Conversation
The LinalgAlignRewriter::drainWorklist logging callbacks print the matched operation's name via op->getName(). The memcpy and reduction rewrite patterns erase their root operation before returning success, so the success callback dereferences freed memory and crashes with an access violation (0xC0000005) inside OperationName::Impl::getName when the pass runs with -debug-only=rock-linalg-align. Snapshot the OperationName before applying the pattern and print from the copy; OperationName does not reference the erased operation's storage. Adds a regression test that erases a memref.copy through the align pass with debug logging enabled. Originally hit via MIGraphX (migraphx_gpu.dll) compiling an ONNX model with ROCMLIR_DEBUG_FLAGS=--debug-only=rock-linalg-align, then minimized to a single rock.fill / threadwise_write_all / memref.copy function. Signed-off-by: kazhang2 <kazhang2@amd.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The LinalgAlignRewriter::drainWorklist logging callbacks print the matched operation's name via op->getName(). The MemcpyRewritePattern::matchAndRewrite erase their root operation before returning success, so the success callback dereferences freed memory and crashes with an access violation (0xC0000005) inside OperationName::Impl::getName when the pass runs with -debug-only=rock-linalg-align.
Technical Details
The three logging callbacks passed to
PatternApplicator::matchAndRewrite(canApply,onFailure,onSuccess) print the matched operation viaop->getName(). The memcpy and reduction rewrite patterns erase their root operation (eraseOp) in MemcpyRewritePattern::matchAndRewriterocMLIR/mlir/lib/Dialect/Rock/Transforms/AlignTiling.cpp
Lines 1114 to 1116 in 0ceaf1c
onSuccessthen runs and callsop->getName(), it reads freed memory. This is only reachable in#ifndef NDEBUGbuilds with the debug flag set; without the flag the buggy logging never executes and the pass works correctly, which is why it went unnoticed.Observed in practice when MIGraphX (
migraphx_gpu.dll) compiles an ONNX model withROCMLIR_DEBUG_FLAGS=--debug-only=rock-linalg-align: the process dies mid-log-line atMatched ... MemcpyRewritePattern pattern on ..., right after** Erase : "memref.copy".Test Plan
reproduce step
run in powershell
@'
module {
func.func @repro(%output: memref<1xf32>) attributes {rock.kernel} {
%zero = arith.constant 0.0 : f32
%regs = rock.alloc() : memref<1xf32, #gpu.address_space>
rock.fill(%regs, %zero) : memref<1xf32, #gpu.address_space>, f32
%tmp = memref.alloc() : memref<1xf32>
rock.threadwise_write_all {forceUnroll, useIndexDiffs}
%regs -> by set
: memref<1xf32, #gpu.address_space> -> memref<1xf32>
memref.copy %tmp, %output : memref<1xf32> to memref<1xf32>
return
}
}
'@ | & .\build\bin\rocmlir-opt.exe --rock-linalg-align --debug-only=rock-linalg-align
Test Result
rocmlir-opt.exe --rock-linalg-align --debug-only=rock-linalg-align
pass
Submission Checklist