Home | History | Annotate | Line # | Download | only in asan
      1 //===-- asan_interceptors.cpp ---------------------------------------------===//
      2 //
      3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
      4 // See https://llvm.org/LICENSE.txt for license information.
      5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
      6 //
      7 //===----------------------------------------------------------------------===//
      8 //
      9 // This file is a part of AddressSanitizer, an address sanity checker.
     10 //
     11 // Interceptors for operators new and delete.
     12 //===----------------------------------------------------------------------===//
     13 
     14 #include <stddef.h>
     15 
     16 #include "asan_allocator.h"
     17 #include "asan_internal.h"
     18 #include "asan_report.h"
     19 #include "asan_stack.h"
     20 #include "interception/interception.h"
     21 
     22 // C++ operators can't have dllexport attributes on Windows. We export them
     23 // anyway by passing extra -export flags to the linker, which is exactly that
     24 // dllexport would normally do. We need to export them in order to make the
     25 // VS2015 dynamic CRT (MD) work.
     26 #if SANITIZER_WINDOWS && defined(_MSC_VER)
     27 #define CXX_OPERATOR_ATTRIBUTE
     28 #define COMMENT_EXPORT(sym) __pragma(comment(linker, "/export:" sym))
     29 #ifdef _WIN64
     30 COMMENT_EXPORT("??2@YAPEAX_K@Z")                     // operator new
     31 COMMENT_EXPORT("??2@YAPEAX_KAEBUnothrow_t@std@@@Z")  // operator new nothrow
     32 COMMENT_EXPORT("??3@YAXPEAX@Z")                      // operator delete
     33 COMMENT_EXPORT("??3@YAXPEAX_K@Z")                    // sized operator delete
     34 COMMENT_EXPORT("??_U@YAPEAX_K@Z")                    // operator new[]
     35 COMMENT_EXPORT("??_V@YAXPEAX@Z")                     // operator delete[]
     36 #else
     37 COMMENT_EXPORT("??2@YAPAXI@Z")                    // operator new
     38 COMMENT_EXPORT("??2@YAPAXIABUnothrow_t@std@@@Z")  // operator new nothrow
     39 COMMENT_EXPORT("??3@YAXPAX@Z")                    // operator delete
     40 COMMENT_EXPORT("??3@YAXPAXI@Z")                   // sized operator delete
     41 COMMENT_EXPORT("??_U@YAPAXI@Z")                   // operator new[]
     42 COMMENT_EXPORT("??_V@YAXPAX@Z")                   // operator delete[]
     43 #endif
     44 #undef COMMENT_EXPORT
     45 #else
     46 #define CXX_OPERATOR_ATTRIBUTE INTERCEPTOR_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
     47 #endif
     48 
     49 using namespace __asan;
     50 
     51 // FreeBSD prior v9.2 have wrong definition of 'size_t'.
     52 // http://svnweb.freebsd.org/base?view=revision&revision=232261
     53 #if SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32
     54 #include <sys/param.h>
     55 #if __FreeBSD_version <= 902001  // v9.2
     56 #define size_t unsigned
     57 #endif  // __FreeBSD_version
     58 #endif  // SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32
     59 
     60 // This code has issues on OSX.
     61 // See https://github.com/google/sanitizers/issues/131.
     62 
     63 // Fake std::nothrow_t and std::align_val_t to avoid including <new>.
     64 namespace std {
     65 struct nothrow_t {};
     66 enum class align_val_t: size_t {};
     67 }  // namespace std
     68 
     69 // TODO(alekseyshl): throw std::bad_alloc instead of dying on OOM.
     70 // For local pool allocation, align to SHADOW_GRANULARITY to match asan
     71 // allocator behavior.
     72 #define OPERATOR_NEW_BODY(type, nothrow)            \
     73   GET_STACK_TRACE_MALLOC;                           \
     74   void *res = asan_memalign(0, size, &stack, type); \
     75   if (!nothrow && UNLIKELY(!res))                   \
     76     ReportOutOfMemory(size, &stack);                \
     77   return res;
     78 #define OPERATOR_NEW_BODY_ALIGN(type, nothrow)                \
     79   GET_STACK_TRACE_MALLOC;                                     \
     80   void *res = asan_memalign((uptr)align, size, &stack, type); \
     81   if (!nothrow && UNLIKELY(!res))                             \
     82     ReportOutOfMemory(size, &stack);                          \
     83   return res;
     84 
     85 // On OS X it's not enough to just provide our own 'operator new' and
     86 // 'operator delete' implementations, because they're going to be in the
     87 // runtime dylib, and the main executable will depend on both the runtime
     88 // dylib and libstdc++, each of those'll have its implementation of new and
     89 // delete.
     90 // To make sure that C++ allocation/deallocation operators are overridden on
     91 // OS X we need to intercept them using their mangled names.
