Skip to content

[Bug] [whitefox-audit] pto_lower_to_ubuf_ops :emitUBBinOp 将 src1RepeatStride 硬编码为 0,导致crash #1564

Description

@yaomicat

Component

Verifier / IR semantics (lib/PTO/IR)

Description

提单:pto_lower_to_ubuf_ops :emitUBBinOp 将 src1RepeatStride 硬编码为 0

1. 问题来源

  • pass: pto_lower_to_ubuf_ops (-pto-lower-to-ubuf-ops)
  • 涉及文件: PTOAS/lib/PTO/Transforms/LowerPTOToUBufOps.cpp
  • 发现途径: run.py confirm LLM 自动确认
  • 确认时间: 2026-09-18T17:28:43

2. 为什么是 bug

请仅针对可疑点 1/2(#1:emitUBBinOp将src1RepeatStride` 硬编码为 0)构造最小差分 PoC;不要同时覆盖其它可疑点。
pass 级判定摘要(仅供背景):crash_candidate(/tmp/wfa_task_xxp6j9gn.pto:3:13: error: A3 VPTO UB lowering requires planned alloc_tile addresses; run PTOViewToMemref, PTOPlanMemory, PTOResolveReservedBuffers, and PTOMaterializeTileHandles before LowerPTOToUBufOps);LLM 原判 false_positive,保守升级为 suspected

control 非法或失败,已丢弃对照;bug 侧为强崩溃(pass-fired / assert/abort)且非 parse,按弱差分落包。

根因线索:合法输入(无 pass 基线 exit=0)在 -pto-lower-to-ubuf-ops 后失败;对照用例可成功通过同一 pass。
bug stderr 摘要:

LLVM ERROR: Building op `scf.for` but it isn't known in this MLIRContext: the dialect may not be loaded or this operation hasn't been added by the dialect. See also https://mlir.llvm.org/getting_started/Faq/#registered-loaded-dependent-whats-up-with-dialects-management
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace.
Stack dump:
0.      Program arguments: /home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt -pto-lower-to-ubuf-ops /home/cplop/whitefox-audit/output/confirm_drafts/pto_lower_to_ubuf_ops/ai_attempts/suspect_1/suspect_1_llm_attempt_1/bug.pto
 #0 0x000073ffef3eaea2 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/home/cplop/code/pto/llvm-project/build-shared/lib/libLLVMSupport.so.19.1+0x1eaea2)
 #1 0x000073ffe

3. 实证结果

  • bug exit=-6 parse_error=False
  • control exit=n/a
LLVM ERROR: Building op `scf.for` but it isn't known in this MLIRContext: the dialect may not be loaded or this operation hasn't been added by the dialect. See also https://mlir.llvm.org/getting_started/Faq/#registered-loaded-dependent-whats-up-with-dialects-management
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace.
Stack dump:
0.      Program arguments: /home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt -pto-lower-to-ubuf-ops /home/cplop/whitefox-audit/output/confirm_drafts/pto_lower_to_ubuf_ops/ai_attempts/suspect_1/suspect_1_llm_attempt_1/bug.pto
 #0 0x000073ffef3eaea2 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/home/cplop/code/pto/llvm-project/build-shared/lib/libLLVMSupport.so.19.1+0x1eaea2)
 #1 0x000073ffef3e7f1f llvm::sys::RunSignalHandlers() (/home/cplop/code/pto/llvm-project/build-shared/lib/libLLVMSupport.so.19.1+0x1e7f1f)
 #2 0x000073ffef3e8065 SignalHandler(int) Signals.cpp:0:0
 #3 0x000073ffeea45330 (/lib/x86_64-linux-gnu/libc.so.6+0x45330)
 #4 0x000073ffeea9ec0c pthread_kill (/lib/x86_64-linux-gnu/libc.so.6+0x9ec0c)
 #5 0x000073ffeea4527e raise (/lib/x86_64-linux-gnu/libc.so.6+0x4527e)
 #6 0x000073ffeea288ff abort (/lib/x86_64-linux-gnu/libc.so.6+0x288ff)
 #7 0x000073ffef25631d CompareNumbers(char const*&, char const*&, char const*, char const*, double, double, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*) (.cold) FileUtilities.cpp:0:0
 #8 0x000062cd

