1*6777b538SAndroid Build Coastguard Worker // Copyright 2019 The Chromium Authors
2*6777b538SAndroid Build Coastguard Worker // Use of this source code is governed by a BSD-style license that can be
3*6777b538SAndroid Build Coastguard Worker // found in the LICENSE file.
4*6777b538SAndroid Build Coastguard Worker
5*6777b538SAndroid Build Coastguard Worker #ifndef BASE_IMMEDIATE_CRASH_H_
6*6777b538SAndroid Build Coastguard Worker #define BASE_IMMEDIATE_CRASH_H_
7*6777b538SAndroid Build Coastguard Worker
8*6777b538SAndroid Build Coastguard Worker #include "base/fuzzing_buildflags.h"
9*6777b538SAndroid Build Coastguard Worker #include "build/build_config.h"
10*6777b538SAndroid Build Coastguard Worker
11*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(USE_FUZZING_ENGINE)
12*6777b538SAndroid Build Coastguard Worker #include <stdlib.h>
13*6777b538SAndroid Build Coastguard Worker
14*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_LINUX)
15*6777b538SAndroid Build Coastguard Worker // The fuzzing coverage display wants to record coverage even
16*6777b538SAndroid Build Coastguard Worker // for failure cases. It's Linux-only. So on Linux, dump coverage
17*6777b538SAndroid Build Coastguard Worker // before we immediately exit. We provide a weak symbol so that
18*6777b538SAndroid Build Coastguard Worker // this causes no link problems on configurations that don't involve
19*6777b538SAndroid Build Coastguard Worker // coverage.
20*6777b538SAndroid Build Coastguard Worker extern "C" int __attribute__((weak)) __llvm_profile_write_file(void);
21*6777b538SAndroid Build Coastguard Worker #endif // BUILDFLAG(IS_LINUX)
22*6777b538SAndroid Build Coastguard Worker
23*6777b538SAndroid Build Coastguard Worker #endif // BUILDFLAG(USE_FUZZING_ENGINE)
24*6777b538SAndroid Build Coastguard Worker
25*6777b538SAndroid Build Coastguard Worker // Crashes in the fastest possible way with no attempt at logging.
26*6777b538SAndroid Build Coastguard Worker // There are several constraints; see http://crbug.com/664209 for more context.
27*6777b538SAndroid Build Coastguard Worker //
28*6777b538SAndroid Build Coastguard Worker // - TRAP_SEQUENCE_() must be fatal. It should not be possible to ignore the
29*6777b538SAndroid Build Coastguard Worker // resulting exception or simply hit 'continue' to skip over it in a debugger.
30*6777b538SAndroid Build Coastguard Worker // - Different instances of TRAP_SEQUENCE_() must not be folded together, to
31*6777b538SAndroid Build Coastguard Worker // ensure crash reports are debuggable. Unlike __builtin_trap(), asm volatile
32*6777b538SAndroid Build Coastguard Worker // blocks will not be folded together.
33*6777b538SAndroid Build Coastguard Worker // Note: TRAP_SEQUENCE_() previously required an instruction with a unique
34*6777b538SAndroid Build Coastguard Worker // nonce since unlike clang, GCC folds together identical asm volatile
35*6777b538SAndroid Build Coastguard Worker // blocks.
36*6777b538SAndroid Build Coastguard Worker // - TRAP_SEQUENCE_() must produce a signal that is distinct from an invalid
37*6777b538SAndroid Build Coastguard Worker // memory access.
38*6777b538SAndroid Build Coastguard Worker // - TRAP_SEQUENCE_() must be treated as a set of noreturn instructions.
39*6777b538SAndroid Build Coastguard Worker // __builtin_unreachable() is used to provide that hint here. clang also uses
40*6777b538SAndroid Build Coastguard Worker // this as a heuristic to pack the instructions in the function epilogue to
41*6777b538SAndroid Build Coastguard Worker // improve code density.
