1*0b57cec5SDimitry Andric //===-- msan.h --------------------------------------------------*- C++ -*-===// 2*0b57cec5SDimitry Andric // 3*0b57cec5SDimitry Andric // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. 4*0b57cec5SDimitry Andric // See https://llvm.org/LICENSE.txt for license information. 5*0b57cec5SDimitry Andric // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception 6*0b57cec5SDimitry Andric // 7*0b57cec5SDimitry Andric //===----------------------------------------------------------------------===// 8*0b57cec5SDimitry Andric // 9*0b57cec5SDimitry Andric // This file is a part of MemorySanitizer. 10*0b57cec5SDimitry Andric // 11*0b57cec5SDimitry Andric // Private MSan header. 12*0b57cec5SDimitry Andric //===----------------------------------------------------------------------===// 13*0b57cec5SDimitry Andric 14*0b57cec5SDimitry Andric #ifndef MSAN_H 15*0b57cec5SDimitry Andric #define MSAN_H 16*0b57cec5SDimitry Andric 17*0b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_flags.h" 18*0b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_internal_defs.h" 19*0b57cec5SDimitry Andric #include "sanitizer_common/sanitizer_stacktrace.h" 20*0b57cec5SDimitry Andric #include "msan_interface_internal.h" 21*0b57cec5SDimitry Andric #include "msan_flags.h" 22*0b57cec5SDimitry Andric #include "ubsan/ubsan_platform.h" 23*0b57cec5SDimitry Andric 24*0b57cec5SDimitry Andric #ifndef MSAN_REPLACE_OPERATORS_NEW_AND_DELETE 25*0b57cec5SDimitry Andric # define MSAN_REPLACE_OPERATORS_NEW_AND_DELETE 1 26*0b57cec5SDimitry Andric #endif 27*0b57cec5SDimitry Andric 28*0b57cec5SDimitry Andric #ifndef MSAN_CONTAINS_UBSAN 29*0b57cec5SDimitry Andric # define MSAN_CONTAINS_UBSAN CAN_SANITIZE_UB 30*0b57cec5SDimitry Andric #endif 31*0b57cec5SDimitry Andric 32*0b57cec5SDimitry Andric struct MappingDesc { 33*0b57cec5SDimitry Andric uptr start; 34*0b57cec5SDimitry Andric uptr end; 35*0b57cec5SDimitry Andric enum Type { 36*0b57cec5SDimitry Andric INVALID, APP, SHADOW, ORIGIN 37*0b57cec5SDimitry Andric } type; 38*0b57cec5SDimitry Andric const char *name; 39*0b57cec5SDimitry Andric }; 40*0b57cec5SDimitry Andric 41*0b57cec5SDimitry Andric 42*0b57cec5SDimitry Andric #if SANITIZER_LINUX && defined(__mips64) 43*0b57cec5SDimitry Andric 44*0b57cec5SDimitry Andric // MIPS64 maps: 45*0b57cec5SDimitry Andric // - 0x0000000000-0x0200000000: Program own segments 46*0b57cec5SDimitry Andric // - 0xa200000000-0xc000000000: PIE program segments 47*0b57cec5SDimitry Andric // - 0xe200000000-0xffffffffff: libraries segments. 48*0b57cec5SDimitry Andric const MappingDesc kMemoryLayout[] = { 49*0b57cec5SDimitry Andric {0x000000000000ULL, 0x000200000000ULL, MappingDesc::APP, "app-1"}, 50*0b57cec5SDimitry Andric {0x000200000000ULL, 0x002200000000ULL, MappingDesc::INVALID, "invalid"}, 51*0b57cec5SDimitry Andric {0x002200000000ULL, 0x004000000000ULL, MappingDesc::SHADOW, "shadow-2"}, 52*0b57cec5SDimitry Andric {0x004000000000ULL, 0x004200000000ULL, MappingDesc::INVALID, "invalid"}, 53*0b57cec5SDimitry Andric {0x004200000000ULL, 0x006000000000ULL, MappingDesc::ORIGIN, "origin-2"}, 54*0b57cec5SDimitry Andric {0x006000000000ULL, 0x006200000000ULL, MappingDesc::INVALID, "invalid"}, 55*0b57cec5SDimitry Andric {0x006200000000ULL, 0x008000000000ULL, MappingDesc::SHADOW, "shadow-3"}, 56*0b57cec5SDimitry Andric {0x008000000000ULL, 0x008200000000ULL, MappingDesc::SHADOW, "shadow-1"}, 57*0b57cec5SDimitry Andric {0x008200000000ULL, 0x00a000000000ULL, MappingDesc::ORIGIN, "origin-3"}, 58*0b57cec5SDimitry Andric {0x00a000000000ULL, 0x00a200000000ULL, MappingDesc::ORIGIN, "origin-1"}, 59*0b57cec5SDimitry Andric {0x00a200000000ULL, 