1d21b3d34SFangrui Song // RUN: %clangxx_msan -O0 %s -o %t && %run %t 2>&1
2d21b3d34SFangrui Song // RUN: %clangxx_msan -O3 %s -o %t && %run %t 2>&1
3d21b3d34SFangrui Song 
4d21b3d34SFangrui Song #include <assert.h>
5d21b3d34SFangrui Song #include <errno.h>
6d21b3d34SFangrui Song #include <glob.h>
7d21b3d34SFangrui Song #include <stdio.h>
8d21b3d34SFangrui Song #include <string.h>
9d21b3d34SFangrui Song 
10d21b3d34SFangrui Song #include <linux/aio_abi.h>
11dd921cb8SEvgenii Stepanov #include <signal.h>
12f6f724c0SVitaly Buka #include <sys/epoll.h>
13d21b3d34SFangrui Song #include <sys/ptrace.h>
14d21b3d34SFangrui Song #include <sys/stat.h>
15d21b3d34SFangrui Song #include <sys/uio.h>
16d21b3d34SFangrui Song 
17d21b3d34SFangrui Song #include <sanitizer/linux_syscall_hooks.h>
18d21b3d34SFangrui Song #include <sanitizer/msan_interface.h>
19d21b3d34SFangrui Song 
20d21b3d34SFangrui Song /* Test the presence of __sanitizer_syscall_ in the tool runtime, and general
21d21b3d34SFangrui Song    sanity of their behaviour. */
22d21b3d34SFangrui Song 
main(int argc,char * argv[])23d21b3d34SFangrui Song int main(int argc, char *argv[]) {
24d21b3d34SFangrui Song   char buf[1000] __attribute__((aligned(8)));
25d21b3d34SFangrui Song   const int kTen = 10;
26d21b3d34SFangrui Song   const int kFortyTwo = 42;
27d21b3d34SFangrui Song   memset(buf, 0, sizeof(buf));
28d21b3d34SFangrui Song   __msan_unpoison(buf, sizeof(buf));
29d21b3d34SFangrui Song   __sanitizer_syscall_pre_recvmsg(0, buf, 0);
30d21b3d34SFangrui Song   __sanitizer_syscall_pre_rt_sigpending(buf, kTen);
31d21b3d34SFangrui Song   __sanitizer_syscall_pre_getdents(0, buf, kTen);
32d21b3d34SFangrui Song   __sanitizer_syscall_pre_getdents64(0, buf, kTen);
33d21b3d34SFangrui Song 
34d21b3d34SFangrui Song   __msan_unpoison(buf, sizeof(buf));
35d21b3d34SFangrui Song   __sanitizer_syscall_post_recvmsg(0, 0, buf, 0);
36d21b3d34SFangrui Song   __sanitizer_syscall_post_rt_sigpending(-1, buf, kTen);
37d21b3d34SFangrui Song   __sanitizer_syscall_post_getdents(0, 0, buf, kTen);
38d21b3d34SFangrui Song   __sanitizer_syscall_post_getdents64(0, 0, buf, kTen);
39d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == -1);
40d21b3d34SFangrui Song 
41d21b3d34SFangrui Song   __msan_unpoison(buf, sizeof(buf));
42d21b3d34SFangrui Song   __sanitizer_syscall_post_recvmsg(kTen, 0, buf, 0);
43d21b3d34SFangrui Song 
44d21b3d34SFangrui Song   // Tell the kernel that the output struct size is 10 bytes, verify that those
45d21b3d34SFangrui Song   // bytes are unpoisoned, and the next byte is not.
