[llvm] [ValueTracking] Fix impliesPoison for instructions with flag-based poison (PR #215368)
via llvm-commits
llvm-commits at lists.llvm.org
Mon Aug 10 12:58:15 PDT 2026
https://github.com/AZero13 updated https://github.com/llvm/llvm-project/pull/215368
>From 89f68bc01ea00f9afb40023437b3adfe5cda1ae7 Mon Sep 17 00:00:00 2001
From: AZero13 <gfunni234 at gmail.com>
Date: Mon, 10 Aug 2026 15:12:51 -0400
Subject: [PATCH 1/2] Precommit test for impliesPoison with FPMathOperator
fast-math flags
---
.../InstSimplify/select-logical-fmf.ll | 28 +++++++++++++++++++
1 file changed, 28 insertions(+)
create mode 100644 llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
diff --git a/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll b/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
new file mode 100644
index 0000000000000..eb77c16fce29a
--- /dev/null
+++ b/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
@@ -0,0 +1,28 @@
+; NOTE: Assertions have been autogenerated by utils/update_test_checks.py
+; RUN: opt < %s -passes=instsimplify -S | FileCheck %s
+
+define i1 @test_fcmp_nnan_implies_poison_select_and(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_and(
+; CHECK-NEXT: [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT: [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
+; CHECK-NEXT: [[SEL:%.*]] = select i1 [[CMP1]], i1 [[CMP2]], i1 false
+; CHECK-NEXT: ret i1 [[SEL]]
+;
+ %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+ %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+ %sel = select i1 %cmp1, i1 %cmp2, i1 false
+ ret i1 %sel
+}
+
+define i1 @test_fcmp_nnan_implies_poison_select_or(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_or(
+; CHECK-NEXT: [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT: [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
+; CHECK-NEXT: [[SEL:%.*]] = select i1 [[CMP1]], i1 true, i1 [[CMP2]]
+; CHECK-NEXT: ret i1 [[SEL]]
+;
+ %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+ %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+ %sel = select i1 %cmp1, i1 true, i1 %cmp2
+ ret i1 %sel
+}
>From 3f11baddedcc3b327a58f9288ddfe6e72afabaf5 Mon Sep 17 00:00:00 2001
From: AZero13 <gfunni234 at gmail.com>
Date: Mon, 10 Aug 2026 14:05:40 -0400
Subject: [PATCH 2/2] [ValueTracking] Fix impliesPoison for instructions with
flag-based poison
This PR fixes a bug in `impliesPoison` where it would return `false` for instructions that only create poison due to their flags (like `fcmp` with `nnan` or `ninf`), even when the two instructions had identical poison states.
Alive2: https://alive2.llvm.org/ce/z/CWqJ5X
---
llvm/lib/Analysis/ValueTracking.cpp | 59 ++++++++++++++++-
.../InstCombine/select-logical-fmf.ll | 66 +++++++++++++++++++
.../InstSimplify/select-logical-fmf.ll | 28 --------
3 files changed, 124 insertions(+), 29 deletions(-)
create mode 100644 llvm/test/Transforms/InstCombine/select-logical-fmf.ll
delete mode 100644 llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
diff --git a/llvm/lib/Analysis/ValueTracking.cpp b/llvm/lib/Analysis/ValueTracking.cpp
index 44a1240f5635a..a7f73330ae84a 100644
--- a/llvm/lib/Analysis/ValueTracking.cpp
+++ b/llvm/lib/Analysis/ValueTracking.cpp
@@ -7909,6 +7909,51 @@ static bool directlyImpliesPoison(const Value *ValAssumedPoison, const Value *V,
return false;
}
+static bool flagConditionsImply(const Instruction *I, const Instruction *J) {
+ if (I->getOpcode() != J->getOpcode() ||
+ I->getNumOperands() != J->getNumOperands())
+ return false;
+
+ // Only handle FPMathOperator for now.
+ const auto *FPI = dyn_cast<FPMathOperator>(I);
+ if (!FPI)
+ return false;
+
+ const auto *FPJ = dyn_cast<FPMathOperator>(J);
+ if (!FPJ)
+ return false;
+ FastMathFlags FI = FPI->getFastMathFlags();
+ FastMathFlags FJ = FPJ->getFastMathFlags();
+
+ // J must have at least the same poison-generating conditions as I.
+ if (FI.noNaNs() && !FJ.noNaNs())
+ return false;
+ if (FI.noInfs() && !FJ.noInfs())
+ return false;
+
+ SimplifyQuery SQ(I->getModule()->getDataLayout());
+
+ for (unsigned i = 0, e = I->getNumOperands(); i != e; ++i) {
+ Value *OpI = I->getOperand(i);
+ Value *OpJ = J->getOperand(i);
+
+ if (OpI == OpJ)
+ continue;
+
+ // The differing operand of I cannot participate in ANY poison condition.
+ if (!isGuaranteedNotToBePoison(OpI))
+ return false;
+
+ // It cannot participate in flag-generated poison.