0x00c000000000ULL, MappingDesc::APP, "app-2"}, 60*0b57cec5SDimitry Andric {0x00c000000000ULL, 0x00e200000000ULL, MappingDesc::INVALID, "invalid"}, 61*0b57cec5SDimitry Andric {0x00e200000000ULL, 0x00ffffffffffULL, MappingDesc::APP, "app-3"}}; 62*0b57cec5SDimitry Andric 63*0b57cec5SDimitry Andric #define MEM_TO_SHADOW(mem) (((uptr)(mem)) ^ 0x8000000000ULL) 64*0b57cec5SDimitry Andric #define SHADOW_TO_ORIGIN(shadow) (((uptr)(shadow)) + 0x2000000000ULL) 65*0b57cec5SDimitry Andric 66*0b57cec5SDimitry Andric #elif SANITIZER_LINUX && defined(__aarch64__) 67*0b57cec5SDimitry Andric 68*0b57cec5SDimitry Andric // The mapping describes both 39-bits, 42-bits, and 48-bits VMA. AArch64 69*0b57cec5SDimitry Andric // maps: 70*0b57cec5SDimitry Andric // - 0x0000000000000-0x0000010000000: 39/42/48-bits program own segments 71*0b57cec5SDimitry Andric // - 0x0005500000000-0x0005600000000: 39-bits PIE program segments 72*0b57cec5SDimitry Andric // - 0x0007f80000000-0x0007fffffffff: 39-bits libraries segments 73*0b57cec5SDimitry Andric // - 0x002aa00000000-0x002ab00000000: 42-bits PIE program segments 74*0b57cec5SDimitry Andric // - 0x003ff00000000-0x003ffffffffff: 42-bits libraries segments 75*0b57cec5SDimitry Andric // - 0x0aaaaa0000000-0x0aaab00000000: 48-bits PIE program segments 76*0b57cec5SDimitry Andric // - 0xffff000000000-0x1000000000000: 48-bits libraries segments 77*0b57cec5SDimitry Andric // It is fragmented in multiples segments to increase the memory available 78*0b57cec5SDimitry Andric // on 42-bits (12.21% of total VMA available for 42-bits and 13.28 for 79*0b57cec5SDimitry Andric // 39 bits). The 48-bits segments only cover the usual PIE/default segments 80*0b57cec5SDimitry Andric // plus some more segments (262144GB total, 0.39% total VMA). 81*0b57cec5SDimitry Andric const MappingDesc kMemoryLayout[] = { 82*0b57cec5SDimitry Andric {0x00000000000ULL, 0x01000000000ULL, MappingDesc::INVALID, "invalid"}, 83*0b57cec5SDimitry Andric {0x01000000000ULL, 0x02000000000ULL, MappingDesc::SHADOW, "shadow-2"}, 84*0b57cec5SDimitry Andric {0x02000000000ULL, 0x03000000000ULL, MappingDesc::ORIGIN, "origin-2"}, 85*0b57cec5SDimitry Andric {0x03000000000ULL, 0x04000000000ULL, MappingDesc::SHADOW, "shadow-1"}, 86*0b57cec5SDimitry Andric {0x04000000000ULL, 0x05000000000ULL, MappingDesc::ORIGIN, "origin-1"}, 87*0b57cec5SDimitry Andric {0x05000000000ULL, 0x06000000000ULL, MappingDesc::APP, "app-1"}, 88*0b57cec5SDimitry Andric {0x06000000000ULL, 0x07000000000ULL, MappingDesc::INVALID, "invalid"}, 89*0b57cec5SDimitry Andric {0x07000000000ULL, 0x08000000000ULL, MappingDesc::APP, "app-2"}, 90*0b57cec5SDimitry Andric {0x08000000000ULL, 0x09000000000ULL, MappingDesc::INVALID, "invalid"}, 91*0b57cec5SDimitry Andric // The mappings below are used only for 42-bits VMA. 92*0b57cec5SDimitry Andric {0x09000000000ULL, 0x0A000000000ULL, MappingDesc::SHADOW, "shadow-3"}, 93*0b57cec5SDimitry Andric {0x0A000000000ULL, 0x0B000000000ULL, MappingDesc::ORIGIN, "origin-3"}, 94*0b57cec5SDimitry Andric {0x0B000000000ULL, 0x0F000000000ULL, MappingDesc::INVALID, "invalid"}, 95*0b57cec5SDimitry Andric {0x0F000000000ULL, 0x10000000000ULL, MappingDesc::APP, "app-3"}, 96*0b57cec5SDimitry Andric {0x10000000000ULL, 0x11000000000ULL, MappingDesc::INVALID, "invalid"}, 97*0b57cec5SDimitry Andric {0x11000000000ULL, 0x12000000000ULL, MappingDesc::APP, "app-4"}, 98*0b57cec5SDimitry Andric {0x12000000000ULL, 0x17000000000ULL, MappingDesc::INVALID, "invalid"}, 99*0b57cec5SDimitry Andric {0x17000000000ULL, 0x18000000000ULL, MappingDesc::SHADOW, "shadow-4"}, 100*0b57cec5SDimitry Andric {0x18000000000ULL, 0x19000000000ULL, MappingDesc::ORIGIN, "origin-4"}, 