1*673dc3d4SNico Weber // RUN: %clangxx_asan -O0 %s -o %t 2>&1 2*673dc3d4SNico Weber // RUN: not %run %t 2>&1 | FileCheck %s --check-prefix=CHECK --check-prefix=MALLOC-CTX 3*673dc3d4SNico Weber 4*673dc3d4SNico Weber // Also works if no malloc context is available. 5*673dc3d4SNico Weber // RUN: %env_asan_opts=malloc_context_size=0:fast_unwind_on_malloc=0 not %run %t 2>&1 | FileCheck %s 6*673dc3d4SNico Weber // RUN: %env_asan_opts=malloc_context_size=0:fast_unwind_on_malloc=1 not %run %t 2>&1 | FileCheck %s 7*673dc3d4SNico Weber 8*673dc3d4SNico Weber // RUN: %clangxx_asan -O0 -fsanitize-recover=address %s -o %t 2>&1 9*673dc3d4SNico Weber // RUN: %env_asan_opts=halt_on_error=false %run %t 2>&1 | FileCheck %s --check-prefix CHECK-RECOVER 10*673dc3d4SNico Weber // REQUIRES: stable-runtime 11*673dc3d4SNico Weber 12*673dc3d4SNico Weber #include <stdlib.h> 13*673dc3d4SNico Weber #include <string.h> main(int argc,char ** argv)14*673dc3d4SNico Weberint main(int argc, char **argv) { 15*673dc3d4SNico Weber char *x = (char*)malloc(10 * sizeof(char)); 16*673dc3d4SNico Weber memset(x, 0, 10); 17*673dc3d4SNico Weber int res = x[argc]; 18*673dc3d4SNico Weber free(x); 19*673dc3d4SNico Weber free(x + argc - 1); // BOOM 20*673dc3d4SNico Weber // CHECK: AddressSanitizer: attempting double-free{{.*}}in thread T0 21*673dc3d4SNico Weber // CHECK: #0 0x{{.*}} in {{.*}}free 22*673dc3d4SNico Weber // CHECK: #1 0x{{.*}} in main {{.*}}double-free.cpp:[[@LINE-3]] 23*673dc3d4SNico Weber // CHECK: freed by thread T0 here: 24*673dc3d4SNico Weber // MALLOC-CTX: #0 0x{{.*}} in {{.*}}free 25*673dc3d4SNico Weber // MALLOC-CTX: #1 0x{{.*}} in main {{.*}}double-free.cpp:[[@LINE-7]] 26*673dc3d4SNico Weber // CHECK: allocated by thread T0 here: 27*673dc3d4SNico Weber // MALLOC-CTX: double-free.cpp:[[@LINE-12]] 28*673dc3d4SNico Weber // CHECK-RECOVER: AddressSanitizer: attempting double-free{{.*}}in thread T0 29*673dc3d4SNico Weber // CHECK-RECOVER-NOT: AddressSanitizer CHECK failed: 30*673dc3d4SNico Weber return res; 31*673dc3d4SNico Weber } 32