https://gcc.gnu.org/bugzilla/show_bug.cgi?id=126601

--- Comment #5 from GCC Commits <cvs-commit at gcc dot gnu.org> ---
The releases/gcc-16 branch has been updated by Jakub Jelinek
<[email protected]>:

https://gcc.gnu.org/g:13a6f9865aa6d938389a8361159b32a715d072f1

commit r16-9504-g13a6f9865aa6d938389a8361159b32a715d072f1
Author: Jakub Jelinek <[email protected]>
Date:   Tue Aug 4 10:37:09 2026 +0200

    widening_mul: Fix up ICE in maybe_optimize_guarding_check [PR126601]

    The following testcase ICEs, because we try to quick_push into an already
    full vector.
    The caller (match_arith_overflow) has
      auto_vec<gimple *, 8> mul_stmts;
    and 0-6 mul_stmts.quick_push (...); calls (none of that in a loop), and
then
    call to that maybe_optimize_guarding_check function which does one
    quick_push, but the function is called in a
      FOR_EACH_IMM_USE_STMT (use_stmt, iter, cast_lhs ? cast_lhs : lhs)
    loop, so if we are unlucky  as on the attached testcase, it is called more
    than twice and either triggers ICE, or worse with checking disabled buffer
    overflow.

    The following patch fixes that by using safe_push in that spot instead.

    2026-08-04  Jakub Jelinek  <[email protected]>

            PR tree-optimization/126601
            * tree-ssa-math-opts.cc (maybe_optimize_guarding_check): Use
safe_push
            on mul_stmts rather than quick_push.

            * gcc.dg/tree-ssa/pr126601.c: New test.

    Reviewed-by: Richard Biener <[email protected]>
    (cherry picked from commit a49c114c7b3edd33a6ff2e50e6276ca1fbe8ad83)

Reply via email to