1 //===-- asan_errors.cpp -----------------------------------------*- C++ -*-===//
3 // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4 // See https://llvm.org/LICENSE.txt for license information.
5 // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
7 //===----------------------------------------------------------------------===//
9 // This file is a part of AddressSanitizer, an address sanity checker.
11 // ASan implementation for error structures.
12 //===----------------------------------------------------------------------===//
14 #include "asan_errors.h"
15 #include "asan_descriptions.h"
16 #include "asan_mapping.h"
17 #include "asan_report.h"
18 #include "asan_stack.h"
19 #include "sanitizer_common/sanitizer_stackdepot.h"
23 static void OnStackUnwind(const SignalContext
&sig
,
24 const void *callback_context
,
25 BufferedStackTrace
*stack
) {
26 bool fast
= common_flags()->fast_unwind_on_fatal
;
27 #if SANITIZER_FREEBSD || SANITIZER_NETBSD
28 // On FreeBSD the slow unwinding that leverages _Unwind_Backtrace()
29 // yields the call stack of the signal's handler and not of the code
30 // that raised the signal (as it does on Linux).
33 // Tests and maybe some users expect that scariness is going to be printed
34 // just before the stack. As only asan has scariness score we have no
35 // corresponding code in the sanitizer_common and we use this callback to
37 static_cast<const ScarinessScoreBase
*>(callback_context
)->Print();
38 stack
->Unwind(StackTrace::GetNextInstructionPc(sig
.pc
), sig
.bp
, sig
.context
,
42 void ErrorDeadlySignal::Print() {
43 ReportDeadlySignal(signal
, tid
, &OnStackUnwind
, &scariness
);
46 void ErrorDoubleFree::Print() {
48 Printf("%s", d
.Error());
49 Report("ERROR: AddressSanitizer: attempting %s on %p in thread %s:\n",
50 scariness
.GetDescription(), (void *)addr_description
.addr
,
51 AsanThreadIdAndName(tid
).c_str());
52 Printf("%s", d
.Default());
54 GET_STACK_TRACE_FATAL(second_free_stack
->trace
[0],
55 second_free_stack
->top_frame_bp
);
57 addr_description
.Print();
58 ReportErrorSummary(scariness
.GetDescription(), &stack
);
61 void ErrorNewDeleteTypeMismatch::Print() {
63 Printf("%s", d
.Error());
64 Report("ERROR: AddressSanitizer: %s on %p in thread %s:\n",
65 scariness
.GetDescription(), (void *)addr_description
.addr
,
66 AsanThreadIdAndName(tid
).c_str());
67 Printf("%s object passed to delete has wrong type:\n", d
.Default());
68 if (delete_size
!= 0) {
70 " size of the allocated type: %zd bytes;\n"
71 " size of the deallocated type: %zd bytes.\n",
72 addr_description
.chunk_access
.chunk_size
, delete_size
);
74 const uptr user_alignment
=
75 addr_description
.chunk_access
.user_requested_alignment
;
76 if (delete_alignment
!= user_alignment
) {
77 char user_alignment_str
[32];
78 char delete_alignment_str
[32];
79 internal_snprintf(user_alignment_str
, sizeof(user_alignment_str
),
80 "%zd bytes", user_alignment
);
81 internal_snprintf(delete_alignment_str
, sizeof(delete_alignment_str
),
82 "%zd bytes", delete_alignment
);
83 static const char *kDefaultAlignment
= "default-aligned";
85 " alignment of the allocated type: %s;\n"
86 " alignment of the deallocated type: %s.\n",
87 user_alignment
> 0 ? user_alignment_str
: kDefaultAlignment
,
88 delete_alignment
> 0 ? delete_alignment_str
: kDefaultAlignment
);
90 CHECK_GT(free_stack
->size
, 0);
92 GET_STACK_TRACE_FATAL(free_stack
->trace
[0], free_stack
->top_frame_bp
);
94 addr_description
.Print();
95 ReportErrorSummary(scariness
.GetDescription(), &stack
);
97 "HINT: if you don't care about these errors you may set "
98 "ASAN_OPTIONS=new_delete_type_mismatch=0\n");
101 void ErrorFreeNotMalloced::Print() {
103 Printf("%s", d
.Error());
105 "ERROR: AddressSanitizer: attempting free on address "
106 "which was not malloc()-ed: %p in thread %s\n",
107 (void *)addr_description
.Address(), AsanThreadIdAndName(tid
).c_str());
108 Printf("%s", d
.Default());
109 CHECK_GT(free_stack
->size
, 0);
111 GET_STACK_TRACE_FATAL(free_stack
->trace
[0], free_stack
->top_frame_bp
);
113 addr_description
.Print();
114 ReportErrorSummary(scariness
.GetDescription(), &stack
);
117 void ErrorAllocTypeMismatch::Print() {
118 static const char *alloc_names
[] = {"INVALID", "malloc", "operator new",
120 static const char *dealloc_names
[] = {"INVALID", "free", "operator delete",
121 "operator delete []"};
122 CHECK_NE(alloc_type
, dealloc_type
);
124 Printf("%s", d
.Error());
125 Report("ERROR: AddressSanitizer: %s (%s vs %s) on %p\n",
126 scariness
.GetDescription(), alloc_names
[alloc_type
],
127 dealloc_names
[dealloc_type
], (void *)addr_description
.Address());
128 Printf("%s", d
.Default());
129 CHECK_GT(dealloc_stack
->size
, 0);
131 GET_STACK_TRACE_FATAL(dealloc_stack
->trace
[0], dealloc_stack
->top_frame_bp
);
133 addr_description
.Print();
134 ReportErrorSummary(scariness
.GetDescription(), &stack
);
136 "HINT: if you don't care about these errors you may set "
137 "ASAN_OPTIONS=alloc_dealloc_mismatch=0\n");
140 void ErrorMallocUsableSizeNotOwned::Print() {
142 Printf("%s", d
.Error());
144 "ERROR: AddressSanitizer: attempting to call malloc_usable_size() for "
145 "pointer which is not owned: %p\n",
146 (void *)addr_description
.Address());
147 Printf("%s", d
.Default());
149 addr_description
.Print();
150 ReportErrorSummary(scariness
.GetDescription(), stack
);
153 void ErrorSanitizerGetAllocatedSizeNotOwned::Print() {
155 Printf("%s", d
.Error());
157 "ERROR: AddressSanitizer: attempting to call "
158 "__sanitizer_get_allocated_size() for pointer which is not owned: %p\n",
159 (void *)addr_description
.Address());
160 Printf("%s", d
.Default());
162 addr_description
.Print();
163 ReportErrorSummary(scariness
.GetDescription(), stack
);
166 void ErrorCallocOverflow::Print() {
168 Printf("%s", d
.Error());
170 "ERROR: AddressSanitizer: calloc parameters overflow: count * size "
171 "(%zd * %zd) cannot be represented in type size_t (thread %s)\n",
172 count
, size
, AsanThreadIdAndName(tid
).c_str());
173 Printf("%s", d
.Default());
175 PrintHintAllocatorCannotReturnNull();
176 ReportErrorSummary(scariness
.GetDescription(), stack
);
179 void ErrorReallocArrayOverflow::Print() {
181 Printf("%s", d
.Error());
183 "ERROR: AddressSanitizer: reallocarray parameters overflow: count * size "
184 "(%zd * %zd) cannot be represented in type size_t (thread %s)\n",
185 count
, size
, AsanThreadIdAndName(tid
).c_str());
186 Printf("%s", d
.Default());
188 PrintHintAllocatorCannotReturnNull();
189 ReportErrorSummary(scariness
.GetDescription(), stack
);
192 void ErrorPvallocOverflow::Print() {
194 Printf("%s", d
.Error());
196 "ERROR: AddressSanitizer: pvalloc parameters overflow: size 0x%zx "
197 "rounded up to system page size 0x%zx cannot be represented in type "
198 "size_t (thread %s)\n",
199 size
