Blame malloc/mcheck.c

Packit 6c4009
/* Standard debugging hooks for `malloc'.
Packit 6c4009
   Copyright (C) 1990-2018 Free Software Foundation, Inc.
Packit 6c4009
   This file is part of the GNU C Library.
Packit 6c4009
   Written May 1989 by Mike Haertel.
Packit 6c4009
Packit 6c4009
   The GNU C Library is free software; you can redistribute it and/or
Packit 6c4009
   modify it under the terms of the GNU Lesser General Public
Packit 6c4009
   License as published by the Free Software Foundation; either
Packit 6c4009
   version 2.1 of the License, or (at your option) any later version.
Packit 6c4009
Packit 6c4009
   The GNU C Library is distributed in the hope that it will be useful,
Packit 6c4009
   but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit 6c4009
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit 6c4009
   Lesser General Public License for more details.
Packit 6c4009
Packit 6c4009
   You should have received a copy of the GNU Lesser General Public
Packit 6c4009
   License along with the GNU C Library; if not, see
Packit 6c4009
   <http://www.gnu.org/licenses/>.  */
Packit 6c4009
Packit 6c4009
#ifndef _MALLOC_INTERNAL
Packit 6c4009
# define _MALLOC_INTERNAL
Packit 6c4009
# include <malloc.h>
Packit 6c4009
# include <mcheck.h>
Packit 6c4009
# include <stdint.h>
Packit 6c4009
# include <stdio.h>
Packit 6c4009
# include <libintl.h>
Packit 6c4009
# include <errno.h>
Packit 6c4009
#endif
Packit 6c4009
Packit 6c4009
/* Old hook values.  */
Packit 6c4009
static void (*old_free_hook)(void *ptr, const void *);
Packit 6c4009
static void *(*old_malloc_hook) (size_t size, const void *);
Packit 6c4009
static void *(*old_memalign_hook) (size_t alignment, size_t size,
Packit 6c4009
				   const void *);
Packit 6c4009
static void *(*old_realloc_hook) (void *ptr, size_t size,
Packit 6c4009
				  const void *);
Packit 6c4009
Packit 6c4009
/* Function to call when something awful happens.  */
Packit 6c4009
static void (*abortfunc) (enum mcheck_status);
Packit 6c4009
Packit 6c4009
/* Arbitrary magical numbers.  */
Packit 6c4009
#define MAGICWORD       0xfedabeeb
Packit 6c4009
#define MAGICFREE       0xd8675309
Packit 6c4009
#define MAGICBYTE       ((char) 0xd7)
Packit 6c4009
#define MALLOCFLOOD     ((char) 0x93)
Packit 6c4009
#define FREEFLOOD       ((char) 0x95)
Packit 6c4009
Packit 6c4009
struct hdr
Packit 6c4009
{
Packit 6c4009
  size_t size;                  /* Exact size requested by user.  */
Packit 6c4009
  unsigned long int magic;      /* Magic number to check header integrity.  */
Packit 6c4009
  struct hdr *prev;
Packit 6c4009
  struct hdr *next;
Packit 6c4009
  void *block;                  /* Real block allocated, for memalign.  */
Packit 6c4009
  unsigned long int magic2;     /* Extra, keeps us doubleword aligned.  */
Packit 6c4009
};
Packit 6c4009
Packit 6c4009
/* This is the beginning of the list of all memory blocks allocated.
