blob: 9a807678412356c550c63a33ab4ed7dac368ccc5 [file] [log] [blame]
Christopher Ferris63860cb2015-11-16 17:30:32 -08001/*
2 * Copyright (C) 2009 The Android Open Source Project
3 * All rights reserved.
4 *
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
7 * are met:
8 * * Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * * Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in
12 * the documentation and/or other materials provided with the
13 * distribution.
14 *
15 * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16 * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17 * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18 * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19 * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21 * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22 * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23 * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24 * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25 * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 */
28
29// Contains a thin layer that calls whatever real native allocator
30// has been defined. For the libc shared library, this allows the
31// implementation of a debug malloc that can intercept all of the allocation
32// calls and add special debugging code to attempt to catch allocation
33// errors. All of the debugging code is implemented in a separate shared
34// library that is only loaded when the property "libc.debug.malloc.options"
35// is set to a non-zero value. There are two functions exported to
36// allow ddms, or other external users to get information from the debug
37// allocation.
38// get_malloc_leak_info: Returns information about all of the known native
39// allocations that are currently in use.
40// free_malloc_leak_info: Frees the data allocated by the call to
41// get_malloc_leak_info.
Christopher Ferris2e1a40a2018-06-13 10:46:34 -070042// write_malloc_leak_info: Writes the leak info data to a file.
Christopher Ferris63860cb2015-11-16 17:30:32 -080043
Colin Cross869691c2016-01-29 12:48:18 -080044#include <pthread.h>
Florian Mayerf7f71e32018-08-31 15:36:48 -070045#include <stdatomic.h>
Colin Cross869691c2016-01-29 12:48:18 -080046
Christopher Ferris63860cb2015-11-16 17:30:32 -080047#include <private/bionic_config.h>
48#include <private/bionic_globals.h>
49#include <private/bionic_malloc_dispatch.h>
50
Evgenii Stepanovbe551f52018-08-13 16:46:15 -070051#if __has_feature(hwaddress_sanitizer)
52// FIXME: implement these in HWASan allocator.
53extern "C" int __sanitizer_iterate(uintptr_t base __unused, size_t size __unused,
54 void (*callback)(uintptr_t base, size_t size, void* arg) __unused,
55 void* arg __unused) {
56 return 0;
57}
58
59extern "C" void __sanitizer_malloc_disable() {
60}
61
62extern "C" void __sanitizer_malloc_enable() {
63}
64#include <sanitizer/hwasan_interface.h>
65#define Malloc(function) __sanitizer_ ## function
66
67#else // __has_feature(hwaddress_sanitizer)
Christopher Ferris63860cb2015-11-16 17:30:32 -080068#include "jemalloc.h"
69#define Malloc(function) je_ ## function
Evgenii Stepanovbe551f52018-08-13 16:46:15 -070070#endif
Christopher Ferris63860cb2015-11-16 17:30:32 -080071
Florian Mayerf7f71e32018-08-31 15:36:48 -070072template <typename T>
73static T* RemoveConst(const T* x) {
74 return const_cast<T*>(x);
75}
76
77// RemoveConst is a workaround for bug in current libcxx. Fix in
78// https://reviews.llvm.org/D47613
79#define atomic_load_explicit_const(obj, order) atomic_load_explicit(RemoveConst(obj), order)
80
81static constexpr memory_order default_read_memory_order = memory_order_acquire;
82
Christopher Ferris63860cb2015-11-16 17:30:32 -080083static constexpr MallocDispatch __libc_malloc_default_dispatch
84 __attribute__((unused)) = {
85 Malloc(calloc),
86 Malloc(free),
87 Malloc(mallinfo),
88 Malloc(malloc),
89 Malloc(malloc_usable_size),
90 Malloc(memalign),
91 Malloc(posix_memalign),
92#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
93 Malloc(pvalloc),
94#endif
95 Malloc(realloc),
96#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
97 Malloc(valloc),
98#endif
Colin Cross869691c2016-01-29 12:48:18 -080099 Malloc(iterate),
100 Malloc(malloc_disable),
101 Malloc(malloc_enable),
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700102 Malloc(mallopt),
Christopher Ferriscae21a92018-02-05 18:14:55 -0800103 Malloc(aligned_alloc),
Christopher Ferris63860cb2015-11-16 17:30:32 -0800104 };
105
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800106// Malloc hooks.
107void* (*volatile __malloc_hook)(size_t, const void*);
108void* (*volatile __realloc_hook)(void*, size_t, const void*);
109void (*volatile __free_hook)(void*, const void*);
110void* (*volatile __memalign_hook)(size_t, size_t, const void*);
111
Christopher Ferris63860cb2015-11-16 17:30:32 -0800112// In a VM process, this is set to 1 after fork()ing out of zygote.
