[llvm] [ValueTracking] Fix impliesPoison for instructions with flag-based poison (PR #215368)

via llvm-commits llvm-commits at lists.llvm.org
Mon Aug 10 12:58:15 PDT 2026


https://github.com/AZero13 updated https://github.com/llvm/llvm-project/pull/215368

>From 89f68bc01ea00f9afb40023437b3adfe5cda1ae7 Mon Sep 17 00:00:00 2001
From: AZero13 <gfunni234 at gmail.com>
Date: Mon, 10 Aug 2026 15:12:51 -0400
Subject: [PATCH 1/2] Precommit test for impliesPoison with FPMathOperator
 fast-math flags

---
 .../InstSimplify/select-logical-fmf.ll        | 28 +++++++++++++++++++
 1 file changed, 28 insertions(+)
 create mode 100644 llvm/test/Transforms/InstSimplify/select-logical-fmf.ll

diff --git a/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll b/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
new file mode 100644
index 0000000000000..eb77c16fce29a
--- /dev/null
+++ b/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
@@ -0,0 +1,28 @@
+; NOTE: Assertions have been autogenerated by utils/update_test_checks.py
+; RUN: opt < %s -passes=instsimplify -S | FileCheck %s
+
+define i1 @test_fcmp_nnan_implies_poison_select_and(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_and(
+; CHECK-NEXT:    [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT:    [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
+; CHECK-NEXT:    [[SEL:%.*]] = select i1 [[CMP1]], i1 [[CMP2]], i1 false
+; CHECK-NEXT:    ret i1 [[SEL]]
+;
+  %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+  %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+  %sel = select i1 %cmp1, i1 %cmp2, i1 false
+  ret i1 %sel
+}
+
+define i1 @test_fcmp_nnan_implies_poison_select_or(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_or(
+; CHECK-NEXT:    [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT:    [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
+; CHECK-NEXT:    [[SEL:%.*]] = select i1 [[CMP1]], i1 true, i1 [[CMP2]]
+; CHECK-NEXT:    ret i1 [[SEL]]
+;
+  %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+  %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+  %sel = select i1 %cmp1, i1 true, i1 %cmp2
+  ret i1 %sel
+}

>From 3f11baddedcc3b327a58f9288ddfe6e72afabaf5 Mon Sep 17 00:00:00 2001
From: AZero13 <gfunni234 at gmail.com>
Date: Mon, 10 Aug 2026 14:05:40 -0400
Subject: [PATCH 2/2] [ValueTracking] Fix impliesPoison for instructions with
 flag-based poison

This PR fixes a bug in `impliesPoison` where it would return `false` for instructions that only create poison due to their flags (like `fcmp` with `nnan` or `ninf`), even when the two instructions had identical poison states.

Alive2: https://alive2.llvm.org/ce/z/CWqJ5X
---
 llvm/lib/Analysis/ValueTracking.cpp           | 59 ++++++++++++++++-
 .../InstCombine/select-logical-fmf.ll         | 66 +++++++++++++++++++
 .../InstSimplify/select-logical-fmf.ll        | 28 --------
 3 files changed, 124 insertions(+), 29 deletions(-)
 create mode 100644 llvm/test/Transforms/InstCombine/select-logical-fmf.ll
 delete mode 100644 llvm/test/Transforms/InstSimplify/select-logical-fmf.ll

diff --git a/llvm/lib/Analysis/ValueTracking.cpp b/llvm/lib/Analysis/ValueTracking.cpp
index 44a1240f5635a..a7f73330ae84a 100644
--- a/llvm/lib/Analysis/ValueTracking.cpp
+++ b/llvm/lib/Analysis/ValueTracking.cpp
@@ -7909,6 +7909,51 @@ static bool directlyImpliesPoison(const Value *ValAssumedPoison, const Value *V,
   return false;
 }
 
