1 //===- GlobalOpt.cpp - Optimize Global Variables --------------------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 // This pass transforms simple global variables that never have their address
11 // taken.  If obviously true, it marks read/write globals as constant, deletes
12 // variables only stored to, etc.
13 //
14 //===----------------------------------------------------------------------===//
15 
16 #define DEBUG_TYPE "globalopt"
17 #include "llvm/Transforms/IPO.h"
18 #include "llvm/ADT/DenseMap.h"
19 #include "llvm/ADT/STLExtras.h"
20 #include "llvm/ADT/SmallPtrSet.h"
21 #include "llvm/ADT/SmallVector.h"
22 #include "llvm/ADT/Statistic.h"
23 #include "llvm/Analysis/ConstantFolding.h"
24 #include "llvm/Analysis/MemoryBuiltins.h"
25 #include "llvm/IR/CallingConv.h"
26 #include "llvm/IR/Constants.h"
27 #include "llvm/IR/DataLayout.h"
28 #include "llvm/IR/DerivedTypes.h"
29 #include "llvm/IR/Instructions.h"
30 #include "llvm/IR/IntrinsicInst.h"
31 #include "llvm/IR/Module.h"
32 #include "llvm/IR/Operator.h"
33 #include "llvm/Pass.h"
34 #include "llvm/Support/CallSite.h"
35 #include "llvm/Support/Debug.h"
36 #include "llvm/Support/ErrorHandling.h"
37 #include "llvm/Support/GetElementPtrTypeIterator.h"
38 #include "llvm/Support/MathExtras.h"
39 #include "llvm/Support/raw_ostream.h"
40 #include "llvm/Target/TargetLibraryInfo.h"
41 #include "llvm/Transforms/Utils/GlobalStatus.h"
42 #include "llvm/Transforms/Utils/ModuleUtils.h"
43 #include <algorithm>
44 using namespace llvm;
45 
46 STATISTIC(NumMarked    , "Number of globals marked constant");
47 STATISTIC(NumUnnamed   , "Number of globals marked unnamed_addr");
48 STATISTIC(NumSRA       , "Number of aggregate globals broken into scalars");
49 STATISTIC(NumHeapSRA   , "Number of heap objects SRA'd");
50 STATISTIC(NumSubstitute,"Number of globals with initializers stored into them");
51 STATISTIC(NumDeleted   , "Number of globals deleted");
52 STATISTIC(NumFnDeleted , "Number of functions deleted");
53 STATISTIC(NumGlobUses  , "Number of global uses devirtualized");
54 STATISTIC(NumLocalized , "Number of globals localized");
55 STATISTIC(NumShrunkToBool  , "Number of global vars shrunk to booleans");
56 STATISTIC(NumFastCallFns   , "Number of functions converted to fastcc");
57 STATISTIC(NumCtorsEvaluated, "Number of static ctors evaluated");
58 STATISTIC(NumNestRemoved   , "Number of nest attributes removed");
59 STATISTIC(NumAliasesResolved, "Number of global aliases resolved");
60 STATISTIC(NumAliasesRemoved, "Number of global aliases eliminated");
61 STATISTIC(NumCXXDtorsRemoved, "Number of global C++ destructors removed");
62 
63 namespace {
64   struct GlobalOpt : public ModulePass {
65     virtual void getAnalysisUsage(AnalysisUsage &AU) const {
66       AU.addRequired<TargetLibraryInfo>();
67     }
68     static char ID; // Pass identification, replacement for typeid
69     GlobalOpt() : ModulePass(ID) {
70       initializeGlobalOptPass(*PassRegistry::getPassRegistry());
71     }
72 
73     bool runOnModule(Module &M);
74 
75   private:
76     GlobalVariable *FindGlobalCtors(Module &M);
77     bool OptimizeFunctions(Module &M);
78     bool OptimizeGlobalVars(Module &M);
79     bool OptimizeGlobalAliases(Module &M);
80     bool OptimizeGlobalCtorsList(GlobalVariable *&GCL);
81     bool ProcessGlobal(GlobalVariable *GV,Module::global_iterator &GVI);
82     bool ProcessInternalGlobal(GlobalVariable *GV,Module::global_iterator &GVI,
83                                const GlobalStatus &GS);
84     bool OptimizeEmptyGlobalCXXDtors(Function *CXAAtExitFn);
85 
86     DataLayout *TD;
87     TargetLibraryInfo *TLI;
88   };
89 }
90 
91 char GlobalOpt::ID = 0;
92 INITIALIZE_PASS_BEGIN(GlobalOpt, "globalopt",
93                 "Global Variable Optimizer", false, false)
94 INITIALIZE_PASS_DEPENDENCY(TargetLibraryInfo)
95 INITIALIZE_PASS_END(GlobalOpt, "globalopt",
96                 "Global Variable Optimizer", false, false)
97 
98 ModulePass *llvm::createGlobalOptimizerPass() { return new GlobalOpt(); }
99 
100 namespace {
101 
102 
103 
104 }
105 
106 /// isLeakCheckerRoot - Is this global variable possibly used by a leak checker
107 /// as a root?  If so, we might not really want to eliminate the stores to it.
108 static bool isLeakCheckerRoot(GlobalVariable *GV) {
109   // A global variable is a root if it is a pointer, or could plausibly contain
110   // a pointer.  There are two challenges; one is that we could have a struct
111   // the has an inner member which is a pointer.  We recurse through the type to
112   // detect these (up to a point).  The other is that we may actually be a union
113   // of a pointer and another type, and so our LLVM type is an integer which
114   // gets converted into a pointer, or our type is an [i8 x #] with a pointer
115   // potentially contained here.
116 
117   if (GV->hasPrivateLinkage())
118     return false;
119 
120   SmallVector<Type *, 4> Types;
121   Types.push_back(cast<PointerType>(GV->getType())->getElementType());
122 
123   unsigned Limit = 20;
124   do {
125     Type *Ty = Types.pop_back_val();
126     switch (Ty->getTypeID()) {
127       default: break;
128       case Type::PointerTyID: return true;
129       case Type::ArrayTyID:
130       case Type::VectorTyID: {
131         SequentialType *STy = cast<SequentialType>(Ty);
132         Types.push_back(STy->getElementType());
133         break;
134       }
135       case Type::StructTyID: {
136         StructType *STy = cast<StructType>(Ty);
137         if (STy->isOpaque()) return true;
138         for (StructType::element_iterator I = STy->element_begin(),
139                  E = STy->element_end(); I != E; ++I) {
140           Type *InnerTy = *I;
141           if (isa<PointerType>(InnerTy)) return true;
142           if (isa<CompositeType>(InnerTy))
143             Types.push_back(InnerTy);
144         }
145         break;
146       }
147     }
148     if (--Limit == 0) return true;
149   } while (!Types.empty());
150   return false;
151 }
152 
153 /// Given a value that is stored to a global but never read, determine whether
154 /// it's safe to remove the store and the chain of computation that feeds the
155 /// store.
156 static bool IsSafeComputationToRemove(Value *V, const TargetLibraryInfo *TLI) {
157   do {
158     if (isa<Constant>(V))
159       return true;
160     if (!V->hasOneUse())
161       return false;
162     if (isa<LoadInst>(V) || isa<InvokeInst>(V) || isa<Argument>(V) ||
163         isa<GlobalValue>(V))
164       return false;
165     if (isAllocationFn(V, TLI))
166       return true;
167 
168     Instruction *I = cast<Instruction>(V);
169     if (I->mayHaveSideEffects())
170       return false;
171     if (GetElementPtrInst *GEP = dyn_cast<GetElementPtrInst>(I)) {
172       if (!GEP->hasAllConstantIndices())
173         return false;
174     } else if (I->getNumOperands() != 1) {
175       return false;
176     }
177 
178     V = I->getOperand(0);
179   } while (1);
180 }
181 
182 /// CleanupPointerRootUsers - This GV is a pointer root.  Loop over all users
183 /// of the global and clean up any that obviously don't assign the global a
184 /// value that isn't dynamically allocated.
185 ///
186 static bool CleanupPointerRootUsers(GlobalVariable *GV,
187                                     const TargetLibraryInfo *TLI) {
188   // A brief explanation of leak checkers.  The goal is to find bugs where
189   // pointers are forgotten, causing an accumulating growth in memory
190   // usage over time.  The common strategy for leak checkers is to whitelist the
191   // memory pointed to by globals at exit.  This is popular because it also
192   // solves another problem where the main thread of a C++ program may shut down
193   // before other threads that are still expecting to use those globals.  To
194   // handle that case, we expect the program may create a singleton and never
195   // destroy it.
196 
197   bool Changed = false;
198 
199   // If Dead[n].first is the only use of a malloc result, we can delete its
200   // chain of computation and the store to the global in Dead[n].second.
201   SmallVector<std::pair<Instruction *, Instruction *>, 32> Dead;
202 
203   // Constants can't be pointers to dynamically allocated memory.
204   for (Value::use_iterator UI = GV->use_begin(), E = GV->use_end();
205        UI != E;) {
206     User *U = *UI++;
207     if (StoreInst *SI = dyn_cast<StoreInst>(U)) {
208       Value *V = SI->getValueOperand();
209       if (isa<Constant>(V)) {
210         Changed = true;
211         SI->eraseFromParent();
212       } else if (Instruction *I = dyn_cast<Instruction>(V)) {
213         if (I->hasOneUse())
214           Dead.push_back(std::make_pair(I, SI));
215       }
216     } else if (MemSetInst *MSI = dyn_cast<MemSetInst>(U)) {
217       if (isa<Constant>(MSI->getValue())) {
218         Changed = true;
219         MSI->eraseFromParent();
220       } else if (Instruction *I = dyn_cast<Instruction>(MSI->getValue())) {
221         if (I->hasOneUse())
222           Dead.push_back(std::make_pair(I, MSI));
223       }
224     } else if (MemTransferInst *MTI = dyn_cast<MemTransferInst>(U)) {
225       GlobalVariable *MemSrc = dyn_cast<GlobalVariable>(MTI->getSource());
226       if (MemSrc && MemSrc->isConstant()) {
227         Changed = true;
228         MTI->eraseFromParent();
229       } else if (Instruction *I = dyn_cast<Instruction>(MemSrc)) {
230         if (I->hasOneUse())
231           Dead.push_back(std::make_pair(I, MTI));
232       }
233     } else if (ConstantExpr *CE = dyn_cast<ConstantExpr>(U)) {
234       if (CE->use_empty()) {
235         CE->destroyConstant();
236         Changed = true;
237       }
238     } else if (Constant *C = dyn_cast<Constant>(U)) {
239       if (isSafeToDestroyConstant(C)) {
240         C->destroyConstant();
241         // This could have invalidated UI, start over from scratch.
242         Dead.clear();
243         CleanupPointerRootUsers(GV, TLI);
244         return true;
245       }
246     }
247   }
248 
249   for (int i = 0, e = Dead.size(); i != e; ++i) {
250     if (IsSafeComputationToRemove(Dead[i].first, TLI)) {
251       Dead[i].second->eraseFromParent();
252       Instruction *I = Dead[i].first;
253       do {
254         if (isAllocationFn(I, TLI))
255           break;
256         Instruction *J = dyn_cast<Instruction>(I->getOperand(0));
257         if (!J)
258           break;
259         I->eraseFromParent();
260         I = J;
261       } while (1);
262       I->eraseFromParent();
263     }
264   }
265 
266   return Changed;
267 }
268 
269 /// CleanupConstantGlobalUsers - We just marked GV constant.  Loop over all
270 /// users of the global, cleaning up the obvious ones.  This is largely just a
271 /// quick scan over the use list to clean up the easy and obvious cruft.  This
272 /// returns true if it made a change.
273 static bool CleanupConstantGlobalUsers(Value *V, Constant *Init,
274                                        DataLayout *TD, TargetLibraryInfo *TLI) {
275   bool Changed = false;
276   SmallVector<User*, 8> WorkList(V->use_begin(), V->use_end());
277   while (!WorkList.empty()) {
278     User *U = WorkList.pop_back_val();
279 
280     if (LoadInst *LI = dyn_cast<LoadInst>(U)) {
281       if (Init) {
282         // Replace the load with the initializer.
283         LI->replaceAllUsesWith(Init);
284         LI->eraseFromParent();
285         Changed = true;
286       }
287     } else if (StoreInst *SI = dyn_cast<StoreInst>(U)) {
288       // Store must be unreachable or storing Init into the global.
289       SI->eraseFromParent();
290       Changed = true;
291     } else if (ConstantExpr *CE = dyn_cast<ConstantExpr>(U)) {
292       if (CE->getOpcode() == Instruction::GetElementPtr) {
293         Constant *SubInit = 0;
294         if (Init)
295           SubInit = ConstantFoldLoadThroughGEPConstantExpr(Init, CE);
296         Changed |= CleanupConstantGlobalUsers(CE, SubInit, TD, TLI);
297       } else if (CE->getOpcode() == Instruction::BitCast &&
298                  CE->getType()->isPointerTy()) {
299         // Pointer cast, delete any stores and memsets to the global.
300         Changed |= CleanupConstantGlobalUsers(CE, 0, TD, TLI);
301       }
302 
303       if (CE->use_empty()) {
304         CE->destroyConstant();
305         Changed = true;
306       }
307     } else if (GetElementPtrInst *GEP = dyn_cast<GetElementPtrInst>(U)) {
308       // Do not transform "gepinst (gep constexpr (GV))" here, because forming
309       // "gepconstexpr (gep constexpr (GV))" will cause the two gep's to fold
310       // and will invalidate our notion of what Init is.
311       Constant *SubInit = 0;
312       if (!isa<ConstantExpr>(GEP->getOperand(0))) {
313         ConstantExpr *CE =
314           dyn_cast_or_null<ConstantExpr>(ConstantFoldInstruction(GEP, TD, TLI));
315         if (Init && CE && CE->getOpcode() == Instruction::GetElementPtr)
316           SubInit = ConstantFoldLoadThroughGEPConstantExpr(Init, CE);
317 
318         // If the initializer is an all-null value and we have an inbounds GEP,
319         // we already know what the result of any load from that GEP is.
320         // TODO: Handle splats.
