[Bug rtl-optimization/101188] [postreload] Uses content of a clobbered register
gjl at gcc dot gnu.org
gcc-bugzilla@gcc.gnu.org
Sun May 28 19:26:58 GMT 2023
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=101188
--- Comment #9 from Georg-Johann Lay <gjl at gcc dot gnu.org> ---
The bug works as follows:
postreload.cc::reload_cse_move2add() loops over all insns, and at some point it
encounters
(insn 44 14 15 2 (set (reg/f:HI 14 r14 [58])
(reg/v/f:HI 16 r16 [orig:51 self ] [51])) "fail1.c":28:5 101
{*movhi_split}
(nil))
During the analysis for that insn, it executes
rtx_insn *next = next_nonnote_nondebug_insn (insn);
rtx set = NULL_RTX;
if (next)
set = single_set (next);
where next is
(insn 15 44 16 2 (parallel [
(set (reg/f:HI 14 r14 [58])
(plus:HI (reg/f:HI 14 r14 [58])
(const_int 68 [0x44])))
(clobber (reg:QI 31 r31))
]) "fail1.c":28:5 175 {addhi3_clobber}
(nil))
Further down, it continues with success = 0:
if (success)
delete_insn (insn);
changed |= success;
insn = next;
[...]
continue;
The scan then continues with NEXT_INSN (insn), which is the insn AFTER insn 15,
so the CLOBBER of QI:31 in insn 15 is bypassed, and note_stores or similar is
never executed on insn 15. The "set = single_set (next)" also bypasses that
insn 15 is a PARALLEL with a CLOBBER of a general purpose register.
Appears the code is in postreload since 2003, when postreload.c was split out
of reload1.c.
More information about the Gcc-bugs
mailing list