1 //===- InlineCost.cpp - Cost analysis for inliner -------------------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 // This file implements inline cost analysis.
11 //
12 //===----------------------------------------------------------------------===//
13 
14 #include "llvm/Analysis/InlineCost.h"
15 #include "llvm/ADT/STLExtras.h"
16 #include "llvm/ADT/SetVector.h"
17 #include "llvm/ADT/SmallPtrSet.h"
18 #include "llvm/ADT/SmallVector.h"
19 #include "llvm/ADT/Statistic.h"
20 #include "llvm/Analysis/AssumptionCache.h"
21 #include "llvm/Analysis/BlockFrequencyInfo.h"
22 #include "llvm/Analysis/CodeMetrics.h"
23 #include "llvm/Analysis/ConstantFolding.h"
24 #include "llvm/Analysis/InstructionSimplify.h"
25 #include "llvm/Analysis/ProfileSummaryInfo.h"
26 #include "llvm/Analysis/TargetTransformInfo.h"
27 #include "llvm/IR/CallSite.h"
28 #include "llvm/IR/CallingConv.h"
29 #include "llvm/IR/DataLayout.h"
30 #include "llvm/IR/GetElementPtrTypeIterator.h"
31 #include "llvm/IR/GlobalAlias.h"
32 #include "llvm/IR/InstVisitor.h"
33 #include "llvm/IR/IntrinsicInst.h"
34 #include "llvm/IR/Operator.h"
35 #include "llvm/Support/Debug.h"
36 #include "llvm/Support/raw_ostream.h"
37 
38 using namespace llvm;
39 
40 #define DEBUG_TYPE "inline-cost"
41 
42 STATISTIC(NumCallsAnalyzed, "Number of call sites analyzed");
43 
44 static cl::opt<int> InlineThreshold(
45     "inline-threshold", cl::Hidden, cl::init(225), cl::ZeroOrMore,
46     cl::desc("Control the amount of inlining to perform (default = 225)"));
47 
48 static cl::opt<int> HintThreshold(
49     "inlinehint-threshold", cl::Hidden, cl::init(325),
50     cl::desc("Threshold for inlining functions with inline hint"));
51 
52 static cl::opt<int>
53     ColdCallSiteThreshold("inline-cold-callsite-threshold", cl::Hidden,
54                           cl::init(45),
55                           cl::desc("Threshold for inlining cold callsites"));
56 
57 // We introduce this threshold to help performance of instrumentation based
58 // PGO before we actually hook up inliner with analysis passes such as BPI and
59 // BFI.
60 static cl::opt<int> ColdThreshold(
61     "inlinecold-threshold", cl::Hidden, cl::init(225),
62     cl::desc("Threshold for inlining functions with cold attribute"));
63 
64 static cl::opt<int>
65     HotCallSiteThreshold("hot-callsite-threshold", cl::Hidden, cl::init(3000),
66                          cl::ZeroOrMore,
67                          cl::desc("Threshold for hot callsites "));
68 
69 namespace {
70 
71 class CallAnalyzer : public InstVisitor<CallAnalyzer, bool> {
72   typedef InstVisitor<CallAnalyzer, bool> Base;
73   friend class InstVisitor<CallAnalyzer, bool>;
74 
75   /// The TargetTransformInfo available for this compilation.
76   const TargetTransformInfo &TTI;
77 
78   /// Getter for the cache of @llvm.assume intrinsics.
79   std::function<AssumptionCache &(Function &)> &GetAssumptionCache;
80 
81   /// Getter for BlockFrequencyInfo
82   Optional<function_ref<BlockFrequencyInfo &(Function &)>> &GetBFI;
83 
84   /// Profile summary information.
85   ProfileSummaryInfo *PSI;
86 
87   /// The called function.
88   Function &F;
89 
90   /// The candidate callsite being analyzed. Please do not use this to do
91   /// analysis in the caller function; we want the inline cost query to be
92   /// easily cacheable. Instead, use the cover function paramHasAttr.
93   CallSite CandidateCS;
94 
95   /// Tunable parameters that control the analysis.
96   const InlineParams &Params;
97 
98   int Threshold;
99   int Cost;
100 
101   bool IsCallerRecursive;
102   bool IsRecursiveCall;
103   bool ExposesReturnsTwice;
104   bool HasDynamicAlloca;
105   bool ContainsNoDuplicateCall;
106   bool HasReturn;
107   bool HasIndirectBr;
108   bool HasFrameEscape;
109 
110   /// Number of bytes allocated statically by the callee.
111   uint64_t AllocatedSize;
112   unsigned NumInstructions, NumVectorInstructions;
113   int FiftyPercentVectorBonus, TenPercentVectorBonus;
114   int VectorBonus;
115 
116   /// While we walk the potentially-inlined instructions, we build up and
117   /// maintain a mapping of simplified values specific to this callsite. The
118   /// idea is to propagate any special information we have about arguments to
119   /// this call through the inlinable section of the function, and account for
120   /// likely simplifications post-inlining. The most important aspect we track
121   /// is CFG altering simplifications -- when we prove a basic block dead, that
122   /// can cause dramatic shifts in the cost of inlining a function.
123   DenseMap<Value *, Constant *> SimplifiedValues;
124 
125   /// Keep track of the values which map back (through function arguments) to
126   /// allocas on the caller stack which could be simplified through SROA.
127   DenseMap<Value *, Value *> SROAArgValues;
128 
129   /// The mapping of caller Alloca values to their accumulated cost savings. If
130   /// we have to disable SROA for one of the allocas, this tells us how much
131   /// cost must be added.
132   DenseMap<Value *, int> SROAArgCosts;
133 
134   /// Keep track of values which map to a pointer base and constant offset.
135   DenseMap<Value *, std::pair<Value *, APInt>> ConstantOffsetPtrs;
136 
137   // Custom simplification helper routines.
138   bool isAllocaDerivedArg(Value *V);
139   bool lookupSROAArgAndCost(Value *V, Value *&Arg,
140                             DenseMap<Value *, int>::iterator &CostIt);
141   void disableSROA(DenseMap<Value *, int>::iterator CostIt);
142   void disableSROA(Value *V);
143   void accumulateSROACost(DenseMap<Value *, int>::iterator CostIt,
144                           int InstructionCost);
145   bool isGEPFree(GetElementPtrInst &GEP);
146   bool accumulateGEPOffset(GEPOperator &GEP, APInt &Offset);
147   bool simplifyCallSite(Function *F, CallSite CS);
148   template <typename Callable>
149   bool simplifyInstruction(Instruction &I, Callable Evaluate);
150   ConstantInt *stripAndComputeInBoundsConstantOffsets(Value *&V);
151 
152   /// Return true if the given argument to the function being considered for
153   /// inlining has the given attribute set either at the call site or the
154   /// function declaration.  Primarily used to inspect call site specific
155   /// attributes since these can be more precise than the ones on the callee
156   /// itself.
157   bool paramHasAttr(Argument *A, Attribute::AttrKind Attr);
158 
159   /// Return true if the given value is known non null within the callee if
160   /// inlined through this particular callsite.
161   bool isKnownNonNullInCallee(Value *V);
162 
163   /// Update Threshold based on callsite properties such as callee
164   /// attributes and callee hotness for PGO builds. The Callee is explicitly
165   /// passed to support analyzing indirect calls whose target is inferred by
166   /// analysis.
167   void updateThreshold(CallSite CS, Function &Callee);
168 
169   /// Return true if size growth is allowed when inlining the callee at CS.
170   bool allowSizeGrowth(CallSite CS);
171 
172   // Custom analysis routines.
173   bool analyzeBlock(BasicBlock *BB, SmallPtrSetImpl<const Value *> &EphValues);
174 
175   // Disable several entry points to the visitor so we don't accidentally use
176   // them by declaring but not defining them here.
177   void visit(Module *);
178   void visit(Module &);
179   void visit(Function *);
180   void visit(Function &);
181   void visit(BasicBlock *);
182   void visit(BasicBlock &);
183 
184   // Provide base case for our instruction visit.
185   bool visitInstruction(Instruction &I);
186 
187   // Our visit overrides.
