blob: f8f7d2ae5212e8ec8305ed3636e2f29b2a11a180 [file] [log] [blame]
Elliott Hughes42b2c6a2013-02-07 10:14:39 -08001/*
2 * Copyright (C) 2008 The Android Open Source Project
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * * Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * * Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in
12 * the documentation and/or other materials provided with the
13 * distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19 * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22 * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25 * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 */
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080028
Yabin Cuica482742016-01-25 17:38:44 -080029#include <android/api-level.h>
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080030#include <elf.h>
31#include <errno.h>
Florian Mayer408e1702022-05-12 13:06:04 -070032#include <malloc.h>
Florian Mayer5d9725b2024-05-15 18:33:49 -070033#include <signal.h>
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080034#include <stddef.h>
35#include <stdint.h>
36#include <stdio.h>
37#include <stdlib.h>
38#include <sys/auxv.h>
39#include <sys/mman.h>
40
Florian Mayer408e1702022-05-12 13:06:04 -070041#include "async_safe/log.h"
42#include "heap_tagging.h"
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080043#include "libc_init_common.h"
Mitch Phillips4cded972021-01-07 17:32:00 -080044#include "platform/bionic/macros.h"
45#include "platform/bionic/mte.h"
Elliott Hughescdb52fc2019-12-12 15:26:14 -080046#include "platform/bionic/page.h"
Elliott Hughes37719372021-09-29 16:52:20 -070047#include "platform/bionic/reserved_signals.h"
Mitch Phillips4cded972021-01-07 17:32:00 -080048#include "private/KernelArgumentBlock.h"
49#include "private/bionic_asm.h"
50#include "private/bionic_asm_note.h"
Peter Collingbournee9491952019-10-28 10:57:26 -070051#include "private/bionic_call_ifunc_resolver.h"
Ryan Prichard45d13492019-01-03 02:51:30 -080052#include "private/bionic_elf_tls.h"
Josh Gaob6453c52016-06-29 16:47:53 -070053#include "private/bionic_globals.h"
Elliott Hugheseb847bc2013-10-09 15:50:50 -070054#include "private/bionic_tls.h"
Kalesh Singhf0050fb2023-12-15 10:02:01 -080055#include "private/elf_note.h"
Florian Mayer408e1702022-05-12 13:06:04 -070056#include "pthread_internal.h"
Mitch Phillips4cded972021-01-07 17:32:00 -080057#include "sys/system_properties.h"
Florian Mayer408e1702022-05-12 13:06:04 -070058#include "sysprop_helpers.h"
Elliott Hugheseb847bc2013-10-09 15:50:50 -070059
Evgenii Stepanovbe551f52018-08-13 16:46:15 -070060#if __has_feature(hwaddress_sanitizer)
61#include <sanitizer/hwasan_interface.h>
62#endif
63
Ryan Prichard27475b52018-05-17 17:14:18 -070064// Leave the variable uninitialized for the sake of the dynamic loader, which
65// links in this file. The loader will initialize this variable before
66// relocating itself.
67#if defined(__i386__)
68__LIBC_HIDDEN__ void* __libc_sysinfo;
69#endif
70
Dmitriy Ivanov53c3c272014-07-11 12:59:16 -070071extern "C" int __cxa_atexit(void (*)(void *), void *, void *);
Mitch Phillips4cded972021-01-07 17:32:00 -080072extern "C" const char* __gnu_basename(const char* path);
Dmitriy Ivanov53c3c272014-07-11 12:59:16 -070073
Yabin Cui744cfd32023-08-24 13:20:23 -070074static void call_array(init_func_t** list, size_t count, int argc, char* argv[], char* envp[]) {
75 while (count-- > 0) {
76 init_func_t* function = *list++;
77 (*function)(argc, argv, envp);
78 }
79}
80
81static void call_fini_array(void* arg) {
82 structors_array_t* structors = reinterpret_cast<structors_array_t*>(arg);
83 fini_func_t** array = structors->fini_array;
84 size_t count = structors->fini_array_count;
85 // Now call each destructor in reverse order.
