Home | History | Annotate | Download | only in fortify
      1 /*
      2  * Copyright (C) 2017 The Android Open Source Project
      3  * All rights reserved.
      4  *
      5  * Redistribution and use in source and binary forms, with or without
      6  * modification, are permitted provided that the following conditions
      7  * are met:
      8  *  * Redistributions of source code must retain the above copyright
      9  *    notice, this list of conditions and the following disclaimer.
     10  *  * Redistributions in binary form must reproduce the above copyright
     11  *    notice, this list of conditions and the following disclaimer in
     12  *    the documentation and/or other materials provided with the
     13  *    distribution.
     14  *
     15  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
     16  * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
     17  * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
     18  * FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
     19  * COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
     20  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
     21  * BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
     22  * OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
     23  * AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
     24  * OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
     25  * OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     26  * SUCH DAMAGE.
     27  */
     28 
     29 #ifndef _FCNTL_H
     30 #error "Never include this file directly; instead, include <fcntl.h>"
     31 #endif
     32 
     33 int __open_2(const char*, int) __INTRODUCED_IN(17);
     34 int __openat_2(int, const char*, int) __INTRODUCED_IN(17);
     35 /*
     36  * These are the easiest way to call the real open even in clang FORTIFY.
     37  */
     38 int __open_real(const char*, int, ...) __RENAME(open);
     39 int __openat_real(int, const char*, int, ...) __RENAME(openat);
     40 
     41 #if defined(__BIONIC_FORTIFY)
     42 #define __open_too_many_args_error "too many arguments"
     43 #define __open_too_few_args_error "called with O_CREAT or O_TMPFILE, but missing mode"
     44 #define __open_useless_modes_warning "has superfluous mode bits; missing O_CREAT?"
     45 /* O_TMPFILE shares bits with O_DIRECTORY. */
     46 #define __open_modes_useful(flags) (((flags) & O_CREAT) || ((flags) & O_TMPFILE) == O_TMPFILE)
     47 #if defined(__clang__)
     48 
     49 #if __ANDROID_API__ >= __ANDROID_API_J_MR1__
     50 __BIONIC_ERROR_FUNCTION_VISIBILITY
     51 int open(const char* pathname, int flags, mode_t modes, ...) __overloadable
     52         __errorattr(__open_too_many_args_error);
     53 
     54 /*
     55  * pass_object_size serves two purposes here, neither of which involve __bos: it
     56  * disqualifies this function from having its address taken (so &open works),
     57  * and it makes overload resolution prefer open(const char *, int) over
     58  * open(const char *, int, ...).
     59  */
     60 __BIONIC_FORTIFY_INLINE
     61 int open(const char* const __pass_object_size pathname, int flags)
     62         __overloadable
     63         __clang_error_if(__open_modes_useful(flags), "'open' " __open_too_few_args_error) {
     64     return __open_2(pathname, flags);
     65 }
     66 
     67 __BIONIC_FORTIFY_INLINE
     68 int open(const char* const __pass_object_size pathname, int flags, mode_t modes)
     69         __overloadable
     70         __clang_warning_if(!__open_modes_useful(flags) && modes,
     71                            "'open' " __open_useless_modes_warning) {
     72     return __open_real(pathname, flags, modes);
     73 }
     74 
     75 __BIONIC_ERROR_FUNCTION_VISIBILITY
     76 int openat(int dirfd, const char* pathname, int flags, mode_t modes, ...)
     77         __overloadable
     78         __errorattr(__open_too_many_args_error);
     79 
     80 __BIONIC_FORTIFY_INLINE
     81 int openat(int dirfd, const char* const __pass_object_size pathname, int flags)
     82         __overloadable
     83         __clang_error_if(__open_modes_useful(flags), "'openat' " __open_too_few_args_error) {
     84     return __openat_2(dirfd, pathname, flags);
     85 }
     86 
     87 __BIONIC_FORTIFY_INLINE
     88 int openat(int dirfd, const char* const __pass_object_size pathname, int flags, mode_t modes)
     89         __overloadable
     90         __clang_warning_if(!__open_modes_useful(flags) && modes,
     91                            "'openat' " __open_useless_modes_warning) {
     92     return __openat_real(dirfd, pathname, flags, modes);
     93 }
     94 #endif /* __ANDROID_API__ >= __ANDROID_API_J_MR1__ */
     95 
     96 #else /* defined(__clang__) */
     97 __errordecl(__creat_missing_mode, __open_too_few_args_error);
     98 __errordecl(__creat_too_many_args, __open_too_many_args_error);
     99 
    100 #if __ANDROID_API__ >= __ANDROID_API_J_MR1__
    101 __BIONIC_FORTIFY_VARIADIC
    102 int open(const char* pathname, int flags, ...) {
    103     if (__builtin_constant_p(flags)) {
    104         if (__open_modes_useful(flags) && __builtin_va_arg_pack_len() == 0) {
    105             __creat_missing_mode();  /* Compile time error. */
    106         }
    107     }
    108 
    109     if (__builtin_va_arg_pack_len() > 1) {
    110         __creat_too_many_args();  /* Compile time error. */
    111     }
    112 
    113     if ((__builtin_va_arg_pack_len() == 0) && !__builtin_constant_p(flags)) {
    114         return __open_2(pathname, flags);
    115     }
    116 
    117     return __open_real(pathname, flags, __builtin_va_arg_pack());
    118 }
    119 
    120 __BIONIC_FORTIFY_VARIADIC
    121 int openat(int dirfd, const char* pathname, int flags, ...) {
    122     if (__builtin_constant_p(flags)) {
    123         if (__open_modes_useful(flags) && __builtin_va_arg_pack_len() == 0) {
    124             __creat_missing_mode();  /* Compile time error. */
    125         }
    126     }
    127 
    128     if (__builtin_va_arg_pack_len() > 1) {
    129         __creat_too_many_args();  /* Compile time error. */
    130     }
    131 
    132     if ((__builtin_va_arg_pack_len() == 0) && !__builtin_constant_p(flags)) {
    133         return __openat_2(dirfd, pathname, flags);
    134     }
    135 
    136     return __openat_real(dirfd, pathname, flags, __builtin_va_arg_pack());
    137 }
    138 #endif /* __ANDROID_API__ >= __ANDROID_API_J_MR1__ */
    139 
    140 #endif /* defined(__clang__) */
    141 
    142 #undef __open_too_many_args_error
    143 #undef __open_too_few_args_error
    144 #undef __open_useless_modes_warning
    145 #undef __open_modes_useful
    146 #endif /* defined(__BIONIC_FORTIFY) */
    147