1; RUN: opt < %s -msan-check-access-address=0 -S -passes=msan 2>&1 | FileCheck  \
2; RUN: -allow-deprecated-dag-overlap %s
3; RUN: opt < %s -msan -msan-check-access-address=0 -S | FileCheck -allow-deprecated-dag-overlap %s
4; RUN: opt < %s -msan-check-access-address=0 -msan-track-origins=1 -S          \
5; RUN: -passes=msan 2>&1 | FileCheck -allow-deprecated-dag-overlap             \
6; RUN: -check-prefix=CHECK -check-prefix=CHECK-ORIGINS %s
7; RUN: opt < %s -msan -msan-check-access-address=0 -msan-track-origins=1 -S | FileCheck -allow-deprecated-dag-overlap -check-prefix=CHECK -check-prefix=CHECK-ORIGINS %s
8
9target datalayout = "e-p:64:64:64-i1:8:8-i8:8:8-i16:16:16-i32:32:32-i64:64:64-f32:32:32-f64:64:64-v64:64:64-v128:128:128-a0:0:64-s0:64:64-f80:128:128-n8:16:32:64-S128"
10target triple = "x86_64-unknown-linux-gnu"
11
12; CHECK: @llvm.global_ctors {{.*}} { i32 0, void ()* @msan.module_ctor, i8* null }
13
14; Check the presence and the linkage type of __msan_track_origins and
15; other interface symbols.
16; CHECK-NOT: @__msan_track_origins
17; CHECK-ORIGINS: @__msan_track_origins = weak_odr constant i32 1
18; CHECK-NOT: @__msan_keep_going = weak_odr constant i32 0
19; CHECK: @__msan_retval_tls = external thread_local(initialexec) global [{{.*}}]
20; CHECK: @__msan_retval_origin_tls = external thread_local(initialexec) global i32
21; CHECK: @__msan_param_tls = external thread_local(initialexec) global [{{.*}}]
22; CHECK: @__msan_param_origin_tls = external thread_local(initialexec) global [{{.*}}]
23; CHECK: @__msan_va_arg_tls = external thread_local(initialexec) global [{{.*}}]
24; CHECK: @__msan_va_arg_overflow_size_tls = external thread_local(initialexec) global i64
25; CHECK: @__msan_origin_tls = external thread_local(initialexec) global i32
26
27
28; Check instrumentation of stores
29
30define void @Store(i32* nocapture %p, i32 %x) nounwind uwtable sanitize_memory {
31entry:
32  store i32 %x, i32* %p, align 4
33  ret void
34}
35
36; CHECK-LABEL: @Store
37; CHECK: load {{.*}} @__msan_param_tls
38; CHECK-ORIGINS: load {{.*}} @__msan_param_origin_tls
39; CHECK: store
40; CHECK-ORIGINS: icmp
41; CHECK-ORIGINS: br i1
42; CHECK-ORIGINS: {{^[0-9]+}}:
43; CHECK-ORIGINS: store
44; CHECK-ORIGINS: br label
45; CHECK-ORIGINS: {{^[0-9]+}}:
46; CHECK: store
47; CHECK: ret void
48
49
50; Check instrumentation of aligned stores
51; Shadow store has the same alignment as the original store; origin store
52; does not specify explicit alignment.
53
54define void @AlignedStore(i32* nocapture %p, i32 %x) nounwind uwtable sanitize_memory {
55entry:
56  store i32 %x, i32* %p, align 32
57  ret void
58}
59
60; CHECK-LABEL: @AlignedStore
61; CHECK: load {{.*}} @__msan_param_tls
62; CHECK-ORIGINS: load {{.*}} @__msan_param_origin_tls
63; CHECK: store {{.*}} align 32
64; CHECK-ORIGINS: icmp
65; CHECK-ORIGINS: br i1
66; CHECK-ORIGINS: {{^[0-9]+}}:
67; CHECK-ORIGINS: store {{.*}} align 32
68; CHECK-ORIGINS: br label
69; CHECK-ORIGINS: {{^[0-9]+}}:
70; CHECK: store {{.*}} align 32
71; CHECK: ret void
72
73
74; load followed by cmp: check that we load the shadow and call __msan_warning.
75define void @LoadAndCmp(i32* nocapture %a) nounwind uwtable sanitize_memory {
76entry:
77  %0 = load i32, i32* %a, align 4
78  %tobool = icmp eq i32 %0, 0
79  br i1 %tobool, label %if.end, label %if.then
80
81if.then:                                          ; preds = %entry
82  tail call void (...) @foo() nounwind
83  br label %if.end
84
85if.end:                                           ; preds = %entry, %if.then
86  ret void
87}
88
89declare void @foo(...)
90
91; CHECK-LABEL: @LoadAndCmp
92; CHECK: = load
93; CHECK: = load
94; CHECK: call void @__msan_warning_noreturn()
95; CHECK-NEXT: call void asm sideeffect
96; CHECK-NEXT: unreachable
97; CHECK: ret void
98
99; Check that we store the shadow for the retval.
100define i32 @ReturnInt() nounwind uwtable readnone sanitize_memory {
101entry:
102  ret i32 123
103}
104
105; CHECK-LABEL: @ReturnInt
106; CHECK: store i32 0,{{.*}}__msan_retval_tls
107; CHECK: ret i32
108
109; Check that we get the shadow for the retval.
