1 //===-- memtag.h ------------------------------------------------*- C++ -*-===//
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
7 //===----------------------------------------------------------------------===//
9 #ifndef SCUDO_MEMTAG_H_
10 #define SCUDO_MEMTAG_H_
12 #include "internal_defs.h"
16 #include <sys/prctl.h>
21 #if (__clang_major__ >= 12 && defined(__aarch64__) && !defined(__ILP32__)) || \
24 // We assume that Top-Byte Ignore is enabled if the architecture supports memory
25 // tagging. Not all operating systems enable TBI, so we only claim architectural
26 // support for memory tagging if the operating system enables TBI.
27 // HWASan uses the top byte for its own purpose and Scudo should not touch it.
28 #if SCUDO_CAN_USE_MTE && !defined(SCUDO_DISABLE_TBI) && \
29 !__has_feature(hwaddress_sanitizer)
30 inline constexpr bool archSupportsMemoryTagging() { return true; }
32 inline constexpr bool archSupportsMemoryTagging() { return false; }
35 inline constexpr uptr
archMemoryTagGranuleSize() { return 16; }
37 inline uptr
untagPointer(uptr Ptr
) { return Ptr
& ((1ULL << 56) - 1); }
39 inline uint8_t extractTag(uptr Ptr
) { return (Ptr
>> 56) & 0xf; }
43 inline constexpr bool archSupportsMemoryTagging() { return false; }
45 inline NORETURN uptr
archMemoryTagGranuleSize() {
46 UNREACHABLE("memory tagging not supported");
49 inline NORETURN uptr
untagPointer(uptr Ptr
) {
51 UNREACHABLE("memory tagging not supported");
54 inline NORETURN
uint8_t extractTag(uptr Ptr
) {
56 UNREACHABLE("memory tagging not supported");
61 #if __clang_major__ >= 12 && defined(__aarch64__) && !defined(__ILP32__)
65 inline bool systemSupportsMemoryTagging() {
67 #define HWCAP2_MTE (1 << 18)
69 return getauxval(AT_HWCAP2
) & HWCAP2_MTE
;
72 inline bool systemDetectsMemoryTagFaultsTestOnly() {
73 #ifndef PR_SET_TAGGED_ADDR_CTRL
74 #define PR_SET_TAGGED_ADDR_CTRL 54
76 #ifndef PR_GET_TAGGED_ADDR_CTRL
77 #define PR_GET_TAGGED_ADDR_CTRL 56
79 #ifndef PR_TAGGED_ADDR_ENABLE
80 #define PR_TAGGED_ADDR_ENABLE (1UL << 0)
82 #ifndef PR_MTE_TCF_SHIFT
83 #define PR_MTE_TCF_SHIFT 1
85 #ifndef PR_MTE_TAG_SHIFT
86 #define PR_MTE_TAG_SHIFT 3
88 #ifndef PR_MTE_TCF_NONE
89 #define PR_MTE_TCF_NONE (0UL << PR_MTE_TCF_SHIFT)
91 #ifndef PR_MTE_TCF_SYNC
92 #define PR_MTE_TCF_SYNC (1UL << PR_MTE_TCF_SHIFT)
94 #ifndef PR_MTE_TCF_MASK
95 #define PR_MTE_TCF_MASK (3UL << PR_MTE_TCF_SHIFT)
97 int res
= prctl(PR_GET_TAGGED_ADDR_CTRL
, 0, 0, 0, 0);
100 return (static_cast<unsigned long>(res
) & PR_MTE_TCF_MASK
) != PR_MTE_TCF_NONE
;
103 inline void enableSystemMemoryTaggingTestOnly() {
104 prctl(PR_SET_TAGGED_ADDR_CTRL
,
105 PR_TAGGED_ADDR_ENABLE
| PR_MTE_TCF_SYNC
| (0xfffe << PR_MTE_TAG_SHIFT
),
109 #else // !SCUDO_CAN_USE_MTE
111 inline bool systemSupportsMemoryTagging() { return false; }
113 inline NORETURN
bool systemDetectsMemoryTagFaultsTestOnly() {
114 UNREACHABLE("memory tagging not supported");
117 inline NORETURN
void enableSystemMemoryTaggingTestOnly() {
118 UNREACHABLE("memory tagging not supported");
121 #endif // SCUDO_CAN_USE_MTE
123 class ScopedDisableMemoryTagChecks
{
127 ScopedDisableMemoryTagChecks() {
128 __asm__
__volatile__(
130 .arch_extension memtag
137 ~ScopedDisableMemoryTagChecks() {
138 __asm__
__volatile__(
140 .arch_extension memtag
148 inline uptr
selectRandomTag(uptr Ptr
, uptr ExcludeMask
) {
149 ExcludeMask
|= 1; // Always exclude Tag 0.
