[llvm] [InstCombine] Fold icmp in select to smin (PR #196823)
Yingwei Zheng via llvm-commits
llvm-commits at lists.llvm.org
Sun May 10 13:11:06 PDT 2026
dtcxzyw wrote:
The following correctness issue was found by [llvm-hackme](https://github.com/dtcxzyw/llvm-hackme).
<!-- llvm-hackme-state: bug_found -->
<!-- llvm-hackme-baseline: 2893aa5d1f31d62a8f1c50e202d7924004792f2b -->
<!-- llvm-hackme-head-sha: 2b3da6230d82d4dcb3c267dd4e26ede0ea26eebe -->
<!-- llvm-hackme-patch-sha256: e0b5426350abb4b69cad0e1436d9692c72feb01915d480d96d7c3b22c9a6773b -->
<!-- llvm-hackme-kind: miscompilation -->
This comment is generated by an automated correctness checking service designed to help identify critical correctness bugs (opt crashes or Alive2 miscompilations) and improve PR review efficiency under limited reviewer bandwidth.
## Reproducer
**Kind**: miscompilation
**IR Reproducer**:
```llvm
; RUN: opt -passes=instcombine<no-verify-fixpoint> -S
define i8 @f(i8 %a, i1 %x) {
%mask = zext i1 %x to i8
%or = or i8 %a, %mask
%cmp = icmp sgt i8 %a, -1
%sel = select i1 %cmp, i8 1, i8 %or
ret i8 %sel
}
```
**Alive2 Counterexample**:
```
----------------------------------------
define i8 @f(i8 %a, i1 %x) {
#0:
%mask = zext i1 %x to i8
%or = or i8 %a, %mask
%cmp = icmp sgt i8 %a, 255
%sel = select i1 %cmp, i8 1, i8 %or
ret i8 %sel
}
=>
define i8 @f(i8 %a, i1 %x) {
#0:
%mask = zext i1 %x to i8
%or = or i8 %a, %mask
%sel = smin i8 %or, 1
ret i8 %sel
}
Transformation doesn't verify!
ERROR: Target is more poisonous than source
Example:
i8 %a = #x00 (0)
i1 %x = poison
Source:
i8 %mask = poison
i8 %or = poison
i1 %cmp = #x1 (1)
i8 %sel = #x01 (1)
Target:
i8 %mask = poison
i8 %or = poison
i8 %sel = poison
Source value: #x01 (1)
Target value: poison
Summary:
0 correct transformations
1 incorrect transformations
0 failed-to-prove transformations
0 Alive2 errors
```
**Opt Output**:
```llvm
; ModuleID = '/tmp/tmpxjq83yde.ll'
source_filename = "/tmp/tmpxjq83yde.ll"
define i8 @f(i8 %a, i1 %x) {
%mask = zext i1 %x to i8
%or = or i8 %a, %mask
%sel = call i8 @llvm.smin.i8(i8 %or, i8 1)
ret i8 %sel
}
; Function Attrs: nocallback nocreateundeforpoison nofree nosync nounwind speculatable willreturn memory(none)
declare i8 @llvm.smin.i8(i8, i8) #0
attributes #0 = { nocallback nocreateundeforpoison nofree nosync nounwind speculatable willreturn memory(none) }
```
**Baseline Revision**: `2893aa5d1f31d62a8f1c50e202d7924004792f2b`
**PR Head SHA**: `2b3da6230d82d4dcb3c267dd4e26ede0ea26eebe`
**Patch SHA256**: `e0b5426350abb4b69cad0e1436d9692c72feb01915d480d96d7c3b22c9a6773b`
https://github.com/llvm/llvm-project/pull/196823
More information about the llvm-commits
mailing list