[llvm] [LAA] Fix off-by-EltSize in negative-step deref bounds check (PR #211964)
Florian Hahn via llvm-commits
llvm-commits at lists.llvm.org
Tue Sep 8 07:54:10 PDT 2026
================
@@ -301,27 +311,12 @@ static bool evaluatePtrAddRecAtMaxBTCWillNotWrap(
if (!AccessedBytes)
return false;
- // Compute MaxOffset per direction: exclusive upper offset of the
- // accessed range.
- const SCEV *MaxOffset;
- if (IsKnownNonNegative) {
- MaxOffset = addSCEVNoOverflow(StartOffset, AccessedBytes, SE);
- if (!MaxOffset)
- return false;
- DerefBytesSCEV = SE.applyLoopGuards(DerefBytesSCEV, *LoopGuards);
- } else {
- // FIXME: two independent off-by-EltSize bugs on this branch:
- // 1. StartOffset here is actually the HIGHEST offset, because it is
- // computed from AR->getStart() rather than
- // AR->evaluateAtIteration(MaxBTC, SE) (see FIXME above).
- // 2. The lower check is over-strict by EltSize and the upper is
- // under-counted by EltSize.
- assert(SE.isKnownNegative(Step) && "must be known negative");
- if (!SE.isKnownPredicate(CmpInst::ICMP_SGE, StartOffset, AccessedBytes))
- return false;
- MaxOffset = StartOffset;
- }
- // MaxOffset must not exceed the deref-region end.
+ // Exclusive upper offset of the accessed range.
+ const SCEV *MaxOffset = addSCEVNoOverflow(LowestOffset, AccessedBytes, SE);
+ if (!MaxOffset)
+ return false;
+ DerefBytesSCEV = SE.applyLoopGuards(DerefBytesSCEV, *LoopGuards);
----------------
fhahn wrote:
It looks like we apply loop guards unconditionally, which probably also improves analysis results in some cases? Could that be done separately?
https://github.com/llvm/llvm-project/pull/211964
More information about the llvm-commits
mailing list