[clang] [Clang] Bound `ext_vector_type` element count by the widest LLVM integer (PR #226375)
via cfe-commits
cfe-commits at lists.llvm.org
Fri Sep 25 01:13:46 PDT 2026
llvmorg-github-actions[bot] wrote:
<!--LLVM PR SUMMARY COMMENT-->
@llvm/pr-subscribers-clang
Author: Akash Manna (akash-manna-sky)
<details>
<summary>Changes</summary>
Fixes #<!-- -->165458
A `bool` vector declared with `ext_vector_type` isn't lowered as an LLVM vector in memory: `ConvertTypeForMem` packs it into a single integer with one bit per element. `BuildExtVectorType` only checked that the element count fits in 32 bits, though, so a vector of 187,553,262 bools got through Sema and the first consumer that needed its memory type (the zero initializer of a tentative definition here) asked `IntegerType::get` for far more than the 2^23 bits it supports. Loads, stores, constant initializers and debug info would have tripped over the same type.
The element count is now bounded by `llvm::IntegerType::MAX_INT_BITS` (2^23 elements) when the type is built, reusing the existing "vector size too large" error, so the type never exists. The bound applies to every element type rather than just `bool`, because Sema also manufactures bool vectors out of other ext vectors: `c ? true : false` with a `char` ext vector condition produces a bool vector of the same length, in C and C++ alike, and crashed the same way. `vector_size` is left alone since it doesn't allow `bool` elements in the first place.
---
Full diff: https://github.com/llvm/llvm-project/pull/226375.diff
4 Files Affected:
- (modified) clang/docs/ReleaseNotes.md (+4)
- (modified) clang/lib/Sema/SemaType.cpp (+5-3)
- (modified) clang/test/Sema/types.c (+9)
- (modified) clang/test/SemaCXX/vector.cpp (+9)
``````````diff
The server is unavailable at this time. Please wait a few minutes before you try again.
``````````
</details>
https://github.com/llvm/llvm-project/pull/226375
More information about the cfe-commits
mailing list