1=====================
2LLVM Coding Standards
3=====================
4
5.. contents::
6   :local:
7
8Introduction
9============
10
11This document attempts to describe a few coding standards that are being used in
12the LLVM source tree.  Although no coding standards should be regarded as
13absolute requirements to be followed in all instances, coding standards are
14particularly important for large-scale code bases that follow a library-based
15design (like LLVM).
16
17While this document may provide guidance for some mechanical formatting issues,
18whitespace, or other "microscopic details", these are not fixed standards.
19Always follow the golden rule:
20
21.. _Golden Rule:
22
23    **If you are extending, enhancing, or bug fixing already implemented code,
24    use the style that is already being used so that the source is uniform and
25    easy to follow.**
26
27Note that some code bases (e.g. ``libc++``) have really good reasons to deviate
28from the coding standards.  In the case of ``libc++``, this is because the
29naming and other conventions are dictated by the C++ standard.  If you think
30there is a specific good reason to deviate from the standards here, please bring
31it up on the LLVM-dev mailing list.
32
33There are some conventions that are not uniformly followed in the code base
34(e.g. the naming convention).  This is because they are relatively new, and a
35lot of code was written before they were put in place.  Our long term goal is
36for the entire codebase to follow the convention, but we explicitly *do not*
37want patches that do large-scale reformatting of existing code.  On the other
38hand, it is reasonable to rename the methods of a class if you're about to
39change it in some other way.  Just do the reformatting as a separate commit
40from the functionality change.
41
42The ultimate goal of these guidelines is to increase the readability and
43maintainability of our common source base.
44
45Languages, Libraries, and Standards
46===================================
47
48Most source code in LLVM and other LLVM projects using these coding standards
49is C++ code. There are some places where C code is used either due to
50environment restrictions, historical restrictions, or due to third-party source
51code imported into the tree. Generally, our preference is for standards
52conforming, modern, and portable C++ code as the implementation language of
53choice.
54
55C++ Standard Versions
56---------------------
57
58LLVM, Clang, and LLD are currently written using C++14 conforming code,
59although we restrict ourselves to features which are available in the major
60toolchains supported as host compilers. The LLDB project is even more
61aggressive in the set of host compilers supported and thus uses still more
62features. Regardless of the supported features, code is expected to (when
63reasonable) be standard, portable, and modern C++14 code. We avoid unnecessary
64vendor-specific extensions, etc.
65
66C++ Standard Library
67--------------------
68
69Use the C++ standard library facilities whenever they are available for
70a particular task. LLVM and related projects emphasize and rely on the standard
71library facilities for as much as possible. Common support libraries providing
72functionality missing from the standard library for which there are standard
73interfaces or active work on adding standard interfaces will often be
74implemented in the LLVM namespace following the expected standard interface.
75
76There are some exceptions such as the standard I/O streams library which are
77avoided. Also, there is much more detailed information on these subjects in the
78:doc:`ProgrammersManual`.
79
80Supported C++14 Language and Library Features
81---------------------------------------------
82
83While LLVM, Clang, and LLD use C++14, not all features are available in all of
84the toolchains which we support. The set of features supported for use in LLVM
85is the intersection of those supported in the minimum requirements described
86in the :doc:`GettingStarted` page, section `Software`.
87The ultimate definition of this set is what build bots with those respective
88toolchains accept. Don't argue with the build bots. However, we have some
89guidance below to help you know what to expect.
90
91Each toolchain provides a good reference for what it accepts:
92
93* Clang: https://clang.llvm.org/cxx_status.html
94* GCC: https://gcc.gnu.org/projects/cxx-status.html#cxx14
95* MSVC: https://msdn.microsoft.com/en-us/library/hh567368.aspx
96
97Other Languages
98---------------
99
100Any code written in the Go programming language is not subject to the
101formatting rules below. Instead, we adopt the formatting rules enforced by
102the `gofmt`_ tool.
103
104Go code should strive to be idiomatic. Two good sets of guidelines for what
105this means are `Effective Go`_ and `Go Code Review Comments`_.
106
107.. _gofmt:
108  https://golang.org/cmd/gofmt/
109
110.. _Effective Go:
111  https://golang.org/doc/effective_go.html
112
113.. _Go Code Review Comments:
114  https://github.com/golang/go/wiki/CodeReviewComments
115
116Mechanical Source Issues
117========================
118
119Source Code Formatting
120----------------------
121
122Commenting
123^^^^^^^^^^
124
125Comments are one critical part of readability and maintainability.  Everyone
126knows they should comment their code, and so should you.  When writing comments,
127write them as English prose, which means they should use proper capitalization,
128punctuation, etc.  Aim to describe what the code is trying to do and why, not
129*how* it does it at a micro level. Here are a few critical things to document:
130
131.. _header file comment:
132
133File Headers
134""""""""""""
135
136Every source file should have a header on it that describes the basic purpose of
137the file.  If a file does not have a header, it should not be checked into the
138tree.  The standard header looks like this:
139
140.. code-block:: c++
141
142  //===-- llvm/Instruction.h - Instruction class definition -------*- C++ -*-===//
143  //
144  // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
145  // See https://llvm.org/LICENSE.txt for license information.
146  // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
147  //
148  //===----------------------------------------------------------------------===//
149  ///
150  /// \file
151  /// This file contains the declaration of the Instruction class, which is the
152  /// base class for all of the VM instructions.
153  ///
154  //===----------------------------------------------------------------------===//
155
156A few things to note about this particular format: The "``-*- C++ -*-``" string
157on the first line is there to tell Emacs that the source file is a C++ file, not
158a C file (Emacs assumes ``.h`` files are C files by default).
159
160.. note::
161
162    This tag is not necessary in ``.cpp`` files.  The name of the file is also
163    on the first line, along with a very short description of the purpose of the
164    file.  This is important when printing out code and flipping though lots of
165    pages.
166
167The next section in the file is a concise note that defines the license that the
168file is released under.  This makes it perfectly clear what terms the source
169code can be distributed under and should not be modified in any way.
170
171The main body is a ``doxygen`` comment (identified by the ``///`` comment
172marker instead of the usual ``//``) describing the purpose of the file.  The
173first sentence (or a passage beginning with ``\brief``) is used as an abstract.
174Any additional information should be separated by a blank line.  If an
175algorithm is being implemented or something tricky is going on, a reference
176to the paper where it is published should be included, as well as any notes or
177*gotchas* in the code to watch out for.
178
179Class overviews
180"""""""""""""""
181
182Classes are one fundamental part of a good object oriented design.  As such, a
183class definition should have a comment block that explains what the class is
184used for and how it works.  Every non-trivial class is expected to have a
185``doxygen`` comment block.
186
187Method information
188""""""""""""""""""
189
190Methods defined in a class (as well as any global functions) should also be
191documented properly.  A quick note about what it does and a description of the
192borderline behaviour is all that is necessary here (unless something
193particularly tricky or insidious is going on).  The hope is that people can
194figure out how to use your interfaces without reading the code itself.
195
196Good things to talk about here are what happens when something unexpected
197happens: does the method return null?  Abort?  Format your hard disk?
198
199Comment Formatting
200^^^^^^^^^^^^^^^^^^
201
202In general, prefer C++ style comments (``//`` for normal comments, ``///`` for
203``doxygen`` documentation comments).  They take less space, require
204less typing, don't have nesting problems, etc.  There are a few cases when it is
205useful to use C style (``/* */``) comments however:
206
207#. When writing C code: Obviously if you are writing C code, use C style
208   comments.