113int gMallocLeakZygoteChild = 0;
114
115// =============================================================================
116// Allocation functions
117// =============================================================================
118extern "C" void* calloc(size_t n_elements, size_t elem_size) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700119 auto _calloc = atomic_load_explicit_const(
120 &__libc_globals->malloc_dispatch.calloc,
121 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800122 if (__predict_false(_calloc != nullptr)) {
123 return _calloc(n_elements, elem_size);
124 }
125 return Malloc(calloc)(n_elements, elem_size);
126}
127
128extern "C" void free(void* mem) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700129 auto _free = atomic_load_explicit_const(
130 &__libc_globals->malloc_dispatch.free,
131 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800132 if (__predict_false(_free != nullptr)) {
133 _free(mem);
134 } else {
135 Malloc(free)(mem);
136 }
137}
138
139extern "C" struct mallinfo mallinfo() {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700140 auto _mallinfo = atomic_load_explicit_const(
141 &__libc_globals->malloc_dispatch.mallinfo,
142 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800143 if (__predict_false(_mallinfo != nullptr)) {
144 return _mallinfo();
145 }
146 return Malloc(mallinfo)();
147}
148
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700149extern "C" int mallopt(int param, int value) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700150 auto _mallopt = atomic_load_explicit_const(
151 &__libc_globals->malloc_dispatch.mallopt,
152 default_read_memory_order);
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700153 if (__predict_false(_mallopt != nullptr)) {
154 return _mallopt(param, value);
155 }
156 return Malloc(mallopt)(param, value);
157}
158
Christopher Ferris63860cb2015-11-16 17:30:32 -0800159extern "C" void* malloc(size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700160 auto _malloc = atomic_load_explicit_const(
161 &__libc_globals->malloc_dispatch.malloc,
162 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800163 if (__predict_false(_malloc != nullptr)) {
164 return _malloc(bytes);
165 }
166 return Malloc(malloc)(bytes);
167}
168
169extern "C" size_t malloc_usable_size(const void* mem) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700170 auto _malloc_usable_size = atomic_load_explicit_const(
171 &__libc_globals->malloc_dispatch.malloc_usable_size,
172 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800173 if (__predict_false(_malloc_usable_size != nullptr)) {
174 return _malloc_usable_size(mem);
175 }
176 return Malloc(malloc_usable_size)(mem);
177}
178
179extern "C" void* memalign(size_t alignment, size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700180 auto _memalign = atomic_load_explicit_const(
181 &__libc_globals->malloc_dispatch.memalign,
182 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800183 if (__predict_false(_memalign != nullptr)) {
184 return _memalign(alignment, bytes);
185 }
186 return Malloc(memalign)(alignment, bytes);
187}
188
189extern "C" int posix_memalign(void** memptr, size_t alignment, size_t size) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700190 auto _posix_memalign = atomic_load_explicit_const(
191 &__libc_globals->malloc_dispatch.posix_memalign,
192 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800193 if (__predict_false(_posix_memalign != nullptr)) {
194 return _posix_memalign(memptr, alignment, size);
195 }
196 return Malloc(posix_memalign)(memptr, alignment, size);
197}
198
Christopher Ferriscae21a92018-02-05 18:14:55 -0800199extern "C" void* aligned_alloc(size_t alignment, size_t size) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700200 auto _aligned_alloc = atomic_load_explicit_const(
201 &__libc_globals->malloc_dispatch.aligned_alloc,
202 default_read_memory_order);
Christopher Ferriscae21a92018-02-05 18:14:55 -0800203 if (__predict_false(_aligned_alloc != nullptr)) {
204 return _aligned_alloc(alignment, size);
205 }
206 return Malloc(aligned_alloc)(alignment, size);
207}
208
Christopher Ferris63860cb2015-11-16 17:30:32 -0800209extern "C" void* realloc(void* old_mem, size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700210 auto _realloc = atomic_load_explicit_const(
211 &__libc_globals->malloc_dispatch.realloc,
212 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800213 if (__predict_false(_realloc != nullptr)) {
214 return _realloc(old_mem, bytes);
215 }
216 return Malloc(realloc)(old_mem, bytes);
217}
218
Elliott Hughesb1770852018-09-18 12:52:42 -0700219extern "C" void* reallocarray(void* old_mem, size_t item_count, size_t item_size) {
