]> git.ipfire.org Git - thirdparty/glibc.git/blame - malloc/mcheck.c
Prefer https to http for gnu.org and fsf.org URLs
[thirdparty/glibc.git] / malloc / mcheck.c
CommitLineData
6d52618b 1/* Standard debugging hooks for `malloc'.
04277e02 2 Copyright (C) 1990-2019 Free Software Foundation, Inc.
41bdb6e2 3 This file is part of the GNU C Library.
6d52618b
UD
4 Written May 1989 by Mike Haertel.
5
41bdb6e2
AJ
6 The GNU C Library is free software; you can redistribute it and/or
7 modify it under the terms of the GNU Lesser General Public
8 License as published by the Free Software Foundation; either
9 version 2.1 of the License, or (at your option) any later version.
6d52618b 10
41bdb6e2 11 The GNU C Library is distributed in the hope that it will be useful,
6d52618b
UD
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
41bdb6e2 14 Lesser General Public License for more details.
6d52618b 15
41bdb6e2 16 You should have received a copy of the GNU Lesser General Public
59ba27a6 17 License along with the GNU C Library; if not, see
5a82c748 18 <https://www.gnu.org/licenses/>. */
6d52618b 19
6c8dbf00 20#ifndef _MALLOC_INTERNAL
9756dfe1
UD
21# define _MALLOC_INTERNAL
22# include <malloc.h>
23# include <mcheck.h>
8e605e78 24# include <stdint.h>
9756dfe1 25# include <stdio.h>
4360eafd 26# include <libintl.h>
3b111893 27# include <errno.h>
6d52618b
UD
28#endif
29
30/* Old hook values. */
f17a4233
JM
31static void (*old_free_hook)(void *ptr, const void *);
32static void *(*old_malloc_hook) (size_t size, const void *);
33static void *(*old_memalign_hook) (size_t alignment, size_t size,
34 const void *);
35static void *(*old_realloc_hook) (void *ptr, size_t size,
36 const void *);
6d52618b
UD
37
38/* Function to call when something awful happens. */
b80163bd 39static void (*abortfunc) (enum mcheck_status);
6d52618b
UD
40
41/* Arbitrary magical numbers. */
6c8dbf00
OB
42#define MAGICWORD 0xfedabeeb
43#define MAGICFREE 0xd8675309
44#define MAGICBYTE ((char) 0xd7)
45#define MALLOCFLOOD ((char) 0x93)
46#define FREEFLOOD ((char) 0x95)
6d52618b
UD
47
48struct hdr
6c8dbf00
OB
49{
50 size_t size; /* Exact size requested by user. */
51 unsigned long int magic; /* Magic number to check header integrity. */
52 struct hdr *prev;
53 struct hdr *next;
f17a4233 54 void *block; /* Real block allocated, for memalign. */
6c8dbf00
OB
55 unsigned long int magic2; /* Extra, keeps us doubleword aligned. */
56};
6d52618b 57
8e605e78
UD
58/* This is the beginning of the list of all memory blocks allocated.
59 It is only constructed if the pedantic testing is requested. */
60static struct hdr *root;
61
adef3744
UD
62static int mcheck_used;
63
8e605e78
UD
64/* Nonzero if pedentic checking of all blocks is requested. */
65static int pedantic;
66
9756dfe1
UD
67#if defined _LIBC || defined STDC_HEADERS || defined USG
68# include <string.h>
69# define flood memset
6d52618b 70#else
f17a4233 71static void flood (void *, int, size_t);
9d46370c 72static void
f17a4233 73flood (void *ptr, int val, size_t size)
6d52618b
UD
74{
75 char *cp = ptr;
76 while (size--)
77 *cp++ = val;
78}
79#endif
80
6d52618b 81static enum mcheck_status