209
210#. When writing a header file that may be ``#include``\d by a C source file.
211
212#. When writing a source file that is used by a tool that only accepts C style
213   comments.
214
215#. When documenting the significance of constants used as actual parameters in
216   a call. This is most helpful for ``bool`` parameters, or passing ``0`` or
217   ``nullptr``. Typically you add the formal parameter name, which ought to be
218   meaningful. For example, it's not clear what the parameter means in this call:
219
220   .. code-block:: c++
221
222     Object.emitName(nullptr);
223
224   An in-line C-style comment makes the intent obvious:
225
226   .. code-block:: c++
227
228     Object.emitName(/*Prefix=*/nullptr);
229
230Commenting out large blocks of code is discouraged, but if you really have to do
231this (for documentation purposes or as a suggestion for debug printing), use
232``#if 0`` and ``#endif``. These nest properly and are better behaved in general
233than C style comments.
234
235Doxygen Use in Documentation Comments
236^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
237
238Use the ``\file`` command to turn the standard file header into a file-level
239comment.
240
241Include descriptive paragraphs for all public interfaces (public classes,
242member and non-member functions).  Don't just restate the information that can
243be inferred from the API name.  The first sentence (or a paragraph beginning
244with ``\brief``) is used as an abstract. Try to use a single sentence as the
245``\brief`` adds visual clutter.  Put detailed discussion into separate
246paragraphs.
247
248To refer to parameter names inside a paragraph, use the ``\p name`` command.
249Don't use the ``\arg name`` command since it starts a new paragraph that
250contains documentation for the parameter.
251
252Wrap non-inline code examples in ``\code ... \endcode``.
253
254To document a function parameter, start a new paragraph with the
255``\param name`` command.  If the parameter is used as an out or an in/out
256parameter, use the ``\param [out] name`` or ``\param [in,out] name`` command,
257respectively.
258
259To describe function return value, start a new paragraph with the ``\returns``
260command.
261
262A minimal documentation comment:
263
264.. code-block:: c++
265
266  /// Sets the xyzzy property to \p Baz.
267  void setXyzzy(bool Baz);
268
269A documentation comment that uses all Doxygen features in a preferred way:
270
271.. code-block:: c++
272
273  /// Does foo and bar.
274  ///
275  /// Does not do foo the usual way if \p Baz is true.
276  ///
277  /// Typical usage:
278  /// \code
279  ///   fooBar(false, "quux", Res);
280  /// \endcode
281  ///
282  /// \param Quux kind of foo to do.
283  /// \param [out] Result filled with bar sequence on foo success.
284  ///
285  /// \returns true on success.
286  bool fooBar(bool Baz, StringRef Quux, std::vector<int> &Result);
287
288Don't duplicate the documentation comment in the header file and in the
289implementation file.  Put the documentation comments for public APIs into the
290header file.  Documentation comments for private APIs can go to the
291implementation file.  In any case, implementation files can include additional
292comments (not necessarily in Doxygen markup) to explain implementation details
293as needed.
294
295Don't duplicate function or class name at the beginning of the comment.
296For humans it is obvious which function or class is being documented;
297automatic documentation processing tools are smart enough to bind the comment
298to the correct declaration.
299
300Wrong:
301
302.. code-block:: c++
303
304  // In Something.h:
305
306  /// Something - An abstraction for some complicated thing.
307  class Something {
308  public:
309    /// fooBar - Does foo and bar.
310    void fooBar();
311  };
312
313  // In Something.cpp:
314
315  /// fooBar - Does foo and bar.
316  void Something::fooBar() { ... }
317
318Correct:
319
320.. code-block:: c++
321
322  // In Something.h:
323
324  /// An abstraction for some complicated thing.
325  class Something {
326  public:
327    /// Does foo and bar.
328    void fooBar();
329  };
330
331  // In Something.cpp:
332
333  // Builds a B-tree in order to do foo.  See paper by...
334  void Something::fooBar() { ... }
335
336It is not required to use additional Doxygen features, but sometimes it might
337be a good idea to do so.
338
339Consider:
340
341* adding comments to any narrow namespace containing a collection of
342  related functions or types;
343
344* using top-level groups to organize a collection of related functions at
345  namespace scope where the grouping is smaller than the namespace;
346
347* using member groups and additional comments attached to member
348  groups to organize within a class.
349
350For example:
351
352.. code-block:: c++
353
354  class Something {
355    /// \name Functions that do Foo.
356    /// @{
357    void fooBar();
358    void fooBaz();
359    /// @}
360    ...
361  };
362
363``#include`` Style
364^^^^^^^^^^^^^^^^^^
365
366Immediately after the `header file comment`_ (and include guards if working on a
367header file), the `minimal list of #includes`_ required by the file should be
368listed.  We prefer these ``#include``\s to be listed in this order:
369
370.. _Main Module Header:
371.. _Local/Private Headers:
372
373#. Main Module Header
374#. Local/Private Headers
375#. LLVM project/subproject headers (``clang/...``, ``lldb/...``, ``llvm/...``, etc)
376#. System ``#include``\s
377
378and each category should be sorted lexicographically by the full path.
379
380The `Main Module Header`_ file applies to ``.cpp`` files which implement an
381interface defined by a ``.h`` file.  This ``#include`` should always be included
382**first** regardless of where it lives on the file system.  By including a
383header file first in the ``.cpp`` files that implement the interfaces, we ensure
384that the header does not have any hidden dependencies which are not explicitly
385``#include``\d in the header, but should be. It is also a form of documentation
386in the ``.cpp`` file to indicate where the interfaces it implements are defined.
387
388LLVM project and subproject headers should be grouped from most specific to least
389specific, for the same reasons described above.  For example, LLDB depends on
390both clang and LLVM, and clang depends on LLVM.  So an LLDB source file should
391include ``lldb`` headers first, followed by ``clang`` headers, followed by
392``llvm`` headers, to reduce the possibility (for example) of an LLDB header
393accidentally picking up a missing include due to the previous inclusion of that
394header in the main source file or some earlier header file.  clang should
395similarly include its own headers before including llvm headers.  This rule
396applies to all LLVM subprojects.
397
398.. _fit into 80 columns:
399
400Source Code Width
401^^^^^^^^^^^^^^^^^
402
403Write your code to fit within 80 columns of text.  This helps those of us who
404like to print out code and look at your code in an ``xterm`` without resizing
405it.
406
407The longer answer is that there must be some limit to the width of the code in
408order to reasonably allow developers to have multiple files side-by-side in
409windows on a modest display.  If you are going to pick a width limit, it is
410somewhat arbitrary but you might as well pick something standard.  Going with 90
411columns (for example) instead of 80 columns wouldn't add any significant value
412and would be detrimental to printing out code.  Also many other projects have
413standardized on 80 columns, so some people have already configured their editors
414for it (vs something else, like 90 columns).
415
416This is one of many contentious issues in coding standards, but it is not up for
417debate.
418
419Whitespace
420^^^^^^^^^^
421
422In all cases, prefer spaces to tabs in source files.  People have different
423preferred indentation levels, and different styles of indentation that they
424like; this is fine.  What isn't fine is that different editors/viewers expand
425tabs out to different tab stops.  This can cause your code to look completely
426unreadable, and it is not worth dealing with.
427
428As always, follow the `Golden Rule`_ above: follow the style of
429existing code if you are modifying and extending it.  If you like four spaces of
430indentation, **DO NOT** do that in the middle of a chunk of code with two spaces
431of indentation.  Also, do not reindent a whole source file: it makes for
432incredible diffs that are absolutely worthless.
