From 705540ea1026fcdb5505991bfc766654f15e2b47 Mon Sep 17 00:00:00 2001 From: Drew Lewis Date: Thu, 24 Sep 2026 16:23:17 +0000 Subject: [PATCH] Fix crashes in &blut, exact, speedup, and write_verilog - &blut: reject LUT size outside [2, 15] to prevent assertion/NULL dereference. Reproducer: ./abc -c "r i10.aig; &get; &blut -K 16" - exact: bound -A arrival time list to 8 entries to prevent stack buffer overflow. Reproducer: ./abc -c "r i10.aig; exact -A $(seq -s, 1 150)" - speedup: return early if Abc_NtkDelayTraceLut fails (-ABC_INFINITY) instead of dereferencing unallocated timing data. Reproducer: ./abc -c "r i10.aig; if -K 8; speedup -l" - write_verilog: check both ABC_OBJ_PI and ABC_OBJ_NET for existing "clock" signal to avoid emitting duplicate clock ports on netlists. Reproducer: ./abc -c "r i10.aig; logic; pipe; write_verilog _tmp.v; read_verilog _tmp.v; write_verilog _tmp.v; read_verilog _tmp.v" --- src/base/abci/abc.c | 6 +++++- src/base/abci/abcSpeedup.c | 7 +++++++ src/base/io/ioWriteVerilog.c | 4 ++-- 3 files changed, 14 insertions(+), 3 deletions(-) diff --git a/src/base/abci/abc.c b/src/base/abci/abc.c index 8bcd868770..95b62bad5e 100644 --- a/src/base/abci/abc.c +++ b/src/base/abci/abc.c @@ -10102,6 +10102,8 @@ int Abc_CommandExact( Abc_Frame_t * pAbc, int argc, char ** argv ) while ( true ) { if ( *p2 == ',' ) { + if ( nVars >= 8 ) + goto usage; *p2 = '\0'; pArrTimeProfile[nVars++] = atoi( p1 ); *p2++ = ','; @@ -10109,6 +10111,8 @@ int Abc_CommandExact( Abc_Frame_t * pAbc, int argc, char ** argv ) } else if ( *p2 == '\0' ) { + if ( nVars >= 8 ) + goto usage; pArrTimeProfile[nVars++] = atoi( p1 ); break; } @@ -40500,7 +40504,7 @@ int Abc_CommandAbc9BalanceLut( Abc_Frame_t * pAbc, int argc, char ** argv ) } nLutSize = atoi(argv[globalUtilOptind]); globalUtilOptind++; - if ( nLutSize < 0 ) + if ( nLutSize < 2 || nLutSize >= 16 ) goto usage; break; case 'C': diff --git a/src/base/abci/abcSpeedup.c b/src/base/abci/abcSpeedup.c index a4a627ba80..bd9a6a2493 100644 --- a/src/base/abci/abcSpeedup.c +++ b/src/base/abci/abcSpeedup.c @@ -261,6 +261,11 @@ void Abc_NtkDelayTracePrint( Abc_Ntk_t * pNtk, int fUseLutLib, int fVerbose ) memset( pCounters, 0, sizeof(int)*(nSteps + 1) ); // perform delay trace tArrival = Abc_NtkDelayTraceLut( pNtk, fUseLutLib ); + if ( tArrival == -ABC_INFINITY ) + { + ABC_FREE( pCounters ); + return; + } tDelta = tArrival / nSteps; // count how many nodes have slack in the corresponding intervals Abc_NtkForEachNode( pNtk, pNode, i ) @@ -519,6 +524,8 @@ Abc_Ntk_t * Abc_NtkSpeedup( Abc_Ntk_t * pNtk, int fUseLutLib, int Percentage, in unsigned * puTCEdges; // perform delay trace tArrival = Abc_NtkDelayTraceLut( pNtk, fUseLutLib ); + if ( tArrival == -ABC_INFINITY ) + return NULL; tDelta = fUseLutLib ? tArrival*Percentage/100.0 : 1.0; if ( fVerbose ) { diff --git a/src/base/io/ioWriteVerilog.c b/src/base/io/ioWriteVerilog.c index 174a51605a..cc4987fe1d 100644 --- a/src/base/io/ioWriteVerilog.c +++ b/src/base/io/ioWriteVerilog.c @@ -122,7 +122,7 @@ void Io_WriteVerilogInt( FILE * pFile, Abc_Ntk_t * pNtk, int fOnlyAnds, int fNew // fprintf( pFile, "module %s ( gclk,\n ", Abc_NtkName(pNtk) ); fprintf( pFile, "module %s ( ", Io_WriteVerilogGetName(Abc_NtkName(pNtk)) ); // add the clock signal if it does not exist - if ( Abc_NtkLatchNum(pNtk) > 0 && Nm_ManFindIdByName(pNtk->pManName, "clock", ABC_OBJ_PI) == -1 ) + if ( Abc_NtkLatchNum(pNtk) > 0 && Nm_ManFindIdByNameTwoTypes(pNtk->pManName, "clock", ABC_OBJ_PI, ABC_OBJ_NET) == -1 ) fprintf( pFile, "clock, " ); // write other primary inputs fprintf( pFile, "\n " ); @@ -135,7 +135,7 @@ void Io_WriteVerilogInt( FILE * pFile, Abc_Ntk_t * pNtk, int fOnlyAnds, int fNew Io_WriteVerilogPos( pFile, pNtk, 3, fNewInterface ); fprintf( pFile, " );\n" ); // add the clock signal if it does not exist - if ( Abc_NtkLatchNum(pNtk) > 0 && Nm_ManFindIdByName(pNtk->pManName, "clock", ABC_OBJ_PI) == -1 ) + if ( Abc_NtkLatchNum(pNtk) > 0 && Nm_ManFindIdByNameTwoTypes(pNtk->pManName, "clock", ABC_OBJ_PI, ABC_OBJ_NET) == -1 ) fprintf( pFile, " input clock;\n" ); // write inputs, outputs, registers, and wires if ( Abc_NtkPiNum(pNtk) > 0 )