[ir] Validate switch results Fixes a fuzzer issue where the result was invalid. Fixed: 441682088 Change-Id: I06198550269396c98f6c9d551162e76ecd4f7a1d Reviewed-on: https://dawn-review.googlesource.com/c/dawn/+/259856 Auto-Submit: James Price <jrprice@google.com> Commit-Queue: dan sinclair <dsinclair@chromium.org> Commit-Queue: James Price <jrprice@google.com> Reviewed-by: dan sinclair <dsinclair@chromium.org>
diff --git a/src/tint/lang/core/ir/validator.cc b/src/tint/lang/core/ir/validator.cc index 9cc9d0c..d2f25e5f 100644 --- a/src/tint/lang/core/ir/validator.cc +++ b/src/tint/lang/core/ir/validator.cc
@@ -3558,6 +3558,7 @@ } void Validator::CheckSwitch(const Switch* s) { + CheckResults(s); CheckOperand(s, Switch::kConditionOperandOffset); if (s->Condition() && !s->Condition()->Type()->IsIntegerScalar()) {
diff --git a/src/tint/lang/core/ir/validator_flow_control_test.cc b/src/tint/lang/core/ir/validator_flow_control_test.cc index b49da34..a098bc3 100644 --- a/src/tint/lang/core/ir/validator_flow_control_test.cc +++ b/src/tint/lang/core/ir/validator_flow_control_test.cc
@@ -2134,4 +2134,23 @@ )")) << res.Failure(); } +TEST_F(IR_ValidatorTest, Switch_NullResult) { + auto* f = b.Function("my_func", ty.void_()); + + b.Append(f->Block(), [&] { + auto* s = b.Switch(1_u); + s->SetResults(Vector<InstructionResult*, 1>{nullptr}); + + b.Append(b.DefaultCase(s), [&] { b.Return(f); }); + b.Return(f); + }); + + auto res = ir::Validate(mod); + ASSERT_NE(res, Success); + EXPECT_THAT(res.Failure().reason, testing::HasSubstr(R"(error: switch: result is undefined + undef = switch 1u [c: (default, $B2)] { # switch_1 + ^^^^^ +)")) << res.Failure(); +} + } // namespace tint::core::ir