1 //===-- AddressSanitizer.cpp - memory error detector ------------*- C++ -*-===// 2 // 3 // The LLVM Compiler Infrastructure 4 // 5 // This file is distributed under the University of Illinois Open Source 6 // License. See LICENSE.TXT for details. 7 // 8 //===----------------------------------------------------------------------===// 9 // 10 // This file is a part of AddressSanitizer, an address sanity checker. 11 // Details of the algorithm: 12 // http://code.google.com/p/address-sanitizer/wiki/AddressSanitizerAlgorithm 13 // 14 //===----------------------------------------------------------------------===// 15 16 #include "llvm/Transforms/Instrumentation.h" 17 #include "llvm/ADT/ArrayRef.h" 18 #include "llvm/ADT/DenseMap.h" 19 #include "llvm/ADT/DepthFirstIterator.h" 20 #include "llvm/ADT/SmallSet.h" 21 #include "llvm/ADT/SmallString.h" 22 #include "llvm/ADT/SmallVector.h" 23 #include "llvm/ADT/Statistic.h" 24 #include "llvm/ADT/StringExtras.h" 25 #include "llvm/ADT/Triple.h" 26 #include "llvm/IR/CallSite.h" 27 #include "llvm/IR/DIBuilder.h" 28 #include "llvm/IR/DataLayout.h" 29 #include "llvm/IR/Function.h" 30 #include "llvm/IR/IRBuilder.h" 31 #include "llvm/IR/InlineAsm.h" 32 #include "llvm/IR/InstVisitor.h" 33 #include "llvm/IR/IntrinsicInst.h" 34 #include "llvm/IR/LLVMContext.h" 35 #include "llvm/IR/MDBuilder.h" 36 #include "llvm/IR/Module.h" 37 #include "llvm/IR/Type.h" 38 #include "llvm/Support/CommandLine.h" 39 #include "llvm/Support/DataTypes.h" 40 #include "llvm/Support/Debug.h" 41 #include "llvm/Support/Endian.h" 42 #include "llvm/Support/system_error.h" 43 #include "llvm/Transforms/Utils/ASanStackFrameLayout.h" 44 #include "llvm/Transforms/Utils/BasicBlockUtils.h" 45 #include "llvm/Transforms/Utils/Cloning.h" 46 #include "llvm/Transforms/Utils/Local.h" 47 #include "llvm/Transforms/Utils/ModuleUtils.h" 48 #include "llvm/Transforms/Utils/SpecialCaseList.h" 49 #include <algorithm> 50 #include <string> 51 52 using namespace llvm; 53 54 #define DEBUG_TYPE "asan" 55 56 static const uint64_t kDefaultShadowScale = 3; 57 static const uint64_t kDefaultShadowOffset32 = 1ULL << 29; 58 static const uint64_t kDefaultShadowOffset64 = 1ULL << 44; 59 static const uint64_t kSmallX86_64ShadowOffset = 0x7FFF8000; // < 2G. 60 static const uint64_t kPPC64_ShadowOffset64 = 1ULL << 41; 61 static const uint64_t kMIPS32_ShadowOffset32 = 0x0aaa8000; 62 static const uint64_t kFreeBSD_ShadowOffset32 = 1ULL << 30; 63 static const uint64_t kFreeBSD_ShadowOffset64 = 1ULL << 46; 64 65 static const size_t kMinStackMallocSize = 1 << 6; // 64B 66 static const size_t kMaxStackMallocSize = 1 << 16; // 64K 67 static const uintptr_t kCurrentStackFrameMagic = 0x41B58AB3; 68 static const uintptr_t kRetiredStackFrameMagic = 0x45E0360E; 69 70 static const char *const kAsanModuleCtorName = "asan.module_ctor"; 71 static const char *const kAsanModuleDtorName = "asan.module_dtor"; 72 static const int kAsanCtorAndCtorPriority = 1; 73 static const char *const kAsanReportErrorTemplate = "__asan_report_"; 74 static const char *const kAsanReportLoadN = "__asan_report_load_n"; 75 static const char *const kAsanReportStoreN = "__asan_report_store_n"; 76 static const char *const kAsanRegisterGlobalsName = "__asan_register_globals"; 77 static const char *const kAsanUnregisterGlobalsName = 78 "__asan_unregister_globals"; 79 static const char *const kAsanPoisonGlobalsName = "__asan_before_dynamic_init"; 80 static const char *const kAsanUnpoisonGlobalsName = "__asan_after_dynamic_init"; 81 static const char *const kAsanInitName = "__asan_init_v3"; 82 static const char *const kAsanCovName = "__sanitizer_cov"; 83 static const char *const kAsanPtrCmp = "__sanitizer_ptr_cmp"; 84 static const char *const kAsanPtrSub = "__sanitizer_ptr_sub"; 85 static const char *const kAsanHandleNoReturnName = "__asan_handle_no_return"; 86 static const int kMaxAsanStackMallocSizeClass = 10; 87 static const char *const kAsanStackMallocNameTemplate = "__asan_stack_malloc_"; 88 static const char *const kAsanStackFreeNameTemplate = "__asan_stack_free_"; 89 static const char *const kAsanGenPrefix = "__asan_gen_"; 90 static const char *const kAsanPoisonStackMemoryName = 91 "__asan_poison_stack_memory"; 92 static const char *const kAsanUnpoisonStackMemoryName = 93 "__asan_unpoison_stack_memory"; 94 95 static const char *const kAsanOptionDetectUAR = 96 "__asan_option_detect_stack_use_after_return"; 97 98 #ifndef NDEBUG 99 static const int kAsanStackAfterReturnMagic = 0xf5; 100 #endif 101 102 // Accesses sizes are powers of two: 1, 2, 4, 8, 16. 103 static const size_t kNumberOfAccessSizes = 5; 104 105 // Command-line flags. 106 107 // This flag may need to be replaced with -f[no-]asan-reads. 108 static cl::opt<bool> ClInstrumentReads("asan-instrument-reads", 109 cl::desc("instrument read instructions"), cl::Hidden, cl::init(true)); 110 static cl::opt<bool> ClInstrumentWrites("asan-instrument-writes", 111 cl::desc("instrument write instructions"), cl::Hidden, cl::init(true)); 112 static cl::opt<bool> ClInstrumentAtomics("asan-instrument-atomics", 113 cl::desc("instrument atomic instructions (rmw, cmpxchg)"), 114 cl::Hidden, cl::init(true)); 115 static cl::opt<bool> ClAlwaysSlowPath("asan-always-slow-path", 116 cl::desc("use instrumentation with slow path for all accesses"), 117 cl::Hidden, cl::init(false)); 118 // This flag limits the number of instructions to be instrumented 119 // in any given BB. Normally, this should be set to unlimited (INT_MAX), 120 // but due to http://llvm.org/bugs/show_bug.cgi?id=12652 we temporary 121 // set it to 10000. 122 static cl::opt<int> ClMaxInsnsToInstrumentPerBB("asan-max-ins-per-bb", 123 cl::init(10000), 124 cl::desc("maximal number of instructions to instrument in any given BB"), 125 cl::Hidden); 126 // This flag may need to be replaced with -f[no]asan-stack. 127 static cl::opt<bool> ClStack("asan-stack", 128 cl::desc("Handle stack memory"), cl::Hidden, cl::init(true)); 129 // This flag may need to be replaced with -f[no]asan-use-after-return. 130 static cl::opt<bool> ClUseAfterReturn("asan-use-after-return", 131 cl::desc("Check return-after-free"), cl::Hidden, cl::init(false)); 132 // This flag may need to be replaced with -f[no]asan-globals. 133 static cl::opt<bool> ClGlobals("asan-globals", 134 cl::desc("Handle global objects"), cl::Hidden, cl::init(true)); 135 static cl::opt<int> ClCoverage("asan-coverage", 136 cl::desc("ASan coverage. 0: none, 1: entry block, 2: all blocks"), 137 cl::Hidden, cl::init(false)); 138 static cl::opt<int> ClCoverageBlockThreshold("asan-coverage-block-threshold", 139 cl::desc("Add coverage instrumentation only to the entry block if there " 140 "are more than this number of blocks."), 141 cl::Hidden, cl::init(1500)); 142 static cl::opt<bool> ClInitializers("asan-initialization-order", 143 cl::desc("Handle C++ initializer order"), cl::Hidden, cl::init(false)); 144 static cl::opt<bool> ClInvalidPointerPairs("asan-detect-invalid-pointer-pair", 145 cl::desc("Instrument <, <=, >, >=, - with pointer operands"), 146 cl::Hidden, cl::init(false)); 147 static cl::opt<unsigned> ClRealignStack("asan-realign-stack", 148 cl::desc("Realign stack to the value of this flag (power of two)"), 149 cl::Hidden, cl::init(32)); 150 static cl::opt<std::string> ClBlacklistFile("asan-blacklist", 151 cl::desc("File containing the list of objects to ignore " 152 "during instrumentation"), cl::Hidden); 153 static cl::opt<int> ClInstrumentationWithCallsThreshold( 154 "asan-instrumentation-with-call-threshold", 155 cl::desc("If the function being instrumented contains more than " 156 "this number of memory accesses, use callbacks instead of " 157 "inline checks (-1 means never use callbacks)."), 158 cl::Hidden, cl::init(10000)); 159 static cl::opt<std::string> ClMemoryAccessCallbackPrefix( 160 "asan-memory-access-callback-prefix", 161 cl::desc("Prefix for memory access callbacks"), cl::Hidden, 162 cl::init("__asan_")); 163 164 // This is an experimental feature that will allow to choose between 165 // instrumented and non-instrumented code at link-time. 166 // If this option is on, just before instrumenting a function we create its 167 // clone; if the function is not changed by asan the clone is deleted. 168 // If we end up with a clone, we put the instrumented function into a section 169 // called "ASAN" and the uninstrumented function into a section called "NOASAN". 170 // 171 // This is still a prototype, we need to figure out a way to keep two copies of 172 // a function so that the linker can easily choose one of them. 173 static cl::opt<bool> ClKeepUninstrumented("asan-keep-uninstrumented-functions", 174 cl::desc("Keep uninstrumented copies of functions"), 175 cl::Hidden, cl::init(false)); 176 177 // These flags allow to change the shadow mapping. 