[compiler-rt] [libFuzzer] Clamp `ConsumeFloatingPointInRange` result to `max` (PR #221552)

Stan Ulbrych via llvm-commits llvm-commits at lists.llvm.org
Tue Sep 8 07:16:54 PDT 2026


https://github.com/StanFromIreland updated https://github.com/llvm/llvm-project/pull/221552

>From a0a7d67107e0d8279fc0a996e40bd8ba9068de1f Mon Sep 17 00:00:00 2001
From: Stan Ulbrych <stan at python.org>
Date: Sun, 6 Sep 2026 11:38:14 +0100
Subject: [PATCH 1/3] [libFuzzer] Clamp ConsumeFloatingPointInRange result to
 max

Fixes #65312. Floating point rounding could push the result above `max`, or even overflow to infinity, so we clamp it instead.
---
 .../include/fuzzer/FuzzedDataProvider.h       |  7 ++++-
 .../tests/FuzzedDataProviderUnittest.cpp      | 27 +++++++++++++++++++
 2 files changed, 33 insertions(+), 1 deletion(-)

diff --git a/compiler-rt/include/fuzzer/FuzzedDataProvider.h b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
index 5fab0c46829d2..cf2153b496767 100644
--- a/compiler-rt/include/fuzzer/FuzzedDataProvider.h
+++ b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
@@ -265,7 +265,12 @@ T FuzzedDataProvider::ConsumeFloatingPointInRange(T min, T max) {
     range = max - min;
   }
 
-  return result + range * ConsumeProbability<T>();
+  result += range * ConsumeProbability<T>();
+
+  // Rounding can push the resul above |max|, although never below |min|. Clamp it.
+  if (result > max)
+    return max;
+  return result;
 }
 
 // Returns a floating point number in the range [0.0, 1.0]. If there's no
diff --git a/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp b/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp
index ea6774e5a5cda..5d61846a17592 100644
--- a/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp
+++ b/compiler-rt/lib/fuzzer/tests/FuzzedDataProviderUnittest.cpp
@@ -425,6 +425,33 @@ TEST(FuzzedDataProvider, ConsumeFloatingPoint) {
                                        -13.37, 31.337));
 }
 
+TEST(FuzzedDataProvider, ConsumeFloatingPointInRangeUpperBound) {
+  const std::vector<uint8_t> AllOnes(32, 0xff);
+  FuzzedDataProvider DataProv(AllOnes.data(), AllOnes.size());
+
+  // |max - min| overflows, and min + range + range overflows to infinity.
+  EXPECT_EQ(std::numeric_limits<float>::max(),
+            DataProv.ConsumeFloatingPointInRange<float>(
+                float(-1.3036394e+38), std::numeric_limits<float>::max()));
+  EXPECT_EQ(std::numeric_limits<double>::max(),
+            DataProv.ConsumeFloatingPointInRange<double>(
+                double(-1.3036394035928049e+308),
+                std::numeric_limits<double>::max()));
+
+  // |max - min| overflows, and the result is finite but above |max|.
+  EXPECT_EQ(float(2.2690335e+37),
+            DataProv.ConsumeFloatingPointInRange<float>(float(-3.1759686e+38),
+                                                        float(2.2690335e+37)));
+
+  // |max - min| does not overflow, but rounds to -min, so min + range is 0.
+  EXPECT_EQ(float(-1.0), DataProv.ConsumeFloatingPointInRange<float>(
+                             float(-1e20), float(-1.0)));
+  EXPECT_EQ(double(-1.0), DataProv.ConsumeFloatingPointInRange<double>(
+                              double(-1e30), double(-1.0)));
+
+  EXPECT_EQ(size_t(1), DataProv.remaining_bytes());
+}
+
 TEST(FuzzedDataProvider, ConsumeData) {
   FuzzedDataProvider DataProv(Data, sizeof(Data));
   uint8_t Buffer[10] = {};

>From 0e980f7bf1f5aa6c489f3d7a1cbe4ffbaac432f0 Mon Sep 17 00:00:00 2001
From: Stan Ulbrych <stan at python.org>
Date: Sun, 6 Sep 2026 11:47:35 +0100
Subject: [PATCH 2/3] `git-clang-format`

---
 compiler-rt/include/fuzzer/FuzzedDataProvider.h | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/compiler-rt/include/fuzzer/FuzzedDataProvider.h b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
index cf2153b496767..23b9f092b7a81 100644
--- a/compiler-rt/include/fuzzer/FuzzedDataProvider.h
+++ b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
@@ -267,7 +267,8 @@ T FuzzedDataProvider::ConsumeFloatingPointInRange(T min, T max) {
 
   result += range * ConsumeProbability<T>();
 
-  // Rounding can push the resul above |max|, although never below |min|. Clamp it.
+  // Rounding can push the resul above |max|, although never below |min|. Clamp
+  // it.
   if (result > max)
     return max;
   return result;

>From 7815af3d92c002571abe4321003097d8df9842a5 Mon Sep 17 00:00:00 2001
From: Stan Ulbrych <stan at python.org>
Date: Tue, 8 Sep 2026 15:16:43 +0100
Subject: [PATCH 3/3] Fix typo

Co-authored-by: Dan Blackwell <danblackwell95 at gmail.com>
---
 compiler-rt/include/fuzzer/FuzzedDataProvider.h | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/compiler-rt/include/fuzzer/FuzzedDataProvider.h b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
index 23b9f092b7a81..cb43c818aeb15 100644
--- a/compiler-rt/include/fuzzer/FuzzedDataProvider.h
+++ b/compiler-rt/include/fuzzer/FuzzedDataProvider.h
@@ -267,7 +267,7 @@ T FuzzedDataProvider::ConsumeFloatingPointInRange(T min, T max) {
 
   result += range * ConsumeProbability<T>();
 
-  // Rounding can push the resul above |max|, although never below |min|. Clamp
+  // Rounding can push the result above |max|, although never below |min|. Clamp
   // it.
   if (result > max)
     return max;



More information about the llvm-commits mailing list