101*0b57cec5SDimitry Andric {0x19000000000ULL, 0x20000000000ULL, MappingDesc::INVALID, "invalid"}, 102*0b57cec5SDimitry Andric {0x20000000000ULL, 0x21000000000ULL, MappingDesc::APP, "app-5"}, 103*0b57cec5SDimitry Andric {0x21000000000ULL, 0x26000000000ULL, MappingDesc::INVALID, "invalid"}, 104*0b57cec5SDimitry Andric {0x26000000000ULL, 0x27000000000ULL, MappingDesc::SHADOW, "shadow-5"}, 105*0b57cec5SDimitry Andric {0x27000000000ULL, 0x28000000000ULL, MappingDesc::ORIGIN, "origin-5"}, 106*0b57cec5SDimitry Andric {0x28000000000ULL, 0x29000000000ULL, MappingDesc::SHADOW, "shadow-7"}, 107*0b57cec5SDimitry Andric {0x29000000000ULL, 0x2A000000000ULL, MappingDesc::ORIGIN, "origin-7"}, 108*0b57cec5SDimitry Andric {0x2A000000000ULL, 0x2B000000000ULL, MappingDesc::APP, "app-6"}, 109*0b57cec5SDimitry Andric {0x2B000000000ULL, 0x2C000000000ULL, MappingDesc::INVALID, "invalid"}, 110*0b57cec5SDimitry Andric {0x2C000000000ULL, 0x2D000000000ULL, MappingDesc::SHADOW, "shadow-6"}, 111*0b57cec5SDimitry Andric {0x2D000000000ULL, 0x2E000000000ULL, MappingDesc::ORIGIN, "origin-6"}, 112*0b57cec5SDimitry Andric {0x2E000000000ULL, 0x2F000000000ULL, MappingDesc::APP, "app-7"}, 113*0b57cec5SDimitry Andric {0x2F000000000ULL, 0x39000000000ULL, MappingDesc::INVALID, "invalid"}, 114*0b57cec5SDimitry Andric {0x39000000000ULL, 0x3A000000000ULL, MappingDesc::SHADOW, "shadow-9"}, 115*0b57cec5SDimitry Andric {0x3A000000000ULL, 0x3B000000000ULL, MappingDesc::ORIGIN, "origin-9"}, 116*0b57cec5SDimitry Andric {0x3B000000000ULL, 0x3C000000000ULL, MappingDesc::APP, "app-8"}, 117*0b57cec5SDimitry Andric {0x3C000000000ULL, 0x3D000000000ULL, MappingDesc::INVALID, "invalid"}, 118*0b57cec5SDimitry Andric {0x3D000000000ULL, 0x3E000000000ULL, MappingDesc::SHADOW, "shadow-8"}, 119*0b57cec5SDimitry Andric {0x3E000000000ULL, 0x3F000000000ULL, MappingDesc::ORIGIN, "origin-8"}, 120*0b57cec5SDimitry Andric {0x3F000000000ULL, 0x40000000000ULL, MappingDesc::APP, "app-9"}, 121*0b57cec5SDimitry Andric // The mappings below are used only for 48-bits VMA. 122*0b57cec5SDimitry Andric // TODO(unknown): 48-bit mapping ony covers the usual PIE, non-PIE 123*0b57cec5SDimitry Andric // segments and some more segments totalizing 262144GB of VMA (which cover 124*0b57cec5SDimitry Andric // only 0.32% of all 48-bit VMA). Memory avaliability can be increase by 125*0b57cec5SDimitry Andric // adding multiple application segments like 39 and 42 mapping. 126*0b57cec5SDimitry Andric {0x0040000000000ULL, 0x0041000000000ULL, MappingDesc::INVALID, "invalid"}, 127*0b57cec5SDimitry Andric {0x0041000000000ULL, 0x0042000000000ULL, MappingDesc::APP, "app-10"}, 128*0b57cec5SDimitry Andric {0x0042000000000ULL, 0x0047000000000ULL, MappingDesc::INVALID, "invalid"}, 129*0b57cec5SDimitry Andric {0x0047000000000ULL, 0x0048000000000ULL, MappingDesc::SHADOW, "shadow-10"}, 130*0b57cec5SDimitry Andric {0x0048000000000ULL, 0x0049000000000ULL, MappingDesc::ORIGIN, "origin-10"}, 131*0b57cec5SDimitry Andric {0x0049000000000ULL, 0x0050000000000ULL, MappingDesc::INVALID, "invalid"}, 132*0b57cec5SDimitry Andric {0x0050000000000ULL, 0x0051000000000ULL, MappingDesc::APP, "app-11"}, 133*0b57cec5SDimitry Andric {0x0051000000000ULL, 0x0056000000000ULL, MappingDesc::INVALID, "invalid"}, 134*0b57cec5SDimitry Andric {0x0056000000000ULL, 0x0057000000000ULL, MappingDesc::SHADOW, "shadow-11"}, 135*0b57cec5SDimitry Andric {0x0057000000000ULL, 0x0058000000000ULL, MappingDesc::ORIGIN, "origin-11"}, 136*0b57cec5SDimitry Andric {0x0058000000000ULL, 0x0059000000000ULL, MappingDesc::APP, "app-12"}, 137*0b57cec5SDimitry Andric {0x0059000000000ULL, 0x005E000000000ULL, MappingDesc::INVALID, "invalid"}, 