433
434Do not commit changes that include trailing whitespace. If you find trailing
435whitespace in a file, do not remove it unless you're otherwise changing that
436line of code. Some common editors will automatically remove trailing whitespace
437when saving a file which causes unrelated changes to appear in diffs and
438commits.
439
440Indent Code Consistently
441^^^^^^^^^^^^^^^^^^^^^^^^
442
443Okay, in your first year of programming you were told that indentation is
444important. If you didn't believe and internalize this then, now is the time.
445Just do it. With the introduction of C++11, there are some new formatting
446challenges that merit some suggestions to help have consistent, maintainable,
447and tool-friendly formatting and indentation.
448
449Format Lambdas Like Blocks Of Code
450""""""""""""""""""""""""""""""""""
451
452When formatting a multi-line lambda, format it like a block of code, that's
453what it is. If there is only one multi-line lambda in a statement, and there
454are no expressions lexically after it in the statement, drop the indent to the
455standard two space indent for a block of code, as if it were an if-block opened
456by the preceding part of the statement:
457
458.. code-block:: c++
459
460  std::sort(foo.begin(), foo.end(), [&](Foo a, Foo b) -> bool {
461    if (a.blah < b.blah)
462      return true;
463    if (a.baz < b.baz)
464      return true;
465    return a.bam < b.bam;
466  });
467
468To take best advantage of this formatting, if you are designing an API which
469accepts a continuation or single callable argument (be it a functor, or
470a ``std::function``), it should be the last argument if at all possible.
471
472If there are multiple multi-line lambdas in a statement, or there is anything
473interesting after the lambda in the statement, indent the block two spaces from
474the indent of the ``[]``:
475
476.. code-block:: c++
477
478  dyn_switch(V->stripPointerCasts(),
479             [] (PHINode *PN) {
480               // process phis...
481             },
482             [] (SelectInst *SI) {
483               // process selects...
484             },
485             [] (LoadInst *LI) {
486               // process loads...
487             },
488             [] (AllocaInst *AI) {
489               // process allocas...
490             });
491
492Braced Initializer Lists
493""""""""""""""""""""""""
494
495With C++11, there are significantly more uses of braced lists to perform
496initialization. These allow you to easily construct aggregate temporaries in
497expressions among other niceness. They now have a natural way of ending up
498nested within each other and within function calls in order to build up
499aggregates (such as option structs) from local variables. To make matters
500worse, we also have many more uses of braces in an expression context that are
501*not* performing initialization.
502
503The historically common formatting of braced initialization of aggregate
504variables does not mix cleanly with deep nesting, general expression contexts,
505function arguments, and lambdas. We suggest new code use a simple rule for
506formatting braced initialization lists: act as-if the braces were parentheses
507in a function call. The formatting rules exactly match those already well
508understood for formatting nested function calls. Examples:
509
510.. code-block:: c++
511
512  foo({a, b, c}, {1, 2, 3});
513
514  llvm::Constant *Mask[] = {
515      llvm::ConstantInt::get(llvm::Type::getInt32Ty(getLLVMContext()), 0),
516      llvm::ConstantInt::get(llvm::Type::getInt32Ty(getLLVMContext()), 1),
517      llvm::ConstantInt::get(llvm::Type::getInt32Ty(getLLVMContext()), 2)};
518
519This formatting scheme also makes it particularly easy to get predictable,
520consistent, and automatic formatting with tools like `Clang Format`_.
521
522.. _Clang Format: https://clang.llvm.org/docs/ClangFormat.html
523
524Language and Compiler Issues
525----------------------------
526
527Treat Compiler Warnings Like Errors
528^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
529
530If your code has compiler warnings in it, something is wrong --- you aren't
531casting values correctly, you have "questionable" constructs in your code, or
532you are doing something legitimately wrong.  Compiler warnings can cover up
533legitimate errors in output and make dealing with a translation unit difficult.
534
535It is not possible to prevent all warnings from all compilers, nor is it
536desirable.  Instead, pick a standard compiler (like ``gcc``) that provides a
537good thorough set of warnings, and stick to it.  At least in the case of
538``gcc``, it is possible to work around any spurious errors by changing the
539syntax of the code slightly.  For example, a warning that annoys me occurs when
540I write code like this:
541
542.. code-block:: c++
543
544  if (V = getValue()) {
545    ...
546  }
547
548``gcc`` will warn me that I probably want to use the ``==`` operator, and that I
549probably mistyped it.  In most cases, I haven't, and I really don't want the
550spurious errors.  To fix this particular problem, I rewrite the code like
551this:
552
553.. code-block:: c++
554
555  if ((V = getValue())) {
556    ...
557  }
558
559which shuts ``gcc`` up.  Any ``gcc`` warning that annoys you can be fixed by
560massaging the code appropriately.
561
562Write Portable Code
563^^^^^^^^^^^^^^^^^^^
564
565In almost all cases, it is possible and within reason to write completely
566portable code.  If there are cases where it isn't possible to write portable
567code, isolate it behind a well defined (and well documented) interface.
568
569In practice, this means that you shouldn't assume much about the host compiler
570(and Visual Studio tends to be the lowest common denominator).  If advanced
571features are used, they should only be an implementation detail of a library
572which has a simple exposed API, and preferably be buried in ``libSystem``.
573
574Do not use RTTI or Exceptions
575^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
576
577In an effort to reduce code and executable size, LLVM does not use RTTI
578(e.g. ``dynamic_cast<>;``) or exceptions.  These two language features violate
579the general C++ principle of *"you only pay for what you use"*, causing
580executable bloat even if exceptions are never used in the code base, or if RTTI
581is never used for a class.  Because of this, we turn them off globally in the
582code.
583
584That said, LLVM does make extensive use of a hand-rolled form of RTTI that use
585templates like :ref:`isa\<>, cast\<>, and dyn_cast\<> <isa>`.
586This form of RTTI is opt-in and can be
587:doc:`added to any class <HowToSetUpLLVMStyleRTTI>`. It is also
588substantially more efficient than ``dynamic_cast<>``.
589
590.. _static constructor:
591
592Do not use Static Constructors
593^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
594
595Static constructors and destructors (e.g. global variables whose types have a
596constructor or destructor) should not be added to the code base, and should be
597removed wherever possible.  Besides `well known problems
598<https://yosefk.com/c++fqa/ctors.html#fqa-10.12>`_ where the order of
599initialization is undefined between globals in different source files, the
600entire concept of static constructors is at odds with the common use case of
601LLVM as a library linked into a larger application.
602
603Consider the use of LLVM as a JIT linked into another application (perhaps for
604`OpenGL, custom languages <https://llvm.org/Users.html>`_, `shaders in movies
605<https://llvm.org/devmtg/2010-11/Gritz-OpenShadingLang.pdf>`_, etc). Due to the
606design of static constructors, they must be executed at startup time of the
607entire application, regardless of whether or how LLVM is used in that larger
608application.  There are two problems with this:
609
610* The time to run the static constructors impacts startup time of applications
611  --- a critical time for GUI apps, among others.
612
613* The static constructors cause the app to pull many extra pages of memory off
614  the disk: both the code for the constructor in each ``.o`` file and the small
615  amount of data that gets touched. In addition, touched/dirty pages put more
616  pressure on the VM system on low-memory machines.
617
618We would really like for there to be zero cost for linking in an additional LLVM
619target or other library into an application, but static constructors violate
620this goal.
