag base will be random. 350b57cec5SDimitry Andric for (tag_t i = 0, e = GenerateRandomTag(); i != e; ++i) 360b57cec5SDimitry Andric stack_allocations_->push(0); 370b57cec5SDimitry Andric } 380b57cec5SDimitry Andric 39fe6060f1SDimitry Andric void Thread::Init(uptr stack_buffer_start, uptr stack_buffer_size, 40fe6060f1SDimitry Andric const InitState *state) { 41fe6060f1SDimitry Andric CHECK_EQ(0, unique_id_); // try to catch bad stack reuse 42fe6060f1SDimitry Andric CHECK_EQ(0, stack_top_); 43fe6060f1SDimitry Andric CHECK_EQ(0, stack_bottom_); 44fe6060f1SDimitry Andric 45349cc55cSDimitry Andric static atomic_uint64_t unique_id; 46349cc55cSDimitry Andric unique_id_ = atomic_fetch_add(&unique_id, 1, memory_order_relaxed); 47*06c3fb27SDimitry Andric if (!IsMainThread()) 48*06c3fb27SDimitry Andric os_id_ = GetTid(); 49349cc55cSDimitry Andric 500b57cec5SDimitry Andric if (auto sz = flags()->heap_history_size) 510b57cec5SDimitry Andric heap_allocations_ = HeapAllocationsRingBuffer::New(sz); 520b57cec5SDimitry Andric 53fe6060f1SDimitry Andric #if !SANITIZER_FUCHSIA 54fe6060f1SDimitry Andric // Do not initialize the stack ring buffer just yet on Fuchsia. Threads will 55fe6060f1SDimitry Andric // be initialized before we enter the thread itself, so we will instead call 56fe6060f1SDimitry Andric // this later. 57fe6060f1SDimitry Andric InitStackRingBuffer(stack_buffer_start, stack_buffer_size); 58fe6060f1SDimitry Andric #endif 59349cc55cSDimitry Andric InitStackAndTls(state); 60bdd1243dSDimitry Andric dtls_ = DTLS_Get(); 61*06c3fb27SDimitry Andric AllocatorThreadStart(allocator_cache()); 62*06c3fb27SDimitry Andric 63*06c3fb27SDimitry Andric if (flags()->verbose_threads) { 64*06c3fb27SDimitry Andric if (IsMainThread()) { 65*06c3fb27SDimitry Andric Printf("sizeof(Thread): %zd sizeof(HeapRB): %zd sizeof(StackRB): %zd\n", 66*06c3fb27SDimitry Andric sizeof(Thread), heap_allocations_->SizeInBytes(), 67*06c3fb27SDimitry Andric stack_allocations_->size() * sizeof(uptr)); 68*06c3fb27SDimitry Andric } 69*06c3fb27SDimitry Andric Print("Creating : "); 70*06c3fb27SDimitry Andric } 71fe6060f1SDimitry Andric } 72fe6060f1SDimitry Andric 73fe6060f1SDimitry Andric void Thread::InitStackRingBuffer(uptr stack_buffer_start, 74fe6060f1SDimitry Andric uptr stack_buffer_size) { 750b57cec5SDimitry Andric HwasanTSDThreadInit(); // Only needed with interceptors. 760b57cec5SDimitry Andric uptr *ThreadLong = GetCurrentThreadLongPtr(); 770b57cec5SDimitry Andric // The following implicitly sets (this) as the current thread. 780b57cec5SDimitry Andric stack_allocations_ = new (ThreadLong) 790b57cec5SDimitry Andric StackAllocationsRingBuffer((void *)stack_buffer_start, stack_buffer_size); 800b57cec5SDimitry Andric // Check that it worked. 810b57cec5SDimitry Andric CHECK_EQ(GetCurrentThread(), this); 820b57cec5SDimitry Andric 830b57cec5SDimitry Andric // ScopedTaggingDisable needs GetCurrentThread to be set up. 840b57cec5SDimitry Andric ScopedTaggingDisabler disabler; 850b57cec5SDimitry Andric 860b57cec5SDimitry Andric if (stack_bottom_) { 870b57cec5SDimitry Andric int local; 880b57cec5SDimitry Andric CHECK(AddrIsInStack((uptr)&local)); 890b57cec5SDimitry Andric CHECK(MemIsApp(stack_bottom_)); 900b57cec5SDimitry Andric CHECK(MemIsApp(stack_top_ - 1)); 910b57cec5SDimitry Andric } 920b57cec5SDimitry Andric } 930b57cec5SDimitry Andric 940b57cec5SDimitry Andric void Thread::ClearShadowForThreadStackAndTLS() { 950b57cec5SDimitry Andric if (stack_top_ != stack_bottom_) 96*06c3fb27SDimitry Andric TagMemory(UntagAddr(stack_bottom_), 97*06c3fb27SDimitry Andric UntagAddr(stack_top_) - UntagAddr(stack_bottom_), 98*06c3fb27SDimitry Andric GetTagFromPointer(stack_top_)); 990b57cec5SDimitry Andric if (tls_begin_ != tls_end_) 100*06c3fb27SDimitry Andric TagMemory(UntagAddr(tls_begin_), 101*06c3fb27SDimitry Andric UntagAddr(tls_end_) - UntagAddr(tls_begin_), 102*06c3fb27SDimitry Andric GetTagFromPointer(tls_begin_)); 1030b57cec5SDimitry Andric } 1040b57cec5SDimitry Andric 1050b57cec5SDimitry Andric void Thread::Destroy() { 1060b57cec5SDimitry Andric if (flags()->verbose_threads) 1070b57cec5SDimitry Andric Print("Destroying: "); 108*06c3fb27SDimitry Andric AllocatorThreadFinish(allocator_cache()); 1090b57cec5SDimitry Andric ClearShadowForThreadStackAndTLS(); 1100b57cec5SDimitry Andric if (heap_allocations_) 1110b57cec5SDimitry Andric heap_allocations_->Delete(); 1120b57cec5SDimitry Andric DTLS_Destroy(); 1135ffd83dbSDimitry Andric // Unregister this as the current thread. 1145ffd83dbSDimitry Andric // Instrumented code can not run on this thread from this point onwards, but 1155ffd83dbSDimitry Andric // malloc/free can still be served. Glibc may call free() very late, after all 1165ffd83dbSDimitry Andric // TSD destructors are done. 1175ffd83dbSDimitry Andric CHECK_EQ(GetCurrentThread(), this); 1185ffd83dbSDimitry Andric *GetCurrentThreadLongPtr() = 0; 1190b57cec5SDimitry Andric } 1200b57cec5SDimitry Andric 1210b57cec5SDimitry Andric void Thread::Print(const char *Prefix) { 122349cc55cSDimitry Andric Printf("%sT%zd %p stack: [%p,%p) sz: %zd tls: [%p,%p)\n", Prefix, unique_id_, 123349cc55cSDimitry Andric (void *)this, stack_bottom(), stack_top(), 124349cc55cSDimitry Andric stack_top() - stack_bottom(), tls_begin(), tls_end()); 1250b57cec5SDimitry Andric } 1260b57cec5SDimitry Andric 1270b57cec5SDimitry Andric static u32 xorshift(u32 state) { 1280b57cec5SDimitry Andric state ^= state << 13; 1290b57cec5SDimitry Andric state ^= state >> 17; 1300b57cec5SDimitry Andric state ^= state << 5; 1310b57cec5SDimitry Andric return state; 1320b57cec5SDimitry Andric } 1330b57cec5SDimitry Andric 1340b57cec5SDimitry Andric // Generate a (pseudo-)random non-zero tag. 135fe6060f1SDimitry Andric tag_t Thread::GenerateRandomTag(uptr num_bits) { 136fe6060f1SDimitry Andric DCHECK_GT(num_bits, 0); 137349cc55cSDimitry Andric if (tagging_disabled_) 138349cc55cSDimitry Andric return 0; 1390b57cec5SDimitry Andric tag_t tag; 140fe6060f1SDimitry Andric const uptr tag_mask = (1ULL << num_bits) - 1; 1410b57cec5SDimitry Andric do { 1420b57cec5SDimitry Andric if (flags()->random_tags) { 143349cc55cSDimitry Andric if (!random_buffer_) { 144349cc55cSDimitry Andric EnsureRandomStateInited(); 1450b57cec5SDimitry Andric random_buffer_ = random_state_ = xorshift(random_state_); 146349cc55cSDimitry Andric } 1470b57cec5SDimitry Andric CHECK(random_buffer_); 148fe6060f1SDimitry Andric tag = random_buffer_ & tag_mask; 149fe6060f1SDimitry Andric random_buffer_ >>= num_bits; 1500b57cec5SDimitry Andric } else { 151349cc55cSDimitry Andric EnsureRandomStateInited(); 152fe6060f1SDimitry Andric random_state_ += 1; 153fe6060f1SDimitry Andric tag = random_state_ & tag_mask; 1540b57cec5SDimitry Andric } 1550b57cec5SDimitry Andric } while (!tag); 1560b57cec5SDimitry Andric return tag; 1570b57cec5SDimitry Andric } 1580b57cec5SDimitry Andric 159*06c3fb27SDimitry Andric void EnsureMainThreadIDIsCorrect() { 