xref: /xnu-10002.61.3/san/memory/ubsan_log.c (revision 0f4c859e951fba394238ab619495c4e1d54d0f34)
1*0f4c859eSApple OSS Distributions /*
2*0f4c859eSApple OSS Distributions  * Copyright (c) 2018-2021 Apple Inc. All rights reserved.
3*0f4c859eSApple OSS Distributions  *
4*0f4c859eSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*0f4c859eSApple OSS Distributions  *
6*0f4c859eSApple OSS Distributions  * This file contains Original Code and/or Modifications of Original Code
7*0f4c859eSApple OSS Distributions  * as defined in and that are subject to the Apple Public Source License
8*0f4c859eSApple OSS Distributions  * Version 2.0 (the 'License'). You may not use this file except in
9*0f4c859eSApple OSS Distributions  * compliance with the License. The rights granted to you under the License
10*0f4c859eSApple OSS Distributions  * may not be used to create, or enable the creation or redistribution of,
11*0f4c859eSApple OSS Distributions  * unlawful or unlicensed copies of an Apple operating system, or to
12*0f4c859eSApple OSS Distributions  * circumvent, violate, or enable the circumvention or violation of, any
13*0f4c859eSApple OSS Distributions  * terms of an Apple operating system software license agreement.
14*0f4c859eSApple OSS Distributions  *
15*0f4c859eSApple OSS Distributions  * Please obtain a copy of the License at
16*0f4c859eSApple OSS Distributions  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*0f4c859eSApple OSS Distributions  *
18*0f4c859eSApple OSS Distributions  * The Original Code and all software distributed under the License are
19*0f4c859eSApple OSS Distributions  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*0f4c859eSApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*0f4c859eSApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*0f4c859eSApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*0f4c859eSApple OSS Distributions  * Please see the License for the specific language governing rights and
24*0f4c859eSApple OSS Distributions  * limitations under the License.
25*0f4c859eSApple OSS Distributions  *
26*0f4c859eSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*0f4c859eSApple OSS Distributions  */
28*0f4c859eSApple OSS Distributions 
29*0f4c859eSApple OSS Distributions #include <os/atomic_private.h>
30*0f4c859eSApple OSS Distributions #include <kern/cpu_data.h>
31*0f4c859eSApple OSS Distributions #include <kern/kalloc.h>
32*0f4c859eSApple OSS Distributions #include <kern/simple_lock.h> // hw_wait_while_equals
33*0f4c859eSApple OSS Distributions #include <libkern/libkern.h>
34*0f4c859eSApple OSS Distributions #include <sys/sysctl.h>
35*0f4c859eSApple OSS Distributions #include "ubsan.h"
36*0f4c859eSApple OSS Distributions 
37*0f4c859eSApple OSS Distributions /*
38*0f4c859eSApple OSS Distributions  * To dump the violation log:
39*0f4c859eSApple OSS Distributions  *   $ sysctl kern.ubsan.log
40*0f4c859eSApple OSS Distributions  *
41*0f4c859eSApple OSS Distributions  * To reset:
42*0f4c859eSApple OSS Distributions  *   $ sysctl kern.ubsan.logentries=0
43*0f4c859eSApple OSS Distributions  */
44*0f4c859eSApple OSS Distributions 
45*0f4c859eSApple OSS Distributions static const size_t ubsan_log_size = 2048;
46*0f4c859eSApple OSS Distributions ubsan_violation_t ubsan_log[ubsan_log_size];
47*0f4c859eSApple OSS Distributions 
48*0f4c859eSApple OSS Distributions /*
49*0f4c859eSApple OSS Distributions  * Implement a fixed-size buffer FIFO, similar to the Chase-Lev DeQueue.
50*0f4c859eSApple OSS Distributions  *
51*0f4c859eSApple OSS Distributions  * See https://fzn.fr/readings/ppopp13.pdf for explanations on barriers.
