https://github.com/tbaederr updated 
https://github.com/llvm/llvm-project/pull/174187

>From 1f02a45a56838ad3542b2b15b14c1ae8bb7bb7e2 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Timm=20B=C3=A4der?= <[email protected]>
Date: Fri, 2 Jan 2026 09:29:56 +0100
Subject: [PATCH] [clang][bytecode] Check builtin_memchr() for one-past-end
 pointers

We can't read from them and this fails later.

Fixes #173942
---
 clang/lib/AST/ByteCode/InterpBuiltin.cpp      | 5 +++++
 clang/test/AST/ByteCode/builtin-functions.cpp | 4 ++++
 2 files changed, 9 insertions(+)

diff --git a/clang/lib/AST/ByteCode/InterpBuiltin.cpp 
b/clang/lib/AST/ByteCode/InterpBuiltin.cpp
index 65101174247d1..065870c5c0ab5 100644
--- a/clang/lib/AST/ByteCode/InterpBuiltin.cpp
+++ b/clang/lib/AST/ByteCode/InterpBuiltin.cpp
@@ -73,6 +73,8 @@ static bool isReadable(const Pointer &P) {
     return false;
   if (!P.isLive())
     return false;
+  if (P.isOnePastEnd())
+    return false;
   return true;
 }
 
@@ -2089,6 +2091,9 @@ static bool interp__builtin_memchr(InterpState &S, 
CodePtr OpPC,
     return false;
   }
 
+  if (!isReadable(Ptr))
+    return false;
+
   if (ID == Builtin::BIstrchr || ID == Builtin::BI__builtin_strchr) {
     int64_t DesiredTrunc;
     if (S.getASTContext().CharTy->isSignedIntegerType())
diff --git a/clang/test/AST/ByteCode/builtin-functions.cpp 
b/clang/test/AST/ByteCode/builtin-functions.cpp
index 3076b5239ebbe..3cde5a2b42e3d 100644
--- a/clang/test/AST/ByteCode/builtin-functions.cpp
+++ b/clang/test/AST/ByteCode/builtin-functions.cpp
@@ -1649,6 +1649,10 @@ namespace Memchr {
     return __builtin_char_memchr(c + 1, 'f', 1) == nullptr;
   }
   static_assert(f());
+
+
+  extern const char char_memchr_arg[0l];
+  char *memchr_result = __builtin_char_memchr(char_memchr_arg, 123, 32);
 }
 
 namespace Strchr {

_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits

Reply via email to