blob: 87d24d1ad157ef8fac4200518239d7847a345ae2 [file] [log] [blame]
Colin Cross16b23492016-01-06 14:41:07 -08001// Copyright 2016 Google Inc. All rights reserved.
2//
3// Licensed under the Apache License, Version 2.0 (the "License");
4// you may not use this file except in compliance with the License.
5// You may obtain a copy of the License at
6//
7// http://www.apache.org/licenses/LICENSE-2.0
8//
9// Unless required by applicable law or agreed to in writing, software
10// distributed under the License is distributed on an "AS IS" BASIS,
11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12// See the License for the specific language governing permissions and
13// limitations under the License.
14
15package cc
16
17import (
18 "fmt"
Jeff Gaston72765392017-11-28 16:37:53 -080019 "sort"
Colin Cross16b23492016-01-06 14:41:07 -080020 "strings"
Vishwath Mohane7128792017-11-17 11:08:10 -080021 "sync"
Colin Cross16b23492016-01-06 14:41:07 -080022
Colin Cross6b753602018-06-21 13:03:07 -070023 "github.com/google/blueprint"
Liz Kammerb2fc4702021-06-25 14:53:40 -040024 "github.com/google/blueprint/proptools"
Colin Cross6b753602018-06-21 13:03:07 -070025
Colin Cross635c3b02016-05-18 15:37:25 -070026 "android/soong/android"
Evgenii Stepanovaf36db12016-08-15 14:18:24 -070027 "android/soong/cc/config"
Kiyoung Kim48f37782021-07-07 12:42:39 +090028 "android/soong/snapshot"
Colin Cross16b23492016-01-06 14:41:07 -080029)
30
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070031var (
32 // Any C flags added by sanitizer which libTooling tools may not
33 // understand also need to be added to ClangLibToolingUnknownCflags in
34 // cc/config/clang.go
Vishwath Mohanf3918d32017-02-14 07:59:33 -080035
Yi Kong20233a42019-08-21 01:38:40 -070036 asanCflags = []string{
37 "-fno-omit-frame-pointer",
Yi Kong20233a42019-08-21 01:38:40 -070038 }
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070039 asanLdflags = []string{"-Wl,-u,__asan_preinit"}
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070040
Florian Mayera9984462023-06-16 16:48:51 -070041 // DO NOT ADD MLLVM FLAGS HERE! ADD THEM BELOW TO hwasanCommonFlags.
Yi Kong286abc62021-11-04 16:14:14 +080042 hwasanCflags = []string{
43 "-fno-omit-frame-pointer",
44 "-Wno-frame-larger-than=",
Evgenii Stepanov96fa3dd2020-03-27 19:38:42 +000045 "-fsanitize-hwaddress-abi=platform",
Yi Kong286abc62021-11-04 16:14:14 +080046 }
47
48 // ThinLTO performs codegen during link time, thus these flags need to
49 // passed to both CFLAGS and LDFLAGS.
50 hwasanCommonflags = []string{
Evgenii Stepanov64bee4d2019-11-22 18:37:10 -080051 // The following improves debug location information
52 // availability at the cost of its accuracy. It increases
53 // the likelihood of a stack variable's frame offset
54 // to be recorded in the debug info, which is important
55 // for the quality of hwasan reports. The downside is a
56 // higher number of "optimized out" stack variables.
57 // b/112437883.
Yi Kong286abc62021-11-04 16:14:14 +080058 "-instcombine-lower-dbg-declare=0",
Florian Mayera9984462023-06-16 16:48:51 -070059 "-hwasan-use-after-scope=1",
Florian Mayerc7466192023-06-16 16:50:59 -070060 "-dom-tree-reachability-max-bbs-to-explore=128",
Evgenii Stepanov64bee4d2019-11-22 18:37:10 -080061 }
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -070062
Trevor Radcliffeded095c2023-06-12 19:18:28 +000063 sanitizeIgnorelistPrefix = "-fsanitize-ignorelist="
64
Trevor Radcliffe391a25d2023-03-22 20:22:27 +000065 cfiBlocklistPath = "external/compiler-rt/lib/cfi"
66 cfiBlocklistFilename = "cfi_blocklist.txt"
Trevor Radcliffef1836e42023-06-01 21:12:08 +000067 cfiEnableFlag = "-fsanitize=cfi"
Trevor Radcliffe9f4b4762023-04-04 20:13:42 +000068 cfiCrossDsoFlag = "-fsanitize-cfi-cross-dso"
69 cfiCflags = []string{"-flto", cfiCrossDsoFlag,
Trevor Radcliffeded095c2023-06-12 19:18:28 +000070 sanitizeIgnorelistPrefix + cfiBlocklistPath + "/" + cfiBlocklistFilename}
Evgenii Stepanovdbf1d4f2018-08-31 12:54:33 -070071 // -flto and -fvisibility are required by clang when -fsanitize=cfi is
72 // used, but have no effect on assembly files
73 cfiAsflags = []string{"-flto", "-fvisibility=default"}
Trevor Radcliffef1836e42023-06-01 21:12:08 +000074 cfiLdflags = []string{"-flto", cfiCrossDsoFlag, cfiEnableFlag,
Pirama Arumuga Nainarbdb17f02017-08-28 21:50:17 -070075 "-Wl,-plugin-opt,O1"}
Trevor Radcliffe391a25d2023-03-22 20:22:27 +000076 cfiExportsMapPath = "build/soong/cc/config"
77 cfiExportsMapFilename = "cfi_exports.map"
78 cfiAssemblySupportFlag = "-fno-sanitize-cfi-canonical-jump-tables"
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -070079
Pirama Arumuga Nainar582fc2d2021-08-27 15:12:56 -070080 intOverflowCflags = []string{"-fsanitize-ignorelist=build/soong/cc/config/integer_overflow_blocklist.txt"}
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -080081
Peter Collingbournebd19db02019-03-06 10:38:48 -080082 minimalRuntimeFlags = []string{"-fsanitize-minimal-runtime", "-fno-sanitize-trap=integer,undefined",
Ivan Lozanoae6ae1d2018-10-08 09:29:39 -070083 "-fno-sanitize-recover=integer,undefined"}
Evgenii Stepanov2c6484e2019-05-15 12:49:54 -070084 hwasanGlobalOptions = []string{"heap_history_size=1023", "stack_history_size=512",
Christopher Ferris2fc8e032023-01-26 14:19:27 -080085 "export_memory_stats=0", "max_malloc_fill_size=131072", "malloc_fill_byte=0"}
Florian Mayer1866bbe2023-03-11 01:07:40 +000086 memtagStackCommonFlags = []string{"-march=armv8-a+memtag", "-mllvm", "-dom-tree-reachability-max-bbs-to-explore=128"}
Trevor Radcliffe4f95ee92023-01-19 16:02:47 +000087
88 hostOnlySanitizeFlags = []string{"-fno-sanitize-recover=all"}
Elliott Hughes3bba0e42023-10-05 14:50:48 -070089 deviceOnlySanitizeFlags = []string{"-fsanitize-trap=all"}
Trevor Radcliffeda64d912023-08-02 20:24:29 +000090
91 noSanitizeLinkRuntimeFlag = "-fno-sanitize-link-runtime"
Dan Willemsencbceaab2016-10-13 16:44:07 -070092)
93
Ivan Lozano3968d8f2020-12-14 11:27:52 -050094type SanitizerType int
Colin Cross16b23492016-01-06 14:41:07 -080095
Colin Cross16b23492016-01-06 14:41:07 -080096const (
Ivan Lozano3968d8f2020-12-14 11:27:52 -050097 Asan SanitizerType = iota + 1
Tri Vo6eafc362021-04-01 11:29:09 -070098 Hwasan
Colin Cross16b23492016-01-06 14:41:07 -080099 tsan
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700100 intOverflow
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800101 scs
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500102 Fuzzer
Ivan Lozano62cd0382021-11-01 10:27:54 -0400103 Memtag_heap
Florian Mayerd8434a42022-08-31 20:57:03 +0000104 Memtag_stack
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200105 Memtag_globals
Liz Kammer75db9312021-07-07 16:41:50 -0400106 cfi // cfi is last to prevent it running before incompatible mutators
Colin Cross16b23492016-01-06 14:41:07 -0800107)
108
Liz Kammer75db9312021-07-07 16:41:50 -0400109var Sanitizers = []SanitizerType{
110 Asan,
111 Hwasan,
112 tsan,
113 intOverflow,
114 scs,
115 Fuzzer,
Ivan Lozano62cd0382021-11-01 10:27:54 -0400116 Memtag_heap,
Florian Mayerd8434a42022-08-31 20:57:03 +0000117 Memtag_stack,
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200118 Memtag_globals,
Liz Kammer75db9312021-07-07 16:41:50 -0400119 cfi, // cfi is last to prevent it running before incompatible mutators
120}
121
Jiyong Park82226632019-02-01 10:50:50 +0900122// Name of the sanitizer variation for this sanitizer type
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500123func (t SanitizerType) variationName() string {
Colin Cross16b23492016-01-06 14:41:07 -0800124 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500125 case Asan:
Colin Cross16b23492016-01-06 14:41:07 -0800126 return "asan"
Tri Vo6eafc362021-04-01 11:29:09 -0700127 case Hwasan:
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700128 return "hwasan"
Colin Cross16b23492016-01-06 14:41:07 -0800129 case tsan:
130 return "tsan"
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700131 case intOverflow:
132 return "intOverflow"
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000133 case cfi:
134 return "cfi"
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800135 case scs:
136 return "scs"
Ivan Lozano62cd0382021-11-01 10:27:54 -0400137 case Memtag_heap:
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700138 return "memtag_heap"
Florian Mayerd8434a42022-08-31 20:57:03 +0000139 case Memtag_stack:
140 return "memtag_stack"
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200141 case Memtag_globals:
142 return "memtag_globals"
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500143 case Fuzzer:
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700144 return "fuzzer"
Colin Cross16b23492016-01-06 14:41:07 -0800145 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500146 panic(fmt.Errorf("unknown SanitizerType %d", t))
Colin Cross16b23492016-01-06 14:41:07 -0800147 }
148}
149
Jiyong Park82226632019-02-01 10:50:50 +0900150// This is the sanitizer names in SANITIZE_[TARGET|HOST]
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500151func (t SanitizerType) name() string {
Jiyong Park82226632019-02-01 10:50:50 +0900152 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500153 case Asan:
Jiyong Park82226632019-02-01 10:50:50 +0900154 return "address"
Tri Vo6eafc362021-04-01 11:29:09 -0700155 case Hwasan:
Jiyong Park82226632019-02-01 10:50:50 +0900156 return "hwaddress"
Ivan Lozano62cd0382021-11-01 10:27:54 -0400157 case Memtag_heap:
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700158 return "memtag_heap"
Florian Mayerd8434a42022-08-31 20:57:03 +0000159 case Memtag_stack:
160 return "memtag_stack"
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200161 case Memtag_globals:
162 return "memtag_globals"
Jiyong Park82226632019-02-01 10:50:50 +0900163 case tsan:
164 return "thread"
165 case intOverflow:
166 return "integer_overflow"
167 case cfi:
168 return "cfi"
169 case scs:
170 return "shadow-call-stack"
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500171 case Fuzzer:
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700172 return "fuzzer"
Jiyong Park82226632019-02-01 10:50:50 +0900173 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500174 panic(fmt.Errorf("unknown SanitizerType %d", t))
Jiyong Park82226632019-02-01 10:50:50 +0900175 }
176}
177
Liz Kammer75db9312021-07-07 16:41:50 -0400178func (t SanitizerType) registerMutators(ctx android.RegisterMutatorsContext) {
179 switch t {
Lukacs T. Berki6c716762022-06-13 20:50:39 +0200180 case cfi, Hwasan, Asan, tsan, Fuzzer, scs:
181 sanitizer := &sanitizerSplitMutator{t}
182 ctx.TopDown(t.variationName()+"_markapexes", sanitizer.markSanitizableApexesMutator)
183 ctx.Transition(t.variationName(), sanitizer)
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200184 case Memtag_heap, Memtag_stack, Memtag_globals, intOverflow:
Liz Kammer75db9312021-07-07 16:41:50 -0400185 // do nothing
186 default:
187 panic(fmt.Errorf("unknown SanitizerType %d", t))
188 }
189}
190
Liz Kammerfd8a49f2022-10-31 10:31:11 -0400191// shouldPropagateToSharedLibraryDeps returns whether a sanitizer type should propagate to share
192// dependencies. In most cases, sanitizers only propagate to static dependencies; however, some
193// sanitizers also must be enabled for shared libraries for linking.
194func (t SanitizerType) shouldPropagateToSharedLibraryDeps() bool {
195 switch t {
196 case Fuzzer:
197 // Typically, shared libs are not split. However, for fuzzer, we split even for shared libs
198 // because a library sanitized for fuzzer can't be linked from a library that isn't sanitized
199 // for fuzzer.
200 return true
201 default:
202 return false
203 }
204}
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500205func (*Module) SanitizerSupported(t SanitizerType) bool {
206 switch t {
207 case Asan:
208 return true
Tri Vo6eafc362021-04-01 11:29:09 -0700209 case Hwasan:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500210 return true
211 case tsan:
212 return true
213 case intOverflow:
214 return true
215 case cfi:
216 return true
217 case scs:
218 return true
219 case Fuzzer:
220 return true
Ivan Lozano62cd0382021-11-01 10:27:54 -0400221 case Memtag_heap:
222 return true
Florian Mayerd8434a42022-08-31 20:57:03 +0000223 case Memtag_stack:
224 return true
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200225 case Memtag_globals:
226 return true
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500227 default:
228 return false
229 }
230}
231
232// incompatibleWithCfi returns true if a sanitizer is incompatible with CFI.