110define void @CopyRetVal(i32* nocapture %a) nounwind uwtable sanitize_memory {
111entry:
112  %call = tail call i32 @ReturnInt() nounwind
113  store i32 %call, i32* %a, align 4
114  ret void
115}
116
117; CHECK-LABEL: @CopyRetVal
118; CHECK: load{{.*}}__msan_retval_tls
119; CHECK: store
120; CHECK: store
121; CHECK: ret void
122
123
124; Check that we generate PHIs for shadow.
125define void @FuncWithPhi(i32* nocapture %a, i32* %b, i32* nocapture %c) nounwind uwtable sanitize_memory {
126entry:
127  %tobool = icmp eq i32* %b, null
128  br i1 %tobool, label %if.else, label %if.then
129
130  if.then:                                          ; preds = %entry
131  %0 = load i32, i32* %b, align 4
132  br label %if.end
133
134  if.else:                                          ; preds = %entry
135  %1 = load i32, i32* %c, align 4
136  br label %if.end
137
138  if.end:                                           ; preds = %if.else, %if.then
139  %t.0 = phi i32 [ %0, %if.then ], [ %1, %if.else ]
140  store i32 %t.0, i32* %a, align 4
141  ret void
142}
143
144; CHECK-LABEL: @FuncWithPhi
145; CHECK: = phi
146; CHECK-NEXT: = phi
147; CHECK: store
148; CHECK: store
149; CHECK: ret void
150
151; Compute shadow for "x << 10"
152define void @ShlConst(i32* nocapture %x) nounwind uwtable sanitize_memory {
153entry:
154  %0 = load i32, i32* %x, align 4
155  %1 = shl i32 %0, 10
156  store i32 %1, i32* %x, align 4
157  ret void
158}
159
160; CHECK-LABEL: @ShlConst
161; CHECK: = load
162; CHECK: = load
163; CHECK: shl
164; CHECK: shl
165; CHECK: store
166; CHECK: store
167; CHECK: ret void
168
169; Compute shadow for "10 << x": it should have 'sext i1'.
170define void @ShlNonConst(i32* nocapture %x) nounwind uwtable sanitize_memory {
171entry:
172  %0 = load i32, i32* %x, align 4
173  %1 = shl i32 10, %0
174  store i32 %1, i32* %x, align 4
175  ret void
176}
177
178; CHECK-LABEL: @ShlNonConst
179; CHECK: = load
180; CHECK: = load
181; CHECK: = sext i1
182; CHECK: store
183; CHECK: store
184; CHECK: ret void
185
186; SExt
187define void @SExt(i32* nocapture %a, i16* nocapture %b) nounwind uwtable sanitize_memory {
188entry:
189  %0 = load i16, i16* %b, align 2
190  %1 = sext i16 %0 to i32
191  store i32 %1, i32* %a, align 4
192  ret void
193}
194
195; CHECK-LABEL: @SExt
196; CHECK: = load
197; CHECK: = load
198; CHECK: = sext
199; CHECK: = sext
200; CHECK: store
201; CHECK: store
202; CHECK: ret void
203
204
205; memset
206define void @MemSet(i8* nocapture %x) nounwind uwtable sanitize_memory {
207entry:
208  call void @llvm.memset.p0i8.i64(i8* %x, i8 42, i64 10, i1 false)
209  ret void
210}
211
212declare void @llvm.memset.p0i8.i64(i8* nocapture, i8, i64, i1) nounwind
213
214; CHECK-LABEL: @MemSet
215; CHECK: call i8* @__msan_memset
216; CHECK: ret void
217
218
219; memcpy
220define void @MemCpy(i8* nocapture %x, i8* nocapture %y) nounwind uwtable sanitize_memory {
221entry:
222  call void @llvm.memcpy.p0i8.p0i8.i64(i8* %x, i8* %y, i64 10, i1 false)
223  ret void
224}
225
226declare void @llvm.memcpy.p0i8.p0i8.i64(i8* nocapture, i8* nocapture, i64, i1) nounwind
227
228; CHECK-LABEL: @MemCpy
229; CHECK: call i8* @__msan_memcpy
230; CHECK: ret void
231
232
233; memmove is lowered to a call
234define void @MemMove(i8* nocapture %x, i8* nocapture %y) nounwind uwtable sanitize_memory {
235entry:
236  call void @llvm.memmove.p0i8.p0i8.i64(i8* %x, i8* %y, i64 10, i1 false)
237  ret void
238}
239
240declare void @llvm.memmove.p0i8.p0i8.i64(i8* nocapture, i8* nocapture, i64, i1) nounwind
241
242; CHECK-LABEL: @MemMove
243; CHECK: call i8* @__msan_memmove
244; CHECK: ret void
245
246;; ------------
247;; Placeholder tests that will fail once element atomic @llvm.mem[cpy|move|set] instrinsics have
248;; been added to the MemIntrinsic class hierarchy. These will act as a reminder to
249;; verify that MSAN handles these intrinsics properly once they have been
250;; added to that class hierarchy.
