util_bug.h 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267
  1. /* Copyright (c) 2003-2004, Roger Dingledine
  2. * Copyright (c) 2004-2006, Roger Dingledine, Nick Mathewson.
  3. * Copyright (c) 2007-2019, The Tor Project, Inc. */
  4. /* See LICENSE for licensing information */
  5. /**
  6. * \file util_bug.h
  7. *
  8. * \brief Macros to manage assertions, fatal and non-fatal.
  9. *
  10. * Guidelines: All the different kinds of assertion in this file are for
  11. * bug-checking only. Don't write code that can assert based on bad inputs.
  12. *
  13. * We provide two kinds of assertion here: "fatal" and "nonfatal". Use
  14. * nonfatal assertions for any bug you can reasonably recover from -- and
  15. * please, try to recover! Many severe bugs in Tor have been caused by using
  16. * a regular assertion when a nonfatal assertion would have been better.
  17. *
  18. * If you need to check a condition with a nonfatal assertion, AND recover
  19. * from that same condition, consider using the BUG() macro inside a
  20. * conditional. For example:
  21. *
  22. * <code>
  23. * // wrong -- use tor_assert_nonfatal() if you just want an assertion.
  24. * BUG(ptr == NULL);
  25. *
  26. * // okay, but needlessly verbose
  27. * tor_assert_nonfatal(ptr != NULL);
  28. * if (ptr == NULL) { ... }
  29. *
  30. * // this is how we do it:
  31. * if (BUG(ptr == NULL)) { ... }
  32. * </code>
  33. **/
  34. #ifndef TOR_UTIL_BUG_H
  35. #define TOR_UTIL_BUG_H
  36. #include "orconfig.h"
  37. #include "lib/cc/compat_compiler.h"
  38. #include "lib/log/log.h"
  39. #include "lib/testsupport/testsupport.h"
  40. /* Replace assert() with a variant that sends failures to the log before
  41. * calling assert() normally.
  42. */
  43. #ifdef NDEBUG
  44. /* Nobody should ever want to build with NDEBUG set. 99% of our asserts will
  45. * be outside the critical path anyway, so it's silly to disable bug-checking
  46. * throughout the entire program just because a few asserts are slowing you
  47. * down. Profile, optimize the critical path, and keep debugging on.
  48. *
  49. * And I'm not just saying that because some of our asserts check
  50. * security-critical properties.
  51. */
  52. #error "Sorry; we don't support building with NDEBUG."
  53. #endif /* defined(NDEBUG) */
  54. #if defined(TOR_UNIT_TESTS) && defined(__GNUC__)
  55. /* We define this GCC macro as a replacement for PREDICT_UNLIKELY() in this
  56. * header, so that in our unit test builds, we'll get compiler warnings about
  57. * stuff like tor_assert(n = 5).
  58. *
  59. * The key here is that (e) is wrapped in exactly one layer of parentheses,
  60. * and then passed right to a conditional. If you do anything else to the
  61. * expression here, or introduce any more parentheses, the compiler won't
  62. * help you.
  63. *
  64. * We only do this for the unit-test build case because it interferes with
  65. * the likely-branch labeling. Note below that in the other case, we define
  66. * these macros to just be synonyms for PREDICT_(UN)LIKELY.
