1 // Tests for the cfi-vcall feature: 2 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-unknown-linux -fvisibility hidden -fsanitize=cfi-vcall -fsanitize-trap=cfi-vcall -emit-llvm -o - %s | FileCheck --check-prefix=CFI --check-prefix=CFI-NVT --check-prefix=ITANIUM --check-prefix=TT-ITANIUM --check-prefix=NDIAG %s 3 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-unknown-linux -fvisibility hidden -fsanitize=cfi-vcall -emit-llvm -o - %s | FileCheck --check-prefix=CFI --check-prefix=CFI-NVT --check-prefix=ITANIUM --check-prefix=TT-ITANIUM --check-prefix=ITANIUM-DIAG --check-prefix=DIAG --check-prefix=DIAG-ABORT %s 4 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-unknown-linux -fvisibility hidden -fsanitize=cfi-vcall -fsanitize-recover=cfi-vcall -emit-llvm -o - %s | FileCheck --check-prefix=CFI --check-prefix=CFI-NVT --check-prefix=ITANIUM --check-prefix=TT-ITANIUM --check-prefix=ITANIUM-DIAG --check-prefix=DIAG --check-prefix=DIAG-RECOVER %s 5 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-pc-windows-msvc -fsanitize=cfi-vcall -fsanitize-trap=cfi-vcall -emit-llvm -o - %s | FileCheck --check-prefix=CFI --check-prefix=CFI-NVT --check-prefix=MS --check-prefix=TT-MS --check-prefix=NDIAG %s 6 7 // Tests for the whole-program-vtables feature: 8 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-unknown-linux -fvisibility hidden -fwhole-program-vtables -emit-llvm -o - %s | FileCheck --check-prefix=VTABLE-OPT --check-prefix=ITANIUM --check-prefix=TT-ITANIUM %s 9 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-pc-windows-msvc -fwhole-program-vtables -emit-llvm -o - %s | FileCheck --check-prefix=VTABLE-OPT --check-prefix=MS --check-prefix=TT-MS %s 10 11 // Tests for cfi + whole-program-vtables: 12 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-unknown-linux -fvisibility hidden -fsanitize=cfi-vcall -fsanitize-trap=cfi-vcall -fwhole-program-vtables -emit-llvm -o - %s | FileCheck --check-prefix=CFI --check-prefix=CFI-VT --check-prefix=ITANIUM --check-prefix=TC-ITANIUM %s 13 // RUN: %clang_cc1 -flto -flto-unit -triple x86_64-pc-windows-msvc -fsanitize=cfi-vcall -fsanitize-trap=cfi-vcall -fwhole-program-vtables -emit-llvm -o - %s | FileCheck --check-prefix=CFI --check-prefix=CFI-VT --check-prefix=MS --check-prefix=TC-MS %s 14 15 // ITANIUM: @_ZTV1A = {{[^!]*}}, !type [[A16:![0-9]+]] 16 // ITANIUM-DIAG-SAME: !type [[ALL16:![0-9]+]] 17 // ITANIUM-SAME: !type [[AF16:![0-9]+]] 18 19 // ITANIUM: @_ZTV1B = {{[^!]