[llvm] [SLP]Fix miscompile from poison base in alias-check versioning (PR #213338)
Alexander Kornienko via llvm-commits
llvm-commits at lists.llvm.org
Wed Aug 5 03:50:06 PDT 2026
alexfh wrote:
@alexey-bataev unfortunately, this fix introduces a crash: https://godbolt.org/z/6bGsq5GzP
```
clang++: /root/llvm-project/llvm/lib/Transforms/Vectorize/SLPVectorizer.cpp:26016: llvm::Value* llvm::slpvectorizer::BoUpSLP::vectorizeTree(const ExtraValueToDebugLocsMap&, llvm::Instruction*, llvm::ArrayRef<std::tuple<llvm::WeakTrackingVH, unsigned int, bool, bool> >): Assertion `(isVectorized(U) || (UserIgnoreList && UserIgnoreList->contains(U)) || (isa_and_nonnull<Instruction>(U) && isDeleted(cast<Instruction>(U)))) && "Deleting out-of-tree value"' failed.
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace and dumped files.
Stack dump:
0. Program arguments: /opt/compiler-explorer/clang-assertions-trunk/bin/clang++ -g -o /app/output.s -masm=intel -fno-verbose-asm -S -x ir -fcolor-diagnostics -fno-crash-diagnostics -O2 --target=aarch64-unknown-linux-gnu <source>
1. Optimizer
2. Running pass "function<eager-inv>(drop-unnecessary-assumes,float2int,lower-constant-intrinsics,loop(loop-rotate<header-duplication;no-prepare-for-lto;check-exit-count>,loop-deletion),loop-distribute,inject-tli-mappings,loop-vectorize<no-interleave-forced-only;no-vectorize-forced-only;>,drop-unnecessary-assumes<drop-deref>,infer-alignment,loop-load-elim,instcombine<max-iterations=1;no-verify-fixpoint>,simplifycfg<bonus-inst-threshold=1;forward-switch-cond;switch-range-to-icmp;switch-to-arithmetic;switch-to-lookup;no-keep-loops;hoist-common-insts;no-hoist-loads-stores-with-cond-faulting;sink-common-insts;speculate-blocks;simplify-cond-branch;no-speculate-unpredictables>,slp-vectorizer,vector-combine,instcombine<max-iterations=1;no-verify-fixpoint>,loop-unroll<O2>,transform-warning,sroa<preserve-cfg;aggregate-to-vector>,infer-alignment,instcombine<max-iterations=1;no-verify-fixpoint>,loop-mssa(licm<allowspeculation>),alignment-from-assumptions,loop-sink,instsimplify,div-rem-pairs,mergeicmps,expand-memcmp,tailcallelim,simplifycfg<bonus-inst-threshold=1;no-forward-switch-cond;switch-range-to-icmp;switch-to-arithmetic;no-switch-to-lookup;keep-loops;no-hoist-common-insts;hoist-loads-stores-with-cond-faulting;no-sink-common-insts;speculate-blocks;simplify-cond-branch;speculate-unpredictables>)" on module "<source>"
3. Running pass "slp-vectorizer" on function "foo"
#0 0x0000000004423f28 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4423f28)
#1 0x0000000004420dd4 llvm::sys::RunSignalHandlers() (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4420dd4)
#2 0x000000000442140c llvm::sys::CleanupOnSignal(unsigned long) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x442140c)
#3 0x00000000043603c8 CrashRecoverySignalHandler(int) CrashRecoveryContext.cpp:0:0
#4 0x0000786181245330 (/lib/x86_64-linux-gnu/libc.so.6+0x45330)
#5 0x000078618129eb2c pthread_kill (/lib/x86_64-linux-gnu/libc.so.6+0x9eb2c)
#6 0x000078618124527e raise (/lib/x86_64-linux-gnu/libc.so.6+0x4527e)
#7 0x00007861812288ff abort (/lib/x86_64-linux-gnu/libc.so.6+0x288ff)
#8 0x000078618122881b (/lib/x86_64-linux-gnu/libc.so.6+0x2881b)
#9 0x000078618123b517 (/lib/x86_64-linux-gnu/libc.so.6+0x3b517)
#10 0x00000000062b0cf7 llvm::slpvectorizer::BoUpSLP::vectorizeTree(llvm::SmallDenseSet<llvm::Value*, 4u, llvm::DenseMapInfo<llvm::Value*, void>> const&, llvm::Instruction*, llvm::ArrayRef<std::tuple<llvm::WeakTrackingVH, unsigned int, bool, bool>>) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62b0cf7)
#11 0x00000000062b187d llvm::slpvectorizer::BoUpSLP::vectorizeTree() (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62b187d)
#12 0x00000000062d4a7c llvm::SLPVectorizerPass::vectorizeStoreChainImpl(llvm::ArrayRef<llvm::Value*>, llvm::slpvectorizer::BoUpSLP&, unsigned int, unsigned int, unsigned int&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62d4a7c)
#13 0x00000000062d56ba llvm::SLPVectorizerPass::vectorizeStoreChain(llvm::ArrayRef<llvm::Value*>, llvm::slpvectorizer::BoUpSLP&, unsigned int, unsigned int, unsigned int&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62d56ba)
