1 //===- InlineCost.cpp - Cost analysis for inliner -------------------------===// 2 // 3 // The LLVM Compiler Infrastructure 4 // 5 // This file is distributed under the University of Illinois Open Source 6 // License. See LICENSE.TXT for details. 7 // 8 //===----------------------------------------------------------------------===// 9 // 10 // This file implements inline cost analysis. 11 // 12 //===----------------------------------------------------------------------===// 13 14 #include "llvm/Analysis/InlineCost.h" 15 #include "llvm/ADT/STLExtras.h" 16 #include "llvm/ADT/SetVector.h" 17 #include "llvm/ADT/SmallPtrSet.h" 18 #include "llvm/ADT/SmallVector.h" 19 #include "llvm/ADT/Statistic.h" 20 #include "llvm/Analysis/AssumptionCache.h" 21 #include "llvm/Analysis/CodeMetrics.h" 22 #include "llvm/Analysis/ConstantFolding.h" 23 #include "llvm/Analysis/InstructionSimplify.h" 24 #include "llvm/Analysis/ProfileSummaryInfo.h" 25 #include "llvm/Analysis/TargetTransformInfo.h" 26 #include "llvm/IR/CallSite.h" 27 #include "llvm/IR/CallingConv.h" 28 #include "llvm/IR/DataLayout.h" 29 #include "llvm/IR/GetElementPtrTypeIterator.h" 30 #include "llvm/IR/GlobalAlias.h" 31 #include "llvm/IR/InstVisitor.h" 32 #include "llvm/IR/IntrinsicInst.h" 33 #include "llvm/IR/Operator.h" 34 #include "llvm/Support/Debug.h" 35 #include "llvm/Support/raw_ostream.h" 36 37 using namespace llvm; 38 39 #define DEBUG_TYPE "inline-cost" 40 41 STATISTIC(NumCallsAnalyzed, "Number of call sites analyzed"); 42 43 // Threshold to use when optsize is specified (and there is no 44 // -inline-threshold). 45 const int OptSizeThreshold = 75; 46 47 // Threshold to use when -Oz is specified (and there is no -inline-threshold). 48 const int OptMinSizeThreshold = 25; 49 50 // Threshold to use when -O[34] is specified (and there is no 51 // -inline-threshold). 52 const int OptAggressiveThreshold = 275; 53 54 static cl::opt<int> DefaultInlineThreshold( 55 "inline-threshold", cl::Hidden, cl::init(225), cl::ZeroOrMore, 56 cl::desc("Control the amount of inlining to perform (default = 225)")); 57 58 static cl::opt<int> HintThreshold( 59 "inlinehint-threshold", cl::Hidden, cl::init(325), 60 cl::desc("Threshold for inlining functions with inline hint")); 61 62 // We introduce this threshold to help performance of instrumentation based 63 // PGO before we actually hook up inliner with analysis passes such as BPI and 64 // BFI. 65 static cl::opt<int> ColdThreshold( 66 "inlinecold-threshold", cl::Hidden, cl::init(225), 67 cl::desc("Threshold for inlining functions with cold attribute")); 68 69 namespace { 70 71 class CallAnalyzer : public InstVisitor<CallAnalyzer, bool> { 72 typedef InstVisitor<CallAnalyzer, bool> Base; 73 friend class InstVisitor<CallAnalyzer, bool>; 74 75 /// The TargetTransformInfo available for this compilation. 76 const TargetTransformInfo &TTI; 77 78 /// The cache of @llvm.assume intrinsics. 79 AssumptionCacheTracker *ACT; 80 81 /// Profile summary information. 82 ProfileSummaryInfo *PSI; 83 84 // The called function. 85 Function &F; 86 87 // The candidate callsite being analyzed. Please do not use this to do 88 // analysis in the caller function; we want the inline cost query to be 89 // easily cacheable. Instead, use the cover function paramHasAttr. 90 CallSite CandidateCS; 91 92 int Threshold; 93 int Cost; 94 95 bool IsCallerRecursive; 96 bool IsRecursiveCall; 97 bool ExposesReturnsTwice; 98 bool HasDynamicAlloca; 99 bool ContainsNoDuplicateCall; 100 bool HasReturn; 101 bool HasIndirectBr; 102 bool HasFrameEscape; 103 104 /// Number of bytes allocated statically by the callee. 105 uint64_t AllocatedSize; 106 unsigned NumInstructions, NumVectorInstructions; 107 int FiftyPercentVectorBonus, TenPercentVectorBonus; 108 int VectorBonus; 109 110 // While we walk the potentially-inlined instructions, we build up and 111 // maintain a mapping of simplified values specific to this callsite. The 112 // idea is to propagate any special information we have about arguments to 113 // this call through the inlinable section of the function, and account for 114 // likely simplifications post-inlining. The most important aspect we track 115 // is CFG altering simplifications -- when we prove a basic block dead, that 116 // can cause dramatic shifts in the cost of inlining a function. 117 DenseMap<Value *, Constant *> SimplifiedValues; 118 119 // Keep track of the values which map back (through function arguments) to 120 // allocas on the caller stack which could be simplified through SROA. 121 DenseMap<Value *, Value *> SROAArgValues; 122 123 // The mapping of caller Alloca values to their accumulated cost savings. If 124 // we have to disable SROA for one of the allocas, this tells us how much 125 // cost must be added. 126 DenseMap<Value *, int> SROAArgCosts; 127 128 // Keep track of values which map to a pointer base and constant offset. 129 DenseMap<Value *, std::pair<Value *, APInt>> ConstantOffsetPtrs; 130 131 // Custom simplification helper routines. 132 bool isAllocaDerivedArg(Value *V); 133 bool lookupSROAArgAndCost(Value *V, Value *&Arg, 134 DenseMap<Value *, int>::iterator &CostIt); 135 void disableSROA(DenseMap<Value *, int>::iterator CostIt); 136 void disableSROA(Value *V); 137 void accumulateSROACost(DenseMap<Value *, int>::iterator CostIt, 138 int InstructionCost); 139 bool isGEPOffsetConstant(GetElementPtrInst &GEP); 140 bool accumulateGEPOffset(GEPOperator &GEP, APInt &Offset); 141 bool simplifyCallSite(Function *F, CallSite CS); 142 ConstantInt *stripAndComputeInBoundsConstantOffsets(Value *&V); 143 144 /// Return true if the given argument to the function being considered for 145 /// inlining has the given attribute set either at the call site or the 146 /// function declaration. Primarily used to inspect call site specific 147 /// attributes since these can be more precise than the ones on the callee 148 /// itself. 149 bool paramHasAttr(Argument *A, Attribute::AttrKind Attr); 150 151 /// Return true if the given value is known non null within the callee if 152 /// inlined through this particular callsite. 153 bool isKnownNonNullInCallee(Value *V); 154 155 /// Update Threshold based on callsite properties such as callee 156 /// attributes and callee hotness for PGO builds. The Callee is explicitly 157 /// passed to support analyzing indirect calls whose target is inferred by 158 /// analysis. 159 void updateThreshold(CallSite CS, Function &Callee); 160 161 /// Return true if size growth is allowed when inlining the callee at CS. 162 bool allowSizeGrowth(CallSite CS); 163 164 // Custom analysis routines. 165 bool analyzeBlock(BasicBlock *BB, SmallPtrSetImpl<const Value *> &EphValues); 166 167 // Disable several entry points to the visitor so we don't accidentally use 168 // them by declaring but not defining them here. 169 void visit(Module *); 170 void visit(Module &); 171 void visit(Function *); 172 void visit(Function &); 173 void visit(BasicBlock *); 174 void visit(BasicBlock &); 175 176 // Provide base case for our instruction visit. 177 bool visitInstruction(Instruction &I); 178 179 // Our visit overrides. 