asan_mac.cc revision 5af39e50366f1aacbebc284f572f08ad1ad07357
11e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany//===-- asan_mac.cc -------------------------------------------------------===// 21e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 31e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// The LLVM Compiler Infrastructure 41e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 51e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// This file is distributed under the University of Illinois Open Source 61e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// License. See LICENSE.TXT for details. 71e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 81e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany//===----------------------------------------------------------------------===// 91e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 101e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// This file is a part of AddressSanitizer, an address sanity checker. 111e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 121e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// Mac-specific details. 131e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany//===----------------------------------------------------------------------===// 141e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 15d6567c5166412f6acdde851e767c26f332d51d3dKostya Serebryany#ifdef __APPLE__ 161e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 1764ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov#include "asan_interceptors.h" 181e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany#include "asan_internal.h" 19d079db6dfbf3b0ec5fa1cc8d093e0dae6f970bf8Alexander Potapenko#include "asan_mac.h" 20895b3872acb5bcccb1769ea69d37dd33c722f99dAlexander Potapenko#include "asan_mapping.h" 211e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany#include "asan_stack.h" 221e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany#include "asan_thread.h" 231e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany#include "asan_thread_registry.h" 24ae4d9caa4f47fa6abcd641719e9f520622940c17Alexey Samsonov#include "sanitizer_common/sanitizer_libc.h" 251e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 26eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko#include <crt_externs.h> // for _NSGetArgv 27eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko#include <dlfcn.h> // for dladdr() 288a34d384255f9bf4c2a9b03a4df81b9af57124d8Alexander Potapenko#include <mach-o/dyld.h> 299b993e8cd0f8964782ee93524603d0c53adc2249Kostya Serebryany#include <mach-o/loader.h> 301e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany#include <sys/mman.h> 31ef14ff6512d7b2e20aa3206dff820b5f90285420Kostya Serebryany#include <sys/resource.h> 3259dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko#include <sys/sysctl.h> 339107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany#include <sys/ucontext.h> 34a874fe5b5d67152e4e737498d532eec80940bdcdKostya Serebryany#include <fcntl.h> 35e205a9daec9ec4afed956cf5455889725b9192fbAlexander Potapenko#include <pthread.h> 36e205a9daec9ec4afed956cf5455889725b9192fbAlexander Potapenko#include <stdlib.h> // for free() 371e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany#include <unistd.h> 38d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany#include <libkern/OSAtomic.h> 3964ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov#include <CoreFoundation/CFString.h> 401e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 411e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanynamespace __asan { 421e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 433f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryanyvoid GetPcSpBp(void *context, uptr *pc, uptr *sp, uptr *bp) { 449107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany ucontext_t *ucontext = (ucontext_t*)context; 455af39e50366f1aacbebc284f572f08ad1ad07357Kostya Serebryany# if SANITIZER_WORDSIZE == 64 469107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany *pc = ucontext->uc_mcontext->__ss.__rip; 479107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany *bp = ucontext->uc_mcontext->__ss.__rbp; 489107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany *sp = ucontext->uc_mcontext->__ss.__rsp; 499107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany# else 509107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany *pc = ucontext->uc_mcontext->__ss.__eip; 519107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany *bp = ucontext->uc_mcontext->__ss.__ebp; 529107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany *sp = ucontext->uc_mcontext->__ss.__esp; 535af39e50366f1aacbebc284f572f08ad1ad07357Kostya Serebryany# endif // SANITIZER_WORDSIZE 549107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany} 559107c26bd88fc9cf44a2cd7d6967eb830ac63be3Kostya Serebryany 56d079db6dfbf3b0ec5fa1cc8d093e0dae6f970bf8Alexander Potapenkoint GetMacosVersion() { 5759dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko int mib[2] = { CTL_KERN, KERN_OSRELEASE }; 5859dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko char version[100]; 593f46cf42b0f8e0667a3bea88cf871ebd4dc0ecdfAlexey Samsonov uptr len = 0, maxlen = sizeof(version) / sizeof(version[0]); 60b0bb7fb31301ee9ac9cf41f21d3a19987dc30609Alexey Samsonov for (uptr i = 0; i < maxlen; i++) version[i] = '\0'; 6159dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko // Get the version length. 