[compiler-rt] [libFuzzer] Clamp `ConsumeFloatingPointInRange` result to `max` (PR #221552)
Stan Ulbrych via llvm-commits
llvm-commits at lists.llvm.org
Tue Sep 8 07:16:54 PDT 2026
https://github.com/StanFromIreland updated https://github.com/llvm/llvm-project/pull/221552
>From a0a7d67107e0d8279fc0a996e40bd8ba9068de1f Mon Sep 17 00:00:00 2001
From: Stan Ulbrych <stan at python.org>
Date: Sun, 6 Sep 2026 11:38:14 +0100
Subject: [PATCH 1/3] [libFuzzer] Clamp ConsumeFloatingPointInRange result to
max
Fixes #65312. Floating point rounding could push the result above `max`, or even overflow to infinity, so we clamp it instead.
---
.../include/fuzzer/FuzzedDataProvider.h | 7 ++++-
.../tests/FuzzedDataProviderUnittest.cpp | 27 +++++++++++++++++++
2 files changed, 33 insertions(+), 1 deletion(-)
diff --git a/compiler-rt/include/fuzzer/FuzzedDataProvider.h b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
index 5fab0c46829d2..cf2153b496767 100644
--- a/compiler-rt/include/fuzzer/FuzzedDataProvider.h
+++ b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
@@ -265,7 +265,12 @@ T FuzzedDataProvider::ConsumeFloatingPointInRange(T min, T max) {
range = max - min;
}
- return result + range * ConsumeProbability<T>();
+ result += range * ConsumeProbability<T>();
+
+ // Rounding can push the resul above |max|, although never below |min|. Clamp it.
+ if (result > max)
+ return max;
+ return result;
}
// Returns a floating point number in the range [0.0, 1.0]. If there's no
diff --git a/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp b/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp
index ea6774e5a5cda..5d61846a17592 100644
--- a/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp
+++ b/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp
@@ -425,6 +425,33 @@ TEST(FuzzedDataProvider, ConsumeFloatingPoint) {
-13.37, 31.337));
}
+TEST(FuzzedDataProvider, ConsumeFloatingPointInRangeUpperBound) {
+ const std::vector<uint8_t> AllOnes(32, 0xff);
+ FuzzedDataProvider DataProv(AllOnes.data(), AllOnes.size());
+
+ // |max - min| overflows, and min + range + range overflows to infinity.
+ EXPECT_EQ(std::numeric_limits<float>::max(),
+ DataProv.ConsumeFloatingPointInRange<float>(
+ float(-1.3036394e+38), std::numeric_limits<float>::max()));
+ EXPECT_EQ(std::numeric_limits<double>::max(),
+ DataProv.ConsumeFloatingPointInRange<double>(
+ double(-1.3036394035928049e+308),
+ std::numeric_limits<double>::max()));
+
+ // |max - min| overflows, and the result is finite but above |max|.
+ EXPECT_EQ(float(2.2690335e+37),
+ DataProv.ConsumeFloatingPointInRange<float>(float(-3.1759686e+38),
+ float(2.2690335e+37)));
+
+ // |max - min| does not overflow, but rounds to -min, so min + range is 0.
+ EXPECT_EQ(float(-1.0), DataProv.ConsumeFloatingPointInRange<float>(
+ float(-1e20), float(-1.0)));
+ EXPECT_EQ(double(-1.0), DataProv.ConsumeFloatingPointInRange<double>(
+ double(-1e30), double(-1.0)));
+
+ EXPECT_EQ(size_t(1), DataProv.remaining_bytes());
+}
+
TEST(FuzzedDataProvider, ConsumeData) {
FuzzedDataProvider DataProv(Data, sizeof(Data));
uint8_t Buffer[10] = {};
>From 0e980f7bf1f5aa6c489f3d7a1cbe4ffbaac432f0 Mon Sep 17 00:00:00 2001
From: Stan Ulbrych <stan at python.org>
Date: Sun, 6 Sep 2026 11:47:35 +0100
Subject: [PATCH 2/3] `git-clang-format`
---
compiler-rt/include/fuzzer/FuzzedDataProvider.h | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/compiler-rt/include/fuzzer/FuzzedDataProvider.h b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
index cf2153b496767..23b9f092b7a81 100644
--- a/compiler-rt/include/fuzzer/FuzzedDataProvider.h
+++ b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
@@ -267,7 +267,8 @@ T FuzzedDataProvider::ConsumeFloatingPointInRange(T min, T max) {
result += range * ConsumeProbability<T>();
- // Rounding can push the resul above |max|, although never below |min|. Clamp it.
+ // Rounding can push the resul above |max|, although never below |min|. Clamp
+ // it.
if (result > max)
return max;
return result;
>From 7815af3d92c002571abe4321003097d8df9842a5 Mon Sep 17 00:00:00 2001
From: Stan Ulbrych <stan at python.org>
Date: Tue, 8 Sep 2026 15:16:43 +0100
Subject: [PATCH 3/3] Fix typo
Co-authored-by: Dan Blackwell <danblackwell95 at gmail.com>
---
compiler-rt/include/fuzzer/FuzzedDataProvider.h | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/compiler-rt/include/fuzzer/FuzzedDataProvider.h b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
index 23b9f092b7a81..cb43c818aeb15 100644
--- a/compiler-rt/include/fuzzer/FuzzedDataProvider.h
+++ b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
@@ -267,7 +267,7 @@ T FuzzedDataProvider::ConsumeFloatingPointInRange(T min, T max) {
result += range * ConsumeProbability<T>();
- // Rounding can push the resul above |max|, although never below |min|. Clamp
+ // Rounding can push the result above |max|, although never below |min|. Clamp
// it.
if (result > max)
return max;
More information about the llvm-commits
mailing list