1 //===- InlineCost.cpp - Cost analysis for inliner -------------------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 // This file implements inline cost analysis.
11 //
12 //===----------------------------------------------------------------------===//
13 
14 #include "llvm/Analysis/InlineCost.h"
15 #include "llvm/ADT/STLExtras.h"
16 #include "llvm/ADT/SetVector.h"
17 #include "llvm/ADT/SmallPtrSet.h"
18 #include "llvm/ADT/SmallVector.h"
19 #include "llvm/ADT/Statistic.h"
20 #include "llvm/Analysis/AssumptionCache.h"
21 #include "llvm/Analysis/CodeMetrics.h"
22 #include "llvm/Analysis/ConstantFolding.h"
23 #include "llvm/Analysis/InstructionSimplify.h"
24 #include "llvm/Analysis/ProfileSummaryInfo.h"
25 #include "llvm/Analysis/TargetTransformInfo.h"
26 #include "llvm/IR/CallSite.h"
27 #include "llvm/IR/CallingConv.h"
28 #include "llvm/IR/DataLayout.h"
29 #include "llvm/IR/GetElementPtrTypeIterator.h"
30 #include "llvm/IR/GlobalAlias.h"
31 #include "llvm/IR/InstVisitor.h"
32 #include "llvm/IR/IntrinsicInst.h"
33 #include "llvm/IR/Operator.h"
34 #include "llvm/Support/Debug.h"
35 #include "llvm/Support/raw_ostream.h"
36 
37 using namespace llvm;
38 
39 #define DEBUG_TYPE "inline-cost"
40 
41 STATISTIC(NumCallsAnalyzed, "Number of call sites analyzed");
42 
43 // Threshold to use when optsize is specified (and there is no
44 // -inline-threshold).
45 const int OptSizeThreshold = 75;
46 
47 // Threshold to use when -Oz is specified (and there is no -inline-threshold).
48 const int OptMinSizeThreshold = 25;
49 
50 // Threshold to use when -O[34] is specified (and there is no
51 // -inline-threshold).
52 const int OptAggressiveThreshold = 275;
53 
54 static cl::opt<int> DefaultInlineThreshold(
55     "inline-threshold", cl::Hidden, cl::init(225), cl::ZeroOrMore,
56     cl::desc("Control the amount of inlining to perform (default = 225)"));
57 
58 static cl::opt<int> HintThreshold(
59     "inlinehint-threshold", cl::Hidden, cl::init(325),
60     cl::desc("Threshold for inlining functions with inline hint"));
61 
62 // We introduce this threshold to help performance of instrumentation based
63 // PGO before we actually hook up inliner with analysis passes such as BPI and
64 // BFI.
65 static cl::opt<int> ColdThreshold(
66     "inlinecold-threshold", cl::Hidden, cl::init(225),
67     cl::desc("Threshold for inlining functions with cold attribute"));
68 
69 namespace {
70 
71 class CallAnalyzer : public InstVisitor<CallAnalyzer, bool> {
72   typedef InstVisitor<CallAnalyzer, bool> Base;
73   friend class InstVisitor<CallAnalyzer, bool>;
74 
75   /// The TargetTransformInfo available for this compilation.
76   const TargetTransformInfo &TTI;
77 
78   /// The cache of @llvm.assume intrinsics.
79   AssumptionCacheTracker *ACT;
80 
81   /// Profile summary information.
82   ProfileSummaryInfo *PSI;
83 
84   // The called function.
85   Function &F;
86 
87   // The candidate callsite being analyzed. Please do not use this to do
88   // analysis in the caller function; we want the inline cost query to be
89   // easily cacheable. Instead, use the cover function paramHasAttr.
90   CallSite CandidateCS;
91 
92   int Threshold;
93   int Cost;
94 
95   bool IsCallerRecursive;
96   bool IsRecursiveCall;
97   bool ExposesReturnsTwice;
98   bool HasDynamicAlloca;
99   bool ContainsNoDuplicateCall;
100   bool HasReturn;
101   bool HasIndirectBr;
102   bool HasFrameEscape;
103 
104   /// Number of bytes allocated statically by the callee.
105   uint64_t AllocatedSize;
106   unsigned NumInstructions, NumVectorInstructions;
107   int FiftyPercentVectorBonus, TenPercentVectorBonus;
108   int VectorBonus;
109 
110   // While we walk the potentially-inlined instructions, we build up and
111   // maintain a mapping of simplified values specific to this callsite. The
112   // idea is to propagate any special information we have about arguments to
113   // this call through the inlinable section of the function, and account for
114   // likely simplifications post-inlining. The most important aspect we track
115   // is CFG altering simplifications -- when we prove a basic block dead, that
116   // can cause dramatic shifts in the cost of inlining a function.
117   DenseMap<Value *, Constant *> SimplifiedValues;
118 
119   // Keep track of the values which map back (through function arguments) to
120   // allocas on the caller stack which could be simplified through SROA.
121   DenseMap<Value *, Value *> SROAArgValues;
122 
123   // The mapping of caller Alloca values to their accumulated cost savings. If
124   // we have to disable SROA for one of the allocas, this tells us how much
125   // cost must be added.
126   DenseMap<Value *, int> SROAArgCosts;
127 
128   // Keep track of values which map to a pointer base and constant offset.
129   DenseMap<Value *, std::pair<Value *, APInt>> ConstantOffsetPtrs;
130 
131   // Custom simplification helper routines.
132   bool isAllocaDerivedArg(Value *V);
133   bool lookupSROAArgAndCost(Value *V, Value *&Arg,
134                             DenseMap<Value *, int>::iterator &CostIt);
135   void disableSROA(DenseMap<Value *, int>::iterator CostIt);
136   void disableSROA(Value *V);
137   void accumulateSROACost(DenseMap<Value *, int>::iterator CostIt,
138                           int InstructionCost);
139   bool isGEPOffsetConstant(GetElementPtrInst &GEP);
140   bool accumulateGEPOffset(GEPOperator &GEP, APInt &Offset);
141   bool simplifyCallSite(Function *F, CallSite CS);
142   ConstantInt *stripAndComputeInBoundsConstantOffsets(Value *&V);
143 
144   /// Return true if the given argument to the function being considered for
145   /// inlining has the given attribute set either at the call site or the
146   /// function declaration.  Primarily used to inspect call site specific
147   /// attributes since these can be more precise than the ones on the callee
148   /// itself.
149   bool paramHasAttr(Argument *A, Attribute::AttrKind Attr);
150 
151   /// Return true if the given value is known non null within the callee if
152   /// inlined through this particular callsite.
153   bool isKnownNonNullInCallee(Value *V);
154 
155   /// Update Threshold based on callsite properties such as callee
156   /// attributes and callee hotness for PGO builds. The Callee is explicitly
157   /// passed to support analyzing indirect calls whose target is inferred by
158   /// analysis.
159   void updateThreshold(CallSite CS, Function &Callee);
160 
161   /// Return true if size growth is allowed when inlining the callee at CS.
162   bool allowSizeGrowth(CallSite CS);
163 
164   // Custom analysis routines.
165   bool analyzeBlock(BasicBlock *BB, SmallPtrSetImpl<const Value *> &EphValues);
166 
167   // Disable several entry points to the visitor so we don't accidentally use
168   // them by declaring but not defining them here.
169   void visit(Module *);
170   void visit(Module &);
171   void visit(Function *);
172   void visit(Function &);
173   void visit(BasicBlock *);
174   void visit(BasicBlock &);
175 
176   // Provide base case for our instruction visit.
177   bool visitInstruction(Instruction &I);
178 
179   // Our visit overrides.