*}}, !type [[A32:![0-9]+]] 20 // ITANIUM-DIAG-SAME: !type [[ALL32:![0-9]+]] 21 // ITANIUM-SAME: !type [[AF32:![0-9]+]] 22 // ITANIUM-SAME: !type [[AF40:![0-9]+]] 23 // ITANIUM-SAME: !type [[AF48:![0-9]+]] 24 // ITANIUM-SAME: !type [[B32:![0-9]+]] 25 // ITANIUM-DIAG-SAME: !type [[ALL32]] 26 // ITANIUM-SAME: !type [[BF32:![0-9]+]] 27 // ITANIUM-SAME: !type [[BF40:![0-9]+]] 28 // ITANIUM-SAME: !type [[BF48:![0-9]+]] 29 30 // ITANIUM: @_ZTV1C = {{[^!]*}}, !type [[A32]] 31 // ITANIUM-DIAG-SAME: !type [[ALL32]] 32 // ITANIUM-SAME: !type [[AF32]] 33 // ITANIUM-SAME: !type [[C32:![0-9]+]] 34 // ITANIUM-DIAG-SAME: !type [[ALL32]] 35 // ITANIUM-SAME: !type [[CF32:![0-9]+]] 36 37 // DIAG: @[[SRC:.*]] = private unnamed_addr constant [{{.*}} x i8] c"{{.*}}type-metadata.cpp\00", align 1 38 // DIAG: @[[TYPE:.*]] = private unnamed_addr constant { i16, i16, [4 x i8] } { i16 -1, i16 0, [4 x i8] c"'A'\00" } 39 // DIAG: @[[BADTYPESTATIC:.*]] = private unnamed_addr global { i8, { [{{.*}} x i8]*, i32, i32 }, { i16, i16, [4 x i8] }* } { i8 0, { [{{.*}} x i8]*, i32, i32 } { [{{.*}} x i8]* @[[SRC]], i32 123, i32 3 }, { i16, i16, [4 x i8] }* @[[TYPE]] } 40 41 // ITANIUM: @_ZTVN12_GLOBAL__N_11DE = {{[^!]*}}, !type [[A32]] 42 // ITANIUM-DIAG-SAME: !type [[ALL32]] 43 // ITANIUM-SAME: !type [[AF32]] 44 // ITANIUM-SAME: !type [[AF40]] 45 // ITANIUM-SAME: !type [[AF48]] 46 // ITANIUM-SAME: !type [[B32]] 47 // ITANIUM-DIAG-SAME: !type [[ALL32]] 48 // ITANIUM-SAME: !type [[BF32]] 49 // ITANIUM-SAME: !type [[BF40]] 50 // ITANIUM-SAME: !type [[BF48]] 51 // ITANIUM-SAME: !type [[C88:![0-9]+]] 52 // ITANIUM-DIAG-SAME: !type [[ALL88:![0-9]+]] 53 // ITANIUM-SAME: !type [[CF32]] 54 // ITANIUM-SAME: !type [[CF40:![0-9]+]] 55 // ITANIUM-SAME: !type [[CF48:![0-9]+]] 56 // ITANIUM-SAME: !type [[D32:![0-9]+]] 57 // ITANIUM-DIAG-SAME: !type [[ALL32]] 58 // ITANIUM-SAME: !type [[DF32:![0-9]+]] 59 // ITANIUM-SAME: !type [[DF40:![0-9]+]] 60 // ITANIUM-SAME: !type [[DF48:![0-9]+]] 61 62 // ITANIUM: @_ZTCN12_GLOBAL__N_11DE0_1B = {{[^!]*}}, !type [[A32]] 63 // ITANIUM-DIAG-SAME: !type [[ALL32]] 64 // ITANIUM-SAME: !type [[B32]] 65 // ITANIUM-DIAG-SAME: !type [[ALL32]] 66 67 // ITANIUM: @_ZTCN12_GLOBAL__N_11DE8_1C = {{[^!]*}}, !type [[A64:![0-9]+]] 68 // ITANIUM-DIAG-SAME: !type [[ALL64:![0-9]+]] 69 // ITANIUM-SAME: !type [[AF64:![0-9]+]] 70 // ITANIUM-SAME: !type [[C32]] 71 // ITANIUM-DIAG-SAME: !type [[ALL32]] 72 // ITANIUM-SAME: !type [[CF64:![0-9]+]] 73 74 // ITANIUM: @_ZTVZ3foovE2FA = {{[^!]*}}, !type [[A16]] 75 // ITANIUM-DIAG-SAME: !type [[ALL16]] 76 // ITANIUM-SAME: !type [[AF16]] 77 // ITANIUM-SAME: !type [[FA16:![0-9]+]] 78 // ITANIUM-DIAG-SAME: !type [[ALL16]] 79 // ITANIUM-SAME: !type [[FAF16:![0-9]+]] 80 81 // MS: comdat($"??_7A@@6B@"), !type [[A8:![0-9]+]] 82 // MS: comdat($"??