Example: pointer_from_integer_2g.c

up: index
prev: pointer_from_integer_2.c
next: provenance_lost_escape_1.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
    #include <stdio.h>
    #include <stdint.h>
    #include "charon_address_guesses.h"
    void f() {
      uintptr_t i=ADDRESS_PFI_2G;
      int *p = (int*)i;
      *p=7;
    }
    int main() {
      int j=5;
      if ((uintptr_t)&j == ADDRESS_PFI_2G)
        f();
      printf("j=%d &j=%p\n",j,(void*)&j); 
    }
[link to run test in Cerberus]

Experimental data (what does this mean?)

cerberus-concrete-PVI-plain j=7 &j=(@70, 0xffffedf8)
cerberus-concrete-PVI-ae j=7 &j=(@70, 0xffffedf8)
cerberus-concrete-PVI-ae-udi j=7 &j=(@70, 0xffffedf8)
gcc-8.3-O0 j=7 &j=0x7ffeefbff32c
gcc-8.3-O2 j=7 &j=0x7ffeefbff32c
gcc-8.3-O3 j=7 &j=0x7ffeefbff32c
gcc-8.3-O2-no-strict-aliasing j=7 &j=0x7ffeefbff2ec
gcc-8.3-O3-no-strict-aliasing j=7 &j=0x7ffeefbff2ec
clang-7.0.1-O0 j=7 &j=0x7ffeefbff318
clang-7.0.1-O2 j=5 &j=0x7ffeefbff31c
clang-7.0.1-O3 j=5 &j=0x7ffeefbff31c
clang-7.0.1-O2-no-strict-aliasing j=5 &j=0x7ffeefbff2dc
clang-7.0.1-O3-no-strict-aliasing j=5 &j=0x7ffeefbff2dc
icc-19-O0 j=7 &j=0x7fffffffe6e0
icc-19-O2 j=7 &j=0x6046c0
icc-19-O3 j=7 &j=0x6046c0
icc-19-O2-no-strict-aliasing j=7 &j=0x6046c0
icc-19-O3-no-strict-aliasing j=7 &j=0x6046c0