[clang][Sema] Reject oversized arrays deduced from initializer lists (#226983)
When an array's size is deduced from its initializer list, Sema skips
the array size check.
On x86_64,
```cpp
typedef char B[1ULL << 60];
B e[16]; // error: array is too large
B d[] = { {0}, {0}, /* ... 16 elements */ }; // accepted, sizeof(d) == 0
```
On i386,
```cpp
struct B { char c[1 << 30]; };
struct B e[5]; // error: array is too large
struct B d[] = { {{0}}, {{0}}, {{0}}, {{0}}, {{0}} }; // accepted, sizeof(d) == 1 GiB
[12 lines not shown]
[Mips] Track ISA mode and distinguish ELF data labels (#228883)
Represent standard MIPS, microMIPS and MIPS16 with a shared ISA mode in
the ELF target streamer. Initialize it from the subtarget, save and
restore it across .set push/pop, and reset it for .set mips0. Disabling
one compressed ISA must not clear the other ISA's active mode. Keep the
assembler's feature bits consistent when switching between them.
Use the mode to mark function and pending instruction labels, propagate
it to aliases, and set the MIPS16 ELF flag for command-line MIPS16 mode.
Clear pending code labels when emitting byte strings or fill directives,
as already done for integer data, so data does not inherit the following
instruction's mode.
Extend the existing label and .ent tests with command-line microMIPS
mode, nested mode changes, initial-mode resets, and data emission.
Assisted-by: OpenAI Codex # Testcases
Return Secret job results to the caller
## Problem
`zfs.resource.encryption.export_key` is a typed job whose result is `Secret[str | None]`, so it returns a `Secret`. The finished-job event sends the raw result to the client and cannot serialize a `Secret`, so the job succeeded but the caller got "Failed to JSON serialize server message" instead of the key.
## Solution
Jobs unwrap a returned `Secret` before storing the result, matching how non-job methods already serialize it. Job listings and debugs still mask the value through the result model.
Unlock zfs resources through typed models
## Problem
Internal callers (failover, boot import, KMIP) started a private dict-based unlock job with its own private models, and results were read with dict indexing. Changing a key from a pipe also rejected valid keys with a leading zero, and change_key accepted keys and passphrases that ZFS would later refuse.
## Solution
- **Unlock**: `zfs.resource.encryption.unlock` gains `start_attachments`, and internal callers start the public job with `ZFSResourceEncryptionUnlockArgsData` and read the returned entry by attribute. `unlock_impl` is now the non-job implementation that takes the model and unwraps secrets once; pool.dataset.unlock calls it directly since it already holds the same job lock.
- **Change key**: the key must be 64 hex characters and a passphrase 8 to 512 characters; a key read from the input pipe is matched as hex text instead of round-tripped through int.
- **Cleanup**: shared `secret_value`/`ancestor_chain` and `is_internal_dataset_name` live in one place each, store_key receives the lowercase ZFS key format while hook payloads are uppercase, and the sync_keys failure is logged with its traceback.
Tidy dataset encryption naming and readability
## Problem
The encryption move left `zfs_resource` wording on the `pool.dataset` side (shared job lock names, the `zr_args` helper, "compatibility wrapper" docstring lines, a `PoolDataset` message raised from zr), and a lot of the moved logic was dense comprehension and `filter`/lambda one-liners that were hard to read.
## Solution
- Job lock names live once in `plugins/zfs/encryption_job_locks.py` with neutral `dataset_encryption_*` names, used by both `pool.dataset` shims and `zfs.resource.encryption`, so both APIs still serialize on the same lock per dataset.
- Shims build zr arguments with the existing `validate_model` instead of a local helper, and their docstrings no longer describe the wrapping.
- zr raises "Dataset {path} does not exist", and the key table model is renamed `EncryptedDatasetModel` (table unchanged).
- Comprehensions, generator expressions, `filter`/`map` lambdas and inline ternaries in the encryption code are plain loops and `if` blocks, with behaviour unchanged.
Move dataset encryption to zfs.resource.encryption
## Problem
Dataset encryption still lived in the `pool.dataset` namespace even though `zfs.resource` is now the dataset API, and zr's own create path had to call back into `pool.dataset.insert_or_update_encrypted_record` to record keys.
## Solution
- **New `zfs.resource.encryption` sub-service** owning lock, unlock, unlock_summary, export_key, export_keys, export_replication_keys, change_key and inherit, with zr conventions (`path`, lowercase enums, `Secret` keys, `ZFS_RESOURCE_*` roles, audit). Public methods delegate to private `*_impl` methods for thread local storage, as the rest of zr does, and everything is synchronous except starting attachment delegates, whose API is async.
