1; RUN: opt < %s -msan-check-access-address=0 -S -passes=msan 2>&1 | FileCheck \ 2; RUN: -allow-deprecated-dag-overlap %s 3; RUN: opt < %s -msan -msan-check-access-address=0 -S | FileCheck -allow-deprecated-dag-overlap %s 4; RUN: opt < %s -msan-check-access-address=0 -msan-track-origins=1 -S \ 5; RUN: -passes=msan 2>&1 | FileCheck -allow-deprecated-dag-overlap \ 6; RUN: -check-prefix=CHECK -check-prefix=CHECK-ORIGINS %s 7; RUN: opt < %s -msan -msan-check-access-address=0 -msan-track-origins=1 -S | FileCheck -allow-deprecated-dag-overlap -check-prefix=CHECK -check-prefix=CHECK-ORIGINS %s 8 9target datalayout = "e-p:64:64:64-i1:8:8-i8:8:8-i16:16:16-i32:32:32-i64:64:64-f32:32:32-f64:64:64-v64:64:64-v128:128:128-a0:0:64-s0:64:64-f80:128:128-n8:16:32:64-S128" 10target triple = "x86_64-unknown-linux-gnu" 11 12; CHECK: @llvm.global_ctors {{.*}} { i32 0, void ()* @msan.module_ctor, i8* null } 13 14; Check the presence and the linkage type of __msan_track_origins and 15; other interface symbols. 16; CHECK-NOT: @__msan_track_origins 17; CHECK-ORIGINS: @__msan_track_origins = weak_odr constant i32 1 18; CHECK-NOT: @__msan_keep_going = weak_odr constant i32 0 19; CHECK: @__msan_retval_tls = external thread_local(initialexec) global [{{.*}}] 20; CHECK: @__msan_retval_origin_tls = external thread_local(initialexec) global i32 21; CHECK: @__msan_param_tls = external thread_local(initialexec) global [{{.*}}] 22; CHECK: @__msan_param_origin_tls = external thread_local(initialexec) global [{{.*}}] 23; CHECK: @__msan_va_arg_tls = external thread_local(initialexec) global [{{.*}}] 24; CHECK: @__msan_va_arg_overflow_size_tls = external thread_local(initialexec) global i64 25; CHECK: @__msan_origin_tls = external thread_local(initialexec) global i32 26 27 28; Check instrumentation of stores 29 30define void @Store(i32* nocapture %p, i32 %x) nounwind uwtable sanitize_memory { 31entry: 32 store i32 %x, i32* %p, align 4 33 ret void 34} 35 36; CHECK-LABEL: @Store 37; CHECK: load {{.*}} @__msan_param_tls 38; CHECK-ORIGINS: load {{.*}} @__msan_param_origin_tls 39; CHECK: store 40; CHECK-ORIGINS: icmp 41; CHECK-ORIGINS: br i1 42; CHECK-ORIGINS: {{^[0-9]+}}: 43; CHECK-ORIGINS: store 44; CHECK-ORIGINS: br label 45; CHECK-ORIGINS: {{^[0-9]+}}: 46; CHECK: store 47; CHECK: ret void 48 49 50; Check instrumentation of aligned stores 51; Shadow store has the same alignment as the original store; origin store 52; does not specify explicit alignment. 53 54define void @AlignedStore(i32* nocapture %p, i32 %x) nounwind uwtable sanitize_memory { 55entry: 56 store i32 %x, i32* %p, align 32 57 ret void 58} 59 60; CHECK-LABEL: @AlignedStore 61; CHECK: load {{.*}} @__msan_param_tls 62; CHECK-ORIGINS: load {{.*}} @__msan_param_origin_tls 63; CHECK: store {{.*}} align 32 64; CHECK-ORIGINS: icmp 65; CHECK-ORIGINS: br i1 66; CHECK-ORIGINS: {{^[0-9]+}}: 67; CHECK-ORIGINS: store {{.*}} align 32 68; CHECK-ORIGINS: br label 69; CHECK-ORIGINS: {{^[0-9]+}}: 70; CHECK: store {{.*}} align 32 71; CHECK: ret void 72 73 74; load followed by cmp: check that we load the shadow and call __msan_warning. 75define void @LoadAndCmp(i32* nocapture %a) nounwind uwtable sanitize_memory { 76entry: 77 %0 = load i32, i32* %a, align 4 78 %tobool = icmp eq i32 %0, 0 79 br i1 %tobool, label %if.end, label %if.then 80 81if.then: ; preds = %entry 82 tail call void (...) @foo() nounwind 83 br label %if.end 84 85if.end: ; preds = %entry, %if.then 86 ret void 87} 88 89declare void @foo(...) 90 91; CHECK-LABEL: @LoadAndCmp 92; CHECK: = load 93; CHECK: = load 94; CHECK: call void @__msan_warning_noreturn() 95; CHECK-NEXT: call void asm sideeffect 96; CHECK-NEXT: unreachable 97; CHECK: ret void 98 99; Check that we store the shadow for the retval. 100define i32 @ReturnInt() nounwind uwtable readnone sanitize_memory { 101entry: 102 ret i32 123 103} 104 105; CHECK-LABEL: @ReturnInt 106; CHECK: store i32 0,{{.*}}__msan_retval_tls 107; CHECK: ret i32 108 109; Check that we get the shadow for the retval. 