sanitizer_common_interceptors_ioctl.inc 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604
  1. //===-- sanitizer_common_interceptors_ioctl.inc -----------------*- C++ -*-===//
  2. //
  3. // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
  4. // See https://llvm.org/LICENSE.txt for license information.
  5. // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
  6. //
  7. //===----------------------------------------------------------------------===//
  8. //
  9. // Ioctl handling in common sanitizer interceptors.
  10. //===----------------------------------------------------------------------===//
  11. #if !SANITIZER_NETBSD
  12. #include "sanitizer_flags.h"
  13. struct ioctl_desc {
  14. unsigned req;
  15. // FIXME: support read+write arguments. Currently READWRITE and WRITE do the
  16. // same thing.
  17. // XXX: The declarations below may use WRITE instead of READWRITE, unless
  18. // explicitly noted.
  19. enum {
  20. NONE,
  21. READ,
  22. WRITE,
  23. READWRITE,
  24. CUSTOM
  25. } type : 3;
  26. unsigned size : 29;
  27. const char* name;
  28. };
  29. const unsigned ioctl_table_max = 500;
  30. static ioctl_desc ioctl_table[ioctl_table_max];
  31. static unsigned ioctl_table_size = 0;
  32. // This can not be declared as a global, because references to struct_*_sz
  33. // require a global initializer. And this table must be available before global
  34. // initializers are run.
  35. static void ioctl_table_fill() {
  36. #define _(rq, tp, sz) \
  37. if (IOCTL_##rq != IOCTL_NOT_PRESENT) { \
  38. CHECK(ioctl_table_size < ioctl_table_max); \
  39. ioctl_table[ioctl_table_size].req = IOCTL_##rq; \
  40. ioctl_table[ioctl_table_size].type = ioctl_desc::tp; \
  41. ioctl_table[ioctl_table_size].size = sz; \
  42. ioctl_table[ioctl_table_size].name = #rq; \
  43. ++ioctl_table_size; \
  44. }
  45. _(FIOASYNC, READ, sizeof(int));
  46. _(FIOCLEX, NONE, 0);
  47. _(FIOGETOWN, WRITE, sizeof(int));
  48. _(FIONBIO, READ, sizeof(int));
  49. _(FIONCLEX, NONE, 0);
  50. _(FIOSETOWN, READ, sizeof(int));
  51. _(SIOCATMARK, WRITE, sizeof(int));
  52. _(SIOCGIFCONF, CUSTOM, 0);
  53. _(SIOCGPGRP, WRITE, sizeof(int));
  54. _(SIOCSPGRP, READ, sizeof(int));
  55. #if !SANITIZER_SOLARIS
  56. _(TIOCCONS, NONE, 0);
  57. #endif
  58. _(TIOCEXCL, NONE, 0);
  59. _(TIOCGETD, WRITE, sizeof(int));
  60. _(TIOCGPGRP, WRITE, pid_t_sz);
  61. _(TIOCGWINSZ, WRITE, struct_winsize_sz);
  62. _(TIOCMBIC, READ, sizeof(int));
  63. _(TIOCMBIS, READ, sizeof(int));
  64. _(TIOCMGET, WRITE, sizeof(int));
  65. _(TIOCMSET, READ, sizeof(int));
  66. _(TIOCNOTTY, NONE, 0);
  67. _(TIOCNXCL, NONE, 0);
  68. _(TIOCOUTQ, WRITE, sizeof(int));
  69. _(TIOCPKT, READ, sizeof(int));
  70. _(TIOCSCTTY, NONE, 0);
  71. _(TIOCSETD, READ, sizeof(int));
  72. _(TIOCSPGRP, READ, pid_t_sz);
  73. _(TIOCSTI, READ, sizeof(char));
  74. _(TIOCSWINSZ, READ, struct_winsize_sz);
  75. #if !SANITIZER_IOS
  76. _(SIOCADDMULTI, READ, struct_ifreq_sz);
  77. _(SIOCDELMULTI, READ, struct_ifreq_sz);
  78. _(SIOCGIFADDR, WRITE, struct_ifreq_sz);
  79. _(SIOCGIFBRDADDR, WRITE, struct_ifreq_sz);
  80. _(SIOCGIFDSTADDR, WRITE, struct_ifreq_sz);
  81. _(SIOCGIFFLAGS, WRITE, struct_ifreq_sz);
  82. _(SIOCGIFMETRIC, WRITE, struct_ifreq_sz);
  83. _(SIOCGIFMTU, WRITE, struct_ifreq_sz);
  84. _(SIOCGIFNETMASK, WRITE, struct_ifreq_sz);
  85. _(SIOCSIFADDR, READ, struct_ifreq_sz);
  86. _(SIOCSIFBRDADDR, READ, struct_ifreq_sz);
  87. _(SIOCSIFDSTADDR, READ, struct_ifreq_sz);
  88. _(SIOCSIFFLAGS, READ, struct_ifreq_sz);
  89. _(SIOCSIFMETRIC, READ, struct_ifreq_sz);
  90. _(SIOCSIFMTU, READ, struct_ifreq_sz);
  91. _(SIOCSIFNETMASK, READ, struct_ifreq_sz);
  92. #endif
  93. #if (SANITIZER_LINUX && !SANITIZER_ANDROID)
  94. _(SIOCGETSGCNT, WRITE, struct_sioc_sg_req_sz);
  95. _(SIOCGETVIFCNT, WRITE, struct_sioc_vif_req_sz);
  96. #endif
  97. #if SANITIZER_LINUX
  98. // Conflicting request ids.