251declare void @llvm.memset.element.unordered.atomic.p0i8.i64(i8* nocapture writeonly, i8, i64, i32) nounwind
252declare void @llvm.memmove.element.unordered.atomic.p0i8.p0i8.i64(i8* nocapture writeonly, i8* nocapture readonly, i64, i32) nounwind
253declare void @llvm.memcpy.element.unordered.atomic.p0i8.p0i8.i64(i8* nocapture writeonly, i8* nocapture readonly, i64, i32) nounwind
254
255define void @atomic_memcpy(i8* nocapture %x, i8* nocapture %y) nounwind {
256  ; CHECK-LABEL: atomic_memcpy
257  ; CHECK-NEXT: call void @llvm.memcpy.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1)
258  ; CHECK-NEXT: ret void
259  call void @llvm.memcpy.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1)
260  ret void
261}
262
263define void @atomic_memmove(i8* nocapture %x, i8* nocapture %y) nounwind {
264  ; CHECK-LABEL: atomic_memmove
265  ; CHECK-NEXT: call void @llvm.memmove.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1)
266  ; CHECK-NEXT: ret void
267  call void @llvm.memmove.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1)
268  ret void
269}
270
271define void @atomic_memset(i8* nocapture %x) nounwind {
272  ; CHECK-LABEL: atomic_memset
273  ; CHECK-NEXT: call void @llvm.memset.element.unordered.atomic.p0i8.i64(i8* align 1 %x, i8 88, i64 16, i32 1)
274  ; CHECK-NEXT: ret void
275  call void @llvm.memset.element.unordered.atomic.p0i8.i64(i8* align 1 %x, i8 88, i64 16, i32 1)
276  ret void
277}
278
279;; ------------
280
281
282; Check that we propagate shadow for "select"
283
284define i32 @Select(i32 %a, i32 %b, i1 %c) nounwind uwtable readnone sanitize_memory {
285entry:
286  %cond = select i1 %c, i32 %a, i32 %b
287  ret i32 %cond
288}
289
290; CHECK-LABEL: @Select
291; CHECK: select i1
292; CHECK-DAG: or i32
293; CHECK-DAG: xor i32
294; CHECK: or i32
295; CHECK-DAG: select i1
296; CHECK-ORIGINS-DAG: select
297; CHECK-ORIGINS-DAG: select
298; CHECK-DAG: select i1
299; CHECK: store i32{{.*}}@__msan_retval_tls
300; CHECK-ORIGINS: store i32{{.*}}@__msan_retval_origin_tls
301; CHECK: ret i32
302
303
304; Check that we propagate origin for "select" with vector condition.
305; Select condition is flattened to i1, which is then used to select one of the
306; argument origins.
307
308define <8 x i16> @SelectVector(<8 x i16> %a, <8 x i16> %b, <8 x i1> %c) nounwind uwtable readnone sanitize_memory {
309entry:
310  %cond = select <8 x i1> %c, <8 x i16> %a, <8 x i16> %b
311  ret <8 x i16> %cond
312}
313
314; CHECK-LABEL: @SelectVector
315; CHECK: select <8 x i1>
316; CHECK-DAG: or <8 x i16>
317; CHECK-DAG: xor <8 x i16>
318; CHECK: or <8 x i16>
319; CHECK-DAG: select <8 x i1>
320; CHECK-ORIGINS-DAG: select
321; CHECK-ORIGINS-DAG: select
322; CHECK-DAG: select <8 x i1>
323; CHECK: store <8 x i16>{{.*}}@__msan_retval_tls
324; CHECK-ORIGINS: store i32{{.*}}@__msan_retval_origin_tls
325; CHECK: ret <8 x i16>
326
327
328; Check that we propagate origin for "select" with scalar condition and vector
329; arguments. Select condition shadow is sign-extended to the vector type and
330; mixed into the result shadow.
331
332define <8 x i16> @SelectVector2(<8 x i16> %a, <8 x i16> %b, i1 %c) nounwind uwtable readnone sanitize_memory {
333entry:
334  %cond = select i1 %c, <8 x i16> %a, <8 x i16> %b
335  ret <8 x i16> %cond
336}
337
338; CHECK-LABEL: @SelectVector2
339; CHECK: select i1
340; CHECK-DAG: or <8 x i16>
341; CHECK-DAG: xor <8 x i16>
342; CHECK: or <8 x i16>
343; CHECK-DAG: select i1
344; CHECK-ORIGINS-DAG: select i1
345; CHECK-ORIGINS-DAG: select i1
346; CHECK-DAG: select i1
347; CHECK: ret <8 x i16>
348
349
350define { i64, i64 } @SelectStruct(i1 zeroext %x, { i64, i64 } %a, { i64, i64 } %b) readnone sanitize_memory {
351entry:
352  %c = select i1 %x, { i64, i64 } %a, { i64, i64 } %b
353  ret { i64, i64 } %c
354}
355
356; CHECK-LABEL: @SelectStruct
357; CHECK: select i1 {{.*}}, { i64, i64 }
358; CHECK-NEXT: select i1 {{.*}}, { i64, i64 } { i64 -1, i64 -1 }, { i64, i64 }
359; CHECK-ORIGINS: select i1
360; CHECK-ORIGINS: select i1
361; CHECK-NEXT: select i1 {{.*}}, { i64, i64 }
362; CHECK: ret { i64, i64 }
363
364
365define { i64*, double } @SelectStruct2(i1 zeroext %x, { i64*, double } %a, { i64*, double } %b) readnone sanitize_memory {
366entry:
367  %c = select i1 %x, { i64*, double } %a, { i64*, double } %b
368  ret { i64*, double } %c
369}
370
371; CHECK-LABEL: @SelectStruct2
372; CHECK: select i1 {{.*}}, { i64, i64 }
373; CHECK-NEXT: select i1 {{.*}}, { i64, i64 } { i64 -1, i64 -1 }, { i64, i64 }
374; CHECK-ORIGINS: select i1
375; CHECK-ORIGINS: select i1
376; CHECK-NEXT: select i1 {{.*}}, { i64*, double }