220 size_t new_size;
221 if (__builtin_mul_overflow(item_count, item_size, &new_size)) {
222 errno = ENOMEM;
223 return nullptr;
224 }
225 return realloc(old_mem, new_size);
226}
227
Christopher Ferris63860cb2015-11-16 17:30:32 -0800228#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
229extern "C" void* pvalloc(size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700230 auto _pvalloc = atomic_load_explicit_const(
231 &__libc_globals->malloc_dispatch.pvalloc,
232 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800233 if (__predict_false(_pvalloc != nullptr)) {
234 return _pvalloc(bytes);
235 }
236 return Malloc(pvalloc)(bytes);
237}
238
239extern "C" void* valloc(size_t bytes) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700240 auto _valloc = atomic_load_explicit_const(
241 &__libc_globals->malloc_dispatch.valloc,
242 default_read_memory_order);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800243 if (__predict_false(_valloc != nullptr)) {
244 return _valloc(bytes);
245 }
246 return Malloc(valloc)(bytes);
247}
248#endif
249
250// We implement malloc debugging only in libc.so, so the code below
251// must be excluded if we compile this file for static libc.a
252#if !defined(LIBC_STATIC)
253
254#include <dlfcn.h>
Christopher Ferris63860cb2015-11-16 17:30:32 -0800255#include <stdio.h>
256#include <stdlib.h>
257
Christopher Ferris7a3681e2017-04-24 17:48:32 -0700258#include <async_safe/log.h>
Christopher Ferris63860cb2015-11-16 17:30:32 -0800259#include <sys/system_properties.h>
260
261extern "C" int __cxa_atexit(void (*func)(void *), void *arg, void *dso);
262
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800263static const char* HOOKS_SHARED_LIB = "libc_malloc_hooks.so";
264static const char* HOOKS_PROPERTY_ENABLE = "libc.debug.hooks.enable";
265static const char* HOOKS_ENV_ENABLE = "LIBC_HOOKS_ENABLE";
266
Christopher Ferris63860cb2015-11-16 17:30:32 -0800267static const char* DEBUG_SHARED_LIB = "libc_malloc_debug.so";
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800268static const char* DEBUG_PROPERTY_OPTIONS = "libc.debug.malloc.options";
269static const char* DEBUG_PROPERTY_PROGRAM = "libc.debug.malloc.program";
270static const char* DEBUG_ENV_OPTIONS = "LIBC_DEBUG_MALLOC_OPTIONS";
Christopher Ferris63860cb2015-11-16 17:30:32 -0800271
Florian Mayerf7f71e32018-08-31 15:36:48 -0700272static const char* HEAPPROFD_SHARED_LIB = "heapprofd_client.so";
273static const char* HEAPPROFD_PREFIX = "heapprofd";
Florian Mayer0dbe6d12018-11-08 11:25:49 +0000274static const char* HEAPPROFD_PROPERTY_ENABLE = "heapprofd.enable";
Florian Mayerf7f71e32018-08-31 15:36:48 -0700275static const int HEAPPROFD_SIGNAL = __SIGRTMIN + 4;
276
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800277enum FunctionEnum : uint8_t {
278 FUNC_INITIALIZE,
279 FUNC_FINALIZE,
280 FUNC_GET_MALLOC_LEAK_INFO,
281 FUNC_FREE_MALLOC_LEAK_INFO,
282 FUNC_MALLOC_BACKTRACE,
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700283 FUNC_WRITE_LEAK_INFO,
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800284 FUNC_LAST,
285};
286static void* g_functions[FUNC_LAST];
Christopher Ferris63860cb2015-11-16 17:30:32 -0800287
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800288typedef void (*finalize_func_t)();
289typedef bool (*init_func_t)(const MallocDispatch*, int*, const char*);
290typedef void (*get_malloc_leak_info_func_t)(uint8_t**, size_t*, size_t*, size_t*, size_t*);
291typedef void (*free_malloc_leak_info_func_t)(uint8_t*);
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700292typedef bool (*write_malloc_leak_info_func_t)(FILE*);
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800293typedef ssize_t (*malloc_backtrace_func_t)(void*, uintptr_t*, size_t);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800294
295// =============================================================================
296// Log functions
297// =============================================================================
298#define error_log(format, ...) \
Christopher Ferris7a3681e2017-04-24 17:48:32 -0700299 async_safe_format_log(ANDROID_LOG_ERROR, "libc", (format), ##__VA_ARGS__ )
Christopher Ferris63860cb2015-11-16 17:30:32 -0800300#define info_log(format, ...) \
Christopher Ferris7a3681e2017-04-24 17:48:32 -0700301 async_safe_format_log(ANDROID_LOG_INFO, "libc", (format), ##__VA_ARGS__ )
Christopher Ferris63860cb2015-11-16 17:30:32 -0800302// =============================================================================
303
304// =============================================================================
305// Exported for use by ddms.