  99. // _(CDROMAUDIOBUFSIZ, NONE, 0);
  100. // _(SNDCTL_TMR_CONTINUE, NONE, 0);
  101. // _(SNDCTL_TMR_START, NONE, 0);
  102. // _(SNDCTL_TMR_STOP, NONE, 0);
  103. // _(SOUND_MIXER_READ_LOUD, WRITE, sizeof(int)); // same as ...READ_ENHANCE
  104. // _(SOUND_MIXER_READ_MUTE, WRITE, sizeof(int)); // same as ...READ_ENHANCE
  105. // _(SOUND_MIXER_WRITE_LOUD, WRITE, sizeof(int)); // same as ...WRITE_ENHANCE
  106. // _(SOUND_MIXER_WRITE_MUTE, WRITE, sizeof(int)); // same as ...WRITE_ENHANCE
  107. _(BLKFLSBUF, NONE, 0);
  108. _(BLKGETSIZE, WRITE, sizeof(uptr));
  109. _(BLKRAGET, WRITE, sizeof(int));
  110. _(BLKRASET, NONE, 0);
  111. _(BLKROGET, WRITE, sizeof(int));
  112. _(BLKROSET, READ, sizeof(int));
  113. _(BLKRRPART, NONE, 0);
  114. _(CDROMEJECT, NONE, 0);
  115. _(CDROMEJECT_SW, NONE, 0);
  116. _(CDROMMULTISESSION, WRITE, struct_cdrom_multisession_sz);
  117. _(CDROMPAUSE, NONE, 0);
  118. _(CDROMPLAYMSF, READ, struct_cdrom_msf_sz);
  119. _(CDROMPLAYTRKIND, READ, struct_cdrom_ti_sz);
  120. _(CDROMREADAUDIO, READ, struct_cdrom_read_audio_sz);
  121. _(CDROMREADCOOKED, READ, struct_cdrom_msf_sz);
  122. _(CDROMREADMODE1, READ, struct_cdrom_msf_sz);
  123. _(CDROMREADMODE2, READ, struct_cdrom_msf_sz);
  124. _(CDROMREADRAW, READ, struct_cdrom_msf_sz);
  125. _(CDROMREADTOCENTRY, WRITE, struct_cdrom_tocentry_sz);
  126. _(CDROMREADTOCHDR, WRITE, struct_cdrom_tochdr_sz);
  127. _(CDROMRESET, NONE, 0);
  128. _(CDROMRESUME, NONE, 0);
  129. _(CDROMSEEK, READ, struct_cdrom_msf_sz);
  130. _(CDROMSTART, NONE, 0);
  131. _(CDROMSTOP, NONE, 0);
  132. _(CDROMSUBCHNL, WRITE, struct_cdrom_subchnl_sz);
  133. _(CDROMVOLCTRL, READ, struct_cdrom_volctrl_sz);
  134. _(CDROMVOLREAD, WRITE, struct_cdrom_volctrl_sz);
  135. _(CDROM_GET_UPC, WRITE, 8);
  136. _(EVIOCGABS, WRITE, struct_input_absinfo_sz); // fixup
  137. _(EVIOCGBIT, WRITE, struct_input_id_sz); // fixup
  138. _(EVIOCGEFFECTS, WRITE, sizeof(int));
  139. _(EVIOCGID, WRITE, struct_input_id_sz);
  140. _(EVIOCGKEY, WRITE, 0);
  141. _(EVIOCGKEYCODE, WRITE, sizeof(int) * 2);
  142. _(EVIOCGLED, WRITE, 0);
  143. _(EVIOCGNAME, WRITE, 0);
  144. _(EVIOCGPHYS, WRITE, 0);
  145. _(EVIOCGRAB, READ, sizeof(int));
  146. _(EVIOCGREP, WRITE, sizeof(int) * 2);
  147. _(EVIOCGSND, WRITE, 0);
  148. _(EVIOCGSW, WRITE, 0);
  149. _(EVIOCGUNIQ, WRITE, 0);
  150. _(EVIOCGVERSION, WRITE, sizeof(int));
  151. _(EVIOCRMFF, READ, sizeof(int));
  152. _(EVIOCSABS, READ, struct_input_absinfo_sz); // fixup
  153. _(EVIOCSFF, READ, struct_ff_effect_sz);
  154. _(EVIOCSKEYCODE, READ, sizeof(int) * 2);
  155. _(EVIOCSREP, READ, sizeof(int) * 2);
  156. _(FDCLRPRM, NONE, 0);
  157. _(FDDEFPRM, READ, struct_floppy_struct_sz);
  158. _(FDFLUSH, NONE, 0);
  159. _(FDFMTBEG, NONE, 0);
  160. _(FDFMTEND, NONE, 0);
  161. _(FDFMTTRK, READ, struct_format_descr_sz);
