[llvm] 2fabed5 - [SPIR-V] Diagnose out-of-bounds argument index in function type metadata (#200601)
via llvm-commits
llvm-commits at lists.llvm.org
Wed Jun 3 04:17:33 PDT 2026
Author: Arseniy Obolenskiy
Date: 2026-06-03T13:17:27+02:00
New Revision: 2fabed5f49d950b669b9f9a5a624d61aa8bdeda0
URL: https://github.com/llvm/llvm-project/commit/2fabed5f49d950b669b9f9a5a624d61aa8bdeda0
DIFF: https://github.com/llvm/llvm-project/commit/2fabed5f49d950b669b9f9a5a624d61aa8bdeda0.diff
LOG: [SPIR-V] Diagnose out-of-bounds argument index in function type metadata (#200601)
The argument index in spv.cloned_funcs/spv.mutated_callsites metadata
was used to index the parameter list with only a lower bound assert
Add boundaries check it and report_fatal_error rather than silently
miscompiling
Added:
llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll
Modified:
llvm/lib/Target/SPIRV/SPIRVUtils.cpp
Removed:
################################################################################
diff --git a/llvm/lib/Target/SPIRV/SPIRVUtils.cpp b/llvm/lib/Target/SPIRV/SPIRVUtils.cpp
index 0ef31f4182b4e..6c5619c4585ef 100644
--- a/llvm/lib/Target/SPIRV/SPIRVUtils.cpp
+++ b/llvm/lib/Target/SPIRV/SPIRVUtils.cpp
@@ -66,13 +66,18 @@ static FunctionType *extractFunctionTypeFromMetadata(NamedMDNode *NMD,
if (auto *Const = getConstInt(MD, 0)) {
auto *CMeta = dyn_cast<ConstantAsMetadata>(MD->getOperand(1));
assert(CMeta && "ConstantAsMetadata operand is expected");
- assert(Const->getSExtValue() >= -1);
+ int64_t Idx = Const->getSExtValue();
// Currently -1 indicates return value, greater values mean
// argument numbers.
- if (Const->getSExtValue() == -1)
+ if (Idx == -1) {
RetTy = CMeta->getType();
- else
- PTys[Const->getSExtValue()] = CMeta->getType();
+ continue;
+ }
+ if (Idx >= 0 && static_cast<uint64_t>(Idx) < PTys.size()) {
+ PTys[Idx] = CMeta->getType();
+ continue;
+ }
+ report_fatal_error("invalid argument index in function type metadata");
}
}
diff --git a/llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll b/llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll
new file mode 100644
index 0000000000000..cd9ecba35a688
--- /dev/null
+++ b/llvm/test/CodeGen/SPIRV/cloned-funcs-metadata-oob.ll
@@ -0,0 +1,15 @@
+; Malformed spv.cloned_funcs metadata referencing an argument index past the
+; end of the parameter list must be diagnosed, not cause an out-of-bounds write.
+
+; RUN: not --crash llc -O0 -mtriple=spirv64-unknown-unknown %s -o - 2>&1 | FileCheck %s
+
+; CHECK: invalid argument index in function type metadata
+
+define i32 @foo(i32 %x) {
+ ret i32 %x
+}
+
+; Index 5 is out of range for the single-parameter function.
+!spv.cloned_funcs = !{!0}
+!0 = !{!"foo", !1}
+!1 = !{i32 5, <4 x i32> zeroinitializer}
More information about the llvm-commits
mailing list