[clang] [Clang] Bound `ext_vector_type` element count by the widest LLVM integer (PR #226375)

via cfe-commits cfe-commits at lists.llvm.org
Fri Sep 25 01:13:46 PDT 2026


llvmorg-github-actions[bot] wrote:


<!--LLVM PR SUMMARY COMMENT-->

@llvm/pr-subscribers-clang

Author: Akash Manna (akash-manna-sky)

<details>
<summary>Changes</summary>

Fixes #<!-- -->165458

A `bool` vector declared with `ext_vector_type` isn't lowered as an LLVM vector in memory: `ConvertTypeForMem` packs it into a single integer with one bit per element. `BuildExtVectorType` only checked that the element count fits in 32 bits, though, so a vector of 187,553,262 bools got through Sema and the first consumer that needed its memory type (the zero initializer of a tentative definition here) asked `IntegerType::get` for far more than the 2^23 bits it supports. Loads, stores, constant initializers and debug info would have tripped over the same type.

The element count is now bounded by `llvm::IntegerType::MAX_INT_BITS` (2^23 elements) when the type is built, reusing the existing "vector size too large" error, so the type never exists. The bound applies to every element type rather than just `bool`, because Sema also manufactures bool vectors out of other ext vectors: `c ? true : false` with a `char` ext vector condition produces a bool vector of the same length, in C and C++ alike, and crashed the same way. `vector_size` is left alone since it doesn't allow `bool` elements in the first place.


---
Full diff: https://github.com/llvm/llvm-project/pull/226375.diff


4 Files Affected:

- (modified) clang/docs/ReleaseNotes.md (+4) 
- (modified) clang/lib/Sema/SemaType.cpp (+5-3) 
- (modified) clang/test/Sema/types.c (+9) 
- (modified) clang/test/SemaCXX/vector.cpp (+9) 


``````````diff
The server is unavailable at this time. Please wait a few minutes before you try again.
``````````

</details>


https://github.com/llvm/llvm-project/pull/226375


More information about the cfe-commits mailing list