【问题标题】:Call to function (unknown) through pointer to incorrect function type通过指向不正确函数类型的指针调用函数(未知)
【发布时间】:2017-08-30 11:05:30
【问题描述】:

我有一个动态链接库的程序。 程序将函数指针传递给该库以执行。

但是 ubsan (Undefined Behavior Sanitizer) 指定指针位于不正确的函数类型上。而这种情况只会发生

  • 如果回调函数有一个类作为参数
  • 如果回调函数有一个类作为参数,但只前向声明
  • 如果我指定编译标志:-fvisibility=hidden。

我使用 clang 编译我的项目。

这是 clang 未定义行为清理程序中的错误吗?

下面的代码被简化为一个简单的测试用例。检查 cmets 看看我们可以在哪里采取行动来消除一些警告

应用程序代码:

Main.cxx

#include "Caller.h"
#include "Param.h"

static void FctVoid()
{
}
static void FctInt(int _param)
{
   static_cast<void>(&_param);
}
static void FctCaller(Caller &_caller)
{
   static_cast<void>(&_caller);
}
static void FctParam(Param const &_param)
{
   static_cast<void>(&_param);
}

int main()
{
   Param param;
   Caller::CallVoid(&FctVoid);
   Caller::CallInt(&FctInt);
   Caller::CallThis(&FctCaller);
   Caller::CallParam(&FctParam, param);
   return 0;
}

库文件的代码是:

来电者.cxx:

#include "Caller.h"
// To uncomment to fix one warning
//#include "Param.h"
void Caller::CallVoid(FctVoidT _fct)
{
   _fct();
}
void Caller::CallInt(FctIntT _fct)
{
   _fct(32);
}
void Caller::CallThis(FctThisT _fct)
{
   Caller caller;
   _fct(caller);
}
void Caller::CallParam(FctParamT const &_fct, Param const &_param)
{
   _fct(_param);
}

caller.h

#ifndef __Caller_h_
#define __Caller_h_
#include "owExport.h"

class Param;
class EXPORT_Library Caller
{
public:
   typedef void(*FctVoidT)();
   static void CallVoid(FctVoidT _fct);
   typedef void(*FctIntT)(int);
   static void CallInt(FctIntT _fct);
   typedef void(*FctThisT)(Caller &);
   static void CallThis(FctThisT _fct);
   typedef void(*FctParamT)(Param const &);
   static void CallParam(FctParamT const &_fct, Param const &_param);
};
#endif

参数.h

#ifndef __Param_h_
#define __Param_h_
#include "owExport.h"
class EXPORT_Library Param
{
public:
};
#endif

owExport.h

#ifndef __owExport_h_
#define __owExport_h_
#define OW_EXPORT __attribute__ ((visibility("default")))
#define OW_IMPORT
// Use this one to fix one warning
#define OW_IMPORT __attribute__ ((visibility("default")))
#ifdef Library_EXPORTS
#  define EXPORT_Library OW_EXPORT
#else
#  define EXPORT_Library OW_IMPORT
#endif
#endif

配置项目的CMakeLists.txt:

cmake_minimum_required(VERSION 3.0.0)
project(TestFunction)
set(BUILD_SHARED_LIBS ON)
set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -std=c++11 -fsanitize=undefined ")

# Act here to for the call of function through pointer to incorrect function type
# set(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -fvisibility=hidden")

add_library(Library Caller.cxx Param.cxx)
add_executable(TestWithLib Main.cxx)
target_link_libraries(TestWithLib Library)

【问题讨论】:

  • 您是否有可能在 ODR 方面搞砸了? clang.llvm.org/docs/LTOVisibility.html
  • 该文档似乎与我的问题相对应。不幸的是,我测试了所有标志组合,但没有发现可以解决问题。
  • 在将Caller.cxx编译成共享库时,是否定义了Library_EXPORTS?
  • 我用我正在使用的 CMakeLists.txt 更新了这个问题。 Library_EXPORTS 由 CMake 使用 add_library 自动定义。
  • 是的,这是我不得不解决一段时间的 Clang 错误。第一个创建 sscce 并将其报告为错误的获胜!

标签: c++ pointers undefined-behavior ubsan


【解决方案1】:

首先:如果您已经编辑问题以添加修复程序,那就不好了。这让人很难回答。

对于您的问题:您基本上有两个问题:首先是符号Caller, second withParam`,两者基本相同。

对于问题的根源:UBSAN 将指针的 typeinfo 与预期的 typeinfo 进行比较。如果 typeinfo 不同,则会显示错误。 typeinfo 比较是通过指针比较来完成的。这对速度很有好处,但引入了一个微妙的问题:即使实际类型实际上相同,它们也可能不会共享相同的typeinfo。当您从共享库中抛出一个类型并希望在可执行文件中捕获它(反之亦然)时,这一点也很重要:捕获是通过 typeinfo 比较完成的,如果两种类型不完全相同(共享相同的 typeinfo)你不会抓住它的。

所以您的第一个问题是class EXPORT_Library Caller:您有条件地将EXPORT_Library 定义为“导出”或不“导出”。如果它是从多个 DSO 导出的,那么 typeinfos 将被合并。在您的情况下,您将其导出到共享库中,而不是在阻止合并它们的可执行文件中。您可以为此使用BOOST_SYMBOL_EXPORTOW_EXPORT

第二个问题是相反的(假设EXPORT_Library==OW_EXPORT):Param 是在包含 Param.h 标头时导出的,这仅由可执行文件完成,而不是由共享库完成。同样 typeinfos 没有合并 -> RTTI 系统的不同类型。

底线:导出所有要在 DSO 边界上使用的类。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2015-05-06
    • 1970-01-01
    • 2015-10-23
    • 1970-01-01
    • 1970-01-01
    • 2012-08-20
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多