188   bool visitAlloca(AllocaInst &I);
189   bool visitPHI(PHINode &I);
190   bool visitGetElementPtr(GetElementPtrInst &I);
191   bool visitBitCast(BitCastInst &I);
192   bool visitPtrToInt(PtrToIntInst &I);
193   bool visitIntToPtr(IntToPtrInst &I);
194   bool visitCastInst(CastInst &I);
195   bool visitUnaryInstruction(UnaryInstruction &I);
196   bool visitCmpInst(CmpInst &I);
197   bool visitSub(BinaryOperator &I);
198   bool visitBinaryOperator(BinaryOperator &I);
199   bool visitLoad(LoadInst &I);
200   bool visitStore(StoreInst &I);
201   bool visitExtractValue(ExtractValueInst &I);
202   bool visitInsertValue(InsertValueInst &I);
203   bool visitCallSite(CallSite CS);
204   bool visitReturnInst(ReturnInst &RI);
205   bool visitBranchInst(BranchInst &BI);
206   bool visitSwitchInst(SwitchInst &SI);
207   bool visitIndirectBrInst(IndirectBrInst &IBI);
208   bool visitResumeInst(ResumeInst &RI);
209   bool visitCleanupReturnInst(CleanupReturnInst &RI);
210   bool visitCatchReturnInst(CatchReturnInst &RI);
211   bool visitUnreachableInst(UnreachableInst &I);
212 
213 public:
214   CallAnalyzer(const TargetTransformInfo &TTI,
215                std::function<AssumptionCache &(Function &)> &GetAssumptionCache,
216                Optional<function_ref<BlockFrequencyInfo &(Function &)>> &GetBFI,
217                ProfileSummaryInfo *PSI, Function &Callee, CallSite CSArg,
218                const InlineParams &Params)
219       : TTI(TTI), GetAssumptionCache(GetAssumptionCache), GetBFI(GetBFI),
220         PSI(PSI), F(Callee), CandidateCS(CSArg), Params(Params),
221         Threshold(Params.DefaultThreshold), Cost(0), IsCallerRecursive(false),
222         IsRecursiveCall(false), ExposesReturnsTwice(false),
223         HasDynamicAlloca(false), ContainsNoDuplicateCall(false),
224         HasReturn(false), HasIndirectBr(false), HasFrameEscape(false),
225         AllocatedSize(0), NumInstructions(0), NumVectorInstructions(0),
226         FiftyPercentVectorBonus(0), TenPercentVectorBonus(0), VectorBonus(0),
227         NumConstantArgs(0), NumConstantOffsetPtrArgs(0), NumAllocaArgs(0),
228         NumConstantPtrCmps(0), NumConstantPtrDiffs(0),
229         NumInstructionsSimplified(0), SROACostSavings(0),
230         SROACostSavingsLost(0) {}
231 
232   bool analyzeCall(CallSite CS);
233 
234   int getThreshold() { return Threshold; }
235   int getCost() { return Cost; }
236 
237   // Keep a bunch of stats about the cost savings found so we can print them
238   // out when debugging.
239   unsigned NumConstantArgs;
240   unsigned NumConstantOffsetPtrArgs;
241   unsigned NumAllocaArgs;
242   unsigned NumConstantPtrCmps;
243   unsigned NumConstantPtrDiffs;
244   unsigned NumInstructionsSimplified;
245   unsigned SROACostSavings;
246   unsigned SROACostSavingsLost;
247 
248   void dump();
249 };
250 
251 } // namespace
252 
253 /// \brief Test whether the given value is an Alloca-derived function argument.
254 bool CallAnalyzer::isAllocaDerivedArg(Value *V) {
255   return SROAArgValues.count(V);
256 }
257 
258 /// \brief Lookup the SROA-candidate argument and cost iterator which V maps to.
259 /// Returns false if V does not map to a SROA-candidate.
260 bool CallAnalyzer::lookupSROAArgAndCost(
261     Value *V, Value *&Arg, DenseMap<Value *, int>::iterator &CostIt) {
262   if (SROAArgValues.empty() || SROAArgCosts.empty())
263     return false;
264 
265   DenseMap<Value *, Value *>::iterator ArgIt = SROAArgValues.find(V);
266   if (ArgIt == SROAArgValues.end())
267     return false;
268 
269   Arg = ArgIt->second;
270   CostIt = SROAArgCosts.find(Arg);
271   return CostIt != SROAArgCosts.end();
272 }
273 
274 /// \brief Disable SROA for the candidate marked by this cost iterator.
275 ///
276 /// This marks the candidate as no longer viable for SROA, and adds the cost
277 /// savings associated with it back into the inline cost measurement.
278 void CallAnalyzer::disableSROA(DenseMap<Value *, int>::iterator CostIt) {
279   // If we're no longer able to perform SROA we need to undo its cost savings
280   // and prevent subsequent analysis.
281   Cost += CostIt->second;
282   SROACostSavings -= CostIt->second;
283   SROACostSavingsLost += CostIt->second;
284   SROAArgCosts.erase(CostIt);
285 }
286 
287 /// \brief If 'V' maps to a SROA candidate, disable SROA for it.
288 void CallAnalyzer::disableSROA(Value *V) {
289   Value *SROAArg;
290   DenseMap<Value *, int>::iterator CostIt;
291   if (lookupSROAArgAndCost(V, SROAArg, CostIt))
292     disableSROA(CostIt);
293 }
294 
295 /// \brief Accumulate the given cost for a particular SROA candidate.
296 void CallAnalyzer::accumulateSROACost(DenseMap<Value *, int>::iterator CostIt,
297                                       int InstructionCost) {
298   CostIt->second += InstructionCost;
299   SROACostSavings += InstructionCost;
300 }
301 
302 /// \brief Accumulate a constant GEP offset into an APInt if possible.
303 ///
304 /// Returns false if unable to compute the offset for any reason. Respects any
305 /// simplified values known during the analysis of this callsite.
306 bool CallAnalyzer::accumulateGEPOffset(GEPOperator &GEP, APInt &Offset) {
307   const DataLayout &DL = F.getParent()->getDataLayout();
308   unsigned IntPtrWidth = DL.getPointerSizeInBits();
309   assert(IntPtrWidth == Offset.getBitWidth());
310 
311   for (gep_type_iterator GTI = gep_type_begin(GEP), GTE = gep_type_end(GEP);
312        GTI != GTE; ++GTI) {
313     ConstantInt *OpC = dyn_cast<ConstantInt>(GTI.getOperand());
314     if (!OpC)
315       if (Constant *SimpleOp = SimplifiedValues.lookup(GTI.getOperand()))
316         OpC = dyn_cast<ConstantInt>(SimpleOp);
317     if (!OpC)
318       return false;
319     if (OpC->isZero())
320       continue;
321 
322     // Handle a struct index, which adds its field offset to the pointer.
323     if (StructType *STy = GTI.getStructTypeOrNull()) {
324       unsigned ElementIdx = OpC->getZExtValue();
325       const StructLayout *SL = DL.getStructLayout(STy);
326       Offset += APInt(IntPtrWidth, SL->getElementOffset(ElementIdx));
327       continue;
328     }
329 
330     APInt TypeSize(IntPtrWidth, DL.getTypeAllocSize(GTI.getIndexedType()));
331     Offset += OpC->getValue().sextOrTrunc(IntPtrWidth) * TypeSize;
332   }
333   return true;
334 }
335 
336 /// \brief Use TTI to check whether a GEP is free.
337 ///
338 /// Respects any simplified values known during the analysis of this callsite.
339 bool CallAnalyzer::isGEPFree(GetElementPtrInst &GEP) {
340   SmallVector<Value *, 4> Indices;
341   for (User::op_iterator I = GEP.idx_begin(), E = GEP.idx_end(); I != E; ++I)
342     if (Constant *SimpleOp = SimplifiedValues.lookup(*I))
343        Indices.push_back(SimpleOp);
344      else
345        Indices.push_back(*I);
346   return TargetTransformInfo::TCC_Free ==
347          TTI.getGEPCost(GEP.getSourceElementType(), GEP.getPointerOperand(),
348                         Indices);
349 }
350 
351 bool CallAnalyzer::visitAlloca(AllocaInst &I) {
352   // Check whether inlining will turn a dynamic alloca into a static
353   // alloca and handle that case.
354   if (I.isArrayAllocation()) {
355     Constant *Size = SimplifiedValues.lookup(I.getArraySize());
356     if (auto *AllocSize = dyn_cast_or_null<ConstantInt>(Size)) {
357       const DataLayout &DL = F.getParent()->getDataLayout();
358       Type *Ty = I.getAllocatedType();
359       AllocatedSize = SaturatingMultiplyAdd(
360           AllocSize->getLimitedValue(), DL.getTypeAllocSize(Ty), AllocatedSize);
361       return Base::visitAlloca(I);
362     }
363   }
364 
365   // Accumulate the allocated size.
366   if (I.isStaticAlloca()) {
367     const DataLayout &DL = F.getParent()->getDataLayout();
368     Type *Ty = I.getAllocatedType();
369     AllocatedSize = SaturatingAdd(DL.getTypeAllocSize(Ty), AllocatedSize);
370   }
371 
372   // We will happily inline static alloca instructions.
373   if (I.isStaticAlloca())
374     return Base::visitAlloca(I);
375 
376   // FIXME: This is overly conservative. Dynamic allocas are inefficient for
377   // a variety of reasons, and so we would like to not inline them into
378   // functions which don't currently have a dynamic alloca. This simply
379   // disables inlining altogether in the presence of a dynamic alloca.
380   HasDynamicAlloca = true;
381   return false;
382 }
383 
384 bool CallAnalyzer::visitPHI(PHINode &I) {
385   // FIXME: We should potentially be tracking values through phi nodes,
386   // especially when they collapse to a single value due to deleted CFG edges
387   // during inlining.
388 
389   // FIXME: We need to propagate SROA *disabling* through phi nodes, even
390   // though we don't want to propagate it's bonuses. The idea is to disable
391   // SROA if it *might* be used in an inappropriate manner.
