• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1 /*
2  * Copyright (C) 2008 The Android Open Source Project
3  * All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *  * Redistributions of source code must retain the above copyright
9  *    notice, this list of conditions and the following disclaimer.
10  *  * Redistributions in binary form must reproduce the above copyright
11  *    notice, this list of conditions and the following disclaimer in
12  *    the documentation and/or other materials provided with the
13  *    distribution.
14  *
15  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include <android/api-level.h>
30 #include <elf.h>
31 #include <errno.h>
32 #include <malloc.h>
33 #include <stddef.h>
34 #include <stdint.h>
35 #include <stdio.h>
36 #include <stdlib.h>
37 #include <sys/auxv.h>
38 #include <sys/mman.h>
39 
40 #include "async_safe/log.h"
41 #include "heap_tagging.h"
42 #include "libc_init_common.h"
43 #include "platform/bionic/macros.h"
44 #include "platform/bionic/mte.h"
45 #include "platform/bionic/page.h"
46 #include "platform/bionic/reserved_signals.h"
47 #include "private/KernelArgumentBlock.h"
48 #include "private/bionic_asm.h"
49 #include "private/bionic_asm_note.h"
50 #include "private/bionic_call_ifunc_resolver.h"
51 #include "private/bionic_elf_tls.h"
52 #include "private/bionic_globals.h"
53 #include "private/bionic_tls.h"
54 #include "pthread_internal.h"
55 #include "sys/system_properties.h"
56 #include "sysprop_helpers.h"
57 
58 #if __has_feature(hwaddress_sanitizer)
59 #include <sanitizer/hwasan_interface.h>
60 #endif
61 
62 // Leave the variable uninitialized for the sake of the dynamic loader, which
63 // links in this file. The loader will initialize this variable before
64 // relocating itself.
65 #if defined(__i386__)
66 __LIBC_HIDDEN__ void* __libc_sysinfo;
67 #endif
68 
69 extern "C" int __cxa_atexit(void (*)(void *), void *, void *);
70 extern "C" const char* __gnu_basename(const char* path);
71 
call_array(init_func_t ** list,int argc,char * argv[],char * envp[])72 static void call_array(init_func_t** list, int argc, char* argv[], char* envp[]) {
73   // First element is -1, list is null-terminated
74   while (*++list) {
75     (*list)(argc, argv, envp);
76   }
77 }
78 
79 #if defined(__arm__) || defined(__i386__)  // Legacy architectures used REL...
80 extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rel) __rel_iplt_start[], __rel_iplt_end[];
81 
call_ifunc_resolvers()82 static void call_ifunc_resolvers() {
83   if (__rel_iplt_start == nullptr || __rel_iplt_end == nullptr) {
84     // These symbols were not emitted by gold. Gold has code to do so, but for
85     // whatever reason it is not being run. In these cases ifuncs cannot be
86     // resolved, so we do not support using ifuncs in static executables linked
87     // with gold.
88     //
89     // Since they are weak, they will be non-null when linked with bfd/lld and
90     // null when linked with gold.
91     return;
92   }
93 
94   for (ElfW(Rel)* r = __rel_iplt_start; r != __rel_iplt_end; ++r) {
95     ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
96     ElfW(Addr) resolver = *offset;
97     *offset = __bionic_call_ifunc_resolver(resolver);
98   }
99 }
100 #else  // ...but modern architectures use RELA instead.
101 extern __LIBC_HIDDEN__ __attribute__((weak)) ElfW(Rela) __rela_iplt_start[], __rela_iplt_end[];
102 
call_ifunc_resolvers()103 static void call_ifunc_resolvers() {
104   if (__rela_iplt_start == nullptr || __rela_iplt_end == nullptr) {
105     // These symbols were not emitted by gold. Gold has code to do so, but for
106     // whatever reason it is not being run. In these cases ifuncs cannot be
107     // resolved, so we do not support using ifuncs in static executables linked
108     // with gold.