321         if (Init && isa<ConstantAggregateZero>(Init) && GEP->isInBounds())
322           SubInit = Constant::getNullValue(GEP->getType()->getElementType());
323       }
324       Changed |= CleanupConstantGlobalUsers(GEP, SubInit, TD, TLI);
325 
326       if (GEP->use_empty()) {
327         GEP->eraseFromParent();
328         Changed = true;
329       }
330     } else if (MemIntrinsic *MI = dyn_cast<MemIntrinsic>(U)) { // memset/cpy/mv
331       if (MI->getRawDest() == V) {
332         MI->eraseFromParent();
333         Changed = true;
334       }
335 
336     } else if (Constant *C = dyn_cast<Constant>(U)) {
337       // If we have a chain of dead constantexprs or other things dangling from
338       // us, and if they are all dead, nuke them without remorse.
339       if (isSafeToDestroyConstant(C)) {
340         C->destroyConstant();
341         CleanupConstantGlobalUsers(V, Init, TD, TLI);
342         return true;
343       }
344     }
345   }
346   return Changed;
347 }
348 
349 /// isSafeSROAElementUse - Return true if the specified instruction is a safe
350 /// user of a derived expression from a global that we want to SROA.
351 static bool isSafeSROAElementUse(Value *V) {
352   // We might have a dead and dangling constant hanging off of here.
353   if (Constant *C = dyn_cast<Constant>(V))
354     return isSafeToDestroyConstant(C);
355 
356   Instruction *I = dyn_cast<Instruction>(V);
357   if (!I) return false;
358 
359   // Loads are ok.
360   if (isa<LoadInst>(I)) return true;
361 
362   // Stores *to* the pointer are ok.
363   if (StoreInst *SI = dyn_cast<StoreInst>(I))
364     return SI->getOperand(0) != V;
365 
366   // Otherwise, it must be a GEP.
367   GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(I);
368   if (GEPI == 0) return false;
369 
370   if (GEPI->getNumOperands() < 3 || !isa<Constant>(GEPI->getOperand(1)) ||
371       !cast<Constant>(GEPI->getOperand(1))->isNullValue())
372     return false;
373 
374   for (Value::use_iterator I = GEPI->use_begin(), E = GEPI->use_end();
375        I != E; ++I)
376     if (!isSafeSROAElementUse(*I))
377       return false;
378   return true;
379 }
380 
381 
382 /// IsUserOfGlobalSafeForSRA - U is a direct user of the specified global value.
383 /// Look at it and its uses and decide whether it is safe to SROA this global.
384 ///
385 static bool IsUserOfGlobalSafeForSRA(User *U, GlobalValue *GV) {
386   // The user of the global must be a GEP Inst or a ConstantExpr GEP.
387   if (!isa<GetElementPtrInst>(U) &&
388       (!isa<ConstantExpr>(U) ||
389        cast<ConstantExpr>(U)->getOpcode() != Instruction::GetElementPtr))
390     return false;
391 
392   // Check to see if this ConstantExpr GEP is SRA'able.  In particular, we
393   // don't like < 3 operand CE's, and we don't like non-constant integer
394   // indices.  This enforces that all uses are 'gep GV, 0, C, ...' for some
395   // value of C.
396   if (U->getNumOperands() < 3 || !isa<Constant>(U->getOperand(1)) ||
397       !cast<Constant>(U->getOperand(1))->isNullValue() ||
398       !isa<ConstantInt>(U->getOperand(2)))
399     return false;
400 
401   gep_type_iterator GEPI = gep_type_begin(U), E = gep_type_end(U);
402   ++GEPI;  // Skip over the pointer index.
403 
404   // If this is a use of an array allocation, do a bit more checking for sanity.
405   if (ArrayType *AT = dyn_cast<ArrayType>(*GEPI)) {
406     uint64_t NumElements = AT->getNumElements();
407     ConstantInt *Idx = cast<ConstantInt>(U->getOperand(2));
408 
409     // Check to make sure that index falls within the array.  If not,
410     // something funny is going on, so we won't do the optimization.
411     //
412     if (Idx->getZExtValue() >= NumElements)
413       return false;
414 
415     // We cannot scalar repl this level of the array unless any array
416     // sub-indices are in-range constants.  In particular, consider:
417     // A[0][i].  We cannot know that the user isn't doing invalid things like
418     // allowing i to index an out-of-range subscript that accesses A[1].
419     //
420     // Scalar replacing *just* the outer index of the array is probably not
421     // going to be a win anyway, so just give up.
422     for (++GEPI; // Skip array index.
423          GEPI != E;
424          ++GEPI) {
425       uint64_t NumElements;
426       if (ArrayType *SubArrayTy = dyn_cast<ArrayType>(*GEPI))
427         NumElements = SubArrayTy->getNumElements();
428       else if (VectorType *SubVectorTy = dyn_cast<VectorType>(*GEPI))
429         NumElements = SubVectorTy->getNumElements();
430       else {
431         assert((*GEPI)->isStructTy() &&
432                "Indexed GEP type is not array, vector, or struct!");
433         continue;
434       }
435 
436       ConstantInt *IdxVal = dyn_cast<ConstantInt>(GEPI.getOperand());
437       if (!IdxVal || IdxVal->getZExtValue() >= NumElements)
438         return false;
439     }
440   }
441 
442   for (Value::use_iterator I = U->use_begin(), E = U->use_end(); I != E; ++I)
443     if (!isSafeSROAElementUse(*I))
444       return false;
445   return true;
446 }
447 
448 /// GlobalUsersSafeToSRA - Look at all uses of the global and decide whether it
449 /// is safe for us to perform this transformation.
450 ///
451 static bool GlobalUsersSafeToSRA(GlobalValue *GV) {
452   for (Value::use_iterator UI = GV->use_begin(), E = GV->use_end();
453        UI != E; ++UI) {
454     if (!IsUserOfGlobalSafeForSRA(*UI, GV))
455       return false;
456   }
457   return true;
458 }
459 
460 
461 /// SRAGlobal - Perform scalar replacement of aggregates on the specified global
462 /// variable.  This opens the door for other optimizations by exposing the
463 /// behavior of the program in a more fine-grained way.  We have determined that
464 /// this transformation is safe already.  We return the first global variable we
465 /// insert so that the caller can reprocess it.
466 static GlobalVariable *SRAGlobal(GlobalVariable *GV, const DataLayout &TD) {
467   // Make sure this global only has simple uses that we can SRA.
468   if (!GlobalUsersSafeToSRA(GV))
469     return 0;
470 
471   assert(GV->hasLocalLinkage() && !GV->isConstant());
472   Constant *Init = GV->getInitializer();
473   Type *Ty = Init->getType();
474 
475   std::vector<GlobalVariable*> NewGlobals;
476   Module::GlobalListType &Globals = GV->getParent()->getGlobalList();
477 
478   // Get the alignment of the global, either explicit or target-specific.
479   unsigned StartAlignment = GV->getAlignment();
480   if (StartAlignment == 0)
481     StartAlignment = TD.getABITypeAlignment(GV->getType());
482 
483   if (StructType *STy = dyn_cast<StructType>(Ty)) {
484     NewGlobals.reserve(STy->getNumElements());
485     const StructLayout &Layout = *TD.getStructLayout(STy);
486     for (unsigned i = 0, e = STy->getNumElements(); i != e; ++i) {
487       Constant *In = Init->getAggregateElement(i);
488       assert(In && "Couldn't get element of initializer?");
489       GlobalVariable *NGV = new GlobalVariable(STy->getElementType(i), false,
490                                                GlobalVariable::InternalLinkage,
491                                                In, GV->getName()+"."+Twine(i),
492                                                GV->getThreadLocalMode(),
493                                               GV->getType()->getAddressSpace());
494       Globals.insert(GV, NGV);
495       NewGlobals.push_back(NGV);
496 
497       // Calculate the known alignment of the field.  If the original aggregate
498       // had 256 byte alignment for example, something might depend on that:
499       // propagate info to each field.
500       uint64_t FieldOffset = Layout.getElementOffset(i);
501       unsigned NewAlign = (unsigned)MinAlign(StartAlignment, FieldOffset);
502       if (NewAlign > TD.getABITypeAlignment(STy->getElementType(i)))
503         NGV->setAlignment(NewAlign);
504     }
505   } else if (SequentialType *STy = dyn_cast<SequentialType>(Ty)) {
506     unsigned NumElements = 0;
507     if (ArrayType *ATy = dyn_cast<ArrayType>(STy))
508       NumElements = ATy->getNumElements();
509     else
510       NumElements = cast<VectorType>(STy)->getNumElements();
511 
512     if (NumElements > 16 && GV->hasNUsesOrMore(16))
513       return 0; // It's not worth it.
514     NewGlobals.reserve(NumElements);
515 
516     uint64_t EltSize = TD.getTypeAllocSize(STy->getElementType());
517     unsigned EltAlign = TD.getABITypeAlignment(STy->getElementType());
518     for (unsigned i = 0, e = NumElements; i != e; ++i) {
519       Constant *In = Init->getAggregateElement(i);
520       assert(In && "Couldn't get element of initializer?");
521 
522       GlobalVariable *NGV = new GlobalVariable(STy->getElementType(), false,
523                                                GlobalVariable::InternalLinkage,
524                                                In, GV->getName()+"."+Twine(i),
525                                                GV->getThreadLocalMode(),
526                                               GV->getType()->getAddressSpace());
527       Globals.insert(GV, NGV);
528       NewGlobals.push_back(NGV);
529 
530       // Calculate the known alignment of the field.  If the original aggregate
531       // had 256 byte alignment for example, something might depend on that:
532       // propagate info to each field.
533       unsigned NewAlign = (unsigned)MinAlign(StartAlignment, EltSize*i);
534       if (NewAlign > EltAlign)
535         NGV->setAlignment(NewAlign);
536     }
537   }
538 
539   if (NewGlobals.empty())
540     return 0;
541 
542   DEBUG(dbgs() << "PERFORMING GLOBAL SRA ON: " << *GV);
543 
544   Constant *NullInt =Constant::getNullValue(Type::getInt32Ty(GV->getContext()));
545 
546   // Loop over all of the uses of the global, replacing the constantexpr geps,
547   // with smaller constantexpr geps or direct references.
548   while (!GV->use_empty()) {
549     User *GEP = GV->use_back();
550     assert(((isa<ConstantExpr>(GEP) &&
551              cast<ConstantExpr>(GEP)->getOpcode()==Instruction::GetElementPtr)||
552             isa<GetElementPtrInst>(GEP)) && "NonGEP CE's are not SRAable!");
553 
554     // Ignore the 1th operand, which has to be zero or else the program is quite
555     // broken (undefined).  Get the 2nd operand, which is the structure or array
556     // index.
557     unsigned Val = cast<ConstantInt>(GEP->getOperand(2))->getZExtValue();
558     if (Val >= NewGlobals.size()) Val = 0; // Out of bound array access.
559 
560     Value *NewPtr = NewGlobals[Val];
561 
562     // Form a shorter GEP if needed.
563     if (GEP->getNumOperands() > 3) {
564       if (ConstantExpr *CE = dyn_cast<ConstantExpr>(GEP)) {
565         SmallVector<Constant*, 8> Idxs;
566         Idxs.push_back(NullInt);
567         for (unsigned i = 3, e = CE->getNumOperands(); i != e; ++i)
568           Idxs.push_back(CE->getOperand(i));
569         NewPtr = ConstantExpr::getGetElementPtr(cast<Constant>(NewPtr), Idxs);
570       } else {
571         GetElementPtrInst *GEPI = cast<GetElementPtrInst>(GEP);
572         SmallVector<Value*, 8> Idxs;
573         Idxs.push_back(NullInt);
574         for (unsigned i = 3, e = GEPI->getNumOperands(); i != e; ++i)
575           Idxs.push_back(GEPI->getOperand(i));
576         NewPtr = GetElementPtrInst::Create(NewPtr, Idxs,
577                                            GEPI->getName()+"."+Twine(Val),GEPI);
578       }
579     }
580     GEP->replaceAllUsesWith(NewPtr);
581 
582     if (GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(GEP))
583       GEPI->eraseFromParent();
584     else
585       cast<ConstantExpr>(GEP)->destroyConstant();
586   }
587 
588   // Delete the old global, now that it is dead.
589   Globals.erase(GV);
590   ++NumSRA;
591 
592   // Loop over the new globals array deleting any globals that are obviously
593   // dead.  This can arise due to scalarization of a structure or an array that
594   // has elements that are dead.
595   unsigned FirstGlobal = 0;
596   for (unsigned i = 0, e = NewGlobals.size(); i != e; ++i)
597     if (NewGlobals[i]->use_empty()) {
598       Globals.erase(NewGlobals[i]);
599       if (FirstGlobal == i) ++FirstGlobal;
600     }
601 
602   return FirstGlobal != NewGlobals.size() ? NewGlobals[FirstGlobal] : 0;
603 }
604 
605 /// AllUsesOfValueWillTrapIfNull - Return true if all users of the specified
606 /// value will trap if the value is dynamically null.  PHIs keeps track of any
607 /// phi nodes we've seen to avoid reprocessing them.
608 static bool AllUsesOfValueWillTrapIfNull(const Value *V,
609                                          SmallPtrSet<const PHINode*, 8> &PHIs) {
610   for (Value::const_use_iterator UI = V->use_begin(), E = V->use_end(); UI != E;
611        ++UI) {
612     const User *U = *UI;
613 
614     if (isa<LoadInst>(U)) {
615       // Will trap.
616     } else if (const StoreInst *SI = dyn_cast<StoreInst>(U)) {
617       if (SI->getOperand(0) == V) {
618         //cerr << "NONTRAPPING USE: " << *U;
619         return false;  // Storing the value.