b80163bd 82checkhdr (const struct hdr *hdr)
6d52618b
UD
83{
84 enum mcheck_status status;
adef3744
UD
85
86 if (!mcheck_used)
87 /* Maybe the mcheck used is disabled? This happens when we find
88 an error and report it. */
89 return MCHECK_OK;
90
8e605e78 91 switch (hdr->magic ^ ((uintptr_t) hdr->prev + (uintptr_t) hdr->next))
6d52618b
UD
92 {
93 default:
94 status = MCHECK_HEAD;
95 break;
96 case MAGICFREE:
97 status = MCHECK_FREE;
98 break;
99 case MAGICWORD:
100 if (((char *) &hdr[1])[hdr->size] != MAGICBYTE)
6c8dbf00 101 status = MCHECK_TAIL;
6e3d59bc 102 else if ((hdr->magic2 ^ (uintptr_t) hdr->block) != MAGICWORD)
6c8dbf00 103 status = MCHECK_HEAD;
6d52618b 104 else
6c8dbf00 105 status = MCHECK_OK;
6d52618b
UD
106 break;
107 }
108 if (status != MCHECK_OK)
adef3744
UD
109 {
110 mcheck_used = 0;
111 (*abortfunc) (status);
112 mcheck_used = 1;
113 }
6d52618b
UD
114 return status;
115}
116
77e1d15a 117void
b80163bd 118mcheck_check_all (void)
8e605e78 119{
fad64255 120 /* Walk through all the active blocks and test whether they were tampered
8e605e78
UD
121 with. */
122 struct hdr *runp = root;
123
30e0f9c3
UD
124 /* Temporarily turn off the checks. */
125 pedantic = 0;
126
8e605e78
UD
127 while (runp != NULL)
128 {
129 (void) checkhdr (runp);
130
131 runp = runp->next;
132 }
30e0f9c3
UD
133
134 /* Turn checks on again. */
135 pedantic = 1;
8e605e78 136}
a14f26ef
RM
137#ifdef _LIBC
138libc_hidden_def (mcheck_check_all)
139#endif
8e605e78 140
8e605e78 141static void
b80163bd 142unlink_blk (struct hdr *ptr)
8e605e78
UD
143{
144 if (ptr->next != NULL)
145 {
146 ptr->next->prev = ptr->prev;
147 ptr->next->magic = MAGICWORD ^ ((uintptr_t) ptr->next->prev
6c8dbf00 148 + (uintptr_t) ptr->next->next);
8e605e78
UD
149 }
150 if (ptr->prev != NULL)
151 {
152 ptr->prev->next = ptr->next;
153 ptr->prev->magic = MAGICWORD ^ ((uintptr_t) ptr->prev->prev
6c8dbf00 154 + (uintptr_t) ptr->prev->next);
8e605e78
UD
155 }
156 else
157 root = ptr->next;
158}
159
8e605e78 160static void
b80163bd 161link_blk (struct hdr *hdr)
8e605e78
UD
162{
163 hdr->prev = NULL;
164 hdr->next = root;
165 root = hdr;
166 hdr->magic = MAGICWORD ^ (uintptr_t) hdr->next;
167
168 /* And the next block. */
169 if (hdr->next != NULL)
170 {
171 hdr->next->prev = hdr;
172 hdr->next->magic = MAGICWORD ^ ((uintptr_t) hdr
6c8dbf00 173 + (uintptr_t) hdr->next->next);
8e605e78
UD
174 }
175}
6d52618b 176static void
f17a4233 177freehook (void *ptr, const void *caller)
6d52618b 178{
8e605e78 179 if (pedantic)
77e1d15a 180 mcheck_check_all ();
6d52618b
UD
181 if (ptr)
182 {
183 struct hdr *hdr = ((struct hdr *) ptr) - 1;
184 checkhdr (hdr);
185 hdr->magic = MAGICFREE;
6e3d59bc 186 hdr->magic2 = MAGICFREE;
8e605e78
UD
187 unlink_blk (hdr);
188 hdr->prev = hdr->next = NULL;
6d52618b 189 flood (ptr, FREEFLOOD, hdr->size);
6e3d59bc 190 ptr = hdr->block;
6d52618b
UD
191 }
192 __free_hook = old_free_hook;
a2b08ee5 193 if (old_free_hook != NULL)
6c8dbf00 194 (*old_free_hook)(ptr, caller);
a2b08ee5 195 else
a334319f 196 free (ptr);
6d52618b
UD
197 __free_hook = freehook;
198}
199
f17a4233
JM
200static void *
201mallochook (size_t size, const void *caller)
6d52618b
UD
202{