138*0b57cec5SDimitry Andric {0x005E000000000ULL, 0x005F000000000ULL, MappingDesc::SHADOW, "shadow-12"}, 139*0b57cec5SDimitry Andric {0x005F000000000ULL, 0x0060000000000ULL, MappingDesc::ORIGIN, "origin-12"}, 140*0b57cec5SDimitry Andric {0x0060000000000ULL, 0x0061000000000ULL, MappingDesc::INVALID, "invalid"}, 141*0b57cec5SDimitry Andric {0x0061000000000ULL, 0x0062000000000ULL, MappingDesc::APP, "app-13"}, 142*0b57cec5SDimitry Andric {0x0062000000000ULL, 0x0067000000000ULL, MappingDesc::INVALID, "invalid"}, 143*0b57cec5SDimitry Andric {0x0067000000000ULL, 0x0068000000000ULL, MappingDesc::SHADOW, "shadow-13"}, 144*0b57cec5SDimitry Andric {0x0068000000000ULL, 0x0069000000000ULL, MappingDesc::ORIGIN, "origin-13"}, 145*0b57cec5SDimitry Andric {0x0069000000000ULL, 0x0AAAAA0000000ULL, MappingDesc::INVALID, "invalid"}, 146*0b57cec5SDimitry Andric {0x0AAAAA0000000ULL, 0x0AAAB00000000ULL, MappingDesc::APP, "app-14"}, 147*0b57cec5SDimitry Andric {0x0AAAB00000000ULL, 0x0AACAA0000000ULL, MappingDesc::INVALID, "invalid"}, 148*0b57cec5SDimitry Andric {0x0AACAA0000000ULL, 0x0AACB00000000ULL, MappingDesc::SHADOW, "shadow-14"}, 149*0b57cec5SDimitry Andric {0x0AACB00000000ULL, 0x0AADAA0000000ULL, MappingDesc::INVALID, "invalid"}, 150*0b57cec5SDimitry Andric {0x0AADAA0000000ULL, 0x0AADB00000000ULL, MappingDesc::ORIGIN, "origin-14"}, 151*0b57cec5SDimitry Andric {0x0AADB00000000ULL, 0x0FF9F00000000ULL, MappingDesc::INVALID, "invalid"}, 152*0b57cec5SDimitry Andric {0x0FF9F00000000ULL, 0x0FFA000000000ULL, MappingDesc::SHADOW, "shadow-15"}, 153*0b57cec5SDimitry Andric {0x0FFA000000000ULL, 0x0FFAF00000000ULL, MappingDesc::INVALID, "invalid"}, 154*0b57cec5SDimitry Andric {0x0FFAF00000000ULL, 0x0FFB000000000ULL, MappingDesc::ORIGIN, "origin-15"}, 155*0b57cec5SDimitry Andric {0x0FFB000000000ULL, 0x0FFFF00000000ULL, MappingDesc::INVALID, "invalid"}, 156*0b57cec5SDimitry Andric {0x0FFFF00000000ULL, 0x1000000000000ULL, MappingDesc::APP, "app-15"}, 157*0b57cec5SDimitry Andric }; 158*0b57cec5SDimitry Andric # define MEM_TO_SHADOW(mem) ((uptr)mem ^ 0x6000000000ULL) 159*0b57cec5SDimitry Andric # define SHADOW_TO_ORIGIN(shadow) (((uptr)(shadow)) + 0x1000000000ULL) 160*0b57cec5SDimitry Andric 161*0b57cec5SDimitry Andric #elif SANITIZER_LINUX && SANITIZER_PPC64 162*0b57cec5SDimitry Andric const MappingDesc kMemoryLayout[] = { 163*0b57cec5SDimitry Andric {0x000000000000ULL, 0x000200000000ULL, MappingDesc::APP, "low memory"}, 164*0b57cec5SDimitry Andric {0x000200000000ULL, 0x080000000000ULL, MappingDesc::INVALID, "invalid"}, 165*0b57cec5SDimitry Andric {0x080000000000ULL, 0x180200000000ULL, MappingDesc::SHADOW, "shadow"}, 166*0b57cec5SDimitry Andric {0x180200000000ULL, 0x1C0000000000ULL, MappingDesc::INVALID, "invalid"}, 167*0b57cec5SDimitry Andric {0x1C0000000000ULL, 0x2C0200000000ULL, MappingDesc::ORIGIN, "origin"}, 168*0b57cec5SDimitry Andric {0x2C0200000000ULL, 0x300000000000ULL, MappingDesc::INVALID, "invalid"}, 169*0b57cec5SDimitry Andric {0x300000000000ULL, 0x800000000000ULL, MappingDesc::APP, "high memory"}}; 170*0b57cec5SDimitry Andric 171*0b57cec5SDimitry Andric // Various kernels use different low end ranges but we can combine them into one 172*0b57cec5SDimitry Andric // big range. They also use different high end ranges but we can map them all to 173*0b57cec5SDimitry Andric // one range. 