  162. _(FDGETDRVPRM, WRITE, struct_floppy_drive_params_sz);
  163. _(FDGETDRVSTAT, WRITE, struct_floppy_drive_struct_sz);
  164. _(FDGETDRVTYP, WRITE, 16);
  165. _(FDGETFDCSTAT, WRITE, struct_floppy_fdc_state_sz);
  166. _(FDGETMAXERRS, WRITE, struct_floppy_max_errors_sz);
  167. _(FDGETPRM, WRITE, struct_floppy_struct_sz);
  168. _(FDMSGOFF, NONE, 0);
  169. _(FDMSGON, NONE, 0);
  170. _(FDPOLLDRVSTAT, WRITE, struct_floppy_drive_struct_sz);
  171. _(FDRAWCMD, WRITE, struct_floppy_raw_cmd_sz);
  172. _(FDRESET, NONE, 0);
  173. _(FDSETDRVPRM, READ, struct_floppy_drive_params_sz);
  174. _(FDSETEMSGTRESH, NONE, 0);
  175. _(FDSETMAXERRS, READ, struct_floppy_max_errors_sz);
  176. _(FDSETPRM, READ, struct_floppy_struct_sz);
  177. _(FDTWADDLE, NONE, 0);
  178. _(FDWERRORCLR, NONE, 0);
  179. _(FDWERRORGET, WRITE, struct_floppy_write_errors_sz);
  180. _(HDIO_DRIVE_CMD, WRITE, sizeof(int));
  181. _(HDIO_GETGEO, WRITE, struct_hd_geometry_sz);
  182. _(HDIO_GET_32BIT, WRITE, sizeof(int));
  183. _(HDIO_GET_DMA, WRITE, sizeof(int));
  184. _(HDIO_GET_IDENTITY, WRITE, struct_hd_driveid_sz);
  185. _(HDIO_GET_KEEPSETTINGS, WRITE, sizeof(int));
  186. _(HDIO_GET_MULTCOUNT, WRITE, sizeof(int));
  187. _(HDIO_GET_NOWERR, WRITE, sizeof(int));
  188. _(HDIO_GET_UNMASKINTR, WRITE, sizeof(int));
  189. _(HDIO_SET_32BIT, NONE, 0);
  190. _(HDIO_SET_DMA, NONE, 0);
  191. _(HDIO_SET_KEEPSETTINGS, NONE, 0);
  192. _(HDIO_SET_MULTCOUNT, NONE, 0);
  193. _(HDIO_SET_NOWERR, NONE, 0);
  194. _(HDIO_SET_UNMASKINTR, NONE, 0);
  195. _(MTIOCGET, WRITE, struct_mtget_sz);
  196. _(MTIOCPOS, WRITE, struct_mtpos_sz);
  197. _(MTIOCTOP, READ, struct_mtop_sz);
  198. _(PPPIOCGASYNCMAP, WRITE, sizeof(int));
  199. _(PPPIOCGDEBUG, WRITE, sizeof(int));
  200. _(PPPIOCGFLAGS, WRITE, sizeof(int));
  201. _(PPPIOCGUNIT, WRITE, sizeof(int));
  202. _(PPPIOCGXASYNCMAP, WRITE, sizeof(int) * 8);
  203. _(PPPIOCSASYNCMAP, READ, sizeof(int));
  204. _(PPPIOCSDEBUG, READ, sizeof(int));
  205. _(PPPIOCSFLAGS, READ, sizeof(int));
  206. _(PPPIOCSMAXCID, READ, sizeof(int));
  207. _(PPPIOCSMRU, READ, sizeof(int));
  208. _(PPPIOCSXASYNCMAP, READ, sizeof(int) * 8);
  209. _(SIOCADDRT, READ, struct_rtentry_sz);
  210. _(SIOCDARP, READ, struct_arpreq_sz);
  211. _(SIOCDELRT, READ, struct_rtentry_sz);
  212. _(SIOCDRARP, READ, struct_arpreq_sz);
  213. _(SIOCGARP, WRITE, struct_arpreq_sz);
  214. _(SIOCGIFENCAP, WRITE, sizeof(int));
  215. _(SIOCGIFHWADDR, WRITE, struct_ifreq_sz);
  216. _(SIOCGIFMAP, WRITE, struct_ifreq_sz);
  217. _(SIOCGIFMEM, WRITE, struct_ifreq_sz);
  218. _(SIOCGIFNAME, NONE, 0);
  219. _(SIOCGIFSLAVE, NONE, 0);
  220. _(SIOCGRARP, WRITE, struct_arpreq_sz);
  221. _(SIOCGSTAMP, WRITE, timeval_sz);
  222. _(SIOCSARP, READ, struct_arpreq_sz);
  223. _(SIOCSIFENCAP, READ, sizeof(int));
  224. _(SIOCSIFHWADDR, READ, struct_ifreq_sz);
  225. _(SIOCSIFLINK, NONE, 0);
