From cd2dd3df15523e2be8d2bbace27641d6ac9fa40d Mon Sep 17 00:00:00 2001 From: Dimitry Andric Date: Sun, 22 Feb 2015 22:43:40 +0000 Subject: Import compiler-rt trunk r230183. https://llvm.org/svn/llvm-project/compiler-rt/trunk@230183 --- test/cfi/overwrite.cpp | 67 ++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 67 insertions(+) create mode 100644 test/cfi/overwrite.cpp (limited to 'test/cfi/overwrite.cpp') diff --git a/test/cfi/overwrite.cpp b/test/cfi/overwrite.cpp new file mode 100644 index 000000000000..d7e58d9277e9 --- /dev/null +++ b/test/cfi/overwrite.cpp @@ -0,0 +1,67 @@ +// RUN: %clangxx_cfi -o %t %s +// RUN: not --crash %t 2>&1 | FileCheck --check-prefix=CFI %s + +// RUN: %clangxx_cfi -DB32 -o %t %s +// RUN: not --crash %t 2>&1 | FileCheck --check-prefix=CFI %s + +// RUN: %clangxx_cfi -DB64 -o %t %s +// RUN: not --crash %t 2>&1 | FileCheck --check-prefix=CFI %s + +// RUN: %clangxx_cfi -DBM -o %t %s +// RUN: not --crash %t 2>&1 | FileCheck --check-prefix=CFI %s + +// RUN: %clangxx -o %t %s +// RUN: %t 2>&1 | FileCheck --check-prefix=NCFI %s + +// Tests that the CFI mechanism crashes the program when a virtual table is +// replaced with a compatible table of function pointers that does not belong to +// any class, by manually overwriting the virtual table of an object and +// attempting to make a call through it. + +#include +#include "utils.h" + +struct A { + virtual void f(); +}; + +void A::f() {} + +void foo() { + fprintf(stderr, "foo\n"); +} + +void *fake_vtable[] = { (void *)&foo }; + +int main() { +#ifdef B32 + break_optimization(new Deriver); +#endif + +#ifdef B64 + break_optimization(new Deriver); + break_optimization(new Deriver); +#endif + +#ifdef BM + break_optimization(new Deriver); + break_optimization(new Deriver); + break_optimization(new Deriver); +#endif + + A *a = new A; + *((void **)a) = fake_vtable; // UB here + break_optimization(a); + + // CFI: 1 + // NCFI: 1 + fprintf(stderr, "1\n"); + + // CFI-NOT: foo + // NCFI: foo + a->f(); + + // CFI-NOT: 2 + // NCFI: 2 + fprintf(stderr, "2\n"); +} -- cgit v1.3