opt_dff: Fix ModWalker use-after-free between constbits and eqbits

Commit fae99416d ("Only init modwalker once.") introduced a shared
ModWalker in OptDffWorker reused across run_constbits() and
run_eqbits(). However, when run_constbits() proves a flip-flop bit is
constant, the below sequence occurs:

OptDffPass::execute()
|
+-> worker.run_constbits()
|    |-> fold_const_bits()
|    |    `-> add_const_target()
|    |         `-> worker.get_modwalker()  #[caches FF Cell* info in modwalker]
|    |-> ...
|    `-> worker.remove_ff_bits()
|         `-> new_ff.emit()                 #[deletes FF Cell* info in module. cell info in modwalker is stale]
|
`-> worker.run_eqbits()
     |-> gather_initial_eq_classes()
     `-> filter_classes_sim()
          |-> BitSim::sim()                         #[passes modwalker which has stale cell info]
          `-> sim.eval_bit()
               |-> cell = modwalker...find().cell   #[derives stale cell info]
               `-> if (cell->is_builtin_ff())       #[*** crashed as cell pointer is already freed *** ]

So, reset modwalker_ptr in remove_ff_bits() whenever flip-flop bits
are removed so run_eqbits() rebuilds a fresh ModWalker only when the
module netlist was modified.

Reported-by: Sean Luchen <[email protected]>
Signed-off-by: Lokesh Vutla <[email protected]>
This commit is contained in:
Lokesh Vutla
2026-10-02 19:36:56 +02:00
committed by nella
parent fb1a2fdae7
commit 0ce1cbcae7
+2
View File
@@ -37,6 +37,8 @@ OptDffWorker::OptDffWorker(const OptDffOptions &opt, Module *mod)
void OptDffWorker::remove_ff_bits(Cell *cell, const pool<int> &drop)
{
modwalker_ptr.reset();
FfData ff(&initvals, cell);
std::vector<int> keep;
for (int i = 0; i < ff.width; i++)