blob: 814fef6a9647051eb50746c1b33aa960380414fa [file] [log] [blame]
Colin Cross16b23492016-01-06 14:41:07 -08001// Copyright 2016 Google Inc. All rights reserved.
2//
3// Licensed under the Apache License, Version 2.0 (the "License");
4// you may not use this file except in compliance with the License.
5// You may obtain a copy of the License at
6//
7// http://www.apache.org/licenses/LICENSE-2.0
8//
9// Unless required by applicable law or agreed to in writing, software
10// distributed under the License is distributed on an "AS IS" BASIS,
11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12// See the License for the specific language governing permissions and
13// limitations under the License.
14
15package cc
16
17import (
18 "fmt"
Jeff Gaston72765392017-11-28 16:37:53 -080019 "sort"
Colin Cross16b23492016-01-06 14:41:07 -080020 "strings"
Vishwath Mohane7128792017-11-17 11:08:10 -080021 "sync"
Colin Cross16b23492016-01-06 14:41:07 -080022
Colin Cross6b753602018-06-21 13:03:07 -070023 "github.com/google/blueprint"
Liz Kammerb2fc4702021-06-25 14:53:40 -040024 "github.com/google/blueprint/proptools"
Colin Cross6b753602018-06-21 13:03:07 -070025
Colin Cross635c3b02016-05-18 15:37:25 -070026 "android/soong/android"
Evgenii Stepanovaf36db12016-08-15 14:18:24 -070027 "android/soong/cc/config"
Kiyoung Kim48f37782021-07-07 12:42:39 +090028 "android/soong/snapshot"
Colin Cross16b23492016-01-06 14:41:07 -080029)
30
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070031var (
32 // Any C flags added by sanitizer which libTooling tools may not
33 // understand also need to be added to ClangLibToolingUnknownCflags in
34 // cc/config/clang.go
Vishwath Mohanf3918d32017-02-14 07:59:33 -080035
Yi Kong20233a42019-08-21 01:38:40 -070036 asanCflags = []string{
37 "-fno-omit-frame-pointer",
Yi Kong20233a42019-08-21 01:38:40 -070038 }
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070039 asanLdflags = []string{"-Wl,-u,__asan_preinit"}
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070040
Yi Kong286abc62021-11-04 16:14:14 +080041 hwasanCflags = []string{
42 "-fno-omit-frame-pointer",
43 "-Wno-frame-larger-than=",
Evgenii Stepanov96fa3dd2020-03-27 19:38:42 +000044 "-fsanitize-hwaddress-abi=platform",
Florian Mayer0b981f52022-02-16 23:46:53 +000045 "-mllvm", "-hwasan-use-after-scope=1",
Yi Kong286abc62021-11-04 16:14:14 +080046 }
47
48 // ThinLTO performs codegen during link time, thus these flags need to
49 // passed to both CFLAGS and LDFLAGS.
50 hwasanCommonflags = []string{
Evgenii Stepanov64bee4d2019-11-22 18:37:10 -080051 // The following improves debug location information
52 // availability at the cost of its accuracy. It increases
53 // the likelihood of a stack variable's frame offset
54 // to be recorded in the debug info, which is important
55 // for the quality of hwasan reports. The downside is a
56 // higher number of "optimized out" stack variables.
57 // b/112437883.
Yi Kong286abc62021-11-04 16:14:14 +080058 "-instcombine-lower-dbg-declare=0",
Mitch Phillipsb1c574f2020-06-22 13:28:23 -070059 // TODO(b/159343917): HWASan and GlobalISel don't play nicely, and
60 // GlobalISel is the default at -O0 on aarch64.
Yi Kong286abc62021-11-04 16:14:14 +080061 "--aarch64-enable-global-isel-at-O=-1",
62 "-fast-isel=false",
Evgenii Stepanov64bee4d2019-11-22 18:37:10 -080063 }
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -070064
Vishwath Mohanb743e9c2017-11-01 09:20:21 +000065 cfiCflags = []string{"-flto", "-fsanitize-cfi-cross-dso",
Pirama Arumuga Nainar582fc2d2021-08-27 15:12:56 -070066 "-fsanitize-ignorelist=external/compiler-rt/lib/cfi/cfi_blocklist.txt"}
Evgenii Stepanovdbf1d4f2018-08-31 12:54:33 -070067 // -flto and -fvisibility are required by clang when -fsanitize=cfi is
68 // used, but have no effect on assembly files
69 cfiAsflags = []string{"-flto", "-fvisibility=default"}
Jayant Chowdhary9677e8c2017-06-15 14:45:18 -070070 cfiLdflags = []string{"-flto", "-fsanitize-cfi-cross-dso", "-fsanitize=cfi",
Pirama Arumuga Nainarbdb17f02017-08-28 21:50:17 -070071 "-Wl,-plugin-opt,O1"}
Inseob Kim74d25562020-08-04 00:41:38 +090072 cfiExportsMapPath = "build/soong/cc/config/cfi_exports.map"
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -070073
Pirama Arumuga Nainar582fc2d2021-08-27 15:12:56 -070074 intOverflowCflags = []string{"-fsanitize-ignorelist=build/soong/cc/config/integer_overflow_blocklist.txt"}
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -080075
Peter Collingbournebd19db02019-03-06 10:38:48 -080076 minimalRuntimeFlags = []string{"-fsanitize-minimal-runtime", "-fno-sanitize-trap=integer,undefined",
Ivan Lozanoae6ae1d2018-10-08 09:29:39 -070077 "-fno-sanitize-recover=integer,undefined"}
Evgenii Stepanov2c6484e2019-05-15 12:49:54 -070078 hwasanGlobalOptions = []string{"heap_history_size=1023", "stack_history_size=512",
Mitch Phillips59760562022-03-22 18:33:44 +000079 "export_memory_stats=0", "max_malloc_fill_size=4096", "malloc_fill_byte=0"}
Dan Willemsencbceaab2016-10-13 16:44:07 -070080)
81
Ivan Lozano3968d8f2020-12-14 11:27:52 -050082type SanitizerType int
Colin Cross16b23492016-01-06 14:41:07 -080083
Colin Cross16b23492016-01-06 14:41:07 -080084const (
Ivan Lozano3968d8f2020-12-14 11:27:52 -050085 Asan SanitizerType = iota + 1
Tri Vo6eafc362021-04-01 11:29:09 -070086 Hwasan
Colin Cross16b23492016-01-06 14:41:07 -080087 tsan
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -070088 intOverflow
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -080089 scs
Ivan Lozano3968d8f2020-12-14 11:27:52 -050090 Fuzzer
Ivan Lozano62cd0382021-11-01 10:27:54 -040091 Memtag_heap
Liz Kammer75db9312021-07-07 16:41:50 -040092 cfi // cfi is last to prevent it running before incompatible mutators
Colin Cross16b23492016-01-06 14:41:07 -080093)
94
Liz Kammer75db9312021-07-07 16:41:50 -040095var Sanitizers = []SanitizerType{
96 Asan,
97 Hwasan,
98 tsan,
99 intOverflow,
100 scs,
101 Fuzzer,
Ivan Lozano62cd0382021-11-01 10:27:54 -0400102 Memtag_heap,
Liz Kammer75db9312021-07-07 16:41:50 -0400103 cfi, // cfi is last to prevent it running before incompatible mutators
104}
105
Jiyong Park82226632019-02-01 10:50:50 +0900106// Name of the sanitizer variation for this sanitizer type
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500107func (t SanitizerType) variationName() string {
Colin Cross16b23492016-01-06 14:41:07 -0800108 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500109 case Asan:
Colin Cross16b23492016-01-06 14:41:07 -0800110 return "asan"
Tri Vo6eafc362021-04-01 11:29:09 -0700111 case Hwasan:
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700112 return "hwasan"
Colin Cross16b23492016-01-06 14:41:07 -0800113 case tsan:
114 return "tsan"
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700115 case intOverflow:
116 return "intOverflow"
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000117 case cfi:
118 return "cfi"
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800119 case scs:
120 return "scs"
Ivan Lozano62cd0382021-11-01 10:27:54 -0400121 case Memtag_heap:
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700122 return "memtag_heap"
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500123 case Fuzzer:
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700124 return "fuzzer"
Colin Cross16b23492016-01-06 14:41:07 -0800125 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500126 panic(fmt.Errorf("unknown SanitizerType %d", t))
Colin Cross16b23492016-01-06 14:41:07 -0800127 }
128}
129
Jiyong Park82226632019-02-01 10:50:50 +0900130// This is the sanitizer names in SANITIZE_[TARGET|HOST]
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500131func (t SanitizerType) name() string {
Jiyong Park82226632019-02-01 10:50:50 +0900132 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500133 case Asan:
Jiyong Park82226632019-02-01 10:50:50 +0900134 return "address"
Tri Vo6eafc362021-04-01 11:29:09 -0700135 case Hwasan:
Jiyong Park82226632019-02-01 10:50:50 +0900136 return "hwaddress"
Ivan Lozano62cd0382021-11-01 10:27:54 -0400137 case Memtag_heap:
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700138 return "memtag_heap"
Jiyong Park82226632019-02-01 10:50:50 +0900139 case tsan:
140 return "thread"
141 case intOverflow:
142 return "integer_overflow"
143 case cfi:
144 return "cfi"
145 case scs:
146 return "shadow-call-stack"
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500147 case Fuzzer:
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700148 return "fuzzer"
Jiyong Park82226632019-02-01 10:50:50 +0900149 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500150 panic(fmt.Errorf("unknown SanitizerType %d", t))
Jiyong Park82226632019-02-01 10:50:50 +0900151 }
152}
153
Liz Kammer75db9312021-07-07 16:41:50 -0400154func (t SanitizerType) registerMutators(ctx android.RegisterMutatorsContext) {
155 switch t {
156 case Asan, Hwasan, Fuzzer, scs, tsan, cfi:
157 ctx.TopDown(t.variationName()+"_deps", sanitizerDepsMutator(t))
158 ctx.BottomUp(t.variationName(), sanitizerMutator(t))
Ivan Lozano62cd0382021-11-01 10:27:54 -0400159 case Memtag_heap, intOverflow:
Liz Kammer75db9312021-07-07 16:41:50 -0400160 // do nothing
161 default:
162 panic(fmt.Errorf("unknown SanitizerType %d", t))
163 }
164}
165
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500166func (*Module) SanitizerSupported(t SanitizerType) bool {
167 switch t {
168 case Asan:
169 return true
Tri Vo6eafc362021-04-01 11:29:09 -0700170 case Hwasan:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500171 return true
172 case tsan:
173 return true
174 case intOverflow:
175 return true
176 case cfi:
177 return true
178 case scs:
179 return true
180 case Fuzzer:
181 return true
Ivan Lozano62cd0382021-11-01 10:27:54 -0400182 case Memtag_heap:
183 return true
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500184 default:
185 return false
186 }
187}
188
189// incompatibleWithCfi returns true if a sanitizer is incompatible with CFI.
190func (t SanitizerType) incompatibleWithCfi() bool {
Tri Vo6eafc362021-04-01 11:29:09 -0700191 return t == Asan || t == Fuzzer || t == Hwasan
Jiyong Park1d1119f2019-07-29 21:27:18 +0900192}
193
Martin Stjernholmb0249572020-09-15 02:32:35 +0100194type SanitizeUserProps struct {
Liz Kammer75b9b402021-06-25 15:19:27 -0400195 // Prevent use of any sanitizers on this module
Martin Stjernholmb0249572020-09-15 02:32:35 +0100196 Never *bool `android:"arch_variant"`
Colin Cross16b23492016-01-06 14:41:07 -0800197
Liz Kammer75b9b402021-06-25 15:19:27 -0400198 // ASan (Address sanitizer), incompatible with static binaries.
199 // Always runs in a diagnostic mode.
200 // Use of address sanitizer disables cfi sanitizer.