178 // The shadow mapping looks like 179 // Shadow = (Mem >> scale) + (1 << offset_log) 180 static cl::opt<int> ClMappingScale("asan-mapping-scale", 181 cl::desc("scale of asan shadow mapping"), cl::Hidden, cl::init(0)); 182 183 // Optimization flags. Not user visible, used mostly for testing 184 // and benchmarking the tool. 185 static cl::opt<bool> ClOpt("asan-opt", 186 cl::desc("Optimize instrumentation"), cl::Hidden, cl::init(true)); 187 static cl::opt<bool> ClOptSameTemp("asan-opt-same-temp", 188 cl::desc("Instrument the same temp just once"), cl::Hidden, 189 cl::init(true)); 190 static cl::opt<bool> ClOptGlobals("asan-opt-globals", 191 cl::desc("Don't instrument scalar globals"), cl::Hidden, cl::init(true)); 192 193 static cl::opt<bool> ClCheckLifetime("asan-check-lifetime", 194 cl::desc("Use llvm.lifetime intrinsics to insert extra checks"), 195 cl::Hidden, cl::init(false)); 196 197 // Debug flags. 198 static cl::opt<int> ClDebug("asan-debug", cl::desc("debug"), cl::Hidden, 199 cl::init(0)); 200 static cl::opt<int> ClDebugStack("asan-debug-stack", cl::desc("debug stack"), 201 cl::Hidden, cl::init(0)); 202 static cl::opt<std::string> ClDebugFunc("asan-debug-func", 203 cl::Hidden, cl::desc("Debug func")); 204 static cl::opt<int> ClDebugMin("asan-debug-min", cl::desc("Debug min inst"), 205 cl::Hidden, cl::init(-1)); 206 static cl::opt<int> ClDebugMax("asan-debug-max", cl::desc("Debug man inst"), 207 cl::Hidden, cl::init(-1)); 208 209 STATISTIC(NumInstrumentedReads, "Number of instrumented reads"); 210 STATISTIC(NumInstrumentedWrites, "Number of instrumented writes"); 211 STATISTIC(NumOptimizedAccessesToGlobalArray, 212 "Number of optimized accesses to global arrays"); 213 STATISTIC(NumOptimizedAccessesToGlobalVar, 214 "Number of optimized accesses to global vars"); 215 216 namespace { 217 /// A set of dynamically initialized globals extracted from metadata. 218 class SetOfDynamicallyInitializedGlobals { 219 public: 220 void Init(Module& M) { 221 // Clang generates metadata identifying all dynamically initialized globals. 222 NamedMDNode *DynamicGlobals = 223 M.getNamedMetadata("llvm.asan.dynamically_initialized_globals"); 224 if (!DynamicGlobals) 225 return; 226 for (int i = 0, n = DynamicGlobals->getNumOperands(); i < n; ++i) { 227 MDNode *MDN = DynamicGlobals->getOperand(i); 228 assert(MDN->getNumOperands() == 1); 229 Value *VG = MDN->getOperand(0); 230 // The optimizer may optimize away a global entirely, in which case we 231 // cannot instrument access to it. 232 if (!VG) 233 continue; 234 DynInitGlobals.insert(cast<GlobalVariable>(VG)); 235 } 236 } 237 bool Contains(GlobalVariable *G) { return DynInitGlobals.count(G) != 0; } 238 private: 239 SmallSet<GlobalValue*, 32> DynInitGlobals; 240 }; 241 242 /// This struct defines the shadow mapping using the rule: 243 /// shadow = (mem >> Scale) ADD-or-OR Offset. 244 struct ShadowMapping { 245 int Scale; 246 uint64_t Offset; 247 bool OrShadowOffset; 248 }; 249 250 static ShadowMapping getShadowMapping(const Module &M, int LongSize) { 251 llvm::Triple TargetTriple(M.getTargetTriple()); 252 bool IsAndroid = TargetTriple.getEnvironment() == llvm::Triple::Android; 253 // bool IsMacOSX = TargetTriple.getOS() == llvm::Triple::MacOSX; 254 bool IsFreeBSD = TargetTriple.getOS() == llvm::Triple::FreeBSD; 255 bool IsLinux = TargetTriple.getOS() == llvm::Triple::Linux; 256 bool IsPPC64 = TargetTriple.getArch() == llvm::Triple::ppc64 || 257 TargetTriple.getArch() == llvm::Triple::ppc64le; 258 bool IsX86_64 = TargetTriple.getArch() == llvm::Triple::x86_64; 259 bool IsMIPS32 = TargetTriple.getArch() == llvm::Triple::mips || 260 TargetTriple.getArch() == llvm::Triple::mipsel; 261 262 ShadowMapping Mapping; 263 264 if (LongSize == 32) { 265 if (IsAndroid) 266 Mapping.Offset = 0; 267 else if (IsMIPS32) 268 Mapping.Offset = kMIPS32_ShadowOffset32; 269 else if (IsFreeBSD) 270 Mapping.Offset = kFreeBSD_ShadowOffset32; 271 else 272 Mapping.Offset = kDefaultShadowOffset32; 273 } else { // LongSize == 64 274 if (IsPPC64) 275 Mapping.Offset = kPPC64_ShadowOffset64; 276 else if (IsFreeBSD) 277 Mapping.Offset = kFreeBSD_ShadowOffset64; 278 else if (IsLinux && IsX86_64) 279 Mapping.Offset = kSmallX86_64ShadowOffset; 280 else 281 Mapping.Offset = kDefaultShadowOffset64; 282 } 283 284 Mapping.Scale = kDefaultShadowScale; 285 if (ClMappingScale) { 286 Mapping.Scale = ClMappingScale; 287 } 288 289 // OR-ing shadow offset if more efficient (at least on x86) if the offset 290 // is a power of two, but on ppc64 we have to use add since the shadow 291 // offset is not necessary 1/8-th of the address space. 292 Mapping.OrShadowOffset = !IsPPC64 && !(Mapping.Offset & (Mapping.Offset - 1)); 293 294 return Mapping; 295 } 296 297 static size_t RedzoneSizeForScale(int MappingScale) { 298 // Redzone used for stack and globals is at least 32 bytes. 299 // For scales 6 and 7, the redzone has to be 64 and 128 bytes respectively. 300 return std::max(32U, 1U << MappingScale); 301 } 302 303 /// AddressSanitizer: instrument the code in module to find memory bugs. 304 struct AddressSanitizer : public FunctionPass { 305 AddressSanitizer(bool CheckInitOrder = true, 306 bool CheckUseAfterReturn = false, 307 bool CheckLifetime = false, 308 StringRef BlacklistFile = StringRef()) 309 : FunctionPass(ID), 310 CheckInitOrder(CheckInitOrder || ClInitializers), 311 CheckUseAfterReturn(CheckUseAfterReturn || ClUseAfterReturn), 312 CheckLifetime(CheckLifetime || ClCheckLifetime), 313 BlacklistFile(BlacklistFile.empty() ? ClBlacklistFile 314 : BlacklistFile) {} 315 const char *getPassName() const override { 316 return "AddressSanitizerFunctionPass"; 317 } 318 void instrumentMop(Instruction *I, bool UseCalls); 319 void instrumentPointerComparisonOrSubtraction(Instruction *I); 320 void instrumentAddress(Instruction *OrigIns, Instruction *InsertBefore, 321 Value *Addr, uint32_t TypeSize, bool IsWrite, 322 Value *SizeArgument, bool UseCalls); 323 Value *createSlowPathCmp(IRBuilder<> &IRB, Value *AddrLong, 324 Value *ShadowValue, uint32_t TypeSize); 325 Instruction *generateCrashCode(Instruction *InsertBefore, Value *Addr, 326 bool IsWrite, size_t AccessSizeIndex, 327 Value *SizeArgument); 328 void instrumentMemIntrinsic(MemIntrinsic *MI); 329 Value *memToShadow(Value *Shadow, IRBuilder<> &IRB); 330 bool runOnFunction(Function &F) override; 331 bool maybeInsertAsanInitAtFunctionEntry(Function &F); 332 bool doInitialization(Module &M) override; 333 static char ID; // Pass identification, replacement for typeid 334 335 private: 336 void initializeCallbacks(Module &M); 337 338 bool LooksLikeCodeInBug11395(Instruction *I); 339 bool GlobalIsLinkerInitialized(GlobalVariable *G); 340 bool InjectCoverage(Function &F, const ArrayRef<BasicBlock*> AllBlocks); 341 void InjectCoverageAtBlock(Function &F, BasicBlock &BB); 342 343 bool CheckInitOrder; 344 bool CheckUseAfterReturn; 345 bool CheckLifetime; 346 SmallString<64> BlacklistFile; 347 348 LLVMContext *C; 349 const DataLayout *DL; 350 int LongSize; 351 Type *IntptrTy; 352 ShadowMapping Mapping; 353 Function *AsanCtorFunction; 354 Function *AsanInitFunction; 355 Function *AsanHandleNoReturnFunc; 356 Function *AsanCovFunction; 357 Function *AsanPtrCmpFunction, *AsanPtrSubFunction; 358 std::unique_ptr<SpecialCaseList> BL; 359 // This array is indexed by AccessIsWrite and log2(AccessSize). 360 Function *AsanErrorCallback[2][kNumberOfAccessSizes]; 361 Function *AsanMemoryAccessCallback[2][kNumberOfAccessSizes]; 362 // This array is indexed by AccessIsWrite. 363 Function *AsanErrorCallbackSized[2], 364 *AsanMemoryAccessCallbackSized[2]; 365 Function *AsanMemmove, *AsanMemcpy, *AsanMemset; 366 InlineAsm *EmptyAsm; 367 SetOfDynamicallyInitializedGlobals DynamicallyInitializedGlobals; 368 369 friend struct FunctionStackPoisoner; 370 }; 371 372 class AddressSanitizerModule : public ModulePass { 373 public: 374 AddressSanitizerModule(bool CheckInitOrder = true, 375 StringRef BlacklistFile = StringRef()) 376 : ModulePass(ID), 377 CheckInitOrder(CheckInitOrder || ClInitializers), 378 BlacklistFile(BlacklistFile.empty() ? ClBlacklistFile 379 : BlacklistFile) {} 380 bool runOnModule(Module &M) override; 381 static char ID; // Pass identification, replacement for typeid 382 const char *getPassName() const override { 383 return "AddressSanitizerModule"; 384 } 385 386 private: 387 void initializeCallbacks(Module &M); 388 389 bool ShouldInstrumentGlobal(GlobalVariable *G); 390 void createInitializerPoisonCalls(Module &M, GlobalValue *ModuleName); 391 size_t MinRedzoneSizeForGlobal() const { 392 return RedzoneSizeForScale(Mapping.Scale); 393 } 394 395 bool CheckInitOrder; 396 SmallString<64> BlacklistFile; 397 398 std::unique_ptr<SpecialCaseList> BL; 399 SetOfDynamicallyInitializedGlobals DynamicallyInitializedGlobals; 400 Type *IntptrTy; 401 LLVMContext *C; 402 const DataLayout *DL; 403 ShadowMapping Mapping; 404 Function *AsanPoisonGlobals; 405 Function *AsanUnpoisonGlobals; 406 Function *AsanRegisterGlobals; 407 Function *AsanUnregisterGlobals; 408 }; 409 410 // Stack poisoning does not play well with exception handling. 