1 //===-- asan_interceptors.cc ----------------------------------------------===//
2 //
3 // This file is distributed under the University of Illinois Open Source
4 // License. See LICENSE.TXT for details.
5 //
6 //===----------------------------------------------------------------------===//
7 //
8 // This file is a part of AddressSanitizer, an address sanity checker.
9 //
10 // Interceptors for operators new and delete.
11 //===----------------------------------------------------------------------===//
12 
13 #include "asan_allocator.h"
14 #include "asan_internal.h"
15 #include "asan_stack.h"
16 
17 #include "interception/interception.h"
18 
19 #include <stddef.h>
20 
21 // C++ operators can't have dllexport attributes on Windows. We export them
22 // anyway by passing extra -export flags to the linker, which is exactly that
23 // dllexport would normally do. We need to export them in order to make the
24 // VS2015 dynamic CRT (MD) work.
25 #if SANITIZER_WINDOWS
26 #define CXX_OPERATOR_ATTRIBUTE
27 #define COMMENT_EXPORT(sym) __pragma(comment(linker, "/export:" sym))
28 #ifdef _WIN64
29 COMMENT_EXPORT("??2@YAPEAX_K@Z")                     // operator new
30 COMMENT_EXPORT("??2@YAPEAX_KAEBUnothrow_t@std@@@Z")  // operator new nothrow
31 COMMENT_EXPORT("??3@YAXPEAX@Z")                      // operator delete
32 COMMENT_EXPORT("??3@YAXPEAX_K@Z")                    // sized operator delete
33 COMMENT_EXPORT("??_U@YAPEAX_K@Z")                    // operator new[]
34 COMMENT_EXPORT("??_V@YAXPEAX@Z")                     // operator delete[]
35 #else
36 COMMENT_EXPORT("??2@YAPAXI@Z")                    // operator new
37 COMMENT_EXPORT("??2@YAPAXIABUnothrow_t@std@@@Z")  // operator new nothrow
38 COMMENT_EXPORT("??3@YAXPAX@Z")                    // operator delete
39 COMMENT_EXPORT("??3@YAXPAXI@Z")                   // sized operator delete
40 COMMENT_EXPORT("??_U@YAPAXI@Z")                   // operator new[]
41 COMMENT_EXPORT("??_V@YAXPAX@Z")                   // operator delete[]
42 #endif
43 #undef COMMENT_EXPORT
44 #else
45 #define CXX_OPERATOR_ATTRIBUTE INTERCEPTOR_ATTRIBUTE
46 #endif
47 
48 using namespace __asan;  // NOLINT
49 
50 // FreeBSD prior v9.2 have wrong definition of 'size_t'.
51 // http://svnweb.freebsd.org/base?view=revision&revision=232261
52 #if SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32
53 #include <sys/param.h>
54 #if __FreeBSD_version <= 902001  // v9.2
55 #define size_t unsigned
56 #endif  // __FreeBSD_version
57 #endif  // SANITIZER_FREEBSD && SANITIZER_WORDSIZE == 32
58 
59 // This code has issues on OSX.
60 // See https://github.com/google/sanitizers/issues/131.
61 
62 // Fake std::nothrow_t and std::align_val_t to avoid including <new>.
63 namespace std {
64 struct nothrow_t {};
65 enum class align_val_t: size_t {};
66 }  // namespace std
67 
68 // TODO(alekseys): throw std::bad_alloc instead of dying on OOM.
69 #define OPERATOR_NEW_BODY(type, nothrow) \
70   GET_STACK_TRACE_MALLOC;\
71   void *res = asan_memalign(0, size, &stack, type);\
72   if (!nothrow && UNLIKELY(!res)) DieOnFailure::OnOOM();\
73   return res;
74 #define OPERATOR_NEW_BODY_ALIGN(type, nothrow) \
75   GET_STACK_TRACE_MALLOC;\
76   void *res = asan_memalign((uptr)align, size, &stack, type);\
77   if (!nothrow && UNLIKELY(!res)) DieOnFailure::OnOOM();\
78   return res;
79 
80 // On OS X it's not enough to just provide our own 'operator new' and
81 // 'operator delete' implementations, because they're going to be in the
82 // runtime dylib, and the main executable will depend on both the runtime
83 // dylib and libstdc++, each of those'll have its implementation of new and
84 // delete.
85 // To make sure that C++ allocation/deallocation operators are overridden on
86 // OS X we need to intercept them using their mangled names.
