[llvm] [CodeGenPrepare] Fix crash in tryUnmergingGEPsAcrossIndirectBr with asm goto (PR #201443)
via llvm-commits
llvm-commits at lists.llvm.org
Sun Sep 13 09:35:21 PDT 2026
hesam-oxe wrote:
@topperc You're right, and I withdraw that explanation — thank you for the correction.
`callbr` **is** a terminator, IR coming out of the frontend is required to have terminators in every block, and every pass boundary should see well-formed IR. My claim that "asm goto blocks are created before terminators are inserted" was wrong; there is no such transient state to defend against, and the verifier would reject it. The block that reaches `CodeGenPrepare` without a terminator is genuinely ill-formed, which is also consistent with the original #201252 report crashing earlier in the pipeline (`DominatorTreeWrapperPass` / SemiNCA `getNodeInfo`) in non-assertions builds — the same malformed block trips whichever consumer walks the CFG first.
So the right question is not "how do we tolerate this in CGP" but **which producer creates a block without a terminator**. Given the reproducer's shape — `__asm__ goto("" : "=r"(a) ...)` with the output bound to a *global* — the suspect is clang's asm-goto output handling: the code path that splits the fallthrough block to insert the store of the asm result. That's where I'd dig next: reduce with `-emit-llvm` at `-O0` vs `-O1`, bisect the pass pipeline to find the exact producer, and then aim the fix there (or in the verifier, so this fails loudly at the source instead of crashing a consumer).
**Where that leaves this PR:** the `hasTerminator()` guard here does stop the crash, but as framed it papers over ill-formed IR rather than fixing its origin — in an assertions build it converts a loud, diagnostic failure into a silent bail. I'd rather not push a fix with the wrong justification attached.
Two options, your call:
1. **I investigate the producer** (clang side) and re-scope this PR at the actual root cause, keeping the regression test; or
2. keep the guard purely as a defensive measure but retitle/rebase the commit message to say exactly that — "defensive bail on ill-formed IR; root cause tracked separately" — with the investigation filed as its own issue.
Which would you prefer? (I can't run an assertions build in my current environment, so the producer hunt will go through godbolt/CE and IR reduction rather than local builds — noting that for transparency.)
https://github.com/llvm/llvm-project/pull/201443
More information about the llvm-commits
mailing list