203 struct hdr *hdr;
204
8e605e78 205 if (pedantic)
77e1d15a 206 mcheck_check_all ();
8e605e78 207
3b111893
UD
208 if (size > ~((size_t) 0) - (sizeof (struct hdr) + 1))
209 {
210 __set_errno (ENOMEM);
211 return NULL;
212 }
213
6d52618b 214 __malloc_hook = old_malloc_hook;
a2b08ee5 215 if (old_malloc_hook != NULL)
6c8dbf00
OB
216 hdr = (struct hdr *) (*old_malloc_hook)(sizeof (struct hdr) + size + 1,
217 caller);
a2b08ee5 218 else
a334319f 219 hdr = (struct hdr *) malloc (sizeof (struct hdr) + size + 1);
6d52618b
UD
220 __malloc_hook = mallochook;
221 if (hdr == NULL)
222 return NULL;
223
224 hdr->size = size;
8e605e78 225 link_blk (hdr);
6e3d59bc
RM
226 hdr->block = hdr;
227 hdr->magic2 = (uintptr_t) hdr ^ MAGICWORD;
228 ((char *) &hdr[1])[size] = MAGICBYTE;
f17a4233
JM
229 flood ((void *) (hdr + 1), MALLOCFLOOD, size);
230 return (void *) (hdr + 1);
6e3d59bc
RM
231}
232
f17a4233 233static void *
1ba4f030 234memalignhook (size_t alignment, size_t size,
f17a4233 235 const void *caller)
6e3d59bc
RM
236{
237 struct hdr *hdr;
1ba4f030 238 size_t slop;
6e3d59bc
RM
239 char *block;
240
241 if (pedantic)
242 mcheck_check_all ();
243
6c8dbf00 244 slop = (sizeof *hdr + alignment - 1) & - alignment;
6e3d59bc 245
3b111893
UD
246 if (size > ~((size_t) 0) - (slop + 1))
247 {
248 __set_errno (ENOMEM);
249 return NULL;
250 }
251
6e3d59bc
RM
252 __memalign_hook = old_memalign_hook;
253 if (old_memalign_hook != NULL)
6c8dbf00 254 block = (*old_memalign_hook)(alignment, slop + size + 1, caller);
6e3d59bc 255 else
a334319f 256 block = memalign (alignment, slop + size + 1);
6e3d59bc
RM
257 __memalign_hook = memalignhook;
258 if (block == NULL)
259 return NULL;
260
261 hdr = ((struct hdr *) (block + slop)) - 1;
262
263 hdr->size = size;
264 link_blk (hdr);
f17a4233 265 hdr->block = (void *) block;
6e3d59bc 266 hdr->magic2 = (uintptr_t) block ^ MAGICWORD;
6d52618b 267 ((char *) &hdr[1])[size] = MAGICBYTE;
f17a4233
JM
268 flood ((void *) (hdr + 1), MALLOCFLOOD, size);
269 return (void *) (hdr + 1);
6d52618b
UD
270}
271
f17a4233
JM
272static void *
273reallochook (void *ptr, size_t size, const void *caller)
6d52618b 274{
129abdd3
UD
275 if (size == 0)
276 {
277 freehook (ptr, caller);
2acd01ac 278 return NULL;
129abdd3
UD
279 }
280
6d52618b 281 struct hdr *hdr;
1ba4f030 282 size_t osize;
6d52618b 283
8e605e78 284 if (pedantic)
77e1d15a 285 mcheck_check_all ();
8e605e78 286
3b111893
UD
287 if (size > ~((size_t) 0) - (sizeof (struct hdr) + 1))
288 {
289 __set_errno (ENOMEM);
290 return NULL;
291 }
292
6d52618b
UD
293 if (ptr)
294 {
295 hdr = ((struct hdr *) ptr) - 1;
296 osize = hdr->size;
297
298 checkhdr (hdr);
8e605e78 299 unlink_blk (hdr);
6d52618b 300 if (size < osize)
6c8dbf00 301 flood ((char *) ptr + size, FREEFLOOD, osize - size);
6d52618b
UD
302 }
303 else
304 {
305 osize = 0;
306 hdr = NULL;
307 }
308 __free_hook = old_free_hook;
309 __malloc_hook = old_malloc_hook;
6e3d59bc 310 __memalign_hook = old_memalign_hook;
6d52618b 311 __realloc_hook = old_realloc_hook;
a2b08ee5 312 if (old_realloc_hook != NULL)
f17a4233 313 hdr = (struct hdr *) (*old_realloc_hook)((void *) hdr,
6c8dbf00
OB
314 sizeof (struct hdr) + size + 1,
