[llvm] [CodeGenPrepare] Fix crash in tryUnmergingGEPsAcrossIndirectBr with asm goto (PR #201443)

via llvm-commits llvm-commits at lists.llvm.org
Sun Sep 13 09:35:21 PDT 2026


hesam-oxe wrote:

@topperc You're right, and I withdraw that explanation — thank you for the correction.

`callbr` **is** a terminator, IR coming out of the frontend is required to have terminators in every block, and every pass boundary should see well-formed IR. My claim that "asm goto blocks are created before terminators are inserted" was wrong; there is no such transient state to defend against, and the verifier would reject it. The block that reaches `CodeGenPrepare` without a terminator is genuinely ill-formed, which is also consistent with the original #201252 report crashing earlier in the pipeline (`DominatorTreeWrapperPass` / SemiNCA `getNodeInfo`) in non-assertions builds — the same malformed block trips whichever consumer walks the CFG first.

So the right question is not "how do we tolerate this in CGP" but **which producer creates a block without a terminator**. Given the reproducer's shape — `__asm__ goto("" : "=r"(a) ...)` with the output bound to a *global* — the suspect is clang's asm-goto output handling: the code path that splits the fallthrough block to insert the store of the asm result. That's where I'd dig next: reduce with `-emit-llvm` at `-O0` vs `-O1`, bisect the pass pipeline to find the exact producer, and then aim the fix there (or in the verifier, so this fails loudly at the source instead of crashing a consumer).

**Where that leaves this PR:** the `hasTerminator()` guard here does stop the crash, but as framed it papers over ill-formed IR rather than fixing its origin — in an assertions build it converts a loud, diagnostic failure into a silent bail. I'd rather not push a fix with the wrong justification attached.

Two options, your call:
1. **I investigate the producer** (clang side) and re-scope this PR at the actual root cause, keeping the regression test; or
2. keep the guard purely as a defensive measure but retitle/rebase the commit message to say exactly that — "defensive bail on ill-formed IR; root cause tracked separately" — with the investigation filed as its own issue.

Which would you prefer? (I can't run an assertions build in my current environment, so the producer hunt will go through godbolt/CE and IR reduction rather than local builds — noting that for transparency.)

https://github.com/llvm/llvm-project/pull/201443


More information about the llvm-commits mailing list