Skip to content

[msan] Add off-by-default flag to fix false negatives from partially undefined constant fixed-length vectors #143837

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 7 commits into from
Jun 20, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 41 additions & 5 deletions llvm/lib/Transforms/Instrumentation/MemorySanitizer.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -265,9 +265,22 @@ static cl::opt<bool>
cl::desc("Print name of local stack variable"),
cl::Hidden, cl::init(true));

static cl::opt<bool> ClPoisonUndef("msan-poison-undef",
cl::desc("poison undef temps"), cl::Hidden,
cl::init(true));
static cl::opt<bool>
ClPoisonUndef("msan-poison-undef",
cl::desc("Poison fully undef temporary values. "
"Partially undefined constant vectors "
"are unaffected by this flag (see "
"-msan-poison-undef-vectors)."),
cl::Hidden, cl::init(true));

static cl::opt<bool> ClPoisonUndefVectors(
"msan-poison-undef-vectors",
cl::desc("Precisely poison partially undefined constant vectors. "
"If false (legacy behavior), the entire vector is "
"considered fully initialized, which may lead to false "
"negatives. Fully undefined constant vectors are "
"unaffected by this flag (see -msan-poison-undef)."),
cl::Hidden, cl::init(false));

static cl::opt<bool>
ClHandleICmp("msan-handle-icmp",
Expand Down Expand Up @@ -1181,6 +1194,7 @@ struct MemorySanitizerVisitor : public InstVisitor<MemorySanitizerVisitor> {
bool PropagateShadow;
bool PoisonStack;
bool PoisonUndef;
bool PoisonUndefVectors;

struct ShadowOriginAndInsertPoint {
Value *Shadow;
Expand All @@ -1207,6 +1221,7 @@ struct MemorySanitizerVisitor : public InstVisitor<MemorySanitizerVisitor> {
PropagateShadow = SanitizeFunction;
PoisonStack = SanitizeFunction && ClPoisonStack;
PoisonUndef = SanitizeFunction && ClPoisonUndef;
PoisonUndefVectors = SanitizeFunction && ClPoisonUndefVectors;

// In the presence of unreachable blocks, we may see Phi nodes with
// incoming nodes from such blocks. Since InstVisitor skips unreachable
Expand Down Expand Up @@ -1989,6 +2004,8 @@ struct MemorySanitizerVisitor : public InstVisitor<MemorySanitizerVisitor> {
}
return Shadow;
}
// Handle fully undefined values
// (partially undefined constant vectors are handled later)
if (UndefValue *U = dyn_cast<UndefValue>(V)) {
Value *AllOnes = (PropagateShadow && PoisonUndef) ? getPoisonedShadow(V)
: getCleanShadow(V);
Expand Down Expand Up @@ -2086,8 +2103,27 @@ struct MemorySanitizerVisitor : public InstVisitor<MemorySanitizerVisitor> {
return ShadowPtr;
}

// TODO: Partially undefined vectors are handled by the fall-through case
// below (see partial-poison.ll); this causes false negatives.
// Check for partially-undefined constant vectors
// TODO: scalable vectors (this is hard because we do not have IRBuilder)
if (isa<FixedVectorType>(V->getType()) && isa<Constant>(V) &&
cast<Constant>(V)->containsUndefOrPoisonElement() && PropagateShadow &&
PoisonUndefVectors) {
unsigned NumElems = cast<FixedVectorType>(V->getType())->getNumElements();
SmallVector<Constant *, 32> ShadowVector(NumElems);
for (unsigned i = 0; i != NumElems; ++i) {
Constant *Elem = cast<Constant>(V)->getAggregateElement(i);
ShadowVector[i] = isa<UndefValue>(Elem) ? getPoisonedShadow(Elem)
: getCleanShadow(Elem);
}

Value *ShadowConstant = ConstantVector::get(ShadowVector);
LLVM_DEBUG(dbgs() << "Partial undef constant vector: " << *V << " ==> "
<< *ShadowConstant << "\n");

return ShadowConstant;
}

// TODO: partially-undefined constant arrays, structures, and nested types

// For everything else the shadow is zero.
return getCleanShadow(V);
Expand Down
39 changes: 32 additions & 7 deletions llvm/test/Instrumentation/MemorySanitizer/partial-poison.ll
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
; NOTE: Assertions have been autogenerated by utils/update_test_checks.py UTC_ARGS: --version 5
; RUN: opt < %s -S -passes='msan' 2>&1 | FileCheck %s
; RUN: opt < %s -S -passes='msan' -msan-poison-undef-vectors=true 2>&1 | FileCheck %s --check-prefixes=CHECK,CHECK-PRECISE
; RUN: opt < %s -S -passes='msan' -msan-poison-undef-vectors=false 2>&1 | FileCheck %s --check-prefixes=CHECK,CHECK-IMPRECISE
;
; Test case to show that MSan computes shadows for partially poisoned vectors
; as fully initialized, resulting in false negatives.
; Regression test case for computing shadows of partially poisoned vectors.
; Partially poisoned structs and arrays are not correctly implemented.

