[llvm] [LAA] Fix off-by-EltSize in negative-step deref bounds check (PR #211964)

Florian Hahn via llvm-commits llvm-commits at lists.llvm.org
Tue Sep 8 07:51:59 PDT 2026


================
@@ -264,15 +274,15 @@ static bool evaluatePtrAddRecAtMaxBTCWillNotWrap(
   Step = SE.getNoopOrSignExtend(Step, WiderTy);
   MaxBTC = SE.getNoopOrZeroExtend(MaxBTC, WiderTy);
 
-  // For the computations below, make sure they don't unsigned wrap.
-  // FIXME: for a negative step the lowest accessed address is not
-  // AR->getStart() but AR->evaluateAtIteration(MaxBTC, SE); the check below
-  // therefore compares StartPtr against the highest accessed address instead
-  // of the lowest.
-  if (!SE.isKnownPredicate(CmpInst::ICMP_UGE, AR->getStart(), StartPtr))
+  const SCEV *LowestAddr = IsKnownNonNegative
+                               ? static_cast<const SCEV *>(AR->getStart())
+                               : AR->evaluateAtIteration(MaxBTC, SE);
+  // Lower-bound safety check: the lowest accessed address must not fall below
+  // StartPtr.
+  if (!SE.isKnownPredicate(CmpInst::ICMP_UGE, LowestAddr, StartPtr))
----------------
fhahn wrote:

Could you double check if we have a case where `AR->getStart()` is itself and Addrec from an outer loop. I think in that case, `getPointerBase` will look thorugh that when computing `StartPtr`, in which case the `LowestOffset` may not be correct?

https://github.com/llvm/llvm-project/pull/211964


More information about the llvm-commits mailing list