411 // When an exception is thrown, we essentially bypass the code 412 // that unpoisones the stack. This is why the run-time library has 413 // to intercept __cxa_throw (as well as longjmp, etc) and unpoison the entire 414 // stack in the interceptor. This however does not work inside the 415 // actual function which catches the exception. Most likely because the 416 // compiler hoists the load of the shadow value somewhere too high. 417 // This causes asan to report a non-existing bug on 453.povray. 418 // It sounds like an LLVM bug. 419 struct FunctionStackPoisoner : public InstVisitor<FunctionStackPoisoner> { 420 Function &F; 421 AddressSanitizer &ASan; 422 DIBuilder DIB; 423 LLVMContext *C; 424 Type *IntptrTy; 425 Type *IntptrPtrTy; 426 ShadowMapping Mapping; 427 428 SmallVector<AllocaInst*, 16> AllocaVec; 429 SmallVector<Instruction*, 8> RetVec; 430 unsigned StackAlignment; 431 432 Function *AsanStackMallocFunc[kMaxAsanStackMallocSizeClass + 1], 433 *AsanStackFreeFunc[kMaxAsanStackMallocSizeClass + 1]; 434 Function *AsanPoisonStackMemoryFunc, *AsanUnpoisonStackMemoryFunc; 435 436 // Stores a place and arguments of poisoning/unpoisoning call for alloca. 437 struct AllocaPoisonCall { 438 IntrinsicInst *InsBefore; 439 AllocaInst *AI; 440 uint64_t Size; 441 bool DoPoison; 442 }; 443 SmallVector<AllocaPoisonCall, 8> AllocaPoisonCallVec; 444 445 // Maps Value to an AllocaInst from which the Value is originated. 446 typedef DenseMap<Value*, AllocaInst*> AllocaForValueMapTy; 447 AllocaForValueMapTy AllocaForValue; 448 449 FunctionStackPoisoner(Function &F, AddressSanitizer &ASan) 450 : F(F), ASan(ASan), DIB(*F.getParent()), C(ASan.C), 451 IntptrTy(ASan.IntptrTy), IntptrPtrTy(PointerType::get(IntptrTy, 0)), 452 Mapping(ASan.Mapping), 453 StackAlignment(1 << Mapping.Scale) {} 454 455 bool runOnFunction() { 456 if (!ClStack) return false; 457 // Collect alloca, ret, lifetime instructions etc. 458 for (BasicBlock *BB : depth_first(&F.getEntryBlock())) 459 visit(*BB); 460 461 if (AllocaVec.empty()) return false; 462 463 initializeCallbacks(*F.getParent()); 464 465 poisonStack(); 466 467 if (ClDebugStack) { 468 DEBUG(dbgs() << F); 469 } 470 return true; 471 } 472 473 // Finds all static Alloca instructions and puts 474 // poisoned red zones around all of them. 475 // Then unpoison everything back before the function returns. 476 void poisonStack(); 477 478 // ----------------------- Visitors. 479 /// \brief Collect all Ret instructions. 480 void visitReturnInst(ReturnInst &RI) { 481 RetVec.push_back(&RI); 482 } 483 484 /// \brief Collect Alloca instructions we want (and can) handle. 485 void visitAllocaInst(AllocaInst &AI) { 486 if (!isInterestingAlloca(AI)) return; 487 488 StackAlignment = std::max(StackAlignment, AI.getAlignment()); 489 AllocaVec.push_back(&AI); 490 } 491 492 /// \brief Collect lifetime intrinsic calls to check for use-after-scope 493 /// errors. 494 void visitIntrinsicInst(IntrinsicInst &II) { 495 if (!ASan.CheckLifetime) return; 496 Intrinsic::ID ID = II.getIntrinsicID(); 497 if (ID != Intrinsic::lifetime_start && 498 ID != Intrinsic::lifetime_end) 499 return; 500 // Found lifetime intrinsic, add ASan instrumentation if necessary. 501 ConstantInt *Size = dyn_cast<ConstantInt>(II.getArgOperand(0)); 502 // If size argument is undefined, don't do anything. 503 if (Size->isMinusOne()) return; 504 // Check that size doesn't saturate uint64_t and can 505 // be stored in IntptrTy. 506 const uint64_t SizeValue = Size->getValue().getLimitedValue(); 507 if (SizeValue == ~0ULL || 508 !ConstantInt::isValueValidForType(IntptrTy, SizeValue)) 509 return; 510 // Find alloca instruction that corresponds to llvm.lifetime argument. 511 AllocaInst *AI = findAllocaForValue(II.getArgOperand(1)); 512 if (!AI) return; 513 bool DoPoison = (ID == Intrinsic::lifetime_end); 514 AllocaPoisonCall APC = {&II, AI, SizeValue, DoPoison}; 515 AllocaPoisonCallVec.push_back(APC); 516 } 517 518 // ---------------------- Helpers. 519 void initializeCallbacks(Module &M); 520 521 // Check if we want (and can) handle this alloca. 522 bool isInterestingAlloca(AllocaInst &AI) const { 523 return (!AI.isArrayAllocation() && AI.isStaticAlloca() && 524 AI.getAllocatedType()->isSized() && 525 // alloca() may be called with 0 size, ignore it. 526 getAllocaSizeInBytes(&AI) > 0); 527 } 528 529 uint64_t getAllocaSizeInBytes(AllocaInst *AI) const { 530 Type *Ty = AI->getAllocatedType(); 531 uint64_t SizeInBytes = ASan.DL->getTypeAllocSize(Ty); 532 return SizeInBytes; 533 } 534 /// Finds alloca where the value comes from. 535 AllocaInst *findAllocaForValue(Value *V); 536 void poisonRedZones(const ArrayRef<uint8_t> ShadowBytes, IRBuilder<> &IRB, 537 Value *ShadowBase, bool DoPoison); 538 void poisonAlloca(Value *V, uint64_t Size, IRBuilder<> &IRB, bool DoPoison); 539 540 void SetShadowToStackAfterReturnInlined(IRBuilder<> &IRB, Value *ShadowBase, 541 int Size); 542 }; 543 544 } // namespace 545 546 char AddressSanitizer::ID = 0; 547 INITIALIZE_PASS(AddressSanitizer, "asan", 548 "AddressSanitizer: detects use-after-free and out-of-bounds bugs.", 549 false, false) 550 FunctionPass *llvm::createAddressSanitizerFunctionPass( 551 bool CheckInitOrder, bool CheckUseAfterReturn, bool CheckLifetime, 552 StringRef BlacklistFile) { 553 return new AddressSanitizer(CheckInitOrder, CheckUseAfterReturn, 554 CheckLifetime, BlacklistFile); 555 } 556 557 char AddressSanitizerModule::ID = 0; 558 INITIALIZE_PASS(AddressSanitizerModule, "asan-module", 559 "AddressSanitizer: detects use-after-free and out-of-bounds bugs." 560 "ModulePass", false, false) 561 ModulePass *llvm::createAddressSanitizerModulePass( 562 bool CheckInitOrder, StringRef BlacklistFile) { 563 return new AddressSanitizerModule(CheckInitOrder, BlacklistFile); 564 } 565 566 static size_t TypeSizeToSizeIndex(uint32_t TypeSize) { 567 size_t Res = countTrailingZeros(TypeSize / 8); 568 assert(Res < kNumberOfAccessSizes); 569 return Res; 570 } 571 572 // \brief Create a constant for Str so that we can pass it to the run-time lib. 573 static GlobalVariable *createPrivateGlobalForString( 574 Module &M, StringRef Str, bool AllowMerging) { 575 Constant *StrConst = ConstantDataArray::getString(M.getContext(), Str); 576 // We use private linkage for module-local strings. If they can be merged 577 // with another one, we set the unnamed_addr attribute. 578 GlobalVariable *GV = 579 new GlobalVariable(M, StrConst->getType(), true, 580 GlobalValue::PrivateLinkage, StrConst, kAsanGenPrefix); 581 if (AllowMerging) 582 GV->setUnnamedAddr(true); 583 GV->setAlignment(1); // Strings may not be merged w/o setting align 1. 584 return GV; 585 } 586 587 static bool GlobalWasGeneratedByAsan(GlobalVariable *G) { 588 return G->getName().find(kAsanGenPrefix) == 0; 589 } 590 591 Value *AddressSanitizer::memToShadow(Value *Shadow, IRBuilder<> &IRB) { 592 // Shadow >> scale 593 Shadow = IRB.CreateLShr(Shadow, Mapping.Scale); 594 if (Mapping.Offset == 0) 595 return Shadow; 596 // (Shadow >> scale) | offset 597 if (Mapping.OrShadowOffset) 598 return IRB.CreateOr(Shadow, ConstantInt::get(IntptrTy, Mapping.Offset)); 599 else 600 return IRB.CreateAdd(Shadow, ConstantInt::get(IntptrTy, Mapping.Offset)); 601 } 602 603 // Instrument memset/memmove/memcpy 604 void AddressSanitizer::instrumentMemIntrinsic(MemIntrinsic *MI) { 605 IRBuilder<> IRB(MI); 606 Instruction *Call = 0; 607 if (isa<MemTransferInst>(MI)) { 608 Call = IRB.CreateCall3( 609 isa<MemMoveInst>(MI) ? AsanMemmove : AsanMemcpy, 610 IRB.CreatePointerCast(MI->getOperand(0), IRB.getInt8PtrTy()), 611 IRB.CreatePointerCast(MI->getOperand(1), IRB.getInt8PtrTy()), 612 IRB.CreateIntCast(MI->getOperand(2), IntptrTy, false)); 613 } else if (isa<MemSetInst>(MI)) { 614 Call = IRB.CreateCall3( 615 AsanMemset, 616 IRB.CreatePointerCast(MI->getOperand(0), IRB.getInt8PtrTy()), 617 IRB.CreateIntCast(MI->getOperand(1), IRB.getInt32Ty(), false), 618 IRB.CreateIntCast(MI->getOperand(2), IntptrTy, false)); 619 } 620 Call->setDebugLoc(MI->getDebugLoc()); 621 MI->eraseFromParent(); 622 } 623 624 // If I is an interesting memory access, return the PointerOperand 625 // and set IsWrite. Otherwise return NULL. 626 static Value *isInterestingMemoryAccess(Instruction *I, bool *IsWrite) { 627 if (LoadInst *LI = dyn_cast<LoadInst>(I)) { 628 if (!ClInstrumentReads) return NULL; 629 *IsWrite = false; 630 return LI->getPointerOperand(); 631 } 632 if (StoreInst *SI = dyn_cast<StoreInst>(I)) { 633 if (!ClInstrumentWrites) return NULL; 634 *IsWrite = true; 635 return SI->getPointerOperand(); 636 } 637 if (AtomicRMWInst *RMW = dyn_cast<AtomicRMWInst>(I)) { 638 if (!ClInstrumentAtomics) return NULL; 639 *IsWrite = true; 640 return RMW->getPointerOperand(); 641 } 642 if (AtomicCmpXchgInst *XCHG = dyn_cast<AtomicCmpXchgInst>(I)) { 643 if (!ClInstrumentAtomics) return NULL; 644 *IsWrite = true; 645 return XCHG->getPointerOperand(); 646 } 647 return NULL; 648 } 649 650 static bool isPointerOperand(Value *V) { 651 return V->getType()->isPointerTy() || isa<PtrToIntInst>(V); 652 } 653 654 // This is a rough heuristic; it may cause both false positives and 655 // false negatives. The proper implementation requires cooperation with 656 // the frontend. 