sanitizer_common_interceptors_ioctl.inc 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607
  1. //===-- sanitizer_common_interceptors_ioctl.inc -----------------*- C++ -*-===//
  2. //
  3. // This file is distributed under the University of Illinois Open Source
  4. // License. See LICENSE.TXT for details.
  5. //
  6. //===----------------------------------------------------------------------===//
  7. //
  8. // Ioctl handling in common sanitizer interceptors.
  9. //===----------------------------------------------------------------------===//
  10. #include "sanitizer_flags.h"
  11. struct ioctl_desc {
  12. unsigned req;
  13. // FIXME: support read+write arguments. Currently READWRITE and WRITE do the
  14. // same thing.
  15. // XXX: The declarations below may use WRITE instead of READWRITE, unless
  16. // explicitly noted.
  17. enum {
  18. NONE,
  19. READ,
  20. WRITE,
  21. READWRITE,
  22. CUSTOM
  23. } type : 3;
  24. unsigned size : 29;
  25. const char* name;
  26. };
  27. const unsigned ioctl_table_max = 500;
  28. static ioctl_desc ioctl_table[ioctl_table_max];
  29. static unsigned ioctl_table_size = 0;
  30. // This can not be declared as a global, because references to struct_*_sz
  31. // require a global initializer. And this table must be available before global
  32. // initializers are run.
  33. static void ioctl_table_fill() {
  34. #define _(rq, tp, sz) \
  35. if (IOCTL_##rq != IOCTL_NOT_PRESENT) { \
  36. CHECK(ioctl_table_size < ioctl_table_max); \
  37. ioctl_table[ioctl_table_size].req = IOCTL_##rq; \
  38. ioctl_table[ioctl_table_size].type = ioctl_desc::tp; \
  39. ioctl_table[ioctl_table_size].size = sz; \
  40. ioctl_table[ioctl_table_size].name = #rq; \
  41. ++ioctl_table_size; \
  42. }
  43. _(FIOASYNC, READ, sizeof(int));
  44. _(FIOCLEX, NONE, 0);
  45. _(FIOGETOWN, WRITE, sizeof(int));
  46. _(FIONBIO, READ, sizeof(int));
  47. _(FIONCLEX, NONE, 0);
  48. _(FIOSETOWN, READ, sizeof(int));
  49. _(SIOCADDMULTI, READ, struct_ifreq_sz);
  50. _(SIOCATMARK, WRITE, sizeof(int));
  51. _(SIOCDELMULTI, READ, struct_ifreq_sz);
  52. _(SIOCGIFADDR, WRITE, struct_ifreq_sz);
  53. _(SIOCGIFBRDADDR, WRITE, struct_ifreq_sz);
  54. _(SIOCGIFCONF, CUSTOM, 0);
  55. _(SIOCGIFDSTADDR, WRITE, struct_ifreq_sz);
  56. _(SIOCGIFFLAGS, WRITE, struct_ifreq_sz);
  57. _(SIOCGIFMETRIC, WRITE, struct_ifreq_sz);
  58. _(SIOCGIFMTU, WRITE, struct_ifreq_sz);
  59. _(SIOCGIFNETMASK, WRITE, struct_ifreq_sz);
  60. _(SIOCGPGRP, WRITE, sizeof(int));
  61. _(SIOCSIFADDR, READ, struct_ifreq_sz);
  62. _(SIOCSIFBRDADDR, READ, struct_ifreq_sz);
  63. _(SIOCSIFDSTADDR, READ, struct_ifreq_sz);
  64. _(SIOCSIFFLAGS, READ, struct_ifreq_sz);
  65. _(SIOCSIFMETRIC, READ, struct_ifreq_sz);
  66. _(SIOCSIFMTU, READ, struct_ifreq_sz);
  67. _(SIOCSIFNETMASK, READ, struct_ifreq_sz);
  68. _(SIOCSPGRP, READ, sizeof(int));
  69. _(TIOCCONS, NONE, 0);
  70. _(TIOCEXCL, NONE, 0);
  71. _(TIOCGETD, WRITE, sizeof(int));
  72. _(TIOCGPGRP, WRITE, pid_t_sz);
  73. _(TIOCGWINSZ, WRITE, struct_winsize_sz);
  74. _(TIOCMBIC, READ, sizeof(int));
  75. _(TIOCMBIS, READ, sizeof(int));
  76. _(TIOCMGET, WRITE, sizeof(int));
  77. _(TIOCMSET, READ, sizeof(int));
  78. _(TIOCNOTTY, NONE, 0);
  79. _(TIOCNXCL, NONE, 0);
  80. _(TIOCOUTQ, WRITE, sizeof(int));
  81. _(TIOCPKT, READ, sizeof(int));
  82. _(TIOCSCTTY, NONE, 0);
  83. _(TIOCSETD, READ, sizeof(int));
  84. _(TIOCSPGRP, READ, pid_t_sz);
  85. _(TIOCSTI, READ, sizeof(char));
  86. _(TIOCSWINSZ, READ, struct_winsize_sz);
  87. #if (SANITIZER_LINUX && !SANITIZER_ANDROID)
  88. _(SIOCGETSGCNT, WRITE, struct_sioc_sg_req_sz);
  89. _(SIOCGETVIFCNT, WRITE, struct_sioc_vif_req_sz);
  90. #endif
  91. #if SANITIZER_LINUX
  92. // Conflicting request ids.