  226. _(SIOCSIFMAP, READ, struct_ifreq_sz);
  227. _(SIOCSIFMEM, READ, struct_ifreq_sz);
  228. _(SIOCSIFSLAVE, NONE, 0);
  229. _(SIOCSRARP, READ, struct_arpreq_sz);
  230. _(SNDCTL_COPR_HALT, WRITE, struct_copr_debug_buf_sz);
  231. _(SNDCTL_COPR_LOAD, READ, struct_copr_buffer_sz);
  232. _(SNDCTL_COPR_RCODE, WRITE, struct_copr_debug_buf_sz);
  233. _(SNDCTL_COPR_RCVMSG, WRITE, struct_copr_msg_sz);
  234. _(SNDCTL_COPR_RDATA, WRITE, struct_copr_debug_buf_sz);
  235. _(SNDCTL_COPR_RESET, NONE, 0);
  236. _(SNDCTL_COPR_RUN, WRITE, struct_copr_debug_buf_sz);
  237. _(SNDCTL_COPR_SENDMSG, READ, struct_copr_msg_sz);
  238. _(SNDCTL_COPR_WCODE, READ, struct_copr_debug_buf_sz);
  239. _(SNDCTL_COPR_WDATA, READ, struct_copr_debug_buf_sz);
  240. _(SNDCTL_DSP_GETBLKSIZE, WRITE, sizeof(int));
  241. _(SNDCTL_DSP_GETFMTS, WRITE, sizeof(int));
  242. _(SNDCTL_DSP_NONBLOCK, NONE, 0);
  243. _(SNDCTL_DSP_POST, NONE, 0);
  244. _(SNDCTL_DSP_RESET, NONE, 0);
  245. _(SNDCTL_DSP_SETFMT, WRITE, sizeof(int));
  246. _(SNDCTL_DSP_SETFRAGMENT, WRITE, sizeof(int));
  247. _(SNDCTL_DSP_SPEED, WRITE, sizeof(int));
  248. _(SNDCTL_DSP_STEREO, WRITE, sizeof(int));
  249. _(SNDCTL_DSP_SUBDIVIDE, WRITE, sizeof(int));
  250. _(SNDCTL_DSP_SYNC, NONE, 0);
  251. _(SNDCTL_FM_4OP_ENABLE, READ, sizeof(int));
  252. _(SNDCTL_FM_LOAD_INSTR, READ, struct_sbi_instrument_sz);
  253. _(SNDCTL_MIDI_INFO, WRITE, struct_midi_info_sz);
  254. _(SNDCTL_MIDI_PRETIME, WRITE, sizeof(int));
  255. _(SNDCTL_SEQ_CTRLRATE, WRITE, sizeof(int));
  256. _(SNDCTL_SEQ_GETINCOUNT, WRITE, sizeof(int));
  257. _(SNDCTL_SEQ_GETOUTCOUNT, WRITE, sizeof(int));
  258. _(SNDCTL_SEQ_NRMIDIS, WRITE, sizeof(int));
  259. _(SNDCTL_SEQ_NRSYNTHS, WRITE, sizeof(int));
  260. _(SNDCTL_SEQ_OUTOFBAND, READ, struct_seq_event_rec_sz);
  261. _(SNDCTL_SEQ_PANIC, NONE, 0);
  262. _(SNDCTL_SEQ_PERCMODE, NONE, 0);
  263. _(SNDCTL_SEQ_RESET, NONE, 0);
  264. _(SNDCTL_SEQ_RESETSAMPLES, READ, sizeof(int));
  265. _(SNDCTL_SEQ_SYNC, NONE, 0);
  266. _(SNDCTL_SEQ_TESTMIDI, READ, sizeof(int));
  267. _(SNDCTL_SEQ_THRESHOLD, READ, sizeof(int));
  268. _(SNDCTL_SYNTH_INFO, WRITE, struct_synth_info_sz);
  269. _(SNDCTL_SYNTH_MEMAVL, WRITE, sizeof(int));
  270. _(SNDCTL_TMR_METRONOME, READ, sizeof(int));
  271. _(SNDCTL_TMR_SELECT, WRITE, sizeof(int));
  272. _(SNDCTL_TMR_SOURCE, WRITE, sizeof(int));
  273. _(SNDCTL_TMR_TEMPO, WRITE, sizeof(int));
  274. _(SNDCTL_TMR_TIMEBASE, WRITE, sizeof(int));
  275. _(SOUND_MIXER_READ_ALTPCM, WRITE, sizeof(int));
  276. _(SOUND_MIXER_READ_BASS, WRITE, sizeof(int));
  277. _(SOUND_MIXER_READ_CAPS, WRITE, sizeof(int));
  278. _(SOUND_MIXER_READ_CD, WRITE, sizeof(int));
  279. _(SOUND_MIXER_READ_DEVMASK, WRITE, sizeof(int));
  280. _(SOUND_MIXER_READ_ENHANCE, WRITE, sizeof(int));
  281. _(SOUND_MIXER_READ_IGAIN, WRITE, sizeof(int));
  282. _(SOUND_MIXER_READ_IMIX, WRITE, sizeof(int));