623f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryany CHECK(sysctl(mib, 2, 0, &len, 0, 0) != -1); 6359dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko CHECK(len < maxlen); 643f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryany CHECK(sysctl(mib, 2, version, &len, 0, 0) != -1); 6559dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko switch (version[0]) { 6659dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko case '9': return MACOS_VERSION_LEOPARD; 6759dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko case '1': { 6859dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko switch (version[1]) { 6959dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko case '0': return MACOS_VERSION_SNOW_LEOPARD; 7059dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko case '1': return MACOS_VERSION_LION; 71679bf63dba568611bf1fe6397fd0c41d43ac041aAlexander Potapenko case '2': return MACOS_VERSION_MOUNTAIN_LION; 7259dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko default: return MACOS_VERSION_UNKNOWN; 7359dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko } 7459dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko } 7559dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko default: return MACOS_VERSION_UNKNOWN; 7659dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko } 7759dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko} 7859dc578df0de177b44c8c78f69d73735e38e5c14Alexander Potapenko 7938dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonovbool PlatformHasDifferentMemcpyAndMemmove() { 8038dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov // On OS X 10.7 memcpy() and memmove() are both resolved 8138dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov // into memmove$VARIANT$sse42. 8238dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov // See also http://code.google.com/p/address-sanitizer/issues/detail?id=34. 8338dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov // TODO(glider): need to check dynamically that memcpy() and memmove() are 8438dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov // actually the same function. 8538dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov return GetMacosVersion() == MACOS_VERSION_SNOW_LEOPARD; 8638dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov} 8738dd4ed885e714c376466f6fe0d69f5f22d37014Alexey Samsonov 88eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenkoextern "C" 89eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenkovoid __asan_init(); 90eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko 91eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenkostatic const char kDyldInsertLibraries[] = "DYLD_INSERT_LIBRARIES"; 92eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko 93eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenkovoid MaybeReexec() { 94eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko if (!flags()->allow_reexec) return; 95eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko#if MAC_INTERPOSE_FUNCTIONS 96eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // If the program is linked with the dynamic ASan runtime library, make sure 97eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // the library is preloaded so that the wrappers work. If it is not, set 98eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // DYLD_INSERT_LIBRARIES and re-exec ourselves. 99eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko Dl_info info; 1004ea14c2fa243684e1d7a017bd4f0d1e38801de0aAlexey Samsonov CHECK(dladdr((void*)((uptr)__asan_init), &info)); 101eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko const char *dyld_insert_libraries = GetEnv(kDyldInsertLibraries); 102eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko if (!dyld_insert_libraries || 103eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko !REAL(strstr)(dyld_insert_libraries, info.dli_fname)) { 104eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // DYLD_INSERT_LIBRARIES is not set or does not contain the runtime 105eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // library. 106eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko char program_name[1024]; 107eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko uint32_t buf_size = sizeof(program_name); 108eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko _NSGetExecutablePath(program_name, &buf_size); 109eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // Ok to use setenv() since the wrappers don't depend on the value of 110eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // asan_inited. 111eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko setenv(kDyldInsertLibraries, info.dli_fname, /*overwrite*/0); 112eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko if (flags()->verbosity >= 1) { 113eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko Report("exec()-ing the program with\n"); 114eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko Report("%s=%s\n", kDyldInsertLibraries, info.dli_fname); 115eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko Report("to enable ASan wrappers.\n"); 116eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko Report("Set ASAN_OPTIONS=allow_reexec=0 to disable this.\n"); 117eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko } 118eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko execv(program_name, *_NSGetArgv()); 119eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko } 120eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko#endif // MAC_INTERPOSE_FUNCTIONS 121eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko // If we're not using the dynamic runtime, do nothing. 122eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko} 123eb8c46e419f4c6f01d1b1a0d1b96cc51a61ecbc3Alexander Potapenko 1241e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// No-op. Mac does not support static linkage anyway. 1251e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyvoid *AsanDoesNotSupportStaticLinkage() { 1263f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryany return 0; 1271e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 1281e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 1294803ab90ead451b55a5833f0fd38b10fd1fc83ebKostya Serebryanybool AsanInterceptsSignal(int signum) { 130cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov return (signum == SIGSEGV || signum == SIGBUS) && flags()->handle_segv; 1314803ab90ead451b55a5833f0fd38b10fd1fc83ebKostya Serebryany} 1324803ab90ead451b55a5833f0fd38b10fd1fc83ebKostya Serebryany 13375b19ebf25af204cf209d108997272822241d6daAlexander Potapenkovoid AsanPlatformThreadInit() { 134e0c94cc6b2f84d3895ad7214cb8a830a9b9ff0c0Alexander Potapenko // For the first program thread, we can't replace the allocator before 135e0c94cc6b2f84d3895ad7214cb8a830a9b9ff0c0Alexander Potapenko // __CFInitialize() has been called. If it hasn't, we'll call 136ec3a5a21fd261f5227b5ad0d76bc148c6d227297Alexander Potapenko // MaybeReplaceCFAllocator() later on this thread. 137e0c94cc6b2f84d3895ad7214cb8a830a9b9ff0c0Alexander Potapenko // For other threads __CFInitialize() has been called before their creation. 138e0c94cc6b2f84d3895ad7214cb8a830a9b9ff0c0Alexander Potapenko // See also asan_malloc_mac.cc. 139e0c94cc6b2f84d3895ad7214cb8a830a9b9ff0c0Alexander Potapenko if (((CFRuntimeBase*)kCFAllocatorSystemDefault)->_cfisa) { 140ec3a5a21fd261f5227b5ad0d76bc148c6d227297Alexander Potapenko MaybeReplaceCFAllocator(); 141e0c94cc6b2f84d3895ad7214cb8a830a9b9ff0c0Alexander Potapenko } 14275b19ebf25af204cf209d108997272822241d6daAlexander Potapenko} 14375b19ebf25af204cf209d108997272822241d6daAlexander Potapenko 144d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya SerebryanyAsanLock::AsanLock(LinkerInitialized) { 145d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany // We assume that OS_SPINLOCK_INIT is zero 146d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany} 147d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany 148d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryanyvoid AsanLock::Lock() { 149d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany CHECK(sizeof(OSSpinLock) <= sizeof(opaque_storage_)); 150d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany CHECK(OS_SPINLOCK_INIT == 0); 1513f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryany CHECK(owner_ != (uptr)pthread_self()); 152d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany OSSpinLockLock((OSSpinLock*)&opaque_storage_); 153d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany CHECK(!owner_); 1543f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryany owner_ = (uptr)pthread_self(); 155d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany} 156d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany 157d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryanyvoid AsanLock::Unlock() { 1583f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryany CHECK(owner_ == (uptr)pthread_self()); 159d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany owner_ = 0; 160d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany OSSpinLockUnlock((OSSpinLock*)&opaque_storage_); 161d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany} 162d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany 1632b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryanyvoid GetStackTrace(StackTrace *stack, uptr max_s, uptr pc, uptr bp) { 1642b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryany stack->size = 0; 1652b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryany stack->trace[0] = pc; 1669cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov if ((max_s) > 1) { 1672b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryany stack->max_size = max_s; 1682b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryany if (!asan_inited) return; 1692b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryany if (AsanThread *t = asanThreadRegistry().GetCurrent()) 1702b939c3abc8b7713ef28000bd768ca6d77445f45Kostya Serebryany stack->FastUnwindStack(pc, bp, t->stack_top(), t->stack_bottom()); 1719cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov } 1729cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov} 1739cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov 1745b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov// The range of pages to be used for escape islands. 1753281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko// TODO(glider): instead of mapping a fixed range we must find a range of 1763281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko// unmapped pages in vmmap and take them. 1771346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko// These constants were chosen empirically and may not work if the shadow 1781346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko// memory layout changes. Unfortunately they do necessarily depend on 1791346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko// kHighMemBeg or kHighMemEnd. 1803f4c3875c42078e22c7e5356c5746fd18756d958Kostya Serebryanystatic void *island_allocator_pos = 0; 1815b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov 1825af39e50366f1aacbebc284f572f08ad1ad07357Kostya Serebryany#if SANITIZER_WORDSIZE == 32 1835b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov# define kIslandEnd (0xffdf0000 - kPageSize) 1845b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov# define kIslandBeg (kIslandEnd - 256 * kPageSize) 1851346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko#else 1865b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov# define kIslandEnd (0x7fffffdf0000 - kPageSize) 1875b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov# define kIslandBeg (kIslandEnd - 256 * kPageSize) 1881346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko#endif 1893281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko 1903281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenkoextern "C" 1915b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonovmach_error_t __interception_allocate_island(void **ptr, 1923f46cf42b0f8e0667a3bea88cf871ebd4dc0ecdfAlexey Samsonov uptr unused_size, 1935b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonov void *unused_hint) { 1943281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko if (!island_allocator_pos) { 1951346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko island_allocator_pos = 196ae4d9caa4f47fa6abcd641719e9f520622940c17Alexey Samsonov internal_mmap((void*)kIslandBeg, kIslandEnd - kIslandBeg, 197ae4d9caa4f47fa6abcd641719e9f520622940c17Alexey Samsonov PROT_READ | PROT_WRITE | PROT_EXEC, 198ae4d9caa4f47fa6abcd641719e9f520622940c17Alexey Samsonov MAP_PRIVATE | MAP_ANON | MAP_FIXED, 199ae4d9caa4f47fa6abcd641719e9f520622940c17Alexey Samsonov -1, 0); 2001346ced2eb8d10305e8d98496d9006cfbbad1548Alexander Potapenko if (island_allocator_pos != (void*)kIslandBeg) { 2013281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko return KERN_NO_SPACE; 2023281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko } 203cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity) { 204ebb9702cff96192c6a6ea963037929ca7ed60eaeAlexander Potapenko Report("Mapped pages %p--%p for branch islands.