Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 1 | /* |
| 2 | * Copyright (C) 2008 The Android Open Source Project |
| 3 | * All rights reserved. |
| 4 | * |
| 5 | * Redistribution and use in source and binary forms, with or without |
| 6 | * modification, are permitted provided that the following conditions |
| 7 | * are met: |
| 8 | * * Redistributions of source code must retain the above copyright |
| 9 | * notice, this list of conditions and the following disclaimer. |
| 10 | * * Redistributions in binary form must reproduce the above copyright |
| 11 | * notice, this list of conditions and the following disclaimer in |
| 12 | * the documentation and/or other materials provided with the |
| 13 | * distribution. |
| 14 | * |
| 15 | * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
| 16 | * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
| 17 | * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS |
| 18 | * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE |
| 19 | * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, |
| 20 | * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, |
| 21 | * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS |
| 22 | * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED |
| 23 | * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, |
| 24 | * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT |
| 25 | * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
| 26 | * SUCH DAMAGE. |
| 27 | */ |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 28 | |
Yabin Cui | ca48274 | 2016-01-25 17:38:44 -0800 | [diff] [blame] | 29 | #include <android/api-level.h> |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 30 | #include <elf.h> |
| 31 | #include <errno.h> |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 32 | #include <malloc.h> |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 33 | #include <stddef.h> |
| 34 | #include <stdint.h> |
| 35 | #include <stdio.h> |
| 36 | #include <stdlib.h> |
| 37 | #include <sys/auxv.h> |
| 38 | #include <sys/mman.h> |
| 39 | |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 40 | #include "async_safe/log.h" |
| 41 | #include "heap_tagging.h" |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 42 | #include "libc_init_common.h" |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 43 | #include "platform/bionic/macros.h" |
| 44 | #include "platform/bionic/mte.h" |
Elliott Hughes | cdb52fc | 2019-12-12 15:26:14 -0800 | [diff] [blame] | 45 | #include "platform/bionic/page.h" |
Elliott Hughes | 3771937 | 2021-09-29 16:52:20 -0700 | [diff] [blame] | 46 | #include "platform/bionic/reserved_signals.h" |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 47 | #include "private/KernelArgumentBlock.h" |
| 48 | #include "private/bionic_asm.h" |
| 49 | #include "private/bionic_asm_note.h" |
Peter Collingbourne | e949195 | 2019-10-28 10:57:26 -0700 | [diff] [blame] | 50 | #include "private/bionic_call_ifunc_resolver.h" |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 51 | #include "private/bionic_elf_tls.h" |
Josh Gao | b6453c5 | 2016-06-29 16:47:53 -0700 | [diff] [blame] | 52 | #include "private/bionic_globals.h" |
Elliott Hughes | eb847bc | 2013-10-09 15:50:50 -0700 | [diff] [blame] | 53 | #include "private/bionic_tls.h" |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 54 | #include "pthread_internal.h" |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 55 | #include "sys/system_properties.h" |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 56 | #include "sysprop_helpers.h" |
Elliott Hughes | eb847bc | 2013-10-09 15:50:50 -0700 | [diff] [blame] | 57 | |
Evgenii Stepanov | be551f5 | 2018-08-13 16:46:15 -0700 | [diff] [blame] | 58 | #if __has_feature(hwaddress_sanitizer) |
| 59 | #include <sanitizer/hwasan_interface.h> |
| 60 | #endif |
| 61 | |
Ryan Prichard | 27475b5 | 2018-05-17 17:14:18 -0700 | [diff] [blame] | 62 | // Leave the variable uninitialized for the sake of the dynamic loader, which |
| 63 | // links in this file. The loader will initialize this variable before |
| 64 | // relocating itself. |
| 65 | #if defined(__i386__) |
| 66 | __LIBC_HIDDEN__ void* __libc_sysinfo; |
| 67 | #endif |
| 68 | |
Dmitriy Ivanov | 53c3c27 | 2014-07-11 12:59:16 -0700 | [diff] [blame] | 69 | extern "C" int __cxa_atexit(void (*)(void *), void *, void *); |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 70 | extern "C" const char* __gnu_basename(const char* path); |
