Fix out-of-bounds crash in Stream affinity analysis for scf.while (#24723)

See issue https://github.com/iree-org/iree/issues/24722

The issue contains a deeper explanation of the issue and a repro case
(which is the same as the lit test here).

When an `scf.while` carries more values through its "before" region than
the op has results (i.e. some loop-carried values are not forwarded to a
result via `scf.condition`), the affinity analysis mapped an `scf.yield`
operand number directly onto `whileOp->getResult(operandNumber)`. Since
the "after" region yield has one operand per init operand (`N`) while
the op may have fewer results (`M`), this lead to `getResult()` being
out of bounds.

Two independent sites made this naive mapping:

- **`Affinity.cpp`**: in the `scf.yield` → `scf.while` branch of
`ValueConsumerAffinityPVS::updateFromUse`, drop the
`whileOp->getResult(operandNumber)` propagation and keep only the
before-region-argument propagation. (Results are already handled by the
`scf.condition` case.)

- **`Explorer.cpp`**: guard the `ReturnLike` result-mapping fallback in
`walkTransitiveUses` with
`!isa<RegionBranchTerminatorOpInterface>(ownerOp)` (region-branch
terminators like `scf.yield` are already handled correctly above) plus a
`use.getOperandNumber() < parent->getNumResults()` bounds check.

Added regression test `@scf_while_extra_loop_carried`, which exercises
the `N > M` shape (two loop-carried values, one result) that previously
asserted.

Note that Claude made the fix suggestions and, while they look okay to
me, I'm not at all familiar with this code.

---------

Signed-off-by: Paul Stark <paul.stark@cdprojektred.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Artem Gindinson <gindinson@roofline.ai>
3 files changed
tree: a855a25958d1ea2553b07cc6ad26a6b67af9d362
  1. .github/
  2. build_tools/
  3. compiler/
  4. docs/
  5. experimental/
  6. integrations/
  7. lib/
  8. llvm-external-projects/
  9. runtime/
  10. samples/
  11. tests/
  12. third_party/
  13. tools/
  14. .bazel_to_cmake.cfg.py
  15. .bazelignore
  16. .bazelrc
  17. .bazelversion
  18. .clang-format
  19. .git-blame-ignore-revs
  20. .gitattributes
  21. .gitignore
  22. .gitmodules
  23. .pre-commit-config.yaml
  24. .yamllint.yml
  25. AUTHORS
  26. BUILD.bazel
  27. CITATION.cff
  28. CMakeLists.txt
  29. configure_bazel.py
  30. CONTRIBUTING.md
  31. LICENSE
  32. MAINTAINERS.md
  33. MODULE.bazel
  34. README.md
  35. RELEASING.md
README.md

IREE: Intermediate Representation Execution Environment

IREE (Intermediate Representation Execution Environment, pronounced as “eerie”) is an MLIR-based end-to-end compiler and runtime that lowers Machine Learning (ML) models to a unified IR that scales up to meet the needs of the datacenter and down to satisfy the constraints and special considerations of mobile and edge deployments.

See our website for project details, user guides, and instructions on building from source.

IREE Discord Status pre-commit OpenSSF Best Practices

Project news

Project status

Release status

Releases notes are published on GitHub releases.

PackageRelease status
GitHub release (stable)GitHub Release
GitHub release (nightly)GitHub Release
iree-base-compilerPyPI version
iree-base-runtimePyPI version

For more details on the release process, see https://iree.dev/developers/general/release-management/.

Build status

CI PkgCI

Nightly build status

Operating systemBuild status
LinuxCI - Linux arm64 clang
macOSCI - macOS x64 clang
macOSCI - macOS arm64 clang

For the full list of workflows see https://iree.dev/developers/general/github-actions/.

Communication channels

Related project channels

  • MLIR topic within LLVM Discourse: IREE is enabled by and heavily relies on MLIR. IREE sometimes is referred to in certain MLIR discussions. Useful if you are also interested in MLIR evolution.

Architecture overview

IREE Architecture IREE Architecture

See our website for more information.

Presentations and talks

Community meeting recordings: IREE YouTube channel

DateTitleRecordingSlides
2025-06-10Data-Tiling in IREE: Achieving High Performance Through Compiler Design (AsiaLLVM)recordingslides
2025-05-17Introduction to GPU architecture and IREE's GPU CodeGen Pipelinerecordingslides
2025-02-12The Long Tail of AI: SPIR-V in IREE and MLIR (Vulkanised)recordingslides
2024-10-01Unveiling the Inner Workings of IREE: An MLIR-Based Compiler for Diverse Hardwarerecording
2021-06-09IREE Runtime Design Tech Talkrecordingslides
2020-08-20IREE CodeGen (MLIR Open Design Meeting)recordingslides
2020-03-18Interactive HAL IR Walkthroughrecording
2020-01-31End-to-end MLIR Workflow in IREE (MLIR Open Design Meeting)recordingslides

License

IREE is licensed under the terms of the Apache 2.0 License with LLVM Exceptions. See LICENSE for more information.