174*0b57cec5SDimitry Andric // Maps low and high app ranges to contiguous space with zero base: 175*0b57cec5SDimitry Andric // Low: 0000 0000 0000 - 0001 ffff ffff -> 1000 0000 0000 - 1001 ffff ffff 176*0b57cec5SDimitry Andric // High: 3000 0000 0000 - 3fff ffff ffff -> 0000 0000 0000 - 0fff ffff ffff 177*0b57cec5SDimitry Andric // High: 4000 0000 0000 - 4fff ffff ffff -> 0000 0000 0000 - 0fff ffff ffff 178*0b57cec5SDimitry Andric // High: 7000 0000 0000 - 7fff ffff ffff -> 0000 0000 0000 - 0fff ffff ffff 179*0b57cec5SDimitry Andric #define LINEARIZE_MEM(mem) \ 180*0b57cec5SDimitry Andric (((uptr)(mem) & ~0xE00000000000ULL) ^ 0x100000000000ULL) 181*0b57cec5SDimitry Andric #define MEM_TO_SHADOW(mem) (LINEARIZE_MEM((mem)) + 0x080000000000ULL) 182*0b57cec5SDimitry Andric #define SHADOW_TO_ORIGIN(shadow) (((uptr)(shadow)) + 0x140000000000ULL) 183*0b57cec5SDimitry Andric 184*0b57cec5SDimitry Andric #elif SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 64 185*0b57cec5SDimitry Andric 186*0b57cec5SDimitry Andric // Low memory: main binary, MAP_32BIT mappings and modules 187*0b57cec5SDimitry Andric // High memory: heap, modules and main thread stack 188*0b57cec5SDimitry Andric const MappingDesc kMemoryLayout[] = { 189*0b57cec5SDimitry Andric {0x000000000000ULL, 0x010000000000ULL, MappingDesc::APP, "low memory"}, 190*0b57cec5SDimitry Andric {0x010000000000ULL, 0x100000000000ULL, MappingDesc::INVALID, "invalid"}, 191*0b57cec5SDimitry Andric {0x100000000000ULL, 0x310000000000ULL, MappingDesc::SHADOW, "shadow"}, 192*0b57cec5SDimitry Andric {0x310000000000ULL, 0x380000000000ULL, MappingDesc::INVALID, "invalid"}, 193*0b57cec5SDimitry Andric {0x380000000000ULL, 0x590000000000ULL, MappingDesc::ORIGIN, "origin"}, 194*0b57cec5SDimitry Andric {0x590000000000ULL, 0x600000000000ULL, MappingDesc::INVALID, "invalid"}, 195*0b57cec5SDimitry Andric {0x600000000000ULL, 0x800000000000ULL, MappingDesc::APP, "high memory"}}; 196*0b57cec5SDimitry Andric 197*0b57cec5SDimitry Andric // Maps low and high app ranges to contiguous space with zero base: 198*0b57cec5SDimitry Andric // Low: 0000 0000 0000 - 00ff ffff ffff -> 2000 0000 0000 - 20ff ffff ffff 199*0b57cec5SDimitry Andric // High: 6000 0000 0000 - 7fff ffff ffff -> 0000 0000 0000 - 1fff ffff ffff 200*0b57cec5SDimitry Andric #define LINEARIZE_MEM(mem) \ 201*0b57cec5SDimitry Andric (((uptr)(mem) & ~0xc00000000000ULL) ^ 0x200000000000ULL) 202*0b57cec5SDimitry Andric #define MEM_TO_SHADOW(mem) (LINEARIZE_MEM((mem)) + 0x100000000000ULL) 203*0b57cec5SDimitry Andric #define SHADOW_TO_ORIGIN(shadow) (((uptr)(shadow)) + 0x280000000000) 204*0b57cec5SDimitry Andric 205*0b57cec5SDimitry Andric #elif SANITIZER_NETBSD || (SANITIZER_LINUX && SANITIZER_WORDSIZE == 64) 206*0b57cec5SDimitry Andric 207*0b57cec5SDimitry Andric #ifdef MSAN_LINUX_X86_64_OLD_MAPPING 208*0b57cec5SDimitry Andric // Requries PIE binary and ASLR enabled. 209*0b57cec5SDimitry Andric // Main thread stack and DSOs at 0x7f0000000000 (sometimes 0x7e0000000000). 210*0b57cec5SDimitry Andric // Heap at 0x600000000000. 211*0b57cec5SDimitry Andric const MappingDesc kMemoryLayout[] = { 212*0b57cec5SDimitry Andric {0x000000000000ULL, 0x200000000000ULL, MappingDesc::INVALID, "invalid"}, 213*0b57cec5SDimitry Andric {0x200000000000ULL, 0x400000000000ULL, MappingDesc::SHADOW, "shadow"}, 214*0b57cec5SDimitry Andric {0x400000000000ULL, 0x600000000000ULL, MappingDesc::ORIGIN, "origin"}, 215*0b57cec5SDimitry Andric {0x600000000000ULL, 0x800000000000ULL, MappingDesc::APP, "app"}}; 216*0b57cec5SDimitry Andric 217*0b57cec5SDimitry Andric #define MEM_TO_SHADOW(mem) (((uptr)(mem)) & ~0x400000000000ULL) 218*0b57cec5SDimitry Andric #define SHADOW_TO_ORIGIN(mem) (((uptr)(mem)) + 0x200000000000ULL) 219*0b57cec5SDimitry Andric #else // MSAN_LINUX_X86_64_OLD_MAPPING 220*0b57cec5SDimitry Andric // All of the following configurations are supported. 