+2016-11-16 Maxim Ostapenko <m.ostapenko@samsung.com>
+
+ PR sanitizer/78307
+ * ubsan/ubsan_handlers.cc (__ubsan_handle_cfi_bad_icall): New function.
+ ( __ubsan_handle_cfi_bad_icall_abort): Likewise.
+ * ubsan/ubsan_handlers.h (struct CFIBadIcallData): New type.
+ * ubsan/ubsan_handlers_cxx.cc (__ubsan_handle_cfi_bad_type): New
+ function.
+ (__ubsan_handle_cfi_bad_type_abort): Likewise.
+ * ubsan/ubsan_handlers_cxx.h (struct CFIBadTypeData): New type.
+ (__ubsan_handle_cfi_bad_type): Export function.
+ (__ubsan_handle_cfi_bad_type_abort): Likewise.
+ * HOWTO_MERGE: Update documentation.
+
2016-11-15 Matthias Klose <doko@ubuntu.com>
* configure: Regenerate.
in corresponding CMakeLists.txt and config-ix.cmake files from compiler-rt source
directory.
* Apply all needed GCC-specific patches to libsanitizer (note that some of
- them might be already included to upstream).
+ them might be already included to upstream). The list of these patches is stored
+ into LOCAL_PATCHES file.
* Apply all necessary compiler changes. Be especially careful here, you must
not break ABI between compiler and library. You can reveal these changes by
inspecting the history of AddressSanitizer.cpp and ThreadSanitizer.cpp files
in libasan, configure/Makefile changes). The review process has O(N^2) complexity, so you
would simplify and probably speed up the review process by doing this.
* Send your patches for review to GCC Patches Mailing List (gcc-patches@gcc.gnu.org).
+* Update LOCAL_PATCHES file when you've committed the whole patch set with new revisions numbers.
#endif
} // namespace __ubsan
+void __ubsan::__ubsan_handle_cfi_bad_icall(CFIBadIcallData *CallData,
+ ValueHandle Function) {
+ GET_REPORT_OPTIONS(false);
+ CFICheckFailData Data = {CFITCK_ICall, CallData->Loc, CallData->Type};
+ handleCFIBadIcall(&Data, Function, Opts);
+}
+
+void __ubsan::__ubsan_handle_cfi_bad_icall_abort(CFIBadIcallData *CallData,
+ ValueHandle Function) {
+ GET_REPORT_OPTIONS(true);
+ CFICheckFailData Data = {CFITCK_ICall, CallData->Loc, CallData->Type};
+ handleCFIBadIcall(&Data, Function, Opts);
+ Die();
+}
+
void __ubsan::__ubsan_handle_cfi_check_fail(CFICheckFailData *Data,
ValueHandle Value,
uptr ValidVtable) {
CFITCK_ICall,
};
+struct CFIBadIcallData {
+ SourceLocation Loc;
+ const TypeDescriptor &Type;
+};
+
struct CFICheckFailData {
CFITypeCheckKind CheckKind;
SourceLocation Loc;
const TypeDescriptor &Type;
};
+/// \brief Handle control flow integrity failure for indirect function calls.
+RECOVERABLE(cfi_bad_icall, CFIBadIcallData *Data, ValueHandle Function)
+
/// \brief Handle control flow integrity failures.
RECOVERABLE(cfi_check_fail, CFICheckFailData *Data, ValueHandle Function,
uptr VtableIsValid)
}
} // namespace __ubsan
+void __ubsan::__ubsan_handle_cfi_bad_type(CFIBadTypeData *TypeData,
+ ValueHandle Vtable) {
+ GET_REPORT_OPTIONS(false);
+ CFITypeCheckKind TypeCheckKind
+ = static_cast<CFITypeCheckKind> (TypeData->TypeCheckKind);
+ CFICheckFailData Data = {TypeCheckKind, TypeData->Loc, TypeData->Type};
+ HandleCFIBadType(&Data, Vtable, false, Opts);
+}
+
+void __ubsan::__ubsan_handle_cfi_bad_type_abort(CFIBadTypeData *TypeData,
+ ValueHandle Vtable) {
+ GET_REPORT_OPTIONS(true);
+ CFITypeCheckKind TypeCheckKind
+ = static_cast<CFITypeCheckKind> (TypeData->TypeCheckKind);
+ CFICheckFailData Data = {TypeCheckKind, TypeData->Loc, TypeData->Type};
+ HandleCFIBadType(&Data, Vtable, false, Opts);
+}
+
#endif // CAN_SANITIZE_UB
unsigned char TypeCheckKind;
};
+struct CFIBadTypeData {
+ SourceLocation Loc;
+ const TypeDescriptor &Type;
+ unsigned char TypeCheckKind;
+};
+
/// \brief Handle a runtime type check failure, caused by an incorrect vptr.
/// When this handler is called, all we know is that the type was not in the
/// cache; this does not necessarily imply the existence of a bug.
extern "C" SANITIZER_INTERFACE_ATTRIBUTE
void __ubsan_handle_dynamic_type_cache_miss_abort(
DynamicTypeCacheMissData *Data, ValueHandle Pointer, ValueHandle Hash);
+
+/// \brief Handle a control flow integrity check failure by printing a
+/// diagnostic.
+extern "C" SANITIZER_INTERFACE_ATTRIBUTE void
+__ubsan_handle_cfi_bad_type(CFIBadTypeData *Data, ValueHandle Vtable);
+extern "C" SANITIZER_INTERFACE_ATTRIBUTE void
+__ubsan_handle_cfi_bad_type_abort(CFIBadTypeData *Data, ValueHandle Vtable);
}
#endif // UBSAN_HANDLERS_H