392 
393   // Phi nodes are always zero-cost.
394   return true;
395 }
396 
397 bool CallAnalyzer::visitGetElementPtr(GetElementPtrInst &I) {
398   Value *SROAArg;
399   DenseMap<Value *, int>::iterator CostIt;
400   bool SROACandidate =
401       lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt);
402 
403   // Try to fold GEPs of constant-offset call site argument pointers. This
404   // requires target data and inbounds GEPs.
405   if (I.isInBounds()) {
406     // Check if we have a base + offset for the pointer.
407     Value *Ptr = I.getPointerOperand();
408     std::pair<Value *, APInt> BaseAndOffset = ConstantOffsetPtrs.lookup(Ptr);
409     if (BaseAndOffset.first) {
410       // Check if the offset of this GEP is constant, and if so accumulate it
411       // into Offset.
412       if (!accumulateGEPOffset(cast<GEPOperator>(I), BaseAndOffset.second)) {
413         // Non-constant GEPs aren't folded, and disable SROA.
414         if (SROACandidate)
415           disableSROA(CostIt);
416         return isGEPFree(I);
417       }
418 
419       // Add the result as a new mapping to Base + Offset.
420       ConstantOffsetPtrs[&I] = BaseAndOffset;
421 
422       // Also handle SROA candidates here, we already know that the GEP is
423       // all-constant indexed.
424       if (SROACandidate)
425         SROAArgValues[&I] = SROAArg;
426 
427       return true;
428     }
429   }
430 
431   // Lambda to check whether a GEP's indices are all constant.
432   auto IsGEPOffsetConstant = [&](GetElementPtrInst &GEP) {
433     for (User::op_iterator I = GEP.idx_begin(), E = GEP.idx_end(); I != E; ++I)
434       if (!isa<Constant>(*I) && !SimplifiedValues.lookup(*I))
435         return false;
436     return true;
437   };
438 
439   if (IsGEPOffsetConstant(I)) {
440     if (SROACandidate)
441       SROAArgValues[&I] = SROAArg;
442 
443     // Constant GEPs are modeled as free.
444     return true;
445   }
446 
447   // Variable GEPs will require math and will disable SROA.
448   if (SROACandidate)
449     disableSROA(CostIt);
450   return isGEPFree(I);
451 }
452 
453 /// Simplify \p I if its operands are constants and update SimplifiedValues.
454 /// \p Evaluate is a callable specific to instruction type that evaluates the
455 /// instruction when all the operands are constants.
456 template <typename Callable>
457 bool CallAnalyzer::simplifyInstruction(Instruction &I, Callable Evaluate) {
458   SmallVector<Constant *, 2> COps;
459   for (Value *Op : I.operands()) {
460     Constant *COp = dyn_cast<Constant>(Op);
461     if (!COp)
462       COp = SimplifiedValues.lookup(Op);
463     if (!COp)
464       return false;
465     COps.push_back(COp);
466   }
467   auto *C = Evaluate(COps);
468   if (!C)
469     return false;
470   SimplifiedValues[&I] = C;
471   return true;
472 }
473 
474 bool CallAnalyzer::visitBitCast(BitCastInst &I) {
475   // Propagate constants through bitcasts.
476   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
477         return ConstantExpr::getBitCast(COps[0], I.getType());
478       }))
479     return true;
480 
481   // Track base/offsets through casts
482   std::pair<Value *, APInt> BaseAndOffset =
483       ConstantOffsetPtrs.lookup(I.getOperand(0));
484   // Casts don't change the offset, just wrap it up.
485   if (BaseAndOffset.first)
486     ConstantOffsetPtrs[&I] = BaseAndOffset;
487 
488   // Also look for SROA candidates here.
489   Value *SROAArg;
490   DenseMap<Value *, int>::iterator CostIt;
491   if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt))
492     SROAArgValues[&I] = SROAArg;
493 
494   // Bitcasts are always zero cost.
495   return true;
496 }
497 
498 bool CallAnalyzer::visitPtrToInt(PtrToIntInst &I) {
499   // Propagate constants through ptrtoint.
500   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
501         return ConstantExpr::getPtrToInt(COps[0], I.getType());
502       }))
503     return true;
504 
505   // Track base/offset pairs when converted to a plain integer provided the
506   // integer is large enough to represent the pointer.
507   unsigned IntegerSize = I.getType()->getScalarSizeInBits();
508   const DataLayout &DL = F.getParent()->getDataLayout();
509   if (IntegerSize >= DL.getPointerSizeInBits()) {
510     std::pair<Value *, APInt> BaseAndOffset =
511         ConstantOffsetPtrs.lookup(I.getOperand(0));
512     if (BaseAndOffset.first)
513       ConstantOffsetPtrs[&I] = BaseAndOffset;
514   }
515 
516   // This is really weird. Technically, ptrtoint will disable SROA. However,
517   // unless that ptrtoint is *used* somewhere in the live basic blocks after
518   // inlining, it will be nuked, and SROA should proceed. All of the uses which
519   // would block SROA would also block SROA if applied directly to a pointer,
520   // and so we can just add the integer in here. The only places where SROA is
521   // preserved either cannot fire on an integer, or won't in-and-of themselves
522   // disable SROA (ext) w/o some later use that we would see and disable.
523   Value *SROAArg;
524   DenseMap<Value *, int>::iterator CostIt;
525   if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt))
526     SROAArgValues[&I] = SROAArg;
527 
528   return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I);
529 }
530 
531 bool CallAnalyzer::visitIntToPtr(IntToPtrInst &I) {
532   // Propagate constants through ptrtoint.
533   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
534         return ConstantExpr::getIntToPtr(COps[0], I.getType());
535       }))
536     return true;
537 
538   // Track base/offset pairs when round-tripped through a pointer without
539   // modifications provided the integer is not too large.
540   Value *Op = I.getOperand(0);
541   unsigned IntegerSize = Op->getType()->getScalarSizeInBits();
542   const DataLayout &DL = F.getParent()->getDataLayout();
543   if (IntegerSize <= DL.getPointerSizeInBits()) {
544     std::pair<Value *, APInt> BaseAndOffset = ConstantOffsetPtrs.lookup(Op);
545     if (BaseAndOffset.first)
546       ConstantOffsetPtrs[&I] = BaseAndOffset;
547   }
548 
549   // "Propagate" SROA here in the same manner as we do for ptrtoint above.
550   Value *SROAArg;
551   DenseMap<Value *, int>::iterator CostIt;
552   if (lookupSROAArgAndCost(Op, SROAArg, CostIt))
553     SROAArgValues[&I] = SROAArg;
554 
555   return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I);
556 }
557 
558 bool CallAnalyzer::visitCastInst(CastInst &I) {
559   // Propagate constants through ptrtoint.
560   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
561         return ConstantExpr::getCast(I.getOpcode(), COps[0], I.getType());
562       }))
563     return true;
564 
565   // Disable SROA in the face of arbitrary casts we don't whitelist elsewhere.
566   disableSROA(I.getOperand(0));
567 
568   return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I);
569 }
570 
571 bool CallAnalyzer::visitUnaryInstruction(UnaryInstruction &I) {
572   Value *Operand = I.getOperand(0);
573   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
574         const DataLayout &DL = F.getParent()->getDataLayout();
575         return ConstantFoldInstOperands(&I, COps[0], DL);
576       }))
577     return true;
578 
579   // Disable any SROA on the argument to arbitrary unary operators.
580   disableSROA(Operand);
581 
582   return false;
583 }
584 
585 bool CallAnalyzer::paramHasAttr(Argument *A, Attribute::AttrKind Attr) {
586   return CandidateCS.paramHasAttr(A->getArgNo(), Attr);
587 }
588 
589 bool CallAnalyzer::isKnownNonNullInCallee(Value *V) {
590   // Does the *call site* have the NonNull attribute set on an argument?  We
591   // use the attribute on the call site to memoize any analysis done in the
592   // caller. This will also trip if the callee function has a non-null
593   // parameter attribute, but that's a less interesting case because hopefully
594   // the callee would already have been simplified based on that.
595   if (Argument *A = dyn_cast<Argument>(V))
596     if (paramHasAttr(A, Attribute::NonNull))
597       return true;
598 
599   // Is this an alloca in the caller?  This is distinct from the attribute case
600   // above because attributes aren't updated within the inliner itself and we
601   // always want to catch the alloca derived case.
602   if (isAllocaDerivedArg(V))
603     // We can actually predict the result of comparisons between an
604     // alloca-derived value and null. Note that this fires regardless of
605     // SROA firing.
606     return true;
607 
608   return false;
609 }
610 
611 bool CallAnalyzer::allowSizeGrowth(CallSite CS) {
612   // If the normal destination of the invoke or the parent block of the call
613   // site is unreachable-terminated, there is little point in inlining this
614   // unless there is literally zero cost.
615   // FIXME: Note that it is possible that an unreachable-terminated block has a
616   // hot entry. For example, in below scenario inlining hot_call_X() may be
617   // beneficial :
618   // main() {
619   //   hot_call_1();
620   //   ...