46d21b3d34SFangrui Song   __msan_poison(buf, kTen + 1);
47d21b3d34SFangrui Song   __sanitizer_syscall_post_rt_sigpending(0, buf, kTen);
48d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == kTen);
49d21b3d34SFangrui Song 
50d21b3d34SFangrui Song   __msan_poison(buf, kTen + 1);
51d21b3d34SFangrui Song   __sanitizer_syscall_post_getdents(kTen, 0, buf, kTen);
52d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == kTen);
53d21b3d34SFangrui Song 
54d21b3d34SFangrui Song   __msan_poison(buf, kTen + 1);
55d21b3d34SFangrui Song   __sanitizer_syscall_post_getdents64(kTen, 0, buf, kTen);
56d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == kTen);
57d21b3d34SFangrui Song 
58d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
59d21b3d34SFangrui Song   __sanitizer_syscall_post_clock_getres(0, 0, buf);
60d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == sizeof(long) * 2);
61d21b3d34SFangrui Song 
62d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
63d21b3d34SFangrui Song   __sanitizer_syscall_post_clock_gettime(0, 0, buf);
64d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == sizeof(long) * 2);
65d21b3d34SFangrui Song 
66d21b3d34SFangrui Song   // Failed syscall does not write to the buffer.
67d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
68d21b3d34SFangrui Song   __sanitizer_syscall_post_clock_gettime(-1, 0, buf);
69d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == 0);
70d21b3d34SFangrui Song 
71d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
72d21b3d34SFangrui Song   __sanitizer_syscall_post_read(5, 42, buf, 10);
73d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == 5);
74d21b3d34SFangrui Song 
75d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
76d21b3d34SFangrui Song   __sanitizer_syscall_post_newfstatat(0, 5, "/path/to/file", buf, 0);
77d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == sizeof(struct stat));
78d21b3d34SFangrui Song 
79d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
80d21b3d34SFangrui Song   int prio = 0;
81d21b3d34SFangrui Song   __sanitizer_syscall_post_mq_timedreceive(kFortyTwo, 5, buf, sizeof(buf), &prio, 0);
82d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == kFortyTwo);
83d21b3d34SFangrui Song   assert(__msan_test_shadow(&prio, sizeof(prio)) == -1);
84d21b3d34SFangrui Song 
85d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
86d21b3d34SFangrui Song   __sanitizer_syscall_post_ptrace(0, PTRACE_PEEKUSER, kFortyTwo, 0xABCD, buf);
87d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == sizeof(void *));
88d21b3d34SFangrui Song 
89d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
90d21b3d34SFangrui Song   struct iocb iocb[3];
91d21b3d34SFangrui Song   struct iocb *iocbp[3] = { &iocb[0], &iocb[1], &iocb[2] };
92d21b3d34SFangrui Song   memset(iocb, 0, sizeof(iocb));
93d21b3d34SFangrui Song   iocb[0].aio_lio_opcode = IOCB_CMD_PREAD;
94d21b3d34SFangrui Song   iocb[0].aio_buf = (__u64)buf;
95d21b3d34SFangrui Song   iocb[0].aio_nbytes = 10;
96d21b3d34SFangrui Song   iocb[1].aio_lio_opcode = IOCB_CMD_PREAD;
97d21b3d34SFangrui Song   iocb[1].aio_buf = (__u64)(&buf[20]);
98d21b3d34SFangrui Song   iocb[1].aio_nbytes = 15;
99d21b3d34SFangrui Song   struct iovec vec[2] = { {&buf[40], 3}, {&buf[50], 20} };
100d21b3d34SFangrui Song   iocb[2].aio_lio_opcode = IOCB_CMD_PREADV;
101d21b3d34SFangrui Song   iocb[2].aio_buf = (__u64)(&vec);
102d21b3d34SFangrui Song   iocb[2].aio_nbytes = 2;
103d21b3d34SFangrui Song   __sanitizer_syscall_pre_io_submit(0, 3, &iocbp);