657 static bool isInterestingPointerComparisonOrSubtraction(Instruction *I) { 658 if (ICmpInst *Cmp = dyn_cast<ICmpInst>(I)) { 659 if (!Cmp->isRelational()) 660 return false; 661 } else if (BinaryOperator *BO = dyn_cast<BinaryOperator>(I)) { 662 if (BO->getOpcode() != Instruction::Sub) 663 return false; 664 } else { 665 return false; 666 } 667 if (!isPointerOperand(I->getOperand(0)) || 668 !isPointerOperand(I->getOperand(1))) 669 return false; 670 return true; 671 } 672 673 bool AddressSanitizer::GlobalIsLinkerInitialized(GlobalVariable *G) { 674 // If a global variable does not have dynamic initialization we don't 675 // have to instrument it. However, if a global does not have initializer 676 // at all, we assume it has dynamic initializer (in other TU). 677 return G->hasInitializer() && !DynamicallyInitializedGlobals.Contains(G); 678 } 679 680 void 681 AddressSanitizer::instrumentPointerComparisonOrSubtraction(Instruction *I) { 682 IRBuilder<> IRB(I); 683 Function *F = isa<ICmpInst>(I) ? AsanPtrCmpFunction : AsanPtrSubFunction; 684 Value *Param[2] = {I->getOperand(0), I->getOperand(1)}; 685 for (int i = 0; i < 2; i++) { 686 if (Param[i]->getType()->isPointerTy()) 687 Param[i] = IRB.CreatePointerCast(Param[i], IntptrTy); 688 } 689 IRB.CreateCall2(F, Param[0], Param[1]); 690 } 691 692 void AddressSanitizer::instrumentMop(Instruction *I, bool UseCalls) { 693 bool IsWrite = false; 694 Value *Addr = isInterestingMemoryAccess(I, &IsWrite); 695 assert(Addr); 696 if (ClOpt && ClOptGlobals) { 697 if (GlobalVariable *G = dyn_cast<GlobalVariable>(Addr)) { 698 // If initialization order checking is disabled, a simple access to a 699 // dynamically initialized global is always valid. 700 if (!CheckInitOrder || GlobalIsLinkerInitialized(G)) { 701 NumOptimizedAccessesToGlobalVar++; 702 return; 703 } 704 } 705 ConstantExpr *CE = dyn_cast<ConstantExpr>(Addr); 706 if (CE && CE->isGEPWithNoNotionalOverIndexing()) { 707 if (GlobalVariable *G = dyn_cast<GlobalVariable>(CE->getOperand(0))) { 708 if (CE->getOperand(1)->isNullValue() && GlobalIsLinkerInitialized(G)) { 709 NumOptimizedAccessesToGlobalArray++; 710 return; 711 } 712 } 713 } 714 } 715 716 Type *OrigPtrTy = Addr->getType(); 717 Type *OrigTy = cast<PointerType>(OrigPtrTy)->getElementType(); 718 719 assert(OrigTy->isSized()); 720 uint32_t TypeSize = DL->getTypeStoreSizeInBits(OrigTy); 721 722 assert((TypeSize % 8) == 0); 723 724 if (IsWrite) 725 NumInstrumentedWrites++; 726 else 727 NumInstrumentedReads++; 728 729 // Instrument a 1-, 2-, 4-, 8-, or 16- byte access with one check. 730 if (TypeSize == 8 || TypeSize == 16 || 731 TypeSize == 32 || TypeSize == 64 || TypeSize == 128) 732 return instrumentAddress(I, I, Addr, TypeSize, IsWrite, 0, UseCalls); 733 // Instrument unusual size (but still multiple of 8). 734 // We can not do it with a single check, so we do 1-byte check for the first 735 // and the last bytes. We call __asan_report_*_n(addr, real_size) to be able 736 // to report the actual access size. 737 IRBuilder<> IRB(I); 738 Value *Size = ConstantInt::get(IntptrTy, TypeSize / 8); 739 Value *AddrLong = IRB.CreatePointerCast(Addr, IntptrTy); 740 if (UseCalls) { 741 CallInst *Check = 742 IRB.CreateCall2(AsanMemoryAccessCallbackSized[IsWrite], AddrLong, Size); 743 Check->setDebugLoc(I->getDebugLoc()); 744 } else { 745 Value *LastByte = IRB.CreateIntToPtr( 746 IRB.CreateAdd(AddrLong, ConstantInt::get(IntptrTy, TypeSize / 8 - 1)), 747 OrigPtrTy); 748 instrumentAddress(I, I, Addr, 8, IsWrite, Size, false); 749 instrumentAddress(I, I, LastByte, 8, IsWrite, Size, false); 750 } 751 } 752 753 // Validate the result of Module::getOrInsertFunction called for an interface 754 // function of AddressSanitizer. If the instrumented module defines a function 755 // with the same name, their prototypes must match, otherwise 756 // getOrInsertFunction returns a bitcast. 757 static Function *checkInterfaceFunction(Constant *FuncOrBitcast) { 758 if (isa<Function>(FuncOrBitcast)) return cast<Function>(FuncOrBitcast); 759 FuncOrBitcast->dump(); 760 report_fatal_error("trying to redefine an AddressSanitizer " 761 "interface function"); 762 } 763 764 Instruction *AddressSanitizer::generateCrashCode( 765 Instruction *InsertBefore, Value *Addr, 766 bool IsWrite, size_t AccessSizeIndex, Value *SizeArgument) { 767 IRBuilder<> IRB(InsertBefore); 768 CallInst *Call = SizeArgument 769 ? IRB.CreateCall2(AsanErrorCallbackSized[IsWrite], Addr, SizeArgument) 770 : IRB.CreateCall(AsanErrorCallback[IsWrite][AccessSizeIndex], Addr); 771 772 // We don't do Call->setDoesNotReturn() because the BB already has 773 // UnreachableInst at the end. 774 // This EmptyAsm is required to avoid callback merge. 775 IRB.CreateCall(EmptyAsm); 776 return Call; 777 } 778 779 Value *AddressSanitizer::createSlowPathCmp(IRBuilder<> &IRB, Value *AddrLong, 780 Value *ShadowValue, 781 uint32_t TypeSize) { 782 size_t Granularity = 1 << Mapping.Scale; 783 // Addr & (Granularity - 1) 784 Value *LastAccessedByte = IRB.CreateAnd( 785 AddrLong, ConstantInt::get(IntptrTy, Granularity - 1)); 786 // (Addr & (Granularity - 1)) + size - 1 787 if (TypeSize / 8 > 1) 788 LastAccessedByte = IRB.CreateAdd( 789 LastAccessedByte, ConstantInt::get(IntptrTy, TypeSize / 8 - 1)); 790 // (uint8_t) ((Addr & (Granularity-1)) + size - 1) 791 LastAccessedByte = IRB.CreateIntCast( 792 LastAccessedByte, ShadowValue->getType(), false); 793 // ((uint8_t) ((Addr & (Granularity-1)) + size - 1)) >= ShadowValue 794 return IRB.CreateICmpSGE(LastAccessedByte, ShadowValue); 795 } 796 797 void AddressSanitizer::instrumentAddress(Instruction *OrigIns, 798 Instruction *InsertBefore, Value *Addr, 799 uint32_t TypeSize, bool IsWrite, 800 Value *SizeArgument, bool UseCalls) { 801 IRBuilder<> IRB(InsertBefore); 802 Value *AddrLong = IRB.CreatePointerCast(Addr, IntptrTy); 803 size_t AccessSizeIndex = TypeSizeToSizeIndex(TypeSize); 804 805 if (UseCalls) { 806 IRB.CreateCall(AsanMemoryAccessCallback[IsWrite][AccessSizeIndex], 807 AddrLong); 808 return; 809 } 810 811 Type *ShadowTy = IntegerType::get( 812 *C, std::max(8U, TypeSize >> Mapping.Scale)); 813 Type *ShadowPtrTy = PointerType::get(ShadowTy, 0); 814 Value *ShadowPtr = memToShadow(AddrLong, IRB); 815 Value *CmpVal = Constant::getNullValue(ShadowTy); 816 Value *ShadowValue = IRB.CreateLoad( 817 IRB.CreateIntToPtr(ShadowPtr, ShadowPtrTy)); 818 819 Value *Cmp = IRB.CreateICmpNE(ShadowValue, CmpVal); 820 size_t Granularity = 1 << Mapping.Scale; 821 TerminatorInst *CrashTerm = 0; 822 823 if (ClAlwaysSlowPath || (TypeSize < 8 * Granularity)) { 824 TerminatorInst *CheckTerm = 825 SplitBlockAndInsertIfThen(Cmp, InsertBefore, false); 826 assert(dyn_cast<BranchInst>(CheckTerm)->isUnconditional()); 827 BasicBlock *NextBB = CheckTerm->getSuccessor(0); 828 IRB.SetInsertPoint(CheckTerm); 829 Value *Cmp2 = createSlowPathCmp(IRB, AddrLong, ShadowValue, TypeSize); 830 BasicBlock *CrashBlock = 831 BasicBlock::Create(*C, "", NextBB->getParent(), NextBB); 832 CrashTerm = new UnreachableInst(*C, CrashBlock); 833 BranchInst *NewTerm = BranchInst::Create(CrashBlock, NextBB, Cmp2); 834 ReplaceInstWithInst(CheckTerm, NewTerm); 835 } else { 836 CrashTerm = SplitBlockAndInsertIfThen(Cmp, InsertBefore, true); 837 } 838 839 Instruction *Crash = generateCrashCode( 840 CrashTerm, AddrLong, IsWrite, AccessSizeIndex, SizeArgument); 841 Crash->setDebugLoc(OrigIns->getDebugLoc()); 842 } 843 844 void AddressSanitizerModule::createInitializerPoisonCalls( 845 Module &M, GlobalValue *ModuleName) { 846 // We do all of our poisoning and unpoisoning within _GLOBAL__I_a. 847 Function *GlobalInit = M.getFunction("_GLOBAL__I_a"); 848 // If that function is not present, this TU contains no globals, or they have 849 // all been optimized away 850 if (!GlobalInit) 851 return; 852 853 // Set up the arguments to our poison/unpoison functions. 854 IRBuilder<> IRB(GlobalInit->begin()->getFirstInsertionPt()); 855 856 // Add a call to poison all external globals before the given function starts. 857 Value *ModuleNameAddr = ConstantExpr::getPointerCast(ModuleName, IntptrTy); 858 IRB.CreateCall(AsanPoisonGlobals, ModuleNameAddr); 859 860 // Add calls to unpoison all globals before each return instruction. 861 for (Function::iterator I = GlobalInit->begin(), E = GlobalInit->end(); 862 I != E; ++I) { 863 if (ReturnInst *RI = dyn_cast<ReturnInst>(I->getTerminator())) { 864 CallInst::Create(AsanUnpoisonGlobals, "", RI); 865 } 866 } 867 } 868 869 bool AddressSanitizerModule::ShouldInstrumentGlobal(GlobalVariable *G) { 870 Type *Ty = cast<PointerType>(G->getType())->getElementType(); 871 DEBUG(dbgs() << "GLOBAL: " << *G << "\n"); 872 873 if (BL->isIn(*G)) return false; 874 if (!Ty->isSized()) return false; 875 if (!G->hasInitializer()) return false; 876 if (GlobalWasGeneratedByAsan(G)) return false; // Our own global. 877 // Touch only those globals that will not be defined in other modules. 878 // Don't handle ODR type linkages since other modules may be built w/o asan. 879 if (G->getLinkage() != GlobalVariable::ExternalLinkage && 880 G->getLinkage() != GlobalVariable::PrivateLinkage && 881 G->getLinkage() != GlobalVariable::InternalLinkage) 882 return false; 883 // Two problems with thread-locals: 884 // - The address of the main thread's copy can't be computed at link-time. 885 // - Need to poison all copies, not just the main thread's one. 886 if (G->isThreadLocal()) 887 return false; 888 // For now, just ignore this Global if the alignment is large. 889 if (G->getAlignment() > MinRedzoneSizeForGlobal()) return false; 890 891 // Ignore all the globals with the names starting with "\01L_OBJC_". 892 // Many of those are put into the .cstring section. The linker compresses 893 // that section by removing the spare \0s after the string terminator, so 894 // our redzones get broken. 895 if ((G->getName().find("\01L_OBJC_") == 0) || 896 (G->getName().find("\01l_OBJC_") == 0)) { 897 DEBUG(dbgs() << "Ignoring \\01L_OBJC_* global: " << *G << "\n"); 898 return false; 899 } 900 901 if (G->hasSection()) { 902 StringRef Section(G->getSection()); 903 // Ignore the globals from the __OBJC section. The ObjC runtime assumes 904 // those conform to /usr/lib/objc/runtime.h, so we can't add redzones to 905 // them. 906 if ((Section.find("__OBJC,") == 0) || 907 (Section.find("__DATA, __objc_") == 0)) { 908 DEBUG(dbgs() << "Ignoring ObjC runtime global: " << *G << "\n"); 909 return false; 910 } 911 // See http://code.google.com/p/address-sanitizer/issues/detail?id=32 912 // Constant CFString instances are compiled in the following way: 913 // -- the string buffer is emitted into 914 // __TEXT,__cstring,cstring_literals 915 // -- the constant NSConstantString structure referencing that buffer 916 // is placed into __DATA,__cfstring 917 // Therefore there's no point in placing redzones into __DATA,__cfstring. 918 // Moreover, it causes the linker to crash on OS X 10.7 919 if (Section.find("__DATA,__cfstring") == 0) { 920 DEBUG(dbgs() << "Ignoring CFString: " << *G << "\n"); 921 return false; 922 } 923 // The linker merges the contents of cstring_literals and removes the 924 // trailing zeroes. 925 if (Section.find("__TEXT,__cstring,cstring_literals") == 0) { 926 DEBUG(dbgs() << "Ignoring a cstring literal: " << *G << "\n"); 927 return false; 928 } 929 // Globals from llvm.metadata aren't emitted, do not instrument them. 930 if (Section == "llvm.metadata") return false; 931 } 932 933 return true; 934 } 935 936 void AddressSanitizerModule::initializeCallbacks(Module &M) { 937 IRBuilder<> IRB(*C); 938 // Declare our poisoning and unpoisoning functions. 939 AsanPoisonGlobals = checkInterfaceFunction(M.getOrInsertFunction( 940 kAsanPoisonGlobalsName, IRB.getVoidTy(), IntptrTy, NULL)); 941 AsanPoisonGlobals->setLinkage(Function::ExternalLinkage); 942 AsanUnpoisonGlobals = checkInterfaceFunction(M.getOrInsertFunction( 943 kAsanUnpoisonGlobalsName, IRB.getVoidTy(), NULL)); 944 AsanUnpoisonGlobals->setLinkage(Function::ExternalLinkage); 945 // Declare functions that register/unregister globals. 946 AsanRegisterGlobals = checkInterfaceFunction(M.getOrInsertFunction( 947 kAsanRegisterGlobalsName, IRB.getVoidTy(), 948 IntptrTy, IntptrTy, NULL)); 949 AsanRegisterGlobals->setLinkage(Function::ExternalLinkage); 950 AsanUnregisterGlobals = checkInterfaceFunction(M.getOrInsertFunction( 951 kAsanUnregisterGlobalsName, 952 IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 953 AsanUnregisterGlobals->setLinkage(Function::ExternalLinkage); 954 } 955 956 // This function replaces all global variables with new variables that have 957 // trailing redzones. It also creates a function that poisons 958 // redzones and inserts this function into llvm.global_ctors. 959 bool AddressSanitizerModule::runOnModule(Module &M) { 960 if (!ClGlobals) return false; 961 962 DataLayoutPass *DLP = getAnalysisIfAvailable<DataLayoutPass>(); 963 if (!DLP) 964 return false; 965 DL = &DLP->getDataLayout(); 966 967 BL.reset(SpecialCaseList::createOrDie(BlacklistFile)); 968 if (BL->isIn(M)) return false; 969 C = &(M.getContext()); 970 int LongSize = DL->getPointerSizeInBits(); 971 IntptrTy = Type::getIntNTy(*C, LongSize); 972 Mapping = getShadowMapping(M, LongSize); 973 initializeCallbacks(M); 974 DynamicallyInitializedGlobals.Init(M); 975 976 SmallVector<GlobalVariable *, 16> GlobalsToChange; 977 978 for (Module::GlobalListType::iterator G = M.global_begin(), 979 E = M.global_end(); G != E; ++G) { 980 if (ShouldInstrumentGlobal(G)) 981 GlobalsToChange.push_back(G); 982 } 983 984 size_t n = GlobalsToChange.size(); 985 if (n == 0) return false; 986 987 // A global is described by a structure 988 // size_t beg; 989 // size_t size; 990 // size_t size_with_redzone; 991 // const char *name; 992 // const char *module_name; 993 // size_t has_dynamic_init; 994 // We initialize an array of such structures and pass it to a run-time call. 995 StructType *GlobalStructTy = StructType::get(IntptrTy, IntptrTy, 996 IntptrTy, IntptrTy, 997 IntptrTy, IntptrTy, NULL); 998 SmallVector<Constant *, 16> Initializers(n); 999 1000 Function *CtorFunc = M.getFunction(kAsanModuleCtorName); 1001 assert(CtorFunc); 1002 IRBuilder<> IRB(CtorFunc->getEntryBlock().getTerminator()); 1003 1004 bool HasDynamicallyInitializedGlobals = false; 1005 1006 // We shouldn't merge same module names, as this string serves as unique 1007 // module ID in runtime. 1008 GlobalVariable *ModuleName = createPrivateGlobalForString( 1009 M, M.getModuleIdentifier(), /*AllowMerging*/false); 1010 1011 for (size_t i = 0; i < n; i++) { 1012 static const uint64_t kMaxGlobalRedzone = 1 << 18; 1013 GlobalVariable *G = GlobalsToChange[i]; 1014 PointerType *PtrTy = cast<PointerType>(G->getType()); 1015 Type *Ty = PtrTy->getElementType(); 1016 uint64_t SizeInBytes = DL->getTypeAllocSize(Ty); 1017 uint64_t MinRZ = MinRedzoneSizeForGlobal(); 1018 // MinRZ <= RZ <= kMaxGlobalRedzone 1019 // and trying to make RZ to be ~ 1/4 of SizeInBytes. 1020 uint64_t RZ = std::max(MinRZ, 1021 std::min(kMaxGlobalRedzone, 1022 (SizeInBytes / MinRZ / 4) * MinRZ)); 1023 uint64_t RightRedzoneSize = RZ; 1024 // Round up to MinRZ 1025 if (SizeInBytes % MinRZ) 1026 RightRedzoneSize += MinRZ - (SizeInBytes % MinRZ); 1027 assert(((RightRedzoneSize + SizeInBytes) % MinRZ) == 0); 1028 Type *RightRedZoneTy = ArrayType::get(IRB.getInt8Ty(), RightRedzoneSize); 1029 // Determine whether this global should be poisoned in initialization. 1030 bool GlobalHasDynamicInitializer = 1031 DynamicallyInitializedGlobals.Contains(G); 1032 // Don't check initialization order if this global is blacklisted. 1033 GlobalHasDynamicInitializer &= !BL->isIn(*G, "init"); 1034 1035 StructType *NewTy = StructType::get(Ty, RightRedZoneTy, NULL); 1036 Constant *NewInitializer = ConstantStruct::get( 1037 NewTy, G->getInitializer(), 1038 Constant::getNullValue(RightRedZoneTy), NULL); 1039 1040 GlobalVariable *Name = 1041 createPrivateGlobalForString(M, G->getName(), /*AllowMerging*/true); 1042 1043 // Create a new global variable with enough space for a redzone. 1044 GlobalValue::LinkageTypes Linkage = G->getLinkage(); 1045 if (G->isConstant() && Linkage == GlobalValue::PrivateLinkage) 1046 Linkage = GlobalValue::InternalLinkage; 1047 GlobalVariable *NewGlobal = new GlobalVariable( 1048 M, NewTy, G->isConstant(), Linkage, 1049 NewInitializer, "", G, G->getThreadLocalMode()); 1050 NewGlobal->copyAttributesFrom(G); 1051 NewGlobal->setAlignment(MinRZ); 1052 1053 Value *Indices2[2]; 1054 Indices2[0] = IRB.getInt32(0); 1055 Indices2[1] = IRB.getInt32(0); 1056 1057 G->replaceAllUsesWith( 1058 ConstantExpr::getGetElementPtr(NewGlobal, Indices2, true)); 1059 NewGlobal->takeName(G); 1060 G->eraseFromParent(); 1061 1062 Initializers[i] = ConstantStruct::get( 1063 GlobalStructTy, 1064 ConstantExpr::getPointerCast(NewGlobal, IntptrTy), 1065 ConstantInt::get(IntptrTy, SizeInBytes), 1066 ConstantInt::get(IntptrTy, SizeInBytes + RightRedzoneSize), 1067 ConstantExpr::getPointerCast(Name, IntptrTy), 1068 ConstantExpr::getPointerCast(ModuleName, IntptrTy), 1069 ConstantInt::get(IntptrTy, GlobalHasDynamicInitializer), 1070 NULL); 1071 1072 // Populate the first and last globals declared in this TU. 1073 if (CheckInitOrder && GlobalHasDynamicInitializer) 1074 HasDynamicallyInitializedGlobals = true; 1075 1076 DEBUG(dbgs() << "NEW GLOBAL: " << *NewGlobal << "\n"); 1077 } 1078 1079 ArrayType *ArrayOfGlobalStructTy = ArrayType::get(GlobalStructTy, n); 1080 GlobalVariable *AllGlobals = new GlobalVariable( 1081 M, ArrayOfGlobalStructTy, false, GlobalVariable::InternalLinkage, 1082 ConstantArray::get(ArrayOfGlobalStructTy, Initializers), ""); 1083 1084 // Create calls for poisoning before initializers run and unpoisoning after. 