From e1cf833c458acb33bc877e2e5ee504c19bb67f05 Mon Sep 17 00:00:00 2001 From: Chandler Carruth Date: Tue, 7 Jul 2026 08:04:40 -0700 Subject: [PATCH] Fix ASan heap-use-after-free in SourceGenTest (#7465) In `SourceGenTest.IdentifierByteSumStableAcrossSeeds`, the `first` variable was storing `llvm::StringRef`s pointing to memory allocated by a temporary `SourceGen` instance. This memory was freed at the end of the loop iteration, leaving `first` with dangling references that were accessed in subsequent iterations. Fix this by storing `std::string` copies of the identifiers in `first` to own the memory, and use `llvm::equal` to compare them. Assisted-by: Antigravity with Gemini --- toolchain/benchmarking/source_gen_test.cpp | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/toolchain/benchmarking/source_gen_test.cpp b/toolchain/benchmarking/source_gen_test.cpp index 7f8ba8a3a62f..f73c104f2692 100644 --- a/toolchain/benchmarking/source_gen_test.cpp +++ b/toolchain/benchmarking/source_gen_test.cpp @@ -11,6 +11,7 @@ #include #include "common/set.h" +#include "llvm/ADT/STLExtras.h" #include "llvm/Support/FormatVariadic.h" #include "testing/base/global_exe_path.h" #include "toolchain/base/install_paths_test_helpers.h" @@ -137,7 +138,7 @@ TEST(SourceGenTest, IdentifierByteSumStableAcrossSeeds) { c.number, c.min_length, c.max_length, c.uniform, c.unique)); std::optional expected_sum; bool any_different = false; - std::optional> first; + std::optional> first; constexpr int NumSeeds = 8; for (int seed : llvm::seq(NumSeeds)) { // Each iteration constructs a fresh generator with an independent random @@ -156,12 +157,12 @@ TEST(SourceGenTest, IdentifierByteSumStableAcrossSeeds) { ssize_t sum = SumSizes(idents); if (!expected_sum) { expected_sum = sum; - first = idents; + first.emplace(idents.begin(), idents.end()); continue; } // The byte sum must be identical regardless of the seed. EXPECT_THAT(sum, Eq(*expected_sum)); - if (idents != *first) { + if (!llvm::equal(idents, *first)) { any_different = true; } }