621   //   hot_call_N()
622   //   exit(0);
623   // }
624   // For now, we are not handling this corner case here as it is rare in real
625   // code. In future, we should elaborate this based on BPI and BFI in more
626   // general threshold adjusting heuristics in updateThreshold().
627   Instruction *Instr = CS.getInstruction();
628   if (InvokeInst *II = dyn_cast<InvokeInst>(Instr)) {
629     if (isa<UnreachableInst>(II->getNormalDest()->getTerminator()))
630       return false;
631   } else if (isa<UnreachableInst>(Instr->getParent()->getTerminator()))
632     return false;
633 
634   return true;
635 }
636 
637 void CallAnalyzer::updateThreshold(CallSite CS, Function &Callee) {
638   // If no size growth is allowed for this inlining, set Threshold to 0.
639   if (!allowSizeGrowth(CS)) {
640     Threshold = 0;
641     return;
642   }
643 
644   Function *Caller = CS.getCaller();
645 
646   // return min(A, B) if B is valid.
647   auto MinIfValid = [](int A, Optional<int> B) {
648     return B ? std::min(A, B.getValue()) : A;
649   };
650 
651   // return max(A, B) if B is valid.
652   auto MaxIfValid = [](int A, Optional<int> B) {
653     return B ? std::max(A, B.getValue()) : A;
654   };
655 
656   // Use the OptMinSizeThreshold or OptSizeThreshold knob if they are available
657   // and reduce the threshold if the caller has the necessary attribute.
658   if (Caller->optForMinSize())
659     Threshold = MinIfValid(Threshold, Params.OptMinSizeThreshold);
660   else if (Caller->optForSize())
661     Threshold = MinIfValid(Threshold, Params.OptSizeThreshold);
662 
663   // Adjust the threshold based on inlinehint attribute and profile based
664   // hotness information if the caller does not have MinSize attribute.
665   if (!Caller->optForMinSize()) {
666     if (Callee.hasFnAttribute(Attribute::InlineHint))
667       Threshold = MaxIfValid(Threshold, Params.HintThreshold);
668     if (PSI) {
669       BlockFrequencyInfo *CallerBFI = GetBFI ? &((*GetBFI)(*Caller)) : nullptr;
670       if (PSI->isHotCallSite(CS, CallerBFI)) {
671         DEBUG(dbgs() << "Hot callsite.\n");
672         Threshold = Params.HotCallSiteThreshold.getValue();
673       } else if (PSI->isFunctionEntryHot(&Callee)) {
674         DEBUG(dbgs() << "Hot callee.\n");
675         // If callsite hotness can not be determined, we may still know
676         // that the callee is hot and treat it as a weaker hint for threshold
677         // increase.
678         Threshold = MaxIfValid(Threshold, Params.HintThreshold);
679       } else if (PSI->isColdCallSite(CS, CallerBFI)) {
680         DEBUG(dbgs() << "Cold callsite.\n");
681         Threshold = MinIfValid(Threshold, Params.ColdCallSiteThreshold);
682       } else if (PSI->isFunctionEntryCold(&Callee)) {
683         DEBUG(dbgs() << "Cold callee.\n");
684         Threshold = MinIfValid(Threshold, Params.ColdThreshold);
685       }
686     }
687   }
688 
689   // Finally, take the target-specific inlining threshold multiplier into
690   // account.
691   Threshold *= TTI.getInliningThresholdMultiplier();
692 }
693 
694 bool CallAnalyzer::visitCmpInst(CmpInst &I) {
695   Value *LHS = I.getOperand(0), *RHS = I.getOperand(1);
696   // First try to handle simplified comparisons.
697   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
698         return ConstantExpr::getCompare(I.getPredicate(), COps[0], COps[1]);
699       }))
700     return true;
701 
702   if (I.getOpcode() == Instruction::FCmp)
703     return false;
704 
705   // Otherwise look for a comparison between constant offset pointers with
706   // a common base.
707   Value *LHSBase, *RHSBase;
708   APInt LHSOffset, RHSOffset;
709   std::tie(LHSBase, LHSOffset) = ConstantOffsetPtrs.lookup(LHS);
710   if (LHSBase) {
711     std::tie(RHSBase, RHSOffset) = ConstantOffsetPtrs.lookup(RHS);
712     if (RHSBase && LHSBase == RHSBase) {
713       // We have common bases, fold the icmp to a constant based on the
714       // offsets.
715       Constant *CLHS = ConstantInt::get(LHS->getContext(), LHSOffset);
716       Constant *CRHS = ConstantInt::get(RHS->getContext(), RHSOffset);
717       if (Constant *C = ConstantExpr::getICmp(I.getPredicate(), CLHS, CRHS)) {
718         SimplifiedValues[&I] = C;
719         ++NumConstantPtrCmps;
720         return true;
721       }
722     }
723   }
724 
725   // If the comparison is an equality comparison with null, we can simplify it
726   // if we know the value (argument) can't be null
727   if (I.isEquality() && isa<ConstantPointerNull>(I.getOperand(1)) &&
728       isKnownNonNullInCallee(I.getOperand(0))) {
729     bool IsNotEqual = I.getPredicate() == CmpInst::ICMP_NE;
730     SimplifiedValues[&I] = IsNotEqual ? ConstantInt::getTrue(I.getType())
731                                       : ConstantInt::getFalse(I.getType());
732     return true;
733   }
734   // Finally check for SROA candidates in comparisons.
735   Value *SROAArg;
736   DenseMap<Value *, int>::iterator CostIt;
737   if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt)) {
738     if (isa<ConstantPointerNull>(I.getOperand(1))) {
739       accumulateSROACost(CostIt, InlineConstants::InstrCost);
740       return true;
741     }
742 
743     disableSROA(CostIt);
744   }
745 
746   return false;
747 }
748 
749 bool CallAnalyzer::visitSub(BinaryOperator &I) {
750   // Try to handle a special case: we can fold computing the difference of two
751   // constant-related pointers.
752   Value *LHS = I.getOperand(0), *RHS = I.getOperand(1);
753   Value *LHSBase, *RHSBase;
754   APInt LHSOffset, RHSOffset;
755   std::tie(LHSBase, LHSOffset) = ConstantOffsetPtrs.lookup(LHS);
756   if (LHSBase) {
757     std::tie(RHSBase, RHSOffset) = ConstantOffsetPtrs.lookup(RHS);
758     if (RHSBase && LHSBase == RHSBase) {
759       // We have common bases, fold the subtract to a constant based on the
760       // offsets.
761       Constant *CLHS = ConstantInt::get(LHS->getContext(), LHSOffset);
762       Constant *CRHS = ConstantInt::get(RHS->getContext(), RHSOffset);
763       if (Constant *C = ConstantExpr::getSub(CLHS, CRHS)) {
764         SimplifiedValues[&I] = C;
765         ++NumConstantPtrDiffs;
766         return true;
767       }
768     }
769   }
770 
771   // Otherwise, fall back to the generic logic for simplifying and handling
772   // instructions.
773   return Base::visitSub(I);
774 }
775 
776 bool CallAnalyzer::visitBinaryOperator(BinaryOperator &I) {
777   Value *LHS = I.getOperand(0), *RHS = I.getOperand(1);
778   auto Evaluate = [&](SmallVectorImpl<Constant *> &COps) {
779     Value *SimpleV = nullptr;
780     const DataLayout &DL = F.getParent()->getDataLayout();
781     if (auto FI = dyn_cast<FPMathOperator>(&I))
782       SimpleV = SimplifyFPBinOp(I.getOpcode(), COps[0], COps[1],
783                                 FI->getFastMathFlags(), DL);
784     else
785       SimpleV = SimplifyBinOp(I.getOpcode(), COps[0], COps[1], DL);
786     return dyn_cast_or_null<Constant>(SimpleV);
787   };
788 
789   if (simplifyInstruction(I, Evaluate))
790     return true;
791 
792   // Disable any SROA on arguments to arbitrary, unsimplified binary operators.
793   disableSROA(LHS);
794   disableSROA(RHS);
795 
796   return false;
797 }
798 
799 bool CallAnalyzer::visitLoad(LoadInst &I) {
800   Value *SROAArg;
801   DenseMap<Value *, int>::iterator CostIt;
802   if (lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt)) {
803     if (I.isSimple()) {
804       accumulateSROACost(CostIt, InlineConstants::InstrCost);
805       return true;
806     }
807 
808     disableSROA(CostIt);
809   }
810 
811   return false;
812 }
813 
814 bool CallAnalyzer::visitStore(StoreInst &I) {
815   Value *SROAArg;
816   DenseMap<Value *, int>::iterator CostIt;
817   if (lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt)) {
818     if (I.isSimple()) {
819       accumulateSROACost(CostIt, InlineConstants::InstrCost);
820       return true;
821     }
822 
823     disableSROA(CostIt);
824   }
825 
826   return false;
827 }
828 
829 bool CallAnalyzer::visitExtractValue(ExtractValueInst &I) {
830   // Constant folding for extract value is trivial.
