xref: /aosp_15_r20/external/llvm/test/Transforms/WholeProgramDevirt/bad-read-from-vtable.ll (revision 9880d6810fe72a1726cb53787c6711e909410d58)
1*9880d681SAndroid Build Coastguard Worker; RUN: opt -S -wholeprogramdevirt %s | FileCheck %s
2*9880d681SAndroid Build Coastguard Worker
3*9880d681SAndroid Build Coastguard Workertarget datalayout = "e-p:64:64"
4*9880d681SAndroid Build Coastguard Workertarget triple = "x86_64-unknown-linux-gnu"
5*9880d681SAndroid Build Coastguard Worker
6*9880d681SAndroid Build Coastguard Worker@vt = global [2 x i8*] [i8* zeroinitializer, i8* bitcast (void (i8*)* @vf to i8*)], !type !0
7*9880d681SAndroid Build Coastguard Worker
8*9880d681SAndroid Build Coastguard Workerdefine void @vf(i8* %this) {
9*9880d681SAndroid Build Coastguard Worker  ret void
10*9880d681SAndroid Build Coastguard Worker}
11*9880d681SAndroid Build Coastguard Worker
12*9880d681SAndroid Build Coastguard Worker; CHECK: define void @unaligned
13*9880d681SAndroid Build Coastguard Workerdefine void @unaligned(i8* %obj) {
14*9880d681SAndroid Build Coastguard Worker  %vtableptr = bitcast i8* %obj to [1 x i8*]**
15*9880d681SAndroid Build Coastguard Worker  %vtable = load [1 x i8*]*, [1 x i8*]** %vtableptr
16*9880d681SAndroid Build Coastguard Worker  %vtablei8 = bitcast [1 x i8*]* %vtable to i8*
17*9880d681SAndroid Build Coastguard Worker  %p = call i1 @llvm.type.test(i8* %vtablei8, metadata !"typeid")
18*9880d681SAndroid Build Coastguard Worker  call void @llvm.assume(i1 %p)
19*9880d681SAndroid Build Coastguard Worker  %fptrptr = getelementptr i8, i8* %vtablei8, i32 1
20*9880d681SAndroid Build Coastguard Worker  %fptrptr_casted = bitcast i8* %fptrptr to i8**
21*9880d681SAndroid Build Coastguard Worker  %fptr = load i8*, i8** %fptrptr_casted
22*9880d681SAndroid Build Coastguard Worker  %fptr_casted = bitcast i8* %fptr to void (i8*)*
23*9880d681SAndroid Build Coastguard Worker  ; CHECK: call void %
24*9880d681SAndroid Build Coastguard Worker  call void %fptr_casted(i8* %obj)
25*9880d681SAndroid Build Coastguard Worker  ret void
26*9880d681SAndroid Build Coastguard Worker}
27*9880d681SAndroid Build Coastguard Worker
28*9880d681SAndroid Build Coastguard Worker; CHECK: define void @outofbounds
29*9880d681SAndroid Build Coastguard Workerdefine void @outofbounds(i8* %obj) {
30*9880d681SAndroid Build Coastguard Worker  %vtableptr = bitcast i8* %obj to [1 x i8*]**
31*9880d681SAndroid Build Coastguard Worker  %vtable = load [1 x i8*]*, [1 x i8*]** %vtableptr
32*9880d681SAndroid Build Coastguard Worker  %vtablei8 = bitcast [1 x i8*]* %vtable to i8*
33*9880d681SAndroid Build Coastguard Worker  %p = call i1 @llvm.type.test(i8* %vtablei8, metadata !"typeid")
34*9880d681SAndroid Build Coastguard Worker  call void @llvm.assume(i1 %p)
35*9880d681SAndroid Build Coastguard Worker  %fptrptr = getelementptr i8, i8* %vtablei8, i32 16
36*9880d681SAndroid Build Coastguard Worker  %fptrptr_casted = bitcast i8* %fptrptr to i8**
37*9880d681SAndroid Build Coastguard Worker  %fptr = load i8*, i8** %fptrptr_casted
38*9880d681SAndroid Build Coastguard Worker  %fptr_casted = bitcast i8* %fptr to void (i8*)*
39*9880d681SAndroid Build Coastguard Worker  ; CHECK: call void %
40*9880d681SAndroid Build Coastguard Worker  call void %fptr_casted(i8* %obj)
41*9880d681SAndroid Build Coastguard Worker  ret void
42*9880d681SAndroid Build Coastguard Worker}
43*9880d681SAndroid Build Coastguard Worker
44*9880d681SAndroid Build Coastguard Worker; CHECK: define void @nonfunction
45*9880d681SAndroid Build Coastguard Workerdefine void @nonfunction(i8* %obj) {
46*9880d681SAndroid Build Coastguard Worker  %vtableptr = bitcast i8* %obj to [1 x i8*]**
47*9880d681SAndroid Build Coastguard Worker  %vtable = load [1 x i8*]*, [1 x i8*]** %vtableptr
48*9880d681SAndroid Build Coastguard Worker  %vtablei8 = bitcast [1 x i8*]* %vtable to i8*
49*9880d681SAndroid Build Coastguard Worker  %p = call i1 @llvm.type.test(i8* %vtablei8, metadata !"typeid")
50*9880d681SAndroid Build Coastguard Worker  call void @llvm.assume(i1 %p)
51*9880d681SAndroid Build Coastguard Worker  %fptrptr = getelementptr i8, i8* %vtablei8, i32 0
52*9880d681SAndroid Build Coastguard Worker  %fptrptr_casted = bitcast i8* %fptrptr to i8**
53*9880d681SAndroid Build Coastguard Worker  %fptr = load i8*, i8** %fptrptr_casted
54*9880d681SAndroid Build Coastguard Worker  %fptr_casted = bitcast i8* %fptr to void (i8*)*
55*9880d681SAndroid Build Coastguard Worker  ; CHECK: call void %
56*9880d681SAndroid Build Coastguard Worker  call void %fptr_casted(i8* %obj)
57*9880d681SAndroid Build Coastguard Worker  ret void
58*9880d681SAndroid Build Coastguard Worker}
59*9880d681SAndroid Build Coastguard Worker
60*9880d681SAndroid Build Coastguard Workerdeclare i1 @llvm.type.test(i8*, metadata)
61*9880d681SAndroid Build Coastguard Workerdeclare void @llvm.assume(i1)
62*9880d681SAndroid Build Coastguard Worker
63*9880d681SAndroid Build Coastguard Worker!0 = !{i32 0, !"typeid"}
64