\n", 205675293d458c9f6c797a7211c11438eb9bfcfe9bbAlexey Samsonov (void*)kIslandBeg, (void*)kIslandEnd); 206ebb9702cff96192c6a6ea963037929ca7ed60eaeAlexander Potapenko } 207ebb9702cff96192c6a6ea963037929ca7ed60eaeAlexander Potapenko // Should not be very performance-critical. 208ebb9702cff96192c6a6ea963037929ca7ed60eaeAlexander Potapenko internal_memset(island_allocator_pos, 0xCC, kIslandEnd - kIslandBeg); 2093281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko }; 2103281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko *ptr = island_allocator_pos; 2113281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko island_allocator_pos = (char*)island_allocator_pos + kPageSize; 212cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity) { 213ebb9702cff96192c6a6ea963037929ca7ed60eaeAlexander Potapenko Report("Branch island allocated at %p\n", *ptr); 214ebb9702cff96192c6a6ea963037929ca7ed60eaeAlexander Potapenko } 2153281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko return err_none; 2163281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko} 2173281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko 2183281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenkoextern "C" 2195b29018cf422e7711fb760b733c32127397a43fcAlexey Samsonovmach_error_t __interception_deallocate_island(void *ptr) { 2203281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko // Do nothing. 2213281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko // TODO(glider): allow to free and reuse the island memory. 2223281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko return err_none; 2233281209790b5e543c79acb2f5008d1df77fb76d9Alexander Potapenko} 224d55f5f8c413622db4bd28b5cca9bfeb4d61564e0Kostya Serebryany 2251e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// Support for the following functions from libdispatch on Mac OS: 2261e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_async_f() 2271e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_async() 2281e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_sync_f() 2291e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_sync() 2301e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_after_f() 2311e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_after() 2321e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_group_async_f() 2331e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_group_async() 2341e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// TODO(glider): libdispatch API contains other functions that we don't support 2351e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// yet. 2361e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 2371e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_sync() and dispatch_sync_f() are synchronous, although chances are 2381e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// they can cause jobs to run on a thread different from the current one. 2391e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// TODO(glider): if so, we need a test for this (otherwise we should remove 2401e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// them). 2411e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 2421e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// The following functions use dispatch_barrier_async_f() (which isn't a library 2431e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// function but is exported) and are thus supported: 2441e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_source_set_cancel_handler_f() 2451e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_source_set_cancel_handler() 2461e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_source_set_event_handler_f() 2471e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// dispatch_source_set_event_handler() 2481e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// 2491e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// The reference manual for Grand Central Dispatch is available at 2501e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// http://developer.apple.com/library/mac/#documentation/Performance/Reference/GCD_libdispatch_Ref/Reference/reference.html 2511e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// The implementation details are at 2521e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// http://libdispatch.macosforge.org/trac/browser/trunk/src/queue.c 2531e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 2545cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovtypedef void* pthread_workqueue_t; 2555cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovtypedef void* pthread_workitem_handle_t; 256f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov 257f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovtypedef void* dispatch_group_t; 258f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovtypedef void* dispatch_queue_t; 259af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkotypedef void* dispatch_source_t; 260ee3925515e4c7966f3ef489f687aa7e5692806a9Kostya Serebryanytypedef u64 dispatch_time_t; 261f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovtypedef void (*dispatch_function_t)(void *block); 2625cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovtypedef void* (*worker_t)(void *block); 2635cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov 2645cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov// A wrapper for the ObjC blocks used to support libdispatch. 2655cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovtypedef struct { 2665cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov void *block; 2675cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov dispatch_function_t func; 268e0cff0bc20ae51790c8edfbceb817e18ebf5355eKostya Serebryany u32 parent_tid; 2695cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov} asan_block_context_t; 2705cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov 271f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov// We use extern declarations of libdispatch functions here instead 272f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov// of including <dispatch/dispatch.h>. This header is not present on 273f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov// Mac OS X Leopard and eariler, and although we don't expect ASan to 274f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov// work on legacy systems, it's bad to break the build of 275f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov// LLVM compiler-rt there. 