xref: /llvm-project/clang/test/CodeGenCXX/ubsan-vtable-checks.cpp (revision a1d77caaabbb5279b734c061dab36b2138ec476d)
1 // RUN: %clang_cc1 -std=c++11 -triple x86_64-unknown-linux -emit-llvm -fsanitize=null %s -o - | FileCheck %s --check-prefix=CHECK-NULL --check-prefix=ITANIUM
2 // RUN: %clang_cc1 -std=c++11 -triple x86_64-windows -emit-llvm -fsanitize=null %s -o - | FileCheck %s --check-prefix=CHECK-NULL --check-prefix=MSABI
3 // RUN: %clang_cc1 -std=c++11 -triple x86_64-unknown-linux -emit-llvm -fsanitize=null,vptr %s -o - | FileCheck %s --check-prefix=CHECK-VPTR --check-prefix=ITANIUM
4 // RUN: %clang_cc1 -std=c++11 -triple x86_64-windows -emit-llvm -fsanitize=null,vptr %s -o - | FileCheck %s --check-prefix=CHECK-VPTR --check-prefix=MSABI  --check-prefix=CHECK-VPTR-MS
5 // RUN: %clang_cc1 -std=c++11 -triple arm64e-ios-13 -emit-llvm -fptrauth-intrinsics -fptrauth-calls -fptrauth-vtable-pointer-type-discrimination -fptrauth-vtable-pointer-address-discrimination -fsanitize=null,vptr %s -o - | FileCheck %s --check-prefix=CHECK-VPTR --check-prefix=ITANIUM --check-prefix=CHECK-PTRAUTH
6 // RUN: %clang_cc1 -std=c++11 -triple aarch64-unknown-linux -emit-llvm -fptrauth-intrinsics -fptrauth-calls -fptrauth-vtable-pointer-type-discrimination -fptrauth-vtable-pointer-address-discrimination -fsanitize=null,vptr %s -o - | FileCheck %s --check-prefix=CHECK-VPTR --check-prefix=ITANIUM --check-prefix=CHECK-PTRAUTH
7 
8 struct T {
9   virtual ~T() {}
10   virtual int v() { return 1; }
11 };
12 
13 struct U : T {
14   ~U();
15   virtual int v() { return 2; }
16 };
17 
18 U::~U() {}
19 
20 // CHECK-VPTR-MS: @__ubsan_vptr_type_cache = external dso_local
21 
22 // ITANIUM: define{{.*}} i32 @_Z5get_vP1T
23 // MSABI: define dso_local noundef i32 @"?get_v
24 int get_v(T* t) {
25   // First, we check that vtable is not loaded before a type check.
26   // CHECK-NULL-NOT: load {{.*}} (ptr{{.*}})**, {{.*}} (ptr{{.*}})***
27   // CHECK-NULL: [[UBSAN_CMP_RES:%[0-9]+]] = icmp ne ptr %{{[_a-z0-9]+}}, null
28   // CHECK-NULL-NEXT: br i1 [[UBSAN_CMP_RES]], label %{{.*}}, label %{{.*}}
29   // CHECK-NULL: call void @__ubsan_handle_type_mismatch_v1_abort
30   // Second, we check that vtable is actually loaded once the type check is done.
31   // CHECK-NULL: load ptr, ptr {{.*}}
32 
33   // CHECK-PTRAUTH: [[CAST_VTABLE:%.*]] = ptrtoint ptr %vtable to i64
34   // CHECK-PTRAUTH: [[STRIPPED_VTABLE:%.*]] = call i64 @llvm.ptrauth.strip(i64 [[CAST_VTABLE]], i32 0), !nosanitize
35   // CHECK-PTRAUTH: [[STRIPPED_PTR:%.*]] = inttoptr i64 [[STRIPPED_VTABLE]] to ptr
36   // CHECK-PTRAUTH: [[STRIPPED_INT:%.*]] = ptrtoint ptr [[STRIPPED_PTR]] to i64
37   // Make sure authed vtable pointer feeds into hashing
38   // CHECK-PTRAUTH: {{%.*}} = mul i64 [[STRIPPED_INT]], {{.*}}
39 
40   // Verify that we authenticate for the actual vcall
41   // CHECK-PTRAUTH: [[BLENDED:%.*]] = call i64 @llvm.ptrauth.blend(i64 {{%.*}}, i64 17113)
42   // CHECK-PTRAUTH: [[CAST_VTABLE:%.*]] = ptrtoint ptr %vtable2 to i64
43   // CHECK-PTRAUTH: [[AUTHED_INT:%.*]] = call i64 @llvm.ptrauth.auth(i64 [[CAST_VTABLE]], i32 2, i64 [[BLENDED]])
44   // CHECK-PTRAUTH: [[AUTHED_PTR:%.*]] = inttoptr i64 [[AUTHED_INT]] to ptr
45   // CHECK-PTRAUTH: {{%.*}} = getelementptr inbounds ptr, ptr [[AUTHED_PTR]], i64 2
46   return t->v();
47 }
48 
49 // ITANIUM: define{{.*}} void @_Z9delete_itP1T
50 // MSABI: define dso_local void @"?delete_it
51 void delete_it(T *t) {
52   // CHECK-VPTR-NOT: load {{.*}} (ptr{{.*}})**, {{.*}} (ptr{{.*}})***
53   // CHECK-VPTR: br i1 {{.*}} label %{{.*}}
54   // CHECK-VPTR: call void @__ubsan_handle_type_mismatch_v1_abort
55   // Second, we check that vtable is actually loaded once the type check is done.
