Compare commits

..

2 commits

Author SHA1 Message Date
cgzones
aaedf6b560
Merge 9ca3279507 into 1d7fc7ffe0 2025-04-05 16:55:44 +02:00
Christian Göttsche
9ca3279507 test: add tests for zero sized realloc(3)
C23 declared calling realloc(3) with a non-NULL pointer and zero size
Undefined behavior.
Check that hardened_malloc handles that case sanely by free'ing the old
pointer and returning a special pointer, like `malloc(3)` called with
size zero.
2025-04-05 16:55:41 +02:00
7 changed files with 59 additions and 9 deletions

View file

@ -1513,11 +1513,6 @@ EXPORT void *h_calloc(size_t nmemb, size_t size) {
} }
EXPORT void *h_realloc(void *old, size_t size) { EXPORT void *h_realloc(void *old, size_t size) {
// deprecated in C17, UB since C23
if (unlikely(old != NULL && size == 0)) {
fatal_error("invalid zero sized realloc");
}
size = adjust_size_for_canary(size); size = adjust_size_for_canary(size);
if (old == NULL) { if (old == NULL) {
return alloc(size); return alloc(size);

2
test/.gitignore vendored
View file

@ -42,4 +42,6 @@ uninitialized_read_large
uninitialized_read_small uninitialized_read_small
realloc_init realloc_init
realloc_c23_undefined_behaviour realloc_c23_undefined_behaviour
realloc_c23_undefined_behaviour_double_free
realloc_c23_undefined_behaviour_use_after_free
__pycache__/ __pycache__/

View file

@ -68,7 +68,9 @@ EXECUTABLES := \
invalid_malloc_object_size_small_quarantine \ invalid_malloc_object_size_small_quarantine \
impossibly_large_malloc \ impossibly_large_malloc \
realloc_init \ realloc_init \
realloc_c23_undefined_behaviour realloc_c23_undefined_behaviour \
realloc_c23_undefined_behaviour_double_free \
realloc_c23_undefined_behaviour_use_after_free
all: $(EXECUTABLES) all: $(EXECUTABLES)

View file

@ -1,16 +1,19 @@
#include <stdio.h>
#include <stdlib.h> #include <stdlib.h>
#include "test_util.h" #include "test_util.h"
OPTNONE int main(void) { OPTNONE int main(void) {
void *p, *q; char *p, *q, *r;
p = malloc(16); p = malloc(16);
if (!p) { if (!p) {
return -1; return 1;
} }
q = realloc(p, 0); q = realloc(p, 0);
free(q);
return 0; return 0;
} }

View file

@ -0,0 +1,19 @@
#include <stdio.h>
#include <stdlib.h>
#include "test_util.h"
OPTNONE int main(void) {
char *p, *q, *r;
p = malloc(16);
if (!p) {
return 1;
}
q = realloc(p, 0);
free(p);
return 0;
}

View file

@ -0,0 +1,21 @@
#include <stdio.h>
#include <stdlib.h>
#include "test_util.h"
OPTNONE int main(void) {
char *p, *q, *r;
p = malloc(256 * 1024);
if (!p) {
return 1;
}
q = realloc(p, 0);
printf("%c\n", *p);
free(q);
return 0;
}

View file

@ -171,9 +171,17 @@ class TestSimpleMemoryCorruption(unittest.TestCase):
def test_realloc_c23_undefined_behaviour(self): def test_realloc_c23_undefined_behaviour(self):
_stdout, stderr, returncode = self.run_test("realloc_c23_undefined_behaviour") _stdout, stderr, returncode = self.run_test("realloc_c23_undefined_behaviour")
self.assertEqual(returncode, 0)
def test_realloc_c23_undefined_behaviour_double_free(self):
_stdout, stderr, returncode = self.run_test("realloc_c23_undefined_behaviour_double_free")
self.assertEqual(returncode, -6) self.assertEqual(returncode, -6)
self.assertEqual(stderr.decode("utf-8"), self.assertEqual(stderr.decode("utf-8"),
"fatal allocator error: invalid zero sized realloc\n") "fatal allocator error: double free (quarantine)\n")
def test_realloc_c23_undefined_behaviour_use_after_free(self):
_stdout, stderr, returncode = self.run_test("realloc_c23_undefined_behaviour_use_after_free")
self.assertEqual(returncode, -11)
def test_write_after_free_large_reuse(self): def test_write_after_free_large_reuse(self):
_stdout, _stderr, returncode = self.run_test( _stdout, _stderr, returncode = self.run_test(