151 __asm__
__volatile__(
153 .arch_extension memtag
154 irg %[TaggedPtr], %[Ptr], %[ExcludeMask]
156 : [TaggedPtr
] "=r"(TaggedPtr
)
157 : [Ptr
] "r"(Ptr
), [ExcludeMask
] "r"(ExcludeMask
));
161 inline uptr
addFixedTag(uptr Ptr
, uptr Tag
) {
163 DCHECK_EQ(untagPointer(Ptr
), Ptr
);
164 return Ptr
| (Tag
<< 56);
167 inline uptr
storeTags(uptr Begin
, uptr End
) {
168 DCHECK_EQ(0, Begin
% 16);
169 uptr LineSize
, Next
, Tmp
;
170 __asm__
__volatile__(
172 .arch_extension memtag
174 // Compute the cache line size in bytes (DCZID_EL0 stores it as the log2
175 // of the number of 4-byte words) and bail out to the slow path if DCZID_EL0
176 // indicates that the DC instructions are unavailable.
180 and DCZID, DCZID, #15
182 lsl %[LineSize], %[LineSize], DCZID
185 // Our main loop doesn't handle the case where we don't need to perform any
186 // DC GZVA operations. If the size of our tagged region is less than
187 // twice the cache line size, bail out to the slow path since it's not
188 // guaranteed that we'll be able to do a DC GZVA.
190 sub Size, %[End], %[Cur]
191 cmp Size, %[LineSize], lsl #1
196 sub LineMask, %[LineSize], #1
198 // STZG until the start of the next cache line.
199 orr %[Next], %[Cur], LineMask
201 stzg %[Cur], [%[Cur]], #16
205 // DC GZVA cache lines until we have no more full cache lines.
206 bic %[Next], %[End], LineMask
210 add %[Cur], %[Cur], %[LineSize]
214 // STZG until the end of the tagged region. This loop is also used to handle
219 stzg %[Cur], [%[Cur]], #16
224 : [Cur
] "+&r"(Begin
), [LineSize
] "=&r"(LineSize
), [Next
] "=&r"(Next
),
228 DCHECK_EQ(0, Begin
% 16);
232 inline void storeTag(uptr Ptr
) {
233 DCHECK_EQ(0, Ptr
% 16);
234 __asm__
__volatile__(R
"(
235 .arch_extension memtag
243 inline uptr
loadTag(uptr Ptr
) {
244 DCHECK_EQ(0, Ptr
% 16);
245 uptr TaggedPtr
= Ptr
;
246 __asm__
__volatile__(
248 .arch_extension memtag
259 inline NORETURN
bool systemSupportsMemoryTagging() {
260 UNREACHABLE("memory tagging not supported");
263 inline NORETURN
bool systemDetectsMemoryTagFaultsTestOnly() {
264 UNREACHABLE("memory tagging not supported");
267 inline NORETURN
void enableSystemMemoryTaggingTestOnly() {
268 UNREACHABLE("memory tagging not supported");
271 struct ScopedDisableMemoryTagChecks
{
272 ScopedDisableMemoryTagChecks() {}
275 inline NORETURN uptr
selectRandomTag(uptr Ptr
, uptr ExcludeMask
) {
278 UNREACHABLE("memory tagging not supported");
281 inline NORETURN uptr
addFixedTag(uptr Ptr
, uptr Tag
) {
284 UNREACHABLE("memory tagging not supported");
287 inline NORETURN uptr
storeTags(uptr Begin
, uptr End
) {
290 UNREACHABLE("memory tagging not supported");
293 inline NORETURN
void storeTag(uptr Ptr
) {
295 UNREACHABLE("memory tagging not supported");
298 inline NORETURN uptr
loadTag(uptr Ptr
) {
300 UNREACHABLE("memory tagging not supported");
305 #pragma GCC diagnostic push
306 #pragma GCC diagnostic ignored "-Wmissing-noreturn"
307 inline void setRandomTag(void *Ptr
, uptr Size
, uptr ExcludeMask
,
308 uptr
*TaggedBegin
, uptr
*TaggedEnd
) {
309 *TaggedBegin
= selectRandomTag(reinterpret_cast<uptr
>(Ptr
), ExcludeMask
);
310 *TaggedEnd
= storeTags(*TaggedBegin
, *TaggedBegin
+ Size
);
312 #pragma GCC diagnostic pop
314 inline void *untagPointer(void *Ptr
) {
315 return reinterpret_cast<void *>(untagPointer(reinterpret_cast<uptr
>(Ptr
)));
318 inline void *loadTag(void *Ptr
) {
319 return reinterpret_cast<void *>(loadTag(reinterpret_cast<uptr
>(Ptr
)));
322 inline void *addFixedTag(void *Ptr
, uptr Tag
) {
323 return reinterpret_cast<void *>(
324 addFixedTag(reinterpret_cast<uptr
>(Ptr
), Tag
));
327 template <typename Config
>
328 inline constexpr bool allocatorSupportsMemoryTagging() {
329 return archSupportsMemoryTagging() && Config::MaySupportMemoryTagging
&&
330 (1 << SCUDO_MIN_ALIGNMENT_LOG
) >= archMemoryTagGranuleSize();