blob: d64d402ab0055d7f801797bb46f5ec093ae2d0b0 [file] [log] [blame]
Elliott Hughes42b2c6a2013-02-07 10:14:39 -08001/*
2 * Copyright (C) 2008 The Android Open Source Project
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * * Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * * Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in
12 * the documentation and/or other materials provided with the
13 * distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19 * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22 * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25 * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 */
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080028
Yabin Cuica482742016-01-25 17:38:44 -080029#include <android/api-level.h>
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080030#include <elf.h>
31#include <errno.h>
Florian Mayer408e1702022-05-12 13:06:04 -070032#include <malloc.h>
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080033#include <stddef.h>
34#include <stdint.h>
35#include <stdio.h>
36#include <stdlib.h>
37#include <sys/auxv.h>
38#include <sys/mman.h>
39
Florian Mayer408e1702022-05-12 13:06:04 -070040#include "async_safe/log.h"
41#include "heap_tagging.h"
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080042#include "libc_init_common.h"
Mitch Phillips4cded972021-01-07 17:32:00 -080043#include "platform/bionic/macros.h"
44#include "platform/bionic/mte.h"
Elliott Hughescdb52fc2019-12-12 15:26:14 -080045#include "platform/bionic/page.h"
Elliott Hughes37719372021-09-29 16:52:20 -070046#include "platform/bionic/reserved_signals.h"
Mitch Phillips4cded972021-01-07 17:32:00 -080047#include "private/KernelArgumentBlock.h"
48#include "private/bionic_asm.h"
49#include "private/bionic_asm_note.h"
Peter Collingbournee9491952019-10-28 10:57:26 -070050#include "private/bionic_call_ifunc_resolver.h"
Ryan Prichard45d13492019-01-03 02:51:30 -080051#include "private/bionic_elf_tls.h"
Josh Gaob6453c52016-06-29 16:47:53 -070052#include "private/bionic_globals.h"
Elliott Hugheseb847bc2013-10-09 15:50:50 -070053#include "private/bionic_tls.h"
Florian Mayer408e1702022-05-12 13:06:04 -070054#include "pthread_internal.h"
Mitch Phillips4cded972021-01-07 17:32:00 -080055#include "sys/system_properties.h"
Florian Mayer408e1702022-05-12 13:06:04 -070056#include "sysprop_helpers.h"
Elliott Hugheseb847bc2013-10-09 15:50:50 -070057
Evgenii Stepanovbe551f52018-08-13 16:46:15 -070058#if __has_feature(hwaddress_sanitizer)
59#include <sanitizer/hwasan_interface.h>
60#endif
61
Ryan Prichard27475b52018-05-17 17:14:18 -070062// Leave the variable uninitialized for the sake of the dynamic loader, which
63// links in this file. The loader will initialize this variable before
64// relocating itself.
65#if defined(__i386__)
66__LIBC_HIDDEN__ void* __libc_sysinfo;
67#endif
68
Dmitriy Ivanov53c3c272014-07-11 12:59:16 -070069extern "C" int __cxa_atexit(void (*)(void *), void *, void *);
Mitch Phillips4cded972021-01-07 17:32:00 -080070extern "C" const char* __gnu_basename(const char* path);
Dmitriy Ivanov53c3c272014-07-11 12:59:16 -070071
Matthew Maurerde306352020-10-23 09:55:33 -070072static void call_array(init_func_t** list, int argc, char* argv[], char* envp[]) {
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080073 // First element is -1, list is null-terminated
74 while (*++list) {
Matthew Maurerde306352020-10-23 09:55:33 -070075 (*list)(argc, argv, envp);
Elliott Hughes42b2c6a2013-02-07 10:14:39 -080076 }
77}
78
Elliott Hughes6cfd1b52022-10-05 00:15:49 +000079#if defined(__arm__) || defined(__i386__) // Legacy architectures used REL...