620       }
621     } else if (const CallInst *CI = dyn_cast<CallInst>(U)) {
622       if (CI->getCalledValue() != V) {
623         //cerr << "NONTRAPPING USE: " << *U;
624         return false;  // Not calling the ptr
625       }
626     } else if (const InvokeInst *II = dyn_cast<InvokeInst>(U)) {
627       if (II->getCalledValue() != V) {
628         //cerr << "NONTRAPPING USE: " << *U;
629         return false;  // Not calling the ptr
630       }
631     } else if (const BitCastInst *CI = dyn_cast<BitCastInst>(U)) {
632       if (!AllUsesOfValueWillTrapIfNull(CI, PHIs)) return false;
633     } else if (const GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(U)) {
634       if (!AllUsesOfValueWillTrapIfNull(GEPI, PHIs)) return false;
635     } else if (const PHINode *PN = dyn_cast<PHINode>(U)) {
636       // If we've already seen this phi node, ignore it, it has already been
637       // checked.
638       if (PHIs.insert(PN) && !AllUsesOfValueWillTrapIfNull(PN, PHIs))
639         return false;
640     } else if (isa<ICmpInst>(U) &&
641                isa<ConstantPointerNull>(UI->getOperand(1))) {
642       // Ignore icmp X, null
643     } else {
644       //cerr << "NONTRAPPING USE: " << *U;
645       return false;
646     }
647   }
648   return true;
649 }
650 
651 /// AllUsesOfLoadedValueWillTrapIfNull - Return true if all uses of any loads
652 /// from GV will trap if the loaded value is null.  Note that this also permits
653 /// comparisons of the loaded value against null, as a special case.
654 static bool AllUsesOfLoadedValueWillTrapIfNull(const GlobalVariable *GV) {
655   for (Value::const_use_iterator UI = GV->use_begin(), E = GV->use_end();
656        UI != E; ++UI) {
657     const User *U = *UI;
658 
659     if (const LoadInst *LI = dyn_cast<LoadInst>(U)) {
660       SmallPtrSet<const PHINode*, 8> PHIs;
661       if (!AllUsesOfValueWillTrapIfNull(LI, PHIs))
662         return false;
663     } else if (isa<StoreInst>(U)) {
664       // Ignore stores to the global.
665     } else {
666       // We don't know or understand this user, bail out.
667       //cerr << "UNKNOWN USER OF GLOBAL!: " << *U;
668       return false;
669     }
670   }
671   return true;
672 }
673 
674 static bool OptimizeAwayTrappingUsesOfValue(Value *V, Constant *NewV) {
675   bool Changed = false;
676   for (Value::use_iterator UI = V->use_begin(), E = V->use_end(); UI != E; ) {
677     Instruction *I = cast<Instruction>(*UI++);
678     if (LoadInst *LI = dyn_cast<LoadInst>(I)) {
679       LI->setOperand(0, NewV);
680       Changed = true;
681     } else if (StoreInst *SI = dyn_cast<StoreInst>(I)) {
682       if (SI->getOperand(1) == V) {
683         SI->setOperand(1, NewV);
684         Changed = true;
685       }
686     } else if (isa<CallInst>(I) || isa<InvokeInst>(I)) {
687       CallSite CS(I);
688       if (CS.getCalledValue() == V) {
689         // Calling through the pointer!  Turn into a direct call, but be careful
690         // that the pointer is not also being passed as an argument.
691         CS.setCalledFunction(NewV);
692         Changed = true;
693         bool PassedAsArg = false;
694         for (unsigned i = 0, e = CS.arg_size(); i != e; ++i)
695           if (CS.getArgument(i) == V) {
696             PassedAsArg = true;
697             CS.setArgument(i, NewV);
698           }
699 
700         if (PassedAsArg) {
701           // Being passed as an argument also.  Be careful to not invalidate UI!
702           UI = V->use_begin();
703         }
704       }
705     } else if (CastInst *CI = dyn_cast<CastInst>(I)) {
706       Changed |= OptimizeAwayTrappingUsesOfValue(CI,
707                                 ConstantExpr::getCast(CI->getOpcode(),
708                                                       NewV, CI->getType()));
709       if (CI->use_empty()) {
710         Changed = true;
711         CI->eraseFromParent();
712       }
713     } else if (GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(I)) {
714       // Should handle GEP here.
715       SmallVector<Constant*, 8> Idxs;
716       Idxs.reserve(GEPI->getNumOperands()-1);
717       for (User::op_iterator i = GEPI->op_begin() + 1, e = GEPI->op_end();
718            i != e; ++i)
719         if (Constant *C = dyn_cast<Constant>(*i))
720           Idxs.push_back(C);
721         else
722           break;
723       if (Idxs.size() == GEPI->getNumOperands()-1)
724         Changed |= OptimizeAwayTrappingUsesOfValue(GEPI,
725                           ConstantExpr::getGetElementPtr(NewV, Idxs));
726       if (GEPI->use_empty()) {
727         Changed = true;
728         GEPI->eraseFromParent();
729       }
730     }
731   }
732 
733   return Changed;
734 }
735 
736 
737 /// OptimizeAwayTrappingUsesOfLoads - The specified global has only one non-null
738 /// value stored into it.  If there are uses of the loaded value that would trap
739 /// if the loaded value is dynamically null, then we know that they cannot be
740 /// reachable with a null optimize away the load.
741 static bool OptimizeAwayTrappingUsesOfLoads(GlobalVariable *GV, Constant *LV,
742                                             DataLayout *TD,
743                                             TargetLibraryInfo *TLI) {
744   bool Changed = false;
745 
746   // Keep track of whether we are able to remove all the uses of the global
747   // other than the store that defines it.
748   bool AllNonStoreUsesGone = true;
749 
750   // Replace all uses of loads with uses of uses of the stored value.
751   for (Value::use_iterator GUI = GV->use_begin(), E = GV->use_end(); GUI != E;){
752     User *GlobalUser = *GUI++;
753     if (LoadInst *LI = dyn_cast<LoadInst>(GlobalUser)) {
754       Changed |= OptimizeAwayTrappingUsesOfValue(LI, LV);
755       // If we were able to delete all uses of the loads
756       if (LI->use_empty()) {
757         LI->eraseFromParent();
758         Changed = true;
759       } else {
760         AllNonStoreUsesGone = false;
761       }
762     } else if (isa<StoreInst>(GlobalUser)) {
763       // Ignore the store that stores "LV" to the global.
764       assert(GlobalUser->getOperand(1) == GV &&
765              "Must be storing *to* the global");
766     } else {
767       AllNonStoreUsesGone = false;
768 
769       // If we get here we could have other crazy uses that are transitively
770       // loaded.
771       assert((isa<PHINode>(GlobalUser) || isa<SelectInst>(GlobalUser) ||
772               isa<ConstantExpr>(GlobalUser) || isa<CmpInst>(GlobalUser) ||
773               isa<BitCastInst>(GlobalUser) ||
774               isa<GetElementPtrInst>(GlobalUser)) &&
775              "Only expect load and stores!");
776     }
777   }
778 
779   if (Changed) {
780     DEBUG(dbgs() << "OPTIMIZED LOADS FROM STORED ONCE POINTER: " << *GV);
781     ++NumGlobUses;
782   }
783 
784   // If we nuked all of the loads, then none of the stores are needed either,
785   // nor is the global.
786   if (AllNonStoreUsesGone) {
787     if (isLeakCheckerRoot(GV)) {
788       Changed |= CleanupPointerRootUsers(GV, TLI);
789     } else {
790       Changed = true;
791       CleanupConstantGlobalUsers(GV, 0, TD, TLI);
792     }
793     if (GV->use_empty()) {
794       DEBUG(dbgs() << "  *** GLOBAL NOW DEAD!\n");
795       Changed = true;
796       GV->eraseFromParent();
797       ++NumDeleted;
798     }
799   }
800   return Changed;
801 }
802 
803 /// ConstantPropUsersOf - Walk the use list of V, constant folding all of the
804 /// instructions that are foldable.
805 static void ConstantPropUsersOf(Value *V,
806                                 DataLayout *TD, TargetLibraryInfo *TLI) {
807   for (Value::use_iterator UI = V->use_begin(), E = V->use_end(); UI != E; )
808     if (Instruction *I = dyn_cast<Instruction>(*UI++))
809       if (Constant *NewC = ConstantFoldInstruction(I, TD, TLI)) {
810         I->replaceAllUsesWith(NewC);
811 
812         // Advance UI to the next non-I use to avoid invalidating it!
813         // Instructions could multiply use V.
814         while (UI != E && *UI == I)
815           ++UI;
816         I->eraseFromParent();
817       }
818 }
819 
820 /// OptimizeGlobalAddressOfMalloc - This function takes the specified global
821 /// variable, and transforms the program as if it always contained the result of
822 /// the specified malloc.  Because it is always the result of the specified
823 /// malloc, there is no reason to actually DO the malloc.  Instead, turn the
824 /// malloc into a global, and any loads of GV as uses of the new global.
825 static GlobalVariable *OptimizeGlobalAddressOfMalloc(GlobalVariable *GV,
826                                                      CallInst *CI,
827                                                      Type *AllocTy,
828                                                      ConstantInt *NElements,
829                                                      DataLayout *TD,
830                                                      TargetLibraryInfo *TLI) {
831   DEBUG(errs() << "PROMOTING GLOBAL: " << *GV << "  CALL = " << *CI << '\n');
832 
833   Type *GlobalType;
834   if (NElements->getZExtValue() == 1)
835     GlobalType = AllocTy;
836   else
837     // If we have an array allocation, the global variable is of an array.
838     GlobalType = ArrayType::get(AllocTy, NElements->getZExtValue());
839 
840   // Create the new global variable.  The contents of the malloc'd memory is
841   // undefined, so initialize with an undef value.
842   GlobalVariable *NewGV = new GlobalVariable(*GV->getParent(),
843                                              GlobalType, false,
844                                              GlobalValue::InternalLinkage,
845                                              UndefValue::get(GlobalType),
846                                              GV->getName()+".body",
847                                              GV,
848                                              GV->getThreadLocalMode());
849 
850   // If there are bitcast users of the malloc (which is typical, usually we have
851   // a malloc + bitcast) then replace them with uses of the new global.  Update
852   // other users to use the global as well.
853   BitCastInst *TheBC = 0;
854   while (!CI->use_empty()) {
855     Instruction *User = cast<Instruction>(CI->use_back());
856     if (BitCastInst *BCI = dyn_cast<BitCastInst>(User)) {
857       if (BCI->getType() == NewGV->getType()) {
858         BCI->replaceAllUsesWith(NewGV);
859         BCI->eraseFromParent();
860       } else {
861         BCI->setOperand(0, NewGV);
862       }
863     } else {
864       if (TheBC == 0)
865         TheBC = new BitCastInst(NewGV, CI->getType(), "newgv", CI);
866       User->replaceUsesOfWith(CI, TheBC);
867     }
868   }
869 
870   Constant *RepValue = NewGV;
871   if (NewGV->getType() != GV->getType()->getElementType())
872     RepValue = ConstantExpr::getBitCast(RepValue,
873                                         GV->getType()->getElementType());
874 
875   // If there is a comparison against null, we will insert a global bool to
876   // keep track of whether the global was initialized yet or not.
877   GlobalVariable *InitBool =
878     new GlobalVariable(Type::getInt1Ty(GV->getContext()), false,
879                        GlobalValue::InternalLinkage,
880                        ConstantInt::getFalse(GV->getContext()),
881                        GV->getName()+".init", GV->getThreadLocalMode());
882   bool InitBoolUsed = false;
883 
884   // Loop over all uses of GV, processing them in turn.
885   while (!GV->use_empty()) {
886     if (StoreInst *SI = dyn_cast<StoreInst>(GV->use_back())) {
887       // The global is initialized when the store to it occurs.
888       new StoreInst(ConstantInt::getTrue(GV->getContext()), InitBool, false, 0,
889                     SI->getOrdering(), SI->getSynchScope(), SI);
890       SI->eraseFromParent();
891       continue;
892     }
893 
894     LoadInst *LI = cast<LoadInst>(GV->use_back());
895     while (!LI->use_empty()) {
896       Use &LoadUse = LI->use_begin().getUse();
897       if (!isa<ICmpInst>(LoadUse.getUser())) {
898         LoadUse = RepValue;
899         continue;
900       }
901 
902       ICmpInst *ICI = cast<ICmpInst>(LoadUse.getUser());
903       // Replace the cmp X, 0 with a use of the bool value.
904       // Sink the load to where the compare was, if atomic rules allow us to.
905       Value *LV = new LoadInst(InitBool, InitBool->getName()+".val", false, 0,
906                                LI->getOrdering(), LI->getSynchScope(),
907                                LI->isUnordered() ? (Instruction*)ICI : LI);
908       InitBoolUsed = true;
909       switch (ICI->getPredicate()) {
910       default: llvm_unreachable("Unknown ICmp Predicate!");
911       case ICmpInst::ICMP_ULT:
912       case ICmpInst::ICMP_SLT:   // X < null -> always false
913         LV = ConstantInt::getFalse(GV->getContext());
914         break;
915       case ICmpInst::ICMP_ULE:
916       case ICmpInst::ICMP_SLE:
917       case ICmpInst::ICMP_EQ:
918         LV = BinaryOperator::CreateNot(LV, "notinit", ICI);
919         break;
920       case ICmpInst::ICMP_NE:
921       case ICmpInst::ICMP_UGE:
922       case ICmpInst::ICMP_SGE:
923       case ICmpInst::ICMP_UGT:
924       case ICmpInst::ICMP_SGT:
925         break;  // no change.
926       }
927       ICI->replaceAllUsesWith(LV);
928       ICI->eraseFromParent();
929     }
930     LI->eraseFromParent();
931   }
932 
933   // If the initialization boolean was used, insert it, otherwise delete it.
934   if (!InitBoolUsed) {
935     while (!InitBool->use_empty())  // Delete initializations
936       cast<StoreInst>(InitBool->use_back())->eraseFromParent();
937     delete InitBool;
938   } else
939     GV->getParent()->getGlobalList().insert(GV, InitBool);
940 
941   // Now the GV is dead, nuke it and the malloc..
942   GV->eraseFromParent();
943   CI->eraseFromParent();
944 
945   // To further other optimizations, loop over all users of NewGV and try to
946   // constant prop them.  This will promote GEP instructions with constant
947   // indices into GEP constant-exprs, which will allow global-opt to hack on it.