  93. // _(CDROMAUDIOBUFSIZ, NONE, 0);
  94. // _(SNDCTL_TMR_CONTINUE, NONE, 0);
  95. // _(SNDCTL_TMR_START, NONE, 0);
  96. // _(SNDCTL_TMR_STOP, NONE, 0);
  97. // _(SOUND_MIXER_READ_LOUD, WRITE, sizeof(int)); // same as ...READ_ENHANCE
  98. // _(SOUND_MIXER_READ_MUTE, WRITE, sizeof(int)); // same as ...READ_ENHANCE
  99. // _(SOUND_MIXER_WRITE_LOUD, WRITE, sizeof(int)); // same as ...WRITE_ENHANCE
  100. // _(SOUND_MIXER_WRITE_MUTE, WRITE, sizeof(int)); // same as ...WRITE_ENHANCE
  101. _(BLKFLSBUF, NONE, 0);
  102. _(BLKGETSIZE, WRITE, sizeof(uptr));
  103. _(BLKRAGET, WRITE, sizeof(int));
  104. _(BLKRASET, NONE, 0);
  105. _(BLKROGET, WRITE, sizeof(int));
  106. _(BLKROSET, READ, sizeof(int));
  107. _(BLKRRPART, NONE, 0);
  108. _(CDROMEJECT, NONE, 0);
  109. _(CDROMEJECT_SW, NONE, 0);
  110. _(CDROMMULTISESSION, WRITE, struct_cdrom_multisession_sz);
  111. _(CDROMPAUSE, NONE, 0);
  112. _(CDROMPLAYMSF, READ, struct_cdrom_msf_sz);
  113. _(CDROMPLAYTRKIND, READ, struct_cdrom_ti_sz);
  114. _(CDROMREADAUDIO, READ, struct_cdrom_read_audio_sz);
  115. _(CDROMREADCOOKED, READ, struct_cdrom_msf_sz);
  116. _(CDROMREADMODE1, READ, struct_cdrom_msf_sz);
  117. _(CDROMREADMODE2, READ, struct_cdrom_msf_sz);
  118. _(CDROMREADRAW, READ, struct_cdrom_msf_sz);
  119. _(CDROMREADTOCENTRY, WRITE, struct_cdrom_tocentry_sz);
  120. _(CDROMREADTOCHDR, WRITE, struct_cdrom_tochdr_sz);
  121. _(CDROMRESET, NONE, 0);
  122. _(CDROMRESUME, NONE, 0);
  123. _(CDROMSEEK, READ, struct_cdrom_msf_sz);
  124. _(CDROMSTART, NONE, 0);
  125. _(CDROMSTOP, NONE, 0);
  126. _(CDROMSUBCHNL, WRITE, struct_cdrom_subchnl_sz);
  127. _(CDROMVOLCTRL, READ, struct_cdrom_volctrl_sz);
  128. _(CDROMVOLREAD, WRITE, struct_cdrom_volctrl_sz);
  129. _(CDROM_GET_UPC, WRITE, 8);
  130. _(EVIOCGABS, WRITE, struct_input_absinfo_sz); // fixup
  131. _(EVIOCGBIT, WRITE, struct_input_id_sz); // fixup
  132. _(EVIOCGEFFECTS, WRITE, sizeof(int));
  133. _(EVIOCGID, WRITE, struct_input_id_sz);
  134. _(EVIOCGKEY, WRITE, 0);
  135. _(EVIOCGKEYCODE, WRITE, sizeof(int) * 2);
  136. _(EVIOCGLED, WRITE, 0);
  137. _(EVIOCGNAME, WRITE, 0);
  138. _(EVIOCGPHYS, WRITE, 0);
  139. _(EVIOCGRAB, READ, sizeof(int));
  140. _(EVIOCGREP, WRITE, sizeof(int) * 2);
  141. _(EVIOCGSND, WRITE, 0);
  142. _(EVIOCGSW, WRITE, 0);
  143. _(EVIOCGUNIQ, WRITE, 0);
  144. _(EVIOCGVERSION, WRITE, sizeof(int));
  145. _(EVIOCRMFF, READ, sizeof(int));
  146. _(EVIOCSABS, READ, struct_input_absinfo_sz); // fixup
  147. _(EVIOCSFF, READ, struct_ff_effect_sz);
  148. _(EVIOCSKEYCODE, READ, sizeof(int) * 2);
  149. _(EVIOCSREP, READ, sizeof(int) * 2);
  150. _(FDCLRPRM, NONE, 0);
  151. _(FDDEFPRM, READ, struct_floppy_struct_sz);
  152. _(FDFLUSH, NONE, 0);
  153. _(FDFMTBEG, NONE, 0);
  154. _(FDFMTEND, NONE, 0);
  155. _(FDFMTTRK, READ, struct_format_descr_sz);
  156. _(FDGETDRVPRM, WRITE, struct_floppy_drive_params_sz);
  157. _(FDGETDRVSTAT, WRITE, struct_floppy_drive_struct_sz);