Dan Alberta535d3c2019-02-14 16:19:59 -080080extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rel) __rel_iplt_start[], __rel_iplt_end[];
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -080081
82static void call_ifunc_resolvers() {
Dan Alberta535d3c2019-02-14 16:19:59 -080083 if (__rel_iplt_start == nullptr || __rel_iplt_end == nullptr) {
Elliott Hughes6cfd1b52022-10-05 00:15:49 +000084 // These symbols were not emitted by gold. Gold has code to do so, but for
Dan Alberta535d3c2019-02-14 16:19:59 -080085 // whatever reason it is not being run. In these cases ifuncs cannot be
86 // resolved, so we do not support using ifuncs in static executables linked
87 // with gold.
88 //
89 // Since they are weak, they will be non-null when linked with bfd/lld and
90 // null when linked with gold.
91 return;
92 }
93
Elliott Hughes6cfd1b52022-10-05 00:15:49 +000094 for (ElfW(Rel)* r = __rel_iplt_start; r != __rel_iplt_end; ++r) {
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -080095 ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
96 ElfW(Addr) resolver = *offset;
Peter Collingbournee9491952019-10-28 10:57:26 -070097 *offset = __bionic_call_ifunc_resolver(resolver);
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -080098 }
99}
Elliott Hughes6cfd1b52022-10-05 00:15:49 +0000100#else // ...but modern architectures use RELA instead.
101extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rela) __rela_iplt_start[], __rela_iplt_end[];
102
103static void call_ifunc_resolvers() {
104 if (__rela_iplt_start == nullptr || __rela_iplt_end == nullptr) {
105 // These symbols were not emitted by gold. Gold has code to do so, but for
106 // whatever reason it is not being run. In these cases ifuncs cannot be
107 // resolved, so we do not support using ifuncs in static executables linked
108 // with gold.
109 //
110 // Since they are weak, they will be non-null when linked with bfd/lld and
111 // null when linked with gold.
112 return;
113 }
114
115 for (ElfW(Rela)* r = __rela_iplt_start; r != __rela_iplt_end; ++r) {
116 ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
117 ElfW(Addr) resolver = r->r_addend;
118 *offset = __bionic_call_ifunc_resolver(resolver);
119 }
120}
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -0800121#endif
122
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800123static void apply_gnu_relro() {
Elliott Hughes0266ae52014-02-10 17:46:57 -0800124 ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800125 unsigned long int phdr_ct = getauxval(AT_PHNUM);
126
Elliott Hughes0266ae52014-02-10 17:46:57 -0800127 for (ElfW(Phdr)* phdr = phdr_start; phdr < (phdr_start + phdr_ct); phdr++) {
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800128 if (phdr->p_type != PT_GNU_RELRO) {
129 continue;
130 }
131
Elliott Hughes0266ae52014-02-10 17:46:57 -0800132 ElfW(Addr) seg_page_start = PAGE_START(phdr->p_vaddr);
133 ElfW(Addr) seg_page_end = PAGE_END(phdr->p_vaddr + phdr->p_memsz);
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800134
135 // Check return value here? What do we do if we fail?
136 mprotect(reinterpret_cast<void*>(seg_page_start), seg_page_end - seg_page_start, PROT_READ);
137 }
138}
139
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800140static void layout_static_tls(KernelArgumentBlock& args) {
Ryan Prichard45d13492019-01-03 02:51:30 -0800141 StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout;
142 layout.reserve_bionic_tls();
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800143
144 const char* progname = args.argv[0];
145 ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
146 size_t phdr_ct = getauxval(AT_PHNUM);
147
Ryan Prichard19883502019-01-16 23:13:38 -0800148 static TlsModule mod;
Ryan Prichard16455b52019-01-18 01:00:59 -0800149 TlsModules& modules = __libc_shared_globals()->tls_modules;
Ryan Prichard19883502019-01-16 23:13:38 -0800150 if (__bionic_get_tls_segment(phdr_start, phdr_ct, 0, &mod.segment)) {
151 if (!__bionic_check_tls_alignment(&mod.segment.alignment)) {
152 async_safe_fatal("error: TLS segment alignment in \"%s\" is not a power of 2: %zu\n",
153 progname, mod.segment.alignment);
154 }
155 mod.static_offset = layout.reserve_exe_segment_and_tcb(&mod.segment, progname);
Ryan Prichard16455b52019-01-18 01:00:59 -0800156 mod.first_generation = kTlsGenerationFirst;
157
158 modules.module_count = 1;
Vy Nguyend5007512020-07-14 17:37:04 -0400159 modules.static_module_count = 1;
Ryan Prichard16455b52019-01-18 01:00:59 -0800160 modules.module_table = &mod;
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800161 } else {
162 layout.reserve_exe_segment_and_tcb(nullptr, progname);
163 }
Ryan Prichard16455b52019-01-18 01:00:59 -0800164 // Enable the fast path in __tls_get_addr.