1085 if (CheckInitOrder && HasDynamicallyInitializedGlobals) 1086 createInitializerPoisonCalls(M, ModuleName); 1087 IRB.CreateCall2(AsanRegisterGlobals, 1088 IRB.CreatePointerCast(AllGlobals, IntptrTy), 1089 ConstantInt::get(IntptrTy, n)); 1090 1091 // We also need to unregister globals at the end, e.g. when a shared library 1092 // gets closed. 1093 Function *AsanDtorFunction = Function::Create( 1094 FunctionType::get(Type::getVoidTy(*C), false), 1095 GlobalValue::InternalLinkage, kAsanModuleDtorName, &M); 1096 BasicBlock *AsanDtorBB = BasicBlock::Create(*C, "", AsanDtorFunction); 1097 IRBuilder<> IRB_Dtor(ReturnInst::Create(*C, AsanDtorBB)); 1098 IRB_Dtor.CreateCall2(AsanUnregisterGlobals, 1099 IRB.CreatePointerCast(AllGlobals, IntptrTy), 1100 ConstantInt::get(IntptrTy, n)); 1101 appendToGlobalDtors(M, AsanDtorFunction, kAsanCtorAndCtorPriority); 1102 1103 DEBUG(dbgs() << M); 1104 return true; 1105 } 1106 1107 void AddressSanitizer::initializeCallbacks(Module &M) { 1108 IRBuilder<> IRB(*C); 1109 // Create __asan_report* callbacks. 1110 for (size_t AccessIsWrite = 0; AccessIsWrite <= 1; AccessIsWrite++) { 1111 for (size_t AccessSizeIndex = 0; AccessSizeIndex < kNumberOfAccessSizes; 1112 AccessSizeIndex++) { 1113 // IsWrite and TypeSize are encoded in the function name. 1114 std::string Suffix = 1115 (AccessIsWrite ? "store" : "load") + itostr(1 << AccessSizeIndex); 1116 AsanErrorCallback[AccessIsWrite][AccessSizeIndex] = 1117 checkInterfaceFunction( 1118 M.getOrInsertFunction(kAsanReportErrorTemplate + Suffix, 1119 IRB.getVoidTy(), IntptrTy, NULL)); 1120 AsanMemoryAccessCallback[AccessIsWrite][AccessSizeIndex] = 1121 checkInterfaceFunction( 1122 M.getOrInsertFunction(ClMemoryAccessCallbackPrefix + Suffix, 1123 IRB.getVoidTy(), IntptrTy, NULL)); 1124 } 1125 } 1126 AsanErrorCallbackSized[0] = checkInterfaceFunction(M.getOrInsertFunction( 1127 kAsanReportLoadN, IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1128 AsanErrorCallbackSized[1] = checkInterfaceFunction(M.getOrInsertFunction( 1129 kAsanReportStoreN, IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1130 1131 AsanMemoryAccessCallbackSized[0] = checkInterfaceFunction( 1132 M.getOrInsertFunction(ClMemoryAccessCallbackPrefix + "loadN", 1133 IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1134 AsanMemoryAccessCallbackSized[1] = checkInterfaceFunction( 1135 M.getOrInsertFunction(ClMemoryAccessCallbackPrefix + "storeN", 1136 IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1137 1138 AsanMemmove = checkInterfaceFunction(M.getOrInsertFunction( 1139 ClMemoryAccessCallbackPrefix + "memmove", IRB.getInt8PtrTy(), 1140 IRB.getInt8PtrTy(), IRB.getInt8PtrTy(), IntptrTy, NULL)); 1141 AsanMemcpy = checkInterfaceFunction(M.getOrInsertFunction( 1142 ClMemoryAccessCallbackPrefix + "memcpy", IRB.getInt8PtrTy(), 1143 IRB.getInt8PtrTy(), IRB.getInt8PtrTy(), IntptrTy, NULL)); 1144 AsanMemset = checkInterfaceFunction(M.getOrInsertFunction( 1145 ClMemoryAccessCallbackPrefix + "memset", IRB.getInt8PtrTy(), 1146 IRB.getInt8PtrTy(), IRB.getInt32Ty(), IntptrTy, NULL)); 1147 1148 AsanHandleNoReturnFunc = checkInterfaceFunction( 1149 M.getOrInsertFunction(kAsanHandleNoReturnName, IRB.getVoidTy(), NULL)); 1150 AsanCovFunction = checkInterfaceFunction(M.getOrInsertFunction( 1151 kAsanCovName, IRB.getVoidTy(), NULL)); 1152 AsanPtrCmpFunction = checkInterfaceFunction(M.getOrInsertFunction( 1153 kAsanPtrCmp, IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1154 AsanPtrSubFunction = checkInterfaceFunction(M.getOrInsertFunction( 1155 kAsanPtrSub, IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1156 // We insert an empty inline asm after __asan_report* to avoid callback merge. 1157 EmptyAsm = InlineAsm::get(FunctionType::get(IRB.getVoidTy(), false), 1158 StringRef(""), StringRef(""), 1159 /*hasSideEffects=*/true); 1160 } 1161 1162 // virtual 1163 bool AddressSanitizer::doInitialization(Module &M) { 1164 // Initialize the private fields. No one has accessed them before. 1165 DataLayoutPass *DLP = getAnalysisIfAvailable<DataLayoutPass>(); 1166 if (!DLP) 1167 report_fatal_error("data layout missing"); 1168 DL = &DLP->getDataLayout(); 1169 1170 BL.reset(SpecialCaseList::createOrDie(BlacklistFile)); 1171 DynamicallyInitializedGlobals.Init(M); 1172 1173 C = &(M.getContext()); 1174 LongSize = DL->getPointerSizeInBits(); 1175 IntptrTy = Type::getIntNTy(*C, LongSize); 1176 1177 AsanCtorFunction = Function::Create( 1178 FunctionType::get(Type::getVoidTy(*C), false), 1179 GlobalValue::InternalLinkage, kAsanModuleCtorName, &M); 1180 BasicBlock *AsanCtorBB = BasicBlock::Create(*C, "", AsanCtorFunction); 1181 // call __asan_init in the module ctor. 1182 IRBuilder<> IRB(ReturnInst::Create(*C, AsanCtorBB)); 1183 AsanInitFunction = checkInterfaceFunction( 1184 M.getOrInsertFunction(kAsanInitName, IRB.getVoidTy(), NULL)); 1185 AsanInitFunction->setLinkage(Function::ExternalLinkage); 1186 IRB.CreateCall(AsanInitFunction); 1187 1188 Mapping = getShadowMapping(M, LongSize); 1189 1190 appendToGlobalCtors(M, AsanCtorFunction, kAsanCtorAndCtorPriority); 1191 return true; 1192 } 1193 1194 bool AddressSanitizer::maybeInsertAsanInitAtFunctionEntry(Function &F) { 1195 // For each NSObject descendant having a +load method, this method is invoked 1196 // by the ObjC runtime before any of the static constructors is called. 1197 // Therefore we need to instrument such methods with a call to __asan_init 1198 // at the beginning in order to initialize our runtime before any access to 1199 // the shadow memory. 1200 // We cannot just ignore these methods, because they may call other 1201 // instrumented functions. 1202 if (F.getName().find(" load]") != std::string::npos) { 1203 IRBuilder<> IRB(F.begin()->begin()); 1204 IRB.CreateCall(AsanInitFunction); 1205 return true; 1206 } 1207 return false; 1208 } 1209 1210 void AddressSanitizer::InjectCoverageAtBlock(Function &F, BasicBlock &BB) { 1211 BasicBlock::iterator IP = BB.getFirstInsertionPt(), BE = BB.end(); 1212 // Skip static allocas at the top of the entry block so they don't become 1213 // dynamic when we split the block. If we used our optimized stack layout, 1214 // then there will only be one alloca and it will come first. 1215 for (; IP != BE; ++IP) { 1216 AllocaInst *AI = dyn_cast<AllocaInst>(IP); 1217 if (!AI || !AI->isStaticAlloca()) 1218 break; 1219 } 1220 1221 IRBuilder<> IRB(IP); 1222 Type *Int8Ty = IRB.getInt8Ty(); 1223 GlobalVariable *Guard = new GlobalVariable( 1224 *F.getParent(), Int8Ty, false, GlobalValue::PrivateLinkage, 1225 Constant::getNullValue(Int8Ty), "__asan_gen_cov_" + F.getName()); 1226 LoadInst *Load = IRB.CreateLoad(Guard); 1227 Load->setAtomic(Monotonic); 1228 Load->setAlignment(1); 1229 Value *Cmp = IRB.CreateICmpEQ(Constant::getNullValue(Int8Ty), Load); 1230 Instruction *Ins = SplitBlockAndInsertIfThen( 1231 Cmp, IP, false, MDBuilder(*C).createBranchWeights(1, 100000)); 1232 IRB.SetInsertPoint(Ins); 1233 // We pass &F to __sanitizer_cov. We could avoid this and rely on 1234 // GET_CALLER_PC, but having the PC of the first instruction is just nice. 1235 Instruction *Call = IRB.CreateCall(AsanCovFunction); 1236 Call->setDebugLoc(IP->getDebugLoc()); 1237 StoreInst *Store = IRB.CreateStore(ConstantInt::get(Int8Ty, 1), Guard); 1238 Store->setAtomic(Monotonic); 1239 Store->setAlignment(1); 1240 } 1241 1242 // Poor man's coverage that works with ASan. 1243 // We create a Guard boolean variable with the same linkage 1244 // as the function and inject this code into the entry block (-asan-coverage=1) 1245 // or all blocks (-asan-coverage=2): 1246 // if (*Guard) { 1247 // __sanitizer_cov(&F); 1248 // *Guard = 1; 1249 // } 1250 // The accesses to Guard are atomic. The rest of the logic is 1251 // in __sanitizer_cov (it's fine to call it more than once). 1252 // 1253 // This coverage implementation provides very limited data: 1254 // it only tells if a given function (block) was ever executed. 1255 // No counters, no per-edge data. 1256 // But for many use cases this is what we need and the added slowdown 1257 // is negligible. This simple implementation will probably be obsoleted 1258 // by the upcoming Clang-based coverage implementation. 1259 // By having it here and now we hope to 1260 // a) get the functionality to users earlier and 1261 // b) collect usage statistics to help improve Clang coverage design. 1262 bool AddressSanitizer::InjectCoverage(Function &F, 1263 const ArrayRef<BasicBlock *> AllBlocks) { 1264 if (!ClCoverage) return false; 1265 1266 if (ClCoverage == 1 || 1267 (unsigned)ClCoverageBlockThreshold < AllBlocks.size()) { 1268 InjectCoverageAtBlock(F, F.getEntryBlock()); 1269 } else { 1270 for (size_t i = 0, n = AllBlocks.size(); i < n; i++) 1271 InjectCoverageAtBlock(F, *AllBlocks[i]); 1272 } 1273 return true; 1274 } 1275 1276 bool AddressSanitizer::runOnFunction(Function &F) { 1277 if (BL->isIn(F)) return false; 1278 if (&F == AsanCtorFunction) return false; 1279 if (F.getLinkage() == GlobalValue::AvailableExternallyLinkage) return false; 1280 DEBUG(dbgs() << "ASAN instrumenting:\n" << F << "\n"); 1281 initializeCallbacks(*F.getParent()); 1282 1283 // If needed, insert __asan_init before checking for SanitizeAddress attr. 1284 maybeInsertAsanInitAtFunctionEntry(F); 1285 1286 if (!F.hasFnAttribute(Attribute::SanitizeAddress)) 1287 return false; 1288 1289 if (!ClDebugFunc.empty() && ClDebugFunc != F.getName()) 1290 return false; 1291 1292 // We want to instrument every address only once per basic block (unless there 1293 // are calls between uses). 