[compiler-rt] [Darwin] Move macOS ASAN reservation above 512G - #191039
Merged
Merged
Conversation
On macOS, the first 512G may contain platform-specific reservations. To ensure compatibility with these reservations, this changes ASAN to always map shadow memory above 512G on macOS. rdar://174252720
Member
|
@llvm/pr-subscribers-compiler-rt-sanitizer Author: Andrew Haberlandt (ndrewh) ChangesOn macOS, the first 512G may contain platform-specific reservations. To ensure compatibility with these reservations, this changes ASAN to always map shadow memory above 512G on macOS. rdar://174252720 Full diff: https://github.com/llvm/llvm-project/pull/191039.diff 2 Files Affected:
diff --git a/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp b/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp
index 3f8de8dd064a5..940175791f376 100644
--- a/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp
+++ b/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp
@@ -1288,6 +1288,25 @@ uptr MapDynamicShadow(uptr shadow_size_bytes, uptr shadow_scale,
return shadow_start;
}
+// Returns a list of ranges which must be covered by shadow memory,
+// and cannot overlap with any fixed mappings made by a sanitizer.
+// This can ensure that the sanitizer runtime does not map over
+// platform-reserved regions.
+void GetAppReservedRanges(InternalMmapVector<ReservedRange>& ranges) {
+ ranges.clear();
+
+# if SANITIZER_OSX
+ // On macOS, the first 512GB are platform-reserved (some of which
+ // may also be available to applications).
+ ranges.push_back({0x1000UL, 0x8000000000UL});
+# endif
+
+ VReport(2, "App ranges:\n");
+ for (auto& [range_start, range_end] : ranges) {
+ VReport(2, " [%p, %p]\n", range_start, range_end);
+ }
+}
+
uptr MapDynamicShadowAndAliases(uptr shadow_size, uptr alias_size,
uptr num_aliases, uptr ring_buffer_size) {
CHECK(false && "HWASan aliasing is unimplemented on Mac");
@@ -1300,6 +1319,16 @@ uptr FindAvailableMemoryRange(uptr size, uptr alignment, uptr left_padding,
const mach_vm_address_t max_vm_address = GetMaxVirtualAddress() + 1;
mach_vm_address_t address = GAP_SEARCH_START_ADDRESS;
mach_vm_address_t free_begin = GAP_SEARCH_START_ADDRESS;
+
+ // Restrict the search to be after any reserved ranges
+ InternalMmapVector<ReservedRange> app_ranges;
+ GetAppReservedRanges(app_ranges);
+
+ for (auto& [range_start, range_end] : app_ranges) {
+ address = Max(address, (mach_vm_address_t)range_end);
+ free_begin = Max(free_begin, (mach_vm_address_t)range_end);
+ }
+
kern_return_t kr = KERN_SUCCESS;
if (largest_gap_found) *largest_gap_found = 0;
if (max_occupied_addr) *max_occupied_addr = 0;
diff --git a/compiler-rt/lib/sanitizer_common/sanitizer_mac.h b/compiler-rt/lib/sanitizer_common/sanitizer_mac.h
index b0e4ac7f40745..7f9a2b77e7d50 100644
--- a/compiler-rt/lib/sanitizer_common/sanitizer_mac.h
+++ b/compiler-rt/lib/sanitizer_common/sanitizer_mac.h
@@ -58,8 +58,13 @@ struct DarwinKernelVersion : VersionBase<DarwinKernelVersion> {
DarwinKernelVersion(u16 major, u16 minor) : VersionBase(major, minor) {}
};
+struct ReservedRange {
+ uptr beg, end;
+};
+
MacosVersion GetMacosAlignedVersion();
DarwinKernelVersion GetDarwinKernelVersion();
+void GetAppReservedRanges(InternalMmapVector<ReservedRange>& ranges);
char **GetEnviron();
|
DanBlackwell
approved these changes
Apr 9, 2026
modularbot
pushed a commit
to modular/modular
that referenced
this pull request
Apr 10, 2026
past the ASAN runtime fix (llvm/llvm-project#191039). MODULAR_ORIG_COMMIT_REV_ID: 1773da5eabdc1456e1fac443ccf0aac439c6a895
Contributor
Author
|
/cherry-pick f63c6ef |
Member
|
Failed to cherry-pick: f63c6ef https://github.com/llvm/llvm-project/actions/runs/24317501960 Please manually backport the fix and push it to your github fork. Once this is done, please create a pull request |
Contributor
Author
|
/cherry-pick 857a98e |
Member
|
/pull-request #192082 |
modularbot
pushed a commit
to modular/modular
that referenced
this pull request
Apr 15, 2026
The ASAN runtime comes from the pre-built @clang-macos toolchain (LLVM 20.1.8), not @llvm-project. The fix (llvm/llvm-project#191039) is only on LLVM main and not yet in any released binary. Update the comment to name the correct blocker and removal condition. MODULAR_ORIG_COMMIT_REV_ID: 391bcba288390517fc8d767d8d061609cb7bd056
YonahGoldberg
pushed a commit
to YonahGoldberg/llvm-project
that referenced
this pull request
Apr 21, 2026
…91039) On macOS, the first 512G may contain platform-specific reservations. To ensure compatibility with these reservations, this changes ASAN to always map shadow memory above 512G on macOS. rdar://174252720
ndrewh
added a commit
to swiftlang/llvm-project
that referenced
this pull request
Apr 29, 2026
🍒 [compiler-rt] [Darwin] Move macOS ASAN reservation above 512G (llvm#191039)
hanno-becker
added a commit
to pq-code-package/mldsa-native
that referenced
this pull request
Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image, whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at process startup: compiler-rt's shadow-memory init re-enters the uninitialized allocator. This made the AArch64 FIPS202 backend_tests job hang until the 6h job timeout, intermittently, depending on which image a matrix leg landed on. Same symptom as python/cpython#145199. The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported as #192082). Point the macOS sanitizer job at the existing 'clang22' dev shell so it builds with clang 22 and can run on macos-latest again. Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
mkannwischer
pushed a commit
to pq-code-package/mldsa-native
that referenced
this pull request
Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image, whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at process startup: compiler-rt's shadow-memory init re-enters the uninitialized allocator. This made the AArch64 FIPS202 backend_tests job hang until the 6h job timeout, intermittently, depending on which image a matrix leg landed on. Same symptom as python/cpython#145199. The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported as #192082). Point the macOS sanitizer job at the existing 'clang22' dev shell so it builds with clang 22 and can run on macos-latest again. Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
hanno-becker
added a commit
to pq-code-package/mlkem-native
that referenced
this pull request
Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image, whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at process startup: compiler-rt's shadow-memory init re-enters the uninitialized allocator. This made the macOS sanitizer jobs hang until the 6h job timeout, intermittently, depending on which image a matrix leg landed on. Same symptom as python/cpython#145199. The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported as #192082). Build the macOS aarch64 target with clang 22 via the existing 'clang22' dev shell so it can run on macos-latest again: - backend_tests: switch nix-shell from 'ci' to 'clang22'. - build_kat: set the macos-latest target's nix_shell to 'clang22', and pass nix-shell to the sanitizer step uniformly with the other steps (it previously omitted nix-shell and fell back to the action default). Other targets (Linux native gcc, macos-15-intel) are unchanged. Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
mkannwischer
pushed a commit
to pq-code-package/mlkem-native
that referenced
this pull request
Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image, whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at process startup: compiler-rt's shadow-memory init re-enters the uninitialized allocator. This made the macOS sanitizer jobs hang until the 6h job timeout, intermittently, depending on which image a matrix leg landed on. Same symptom as python/cpython#145199. The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported as #192082). Build the macOS aarch64 target with clang 22 via the existing 'clang22' dev shell so it can run on macos-latest again: - backend_tests: switch nix-shell from 'ci' to 'clang22'. - build_kat: set the macos-latest target's nix_shell to 'clang22', and pass nix-shell to the sanitizer step uniformly with the other steps (it previously omitted nix-shell and fell back to the action default). Other targets (Linux native gcc, macos-15-intel) are unchanged. Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
andrewhop
pushed a commit
to andrewhop/mlkem-native
that referenced
this pull request
Jul 27, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image, whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at process startup: compiler-rt's shadow-memory init re-enters the uninitialized allocator. This made the macOS sanitizer jobs hang until the 6h job timeout, intermittently, depending on which image a matrix leg landed on. Same symptom as python/cpython#145199. The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported as #192082). Build the macOS aarch64 target with clang 22 via the existing 'clang22' dev shell so it can run on macos-latest again: - backend_tests: switch nix-shell from 'ci' to 'clang22'. - build_kat: set the macos-latest target's nix_shell to 'clang22', and pass nix-shell to the sanitizer step uniformly with the other steps (it previously omitted nix-shell and fell back to the action default). Other targets (Linux native gcc, macos-15-intel) are unchanged. Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
benz0li
pushed a commit
to benz0li/modular
that referenced
this pull request
Aug 18, 2026
workaround Bump the pre-built Clang toolchain from LLVM 20.1.8 to 22.1.4 and remove two workarounds now fixed upstream: - Remove `__asan_default_options` shim: ASAN on macOS now uses `atos -i` natively for inlined frames (llvm/llvm-project#170815). - Remove `UNSUPPORTED: macos-26+` guards on ASAN lit tests: the `FindAvailableMemoryRange` hang is fixed in 22.1.4 (llvm/llvm-project#191039). Also update `clang.BUILD` version paths and suppress two new LLVM 22 warnings in external deps. MODULAR_ORIG_COMMIT_REV_ID: 4657c5c36fa81494a4209f19feca54521755406d
robinber
pushed a commit
to robinber/modular
that referenced
this pull request
Aug 18, 2026
past the ASAN runtime fix (llvm/llvm-project#191039). MODULAR_ORIG_COMMIT_REV_ID: 1773da5eabdc1456e1fac443ccf0aac439c6a895
This was referenced Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On macOS, the first 512G may contain platform-specific reservations. To ensure compatibility with these reservations, this changes ASAN to always map shadow memory above 512G on macOS.
rdar://174252720