109     //
110     // Since they are weak, they will be non-null when linked with bfd/lld and
111     // null when linked with gold.
112     return;
113   }
114 
115   for (ElfW(Rela)* r = __rela_iplt_start; r != __rela_iplt_end; ++r) {
116     ElfW(Addr)* offset = reinterpret_cast<ElfW(Addr)*>(r->r_offset);
117     ElfW(Addr) resolver = r->r_addend;
118     *offset = __bionic_call_ifunc_resolver(resolver);
119   }
120 }
121 #endif
122 
apply_gnu_relro()123 static void apply_gnu_relro() {
124   ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
125   unsigned long int phdr_ct = getauxval(AT_PHNUM);
126 
127   for (ElfW(Phdr)* phdr = phdr_start; phdr < (phdr_start + phdr_ct); phdr++) {
128     if (phdr->p_type != PT_GNU_RELRO) {
129       continue;
130     }
131 
132     ElfW(Addr) seg_page_start = PAGE_START(phdr->p_vaddr);
133     ElfW(Addr) seg_page_end = PAGE_END(phdr->p_vaddr + phdr->p_memsz);
134 
135     // Check return value here? What do we do if we fail?
136     mprotect(reinterpret_cast<void*>(seg_page_start), seg_page_end - seg_page_start, PROT_READ);
137   }
138 }
139 
layout_static_tls(KernelArgumentBlock & args)140 static void layout_static_tls(KernelArgumentBlock& args) {
141   StaticTlsLayout& layout = __libc_shared_globals()->static_tls_layout;
142   layout.reserve_bionic_tls();
143 
144   const char* progname = args.argv[0];
145   ElfW(Phdr)* phdr_start = reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR));
146   size_t phdr_ct = getauxval(AT_PHNUM);
147 
148   static TlsModule mod;
149   TlsModules& modules = __libc_shared_globals()->tls_modules;
150   if (__bionic_get_tls_segment(phdr_start, phdr_ct, 0, &mod.segment)) {
151     if (!__bionic_check_tls_alignment(&mod.segment.alignment)) {
152       async_safe_fatal("error: TLS segment alignment in \"%s\" is not a power of 2: %zu\n",
153                        progname, mod.segment.alignment);
154     }
155     mod.static_offset = layout.reserve_exe_segment_and_tcb(&mod.segment, progname);
156     mod.first_generation = kTlsGenerationFirst;
157 
158     modules.module_count = 1;
159     modules.static_module_count = 1;
160     modules.module_table = &mod;
161   } else {
162     layout.reserve_exe_segment_and_tcb(nullptr, progname);
163   }
164   // Enable the fast path in __tls_get_addr.
165   __libc_tls_generation_copy = modules.generation;
166 
167   layout.finish_layout();
168 }
169 
170 #ifdef __aarch64__
__read_memtag_note(const ElfW (Nhdr)* note,const char * name,const char * desc,unsigned * result)171 static bool __read_memtag_note(const ElfW(Nhdr)* note, const char* name, const char* desc,
172                                unsigned* result) {
173   if (note->n_type != NT_ANDROID_TYPE_MEMTAG) {
174     return false;
175   }
176   if (note->n_namesz != 8 || strncmp(name, "Android", 8) != 0) {
177     return false;
178   }
179   // Previously (in Android 12), if the note was != 4 bytes, we check-failed
180   // here. Let's be more permissive to allow future expansion.
