Skip to content

[Bug][whitefox-audit]pto_analyze_simt_persistent_fragment pass 编译报错:error: 'llvm.store' op persistent SIMT fragment byte offset 1 must be non-negative and aligned to element byte size 4 #1520

Description

@yaomicat

Component

PTO Dialect / ODS (include/PTO/IR)

Description

提单:pto_analyze_simt_persistent_fragment pass 编译报错:error: 'llvm.store' op persistent SIMT fragment byte offset 1 must be non-negative and aligned to element byte size 4

1. 问题来源

  • pass: pto_analyze_simt_persistent_fragment (-pto-analyze-simt-persistent-fragment)
  • 涉及文件: /home/cplop/code/pto/PTOAS/lib/PTO/Transforms/PTOAnalyzeSIMTPersistentFragment.cpp
  • 发现途径: run.py confirm LLM 自动确认
  • 确认时间: 2026-09-11T15:25:03

2. 为什么是 bug

bug PoC 差分 crash: /tmp/wfa_task_ks3c39y8.pto:9:7: error: 'llvm.store' op persistent SIMT fragment byte offset 1 must be non-negative and aligned to element byte size 4

差分复现:合法输入经 pass 后失败 + control 通过。

根因线索:合法输入(无 pass 基线 exit=0)在 -pto-analyze-simt-persistent-fragment 后失败;对照用例可成功通过同一 pass。
bug stderr 摘要:

/home/cplop/whitefox-audit/output/confirm_drafts/pto_analyze_simt_persistent_fragment/ai_attempts/report_bug_poc/bug.pto:9:7: error: 'llvm.store' op persistent SIMT fragment byte offset 1 must be non-negative and aligned to element byte size 4
      llvm.store %one, %element1 : f32, !llvm.ptr
      ^
/home/cplop/whitefox-audit/output/confirm_drafts/pto_analyze_simt_persistent_fragment/ai_attempts/report_bug_poc/bug.pto:9:7: note: see current operation: "llvm.store"(%2, %4) <{ordering = 0 : i64}> : (f32, !llvm.ptr) -> ()

3. 实证结果

  • bug exit=1 parse_error=False
  • control exit=0
/home/cplop/whitefox-audit/output/confirm_drafts/pto_analyze_simt_persistent_fragment/ai_attempts/report_bug_poc/bug.pto:9:7: error: 'llvm.store' op persistent SIMT fragment byte offset 1 must be non-negative and aligned to element byte size 4
      llvm.store %one, %element1 : f32, !llvm.ptr
      ^
/home/cplop/whitefox-audit/output/confirm_drafts/pto_analyze_simt_persistent_fragment/ai_attempts/report_bug_poc/bug.pto:9:7: note: see current operation: "llvm.store"(%2, %4) <{ordering = 0 : i64}> : (f32, !llvm.ptr) -> ()

4. 复现

bash /home/cplop/whitefox-audit/test/pto_analyze_simt_persistent_fragment_bug_1/reproduce.sh

5. 修复建议

  1. 确认 bug.pto 无 pass 时 exit=0(本包已验证)。
  2. 对照 stderr 定位是 pass 内部 assert/signalPassFailure,还是变换后 IR 破坏 SSA/类型。
  3. 在 /home/cplop/code/pto/PTOAS/lib/PTO/Transforms/PTOAnalyzeSIMTPersistentFragment.cpp 中找到对应 rewrite/hoist 路径,补齐与 control 路径对称的守卫(dominance / 类型 byte-width / 操作数完备性等)。
  4. 用本目录 bug.pto 作 lit 回归:修复后应 exit=0。

Reproduction (minimal)

bug.pto

module attributes {pto.target_arch = "a5", pto.kernel_kind = #pto.kernel_kind<vector>} {
  func.func @persistent_fragment_analysis(%dst: !pto.ptr<f32, ub>) attributes {pto.entry} {
    %c3_i32 = arith.constant 3 : i32
    %fragment = llvm.alloca %c3_i32 x f32 {pto.persistent} : (i32) -> !llvm.ptr
    pto.section.simt<<<32, 1, 1>>> {
      %one = arith.constant 1.000000e+00 : f32
      %c1_i64 = arith.constant 1 : i64
      %element1 = llvm.getelementptr %fragment[%c1_i64] : (!llvm.ptr, i64) -> !llvm.ptr, i8
      llvm.store %one, %element1 : f32, !llvm.ptr
    }
    func.return
  }
}

control.pto

module attributes {pto.target_arch = "a5", pto.kernel_kind = #pto.kernel_kind<vector>} {
  func.func @persistent_fragment_analysis(%dst: !pto.ptr<f32, ub>) attributes {pto.entry} {
    %c3_i32 = arith.constant 3 : i32
    %fragment = llvm.alloca %c3_i32 x f32 {pto.persistent} : (i32) -> !llvm.ptr
    pto.section.simt<<<32, 1, 1>>> {
      %one = arith.constant 1.000000e+00 : f32
      %c4_i64 = arith.constant 4 : i64
      %element1 = llvm.getelementptr %fragment[%c4_i64] : (!llvm.ptr, i64) -> !llvm.ptr, i8
      llvm.store %one, %element1 : f32, !llvm.ptr
    }
    func.return
  }
}