  283. _(SOUND_MIXER_READ_LINE, WRITE, sizeof(int));
  284. _(SOUND_MIXER_READ_LINE1, WRITE, sizeof(int));
  285. _(SOUND_MIXER_READ_LINE2, WRITE, sizeof(int));
  286. _(SOUND_MIXER_READ_LINE3, WRITE, sizeof(int));
  287. _(SOUND_MIXER_READ_MIC, WRITE, sizeof(int));
  288. _(SOUND_MIXER_READ_OGAIN, WRITE, sizeof(int));
  289. _(SOUND_MIXER_READ_PCM, WRITE, sizeof(int));
  290. _(SOUND_MIXER_READ_RECLEV, WRITE, sizeof(int));
  291. _(SOUND_MIXER_READ_RECMASK, WRITE, sizeof(int));
  292. _(SOUND_MIXER_READ_RECSRC, WRITE, sizeof(int));
  293. _(SOUND_MIXER_READ_SPEAKER, WRITE, sizeof(int));
  294. _(SOUND_MIXER_READ_STEREODEVS, WRITE, sizeof(int));
  295. _(SOUND_MIXER_READ_SYNTH, WRITE, sizeof(int));
  296. _(SOUND_MIXER_READ_TREBLE, WRITE, sizeof(int));
  297. _(SOUND_MIXER_READ_VOLUME, WRITE, sizeof(int));
  298. _(SOUND_MIXER_WRITE_ALTPCM, WRITE, sizeof(int));
  299. _(SOUND_MIXER_WRITE_BASS, WRITE, sizeof(int));
  300. _(SOUND_MIXER_WRITE_CD, WRITE, sizeof(int));
  301. _(SOUND_MIXER_WRITE_ENHANCE, WRITE, sizeof(int));
  302. _(SOUND_MIXER_WRITE_IGAIN, WRITE, sizeof(int));
  303. _(SOUND_MIXER_WRITE_IMIX, WRITE, sizeof(int));
  304. _(SOUND_MIXER_WRITE_LINE, WRITE, sizeof(int));
  305. _(SOUND_MIXER_WRITE_LINE1, WRITE, sizeof(int));
  306. _(SOUND_MIXER_WRITE_LINE2, WRITE, sizeof(int));
  307. _(SOUND_MIXER_WRITE_LINE3, WRITE, sizeof(int));
  308. _(SOUND_MIXER_WRITE_MIC, WRITE, sizeof(int));
  309. _(SOUND_MIXER_WRITE_OGAIN, WRITE, sizeof(int));
  310. _(SOUND_MIXER_WRITE_PCM, WRITE, sizeof(int));
  311. _(SOUND_MIXER_WRITE_RECLEV, WRITE, sizeof(int));
  312. _(SOUND_MIXER_WRITE_RECSRC, WRITE, sizeof(int));
  313. _(SOUND_MIXER_WRITE_SPEAKER, WRITE, sizeof(int));
  314. _(SOUND_MIXER_WRITE_SYNTH, WRITE, sizeof(int));
  315. _(SOUND_MIXER_WRITE_TREBLE, WRITE, sizeof(int));
  316. _(SOUND_MIXER_WRITE_VOLUME, WRITE, sizeof(int));
  317. _(SOUND_PCM_READ_BITS, WRITE, sizeof(int));
  318. _(SOUND_PCM_READ_CHANNELS, WRITE, sizeof(int));
  319. _(SOUND_PCM_READ_FILTER, WRITE, sizeof(int));
  320. _(SOUND_PCM_READ_RATE, WRITE, sizeof(int));
  321. _(SOUND_PCM_WRITE_CHANNELS, WRITE, sizeof(int));
  322. _(SOUND_PCM_WRITE_FILTER, WRITE, sizeof(int));
  323. _(TCFLSH, NONE, 0);
  324. #if SANITIZER_GLIBC
  325. _(TCGETA, WRITE, struct_termio_sz);
  326. #endif
  327. _(TCGETS, WRITE, struct_termios_sz);
  328. _(TCSBRK, NONE, 0);
  329. _(TCSBRKP, NONE, 0);
  330. #if SANITIZER_GLIBC
  331. _(TCSETA, READ, struct_termio_sz);
  332. _(TCSETAF, READ, struct_termio_sz);
  333. _(TCSETAW, READ, struct_termio_sz);
  334. #endif
  335. _(TCSETS, READ, struct_termios_sz);
  336. _(TCSETSF, READ, struct_termios_sz);
  337. _(TCSETSW, READ, struct_termios_sz);
  338. _(TCXONC, NONE, 0);
  339. _(TIOCGLCKTRMIOS, WRITE, struct_termios_sz);
  340. _(TIOCGSOFTCAR, WRITE, sizeof(int));
  341. _(TIOCINQ, WRITE, sizeof(int));
