[go] runtime: fix bitmap marking to exclude ASAN redzone

1 view
Skip to first unread message

Gerrit Bot (Gerrit)

unread,
3:15 AM (4 hours ago) 3:15 AM
to goph...@pubsubhelper.golang.org, 秦龙, golang-co...@googlegroups.com

Gerrit Bot has uploaded the change for review

Commit message

runtime: fix bitmap marking to exclude ASAN redzone

When ASAN is enabled, a redzone is appended to allocation size by the compiler-rt.
This causes dataSize to be larger than the actual user data size, which affects
bitmap calculation when the redzone size is comparable to or larger than typ.Size_.

To fix this, use actualSize() to subtract the redzone size before computing the
bitmap mask and scanSize, ensuring only the actual user data region is reflected
in the bitmap.

Fixes #80136
Change-Id: I07db55a51933fc59245f066a7ee41242186f3137
GitHub-Last-Rev: 9acc94430d80881a4f3d11c019cea33684e23ca1
GitHub-Pull-Request: golang/go#80180

Change diff

diff --git a/src/runtime/malloc.go b/src/runtime/malloc.go
index 8c5ec38..b62b56c 100644
--- a/src/runtime/malloc.go
+++ b/src/runtime/malloc.go
@@ -2483,3 +2483,29 @@
return 16 << 7
}
}
+
+// actualSize computes the user allocation size from the total size including redzone.
+// Refer to the implementation of the compiler-rt.
+func actualSize(allocSize uintptr) uintptr {
+ if !asanenabled{
+ return allocSize
+ }
+ switch {
+ case allocSize > (1<<16) - 1024 + 16<<6:
+ return allocSize - 16<<7
+ case allocSize > (1<<15) - 512 + 16<<5:
+ return allocSize - 16<<6
+ case allocSize > (1<<14) - 256 + 16<<4:
+ return allocSize - 16<<5
+ case allocSize > 4096 - 128 + 16<<3:
+ return allocSize - 16<<4
+ case allocSize > 512 - 64 + 16<<2:
+ return allocSize - 16<<3
+ case allocSize > 128 - 32 + 16<<1:
+ return allocSize - 16<<2
+ case allocSize > 64 - 16 + 16<<0:
+ return allocSize - 16<<1
+ default:
+ return allocSize - 16<<0
+ }
+}
diff --git a/src/runtime/mbitmap.go b/src/runtime/mbitmap.go
index 7c05cd6..ac1ab9d 100644
--- a/src/runtime/mbitmap.go
+++ b/src/runtime/mbitmap.go
@@ -625,6 +625,12 @@
// The objects here are always really small, so a single load is sufficient.
src0 := readUintptr(getGCMask(typ))

+ // When ASAN is enabled, a redzone is appended to the data, and the redzone would affect
+ // bitmap calculation by being incorrectly marked as pointers.
+ srcDataSize := dataSize
+ if asanenabled {
+ dataSize = actualSize(srcDataSize)
+ }
// Create repetitions of the bitmap if we have a small slice backing store.
src := src0
if typ.Size_ == goarch.PtrSize {
@@ -635,7 +641,7 @@
// N.B. We rely on dataSize being an exact multiple of the type size.
// The alternative is to be defensive and mask out src to the length
// of dataSize. The purpose is to save on one additional masking operation.
- if doubleCheckHeapSetType && !asanenabled && dataSize%typ.Size_ != 0 {
+ if doubleCheckHeapSetType && dataSize%typ.Size_ != 0 {
throw("runtime: (*mspan).writeHeapBitsSmall: dataSize is not a multiple of typ.Size_")
}
scanSize = typ.PtrBytes
@@ -643,13 +649,11 @@
src |= src0 << (i / goarch.PtrSize)
scanSize += typ.Size_
}
- if asanenabled {
- // Mask src down to dataSize. dataSize is going to be a strange size because of
- // the redzone required for allocations when asan is enabled.
- src &= (1 << (dataSize / goarch.PtrSize)) - 1
- }
}