377; CHECK: ret { i64*, double }
378
379
380define i8* @IntToPtr(i64 %x) nounwind uwtable readnone sanitize_memory {
381entry:
382  %0 = inttoptr i64 %x to i8*
383  ret i8* %0
384}
385
386; CHECK-LABEL: @IntToPtr
387; CHECK: load i64, i64*{{.*}}__msan_param_tls
388; CHECK-ORIGINS-NEXT: load i32, i32*{{.*}}__msan_param_origin_tls
389; CHECK-NEXT: inttoptr
390; CHECK-NEXT: store i64{{.*}}__msan_retval_tls
391; CHECK: ret i8*
392
393
394define i8* @IntToPtr_ZExt(i16 %x) nounwind uwtable readnone sanitize_memory {
395entry:
396  %0 = inttoptr i16 %x to i8*
397  ret i8* %0
398}
399
400; CHECK-LABEL: @IntToPtr_ZExt
401; CHECK: load i16, i16*{{.*}}__msan_param_tls
402; CHECK: zext
403; CHECK-NEXT: inttoptr
404; CHECK-NEXT: store i64{{.*}}__msan_retval_tls
405; CHECK: ret i8*
406
407
408; Check that we insert exactly one check on udiv
409; (2nd arg shadow is checked, 1st arg shadow is propagated)
410
411define i32 @Div(i32 %a, i32 %b) nounwind uwtable readnone sanitize_memory {
412entry:
413  %div = udiv i32 %a, %b
414  ret i32 %div
415}
416
417; CHECK-LABEL: @Div
418; CHECK: icmp
419; CHECK: call void @__msan_warning
420; CHECK-NOT: icmp
421; CHECK: udiv
422; CHECK-NOT: icmp
423; CHECK: ret i32
424
425; Check that fdiv, unlike udiv, simply propagates shadow.
426
427define float @FDiv(float %a, float %b) nounwind uwtable readnone sanitize_memory {
428entry:
429  %c = fdiv float %a, %b
430  ret float %c
431}
432
433; CHECK-LABEL: @FDiv
434; CHECK: %[[SA:.*]] = load i32,{{.*}}@__msan_param_tls
435; CHECK: %[[SB:.*]] = load i32,{{.*}}@__msan_param_tls
436; CHECK: %[[SC:.*]] = or i32 %[[SB]], %[[SA]]
437; CHECK: = fdiv float
438; CHECK: store i32 %[[SC]], i32* {{.*}}@__msan_retval_tls
439; CHECK: ret float
440
441; Check that we propagate shadow for x<0, x>=0, etc (i.e. sign bit tests)
442
443define zeroext i1 @ICmpSLTZero(i32 %x) nounwind uwtable readnone sanitize_memory {
444  %1 = icmp slt i32 %x, 0
445  ret i1 %1
446}
447
448; CHECK-LABEL: @ICmpSLTZero
449; CHECK: icmp slt
450; CHECK-NOT: call void @__msan_warning
451; CHECK: icmp slt
452; CHECK-NOT: call void @__msan_warning
453; CHECK: ret i1
454
455define zeroext i1 @ICmpSGEZero(i32 %x) nounwind uwtable readnone sanitize_memory {
456  %1 = icmp sge i32 %x, 0
457  ret i1 %1
458}
459
460; CHECK-LABEL: @ICmpSGEZero
461; CHECK: icmp slt
462; CHECK-NOT: call void @__msan_warning
463; CHECK: icmp sge
464; CHECK-NOT: call void @__msan_warning
465; CHECK: ret i1
466
467define zeroext i1 @ICmpSGTZero(i32 %x) nounwind uwtable readnone sanitize_memory {
468  %1 = icmp sgt i32 0, %x
469  ret i1 %1
470}
471
472; CHECK-LABEL: @ICmpSGTZero
473; CHECK: icmp slt
474; CHECK-NOT: call void @__msan_warning
475; CHECK: icmp sgt
476; CHECK-NOT: call void @__msan_warning
477; CHECK: ret i1
478
479define zeroext i1 @ICmpSLEZero(i32 %x) nounwind uwtable readnone sanitize_memory {
480  %1 = icmp sle i32 0, %x
481  ret i1 %1
482}
483
484; CHECK-LABEL: @ICmpSLEZero
485; CHECK: icmp slt
486; CHECK-NOT: call void @__msan_warning
487; CHECK: icmp sle
488; CHECK-NOT: call void @__msan_warning
489; CHECK: ret i1
490
491
492; Check that we propagate shadow for x<=-1, x>-1, etc (i.e. sign bit tests)
493
494define zeroext i1 @ICmpSLTAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory {
495  %1 = icmp slt i32 -1, %x
496  ret i1 %1
497}
498
499; CHECK-LABEL: @ICmpSLTAllOnes
500; CHECK: icmp slt
501; CHECK-NOT: call void @__msan_warning
502; CHECK: icmp slt
503; CHECK-NOT: call void @__msan_warning
504; CHECK: ret i1
505
506define zeroext i1 @ICmpSGEAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory {
507  %1 = icmp sge i32 -1, %x
508  ret i1 %1
509}
510
511; CHECK-LABEL: @ICmpSGEAllOnes
512; CHECK: icmp slt
513; CHECK-NOT: call void @__msan_warning
514; CHECK: icmp sge
515; CHECK-NOT: call void @__msan_warning
516; CHECK: ret i1
517
518define zeroext i1 @ICmpSGTAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory {
519  %1 = icmp sgt i32 %x, -1
520  ret i1 %1
521}
522
523; CHECK-LABEL: @ICmpSGTAllOnes
524; CHECK: icmp slt
525; CHECK-NOT: call void @__msan_warning
526; CHECK: icmp sgt
527; CHECK-NOT: call void @__msan_warning
528; CHECK: ret i1
529
530define zeroext i1 @ICmpSLEAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory {
531  %1 = icmp sle i32 %x, -1
532  ret i1 %1
533}
534
535; CHECK-LABEL: @ICmpSLEAllOnes
536; CHECK: icmp slt
537; CHECK-NOT: call void @__msan_warning
538; CHECK: icmp sle
539; CHECK-NOT: call void @__msan_warning
540; CHECK: ret i1
541
542
543; Check that we propagate shadow for x<0, x>=0, etc (i.e. sign bit tests)
544; of the vector arguments.