#14 0x00000000062d5c12 (anonymous namespace)::StoreChainContext::vectorizeOneVF(llvm::TargetTransformInfo const&, unsigned int, llvm::SmallPtrSet<llvm::Value*, 16u>&, bool&, llvm::function_ref<std::optional<bool> (llvm::ArrayRef<llvm::Value*>, unsigned int, unsigned int, unsigned int&)>) (.constprop.0) SLPVectorizer.cpp:0:0
#15 0x00000000062d7f2d llvm::SLPVectorizerPass::vectorizeStores(llvm::ArrayRef<llvm::StoreInst*>, llvm::slpvectorizer::BoUpSLP&, llvm::DenseSet<std::tuple<llvm::Value*, llvm::Value*, llvm::Value*, llvm::Value*, unsigned int>, llvm::DenseMapInfo<std::tuple<llvm::Value*, llvm::Value*, llvm::Value*, llvm::Value*, unsigned int>, void>>&, bool) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62d7f2d)
#16 0x00000000062d9662 llvm::SLPVectorizerPass::vectorizeStoreChains(llvm::slpvectorizer::BoUpSLP&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62d9662)
#17 0x00000000062e3653 llvm::SLPVectorizerPass::runImpl(llvm::Function&, llvm::ScalarEvolution*, llvm::TargetTransformInfo*, llvm::TargetLibraryInfo*, llvm::AAResults*, llvm::LoopInfo*, llvm::DominatorTree*, llvm::AssumptionCache*, llvm::DemandedBits*, llvm::OptimizationRemarkEmitter*) (.part.0) SLPVectorizer.cpp:0:0
#18 0x00000000062e45b1 llvm::SLPVectorizerPass::run(llvm::Function&, llvm::AnalysisManager<llvm::Function>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x62e45b1)
#19 0x00000000057c97de llvm::detail::PassModel<llvm::Function, llvm::SLPVectorizerPass, llvm::AnalysisManager<llvm::Function>>::runImpl(llvm::detail::PassConcept<llvm::Function, llvm::AnalysisManager<llvm::Function>>&, llvm::Function&, llvm::AnalysisManager<llvm::Function>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x57c97de)
#20 0x0000000003d5b814 llvm::PassManager<llvm::Function, llvm::AnalysisManager<llvm::Function>>::run(llvm::Function&, llvm::AnalysisManager<llvm::Function>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x3d5b814)
#21 0x000000000128c1ce llvm::detail::PassModel<llvm::Function, llvm::PassManager<llvm::Function, llvm::AnalysisManager<llvm::Function>>, llvm::AnalysisManager<llvm::Function>>::runImpl(llvm::detail::PassConcept<llvm::Function, llvm::AnalysisManager<llvm::Function>>&, llvm::Function&, llvm::AnalysisManager<llvm::Function>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x128c1ce)
#22 0x0000000003d5a273 llvm::ModuleToFunctionPassAdaptor::run(llvm::Module&, llvm::AnalysisManager<llvm::Module>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x3d5a273)
#23 0x000000000128c26e llvm::detail::PassModel<llvm::Module, llvm::ModuleToFunctionPassAdaptor, llvm::AnalysisManager<llvm::Module>>::runImpl(llvm::detail::PassConcept<llvm::Module, llvm::AnalysisManager<llvm::Module>>&, llvm::Module&, llvm::AnalysisManager<llvm::Module>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x128c26e)
#24 0x0000000003d598c4 llvm::PassManager<llvm::Module, llvm::AnalysisManager<llvm::Module>>::run(llvm::Module&, llvm::AnalysisManager<llvm::Module>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x3d598c4)
#25 0x000000000484c6bc (anonymous namespace)::EmitAssemblyHelper::RunOptimizationPipeline(clang::BackendAction, std::unique_ptr<llvm::raw_pwrite_stream, std::default_delete<llvm::raw_pwrite_stream>>&, std::unique_ptr<llvm::ToolOutputFile, std::default_delete<llvm::ToolOutputFile>>&, clang::BackendConsumer*) BackendUtil.cpp:0:0
#26 0x000000000484e823 (anonymous namespace)::EmitAssemblyHelper::emitAssembly(clang::BackendAction, std::unique_ptr<llvm::raw_pwrite_stream, std::default_delete<llvm::raw_pwrite_stream>>, clang::BackendConsumer*) BackendUtil.cpp:0:0
#27 0x0000000004851493 clang::emitBackendOutput(clang::CompilerInstance&, clang::CodeGenOptions&, llvm::StringRef, llvm::Module*, clang::BackendAction, llvm::IntrusiveRefCntPtr<llvm::vfs::FileSystem>, std::unique_ptr<llvm::raw_pwrite_stream, std::default_delete<llvm::raw_pwrite_stream>>, clang::BackendConsumer*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4851493)
