[clang] [clang] Reject references to vector types in `__builtin_vectorelements` (PR #219767)
Akash Manna via cfe-commits
cfe-commits at lists.llvm.org
Sun Aug 30 01:31:15 PDT 2026
https://github.com/akash-manna-sky updated https://github.com/llvm/llvm-project/pull/219767
>From 6ee72a2b6e324ba6a1265e25c0670ac956546fa2 Mon Sep 17 00:00:00 2001
From: Akash Manna <akash.manna.mymail at gmail.com>
Date: Sun, 30 Aug 2026 10:57:14 +0530
Subject: [PATCH 1/3] [clang] Reject references to vector types in
__builtin_vectorelements
Fixes #216997
CheckUnaryExprOrTypeTraitOperand looks through reference types for all
trait kinds before dispatching to the __builtin_vectorelements check, so
a reference to a vector type passed Sema while the expression kept the
reference as its argument type. Constant evaluation and codegen require
that type to be a vector type and assert otherwise.
Check the __builtin_vectorelements operand before the reference is
looked through, so it is diagnosed like any other non-vector type.
---
clang/docs/ReleaseNotes.md | 2 ++
clang/lib/Sema/SemaExpr.cpp | 10 ++++++----
clang/test/SemaCXX/GH216997.cpp | 32 ++++++++++++++++++++++++++++++++
3 files changed, 40 insertions(+), 4 deletions(-)
create mode 100644 clang/test/SemaCXX/GH216997.cpp
diff --git a/clang/docs/ReleaseNotes.md b/clang/docs/ReleaseNotes.md
index bdbabf2cd98d0..a80bba3d99003 100644
--- a/clang/docs/ReleaseNotes.md
+++ b/clang/docs/ReleaseNotes.md
@@ -457,6 +457,8 @@ features cannot lower the translation-unit ABI level;
such as when the call is used as an `auto` non-type template argument.
- Fixed a crash in ``__builtin_dump_struct`` when ``-Werror`` promotes
format warnings to errors. (#GH211943)
+- Fixed a crash when `__builtin_vectorelements` is applied to a reference to a
+ vector type; this is now diagnosed as an invalid argument type. (#GH216997)
#### Bug Fixes to Attribute Support
diff --git a/clang/lib/Sema/SemaExpr.cpp b/clang/lib/Sema/SemaExpr.cpp
index 34f6ccdbc2fe6..348d3e9ef33c0 100644
--- a/clang/lib/Sema/SemaExpr.cpp
+++ b/clang/lib/Sema/SemaExpr.cpp
@@ -4742,6 +4742,12 @@ bool Sema::CheckUnaryExprOrTypeTraitOperand(QualType ExprType,
if (ExprType->isDependentType())
return false;
+ // A reference to a vector type is not a vector type; check this before the
+ // reference is looked through below.
+ if (ExprKind == UETT_VectorElements)
+ return CheckVectorElementsTraitOperandType(*this, ExprType, OpLoc,
+ ExprRange);
+
// C++ [expr.sizeof]p2:
// When applied to a reference or a reference type, the result
// is the size of the referenced type.
@@ -4767,10 +4773,6 @@ bool Sema::CheckUnaryExprOrTypeTraitOperand(QualType ExprType,
if (ExprKind == UETT_VecStep)
return CheckVecStepTraitOperandType(*this, ExprType, OpLoc, ExprRange);
- if (ExprKind == UETT_VectorElements)
- return CheckVectorElementsTraitOperandType(*this, ExprType, OpLoc,
- ExprRange);
-
if (ExprKind == UETT_PtrAuthTypeDiscriminator)
return checkPtrAuthTypeDiscriminatorOperandType(*this, ExprType, OpLoc,
ExprRange);
diff --git a/clang/test/SemaCXX/GH216997.cpp b/clang/test/SemaCXX/GH216997.cpp
new file mode 100644
index 0000000000000..407c618421484
--- /dev/null
+++ b/clang/test/SemaCXX/GH216997.cpp
@@ -0,0 +1,32 @@
+// RUN: %clang_cc1 -triple x86_64 -std=c++20 -fsyntax-only -verify %s
+// RUN: %clang_cc1 -triple x86_64 -std=c++20 -fsyntax-only -verify -fexperimental-new-constant-interpreter %s
+
+// Reproducer from GH216997.