545
546define <2 x i1> @ICmpSLT_vector_Zero(<2 x i32*> %x) nounwind uwtable readnone sanitize_memory {
547  %1 = icmp slt <2 x i32*> %x, zeroinitializer
548  ret <2 x i1> %1
549}
550
551; CHECK-LABEL: @ICmpSLT_vector_Zero
552; CHECK: icmp slt <2 x i64>
553; CHECK-NOT: call void @__msan_warning
554; CHECK: icmp slt <2 x i32*>
555; CHECK-NOT: call void @__msan_warning
556; CHECK: ret <2 x i1>
557
558; Check that we propagate shadow for x<=-1, x>0, etc (i.e. sign bit tests)
559; of the vector arguments.
560
561define <2 x i1> @ICmpSLT_vector_AllOnes(<2 x i32> %x) nounwind uwtable readnone sanitize_memory {
562  %1 = icmp slt <2 x i32> <i32 -1, i32 -1>, %x
563  ret <2 x i1> %1
564}
565
566; CHECK-LABEL: @ICmpSLT_vector_AllOnes
567; CHECK: icmp slt <2 x i32>
568; CHECK-NOT: call void @__msan_warning
569; CHECK: icmp slt <2 x i32>
570; CHECK-NOT: call void @__msan_warning
571; CHECK: ret <2 x i1>
572
573
574; Check that we propagate shadow for unsigned relational comparisons with
575; constants
576
577define zeroext i1 @ICmpUGTConst(i32 %x) nounwind uwtable readnone sanitize_memory {
578entry:
579  %cmp = icmp ugt i32 %x, 7
580  ret i1 %cmp
581}
582
583; CHECK-LABEL: @ICmpUGTConst
584; CHECK: icmp ugt i32
585; CHECK-NOT: call void @__msan_warning
586; CHECK: icmp ugt i32
587; CHECK-NOT: call void @__msan_warning
588; CHECK: icmp ugt i32
589; CHECK-NOT: call void @__msan_warning
590; CHECK: ret i1
591
592
593; Check that loads of shadow have the same alignment as the original loads.
594; Check that loads of origin have the alignment of max(4, original alignment).
595
596define i32 @ShadowLoadAlignmentLarge() nounwind uwtable sanitize_memory {
597  %y = alloca i32, align 64
598  %1 = load volatile i32, i32* %y, align 64
599  ret i32 %1
600}
601
602; CHECK-LABEL: @ShadowLoadAlignmentLarge
603; CHECK: load volatile i32, i32* {{.*}} align 64
604; CHECK: load i32, i32* {{.*}} align 64
605; CHECK: ret i32
606
607define i32 @ShadowLoadAlignmentSmall() nounwind uwtable sanitize_memory {
608  %y = alloca i32, align 2
609  %1 = load volatile i32, i32* %y, align 2
610  ret i32 %1
611}
612
613; CHECK-LABEL: @ShadowLoadAlignmentSmall
614; CHECK: load volatile i32, i32* {{.*}} align 2
615; CHECK: load i32, i32* {{.*}} align 2
616; CHECK-ORIGINS: load i32, i32* {{.*}} align 4
617; CHECK: ret i32
618
619
620; Test vector manipulation instructions.
621; Check that the same bit manipulation is applied to the shadow values.
622; Check that there is a zero test of the shadow of %idx argument, where present.
