[llvm] [InstCombine] Fold patterns which uses <2N x iM> type for comparisons on <N x i2M> vector types (PR #184328)
Yunbo Ni via llvm-commits
llvm-commits at lists.llvm.org
Sun May 10 02:22:50 PDT 2026
================
----------------
cardigan1008 wrote:
Hi, this is a related miscompilation case: https://alive2.llvm.org/ce/z/qd2cWM
The fix treats `select C, X, 0` as interchangeable with `and C, X` in vector mask-combine idioms. That is not valid under LLVM poison semantics. A vector select only propagates poison from the chosen value for each lane; if the condition lane is false, poison in the true value is masked. A bitwise and, and especially the replacement widened compare, unconditionally depend on both halves of the widened element. The fold therefore incorrectly speculates dependence on a half-lane that the original logical-select form could avoid.
The weakness is specifically in accepting the `m_Select(Equal, Shuffle, m_Zero())` alternative in `foldVecCmpEqOnHalfElementSize` and replacing it with a full-width compare without proving that the shuffled half cannot be poison when the condition is false. The same poison-masking issue likely also affects the analogous greater-than logical-select pattern, but this minimal equality test is sufficient to expose a real miscompile in the patched transform.
There are other similar bugs, you could refer to https://archer.top/artifact/run/184328/run.review.md.
> Found with [Archer](https://github.com/cuhk-s3/Archer). Please let me know if anything is wrong.
https://github.com/llvm/llvm-project/pull/184328
More information about the llvm-commits
mailing list