[llvm] [LAA] Fix off-by-EltSize in negative-step deref bounds check (PR #211964)
Aleksandr Popov via llvm-commits
llvm-commits at lists.llvm.org
Thu Oct 1 06:45:06 PDT 2026
================
@@ -301,27 +311,12 @@ static bool evaluatePtrAddRecAtMaxBTCWillNotWrap(
if (!AccessedBytes)
return false;
- // Compute MaxOffset per direction: exclusive upper offset of the
- // accessed range.
- const SCEV *MaxOffset;
- if (IsKnownNonNegative) {
- MaxOffset = addSCEVNoOverflow(StartOffset, AccessedBytes, SE);
- if (!MaxOffset)
- return false;
- DerefBytesSCEV = SE.applyLoopGuards(DerefBytesSCEV, *LoopGuards);
- } else {
- // FIXME: two independent off-by-EltSize bugs on this branch:
- // 1. StartOffset here is actually the HIGHEST offset, because it is
- // computed from AR->getStart() rather than
- // AR->evaluateAtIteration(MaxBTC, SE) (see FIXME above).
- // 2. The lower check is over-strict by EltSize and the upper is
- // under-counted by EltSize.
- assert(SE.isKnownNegative(Step) && "must be known negative");
- if (!SE.isKnownPredicate(CmpInst::ICMP_SGE, StartOffset, AccessedBytes))
- return false;
- MaxOffset = StartOffset;
- }
- // MaxOffset must not exceed the deref-region end.
+ // Exclusive upper offset of the accessed range.
+ const SCEV *MaxOffset = addSCEVNoOverflow(LowestOffset, AccessedBytes, SE);
+ if (!MaxOffset)
+ return false;
+ DerefBytesSCEV = SE.applyLoopGuards(DerefBytesSCEV, *LoopGuards);
----------------
aleks-tmb wrote:
Agree, will add it as a follow-up.
Also, I added one more test for vectorization that's independent of that change, since the current one depends on it. I extracted the tests into a precommit patch, if that makes sense: https://github.com/llvm/llvm-project/pull/228062
https://github.com/llvm/llvm-project/pull/211964
More information about the llvm-commits
mailing list