     92 #if !SANITIZER_APPLE
     93 CXX_OPERATOR_ATTRIBUTE
     94 void *operator new(size_t size)
     95 { OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/); }
     96 CXX_OPERATOR_ATTRIBUTE
     97 void *operator new[](size_t size)
     98 { OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/); }
     99 CXX_OPERATOR_ATTRIBUTE
    100 void *operator new(size_t size, std::nothrow_t const&)
    101 { OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/); }
    102 CXX_OPERATOR_ATTRIBUTE
    103 void *operator new[](size_t size, std::nothrow_t const&)
    104 { OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/); }
    105 CXX_OPERATOR_ATTRIBUTE
    106 void *operator new(size_t size, std::align_val_t align)
    107 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, false /*nothrow*/); }
    108 CXX_OPERATOR_ATTRIBUTE
    109 void *operator new[](size_t size, std::align_val_t align)
    110 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, false /*nothrow*/); }
    111 CXX_OPERATOR_ATTRIBUTE
    112 void *operator new(size_t size, std::align_val_t align, std::nothrow_t const&)
    113 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, true /*nothrow*/); }
    114 CXX_OPERATOR_ATTRIBUTE
    115 void *operator new[](size_t size, std::align_val_t align, std::nothrow_t const&)
    116 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, true /*nothrow*/); }
    117 
    118 #else  // SANITIZER_APPLE
    119 INTERCEPTOR(void *, _Znwm, size_t size) {
    120   OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/);
    121 }
    122 INTERCEPTOR(void *, _Znam, size_t size) {
    123   OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/);
    124 }
    125 INTERCEPTOR(void *, _ZnwmRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
    126   OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/);
    127 }
    128 INTERCEPTOR(void *, _ZnamRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
    129   OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/);
    130 }
    131 #endif  // !SANITIZER_APPLE
    132 
    133 #define OPERATOR_DELETE_BODY(type) \
    134   GET_STACK_TRACE_FREE;            \
    135   asan_delete(ptr, 0, 0, &stack, type);
    136 
    137 #define OPERATOR_DELETE_BODY_SIZE(type) \
    138   GET_STACK_TRACE_FREE;                 \
    139   asan_delete(ptr, size, 0, &stack, type);
    140 
    141 #define OPERATOR_DELETE_BODY_ALIGN(type) \
    142   GET_STACK_TRACE_FREE;                  \
    143   asan_delete(ptr, 0, static_cast<uptr>(align), &stack, type);
    144 
    145 #define OPERATOR_DELETE_BODY_SIZE_ALIGN(type) \
    146   GET_STACK_TRACE_FREE;                       \
    147   asan_delete(ptr, size, static_cast<uptr>(align), &stack, type);
    148 
    149 #if !SANITIZER_APPLE
    150 CXX_OPERATOR_ATTRIBUTE
    151 void operator delete(void *ptr) NOEXCEPT
    152 { OPERATOR_DELETE_BODY(FROM_NEW); }
    153 CXX_OPERATOR_ATTRIBUTE
    154 void operator delete[](void *ptr) NOEXCEPT
    155 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
    156 CXX_OPERATOR_ATTRIBUTE
    157 void operator delete(void *ptr, std::nothrow_t const&)
    158 { OPERATOR_DELETE_BODY(FROM_NEW); }
    159 CXX_OPERATOR_ATTRIBUTE
    160 void operator delete[](void *ptr, std::nothrow_t const&)
    161 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
    162 CXX_OPERATOR_ATTRIBUTE
    163 void operator delete(void *ptr, size_t size) NOEXCEPT
    164 { OPERATOR_DELETE_BODY_SIZE(FROM_NEW); }
    165 CXX_OPERATOR_ATTRIBUTE
    166 void operator delete[](void *ptr, size_t size) NOEXCEPT
    167 { OPERATOR_DELETE_BODY_SIZE(FROM_NEW_BR); }
    168 CXX_OPERATOR_ATTRIBUTE
    169 void operator delete(void *ptr, std::align_val_t align) NOEXCEPT
    170 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); }
    171 CXX_OPERATOR_ATTRIBUTE
    172 void operator delete[](void *ptr, std::align_val_t align) NOEXCEPT
    173 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); }
    174 CXX_OPERATOR_ATTRIBUTE
    175 void operator delete(void *ptr, std::align_val_t align, std::nothrow_t const&)
    176 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); }
    177 CXX_OPERATOR_ATTRIBUTE
    178 void operator delete[](void *ptr, std::align_val_t align, std::nothrow_t const&)
    179 { OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); }
    180 CXX_OPERATOR_ATTRIBUTE
    181 void operator delete(void *ptr, size_t size, std::align_val_t align) NOEXCEPT
    182 { OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW); }
    183 CXX_OPERATOR_ATTRIBUTE
    184 void operator delete[](void *ptr, size_t size, std::align_val_t align) NOEXCEPT
    185 { OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW_BR); }
    186 
    187 #else  // SANITIZER_APPLE
    188 INTERCEPTOR(void, _ZdlPv, void *ptr)
    189 { OPERATOR_DELETE_BODY(FROM_NEW); }
    190 INTERCEPTOR(void, _ZdaPv, void *ptr)
    191 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
    192 INTERCEPTOR(void, _ZdlPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&)
    193 { OPERATOR_DELETE_BODY(FROM_NEW); }
    194 INTERCEPTOR(void, _ZdaPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&)
    195 { OPERATOR_DELETE_BODY(FROM_NEW_BR); }
    196 #endif  // !SANITIZER_APPLE
    197