golang使用cgo调用c库时未检测到sanitizer-leak

Sha*_*ANG 7 c c++ memory-leaks go address-sanitizer

概括

之前我使用过 clang-3.8.1,并且在使用 AddressSanitizer 时 sanitizer 崩溃了。而且leakSanitizer根本不起作用。

然后我尝试使用clang-llvm-10.0,AddressSanitizer可以检测到地址问题并正常工作。

但是golang使用cgo调用C时无法检测到泄漏问题。当golang使用CGO时,是否可以使用leak-sanitizer来检测C/C++库中的内存泄漏问题?

例子

  • cgo-sanitizer.go:按预期检测到地址问题。
package main

// #include <stdlib.h>
//
// int test()
// {
//   int *p = (int *)malloc(10 * sizeof(int));
//   free(p);
//   p[1] = 42;
//   return p[1];
// }
import "C"
import "fmt"

func main() {
  fmt.Println(int(C.test()))
  // Output: 42
}
Run Code Online (Sandbox Code Playgroud)
  • 输出
[root@380c7770b175 cplusplus]# CC="clang" CGO_CFLAGS="-O0 -g -fsanitize=address" CGO_LDFLAGS="-fsanitize=address" go run cgo-sanitizer.go
=================================================================
==25680==ERROR: AddressSanitizer: heap-use-after-free on address 0x604000000014 at pc 0x00000054fc2d bp 0x7ffd96a943b0 sp 0x7ffd96a943a8
WRITE of size 4 at 0x604000000014 thread T0
    #0 0x54fc2c in test (/tmp/go-build237509829/b001/exe/cgo-sanitizer+0x54fc2c)
    #1 0x54fcc1 in _cgo_a3187169dba5_Cfunc_test (/tmp/go-build237509829/b001/exe/cgo-sanitizer+0x54fcc1)
    #2 0x5159df  (/tmp/go-build237509829/b001/exe/cgo-sanitizer+0x5159df)
Run Code Online (Sandbox Code Playgroud)
  • cgo-sanitizer-leak.go:未检测到泄漏问题。为什么
[root@380c7770b175 cplusplus]# CC="clang" CGO_CFLAGS="-O0 -g -fsanitize=address" CGO_LDFLAGS="-fsanitize=address" go run cgo-sanitizer.go
=================================================================
==25680==ERROR: AddressSanitizer: heap-use-after-free on address 0x604000000014 at pc 0x00000054fc2d bp 0x7ffd96a943b0 sp 0x7ffd96a943a8
WRITE of size 4 at 0x604000000014 thread T0
    #0 0x54fc2c in test (/tmp/go-build237509829/b001/exe/cgo-sanitizer+0x54fc2c)
    #1 0x54fcc1 in _cgo_a3187169dba5_Cfunc_test (/tmp/go-build237509829/b001/exe/cgo-sanitizer+0x54fcc1)
    #2 0x5159df  (/tmp/go-build237509829/b001/exe/cgo-sanitizer+0x5159df)
Run Code Online (Sandbox Code Playgroud)
package main

// #include <stdlib.h>
//
// int *p;
// int test()
// {
//   p = (int *)malloc(10 * sizeof(int));
//   p = 0;
//   return 52;
// }
import "C"
import "fmt"

func main() {
  fmt.Println(int(C.test()))
  // Output: 52
}
Run Code Online (Sandbox Code Playgroud)

环境

[root@380c7770b175 cplusplus]# CC="clang" CGO_CFLAGS="-O0 -g -fsanitize=leak" CGO_LDFLAGS="-fsanitize=address" go run cgo-sanitizer-leak.go
52
Run Code Online (Sandbox Code Playgroud)

原问题

https://github.com/google/sanitizers/issues/1223

Sha*_*ANG 5

我已经通过在进程退出时显式调用__lsan_do_leak_check(), 解决了这个问题。

__lsan_do_leak_check() 声明于

https://github.com/llvm/llvm-project/blob/master/compiler-rt/include/sanitizer/lsan_interface.h

我猜这与 c-main 启动机制有关,并且 __lsan_do_leak_check() 没有为 golang 启动注册。

欢迎任何能够不断挖掘它的人。