[llvm] [SeparateConstOffsetFromGEP] Fix incorrect inbounds flag in case of non-negative index but negative offset (PR #190192)

Sergey Kachkov via llvm-commits llvm-commits at lists.llvm.org
Thu Apr 2 09:04:39 PDT 2026


skachkov-sc wrote:

> I might be misunderstanding something here, but isn't the case you describe poison in the input program? `inbounds` implies `nusw` (according to the [langref](https://llvm.org/docs/LangRef.html#id241)), which says that "The multiplication of an index by the type size does not wrap the pointer index type in a signed sense (mul nsw)."
> 
> The case where a GEP has `inbounds` and the index is non-negative, but its offset (in bytes) is negative as you describe would violate that, right?

In input program (https://godbolt.org/z/G5o6E7vKb) GEP takes %sub value as an index (not %shr), so the possible index values for %sub are 2, 3 or 4 (they are not overflowed after multiplication by 8). The problem appears only when we replace index from %sub to %shr - it has some huge non-negative value that wraps when it's multiplied by the type size. You are right that we can't even preserve nusw/nuw attributes after splitGEP here (that have more lenient rules than inbounds attribute)

https://github.com/llvm/llvm-project/pull/190192


More information about the llvm-commits mailing list