blob: 8d8d4207d0b2102f0ac07b2a20d564c0cab97e2e [file] [log] [blame]
Christopher Ferris63860cb2015-11-16 17:30:32 -08001/*
2 * Copyright (C) 2009 The Android Open Source Project
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * * Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * * Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in
12 * the documentation and/or other materials provided with the
13 * distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19 * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22 * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25 * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 */
28
29// Contains a thin layer that calls whatever real native allocator
30// has been defined. For the libc shared library, this allows the
31// implementation of a debug malloc that can intercept all of the allocation
32// calls and add special debugging code to attempt to catch allocation
33// errors. All of the debugging code is implemented in a separate shared
34// library that is only loaded when the property "libc.debug.malloc.options"
35// is set to a non-zero value. There are two functions exported to
36// allow ddms, or other external users to get information from the debug
37// allocation.
38// get_malloc_leak_info: Returns information about all of the known native
39// allocations that are currently in use.
40// free_malloc_leak_info: Frees the data allocated by the call to
41// get_malloc_leak_info.
Christopher Ferris2e1a40a2018-06-13 10:46:34 -070042// write_malloc_leak_info: Writes the leak info data to a file.
Christopher Ferris63860cb2015-11-16 17:30:32 -080043
Colin Cross869691c2016-01-29 12:48:18 -080044#include <pthread.h>
Florian Mayerf7f71e32018-08-31 15:36:48 -070045#include <stdatomic.h>
Colin Cross869691c2016-01-29 12:48:18 -080046
Christopher Ferris63860cb2015-11-16 17:30:32 -080047#include <private/bionic_config.h>
48#include <private/bionic_globals.h>
49#include <private/bionic_malloc_dispatch.h>
50
Evgenii Stepanovbe551f52018-08-13 16:46:15 -070051#if __has_feature(hwaddress_sanitizer)
52// FIXME: implement these in HWASan allocator.
53extern "C" int __sanitizer_iterate(uintptr_t base __unused, size_t size __unused,
54 void (*callback)(uintptr_t base, size_t size, void* arg) __unused,
55 void* arg __unused) {
56 return 0;
57}
58
59extern "C" void __sanitizer_malloc_disable() {
60}
61
62extern "C" void __sanitizer_malloc_enable() {
63}
64#include <sanitizer/hwasan_interface.h>
65#define Malloc(function) __sanitizer_ ## function
66
67#else // __has_feature(hwaddress_sanitizer)
Christopher Ferris63860cb2015-11-16 17:30:32 -080068#include "jemalloc.h"
69#define Malloc(function) je_ ## function
Evgenii Stepanovbe551f52018-08-13 16:46:15 -070070#endif
Christopher Ferris63860cb2015-11-16 17:30:32 -080071
Florian Mayerf7f71e32018-08-31 15:36:48 -070072template <typename T>
73static T* RemoveConst(const T* x) {
74 return const_cast<T*>(x);
75}
76
77// RemoveConst is a workaround for bug in current libcxx. Fix in
78// https://reviews.llvm.org/D47613
79#define atomic_load_explicit_const(obj, order) atomic_load_explicit(RemoveConst(obj), order)
80
81static constexpr memory_order default_read_memory_order = memory_order_acquire;
82
Christopher Ferris63860cb2015-11-16 17:30:32 -080083static constexpr MallocDispatch __libc_malloc_default_dispatch
84 __attribute__((unused)) = {
85 Malloc(calloc),
86 Malloc(free),
87 Malloc(mallinfo),
88 Malloc(malloc),
89 Malloc(malloc_usable_size),
90 Malloc(memalign),
91 Malloc(posix_memalign),
92#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
93 Malloc(pvalloc),
94#endif
95 Malloc(realloc),
96#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
97 Malloc(valloc),
98#endif
Colin Cross869691c2016-01-29 12:48:18 -080099 Malloc(iterate),
100 Malloc(malloc_disable),
101 Malloc(malloc_enable),
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700102 Malloc(mallopt),
Christopher Ferriscae21a92018-02-05 18:14:55 -0800103 Malloc(aligned_alloc),
Christopher Ferris63860cb2015-11-16 17:30:32 -0800104 };
105
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800106// Malloc hooks.
107void* (*volatile __malloc_hook)(size_t, const void*);
108void* (*volatile __realloc_hook)(void*, size_t, const void*);
109void (*volatile __free_hook)(void*, const void*);
110void* (*volatile __memalign_hook)(size_t, size_t, const void*);
111
Christopher Ferris63860cb2015-11-16 17:30:32 -0800112// In a VM process, this is set to 1 after fork()ing out of zygote.
