[llvm] 51845a5 - [SLP] Fix crash on extractelement with out-of-bounds index.....Fixes … (#176918)
via llvm-commits
llvm-commits at lists.llvm.org
Wed Jan 28 03:08:09 PST 2026
Author: Soumik15630m
Date: 2026-01-28T06:08:03-05:00
New Revision: 51845a53fd2e2f6b0a18dfad3f912e9f676a5fc9
URL: https://github.com/llvm/llvm-project/commit/51845a53fd2e2f6b0a18dfad3f912e9f676a5fc9
DIFF: https://github.com/llvm/llvm-project/commit/51845a53fd2e2f6b0a18dfad3f912e9f676a5fc9.diff
LOG: [SLP] Fix crash on extractelement with out-of-bounds index.....Fixes … (#176918)
…The cose modeling logic was attempting to set a bit in APInt for an
out-of-bounds index, causing an assertion failure. This patch ignores
OOB indices as they produce poison- which is already handled.
Fixes #176780
this is the same test result which produces this bug
<img width="1600" height="964" alt="image"
src="https://github.com/user-attachments/assets/80593902-9d15-4e18-850b-a558bca8518e"
/>
Added:
llvm/test/Transforms/SLPVectorizer/X86/crash-on-out-of-bound-extract.ll
Modified:
llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp
Removed:
################################################################################
diff --git a/llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp b/llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp
index 3034e94b59972..ce47868023880 100644
--- a/llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp
+++ b/llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp
@@ -902,7 +902,14 @@ static std::optional<unsigned> getExtractIndex(const Instruction *E) {
auto *CI = dyn_cast<ConstantInt>(E->getOperand(1));
if (!CI)
return std::nullopt;
- return CI->getZExtValue();
+ // Check if the index is out of bound - we can get the source vector from
+ // operand 0
+ unsigned Idx = CI->getZExtValue();
+ auto *EE = cast<ExtractElementInst>(E);
+ const unsigned VF = ::getNumElements(EE->getVectorOperandType());
+ if (Idx >= VF)
+ return std::nullopt;
+ return Idx;
}
auto *EI = cast<ExtractValueInst>(E);
if (EI->getNumIndices() != 1)
diff --git a/llvm/test/Transforms/SLPVectorizer/X86/crash-on-out-of-bound-extract.ll b/llvm/test/Transforms/SLPVectorizer/X86/crash-on-out-of-bound-extract.ll
new file mode 100644
index 0000000000000..aff48f0fc6cb1
--- /dev/null
+++ b/llvm/test/Transforms/SLPVectorizer/X86/crash-on-out-of-bound-extract.ll
@@ -0,0 +1,32 @@
+; NOTE: Assertions have been autogenerated by utils/update_test_checks.py UTC_ARGS: --version 6
+; RUN: opt -passes=slp-vectorizer -S < %s | FileCheck %s
+
+
+
+define <4 x i32> @test(<4 x i32> %A){
+; CHECK-LABEL: define <4 x i32> @test(
+; CHECK-SAME: <4 x i32> [[A:%.*]]) {
+; CHECK-NEXT: [[ENTRY:.*:]]
+; CHECK-NEXT: [[TMP0:%.*]] = shufflevector <4 x i32> [[A]], <4 x i32> poison, <4 x i32> <i32 0, i32 poison, i32 poison, i32 2>
+; CHECK-NEXT: [[TMP3:%.*]] = shufflevector <4 x i32> [[A]], <4 x i32> poison, <4 x i32> <i32 0, i32 1, i32 1, i32 3>
+; CHECK-NEXT: [[TMP2:%.*]] = sdiv <4 x i32> [[TMP0]], [[TMP3]]
+; CHECK-NEXT: [[TMP1:%.*]] = shufflevector <4 x i32> [[TMP2]], <4 x i32> poison, <4 x i32> <i32 0, i32 1, i32 3, i32 2>
+; CHECK-NEXT: ret <4 x i32> [[TMP1]]
+;
+entry:
+ %e0 = extractelement <4 x i32> %A, i64 0
+ %e1 = extractelement <4 x i32> %A, i64 1
+ %e2 = extractelement <4 x i32> %A, i64 2
+ %e3 = extractelement <4 x i32> %A, i64 3
+ %oob = extractelement <4 x i32> %A, i64 4
+ %d0 = sdiv i32 %e0, %e0
+ %d1 = sdiv i32 %oob, %e1
+ %d2 = sdiv i32 %e2, %e3
+ %d3 = sdiv i32 %oob, %e1
+ %v0 = insertelement <4 x i32> poison, i32 %d0, i64 0
+ %v1 = insertelement <4 x i32> %v0, i32 %d1, i64 1
+ %v2 = insertelement <4 x i32> %v1, i32 %d2, i64 2
+ %v3 = insertelement <4 x i32> %v2, i32 %d3, i64 3
+ ret <4 x i32> %v3
+
+}
More information about the llvm-commits
mailing list