165 __libc_tls_generation_copy = modules.generation;
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800166
Ryan Prichard45d13492019-01-03 02:51:30 -0800167 layout.finish_layout();
168}
169
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800170#ifdef __aarch64__
171static bool __read_memtag_note(const ElfW(Nhdr)* note, const char* name, const char* desc,
172 unsigned* result) {
Mitch Phillips93400372022-02-07 13:49:20 -0800173 if (note->n_type != NT_ANDROID_TYPE_MEMTAG) {
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800174 return false;
175 }
Mitch Phillips9425b162022-02-04 17:13:27 -0800176 if (note->n_namesz != 8 || strncmp(name, "Android", 8) != 0) {
177 return false;
178 }
179 // Previously (in Android 12), if the note was != 4 bytes, we check-failed
180 // here. Let's be more permissive to allow future expansion.
181 if (note->n_descsz < 4) {
182 async_safe_fatal("unrecognized android.memtag note: n_descsz = %d, expected >= 4",
183 note->n_descsz);
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800184 }
185 *result = *reinterpret_cast<const ElfW(Word)*>(desc);
186 return true;
187}
188
189static unsigned __get_memtag_note(const ElfW(Phdr)* phdr_start, size_t phdr_ct,
190 const ElfW(Addr) load_bias) {
191 for (size_t i = 0; i < phdr_ct; ++i) {
192 const ElfW(Phdr)* phdr = &phdr_start[i];
193 if (phdr->p_type != PT_NOTE) {
194 continue;
195 }
196 ElfW(Addr) p = load_bias + phdr->p_vaddr;
197 ElfW(Addr) note_end = load_bias + phdr->p_vaddr + phdr->p_memsz;
198 while (p + sizeof(ElfW(Nhdr)) <= note_end) {
199 const ElfW(Nhdr)* note = reinterpret_cast<const ElfW(Nhdr)*>(p);
200 p += sizeof(ElfW(Nhdr));
201 const char* name = reinterpret_cast<const char*>(p);
202 p += align_up(note->n_namesz, 4);
203 const char* desc = reinterpret_cast<const char*>(p);
204 p += align_up(note->n_descsz, 4);
205 if (p > note_end) {
206 break;
207 }
208 unsigned ret;
209 if (__read_memtag_note(note, name, desc, &ret)) {
210 return ret;
211 }
212 }
213 }
214 return 0;
215}
216
Mitch Phillips4cded972021-01-07 17:32:00 -0800217// Returns true if there's an environment setting (either sysprop or env var)
218// that should overwrite the ELF note, and places the equivalent heap tagging
219// level into *level.