4. 复现

pto-test-opt -pto-lower-to-ubuf-ops bug.pto

5. 修复建议

  1. 确认 bug.pto 无 pass 时 exit=0(本包已验证)。
  2. 对照 stderr 定位是 pass 内部 assert/signalPassFailure,还是变换后 IR 破坏 SSA/类型。
  3. 在 PTOAS/lib/PTO/Transforms/LowerPTOToUBufOps.cpp 中找到对应 rewrite/hoist 路径,补齐与 control 路径对称的守卫(dominance / 类型 byte-width / 操作数完备性等)。
  4. 用本目录 bug.pto 作 lit 回归:修复后应 exit=0。

Reproduction (minimal)

bug.pto

module @name attributes {pto.target_arch = "a3", pto.kernel_kind = #pto.kernel_kind<vector>} {
  func.func @tadd_multi_repeat() attributes {pto.aicore} {
    %c0 = arith.constant 0 : i64
    %dst = "pto.alloc_tile"(%c0) {operandSegmentSizes = array<i32: 1, 0, 0>} : (i64) -> !pto.tile_buf<loc=vec, dtype=f32, rows=2, cols=256, v_row=2, v_col=128, blayout=row_major, slayout=none_box, fractal=512, pad=0>
    %src0 = "pto.alloc_tile"(%c0) {operandSegmentSizes = array<i32: 1, 0, 0>} : (i64) -> !pto.tile_buf<loc=vec, dtype=f32, rows=2, cols=256, v_row=2, v_col=128, blayout=row_major, slayout=none_box, fractal=512, pad=0>
    %src1 = "pto.alloc_tile"(%c0) {operandSegmentSizes = array<i32: 1, 0, 0>} : (i64) -> !pto.tile_buf<loc=vec, dtype=f32, rows=2, cols=256, v_row=2, v_col=128, blayout=row_major, slayout=none_box, fractal=512, pad=0>
    "pto.tadd"(%dst, %src0, %src1) : (!pto.tile_buf<loc=vec, dtype=f32, rows=2, cols=256, v_row=2, v_col=128, blayout=row_major, slayout=none_box, fractal=512, pad=0>, !pto.tile_buf<loc=vec, dtype=f32, rows=2, cols=256, v_row=2, v_col=128, blayout=row_major, slayout=none_box, fractal=512, pad=0>, !pto.tile_buf<loc=vec, dtype=f32, rows=2, cols=256, v_row=2, v_col=128, blayout=row_major, slayout=none_box, fractal=512, pad=0>) -> ()
    return
  }
}