113int gMallocLeakZygoteChild = 0;
114
115// =============================================================================
116// Allocation functions
117// =============================================================================
118extern "C" void* calloc(size_t n_elements, size_t elem_size) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700119 auto _calloc = atomic_load_explicit_const(
120 &__libc_globals->malloc_dispatch.calloc,
121 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800122 if (__predict_false(_calloc != nullptr)) {
123 return _calloc(n_elements, elem_size);
124 }
125 return Malloc(calloc)(n_elements, elem_size);
126}
127
128extern "C" void free(void* mem) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700129 auto _free = atomic_load_explicit_const(
130 &__libc_globals->malloc_dispatch.free,
131 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800132 if (__predict_false(_free != nullptr)) {
133 _free(mem);
134 } else {
135 Malloc(free)(mem);
136 }
137}
138
139extern "C" struct mallinfo mallinfo() {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700140 auto _mallinfo = atomic_load_explicit_const(
141 &__libc_globals->malloc_dispatch.mallinfo,
142 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800143 if (__predict_false(_mallinfo != nullptr)) {
144 return _mallinfo();
145 }
146 return Malloc(mallinfo)();
147}
148
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700149extern "C" int mallopt(int param, int value) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700150 auto _mallopt = atomic_load_explicit_const(
151 &__libc_globals->malloc_dispatch.mallopt,
152 default_read_memory_order);
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700153 if (__predict_false(_mallopt != nullptr)) {
154 return _mallopt(param, value);
155 }
156 return Malloc(mallopt)(param, value);
157}
158
Christopher Ferris63860cb2015-11-16 17:30:32 -0800159extern "C" void* malloc(size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700160 auto _malloc = atomic_load_explicit_const(
161 &__libc_globals->malloc_dispatch.malloc,
162 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800163 if (__predict_false(_malloc != nullptr)) {
164 return _malloc(bytes);
165 }
166 return Malloc(malloc)(bytes);
167}
168
169extern "C" size_t malloc_usable_size(const void* mem) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700170 auto _malloc_usable_size = atomic_load_explicit_const(
171 &__libc_globals->malloc_dispatch.malloc_usable_size,
172 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800173 if (__predict_false(_malloc_usable_size != nullptr)) {
174 return _malloc_usable_size(mem);
175 }
176 return Malloc(malloc_usable_size)(mem);
177}
178
179extern "C" void* memalign(size_t alignment, size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700180 auto _memalign = atomic_load_explicit_const(
181 &__libc_globals->malloc_dispatch.memalign,
182 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800183 if (__predict_false(_memalign != nullptr)) {
184 return _memalign(alignment, bytes);
185 }
186 return Malloc(memalign)(alignment, bytes);
187}
188
189extern "C" int posix_memalign(void** memptr, size_t alignment, size_t size) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700190 auto _posix_memalign = atomic_load_explicit_const(
191 &__libc_globals->malloc_dispatch.posix_memalign,
192 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800193 if (__predict_false(_posix_memalign != nullptr)) {
194 return _posix_memalign(memptr, alignment, size);
195 }
196 return Malloc(posix_memalign)(memptr, alignment, size);
197}
198
Christopher Ferriscae21a92018-02-05 18:14:55 -0800199extern "C" void* aligned_alloc(size_t alignment, size_t size) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700200 auto _aligned_alloc = atomic_load_explicit_const(
201 &__libc_globals->malloc_dispatch.aligned_alloc,
202 default_read_memory_order);
Christopher Ferriscae21a92018-02-05 18:14:55 -0800203 if (__predict_false(_aligned_alloc != nullptr)) {
204 return _aligned_alloc(alignment, size);
205 }
206 return Malloc(aligned_alloc)(alignment, size);
207}
208
Christopher Ferris63860cb2015-11-16 17:30:32 -0800209extern "C" void* realloc(void* old_mem, size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700210 auto _realloc = atomic_load_explicit_const(
211 &__libc_globals->malloc_dispatch.realloc,
212 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800213 if (__predict_false(_realloc != nullptr)) {
214 return _realloc(old_mem, bytes);
215 }
216 return Malloc(realloc)(old_mem, bytes);
217}
218
