[compiler-rt] Reland: [ASan][Windows] Fix memmove/memcpy interception on x64 (#192060) (PR #193633)
Alexandre Ganea via llvm-commits
llvm-commits at lists.llvm.org
Wed Apr 29 06:28:44 PDT 2026
================
@@ -807,7 +815,27 @@ struct Allocator {
uptr memcpy_size = Min(new_size, m->UsedSize());
// If realloc() races with free(), we may start copying freed memory.
// However, we will report racy double-free later anyway.
+#if SANITIZER_WINDOWS64
+ // On Win64, REAL(memcpy) only points at a distinct non-interceptor
+ // function when memcpy and memmove are separate CRT entry points. When
+ // they are aliased we keep REAL(memcpy) == REAL(memmove), and both may
+ // dispatch back through the intercepted libc routine, which performs
+ // shadow-checked reads. That is a problem for chunks upgraded from
+ // malloc(0) / HeapReAlloc(..., 0): the single live byte is still
+ // shadow-poisoned (from_zero_alloc / asan_mark_zero_allocation), so a
+ // shadow-checked copy of Min(new_size, UsedSize()) bytes reports a
+ // spurious heap-buffer-overflow (see ReallocTest,
+ // heaprealloc_alloc_zero). Fall back to internal_memcpy (which bypasses
----------------
aganea wrote:
We don't. Clarified a bit more the behavior in `ReallocCopyContents`, please take a look.
https://github.com/llvm/llvm-project/pull/193633
More information about the llvm-commits
mailing list