  342. _(TIOCLINUX, READ, sizeof(char));
  343. _(TIOCSERCONFIG, NONE, 0);
  344. _(TIOCSERGETLSR, WRITE, sizeof(int));
  345. _(TIOCSERGWILD, WRITE, sizeof(int));
  346. _(TIOCSERSWILD, READ, sizeof(int));
  347. _(TIOCSLCKTRMIOS, READ, struct_termios_sz);
  348. _(TIOCSSOFTCAR, READ, sizeof(int));
  349. _(VT_ACTIVATE, NONE, 0);
  350. _(VT_DISALLOCATE, NONE, 0);
  351. _(VT_GETMODE, WRITE, struct_vt_mode_sz);
  352. _(VT_GETSTATE, WRITE, struct_vt_stat_sz);
  353. _(VT_OPENQRY, WRITE, sizeof(int));
  354. _(VT_RELDISP, NONE, 0);
  355. _(VT_RESIZE, READ, struct_vt_sizes_sz);
  356. _(VT_RESIZEX, READ, struct_vt_consize_sz);
  357. _(VT_SENDSIG, NONE, 0);
  358. _(VT_SETMODE, READ, struct_vt_mode_sz);
  359. _(VT_WAITACTIVE, NONE, 0);
  360. #endif
  361. #if SANITIZER_GLIBC
  362. // _(SIOCDEVPLIP, WRITE, struct_ifreq_sz); // the same as EQL_ENSLAVE
  363. _(EQL_EMANCIPATE, WRITE, struct_ifreq_sz);
  364. _(EQL_ENSLAVE, WRITE, struct_ifreq_sz);
  365. _(EQL_GETMASTRCFG, WRITE, struct_ifreq_sz);
  366. _(EQL_GETSLAVECFG, WRITE, struct_ifreq_sz);
  367. _(EQL_SETMASTRCFG, WRITE, struct_ifreq_sz);
  368. _(EQL_SETSLAVECFG, WRITE, struct_ifreq_sz);
  369. _(EVIOCGKEYCODE_V2, WRITE, struct_input_keymap_entry_sz);
  370. _(EVIOCGPROP, WRITE, 0);
  371. _(EVIOCSKEYCODE_V2, READ, struct_input_keymap_entry_sz);
  372. _(FS_IOC_GETFLAGS, WRITE, sizeof(int));
  373. _(FS_IOC_GETVERSION, WRITE, sizeof(int));
  374. _(FS_IOC_SETFLAGS, READ, sizeof(int));
  375. _(FS_IOC_SETVERSION, READ, sizeof(int));
  376. _(GIO_CMAP, WRITE, 48);
  377. _(GIO_FONT, WRITE, 8192);
  378. _(GIO_SCRNMAP, WRITE, e_tabsz);
  379. _(GIO_UNIMAP, WRITE, struct_unimapdesc_sz);
  380. _(GIO_UNISCRNMAP, WRITE, sizeof(short) * e_tabsz);
  381. _(KDADDIO, NONE, 0);
  382. _(KDDELIO, NONE, 0);
  383. _(KDDISABIO, NONE, 0);
  384. _(KDENABIO, NONE, 0);
  385. _(KDGETKEYCODE, WRITE, struct_kbkeycode_sz);
  386. _(KDGETLED, WRITE, 1);
  387. _(KDGETMODE, WRITE, sizeof(int));
  388. _(KDGKBDIACR, WRITE, struct_kbdiacrs_sz);
  389. _(KDGKBENT, WRITE, struct_kbentry_sz);
  390. _(KDGKBLED, WRITE, sizeof(int));
  391. _(KDGKBMETA, WRITE, sizeof(int));
  392. _(KDGKBMODE, WRITE, sizeof(int));
  393. _(KDGKBSENT, WRITE, struct_kbsentry_sz);
  394. _(KDGKBTYPE, WRITE, 1);
  395. _(KDMAPDISP, NONE, 0);
  396. _(KDMKTONE, NONE, 0);
  397. _(KDSETKEYCODE, READ, struct_kbkeycode_sz);
  398. _(KDSETLED, NONE, 0);
  399. _(KDSETMODE, NONE, 0);
  400. _(KDSIGACCEPT, NONE, 0);
  401. _(KDSKBDIACR, READ, struct_kbdiacrs_sz);
  402. _(KDSKBENT, READ, struct_kbentry_sz);
  403. _(KDSKBLED, NONE, 0);
  404. _(KDSKBMETA, NONE, 0);
  405. _(KDSKBMODE, NONE, 0);
  406. _(KDSKBSENT, READ, struct_kbsentry_sz);
  407. _(KDUNMAPDISP, NONE, 0);
  408. _(KIOCSOUND, NONE, 0);
  409. _(LPABORT, NONE, 0);
  410. _(LPABORTOPEN, NONE, 0);
  411. _(LPCAREFUL, NONE, 0);
  412. _(LPCHAR, NONE, 0);
