[llvm] [Peephole] Fix "Use not jointly dominated by defs." crash (PR #202216)
Paweł Bylica via llvm-commits
llvm-commits at lists.llvm.org
Sun Jun 7 10:30:54 PDT 2026
https://github.com/chfast created https://github.com/llvm/llvm-project/pull/202216
The instruction created by foldLoadInto can reuse the memory of the compare just erased by optimizeCompareInstr. Erasing the stale pointer from LocalMIs afterwards dropped the new instruction instead, and optimizeExtInstr then rewrote it to use a not-yet-defined extension result.
Fixes #199237.
>From 0fb783103ab0d0e2a4573e39e3887d698ea4ddbf Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Pawe=C5=82=20Bylica?= <pawel at hepcolgum.band>
Date: Sun, 7 Jun 2026 18:30:33 +0200
Subject: [PATCH] [Peephole] Fix "Use not jointly dominated by defs." crash
The instruction created by foldLoadInto can reuse the memory of the compare just erased by optimizeCompareInstr. Erasing the stale pointer from LocalMIs afterwards dropped the new instruction instead, and optimizeExtInstr then rewrote it to use a not-yet-defined extension result.
Fixes #199237.
---
llvm/lib/CodeGen/PeepholeOptimizer.cpp | 5 ++-
.../X86/peephole-fold-load-after-cmp.ll | 37 +++++++++++++++++++
2 files changed, 41 insertions(+), 1 deletion(-)
create mode 100644 llvm/test/CodeGen/X86/peephole-fold-load-after-cmp.ll
diff --git a/llvm/lib/CodeGen/PeepholeOptimizer.cpp b/llvm/lib/CodeGen/PeepholeOptimizer.cpp
index ec8a0336a2105..421a076794f0d 100644
--- a/llvm/lib/CodeGen/PeepholeOptimizer.cpp
+++ b/llvm/lib/CodeGen/PeepholeOptimizer.cpp
@@ -963,6 +963,9 @@ bool PeepholeOptimizer::optimizeCmpInstr(
LLVM_DEBUG(dbgs() << " -> Successfully optimized compare!\n");
++NumCmps;
+ // MI erased/rewritten, drop it before foldLoadInto can reuse its memory.
+ LocalMIs.erase(&MI);
+
// The eliminated compare may have been the extra use preventing a
// load from being folded into the flag-setting instruction.
if (SrcReg.isVirtual() && MRI->hasOneNonDBGUser(SrcReg)) {
@@ -1843,7 +1846,7 @@ bool PeepholeOptimizer::run(MachineFunction &MF) {
}
if (MI->isCompare() && optimizeCmpInstr(*MI, MF, LocalMIs)) {
- LocalMIs.erase(MI);
+ // optimizeCmpInstr already removed MI from LocalMIs.
Changed = true;
continue;
}
diff --git a/llvm/test/CodeGen/X86/peephole-fold-load-after-cmp.ll b/llvm/test/CodeGen/X86/peephole-fold-load-after-cmp.ll
new file mode 100644
index 0000000000000..f86063bba2938
--- /dev/null
+++ b/llvm/test/CodeGen/X86/peephole-fold-load-after-cmp.ll
@@ -0,0 +1,37 @@
+; NOTE: Assertions have been autogenerated by utils/update_llc_test_checks.py
+; RUN: llc < %s -mtriple=x86_64-- -verify-machineinstrs | FileCheck %s
+
+; Make sure this does not crash with "Use not jointly dominated by defs."
+; The load-folded compare was dropped from LocalMIs via a stale pointer and
+; rewritten to use a not-yet-defined extension result.
+
+ at g = global i8 0
+
+define void @pr199237() {
+; CHECK-LABEL: pr199237:
+; CHECK: # %bb.0: # %BB
+; CHECK-NEXT: movq g at GOTPCREL(%rip), %rax
+; CHECK-NEXT: movzbl (%rax), %ecx
+; CHECK-NEXT: cmpb 0, %cl
+; CHECK-NEXT: setg (%rax)
+; CHECK-NEXT: setae 0
+; CHECK-NEXT: movsbq %cl, %rax
+; CHECK-NEXT: .p2align 4
+; CHECK-NEXT: .LBB0_1: # %BB2
+; CHECK-NEXT: # =>This Inner Loop Header: Depth=1
+; CHECK-NEXT: movq %rax, 0
+; CHECK-NEXT: jmp .LBB0_1
+BB:
+ %v = load i8, ptr @g, align 1
+ %w = load i8, ptr null, align 1
+ %c1 = icmp sgt i8 %v, %w
+ store i1 %c1, ptr @g, align 1
+ %c2 = icmp ule i8 %w, %v
+ store i1 %c2, ptr null, align 1
+ br label %BB2
+
+BB2:
+ %gep = getelementptr i8, ptr null, i8 %v
+ store ptr %gep, ptr null, align 8
+ br label %BB2
+}
More information about the llvm-commits
mailing list