306// =============================================================================
307
308// Retrieve native heap information.
309//
310// "*info" is set to a buffer we allocate
311// "*overall_size" is set to the size of the "info" buffer
312// "*info_size" is set to the size of a single entry
313// "*total_memory" is set to the sum of all allocations we're tracking; does
314// not include heap overhead
315// "*backtrace_size" is set to the maximum number of entries in the back trace
316extern "C" void get_malloc_leak_info(uint8_t** info, size_t* overall_size,
317 size_t* info_size, size_t* total_memory, size_t* backtrace_size) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800318 void* func = g_functions[FUNC_GET_MALLOC_LEAK_INFO];
319 if (func == nullptr) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800320 return;
321 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800322 reinterpret_cast<get_malloc_leak_info_func_t>(func)(info, overall_size, info_size, total_memory,
323 backtrace_size);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800324}
325
326extern "C" void free_malloc_leak_info(uint8_t* info) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800327 void* func = g_functions[FUNC_FREE_MALLOC_LEAK_INFO];
328 if (func == nullptr) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800329 return;
330 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800331 reinterpret_cast<free_malloc_leak_info_func_t>(func)(info);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800332}
Colin Cross869691c2016-01-29 12:48:18 -0800333
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700334extern "C" void write_malloc_leak_info(FILE* fp) {
335 if (fp == nullptr) {
336 error_log("write_malloc_leak_info called with a nullptr");
337 return;
338 }
339
340 void* func = g_functions[FUNC_WRITE_LEAK_INFO];
341 bool written = false;
342 if (func != nullptr) {
343 written = reinterpret_cast<write_malloc_leak_info_func_t>(func)(fp);
344 }
345
346 if (!written) {
347 fprintf(fp, "Native heap dump not available. To enable, run these commands (requires root):\n");
348 fprintf(fp, "# adb shell stop\n");
349 fprintf(fp, "# adb shell setprop libc.debug.malloc.options backtrace\n");
350 fprintf(fp, "# adb shell start\n");
351 }
352}
353
Christopher Ferris63860cb2015-11-16 17:30:32 -0800354// =============================================================================
355
356template<typename FunctionType>
Florian Mayerf7f71e32018-08-31 15:36:48 -0700357static bool InitMallocFunction(void* malloc_impl_handler, _Atomic(FunctionType)* func, const char* prefix, const char* suffix) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800358 char symbol[128];
359 snprintf(symbol, sizeof(symbol), "%s_%s", prefix, suffix);
360 *func = reinterpret_cast<FunctionType>(dlsym(malloc_impl_handler, symbol));
361 if (*func == nullptr) {
362 error_log("%s: dlsym(\"%s\") failed", getprogname(), symbol);
363 return false;
364 }
365 return true;
366}
367
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800368static bool InitMallocFunctions(void* impl_handler, MallocDispatch* table, const char* prefix) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700369 if (!InitMallocFunction<MallocFree>(impl_handler, &table->free, prefix, "free")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800370 return false;
371 }
Florian Mayerf7f71e32018-08-31 15:36:48 -0700372 if (!InitMallocFunction<MallocCalloc>(impl_handler, &table->calloc, prefix, "calloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800373 return false;
374 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800375 if (!InitMallocFunction<MallocMallinfo>(impl_handler, &table->mallinfo, prefix, "mallinfo")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800376 return false;
377 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800378 if (!InitMallocFunction<MallocMallopt>(impl_handler, &table->mallopt, prefix, "mallopt")) {
Christopher Ferrisa1c0d2f2017-05-15 15:50:19 -0700379 return false;
380 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800381 if (!InitMallocFunction<MallocMalloc>(impl_handler, &table->malloc, prefix, "malloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800382 return false;
