[llvm] [SCEV] Strip incorrec code in proving RHS > Start in howManyLT (PR #222878)

Ramkumar Ramachandra via llvm-commits llvm-commits at lists.llvm.org
Fri Sep 11 14:45:59 PDT 2026


https://github.com/artagnon updated https://github.com/llvm/llvm-project/pull/222878

>From 60a93249d37f954a43cc71d43a3d7e84a9cb246f Mon Sep 17 00:00:00 2001
From: Ramkumar Ramachandra <artagnon at tenstorrent.com>
Date: Fri, 11 Sep 2026 09:06:22 +0100
Subject: [PATCH] [SCEV] Strip incorrect code in proving RHS > Start in
 howManyLT

The stripped simplification was incorrect, and probably fixes an
underlying miscompile.

Proof: https://alive2.llvm.org/ce/z/cmVLce

Co-authored-by: Nikita Popov <npopov at redhat.com>
---
 llvm/lib/Analysis/ScalarEvolution.cpp | 19 ++-----------------
 1 file changed, 2 insertions(+), 17 deletions(-)

diff --git a/llvm/lib/Analysis/ScalarEvolution.cpp b/llvm/lib/Analysis/ScalarEvolution.cpp
index 06f350fd2179b..9e32cb68d043c 100644
--- a/llvm/lib/Analysis/ScalarEvolution.cpp
+++ b/llvm/lib/Analysis/ScalarEvolution.cpp
@@ -13723,23 +13723,8 @@ ScalarEvolution::howManyLessThans(const SCEV *LHS, const SCEV *RHS,
         const SCEV *GuardedRHS = applyLoopGuards(OrigRHS, L);
         const SCEV *GuardedStart = applyLoopGuards(OrigStart, L);
 
-        if (isLoopEntryGuardedByCond(L, CondGE, OrigRHS, OrigStart) ||
-            isKnownPredicate(CondGE, GuardedRHS, GuardedStart))
-          return true;
-
-        // (RHS > Start - 1) implies RHS >= Start.
-        // * "RHS >= Start" is trivially equivalent to "RHS > Start - 1" if
-        //   "Start - 1" doesn't overflow.
-        // * For signed comparison, if Start - 1 does overflow, it's equal
-        //   to INT_MAX, and "RHS >s INT_MAX" is trivially false.
-        // * For unsigned comparison, if Start - 1 does overflow, it's equal
-        //   to UINT_MAX, and "RHS >u UINT_MAX" is trivially false.
-        //
-        // FIXME: Should isLoopEntryGuardedByCond do this for us?
-        auto CondGT = IsSigned ? ICmpInst::ICMP_SGT : ICmpInst::ICMP_UGT;
-        auto *StartMinusOne =
-            getAddExpr(OrigStart, getMinusOne(OrigStart->getType()));
-        return isLoopEntryGuardedByCond(L, CondGT, OrigRHS, StartMinusOne);
+        return isLoopEntryGuardedByCond(L, CondGE, OrigRHS, OrigStart) ||
+               isKnownPredicate(CondGE, GuardedRHS, GuardedStart);
       };
 
       // If we know that RHS >= Start in the context of loop, then we know



More information about the llvm-commits mailing list