Packit 6c4009
   It is only constructed if the pedantic testing is requested.  */
Packit 6c4009
static struct hdr *root;
Packit 6c4009
Packit 6c4009
static int mcheck_used;
Packit 6c4009
Packit 6c4009
/* Nonzero if pedentic checking of all blocks is requested.  */
Packit 6c4009
static int pedantic;
Packit 6c4009
Packit 6c4009
#if defined _LIBC || defined STDC_HEADERS || defined USG
Packit 6c4009
# include <string.h>
Packit 6c4009
# define flood memset
Packit 6c4009
#else
Packit 6c4009
static void flood (void *, int, size_t);
Packit 6c4009
static void
Packit 6c4009
flood (void *ptr, int val, size_t size)
Packit 6c4009
{
Packit 6c4009
  char *cp = ptr;
Packit 6c4009
  while (size--)
Packit 6c4009
    *cp++ = val;
Packit 6c4009
}
Packit 6c4009
#endif
Packit 6c4009
Packit 6c4009
static enum mcheck_status
Packit 6c4009
checkhdr (const struct hdr *hdr)
Packit 6c4009
{
Packit 6c4009
  enum mcheck_status status;
Packit 6c4009
Packit 6c4009
  if (!mcheck_used)
Packit 6c4009
    /* Maybe the mcheck used is disabled?  This happens when we find
Packit 6c4009
       an error and report it.  */
Packit 6c4009
    return MCHECK_OK;
Packit 6c4009
Packit 6c4009
  switch (hdr->magic ^ ((uintptr_t) hdr->prev + (uintptr_t) hdr->next))
Packit 6c4009
    {
Packit 6c4009
    default:
Packit 6c4009
      status = MCHECK_HEAD;
Packit 6c4009
      break;
Packit 6c4009
    case MAGICFREE:
Packit 6c4009
      status = MCHECK_FREE;
Packit 6c4009
      break;
Packit 6c4009
    case MAGICWORD:
Packit 6c4009
      if (((char *) &hdr[1])[hdr->size] != MAGICBYTE)
Packit 6c4009
        status = MCHECK_TAIL;
Packit 6c4009
      else if ((hdr->magic2 ^ (uintptr_t) hdr->block) != MAGICWORD)
Packit 6c4009
        status = MCHECK_HEAD;
Packit 6c4009
      else
Packit 6c4009
        status = MCHECK_OK;
Packit 6c4009
      break;
Packit 6c4009
    }
Packit 6c4009
  if (status != MCHECK_OK)
Packit 6c4009
    {
Packit 6c4009
      mcheck_used = 0;
Packit 6c4009
      (*abortfunc) (status);
Packit 6c4009
      mcheck_used = 1;
Packit 6c4009
    }
Packit 6c4009
  return status;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
void
Packit 6c4009
mcheck_check_all (void)
Packit 6c4009
{
Packit 6c4009
  /* Walk through all the active blocks and test whether they were tampered
Packit 6c4009
     with.  */
Packit 6c4009
  struct hdr *runp = root;
Packit 6c4009
Packit 6c4009
  /* Temporarily turn off the checks.  */
Packit 6c4009
  pedantic = 0;
Packit 6c4009
Packit 6c4009
  while (runp != NULL)
Packit 6c4009
    {
Packit 6c4009
      (void) checkhdr (runp);
Packit 6c4009
Packit 6c4009
      runp = runp->next;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  /* Turn checks on again.  */
Packit 6c4009
  pedantic = 1;
Packit 6c4009
}
Packit 6c4009
#ifdef _LIBC
Packit 6c4009
libc_hidden_def (mcheck_check_all)
Packit 6c4009
#endif
Packit 6c4009
Packit 6c4009
static void
Packit 6c4009
unlink_blk (struct hdr *ptr)
Packit 6c4009
{
Packit 6c4009
  if (ptr->next != NULL)
Packit 6c4009
    {
Packit 6c4009
      ptr->next->prev = ptr->prev;
Packit 6c4009
      ptr->next->magic = MAGICWORD ^ ((uintptr_t) ptr->next->prev
Packit 6c4009
                                      + (uintptr_t) ptr->next->next);
Packit 6c4009
    }
Packit 6c4009
  if (ptr->prev != NULL)
Packit 6c4009
    {
Packit 6c4009
      ptr->prev->next = ptr->next;