42*6777b538SAndroid Build Coastguard Worker // - base::ImmediateCrash() is used in allocation hooks. To prevent recursions,
43*6777b538SAndroid Build Coastguard Worker // TRAP_SEQUENCE_() must not allocate.
44*6777b538SAndroid Build Coastguard Worker //
45*6777b538SAndroid Build Coastguard Worker // Additional properties that are nice to have:
46*6777b538SAndroid Build Coastguard Worker // - TRAP_SEQUENCE_() should be as compact as possible.
47*6777b538SAndroid Build Coastguard Worker // - The first instruction of TRAP_SEQUENCE_() should not change, to avoid
48*6777b538SAndroid Build Coastguard Worker // shifting crash reporting clusters. As a consequence of this, explicit
49*6777b538SAndroid Build Coastguard Worker // assembly is preferred over intrinsics.
50*6777b538SAndroid Build Coastguard Worker // Note: this last bullet point may no longer be true, and may be removed in
51*6777b538SAndroid Build Coastguard Worker // the future.
52*6777b538SAndroid Build Coastguard Worker
53*6777b538SAndroid Build Coastguard Worker // Note: TRAP_SEQUENCE Is currently split into two macro helpers due to the fact
54*6777b538SAndroid Build Coastguard Worker // that clang emits an actual instruction for __builtin_unreachable() on certain
55*6777b538SAndroid Build Coastguard Worker // platforms (see https://crbug.com/958675). In addition, the int3/bkpt/brk will
56*6777b538SAndroid Build Coastguard Worker // be removed in followups, so splitting it up like this now makes it easy to
57*6777b538SAndroid Build Coastguard Worker // land the followups.
58*6777b538SAndroid Build Coastguard Worker
59*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC)
60*6777b538SAndroid Build Coastguard Worker
61*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_NACL)
62*6777b538SAndroid Build Coastguard Worker
63*6777b538SAndroid Build Coastguard Worker // Crash report accuracy is not guaranteed on NaCl.
64*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() __builtin_trap()
65*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("")
66*6777b538SAndroid Build Coastguard Worker
67*6777b538SAndroid Build Coastguard Worker #elif defined(ARCH_CPU_X86_FAMILY)
68*6777b538SAndroid Build Coastguard Worker
69*6777b538SAndroid Build Coastguard Worker // TODO(https://crbug.com/958675): In theory, it should be possible to use just
70*6777b538SAndroid Build Coastguard Worker // int3. However, there are a number of crashes with SIGILL as the exception
71*6777b538SAndroid Build Coastguard Worker // code, so it seems likely that there's a signal handler that allows execution
72*6777b538SAndroid Build Coastguard Worker // to continue after SIGTRAP.
73*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() asm volatile("int3")
74*6777b538SAndroid Build Coastguard Worker
75*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_APPLE)
76*6777b538SAndroid Build Coastguard Worker // Intentionally empty: __builtin_unreachable() is always part of the sequence
77*6777b538SAndroid Build Coastguard Worker // (see IMMEDIATE_CRASH below) and already emits a ud2 on Mac.
78*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("")
79*6777b538SAndroid Build Coastguard Worker #else
80*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("ud2")
81*6777b538SAndroid Build Coastguard Worker #endif // BUILDFLAG(IS_APPLE)
82*6777b538SAndroid Build Coastguard Worker
83*6777b538SAndroid Build Coastguard Worker #elif defined(ARCH_CPU_ARMEL)
84*6777b538SAndroid Build Coastguard Worker
85*6777b538SAndroid Build Coastguard Worker // bkpt will generate a SIGBUS when running on armv7 and a SIGTRAP when running
86*6777b538SAndroid Build Coastguard Worker // as a 32 bit userspace app on arm64. There doesn't seem to be any way to
87*6777b538SAndroid Build Coastguard Worker // cause a SIGTRAP from userspace without using a syscall (which would be a
88*6777b538SAndroid Build Coastguard Worker // problem for sandboxing).