, GetPageSizeCached(), AsanThreadIdAndName(tid
).c_str());
200 Printf("%s", d
.Default());
202 PrintHintAllocatorCannotReturnNull();
203 ReportErrorSummary(scariness
.GetDescription(), stack
);
206 void ErrorInvalidAllocationAlignment::Print() {
208 Printf("%s", d
.Error());
210 "ERROR: AddressSanitizer: invalid allocation alignment: %zd, "
211 "alignment must be a power of two (thread %s)\n",
212 alignment
, AsanThreadIdAndName(tid
).c_str());
213 Printf("%s", d
.Default());
215 PrintHintAllocatorCannotReturnNull();
216 ReportErrorSummary(scariness
.GetDescription(), stack
);
219 void ErrorInvalidAlignedAllocAlignment::Print() {
221 Printf("%s", d
.Error());
223 Report("ERROR: AddressSanitizer: invalid alignment requested in "
224 "aligned_alloc: %zd, alignment must be a power of two and the "
225 "requested size 0x%zx must be a multiple of alignment "
226 "(thread %s)\n", alignment
, size
, AsanThreadIdAndName(tid
).c_str());
228 Report("ERROR: AddressSanitizer: invalid alignment requested in "
229 "aligned_alloc: %zd, the requested size 0x%zx must be a multiple of "
230 "alignment (thread %s)\n", alignment
, size
,
231 AsanThreadIdAndName(tid
).c_str());
233 Printf("%s", d
.Default());
235 PrintHintAllocatorCannotReturnNull();
236 ReportErrorSummary(scariness
.GetDescription(), stack
);
239 void ErrorInvalidPosixMemalignAlignment::Print() {
241 Printf("%s", d
.Error());
243 "ERROR: AddressSanitizer: invalid alignment requested in posix_memalign: "
244 "%zd, alignment must be a power of two and a multiple of sizeof(void*) "
245 "== %zd (thread %s)\n",
246 alignment
, sizeof(void *), AsanThreadIdAndName(tid
).c_str());
247 Printf("%s", d
.Default());
249 PrintHintAllocatorCannotReturnNull();
250 ReportErrorSummary(scariness
.GetDescription(), stack
);
253 void ErrorAllocationSizeTooBig::Print() {
255 Printf("%s", d
.Error());
257 "ERROR: AddressSanitizer: requested allocation size 0x%zx (0x%zx after "
258 "adjustments for alignment, red zones etc.) exceeds maximum supported "
259 "size of 0x%zx (thread %s)\n",
260 user_size
, total_size
, max_size
, AsanThreadIdAndName(tid
).c_str());
261 Printf("%s", d
.Default());
263 PrintHintAllocatorCannotReturnNull();
264 ReportErrorSummary(scariness
.GetDescription(), stack
);
267 void ErrorRssLimitExceeded::Print() {
269 Printf("%s", d
.Error());
271 "ERROR: AddressSanitizer: specified RSS limit exceeded, currently set to "
272 "soft_rss_limit_mb=%zd\n", common_flags()->soft_rss_limit_mb
);
273 Printf("%s", d
.Default());
275 PrintHintAllocatorCannotReturnNull();
276 ReportErrorSummary(scariness
.GetDescription(), stack
);
279 void ErrorOutOfMemory::Print() {
281 Printf("%s", d
.Error());
283 "ERROR: AddressSanitizer: allocator is out of memory trying to allocate "
284 "0x%zx bytes\n", requested_size
);
285 Printf("%s", d
.Default());
287 PrintHintAllocatorCannotReturnNull();
288 ReportErrorSummary(scariness
.GetDescription(), stack
);
291 void ErrorStringFunctionMemoryRangesOverlap::Print() {
294 internal_snprintf(bug_type
, sizeof(bug_type
), "%s-param-overlap", function
);
295 Printf("%s", d
.Error());
297 "ERROR: AddressSanitizer: %s: memory ranges [%p,%p) and [%p, %p) "
299 bug_type
, (void *)addr1_description
.Address(),
300 (void *)(addr1_description
.Address() + length1
),
301 (void *)addr2_description
.Address(),
302 (void *)(addr2_description
.Address() + length2
));
303 Printf("%s", d