#28 0x0000000004f2578d clang::CodeGenAction::ExecuteAction() (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4f2578d)
#29 0x0000000005252b28 clang::FrontendAction::Execute() (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x5252b28)
#30 0x00000000051df6ad clang::CompilerInstance::ExecuteAction(clang::FrontendAction&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x51df6ad)
#31 0x0000000005327dbd clang::ExecuteCompilerInvocation(clang::CompilerInstance*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x5327dbd)
#32 0x0000000000dab3bc cc1_main(llvm::ArrayRef<char const*>, char const*, void*) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xdab3bc)
#33 0x0000000000da1fda ExecuteCC1Tool(llvm::SmallVectorImpl<char const*>&, llvm::ToolContext const&, llvm::IntrusiveRefCntPtr<llvm::vfs::FileSystem>) driver.cpp:0:0
#34 0x0000000000da215d int llvm::function_ref<int (llvm::SmallVectorImpl<char const*>&)>::callback_fn<clang_main(int, char**, llvm::ToolContext const&)::'lambda'(llvm::SmallVectorImpl<char const*>&)>(long, llvm::SmallVectorImpl<char const*>&) driver.cpp:0:0
#35 0x0000000004f9ce59 void llvm::function_ref<void ()>::callback_fn<clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const::'lambda'()>(long) Job.cpp:0:0
#36 0x0000000004360804 llvm::CrashRecoveryContext::RunSafely(llvm::function_ref<void ()>) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4360804)
#37 0x0000000004f9d9c5 clang::driver::CC1Command::Execute(llvm::ArrayRef<std::optional<llvm::StringRef>>, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*, bool*) const (.part.0) Job.cpp:0:0
#38 0x0000000004f558a2 clang::driver::Compilation::ExecuteCommand(clang::driver::Command const&, clang::driver::Command const*&, bool) const (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4f558a2)
#39 0x0000000004f5a207 clang::driver::Compilation::ExecuteJobs(clang::driver::JobList const&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&, bool) const (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4f5a207)
#40 0x0000000004f64775 clang::driver::Driver::ExecuteCompilation(clang::driver::Compilation&, llvm::SmallVectorImpl<std::pair<int, clang::driver::Command const*>>&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0x4f64775)
#41 0x0000000000da78ba clang_main(int, char**, llvm::ToolContext const&) (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xda78ba)
#42 0x0000000000cc35ba main (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xcc35ba)
#43 0x000078618122a1ca (/lib/x86_64-linux-gnu/libc.so.6+0x2a1ca)
#44 0x000078618122a28b __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28b)
#45 0x0000000000da1985 _start (/opt/compiler-explorer/clang-assertions-trunk/bin/clang+++0xda1985)
clang++: error: clang frontend command failed due to signal (use -v to see invocation)
Compiler returned: 134
```
The reduced test case is:
```
target datalayout = "e-m:e-p270:32:32-p271:32:32-p272:64:64-i8:8:32-i16:16:32-i64:64-i128:128-n32:64-S128-Fn32"
target triple = "aarch64-unknown-linux-gnu"
define void @foo(ptr %arg, ptr %arg2) {
bbl:
br label %bbl3
bbl3: ; preds = %bbl3, %bbl
%phi = phi i64 [ 0, %bbl ], [ %add, %bbl3 ]
%getelementptr = getelementptr [4 x i8], ptr %arg2, i64 %phi
%getelementptr4 = getelementptr [4 x i8], ptr %arg, i64 %phi
%call = call i64 @wibble(ptr %getelementptr4)
%load = load i32, ptr %getelementptr, align 4
%zext = zext i32 %load to i64
%or = or i64 %call, %zext
%inttoptr = inttoptr i64 %or to ptr
call void @eggs(ptr %getelementptr4, ptr %inttoptr)
%add = add i64 %phi, 1
%icmp = icmp eq i64 %phi, 8
br i1 %icmp, label %bbl5, label %bbl3
bbl5: ; preds = %bbl3
ret void
}
define void @eggs(ptr %arg, ptr %arg2) {
bbl:
%icmp = icmp eq ptr %arg2, null
br i1 %icmp, label %bbl4, label %bbl5
bbl4: ; preds = %bbl
store i32 1, ptr %arg, align 4
ret void
bbl5: ; preds = %bbl
store i32 0, ptr %arg, align 4
ret void
}
define i64 @wibble(ptr %arg) {
bbl:
%ptrtoint = ptrtoint ptr %arg to i64
ret i64 %ptrtoint
}
```
https://github.com/llvm/llvm-project/pull/213338
More information about the llvm-commits
mailing list