104d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == 10);
105d21b3d34SFangrui Song   assert(__msan_test_shadow(buf + 20, sizeof(buf) - 20) == 15);
106d21b3d34SFangrui Song   assert(__msan_test_shadow(buf + 40, sizeof(buf) - 40) == 3);
107d21b3d34SFangrui Song   assert(__msan_test_shadow(buf + 50, sizeof(buf) - 50) == 20);
108d21b3d34SFangrui Song 
109d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
110d21b3d34SFangrui Song   char *p = buf;
111d21b3d34SFangrui Song   __msan_poison(&p, sizeof(p));
112d21b3d34SFangrui Song   __sanitizer_syscall_post_io_setup(0, 1, &p);
113d21b3d34SFangrui Song   assert(__msan_test_shadow(&p, sizeof(p)) == -1);
114d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) >= 32);
115d21b3d34SFangrui Song 
116d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
117d21b3d34SFangrui Song   __sanitizer_syscall_post_pipe(0, (int *)buf);
118d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == 2 * sizeof(int));
119d21b3d34SFangrui Song 
120d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
121d21b3d34SFangrui Song   __sanitizer_syscall_post_pipe2(0, (int *)buf, 0);
122d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == 2 * sizeof(int));
123d21b3d34SFangrui Song 
124d21b3d34SFangrui Song   __msan_poison(buf, sizeof(buf));
125d21b3d34SFangrui Song   __sanitizer_syscall_post_socketpair(0, 0, 0, 0, (int *)buf);
126d21b3d34SFangrui Song   assert(__msan_test_shadow(buf, sizeof(buf)) == 2 * sizeof(int));
127d21b3d34SFangrui Song 
128dd921cb8SEvgenii Stepanov   __msan_poison(buf, sizeof(buf));
129dd921cb8SEvgenii Stepanov   __sanitizer_syscall_post_sigaltstack(0, nullptr, (stack_t *)buf);
130dd921cb8SEvgenii Stepanov   assert(__msan_test_shadow(buf, sizeof(buf)) == sizeof(stack_t));
131dd921cb8SEvgenii Stepanov 
132f6f724c0SVitaly Buka   __msan_poison(buf, sizeof(buf));
133f6f724c0SVitaly Buka   long max_events = sizeof(buf) / sizeof(epoll_event);
134f6f724c0SVitaly Buka   __sanitizer_syscall_pre_epoll_wait(0, buf, max_events, 0);
135f6f724c0SVitaly Buka   __sanitizer_syscall_post_epoll_wait(max_events, 0, buf, max_events, 0);
136f6f724c0SVitaly Buka   assert(__msan_test_shadow(buf, sizeof(buf)) == max_events * sizeof(epoll_event));
137f6f724c0SVitaly Buka 
138f6f724c0SVitaly Buka   __msan_poison(buf, sizeof(buf));
139f6f724c0SVitaly Buka   sigset_t sigset = {};
140f6f724c0SVitaly Buka   __sanitizer_syscall_pre_epoll_pwait(0, buf, max_events, 0, &sigset, sizeof(sigset));
141f6f724c0SVitaly Buka   __sanitizer_syscall_post_epoll_pwait(max_events, 0, buf, max_events, 0, &sigset, sizeof(sigset));
142f6f724c0SVitaly Buka   assert(__msan_test_shadow(buf, sizeof(buf)) == max_events * sizeof(epoll_event));
143f6f724c0SVitaly Buka 
144*ecc2c9baSVitaly Buka   __msan_poison(buf, sizeof(buf));
145*ecc2c9baSVitaly Buka   sigset = {};
146*ecc2c9baSVitaly Buka   timespec timespec = {};
147*ecc2c9baSVitaly Buka   __sanitizer_syscall_pre_epoll_pwait2(0, buf, max_events, &timespec,
148*ecc2c9baSVitaly Buka                                        &sigset, sizeof(sigset));
149*ecc2c9baSVitaly Buka   __sanitizer_syscall_post_epoll_pwait2(max_events, 0, buf, max_events,
150*ecc2c9baSVitaly Buka                                         &timespec, &sigset, sizeof(sigset));
151*ecc2c9baSVitaly Buka   assert(__msan_test_shadow(buf, sizeof(buf)) == max_events * sizeof(epoll_event));
152*ecc2c9baSVitaly Buka 
153d21b3d34SFangrui Song   return 0;
154d21b3d34SFangrui Song }
155