Elliott Hughesb1770852018-09-18 12:52:42 -0700219extern "C" void* reallocarray(void* old_mem, size_t item_count, size_t item_size) {
220 size_t new_size;
221 if (__builtin_mul_overflow(item_count, item_size, &new_size)) {
222 errno = ENOMEM;
223 return nullptr;
224 }
225 return realloc(old_mem, new_size);
226}
227
Christopher Ferris63860cb2015-11-16 17:30:32 -0800228#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
229extern "C" void* pvalloc(size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700230 auto _pvalloc = atomic_load_explicit_const(
231 &__libc_globals->malloc_dispatch.pvalloc,
232 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800233 if (__predict_false(_pvalloc != nullptr)) {
234 return _pvalloc(bytes);
235 }
236 return Malloc(pvalloc)(bytes);
237}
238
239extern "C" void* valloc(size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700240 auto _valloc = atomic_load_explicit_const(
241 &__libc_globals->malloc_dispatch.valloc,
242 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800243 if (__predict_false(_valloc != nullptr)) {
244 return _valloc(bytes);
245 }
246 return Malloc(valloc)(bytes);
247}
248#endif
249
250// We implement malloc debugging only in libc.so, so the code below
251// must be excluded if we compile this file for static libc.a
252#if !defined(LIBC_STATIC)
253
254#include <dlfcn.h>
Christopher Ferris63860cb2015-11-16 17:30:32 -0800255#include <stdio.h>
256#include <stdlib.h>
257
Christopher Ferris7a3681e2017-04-24 17:48:32 -0700258#include <async_safe/log.h>
Christopher Ferris63860cb2015-11-16 17:30:32 -0800259#include <sys/system_properties.h>
260
261extern "C" int __cxa_atexit(void (*func)(void *), void *arg, void *dso);
262
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800263static const char* HOOKS_SHARED_LIB = "libc_malloc_hooks.so";
264static const char* HOOKS_PROPERTY_ENABLE = "libc.debug.hooks.enable";
265static const char* HOOKS_ENV_ENABLE = "LIBC_HOOKS_ENABLE";
266
Christopher Ferris63860cb2015-11-16 17:30:32 -0800267static const char* DEBUG_SHARED_LIB = "libc_malloc_debug.so";
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800268static const char* DEBUG_PROPERTY_OPTIONS = "libc.debug.malloc.options";
269static const char* DEBUG_PROPERTY_PROGRAM = "libc.debug.malloc.program";
270static const char* DEBUG_ENV_OPTIONS = "LIBC_DEBUG_MALLOC_OPTIONS";
Christopher Ferris63860cb2015-11-16 17:30:32 -0800271
Florian Mayerf7f71e32018-08-31 15:36:48 -0700272static const char* HEAPPROFD_SHARED_LIB = "heapprofd_client.so";
273static const char* HEAPPROFD_PREFIX = "heapprofd";
Florian Mayer0dbe6d12018-11-08 11:25:49 +0000274static const char* HEAPPROFD_PROPERTY_ENABLE = "heapprofd.enable";
Florian Mayerf7f71e32018-08-31 15:36:48 -0700275static const int HEAPPROFD_SIGNAL = __SIGRTMIN + 4;
276
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800277enum FunctionEnum : uint8_t {
278 FUNC_INITIALIZE,
279 FUNC_FINALIZE,
280 FUNC_GET_MALLOC_LEAK_INFO,
281 FUNC_FREE_MALLOC_LEAK_INFO,
282 FUNC_MALLOC_BACKTRACE,
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700283 FUNC_WRITE_LEAK_INFO,
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800284 FUNC_LAST,
285};
286static void* g_functions[FUNC_LAST];
Christopher Ferris63860cb2015-11-16 17:30:32 -0800287
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800288typedef void (*finalize_func_t)();
289typedef bool (*init_func_t)(const MallocDispatch*, int*, const char*);
290typedef void (*get_malloc_leak_info_func_t)(uint8_t**, size_t*, size_t*, size_t*, size_t*);
291typedef void (*free_malloc_leak_info_func_t)(uint8_t*);
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700292typedef bool (*write_malloc_leak_info_func_t)(FILE*);
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800293typedef ssize_t (*malloc_backtrace_func_t)(void*, uintptr_t*, size_t);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800294
295// =============================================================================
296// Log functions
297// =============================================================================
298#define error_log(format, ...) \
Christopher Ferris7a3681e2017-04-24 17:48:32 -0700299 async_safe_format_log(ANDROID_LOG_ERROR, "libc", (format), ##__VA_ARGS__ )
Christopher Ferris63860cb2015-11-16 17:30:32 -0800300#define info_log(format, ...) \
Christopher Ferris7a3681e2017-04-24 17:48:32 -0700301 async_safe_format_log(ANDROID_LOG_INFO, "libc", (format), ##__VA_ARGS__ )
Christopher Ferris63860cb2015-11-16 17:30:32 -0800302// =============================================================================
303
304// =============================================================================
305// Exported for use by ddms.