315 caller);
a2b08ee5 316 else
f17a4233 317 hdr = (struct hdr *) realloc ((void *) hdr,
6c8dbf00 318 sizeof (struct hdr) + size + 1);
6d52618b
UD
319 __free_hook = freehook;
320 __malloc_hook = mallochook;
6e3d59bc 321 __memalign_hook = memalignhook;
6d52618b
UD
322 __realloc_hook = reallochook;
323 if (hdr == NULL)
324 return NULL;
325
326 hdr->size = size;
8e605e78 327 link_blk (hdr);
6e3d59bc
RM
328 hdr->block = hdr;
329 hdr->magic2 = (uintptr_t) hdr ^ MAGICWORD;
6d52618b
UD
330 ((char *) &hdr[1])[size] = MAGICBYTE;
331 if (size > osize)
332 flood ((char *) (hdr + 1) + osize, MALLOCFLOOD, size - osize);
f17a4233 333 return (void *) (hdr + 1);
6d52618b
UD
334}
335
b80163bd 336__attribute__ ((noreturn))
6d52618b 337static void
b80163bd 338mabort (enum mcheck_status status)
6d52618b
UD
339{
340 const char *msg;
341 switch (status)
342 {
343 case MCHECK_OK:
6c8dbf00 344 msg = _ ("memory is consistent, library is buggy\n");
6d52618b
UD
345 break;
346 case MCHECK_HEAD:
6c8dbf00 347 msg = _ ("memory clobbered before allocated block\n");
6d52618b
UD
348 break;
349 case MCHECK_TAIL:
6c8dbf00 350 msg = _ ("memory clobbered past end of allocated block\n");
6d52618b
UD
351 break;
352 case MCHECK_FREE:
6c8dbf00 353 msg = _ ("block freed twice\n");
6d52618b
UD
354 break;
355 default:
6c8dbf00 356 msg = _ ("bogus mcheck_status, library is buggy\n");
6d52618b
UD
357 break;
358 }
359#ifdef _LIBC
360 __libc_fatal (msg);
361#else
9756dfe1 362 fprintf (stderr, "mcheck: %s", msg);
6d52618b
UD
363 fflush (stderr);
364 abort ();
365#endif
366}
367
f0c1dedf
AJ
368/* Memory barrier so that GCC does not optimize out the argument. */
369#define malloc_opt_barrier(x) \
6c8dbf00 370 ({ __typeof (x) __x = x; __asm ("" : "+m" (__x)); __x; })
f0c1dedf 371
85231522
JM
372int
373mcheck (void (*func) (enum mcheck_status))
6d52618b
UD
374{
375 abortfunc = (func != NULL) ? func : &mabort;
376
377 /* These hooks may not be safely inserted if malloc is already in use. */
9756dfe1 378 if (__malloc_initialized <= 0 && !mcheck_used)
6d52618b 379 {
1b20d937 380 /* We call malloc() once here to ensure it is initialized. */
a334319f 381 void *p = malloc (0);
f0c1dedf
AJ
382 /* GCC might optimize out the malloc/free pair without a barrier. */
383 p = malloc_opt_barrier (p);
a334319f 384 free (p);
1b20d937 385
6d52618b
UD
386 old_free_hook = __free_hook;
387 __free_hook = freehook;
388 old_malloc_hook = __malloc_hook;
389 __malloc_hook = mallochook;
6e3d59bc
RM
390 old_memalign_hook = __memalign_hook;
391 __memalign_hook = memalignhook;
6d52618b
UD
392 old_realloc_hook = __realloc_hook;
393 __realloc_hook = reallochook;
394 mcheck_used = 1;
395 }
396
397 return mcheck_used ? 0 : -1;
398}
509d1b68
RM
399#ifdef _LIBC
400libc_hidden_def (mcheck)
401#endif
6d52618b 402
85231522
JM
403int
404mcheck_pedantic (void (*func) (enum mcheck_status))
8e605e78 405{
77e1d15a
UD
406 int res = mcheck (func);
407 if (res == 0)
408 pedantic = 1;
409 return res;
8e605e78
UD
410}
411
6d52618b 412enum mcheck_status
f17a4233 413mprobe (void *ptr)
6d52618b 414{
997a4165 415 return mcheck_used ? checkhdr (((struct hdr *) ptr) - 1) : MCHECK_DISABLED;
6d52618b 416}