Dmitriy Ivanov | 53c3c27 | 2014-07-11 12:59:16 -0700 | [diff] [blame] | 71 | |
Yabin Cui | 744cfd3 | 2023-08-24 13:20:23 -0700 | [diff] [blame] | 72 | static void call_array(init_func_t** list, size_t count, int argc, char* argv[], char* envp[]) { |
| 73 | while (count-- > 0) { |
| 74 | init_func_t* function = *list++; |
| 75 | (*function)(argc, argv, envp); |
| 76 | } |
| 77 | } |
| 78 | |
| 79 | static void call_fini_array(void* arg) { |
| 80 | structors_array_t* structors = reinterpret_cast<structors_array_t*>(arg); |
| 81 | fini_func_t** array = structors->fini_array; |
| 82 | size_t count = structors->fini_array_count; |
| 83 | // Now call each destructor in reverse order. |
| 84 | while (count-- > 0) { |
| 85 | fini_func_t* function = array[count]; |
| 86 | (*function)(); |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 87 | } |
| 88 | } |
| 89 | |
Elliott Hughes | 6cfd1b5 | 2022-10-05 00:15:49 +0000 | [diff] [blame] | 90 | #if defined(__arm__) || defined(__i386__) // Legacy architectures used REL... |
Dan Albert | a535d3c | 2019-02-14 16:19:59 -0800 | [diff] [blame] | 91 | extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rel) __rel_iplt_start[], __rel_iplt_end[]; |
Peter Collingbourne | 7a0f04c | 2019-01-23 17:56:24 -0800 | [diff] [blame] | 92 | |
| 93 | static void call_ifunc_resolvers() { |
Dan Albert | a535d3c | 2019-02-14 16:19:59 -0800 | [diff] [blame] | 94 | if (__rel_iplt_start == nullptr || __rel_iplt_end == nullptr) { |
Elliott Hughes | 6cfd1b5 | 2022-10-05 00:15:49 +0000 | [diff] [blame] | 95 | // These symbols were not emitted by gold. Gold has code to do so, but for |
Dan Albert | a535d3c | 2019-02-14 16:19:59 -0800 | [diff] [blame] | 96 | // whatever reason it is not being run. In these cases ifuncs cannot be |
| 97 | // resolved, so we do not support using ifuncs in static executables linked |
| 98 | // with gold. |
| 99 | // |
| 100 | // Since they are weak, they will be non-null when linked with bfd/lld and |
| 101 | // null when linked with gold. |
| 102 | return; |
| 103 | } |
| 104 | |
Elliott Hughes | 6cfd1b5 | 2022-10-05 00:15:49 +0000 | [diff] [blame] | 105 | for (ElfW(Rel)* r = __rel_iplt_start; r != __rel_iplt_end; ++r) { |
Peter Collingbourne | 7a0f04c | 2019-01-23 17:56:24 -0800 | [diff] [blame] | 106 | ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset); |
| 107 | ElfW(Addr) resolver = *offset; |
Peter Collingbourne | e949195 | 2019-10-28 10:57:26 -0700 | [diff] [blame] | 108 | *offset = __bionic_call_ifunc_resolver(resolver); |
Peter Collingbourne | 7a0f04c | 2019-01-23 17:56:24 -0800 | [diff] [blame] | 109 | } |
| 110 | } |
Elliott Hughes | 6cfd1b5 | 2022-10-05 00:15:49 +0000 | [diff] [blame] | 111 | #else // ...but modern architectures use RELA instead. |
| 112 | extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rela) __rela_iplt_start[], __rela_iplt_end[]; |
| 113 | |
| 114 | static void call_ifunc_resolvers() { |
| 115 | if (__rela_iplt_start == nullptr || __rela_iplt_end == nullptr) { |
| 116 | // These symbols were not emitted by gold. Gold has code to do so, but for |
| 117 | // whatever reason it is not being run. In these cases ifuncs cannot be |
| 118 | // resolved, so we do not support using ifuncs in static executables linked |
| 119 | // with gold. |
| 120 | // |
| 121 | // Since they are weak, they will be non-null when linked with bfd/lld and |
| 122 | // null when linked with gold. |
| 123 | return; |
| 124 | } |
| 125 | |
| 126 | for (ElfW(Rela)* r = __rela_iplt_start; r != __rela_iplt_end; ++r) { |
| 127 | ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset); |
| 128 | ElfW(Addr) resolver = r->r_addend; |
| 129 | *offset = __bionic_call_ifunc_resolver(resolver); |
| 130 | } |
| 131 | } |
Peter Collingbourne | 7a0f04c | 2019-01-23 17:56:24 -0800 | [diff] [blame] | 132 | #endif |
| 133 | |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 134 | static void apply_gnu_relro() { |
Elliott Hughes | 0266ae5 | 2014-02-10 17:46:57 -0800 | [diff] [blame] | 135 | ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)); |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 136 | unsigned long int phdr_ct = getauxval(AT_PHNUM); |
| 137 | |
Elliott Hughes | 0266ae5 | 2014-02-10 17:46:57 -0800 | [diff] [blame] | 138 | for (ElfW(Phdr)* phdr = phdr_start; phdr < (phdr_start + phdr_ct); phdr++) { |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 139 | if (phdr->p_type != PT_GNU_RELRO) { |