181   if (note->n_descsz < 4) {
182     async_safe_fatal("unrecognized android.memtag note: n_descsz = %d, expected >= 4",
183                      note->n_descsz);
184   }
185   *result = *reinterpret_cast<const ElfW(Word)*>(desc);
186   return true;
187 }
188 
__get_memtag_note(const ElfW (Phdr)* phdr_start,size_t phdr_ct,const ElfW (Addr)load_bias)189 static unsigned __get_memtag_note(const ElfW(Phdr)* phdr_start, size_t phdr_ct,
190                                   const ElfW(Addr) load_bias) {
191   for (size_t i = 0; i < phdr_ct; ++i) {
192     const ElfW(Phdr)* phdr = &phdr_start[i];
193     if (phdr->p_type != PT_NOTE) {
194       continue;
195     }
196     ElfW(Addr) p = load_bias + phdr->p_vaddr;
197     ElfW(Addr) note_end = load_bias + phdr->p_vaddr + phdr->p_memsz;
198     while (p + sizeof(ElfW(Nhdr)) <= note_end) {
199       const ElfW(Nhdr)* note = reinterpret_cast<const ElfW(Nhdr)*>(p);
200       p += sizeof(ElfW(Nhdr));
201       const char* name = reinterpret_cast<const char*>(p);
202       p += align_up(note->n_namesz, 4);
203       const char* desc = reinterpret_cast<const char*>(p);
204       p += align_up(note->n_descsz, 4);
205       if (p > note_end) {
206         break;
207       }
208       unsigned ret;
209       if (__read_memtag_note(note, name, desc, &ret)) {
210         return ret;
211       }
212     }
213   }
214   return 0;
215 }
216 
217 // Returns true if there's an environment setting (either sysprop or env var)
218 // that should overwrite the ELF note, and places the equivalent heap tagging
219 // level into *level.
get_environment_memtag_setting(HeapTaggingLevel * level)220 static bool get_environment_memtag_setting(HeapTaggingLevel* level) {
221   static const char kMemtagPrognameSyspropPrefix[] = "arm64.memtag.process.";
222   static const char kMemtagGlobalSysprop[] = "persist.arm64.memtag.default";
223   static const char kMemtagOverrideSyspropPrefix[] =
224       "persist.device_config.memory_safety_native.mode_override.process.";
225 
226   const char* progname = __libc_shared_globals()->init_progname;
227   if (progname == nullptr) return false;
228 
229   const char* basename = __gnu_basename(progname);
230 
231   char options_str[PROP_VALUE_MAX];
232   char sysprop_name[512];
233   async_safe_format_buffer(sysprop_name, sizeof(sysprop_name), "%s%s", kMemtagPrognameSyspropPrefix,
234                            basename);
235   char remote_sysprop_name[512];
236   async_safe_format_buffer(remote_sysprop_name, sizeof(remote_sysprop_name), "%s%s",
237                            kMemtagOverrideSyspropPrefix, basename);
238   const char* sys_prop_names[] = {sysprop_name, remote_sysprop_name, kMemtagGlobalSysprop};
239 
240   if (!get_config_from_env_or_sysprops("MEMTAG_OPTIONS", sys_prop_names, arraysize(sys_prop_names),
241                                        options_str, sizeof(options_str))) {
242     return false;
243   }
244 
245   if (strcmp("sync", options_str) == 0) {
246     *level = M_HEAP_TAGGING_LEVEL_SYNC;
247   } else if (strcmp("async", options_str) == 0) {
248     *level = M_HEAP_TAGGING_LEVEL_ASYNC;
249   } else if (strcmp("off", options_str) == 0) {
250     *level = M_HEAP_TAGGING_LEVEL_TBI;
251   } else {
252     async_safe_format_log(
253         ANDROID_LOG_ERROR, "libc",
254         "unrecognized memtag level: \"%s\" (options are \"sync\", \"async\", or \"off\").",
255         options_str);
256     return false;
257   }
258 
259   return true;
260 }
261 
262 // Returns the initial heap tagging level. Note: This function will never return
263 // M_HEAP_TAGGING_LEVEL_NONE, if MTE isn't enabled for this process we enable
264 // M_HEAP_TAGGING_LEVEL_TBI.