221*0b57cec5SDimitry Andric // ASLR disabled: main executable and DSOs at 0x555550000000 222*0b57cec5SDimitry Andric // PIE and ASLR: main executable and DSOs at 0x7f0000000000 223*0b57cec5SDimitry Andric // non-PIE: main executable below 0x100000000, DSOs at 0x7f0000000000 224*0b57cec5SDimitry Andric // Heap at 0x700000000000. 225*0b57cec5SDimitry Andric const MappingDesc kMemoryLayout[] = { 226*0b57cec5SDimitry Andric {0x000000000000ULL, 0x010000000000ULL, MappingDesc::APP, "app-1"}, 227*0b57cec5SDimitry Andric {0x010000000000ULL, 0x100000000000ULL, MappingDesc::SHADOW, "shadow-2"}, 228*0b57cec5SDimitry Andric {0x100000000000ULL, 0x110000000000ULL, MappingDesc::INVALID, "invalid"}, 229*0b57cec5SDimitry Andric {0x110000000000ULL, 0x200000000000ULL, MappingDesc::ORIGIN, "origin-2"}, 230*0b57cec5SDimitry Andric {0x200000000000ULL, 0x300000000000ULL, MappingDesc::SHADOW, "shadow-3"}, 231*0b57cec5SDimitry Andric {0x300000000000ULL, 0x400000000000ULL, MappingDesc::ORIGIN, "origin-3"}, 232*0b57cec5SDimitry Andric {0x400000000000ULL, 0x500000000000ULL, MappingDesc::INVALID, "invalid"}, 233*0b57cec5SDimitry Andric {0x500000000000ULL, 0x510000000000ULL, MappingDesc::SHADOW, "shadow-1"}, 234*0b57cec5SDimitry Andric {0x510000000000ULL, 0x600000000000ULL, MappingDesc::APP, "app-2"}, 235*0b57cec5SDimitry Andric {0x600000000000ULL, 0x610000000000ULL, MappingDesc::ORIGIN, "origin-1"}, 236*0b57cec5SDimitry Andric {0x610000000000ULL, 0x700000000000ULL, MappingDesc::INVALID, "invalid"}, 237*0b57cec5SDimitry Andric {0x700000000000ULL, 0x800000000000ULL, MappingDesc::APP, "app-3"}}; 238*0b57cec5SDimitry Andric #define MEM_TO_SHADOW(mem) (((uptr)(mem)) ^ 0x500000000000ULL) 239*0b57cec5SDimitry Andric #define SHADOW_TO_ORIGIN(mem) (((uptr)(mem)) + 0x100000000000ULL) 240*0b57cec5SDimitry Andric #endif // MSAN_LINUX_X86_64_OLD_MAPPING 241*0b57cec5SDimitry Andric 242*0b57cec5SDimitry Andric #else 243*0b57cec5SDimitry Andric #error "Unsupported platform" 244*0b57cec5SDimitry Andric #endif 245*0b57cec5SDimitry Andric 246*0b57cec5SDimitry Andric const uptr kMemoryLayoutSize = sizeof(kMemoryLayout) / sizeof(kMemoryLayout[0]); 247*0b57cec5SDimitry Andric 248*0b57cec5SDimitry Andric #define MEM_TO_ORIGIN(mem) (SHADOW_TO_ORIGIN(MEM_TO_SHADOW((mem)))) 249*0b57cec5SDimitry Andric 250*0b57cec5SDimitry Andric #ifndef __clang__ 251*0b57cec5SDimitry Andric __attribute__((optimize("unroll-loops"))) 252*0b57cec5SDimitry Andric #endif 253*0b57cec5SDimitry Andric inline bool addr_is_type(uptr addr, MappingDesc::Type mapping_type) { 254*0b57cec5SDimitry Andric // It is critical for performance that this loop is unrolled (because then it is 255*0b57cec5SDimitry Andric // simplified into just a few constant comparisons). 256*0b57cec5SDimitry Andric #ifdef __clang__ 257*0b57cec5SDimitry Andric #pragma unroll 258*0b57cec5SDimitry Andric #endif 259*0b57cec5SDimitry Andric for (unsigned i = 0; i < kMemoryLayoutSize; ++i) 260*0b57cec5SDimitry Andric if (kMemoryLayout[i].type == mapping_type && 261*0b57cec5SDimitry Andric addr >= kMemoryLayout[i].start && addr < kMemoryLayout[i].end) 262*0b57cec5SDimitry Andric return true; 263*0b57cec5SDimitry Andric return false; 264*0b57cec5SDimitry Andric } 265*0b57cec5SDimitry Andric 266*0b57cec5SDimitry Andric #define MEM_IS_APP(mem) addr_is_type((uptr)(mem), MappingDesc::APP) 267*0b57cec5SDimitry Andric #define MEM_IS_SHADOW(mem) addr_is_type((uptr)(mem), MappingDesc::SHADOW) 268*0b57cec5SDimitry Andric #define MEM_IS_ORIGIN(mem) addr_is_type((uptr)(mem), MappingDesc::ORIGIN) 269*0b57cec5SDimitry Andric 270*0b57cec5SDimitry Andric // These constants must be kept in sync with the ones in MemorySanitizer.cc. 271*0b57cec5SDimitry Andric const int kMsanParamTlsSize = 