| 140 | continue; |
| 141 | } |
| 142 | |
Peter Collingbourne | bb11ee6 | 2022-05-02 12:26:16 -0700 | [diff] [blame] | 143 | ElfW(Addr) seg_page_start = page_start(phdr->p_vaddr); |
| 144 | ElfW(Addr) seg_page_end = page_end(phdr->p_vaddr + phdr->p_memsz); |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 145 | |
| 146 | // Check return value here? What do we do if we fail? |
| 147 | mprotect(reinterpret_cast<void*>(seg_page_start), seg_page_end - seg_page_start, PROT_READ); |
| 148 | } |
| 149 | } |
| 150 | |
Ryan Prichard | e5e69e0 | 2019-01-01 18:53:48 -0800 | [diff] [blame] | 151 | static void layout_static_tls(KernelArgumentBlock& args) { |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 152 | StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout; |
| 153 | layout.reserve_bionic_tls(); |
Ryan Prichard | e5e69e0 | 2019-01-01 18:53:48 -0800 | [diff] [blame] | 154 | |
| 155 | const char* progname = args.argv[0]; |
| 156 | ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)); |
| 157 | size_t phdr_ct = getauxval(AT_PHNUM); |
| 158 | |
Ryan Prichard | 1988350 | 2019-01-16 23:13:38 -0800 | [diff] [blame] | 159 | static TlsModule mod; |
Ryan Prichard | 16455b5 | 2019-01-18 01:00:59 -0800 | [diff] [blame] | 160 | TlsModules& modules = __libc_shared_globals()->tls_modules; |
Ryan Prichard | 1988350 | 2019-01-16 23:13:38 -0800 | [diff] [blame] | 161 | if (__bionic_get_tls_segment(phdr_start, phdr_ct, 0, &mod.segment)) { |
| 162 | if (!__bionic_check_tls_alignment(&mod.segment.alignment)) { |
| 163 | async_safe_fatal("error: TLS segment alignment in \"%s\" is not a power of 2: %zu\n", |
| 164 | progname, mod.segment.alignment); |
| 165 | } |
| 166 | mod.static_offset = layout.reserve_exe_segment_and_tcb(&mod.segment, progname); |
Ryan Prichard | 16455b5 | 2019-01-18 01:00:59 -0800 | [diff] [blame] | 167 | mod.first_generation = kTlsGenerationFirst; |
| 168 | |
| 169 | modules.module_count = 1; |
Vy Nguyen | d500751 | 2020-07-14 17:37:04 -0400 | [diff] [blame] | 170 | modules.static_module_count = 1; |
Ryan Prichard | 16455b5 | 2019-01-18 01:00:59 -0800 | [diff] [blame] | 171 | modules.module_table = &mod; |
Ryan Prichard | e5e69e0 | 2019-01-01 18:53:48 -0800 | [diff] [blame] | 172 | } else { |
| 173 | layout.reserve_exe_segment_and_tcb(nullptr, progname); |
| 174 | } |
Ryan Prichard | 16455b5 | 2019-01-18 01:00:59 -0800 | [diff] [blame] | 175 | // Enable the fast path in __tls_get_addr. |
| 176 | __libc_tls_generation_copy = modules.generation; |
Ryan Prichard | e5e69e0 | 2019-01-01 18:53:48 -0800 | [diff] [blame] | 177 | |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 178 | layout.finish_layout(); |
| 179 | } |
| 180 | |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 181 | #ifdef __aarch64__ |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 182 | static bool __get_elf_note(const ElfW(Phdr) * phdr_start, size_t phdr_ct, |
| 183 | const ElfW(Addr) load_bias, unsigned desired_type, |
| 184 | const char* desired_name, const ElfW(Nhdr) * *note_out, |
| 185 | const char** desc_out) { |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 186 | for (size_t i = 0; i < phdr_ct; ++i) { |
| 187 | const ElfW(Phdr)* phdr = &phdr_start[i]; |
| 188 | if (phdr->p_type != PT_NOTE) { |
| 189 | continue; |
| 190 | } |
| 191 | ElfW(Addr) p = load_bias + phdr->p_vaddr; |
| 192 | ElfW(Addr) note_end = load_bias + phdr->p_vaddr + phdr->p_memsz; |
| 193 | while (p + sizeof(ElfW(Nhdr)) <= note_end) { |
| 194 | const ElfW(Nhdr)* note = reinterpret_cast<const ElfW(Nhdr)*>(p); |
| 195 | p += sizeof(ElfW(Nhdr)); |
| 196 | const char* name = reinterpret_cast<const char*>(p); |
| 197 | p += align_up(note->n_namesz, 4); |
| 198 | const char* desc = reinterpret_cast<const char*>(p); |
| 199 | p += align_up(note->n_descsz, 4); |
| 200 | if (p > note_end) { |
| 201 | break; |
| 202 | } |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 203 | if (note->n_type != desired_type) { |
| 204 | continue; |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 205 | } |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 206 | size_t desired_name_len = strlen(desired_name); |
| 207 | if (note->n_namesz != desired_name_len + 1 || |
| 208 | strncmp(desired_name, name, desired_name_len) != 0) { |
| 209 | break; |
| 210 | } |
| 211 | *note_out = note; |
| 212 | *desc_out = desc; |
| 213 | return true; |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 214 | } |