  158. _(FDGETDRVTYP, WRITE, 16);
  159. _(FDGETFDCSTAT, WRITE, struct_floppy_fdc_state_sz);
  160. _(FDGETMAXERRS, WRITE, struct_floppy_max_errors_sz);
  161. _(FDGETPRM, WRITE, struct_floppy_struct_sz);
  162. _(FDMSGOFF, NONE, 0);
  163. _(FDMSGON, NONE, 0);
  164. _(FDPOLLDRVSTAT, WRITE, struct_floppy_drive_struct_sz);
  165. _(FDRAWCMD, WRITE, struct_floppy_raw_cmd_sz);
  166. _(FDRESET, NONE, 0);
  167. _(FDSETDRVPRM, READ, struct_floppy_drive_params_sz);
  168. _(FDSETEMSGTRESH, NONE, 0);
  169. _(FDSETMAXERRS, READ, struct_floppy_max_errors_sz);
  170. _(FDSETPRM, READ, struct_floppy_struct_sz);
  171. _(FDTWADDLE, NONE, 0);
  172. _(FDWERRORCLR, NONE, 0);
  173. _(FDWERRORGET, WRITE, struct_floppy_write_errors_sz);
  174. _(HDIO_DRIVE_CMD, WRITE, sizeof(int));
  175. _(HDIO_GETGEO, WRITE, struct_hd_geometry_sz);
  176. _(HDIO_GET_32BIT, WRITE, sizeof(int));
  177. _(HDIO_GET_DMA, WRITE, sizeof(int));
  178. _(HDIO_GET_IDENTITY, WRITE, struct_hd_driveid_sz);
  179. _(HDIO_GET_KEEPSETTINGS, WRITE, sizeof(int));
  180. _(HDIO_GET_MULTCOUNT, WRITE, sizeof(int));
  181. _(HDIO_GET_NOWERR, WRITE, sizeof(int));
  182. _(HDIO_GET_UNMASKINTR, WRITE, sizeof(int));
  183. _(HDIO_SET_32BIT, NONE, 0);
  184. _(HDIO_SET_DMA, NONE, 0);
  185. _(HDIO_SET_KEEPSETTINGS, NONE, 0);
  186. _(HDIO_SET_MULTCOUNT, NONE, 0);
  187. _(HDIO_SET_NOWERR, NONE, 0);
  188. _(HDIO_SET_UNMASKINTR, NONE, 0);
  189. _(MTIOCGET, WRITE, struct_mtget_sz);
  190. _(MTIOCPOS, WRITE, struct_mtpos_sz);
  191. _(MTIOCTOP, READ, struct_mtop_sz);
  192. _(PPPIOCGASYNCMAP, WRITE, sizeof(int));
  193. _(PPPIOCGDEBUG, WRITE, sizeof(int));
  194. _(PPPIOCGFLAGS, WRITE, sizeof(int));
  195. _(PPPIOCGUNIT, WRITE, sizeof(int));
  196. _(PPPIOCGXASYNCMAP, WRITE, sizeof(int) * 8);
  197. _(PPPIOCSASYNCMAP, READ, sizeof(int));
  198. _(PPPIOCSDEBUG, READ, sizeof(int));
  199. _(PPPIOCSFLAGS, READ, sizeof(int));
  200. _(PPPIOCSMAXCID, READ, sizeof(int));
  201. _(PPPIOCSMRU, READ, sizeof(int));
  202. _(PPPIOCSXASYNCMAP, READ, sizeof(int) * 8);
  203. _(SIOCADDRT, READ, struct_rtentry_sz);
  204. _(SIOCDARP, READ, struct_arpreq_sz);
  205. _(SIOCDELRT, READ, struct_rtentry_sz);
  206. _(SIOCDRARP, READ, struct_arpreq_sz);
  207. _(SIOCGARP, WRITE, struct_arpreq_sz);
  208. _(SIOCGIFENCAP, WRITE, sizeof(int));
  209. _(SIOCGIFHWADDR, WRITE, struct_ifreq_sz);
  210. _(SIOCGIFMAP, WRITE, struct_ifreq_sz);
  211. _(SIOCGIFMEM, WRITE, struct_ifreq_sz);
  212. _(SIOCGIFNAME, NONE, 0);
  213. _(SIOCGIFSLAVE, NONE, 0);
  214. _(SIOCGRARP, WRITE, struct_arpreq_sz);
  215. _(SIOCGSTAMP, WRITE, timeval_sz);
  216. _(SIOCSARP, READ, struct_arpreq_sz);
  217. _(SIOCSIFENCAP, READ, sizeof(int));
  218. _(SIOCSIFHWADDR, READ, struct_ifreq_sz);
  219. _(SIOCSIFLINK, NONE, 0);
  220. _(SIOCSIFMAP, READ, struct_ifreq_sz);
  221. _(SIOCSIFMEM, READ, struct_ifreq_sz);
  222. _(SIOCSIFSLAVE, NONE, 0);
  223. _(SIOCSRARP, READ, struct_arpreq_sz);