+ if asanenabled {
+ scanSize += srcDataSize - dataSize
+ }
// Since we're never writing more than one uintptr's worth of bits, we're either going
// to do one or two writes.
dstBase, _ := spanHeapBitsRange(span.base(), pageSize, span.elemsize)
@@ -810,6 +814,9 @@
maxIterBytes := span.elemsize
if header == nil {
maxIterBytes = dataSize
+ if asanenabled {
+ maxIterBytes = actualSize(dataSize)
+ }
}
off := alignUp(uintptr(cheaprand())%dataSize, goarch.PtrSize)
size := dataSize - off
@@ -836,6 +843,9 @@
maxIterBytes := span.elemsize
if header == nil {
maxIterBytes = dataSize
+ if asanenabled {
+ maxIterBytes = actualSize(dataSize)
+ }
}
bad := false
for i := uintptr(0); i < maxIterBytes; i += goarch.PtrSize {

Change information

Files:
  • M src/runtime/malloc.go
  • M src/runtime/mbitmap.go
Change size: S
Delta: 2 files changed, 42 insertions(+), 6 deletions(-)
Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
  • requirement is not satisfiedCode-Review
  • requirement satisfiedNo-Unresolved-Comments
  • requirement is not satisfiedReview-Enforcement
  • requirement is not satisfiedTryBots-Pass
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: newchange
Gerrit-Project: go
Gerrit-Branch: master
Gerrit-Change-Id: I07db55a51933fc59245f066a7ee41242186f3137
Gerrit-Change-Number: 795000
Gerrit-PatchSet: 1
Gerrit-Owner: Gerrit Bot <letsus...@gmail.com>
Gerrit-CC: 秦龙 <qinlo...@gmail.com>
unsatisfied_requirement
satisfied_requirement
open
diffy

Gopher Robot (Gerrit)

unread,
3:15 AM (4 hours ago) 3:15 AM
to 秦龙, Gerrit Bot, goph...@pubsubhelper.golang.org, golang-co...@googlegroups.com

Gopher Robot added 1 comment

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Gopher Robot . unresolved

I spotted some possible problems with your PR:

  1. You have a long 83 character line in the commit message body. Please add line breaks to long lines that should be wrapped. Lines in the commit message body should be wrapped at ~76 characters unless needed for things like URLs or tables. (Note: GitHub might render long lines as soft-wrapped, so double-check in the Gerrit commit message shown above.)

Please address any problems by updating the GitHub PR.

When complete, mark this comment as 'Done' and click the [blue 'Reply' button](https://go.dev/wiki/GerritBot#i-left-a-reply-to-a-comment-in-gerrit-but-no-one-but-me-can-see-it) above. These findings are based on heuristics; if a finding does not apply, briefly reply here saying so.

To update the commit title or commit message body shown here in Gerrit, you must edit the GitHub PR title and PR description (the first comment) in the GitHub web interface using the 'Edit' button or 'Edit' menu entry there. Note: pushing a new commit to the PR will not automatically update the commit message used by Gerrit.

For more details, see:

(In general for Gerrit code reviews, the change author is expected to [log in to Gerrit](https://go-review.googlesource.com/login/) with a Gmail or other Google account and then close out each piece of feedback by marking it as 'Done' if implemented as suggested or otherwise reply to each review comment. See the [Review](https://go.dev/doc/contribute#review) section of the Contributing Guide for details.)