383 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800384 if (!InitMallocFunction<MallocMallocUsableSize>(impl_handler, &table->malloc_usable_size, prefix,
385 "malloc_usable_size")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800386 return false;
387 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800388 if (!InitMallocFunction<MallocMemalign>(impl_handler, &table->memalign, prefix, "memalign")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800389 return false;
390 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800391 if (!InitMallocFunction<MallocPosixMemalign>(impl_handler, &table->posix_memalign, prefix,
392 "posix_memalign")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800393 return false;
394 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800395 if (!InitMallocFunction<MallocAlignedAlloc>(impl_handler, &table->aligned_alloc,
Christopher Ferriscae21a92018-02-05 18:14:55 -0800396 prefix, "aligned_alloc")) {
397 return false;
398 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800399 if (!InitMallocFunction<MallocRealloc>(impl_handler, &table->realloc, prefix, "realloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800400 return false;
401 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800402 if (!InitMallocFunction<MallocIterate>(impl_handler, &table->iterate, prefix, "iterate")) {
Colin Cross869691c2016-01-29 12:48:18 -0800403 return false;
404 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800405 if (!InitMallocFunction<MallocMallocDisable>(impl_handler, &table->malloc_disable, prefix,
406 "malloc_disable")) {
Colin Cross869691c2016-01-29 12:48:18 -0800407 return false;
408 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800409 if (!InitMallocFunction<MallocMallocEnable>(impl_handler, &table->malloc_enable, prefix,
410 "malloc_enable")) {
Colin Cross869691c2016-01-29 12:48:18 -0800411 return false;
412 }
Christopher Ferris63860cb2015-11-16 17:30:32 -0800413#if defined(HAVE_DEPRECATED_MALLOC_FUNCS)
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800414 if (!InitMallocFunction<MallocPvalloc>(impl_handler, &table->pvalloc, prefix, "pvalloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800415 return false;
416 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800417 if (!InitMallocFunction<MallocValloc>(impl_handler, &table->valloc, prefix, "valloc")) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800418 return false;
419 }
420#endif
421
422 return true;
423}
424
425static void malloc_fini_impl(void*) {
426 // Our BSD stdio implementation doesn't close the standard streams,
427 // it only flushes them. Other unclosed FILE*s will show up as
428 // malloc leaks, but to avoid the standard streams showing up in
429 // leak reports, close them here.
430 fclose(stdin);
431 fclose(stdout);
432 fclose(stderr);
433
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800434 reinterpret_cast<finalize_func_t>(g_functions[FUNC_FINALIZE])();
435}
436
437static bool CheckLoadMallocHooks(char** options) {
438 char* env = getenv(HOOKS_ENV_ENABLE);
439 if ((env == nullptr || env[0] == '\0' || env[0] == '0') &&
440 (__system_property_get(HOOKS_PROPERTY_ENABLE, *options) == 0 || *options[0] == '\0' || *options[0] == '0')) {
441 return false;
442 }
443 *options = nullptr;
444 return true;
445}
446
447static bool CheckLoadMallocDebug(char** options) {
448 // If DEBUG_MALLOC_ENV_OPTIONS is set then it overrides the system properties.
449 char* env = getenv(DEBUG_ENV_OPTIONS);
450 if (env == nullptr || env[0] == '\0') {
451 if (__system_property_get(DEBUG_PROPERTY_OPTIONS, *options) == 0 || *options[0] == '\0') {
452 return false;
453 }
454
455 // Check to see if only a specific program should have debug malloc enabled.
456 char program[PROP_VALUE_MAX];
457 if (__system_property_get(DEBUG_PROPERTY_PROGRAM, program) != 0 &&
458 strstr(getprogname(), program) == nullptr) {
459 return false;
460 }
461 } else {
462 *options = env;
463 }
464 return true;
465}
466
Florian Mayer0dbe6d12018-11-08 11:25:49 +0000467static bool CheckLoadHeapprofd() {
468 // First check for heapprofd.enable. If it is set to "all", enable
469 // heapprofd for all processes. Otherwise, check heapprofd.enable.${prog},
470 // if it is set and not 0, enable heap profiling for this process.