- **Private methods moved and renamed** (store_key, delete_keys, stored_keys, sync_keys, encryption_roots, encryption_state, replication_keys, encryption_root_mapping, unlock_impl), together with the `storage_encrypteddataset` model. Every internal caller (failover, pool create/import/export, KMIP, replication, zfs events, zr create) now calls zr directly; no `pool.dataset` alias is left.
- **`pool.dataset` encryption methods are thin shims** keeping their models, roles and pipes. They call the zr `*_impl` methods through the namespace with their own job, so no nested jobs are created, and they share zr's job locks so both APIs serialize on the same dataset. Error messages are unchanged; validation attributes now follow zr names.
- `unlock_impl` has a private Secret-typed accepts model so passphrases handed over by failover stay redacted in job listings.
- Hook names and payloads, including the uppercase key formats failover relies on, are unchanged, and nothing renamed is called across HA controllers.
[flang][Driver] Enable bare -O flag alias when specified with -flto (#228483)
Currently, `O_flag` (`-O` as an alias for `-O1`) in Options.td is not
visible to FlangOption. As a result, invoking flang with a bare `-O`
(without a trailing digit) is treated by the joined `-O` definition as
`-O""`, causing an error when forwarded to the linker.
Add `FlangOption` to `O_flag`'s Visibility so that `flang -O` correctly
aliases to `-O1`.
Assisted-by: IBM Bob
Resolve https://github.com/llvm/llvm-project/issues/227474
[scudo] Validate list endpoints and links before removing a node (#229245)
`DoublyLinkedList::remove()` currently modifies the predecessor's link
before validating the successor's reciprocal link, and checks endpoint
consistency only in debug builds. A corrupted successor can therefore be
rejected after a list write has already occurred, while inconsistent
null links can bypass endpoint checks in release builds.
Check that the list is nonempty, enforce endpoint consistency in release
builds, and validate both reciprocal links before modifying any list
state. The production change is confined to `remove()`. This strengthens
consistency checks; it does not authenticate list membership or protect
against mutually consistent forged interior nodes.
Tests cover all 24 removal orders of four nodes, plus empty-list
removal, both directions of endpoint inconsistency, and corrupted
reciprocal links, using pointer and index links.
Local validation on Linux x86_64 in WSL, Clang 21.1.8:
[23 lines not shown]
[AMDGPU] Require wave ID masks to be constants (#229917)
PR #177713 added some cases to the wave ID recognizer, such
as (ThreadID & Mask) >> log2(WaveSize) but, after it landed, Claude
noticed a bug. `Mask` in those types of expressions was an arbitrary
vale, which could be divergent, meaning that the "uniform" value of
that expression wouldn't actually be uniform.
The quick fix that preserves most of the cases we're worried about in
practice is to restrict these patterns to constant masks.
AI disclosure: Claude found the issue and created the patch, I wrote
this message.
Co-Authored-By: Claude Opus 5 (1M context) <noreply at anthropic.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply at anthropic.com>
[AMDGPU][NFC] Pre-commit tests to not match non-constant wave ID masks (#229916)
Non-constant masks can cause divergences even if we're shifting the
divergent part of a thread ID, and we didn't account for that in the
pattern matches.
AI disclosure: Claude found these and wrote the tests
Co-Authored-By: Claude Opus 5 (1M context) <noreply at anthropic.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply at anthropic.com>
loader.efi: devinit() just after parsing args instead
c4640126f1160 ("loader.efi: Apply command-line DHCP overrides earlier")
was really good, but moving it just one statement earlier is even
better. polarian on Libera describes a GELI setup on a system that
doesn't advertise a serial console via ConOut. They don't have serial
input at the point that they would get prompted for the GELI passphrase,
but if we parse args just before devinit() then he can override the
console with `efibootmgr -e`. This gives UEFI one advantage over BIOS
loader, as /boot.config isn't available to provide that kind of override
if your impediment is GELI.
We also considered reading loader.env earlier, but we have a chicken/egg
problem in that we must have probed for the ESP to be able to open() it.
We would instead need a devinit_early() and devinit_late() scheme that
allows GELI probing to be deferred until the later pass, after reading
loader.env to pick up the console override. That's an idea I'd still
like to discuss because it's more robust than hoping that firmware won't
wipe out our efibootmgr(8) entries.
[4 lines not shown]
Use block identity to find escapes in createIteratorLoop
createIteratorLoop decided that a branch target was outside the loop body
by comparing block numbers with a snapshot taken before the body generator
ran. Block numbers can change: renumbering tripped an assertion, and a
pre-existing block moved within the function got a new number and was
treated as part of the body.
Record the blocks that exist before the body generator runs instead, and
reject branches to any of them other than the body and the latch. Add tests
for renumbering, a moved block, and a callback-created block that branches
to the loop exit.
[Mips][FastISel] Also add low part when materializing private functions (#229717)
I have no idea why the code was explicitly written to exclude private
functions; it seems obviously incorrect to me.