89*6777b538SAndroid Build Coastguard Worker // TODO(https://crbug.com/958675): Remove bkpt from this sequence.
90*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() asm volatile("bkpt #0")
91*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("udf #0")
92*6777b538SAndroid Build Coastguard Worker
93*6777b538SAndroid Build Coastguard Worker #elif defined(ARCH_CPU_ARM64)
94*6777b538SAndroid Build Coastguard Worker
95*6777b538SAndroid Build Coastguard Worker // This will always generate a SIGTRAP on arm64.
96*6777b538SAndroid Build Coastguard Worker // TODO(https://crbug.com/958675): Remove brk from this sequence.
97*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() asm volatile("brk #0")
98*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("hlt #0")
99*6777b538SAndroid Build Coastguard Worker
100*6777b538SAndroid Build Coastguard Worker #else
101*6777b538SAndroid Build Coastguard Worker
102*6777b538SAndroid Build Coastguard Worker // Crash report accuracy will not be guaranteed on other architectures, but at
103*6777b538SAndroid Build Coastguard Worker // least this will crash as expected.
104*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() __builtin_trap()
105*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("")
106*6777b538SAndroid Build Coastguard Worker
107*6777b538SAndroid Build Coastguard Worker #endif // ARCH_CPU_*
108*6777b538SAndroid Build Coastguard Worker
109*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_MSVC)
110*6777b538SAndroid Build Coastguard Worker
111*6777b538SAndroid Build Coastguard Worker #if !defined(__clang__)
112*6777b538SAndroid Build Coastguard Worker
113*6777b538SAndroid Build Coastguard Worker // MSVC x64 doesn't support inline asm, so use the MSVC intrinsic.
114*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() __debugbreak()
115*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_()
116*6777b538SAndroid Build Coastguard Worker
117*6777b538SAndroid Build Coastguard Worker #elif defined(ARCH_CPU_ARM64)
118*6777b538SAndroid Build Coastguard Worker
119*6777b538SAndroid Build Coastguard Worker // Windows ARM64 uses "BRK #F000" as its breakpoint instruction, and
120*6777b538SAndroid Build Coastguard Worker // __debugbreak() generates that in both VC++ and clang.
121*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() __debugbreak()
122*6777b538SAndroid Build Coastguard Worker // Intentionally empty: __builtin_unreachable() is always part of the sequence
123*6777b538SAndroid Build Coastguard Worker // (see IMMEDIATE_CRASH below) and already emits a ud2 on Win64,
124*6777b538SAndroid Build Coastguard Worker // https://crbug.com/958373
125*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() __asm volatile("")
126*6777b538SAndroid Build Coastguard Worker
127*6777b538SAndroid Build Coastguard Worker #else
128*6777b538SAndroid Build Coastguard Worker
129*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE1_() asm volatile("int3")
130*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE2_() asm volatile("ud2")
131*6777b538SAndroid Build Coastguard Worker
132*6777b538SAndroid Build Coastguard Worker #endif // __clang__
133*6777b538SAndroid Build Coastguard Worker
134*6777b538SAndroid Build Coastguard Worker #else
135*6777b538SAndroid Build Coastguard Worker
136*6777b538SAndroid Build Coastguard Worker #error No supported trap sequence!
137*6777b538SAndroid Build Coastguard Worker
138*6777b538SAndroid Build Coastguard Worker #endif // COMPILER_GCC
139*6777b538SAndroid Build Coastguard Worker
140*6777b538SAndroid Build Coastguard Worker #define TRAP_SEQUENCE_() \
141*6777b538SAndroid Build Coastguard Worker do { \
142*6777b538SAndroid Build Coastguard Worker TRAP_SEQUENCE1_(); \
143*6777b538SAndroid Build Coastguard Worker TRAP_SEQUENCE2_(); \
144*6777b538SAndroid Build Coastguard Worker } while (false)
145*6777b538SAndroid Build Coastguard Worker
146*6777b538SAndroid Build Coastguard Worker // This version of ALWAYS_INLINE inlines even in is_debug=true.
