10b57cec5SDimitry Andric //===-- chunk.h -------------------------------------------------*- C++ -*-===// 20b57cec5SDimitry Andric // 30b57cec5SDimitry Andric // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. 40b57cec5SDimitry Andric // See https://llvm.org/LICENSE.txt for license information. 50b57cec5SDimitry Andric // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception 60b57cec5SDimitry Andric // 70b57cec5SDimitry Andric //===----------------------------------------------------------------------===// 80b57cec5SDimitry Andric 90b57cec5SDimitry Andric #ifndef SCUDO_CHUNK_H_ 100b57cec5SDimitry Andric #define SCUDO_CHUNK_H_ 110b57cec5SDimitry Andric 120b57cec5SDimitry Andric #include "platform.h" 130b57cec5SDimitry Andric 140b57cec5SDimitry Andric #include "atomic_helpers.h" 150b57cec5SDimitry Andric #include "checksum.h" 160b57cec5SDimitry Andric #include "common.h" 170b57cec5SDimitry Andric #include "report.h" 180b57cec5SDimitry Andric 190b57cec5SDimitry Andric namespace scudo { 200b57cec5SDimitry Andric 210b57cec5SDimitry Andric extern Checksum HashAlgorithm; 220b57cec5SDimitry Andric 23480093f4SDimitry Andric inline u16 computeChecksum(u32 Seed, uptr Value, uptr *Array, uptr ArraySize) { 240b57cec5SDimitry Andric // If the hardware CRC32 feature is defined here, it was enabled everywhere, 2568d75effSDimitry Andric // as opposed to only for crc32_hw.cpp. This means that other hardware 2668d75effSDimitry Andric // specific instructions were likely emitted at other places, and as a result 2768d75effSDimitry Andric // there is no reason to not use it here. 283a9a9c0cSDimitry Andric #if defined(__CRC32__) || defined(__SSE4_2__) || defined(__ARM_FEATURE_CRC32) 290b57cec5SDimitry Andric u32 Crc = static_cast<u32>(CRC32_INTRINSIC(Seed, Value)); 300b57cec5SDimitry Andric for (uptr I = 0; I < ArraySize; I++) 310b57cec5SDimitry Andric Crc = static_cast<u32>(CRC32_INTRINSIC(Crc, Array[I])); 3268d75effSDimitry Andric return static_cast<u16>(Crc ^ (Crc >> 16)); 330b57cec5SDimitry Andric #else 340b57cec5SDimitry Andric if (HashAlgorithm == Checksum::HardwareCRC32) { 350b57cec5SDimitry Andric u32 Crc = computeHardwareCRC32(Seed, Value); 360b57cec5SDimitry Andric for (uptr I = 0; I < ArraySize; I++) 370b57cec5SDimitry Andric Crc = computeHardwareCRC32(Crc, Array[I]); 3868d75effSDimitry Andric return static_cast<u16>(Crc ^ (Crc >> 16)); 390b57cec5SDimitry Andric } else { 4068d75effSDimitry Andric u16 Checksum = computeBSDChecksum(static_cast<u16>(Seed), Value); 410b57cec5SDimitry Andric for (uptr I = 0; I < ArraySize; I++) 420b57cec5SDimitry Andric Checksum = computeBSDChecksum(Checksum, Array[I]); 430b57cec5SDimitry Andric return Checksum; 440b57cec5SDimitry Andric } 45*81ad6265SDimitry Andric #endif // defined(__CRC32__) || defined(__SSE4_2__) || 46*81ad6265SDimitry Andric // defined(__ARM_FEATURE_CRC32) 470b57cec5SDimitry Andric } 480b57cec5SDimitry Andric 490b57cec5SDimitry Andric namespace Chunk { 500b57cec5SDimitry Andric 510b57cec5SDimitry Andric // Note that in an ideal world, `State` and `Origin` should be `enum class`, and 520b57cec5SDimitry Andric // the associated `UnpackedHeader` fields of their respective enum class type 530b57cec5SDimitry Andric // but https://gcc.gnu.org/bugzilla/show_bug.cgi?id=61414 prevents it from 540b57cec5SDimitry Andric // happening, as it will error, complaining the number of bits is not enough. 