_7B@@6B0@@"), !type [[B8:![0-9]+]] 83 // MS: comdat($"??_7B@@6BA@@@"), !type [[A8]] 84 // MS: comdat($"??_7C@@6B@"), !type [[A8]] 85 // MS: comdat($"??_7D@?A0x{{[^@]*}}@@6BB@@@"), !type [[B8]], !type [[D8:![0-9]+]] 86 // MS: comdat($"??_7D@?A0x{{[^@]*}}@@6BA@@@"), !type [[A8]] 87 // MS: comdat($"??_7FA@?1??foo@@YAXXZ@6B@"), !type [[A8]], !type [[FA8:![0-9]+]] 88 89 struct A { 90 A(); 91 virtual void f(); 92 }; 93 94 struct B : virtual A { 95 B(); 96 virtual void g(); 97 virtual void h(); 98 }; 99 100 struct C : virtual A { 101 C(); 102 }; 103 104 namespace { 105 106 struct D : B, C { 107 D(); 108 virtual void f(); 109 virtual void h(); 110 }; 111 112 } 113 114 A::A() {} 115 B::B() {} 116 C::C() {} 117 D::D() {} 118 119 void A::f() { 120 } 121 122 void B::g() { 123 } 124 125 void D::f() { 126 } 127 128 void D::h() { 129 } 130 131 // ITANIUM: define hidden void @_Z2afP1A 132 // MS: define dso_local void @"?af@@YAXPEAUA@@@Z" 133 void af(A *a) { 134 // TT-ITANIUM: [[P:%[^ ]*]] = call i1 @llvm.type.test(i8* [[VT:%[^ ]*]], metadata !"_ZTS1A") 135 // TT-MS: [[P:%[^ ]*]] = call i1 @llvm.type.test(i8* [[VT:%[^ ]*]], metadata !"?AUA@@") 136 // TC-ITANIUM: [[PAIR:%[^ ]*]] = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 0, metadata !"_ZTS1A") 137 // TC-MS: [[PAIR:%[^ ]*]] = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 0, metadata !"?AUA@@") 138 // CFI-VT: [[P:%[^ ]*]] = extractvalue { i8*, i1 } [[PAIR]], 1 139 // DIAG-NEXT: [[VTVALID0:%[^ ]*]] = call i1 @llvm.type.test(i8* [[VT]], metadata !"all-vtables") 140 // VTABLE-OPT: call void @llvm.assume(i1 [[P]]) 141 // CFI-NEXT: br i1 [[P]], label %[[CONTBB:[^ ,]*]], label %[[TRAPBB:[^ ,]*]] 142 // CFI-NEXT: {{^$}} 143 144 // CFI: [[TRAPBB]] 145 // NDIAG-NEXT: call void @llvm.trap() 146 // NDIAG-NEXT: unreachable 147 // DIAG-NEXT: [[VTINT:%[^ ]*]] = ptrtoint i8* [[VT]] to i64 148 // DIAG-NEXT: [[VTVALID:%[^ ]*]] = zext i1 [[VTVALID0]] to i64 149 // DIAG-ABORT-NEXT: call void @__ubsan_handle_cfi_check_fail_abort(i8* getelementptr inbounds ({{.*}} @[[BADTYPESTATIC]], i32 0, i32 0), i64 [[VTINT]], i64 [[VTVALID]]) 150 // DIAG-ABORT-NEXT: unreachable 151 // DIAG-RECOVER-NEXT: call void @__ubsan_handle_cfi_check_fail(i8* getelementptr inbounds ({{.*}} @[[BADTYPESTATIC]], i32 0, i32 0), i64 [[VTINT]], i64 [[VTVALID]]) 152 // DIAG-RECOVER-NEXT: br label %[[CONTBB]] 153 154 // CFI: [[CONTBB]] 155 // CFI-NVT: [[PTR:%[^ ]*]] = load 156 // CFI-VT: [[PTRI8:%[^ ]*]] = extractvalue { i8*, i1 } [[PAIR]], 0 157 // CFI-VT: [[PTR:%[^ ]*]] = bitcast i8* [[PTRI8]] to 158 // CFI: call void [[PTR]] 159 #line 123 160 a->f(); 161 } 162 163 // ITANIUM: define internal void @_Z3df1PN12_GLOBAL__N_11DE 164 // MS: define internal void @"?df1@@YAXPEAUD@?A0x{{[^@]*}}@@@Z" 165 void df1(D *d) { 166 // TT-ITANIUM: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata ![[DTYPE:[0-9]+]]) 167 // TT-MS: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata !"?AUA@@") 168 // TC-ITANIUM: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 0, metadata ![[DTYPE:[0-9]+]]) 169 // TC-MS: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 0, metadata !"?AUA@@") 170 d->f(); 171 } 172 173 // ITANIUM: define internal void @_Z3dg1PN12_GLOBAL__N_11DE 174 // MS: define internal void @"?dg1@@YAXPEAUD@?A0x{{[^@]*}}@@@Z" 175 void dg1(D *d) { 176 // TT-ITANIUM: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata !"_ZTS1B") 177 // TT-MS: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata !"?AUB@@") 178 // TC-ITANIUM: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 8, metadata !"_ZTS1B") 179 // TC-MS: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 0, metadata !"?AUB@@") 180 d->g(); 181 } 182 183 // ITANIUM: define internal void @_Z3dh1PN12_GLOBAL__N_11DE 184 // MS: define internal void @"?dh1@@YAXPEAUD@?A0x{{[^@]*}}@@@Z" 185 void dh1(D *d) { 186 // TT-ITANIUM: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata ![[DTYPE]]) 187 // TT-MS: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata ![[DTYPE:[0-9]+]]) 188 // TC-ITANIUM: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 16, metadata ![[DTYPE]]) 189 // TC-MS: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 8, metadata ![[DTYPE:[0-9]+]]) 190 d->h(); 191 } 192 193 // ITANIUM: define internal void @_Z3df2PN12_GLOBAL__N_11DE 194 // MS: define internal void @"?df2@@YAXPEAUD@?A0x{{[^@]*}}@@@Z" 195 __attribute__((no_sanitize("cfi"))) 196 void df2(D *d) { 197 // CFI-NVT-NOT: call i1 @llvm.type.test 198 // CFI-VT: [[P:%[^ ]*]] = call i1 @llvm.type.test 199 // CFI-VT: call void @llvm.assume(i1 [[P]]) 200 d->f(); 201 } 202 203 // ITANIUM: define internal void @_Z3df3PN12_GLOBAL__N_11DE 204 // MS: define internal void @"?df3@@YAXPEAUD@?A0x{{[^@]*}}@@@Z" 205 __attribute__((no_sanitize("address"))) __attribute__((no_sanitize("cfi-vcall"))) 206 void df3(D *d) { 207 // CFI-NVT-NOT: call i1 @llvm.type.test 208 // CFI-VT: [[P:%[^ ]*]] = call i1 @llvm.type.test 209 // CFI-VT: call void @llvm.assume(i1 [[P]]) 210 d->f(); 211 } 212 213 D d; 214 215 void foo() { 216 df1(&d); 217 dg1(&d); 218 dh1(&d); 219 df2(&d); 220 df3(&d); 221 222 struct FA : A { 223 void f() {} 224 } fa; 225 af(&fa); 226 } 227 228 namespace test2 { 229 230 struct A { 231 virtual void m_fn1(); 232 }; 233 struct B { 234 virtual void m_fn2(); 235 }; 236 struct C : B, A {}; 237 struct D : C { 238 void m_fn1(); 239 }; 240 241 // ITANIUM: define hidden void @_ZN5test21fEPNS_1DE 242 // MS: define dso_local void @"?f@test2@@YAXPEAUD@1@@Z" 243 void f(D *d) { 244 // TT-ITANIUM: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata !"_ZTSN5test21DE") 245 // TT-MS: {{%[^ ]*}} = call i1 @llvm.type.test(i8* {{%[^ ]*}}, metadata !"?AUA@test2@@") 246 // TC-ITANIUM: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 8, metadata !"_ZTSN5test21DE") 247 // TC-MS: {{%[^ ]*}} = call { i8*, i1 } @llvm.type.checked.load(i8* {{%[^ ]*}}, i32 0, metadata !"?AUA@test2@@") 248 d->m_fn1(); 249 } 250 251 } 252 253 // ITANIUM: [[A16]] = !{i64 16, !"_ZTS1A"} 254 // ITANIUM-DIAG: [[ALL16]] = !{i64 16, !"all-vtables"} 255 // ITANIUM: [[AF16]] = !{i64 16, !"_ZTSM1AFvvE.virtual"} 256 // ITANIUM: [[A32]] = !{i64 32, !"_ZTS1A"} 257 // ITANIUM-DIAG: [[ALL32]] = !{i64 32, !"all-vtables"} 258 // ITANIUM: [[AF32]] = !{i64 32, !"_ZTSM1AFvvE.virtual"} 259 // ITANIUM: [[AF40]] = !{i64 40, !"_ZTSM1AFvvE.virtual"} 260 // ITANIUM: [[AF48]] = !{i64 48, !"_ZTSM1AFvvE.virtual"} 261 // ITANIUM: [[B32]] = !{i64 32, !"_ZTS1B"} 262 // ITANIUM: [[BF32]] = !{i64 32, !"_ZTSM1BFvvE.virtual"} 263 // ITANIUM: [[BF40]] = !{i64 40, !"_ZTSM1BFvvE.virtual"} 264 // ITANIUM: [[BF48]] = !{i64 48, !"_ZTSM1BFvvE.virtual"} 265 // ITANIUM: [[C32]] = !{i64 32, !"_ZTS1C"} 266 // ITANIUM: [[CF32]] = !{i64 32, !"_ZTSM1CFvvE.virtual"} 267 // ITANIUM: [[C88]] = !{i64 88, !"_ZTS1C"} 268 // ITANIUM-DIAG: [[ALL88]] = !{i64 88, !"all-vtables"} 269 // ITANIUM: [[CF40]] = !{i64 40, !"_ZTSM1CFvvE.virtual"} 270 // ITANIUM: [[CF48]] = !{i64 48, !"_ZTSM1CFvvE.virtual"} 271 // ITANIUM: [[D32]] = !{i64 32, [[D_ID:![0-9]+]]} 272 // ITANIUM: [[D_ID]] = distinct !{} 273 // ITANIUM: [[DF32]] = !{i64 32, [[DF_ID:![0-9]+]]} 274 // ITANIUM: [[DF_ID]] = distinct !{} 275 // ITANIUM: [[DF40]] = !{i64 40, [[DF_ID]]} 276 // ITANIUM: [[DF48]] = !{i64 48, [[DF_ID]]} 277 // ITANIUM: [[A64]] = !{i64 64, !"_ZTS1A"} 278 // ITANIUM-DIAG: [[ALL64]] = !{i64 64, !"all-vtables"} 279 // ITANIUM: [[AF64]] = !{i64 64, !"_ZTSM1AFvvE.virtual"} 280 // ITANIUM: [[CF64]] = !{i64 64, !"_ZTSM1CFvvE.virtual"} 281 // ITANIUM: [[FA16]] = !{i64 16, [[FA_ID:![0-9]+]]} 282 // ITANIUM: [[FA_ID]] = distinct !{} 283 // ITANIUM: [[FAF16]] = !{i64 16, [[FAF_ID:![0-9]+]]} 284 // ITANIUM: [[FAF_ID]] = distinct !{} 285 286 // MS: [[A8]] = !{i64 8, !"?AUA@@"} 287 // MS: [[B8]] = !{i64 8, !"?AUB@@"} 288 // MS: [[D8]] = !{i64 8, [[D_ID:![0-9]+]]} 289 // MS: [[D_ID]] = distinct !{} 290 // MS: [[FA8]] = !{i64 8, [[FA_ID:![0-9]+]]} 291 // MS: [[FA_ID]] = distinct !{} 292