[llvm] [LAA] Fix off-by-EltSize in negative-step deref bounds check (PR #211964)
Florian Hahn via llvm-commits
llvm-commits at lists.llvm.org
Tue Sep 8 07:51:59 PDT 2026
================
@@ -264,15 +274,15 @@ static bool evaluatePtrAddRecAtMaxBTCWillNotWrap(
Step = SE.getNoopOrSignExtend(Step, WiderTy);
MaxBTC = SE.getNoopOrZeroExtend(MaxBTC, WiderTy);
- // For the computations below, make sure they don't unsigned wrap.
- // FIXME: for a negative step the lowest accessed address is not
- // AR->getStart() but AR->evaluateAtIteration(MaxBTC, SE); the check below
- // therefore compares StartPtr against the highest accessed address instead
- // of the lowest.
- if (!SE.isKnownPredicate(CmpInst::ICMP_UGE, AR->getStart(), StartPtr))
+ const SCEV *LowestAddr = IsKnownNonNegative
+ ? static_cast<const SCEV *>(AR->getStart())
+ : AR->evaluateAtIteration(MaxBTC, SE);
+ // Lower-bound safety check: the lowest accessed address must not fall below
+ // StartPtr.
+ if (!SE.isKnownPredicate(CmpInst::ICMP_UGE, LowestAddr, StartPtr))
----------------
fhahn wrote:
Could you double check if we have a case where `AR->getStart()` is itself and Addrec from an outer loop. I think in that case, `getPointerBase` will look thorugh that when computing `StartPtr`, in which case the `LowestOffset` may not be correct?
https://github.com/llvm/llvm-project/pull/211964
More information about the llvm-commits
mailing list