| 215 | } |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 216 | return false; |
| 217 | } |
| 218 | |
| 219 | static HeapTaggingLevel __get_memtag_level_from_note(const ElfW(Phdr) * phdr_start, size_t phdr_ct, |
| 220 | const ElfW(Addr) load_bias, bool* stack) { |
| 221 | const ElfW(Nhdr) * note; |
| 222 | const char* desc; |
| 223 | if (!__get_elf_note(phdr_start, phdr_ct, load_bias, NT_ANDROID_TYPE_MEMTAG, "Android", ¬e, |
| 224 | &desc)) { |
| 225 | return M_HEAP_TAGGING_LEVEL_TBI; |
| 226 | } |
| 227 | |
| 228 | // Previously (in Android 12), if the note was != 4 bytes, we check-failed |
| 229 | // here. Let's be more permissive to allow future expansion. |
| 230 | if (note->n_descsz < 4) { |
| 231 | async_safe_fatal("unrecognized android.memtag note: n_descsz = %d, expected >= 4", |
| 232 | note->n_descsz); |
| 233 | } |
| 234 | |
| 235 | // `desc` is always aligned due to ELF requirements, enforced in __get_elf_note(). |
| 236 | ElfW(Word) note_val = *reinterpret_cast<const ElfW(Word)*>(desc); |
| 237 | *stack = (note_val & NT_MEMTAG_STACK) != 0; |
| 238 | |
| 239 | // Warning: In Android 12, any value outside of bits [0..3] resulted in a check-fail. |
| 240 | if (!(note_val & (NT_MEMTAG_HEAP | NT_MEMTAG_STACK))) { |
| 241 | async_safe_format_log(ANDROID_LOG_INFO, "libc", |
| 242 | "unrecognised memtag note_val did not specificy heap or stack: %u", |
| 243 | note_val); |
| 244 | return M_HEAP_TAGGING_LEVEL_TBI; |
| 245 | } |
| 246 | |
| 247 | unsigned mode = note_val & NT_MEMTAG_LEVEL_MASK; |
| 248 | switch (mode) { |
| 249 | case NT_MEMTAG_LEVEL_NONE: |
| 250 | // Note, previously (in Android 12), NT_MEMTAG_LEVEL_NONE was |
| 251 | // NT_MEMTAG_LEVEL_DEFAULT, which implied SYNC mode. This was never used |
| 252 | // by anyone, but we note it (heh) here for posterity, in case the zero |
| 253 | // level becomes meaningful, and binaries with this note can be executed |
| 254 | // on Android 12 devices. |
| 255 | return M_HEAP_TAGGING_LEVEL_TBI; |
| 256 | case NT_MEMTAG_LEVEL_ASYNC: |
| 257 | return M_HEAP_TAGGING_LEVEL_ASYNC; |
| 258 | case NT_MEMTAG_LEVEL_SYNC: |
| 259 | default: |
| 260 | // We allow future extensions to specify mode 3 (currently unused), with |
| 261 | // the idea that it might be used for ASYMM mode or something else. On |
| 262 | // this version of Android, it falls back to SYNC mode. |
| 263 | return M_HEAP_TAGGING_LEVEL_SYNC; |
| 264 | } |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 265 | } |
| 266 | |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 267 | // Returns true if there's an environment setting (either sysprop or env var) |
| 268 | // that should overwrite the ELF note, and places the equivalent heap tagging |
| 269 | // level into *level. |
Florian Mayer | dd44378 | 2023-05-17 20:59:14 +0000 | [diff] [blame] | 270 | static bool get_environment_memtag_setting(HeapTaggingLevel* level) { |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 271 | static const char kMemtagPrognameSyspropPrefix[] = "arm64.memtag.process."; |
Florian Mayer | dde3176 | 2022-01-24 18:29:50 -0800 | [diff] [blame] | 272 | static const char kMemtagGlobalSysprop[] = "persist.arm64.memtag.default"; |
Florian Mayer | dee80d5 | 2022-08-01 15:16:01 -0700 | [diff] [blame] | 273 | static const char kMemtagOverrideSyspropPrefix[] = |
| 274 | "persist.device_config.memory_safety_native.mode_override.process."; |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 275 | |
Florian Mayer | dd44378 | 2023-05-17 20:59:14 +0000 | [diff] [blame] | 276 | const char* progname = __libc_shared_globals()->init_progname; |
| 277 | if (progname == nullptr) return false; |
| 278 | |
| 279 | const char* basename = __gnu_basename(progname); |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 280 | |
Florian Mayer | 2791429 | 2022-08-01 15:02:25 -0700 | [diff] [blame] | 281 | char options_str[PROP_VALUE_MAX]; |
| 282 | char sysprop_name[512]; |
| 283 | async_safe_format_buffer(sysprop_name, sizeof(sysprop_name), "%s%s", kMemtagPrognameSyspropPrefix, |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 284 | basename); |
Florian Mayer | dee80d5 | 2022-08-01 15:16:01 -0700 | [diff] [blame] | 285 | char remote_sysprop_name[512]; |
| 286 | async_safe_format_buffer(remote_sysprop_name, sizeof(remote_sysprop_name), "%s%s", |
| 287 | kMemtagOverrideSyspropPrefix, basename); |