86 while (count-- > 0) {
87 fini_func_t* function = array[count];
88 (*function)();
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080089 }
90}
91
Elliott Hughes6cfd1b52022-10-05 00:15:49 +000092#if defined(__arm__) || defined(__i386__) // Legacy architectures used REL...
Dan Alberta535d3c2019-02-14 16:19:59 -080093extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rel) __rel_iplt_start[], __rel_iplt_end[];
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -080094
95static void call_ifunc_resolvers() {
Elliott Hughes6cfd1b52022-10-05 00:15:49 +000096 for (ElfW(Rel)* r = __rel_iplt_start; r != __rel_iplt_end; ++r) {
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -080097 ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
98 ElfW(Addr) resolver = *offset;
Peter Collingbournee9491952019-10-28 10:57:26 -070099 *offset = __bionic_call_ifunc_resolver(resolver);
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -0800100 }
101}
Elliott Hughes6cfd1b52022-10-05 00:15:49 +0000102#else // ...but modern architectures use RELA instead.
103extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rela) __rela_iplt_start[], __rela_iplt_end[];
104
105static void call_ifunc_resolvers() {
Elliott Hughes6cfd1b52022-10-05 00:15:49 +0000106 for (ElfW(Rela)* r = __rela_iplt_start; r != __rela_iplt_end; ++r) {
107 ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
108 ElfW(Addr) resolver = r->r_addend;
109 *offset = __bionic_call_ifunc_resolver(resolver);
110 }
111}
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -0800112#endif
113
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800114static void apply_gnu_relro() {
Elliott Hughes0266ae52014-02-10 17:46:57 -0800115 ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800116 unsigned long int phdr_ct = getauxval(AT_PHNUM);
117
Elliott Hughes0266ae52014-02-10 17:46:57 -0800118 for (ElfW(Phdr)* phdr = phdr_start; phdr < (phdr_start + phdr_ct); phdr++) {
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800119 if (phdr->p_type != PT_GNU_RELRO) {
120 continue;
121 }
122
Peter Collingbournebb11ee62022-05-02 12:26:16 -0700123 ElfW(Addr) seg_page_start = page_start(phdr->p_vaddr);
124 ElfW(Addr) seg_page_end = page_end(phdr->p_vaddr + phdr->p_memsz);
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800125
126 // Check return value here? What do we do if we fail?
127 mprotect(reinterpret_cast<void*>(seg_page_start), seg_page_end - seg_page_start, PROT_READ);
128 }
129}
130
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800131static void layout_static_tls(KernelArgumentBlock& args) {
Ryan Prichard45d13492019-01-03 02:51:30 -0800132 StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout;
133 layout.reserve_bionic_tls();
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800134
135 const char* progname = args.argv[0];
136 ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
137 size_t phdr_ct = getauxval(AT_PHNUM);
138
Ryan Prichard19883502019-01-16 23:13:38 -0800139 static TlsModule mod;
Ryan Prichard16455b52019-01-18 01:00:59 -0800140 TlsModules& modules = __libc_shared_globals()->tls_modules;
Ryan Prichard19883502019-01-16 23:13:38 -0800141 if (__bionic_get_tls_segment(phdr_start, phdr_ct, 0, &mod.segment)) {
Ryan Prichard43963922024-03-14 16:51:27 -0700142 if (!__bionic_check_tls_align(mod.segment.aligned_size.align.value)) {
Ryan Prichard19883502019-01-16 23:13:38 -0800143 async_safe_fatal("error: TLS segment alignment in \"%s\" is not a power of 2: %zu\n",
Ryan Prichard43963922024-03-14 16:51:27 -0700144 progname, mod.segment.aligned_size.align.value);
Ryan Prichard19883502019-01-16 23:13:38 -0800145 }
146 mod.static_offset = layout.reserve_exe_segment_and_tcb(&mod.segment, progname);
Ryan Prichard16455b52019-01-18 01:00:59 -0800147 mod.first_generation = kTlsGenerationFirst;
148
149 modules.module_count = 1;
Vy Nguyend5007512020-07-14 17:37:04 -0400150 modules.static_module_count = 1;
Ryan Prichard16455b52019-01-18 01:00:59 -0800151 modules.module_table = &mod;
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800152 } else {
153 layout.reserve_exe_segment_and_tcb(nullptr, progname);
154 }
Ryan Prichard16455b52019-01-18 01:00:59 -0800155 // Enable the fast path in __tls_get_addr.
