Thanks both of you for the help. I just missed that Create function had
many optional arguments... sorry for that. However my problem wasn't coming
from here (IRBuilder CreateCall function still return a pointer to CallInst
so I just added 2 times the call?). I didn't wanted to detail the all issue
previously because I knew I had a problem with my syntax. So here's my

I am doing this replacement operation in a FunctionPass (this is no
restriction, I could do it on a ModulePass if that's a solution). On each
Function given I do an iteration over the instructions and replace (if it's
a call to the right function) the call. It's like this:

bool FDPFunction::runOnFunction(Function &F) {
  bool res = false;
  TLI = &getAnalysis<TargetLibraryInfoWrapperPass>().getTLI();

  for (inst_iterator i = inst_begin(F), e = inst_end(F); i != e; ++i) {
    Instruction *I = &*i;

    if (!I) {
      errs() << "error: null pointer instruction\n";
    } else if (isMyFunctionCall(I, TLI)) {
      errs() << "found a call to the function to replace\n";
      res = true;
    } else {
      errs() << "default: trash instruction\n";

  return res;

The problem is that after the first replacement, the iterator becomes a
null pointer. With the break instruction the program is correctly
instrumented for the first call (about that: what is the use of
replaceAllUsesWith function? I thought it would replace all uses of the
function... but just one is done). I can then link it and execute with lli
(I still get a: "*** Error in `lli': corrupted double-linked list:
0xaddress ***" but after the whole execution is done).

But if I remove the break and the if condition associated, well I get a
null pointer exception : Assertion `Val && "isa<> used on a null pointer"'

I tried to clone the current instruction to not modify the iterator but the
ReplaceInstWithInst will cause troubles (probably because a copied
instruction has no parents):

#0 0x0000000002a95b5c llvm::sys::PrintStackTrace(llvm::raw_ostream&)
#1 0x0000000002a95edf PrintStackTraceSignalHandler(void*)
not modify the iterator but the ReplaceInstWithInst will cause
#2 0x0000000002a94145 llvm::sys::RunSignalHandlers()
#3 0x0000000002a953a8 SignalHandler(int)
#4 0x00007fe358d3dd10 __restore_rt
#5 0x00000000011fe489 llvm::iplist<llvm::Instruction,
>::insert(llvm::ilist_iterator<llvm::Instruction>, llvm::Instruction*)
#6 0x0000000002abc20d llvm::ReI tried to clone the current instruction to
not modify the iterator but the ReplaceInstWithInst will cause
#7 0x0000000002abc2a5 llvm::ReplaceInstWithInst(llvm::Instruction*, llvm::Instruction*)
#7 0x0000000002abc2a5 llvm::ReplaceInstWithInst(llvm::Instruction*,

Any idea on what could be the cause of the null pointer and how to avoid it?

Thanks a lot for your time!

> Hi everyone,
> I am trying to replace the call of a certain function with a call to
> another function. It would for example replace the following:
> %call = tail call noalias i8* @func(i64 10)
> by
> %call = tail call noalias i8* @other_func(i64 10)
> I managed to declare other_func correctly but I am having troubles to
> understand how I should proceed to do the replacement.
> I tried to use ReplaceInstWithInst function as follows:
> CallInst *call_to_other_func_inst =
> IRBuilder.CreateCall(ptr_to_other_func, args);
> ReplaceInstWithInst(call_to_func_inst, newI);
> LLVM builds correctly but the instrumentation crashes at optimization
> time. I know this isn't the correct way to do it because IRBuilder
> generates IR and I just want to have an instance of a CallInst. But I don't
> see how it is supposed to be done?
> Do you have assertions enabled?  If so, is the crash an assertion failure
> and, if so, which assertion is failing?  It's nearly impossible to tell
> what the problem is just by knowing that it is crashing.
> There are methods to create CallInst in the Instruction.h file but those
> needs to give an inserting point. Shoud I insert the call to other_func
> before the one to func and just remove the call instruction to func?
> Yes.  You need to place the new call instruction within the same basic
> block as the old call instruction.  Placing it right before the old call
> instruction is a good place.
> The code that Ashutosh provided is what I'd use to do what you're doing.
> Regards,
> John Criswell
> Thanks for your help,
> Pierre