621
622That said, LLVM unfortunately does contain static constructors.  It would be a
623`great project <https://llvm.org/PR11944>`_ for someone to purge all static
624constructors from LLVM, and then enable the ``-Wglobal-constructors`` warning
625flag (when building with Clang) to ensure we do not regress in the future.
626
627Use of ``class`` and ``struct`` Keywords
628^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
629
630In C++, the ``class`` and ``struct`` keywords can be used almost
631interchangeably. The only difference is when they are used to declare a class:
632``class`` makes all members private by default while ``struct`` makes all
633members public by default.
634
635Unfortunately, not all compilers follow the rules and some will generate
636different symbols based on whether ``class`` or ``struct`` was used to declare
637the symbol (e.g., MSVC).  This can lead to problems at link time.
638
639* All declarations and definitions of a given ``class`` or ``struct`` must use
640  the same keyword.  For example:
641
642.. code-block:: c++
643
644  class Foo;
645
646  // Breaks mangling in MSVC.
647  struct Foo { int Data; };
648
649* As a rule of thumb, ``struct`` should be kept to structures where *all*
650  members are declared public.
651
652.. code-block:: c++
653
654  // Foo feels like a class... this is strange.
655  struct Foo {
656  private:
657    int Data;
658  public:
659    Foo() : Data(0) { }
660    int getData() const { return Data; }
661    void setData(int D) { Data = D; }
662  };
663
664  // Bar isn't POD, but it does look like a struct.
665  struct Bar {
666    int Data;
667    Bar() : Data(0) { }
668  };
669
670Do not use Braced Initializer Lists to Call a Constructor
671^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
672
673In C++11 there is a "generalized initialization syntax" which allows calling
674constructors using braced initializer lists. Do not use these to call
675constructors with any interesting logic or if you care that you're calling some
676*particular* constructor. Those should look like function calls using
677parentheses rather than like aggregate initialization. Similarly, if you need
678to explicitly name the type and call its constructor to create a temporary,
679don't use a braced initializer list. Instead, use a braced initializer list
680(without any type for temporaries) when doing aggregate initialization or
681something notionally equivalent. Examples:
682
683.. code-block:: c++
684
685  class Foo {
686  public:
687    // Construct a Foo by reading data from the disk in the whizbang format, ...
688    Foo(std::string filename);
689
690    // Construct a Foo by looking up the Nth element of some global data ...
691    Foo(int N);
692
693    // ...
694  };
695
696  // The Foo constructor call is very deliberate, no braces.
697  std::fill(foo.begin(), foo.end(), Foo("name"));
698
699  // The pair is just being constructed like an aggregate, use braces.
700  bar_map.insert({my_key, my_value});
701
702If you use a braced initializer list when initializing a variable, use an equals before the open curly brace:
703
704.. code-block:: c++
705
706  int data[] = {0, 1, 2, 3};
707
708Use ``auto`` Type Deduction to Make Code More Readable
709^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
710
711Some are advocating a policy of "almost always ``auto``" in C++11, however LLVM
712uses a more moderate stance. Use ``auto`` if and only if it makes the code more
713readable or easier to maintain. Don't "almost always" use ``auto``, but do use
714``auto`` with initializers like ``cast<Foo>(...)`` or other places where the
715type is already obvious from the context. Another time when ``auto`` works well
716for these purposes is when the type would have been abstracted away anyways,
717often behind a container's typedef such as ``std::vector<T>::iterator``.
718
719Similarly, C++14 adds generic lambda expressions where parameter types can be
720``auto``. Use these where you would have used a template.
721
722Beware unnecessary copies with ``auto``
723^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
724
725The convenience of ``auto`` makes it easy to forget that its default behavior
726is a copy.  Particularly in range-based ``for`` loops, careless copies are
727expensive.
728
729As a rule of thumb, use ``auto &`` unless you need to copy the result, and use
730``auto *`` when copying pointers.
731
732.. code-block:: c++
733
734  // Typically there's no reason to copy.
735  for (const auto &Val : Container) { observe(Val); }
736  for (auto &Val : Container) { Val.change(); }
737
738  // Remove the reference if you really want a new copy.
739  for (auto Val : Container) { Val.change(); saveSomewhere(Val); }
740
741  // Copy pointers, but make it clear that they're pointers.
742  for (const auto *Ptr : Container) { observe(*Ptr); }
743  for (auto *Ptr : Container) { Ptr->change(); }
744
745Beware of non-determinism due to ordering of pointers
746^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
747
748In general, there is no relative ordering among pointers. As a result,
749when unordered containers like sets and maps are used with pointer keys
750the iteration order is undefined. Hence, iterating such containers may
751result in non-deterministic code generation. While the generated code
752might not necessarily be "wrong code", this non-determinism might result
753in unexpected runtime crashes or simply hard to reproduce bugs on the
754customer side making it harder to debug and fix.
755
756As a rule of thumb, in case an ordered result is expected, remember to
757sort an unordered container before iteration. Or use ordered containers
758like vector/MapVector/SetVector if you want to iterate pointer keys.
759
760Beware of non-deterministic sorting order of equal elements
761^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
762
763std::sort uses a non-stable sorting algorithm in which the order of equal
764elements is not guaranteed to be preserved. Thus using std::sort for a
765container having equal elements may result in non-determinstic behavior.
766To uncover such instances of non-determinism, LLVM has introduced a new
767llvm::sort wrapper function. For an EXPENSIVE_CHECKS build this will randomly
768shuffle the container before sorting. As a rule of thumb, always make sure to
769use llvm::sort instead of std::sort.
770
771Style Issues
772============
773
774The High-Level Issues
775---------------------
776
777Self-contained Headers
778^^^^^^^^^^^^^^^^^^^^^^
779
780Header files should be self-contained (compile on their own) and end in .h.
781Non-header files that are meant for inclusion should end in .inc and be used
782sparingly.
783
784All header files should be self-contained. Users and refactoring tools should
785not have to adhere to special conditions to include the header. Specifically, a
786header should have header guards and include all other headers it needs.
787
788There are rare cases where a file designed to be included is not
789self-contained. These are typically intended to be included at unusual
790locations, such as the middle of another file. They might not use header
791guards, and might not include their prerequisites. Name such files with the
792.inc extension. Use sparingly, and prefer self-contained headers when possible.
793
794In general, a header should be implemented by one or more ``.cpp`` files.  Each
795of these ``.cpp`` files should include the header that defines their interface
796first.  This ensures that all of the dependences of the header have been
797properly added to the header itself, and are not implicit.  System headers
798should be included after user headers for a translation unit.
799
800Library Layering
801^^^^^^^^^^^^^^^^
802
803A directory of header files (for example ``include/llvm/Foo``) defines a
804library (``Foo``). Dependencies between libraries are defined by the
805``LLVMBuild.txt`` file in their implementation (``lib/Foo``). One library (both
806its headers and implementation) should only use things from the libraries
807listed in its dependencies.
808
809Some of this constraint can be enforced by classic Unix linkers (Mac & Windows
810linkers, as well as lld, do not enforce this constraint). A Unix linker
811searches left to right through the libraries specified on its command line and
812never revisits a library. In this way, no circular dependencies between
813libraries can exist.
814
815This doesn't fully enforce all inter-library dependencies, and importantly
816doesn't enforce header file circular dependencies created by inline functions.
817A good way to answer the "is this layered correctly" would be to consider
818whether a Unix linker would succeed at linking the program if all inline
819functions were defined out-of-line. (& for all valid orderings of dependencies
820- since linking resolution is linear, it's possible that some implicit
821dependencies can sneak through: A depends on B and C, so valid orderings are
822"C B A" or "B C A", in both cases the explicit dependencies come before their
823use. But in the first case, B could still link successfully if it implicitly
824depended on C, or the opposite in the second case)
825
826.. _minimal list of #includes:
827
828``#include`` as Little as Possible
829^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
830
831``#include`` hurts compile time performance.  Don't do it unless you have to,
832especially in header files.
833
834But wait! Sometimes you need to have the definition of a class to use it, or to
835inherit from it.  In these cases go ahead and ``#include`` that header file.  Be
836aware however that there are many cases where you don't need to have the full
837definition of a class.  If you are using a pointer or reference to a class, you
838don't need the header file.  If you are simply returning a class instance from a
839prototyped function or method, you don't need it.  In fact, for most cases, you
840simply don't need the definition of a class. And not ``#include``\ing speeds up
841compilation.
842
843It is easy to try to go too overboard on this recommendation, however.  You
844**must** include all of the header files that you are using --- you can include
845them either directly or indirectly through another header file.  To make sure
846that you don't accidentally forget to include a header file in your module
847header, make sure to include your module header **first** in the implementation
848file (as mentioned above).  This way there won't be any hidden dependencies that
849you'll find out about later.
850
851Keep "Internal" Headers Private
852^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
853
854Many modules have a complex implementation that causes them to use more than one
855implementation (``.cpp``) file.  It is often tempting to put the internal
856communication interface (helper classes, extra functions, etc) in the public
857module header file.  Don't do this!
858
859If you really need to do something like this, put a private header file in the
860same directory as the source files, and include it locally.  This ensures that
861your private interface remains private and undisturbed by outsiders.
862
863.. note::
864
865    It's okay to put extra implementation methods in a public class itself. Just
866    make them private (or protected) and all is well.
867
868.. _early exits:
869
870Use Early Exits and ``continue`` to Simplify Code
871^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
872
873When reading code, keep in mind how much state and how many previous decisions
874have to be remembered by the reader to understand a block of code.  Aim to
875reduce indentation where possible when it doesn't make it more difficult to
876understand the code.  One great way to do this is by making use of early exits
877and the ``continue`` keyword in long loops.  As an example of using an early
878exit from a function, consider this "bad" code:
879
880.. code-block:: c++
881
882  Value *doSomething(Instruction *I) {
883    if (!I->isTerminator() &&
884        I->hasOneUse() && doOtherThing(I)) {
885      ... some long code ....
886    }
887
888    return 0;
889  }
890
891This code has several problems if the body of the ``'if'`` is large.  When
892you're looking at the top of the function, it isn't immediately clear that this
893*only* does interesting things with non-terminator instructions, and only
894applies to things with the other predicates.  Second, it is relatively difficult
895to describe (in comments) why these predicates are important because the ``if``
896statement makes it difficult to lay out the comments.  Third, when you're deep
897within the body of the code, it is indented an extra level.  Finally, when
898reading the top of the function, it isn't clear what the result is if the
899predicate isn't true; you have to read to the end of the function to know that
900it returns null.
901
902It is much preferred to format the code like this:
903
904.. code-block:: c++
905
906  Value *doSomething(Instruction *I) {
907    // Terminators never need 'something' done to them because ...
908    if (I->isTerminator())
909      return 0;
910
911    // We conservatively avoid transforming instructions with multiple uses
912    // because goats like cheese.
913    if (!I->hasOneUse())
914      return 0;
915
916    // This is really just here for example.
917    if (!doOtherThing(I))
918      return 0;
919
920    ... some long code ....
921  }
922
923This fixes these problems.  A similar problem frequently happens in ``for``
924loops.  A silly example is something like this:
925
926.. code-block:: c++
927
928  for (Instruction &I : BB) {
929    if (auto *BO = dyn_cast<BinaryOperator>(&I)) {
930      Value *LHS = BO->getOperand(0);
931      Value *RHS = BO->getOperand(1);
932      if (LHS != RHS) {
933        ...
934      }
935    }
936  }
937
938When you have very, very small loops, this sort of structure is fine. But if it
939exceeds more than 10-15 lines, it becomes difficult for people to read and
940understand at a glance. The problem with this sort of code is that it gets very
941nested very quickly. Meaning that the reader of the code has to keep a lot of
942context in their brain to remember what is going immediately on in the loop,
943because they don't know if/when the ``if`` conditions will have ``else``\s etc.
944It is strongly preferred to structure the loop like this:
945
946.. code-block:: c++
947
948  for (Instruction &I : BB) {
949    auto *BO = dyn_cast<BinaryOperator>(&I);
950    if (!BO) continue;
951
952    Value *LHS = BO->getOperand(0);
953    Value *RHS = BO->getOperand(1);
954    if (LHS == RHS) continue;
955
956    ...
957  }
958
959This has all the benefits of using early exits for functions: it reduces nesting
960of the loop, it makes it easier to describe why the conditions are true, and it
961makes it obvious to the reader that there is no ``else`` coming up that they
962have to push context into their brain for.  If a loop is large, this can be a
963big understandability win.
964
965Don't use ``else`` after a ``return``
966^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
967
968For similar reasons above (reduction of indentation and easier reading), please
969do not use ``'else'`` or ``'else if'`` after something that interrupts control
970flow --- like ``return``, ``break``, ``continue``, ``goto``, etc. For
971example, this is *bad*:
972
973.. code-block:: c++
974
975  case 'J': {
976    if (Signed) {
977      Type = Context.getsigjmp_bufType();
978      if (Type.isNull()) {
979        Error = ASTContext::GE_Missing_sigjmp_buf;
980        return QualType();
981      } else {
982        break;
983      }
984    } else {
985      Type = Context.getjmp_bufType();
986      if (Type.isNull()) {
987        Error = ASTContext::GE_Missing_jmp_buf;
988        return QualType();
989      } else {
990        break;
991      }
992    }
993  }
994
995It is better to write it like this:
996
997.. code-block:: c++
998
999  case 'J':
1000    if (Signed) {
1001      Type = Context.getsigjmp_bufType();
1002      if (Type.isNull()) {
1003        Error = ASTContext::GE_Missing_sigjmp_buf;
1004        return QualType();
1005      }
1006    } else {
1007      Type = Context.getjmp_bufType();
1008      if (Type.isNull()) {
1009        Error = ASTContext::GE_Missing_jmp_buf;
1010        return QualType();
1011      }
1012    }
1013    break;
1014
1015Or better yet (in this case) as:
1016
1017.. code-block:: c++
1018
1019  case 'J':
1020    if (Signed)
1021      Type = Context.getsigjmp_bufType();
1022    else
1023      Type = Context.getjmp_bufType();
1024
1025    if (Type.isNull()) {
1026      Error = Signed ? ASTContext::GE_Missing_sigjmp_buf :
1027                       ASTContext::GE_Missing_jmp_buf;
1028      return QualType();
1029    }
1030    break;
1031
1032The idea is to reduce indentation and the amount of code you have to keep track
1033of when reading the code.
1034
1035Turn Predicate Loops into Predicate Functions
1036^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1037
1038It is very common to write small loops that just compute a boolean value.  There
1039are a number of ways that people commonly write these, but an example of this
1040sort of thing is:
1041
1042.. code-block:: c++
1043
1044  bool FoundFoo = false;
1045  for (unsigned I = 0, E = BarList.size(); I != E; ++I)
1046    if (BarList[I]->isFoo()) {
1047      FoundFoo = true;
1048      break;
1049    }
1050
1051  if (FoundFoo) {
1052    ...