156 __libc_tls_generation_copy = modules.generation;
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800157
Ryan Prichard45d13492019-01-03 02:51:30 -0800158 layout.finish_layout();
159}
160
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800161#ifdef __aarch64__
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200162static HeapTaggingLevel __get_memtag_level_from_note(const ElfW(Phdr) * phdr_start, size_t phdr_ct,
163 const ElfW(Addr) load_bias, bool* stack) {
164 const ElfW(Nhdr) * note;
165 const char* desc;
Kalesh Singhf0050fb2023-12-15 10:02:01 -0800166 if (!__find_elf_note(NT_ANDROID_TYPE_MEMTAG, "Android", phdr_start, phdr_ct, &note, &desc,
167 load_bias)) {
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200168 return M_HEAP_TAGGING_LEVEL_TBI;
169 }
170
171 // Previously (in Android 12), if the note was != 4 bytes, we check-failed
172 // here. Let's be more permissive to allow future expansion.
173 if (note->n_descsz < 4) {
174 async_safe_fatal("unrecognized android.memtag note: n_descsz = %d, expected >= 4",
175 note->n_descsz);
176 }
177
Kalesh Singhf0050fb2023-12-15 10:02:01 -0800178 // `desc` is always aligned due to ELF requirements, enforced in __find_elf_note().
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200179 ElfW(Word) note_val = *reinterpret_cast<const ElfW(Word)*>(desc);
180 *stack = (note_val & NT_MEMTAG_STACK) != 0;
181
182 // Warning: In Android 12, any value outside of bits [0..3] resulted in a check-fail.
183 if (!(note_val & (NT_MEMTAG_HEAP | NT_MEMTAG_STACK))) {
184 async_safe_format_log(ANDROID_LOG_INFO, "libc",
185 "unrecognised memtag note_val did not specificy heap or stack: %u",
186 note_val);
187 return M_HEAP_TAGGING_LEVEL_TBI;
188 }
189
190 unsigned mode = note_val & NT_MEMTAG_LEVEL_MASK;
191 switch (mode) {
192 case NT_MEMTAG_LEVEL_NONE:
193 // Note, previously (in Android 12), NT_MEMTAG_LEVEL_NONE was
194 // NT_MEMTAG_LEVEL_DEFAULT, which implied SYNC mode. This was never used
195 // by anyone, but we note it (heh) here for posterity, in case the zero
196 // level becomes meaningful, and binaries with this note can be executed
197 // on Android 12 devices.
198 return M_HEAP_TAGGING_LEVEL_TBI;
199 case NT_MEMTAG_LEVEL_ASYNC:
200 return M_HEAP_TAGGING_LEVEL_ASYNC;
201 case NT_MEMTAG_LEVEL_SYNC:
202 default:
203 // We allow future extensions to specify mode 3 (currently unused), with
204 // the idea that it might be used for ASYMM mode or something else. On
205 // this version of Android, it falls back to SYNC mode.
206 return M_HEAP_TAGGING_LEVEL_SYNC;
207 }
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800208}
209
Mitch Phillips4cded972021-01-07 17:32:00 -0800210// Returns true if there's an environment setting (either sysprop or env var)
211// that should overwrite the ELF note, and places the equivalent heap tagging
212// level into *level.
