10b57cec5SDimitry Andric 20b57cec5SDimitry Andric #include "hwasan.h" 30b57cec5SDimitry Andric #include "hwasan_mapping.h" 40b57cec5SDimitry Andric #include "hwasan_thread.h" 50b57cec5SDimitry Andric #include "hwasan_poisoning.h" 60b57cec5SDimitry Andric #include "hwasan_interface_internal.h" 70b57cec5SDimitry Andric 80b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_file.h" 90b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_placement_new.h" 100b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_tls_get_addr.h" 110b57cec5SDimitry Andric 120b57cec5SDimitry Andric 130b57cec5SDimitry Andric namespace __hwasan { 140b57cec5SDimitry Andric 150b57cec5SDimitry Andric static u32 RandomSeed() { 160b57cec5SDimitry Andric u32 seed; 170b57cec5SDimitry Andric do { 180b57cec5SDimitry Andric if (UNLIKELY(!GetRandom(reinterpret_cast<void *>(&seed), sizeof(seed), 190b57cec5SDimitry Andric /*blocking=*/false))) { 200b57cec5SDimitry Andric seed = static_cast<u32>( 210b57cec5SDimitry Andric (NanoTime() >> 12) ^ 220b57cec5SDimitry Andric (reinterpret_cast<uptr>(__builtin_frame_address(0)) >> 4)); 230b57cec5SDimitry Andric } 240b57cec5SDimitry Andric } while (!seed); 250b57cec5SDimitry Andric return seed; 260b57cec5SDimitry Andric } 270b57cec5SDimitry Andric 280b57cec5SDimitry Andric void Thread::InitRandomState() { 290b57cec5SDimitry Andric random_state_ = flags()->random_tags ? RandomSeed() : unique_id_; 300b57cec5SDimitry Andric 310b57cec5SDimitry Andric // Push a random number of zeros onto the ring buffer so that the first stack 320b57cec5SDimitry Andric // tag base will be random. 330b57cec5SDimitry Andric for (tag_t i = 0, e = GenerateRandomTag(); i != e; ++i) 340b57cec5SDimitry Andric stack_allocations_->push(0); 350b57cec5SDimitry Andric } 360b57cec5SDimitry Andric 37*fe6060f1SDimitry Andric void Thread::Init(uptr stack_buffer_start, uptr stack_buffer_size, 38*fe6060f1SDimitry Andric const InitState *state) { 39*fe6060f1SDimitry Andric CHECK_EQ(0, unique_id_); // try to catch bad stack reuse 40*fe6060f1SDimitry Andric CHECK_EQ(0, stack_top_); 41*fe6060f1SDimitry Andric CHECK_EQ(0, stack_bottom_); 42*fe6060f1SDimitry Andric 430b57cec5SDimitry Andric static u64 unique_id; 440b57cec5SDimitry Andric unique_id_ = unique_id++; 450b57cec5SDimitry Andric if (auto sz = flags()->heap_history_size) 460b57cec5SDimitry Andric heap_allocations_ = HeapAllocationsRingBuffer::New(sz); 470b57cec5SDimitry Andric 48*fe6060f1SDimitry Andric InitStackAndTls(state); 49*fe6060f1SDimitry Andric #if !SANITIZER_FUCHSIA 50*fe6060f1SDimitry Andric // Do not initialize the stack ring buffer just yet on Fuchsia. Threads will 51*fe6060f1SDimitry Andric // be initialized before we enter the thread itself, so we will instead call 52*fe6060f1SDimitry Andric // this later. 53*fe6060f1SDimitry Andric InitStackRingBuffer(stack_buffer_start, stack_buffer_size); 54*fe6060f1SDimitry Andric #endif 55*fe6060f1SDimitry Andric } 56*fe6060f1SDimitry Andric 57*fe6060f1SDimitry Andric void Thread::InitStackRingBuffer(uptr stack_buffer_start, 58*fe6060f1SDimitry Andric uptr stack_buffer_size) { 590b57cec5SDimitry Andric HwasanTSDThreadInit(); // Only needed with interceptors. 600b57cec5SDimitry Andric uptr *ThreadLong = GetCurrentThreadLongPtr(); 610b57cec5SDimitry Andric // The following implicitly sets (this) as the current thread. 620b57cec5SDimitry Andric stack_allocations_ = new (ThreadLong) 630b57cec5SDimitry Andric StackAllocationsRingBuffer((void *)stack_buffer_start, stack_buffer_size); 640b57cec5SDimitry Andric // Check that it worked. 