Expected behavior

编译通过

Actual behavior / error logs

LLVM ERROR: Building op `scf.for` but it isn't known in this MLIRContext: the dialect may not be loaded or this operation hasn't been added by the dialect. See also https://mlir.llvm.org/getting_started/Faq/#registered-loaded-dependent-whats-up-with-dialects-management
PLEASE submit a bug report to https://github.com/llvm/llvm-project/issues/ and include the crash backtrace.
Stack dump:
0.      Program arguments: /home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt -pto-lower-to-ubuf-ops /home/cplop/whitefox-audit/test/pto_lower_to_ubuf_ops_bug_1/bug.pto
 #0 0x0000798ca71eaea2 llvm::sys::PrintStackTrace(llvm::raw_ostream&, int) (/home/cplop/code/pto/llvm-project/build-shared/lib/libLLVMSupport.so.19.1+0x1eaea2)
 #1 0x0000798ca71e7f1f llvm::sys::RunSignalHandlers() (/home/cplop/code/pto/llvm-project/build-shared/lib/libLLVMSupport.so.19.1+0x1e7f1f)
 #2 0x0000798ca71e8065 SignalHandler(int) Signals.cpp:0:0
 #3 0x0000798ca6845330 (/lib/x86_64-linux-gnu/libc.so.6+0x45330)
 #4 0x0000798ca689ec0c pthread_kill (/lib/x86_64-linux-gnu/libc.so.6+0x9ec0c)
 #5 0x0000798ca684527e raise (/lib/x86_64-linux-gnu/libc.so.6+0x4527e)
 #6 0x0000798ca68288ff abort (/lib/x86_64-linux-gnu/libc.so.6+0x288ff)
 #7 0x0000798ca705631d CompareNumbers(char const*&, char const*&, char const*, char const*, double, double, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char>>*) (.cold) FileUtilities.cpp:0:0
 #8 0x00006128b4981fcd mlir::RegisteredOperationName mlir::OpBuilder::getCheckRegisteredInfo<mlir::scf::ForOp>(mlir::MLIRContext*) (/home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt+0x1041fcd)
 #9 0x00006128b4da884a mlir::scf::ForOp mlir::OpBuilder::create<mlir::scf::ForOp, mlir::Value, mlir::Value, mlir::Value>(mlir::Location, mlir::Value&&, mlir::Value&&, mlir::Value&&) (/home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt+0x146884a)
#10 0x00006128b4dab495 void (anonymous namespace)::LowerPTOToUBufOpsPass::modeColVLAlign<mlir::pto::UBVaddOp>(mlir::Location, mlir::OpBuilder&, mlir::Value, mlir::Value, mlir::Value, mlir::pto::PtrType, (anonymous namespace)::TileShapeInfo const&) LowerPTOToUBufOps.cpp:0:0
#11 0x00006128b4d9b4cb void (anonymous namespace)::LowerPTOToUBufOpsPass::dispatch<mlir::pto::UBVaddOp>(mlir::Location, mlir::OpBuilder&, mlir::Value, mlir::Value, mlir::Value, mlir::pto::PtrType, (anonymous namespace)::TileShapeInfo const&) LowerPTOToUBufOps.cpp:0:0
#12 0x00006128b4d9158c (anonymous namespace)::LowerPTOToUBufOpsPass::runOnOperation() LowerPTOToUBufOps.cpp:0:0
#13 0x0000798ca77f13ee mlir::detail::OpToOpPassAdaptor::run(mlir::Pass*, mlir::Operation*, mlir::AnalysisManager, bool, unsigned int) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRPass.so.19.1+0x243ee)
#14 0x0000798ca77f1a20 mlir::detail::OpToOpPassAdaptor::runPipeline(mlir::OpPassManager&, mlir::Operation*, mlir::AnalysisManager, bool, unsigned int, mlir::PassInstrumentor*, mlir::PassInstrumentation::PipelineParentInfo const*) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRPass.so.19.1+0x24a20)
#15 0x0000798ca77f1e43 mlir::detail::OpToOpPassAdaptor::runOnOperationAsyncImpl(bool)::'lambda'(mlir::detail::OpToOpPassAdaptor::runOnOperationAsyncImpl(bool)::OpPMInfo&)::operator()(mlir::detail::OpToOpPassAdaptor::runOnOperationAsyncImpl(bool)::OpPMInfo&) const Pass.cpp:0:0
#16 0x0000798ca77f08a5 mlir::detail::OpToOpPassAdaptor::runOnOperationAsyncImpl(bool) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRPass.so.19.1+0x238a5)
#17 0x0000798ca77f11a2 mlir::detail::OpToOpPassAdaptor::run(mlir::Pass*, mlir::Operation*, mlir::AnalysisManager, bool, unsigned int) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRPass.so.19.1+0x241a2)
#18 0x0000798ca77f1a20 mlir::detail::OpToOpPassAdaptor::runPipeline(mlir::OpPassManager&, mlir::Operation*, mlir::AnalysisManager, bool, unsigned int, mlir::PassInstrumentor*, mlir::PassInstrumentation::PipelineParentInfo const*) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRPass.so.19.1+0x24a20)
#19 0x0000798ca77f2915 mlir::PassManager::run(mlir::Operation*) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRPass.so.19.1+0x25915)
#20 0x0000798ca7fb3fbf performActions(llvm::raw_ostream&, std::shared_ptr<llvm::SourceMgr> const&, mlir::MLIRContext*, mlir::MlirOptMainConfig const&) MlirOptMain.cpp:0:0
#21 0x0000798ca7fb4813 processBuffer(llvm::raw_ostream&, std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, mlir::MlirOptMainConfig const&, mlir::DialectRegistry&, llvm::ThreadPoolInterface*) MlirOptMain.cpp:0:0
#22 0x0000798ca7fb495c llvm::LogicalResult llvm::function_ref<llvm::LogicalResult (std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, llvm::raw_ostream&)>::callback_fn<mlir::MlirOptMain(llvm::raw_ostream&, std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, mlir::DialectRegistry&, mlir::MlirOptMainConfig const&)::'lambda'(std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, llvm::raw_ostream&)>(long, std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, llvm::raw_ostream&) MlirOptMain.cpp:0:0
#23 0x0000798ca76ba1fe mlir::splitAndProcessBuffer(std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, llvm::function_ref<llvm::LogicalResult (std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, llvm::raw_ostream&)>, llvm::raw_ostream&, llvm::StringRef, llvm::StringRef) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIRSupport.so.19.1+0x211fe)
#24 0x0000798ca7fabbbb mlir::MlirOptMain(llvm::raw_ostream&, std::unique_ptr<llvm::MemoryBuffer, std::default_delete<llvm::MemoryBuffer>>, mlir::DialectRegistry&, mlir::MlirOptMainConfig const&) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIROptLib.so.19.1+0xabbb)
#25 0x0000798ca7fb4aac mlir::MlirOptMain(int, char**, llvm::StringRef, llvm::StringRef, mlir::DialectRegistry&) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIROptLib.so.19.1+0x13aac)
#26 0x0000798ca7fb4fbf mlir::MlirOptMain(int, char**, llvm::StringRef, mlir::DialectRegistry&) (/home/cplop/code/pto/llvm-project/build-shared/lib/libMLIROptLib.so.19.1+0x13fbf)
#27 0x00006128b3a0a67f main (/home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt+0xca67f)
#28 0x0000798ca682a1ca (/lib/x86_64-linux-gnu/libc.so.6+0x2a1ca)
#29 0x0000798ca682a28b __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x2a28b)
#30 0x00006128b39fb545 _start (/home/cplop/code/pto/PTOAS/build/tools/pto-test-opt/pto-test-opt+0xbb545)

