[Mlir-commits] [mlir] [mlir][memref] Fix crash in ReinterpretCastOpConstantFolder for negative sizes (PR #189237)

Mehdi Amini llvmlistbot at llvm.org
Sun Mar 29 06:08:17 PDT 2026


https://github.com/joker-eph created https://github.com/llvm/llvm-project/pull/189237

`ReinterpretCastOpConstantFolder` could fold `memref.reinterpret_cast` ops whose sizes contain negative constants (e.g. `-1 : index`). After calling `getConstifiedMixedSizes()` the folder passed these values into `ReinterpretCastOp::create`, which internally calls `MemRefType::get` and hits an assertion that all static dimension sizes are non-negative.

Fix by skipping the fold when any constant size is negative.

Fixes https://github.com/llvm/llvm-project/issues/188407

Assisted-by: Claude Code

>From aa2ea85f4faca4e7d85a21d9f2a884f82713fcbf Mon Sep 17 00:00:00 2001
From: Mehdi Amini <joker.eph at gmail.com>
Date: Sat, 28 Mar 2026 14:22:01 -0700
Subject: [PATCH] [mlir][memref] Fix crash in ReinterpretCastOpConstantFolder
 for negative sizes

`ReinterpretCastOpConstantFolder` could fold `memref.reinterpret_cast`
ops whose sizes contain negative constants (e.g. `-1 : index`). After
calling `getConstifiedMixedSizes()` the folder passed these values into
`ReinterpretCastOp::create`, which internally calls `MemRefType::get`
and hits an assertion that all static dimension sizes are non-negative.

Fix by skipping the fold when any constant size is negative.

Fixes https://github.com/llvm/llvm-project/issues/188407

Assisted-by: Claude Code
---
 mlir/lib/Dialect/MemRef/IR/MemRefOps.cpp   |  8 ++++++++
 mlir/test/Dialect/MemRef/canonicalize.mlir | 21 +++++++++++++++++++++
 2 files changed, 29 insertions(+)

diff --git a/mlir/lib/Dialect/MemRef/IR/MemRefOps.cpp b/mlir/lib/Dialect/MemRef/IR/MemRefOps.cpp
index 404b2aacf1450..5354c628ae6db 100644
--- a/mlir/lib/Dialect/MemRef/IR/MemRefOps.cpp
+++ b/mlir/lib/Dialect/MemRef/IR/MemRefOps.cpp
@@ -2291,6 +2291,14 @@ struct ReinterpretCastOpConstantFolder
                        [](OpFoldResult ofr) { return isa<Attribute>(ofr); }))
       return failure();
 
+    // Do not fold if any size is a negative constant; MemRefType::get asserts
+    // non-negative static sizes.
+    for (OpFoldResult sizeOfr : sizes)
+      if (auto cst = getConstantIntValue(sizeOfr))
+        if (*cst < 0)
+          return rewriter.notifyMatchFailure(
+              op, "negative constant size is invalid");
+
     auto newReinterpretCast = ReinterpretCastOp::create(
         rewriter, op->getLoc(), op.getSource(), offsets[0], sizes, strides);
 
diff --git a/mlir/test/Dialect/MemRef/canonicalize.mlir b/mlir/test/Dialect/MemRef/canonicalize.mlir
index 92754dc919695..604da0592c93a 100644
--- a/mlir/test/Dialect/MemRef/canonicalize.mlir
+++ b/mlir/test/Dialect/MemRef/canonicalize.mlir
@@ -1287,6 +1287,27 @@ func.func @reinterpret_of_extract_strided_metadata_w_different_offset(%arg0 : me
 
 // -----
 
+// Check that reinterpret_cast with a negative constant size is not folded.
+// Folding would attempt to create a MemRefType with a negative static dimension,
+// which triggers an assertion in MemRefType::get (issue #188407).
+// CHECK-LABEL: func @reinterpret_cast_no_fold_negative_size
+//  CHECK-SAME: (%[[ARG:.*]]: memref<2x3xf32>)
+//       CHECK: %[[C0:.*]] = arith.constant 0 : index
+//       CHECK: %[[C1:.*]] = arith.constant 1 : index
+//       CHECK: %[[SZ:.*]] = arith.constant -1 : index
+//       CHECK: memref.reinterpret_cast %[[ARG]] to offset: [%[[C0]]], sizes: [%[[C1]], %[[SZ]]], strides: [%[[SZ]], %[[C1]]]
+func.func @reinterpret_cast_no_fold_negative_size(%arg0: memref<2x3xf32>) -> memref<?x?xf32, strided<[?, ?], offset: ?>> {
+  %c0 = arith.constant 0 : index
+  %c1 = arith.constant 1 : index
+  %sz = arith.constant -1 : index
+  %output = memref.reinterpret_cast %arg0 to
+            offset: [%c0], sizes: [%c1, %sz], strides: [%sz, %c1]
+            : memref<2x3xf32> to memref<?x?xf32, strided<[?, ?], offset: ?>>
+  return %output : memref<?x?xf32, strided<[?, ?], offset: ?>>
+}
+
+// -----
+
 func.func @canonicalize_rank_reduced_subview(%arg0 : memref<8x?xf32>,
     %arg1 : index) -> memref<?xf32, strided<[?], offset: ?>> {
   %c0 = arith.constant 0 : index



More information about the Mlir-commits mailing list