180 bool visitAlloca(AllocaInst &I); 181 bool visitPHI(PHINode &I); 182 bool visitGetElementPtr(GetElementPtrInst &I); 183 bool visitBitCast(BitCastInst &I); 184 bool visitPtrToInt(PtrToIntInst &I); 185 bool visitIntToPtr(IntToPtrInst &I); 186 bool visitCastInst(CastInst &I); 187 bool visitUnaryInstruction(UnaryInstruction &I); 188 bool visitCmpInst(CmpInst &I); 189 bool visitSub(BinaryOperator &I); 190 bool visitBinaryOperator(BinaryOperator &I); 191 bool visitLoad(LoadInst &I); 192 bool visitStore(StoreInst &I); 193 bool visitExtractValue(ExtractValueInst &I); 194 bool visitInsertValue(InsertValueInst &I); 195 bool visitCallSite(CallSite CS); 196 bool visitReturnInst(ReturnInst &RI); 197 bool visitBranchInst(BranchInst &BI); 198 bool visitSwitchInst(SwitchInst &SI); 199 bool visitIndirectBrInst(IndirectBrInst &IBI); 200 bool visitResumeInst(ResumeInst &RI); 201 bool visitCleanupReturnInst(CleanupReturnInst &RI); 202 bool visitCatchReturnInst(CatchReturnInst &RI); 203 bool visitUnreachableInst(UnreachableInst &I); 204 205 public: 206 CallAnalyzer(const TargetTransformInfo &TTI, AssumptionCacheTracker *ACT, 207 ProfileSummaryInfo *PSI, Function &Callee, int Threshold, 208 CallSite CSArg) 209 : TTI(TTI), ACT(ACT), PSI(PSI), F(Callee), CandidateCS(CSArg), 210 Threshold(Threshold), Cost(0), IsCallerRecursive(false), 211 IsRecursiveCall(false), ExposesReturnsTwice(false), 212 HasDynamicAlloca(false), ContainsNoDuplicateCall(false), 213 HasReturn(false), HasIndirectBr(false), HasFrameEscape(false), 214 AllocatedSize(0), NumInstructions(0), NumVectorInstructions(0), 215 FiftyPercentVectorBonus(0), TenPercentVectorBonus(0), VectorBonus(0), 216 NumConstantArgs(0), NumConstantOffsetPtrArgs(0), NumAllocaArgs(0), 217 NumConstantPtrCmps(0), NumConstantPtrDiffs(0), 218 NumInstructionsSimplified(0), SROACostSavings(0), 219 SROACostSavingsLost(0) {} 220 221 bool analyzeCall(CallSite CS); 222 223 int getThreshold() { return Threshold; } 224 int getCost() { return Cost; } 225 226 // Keep a bunch of stats about the cost savings found so we can print them 227 // out when debugging. 228 unsigned NumConstantArgs; 229 unsigned NumConstantOffsetPtrArgs; 230 unsigned NumAllocaArgs; 231 unsigned NumConstantPtrCmps; 232 unsigned NumConstantPtrDiffs; 233 unsigned NumInstructionsSimplified; 234 unsigned SROACostSavings; 235 unsigned SROACostSavingsLost; 236 237 void dump(); 238 }; 239 240 } // namespace 241 242 /// \brief Test whether the given value is an Alloca-derived function argument. 243 bool CallAnalyzer::isAllocaDerivedArg(Value *V) { 244 return SROAArgValues.count(V); 245 } 246 247 /// \brief Lookup the SROA-candidate argument and cost iterator which V maps to. 248 /// Returns false if V does not map to a SROA-candidate. 249 bool CallAnalyzer::lookupSROAArgAndCost( 250 Value *V, Value *&Arg, DenseMap<Value *, int>::iterator &CostIt) { 251 if (SROAArgValues.empty() || SROAArgCosts.empty()) 252 return false; 253 254 DenseMap<Value *, Value *>::iterator ArgIt = SROAArgValues.find(V); 255 if (ArgIt == SROAArgValues.end()) 256 return false; 257 258 Arg = ArgIt->second; 259 CostIt = SROAArgCosts.find(Arg); 260 return CostIt != SROAArgCosts.end(); 261 } 262 263 /// \brief Disable SROA for the candidate marked by this cost iterator. 264 /// 265 /// This marks the candidate as no longer viable for SROA, and adds the cost 266 /// savings associated with it back into the inline cost measurement. 267 void CallAnalyzer::disableSROA(DenseMap<Value *, int>::iterator CostIt) { 268 // If we're no longer able to perform SROA we need to undo its cost savings 269 // and prevent subsequent analysis. 270 Cost += CostIt->second; 271 SROACostSavings -= CostIt->second; 272 SROACostSavingsLost += CostIt->second; 273 SROAArgCosts.erase(CostIt); 274 } 275 276 /// \brief If 'V' maps to a SROA candidate, disable SROA for it. 277 void CallAnalyzer::disableSROA(Value *V) { 278 Value *SROAArg; 279 DenseMap<Value *, int>::iterator CostIt; 280 if (lookupSROAArgAndCost(V, SROAArg, CostIt)) 281 disableSROA(CostIt); 282 } 283 284 /// \brief Accumulate the given cost for a particular SROA candidate. 285 void CallAnalyzer::accumulateSROACost(DenseMap<Value *, int>::iterator CostIt, 286 int InstructionCost) { 287 CostIt->second += InstructionCost; 288 SROACostSavings += InstructionCost; 289 } 290 291 /// \brief Check whether a GEP's indices are all constant. 292 /// 293 /// Respects any simplified values known during the analysis of this callsite. 294 bool CallAnalyzer::isGEPOffsetConstant(GetElementPtrInst &GEP) { 295 for (User::op_iterator I = GEP.idx_begin(), E = GEP.idx_end(); I != E; ++I) 296 if (!isa<Constant>(*I) && !SimplifiedValues.lookup(*I)) 297 return false; 298 299 return true; 300 } 301 302 /// \brief Accumulate a constant GEP offset into an APInt if possible. 303 /// 304 /// Returns false if unable to compute the offset for any reason. Respects any 305 /// simplified values known during the analysis of this callsite. 306 bool CallAnalyzer::accumulateGEPOffset(GEPOperator &GEP, APInt &Offset) { 307 const DataLayout &DL = F.getParent()->getDataLayout(); 308 unsigned IntPtrWidth = DL.getPointerSizeInBits(); 309 assert(IntPtrWidth == Offset.getBitWidth()); 310 311 for (gep_type_iterator GTI = gep_type_begin(GEP), GTE = gep_type_end(GEP); 312 GTI != GTE; ++GTI) { 313 ConstantInt *OpC = dyn_cast<ConstantInt>(GTI.getOperand()); 314 if (!OpC) 315 if (Constant *SimpleOp = SimplifiedValues.lookup(GTI.getOperand())) 316 OpC = dyn_cast<ConstantInt>(SimpleOp); 317 if (!OpC) 318 return false; 319 if (OpC->isZero()) 320 continue; 321 322 // Handle a struct index, which adds its field offset to the pointer. 323 if (StructType *STy = dyn_cast<StructType>(*GTI)) { 324 unsigned ElementIdx = OpC->getZExtValue(); 325 const StructLayout *SL = DL.getStructLayout(STy); 326 Offset += APInt(IntPtrWidth, SL->getElementOffset(ElementIdx)); 327 continue; 328 } 329 330 APInt TypeSize(IntPtrWidth, DL.getTypeAllocSize(GTI.getIndexedType())); 331 Offset += OpC->getValue().sextOrTrunc(IntPtrWidth) * TypeSize; 332 } 333 return true; 334 } 335 336 bool CallAnalyzer::visitAlloca(AllocaInst &I) { 337 // Check whether inlining will turn a dynamic alloca into a static 338 // alloca and handle that case. 339 if (I.isArrayAllocation()) { 340 Constant *Size = SimplifiedValues.lookup(I.getArraySize()); 341 if (auto *AllocSize = dyn_cast_or_null<ConstantInt>(Size)) { 342 const DataLayout &DL = F.getParent()->getDataLayout(); 343 Type *Ty = I.getAllocatedType(); 344 AllocatedSize = SaturatingMultiplyAdd( 345 AllocSize->getLimitedValue(), DL.getTypeAllocSize(Ty), AllocatedSize); 346 return Base::visitAlloca(I); 347 } 348 } 349 350 // Accumulate the allocated size. 351 if (I.isStaticAlloca()) { 352 const DataLayout &DL = F.getParent()->getDataLayout(); 353 Type *Ty = I.getAllocatedType(); 354 AllocatedSize = SaturatingAdd(DL.getTypeAllocSize(Ty), AllocatedSize); 355 } 356 357 // We will happily inline static alloca instructions. 358 if (I.isStaticAlloca()) 359 return Base::visitAlloca(I); 360 361 // FIXME: This is overly conservative. Dynamic allocas are inefficient for 362 // a variety of reasons, and so we would like to not inline them into 363 // functions which don't currently have a dynamic alloca. This simply 364 // disables inlining altogether in the presence of a dynamic alloca. 365 HasDynamicAlloca = true; 366 return false; 367 } 368 369 bool CallAnalyzer::visitPHI(PHINode &I) { 370 // FIXME: We should potentially be tracking values through phi nodes, 371 // especially when they collapse to a single value due to deleted CFG edges 372 // during inlining. 373 374 // FIXME: We need to propagate SROA *disabling* through phi nodes, even 375 // though we don't want to propagate it's bonuses. The idea is to disable 376 // SROA if it *might* be used in an inappropriate manner. 