Packit 6c4009
      ptr->prev->magic = MAGICWORD ^ ((uintptr_t) ptr->prev->prev
Packit 6c4009
                                      + (uintptr_t) ptr->prev->next);
Packit 6c4009
    }
Packit 6c4009
  else
Packit 6c4009
    root = ptr->next;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
static void
Packit 6c4009
link_blk (struct hdr *hdr)
Packit 6c4009
{
Packit 6c4009
  hdr->prev = NULL;
Packit 6c4009
  hdr->next = root;
Packit 6c4009
  root = hdr;
Packit 6c4009
  hdr->magic = MAGICWORD ^ (uintptr_t) hdr->next;
Packit 6c4009
Packit 6c4009
  /* And the next block.  */
Packit 6c4009
  if (hdr->next != NULL)
Packit 6c4009
    {
Packit 6c4009
      hdr->next->prev = hdr;
Packit 6c4009
      hdr->next->magic = MAGICWORD ^ ((uintptr_t) hdr
Packit 6c4009
                                      + (uintptr_t) hdr->next->next);
Packit 6c4009
    }
Packit 6c4009
}
Packit 6c4009
static void
Packit 6c4009
freehook (void *ptr, const void *caller)
Packit 6c4009
{
Packit 6c4009
  if (pedantic)
Packit 6c4009
    mcheck_check_all ();
Packit 6c4009
  if (ptr)
Packit 6c4009
    {
Packit 6c4009
      struct hdr *hdr = ((struct hdr *) ptr) - 1;
Packit 6c4009
      checkhdr (hdr);
Packit 6c4009
      hdr->magic = MAGICFREE;
Packit 6c4009
      hdr->magic2 = MAGICFREE;
Packit 6c4009
      unlink_blk (hdr);
Packit 6c4009
      hdr->prev = hdr->next = NULL;
Packit 6c4009
      flood (ptr, FREEFLOOD, hdr->size);
Packit 6c4009
      ptr = hdr->block;
Packit 6c4009
    }
Packit 6c4009
  __free_hook = old_free_hook;
Packit 6c4009
  if (old_free_hook != NULL)
Packit 6c4009
    (*old_free_hook)(ptr, caller);
Packit 6c4009
  else
Packit 6c4009
    free (ptr);
Packit 6c4009
  __free_hook = freehook;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
static void *
Packit 6c4009
mallochook (size_t size, const void *caller)
Packit 6c4009
{
Packit 6c4009
  struct hdr *hdr;
Packit 6c4009
Packit 6c4009
  if (pedantic)
Packit 6c4009
    mcheck_check_all ();
Packit 6c4009
Packit 6c4009
  if (size > ~((size_t) 0) - (sizeof (struct hdr) + 1))
Packit 6c4009
    {
Packit 6c4009
      __set_errno (ENOMEM);
Packit 6c4009
      return NULL;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  __malloc_hook = old_malloc_hook;
Packit 6c4009
  if (old_malloc_hook != NULL)
Packit 6c4009
    hdr = (struct hdr *) (*old_malloc_hook)(sizeof (struct hdr) + size + 1,
Packit 6c4009
                                            caller);
Packit 6c4009
  else
Packit 6c4009
    hdr = (struct hdr *) malloc (sizeof (struct hdr) + size + 1);
Packit 6c4009
  __malloc_hook = mallochook;
Packit 6c4009
  if (hdr == NULL)
Packit 6c4009
    return NULL;
Packit 6c4009
Packit 6c4009
  hdr->size = size;
Packit 6c4009
  link_blk (hdr);
Packit 6c4009
  hdr->block = hdr;
Packit 6c4009
  hdr->magic2 = (uintptr_t) hdr ^ MAGICWORD;
Packit 6c4009
  ((char *) &hdr[1])[size] = MAGICBYTE;
Packit 6c4009
  flood ((void *) (hdr + 1), MALLOCFLOOD, size);
Packit 6c4009
  return (void *) (hdr + 1);
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
static void *
Packit 6c4009
memalignhook (size_t alignment, size_t size,
Packit 6c4009
              const void *caller)
Packit 6c4009
{
Packit 6c4009
  struct hdr *hdr;
Packit 6c4009
  size_t slop;
Packit 6c4009
  char *block;
Packit 6c4009
Packit 6c4009
  if (pedantic)
Packit 6c4009
    mcheck_check_all ();
Packit 6c4009