220static bool get_environment_memtag_setting(HeapTaggingLevel* level) {
221 static const char kMemtagPrognameSyspropPrefix[] = "arm64.memtag.process.";
Florian Mayerdde31762022-01-24 18:29:50 -0800222 static const char kMemtagGlobalSysprop[] = "persist.arm64.memtag.default";
Florian Mayerdee80d52022-08-01 15:16:01 -0700223 static const char kMemtagOverrideSyspropPrefix[] =
224 "persist.device_config.memory_safety_native.mode_override.process.";
Mitch Phillips4cded972021-01-07 17:32:00 -0800225
226 const char* progname = __libc_shared_globals()->init_progname;
227 if (progname == nullptr) return false;
228
229 const char* basename = __gnu_basename(progname);
230
Florian Mayer27914292022-08-01 15:02:25 -0700231 char options_str[PROP_VALUE_MAX];
232 char sysprop_name[512];
233 async_safe_format_buffer(sysprop_name, sizeof(sysprop_name), "%s%s", kMemtagPrognameSyspropPrefix,
Mitch Phillips4cded972021-01-07 17:32:00 -0800234 basename);
Florian Mayerdee80d52022-08-01 15:16:01 -0700235 char remote_sysprop_name[512];
236 async_safe_format_buffer(remote_sysprop_name, sizeof(remote_sysprop_name), "%s%s",
237 kMemtagOverrideSyspropPrefix, basename);
238 const char* sys_prop_names[] = {sysprop_name, remote_sysprop_name, kMemtagGlobalSysprop};
Mitch Phillips4cded972021-01-07 17:32:00 -0800239
Florian Mayerdde31762022-01-24 18:29:50 -0800240 if (!get_config_from_env_or_sysprops("MEMTAG_OPTIONS", sys_prop_names, arraysize(sys_prop_names),
Florian Mayer27914292022-08-01 15:02:25 -0700241 options_str, sizeof(options_str))) {
Mitch Phillips4cded972021-01-07 17:32:00 -0800242 return false;
243 }
244
245 if (strcmp("sync", options_str) == 0) {
246 *level = M_HEAP_TAGGING_LEVEL_SYNC;
247 } else if (strcmp("async", options_str) == 0) {
248 *level = M_HEAP_TAGGING_LEVEL_ASYNC;
249 } else if (strcmp("off", options_str) == 0) {
250 *level = M_HEAP_TAGGING_LEVEL_TBI;
251 } else {
252 async_safe_format_log(
253 ANDROID_LOG_ERROR, "libc",
254 "unrecognized memtag level: \"%s\" (options are \"sync\", \"async\", or \"off\").",
255 options_str);
256 return false;
257 }
258
259 return true;
260}
261
262// Returns the initial heap tagging level. Note: This function will never return
263// M_HEAP_TAGGING_LEVEL_NONE, if MTE isn't enabled for this process we enable
264// M_HEAP_TAGGING_LEVEL_TBI.
265static HeapTaggingLevel __get_heap_tagging_level(const void* phdr_start, size_t phdr_ct,
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700266 uintptr_t load_bias, bool* stack) {
267 unsigned note_val =
268 __get_memtag_note(reinterpret_cast<const ElfW(Phdr)*>(phdr_start), phdr_ct, load_bias);
269 *stack = note_val & NT_MEMTAG_STACK;
270
Mitch Phillips4cded972021-01-07 17:32:00 -0800271 HeapTaggingLevel level;
272 if (get_environment_memtag_setting(&level)) return level;
273
Mitch Phillips9425b162022-02-04 17:13:27 -0800274 // Note, previously (in Android 12), any value outside of bits [0..3] resulted
275 // in a check-fail. In order to be permissive of further extensions, we
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700276 // relaxed this restriction.
277 if (!(note_val & (NT_MEMTAG_HEAP | NT_MEMTAG_STACK))) return M_HEAP_TAGGING_LEVEL_TBI;
Mitch Phillips4cded972021-01-07 17:32:00 -0800278
Mitch Phillips9425b162022-02-04 17:13:27 -0800279 unsigned mode = note_val & NT_MEMTAG_LEVEL_MASK;
280 switch (mode) {
281 case NT_MEMTAG_LEVEL_NONE:
282 // Note, previously (in Android 12), NT_MEMTAG_LEVEL_NONE was
283 // NT_MEMTAG_LEVEL_DEFAULT, which implied SYNC mode. This was never used
284 // by anyone, but we note it (heh) here for posterity, in case the zero
285 // level becomes meaningful, and binaries with this note can be executed
286 // on Android 12 devices.
287 return M_HEAP_TAGGING_LEVEL_TBI;
Mitch Phillips4cded972021-01-07 17:32:00 -0800288 case NT_MEMTAG_LEVEL_ASYNC:
289 return M_HEAP_TAGGING_LEVEL_ASYNC;
Mitch Phillips4cded972021-01-07 17:32:00 -0800290 case NT_MEMTAG_LEVEL_SYNC:
Mitch Phillips4cded972021-01-07 17:32:00 -0800291 default:
Mitch Phillips9425b162022-02-04 17:13:27 -0800292 // We allow future extensions to specify mode 3 (currently unused), with
293 // the idea that it might be used for ASYMM mode or something else. On
294 // this version of Android, it falls back to SYNC mode.