reproduce.sh

#!/usr/bin/env bash
# 一键复现: pto_analyze_simt_persistent_fragment / pto_analyze_simt_persistent_fragment_bug_1
set -u
HERE="$(cd "$(dirname "$0")" && pwd)"
REPO=/home/cplop/code/pto/PTOAS
PASS='-pto-analyze-simt-persistent-fragment'
BIN="${1:-}"
if [ -z "$BIN" ]; then
  for cand in "$REPO/build/tools/pto-test-opt/pto-test-opt" \
              "$REPO/build-coverage/tools/pto-test-opt/pto-test-opt"; do
    [ -x "$cand" ] && BIN="$cand" && break
  done
fi
if [ -z "$BIN" ] || [ ! -x "$BIN" ]; then
  echo "[!] 未找到 pto-test-opt" >&2
  exit 3
fi
echo "[i] 使用二进制: $BIN"
run_one() {
  local name="$1"
  "$BIN" $PASS "$HERE/${name}.pto" >"$HERE/${name}.out.pto" 2>"$HERE/${name}.stderr.txt"
  echo "$?"
}

ctl=$(run_one control)
bug=$(run_one bug)
echo "[control] exit=$ctl (预期 0)"
echo "[bug] exit=$bug (预期非 0)"
echo "--- bug.stderr ---"
cat "$HERE/bug.stderr.txt"
if [ "$ctl" -eq 0 ] && [ "$bug" -ne 0 ]; then
  echo "[OK] 差分复现成功(bug 失败 + control 通过)"
  exit 1
fi
if [ "$ctl" -eq 0 ] && [ "$bug" -eq 0 ]; then
  echo "[OK] 未复现(可能已修复)"
  exit 0
fi
echo "[!] 结果异常"
exit 2

Expected behavior

编译通过

Actual behavior / error logs

pto-test-opt -pto-analyze-simt-persistent-fragment bug.pto:

/home/cplop/whitefox-audit/test/pto_analyze_simt_persistent_fragment_bug_1/bug.pto:9:7: error: 'llvm.store' op persistent SIMT fragment byte offset 1 must be non-negative and aligned to element byte size 4
      llvm.store %one, %element1 : f32, !llvm.ptr
      ^
/home/cplop/whitefox-audit/test/pto_analyze_simt_persistent_fragment_bug_1/bug.pto:9:7: note: see current operation: "llvm.store"(%2, %4) <{ordering = 0 : i64}> : (f32, !llvm.ptr) -> ()

pto-test-opt bug.pto(去掉-pto-analyze-simt-persistent-fragment选项编译通过):

module attributes {pto.kernel_kind = #pto.kernel_kind<vector>, pto.target_arch = "a5"} {
  func.func @persistent_fragment_analysis(%arg0: !pto.ptr<f32, ub>) attributes {pto.entry} {
    %c3_i32 = arith.constant 3 : i32
    %0 = llvm.alloca %c3_i32 x f32 {pto.persistent} : (i32) -> !llvm.ptr
    pto.section.simt<<<32, 1, 1>>> {
      %cst = arith.constant 1.000000e+00 : f32
      %c1_i64 = arith.constant 1 : i64
      %1 = llvm.getelementptr %0[%c1_i64] : (!llvm.ptr, i64) -> !llvm.ptr, i8
      llvm.store %cst, %1 : f32, !llvm.ptr
    }
    return
  }
}

Git commit

f45729d

Host platform

None

Target Ascend arch (if relevant)

None

PTOAS build level (if relevant)

None

Activity

  1. added
    bugSomething isn't working
    QAIssues from the QA team
    on Sep 11, 2026
  2. jimmychou0 commented on Oct 8, 2026

    @jimmychou0
    Contributor

    这是 -pto-analyze-simt-persistent-fragment 的预期 fail-fast 校验,而非缺陷,建议关闭。

    原因:bug.pto 的 fragment 是 f32 alloca(元素 4 字节),但访问用的是 i8 型 GEP,index=1 即字节偏移 1,在此做 f32 store 属于未对齐访问(LLVM 语义下默认按 ABI 对齐,已是 UB)。control.pto 的 index=4 对应字节偏移 4,恰好对齐且在界内,所以通过——差异只在 GEP index 是否按元素字节数对齐。

    按设计文档 docs/designs/ptoas_persistent_simt_fragment_plan.md,persistent fragment 的访问 offset 必须静态、按元素对齐、在界内,不满足即报错,不做静默回退——物化阶段要把每个 element 映射到固定 slot,未对齐访问无法表示。当前诊断准确、退出干净(exit=1,无 crash/误编译),且已有回归测试固化该行为:test/lit/vpto/materialize_simt_persistent_fragment_unaligned_offset_invalid.pto

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

QAIssues from the QA teambugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions