Skip to content

[compiler-rt] [Darwin] Move macOS ASAN reservation above 512G - #191039

Merged
ndrewh merged 1 commit into
llvm:mainfrom
ndrewh:macos-reserved-ranges
Apr 9, 2026
Merged

ndrewh merged 1 commit into
llvm:mainfrom
ndrewh:macos-reserved-ranges

Conversation

@ndrewh

@ndrewh ndrewh commented Apr 8, 2026

Copy link
Copy Markdown
Contributor

On macOS, the first 512G may contain platform-specific reservations. To ensure compatibility with these reservations, this changes ASAN to always map shadow memory above 512G on macOS.

rdar://174252720

On macOS, the first 512G may contain platform-specific reservations.
To ensure compatibility with these reservations, this changes
ASAN to always map shadow memory above 512G on macOS.

rdar://174252720
@llvmbot

llvmbot commented Apr 8, 2026

Copy link
Copy Markdown
Member

@llvm/pr-subscribers-compiler-rt-sanitizer

Author: Andrew Haberlandt (ndrewh)

Changes

On macOS, the first 512G may contain platform-specific reservations. To ensure compatibility with these reservations, this changes ASAN to always map shadow memory above 512G on macOS.

rdar://174252720


Full diff: https://github.com/llvm/llvm-project/pull/191039.diff

2 Files Affected:

  • (modified) compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp (+29)
  • (modified) compiler-rt/lib/sanitizer_common/sanitizer_mac.h (+5)
diff --git a/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp b/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp
index 3f8de8dd064a5..940175791f376 100644
--- a/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp
+++ b/compiler-rt/lib/sanitizer_common/sanitizer_mac.cpp
@@ -1288,6 +1288,25 @@ uptr MapDynamicShadow(uptr shadow_size_bytes, uptr shadow_scale,
   return shadow_start;
 }
 
+// Returns a list of ranges which must be covered by shadow memory,
+// and cannot overlap with any fixed mappings made by a sanitizer.
+// This can ensure that the sanitizer runtime does not map over
+// platform-reserved regions.
+void GetAppReservedRanges(InternalMmapVector<ReservedRange>& ranges) {
+  ranges.clear();
+
+#  if SANITIZER_OSX
+  // On macOS, the first 512GB are platform-reserved (some of which
+  // may also be available to applications).
+  ranges.push_back({0x1000UL, 0x8000000000UL});
+#  endif
+
+  VReport(2, "App ranges:\n");
+  for (auto& [range_start, range_end] : ranges) {
+    VReport(2, "  [%p, %p]\n", range_start, range_end);
+  }
+}
+
 uptr MapDynamicShadowAndAliases(uptr shadow_size, uptr alias_size,
                                 uptr num_aliases, uptr ring_buffer_size) {
   CHECK(false && "HWASan aliasing is unimplemented on Mac");
@@ -1300,6 +1319,16 @@ uptr FindAvailableMemoryRange(uptr size, uptr alignment, uptr left_padding,
   const mach_vm_address_t max_vm_address = GetMaxVirtualAddress() + 1;
   mach_vm_address_t address = GAP_SEARCH_START_ADDRESS;
   mach_vm_address_t free_begin = GAP_SEARCH_START_ADDRESS;
+
+  // Restrict the search to be after any reserved ranges
+  InternalMmapVector<ReservedRange> app_ranges;
+  GetAppReservedRanges(app_ranges);
+
+  for (auto& [range_start, range_end] : app_ranges) {
+    address = Max(address, (mach_vm_address_t)range_end);
+    free_begin = Max(free_begin, (mach_vm_address_t)range_end);
+  }
+
   kern_return_t kr = KERN_SUCCESS;
   if (largest_gap_found) *largest_gap_found = 0;
   if (max_occupied_addr) *max_occupied_addr = 0;
diff --git a/compiler-rt/lib/sanitizer_common/sanitizer_mac.h b/compiler-rt/lib/sanitizer_common/sanitizer_mac.h
index b0e4ac7f40745..7f9a2b77e7d50 100644
--- a/compiler-rt/lib/sanitizer_common/sanitizer_mac.h
+++ b/compiler-rt/lib/sanitizer_common/sanitizer_mac.h
@@ -58,8 +58,13 @@ struct DarwinKernelVersion : VersionBase<DarwinKernelVersion> {
   DarwinKernelVersion(u16 major, u16 minor) : VersionBase(major, minor) {}
 };
 