295 return M_HEAP_TAGGING_LEVEL_SYNC;
Mitch Phillips4cded972021-01-07 17:32:00 -0800296 }
297}
298
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800299// Figure out the desired memory tagging mode (sync/async, heap/globals/stack) for this executable.
300// This function is called from the linker before the main executable is relocated.
301__attribute__((no_sanitize("hwaddress", "memtag"))) void __libc_init_mte(const void* phdr_start,
302 size_t phdr_ct,
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700303 uintptr_t load_bias,
304 void* stack_top) {
305 bool memtag_stack;
306 HeapTaggingLevel level = __get_heap_tagging_level(phdr_start, phdr_ct, load_bias, &memtag_stack);
Florian Mayer408e1702022-05-12 13:06:04 -0700307 char* env = getenv("BIONIC_MEMTAG_UPGRADE_SECS");
Florian Mayer14cbb792022-08-10 14:57:14 -0700308 static const char kAppProcessName[] = "app_process64";
309 const char* progname = __libc_shared_globals()->init_progname;
310 progname = progname ? __gnu_basename(progname) : nullptr;
311 if (progname &&
312 strncmp(progname, kAppProcessName, sizeof(kAppProcessName)) == 0) {
313 // disable timed upgrade for zygote, as the thread spawned will violate the requirement
314 // that it be single-threaded.
315 env = nullptr;
316 }
Florian Mayer408e1702022-05-12 13:06:04 -0700317 int64_t timed_upgrade = 0;
318 if (env) {
319 char* endptr;
320 timed_upgrade = strtoll(env, &endptr, 10);
321 if (*endptr != '\0' || timed_upgrade < 0) {
322 async_safe_format_log(ANDROID_LOG_ERROR, "libc",
323 "Invalid value for BIONIC_MEMTAG_UPGRADE_SECS: %s",
324 env);
325 timed_upgrade = 0;
326 }
327 // Make sure that this does not get passed to potential processes inheriting
328 // this environment.
329 unsetenv("BIONIC_MEMTAG_UPGRADE_SECS");
330 }
331 if (timed_upgrade) {
332 if (level == M_HEAP_TAGGING_LEVEL_ASYNC) {
333 async_safe_format_log(ANDROID_LOG_INFO, "libc",
334 "Attempting timed MTE upgrade from async to sync.");
335 __libc_shared_globals()->heap_tagging_upgrade_timer_sec = timed_upgrade;
336 level = M_HEAP_TAGGING_LEVEL_SYNC;
337 } else if (level != M_HEAP_TAGGING_LEVEL_SYNC) {
338 async_safe_format_log(
339 ANDROID_LOG_ERROR, "libc",
340 "Requested timed MTE upgrade from invalid %s to sync. Ignoring.",
341 DescribeTaggingLevel(level));
342 }
343 }
Mitch Phillips4cded972021-01-07 17:32:00 -0800344 if (level == M_HEAP_TAGGING_LEVEL_SYNC || level == M_HEAP_TAGGING_LEVEL_ASYNC) {
345 unsigned long prctl_arg = PR_TAGGED_ADDR_ENABLE | PR_MTE_TAG_SET_NONZERO;
346 prctl_arg |= (level == M_HEAP_TAGGING_LEVEL_SYNC) ? PR_MTE_TCF_SYNC : PR_MTE_TCF_ASYNC;
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800347
Peter Collingbourne48bf46b2021-07-01 15:16:40 -0700348 // When entering ASYNC mode, specify that we want to allow upgrading to SYNC by OR'ing in the
349 // SYNC flag. But if the kernel doesn't support specifying multiple TCF modes, fall back to
350 // specifying a single mode.
351 if (prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg | PR_MTE_TCF_SYNC, 0, 0, 0) == 0 ||
352 prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg, 0, 0, 0) == 0) {
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800353 __libc_shared_globals()->initial_heap_tagging_level = level;
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700354 __libc_shared_globals()->initial_memtag_stack = memtag_stack;
355
356 if (memtag_stack) {
357 void* page_start =
358 reinterpret_cast<void*>(PAGE_START(reinterpret_cast<uintptr_t>(stack_top)));
359 if (mprotect(page_start, PAGE_SIZE, PROT_READ | PROT_WRITE | PROT_MTE | PROT_GROWSDOWN)) {
360 async_safe_fatal("error: failed to set PROT_MTE on main thread stack: %s\n",
361 strerror(errno));
362 }
363 }
364
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800365 return;
366 }
367 }
368
Mitch Phillips4cded972021-01-07 17:32:00 -0800369 // MTE was either not enabled, or wasn't supported on this device. Try and use
370 // TBI.
