llvm-project
44e3f3cb - [CIR] Fix use-after-free when emitting ternary with a throw-expression arm (#208850)

Commit
7 days ago
[CIR] Fix use-after-free when emitting ternary with a throw-expression arm (#208850) Fixes #208848. When a conditional operator arm is a noreturn expression, such as `throw`, `VisitAbstractConditionalOperator` saved an insertion point in the empty dead-code block created after the expression. The intent was to insert a `cir.yield` later, once the types of both arms were known. However, `LexicalScope::cleanup()` removes that empty block when the arm’s scope exits, leaving the deferred insertion point with a dangling block pointer. Avoid saving the insertion point for noreturn arms. These regions already terminate with `cir.unreachable` and do not require a `cir.yield`. The CIR verifier accepts ternary regions that terminate with `cir.unreachable`. Extended `ternary-throw.cpp` with scalar-rvalue cases covering `throw` in either arm and in both arms. The existing tests only covered glvalue conditionals, which take the LValue emission path and never reach this code.
Author
Parents
Loading