+struct ReservedRange {
+  uptr beg, end;
+};
+
 MacosVersion GetMacosAlignedVersion();
 DarwinKernelVersion GetDarwinKernelVersion();
+void GetAppReservedRanges(InternalMmapVector<ReservedRange>& ranges);
 
 char **GetEnviron();
 

@ndrewh
ndrewh merged commit 857a98e into llvm:main Apr 9, 2026
13 checks passed
modularbot pushed a commit to modular/modular that referenced this pull request Apr 10, 2026
past the ASAN runtime fix (llvm/llvm-project#191039).

MODULAR_ORIG_COMMIT_REV_ID: 1773da5eabdc1456e1fac443ccf0aac439c6a895
@ndrewh ndrewh added this to the LLVM 22.x Release milestone Apr 12, 2026
@ndrewh

ndrewh commented Apr 12, 2026

Copy link
Copy Markdown
Contributor Author

/cherry-pick f63c6ef

@llvmbot

llvmbot commented Apr 12, 2026

Copy link
Copy Markdown
Member

Failed to cherry-pick: f63c6ef

https://github.com/llvm/llvm-project/actions/runs/24317501960

Please manually backport the fix and push it to your github fork. Once this is done, please create a pull request

@ndrewh

ndrewh commented Apr 14, 2026

Copy link
Copy Markdown
Contributor Author

/cherry-pick 857a98e

@llvmbot

llvmbot commented Apr 14, 2026

Copy link
Copy Markdown
Member

/pull-request #192082

modularbot pushed a commit to modular/modular that referenced this pull request Apr 15, 2026
The ASAN runtime comes from the pre-built @clang-macos toolchain (LLVM
20.1.8), not @llvm-project. The fix (llvm/llvm-project#191039) is only
on LLVM main and not yet in any released binary. Update the comment to
name the correct blocker and removal condition.

MODULAR_ORIG_COMMIT_REV_ID: 391bcba288390517fc8d767d8d061609cb7bd056
c-rhodes pushed a commit to llvmbot/llvm-project that referenced this pull request Apr 17, 2026
…91039)

On macOS, the first 512G may contain platform-specific reservations. To
ensure compatibility with these reservations, this changes ASAN to
always map shadow memory above 512G on macOS.

rdar://174252720
(cherry picked from commit 857a98e)
YonahGoldberg pushed a commit to YonahGoldberg/llvm-project that referenced this pull request Apr 21, 2026
…91039)

On macOS, the first 512G may contain platform-specific reservations. To
ensure compatibility with these reservations, this changes ASAN to
always map shadow memory above 512G on macOS.

rdar://174252720
ndrewh added a commit to swiftlang/llvm-project that referenced this pull request Apr 29, 2026
…91039)

On macOS, the first 512G may contain platform-specific reservations. To
ensure compatibility with these reservations, this changes ASAN to
always map shadow memory above 512G on macOS.

rdar://174252720
(cherry picked from commit 857a98e)
ndrewh added a commit to swiftlang/llvm-project that referenced this pull request Apr 29, 2026
🍒 [compiler-rt] [Darwin] Move macOS ASAN reservation above 512G (llvm#191039)
hanno-becker added a commit to pq-code-package/mldsa-native that referenced this pull request Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image,
whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at
process startup: compiler-rt's shadow-memory init re-enters the
uninitialized allocator. This made the AArch64 FIPS202 backend_tests job
hang until the 6h job timeout, intermittently, depending on which image a
matrix leg landed on. Same symptom as python/cpython#145199.

The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported
as #192082). Point the macOS sanitizer job at the existing 'clang22' dev
shell so it builds with clang 22 and can run on macos-latest again.

Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
mkannwischer pushed a commit to pq-code-package/mldsa-native that referenced this pull request Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image,
whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at
process startup: compiler-rt's shadow-memory init re-enters the
uninitialized allocator. This made the AArch64 FIPS202 backend_tests job
hang until the 6h job timeout, intermittently, depending on which image a
matrix leg landed on. Same symptom as python/cpython#145199.