2765cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovextern "C" { 277f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovvoid dispatch_async_f(dispatch_queue_t dq, void *ctxt, 278f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov dispatch_function_t func); 279f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovvoid dispatch_sync_f(dispatch_queue_t dq, void *ctxt, 280f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov dispatch_function_t func); 281f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovvoid dispatch_after_f(dispatch_time_t when, dispatch_queue_t dq, void *ctxt, 282f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov dispatch_function_t func); 2835cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovvoid dispatch_barrier_async_f(dispatch_queue_t dq, void *ctxt, 2845cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov dispatch_function_t func); 285f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonovvoid dispatch_group_async_f(dispatch_group_t group, dispatch_queue_t dq, 286f7ceaad2919d2e26e9edea29232bc9dd8f145c42Alexey Samsonov void *ctxt, dispatch_function_t func); 2875cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonovint pthread_workqueue_additem_np(pthread_workqueue_t workq, 2885cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov void *(*workitem_func)(void *), void * workitem_arg, 2895cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov pthread_workitem_handle_t * itemhandlep, unsigned int *gencountp); 2905cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov} // extern "C" 2915cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov 292af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkostatic ALWAYS_INLINE 293c3390df6670cb166119b961eb27a033fb9073496Kostya Serebryanyvoid asan_register_worker_thread(int parent_tid, StackTrace *stack) { 294af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko AsanThread *t = asanThreadRegistry().GetCurrent(); 295af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko if (!t) { 296af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko t = AsanThread::Create(parent_tid, 0, 0, stack); 297af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asanThreadRegistry().RegisterThread(t); 298af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko t->Init(); 299af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asanThreadRegistry().SetCurrent(t); 300af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko } 301af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko} 302af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko 3032483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko// For use by only those functions that allocated the context via 3042483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko// alloc_asan_context(). 3051e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyextern "C" 3061e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyvoid asan_dispatch_call_block_and_release(void *block) { 3079cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov GET_STACK_TRACE_HERE(kStackTraceMax); 3081e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_block_context_t *context = (asan_block_context_t*)block; 309cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity >= 2) { 3101e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany Report("asan_dispatch_call_block_and_release(): " 3111e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany "context: %p, pthread_self: %p\n", 3121e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany block, pthread_self()); 3131e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany } 314af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asan_register_worker_thread(context->parent_tid, &stack); 3151e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany // Call the original dispatcher for the block. 3161e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany context->func(context->block); 3171e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_free(context, &stack); 3181e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 3191e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 3201e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} // namespace __asan 3211e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 3221e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyusing namespace __asan; // NOLINT 3231e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 3241e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// Wrap |ctxt| and |func| into an asan_block_context_t. 3251e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// The caller retains control of the allocated context. 3261e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyextern "C" 3271e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyasan_block_context_t *alloc_asan_context(void *ctxt, dispatch_function_t func, 328c3390df6670cb166119b961eb27a033fb9073496Kostya Serebryany StackTrace *stack) { 3291e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_block_context_t *asan_ctxt = 3301e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany (asan_block_context_t*) asan_malloc(sizeof(asan_block_context_t), stack); 3311e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_ctxt->block = ctxt; 3321e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_ctxt->func = func; 333e0cff0bc20ae51790c8edfbceb817e18ebf5355eKostya Serebryany asan_ctxt->parent_tid = asanThreadRegistry().GetCurrentTidOrInvalid(); 3341e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany return asan_ctxt; 3351e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 3361e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 337b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko// Define interceptor for dispatch_*_f function with the three most common 338b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko// parameters: dispatch_queue_t, context, dispatch_function_t. 