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800371 if (prctl(PR_SET_TAGGED_ADDR_CTRL, PR_TAGGED_ADDR_ENABLE, 0, 0, 0) == 0) {
372 __libc_shared_globals()->initial_heap_tagging_level = M_HEAP_TAGGING_LEVEL_TBI;
373 }
Florian Mayer408e1702022-05-12 13:06:04 -0700374 // We did not enable MTE, so we do not need to arm the upgrade timer.
375 __libc_shared_globals()->heap_tagging_upgrade_timer_sec = 0;
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800376}
377#else // __aarch64__
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700378void __libc_init_mte(const void*, size_t, uintptr_t, void*) {}
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800379#endif // __aarch64__
380
Elliott Hughes37719372021-09-29 16:52:20 -0700381void __libc_init_profiling_handlers() {
382 // The dynamic variant of this function is more interesting, but this
383 // at least ensures that static binaries aren't killed by the kernel's
384 // default disposition for these two real-time signals that would have
385 // handlers installed if this was a dynamic binary.
386 signal(BIONIC_SIGNAL_PROFILER, SIG_IGN);
387 signal(BIONIC_SIGNAL_ART_PROFILER, SIG_IGN);
388}
389
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700390__attribute__((no_sanitize("memtag"))) __noreturn static void __real_libc_init(
391 void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
392 structors_array_t const* const structors, bionic_tcb* temp_tcb) {
Christopher Ferris93ea09f2017-10-05 15:18:47 -0700393 BIONIC_STOP_UNWIND;
394
Ryan Prichard9cfca862018-11-22 02:44:09 -0800395 // Initialize TLS early so system calls and errno work.
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800396 KernelArgumentBlock args(raw_args);
Ryan Prichard45d13492019-01-03 02:51:30 -0800397 __libc_init_main_thread_early(args, temp_tcb);
Ryan Prichard07440a82018-11-22 03:16:06 -0800398 __libc_init_main_thread_late();
399 __libc_init_globals();
Ryan Prichard9cfca862018-11-22 02:44:09 -0800400 __libc_shared_globals()->init_progname = args.argv[0];
Ryan Prichard48b11592018-11-22 02:41:36 -0800401 __libc_init_AT_SECURE(args.envp);
Ryan Pricharde5e69e02019-01-01 18:53:48 -0800402 layout_static_tls(args);
Ryan Prichard45d13492019-01-03 02:51:30 -0800403 __libc_init_main_thread_final();
Ryan Prichard48b11592018-11-22 02:41:36 -0800404 __libc_init_common();
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800405 __libc_init_mte(reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)), getauxval(AT_PHNUM),
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700406 /*load_bias = */ 0, /*stack_top = */ raw_args);
Evgenii Stepanov8564b8d2020-12-15 13:55:32 -0800407 __libc_init_scudo();
Elliott Hughes37719372021-09-29 16:52:20 -0700408 __libc_init_profiling_handlers();
Mitch Phillips1d2aadc2019-11-14 16:02:09 -0800409 __libc_init_fork_handler();
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800410
Peter Collingbourne7a0f04c2019-01-23 17:56:24 -0800411 call_ifunc_resolvers();
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800412 apply_gnu_relro();
413
414 // Several Linux ABIs don't pass the onexit pointer, and the ones that
415 // do never use it. Therefore, we ignore it.
416
Matthew Maurerde306352020-10-23 09:55:33 -0700417 call_array(structors->preinit_array, args.argc, args.argv, args.envp);
418 call_array(structors->init_array, args.argc, args.argv, args.envp);
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800419
420 // The executable may have its own destructors listed in its .fini_array
421 // so we need to ensure that these are called when the program exits
422 // normally.