| 288 | const char* sys_prop_names[] = {sysprop_name, remote_sysprop_name, kMemtagGlobalSysprop}; |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 289 | |
Florian Mayer | dde3176 | 2022-01-24 18:29:50 -0800 | [diff] [blame] | 290 | if (!get_config_from_env_or_sysprops("MEMTAG_OPTIONS", sys_prop_names, arraysize(sys_prop_names), |
Florian Mayer | dd44378 | 2023-05-17 20:59:14 +0000 | [diff] [blame] | 291 | options_str, sizeof(options_str))) { |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 292 | return false; |
| 293 | } |
| 294 | |
| 295 | if (strcmp("sync", options_str) == 0) { |
| 296 | *level = M_HEAP_TAGGING_LEVEL_SYNC; |
| 297 | } else if (strcmp("async", options_str) == 0) { |
| 298 | *level = M_HEAP_TAGGING_LEVEL_ASYNC; |
| 299 | } else if (strcmp("off", options_str) == 0) { |
| 300 | *level = M_HEAP_TAGGING_LEVEL_TBI; |
| 301 | } else { |
Florian Mayer | dd44378 | 2023-05-17 20:59:14 +0000 | [diff] [blame] | 302 | async_safe_format_log( |
| 303 | ANDROID_LOG_ERROR, "libc", |
| 304 | "unrecognized memtag level: \"%s\" (options are \"sync\", \"async\", or \"off\").", |
| 305 | options_str); |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 306 | return false; |
| 307 | } |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 308 | |
Florian Mayer | dd44378 | 2023-05-17 20:59:14 +0000 | [diff] [blame] | 309 | return true; |
Florian Mayer | b3f3e86 | 2023-03-17 11:27:47 -0700 | [diff] [blame] | 310 | } |
| 311 | |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 312 | // Returns the initial heap tagging level. Note: This function will never return |
| 313 | // M_HEAP_TAGGING_LEVEL_NONE, if MTE isn't enabled for this process we enable |
| 314 | // M_HEAP_TAGGING_LEVEL_TBI. |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 315 | static HeapTaggingLevel __get_tagging_level(const memtag_dynamic_entries_t* memtag_dynamic_entries, |
| 316 | const void* phdr_start, size_t phdr_ct, |
| 317 | uintptr_t load_bias, bool* stack) { |
| 318 | HeapTaggingLevel level = M_HEAP_TAGGING_LEVEL_TBI; |
Evgenii Stepanov | f9fa32a | 2022-05-12 15:54:38 -0700 | [diff] [blame] | 319 | |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 320 | // If the dynamic entries exist, use those. Otherwise, fall back to the old |
| 321 | // Android note, which is still used for fully static executables. When |
| 322 | // -fsanitize=memtag* is used in newer toolchains, currently both the dynamic |
| 323 | // entries and the old note are created, but we'd expect to move to just the |
| 324 | // dynamic entries for dynamically linked executables in the future. In |
| 325 | // addition, there's still some cleanup of the build system (that uses a |
| 326 | // manually-constructed note) needed. For more information about the dynamic |
| 327 | // entries, see: |
| 328 | // https://github.com/ARM-software/abi-aa/blob/main/memtagabielf64/memtagabielf64.rst#dynamic-section |
| 329 | if (memtag_dynamic_entries && memtag_dynamic_entries->has_memtag_mode) { |
| 330 | switch (memtag_dynamic_entries->memtag_mode) { |
| 331 | case 0: |
| 332 | level = M_HEAP_TAGGING_LEVEL_SYNC; |
| 333 | break; |
| 334 | case 1: |
| 335 | level = M_HEAP_TAGGING_LEVEL_ASYNC; |
| 336 | break; |
| 337 | default: |
| 338 | async_safe_format_log(ANDROID_LOG_INFO, "libc", |
| 339 | "unrecognised DT_AARCH64_MEMTAG_MODE value: %u", |
| 340 | memtag_dynamic_entries->memtag_mode); |
| 341 | } |
| 342 | *stack = memtag_dynamic_entries->memtag_stack; |
| 343 | } else { |
| 344 | level = __get_memtag_level_from_note(reinterpret_cast<const ElfW(Phdr)*>(phdr_start), phdr_ct, |
| 345 | load_bias, stack); |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 346 | } |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 347 | |
| 348 | // We can't short-circuit the environment override, as `stack` is still inherited from the |
| 349 | // binary's settings. |
| 350 | if (get_environment_memtag_setting(&level)) { |
| 351 | if (level == M_HEAP_TAGGING_LEVEL_NONE || level == M_HEAP_TAGGING_LEVEL_TBI) { |
| 352 | *stack = false; |
| 353 | } |
| 354 | } |
| 355 | return level; |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 356 | } |
| 357 | |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 358 | // Figure out the desired memory tagging mode (sync/async, heap/globals/stack) for this executable. |
| 359 | // This function is called from the linker before the main executable is relocated. |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 360 | __attribute__((no_sanitize("hwaddress", "memtag"))) void __libc_init_mte( |