180   bool visitAlloca(AllocaInst &I);
181   bool visitPHI(PHINode &I);
182   bool visitGetElementPtr(GetElementPtrInst &I);
183   bool visitBitCast(BitCastInst &I);
184   bool visitPtrToInt(PtrToIntInst &I);
185   bool visitIntToPtr(IntToPtrInst &I);
186   bool visitCastInst(CastInst &I);
187   bool visitUnaryInstruction(UnaryInstruction &I);
188   bool visitCmpInst(CmpInst &I);
189   bool visitSub(BinaryOperator &I);
190   bool visitBinaryOperator(BinaryOperator &I);
191   bool visitLoad(LoadInst &I);
192   bool visitStore(StoreInst &I);
193   bool visitExtractValue(ExtractValueInst &I);
194   bool visitInsertValue(InsertValueInst &I);
195   bool visitCallSite(CallSite CS);
196   bool visitReturnInst(ReturnInst &RI);
197   bool visitBranchInst(BranchInst &BI);
198   bool visitSwitchInst(SwitchInst &SI);
199   bool visitIndirectBrInst(IndirectBrInst &IBI);
200   bool visitResumeInst(ResumeInst &RI);
201   bool visitCleanupReturnInst(CleanupReturnInst &RI);
202   bool visitCatchReturnInst(CatchReturnInst &RI);
203   bool visitUnreachableInst(UnreachableInst &I);
204 
205 public:
206   CallAnalyzer(const TargetTransformInfo &TTI, AssumptionCacheTracker *ACT,
207                ProfileSummaryInfo *PSI, Function &Callee, int Threshold,
208                CallSite CSArg)
209       : TTI(TTI), ACT(ACT), PSI(PSI), F(Callee), CandidateCS(CSArg),
210         Threshold(Threshold), Cost(0), IsCallerRecursive(false),
211         IsRecursiveCall(false), ExposesReturnsTwice(false),
212         HasDynamicAlloca(false), ContainsNoDuplicateCall(false),
213         HasReturn(false), HasIndirectBr(false), HasFrameEscape(false),
214         AllocatedSize(0), NumInstructions(0), NumVectorInstructions(0),
215         FiftyPercentVectorBonus(0), TenPercentVectorBonus(0), VectorBonus(0),
216         NumConstantArgs(0), NumConstantOffsetPtrArgs(0), NumAllocaArgs(0),
217         NumConstantPtrCmps(0), NumConstantPtrDiffs(0),
218         NumInstructionsSimplified(0), SROACostSavings(0),
219         SROACostSavingsLost(0) {}
220 
221   bool analyzeCall(CallSite CS);
222 
223   int getThreshold() { return Threshold; }
224   int getCost() { return Cost; }
225 
226   // Keep a bunch of stats about the cost savings found so we can print them
227   // out when debugging.
228   unsigned NumConstantArgs;
229   unsigned NumConstantOffsetPtrArgs;
230   unsigned NumAllocaArgs;
231   unsigned NumConstantPtrCmps;
232   unsigned NumConstantPtrDiffs;
233   unsigned NumInstructionsSimplified;
234   unsigned SROACostSavings;
235   unsigned SROACostSavingsLost;
236 
237   void dump();
238 };
239 
240 } // namespace
241 
242 /// \brief Test whether the given value is an Alloca-derived function argument.
243 bool CallAnalyzer::isAllocaDerivedArg(Value *V) {
244   return SROAArgValues.count(V);
245 }
246 
247 /// \brief Lookup the SROA-candidate argument and cost iterator which V maps to.
248 /// Returns false if V does not map to a SROA-candidate.
249 bool CallAnalyzer::lookupSROAArgAndCost(
250     Value *V, Value *&Arg, DenseMap<Value *, int>::iterator &CostIt) {
251   if (SROAArgValues.empty() || SROAArgCosts.empty())
252     return false;
253 
254   DenseMap<Value *, Value *>::iterator ArgIt = SROAArgValues.find(V);
255   if (ArgIt == SROAArgValues.end())
256     return false;
257 
258   Arg = ArgIt->second;
259   CostIt = SROAArgCosts.find(Arg);
260   return CostIt != SROAArgCosts.end();
261 }
262 
263 /// \brief Disable SROA for the candidate marked by this cost iterator.
264 ///
265 /// This marks the candidate as no longer viable for SROA, and adds the cost
266 /// savings associated with it back into the inline cost measurement.
267 void CallAnalyzer::disableSROA(DenseMap<Value *, int>::iterator CostIt) {
268   // If we're no longer able to perform SROA we need to undo its cost savings
269   // and prevent subsequent analysis.
270   Cost += CostIt->second;
271   SROACostSavings -= CostIt->second;
272   SROACostSavingsLost += CostIt->second;
273   SROAArgCosts.erase(CostIt);
274 }
275 
276 /// \brief If 'V' maps to a SROA candidate, disable SROA for it.
277 void CallAnalyzer::disableSROA(Value *V) {
278   Value *SROAArg;
279   DenseMap<Value *, int>::iterator CostIt;
280   if (lookupSROAArgAndCost(V, SROAArg, CostIt))
281     disableSROA(CostIt);
282 }
283 
284 /// \brief Accumulate the given cost for a particular SROA candidate.
285 void CallAnalyzer::accumulateSROACost(DenseMap<Value *, int>::iterator CostIt,
286                                       int InstructionCost) {
287   CostIt->second += InstructionCost;
288   SROACostSavings += InstructionCost;
289 }
290 
291 /// \brief Check whether a GEP's indices are all constant.
292 ///
293 /// Respects any simplified values known during the analysis of this callsite.
294 bool CallAnalyzer::isGEPOffsetConstant(GetElementPtrInst &GEP) {
295   for (User::op_iterator I = GEP.idx_begin(), E = GEP.idx_end(); I != E; ++I)
296     if (!isa<Constant>(*I) && !SimplifiedValues.lookup(*I))
297       return false;
298 
299   return true;
300 }
301 
302 /// \brief Accumulate a constant GEP offset into an APInt if possible.
303 ///
304 /// Returns false if unable to compute the offset for any reason. Respects any
305 /// simplified values known during the analysis of this callsite.
306 bool CallAnalyzer::accumulateGEPOffset(GEPOperator &GEP, APInt &Offset) {
307   const DataLayout &DL = F.getParent()->getDataLayout();
308   unsigned IntPtrWidth = DL.getPointerSizeInBits();
309   assert(IntPtrWidth == Offset.getBitWidth());
310 
311   for (gep_type_iterator GTI = gep_type_begin(GEP), GTE = gep_type_end(GEP);
312        GTI != GTE; ++GTI) {
313     ConstantInt *OpC = dyn_cast<ConstantInt>(GTI.getOperand());
314     if (!OpC)
315       if (Constant *SimpleOp = SimplifiedValues.lookup(GTI.getOperand()))
316         OpC = dyn_cast<ConstantInt>(SimpleOp);
317     if (!OpC)
318       return false;
319     if (OpC->isZero())
320       continue;
321 
322     // Handle a struct index, which adds its field offset to the pointer.
323     if (StructType *STy = dyn_cast<StructType>(*GTI)) {
324       unsigned ElementIdx = OpC->getZExtValue();
325       const StructLayout *SL = DL.getStructLayout(STy);
326       Offset += APInt(IntPtrWidth, SL->getElementOffset(ElementIdx));
327       continue;
328     }
329 
330     APInt TypeSize(IntPtrWidth, DL.getTypeAllocSize(GTI.getIndexedType()));
331     Offset += OpC->getValue().sextOrTrunc(IntPtrWidth) * TypeSize;
332   }
333   return true;
334 }
335 
336 bool CallAnalyzer::visitAlloca(AllocaInst &I) {
337   // Check whether inlining will turn a dynamic alloca into a static
338   // alloca and handle that case.
339   if (I.isArrayAllocation()) {
340     Constant *Size = SimplifiedValues.lookup(I.getArraySize());
341     if (auto *AllocSize = dyn_cast_or_null<ConstantInt>(Size)) {
342       const DataLayout &DL = F.getParent()->getDataLayout();
343       Type *Ty = I.getAllocatedType();
344       AllocatedSize = SaturatingMultiplyAdd(
345           AllocSize->getLimitedValue(), DL.getTypeAllocSize(Ty), AllocatedSize);
346       return Base::visitAlloca(I);
347     }
348   }
349 
350   // Accumulate the allocated size.
351   if (I.isStaticAlloca()) {
352     const DataLayout &DL = F.getParent()->getDataLayout();
353     Type *Ty = I.getAllocatedType();
354     AllocatedSize = SaturatingAdd(DL.getTypeAllocSize(Ty), AllocatedSize);
355   }
356 
357   // We will happily inline static alloca instructions.
358   if (I.isStaticAlloca())
359     return Base::visitAlloca(I);
360 
361   // FIXME: This is overly conservative. Dynamic allocas are inefficient for
362   // a variety of reasons, and so we would like to not inline them into
363   // functions which don't currently have a dynamic alloca. This simply
364   // disables inlining altogether in the presence of a dynamic alloca.
365   HasDynamicAlloca = true;
366   return false;
367 }
368 
369 bool CallAnalyzer::visitPHI(PHINode &I) {
370   // FIXME: We should potentially be tracking values through phi nodes,
371   // especially when they collapse to a single value due to deleted CFG edges
372   // during inlining.
373 
374   // FIXME: We need to propagate SROA *disabling* through phi nodes, even
375   // though we don't want to propagate it's bonuses. The idea is to disable
376   // SROA if it *might* be used in an inappropriate manner.
377 
378   // Phi nodes are always zero-cost.