Git commit

0096c83

Host platform

None

Target Ascend arch (if relevant)

None

PTOAS build level (if relevant)

None

Activity

  1. added
    bugSomething isn't working
    QAIssues from the QA team
    on Sep 20, 2026
  2. changed the title [-][Bug] pto_lower_to_ubuf_ops :emitUBBinOp` 将 `src1RepeatStride` 硬编码为 0[/-] [+][Bug] pto_lower_to_ubuf_ops :emitUBBinOp` 将 `src1RepeatStride` 硬编码为 0,导致crash[/+] on Sep 20, 2026
  3. changed the title [-][Bug] pto_lower_to_ubuf_ops :emitUBBinOp` 将 `src1RepeatStride` 硬编码为 0,导致crash[/-] [+][Bug] pto_lower_to_ubuf_ops :`emitUBBinOp` 将 `src1RepeatStride` 硬编码为 0,导致crash[/+] on Sep 20, 2026
  4. changed the title [-][Bug] pto_lower_to_ubuf_ops :`emitUBBinOp` 将 `src1RepeatStride` 硬编码为 0,导致crash[/-] [+][Bug] [whitefox-audit] pto_lower_to_ubuf_ops :`emitUBBinOp` 将 `src1RepeatStride` 硬编码为 0,导致crash[/+] on Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

QAIssues from the QA teambugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions