1//===-- sanitizer_coverage_libcdep_new.cpp --------------------------------===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8// Sanitizer Coverage Controller for Trace PC Guard.
9
10#include "sanitizer_platform.h"
11
12#if !SANITIZER_FUCHSIA
13#include "sancov_flags.h"
14#include "sanitizer_allocator_internal.h"
15#include "sanitizer_atomic.h"
16#include "sanitizer_common.h"
17#include "sanitizer_file.h"
18
19using namespace __sanitizer;
20
21using AddressRange = LoadedModule::AddressRange;
22
23namespace __sancov {
24namespace {
25
26static const u64 Magic64 = 0xC0BFFFFFFFFFFF64ULL;
27static const u64 Magic32 = 0xC0BFFFFFFFFFFF32ULL;
28static const u64 Magic = SANITIZER_WORDSIZE == 64 ? Magic64 : Magic32;
29
30static fd_t OpenFile(const char* path) {
31  error_t err;
32  fd_t fd = OpenFile(path, WrOnly, &err);
33  if (fd == kInvalidFd)
34    Report("SanitizerCoverage: failed to open %s for writing (reason: %d)\n",
35           path, err);
36  return fd;
37}
38
39static void GetCoverageFilename(char* path, const char* name,
40                                const char* extension) {
41  CHECK(name);
42  internal_snprintf(path, kMaxPathLength, "%s/%s.%zd.%s",
43                    common_flags()->coverage_dir, name, internal_getpid(),
44                    extension);
45}
46
47static void WriteModuleCoverage(char* file_path, const char* module_name,
48                                const uptr* pcs, uptr len) {
49  GetCoverageFilename(file_path, StripModuleName(module_name), "sancov");
50  fd_t fd = OpenFile(file_path);
51  WriteToFile(fd, &Magic, sizeof(Magic));
52  WriteToFile(fd, pcs, len * sizeof(*pcs));
53  CloseFile(fd);
54  Printf("SanitizerCoverage: %s: %zd PCs written\n", file_path, len);
55}
56
57static void SanitizerDumpCoverage(const uptr* unsorted_pcs, uptr len) {
58  if (!len) return;
59
60  char* file_path = static_cast<char*>(InternalAlloc(kMaxPathLength));
61  char* module_name = static_cast<char*>(InternalAlloc(kMaxPathLength));
62  uptr* pcs = static_cast<uptr*>(InternalAlloc(len * sizeof(uptr)));
63
64  internal_memcpy(pcs, unsorted_pcs, len * sizeof(uptr));
65  Sort(pcs, len);
66
67  bool module_found = false;
68  uptr last_base = 0;
69  uptr module_start_idx = 0;
70
71  for (uptr i = 0; i < len; ++i) {
72    const uptr pc = pcs[i];
73    if (!pc) continue;
74
75    if (!__sanitizer_get_module_and_offset_for_pc(pc, nullptr, 0, &pcs[i])) {
76      Printf("ERROR: unknown pc 0x%x (may happen if dlclose is used)\n", pc);
77      continue;
78    }
79    uptr module_base = pc - pcs[i];
80
81    if (module_base != last_base || !module_found) {
82      if (module_found) {
83        WriteModuleCoverage(file_path, module_name, &pcs[module_start_idx],
84                            i - module_start_idx);
85      }
86
87      last_base = module_base;
88      module_start_idx = i;
89      module_found = true;
90      __sanitizer_get_module_and_offset_for_pc(pc, module_name, kMaxPathLength,
91                                               &pcs[i]);
92    }
93  }
94
95  if (module_found) {
96    WriteModuleCoverage(file_path, module_name, &pcs[module_start_idx],
97                        len - module_start_idx);
98  }
99
100  InternalFree(file_path);
101  InternalFree(module_name);
102  InternalFree(pcs);
103}
104
105// Collects trace-pc guard coverage.
106// This class relies on zero-initialization.
