[all-commits] [llvm/llvm-project] bcdf3c: [RISCV] Fix crash in combinePExtTruncate for trunc...

Kito Cheng via All-commits all-commits at lists.llvm.org
Thu Mar 12 20:31:25 PDT 2026


  Branch: refs/heads/main
  Home:   https://github.com/llvm/llvm-project
  Commit: bcdf3c930b8bbf59e7fc65da37c5baa89aa73f30
      https://github.com/llvm/llvm-project/commit/bcdf3c930b8bbf59e7fc65da37c5baa89aa73f30
  Author: Kito Cheng <kito.cheng at sifive.com>
  Date:   2026-03-13 (Fri, 13 Mar 2026)

  Changed paths:
    M llvm/lib/Target/RISCV/RISCVISelLowering.cpp
    A llvm/test/CodeGen/RISCV/rvp-narrowing-shift-trunc.ll

  Log Message:
  -----------
  [RISCV] Fix crash in combinePExtTruncate for truncate(srl) without MUL/SUB (#186141)

combinePExtTruncate is called from performTRUNCATECombine when the
P-extension is enabled. It attempts to match patterns like
truncate(srl(mul/sub(...), shamt)) and combine them into P-extension
narrowing shift instructions (e.g. PNSRLI, PNSRAI).

However, after extracting the shift input operand `Op` from the SRL
node, the function unconditionally accessed Op.getOperand(0) and
Op.getOperand(1) without first verifying that Op has at least two
operands. For example, when combining:

```
  truncate(v2i16
    srl(v2i32
      bitcast(v2i32 i64),   <-- Op = bitcast, a unary op with 1 operand
      BUILD_VECTOR <8, 8>))
```

Op is a BITCAST node (unary, only 1 operand), so accessing
Op.getOperand(1) triggers an out-of-bounds assertion:

```
  Assertion `Num < NumOperands && "Invalid child # of SDNode!"' failed.
```

Add an early return when Op has fewer than two operands.



To unsubscribe from these emails, change your notification settings at https://github.com/llvm/llvm-project/settings/notifications


More information about the All-commits mailing list