https://gcc.gnu.org/bugzilla/show_bug.cgi?id=127606
--- Comment #7 from Uroš Bizjak <ubizjak at gmail dot com> --- (In reply to Richard Biener from comment #5) > 6. When reloading the operands: > - For insn 218, LRA reloaded operand 0 using zero-extension (movzbl > 4(%rsp), %esi), zeroing bits 8..31. > - For insn 219, LRA simplified the memory subreg into a 32-bit SImode > load > directly from 4(%rsp) (xor 4(%rsp), %edx). > 7. This read 3 bytes of uninitialized stack memory into bits 8..31 of aq, > which propagated through cq and cm to cause the uninitialized memory > errors reported by Valgrind. IMO, this should be fixed in LRA. LRA should reload operands in both cases as QImode read to a temporary register that is later used in SImode. Please note that "movzbl 4(%rsp), %esi" is in fact *movqi_internal/4" and is regarded as plain QImode move. So, movzbl is not there in the role of zero-extend, but just as a plain QImode move due to an implementation detail of x86. The problematic insn is "xor 4(%rsp), %edx". LRA should *not* simplify paradoxical memory subreg to a load in a wide mode. It should reload the value to a temporary QImode register in a narrow mode and use temporary register as SImode register in XOR. So, this exposes LRA issue. Any other fix will paper over it.