[Clang][AArch64] Command-line options for A-profile's Return Address Authentication Hardening (#176171)
This patch introduces a new command-line option to enable the AArch64
A-profile's Return Address Authentication Hardening. It also introduces
a new function attribute with the same naming as the new command-line
option.
At the time of this patch, this new option enables the hardening against
the PACMAN attack [1] using a load from the return address [2].
The new option, -mharden-pac-ret, can take one of two values:
- none: disable hardening. (The default if the option is absent)
- load-return-address: enables hardening using the mitigation based on
load from return address.
The corresponding function attribute takes the option and its possible
values using the same naming. Also, the function attributes take
precedence over the command-line options.
[6 lines not shown]
[lldb] Update formatter_bytecode.py to ABI version 2 (#229923)
Update the assembler and the Python to bytecode compiler to target the
version 2 formatter ABI, in which `self` is a Dictionary owned by LLDB
and passed as the first argument to every synthetic method.
The primary feature of this change is the separation of storage, locals
are on the stack, attributes are stored in the `self` Dictionary. Since
locals and attrs no longer intermingle in the stack, local variables are
now allowed in `__init__` and `update`, and attributes can be
reassigned.
In the compiler:
* `self.x = expr` is compiled to `0 pick "x" <expr> dict_set`
* `self.x` is compiled to `0 pick "x" dict_get`
* Arguments and local variables are on the stack above `self`
Assisted-by: claude
[OpenMP][OMPIRBuilder] Allow multi-block bodies in createIteratorLoop
createIteratorLoop requires the body generator to leave a single block that
falls through or branches to the loop latch. A body generator that lowers
expressions with their own control flow cannot meet that requirement. The
upcoming user is omp.iterator translation, once its region can contain
several blocks (#227454).
Allow the body to span several blocks. If exactly one block is left without
a terminator, it is branched to the latch; otherwise some block must already
branch there. Bodies that leave more than one block unterminated, or that
branch out of the loop, are rejected with an error.
Assisted with Copilot and Claude Opus 5.
[InstCombine] Fold fdiv by splat of pow/exp/powi into fmul (#227238)
Extend foldFDivPowDivisor to look through a one-use splat divisor. The
exponent is negated on the scalar and the result is splatted again:
$$\frac{Z}{\mathrm{splat}(x^{y})} \to Z \cdot \mathrm{splat}(x^{-y})$$
$$\frac{Z}{\mathrm{splat}(e^{y})} \to Z \cdot \mathrm{splat}(e^{-y})$$
$$\frac{Z}{\mathrm{splat}(2^{y})} \to Z \cdot \mathrm{splat}(2^{-y})$$
$$\frac{Z}{\mathrm{splat}(x^{n})} \to Z \cdot \mathrm{splat}(x^{-n}),
\quad n \in \mathbb{Z}\ (\mathrm{powi})$$
Same FMF requirements as the scalar fold: reassoc and arcp, plus ninf
for powi. This removes the reciprocal, e.g. v_rcp on AMDGPU.
AMDGPU example: https://godbolt.org/z/nvWc38GTx
[orc-rt] Add SymbolLookupFlags and SymbolLookupSet utilities (#229958)
Move NativeDylibManager's nested LookupFlags enum and SymbolLookupSet
typedef out into reusable support utilities:
- SymbolLookupFlags.h: enum class SymbolLookupFlags, with the existing
RequiredSymbol and WeaklyReferencedSymbol values.
- SymbolLookupSet.h: SymbolLookupSet and SymbolLookupResult, thin
wrappers around std::vector<std::pair<std::string, SymbolLookupFlags>>
and std::vector<std::optional<void*>> respectively.
- sps/SPSSymbolLookupSet.h: SPS serialization for all three. The flags
serialization (previously private to NativeDylibManagerSPSCI.cpp, and
duplicated in its unit test) is unchanged: RequiredSymbol serializes as
true, matching llvm::orc::RemoteSymbolLookupSetElement's 'Required'
field.
NativeDylibManager::lookup now takes a SymbolLookupSet and reports a
SymbolLookupResult, and sys::lookupLibrarySymbols takes the
SymbolLookupSet directly, saving lookup a copy of the names.
Assisted-by: Claude
[CodeGen] Drop dead SlotIndexes before allocation
SlotIndexes keeps the index list entry of an erased instruction and only
clears its instruction pointer. Live range sizes are measured in slot
indexes and greedy ranks ranges by size, so the leftovers inflate some
ranges more than others and reorder allocation, spilling heavily on
register-starved functions.
Add SlotIndexes::compactIndexes() to erase them. Erased entries are
unlinked, so LiveIntervals first reports the indexes it holds via
appendReferencedIndexes().
Off by default behind -greedy-compact-slot-indexes, since it changes
allocation across much of the test suite.