The GWP-ASan recoverable mode allows a process to continue to function after a GWP-ASan error is detected. The error will continue to be dumped, but GWP-ASan now has APIs that a signal handler (like the example optional crash handler) can call in order to allow the continuation of a process. When an error occurs with an allocation, the slot used for that allocation will be permanently disabled. This means that free() of that pointer is a no-op, and use-after-frees will succeed (writing and reading the data present in the page). For heap-buffer-overflow/underflow, the guard page is marked as accessible and buffer-overflows will succeed (writing and reading the data present in the now-accessible guard page). This does impact adjacent allocations, buffer-underflow and buffer-overflows from adjacent allocations will no longer touch an inaccessible guard page. This could be improved in future by having two guard pages between each adjacent allocation, but that's out of scope of this patch. Each allocation only ever has a single error report generated. It's whatever came first between invalid-free, double-free, use-after-free or heap-buffer-overflow, but only one. Reviewed By: eugenis, fmayer Differential Revision: https://reviews.llvm.org/D140173
35 lines
1.5 KiB
C++
35 lines
1.5 KiB
C++
//===-- segv_handler.h ------------------------------------------*- C++ -*-===//
|
|
//
|
|
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
|
|
// See https://llvm.org/LICENSE.txt for license information.
|
|
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
|
|
//
|
|
//===----------------------------------------------------------------------===//
|
|
|
|
#ifndef GWP_ASAN_OPTIONAL_SEGV_HANDLER_H_
|
|
#define GWP_ASAN_OPTIONAL_SEGV_HANDLER_H_
|
|
|
|
#include "gwp_asan/guarded_pool_allocator.h"
|
|
#include "gwp_asan/optional/backtrace.h"
|
|
#include "gwp_asan/optional/printf.h"
|
|
|
|
namespace gwp_asan {
|
|
namespace segv_handler {
|
|
// Install the SIGSEGV crash handler for printing use-after-free and heap-
|
|
// buffer-{under|over}flow exceptions if the user asked for it. This is platform
|
|
// specific as even though POSIX and Windows both support registering handlers
|
|
// through signal(), we have to use platform-specific signal handlers to obtain
|
|
// the address that caused the SIGSEGV exception. GPA->init() must be called
|
|
// before this function.
|
|
void installSignalHandlers(gwp_asan::GuardedPoolAllocator *GPA, Printf_t Printf,
|
|
gwp_asan::backtrace::PrintBacktrace_t PrintBacktrace,
|
|
gwp_asan::backtrace::SegvBacktrace_t SegvBacktrace,
|
|
bool Recoverable = false);
|
|
|
|
// Uninistall the signal handlers, test-only.
|
|
void uninstallSignalHandlers();
|
|
} // namespace segv_handler
|
|
} // namespace gwp_asan
|
|
|
|
#endif // GWP_ASAN_OPTIONAL_SEGV_HANDLER_H_
|