377 378 // Phi nodes are always zero-cost. 379 return true; 380 } 381 382 bool CallAnalyzer::visitGetElementPtr(GetElementPtrInst &I) { 383 Value *SROAArg; 384 DenseMap<Value *, int>::iterator CostIt; 385 bool SROACandidate = 386 lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt); 387 388 // Try to fold GEPs of constant-offset call site argument pointers. This 389 // requires target data and inbounds GEPs. 390 if (I.isInBounds()) { 391 // Check if we have a base + offset for the pointer. 392 Value *Ptr = I.getPointerOperand(); 393 std::pair<Value *, APInt> BaseAndOffset = ConstantOffsetPtrs.lookup(Ptr); 394 if (BaseAndOffset.first) { 395 // Check if the offset of this GEP is constant, and if so accumulate it 396 // into Offset. 397 if (!accumulateGEPOffset(cast<GEPOperator>(I), BaseAndOffset.second)) { 398 // Non-constant GEPs aren't folded, and disable SROA. 399 if (SROACandidate) 400 disableSROA(CostIt); 401 return false; 402 } 403 404 // Add the result as a new mapping to Base + Offset. 405 ConstantOffsetPtrs[&I] = BaseAndOffset; 406 407 // Also handle SROA candidates here, we already know that the GEP is 408 // all-constant indexed. 409 if (SROACandidate) 410 SROAArgValues[&I] = SROAArg; 411 412 return true; 413 } 414 } 415 416 if (isGEPOffsetConstant(I)) { 417 if (SROACandidate) 418 SROAArgValues[&I] = SROAArg; 419 420 // Constant GEPs are modeled as free. 421 return true; 422 } 423 424 // Variable GEPs will require math and will disable SROA. 425 if (SROACandidate) 426 disableSROA(CostIt); 427 return false; 428 } 429 430 bool CallAnalyzer::visitBitCast(BitCastInst &I) { 431 // Propagate constants through bitcasts. 432 Constant *COp = dyn_cast<Constant>(I.getOperand(0)); 433 if (!COp) 434 COp = SimplifiedValues.lookup(I.getOperand(0)); 435 if (COp) 436 if (Constant *C = ConstantExpr::getBitCast(COp, I.getType())) { 437 SimplifiedValues[&I] = C; 438 return true; 439 } 440 441 // Track base/offsets through casts 442 std::pair<Value *, APInt> BaseAndOffset = 443 ConstantOffsetPtrs.lookup(I.getOperand(0)); 444 // Casts don't change the offset, just wrap it up. 445 if (BaseAndOffset.first) 446 ConstantOffsetPtrs[&I] = BaseAndOffset; 447 448 // Also look for SROA candidates here. 449 Value *SROAArg; 450 DenseMap<Value *, int>::iterator CostIt; 451 if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt)) 452 SROAArgValues[&I] = SROAArg; 453 454 // Bitcasts are always zero cost. 455 return true; 456 } 457 458 bool CallAnalyzer::visitPtrToInt(PtrToIntInst &I) { 459 // Propagate constants through ptrtoint. 460 Constant *COp = dyn_cast<Constant>(I.getOperand(0)); 461 if (!COp) 462 COp = SimplifiedValues.lookup(I.getOperand(0)); 463 if (COp) 464 if (Constant *C = ConstantExpr::getPtrToInt(COp, I.getType())) { 465 SimplifiedValues[&I] = C; 466 return true; 467 } 468 469 // Track base/offset pairs when converted to a plain integer provided the 470 // integer is large enough to represent the pointer. 471 unsigned IntegerSize = I.getType()->getScalarSizeInBits(); 472 const DataLayout &DL = F.getParent()->getDataLayout(); 473 if (IntegerSize >= DL.getPointerSizeInBits()) { 474 std::pair<Value *, APInt> BaseAndOffset = 475 ConstantOffsetPtrs.lookup(I.getOperand(0)); 476 if (BaseAndOffset.first) 477 ConstantOffsetPtrs[&I] = BaseAndOffset; 478 } 479 480 // This is really weird. Technically, ptrtoint will disable SROA. However, 481 // unless that ptrtoint is *used* somewhere in the live basic blocks after 482 // inlining, it will be nuked, and SROA should proceed. All of the uses which 483 // would block SROA would also block SROA if applied directly to a pointer, 484 // and so we can just add the integer in here. The only places where SROA is 485 // preserved either cannot fire on an integer, or won't in-and-of themselves 486 // disable SROA (ext) w/o some later use that we would see and disable. 487 Value *SROAArg; 488 DenseMap<Value *, int>::iterator CostIt; 489 if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt)) 490 SROAArgValues[&I] = SROAArg; 491 492 return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I); 493 } 494 495 bool CallAnalyzer::visitIntToPtr(IntToPtrInst &I) { 496 // Propagate constants through ptrtoint. 497 Constant *COp = dyn_cast<Constant>(I.getOperand(0)); 498 if (!COp) 499 COp = SimplifiedValues.lookup(I.getOperand(0)); 500 if (COp) 501 if (Constant *C = ConstantExpr::getIntToPtr(COp, I.getType())) { 502 SimplifiedValues[&I] = C; 503 return true; 504 } 505 506 // Track base/offset pairs when round-tripped through a pointer without 507 // modifications provided the integer is not too large. 508 Value *Op = I.getOperand(0); 509 unsigned IntegerSize = Op->getType()->getScalarSizeInBits(); 510 const DataLayout &DL = F.getParent()->getDataLayout(); 511 if (IntegerSize <= DL.getPointerSizeInBits()) { 512 std::pair<Value *, APInt> BaseAndOffset = ConstantOffsetPtrs.lookup(Op); 513 if (BaseAndOffset.first) 514 ConstantOffsetPtrs[&I] = BaseAndOffset; 515 } 516 517 // "Propagate" SROA here in the same manner as we do for ptrtoint above. 518 Value *SROAArg; 519 DenseMap<Value *, int>::iterator CostIt; 520 if (lookupSROAArgAndCost(Op, SROAArg, CostIt)) 521 SROAArgValues[&I] = SROAArg; 522 523 return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I); 524 } 525 526 bool CallAnalyzer::visitCastInst(CastInst &I) { 527 // Propagate constants through ptrtoint. 528 Constant *COp = dyn_cast<Constant>(I.getOperand(0)); 529 if (!COp) 530 COp = SimplifiedValues.lookup(I.getOperand(0)); 531 if (COp) 532 if (Constant *C = ConstantExpr::getCast(I.getOpcode(), COp, I.getType())) { 533 SimplifiedValues[&I] = C; 534 return true; 535 } 536 537 // Disable SROA in the face of arbitrary casts we don't whitelist elsewhere. 538 disableSROA(I.getOperand(0)); 539 540 return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I); 541 } 542 543 bool CallAnalyzer::visitUnaryInstruction(UnaryInstruction &I) { 544 Value *Operand = I.getOperand(0); 545 Constant *COp = dyn_cast<Constant>(Operand); 546 if (!COp) 547 COp = SimplifiedValues.lookup(Operand); 548 if (COp) { 549 const DataLayout &DL = F.getParent()->getDataLayout(); 550 if (Constant *C = ConstantFoldInstOperands(&I, COp, DL)) { 551 SimplifiedValues[&I] = C; 552 return true; 553 } 554 } 555 556 // Disable any SROA on the argument to arbitrary unary operators. 557 disableSROA(Operand); 558 559 return false; 560 } 561 562 bool CallAnalyzer::paramHasAttr(Argument *A, Attribute::AttrKind Attr) { 563 unsigned ArgNo = A->getArgNo(); 564 return CandidateCS.paramHasAttr(ArgNo + 1, Attr); 565 } 566 567 bool CallAnalyzer::isKnownNonNullInCallee(Value *V) { 568 // Does the *call site* have the NonNull attribute set on an argument? We 569 // use the attribute on the call site to memoize any analysis done in the 570 // caller. This will also trip if the callee function has a non-null 571 // parameter attribute, but that's a less interesting case because hopefully 572 // the callee would already have been simplified based on that. 573 if (Argument *A = dyn_cast<Argument>(V)) 574 if (paramHasAttr(A, Attribute::NonNull)) 575 return true; 576 577 // Is this an alloca in the caller? This is distinct from the attribute case 578 // above because attributes aren't updated within the inliner itself and we 579 // always want to catch the alloca derived case. 580 if (isAllocaDerivedArg(V)) 581 // We can actually predict the result of comparisons between an 582 // alloca-derived value and null. Note that this fires regardless of 583 // SROA firing. 