-
Notifications
You must be signed in to change notification settings - Fork 15.2k
[llvm] Bail out when meeting pointer with negative offset instead of … #120424
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 2 commits
ab73245
b228a0b
a2ef6ff
0a71d26
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -838,11 +838,14 @@ OffsetSpan ObjectSizeOffsetVisitor::computeImpl(Value *V) { | |
|
|
||
| // We end up pointing on a location that's outside of the original object. | ||
| if (ORT.knownBefore() && ORT.Before.isNegative()) { | ||
| // This is UB, and we'd rather return an empty location then. | ||
| // This means that we *may* be accessing memory before the allocation. It's | ||
| // unsure though, so bail out instead of returning a potentially misleading | ||
| // result. | ||
| // TODO: working with ranges instead of value would make it possible to take | ||
| // a better decision. | ||
| if (Options.EvalMode == ObjectSizeOpts::Mode::Min || | ||
| Options.EvalMode == ObjectSizeOpts::Mode::Max) { | ||
| ORT.Before = APInt::getZero(ORT.Before.getBitWidth()); | ||
| ORT.After = APInt::getZero(ORT.Before.getBitWidth()); | ||
| return ObjectSizeOffsetVisitor::unknown(); | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Is the comment above incorrect? IIUC the case @mstorsjo shared doesn't count UB
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Indeed; regularly with UB, when looking at various potential execution paths, the compiler can assume that the ones that are UB just won't happen at runtime. (Not sure how that translates best to this feature though, which is intended to protect against things at runtime that really are unintended.)
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Not at all, i'll update it. The idea would be 'if we are uncertain about the accuracy and the validity of the access, better be safe and bail out rather than return a potentially invalid result. |
||
| } | ||
| // Otherwise it's fine, caller can handle negative offset. | ||
| } | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -78,7 +78,8 @@ define i64 @select_neg_oob_offset(i1 %c0, i1 %c1) { | |
| ; CHECK-NEXT: [[PTR:%.*]] = alloca i8, i64 10, align 1 | ||
| ; CHECK-NEXT: [[OFFSET:%.*]] = select i1 [[C0:%.*]], i64 -3, i64 -4 | ||
| ; CHECK-NEXT: [[PTR_SLIDE:%.*]] = getelementptr inbounds i8, ptr [[PTR]], i64 [[OFFSET]] | ||
| ; CHECK-NEXT: ret i64 0 | ||
| ; CHECK-NEXT: [[RES:%.*]] = select i1 [[C1:%.*]], i64 -1, i64 0 | ||
| ; CHECK-NEXT: ret i64 [[RES]] | ||
| ; | ||
| %ptr = alloca i8, i64 10 | ||
| %offset = select i1 %c0, i64 -3, i64 -4 | ||
|
|
@@ -106,4 +107,23 @@ define i64 @select_gep_offsets(i1 %cond) { | |
| ret i64 %res | ||
| } | ||
|
|
||
| define i64 @select_gep_oob_offsets(i1 %cond) { | ||
|
||
| ; CHECK-LABEL: @select_gep_oob_offsets( | ||
| ; CHECK-NEXT: [[BASE1:%.*]] = alloca [288 x i8], align 16 | ||
| ; CHECK-NEXT: [[SELECT0:%.*]] = select i1 [[COND:%.*]], i64 -4, i64 -64 | ||
| ; CHECK-NEXT: [[SELECT1:%.*]] = select i1 [[COND]], i64 16, i64 64 | ||
| ; CHECK-NEXT: [[GEP0:%.*]] = getelementptr inbounds nuw i8, ptr [[BASE1]], i64 [[SELECT1]] | ||
| ; CHECK-NEXT: [[GEP1:%.*]] = getelementptr inbounds i8, ptr [[GEP0]], i64 [[SELECT0]] | ||
| ; CHECK-NEXT: ret i64 -1 | ||
| ; | ||
| %base1 = alloca [288 x i8], align 16 | ||
| %select0 = select i1 %cond, i64 -4, i64 -64 | ||
| %select1 = select i1 %cond, i64 16, i64 64 | ||
| %gep0 = getelementptr inbounds nuw i8, ptr %base1, i64 %select1 | ||
| %gep1 = getelementptr inbounds i8, ptr %gep0, i64 %select0 | ||
| %call = call i64 @llvm.objectsize.i64.p0(ptr %gep1, i1 false, i1 true, i1 false) | ||
| ret i64 %call | ||
| } | ||
|
|
||
|
|
||
| attributes #0 = { nounwind allocsize(0) } | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.