379   return true;
380 }
381 
382 bool CallAnalyzer::visitGetElementPtr(GetElementPtrInst &I) {
383   Value *SROAArg;
384   DenseMap<Value *, int>::iterator CostIt;
385   bool SROACandidate =
386       lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt);
387 
388   // Try to fold GEPs of constant-offset call site argument pointers. This
389   // requires target data and inbounds GEPs.
390   if (I.isInBounds()) {
391     // Check if we have a base + offset for the pointer.
392     Value *Ptr = I.getPointerOperand();
393     std::pair<Value *, APInt> BaseAndOffset = ConstantOffsetPtrs.lookup(Ptr);
394     if (BaseAndOffset.first) {
395       // Check if the offset of this GEP is constant, and if so accumulate it
396       // into Offset.
397       if (!accumulateGEPOffset(cast<GEPOperator>(I), BaseAndOffset.second)) {
398         // Non-constant GEPs aren't folded, and disable SROA.
399         if (SROACandidate)
400           disableSROA(CostIt);
401         return false;
402       }
403 
404       // Add the result as a new mapping to Base + Offset.
405       ConstantOffsetPtrs[&I] = BaseAndOffset;
406 
407       // Also handle SROA candidates here, we already know that the GEP is
408       // all-constant indexed.
409       if (SROACandidate)
410         SROAArgValues[&I] = SROAArg;
411 
412       return true;
413     }
414   }
415 
416   if (isGEPOffsetConstant(I)) {
417     if (SROACandidate)
418       SROAArgValues[&I] = SROAArg;
419 
420     // Constant GEPs are modeled as free.
421     return true;
422   }
423 
424   // Variable GEPs will require math and will disable SROA.
425   if (SROACandidate)
426     disableSROA(CostIt);
427   return false;
428 }
429 
430 bool CallAnalyzer::visitBitCast(BitCastInst &I) {
431   // Propagate constants through bitcasts.
432   Constant *COp = dyn_cast<Constant>(I.getOperand(0));
433   if (!COp)
434     COp = SimplifiedValues.lookup(I.getOperand(0));
435   if (COp)
436     if (Constant *C = ConstantExpr::getBitCast(COp, I.getType())) {
437       SimplifiedValues[&I] = C;
438       return true;
439     }
440 
441   // Track base/offsets through casts
442   std::pair<Value *, APInt> BaseAndOffset =
443       ConstantOffsetPtrs.lookup(I.getOperand(0));
444   // Casts don't change the offset, just wrap it up.
445   if (BaseAndOffset.first)
446     ConstantOffsetPtrs[&I] = BaseAndOffset;
447 
448   // Also look for SROA candidates here.
449   Value *SROAArg;
450   DenseMap<Value *, int>::iterator CostIt;
451   if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt))
452     SROAArgValues[&I] = SROAArg;
453 
454   // Bitcasts are always zero cost.
455   return true;
456 }
457 
458 bool CallAnalyzer::visitPtrToInt(PtrToIntInst &I) {
459   // Propagate constants through ptrtoint.
460   Constant *COp = dyn_cast<Constant>(I.getOperand(0));
461   if (!COp)
462     COp = SimplifiedValues.lookup(I.getOperand(0));
463   if (COp)
464     if (Constant *C = ConstantExpr::getPtrToInt(COp, I.getType())) {
465       SimplifiedValues[&I] = C;
466       return true;
467     }
468 
469   // Track base/offset pairs when converted to a plain integer provided the
470   // integer is large enough to represent the pointer.
471   unsigned IntegerSize = I.getType()->getScalarSizeInBits();
472   const DataLayout &DL = F.getParent()->getDataLayout();
473   if (IntegerSize >= DL.getPointerSizeInBits()) {
474     std::pair<Value *, APInt> BaseAndOffset =
475         ConstantOffsetPtrs.lookup(I.getOperand(0));
476     if (BaseAndOffset.first)
477       ConstantOffsetPtrs[&I] = BaseAndOffset;
478   }
479 
480   // This is really weird. Technically, ptrtoint will disable SROA. However,
481   // unless that ptrtoint is *used* somewhere in the live basic blocks after
482   // inlining, it will be nuked, and SROA should proceed. All of the uses which
483   // would block SROA would also block SROA if applied directly to a pointer,
484   // and so we can just add the integer in here. The only places where SROA is
485   // preserved either cannot fire on an integer, or won't in-and-of themselves
486   // disable SROA (ext) w/o some later use that we would see and disable.
487   Value *SROAArg;
488   DenseMap<Value *, int>::iterator CostIt;
489   if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt))
490     SROAArgValues[&I] = SROAArg;
491 
492   return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I);
493 }
494 
495 bool CallAnalyzer::visitIntToPtr(IntToPtrInst &I) {
496   // Propagate constants through ptrtoint.
497   Constant *COp = dyn_cast<Constant>(I.getOperand(0));
498   if (!COp)
499     COp = SimplifiedValues.lookup(I.getOperand(0));
500   if (COp)
501     if (Constant *C = ConstantExpr::getIntToPtr(COp, I.getType())) {
502       SimplifiedValues[&I] = C;
503       return true;
504     }
505 
506   // Track base/offset pairs when round-tripped through a pointer without
507   // modifications provided the integer is not too large.
508   Value *Op = I.getOperand(0);
509   unsigned IntegerSize = Op->getType()->getScalarSizeInBits();
510   const DataLayout &DL = F.getParent()->getDataLayout();
511   if (IntegerSize <= DL.getPointerSizeInBits()) {
512     std::pair<Value *, APInt> BaseAndOffset = ConstantOffsetPtrs.lookup(Op);
513     if (BaseAndOffset.first)
514       ConstantOffsetPtrs[&I] = BaseAndOffset;
515   }
516 
517   // "Propagate" SROA here in the same manner as we do for ptrtoint above.
518   Value *SROAArg;
519   DenseMap<Value *, int>::iterator CostIt;
520   if (lookupSROAArgAndCost(Op, SROAArg, CostIt))
521     SROAArgValues[&I] = SROAArg;
522 
523   return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I);
524 }
525 
526 bool CallAnalyzer::visitCastInst(CastInst &I) {
527   // Propagate constants through ptrtoint.
528   Constant *COp = dyn_cast<Constant>(I.getOperand(0));
529   if (!COp)
530     COp = SimplifiedValues.lookup(I.getOperand(0));
531   if (COp)
532     if (Constant *C = ConstantExpr::getCast(I.getOpcode(), COp, I.getType())) {
533       SimplifiedValues[&I] = C;
534       return true;
535     }
536 
537   // Disable SROA in the face of arbitrary casts we don't whitelist elsewhere.
538   disableSROA(I.getOperand(0));
539 
540   return TargetTransformInfo::TCC_Free == TTI.getUserCost(&I);
541 }
542 
543 bool CallAnalyzer::visitUnaryInstruction(UnaryInstruction &I) {
544   Value *Operand = I.getOperand(0);
545   Constant *COp = dyn_cast<Constant>(Operand);
546   if (!COp)
547     COp = SimplifiedValues.lookup(Operand);
548   if (COp) {
549     const DataLayout &DL = F.getParent()->getDataLayout();
550     if (Constant *C = ConstantFoldInstOperands(&I, COp, DL)) {
551       SimplifiedValues[&I] = C;
552       return true;
553     }
554   }
555 
556   // Disable any SROA on the argument to arbitrary unary operators.
557   disableSROA(Operand);
558 
559   return false;
560 }
561 
562 bool CallAnalyzer::paramHasAttr(Argument *A, Attribute::AttrKind Attr) {
563   unsigned ArgNo = A->getArgNo();
564   return CandidateCS.paramHasAttr(ArgNo + 1, Attr);
565 }
566 
567 bool CallAnalyzer::isKnownNonNullInCallee(Value *V) {
568   // Does the *call site* have the NonNull attribute set on an argument?  We
569   // use the attribute on the call site to memoize any analysis done in the
570   // caller. This will also trip if the callee function has a non-null
571   // parameter attribute, but that's a less interesting case because hopefully
572   // the callee would already have been simplified based on that.
573   if (Argument *A = dyn_cast<Argument>(V))
574     if (paramHasAttr(A, Attribute::NonNull))
575       return true;
576 
577   // Is this an alloca in the caller?  This is distinct from the attribute case
578   // above because attributes aren't updated within the inliner itself and we
579   // always want to catch the alloca derived case.
580   if (isAllocaDerivedArg(V))
581     // We can actually predict the result of comparisons between an
582     // alloca-derived value and null. Note that this fires regardless of
583     // SROA firing.
584     return true;
585 
586   return false;
587 }
588 
589 bool CallAnalyzer::allowSizeGrowth(CallSite CS) {
590   // If the normal destination of the invoke or the parent block of the call
591   // site is unreachable-terminated, there is little point in inlining this
592   // unless there is literally zero cost.