584 return true; 585 586 return false; 587 } 588 589 bool CallAnalyzer::allowSizeGrowth(CallSite CS) { 590 // If the normal destination of the invoke or the parent block of the call 591 // site is unreachable-terminated, there is little point in inlining this 592 // unless there is literally zero cost. 593 // FIXME: Note that it is possible that an unreachable-terminated block has a 594 // hot entry. For example, in below scenario inlining hot_call_X() may be 595 // beneficial : 596 // main() { 597 // hot_call_1(); 598 // ... 599 // hot_call_N() 600 // exit(0); 601 // } 602 // For now, we are not handling this corner case here as it is rare in real 603 // code. In future, we should elaborate this based on BPI and BFI in more 604 // general threshold adjusting heuristics in updateThreshold(). 605 Instruction *Instr = CS.getInstruction(); 606 if (InvokeInst *II = dyn_cast<InvokeInst>(Instr)) { 607 if (isa<UnreachableInst>(II->getNormalDest()->getTerminator())) 608 return false; 609 } else if (isa<UnreachableInst>(Instr->getParent()->getTerminator())) 610 return false; 611 612 return true; 613 } 614 615 void CallAnalyzer::updateThreshold(CallSite CS, Function &Callee) { 616 // If no size growth is allowed for this inlining, set Threshold to 0. 617 if (!allowSizeGrowth(CS)) { 618 Threshold = 0; 619 return; 620 } 621 622 Function *Caller = CS.getCaller(); 623 if (DefaultInlineThreshold.getNumOccurrences() > 0) { 624 // Explicitly specified -inline-threhold overrides the threshold passed to 625 // CallAnalyzer's constructor. 626 Threshold = DefaultInlineThreshold; 627 } else { 628 // If -inline-threshold is not given, listen to the optsize and minsize 629 // attributes when they would decrease the threshold. 630 if (Caller->optForMinSize() && OptMinSizeThreshold < Threshold) 631 Threshold = OptMinSizeThreshold; 632 else if (Caller->optForSize() && OptSizeThreshold < Threshold) 633 Threshold = OptSizeThreshold; 634 } 635 636 // Listen to the inlinehint attribute or profile based hotness information 637 // when it would increase the threshold and the caller does not need to 638 // minimize its size. 639 bool InlineHint = Callee.hasFnAttribute(Attribute::InlineHint) || 640 PSI->isHotFunction(&Callee); 641 if (InlineHint && HintThreshold > Threshold && !Caller->optForMinSize()) 642 Threshold = HintThreshold; 643 644 bool ColdCallee = PSI->isColdFunction(&Callee); 645 // Command line argument for DefaultInlineThreshold will override the default 646 // ColdThreshold. If we have -inline-threshold but no -inlinecold-threshold, 647 // do not use the default cold threshold even if it is smaller. 648 if ((DefaultInlineThreshold.getNumOccurrences() == 0 || 649 ColdThreshold.getNumOccurrences() > 0) && 650 ColdCallee && ColdThreshold < Threshold) 651 Threshold = ColdThreshold; 652 653 // Finally, take the target-specific inlining threshold multiplier into 654 // account. 655 Threshold *= TTI.getInliningThresholdMultiplier(); 656 } 657 658 bool CallAnalyzer::visitCmpInst(CmpInst &I) { 659 Value *LHS = I.getOperand(0), *RHS = I.getOperand(1); 660 // First try to handle simplified comparisons. 661 if (!isa<Constant>(LHS)) 662 if (Constant *SimpleLHS = SimplifiedValues.lookup(LHS)) 663 LHS = SimpleLHS; 664 if (!isa<Constant>(RHS)) 665 if (Constant *SimpleRHS = SimplifiedValues.lookup(RHS)) 666 RHS = SimpleRHS; 667 if (Constant *CLHS = dyn_cast<Constant>(LHS)) { 668 if (Constant *CRHS = dyn_cast<Constant>(RHS)) 669 if (Constant *C = 670 ConstantExpr::getCompare(I.getPredicate(), CLHS, CRHS)) { 671 SimplifiedValues[&I] = C; 672 return true; 673 } 674 } 675 676 if (I.getOpcode() == Instruction::FCmp) 677 return false; 678 679 // Otherwise look for a comparison between constant offset pointers with 680 // a common base. 681 Value *LHSBase, *RHSBase; 682 APInt LHSOffset, RHSOffset; 683 std::tie(LHSBase, LHSOffset) = ConstantOffsetPtrs.lookup(LHS); 684 if (LHSBase) { 685 std::tie(RHSBase, RHSOffset) = ConstantOffsetPtrs.lookup(RHS); 686 if (RHSBase && LHSBase == RHSBase) { 687 // We have common bases, fold the icmp to a constant based on the 688 // offsets. 689 Constant *CLHS = ConstantInt::get(LHS->getContext(), LHSOffset); 690 Constant *CRHS = ConstantInt::get(RHS->getContext(), RHSOffset); 691 if (Constant *C = ConstantExpr::getICmp(I.getPredicate(), CLHS, CRHS)) { 692 SimplifiedValues[&I] = C; 693 ++NumConstantPtrCmps; 694 return true; 695 } 696 } 697 } 698 699 // If the comparison is an equality comparison with null, we can simplify it 700 // if we know the value (argument) can't be null 701 if (I.isEquality() && isa<ConstantPointerNull>(I.getOperand(1)) && 702 isKnownNonNullInCallee(I.getOperand(0))) { 703 bool IsNotEqual = I.getPredicate() == CmpInst::ICMP_NE; 704 SimplifiedValues[&I] = IsNotEqual ? ConstantInt::getTrue(I.getType()) 705 : ConstantInt::getFalse(I.getType()); 706 return true; 707 } 708 // Finally check for SROA candidates in comparisons. 709 Value *SROAArg; 710 DenseMap<Value *, int>::iterator CostIt; 711 if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt)) { 712 if (isa<ConstantPointerNull>(I.getOperand(1))) { 713 accumulateSROACost(CostIt, InlineConstants::InstrCost); 714 return true; 715 } 716 717 disableSROA(CostIt); 718 } 719 720 return false; 721 } 722 723 bool CallAnalyzer::visitSub(BinaryOperator &I) { 724 // Try to handle a special case: we can fold computing the difference of two 725 // constant-related pointers. 726 Value *LHS = I.getOperand(0), *RHS = I.getOperand(1); 727 Value *LHSBase, *RHSBase; 728 APInt LHSOffset, RHSOffset; 729 std::tie(LHSBase, LHSOffset) = ConstantOffsetPtrs.lookup(LHS); 730 if (LHSBase) { 731 std::tie(RHSBase, RHSOffset) = ConstantOffsetPtrs.lookup(RHS); 732 if (RHSBase && LHSBase == RHSBase) { 733 // We have common bases, fold the subtract to a constant based on the 734 // offsets. 735 Constant *CLHS = ConstantInt::get(LHS->getContext(), LHSOffset); 736 Constant *CRHS = ConstantInt::get(RHS->getContext(), RHSOffset); 737 if (Constant *C = ConstantExpr::getSub(CLHS, CRHS)) { 738 SimplifiedValues[&I] = C; 739 ++NumConstantPtrDiffs; 740 return true; 741 } 742 } 743 } 744 745 // Otherwise, fall back to the generic logic for simplifying and handling 746 // instructions. 747 return Base::visitSub(I); 748 } 749 750 bool CallAnalyzer::visitBinaryOperator(BinaryOperator &I) { 751 Value *LHS = I.getOperand(0), *RHS = I.getOperand(1); 752 const DataLayout &DL = F.getParent()->getDataLayout(); 753 if (!isa<Constant>(LHS)) 754 if (Constant *SimpleLHS = SimplifiedValues.lookup(LHS)) 755 LHS = SimpleLHS; 756 if (!isa<Constant>(RHS)) 757 if (Constant *SimpleRHS = SimplifiedValues.lookup(RHS)) 758 RHS = SimpleRHS; 759 Value *SimpleV = nullptr; 760 if (auto FI = dyn_cast<FPMathOperator>(&I)) 761 SimpleV = 762 SimplifyFPBinOp(I.getOpcode(), LHS, RHS, FI->getFastMathFlags(), DL); 763 else 764 SimpleV = SimplifyBinOp(I.getOpcode(), LHS, RHS, DL); 765 766 if (Constant *C = dyn_cast_or_null<Constant>(SimpleV)) { 767 SimplifiedValues[&I] = C; 768 return true; 769 } 770 771 // Disable any SROA on arguments to arbitrary, unsimplified binary operators. 772 disableSROA(LHS); 773 disableSROA(RHS); 774 775 return false; 776 } 777 778 bool CallAnalyzer::visitLoad(LoadInst &I) { 779 Value *SROAArg; 780 DenseMap<Value *, int>::iterator CostIt; 781 if (lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt)) { 782 if (I.isSimple()) { 783 accumulateSROACost(CostIt, InlineConstants::InstrCost); 784 return true; 785 } 786 787 disableSROA(CostIt); 788 } 789 790 return false; 791 } 792 793 bool CallAnalyzer::visitStore(StoreInst &I) { 794 Value *SROAArg; 795 DenseMap<Value *, int>::iterator CostIt; 796 if (lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt)) { 797 if (I.isSimple()) { 798 accumulateSROACost(CostIt, InlineConstants::InstrCost); 799 return true; 800 } 801 802 disableSROA(CostIt); 803 } 804 805 return false; 806 } 807 808 bool CallAnalyzer::visitExtractValue(ExtractValueInst &I) { 809 // Constant folding for extract value is trivial. 