800; 272*0b57cec5SDimitry Andric const int kMsanRetvalTlsSize = 800; 273*0b57cec5SDimitry Andric 274*0b57cec5SDimitry Andric namespace __msan { 275*0b57cec5SDimitry Andric extern int msan_inited; 276*0b57cec5SDimitry Andric extern bool msan_init_is_running; 277*0b57cec5SDimitry Andric extern int msan_report_count; 278*0b57cec5SDimitry Andric 279*0b57cec5SDimitry Andric bool ProtectRange(uptr beg, uptr end); 280*0b57cec5SDimitry Andric bool InitShadow(bool init_origins); 281*0b57cec5SDimitry Andric char *GetProcSelfMaps(); 282*0b57cec5SDimitry Andric void InitializeInterceptors(); 283*0b57cec5SDimitry Andric 284*0b57cec5SDimitry Andric void MsanAllocatorInit(); 285*0b57cec5SDimitry Andric void MsanAllocatorThreadFinish(); 286*0b57cec5SDimitry Andric void MsanDeallocate(StackTrace *stack, void *ptr); 287*0b57cec5SDimitry Andric 288*0b57cec5SDimitry Andric void *msan_malloc(uptr size, StackTrace *stack); 289*0b57cec5SDimitry Andric void *msan_calloc(uptr nmemb, uptr size, StackTrace *stack); 290*0b57cec5SDimitry Andric void *msan_realloc(void *ptr, uptr size, StackTrace *stack); 291*0b57cec5SDimitry Andric void *msan_reallocarray(void *ptr, uptr nmemb, uptr size, StackTrace *stack); 292*0b57cec5SDimitry Andric void *msan_valloc(uptr size, StackTrace *stack); 293*0b57cec5SDimitry Andric void *msan_pvalloc(uptr size, StackTrace *stack); 294*0b57cec5SDimitry Andric void *msan_aligned_alloc(uptr alignment, uptr size, StackTrace *stack); 295*0b57cec5SDimitry Andric void *msan_memalign(uptr alignment, uptr size, StackTrace *stack); 296*0b57cec5SDimitry Andric int msan_posix_memalign(void **memptr, uptr alignment, uptr size, 297*0b57cec5SDimitry Andric StackTrace *stack); 298*0b57cec5SDimitry Andric 299*0b57cec5SDimitry Andric void InstallTrapHandler(); 300*0b57cec5SDimitry Andric void InstallAtExitHandler(); 301*0b57cec5SDimitry Andric 302*0b57cec5SDimitry Andric const char *GetStackOriginDescr(u32 id, uptr *pc); 303*0b57cec5SDimitry Andric 304*0b57cec5SDimitry Andric void EnterSymbolizer(); 305*0b57cec5SDimitry Andric void ExitSymbolizer(); 306*0b57cec5SDimitry Andric bool IsInSymbolizer(); 307*0b57cec5SDimitry Andric 308*0b57cec5SDimitry Andric struct SymbolizerScope { 309*0b57cec5SDimitry Andric SymbolizerScope() { EnterSymbolizer(); } 310*0b57cec5SDimitry Andric ~SymbolizerScope() { ExitSymbolizer(); } 311*0b57cec5SDimitry Andric }; 312*0b57cec5SDimitry Andric 313*0b57cec5SDimitry Andric void PrintWarning(uptr pc, uptr bp); 314*0b57cec5SDimitry Andric void PrintWarningWithOrigin(uptr pc, uptr bp, u32 origin); 315*0b57cec5SDimitry Andric 316*0b57cec5SDimitry Andric // Unpoison first n function arguments. 317*0b57cec5SDimitry Andric void UnpoisonParam(uptr n); 318*0b57cec5SDimitry Andric void UnpoisonThreadLocalState(); 319*0b57cec5SDimitry Andric 320*0b57cec5SDimitry Andric // Returns a "chained" origin id, pointing to the given stack trace followed by 321*0b57cec5SDimitry Andric // the previous origin id. 322*0b57cec5SDimitry Andric u32 ChainOrigin(u32 id, StackTrace *stack); 323*0b57cec5SDimitry Andric 324*0b57cec5SDimitry Andric const int STACK_TRACE_TAG_POISON = StackTrace::TAG_CUSTOM + 1; 325*0b57cec5SDimitry Andric 326*0b57cec5SDimitry Andric #define GET_MALLOC_STACK_TRACE \ 327*0b57cec5SDimitry Andric BufferedStackTrace stack; \ 328*0b57cec5SDimitry Andric if (__msan_get_track_origins() && msan_inited) \ 329*0b57cec5SDimitry Andric stack.Unwind(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME(), \ 330*0b57cec5SDimitry Andric nullptr, common_flags()->fast_unwind_on_malloc, \ 331*0b57cec5SDimitry Andric common_flags()->malloc_context_size) 332*0b57cec5SDimitry Andric 333*0b57cec5SDimitry Andric // For platforms which support slow unwinder only, we restrict the store context 334*0b57cec5SDimitry Andric // size to 1, basically only storing the current pc. We do this because the slow 335*0b57cec5SDimitry Andric // unwinder which is based on libunwind is not async signal safe and causes 336*0b57cec5SDimitry Andric // random freezes in forking applications as well as in signal handlers. 