[Util] Fix 32-bit wrap of util.string.format placeholder-count check (#24685)
## Summary
Compute `util.string.format`'s expected-operand count in 64-bit so a
near-`UINT_MAX` placeholder index cannot wrap the check and slip past
verification into an out-of-bounds access.
## Context
`util.string.format` interpolates its operands into `{N}`-style
placeholders. Its verifier — and `StringFormatOp::fold` — determine how
many operands the op should have from the highest placeholder index in
the format string, computed as `maxArgIndex + 1`. `maxArgIndex` was a
32-bit `unsigned`.
## Problem
A format string with an explicit placeholder index of `UINT_MAX` makes
`maxArgIndex + 1` overflow to `0`, so the verifier expects `0` operands
and accepts the op even though the placeholder references argument
`4294967295`. `fold` (and the verifier's own indexing) then read
`argStrings[4294967295]` on an empty list — an out-of-bounds read. For
example, before this change the following op passed verification:
```mlir
%0 = util.string.format "{4294967295}"() : () -> !util.buffer
```
## Fix
Cast `maxArgIndex` to `uint64_t` so `maxArgIndex + 1` no longer wraps; an
out-of-range placeholder is now rejected at verification. The same
computation exists in two copies of `parseFormatString` (the verifier in
`UtilOps.cpp` and the folder in `UtilOpFolders.cpp`); both are updated.
`string_format_index_overflow` in `op_verification.mlir` checks the op
above is now rejected with a diagnostic instead of passing verification.
---
Disclosure: this contribution was authored with an AI coding assistant
(Claude) and reviewed before submission.
Signed-off-by: Eylon Krause <eylon1909@gmail.com>IREE (Intermediate Representation Execution Environment, pronounced as “eerie”) is an MLIR-based end-to-end compiler and runtime that lowers Machine Learning (ML) models to a unified IR that scales up to meet the needs of the datacenter and down to satisfy the constraints and special considerations of mobile and edge deployments.
See our website for project details, user guides, and instructions on building from source.
Releases notes are published on GitHub releases.
| Package | Release status |
|---|---|
| GitHub release (stable) | |
| GitHub release (nightly) | |
iree-base-compiler | |
iree-base-runtime |
For more details on the release process, see https://iree.dev/developers/general/release-management/.
| Operating system | Build status |
|---|---|
| Linux | |
| macOS | |
| macOS |
For the full list of workflows see https://iree.dev/developers/general/github-actions/.
See our website for more information.
Community meeting recordings: IREE YouTube channel
| Date | Title | Recording | Slides |
|---|---|---|---|
| 2025-06-10 | Data-Tiling in IREE: Achieving High Performance Through Compiler Design (AsiaLLVM) | recording | slides |
| 2025-05-17 | Introduction to GPU architecture and IREE's GPU CodeGen Pipeline | recording | slides |
| 2025-02-12 | The Long Tail of AI: SPIR-V in IREE and MLIR (Vulkanised) | recording | slides |
| 2024-10-01 | Unveiling the Inner Workings of IREE: An MLIR-Based Compiler for Diverse Hardware | recording | |
| 2021-06-09 | IREE Runtime Design Tech Talk | recording | slides |
| 2020-08-20 | IREE CodeGen (MLIR Open Design Meeting) | recording | slides |
| 2020-03-18 | Interactive HAL IR Walkthrough | recording | |
| 2020-01-31 | End-to-end MLIR Workflow in IREE (MLIR Open Design Meeting) | recording | slides |
IREE is licensed under the terms of the Apache 2.0 License with LLVM Exceptions. See LICENSE for more information.