1//===-- asan_interceptors.cpp ---------------------------------------------===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8//
9// This file is a part of AddressSanitizer, an address sanity checker.
10//
11// Interceptors for operators new and delete.
12//===----------------------------------------------------------------------===//
13
14#include <stddef.h>
15
16#include "asan_allocator.h"
17#include "asan_internal.h"
18#include "asan_report.h"
19#include "asan_stack.h"
20#include "interception/interception.h"
21
22// C++ operators can't have dllexport attributes on Windows. We export them
23// anyway by passing extra -export flags to the linker, which is exactly that
24// dllexport would normally do. We need to export them in order to make the
25// VS2015 dynamic CRT (MD) work.
26#if SANITIZER_WINDOWS && defined(_MSC_VER)
27#define CXX_OPERATOR_ATTRIBUTE
28#define COMMENT_EXPORT(sym) __pragma(comment(linker, "/export:" sym))
29#ifdef _WIN64
30COMMENT_EXPORT("??2@YAPEAX_K@Z")                     // operator new
31COMMENT_EXPORT("??2@YAPEAX_KAEBUnothrow_t@std@@@Z")  // operator new nothrow
32COMMENT_EXPORT("??3@YAXPEAX@Z")                      // operator delete
33COMMENT_EXPORT("??3@YAXPEAX_K@Z")                    // sized operator delete
34COMMENT_EXPORT("??_U@YAPEAX_K@Z")                    // operator new[]
35COMMENT_EXPORT("??_V@YAXPEAX@Z")                     // operator delete[]
36#else
37COMMENT_EXPORT("??2@YAPAXI@Z")                    // operator new
38COMMENT_EXPORT("??2@YAPAXIABUnothrow_t@std@@@Z")  // operator new nothrow
39COMMENT_EXPORT("??3@YAXPAX@Z")                    // operator delete
40COMMENT_EXPORT("??3@YAXPAXI@Z")                   // sized operator delete
41COMMENT_EXPORT("??_U@YAPAXI@Z")                   // operator new[]
42COMMENT_EXPORT("??_V@YAXPAX@Z")                   // operator delete[]
43#endif
44#undef COMMENT_EXPORT
45#else
46#define CXX_OPERATOR_ATTRIBUTE INTERCEPTOR_ATTRIBUTE SANITIZER_WEAK_ATTRIBUTE
47#endif
48
49using namespace __asan;
50
51// FreeBSD prior v9.2 have wrong definition of 'size_t'.
52// http://svnweb.freebsd.org/base?view=revision&revision=232261
53#if SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32
54#include <sys/param.h>
55#if __FreeBSD_version <= 902001  // v9.2
56#define size_t unsigned
57#endif  // __FreeBSD_version
58#endif  // SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32
59
60// This code has issues on OSX.
61// See https://github.com/google/sanitizers/issues/131.
62
63// Fake std::nothrow_t and std::align_val_t to avoid including <new>.
64namespace std {
65struct nothrow_t {};
66enum class align_val_t: size_t {};
67}  // namespace std
68
69// TODO(alekseyshl): throw std::bad_alloc instead of dying on OOM.
70// For local pool allocation, align to SHADOW_GRANULARITY to match asan
71// allocator behavior.
72#define OPERATOR_NEW_BODY(type, nothrow)            \
73  GET_STACK_TRACE_MALLOC;                           \
74  void *res = asan_memalign(0, size, &stack, type); \
75  if (!nothrow && UNLIKELY(!res))                   \
76    ReportOutOfMemory(size, &stack);                \
77  return res;
78#define OPERATOR_NEW_BODY_ALIGN(type, nothrow)                \
79  GET_STACK_TRACE_MALLOC;                                     \
80  void *res = asan_memalign((uptr)align, size, &stack, type); \
81  if (!nothrow && UNLIKELY(!res))                             \
82    ReportOutOfMemory(size, &stack);                          \
83  return res;
84
85// On OS X it's not enough to just provide our own 'operator new' and
86// 'operator delete' implementations, because they're going to be in the
87// runtime dylib, and the main executable will depend on both the runtime
88// dylib and libstdc++, each of those'll have its implementation of new and
89// delete.
90// To make sure that C++ allocation/deallocation operators are overridden on
91// OS X we need to intercept them using their mangled names.