306// =============================================================================
307
308// Retrieve native heap information.
309//
310// "*info" is set to a buffer we allocate
311// "*overall_size" is set to the size of the "info" buffer
312// "*info_size" is set to the size of a single entry
313// "*total_memory" is set to the sum of all allocations we're tracking; does
314// not include heap overhead
315// "*backtrace_size" is set to the maximum number of entries in the back trace
316extern "C" void get_malloc_leak_info(uint8_t** info, size_t* overall_size,
317 size_t* info_size, size_t* total_memory, size_t* backtrace_size) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800318 void* func = g_functions[FUNC_GET_MALLOC_LEAK_INFO];
319 if (func == nullptr) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800320 return;
321 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800322 reinterpret_cast<get_malloc_leak_info_func_t>(func)(info, overall_size, info_size, total_memory,
323 backtrace_size);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800324}
325
326extern "C" void free_malloc_leak_info(uint8_t* info) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800327 void* func = g_functions[FUNC_FREE_MALLOC_LEAK_INFO];
328 if (func == nullptr) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800329 return;
330 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800331 reinterpret_cast<free_malloc_leak_info_func_t>(func)(info);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800332}
Colin Cross869691c2016-01-29 12:48:18 -0800333
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700334extern "C" void write_malloc_leak_info(FILE* fp) {
335 if (fp == nullptr) {
336 error_log("write_malloc_leak_info called with a nullptr");
337 return;
338 }
339
340 void* func = g_functions[FUNC_WRITE_LEAK_INFO];
341 bool written = false;
342 if (func != nullptr) {
343 written = reinterpret_cast<write_malloc_leak_info_func_t>(func)(fp);
344 }
345
346 if (!written) {
347 fprintf(fp, "Native heap dump not available. To enable, run these commands (requires root):\n");
348 fprintf(fp, "# adb shell stop\n");
349 fprintf(fp, "# adb shell setprop libc.debug.malloc.options backtrace\n");
350 fprintf(fp, "# adb shell start\n");
351 }
352}
353
Christopher Ferris63860cb2015-11-16 17:30:32 -0800354// =============================================================================
355
356template<typename FunctionType>
Florian Mayerf7f71e32018-08-31 15:36:48 -0700357static bool InitMallocFunction(void* malloc_impl_handler, _Atomic(FunctionType)* func, const char* prefix, const char* suffix) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800358 char symbol[128];
359 snprintf(symbol, sizeof(symbol), "%s_%s", prefix, suffix);
360 *func = reinterpret_cast<FunctionType>(dlsym(malloc_impl_handler, symbol));
361 if (*func == nullptr) {
362 error_log("%s: dlsym(\"%s\") failed", getprogname(), symbol);
363 return false;
364 }
365 return true;
366}
367
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800368static bool InitMallocFunctions(void* impl_handler, MallocDispatch* table, const char* prefix) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700369 // We initialize free first to prevent the following situation:
370 // Heapprofd's MallocMalloc is installed, and an allocation is observed
371 // and logged to the heap dump. The corresponding free happens before
372 // heapprofd's MallocFree is installed, and is not logged in the heap
373 // dump. This leads to the allocation wrongly being active in the heap
374 // dump indefinitely.