  67. */
  68. #define ASSERT_PREDICT_UNLIKELY_(e) \
  69. ( { \
  70. int tor__assert_tmp_value__; \
  71. if (e) \
  72. tor__assert_tmp_value__ = 1; \
  73. else \
  74. tor__assert_tmp_value__ = 0; \
  75. tor__assert_tmp_value__; \
  76. } )
  77. #define ASSERT_PREDICT_LIKELY_(e) ASSERT_PREDICT_UNLIKELY_(e)
  78. #else /* !(defined(TOR_UNIT_TESTS) && defined(__GNUC__)) */
  79. #define ASSERT_PREDICT_UNLIKELY_(e) PREDICT_UNLIKELY(e)
  80. #define ASSERT_PREDICT_LIKELY_(e) PREDICT_LIKELY(e)
  81. #endif /* defined(TOR_UNIT_TESTS) && defined(__GNUC__) */
  82. /* Sometimes we don't want to use assertions during branch coverage tests; it
  83. * leads to tons of unreached branches which in reality are only assertions we
  84. * didn't hit. */
  85. #if defined(TOR_UNIT_TESTS) && defined(DISABLE_ASSERTS_IN_UNIT_TESTS)
  86. #define tor_assert(a) STMT_BEGIN \
  87. (void)(a); \
  88. STMT_END
  89. #define tor_assertf(a, fmt, ...) STMT_BEGIN \
  90. (void)(a); \
  91. (void)(fmt); \
  92. STMT_END
  93. #else /* !(defined(TOR_UNIT_TESTS) && defined(DISABLE_ASSERTS_IN_UNIT_T...)) */
  94. /** Like assert(3), but send assertion failures to the log as well as to
  95. * stderr. */
  96. #define tor_assert(expr) tor_assertf(expr, NULL)
  97. #define tor_assertf(expr, fmt, ...) STMT_BEGIN \
  98. if (ASSERT_PREDICT_LIKELY_(expr)) { \
  99. } else { \
  100. tor_assertion_failed_(SHORT_FILE__, __LINE__, __func__, #expr, \
  101. fmt, ##__VA_ARGS__); \
  102. tor_abort_(); \
  103. } STMT_END
  104. #endif /* defined(TOR_UNIT_TESTS) && defined(DISABLE_ASSERTS_IN_UNIT_TESTS) */
  105. #define tor_assert_unreached() \
  106. STMT_BEGIN { \
  107. tor_assertion_failed_(SHORT_FILE__, __LINE__, __func__, \
  108. "line should be unreached", NULL); \
  109. tor_abort_(); \
  110. } STMT_END
  111. /* Non-fatal bug assertions. The "unreached" variants mean "this line should
  112. * never be reached." The "once" variants mean "Don't log a warning more than
  113. * once".
  114. *
  115. * The 'BUG' macro checks a boolean condition and logs an error message if it
  116. * is true. Example usage:
  117. * if (BUG(x == NULL))
  118. * return -1;
  119. */
  120. #ifdef __COVERITY__
  121. #undef BUG
  122. // Coverity defines this in global headers; let's override it. This is a
  123. // magic coverity-only preprocessor thing.
  124. #nodef BUG(x) (x)
  125. #endif /* defined(__COVERITY__) */
  126. #if defined(__COVERITY__) || defined(__clang_analyzer__)
  127. // We're running with a static analysis tool: let's treat even nonfatal
  128. // assertion failures as something that we need to avoid.
  129. #define ALL_BUGS_ARE_FATAL
  130. #endif
  131. #ifdef ALL_BUGS_ARE_FATAL
  132. #define tor_assert_nonfatal_unreached() tor_assert(0)
  133. #define tor_assert_nonfatal(cond) tor_assert((cond))
  134. #define tor_assertf_nonfatal(cond, fmt, ...) \
  135. tor_assertf(cond, fmt, ##__VA_ARGS__)
  136. #define tor_assert_nonfatal_unreached_once() tor_assert(0)
  137. #define tor_assert_nonfatal_once(cond) tor_assert((cond))
  138. #define BUG(cond) \
  139. (ASSERT_PREDICT_UNLIKELY_(cond) ? \
  140. (tor_assertion_failed_(SHORT_FILE__,__LINE__,__func__,"!("#cond")",NULL), \
  141. tor_abort_(), 1) \
  142. : 0)
  143. #elif defined(TOR_UNIT_TESTS) && defined(DISABLE_ASSERTS_IN_UNIT_TESTS)
  144. #define tor_assert_nonfatal_unreached() STMT_NIL
  145. #define tor_assert_nonfatal(cond) ((void)(cond))
  146. #define tor_assertf_nonfatal(cond, fmt, ...) STMT_BEGIN \
  147. (void)cond; \
  148. (void)fmt; \
  149. STMT_END
  150. #define tor_assert_nonfatal_unreached_once() STMT_NIL
  151. #define tor_assert_nonfatal_once(cond) ((void)(cond))
  152. #define BUG(cond) (ASSERT_PREDICT_UNLIKELY_(cond) ? 1 : 0)
  153. #else /* Normal case, !ALL_BUGS_ARE_FATAL, !DISABLE_ASSERTS_IN_UNIT_TESTS */