92#if !SANITIZER_APPLE
93CXX_OPERATOR_ATTRIBUTE
94void *operator new(size_t size)
95{ OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/); }
96CXX_OPERATOR_ATTRIBUTE
97void *operator new[](size_t size)
98{ OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/); }
99CXX_OPERATOR_ATTRIBUTE
100void *operator new(size_t size, std::nothrow_t const&)
101{ OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/); }
102CXX_OPERATOR_ATTRIBUTE
103void *operator new[](size_t size, std::nothrow_t const&)
104{ OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/); }
105CXX_OPERATOR_ATTRIBUTE
106void *operator new(size_t size, std::align_val_t align)
107{ OPERATOR_NEW_BODY_ALIGN(FROM_NEW, false /*nothrow*/); }
108CXX_OPERATOR_ATTRIBUTE
109void *operator new[](size_t size, std::align_val_t align)
110{ OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, false /*nothrow*/); }
111CXX_OPERATOR_ATTRIBUTE
112void *operator new(size_t size, std::align_val_t align, std::nothrow_t const&)
113{ OPERATOR_NEW_BODY_ALIGN(FROM_NEW, true /*nothrow*/); }
114CXX_OPERATOR_ATTRIBUTE
115void *operator new[](size_t size, std::align_val_t align, std::nothrow_t const&)
116{ OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, true /*nothrow*/); }
117
118#else  // SANITIZER_APPLE
119INTERCEPTOR(void *, _Znwm, size_t size) {
120  OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/);
121}
122INTERCEPTOR(void *, _Znam, size_t size) {
123  OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/);
124}
125INTERCEPTOR(void *, _ZnwmRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
126  OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/);
127}
128INTERCEPTOR(void *, _ZnamRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
129  OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/);
130}
131#endif  // !SANITIZER_APPLE
132
133#define OPERATOR_DELETE_BODY(type) \
134  GET_STACK_TRACE_FREE;            \
135  asan_delete(ptr, 0, 0, &stack, type);
136
137#define OPERATOR_DELETE_BODY_SIZE(type) \
138  GET_STACK_TRACE_FREE;                 \
139  asan_delete(ptr, size, 0, &stack, type);
140
141#define OPERATOR_DELETE_BODY_ALIGN(type) \
142  GET_STACK_TRACE_FREE;                  \
143  asan_delete(ptr, 0, static_cast<uptr>(align), &stack, type);
144
145#define OPERATOR_DELETE_BODY_SIZE_ALIGN(type) \
146  GET_STACK_TRACE_FREE;                       \
147  asan_delete(ptr, size, static_cast<uptr>(align), &stack, type);
148
149#if !SANITIZER_APPLE
150CXX_OPERATOR_ATTRIBUTE
151void operator delete(void *ptr) NOEXCEPT
152{ OPERATOR_DELETE_BODY(FROM_NEW); }
153CXX_OPERATOR_ATTRIBUTE
154void operator delete[](void *ptr) NOEXCEPT
155{ OPERATOR_DELETE_BODY(FROM_NEW_BR); }
156CXX_OPERATOR_ATTRIBUTE
157void operator delete(void *ptr, std::nothrow_t const&)
158{ OPERATOR_DELETE_BODY(FROM_NEW); }
159CXX_OPERATOR_ATTRIBUTE
160void operator delete[](void *ptr, std::nothrow_t const&)
161{ OPERATOR_DELETE_BODY(FROM_NEW_BR); }
162CXX_OPERATOR_ATTRIBUTE
163void operator delete(void *ptr, size_t size) NOEXCEPT
164{ OPERATOR_DELETE_BODY_SIZE(FROM_NEW); }
165CXX_OPERATOR_ATTRIBUTE
166void operator delete[](void *ptr, size_t size) NOEXCEPT
167{ OPERATOR_DELETE_BODY_SIZE(FROM_NEW_BR); }
168CXX_OPERATOR_ATTRIBUTE
169void operator delete(void *ptr, std::align_val_t align) NOEXCEPT
170{ OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); }
171CXX_OPERATOR_ATTRIBUTE
172void operator delete[](void *ptr, std::align_val_t align) NOEXCEPT
173{ OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); }
174CXX_OPERATOR_ATTRIBUTE
175void operator delete(void *ptr, std::align_val_t align, std::nothrow_t const&)
176{ OPERATOR_DELETE_BODY_ALIGN(FROM_NEW); }
177CXX_OPERATOR_ATTRIBUTE
178void operator delete[](void *ptr, std::align_val_t align, std::nothrow_t const&)
179{ OPERATOR_DELETE_BODY_ALIGN(FROM_NEW_BR); }
180CXX_OPERATOR_ATTRIBUTE
181void operator delete(void *ptr, size_t size, std::align_val_t align) NOEXCEPT
182{ OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW); }
183CXX_OPERATOR_ATTRIBUTE
184void operator delete[](void *ptr, size_t size, std::align_val_t align) NOEXCEPT
185{ OPERATOR_DELETE_BODY_SIZE_ALIGN(FROM_NEW_BR); }
186
187#else  // SANITIZER_APPLE
188INTERCEPTOR(void, _ZdlPv, void *ptr)
189{ OPERATOR_DELETE_BODY(FROM_NEW); }
190INTERCEPTOR(void, _ZdaPv, void *ptr)
191{ OPERATOR_DELETE_BODY(FROM_NEW_BR); }
192INTERCEPTOR(void, _ZdlPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&)
193{ OPERATOR_DELETE_BODY(FROM_NEW); }
194INTERCEPTOR(void, _ZdaPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&)
195{ OPERATOR_DELETE_BODY(FROM_NEW_BR); }
196#endif  // !SANITIZER_APPLE
197