| 361 | const memtag_dynamic_entries_t* memtag_dynamic_entries, const void* phdr_start, size_t phdr_ct, |
| 362 | uintptr_t load_bias, void* stack_top) { |
| 363 | bool memtag_stack = false; |
| 364 | HeapTaggingLevel level = |
| 365 | __get_tagging_level(memtag_dynamic_entries, phdr_start, phdr_ct, load_bias, &memtag_stack); |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 366 | char* env = getenv("BIONIC_MEMTAG_UPGRADE_SECS"); |
Florian Mayer | 14cbb79 | 2022-08-10 14:57:14 -0700 | [diff] [blame] | 367 | static const char kAppProcessName[] = "app_process64"; |
| 368 | const char* progname = __libc_shared_globals()->init_progname; |
| 369 | progname = progname ? __gnu_basename(progname) : nullptr; |
| 370 | if (progname && |
| 371 | strncmp(progname, kAppProcessName, sizeof(kAppProcessName)) == 0) { |
| 372 | // disable timed upgrade for zygote, as the thread spawned will violate the requirement |
| 373 | // that it be single-threaded. |
| 374 | env = nullptr; |
| 375 | } |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 376 | int64_t timed_upgrade = 0; |
| 377 | if (env) { |
| 378 | char* endptr; |
| 379 | timed_upgrade = strtoll(env, &endptr, 10); |
| 380 | if (*endptr != '\0' || timed_upgrade < 0) { |
| 381 | async_safe_format_log(ANDROID_LOG_ERROR, "libc", |
| 382 | "Invalid value for BIONIC_MEMTAG_UPGRADE_SECS: %s", |
| 383 | env); |
| 384 | timed_upgrade = 0; |
| 385 | } |
| 386 | // Make sure that this does not get passed to potential processes inheriting |
| 387 | // this environment. |
| 388 | unsetenv("BIONIC_MEMTAG_UPGRADE_SECS"); |
| 389 | } |
| 390 | if (timed_upgrade) { |
| 391 | if (level == M_HEAP_TAGGING_LEVEL_ASYNC) { |
| 392 | async_safe_format_log(ANDROID_LOG_INFO, "libc", |
| 393 | "Attempting timed MTE upgrade from async to sync."); |
| 394 | __libc_shared_globals()->heap_tagging_upgrade_timer_sec = timed_upgrade; |
| 395 | level = M_HEAP_TAGGING_LEVEL_SYNC; |
| 396 | } else if (level != M_HEAP_TAGGING_LEVEL_SYNC) { |
| 397 | async_safe_format_log( |
| 398 | ANDROID_LOG_ERROR, "libc", |
| 399 | "Requested timed MTE upgrade from invalid %s to sync. Ignoring.", |
| 400 | DescribeTaggingLevel(level)); |
| 401 | } |
| 402 | } |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 403 | if (level == M_HEAP_TAGGING_LEVEL_SYNC || level == M_HEAP_TAGGING_LEVEL_ASYNC) { |
| 404 | unsigned long prctl_arg = PR_TAGGED_ADDR_ENABLE | PR_MTE_TAG_SET_NONZERO; |
| 405 | prctl_arg |= (level == M_HEAP_TAGGING_LEVEL_SYNC) ? PR_MTE_TCF_SYNC : PR_MTE_TCF_ASYNC; |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 406 | |
Peter Collingbourne | 48bf46b | 2021-07-01 15:16:40 -0700 | [diff] [blame] | 407 | // When entering ASYNC mode, specify that we want to allow upgrading to SYNC by OR'ing in the |
| 408 | // SYNC flag. But if the kernel doesn't support specifying multiple TCF modes, fall back to |
| 409 | // specifying a single mode. |
| 410 | if (prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg | PR_MTE_TCF_SYNC, 0, 0, 0) == 0 || |
| 411 | prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg, 0, 0, 0) == 0) { |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 412 | __libc_shared_globals()->initial_heap_tagging_level = level; |
Evgenii Stepanov | f9fa32a | 2022-05-12 15:54:38 -0700 | [diff] [blame] | 413 | __libc_shared_globals()->initial_memtag_stack = memtag_stack; |
| 414 | |
| 415 | if (memtag_stack) { |
Peter Collingbourne | bb11ee6 | 2022-05-02 12:26:16 -0700 | [diff] [blame] | 416 | void* pg_start = |
| 417 | reinterpret_cast<void*>(page_start(reinterpret_cast<uintptr_t>(stack_top))); |
Kalesh Singh | 183f58b | 2023-08-21 11:40:03 -0700 | [diff] [blame] | 418 | if (mprotect(pg_start, page_size(), PROT_READ | PROT_WRITE | PROT_MTE | PROT_GROWSDOWN)) { |
Elliott Hughes | 2557f73 | 2023-07-12 21:15:23 +0000 | [diff] [blame] | 419 | async_safe_fatal("error: failed to set PROT_MTE on main thread stack: %m"); |
Evgenii Stepanov | f9fa32a | 2022-05-12 15:54:38 -0700 | [diff] [blame] | 420 | } |
| 421 | } |
| 422 | |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 423 | return; |
| 424 | } |
| 425 | } |
| 426 | |
Mitch Phillips | 4cded97 | 2021-01-07 17:32:00 -0800 | [diff] [blame] | 427 | // MTE was either not enabled, or wasn't supported on this device. Try and use |