471 char property_value[PROP_VALUE_MAX];
472 if (__system_property_get(HEAPPROFD_PROPERTY_ENABLE, property_value) == 0) {
473 return false;
474 }
475 if (strcmp(property_value, "all") == 0) {
476 return true;
477 }
478
479 char program_property[128];
480 int ret = snprintf(program_property, sizeof(program_property), "%s.%s",
481 HEAPPROFD_PROPERTY_ENABLE, getprogname());
482
483 if (ret < 0 || static_cast<size_t>(ret) >= sizeof(program_property)) {
484 if (ret < 0) {
485 error_log("Failed to concatenate heapprofd property %s.%s: %s",
486 HEAPPROFD_PROPERTY_ENABLE, getprogname(), strerror(errno));
487 } else {
488 error_log("Overflow in concatenating heapprofd property");
489 }
490 return false;
491 }
492
493 if (__system_property_get(program_property, property_value) == 0) {
494 return false;
495 }
496
497 return program_property[0] != '\0';
498}
499
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800500static void ClearGlobalFunctions() {
501 for (size_t i = 0; i < FUNC_LAST; i++) {
502 g_functions[i] = nullptr;
503 }
504}
505
506static void* LoadSharedLibrary(const char* shared_lib, const char* prefix, MallocDispatch* dispatch_table) {
507 void* impl_handle = dlopen(shared_lib, RTLD_NOW | RTLD_LOCAL);
508 if (impl_handle == nullptr) {
509 error_log("%s: Unable to open shared library %s: %s", getprogname(), shared_lib, dlerror());
510 return nullptr;
511 }
512
513 static constexpr const char* names[] = {
514 "initialize",
515 "finalize",
516 "get_malloc_leak_info",
517 "free_malloc_leak_info",
518 "malloc_backtrace",
Christopher Ferris2e1a40a2018-06-13 10:46:34 -0700519 "write_malloc_leak_info",
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800520 };
521 for (size_t i = 0; i < FUNC_LAST; i++) {
522 char symbol[128];
523 snprintf(symbol, sizeof(symbol), "%s_%s", prefix, names[i]);
524 g_functions[i] = dlsym(impl_handle, symbol);
525 if (g_functions[i] == nullptr) {
526 error_log("%s: %s routine not found in %s", getprogname(), symbol, shared_lib);
527 dlclose(impl_handle);
528 ClearGlobalFunctions();
529 return nullptr;
530 }
531 }
532
533 if (!InitMallocFunctions(impl_handle, dispatch_table, prefix)) {
534 dlclose(impl_handle);
535 ClearGlobalFunctions();
536 return nullptr;
537 }
538
539 return impl_handle;
Christopher Ferris63860cb2015-11-16 17:30:32 -0800540}
541
Florian Mayer176a4752018-10-23 11:48:34 +0100542// A function pointer to heapprofds init function. Used to re-initialize
543// heapprofd. This will start a new profiling session and tear down the old
544// one in case it is still active.
545static _Atomic init_func_t g_heapprofd_init_func = nullptr;
546
Florian Mayerf7f71e32018-08-31 15:36:48 -0700547static void install_hooks(libc_globals* globals, const char* options,
548 const char* prefix, const char* shared_lib) {
Florian Mayer176a4752018-10-23 11:48:34 +0100549 init_func_t init_func = atomic_load(&g_heapprofd_init_func);
550 if (init_func != nullptr) {
551 init_func(&__libc_malloc_default_dispatch, &gMallocLeakZygoteChild, options);
552 info_log("%s: malloc %s re-enabled", getprogname(), prefix);
553 return;
554 }
555
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800556 MallocDispatch dispatch_table;
557 void* impl_handle = LoadSharedLibrary(shared_lib, prefix, &dispatch_table);
558 if (impl_handle == nullptr) {
Christopher Ferris63860cb2015-11-16 17:30:32 -0800559 return;
560 }
Florian Mayer176a4752018-10-23 11:48:34 +0100561 init_func = reinterpret_cast<init_func_t>(g_functions[FUNC_INITIALIZE]);
Tamas Berghammerac81fe82016-08-26 15:54:59 +0100562 if (!init_func(&__libc_malloc_default_dispatch, &gMallocLeakZygoteChild, options)) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800563 dlclose(impl_handle);
564 ClearGlobalFunctions();
Christopher Ferris63860cb2015-11-16 17:30:32 -0800565 return;
566 }
567
Florian Mayer176a4752018-10-23 11:48:34 +0100568 atomic_store(&g_heapprofd_init_func, init_func);
Florian Mayere965bcd2018-11-23 15:35:42 +0000569 // We assign free first explicitly to prevent the case where we observe a
570 // alloc, but miss the corresponding free because of initialization order.
571 //
572 // This is safer than relying on the declaration order inside
573 // MallocDispatch at the cost of an extra atomic pointer write on
574 // initialization.
575 atomic_store(&globals->malloc_dispatch.free, dispatch_table.free);
576 // The struct gets assigned elementwise and each of the elements is an
577 // _Atomic. Assigning to an _Atomic is an atomic_store operation.
578 // The assignment is done in declaration order.
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800579 globals->malloc_dispatch = dispatch_table;
Christopher Ferris63860cb2015-11-16 17:30:32 -0800580
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800581 info_log("%s: malloc %s enabled", getprogname(), prefix);
Christopher Ferris63860cb2015-11-16 17:30:32 -0800582
583 // Use atexit to trigger the cleanup function. This avoids a problem
584 // where another atexit function is used to cleanup allocated memory,
585 // but the finalize function was already called. This particular error
586 // seems to be triggered by a zygote spawned process calling exit.