831   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
832         return ConstantExpr::getExtractValue(COps[0], I.getIndices());
833       }))
834     return true;
835 
836   // SROA can look through these but give them a cost.
837   return false;
838 }
839 
840 bool CallAnalyzer::visitInsertValue(InsertValueInst &I) {
841   // Constant folding for insert value is trivial.
842   if (simplifyInstruction(I, [&](SmallVectorImpl<Constant *> &COps) {
843         return ConstantExpr::getInsertValue(/*AggregateOperand*/ COps[0],
844                                             /*InsertedValueOperand*/ COps[1],
845                                             I.getIndices());
846       }))
847     return true;
848 
849   // SROA can look through these but give them a cost.
850   return false;
851 }
852 
853 /// \brief Try to simplify a call site.
854 ///
855 /// Takes a concrete function and callsite and tries to actually simplify it by
856 /// analyzing the arguments and call itself with instsimplify. Returns true if
857 /// it has simplified the callsite to some other entity (a constant), making it
858 /// free.
859 bool CallAnalyzer::simplifyCallSite(Function *F, CallSite CS) {
860   // FIXME: Using the instsimplify logic directly for this is inefficient
861   // because we have to continually rebuild the argument list even when no
862   // simplifications can be performed. Until that is fixed with remapping
863   // inside of instsimplify, directly constant fold calls here.
864   if (!canConstantFoldCallTo(F))
865     return false;
866 
867   // Try to re-map the arguments to constants.
868   SmallVector<Constant *, 4> ConstantArgs;
869   ConstantArgs.reserve(CS.arg_size());
870   for (CallSite::arg_iterator I = CS.arg_begin(), E = CS.arg_end(); I != E;
871        ++I) {
872     Constant *C = dyn_cast<Constant>(*I);
873     if (!C)
874       C = dyn_cast_or_null<Constant>(SimplifiedValues.lookup(*I));
875     if (!C)
876       return false; // This argument doesn't map to a constant.
877 
878     ConstantArgs.push_back(C);
879   }
880   if (Constant *C = ConstantFoldCall(F, ConstantArgs)) {
881     SimplifiedValues[CS.getInstruction()] = C;
882     return true;
883   }
884 
885   return false;
886 }
887 
888 bool CallAnalyzer::visitCallSite(CallSite CS) {
889   if (CS.hasFnAttr(Attribute::ReturnsTwice) &&
890       !F.hasFnAttribute(Attribute::ReturnsTwice)) {
891     // This aborts the entire analysis.
892     ExposesReturnsTwice = true;
893     return false;
894   }
895   if (CS.isCall() && cast<CallInst>(CS.getInstruction())->cannotDuplicate())
896     ContainsNoDuplicateCall = true;
897 
898   if (Function *F = CS.getCalledFunction()) {
899     // When we have a concrete function, first try to simplify it directly.
900     if (simplifyCallSite(F, CS))
901       return true;
902 
903     // Next check if it is an intrinsic we know about.
904     // FIXME: Lift this into part of the InstVisitor.
905     if (IntrinsicInst *II = dyn_cast<IntrinsicInst>(CS.getInstruction())) {
906       switch (II->getIntrinsicID()) {
907       default:
908         return Base::visitCallSite(CS);
909 
910       case Intrinsic::load_relative:
911         // This is normally lowered to 4 LLVM instructions.
912         Cost += 3 * InlineConstants::InstrCost;
913         return false;
914 
915       case Intrinsic::memset:
916       case Intrinsic::memcpy:
917       case Intrinsic::memmove:
918         // SROA can usually chew through these intrinsics, but they aren't free.
919         return false;
920       case Intrinsic::localescape:
921         HasFrameEscape = true;
922         return false;
923       }
924     }
925 
926     if (F == CS.getInstruction()->getParent()->getParent()) {
927       // This flag will fully abort the analysis, so don't bother with anything
928       // else.
929       IsRecursiveCall = true;
930       return false;
931     }
932 
933     if (TTI.isLoweredToCall(F)) {
934       // We account for the average 1 instruction per call argument setup
935       // here.
936       Cost += CS.arg_size() * InlineConstants::InstrCost;
937 
938       // Everything other than inline ASM will also have a significant cost
939       // merely from making the call.
940       if (!isa<InlineAsm>(CS.getCalledValue()))
941         Cost += InlineConstants::CallPenalty;
942     }
943 
944     return Base::visitCallSite(CS);
945   }
946 
947   // Otherwise we're in a very special case -- an indirect function call. See
948   // if we can be particularly clever about this.
949   Value *Callee = CS.getCalledValue();
950 
951   // First, pay the price of the argument setup. We account for the average
952   // 1 instruction per call argument setup here.
953   Cost += CS.arg_size() * InlineConstants::InstrCost;
954 
955   // Next, check if this happens to be an indirect function call to a known
956   // function in this inline context. If not, we've done all we can.
957   Function *F = dyn_cast_or_null<Function>(SimplifiedValues.lookup(Callee));
958   if (!F)
959     return Base::visitCallSite(CS);
960 
961   // If we have a constant that we are calling as a function, we can peer
962   // through it and see the function target. This happens not infrequently
963   // during devirtualization and so we want to give it a hefty bonus for
964   // inlining, but cap that bonus in the event that inlining wouldn't pan
965   // out. Pretend to inline the function, with a custom threshold.
966   auto IndirectCallParams = Params;
967   IndirectCallParams.DefaultThreshold = InlineConstants::IndirectCallThreshold;
968   CallAnalyzer CA(TTI, GetAssumptionCache, GetBFI, PSI, *F, CS,
969                   IndirectCallParams);
970   if (CA.analyzeCall(CS)) {
971     // We were able to inline the indirect call! Subtract the cost from the
972     // threshold to get the bonus we want to apply, but don't go below zero.
973     Cost -= std::max(0, CA.getThreshold() - CA.getCost());
974   }
975 
976   return Base::visitCallSite(CS);
977 }
978 
979 bool CallAnalyzer::visitReturnInst(ReturnInst &RI) {
980   // At least one return instruction will be free after inlining.
981   bool Free = !HasReturn;
982   HasReturn = true;
983   return Free;
984 }
985 
986 bool CallAnalyzer::visitBranchInst(BranchInst &BI) {
987   // We model unconditional branches as essentially free -- they really
988   // shouldn't exist at all, but handling them makes the behavior of the
989   // inliner more regular and predictable. Interestingly, conditional branches
990   // which will fold away are also free.
991   return BI.isUnconditional() || isa<ConstantInt>(BI.getCondition()) ||
992          dyn_cast_or_null<ConstantInt>(
993              SimplifiedValues.lookup(BI.getCondition()));
994 }
995 
996 bool CallAnalyzer::visitSwitchInst(SwitchInst &SI) {
997   // We model unconditional switches as free, see the comments on handling
998   // branches.
999   if (isa<ConstantInt>(SI.getCondition()))
1000     return true;
1001   if (Value *V = SimplifiedValues.lookup(SI.getCondition()))
1002     if (isa<ConstantInt>(V))
1003       return true;
1004 
1005   // Otherwise, we need to accumulate a cost proportional to the number of
1006   // distinct successor blocks. This fan-out in the CFG cannot be represented
1007   // for free even if we can represent the core switch as a jumptable that
1008   // takes a single instruction.
1009   //
1010   // NB: We convert large switches which are just used to initialize large phi
1011   // nodes to lookup tables instead in simplify-cfg, so this shouldn't prevent
1012   // inlining those. It will prevent inlining in cases where the optimization
1013   // does not (yet) fire.
1014   SmallPtrSet<BasicBlock *, 8> SuccessorBlocks;
1015   SuccessorBlocks.insert(SI.getDefaultDest());
1016   for (auto Case : SI.cases())
1017     SuccessorBlocks.insert(Case.getCaseSuccessor());
1018   // Add cost corresponding to the number of distinct destinations. The first
1019   // we model as free because of fallthrough.
1020   Cost += (SuccessorBlocks.size() - 1) * InlineConstants::InstrCost;
1021   return false;
1022 }
1023 
1024 bool CallAnalyzer::visitIndirectBrInst(IndirectBrInst &IBI) {
1025   // We never want to inline functions that contain an indirectbr.  This is
1026   // incorrect because all the blockaddress's (in static global initializers
1027   // for example) would be referring to the original function, and this
1028   // indirect jump would jump from the inlined copy of the function into the
1029   // original function which is extremely undefined behavior.
1030   // FIXME: This logic isn't really right; we can safely inline functions with
1031   // indirectbr's as long as no other function or global references the
1032   // blockaddress of a block within the current function.
1033   HasIndirectBr = true;
1034   return false;
1035 }
1036 
1037 bool CallAnalyzer::visitResumeInst(ResumeInst &RI) {
1038   // FIXME: It's not clear that a single instruction is an accurate model for
1039   // the inline cost of a resume instruction.
1040   return false;
1041 }
1042 
1043 bool CallAnalyzer::visitCleanupReturnInst(CleanupReturnInst &CRI) {
1044   // FIXME: It's not clear that a single instruction is an accurate model for
1045   // the inline cost of a cleanupret instruction.