948   ConstantPropUsersOf(NewGV, TD, TLI);
949   if (RepValue != NewGV)
950     ConstantPropUsersOf(RepValue, TD, TLI);
951 
952   return NewGV;
953 }
954 
955 /// ValueIsOnlyUsedLocallyOrStoredToOneGlobal - Scan the use-list of V checking
956 /// to make sure that there are no complex uses of V.  We permit simple things
957 /// like dereferencing the pointer, but not storing through the address, unless
958 /// it is to the specified global.
959 static bool ValueIsOnlyUsedLocallyOrStoredToOneGlobal(const Instruction *V,
960                                                       const GlobalVariable *GV,
961                                          SmallPtrSet<const PHINode*, 8> &PHIs) {
962   for (Value::const_use_iterator UI = V->use_begin(), E = V->use_end();
963        UI != E; ++UI) {
964     const Instruction *Inst = cast<Instruction>(*UI);
965 
966     if (isa<LoadInst>(Inst) || isa<CmpInst>(Inst)) {
967       continue; // Fine, ignore.
968     }
969 
970     if (const StoreInst *SI = dyn_cast<StoreInst>(Inst)) {
971       if (SI->getOperand(0) == V && SI->getOperand(1) != GV)
972         return false;  // Storing the pointer itself... bad.
973       continue; // Otherwise, storing through it, or storing into GV... fine.
974     }
975 
976     // Must index into the array and into the struct.
977     if (isa<GetElementPtrInst>(Inst) && Inst->getNumOperands() >= 3) {
978       if (!ValueIsOnlyUsedLocallyOrStoredToOneGlobal(Inst, GV, PHIs))
979         return false;
980       continue;
981     }
982 
983     if (const PHINode *PN = dyn_cast<PHINode>(Inst)) {
984       // PHIs are ok if all uses are ok.  Don't infinitely recurse through PHI
985       // cycles.
986       if (PHIs.insert(PN))
987         if (!ValueIsOnlyUsedLocallyOrStoredToOneGlobal(PN, GV, PHIs))
988           return false;
989       continue;
990     }
991 
992     if (const BitCastInst *BCI = dyn_cast<BitCastInst>(Inst)) {
993       if (!ValueIsOnlyUsedLocallyOrStoredToOneGlobal(BCI, GV, PHIs))
994         return false;
995       continue;
996     }
997 
998     return false;
999   }
1000   return true;
1001 }
1002 
1003 /// ReplaceUsesOfMallocWithGlobal - The Alloc pointer is stored into GV
1004 /// somewhere.  Transform all uses of the allocation into loads from the
1005 /// global and uses of the resultant pointer.  Further, delete the store into
1006 /// GV.  This assumes that these value pass the
1007 /// 'ValueIsOnlyUsedLocallyOrStoredToOneGlobal' predicate.
1008 static void ReplaceUsesOfMallocWithGlobal(Instruction *Alloc,
1009                                           GlobalVariable *GV) {
1010   while (!Alloc->use_empty()) {
1011     Instruction *U = cast<Instruction>(*Alloc->use_begin());
1012     Instruction *InsertPt = U;
1013     if (StoreInst *SI = dyn_cast<StoreInst>(U)) {
1014       // If this is the store of the allocation into the global, remove it.
1015       if (SI->getOperand(1) == GV) {
1016         SI->eraseFromParent();
1017         continue;
1018       }
1019     } else if (PHINode *PN = dyn_cast<PHINode>(U)) {
1020       // Insert the load in the corresponding predecessor, not right before the
1021       // PHI.
1022       InsertPt = PN->getIncomingBlock(Alloc->use_begin())->getTerminator();
1023     } else if (isa<BitCastInst>(U)) {
1024       // Must be bitcast between the malloc and store to initialize the global.
1025       ReplaceUsesOfMallocWithGlobal(U, GV);
1026       U->eraseFromParent();
1027       continue;
1028     } else if (GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(U)) {
1029       // If this is a "GEP bitcast" and the user is a store to the global, then
1030       // just process it as a bitcast.
1031       if (GEPI->hasAllZeroIndices() && GEPI->hasOneUse())
1032         if (StoreInst *SI = dyn_cast<StoreInst>(GEPI->use_back()))
1033           if (SI->getOperand(1) == GV) {
1034             // Must be bitcast GEP between the malloc and store to initialize
1035             // the global.
1036             ReplaceUsesOfMallocWithGlobal(GEPI, GV);
1037             GEPI->eraseFromParent();
1038             continue;
1039           }
1040     }
1041 
1042     // Insert a load from the global, and use it instead of the malloc.
1043     Value *NL = new LoadInst(GV, GV->getName()+".val", InsertPt);
1044     U->replaceUsesOfWith(Alloc, NL);
1045   }
1046 }
1047 
1048 /// LoadUsesSimpleEnoughForHeapSRA - Verify that all uses of V (a load, or a phi
1049 /// of a load) are simple enough to perform heap SRA on.  This permits GEP's
1050 /// that index through the array and struct field, icmps of null, and PHIs.
1051 static bool LoadUsesSimpleEnoughForHeapSRA(const Value *V,
1052                         SmallPtrSet<const PHINode*, 32> &LoadUsingPHIs,
1053                         SmallPtrSet<const PHINode*, 32> &LoadUsingPHIsPerLoad) {
1054   // We permit two users of the load: setcc comparing against the null
1055   // pointer, and a getelementptr of a specific form.
1056   for (Value::const_use_iterator UI = V->use_begin(), E = V->use_end(); UI != E;
1057        ++UI) {
1058     const Instruction *User = cast<Instruction>(*UI);
1059 
1060     // Comparison against null is ok.
1061     if (const ICmpInst *ICI = dyn_cast<ICmpInst>(User)) {
1062       if (!isa<ConstantPointerNull>(ICI->getOperand(1)))
1063         return false;
1064       continue;
1065     }
1066 
1067     // getelementptr is also ok, but only a simple form.
1068     if (const GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(User)) {
1069       // Must index into the array and into the struct.
1070       if (GEPI->getNumOperands() < 3)
1071         return false;
1072 
1073       // Otherwise the GEP is ok.
1074       continue;
1075     }
1076 
1077     if (const PHINode *PN = dyn_cast<PHINode>(User)) {
1078       if (!LoadUsingPHIsPerLoad.insert(PN))
1079         // This means some phi nodes are dependent on each other.
1080         // Avoid infinite looping!
1081         return false;
1082       if (!LoadUsingPHIs.insert(PN))
1083         // If we have already analyzed this PHI, then it is safe.
1084         continue;
1085 
1086       // Make sure all uses of the PHI are simple enough to transform.
1087       if (!LoadUsesSimpleEnoughForHeapSRA(PN,
1088                                           LoadUsingPHIs, LoadUsingPHIsPerLoad))
1089         return false;
1090 
1091       continue;
1092     }
1093 
1094     // Otherwise we don't know what this is, not ok.
1095     return false;
1096   }
1097 
1098   return true;
1099 }
1100 
1101 
1102 /// AllGlobalLoadUsesSimpleEnoughForHeapSRA - If all users of values loaded from
1103 /// GV are simple enough to perform HeapSRA, return true.
1104 static bool AllGlobalLoadUsesSimpleEnoughForHeapSRA(const GlobalVariable *GV,
1105                                                     Instruction *StoredVal) {
1106   SmallPtrSet<const PHINode*, 32> LoadUsingPHIs;
1107   SmallPtrSet<const PHINode*, 32> LoadUsingPHIsPerLoad;
1108   for (Value::const_use_iterator UI = GV->use_begin(), E = GV->use_end();
1109        UI != E; ++UI)
1110     if (const LoadInst *LI = dyn_cast<LoadInst>(*UI)) {
1111       if (!LoadUsesSimpleEnoughForHeapSRA(LI, LoadUsingPHIs,
1112                                           LoadUsingPHIsPerLoad))
1113         return false;
1114       LoadUsingPHIsPerLoad.clear();
1115     }
1116 
1117   // If we reach here, we know that all uses of the loads and transitive uses
1118   // (through PHI nodes) are simple enough to transform.  However, we don't know
1119   // that all inputs the to the PHI nodes are in the same equivalence sets.
1120   // Check to verify that all operands of the PHIs are either PHIS that can be
1121   // transformed, loads from GV, or MI itself.
1122   for (SmallPtrSet<const PHINode*, 32>::const_iterator I = LoadUsingPHIs.begin()
1123        , E = LoadUsingPHIs.end(); I != E; ++I) {
1124     const PHINode *PN = *I;
1125     for (unsigned op = 0, e = PN->getNumIncomingValues(); op != e; ++op) {
1126       Value *InVal = PN->getIncomingValue(op);
1127 
1128       // PHI of the stored value itself is ok.
1129       if (InVal == StoredVal) continue;
1130 
1131       if (const PHINode *InPN = dyn_cast<PHINode>(InVal)) {
1132         // One of the PHIs in our set is (optimistically) ok.
1133         if (LoadUsingPHIs.count(InPN))
1134           continue;
1135         return false;
1136       }
1137 
1138       // Load from GV is ok.
1139       if (const LoadInst *LI = dyn_cast<LoadInst>(InVal))
1140         if (LI->getOperand(0) == GV)
1141           continue;
1142 
1143       // UNDEF? NULL?
1144 
1145       // Anything else is rejected.
1146       return false;
1147     }
1148   }
1149 
1150   return true;
1151 }
1152 
1153 static Value *GetHeapSROAValue(Value *V, unsigned FieldNo,
1154                DenseMap<Value*, std::vector<Value*> > &InsertedScalarizedValues,
1155                    std::vector<std::pair<PHINode*, unsigned> > &PHIsToRewrite) {
1156   std::vector<Value*> &FieldVals = InsertedScalarizedValues[V];
1157 
1158   if (FieldNo >= FieldVals.size())
1159     FieldVals.resize(FieldNo+1);
1160 
1161   // If we already have this value, just reuse the previously scalarized
1162   // version.
1163   if (Value *FieldVal = FieldVals[FieldNo])
1164     return FieldVal;
1165 
1166   // Depending on what instruction this is, we have several cases.
1167   Value *Result;
1168   if (LoadInst *LI = dyn_cast<LoadInst>(V)) {
1169     // This is a scalarized version of the load from the global.  Just create
1170     // a new Load of the scalarized global.
1171     Result = new LoadInst(GetHeapSROAValue(LI->getOperand(0), FieldNo,
1172                                            InsertedScalarizedValues,
1173                                            PHIsToRewrite),
1174                           LI->getName()+".f"+Twine(FieldNo), LI);
1175   } else if (PHINode *PN = dyn_cast<PHINode>(V)) {
1176     // PN's type is pointer to struct.  Make a new PHI of pointer to struct
1177     // field.
1178     StructType *ST = cast<StructType>(PN->getType()->getPointerElementType());
1179 
1180     PHINode *NewPN =
1181      PHINode::Create(PointerType::getUnqual(ST->getElementType(FieldNo)),
1182                      PN->getNumIncomingValues(),
1183                      PN->getName()+".f"+Twine(FieldNo), PN);
1184     Result = NewPN;
1185     PHIsToRewrite.push_back(std::make_pair(PN, FieldNo));
1186   } else {
1187     llvm_unreachable("Unknown usable value");
1188   }
1189 
1190   return FieldVals[FieldNo] = Result;
1191 }
1192 
1193 /// RewriteHeapSROALoadUser - Given a load instruction and a value derived from
1194 /// the load, rewrite the derived value to use the HeapSRoA'd load.
1195 static void RewriteHeapSROALoadUser(Instruction *LoadUser,
1196              DenseMap<Value*, std::vector<Value*> > &InsertedScalarizedValues,
1197                    std::vector<std::pair<PHINode*, unsigned> > &PHIsToRewrite) {
1198   // If this is a comparison against null, handle it.
1199   if (ICmpInst *SCI = dyn_cast<ICmpInst>(LoadUser)) {
1200     assert(isa<ConstantPointerNull>(SCI->getOperand(1)));
1201     // If we have a setcc of the loaded pointer, we can use a setcc of any
1202     // field.
1203     Value *NPtr = GetHeapSROAValue(SCI->getOperand(0), 0,
1204                                    InsertedScalarizedValues, PHIsToRewrite);
1205 
1206     Value *New = new ICmpInst(SCI, SCI->getPredicate(), NPtr,
1207                               Constant::getNullValue(NPtr->getType()),
1208                               SCI->getName());
1209     SCI->replaceAllUsesWith(New);
1210     SCI->eraseFromParent();
1211     return;
1212   }
1213 
1214   // Handle 'getelementptr Ptr, Idx, i32 FieldNo ...'
1215   if (GetElementPtrInst *GEPI = dyn_cast<GetElementPtrInst>(LoadUser)) {
1216     assert(GEPI->getNumOperands() >= 3 && isa<ConstantInt>(GEPI->getOperand(2))
1217            && "Unexpected GEPI!");
1218 
1219     // Load the pointer for this field.
1220     unsigned FieldNo = cast<ConstantInt>(GEPI->getOperand(2))->getZExtValue();
1221     Value *NewPtr = GetHeapSROAValue(GEPI->getOperand(0), FieldNo,
1222                                      InsertedScalarizedValues, PHIsToRewrite);
1223 
1224     // Create the new GEP idx vector.
1225     SmallVector<Value*, 8> GEPIdx;
1226     GEPIdx.push_back(GEPI->getOperand(1));
1227     GEPIdx.append(GEPI->op_begin()+3, GEPI->op_end());
1228 
1229     Value *NGEPI = GetElementPtrInst::Create(NewPtr, GEPIdx,
1230                                              GEPI->getName(), GEPI);
1231     GEPI->replaceAllUsesWith(NGEPI);
1232     GEPI->eraseFromParent();
1233     return;
1234   }
1235 
1236   // Recursively transform the users of PHI nodes.  This will lazily create the
1237   // PHIs that are needed for individual elements.  Keep track of what PHIs we
1238   // see in InsertedScalarizedValues so that we don't get infinite loops (very
1239   // antisocial).  If the PHI is already in InsertedScalarizedValues, it has
1240   // already been seen first by another load, so its uses have already been
1241   // processed.
1242   PHINode *PN = cast<PHINode>(LoadUser);
1243   if (!InsertedScalarizedValues.insert(std::make_pair(PN,
1244                                               std::vector<Value*>())).second)
1245     return;
1246 
1247   // If this is the first time we've seen this PHI, recursively process all
1248   // users.
1249   for (Value::use_iterator UI = PN->use_begin(), E = PN->use_end(); UI != E; ) {
1250     Instruction *User = cast<Instruction>(*UI++);
1251     RewriteHeapSROALoadUser(User, InsertedScalarizedValues, PHIsToRewrite);
1252   }
1253 }
1254 
1255 /// RewriteUsesOfLoadForHeapSRoA - We are performing Heap SRoA on a global.  Ptr
1256 /// is a value loaded from the global.  Eliminate all uses of Ptr, making them
1257 /// use FieldGlobals instead.  All uses of loaded values satisfy
1258 /// AllGlobalLoadUsesSimpleEnoughForHeapSRA.
1259 static void RewriteUsesOfLoadForHeapSRoA(LoadInst *Load,
1260                DenseMap<Value*, std::vector<Value*> > &InsertedScalarizedValues,
1261                    std::vector<std::pair<PHINode*, unsigned> > &PHIsToRewrite) {
1262   for (Value::use_iterator UI = Load->use_begin(), E = Load->use_end();
1263        UI != E; ) {
1264     Instruction *User = cast<Instruction>(*UI++);
1265     RewriteHeapSROALoadUser(User, InsertedScalarizedValues, PHIsToRewrite);
1266   }
1267 
1268   if (Load->use_empty()) {
1269     Load->eraseFromParent();
1270     InsertedScalarizedValues.erase(Load);
1271   }
1272 }
1273 
1274 /// PerformHeapAllocSRoA - CI is an allocation of an array of structures.  Break
1275 /// it up into multiple allocations of arrays of the fields.
1276 static GlobalVariable *PerformHeapAllocSRoA(GlobalVariable *GV, CallInst *CI,
1277                                             Value *NElems, DataLayout *TD,
1278                                             const TargetLibraryInfo *TLI) {
1279   DEBUG(dbgs() << "SROA HEAP ALLOC: " << *GV << "  MALLOC = " << *CI << '\n');
1280   Type *MAT = getMallocAllocatedType(CI, TLI);
1281   StructType *STy = cast<StructType>(MAT);
1282 
1283   // There is guaranteed to be at least one use of the malloc (storing
1284   // it into GV).  If there are other uses, change them to be uses of
1285   // the global to simplify later code.  This also deletes the store
1286   // into GV.
1287   ReplaceUsesOfMallocWithGlobal(CI, GV);
1288 
1289   // Okay, at this point, there are no users of the malloc.  Insert N
1290   // new mallocs at the same place as CI, and N globals.
1291   std::vector<Value*> FieldGlobals;
1292   std::vector<Value*> FieldMallocs;
1293 
1294   for (unsigned FieldNo = 0, e = STy->getNumElements(); FieldNo != e;++FieldNo){
1295     Type *FieldTy = STy->getElementType(FieldNo);
1296     PointerType *PFieldTy = PointerType::getUnqual(FieldTy);
1297 
1298     GlobalVariable *NGV =
1299       new GlobalVariable(*GV->getParent(),
1300                          PFieldTy, false, GlobalValue::InternalLinkage,
1301                          Constant::getNullValue(PFieldTy),
1302                          GV->getName() + ".f" + Twine(FieldNo), GV,
1303                          GV->getThreadLocalMode());
1304     FieldGlobals.push_back(NGV);
1305 
1306     unsigned TypeSize = TD->getTypeAllocSize(FieldTy);
1307     if (StructType *ST = dyn_cast<StructType>(FieldTy))
1308       TypeSize = TD->getStructLayout(ST)->getSizeInBytes();
1309     Type *IntPtrTy = TD->getIntPtrType(CI->getType());
1310     Value *NMI = CallInst::CreateMalloc(CI, IntPtrTy, FieldTy,
1311                                         ConstantInt::get(IntPtrTy, TypeSize),
1312                                         NElems, 0,
1313                                         CI->getName() + ".f" + Twine(FieldNo));
1314     FieldMallocs.push_back(NMI);
1315     new StoreInst(NMI, NGV, CI);
1316   }
1317 
1318   // The tricky aspect of this transformation is handling the case when malloc
1319   // fails.  In the original code, malloc failing would set the result pointer
1320   // of malloc to null.  In this case, some mallocs could succeed and others
1321   // could fail.  As such, we emit code that looks like this:
1322   //    F0 = malloc(field0)
1323   //    F1 = malloc(field1)
1324   //    F2 = malloc(field2)
1325   //    if (F0 == 0 || F1 == 0 || F2 == 0) {
1326   //      if (F0) { free(F0); F0 = 0; }
1327   //      if (F1) { free(F1); F1 = 0; }
1328   //      if (F2) { free(F2); F2 = 0; }
1329   //    }
1330   // The malloc can also fail if its argument is too large.
1331   Constant *ConstantZero = ConstantInt::get(CI->getArgOperand(0)->getType(), 0);
1332   Value *RunningOr = new ICmpInst(CI, ICmpInst::ICMP_SLT, CI->getArgOperand(0),
1333                                   ConstantZero, "isneg");
1334   for (unsigned i = 0, e = FieldMallocs.size(); i != e; ++i) {
1335     Value *Cond = new ICmpInst(CI, ICmpInst::ICMP_EQ, FieldMallocs[i],
1336                              Constant::getNullValue(FieldMallocs[i]->getType()),
1337                                "isnull");
1338     RunningOr = BinaryOperator::CreateOr(RunningOr, Cond, "tmp", CI);
1339   }
1340 
1341   // Split the basic block at the old malloc.
1342   BasicBlock *OrigBB = CI->getParent();
1343   BasicBlock *ContBB = OrigBB->splitBasicBlock(CI, "malloc_cont");
1344 
1345   // Create the block to check the first condition.  Put all these blocks at the
1346   // end of the function as they are unlikely to be executed.
1347   BasicBlock *NullPtrBlock = BasicBlock::Create(OrigBB->getContext(),
1348                                                 "malloc_ret_null",
1349                                                 OrigBB->getParent());
1350 
1351   // Remove the uncond branch from OrigBB to ContBB, turning it into a cond
1352   // branch on RunningOr.
1353   OrigBB->getTerminator()->eraseFromParent();
1354   BranchInst::Create(NullPtrBlock, ContBB, RunningOr, OrigBB);
1355 
1356   // Within the NullPtrBlock, we need to emit a comparison and branch for each
1357   // pointer, because some may be null while others are not.
1358   for (unsigned i = 0, e = FieldGlobals.size(); i != e; ++i) {
1359     Value *GVVal = new LoadInst(FieldGlobals[i], "tmp", NullPtrBlock);
1360     Value *Cmp = new ICmpInst(*NullPtrBlock, ICmpInst::ICMP_NE, GVVal,
1361                               Constant::getNullValue(GVVal->getType()));
1362     BasicBlock *FreeBlock = BasicBlock::Create(Cmp->getContext(), "free_it",
1363                                                OrigBB->getParent());
1364     BasicBlock *NextBlock = BasicBlock::Create(Cmp->getContext(), "next",
1365                                                OrigBB->getParent());
1366     Instruction *BI = BranchInst::Create(FreeBlock, NextBlock,
1367                                          Cmp, NullPtrBlock);
1368 
1369     // Fill in FreeBlock.
1370     CallInst::CreateFree(GVVal, BI);
1371     new StoreInst(Constant::getNullValue(GVVal->getType()), FieldGlobals[i],
1372                   FreeBlock);
1373     BranchInst::Create(NextBlock, FreeBlock);
1374 
1375     NullPtrBlock = NextBlock;
1376   }
1377 
1378   BranchInst::Create(ContBB, NullPtrBlock);
1379 
1380   // CI is no longer needed, remove it.
1381   CI->eraseFromParent();
1382 
1383   /// InsertedScalarizedLoads - As we process loads, if we can't immediately
1384   /// update all uses of the load, keep track of what scalarized loads are
1385   /// inserted for a given load.
1386   DenseMap<Value*, std::vector<Value*> > InsertedScalarizedValues;
1387   InsertedScalarizedValues[GV] = FieldGlobals;
1388 
1389   std::vector<std::pair<PHINode*, unsigned> > PHIsToRewrite;
1390 
1391   // Okay, the malloc site is completely handled.  All of the uses of GV are now
1392   // loads, and all uses of those loads are simple.  Rewrite them to use loads
1393   // of the per-field globals instead.
1394   for (Value::use_iterator UI = GV->use_begin(), E = GV->use_end(); UI != E;) {
1395     Instruction *User = cast<Instruction>(*UI++);
1396 
1397     if (LoadInst *LI = dyn_cast<LoadInst>(User)) {
1398       RewriteUsesOfLoadForHeapSRoA(LI, InsertedScalarizedValues, PHIsToRewrite);
1399       continue;
1400     }
1401 
1402     // Must be a store of null.
1403     StoreInst *SI = cast<StoreInst>(User);
1404     assert(isa<ConstantPointerNull>(SI->getOperand(0)) &&
1405            "Unexpected heap-sra user!");
1406 
1407     // Insert a store of null into each global.
1408     for (unsigned i = 0, e = FieldGlobals.size(); i != e; ++i) {
1409       PointerType *PT = cast<PointerType>(FieldGlobals[i]->getType());
1410       Constant *Null = Constant::getNullValue(PT->getElementType());
1411       new StoreInst(Null, FieldGlobals[i], SI);
1412     }
1413     // Erase the original store.
1414     SI->eraseFromParent();
1415   }
1416 
1417   // While we have PHIs that are interesting to rewrite, do it.
1418   while (!PHIsToRewrite.empty()) {
1419     PHINode *PN = PHIsToRewrite.back().first;
1420     unsigned FieldNo = PHIsToRewrite.back().second;
1421     PHIsToRewrite.pop_back();
1422     PHINode *FieldPN = cast<PHINode>(InsertedScalarizedValues[PN][FieldNo]);
1423     assert(FieldPN->getNumIncomingValues() == 0 &&"Already processed this phi");
1424 
1425     // Add all the incoming values.  This can materialize more phis.
1426     for (unsigned i = 0, e = PN->getNumIncomingValues(); i != e; ++i) {
1427       Value *InVal = PN->getIncomingValue(i);
1428       InVal = GetHeapSROAValue(InVal, FieldNo, InsertedScalarizedValues,
1429                                PHIsToRewrite);
1430       FieldPN->addIncoming(InVal, PN->getIncomingBlock(i));
1431     }
1432   }
1433 
1434   // Drop all inter-phi links and any loads that made it this far.
1435   for (DenseMap<Value*, std::vector<Value*> >::iterator
1436        I = InsertedScalarizedValues.begin(), E = InsertedScalarizedValues.end();
1437        I != E; ++I) {
1438     if (PHINode *PN = dyn_cast<PHINode>(I->first))
1439       PN->dropAllReferences();
1440     else if (LoadInst *LI = dyn_cast<LoadInst>(I->first))
1441       LI->dropAllReferences();
1442   }
1443 
1444   // Delete all the phis and loads now that inter-references are dead.
1445   for (DenseMap<Value*, std::vector<Value*> >::iterator
1446        I = InsertedScalarizedValues.begin(), E = InsertedScalarizedValues.end();
1447        I != E; ++I) {
1448     if (PHINode *PN = dyn_cast<PHINode>(I->first))
1449       PN->eraseFromParent();
1450     else if (LoadInst *LI = dyn_cast<LoadInst>(I->first))
1451       LI->eraseFromParent();
1452   }
1453 
1454   // The old global is now dead, remove it.
1455   GV->eraseFromParent();
1456 
1457   ++NumHeapSRA;
1458   return cast<GlobalVariable>(FieldGlobals[0]);
1459 }
1460 
1461 /// TryToOptimizeStoreOfMallocToGlobal - This function is called when we see a
1462 /// pointer global variable with a single value stored it that is a malloc or
1463 /// cast of malloc.
1464 static bool TryToOptimizeStoreOfMallocToGlobal(GlobalVariable *GV,
1465                                                CallInst *CI,
1466                                                Type *AllocTy,
1467                                                AtomicOrdering Ordering,
1468                                                Module::global_iterator &GVI,
1469                                                DataLayout *TD,
1470                                                TargetLibraryInfo *TLI) {
1471   if (!TD)
1472     return false;
1473 
1474   // If this is a malloc of an abstract type, don't touch it.
1475   if (!AllocTy->isSized())
1476     return false;
1477 
1478   // We can't optimize this global unless all uses of it are *known* to be
1479   // of the malloc value, not of the null initializer value (consider a use
1480   // that compares the global's value against zero to see if the malloc has
1481   // been reached).  To do this, we check to see if all uses of the global
1482   // would trap if the global were null: this proves that they must all
1483   // happen after the malloc.
1484   if (!AllUsesOfLoadedValueWillTrapIfNull(GV))
1485     return false;
1486 
1487   // We can't optimize this if the malloc itself is used in a complex way,
1488   // for example, being stored into multiple globals.  This allows the
1489   // malloc to be stored into the specified global, loaded icmp'd, and
1490   // GEP'd.  These are all things we could transform to using the global
1491   // for.
1492   SmallPtrSet<const PHINode*, 8> PHIs;
1493   if (!ValueIsOnlyUsedLocallyOrStoredToOneGlobal(CI, GV, PHIs))
1494     return false;
1495 
1496   // If we have a global that is only initialized with a fixed size malloc,
1497   // transform the program to use global memory instead of malloc'd memory.
1498   // This eliminates dynamic allocation, avoids an indirection accessing the
1499   // data, and exposes the resultant global to further GlobalOpt.
1500   // We cannot optimize the malloc if we cannot determine malloc array size.
1501   Value *NElems = getMallocArraySize(CI, TD, TLI, true);
1502   if (!NElems)
1503     return false;
1504 
1505   if (ConstantInt *NElements = dyn_cast<ConstantInt>(NElems))
1506     // Restrict this transformation to only working on small allocations
1507     // (2048 bytes currently), as we don't want to introduce a 16M global or
1508     // something.