+ if (FI.noNaNs() && !isKnownNeverNaN(OpI, SQ))
+ return false;
+ if (FI.noInfs() && !isKnownNeverInfinity(OpI, SQ))
+ return false;
+ }
+
+ return true;
+}
+
static bool impliesPoison(const Value *ValAssumedPoison, const Value *V,
unsigned Depth) {
if (isGuaranteedNotToBePoison(ValAssumedPoison))
@@ -7922,11 +7967,23 @@ static bool impliesPoison(const Value *ValAssumedPoison, const Value *V,
return false;
const auto *I = dyn_cast<Instruction>(ValAssumedPoison);
- if (I && !canCreatePoison(cast<Operator>(I))) {
+ if (!I)
+ return false;
+
+ if (!canCreatePoison(cast<Operator>(I))) {
return all_of(I->operands(), [=](const Value *Op) {
return impliesPoison(Op, V, Depth + 1);
});
}
+
+ // If I can only create poison due to flags/metadata, check whether V
+ // has the same poison conditions.
+ if (!canCreatePoison(cast<Operator>(I),
+ /*ConsiderFlagsAndMetadata=*/false)) {
+ if (const auto *J = dyn_cast<Instruction>(V))
+ return flagConditionsImply(I, J);
+ }
+
return false;
}
diff --git a/llvm/test/Transforms/InstCombine/select-logical-fmf.ll b/llvm/test/Transforms/InstCombine/select-logical-fmf.ll
new file mode 100644
index 0000000000000..0773616894bad
--- /dev/null
+++ b/llvm/test/Transforms/InstCombine/select-logical-fmf.ll
@@ -0,0 +1,66 @@
+; NOTE: Assertions have been autogenerated by utils/update_test_checks.py
+; RUN: opt < %s -passes=instcombine -S | FileCheck %s
+
+; Positive: different known-safe constants
+define i1 @test_fcmp_nnan_implies_poison_select_and(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_and(
+; CHECK-NEXT: ret i1 false
+;
+ %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+ %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+ %sel = select i1 %cmp1, i1 %cmp2, i1 false
+ ret i1 %sel
+}
+
+define i1 @test_fcmp_nnan_implies_poison_select_or(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_or(
+; CHECK-NEXT: [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT: [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
+; CHECK-NEXT: [[SEL:%.*]] = or i1 [[CMP1]], [[CMP2]]
+; CHECK-NEXT: ret i1 [[SEL]]
+;
+ %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+ %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+ %sel = select i1 %cmp1, i1 true, i1 %cmp2
+ ret i1 %sel
+}
+
+; Positive: same operand
+define i1 @same_operand(float %x) {
+; CHECK-LABEL: @same_operand(
+; CHECK-NEXT: [[A:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT: [[B:%.*]] = fcmp nnan ogt float [[X]], 5.000000e-01
+; CHECK-NEXT: [[R:%.*]] = and i1 [[A]], [[B]]
+; CHECK-NEXT: ret i1 [[R]]
+;
+ %a = fcmp nnan olt float %x, 1.0
+ %b = fcmp nnan ogt float %x, 0.5
+ %r = select i1 %a, i1 %b, i1 false
+ ret i1 %r
+}
+
+; Negative: differing potentially-NaN operand
+define i1 @different_operand(float %x, float %y) {
+; CHECK-LABEL: @different_operand(
+; CHECK-NEXT: [[A:%.*]] = fcmp nnan olt float [[X:%.*]], [[Y:%.*]]
+; CHECK-NEXT: [[B:%.*]] = fcmp nnan ogt float [[X]], 5.000000e-01
+; CHECK-NEXT: [[R:%.*]] = and i1 [[A]], [[B]]
+; CHECK-NEXT: ret i1 [[R]]
+;
+ %a = fcmp nnan olt float %x, %y
+ %b = fcmp nnan ogt float %x, 0.5
+ %r = select i1 %a, i1 %b, i1 false
+ ret i1 %r
+}
+
+; Negative: missing nnan
+define i1 @missing_flag(float %x) {
+; CHECK-LABEL: @missing_flag(
+; CHECK-NEXT: [[B:%.*]] = fcmp olt float [[X:%.*]], 5.000000e-01
+; CHECK-NEXT: ret i1 [[B]]
+;
+ %a = fcmp nnan olt float %x, 1.0
+ %b = fcmp olt float %x, 0.5
+ %r = select i1 %a, i1 %b, i1 false
+ ret i1 %r
+}
diff --git a/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll b/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
deleted file mode 100644
index eb77c16fce29a..0000000000000
--- a/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
+++ /dev/null
@@ -1,28 +0,0 @@
-; NOTE: Assertions have been autogenerated by utils/update_test_checks.py
-; RUN: opt < %s -passes=instsimplify -S | FileCheck %s
-
-define i1 @test_fcmp_nnan_implies_poison_select_and(float %x) {
-; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_and(
-; CHECK-NEXT: [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
-; CHECK-NEXT: [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
-; CHECK-NEXT: [[SEL:%.*]] = select i1 [[CMP1]], i1 [[CMP2]], i1 false
-; CHECK-NEXT: ret i1 [[SEL]]
-;
- %cmp1 = fcmp nnan olt float %x, 1.000000e+00
- %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
- %sel = select i1 %cmp1, i1 %cmp2, i1 false
- ret i1 %sel
-}
-
-define i1 @test_fcmp_nnan_implies_poison_select_or(float %x) {
-; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_or(
-; CHECK-NEXT: [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
-; CHECK-NEXT: [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
-; CHECK-NEXT: [[SEL:%.*]] = select i1 [[CMP1]], i1 true, i1 [[CMP2]]
-; CHECK-NEXT: ret i1 [[SEL]]
-;
- %cmp1 = fcmp nnan olt float %x, 1.000000e+00
- %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
- %sel = select i1 %cmp1, i1 true, i1 %cmp2
- ret i1 %sel
-}
More information about the llvm-commits
mailing list