[llvm] [llubi] Add basic support for provenance modeling (PR #185977)

Ralf Jung via llvm-commits llvm-commits at lists.llvm.org
Thu Jun 4 09:19:13 PDT 2026


================
@@ -27,15 +27,18 @@ class AnyValue;
 /// - If the concrete mask bit is 0, the bit is either undef or poison. The
 /// value bit indicates whether it is undef.
 /// - If the concrete mask bit is 1, the bit is a concrete value. The value bit
-/// stores the concrete bit value.
+/// stores the concrete bit value. The tag mask bit indicates whether it is a
+/// pointer bit, and the tag value bit is used for provenance tracking of
+/// pointers.
 struct Byte {
   uint8_t ConcreteMask;
   uint8_t Value;
-  // TODO: captured capabilities of pointers.
+  uint8_t TagMask;  // A mask to indicate which bits are pointer bits.
+  uint8_t TagValue; // Part of the tag for provenance tracking of pointers.
----------------
RalfJung wrote:

(Sorry for being late to the party)

So... the provenance is only one bit per bit / one byte per byte? I don't see how this can represent all possible values. In general, every byte in memory could have different provenance than its neighbors.

Is the idea that if you reorder the bytes / don't put them back together the right way, the 64-bit-tag will probably not be valid (since they are random)? That is quite clever, and only works because we said that for now you do have to put the bytes back together in the original order. However, I have to say, as a person mostly concerned with strict formal guarantees, this probabilistic approach leaves me somewhat uneasy.^^

https://github.com/llvm/llvm-project/pull/185977


More information about the llvm-commits mailing list