The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported
as #192082). Point the macOS sanitizer job at the existing 'clang22' dev
shell so it builds with clang 22 and can run on macos-latest again.

Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
hanno-becker added a commit to pq-code-package/mlkem-native that referenced this pull request Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image,
whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at
process startup: compiler-rt's shadow-memory init re-enters the
uninitialized allocator. This made the macOS sanitizer jobs hang until the
6h job timeout, intermittently, depending on which image a matrix leg
landed on. Same symptom as python/cpython#145199.

The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported
as #192082). Build the macOS aarch64 target with clang 22 via the existing
'clang22' dev shell so it can run on macos-latest again:
  - backend_tests: switch nix-shell from 'ci' to 'clang22'.
  - build_kat: set the macos-latest target's nix_shell to 'clang22', and
    pass nix-shell to the sanitizer step uniformly with the other steps
    (it previously omitted nix-shell and fell back to the action default).
    Other targets (Linux native gcc, macos-15-intel) are unchanged.

Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
mkannwischer pushed a commit to pq-code-package/mlkem-native that referenced this pull request Jun 26, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image,
whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at
process startup: compiler-rt's shadow-memory init re-enters the
uninitialized allocator. This made the macOS sanitizer jobs hang until the
6h job timeout, intermittently, depending on which image a matrix leg
landed on. Same symptom as python/cpython#145199.

The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported
as #192082). Build the macOS aarch64 target with clang 22 via the existing
'clang22' dev shell so it can run on macos-latest again:
  - backend_tests: switch nix-shell from 'ci' to 'clang22'.
  - build_kat: set the macos-latest target's nix_shell to 'clang22', and
    pass nix-shell to the sanitizer step uniformly with the other steps
    (it previously omitted nix-shell and fell back to the action default).
    Other targets (Linux native gcc, macos-15-intel) are unchanged.

Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
andrewhop pushed a commit to andrewhop/mlkem-native that referenced this pull request Jul 27, 2026
The macos-latest label has migrated to the macOS 26 (Tahoe) arm64 image,
whose default-toolchain ASan runtime (nixpkgs clang 21.x) deadlocks at
process startup: compiler-rt's shadow-memory init re-enters the
uninitialized allocator. This made the macOS sanitizer jobs hang until the
6h job timeout, intermittently, depending on which image a matrix leg
landed on. Same symptom as python/cpython#145199.

The fix landed upstream in LLVM >= 22 (llvm/llvm-project#191039, backported
as #192082). Build the macOS aarch64 target with clang 22 via the existing
'clang22' dev shell so it can run on macos-latest again:
  - backend_tests: switch nix-shell from 'ci' to 'clang22'.
  - build_kat: set the macos-latest target's nix_shell to 'clang22', and
    pass nix-shell to the sanitizer step uniformly with the other steps
    (it previously omitted nix-shell and fell back to the action default).
    Other targets (Linux native gcc, macos-15-intel) are unchanged.

Signed-off-by: Hanno Becker <beckphan@amazon.co.uk>
benz0li pushed a commit to benz0li/modular that referenced this pull request Aug 18, 2026
workaround

Bump the pre-built Clang toolchain from LLVM 20.1.8 to 22.1.4 and remove
two workarounds now fixed upstream:

- Remove `__asan_default_options` shim: ASAN on macOS now uses `atos -i`
  natively for inlined frames (llvm/llvm-project#170815).
- Remove `UNSUPPORTED: macos-26+` guards on ASAN lit tests: the
  `FindAvailableMemoryRange` hang is fixed in 22.1.4
  (llvm/llvm-project#191039).

Also update `clang.BUILD` version paths and suppress two new LLVM 22
warnings in external deps.

MODULAR_ORIG_COMMIT_REV_ID: 4657c5c36fa81494a4209f19feca54521755406d
robinber pushed a commit to robinber/modular that referenced this pull request Aug 18, 2026
past the ASAN runtime fix (llvm/llvm-project#191039).

MODULAR_ORIG_COMMIT_REV_ID: 1773da5eabdc1456e1fac443ccf0aac439c6a895
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

Development

Successfully merging this pull request may close these issues.

3 participants