Files
yosys/passes/opt/dff
Lokesh Vutla 0ce1cbcae7 opt_dff: Fix ModWalker use-after-free between constbits and eqbits
Commit fae99416d ("Only init modwalker once.") introduced a shared
ModWalker in OptDffWorker reused across run_constbits() and
run_eqbits(). However, when run_constbits() proves a flip-flop bit is
constant, the below sequence occurs:

OptDffPass::execute()
|
+-> worker.run_constbits()
|    |-> fold_const_bits()
|    |    `-> add_const_target()
|    |         `-> worker.get_modwalker()  #[caches FF Cell* info in modwalker]
|    |-> ...
|    `-> worker.remove_ff_bits()
|         `-> new_ff.emit()                 #[deletes FF Cell* info in module. cell info in modwalker is stale]
|
`-> worker.run_eqbits()
     |-> gather_initial_eq_classes()
     `-> filter_classes_sim()
          |-> BitSim::sim()                         #[passes modwalker which has stale cell info]
          `-> sim.eval_bit()
               |-> cell = modwalker...find().cell   #[derives stale cell info]
               `-> if (cell->is_builtin_ff())       #[*** crashed as cell pointer is already freed *** ]

So, reset modwalker_ptr in remove_ff_bits() whenever flip-flop bits
are removed so run_eqbits() rebuilds a fresh ModWalker only when the
module netlist was modified.

Reported-by: Sean Luchen <[email protected]>
Signed-off-by: Lokesh Vutla <[email protected]>
2026-10-02 19:36:56 +02:00
..
2026-08-27 23:10:40 +06:00
2026-08-27 23:10:40 +06:00
2026-08-27 23:10:40 +06:00
2026-08-27 23:10:40 +06:00