233func (t SanitizerType) incompatibleWithCfi() bool {
Tri Vo6eafc362021-04-01 11:29:09 -0700234 return t == Asan || t == Fuzzer || t == Hwasan
Jiyong Park1d1119f2019-07-29 21:27:18 +0900235}
236
Martin Stjernholmb0249572020-09-15 02:32:35 +0100237type SanitizeUserProps struct {
Liz Kammer75b9b402021-06-25 15:19:27 -0400238 // Prevent use of any sanitizers on this module
Martin Stjernholmb0249572020-09-15 02:32:35 +0100239 Never *bool `android:"arch_variant"`
Colin Cross16b23492016-01-06 14:41:07 -0800240
Liz Kammer75b9b402021-06-25 15:19:27 -0400241 // ASan (Address sanitizer), incompatible with static binaries.
242 // Always runs in a diagnostic mode.
243 // Use of address sanitizer disables cfi sanitizer.
244 // Hwaddress sanitizer takes precedence over this sanitizer.
245 Address *bool `android:"arch_variant"`
246 // TSan (Thread sanitizer), incompatible with static binaries and 32 bit architectures.
247 // Always runs in a diagnostic mode.
248 // Use of thread sanitizer disables cfi and scudo sanitizers.
249 // Hwaddress sanitizer takes precedence over this sanitizer.
250 Thread *bool `android:"arch_variant"`
251 // HWASan (Hardware Address sanitizer).
252 // Use of hwasan sanitizer disables cfi, address, thread, and scudo sanitizers.
Martin Stjernholmb0249572020-09-15 02:32:35 +0100253 Hwaddress *bool `android:"arch_variant"`
Colin Cross16b23492016-01-06 14:41:07 -0800254
Liz Kammer75b9b402021-06-25 15:19:27 -0400255 // Undefined behavior sanitizer
256 All_undefined *bool `android:"arch_variant"`
257 // Subset of undefined behavior sanitizer
258 Undefined *bool `android:"arch_variant"`
259 // List of specific undefined behavior sanitizers to enable
260 Misc_undefined []string `android:"arch_variant"`
261 // Fuzzer, incompatible with static binaries.
262 Fuzzer *bool `android:"arch_variant"`
263 // safe-stack sanitizer, incompatible with 32-bit architectures.
264 Safestack *bool `android:"arch_variant"`
265 // cfi sanitizer, incompatible with asan, hwasan, fuzzer, or Darwin
266 Cfi *bool `android:"arch_variant"`
267 // signed/unsigned integer overflow sanitizer, incompatible with Darwin.
268 Integer_overflow *bool `android:"arch_variant"`
269 // scudo sanitizer, incompatible with asan, hwasan, tsan
270 // This should not be used in Android 11+ : https://source.android.com/devices/tech/debug/scudo
271 // deprecated
272 Scudo *bool `android:"arch_variant"`
Elliott Hughese4793bc2023-02-09 21:15:47 +0000273 // shadow-call-stack sanitizer, only available on arm64/riscv64.
Liz Kammer75b9b402021-06-25 15:19:27 -0400274 Scs *bool `android:"arch_variant"`
275 // Memory-tagging, only available on arm64
276 // if diag.memtag unset or false, enables async memory tagging
Florian Mayer00ab5cf2022-08-31 18:30:18 +0000277 Memtag_heap *bool `android:"arch_variant"`
Florian Mayerd8434a42022-08-31 20:57:03 +0000278 // Memory-tagging stack instrumentation, only available on arm64
279 // Adds instrumentation to detect stack buffer overflows and use-after-scope using MTE.
280 Memtag_stack *bool `android:"arch_variant"`
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200281 // Memory-tagging globals instrumentation, only available on arm64
282 // Adds instrumentation to detect global buffer overflows using MTE.
283 Memtag_globals *bool `android:"arch_variant"`
Martin Stjernholmb0249572020-09-15 02:32:35 +0100284
285 // A modifier for ASAN and HWASAN for write only instrumentation
286 Writeonly *bool `android:"arch_variant"`
287
288 // Sanitizers to run in the diagnostic mode (as opposed to the release mode).
289 // Replaces abort() on error with a human-readable error message.
290 // Address and Thread sanitizers always run in diagnostic mode.
291 Diag struct {
Liz Kammer75b9b402021-06-25 15:19:27 -0400292 // Undefined behavior sanitizer, diagnostic mode
293 Undefined *bool `android:"arch_variant"`
294 // cfi sanitizer, diagnostic mode, incompatible with asan, hwasan, fuzzer, or Darwin
295 Cfi *bool `android:"arch_variant"`
296 // signed/unsigned integer overflow sanitizer, diagnostic mode, incompatible with Darwin.
297 Integer_overflow *bool `android:"arch_variant"`
298 // Memory-tagging, only available on arm64
299 // requires sanitizer.memtag: true
300 // if set, enables sync memory tagging
301 Memtag_heap *bool `android:"arch_variant"`
302 // List of specific undefined behavior sanitizers to enable in diagnostic mode
303 Misc_undefined []string `android:"arch_variant"`
304 // List of sanitizers to pass to -fno-sanitize-recover
305 // results in only the first detected error for these sanitizers being reported and program then
306 // exits with a non-zero exit code.
307 No_recover []string `android:"arch_variant"`
Cindy Zhoud3fe4922020-12-01 11:14:30 -0800308 } `android:"arch_variant"`
Colin Cross16b23492016-01-06 14:41:07 -0800309
Cindy Zhou8cd45de2020-11-16 08:41:00 -0800310 // Sanitizers to run with flag configuration specified
311 Config struct {
312 // Enables CFI support flags for assembly-heavy libraries
313 Cfi_assembly_support *bool `android:"arch_variant"`
Cindy Zhoud3fe4922020-12-01 11:14:30 -0800314 } `android:"arch_variant"`
Cindy Zhou8cd45de2020-11-16 08:41:00 -0800315
Liz Kammer75b9b402021-06-25 15:19:27 -0400316 // List of sanitizers to pass to -fsanitize-recover
317 // allows execution to continue for these sanitizers to detect multiple errors rather than only
318 // the first one
Martin Stjernholmb0249572020-09-15 02:32:35 +0100319 Recover []string
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000320
Pirama Arumuga Nainar582fc2d2021-08-27 15:12:56 -0700321 // value to pass to -fsanitize-ignorelist
Martin Stjernholmb0249572020-09-15 02:32:35 +0100322 Blocklist *string
323}
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700324
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400325type sanitizeMutatedProperties struct {
326 // Whether sanitizers can be enabled on this module
327 Never *bool `blueprint:"mutated"`
328
329 // Whether ASan (Address sanitizer) is enabled for this module.
330 // Hwaddress sanitizer takes precedence over this sanitizer.
331 Address *bool `blueprint:"mutated"`
332 // Whether TSan (Thread sanitizer) is enabled for this module
333 Thread *bool `blueprint:"mutated"`
334 // Whether HWASan (Hardware Address sanitizer) is enabled for this module
335 Hwaddress *bool `blueprint:"mutated"`
336
337 // Whether Undefined behavior sanitizer is enabled for this module
338 All_undefined *bool `blueprint:"mutated"`
339 // Whether undefined behavior sanitizer subset is enabled for this module
340 Undefined *bool `blueprint:"mutated"`
341 // List of specific undefined behavior sanitizers enabled for this module
342 Misc_undefined []string `blueprint:"mutated"`
343 // Whether Fuzzeris enabled for this module
344 Fuzzer *bool `blueprint:"mutated"`
345 // whether safe-stack sanitizer is enabled for this module
346 Safestack *bool `blueprint:"mutated"`
347 // Whether cfi sanitizer is enabled for this module
348 Cfi *bool `blueprint:"mutated"`
349 // Whether signed/unsigned integer overflow sanitizer is enabled for this module
350 Integer_overflow *bool `blueprint:"mutated"`
351 // Whether scudo sanitizer is enabled for this module
352 Scudo *bool `blueprint:"mutated"`
353 // Whether shadow-call-stack sanitizer is enabled for this module.
354 Scs *bool `blueprint:"mutated"`
355 // Whether Memory-tagging is enabled for this module
356 Memtag_heap *bool `blueprint:"mutated"`
357 // Whether Memory-tagging stack instrumentation is enabled for this module
358 Memtag_stack *bool `blueprint:"mutated"`
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200359 // Whether Memory-tagging globals instrumentation is enabled for this module
360 Memtag_globals *bool `android:"arch_variant"`
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400361
362 // Whether a modifier for ASAN and HWASAN for write only instrumentation is enabled for this
363 // module
364 Writeonly *bool `blueprint:"mutated"`
365
366 // Sanitizers to run in the diagnostic mode (as opposed to the release mode).
367 Diag struct {
368 // Whether Undefined behavior sanitizer, diagnostic mode is enabled for this module
369 Undefined *bool `blueprint:"mutated"`
370 // Whether cfi sanitizer, diagnostic mode is enabled for this module
371 Cfi *bool `blueprint:"mutated"`
372 // Whether signed/unsigned integer overflow sanitizer, diagnostic mode is enabled for this
373 // module
374 Integer_overflow *bool `blueprint:"mutated"`
375 // Whether Memory-tagging, diagnostic mode is enabled for this module
376 Memtag_heap *bool `blueprint:"mutated"`
377 // List of specific undefined behavior sanitizers enabled in diagnostic mode
378 Misc_undefined []string `blueprint:"mutated"`
379 } `blueprint:"mutated"`
380}
381
Martin Stjernholmb0249572020-09-15 02:32:35 +0100382type SanitizeProperties struct {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400383 Sanitize SanitizeUserProps `android:"arch_variant"`
384 SanitizeMutated sanitizeMutatedProperties `blueprint:"mutated"`
385
386 SanitizerEnabled bool `blueprint:"mutated"`
387 MinimalRuntimeDep bool `blueprint:"mutated"`
388 BuiltinsDep bool `blueprint:"mutated"`
389 UbsanRuntimeDep bool `blueprint:"mutated"`
390 InSanitizerDir bool `blueprint:"mutated"`
391 Sanitizers []string `blueprint:"mutated"`
392 DiagSanitizers []string `blueprint:"mutated"`
Colin Cross16b23492016-01-06 14:41:07 -0800393}
394
395type sanitize struct {
396 Properties SanitizeProperties
397}
398
Cindy Zhou18417cb2020-12-10 07:12:38 -0800399// Mark this tag with a check to see if apex dependency check should be skipped
400func (t libraryDependencyTag) SkipApexAllowedDependenciesCheck() bool {
401 return t.skipApexAllowedDependenciesCheck
402}
403
404var _ android.SkipApexAllowedDependenciesCheck = (*libraryDependencyTag)(nil)
405
Trevor Radcliffe4f95ee92023-01-19 16:02:47 +0000406var exportedVars = android.NewExportedVariables(pctx)
407
Vishwath Mohane7128792017-11-17 11:08:10 -0800408func init() {
Trevor Radcliffe4f95ee92023-01-19 16:02:47 +0000409 exportedVars.ExportStringListStaticVariable("HostOnlySanitizeFlags", hostOnlySanitizeFlags)
410 exportedVars.ExportStringList("DeviceOnlySanitizeFlags", deviceOnlySanitizeFlags)
411
Trevor Radcliffe3876c5a2023-08-02 15:41:50 +0000412 exportedVars.ExportStringList("MinimalRuntimeFlags", minimalRuntimeFlags)
413
Trevor Radcliffe391a25d2023-03-22 20:22:27 +0000414 // Leave out "-flto" from the slices exported to bazel, as we will use the
Trevor Radcliffe9f4b4762023-04-04 20:13:42 +0000415 // dedicated LTO feature for this. For C Flags and Linker Flags, also leave
Trevor Radcliffef1836e42023-06-01 21:12:08 +0000416 // out the cross DSO flag which will be added separately under the correct conditions.
417 exportedVars.ExportStringList("CfiCFlags", append(cfiCflags[2:], cfiEnableFlag))
Trevor Radcliffe9f4b4762023-04-04 20:13:42 +0000418 exportedVars.ExportStringList("CfiLdFlags", cfiLdflags[2:])
Trevor Radcliffe391a25d2023-03-22 20:22:27 +0000419 exportedVars.ExportStringList("CfiAsFlags", cfiAsflags[1:])
Trevor Radcliffe391a25d2023-03-22 20:22:27 +0000420
Trevor Radcliffeded095c2023-06-12 19:18:28 +0000421 exportedVars.ExportString("SanitizeIgnorelistPrefix", sanitizeIgnorelistPrefix)
Trevor Radcliffe9f4b4762023-04-04 20:13:42 +0000422 exportedVars.ExportString("CfiCrossDsoFlag", cfiCrossDsoFlag)
Trevor Radcliffe391a25d2023-03-22 20:22:27 +0000423 exportedVars.ExportString("CfiBlocklistPath", cfiBlocklistPath)
424 exportedVars.ExportString("CfiBlocklistFilename", cfiBlocklistFilename)
425 exportedVars.ExportString("CfiExportsMapPath", cfiExportsMapPath)
426 exportedVars.ExportString("CfiExportsMapFilename", cfiExportsMapFilename)
427 exportedVars.ExportString("CfiAssemblySupportFlag", cfiAssemblySupportFlag)
428
Trevor Radcliffeda64d912023-08-02 20:24:29 +0000429 exportedVars.ExportString("NoSanitizeLinkRuntimeFlag", noSanitizeLinkRuntimeFlag)
430
Vishwath Mohane7128792017-11-17 11:08:10 -0800431 android.RegisterMakeVarsProvider(pctx, cfiMakeVarsProvider)
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700432 android.RegisterMakeVarsProvider(pctx, hwasanMakeVarsProvider)
Vishwath Mohane7128792017-11-17 11:08:10 -0800433}
434
Colin Cross16b23492016-01-06 14:41:07 -0800435func (sanitize *sanitize) props() []interface{} {
436 return []interface{}{&sanitize.Properties}
437}
438
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400439func (p *sanitizeMutatedProperties) copyUserPropertiesToMutated(userProps *SanitizeUserProps) {
440 p.Never = userProps.Never
441 p.Address = userProps.Address
442 p.All_undefined = userProps.All_undefined
443 p.Cfi = userProps.Cfi
444 p.Fuzzer = userProps.Fuzzer
445 p.Hwaddress = userProps.Hwaddress
446 p.Integer_overflow = userProps.Integer_overflow
447 p.Memtag_heap = userProps.Memtag_heap
448 p.Memtag_stack = userProps.Memtag_stack
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200449 p.Memtag_globals = userProps.Memtag_globals
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400450 p.Safestack = userProps.Safestack
451 p.Scs = userProps.Scs
452 p.Scudo = userProps.Scudo
453 p.Thread = userProps.Thread
454 p.Undefined = userProps.Undefined
455 p.Writeonly = userProps.Writeonly
456
457 p.Misc_undefined = make([]string, 0, len(userProps.Misc_undefined))
458 for _, v := range userProps.Misc_undefined {
459 p.Misc_undefined = append(p.Misc_undefined, v)
460 }
461
462 p.Diag.Cfi = userProps.Diag.Cfi
463 p.Diag.Integer_overflow = userProps.Diag.Integer_overflow
464 p.Diag.Memtag_heap = userProps.Diag.Memtag_heap
465 p.Diag.Undefined = userProps.Diag.Undefined
466
467 p.Diag.Misc_undefined = make([]string, 0, len(userProps.Diag.Misc_undefined))
468 for _, v := range userProps.Diag.Misc_undefined {
469 p.Diag.Misc_undefined = append(p.Diag.Misc_undefined, v)
470 }
471}
472
Colin Cross16b23492016-01-06 14:41:07 -0800473func (sanitize *sanitize) begin(ctx BaseModuleContext) {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400474 s := &sanitize.Properties.SanitizeMutated
475 s.copyUserPropertiesToMutated(&sanitize.Properties.Sanitize)
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700476
Colin Cross16b23492016-01-06 14:41:07 -0800477 // Don't apply sanitizers to NDK code.
