|
| 1 | +// RUN: %clang_cl_asan %Od %s %Fe%t %MD |
| 2 | +// RUN: %env_asan_opts=windows_hook_rtl_allocators=true not %run %t 2>&1 | FileCheck %s |
| 3 | + |
| 4 | +#include <stdio.h> |
| 5 | +#include <windows.h> |
| 6 | + |
| 7 | +using AllocateFunctionPtr = PVOID(__stdcall *)(PVOID, ULONG, SIZE_T); |
| 8 | +using ReAllocateFunctionPtr = PVOID(__stdcall *)(PVOID, ULONG, PVOID, SIZE_T); |
| 9 | +using FreeFunctionPtr = PVOID(__stdcall *)(PVOID, ULONG, PVOID); |
| 10 | + |
| 11 | +int main() { |
| 12 | + HMODULE NtDllHandle = GetModuleHandle("ntdll.dll"); |
| 13 | + if (!NtDllHandle) { |
| 14 | + fputs("Couldn't load ntdll??\n", stderr); |
| 15 | + return -1; |
| 16 | + } |
| 17 | + |
| 18 | + auto RtlAllocateHeap_ptr = |
| 19 | + (AllocateFunctionPtr)GetProcAddress(NtDllHandle, "RtlAllocateHeap"); |
| 20 | + if (RtlAllocateHeap_ptr == 0) { |
| 21 | + fputs("Couldn't RtlAllocateHeap\n", stderr); |
| 22 | + return -1; |
| 23 | + } |
| 24 | + |
| 25 | + auto RtlReAllocateHeap_ptr = |
| 26 | + (ReAllocateFunctionPtr)GetProcAddress(NtDllHandle, "RtlReAllocateHeap"); |
| 27 | + if (RtlReAllocateHeap_ptr == 0) { |
| 28 | + fputs("Couldn't find RtlReAllocateHeap\n", stderr); |
| 29 | + return -1; |
| 30 | + } |
| 31 | + |
| 32 | + auto RtlFreeHeap_ptr = |
| 33 | + (FreeFunctionPtr)GetProcAddress(NtDllHandle, "RtlFreeHeap"); |
| 34 | + if (RtlFreeHeap_ptr == 0) { |
| 35 | + fputs("Couldn't RtlFreeHeap\n", stderr); |
| 36 | + return -1; |
| 37 | + } |
| 38 | + |
| 39 | + char *ptr1; |
| 40 | + char *ptr2; |
| 41 | + ptr2 = ptr1 = (char *)RtlAllocateHeap_ptr(GetProcessHeap(), 0, 15); |
| 42 | + if (ptr1) |
| 43 | + fputs("Okay alloc\n", stderr); |
| 44 | + // CHECK: Okay alloc |
| 45 | + |
| 46 | + // TODO: Growing is currently not supported |
| 47 | + ptr2 = (char *)RtlReAllocateHeap_ptr(GetProcessHeap(), |
| 48 | + HEAP_REALLOC_IN_PLACE_ONLY, ptr1, 23); |
| 49 | + if (ptr2 == NULL) |
| 50 | + fputs("Okay grow failed\n", stderr); |
| 51 | + // CHECK: Okay grow failed |
| 52 | + |
| 53 | + // TODO: Shrinking is currently not supported |
| 54 | + ptr2 = (char *)RtlReAllocateHeap_ptr(GetProcessHeap(), |
| 55 | + HEAP_REALLOC_IN_PLACE_ONLY, ptr1, 7); |
| 56 | + if (ptr2 == ptr1) |
| 57 | + fputs("Okay shrinking return the original pointer\n", stderr); |
| 58 | + // CHECK: Okay shrinking return the original pointer |
| 59 | + |
| 60 | + ptr1[7] = 'a'; |
| 61 | + fputs("Okay 7\n", stderr); |
| 62 | + // CHECK: Okay 7 |
| 63 | + |
| 64 | + // TODO: Writing behind the shrinked part is currently not detected. |
| 65 | + // Therefore test writing behind the original allocation for now. |
| 66 | + ptr1[16] = 'a'; |
| 67 | + // CHECK: AddressSanitizer: heap-buffer-overflow on address [[ADDR:0x[0-9a-f]+]] |
| 68 | + // CHECK: WRITE of size 1 at [[ADDR]] thread T0 |
| 69 | + |
| 70 | + RtlFreeHeap_ptr(GetProcessHeap(), 0, ptr1); |
| 71 | +} |
0 commit comments