``` $ cat a.ll define i1 @f(i8* %a, i8* %b) { %cond1 = icmp ne i8* %a, %b %a2 = getelementptr inbounds i8, i8* %a, i64 -1 %cond2 = icmp ugt i8* %a2, %b %res = select i1 %cond1, i1 %cond2, i1 false ret i1 %res } $ opt -instsimplify ./a.ll -S -o - define i1 @f(i8* %a, i8* %b) { %a2 = getelementptr inbounds i8, i8* %a, i64 -1 %cond2 = icmp ugt i8* %a2, %b ret i1 %cond2 } ``` This is incorrect: if a = b = null, %res before opt is false whereas the output after opt is poison. https://alive2.llvm.org/ce/z/SDy_PX The reason is that SimplifyWithOpReplaced calls SimplifyCmpInst which folds `(gep inbounds a, -1) >u a` to `false` even if AllowRefinement is false. A solution that I came up with is to add 'AllowRefinement' field to SimplifyQuery as well and let SimplifyICmpInst() stop this folding if the flag is set, but I found that SimplifyQuery is used in many places other than InstructionSimplify. Would it be still a reasonable solution though?
A suggested fix: https://reviews.llvm.org/D98391
Fixed via https://reviews.llvm.org/D99027 , https://reviews.llvm.org/rG7e18cd887cd402e3d5465c57c218079e4df65231