Packit 6c4009
  slop = (sizeof *hdr + alignment - 1) & - alignment;
Packit 6c4009
Packit 6c4009
  if (size > ~((size_t) 0) - (slop + 1))
Packit 6c4009
    {
Packit 6c4009
      __set_errno (ENOMEM);
Packit 6c4009
      return NULL;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  __memalign_hook = old_memalign_hook;
Packit 6c4009
  if (old_memalign_hook != NULL)
Packit 6c4009
    block = (*old_memalign_hook)(alignment, slop + size + 1, caller);
Packit 6c4009
  else
Packit 6c4009
    block = memalign (alignment, slop + size + 1);
Packit 6c4009
  __memalign_hook = memalignhook;
Packit 6c4009
  if (block == NULL)
Packit 6c4009
    return NULL;
Packit 6c4009
Packit 6c4009
  hdr = ((struct hdr *) (block + slop)) - 1;
Packit 6c4009
Packit 6c4009
  hdr->size = size;
Packit 6c4009
  link_blk (hdr);
Packit 6c4009
  hdr->block = (void *) block;
Packit 6c4009
  hdr->magic2 = (uintptr_t) block ^ MAGICWORD;
Packit 6c4009
  ((char *) &hdr[1])[size] = MAGICBYTE;
Packit 6c4009
  flood ((void *) (hdr + 1), MALLOCFLOOD, size);
Packit 6c4009
  return (void *) (hdr + 1);
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
static void *
Packit 6c4009
reallochook (void *ptr, size_t size, const void *caller)
Packit 6c4009
{
Packit 6c4009
  if (size == 0)
Packit 6c4009
    {
Packit 6c4009
      freehook (ptr, caller);
Packit 6c4009
      return NULL;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  struct hdr *hdr;
Packit 6c4009
  size_t osize;
Packit 6c4009
Packit 6c4009
  if (pedantic)
Packit 6c4009
    mcheck_check_all ();
Packit 6c4009
Packit 6c4009
  if (size > ~((size_t) 0) - (sizeof (struct hdr) + 1))
Packit 6c4009
    {
Packit 6c4009
      __set_errno (ENOMEM);
Packit 6c4009
      return NULL;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  if (ptr)
Packit 6c4009
    {
Packit 6c4009
      hdr = ((struct hdr *) ptr) - 1;
Packit 6c4009
      osize = hdr->size;
Packit 6c4009
Packit 6c4009
      checkhdr (hdr);
Packit 6c4009
      unlink_blk (hdr);
Packit 6c4009
      if (size < osize)
Packit 6c4009
        flood ((char *) ptr + size, FREEFLOOD, osize - size);
Packit 6c4009
    }
Packit 6c4009
  else
Packit 6c4009
    {
Packit 6c4009
      osize = 0;
Packit 6c4009
      hdr = NULL;
Packit 6c4009
    }
Packit 6c4009
  __free_hook = old_free_hook;
Packit 6c4009
  __malloc_hook = old_malloc_hook;
Packit 6c4009
  __memalign_hook = old_memalign_hook;
Packit 6c4009
  __realloc_hook = old_realloc_hook;
Packit 6c4009
  if (old_realloc_hook != NULL)
Packit 6c4009
    hdr = (struct hdr *) (*old_realloc_hook)((void *) hdr,
Packit 6c4009
                                             sizeof (struct hdr) + size + 1,
Packit 6c4009
                                             caller);
Packit 6c4009
  else
Packit 6c4009
    hdr = (struct hdr *) realloc ((void *) hdr,
Packit 6c4009
                                  sizeof (struct hdr) + size + 1);
Packit 6c4009
  __free_hook = freehook;
Packit 6c4009
  __malloc_hook = mallochook;
Packit 6c4009
  __memalign_hook = memalignhook;
Packit 6c4009
  __realloc_hook = reallochook;
Packit 6c4009
  if (hdr == NULL)
Packit 6c4009
    return NULL;
Packit 6c4009
Packit 6c4009
  hdr->size = size;
Packit 6c4009
  link_blk (hdr);
Packit 6c4009
  hdr->block = hdr;
Packit 6c4009
  hdr->magic2 = (uintptr_t) hdr ^ MAGICWORD;
Packit 6c4009
  ((char *) &hdr[1])[size] = MAGICBYTE;