593   // FIXME: Note that it is possible that an unreachable-terminated block has a
594   // hot entry. For example, in below scenario inlining hot_call_X() may be
595   // beneficial :
596   // main() {
597   //   hot_call_1();
598   //   ...
599   //   hot_call_N()
600   //   exit(0);
601   // }
602   // For now, we are not handling this corner case here as it is rare in real
603   // code. In future, we should elaborate this based on BPI and BFI in more
604   // general threshold adjusting heuristics in updateThreshold().
605   Instruction *Instr = CS.getInstruction();
606   if (InvokeInst *II = dyn_cast<InvokeInst>(Instr)) {
607     if (isa<UnreachableInst>(II->getNormalDest()->getTerminator()))
608       return false;
609   } else if (isa<UnreachableInst>(Instr->getParent()->getTerminator()))
610     return false;
611 
612   return true;
613 }
614 
615 void CallAnalyzer::updateThreshold(CallSite CS, Function &Callee) {
616   // If no size growth is allowed for this inlining, set Threshold to 0.
617   if (!allowSizeGrowth(CS)) {
618     Threshold = 0;
619     return;
620   }
621 
622   Function *Caller = CS.getCaller();
623   if (DefaultInlineThreshold.getNumOccurrences() > 0) {
624     // Explicitly specified -inline-threhold overrides the threshold passed to
625     // CallAnalyzer's constructor.
626     Threshold = DefaultInlineThreshold;
627   } else {
628     // If -inline-threshold is not given, listen to the optsize and minsize
629     // attributes when they would decrease the threshold.
630     if (Caller->optForMinSize() && OptMinSizeThreshold < Threshold)
631       Threshold = OptMinSizeThreshold;
632     else if (Caller->optForSize() && OptSizeThreshold < Threshold)
633       Threshold = OptSizeThreshold;
634   }
635 
636   // Listen to the inlinehint attribute or profile based hotness information
637   // when it would increase the threshold and the caller does not need to
638   // minimize its size.
639   bool InlineHint = Callee.hasFnAttribute(Attribute::InlineHint) ||
640                     PSI->isHotFunction(&Callee);
641   if (InlineHint && HintThreshold > Threshold && !Caller->optForMinSize())
642     Threshold = HintThreshold;
643 
644   bool ColdCallee = PSI->isColdFunction(&Callee);
645   // Command line argument for DefaultInlineThreshold will override the default
646   // ColdThreshold. If we have -inline-threshold but no -inlinecold-threshold,
647   // do not use the default cold threshold even if it is smaller.
648   if ((DefaultInlineThreshold.getNumOccurrences() == 0 ||
649        ColdThreshold.getNumOccurrences() > 0) &&
650       ColdCallee && ColdThreshold < Threshold)
651     Threshold = ColdThreshold;
652 
653   // Finally, take the target-specific inlining threshold multiplier into
654   // account.
655   Threshold *= TTI.getInliningThresholdMultiplier();
656 }
657 
658 bool CallAnalyzer::visitCmpInst(CmpInst &I) {
659   Value *LHS = I.getOperand(0), *RHS = I.getOperand(1);
660   // First try to handle simplified comparisons.
661   if (!isa<Constant>(LHS))
662     if (Constant *SimpleLHS = SimplifiedValues.lookup(LHS))
663       LHS = SimpleLHS;
664   if (!isa<Constant>(RHS))
665     if (Constant *SimpleRHS = SimplifiedValues.lookup(RHS))
666       RHS = SimpleRHS;
667   if (Constant *CLHS = dyn_cast<Constant>(LHS)) {
668     if (Constant *CRHS = dyn_cast<Constant>(RHS))
669       if (Constant *C =
670               ConstantExpr::getCompare(I.getPredicate(), CLHS, CRHS)) {
671         SimplifiedValues[&I] = C;
672         return true;
673       }
674   }
675 
676   if (I.getOpcode() == Instruction::FCmp)
677     return false;
678 
679   // Otherwise look for a comparison between constant offset pointers with
680   // a common base.
681   Value *LHSBase, *RHSBase;
682   APInt LHSOffset, RHSOffset;
683   std::tie(LHSBase, LHSOffset) = ConstantOffsetPtrs.lookup(LHS);
684   if (LHSBase) {
685     std::tie(RHSBase, RHSOffset) = ConstantOffsetPtrs.lookup(RHS);
686     if (RHSBase && LHSBase == RHSBase) {
687       // We have common bases, fold the icmp to a constant based on the
688       // offsets.
689       Constant *CLHS = ConstantInt::get(LHS->getContext(), LHSOffset);
690       Constant *CRHS = ConstantInt::get(RHS->getContext(), RHSOffset);
691       if (Constant *C = ConstantExpr::getICmp(I.getPredicate(), CLHS, CRHS)) {
692         SimplifiedValues[&I] = C;
693         ++NumConstantPtrCmps;
694         return true;
695       }
696     }
697   }
698 
699   // If the comparison is an equality comparison with null, we can simplify it
700   // if we know the value (argument) can't be null
701   if (I.isEquality() && isa<ConstantPointerNull>(I.getOperand(1)) &&
702       isKnownNonNullInCallee(I.getOperand(0))) {
703     bool IsNotEqual = I.getPredicate() == CmpInst::ICMP_NE;
704     SimplifiedValues[&I] = IsNotEqual ? ConstantInt::getTrue(I.getType())
705                                       : ConstantInt::getFalse(I.getType());
706     return true;
707   }
708   // Finally check for SROA candidates in comparisons.
709   Value *SROAArg;
710   DenseMap<Value *, int>::iterator CostIt;
711   if (lookupSROAArgAndCost(I.getOperand(0), SROAArg, CostIt)) {
712     if (isa<ConstantPointerNull>(I.getOperand(1))) {
713       accumulateSROACost(CostIt, InlineConstants::InstrCost);
714       return true;
715     }
716 
717     disableSROA(CostIt);
718   }
719 
720   return false;
721 }
722 
723 bool CallAnalyzer::visitSub(BinaryOperator &I) {
724   // Try to handle a special case: we can fold computing the difference of two
725   // constant-related pointers.
726   Value *LHS = I.getOperand(0), *RHS = I.getOperand(1);
727   Value *LHSBase, *RHSBase;
728   APInt LHSOffset, RHSOffset;
729   std::tie(LHSBase, LHSOffset) = ConstantOffsetPtrs.lookup(LHS);
730   if (LHSBase) {
731     std::tie(RHSBase, RHSOffset) = ConstantOffsetPtrs.lookup(RHS);
732     if (RHSBase && LHSBase == RHSBase) {
733       // We have common bases, fold the subtract to a constant based on the
734       // offsets.
735       Constant *CLHS = ConstantInt::get(LHS->getContext(), LHSOffset);
736       Constant *CRHS = ConstantInt::get(RHS->getContext(), RHSOffset);
737       if (Constant *C = ConstantExpr::getSub(CLHS, CRHS)) {
738         SimplifiedValues[&I] = C;
739         ++NumConstantPtrDiffs;
740         return true;
741       }
742     }
743   }
744 
745   // Otherwise, fall back to the generic logic for simplifying and handling
746   // instructions.
747   return Base::visitSub(I);
748 }
749 
750 bool CallAnalyzer::visitBinaryOperator(BinaryOperator &I) {
751   Value *LHS = I.getOperand(0), *RHS = I.getOperand(1);
752   const DataLayout &DL = F.getParent()->getDataLayout();
753   if (!isa<Constant>(LHS))
754     if (Constant *SimpleLHS = SimplifiedValues.lookup(LHS))
755       LHS = SimpleLHS;
756   if (!isa<Constant>(RHS))
757     if (Constant *SimpleRHS = SimplifiedValues.lookup(RHS))
758       RHS = SimpleRHS;
759   Value *SimpleV = nullptr;
760   if (auto FI = dyn_cast<FPMathOperator>(&I))
761     SimpleV =
762         SimplifyFPBinOp(I.getOpcode(), LHS, RHS, FI->getFastMathFlags(), DL);
763   else
764     SimpleV = SimplifyBinOp(I.getOpcode(), LHS, RHS, DL);
765 
766   if (Constant *C = dyn_cast_or_null<Constant>(SimpleV)) {
767     SimplifiedValues[&I] = C;
768     return true;
769   }
770 
771   // Disable any SROA on arguments to arbitrary, unsimplified binary operators.