375 if (!InitMallocFunction<MallocFree>(impl_handler, &table->free, prefix, "free")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800376 return false;
377 }
Florian Mayerf7f71e32018-08-31 15:36:48 -0700378 if (!InitMallocFunction<MallocCalloc>(impl_handler, &table->calloc, prefix, "calloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800379 return false;
380 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800381 if (!InitMallocFunction<MallocMallinfo>(impl_handler, &table->mallinfo, prefix, "mallinfo")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800382 return false;
383 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800384 if (!InitMallocFunction<MallocMallopt>(impl_handler, &table->mallopt, prefix, "mallopt")) {
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700385 return false;
386 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800387 if (!InitMallocFunction<MallocMalloc>(impl_handler, &table->malloc, prefix, "malloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800388 return false;
389 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800390 if (!InitMallocFunction<MallocMallocUsableSize>(impl_handler, &table->malloc_usable_size, prefix,
391 "malloc_usable_size")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800392 return false;
393 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800394 if (!InitMallocFunction<MallocMemalign>(impl_handler, &table->memalign, prefix, "memalign")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800395 return false;
396 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800397 if (!InitMallocFunction<MallocPosixMemalign>(impl_handler, &table->posix_memalign, prefix,
398 "posix_memalign")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800399 return false;
400 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800401 if (!InitMallocFunction<MallocAlignedAlloc>(impl_handler, &table->aligned_alloc,
Christopher Ferriscae21a92018-02-05 18:14:55 -0800402 prefix, "aligned_alloc")) {
403 return false;
404 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800405 if (!InitMallocFunction<MallocRealloc>(impl_handler, &table->realloc, prefix, "realloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800406 return false;
407 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800408 if (!InitMallocFunction<MallocIterate>(impl_handler, &table->iterate, prefix, "iterate")) {
Colin Cross869691c2016-01-29 12:48:18 -0800409 return false;
410 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800411 if (!InitMallocFunction<MallocMallocDisable>(impl_handler, &table->malloc_disable, prefix,
412 "malloc_disable")) {
Colin Cross869691c2016-01-29 12:48:18 -0800413 return false;
414 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800415 if (!InitMallocFunction<MallocMallocEnable>(impl_handler, &table->malloc_enable, prefix,
416 "malloc_enable")) {
Colin Cross869691c2016-01-29 12:48:18 -0800417 return false;
418 }
Christopher Ferris63860cb2015-11-16 17:30:32 -0800419#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800420 if (!InitMallocFunction<MallocPvalloc>(impl_handler, &table->pvalloc, prefix, "pvalloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800421 return false;
422 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800423 if (!InitMallocFunction<MallocValloc>(impl_handler, &table->valloc, prefix, "valloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800424 return false;
425 }
426#endif
427
428 return true;
429}
430
431static void malloc_fini_impl(void*) {
432 // Our BSD stdio implementation doesn't close the standard streams,
433 // it only flushes them. Other unclosed FILE*s will show up as
434 // malloc leaks, but to avoid the standard streams showing up in
435 // leak reports, close them here.
436 fclose(stdin);
437 fclose(stdout);
438 fclose(stderr);
439
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800440 reinterpret_cast<finalize_func_t>(g_functions[FUNC_FINALIZE])();
441}
442
443static bool CheckLoadMallocHooks(char** options) {
444 char* env = getenv(HOOKS_ENV_ENABLE);
445 if ((env == nullptr || env[0] == '\0' || env[0] == '0') &&
446 (__system_property_get(HOOKS_PROPERTY_ENABLE, *options) == 0 || *options[0] == '\0' || *options[0] == '0')) {
447 return false;
448 }
449 *options = nullptr;
450 return true;
451}
452
453static bool CheckLoadMallocDebug(char** options) {
454 // If DEBUG_MALLOC_ENV_OPTIONS is set then it overrides the system properties.
455 char* env = getenv(DEBUG_ENV_OPTIONS);
456 if (env == nullptr || env[0] == '\0') {
457 if (__system_property_get(DEBUG_PROPERTY_OPTIONS, *options) == 0 || *options[0] == '\0') {
458 return false;
459 }
460
461 // Check to see if only a specific program should have debug malloc enabled.
462 char program[PROP_VALUE_MAX];
463 if (__system_property_get(DEBUG_PROPERTY_PROGRAM, program) != 0 &&
464 strstr(getprogname(), program) == nullptr) {
465 return false;
466 }
467 } else {
468 *options = env;
469 }
470 return true;
471}
472
Florian Mayer0dbe6d12018-11-08 11:25:49 +0000473static bool CheckLoadHeapprofd() {
474 // First check for heapprofd.enable. If it is set to "all", enable
475 // heapprofd for all processes. Otherwise, check heapprofd.enable.${prog},
476 // if it is set and not 0, enable heap profiling for this process.