| 428 | // TBI. |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 429 | if (prctl(PR_SET_TAGGED_ADDR_CTRL, PR_TAGGED_ADDR_ENABLE, 0, 0, 0) == 0) { |
| 430 | __libc_shared_globals()->initial_heap_tagging_level = M_HEAP_TAGGING_LEVEL_TBI; |
| 431 | } |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 432 | // We did not enable MTE, so we do not need to arm the upgrade timer. |
| 433 | __libc_shared_globals()->heap_tagging_upgrade_timer_sec = 0; |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 434 | } |
| 435 | #else // __aarch64__ |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 436 | void __libc_init_mte(const memtag_dynamic_entries_t*, const void*, size_t, uintptr_t, void*) {} |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 437 | #endif // __aarch64__ |
| 438 | |
Elliott Hughes | 3771937 | 2021-09-29 16:52:20 -0700 | [diff] [blame] | 439 | void __libc_init_profiling_handlers() { |
| 440 | // The dynamic variant of this function is more interesting, but this |
| 441 | // at least ensures that static binaries aren't killed by the kernel's |
| 442 | // default disposition for these two real-time signals that would have |
| 443 | // handlers installed if this was a dynamic binary. |
| 444 | signal(BIONIC_SIGNAL_PROFILER, SIG_IGN); |
| 445 | signal(BIONIC_SIGNAL_ART_PROFILER, SIG_IGN); |
| 446 | } |
| 447 | |
Evgenii Stepanov | f9fa32a | 2022-05-12 15:54:38 -0700 | [diff] [blame] | 448 | __attribute__((no_sanitize("memtag"))) __noreturn static void __real_libc_init( |
| 449 | void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**), |
| 450 | structors_array_t const* const structors, bionic_tcb* temp_tcb) { |
Christopher Ferris | 93ea09f | 2017-10-05 15:18:47 -0700 | [diff] [blame] | 451 | BIONIC_STOP_UNWIND; |
| 452 | |
Ryan Prichard | 9cfca86 | 2018-11-22 02:44:09 -0800 | [diff] [blame] | 453 | // Initialize TLS early so system calls and errno work. |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 454 | KernelArgumentBlock args(raw_args); |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 455 | __libc_init_main_thread_early(args, temp_tcb); |
Ryan Prichard | 07440a8 | 2018-11-22 03:16:06 -0800 | [diff] [blame] | 456 | __libc_init_main_thread_late(); |
| 457 | __libc_init_globals(); |
Ryan Prichard | 9cfca86 | 2018-11-22 02:44:09 -0800 | [diff] [blame] | 458 | __libc_shared_globals()->init_progname = args.argv[0]; |
Ryan Prichard | 48b1159 | 2018-11-22 02:41:36 -0800 | [diff] [blame] | 459 | __libc_init_AT_SECURE(args.envp); |
Ryan Prichard | e5e69e0 | 2019-01-01 18:53:48 -0800 | [diff] [blame] | 460 | layout_static_tls(args); |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 461 | __libc_init_main_thread_final(); |
Ryan Prichard | 48b1159 | 2018-11-22 02:41:36 -0800 | [diff] [blame] | 462 | __libc_init_common(); |
Mitch Phillips | 7c1f377 | 2023-09-28 13:45:59 +0200 | [diff] [blame] | 463 | __libc_init_mte(/*memtag_dynamic_entries=*/nullptr, |
| 464 | reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)), getauxval(AT_PHNUM), |
Evgenii Stepanov | f9fa32a | 2022-05-12 15:54:38 -0700 | [diff] [blame] | 465 | /*load_bias = */ 0, /*stack_top = */ raw_args); |
Evgenii Stepanov | 8564b8d | 2020-12-15 13:55:32 -0800 | [diff] [blame] | 466 | __libc_init_scudo(); |
Elliott Hughes | 3771937 | 2021-09-29 16:52:20 -0700 | [diff] [blame] | 467 | __libc_init_profiling_handlers(); |
Mitch Phillips | 1d2aadc | 2019-11-14 16:02:09 -0800 | [diff] [blame] | 468 | __libc_init_fork_handler(); |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 469 | |
Peter Collingbourne | 7a0f04c | 2019-01-23 17:56:24 -0800 | [diff] [blame] | 470 | call_ifunc_resolvers(); |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 471 | apply_gnu_relro(); |
| 472 | |
| 473 | // Several Linux ABIs don't pass the onexit pointer, and the ones that |
| 474 | // do never use it. Therefore, we ignore it. |
| 475 | |
Yabin Cui | 744cfd3 | 2023-08-24 13:20:23 -0700 | [diff] [blame] | 476 | call_array(structors->preinit_array, structors->preinit_array_count, args.argc, args.argv, |
| 477 | args.envp); |
| 478 | call_array(structors->init_array, structors->init_array_count, args.argc, args.argv, args.envp); |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 479 | |
| 480 | // The executable may have its own destructors listed in its .fini_array |
| 481 | // so we need to ensure that these are called when the program exits |
| 482 | // normally. |
Yabin Cui | 744cfd3 | 2023-08-24 13:20:23 -0700 | [diff] [blame] | 483 | if (structors->fini_array_count > 0) { |