623
624define i32 @ExtractElement(<4 x i32> %vec, i32 %idx) sanitize_memory {
625  %x = extractelement <4 x i32> %vec, i32 %idx
626  ret i32 %x
627}
628
629; CHECK-LABEL: @ExtractElement
630; CHECK: extractelement
631; CHECK: call void @__msan_warning
632; CHECK: extractelement
633; CHECK: ret i32
634
635define <4 x i32> @InsertElement(<4 x i32> %vec, i32 %idx, i32 %x) sanitize_memory {
636  %vec1 = insertelement <4 x i32> %vec, i32 %x, i32 %idx
637  ret <4 x i32> %vec1
638}
639
640; CHECK-LABEL: @InsertElement
641; CHECK: insertelement
642; CHECK: call void @__msan_warning
643; CHECK: insertelement
644; CHECK: ret <4 x i32>
645
646define <4 x i32> @ShuffleVector(<4 x i32> %vec, <4 x i32> %vec1) sanitize_memory {
647  %vec2 = shufflevector <4 x i32> %vec, <4 x i32> %vec1,
648                        <4 x i32> <i32 0, i32 4, i32 1, i32 5>
649  ret <4 x i32> %vec2
650}
651
652; CHECK-LABEL: @ShuffleVector
653; CHECK: shufflevector
654; CHECK-NOT: call void @__msan_warning
655; CHECK: shufflevector
656; CHECK: ret <4 x i32>
657
658
659; Test bswap intrinsic instrumentation
660define i32 @BSwap(i32 %x) nounwind uwtable readnone sanitize_memory {
661  %y = tail call i32 @llvm.bswap.i32(i32 %x)
662  ret i32 %y
663}
664
665declare i32 @llvm.bswap.i32(i32) nounwind readnone
666
667; CHECK-LABEL: @BSwap
668; CHECK-NOT: call void @__msan_warning
669; CHECK: @llvm.bswap.i32
670; CHECK-NOT: call void @__msan_warning
671; CHECK: @llvm.bswap.i32
672; CHECK-NOT: call void @__msan_warning
673; CHECK: ret i32
674
675; Test handling of vectors of pointers.
676; Check that shadow of such vector is a vector of integers.
677
678define <8 x i8*> @VectorOfPointers(<8 x i8*>* %p) nounwind uwtable sanitize_memory {
679  %x = load <8 x i8*>, <8 x i8*>* %p
680  ret <8 x i8*> %x
681}
682
683; CHECK-LABEL: @VectorOfPointers
684; CHECK: load <8 x i8*>, <8 x i8*>*
685; CHECK: load <8 x i64>, <8 x i64>*
686; CHECK: store <8 x i64> {{.*}} @__msan_retval_tls
687; CHECK: ret <8 x i8*>
688
689; Test handling of va_copy.
690
691declare void @llvm.va_copy(i8*, i8*) nounwind
692
693define void @VACopy(i8* %p1, i8* %p2) nounwind uwtable sanitize_memory {
694  call void @llvm.va_copy(i8* %p1, i8* %p2) nounwind
695  ret void
696}
697
698; CHECK-LABEL: @VACopy
699; CHECK: call void @llvm.memset.p0i8.i64({{.*}}, i8 0, i64 24, i1 false)
700; CHECK: ret void
701
702
703; Test that va_start instrumentation does not use va_arg_tls*.
704; It should work with a local stack copy instead.
705
706%struct.__va_list_tag = type { i32, i32, i8*, i8* }
707declare void @llvm.va_start(i8*) nounwind
708
709; Function Attrs: nounwind uwtable
710define void @VAStart(i32 %x, ...) sanitize_memory {
711entry:
712  %x.addr = alloca i32, align 4
713  %va = alloca [1 x %struct.__va_list_tag], align 16
714  store i32 %x, i32* %x.addr, align 4
715  %arraydecay = getelementptr inbounds [1 x %struct.__va_list_tag], [1 x %struct.__va_list_tag]* %va, i32 0, i32 0
716  %arraydecay1 = bitcast %struct.__va_list_tag* %arraydecay to i8*
717  call void @llvm.va_start(i8* %arraydecay1)
718  ret void
719}
720
721; CHECK-LABEL: @VAStart
722; CHECK: call void @llvm.va_start
723; CHECK-NOT: @__msan_va_arg_tls
724; CHECK-NOT: @__msan_va_arg_overflow_size_tls
725; CHECK: ret void
726
727
728; Test handling of volatile stores.
729; Check that MemorySanitizer does not add a check of the value being stored.
730
731define void @VolatileStore(i32* nocapture %p, i32 %x) nounwind uwtable sanitize_memory {
732entry:
733  store volatile i32 %x, i32* %p, align 4
734  ret void
735}
736
737; CHECK-LABEL: @VolatileStore
738; CHECK-NOT: @__msan_warning
739; CHECK: ret void
740
741
742; Test that checks are omitted and returned value is always initialized if
743; sanitize_memory attribute is missing.