201 // Hwaddress sanitizer takes precedence over this sanitizer.
202 Address *bool `android:"arch_variant"`
203 // TSan (Thread sanitizer), incompatible with static binaries and 32 bit architectures.
204 // Always runs in a diagnostic mode.
205 // Use of thread sanitizer disables cfi and scudo sanitizers.
206 // Hwaddress sanitizer takes precedence over this sanitizer.
207 Thread *bool `android:"arch_variant"`
208 // HWASan (Hardware Address sanitizer).
209 // Use of hwasan sanitizer disables cfi, address, thread, and scudo sanitizers.
Martin Stjernholmb0249572020-09-15 02:32:35 +0100210 Hwaddress *bool `android:"arch_variant"`
Colin Cross16b23492016-01-06 14:41:07 -0800211
Liz Kammer75b9b402021-06-25 15:19:27 -0400212 // Undefined behavior sanitizer
213 All_undefined *bool `android:"arch_variant"`
214 // Subset of undefined behavior sanitizer
215 Undefined *bool `android:"arch_variant"`
216 // List of specific undefined behavior sanitizers to enable
217 Misc_undefined []string `android:"arch_variant"`
218 // Fuzzer, incompatible with static binaries.
219 Fuzzer *bool `android:"arch_variant"`
220 // safe-stack sanitizer, incompatible with 32-bit architectures.
221 Safestack *bool `android:"arch_variant"`
222 // cfi sanitizer, incompatible with asan, hwasan, fuzzer, or Darwin
223 Cfi *bool `android:"arch_variant"`
224 // signed/unsigned integer overflow sanitizer, incompatible with Darwin.
225 Integer_overflow *bool `android:"arch_variant"`
226 // scudo sanitizer, incompatible with asan, hwasan, tsan
227 // This should not be used in Android 11+ : https://source.android.com/devices/tech/debug/scudo
228 // deprecated
229 Scudo *bool `android:"arch_variant"`
230 // shadow-call-stack sanitizer, only available on arm64
231 Scs *bool `android:"arch_variant"`
232 // Memory-tagging, only available on arm64
233 // if diag.memtag unset or false, enables async memory tagging
234 Memtag_heap *bool `android:"arch_variant"`
Martin Stjernholmb0249572020-09-15 02:32:35 +0100235
236 // A modifier for ASAN and HWASAN for write only instrumentation
237 Writeonly *bool `android:"arch_variant"`
238
239 // Sanitizers to run in the diagnostic mode (as opposed to the release mode).
240 // Replaces abort() on error with a human-readable error message.
241 // Address and Thread sanitizers always run in diagnostic mode.
242 Diag struct {
Liz Kammer75b9b402021-06-25 15:19:27 -0400243 // Undefined behavior sanitizer, diagnostic mode
244 Undefined *bool `android:"arch_variant"`
245 // cfi sanitizer, diagnostic mode, incompatible with asan, hwasan, fuzzer, or Darwin
246 Cfi *bool `android:"arch_variant"`
247 // signed/unsigned integer overflow sanitizer, diagnostic mode, incompatible with Darwin.
248 Integer_overflow *bool `android:"arch_variant"`
249 // Memory-tagging, only available on arm64
250 // requires sanitizer.memtag: true
251 // if set, enables sync memory tagging
252 Memtag_heap *bool `android:"arch_variant"`
253 // List of specific undefined behavior sanitizers to enable in diagnostic mode
254 Misc_undefined []string `android:"arch_variant"`
255 // List of sanitizers to pass to -fno-sanitize-recover
256 // results in only the first detected error for these sanitizers being reported and program then
257 // exits with a non-zero exit code.
258 No_recover []string `android:"arch_variant"`
Cindy Zhoud3fe4922020-12-01 11:14:30 -0800259 } `android:"arch_variant"`
Colin Cross16b23492016-01-06 14:41:07 -0800260
Cindy Zhou8cd45de2020-11-16 08:41:00 -0800261 // Sanitizers to run with flag configuration specified
262 Config struct {
263 // Enables CFI support flags for assembly-heavy libraries
264 Cfi_assembly_support *bool `android:"arch_variant"`
Cindy Zhoud3fe4922020-12-01 11:14:30 -0800265 } `android:"arch_variant"`
Cindy Zhou8cd45de2020-11-16 08:41:00 -0800266
Liz Kammer75b9b402021-06-25 15:19:27 -0400267 // List of sanitizers to pass to -fsanitize-recover
268 // allows execution to continue for these sanitizers to detect multiple errors rather than only
269 // the first one
Martin Stjernholmb0249572020-09-15 02:32:35 +0100270 Recover []string
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000271
Pirama Arumuga Nainar582fc2d2021-08-27 15:12:56 -0700272 // value to pass to -fsanitize-ignorelist
Martin Stjernholmb0249572020-09-15 02:32:35 +0100273 Blocklist *string
274}
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700275
Martin Stjernholmb0249572020-09-15 02:32:35 +0100276type SanitizeProperties struct {
Martin Stjernholmb0249572020-09-15 02:32:35 +0100277 Sanitize SanitizeUserProps `android:"arch_variant"`
278 SanitizerEnabled bool `blueprint:"mutated"`
279 SanitizeDep bool `blueprint:"mutated"`
280 MinimalRuntimeDep bool `blueprint:"mutated"`
281 BuiltinsDep bool `blueprint:"mutated"`
282 UbsanRuntimeDep bool `blueprint:"mutated"`
283 InSanitizerDir bool `blueprint:"mutated"`
284 Sanitizers []string `blueprint:"mutated"`
285 DiagSanitizers []string `blueprint:"mutated"`
Colin Cross16b23492016-01-06 14:41:07 -0800286}
287
288type sanitize struct {
289 Properties SanitizeProperties
290}
291
Cindy Zhou18417cb2020-12-10 07:12:38 -0800292// Mark this tag with a check to see if apex dependency check should be skipped
293func (t libraryDependencyTag) SkipApexAllowedDependenciesCheck() bool {
294 return t.skipApexAllowedDependenciesCheck
295}
296
297var _ android.SkipApexAllowedDependenciesCheck = (*libraryDependencyTag)(nil)
298
Vishwath Mohane7128792017-11-17 11:08:10 -0800299func init() {
300 android.RegisterMakeVarsProvider(pctx, cfiMakeVarsProvider)
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700301 android.RegisterMakeVarsProvider(pctx, hwasanMakeVarsProvider)
Vishwath Mohane7128792017-11-17 11:08:10 -0800302}
303
Colin Cross16b23492016-01-06 14:41:07 -0800304func (sanitize *sanitize) props() []interface{} {
305 return []interface{}{&sanitize.Properties}
306}
307
308func (sanitize *sanitize) begin(ctx BaseModuleContext) {
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700309 s := &sanitize.Properties.Sanitize
310
Colin Cross16b23492016-01-06 14:41:07 -0800311 // Don't apply sanitizers to NDK code.
Jeff Gastonaf3cc2d2017-09-27 17:01:44 -0700312 if ctx.useSdk() {
Nan Zhang0007d812017-11-07 10:57:05 -0800313 s.Never = BoolPtr(true)
Colin Cross16b23492016-01-06 14:41:07 -0800314 }
315
316 // Never always wins.
Nan Zhang0007d812017-11-07 10:57:05 -0800317 if Bool(s.Never) {
Colin Cross16b23492016-01-06 14:41:07 -0800318 return
319 }
320
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800321 // cc_test targets default to SYNC MemTag unless explicitly set to ASYNC (via diag: {memtag_heap}).
Liz Kammer7b920b42021-06-22 16:57:27 -0400322 if ctx.testBinary() {
323 if s.Memtag_heap == nil {
324 s.Memtag_heap = proptools.BoolPtr(true)
325 }
326 if s.Diag.Memtag_heap == nil {
327 s.Diag.Memtag_heap = proptools.BoolPtr(true)
328 }
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800329 }
330
Colin Cross16b23492016-01-06 14:41:07 -0800331 var globalSanitizers []string
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700332 var globalSanitizersDiag []string
333
Dan Willemsen8536d6b2018-10-07 20:54:34 -0700334 if ctx.Host() {
335 if !ctx.Windows() {
336 globalSanitizers = ctx.Config().SanitizeHost()
337 }
338 } else {
339 arches := ctx.Config().SanitizeDeviceArch()
340 if len(arches) == 0 || inList(ctx.Arch().ArchType.Name, arches) {
341 globalSanitizers = ctx.Config().SanitizeDevice()
342 globalSanitizersDiag = ctx.Config().SanitizeDeviceDiag()
Colin Cross16b23492016-01-06 14:41:07 -0800343 }
344 }
345
Colin Cross16b23492016-01-06 14:41:07 -0800346 if len(globalSanitizers) > 0 {
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000347 var found bool
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700348 if found, globalSanitizers = removeFromList("undefined", globalSanitizers); found && s.All_undefined == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400349 s.All_undefined = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000350 }
Colin Cross16b23492016-01-06 14:41:07 -0800351
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700352 if found, globalSanitizers = removeFromList("default-ub", globalSanitizers); found && s.Undefined == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400353 s.Undefined = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000354 }
355
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700356 if found, globalSanitizers = removeFromList("address", globalSanitizers); found && s.Address == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400357 s.Address = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000358 }
359
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700360 if found, globalSanitizers = removeFromList("thread", globalSanitizers); found && s.Thread == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400361 s.Thread = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000362 }
363
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700364 if found, globalSanitizers = removeFromList("fuzzer", globalSanitizers); found && s.Fuzzer == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400365 s.Fuzzer = proptools.BoolPtr(true)
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700366 }
367
368 if found, globalSanitizers = removeFromList("safe-stack", globalSanitizers); found && s.Safestack == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400369 s.Safestack = proptools.BoolPtr(true)
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000370 }
371
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700372 if found, globalSanitizers = removeFromList("cfi", globalSanitizers); found && s.Cfi == nil {
Colin Cross6510f912017-11-29 00:27:14 -0800373 if !ctx.Config().CFIDisabledForPath(ctx.ModuleDir()) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400374 s.Cfi = proptools.BoolPtr(true)
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700375 }
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700376 }
377
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700378 // Global integer_overflow builds do not support static libraries.
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700379 if found, globalSanitizers = removeFromList("integer_overflow", globalSanitizers); found && s.Integer_overflow == nil {
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700380 if !ctx.Config().IntegerOverflowDisabledForPath(ctx.ModuleDir()) && !ctx.static() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400381 s.Integer_overflow = proptools.BoolPtr(true)
Ivan Lozano5f595532017-07-13 14:46:05 -0700382 }
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700383 }
384
Kostya Kortchinskyd18ae5c2018-06-12 14:46:54 -0700385 if found, globalSanitizers = removeFromList("scudo", globalSanitizers); found && s.Scudo == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400386 s.Scudo = proptools.BoolPtr(true)
Kostya Kortchinskyd18ae5c2018-06-12 14:46:54 -0700387 }
388
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700389 if found, globalSanitizers = removeFromList("hwaddress", globalSanitizers); found && s.Hwaddress == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400390 s.Hwaddress = proptools.BoolPtr(true)
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700391 }
392
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000393 if found, globalSanitizers = removeFromList("writeonly", globalSanitizers); found && s.Writeonly == nil {
394 // Hwaddress and Address are set before, so we can check them here
395 // If they aren't explicitly set in the blueprint/SANITIZE_(HOST|TARGET), they would be nil instead of false
396 if s.Address == nil && s.Hwaddress == nil {
397 ctx.ModuleErrorf("writeonly modifier cannot be used without 'address' or 'hwaddress'")
398 }
Liz Kammerb2fc4702021-06-25 14:53:40 -0400399 s.Writeonly = proptools.BoolPtr(true)
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000400 }
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700401 if found, globalSanitizers = removeFromList("memtag_heap", globalSanitizers); found && s.Memtag_heap == nil {
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800402 if !ctx.Config().MemtagHeapDisabledForPath(ctx.ModuleDir()) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400403 s.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800404 }
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700405 }
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000406
Evgenii Stepanov05bafd32016-07-07 17:38:41 +0000407 if len(globalSanitizers) > 0 {
408 ctx.ModuleErrorf("unknown global sanitizer option %s", globalSanitizers[0])
409 }
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700410
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700411 // Global integer_overflow builds do not support static library diagnostics.