1046   return false;
1047 }
1048 
1049 bool CallAnalyzer::visitCatchReturnInst(CatchReturnInst &CRI) {
1050   // FIXME: It's not clear that a single instruction is an accurate model for
1051   // the inline cost of a catchret instruction.
1052   return false;
1053 }
1054 
1055 bool CallAnalyzer::visitUnreachableInst(UnreachableInst &I) {
1056   // FIXME: It might be reasonably to discount the cost of instructions leading
1057   // to unreachable as they have the lowest possible impact on both runtime and
1058   // code size.
1059   return true; // No actual code is needed for unreachable.
1060 }
1061 
1062 bool CallAnalyzer::visitInstruction(Instruction &I) {
1063   // Some instructions are free. All of the free intrinsics can also be
1064   // handled by SROA, etc.
1065   if (TargetTransformInfo::TCC_Free == TTI.getUserCost(&I))
1066     return true;
1067 
1068   // We found something we don't understand or can't handle. Mark any SROA-able
1069   // values in the operand list as no longer viable.
1070   for (User::op_iterator OI = I.op_begin(), OE = I.op_end(); OI != OE; ++OI)
1071     disableSROA(*OI);
1072 
1073   return false;
1074 }
1075 
1076 /// \brief Analyze a basic block for its contribution to the inline cost.
1077 ///
1078 /// This method walks the analyzer over every instruction in the given basic
1079 /// block and accounts for their cost during inlining at this callsite. It
1080 /// aborts early if the threshold has been exceeded or an impossible to inline
1081 /// construct has been detected. It returns false if inlining is no longer
1082 /// viable, and true if inlining remains viable.
1083 bool CallAnalyzer::analyzeBlock(BasicBlock *BB,
1084                                 SmallPtrSetImpl<const Value *> &EphValues) {
1085   for (BasicBlock::iterator I = BB->begin(), E = BB->end(); I != E; ++I) {
1086     // FIXME: Currently, the number of instructions in a function regardless of
1087     // our ability to simplify them during inline to constants or dead code,
1088     // are actually used by the vector bonus heuristic. As long as that's true,
1089     // we have to special case debug intrinsics here to prevent differences in
1090     // inlining due to debug symbols. Eventually, the number of unsimplified
1091     // instructions shouldn't factor into the cost computation, but until then,
1092     // hack around it here.
1093     if (isa<DbgInfoIntrinsic>(I))
1094       continue;
1095 
1096     // Skip ephemeral values.
1097     if (EphValues.count(&*I))
1098       continue;
1099 
1100     ++NumInstructions;
1101     if (isa<ExtractElementInst>(I) || I->getType()->isVectorTy())
1102       ++NumVectorInstructions;
1103 
1104     // If the instruction is floating point, and the target says this operation
1105     // is expensive or the function has the "use-soft-float" attribute, this may
1106     // eventually become a library call. Treat the cost as such.
1107     if (I->getType()->isFloatingPointTy()) {
1108       bool hasSoftFloatAttr = false;
1109 
1110       // If the function has the "use-soft-float" attribute, mark it as
1111       // expensive.
1112       if (F.hasFnAttribute("use-soft-float")) {
1113         Attribute Attr = F.getFnAttribute("use-soft-float");
1114         StringRef Val = Attr.getValueAsString();
1115         if (Val == "true")
1116           hasSoftFloatAttr = true;
1117       }
1118 
1119       if (TTI.getFPOpCost(I->getType()) == TargetTransformInfo::TCC_Expensive ||
1120           hasSoftFloatAttr)
1121         Cost += InlineConstants::CallPenalty;
1122     }
1123 
1124     // If the instruction simplified to a constant, there is no cost to this
1125     // instruction. Visit the instructions using our InstVisitor to account for
1126     // all of the per-instruction logic. The visit tree returns true if we
1127     // consumed the instruction in any way, and false if the instruction's base
1128     // cost should count against inlining.
1129     if (Base::visit(&*I))
1130       ++NumInstructionsSimplified;
1131     else
1132       Cost += InlineConstants::InstrCost;
1133 
1134     // If the visit this instruction detected an uninlinable pattern, abort.
1135     if (IsRecursiveCall || ExposesReturnsTwice || HasDynamicAlloca ||
1136         HasIndirectBr || HasFrameEscape)
1137       return false;
1138 
1139     // If the caller is a recursive function then we don't want to inline
1140     // functions which allocate a lot of stack space because it would increase
1141     // the caller stack usage dramatically.
1142     if (IsCallerRecursive &&
1143         AllocatedSize > InlineConstants::TotalAllocaSizeRecursiveCaller)
1144       return false;
1145 
1146     // Check if we've past the maximum possible threshold so we don't spin in
1147     // huge basic blocks that will never inline.
1148     if (Cost > Threshold)
1149       return false;
1150   }
1151 
1152   return true;
1153 }
1154 
1155 /// \brief Compute the base pointer and cumulative constant offsets for V.
1156 ///
1157 /// This strips all constant offsets off of V, leaving it the base pointer, and
1158 /// accumulates the total constant offset applied in the returned constant. It
1159 /// returns 0 if V is not a pointer, and returns the constant '0' if there are
1160 /// no constant offsets applied.
1161 ConstantInt *CallAnalyzer::stripAndComputeInBoundsConstantOffsets(Value *&V) {
1162   if (!V->getType()->isPointerTy())
1163     return nullptr;
1164 
1165   const DataLayout &DL = F.getParent()->getDataLayout();
1166   unsigned IntPtrWidth = DL.getPointerSizeInBits();
1167   APInt Offset = APInt::getNullValue(IntPtrWidth);
1168 
1169   // Even though we don't look through PHI nodes, we could be called on an
1170   // instruction in an unreachable block, which may be on a cycle.
1171   SmallPtrSet<Value *, 4> Visited;
1172   Visited.insert(V);
1173   do {
1174     if (GEPOperator *GEP = dyn_cast<GEPOperator>(V)) {
1175       if (!GEP->isInBounds() || !accumulateGEPOffset(*GEP, Offset))
1176         return nullptr;
1177       V = GEP->getPointerOperand();
1178     } else if (Operator::getOpcode(V) == Instruction::BitCast) {
1179       V = cast<Operator>(V)->getOperand(0);
1180     } else if (GlobalAlias *GA = dyn_cast<GlobalAlias>(V)) {
1181       if (GA->isInterposable())
1182         break;
1183       V = GA->getAliasee();
1184     } else {
1185       break;
1186     }
1187     assert(V->getType()->isPointerTy() && "Unexpected operand type!");
1188   } while (Visited.insert(V).second);
1189 
1190   Type *IntPtrTy = DL.getIntPtrType(V->getContext());
1191   return cast<ConstantInt>(ConstantInt::get(IntPtrTy, Offset));
1192 }
1193 
1194 /// \brief Analyze a call site for potential inlining.
1195 ///
1196 /// Returns true if inlining this call is viable, and false if it is not
1197 /// viable. It computes the cost and adjusts the threshold based on numerous
1198 /// factors and heuristics. If this method returns false but the computed cost
1199 /// is below the computed threshold, then inlining was forcibly disabled by
1200 /// some artifact of the routine.
1201 bool CallAnalyzer::analyzeCall(CallSite CS) {
1202   ++NumCallsAnalyzed;
1203 
1204   // Perform some tweaks to the cost and threshold based on the direct
1205   // callsite information.
1206 
1207   // We want to more aggressively inline vector-dense kernels, so up the
1208   // threshold, and we'll lower it if the % of vector instructions gets too
1209   // low. Note that these bonuses are some what arbitrary and evolved over time
1210   // by accident as much as because they are principled bonuses.
1211   //
1212   // FIXME: It would be nice to remove all such bonuses. At least it would be
1213   // nice to base the bonus values on something more scientific.
1214   assert(NumInstructions == 0);
1215   assert(NumVectorInstructions == 0);
1216 
1217   // Update the threshold based on callsite properties
1218   updateThreshold(CS, F);
1219 
1220   FiftyPercentVectorBonus = 3 * Threshold / 2;
1221   TenPercentVectorBonus = 3 * Threshold / 4;
1222   const DataLayout &DL = F.getParent()->getDataLayout();
1223 
1224   // Track whether the post-inlining function would have more than one basic
1225   // block. A single basic block is often intended for inlining. Balloon the
1226   // threshold by 50% until we pass the single-BB phase.
1227   bool SingleBB = true;
1228   int SingleBBBonus = Threshold / 2;
1229 
1230   // Speculatively apply all possible bonuses to Threshold. If cost exceeds
1231   // this Threshold any time, and cost cannot decrease, we can stop processing
1232   // the rest of the function body.
1233   Threshold += (SingleBBBonus + FiftyPercentVectorBonus);
1234 
1235   // Give out bonuses per argument, as the instructions setting them up will
1236   // be gone after inlining.
1237   for (unsigned I = 0, E = CS.arg_size(); I != E; ++I) {
1238     if (CS.isByValArgument(I)) {
1239       // We approximate the number of loads and stores needed by dividing the
1240       // size of the byval type by the target's pointer size.
