Example: pointer_from_integer_1ie.c

up: index
prev: pointer_from_integer_1i.c
next: pointer_from_integer_2.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
    #include <stdio.h>
    #include <stdint.h>
    #include "charon_address_guesses.h"
    void f(uintptr_t i) {
      int j=5; 
      uintptr_t k = (uintptr_t)&j;
      int *p = (int*)i;
      *p=7;
      printf("j=%d\n",j); 
    }
    int main() {
      uintptr_t j = ADDRESS_PFI_1I;
      f(j);
    }
[link to run test in Cerberus]

Experimental data (what does this mean?)

cerberus-concrete-PVI-plain j=7
cerberus-concrete-PVI-ae j=7
cerberus-concrete-PVI-ae-udi j=7
gcc-8.3-O0 exit codes: compile 0 / execute 139
gcc-8.3-O2 exit codes: compile 0 / execute 139
gcc-8.3-O3 exit codes: compile 0 / execute 139
gcc-8.3-O2-no-strict-aliasing exit codes: compile 0 / execute 139
gcc-8.3-O3-no-strict-aliasing exit codes: compile 0 / execute 139
clang-7.0.1-O0 exit codes: compile 0 / execute 139
clang-7.0.1-O2 exit codes: compile 0 / execute 139
clang-7.0.1-O3 exit codes: compile 0 / execute 139
clang-7.0.1-O2-no-strict-aliasing exit codes: compile 0 / execute 139
clang-7.0.1-O3-no-strict-aliasing exit codes: compile 0 / execute 139
icc-19-O0 exit codes: compile 0 / execute 139 Segmentation fault (core dumped)
icc-19-O2 exit codes: compile 0 / execute 139 Segmentation fault (core dumped)
icc-19-O3 exit codes: compile 0 / execute 139 Segmentation fault (core dumped)
icc-19-O2-no-strict-aliasing exit codes: compile 0 / execute 139 Segmentation fault (core dumped)
icc-19-O3-no-strict-aliasing exit codes: compile 0 / execute 139 Segmentation fault (core dumped)