[llvm] [TBAA] Recover !tbaa for a memcpy of struct with same type fields (PR #214116)

Andy Kaylor via llvm-commits llvm-commits at lists.llvm.org
Tue Aug 25 12:15:56 PDT 2026


================
@@ -818,7 +818,29 @@ AAMDNodes AAMDNodes::adjustForAccess(unsigned AccessSize) {
       M->getOperand(2) && isa<MDNode>(M->getOperand(2)))
     New.TBAA = cast<MDNode>(M->getOperand(2));
 
+  // The access may cover several !tbaa.struct fields (e.g. a {int, int} copy
+  // widened to an i64 load/store). If those fields share a single tag and tile
+  // [0, AccessSize) with no gaps, that tag still describes the whole access.
   New.TBAAStruct = nullptr;
+  if (New.TBAA || !M)
+    return New;
+  MDNode *CommonTag = nullptr;
+  uint64_t Offset = 0;
+  for (size_t I = 0, E = M->getNumOperands(); I < E; I += 3) {
----------------
andykaylor wrote:

This assumes that the node is well-formed with the number of operands being a multiple of three. It will assert if we get here with a malformed node. Arguably, the verifier should have rejected that, but it doesn't currently do so. This seems to be a common assumption in the TBAA code, but it could be guarded against here, as it is on like 812 above.
```suggestion
  for (size_t I = 0, E = M->getNumOperands(); I + 2 < E; I += 3) {
```

https://github.com/llvm/llvm-project/pull/214116


More information about the llvm-commits mailing list