337*0b57cec5SDimitry Andric #define GET_STORE_STACK_TRACE_PC_BP(pc, bp) \ 338*0b57cec5SDimitry Andric BufferedStackTrace stack; \ 339*0b57cec5SDimitry Andric if (__msan_get_track_origins() > 1 && msan_inited) { \ 340*0b57cec5SDimitry Andric int size = flags()->store_context_size; \ 341*0b57cec5SDimitry Andric if (!SANITIZER_CAN_FAST_UNWIND) \ 342*0b57cec5SDimitry Andric size = Min(size, 1); \ 343*0b57cec5SDimitry Andric stack.Unwind(pc, bp, nullptr, common_flags()->fast_unwind_on_malloc, size);\ 344*0b57cec5SDimitry Andric } 345*0b57cec5SDimitry Andric 346*0b57cec5SDimitry Andric #define GET_STORE_STACK_TRACE \ 347*0b57cec5SDimitry Andric GET_STORE_STACK_TRACE_PC_BP(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME()) 348*0b57cec5SDimitry Andric 349*0b57cec5SDimitry Andric #define GET_FATAL_STACK_TRACE_PC_BP(pc, bp) \ 350*0b57cec5SDimitry Andric BufferedStackTrace stack; \ 351*0b57cec5SDimitry Andric if (msan_inited) \ 352*0b57cec5SDimitry Andric stack.Unwind(pc, bp, nullptr, common_flags()->fast_unwind_on_fatal) 353*0b57cec5SDimitry Andric 354*0b57cec5SDimitry Andric #define GET_FATAL_STACK_TRACE_HERE \ 355*0b57cec5SDimitry Andric GET_FATAL_STACK_TRACE_PC_BP(StackTrace::GetCurrentPc(), GET_CURRENT_FRAME()) 356*0b57cec5SDimitry Andric 357*0b57cec5SDimitry Andric #define PRINT_CURRENT_STACK_CHECK() \ 358*0b57cec5SDimitry Andric { \ 359*0b57cec5SDimitry Andric GET_FATAL_STACK_TRACE_HERE; \ 360*0b57cec5SDimitry Andric stack.Print(); \ 361*0b57cec5SDimitry Andric } 362*0b57cec5SDimitry Andric 363*0b57cec5SDimitry Andric class ScopedThreadLocalStateBackup { 364*0b57cec5SDimitry Andric public: 365*0b57cec5SDimitry Andric ScopedThreadLocalStateBackup() { Backup(); } 366*0b57cec5SDimitry Andric ~ScopedThreadLocalStateBackup() { Restore(); } 367*0b57cec5SDimitry Andric void Backup(); 368*0b57cec5SDimitry Andric void Restore(); 369*0b57cec5SDimitry Andric private: 370*0b57cec5SDimitry Andric u64 va_arg_overflow_size_tls; 371*0b57cec5SDimitry Andric }; 372*0b57cec5SDimitry Andric 373*0b57cec5SDimitry Andric void MsanTSDInit(void (*destructor)(void *tsd)); 374*0b57cec5SDimitry Andric void *MsanTSDGet(); 375*0b57cec5SDimitry Andric void MsanTSDSet(void *tsd); 376*0b57cec5SDimitry Andric void MsanTSDDtor(void *tsd); 377*0b57cec5SDimitry Andric 378*0b57cec5SDimitry Andric } // namespace __msan 379*0b57cec5SDimitry Andric 380*0b57cec5SDimitry Andric #define MSAN_MALLOC_HOOK(ptr, size) \ 381*0b57cec5SDimitry Andric do { \ 382*0b57cec5SDimitry Andric if (&__sanitizer_malloc_hook) { \ 383*0b57cec5SDimitry Andric UnpoisonParam(2); \ 384*0b57cec5SDimitry Andric __sanitizer_malloc_hook(ptr, size); \ 385*0b57cec5SDimitry Andric } \ 386*0b57cec5SDimitry Andric RunMallocHooks(ptr, size); \ 387*0b57cec5SDimitry Andric } while (false) 388*0b57cec5SDimitry Andric #define MSAN_FREE_HOOK(ptr) \ 389*0b57cec5SDimitry Andric do { \ 390*0b57cec5SDimitry Andric if (&__sanitizer_free_hook) { \ 391*0b57cec5SDimitry Andric UnpoisonParam(1); \ 392*0b57cec5SDimitry Andric __sanitizer_free_hook(ptr); \ 393*0b57cec5SDimitry Andric } \ 394*0b57cec5SDimitry Andric RunFreeHooks(ptr); \ 395*0b57cec5SDimitry Andric } while (false) 396*0b57cec5SDimitry Andric 397*0b57cec5SDimitry Andric #endif // MSAN_H 398