744
745define i32 @NoSanitizeMemory(i32 %x) uwtable {
746entry:
747  %tobool = icmp eq i32 %x, 0
748  br i1 %tobool, label %if.end, label %if.then
749
750if.then:                                          ; preds = %entry
751  tail call void @bar()
752  br label %if.end
753
754if.end:                                           ; preds = %entry, %if.then
755  ret i32 %x
756}
757
758declare void @bar()
759
760; CHECK-LABEL: @NoSanitizeMemory
761; CHECK-NOT: @__msan_warning
762; CHECK: store i32 0, {{.*}} @__msan_retval_tls
763; CHECK-NOT: @__msan_warning
764; CHECK: ret i32
765
766
767; Test that stack allocations are unpoisoned in functions missing
768; sanitize_memory attribute
769
770define i32 @NoSanitizeMemoryAlloca() {
771entry:
772  %p = alloca i32, align 4
773  %x = call i32 @NoSanitizeMemoryAllocaHelper(i32* %p)
774  ret i32 %x
775}
776
777declare i32 @NoSanitizeMemoryAllocaHelper(i32* %p)
778
779; CHECK-LABEL: @NoSanitizeMemoryAlloca
780; CHECK: call void @llvm.memset.p0i8.i64(i8* align 4 {{.*}}, i8 0, i64 4, i1 false)
781; CHECK: call i32 @NoSanitizeMemoryAllocaHelper(i32*
782; CHECK: ret i32
783
784
785; Test that undef is unpoisoned in functions missing
786; sanitize_memory attribute
787
788define i32 @NoSanitizeMemoryUndef() {
789entry:
790  %x = call i32 @NoSanitizeMemoryUndefHelper(i32 undef)
791  ret i32 %x
792}
793
794declare i32 @NoSanitizeMemoryUndefHelper(i32 %x)
795
796; CHECK-LABEL: @NoSanitizeMemoryUndef
797; CHECK: store i32 0, i32* {{.*}} @__msan_param_tls
798; CHECK: call i32 @NoSanitizeMemoryUndefHelper(i32 undef)
799; CHECK: ret i32
800
801
802; Test PHINode instrumentation in blacklisted functions
803
804define i32 @NoSanitizeMemoryPHI(i32 %x) {
805entry:
806  %tobool = icmp ne i32 %x, 0
807  br i1 %tobool, label %cond.true, label %cond.false
808
809cond.true:                                        ; preds = %entry
810  br label %cond.end
811
812cond.false:                                       ; preds = %entry
813  br label %cond.end
814
815cond.end:                                         ; preds = %cond.false, %cond.true
816  %cond = phi i32 [ undef, %cond.true ], [ undef, %cond.false ]
817  ret i32 %cond
818}
819
820; CHECK: [[A:%.*]] = phi i32 [ undef, %cond.true ], [ undef, %cond.false ]
821; CHECK: store i32 0, i32* bitcast {{.*}} @__msan_retval_tls
822; CHECK: ret i32 [[A]]
823
824
825; Test that there are no __msan_param_origin_tls stores when
826; argument shadow is a compile-time zero constant (which is always the case
827; in functions missing sanitize_memory attribute).
828
829define i32 @NoSanitizeMemoryParamTLS(i32* nocapture readonly %x) {
830entry:
831  %0 = load i32, i32* %x, align 4
832  %call = tail call i32 @NoSanitizeMemoryParamTLSHelper(i32 %0)
833  ret i32 %call
834}
835
836declare i32 @NoSanitizeMemoryParamTLSHelper(i32 %x)
837
838; CHECK-LABEL: define i32 @NoSanitizeMemoryParamTLS(
839; CHECK-NOT: __msan_param_origin_tls
840; CHECK: ret i32
841
842
843; Test argument shadow alignment
844
845define <2 x i64> @ArgumentShadowAlignment(i64 %a, <2 x i64> %b) sanitize_memory {
846entry:
847  ret <2 x i64> %b
848}
849
850; CHECK-LABEL: @ArgumentShadowAlignment
851; CHECK: load <2 x i64>, <2 x i64>* {{.*}} @__msan_param_tls {{.*}}, align 8
852; CHECK: store <2 x i64> {{.*}} @__msan_retval_tls {{.*}}, align 8
853; CHECK: ret <2 x i64>
854
855
856; Test origin propagation for insertvalue
857
858define { i64, i32 } @make_pair_64_32(i64 %x, i32 %y) sanitize_memory {
859entry:
860  %a = insertvalue { i64, i32 } undef, i64 %x, 0
861  %b = insertvalue { i64, i32 } %a, i32 %y, 1
862  ret { i64, i32 } %b
863}
864
865; CHECK-ORIGINS: @make_pair_64_32
866; First element shadow
867; CHECK-ORIGINS: insertvalue { i64, i32 } { i64 -1, i32 -1 }, i64 {{.*}}, 0
868; First element origin
869; CHECK-ORIGINS: icmp ne i64
870; CHECK-ORIGINS: select i1
871; First element app value
872; CHECK-ORIGINS: insertvalue { i64, i32 } undef, i64 {{.*}}, 0
873; Second element shadow
874; CHECK-ORIGINS: insertvalue { i64, i32 } {{.*}}, i32 {{.*}}, 1
875; Second element origin
876; CHECK-ORIGINS: icmp ne i32
877; CHECK-ORIGINS: select i1
878; Second element app value
879; CHECK-ORIGINS: insertvalue { i64, i32 } {{.*}}, i32 {{.*}}, 1
880; CHECK-ORIGINS: ret { i64, i32 }
881
882
883; Test shadow propagation for aggregates passed through ellipsis.
884
885%struct.StructByVal = type { i32, i32, i32, i32 }
886
887declare void @VAArgStructFn(i32 %guard, ...)