Jeff Gastonaf3cc2d2017-09-27 17:01:44 -0700478 if ctx.useSdk() {
Nan Zhang0007d812017-11-07 10:57:05 -0800479 s.Never = BoolPtr(true)
Colin Cross16b23492016-01-06 14:41:07 -0800480 }
481
482 // Never always wins.
Nan Zhang0007d812017-11-07 10:57:05 -0800483 if Bool(s.Never) {
Colin Cross16b23492016-01-06 14:41:07 -0800484 return
485 }
486
Florian Mayerd8434a42022-08-31 20:57:03 +0000487 // cc_test targets default to SYNC MemTag unless explicitly set to ASYNC (via diag: {memtag_heap: false}).
Liz Kammer7b920b42021-06-22 16:57:27 -0400488 if ctx.testBinary() {
489 if s.Memtag_heap == nil {
490 s.Memtag_heap = proptools.BoolPtr(true)
491 }
492 if s.Diag.Memtag_heap == nil {
493 s.Diag.Memtag_heap = proptools.BoolPtr(true)
494 }
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800495 }
496
Colin Cross16b23492016-01-06 14:41:07 -0800497 var globalSanitizers []string
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700498 var globalSanitizersDiag []string
499
Dan Willemsen8536d6b2018-10-07 20:54:34 -0700500 if ctx.Host() {
501 if !ctx.Windows() {
502 globalSanitizers = ctx.Config().SanitizeHost()
503 }
504 } else {
505 arches := ctx.Config().SanitizeDeviceArch()
506 if len(arches) == 0 || inList(ctx.Arch().ArchType.Name, arches) {
507 globalSanitizers = ctx.Config().SanitizeDevice()
508 globalSanitizersDiag = ctx.Config().SanitizeDeviceDiag()
Colin Cross16b23492016-01-06 14:41:07 -0800509 }
510 }
511
Colin Cross16b23492016-01-06 14:41:07 -0800512 if len(globalSanitizers) > 0 {
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000513 var found bool
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700514 if found, globalSanitizers = removeFromList("undefined", globalSanitizers); found && s.All_undefined == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400515 s.All_undefined = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000516 }
Colin Cross16b23492016-01-06 14:41:07 -0800517
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700518 if found, globalSanitizers = removeFromList("default-ub", globalSanitizers); found && s.Undefined == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400519 s.Undefined = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000520 }
521
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700522 if found, globalSanitizers = removeFromList("address", globalSanitizers); found && s.Address == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400523 s.Address = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000524 }
525
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700526 if found, globalSanitizers = removeFromList("thread", globalSanitizers); found && s.Thread == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400527 s.Thread = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000528 }
529
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700530 if found, globalSanitizers = removeFromList("fuzzer", globalSanitizers); found && s.Fuzzer == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400531 s.Fuzzer = proptools.BoolPtr(true)
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700532 }
533
534 if found, globalSanitizers = removeFromList("safe-stack", globalSanitizers); found && s.Safestack == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400535 s.Safestack = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000536 }
537
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700538 if found, globalSanitizers = removeFromList("cfi", globalSanitizers); found && s.Cfi == nil {
Colin Cross6510f912017-11-29 00:27:14 -0800539 if !ctx.Config().CFIDisabledForPath(ctx.ModuleDir()) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400540 s.Cfi = proptools.BoolPtr(true)
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700541 }
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700542 }
543
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700544 // Global integer_overflow builds do not support static libraries.
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700545 if found, globalSanitizers = removeFromList("integer_overflow", globalSanitizers); found && s.Integer_overflow == nil {
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700546 if !ctx.Config().IntegerOverflowDisabledForPath(ctx.ModuleDir()) && !ctx.static() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400547 s.Integer_overflow = proptools.BoolPtr(true)
Ivan Lozano5f595532017-07-13 14:46:05 -0700548 }
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700549 }
550
Kostya Kortchinskyd18ae5c2018-06-12 14:46:54 -0700551 if found, globalSanitizers = removeFromList("scudo", globalSanitizers); found && s.Scudo == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400552 s.Scudo = proptools.BoolPtr(true)
Kostya Kortchinskyd18ae5c2018-06-12 14:46:54 -0700553 }
554
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700555 if found, globalSanitizers = removeFromList("hwaddress", globalSanitizers); found && s.Hwaddress == nil {
Tomislav Novakf734f002023-08-22 10:51:44 -0700556 if !ctx.Config().HWASanDisabledForPath(ctx.ModuleDir()) {
557 s.Hwaddress = proptools.BoolPtr(true)
558 }
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700559 }
560
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000561 if found, globalSanitizers = removeFromList("writeonly", globalSanitizers); found && s.Writeonly == nil {
562 // Hwaddress and Address are set before, so we can check them here
563 // If they aren't explicitly set in the blueprint/SANITIZE_(HOST|TARGET), they would be nil instead of false
564 if s.Address == nil && s.Hwaddress == nil {
565 ctx.ModuleErrorf("writeonly modifier cannot be used without 'address' or 'hwaddress'")
566 }
Liz Kammerb2fc4702021-06-25 14:53:40 -0400567 s.Writeonly = proptools.BoolPtr(true)
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000568 }
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700569 if found, globalSanitizers = removeFromList("memtag_heap", globalSanitizers); found && s.Memtag_heap == nil {
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800570 if !ctx.Config().MemtagHeapDisabledForPath(ctx.ModuleDir()) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400571 s.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800572 }
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700573 }
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000574
Florian Mayerd8434a42022-08-31 20:57:03 +0000575 if found, globalSanitizers = removeFromList("memtag_stack", globalSanitizers); found && s.Memtag_stack == nil {
576 s.Memtag_stack = proptools.BoolPtr(true)
577 }
578
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200579 if found, globalSanitizers = removeFromList("memtag_globals", globalSanitizers); found && s.Memtag_globals == nil {
580 s.Memtag_globals = proptools.BoolPtr(true)
581 }
582
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000583 if len(globalSanitizers) > 0 {
584 ctx.ModuleErrorf("unknown global sanitizer option %s", globalSanitizers[0])
585 }
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700586
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700587 // Global integer_overflow builds do not support static library diagnostics.
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700588 if found, globalSanitizersDiag = removeFromList("integer_overflow", globalSanitizersDiag); found &&
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700589 s.Diag.Integer_overflow == nil && Bool(s.Integer_overflow) && !ctx.static() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400590 s.Diag.Integer_overflow = proptools.BoolPtr(true)
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700591 }
592
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700593 if found, globalSanitizersDiag = removeFromList("cfi", globalSanitizersDiag); found &&
594 s.Diag.Cfi == nil && Bool(s.Cfi) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400595 s.Diag.Cfi = proptools.BoolPtr(true)
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700596 }
597
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800598 if found, globalSanitizersDiag = removeFromList("memtag_heap", globalSanitizersDiag); found &&
599 s.Diag.Memtag_heap == nil && Bool(s.Memtag_heap) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400600 s.Diag.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800601 }
602
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700603 if len(globalSanitizersDiag) > 0 {
604 ctx.ModuleErrorf("unknown global sanitizer diagnostics option %s", globalSanitizersDiag[0])
605 }
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700606 }
Colin Cross3c344ef2016-07-18 15:44:56 -0700607
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800608 // Enable Memtag for all components in the include paths (for Aarch64 only)
Colin Cross88a029f2022-06-23 14:51:20 -0700609 if ctx.Arch().ArchType == android.Arm64 && ctx.toolchain().Bionic() {
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800610 if ctx.Config().MemtagHeapSyncEnabledForPath(ctx.ModuleDir()) {
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800611 if s.Memtag_heap == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400612 s.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800613 }
614 if s.Diag.Memtag_heap == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400615 s.Diag.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800616 }
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800617 } else if ctx.Config().MemtagHeapAsyncEnabledForPath(ctx.ModuleDir()) {
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800618 if s.Memtag_heap == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400619 s.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800620 }
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800621 }
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700622 }
623
Hang Lua98aab92023-03-17 13:17:22 +0800624 // Enable HWASan for all components in the include paths (for Aarch64 only)
625 if s.Hwaddress == nil && ctx.Config().HWASanEnabledForPath(ctx.ModuleDir()) &&
626 ctx.Arch().ArchType == android.Arm64 && ctx.toolchain().Bionic() {
627 s.Hwaddress = proptools.BoolPtr(true)
628 }
629
Elvis Chien9c993542021-06-25 01:15:17 +0800630 // Enable CFI for non-host components in the include paths
631 if s.Cfi == nil && ctx.Config().CFIEnabledForPath(ctx.ModuleDir()) && !ctx.Host() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400632 s.Cfi = proptools.BoolPtr(true)
Vishwath Mohan3af8ee02018-03-30 02:55:23 +0000633 if inList("cfi", ctx.Config().SanitizeDeviceDiag()) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400634 s.Diag.Cfi = proptools.BoolPtr(true)
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700635 }
636 }
637
Elliott Hughesda3a0712020-03-06 16:55:28 -0800638 // Is CFI actually enabled?
639 if !ctx.Config().EnableCFI() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400640 s.Cfi = nil
641 s.Diag.Cfi = nil
Vishwath Mohan1b017a72017-01-19 13:54:55 -0800642 }
643
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700644 // HWASan requires AArch64 hardware feature (top-byte-ignore).
Colin Cross88a029f2022-06-23 14:51:20 -0700645 if ctx.Arch().ArchType != android.Arm64 || !ctx.toolchain().Bionic() {
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700646 s.Hwaddress = nil
647 }
648
Elliott Hughese4793bc2023-02-09 21:15:47 +0000649 // SCS is only implemented on AArch64/riscv64.
650 if (ctx.Arch().ArchType != android.Arm64 && ctx.Arch().ArchType != android.Riscv64) || !ctx.toolchain().Bionic() {
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800651 s.Scs = nil
652 }
653
Ivan Lozano62cd0382021-11-01 10:27:54 -0400654 // Memtag_heap is only implemented on AArch64.
Florian Mayerd8434a42022-08-31 20:57:03 +0000655 // Memtag ABI is Android specific for now, so disable for host.
656 if ctx.Arch().ArchType != android.Arm64 || !ctx.toolchain().Bionic() || ctx.Host() {
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700657 s.Memtag_heap = nil
Florian Mayerd8434a42022-08-31 20:57:03 +0000658 s.Memtag_stack = nil
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200659 s.Memtag_globals = nil
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700660 }
661
Vishwath Mohan8f4fdd82017-04-20 07:42:52 -0700662 // Also disable CFI if ASAN is enabled.
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700663 if Bool(s.Address) || Bool(s.Hwaddress) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400664 s.Cfi = nil
665 s.Diag.Cfi = nil
Florian Mayerd8434a42022-08-31 20:57:03 +0000666 // HWASAN and ASAN win against MTE.
667 s.Memtag_heap = nil
668 s.Memtag_stack = nil
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200669 s.Memtag_globals = nil
Vishwath Mohan8f4fdd82017-04-20 07:42:52 -0700670 }
671
Colin Crossed12a042022-02-07 13:55:55 -0800672 // Disable sanitizers that depend on the UBSan runtime for windows/darwin builds.
673 if !ctx.Os().Linux() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400674 s.Cfi = nil
675 s.Diag.Cfi = nil
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700676 s.Misc_undefined = nil
677 s.Undefined = nil
678 s.All_undefined = nil
679 s.Integer_overflow = nil
Vishwath Mohane7128792017-11-17 11:08:10 -0800680 }
681
Colin Crossed12a042022-02-07 13:55:55 -0800682 // Disable CFI for musl
683 if ctx.toolchain().Musl() {
684 s.Cfi = nil
685 s.Diag.Cfi = nil
686 }
687
Colin Cross390fc742023-05-02 13:02:51 -0700688 // TODO(b/280478629): runtimes don't exist for musl arm64 yet.
689 if ctx.toolchain().Musl() && ctx.Arch().ArchType == android.Arm64 {
690 s.Address = nil
691 s.Hwaddress = nil
692 s.Thread = nil
693 s.Scudo = nil
694 s.Fuzzer = nil
695 s.Cfi = nil
696 s.Diag.Cfi = nil
697 s.Misc_undefined = nil
698 s.Undefined = nil
699 s.All_undefined = nil
700 s.Integer_overflow = nil
701 }
702
Vishwath Mohan9ccbba02018-05-28 13:54:48 -0700703 // Also disable CFI for VNDK variants of components
704 if ctx.isVndk() && ctx.useVndk() {
Justin Yun08270c62022-12-19 17:01:26 +0900705 s.Cfi = nil
706 s.Diag.Cfi = nil
Inseob Kimeec88e12020-01-22 11:11:29 +0900707 }
708
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700709 // HWASan ramdisk (which is built from recovery) goes over some bootloader limit.