772   disableSROA(LHS);
773   disableSROA(RHS);
774 
775   return false;
776 }
777 
778 bool CallAnalyzer::visitLoad(LoadInst &I) {
779   Value *SROAArg;
780   DenseMap<Value *, int>::iterator CostIt;
781   if (lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt)) {
782     if (I.isSimple()) {
783       accumulateSROACost(CostIt, InlineConstants::InstrCost);
784       return true;
785     }
786 
787     disableSROA(CostIt);
788   }
789 
790   return false;
791 }
792 
793 bool CallAnalyzer::visitStore(StoreInst &I) {
794   Value *SROAArg;
795   DenseMap<Value *, int>::iterator CostIt;
796   if (lookupSROAArgAndCost(I.getPointerOperand(), SROAArg, CostIt)) {
797     if (I.isSimple()) {
798       accumulateSROACost(CostIt, InlineConstants::InstrCost);
799       return true;
800     }
801 
802     disableSROA(CostIt);
803   }
804 
805   return false;
806 }
807 
808 bool CallAnalyzer::visitExtractValue(ExtractValueInst &I) {
809   // Constant folding for extract value is trivial.
810   Constant *C = dyn_cast<Constant>(I.getAggregateOperand());
811   if (!C)
812     C = SimplifiedValues.lookup(I.getAggregateOperand());
813   if (C) {
814     SimplifiedValues[&I] = ConstantExpr::getExtractValue(C, I.getIndices());
815     return true;
816   }
817 
818   // SROA can look through these but give them a cost.
819   return false;
820 }
821 
822 bool CallAnalyzer::visitInsertValue(InsertValueInst &I) {
823   // Constant folding for insert value is trivial.
824   Constant *AggC = dyn_cast<Constant>(I.getAggregateOperand());
825   if (!AggC)
826     AggC = SimplifiedValues.lookup(I.getAggregateOperand());
827   Constant *InsertedC = dyn_cast<Constant>(I.getInsertedValueOperand());
828   if (!InsertedC)
829     InsertedC = SimplifiedValues.lookup(I.getInsertedValueOperand());
830   if (AggC && InsertedC) {
831     SimplifiedValues[&I] =
832         ConstantExpr::getInsertValue(AggC, InsertedC, I.getIndices());
833     return true;
834   }
835 
836   // SROA can look through these but give them a cost.
837   return false;
838 }
839 
840 /// \brief Try to simplify a call site.
841 ///
842 /// Takes a concrete function and callsite and tries to actually simplify it by
843 /// analyzing the arguments and call itself with instsimplify. Returns true if
844 /// it has simplified the callsite to some other entity (a constant), making it
845 /// free.
846 bool CallAnalyzer::simplifyCallSite(Function *F, CallSite CS) {
847   // FIXME: Using the instsimplify logic directly for this is inefficient
848   // because we have to continually rebuild the argument list even when no
849   // simplifications can be performed. Until that is fixed with remapping
850   // inside of instsimplify, directly constant fold calls here.
851   if (!canConstantFoldCallTo(F))
852     return false;
853 
854   // Try to re-map the arguments to constants.
855   SmallVector<Constant *, 4> ConstantArgs;
856   ConstantArgs.reserve(CS.arg_size());
857   for (CallSite::arg_iterator I = CS.arg_begin(), E = CS.arg_end(); I != E;
858        ++I) {
859     Constant *C = dyn_cast<Constant>(*I);
860     if (!C)
861       C = dyn_cast_or_null<Constant>(SimplifiedValues.lookup(*I));
862     if (!C)
863       return false; // This argument doesn't map to a constant.
864 
865     ConstantArgs.push_back(C);
866   }
867   if (Constant *C = ConstantFoldCall(F, ConstantArgs)) {
868     SimplifiedValues[CS.getInstruction()] = C;
869     return true;
870   }
871 
872   return false;
873 }
874 
875 bool CallAnalyzer::visitCallSite(CallSite CS) {
876   if (CS.hasFnAttr(Attribute::ReturnsTwice) &&
877       !F.hasFnAttribute(Attribute::ReturnsTwice)) {
878     // This aborts the entire analysis.
879     ExposesReturnsTwice = true;
880     return false;
881   }
882   if (CS.isCall() && cast<CallInst>(CS.getInstruction())->cannotDuplicate())
883     ContainsNoDuplicateCall = true;
884 
885   if (Function *F = CS.getCalledFunction()) {
886     // When we have a concrete function, first try to simplify it directly.
887     if (simplifyCallSite(F, CS))
888       return true;
889 
890     // Next check if it is an intrinsic we know about.
891     // FIXME: Lift this into part of the InstVisitor.
892     if (IntrinsicInst *II = dyn_cast<IntrinsicInst>(CS.getInstruction())) {
893       switch (II->getIntrinsicID()) {
894       default:
895         return Base::visitCallSite(CS);
896 
897       case Intrinsic::load_relative:
898         // This is normally lowered to 4 LLVM instructions.
899         Cost += 3 * InlineConstants::InstrCost;
900         return false;
901 
902       case Intrinsic::memset:
903       case Intrinsic::memcpy:
904       case Intrinsic::memmove:
905         // SROA can usually chew through these intrinsics, but they aren't free.
906         return false;
907       case Intrinsic::localescape:
908         HasFrameEscape = true;
909         return false;
910       }
911     }
912 
913     if (F == CS.getInstruction()->getParent()->getParent()) {
914       // This flag will fully abort the analysis, so don't bother with anything
915       // else.
916       IsRecursiveCall = true;
917       return false;
918     }
919 
920     if (TTI.isLoweredToCall(F)) {
921       // We account for the average 1 instruction per call argument setup
922       // here.
923       Cost += CS.arg_size() * InlineConstants::InstrCost;
924 
925       // Everything other than inline ASM will also have a significant cost
926       // merely from making the call.
927       if (!isa<InlineAsm>(CS.getCalledValue()))
928         Cost += InlineConstants::CallPenalty;
929     }
930 
931     return Base::visitCallSite(CS);
932   }
933 
934   // Otherwise we're in a very special case -- an indirect function call. See
935   // if we can be particularly clever about this.
936   Value *Callee = CS.getCalledValue();
937 
938   // First, pay the price of the argument setup. We account for the average
939   // 1 instruction per call argument setup here.
940   Cost += CS.arg_size() * InlineConstants::InstrCost;
941 
942   // Next, check if this happens to be an indirect function call to a known
943   // function in this inline context. If not, we've done all we can.
944   Function *F = dyn_cast_or_null<Function>(SimplifiedValues.lookup(Callee));
945   if (!F)
946     return Base::visitCallSite(CS);
947 
948   // If we have a constant that we are calling as a function, we can peer
949   // through it and see the function target. This happens not infrequently
950   // during devirtualization and so we want to give it a hefty bonus for
951   // inlining, but cap that bonus in the event that inlining wouldn't pan
952   // out. Pretend to inline the function, with a custom threshold.
953   CallAnalyzer CA(TTI, ACT, PSI, *F, InlineConstants::IndirectCallThreshold,
954                   CS);
955   if (CA.analyzeCall(CS)) {
956     // We were able to inline the indirect call! Subtract the cost from the
957     // threshold to get the bonus we want to apply, but don't go below zero.
958     Cost -= std::max(0, CA.getThreshold() - CA.getCost());
959   }
960 
961   return Base::visitCallSite(CS);
962 }
963 
964 bool CallAnalyzer::visitReturnInst(ReturnInst &RI) {
965   // At least one return instruction will be free after inlining.
966   bool Free = !HasReturn;
967   HasReturn = true;
968   return Free;
969 }
970 
971 bool CallAnalyzer::visitBranchInst(BranchInst &BI) {
972   // We model unconditional branches as essentially free -- they really
973   // shouldn't exist at all, but handling them makes the behavior of the
974   // inliner more regular and predictable. Interestingly, conditional branches
975   // which will fold away are also free.
976   return BI.isUnconditional() || isa<ConstantInt>(BI.getCondition()) ||
977          dyn_cast_or_null<ConstantInt>(
978              SimplifiedValues.lookup(BI.getCondition()));
979 }
980 
981 bool CallAnalyzer::visitSwitchInst(SwitchInst &SI) {
982   // We model unconditional switches as free, see the comments on handling
983   // branches.
984   if (isa<ConstantInt>(SI.getCondition()))
985     return true;
986   if (Value *V = SimplifiedValues.lookup(SI.getCondition()))
987     if (isa<ConstantInt>(V))
988       return true;
989 
990   // Otherwise, we need to accumulate a cost proportional to the number of
991   // distinct successor blocks. This fan-out in the CFG cannot be represented
992   // for free even if we can represent the core switch as a jumptable that
993   // takes a single instruction.
994   //
995   // NB: We convert large switches which are just used to initialize large phi
996   // nodes to lookup tables instead in simplify-cfg, so this shouldn't prevent
997   // inlining those. It will prevent inlining in cases where the optimization
998   // does not (yet) fire.
