-
Notifications
You must be signed in to change notification settings - Fork 13.6k
[ASan][libc++] Annotating std::basic_string
with all allocators
#75845
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
AdvenamTacet
merged 7 commits into
llvm:main
from
trail-of-forks:string-annotations-all-allocators
Jan 13, 2024
Merged
Changes from all commits
Commits
Show all changes
7 commits
Select commit
Hold shift + click to select a range
7af271d
[ASan][libc++] Annotating `std::basic_string` with all allocators
1eea92e
Code review from EricWF
428a15f
Remove constexpr magic
a73df63
Mention CWG2523
d6a2fcc
Remove a comment
AdvenamTacet 55980f5
Add arguments to main
AdvenamTacet 200aaf2
Add return to main
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
56 changes: 56 additions & 0 deletions
56
libcxx/test/libcxx/containers/strings/basic.string/asan.pass.cpp
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
//===----------------------------------------------------------------------===// | ||
// | ||
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. | ||
// See https://llvm.org/LICENSE.txt for license information. | ||
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception | ||
// | ||
//===----------------------------------------------------------------------===// | ||
|
||
// REQUIRES: asan | ||
// UNSUPPORTED: c++03 | ||
|
||
// Basic test if ASan annotations work for basic_string. | ||
|
||
#include <string> | ||
#include <cassert> | ||
#include <cstdlib> | ||
|
||
#include "asan_testing.h" | ||
#include "min_allocator.h" | ||
#include "test_iterators.h" | ||
#include "test_macros.h" | ||
|
||
extern "C" void __sanitizer_set_death_callback(void (*callback)(void)); | ||
|
||
void do_exit() { exit(0); } | ||
|
||
int main(int, char**) { | ||
{ | ||
typedef cpp17_input_iterator<char*> MyInputIter; | ||
// Should not trigger ASan. | ||
std::basic_string<char, std::char_traits<char>, safe_allocator<char>> v; | ||
char i[] = {'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'a', 'b', 'c', 'd', 'e', | ||
'f', 'g', 'h', 'i', 'j', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j'}; | ||
|
||
v.insert(v.begin(), MyInputIter(i), MyInputIter(i + 29)); | ||
assert(v[0] == 'a'); | ||
assert(is_string_asan_correct(v)); | ||
} | ||
|
||
__sanitizer_set_death_callback(do_exit); | ||
{ | ||
using T = char; | ||
using C = std::basic_string<T, std::char_traits<T>, safe_allocator<T>>; | ||
const T t[] = {'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'a', 'b', 'c', 'd', 'e', | ||
'f', 'g', 'h', 'i', 'j', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j'}; | ||
C c(std::begin(t), std::end(t)); | ||
assert(is_string_asan_correct(c)); | ||
assert(__sanitizer_verify_contiguous_container(c.data(), c.data() + c.size() + 1, c.data() + c.capacity() + 1) != | ||
0); | ||
T foo = c[c.size() + 1]; // should trigger ASAN and call do_exit(). | ||
assert(false); // if we got here, ASAN didn't trigger | ||
((void)foo); | ||
|
||
return 0; | ||
} | ||
AdvenamTacet marked this conversation as resolved.
Show resolved
Hide resolved
|
||
} |
102 changes: 102 additions & 0 deletions
102
libcxx/test/libcxx/containers/strings/basic.string/asan_turning_off.pass.cpp
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,102 @@ | ||
//===----------------------------------------------------------------------===// | ||
// | ||
// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions. | ||
// See https://llvm.org/LICENSE.txt for license information. | ||
// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception | ||
// | ||
//===----------------------------------------------------------------------===// | ||
|
||
// REQUIRES: asan | ||
// UNSUPPORTED: c++03 | ||
|
||
// Test based on: https://bugs.chromium.org/p/chromium/issues/detail?id=1419798#c5 | ||
// Some allocators during deallocation may not call destructors and just reuse memory. | ||
AdvenamTacet marked this conversation as resolved.