477 char property_value[PROP_VALUE_MAX];
478 if (__system_property_get(HEAPPROFD_PROPERTY_ENABLE, property_value) == 0) {
479 return false;
480 }
481 if (strcmp(property_value, "all") == 0) {
482 return true;
483 }
484
485 char program_property[128];
486 int ret = snprintf(program_property, sizeof(program_property), "%s.%s",
487 HEAPPROFD_PROPERTY_ENABLE, getprogname());
488
489 if (ret < 0 || static_cast<size_t>(ret) >= sizeof(program_property)) {
490 if (ret < 0) {
491 error_log("Failed to concatenate heapprofd property %s.%s: %s",
492 HEAPPROFD_PROPERTY_ENABLE, getprogname(), strerror(errno));
493 } else {
494 error_log("Overflow in concatenating heapprofd property");
495 }
496 return false;
497 }
498
499 if (__system_property_get(program_property, property_value) == 0) {
500 return false;
501 }
502
503 return program_property[0] != '\0';
504}
505
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800506static void ClearGlobalFunctions() {
507 for (size_t i = 0; i < FUNC_LAST; i++) {
508 g_functions[i] = nullptr;
509 }
510}
511
512static void* LoadSharedLibrary(const char* shared_lib, const char* prefix, MallocDispatch* dispatch_table) {
513 void* impl_handle = dlopen(shared_lib, RTLD_NOW | RTLD_LOCAL);
514 if (impl_handle == nullptr) {
515 error_log("%s: Unable to open shared library %s: %s", getprogname(), shared_lib, dlerror());
516 return nullptr;
517 }
518
519 static constexpr const char* names[] = {
520 "initialize",
521 "finalize",
522 "get_malloc_leak_info",
523 "free_malloc_leak_info",
524 "malloc_backtrace",
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700525 "write_malloc_leak_info",
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800526 };
527 for (size_t i = 0; i < FUNC_LAST; i++) {
528 char symbol[128];
529 snprintf(symbol, sizeof(symbol), "%s_%s", prefix, names[i]);
530 g_functions[i] = dlsym(impl_handle, symbol);
531 if (g_functions[i] == nullptr) {
532 error_log("%s: %s routine not found in %s", getprogname(), symbol, shared_lib);
533 dlclose(impl_handle);
534 ClearGlobalFunctions();
535 return nullptr;
536 }
537 }
538
539 if (!InitMallocFunctions(impl_handle, dispatch_table, prefix)) {
540 dlclose(impl_handle);
541 ClearGlobalFunctions();
542 return nullptr;
543 }
544
545 return impl_handle;
Christopher Ferris63860cb2015-11-16 17:30:32 -0800546}
547
Florian Mayer176a4752018-10-23 11:48:34 +0100548// A function pointer to heapprofds init function. Used to re-initialize
549// heapprofd. This will start a new profiling session and tear down the old
550// one in case it is still active.
551static _Atomic init_func_t g_heapprofd_init_func = nullptr;
552
Florian Mayerf7f71e32018-08-31 15:36:48 -0700553static void install_hooks(libc_globals* globals, const char* options,
554 const char* prefix, const char* shared_lib) {
Florian Mayer176a4752018-10-23 11:48:34 +0100555 init_func_t init_func = atomic_load(&g_heapprofd_init_func);
556 if (init_func != nullptr) {
557 init_func(&__libc_malloc_default_dispatch, &gMallocLeakZygoteChild, options);
558 info_log("%s: malloc %s re-enabled", getprogname(), prefix);
559 return;
560 }
561
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800562 MallocDispatch dispatch_table;
563 void* impl_handle = LoadSharedLibrary(shared_lib, prefix, &dispatch_table);
564 if (impl_handle == nullptr) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800565 return;
566 }
Florian Mayer176a4752018-10-23 11:48:34 +0100567 init_func = reinterpret_cast<init_func_t>(g_functions[FUNC_INITIALIZE]);
Tamas Berghammerac81fe82016-08-26 15:54:59 +0100568 if (!init_func(&__libc_malloc_default_dispatch, &gMallocLeakZygoteChild, options)) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800569 dlclose(impl_handle);
570 ClearGlobalFunctions();
Christopher Ferris63860cb2015-11-16 17:30:32 -0800571 return;
572 }
573
Florian Mayer176a4752018-10-23 11:48:34 +0100574 atomic_store(&g_heapprofd_init_func, init_func);
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800575 globals->malloc_dispatch = dispatch_table;
Christopher Ferris63860cb2015-11-16 17:30:32 -0800576
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800577 info_log("%s: malloc %s enabled", getprogname(), prefix);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800578
579 // Use atexit to trigger the cleanup function. This avoids a problem
580 // where another atexit function is used to cleanup allocated memory,
581 // but the finalize function was already called. This particular error
582 // seems to be triggered by a zygote spawned process calling exit.