1294 SmallSet<Value*, 16> TempsToInstrument; 1295 SmallVector<Instruction*, 16> ToInstrument; 1296 SmallVector<Instruction*, 8> NoReturnCalls; 1297 SmallVector<BasicBlock*, 16> AllBlocks; 1298 SmallVector<Instruction*, 16> PointerComparisonsOrSubtracts; 1299 int NumAllocas = 0; 1300 bool IsWrite; 1301 1302 // Fill the set of memory operations to instrument. 1303 for (Function::iterator FI = F.begin(), FE = F.end(); 1304 FI != FE; ++FI) { 1305 AllBlocks.push_back(FI); 1306 TempsToInstrument.clear(); 1307 int NumInsnsPerBB = 0; 1308 for (BasicBlock::iterator BI = FI->begin(), BE = FI->end(); 1309 BI != BE; ++BI) { 1310 if (LooksLikeCodeInBug11395(BI)) return false; 1311 if (Value *Addr = isInterestingMemoryAccess(BI, &IsWrite)) { 1312 if (ClOpt && ClOptSameTemp) { 1313 if (!TempsToInstrument.insert(Addr)) 1314 continue; // We've seen this temp in the current BB. 1315 } 1316 } else if (ClInvalidPointerPairs && 1317 isInterestingPointerComparisonOrSubtraction(BI)) { 1318 PointerComparisonsOrSubtracts.push_back(BI); 1319 continue; 1320 } else if (isa<MemIntrinsic>(BI)) { 1321 // ok, take it. 1322 } else { 1323 if (isa<AllocaInst>(BI)) 1324 NumAllocas++; 1325 CallSite CS(BI); 1326 if (CS) { 1327 // A call inside BB. 1328 TempsToInstrument.clear(); 1329 if (CS.doesNotReturn()) 1330 NoReturnCalls.push_back(CS.getInstruction()); 1331 } 1332 continue; 1333 } 1334 ToInstrument.push_back(BI); 1335 NumInsnsPerBB++; 1336 if (NumInsnsPerBB >= ClMaxInsnsToInstrumentPerBB) 1337 break; 1338 } 1339 } 1340 1341 Function *UninstrumentedDuplicate = 0; 1342 bool LikelyToInstrument = 1343 !NoReturnCalls.empty() || !ToInstrument.empty() || (NumAllocas > 0); 1344 if (ClKeepUninstrumented && LikelyToInstrument) { 1345 ValueToValueMapTy VMap; 1346 UninstrumentedDuplicate = CloneFunction(&F, VMap, false); 1347 UninstrumentedDuplicate->removeFnAttr(Attribute::SanitizeAddress); 1348 UninstrumentedDuplicate->setName("NOASAN_" + F.getName()); 1349 F.getParent()->getFunctionList().push_back(UninstrumentedDuplicate); 1350 } 1351 1352 bool UseCalls = false; 1353 if (ClInstrumentationWithCallsThreshold >= 0 && 1354 ToInstrument.size() > (unsigned)ClInstrumentationWithCallsThreshold) 1355 UseCalls = true; 1356 1357 // Instrument. 1358 int NumInstrumented = 0; 1359 for (size_t i = 0, n = ToInstrument.size(); i != n; i++) { 1360 Instruction *Inst = ToInstrument[i]; 1361 if (ClDebugMin < 0 || ClDebugMax < 0 || 1362 (NumInstrumented >= ClDebugMin && NumInstrumented <= ClDebugMax)) { 1363 if (isInterestingMemoryAccess(Inst, &IsWrite)) 1364 instrumentMop(Inst, UseCalls); 1365 else 1366 instrumentMemIntrinsic(cast<MemIntrinsic>(Inst)); 1367 } 1368 NumInstrumented++; 1369 } 1370 1371 FunctionStackPoisoner FSP(F, *this); 1372 bool ChangedStack = FSP.runOnFunction(); 1373 1374 // We must unpoison the stack before every NoReturn call (throw, _exit, etc). 1375 // See e.g. http://code.google.com/p/address-sanitizer/issues/detail?id=37 1376 for (size_t i = 0, n = NoReturnCalls.size(); i != n; i++) { 1377 Instruction *CI = NoReturnCalls[i]; 1378 IRBuilder<> IRB(CI); 1379 IRB.CreateCall(AsanHandleNoReturnFunc); 1380 } 1381 1382 for (size_t i = 0, n = PointerComparisonsOrSubtracts.size(); i != n; i++) { 1383 instrumentPointerComparisonOrSubtraction(PointerComparisonsOrSubtracts[i]); 1384 NumInstrumented++; 1385 } 1386 1387 bool res = NumInstrumented > 0 || ChangedStack || !NoReturnCalls.empty(); 1388 1389 if (InjectCoverage(F, AllBlocks)) 1390 res = true; 1391 1392 DEBUG(dbgs() << "ASAN done instrumenting: " << res << " " << F << "\n"); 1393 1394 if (ClKeepUninstrumented) { 1395 if (!res) { 1396 // No instrumentation is done, no need for the duplicate. 1397 if (UninstrumentedDuplicate) 1398 UninstrumentedDuplicate->eraseFromParent(); 1399 } else { 1400 // The function was instrumented. We must have the duplicate. 1401 assert(UninstrumentedDuplicate); 1402 UninstrumentedDuplicate->setSection("NOASAN"); 1403 assert(!F.hasSection()); 1404 F.setSection("ASAN"); 1405 } 1406 } 1407 1408 return res; 1409 } 1410 1411 // Workaround for bug 11395: we don't want to instrument stack in functions 1412 // with large assembly blobs (32-bit only), otherwise reg alloc may crash. 1413 // FIXME: remove once the bug 11395 is fixed. 1414 bool AddressSanitizer::LooksLikeCodeInBug11395(Instruction *I) { 1415 if (LongSize != 32) return false; 1416 CallInst *CI = dyn_cast<CallInst>(I); 1417 if (!CI || !CI->isInlineAsm()) return false; 1418 if (CI->getNumArgOperands() <= 5) return false; 1419 // We have inline assembly with quite a few arguments. 1420 return true; 1421 } 1422 1423 void FunctionStackPoisoner::initializeCallbacks(Module &M) { 1424 IRBuilder<> IRB(*C); 1425 for (int i = 0; i <= kMaxAsanStackMallocSizeClass; i++) { 1426 std::string Suffix = itostr(i); 1427 AsanStackMallocFunc[i] = checkInterfaceFunction( 1428 M.getOrInsertFunction(kAsanStackMallocNameTemplate + Suffix, IntptrTy, 1429 IntptrTy, IntptrTy, NULL)); 1430 AsanStackFreeFunc[i] = checkInterfaceFunction(M.getOrInsertFunction( 1431 kAsanStackFreeNameTemplate + Suffix, IRB.getVoidTy(), IntptrTy, 1432 IntptrTy, IntptrTy, NULL)); 1433 } 1434 AsanPoisonStackMemoryFunc = checkInterfaceFunction(M.getOrInsertFunction( 1435 kAsanPoisonStackMemoryName, IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1436 AsanUnpoisonStackMemoryFunc = checkInterfaceFunction(M.getOrInsertFunction( 1437 kAsanUnpoisonStackMemoryName, IRB.getVoidTy(), IntptrTy, IntptrTy, NULL)); 1438 } 1439 1440 void 1441 FunctionStackPoisoner::poisonRedZones(const ArrayRef<uint8_t> ShadowBytes, 1442 IRBuilder<> &IRB, Value *ShadowBase, 1443 bool DoPoison) { 1444 size_t n = ShadowBytes.size(); 1445 size_t i = 0; 1446 // We need to (un)poison n bytes of stack shadow. Poison as many as we can 1447 // using 64-bit stores (if we are on 64-bit arch), then poison the rest 1448 // with 32-bit stores, then with 16-byte stores, then with 8-byte stores. 1449 for (size_t LargeStoreSizeInBytes = ASan.LongSize / 8; 1450 LargeStoreSizeInBytes != 0; LargeStoreSizeInBytes /= 2) { 1451 for (; i + LargeStoreSizeInBytes - 1 < n; i += LargeStoreSizeInBytes) { 1452 uint64_t Val = 0; 1453 for (size_t j = 0; j < LargeStoreSizeInBytes; j++) { 1454 if (ASan.DL->isLittleEndian()) 1455 Val |= (uint64_t)ShadowBytes[i + j] << (8 * j); 1456 else 1457 Val = (Val << 8) | ShadowBytes[i + j]; 1458 } 1459 if (!Val) continue; 1460 Value *Ptr = IRB.CreateAdd(ShadowBase, ConstantInt::get(IntptrTy, i)); 1461 Type *StoreTy = Type::getIntNTy(*C, LargeStoreSizeInBytes * 8); 1462 Value *Poison = ConstantInt::get(StoreTy, DoPoison ? Val : 0); 1463 IRB.CreateStore(Poison, IRB.CreateIntToPtr(Ptr, StoreTy->getPointerTo())); 1464 } 1465 } 1466 } 1467 1468 // Fake stack allocator (asan_fake_stack.h) has 11 size classes 1469 // for every power of 2 from kMinStackMallocSize to kMaxAsanStackMallocSizeClass 1470 static int StackMallocSizeClass(uint64_t LocalStackSize) { 1471 assert(LocalStackSize <= kMaxStackMallocSize); 1472 uint64_t MaxSize = kMinStackMallocSize; 1473 for (int i = 0; ; i++, MaxSize *= 2) 1474 if (LocalStackSize <= MaxSize) 1475 return i; 1476 llvm_unreachable("impossible LocalStackSize"); 1477 } 1478 1479 // Set Size bytes starting from ShadowBase to kAsanStackAfterReturnMagic. 1480 // We can not use MemSet intrinsic because it may end up calling the actual 1481 // memset. Size is a multiple of 8. 1482 // Currently this generates 8-byte stores on x86_64; it may be better to 1483 // generate wider stores. 1484 void FunctionStackPoisoner::SetShadowToStackAfterReturnInlined( 1485 IRBuilder<> &IRB, Value *ShadowBase, int Size) { 1486 assert(!(Size % 8)); 1487 assert(kAsanStackAfterReturnMagic == 0xf5); 1488 for (int i = 0; i < Size; i += 8) { 1489 Value *p = IRB.CreateAdd(ShadowBase, ConstantInt::get(IntptrTy, i)); 1490 IRB.CreateStore(ConstantInt::get(IRB.getInt64Ty(), 0xf5f5f5f5f5f5f5f5ULL), 1491 IRB.CreateIntToPtr(p, IRB.getInt64Ty()->getPointerTo())); 1492 } 1493 } 1494 1495 void FunctionStackPoisoner::poisonStack() { 1496 int StackMallocIdx = -1; 1497 1498 assert(AllocaVec.size() > 0); 1499 Instruction *InsBefore = AllocaVec[0]; 1500 IRBuilder<> IRB(InsBefore); 1501 1502 SmallVector<ASanStackVariableDescription, 16> SVD; 1503 SVD.reserve(AllocaVec.size()); 1504 for (size_t i = 0, n = AllocaVec.size(); i < n; i++) { 1505 AllocaInst *AI = AllocaVec[i]; 1506 ASanStackVariableDescription D = { AI->getName().data(), 1507 getAllocaSizeInBytes(AI), 1508 AI->getAlignment(), AI, 0}; 1509 SVD.push_back(D); 1510 } 1511 // Minimal header size (left redzone) is 4 pointers, 1512 // i.e. 32 bytes on 64-bit platforms and 16 bytes in 32-bit platforms. 