[llvm] [BPF] Fix out-of-bounds write in fillGenericConstant (PR #203759)

Quanye Yang via llvm-commits llvm-commits at lists.llvm.org
Mon Jun 29 23:08:28 PDT 2026


quanyeyang wrote:

Thanks everyone for the reviews.

I'll close this PR for now. Summary of my understanding:

- The crash is reachable from valid LLVM IR/bitcode (as in the original fuzzer PoC
  and the reduced `.ll` test), but not from C due to Clang's 2^60 struct size limit.
- I agree the overflow check belongs in `getConstantFieldValue()` rather than a
  generic bounds check in `fillGenericConstant()`, as @eddyz87 suggested.
- I also understand @yonghong-song and @4ast's concern about adding defensive
  checks for fuzzer-only inputs.

If the BPF maintainers decide this is worth fixing, I'm happy to revisit with
an overflow check in `getConstantFieldValue()`.

Closing as not planned for now.

https://github.com/llvm/llvm-project/pull/203759


More information about the llvm-commits mailing list