Thanks for participating in the TVM community! We use https://discuss.tvm.apache.org/ for any general usage questions and discussions. The issue tracker is used for actionable items such as feature proposals discussion, roadmaps, and bug tracking. You are always welcomed to post on the forum first 😸
Issues that are inactive for a period of time may get closed. We adopt this policy so that we won't lose track of actionable issues that may fall at the bottom of the pile. Feel free to reopen a new one if you feel there is an additional problem that needs attention when an old one gets closed.
Expected behavior
relax.floor_divide (and relax.divide) on integer tensors should have a defined behavior for a zero divisor — either a documented result, or a TVM error raised at execution time.
What it should not do is kill the host process: a single zero element in the input makes the compiled module un-runnable, and there is no way for the caller to catch it or recover.
Actual behavior
The integer // is lowered to LLVM sdiv.
On x86-64, sdiv raises #DE, which the kernel delivers as SIGFPE, terminating the process:
=== 1. parse ===
parse OK
=== 2. build ===
build OK
=== 3. run with y != 0 (expect fine) ===
output[0][:5]: [4 3 2 4 0]
=== 4. run with y containing 0 (the fuzzer-generated input) ===
y has zeros: True
about to execute integer division by zero ...
Floating point exception (core dumped)
The shell reports exit status 136 / SIGFPE.
There is no TVM error and no Python exception — the interpreter process is terminated.
Note that this is a different failure from the companion non-float DivNode report. Both involve division not being handled defensively, but this issue is a runtime trap inside CreateSDiv, rather than a compile-time internal check.
Environment
-
TVM version: 0.26.dev0
-
Commit: 8312a17f8734ddfd56e5f3977cd5df25b83ec49f
[REFACTOR][Arith] Evaluate iterator domains through Var maps (#20354)
2026-09-15
-
OS: Ubuntu 20.04.6 LTS
-
Kernel: 5.15.0-139-generic
-
Compiler: GCC 13.1.0
-
Target: llvm (host)
-
CPU: Intel Xeon Gold 6326
-
Build: Standard CMake build with USE_LLVM=ON
Steps to reproduce
import numpy as np
import tvm
from tvm import relax
from tvm.script import ir as I
from tvm.script import tirx as T
from tvm.script import relax as R
@I.ir_module
class Module:
# ---- integer path (x // y) ----------------------------------------------
@T.prim_func(private=True, s_tir=True)
def floor_divide(
x: T.Buffer((T.int64(27), T.int64(61)), "int64"),
y: T.Buffer((T.int64(27), T.int64(61)), "int64"),
T_floor_divide: T.Buffer((T.int64(27), T.int64(61)), "int64"),
):
T.func_attr({"tir.noalias": T.bool(True)})
for ax0, ax1 in T.grid(T.int64(27), T.int64(61)):
with T.sblock("T_floor_divide"):
v_ax0, v_ax1 = T.axis.remap("SS", [ax0, ax1])
T.reads(x[v_ax0, v_ax1], y[v_ax0, v_ax1])
T.writes(T_floor_divide[v_ax0, v_ax1])
T_floor_divide[v_ax0, v_ax1] = (
x[v_ax0, v_ax1] // y[v_ax0, v_ax1]
)
@R.function
def main(
x: R.Tensor((27, 61), dtype="int64"),
y: R.Tensor((27, 61), dtype="int64"),
) -> R.Tensor((27, 61), dtype="int64"):
R.func_attr({"num_input": 1})
cls = Module
with R.dataflow():
gv_1 = R.call_tir(
cls.floor_divide,
(x, y),
out_ty=R.Tensor((27, 61), dtype="int64"),
)
R.output(gv_1)
return gv_1
print("=== 1. parse ===")
mod = Module
print("parse OK")
print("\n=== 2. build ===")
with tvm.transform.PassContext(disabled_pass=["RemoveUnusedParameters"]):
mod = relax.transform.FuseTIR()(mod)
mod = relax.transform.LegalizeOps()(mod)
mod = relax.transform.LambdaLift()(mod)
with tvm.transform.PassContext(opt_level=4):
ex = relax.build(mod, target="llvm")
vm = relax.VirtualMachine(ex, tvm.cpu())
print("build OK")
x = tvm.runtime.tensor(
np.random.randint(10, size=(27, 61)).astype("int64")
)
y = tvm.runtime.tensor(
np.random.randint(10, size=(27, 61)).astype("int64")
)
print("\n=== 3. run with y != 0 (expect fine) ===")
y_safe = tvm.runtime.tensor(
np.ones((27, 61), dtype="int64") * 2
)
out = vm["main"](x, y_safe)
print("output[0][:5]:", out.numpy()[0][:5])
print("\n=== 4. run with y containing 0 (the fuzzer-generated input) ===")
print("y has zeros:", bool((y.numpy() == 0).any()), flush=True)
print("about to execute integer division by zero ...", flush=True)
out = vm["main"](x, y) # <-- SIGFPE
print("output[0][:5]:", out.numpy()[0][:5])
Triage
needs-triage
Bug
target: llvm
Please follow this repository's security policy and code of conduct.
Thanks for participating in the TVM community! We use https://discuss.tvm.apache.org/ for any general usage questions and discussions. The issue tracker is used for actionable items such as feature proposals discussion, roadmaps, and bug tracking. You are always welcomed to post on the forum first 😸
Issues that are inactive for a period of time may get closed. We adopt this policy so that we won't lose track of actionable issues that may fall at the bottom of the pile. Feel free to reopen a new one if you feel there is an additional problem that needs attention when an old one gets closed.
Expected behavior
relax.floor_divide(andrelax.divide) on integer tensors should have a defined behavior for a zero divisor — either a documented result, or a TVM error raised at execution time.What it should not do is kill the host process: a single zero element in the input makes the compiled module un-runnable, and there is no way for the caller to catch it or recover.
Actual behavior
The integer
//is lowered to LLVMsdiv.On x86-64,
sdivraises#DE, which the kernel delivers asSIGFPE, terminating the process:The shell reports exit status
136/SIGFPE.There is no TVM error and no Python exception — the interpreter process is terminated.
Note that this is a different failure from the companion non-float
DivNodereport. Both involve division not being handled defensively, but this issue is a runtime trap insideCreateSDiv, rather than a compile-time internal check.Environment
TVM version:
0.26.dev0Commit:
8312a17f8734ddfd56e5f3977cd5df25b83ec49f[REFACTOR][Arith] Evaluate iterator domains through Var maps (#20354)2026-09-15OS: Ubuntu
20.04.6 LTSKernel:
5.15.0-139-genericCompiler: GCC
13.1.0Target:
llvm(host)CPU: Intel Xeon Gold 6326
Build: Standard CMake build with
USE_LLVM=ONSteps to reproduce
Triage
needs-triageBugtarget: llvmPlease follow this repository's security policy and code of conduct.