.Default());
306 addr1_description
.Print();
307 addr2_description
.Print();
308 ReportErrorSummary(bug_type
, stack
);
311 void ErrorStringFunctionSizeOverflow::Print() {
313 Printf("%s", d
.Error());
314 Report("ERROR: AddressSanitizer: %s: (size=%zd)\n",
315 scariness
.GetDescription(), size
);
316 Printf("%s", d
.Default());
319 addr_description
.Print();
320 ReportErrorSummary(scariness
.GetDescription(), stack
);
323 void ErrorBadParamsToAnnotateContiguousContainer::Print() {
325 "ERROR: AddressSanitizer: bad parameters to "
326 "__sanitizer_annotate_contiguous_container:\n"
331 (void *)beg
, (void *)end
, (void *)old_mid
, (void *)new_mid
);
332 uptr granularity
= ASAN_SHADOW_GRANULARITY
;
333 if (!IsAligned(beg
, granularity
))
334 Report("ERROR: beg is not aligned by %zu\n", granularity
);
336 ReportErrorSummary(scariness
.GetDescription(), stack
);
339 void ErrorODRViolation::Print() {
341 Printf("%s", d
.Error());
342 Report("ERROR: AddressSanitizer: %s (%p):\n", scariness
.GetDescription(),
343 (void *)global1
.beg
);
344 Printf("%s", d
.Default());
345 InternalScopedString g1_loc
;
346 InternalScopedString g2_loc
;
347 PrintGlobalLocation(&g1_loc
, global1
);
348 PrintGlobalLocation(&g2_loc
, global2
);
349 Printf(" [1] size=%zd '%s' %s\n", global1
.size
,
350 MaybeDemangleGlobalName(global1
.name
), g1_loc
.data());
351 Printf(" [2] size=%zd '%s' %s\n", global2
.size
,
352 MaybeDemangleGlobalName(global2
.name
), g2_loc
.data());
353 if (stack_id1
&& stack_id2
) {
354 Printf("These globals were registered at these points:\n");
356 StackDepotGet(stack_id1
).Print();
358 StackDepotGet(stack_id2
).Print();
361 "HINT: if you don't care about these errors you may set "
362 "ASAN_OPTIONS=detect_odr_violation=0\n");
363 InternalScopedString error_msg
;
364 error_msg
.append("%s: global '%s' at %s", scariness
.GetDescription(),
365 MaybeDemangleGlobalName(global1
.name
), g1_loc
.data());
366 ReportErrorSummary(error_msg
.data());
369 void ErrorInvalidPointerPair::Print() {
371 Printf("%s", d
.Error());
372 Report("ERROR: AddressSanitizer: %s: %p %p\n", scariness
.GetDescription(),
373 (void *)addr1_description
.Address(),
374 (void *)addr2_description
.Address());
375 Printf("%s", d
.Default());
376 GET_STACK_TRACE_FATAL(pc
, bp
);
378 addr1_description
.Print();
379 addr2_description
.Print();
380 ReportErrorSummary(scariness
.GetDescription(), &stack
);
383 static bool AdjacentShadowValuesAreFullyPoisoned(u8
*s
) {
384 return s
[-1] > 127 && s
[1] > 127;
387 ErrorGeneric::ErrorGeneric(u32 tid
, uptr pc_
, uptr bp_
, uptr sp_
, uptr addr
,
388 bool is_write_
, uptr access_size_
)
390 addr_description(addr
, access_size_
, /*shouldLockThreadRegistry=*/false),
394 access_size(access_size_
),
399 if (access_size
<= 9) {
400 char desr
[] = "?-byte";
401 desr
[0] = '0' + access_size
;
402 scariness
.Scare(access_size
+ access_size
/ 2, desr
);
403 } else if (access_size
>= 10) {
404 scariness
.Scare(15, "multi-byte");
406 is_write
? scariness
.Scare(20, "write") : scariness
.Scare(1, "read");
408 // Determine the error type.
409 bug_descr
= "unknown-crash";
410 if (AddrIsInMem(addr
)) {
411 u8
*shadow_addr
= (u8
*)MemToShadow(addr
);
412 // If we are accessing 16 bytes, look at the second shadow byte.
413 if (*shadow_addr
== 0 && access_size
> ASAN_SHADOW_GRANULARITY
)
415 // If we are in the partial right redzone, look at the next shadow byte.