  224. _(SNDCTL_COPR_HALT, WRITE, struct_copr_debug_buf_sz);
  225. _(SNDCTL_COPR_LOAD, READ, struct_copr_buffer_sz);
  226. _(SNDCTL_COPR_RCODE, WRITE, struct_copr_debug_buf_sz);
  227. _(SNDCTL_COPR_RCVMSG, WRITE, struct_copr_msg_sz);
  228. _(SNDCTL_COPR_RDATA, WRITE, struct_copr_debug_buf_sz);
  229. _(SNDCTL_COPR_RESET, NONE, 0);
  230. _(SNDCTL_COPR_RUN, WRITE, struct_copr_debug_buf_sz);
  231. _(SNDCTL_COPR_SENDMSG, READ, struct_copr_msg_sz);
  232. _(SNDCTL_COPR_WCODE, READ, struct_copr_debug_buf_sz);
  233. _(SNDCTL_COPR_WDATA, READ, struct_copr_debug_buf_sz);
  234. _(SNDCTL_DSP_GETBLKSIZE, WRITE, sizeof(int));
  235. _(SNDCTL_DSP_GETFMTS, WRITE, sizeof(int));
  236. _(SNDCTL_DSP_NONBLOCK, NONE, 0);
  237. _(SNDCTL_DSP_POST, NONE, 0);
  238. _(SNDCTL_DSP_RESET, NONE, 0);
  239. _(SNDCTL_DSP_SETFMT, WRITE, sizeof(int));
  240. _(SNDCTL_DSP_SETFRAGMENT, WRITE, sizeof(int));
  241. _(SNDCTL_DSP_SPEED, WRITE, sizeof(int));
  242. _(SNDCTL_DSP_STEREO, WRITE, sizeof(int));
  243. _(SNDCTL_DSP_SUBDIVIDE, WRITE, sizeof(int));
  244. _(SNDCTL_DSP_SYNC, NONE, 0);
  245. _(SNDCTL_FM_4OP_ENABLE, READ, sizeof(int));
  246. _(SNDCTL_FM_LOAD_INSTR, READ, struct_sbi_instrument_sz);
  247. _(SNDCTL_MIDI_INFO, WRITE, struct_midi_info_sz);
  248. _(SNDCTL_MIDI_PRETIME, WRITE, sizeof(int));
  249. _(SNDCTL_SEQ_CTRLRATE, WRITE, sizeof(int));
  250. _(SNDCTL_SEQ_GETINCOUNT, WRITE, sizeof(int));
  251. _(SNDCTL_SEQ_GETOUTCOUNT, WRITE, sizeof(int));
  252. _(SNDCTL_SEQ_NRMIDIS, WRITE, sizeof(int));
  253. _(SNDCTL_SEQ_NRSYNTHS, WRITE, sizeof(int));
  254. _(SNDCTL_SEQ_OUTOFBAND, READ, struct_seq_event_rec_sz);
  255. _(SNDCTL_SEQ_PANIC, NONE, 0);
  256. _(SNDCTL_SEQ_PERCMODE, NONE, 0);
  257. _(SNDCTL_SEQ_RESET, NONE, 0);
  258. _(SNDCTL_SEQ_RESETSAMPLES, READ, sizeof(int));
  259. _(SNDCTL_SEQ_SYNC, NONE, 0);
  260. _(SNDCTL_SEQ_TESTMIDI, READ, sizeof(int));
  261. _(SNDCTL_SEQ_THRESHOLD, READ, sizeof(int));
  262. _(SNDCTL_SYNTH_INFO, WRITE, struct_synth_info_sz);
  263. _(SNDCTL_SYNTH_MEMAVL, WRITE, sizeof(int));
  264. _(SNDCTL_TMR_METRONOME, READ, sizeof(int));
  265. _(SNDCTL_TMR_SELECT, WRITE, sizeof(int));
  266. _(SNDCTL_TMR_SOURCE, WRITE, sizeof(int));
  267. _(SNDCTL_TMR_TEMPO, WRITE, sizeof(int));
  268. _(SNDCTL_TMR_TIMEBASE, WRITE, sizeof(int));
  269. _(SOUND_MIXER_READ_ALTPCM, WRITE, sizeof(int));
  270. _(SOUND_MIXER_READ_BASS, WRITE, sizeof(int));
  271. _(SOUND_MIXER_READ_CAPS, WRITE, sizeof(int));
  272. _(SOUND_MIXER_READ_CD, WRITE, sizeof(int));
  273. _(SOUND_MIXER_READ_DEVMASK, WRITE, sizeof(int));
  274. _(SOUND_MIXER_READ_ENHANCE, WRITE, sizeof(int));
  275. _(SOUND_MIXER_READ_IGAIN, WRITE, sizeof(int));
  276. _(SOUND_MIXER_READ_IMIX, WRITE, sizeof(int));
  277. _(SOUND_MIXER_READ_LINE, WRITE, sizeof(int));
  278. _(SOUND_MIXER_READ_LINE1, WRITE, sizeof(int));
  279. _(SOUND_MIXER_READ_LINE2, WRITE, sizeof(int));
  280. _(SOUND_MIXER_READ_LINE3, WRITE, sizeof(int));
