diff options
author | Jason Merrill <jason@redhat.com> | 2020-05-29 11:59:33 -0400 |
---|---|---|
committer | Giuliano Belinassi <giuliano.belinassi@usp.br> | 2020-08-17 13:09:22 -0300 |
commit | 48a12f092709c1a852baaadf823ab0fbf199d3eb (patch) | |
tree | bb729a26052147e4f35ebaa712b4d283bd6a6108 /gcc | |
parent | 3530c5ee97fbb0f70babf3200015711f8a9cc2c8 (diff) | |
download | gcc-48a12f092709c1a852baaadf823ab0fbf199d3eb.zip gcc-48a12f092709c1a852baaadf823ab0fbf199d3eb.tar.gz gcc-48a12f092709c1a852baaadf823ab0fbf199d3eb.tar.bz2 |
c++: vptr ubsan and derived class [PR95311].
We weren't able to find OBJ_TYPE_REF_OBJECT walking through
OBJ_TYPE_REF_EXPR because we had folded away the ADDR_EXPR.
gcc/cp/ChangeLog:
PR c++/95311
PR c++/95221
* class.c (build_vfn_ref): Don't fold the INDIRECT_REF.
gcc/testsuite/ChangeLog:
PR c++/95311
* g++.dg/ubsan/vptr-16.C: New test.
Diffstat (limited to 'gcc')
-rw-r--r-- | gcc/cp/class.c | 8 | ||||
-rw-r--r-- | gcc/testsuite/g++.dg/ubsan/vptr-16.C | 14 |
2 files changed, 20 insertions, 2 deletions
diff --git a/gcc/cp/class.c b/gcc/cp/class.c index bab15524..ca492cd 100644 --- a/gcc/cp/class.c +++ b/gcc/cp/class.c @@ -729,9 +729,13 @@ build_vtbl_ref (tree instance, tree idx) tree build_vfn_ref (tree instance_ptr, tree idx) { - tree aref; + tree obtype = TREE_TYPE (TREE_TYPE (instance_ptr)); + + /* Leave the INDIRECT_REF unfolded so cp_ubsan_maybe_instrument_member_call + can find instance_ptr. */ + tree ind = build1 (INDIRECT_REF, obtype, instance_ptr); - aref = build_vtbl_ref (cp_build_fold_indirect_ref (instance_ptr), idx); + tree aref = build_vtbl_ref (ind, idx); /* When using function descriptors, the address of the vtable entry is treated as a function pointer. */ diff --git a/gcc/testsuite/g++.dg/ubsan/vptr-16.C b/gcc/testsuite/g++.dg/ubsan/vptr-16.C new file mode 100644 index 0000000..a3db66e --- /dev/null +++ b/gcc/testsuite/g++.dg/ubsan/vptr-16.C @@ -0,0 +1,14 @@ +// PR c++/95311 +// { dg-additional-options -fsanitize=undefined } + +class a { + virtual long b() const; +}; +class c : a { +public: + long b() const; +}; +class d : c { + long e(); +}; +long d::e() { b(); return 0; } |