[llvm] [BPF] Fix out-of-bounds write in fillGenericConstant (PR #203759)
Quanye Yang via llvm-commits
llvm-commits at lists.llvm.org
Mon Jun 29 23:08:28 PDT 2026
quanyeyang wrote:
Thanks everyone for the reviews.
I'll close this PR for now. Summary of my understanding:
- The crash is reachable from valid LLVM IR/bitcode (as in the original fuzzer PoC
and the reduced `.ll` test), but not from C due to Clang's 2^60 struct size limit.
- I agree the overflow check belongs in `getConstantFieldValue()` rather than a
generic bounds check in `fillGenericConstant()`, as @eddyz87 suggested.
- I also understand @yonghong-song and @4ast's concern about adding defensive
checks for fuzzer-only inputs.
If the BPF maintainers decide this is worth fixing, I'm happy to revisit with
an overflow check in `getConstantFieldValue()`.
Closing as not planned for now.
https://github.com/llvm/llvm-project/pull/203759
More information about the llvm-commits
mailing list