810 Constant *C = dyn_cast<Constant>(I.getAggregateOperand()); 811 if (!C) 812 C = SimplifiedValues.lookup(I.getAggregateOperand()); 813 if (C) { 814 SimplifiedValues[&I] = ConstantExpr::getExtractValue(C, I.getIndices()); 815 return true; 816 } 817 818 // SROA can look through these but give them a cost. 819 return false; 820 } 821 822 bool CallAnalyzer::visitInsertValue(InsertValueInst &I) { 823 // Constant folding for insert value is trivial. 824 Constant *AggC = dyn_cast<Constant>(I.getAggregateOperand()); 825 if (!AggC) 826 AggC = SimplifiedValues.lookup(I.getAggregateOperand()); 827 Constant *InsertedC = dyn_cast<Constant>(I.getInsertedValueOperand()); 828 if (!InsertedC) 829 InsertedC = SimplifiedValues.lookup(I.getInsertedValueOperand()); 830 if (AggC && InsertedC) { 831 SimplifiedValues[&I] = 832 ConstantExpr::getInsertValue(AggC, InsertedC, I.getIndices()); 833 return true; 834 } 835 836 // SROA can look through these but give them a cost. 837 return false; 838 } 839 840 /// \brief Try to simplify a call site. 841 /// 842 /// Takes a concrete function and callsite and tries to actually simplify it by 843 /// analyzing the arguments and call itself with instsimplify. Returns true if 844 /// it has simplified the callsite to some other entity (a constant), making it 845 /// free. 846 bool CallAnalyzer::simplifyCallSite(Function *F, CallSite CS) { 847 // FIXME: Using the instsimplify logic directly for this is inefficient 848 // because we have to continually rebuild the argument list even when no 849 // simplifications can be performed. Until that is fixed with remapping 850 // inside of instsimplify, directly constant fold calls here. 851 if (!canConstantFoldCallTo(F)) 852 return false; 853 854 // Try to re-map the arguments to constants. 855 SmallVector<Constant *, 4> ConstantArgs; 856 ConstantArgs.reserve(CS.arg_size()); 857 for (CallSite::arg_iterator I = CS.arg_begin(), E = CS.arg_end(); I != E; 858 ++I) { 859 Constant *C = dyn_cast<Constant>(*I); 860 if (!C) 861 C = dyn_cast_or_null<Constant>(SimplifiedValues.lookup(*I)); 862 if (!C) 863 return false; // This argument doesn't map to a constant. 864 865 ConstantArgs.push_back(C); 866 } 867 if (Constant *C = ConstantFoldCall(F, ConstantArgs)) { 868 SimplifiedValues[CS.getInstruction()] = C; 869 return true; 870 } 871 872 return false; 873 } 874 875 bool CallAnalyzer::visitCallSite(CallSite CS) { 876 if (CS.hasFnAttr(Attribute::ReturnsTwice) && 877 !F.hasFnAttribute(Attribute::ReturnsTwice)) { 878 // This aborts the entire analysis. 879 ExposesReturnsTwice = true; 880 return false; 881 } 882 if (CS.isCall() && cast<CallInst>(CS.getInstruction())->cannotDuplicate()) 883 ContainsNoDuplicateCall = true; 884 885 if (Function *F = CS.getCalledFunction()) { 886 // When we have a concrete function, first try to simplify it directly. 887 if (simplifyCallSite(F, CS)) 888 return true; 889 890 // Next check if it is an intrinsic we know about. 891 // FIXME: Lift this into part of the InstVisitor. 892 if (IntrinsicInst *II = dyn_cast<IntrinsicInst>(CS.getInstruction())) { 893 switch (II->getIntrinsicID()) { 894 default: 895 return Base::visitCallSite(CS); 896 897 case Intrinsic::load_relative: 898 // This is normally lowered to 4 LLVM instructions. 899 Cost += 3 * InlineConstants::InstrCost; 900 return false; 901 902 case Intrinsic::memset: 903 case Intrinsic::memcpy: 904 case Intrinsic::memmove: 905 // SROA can usually chew through these intrinsics, but they aren't free. 906 return false; 907 case Intrinsic::localescape: 908 HasFrameEscape = true; 909 return false; 910 } 911 } 912 913 if (F == CS.getInstruction()->getParent()->getParent()) { 914 // This flag will fully abort the analysis, so don't bother with anything 915 // else. 916 IsRecursiveCall = true; 917 return false; 918 } 919 920 if (TTI.isLoweredToCall(F)) { 921 // We account for the average 1 instruction per call argument setup 922 // here. 923 Cost += CS.arg_size() * InlineConstants::InstrCost; 924 925 // Everything other than inline ASM will also have a significant cost 926 // merely from making the call. 927 if (!isa<InlineAsm>(CS.getCalledValue())) 928 Cost += InlineConstants::CallPenalty; 929 } 930 931 return Base::visitCallSite(CS); 932 } 933 934 // Otherwise we're in a very special case -- an indirect function call. See 935 // if we can be particularly clever about this. 936 Value *Callee = CS.getCalledValue(); 937 938 // First, pay the price of the argument setup. We account for the average 939 // 1 instruction per call argument setup here. 940 Cost += CS.arg_size() * InlineConstants::InstrCost; 941 942 // Next, check if this happens to be an indirect function call to a known 943 // function in this inline context. If not, we've done all we can. 944 Function *F = dyn_cast_or_null<Function>(SimplifiedValues.lookup(Callee)); 945 if (!F) 946 return Base::visitCallSite(CS); 947 948 // If we have a constant that we are calling as a function, we can peer 949 // through it and see the function target. This happens not infrequently 950 // during devirtualization and so we want to give it a hefty bonus for 951 // inlining, but cap that bonus in the event that inlining wouldn't pan 952 // out. Pretend to inline the function, with a custom threshold. 953 CallAnalyzer CA(TTI, ACT, PSI, *F, InlineConstants::IndirectCallThreshold, 954 CS); 955 if (CA.analyzeCall(CS)) { 956 // We were able to inline the indirect call! Subtract the cost from the 957 // threshold to get the bonus we want to apply, but don't go below zero. 958 Cost -= std::max(0, CA.getThreshold() - CA.getCost()); 959 } 960 961 return Base::visitCallSite(CS); 962 } 963 964 bool CallAnalyzer::visitReturnInst(ReturnInst &RI) { 965 // At least one return instruction will be free after inlining. 966 bool Free = !HasReturn; 967 HasReturn = true; 968 return Free; 969 } 970 971 bool CallAnalyzer::visitBranchInst(BranchInst &BI) { 972 // We model unconditional branches as essentially free -- they really 973 // shouldn't exist at all, but handling them makes the behavior of the 974 // inliner more regular and predictable. Interestingly, conditional branches 975 // which will fold away are also free. 976 return BI.isUnconditional() || isa<ConstantInt>(BI.getCondition()) || 977 dyn_cast_or_null<ConstantInt>( 978 SimplifiedValues.lookup(BI.getCondition())); 979 } 980 981 bool CallAnalyzer::visitSwitchInst(SwitchInst &SI) { 982 // We model unconditional switches as free, see the comments on handling 983 // branches. 984 if (isa<ConstantInt>(SI.getCondition())) 985 return true; 986 if (Value *V = SimplifiedValues.lookup(SI.getCondition())) 987 if (isa<ConstantInt>(V)) 988 return true; 989 990 // Otherwise, we need to accumulate a cost proportional to the number of 991 // distinct successor blocks. This fan-out in the CFG cannot be represented 992 // for free even if we can represent the core switch as a jumptable that 993 // takes a single instruction. 994 // 995 // NB: We convert large switches which are just used to initialize large phi 996 // nodes to lookup tables instead in simplify-cfg, so this shouldn't prevent 997 // inlining those. It will prevent inlining in cases where the optimization 998 // does not (yet) fire. 999 SmallPtrSet<BasicBlock *, 8> SuccessorBlocks; 1000 SuccessorBlocks.insert(SI.getDefaultDest()); 1001 for (auto I = SI.case_begin(), E = SI.case_end(); I != E; ++I) 1002 SuccessorBlocks.insert(I.getCaseSuccessor()); 1003 // Add cost corresponding to the number of distinct destinations. The first 1004 // we model as free because of fallthrough. 