1053  }
1054
1055This sort of code is awkward to write, and is almost always a bad sign.  Instead
1056of this sort of loop, we strongly prefer to use a predicate function (which may
1057be `static`_) that uses `early exits`_ to compute the predicate.  We prefer the
1058code to be structured like this:
1059
1060.. code-block:: c++
1061
1062  /// \returns true if the specified list has an element that is a foo.
1063  static bool containsFoo(const std::vector<Bar*> &List) {
1064    for (unsigned I = 0, E = List.size(); I != E; ++I)
1065      if (List[I]->isFoo())
1066        return true;
1067    return false;
1068  }
1069  ...
1070
1071  if (containsFoo(BarList)) {
1072    ...
1073  }
1074
1075There are many reasons for doing this: it reduces indentation and factors out
1076code which can often be shared by other code that checks for the same predicate.
1077More importantly, it *forces you to pick a name* for the function, and forces
1078you to write a comment for it.  In this silly example, this doesn't add much
1079value.  However, if the condition is complex, this can make it a lot easier for
1080the reader to understand the code that queries for this predicate.  Instead of
1081being faced with the in-line details of how we check to see if the BarList
1082contains a foo, we can trust the function name and continue reading with better
1083locality.
1084
1085The Low-Level Issues
1086--------------------
1087
1088Name Types, Functions, Variables, and Enumerators Properly
1089^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1090
1091Poorly-chosen names can mislead the reader and cause bugs. We cannot stress
1092enough how important it is to use *descriptive* names.  Pick names that match
1093the semantics and role of the underlying entities, within reason.  Avoid
1094abbreviations unless they are well known.  After picking a good name, make sure
1095to use consistent capitalization for the name, as inconsistency requires clients
1096to either memorize the APIs or to look it up to find the exact spelling.
1097
1098In general, names should be in camel case (e.g. ``TextFileReader`` and
1099``isLValue()``).  Different kinds of declarations have different rules:
1100
1101* **Type names** (including classes, structs, enums, typedefs, etc) should be
1102  nouns and start with an upper-case letter (e.g. ``TextFileReader``).
1103
1104* **Variable names** should be nouns (as they represent state).  The name should
1105  be camel case, and start with an upper case letter (e.g. ``Leader`` or
1106  ``Boats``).
1107
1108* **Function names** should be verb phrases (as they represent actions), and
1109  command-like function should be imperative.  The name should be camel case,
1110  and start with a lower case letter (e.g. ``openFile()`` or ``isFoo()``).
1111
1112* **Enum declarations** (e.g. ``enum Foo {...}``) are types, so they should
1113  follow the naming conventions for types.  A common use for enums is as a
1114  discriminator for a union, or an indicator of a subclass.  When an enum is
1115  used for something like this, it should have a ``Kind`` suffix
1116  (e.g. ``ValueKind``).
1117
1118* **Enumerators** (e.g. ``enum { Foo, Bar }``) and **public member variables**
1119  should start with an upper-case letter, just like types.  Unless the
1120  enumerators are defined in their own small namespace or inside a class,
1121  enumerators should have a prefix corresponding to the enum declaration name.
1122  For example, ``enum ValueKind { ... };`` may contain enumerators like
1123  ``VK_Argument``, ``VK_BasicBlock``, etc.  Enumerators that are just
1124  convenience constants are exempt from the requirement for a prefix.  For
1125  instance:
1126
1127  .. code-block:: c++
1128
1129      enum {
1130        MaxSize = 42,
1131        Density = 12
1132      };
1133
1134As an exception, classes that mimic STL classes can have member names in STL's
1135style of lower-case words separated by underscores (e.g. ``begin()``,
1136``push_back()``, and ``empty()``). Classes that provide multiple
1137iterators should add a singular prefix to ``begin()`` and ``end()``
1138(e.g. ``global_begin()`` and ``use_begin()``).
1139
1140Here are some examples of good and bad names:
1141
1142.. code-block:: c++
1143
1144  class VehicleMaker {
1145    ...
1146    Factory<Tire> F;            // Bad -- abbreviation and non-descriptive.
1147    Factory<Tire> Factory;      // Better.
1148    Factory<Tire> TireFactory;  // Even better -- if VehicleMaker has more than one
1149                                // kind of factories.
1150  };
1151
1152  Vehicle makeVehicle(VehicleType Type) {
1153    VehicleMaker M;                         // Might be OK if having a short life-span.
1154    Tire Tmp1 = M.makeTire();               // Bad -- 'Tmp1' provides no information.
1155    Light Headlight = M.makeLight("head");  // Good -- descriptive.
1156    ...
1157  }
1158
1159Assert Liberally
1160^^^^^^^^^^^^^^^^
1161
1162Use the "``assert``" macro to its fullest.  Check all of your preconditions and
1163assumptions, you never know when a bug (not necessarily even yours) might be
1164caught early by an assertion, which reduces debugging time dramatically.  The
1165"``<cassert>``" header file is probably already included by the header files you
1166are using, so it doesn't cost anything to use it.
1167
1168To further assist with debugging, make sure to put some kind of error message in
1169the assertion statement, which is printed if the assertion is tripped. This
1170helps the poor debugger make sense of why an assertion is being made and
1171enforced, and hopefully what to do about it.  Here is one complete example:
1172
1173.. code-block:: c++
1174
1175  inline Value *getOperand(unsigned I) {
1176    assert(I < Operands.size() && "getOperand() out of range!");
1177    return Operands[I];
1178  }
1179
1180Here are more examples:
1181
1182.. code-block:: c++
1183
1184  assert(Ty->isPointerType() && "Can't allocate a non-pointer type!");
1185
1186  assert((Opcode == Shl || Opcode == Shr) && "ShiftInst Opcode invalid!");
1187
1188  assert(idx < getNumSuccessors() && "Successor # out of range!");
1189
1190  assert(V1.getType() == V2.getType() && "Constant types must be identical!");
1191
1192  assert(isa<PHINode>(Succ->front()) && "Only works on PHId BBs!");
1193
1194You get the idea.
1195
1196In the past, asserts were used to indicate a piece of code that should not be
1197reached.  These were typically of the form:
1198
1199.. code-block:: c++
1200
1201  assert(0 && "Invalid radix for integer literal");
1202
1203This has a few issues, the main one being that some compilers might not
1204understand the assertion, or warn about a missing return in builds where
1205assertions are compiled out.
1206
1207Today, we have something much better: ``llvm_unreachable``:
1208
1209.. code-block:: c++
1210
1211  llvm_unreachable("Invalid radix for integer literal");
1212
1213When assertions are enabled, this will print the message if it's ever reached
1214and then exit the program. When assertions are disabled (i.e. in release
1215builds), ``llvm_unreachable`` becomes a hint to compilers to skip generating
1216code for this branch. If the compiler does not support this, it will fall back
1217to the "abort" implementation.
1218
1219Neither assertions or ``llvm_unreachable`` will abort the program on a release
1220build. If the error condition can be triggered by user input then the
1221recoverable error mechanism described in :doc:`ProgrammersManual` should be
1222used instead. In cases where this is not practical, ``report_fatal_error`` may
1223be used.