__get_heap_tagging_level(const void * phdr_start,size_t phdr_ct,uintptr_t load_bias,bool * stack)265 static HeapTaggingLevel __get_heap_tagging_level(const void* phdr_start, size_t phdr_ct,
266                                                  uintptr_t load_bias, bool* stack) {
267   unsigned note_val =
268       __get_memtag_note(reinterpret_cast<const ElfW(Phdr)*>(phdr_start), phdr_ct, load_bias);
269   *stack = note_val & NT_MEMTAG_STACK;
270 
271   HeapTaggingLevel level;
272   if (get_environment_memtag_setting(&level)) return level;
273 
274   // Note, previously (in Android 12), any value outside of bits [0..3] resulted
275   // in a check-fail. In order to be permissive of further extensions, we
276   // relaxed this restriction.
277   if (!(note_val & (NT_MEMTAG_HEAP | NT_MEMTAG_STACK))) return M_HEAP_TAGGING_LEVEL_TBI;
278 
279   unsigned mode = note_val & NT_MEMTAG_LEVEL_MASK;
280   switch (mode) {
281     case NT_MEMTAG_LEVEL_NONE:
282       // Note, previously (in Android 12), NT_MEMTAG_LEVEL_NONE was
283       // NT_MEMTAG_LEVEL_DEFAULT, which implied SYNC mode. This was never used
284       // by anyone, but we note it (heh) here for posterity, in case the zero
285       // level becomes meaningful, and binaries with this note can be executed
286       // on Android 12 devices.
287       return M_HEAP_TAGGING_LEVEL_TBI;
288     case NT_MEMTAG_LEVEL_ASYNC:
289       return M_HEAP_TAGGING_LEVEL_ASYNC;
290     case NT_MEMTAG_LEVEL_SYNC:
291     default:
292       // We allow future extensions to specify mode 3 (currently unused), with
293       // the idea that it might be used for ASYMM mode or something else. On
294       // this version of Android, it falls back to SYNC mode.
295       return M_HEAP_TAGGING_LEVEL_SYNC;
296   }
297 }
298 
299 // Figure out the desired memory tagging mode (sync/async, heap/globals/stack) for this executable.
300 // This function is called from the linker before the main executable is relocated.
__libc_init_mte(const void * phdr_start,size_t phdr_ct,uintptr_t load_bias,void * stack_top)301 __attribute__((no_sanitize("hwaddress", "memtag"))) void __libc_init_mte(const void* phdr_start,
302                                                                          size_t phdr_ct,
303                                                                          uintptr_t load_bias,
304                                                                          void* stack_top) {
305   bool memtag_stack;
306   HeapTaggingLevel level = __get_heap_tagging_level(phdr_start, phdr_ct, load_bias, &memtag_stack);
307   char* env = getenv("BIONIC_MEMTAG_UPGRADE_SECS");
308   static const char kAppProcessName[] = "app_process64";
309   const char* progname = __libc_shared_globals()->init_progname;
310   progname = progname ? __gnu_basename(progname) : nullptr;
311   if (progname &&
312       strncmp(progname, kAppProcessName, sizeof(kAppProcessName)) == 0) {
313     // disable timed upgrade for zygote, as the thread spawned will violate the requirement
314     // that it be single-threaded.
315     env = nullptr;
316   }
317   int64_t timed_upgrade = 0;
318   if (env) {
319     char* endptr;
320     timed_upgrade = strtoll(env, &endptr, 10);
321     if (*endptr != '\0' || timed_upgrade < 0) {
322       async_safe_format_log(ANDROID_LOG_ERROR, "libc",
323                             "Invalid value for BIONIC_MEMTAG_UPGRADE_SECS: %s",
324                             env);
325       timed_upgrade = 0;
326     }
327     // Make sure that this does not get passed to potential processes inheriting
328     // this environment.