Open in Gerrit

Related details

Attention set is empty
Submit Requirements:
    • requirement is not satisfiedCode-Review
    • requirement is not satisfiedNo-Unresolved-Comments
    • requirement is not satisfiedReview-Enforcement
    • requirement is not satisfiedTryBots-Pass
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: go
    Gerrit-Branch: master
    Gerrit-Change-Id: I07db55a51933fc59245f066a7ee41242186f3137
    Gerrit-Change-Number: 795000
    Gerrit-PatchSet: 1
    Gerrit-Owner: Gerrit Bot <letsus...@gmail.com>
    Gerrit-CC: Gopher Robot <go...@golang.org>
    Gerrit-CC: 秦龙 <qinlo...@gmail.com>
    Gerrit-Comment-Date: Sat, 27 Jun 2026 07:15:29 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: No
    unsatisfied_requirement
    open
    diffy

    秦龙 (Gerrit)

    unread,
    4:54 AM (2 hours ago) 4:54 AM
    to Gerrit Bot, goph...@pubsubhelper.golang.org, Ian Lance Taylor, Keith Randall, Michael Pratt, Gopher Robot, golang-co...@googlegroups.com
    Attention needed from Ian Lance Taylor, Keith Randall and Michael Pratt

    秦龙 voted and added 2 comments

    Votes added by 秦龙

    Code-Review+1

    2 comments

    Patchset-level comments
    Gopher Robot . resolved

    I spotted some possible problems with your PR:

      1. You have a long 83 character line in the commit message body. Please add line breaks to long lines that should be wrapped. Lines in the commit message body should be wrapped at ~76 characters unless needed for things like URLs or tables. (Note: GitHub might render long lines as soft-wrapped, so double-check in the Gerrit commit message shown above.)

    Please address any problems by updating the GitHub PR.

    When complete, mark this comment as 'Done' and click the [blue 'Reply' button](https://go.dev/wiki/GerritBot#i-left-a-reply-to-a-comment-in-gerrit-but-no-one-but-me-can-see-it) above. These findings are based on heuristics; if a finding does not apply, briefly reply here saying so.

    To update the commit title or commit message body shown here in Gerrit, you must edit the GitHub PR title and PR description (the first comment) in the GitHub web interface using the 'Edit' button or 'Edit' menu entry there. Note: pushing a new commit to the PR will not automatically update the commit message used by Gerrit.

    For more details, see:

    (In general for Gerrit code reviews, the change author is expected to [log in to Gerrit](https://go-review.googlesource.com/login/) with a Gmail or other Google account and then close out each piece of feedback by marking it as 'Done' if implemented as suggested or otherwise reply to each review comment. See the [Review](https://go.dev/doc/contribute#review) section of the Contributing Guide for details.)

    秦龙

    Done

    秦龙 . resolved

    done

    Open in Gerrit

    Related details

    Attention is currently required from:
    • Ian Lance Taylor
    • Keith Randall
    • Michael Pratt
    Submit Requirements:
      • requirement is not satisfiedCode-Review
      • requirement satisfiedNo-Unresolved-Comments
      • requirement is not satisfiedReview-Enforcement
      • requirement is not satisfiedTryBots-Pass
      Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
      Gerrit-MessageType: comment
      Gerrit-Project: go
      Gerrit-Branch: master
      Gerrit-Change-Id: I07db55a51933fc59245f066a7ee41242186f3137
      Gerrit-Change-Number: 795000
      Gerrit-PatchSet: 1
      Gerrit-Owner: Gerrit Bot <letsus...@gmail.com>
      Gerrit-Reviewer: Ian Lance Taylor <ia...@golang.org>
      Gerrit-Reviewer: Keith Randall <k...@golang.org>
      Gerrit-Reviewer: Michael Pratt <mpr...@google.com>
      Gerrit-Reviewer: 秦龙 <qinlo...@gmail.com>
      Gerrit-CC: Gopher Robot <go...@golang.org>
      Gerrit-Attention: Keith Randall <k...@golang.org>
      Gerrit-Attention: Ian Lance Taylor <ia...@golang.org>
      Gerrit-Attention: Michael Pratt <mpr...@google.com>
      Gerrit-Comment-Date: Sat, 27 Jun 2026 08:54:18 +0000
      Gerrit-HasComments: Yes
      Gerrit-Has-Labels: Yes
      Comment-In-Reply-To: Gopher Robot <go...@golang.org>
      unsatisfied_requirement
      satisfied_requirement
      open
      diffy
      Reply all
      Reply to author
      Forward
      0 new messages