[compiler-rt] [asan][test] Distinguish real and fake stack shadow in Windows SEH (PR #226343)

via llvm-commits llvm-commits at lists.llvm.org
Thu Sep 24 19:53:12 PDT 2026


llvmorg-github-actions[bot] wrote:


<!--LLVM PR SUMMARY COMMENT-->

@llvm/pr-subscribers-compiler-rt-sanitizer

Author: kingakasa

<details>
<summary>Changes</summary>

The Windows SEH tests currently expect a local buffer's redzone to be unpoisoned after exception handling. That describes the existing real-stack cleanup behavior, but is incorrect when use-after-return detection places the still-live local buffer on the fake stack: its redzone should remain poisoned.

Query whether the buffer belongs to the current fake stack and check the corresponding shadow state. Apply the same distinction to seh.cpp and dll_seh.cpp. This preserves coverage of the existing real-stack behavior and checks that live fake-stack redzones survive the transfer.

Validation:
- Before this change, both tests fail with detect_stack_use_after_return=true and pass with it false in the dynamic CRT control.
- After the change, both tests pass under default settings and with detect_stack_use_after_return explicitly true and false, for dynamic and static CRT configurations: 12/12 lit executions.
- These are test-only changes, exercised against the unmodified baseline compiler and runtime.

Tested independently on Windows x64 using a fresh Release LLVM/Clang build with assertions enabled and a matching Release ASan runtime, based on `6dc4a4ba2850369afd537001377fb9d404653d26`.

Changed-line clang-format and git diff --check pass.

Assisted-by: OpenAI Codex


---
Full diff: https://github.com/llvm/llvm-project/pull/226343.diff


2 Files Affected:

- (modified) compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp (+8-3) 
- (modified) compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp (+8-3) 


``````````diff
diff --git a/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp b/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp
index 9a29bee75c1b57..99481f54afc1c3 100644
--- a/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp
+++ b/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp
@@ -14,6 +14,8 @@
 // Should just "#include <sanitizer/asan_interface.h>" when C++ exceptions are
 // supported and we don't need to use CL.
 extern "C" bool __asan_address_is_poisoned(void *p);
+extern "C" void *__asan_get_current_fake_stack();
+extern "C" void *__asan_addr_is_in_fake_stack(void *, void *, void **, void **);
 
 void ThrowAndCatch();
 
@@ -43,8 +45,11 @@ int test_function() {
   ThrowAndCatch();
   fprintf(stderr, "After:  %p poisoned: %d\n",  &x,
           __asan_address_is_poisoned(x + 32));
-  // FIXME: Invert this assertion once we fix
-  // https://code.google.com/p/address-sanitizer/issues/detail?id=258
-  assert(!__asan_address_is_poisoned(x + 32));
+  // Exception handling currently clears real-stack redzones (issue 258).
+  // A live fake-stack allocation must retain its redzones.
+  bool on_fake_stack =
+      __asan_addr_is_in_fake_stack(__asan_get_current_fake_stack(), x, nullptr,
+                                   nullptr) != nullptr;
+  assert(__asan_address_is_poisoned(x + 32) == on_fake_stack);
   return 0;
 }
diff --git a/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp b/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp
index f3c7e1a33a568f..d9bbd4337c28af 100644
--- a/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp
+++ b/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp
@@ -20,6 +20,8 @@
 // Should just "#include <sanitizer/asan_interface.h>" when C++ exceptions are
 // supported and we don't need to use CL.
 extern "C" bool __asan_address_is_poisoned(void *p);
+extern "C" void *__asan_get_current_fake_stack();
+extern "C" void *__asan_addr_is_in_fake_stack(void *, void *, void **, void **);
 
 void ThrowAndCatch();
 
@@ -51,8 +53,11 @@ int main() {
   ThrowAndCatch();
   fprintf(stderr, "After:  %p poisoned: %d\n",  &x,
           __asan_address_is_poisoned(x + 32));
-  // FIXME: Invert this assertion once we fix
-  // https://code.google.com/p/address-sanitizer/issues/detail?id=258
-  assert(!__asan_address_is_poisoned(x + 32));
+  // Exception handling currently clears real-stack redzones (issue 258).
+  // A live fake-stack allocation must retain its redzones.
+  bool on_fake_stack =
+      __asan_addr_is_in_fake_stack(__asan_get_current_fake_stack(), x, nullptr,
+                                   nullptr) != nullptr;
+  assert(__asan_address_is_poisoned(x + 32) == on_fake_stack);
 }
 #endif

``````````

</details>


https://github.com/llvm/llvm-project/pull/226343


More information about the llvm-commits mailing list