  413. _(LPGETIRQ, WRITE, sizeof(int));
  414. _(LPGETSTATUS, WRITE, sizeof(int));
  415. _(LPRESET, NONE, 0);
  416. _(LPSETIRQ, NONE, 0);
  417. _(LPTIME, NONE, 0);
  418. _(LPWAIT, NONE, 0);
  419. _(MTIOCGETCONFIG, WRITE, struct_mtconfiginfo_sz);
  420. _(MTIOCSETCONFIG, READ, struct_mtconfiginfo_sz);
  421. _(PIO_CMAP, NONE, 0);
  422. _(PIO_FONT, READ, 8192);
  423. _(PIO_SCRNMAP, READ, e_tabsz);
  424. _(PIO_UNIMAP, READ, struct_unimapdesc_sz);
  425. _(PIO_UNIMAPCLR, READ, struct_unimapinit_sz);
  426. _(PIO_UNISCRNMAP, READ, sizeof(short) * e_tabsz);
  427. _(SCSI_IOCTL_PROBE_HOST, READ, sizeof(int));
  428. _(SCSI_IOCTL_TAGGED_DISABLE, NONE, 0);
  429. _(SCSI_IOCTL_TAGGED_ENABLE, NONE, 0);
  430. _(SNDCTL_DSP_GETISPACE, WRITE, struct_audio_buf_info_sz);
  431. _(SNDCTL_DSP_GETOSPACE, WRITE, struct_audio_buf_info_sz);
  432. _(TIOCGSERIAL, WRITE, struct_serial_struct_sz);
  433. _(TIOCSERGETMULTI, WRITE, struct_serial_multiport_struct_sz);
  434. _(TIOCSERSETMULTI, READ, struct_serial_multiport_struct_sz);
  435. _(TIOCSSERIAL, READ, struct_serial_struct_sz);
  436. // The following ioctl requests are shared between AX25, IPX, netrom and
  437. // mrouted.
  438. // _(SIOCAIPXITFCRT, READ, sizeof(char));
  439. // _(SIOCAX25GETUID, READ, struct_sockaddr_ax25_sz);
  440. // _(SIOCNRGETPARMS, WRITE, struct_nr_parms_struct_sz);
  441. // _(SIOCAIPXPRISLT, READ, sizeof(char));
  442. // _(SIOCNRSETPARMS, READ, struct_nr_parms_struct_sz);
  443. // _(SIOCAX25ADDUID, READ, struct_sockaddr_ax25_sz);
  444. // _(SIOCNRDECOBS, NONE, 0);
  445. // _(SIOCAX25DELUID, READ, struct_sockaddr_ax25_sz);
  446. // _(SIOCIPXCFGDATA, WRITE, struct_ipx_config_data_sz);
  447. // _(SIOCAX25NOUID, READ, sizeof(int));
  448. // _(SIOCNRRTCTL, READ, sizeof(int));
  449. // _(SIOCAX25DIGCTL, READ, sizeof(int));
  450. // _(SIOCAX25GETPARMS, WRITE, struct_ax25_parms_struct_sz);
  451. // _(SIOCAX25SETPARMS, READ, struct_ax25_parms_struct_sz);
  452. #endif
  453. #undef _
  454. }
  455. static bool ioctl_initialized = false;
  456. struct ioctl_desc_compare {
  457. bool operator()(const ioctl_desc& left, const ioctl_desc& right) const {
  458. return left.req < right.req;
  459. }
  460. };
  461. static void ioctl_init() {
  462. ioctl_table_fill();
  463. Sort(ioctl_table, ioctl_table_size, ioctl_desc_compare());
  464. bool bad = false;
  465. for (unsigned i = 0; i < ioctl_table_size - 1; ++i) {
  466. if (ioctl_table[i].req >= ioctl_table[i + 1].req) {
  467. Printf("Duplicate or unsorted ioctl request id %x >= %x (%s vs %s)\n",
  468. ioctl_table[i].req, ioctl_table[i + 1].req, ioctl_table[i].name,
  469. ioctl_table[i + 1].name);
  470. bad = true;
  471. }
  472. }
  473. if (bad) Die();
  474. ioctl_initialized = true;
  475. }
  476. // Handle the most evil ioctls that encode argument value as part of request id.