160*06c3fb27SDimitry Andric auto *t = __hwasan::GetCurrentThread(); 161*06c3fb27SDimitry Andric if (t && (t->IsMainThread())) 162*06c3fb27SDimitry Andric t->set_os_id(GetTid()); 163*06c3fb27SDimitry Andric } 164*06c3fb27SDimitry Andric 1650b57cec5SDimitry Andric } // namespace __hwasan 166bdd1243dSDimitry Andric 167bdd1243dSDimitry Andric // --- Implementation of LSan-specific functions --- {{{1 168bdd1243dSDimitry Andric namespace __lsan { 169bdd1243dSDimitry Andric 170bdd1243dSDimitry Andric static __hwasan::HwasanThreadList *GetHwasanThreadListLocked() { 171bdd1243dSDimitry Andric auto &tl = __hwasan::hwasanThreadList(); 172bdd1243dSDimitry Andric tl.CheckLocked(); 173bdd1243dSDimitry Andric return &tl; 174bdd1243dSDimitry Andric } 175bdd1243dSDimitry Andric 176bdd1243dSDimitry Andric static __hwasan::Thread *GetThreadByOsIDLocked(tid_t os_id) { 177bdd1243dSDimitry Andric return GetHwasanThreadListLocked()->FindThreadLocked( 178bdd1243dSDimitry Andric [os_id](__hwasan::Thread *t) { return t->os_id() == os_id; }); 179bdd1243dSDimitry Andric } 180bdd1243dSDimitry Andric 181*06c3fb27SDimitry Andric void LockThreads() { 182*06c3fb27SDimitry Andric __hwasan::hwasanThreadList().Lock(); 183*06c3fb27SDimitry Andric __hwasan::hwasanThreadArgRetval().Lock(); 184bdd1243dSDimitry Andric } 185bdd1243dSDimitry Andric 186*06c3fb27SDimitry Andric void UnlockThreads() { 187*06c3fb27SDimitry Andric __hwasan::hwasanThreadArgRetval().Unlock(); 188*06c3fb27SDimitry Andric __hwasan::hwasanThreadList().Unlock(); 189*06c3fb27SDimitry Andric } 190*06c3fb27SDimitry Andric 191*06c3fb27SDimitry Andric void EnsureMainThreadIDIsCorrect() { __hwasan::EnsureMainThreadIDIsCorrect(); } 192*06c3fb27SDimitry Andric 193bdd1243dSDimitry Andric bool GetThreadRangesLocked(tid_t os_id, uptr *stack_begin, uptr *stack_end, 194bdd1243dSDimitry Andric uptr *tls_begin, uptr *tls_end, uptr *cache_begin, 195bdd1243dSDimitry Andric uptr *cache_end, DTLS **dtls) { 196bdd1243dSDimitry Andric auto *t = GetThreadByOsIDLocked(os_id); 197bdd1243dSDimitry Andric if (!t) 198bdd1243dSDimitry Andric return false; 199bdd1243dSDimitry Andric *stack_begin = t->stack_bottom(); 200bdd1243dSDimitry Andric *stack_end = t->stack_top(); 201bdd1243dSDimitry Andric *tls_begin = t->tls_begin(); 202bdd1243dSDimitry Andric *tls_end = t->tls_end(); 203bdd1243dSDimitry Andric // Fixme: is this correct for HWASan. 204bdd1243dSDimitry Andric *cache_begin = 0; 205bdd1243dSDimitry Andric *cache_end = 0; 206bdd1243dSDimitry Andric *dtls = t->dtls(); 207bdd1243dSDimitry Andric return true; 208bdd1243dSDimitry Andric } 209bdd1243dSDimitry Andric 210bdd1243dSDimitry Andric void GetAllThreadAllocatorCachesLocked(InternalMmapVector<uptr> *caches) {} 211bdd1243dSDimitry Andric 212bdd1243dSDimitry Andric void GetThreadExtraStackRangesLocked(tid_t os_id, 213bdd1243dSDimitry Andric InternalMmapVector<Range> *ranges) {} 214bdd1243dSDimitry Andric void GetThreadExtraStackRangesLocked(InternalMmapVector<Range> *ranges) {} 215bdd1243dSDimitry Andric 216*06c3fb27SDimitry Andric void GetAdditionalThreadContextPtrsLocked(InternalMmapVector<uptr> *ptrs) { 217*06c3fb27SDimitry Andric __hwasan::hwasanThreadArgRetval().GetAllPtrsLocked(ptrs); 218*06c3fb27SDimitry Andric } 219*06c3fb27SDimitry Andric 220bdd1243dSDimitry Andric void GetRunningThreadsLocked(InternalMmapVector<tid_t> *threads) {} 221bdd1243dSDimitry Andric 222bdd1243dSDimitry Andric } // namespace __lsan 223