329     unsetenv("BIONIC_MEMTAG_UPGRADE_SECS");
330   }
331   if (timed_upgrade) {
332     if (level == M_HEAP_TAGGING_LEVEL_ASYNC) {
333       async_safe_format_log(ANDROID_LOG_INFO, "libc",
334                             "Attempting timed MTE upgrade from async to sync.");
335       __libc_shared_globals()->heap_tagging_upgrade_timer_sec = timed_upgrade;
336       level = M_HEAP_TAGGING_LEVEL_SYNC;
337     } else if (level != M_HEAP_TAGGING_LEVEL_SYNC) {
338       async_safe_format_log(
339           ANDROID_LOG_ERROR, "libc",
340           "Requested timed MTE upgrade from invalid %s to sync. Ignoring.",
341           DescribeTaggingLevel(level));
342     }
343   }
344   if (level == M_HEAP_TAGGING_LEVEL_SYNC || level == M_HEAP_TAGGING_LEVEL_ASYNC) {
345     unsigned long prctl_arg = PR_TAGGED_ADDR_ENABLE | PR_MTE_TAG_SET_NONZERO;
346     prctl_arg |= (level == M_HEAP_TAGGING_LEVEL_SYNC) ? PR_MTE_TCF_SYNC : PR_MTE_TCF_ASYNC;
347 
348     // When entering ASYNC mode, specify that we want to allow upgrading to SYNC by OR'ing in the
349     // SYNC flag. But if the kernel doesn't support specifying multiple TCF modes, fall back to
350     // specifying a single mode.
351     if (prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg | PR_MTE_TCF_SYNC, 0, 0, 0) == 0 ||
352         prctl(PR_SET_TAGGED_ADDR_CTRL, prctl_arg, 0, 0, 0) == 0) {
353       __libc_shared_globals()->initial_heap_tagging_level = level;
354       __libc_shared_globals()->initial_memtag_stack = memtag_stack;
355 
356       if (memtag_stack) {
357         void* page_start =
358             reinterpret_cast<void*>(PAGE_START(reinterpret_cast<uintptr_t>(stack_top)));
359         if (mprotect(page_start, PAGE_SIZE, PROT_READ | PROT_WRITE | PROT_MTE | PROT_GROWSDOWN)) {
360           async_safe_fatal("error: failed to set PROT_MTE on main thread stack: %s\n",
361                            strerror(errno));
362         }
363       }
364 
365       return;
366     }
367   }
368 
369   // MTE was either not enabled, or wasn't supported on this device. Try and use
370   // TBI.
371   if (prctl(PR_SET_TAGGED_ADDR_CTRL, PR_TAGGED_ADDR_ENABLE, 0, 0, 0) == 0) {
372     __libc_shared_globals()->initial_heap_tagging_level = M_HEAP_TAGGING_LEVEL_TBI;
373   }
374   // We did not enable MTE, so we do not need to arm the upgrade timer.
375   __libc_shared_globals()->heap_tagging_upgrade_timer_sec = 0;
376 }
377 #else   // __aarch64__
__libc_init_mte(const void *,size_t,uintptr_t,void *)378 void __libc_init_mte(const void*, size_t, uintptr_t, void*) {}
379 #endif  // __aarch64__
380 
__libc_init_profiling_handlers()381 void __libc_init_profiling_handlers() {
382   // The dynamic variant of this function is more interesting, but this
383   // at least ensures that static binaries aren't killed by the kernel's
384   // default disposition for these two real-time signals that would have
385   // handlers installed if this was a dynamic binary.
386   signal(BIONIC_SIGNAL_PROFILER, SIG_IGN);
387   signal(BIONIC_SIGNAL_ART_PROFILER, SIG_IGN);
388 }
389 
__real_libc_init(void * raw_args,void (* onexit)(void)__unused,int (* slingshot)(int,char **,char **),structors_array_t const * const structors,bionic_tcb * temp_tcb)390 __attribute__((no_sanitize("memtag"))) __noreturn static void __real_libc_init(
391     void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
392     structors_array_t const* const structors, bionic_tcb* temp_tcb) {
393   BIONIC_STOP_UNWIND;
394 
395   // Initialize TLS early so system calls and errno work.