52*0f4c859eSApple OSS Distributions  */
53*0f4c859eSApple OSS Distributions _Atomic size_t ubsan_log_head = 0; /* first valid entry */
54*0f4c859eSApple OSS Distributions _Atomic size_t ubsan_log_tail = 0; /* next free slot (reader) */
55*0f4c859eSApple OSS Distributions _Atomic size_t ubsan_log_next = 0; /* next free slot (writer) */
56*0f4c859eSApple OSS Distributions 
57*0f4c859eSApple OSS Distributions static const bool ubsan_logging = true;
58*0f4c859eSApple OSS Distributions 
59*0f4c859eSApple OSS Distributions static inline size_t
next_entry(size_t x)60*0f4c859eSApple OSS Distributions next_entry(size_t x)
61*0f4c859eSApple OSS Distributions {
62*0f4c859eSApple OSS Distributions 	return (x + 1) % ubsan_log_size;
63*0f4c859eSApple OSS Distributions }
64*0f4c859eSApple OSS Distributions 
65*0f4c859eSApple OSS Distributions void
ubsan_log_append(ubsan_violation_t * violation)66*0f4c859eSApple OSS Distributions ubsan_log_append(ubsan_violation_t *violation)
67*0f4c859eSApple OSS Distributions {
68*0f4c859eSApple OSS Distributions 	if (!ubsan_logging) {
69*0f4c859eSApple OSS Distributions 		return;
70*0f4c859eSApple OSS Distributions 	}
71*0f4c859eSApple OSS Distributions 
72*0f4c859eSApple OSS Distributions 	/* reserve a slot */
73*0f4c859eSApple OSS Distributions 	size_t i, e, n;
74*0f4c859eSApple OSS Distributions 
75*0f4c859eSApple OSS Distributions 	disable_preemption();
76*0f4c859eSApple OSS Distributions 
77*0f4c859eSApple OSS Distributions 	os_atomic_rmw_loop(&ubsan_log_next, i, n, relaxed, {
78*0f4c859eSApple OSS Distributions 		n = next_entry(i);
79*0f4c859eSApple OSS Distributions 		if (n == os_atomic_load(&ubsan_log_tail, acquire)) {
80*0f4c859eSApple OSS Distributions 		        enable_preemption();
81*0f4c859eSApple OSS Distributions 		        return; /* full */
82*0f4c859eSApple OSS Distributions 		}
83*0f4c859eSApple OSS Distributions 	});
84*0f4c859eSApple OSS Distributions 
85*0f4c859eSApple OSS Distributions 	ubsan_log[i] = *violation;
86*0f4c859eSApple OSS Distributions 	os_atomic_thread_fence(release);
87*0f4c859eSApple OSS Distributions 
88*0f4c859eSApple OSS Distributions 	/* make the entry available */
89*0f4c859eSApple OSS Distributions again:
90*0f4c859eSApple OSS Distributions 	os_atomic_rmw_loop(&ubsan_log_head, e, n, relaxed, {
91*0f4c859eSApple OSS Distributions 		if (e != i) {
92*0f4c859eSApple OSS Distributions 		        // we need to wait for another enqueuer
93*0f4c859eSApple OSS Distributions 		        os_atomic_rmw_loop_give_up({
94*0f4c859eSApple OSS Distributions 				hw_wait_while_equals_long(&ubsan_log_head, e);
95*0f4c859eSApple OSS Distributions 				goto again;
96*0f4c859eSApple OSS Distributions 			});
97*0f4c859eSApple OSS Distributions 		}
98*0f4c859eSApple OSS Distributions 	});
99*0f4c859eSApple OSS Distributions 
100*0f4c859eSApple OSS Distributions 	enable_preemption();
101*0f4c859eSApple OSS Distributions }
102*0f4c859eSApple OSS Distributions 
103*0f4c859eSApple OSS Distributions static size_t
ubsan_log_recorded(size_t head,size_t tail)104*0f4c859eSApple OSS Distributions ubsan_log_recorded(size_t head, size_t tail)
105*0f4c859eSApple OSS Distributions {
106*0f4c859eSApple OSS Distributions 	if (head >= tail) {
107*0f4c859eSApple OSS Distributions 		return head - tail;
108*0f4c859eSApple OSS Distributions 	}
109*0f4c859eSApple OSS Distributions 	return ubsan_log_size - (tail - head + 1);
110*0f4c859eSApple OSS Distributions }
111*0f4c859eSApple OSS Distributions 
112*0f4c859eSApple OSS Distributions static int
113*0f4c859eSApple OSS Distributions sysctl_ubsan_log_dump SYSCTL_HANDLER_ARGS
114*0f4c859eSApple OSS Distributions {
115*0f4c859eSApple OSS Distributions #pragma unused(oidp, arg1, arg2)
116*0f4c859eSApple OSS Distributions 	const size_t buf_size = ubsan_log_size * 256;
117*0f4c859eSApple OSS Distributions 	size_t head, tail;
118*0f4c859eSApple OSS Distributions 
119*0f4c859eSApple OSS Distributions 	head = os_atomic_load(&ubsan_log_head, relaxed);
120*0f4c859eSApple OSS Distributions 	os_atomic_thread_fence(seq_cst);
121*0f4c859eSApple OSS Distributions 	tail = os_atomic_load(&ubsan_log_tail, relaxed);
