From patchwork Sat Jan 10 08:32:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Jakub Jelinek X-Patchwork-Id: 127811 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [127.0.0.1]) by sourceware.org (Postfix) with ESMTP id 29E8B4BA2E07 for ; Sat, 10 Jan 2026 08:32:50 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 29E8B4BA2E07 Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=dGAw+9bP X-Original-To: gcc-patches@gcc.gnu.org Delivered-To: gcc-patches@gcc.gnu.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTP id 0F63C4BA2E04 for ; Sat, 10 Jan 2026 08:32:09 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 0F63C4BA2E04 Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 0F63C4BA2E04 Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1768033929; cv=none; b=mOFYTi39Qps8knC3bBo1SRYS22WIa17a4FcRoLIa346DThbxbVFJugLz0Lp1kbLWP6wHj+HmYowjm5Yi1GptT+6Gpfrrs26p+KakO8y76gxFF2tc5Gi2Py19eFc6yaj26WJE5g96IG+0dwYxpDePWEpHl6HoKXWEccpar3fwPJk= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1768033929; c=relaxed/simple; bh=OkjIo9vtR4Uzp7IxAUSCsh+ECcgneGLp8ASpGuDECDI=; h=DKIM-Signature:Date:From:To:Subject:Message-ID:MIME-Version; b=jxKZyl6pTdTWcWdEMz63lsTnGDO4CFzf6FnelYW43vGAvstlJAdCaMb4CabSRutP3GFd8nPIQ8k34Vg7/r6SRfkBrG0sy6Akp/sarZ1koeMrtL4RSM/uSPHT850hvUZh1DnGKWBud7Z/25Buc3wAxQysGTPI0qszPBTdvBZ9KPI= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 0F63C4BA2E04 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1768033928; h=from:from:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type; bh=dW45Bl7CAGiz8BxVT1Iipxc/V9Tz6dwV00fH+xunXRA=; b=dGAw+9bPzidOUlNpk4teCZME8Fh1BXLOAuQH08yRr9NnoBL2R4b7YGkzkQ2QhnUD2J/UR0 Lcb7p2aHL9FuUUXqXPeTGO8UczyRrR2sFuzWMBeH/eMS4XRaMMmttD6w3XAPAbCZ+7RWJP VAU7gqXEsCkb9SNk5YAGnLqD1CJzN/o= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-484-_sgs7MmMPzKa4slk_YCPng-1; Sat, 10 Jan 2026 03:32:06 -0500 X-MC-Unique: _sgs7MmMPzKa4slk_YCPng-1 X-Mimecast-MFC-AGG-ID: _sgs7MmMPzKa4slk_YCPng_1768033925 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4EFB31800578; Sat, 10 Jan 2026 08:32:05 +0000 (UTC) Received: from tucnak.zalov.cz (unknown [10.44.32.27]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B67051955F66; Sat, 10 Jan 2026 08:32:04 +0000 (UTC) Received: from tucnak.zalov.cz (localhost [127.0.0.1]) by tucnak.zalov.cz (8.18.1/8.18.1) with ESMTPS id 60A8W1do3647432 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NOT); Sat, 10 Jan 2026 09:32:02 +0100 Received: (from jakub@localhost) by tucnak.zalov.cz (8.18.1/8.18.1/Submit) id 60A8W1uO3647429; Sat, 10 Jan 2026 09:32:01 +0100 Date: Sat, 10 Jan 2026 09:32:01 +0100 From: Jakub Jelinek To: Andrew MacLeod , Richard Biener Cc: gcc-patches@gcc.gnu.org Subject: [PATCH] ranger: Verify gimple_call_num_args for several builtins [PR123431] Message-ID: MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: q9-fL62u-FudWcUPsZWxmOH2Mm2RHA-V_juqt7fmWHQ_1768033925 X-Mimecast-Originator: redhat.com Content-Disposition: inline X-Spam-Status: No, score=-3.6 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, RCVD_IN_VALIDITY_RPBL_BLOCKED, RCVD_IN_VALIDITY_SAFE_BLOCKED, SPF_HELO_PASS, SPF_NONE, TXREP, URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: gcc-patches@gcc.gnu.