416 if (*shadow_addr
> 0 && *shadow_addr
< 128) shadow_addr
++;
417 bool far_from_bounds
= false;
418 shadow_val
= *shadow_addr
;
419 int bug_type_score
= 0;
420 // For use-after-frees reads are almost as bad as writes.
421 int read_after_free_bonus
= 0;
422 switch (shadow_val
) {
423 case kAsanHeapLeftRedzoneMagic
:
424 case kAsanArrayCookieMagic
:
425 bug_descr
= "heap-buffer-overflow";
427 far_from_bounds
= AdjacentShadowValuesAreFullyPoisoned(shadow_addr
);
429 case kAsanHeapFreeMagic
:
430 bug_descr
= "heap-use-after-free";
432 if (!is_write
) read_after_free_bonus
= 18;
434 case kAsanStackLeftRedzoneMagic
:
435 bug_descr
= "stack-buffer-underflow";
437 far_from_bounds
= AdjacentShadowValuesAreFullyPoisoned(shadow_addr
);
439 case kAsanInitializationOrderMagic
:
440 bug_descr
= "initialization-order-fiasco";
443 case kAsanStackMidRedzoneMagic
:
444 case kAsanStackRightRedzoneMagic
:
445 bug_descr
= "stack-buffer-overflow";
447 far_from_bounds
= AdjacentShadowValuesAreFullyPoisoned(shadow_addr
);
449 case kAsanStackAfterReturnMagic
:
450 bug_descr
= "stack-use-after-return";
452 if (!is_write
) read_after_free_bonus
= 18;
454 case kAsanUserPoisonedMemoryMagic
:
455 bug_descr
= "use-after-poison";
458 case kAsanContiguousContainerOOBMagic
:
459 bug_descr
= "container-overflow";
462 case kAsanStackUseAfterScopeMagic
:
463 bug_descr
= "stack-use-after-scope";
466 case kAsanGlobalRedzoneMagic
:
467 bug_descr
= "global-buffer-overflow";
469 far_from_bounds
= AdjacentShadowValuesAreFullyPoisoned(shadow_addr
);
471 case kAsanIntraObjectRedzone
:
472 bug_descr
= "intra-object-overflow";
475 case kAsanAllocaLeftMagic
:
476 case kAsanAllocaRightMagic
:
477 bug_descr
= "dynamic-stack-buffer-overflow";
479 far_from_bounds
= AdjacentShadowValuesAreFullyPoisoned(shadow_addr
);
482 scariness
.Scare(bug_type_score
+ read_after_free_bonus
, bug_descr
);
483 if (far_from_bounds
) scariness
.Scare(10, "far-from-bounds");
488 static void PrintContainerOverflowHint() {
489 Printf("HINT: if you don't care about these errors you may set "
490 "ASAN_OPTIONS=detect_container_overflow=0.\n"
491 "If you suspect a false positive see also: "
492 "https://github.com/google/sanitizers/wiki/"
493 "AddressSanitizerContainerOverflow.\n");
496 static void PrintShadowByte(InternalScopedString
*str
, const char *before
,
497 u8 byte
, const char *after
= "\n") {
498 PrintMemoryByte(str
, before
, byte
, /*in_shadow*/true, after
);
501 static void PrintLegend(InternalScopedString
*str
) {
503 "Shadow byte legend (one shadow byte represents %d "
504 "application bytes):\n",
505 (int)ASAN_SHADOW_GRANULARITY
);
506 PrintShadowByte(str
, " Addressable: ", 0);
507 str
->append(" Partially addressable: ");
508 for (u8 i
= 1; i
< ASAN_SHADOW_GRANULARITY
; i
++)
509 PrintShadowByte(str
, "", i
, " ");
511 PrintShadowByte(str
, " Heap left redzone: ",
512 kAsanHeapLeftRedzoneMagic
);
513 PrintShadowByte(str
, " Freed heap region: ", kAsanHeapFreeMagic
);
514 PrintShadowByte(str
, " Stack left redzone: ",
515 kAsanStackLeftRedzoneMagic
);
516 PrintShadowByte(str
, " Stack mid redzone: ",