1005 Cost += (SuccessorBlocks.size() - 1) * InlineConstants::InstrCost; 1006 return false; 1007 } 1008 1009 bool CallAnalyzer::visitIndirectBrInst(IndirectBrInst &IBI) { 1010 // We never want to inline functions that contain an indirectbr. This is 1011 // incorrect because all the blockaddress's (in static global initializers 1012 // for example) would be referring to the original function, and this 1013 // indirect jump would jump from the inlined copy of the function into the 1014 // original function which is extremely undefined behavior. 1015 // FIXME: This logic isn't really right; we can safely inline functions with 1016 // indirectbr's as long as no other function or global references the 1017 // blockaddress of a block within the current function. 1018 HasIndirectBr = true; 1019 return false; 1020 } 1021 1022 bool CallAnalyzer::visitResumeInst(ResumeInst &RI) { 1023 // FIXME: It's not clear that a single instruction is an accurate model for 1024 // the inline cost of a resume instruction. 1025 return false; 1026 } 1027 1028 bool CallAnalyzer::visitCleanupReturnInst(CleanupReturnInst &CRI) { 1029 // FIXME: It's not clear that a single instruction is an accurate model for 1030 // the inline cost of a cleanupret instruction. 1031 return false; 1032 } 1033 1034 bool CallAnalyzer::visitCatchReturnInst(CatchReturnInst &CRI) { 1035 // FIXME: It's not clear that a single instruction is an accurate model for 1036 // the inline cost of a catchret instruction. 1037 return false; 1038 } 1039 1040 bool CallAnalyzer::visitUnreachableInst(UnreachableInst &I) { 1041 // FIXME: It might be reasonably to discount the cost of instructions leading 1042 // to unreachable as they have the lowest possible impact on both runtime and 1043 // code size. 1044 return true; // No actual code is needed for unreachable. 1045 } 1046 1047 bool CallAnalyzer::visitInstruction(Instruction &I) { 1048 // Some instructions are free. All of the free intrinsics can also be 1049 // handled by SROA, etc. 1050 if (TargetTransformInfo::TCC_Free == TTI.getUserCost(&I)) 1051 return true; 1052 1053 // We found something we don't understand or can't handle. Mark any SROA-able 1054 // values in the operand list as no longer viable. 1055 for (User::op_iterator OI = I.op_begin(), OE = I.op_end(); OI != OE; ++OI) 1056 disableSROA(*OI); 1057 1058 return false; 1059 } 1060 1061 /// \brief Analyze a basic block for its contribution to the inline cost. 1062 /// 1063 /// This method walks the analyzer over every instruction in the given basic 1064 /// block and accounts for their cost during inlining at this callsite. It 1065 /// aborts early if the threshold has been exceeded or an impossible to inline 1066 /// construct has been detected. It returns false if inlining is no longer 1067 /// viable, and true if inlining remains viable. 1068 bool CallAnalyzer::analyzeBlock(BasicBlock *BB, 1069 SmallPtrSetImpl<const Value *> &EphValues) { 1070 for (BasicBlock::iterator I = BB->begin(), E = BB->end(); I != E; ++I) { 1071 // FIXME: Currently, the number of instructions in a function regardless of 1072 // our ability to simplify them during inline to constants or dead code, 1073 // are actually used by the vector bonus heuristic. As long as that's true, 1074 // we have to special case debug intrinsics here to prevent differences in 1075 // inlining due to debug symbols. Eventually, the number of unsimplified 1076 // instructions shouldn't factor into the cost computation, but until then, 1077 // hack around it here. 1078 if (isa<DbgInfoIntrinsic>(I)) 1079 continue; 1080 1081 // Skip ephemeral values. 1082 if (EphValues.count(&*I)) 1083 continue; 1084 1085 ++NumInstructions; 1086 if (isa<ExtractElementInst>(I) || I->getType()->isVectorTy()) 1087 ++NumVectorInstructions; 1088 1089 // If the instruction is floating point, and the target says this operation 1090 // is expensive or the function has the "use-soft-float" attribute, this may 1091 // eventually become a library call. Treat the cost as such. 1092 if (I->getType()->isFloatingPointTy()) { 1093 bool hasSoftFloatAttr = false; 1094 1095 // If the function has the "use-soft-float" attribute, mark it as 1096 // expensive. 1097 if (F.hasFnAttribute("use-soft-float")) { 1098 Attribute Attr = F.getFnAttribute("use-soft-float"); 1099 StringRef Val = Attr.getValueAsString(); 1100 if (Val == "true") 1101 hasSoftFloatAttr = true; 1102 } 1103 1104 if (TTI.getFPOpCost(I->getType()) == TargetTransformInfo::TCC_Expensive || 1105 hasSoftFloatAttr) 1106 Cost += InlineConstants::CallPenalty; 1107 } 1108 1109 // If the instruction simplified to a constant, there is no cost to this 1110 // instruction. Visit the instructions using our InstVisitor to account for 1111 // all of the per-instruction logic. The visit tree returns true if we 1112 // consumed the instruction in any way, and false if the instruction's base 1113 // cost should count against inlining. 1114 if (Base::visit(&*I)) 1115 ++NumInstructionsSimplified; 1116 else 1117 Cost += InlineConstants::InstrCost; 1118 1119 // If the visit this instruction detected an uninlinable pattern, abort. 1120 if (IsRecursiveCall || ExposesReturnsTwice || HasDynamicAlloca || 1121 HasIndirectBr || HasFrameEscape) 1122 return false; 1123 1124 // If the caller is a recursive function then we don't want to inline 1125 // functions which allocate a lot of stack space because it would increase 1126 // the caller stack usage dramatically. 1127 if (IsCallerRecursive && 1128 AllocatedSize > InlineConstants::TotalAllocaSizeRecursiveCaller) 1129 return false; 1130 1131 // Check if we've past the maximum possible threshold so we don't spin in 1132 // huge basic blocks that will never inline. 1133 if (Cost > Threshold) 1134 return false; 1135 } 1136 1137 return true; 1138 } 1139 1140 /// \brief Compute the base pointer and cumulative constant offsets for V. 1141 /// 1142 /// This strips all constant offsets off of V, leaving it the base pointer, and 1143 /// accumulates the total constant offset applied in the returned constant. It 1144 /// returns 0 if V is not a pointer, and returns the constant '0' if there are 1145 /// no constant offsets applied. 1146 ConstantInt *CallAnalyzer::stripAndComputeInBoundsConstantOffsets(Value *&V) { 1147 if (!V->getType()->isPointerTy()) 1148 return nullptr; 1149 1150 const DataLayout &DL = F.getParent()->getDataLayout(); 1151 unsigned IntPtrWidth = DL.getPointerSizeInBits(); 1152 APInt Offset = APInt::getNullValue(IntPtrWidth); 1153 1154 // Even though we don't look through PHI nodes, we could be called on an 1155 // instruction in an unreachable block, which may be on a cycle. 1156 SmallPtrSet<Value *, 4> Visited; 1157 Visited.insert(V); 1158 do { 1159 if (GEPOperator *GEP = dyn_cast<GEPOperator>(V)) { 1160 if (!GEP->isInBounds() || !accumulateGEPOffset(*GEP, Offset)) 1161 return nullptr; 1162 V = GEP->getPointerOperand(); 1163 } else if (Operator::getOpcode(V) == Instruction::BitCast) { 1164 V = cast<Operator>(V)->getOperand(0); 1165 } else if (GlobalAlias *GA = dyn_cast<GlobalAlias>(V)) { 1166 if (GA->isInterposable()) 1167 break; 1168 V = GA->getAliasee(); 1169 } else { 1170 break; 1171 } 1172 assert(V->getType()->isPointerTy() && "Unexpected operand type!"); 1173 } while (Visited.insert(V).second); 1174 1175 Type *IntPtrTy = DL.getIntPtrType(V->getContext()); 1176 return cast<ConstantInt>(ConstantInt::get(IntPtrTy, Offset)); 1177 } 1178 1179 /// \brief Analyze a call site for potential inlining. 