650b57cec5SDimitry Andric CHECK_EQ(GetCurrentThread(), this); 660b57cec5SDimitry Andric 670b57cec5SDimitry Andric // ScopedTaggingDisable needs GetCurrentThread to be set up. 680b57cec5SDimitry Andric ScopedTaggingDisabler disabler; 690b57cec5SDimitry Andric 700b57cec5SDimitry Andric if (stack_bottom_) { 710b57cec5SDimitry Andric int local; 720b57cec5SDimitry Andric CHECK(AddrIsInStack((uptr)&local)); 730b57cec5SDimitry Andric CHECK(MemIsApp(stack_bottom_)); 740b57cec5SDimitry Andric CHECK(MemIsApp(stack_top_ - 1)); 750b57cec5SDimitry Andric } 760b57cec5SDimitry Andric 770b57cec5SDimitry Andric if (flags()->verbose_threads) { 780b57cec5SDimitry Andric if (IsMainThread()) { 790b57cec5SDimitry Andric Printf("sizeof(Thread): %zd sizeof(HeapRB): %zd sizeof(StackRB): %zd\n", 800b57cec5SDimitry Andric sizeof(Thread), heap_allocations_->SizeInBytes(), 810b57cec5SDimitry Andric stack_allocations_->size() * sizeof(uptr)); 820b57cec5SDimitry Andric } 830b57cec5SDimitry Andric Print("Creating : "); 840b57cec5SDimitry Andric } 850b57cec5SDimitry Andric } 860b57cec5SDimitry Andric 870b57cec5SDimitry Andric void Thread::ClearShadowForThreadStackAndTLS() { 880b57cec5SDimitry Andric if (stack_top_ != stack_bottom_) 890b57cec5SDimitry Andric TagMemory(stack_bottom_, stack_top_ - stack_bottom_, 0); 900b57cec5SDimitry Andric if (tls_begin_ != tls_end_) 910b57cec5SDimitry Andric TagMemory(tls_begin_, tls_end_ - tls_begin_, 0); 920b57cec5SDimitry Andric } 930b57cec5SDimitry Andric 940b57cec5SDimitry Andric void Thread::Destroy() { 950b57cec5SDimitry Andric if (flags()->verbose_threads) 960b57cec5SDimitry Andric Print("Destroying: "); 970b57cec5SDimitry Andric AllocatorSwallowThreadLocalCache(allocator_cache()); 980b57cec5SDimitry Andric ClearShadowForThreadStackAndTLS(); 990b57cec5SDimitry Andric if (heap_allocations_) 1000b57cec5SDimitry Andric heap_allocations_->Delete(); 1010b57cec5SDimitry Andric DTLS_Destroy(); 1025ffd83dbSDimitry Andric // Unregister this as the current thread. 1035ffd83dbSDimitry Andric // Instrumented code can not run on this thread from this point onwards, but 1045ffd83dbSDimitry Andric // malloc/free can still be served. Glibc may call free() very late, after all 1055ffd83dbSDimitry Andric // TSD destructors are done. 1065ffd83dbSDimitry Andric CHECK_EQ(GetCurrentThread(), this); 1075ffd83dbSDimitry Andric *GetCurrentThreadLongPtr() = 0; 1080b57cec5SDimitry Andric } 1090b57cec5SDimitry Andric 1100b57cec5SDimitry Andric void Thread::Print(const char *Prefix) { 1110b57cec5SDimitry Andric Printf("%sT%zd %p stack: [%p,%p) sz: %zd tls: [%p,%p)\n", Prefix, 1120b57cec5SDimitry Andric unique_id_, this, stack_bottom(), stack_top(), 1130b57cec5SDimitry Andric stack_top() - stack_bottom(), 1140b57cec5SDimitry Andric tls_begin(), tls_end()); 1150b57cec5SDimitry Andric } 1160b57cec5SDimitry Andric 1170b57cec5SDimitry Andric static u32 xorshift(u32 state) { 1180b57cec5SDimitry Andric state ^= state << 13; 1190b57cec5SDimitry Andric state ^= state >> 17; 1200b57cec5SDimitry Andric state ^= state << 5; 1210b57cec5SDimitry Andric return state; 1220b57cec5SDimitry Andric } 1230b57cec5SDimitry Andric 1240b57cec5SDimitry Andric // Generate a (pseudo-)random non-zero tag. 125*fe6060f1SDimitry Andric tag_t Thread::GenerateRandomTag(uptr num_bits) { 126*fe6060f1SDimitry Andric DCHECK_GT(num_bits, 0); 1270b57cec5SDimitry Andric if (tagging_disabled_) return 0; 1280b57cec5SDimitry Andric tag_t tag; 129*fe6060f1SDimitry Andric const uptr tag_mask = (1ULL << num_bits) - 1; 1300b57cec5SDimitry Andric do { 1310b57cec5SDimitry Andric if (flags()->random_tags) { 1320b57cec5SDimitry Andric if (!random_buffer_) 1330b57cec5SDimitry Andric random_buffer_ = random_state_ = xorshift(random_state_); 1340b57cec5SDimitry Andric CHECK(random_buffer_); 135*fe6060f1SDimitry Andric tag = random_buffer_ & tag_mask; 136*fe6060f1SDimitry Andric random_buffer_ >>= num_bits; 1370b57cec5SDimitry Andric } else { 138*fe6060f1SDimitry Andric random_state_ += 1; 139*fe6060f1SDimitry Andric tag = random_state_ & tag_mask; 1400b57cec5SDimitry Andric } 1410b57cec5SDimitry Andric } while (!tag); 1420b57cec5SDimitry Andric return tag; 1430b57cec5SDimitry Andric } 1440b57cec5SDimitry Andric 1450b57cec5SDimitry Andric } // namespace __hwasan 146