888
889define void @VAArgStruct(%struct.StructByVal* nocapture %s) sanitize_memory {
890entry:
891  %agg.tmp2 = alloca %struct.StructByVal, align 8
892  %0 = bitcast %struct.StructByVal* %s to i8*
893  %agg.tmp.sroa.0.0..sroa_cast = bitcast %struct.StructByVal* %s to i64*
894  %agg.tmp.sroa.0.0.copyload = load i64, i64* %agg.tmp.sroa.0.0..sroa_cast, align 4
895  %agg.tmp.sroa.2.0..sroa_idx = getelementptr inbounds %struct.StructByVal, %struct.StructByVal* %s, i64 0, i32 2
896  %agg.tmp.sroa.2.0..sroa_cast = bitcast i32* %agg.tmp.sroa.2.0..sroa_idx to i64*
897  %agg.tmp.sroa.2.0.copyload = load i64, i64* %agg.tmp.sroa.2.0..sroa_cast, align 4
898  %1 = bitcast %struct.StructByVal* %agg.tmp2 to i8*
899  call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 4 %1, i8* align 4 %0, i64 16, i1 false)
900  call void (i32, ...) @VAArgStructFn(i32 undef, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, %struct.StructByVal* byval align 8 %agg.tmp2)
901  ret void
902}
903
904; "undef" and the first 2 structs go to general purpose registers;
905; the third struct goes to the overflow area byval
906
907; CHECK-LABEL: @VAArgStruct
908; undef not stored to __msan_va_arg_tls - it's a fixed argument
909; first struct through general purpose registers
910; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 8){{.*}}, align 8
911; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 16){{.*}}, align 8
912; second struct through general purpose registers
913; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 24){{.*}}, align 8
914; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 32){{.*}}, align 8
915; third struct through the overflow area byval
916; CHECK: ptrtoint %struct.StructByVal* {{.*}} to i64
917; CHECK: bitcast { i32, i32, i32, i32 }* {{.*}}@__msan_va_arg_tls {{.*}}, i64 176
918; CHECK: call void @llvm.memcpy.p0i8.p0i8.i64
919; CHECK: store i64 16, i64* @__msan_va_arg_overflow_size_tls
920; CHECK: call void (i32, ...) @VAArgStructFn
921; CHECK: ret void
922
923; Same code compiled without SSE (see attributes below).
924; The register save area is only 48 bytes instead of 176.
925define void @VAArgStructNoSSE(%struct.StructByVal* nocapture %s) sanitize_memory #0 {
926entry:
927  %agg.tmp2 = alloca %struct.StructByVal, align 8
928  %0 = bitcast %struct.StructByVal* %s to i8*
929  %agg.tmp.sroa.0.0..sroa_cast = bitcast %struct.StructByVal* %s to i64*
930  %agg.tmp.sroa.0.0.copyload = load i64, i64* %agg.tmp.sroa.0.0..sroa_cast, align 4
931  %agg.tmp.sroa.2.0..sroa_idx = getelementptr inbounds %struct.StructByVal, %struct.StructByVal* %s, i64 0, i32 2
932  %agg.tmp.sroa.2.0..sroa_cast = bitcast i32* %agg.tmp.sroa.2.0..sroa_idx to i64*
933  %agg.tmp.sroa.2.0.copyload = load i64, i64* %agg.tmp.sroa.2.0..sroa_cast, align 4
934  %1 = bitcast %struct.StructByVal* %agg.tmp2 to i8*
935  call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 4 %1, i8* align 4 %0, i64 16, i1 false)
936  call void (i32, ...) @VAArgStructFn(i32 undef, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, %struct.StructByVal* byval align 8 %agg.tmp2)
937  ret void
938}
939
940attributes #0 = { "target-features"="+fxsr,+x87,-sse" }
941
942; CHECK: bitcast { i32, i32, i32, i32 }* {{.*}}@__msan_va_arg_tls {{.*}}, i64 48
943
944declare i32 @InnerTailCall(i32 %a)
945
946define void @MismatchedReturnTypeTailCall(i32 %a) sanitize_memory {
947  %b = tail call i32 @InnerTailCall(i32 %a)
948  ret void
949}
950
951; We used to strip off the 'tail' modifier, but now that we unpoison return slot
952; shadow before the call, we don't need to anymore.
953
954; CHECK-LABEL: define void @MismatchedReturnTypeTailCall
955; CHECK: tail call i32 @InnerTailCall
956; CHECK: ret void
957
958
959declare i32 @MustTailCall(i32 %a)
960
961define i32 @CallMustTailCall(i32 %a) sanitize_memory {
962  %b = musttail call i32 @MustTailCall(i32 %a)
963  ret i32 %b
964}
965
966; For "musttail" calls we can not insert any shadow manipulating code between
967; call and the return instruction. And we don't need to, because everything is
968; taken care of in the callee.
969
970; CHECK-LABEL: define i32 @CallMustTailCall
971; CHECK: musttail call i32 @MustTailCall
972; No instrumentation between call and ret.
973; CHECK-NEXT: ret i32
974
975declare i32* @MismatchingMustTailCall(i32 %a)
976
977define i8* @MismatchingCallMustTailCall(i32 %a) sanitize_memory {
978  %b = musttail call i32* @MismatchingMustTailCall(i32 %a)
979  %c = bitcast i32* %b to i8*
980  ret i8* %c
981}
982
983; For "musttail" calls we can not insert any shadow manipulating code between
984; call and the return instruction. And we don't need to, because everything is
985; taken care of in the callee.
986
987; CHECK-LABEL: define i8* @MismatchingCallMustTailCall
988; CHECK: musttail call i32* @MismatchingMustTailCall
989; No instrumentation between call and ret.
990; CHECK-NEXT: bitcast i32* {{.*}} to i8*
991; CHECK-NEXT: ret i8*
992
993
994; CHECK-LABEL: define internal void @msan.module_ctor() {
995; CHECK: call void @__msan_init()
996