[llvm] 85f694b - [ASan] Convert pointer-pair operands based on type (#218494)
via llvm-commits
llvm-commits at lists.llvm.org
Sun Sep 13 10:48:47 PDT 2026
Author: ʟᴜɴᴇx
Date: 2026-09-13T10:48:42-07:00
New Revision: 85f694b3eeafc07e5c586fa15715facefba71094
URL: https://github.com/llvm/llvm-project/commit/85f694b3eeafc07e5c586fa15715facefba71094
DIFF: https://github.com/llvm/llvm-project/commit/85f694b3eeafc07e5c586fa15715facefba71094.diff
LOG: [ASan] Convert pointer-pair operands based on type (#218494)
`CreatePointerCast` was being called on everything without checking what
it actually is, so if the operand came from ptrtoint ... to i32 it just
crashes (its not a pointer).
now it check the type first - pointers get pointer-cast, ints get
zext/trunc'd to intptr width.
Fixes #217544
also edited regression tests for this
Added:
Modified:
llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
Removed:
################################################################################
diff --git a/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp b/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
index c5576f31cfe46..451a60c5b6ecd 100644
--- a/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
+++ b/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
@@ -1693,11 +1693,23 @@ bool AddressSanitizer::GlobalIsLinkerInitialized(GlobalVariable *G) {
return true;
}
+static bool isPointerPairOperand(Value *V, Type *IntptrTy) {
+ Type *Ty = V->getType();
+ if (Ty->isPtrOrPtrVectorTy())
+ return true;
+ return Ty->isIntOrIntVectorTy() &&
+ Ty->getScalarSizeInBits() == IntptrTy->getScalarSizeInBits();
+}
+
bool AddressSanitizer::instrumentPointerComparisonOrSubtraction(
Instruction *I, RuntimeCallInserter &RTCI) {
+ Value *Param[2] = {I->getOperand(0), I->getOperand(1)};
+ if (!isPointerPairOperand(Param[0], IntptrTy) ||
+ !isPointerPairOperand(Param[1], IntptrTy))
+ return false;
+
IRBuilder<> IRB(I);
FunctionCallee F = isa<ICmpInst>(I) ? AsanPtrCmpFunction : AsanPtrSubFunction;
- Value *Param[2] = {I->getOperand(0), I->getOperand(1)};
if (const auto *Ty = Param[0]->getType(); Ty->isVectorTy()) {
const auto *VTy = dyn_cast<FixedVectorType>(Ty);
diff --git a/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll b/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
index 7632a79436662..b8cc2b30343fd 100644
--- a/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
+++ b/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
@@ -71,3 +71,30 @@ define <2 x i1> @mycmp_vector(<2 x ptr> %p, <2 x ptr> %q) sanitize_address {
%z = icmp ult <2 x i64> %x, %y
ret <2 x i1> %z
}
+
+define i32 @mysub_ptrtoint_trunc(ptr %p, ptr %q) sanitize_address {
+; ALL-LABEL: @mysub_ptrtoint_trunc
+; ALL-NOT: call void @__sanitizer_ptr_sub
+ %x = ptrtoint ptr %p to i32
+ %y = ptrtoint ptr %q to i32
+ %z = sub i32 %x, %y
+ ret i32 %z
+}
+
+define <2 x i32> @mysub_vector_ptrtoint_trunc(<2 x ptr> %p, <2 x ptr> %q) sanitize_address {
+; ALL-LABEL: @mysub_vector_ptrtoint_trunc
+; ALL-NOT: call void @__sanitizer_ptr_sub
+ %x = ptrtoint <2 x ptr> %p to <2 x i32>
+ %y = ptrtoint <2 x ptr> %q to <2 x i32>
+ %z = sub <2 x i32> %x, %y
+ ret <2 x i32> %z
+}
+
+define i128 @mysub_ptrtoint_widen(ptr %p, ptr %q) sanitize_address {
+; ALL-LABEL: @mysub_ptrtoint_widen
+; ALL-NOT: call void @__sanitizer_ptr_sub
+ %x = ptrtoint ptr %p to i128
+ %y = ptrtoint ptr %q to i128
+ %z = sub i128 %x, %y
+ ret i128 %z
+}
More information about the llvm-commits
mailing list