[llvm] [Support] Disable CFI on typed Allocate to unconstructed storage (PR #217992)

via llvm-commits llvm-commits at lists.llvm.org
Fri Aug 21 11:03:35 PDT 2026


https://github.com/compilersutra created https://github.com/llvm/llvm-project/pull/217992

## Summary
- `AllocatorBase::Allocate<T>()` / `SpecificBumpPtrAllocator::Allocate()` return a typed pointer to unconstructed storage for placement-new.
- Under `-fsanitize=cfi`, `cfi-unrelated-cast` checks that pointer as if it were already a live object and traps (`ud1`) before the constructor runs (e.g. `MachineFunctionInfo::create` in a CFI+ThinLTO `llc`).
- Disable CFI on those allocate helpers, matching the libc++ `_LIBCPP_NO_CFI` pattern for the same class of false positive.

Fixes #217818

## Test plan
- [x] Rebuild CFI-instrumented `llc` (ThinLTO + `-fsanitize=cfi`)
- [x] `llvm-lit -sv llvm/test/Analysis/CostModel/AArch64/free-widening-casts.ll` → Passed
- [x] Direct repro no longer SIGILL:
  `llc free-widening-casts.ll -mtriple=aarch64--linux-gnu -o /tmp/out.s`
- [ ] `ninja check-llvm` on CFI build (failures drop substantially; remaining fails are unrelated)


Made with [Cursor](https://cursor.com)

>From 94fcf002999030d917c6d601b2e30f5d78cf56c8 Mon Sep 17 00:00:00 2001
From: compilersutra <osc at compilersutra.com>
Date: Fri, 21 Aug 2026 23:33:01 +0530
Subject: [PATCH] [Support] Disable CFI on typed Allocate to unconstructed
 storage

BumpPtrAllocator's Allocate<T>() returns a T* for placement-new before
the object exists. cfi-unrelated-cast treats that as a live object and
traps (e.g. MachineFunctionInfo::create under a CFI+ThinLTO build).

Matches the libc++ approach of suppressing CFI on this pattern.

Fixes #217818

Co-authored-by: Cursor <cursoragent at cursor.com>
---
 llvm/include/llvm/Support/Allocator.h     | 3 ++-
 llvm/include/llvm/Support/AllocatorBase.h | 3 ++-
 2 files changed, 4 insertions(+), 2 deletions(-)

diff --git a/llvm/include/llvm/Support/Allocator.h b/llvm/include/llvm/Support/Allocator.h
index bb0ca118e2015..31d38e0eaf787 100644
--- a/llvm/include/llvm/Support/Allocator.h
+++ b/llvm/include/llvm/Support/Allocator.h
@@ -450,7 +450,8 @@ template <typename T> class SpecificBumpPtrAllocator {
   }
 
   /// Allocate space for an array of objects without constructing them.
-  T *Allocate(size_t num = 1) {
+  // CFI: typed pointer to unconstructed storage for placement-new.
+  LLVM_NO_SANITIZE("cfi") T *Allocate(size_t num = 1) {
     // Slabs are max_align_t-aligned and every size is a multiple of alignof(T),
     // so the bump pointer is already alignof(T)-aligned. Request alignment 1 so
     // the fast path skips realigning CurPtr; over-aligned T still needs it.
diff --git a/llvm/include/llvm/Support/AllocatorBase.h b/llvm/include/llvm/Support/AllocatorBase.h
index 6414c5dc5122c..ff604c7d49496 100644
--- a/llvm/include/llvm/Support/AllocatorBase.h
+++ b/llvm/include/llvm/Support/AllocatorBase.h
@@ -73,7 +73,8 @@ template <typename DerivedT> class AllocatorBase {
   // core methods.
 
   /// Allocate space for a sequence of objects without constructing them.
-  template <typename T> T *Allocate(size_t Num = 1) {
+  // CFI: typed pointer to unconstructed storage for placement-new.
+  template <typename T> LLVM_NO_SANITIZE("cfi") T *Allocate(size_t Num = 1) {
     return static_cast<T *>(Allocate(Num * sizeof(T), alignof(T)));
   }
 



More information about the llvm-commits mailing list