Show resolved
Hide resolved
|
||
// In those situations, one may want to deactivate annotations for a specific allocator. | ||
// It's possible with __asan_annotate_container_with_allocator template class. | ||
// This test confirms that those allocators work after turning off annotations. | ||
// | ||
// A context to this test is a situations when memory is repurposed and destructors are not called. | ||
// Related issue: https://github.com/llvm/llvm-project/issues/60384 | ||
// | ||
// That issue appeared in the past and was addressed here: https://reviews.llvm.org/D145628 | ||
// | ||
// There was also a discussion, if it's UB. | ||
// Related discussion: https://reviews.llvm.org/D136765#4155262 | ||
// Related notes: https://eel.is/c++draft/basic.life#6 | ||
// Probably it's no longer UB due a change in CWG2523. | ||
// https://cplusplus.github.io/CWG/issues/2523.html | ||
// | ||
// Therefore we make sure that it works that way, also because people rely on this behavior. | ||
// Annotations are turned off only, if a user explicitly turns off annotations for a specific allocator. | ||
|
||
#include <assert.h> | ||
#include <stdlib.h> | ||
#include <string> | ||
#include <new> | ||
|
||
// Allocator with pre-allocated (with malloc in constructor) buffers. | ||
// Memory may be freed without calling destructors. | ||
struct reuse_allocator { | ||
static size_t const N = 100; | ||
reuse_allocator() { | ||
for (size_t i = 0; i < N; ++i) | ||
__buffers[i] = malloc(8 * 1024); | ||
} | ||
~reuse_allocator() { | ||
for (size_t i = 0; i < N; ++i) | ||
free(__buffers[i]); | ||
} | ||
void* alloc() { | ||
assert(__next_id < N); | ||
return __buffers[__next_id++]; | ||
} | ||
void reset() { __next_id = 0; } | ||
void* __buffers[N]; | ||
size_t __next_id = 0; | ||
} reuse_buffers; | ||
|
||
template <typename T> | ||
struct user_allocator { | ||
using value_type = T; | ||
user_allocator() = default; | ||
template <class U> | ||
user_allocator(user_allocator<U>) {} | ||
friend bool operator==(user_allocator, user_allocator) { return true; } | ||
friend bool operator!=(user_allocator x, user_allocator y) { return !(x == y); } | ||
|
||
T* allocate(size_t n) { | ||
if (n * sizeof(T) > 8 * 1024) | ||
throw std::bad_array_new_length(); | ||
return (T*)reuse_buffers.alloc(); | ||
} | ||
void deallocate(T*, size_t) noexcept {} | ||
}; | ||
|
||
// Turn off annotations for user_allocator: | ||
template <class T> | ||
struct std::__asan_annotate_container_with_allocator<user_allocator<T>> { | ||
AdvenamTacet marked this conversation as resolved.
Show resolved
Hide resolved
|
||
static bool const value = false; | ||
}; | ||
|
||
int main(int, char**) { | ||
using S = std::basic_string<char, std::char_traits<char>, user_allocator<char>>; | ||
|
||
{ | ||
// Create a string with a buffer from reuse allocator object: | ||
S* s = new (reuse_buffers.alloc()) S(); | ||
EricWF marked this conversation as resolved.
Show resolved
Hide resolved
|
||
// Use string, so it's poisoned, if container annotations for that allocator are not turned off: | ||
for (int i = 0; i < 40; i++) | ||
s->push_back('a'); | ||
} | ||
// Reset the state of the allocator, don't call destructors, allow memory to be reused: | ||
reuse_buffers.reset(); | ||
{ | ||
// Create a next string with the same allocator, so the same buffer due to the reset: | ||
S s; | ||
// Use memory inside the string again, if it's poisoned, an error will be raised: | ||
for (int i = 0; i < 60; i++) | ||
s.push_back('a'); | ||
} | ||
|
||
return 0; | ||
} |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.