587 int ret_value = __cxa_atexit(malloc_fini_impl, nullptr, nullptr);
588 if (ret_value != 0) {
589 error_log("failed to set atexit cleanup function: %d", ret_value);
590 }
591}
592
Florian Mayerf7f71e32018-08-31 15:36:48 -0700593extern "C" void InstallInitHeapprofdHook(int);
594
595// Initializes memory allocation framework once per process.
596static void malloc_init_impl(libc_globals* globals) {
597 struct sigaction action = {};
598 action.sa_handler = InstallInitHeapprofdHook;
599 sigaction(HEAPPROFD_SIGNAL, &action, nullptr);
600
601 const char* prefix;
602 const char* shared_lib;
603 char prop[PROP_VALUE_MAX];
604 char* options = prop;
605 // Prefer malloc debug since it existed first and is a more complete
606 // malloc interceptor than the hooks.
607 if (CheckLoadMallocDebug(&options)) {
608 prefix = "debug";
609 shared_lib = DEBUG_SHARED_LIB;
610 } else if (CheckLoadMallocHooks(&options)) {
611 prefix = "hooks";
612 shared_lib = HOOKS_SHARED_LIB;
Florian Mayer0dbe6d12018-11-08 11:25:49 +0000613 } else if (CheckLoadHeapprofd()) {
614 prefix = "heapprofd";
615 shared_lib = HEAPPROFD_SHARED_LIB;
Florian Mayerf7f71e32018-08-31 15:36:48 -0700616 } else {
617 return;
618 }
619 install_hooks(globals, options, prefix, shared_lib);
620}
621
Christopher Ferris63860cb2015-11-16 17:30:32 -0800622// Initializes memory allocation framework.
623// This routine is called from __libc_init routines in libc_init_dynamic.cpp.
624__LIBC_HIDDEN__ void __libc_init_malloc(libc_globals* globals) {
625 malloc_init_impl(globals);
626}
Florian Mayerf7f71e32018-08-31 15:36:48 -0700627
628// The logic for triggering heapprofd below is as following.
629// 1. HEAPPROFD_SIGNAL is received by the process.
Florian Mayer176a4752018-10-23 11:48:34 +0100630// 2. If neither InitHeapprofd nor InitHeapprofdHook are currently installed
631// (g_heapprofd_init_hook_installed is false), InitHeapprofdHook is
632// installed and g_heapprofd_init_in_progress is set to true.
633//
634// On the next subsequent malloc, InitHeapprofdHook is called and
635// 3a. If the signal is currently being handled (g_heapprofd_init_in_progress
Florian Mayerf7f71e32018-08-31 15:36:48 -0700636// is true), no action is taken.
Florian Mayer176a4752018-10-23 11:48:34 +0100637// 3b. Otherwise, The signal handler (InstallInitHeapprofdHook) installs a
Florian Mayerf7f71e32018-08-31 15:36:48 -0700638// temporary malloc hook (InitHeapprofdHook).
Florian Mayer176a4752018-10-23 11:48:34 +0100639// 4. When this hook gets run the first time, it uninstalls itself and spawns
Florian Mayerf7f71e32018-08-31 15:36:48 -0700640// a thread running InitHeapprofd that loads heapprofd.so and installs the
641// hooks within.
Florian Mayer176a4752018-10-23 11:48:34 +0100642// 5. g_heapprofd_init_in_progress and g_heapprofd_init_hook_installed are
643// reset to false so heapprofd can be reinitialized. Reinitialization
644// means that a new profiling session is started and any still active is
645// torn down.
Florian Mayerf7f71e32018-08-31 15:36:48 -0700646//
647// This roundabout way is needed because we are running non AS-safe code, so
648// we cannot run it directly in the signal handler. The other approach of
649// running a standby thread and signalling through write(2) and read(2) would
650// significantly increase the number of active threads in the system.
651
652static _Atomic bool g_heapprofd_init_in_progress = false;
Florian Mayer176a4752018-10-23 11:48:34 +0100653static _Atomic bool g_heapprofd_init_hook_installed = false;
Florian Mayerf7f71e32018-08-31 15:36:48 -0700654
655static void* InitHeapprofd(void*) {
656 __libc_globals.mutate([](libc_globals* globals) {
657 install_hooks(globals, nullptr, HEAPPROFD_PREFIX, HEAPPROFD_SHARED_LIB);
658 });
659 atomic_store(&g_heapprofd_init_in_progress, false);
Florian Mayer176a4752018-10-23 11:48:34 +0100660 // Allow to install hook again to re-initialize heap profiling after the
661 // current session finished.
