[clang] [clang] Fix crash constant-evaluating huge arrays of zero-sized elements (PR #226899)

via cfe-commits cfe-commits at lists.llvm.org
Mon Sep 28 00:55:18 PDT 2026


llvmorg-github-actions[bot] wrote:


<!--LLVM PR SUMMARY COMMENT-->

@llvm/pr-subscribers-clang

Author: Akash Manna (akash-manna-sky)

<details>
<summary>Changes</summary>

Fixes #<!-- -->173728

An array of zero-sized elements like `struct T {} s[-sizeof(0)][0]` slipped past Sema's size check, because that check only looks at the total size in bytes, and zero times anything is zero. So we ended up with an array of 2^64 - 4 elements. The constant evaluator, which runs on this code on its own (e.g. `isEvaluatable` in codegen or range checks for `-W` warnings), then tried to default-construct it: the element count got truncated to `unsigned` and we either ran out of memory allocating an `APValue` per element, or hit the "bounds check failed for in-bounds index" assertion in `adjustIndex` first. This goes back to at least Clang 3.4.

Sema now checks the element count against the same limit as the byte size, so these arrays are rejected with the usual "array is too large" error, like GCC does. For counts that are still allowed, the array paths in `VisitCXXConstructExpr` and `VisitArrayInitLoopExpr` now go through the existing `CheckArraySize` guard, the same one used for `new` and array destruction, so evaluation just gives up instead of trying to build billions of elements.


---
Full diff: https://github.com/llvm/llvm-project/pull/226899.diff


7 Files Affected:

- (modified) clang/docs/ReleaseNotes.md (+4) 
- (modified) clang/lib/AST/ExprConstant.cpp (+4) 
- (modified) clang/lib/Sema/SemaType.cpp (+8-6) 
- (modified) clang/test/CodeGenCXX/stmtexpr.cpp (+5) 
- (modified) clang/test/Sema/array-size-64.c (+7) 
- (modified) clang/test/SemaCXX/cxx2a-constexpr-dynalloc-limits.cpp (+34) 
- (modified) clang/test/SemaCXX/zero-length-arrays.cpp (+41-2) 


``````````diff
The server is unavailable at this time. Please wait a few minutes before you try again.
``````````

</details>


https://github.com/llvm/llvm-project/pull/226899


More information about the cfe-commits mailing list