[llvm] 2a9a78d - [IR] Fix null pointer dereference in Constant::toConstantRange() for ConstantByte (#193874)
via llvm-commits
llvm-commits at lists.llvm.org
Wed May 6 22:58:38 PDT 2026
Author: Jim Lin
Date: 2026-05-07T13:58:02+08:00
New Revision: 2a9a78d0eec8a3a4a75c565f552443114d476217
URL: https://github.com/llvm/llvm-project/commit/2a9a78d0eec8a3a4a75c565f552443114d476217
DIFF: https://github.com/llvm/llvm-project/commit/2a9a78d0eec8a3a4a75c565f552443114d476217.diff
LOG: [IR] Fix null pointer dereference in Constant::toConstantRange() for ConstantByte (#193874)
In the ConstantVector path of toConstantRange(), the code checks that
each element is either a ConstantInt or ConstantByte but unconditionally
dereferences the ConstantInt pointer to get the value. When the element
is a ConstantByte, the ConstantInt pointer is null, causing a crash.
This was introduced in 57568c288dbe when ConstantByte support was added
to toConstantRange() but the fallback to CB->getValue() was missed.
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply at anthropic.com>
Added:
Modified:
llvm/lib/IR/Constants.cpp
llvm/unittests/IR/ConstantsTest.cpp
Removed:
################################################################################
diff --git a/llvm/lib/IR/Constants.cpp b/llvm/lib/IR/Constants.cpp
index ed30b5dac51fd..6294a9d9efec6 100644
--- a/llvm/lib/IR/Constants.cpp
+++ b/llvm/lib/IR/Constants.cpp
@@ -2030,7 +2030,7 @@ ConstantRange Constant::toConstantRange() const {
auto *CB = dyn_cast<ConstantByte>(Elem);
if (!CI && !CB)
return ConstantRange::getFull(BitWidth);
- CR = CR.unionWith(CI->getValue());
+ CR = CR.unionWith(CI ? CI->getValue() : CB->getValue());
}
return CR;
}
diff --git a/llvm/unittests/IR/ConstantsTest.cpp b/llvm/unittests/IR/ConstantsTest.cpp
index 60fde98c129ac..b97d38a7b37ad 100644
--- a/llvm/unittests/IR/ConstantsTest.cpp
+++ b/llvm/unittests/IR/ConstantsTest.cpp
@@ -10,6 +10,7 @@
#include "llvm-c/Core.h"
#include "llvm/AsmParser/Parser.h"
#include "llvm/IR/ConstantFold.h"
+#include "llvm/IR/ConstantRange.h"
#include "llvm/IR/DerivedTypes.h"
#include "llvm/IR/InstrTypes.h"
#include "llvm/IR/Instruction.h"
@@ -896,5 +897,27 @@ TEST(ConstantsTest, Float128Test) {
LLVMContextDispose(C);
}
+TEST(ConstantsTest, ToConstantRangeConstantByteVector) {
+ LLVMContext Context;
+ // Use 7-bit ByteType so the vector is not folded into ConstantDataVector
+ // (ConstantDataSequential only supports 8/16/32/64-bit element types).
+ ByteType *B7Ty = Type::getByteNTy(Context, 7);
+
+ ConstantByte *CB1 = ConstantByte::get(B7Ty, 10);
+ ConstantByte *CB2 = ConstantByte::get(B7Ty, 20);
+ Constant *Elts[] = {CB1, CB2};
+ Constant *CV = ConstantVector::get(Elts);
+ ASSERT_TRUE(isa<ConstantVector>(CV));
+
+ ConstantRange CR = CV->toConstantRange();
+ EXPECT_EQ(CR, ConstantRange(APInt(7, 10), APInt(7, 21)));
+
+ Constant *CVWithPoison =
+ ConstantVector::get({CB1, PoisonValue::get(B7Ty), CB2});
+ ASSERT_TRUE(isa<ConstantVector>(CVWithPoison));
+ ConstantRange CRPoison = CVWithPoison->toConstantRange();
+ EXPECT_EQ(CRPoison, ConstantRange(APInt(7, 10), APInt(7, 21)));
+}
+
} // end anonymous namespace
} // end namespace llvm
More information about the llvm-commits
mailing list