56   // CHECK-VPTR: load ptr, ptr {{.*}}
57 
58   // First, we check that vtable is not loaded before a type check.
59   // CHECK-PTRAUTH: ptrtoint ptr {{%.*}} to i64
60   // CHECK-PTRAUTH: [[CAST_VTABLE:%.*]] = ptrtoint ptr [[VTABLE:%.*]] to i64
61   // CHECK-PTRAUTH: [[STRIPPED_VTABLE:%.*]] = call i64 @llvm.ptrauth.strip(i64 [[CAST_VTABLE]], i32 0)
62   // CHECK-PTRAUTH: [[STRIPPED_PTR:%.*]] = inttoptr i64 [[STRIPPED_VTABLE]] to ptr
63   // CHECK-PTRAUTH: [[STRIPPED_INT:%.*]] = ptrtoint ptr [[STRIPPED_PTR]] to i64
64   // CHECK-PTRAUTH: {{%.*}} = mul i64 [[STRIPPED_INT]], {{.*}}
65   // CHECK-PTRAUTH: call void @__ubsan_handle_dynamic_type_cache_miss_abort(
66   // Second, we check that vtable is actually loaded once the type check is done.
67   // ptrauth for the virtual function load
68   // CHECK-PTRAUTH: [[VTABLE2:%.*]] = load ptr, ptr {{.*}}
69   // CHECK-PTRAUTH: [[BLENDED:%.*]] = call i64 @llvm.ptrauth.blend(i64 %{{.*}}, i64 17113)
70   // CHECK-PTRAUTH: [[CAST_VTABLE:%.*]] = ptrtoint ptr [[VTABLE2]] to i64
71   // CHECK-PTRAUTH: [[AUTHED_INT:%.*]] = call i64 @llvm.ptrauth.auth(i64 [[CAST_VTABLE]], i32 2, i64 [[BLENDED]])
72   // CHECK-PTRAUTH: [[AUTHED_PTR:%.*]] = inttoptr i64 [[AUTHED_INT]] to ptr
73   // CHECK-PTRAUTH: getelementptr inbounds ptr, ptr
74   // CHECK-PTRAUTH {{%.*}} = getelementptr inbounds ptr, ptr [[AUTHED_PTR]], i64 1
75   delete t;
76 }
77 
78 // ITANIUM: define{{.*}} ptr @_Z7dyncastP1T
79 // MSABI: define dso_local noundef ptr @"?dyncast
80 U* dyncast(T *t) {
81   // First, we check that dynamic_cast is not called before a type check.
82   // CHECK-VPTR-NOT: call ptr @__{{dynamic_cast|RTDynamicCast}}
83   // CHECK-VPTR: br i1 {{.*}} label %{{.*}}
84   // CHECK-PTRAUTH: [[V0:%.*]] = ptrtoint ptr {{%.*}} to i64
85   // CHECK-PTRAUTH: [[BLENDED:%.*]] = call i64 @llvm.ptrauth.blend(i64 [[V0]], i64 17113)
86   // CHECK-PTRAUTH: [[CAST_VTABLE:%.*]] = ptrtoint ptr {{%.*}} to i64
87   // CHECK-PTRAUTH: [[STRIPPED_VTABLE:%.*]] = call i64 @llvm.ptrauth.strip(i64 [[CAST_VTABLE]], i32 0)
88   // CHECK-PTRAUTH: [[STRIPPED_PTR:%.*]] = inttoptr i64 [[STRIPPED_VTABLE]] to ptr
89   // CHECK-PTRAUTH: [[STRIPPED_INT:%.*]] = ptrtoint ptr [[STRIPPED_PTR]] to i64
90   // CHECK-PTRAUTH: {{%.*}} = mul i64 [[STRIPPED_INT]], {{.*}}
91   // CHECK-VPTR: call void @__ubsan_handle_dynamic_type_cache_miss_abort
92   // CHECK-PTRAUTH: [[BLENDED:%.*]] = call i64 @llvm.ptrauth.blend(i64 {{%.*}}, i64 17113)
93   // CHECK-PTRAUTH: [[CAST_VTABLE:%.*]] = ptrtoint ptr %vtable1 to i64
94   // CHECK-PTRAUTH: [[AUTHED_INT:%.*]] = call i64 @llvm.ptrauth.auth(i64 [[CAST_VTABLE]], i32 2, i64 [[BLENDED]])
95   // CHECK-PTRAUTH: [[AUTHED_PTR:%.*]] = inttoptr i64 [[AUTHED_INT]] to ptr
96   // CHECK-PTRAUTH: {{%.*}} = load volatile i8, ptr [[AUTHED_PTR]], align 8
97   // Second, we check that dynamic_cast is actually called once the type check is done.
98   // CHECK-VPTR: call ptr @__{{dynamic_cast|RTDynamicCast}}
99   return dynamic_cast<U*>(t);
100 }
101