339b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko#define INTERCEPT_DISPATCH_X_F_3(dispatch_x_f) \ 340b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko INTERCEPTOR(void, dispatch_x_f, dispatch_queue_t dq, void *ctxt, \ 341b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko dispatch_function_t func) { \ 342b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko GET_STACK_TRACE_HERE(kStackTraceMax); \ 343b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko asan_block_context_t *asan_ctxt = alloc_asan_context(ctxt, func, &stack); \ 344b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko if (flags()->verbosity >= 2) { \ 345b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko Report(#dispatch_x_f "(): context: %p, pthread_self: %p\n", \ 346b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko asan_ctxt, pthread_self()); \ 347b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko PRINT_CURRENT_STACK(); \ 348b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko } \ 349b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko return REAL(dispatch_x_f)(dq, (void*)asan_ctxt, \ 350b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko asan_dispatch_call_block_and_release); \ 3510ffc227f91b068c78908f735a4846f92e339a337Kostya Serebryany } 352b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander Potapenko 353b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander PotapenkoINTERCEPT_DISPATCH_X_F_3(dispatch_async_f) 354b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander PotapenkoINTERCEPT_DISPATCH_X_F_3(dispatch_sync_f) 355b09dd34786713a150fed5c5ab1529f01de0e2bc0Alexander PotapenkoINTERCEPT_DISPATCH_X_F_3(dispatch_barrier_async_f) 3561e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 357f2598fc21bf651d23feab396a7581d48c01c3be5Alexey SamsonovINTERCEPTOR(void, dispatch_after_f, dispatch_time_t when, 358f2598fc21bf651d23feab396a7581d48c01c3be5Alexey Samsonov dispatch_queue_t dq, void *ctxt, 359f2598fc21bf651d23feab396a7581d48c01c3be5Alexey Samsonov dispatch_function_t func) { 3609cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov GET_STACK_TRACE_HERE(kStackTraceMax); 3611e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_block_context_t *asan_ctxt = alloc_asan_context(ctxt, func, &stack); 362cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity >= 2) { 3631e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany Report("dispatch_after_f: %p\n", asan_ctxt); 3641e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany PRINT_CURRENT_STACK(); 3651e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany } 36609672caefb5694f1981a1712fdefa44840a95e67Alexey Samsonov return REAL(dispatch_after_f)(when, dq, (void*)asan_ctxt, 36709672caefb5694f1981a1712fdefa44840a95e67Alexey Samsonov asan_dispatch_call_block_and_release); 3681e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 3691e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 370af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander PotapenkoINTERCEPTOR(void, dispatch_group_async_f, dispatch_group_t group, 371af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_queue_t dq, void *ctxt, 372af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_function_t func) { 373af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_STACK_TRACE_HERE(kStackTraceMax); 374af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asan_block_context_t *asan_ctxt = alloc_asan_context(ctxt, func, &stack); 375af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko if (flags()->verbosity >= 2) { 376af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko Report("dispatch_group_async_f(): context: %p, pthread_self: %p\n", 377af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asan_ctxt, pthread_self()); 378af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko PRINT_CURRENT_STACK(); 379af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko } 380af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko REAL(dispatch_group_async_f)(group, dq, (void*)asan_ctxt, 381af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asan_dispatch_call_block_and_release); 382af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko} 383af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko 3842483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko#if MAC_INTERPOSE_FUNCTIONS 385af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko// dispatch_async, dispatch_group_async and others tailcall the corresponding 386af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko// dispatch_*_f functions. When wrapping functions with mach_override, those 387af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko// dispatch_*_f are intercepted automatically. But with dylib interposition 388af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko// this does not work, because the calls within the same library are not 389af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko// interposed. 3902483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko// Therefore we need to re-implement dispatch_async and friends. 3912483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko 392af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkoextern "C" { 393af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko// FIXME: consolidate these declarations with asan_intercepted_functions.h. 394af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkovoid dispatch_async(dispatch_queue_t dq, void(^work)(void)); 395af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkovoid dispatch_group_async(dispatch_group_t dg, dispatch_queue_t dq, 396af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko void(^work)(void)); 397af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkovoid dispatch_after(dispatch_time_t when, dispatch_queue_t queue, 398af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko void(^work)(void)); 399af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkovoid dispatch_source_set_cancel_handler(dispatch_source_t ds, 400af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko void(^work)(void)); 401af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenkovoid dispatch_source_set_event_handler(dispatch_source_t ds, void(^work)(void)); 