550b57cec5SDimitry Andric enum Origin : u8 { 560b57cec5SDimitry Andric Malloc = 0, 570b57cec5SDimitry Andric New = 1, 580b57cec5SDimitry Andric NewArray = 2, 590b57cec5SDimitry Andric Memalign = 3, 600b57cec5SDimitry Andric }; 610b57cec5SDimitry Andric 620b57cec5SDimitry Andric enum State : u8 { Available = 0, Allocated = 1, Quarantined = 2 }; 630b57cec5SDimitry Andric 640b57cec5SDimitry Andric typedef u64 PackedHeader; 650b57cec5SDimitry Andric // Update the 'Mask' constants to reflect changes in this structure. 660b57cec5SDimitry Andric struct UnpackedHeader { 6768d75effSDimitry Andric uptr ClassId : 8; 680b57cec5SDimitry Andric u8 State : 2; 69e8d8bef9SDimitry Andric // Origin if State == Allocated, or WasZeroed otherwise. 70e8d8bef9SDimitry Andric u8 OriginOrWasZeroed : 2; 7168d75effSDimitry Andric uptr SizeOrUnusedBytes : 20; 7268d75effSDimitry Andric uptr Offset : 16; 7368d75effSDimitry Andric uptr Checksum : 16; 740b57cec5SDimitry Andric }; 750b57cec5SDimitry Andric typedef atomic_u64 AtomicPackedHeader; 76480093f4SDimitry Andric static_assert(sizeof(UnpackedHeader) == sizeof(PackedHeader), ""); 770b57cec5SDimitry Andric 780b57cec5SDimitry Andric // Those constants are required to silence some -Werror=conversion errors when 790b57cec5SDimitry Andric // assigning values to the related bitfield variables. 800b57cec5SDimitry Andric constexpr uptr ClassIdMask = (1UL << 8) - 1; 8168d75effSDimitry Andric constexpr u8 StateMask = (1U << 2) - 1; 8268d75effSDimitry Andric constexpr u8 OriginMask = (1U << 2) - 1; 830b57cec5SDimitry Andric constexpr uptr SizeOrUnusedBytesMask = (1UL << 20) - 1; 840b57cec5SDimitry Andric constexpr uptr OffsetMask = (1UL << 16) - 1; 8568d75effSDimitry Andric constexpr uptr ChecksumMask = (1UL << 16) - 1; 860b57cec5SDimitry Andric 870b57cec5SDimitry Andric constexpr uptr getHeaderSize() { 880b57cec5SDimitry Andric return roundUpTo(sizeof(PackedHeader), 1U << SCUDO_MIN_ALIGNMENT_LOG); 890b57cec5SDimitry Andric } 900b57cec5SDimitry Andric 91480093f4SDimitry Andric inline AtomicPackedHeader *getAtomicHeader(void *Ptr) { 920b57cec5SDimitry Andric return reinterpret_cast<AtomicPackedHeader *>(reinterpret_cast<uptr>(Ptr) - 930b57cec5SDimitry Andric getHeaderSize()); 940b57cec5SDimitry Andric } 950b57cec5SDimitry Andric 96480093f4SDimitry Andric inline const AtomicPackedHeader *getConstAtomicHeader(const void *Ptr) { 970b57cec5SDimitry Andric return reinterpret_cast<const AtomicPackedHeader *>( 980b57cec5SDimitry Andric reinterpret_cast<uptr>(Ptr) - getHeaderSize()); 990b57cec5SDimitry Andric } 1000b57cec5SDimitry Andric 1010b57cec5SDimitry Andric // We do not need a cryptographically strong hash for the checksum, but a CRC 1020b57cec5SDimitry Andric // type function that can alert us in the event a header is invalid or 1030b57cec5SDimitry Andric // corrupted. Ideally slightly better than a simple xor of all fields. 