Yifan Hong60e0cfb2020-10-21 15:17:56 -0700710 // Keep libc instrumented so that ramdisk / vendor_ramdisk / recovery can run hwasan-instrumented code if necessary.
711 if (ctx.inRamdisk() || ctx.inVendorRamdisk() || ctx.inRecovery()) && !strings.HasPrefix(ctx.ModuleDir(), "bionic/libc") {
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700712 s.Hwaddress = nil
713 }
714
Colin Cross3c344ef2016-07-18 15:44:56 -0700715 if ctx.staticBinary() {
716 s.Address = nil
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700717 s.Fuzzer = nil
Colin Cross3c344ef2016-07-18 15:44:56 -0700718 s.Thread = nil
Colin Cross16b23492016-01-06 14:41:07 -0800719 }
720
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700721 if Bool(s.All_undefined) {
722 s.Undefined = nil
723 }
724
Evgenii Stepanov0a8a0d02016-05-12 13:54:53 -0700725 if !ctx.toolchain().Is64Bit() {
726 // TSAN and SafeStack are not supported on 32-bit architectures
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700727 s.Thread = nil
728 s.Safestack = nil
Colin Cross16b23492016-01-06 14:41:07 -0800729 // TODO(ccross): error for compile_multilib = "32"?
730 }
731
Evgenii Stepanov76cee232017-01-27 15:44:44 -0800732 if ctx.Os() != android.Windows && (Bool(s.All_undefined) || Bool(s.Undefined) || Bool(s.Address) || Bool(s.Thread) ||
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700733 Bool(s.Fuzzer) || Bool(s.Safestack) || Bool(s.Cfi) || Bool(s.Integer_overflow) || len(s.Misc_undefined) > 0 ||
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200734 Bool(s.Scudo) || Bool(s.Hwaddress) || Bool(s.Scs) || Bool(s.Memtag_heap) || Bool(s.Memtag_stack) ||
735 Bool(s.Memtag_globals)) {
Colin Cross3c344ef2016-07-18 15:44:56 -0700736 sanitize.Properties.SanitizerEnabled = true
737 }
738
Kostya Kortchinskyd5275c82019-02-01 08:42:56 -0800739 // Disable Scudo if ASan or TSan is enabled, or if it's disabled globally.
740 if Bool(s.Address) || Bool(s.Thread) || Bool(s.Hwaddress) || ctx.Config().DisableScudo() {
Kostya Kortchinskyd18ae5c2018-06-12 14:46:54 -0700741 s.Scudo = nil
742 }
743
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700744 if Bool(s.Hwaddress) {
745 s.Address = nil
746 s.Thread = nil
747 }
Mitch Phillips5007c4a2022-03-02 01:25:22 +0000748
749 // TODO(b/131771163): CFI transiently depends on LTO, and thus Fuzzer is
750 // mutually incompatible.
751 if Bool(s.Fuzzer) {
752 s.Cfi = nil
753 }
Colin Cross16b23492016-01-06 14:41:07 -0800754}
755
Chih-Hung Hsieh3567e622018-11-15 14:01:36 -0800756func toDisableImplicitIntegerChange(flags []string) bool {
757 // Returns true if any flag is fsanitize*integer, and there is
758 // no explicit flag about sanitize=implicit-integer-sign-change.
759 for _, f := range flags {
760 if strings.Contains(f, "sanitize=implicit-integer-sign-change") {
761 return false
762 }
763 }
764 for _, f := range flags {
765 if strings.HasPrefix(f, "-fsanitize") && strings.Contains(f, "integer") {
766 return true
767 }
768 }
769 return false
770}
771
Yabin Cuidb7dda82020-11-30 15:47:45 -0800772func toDisableUnsignedShiftBaseChange(flags []string) bool {
773 // Returns true if any flag is fsanitize*integer, and there is
774 // no explicit flag about sanitize=unsigned-shift-base.
775 for _, f := range flags {
776 if strings.Contains(f, "sanitize=unsigned-shift-base") {
777 return false
778 }
779 }
780 for _, f := range flags {
781 if strings.HasPrefix(f, "-fsanitize") && strings.Contains(f, "integer") {
782 return true
783 }
784 }
785 return false
786}
787
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400788func (s *sanitize) flags(ctx ModuleContext, flags Flags) Flags {
789 if !s.Properties.SanitizerEnabled && !s.Properties.UbsanRuntimeDep {
Colin Cross16b23492016-01-06 14:41:07 -0800790 return flags
791 }
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400792 sanProps := &s.Properties.SanitizeMutated
Colin Cross16b23492016-01-06 14:41:07 -0800793
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400794 if Bool(sanProps.Address) {
Colin Cross635c3b02016-05-18 15:37:25 -0700795 if ctx.Arch().ArchType == android.Arm {
Colin Cross16b23492016-01-06 14:41:07 -0800796 // Frame pointer based unwinder in ASan requires ARM frame setup.
797 // TODO: put in flags?
798 flags.RequiredInstructionSet = "arm"
799 }
Colin Cross4af21ed2019-11-04 09:37:55 -0800800 flags.Local.CFlags = append(flags.Local.CFlags, asanCflags...)
801 flags.Local.LdFlags = append(flags.Local.LdFlags, asanLdflags...)
Colin Cross16b23492016-01-06 14:41:07 -0800802
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400803 if Bool(sanProps.Writeonly) {
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000804 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", "-asan-instrument-reads=0")
805 }
806
Colin Cross16b23492016-01-06 14:41:07 -0800807 if ctx.Host() {
808 // -nodefaultlibs (provided with libc++) prevents the driver from linking
809 // libraries needed with -fsanitize=address. http://b/18650275 (WAI)
Colin Cross4af21ed2019-11-04 09:37:55 -0800810 flags.Local.LdFlags = append(flags.Local.LdFlags, "-Wl,--no-as-needed")
Colin Cross16b23492016-01-06 14:41:07 -0800811 } else {
Colin Cross4af21ed2019-11-04 09:37:55 -0800812 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", "-asan-globals=0")
Jiyong Parka2aca282019-02-02 13:13:38 +0900813 if ctx.bootstrap() {
814 flags.DynamicLinker = "/system/bin/bootstrap/linker_asan"
815 } else {
816 flags.DynamicLinker = "/system/bin/linker_asan"
817 }
Colin Cross16b23492016-01-06 14:41:07 -0800818 if flags.Toolchain.Is64Bit() {
819 flags.DynamicLinker += "64"
820 }
821 }
Colin Cross16b23492016-01-06 14:41:07 -0800822 }
823
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400824 if Bool(sanProps.Hwaddress) {
Colin Cross4af21ed2019-11-04 09:37:55 -0800825 flags.Local.CFlags = append(flags.Local.CFlags, hwasanCflags...)
Yi Kong286abc62021-11-04 16:14:14 +0800826
827 for _, flag := range hwasanCommonflags {
828 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", flag)
829 }
830 for _, flag := range hwasanCommonflags {
831 flags.Local.LdFlags = append(flags.Local.LdFlags, "-Wl,-mllvm,"+flag)
832 }
833
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400834 if Bool(sanProps.Writeonly) {
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000835 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", "-hwasan-instrument-reads=0")
836 }
Florian Mayer95cd6db2023-03-23 17:48:07 -0700837 if !ctx.staticBinary() && !ctx.Host() {
838 if ctx.bootstrap() {
839 flags.DynamicLinker = "/system/bin/bootstrap/linker_hwasan64"
840 } else {
841 flags.DynamicLinker = "/system/bin/linker_hwasan64"
842 }
843 }
Yabin Cui6be405e2017-10-19 15:52:11 -0700844 }
845
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400846 if Bool(sanProps.Fuzzer) {
Colin Cross4af21ed2019-11-04 09:37:55 -0800847 flags.Local.CFlags = append(flags.Local.CFlags, "-fsanitize=fuzzer-no-link")
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700848
Mitch Phillips5007c4a2022-03-02 01:25:22 +0000849 // TODO(b/131771163): LTO and Fuzzer support is mutually incompatible.
850 _, flags.Local.LdFlags = removeFromList("-flto", flags.Local.LdFlags)
851 _, flags.Local.CFlags = removeFromList("-flto", flags.Local.CFlags)
852 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fno-lto")
853 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-lto")
854
Mitch Phillipsb8e593d2019-10-09 17:18:59 -0700855 // TODO(b/142430592): Upstream linker scripts for sanitizer runtime libraries
856 // discard the sancov_lowest_stack symbol, because it's emulated TLS (and thus
857 // doesn't match the linker script due to the "__emutls_v." prefix).
Colin Cross4af21ed2019-11-04 09:37:55 -0800858 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fno-sanitize-coverage=stack-depth")
859 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-coverage=stack-depth")
Mitch Phillipsb8e593d2019-10-09 17:18:59 -0700860
Mitch Phillipsb9b3e792019-08-28 12:41:07 -0700861 // Disable fortify for fuzzing builds. Generally, we'll be building with
862 // UBSan or ASan here and the fortify checks pollute the stack traces.
Colin Cross4af21ed2019-11-04 09:37:55 -0800863 flags.Local.CFlags = append(flags.Local.CFlags, "-U_FORTIFY_SOURCE")
Mitch Phillips734b4cb2019-12-10 08:44:52 -0800864
865 // Build fuzzer-sanitized libraries with an $ORIGIN DT_RUNPATH. Android's
866 // linker uses DT_RUNPATH, not DT_RPATH. When we deploy cc_fuzz targets and
867 // their libraries to /data/fuzz/<arch>/lib, any transient shared library gets
868 // the DT_RUNPATH from the shared library above it, and not the executable,
869 // meaning that the lookup falls back to the system. Adding the $ORIGIN to the
870 // DT_RUNPATH here means that transient shared libraries can be found
871 // colocated with their parents.
872 flags.Local.LdFlags = append(flags.Local.LdFlags, `-Wl,-rpath,\$$ORIGIN`)
Colin Cross16b23492016-01-06 14:41:07 -0800873 }
874
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400875 if Bool(sanProps.Cfi) {
Evgenii Stepanov7ebf9fa2017-01-20 14:13:06 -0800876 if ctx.Arch().ArchType == android.Arm {
877 // __cfi_check needs to be built as Thumb (see the code in linker_cfi.cpp). LLVM is not set up
878 // to do this on a function basis, so force Thumb on the entire module.
879 flags.RequiredInstructionSet = "thumb"
880 }
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000881
Colin Cross4af21ed2019-11-04 09:37:55 -0800882 flags.Local.CFlags = append(flags.Local.CFlags, cfiCflags...)
883 flags.Local.AsFlags = append(flags.Local.AsFlags, cfiAsflags...)
AdityaK6e6f5222024-04-03 14:53:22 -0700884 flags.CFlagsDeps = append(flags.CFlagsDeps, android.PathForSource(ctx, cfiBlocklistPath + "/" + cfiBlocklistFilename))
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400885 if Bool(s.Properties.Sanitize.Config.Cfi_assembly_support) {
Trevor Radcliffe391a25d2023-03-22 20:22:27 +0000886 flags.Local.CFlags = append(flags.Local.CFlags, cfiAssemblySupportFlag)
Cindy Zhou8cd45de2020-11-16 08:41:00 -0800887 }
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000888 // Only append the default visibility flag if -fvisibility has not already been set
889 // to hidden.
Colin Cross4af21ed2019-11-04 09:37:55 -0800890 if !inList("-fvisibility=hidden", flags.Local.CFlags) {
891 flags.Local.CFlags = append(flags.Local.CFlags, "-fvisibility=default")
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000892 }
Colin Cross4af21ed2019-11-04 09:37:55 -0800893 flags.Local.LdFlags = append(flags.Local.LdFlags, cfiLdflags...)
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000894
895 if ctx.staticBinary() {
Colin Cross4af21ed2019-11-04 09:37:55 -0800896 _, flags.Local.CFlags = removeFromList("-fsanitize-cfi-cross-dso", flags.Local.CFlags)
897 _, flags.Local.LdFlags = removeFromList("-fsanitize-cfi-cross-dso", flags.Local.LdFlags)
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000898 }
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700899 }
900
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400901 if Bool(sanProps.Memtag_stack) {
Florian Mayerd8434a42022-08-31 20:57:03 +0000902 flags.Local.CFlags = append(flags.Local.CFlags, memtagStackCommonFlags...)
903 flags.Local.AsFlags = append(flags.Local.AsFlags, memtagStackCommonFlags...)
904 flags.Local.LdFlags = append(flags.Local.LdFlags, memtagStackCommonFlags...)
905 }
906
Mitch Phillips92d19fa2023-06-01 14:23:09 +0200907 if (Bool(sanProps.Memtag_heap) || Bool(sanProps.Memtag_stack) || Bool(sanProps.Memtag_globals)) && ctx.binary() {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400908 if Bool(sanProps.Diag.Memtag_heap) {
Florian Mayerd8434a42022-08-31 20:57:03 +0000909 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fsanitize-memtag-mode=sync")
910 } else {
911 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fsanitize-memtag-mode=async")
912 }
913 }
914
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400915 if Bool(sanProps.Integer_overflow) {
Colin Cross4af21ed2019-11-04 09:37:55 -0800916 flags.Local.CFlags = append(flags.Local.CFlags, intOverflowCflags...)
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700917 }
918
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400919 if len(s.Properties.Sanitizers) > 0 {
920 sanitizeArg := "-fsanitize=" + strings.Join(s.Properties.Sanitizers, ",")
Colin Cross4af21ed2019-11-04 09:37:55 -0800921 flags.Local.CFlags = append(flags.Local.CFlags, sanitizeArg)
922 flags.Local.AsFlags = append(flags.Local.AsFlags, sanitizeArg)
Colin Cross234b01d2022-02-07 13:49:03 -0800923 flags.Local.LdFlags = append(flags.Local.LdFlags, sanitizeArg)
924
Colin Crossed12a042022-02-07 13:55:55 -0800925 if ctx.toolchain().Bionic() || ctx.toolchain().Musl() {
926 // Bionic and musl sanitizer runtimes have already been added as dependencies so that
927 // the right variant of the runtime will be used (with the "-android" or "-musl"
928 // suffixes), so don't let clang the runtime library.
