[compiler-rt] [asan][test] Distinguish real and fake stack shadow in Windows SEH (PR #226343)
via llvm-commits
llvm-commits at lists.llvm.org
Thu Sep 24 19:53:12 PDT 2026
llvmorg-github-actions[bot] wrote:
<!--LLVM PR SUMMARY COMMENT-->
@llvm/pr-subscribers-compiler-rt-sanitizer
Author: kingakasa
<details>
<summary>Changes</summary>
The Windows SEH tests currently expect a local buffer's redzone to be unpoisoned after exception handling. That describes the existing real-stack cleanup behavior, but is incorrect when use-after-return detection places the still-live local buffer on the fake stack: its redzone should remain poisoned.
Query whether the buffer belongs to the current fake stack and check the corresponding shadow state. Apply the same distinction to seh.cpp and dll_seh.cpp. This preserves coverage of the existing real-stack behavior and checks that live fake-stack redzones survive the transfer.
Validation:
- Before this change, both tests fail with detect_stack_use_after_return=true and pass with it false in the dynamic CRT control.
- After the change, both tests pass under default settings and with detect_stack_use_after_return explicitly true and false, for dynamic and static CRT configurations: 12/12 lit executions.
- These are test-only changes, exercised against the unmodified baseline compiler and runtime.
Tested independently on Windows x64 using a fresh Release LLVM/Clang build with assertions enabled and a matching Release ASan runtime, based on `6dc4a4ba2850369afd537001377fb9d404653d26`.
Changed-line clang-format and git diff --check pass.
Assisted-by: OpenAI Codex
---
Full diff: https://github.com/llvm/llvm-project/pull/226343.diff
2 Files Affected:
- (modified) compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp (+8-3)
- (modified) compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp (+8-3)
``````````diff
diff --git a/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp b/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp
index 9a29bee75c1b57..99481f54afc1c3 100644
--- a/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp
+++ b/compiler-rt/test/asan/TestCases/Windows/msvc/dll_seh.cpp
@@ -14,6 +14,8 @@
// Should just "#include <sanitizer/asan_interface.h>" when C++ exceptions are
// supported and we don't need to use CL.
extern "C" bool __asan_address_is_poisoned(void *p);
+extern "C" void *__asan_get_current_fake_stack();
+extern "C" void *__asan_addr_is_in_fake_stack(void *, void *, void **, void **);
void ThrowAndCatch();
@@ -43,8 +45,11 @@ int test_function() {
ThrowAndCatch();
fprintf(stderr, "After: %p poisoned: %d\n", &x,
__asan_address_is_poisoned(x + 32));
- // FIXME: Invert this assertion once we fix
- // https://code.google.com/p/address-sanitizer/issues/detail?id=258
- assert(!__asan_address_is_poisoned(x + 32));
+ // Exception handling currently clears real-stack redzones (issue 258).
+ // A live fake-stack allocation must retain its redzones.
+ bool on_fake_stack =
+ __asan_addr_is_in_fake_stack(__asan_get_current_fake_stack(), x, nullptr,
+ nullptr) != nullptr;
+ assert(__asan_address_is_poisoned(x + 32) == on_fake_stack);
return 0;
}
diff --git a/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp b/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp
index f3c7e1a33a568f..d9bbd4337c28af 100644
--- a/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp
+++ b/compiler-rt/test/asan/TestCases/Windows/msvc/seh.cpp
@@ -20,6 +20,8 @@
// Should just "#include <sanitizer/asan_interface.h>" when C++ exceptions are
// supported and we don't need to use CL.
extern "C" bool __asan_address_is_poisoned(void *p);
+extern "C" void *__asan_get_current_fake_stack();
+extern "C" void *__asan_addr_is_in_fake_stack(void *, void *, void **, void **);
void ThrowAndCatch();
@@ -51,8 +53,11 @@ int main() {
ThrowAndCatch();
fprintf(stderr, "After: %p poisoned: %d\n", &x,
__asan_address_is_poisoned(x + 32));
- // FIXME: Invert this assertion once we fix
- // https://code.google.com/p/address-sanitizer/issues/detail?id=258
- assert(!__asan_address_is_poisoned(x + 32));
+ // Exception handling currently clears real-stack redzones (issue 258).
+ // A live fake-stack allocation must retain its redzones.
+ bool on_fake_stack =
+ __asan_addr_is_in_fake_stack(__asan_get_current_fake_stack(), x, nullptr,
+ nullptr) != nullptr;
+ assert(__asan_address_is_poisoned(x + 32) == on_fake_stack);
}
#endif
``````````
</details>
https://github.com/llvm/llvm-project/pull/226343
More information about the llvm-commits
mailing list