[llvm] 2a9a78d - [IR] Fix null pointer dereference in Constant::toConstantRange() for ConstantByte (#193874)

via llvm-commits llvm-commits at lists.llvm.org
Wed May 6 22:58:38 PDT 2026


Author: Jim Lin
Date: 2026-05-07T13:58:02+08:00
New Revision: 2a9a78d0eec8a3a4a75c565f552443114d476217

URL: https://github.com/llvm/llvm-project/commit/2a9a78d0eec8a3a4a75c565f552443114d476217
DIFF: https://github.com/llvm/llvm-project/commit/2a9a78d0eec8a3a4a75c565f552443114d476217.diff

LOG: [IR] Fix null pointer dereference in Constant::toConstantRange() for ConstantByte (#193874)

In the ConstantVector path of toConstantRange(), the code checks that
each element is either a ConstantInt or ConstantByte but unconditionally
dereferences the ConstantInt pointer to get the value. When the element
is a ConstantByte, the ConstantInt pointer is null, causing a crash.

This was introduced in 57568c288dbe when ConstantByte support was added
to toConstantRange() but the fallback to CB->getValue() was missed.

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply at anthropic.com>

Added: 
    

Modified: 
    llvm/lib/IR/Constants.cpp
    llvm/unittests/IR/ConstantsTest.cpp

Removed: 
    


################################################################################
diff  --git a/llvm/lib/IR/Constants.cpp b/llvm/lib/IR/Constants.cpp
index ed30b5dac51fd..6294a9d9efec6 100644
--- a/llvm/lib/IR/Constants.cpp
+++ b/llvm/lib/IR/Constants.cpp
@@ -2030,7 +2030,7 @@ ConstantRange Constant::toConstantRange() const {
       auto *CB = dyn_cast<ConstantByte>(Elem);
       if (!CI && !CB)
         return ConstantRange::getFull(BitWidth);
-      CR = CR.unionWith(CI->getValue());
+      CR = CR.unionWith(CI ? CI->getValue() : CB->getValue());
     }
     return CR;
   }

diff  --git a/llvm/unittests/IR/ConstantsTest.cpp b/llvm/unittests/IR/ConstantsTest.cpp
index 60fde98c129ac..b97d38a7b37ad 100644
--- a/llvm/unittests/IR/ConstantsTest.cpp
+++ b/llvm/unittests/IR/ConstantsTest.cpp
@@ -10,6 +10,7 @@
 #include "llvm-c/Core.h"
 #include "llvm/AsmParser/Parser.h"
 #include "llvm/IR/ConstantFold.h"
+#include "llvm/IR/ConstantRange.h"
 #include "llvm/IR/DerivedTypes.h"
 #include "llvm/IR/InstrTypes.h"
 #include "llvm/IR/Instruction.h"
@@ -896,5 +897,27 @@ TEST(ConstantsTest, Float128Test) {
   LLVMContextDispose(C);
 }
 
+TEST(ConstantsTest, ToConstantRangeConstantByteVector) {
+  LLVMContext Context;
+  // Use 7-bit ByteType so the vector is not folded into ConstantDataVector
+  // (ConstantDataSequential only supports 8/16/32/64-bit element types).
+  ByteType *B7Ty = Type::getByteNTy(Context, 7);
+
+  ConstantByte *CB1 = ConstantByte::get(B7Ty, 10);
+  ConstantByte *CB2 = ConstantByte::get(B7Ty, 20);
+  Constant *Elts[] = {CB1, CB2};
+  Constant *CV = ConstantVector::get(Elts);
+  ASSERT_TRUE(isa<ConstantVector>(CV));
+
+  ConstantRange CR = CV->toConstantRange();
+  EXPECT_EQ(CR, ConstantRange(APInt(7, 10), APInt(7, 21)));
+
+  Constant *CVWithPoison =
+      ConstantVector::get({CB1, PoisonValue::get(B7Ty), CB2});
+  ASSERT_TRUE(isa<ConstantVector>(CVWithPoison));
+  ConstantRange CRPoison = CVWithPoison->toConstantRange();
+  EXPECT_EQ(CRPoison, ConstantRange(APInt(7, 10), APInt(7, 21)));
+}
+
 } // end anonymous namespace
 } // end namespace llvm


        


More information about the llvm-commits mailing list