Trevor Radcliffeda64d912023-08-02 20:24:29 +0000929 flags.Local.LdFlags = append(flags.Local.LdFlags, noSanitizeLinkRuntimeFlag)
Colin Cross234b01d2022-02-07 13:49:03 -0800930 } else {
Evgenii Stepanov76cee232017-01-27 15:44:44 -0800931 // Host sanitizers only link symbols in the final executable, so
932 // there will always be undefined symbols in intermediate libraries.
Colin Cross4af21ed2019-11-04 09:37:55 -0800933 _, flags.Global.LdFlags = removeFromList("-Wl,--no-undefined", flags.Global.LdFlags)
Colin Cross6c18d002022-06-02 15:11:50 -0700934 }
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500935
Colin Cross6c18d002022-06-02 15:11:50 -0700936 if !ctx.toolchain().Bionic() {
937 // non-Bionic toolchain prebuilts are missing UBSan's vptr and function san.
938 // Musl toolchain prebuilts have vptr and function sanitizers, but enabling them
939 // implicitly enables RTTI which causes RTTI mismatch issues with dependencies.
940
Colin Cross234b01d2022-02-07 13:49:03 -0800941 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize=vptr,function")
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500942 }
943
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400944 if Bool(sanProps.Fuzzer) {
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700945 // When fuzzing, we wish to crash with diagnostics on any bug.
Colin Cross4af21ed2019-11-04 09:37:55 -0800946 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-trap=all", "-fno-sanitize-recover=all")
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700947 } else if ctx.Host() {
Trevor Radcliffe4f95ee92023-01-19 16:02:47 +0000948 flags.Local.CFlags = append(flags.Local.CFlags, hostOnlySanitizeFlags...)
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700949 } else {
Trevor Radcliffe4f95ee92023-01-19 16:02:47 +0000950 flags.Local.CFlags = append(flags.Local.CFlags, deviceOnlySanitizeFlags...)
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700951 }
Evgenii Stepanov59012812022-06-24 11:09:18 -0700952
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400953 if enableMinimalRuntime(s) {
Evgenii Stepanov59012812022-06-24 11:09:18 -0700954 flags.Local.CFlags = append(flags.Local.CFlags, strings.Join(minimalRuntimeFlags, " "))
955 }
956
Chih-Hung Hsieh3567e622018-11-15 14:01:36 -0800957 // http://b/119329758, Android core does not boot up with this sanitizer yet.
Colin Cross4af21ed2019-11-04 09:37:55 -0800958 if toDisableImplicitIntegerChange(flags.Local.CFlags) {
959 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize=implicit-integer-sign-change")
Chih-Hung Hsieh3567e622018-11-15 14:01:36 -0800960 }
Yabin Cuidb7dda82020-11-30 15:47:45 -0800961 // http://b/171275751, Android doesn't build with this sanitizer yet.
962 if toDisableUnsignedShiftBaseChange(flags.Local.CFlags) {
963 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize=unsigned-shift-base")
964 }
Colin Cross16b23492016-01-06 14:41:07 -0800965 }
966
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400967 if len(s.Properties.DiagSanitizers) > 0 {
968 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-trap="+strings.Join(s.Properties.DiagSanitizers, ","))
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700969 }
970 // FIXME: enable RTTI if diag + (cfi or vptr)
971
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400972 if s.Properties.Sanitize.Recover != nil {
Colin Cross4af21ed2019-11-04 09:37:55 -0800973 flags.Local.CFlags = append(flags.Local.CFlags, "-fsanitize-recover="+
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400974 strings.Join(s.Properties.Sanitize.Recover, ","))
Andreas Gampe97071162017-05-08 13:15:23 -0700975 }
976
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400977 if s.Properties.Sanitize.Diag.No_recover != nil {
Colin Cross4af21ed2019-11-04 09:37:55 -0800978 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-recover="+
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400979 strings.Join(s.Properties.Sanitize.Diag.No_recover, ","))
Ivan Lozano7929bba2018-12-12 09:36:31 -0800980 }
981
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400982 blocklist := android.OptionalPathForModuleSrc(ctx, s.Properties.Sanitize.Blocklist)
Pirama Arumuga Nainar6c4ccca2020-07-27 11:49:51 -0700983 if blocklist.Valid() {
Trevor Radcliffeded095c2023-06-12 19:18:28 +0000984 flags.Local.CFlags = append(flags.Local.CFlags, sanitizeIgnorelistPrefix+blocklist.String())
Pirama Arumuga Nainar6c4ccca2020-07-27 11:49:51 -0700985 flags.CFlagsDeps = append(flags.CFlagsDeps, blocklist.Path())
986 }
987
Colin Cross16b23492016-01-06 14:41:07 -0800988 return flags
989}
990
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400991func (s *sanitize) AndroidMkEntries(ctx AndroidMkContext, entries *android.AndroidMkEntries) {
Jiyong Park1d1119f2019-07-29 21:27:18 +0900992 // Add a suffix for cfi/hwasan/scs-enabled static/header libraries to allow surfacing
993 // both the sanitized and non-sanitized variants to make without a name conflict.
Colin Crossd80cbca2020-02-24 12:01:37 -0800994 if entries.Class == "STATIC_LIBRARIES" || entries.Class == "HEADER_LIBRARIES" {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400995 if Bool(s.Properties.SanitizeMutated.Cfi) {
Colin Crossd80cbca2020-02-24 12:01:37 -0800996 entries.SubName += ".cfi"
Jiyong Park1d1119f2019-07-29 21:27:18 +0900997 }
Liz Kammer2c1d6aa2022-10-03 15:07:37 -0400998 if Bool(s.Properties.SanitizeMutated.Hwaddress) {
Colin Crossd80cbca2020-02-24 12:01:37 -0800999 entries.SubName += ".hwasan"
Jiyong Park1d1119f2019-07-29 21:27:18 +09001000 }
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001001 if Bool(s.Properties.SanitizeMutated.Scs) {
Colin Crossd80cbca2020-02-24 12:01:37 -08001002 entries.SubName += ".scs"
Jiyong Park1d1119f2019-07-29 21:27:18 +09001003 }
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -08001004 }
Colin Cross8ff9ef42017-05-08 13:44:11 -07001005}
1006
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001007func (s *sanitize) inSanitizerDir() bool {
1008 return s.Properties.InSanitizerDir
Colin Cross30d5f512016-05-03 18:02:42 -07001009}
1010
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001011// getSanitizerBoolPtr returns the SanitizerTypes associated bool pointer from SanitizeProperties.
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001012func (s *sanitize) getSanitizerBoolPtr(t SanitizerType) *bool {
Vishwath Mohan95229302017-08-11 00:53:16 +00001013 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001014 case Asan:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001015 return s.Properties.SanitizeMutated.Address
Tri Vo6eafc362021-04-01 11:29:09 -07001016 case Hwasan:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001017 return s.Properties.SanitizeMutated.Hwaddress
Vishwath Mohan95229302017-08-11 00:53:16 +00001018 case tsan:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001019 return s.Properties.SanitizeMutated.Thread
Vishwath Mohan95229302017-08-11 00:53:16 +00001020 case intOverflow:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001021 return s.Properties.SanitizeMutated.Integer_overflow
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001022 case cfi:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001023 return s.Properties.SanitizeMutated.Cfi
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -08001024 case scs:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001025 return s.Properties.SanitizeMutated.Scs
Ivan Lozano62cd0382021-11-01 10:27:54 -04001026 case Memtag_heap:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001027 return s.Properties.SanitizeMutated.Memtag_heap
Florian Mayerd8434a42022-08-31 20:57:03 +00001028 case Memtag_stack:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001029 return s.Properties.SanitizeMutated.Memtag_stack
Mitch Phillips92d19fa2023-06-01 14:23:09 +02001030 case Memtag_globals:
1031 return s.Properties.SanitizeMutated.Memtag_globals
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001032 case Fuzzer:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001033 return s.Properties.SanitizeMutated.Fuzzer
Vishwath Mohan95229302017-08-11 00:53:16 +00001034 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001035 panic(fmt.Errorf("unknown SanitizerType %d", t))
Vishwath Mohan95229302017-08-11 00:53:16 +00001036 }
1037}
1038
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001039// isUnsanitizedVariant returns true if no sanitizers are enabled.
Dan Albert7d1eecf2018-01-19 12:30:45 -08001040func (sanitize *sanitize) isUnsanitizedVariant() bool {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001041 return !sanitize.isSanitizerEnabled(Asan) &&
Tri Vo6eafc362021-04-01 11:29:09 -07001042 !sanitize.isSanitizerEnabled(Hwasan) &&
Dan Albert7d1eecf2018-01-19 12:30:45 -08001043 !sanitize.isSanitizerEnabled(tsan) &&
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -08001044 !sanitize.isSanitizerEnabled(cfi) &&
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -07001045 !sanitize.isSanitizerEnabled(scs) &&
Ivan Lozano62cd0382021-11-01 10:27:54 -04001046 !sanitize.isSanitizerEnabled(Memtag_heap) &&
Florian Mayerd8434a42022-08-31 20:57:03 +00001047 !sanitize.isSanitizerEnabled(Memtag_stack) &&
Mitch Phillips92d19fa2023-06-01 14:23:09 +02001048 !sanitize.isSanitizerEnabled(Memtag_globals) &&
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001049 !sanitize.isSanitizerEnabled(Fuzzer)
Dan Albert7d1eecf2018-01-19 12:30:45 -08001050}
1051
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001052// isVariantOnProductionDevice returns true if variant is for production devices (no non-production sanitizers enabled).
Jayant Chowdharyb7e08ca2018-05-10 15:29:24 -07001053func (sanitize *sanitize) isVariantOnProductionDevice() bool {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001054 return !sanitize.isSanitizerEnabled(Asan) &&
Tri Vo6eafc362021-04-01 11:29:09 -07001055 !sanitize.isSanitizerEnabled(Hwasan) &&
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -07001056 !sanitize.isSanitizerEnabled(tsan) &&
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001057 !sanitize.isSanitizerEnabled(Fuzzer)
Jayant Chowdharyb7e08ca2018-05-10 15:29:24 -07001058}
1059
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001060func (sanitize *sanitize) SetSanitizer(t SanitizerType, b bool) {
Liz Kammerb2fc4702021-06-25 14:53:40 -04001061 bPtr := proptools.BoolPtr(b)
1062 if !b {
1063 bPtr = nil
1064 }
Colin Cross16b23492016-01-06 14:41:07 -08001065 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001066 case Asan:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001067 sanitize.Properties.SanitizeMutated.Address = bPtr
Florian Mayer1bda2462022-09-29 15:48:08 -07001068 // For ASAN variant, we need to disable Memtag_stack
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001069 sanitize.Properties.SanitizeMutated.Memtag_stack = nil
Mitch Phillips92d19fa2023-06-01 14:23:09 +02001070 sanitize.Properties.SanitizeMutated.Memtag_globals = nil
Tri Vo6eafc362021-04-01 11:29:09 -07001071 case Hwasan:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001072 sanitize.Properties.SanitizeMutated.Hwaddress = bPtr
Florian Mayer1bda2462022-09-29 15:48:08 -07001073 // For HWAsan variant, we need to disable Memtag_stack
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001074 sanitize.Properties.SanitizeMutated.Memtag_stack = nil
Mitch Phillips92d19fa2023-06-01 14:23:09 +02001075 sanitize.Properties.SanitizeMutated.Memtag_globals = nil
Colin Cross16b23492016-01-06 14:41:07 -08001076 case tsan:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001077 sanitize.Properties.SanitizeMutated.Thread = bPtr
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -07001078 case intOverflow:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001079 sanitize.Properties.SanitizeMutated.Integer_overflow = bPtr
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001080 case cfi:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001081 sanitize.Properties.SanitizeMutated.Cfi = bPtr
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -08001082 case scs:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001083 sanitize.Properties.SanitizeMutated.Scs = bPtr
Ivan Lozano62cd0382021-11-01 10:27:54 -04001084 case Memtag_heap:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001085 sanitize.Properties.SanitizeMutated.Memtag_heap = bPtr
Florian Mayerd8434a42022-08-31 20:57:03 +00001086 case Memtag_stack:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001087 sanitize.Properties.SanitizeMutated.Memtag_stack = bPtr
Florian Mayer1bda2462022-09-29 15:48:08 -07001088 // We do not need to disable ASAN or HWASan here, as there is no Memtag_stack variant.
Mitch Phillips92d19fa2023-06-01 14:23:09 +02001089 case Memtag_globals:
1090 sanitize.Properties.Sanitize.Memtag_globals = bPtr
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001091 case Fuzzer:
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001092 sanitize.Properties.SanitizeMutated.Fuzzer = bPtr
Colin Cross16b23492016-01-06 14:41:07 -08001093 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001094 panic(fmt.Errorf("unknown SanitizerType %d", t))
Colin Cross16b23492016-01-06 14:41:07 -08001095 }
1096 if b {
1097 sanitize.Properties.SanitizerEnabled = true
1098 }
1099}
1100
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001101// Check if the sanitizer is explicitly disabled (as opposed to nil by
1102// virtue of not being set).
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001103func (sanitize *sanitize) isSanitizerExplicitlyDisabled(t SanitizerType) bool {
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001104 if sanitize == nil {
1105 return false
1106 }
1107
1108 sanitizerVal := sanitize.getSanitizerBoolPtr(t)
1109 return sanitizerVal != nil && *sanitizerVal == false
1110}
1111
1112// There isn't an analog of the method above (ie:isSanitizerExplicitlyEnabled)
1113// because enabling a sanitizer either directly (via the blueprint) or
1114// indirectly (via a mutator) sets the bool ptr to true, and you can't
1115// distinguish between the cases. It isn't needed though - both cases can be
1116// treated identically.