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Gcc-patches mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: Jakub Jelinek Errors-To: gcc-patches-bounces~patchwork=sourceware.org@gcc.gnu.org Hi! While gimple_call_combined_fn already do call gimple_builtin_call_types_compatible_p and for most of builtins ensures the right types of arguments, for type generic builtins it does not, from POV of that function those functions are rettype (...). Now, while the FE does some number of argument checking for the type generic builtins, as the testcase below shows, it can be gamed. So, this patch checks the number of arguments for type generic builtins and does nothing if they have unexpected number of arguments. Also for the returns arg verifies it can access the first argument. Bootstrapped/regtested on x86_64-linux and i686-linux, ok for trunk? 2026-01-10 Jakub Jelinek PR tree-optimization/123431 * gimple-range-op.cc (gimple_range_op_handler::maybe_builtin_call): Punt if type-generic builtins with a single argument don't have exactly one argument. For returns_arg punt if call doesn't have at least one argument. * gcc.dg/pr123431.c: New test. Jakub --- gcc/gimple-range-op.cc.jj 2026-01-02 09:56:10.182336262 +0100 +++ gcc/gimple-range-op.cc 2026-01-09 15:00:01.166808500 +0100 @@ -1410,6 +1410,8 @@ gimple_range_op_handler::maybe_builtin_c switch (func) { case CFN_BUILT_IN_CONSTANT_P: + if (gimple_call_num_args (call) != 1) + return; m_op1 = gimple_call_arg (call, 0); if (irange::supports_p (TREE_TYPE (m_op1))) m_operator = &op_cfn_constant_p; @@ -1420,21 +1422,29 @@ gimple_range_op_handler::maybe_builtin_c break; CASE_FLT_FN (CFN_BUILT_IN_SIGNBIT): + if (gimple_call_num_args (call) != 1) + return; m_op1 = gimple_call_arg (call, 0); m_operator = &op_cfn_signbit; break; CASE_FLT_FN (CFN_BUILT_IN_ISINF): + if (gimple_call_num_args (call) != 1) + return; m_op1 = gimple_call_arg (call, 0); m_operator = &op_cfn_isinf; break; case CFN_BUILT_IN_ISFINITE: + if (gimple_call_num_args (call) != 1) + return; m_op1 = gimple_call_arg (call, 0); m_operator = &op_cfn_isfinite; break; case CFN_BUILT_IN_ISNORMAL: + if (gimple_call_num_args (call) != 1) + return; m_op1 = gimple_call_arg (call, 0); m_operator = &op_cfn_isnormal; break; @@ -1565,7 +1575,9 @@ gimple_range_op_handler::maybe_builtin_c default: { unsigned arg; - if (gimple_call_fnspec (call).returns_arg (&arg) && arg == 0) + if (gimple_call_fnspec (call).returns_arg (&arg) + && arg == 0 + && gimple_call_num_args (call) > 0) { m_op1 = gimple_call_arg (call, 0); m_operator = &op_cfn_pass_through_arg1; --- gcc/testsuite/gcc.dg/pr123431.c.jj 2026-01-09 15:10:58.084406597 +0100 +++ gcc/testsuite/gcc.dg/pr123431.c 2026-01-09 15:10:20.589057380 +0100 @@ -0,0 +1,19 @@ +/* PR tree-optimization/123431 */ +/* { dg-do compile } */ +/* { dg-options "-O2" } */ + +extern void foo (int); + +extern inline __attribute__((always_inline)) void +bar (int x, ...) +{ + if (__builtin_constant_p (__builtin_va_arg_pack ())) + foo (x); +} + +void +baz (int x) +{ + bar (1, 2); + bar (3, x); +}