110define void @CopyRetVal(i32* nocapture %a) nounwind uwtable sanitize_memory { 111entry: 112 %call = tail call i32 @ReturnInt() nounwind 113 store i32 %call, i32* %a, align 4 114 ret void 115} 116 117; CHECK-LABEL: @CopyRetVal 118; CHECK: load{{.*}}__msan_retval_tls 119; CHECK: store 120; CHECK: store 121; CHECK: ret void 122 123 124; Check that we generate PHIs for shadow. 125define void @FuncWithPhi(i32* nocapture %a, i32* %b, i32* nocapture %c) nounwind uwtable sanitize_memory { 126entry: 127 %tobool = icmp eq i32* %b, null 128 br i1 %tobool, label %if.else, label %if.then 129 130 if.then: ; preds = %entry 131 %0 = load i32, i32* %b, align 4 132 br label %if.end 133 134 if.else: ; preds = %entry 135 %1 = load i32, i32* %c, align 4 136 br label %if.end 137 138 if.end: ; preds = %if.else, %if.then 139 %t.0 = phi i32 [ %0, %if.then ], [ %1, %if.else ] 140 store i32 %t.0, i32* %a, align 4 141 ret void 142} 143 144; CHECK-LABEL: @FuncWithPhi 145; CHECK: = phi 146; CHECK-NEXT: = phi 147; CHECK: store 148; CHECK: store 149; CHECK: ret void 150 151; Compute shadow for "x << 10" 152define void @ShlConst(i32* nocapture %x) nounwind uwtable sanitize_memory { 153entry: 154 %0 = load i32, i32* %x, align 4 155 %1 = shl i32 %0, 10 156 store i32 %1, i32* %x, align 4 157 ret void 158} 159 160; CHECK-LABEL: @ShlConst 161; CHECK: = load 162; CHECK: = load 163; CHECK: shl 164; CHECK: shl 165; CHECK: store 166; CHECK: store 167; CHECK: ret void 168 169; Compute shadow for "10 << x": it should have 'sext i1'. 170define void @ShlNonConst(i32* nocapture %x) nounwind uwtable sanitize_memory { 171entry: 172 %0 = load i32, i32* %x, align 4 173 %1 = shl i32 10, %0 174 store i32 %1, i32* %x, align 4 175 ret void 176} 177 178; CHECK-LABEL: @ShlNonConst 179; CHECK: = load 180; CHECK: = load 181; CHECK: = sext i1 182; CHECK: store 183; CHECK: store 184; CHECK: ret void 185 186; SExt 187define void @SExt(i32* nocapture %a, i16* nocapture %b) nounwind uwtable sanitize_memory { 188entry: 189 %0 = load i16, i16* %b, align 2 190 %1 = sext i16 %0 to i32 191 store i32 %1, i32* %a, align 4 192 ret void 193} 194 195; CHECK-LABEL: @SExt 196; CHECK: = load 197; CHECK: = load 198; CHECK: = sext 199; CHECK: = sext 200; CHECK: store 201; CHECK: store 202; CHECK: ret void 203 204 205; memset 206define void @MemSet(i8* nocapture %x) nounwind uwtable sanitize_memory { 207entry: 208 call void @llvm.memset.p0i8.i64(i8* %x, i8 42, i64 10, i1 false) 209 ret void 210} 211 212declare void @llvm.memset.p0i8.i64(i8* nocapture, i8, i64, i1) nounwind 213 214; CHECK-LABEL: @MemSet 215; CHECK: call i8* @__msan_memset 216; CHECK: ret void 217 218 219; memcpy 220define void @MemCpy(i8* nocapture %x, i8* nocapture %y) nounwind uwtable sanitize_memory { 221entry: 222 call void @llvm.memcpy.p0i8.p0i8.i64(i8* %x, i8* %y, i64 10, i1 false) 223 ret void 224} 225 226declare void @llvm.memcpy.p0i8.p0i8.i64(i8* nocapture, i8* nocapture, i64, i1) nounwind 227 228; CHECK-LABEL: @MemCpy 229; CHECK: call i8* @__msan_memcpy 230; CHECK: ret void 231 232 233; memmove is lowered to a call 234define void @MemMove(i8* nocapture %x, i8* nocapture %y) nounwind uwtable sanitize_memory { 235entry: 236 call void @llvm.memmove.p0i8.p0i8.i64(i8* %x, i8* %y, i64 10, i1 false) 237 ret void 238} 239 240declare void @llvm.memmove.p0i8.p0i8.i64(i8* nocapture, i8* nocapture, i64, i1) nounwind 241 242; CHECK-LABEL: @MemMove 243; CHECK: call i8* @__msan_memmove 244; CHECK: ret void 245 246;; ------------ 247;; Placeholder tests that will fail once element atomic @llvm.mem[cpy|move|set] instrinsics have 248;; been added to the MemIntrinsic class hierarchy. These will act as a reminder to 249;; verify that MSAN handles these intrinsics properly once they have been 250;; added to that class hierarchy. 251declare void @llvm.memset.element.unordered.atomic.p0i8.i64(i8* nocapture writeonly, i8, i64, i32) nounwind 252declare void @llvm.memmove.element.unordered.atomic.p0i8.p0i8.i64(i8* nocapture writeonly, i8* nocapture readonly, i64, i32) nounwind 253declare void @llvm.memcpy.element.unordered.atomic.p0i8.p0i8.i64(i8* nocapture writeonly, i8* nocapture readonly, i64, i32) nounwind 254 255define void @atomic_memcpy(i8* nocapture %x, i8* nocapture %y) nounwind { 256 ; CHECK-LABEL: atomic_memcpy 257 ; CHECK-NEXT: call void @llvm.memcpy.