Liz Kammerba23cb62023-09-26 16:48:04 -04001117func (s *sanitize) isSanitizerEnabled(t SanitizerType) bool {
1118 if s == nil {
1119 return false
1120 }
1121 if proptools.Bool(s.Properties.SanitizeMutated.Never) {
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001122 return false
1123 }
1124
Liz Kammerba23cb62023-09-26 16:48:04 -04001125 sanitizerVal := s.getSanitizerBoolPtr(t)
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001126 return sanitizerVal != nil && *sanitizerVal == true
1127}
1128
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001129// IsSanitizableDependencyTag returns true if the dependency tag is sanitizable.
1130func IsSanitizableDependencyTag(tag blueprint.DependencyTag) bool {
Colin Cross6e511a92020-07-27 21:26:48 -07001131 switch t := tag.(type) {
1132 case dependencyTag:
1133 return t == reuseObjTag || t == objDepTag
1134 case libraryDependencyTag:
1135 return true
1136 default:
1137 return false
1138 }
Colin Cross6b753602018-06-21 13:03:07 -07001139}
1140
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001141func (m *Module) SanitizableDepTagChecker() SantizableDependencyTagChecker {
1142 return IsSanitizableDependencyTag
1143}
1144
Inseob Kimc42f2f22020-07-29 20:32:10 +09001145// Determines if the current module is a static library going to be captured
1146// as vendor snapshot. Such modules must create both cfi and non-cfi variants,
1147// except for ones which explicitly disable cfi.
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001148func needsCfiForVendorSnapshot(mctx android.BaseModuleContext) bool {
Justin Yun8814fc52022-12-15 21:45:35 +09001149 if inList("hwaddress", mctx.Config().SanitizeDevice()) {
1150 // cfi will not be built if SANITIZE_TARGET=hwaddress is set
1151 return false
1152 }
1153
Kiyoung Kim48f37782021-07-07 12:42:39 +09001154 if snapshot.IsVendorProprietaryModule(mctx) {
Inseob Kimc42f2f22020-07-29 20:32:10 +09001155 return false
1156 }
1157
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001158 c := mctx.Module().(PlatformSanitizeable)
Inseob Kimc42f2f22020-07-29 20:32:10 +09001159
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001160 if !c.InVendor() {
Inseob Kimc42f2f22020-07-29 20:32:10 +09001161 return false
1162 }
1163
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001164 if !c.StaticallyLinked() {
Inseob Kimc42f2f22020-07-29 20:32:10 +09001165 return false
1166 }
1167
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001168 if c.IsPrebuilt() {
Inseob Kimc42f2f22020-07-29 20:32:10 +09001169 return false
1170 }
1171
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001172 if !c.SanitizerSupported(cfi) {
1173 return false
1174 }
1175
1176 return c.SanitizePropDefined() &&
1177 !c.SanitizeNever() &&
1178 !c.IsSanitizerExplicitlyDisabled(cfi)
Inseob Kimc42f2f22020-07-29 20:32:10 +09001179}
1180
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001181type sanitizerSplitMutator struct {
1182 sanitizer SanitizerType
1183}
1184
1185// If an APEX is sanitized or not depends on whether it contains at least one
1186// sanitized module. Transition mutators cannot propagate information up the
1187// dependency graph this way, so we need an auxiliary mutator to do so.
1188func (s *sanitizerSplitMutator) markSanitizableApexesMutator(ctx android.TopDownMutatorContext) {
1189 if sanitizeable, ok := ctx.Module().(Sanitizeable); ok {
1190 enabled := sanitizeable.IsSanitizerEnabled(ctx.Config(), s.sanitizer.name())
1191 ctx.VisitDirectDeps(func(dep android.Module) {
Ivan Lozano5467a392023-08-23 14:20:25 -04001192 if c, ok := dep.(PlatformSanitizeable); ok && c.IsSanitizerEnabled(s.sanitizer) {
Inseob Kimc42f2f22020-07-29 20:32:10 +09001193 enabled = true
Inseob Kimc42f2f22020-07-29 20:32:10 +09001194 }
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001195 })
1196
1197 if enabled {
1198 sanitizeable.EnableSanitizer(s.sanitizer.name())
1199 }
1200 }
1201}
1202
1203func (s *sanitizerSplitMutator) Split(ctx android.BaseModuleContext) []string {
1204 if c, ok := ctx.Module().(PlatformSanitizeable); ok && c.SanitizePropDefined() {
1205 if s.sanitizer == cfi && needsCfiForVendorSnapshot(ctx) {
1206 return []string{"", s.sanitizer.variationName()}
1207 }
1208
1209 // If the given sanitizer is not requested in the .bp file for a module, it
1210 // won't automatically build the sanitized variation.
1211 if !c.IsSanitizerEnabled(s.sanitizer) {
1212 return []string{""}
1213 }
1214
1215 if c.Binary() {
1216 // If a sanitizer is enabled for a binary, we do not build the version
1217 // without the sanitizer
1218 return []string{s.sanitizer.variationName()}
1219 } else if c.StaticallyLinked() || c.Header() {
1220 // For static libraries, we build both versions. Some Make modules
1221 // apparently depend on this behavior.
1222 return []string{"", s.sanitizer.variationName()}
1223 } else {
1224 // We only build the requested variation of dynamic libraries
1225 return []string{s.sanitizer.variationName()}
1226 }
1227 }
1228
1229 if _, ok := ctx.Module().(JniSanitizeable); ok {
1230 // TODO: this should call into JniSanitizable.IsSanitizerEnabledForJni but
1231 // that is short-circuited for now
1232 return []string{""}
1233 }
1234
1235 // If an APEX has a sanitized dependency, we build the APEX in the sanitized
1236 // variation. This is useful because such APEXes require extra dependencies.
1237 if sanitizeable, ok := ctx.Module().(Sanitizeable); ok {
1238 enabled := sanitizeable.IsSanitizerEnabled(ctx.Config(), s.sanitizer.name())
1239 if enabled {
1240 return []string{s.sanitizer.variationName()}
1241 } else {
1242 return []string{""}
1243 }
1244 }
1245
Ivan Lozano5467a392023-08-23 14:20:25 -04001246 if c, ok := ctx.Module().(LinkableInterface); ok {
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001247 // Check if it's a snapshot module supporting sanitizer
Ivan Lozano5467a392023-08-23 14:20:25 -04001248 if c.IsSnapshotSanitizer() {
1249 if c.IsSnapshotSanitizerAvailable(s.sanitizer) {
Justin Yun08270c62022-12-19 17:01:26 +09001250 return []string{"", s.sanitizer.variationName()}
1251 } else {
1252 return []string{""}
1253 }
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001254 }
1255 }
1256
1257 return []string{""}
1258}
1259
1260func (s *sanitizerSplitMutator) OutgoingTransition(ctx android.OutgoingTransitionContext, sourceVariation string) string {
1261 if c, ok := ctx.Module().(PlatformSanitizeable); ok {
1262 if !c.SanitizableDepTagChecker()(ctx.DepTag()) {
1263 // If the dependency is through a non-sanitizable tag, use the
1264 // non-sanitized variation
1265 return ""
1266 }
1267
1268 return sourceVariation
1269 } else if _, ok := ctx.Module().(JniSanitizeable); ok {
1270 // TODO: this should call into JniSanitizable.IsSanitizerEnabledForJni but
1271 // that is short-circuited for now
1272 return ""
1273 } else {
1274 // Otherwise, do not rock the boat.
1275 return sourceVariation
1276 }
1277}
1278
1279func (s *sanitizerSplitMutator) IncomingTransition(ctx android.IncomingTransitionContext, incomingVariation string) string {
1280 if d, ok := ctx.Module().(PlatformSanitizeable); ok {
Ivan Lozano5467a392023-08-23 14:20:25 -04001281 if dm, ok := ctx.Module().(LinkableInterface); ok {
1282 if dm.IsSnapshotSanitizerAvailable(s.sanitizer) {
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001283 return incomingVariation
Inseob Kimc42f2f22020-07-29 20:32:10 +09001284 }
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001285 }
1286
1287 if !d.SanitizePropDefined() ||
1288 d.SanitizeNever() ||
1289 d.IsSanitizerExplicitlyDisabled(s.sanitizer) ||
1290 !d.SanitizerSupported(s.sanitizer) {
1291 // If a module opts out of a sanitizer, use its non-sanitized variation
1292 return ""
1293 }
1294
1295 // Binaries are always built in the variation they requested.
1296 if d.Binary() {
1297 if d.IsSanitizerEnabled(s.sanitizer) {
1298 return s.sanitizer.variationName()
1299 } else {
1300 return ""
Muhammad Haseeb Ahmad7e744052022-03-25 22:50:53 +00001301 }
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001302 }
1303
1304 // If a shared library requests to be sanitized, it will be built for that
1305 // sanitizer. Otherwise, some sanitizers propagate through shared library
1306 // dependency edges, some do not.
1307 if !d.StaticallyLinked() && !d.Header() {
1308 if d.IsSanitizerEnabled(s.sanitizer) {
1309 return s.sanitizer.variationName()
1310 }
1311
Liz Kammerfd8a49f2022-10-31 10:31:11 -04001312 // Some sanitizers do not propagate to shared dependencies
1313 if !s.sanitizer.shouldPropagateToSharedLibraryDeps() {
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001314 return ""
1315 }
1316 }
1317
1318 // Static and header libraries inherit whether they are sanitized from the
1319 // module they are linked into
1320 return incomingVariation
1321 } else if d, ok := ctx.Module().(Sanitizeable); ok {
1322 // If an APEX contains a sanitized module, it will be built in the variation
1323 // corresponding to that sanitizer.
1324 enabled := d.IsSanitizerEnabled(ctx.Config(), s.sanitizer.name())
1325 if enabled {
1326 return s.sanitizer.variationName()
1327 }
1328
1329 return incomingVariation
1330 }
1331
1332 return ""
1333}
1334
1335func (s *sanitizerSplitMutator) Mutate(mctx android.BottomUpMutatorContext, variationName string) {
1336 sanitizerVariation := variationName == s.sanitizer.variationName()
1337
1338 if c, ok := mctx.Module().(PlatformSanitizeable); ok && c.SanitizePropDefined() {
1339 sanitizerEnabled := c.IsSanitizerEnabled(s.sanitizer)
1340
1341 oneMakeVariation := false
1342 if c.StaticallyLinked() || c.Header() {
1343 if s.sanitizer != cfi && s.sanitizer != scs && s.sanitizer != Hwasan {
1344 // These sanitizers export only one variation to Make. For the rest,
1345 // Make targets can depend on both the sanitized and non-sanitized
1346 // versions.
1347 oneMakeVariation = true
1348 }
1349 } else if !c.Binary() {
1350 // Shared library. These are the sanitizers that do propagate through shared
1351 // library dependencies and therefore can cause multiple variations of a
1352 // shared library to be built.
1353 if s.sanitizer != cfi && s.sanitizer != Hwasan && s.sanitizer != scs && s.sanitizer != Asan {
1354 oneMakeVariation = true
1355 }
1356 }
1357
1358 if oneMakeVariation {
1359 if sanitizerEnabled != sanitizerVariation {
1360 c.SetPreventInstall()
1361 c.SetHideFromMake()
1362 }
1363 }
1364
1365 if sanitizerVariation {
1366 c.SetSanitizer(s.sanitizer, true)
1367
1368 // CFI is incompatible with ASAN so disable it in ASAN variations
1369 if s.sanitizer.incompatibleWithCfi() {
1370 cfiSupported := mctx.Module().(PlatformSanitizeable).SanitizerSupported(cfi)
1371 if mctx.Device() && cfiSupported {
1372 c.SetSanitizer(cfi, false)
Jiyong Parkf97782b2019-02-13 20:28:58 +09001373 }
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001374 }
1375
1376 // locate the asan libraries under /data/asan
1377 if !c.Binary() && !c.StaticallyLinked() && !c.Header() && mctx.Device() && s.sanitizer == Asan && sanitizerEnabled {
1378 c.SetInSanitizerDir()
1379 }
1380
1381 if c.StaticallyLinked() && c.ExportedToMake() {
1382 if s.sanitizer == Hwasan {
1383 hwasanStaticLibs(mctx.Config()).add(c, c.Module().Name())
1384 } else if s.sanitizer == cfi {
1385 cfiStaticLibs(mctx.Config()).add(c, c.Module().Name())
1386 }
1387 }
1388 } else if c.IsSanitizerEnabled(s.sanitizer) {
1389 // Disable the sanitizer for the non-sanitized variation
1390 c.SetSanitizer(s.sanitizer, false)
1391 }
1392 } else if sanitizeable, ok := mctx.Module().(Sanitizeable); ok {
1393 // If an APEX has sanitized dependencies, it gets a few more dependencies
1394 if sanitizerVariation {
1395 sanitizeable.AddSanitizerDependencies(mctx, s.sanitizer.name())
1396 }
Ivan Lozano5467a392023-08-23 14:20:25 -04001397 } else if c, ok := mctx.Module().(LinkableInterface); ok {
1398 if c.IsSnapshotSanitizerAvailable(s.sanitizer) {
1399 if !c.IsSnapshotUnsanitizedVariant() {
Justin Yun39c30312022-11-23 16:20:12 +09001400 // Snapshot sanitizer may have only one variantion.
1401 // Skip exporting the module if it already has a sanitizer variation.
1402 c.SetPreventInstall()
1403 c.SetHideFromMake()
1404 return
1405 }
Ivan Lozano5467a392023-08-23 14:20:25 -04001406 c.SetSnapshotSanitizerVariation(s.sanitizer, sanitizerVariation)
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001407
1408 // Export the static lib name to make
Ivan Lozano5467a392023-08-23 14:20:25 -04001409 if c.Static() && c.ExportedToMake() {
Justin Yun39c30312022-11-23 16:20:12 +09001410 // use BaseModuleName which is the name for Make.
