[llvm] [IR] Reject token and label overload types in intrinsic signature matching (PR #210799)

Akshay K via llvm-commits llvm-commits at lists.llvm.org
Wed Aug 26 07:20:40 PDT 2026


https://github.com/kumarak updated https://github.com/llvm/llvm-project/pull/210799

>From 96c498dfacb38626f87cb542da36537b58170248 Mon Sep 17 00:00:00 2001
From: AkshayK <iit.akshay at gmail.com>
Date: Mon, 20 Jul 2026 14:08:06 -0400
Subject: [PATCH] [IR] Reject token overload types in intrinsic signature
 matching

Declaring an llvm_any_ty intrinsic with a token overload type, e.g.

  declare token @llvm.ssa.copy.token(token)

crashed opt at parse time: the unconstrained Any matcher accepted token,
and remangleIntrinsicFunction (run before the Verifier) then hit
llvm_unreachable("Unhandled type") mangling it into the intrinsic name.

Token has no name mangling, so no overloaded intrinsic can be
instantiated on it. Reject it in matchIntrinsicType's Overloaded case,
degrading the crash into the same broken-module diagnostic that
constrained overloads already produce. Fixed llvm_token_ty operands
(gc.result, coro.*, ...) are unaffected.

Label needs no such check: it is excluded from function signatures by
FunctionType::isValidReturnType/isValidArgumentType and the LLParser, so
it never reaches matchIntrinsicType.

Fixes #210641.
---
 llvm/lib/IR/Intrinsics.cpp                          |  6 ++++++
 .../Assembler/intrinsic-token-overload-invalid.ll   | 13 +++++++++++++
 2 files changed, 19 insertions(+)
 create mode 100644 llvm/test/Assembler/intrinsic-token-overload-invalid.ll

diff --git a/llvm/lib/IR/Intrinsics.cpp b/llvm/lib/IR/Intrinsics.cpp
index 266af8e06a230..4a66391832d49 100644
--- a/llvm/lib/IR/Intrinsics.cpp
+++ b/llvm/lib/IR/Intrinsics.cpp
@@ -1098,6 +1098,12 @@ matchIntrinsicType(Type *Ty, ArrayRef<Intrinsic::IITDescriptor> &Infos,
            "Table consistency error");
     OverloadTys.push_back(Ty);
 
+    // Token has no mangling (see getMangledTypeStr), so it cannot be an
+    // overload type; reject it with a signature error. Label is already
+    // excluded from function signatures, so it never reaches here.
+    if (Ty->isTokenTy())
+      return PrintMsg(false, "any manglable type", OIdx);
+
     IITDescriptor::AnyKindVectorConstraint VC;
     IITDescriptor::AnyKindElementConstraint EC;
     std::tie(VC, EC) = D.getOverloadConstraints();
diff --git a/llvm/test/Assembler/intrinsic-token-overload-invalid.ll b/llvm/test/Assembler/intrinsic-token-overload-invalid.ll
new file mode 100644
index 0000000000000..84d0882b50085
--- /dev/null
+++ b/llvm/test/Assembler/intrinsic-token-overload-invalid.ll
@@ -0,0 +1,13 @@
+; RUN: not opt -disable-output %s 2>&1 | FileCheck %s
+
+; Token overloads of llvm_any_ty intrinsics used to crash parse-time intrinsic
+; remangling with "Unhandled type" in the name mangler (#210641). They must be
+; rejected with a normal signature error, like constrained overloads are.
+
+; CHECK: intrinsic return type (overload type 0) expected any manglable type, but got token
+declare token @llvm.ssa.copy.ttoken(token)
+
+; CHECK: intrinsic argument 0 type (overload type 0) expected any manglable type, but got token
+declare i1 @llvm.is.constant.ttoken(token)
+
+; CHECK: error: input module is broken!



More information about the llvm-commits mailing list