xref: /aosp_15_r20/bionic/tests/hwasan_test.cpp (revision 8d67ca893c1523eb926b9080dbe4e2ffd2a27ba1)
1*8d67ca89SAndroid Build Coastguard Worker /*
2*8d67ca89SAndroid Build Coastguard Worker  * Copyright (C) 2023 The Android Open Source Project
3*8d67ca89SAndroid Build Coastguard Worker  * All rights reserved.
4*8d67ca89SAndroid Build Coastguard Worker  *
5*8d67ca89SAndroid Build Coastguard Worker  * Redistribution and use in source and binary forms, with or without
6*8d67ca89SAndroid Build Coastguard Worker  * modification, are permitted provided that the following conditions
7*8d67ca89SAndroid Build Coastguard Worker  * are met:
8*8d67ca89SAndroid Build Coastguard Worker  *  * Redistributions of source code must retain the above copyright
9*8d67ca89SAndroid Build Coastguard Worker  *    notice, this list of conditions and the following disclaimer.
10*8d67ca89SAndroid Build Coastguard Worker  *  * Redistributions in binary form must reproduce the above copyright
11*8d67ca89SAndroid Build Coastguard Worker  *    notice, this list of conditions and the following disclaimer in
12*8d67ca89SAndroid Build Coastguard Worker  *    the documentation and/or other materials provided with the
13*8d67ca89SAndroid Build Coastguard Worker  *    distribution.
14*8d67ca89SAndroid Build Coastguard Worker  *
15*8d67ca89SAndroid Build Coastguard Worker  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
16*8d67ca89SAndroid Build Coastguard Worker  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
17*8d67ca89SAndroid Build Coastguard Worker  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
18*8d67ca89SAndroid Build Coastguard Worker  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
19*8d67ca89SAndroid Build Coastguard Worker  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
20*8d67ca89SAndroid Build Coastguard Worker  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
21*8d67ca89SAndroid Build Coastguard Worker  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
22*8d67ca89SAndroid Build Coastguard Worker  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
23*8d67ca89SAndroid Build Coastguard Worker  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
24*8d67ca89SAndroid Build Coastguard Worker  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
25*8d67ca89SAndroid Build Coastguard Worker  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26*8d67ca89SAndroid Build Coastguard Worker  * SUCH DAMAGE.
27*8d67ca89SAndroid Build Coastguard Worker  */
28*8d67ca89SAndroid Build Coastguard Worker 
29*8d67ca89SAndroid Build Coastguard Worker #include <dlfcn.h>
30*8d67ca89SAndroid Build Coastguard Worker #include <stdlib.h>
31*8d67ca89SAndroid Build Coastguard Worker 
32*8d67ca89SAndroid Build Coastguard Worker #include <gtest/gtest.h>
33*8d67ca89SAndroid Build Coastguard Worker 
34*8d67ca89SAndroid Build Coastguard Worker #include <android-base/silent_death_test.h>
35*8d67ca89SAndroid Build Coastguard Worker #include <android-base/test_utils.h>
36*8d67ca89SAndroid Build Coastguard Worker 
37*8d67ca89SAndroid Build Coastguard Worker using HwasanDeathTest = SilentDeathTest;
38*8d67ca89SAndroid Build Coastguard Worker 
39*8d67ca89SAndroid Build Coastguard Worker 
40*8d67ca89SAndroid Build Coastguard Worker #ifdef HWASAN_TEST_STATIC
41*8d67ca89SAndroid Build Coastguard Worker #define MAYBE_DlopenAbsolutePath DISABLED_DlopenAbsolutePath
42*8d67ca89SAndroid Build Coastguard Worker // TODO(fmayer): figure out why uaf is misclassified as out of bounds for
43*8d67ca89SAndroid Build Coastguard Worker // static executables.