Florian Mayerdd443782023-05-17 20:59:14 +0000213static bool get_environment_memtag_setting(HeapTaggingLevel* level) {
Mitch Phillips4cded972021-01-07 17:32:00 -0800214 static const char kMemtagPrognameSyspropPrefix[] = "arm64.memtag.process.";
Florian Mayerdde31762022-01-24 18:29:50 -0800215 static const char kMemtagGlobalSysprop[] = "persist.arm64.memtag.default";
Florian Mayerdee80d52022-08-01 15:16:01 -0700216 static const char kMemtagOverrideSyspropPrefix[] =
217 "persist.device_config.memory_safety_native.mode_override.process.";
Mitch Phillips4cded972021-01-07 17:32:00 -0800218
Florian Mayerdd443782023-05-17 20:59:14 +0000219 const char* progname = __libc_shared_globals()->init_progname;
220 if (progname == nullptr) return false;
221
222 const char* basename = __gnu_basename(progname);
Mitch Phillips4cded972021-01-07 17:32:00 -0800223
Florian Mayer27914292022-08-01 15:02:25 -0700224 char options_str[PROP_VALUE_MAX];
225 char sysprop_name[512];
226 async_safe_format_buffer(sysprop_name, sizeof(sysprop_name), "%s%s", kMemtagPrognameSyspropPrefix,
Mitch Phillips4cded972021-01-07 17:32:00 -0800227 basename);
Florian Mayerdee80d52022-08-01 15:16:01 -0700228 char remote_sysprop_name[512];
229 async_safe_format_buffer(remote_sysprop_name, sizeof(remote_sysprop_name), "%s%s",
230 kMemtagOverrideSyspropPrefix, basename);
231 const char* sys_prop_names[] = {sysprop_name, remote_sysprop_name, kMemtagGlobalSysprop};
Mitch Phillips4cded972021-01-07 17:32:00 -0800232
Florian Mayerdde31762022-01-24 18:29:50 -0800233 if (!get_config_from_env_or_sysprops("MEMTAG_OPTIONS", sys_prop_names, arraysize(sys_prop_names),
Florian Mayerdd443782023-05-17 20:59:14 +0000234 options_str, sizeof(options_str))) {
Mitch Phillips4cded972021-01-07 17:32:00 -0800235 return false;
236 }
237
238 if (strcmp("sync", options_str) == 0) {
239 *level = M_HEAP_TAGGING_LEVEL_SYNC;
240 } else if (strcmp("async", options_str) == 0) {
241 *level = M_HEAP_TAGGING_LEVEL_ASYNC;
242 } else if (strcmp("off", options_str) == 0) {
243 *level = M_HEAP_TAGGING_LEVEL_TBI;
244 } else {
Florian Mayerdd443782023-05-17 20:59:14 +0000245 async_safe_format_log(
246 ANDROID_LOG_ERROR, "libc",
247 "unrecognized memtag level: \"%s\" (options are \"sync\", \"async\", or \"off\").",
248 options_str);
Mitch Phillips4cded972021-01-07 17:32:00 -0800249 return false;
250 }
Mitch Phillips4cded972021-01-07 17:32:00 -0800251
Florian Mayerdd443782023-05-17 20:59:14 +0000252 return true;
Florian Mayerb3f3e862023-03-17 11:27:47 -0700253}
254
Mitch Phillips4cded972021-01-07 17:32:00 -0800255// Returns the initial heap tagging level. Note: This function will never return
256// M_HEAP_TAGGING_LEVEL_NONE, if MTE isn't enabled for this process we enable
257// M_HEAP_TAGGING_LEVEL_TBI.
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200258static HeapTaggingLevel __get_tagging_level(const memtag_dynamic_entries_t* memtag_dynamic_entries,
259 const void* phdr_start, size_t phdr_ct,
260 uintptr_t load_bias, bool* stack) {
261 HeapTaggingLevel level = M_HEAP_TAGGING_LEVEL_TBI;
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700262
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200263 // If the dynamic entries exist, use those. Otherwise, fall back to the old
264 // Android note, which is still used for fully static executables. When
265 // -fsanitize=memtag* is used in newer toolchains, currently both the dynamic
266 // entries and the old note are created, but we'd expect to move to just the
267 // dynamic entries for dynamically linked executables in the future. In
268 // addition, there's still some cleanup of the build system (that uses a
269 // manually-constructed note) needed. For more information about the dynamic
270 // entries, see:
271 // https://github.com/ARM-software/abi-aa/blob/main/memtagabielf64/memtagabielf64.rst#dynamic-section
272 if (memtag_dynamic_entries && memtag_dynamic_entries->has_memtag_mode) {
273 switch (memtag_dynamic_entries->memtag_mode) {
274 case 0:
275 level = M_HEAP_TAGGING_LEVEL_SYNC;
276 break;
277 case 1:
278 level = M_HEAP_TAGGING_LEVEL_ASYNC;
279 break;
280 default:
281 async_safe_format_log(ANDROID_LOG_INFO, "libc",
282 "unrecognised DT_AARCH64_MEMTAG_MODE value: %u",
283 memtag_dynamic_entries->memtag_mode);
284 }
285 *stack = memtag_dynamic_entries->memtag_stack;
286 } else {
287 level = __get_memtag_level_from_note(reinterpret_cast<const ElfW(Phdr)*>(phdr_start), phdr_ct,
288 load_bias, stack);
Mitch Phillips4cded972021-01-07 17:32:00 -0800289 }
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200290
291 // We can't short-circuit the environment override, as `stack` is still inherited from the
292 // binary's settings.
Florian Mayerc0aa70a2024-06-24 15:49:20 -0700293 get_environment_memtag_setting(&level);
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200294 return level;
Mitch Phillips4cded972021-01-07 17:32:00 -0800295}
296
Florian Mayer5d9725b2024-05-15 18:33:49 -0700297static void __enable_mte_signal_handler(int, siginfo_t* info, void*) {
298 if (info->si_code != SI_TIMER) {
299 async_safe_format_log(ANDROID_LOG_ERROR, "libc", "Got BIONIC_ENABLE_MTE not from SI_TIMER");
300 return;
301 }
302 int tagged_addr_ctrl = prctl(PR_GET_TAGGED_ADDR_CTRL, 0, 0, 0, 0);
303 if (tagged_addr_ctrl < 0) {
304 async_safe_fatal("failed to PR_GET_TAGGED_ADDR_CTRL: %m");
305 }
306 if ((tagged_addr_ctrl & PR_MTE_TCF_MASK) != PR_MTE_TCF_NONE) {
307 return;
308 }
309 async_safe_format_log(ANDROID_LOG_INFO, "libc",
310 "Re-enabling MTE, value: %x (tagged_addr_ctrl %lu)",
311 info->si_value.sival_int, info->si_value.sival_int & PR_MTE_TCF_MASK);
312 tagged_addr_ctrl =
313 (tagged_addr_ctrl & ~PR_MTE_TCF_MASK) | (info->si_value.sival_int & PR_MTE_TCF_MASK);
314 if (prctl(PR_SET_TAGGED_ADDR_CTRL, tagged_addr_ctrl, 0, 0, 0) < 0) {
315 async_safe_fatal("failed to PR_SET_TAGGED_ADDR_CTRL %d: %m", tagged_addr_ctrl);
316 }
317}
318
Florian Mayerf3326582024-05-13 15:12:49 -0700319static int64_t __get_memtag_upgrade_secs() {
320 char* env = getenv("BIONIC_MEMTAG_UPGRADE_SECS");
321 if (!env) return 0;
322 int64_t timed_upgrade = 0;
323 static const char kAppProcessName[] = "app_process64";
324 const char* progname = __libc_shared_globals()->init_progname;
325 progname = progname ? __gnu_basename(progname) : nullptr;
326 // disable timed upgrade for zygote, as the thread spawned will violate the requirement
327 // that it be single-threaded.
328 if (!progname || strncmp(progname, kAppProcessName, sizeof(kAppProcessName)) != 0) {
329 char* endptr;
330 timed_upgrade = strtoll(env, &endptr, 10);
331 if (*endptr != '\0' || timed_upgrade < 0) {
332 async_safe_format_log(ANDROID_LOG_ERROR, "libc",
333 "Invalid value for BIONIC_MEMTAG_UPGRADE_SECS: %s", env);
334 timed_upgrade = 0;
335 }
336 }
337 // Make sure that this does not get passed to potential processes inheriting
338 // this environment.
339 unsetenv("BIONIC_MEMTAG_UPGRADE_SECS");
340 return timed_upgrade;
341}
342
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800343// Figure out the desired memory tagging mode (sync/async, heap/globals/stack) for this executable.
344// This function is called from the linker before the main executable is relocated.
