https://github.com/m1kit updated 
https://github.com/llvm/llvm-project/pull/135787

>From 15631133faed63a1c4bf7b3c9076629985e48bf9 Mon Sep 17 00:00:00 2001
From: mikit <37488201+m1...@users.noreply.github.com>
Date: Tue, 15 Apr 2025 22:32:24 +0900
Subject: [PATCH 1/2] [CodeGen] Fix new-delete-type-mismatch in ~CodeGenTypes()

It is undefined behavior to use `delete` expression on something
which was not created with corresponding `new` expression.
Switching to explicit global `operator delete()` call to match with
`operator new()` call at `CGFunctionInfo::create()`.

This issue is raised by Chromium ClusterFuzz, with ASan enabled.
https://crbug.com/410141973
---
 clang/lib/CodeGen/CodeGenTypes.cpp | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/clang/lib/CodeGen/CodeGenTypes.cpp 
b/clang/lib/CodeGen/CodeGenTypes.cpp
index b94c11802a268..dec3b087b107f 100644
--- a/clang/lib/CodeGen/CodeGenTypes.cpp
+++ b/clang/lib/CodeGen/CodeGenTypes.cpp
@@ -41,7 +41,7 @@ CodeGenTypes::CodeGenTypes(CodeGenModule &cgm)
 CodeGenTypes::~CodeGenTypes() {
   for (llvm::FoldingSet<CGFunctionInfo>::iterator
        I = FunctionInfos.begin(), E = FunctionInfos.end(); I != E; )
-    delete &*I++;
+    operator delete(&*I++);
 }
 
 CGCXXABI &CodeGenTypes::getCXXABI() const { return getCGM().getCXXABI(); }

>From 7fae0f5c2150cf443b37660f5429da3d5b388429 Mon Sep 17 00:00:00 2001
From: mikit <37488201+m1...@users.noreply.github.com>
Date: Tue, 15 Apr 2025 17:49:05 +0000
Subject: [PATCH 2/2] Call dtor

---
 clang/lib/CodeGen/CodeGenTypes.cpp | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/clang/lib/CodeGen/CodeGenTypes.cpp 
b/clang/lib/CodeGen/CodeGenTypes.cpp
index dec3b087b107f..3600203fe2fea 100644
--- a/clang/lib/CodeGen/CodeGenTypes.cpp
+++ b/clang/lib/CodeGen/CodeGenTypes.cpp
@@ -40,8 +40,10 @@ CodeGenTypes::CodeGenTypes(CodeGenModule &cgm)
 
 CodeGenTypes::~CodeGenTypes() {
   for (llvm::FoldingSet<CGFunctionInfo>::iterator
-       I = FunctionInfos.begin(), E = FunctionInfos.end(); I != E; )
+       I = FunctionInfos.begin(), E = FunctionInfos.end(); I != E; ) {
+    I->~CGFunctionInfo();
     operator delete(&*I++);
+  }
 }
 
 CGCXXABI &CodeGenTypes::getCXXABI() const { return getCGM().getCXXABI(); }

_______________________________________________
cfe-commits mailing list
cfe-commits@lists.llvm.org
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits

Reply via email to