[Bug tree-optimization/126601] [13/14/15/16/17 Regression] ICE in match_arith_overflow with widen-mul since r11-6580

"cvs-commit at gcc dot gnu.org via Gcc-bugs" <[email protected]> Tue, 04 Aug 2026 08:38:12 +0000
Newsgroups gmane.comp.gcc.bugs
Message-ID <[email protected]/bugzilla/>
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=3D126601

--- Comment #4 from GCC Commits <cvs-commit at gcc dot gnu.org> ---
The master branch has been updated by Jakub Jelinek <[email protected]>:

https://gcc.gnu.org/g:a49c114c7b3edd33a6ff2e50e6276ca1fbe8ad83

commit r17-2926-ga49c114c7b3edd33a6ff2e50e6276ca1fbe8ad83
Author: Jakub Jelinek <[email protected]>
Date:   Tue Aug 4 10:37:09 2026 +0200

    widening_mul: Fix up ICE in maybe_optimize_guarding_check [PR126601]

    The following testcase ICEs, because we try to quick_push into an alrea=
dy
    full vector.
    The caller (match_arith_overflow) has
      auto_vec<gimple *, 8> mul_stmts;
    and 0-6 mul_stmts.quick_push (...); calls (none of that in a loop), and
then
    call to that maybe_optimize_guarding_check function which does one
    quick_push, but the function is called in a
      FOR_EACH_IMM_USE_STMT (use_stmt, iter, cast_lhs ? cast_lhs : lhs)
    loop, so if we are unlucky  as on the attached testcase, it is called m=
ore
    than twice and either triggers ICE, or worse with checking disabled buf=
fer
    overflow.

    The following patch fixes that by using safe_push in that spot instead.

    2026-08-04  Jakub Jelinek  <[email protected]>

            PR tree-optimization/126601
            * tree-ssa-math-opts.cc (maybe_optimize_guarding_check): Use
safe_push
            on mul_stmts rather than quick_push.

            * gcc.dg/tree-ssa/pr126601.c: New test.

    Reviewed-by: Richard Biener <[email protected]>=