396   KernelArgumentBlock args(raw_args);
397   __libc_init_main_thread_early(args, temp_tcb);
398   __libc_init_main_thread_late();
399   __libc_init_globals();
400   __libc_shared_globals()->init_progname = args.argv[0];
401   __libc_init_AT_SECURE(args.envp);
402   layout_static_tls(args);
403   __libc_init_main_thread_final();
404   __libc_init_common();
405   __libc_init_mte(reinterpret_cast<ElfW(Phdr)*>(getauxval(AT_PHDR)), getauxval(AT_PHNUM),
406                   /*load_bias = */ 0, /*stack_top = */ raw_args);
407   __libc_init_scudo();
408   __libc_init_profiling_handlers();
409   __libc_init_fork_handler();
410 
411   call_ifunc_resolvers();
412   apply_gnu_relro();
413 
414   // Several Linux ABIs don't pass the onexit pointer, and the ones that
415   // do never use it.  Therefore, we ignore it.
416 
417   call_array(structors->preinit_array, args.argc, args.argv, args.envp);
418   call_array(structors->init_array, args.argc, args.argv, args.envp);
419 
420   // The executable may have its own destructors listed in its .fini_array
421   // so we need to ensure that these are called when the program exits
422   // normally.
423   if (structors->fini_array != nullptr) {
424     __cxa_atexit(__libc_fini,structors->fini_array,nullptr);
425   }
426 
427   __libc_init_mte_late();
428 
429   exit(slingshot(args.argc, args.argv, args.envp));
430 }
431 
432 extern "C" void __hwasan_init_static();
433 
434 // This __libc_init() is only used for static executables, and is called from crtbegin.c.
435 //
436 // The 'structors' parameter contains pointers to various initializer
437 // arrays that must be run before the program's 'main' routine is launched.
__libc_init(void * raw_args,void (* onexit)(void)__unused,int (* slingshot)(int,char **,char **),structors_array_t const * const structors)438 __attribute__((no_sanitize("hwaddress", "memtag"))) __noreturn void __libc_init(
439     void* raw_args, void (*onexit)(void) __unused, int (*slingshot)(int, char**, char**),
440     structors_array_t const* const structors) {
441   bionic_tcb temp_tcb = {};
442 #if __has_feature(hwaddress_sanitizer)
443   // Install main thread TLS early. It will be initialized later in __libc_init_main_thread. For now
444   // all we need is access to TLS_SLOT_SANITIZER.
445   __set_tls(&temp_tcb.tls_slot(0));
446   // Initialize HWASan enough to run instrumented code. This sets up TLS_SLOT_SANITIZER, among other
447   // things.
448   __hwasan_init_static();
449   // We are ready to run HWASan-instrumented code, proceed with libc initialization...
450 #endif
451   __real_libc_init(raw_args, onexit, slingshot, structors, &temp_tcb);
452 }
453 
454 static int g_target_sdk_version{__ANDROID_API__};
455 
android_get_application_target_sdk_version()456 extern "C" int android_get_application_target_sdk_version() {
457   return g_target_sdk_version;
458 }
459 
android_set_application_target_sdk_version(int target)460 extern "C" void android_set_application_target_sdk_version(int target) {
461   g_target_sdk_version = target;
462   __libc_set_target_sdk_version(target);
463 }
464 
465 // This function is called in the dynamic linker before ifunc resolvers have run, so this file is
466 // compiled with -ffreestanding to avoid implicit string.h function calls. (It shouldn't strictly
467 // be necessary, though.)
__libc_shared_globals()468 __LIBC_HIDDEN__ libc_shared_globals* __libc_shared_globals() {
469   static libc_shared_globals globals;
470   return &globals;
471 }
472