147*6777b538SAndroid Build Coastguard Worker // TODO(pbos): See if NDEBUG can be dropped from ALWAYS_INLINE as well, and if
148*6777b538SAndroid Build Coastguard Worker // so merge. Otherwise document why it cannot inline in debug in
149*6777b538SAndroid Build Coastguard Worker // base/compiler_specific.h.
150*6777b538SAndroid Build Coastguard Worker #if defined(COMPILER_GCC)
151*6777b538SAndroid Build Coastguard Worker #define IMMEDIATE_CRASH_ALWAYS_INLINE inline __attribute__((__always_inline__))
152*6777b538SAndroid Build Coastguard Worker #elif defined(COMPILER_MSVC)
153*6777b538SAndroid Build Coastguard Worker #define IMMEDIATE_CRASH_ALWAYS_INLINE __forceinline
154*6777b538SAndroid Build Coastguard Worker #else
155*6777b538SAndroid Build Coastguard Worker #define IMMEDIATE_CRASH_ALWAYS_INLINE inline
156*6777b538SAndroid Build Coastguard Worker #endif
157*6777b538SAndroid Build Coastguard Worker
158*6777b538SAndroid Build Coastguard Worker namespace base {
159*6777b538SAndroid Build Coastguard Worker
ImmediateCrash()160*6777b538SAndroid Build Coastguard Worker [[noreturn]] IMMEDIATE_CRASH_ALWAYS_INLINE void ImmediateCrash() {
161*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(USE_FUZZING_ENGINE)
162*6777b538SAndroid Build Coastguard Worker // If fuzzing, exit in such a way that atexit() handlers are run in order
163*6777b538SAndroid Build Coastguard Worker // to write out failing fuzz cases. This is similar
164*6777b538SAndroid Build Coastguard Worker // behavior to __sanitizer::Die.
165*6777b538SAndroid Build Coastguard Worker // libfuzzer has its own atexit handler which unfortunately calls the
166*6777b538SAndroid Build Coastguard Worker // equivalent of base::ImmediateCrash, thus not running any other atexit
167*6777b538SAndroid Build Coastguard Worker // handlers. We want to dump coverage information so we'll do that
168*6777b538SAndroid Build Coastguard Worker // here explicitly too.
169*6777b538SAndroid Build Coastguard Worker #if BUILDFLAG(IS_LINUX)
170*6777b538SAndroid Build Coastguard Worker if (__llvm_profile_write_file) {
171*6777b538SAndroid Build Coastguard Worker __llvm_profile_write_file();
172*6777b538SAndroid Build Coastguard Worker }
173*6777b538SAndroid Build Coastguard Worker #endif // BUILDFLAG(IS_LINUX)
174*6777b538SAndroid Build Coastguard Worker exit(-1);
175*6777b538SAndroid Build Coastguard Worker #else // BUILDFLAG(USE_FUZZING_ENGINE)
176*6777b538SAndroid Build Coastguard Worker TRAP_SEQUENCE_();
177*6777b538SAndroid Build Coastguard Worker #endif // BUILDFLAG(USE_FUZZING_ENGINE)
178*6777b538SAndroid Build Coastguard Worker #if defined(__clang__) || defined(COMPILER_GCC)
179*6777b538SAndroid Build Coastguard Worker __builtin_unreachable();
180*6777b538SAndroid Build Coastguard Worker #endif // defined(__clang__) || defined(COMPILER_GCC)
181*6777b538SAndroid Build Coastguard Worker }
182*6777b538SAndroid Build Coastguard Worker
183*6777b538SAndroid Build Coastguard Worker } // namespace base
184*6777b538SAndroid Build Coastguard Worker
185*6777b538SAndroid Build Coastguard Worker #endif // BASE_IMMEDIATE_CRASH_H_
186