1241       PointerType *PTy = cast<PointerType>(CS.getArgument(I)->getType());
1242       unsigned TypeSize = DL.getTypeSizeInBits(PTy->getElementType());
1243       unsigned PointerSize = DL.getPointerSizeInBits();
1244       // Ceiling division.
1245       unsigned NumStores = (TypeSize + PointerSize - 1) / PointerSize;
1246 
1247       // If it generates more than 8 stores it is likely to be expanded as an
1248       // inline memcpy so we take that as an upper bound. Otherwise we assume
1249       // one load and one store per word copied.
1250       // FIXME: The maxStoresPerMemcpy setting from the target should be used
1251       // here instead of a magic number of 8, but it's not available via
1252       // DataLayout.
1253       NumStores = std::min(NumStores, 8U);
1254 
1255       Cost -= 2 * NumStores * InlineConstants::InstrCost;
1256     } else {
1257       // For non-byval arguments subtract off one instruction per call
1258       // argument.
1259       Cost -= InlineConstants::InstrCost;
1260     }
1261   }
1262   // The call instruction also disappears after inlining.
1263   Cost -= InlineConstants::InstrCost + InlineConstants::CallPenalty;
1264 
1265   // If there is only one call of the function, and it has internal linkage,
1266   // the cost of inlining it drops dramatically.
1267   bool OnlyOneCallAndLocalLinkage =
1268       F.hasLocalLinkage() && F.hasOneUse() && &F == CS.getCalledFunction();
1269   if (OnlyOneCallAndLocalLinkage)
1270     Cost -= InlineConstants::LastCallToStaticBonus;
1271 
1272   // If this function uses the coldcc calling convention, prefer not to inline
1273   // it.
1274   if (F.getCallingConv() == CallingConv::Cold)
1275     Cost += InlineConstants::ColdccPenalty;
1276 
1277   // Check if we're done. This can happen due to bonuses and penalties.
1278   if (Cost > Threshold)
1279     return false;
1280 
1281   if (F.empty())
1282     return true;
1283 
1284   Function *Caller = CS.getInstruction()->getParent()->getParent();
1285   // Check if the caller function is recursive itself.
1286   for (User *U : Caller->users()) {
1287     CallSite Site(U);
1288     if (!Site)
1289       continue;
1290     Instruction *I = Site.getInstruction();
1291     if (I->getParent()->getParent() == Caller) {
1292       IsCallerRecursive = true;
1293       break;
1294     }
1295   }
1296 
1297   // Populate our simplified values by mapping from function arguments to call
1298   // arguments with known important simplifications.
1299   CallSite::arg_iterator CAI = CS.arg_begin();
1300   for (Function::arg_iterator FAI = F.arg_begin(), FAE = F.arg_end();
1301        FAI != FAE; ++FAI, ++CAI) {
1302     assert(CAI != CS.arg_end());
1303     if (Constant *C = dyn_cast<Constant>(CAI))
1304       SimplifiedValues[&*FAI] = C;
1305 
1306     Value *PtrArg = *CAI;
1307     if (ConstantInt *C = stripAndComputeInBoundsConstantOffsets(PtrArg)) {
1308       ConstantOffsetPtrs[&*FAI] = std::make_pair(PtrArg, C->getValue());
1309 
1310       // We can SROA any pointer arguments derived from alloca instructions.
1311       if (isa<AllocaInst>(PtrArg)) {
1312         SROAArgValues[&*FAI] = PtrArg;
1313         SROAArgCosts[PtrArg] = 0;
1314       }
1315     }
1316   }
1317   NumConstantArgs = SimplifiedValues.size();
1318   NumConstantOffsetPtrArgs = ConstantOffsetPtrs.size();
1319   NumAllocaArgs = SROAArgValues.size();
1320 
1321   // FIXME: If a caller has multiple calls to a callee, we end up recomputing
1322   // the ephemeral values multiple times (and they're completely determined by
1323   // the callee, so this is purely duplicate work).
1324   SmallPtrSet<const Value *, 32> EphValues;
1325   CodeMetrics::collectEphemeralValues(&F, &GetAssumptionCache(F), EphValues);
1326 
1327   // The worklist of live basic blocks in the callee *after* inlining. We avoid
1328   // adding basic blocks of the callee which can be proven to be dead for this
1329   // particular call site in order to get more accurate cost estimates. This
1330   // requires a somewhat heavyweight iteration pattern: we need to walk the
1331   // basic blocks in a breadth-first order as we insert live successors. To
1332   // accomplish this, prioritizing for small iterations because we exit after
1333   // crossing our threshold, we use a small-size optimized SetVector.
1334   typedef SetVector<BasicBlock *, SmallVector<BasicBlock *, 16>,
1335                     SmallPtrSet<BasicBlock *, 16>>
1336       BBSetVector;
1337   BBSetVector BBWorklist;
1338   BBWorklist.insert(&F.getEntryBlock());
1339   // Note that we *must not* cache the size, this loop grows the worklist.
1340   for (unsigned Idx = 0; Idx != BBWorklist.size(); ++Idx) {
1341     // Bail out the moment we cross the threshold. This means we'll under-count
1342     // the cost, but only when undercounting doesn't matter.
1343     if (Cost > Threshold)
1344       break;
1345 
1346     BasicBlock *BB = BBWorklist[Idx];
1347     if (BB->empty())
1348       continue;
1349 
1350     // Disallow inlining a blockaddress. A blockaddress only has defined
1351     // behavior for an indirect branch in the same function, and we do not
1352     // currently support inlining indirect branches. But, the inliner may not
1353     // see an indirect branch that ends up being dead code at a particular call
1354     // site. If the blockaddress escapes the function, e.g., via a global
1355     // variable, inlining may lead to an invalid cross-function reference.
1356     if (BB->hasAddressTaken())
1357       return false;
1358 
1359     // Analyze the cost of this block. If we blow through the threshold, this
1360     // returns false, and we can bail on out.
1361     if (!analyzeBlock(BB, EphValues))
1362       return false;
1363 
1364     TerminatorInst *TI = BB->getTerminator();
1365 
1366     // Add in the live successors by first checking whether we have terminator
1367     // that may be simplified based on the values simplified by this call.
1368     if (BranchInst *BI = dyn_cast<BranchInst>(TI)) {
1369       if (BI->isConditional()) {
1370         Value *Cond = BI->getCondition();
1371         if (ConstantInt *SimpleCond =
1372                 dyn_cast_or_null<ConstantInt>(SimplifiedValues.lookup(Cond))) {
1373           BBWorklist.insert(BI->getSuccessor(SimpleCond->isZero() ? 1 : 0));
1374           continue;
1375         }
1376       }
1377     } else if (SwitchInst *SI = dyn_cast<SwitchInst>(TI)) {
1378       Value *Cond = SI->getCondition();
1379       if (ConstantInt *SimpleCond =
1380               dyn_cast_or_null<ConstantInt>(SimplifiedValues.lookup(Cond))) {
1381         BBWorklist.insert(SI->findCaseValue(SimpleCond)->getCaseSuccessor());
1382         continue;
1383       }
1384     }
1385 
1386     // If we're unable to select a particular successor, just count all of
1387     // them.
1388     for (unsigned TIdx = 0, TSize = TI->getNumSuccessors(); TIdx != TSize;
1389          ++TIdx)
1390       BBWorklist.insert(TI->getSuccessor(TIdx));
1391 
1392     // If we had any successors at this point, than post-inlining is likely to
1393     // have them as well. Note that we assume any basic blocks which existed
1394     // due to branches or switches which folded above will also fold after
1395     // inlining.
1396     if (SingleBB && TI->getNumSuccessors() > 1) {
1397       // Take off the bonus we applied to the threshold.
1398       Threshold -= SingleBBBonus;
1399       SingleBB = false;
1400     }
1401   }
1402 
1403   // If this is a noduplicate call, we can still inline as long as
1404   // inlining this would cause the removal of the caller (so the instruction
1405   // is not actually duplicated, just moved).
1406   if (!OnlyOneCallAndLocalLinkage && ContainsNoDuplicateCall)
1407     return false;
1408 
1409   // We applied the maximum possible vector bonus at the beginning. Now,
1410   // subtract the excess bonus, if any, from the Threshold before
1411   // comparing against Cost.
1412   if (NumVectorInstructions <= NumInstructions / 10)
1413     Threshold -= FiftyPercentVectorBonus;
1414   else if (NumVectorInstructions <= NumInstructions / 2)
1415     Threshold -= (FiftyPercentVectorBonus - TenPercentVectorBonus);
1416 
1417   return Cost < std::max(1, Threshold);
1418 }
1419 
1420 #if !defined(NDEBUG) || defined(LLVM_ENABLE_DUMP)
1421 /// \brief Dump stats about this call's analysis.
