[llvm] 85f694b - [ASan] Convert pointer-pair operands based on type (#218494)

via llvm-commits llvm-commits at lists.llvm.org
Sun Sep 13 10:48:47 PDT 2026


Author: ʟᴜɴᴇx
Date: 2026-09-13T10:48:42-07:00
New Revision: 85f694b3eeafc07e5c586fa15715facefba71094

URL: https://github.com/llvm/llvm-project/commit/85f694b3eeafc07e5c586fa15715facefba71094
DIFF: https://github.com/llvm/llvm-project/commit/85f694b3eeafc07e5c586fa15715facefba71094.diff

LOG: [ASan] Convert pointer-pair operands based on type (#218494)

`CreatePointerCast` was being called on everything without checking what
it actually is, so if the operand came from ptrtoint ... to i32 it just
crashes (its not a pointer).

now it check the type first - pointers get pointer-cast, ints get
zext/trunc'd to intptr width.

Fixes #217544

also edited regression tests for this

Added: 
    

Modified: 
    llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
    llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll

Removed: 
    


################################################################################
diff  --git a/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp b/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
index c5576f31cfe46..451a60c5b6ecd 100644
--- a/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
+++ b/llvm/lib/Transforms/Instrumentation/AddressSanitizer.cpp
@@ -1693,11 +1693,23 @@ bool AddressSanitizer::GlobalIsLinkerInitialized(GlobalVariable *G) {
   return true;
 }
 
+static bool isPointerPairOperand(Value *V, Type *IntptrTy) {
+  Type *Ty = V->getType();
+  if (Ty->isPtrOrPtrVectorTy())
+    return true;
+  return Ty->isIntOrIntVectorTy() &&
+         Ty->getScalarSizeInBits() == IntptrTy->getScalarSizeInBits();
+}
+
 bool AddressSanitizer::instrumentPointerComparisonOrSubtraction(
     Instruction *I, RuntimeCallInserter &RTCI) {
+  Value *Param[2] = {I->getOperand(0), I->getOperand(1)};
+  if (!isPointerPairOperand(Param[0], IntptrTy) ||
+      !isPointerPairOperand(Param[1], IntptrTy))
+    return false;
+
   IRBuilder<> IRB(I);
   FunctionCallee F = isa<ICmpInst>(I) ? AsanPtrCmpFunction : AsanPtrSubFunction;
-  Value *Param[2] = {I->getOperand(0), I->getOperand(1)};
 
   if (const auto *Ty = Param[0]->getType(); Ty->isVectorTy()) {
     const auto *VTy = dyn_cast<FixedVectorType>(Ty);

diff  --git a/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll b/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
index 7632a79436662..b8cc2b30343fd 100644
--- a/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
+++ b/llvm/test/Instrumentation/AddressSanitizer/asan-detect-invalid-pointer-pair.ll
@@ -71,3 +71,30 @@ define <2 x i1> @mycmp_vector(<2 x ptr> %p, <2 x ptr> %q) sanitize_address {
   %z = icmp ult <2 x i64> %x, %y
   ret <2 x i1> %z
 }
+
+define i32 @mysub_ptrtoint_trunc(ptr %p, ptr %q) sanitize_address {
+; ALL-LABEL: @mysub_ptrtoint_trunc
+; ALL-NOT: call void @__sanitizer_ptr_sub
+  %x = ptrtoint ptr %p to i32
+  %y = ptrtoint ptr %q to i32
+  %z = sub i32 %x, %y
+  ret i32 %z
+}
+
+define <2 x i32> @mysub_vector_ptrtoint_trunc(<2 x ptr> %p, <2 x ptr> %q) sanitize_address {
+; ALL-LABEL: @mysub_vector_ptrtoint_trunc
+; ALL-NOT: call void @__sanitizer_ptr_sub
+  %x = ptrtoint <2 x ptr> %p to <2 x i32>
+  %y = ptrtoint <2 x ptr> %q to <2 x i32>
+  %z = sub <2 x i32> %x, %y
+  ret <2 x i32> %z
+}
+
+define i128 @mysub_ptrtoint_widen(ptr %p, ptr %q) sanitize_address {
+; ALL-LABEL: @mysub_ptrtoint_widen
+; ALL-NOT: call void @__sanitizer_ptr_sub
+  %x = ptrtoint ptr %p to i128
+  %y = ptrtoint ptr %q to i128
+  %z = sub i128 %x, %y
+  ret i128 %z
+}


        


More information about the llvm-commits mailing list