From ead2f775271612a5d06664355dd09e5fcfd09b08 Mon Sep 17 00:00:00 2001 From: Ian Romanick Date: Fri, 23 Jan 2026 10:07:27 -0800 Subject: [PATCH] nir: Use STACK_ARRAY instead of NIR_VLA The number of fields comes from the shader, so it could be a value large enough that using alloca would be problematic. Fixes: c11833ab24d ("nir,spirv: Rework function calls") Reviewed-by: Caio Oliveira Reviewed-by: Ryan Neph Reviewed-by: Lionel Landwerlin (cherry picked from commit 9017d37e84771f921a63676dd8b955df9ef20f29) Part-of: Upstream: https://gitlab.freedesktop.org/mesa/mesa/-/commit/cc3303b3d244121ce6f27b0ef1ffc9909fc75e52 [removed changes to .pick_status.json, not applicable to 24.0.9] [conflict in git context around the added include directive due to missing 76061b7fa33a ("nir: Don't include u_printf.h in nir.h, only where necessary."), 91872c9c5158 ("nir: clang-format")] CVE: CVE-2026-40393 Signed-off-by: Quentin Schulz --- src/compiler/nir/nir_functions.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/compiler/nir/nir_functions.c b/src/compiler/nir/nir_functions.c index d17ebd83ead..abd5e8a095d 100644 --- a/src/compiler/nir/nir_functions.c +++ b/src/compiler/nir/nir_functions.c @@ -21,10 +21,10 @@ * IN THE SOFTWARE. */ +#include "util/stack_array.h" #include "nir.h" #include "nir_builder.h" #include "nir_control_flow.h" -#include "nir_vla.h" /* * TODO: write a proper inliner for GPUs. @@ -177,12 +177,13 @@ static bool inline_functions_pass(nir_builder *b, * to an SSA value first. */ const unsigned num_params = call->num_params; - NIR_VLA(nir_def *, params, num_params); + STACK_ARRAY(nir_def *, params, num_params); for (unsigned i = 0; i < num_params; i++) { params[i] = call->params[i].ssa; } nir_inline_function_impl(b, call->callee->impl, params, NULL); + STACK_ARRAY_FINISH(params); return true; }