999   SmallPtrSet<BasicBlock *, 8> SuccessorBlocks;
1000   SuccessorBlocks.insert(SI.getDefaultDest());
1001   for (auto I = SI.case_begin(), E = SI.case_end(); I != E; ++I)
1002     SuccessorBlocks.insert(I.getCaseSuccessor());
1003   // Add cost corresponding to the number of distinct destinations. The first
1004   // we model as free because of fallthrough.
1005   Cost += (SuccessorBlocks.size() - 1) * InlineConstants::InstrCost;
1006   return false;
1007 }
1008 
1009 bool CallAnalyzer::visitIndirectBrInst(IndirectBrInst &IBI) {
1010   // We never want to inline functions that contain an indirectbr.  This is
1011   // incorrect because all the blockaddress's (in static global initializers
1012   // for example) would be referring to the original function, and this
1013   // indirect jump would jump from the inlined copy of the function into the
1014   // original function which is extremely undefined behavior.
1015   // FIXME: This logic isn't really right; we can safely inline functions with
1016   // indirectbr's as long as no other function or global references the
1017   // blockaddress of a block within the current function.
1018   HasIndirectBr = true;
1019   return false;
1020 }
1021 
1022 bool CallAnalyzer::visitResumeInst(ResumeInst &RI) {
1023   // FIXME: It's not clear that a single instruction is an accurate model for
1024   // the inline cost of a resume instruction.
1025   return false;
1026 }
1027 
1028 bool CallAnalyzer::visitCleanupReturnInst(CleanupReturnInst &CRI) {
1029   // FIXME: It's not clear that a single instruction is an accurate model for
1030   // the inline cost of a cleanupret instruction.
1031   return false;
1032 }
1033 
1034 bool CallAnalyzer::visitCatchReturnInst(CatchReturnInst &CRI) {
1035   // FIXME: It's not clear that a single instruction is an accurate model for
1036   // the inline cost of a catchret instruction.
1037   return false;
1038 }
1039 
1040 bool CallAnalyzer::visitUnreachableInst(UnreachableInst &I) {
1041   // FIXME: It might be reasonably to discount the cost of instructions leading
1042   // to unreachable as they have the lowest possible impact on both runtime and
1043   // code size.
1044   return true; // No actual code is needed for unreachable.
1045 }
1046 
1047 bool CallAnalyzer::visitInstruction(Instruction &I) {
1048   // Some instructions are free. All of the free intrinsics can also be
1049   // handled by SROA, etc.
1050   if (TargetTransformInfo::TCC_Free == TTI.getUserCost(&I))
1051     return true;
1052 
1053   // We found something we don't understand or can't handle. Mark any SROA-able
1054   // values in the operand list as no longer viable.
1055   for (User::op_iterator OI = I.op_begin(), OE = I.op_end(); OI != OE; ++OI)
1056     disableSROA(*OI);
1057 
1058   return false;
1059 }
1060 
1061 /// \brief Analyze a basic block for its contribution to the inline cost.
1062 ///
1063 /// This method walks the analyzer over every instruction in the given basic
1064 /// block and accounts for their cost during inlining at this callsite. It
1065 /// aborts early if the threshold has been exceeded or an impossible to inline
1066 /// construct has been detected. It returns false if inlining is no longer
1067 /// viable, and true if inlining remains viable.
1068 bool CallAnalyzer::analyzeBlock(BasicBlock *BB,
1069                                 SmallPtrSetImpl<const Value *> &EphValues) {
1070   for (BasicBlock::iterator I = BB->begin(), E = BB->end(); I != E; ++I) {
1071     // FIXME: Currently, the number of instructions in a function regardless of
1072     // our ability to simplify them during inline to constants or dead code,
1073     // are actually used by the vector bonus heuristic. As long as that's true,
1074     // we have to special case debug intrinsics here to prevent differences in
1075     // inlining due to debug symbols. Eventually, the number of unsimplified
1076     // instructions shouldn't factor into the cost computation, but until then,
1077     // hack around it here.
1078     if (isa<DbgInfoIntrinsic>(I))
1079       continue;
1080 
1081     // Skip ephemeral values.
1082     if (EphValues.count(&*I))
1083       continue;
1084 
1085     ++NumInstructions;
1086     if (isa<ExtractElementInst>(I) || I->getType()->isVectorTy())
1087       ++NumVectorInstructions;
1088 
1089     // If the instruction is floating point, and the target says this operation
1090     // is expensive or the function has the "use-soft-float" attribute, this may
1091     // eventually become a library call. Treat the cost as such.
1092     if (I->getType()->isFloatingPointTy()) {
1093       bool hasSoftFloatAttr = false;
1094 
1095       // If the function has the "use-soft-float" attribute, mark it as
1096       // expensive.
1097       if (F.hasFnAttribute("use-soft-float")) {
1098         Attribute Attr = F.getFnAttribute("use-soft-float");
1099         StringRef Val = Attr.getValueAsString();
1100         if (Val == "true")
1101           hasSoftFloatAttr = true;
1102       }
1103 
1104       if (TTI.getFPOpCost(I->getType()) == TargetTransformInfo::TCC_Expensive ||
1105           hasSoftFloatAttr)
1106         Cost += InlineConstants::CallPenalty;
1107     }
1108 
1109     // If the instruction simplified to a constant, there is no cost to this
1110     // instruction. Visit the instructions using our InstVisitor to account for
1111     // all of the per-instruction logic. The visit tree returns true if we
1112     // consumed the instruction in any way, and false if the instruction's base
1113     // cost should count against inlining.
1114     if (Base::visit(&*I))
1115       ++NumInstructionsSimplified;
1116     else
1117       Cost += InlineConstants::InstrCost;
1118 
1119     // If the visit this instruction detected an uninlinable pattern, abort.
1120     if (IsRecursiveCall || ExposesReturnsTwice || HasDynamicAlloca ||
1121         HasIndirectBr || HasFrameEscape)
1122       return false;
1123 
1124     // If the caller is a recursive function then we don't want to inline
1125     // functions which allocate a lot of stack space because it would increase
1126     // the caller stack usage dramatically.
1127     if (IsCallerRecursive &&
1128         AllocatedSize > InlineConstants::TotalAllocaSizeRecursiveCaller)
1129       return false;
1130 
1131     // Check if we've past the maximum possible threshold so we don't spin in
1132     // huge basic blocks that will never inline.
1133     if (Cost > Threshold)
1134       return false;
1135   }
1136 
1137   return true;
1138 }
1139 
1140 /// \brief Compute the base pointer and cumulative constant offsets for V.
1141 ///
1142 /// This strips all constant offsets off of V, leaving it the base pointer, and
1143 /// accumulates the total constant offset applied in the returned constant. It
1144 /// returns 0 if V is not a pointer, and returns the constant '0' if there are
1145 /// no constant offsets applied.
1146 ConstantInt *CallAnalyzer::stripAndComputeInBoundsConstantOffsets(Value *&V) {
1147   if (!V->getType()->isPointerTy())
1148     return nullptr;
1149 
1150   const DataLayout &DL = F.getParent()->getDataLayout();
1151   unsigned IntPtrWidth = DL.getPointerSizeInBits();
1152   APInt Offset = APInt::getNullValue(IntPtrWidth);
1153 
1154   // Even though we don't look through PHI nodes, we could be called on an
1155   // instruction in an unreachable block, which may be on a cycle.
1156   SmallPtrSet<Value *, 4> Visited;
1157   Visited.insert(V);
1158   do {
1159     if (GEPOperator *GEP = dyn_cast<GEPOperator>(V)) {
1160       if (!GEP->isInBounds() || !accumulateGEPOffset(*GEP, Offset))
1161         return nullptr;
1162       V = GEP->getPointerOperand();
1163     } else if (Operator::getOpcode(V) == Instruction::BitCast) {
1164       V = cast<Operator>(V)->getOperand(0);
1165     } else if (GlobalAlias *GA = dyn_cast<GlobalAlias>(V)) {
1166       if (GA->isInterposable())
1167         break;
1168       V = GA->getAliasee();
1169     } else {
1170       break;
1171     }
1172     assert(V->getType()->isPointerTy() && "Unexpected operand type!");
1173   } while (Visited.insert(V).second);
1174 
1175   Type *IntPtrTy = DL.getIntPtrType(V->getContext());
1176   return cast<ConstantInt>(ConstantInt::get(IntPtrTy, Offset));
1177 }
1178 
1179 /// \brief Analyze a call site for potential inlining.
1180 ///
1181 /// Returns true if inlining this call is viable, and false if it is not
1182 /// viable. It computes the cost and adjusts the threshold based on numerous
1183 /// factors and heuristics. If this method returns false but the computed cost
1184 /// is below the computed threshold, then inlining was forcibly disabled by
1185 /// some artifact of the routine.
1186 bool CallAnalyzer::analyzeCall(CallSite CS) {
1187   ++NumCallsAnalyzed;
1188 
1189   // Perform some tweaks to the cost and threshold based on the direct
1190   // callsite information.
1191 
1192   // We want to more aggressively inline vector-dense kernels, so up the
1193   // threshold, and we'll lower it if the % of vector instructions gets too
1194   // low. Note that these bonuses are some what arbitrary and evolved over time
1195   // by accident as much as because they are principled bonuses.
1196   //
1197   // FIXME: It would be nice to remove all such bonuses. At least it would be
1198   // nice to base the bonus values on something more scientific.
1199   assert(NumInstructions == 0);
1200   assert(NumVectorInstructions == 0);
1201 
1202   // Update the threshold based on callsite properties
1203   updateThreshold(CS, F);
1204 
1205   FiftyPercentVectorBonus = 3 * Threshold / 2;
1206   TenPercentVectorBonus = 3 * Threshold / 4;
1207   const DataLayout &DL = F.getParent()->getDataLayout();
1208 
1209   // Track whether the post-inlining function would have more than one basic
1210   // block. A single basic block is often intended for inlining. Balloon the
1211   // threshold by 50% until we pass the single-BB phase.
1212   bool SingleBB = true;
1213   int SingleBBBonus = Threshold / 2;
1214 
1215   // Speculatively apply all possible bonuses to Threshold. If cost exceeds
1216   // this Threshold any time, and cost cannot decrease, we can stop processing
1217   // the rest of the function body.
1218   Threshold += (SingleBBBonus + FiftyPercentVectorBonus);
1219 
1220   // Give out bonuses per argument, as the instructions setting them up will
1221   // be gone after inlining.
1222   for (unsigned I = 0, E = CS.arg_size(); I != E; ++I) {
1223     if (CS.isByValArgument(I)) {
1224       // We approximate the number of loads and stores needed by dividing the
1225       // size of the byval type by the target's pointer size.
1226       PointerType *PTy = cast<PointerType>(CS.getArgument(I)->getType());
1227       unsigned TypeSize = DL.getTypeSizeInBits(PTy->getElementType());
1228       unsigned PointerSize = DL.getPointerSizeInBits();
1229       // Ceiling division.
1230       unsigned NumStores = (TypeSize + PointerSize - 1) / PointerSize;
1231 
1232       // If it generates more than 8 stores it is likely to be expanded as an
1233       // inline memcpy so we take that as an upper bound. Otherwise we assume
1234       // one load and one store per word copied.
1235       // FIXME: The maxStoresPerMemcpy setting from the target should be used
1236       // here instead of a magic number of 8, but it's not available via
1237       // DataLayout.
1238       NumStores = std::min(NumStores, 8U);
1239 
1240       Cost -= 2 * NumStores * InlineConstants::InstrCost;
1241     } else {
1242       // For non-byval arguments subtract off one instruction per call
1243       // argument.
1244       Cost -= InlineConstants::InstrCost;
1245     }
1246   }
1247 
1248   // If there is only one call of the function, and it has internal linkage,
1249   // the cost of inlining it drops dramatically.
1250   bool OnlyOneCallAndLocalLinkage =
1251       F.hasLocalLinkage() && F.hasOneUse() && &F == CS.getCalledFunction();
1252   if (OnlyOneCallAndLocalLinkage)
1253     Cost += InlineConstants::LastCallToStaticBonus;
1254 
1255   // If this function uses the coldcc calling convention, prefer not to inline
1256   // it.
1257   if (F.getCallingConv() == CallingConv::Cold)
1258     Cost += InlineConstants::ColdccPenalty;
1259 
1260   // Check if we're done. This can happen due to bonuses and penalties.
1261   if (Cost > Threshold)
1262     return false;
1263 
1264   if (F.empty())
1265     return true;
1266 
1267   Function *Caller = CS.getInstruction()->getParent()->getParent();
1268   // Check if the caller function is recursive itself.
1269   for (User *U : Caller->users()) {
1270     CallSite Site(U);
1271     if (!Site)
1272       continue;
1273     Instruction *I = Site.getInstruction();
1274     if (I->getParent()->getParent() == Caller) {
1275       IsCallerRecursive = true;
1276       break;
1277     }
1278   }
1279 
1280   // Populate our simplified values by mapping from function arguments to call
1281   // arguments with known important simplifications.
1282   CallSite::arg_iterator CAI = CS.arg_begin();
1283   for (Function::arg_iterator FAI = F.arg_begin(), FAE = F.arg_end();
1284        FAI != FAE; ++FAI, ++CAI) {
1285     assert(CAI != CS.arg_end());
1286     if (Constant *C = dyn_cast<Constant>(CAI))
1287       SimplifiedValues[&*FAI] = C;
1288 
1289     Value *PtrArg = *CAI;
1290     if (ConstantInt *C = stripAndComputeInBoundsConstantOffsets(PtrArg)) {
1291       ConstantOffsetPtrs[&*FAI] = std::make_pair(PtrArg, C->getValue());
1292 
1293       // We can SROA any pointer arguments derived from alloca instructions.
1294       if (isa<AllocaInst>(PtrArg)) {
1295         SROAArgValues[&*FAI] = PtrArg;
1296         SROAArgCosts[PtrArg] = 0;
1297       }
1298     }
1299   }
1300   NumConstantArgs = SimplifiedValues.size();
1301   NumConstantOffsetPtrArgs = ConstantOffsetPtrs.size();
1302   NumAllocaArgs = SROAArgValues.size();
1303 
1304   // FIXME: If a caller has multiple calls to a callee, we end up recomputing
1305   // the ephemeral values multiple times (and they're completely determined by
1306   // the callee, so this is purely duplicate work).
1307   SmallPtrSet<const Value *, 32> EphValues;
1308   CodeMetrics::collectEphemeralValues(&F, &ACT->getAssumptionCache(F),
1309                                       EphValues);
1310 
1311   // The worklist of live basic blocks in the callee *after* inlining. We avoid
1312   // adding basic blocks of the callee which can be proven to be dead for this
1313   // particular call site in order to get more accurate cost estimates. This
1314   // requires a somewhat heavyweight iteration pattern: we need to walk the
1315   // basic blocks in a breadth-first order as we insert live successors. To
1316   // accomplish this, prioritizing for small iterations because we exit after
1317   // crossing our threshold, we use a small-size optimized SetVector.
1318   typedef SetVector<BasicBlock *, SmallVector<BasicBlock *, 16>,
1319                     SmallPtrSet<BasicBlock *, 16>>
1320       BBSetVector;
1321   BBSetVector BBWorklist;
1322   BBWorklist.insert(&F.getEntryBlock());
1323   // Note that we *must not* cache the size, this loop grows the worklist.
1324   for (unsigned Idx = 0; Idx != BBWorklist.size(); ++Idx) {
1325     // Bail out the moment we cross the threshold. This means we'll under-count
1326     // the cost, but only when undercounting doesn't matter.
1327     if (Cost > Threshold)
1328       break;
1329 
1330     BasicBlock *BB = BBWorklist[Idx];
1331     if (BB->empty())
1332       continue;
1333 
1334     // Disallow inlining a blockaddress. A blockaddress only has defined
1335     // behavior for an indirect branch in the same function, and we do not
1336     // currently support inlining indirect branches. But, the inliner may not
1337     // see an indirect branch that ends up being dead code at a particular call
1338     // site. If the blockaddress escapes the function, e.g., via a global
1339     // variable, inlining may lead to an invalid cross-function reference.
1340     if (BB->hasAddressTaken())
1341       return false;
1342 
1343     // Analyze the cost of this block. If we blow through the threshold, this
1344     // returns false, and we can bail on out.
1345     if (!analyzeBlock(BB, EphValues))
1346       return false;
1347 
1348     TerminatorInst *TI = BB->getTerminator();
1349 
1350     // Add in the live successors by first checking whether we have terminator
1351     // that may be simplified based on the values simplified by this call.
1352     if (BranchInst *BI = dyn_cast<BranchInst>(TI)) {
1353       if (BI->isConditional()) {
1354         Value *Cond = BI->getCondition();
1355         if (ConstantInt *SimpleCond =
1356                 dyn_cast_or_null<ConstantInt>(SimplifiedValues.lookup(Cond))) {
1357           BBWorklist.insert(BI->getSuccessor(SimpleCond->isZero() ? 1 : 0));
1358           continue;
1359         }
1360       }
1361     } else if (SwitchInst *SI = dyn_cast<SwitchInst>(TI)) {
1362       Value *Cond = SI->getCondition();
1363       if (ConstantInt *SimpleCond =
1364               dyn_cast_or_null<ConstantInt>(SimplifiedValues.lookup(Cond))) {
1365         BBWorklist.insert(SI->findCaseValue(SimpleCond).getCaseSuccessor());
1366         continue;
1367       }
1368     }
1369 
1370     // If we're unable to select a particular successor, just count all of
1371     // them.