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001411 if s.sanitizer == cfi {
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001412 cfiStaticLibs(mctx.Config()).add(c, c.BaseModuleName())
Justin Yun39c30312022-11-23 16:20:12 +09001413 } else if s.sanitizer == Hwasan {
1414 hwasanStaticLibs(mctx.Config()).add(c, c.BaseModuleName())
Lukacs T. Berki6c716762022-06-13 20:50:39 +02001415 }
1416 }
Colin Cross16b23492016-01-06 14:41:07 -08001417 }
1418 }
1419}
1420
Ivan Lozano5467a392023-08-23 14:20:25 -04001421func (c *Module) IsSnapshotSanitizer() bool {
1422 if _, ok := c.linker.(SnapshotSanitizer); ok {
1423 return true
1424 }
1425 return false
1426}
1427
1428func (c *Module) IsSnapshotSanitizerAvailable(t SanitizerType) bool {
1429 if ss, ok := c.linker.(SnapshotSanitizer); ok {
1430 return ss.IsSanitizerAvailable(t)
1431 }
1432 return false
1433}
1434
1435func (c *Module) SetSnapshotSanitizerVariation(t SanitizerType, enabled bool) {
1436 if ss, ok := c.linker.(SnapshotSanitizer); ok {
1437 ss.SetSanitizerVariation(t, enabled)
1438 } else {
1439 panic(fmt.Errorf("Calling SetSnapshotSanitizerVariation on a non-snapshotLibraryDecorator: %s", c.Name()))
1440 }
1441}
1442
1443func (c *Module) IsSnapshotUnsanitizedVariant() bool {
1444 if ss, ok := c.linker.(SnapshotSanitizer); ok {
1445 return ss.IsUnsanitizedVariant()
1446 }
1447 return false
1448}
1449
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001450func (c *Module) SanitizeNever() bool {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001451 return Bool(c.sanitize.Properties.SanitizeMutated.Never)
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001452}
1453
1454func (c *Module) IsSanitizerExplicitlyDisabled(t SanitizerType) bool {
1455 return c.sanitize.isSanitizerExplicitlyDisabled(t)
1456}
1457
Ivan Lozano30c5db22018-02-21 15:49:20 -08001458// Propagate the ubsan minimal runtime dependency when there are integer overflow sanitized static dependencies.
Colin Cross6b753602018-06-21 13:03:07 -07001459func sanitizerRuntimeDepsMutator(mctx android.TopDownMutatorContext) {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001460 // Change this to PlatformSanitizable when/if non-cc modules support ubsan sanitizers.
Colin Cross6b753602018-06-21 13:03:07 -07001461 if c, ok := mctx.Module().(*Module); ok && c.sanitize != nil {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001462 isSanitizableDependencyTag := c.SanitizableDepTagChecker()
Colin Cross6b753602018-06-21 13:03:07 -07001463 mctx.WalkDeps(func(child, parent android.Module) bool {
1464 if !isSanitizableDependencyTag(mctx.OtherModuleDependencyTag(child)) {
1465 return false
1466 }
Ivan Lozano30c5db22018-02-21 15:49:20 -08001467
Inseob Kimeec88e12020-01-22 11:11:29 +09001468 d, ok := child.(*Module)
1469 if !ok || !d.static() {
1470 return false
1471 }
1472 if d.sanitize != nil {
Colin Cross6b753602018-06-21 13:03:07 -07001473 if enableMinimalRuntime(d.sanitize) {
1474 // If a static dependency is built with the minimal runtime,
1475 // make sure we include the ubsan minimal runtime.
1476 c.sanitize.Properties.MinimalRuntimeDep = true
Inseob Kim8471cda2019-11-15 09:59:12 +09001477 } else if enableUbsanRuntime(d.sanitize) {
Colin Cross6b753602018-06-21 13:03:07 -07001478 // If a static dependency runs with full ubsan diagnostics,
1479 // make sure we include the ubsan runtime.
1480 c.sanitize.Properties.UbsanRuntimeDep = true
Ivan Lozano30c5db22018-02-21 15:49:20 -08001481 }
Colin Cross0b908332019-06-19 23:00:20 -07001482
1483 if c.sanitize.Properties.MinimalRuntimeDep &&
1484 c.sanitize.Properties.UbsanRuntimeDep {
1485 // both flags that this mutator might set are true, so don't bother recursing
1486 return false
1487 }
1488
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001489 if c.Os() == android.Linux {
1490 c.sanitize.Properties.BuiltinsDep = true
1491 }
1492
Colin Cross0b908332019-06-19 23:00:20 -07001493 return true
Colin Cross6b753602018-06-21 13:03:07 -07001494 }
Inseob Kimeec88e12020-01-22 11:11:29 +09001495
Jose Galmesf7294582020-11-13 12:07:36 -08001496 if p, ok := d.linker.(*snapshotLibraryDecorator); ok {
Inseob Kimeec88e12020-01-22 11:11:29 +09001497 if Bool(p.properties.Sanitize_minimal_dep) {
1498 c.sanitize.Properties.MinimalRuntimeDep = true
1499 }
1500 if Bool(p.properties.Sanitize_ubsan_dep) {
1501 c.sanitize.Properties.UbsanRuntimeDep = true
1502 }
1503 }
1504
1505 return false
Colin Cross6b753602018-06-21 13:03:07 -07001506 })
Ivan Lozano30c5db22018-02-21 15:49:20 -08001507 }
1508}
1509
Jiyong Park379de2f2018-12-19 02:47:14 +09001510// Add the dependency to the runtime library for each of the sanitizer variants
1511func sanitizerRuntimeMutator(mctx android.BottomUpMutatorContext) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001512 if c, ok := mctx.Module().(*Module); ok && c.sanitize != nil {
Pirama Arumuga Nainar6aa21022019-01-25 00:20:35 +00001513 if !c.Enabled() {
1514 return
1515 }
Jiyong Park379de2f2018-12-19 02:47:14 +09001516 var sanitizers []string
1517 var diagSanitizers []string
1518
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001519 sanProps := &c.sanitize.Properties.SanitizeMutated
1520
1521 if Bool(sanProps.All_undefined) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001522 sanitizers = append(sanitizers, "undefined")
1523 } else {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001524 if Bool(sanProps.Undefined) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001525 sanitizers = append(sanitizers,
1526 "bool",
1527 "integer-divide-by-zero",
1528 "return",
1529 "returns-nonnull-attribute",
1530 "shift-exponent",
1531 "unreachable",
1532 "vla-bound",
1533 // TODO(danalbert): The following checks currently have compiler performance issues.
1534 //"alignment",
1535 //"bounds",
1536 //"enum",
1537 //"float-cast-overflow",
1538 //"float-divide-by-zero",
1539 //"nonnull-attribute",
1540 //"null",
1541 //"shift-base",
1542 //"signed-integer-overflow",
1543 // TODO(danalbert): Fix UB in libc++'s __tree so we can turn this on.
1544 // https://llvm.org/PR19302
1545 // http://reviews.llvm.org/D6974
1546 // "object-size",
1547 )
1548 }
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001549 sanitizers = append(sanitizers, sanProps.Misc_undefined...)
Jiyong Park379de2f2018-12-19 02:47:14 +09001550 }
1551
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001552 if Bool(sanProps.Diag.Undefined) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001553 diagSanitizers = append(diagSanitizers, "undefined")
1554 }
1555
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001556 diagSanitizers = append(diagSanitizers, sanProps.Diag.Misc_undefined...)
Jiyong Park379de2f2018-12-19 02:47:14 +09001557
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001558 if Bool(sanProps.Address) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001559 sanitizers = append(sanitizers, "address")
1560 diagSanitizers = append(diagSanitizers, "address")
1561 }
1562
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001563 if Bool(sanProps.Hwaddress) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001564 sanitizers = append(sanitizers, "hwaddress")
1565 }
1566
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001567 if Bool(sanProps.Thread) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001568 sanitizers = append(sanitizers, "thread")
1569 }
1570
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001571 if Bool(sanProps.Safestack) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001572 sanitizers = append(sanitizers, "safe-stack")
1573 }
1574
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001575 if Bool(sanProps.Cfi) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001576 sanitizers = append(sanitizers, "cfi")
1577
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001578 if Bool(sanProps.Diag.Cfi) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001579 diagSanitizers = append(diagSanitizers, "cfi")
1580 }
1581 }
1582
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001583 if Bool(sanProps.Integer_overflow) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001584 sanitizers = append(sanitizers, "unsigned-integer-overflow")
1585 sanitizers = append(sanitizers, "signed-integer-overflow")
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001586 if Bool(sanProps.Diag.Integer_overflow) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001587 diagSanitizers = append(diagSanitizers, "unsigned-integer-overflow")
1588 diagSanitizers = append(diagSanitizers, "signed-integer-overflow")
1589 }
1590 }
1591
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001592 if Bool(sanProps.Scudo) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001593 sanitizers = append(sanitizers, "scudo")
1594 }
1595
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001596 if Bool(sanProps.Scs) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001597 sanitizers = append(sanitizers, "shadow-call-stack")
1598 }
1599
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001600 if Bool(sanProps.Memtag_heap) && c.Binary() {
Florian Mayerd8434a42022-08-31 20:57:03 +00001601 sanitizers = append(sanitizers, "memtag-heap")
1602 }
1603
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001604 if Bool(sanProps.Memtag_stack) {
Florian Mayerd8434a42022-08-31 20:57:03 +00001605 sanitizers = append(sanitizers, "memtag-stack")
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -07001606 }
1607
Mitch Phillips92d19fa2023-06-01 14:23:09 +02001608 if Bool(sanProps.Memtag_globals) {
1609 sanitizers = append(sanitizers, "memtag-globals")
1610 // TODO(mitchp): For now, enable memtag-heap with memtag-globals because the linker
1611 // isn't new enough (https://reviews.llvm.org/differential/changeset/?ref=4243566).
1612 sanitizers = append(sanitizers, "memtag-heap")
1613 }
1614
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001615 if Bool(sanProps.Fuzzer) {
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -07001616 sanitizers = append(sanitizers, "fuzzer-no-link")
1617 }
1618
Jiyong Park379de2f2018-12-19 02:47:14 +09001619 // Save the list of sanitizers. These will be used again when generating
1620 // the build rules (for Cflags, etc.)
1621 c.sanitize.Properties.Sanitizers = sanitizers
1622 c.sanitize.Properties.DiagSanitizers = diagSanitizers
1623
Ivan Lozanof3b190f2020-03-06 12:01:21 -05001624 // TODO(b/150822854) Hosts have a different default behavior and assume the runtime library is used.
1625 if c.Host() {
1626 diagSanitizers = sanitizers
1627 }
1628
Colin Crosse323a792023-02-15 13:57:57 -08001629 addStaticDeps := func(dep string, hideSymbols bool) {
Colin Cross06c80eb2022-02-10 10:34:19 -08001630 // If we're using snapshots, redirect to snapshot whenever possible
Colin Crossff694a82023-12-13 15:54:49 -08001631 snapshot, _ := android.ModuleProvider(mctx, SnapshotInfoProvider)
Colin Crosse323a792023-02-15 13:57:57 -08001632 if lib, ok := snapshot.StaticLibs[dep]; ok {
1633 dep = lib
Colin Cross06c80eb2022-02-10 10:34:19 -08001634 }
1635
1636 // static executable gets static runtime libs
Colin Crosse323a792023-02-15 13:57:57 -08001637 depTag := libraryDependencyTag{Kind: staticLibraryDependency, unexportedSymbols: hideSymbols}
Colin Cross06c80eb2022-02-10 10:34:19 -08001638 variations := append(mctx.Target().Variations(),
1639 blueprint.Variation{Mutator: "link", Variation: "static"})
1640 if c.Device() {
1641 variations = append(variations, c.ImageVariation())
1642 }
1643 if c.UseSdk() {
1644 variations = append(variations,
1645 blueprint.Variation{Mutator: "sdk", Variation: "sdk"})
1646 }
Colin Crosse323a792023-02-15 13:57:57 -08001647 mctx.AddFarVariationDependencies(variations, depTag, dep)
Colin Cross06c80eb2022-02-10 10:34:19 -08001648 }
Colin Crosse323a792023-02-15 13:57:57 -08001649
1650 // Determine the runtime library required
1651 runtimeSharedLibrary := ""
1652 toolchain := c.toolchain(mctx)
1653 if Bool(sanProps.Address) {
Colin Crossb781d232023-02-15 12:40:20 -08001654 if toolchain.Musl() || (c.staticBinary() && toolchain.Bionic()) {
1655 // Use a static runtime for musl to match what clang does for glibc.
1656 addStaticDeps(config.AddressSanitizerStaticRuntimeLibrary(toolchain), false)
1657 addStaticDeps(config.AddressSanitizerCXXStaticRuntimeLibrary(toolchain), false)
1658 } else {
1659 runtimeSharedLibrary = config.AddressSanitizerRuntimeLibrary(toolchain)
1660 }
Colin Crosse323a792023-02-15 13:57:57 -08001661 } else if Bool(sanProps.Hwaddress) {
1662 if c.staticBinary() {
1663 addStaticDeps(config.HWAddressSanitizerStaticLibrary(toolchain), true)
1664 addStaticDeps("libdl", false)
1665 } else {
1666 runtimeSharedLibrary = config.HWAddressSanitizerRuntimeLibrary(toolchain)
1667 }
1668 } else if Bool(sanProps.Thread) {
1669 runtimeSharedLibrary = config.ThreadSanitizerRuntimeLibrary(toolchain)
1670 } else if Bool(sanProps.Scudo) {
1671 if len(diagSanitizers) == 0 && !c.sanitize.Properties.UbsanRuntimeDep {
1672 runtimeSharedLibrary = config.ScudoMinimalRuntimeLibrary(toolchain)
1673 } else {
1674 runtimeSharedLibrary = config.ScudoRuntimeLibrary(toolchain)
1675 }
1676 } else if len(diagSanitizers) > 0 || c.sanitize.Properties.UbsanRuntimeDep ||
1677 Bool(sanProps.Fuzzer) ||
1678 Bool(sanProps.Undefined) ||
1679 Bool(sanProps.All_undefined) {
Colin Cross0df81532023-08-23 22:20:51 -07001680 if toolchain.Musl() || c.staticBinary() {
1681 // Use a static runtime for static binaries. For sanitized glibc binaries the runtime is
1682 // added automatically by clang, but for static glibc binaries that are not sanitized but
1683 // have a sanitized dependency the runtime needs to be added manually.