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1) 258 ; CHECK-NEXT: ret void 259 call void @llvm.memcpy.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1) 260 ret void 261} 262 263define void @atomic_memmove(i8* nocapture %x, i8* nocapture %y) nounwind { 264 ; CHECK-LABEL: atomic_memmove 265 ; CHECK-NEXT: call void @llvm.memmove.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1) 266 ; CHECK-NEXT: ret void 267 call void @llvm.memmove.element.unordered.atomic.p0i8.p0i8.i64(i8* align 1 %x, i8* align 2 %y, i64 16, i32 1) 268 ret void 269} 270 271define void @atomic_memset(i8* nocapture %x) nounwind { 272 ; CHECK-LABEL: atomic_memset 273 ; CHECK-NEXT: call void @llvm.memset.element.unordered.atomic.p0i8.i64(i8* align 1 %x, i8 88, i64 16, i32 1) 274 ; CHECK-NEXT: ret void 275 call void @llvm.memset.element.unordered.atomic.p0i8.i64(i8* align 1 %x, i8 88, i64 16, i32 1) 276 ret void 277} 278 279;; ------------ 280 281 282; Check that we propagate shadow for "select" 283 284define i32 @Select(i32 %a, i32 %b, i1 %c) nounwind uwtable readnone sanitize_memory { 285entry: 286 %cond = select i1 %c, i32 %a, i32 %b 287 ret i32 %cond 288} 289 290; CHECK-LABEL: @Select 291; CHECK: select i1 292; CHECK-DAG: or i32 293; CHECK-DAG: xor i32 294; CHECK: or i32 295; CHECK-DAG: select i1 296; CHECK-ORIGINS-DAG: select 297; CHECK-ORIGINS-DAG: select 298; CHECK-DAG: select i1 299; CHECK: store i32{{.*}}@__msan_retval_tls 300; CHECK-ORIGINS: store i32{{.*}}@__msan_retval_origin_tls 301; CHECK: ret i32 302 303 304; Check that we propagate origin for "select" with vector condition. 305; Select condition is flattened to i1, which is then used to select one of the 306; argument origins. 307 308define <8 x i16> @SelectVector(<8 x i16> %a, <8 x i16> %b, <8 x i1> %c) nounwind uwtable readnone sanitize_memory { 309entry: 310 %cond = select <8 x i1> %c, <8 x i16> %a, <8 x i16> %b 311 ret <8 x i16> %cond 312} 313 314; CHECK-LABEL: @SelectVector 315; CHECK: select <8 x i1> 316; CHECK-DAG: or <8 x i16> 317; CHECK-DAG: xor <8 x i16> 318; CHECK: or <8 x i16> 319; CHECK-DAG: select <8 x i1> 320; CHECK-ORIGINS-DAG: select 321; CHECK-ORIGINS-DAG: select 322; CHECK-DAG: select <8 x i1> 323; CHECK: store <8 x i16>{{.*}}@__msan_retval_tls 324; CHECK-ORIGINS: store i32{{.*}}@__msan_retval_origin_tls 325; CHECK: ret <8 x i16> 326 327 328; Check that we propagate origin for "select" with scalar condition and vector 329; arguments. Select condition shadow is sign-extended to the vector type and 330; mixed into the result shadow. 331 332define <8 x i16> @SelectVector2(<8 x i16> %a, <8 x i16> %b, i1 %c) nounwind uwtable readnone sanitize_memory { 333entry: 334 %cond = select i1 %c, <8 x i16> %a, <8 x i16> %b 335 ret <8 x i16> %cond 336} 337 338; CHECK-LABEL: @SelectVector2 339; CHECK: select i1 340; CHECK-DAG: or <8 x i16> 341; CHECK-DAG: xor <8 x i16> 342; CHECK: or <8 x i16> 343; CHECK-DAG: select i1 344; CHECK-ORIGINS-DAG: select i1 345; CHECK-ORIGINS-DAG: select i1 346; CHECK-DAG: select i1 347; CHECK: ret <8 x i16> 348 349 350define { i64, i64 } @SelectStruct(i1 zeroext %x, { i64, i64 } %a, { i64, i64 } %b) readnone sanitize_memory { 351entry: 352 %c = select i1 %x, { i64, i64 } %a, { i64, i64 } %b 353 ret { i64, i64 } %c 354} 355 356; CHECK-LABEL: @SelectStruct 357; CHECK: select i1 {{.*}}, { i64, i64 } 358; CHECK-NEXT: select i1 {{.*}}, { i64, i64 } { i64 -1, i64 -1 }, { i64, i64 } 359; CHECK-ORIGINS: select i1 360; CHECK-ORIGINS: select i1 361; CHECK-NEXT: select i1 {{.*}}, { i64, i64 } 362; CHECK: ret { i64, i64 } 363 364 365define { i64*, double } @SelectStruct2(i1 zeroext %x, { i64*, double } %a, { i64*, double } %b) readnone sanitize_memory { 366entry: 367 %c = select i1 %x, { i64*, double } %a, { i64*, double } %b 368 ret { i64*, double } %c 369} 370 371; CHECK-LABEL: @SelectStruct2 372; CHECK: select i1 {{.