[compiler-rt] Reland: [ASan][Windows] Fix memmove/memcpy interception on x64 (#192060) (PR #193633)

Alexandre Ganea via llvm-commits llvm-commits at lists.llvm.org
Wed Apr 29 06:28:44 PDT 2026


================
@@ -807,7 +815,27 @@ struct Allocator {
       uptr memcpy_size = Min(new_size, m->UsedSize());
       // If realloc() races with free(), we may start copying freed memory.
       // However, we will report racy double-free later anyway.
+#if SANITIZER_WINDOWS64
+      // On Win64, REAL(memcpy) only points at a distinct non-interceptor
+      // function when memcpy and memmove are separate CRT entry points. When
+      // they are aliased we keep REAL(memcpy) == REAL(memmove), and both may
+      // dispatch back through the intercepted libc routine, which performs
+      // shadow-checked reads. That is a problem for chunks upgraded from
+      // malloc(0) / HeapReAlloc(..., 0): the single live byte is still
+      // shadow-poisoned (from_zero_alloc / asan_mark_zero_allocation), so a
+      // shadow-checked copy of Min(new_size, UsedSize()) bytes reports a
+      // spurious heap-buffer-overflow (see ReallocTest,
+      // heaprealloc_alloc_zero). Fall back to internal_memcpy (which bypasses
----------------
aganea wrote:

We don't. Clarified a bit more the behavior in `ReallocCopyContents`, please take a look.

https://github.com/llvm/llvm-project/pull/193633


More information about the llvm-commits mailing list