1509     if (NElements->getZExtValue() * TD->getTypeAllocSize(AllocTy) < 2048) {
1510       GVI = OptimizeGlobalAddressOfMalloc(GV, CI, AllocTy, NElements, TD, TLI);
1511       return true;
1512     }
1513 
1514   // If the allocation is an array of structures, consider transforming this
1515   // into multiple malloc'd arrays, one for each field.  This is basically
1516   // SRoA for malloc'd memory.
1517 
1518   if (Ordering != NotAtomic)
1519     return false;
1520 
1521   // If this is an allocation of a fixed size array of structs, analyze as a
1522   // variable size array.  malloc [100 x struct],1 -> malloc struct, 100
1523   if (NElems == ConstantInt::get(CI->getArgOperand(0)->getType(), 1))
1524     if (ArrayType *AT = dyn_cast<ArrayType>(AllocTy))
1525       AllocTy = AT->getElementType();
1526 
1527   StructType *AllocSTy = dyn_cast<StructType>(AllocTy);
1528   if (!AllocSTy)
1529     return false;
1530 
1531   // This the structure has an unreasonable number of fields, leave it
1532   // alone.
1533   if (AllocSTy->getNumElements() <= 16 && AllocSTy->getNumElements() != 0 &&
1534       AllGlobalLoadUsesSimpleEnoughForHeapSRA(GV, CI)) {
1535 
1536     // If this is a fixed size array, transform the Malloc to be an alloc of
1537     // structs.  malloc [100 x struct],1 -> malloc struct, 100
1538     if (ArrayType *AT = dyn_cast<ArrayType>(getMallocAllocatedType(CI, TLI))) {
1539       Type *IntPtrTy = TD->getIntPtrType(CI->getType());
1540       unsigned TypeSize = TD->getStructLayout(AllocSTy)->getSizeInBytes();
1541       Value *AllocSize = ConstantInt::get(IntPtrTy, TypeSize);
1542       Value *NumElements = ConstantInt::get(IntPtrTy, AT->getNumElements());
1543       Instruction *Malloc = CallInst::CreateMalloc(CI, IntPtrTy, AllocSTy,
1544                                                    AllocSize, NumElements,
1545                                                    0, CI->getName());
1546       Instruction *Cast = new BitCastInst(Malloc, CI->getType(), "tmp", CI);
1547       CI->replaceAllUsesWith(Cast);
1548       CI->eraseFromParent();
1549       if (BitCastInst *BCI = dyn_cast<BitCastInst>(Malloc))
1550         CI = cast<CallInst>(BCI->getOperand(0));
1551       else
1552         CI = cast<CallInst>(Malloc);
1553     }
1554 
1555     GVI = PerformHeapAllocSRoA(GV, CI, getMallocArraySize(CI, TD, TLI, true),
1556                                TD, TLI);
1557     return true;
1558   }
1559 
1560   return false;
1561 }
1562 
1563 // OptimizeOnceStoredGlobal - Try to optimize globals based on the knowledge
1564 // that only one value (besides its initializer) is ever stored to the global.
1565 static bool OptimizeOnceStoredGlobal(GlobalVariable *GV, Value *StoredOnceVal,
1566                                      AtomicOrdering Ordering,
1567                                      Module::global_iterator &GVI,
1568                                      DataLayout *TD, TargetLibraryInfo *TLI) {
1569   // Ignore no-op GEPs and bitcasts.
1570   StoredOnceVal = StoredOnceVal->stripPointerCasts();
1571 
1572   // If we are dealing with a pointer global that is initialized to null and
1573   // only has one (non-null) value stored into it, then we can optimize any
1574   // users of the loaded value (often calls and loads) that would trap if the
1575   // value was null.
1576   if (GV->getInitializer()->getType()->isPointerTy() &&
1577       GV->getInitializer()->isNullValue()) {
1578     if (Constant *SOVC = dyn_cast<Constant>(StoredOnceVal)) {
1579       if (GV->getInitializer()->getType() != SOVC->getType())
1580         SOVC = ConstantExpr::getBitCast(SOVC, GV->getInitializer()->getType());
1581 
1582       // Optimize away any trapping uses of the loaded value.
1583       if (OptimizeAwayTrappingUsesOfLoads(GV, SOVC, TD, TLI))
1584         return true;
1585     } else if (CallInst *CI = extractMallocCall(StoredOnceVal, TLI)) {
1586       Type *MallocType = getMallocAllocatedType(CI, TLI);
1587       if (MallocType &&
1588           TryToOptimizeStoreOfMallocToGlobal(GV, CI, MallocType, Ordering, GVI,
1589                                              TD, TLI))
1590         return true;
1591     }
1592   }
1593 
1594   return false;
1595 }
1596 
1597 /// TryToShrinkGlobalToBoolean - At this point, we have learned that the only
1598 /// two values ever stored into GV are its initializer and OtherVal.  See if we
1599 /// can shrink the global into a boolean and select between the two values
1600 /// whenever it is used.  This exposes the values to other scalar optimizations.
1601 static bool TryToShrinkGlobalToBoolean(GlobalVariable *GV, Constant *OtherVal) {
1602   Type *GVElType = GV->getType()->getElementType();
1603 
1604   // If GVElType is already i1, it is already shrunk.  If the type of the GV is
1605   // an FP value, pointer or vector, don't do this optimization because a select
1606   // between them is very expensive and unlikely to lead to later
1607   // simplification.  In these cases, we typically end up with "cond ? v1 : v2"
1608   // where v1 and v2 both require constant pool loads, a big loss.
1609   if (GVElType == Type::getInt1Ty(GV->getContext()) ||
1610       GVElType->isFloatingPointTy() ||
1611       GVElType->isPointerTy() || GVElType->isVectorTy())
1612     return false;
1613 
1614   // Walk the use list of the global seeing if all the uses are load or store.
1615   // If there is anything else, bail out.
1616   for (Value::use_iterator I = GV->use_begin(), E = GV->use_end(); I != E; ++I){
1617     User *U = *I;
1618     if (!isa<LoadInst>(U) && !isa<StoreInst>(U))
1619       return false;
1620   }
1621 
1622   DEBUG(dbgs() << "   *** SHRINKING TO BOOL: " << *GV);
1623 
1624   // Create the new global, initializing it to false.
1625   GlobalVariable *NewGV = new GlobalVariable(Type::getInt1Ty(GV->getContext()),
1626                                              false,
1627                                              GlobalValue::InternalLinkage,
1628                                         ConstantInt::getFalse(GV->getContext()),
1629                                              GV->getName()+".b",
1630                                              GV->getThreadLocalMode(),
1631                                              GV->getType()->getAddressSpace());
1632   GV->getParent()->getGlobalList().insert(GV, NewGV);
1633 
1634   Constant *InitVal = GV->getInitializer();
1635   assert(InitVal->getType() != Type::getInt1Ty(GV->getContext()) &&
1636          "No reason to shrink to bool!");
1637 
1638   // If initialized to zero and storing one into the global, we can use a cast
1639   // instead of a select to synthesize the desired value.
1640   bool IsOneZero = false;
1641   if (ConstantInt *CI = dyn_cast<ConstantInt>(OtherVal))
1642     IsOneZero = InitVal->isNullValue() && CI->isOne();
1643 
1644   while (!GV->use_empty()) {
1645     Instruction *UI = cast<Instruction>(GV->use_back());
1646     if (StoreInst *SI = dyn_cast<StoreInst>(UI)) {
1647       // Change the store into a boolean store.
1648       bool StoringOther = SI->getOperand(0) == OtherVal;
1649       // Only do this if we weren't storing a loaded value.
1650       Value *StoreVal;
1651       if (StoringOther || SI->getOperand(0) == InitVal) {
1652         StoreVal = ConstantInt::get(Type::getInt1Ty(GV->getContext()),
1653                                     StoringOther);
1654       } else {
1655         // Otherwise, we are storing a previously loaded copy.  To do this,
1656         // change the copy from copying the original value to just copying the
1657         // bool.
1658         Instruction *StoredVal = cast<Instruction>(SI->getOperand(0));
1659 
1660         // If we've already replaced the input, StoredVal will be a cast or
1661         // select instruction.  If not, it will be a load of the original
1662         // global.
1663         if (LoadInst *LI = dyn_cast<LoadInst>(StoredVal)) {
1664           assert(LI->getOperand(0) == GV && "Not a copy!");
1665           // Insert a new load, to preserve the saved value.
1666           StoreVal = new LoadInst(NewGV, LI->getName()+".b", false, 0,
1667                                   LI->getOrdering(), LI->getSynchScope(), LI);
1668         } else {
1669           assert((isa<CastInst>(StoredVal) || isa<SelectInst>(StoredVal)) &&
1670                  "This is not a form that we understand!");
1671           StoreVal = StoredVal->getOperand(0);
1672           assert(isa<LoadInst>(StoreVal) && "Not a load of NewGV!");
1673         }
1674       }
1675       new StoreInst(StoreVal, NewGV, false, 0,
1676                     SI->getOrdering(), SI->getSynchScope(), SI);
1677     } else {
1678       // Change the load into a load of bool then a select.
1679       LoadInst *LI = cast<LoadInst>(UI);
1680       LoadInst *NLI = new LoadInst(NewGV, LI->getName()+".b", false, 0,
1681                                    LI->getOrdering(), LI->getSynchScope(), LI);
1682       Value *NSI;
1683       if (IsOneZero)
1684         NSI = new ZExtInst(NLI, LI->getType(), "", LI);
1685       else
1686         NSI = SelectInst::Create(NLI, OtherVal, InitVal, "", LI);
1687       NSI->takeName(LI);
1688       LI->replaceAllUsesWith(NSI);
1689     }
1690     UI->eraseFromParent();
1691   }
1692 
1693   // Retain the name of the old global variable. People who are debugging their
1694   // programs may expect these variables to be named the same.
1695   NewGV->takeName(GV);
1696   GV->eraseFromParent();
1697   return true;
1698 }
1699 
1700 
1701 /// ProcessGlobal - Analyze the specified global variable and optimize it if
1702 /// possible.  If we make a change, return true.
1703 bool GlobalOpt::ProcessGlobal(GlobalVariable *GV,
1704                               Module::global_iterator &GVI) {
1705   if (!GV->isDiscardableIfUnused())
1706     return false;
1707 
1708   // Do more involved optimizations if the global is internal.
1709   GV->removeDeadConstantUsers();
1710 
1711   if (GV->use_empty()) {
1712     DEBUG(dbgs() << "GLOBAL DEAD: " << *GV);
1713     GV->eraseFromParent();
1714     ++NumDeleted;
1715     return true;
1716   }
1717 
1718   if (!GV->hasLocalLinkage())
1719     return false;
1720 
1721   GlobalStatus GS;
1722 
1723   if (GlobalStatus::analyzeGlobal(GV, GS))
1724     return false;
1725 
1726   if (!GS.IsCompared && !GV->hasUnnamedAddr()) {
1727     GV->setUnnamedAddr(true);
1728     NumUnnamed++;
1729   }
1730 
1731   if (GV->isConstant() || !GV->hasInitializer())
1732     return false;
1733 
1734   return ProcessInternalGlobal(GV, GVI, GS);
1735 }
1736 
1737 /// ProcessInternalGlobal - Analyze the specified global variable and optimize
1738 /// it if possible.  If we make a change, return true.
1739 bool GlobalOpt::ProcessInternalGlobal(GlobalVariable *GV,
1740                                       Module::global_iterator &GVI,
1741                                       const GlobalStatus &GS) {
1742   // If this is a first class global and has only one accessing function
1743   // and this function is main (which we know is not recursive), we replace
1744   // the global with a local alloca in this function.
1745   //
1746   // NOTE: It doesn't make sense to promote non single-value types since we
1747   // are just replacing static memory to stack memory.
1748   //
1749   // If the global is in different address space, don't bring it to stack.
1750   if (!GS.HasMultipleAccessingFunctions &&
1751       GS.AccessingFunction && !GS.HasNonInstructionUser &&
1752       GV->getType()->getElementType()->isSingleValueType() &&
1753       GS.AccessingFunction->getName() == "main" &&
1754       GS.AccessingFunction->hasExternalLinkage() &&
1755       GV->getType()->getAddressSpace() == 0) {
1756     DEBUG(dbgs() << "LOCALIZING GLOBAL: " << *GV);
1757     Instruction &FirstI = const_cast<Instruction&>(*GS.AccessingFunction
1758                                                    ->getEntryBlock().begin());
1759     Type *ElemTy = GV->getType()->getElementType();
1760     // FIXME: Pass Global's alignment when globals have alignment
1761     AllocaInst *Alloca = new AllocaInst(ElemTy, NULL, GV->getName(), &FirstI);
1762     if (!isa<UndefValue>(GV->getInitializer()))
1763       new StoreInst(GV->getInitializer(), Alloca, &FirstI);
1764 
1765     GV->replaceAllUsesWith(Alloca);
1766     GV->eraseFromParent();
1767     ++NumLocalized;
1768     return true;
1769   }
1770 
1771   // If the global is never loaded (but may be stored to), it is dead.
1772   // Delete it now.
1773   if (!GS.IsLoaded) {
1774     DEBUG(dbgs() << "GLOBAL NEVER LOADED: " << *GV);
1775 
1776     bool Changed;
1777     if (isLeakCheckerRoot(GV)) {
1778       // Delete any constant stores to the global.
1779       Changed = CleanupPointerRootUsers(GV, TLI);
1780     } else {
1781       // Delete any stores we can find to the global.  We may not be able to
1782       // make it completely dead though.
1783       Changed = CleanupConstantGlobalUsers(GV, GV->getInitializer(), TD, TLI);
1784     }
1785 
1786     // If the global is dead now, delete it.
1787     if (GV->use_empty()) {
1788       GV->eraseFromParent();
1789       ++NumDeleted;
1790       Changed = true;
1791     }
1792     return Changed;
1793 
1794   } else if (GS.StoredType <= GlobalStatus::InitializerStored) {
1795     DEBUG(dbgs() << "MARKING CONSTANT: " << *GV << "\n");
1796     GV->setConstant(true);
1797 
1798     // Clean up any obviously simplifiable users now.
1799     CleanupConstantGlobalUsers(GV, GV->getInitializer(), TD, TLI);
1800 
1801     // If the global is dead now, just nuke it.
1802     if (GV->use_empty()) {
1803       DEBUG(dbgs() << "   *** Marking constant allowed us to simplify "
1804             << "all users and delete global!\n");
1805       GV->eraseFromParent();
1806       ++NumDeleted;
1807     }
1808 
1809     ++NumMarked;
1810     return true;
1811   } else if (!GV->getInitializer()->getType()->isSingleValueType()) {
1812     if (DataLayout *TD = getAnalysisIfAvailable<DataLayout>())
1813       if (GlobalVariable *FirstNewGV = SRAGlobal(GV, *TD)) {
1814         GVI = FirstNewGV;  // Don't skip the newly produced globals!
1815         return true;
1816       }
1817   } else if (GS.StoredType == GlobalStatus::StoredOnce) {
1818     // If the initial value for the global was an undef value, and if only
1819     // one other value was stored into it, we can just change the
1820     // initializer to be the stored value, then delete all stores to the
1821     // global.  This allows us to mark it constant.
1822     if (Constant *SOVConstant = dyn_cast<Constant>(GS.StoredOnceValue))
1823       if (isa<UndefValue>(GV->getInitializer())) {
1824         // Change the initial value here.
1825         GV->setInitializer(SOVConstant);
1826 
1827         // Clean up any obviously simplifiable users now.
1828         CleanupConstantGlobalUsers(GV, GV->getInitializer(), TD, TLI);
1829 
1830         if (GV->use_empty()) {
1831           DEBUG(dbgs() << "   *** Substituting initializer allowed us to "
1832                        << "simplify all users and delete global!\n");
1833           GV->eraseFromParent();
1834           ++NumDeleted;
1835         } else {
1836           GVI = GV;
1837         }
1838         ++NumSubstitute;
1839         return true;
1840       }
1841 
1842     // Try to optimize globals based on the knowledge that only one value
1843     // (besides its initializer) is ever stored to the global.
1844     if (OptimizeOnceStoredGlobal(GV, GS.StoredOnceValue, GS.Ordering, GVI,
1845                                  TD, TLI))
1846       return true;
1847 
1848     // Otherwise, if the global was not a boolean, we can shrink it to be a
1849     // boolean.
1850     if (Constant *SOVConstant = dyn_cast<Constant>(GS.StoredOnceValue)) {
1851       if (GS.Ordering == NotAtomic) {
1852         if (TryToShrinkGlobalToBoolean(GV, SOVConstant)) {
1853           ++NumShrunkToBool;
1854           return true;
1855         }
1856       }
1857     }
1858   }
1859 
1860   return false;
1861 }
1862 
1863 /// ChangeCalleesToFastCall - Walk all of the direct calls of the specified
1864 /// function, changing them to FastCC.
1865 static void ChangeCalleesToFastCall(Function *F) {
1866   for (Value::use_iterator UI = F->use_begin(), E = F->use_end(); UI != E;++UI){
1867     if (isa<BlockAddress>(*UI))
1868       continue;
1869     CallSite User(cast<Instruction>(*UI));
1870     User.setCallingConv(CallingConv::Fast);
1871   }
1872 }
1873 
1874 static AttributeSet StripNest(LLVMContext &C, const AttributeSet &Attrs) {
1875   for (unsigned i = 0, e = Attrs.getNumSlots(); i != e; ++i) {
1876     unsigned Index = Attrs.getSlotIndex(i);
1877     if (!Attrs.getSlotAttributes(i).hasAttribute(Index, Attribute::Nest))
1878       continue;
1879 
1880     // There can be only one.
1881     return Attrs.removeAttribute(C, Index, Attribute::Nest);
1882   }
1883 
1884   return Attrs;
1885 }
1886 
1887 static void RemoveNestAttribute(Function *F) {
1888   F->setAttributes(StripNest(F->getContext(), F->getAttributes()));
1889   for (Value::use_iterator UI = F->use_begin(), E = F->use_end(); UI != E;++UI){
1890     if (isa<BlockAddress>(*UI))
1891       continue;
1892     CallSite User(cast<Instruction>(*UI));
1893     User.setAttributes(StripNest(F->getContext(), User.getAttributes()));
1894   }
1895 }
1896 
1897 bool GlobalOpt::OptimizeFunctions(Module &M) {
1898   bool Changed = false;
1899   // Optimize functions.
1900   for (Module::iterator FI = M.begin(), E = M.end(); FI != E; ) {
1901     Function *F = FI++;
1902     // Functions without names cannot be referenced outside this module.
1903     if (!F->hasName() && !F->isDeclaration())
1904       F->setLinkage(GlobalValue::InternalLinkage);
1905     F->removeDeadConstantUsers();
1906     if (F->isDefTriviallyDead()) {
1907       F->eraseFromParent();
1908       Changed = true;
1909       ++NumFnDeleted;
1910     } else if (F->hasLocalLinkage()) {
1911       if (F->getCallingConv() == CallingConv::C && !F->isVarArg() &&
1912           !F->hasAddressTaken()) {
1913         // If this function has C calling conventions, is not a varargs
1914         // function, and is only called directly, promote it to use the Fast
1915         // calling convention.
1916         F->setCallingConv(CallingConv::Fast);
1917         ChangeCalleesToFastCall(F);
1918         ++NumFastCallFns;
1919         Changed = true;
1920       }
1921 
1922       if (F->getAttributes().hasAttrSomewhere(Attribute::Nest) &&
1923           !F->hasAddressTaken()) {
1924         // The function is not used by a trampoline intrinsic, so it is safe
1925         // to remove the 'nest' attribute.
1926         RemoveNestAttribute(F);
1927         ++NumNestRemoved;
1928         Changed = true;
1929       }
1930     }
1931   }
1932   return Changed;
1933 }
1934 
1935 bool GlobalOpt::OptimizeGlobalVars(Module &M) {
1936   bool Changed = false;
1937   for (Module::global_iterator GVI = M.global_begin(), E = M.global_end();
1938        GVI != E; ) {
1939     GlobalVariable *GV = GVI++;
1940     // Global variables without names cannot be referenced outside this module.
1941     if (!GV->hasName() && !GV->isDeclaration())
1942       GV->setLinkage(GlobalValue::InternalLinkage);
1943     // Simplify the initializer.
1944     if (GV->hasInitializer())
1945       if (ConstantExpr *CE = dyn_cast<ConstantExpr>(GV->getInitializer())) {
1946         Constant *New = ConstantFoldConstantExpression(CE, TD, TLI);
1947         if (New && New != CE)
1948           GV->setInitializer(New);
1949       }
1950 
1951     Changed |= ProcessGlobal(GV, GVI);
1952   }
1953   return Changed;
1954 }
1955 
1956 /// FindGlobalCtors - Find the llvm.global_ctors list, verifying that all
1957 /// initializers have an init priority of 65535.
1958 GlobalVariable *GlobalOpt::FindGlobalCtors(Module &M) {
1959   GlobalVariable *GV = M.getGlobalVariable("llvm.global_ctors");
1960   if (GV == 0) return 0;
1961 
1962   // Verify that the initializer is simple enough for us to handle. We are
1963   // only allowed to optimize the initializer if it is unique.
1964   if (!GV->hasUniqueInitializer()) return 0;
1965 
1966   if (isa<ConstantAggregateZero>(GV->getInitializer()))
1967     return GV;
1968   ConstantArray *CA = cast<ConstantArray>(GV->getInitializer());
1969 
1970   for (User::op_iterator i = CA->op_begin(), e = CA->op_end(); i != e; ++i) {
1971     if (isa<ConstantAggregateZero>(*i))
1972       continue;
1973     ConstantStruct *CS = cast<ConstantStruct>(*i);
1974     if (isa<ConstantPointerNull>(CS->getOperand(1)))
1975       continue;
1976 
1977     // Must have a function or null ptr.
1978     if (!isa<Function>(CS->getOperand(1)))
1979       return 0;
1980 
1981     // Init priority must be standard.
1982     ConstantInt *CI = cast<ConstantInt>(CS->getOperand(0));
1983     if (CI->getZExtValue() != 65535)
1984       return 0;
1985   }
1986 
1987   return GV;
1988 }
1989 
1990 /// ParseGlobalCtors - Given a llvm.global_ctors list that we can understand,
1991 /// return a list of the functions and null terminator as a vector.
1992 static std::vector<Function*> ParseGlobalCtors(GlobalVariable *GV) {
1993   if (GV->getInitializer()->isNullValue())
1994     return std::vector<Function*>();
1995   ConstantArray *CA = cast<ConstantArray>(GV->getInitializer());
1996   std::vector<Function*> Result;
1997   Result.reserve(CA->getNumOperands());
1998   for (User::op_iterator i = CA->op_begin(), e = CA->op_end(); i != e; ++i) {
1999     ConstantStruct *CS = cast<ConstantStruct>(*i);
2000     Result.push_back(dyn_cast<Function>(CS->getOperand(1)));
2001   }
2002   return Result;
2003 }
2004 
2005 /// InstallGlobalCtors - Given a specified llvm.global_ctors list, install the
2006 /// specified array, returning the new global to use.
2007 static GlobalVariable *InstallGlobalCtors(GlobalVariable *GCL,
2008                                           const std::vector<Function*> &Ctors) {
2009   // If we made a change, reassemble the initializer list.
2010   Constant *CSVals[2];
2011   CSVals[0] = ConstantInt::get(Type::getInt32Ty(GCL->getContext()), 65535);
2012   CSVals[1] = 0;
2013 
2014   StructType *StructTy =
2015     cast<StructType>(GCL->getType()->getElementType()->getArrayElementType());
2016 
2017   // Create the new init list.
2018   std::vector<Constant*> CAList;
2019   for (unsigned i = 0, e = Ctors.size(); i != e; ++i) {
2020     if (Ctors[i]) {
2021       CSVals[1] = Ctors[i];
2022     } else {
2023       Type *FTy = FunctionType::get(Type::getVoidTy(GCL->getContext()),
2024                                           false);
2025       PointerType *PFTy = PointerType::getUnqual(FTy);
2026       CSVals[1] = Constant::getNullValue(PFTy);
2027       CSVals[0] = ConstantInt::get(Type::getInt32Ty(GCL->getContext()),
2028                                    0x7fffffff);
2029     }
2030     CAList.push_back(ConstantStruct::get(StructTy, CSVals));
2031   }
2032 
2033   // Create the array initializer.
2034   Constant *CA = ConstantArray::get(ArrayType::get(StructTy,
2035                                                    CAList.size()), CAList);
2036 
2037   // If we didn't change the number of elements, don't create a new GV.
2038   if (CA->getType() == GCL->getInitializer()->getType()) {
2039     GCL->setInitializer(CA);
2040     return GCL;
2041   }
2042 
2043   // Create the new global and insert it next to the existing list.
2044   GlobalVariable *NGV = new GlobalVariable(CA->getType(), GCL->isConstant(),
2045                                            GCL->getLinkage(), CA, "",
2046                                            GCL->getThreadLocalMode());
2047   GCL->getParent()->getGlobalList().insert(GCL, NGV);
2048   NGV->takeName(GCL);
2049 
2050   // Nuke the old list, replacing any uses with the new one.
2051   if (!GCL->use_empty()) {
2052     Constant *V = NGV;
2053     if (V->getType() != GCL->getType())
2054       V = ConstantExpr::getBitCast(V, GCL->getType());
2055     GCL->replaceAllUsesWith(V);
2056   }
2057   GCL->eraseFromParent();
2058 
2059   if (Ctors.size())
2060     return NGV;
2061   else
2062     return 0;
2063 }
2064 
2065 
2066 static inline bool
2067 isSimpleEnoughValueToCommit(Constant *C,
2068                             SmallPtrSet<Constant*, 8> &SimpleConstants,
2069                             const DataLayout *TD);
2070 
2071 
2072 /// isSimpleEnoughValueToCommit - Return true if the specified constant can be
2073 /// handled by the code generator.  We don't want to generate something like:
2074 ///   void *X = &X/42;
2075 /// because the code generator doesn't have a relocation that can handle that.
2076 ///
2077 /// This function should be called if C was not found (but just got inserted)
2078 /// in SimpleConstants to avoid having to rescan the same constants all the
2079 /// time.
2080 static bool isSimpleEnoughValueToCommitHelper(Constant *C,
2081                                    SmallPtrSet<Constant*, 8> &SimpleConstants,
2082                                    const DataLayout *TD) {
2083   // Simple integer, undef, constant aggregate zero, global addresses, etc are
2084   // all supported.
2085   if (C->getNumOperands() == 0 || isa<BlockAddress>(C) ||
2086       isa<GlobalValue>(C))
2087     return true;
2088 
2089   // Aggregate values are safe if all their elements are.
2090   if (isa<ConstantArray>(C) || isa<ConstantStruct>(C) ||
2091       isa<ConstantVector>(C)) {
2092     for (unsigned i = 0, e = C->getNumOperands(); i != e; ++i) {
2093       Constant *Op = cast<Constant>(C->getOperand(i));
2094       if (!isSimpleEnoughValueToCommit(Op, SimpleConstants, TD))
2095         return false;
2096     }
2097     return true;
2098   }
2099 
2100   // We don't know exactly what relocations are allowed in constant expressions,
2101   // so we allow &global+constantoffset, which is safe and uniformly supported
2102   // across targets.
2103   ConstantExpr *CE = cast<ConstantExpr>(C);
2104   switch (CE->getOpcode()) {
2105   case Instruction::BitCast:
2106     // Bitcast is fine if the casted value is fine.
2107     return isSimpleEnoughValueToCommit(CE->getOperand(0), SimpleConstants, TD);
2108 
2109   case Instruction::IntToPtr:
2110   case Instruction::PtrToInt:
2111     // int <=> ptr is fine if the int type is the same size as the
2112     // pointer type.
2113     if (!TD || TD->getTypeSizeInBits(CE->getType()) !=
2114                TD->getTypeSizeInBits(CE->getOperand(0)->getType()))
2115       return false;
2116     return isSimpleEnoughValueToCommit(CE->getOperand(0), SimpleConstants, TD);
2117 
2118   // GEP is fine if it is simple + constant offset.