662 atomic_store(&g_heapprofd_init_hook_installed, false);
Florian Mayerf7f71e32018-08-31 15:36:48 -0700663 return nullptr;
664}
665
666static void* InitHeapprofdHook(size_t bytes) {
Florian Mayer176a4752018-10-23 11:48:34 +0100667 if (!atomic_exchange(&g_heapprofd_init_hook_installed, true)) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700668 __libc_globals.mutate([](libc_globals* globals) {
669 atomic_store(&globals->malloc_dispatch.malloc, nullptr);
670 });
671
672 pthread_t thread_id;
673 if (pthread_create(&thread_id, nullptr, InitHeapprofd, nullptr) == -1)
674 error_log("%s: heapprofd: failed to pthread_create.", getprogname());
675 else if (pthread_detach(thread_id) == -1)
676 error_log("%s: heapprofd: failed to pthread_detach", getprogname());
677 if (pthread_setname_np(thread_id, "heapprofdinit") == -1)
678 error_log("%s: heapprod: failed to pthread_setname_np", getprogname());
679 }
680 return Malloc(malloc)(bytes);
681}
682
683extern "C" void InstallInitHeapprofdHook(int) {
684 if (!atomic_exchange(&g_heapprofd_init_in_progress, true)) {
685 __libc_globals.mutate([](libc_globals* globals) {
Florian Mayere965bcd2018-11-23 15:35:42 +0000686 atomic_store(&globals->malloc_dispatch.malloc, InitHeapprofdHook);
Florian Mayerf7f71e32018-08-31 15:36:48 -0700687 });
688 }
689}
690
Christopher Ferris63860cb2015-11-16 17:30:32 -0800691#endif // !LIBC_STATIC
Colin Cross869691c2016-01-29 12:48:18 -0800692
693// =============================================================================
694// Exported for use by libmemunreachable.
695// =============================================================================
696
697// Calls callback for every allocation in the anonymous heap mapping
698// [base, base+size). Must be called between malloc_disable and malloc_enable.
699extern "C" int malloc_iterate(uintptr_t base, size_t size,
700 void (*callback)(uintptr_t base, size_t size, void* arg), void* arg) {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700701 auto _iterate = atomic_load_explicit_const(
702 &__libc_globals->malloc_dispatch.iterate,
703 default_read_memory_order);
Colin Cross869691c2016-01-29 12:48:18 -0800704 if (__predict_false(_iterate != nullptr)) {
705 return _iterate(base, size, callback, arg);
706 }
707 return Malloc(iterate)(base, size, callback, arg);
708}
709
710// Disable calls to malloc so malloc_iterate gets a consistent view of
711// allocated memory.
712extern "C" void malloc_disable() {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700713 auto _malloc_disable = atomic_load_explicit_const(
714 & __libc_globals->malloc_dispatch.malloc_disable,
715 default_read_memory_order);
Colin Cross869691c2016-01-29 12:48:18 -0800716 if (__predict_false(_malloc_disable != nullptr)) {
717 return _malloc_disable();
718 }
719 return Malloc(malloc_disable)();
720}
721
722// Re-enable calls to malloc after a previous call to malloc_disable.
723extern "C" void malloc_enable() {
Florian Mayerf7f71e32018-08-31 15:36:48 -0700724 auto _malloc_enable = atomic_load_explicit_const(
725 &__libc_globals->malloc_dispatch.malloc_enable,
726 default_read_memory_order);
Colin Cross869691c2016-01-29 12:48:18 -0800727 if (__predict_false(_malloc_enable != nullptr)) {
728 return _malloc_enable();
729 }
730 return Malloc(malloc_enable)();
731}
Colin Cross2d4721c2016-02-02 11:57:54 -0800732
733#ifndef LIBC_STATIC
734extern "C" ssize_t malloc_backtrace(void* pointer, uintptr_t* frames, size_t frame_count) {
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800735 void* func = g_functions[FUNC_MALLOC_BACKTRACE];
736 if (func == nullptr) {
Colin Cross2d4721c2016-02-02 11:57:54 -0800737 return 0;
738 }
Christopher Ferrisdb478a62018-02-07 18:42:14 -0800739 return reinterpret_cast<malloc_backtrace_func_t>(func)(pointer, frames, frame_count);
Colin Cross2d4721c2016-02-02 11:57:54 -0800740}
741#else
742extern "C" ssize_t malloc_backtrace(void*, uintptr_t*, size_t) {
743 return 0;
744}
745#endif