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700412 if found, globalSanitizersDiag = removeFromList("integer_overflow", globalSanitizersDiag); found &&
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700413 s.Diag.Integer_overflow == nil && Bool(s.Integer_overflow) && !ctx.static() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400414 s.Diag.Integer_overflow = proptools.BoolPtr(true)
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700415 }
416
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700417 if found, globalSanitizersDiag = removeFromList("cfi", globalSanitizersDiag); found &&
418 s.Diag.Cfi == nil && Bool(s.Cfi) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400419 s.Diag.Cfi = proptools.BoolPtr(true)
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700420 }
421
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800422 if found, globalSanitizersDiag = removeFromList("memtag_heap", globalSanitizersDiag); found &&
423 s.Diag.Memtag_heap == nil && Bool(s.Memtag_heap) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400424 s.Diag.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800425 }
426
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700427 if len(globalSanitizersDiag) > 0 {
428 ctx.ModuleErrorf("unknown global sanitizer diagnostics option %s", globalSanitizersDiag[0])
429 }
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700430 }
Colin Cross3c344ef2016-07-18 15:44:56 -0700431
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800432 // Enable Memtag for all components in the include paths (for Aarch64 only)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800433 if ctx.Arch().ArchType == android.Arm64 {
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800434 if ctx.Config().MemtagHeapSyncEnabledForPath(ctx.ModuleDir()) {
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800435 if s.Memtag_heap == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400436 s.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800437 }
438 if s.Diag.Memtag_heap == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400439 s.Diag.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800440 }
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800441 } else if ctx.Config().MemtagHeapAsyncEnabledForPath(ctx.ModuleDir()) {
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800442 if s.Memtag_heap == nil {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400443 s.Memtag_heap = proptools.BoolPtr(true)
Evgenii Stepanov04896ca2021-01-12 18:28:33 -0800444 }
Evgenii Stepanov4beaa0c2021-01-05 16:41:26 -0800445 }
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700446 }
447
Elvis Chien9c993542021-06-25 01:15:17 +0800448 // Enable CFI for non-host components in the include paths
449 if s.Cfi == nil && ctx.Config().CFIEnabledForPath(ctx.ModuleDir()) && !ctx.Host() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400450 s.Cfi = proptools.BoolPtr(true)
Vishwath Mohan3af8ee02018-03-30 02:55:23 +0000451 if inList("cfi", ctx.Config().SanitizeDeviceDiag()) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400452 s.Diag.Cfi = proptools.BoolPtr(true)
Vishwath Mohan1fa3ac52017-10-31 02:26:14 -0700453 }
454 }
455
Elliott Hughesda3a0712020-03-06 16:55:28 -0800456 // Is CFI actually enabled?
457 if !ctx.Config().EnableCFI() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400458 s.Cfi = nil
459 s.Diag.Cfi = nil
Vishwath Mohan1b017a72017-01-19 13:54:55 -0800460 }
461
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700462 // HWASan requires AArch64 hardware feature (top-byte-ignore).
463 if ctx.Arch().ArchType != android.Arm64 {
464 s.Hwaddress = nil
465 }
466
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800467 // SCS is only implemented on AArch64.
Peter Collingbournebd19db02019-03-06 10:38:48 -0800468 if ctx.Arch().ArchType != android.Arm64 {
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800469 s.Scs = nil
470 }
471
Ivan Lozano62cd0382021-11-01 10:27:54 -0400472 // Memtag_heap is only implemented on AArch64.
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700473 if ctx.Arch().ArchType != android.Arm64 {
474 s.Memtag_heap = nil
475 }
476
Vishwath Mohan8f4fdd82017-04-20 07:42:52 -0700477 // Also disable CFI if ASAN is enabled.
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700478 if Bool(s.Address) || Bool(s.Hwaddress) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400479 s.Cfi = nil
480 s.Diag.Cfi = nil
Vishwath Mohan8f4fdd82017-04-20 07:42:52 -0700481 }
482
Colin Crossed12a042022-02-07 13:55:55 -0800483 // Disable sanitizers that depend on the UBSan runtime for windows/darwin builds.
484 if !ctx.Os().Linux() {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400485 s.Cfi = nil
486 s.Diag.Cfi = nil
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700487 s.Misc_undefined = nil
488 s.Undefined = nil
489 s.All_undefined = nil
490 s.Integer_overflow = nil
Vishwath Mohane7128792017-11-17 11:08:10 -0800491 }
492
Colin Crossed12a042022-02-07 13:55:55 -0800493 // Disable CFI for musl
494 if ctx.toolchain().Musl() {
495 s.Cfi = nil
496 s.Diag.Cfi = nil
497 }
498
Vishwath Mohan9ccbba02018-05-28 13:54:48 -0700499 // Also disable CFI for VNDK variants of components
500 if ctx.isVndk() && ctx.useVndk() {
Inseob Kimc42f2f22020-07-29 20:32:10 +0900501 if ctx.static() {
502 // Cfi variant for static vndk should be captured as vendor snapshot,
503 // so don't strictly disable Cfi.
504 s.Cfi = nil
505 s.Diag.Cfi = nil
506 } else {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400507 s.Cfi = nil
508 s.Diag.Cfi = nil
Inseob Kimc42f2f22020-07-29 20:32:10 +0900509 }
Inseob Kimeec88e12020-01-22 11:11:29 +0900510 }
511
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700512 // HWASan ramdisk (which is built from recovery) goes over some bootloader limit.
Yifan Hong60e0cfb2020-10-21 15:17:56 -0700513 // Keep libc instrumented so that ramdisk / vendor_ramdisk / recovery can run hwasan-instrumented code if necessary.
514 if (ctx.inRamdisk() || ctx.inVendorRamdisk() || ctx.inRecovery()) && !strings.HasPrefix(ctx.ModuleDir(), "bionic/libc") {
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700515 s.Hwaddress = nil
516 }
517
Colin Cross3c344ef2016-07-18 15:44:56 -0700518 if ctx.staticBinary() {
519 s.Address = nil
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700520 s.Fuzzer = nil
Colin Cross3c344ef2016-07-18 15:44:56 -0700521 s.Thread = nil
Colin Cross16b23492016-01-06 14:41:07 -0800522 }
523
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700524 if Bool(s.All_undefined) {
525 s.Undefined = nil
526 }
527
Evgenii Stepanov0a8a0d02016-05-12 13:54:53 -0700528 if !ctx.toolchain().Is64Bit() {
529 // TSAN and SafeStack are not supported on 32-bit architectures
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700530 s.Thread = nil
531 s.Safestack = nil
Colin Cross16b23492016-01-06 14:41:07 -0800532 // TODO(ccross): error for compile_multilib = "32"?
533 }
534
Evgenii Stepanov76cee232017-01-27 15:44:44 -0800535 if ctx.Os() != android.Windows && (Bool(s.All_undefined) || Bool(s.Undefined) || Bool(s.Address) || Bool(s.Thread) ||
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700536 Bool(s.Fuzzer) || Bool(s.Safestack) || Bool(s.Cfi) || Bool(s.Integer_overflow) || len(s.Misc_undefined) > 0 ||
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700537 Bool(s.Scudo) || Bool(s.Hwaddress) || Bool(s.Scs) || Bool(s.Memtag_heap)) {
Colin Cross3c344ef2016-07-18 15:44:56 -0700538 sanitize.Properties.SanitizerEnabled = true
539 }
540
Kostya Kortchinskyd5275c82019-02-01 08:42:56 -0800541 // Disable Scudo if ASan or TSan is enabled, or if it's disabled globally.
542 if Bool(s.Address) || Bool(s.Thread) || Bool(s.Hwaddress) || ctx.Config().DisableScudo() {
Kostya Kortchinskyd18ae5c2018-06-12 14:46:54 -0700543 s.Scudo = nil
544 }
545
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700546 if Bool(s.Hwaddress) {
547 s.Address = nil
548 s.Thread = nil
549 }
Mitch Phillips5007c4a2022-03-02 01:25:22 +0000550
551 // TODO(b/131771163): CFI transiently depends on LTO, and thus Fuzzer is
552 // mutually incompatible.
553 if Bool(s.Fuzzer) {
554 s.Cfi = nil
555 }
Colin Cross16b23492016-01-06 14:41:07 -0800556}
557
Chih-Hung Hsieh3567e622018-11-15 14:01:36 -0800558func toDisableImplicitIntegerChange(flags []string) bool {
559 // Returns true if any flag is fsanitize*integer, and there is
560 // no explicit flag about sanitize=implicit-integer-sign-change.
561 for _, f := range flags {
562 if strings.Contains(f, "sanitize=implicit-integer-sign-change") {
563 return false
564 }
565 }
566 for _, f := range flags {
567 if strings.HasPrefix(f, "-fsanitize") && strings.Contains(f, "integer") {
568 return true
569 }
570 }
571 return false
572}
573
Yabin Cuidb7dda82020-11-30 15:47:45 -0800574func toDisableUnsignedShiftBaseChange(flags []string) bool {
575 // Returns true if any flag is fsanitize*integer, and there is
576 // no explicit flag about sanitize=unsigned-shift-base.
577 for _, f := range flags {
578 if strings.Contains(f, "sanitize=unsigned-shift-base") {
579 return false
580 }
581 }
582 for _, f := range flags {
583 if strings.HasPrefix(f, "-fsanitize") && strings.Contains(f, "integer") {
584 return true
585 }
586 }
587 return false
588}
589
Colin Cross16b23492016-01-06 14:41:07 -0800590func (sanitize *sanitize) flags(ctx ModuleContext, flags Flags) Flags {
Ivan Lozano59fdea22018-05-10 14:17:22 -0700591 minimalRuntimeLib := config.UndefinedBehaviorSanitizerMinimalRuntimeLibrary(ctx.toolchain()) + ".a"
Ivan Lozano30c5db22018-02-21 15:49:20 -0800592
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500593 if sanitize.Properties.MinimalRuntimeDep {
Colin Cross4af21ed2019-11-04 09:37:55 -0800594 flags.Local.LdFlags = append(flags.Local.LdFlags,
Colin Cross4af21ed2019-11-04 09:37:55 -0800595 "-Wl,--exclude-libs,"+minimalRuntimeLib)
Ivan Lozano30c5db22018-02-21 15:49:20 -0800596 }
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500597
Ivan Lozanoa9255a82018-03-13 10:41:07 -0700598 if !sanitize.Properties.SanitizerEnabled && !sanitize.Properties.UbsanRuntimeDep {
Colin Cross16b23492016-01-06 14:41:07 -0800599 return flags
600 }
601
Evgenii Stepanovfcfe56d2016-07-07 10:54:07 -0700602 if Bool(sanitize.Properties.Sanitize.Address) {
Colin Cross635c3b02016-05-18 15:37:25 -0700603 if ctx.Arch().ArchType == android.Arm {
Colin Cross16b23492016-01-06 14:41:07 -0800604 // Frame pointer based unwinder in ASan requires ARM frame setup.
605 // TODO: put in flags?
606 flags.RequiredInstructionSet = "arm"
607 }
Colin Cross4af21ed2019-11-04 09:37:55 -0800608 flags.Local.CFlags = append(flags.Local.CFlags, asanCflags...)
609 flags.Local.LdFlags = append(flags.Local.LdFlags, asanLdflags...)
Colin Cross16b23492016-01-06 14:41:07 -0800610
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000611 if Bool(sanitize.Properties.Sanitize.Writeonly) {
612 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", "-asan-instrument-reads=0")
613 }
614
Colin Cross16b23492016-01-06 14:41:07 -0800615 if ctx.Host() {
616 // -nodefaultlibs (provided with libc++) prevents the driver from linking
617 // libraries needed with -fsanitize=address. http://b/18650275 (WAI)
Colin Cross4af21ed2019-11-04 09:37:55 -0800618 flags.Local.LdFlags = append(flags.Local.LdFlags, "-Wl,--no-as-needed")
Colin Cross16b23492016-01-06 14:41:07 -0800619 } else {
Colin Cross4af21ed2019-11-04 09:37:55 -0800620 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", "-asan-globals=0")
Jiyong Parka2aca282019-02-02 13:13:38 +0900621 if ctx.bootstrap() {
622 flags.DynamicLinker = "/system/bin/bootstrap/linker_asan"
623 } else {
624 flags.DynamicLinker = "/system/bin/linker_asan"
625 }
Colin Cross16b23492016-01-06 14:41:07 -0800626 if flags.Toolchain.Is64Bit() {
627 flags.DynamicLinker += "64"
628 }
629 }
Colin Cross16b23492016-01-06 14:41:07 -0800630 }
631
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700632 if Bool(sanitize.Properties.Sanitize.Hwaddress) {
Colin Cross4af21ed2019-11-04 09:37:55 -0800633 flags.Local.CFlags = append(flags.Local.CFlags, hwasanCflags...)
Yi Kong286abc62021-11-04 16:14:14 +0800634
635 for _, flag := range hwasanCommonflags {
636 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", flag)
637 }
638 for _, flag := range hwasanCommonflags {
639 flags.Local.LdFlags = append(flags.Local.LdFlags, "-Wl,-mllvm,"+flag)
640 }
641
Jasraj Bedibb4511d2020-07-23 22:58:17 +0000642 if Bool(sanitize.Properties.Sanitize.Writeonly) {
643 flags.Local.CFlags = append(flags.Local.CFlags, "-mllvm", "-hwasan-instrument-reads=0")
644 }
Yabin Cui6be405e2017-10-19 15:52:11 -0700645 }
646
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700647 if Bool(sanitize.Properties.Sanitize.Fuzzer) {
Colin Cross4af21ed2019-11-04 09:37:55 -0800648 flags.Local.CFlags = append(flags.Local.CFlags, "-fsanitize=fuzzer-no-link")
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700649
Mitch Phillips5007c4a2022-03-02 01:25:22 +0000650 // TODO(b/131771163): LTO and Fuzzer support is mutually incompatible.
651 _, flags.Local.LdFlags = removeFromList("-flto", flags.Local.LdFlags)
652 _, flags.Local.CFlags = removeFromList("-flto", flags.Local.CFlags)
653 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fno-lto")
654 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-lto")
655
Mitch Phillipsb8e593d2019-10-09 17:18:59 -0700656 // TODO(b/142430592): Upstream linker scripts for sanitizer runtime libraries
657 // discard the sancov_lowest_stack symbol, because it's emulated TLS (and thus
658 // doesn't match the linker script due to the "__emutls_v." prefix).
Colin Cross4af21ed2019-11-04 09:37:55 -0800659 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fno-sanitize-coverage=stack-depth")
660 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-coverage=stack-depth")
Mitch Phillipsb8e593d2019-10-09 17:18:59 -0700661
Mitch Phillipsb9b3e792019-08-28 12:41:07 -0700662 // Disable fortify for fuzzing builds. Generally, we'll be building with
663 // UBSan or ASan here and the fortify checks pollute the stack traces.
Colin Cross4af21ed2019-11-04 09:37:55 -0800664 flags.Local.CFlags = append(flags.Local.CFlags, "-U_FORTIFY_SOURCE")
Mitch Phillips734b4cb2019-12-10 08:44:52 -0800665
666 // Build fuzzer-sanitized libraries with an $ORIGIN DT_RUNPATH. Android's
667 // linker uses DT_RUNPATH, not DT_RPATH. When we deploy cc_fuzz targets and
668 // their libraries to /data/fuzz/<arch>/lib, any transient shared library gets
669 // the DT_RUNPATH from the shared library above it, and not the executable,
670 // meaning that the lookup falls back to the system. Adding the $ORIGIN to the
671 // DT_RUNPATH here means that transient shared libraries can be found
672 // colocated with their parents.
673 flags.Local.LdFlags = append(flags.Local.LdFlags, `-Wl,-rpath,\$$ORIGIN`)
Colin Cross16b23492016-01-06 14:41:07 -0800674 }
675
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700676 if Bool(sanitize.Properties.Sanitize.Cfi) {
Evgenii Stepanov7ebf9fa2017-01-20 14:13:06 -0800677 if ctx.Arch().ArchType == android.Arm {
678 // __cfi_check needs to be built as Thumb (see the code in linker_cfi.cpp). LLVM is not set up
679 // to do this on a function basis, so force Thumb on the entire module.
680 flags.RequiredInstructionSet = "thumb"
681 }
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000682
Colin Cross4af21ed2019-11-04 09:37:55 -0800683 flags.Local.CFlags = append(flags.Local.CFlags, cfiCflags...)
684 flags.Local.AsFlags = append(flags.Local.AsFlags, cfiAsflags...)
Cindy Zhou8cd45de2020-11-16 08:41:00 -0800685 if Bool(sanitize.Properties.Sanitize.Config.Cfi_assembly_support) {
686 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-cfi-canonical-jump-tables")
687 }
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000688 // Only append the default visibility flag if -fvisibility has not already been set
689 // to hidden.
Colin Cross4af21ed2019-11-04 09:37:55 -0800690 if !inList("-fvisibility=hidden", flags.Local.CFlags) {
691 flags.Local.CFlags = append(flags.Local.CFlags, "-fvisibility=default")
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000692 }
Colin Cross4af21ed2019-11-04 09:37:55 -0800693 flags.Local.LdFlags = append(flags.Local.LdFlags, cfiLdflags...)
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000694
695 if ctx.staticBinary() {
Colin Cross4af21ed2019-11-04 09:37:55 -0800696 _, flags.Local.CFlags = removeFromList("-fsanitize-cfi-cross-dso", flags.Local.CFlags)
697 _, flags.Local.LdFlags = removeFromList("-fsanitize-cfi-cross-dso", flags.Local.LdFlags)
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000698 }
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700699 }
700
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700701 if Bool(sanitize.Properties.Sanitize.Integer_overflow) {
Colin Cross4af21ed2019-11-04 09:37:55 -0800702 flags.Local.CFlags = append(flags.Local.CFlags, intOverflowCflags...)
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700703 }
704
Jiyong Park379de2f2018-12-19 02:47:14 +0900705 if len(sanitize.Properties.Sanitizers) > 0 {
706 sanitizeArg := "-fsanitize=" + strings.Join(sanitize.Properties.Sanitizers, ",")
Colin Cross4af21ed2019-11-04 09:37:55 -0800707 flags.Local.CFlags = append(flags.Local.CFlags, sanitizeArg)
708 flags.Local.AsFlags = append(flags.Local.AsFlags, sanitizeArg)
Colin Cross234b01d2022-02-07 13:49:03 -0800709 flags.Local.LdFlags = append(flags.Local.LdFlags, sanitizeArg)
710
Colin Crossed12a042022-02-07 13:55:55 -0800711 if ctx.toolchain().Bionic() || ctx.toolchain().Musl() {
712 // Bionic and musl sanitizer runtimes have already been added as dependencies so that
713 // the right variant of the runtime will be used (with the "-android" or "-musl"
714 // suffixes), so don't let clang the runtime library.
Colin Cross234b01d2022-02-07 13:49:03 -0800715 flags.Local.LdFlags = append(flags.Local.LdFlags, "-fno-sanitize-link-runtime")
716 } else {
Evgenii Stepanov76cee232017-01-27 15:44:44 -0800717 // Host sanitizers only link symbols in the final executable, so
718 // there will always be undefined symbols in intermediate libraries.
Colin Cross4af21ed2019-11-04 09:37:55 -0800719 _, flags.Global.LdFlags = removeFromList("-Wl,--no-undefined", flags.Global.LdFlags)
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500720
Colin Cross234b01d2022-02-07 13:49:03 -0800721 // non-Bionic toolchain prebuilts are missing UBSan's vptr and function san
722 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize=vptr,function")
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500723 }
724
725 if enableMinimalRuntime(sanitize) {
726 flags.Local.CFlags = append(flags.Local.CFlags, strings.Join(minimalRuntimeFlags, " "))
Ivan Lozano9ac32c72020-02-19 15:24:02 -0500727 flags.Local.LdFlags = append(flags.Local.LdFlags, "-Wl,--exclude-libs,"+minimalRuntimeLib)
Colin Cross16b23492016-01-06 14:41:07 -0800728 }
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700729
730 if Bool(sanitize.Properties.Sanitize.Fuzzer) {
731 // When fuzzing, we wish to crash with diagnostics on any bug.
Colin Cross4af21ed2019-11-04 09:37:55 -0800732 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-trap=all", "-fno-sanitize-recover=all")
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700733 } else if ctx.Host() {
Colin Cross4af21ed2019-11-04 09:37:55 -0800734 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-recover=all")
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700735 } else {
Colin Cross4af21ed2019-11-04 09:37:55 -0800736 flags.Local.CFlags = append(flags.Local.CFlags, "-fsanitize-trap=all", "-ftrap-function=abort")
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700737 }
Chih-Hung Hsieh3567e622018-11-15 14:01:36 -0800738 // http://b/119329758, Android core does not boot up with this sanitizer yet.
Colin Cross4af21ed2019-11-04 09:37:55 -0800739 if toDisableImplicitIntegerChange(flags.Local.CFlags) {
740 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize=implicit-integer-sign-change")
Chih-Hung Hsieh3567e622018-11-15 14:01:36 -0800741 }
Yabin Cuidb7dda82020-11-30 15:47:45 -0800742 // http://b/171275751, Android doesn't build with this sanitizer yet.
743 if toDisableUnsignedShiftBaseChange(flags.Local.CFlags) {
744 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize=unsigned-shift-base")
745 }
Colin Cross16b23492016-01-06 14:41:07 -0800746 }
747
Jiyong Park379de2f2018-12-19 02:47:14 +0900748 if len(sanitize.Properties.DiagSanitizers) > 0 {
Colin Cross4af21ed2019-11-04 09:37:55 -0800749 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-trap="+strings.Join(sanitize.Properties.DiagSanitizers, ","))
Evgenii Stepanov1e405e12016-08-16 15:39:54 -0700750 }
751 // FIXME: enable RTTI if diag + (cfi or vptr)
752
Andreas Gampe97071162017-05-08 13:15:23 -0700753 if sanitize.Properties.Sanitize.Recover != nil {
Colin Cross4af21ed2019-11-04 09:37:55 -0800754 flags.Local.CFlags = append(flags.Local.CFlags, "-fsanitize-recover="+
Andreas Gampe97071162017-05-08 13:15:23 -0700755 strings.Join(sanitize.Properties.Sanitize.Recover, ","))
756 }
757
Ivan Lozano7929bba2018-12-12 09:36:31 -0800758 if sanitize.Properties.Sanitize.Diag.No_recover != nil {
Colin Cross4af21ed2019-11-04 09:37:55 -0800759 flags.Local.CFlags = append(flags.Local.CFlags, "-fno-sanitize-recover="+
Ivan Lozano7929bba2018-12-12 09:36:31 -0800760 strings.Join(sanitize.Properties.Sanitize.Diag.No_recover, ","))
761 }
762
Pirama Arumuga Nainar6c4ccca2020-07-27 11:49:51 -0700763 blocklist := android.OptionalPathForModuleSrc(ctx, sanitize.Properties.Sanitize.Blocklist)
764 if blocklist.Valid() {
Pirama Arumuga Nainar582fc2d2021-08-27 15:12:56 -0700765 flags.Local.CFlags = append(flags.Local.CFlags, "-fsanitize-ignorelist="+blocklist.String())
Pirama Arumuga Nainar6c4ccca2020-07-27 11:49:51 -0700766 flags.CFlagsDeps = append(flags.CFlagsDeps, blocklist.Path())
767 }
768
Colin Cross16b23492016-01-06 14:41:07 -0800769 return flags
770}
771
Colin Crossd80cbca2020-02-24 12:01:37 -0800772func (sanitize *sanitize) AndroidMkEntries(ctx AndroidMkContext, entries *android.AndroidMkEntries) {
Jiyong Park1d1119f2019-07-29 21:27:18 +0900773 // Add a suffix for cfi/hwasan/scs-enabled static/header libraries to allow surfacing
774 // both the sanitized and non-sanitized variants to make without a name conflict.
Colin Crossd80cbca2020-02-24 12:01:37 -0800775 if entries.Class == "STATIC_LIBRARIES" || entries.Class == "HEADER_LIBRARIES" {
Jiyong Park1d1119f2019-07-29 21:27:18 +0900776 if Bool(sanitize.Properties.Sanitize.Cfi) {
Colin Crossd80cbca2020-02-24 12:01:37 -0800777 entries.SubName += ".cfi"
Jiyong Park1d1119f2019-07-29 21:27:18 +0900778 }
779 if Bool(sanitize.Properties.Sanitize.Hwaddress) {
Colin Crossd80cbca2020-02-24 12:01:37 -0800780 entries.SubName += ".hwasan"
Jiyong Park1d1119f2019-07-29 21:27:18 +0900781 }
782 if Bool(sanitize.Properties.Sanitize.Scs) {
Colin Crossd80cbca2020-02-24 12:01:37 -0800783 entries.SubName += ".scs"
Jiyong Park1d1119f2019-07-29 21:27:18 +0900784 }
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800785 }
Colin Cross8ff9ef42017-05-08 13:44:11 -0700786}
787
Vishwath Mohan1dd88392017-03-29 22:00:18 -0700788func (sanitize *sanitize) inSanitizerDir() bool {
789 return sanitize.Properties.InSanitizerDir
Colin Cross30d5f512016-05-03 18:02:42 -0700790}
791
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500792// getSanitizerBoolPtr returns the SanitizerTypes associated bool pointer from SanitizeProperties.
793func (sanitize *sanitize) getSanitizerBoolPtr(t SanitizerType) *bool {
Vishwath Mohan95229302017-08-11 00:53:16 +0000794 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500795 case Asan:
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000796 return sanitize.Properties.Sanitize.Address
Tri Vo6eafc362021-04-01 11:29:09 -0700797 case Hwasan:
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700798 return sanitize.Properties.Sanitize.Hwaddress
Vishwath Mohan95229302017-08-11 00:53:16 +0000799 case tsan:
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000800 return sanitize.Properties.Sanitize.Thread
Vishwath Mohan95229302017-08-11 00:53:16 +0000801 case intOverflow:
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000802 return sanitize.Properties.Sanitize.Integer_overflow
803 case cfi:
804 return sanitize.Properties.Sanitize.Cfi
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800805 case scs:
806 return sanitize.Properties.Sanitize.Scs
Ivan Lozano62cd0382021-11-01 10:27:54 -0400807 case Memtag_heap:
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -0700808 return sanitize.Properties.Sanitize.Memtag_heap
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500809 case Fuzzer:
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700810 return sanitize.Properties.Sanitize.Fuzzer
Vishwath Mohan95229302017-08-11 00:53:16 +0000811 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500812 panic(fmt.Errorf("unknown SanitizerType %d", t))
Vishwath Mohan95229302017-08-11 00:53:16 +0000813 }
814}
815
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500816// isUnsanitizedVariant returns true if no sanitizers are enabled.
Dan Albert7d1eecf2018-01-19 12:30:45 -0800817func (sanitize *sanitize) isUnsanitizedVariant() bool {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500818 return !sanitize.isSanitizerEnabled(Asan) &&
Tri Vo6eafc362021-04-01 11:29:09 -0700819 !sanitize.isSanitizerEnabled(Hwasan) &&
Dan Albert7d1eecf2018-01-19 12:30:45 -0800820 !sanitize.isSanitizerEnabled(tsan) &&
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800821 !sanitize.isSanitizerEnabled(cfi) &&
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700822 !sanitize.isSanitizerEnabled(scs) &&
Ivan Lozano62cd0382021-11-01 10:27:54 -0400823 !sanitize.isSanitizerEnabled(Memtag_heap) &&
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500824 !sanitize.isSanitizerEnabled(Fuzzer)
Dan Albert7d1eecf2018-01-19 12:30:45 -0800825}
826
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500827// isVariantOnProductionDevice returns true if variant is for production devices (no non-production sanitizers enabled).
Jayant Chowdharyb7e08ca2018-05-10 15:29:24 -0700828func (sanitize *sanitize) isVariantOnProductionDevice() bool {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500829 return !sanitize.isSanitizerEnabled(Asan) &&
Tri Vo6eafc362021-04-01 11:29:09 -0700830 !sanitize.isSanitizerEnabled(Hwasan) &&
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -0700831 !sanitize.isSanitizerEnabled(tsan) &&
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500832 !sanitize.isSanitizerEnabled(Fuzzer)
Jayant Chowdharyb7e08ca2018-05-10 15:29:24 -0700833}
834
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500835func (sanitize *sanitize) SetSanitizer(t SanitizerType, b bool) {
Liz Kammerb2fc4702021-06-25 14:53:40 -0400836 bPtr := proptools.BoolPtr(b)
837 if !b {
838 bPtr = nil
839 }
Colin Cross16b23492016-01-06 14:41:07 -0800840 switch t {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500841 case Asan:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400842 sanitize.Properties.Sanitize.Address = bPtr
Tri Vo6eafc362021-04-01 11:29:09 -0700843 case Hwasan:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400844 sanitize.Properties.Sanitize.Hwaddress = bPtr
Colin Cross16b23492016-01-06 14:41:07 -0800845 case tsan:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400846 sanitize.Properties.Sanitize.Thread = bPtr
Ivan Lozano0c3a1ef2017-06-28 09:10:48 -0700847 case intOverflow:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400848 sanitize.Properties.Sanitize.Integer_overflow = bPtr
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000849 case cfi:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400850 sanitize.Properties.Sanitize.Cfi = bPtr
Peter Collingbourne8c7e6e22018-11-19 16:03:58 -0800851 case scs:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400852 sanitize.Properties.Sanitize.Scs = bPtr
Ivan Lozano62cd0382021-11-01 10:27:54 -0400853 case Memtag_heap:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400854 sanitize.Properties.Sanitize.Memtag_heap = bPtr
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500855 case Fuzzer:
Liz Kammerb2fc4702021-06-25 14:53:40 -0400856 sanitize.Properties.Sanitize.Fuzzer = bPtr
Colin Cross16b23492016-01-06 14:41:07 -0800857 default:
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500858 panic(fmt.Errorf("unknown SanitizerType %d", t))
Colin Cross16b23492016-01-06 14:41:07 -0800859 }
860 if b {
861 sanitize.Properties.SanitizerEnabled = true
862 }
863}
864
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000865// Check if the sanitizer is explicitly disabled (as opposed to nil by
866// virtue of not being set).
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500867func (sanitize *sanitize) isSanitizerExplicitlyDisabled(t SanitizerType) bool {
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000868 if sanitize == nil {
869 return false
870 }
871
872 sanitizerVal := sanitize.getSanitizerBoolPtr(t)
873 return sanitizerVal != nil && *sanitizerVal == false
874}
875
876// There isn't an analog of the method above (ie:isSanitizerExplicitlyEnabled)
877// because enabling a sanitizer either directly (via the blueprint) or
878// indirectly (via a mutator) sets the bool ptr to true, and you can't
879// distinguish between the cases. It isn't needed though - both cases can be
880// treated identically.
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500881func (sanitize *sanitize) isSanitizerEnabled(t SanitizerType) bool {
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000882 if sanitize == nil {
883 return false
884 }
885
886 sanitizerVal := sanitize.getSanitizerBoolPtr(t)
887 return sanitizerVal != nil && *sanitizerVal == true
888}
889
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500890// IsSanitizableDependencyTag returns true if the dependency tag is sanitizable.
891func IsSanitizableDependencyTag(tag blueprint.DependencyTag) bool {
Colin Cross6e511a92020-07-27 21:26:48 -0700892 switch t := tag.(type) {
893 case dependencyTag:
894 return t == reuseObjTag || t == objDepTag
895 case libraryDependencyTag:
896 return true
897 default:
898 return false
899 }
Colin Cross6b753602018-06-21 13:03:07 -0700900}
901
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500902func (m *Module) SanitizableDepTagChecker() SantizableDependencyTagChecker {
903 return IsSanitizableDependencyTag
904}
905
Inseob Kimc42f2f22020-07-29 20:32:10 +0900906// Determines if the current module is a static library going to be captured
907// as vendor snapshot. Such modules must create both cfi and non-cfi variants,
908// except for ones which explicitly disable cfi.
909func needsCfiForVendorSnapshot(mctx android.TopDownMutatorContext) bool {
Kiyoung Kim48f37782021-07-07 12:42:39 +0900910 if snapshot.IsVendorProprietaryModule(mctx) {
Inseob Kimc42f2f22020-07-29 20:32:10 +0900911 return false
912 }
913
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500914 c := mctx.Module().(PlatformSanitizeable)
Inseob Kimc42f2f22020-07-29 20:32:10 +0900915
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500916 if !c.InVendor() {
Inseob Kimc42f2f22020-07-29 20:32:10 +0900917 return false
918 }
919
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500920 if !c.StaticallyLinked() {
Inseob Kimc42f2f22020-07-29 20:32:10 +0900921 return false
922 }
923
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500924 if c.IsPrebuilt() {
Inseob Kimc42f2f22020-07-29 20:32:10 +0900925 return false
926 }
927
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500928 if !c.SanitizerSupported(cfi) {
929 return false
930 }
931
932 return c.SanitizePropDefined() &&
933 !c.SanitizeNever() &&
934 !c.IsSanitizerExplicitlyDisabled(cfi)
Inseob Kimc42f2f22020-07-29 20:32:10 +0900935}
936
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700937// Propagate sanitizer requirements down from binaries
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500938func sanitizerDepsMutator(t SanitizerType) func(android.TopDownMutatorContext) {
Colin Cross635c3b02016-05-18 15:37:25 -0700939 return func(mctx android.TopDownMutatorContext) {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500940 if c, ok := mctx.Module().(PlatformSanitizeable); ok {
941 enabled := c.IsSanitizerEnabled(t)
Inseob Kimc42f2f22020-07-29 20:32:10 +0900942 if t == cfi && needsCfiForVendorSnapshot(mctx) {
943 // We shouldn't change the result of isSanitizerEnabled(cfi) to correctly
944 // determine defaultVariation in sanitizerMutator below.
945 // Instead, just mark SanitizeDep to forcefully create cfi variant.
946 enabled = true
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500947 c.SetSanitizeDep(true)
Inseob Kimc42f2f22020-07-29 20:32:10 +0900948 }
949 if enabled {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500950 isSanitizableDependencyTag := c.SanitizableDepTagChecker()
Inseob Kimc42f2f22020-07-29 20:32:10 +0900951 mctx.WalkDeps(func(child, parent android.Module) bool {
952 if !isSanitizableDependencyTag(mctx.OtherModuleDependencyTag(child)) {
953 return false
954 }
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500955 if d, ok := child.(PlatformSanitizeable); ok && d.SanitizePropDefined() &&
956 !d.SanitizeNever() &&
957 !d.IsSanitizerExplicitlyDisabled(t) {
Colin Crossaf98f582021-05-12 17:27:32 -0700958 if t == cfi || t == Hwasan || t == scs || t == Asan {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500959 if d.StaticallyLinked() && d.SanitizerSupported(t) {
960 // Rust does not support some of these sanitizers, so we need to check if it's
961 // supported before setting this true.
962 d.SetSanitizeDep(true)
Inseob Kimc42f2f22020-07-29 20:32:10 +0900963 }
964 } else {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500965 d.SetSanitizeDep(true)
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -0700966 }
Vishwath Mohanb743e9c2017-11-01 09:20:21 +0000967 }
Inseob Kimc42f2f22020-07-29 20:32:10 +0900968 return true
969 })
970 }
Jiyong Parkf97782b2019-02-13 20:28:58 +0900971 } else if sanitizeable, ok := mctx.Module().(Sanitizeable); ok {
972 // If an APEX module includes a lib which is enabled for a sanitizer T, then
973 // the APEX module is also enabled for the same sanitizer type.
974 mctx.VisitDirectDeps(func(child android.Module) {
975 if c, ok := child.(*Module); ok && c.sanitize.isSanitizerEnabled(t) {
976 sanitizeable.EnableSanitizer(t.name())
977 }
978 })
Colin Cross16b23492016-01-06 14:41:07 -0800979 }
980 }
981}
982
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500983func (c *Module) SanitizeNever() bool {
984 return Bool(c.sanitize.Properties.Sanitize.Never)
985}
986
987func (c *Module) IsSanitizerExplicitlyDisabled(t SanitizerType) bool {
988 return c.sanitize.isSanitizerExplicitlyDisabled(t)
989}
990
Ivan Lozano30c5db22018-02-21 15:49:20 -0800991// Propagate the ubsan minimal runtime dependency when there are integer overflow sanitized static dependencies.
Colin Cross6b753602018-06-21 13:03:07 -0700992func sanitizerRuntimeDepsMutator(mctx android.TopDownMutatorContext) {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500993 // Change this to PlatformSanitizable when/if non-cc modules support ubsan sanitizers.
Colin Cross6b753602018-06-21 13:03:07 -0700994 if c, ok := mctx.Module().(*Module); ok && c.sanitize != nil {
Ivan Lozano3968d8f2020-12-14 11:27:52 -0500995 isSanitizableDependencyTag := c.SanitizableDepTagChecker()
Colin Cross6b753602018-06-21 13:03:07 -0700996 mctx.WalkDeps(func(child, parent android.Module) bool {
997 if !isSanitizableDependencyTag(mctx.OtherModuleDependencyTag(child)) {
998 return false
999 }
Ivan Lozano30c5db22018-02-21 15:49:20 -08001000
Inseob Kimeec88e12020-01-22 11:11:29 +09001001 d, ok := child.(*Module)
1002 if !ok || !d.static() {
1003 return false
1004 }
1005 if d.sanitize != nil {
Colin Cross6b753602018-06-21 13:03:07 -07001006 if enableMinimalRuntime(d.sanitize) {
1007 // If a static dependency is built with the minimal runtime,
1008 // make sure we include the ubsan minimal runtime.
1009 c.sanitize.Properties.MinimalRuntimeDep = true
Inseob Kim8471cda2019-11-15 09:59:12 +09001010 } else if enableUbsanRuntime(d.sanitize) {
Colin Cross6b753602018-06-21 13:03:07 -07001011 // If a static dependency runs with full ubsan diagnostics,
1012 // make sure we include the ubsan runtime.
1013 c.sanitize.Properties.UbsanRuntimeDep = true
Ivan Lozano30c5db22018-02-21 15:49:20 -08001014 }
Colin Cross0b908332019-06-19 23:00:20 -07001015
1016 if c.sanitize.Properties.MinimalRuntimeDep &&
1017 c.sanitize.Properties.UbsanRuntimeDep {
1018 // both flags that this mutator might set are true, so don't bother recursing
1019 return false
1020 }
1021
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001022 if c.Os() == android.Linux {
1023 c.sanitize.Properties.BuiltinsDep = true
1024 }
1025
Colin Cross0b908332019-06-19 23:00:20 -07001026 return true
Colin Cross6b753602018-06-21 13:03:07 -07001027 }
Inseob Kimeec88e12020-01-22 11:11:29 +09001028
Jose Galmesf7294582020-11-13 12:07:36 -08001029 if p, ok := d.linker.(*snapshotLibraryDecorator); ok {
Inseob Kimeec88e12020-01-22 11:11:29 +09001030 if Bool(p.properties.Sanitize_minimal_dep) {
1031 c.sanitize.Properties.MinimalRuntimeDep = true
1032 }
1033 if Bool(p.properties.Sanitize_ubsan_dep) {
1034 c.sanitize.Properties.UbsanRuntimeDep = true
1035 }
1036 }
1037
1038 return false
Colin Cross6b753602018-06-21 13:03:07 -07001039 })
Ivan Lozano30c5db22018-02-21 15:49:20 -08001040 }
1041}
1042
Jiyong Park379de2f2018-12-19 02:47:14 +09001043// Add the dependency to the runtime library for each of the sanitizer variants
1044func sanitizerRuntimeMutator(mctx android.BottomUpMutatorContext) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001045 if c, ok := mctx.Module().(*Module); ok && c.sanitize != nil {
Pirama Arumuga Nainar6aa21022019-01-25 00:20:35 +00001046 if !c.Enabled() {
1047 return
1048 }
Jiyong Park379de2f2018-12-19 02:47:14 +09001049 var sanitizers []string
1050 var diagSanitizers []string
1051
1052 if Bool(c.sanitize.Properties.Sanitize.All_undefined) {
1053 sanitizers = append(sanitizers, "undefined")
1054 } else {
1055 if Bool(c.sanitize.Properties.Sanitize.Undefined) {
1056 sanitizers = append(sanitizers,
1057 "bool",
1058 "integer-divide-by-zero",
1059 "return",
1060 "returns-nonnull-attribute",
1061 "shift-exponent",
1062 "unreachable",
1063 "vla-bound",
1064 // TODO(danalbert): The following checks currently have compiler performance issues.
1065 //"alignment",
1066 //"bounds",
1067 //"enum",
1068 //"float-cast-overflow",
1069 //"float-divide-by-zero",
1070 //"nonnull-attribute",
1071 //"null",
1072 //"shift-base",
1073 //"signed-integer-overflow",
1074 // TODO(danalbert): Fix UB in libc++'s __tree so we can turn this on.
1075 // https://llvm.org/PR19302
1076 // http://reviews.llvm.org/D6974
1077 // "object-size",
1078 )
1079 }
1080 sanitizers = append(sanitizers, c.sanitize.Properties.Sanitize.Misc_undefined...)
1081 }
1082
1083 if Bool(c.sanitize.Properties.Sanitize.Diag.Undefined) {
1084 diagSanitizers = append(diagSanitizers, "undefined")
1085 }
1086
1087 diagSanitizers = append(diagSanitizers, c.sanitize.Properties.Sanitize.Diag.Misc_undefined...)
1088
1089 if Bool(c.sanitize.Properties.Sanitize.Address) {
1090 sanitizers = append(sanitizers, "address")
1091 diagSanitizers = append(diagSanitizers, "address")
1092 }
1093
1094 if Bool(c.sanitize.Properties.Sanitize.Hwaddress) {
1095 sanitizers = append(sanitizers, "hwaddress")
1096 }
1097
1098 if Bool(c.sanitize.Properties.Sanitize.Thread) {
1099 sanitizers = append(sanitizers, "thread")
1100 }
1101
1102 if Bool(c.sanitize.Properties.Sanitize.Safestack) {
1103 sanitizers = append(sanitizers, "safe-stack")
1104 }
1105
1106 if Bool(c.sanitize.Properties.Sanitize.Cfi) {
1107 sanitizers = append(sanitizers, "cfi")
1108
1109 if Bool(c.sanitize.Properties.Sanitize.Diag.Cfi) {
1110 diagSanitizers = append(diagSanitizers, "cfi")
1111 }
1112 }
1113
1114 if Bool(c.sanitize.Properties.Sanitize.Integer_overflow) {
1115 sanitizers = append(sanitizers, "unsigned-integer-overflow")
1116 sanitizers = append(sanitizers, "signed-integer-overflow")
1117 if Bool(c.sanitize.Properties.Sanitize.Diag.Integer_overflow) {
1118 diagSanitizers = append(diagSanitizers, "unsigned-integer-overflow")
1119 diagSanitizers = append(diagSanitizers, "signed-integer-overflow")
1120 }
1121 }
1122
1123 if Bool(c.sanitize.Properties.Sanitize.Scudo) {
1124 sanitizers = append(sanitizers, "scudo")
1125 }
1126
1127 if Bool(c.sanitize.Properties.Sanitize.Scs) {
1128 sanitizers = append(sanitizers, "shadow-call-stack")
1129 }
1130
Ivan Lozanod7586b62021-04-01 09:49:36 -04001131 if Bool(c.sanitize.Properties.Sanitize.Memtag_heap) && c.Binary() {
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -07001132 noteDep := "note_memtag_heap_async"
1133 if Bool(c.sanitize.Properties.Sanitize.Diag.Memtag_heap) {
1134 noteDep = "note_memtag_heap_sync"
1135 }
Inseob Kim253f5212021-04-08 17:10:31 +09001136 // If we're using snapshots, redirect to snapshot whenever possible
1137 // TODO(b/178470649): clean manual snapshot redirections
1138 snapshot := mctx.Provider(SnapshotInfoProvider).(SnapshotInfo)
1139 if lib, ok := snapshot.StaticLibs[noteDep]; ok {
1140 noteDep = lib
1141 }
Ivan Lozano62cd0382021-11-01 10:27:54 -04001142 depTag := StaticDepTag(true)
Evgenii Stepanov193ac2e2020-04-28 15:09:12 -07001143 variations := append(mctx.Target().Variations(),
1144 blueprint.Variation{Mutator: "link", Variation: "static"})
1145 if c.Device() {
1146 variations = append(variations, c.ImageVariation())
1147 }
1148 mctx.AddFarVariationDependencies(variations, depTag, noteDep)
1149 }
1150
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -07001151 if Bool(c.sanitize.Properties.Sanitize.Fuzzer) {
1152 sanitizers = append(sanitizers, "fuzzer-no-link")
1153 }
1154
Jiyong Park379de2f2018-12-19 02:47:14 +09001155 // Save the list of sanitizers. These will be used again when generating
1156 // the build rules (for Cflags, etc.)
1157 c.sanitize.Properties.Sanitizers = sanitizers
1158 c.sanitize.Properties.DiagSanitizers = diagSanitizers
1159
Ivan Lozanof3b190f2020-03-06 12:01:21 -05001160 // TODO(b/150822854) Hosts have a different default behavior and assume the runtime library is used.