1224
1225Another issue is that values used only by assertions will produce an "unused
1226value" warning when assertions are disabled.  For example, this code will warn:
1227
1228.. code-block:: c++
1229
1230  unsigned Size = V.size();
1231  assert(Size > 42 && "Vector smaller than it should be");
1232
1233  bool NewToSet = Myset.insert(Value);
1234  assert(NewToSet && "The value shouldn't be in the set yet");
1235
1236These are two interesting different cases. In the first case, the call to
1237``V.size()`` is only useful for the assert, and we don't want it executed when
1238assertions are disabled.  Code like this should move the call into the assert
1239itself.  In the second case, the side effects of the call must happen whether
1240the assert is enabled or not.  In this case, the value should be cast to void to
1241disable the warning.  To be specific, it is preferred to write the code like
1242this:
1243
1244.. code-block:: c++
1245
1246  assert(V.size() > 42 && "Vector smaller than it should be");
1247
1248  bool NewToSet = Myset.insert(Value); (void)NewToSet;
1249  assert(NewToSet && "The value shouldn't be in the set yet");
1250
1251Do Not Use ``using namespace std``
1252^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1253
1254In LLVM, we prefer to explicitly prefix all identifiers from the standard
1255namespace with an "``std::``" prefix, rather than rely on "``using namespace
1256std;``".
1257
1258In header files, adding a ``'using namespace XXX'`` directive pollutes the
1259namespace of any source file that ``#include``\s the header.  This is clearly a
1260bad thing.
1261
1262In implementation files (e.g. ``.cpp`` files), the rule is more of a stylistic
1263rule, but is still important.  Basically, using explicit namespace prefixes
1264makes the code **clearer**, because it is immediately obvious what facilities
1265are being used and where they are coming from. And **more portable**, because
1266namespace clashes cannot occur between LLVM code and other namespaces.  The
1267portability rule is important because different standard library implementations
1268expose different symbols (potentially ones they shouldn't), and future revisions
1269to the C++ standard will add more symbols to the ``std`` namespace.  As such, we
1270never use ``'using namespace std;'`` in LLVM.
1271
1272The exception to the general rule (i.e. it's not an exception for the ``std``
1273namespace) is for implementation files.  For example, all of the code in the
1274LLVM project implements code that lives in the 'llvm' namespace.  As such, it is
1275ok, and actually clearer, for the ``.cpp`` files to have a ``'using namespace
1276llvm;'`` directive at the top, after the ``#include``\s.  This reduces
1277indentation in the body of the file for source editors that indent based on
1278braces, and keeps the conceptual context cleaner.  The general form of this rule
1279is that any ``.cpp`` file that implements code in any namespace may use that
1280namespace (and its parents'), but should not use any others.
1281
1282Provide a Virtual Method Anchor for Classes in Headers
1283^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1284
1285If a class is defined in a header file and has a vtable (either it has virtual
1286methods or it derives from classes with virtual methods), it must always have at
1287least one out-of-line virtual method in the class.  Without this, the compiler
1288will copy the vtable and RTTI into every ``.o`` file that ``#include``\s the
1289header, bloating ``.o`` file sizes and increasing link times.
1290
1291Don't use default labels in fully covered switches over enumerations
1292^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1293
1294``-Wswitch`` warns if a switch, without a default label, over an enumeration
1295does not cover every enumeration value. If you write a default label on a fully
1296covered switch over an enumeration then the ``-Wswitch`` warning won't fire
1297when new elements are added to that enumeration. To help avoid adding these
1298kinds of defaults, Clang has the warning ``-Wcovered-switch-default`` which is
1299off by default but turned on when building LLVM with a version of Clang that
1300supports the warning.
1301
1302A knock-on effect of this stylistic requirement is that when building LLVM with
1303GCC you may get warnings related to "control may reach end of non-void function"
1304if you return from each case of a covered switch-over-enum because GCC assumes
1305that the enum expression may take any representable value, not just those of
1306individual enumerators. To suppress this warning, use ``llvm_unreachable`` after
1307the switch.
1308
1309Use range-based ``for`` loops wherever possible
1310^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1311
1312The introduction of range-based ``for`` loops in C++11 means that explicit
1313manipulation of iterators is rarely necessary. We use range-based ``for``
1314loops wherever possible for all newly added code. For example:
1315
1316.. code-block:: c++
1317
1318  BasicBlock *BB = ...
1319  for (Instruction &I : *BB)
1320    ... use I ...
1321
1322Don't evaluate ``end()`` every time through a loop
1323^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1324
1325In cases where range-based ``for`` loops can't be used and it is necessary
1326to write an explicit iterator-based loop, pay close attention to whether
1327``end()`` is re-evaluted on each loop iteration. One common mistake is to
1328write a loop in this style:
1329
1330.. code-block:: c++
1331
1332  BasicBlock *BB = ...
1333  for (auto I = BB->begin(); I != BB->end(); ++I)
1334    ... use I ...
1335
1336The problem with this construct is that it evaluates "``BB->end()``" every time
1337through the loop.  Instead of writing the loop like this, we strongly prefer
1338loops to be written so that they evaluate it once before the loop starts.  A
1339convenient way to do this is like so:
1340
1341.. code-block:: c++
1342
1343  BasicBlock *BB = ...
1344  for (auto I = BB->begin(), E = BB->end(); I != E; ++I)
1345    ... use I ...
1346
1347The observant may quickly point out that these two loops may have different
1348semantics: if the container (a basic block in this case) is being mutated, then
1349"``BB->end()``" may change its value every time through the loop and the second
1350loop may not in fact be correct.  If you actually do depend on this behavior,
1351please write the loop in the first form and add a comment indicating that you
1352did it intentionally.
1353
1354Why do we prefer the second form (when correct)?  Writing the loop in the first
1355form has two problems. First it may be less efficient than evaluating it at the
1356start of the loop.  In this case, the cost is probably minor --- a few extra
1357loads every time through the loop.  However, if the base expression is more
1358complex, then the cost can rise quickly.  I've seen loops where the end
1359expression was actually something like: "``SomeMap[X]->end()``" and map lookups
1360really aren't cheap.  By writing it in the second form consistently, you
1361eliminate the issue entirely and don't even have to think about it.
1362
1363The second (even bigger) issue is that writing the loop in the first form hints
1364to the reader that the loop is mutating the container (a fact that a comment
1365would handily confirm!).  If you write the loop in the second form, it is
1366immediately obvious without even looking at the body of the loop that the
1367container isn't being modified, which makes it easier to read the code and
1368understand what it does.
1369
1370While the second form of the loop is a few extra keystrokes, we do strongly
1371prefer it.
1372
1373``#include <iostream>`` is Forbidden
1374^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1375
1376The use of ``#include <iostream>`` in library files is hereby **forbidden**,
1377because many common implementations transparently inject a `static constructor`_
1378into every translation unit that includes it.
1379
1380Note that using the other stream headers (``<sstream>`` for example) is not
1381problematic in this regard --- just ``<iostream>``. However, ``raw_ostream``
1382provides various APIs that are better performing for almost every use than
1383``std::ostream`` style APIs.
1384
1385.. note::
1386
1387  New code should always use `raw_ostream`_ for writing, or the
1388  ``llvm::MemoryBuffer`` API for reading files.
1389
1390.. _raw_ostream:
1391
1392Use ``raw_ostream``
1393^^^^^^^^^^^^^^^^^^^
1394
1395LLVM includes a lightweight, simple, and efficient stream implementation in
1396``llvm/Support/raw_ostream.h``, which provides all of the common features of
1397``std::ostream``.  All new code should use ``raw_ostream`` instead of
1398``ostream``.
1399
1400Unlike ``std::ostream``, ``raw_ostream`` is not a template and can be forward
1401declared as ``class raw_ostream``.  Public headers should generally not include
1402the ``raw_ostream`` header, but use forward declarations and constant references
1403to ``raw_ostream`` instances.
