https://github.com/AZero13 updated https://github.com/llvm/llvm-project/pull/209593
>From d8c3c934907e7d3fdf84009e2aa02504c6b5baa1 Mon Sep 17 00:00:00 2001 From: AZero13 <[email protected]> Date: Tue, 14 Jul 2026 14:57:42 -0400 Subject: [PATCH] [Clang] Restrict CWG1504 devirtualization to pointer arithmetic on record types Fixes a regression introduced in PR #207540 where virtual calls (including destructor calls in delete expressions) were incorrectly devirtualized on pointers obtained from pointer arithmetic on pointers (e.g. array-of-pointers subscripts). --- clang/lib/AST/DeclCXX.cpp | 13 +++++ clang/lib/AST/Expr.cpp | 40 +++++++++++++ clang/test/CXX/drs/cwg15xx.cpp | 19 ++++++ .../devirtualize-virtual-function-calls.cpp | 58 ++++++++++++++++++- clang/www/cxx_dr_status.html | 2 +- 5 files changed, 129 insertions(+), 3 deletions(-) diff --git a/clang/lib/AST/DeclCXX.cpp b/clang/lib/AST/DeclCXX.cpp index 0573cdf95952a..f1e658c5ca7b5 100644 --- a/clang/lib/AST/DeclCXX.cpp +++ b/clang/lib/AST/DeclCXX.cpp @@ -2600,6 +2600,19 @@ CXXMethodDecl *CXXMethodDecl::getDevirtualizedMethod(const Expr *Base, } } + // CWG1504: Pointer arithmetic on a base pointer into a derived array is UB. + // Expr::getBestDynamicClassTypeExpr does not strip non-zero offset + // expressions, meaning the dynamic type is guaranteed to be the static type. + if (isa<ArraySubscriptExpr>(Base) || + (isa<UnaryOperator>(Base) && + cast<UnaryOperator>(Base)->getOpcode() == UO_Deref) || + (isa<BinaryOperator>(Base) && + cast<BinaryOperator>(Base)->getType()->isPointerType() && + (cast<BinaryOperator>(Base)->getOpcode() == BO_Add || + cast<BinaryOperator>(Base)->getOpcode() == BO_Sub))) { + return DevirtualizedMethod; + } + // We can't devirtualize the call. return nullptr; } diff --git a/clang/lib/AST/Expr.cpp b/clang/lib/AST/Expr.cpp index 0bb9c6aa01c39..2e62cf463b8d9 100644 --- a/clang/lib/AST/Expr.cpp +++ b/clang/lib/AST/Expr.cpp @@ -61,6 +61,46 @@ const Expr *Expr::getBestDynamicClassTypeExpr() const { continue; } + // CWG1504: Pointer arithmetic on an array of objects. If the index is + // non-zero, the dynamic type must be the same as the static type. + const Expr *Base = nullptr; + const Expr *Idx = nullptr; + const CXXRecordDecl *CRD = nullptr; + + if (const auto *ASE = dyn_cast<ArraySubscriptExpr>(E)) { + Base = ASE->getBase(); + Idx = ASE->getIdx(); + CRD = ASE->getType()->getAsCXXRecordDecl(); + } else if (const auto *UO = dyn_cast<UnaryOperator>(E); + UO && UO->getOpcode() == UO_Deref) { + if (const auto *BO = dyn_cast<BinaryOperator>( + UO->getSubExpr()->IgnoreParenImpCasts()); + BO && (BO->getOpcode() == BO_Add || BO->getOpcode() == BO_Sub)) { + Base = BO->getLHS()->getType()->isPointerType() ? BO->getLHS() + : BO->getRHS(); + Idx = BO->getLHS()->getType()->isPointerType() ? BO->getRHS() + : BO->getLHS(); + CRD = UO->getType()->getAsCXXRecordDecl(); + } + } else if (const auto *BO = dyn_cast<BinaryOperator>(E); + BO && (BO->getOpcode() == BO_Add || BO->getOpcode() == BO_Sub) && + BO->getType()->isPointerType()) { + Base = BO->getLHS()->getType()->isPointerType() ? BO->getLHS() + : BO->getRHS(); + Idx = BO->getLHS()->getType()->isPointerType() ? BO->getRHS() + : BO->getLHS(); + CRD = BO->getType()->getPointeeType()->getAsCXXRecordDecl(); + } + + if (Base && Idx && CRD && CRD->isDynamicClass()) { + Expr::EvalResult Result; + if (!Idx->EvaluateAsInt(Result, CRD->getASTContext()) || + Result.Val.getInt().isZero()) { + E = Base; + continue; + } + } + break; } diff --git a/clang/test/CXX/drs/cwg15xx.cpp b/clang/test/CXX/drs/cwg15xx.cpp index 5a9b80ed028c4..b9e0525772779 100644 --- a/clang/test/CXX/drs/cwg15xx.cpp +++ b/clang/test/CXX/drs/cwg15xx.cpp @@ -11,6 +11,25 @@ // cxx98-error@-1 {{variadic macros are a C99 feature}} #endif +namespace cwg1504 { // cwg1504: 3.1 +#if __cplusplus >= 201103L + // CWG1504: Pointer arithmetic after derived-base conversion + struct Base { int x; }; + struct Derived : Base { int y; }; + constexpr Derived arr[2] = {}; + + // Pointer arithmetic on a base pointer into a derived array is UB, + // and the constexpr evaluator must diagnose it. + constexpr int test(int n) { + return ((const Base*)arr)[n].x; // #cwg1504-x + } + constexpr int bad = test(1); + // since-cxx11-error@-1 {{constexpr variable 'bad' must be initialized by a constant expression}} + // since-cxx11-note@#cwg1504-x {{cannot access field of pointer past the end of object}} + // since-cxx11-note@-3 {{in call to 'test(1)'}} +#endif +} // namespace cwg1504 + namespace cwg1512 { // cwg1512: 4 void f(char *p) { if (p > 0) {} diff --git a/clang/test/CodeGenCXX/devirtualize-virtual-function-calls.cpp b/clang/test/CodeGenCXX/devirtualize-virtual-function-calls.cpp index b50881db63e05..dac2c2b183d7d 100644 --- a/clang/test/CodeGenCXX/devirtualize-virtual-function-calls.cpp +++ b/clang/test/CodeGenCXX/devirtualize-virtual-function-calls.cpp @@ -92,10 +92,48 @@ void fd(D d, XD xd, D *p) { // CHECK: call void % p[0].f(); - // FIXME: We can devirtualize this, by C++1z [expr.add]/6 (if the array + // We can devirtualize this, by CWG1504 / [expr.add]/6 (if the array // element type and the pointee type are not similar, behavior is undefined). - // CHECK: call void % + // CHECK: call void @_ZN1A1fEv p[1].f(); + + // Negative indices are also UB for the same reason. + // CHECK: call void @_ZN1A1fEv + p[-1].f(); + + // Pointer arithmetic with arrow syntax: (p + N)->f() + // CHECK: call void @_ZN1A1fEv + (p + 1)->f(); + + // Pointer subtraction with arrow syntax: (p - N)->f() + // CHECK: call void @_ZN1A1fEv + (p - 1)->f(); + + // Can't devirtualize with non-constant index; we can't prove N != 0. + int n = 1; + // CHECK: call void % + p[n].f(); + + // Zero through expression: p[1-1] evaluates to 0, can't devirtualize. + // CHECK: call void % + p[1-1].f(); + + // (p + 0)->f() also can't be devirtualized (same as *p). + // CHECK: call void % + (p + 0)->f(); + + // 1 + p is legal pointer arithmetic too. + // CHECK: call void @_ZN1A1fEv + (1 + p)->f(); + + // Constant variables are evaluated. + const int N = 1; + // CHECK: call void @_ZN1A1fEv + p[N].f(); + + // Pointer arithmetic with deref: *(p + 1) + // CHECK: call void @_ZN1A1fEv + (*(p + 1)).f(); } struct B { @@ -195,3 +233,19 @@ namespace test5 { q.f(); } } + +namespace test6 { + struct Thing { + virtual ~Thing(); + virtual void f(); + }; + + // CHECK-LABEL: define {{.*}} @_ZN5test63fooEPPNS_5ThingE + void foo(Thing **instances) { + // CHECK: call void % + instances[1]->f(); + + // CHECK: call void % + delete instances[1]; + } +} diff --git a/clang/www/cxx_dr_status.html b/clang/www/cxx_dr_status.html index af91ac559d274..ffa16dc066bfe 100755 --- a/clang/www/cxx_dr_status.html +++ b/clang/www/cxx_dr_status.html @@ -10309,7 +10309,7 @@ <h2 id="cxxdr">C++ defect report implementation status</h2> <td>[<a href="https://wg21.link/expr.add">expr.add</a>]</td> <td>CD3</td> <td>Pointer arithmetic after derived-base conversion</td> - <td class="unknown" align="center">Unknown</td> + <td class="full" align="center">Clang 3.1</td> </tr> <tr id="1505"> <td><a href="https://cplusplus.github.io/CWG/issues/1505.html">1505</a></td> _______________________________________________ cfe-commits mailing list [email protected] https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits
