1/*
2 * Copyright (C) 2019 Apple Inc. All rights reserved.
3 *
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
6 * are met:
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
12 *
13 * THIS SOFTWARE IS PROVIDED BY APPLE INC. ``AS IS'' AND ANY
14 * EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
16 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR
17 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
18 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO,
19 * PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR
20 * PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY
21 * OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
22 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
23 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
24 */
25
26#include "config.h"
27#include "Integrity.h"
28
29#include "HeapCellInlines.h"
30#include "IntegrityInlines.h"
31#include "JSCellInlines.h"
32#include "Options.h"
33#include "VMInspectorInlines.h"
34
35namespace JSC {
36namespace Integrity {
37
38namespace {
39constexpr bool verbose = false;
40}
41
42Random::Random(VM& vm)
43{
44 reloadAndCheckShouldAuditSlow(vm);
45}
46
47bool Random::reloadAndCheckShouldAuditSlow(VM& vm)
48{
49 auto locker = holdLock(m_lock);
50
51 if (!Options::randomIntegrityAuditRate()) {
52 m_triggerBits = 0; // Never trigger, and don't bother reloading.
53 if (verbose)
54 dataLogLn("disabled Integrity audits: trigger bits ", RawPointer(reinterpret_cast<void*>(m_triggerBits)));
55 return false;
56 }
57
58 // Reload the trigger bits.
59 m_triggerBits = 1ull << 63;
60
61 uint32_t threshold = UINT_MAX * Options::randomIntegrityAuditRate();
62 for (int i = 0; i < numberOfTriggerBits; ++i) {
63 bool trigger = vm.random().getUint32() <= threshold;
64 m_triggerBits = m_triggerBits | (static_cast<uint64_t>(trigger) << i);
65 }
66 if (verbose)
67 dataLogLn("reloaded Integrity trigger bits ", RawPointer(reinterpret_cast<void*>(m_triggerBits)));
68 ASSERT(m_triggerBits >= (1ull << 63));
69 return vm.random().getUint32() <= threshold;
70}
71
72void auditCellFully(VM& vm, JSCell* cell)
73{
74 VMInspector::verifyCell<VMInspector::ReleaseAssert>(vm, cell);
75}
76
77void auditCellMinimallySlow(VM&, JSCell* cell)
78{
79 if (Gigacage::contains(cell)) {
80 if (cell->type() != JSImmutableButterflyType) {
81 if (verbose)
82 dataLogLn("Bad cell ", RawPointer(cell), " ", JSValue(cell));
83 CRASH();
84 }
85 }
86}
87
88} // namespace Integrity
89} // namespace JSC
90