1404
1405Avoid ``std::endl``
1406^^^^^^^^^^^^^^^^^^^
1407
1408The ``std::endl`` modifier, when used with ``iostreams`` outputs a newline to
1409the output stream specified.  In addition to doing this, however, it also
1410flushes the output stream.  In other words, these are equivalent:
1411
1412.. code-block:: c++
1413
1414  std::cout << std::endl;
1415  std::cout << '\n' << std::flush;
1416
1417Most of the time, you probably have no reason to flush the output stream, so
1418it's better to use a literal ``'\n'``.
1419
1420Don't use ``inline`` when defining a function in a class definition
1421^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
1422
1423A member function defined in a class definition is implicitly inline, so don't
1424put the ``inline`` keyword in this case.
1425
1426Don't:
1427
1428.. code-block:: c++
1429
1430  class Foo {
1431  public:
1432    inline void bar() {
1433      // ...
1434    }
1435  };
1436
1437Do:
1438
1439.. code-block:: c++
1440
1441  class Foo {
1442  public:
1443    void bar() {
1444      // ...
1445    }
1446  };
1447
1448Microscopic Details
1449-------------------
1450
1451This section describes preferred low-level formatting guidelines along with
1452reasoning on why we prefer them.
1453
1454Spaces Before Parentheses
1455^^^^^^^^^^^^^^^^^^^^^^^^^
1456
1457We prefer to put a space before an open parenthesis only in control flow
1458statements, but not in normal function call expressions and function-like
1459macros.  For example, this is good:
1460
1461.. code-block:: c++
1462
1463  if (X) ...
1464  for (I = 0; I != 100; ++I) ...
1465  while (LLVMRocks) ...
1466
1467  somefunc(42);
1468  assert(3 != 4 && "laws of math are failing me");
1469
1470  A = foo(42, 92) + bar(X);
1471
1472and this is bad:
1473
1474.. code-block:: c++
1475
1476  if(X) ...
1477  for(I = 0; I != 100; ++I) ...
1478  while(LLVMRocks) ...
1479
1480  somefunc (42);
1481  assert (3 != 4 && "laws of math are failing me");
1482
1483  A = foo (42, 92) + bar (X);
1484
1485The reason for doing this is not completely arbitrary.  This style makes control
1486flow operators stand out more, and makes expressions flow better. The function
1487call operator binds very tightly as a postfix operator.  Putting a space after a
1488function name (as in the last example) makes it appear that the code might bind
1489the arguments of the left-hand-side of a binary operator with the argument list
1490of a function and the name of the right side.  More specifically, it is easy to
1491misread the "``A``" example as:
1492
1493.. code-block:: c++
1494
1495  A = foo ((42, 92) + bar) (X);
1496
1497when skimming through the code.  By avoiding a space in a function, we avoid
1498this misinterpretation.
1499
1500Prefer Preincrement
1501^^^^^^^^^^^^^^^^^^^
1502
1503Hard fast rule: Preincrement (``++X``) may be no slower than postincrement
1504(``X++``) and could very well be a lot faster than it.  Use preincrementation
1505whenever possible.
1506
1507The semantics of postincrement include making a copy of the value being
1508incremented, returning it, and then preincrementing the "work value".  For
1509primitive types, this isn't a big deal. But for iterators, it can be a huge
1510issue (for example, some iterators contains stack and set objects in them...
1511copying an iterator could invoke the copy ctor's of these as well).  In general,
1512get in the habit of always using preincrement, and you won't have a problem.
1513
1514
1515Namespace Indentation
1516^^^^^^^^^^^^^^^^^^^^^
1517
1518In general, we strive to reduce indentation wherever possible.  This is useful
1519because we want code to `fit into 80 columns`_ without wrapping horribly, but
1520also because it makes it easier to understand the code. To facilitate this and
1521avoid some insanely deep nesting on occasion, don't indent namespaces. If it
1522helps readability, feel free to add a comment indicating what namespace is
1523being closed by a ``}``.  For example:
1524
1525.. code-block:: c++
1526
1527  namespace llvm {
1528  namespace knowledge {
1529
1530  /// This class represents things that Smith can have an intimate
1531  /// understanding of and contains the data associated with it.
1532  class Grokable {
1533  ...
1534  public:
1535    explicit Grokable() { ... }
1536    virtual ~Grokable() = 0;
1537
1538    ...
1539
1540  };
1541
1542  } // end namespace knowledge
1543  } // end namespace llvm
1544
1545
1546Feel free to skip the closing comment when the namespace being closed is
1547obvious for any reason. For example, the outer-most namespace in a header file
1548is rarely a source of confusion. But namespaces both anonymous and named in
1549source files that are being closed half way through the file probably could use
1550clarification.
1551
1552.. _static:
1553
1554Anonymous Namespaces
1555^^^^^^^^^^^^^^^^^^^^
1556
1557After talking about namespaces in general, you may be wondering about anonymous
1558namespaces in particular.  Anonymous namespaces are a great language feature
1559that tells the C++ compiler that the contents of the namespace are only visible
1560within the current translation unit, allowing more aggressive optimization and
1561eliminating the possibility of symbol name collisions.  Anonymous namespaces are
1562to C++ as "static" is to C functions and global variables.  While "``static``"
1563is available in C++, anonymous namespaces are more general: they can make entire
1564classes private to a file.
1565
1566The problem with anonymous namespaces is that they naturally want to encourage
1567indentation of their body, and they reduce locality of reference: if you see a
1568random function definition in a C++ file, it is easy to see if it is marked
1569static, but seeing if it is in an anonymous namespace requires scanning a big
1570chunk of the file.
1571
1572Because of this, we have a simple guideline: make anonymous namespaces as small
1573as possible, and only use them for class declarations.  For example, this is
1574good:
1575
1576.. code-block:: c++
1577
1578  namespace {
1579  class StringSort {
1580  ...
1581  public:
1582    StringSort(...)
1583    bool operator<(const char *RHS) const;
1584  };
1585  } // end anonymous namespace
1586
1587  static void runHelper() {
1588    ...
1589  }
1590
1591  bool StringSort::operator<(const char *RHS) const {
1592    ...
1593  }
1594
1595This is bad:
1596
1597.. code-block:: c++
1598
1599  namespace {
1600
1601  class StringSort {
1602  ...
1603  public:
1604    StringSort(...)
1605    bool operator<(const char *RHS) const;
1606  };
1607
1608  void runHelper() {
1609    ...
1610  }
1611
1612  bool StringSort::operator<(const char *RHS) const {
1613    ...
1614  }
1615
1616  } // end anonymous namespace
1617
1618This is bad specifically because if you're looking at "``runHelper``" in the middle
1619of a large C++ file, that you have no immediate way to tell if it is local to
1620the file.  When it is marked static explicitly, this is immediately obvious.
1621Also, there is no reason to enclose the definition of "``operator<``" in the
1622namespace just because it was declared there.
1623
1624See Also
1625========
1626
1627A lot of these comments and recommendations have been culled from other sources.
1628Two particularly important books for our work are:
1629
1630#. `Effective C++
1631   <https://www.amazon.com/Effective-Specific-Addison-Wesley-Professional-Computing/dp/0321334876>`_
1632   by Scott Meyers.  Also interesting and useful are "More Effective C++" and
1633   "Effective STL" by the same author.
1634
1635#. `Large-Scale C++ Software Design
1636   <https://www.amazon.com/Large-Scale-Software-Design-John-Lakos/dp/0201633620>`_
1637   by John Lakos
1638
1639If you get some free time, and you haven't read them: do so, you might learn
1640something.
1641