target datalayout = "e-p:64:64:64-i1:8:8-i8:8:8-i16:16:16-i32:32:32-i64:64:64-f32:32:32-f64:64:64-v64:64:64-v128:128:128-a0:0:64-s0:64:64-f80:128:128-n8:16:32:64-S128"
target triple = "x86_64-unknown-linux-gnu"
Expand All @@ -11,7 +12,8 @@ define <2 x i64> @left_poison(ptr %add.ptr) sanitize_memory {
; CHECK-LABEL: define <2 x i64> @left_poison(
; CHECK-SAME: ptr [[ADD_PTR:%.*]]) #[[ATTR0:[0-9]+]] {
; CHECK-NEXT: call void @llvm.donothing()
; CHECK-NEXT: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-PRECISE: store <2 x i64> <i64 -1, i64 0>, ptr @__msan_retval_tls, align 8
; CHECK-IMPRECISE: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-NEXT: ret <2 x i64> <i64 poison, i64 42>
;
ret <2 x i64> <i64 poison, i64 42>
Expand All @@ -21,7 +23,8 @@ define <2 x i64> @right_poison(ptr %add.ptr) sanitize_memory {
; CHECK-LABEL: define <2 x i64> @right_poison(
; CHECK-SAME: ptr [[ADD_PTR:%.*]]) #[[ATTR0]] {
; CHECK-NEXT: call void @llvm.donothing()
; CHECK-NEXT: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-PRECISE: store <2 x i64> <i64 0, i64 -1>, ptr @__msan_retval_tls, align 8
; CHECK-IMPRECISE: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-NEXT: ret <2 x i64> <i64 42, i64 poison>
;
ret <2 x i64> <i64 42, i64 poison>
Expand Down Expand Up @@ -51,7 +54,8 @@ define <2 x i64> @left_undef(ptr %add.ptr) sanitize_memory {
; CHECK-LABEL: define <2 x i64> @left_undef(
; CHECK-SAME: ptr [[ADD_PTR:%.*]]) #[[ATTR0]] {
; CHECK-NEXT: call void @llvm.donothing()
; CHECK-NEXT: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-PRECISE: store <2 x i64> <i64 -1, i64 0>, ptr @__msan_retval_tls, align 8
; CHECK-IMPRECISE: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-NEXT: ret <2 x i64> <i64 undef, i64 42>
;
ret <2 x i64> <i64 undef, i64 42>
Expand All @@ -61,7 +65,8 @@ define <2 x i64> @right_undef(ptr %add.ptr) sanitize_memory {
; CHECK-LABEL: define <2 x i64> @right_undef(
; CHECK-SAME: ptr [[ADD_PTR:%.*]]) #[[ATTR0]] {
; CHECK-NEXT: call void @llvm.donothing()
; CHECK-NEXT: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-PRECISE: store <2 x i64> <i64 0, i64 -1>, ptr @__msan_retval_tls, align 8
; CHECK-IMPRECISE: store <2 x i64> zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-NEXT: ret <2 x i64> <i64 42, i64 undef>
;
ret <2 x i64> <i64 42, i64 undef>
Expand All @@ -76,3 +81,23 @@ define <2 x i64> @full_undef(ptr %add.ptr) sanitize_memory {
;
ret <2 x i64> <i64 undef, i64 undef>
}

define {i64, i64} @struct_left_undef() sanitize_memory {
; CHECK-LABEL: define { i64, i64 } @struct_left_undef(
; CHECK-SAME: ) #[[ATTR0]] {
; CHECK-NEXT: call void @llvm.donothing()
; CHECK-NEXT: store { i64, i64 } zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-NEXT: ret { i64, i64 } { i64 undef, i64 42 }
;
ret {i64, i64} { i64 undef, i64 42 }
}

define [2x i64] @array_right_undef() sanitize_memory {
; CHECK-LABEL: define [2 x i64] @array_right_undef(
; CHECK-SAME: ) #[[ATTR0]] {
; CHECK-NEXT: call void @llvm.donothing()
; CHECK-NEXT: store [2 x i64] zeroinitializer, ptr @__msan_retval_tls, align 8
; CHECK-NEXT: ret [2 x i64] [i64 42, i64 undef]
;
ret [2x i64] [ i64 42, i64 undef ]
}
Loading