1372     for (unsigned TIdx = 0, TSize = TI->getNumSuccessors(); TIdx != TSize;
1373          ++TIdx)
1374       BBWorklist.insert(TI->getSuccessor(TIdx));
1375 
1376     // If we had any successors at this point, than post-inlining is likely to
1377     // have them as well. Note that we assume any basic blocks which existed
1378     // due to branches or switches which folded above will also fold after
1379     // inlining.
1380     if (SingleBB && TI->getNumSuccessors() > 1) {
1381       // Take off the bonus we applied to the threshold.
1382       Threshold -= SingleBBBonus;
1383       SingleBB = false;
1384     }
1385   }
1386 
1387   // If this is a noduplicate call, we can still inline as long as
1388   // inlining this would cause the removal of the caller (so the instruction
1389   // is not actually duplicated, just moved).
1390   if (!OnlyOneCallAndLocalLinkage && ContainsNoDuplicateCall)
1391     return false;
1392 
1393   // We applied the maximum possible vector bonus at the beginning. Now,
1394   // subtract the excess bonus, if any, from the Threshold before
1395   // comparing against Cost.
1396   if (NumVectorInstructions <= NumInstructions / 10)
1397     Threshold -= FiftyPercentVectorBonus;
1398   else if (NumVectorInstructions <= NumInstructions / 2)
1399     Threshold -= (FiftyPercentVectorBonus - TenPercentVectorBonus);
1400 
1401   return Cost < std::max(1, Threshold);
1402 }
1403 
1404 #if !defined(NDEBUG) || defined(LLVM_ENABLE_DUMP)
1405 /// \brief Dump stats about this call's analysis.
1406 LLVM_DUMP_METHOD void CallAnalyzer::dump() {
1407 #define DEBUG_PRINT_STAT(x) dbgs() << "      " #x ": " << x << "\n"
1408   DEBUG_PRINT_STAT(NumConstantArgs);
1409   DEBUG_PRINT_STAT(NumConstantOffsetPtrArgs);
1410   DEBUG_PRINT_STAT(NumAllocaArgs);
1411   DEBUG_PRINT_STAT(NumConstantPtrCmps);
1412   DEBUG_PRINT_STAT(NumConstantPtrDiffs);
1413   DEBUG_PRINT_STAT(NumInstructionsSimplified);
1414   DEBUG_PRINT_STAT(NumInstructions);
1415   DEBUG_PRINT_STAT(SROACostSavings);
1416   DEBUG_PRINT_STAT(SROACostSavingsLost);
1417   DEBUG_PRINT_STAT(ContainsNoDuplicateCall);
1418   DEBUG_PRINT_STAT(Cost);
1419   DEBUG_PRINT_STAT(Threshold);
1420 #undef DEBUG_PRINT_STAT
1421 }
1422 #endif
1423 
1424 /// \brief Test that two functions either have or have not the given attribute
1425 ///        at the same time.
1426 template <typename AttrKind>
1427 static bool attributeMatches(Function *F1, Function *F2, AttrKind Attr) {
1428   return F1->getFnAttribute(Attr) == F2->getFnAttribute(Attr);
1429 }
1430 
1431 /// \brief Test that there are no attribute conflicts between Caller and Callee
1432 ///        that prevent inlining.
1433 static bool functionsHaveCompatibleAttributes(Function *Caller,
1434                                               Function *Callee,
1435                                               TargetTransformInfo &TTI) {
1436   return TTI.areInlineCompatible(Caller, Callee) &&
1437          AttributeFuncs::areInlineCompatible(*Caller, *Callee);
1438 }
1439 
1440 InlineCost llvm::getInlineCost(CallSite CS, int DefaultThreshold,
1441                                TargetTransformInfo &CalleeTTI,
1442                                AssumptionCacheTracker *ACT,
1443                                ProfileSummaryInfo *PSI) {
1444   return getInlineCost(CS, CS.getCalledFunction(), DefaultThreshold, CalleeTTI,
1445                        ACT, PSI);
1446 }
1447 
1448 int llvm::computeThresholdFromOptLevels(unsigned OptLevel,
1449                                         unsigned SizeOptLevel) {
1450   if (OptLevel > 2)
1451     return OptAggressiveThreshold;
1452   if (SizeOptLevel == 1) // -Os
1453     return OptSizeThreshold;
1454   if (SizeOptLevel == 2) // -Oz
1455     return OptMinSizeThreshold;
1456   return DefaultInlineThreshold;
1457 }
1458 
1459 int llvm::getDefaultInlineThreshold() { return DefaultInlineThreshold; }
1460 
1461 InlineCost llvm::getInlineCost(CallSite CS, Function *Callee,
1462                                int DefaultThreshold,
1463                                TargetTransformInfo &CalleeTTI,
1464                                AssumptionCacheTracker *ACT,
1465                                ProfileSummaryInfo *PSI) {
1466 
1467   // Cannot inline indirect calls.
1468   if (!Callee)
1469     return llvm::InlineCost::getNever();
1470 
1471   // Calls to functions with always-inline attributes should be inlined
1472   // whenever possible.
1473   if (CS.hasFnAttr(Attribute::AlwaysInline)) {
1474     if (isInlineViable(*Callee))
1475       return llvm::InlineCost::getAlways();
1476     return llvm::InlineCost::getNever();
1477   }
1478 
1479   // Never inline functions with conflicting attributes (unless callee has
1480   // always-inline attribute).
1481   if (!functionsHaveCompatibleAttributes(CS.getCaller(), Callee, CalleeTTI))
1482     return llvm::InlineCost::getNever();
1483 
1484   // Don't inline this call if the caller has the optnone attribute.
1485   if (CS.getCaller()->hasFnAttribute(Attribute::OptimizeNone))
1486     return llvm::InlineCost::getNever();
1487 
1488   // Don't inline functions which can be interposed at link-time.  Don't inline
1489   // functions marked noinline or call sites marked noinline.
1490   // Note: inlining non-exact non-interposable fucntions is fine, since we know
1491   // we have *a* correct implementation of the source level function.
1492   if (Callee->isInterposable() || Callee->hasFnAttribute(Attribute::NoInline) ||
1493       CS.isNoInline())
1494     return llvm::InlineCost::getNever();
1495 
1496   DEBUG(llvm::dbgs() << "      Analyzing call of " << Callee->getName()
1497                      << "...\n");
1498 
1499   CallAnalyzer CA(CalleeTTI, ACT, PSI, *Callee, DefaultThreshold, CS);
1500   bool ShouldInline = CA.analyzeCall(CS);
1501 
1502   DEBUG(CA.dump());
1503 
1504   // Check if there was a reason to force inlining or no inlining.
1505   if (!ShouldInline && CA.getCost() < CA.getThreshold())
1506     return InlineCost::getNever();
1507   if (ShouldInline && CA.getCost() >= CA.getThreshold())
1508     return InlineCost::getAlways();
1509 
1510   return llvm::InlineCost::get(CA.getCost(), CA.getThreshold());
1511 }
1512 
1513 bool llvm::isInlineViable(Function &F) {
1514   bool ReturnsTwice = F.hasFnAttribute(Attribute::ReturnsTwice);
1515   for (Function::iterator BI = F.begin(), BE = F.end(); BI != BE; ++BI) {
1516     // Disallow inlining of functions which contain indirect branches or
1517     // blockaddresses.
1518     if (isa<IndirectBrInst>(BI->getTerminator()) || BI->hasAddressTaken())
1519       return false;
1520 
1521     for (auto &II : *BI) {
1522       CallSite CS(&II);
1523       if (!CS)
1524         continue;
1525 
1526       // Disallow recursive calls.
1527       if (&F == CS.getCalledFunction())
1528         return false;
1529 
1530       // Disallow calls which expose returns-twice to a function not previously
1531       // attributed as such.
1532       if (!ReturnsTwice && CS.isCall() &&
1533           cast<CallInst>(CS.getInstruction())->canReturnTwice())
1534         return false;
1535 
1536       // Disallow inlining functions that call @llvm.localescape. Doing this
1537       // correctly would require major changes to the inliner.
1538       if (CS.getCalledFunction() &&
1539           CS.getCalledFunction()->getIntrinsicID() ==
1540               llvm::Intrinsic::localescape)
1541         return false;
1542     }
1543   }
1544 
1545   return true;
1546 }
1547