  281. _(SOUND_MIXER_READ_MIC, WRITE, sizeof(int));
  282. _(SOUND_MIXER_READ_OGAIN, WRITE, sizeof(int));
  283. _(SOUND_MIXER_READ_PCM, WRITE, sizeof(int));
  284. _(SOUND_MIXER_READ_RECLEV, WRITE, sizeof(int));
  285. _(SOUND_MIXER_READ_RECMASK, WRITE, sizeof(int));
  286. _(SOUND_MIXER_READ_RECSRC, WRITE, sizeof(int));
  287. _(SOUND_MIXER_READ_SPEAKER, WRITE, sizeof(int));
  288. _(SOUND_MIXER_READ_STEREODEVS, WRITE, sizeof(int));
  289. _(SOUND_MIXER_READ_SYNTH, WRITE, sizeof(int));
  290. _(SOUND_MIXER_READ_TREBLE, WRITE, sizeof(int));
  291. _(SOUND_MIXER_READ_VOLUME, WRITE, sizeof(int));
  292. _(SOUND_MIXER_WRITE_ALTPCM, WRITE, sizeof(int));
  293. _(SOUND_MIXER_WRITE_BASS, WRITE, sizeof(int));
  294. _(SOUND_MIXER_WRITE_CD, WRITE, sizeof(int));
  295. _(SOUND_MIXER_WRITE_ENHANCE, WRITE, sizeof(int));
  296. _(SOUND_MIXER_WRITE_IGAIN, WRITE, sizeof(int));
  297. _(SOUND_MIXER_WRITE_IMIX, WRITE, sizeof(int));
  298. _(SOUND_MIXER_WRITE_LINE, WRITE, sizeof(int));
  299. _(SOUND_MIXER_WRITE_LINE1, WRITE, sizeof(int));
  300. _(SOUND_MIXER_WRITE_LINE2, WRITE, sizeof(int));
  301. _(SOUND_MIXER_WRITE_LINE3, WRITE, sizeof(int));
  302. _(SOUND_MIXER_WRITE_MIC, WRITE, sizeof(int));
  303. _(SOUND_MIXER_WRITE_OGAIN, WRITE, sizeof(int));
  304. _(SOUND_MIXER_WRITE_PCM, WRITE, sizeof(int));
  305. _(SOUND_MIXER_WRITE_RECLEV, WRITE, sizeof(int));
  306. _(SOUND_MIXER_WRITE_RECSRC, WRITE, sizeof(int));
  307. _(SOUND_MIXER_WRITE_SPEAKER, WRITE, sizeof(int));
  308. _(SOUND_MIXER_WRITE_SYNTH, WRITE, sizeof(int));
  309. _(SOUND_MIXER_WRITE_TREBLE, WRITE, sizeof(int));
  310. _(SOUND_MIXER_WRITE_VOLUME, WRITE, sizeof(int));
  311. _(SOUND_PCM_READ_BITS, WRITE, sizeof(int));
  312. _(SOUND_PCM_READ_CHANNELS, WRITE, sizeof(int));
  313. _(SOUND_PCM_READ_FILTER, WRITE, sizeof(int));
  314. _(SOUND_PCM_READ_RATE, WRITE, sizeof(int));
  315. _(SOUND_PCM_WRITE_CHANNELS, WRITE, sizeof(int));
  316. _(SOUND_PCM_WRITE_FILTER, WRITE, sizeof(int));
  317. _(TCFLSH, NONE, 0);
  318. _(TCGETA, WRITE, struct_termio_sz);
  319. _(TCGETS, WRITE, struct_termios_sz);
  320. _(TCSBRK, NONE, 0);
  321. _(TCSBRKP, NONE, 0);
  322. _(TCSETA, READ, struct_termio_sz);
  323. _(TCSETAF, READ, struct_termio_sz);
  324. _(TCSETAW, READ, struct_termio_sz);
  325. _(TCSETS, READ, struct_termios_sz);
  326. _(TCSETSF, READ, struct_termios_sz);
  327. _(TCSETSW, READ, struct_termios_sz);
  328. _(TCXONC, NONE, 0);
  329. _(TIOCGLCKTRMIOS, WRITE, struct_termios_sz);
  330. _(TIOCGSOFTCAR, WRITE, sizeof(int));
  331. _(TIOCINQ, WRITE, sizeof(int));
  332. _(TIOCLINUX, READ, sizeof(char));
  333. _(TIOCSERCONFIG, NONE, 0);
  334. _(TIOCSERGETLSR, WRITE, sizeof(int));
  335. _(TIOCSERGWILD, WRITE, sizeof(int));
  336. _(TIOCSERSWILD, READ, sizeof(int));
  337. _(TIOCSLCKTRMIOS, READ, struct_termios_sz);
  338. _(TIOCSSOFTCAR, READ, sizeof(int));
  339. _(VT_ACTIVATE, NONE, 0);
  340. _(VT_DISALLOCATE, NONE, 0);