+static bool flagConditionsImply(const Instruction *I, const Instruction *J) {
+  if (I->getOpcode() != J->getOpcode() ||
+      I->getNumOperands() != J->getNumOperands())
+    return false;
+
+  // Only handle FPMathOperator for now.
+  const auto *FPI = dyn_cast<FPMathOperator>(I);
+  if (!FPI)
+    return false;
+
+  const auto *FPJ = dyn_cast<FPMathOperator>(J);
+  if (!FPJ)
+    return false;
+  FastMathFlags FI = FPI->getFastMathFlags();
+  FastMathFlags FJ = FPJ->getFastMathFlags();
+
+  // J must have at least the same poison-generating conditions as I.
+  if (FI.noNaNs() && !FJ.noNaNs())
+    return false;
+  if (FI.noInfs() && !FJ.noInfs())
+    return false;
+
+  SimplifyQuery SQ(I->getModule()->getDataLayout());
+
+  for (unsigned i = 0, e = I->getNumOperands(); i != e; ++i) {
+    Value *OpI = I->getOperand(i);
+    Value *OpJ = J->getOperand(i);
+
+    if (OpI == OpJ)
+      continue;
+
+    // The differing operand of I cannot participate in ANY poison condition.
+    if (!isGuaranteedNotToBePoison(OpI))
+      return false;
+
+    // It cannot participate in flag-generated poison.
+    if (FI.noNaNs() && !isKnownNeverNaN(OpI, SQ))
+      return false;
+    if (FI.noInfs() && !isKnownNeverInfinity(OpI, SQ))
+      return false;
+  }
+
+  return true;
+}
+
 static bool impliesPoison(const Value *ValAssumedPoison, const Value *V,
                           unsigned Depth) {
   if (isGuaranteedNotToBePoison(ValAssumedPoison))
@@ -7922,11 +7967,23 @@ static bool impliesPoison(const Value *ValAssumedPoison, const Value *V,
     return false;
 
   const auto *I = dyn_cast<Instruction>(ValAssumedPoison);
-  if (I && !canCreatePoison(cast<Operator>(I))) {
+  if (!I)
+    return false;
+
+  if (!canCreatePoison(cast<Operator>(I))) {
     return all_of(I->operands(), [=](const Value *Op) {
       return impliesPoison(Op, V, Depth + 1);
     });
   }
+
+  // If I can only create poison due to flags/metadata, check whether V
+  // has the same poison conditions.
+  if (!canCreatePoison(cast<Operator>(I),
+                       /*ConsiderFlagsAndMetadata=*/false)) {
+    if (const auto *J = dyn_cast<Instruction>(V))
+      return flagConditionsImply(I, J);
+  }
+
   return false;
 }
 
