Example: provenance_lost_escape_1.c

up: index
prev: pointer_from_integer_2g.c
next: provenance_roundtrip_via_intptr_t_onepast.c

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
    #include <stdio.h>
    #include <string.h>
    #include <stdint.h>
    #include "charon_address_guesses.h"
    int x=1; // assume allocation ID @1, at ADDR_PLE_1
    int main() {
      int *p = &x;                      
      uintptr_t i1 = (intptr_t)p;            // (@1,ADDR_PLE_1)
      uintptr_t i2 = i1 & 0x00000000FFFFFFFF;// 
      uintptr_t i3 = i2 & 0xFFFFFFFF00000000;// (@1,0x0)
      uintptr_t i4 = i3 + ADDR_PLE_1;        // (@1,ADDR_PLE_1)
      int *q = (int *)i4;
      printf("Addresses: p=%p\n",(void*)p);
      if (memcmp(&i1, &i4, sizeof(i1)) == 0) {
        *q = 11;  // does this have defined behaviour?
        printf("x=%d *p=%d *q=%d\n",x,*p,*q);
      }
    }
[link to run test in Cerberus]

Experimental data (what does this mean?)

cerberus-concrete-PVI-plain Addresses: p=(@68, 0xffffee0c)
x=11 *p=11 *q=11
cerberus-concrete-PVI-ae Addresses: p=(@68, 0xffffee0c)
x=11 *p=11 *q=11
cerberus-concrete-PVI-ae-udi Addresses: p=(@68, 0xffffee0c)
x=11 *p=11 *q=11
gcc-8.3-O0 Addresses: p=0x100001020
x=11 *p=11 *q=11
gcc-8.3-O2 Addresses: p=0x100001018
x=11 *p=11 *q=11
gcc-8.3-O3 Addresses: p=0x100001018
x=11 *p=11 *q=11
gcc-8.3-O2-no-strict-aliasing Addresses: p=0x100001018
x=11 *p=11 *q=11
gcc-8.3-O3-no-strict-aliasing Addresses: p=0x100001018
x=11 *p=11 *q=11
clang-7.0.1-O0 Addresses: p=0x100001018
x=11 *p=11 *q=11
clang-7.0.1-O2 Addresses: p=0x100001018
x=11 *p=11 *q=11
clang-7.0.1-O3 Addresses: p=0x100001018
x=11 *p=11 *q=11
clang-7.0.1-O2-no-strict-aliasing Addresses: p=0x100001018
x=11 *p=11 *q=11
clang-7.0.1-O3-no-strict-aliasing Addresses: p=0x100001018
x=11 *p=11 *q=11
icc-19-O0 Addresses: p=0x600b70
x=11 *p=11 *q=11
icc-19-O2 Addresses: p=0x6046c0
x=1 *p=1 *q=11
icc-19-O3 Addresses: p=0x6046c0
x=1 *p=1 *q=11
icc-19-O2-no-strict-aliasing Addresses: p=0x6046c0
x=1 *p=1 *q=11
icc-19-O3-no-strict-aliasing Addresses: p=0x6046c0
x=1 *p=1 *q=11