104480093f4SDimitry Andric static inline u16 computeHeaderChecksum(u32 Cookie, const void *Ptr, 1050b57cec5SDimitry Andric UnpackedHeader *Header) { 1060b57cec5SDimitry Andric UnpackedHeader ZeroChecksumHeader = *Header; 1070b57cec5SDimitry Andric ZeroChecksumHeader.Checksum = 0; 1080b57cec5SDimitry Andric uptr HeaderHolder[sizeof(UnpackedHeader) / sizeof(uptr)]; 1090b57cec5SDimitry Andric memcpy(&HeaderHolder, &ZeroChecksumHeader, sizeof(HeaderHolder)); 1100b57cec5SDimitry Andric return computeChecksum(Cookie, reinterpret_cast<uptr>(Ptr), HeaderHolder, 1110b57cec5SDimitry Andric ARRAY_SIZE(HeaderHolder)); 1120b57cec5SDimitry Andric } 1130b57cec5SDimitry Andric 114480093f4SDimitry Andric inline void storeHeader(u32 Cookie, void *Ptr, 1150b57cec5SDimitry Andric UnpackedHeader *NewUnpackedHeader) { 1160b57cec5SDimitry Andric NewUnpackedHeader->Checksum = 1170b57cec5SDimitry Andric computeHeaderChecksum(Cookie, Ptr, NewUnpackedHeader); 1180b57cec5SDimitry Andric PackedHeader NewPackedHeader = bit_cast<PackedHeader>(*NewUnpackedHeader); 1190b57cec5SDimitry Andric atomic_store_relaxed(getAtomicHeader(Ptr), NewPackedHeader); 1200b57cec5SDimitry Andric } 1210b57cec5SDimitry Andric 122480093f4SDimitry Andric inline void loadHeader(u32 Cookie, const void *Ptr, 1230b57cec5SDimitry Andric UnpackedHeader *NewUnpackedHeader) { 1240b57cec5SDimitry Andric PackedHeader NewPackedHeader = atomic_load_relaxed(getConstAtomicHeader(Ptr)); 1250b57cec5SDimitry Andric *NewUnpackedHeader = bit_cast<UnpackedHeader>(NewPackedHeader); 1260b57cec5SDimitry Andric if (UNLIKELY(NewUnpackedHeader->Checksum != 1270b57cec5SDimitry Andric computeHeaderChecksum(Cookie, Ptr, NewUnpackedHeader))) 1280b57cec5SDimitry Andric reportHeaderCorruption(const_cast<void *>(Ptr)); 1290b57cec5SDimitry Andric } 1300b57cec5SDimitry Andric 131480093f4SDimitry Andric inline void compareExchangeHeader(u32 Cookie, void *Ptr, 1320b57cec5SDimitry Andric UnpackedHeader *NewUnpackedHeader, 1330b57cec5SDimitry Andric UnpackedHeader *OldUnpackedHeader) { 1340b57cec5SDimitry Andric NewUnpackedHeader->Checksum = 1350b57cec5SDimitry Andric computeHeaderChecksum(Cookie, Ptr, NewUnpackedHeader); 1360b57cec5SDimitry Andric PackedHeader NewPackedHeader = bit_cast<PackedHeader>(*NewUnpackedHeader); 1370b57cec5SDimitry Andric PackedHeader OldPackedHeader = bit_cast<PackedHeader>(*OldUnpackedHeader); 1380b57cec5SDimitry Andric if (UNLIKELY(!atomic_compare_exchange_strong( 1390b57cec5SDimitry Andric getAtomicHeader(Ptr), &OldPackedHeader, NewPackedHeader, 1400b57cec5SDimitry Andric memory_order_relaxed))) 1410b57cec5SDimitry Andric reportHeaderRace(Ptr); 1420b57cec5SDimitry Andric } 1430b57cec5SDimitry Andric 144480093f4SDimitry Andric inline bool isValid(u32 Cookie, const void *Ptr, 145480093f4SDimitry Andric UnpackedHeader *NewUnpackedHeader) { 1460b57cec5SDimitry Andric PackedHeader NewPackedHeader = atomic_load_relaxed(getConstAtomicHeader(Ptr)); 1470b57cec5SDimitry Andric *NewUnpackedHeader = bit_cast<UnpackedHeader>(NewPackedHeader); 1480b57cec5SDimitry Andric return NewUnpackedHeader->Checksum == 1490b57cec5SDimitry Andric computeHeaderChecksum(Cookie, Ptr, NewUnpackedHeader); 1500b57cec5SDimitry Andric } 1510b57cec5SDimitry Andric 1520b57cec5SDimitry Andric } // namespace Chunk 1530b57cec5SDimitry Andric 1540b57cec5SDimitry Andric } // namespace scudo 1550b57cec5SDimitry Andric 1560b57cec5SDimitry Andric #endif // SCUDO_CHUNK_H_ 157