@@ -528,7 +528,7 @@ static void set_canary(UNUSED const struct slab_metadata *metadata, UNUSED void
528528 }
529529#endif
530530
531- memcpy ((char * )p + size - canary_size , & metadata -> canary_value , canary_size );
531+ h_memcpy_real ((char * )p + size - canary_size , & metadata -> canary_value , canary_size );
532532#endif
533533}
534534
@@ -541,7 +541,7 @@ static void check_canary(UNUSED const struct slab_metadata *metadata, UNUSED con
541541#endif
542542
543543 u64 canary_value ;
544- memcpy (& canary_value , (const char * )p + size - canary_size , canary_size );
544+ h_memcpy_real (& canary_value , (const char * )p + size - canary_size , canary_size );
545545
546546#ifdef HAS_ARM_MTE
547547 if (unlikely (canary_value == 0 )) {
@@ -831,7 +831,7 @@ static inline void deallocate_small(void *p, const size_t *expected_size) {
831831#endif
832832
833833 if (ZERO_ON_FREE && !skip_zero ) {
834- memset (p , 0 , size - canary_size );
834+ h_memset_real (p , 0 , size - canary_size );
835835 }
836836 }
837837
@@ -1502,7 +1502,7 @@ EXPORT void *h_calloc(size_t nmemb, size_t size) {
15021502 total_size = adjust_size_for_canary (total_size );
15031503 void * p = alloc (total_size );
15041504 if (!ZERO_ON_FREE && likely (p != NULL ) && total_size && total_size <= max_slab_size_class ) {
1505- memset (p , 0 , total_size - canary_size );
1505+ h_memset_real (p , 0 , total_size - canary_size );
15061506 }
15071507#ifdef HAS_ARM_MTE
15081508 // use an assert instead of adding a conditional to memset() above (freed memory is always
@@ -1624,7 +1624,7 @@ EXPORT void *h_realloc(void *old, size_t size) {
16241624 mutex_unlock (& ra -> lock );
16251625
16261626 if (memory_remap_fixed (old , old_size , new , size )) {
1627- memcpy (new , old , copy_size );
1627+ h_memcpy_real (new , old , copy_size );
16281628 deallocate_pages (old , old_size , old_guard_size );
16291629 } else {
16301630 memory_unmap ((char * )old - old_guard_size , old_guard_size );
@@ -1646,7 +1646,7 @@ EXPORT void *h_realloc(void *old, size_t size) {
16461646 if (copy_size > 0 && copy_size <= max_slab_size_class ) {
16471647 copy_size -= canary_size ;
16481648 }
1649- memcpy (new , old_orig , copy_size );
1649+ h_memcpy_real (new , old_orig , copy_size );
16501650 if (old_size <= max_slab_size_class ) {
16511651 deallocate_small (old , NULL );
16521652 } else {
@@ -1874,6 +1874,100 @@ EXPORT size_t h_malloc_object_size_fast(const void *p) {
18741874 return SIZE_MAX ;
18751875}
18761876
1877+ inline void * h_memcpy_real (void * dst , const void * src , size_t len ) {
1878+ #if CONFIG_BLOCK_OPS_CHECK_SIZE
1879+ if (dst == src || len == 0 ) {
1880+ return dst ;
1881+ }
1882+
1883+ char * p_dst = (char * )dst ;
1884+ char const * p_src = (char const * )src ;
1885+
1886+ while (len -- ) {
1887+ * p_dst ++ = * p_src ++ ;
1888+ }
1889+
1890+ return dst ;
1891+ #else
1892+ return memcpy (dst , src , len );
1893+ #endif
1894+ }
1895+
1896+ inline void * h_memmove_real (void * dst , const void * src , size_t len ) {
1897+ #if CONFIG_BLOCK_OPS_CHECK_SIZE
1898+ if (dst == src || len == 0 ) {
1899+ return dst ;
1900+ }
1901+
1902+ char * p_dst = (char * )dst ;
1903+ char const * p_src = (char const * )src ;
1904+
1905+ if (p_src < p_dst ) {
1906+ p_dst += len ;
1907+ p_src += len ;
1908+ while (len -- ) {
1909+ * -- p_dst = * -- p_src ;
1910+ }
1911+ } else {
1912+ dst = h_memcpy_real (dst , src , len );
1913+ }
1914+
1915+ return dst ;
1916+ #else
1917+ return memmove (dst , src , len );
1918+ #endif
1919+ }
1920+
1921+ inline void * h_memset_real (void * dst , int value , size_t len ) {
1922+ #if CONFIG_BLOCK_OPS_CHECK_SIZE
1923+ if (len == 0 ) {
1924+ return dst ;
1925+ }
1926+
1927+ char * p_dst = (char * )dst ;
1928+
1929+ while (len -- ) {
1930+ * p_dst ++ = value ;
1931+ }
1932+
1933+ return dst ;
1934+ #else
1935+ return memset (dst , value , len );
1936+ #endif
1937+ }
1938+
1939+ #if CONFIG_BLOCK_OPS_CHECK_SIZE
1940+ EXPORT void * h_memcpy (void * dst , const void * src , size_t len ) {
1941+ if (len > malloc_object_size_fast (src )) {
1942+ fatal_error ("memcpy read overflow" );
1943+ }
1944+ if (len > malloc_object_size_fast (dst )) {
1945+ fatal_error ("memcpy buffer overflow" );
1946+ }
1947+
1948+ return h_memcpy_real (dst , src , len );
1949+ }
1950+
1951+ EXPORT void * h_memmove (void * dst , const void * src , size_t len ) {
1952+ if (len > malloc_object_size_fast (src )) {
1953+ fatal_error ("memmove read overflow" );
1954+ }
1955+ if (len > malloc_object_size_fast (dst )) {
1956+ fatal_error ("memmove buffer overflow" );
1957+ }
1958+
1959+ return h_memmove_real (dst , src , len );
1960+ }
1961+
1962+ EXPORT void * h_memset (void * dst , int value , size_t len ) {
1963+ if (len > malloc_object_size_fast (dst )) {
1964+ fatal_error ("memset buffer overflow" );
1965+ }
1966+
1967+ return h_memset_real (dst , value , len );
1968+ }
1969+ #endif
1970+
18771971EXPORT int h_mallopt (UNUSED int param , UNUSED int value ) {
18781972#ifdef __ANDROID__
18791973 if (param == M_PURGE ) {
0 commit comments