*}}, { i64, i64 } 373; CHECK-NEXT: select i1 {{.*}}, { i64, i64 } { i64 -1, i64 -1 }, { i64, i64 } 374; CHECK-ORIGINS: select i1 375; CHECK-ORIGINS: select i1 376; CHECK-NEXT: select i1 {{.*}}, { i64*, double } 377; CHECK: ret { i64*, double } 378 379 380define i8* @IntToPtr(i64 %x) nounwind uwtable readnone sanitize_memory { 381entry: 382 %0 = inttoptr i64 %x to i8* 383 ret i8* %0 384} 385 386; CHECK-LABEL: @IntToPtr 387; CHECK: load i64, i64*{{.*}}__msan_param_tls 388; CHECK-ORIGINS-NEXT: load i32, i32*{{.*}}__msan_param_origin_tls 389; CHECK-NEXT: inttoptr 390; CHECK-NEXT: store i64{{.*}}__msan_retval_tls 391; CHECK: ret i8* 392 393 394define i8* @IntToPtr_ZExt(i16 %x) nounwind uwtable readnone sanitize_memory { 395entry: 396 %0 = inttoptr i16 %x to i8* 397 ret i8* %0 398} 399 400; CHECK-LABEL: @IntToPtr_ZExt 401; CHECK: load i16, i16*{{.*}}__msan_param_tls 402; CHECK: zext 403; CHECK-NEXT: inttoptr 404; CHECK-NEXT: store i64{{.*}}__msan_retval_tls 405; CHECK: ret i8* 406 407 408; Check that we insert exactly one check on udiv 409; (2nd arg shadow is checked, 1st arg shadow is propagated) 410 411define i32 @Div(i32 %a, i32 %b) nounwind uwtable readnone sanitize_memory { 412entry: 413 %div = udiv i32 %a, %b 414 ret i32 %div 415} 416 417; CHECK-LABEL: @Div 418; CHECK: icmp 419; CHECK: call void @__msan_warning 420; CHECK-NOT: icmp 421; CHECK: udiv 422; CHECK-NOT: icmp 423; CHECK: ret i32 424 425; Check that fdiv, unlike udiv, simply propagates shadow. 426 427define float @FDiv(float %a, float %b) nounwind uwtable readnone sanitize_memory { 428entry: 429 %c = fdiv float %a, %b 430 ret float %c 431} 432 433; CHECK-LABEL: @FDiv 434; CHECK: %[[SA:.*]] = load i32,{{.*}}@__msan_param_tls 435; CHECK: %[[SB:.*]] = load i32,{{.*}}@__msan_param_tls 436; CHECK: %[[SC:.*]] = or i32 %[[SB]], %[[SA]] 437; CHECK: = fdiv float 438; CHECK: store i32 %[[SC]], i32* {{.*}}@__msan_retval_tls 439; CHECK: ret float 440 441; Check that we propagate shadow for x<0, x>=0, etc (i.e. sign bit tests) 442 443define zeroext i1 @ICmpSLTZero(i32 %x) nounwind uwtable readnone sanitize_memory { 444 %1 = icmp slt i32 %x, 0 445 ret i1 %1 446} 447 448; CHECK-LABEL: @ICmpSLTZero 449; CHECK: icmp slt 450; CHECK-NOT: call void @__msan_warning 451; CHECK: icmp slt 452; CHECK-NOT: call void @__msan_warning 453; CHECK: ret i1 454 455define zeroext i1 @ICmpSGEZero(i32 %x) nounwind uwtable readnone sanitize_memory { 456 %1 = icmp sge i32 %x, 0 457 ret i1 %1 458} 459 460; CHECK-LABEL: @ICmpSGEZero 461; CHECK: icmp slt 462; CHECK-NOT: call void @__msan_warning 463; CHECK: icmp sge 464; CHECK-NOT: call void @__msan_warning 465; CHECK: ret i1 466 467define zeroext i1 @ICmpSGTZero(i32 %x) nounwind uwtable readnone sanitize_memory { 468 %1 = icmp sgt i32 0, %x 469 ret i1 %1 470} 471 472; CHECK-LABEL: @ICmpSGTZero 473; CHECK: icmp slt 474; CHECK-NOT: call void @__msan_warning 475; CHECK: icmp sgt 476; CHECK-NOT: call void @__msan_warning 477; CHECK: ret i1 478 479define zeroext i1 @ICmpSLEZero(i32 %x) nounwind uwtable readnone sanitize_memory { 480 %1 = icmp sle i32 0, %x 481 ret i1 %1 482} 483 484; CHECK-LABEL: @ICmpSLEZero 485; CHECK: icmp slt 486; CHECK-NOT: call void @__msan_warning 487; CHECK: icmp sle 488; CHECK-NOT: call void @__msan_warning 489; CHECK: ret i1 490 491 492; Check that we propagate shadow for x<=-1, x>-1, etc (i.e. sign bit tests) 493 494define zeroext i1 @ICmpSLTAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory { 495 %1 = icmp slt i32 -1, %x 496 ret i1 %1 497} 498 499; CHECK-LABEL: @ICmpSLTAllOnes 500; CHECK: icmp slt 501; CHECK-NOT: call void @__msan_warning 502; CHECK: icmp slt 503; CHECK-NOT: call void @__msan_warning 504; CHECK: ret i1 505 506define zeroext i1 @ICmpSGEAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory { 507 %1 = icmp sge i32 -1, %x 508 ret i1 %1 509} 510 511; CHECK-LABEL: @ICmpSGEAllOnes 512; CHECK: icmp slt 513; CHECK-NOT: call void @__msan_warning 514; CHECK: icmp sge 515; CHECK-NOT: call void @__msan_warning 516; CHECK: ret i1 517 518define zeroext i1 @ICmpSGTAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory { 519 %1 = icmp sgt i32 %x, -1 520 ret i1 %1 521} 522 523; CHECK-LABEL: @ICmpSGTAllOnes 524; CHECK: icmp slt 525; CHECK-NOT: call void @__msan_warning 526; CHECK: icmp sgt 527; CHECK-NOT: call void @__msan_warning 528; CHECK: ret i1 529 530define zeroext i1 @ICmpSLEAllOnes(i32 %x) nounwind uwtable readnone sanitize_memory { 531 %1 = icmp sle i32 %x, -1 532 ret i1 %1 533} 534 535; CHECK-LABEL: @ICmpSLEAllOnes 536; CHECK: icmp slt 537; CHECK-NOT: call void @__msan_warning 538; CHECK: icmp sle 539; CHECK-NOT: call void @__msan_warning 540; CHECK: ret i1 541 542 543; Check that we propagate shadow for x<0, x>=0, etc (i.e. sign bit tests) 544; of the vector arguments. 545 546define <2 x i1> @ICmpSLT_vector_Zero(<2 x i32*> %x) nounwind uwtable readnone sanitize_memory { 547 %1 = icmp slt <2 x i32*> %x, zeroinitializer 548 ret <2 x i1> %1 549} 550 551; CHECK-LABEL: @ICmpSLT_vector_Zero 552; CHECK: icmp slt <2 x i64> 553; CHECK-NOT: call void @__msan_warning 554; CHECK: icmp slt <2 x i32*> 555; CHECK-NOT: call void @__msan_warning 556; CHECK: ret <2 x i1> 557 558; Check that we propagate shadow for x<=-1, x>0, etc (i.e. sign bit tests) 559; of the vector arguments. 560 561define <2 x i1> @ICmpSLT_vector_AllOnes(<2 x i32> %x) nounwind uwtable readnone sanitize_memory { 562 %1 = icmp slt <2 x i32> <i32 -1, i32 -1>, %x 563 ret <2 x i1> %1 564} 565 566; CHECK-LABEL: @ICmpSLT_vector_AllOnes 567; CHECK: icmp slt <2 x i32> 568; CHECK-NOT: call void @__msan_warning 569; CHECK: icmp slt <2 x i32> 570; CHECK-NOT: call void @__msan_warning 571; CHECK: ret <2 x i1> 572 573 574; Check that we propagate shadow for unsigned relational comparisons with 575; constants 576 577define zeroext i1 @ICmpUGTConst(i32 %x) nounwind uwtable readnone sanitize_memory { 578entry: 579 %cmp = icmp ugt i32 %x, 7 580 ret i1 %cmp 581} 582 583; CHECK-LABEL: @ICmpUGTConst 584; CHECK: icmp ugt i32 585; CHECK-NOT: call void @__msan_warning 586; CHECK: icmp ugt i32 587; CHECK-NOT: call void @__msan_warning 588; CHECK: icmp ugt i32 589; CHECK-NOT: call void @__msan_warning 590; CHECK: ret i1 591 592 593; Check that loads of shadow have the same alignment as the original loads. 594; Check that loads of origin have the alignment of max(4, original alignment). 595 596define i32 @ShadowLoadAlignmentLarge() nounwind uwtable sanitize_memory { 597 %y = alloca i32, align 64 598 %1 = load volatile i32, i32* %y, align 64 599 ret i32 %1 600} 601 602; CHECK-LABEL: @ShadowLoadAlignmentLarge 603; CHECK: load volatile i32, i32* {{.*}} align 64 604; CHECK: load i32, i32* {{.*}} align 64 605; CHECK: ret i32 606 607define i32 @ShadowLoadAlignmentSmall() nounwind uwtable sanitize_memory { 608 %y = alloca i32, align 2 609 %1 = load volatile i32, i32* %y, align 2 610 ret i32 %1 611} 612 613; CHECK-LABEL: @ShadowLoadAlignmentSmall 614; CHECK: load volatile i32, i32* {{.*}} align 2 615; CHECK: load i32, i32* {{.*}} align 2 616; CHECK-ORIGINS: load i32, i32* {{.*}} align 4 617; CHECK: ret i32 618 619 620; Test vector manipulation instructions. 621; Check that the same bit manipulation is applied to the shadow values. 622; Check that there is a zero test of the shadow of %idx argument, where present. 623 624define i32 @ExtractElement(<4 x i32> %vec, i32 %idx) sanitize_memory { 625 %x = extractelement <4 x i32> %vec, i32 %idx 626 ret i32 %x 627} 628 629; CHECK-LABEL: @ExtractElement 630; CHECK: extractelement 631; CHECK: call void @__msan_warning 632; CHECK: extractelement 633; CHECK: ret i32 634 635define <4 x i32> @InsertElement(<4 x i32> %vec, i32 %idx, i32 %x) sanitize_memory { 636 %vec1 = insertelement <4 x i32> %vec, i32 %x, i32 %idx 637 ret <4 x i32> %vec1 638} 639 640; CHECK-LABEL: @InsertElement 641; CHECK: insertelement 642; CHECK: call void @__msan_warning 643; CHECK: insertelement 644; CHECK: ret <4 x i32> 645 646define <4 x i32> @ShuffleVector(<4 x i32> %vec, <4 x i32> %vec1) sanitize_memory { 647 %vec2 = shufflevector <4 x i32> %vec, <4 x i32> %vec1, 648 <4 x i32> <i32 0, i32 4, i32 1, i32 5> 649 ret <4 x i32> %vec2 650} 