+using vec __attribute__((vector_size(16))) = int &bar; // expected-error {{type-id cannot have a name}}
+int baz = __builtin_vectorelements(vec); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+
+using vec_ref __attribute__((vector_size(16))) = int &;
+static_assert(sizeof(vec_ref) == 16, "");
+int a = __builtin_vectorelements(vec_ref); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+
+typedef int veci4 __attribute__((vector_size(16)));
+int b = __builtin_vectorelements(veci4 &); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+int c = __builtin_vectorelements(veci4 &&); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+int d = __builtin_vectorelements(const veci4 &); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+
+veci4 v;
+int e = __builtin_vectorelements(decltype((v))); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+
+template <typename T>
+int f() {
+ return __builtin_vectorelements(T); // expected-error {{argument to __builtin_vectorelements must be of vector type}}
+}
+int g = f<veci4>();
+int h = f<veci4 &>(); // expected-note {{in instantiation of function template specialization}}
+
+void ok(veci4 &r, veci4 &&rr) {
+ (void)__builtin_vectorelements(r);
+ (void)__builtin_vectorelements(rr);
+ (void)__builtin_vectorelements(const veci4);
+ (void)__builtin_vectorelements(decltype(v));
+}
>From eeacd507c7beb32a005633286e0d5fbef1d77b70 Mon Sep 17 00:00:00 2001
From: Akash Manna <akash.manna.mymail at gmail.com>
Date: Sun, 30 Aug 2026 11:02:56 +0530
Subject: [PATCH 2/3] Fix assertion failure for __builtin_vectorelements with
vector type references
---
clang/docs/ReleaseNotes.md | 5 +++--
1 file changed, 3 insertions(+), 2 deletions(-)
diff --git a/clang/docs/ReleaseNotes.md b/clang/docs/ReleaseNotes.md
index a80bba3d99003..ba737310919c4 100644
--- a/clang/docs/ReleaseNotes.md
+++ b/clang/docs/ReleaseNotes.md
@@ -457,8 +457,9 @@ features cannot lower the translation-unit ABI level;
such as when the call is used as an `auto` non-type template argument.
- Fixed a crash in ``__builtin_dump_struct`` when ``-Werror`` promotes
format warnings to errors. (#GH211943)
-- Fixed a crash when `__builtin_vectorelements` is applied to a reference to a
- vector type; this is now diagnosed as an invalid argument type. (#GH216997)
+- Fixed an assertion failure when `__builtin_vectorelements` is applied to a
+ reference to a vector type; this is now diagnosed as an invalid argument type.
+ (#GH216997)
#### Bug Fixes to Attribute Support
>From 604cb90d3496d07ca142f4999a6180bc361faf4e Mon Sep 17 00:00:00 2001
From: Akash Manna <akash.manna.mymail at gmail.com>
Date: Sun, 30 Aug 2026 14:00:55 +0530
Subject: [PATCH 3/3] [clang] Shorten release note for __builtin_vectorelements
fix
---
clang/docs/ReleaseNotes.md | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/clang/docs/ReleaseNotes.md b/clang/docs/ReleaseNotes.md
index ba737310919c4..f57af9e9c936f 100644
--- a/clang/docs/ReleaseNotes.md
+++ b/clang/docs/ReleaseNotes.md
@@ -458,8 +458,7 @@ features cannot lower the translation-unit ABI level;
- Fixed a crash in ``__builtin_dump_struct`` when ``-Werror`` promotes
format warnings to errors. (#GH211943)
- Fixed an assertion failure when `__builtin_vectorelements` is applied to a
- reference to a vector type; this is now diagnosed as an invalid argument type.
- (#GH216997)
+ reference to a vector type. (#GH216997)
#### Bug Fixes to Attribute Support
More information about the cfe-commits
mailing list