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200345__attribute__((no_sanitize("hwaddress", "memtag"))) void __libc_init_mte(
346 const memtag_dynamic_entries_t* memtag_dynamic_entries, const void* phdr_start, size_t phdr_ct,
347 uintptr_t load_bias, void* stack_top) {
348 bool memtag_stack = false;
349 HeapTaggingLevel level =
350 __get_tagging_level(memtag_dynamic_entries, phdr_start, phdr_ct, load_bias, &memtag_stack);
Florian Mayerc0aa70a2024-06-24 15:49:20 -0700351 // initial_memtag_stack is used by the linker (in linker.cpp) to communicate than any library
352 // linked by this executable enables memtag-stack.
353 // memtag_stack is also set for static executables if they request memtag stack via the note,
354 // in which case it will differ from initial_memtag_stack.
355 if (__libc_shared_globals()->initial_memtag_stack || memtag_stack) {
Florian Mayere65e1932024-02-15 22:20:54 +0000356 memtag_stack = true;
Florian Mayerc0aa70a2024-06-24 15:49:20 -0700357 __libc_shared_globals()->initial_memtag_stack_abi = true;
358 __get_bionic_tcb()->tls_slot(TLS_SLOT_STACK_MTE) = __allocate_stack_mte_ringbuffer(0, nullptr);
Florian Mayere65e1932024-02-15 22:20:54 +0000359 }
Florian Mayerf3326582024-05-13 15:12:49 -0700360 if (int64_t timed_upgrade = __get_memtag_upgrade_secs()) {
Florian Mayer408e1702022-05-12 13:06:04 -0700361 if (level == M_HEAP_TAGGING_LEVEL_ASYNC) {
362 async_safe_format_log(ANDROID_LOG_INFO, "libc",
363 "Attempting timed MTE upgrade from async to sync.");
364 __libc_shared_globals()->heap_tagging_upgrade_timer_sec = timed_upgrade;
365 level = M_HEAP_TAGGING_LEVEL_SYNC;
366 } else if (level != M_HEAP_TAGGING_LEVEL_SYNC) {
367 async_safe_format_log(
368 ANDROID_LOG_ERROR, "libc",
369 "Requested timed MTE upgrade from invalid %s to sync. Ignoring.",
370 DescribeTaggingLevel(level));
371 }
372 }
Mitch Phillips4cded972021-01-07 17:32:00 -0800373 if (level == M_HEAP_TAGGING_LEVEL_SYNC || level == M_HEAP_TAGGING_LEVEL_ASYNC) {
374 unsigned long prctl_arg = PR_TAGGED_ADDR_ENABLE | PR_MTE_TAG_SET_NONZERO;
375 prctl_arg |= (level == M_HEAP_TAGGING_LEVEL_SYNC) ? PR_MTE_TCF_SYNC : PR_MTE_TCF_ASYNC;
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800376
Peter Collingbourne48bf46b2021-07-01 15:16:40 -0700377 // When entering ASYNC mode, specify that we want to allow upgrading to SYNC by OR'ing in the
378 // SYNC flag. But if the kernel doesn't support specifying multiple TCF modes, fall back to
379 // specifying a single mode.
380 if (prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg | PR_MTE_TCF_SYNC, 0, 0, 0) == 0 ||
381 prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg, 0, 0, 0) == 0) {
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800382 __libc_shared_globals()->initial_heap_tagging_level = level;
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700383 __libc_shared_globals()->initial_memtag_stack = memtag_stack;
384
385 if (memtag_stack) {
Peter Collingbournebb11ee62022-05-02 12:26:16 -0700386 void* pg_start =
387 reinterpret_cast<void*>(page_start(reinterpret_cast<uintptr_t>(stack_top)));
Kalesh Singh183f58b2023-08-21 11:40:03 -0700388 if (mprotect(pg_start, page_size(), PROT_READ | PROT_WRITE | PROT_MTE | PROT_GROWSDOWN)) {
Elliott Hughes2557f732023-07-12 21:15:23 +0000389 async_safe_fatal("error: failed to set PROT_MTE on main thread stack: %m");
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700390 }
391 }
Florian Mayer5d9725b2024-05-15 18:33:49 -0700392 struct sigaction action = {};
393 action.sa_flags = SA_SIGINFO | SA_RESTART;
394 action.sa_sigaction = __enable_mte_signal_handler;
395 sigaction(BIONIC_ENABLE_MTE, &action, nullptr);
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800396 return;
397 }
398 }
399
Mitch Phillips4cded972021-01-07 17:32:00 -0800400 // MTE was either not enabled, or wasn't supported on this device. Try and use
401 // TBI.