  477. static unsigned ioctl_request_fixup(unsigned req) {
  478. #if SANITIZER_LINUX
  479. // Strip size and event number.
  480. const unsigned kEviocgbitMask =
  481. (IOC_SIZEMASK << IOC_SIZESHIFT) | EVIOC_EV_MAX;
  482. if ((req & ~kEviocgbitMask) == IOCTL_EVIOCGBIT)
  483. return IOCTL_EVIOCGBIT;
  484. // Strip absolute axis number.
  485. if ((req & ~EVIOC_ABS_MAX) == IOCTL_EVIOCGABS)
  486. return IOCTL_EVIOCGABS;
  487. if ((req & ~EVIOC_ABS_MAX) == IOCTL_EVIOCSABS)
  488. return IOCTL_EVIOCSABS;
  489. #endif
  490. return req;
  491. }
  492. static const ioctl_desc *ioctl_table_lookup(unsigned req) {
  493. int left = 0;
  494. int right = ioctl_table_size;
  495. while (left < right) {
  496. int mid = (left + right) / 2;
  497. if (ioctl_table[mid].req < req)
  498. left = mid + 1;
  499. else
  500. right = mid;
  501. }
  502. if (left == right && ioctl_table[left].req == req)
  503. return ioctl_table + left;
  504. else
  505. return nullptr;
  506. }
  507. static bool ioctl_decode(unsigned req, ioctl_desc *desc) {
  508. CHECK(desc);
  509. desc->req = req;
  510. desc->name = "<DECODED_IOCTL>";
  511. desc->size = IOC_SIZE(req);
  512. // Sanity check.
  513. if (desc->size > 0xFFFF) return false;
  514. unsigned dir = IOC_DIR(req);
  515. switch (dir) {
  516. case IOC_NONE:
  517. desc->type = ioctl_desc::NONE;
  518. break;
  519. case IOC_READ | IOC_WRITE:
  520. desc->type = ioctl_desc::READWRITE;
  521. break;
  522. case IOC_READ:
  523. desc->type = ioctl_desc::WRITE;
  524. break;
  525. case IOC_WRITE:
  526. desc->type = ioctl_desc::READ;
  527. break;
  528. default:
  529. return false;
  530. }
  531. // Size can be 0 iff type is NONE.
  532. if ((desc->type == IOC_NONE) != (desc->size == 0)) return false;
  533. // Sanity check.
  534. if (IOC_TYPE(req) == 0) return false;
  535. return true;
  536. }
  537. static const ioctl_desc *ioctl_lookup(unsigned req) {
  538. req = ioctl_request_fixup(req);
  539. const ioctl_desc *desc = ioctl_table_lookup(req);
  540. if (desc) return desc;
  541. // Try stripping access size from the request id.
  542. desc = ioctl_table_lookup(req & ~(IOC_SIZEMASK << IOC_SIZESHIFT));
  543. // Sanity check: requests that encode access size are either read or write and
  544. // have size of 0 in the table.
  545. if (desc && desc->size == 0 &&
  546. (desc->type == ioctl_desc::READWRITE || desc->type == ioctl_desc::WRITE ||
  547. desc->type == ioctl_desc::READ))
  548. return desc;
  549. return nullptr;
  550. }
  551. static void ioctl_common_pre(void *ctx, const ioctl_desc *desc, int d,
  552. unsigned request, void *arg) {
  553. if (desc->type == ioctl_desc::READ || desc->type == ioctl_desc::READWRITE) {
  554. unsigned size = desc->size ? desc->size : IOC_SIZE(request);
  555. COMMON_INTERCEPTOR_READ_RANGE(ctx, arg, size);
  556. }
  557. if (desc->type != ioctl_desc::CUSTOM)
  558. return;
  559. if (request == IOCTL_SIOCGIFCONF) {
  560. struct __sanitizer_ifconf *ifc = (__sanitizer_ifconf *)arg;
  561. COMMON_INTERCEPTOR_READ_RANGE(ctx, (char*)&ifc->ifc_len,
  562. sizeof(ifc->ifc_len));
  563. }
  564. }
  565. static void ioctl_common_post(void *ctx, const ioctl_desc *desc, int res, int d,
  566. unsigned request, void *arg) {
  567. if (desc->type == ioctl_desc::WRITE || desc->type == ioctl_desc::READWRITE) {
  568. // FIXME: add verbose output
  569. unsigned size = desc->size ? desc->size : IOC_SIZE(request);
  570. COMMON_INTERCEPTOR_WRITE_RANGE(ctx, arg, size);
  571. }
  572. if (desc->type != ioctl_desc::CUSTOM)
  573. return;
  574. if (request == IOCTL_SIOCGIFCONF) {
  575. struct __sanitizer_ifconf *ifc = (__sanitizer_ifconf *)arg;
  576. COMMON_INTERCEPTOR_WRITE_RANGE(ctx, ifc->ifc_ifcu.ifcu_req, ifc->ifc_len);
  577. }
  578. }
  579. #endif