[llvm-bugs] [Bug 45954] New: Incorrect instcombine fold of vector ult -> sgt
via llvm-bugs
llvm-bugs at lists.llvm.org
Sun May 17 04:53:52 PDT 2020
https://bugs.llvm.org/show_bug.cgi?id=45954
Bug ID: 45954
Summary: Incorrect instcombine fold of vector ult -> sgt
Product: libraries
Version: trunk
Hardware: All
OS: All
Status: NEW
Keywords: miscompilation
Severity: normal
Priority: P
Component: Scalar Optimizations
Assignee: unassignedbugs at nondot.org
Reporter: nunoplopes at sapo.pt
CC: lebedev.ri at gmail.com, llvm-bugs at lists.llvm.org,
regehr at cs.utah.edu, spatel+llvm at rotateright.com
Test:
Transforms/InstCombine/canonicalize-clamp-like-pattern-between-zero-and-positive-threshold.ll
Summary: There's a off-by-one in the transformation below that makes the
optimize code return the wrong value.
The original code can return either %x or %replacement_low, while the optimized
code returns %replacement_high for %x[1] == 65536.
define <3 x i32> @t20_ult_slt_vec_undef1(<3 x i32> %x, <3 x i32>
%replacement_low, <3 x i32> %replacement_high) {
%t0 = icmp slt <3 x i32> %x, { 65536, 65537, 65536 }
%t1 = select <3 x i1> %t0, <3 x i32> %replacement_low, <3 x i32>
%replacement_high
%t2 = icmp ult <3 x i32> %x, { 65536, undef, 65536 }
%r = select <3 x i1> %t2, <3 x i32> %x, <3 x i32> %t1
ret <3 x i32> %r
}
=>
define <3 x i32> @t20_ult_slt_vec_undef1(<3 x i32> %x, <3 x i32>
%replacement_low, <3 x i32> %replacement_high) {
%1 = icmp slt <3 x i32> %x, { 0, 0, 0 }
%2 = icmp sgt <3 x i32> %x, { 65535, 65535, 65535 }
%3 = select <3 x i1> %1, <3 x i32> %replacement_low, <3 x i32> %x
%r = select <3 x i1> %2, <3 x i32> %replacement_high, <3 x i32> %3
ret <3 x i32> %r
}
Transformation doesn't verify!
ERROR: Value mismatch
Example:
<3 x i32> %x = < #x0000ffff (65535), #x00010000 (65536), #x08000000 (134217728)
>
<3 x i32> %replacement_low = < *, #x00000000 (0), * >
<3 x i32> %replacement_high = < *, #x00001000 (4096), #x0000ffff (65535) >
Source:
<3 x i1> %t0 = < #x1 (1), #x1 (1), #x0 (0) >
<3 x i32> %t1 = < *, #x00000000 (0), #x0000ffff (65535) >
<3 x i1> %t2 = < #x1 (1), undef, #x0 (0) >
<3 x i32> %r = < #x0000ffff (65535), #x00000000 (0) [based on undef value],
#x0000ffff (65535) >
Target:
<3 x i1> %1 = < #x0 (0), #x0 (0), #x0 (0) >
<3 x i1> %2 = < #x0 (0), #x1 (1), #x1 (1) >
<3 x i32> %3 = < #x0000ffff (65535), #x00010000 (65536), #x08000000 (134217728)
>
<3 x i32> %r = < #x0000ffff (65535), #x00001000 (4096), #x0000ffff (65535) >
Source value: < #x0000ffff (65535), #x00000000 (0), #x0000ffff (65535) >
Target value: < #x0000ffff (65535), #x00001000 (4096), #x0000ffff (65535) >
https://web.ist.utl.pt/nuno.lopes/alive2/index.php?hash=72296a443c683892&test=Transforms%2FInstCombine%2Fcanonicalize-clamp-like-pattern-between-zero-and-positive-threshold.ll
--
You are receiving this mail because:
You are on the CC list for the bug.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.llvm.org/pipermail/llvm-bugs/attachments/20200517/8b03ebac/attachment.html>
More information about the llvm-bugs
mailing list