  341. _(VT_GETMODE, WRITE, struct_vt_mode_sz);
  342. _(VT_GETSTATE, WRITE, struct_vt_stat_sz);
  343. _(VT_OPENQRY, WRITE, sizeof(int));
  344. _(VT_RELDISP, NONE, 0);
  345. _(VT_RESIZE, READ, struct_vt_sizes_sz);
  346. _(VT_RESIZEX, READ, struct_vt_consize_sz);
  347. _(VT_SENDSIG, NONE, 0);
  348. _(VT_SETMODE, READ, struct_vt_mode_sz);
  349. _(VT_WAITACTIVE, NONE, 0);
  350. #endif
  351. #if SANITIZER_LINUX && !SANITIZER_ANDROID
  352. // _(SIOCDEVPLIP, WRITE, struct_ifreq_sz); // the same as EQL_ENSLAVE
  353. _(CYGETDEFTHRESH, WRITE, sizeof(int));
  354. _(CYGETDEFTIMEOUT, WRITE, sizeof(int));
  355. _(CYGETMON, WRITE, struct_cyclades_monitor_sz);
  356. _(CYGETTHRESH, WRITE, sizeof(int));
  357. _(CYGETTIMEOUT, WRITE, sizeof(int));
  358. _(CYSETDEFTHRESH, NONE, 0);
  359. _(CYSETDEFTIMEOUT, NONE, 0);
  360. _(CYSETTHRESH, NONE, 0);
  361. _(CYSETTIMEOUT, NONE, 0);
  362. _(EQL_EMANCIPATE, WRITE, struct_ifreq_sz);
  363. _(EQL_ENSLAVE, WRITE, struct_ifreq_sz);
  364. _(EQL_GETMASTRCFG, WRITE, struct_ifreq_sz);
  365. _(EQL_GETSLAVECFG, WRITE, struct_ifreq_sz);
  366. _(EQL_SETMASTRCFG, WRITE, struct_ifreq_sz);
  367. _(EQL_SETSLAVECFG, WRITE, struct_ifreq_sz);
  368. _(EVIOCGKEYCODE_V2, WRITE, struct_input_keymap_entry_sz);
  369. _(EVIOCGPROP, WRITE, 0);
  370. _(EVIOCSKEYCODE_V2, READ, struct_input_keymap_entry_sz);
  371. _(FS_IOC_GETFLAGS, WRITE, sizeof(int));
  372. _(FS_IOC_GETVERSION, WRITE, sizeof(int));
  373. _(FS_IOC_SETFLAGS, READ, sizeof(int));
  374. _(FS_IOC_SETVERSION, READ, sizeof(int));
  375. _(GIO_CMAP, WRITE, 48);
  376. _(GIO_FONT, WRITE, 8192);
  377. _(GIO_SCRNMAP, WRITE, e_tabsz);
  378. _(GIO_UNIMAP, WRITE, struct_unimapdesc_sz);
  379. _(GIO_UNISCRNMAP, WRITE, sizeof(short) * e_tabsz);
  380. _(KDADDIO, NONE, 0);
  381. _(KDDELIO, NONE, 0);
  382. _(KDDISABIO, NONE, 0);
  383. _(KDENABIO, NONE, 0);
  384. _(KDGETKEYCODE, WRITE, struct_kbkeycode_sz);
  385. _(KDGETLED, WRITE, 1);
  386. _(KDGETMODE, WRITE, sizeof(int));
  387. _(KDGKBDIACR, WRITE, struct_kbdiacrs_sz);
  388. _(KDGKBENT, WRITE, struct_kbentry_sz);
  389. _(KDGKBLED, WRITE, sizeof(int));
  390. _(KDGKBMETA, WRITE, sizeof(int));
  391. _(KDGKBMODE, WRITE, sizeof(int));
  392. _(KDGKBSENT, WRITE, struct_kbsentry_sz);
  393. _(KDGKBTYPE, WRITE, 1);
  394. _(KDMAPDISP, NONE, 0);
  395. _(KDMKTONE, NONE, 0);
  396. _(KDSETKEYCODE, READ, struct_kbkeycode_sz);
  397. _(KDSETLED, NONE, 0);
  398. _(KDSETMODE, NONE, 0);
  399. _(KDSIGACCEPT, NONE, 0);
  400. _(KDSKBDIACR, READ, struct_kbdiacrs_sz);
  401. _(KDSKBENT, READ, struct_kbentry_sz);
  402. _(KDSKBLED, NONE, 0);
  403. _(KDSKBMETA, NONE, 0);
  404. _(KDSKBMODE, NONE, 0);
  405. _(KDSKBSENT, READ, struct_kbsentry_sz);
  406. _(KDUNMAPDISP, NONE, 0);
  407. _(KIOCSOUND, NONE, 0);
  408. _(LPABORT, NONE, 0);
  409. _(LPABORTOPEN, NONE, 0);
  410. _(LPCAREFUL, NONE, 0);
  411. _(LPCHAR, NONE, 0);
  412. _(LPGETIRQ, WRITE, sizeof(int));