  154. #define tor_assert_nonfatal_unreached() STMT_BEGIN \
  155. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, NULL, 0, NULL); \
  156. STMT_END
  157. #define tor_assert_nonfatal(cond) STMT_BEGIN \
  158. if (ASSERT_PREDICT_LIKELY_(cond)) { \
  159. } else { \
  160. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, #cond, 0, NULL);\
  161. } \
  162. STMT_END
  163. #define tor_assertf_nonfatal(cond, fmt, ...) STMT_BEGIN \
  164. if (ASSERT_PREDICT_UNLIKELY_(cond)) { \
  165. } else { \
  166. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, #cond, 0, \
  167. fmt, ##__VA_ARGS__); \
  168. } \
  169. STMT_END
  170. #define tor_assert_nonfatal_unreached_once() STMT_BEGIN \
  171. static int warning_logged__ = 0; \
  172. if (!warning_logged__) { \
  173. warning_logged__ = 1; \
  174. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, NULL, 1, NULL); \
  175. } \
  176. STMT_END
  177. #define tor_assert_nonfatal_once(cond) STMT_BEGIN \
  178. static int warning_logged__ = 0; \
  179. if (ASSERT_PREDICT_LIKELY_(cond)) { \
  180. } else if (!warning_logged__) { \
  181. warning_logged__ = 1; \
  182. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, #cond, 1, NULL);\
  183. } \
  184. STMT_END
  185. #define BUG(cond) \
  186. (ASSERT_PREDICT_UNLIKELY_(cond) ? \
  187. (tor_bug_occurred_(SHORT_FILE__,__LINE__,__func__,"!("#cond")",1,NULL),1) \
  188. : 0)
  189. #endif /* defined(ALL_BUGS_ARE_FATAL) || ... */
  190. #ifdef __GNUC__
  191. #define IF_BUG_ONCE__(cond,var) \
  192. if (( { \
  193. static int var = 0; \
  194. int bool_result = !!(cond); \
  195. if (bool_result && !var) { \
  196. var = 1; \
  197. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, \
  198. "!("#cond")", 1, NULL); \
  199. } \
  200. bool_result; } ))
  201. #else /* !defined(__GNUC__) */
  202. #define IF_BUG_ONCE__(cond,var) \
  203. static int var = 0; \
  204. if ((cond) ? \
  205. (var ? 1 : \
  206. (var=1, \
  207. tor_bug_occurred_(SHORT_FILE__, __LINE__, __func__, \
  208. "!("#cond")", 1, NULL), \
  209. 1)) \
  210. : 0)
  211. #endif /* defined(__GNUC__) */
  212. #define IF_BUG_ONCE_VARNAME_(a) \
  213. warning_logged_on_ ## a ## __
  214. #define IF_BUG_ONCE_VARNAME__(a) \
  215. IF_BUG_ONCE_VARNAME_(a)
  216. /** This macro behaves as 'if (bug(x))', except that it only logs its
  217. * warning once, no matter how many times it triggers.
  218. */
  219. #define IF_BUG_ONCE(cond) \
  220. IF_BUG_ONCE__(ASSERT_PREDICT_UNLIKELY_(cond), \
  221. IF_BUG_ONCE_VARNAME__(__LINE__))
  222. /** Define this if you want Tor to crash when any problem comes up,
  223. * so you can get a coredump and track things down. */
  224. // #define tor_fragile_assert() tor_assert_unreached(0)
  225. #define tor_fragile_assert() tor_assert_nonfatal_unreached_once()
  226. void tor_assertion_failed_(const char *fname, unsigned int line,
  227. const char *func, const char *expr,
  228. const char *fmt, ...);
  229. void tor_bug_occurred_(const char *fname, unsigned int line,
  230. const char *func, const char *expr,
  231. int once, const char *fmt, ...);
  232. void tor_abort_(void) ATTR_NORETURN;
  233. #ifdef _WIN32
  234. #define SHORT_FILE__ (tor_fix_source_file(__FILE__))
  235. const char *tor_fix_source_file(const char *fname);
  236. #else
  237. #define SHORT_FILE__ (__FILE__)
  238. #define tor_fix_source_file(s) (s)
  239. #endif /* defined(_WIN32) */
  240. #ifdef TOR_UNIT_TESTS
  241. void tor_capture_bugs_(int n);
  242. void tor_end_capture_bugs_(void);
  243. const struct smartlist_t *tor_get_captured_bug_log_(void);
  244. void tor_set_failed_assertion_callback(void (*fn)(void));
  245. #endif /* defined(TOR_UNIT_TESTS) */
  246. #endif /* !defined(TOR_UTIL_BUG_H) */