1180 /// 1181 /// Returns true if inlining this call is viable, and false if it is not 1182 /// viable. It computes the cost and adjusts the threshold based on numerous 1183 /// factors and heuristics. If this method returns false but the computed cost 1184 /// is below the computed threshold, then inlining was forcibly disabled by 1185 /// some artifact of the routine. 1186 bool CallAnalyzer::analyzeCall(CallSite CS) { 1187 ++NumCallsAnalyzed; 1188 1189 // Perform some tweaks to the cost and threshold based on the direct 1190 // callsite information. 1191 1192 // We want to more aggressively inline vector-dense kernels, so up the 1193 // threshold, and we'll lower it if the % of vector instructions gets too 1194 // low. Note that these bonuses are some what arbitrary and evolved over time 1195 // by accident as much as because they are principled bonuses. 1196 // 1197 // FIXME: It would be nice to remove all such bonuses. At least it would be 1198 // nice to base the bonus values on something more scientific. 1199 assert(NumInstructions == 0); 1200 assert(NumVectorInstructions == 0); 1201 1202 // Update the threshold based on callsite properties 1203 updateThreshold(CS, F); 1204 1205 FiftyPercentVectorBonus = 3 * Threshold / 2; 1206 TenPercentVectorBonus = 3 * Threshold / 4; 1207 const DataLayout &DL = F.getParent()->getDataLayout(); 1208 1209 // Track whether the post-inlining function would have more than one basic 1210 // block. A single basic block is often intended for inlining. Balloon the 1211 // threshold by 50% until we pass the single-BB phase. 1212 bool SingleBB = true; 1213 int SingleBBBonus = Threshold / 2; 1214 1215 // Speculatively apply all possible bonuses to Threshold. If cost exceeds 1216 // this Threshold any time, and cost cannot decrease, we can stop processing 1217 // the rest of the function body. 1218 Threshold += (SingleBBBonus + FiftyPercentVectorBonus); 1219 1220 // Give out bonuses per argument, as the instructions setting them up will 1221 // be gone after inlining. 1222 for (unsigned I = 0, E = CS.arg_size(); I != E; ++I) { 1223 if (CS.isByValArgument(I)) { 1224 // We approximate the number of loads and stores needed by dividing the 1225 // size of the byval type by the target's pointer size. 1226 PointerType *PTy = cast<PointerType>(CS.getArgument(I)->getType()); 1227 unsigned TypeSize = DL.getTypeSizeInBits(PTy->getElementType()); 1228 unsigned PointerSize = DL.getPointerSizeInBits(); 1229 // Ceiling division. 1230 unsigned NumStores = (TypeSize + PointerSize - 1) / PointerSize; 1231 1232 // If it generates more than 8 stores it is likely to be expanded as an 1233 // inline memcpy so we take that as an upper bound. Otherwise we assume 1234 // one load and one store per word copied. 1235 // FIXME: The maxStoresPerMemcpy setting from the target should be used 1236 // here instead of a magic number of 8, but it's not available via 1237 // DataLayout. 1238 NumStores = std::min(NumStores, 8U); 1239 1240 Cost -= 2 * NumStores * InlineConstants::InstrCost; 1241 } else { 1242 // For non-byval arguments subtract off one instruction per call 1243 // argument. 1244 Cost -= InlineConstants::InstrCost; 1245 } 1246 } 1247 1248 // If there is only one call of the function, and it has internal linkage, 1249 // the cost of inlining it drops dramatically. 1250 bool OnlyOneCallAndLocalLinkage = 1251 F.hasLocalLinkage() && F.hasOneUse() && &F == CS.getCalledFunction(); 1252 if (OnlyOneCallAndLocalLinkage) 1253 Cost += InlineConstants::LastCallToStaticBonus; 1254 1255 // If this function uses the coldcc calling convention, prefer not to inline 1256 // it. 1257 if (F.getCallingConv() == CallingConv::Cold) 1258 Cost += InlineConstants::ColdccPenalty; 1259 1260 // Check if we're done. This can happen due to bonuses and penalties. 1261 if (Cost > Threshold) 1262 return false; 1263 1264 if (F.empty()) 1265 return true; 1266 1267 Function *Caller = CS.getInstruction()->getParent()->getParent(); 1268 // Check if the caller function is recursive itself. 1269 for (User *U : Caller->users()) { 1270 CallSite Site(U); 1271 if (!Site) 1272 continue; 1273 Instruction *I = Site.getInstruction(); 1274 if (I->getParent()->getParent() == Caller) { 1275 IsCallerRecursive = true; 1276 break; 1277 } 1278 } 1279 1280 // Populate our simplified values by mapping from function arguments to call 1281 // arguments with known important simplifications. 1282 CallSite::arg_iterator CAI = CS.arg_begin(); 1283 for (Function::arg_iterator FAI = F.arg_begin(), FAE = F.arg_end(); 1284 FAI != FAE; ++FAI, ++CAI) { 1285 assert(CAI != CS.arg_end()); 1286 if (Constant *C = dyn_cast<Constant>(CAI)) 1287 SimplifiedValues[&*FAI] = C; 1288 1289 Value *PtrArg = *CAI; 1290 if (ConstantInt *C = stripAndComputeInBoundsConstantOffsets(PtrArg)) { 1291 ConstantOffsetPtrs[&*FAI] = std::make_pair(PtrArg, C->getValue()); 1292 1293 // We can SROA any pointer arguments derived from alloca instructions. 1294 if (isa<AllocaInst>(PtrArg)) { 1295 SROAArgValues[&*FAI] = PtrArg; 1296 SROAArgCosts[PtrArg] = 0; 1297 } 1298 } 1299 } 1300 NumConstantArgs = SimplifiedValues.size(); 1301 NumConstantOffsetPtrArgs = ConstantOffsetPtrs.size(); 1302 NumAllocaArgs = SROAArgValues.size(); 1303 1304 // FIXME: If a caller has multiple calls to a callee, we end up recomputing 1305 // the ephemeral values multiple times (and they're completely determined by 1306 // the callee, so this is purely duplicate work). 1307 SmallPtrSet<const Value *, 32> EphValues; 1308 CodeMetrics::collectEphemeralValues(&F, &ACT->getAssumptionCache(F), 1309 EphValues); 1310 1311 // The worklist of live basic blocks in the callee *after* inlining. We avoid 1312 // adding basic blocks of the callee which can be proven to be dead for this 1313 // particular call site in order to get more accurate cost estimates. This 1314 // requires a somewhat heavyweight iteration pattern: we need to walk the 1315 // basic blocks in a breadth-first order as we insert live successors. To 1316 // accomplish this, prioritizing for small iterations because we exit after 1317 // crossing our threshold, we use a small-size optimized SetVector. 1318 typedef SetVector<BasicBlock *, SmallVector<BasicBlock *, 16>, 1319 SmallPtrSet<BasicBlock *, 16>> 1320 BBSetVector; 1321 BBSetVector BBWorklist; 1322 BBWorklist.insert(&F.getEntryBlock()); 1323 // Note that we *must not* cache the size, this loop grows the worklist. 1324 for (unsigned Idx = 0; Idx != BBWorklist.size(); ++Idx) { 1325 // Bail out the moment we cross the threshold. This means we'll under-count 1326 // the cost, but only when undercounting doesn't matter. 1327 if (Cost > Threshold) 1328 break; 1329 1330 BasicBlock *BB = BBWorklist[Idx]; 1331 if (BB->empty()) 1332 continue; 1333 1334 // Disallow inlining a blockaddress. A blockaddress only has defined 1335 // behavior for an indirect branch in the same function, and we do not 1336 // currently support inlining indirect branches. But, the inliner may not 1337 // see an indirect branch that ends up being dead code at a particular call 1338 // site. If the blockaddress escapes the function, e.g., via a global 1339 // variable, inlining may lead to an invalid cross-function reference. 