  413. _(LPGETSTATUS, WRITE, sizeof(int));
  414. _(LPRESET, NONE, 0);
  415. _(LPSETIRQ, NONE, 0);
  416. _(LPTIME, NONE, 0);
  417. _(LPWAIT, NONE, 0);
  418. _(MTIOCGETCONFIG, WRITE, struct_mtconfiginfo_sz);
  419. _(MTIOCSETCONFIG, READ, struct_mtconfiginfo_sz);
  420. _(PIO_CMAP, NONE, 0);
  421. _(PIO_FONT, READ, 8192);
  422. _(PIO_SCRNMAP, READ, e_tabsz);
  423. _(PIO_UNIMAP, READ, struct_unimapdesc_sz);
  424. _(PIO_UNIMAPCLR, READ, struct_unimapinit_sz);
  425. _(PIO_UNISCRNMAP, READ, sizeof(short) * e_tabsz);
  426. _(SCSI_IOCTL_PROBE_HOST, READ, sizeof(int));
  427. _(SCSI_IOCTL_TAGGED_DISABLE, NONE, 0);
  428. _(SCSI_IOCTL_TAGGED_ENABLE, NONE, 0);
  429. _(SNDCTL_DSP_GETISPACE, WRITE, struct_audio_buf_info_sz);
  430. _(SNDCTL_DSP_GETOSPACE, WRITE, struct_audio_buf_info_sz);
  431. _(TIOCGSERIAL, WRITE, struct_serial_struct_sz);
  432. _(TIOCSERGETMULTI, WRITE, struct_serial_multiport_struct_sz);
  433. _(TIOCSERSETMULTI, READ, struct_serial_multiport_struct_sz);
  434. _(TIOCSSERIAL, READ, struct_serial_struct_sz);
  435. // The following ioctl requests are shared between AX25, IPX, netrom and
  436. // mrouted.
  437. // _(SIOCAIPXITFCRT, READ, sizeof(char));
  438. // _(SIOCAX25GETUID, READ, struct_sockaddr_ax25_sz);
  439. // _(SIOCNRGETPARMS, WRITE, struct_nr_parms_struct_sz);
  440. // _(SIOCAIPXPRISLT, READ, sizeof(char));
  441. // _(SIOCNRSETPARMS, READ, struct_nr_parms_struct_sz);
  442. // _(SIOCAX25ADDUID, READ, struct_sockaddr_ax25_sz);
  443. // _(SIOCNRDECOBS, NONE, 0);
  444. // _(SIOCAX25DELUID, READ, struct_sockaddr_ax25_sz);
  445. // _(SIOCIPXCFGDATA, WRITE, struct_ipx_config_data_sz);
  446. // _(SIOCAX25NOUID, READ, sizeof(int));
  447. // _(SIOCNRRTCTL, READ, sizeof(int));
  448. // _(SIOCAX25DIGCTL, READ, sizeof(int));
  449. // _(SIOCAX25GETPARMS, WRITE, struct_ax25_parms_struct_sz);
  450. // _(SIOCAX25SETPARMS, READ, struct_ax25_parms_struct_sz);
  451. #endif
  452. #undef _
  453. }
  454. static bool ioctl_initialized = false;
  455. struct ioctl_desc_compare {
  456. bool operator()(const ioctl_desc& left, const ioctl_desc& right) const {
  457. return left.req < right.req;
  458. }
  459. };
  460. static void ioctl_init() {
  461. ioctl_table_fill();
  462. InternalSort(&ioctl_table, ioctl_table_size, ioctl_desc_compare());
  463. bool bad = false;
  464. for (unsigned i = 0; i < ioctl_table_size - 1; ++i) {
  465. if (ioctl_table[i].req >= ioctl_table[i + 1].req) {
  466. Printf("Duplicate or unsorted ioctl request id %x >= %x (%s vs %s)\n",
  467. ioctl_table[i].req, ioctl_table[i + 1].req, ioctl_table[i].name,
  468. ioctl_table[i + 1].name);
  469. bad = true;
  470. }
  471. }
  472. if (bad) Die();
  473. ioctl_initialized = true;
  474. }
  475. // Handle the most evil ioctls that encode argument value as part of request id.
  476. static unsigned ioctl_request_fixup(unsigned req) {
  477. #if SANITIZER_LINUX
  478. // Strip size and event number.
  479. const unsigned kEviocgbitMask =
  480. (IOC_SIZEMASK << IOC_SIZESHIFT) | EVIOC_EV_MAX;
  481. if ((req & ~kEviocgbitMask) == IOCTL_EVIOCGBIT)
  482. return IOCTL_EVIOCGBIT;
  483. // Strip absolute axis number.
  484. if ((req & ~EVIOC_ABS_MAX) == IOCTL_EVIOCGABS)
  485. return IOCTL_EVIOCGABS;
  486. if ((req & ~EVIOC_ABS_MAX) == IOCTL_EVIOCSABS)
  487. return IOCTL_EVIOCSABS;
  488. #endif
  489. return req;
  490. }
  491. static const ioctl_desc *ioctl_table_lookup(unsigned req) {
  492. int left = 0;
  493. int right = ioctl_table_size;
  494. while (left < right) {
  495. int mid = (left + right) / 2;
  496. if (ioctl_table[mid].req < req)
  497. left = mid + 1;
  498. else
  499. right = mid;
  500. }
  501. if (left == right && ioctl_table[left].req == req)
  502. return ioctl_table + left;
  503. else
  504. return 0;
  505. }
  506. static bool ioctl_decode(unsigned req, ioctl_desc *desc) {
  507. CHECK(desc);
  508. desc->req = req;
  509. desc->name = "<DECODED_IOCTL>";
  510. desc->size = IOC_SIZE(req);
  511. // Sanity check.
  512. if (desc->size > 0xFFFF) return false;
  513. unsigned dir = IOC_DIR(req);
  514. switch (dir) {
  515. case IOC_NONE:
  516. desc->type = ioctl_desc::NONE;
  517. break;
  518. case IOC_READ | IOC_WRITE:
  519. desc->type = ioctl_desc::READWRITE;
  520. break;
  521. case IOC_READ:
  522. desc->type = ioctl_desc::WRITE;
  523. break;
  524. case IOC_WRITE:
  525. desc->type = ioctl_desc::READ;
  526. break;
  527. default:
  528. return false;
  529. }
  530. // Size can be 0 iff type is NONE.
  531. if ((desc->type == IOC_NONE) != (desc->size == 0)) return false;
  532. // Sanity check.
  533. if (IOC_TYPE(req) == 0) return false;
  534. return true;
  535. }
  536. static const ioctl_desc *ioctl_lookup(unsigned req) {
  537. req = ioctl_request_fixup(req);
  538. const ioctl_desc *desc = ioctl_table_lookup(req);
  539. if (desc) return desc;
  540. // Try stripping access size from the request id.
  541. desc = ioctl_table_lookup(req & ~(IOC_SIZEMASK << IOC_SIZESHIFT));
  542. // Sanity check: requests that encode access size are either read or write and
  543. // have size of 0 in the table.
  544. if (desc && desc->size == 0 &&
  545. (desc->type == ioctl_desc::READWRITE || desc->type == ioctl_desc::WRITE ||
  546. desc->type == ioctl_desc::READ))
  547. return desc;
  548. return 0;
  549. }
  550. static void ioctl_common_pre(void *ctx, const ioctl_desc *desc, int d,
  551. unsigned request, void *arg) {
  552. if (desc->type == ioctl_desc::READ || desc->type == ioctl_desc::READWRITE) {
  553. unsigned size = desc->size ? desc->size : IOC_SIZE(request);
  554. COMMON_INTERCEPTOR_READ_RANGE(ctx, arg, size);
  555. }
  556. if (desc->type != ioctl_desc::CUSTOM)
  557. return;
  558. switch (request) {
  559. case 0x00008912: { // SIOCGIFCONF
  560. struct __sanitizer_ifconf *ifc = (__sanitizer_ifconf *)arg;
  561. COMMON_INTERCEPTOR_READ_RANGE(ctx, &ifc->ifc_len, sizeof(ifc->ifc_len));
  562. break;
  563. }
  564. }
  565. return;
  566. }
  567. static void ioctl_common_post(void *ctx, const ioctl_desc *desc, int res, int d,
  568. unsigned request, void *arg) {
  569. if (desc->type == ioctl_desc::WRITE || desc->type == ioctl_desc::READWRITE) {
  570. // FIXME: add verbose output
  571. unsigned size = desc->size ? desc->size : IOC_SIZE(request);
  572. COMMON_INTERCEPTOR_WRITE_RANGE(ctx, arg, size);
  573. }
  574. if (desc->type != ioctl_desc::CUSTOM)
  575. return;
  576. switch (request) {
  577. case 0x00008912: { // SIOCGIFCONF
  578. struct __sanitizer_ifconf *ifc = (__sanitizer_ifconf *)arg;
  579. COMMON_INTERCEPTOR_WRITE_RANGE(ctx, ifc->ifc_ifcu.ifcu_req, ifc->ifc_len);
  580. break;
  581. }
  582. }
  583. return;
  584. }