[llvm] [IR] Fix null pointer dereference in Constant::toConstantRange() for ConstantByte (PR #193874)
Jim Lin via llvm-commits
llvm-commits at lists.llvm.org
Thu Apr 23 17:56:05 PDT 2026
https://github.com/tclin914 created https://github.com/llvm/llvm-project/pull/193874
In the ConstantVector path of toConstantRange(), the code checks that each element is either a ConstantInt or ConstantByte but unconditionally dereferences the ConstantInt pointer to get the value. When the element is a ConstantByte, the ConstantInt pointer is null, causing a crash.
This was introduced in 57568c288dbe when ConstantByte support was added to toConstantRange() but the fallback to CB->getValue() was missed.
>From 0cffc3de667e0c952701fc247c1a01ee965abb5a Mon Sep 17 00:00:00 2001
From: Jim Lin <jim at andestech.com>
Date: Fri, 24 Apr 2026 00:19:03 +0000
Subject: [PATCH] [IR] Fix null pointer dereference in
Constant::toConstantRange() for ConstantByte
In the ConstantVector path of toConstantRange(), the code checks that
each element is either a ConstantInt or ConstantByte but unconditionally
dereferences the ConstantInt pointer to get the value. When the element
is a ConstantByte, the ConstantInt pointer is null, causing a crash.
This was introduced in 57568c288dbe when ConstantByte support was added
to toConstantRange() but the fallback to CB->getValue() was missed.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply at anthropic.com>
---
llvm/lib/IR/Constants.cpp | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/llvm/lib/IR/Constants.cpp b/llvm/lib/IR/Constants.cpp
index f07ce527c1240..11b8518830884 100644
--- a/llvm/lib/IR/Constants.cpp
+++ b/llvm/lib/IR/Constants.cpp
@@ -1989,7 +1989,7 @@ ConstantRange Constant::toConstantRange() const {
auto *CB = dyn_cast<ConstantByte>(Elem);
if (!CI && !CB)
return ConstantRange::getFull(BitWidth);
- CR = CR.unionWith(CI->getValue());
+ CR = CR.unionWith(CI ? CI->getValue() : CB->getValue());
}
return CR;
}
More information about the llvm-commits
mailing list