| 484 | __cxa_atexit(call_fini_array, const_cast<structors_array_t*>(structors), nullptr); |
Dmitriy Ivanov | 4b41555 | 2014-09-04 21:54:34 +0000 | [diff] [blame] | 485 | } |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 486 | |
Florian Mayer | 408e170 | 2022-05-12 13:06:04 -0700 | [diff] [blame] | 487 | __libc_init_mte_late(); |
| 488 | |
Elliott Hughes | 42b2c6a | 2013-02-07 10:14:39 -0800 | [diff] [blame] | 489 | exit(slingshot(args.argc, args.argv, args.envp)); |
| 490 | } |
Yabin Cui | ca48274 | 2016-01-25 17:38:44 -0800 | [diff] [blame] | 491 | |
Peter Collingbourne | d75e308 | 2019-01-31 16:27:54 -0800 | [diff] [blame] | 492 | extern "C" void __hwasan_init_static(); |
Evgenii Stepanov | 13e8dcb | 2018-09-19 16:29:12 -0700 | [diff] [blame] | 493 | |
Elliott Hughes | f9930b7 | 2020-02-10 10:30:38 -0800 | [diff] [blame] | 494 | // This __libc_init() is only used for static executables, and is called from crtbegin.c. |
| 495 | // |
| 496 | // The 'structors' parameter contains pointers to various initializer |
| 497 | // arrays that must be run before the program's 'main' routine is launched. |
Evgenii Stepanov | f9fa32a | 2022-05-12 15:54:38 -0700 | [diff] [blame] | 498 | __attribute__((no_sanitize("hwaddress", "memtag"))) __noreturn void __libc_init( |
| 499 | void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**), |
| 500 | structors_array_t const* const structors) { |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 501 | bionic_tcb temp_tcb = {}; |
Evgenii Stepanov | be551f5 | 2018-08-13 16:46:15 -0700 | [diff] [blame] | 502 | #if __has_feature(hwaddress_sanitizer) |
Evgenii Stepanov | 13e8dcb | 2018-09-19 16:29:12 -0700 | [diff] [blame] | 503 | // Install main thread TLS early. It will be initialized later in __libc_init_main_thread. For now |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 504 | // all we need is access to TLS_SLOT_SANITIZER. |
| 505 | __set_tls(&temp_tcb.tls_slot(0)); |
Peter Collingbourne | d75e308 | 2019-01-31 16:27:54 -0800 | [diff] [blame] | 506 | // Initialize HWASan enough to run instrumented code. This sets up TLS_SLOT_SANITIZER, among other |
| 507 | // things. |
| 508 | __hwasan_init_static(); |
Evgenii Stepanov | 13e8dcb | 2018-09-19 16:29:12 -0700 | [diff] [blame] | 509 | // We are ready to run HWASan-instrumented code, proceed with libc initialization... |
Evgenii Stepanov | be551f5 | 2018-08-13 16:46:15 -0700 | [diff] [blame] | 510 | #endif |
Ryan Prichard | 45d1349 | 2019-01-03 02:51:30 -0800 | [diff] [blame] | 511 | __real_libc_init(raw_args, onexit, slingshot, structors, &temp_tcb); |
Evgenii Stepanov | be551f5 | 2018-08-13 16:46:15 -0700 | [diff] [blame] | 512 | } |
| 513 | |
Elliott Hughes | ff1428a | 2018-11-12 16:01:37 -0800 | [diff] [blame] | 514 | static int g_target_sdk_version{__ANDROID_API__}; |
Elliott Hughes | 46a943c | 2018-04-03 15:56:35 -0700 | [diff] [blame] | 515 | |
Elliott Hughes | ff1428a | 2018-11-12 16:01:37 -0800 | [diff] [blame] | 516 | extern "C" int android_get_application_target_sdk_version() { |
Elliott Hughes | 46a943c | 2018-04-03 15:56:35 -0700 | [diff] [blame] | 517 | return g_target_sdk_version; |
| 518 | } |
| 519 | |
Elliott Hughes | ff1428a | 2018-11-12 16:01:37 -0800 | [diff] [blame] | 520 | extern "C" void android_set_application_target_sdk_version(int target) { |
Elliott Hughes | 46a943c | 2018-04-03 15:56:35 -0700 | [diff] [blame] | 521 | g_target_sdk_version = target; |
Peter Collingbourne | 2659d7b | 2021-03-05 13:31:41 -0800 | [diff] [blame] | 522 | __libc_set_target_sdk_version(target); |
Yabin Cui | ca48274 | 2016-01-25 17:38:44 -0800 | [diff] [blame] | 523 | } |
Ryan Prichard | abf736a | 2018-11-22 02:40:17 -0800 | [diff] [blame] | 524 | |
Ryan Prichard | 249757b | 2019-11-01 17:18:28 -0700 | [diff] [blame] | 525 | // This function is called in the dynamic linker before ifunc resolvers have run, so this file is |
| 526 | // compiled with -ffreestanding to avoid implicit string.h function calls. (It shouldn't strictly |
| 527 | // be necessary, though.) |
Ryan Prichard | abf736a | 2018-11-22 02:40:17 -0800 | [diff] [blame] | 528 | __LIBC_HIDDEN__ libc_shared_globals* __libc_shared_globals() { |
Ryan Prichard | 0b0ee0c | 2018-12-14 17:34:05 -0800 | [diff] [blame] | 529 | static libc_shared_globals globals; |
Ryan Prichard | abf736a | 2018-11-22 02:40:17 -0800 | [diff] [blame] | 530 | return &globals; |
| 531 | } |