4022483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko} 4032483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko 404af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko#define GET_ASAN_BLOCK(work) \ 405af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko void (^asan_block)(void); \ 406af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko int parent_tid = asanThreadRegistry().GetCurrentTidOrInvalid(); \ 407af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asan_block = ^(void) { \ 408af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_STACK_TRACE_HERE(kStackTraceMax); \ 409af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko asan_register_worker_thread(parent_tid, &stack); \ 410af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko work(); \ 4112483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko } 4122483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko 4132483ce3e635515d907c0cd8c97db315142fb28dbAlexander PotapenkoINTERCEPTOR(void, dispatch_async, 414af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_queue_t dq, void(^work)(void)) { 415af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_ASAN_BLOCK(work); 416af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko REAL(dispatch_async)(dq, asan_block); 417af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko} 418af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko 419af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander PotapenkoINTERCEPTOR(void, dispatch_group_async, 420af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_group_t dg, dispatch_queue_t dq, void(^work)(void)) { 421af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_ASAN_BLOCK(work); 422af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko REAL(dispatch_group_async)(dg, dq, asan_block); 4232483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko} 4242483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko 4252483ce3e635515d907c0cd8c97db315142fb28dbAlexander PotapenkoINTERCEPTOR(void, dispatch_after, 426af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_time_t when, dispatch_queue_t queue, void(^work)(void)) { 427af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_ASAN_BLOCK(work); 428af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko REAL(dispatch_after)(when, queue, asan_block); 4292483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko} 4302483ce3e635515d907c0cd8c97db315142fb28dbAlexander Potapenko 431af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander PotapenkoINTERCEPTOR(void, dispatch_source_set_cancel_handler, 432af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_source_t ds, void(^work)(void)) { 433af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_ASAN_BLOCK(work); 434af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko REAL(dispatch_source_set_cancel_handler)(ds, asan_block); 4351e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 4361e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 437af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander PotapenkoINTERCEPTOR(void, dispatch_source_set_event_handler, 438af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko dispatch_source_t ds, void(^work)(void)) { 439af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko GET_ASAN_BLOCK(work); 440af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko REAL(dispatch_source_set_event_handler)(ds, asan_block); 441af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko} 442af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko#endif 443af198e421ea198c5f9fa8cd691aa9a209b3d96a0Alexander Potapenko 4441e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// The following stuff has been extremely helpful while looking for the 4451e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// unhandled functions that spawned jobs on Chromium shutdown. If the verbosity 4461e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// level is 2 or greater, we wrap pthread_workqueue_additem_np() in order to 4471e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// find the points of worker thread creation (each of such threads may be used 4481e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// to run several tasks, that's why this is not enough to support the whole 4491e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany// libdispatch API. 4501e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyextern "C" 4511e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryanyvoid *wrap_workitem_func(void *arg) { 452cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity >= 2) { 4531e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany Report("wrap_workitem_func: %p, pthread_self: %p\n", arg, pthread_self()); 4541e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany } 4551e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_block_context_t *ctxt = (asan_block_context_t*)arg; 4561e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany worker_t fn = (worker_t)(ctxt->func); 4571e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany void *result = fn(ctxt->block); 4589cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov GET_STACK_TRACE_HERE(kStackTraceMax); 4591e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_free(arg, &stack); 4601e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany return result; 4611e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 4621e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany 463f2598fc21bf651d23feab396a7581d48c01c3be5Alexey SamsonovINTERCEPTOR(int, pthread_workqueue_additem_np, pthread_workqueue_t workq, 4641e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany void *(*workitem_func)(void *), void * workitem_arg, 4651e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany pthread_workitem_handle_t * itemhandlep, unsigned int *gencountp) { 4669cfa194cc62026fc7c6e82f7303eee8ad4d10cf4Evgeniy Stepanov GET_STACK_TRACE_HERE(kStackTraceMax); 4671e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_block_context_t *asan_ctxt = 4681e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany (asan_block_context_t*) asan_malloc(sizeof(asan_block_context_t), &stack); 4691e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_ctxt->block = workitem_arg; 4701e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany asan_ctxt->func = (dispatch_function_t)workitem_func; 471e0cff0bc20ae51790c8edfbceb817e18ebf5355eKostya Serebryany asan_ctxt->parent_tid = asanThreadRegistry().GetCurrentTidOrInvalid(); 472cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity >= 2) { 4731e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany Report("pthread_workqueue_additem_np: %p\n", asan_ctxt); 4741e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany PRINT_CURRENT_STACK(); 4751e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany } 47609672caefb5694f1981a1712fdefa44840a95e67Alexey Samsonov return REAL(pthread_workqueue_additem_np)(workq, wrap_workitem_func, 47709672caefb5694f1981a1712fdefa44840a95e67Alexey Samsonov asan_ctxt, itemhandlep, 47809672caefb5694f1981a1712fdefa44840a95e67Alexey Samsonov gencountp); 4791e172b4bdec57329bf904f063a29f99cddf2d85fKostya Serebryany} 480d6567c5166412f6acdde851e767c26f332d51d3dKostya Serebryany 481431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko// See http://opensource.apple.com/source/CF/CF-635.15/CFString.c 482431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenkoint __CFStrIsConstant(CFStringRef str) { 483431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko CFRuntimeBase *base = (CFRuntimeBase*)str; 484431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko#if __LP64__ 485431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko return base->_rc == 0; 486431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko#else 487431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko return (base->_cfinfo[CF_RC_BITS]) == 0; 488431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko#endif 489431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko} 490431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko 491f2598fc21bf651d23feab396a7581d48c01c3be5Alexey SamsonovINTERCEPTOR(CFStringRef, CFStringCreateCopy, CFAllocatorRef alloc, 492f2598fc21bf651d23feab396a7581d48c01c3be5Alexey Samsonov CFStringRef str) { 493431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko if (__CFStrIsConstant(str)) { 494431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko return str; 495431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko } else { 49609672caefb5694f1981a1712fdefa44840a95e67Alexey Samsonov return REAL(CFStringCreateCopy)(alloc, str); 497431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko } 498431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko} 499431e51782d62d1257348e41e24da6b544fe70507Alexander Potapenko 500decaec9ee3177b5e81e358ad8e93ab70b38a1cc0Alexander PotapenkoDECLARE_REAL_AND_INTERCEPTOR(void, free, void *ptr) 501decaec9ee3177b5e81e358ad8e93ab70b38a1cc0Alexander Potapenko 5024ea14c2fa243684e1d7a017bd4f0d1e38801de0aAlexey SamsonovDECLARE_REAL_AND_INTERCEPTOR(void, __CFInitialize, void) 503decaec9ee3177b5e81e358ad8e93ab70b38a1cc0Alexander Potapenko 50464ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonovnamespace __asan { 505beba6448539095b67cab266d09cd7b7d313b8c3dAlexey Samsonov 506beba6448539095b67cab266d09cd7b7d313b8c3dAlexey Samsonovvoid InitializeMacInterceptors() { 5075cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov CHECK(INTERCEPT_FUNCTION(dispatch_async_f)); 5085cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov CHECK(INTERCEPT_FUNCTION(dispatch_sync_f)); 5095cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov CHECK(INTERCEPT_FUNCTION(dispatch_after_f)); 5105cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov CHECK(INTERCEPT_FUNCTION(dispatch_barrier_async_f)); 5115cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov CHECK(INTERCEPT_FUNCTION(dispatch_group_async_f)); 5125cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov // We don't need to intercept pthread_workqueue_additem_np() to support the 5135cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov // libdispatch API, but it helps us to debug the unsupported functions. Let's 5145cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov // intercept it only during verbose runs. 515cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->verbosity >= 2) { 5165cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov CHECK(INTERCEPT_FUNCTION(pthread_workqueue_additem_np)); 5175cf832dc0a6566ae4bb8d48b1f41da623d2c2c1aAlexey Samsonov } 51864ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // Normally CFStringCreateCopy should not copy constant CF strings. 51964ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // Replacing the default CFAllocator causes constant strings to be copied 52064ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // rather than just returned, which leads to bugs in big applications like 52164ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // Chromium and WebKit, see 52264ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // http://code.google.com/p/address-sanitizer/issues/detail?id=10 52364ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // Until this problem is fixed we need to check that the string is 52464ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov // non-constant before calling CFStringCreateCopy. 52564ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov CHECK(INTERCEPT_FUNCTION(CFStringCreateCopy)); 526e205a9daec9ec4afed956cf5455889725b9192fbAlexander Potapenko // Some of the library functions call free() directly, so we have to 527e205a9daec9ec4afed956cf5455889725b9192fbAlexander Potapenko // intercept it. 528e205a9daec9ec4afed956cf5455889725b9192fbAlexander Potapenko CHECK(INTERCEPT_FUNCTION(free)); 529cb8c4dce691097718d5af41b36899b72ef4b1d84Alexey Samsonov if (flags()->replace_cfallocator) { 530decaec9ee3177b5e81e358ad8e93ab70b38a1cc0Alexander Potapenko CHECK(INTERCEPT_FUNCTION(__CFInitialize)); 531decaec9ee3177b5e81e358ad8e93ab70b38a1cc0Alexander Potapenko } 53264ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov} 533beba6448539095b67cab266d09cd7b7d313b8c3dAlexey Samsonov 53464ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov} // namespace __asan 53564ce2db7c838cd95315f7a4428e8a628eaa3e2fcAlexey Samsonov 536d6567c5166412f6acdde851e767c26f332d51d3dKostya Serebryany#endif // __APPLE__ 537