1684 // Also manually add a static runtime for musl to match what clang does for glibc.
1685 // Otherwise dlopening libraries that depend on libclang_rt.ubsan_standalone.so fails with:
Colin Crosse323a792023-02-15 13:57:57 -08001686 // Error relocating ...: initial-exec TLS resolves to dynamic definition
1687 addStaticDeps(config.UndefinedBehaviorSanitizerRuntimeLibrary(toolchain)+".static", true)
1688 } else {
1689 runtimeSharedLibrary = config.UndefinedBehaviorSanitizerRuntimeLibrary(toolchain)
1690 }
1691 }
1692
Colin Cross06c80eb2022-02-10 10:34:19 -08001693 if enableMinimalRuntime(c.sanitize) || c.sanitize.Properties.MinimalRuntimeDep {
Colin Crosse323a792023-02-15 13:57:57 -08001694 addStaticDeps(config.UndefinedBehaviorSanitizerMinimalRuntimeLibrary(toolchain), true)
Colin Cross06c80eb2022-02-10 10:34:19 -08001695 }
1696 if c.sanitize.Properties.BuiltinsDep {
Colin Crosse323a792023-02-15 13:57:57 -08001697 addStaticDeps(config.BuiltinsRuntimeLibrary(toolchain), true)
Colin Cross06c80eb2022-02-10 10:34:19 -08001698 }
1699
Colin Crosse323a792023-02-15 13:57:57 -08001700 if runtimeSharedLibrary != "" && (toolchain.Bionic() || toolchain.Musl() || c.sanitize.Properties.UbsanRuntimeDep) {
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001701 // UBSan is supported on non-bionic linux host builds as well
Jiyong Park379de2f2018-12-19 02:47:14 +09001702
1703 // Adding dependency to the runtime library. We are using *FarVariation*
1704 // because the runtime libraries themselves are not mutated by sanitizer
1705 // mutators and thus don't have sanitizer variants whereas this module
1706 // has been already mutated.
1707 //
1708 // Note that by adding dependency with {static|shared}DepTag, the lib is
1709 // added to libFlags and LOCAL_SHARED_LIBRARIES by cc.Module
Colin Crosse323a792023-02-15 13:57:57 -08001710 if c.staticBinary() {
1711 // Most sanitizers are either disabled for static binaries or have already
1712 // handled the static binary case above through a direct call to addStaticDeps.
1713 // If not, treat the runtime shared library as a static library and hope for
1714 // the best.
1715 addStaticDeps(runtimeSharedLibrary, true)
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001716 } else if !c.static() && !c.Header() {
Colin Crosse0edaf92021-01-11 17:31:17 -08001717 // If we're using snapshots, redirect to snapshot whenever possible
Colin Crossff694a82023-12-13 15:54:49 -08001718 snapshot, _ := android.ModuleProvider(mctx, SnapshotInfoProvider)
Colin Crosse323a792023-02-15 13:57:57 -08001719 if lib, ok := snapshot.SharedLibs[runtimeSharedLibrary]; ok {
1720 runtimeSharedLibrary = lib
Inseob Kimeec88e12020-01-22 11:11:29 +09001721 }
Colin Crosse0edaf92021-01-11 17:31:17 -08001722
Cindy Zhou18417cb2020-12-10 07:12:38 -08001723 // Skip apex dependency check for sharedLibraryDependency
1724 // when sanitizer diags are enabled. Skipping the check will allow
1725 // building with diag libraries without having to list the
1726 // dependency in Apex's allowed_deps file.
1727 diagEnabled := len(diagSanitizers) > 0
Jiyong Park3b1746a2019-01-29 11:15:04 +09001728 // dynamic executable and shared libs get shared runtime libs
Cindy Zhou18417cb2020-12-10 07:12:38 -08001729 depTag := libraryDependencyTag{
1730 Kind: sharedLibraryDependency,
1731 Order: earlyLibraryDependency,
1732
1733 skipApexAllowedDependenciesCheck: diagEnabled,
1734 }
Colin Cross42507332020-08-21 16:15:23 -07001735 variations := append(mctx.Target().Variations(),
1736 blueprint.Variation{Mutator: "link", Variation: "shared"})
1737 if c.Device() {
1738 variations = append(variations, c.ImageVariation())
1739 }
Colin Cross06c80eb2022-02-10 10:34:19 -08001740 if c.UseSdk() {
1741 variations = append(variations,
1742 blueprint.Variation{Mutator: "sdk", Variation: "sdk"})
1743 }
Colin Crosse323a792023-02-15 13:57:57 -08001744 AddSharedLibDependenciesWithVersions(mctx, c, variations, depTag, runtimeSharedLibrary, "", true)
Jiyong Park379de2f2018-12-19 02:47:14 +09001745 }
1746 // static lib does not have dependency to the runtime library. The
1747 // dependency will be added to the executables or shared libs using
1748 // the static lib.
1749 }
1750 }
1751}
1752
1753type Sanitizeable interface {
1754 android.Module
Lukacs T. Berki01a648a2022-06-17 08:59:37 +02001755 IsSanitizerEnabled(config android.Config, sanitizerName string) bool
Jiyong Parkf97782b2019-02-13 20:28:58 +09001756 EnableSanitizer(sanitizerName string)
Jooyung Han8ce8db92020-05-15 19:05:05 +09001757 AddSanitizerDependencies(ctx android.BottomUpMutatorContext, sanitizerName string)
Jiyong Park379de2f2018-12-19 02:47:14 +09001758}
1759
Muhammad Haseeb Ahmad7e744052022-03-25 22:50:53 +00001760type JniSanitizeable interface {
1761 android.Module
1762 IsSanitizerEnabledForJni(ctx android.BaseModuleContext, sanitizerName string) bool
1763}
1764
Ivan Lozanod7586b62021-04-01 09:49:36 -04001765func (c *Module) MinimalRuntimeDep() bool {
1766 return c.sanitize.Properties.MinimalRuntimeDep
1767}
1768
1769func (c *Module) UbsanRuntimeDep() bool {
1770 return c.sanitize.Properties.UbsanRuntimeDep
1771}
1772
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001773func (c *Module) SanitizePropDefined() bool {
1774 return c.sanitize != nil
1775}
1776
1777func (c *Module) IsSanitizerEnabled(t SanitizerType) bool {
1778 return c.sanitize.isSanitizerEnabled(t)
1779}
1780
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001781func (c *Module) StaticallyLinked() bool {
1782 return c.static()
1783}
1784
1785func (c *Module) SetInSanitizerDir() {
1786 if c.sanitize != nil {
1787 c.sanitize.Properties.InSanitizerDir = true
1788 }
1789}
1790
1791func (c *Module) SetSanitizer(t SanitizerType, b bool) {
1792 if c.sanitize != nil {
1793 c.sanitize.SetSanitizer(t, b)
1794 }
1795}
1796
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001797var _ PlatformSanitizeable = (*Module)(nil)
1798
Inseob Kim74d25562020-08-04 00:41:38 +09001799type sanitizerStaticLibsMap struct {
1800 // libsMap contains one list of modules per each image and each arch.
1801 // e.g. libs[vendor]["arm"] contains arm modules installed to vendor
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001802 libsMap map[ImageVariantType]map[string][]string
Inseob Kim74d25562020-08-04 00:41:38 +09001803 libsMapLock sync.Mutex
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001804 sanitizerType SanitizerType
Inseob Kim74d25562020-08-04 00:41:38 +09001805}
1806
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001807func newSanitizerStaticLibsMap(t SanitizerType) *sanitizerStaticLibsMap {
Inseob Kim74d25562020-08-04 00:41:38 +09001808 return &sanitizerStaticLibsMap{
1809 sanitizerType: t,
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001810 libsMap: make(map[ImageVariantType]map[string][]string),
Inseob Kim74d25562020-08-04 00:41:38 +09001811 }
1812}
1813
1814// Add the current module to sanitizer static libs maps
1815// Each module should pass its exported name as names of Make and Soong can differ.
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001816func (s *sanitizerStaticLibsMap) add(c LinkableInterface, name string) {
1817 image := GetImageVariantType(c)
1818 arch := c.Module().Target().Arch.ArchType.String()
Inseob Kim74d25562020-08-04 00:41:38 +09001819
1820 s.libsMapLock.Lock()
1821 defer s.libsMapLock.Unlock()
1822
1823 if _, ok := s.libsMap[image]; !ok {
1824 s.libsMap[image] = make(map[string][]string)
1825 }
1826
1827 s.libsMap[image][arch] = append(s.libsMap[image][arch], name)
1828}
1829
1830// Exports makefile variables in the following format:
1831// SOONG_{sanitizer}_{image}_{arch}_STATIC_LIBRARIES
1832// e.g. SOONG_cfi_core_x86_STATIC_LIBRARIES
1833// These are to be used by use_soong_sanitized_static_libraries.
1834// See build/make/core/binary.mk for more details.
1835func (s *sanitizerStaticLibsMap) exportToMake(ctx android.MakeVarsContext) {
Cole Faust18994c72023-02-28 16:02:16 -08001836 for _, image := range android.SortedKeys(s.libsMap) {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001837 archMap := s.libsMap[ImageVariantType(image)]
Cole Faust18994c72023-02-28 16:02:16 -08001838 for _, arch := range android.SortedKeys(archMap) {
Inseob Kim74d25562020-08-04 00:41:38 +09001839 libs := archMap[arch]
1840 sort.Strings(libs)
1841
1842 key := fmt.Sprintf(
1843 "SOONG_%s_%s_%s_STATIC_LIBRARIES",
1844 s.sanitizerType.variationName(),
1845 image, // already upper
1846 arch)
1847
1848 ctx.Strict(key, strings.Join(libs, " "))
1849 }
1850 }
1851}
1852
Colin Cross571cccf2019-02-04 11:22:08 -08001853var cfiStaticLibsKey = android.NewOnceKey("cfiStaticLibs")
1854
Inseob Kim74d25562020-08-04 00:41:38 +09001855func cfiStaticLibs(config android.Config) *sanitizerStaticLibsMap {
Colin Cross571cccf2019-02-04 11:22:08 -08001856 return config.Once(cfiStaticLibsKey, func() interface{} {
Inseob Kim74d25562020-08-04 00:41:38 +09001857 return newSanitizerStaticLibsMap(cfi)
1858 }).(*sanitizerStaticLibsMap)
Vishwath Mohane7128792017-11-17 11:08:10 -08001859}
1860
Colin Cross571cccf2019-02-04 11:22:08 -08001861var hwasanStaticLibsKey = android.NewOnceKey("hwasanStaticLibs")
1862
Inseob Kim74d25562020-08-04 00:41:38 +09001863func hwasanStaticLibs(config android.Config) *sanitizerStaticLibsMap {
Colin Cross571cccf2019-02-04 11:22:08 -08001864 return config.Once(hwasanStaticLibsKey, func() interface{} {
Tri Vo6eafc362021-04-01 11:29:09 -07001865 return newSanitizerStaticLibsMap(Hwasan)
Inseob Kim74d25562020-08-04 00:41:38 +09001866 }).(*sanitizerStaticLibsMap)
Jiyong Park1d1119f2019-07-29 21:27:18 +09001867}
1868
Ivan Lozano30c5db22018-02-21 15:49:20 -08001869func enableMinimalRuntime(sanitize *sanitize) bool {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001870 if sanitize.isSanitizerEnabled(Asan) {
1871 return false
1872 } else if sanitize.isSanitizerEnabled(Hwasan) {
1873 return false
1874 } else if sanitize.isSanitizerEnabled(Fuzzer) {
1875 return false
Ivan Lozano30c5db22018-02-21 15:49:20 -08001876 }
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001877
1878 if enableUbsanRuntime(sanitize) {
1879 return false
1880 }
1881
1882 sanitizeProps := &sanitize.Properties.SanitizeMutated
1883 if Bool(sanitizeProps.Diag.Cfi) {
1884 return false
1885 }
1886
1887 return Bool(sanitizeProps.Integer_overflow) ||
1888 len(sanitizeProps.Misc_undefined) > 0 ||
1889 Bool(sanitizeProps.Undefined) ||
1890 Bool(sanitizeProps.All_undefined)
Ivan Lozano30c5db22018-02-21 15:49:20 -08001891}
1892
Ivan Lozanod7586b62021-04-01 09:49:36 -04001893func (m *Module) UbsanRuntimeNeeded() bool {
1894 return enableUbsanRuntime(m.sanitize)
1895}
1896
1897func (m *Module) MinimalRuntimeNeeded() bool {
1898 return enableMinimalRuntime(m.sanitize)
1899}
1900
Inseob Kim8471cda2019-11-15 09:59:12 +09001901func enableUbsanRuntime(sanitize *sanitize) bool {
Liz Kammer2c1d6aa2022-10-03 15:07:37 -04001902 sanitizeProps := &sanitize.Properties.SanitizeMutated
1903 return Bool(sanitizeProps.Diag.Integer_overflow) ||
1904 Bool(sanitizeProps.Diag.Undefined) ||
1905 len(sanitizeProps.Diag.Misc_undefined) > 0
Inseob Kim8471cda2019-11-15 09:59:12 +09001906}
1907
Vishwath Mohane7128792017-11-17 11:08:10 -08001908func cfiMakeVarsProvider(ctx android.MakeVarsContext) {
Inseob Kim74d25562020-08-04 00:41:38 +09001909 cfiStaticLibs(ctx.Config()).exportToMake(ctx)
Vishwath Mohane7128792017-11-17 11:08:10 -08001910}
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -07001911
1912func hwasanMakeVarsProvider(ctx android.MakeVarsContext) {
Inseob Kim74d25562020-08-04 00:41:38 +09001913 hwasanStaticLibs(ctx.Config()).exportToMake(ctx)
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -07001914}