diff --git a/llvm/test/Transforms/InstCombine/select-logical-fmf.ll b/llvm/test/Transforms/InstCombine/select-logical-fmf.ll
new file mode 100644
index 0000000000000..0773616894bad
--- /dev/null
+++ b/llvm/test/Transforms/InstCombine/select-logical-fmf.ll
@@ -0,0 +1,66 @@
+; NOTE: Assertions have been autogenerated by utils/update_test_checks.py
+; RUN: opt < %s -passes=instcombine -S | FileCheck %s
+
+; Positive: different known-safe constants
+define i1 @test_fcmp_nnan_implies_poison_select_and(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_and(
+; CHECK-NEXT:    ret i1 false
+;
+  %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+  %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+  %sel = select i1 %cmp1, i1 %cmp2, i1 false
+  ret i1 %sel
+}
+
+define i1 @test_fcmp_nnan_implies_poison_select_or(float %x) {
+; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_or(
+; CHECK-NEXT:    [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT:    [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
+; CHECK-NEXT:    [[SEL:%.*]] = or i1 [[CMP1]], [[CMP2]]
+; CHECK-NEXT:    ret i1 [[SEL]]
+;
+  %cmp1 = fcmp nnan olt float %x, 1.000000e+00
+  %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
+  %sel = select i1 %cmp1, i1 true, i1 %cmp2
+  ret i1 %sel
+}
+
+; Positive: same operand
+define i1 @same_operand(float %x) {
+; CHECK-LABEL: @same_operand(
+; CHECK-NEXT:    [[A:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
+; CHECK-NEXT:    [[B:%.*]] = fcmp nnan ogt float [[X]], 5.000000e-01
+; CHECK-NEXT:    [[R:%.*]] = and i1 [[A]], [[B]]
+; CHECK-NEXT:    ret i1 [[R]]
+;
+  %a = fcmp nnan olt float %x, 1.0
+  %b = fcmp nnan ogt float %x, 0.5
+  %r = select i1 %a, i1 %b, i1 false
+  ret i1 %r
+}
+
+; Negative: differing potentially-NaN operand
+define i1 @different_operand(float %x, float %y) {
+; CHECK-LABEL: @different_operand(
+; CHECK-NEXT:    [[A:%.*]] = fcmp nnan olt float [[X:%.*]], [[Y:%.*]]
+; CHECK-NEXT:    [[B:%.*]] = fcmp nnan ogt float [[X]], 5.000000e-01
+; CHECK-NEXT:    [[R:%.*]] = and i1 [[A]], [[B]]
+; CHECK-NEXT:    ret i1 [[R]]
+;
+  %a = fcmp nnan olt float %x, %y
+  %b = fcmp nnan ogt float %x, 0.5
+  %r = select i1 %a, i1 %b, i1 false
+  ret i1 %r
+}
+
+; Negative: missing nnan
+define i1 @missing_flag(float %x) {
+; CHECK-LABEL: @missing_flag(
+; CHECK-NEXT:    [[B:%.*]] = fcmp olt float [[X:%.*]], 5.000000e-01
+; CHECK-NEXT:    ret i1 [[B]]
+;
+  %a = fcmp nnan olt float %x, 1.0
+  %b = fcmp olt float %x, 0.5
+  %r = select i1 %a, i1 %b, i1 false
+  ret i1 %r
+}
diff --git a/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll b/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
deleted file mode 100644
index eb77c16fce29a..0000000000000
--- a/llvm/test/Transforms/InstSimplify/select-logical-fmf.ll
+++ /dev/null
@@ -1,28 +0,0 @@
-; NOTE: Assertions have been autogenerated by utils/update_test_checks.py
-; RUN: opt < %s -passes=instsimplify -S | FileCheck %s
-
-define i1 @test_fcmp_nnan_implies_poison_select_and(float %x) {
-; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_and(
-; CHECK-NEXT:    [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
-; CHECK-NEXT:    [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
-; CHECK-NEXT:    [[SEL:%.*]] = select i1 [[CMP1]], i1 [[CMP2]], i1 false
-; CHECK-NEXT:    ret i1 [[SEL]]
-;
-  %cmp1 = fcmp nnan olt float %x, 1.000000e+00
-  %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
-  %sel = select i1 %cmp1, i1 %cmp2, i1 false
-  ret i1 %sel
-}
-
-define i1 @test_fcmp_nnan_implies_poison_select_or(float %x) {
-; CHECK-LABEL: @test_fcmp_nnan_implies_poison_select_or(
-; CHECK-NEXT:    [[CMP1:%.*]] = fcmp nnan olt float [[X:%.*]], 1.000000e+00
-; CHECK-NEXT:    [[CMP2:%.*]] = fcmp nnan ogt float [[X]], 2.000000e+00
-; CHECK-NEXT:    [[SEL:%.*]] = select i1 [[CMP1]], i1 true, i1 [[CMP2]]
-; CHECK-NEXT:    ret i1 [[SEL]]
-;
-  %cmp1 = fcmp nnan olt float %x, 1.000000e+00
-  %cmp2 = fcmp nnan ogt float %x, 2.000000e+00
-  %sel = select i1 %cmp1, i1 true, i1 %cmp2
-  ret i1 %sel
-}



More information about the llvm-commits mailing list