[Metal] Fix fill_buffer_1byte edge handling for unaligned offsets (#24639)
fill_buffer_1byte silently corrupted data for any buffer_offset % 4 in
{1, 3}, and corrupted neighboring bytes for fills contained within a
single 4-byte word. Two independent defects, both in the edge handling:
1. left_mask selected the wrong byte positions. It was computed as ~((1
<< (8 * (4 - left_byte_count))) - 1), selecting byte positions [4-k, 4)
of the left word. But the left edge must overwrite the high (4-k) bytes,
i.e. positions [k, 4), so the mask must be ~((1 << (8 * k)) - 1). The
stray "4 -" is the asymmetry with the correct right_mask (which uses
right_byte_count directly). For k in {1, 3} the wrong mask is a
symmetric 2-byte misplacement (|4-2k| == 2):
- offset % 4 == 1: under-fill -- the leading 2 in-region bytes are left
stale.
- offset % 4 == 3: underrun -- the 2 bytes immediately preceding the
region are clobbered.
2. When the entire fill range fits within one 32-bit word, the left and
right read-modify-write blocks both attacked that same word with masks
assuming a complete edge, writing pattern bytes outside [offset, offset
+ length). Reachable via short 1/2-byte-pattern fills (duplicated to 4
bytes on the host) whose length lands within one word.
Beyond the k == 0 case (handled by fill_buffer_4byte), the kernel was
correct only for offset % 4 == 2 with length >= 2.
Fix (kernel-only):
- Correct left_mask: use left_byte_count instead of (4 -
left_byte_count).
- Add a single-word guard: when left_start == right_start, perform one
read-modify-write over bytes [left_byte_count, right_byte_count) using
mask = left_mask & right_mask; otherwise keep the existing separate
left/right blocks. This also makes length == 0 a safe no-op via mask
collapse, where the original corrupted up to 4 neighbor bytes.
No host-side change: the middle word range [middle_start, right_start)
and thus the thread-count requirement are unchanged, and the existing
dispatch sizing in builtin_executables.m already over-dispatches safely.
Verified:
CTS/CommandBufferFillBufferTest.FillSizeAlignmentAndPatternClasses/metal
and CTS/QueueTransferTest.FillSizeAlignmentAndPatternClasses/metal now
pass (previously failed with a 2-byte under-fill at offset%4==1 and a
2-byte underrun at offset%4==3); all *Fill* cases pass (22/22 in
command_buffer_tests, 8/8 in queue_tests).
Signed-off-by: Alex Vasile <48962821+Alex-Vasile@users.noreply.github.com>IREE (Intermediate Representation Execution Environment, pronounced as “eerie”) is an MLIR-based end-to-end compiler and runtime that lowers Machine Learning (ML) models to a unified IR that scales up to meet the needs of the datacenter and down to satisfy the constraints and special considerations of mobile and edge deployments.
See our website for project details, user guides, and instructions on building from source.
Releases notes are published on GitHub releases.
| Package | Release status |
|---|---|
| GitHub release (stable) | |
| GitHub release (nightly) | |
iree-base-compiler | |
iree-base-runtime |
For more details on the release process, see https://iree.dev/developers/general/release-management/.
| Operating system | Build status |
|---|---|
| Linux | |
| macOS | |
| macOS |
For the full list of workflows see https://iree.dev/developers/general/github-actions/.
See our website for more information.
Community meeting recordings: IREE YouTube channel
| Date | Title | Recording | Slides |
|---|---|---|---|
| 2025-06-10 | Data-Tiling in IREE: Achieving High Performance Through Compiler Design (AsiaLLVM) | recording | slides |
| 2025-05-17 | Introduction to GPU architecture and IREE's GPU CodeGen Pipeline | recording | slides |
| 2025-02-12 | The Long Tail of AI: SPIR-V in IREE and MLIR (Vulkanised) | recording | slides |
| 2024-10-01 | Unveiling the Inner Workings of IREE: An MLIR-Based Compiler for Diverse Hardware | recording | |
| 2021-06-09 | IREE Runtime Design Tech Talk | recording | slides |
| 2020-08-20 | IREE CodeGen (MLIR Open Design Meeting) | recording | slides |
| 2020-03-18 | Interactive HAL IR Walkthrough | recording | |
| 2020-01-31 | End-to-end MLIR Workflow in IREE (MLIR Open Design Meeting) | recording | slides |
IREE is licensed under the terms of the Apache 2.0 License with LLVM Exceptions. See LICENSE for more information.