1161 if c.Host() {
1162 diagSanitizers = sanitizers
1163 }
1164
Jiyong Park379de2f2018-12-19 02:47:14 +09001165 // Determine the runtime library required
1166 runtimeLibrary := ""
Ryan Prichardb49fe1b2019-10-11 15:03:34 -07001167 var extraStaticDeps []string
Jiyong Park379de2f2018-12-19 02:47:14 +09001168 toolchain := c.toolchain(mctx)
1169 if Bool(c.sanitize.Properties.Sanitize.Address) {
1170 runtimeLibrary = config.AddressSanitizerRuntimeLibrary(toolchain)
1171 } else if Bool(c.sanitize.Properties.Sanitize.Hwaddress) {
1172 if c.staticBinary() {
1173 runtimeLibrary = config.HWAddressSanitizerStaticLibrary(toolchain)
Ryan Prichardb49fe1b2019-10-11 15:03:34 -07001174 extraStaticDeps = []string{"libdl"}
Jiyong Park379de2f2018-12-19 02:47:14 +09001175 } else {
1176 runtimeLibrary = config.HWAddressSanitizerRuntimeLibrary(toolchain)
1177 }
1178 } else if Bool(c.sanitize.Properties.Sanitize.Thread) {
1179 runtimeLibrary = config.ThreadSanitizerRuntimeLibrary(toolchain)
1180 } else if Bool(c.sanitize.Properties.Sanitize.Scudo) {
1181 if len(diagSanitizers) == 0 && !c.sanitize.Properties.UbsanRuntimeDep {
1182 runtimeLibrary = config.ScudoMinimalRuntimeLibrary(toolchain)
1183 } else {
1184 runtimeLibrary = config.ScudoRuntimeLibrary(toolchain)
1185 }
Mitch Phillipsb8e593d2019-10-09 17:18:59 -07001186 } else if len(diagSanitizers) > 0 || c.sanitize.Properties.UbsanRuntimeDep ||
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001187 Bool(c.sanitize.Properties.Sanitize.Fuzzer) ||
1188 Bool(c.sanitize.Properties.Sanitize.Undefined) ||
1189 Bool(c.sanitize.Properties.Sanitize.All_undefined) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001190 runtimeLibrary = config.UndefinedBehaviorSanitizerRuntimeLibrary(toolchain)
Colin Cross32f1de32021-03-29 13:41:37 -07001191 if c.staticBinary() {
1192 runtimeLibrary += ".static"
1193 }
Jiyong Park379de2f2018-12-19 02:47:14 +09001194 }
1195
Colin Cross06c80eb2022-02-10 10:34:19 -08001196 addStaticDeps := func(deps ...string) {
1197 // If we're using snapshots, redirect to snapshot whenever possible
1198 snapshot := mctx.Provider(SnapshotInfoProvider).(SnapshotInfo)
1199 for idx, dep := range deps {
1200 if lib, ok := snapshot.StaticLibs[dep]; ok {
1201 deps[idx] = lib
1202 }
1203 }
1204
1205 // static executable gets static runtime libs
1206 depTag := libraryDependencyTag{Kind: staticLibraryDependency}
1207 variations := append(mctx.Target().Variations(),
1208 blueprint.Variation{Mutator: "link", Variation: "static"})
1209 if c.Device() {
1210 variations = append(variations, c.ImageVariation())
1211 }
1212 if c.UseSdk() {
1213 variations = append(variations,
1214 blueprint.Variation{Mutator: "sdk", Variation: "sdk"})
1215 }
1216 mctx.AddFarVariationDependencies(variations, depTag, deps...)
1217
1218 }
1219 if enableMinimalRuntime(c.sanitize) || c.sanitize.Properties.MinimalRuntimeDep {
1220 addStaticDeps(config.UndefinedBehaviorSanitizerMinimalRuntimeLibrary(toolchain))
1221 }
1222 if c.sanitize.Properties.BuiltinsDep {
1223 addStaticDeps(config.BuiltinsRuntimeLibrary(toolchain))
1224 }
1225
Colin Crossed12a042022-02-07 13:55:55 -08001226 if runtimeLibrary != "" && (toolchain.Bionic() || toolchain.Musl() || c.sanitize.Properties.UbsanRuntimeDep) {
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001227 // UBSan is supported on non-bionic linux host builds as well
Jiyong Park379de2f2018-12-19 02:47:14 +09001228
1229 // Adding dependency to the runtime library. We are using *FarVariation*
1230 // because the runtime libraries themselves are not mutated by sanitizer
1231 // mutators and thus don't have sanitizer variants whereas this module
1232 // has been already mutated.
1233 //
1234 // Note that by adding dependency with {static|shared}DepTag, the lib is
1235 // added to libFlags and LOCAL_SHARED_LIBRARIES by cc.Module
1236 if c.staticBinary() {
Colin Cross06c80eb2022-02-10 10:34:19 -08001237 addStaticDeps(runtimeLibrary)
1238 addStaticDeps(extraStaticDeps...)
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001239 } else if !c.static() && !c.Header() {
Colin Crosse0edaf92021-01-11 17:31:17 -08001240 // If we're using snapshots, redirect to snapshot whenever possible
1241 snapshot := mctx.Provider(SnapshotInfoProvider).(SnapshotInfo)
1242 if lib, ok := snapshot.SharedLibs[runtimeLibrary]; ok {
1243 runtimeLibrary = lib
Inseob Kimeec88e12020-01-22 11:11:29 +09001244 }
Colin Crosse0edaf92021-01-11 17:31:17 -08001245
Cindy Zhou18417cb2020-12-10 07:12:38 -08001246 // Skip apex dependency check for sharedLibraryDependency
1247 // when sanitizer diags are enabled. Skipping the check will allow
1248 // building with diag libraries without having to list the
1249 // dependency in Apex's allowed_deps file.
1250 diagEnabled := len(diagSanitizers) > 0
Jiyong Park3b1746a2019-01-29 11:15:04 +09001251 // dynamic executable and shared libs get shared runtime libs
Cindy Zhou18417cb2020-12-10 07:12:38 -08001252 depTag := libraryDependencyTag{
1253 Kind: sharedLibraryDependency,
1254 Order: earlyLibraryDependency,
1255
1256 skipApexAllowedDependenciesCheck: diagEnabled,
1257 }
Colin Cross42507332020-08-21 16:15:23 -07001258 variations := append(mctx.Target().Variations(),
1259 blueprint.Variation{Mutator: "link", Variation: "shared"})
1260 if c.Device() {
1261 variations = append(variations, c.ImageVariation())
1262 }
Colin Cross06c80eb2022-02-10 10:34:19 -08001263 if c.UseSdk() {
1264 variations = append(variations,
1265 blueprint.Variation{Mutator: "sdk", Variation: "sdk"})
1266 }
Ivan Lozanod67a6b02021-05-20 13:01:32 -04001267 AddSharedLibDependenciesWithVersions(mctx, c, variations, depTag, runtimeLibrary, "", true)
Jiyong Park379de2f2018-12-19 02:47:14 +09001268 }
1269 // static lib does not have dependency to the runtime library. The
1270 // dependency will be added to the executables or shared libs using
1271 // the static lib.
1272 }
1273 }
1274}
1275
1276type Sanitizeable interface {
1277 android.Module
Jiyong Park388ef3f2019-01-28 19:47:32 +09001278 IsSanitizerEnabled(ctx android.BaseModuleContext, sanitizerName string) bool
Jiyong Parkf97782b2019-02-13 20:28:58 +09001279 EnableSanitizer(sanitizerName string)
Jooyung Han8ce8db92020-05-15 19:05:05 +09001280 AddSanitizerDependencies(ctx android.BottomUpMutatorContext, sanitizerName string)
Jiyong Park379de2f2018-12-19 02:47:14 +09001281}
1282
Ivan Lozanod7586b62021-04-01 09:49:36 -04001283func (c *Module) MinimalRuntimeDep() bool {
1284 return c.sanitize.Properties.MinimalRuntimeDep
1285}
1286
1287func (c *Module) UbsanRuntimeDep() bool {
1288 return c.sanitize.Properties.UbsanRuntimeDep
1289}
1290
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001291func (c *Module) SanitizePropDefined() bool {
1292 return c.sanitize != nil
1293}
1294
1295func (c *Module) IsSanitizerEnabled(t SanitizerType) bool {
1296 return c.sanitize.isSanitizerEnabled(t)
1297}
1298
1299func (c *Module) SanitizeDep() bool {
1300 return c.sanitize.Properties.SanitizeDep
1301}
1302
1303func (c *Module) StaticallyLinked() bool {
1304 return c.static()
1305}
1306
1307func (c *Module) SetInSanitizerDir() {
1308 if c.sanitize != nil {
1309 c.sanitize.Properties.InSanitizerDir = true
1310 }
1311}
1312
1313func (c *Module) SetSanitizer(t SanitizerType, b bool) {
1314 if c.sanitize != nil {
1315 c.sanitize.SetSanitizer(t, b)
1316 }
1317}
1318
1319func (c *Module) SetSanitizeDep(b bool) {
1320 if c.sanitize != nil {
1321 c.sanitize.Properties.SanitizeDep = b
1322 }
1323}
1324
1325var _ PlatformSanitizeable = (*Module)(nil)
1326
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001327// Create sanitized variants for modules that need them
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001328func sanitizerMutator(t SanitizerType) func(android.BottomUpMutatorContext) {
Colin Cross635c3b02016-05-18 15:37:25 -07001329 return func(mctx android.BottomUpMutatorContext) {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001330 if c, ok := mctx.Module().(PlatformSanitizeable); ok && c.SanitizePropDefined() {
Ivan Lozano5482d6a2021-11-01 10:13:25 -04001331
1332 // Make sure we're not setting CFI to any value if it's not supported.
1333 cfiSupported := mctx.Module().(PlatformSanitizeable).SanitizerSupported(cfi)
1334
Liz Kammer187d5442021-06-25 14:50:12 -04001335 if c.Binary() && c.IsSanitizerEnabled(t) {
Jiyong Park82226632019-02-01 10:50:50 +09001336 modules := mctx.CreateVariations(t.variationName())
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001337 modules[0].(PlatformSanitizeable).SetSanitizer(t, true)
1338 } else if c.IsSanitizerEnabled(t) || c.SanitizeDep() {
1339 isSanitizerEnabled := c.IsSanitizerEnabled(t)
Colin Crossaf98f582021-05-12 17:27:32 -07001340 if c.StaticallyLinked() || c.Header() || t == Fuzzer {
Jiyong Park1d1119f2019-07-29 21:27:18 +09001341 // Static and header libs are split into non-sanitized and sanitized variants.
1342 // Shared libs are not split. However, for asan and fuzzer, we split even for shared
1343 // libs because a library sanitized for asan/fuzzer can't be linked from a library
1344 // that isn't sanitized for asan/fuzzer.
1345 //
1346 // Note for defaultVariation: since we don't split for shared libs but for static/header
1347 // libs, it is possible for the sanitized variant of a static/header lib to depend
1348 // on non-sanitized variant of a shared lib. Such unfulfilled variation causes an
1349 // error when the module is split. defaultVariation is the name of the variation that
1350 // will be used when such a dangling dependency occurs during the split of the current
1351 // module. By setting it to the name of the sanitized variation, the dangling dependency
1352 // is redirected to the sanitized variant of the dependent module.
1353 defaultVariation := t.variationName()
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001354 // Not all PlatformSanitizeable modules support the CFI sanitizer
Jiyong Park1d1119f2019-07-29 21:27:18 +09001355 mctx.SetDefaultDependencyVariation(&defaultVariation)
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001356
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001357 modules := mctx.CreateVariations("", t.variationName())
1358 modules[0].(PlatformSanitizeable).SetSanitizer(t, false)
1359 modules[1].(PlatformSanitizeable).SetSanitizer(t, true)
1360 modules[0].(PlatformSanitizeable).SetSanitizeDep(false)
1361 modules[1].(PlatformSanitizeable).SetSanitizeDep(false)
1362
1363 if mctx.Device() && t.incompatibleWithCfi() && cfiSupported {
Ivan Lozano4774a812020-03-10 16:23:57 -04001364 // TODO: Make sure that cfi mutator runs "after" any of the sanitizers that
1365 // are incompatible with cfi
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001366 modules[1].(PlatformSanitizeable).SetSanitizer(cfi, false)
Ivan Lozano4774a812020-03-10 16:23:57 -04001367 }
1368
Jiyong Park1d1119f2019-07-29 21:27:18 +09001369 // For cfi/scs/hwasan, we can export both sanitized and un-sanitized variants
1370 // to Make, because the sanitized version has a different suffix in name.
1371 // For other types of sanitizers, suppress the variation that is disabled.