1422 LLVM_DUMP_METHOD void CallAnalyzer::dump() {
1423 #define DEBUG_PRINT_STAT(x) dbgs() << "      " #x ": " << x << "\n"
1424   DEBUG_PRINT_STAT(NumConstantArgs);
1425   DEBUG_PRINT_STAT(NumConstantOffsetPtrArgs);
1426   DEBUG_PRINT_STAT(NumAllocaArgs);
1427   DEBUG_PRINT_STAT(NumConstantPtrCmps);
1428   DEBUG_PRINT_STAT(NumConstantPtrDiffs);
1429   DEBUG_PRINT_STAT(NumInstructionsSimplified);
1430   DEBUG_PRINT_STAT(NumInstructions);
1431   DEBUG_PRINT_STAT(SROACostSavings);
1432   DEBUG_PRINT_STAT(SROACostSavingsLost);
1433   DEBUG_PRINT_STAT(ContainsNoDuplicateCall);
1434   DEBUG_PRINT_STAT(Cost);
1435   DEBUG_PRINT_STAT(Threshold);
1436 #undef DEBUG_PRINT_STAT
1437 }
1438 #endif
1439 
1440 /// \brief Test that there are no attribute conflicts between Caller and Callee
1441 ///        that prevent inlining.
1442 static bool functionsHaveCompatibleAttributes(Function *Caller,
1443                                               Function *Callee,
1444                                               TargetTransformInfo &TTI) {
1445   return TTI.areInlineCompatible(Caller, Callee) &&
1446          AttributeFuncs::areInlineCompatible(*Caller, *Callee);
1447 }
1448 
1449 InlineCost llvm::getInlineCost(
1450     CallSite CS, const InlineParams &Params, TargetTransformInfo &CalleeTTI,
1451     std::function<AssumptionCache &(Function &)> &GetAssumptionCache,
1452     Optional<function_ref<BlockFrequencyInfo &(Function &)>> GetBFI,
1453     ProfileSummaryInfo *PSI) {
1454   return getInlineCost(CS, CS.getCalledFunction(), Params, CalleeTTI,
1455                        GetAssumptionCache, GetBFI, PSI);
1456 }
1457 
1458 InlineCost llvm::getInlineCost(
1459     CallSite CS, Function *Callee, const InlineParams &Params,
1460     TargetTransformInfo &CalleeTTI,
1461     std::function<AssumptionCache &(Function &)> &GetAssumptionCache,
1462     Optional<function_ref<BlockFrequencyInfo &(Function &)>> GetBFI,
1463     ProfileSummaryInfo *PSI) {
1464 
1465   // Cannot inline indirect calls.
1466   if (!Callee)
1467     return llvm::InlineCost::getNever();
1468 
1469   // Calls to functions with always-inline attributes should be inlined
1470   // whenever possible.
1471   if (CS.hasFnAttr(Attribute::AlwaysInline)) {
1472     if (isInlineViable(*Callee))
1473       return llvm::InlineCost::getAlways();
1474     return llvm::InlineCost::getNever();
1475   }
1476 
1477   // Never inline functions with conflicting attributes (unless callee has
1478   // always-inline attribute).
1479   if (!functionsHaveCompatibleAttributes(CS.getCaller(), Callee, CalleeTTI))
1480     return llvm::InlineCost::getNever();
1481 
1482   // Don't inline this call if the caller has the optnone attribute.
1483   if (CS.getCaller()->hasFnAttribute(Attribute::OptimizeNone))
1484     return llvm::InlineCost::getNever();
1485 
1486   // Don't inline functions which can be interposed at link-time.  Don't inline
1487   // functions marked noinline or call sites marked noinline.
1488   // Note: inlining non-exact non-interposable functions is fine, since we know
1489   // we have *a* correct implementation of the source level function.
1490   if (Callee->isInterposable() || Callee->hasFnAttribute(Attribute::NoInline) ||
1491       CS.isNoInline())
1492     return llvm::InlineCost::getNever();
1493 
1494   DEBUG(llvm::dbgs() << "      Analyzing call of " << Callee->getName()
1495                      << "...\n");
1496 
1497   CallAnalyzer CA(CalleeTTI, GetAssumptionCache, GetBFI, PSI, *Callee, CS,
1498                   Params);
1499   bool ShouldInline = CA.analyzeCall(CS);
1500 
1501   DEBUG(CA.dump());
1502 
1503   // Check if there was a reason to force inlining or no inlining.
1504   if (!ShouldInline && CA.getCost() < CA.getThreshold())
1505     return InlineCost::getNever();
1506   if (ShouldInline && CA.getCost() >= CA.getThreshold())
1507     return InlineCost::getAlways();
1508 
1509   return llvm::InlineCost::get(CA.getCost(), CA.getThreshold());
1510 }
1511 
1512 bool llvm::isInlineViable(Function &F) {
1513   bool ReturnsTwice = F.hasFnAttribute(Attribute::ReturnsTwice);
1514   for (Function::iterator BI = F.begin(), BE = F.end(); BI != BE; ++BI) {
1515     // Disallow inlining of functions which contain indirect branches or
1516     // blockaddresses.
1517     if (isa<IndirectBrInst>(BI->getTerminator()) || BI->hasAddressTaken())
1518       return false;
1519 
1520     for (auto &II : *BI) {
1521       CallSite CS(&II);
1522       if (!CS)
1523         continue;
1524 
1525       // Disallow recursive calls.
1526       if (&F == CS.getCalledFunction())
1527         return false;
1528 
1529       // Disallow calls which expose returns-twice to a function not previously
1530       // attributed as such.
1531       if (!ReturnsTwice && CS.isCall() &&
1532           cast<CallInst>(CS.getInstruction())->canReturnTwice())
1533         return false;
1534 
1535       // Disallow inlining functions that call @llvm.localescape. Doing this
1536       // correctly would require major changes to the inliner.
1537       if (CS.getCalledFunction() &&
1538           CS.getCalledFunction()->getIntrinsicID() ==
1539               llvm::Intrinsic::localescape)
1540         return false;
1541     }
1542   }
1543 
1544   return true;
1545 }
1546 
1547 // APIs to create InlineParams based on command line flags and/or other
1548 // parameters.
1549 
1550 InlineParams llvm::getInlineParams(int Threshold) {
1551   InlineParams Params;
1552 
1553   // This field is the threshold to use for a callee by default. This is
1554   // derived from one or more of:
1555   //  * optimization or size-optimization levels,
1556   //  * a value passed to createFunctionInliningPass function, or
1557   //  * the -inline-threshold flag.
1558   //  If the -inline-threshold flag is explicitly specified, that is used
1559   //  irrespective of anything else.
1560   if (InlineThreshold.getNumOccurrences() > 0)
1561     Params.DefaultThreshold = InlineThreshold;
1562   else
1563     Params.DefaultThreshold = Threshold;
1564 
1565   // Set the HintThreshold knob from the -inlinehint-threshold.
1566   Params.HintThreshold = HintThreshold;
1567 
1568   // Set the HotCallSiteThreshold knob from the -hot-callsite-threshold.
1569   Params.HotCallSiteThreshold = HotCallSiteThreshold;
1570 
1571   // Set the ColdCallSiteThreshold knob from the -inline-cold-callsite-threshold.
1572   Params.ColdCallSiteThreshold = ColdCallSiteThreshold;
1573 
1574   // Set the OptMinSizeThreshold and OptSizeThreshold params only if the
1575   // Set the OptMinSizeThreshold and OptSizeThreshold params only if the
1576   // -inlinehint-threshold commandline option is not explicitly given. If that
1577   // option is present, then its value applies even for callees with size and
1578   // minsize attributes.
1579   // If the -inline-threshold is not specified, set the ColdThreshold from the
1580   // -inlinecold-threshold even if it is not explicitly passed. If
1581   // -inline-threshold is specified, then -inlinecold-threshold needs to be
1582   // explicitly specified to set the ColdThreshold knob
1583   if (InlineThreshold.getNumOccurrences() == 0) {
1584     Params.OptMinSizeThreshold = InlineConstants::OptMinSizeThreshold;
1585     Params.OptSizeThreshold = InlineConstants::OptSizeThreshold;
1586     Params.ColdThreshold = ColdThreshold;
1587   } else if (ColdThreshold.getNumOccurrences() > 0) {
1588     Params.ColdThreshold = ColdThreshold;
1589   }
1590   return Params;
1591 }
1592 
1593 InlineParams llvm::getInlineParams() {
1594   return getInlineParams(InlineThreshold);
1595 }
1596 
1597 // Compute the default threshold for inlining based on the opt level and the
1598 // size opt level.
1599 static int computeThresholdFromOptLevels(unsigned OptLevel,
1600                                          unsigned SizeOptLevel) {
1601   if (OptLevel > 2)
1602     return InlineConstants::OptAggressiveThreshold;
1603   if (SizeOptLevel == 1) // -Os
1604     return InlineConstants::OptSizeThreshold;
1605   if (SizeOptLevel == 2) // -Oz
1606     return InlineConstants::OptMinSizeThreshold;
1607   return InlineThreshold;
1608 }
1609 
1610 InlineParams llvm::getInlineParams(unsigned OptLevel, unsigned SizeOptLevel) {
1611   return getInlineParams(computeThresholdFromOptLevels(OptLevel, SizeOptLevel));
1612 }
1613