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800402 if (prctl(PR_SET_TAGGED_ADDR_CTRL, PR_TAGGED_ADDR_ENABLE, 0, 0, 0) == 0) {
403 __libc_shared_globals()->initial_heap_tagging_level = M_HEAP_TAGGING_LEVEL_TBI;
404 }
Florian Mayer408e1702022-05-12 13:06:04 -0700405 // We did not enable MTE, so we do not need to arm the upgrade timer.
406 __libc_shared_globals()->heap_tagging_upgrade_timer_sec = 0;
Florian Mayere65e1932024-02-15 22:20:54 +0000407 // We also didn't enable memtag_stack.
408 __libc_shared_globals()->initial_memtag_stack = false;
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800409}
410#else // __aarch64__
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200411void __libc_init_mte(const memtag_dynamic_entries_t*, const void*, size_t, uintptr_t, void*) {}
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800412#endif // __aarch64__
413
Elliott Hughes37719372021-09-29 16:52:20 -0700414void __libc_init_profiling_handlers() {
415 // The dynamic variant of this function is more interesting, but this
416 // at least ensures that static binaries aren't killed by the kernel's
417 // default disposition for these two real-time signals that would have
418 // handlers installed if this was a dynamic binary.
419 signal(BIONIC_SIGNAL_PROFILER, SIG_IGN);
420 signal(BIONIC_SIGNAL_ART_PROFILER, SIG_IGN);
421}
422
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700423__attribute__((no_sanitize("memtag"))) __noreturn static void __real_libc_init(
424 void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
425 structors_array_t const* const structors, bionic_tcb* temp_tcb) {
Christopher Ferris93ea09f2017-10-05 15:18:47 -0700426 BIONIC_STOP_UNWIND;
427
Ryan Prichard9cfca862018-11-22 02:44:09 -0800428 // Initialize TLS early so system calls and errno work.
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800429 KernelArgumentBlock args(raw_args);
Ryan Prichard45d13492019-01-03 02:51:30 -0800430 __libc_init_main_thread_early(args, temp_tcb);
Ryan Prichard07440a82018-11-22 03:16:06 -0800431 __libc_init_main_thread_late();
432 __libc_init_globals();
Ryan Prichard9cfca862018-11-22 02:44:09 -0800433 __libc_shared_globals()->init_progname = args.argv[0];
Ryan Prichard48b11592018-11-22 02:41:36 -0800434 __libc_init_AT_SECURE(args.envp);
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800435 layout_static_tls(args);
Ryan Prichard45d13492019-01-03 02:51:30 -0800436 __libc_init_main_thread_final();
Ryan Prichard48b11592018-11-22 02:41:36 -0800437 __libc_init_common();
Mitch Phillips7c1f3772023-09-28 13:45:59 +0200438 __libc_init_mte(/*memtag_dynamic_entries=*/nullptr,
439 reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)), getauxval(AT_PHNUM),
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700440 /*load_bias = */ 0, /*stack_top = */ raw_args);
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800441 __libc_init_scudo();
Elliott Hughes37719372021-09-29 16:52:20 -0700442 __libc_init_profiling_handlers();
Mitch Phillips1d2aadc2019-11-14 16:02:09 -0800443 __libc_init_fork_handler();
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800444
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -0800445 call_ifunc_resolvers();
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800446 apply_gnu_relro();
447
448 // Several Linux ABIs don't pass the onexit pointer, and the ones that
449 // do never use it. Therefore, we ignore it.
450
Yabin Cui744cfd32023-08-24 13:20:23 -0700451 call_array(structors->preinit_array, structors->preinit_array_count, args.argc, args.argv,
452 args.envp);
453 call_array(structors->init_array, structors->init_array_count, args.argc, args.argv, args.envp);
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800454
455 // The executable may have its own destructors listed in its .fini_array
456 // so we need to ensure that these are called when the program exits
457 // normally.