122*0f4c859eSApple OSS Distributions 
123*0f4c859eSApple OSS Distributions 	size_t nentries = ubsan_log_recorded(head, tail);
124*0f4c859eSApple OSS Distributions 	if (nentries == 0) {
125*0f4c859eSApple OSS Distributions 		return 0; /* log is empty */
126*0f4c859eSApple OSS Distributions 	}
127*0f4c859eSApple OSS Distributions 
128*0f4c859eSApple OSS Distributions 	char *buf = kalloc_data(buf_size, Z_WAITOK | Z_ZERO);
129*0f4c859eSApple OSS Distributions 	if (!buf) {
130*0f4c859eSApple OSS Distributions 		return 0;
131*0f4c859eSApple OSS Distributions 	}
132*0f4c859eSApple OSS Distributions 
133*0f4c859eSApple OSS Distributions 	ubsan_buf_t ubsan_buf;
134*0f4c859eSApple OSS Distributions 	ubsan_json_init(&ubsan_buf, buf, buf_size);
135*0f4c859eSApple OSS Distributions 	ubsan_json_begin(&ubsan_buf, nentries);
136*0f4c859eSApple OSS Distributions 
137*0f4c859eSApple OSS Distributions 	for (size_t i = tail; i != head; i = next_entry(i)) {
138*0f4c859eSApple OSS Distributions 		if (!ubsan_json_format(&ubsan_log[i], &ubsan_buf)) {
139*0f4c859eSApple OSS Distributions 			break;
140*0f4c859eSApple OSS Distributions 		}
141*0f4c859eSApple OSS Distributions 	}
142*0f4c859eSApple OSS Distributions 
143*0f4c859eSApple OSS Distributions 	size_t buf_written = ubsan_json_finish(&ubsan_buf);
144*0f4c859eSApple OSS Distributions 
145*0f4c859eSApple OSS Distributions 	int err = SYSCTL_OUT(req, buf, buf_written);
146*0f4c859eSApple OSS Distributions 
147*0f4c859eSApple OSS Distributions 	kfree_data(buf, buf_size);
148*0f4c859eSApple OSS Distributions 	return err;
149*0f4c859eSApple OSS Distributions }
150*0f4c859eSApple OSS Distributions 
151*0f4c859eSApple OSS Distributions static int
152*0f4c859eSApple OSS Distributions sysctl_ubsan_log_entries SYSCTL_HANDLER_ARGS
153*0f4c859eSApple OSS Distributions {
154*0f4c859eSApple OSS Distributions #pragma unused(oidp, arg1, arg2)
155*0f4c859eSApple OSS Distributions 	size_t head, tail;
156*0f4c859eSApple OSS Distributions 
157*0f4c859eSApple OSS Distributions 	head = os_atomic_load(&ubsan_log_head, relaxed);
158*0f4c859eSApple OSS Distributions 	os_atomic_thread_fence(seq_cst);
159*0f4c859eSApple OSS Distributions 	tail = os_atomic_load(&ubsan_log_tail, relaxed);
160*0f4c859eSApple OSS Distributions 
161*0f4c859eSApple OSS Distributions 	size_t nentries = ubsan_log_recorded(head, tail);
162*0f4c859eSApple OSS Distributions 	int changed = 0;
163*0f4c859eSApple OSS Distributions 	int err = sysctl_io_number(req, nentries, sizeof(nentries), &nentries, &changed);
164*0f4c859eSApple OSS Distributions 
165*0f4c859eSApple OSS Distributions 	if (err || !changed) {
166*0f4c859eSApple OSS Distributions 		return err;
167*0f4c859eSApple OSS Distributions 	}
168*0f4c859eSApple OSS Distributions 	if (nentries != 0) {
169*0f4c859eSApple OSS Distributions 		return EINVAL;
170*0f4c859eSApple OSS Distributions 	}
171*0f4c859eSApple OSS Distributions 
172*0f4c859eSApple OSS Distributions 	os_atomic_store(&ubsan_log_tail, head, relaxed);
173*0f4c859eSApple OSS Distributions 
174*0f4c859eSApple OSS Distributions 	return 0;
175*0f4c859eSApple OSS Distributions }
176*0f4c859eSApple OSS Distributions 
177*0f4c859eSApple OSS Distributions SYSCTL_DECL(ubsan);
178*0f4c859eSApple OSS Distributions SYSCTL_NODE(_kern, OID_AUTO, ubsan, CTLFLAG_RW | CTLFLAG_LOCKED, 0, "");
179*0f4c859eSApple OSS Distributions 
180*0f4c859eSApple OSS Distributions SYSCTL_COMPAT_UINT(_kern_ubsan, OID_AUTO, logsize, CTLFLAG_RD, NULL, (unsigned)ubsan_log_size, "");
181*0f4c859eSApple OSS Distributions 
182*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_ubsan, OID_AUTO, logentries,
183*0f4c859eSApple OSS Distributions     CTLTYPE_INT | CTLFLAG_RW,
184*0f4c859eSApple OSS Distributions     0, 0, sysctl_ubsan_log_entries, "I", "");
185*0f4c859eSApple OSS Distributions 
186*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_ubsan, OID_AUTO, log,
187*0f4c859eSApple OSS Distributions     CTLTYPE_STRING | CTLFLAG_RD | CTLFLAG_MASKED,
188*0f4c859eSApple OSS Distributions     0, 0, sysctl_ubsan_log_dump, "A", "");
189