Packit 6c4009
  if (size > osize)
Packit 6c4009
    flood ((char *) (hdr + 1) + osize, MALLOCFLOOD, size - osize);
Packit 6c4009
  return (void *) (hdr + 1);
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
__attribute__ ((noreturn))
Packit 6c4009
static void
Packit 6c4009
mabort (enum mcheck_status status)
Packit 6c4009
{
Packit 6c4009
  const char *msg;
Packit 6c4009
  switch (status)
Packit 6c4009
    {
Packit 6c4009
    case MCHECK_OK:
Packit 6c4009
      msg = _ ("memory is consistent, library is buggy\n");
Packit 6c4009
      break;
Packit 6c4009
    case MCHECK_HEAD:
Packit 6c4009
      msg = _ ("memory clobbered before allocated block\n");
Packit 6c4009
      break;
Packit 6c4009
    case MCHECK_TAIL:
Packit 6c4009
      msg = _ ("memory clobbered past end of allocated block\n");
Packit 6c4009
      break;
Packit 6c4009
    case MCHECK_FREE:
Packit 6c4009
      msg = _ ("block freed twice\n");
Packit 6c4009
      break;
Packit 6c4009
    default:
Packit 6c4009
      msg = _ ("bogus mcheck_status, library is buggy\n");
Packit 6c4009
      break;
Packit 6c4009
    }
Packit 6c4009
#ifdef _LIBC
Packit 6c4009
  __libc_fatal (msg);
Packit 6c4009
#else
Packit 6c4009
  fprintf (stderr, "mcheck: %s", msg);
Packit 6c4009
  fflush (stderr);
Packit 6c4009
  abort ();
Packit 6c4009
#endif
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
/* Memory barrier so that GCC does not optimize out the argument.  */
Packit 6c4009
#define malloc_opt_barrier(x) \
Packit 6c4009
  ({ __typeof (x) __x = x; __asm ("" : "+m" (__x)); __x; })
Packit 6c4009
Packit 6c4009
int
Packit 6c4009
mcheck (void (*func) (enum mcheck_status))
Packit 6c4009
{
Packit 6c4009
  abortfunc = (func != NULL) ? func : &mabort;
Packit 6c4009
Packit 6c4009
  /* These hooks may not be safely inserted if malloc is already in use.  */
Packit 6c4009
  if (__malloc_initialized <= 0 && !mcheck_used)
Packit 6c4009
    {
Packit 6c4009
      /* We call malloc() once here to ensure it is initialized.  */
Packit 6c4009
      void *p = malloc (0);
Packit 6c4009
      /* GCC might optimize out the malloc/free pair without a barrier.  */
Packit 6c4009
      p = malloc_opt_barrier (p);
Packit 6c4009
      free (p);
Packit 6c4009
Packit 6c4009
      old_free_hook = __free_hook;
Packit 6c4009
      __free_hook = freehook;
Packit 6c4009
      old_malloc_hook = __malloc_hook;
Packit 6c4009
      __malloc_hook = mallochook;
Packit 6c4009
      old_memalign_hook = __memalign_hook;
Packit 6c4009
      __memalign_hook = memalignhook;
Packit 6c4009
      old_realloc_hook = __realloc_hook;
Packit 6c4009
      __realloc_hook = reallochook;
Packit 6c4009
      mcheck_used = 1;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  return mcheck_used ? 0 : -1;
Packit 6c4009
}
Packit 6c4009
#ifdef _LIBC
Packit 6c4009
libc_hidden_def (mcheck)
Packit 6c4009
#endif
Packit 6c4009
Packit 6c4009
int
Packit 6c4009
mcheck_pedantic (void (*func) (enum mcheck_status))
Packit 6c4009
{
Packit 6c4009
  int res = mcheck (func);
Packit 6c4009
  if (res == 0)
Packit 6c4009
    pedantic = 1;
Packit 6c4009
  return res;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
enum mcheck_status
Packit 6c4009
mprobe (void *ptr)
Packit 6c4009
{
Packit 6c4009
  return mcheck_used ? checkhdr (((struct hdr *) ptr) - 1) : MCHECK_DISABLED;
Packit 6c4009
}