1340 if (BB->hasAddressTaken()) 1341 return false; 1342 1343 // Analyze the cost of this block. If we blow through the threshold, this 1344 // returns false, and we can bail on out. 1345 if (!analyzeBlock(BB, EphValues)) 1346 return false; 1347 1348 TerminatorInst *TI = BB->getTerminator(); 1349 1350 // Add in the live successors by first checking whether we have terminator 1351 // that may be simplified based on the values simplified by this call. 1352 if (BranchInst *BI = dyn_cast<BranchInst>(TI)) { 1353 if (BI->isConditional()) { 1354 Value *Cond = BI->getCondition(); 1355 if (ConstantInt *SimpleCond = 1356 dyn_cast_or_null<ConstantInt>(SimplifiedValues.lookup(Cond))) { 1357 BBWorklist.insert(BI->getSuccessor(SimpleCond->isZero() ? 1 : 0)); 1358 continue; 1359 } 1360 } 1361 } else if (SwitchInst *SI = dyn_cast<SwitchInst>(TI)) { 1362 Value *Cond = SI->getCondition(); 1363 if (ConstantInt *SimpleCond = 1364 dyn_cast_or_null<ConstantInt>(SimplifiedValues.lookup(Cond))) { 1365 BBWorklist.insert(SI->findCaseValue(SimpleCond).getCaseSuccessor()); 1366 continue; 1367 } 1368 } 1369 1370 // If we're unable to select a particular successor, just count all of 1371 // them. 1372 for (unsigned TIdx = 0, TSize = TI->getNumSuccessors(); TIdx != TSize; 1373 ++TIdx) 1374 BBWorklist.insert(TI->getSuccessor(TIdx)); 1375 1376 // If we had any successors at this point, than post-inlining is likely to 1377 // have them as well. Note that we assume any basic blocks which existed 1378 // due to branches or switches which folded above will also fold after 1379 // inlining. 1380 if (SingleBB && TI->getNumSuccessors() > 1) { 1381 // Take off the bonus we applied to the threshold. 1382 Threshold -= SingleBBBonus; 1383 SingleBB = false; 1384 } 1385 } 1386 1387 // If this is a noduplicate call, we can still inline as long as 1388 // inlining this would cause the removal of the caller (so the instruction 1389 // is not actually duplicated, just moved). 1390 if (!OnlyOneCallAndLocalLinkage && ContainsNoDuplicateCall) 1391 return false; 1392 1393 // We applied the maximum possible vector bonus at the beginning. Now, 1394 // subtract the excess bonus, if any, from the Threshold before 1395 // comparing against Cost. 1396 if (NumVectorInstructions <= NumInstructions / 10) 1397 Threshold -= FiftyPercentVectorBonus; 1398 else if (NumVectorInstructions <= NumInstructions / 2) 1399 Threshold -= (FiftyPercentVectorBonus - TenPercentVectorBonus); 1400 1401 return Cost < std::max(1, Threshold); 1402 } 1403 1404 #if !defined(NDEBUG) || defined(LLVM_ENABLE_DUMP) 1405 /// \brief Dump stats about this call's analysis. 1406 LLVM_DUMP_METHOD void CallAnalyzer::dump() { 1407 #define DEBUG_PRINT_STAT(x) dbgs() << " " #x ": " << x << "\n" 1408 DEBUG_PRINT_STAT(NumConstantArgs); 1409 DEBUG_PRINT_STAT(NumConstantOffsetPtrArgs); 1410 DEBUG_PRINT_STAT(NumAllocaArgs); 1411 DEBUG_PRINT_STAT(NumConstantPtrCmps); 1412 DEBUG_PRINT_STAT(NumConstantPtrDiffs); 1413 DEBUG_PRINT_STAT(NumInstructionsSimplified); 1414 DEBUG_PRINT_STAT(NumInstructions); 1415 DEBUG_PRINT_STAT(SROACostSavings); 1416 DEBUG_PRINT_STAT(SROACostSavingsLost); 1417 DEBUG_PRINT_STAT(ContainsNoDuplicateCall); 1418 DEBUG_PRINT_STAT(Cost); 1419 DEBUG_PRINT_STAT(Threshold); 1420 #undef DEBUG_PRINT_STAT 1421 } 1422 #endif 1423 1424 /// \brief Test that two functions either have or have not the given attribute 1425 /// at the same time. 1426 template <typename AttrKind> 1427 static bool attributeMatches(Function *F1, Function *F2, AttrKind Attr) { 1428 return F1->getFnAttribute(Attr) == F2->getFnAttribute(Attr); 1429 } 1430 1431 /// \brief Test that there are no attribute conflicts between Caller and Callee 1432 /// that prevent inlining. 1433 static bool functionsHaveCompatibleAttributes(Function *Caller, 1434 Function *Callee, 1435 TargetTransformInfo &TTI) { 1436 return TTI.areInlineCompatible(Caller, Callee) && 1437 AttributeFuncs::areInlineCompatible(*Caller, *Callee); 1438 } 1439 1440 InlineCost llvm::getInlineCost(CallSite CS, int DefaultThreshold, 1441 TargetTransformInfo &CalleeTTI, 1442 AssumptionCacheTracker *ACT, 1443 ProfileSummaryInfo *PSI) { 1444 return getInlineCost(CS, CS.getCalledFunction(), DefaultThreshold, CalleeTTI, 1445 ACT, PSI); 1446 } 1447 1448 int llvm::computeThresholdFromOptLevels(unsigned OptLevel, 1449 unsigned SizeOptLevel) { 1450 if (OptLevel > 2) 1451 return OptAggressiveThreshold; 1452 if (SizeOptLevel == 1) // -Os 1453 return OptSizeThreshold; 1454 if (SizeOptLevel == 2) // -Oz 1455 return OptMinSizeThreshold; 1456 return DefaultInlineThreshold; 1457 } 1458 1459 int llvm::getDefaultInlineThreshold() { return DefaultInlineThreshold; } 1460 1461 InlineCost llvm::getInlineCost(CallSite CS, Function *Callee, 1462 int DefaultThreshold, 1463 TargetTransformInfo &CalleeTTI, 1464 AssumptionCacheTracker *ACT, 1465 ProfileSummaryInfo *PSI) { 1466 1467 // Cannot inline indirect calls. 1468 if (!Callee) 1469 return llvm::InlineCost::getNever(); 1470 1471 // Calls to functions with always-inline attributes should be inlined 1472 // whenever possible. 1473 if (CS.hasFnAttr(Attribute::AlwaysInline)) { 1474 if (isInlineViable(*Callee)) 1475 return llvm::InlineCost::getAlways(); 1476 return llvm::InlineCost::getNever(); 1477 } 1478 1479 // Never inline functions with conflicting attributes (unless callee has 1480 // always-inline attribute). 1481 if (!functionsHaveCompatibleAttributes(CS.getCaller(), Callee, CalleeTTI)) 1482 return llvm::InlineCost::getNever(); 1483 1484 // Don't inline this call if the caller has the optnone attribute. 1485 if (CS.getCaller()->hasFnAttribute(Attribute::OptimizeNone)) 1486 return llvm::InlineCost::getNever(); 1487 1488 // Don't inline functions which can be interposed at link-time. Don't inline 1489 // functions marked noinline or call sites marked noinline. 1490 // Note: inlining non-exact non-interposable fucntions is fine, since we know 1491 // we have *a* correct implementation of the source level function. 1492 if (Callee->isInterposable() || Callee->hasFnAttribute(Attribute::NoInline) || 1493 CS.isNoInline()) 1494 return llvm::InlineCost::getNever(); 1495 1496 DEBUG(llvm::dbgs() << " Analyzing call of " << Callee->getName() 1497 << "...\n"); 1498 1499 CallAnalyzer CA(CalleeTTI, ACT, PSI, *Callee, DefaultThreshold, CS); 1500 bool ShouldInline = CA.analyzeCall(CS); 1501 1502 DEBUG(CA.dump()); 1503 1504 // Check if there was a reason to force inlining or no inlining. 1505 if (!ShouldInline && CA.getCost() < CA.getThreshold()) 1506 return InlineCost::getNever(); 1507 if (ShouldInline && CA.getCost() >= CA.getThreshold()) 1508 return InlineCost::getAlways(); 1509 1510 return llvm::InlineCost::get(CA.getCost(), CA.getThreshold()); 1511 } 1512 1513 bool llvm::isInlineViable(Function &F) { 1514 bool ReturnsTwice = F.hasFnAttribute(Attribute::ReturnsTwice); 1515 for (Function::iterator BI = F.begin(), BE = F.end(); BI != BE; ++BI) { 1516 // Disallow inlining of functions which contain indirect branches or 1517 // blockaddresses. 1518 if (isa<IndirectBrInst>(BI->getTerminator()) || BI->hasAddressTaken()) 1519 return false; 1520 1521 for (auto &II : *BI) { 1522 CallSite CS(&II); 1523 if (!CS) 1524 continue; 1525 1526 // Disallow recursive calls. 1527 if (&F == CS.getCalledFunction()) 1528 return false; 1529 1530 // Disallow calls which expose returns-twice to a function not previously 1531 // attributed as such. 1532 if (!ReturnsTwice && CS.isCall() && 1533 cast<CallInst>(CS.getInstruction())->canReturnTwice()) 1534 return false; 1535 1536 // Disallow inlining functions that call @llvm.localescape. Doing this 1537 // correctly would require major changes to the inliner. 1538 if (CS.getCalledFunction() && 1539 CS.getCalledFunction()->getIntrinsicID() == 1540 llvm::Intrinsic::localescape) 1541 return false; 1542 } 1543 } 1544 1545 return true; 1546 } 1547