blob: d0fa25bc62ba36a9349081622e559b2db57c71cd [file] [log] [blame]
Pirama Arumuga Nainarcdce50b2015-07-01 12:26:56 -07001// Test haystack overflow in strstr function
Pirama Arumuga Nainar799172d2016-03-03 15:50:30 -08002// RUN: %clang_asan %s -o %t && %env_asan_opts=strict_string_checks=true not %run %t 2>&1 | FileCheck %s
Pirama Arumuga Nainarcdce50b2015-07-01 12:26:56 -07003
4// Test intercept_strstr asan option
5// Disable other interceptors because strlen may be called inside strstr
Pirama Arumuga Nainar799172d2016-03-03 15:50:30 -08006// RUN: %env_asan_opts=intercept_strstr=false:replace_str=false %run %t 2>&1
Pirama Arumuga Nainarcdce50b2015-07-01 12:26:56 -07007
8#include <assert.h>
9#include <string.h>
Pirama Arumuga Nainar799172d2016-03-03 15:50:30 -080010#include <sanitizer/asan_interface.h>
Pirama Arumuga Nainarcdce50b2015-07-01 12:26:56 -070011
12int main(int argc, char **argv) {
13 char *r = 0;
14 char s2[] = "c";
Pirama Arumuga Nainar799172d2016-03-03 15:50:30 -080015 char s1[4] = "acb";
16 __asan_poison_memory_region ((char *)&s1[2], 2);
Pirama Arumuga Nainarcdce50b2015-07-01 12:26:56 -070017 r = strstr(s1, s2);
Pirama Arumuga Nainar799172d2016-03-03 15:50:30 -080018 // CHECK:'s1' <== Memory access at offset {{[0-9]+}} partially overflows this variable
Pirama Arumuga Nainarcdce50b2015-07-01 12:26:56 -070019 assert(r == s1 + 1);
20 return 0;
21}