Yi Kong32bc0fc2018-08-02 17:31:13 -0700423 if (structors->fini_array != nullptr) {
424 __cxa_atexit(__libc_fini,structors->fini_array,nullptr);
Dmitriy Ivanov4b415552014-09-04 21:54:34 +0000425 }
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800426
Florian Mayer408e1702022-05-12 13:06:04 -0700427 __libc_init_mte_late();
428
Elliott Hughes42b2c6a2013-02-07 10:14:39 -0800429 exit(slingshot(args.argc, args.argv, args.envp));
430}
Yabin Cuica482742016-01-25 17:38:44 -0800431
Peter Collingbourned75e3082019-01-31 16:27:54 -0800432extern "C" void __hwasan_init_static();
Evgenii Stepanov13e8dcb2018-09-19 16:29:12 -0700433
Elliott Hughesf9930b72020-02-10 10:30:38 -0800434// This __libc_init() is only used for static executables, and is called from crtbegin.c.
435//
436// The 'structors' parameter contains pointers to various initializer
437// arrays that must be run before the program's 'main' routine is launched.
Evgenii Stepanovf9fa32a2022-05-12 15:54:38 -0700438__attribute__((no_sanitize("hwaddress", "memtag"))) __noreturn void __libc_init(
439 void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
440 structors_array_t const* const structors) {
Ryan Prichard45d13492019-01-03 02:51:30 -0800441 bionic_tcb temp_tcb = {};
Evgenii Stepanovbe551f52018-08-13 16:46:15 -0700442#if __has_feature(hwaddress_sanitizer)
Evgenii Stepanov13e8dcb2018-09-19 16:29:12 -0700443 // Install main thread TLS early. It will be initialized later in __libc_init_main_thread. For now
Ryan Prichard45d13492019-01-03 02:51:30 -0800444 // all we need is access to TLS_SLOT_SANITIZER.
445 __set_tls(&temp_tcb.tls_slot(0));
Peter Collingbourned75e3082019-01-31 16:27:54 -0800446 // Initialize HWASan enough to run instrumented code. This sets up TLS_SLOT_SANITIZER, among other
447 // things.
448 __hwasan_init_static();
Evgenii Stepanov13e8dcb2018-09-19 16:29:12 -0700449 // We are ready to run HWASan-instrumented code, proceed with libc initialization...
Evgenii Stepanovbe551f52018-08-13 16:46:15 -0700450#endif
Ryan Prichard45d13492019-01-03 02:51:30 -0800451 __real_libc_init(raw_args, onexit, slingshot, structors, &temp_tcb);
Evgenii Stepanovbe551f52018-08-13 16:46:15 -0700452}
453
Elliott Hughesff1428a2018-11-12 16:01:37 -0800454static int g_target_sdk_version{__ANDROID_API__};
Elliott Hughes46a943c2018-04-03 15:56:35 -0700455
Elliott Hughesff1428a2018-11-12 16:01:37 -0800456extern "C" int android_get_application_target_sdk_version() {
Elliott Hughes46a943c2018-04-03 15:56:35 -0700457 return g_target_sdk_version;
458}
459
Elliott Hughesff1428a2018-11-12 16:01:37 -0800460extern "C" void android_set_application_target_sdk_version(int target) {
Elliott Hughes46a943c2018-04-03 15:56:35 -0700461 g_target_sdk_version = target;
Peter Collingbourne2659d7b2021-03-05 13:31:41 -0800462 __libc_set_target_sdk_version(target);
Yabin Cuica482742016-01-25 17:38:44 -0800463}
Ryan Prichardabf736a2018-11-22 02:40:17 -0800464
Ryan Prichard249757b2019-11-01 17:18:28 -0700465// This function is called in the dynamic linker before ifunc resolvers have run, so this file is
466// compiled with -ffreestanding to avoid implicit string.h function calls. (It shouldn't strictly
467// be necessary, though.)
Ryan Prichardabf736a2018-11-22 02:40:17 -0800468__LIBC_HIDDEN__ libc_shared_globals* __libc_shared_globals() {
Ryan Prichard0b0ee0c2018-12-14 17:34:05 -0800469 static libc_shared_globals globals;
Ryan Prichardabf736a2018-11-22 02:40:17 -0800470 return &globals;
471}