87 #if !SANITIZER_MAC
88 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size)89 void *operator new(size_t size)
90 { OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/); }
91 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size)92 void *operator new[](size_t size)
93 { OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/); }
94 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size,std::nothrow_t const &)95 void *operator new(size_t size, std::nothrow_t const&)
96 { OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/); }
97 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size,std::nothrow_t const &)98 void *operator new[](size_t size, std::nothrow_t const&)
99 { OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/); }
100 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size,std::align_val_t align)101 void *operator new(size_t size, std::align_val_t align)
102 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, false /*nothrow*/); }
103 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size,std::align_val_t align)104 void *operator new[](size_t size, std::align_val_t align)
105 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, false /*nothrow*/); }
106 CXX_OPERATOR_ATTRIBUTE
operator new(size_t size,std::align_val_t align,std::nothrow_t const &)107 void *operator new(size_t size, std::align_val_t align, std::nothrow_t const&)
108 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW, true /*nothrow*/); }
109 CXX_OPERATOR_ATTRIBUTE
operator new[](size_t size,std::align_val_t align,std::nothrow_t const &)110 void *operator new[](size_t size, std::align_val_t align, std::nothrow_t const&)
111 { OPERATOR_NEW_BODY_ALIGN(FROM_NEW_BR, true /*nothrow*/); }
112 
113 #else  // SANITIZER_MAC
INTERCEPTOR(void *,_Znwm,size_t size)114 INTERCEPTOR(void *, _Znwm, size_t size) {
115   OPERATOR_NEW_BODY(FROM_NEW, false /*nothrow*/);
116 }
INTERCEPTOR(void *,_Znam,size_t size)117 INTERCEPTOR(void *, _Znam, size_t size) {
118   OPERATOR_NEW_BODY(FROM_NEW_BR, false /*nothrow*/);
119 }
INTERCEPTOR(void *,_ZnwmRKSt9nothrow_t,size_t size,std::nothrow_t const &)120 INTERCEPTOR(void *, _ZnwmRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
121   OPERATOR_NEW_BODY(FROM_NEW, true /*nothrow*/);
122 }
INTERCEPTOR(void *,_ZnamRKSt9nothrow_t,size_t size,std::nothrow_t const &)123 INTERCEPTOR(void *, _ZnamRKSt9nothrow_t, size_t size, std::nothrow_t const&) {
124   OPERATOR_NEW_BODY(FROM_NEW_BR, true /*nothrow*/);
125 }
126 #endif
127 
128 #define OPERATOR_DELETE_BODY(type) \
129   GET_STACK_TRACE_FREE;\
130   asan_free(ptr, &stack, type);
131 
132 #if !SANITIZER_MAC
133 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr)134 void operator delete(void *ptr) NOEXCEPT {
135   OPERATOR_DELETE_BODY(FROM_NEW);
136 }
137 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr)138 void operator delete[](void *ptr) NOEXCEPT {
139   OPERATOR_DELETE_BODY(FROM_NEW_BR);
140 }
141 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,std::nothrow_t const &)142 void operator delete(void *ptr, std::nothrow_t const&) {
143   OPERATOR_DELETE_BODY(FROM_NEW);
144 }
145 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,std::nothrow_t const &)146 void operator delete[](void *ptr, std::nothrow_t const&) {
147   OPERATOR_DELETE_BODY(FROM_NEW_BR);
148 }
149 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,size_t size)150 void operator delete(void *ptr, size_t size) NOEXCEPT {
151   GET_STACK_TRACE_FREE;
152   asan_sized_free(ptr, size, &stack, FROM_NEW);
153 }
154 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,size_t size)155 void operator delete[](void *ptr, size_t size) NOEXCEPT {
156   GET_STACK_TRACE_FREE;
157   asan_sized_free(ptr, size, &stack, FROM_NEW_BR);
158 }
159 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,std::align_val_t)160 void operator delete(void *ptr, std::align_val_t) NOEXCEPT {
161   OPERATOR_DELETE_BODY(FROM_NEW);
162 }
163 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,std::align_val_t)164 void operator delete[](void *ptr, std::align_val_t) NOEXCEPT {
165   OPERATOR_DELETE_BODY(FROM_NEW_BR);
166 }
167 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,std::align_val_t,std::nothrow_t const &)168 void operator delete(void *ptr, std::align_val_t, std::nothrow_t const&) {
169   OPERATOR_DELETE_BODY(FROM_NEW);
170 }
171 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,std::align_val_t,std::nothrow_t const &)172 void operator delete[](void *ptr, std::align_val_t, std::nothrow_t const&) {
173   OPERATOR_DELETE_BODY(FROM_NEW_BR);
174 }
175 CXX_OPERATOR_ATTRIBUTE
operator delete(void * ptr,size_t size,std::align_val_t)176 void operator delete(void *ptr, size_t size, std::align_val_t) NOEXCEPT {
177   GET_STACK_TRACE_FREE;
178   asan_sized_free(ptr, size, &stack, FROM_NEW);
179 }
180 CXX_OPERATOR_ATTRIBUTE
operator delete[](void * ptr,size_t size,std::align_val_t)181 void operator delete[](void *ptr, size_t size, std::align_val_t) NOEXCEPT {
182   GET_STACK_TRACE_FREE;
183   asan_sized_free(ptr, size, &stack, FROM_NEW_BR);
184 }
185 
186 #else  // SANITIZER_MAC
INTERCEPTOR(void,_ZdlPv,void * ptr)187 INTERCEPTOR(void, _ZdlPv, void *ptr) {
188   OPERATOR_DELETE_BODY(FROM_NEW);
189 }
INTERCEPTOR(void,_ZdaPv,void * ptr)190 INTERCEPTOR(void, _ZdaPv, void *ptr) {
191   OPERATOR_DELETE_BODY(FROM_NEW_BR);
192 }
INTERCEPTOR(void,_ZdlPvRKSt9nothrow_t,void * ptr,std::nothrow_t const &)193 INTERCEPTOR(void, _ZdlPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&) {
194   OPERATOR_DELETE_BODY(FROM_NEW);
195 }
INTERCEPTOR(void,_ZdaPvRKSt9nothrow_t,void * ptr,std::nothrow_t const &)196 INTERCEPTOR(void, _ZdaPvRKSt9nothrow_t, void *ptr, std::nothrow_t const&) {
197   OPERATOR_DELETE_BODY(FROM_NEW_BR);
198 }
199 #endif
200