[llvm] [LAA] Fix off-by-EltSize in negative-step deref bounds check (PR #211964)

Florian Hahn via llvm-commits llvm-commits at lists.llvm.org
Tue Sep 8 07:54:10 PDT 2026


================
@@ -301,27 +311,12 @@ static bool evaluatePtrAddRecAtMaxBTCWillNotWrap(
   if (!AccessedBytes)
     return false;
 
-  // Compute MaxOffset per direction: exclusive upper offset of the
-  // accessed range.
-  const SCEV *MaxOffset;
-  if (IsKnownNonNegative) {
-    MaxOffset = addSCEVNoOverflow(StartOffset, AccessedBytes, SE);
-    if (!MaxOffset)
-      return false;
-    DerefBytesSCEV = SE.applyLoopGuards(DerefBytesSCEV, *LoopGuards);
-  } else {
-    // FIXME: two independent off-by-EltSize bugs on this branch:
-    //  1. StartOffset here is actually the HIGHEST offset, because it is
-    //     computed from AR->getStart() rather than
-    //     AR->evaluateAtIteration(MaxBTC, SE) (see FIXME above).
-    //  2. The lower check is over-strict by EltSize and the upper is
-    //     under-counted by EltSize.
-    assert(SE.isKnownNegative(Step) && "must be known negative");
-    if (!SE.isKnownPredicate(CmpInst::ICMP_SGE, StartOffset, AccessedBytes))
-      return false;
-    MaxOffset = StartOffset;
-  }
-  // MaxOffset must not exceed the deref-region end.
+  // Exclusive upper offset of the accessed range.
+  const SCEV *MaxOffset = addSCEVNoOverflow(LowestOffset, AccessedBytes, SE);
+  if (!MaxOffset)
+    return false;
+  DerefBytesSCEV = SE.applyLoopGuards(DerefBytesSCEV, *LoopGuards);
----------------
fhahn wrote:

It looks like we apply loop guards unconditionally, which probably also improves analysis results in some cases? Could that be done separately?

https://github.com/llvm/llvm-project/pull/211964


More information about the llvm-commits mailing list