517 kAsanStackMidRedzoneMagic
);
518 PrintShadowByte(str
, " Stack right redzone: ",
519 kAsanStackRightRedzoneMagic
);
520 PrintShadowByte(str
, " Stack after return: ",
521 kAsanStackAfterReturnMagic
);
522 PrintShadowByte(str
, " Stack use after scope: ",
523 kAsanStackUseAfterScopeMagic
);
524 PrintShadowByte(str
, " Global redzone: ", kAsanGlobalRedzoneMagic
);
525 PrintShadowByte(str
, " Global init order: ",
526 kAsanInitializationOrderMagic
);
527 PrintShadowByte(str
, " Poisoned by user: ",
528 kAsanUserPoisonedMemoryMagic
);
529 PrintShadowByte(str
, " Container overflow: ",
530 kAsanContiguousContainerOOBMagic
);
531 PrintShadowByte(str
, " Array cookie: ",
532 kAsanArrayCookieMagic
);
533 PrintShadowByte(str
, " Intra object redzone: ",
534 kAsanIntraObjectRedzone
);
535 PrintShadowByte(str
, " ASan internal: ", kAsanInternalHeapMagic
);
536 PrintShadowByte(str
, " Left alloca redzone: ", kAsanAllocaLeftMagic
);
537 PrintShadowByte(str
, " Right alloca redzone: ", kAsanAllocaRightMagic
);
540 static void PrintShadowBytes(InternalScopedString
*str
, const char *before
,
541 u8
*bytes
, u8
*guilty
, uptr n
) {
544 str
->append("%s%p:", before
, (void *)bytes
);
545 for (uptr i
= 0; i
< n
; i
++) {
548 p
== guilty
? "[" : (p
- 1 == guilty
&& i
!= 0) ? "" : " ";
549 const char *after
= p
== guilty
? "]" : "";
550 PrintShadowByte(str
, before
, *p
, after
);
555 static void PrintShadowMemoryForAddress(uptr addr
) {
556 if (!AddrIsInMem(addr
)) return;
557 uptr shadow_addr
= MemToShadow(addr
);
558 const uptr n_bytes_per_row
= 16;
559 uptr aligned_shadow
= shadow_addr
& ~(n_bytes_per_row
- 1);
560 InternalScopedString str
;
561 str
.append("Shadow bytes around the buggy address:\n");
562 for (int i
= -5; i
<= 5; i
++) {
563 uptr row_shadow_addr
= aligned_shadow
+ i
* n_bytes_per_row
;
564 // Skip rows that would be outside the shadow range. This can happen when
565 // the user address is near the bottom, top, or shadow gap of the address
567 if (!AddrIsInShadow(row_shadow_addr
)) continue;
568 const char *prefix
= (i
== 0) ? "=>" : " ";
569 PrintShadowBytes(&str
, prefix
, (u8
*)row_shadow_addr
, (u8
*)shadow_addr
,
572 if (flags()->print_legend
) PrintLegend(&str
);
573 Printf("%s", str
.data());
576 void ErrorGeneric::Print() {
578 Printf("%s", d
.Error());
579 uptr addr
= addr_description
.Address();
580 Report("ERROR: AddressSanitizer: %s on address %p at pc %p bp %p sp %p\n",
581 bug_descr
, (void *)addr
, (void *)pc
, (void *)bp
, (void *)sp
);
582 Printf("%s", d
.Default());
584 Printf("%s%s of size %zu at %p thread %s%s\n", d
.Access(),
585 access_size
? (is_write
? "WRITE" : "READ") : "ACCESS", access_size
,
586 (void *)addr
, AsanThreadIdAndName(tid
).c_str(), d
.Default());
589 GET_STACK_TRACE_FATAL(pc
, bp
);
592 // Pass bug_descr because we have a special case for
593 // initialization-order-fiasco
594 addr_description
.Print(bug_descr
);
595 if (shadow_val
== kAsanContiguousContainerOOBMagic
)
596 PrintContainerOverflowHint();
597 ReportErrorSummary(bug_descr
, &stack
);
598 PrintShadowMemoryForAddress(addr
);
601 } // namespace __asan