107class TracePcGuardController {
108 public:
109  void Initialize() {
110    CHECK(!initialized);
111
112    initialized = true;
113    InitializeSancovFlags();
114
115    pc_vector.Initialize(0);
116  }
117
118  void InitTracePcGuard(u32* start, u32* end) {
119    if (!initialized) Initialize();
120    CHECK(!*start);
121    CHECK_NE(start, end);
122
123    u32 i = pc_vector.size();
124    for (u32* p = start; p < end; p++) *p = ++i;
125    pc_vector.resize(i);
126  }
127
128  void TracePcGuard(u32* guard, uptr pc) {
129    u32 idx = *guard;
130    if (!idx) return;
131    // we start indices from 1.
132    atomic_uintptr_t* pc_ptr =
133        reinterpret_cast<atomic_uintptr_t*>(&pc_vector[idx - 1]);
134    if (atomic_load(pc_ptr, memory_order_relaxed) == 0)
135      atomic_store(pc_ptr, pc, memory_order_relaxed);
136  }
137
138  void Reset() {
139    internal_memset(&pc_vector[0], 0, sizeof(pc_vector[0]) * pc_vector.size());
140  }
141
142  void Dump() {
143    if (!initialized || !common_flags()->coverage) return;
144    __sanitizer_dump_coverage(pc_vector.data(), pc_vector.size());
145  }
146
147 private:
148  bool initialized;
149  InternalMmapVectorNoCtor<uptr> pc_vector;
150};
151
152static TracePcGuardController pc_guard_controller;
153
154}  // namespace
155}  // namespace __sancov
156
157namespace __sanitizer {
158void InitializeCoverage(bool enabled, const char *dir) {
159  static bool coverage_enabled = false;
160  if (coverage_enabled)
161    return;  // May happen if two sanitizer enable coverage in the same process.
162  coverage_enabled = enabled;
163  Atexit(__sanitizer_cov_dump);
164  AddDieCallback(__sanitizer_cov_dump);
165}
166} // namespace __sanitizer
167
168extern "C" {
169SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_dump_coverage(const uptr* pcs,
170                                                             uptr len) {
171  return __sancov::SanitizerDumpCoverage(pcs, len);
172}
173
174SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard, u32* guard) {
175  if (!*guard) return;
176  __sancov::pc_guard_controller.TracePcGuard(guard, GET_CALLER_PC() - 1);
177}
178
179SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_guard_init,
180                             u32* start, u32* end) {
181  if (start == end || *start) return;
182  __sancov::pc_guard_controller.InitTracePcGuard(start, end);
183}
184
185SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_dump_trace_pc_guard_coverage() {
186  __sancov::pc_guard_controller.Dump();
187}
188SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_cov_dump() {
189  __sanitizer_dump_trace_pc_guard_coverage();
190}
191SANITIZER_INTERFACE_ATTRIBUTE void __sanitizer_cov_reset() {
192  __sancov::pc_guard_controller.Reset();
193}
194// Default empty implementations (weak). Users should redefine them.
195SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp, void) {}
196SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp1, void) {}
197SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp2, void) {}
198SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp4, void) {}
199SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_cmp8, void) {}
200SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp1, void) {}
201SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp2, void) {}
202SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp4, void) {}
203SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_const_cmp8, void) {}
204SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_switch, void) {}
205SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_div4, void) {}
206SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_div8, void) {}
207SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_gep, void) {}
208SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_trace_pc_indir, void) {}
209SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_8bit_counters_init, void) {}
210SANITIZER_INTERFACE_WEAK_DEF(void, __sanitizer_cov_pcs_init, void) {}
211}  // extern "C"
212// Weak definition for code instrumented with -fsanitize-coverage=stack-depth
213// and later linked with code containing a strong definition.
214// E.g., -fsanitize=fuzzer-no-link
215SANITIZER_INTERFACE_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
216SANITIZER_TLS_INITIAL_EXEC_ATTRIBUTE uptr __sancov_lowest_stack;
217
218#endif  // !SANITIZER_FUCHSIA
219