651 652; CHECK-LABEL: @ShuffleVector 653; CHECK: shufflevector 654; CHECK-NOT: call void @__msan_warning 655; CHECK: shufflevector 656; CHECK: ret <4 x i32> 657 658 659; Test bswap intrinsic instrumentation 660define i32 @BSwap(i32 %x) nounwind uwtable readnone sanitize_memory { 661 %y = tail call i32 @llvm.bswap.i32(i32 %x) 662 ret i32 %y 663} 664 665declare i32 @llvm.bswap.i32(i32) nounwind readnone 666 667; CHECK-LABEL: @BSwap 668; CHECK-NOT: call void @__msan_warning 669; CHECK: @llvm.bswap.i32 670; CHECK-NOT: call void @__msan_warning 671; CHECK: @llvm.bswap.i32 672; CHECK-NOT: call void @__msan_warning 673; CHECK: ret i32 674 675; Test handling of vectors of pointers. 676; Check that shadow of such vector is a vector of integers. 677 678define <8 x i8*> @VectorOfPointers(<8 x i8*>* %p) nounwind uwtable sanitize_memory { 679 %x = load <8 x i8*>, <8 x i8*>* %p 680 ret <8 x i8*> %x 681} 682 683; CHECK-LABEL: @VectorOfPointers 684; CHECK: load <8 x i8*>, <8 x i8*>* 685; CHECK: load <8 x i64>, <8 x i64>* 686; CHECK: store <8 x i64> {{.*}} @__msan_retval_tls 687; CHECK: ret <8 x i8*> 688 689; Test handling of va_copy. 690 691declare void @llvm.va_copy(i8*, i8*) nounwind 692 693define void @VACopy(i8* %p1, i8* %p2) nounwind uwtable sanitize_memory { 694 call void @llvm.va_copy(i8* %p1, i8* %p2) nounwind 695 ret void 696} 697 698; CHECK-LABEL: @VACopy 699; CHECK: call void @llvm.memset.p0i8.i64({{.*}}, i8 0, i64 24, i1 false) 700; CHECK: ret void 701 702 703; Test that va_start instrumentation does not use va_arg_tls*. 704; It should work with a local stack copy instead. 705 706%struct.__va_list_tag = type { i32, i32, i8*, i8* } 707declare void @llvm.va_start(i8*) nounwind 708 709; Function Attrs: nounwind uwtable 710define void @VAStart(i32 %x, ...) sanitize_memory { 711entry: 712 %x.addr = alloca i32, align 4 713 %va = alloca [1 x %struct.__va_list_tag], align 16 714 store i32 %x, i32* %x.addr, align 4 715 %arraydecay = getelementptr inbounds [1 x %struct.__va_list_tag], [1 x %struct.__va_list_tag]* %va, i32 0, i32 0 716 %arraydecay1 = bitcast %struct.__va_list_tag* %arraydecay to i8* 717 call void @llvm.va_start(i8* %arraydecay1) 718 ret void 719} 720 721; CHECK-LABEL: @VAStart 722; CHECK: call void @llvm.va_start 723; CHECK-NOT: @__msan_va_arg_tls 724; CHECK-NOT: @__msan_va_arg_overflow_size_tls 725; CHECK: ret void 726 727 728; Test handling of volatile stores. 729; Check that MemorySanitizer does not add a check of the value being stored. 730 731define void @VolatileStore(i32* nocapture %p, i32 %x) nounwind uwtable sanitize_memory { 732entry: 733 store volatile i32 %x, i32* %p, align 4 734 ret void 735} 736 737; CHECK-LABEL: @VolatileStore 738; CHECK-NOT: @__msan_warning 739; CHECK: ret void 740 741 742; Test that checks are omitted and returned value is always initialized if 743; sanitize_memory attribute is missing. 744 745define i32 @NoSanitizeMemory(i32 %x) uwtable { 746entry: 747 %tobool = icmp eq i32 %x, 0 748 br i1 %tobool, label %if.end, label %if.then 749 750if.then: ; preds = %entry 751 tail call void @bar() 752 br label %if.end 753 754if.end: ; preds = %entry, %if.then 755 ret i32 %x 756} 757 758declare void @bar() 759 760; CHECK-LABEL: @NoSanitizeMemory 761; CHECK-NOT: @__msan_warning 762; CHECK: store i32 0, {{.*}} @__msan_retval_tls 763; CHECK-NOT: @__msan_warning 764; CHECK: ret i32 765 766 767; Test that stack allocations are unpoisoned in functions missing 768; sanitize_memory attribute 769 770define i32 @NoSanitizeMemoryAlloca() { 771entry: 772 %p = alloca i32, align 4 773 %x = call i32 @NoSanitizeMemoryAllocaHelper(i32* %p) 774 ret i32 %x 775} 776 777declare i32 @NoSanitizeMemoryAllocaHelper(i32* %p) 778 779; CHECK-LABEL: @NoSanitizeMemoryAlloca 780; CHECK: call void @llvm.memset.p0i8.i64(i8* align 4 {{.*}}, i8 0, i64 4, i1 false) 781; CHECK: call i32 @NoSanitizeMemoryAllocaHelper(i32* 782; CHECK: ret i32 783 784 785; Test that undef is unpoisoned in functions missing 786; sanitize_memory attribute 787 788define i32 @NoSanitizeMemoryUndef() { 789entry: 790 %x = call i32 @NoSanitizeMemoryUndefHelper(i32 undef) 791 ret i32 %x 792} 793 794declare i32 @NoSanitizeMemoryUndefHelper(i32 %x) 795 796; CHECK-LABEL: @NoSanitizeMemoryUndef 797; CHECK: store i32 0, i32* {{.