44*8d67ca89SAndroid Build Coastguard Worker #define MAYBE_UseAfterFree DISABLED_UseAfterFree
45*8d67ca89SAndroid Build Coastguard Worker #else
46*8d67ca89SAndroid Build Coastguard Worker #define MAYBE_DlopenAbsolutePath DlopenAbsolutePath
47*8d67ca89SAndroid Build Coastguard Worker #define MAYBE_UseAfterFree UseAfterFree
48*8d67ca89SAndroid Build Coastguard Worker #endif
49*8d67ca89SAndroid Build Coastguard Worker 
TEST_F(HwasanDeathTest,MAYBE_UseAfterFree)50*8d67ca89SAndroid Build Coastguard Worker TEST_F(HwasanDeathTest, MAYBE_UseAfterFree) {
51*8d67ca89SAndroid Build Coastguard Worker   EXPECT_DEATH(
52*8d67ca89SAndroid Build Coastguard Worker       {
53*8d67ca89SAndroid Build Coastguard Worker         void* m = malloc(1);
54*8d67ca89SAndroid Build Coastguard Worker         volatile char* x = const_cast<volatile char*>(reinterpret_cast<char*>(m));
55*8d67ca89SAndroid Build Coastguard Worker         *x = 1;
56*8d67ca89SAndroid Build Coastguard Worker         free(m);
57*8d67ca89SAndroid Build Coastguard Worker         *x = 2;
58*8d67ca89SAndroid Build Coastguard Worker       },
59*8d67ca89SAndroid Build Coastguard Worker       "use-after-free");
60*8d67ca89SAndroid Build Coastguard Worker }
61*8d67ca89SAndroid Build Coastguard Worker 
TEST_F(HwasanDeathTest,OutOfBounds)62*8d67ca89SAndroid Build Coastguard Worker TEST_F(HwasanDeathTest, OutOfBounds) {
63*8d67ca89SAndroid Build Coastguard Worker   EXPECT_DEATH(
64*8d67ca89SAndroid Build Coastguard Worker       {
65*8d67ca89SAndroid Build Coastguard Worker         void* m = malloc(1);
66*8d67ca89SAndroid Build Coastguard Worker         volatile char* x = const_cast<volatile char*>(reinterpret_cast<char*>(m));
67*8d67ca89SAndroid Build Coastguard Worker         x[1] = 1;
68*8d67ca89SAndroid Build Coastguard Worker       },
69*8d67ca89SAndroid Build Coastguard Worker       "buffer-overflow");
70*8d67ca89SAndroid Build Coastguard Worker }
71*8d67ca89SAndroid Build Coastguard Worker 
72*8d67ca89SAndroid Build Coastguard Worker // Check whether dlopen of /foo/bar.so checks /foo/hwasan/bar.so first.
TEST(HwasanTest,MAYBE_DlopenAbsolutePath)73*8d67ca89SAndroid Build Coastguard Worker TEST(HwasanTest, MAYBE_DlopenAbsolutePath) {
74*8d67ca89SAndroid Build Coastguard Worker   std::string path = android::base::GetExecutableDirectory() + "/libtest_simple_hwasan.so";
75*8d67ca89SAndroid Build Coastguard Worker   ASSERT_EQ(0, access(path.c_str(), F_OK));  // Verify test setup.
76*8d67ca89SAndroid Build Coastguard Worker   std::string hwasan_path =
77*8d67ca89SAndroid Build Coastguard Worker       android::base::GetExecutableDirectory() + "/hwasan/libtest_simple_hwasan.so";
78*8d67ca89SAndroid Build Coastguard Worker   ASSERT_EQ(0, access(hwasan_path.c_str(), F_OK));  // Verify test setup.
79*8d67ca89SAndroid Build Coastguard Worker 
80*8d67ca89SAndroid Build Coastguard Worker   void* handle = dlopen(path.c_str(), RTLD_NOW);
81*8d67ca89SAndroid Build Coastguard Worker   ASSERT_TRUE(handle != nullptr);
82*8d67ca89SAndroid Build Coastguard Worker   uint32_t* compiled_with_hwasan =
83*8d67ca89SAndroid Build Coastguard Worker       reinterpret_cast<uint32_t*>(dlsym(handle, "dlopen_testlib_compiled_with_hwasan"));
84*8d67ca89SAndroid Build Coastguard Worker   EXPECT_TRUE(*compiled_with_hwasan);
85*8d67ca89SAndroid Build Coastguard Worker   dlclose(handle);
86*8d67ca89SAndroid Build Coastguard Worker }
87*8d67ca89SAndroid Build Coastguard Worker 
TEST(HwasanTest,IsRunningWithHWasan)88*8d67ca89SAndroid Build Coastguard Worker TEST(HwasanTest, IsRunningWithHWasan) {
89*8d67ca89SAndroid Build Coastguard Worker   EXPECT_TRUE(running_with_hwasan());
90*8d67ca89SAndroid Build Coastguard Worker }
91