Yabin Cui744cfd32023-08-24 13:20:23 -0700458 if (structors->fini_array_count > 0) {
459 __cxa_atexit(call_fini_array, const_cast<structors_array_t*>(structors), nullptr);
Dmitriy Ivanov4b415552014-09-04 21:54:34 +0000460 }
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800461
Florian Mayer408e1702022-05-12 13:06:04 -0700462 __libc_init_mte_late();
463
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800464 exit(slingshot(args.argc, args.argv, args.envp));
465}
Yabin Cuica482742016-01-25 17:38:44 -0800466
Peter Collingbourned75e3082019-01-31 16:27:54 -0800467extern "C" void __hwasan_init_static();
Evgenii Stepanov13e8dcb2018-09-19 16:29:12 -0700468
Elliott Hughesf9930b72020-02-10 10:30:38 -0800469// This __libc_init() is only used for static executables, and is called from crtbegin.c.
470//
471// The 'structors' parameter contains pointers to various initializer
472// arrays that must be run before the program's 'main' routine is launched.
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700473__attribute__((no_sanitize("hwaddress", "memtag"))) __noreturn void __libc_init(
474 void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
475 structors_array_t const* const structors) {
Ryan Prichard45d13492019-01-03 02:51:30 -0800476 bionic_tcb temp_tcb = {};
Evgenii Stepanovbe551f52018-08-13 16:46:15 -0700477#if __has_feature(hwaddress_sanitizer)
Evgenii Stepanov13e8dcb2018-09-19 16:29:12 -0700478 // Install main thread TLS early. It will be initialized later in __libc_init_main_thread. For now
Ryan Prichard45d13492019-01-03 02:51:30 -0800479 // all we need is access to TLS_SLOT_SANITIZER.
480 __set_tls(&temp_tcb.tls_slot(0));
Peter Collingbourned75e3082019-01-31 16:27:54 -0800481 // Initialize HWASan enough to run instrumented code. This sets up TLS_SLOT_SANITIZER, among other
482 // things.
483 __hwasan_init_static();
Evgenii Stepanov13e8dcb2018-09-19 16:29:12 -0700484 // We are ready to run HWASan-instrumented code, proceed with libc initialization...
Evgenii Stepanovbe551f52018-08-13 16:46:15 -0700485#endif
Ryan Prichard45d13492019-01-03 02:51:30 -0800486 __real_libc_init(raw_args, onexit, slingshot, structors, &temp_tcb);
Evgenii Stepanovbe551f52018-08-13 16:46:15 -0700487}
488
Elliott Hughesff1428a2018-11-12 16:01:37 -0800489static int g_target_sdk_version{__ANDROID_API__};
Elliott Hughes46a943c2018-04-03 15:56:35 -0700490
Elliott Hughesff1428a2018-11-12 16:01:37 -0800491extern "C" int android_get_application_target_sdk_version() {
Elliott Hughes46a943c2018-04-03 15:56:35 -0700492 return g_target_sdk_version;
493}
494
Elliott Hughesff1428a2018-11-12 16:01:37 -0800495extern "C" void android_set_application_target_sdk_version(int target) {
Elliott Hughes46a943c2018-04-03 15:56:35 -0700496 g_target_sdk_version = target;
Peter Collingbourne2659d7b2021-03-05 13:31:41 -0800497 __libc_set_target_sdk_version(target);
Yabin Cuica482742016-01-25 17:38:44 -0800498}
Ryan Prichardabf736a2018-11-22 02:40:17 -0800499
Ryan Prichard249757b2019-11-01 17:18:28 -0700500// This function is called in the dynamic linker before ifunc resolvers have run, so this file is
501// compiled with -ffreestanding to avoid implicit string.h function calls. (It shouldn't strictly
502// be necessary, though.)
Ryan Prichardabf736a2018-11-22 02:40:17 -0800503__LIBC_HIDDEN__ libc_shared_globals* __libc_shared_globals() {
Evgenii Stepanov6bbb75a2023-12-06 18:54:45 +0000504 static libc_shared_globals globals;
Ryan Prichardabf736a2018-11-22 02:40:17 -0800505 return &globals;
506}