mirror of
https://github.com/YosysHQ/yosys.git
synced 2026-10-06 01:53:53 +02:00
opt_dff: Fix ModWalker use-after-free between constbits and eqbits
Commit fae99416d ("Only init modwalker once.") introduced a shared
ModWalker in OptDffWorker reused across run_constbits() and
run_eqbits(). However, when run_constbits() proves a flip-flop bit is
constant, the below sequence occurs:
OptDffPass::execute()
|
+-> worker.run_constbits()
| |-> fold_const_bits()
| | `-> add_const_target()
| | `-> worker.get_modwalker() #[caches FF Cell* info in modwalker]
| |-> ...
| `-> worker.remove_ff_bits()
| `-> new_ff.emit() #[deletes FF Cell* info in module. cell info in modwalker is stale]
|
`-> worker.run_eqbits()
|-> gather_initial_eq_classes()
`-> filter_classes_sim()
|-> BitSim::sim() #[passes modwalker which has stale cell info]
`-> sim.eval_bit()
|-> cell = modwalker...find().cell #[derives stale cell info]
`-> if (cell->is_builtin_ff()) #[*** crashed as cell pointer is already freed *** ]
So, reset modwalker_ptr in remove_ff_bits() whenever flip-flop bits
are removed so run_eqbits() rebuilds a fresh ModWalker only when the
module netlist was modified.
Reported-by: Sean Luchen <[email protected]>
Signed-off-by: Lokesh Vutla <[email protected]>
This commit is contained in:
@@ -37,6 +37,8 @@ OptDffWorker::OptDffWorker(const OptDffOptions &opt, Module *mod)
|
||||
|
||||
void OptDffWorker::remove_ff_bits(Cell *cell, const pool<int> &drop)
|
||||
{
|
||||
modwalker_ptr.reset();
|
||||
|
||||
FfData ff(&initvals, cell);
|
||||
std::vector<int> keep;
|
||||
for (int i = 0; i < ff.width; i++)
|
||||
|
||||
Reference in New Issue
Block a user