Tri Vo6eafc362021-04-01 11:29:09 -07001372 if t != cfi && t != scs && t != Hwasan {
Jiyong Park1d1119f2019-07-29 21:27:18 +09001373 if isSanitizerEnabled {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001374 modules[0].(PlatformSanitizeable).SetPreventInstall()
1375 modules[0].(PlatformSanitizeable).SetHideFromMake()
Jiyong Park1d1119f2019-07-29 21:27:18 +09001376 } else {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001377 modules[1].(PlatformSanitizeable).SetPreventInstall()
1378 modules[1].(PlatformSanitizeable).SetHideFromMake()
Jiyong Park1d1119f2019-07-29 21:27:18 +09001379 }
1380 }
Vishwath Mohanb743e9c2017-11-01 09:20:21 +00001381
Jiyong Park1d1119f2019-07-29 21:27:18 +09001382 // Export the static lib name to make
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001383 if c.StaticallyLinked() && c.ExportedToMake() {
Jiyong Park1d1119f2019-07-29 21:27:18 +09001384 if t == cfi {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001385 cfiStaticLibs(mctx.Config()).add(c, c.Module().Name())
Tri Vo6eafc362021-04-01 11:29:09 -07001386 } else if t == Hwasan {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001387 hwasanStaticLibs(mctx.Config()).add(c, c.Module().Name())
Jiyong Park1d1119f2019-07-29 21:27:18 +09001388 }
1389 }
1390 } else {
1391 // Shared libs are not split. Only the sanitized variant is created.
1392 modules := mctx.CreateVariations(t.variationName())
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001393 modules[0].(PlatformSanitizeable).SetSanitizer(t, true)
1394 modules[0].(PlatformSanitizeable).SetSanitizeDep(false)
Vishwath Mohane7128792017-11-17 11:08:10 -08001395
Jiyong Park1d1119f2019-07-29 21:27:18 +09001396 // locate the asan libraries under /data/asan
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001397 if mctx.Device() && t == Asan && isSanitizerEnabled {
1398 modules[0].(PlatformSanitizeable).SetInSanitizerDir()
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -07001399 }
Ivan Lozano4774a812020-03-10 16:23:57 -04001400
Ivan Lozano5482d6a2021-11-01 10:13:25 -04001401 if mctx.Device() && t.incompatibleWithCfi() && cfiSupported {
Ivan Lozano4774a812020-03-10 16:23:57 -04001402 // TODO: Make sure that cfi mutator runs "after" any of the sanitizers that
1403 // are incompatible with cfi
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001404 modules[0].(PlatformSanitizeable).SetSanitizer(cfi, false)
Ivan Lozano4774a812020-03-10 16:23:57 -04001405 }
Vishwath Mohane21fe422017-11-01 19:42:45 -07001406 }
Colin Cross16b23492016-01-06 14:41:07 -08001407 }
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001408 c.SetSanitizeDep(false)
Jiyong Park82226632019-02-01 10:50:50 +09001409 } else if sanitizeable, ok := mctx.Module().(Sanitizeable); ok && sanitizeable.IsSanitizerEnabled(mctx, t.name()) {
Jiyong Park379de2f2018-12-19 02:47:14 +09001410 // APEX modules fall here
Jooyung Han8ce8db92020-05-15 19:05:05 +09001411 sanitizeable.AddSanitizerDependencies(mctx, t.name())
Jiyong Park82226632019-02-01 10:50:50 +09001412 mctx.CreateVariations(t.variationName())
Inseob Kimc42f2f22020-07-29 20:32:10 +09001413 } else if c, ok := mctx.Module().(*Module); ok {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001414 //TODO: When Rust modules have vendor support, enable this path for PlatformSanitizeable
1415
Inseob Kimc42f2f22020-07-29 20:32:10 +09001416 // Check if it's a snapshot module supporting sanitizer
1417 if s, ok := c.linker.(snapshotSanitizer); ok && s.isSanitizerEnabled(t) {
1418 // Set default variation as above.
1419 defaultVariation := t.variationName()
1420 mctx.SetDefaultDependencyVariation(&defaultVariation)
1421 modules := mctx.CreateVariations("", t.variationName())
1422 modules[0].(*Module).linker.(snapshotSanitizer).setSanitizerVariation(t, false)
1423 modules[1].(*Module).linker.(snapshotSanitizer).setSanitizerVariation(t, true)
1424
1425 // Export the static lib name to make
1426 if c.static() && c.ExportedToMake() {
1427 if t == cfi {
1428 // use BaseModuleName which is the name for Make.
1429 cfiStaticLibs(mctx.Config()).add(c, c.BaseModuleName())
1430 }
1431 }
1432 }
Colin Cross16b23492016-01-06 14:41:07 -08001433 }
1434 }
1435}
Vishwath Mohane7128792017-11-17 11:08:10 -08001436
Inseob Kim74d25562020-08-04 00:41:38 +09001437type sanitizerStaticLibsMap struct {
1438 // libsMap contains one list of modules per each image and each arch.
1439 // e.g. libs[vendor]["arm"] contains arm modules installed to vendor
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001440 libsMap map[ImageVariantType]map[string][]string
Inseob Kim74d25562020-08-04 00:41:38 +09001441 libsMapLock sync.Mutex
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001442 sanitizerType SanitizerType
Inseob Kim74d25562020-08-04 00:41:38 +09001443}
1444
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001445func newSanitizerStaticLibsMap(t SanitizerType) *sanitizerStaticLibsMap {
Inseob Kim74d25562020-08-04 00:41:38 +09001446 return &sanitizerStaticLibsMap{
1447 sanitizerType: t,
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001448 libsMap: make(map[ImageVariantType]map[string][]string),
Inseob Kim74d25562020-08-04 00:41:38 +09001449 }
1450}
1451
1452// Add the current module to sanitizer static libs maps
1453// Each module should pass its exported name as names of Make and Soong can differ.
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001454func (s *sanitizerStaticLibsMap) add(c LinkableInterface, name string) {
1455 image := GetImageVariantType(c)
1456 arch := c.Module().Target().Arch.ArchType.String()
Inseob Kim74d25562020-08-04 00:41:38 +09001457
1458 s.libsMapLock.Lock()
1459 defer s.libsMapLock.Unlock()
1460
1461 if _, ok := s.libsMap[image]; !ok {
1462 s.libsMap[image] = make(map[string][]string)
1463 }
1464
1465 s.libsMap[image][arch] = append(s.libsMap[image][arch], name)
1466}
1467
1468// Exports makefile variables in the following format:
1469// SOONG_{sanitizer}_{image}_{arch}_STATIC_LIBRARIES
1470// e.g. SOONG_cfi_core_x86_STATIC_LIBRARIES
1471// These are to be used by use_soong_sanitized_static_libraries.
1472// See build/make/core/binary.mk for more details.
1473func (s *sanitizerStaticLibsMap) exportToMake(ctx android.MakeVarsContext) {
1474 for _, image := range android.SortedStringKeys(s.libsMap) {
Ivan Lozano3968d8f2020-12-14 11:27:52 -05001475 archMap := s.libsMap[ImageVariantType(image)]
Inseob Kim74d25562020-08-04 00:41:38 +09001476 for _, arch := range android.SortedStringKeys(archMap) {
1477 libs := archMap[arch]
1478 sort.Strings(libs)
1479
1480 key := fmt.Sprintf(
1481 "SOONG_%s_%s_%s_STATIC_LIBRARIES",
1482 s.sanitizerType.variationName(),
1483 image, // already upper
1484 arch)
1485
1486 ctx.Strict(key, strings.Join(libs, " "))
1487 }
1488 }
1489}
1490
Colin Cross571cccf2019-02-04 11:22:08 -08001491var cfiStaticLibsKey = android.NewOnceKey("cfiStaticLibs")
1492
Inseob Kim74d25562020-08-04 00:41:38 +09001493func cfiStaticLibs(config android.Config) *sanitizerStaticLibsMap {
Colin Cross571cccf2019-02-04 11:22:08 -08001494 return config.Once(cfiStaticLibsKey, func() interface{} {
Inseob Kim74d25562020-08-04 00:41:38 +09001495 return newSanitizerStaticLibsMap(cfi)
1496 }).(*sanitizerStaticLibsMap)
Vishwath Mohane7128792017-11-17 11:08:10 -08001497}
1498
Colin Cross571cccf2019-02-04 11:22:08 -08001499var hwasanStaticLibsKey = android.NewOnceKey("hwasanStaticLibs")
1500
Inseob Kim74d25562020-08-04 00:41:38 +09001501func hwasanStaticLibs(config android.Config) *sanitizerStaticLibsMap {
Colin Cross571cccf2019-02-04 11:22:08 -08001502 return config.Once(hwasanStaticLibsKey, func() interface{} {
Tri Vo6eafc362021-04-01 11:29:09 -07001503 return newSanitizerStaticLibsMap(Hwasan)
Inseob Kim74d25562020-08-04 00:41:38 +09001504 }).(*sanitizerStaticLibsMap)
Jiyong Park1d1119f2019-07-29 21:27:18 +09001505}
1506
Ivan Lozano30c5db22018-02-21 15:49:20 -08001507func enableMinimalRuntime(sanitize *sanitize) bool {
1508 if !Bool(sanitize.Properties.Sanitize.Address) &&
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -07001509 !Bool(sanitize.Properties.Sanitize.Hwaddress) &&
Mitch Phillips5a6ea6c2019-05-01 14:42:05 -07001510 !Bool(sanitize.Properties.Sanitize.Fuzzer) &&
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001511
Ivan Lozano30c5db22018-02-21 15:49:20 -08001512 (Bool(sanitize.Properties.Sanitize.Integer_overflow) ||
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001513 len(sanitize.Properties.Sanitize.Misc_undefined) > 0 ||
1514 Bool(sanitize.Properties.Sanitize.Undefined) ||
1515 Bool(sanitize.Properties.Sanitize.All_undefined)) &&
1516
Ivan Lozano30c5db22018-02-21 15:49:20 -08001517 !(Bool(sanitize.Properties.Sanitize.Diag.Integer_overflow) ||
1518 Bool(sanitize.Properties.Sanitize.Diag.Cfi) ||
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001519 Bool(sanitize.Properties.Sanitize.Diag.Undefined) ||
Ivan Lozano30c5db22018-02-21 15:49:20 -08001520 len(sanitize.Properties.Sanitize.Diag.Misc_undefined) > 0) {
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001521
Ivan Lozano30c5db22018-02-21 15:49:20 -08001522 return true
1523 }
1524 return false
1525}
1526
Ivan Lozanod7586b62021-04-01 09:49:36 -04001527func (m *Module) UbsanRuntimeNeeded() bool {
1528 return enableUbsanRuntime(m.sanitize)
1529}
1530
1531func (m *Module) MinimalRuntimeNeeded() bool {
1532 return enableMinimalRuntime(m.sanitize)
1533}
1534
Inseob Kim8471cda2019-11-15 09:59:12 +09001535func enableUbsanRuntime(sanitize *sanitize) bool {
1536 return Bool(sanitize.Properties.Sanitize.Diag.Integer_overflow) ||
Ivan Lozano9ac32c72020-02-19 15:24:02 -05001537 Bool(sanitize.Properties.Sanitize.Diag.Undefined) ||
Inseob Kim8471cda2019-11-15 09:59:12 +09001538 len(sanitize.Properties.Sanitize.Diag.Misc_undefined) > 0
1539}
1540
Vishwath Mohane7128792017-11-17 11:08:10 -08001541func cfiMakeVarsProvider(ctx android.MakeVarsContext) {
Inseob Kim74d25562020-08-04 00:41:38 +09001542 cfiStaticLibs(ctx.Config()).exportToMake(ctx)
Vishwath Mohane7128792017-11-17 11:08:10 -08001543}
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -07001544
1545func hwasanMakeVarsProvider(ctx android.MakeVarsContext) {
Inseob Kim74d25562020-08-04 00:41:38 +09001546 hwasanStaticLibs(ctx.Config()).exportToMake(ctx)
Evgenii Stepanovd97a6e92018-08-02 16:19:13 -07001547}