1513 size_t MinHeaderSize = ASan.LongSize / 2; 1514 ASanStackFrameLayout L; 1515 ComputeASanStackFrameLayout(SVD, 1UL << Mapping.Scale, MinHeaderSize, &L); 1516 DEBUG(dbgs() << L.DescriptionString << " --- " << L.FrameSize << "\n"); 1517 uint64_t LocalStackSize = L.FrameSize; 1518 bool DoStackMalloc = 1519 ASan.CheckUseAfterReturn && LocalStackSize <= kMaxStackMallocSize; 1520 1521 Type *ByteArrayTy = ArrayType::get(IRB.getInt8Ty(), LocalStackSize); 1522 AllocaInst *MyAlloca = 1523 new AllocaInst(ByteArrayTy, "MyAlloca", InsBefore); 1524 assert((ClRealignStack & (ClRealignStack - 1)) == 0); 1525 size_t FrameAlignment = std::max(L.FrameAlignment, (size_t)ClRealignStack); 1526 MyAlloca->setAlignment(FrameAlignment); 1527 assert(MyAlloca->isStaticAlloca()); 1528 Value *OrigStackBase = IRB.CreatePointerCast(MyAlloca, IntptrTy); 1529 Value *LocalStackBase = OrigStackBase; 1530 1531 if (DoStackMalloc) { 1532 // LocalStackBase = OrigStackBase 1533 // if (__asan_option_detect_stack_use_after_return) 1534 // LocalStackBase = __asan_stack_malloc_N(LocalStackBase, OrigStackBase); 1535 StackMallocIdx = StackMallocSizeClass(LocalStackSize); 1536 assert(StackMallocIdx <= kMaxAsanStackMallocSizeClass); 1537 Constant *OptionDetectUAR = F.getParent()->getOrInsertGlobal( 1538 kAsanOptionDetectUAR, IRB.getInt32Ty()); 1539 Value *Cmp = IRB.CreateICmpNE(IRB.CreateLoad(OptionDetectUAR), 1540 Constant::getNullValue(IRB.getInt32Ty())); 1541 Instruction *Term = SplitBlockAndInsertIfThen(Cmp, InsBefore, false); 1542 BasicBlock *CmpBlock = cast<Instruction>(Cmp)->getParent(); 1543 IRBuilder<> IRBIf(Term); 1544 LocalStackBase = IRBIf.CreateCall2( 1545 AsanStackMallocFunc[StackMallocIdx], 1546 ConstantInt::get(IntptrTy, LocalStackSize), OrigStackBase); 1547 BasicBlock *SetBlock = cast<Instruction>(LocalStackBase)->getParent(); 1548 IRB.SetInsertPoint(InsBefore); 1549 PHINode *Phi = IRB.CreatePHI(IntptrTy, 2); 1550 Phi->addIncoming(OrigStackBase, CmpBlock); 1551 Phi->addIncoming(LocalStackBase, SetBlock); 1552 LocalStackBase = Phi; 1553 } 1554 1555 // Insert poison calls for lifetime intrinsics for alloca. 1556 bool HavePoisonedAllocas = false; 1557 for (size_t i = 0, n = AllocaPoisonCallVec.size(); i < n; i++) { 1558 const AllocaPoisonCall &APC = AllocaPoisonCallVec[i]; 1559 assert(APC.InsBefore); 1560 assert(APC.AI); 1561 IRBuilder<> IRB(APC.InsBefore); 1562 poisonAlloca(APC.AI, APC.Size, IRB, APC.DoPoison); 1563 HavePoisonedAllocas |= APC.DoPoison; 1564 } 1565 1566 // Replace Alloca instructions with base+offset. 1567 for (size_t i = 0, n = SVD.size(); i < n; i++) { 1568 AllocaInst *AI = SVD[i].AI; 1569 Value *NewAllocaPtr = IRB.CreateIntToPtr( 1570 IRB.CreateAdd(LocalStackBase, 1571 ConstantInt::get(IntptrTy, SVD[i].Offset)), 1572 AI->getType()); 1573 replaceDbgDeclareForAlloca(AI, NewAllocaPtr, DIB); 1574 AI->replaceAllUsesWith(NewAllocaPtr); 1575 } 1576 1577 // The left-most redzone has enough space for at least 4 pointers. 1578 // Write the Magic value to redzone[0]. 1579 Value *BasePlus0 = IRB.CreateIntToPtr(LocalStackBase, IntptrPtrTy); 1580 IRB.CreateStore(ConstantInt::get(IntptrTy, kCurrentStackFrameMagic), 1581 BasePlus0); 1582 // Write the frame description constant to redzone[1]. 1583 Value *BasePlus1 = IRB.CreateIntToPtr( 1584 IRB.CreateAdd(LocalStackBase, ConstantInt::get(IntptrTy, ASan.LongSize/8)), 1585 IntptrPtrTy); 1586 GlobalVariable *StackDescriptionGlobal = 1587 createPrivateGlobalForString(*F.getParent(), L.DescriptionString, 1588 /*AllowMerging*/true); 1589 Value *Description = IRB.CreatePointerCast(StackDescriptionGlobal, 1590 IntptrTy); 1591 IRB.CreateStore(Description, BasePlus1); 1592 // Write the PC to redzone[2]. 1593 Value *BasePlus2 = IRB.CreateIntToPtr( 1594 IRB.CreateAdd(LocalStackBase, ConstantInt::get(IntptrTy, 1595 2 * ASan.LongSize/8)), 1596 IntptrPtrTy); 1597 IRB.CreateStore(IRB.CreatePointerCast(&F, IntptrTy), BasePlus2); 1598 1599 // Poison the stack redzones at the entry. 1600 Value *ShadowBase = ASan.memToShadow(LocalStackBase, IRB); 1601 poisonRedZones(L.ShadowBytes, IRB, ShadowBase, true); 1602 1603 // (Un)poison the stack before all ret instructions. 1604 for (size_t i = 0, n = RetVec.size(); i < n; i++) { 1605 Instruction *Ret = RetVec[i]; 1606 IRBuilder<> IRBRet(Ret); 1607 // Mark the current frame as retired. 1608 IRBRet.CreateStore(ConstantInt::get(IntptrTy, kRetiredStackFrameMagic), 1609 BasePlus0); 1610 if (DoStackMalloc) { 1611 assert(StackMallocIdx >= 0); 1612 // if LocalStackBase != OrigStackBase: 1613 // // In use-after-return mode, poison the whole stack frame. 1614 // if StackMallocIdx <= 4 1615 // // For small sizes inline the whole thing: 1616 // memset(ShadowBase, kAsanStackAfterReturnMagic, ShadowSize); 1617 // **SavedFlagPtr(LocalStackBase) = 0 1618 // else 1619 // __asan_stack_free_N(LocalStackBase, OrigStackBase) 1620 // else 1621 // <This is not a fake stack; unpoison the redzones> 1622 Value *Cmp = IRBRet.CreateICmpNE(LocalStackBase, OrigStackBase); 1623 TerminatorInst *ThenTerm, *ElseTerm; 1624 SplitBlockAndInsertIfThenElse(Cmp, Ret, &ThenTerm, &ElseTerm); 1625 1626 IRBuilder<> IRBPoison(ThenTerm); 1627 if (StackMallocIdx <= 4) { 1628 int ClassSize = kMinStackMallocSize << StackMallocIdx; 1629 SetShadowToStackAfterReturnInlined(IRBPoison, ShadowBase, 1630 ClassSize >> Mapping.Scale); 1631 Value *SavedFlagPtrPtr = IRBPoison.CreateAdd( 1632 LocalStackBase, 1633 ConstantInt::get(IntptrTy, ClassSize - ASan.LongSize / 8)); 1634 Value *SavedFlagPtr = IRBPoison.CreateLoad( 1635 IRBPoison.CreateIntToPtr(SavedFlagPtrPtr, IntptrPtrTy)); 1636 IRBPoison.CreateStore( 1637 Constant::getNullValue(IRBPoison.getInt8Ty()), 1638 IRBPoison.CreateIntToPtr(SavedFlagPtr, IRBPoison.getInt8PtrTy())); 1639 } else { 1640 // For larger frames call __asan_stack_free_*. 1641 IRBPoison.CreateCall3(AsanStackFreeFunc[StackMallocIdx], LocalStackBase, 1642 ConstantInt::get(IntptrTy, LocalStackSize), 1643 OrigStackBase); 1644 } 1645 1646 IRBuilder<> IRBElse(ElseTerm); 1647 poisonRedZones(L.ShadowBytes, IRBElse, ShadowBase, false); 1648 } else if (HavePoisonedAllocas) { 1649 // If we poisoned some allocas in llvm.lifetime analysis, 1650 // unpoison whole stack frame now. 1651 assert(LocalStackBase == OrigStackBase); 1652 poisonAlloca(LocalStackBase, LocalStackSize, IRBRet, false); 1653 } else { 1654 poisonRedZones(L.ShadowBytes, IRBRet, ShadowBase, false); 1655 } 1656 } 1657 1658 // We are done. Remove the old unused alloca instructions. 1659 for (size_t i = 0, n = AllocaVec.size(); i < n; i++) 1660 AllocaVec[i]->eraseFromParent(); 1661 } 1662 1663 void FunctionStackPoisoner::poisonAlloca(Value *V, uint64_t Size, 1664 IRBuilder<> &IRB, bool DoPoison) { 1665 // For now just insert the call to ASan runtime. 1666 Value *AddrArg = IRB.CreatePointerCast(V, IntptrTy); 1667 Value *SizeArg = ConstantInt::get(IntptrTy, Size); 1668 IRB.CreateCall2(DoPoison ? AsanPoisonStackMemoryFunc 1669 : AsanUnpoisonStackMemoryFunc, 1670 AddrArg, SizeArg); 1671 } 1672 1673 // Handling llvm.lifetime intrinsics for a given %alloca: 1674 // (1) collect all llvm.lifetime.xxx(%size, %value) describing the alloca. 1675 // (2) if %size is constant, poison memory for llvm.lifetime.end (to detect 1676 // invalid accesses) and unpoison it for llvm.lifetime.start (the memory 1677 // could be poisoned by previous llvm.lifetime.end instruction, as the 1678 // variable may go in and out of scope several times, e.g. in loops). 1679 // (3) if we poisoned at least one %alloca in a function, 1680 // unpoison the whole stack frame at function exit. 1681 1682 AllocaInst *FunctionStackPoisoner::findAllocaForValue(Value *V) { 1683 if (AllocaInst *AI = dyn_cast<AllocaInst>(V)) 1684 // We're intested only in allocas we can handle. 1685 return isInterestingAlloca(*AI) ? AI : 0; 1686 // See if we've already calculated (or started to calculate) alloca for a 1687 // given value. 1688 AllocaForValueMapTy::iterator I = AllocaForValue.find(V); 1689 if (I != AllocaForValue.end()) 1690 return I->second; 1691 // Store 0 while we're calculating alloca for value V to avoid 1692 // infinite recursion if the value references itself. 1693 AllocaForValue[V] = 0; 1694 AllocaInst *Res = 0; 1695 if (CastInst *CI = dyn_cast<CastInst>(V)) 1696 Res = findAllocaForValue(CI->getOperand(0)); 1697 else if (PHINode *PN = dyn_cast<PHINode>(V)) { 1698 for (unsigned i = 0, e = PN->getNumIncomingValues(); i != e; ++i) { 1699 Value *IncValue = PN->getIncomingValue(i); 1700 // Allow self-referencing phi-nodes. 1701 if (IncValue == PN) continue; 1702 AllocaInst *IncValueAI = findAllocaForValue(IncValue); 1703 // AI for incoming values should exist and should all be equal. 1704 if (IncValueAI == 0 || (Res != 0 && IncValueAI != Res)) 1705 return 0; 1706 Res = IncValueAI; 1707 } 1708 } 1709 if (Res != 0) 1710 AllocaForValue[V] = Res; 1711 return Res; 1712 } 1713