*}} @__msan_param_tls 798; CHECK: call i32 @NoSanitizeMemoryUndefHelper(i32 undef) 799; CHECK: ret i32 800 801 802; Test PHINode instrumentation in blacklisted functions 803 804define i32 @NoSanitizeMemoryPHI(i32 %x) { 805entry: 806 %tobool = icmp ne i32 %x, 0 807 br i1 %tobool, label %cond.true, label %cond.false 808 809cond.true: ; preds = %entry 810 br label %cond.end 811 812cond.false: ; preds = %entry 813 br label %cond.end 814 815cond.end: ; preds = %cond.false, %cond.true 816 %cond = phi i32 [ undef, %cond.true ], [ undef, %cond.false ] 817 ret i32 %cond 818} 819 820; CHECK: [[A:%.*]] = phi i32 [ undef, %cond.true ], [ undef, %cond.false ] 821; CHECK: store i32 0, i32* bitcast {{.*}} @__msan_retval_tls 822; CHECK: ret i32 [[A]] 823 824 825; Test that there are no __msan_param_origin_tls stores when 826; argument shadow is a compile-time zero constant (which is always the case 827; in functions missing sanitize_memory attribute). 828 829define i32 @NoSanitizeMemoryParamTLS(i32* nocapture readonly %x) { 830entry: 831 %0 = load i32, i32* %x, align 4 832 %call = tail call i32 @NoSanitizeMemoryParamTLSHelper(i32 %0) 833 ret i32 %call 834} 835 836declare i32 @NoSanitizeMemoryParamTLSHelper(i32 %x) 837 838; CHECK-LABEL: define i32 @NoSanitizeMemoryParamTLS( 839; CHECK-NOT: __msan_param_origin_tls 840; CHECK: ret i32 841 842 843; Test argument shadow alignment 844 845define <2 x i64> @ArgumentShadowAlignment(i64 %a, <2 x i64> %b) sanitize_memory { 846entry: 847 ret <2 x i64> %b 848} 849 850; CHECK-LABEL: @ArgumentShadowAlignment 851; CHECK: load <2 x i64>, <2 x i64>* {{.*}} @__msan_param_tls {{.*}}, align 8 852; CHECK: store <2 x i64> {{.*}} @__msan_retval_tls {{.*}}, align 8 853; CHECK: ret <2 x i64> 854 855 856; Test origin propagation for insertvalue 857 858define { i64, i32 } @make_pair_64_32(i64 %x, i32 %y) sanitize_memory { 859entry: 860 %a = insertvalue { i64, i32 } undef, i64 %x, 0 861 %b = insertvalue { i64, i32 } %a, i32 %y, 1 862 ret { i64, i32 } %b 863} 864 865; CHECK-ORIGINS: @make_pair_64_32 866; First element shadow 867; CHECK-ORIGINS: insertvalue { i64, i32 } { i64 -1, i32 -1 }, i64 {{.*}}, 0 868; First element origin 869; CHECK-ORIGINS: icmp ne i64 870; CHECK-ORIGINS: select i1 871; First element app value 872; CHECK-ORIGINS: insertvalue { i64, i32 } undef, i64 {{.*}}, 0 873; Second element shadow 874; CHECK-ORIGINS: insertvalue { i64, i32 } {{.*}}, i32 {{.*}}, 1 875; Second element origin 876; CHECK-ORIGINS: icmp ne i32 877; CHECK-ORIGINS: select i1 878; Second element app value 879; CHECK-ORIGINS: insertvalue { i64, i32 } {{.*}}, i32 {{.*}}, 1 880; CHECK-ORIGINS: ret { i64, i32 } 881 882 883; Test shadow propagation for aggregates passed through ellipsis. 884 885%struct.StructByVal = type { i32, i32, i32, i32 } 886 887declare void @VAArgStructFn(i32 %guard, ...) 888 889define void @VAArgStruct(%struct.StructByVal* nocapture %s) sanitize_memory { 890entry: 891 %agg.tmp2 = alloca %struct.StructByVal, align 8 892 %0 = bitcast %struct.StructByVal* %s to i8* 893 %agg.tmp.sroa.0.0..sroa_cast = bitcast %struct.StructByVal* %s to i64* 894 %agg.tmp.sroa.0.0.copyload = load i64, i64* %agg.tmp.sroa.0.0..sroa_cast, align 4 895 %agg.tmp.sroa.2.0..sroa_idx = getelementptr inbounds %struct.StructByVal, %struct.StructByVal* %s, i64 0, i32 2 896 %agg.tmp.sroa.2.0..sroa_cast = bitcast i32* %agg.tmp.sroa.2.0..sroa_idx to i64* 897 %agg.tmp.sroa.2.0.copyload = load i64, i64* %agg.tmp.sroa.2.0..sroa_cast, align 4 898 %1 = bitcast %struct.StructByVal* %agg.tmp2 to i8* 899 call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 4 %1, i8* align 4 %0, i64 16, i1 false) 900 call void (i32, ...) @VAArgStructFn(i32 undef, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, %struct.StructByVal* byval align 8 %agg.tmp2) 901 ret void 902} 903 904; "undef" and the first 2 structs go to general purpose registers; 905; the third struct goes to the overflow area byval 906 907; CHECK-LABEL: @VAArgStruct 908; undef not stored to __msan_va_arg_tls - it's a fixed argument 909; first struct through general purpose registers 910; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 8){{.