583 int ret_value = __cxa_atexit(malloc_fini_impl, nullptr, nullptr);
584 if (ret_value != 0) {
585 error_log("failed to set atexit cleanup function: %d", ret_value);
586 }
587}
588
Florian Mayerf7f71e32018-08-31 15:36:48 -0700589extern "C" void InstallInitHeapprofdHook(int);
590
591// Initializes memory allocation framework once per process.
592static void malloc_init_impl(libc_globals* globals) {
593 struct sigaction action = {};
594 action.sa_handler = InstallInitHeapprofdHook;
595 sigaction(HEAPPROFD_SIGNAL, &action, nullptr);
596
597 const char* prefix;
598 const char* shared_lib;
599 char prop[PROP_VALUE_MAX];
600 char* options = prop;
601 // Prefer malloc debug since it existed first and is a more complete
602 // malloc interceptor than the hooks.
603 if (CheckLoadMallocDebug(&options)) {
604 prefix = "debug";
605 shared_lib = DEBUG_SHARED_LIB;
606 } else if (CheckLoadMallocHooks(&options)) {
607 prefix = "hooks";
608 shared_lib = HOOKS_SHARED_LIB;
Florian Mayer0dbe6d12018-11-08 11:25:49 +0000609 } else if (CheckLoadHeapprofd()) {
610 prefix = "heapprofd";
611 shared_lib = HEAPPROFD_SHARED_LIB;
Florian Mayerf7f71e32018-08-31 15:36:48 -0700612 } else {
613 return;
614 }
615 install_hooks(globals, options, prefix, shared_lib);
616}
617
Christopher Ferris63860cb2015-11-16 17:30:32 -0800618// Initializes memory allocation framework.
619// This routine is called from __libc_init routines in libc_init_dynamic.cpp.
620__LIBC_HIDDEN__ void __libc_init_malloc(libc_globals* globals) {
621 malloc_init_impl(globals);
622}
Florian Mayerf7f71e32018-08-31 15:36:48 -0700623
624// The logic for triggering heapprofd below is as following.
625// 1. HEAPPROFD_SIGNAL is received by the process.
Florian Mayer176a4752018-10-23 11:48:34 +0100626// 2. If neither InitHeapprofd nor InitHeapprofdHook are currently installed
627// (g_heapprofd_init_hook_installed is false), InitHeapprofdHook is
628// installed and g_heapprofd_init_in_progress is set to true.
629//
630// On the next subsequent malloc, InitHeapprofdHook is called and
631// 3a. If the signal is currently being handled (g_heapprofd_init_in_progress
Florian Mayerf7f71e32018-08-31 15:36:48 -0700632// is true), no action is taken.
Florian Mayer176a4752018-10-23 11:48:34 +0100633// 3b. Otherwise, The signal handler (InstallInitHeapprofdHook) installs a
Florian Mayerf7f71e32018-08-31 15:36:48 -0700634// temporary malloc hook (InitHeapprofdHook).
Florian Mayer176a4752018-10-23 11:48:34 +0100635// 4. When this hook gets run the first time, it uninstalls itself and spawns
Florian Mayerf7f71e32018-08-31 15:36:48 -0700636// a thread running InitHeapprofd that loads heapprofd.so and installs the
637// hooks within.
Florian Mayer176a4752018-10-23 11:48:34 +0100638// 5. g_heapprofd_init_in_progress and g_heapprofd_init_hook_installed are
639// reset to false so heapprofd can be reinitialized. Reinitialization
640// means that a new profiling session is started and any still active is
641// torn down.
Florian Mayerf7f71e32018-08-31 15:36:48 -0700642//
643// This roundabout way is needed because we are running non AS-safe code, so
644// we cannot run it directly in the signal handler. The other approach of
645// running a standby thread and signalling through write(2) and read(2) would
646// significantly increase the number of active threads in the system.
647
648static _Atomic bool g_heapprofd_init_in_progress = false;
Florian Mayer176a4752018-10-23 11:48:34 +0100649static _Atomic bool g_heapprofd_init_hook_installed = false;
Florian Mayerf7f71e32018-08-31 15:36:48 -0700650
651static void* InitHeapprofd(void*) {
652 __libc_globals.mutate([](libc_globals* globals) {
653 install_hooks(globals, nullptr, HEAPPROFD_PREFIX, HEAPPROFD_SHARED_LIB);
654 });
655 atomic_store(&g_heapprofd_init_in_progress, false);
Florian Mayer176a4752018-10-23 11:48:34 +0100656 // Allow to install hook again to re-initialize heap profiling after the
657 // current session finished.
