[llvm] 2fabed5 - [SPIR-V] Diagnose out-of-bounds argument index in function type metadata (#200601)

via llvm-commits llvm-commits at lists.llvm.org
Wed Jun 3 04:17:33 PDT 2026


Author: Arseniy Obolenskiy
Date: 2026-06-03T13:17:27+02:00
New Revision: 2fabed5f49d950b669b9f9a5a624d61aa8bdeda0

URL: https://github.com/llvm/llvm-project/commit/2fabed5f49d950b669b9f9a5a624d61aa8bdeda0
DIFF: https://github.com/llvm/llvm-project/commit/2fabed5f49d950b669b9f9a5a624d61aa8bdeda0.diff

LOG: [SPIR-V] Diagnose out-of-bounds argument index in function type metadata (#200601)

The argument index in spv.cloned_funcs/spv.mutated_callsites metadata
was used to index the parameter list with only a lower bound assert

Add boundaries check it and report_fatal_error rather than silently
miscompiling

Added: 
    llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll

Modified: 
    llvm/lib/Target/SPIRV/SPIRVUtils.cpp

Removed: 
    


################################################################################
diff  --git a/llvm/lib/Target/SPIRV/SPIRVUtils.cpp b/llvm/lib/Target/SPIRV/SPIRVUtils.cpp
index 0ef31f4182b4e..6c5619c4585ef 100644
--- a/llvm/lib/Target/SPIRV/SPIRVUtils.cpp
+++ b/llvm/lib/Target/SPIRV/SPIRVUtils.cpp
@@ -66,13 +66,18 @@ static FunctionType *extractFunctionTypeFromMetadata(NamedMDNode *NMD,
     if (auto *Const = getConstInt(MD, 0)) {
       auto *CMeta = dyn_cast<ConstantAsMetadata>(MD->getOperand(1));
       assert(CMeta && "ConstantAsMetadata operand is expected");
-      assert(Const->getSExtValue() >= -1);
+      int64_t Idx = Const->getSExtValue();
       // Currently -1 indicates return value, greater values mean
       // argument numbers.
-      if (Const->getSExtValue() == -1)
+      if (Idx == -1) {
         RetTy = CMeta->getType();
-      else
-        PTys[Const->getSExtValue()] = CMeta->getType();
+        continue;
+      }
+      if (Idx >= 0 && static_cast<uint64_t>(Idx) < PTys.size()) {
+        PTys[Idx] = CMeta->getType();
+        continue;
+      }
+      report_fatal_error("invalid argument index in function type metadata");
     }
   }
 

diff  --git a/llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll b/llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll
new file mode 100644
index 0000000000000..cd9ecba35a688
--- /dev/null
+++ b/llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll
@@ -0,0 +1,15 @@
+; Malformed spv.cloned_funcs metadata referencing an argument index past the
+; end of the parameter list must be diagnosed, not cause an out-of-bounds write.
+
+; RUN: not --crash llc -O0 -mtriple=spirv64-unknown-unknown %s -o - 2>&1 | FileCheck %s
+
+; CHECK: invalid argument index in function type metadata
+
+define i32 @foo(i32 %x) {
+  ret i32 %x
+}
+
+; Index 5 is out of range for the single-parameter function.
+!spv.cloned_funcs = !{!0}
+!0 = !{!"foo", !1}
+!1 = !{i32 5, <4 x i32> zeroinitializer}


        


More information about the llvm-commits mailing list