*}}, align 8 911; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 16){{.*}}, align 8 912; second struct through general purpose registers 913; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 24){{.*}}, align 8 914; CHECK: store i64 {{.*}}, i64* {{.*}}@__msan_va_arg_tls{{.*}}, i64 32){{.*}}, align 8 915; third struct through the overflow area byval 916; CHECK: ptrtoint %struct.StructByVal* {{.*}} to i64 917; CHECK: bitcast { i32, i32, i32, i32 }* {{.*}}@__msan_va_arg_tls {{.*}}, i64 176 918; CHECK: call void @llvm.memcpy.p0i8.p0i8.i64 919; CHECK: store i64 16, i64* @__msan_va_arg_overflow_size_tls 920; CHECK: call void (i32, ...) @VAArgStructFn 921; CHECK: ret void 922 923; Same code compiled without SSE (see attributes below). 924; The register save area is only 48 bytes instead of 176. 925define void @VAArgStructNoSSE(%struct.StructByVal* nocapture %s) sanitize_memory #0 { 926entry: 927 %agg.tmp2 = alloca %struct.StructByVal, align 8 928 %0 = bitcast %struct.StructByVal* %s to i8* 929 %agg.tmp.sroa.0.0..sroa_cast = bitcast %struct.StructByVal* %s to i64* 930 %agg.tmp.sroa.0.0.copyload = load i64, i64* %agg.tmp.sroa.0.0..sroa_cast, align 4 931 %agg.tmp.sroa.2.0..sroa_idx = getelementptr inbounds %struct.StructByVal, %struct.StructByVal* %s, i64 0, i32 2 932 %agg.tmp.sroa.2.0..sroa_cast = bitcast i32* %agg.tmp.sroa.2.0..sroa_idx to i64* 933 %agg.tmp.sroa.2.0.copyload = load i64, i64* %agg.tmp.sroa.2.0..sroa_cast, align 4 934 %1 = bitcast %struct.StructByVal* %agg.tmp2 to i8* 935 call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 4 %1, i8* align 4 %0, i64 16, i1 false) 936 call void (i32, ...) @VAArgStructFn(i32 undef, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, i64 %agg.tmp.sroa.0.0.copyload, i64 %agg.tmp.sroa.2.0.copyload, %struct.StructByVal* byval align 8 %agg.tmp2) 937 ret void 938} 939 940attributes #0 = { "target-features"="+fxsr,+x87,-sse" } 941 942; CHECK: bitcast { i32, i32, i32, i32 }* {{.*}}@__msan_va_arg_tls {{.*}}, i64 48 943 944declare i32 @InnerTailCall(i32 %a) 945 946define void @MismatchedReturnTypeTailCall(i32 %a) sanitize_memory { 947 %b = tail call i32 @InnerTailCall(i32 %a) 948 ret void 949} 950 951; We used to strip off the 'tail' modifier, but now that we unpoison return slot 952; shadow before the call, we don't need to anymore. 953 954; CHECK-LABEL: define void @MismatchedReturnTypeTailCall 955; CHECK: tail call i32 @InnerTailCall 956; CHECK: ret void 957 958 959declare i32 @MustTailCall(i32 %a) 960 961define i32 @CallMustTailCall(i32 %a) sanitize_memory { 962 %b = musttail call i32 @MustTailCall(i32 %a) 963 ret i32 %b 964} 965 966; For "musttail" calls we can not insert any shadow manipulating code between 967; call and the return instruction. And we don't need to, because everything is 968; taken care of in the callee. 969 970; CHECK-LABEL: define i32 @CallMustTailCall 971; CHECK: musttail call i32 @MustTailCall 972; No instrumentation between call and ret. 973; CHECK-NEXT: ret i32 974 975declare i32* @MismatchingMustTailCall(i32 %a) 976 977define i8* @MismatchingCallMustTailCall(i32 %a) sanitize_memory { 978 %b = musttail call i32* @MismatchingMustTailCall(i32 %a) 979 %c = bitcast i32* %b to i8* 980 ret i8* %c 981} 982 983; For "musttail" calls we can not insert any shadow manipulating code between 984; call and the return instruction. And we don't need to, because everything is 985; taken care of in the callee. 986 987; CHECK-LABEL: define i8* @MismatchingCallMustTailCall 988; CHECK: musttail call i32* @MismatchingMustTailCall 989; No instrumentation between call and ret. 990; CHECK-NEXT: bitcast i32* {{.*}} to i8* 991; CHECK-NEXT: ret i8* 992 993 994; CHECK-LABEL: define internal void @msan.module_ctor() { 995; CHECK: call void @__msan_init() 996