658 atomic_store(&g_heapprofd_init_hook_installed, false);
Florian Mayerf7f71e32018-08-31 15:36:48 -0700659 return nullptr;
660}
661
662static void* InitHeapprofdHook(size_t bytes) {
Florian Mayer176a4752018-10-23 11:48:34 +0100663 if (!atomic_exchange(&g_heapprofd_init_hook_installed, true)) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700664 __libc_globals.mutate([](libc_globals* globals) {
665 atomic_store(&globals->malloc_dispatch.malloc, nullptr);
666 });
667
668 pthread_t thread_id;
669 if (pthread_create(&thread_id, nullptr, InitHeapprofd, nullptr) == -1)
670 error_log("%s: heapprofd: failed to pthread_create.", getprogname());
671 else if (pthread_detach(thread_id) == -1)
672 error_log("%s: heapprofd: failed to pthread_detach", getprogname());
673 if (pthread_setname_np(thread_id, "heapprofdinit") == -1)
674 error_log("%s: heapprod: failed to pthread_setname_np", getprogname());
675 }
676 return Malloc(malloc)(bytes);
677}
678
679extern "C" void InstallInitHeapprofdHook(int) {
680 if (!atomic_exchange(&g_heapprofd_init_in_progress, true)) {
681 __libc_globals.mutate([](libc_globals* globals) {
682 globals->malloc_dispatch.malloc = InitHeapprofdHook;
683 });
684 }
685}
686
Christopher Ferris63860cb2015-11-16 17:30:32 -0800687#endif // !LIBC_STATIC
Colin Cross869691c2016-01-29 12:48:18 -0800688
689// =============================================================================
690// Exported for use by libmemunreachable.
691// =============================================================================
692
693// Calls callback for every allocation in the anonymous heap mapping
694// [base, base+size). Must be called between malloc_disable and malloc_enable.
695extern "C" int malloc_iterate(uintptr_t base, size_t size,
696 void (*callback)(uintptr_t base, size_t size, void* arg), void* arg) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700697 auto _iterate = atomic_load_explicit_const(
698 &__libc_globals->malloc_dispatch.iterate,
699 default_read_memory_order);
Colin Cross869691c2016-01-29 12:48:18 -0800700 if (__predict_false(_iterate != nullptr)) {
701 return _iterate(base, size, callback, arg);
702 }
703 return Malloc(iterate)(base, size, callback, arg);
704}
705
706// Disable calls to malloc so malloc_iterate gets a consistent view of
707// allocated memory.
708extern "C" void malloc_disable() {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700709 auto _malloc_disable = atomic_load_explicit_const(
710 & __libc_globals->malloc_dispatch.malloc_disable,
711 default_read_memory_order);
Colin Cross869691c2016-01-29 12:48:18 -0800712 if (__predict_false(_malloc_disable != nullptr)) {
713 return _malloc_disable();
714 }
715 return Malloc(malloc_disable)();
716}
717
718// Re-enable calls to malloc after a previous call to malloc_disable.
719extern "C" void malloc_enable() {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700720 auto _malloc_enable = atomic_load_explicit_const(
721 &__libc_globals->malloc_dispatch.malloc_enable,
722 default_read_memory_order);
Colin Cross869691c2016-01-29 12:48:18 -0800723 if (__predict_false(_malloc_enable != nullptr)) {
724 return _malloc_enable();
725 }
726 return Malloc(malloc_enable)();
727}
Colin Cross2d4721c2016-02-02 11:57:54 -0800728
729#ifndef LIBC_STATIC
730extern "C" ssize_t malloc_backtrace(void* pointer, uintptr_t* frames, size_t frame_count) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800731 void* func = g_functions[FUNC_MALLOC_BACKTRACE];
732 if (func == nullptr) {
Colin Cross2d4721c2016-02-02 11:57:54 -0800733 return 0;
734 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800735 return reinterpret_cast<malloc_backtrace_func_t>(func)(pointer, frames, frame_count);
Colin Cross2d4721c2016-02-02 11:57:54 -0800736}
737#else
738extern "C" ssize_t malloc_backtrace(void*, uintptr_t*, size_t) {
739 return 0;
740}
741#endif