2119   case Instruction::GetElementPtr:
2120     for (unsigned i = 1, e = CE->getNumOperands(); i != e; ++i)
2121       if (!isa<ConstantInt>(CE->getOperand(i)))
2122         return false;
2123     return isSimpleEnoughValueToCommit(CE->getOperand(0), SimpleConstants, TD);
2124 
2125   case Instruction::Add:
2126     // We allow simple+cst.
2127     if (!isa<ConstantInt>(CE->getOperand(1)))
2128       return false;
2129     return isSimpleEnoughValueToCommit(CE->getOperand(0), SimpleConstants, TD);
2130   }
2131   return false;
2132 }
2133 
2134 static inline bool
2135 isSimpleEnoughValueToCommit(Constant *C,
2136                             SmallPtrSet<Constant*, 8> &SimpleConstants,
2137                             const DataLayout *TD) {
2138   // If we already checked this constant, we win.
2139   if (!SimpleConstants.insert(C)) return true;
2140   // Check the constant.
2141   return isSimpleEnoughValueToCommitHelper(C, SimpleConstants, TD);
2142 }
2143 
2144 
2145 /// isSimpleEnoughPointerToCommit - Return true if this constant is simple
2146 /// enough for us to understand.  In particular, if it is a cast to anything
2147 /// other than from one pointer type to another pointer type, we punt.
2148 /// We basically just support direct accesses to globals and GEP's of
2149 /// globals.  This should be kept up to date with CommitValueTo.
2150 static bool isSimpleEnoughPointerToCommit(Constant *C) {
2151   // Conservatively, avoid aggregate types. This is because we don't
2152   // want to worry about them partially overlapping other stores.
2153   if (!cast<PointerType>(C->getType())->getElementType()->isSingleValueType())
2154     return false;
2155 
2156   if (GlobalVariable *GV = dyn_cast<GlobalVariable>(C))
2157     // Do not allow weak/*_odr/linkonce/dllimport/dllexport linkage or
2158     // external globals.
2159     return GV->hasUniqueInitializer();
2160 
2161   if (ConstantExpr *CE = dyn_cast<ConstantExpr>(C)) {
2162     // Handle a constantexpr gep.
2163     if (CE->getOpcode() == Instruction::GetElementPtr &&
2164         isa<GlobalVariable>(CE->getOperand(0)) &&
2165         cast<GEPOperator>(CE)->isInBounds()) {
2166       GlobalVariable *GV = cast<GlobalVariable>(CE->getOperand(0));
2167       // Do not allow weak/*_odr/linkonce/dllimport/dllexport linkage or
2168       // external globals.
2169       if (!GV->hasUniqueInitializer())
2170         return false;
2171 
2172       // The first index must be zero.
2173       ConstantInt *CI = dyn_cast<ConstantInt>(*llvm::next(CE->op_begin()));
2174       if (!CI || !CI->isZero()) return false;
2175 
2176       // The remaining indices must be compile-time known integers within the
2177       // notional bounds of the corresponding static array types.
2178       if (!CE->isGEPWithNoNotionalOverIndexing())
2179         return false;
2180 
2181       return ConstantFoldLoadThroughGEPConstantExpr(GV->getInitializer(), CE);
2182 
2183     // A constantexpr bitcast from a pointer to another pointer is a no-op,
2184     // and we know how to evaluate it by moving the bitcast from the pointer
2185     // operand to the value operand.
2186     } else if (CE->getOpcode() == Instruction::BitCast &&
2187                isa<GlobalVariable>(CE->getOperand(0))) {
2188       // Do not allow weak/*_odr/linkonce/dllimport/dllexport linkage or
2189       // external globals.
2190       return cast<GlobalVariable>(CE->getOperand(0))->hasUniqueInitializer();
2191     }
2192   }
2193 
2194   return false;
2195 }
2196 
2197 /// EvaluateStoreInto - Evaluate a piece of a constantexpr store into a global
2198 /// initializer.  This returns 'Init' modified to reflect 'Val' stored into it.
2199 /// At this point, the GEP operands of Addr [0, OpNo) have been stepped into.
2200 static Constant *EvaluateStoreInto(Constant *Init, Constant *Val,
2201                                    ConstantExpr *Addr, unsigned OpNo) {
2202   // Base case of the recursion.
2203   if (OpNo == Addr->getNumOperands()) {
2204     assert(Val->getType() == Init->getType() && "Type mismatch!");
2205     return Val;
2206   }
2207 
2208   SmallVector<Constant*, 32> Elts;
2209   if (StructType *STy = dyn_cast<StructType>(Init->getType())) {
2210     // Break up the constant into its elements.
2211     for (unsigned i = 0, e = STy->getNumElements(); i != e; ++i)
2212       Elts.push_back(Init->getAggregateElement(i));
2213 
2214     // Replace the element that we are supposed to.
2215     ConstantInt *CU = cast<ConstantInt>(Addr->getOperand(OpNo));
2216     unsigned Idx = CU->getZExtValue();
2217     assert(Idx < STy->getNumElements() && "Struct index out of range!");
2218     Elts[Idx] = EvaluateStoreInto(Elts[Idx], Val, Addr, OpNo+1);
2219 
2220     // Return the modified struct.
2221     return ConstantStruct::get(STy, Elts);
2222   }
2223 
2224   ConstantInt *CI = cast<ConstantInt>(Addr->getOperand(OpNo));
2225   SequentialType *InitTy = cast<SequentialType>(Init->getType());
2226 
2227   uint64_t NumElts;
2228   if (ArrayType *ATy = dyn_cast<ArrayType>(InitTy))
2229     NumElts = ATy->getNumElements();
2230   else
2231     NumElts = InitTy->getVectorNumElements();
2232 
2233   // Break up the array into elements.
2234   for (uint64_t i = 0, e = NumElts; i != e; ++i)
2235     Elts.push_back(Init->getAggregateElement(i));
2236 
2237   assert(CI->getZExtValue() < NumElts);
2238   Elts[CI->getZExtValue()] =
2239     EvaluateStoreInto(Elts[CI->getZExtValue()], Val, Addr, OpNo+1);
2240 
2241   if (Init->getType()->isArrayTy())
2242     return ConstantArray::get(cast<ArrayType>(InitTy), Elts);
2243   return ConstantVector::get(Elts);
2244 }
2245 
2246 /// CommitValueTo - We have decided that Addr (which satisfies the predicate
2247 /// isSimpleEnoughPointerToCommit) should get Val as its value.  Make it happen.
2248 static void CommitValueTo(Constant *Val, Constant *Addr) {
2249   if (GlobalVariable *GV = dyn_cast<GlobalVariable>(Addr)) {
2250     assert(GV->hasInitializer());
2251     GV->setInitializer(Val);
2252     return;
2253   }
2254 
2255   ConstantExpr *CE = cast<ConstantExpr>(Addr);
2256   GlobalVariable *GV = cast<GlobalVariable>(CE->getOperand(0));
2257   GV->setInitializer(EvaluateStoreInto(GV->getInitializer(), Val, CE, 2));
2258 }
2259 
2260 namespace {
2261 
2262 /// Evaluator - This class evaluates LLVM IR, producing the Constant
2263 /// representing each SSA instruction.  Changes to global variables are stored
2264 /// in a mapping that can be iterated over after the evaluation is complete.
2265 /// Once an evaluation call fails, the evaluation object should not be reused.
2266 class Evaluator {
2267 public:
2268   Evaluator(const DataLayout *TD, const TargetLibraryInfo *TLI)
2269     : TD(TD), TLI(TLI) {
2270     ValueStack.push_back(new DenseMap<Value*, Constant*>);
2271   }
2272 
2273   ~Evaluator() {
2274     DeleteContainerPointers(ValueStack);
2275     while (!AllocaTmps.empty()) {
2276       GlobalVariable *Tmp = AllocaTmps.back();
2277       AllocaTmps.pop_back();
2278 
2279       // If there are still users of the alloca, the program is doing something
2280       // silly, e.g. storing the address of the alloca somewhere and using it
2281       // later.  Since this is undefined, we'll just make it be null.
2282       if (!Tmp->use_empty())
2283         Tmp->replaceAllUsesWith(Constant::getNullValue(Tmp->getType()));
2284       delete Tmp;
2285     }
2286   }
2287 
2288   /// EvaluateFunction - Evaluate a call to function F, returning true if
2289   /// successful, false if we can't evaluate it.  ActualArgs contains the formal
2290   /// arguments for the function.
2291   bool EvaluateFunction(Function *F, Constant *&RetVal,
2292                         const SmallVectorImpl<Constant*> &ActualArgs);
2293 
2294   /// EvaluateBlock - Evaluate all instructions in block BB, returning true if
2295   /// successful, false if we can't evaluate it.  NewBB returns the next BB that
2296   /// control flows into, or null upon return.
2297   bool EvaluateBlock(BasicBlock::iterator CurInst, BasicBlock *&NextBB);
2298 
2299   Constant *getVal(Value *V) {
2300     if (Constant *CV = dyn_cast<Constant>(V)) return CV;
2301     Constant *R = ValueStack.back()->lookup(V);
2302     assert(R && "Reference to an uncomputed value!");
2303     return R;
2304   }
2305 
2306   void setVal(Value *V, Constant *C) {
2307     ValueStack.back()->operator[](V) = C;
2308   }
2309 
2310   const DenseMap<Constant*, Constant*> &getMutatedMemory() const {
2311     return MutatedMemory;
2312   }
2313 
2314   const SmallPtrSet<GlobalVariable*, 8> &getInvariants() const {
2315     return Invariants;
2316   }
2317 
2318 private:
2319   Constant *ComputeLoadResult(Constant *P);
2320 
2321   /// ValueStack - As we compute SSA register values, we store their contents
2322   /// here. The back of the vector contains the current function and the stack
2323   /// contains the values in the calling frames.
2324   SmallVector<DenseMap<Value*, Constant*>*, 4> ValueStack;
2325 
2326   /// CallStack - This is used to detect recursion.  In pathological situations
2327   /// we could hit exponential behavior, but at least there is nothing
2328   /// unbounded.
2329   SmallVector<Function*, 4> CallStack;
2330 
2331   /// MutatedMemory - For each store we execute, we update this map.  Loads
2332   /// check this to get the most up-to-date value.  If evaluation is successful,
2333   /// this state is committed to the process.
2334   DenseMap<Constant*, Constant*> MutatedMemory;
2335 
2336   /// AllocaTmps - To 'execute' an alloca, we create a temporary global variable
2337   /// to represent its body.  This vector is needed so we can delete the
2338   /// temporary globals when we are done.
2339   SmallVector<GlobalVariable*, 32> AllocaTmps;
2340 
2341   /// Invariants - These global variables have been marked invariant by the
2342   /// static constructor.
2343   SmallPtrSet<GlobalVariable*, 8> Invariants;
2344 
2345   /// SimpleConstants - These are constants we have checked and know to be
2346   /// simple enough to live in a static initializer of a global.
2347   SmallPtrSet<Constant*, 8> SimpleConstants;
2348 
2349   const DataLayout *TD;
2350   const TargetLibraryInfo *TLI;
2351 };
2352 
2353 }  // anonymous namespace
2354 
2355 /// ComputeLoadResult - Return the value that would be computed by a load from
2356 /// P after the stores reflected by 'memory' have been performed.  If we can't
2357 /// decide, return null.
2358 Constant *Evaluator::ComputeLoadResult(Constant *P) {
2359   // If this memory location has been recently stored, use the stored value: it
2360   // is the most up-to-date.
2361   DenseMap<Constant*, Constant*>::const_iterator I = MutatedMemory.find(P);
2362   if (I != MutatedMemory.end()) return I->second;
2363 
2364   // Access it.
2365   if (GlobalVariable *GV = dyn_cast<GlobalVariable>(P)) {
2366     if (GV->hasDefinitiveInitializer())
2367       return GV->getInitializer();
2368     return 0;
2369   }
2370 
2371   // Handle a constantexpr getelementptr.
2372   if (ConstantExpr *CE = dyn_cast<ConstantExpr>(P))
2373     if (CE->getOpcode() == Instruction::GetElementPtr &&
2374         isa<GlobalVariable>(CE->getOperand(0))) {
2375       GlobalVariable *GV = cast<GlobalVariable>(CE->getOperand(0));
2376       if (GV->hasDefinitiveInitializer())
2377         return ConstantFoldLoadThroughGEPConstantExpr(GV->getInitializer(), CE);
2378     }
2379 
2380   return 0;  // don't know how to evaluate.
2381 }
2382 
2383 /// EvaluateBlock - Evaluate all instructions in block BB, returning true if
2384 /// successful, false if we can't evaluate it.  NewBB returns the next BB that
2385 /// control flows into, or null upon return.
2386 bool Evaluator::EvaluateBlock(BasicBlock::iterator CurInst,
2387                               BasicBlock *&NextBB) {
2388   // This is the main evaluation loop.
2389   while (1) {
2390     Constant *InstResult = 0;
2391 
2392     DEBUG(dbgs() << "Evaluating Instruction: " << *CurInst << "\n");
2393 
2394     if (StoreInst *SI = dyn_cast<StoreInst>(CurInst)) {
2395       if (!SI->isSimple()) {
2396         DEBUG(dbgs() << "Store is not simple! Can not evaluate.\n");
2397         return false;  // no volatile/atomic accesses.
2398       }
2399       Constant *Ptr = getVal(SI->getOperand(1));
2400       if (ConstantExpr *CE = dyn_cast<ConstantExpr>(Ptr)) {
2401         DEBUG(dbgs() << "Folding constant ptr expression: " << *Ptr);
2402         Ptr = ConstantFoldConstantExpression(CE, TD, TLI);
2403         DEBUG(dbgs() << "; To: " << *Ptr << "\n");
2404       }
2405       if (!isSimpleEnoughPointerToCommit(Ptr)) {
2406         // If this is too complex for us to commit, reject it.
2407         DEBUG(dbgs() << "Pointer is too complex for us to evaluate store.");
2408         return false;
2409       }
2410 
2411       Constant *Val = getVal(SI->getOperand(0));
2412 
2413       // If this might be too difficult for the backend to handle (e.g. the addr
2414       // of one global variable divided by another) then we can't commit it.
2415       if (!isSimpleEnoughValueToCommit(Val, SimpleConstants, TD)) {
2416         DEBUG(dbgs() << "Store value is too complex to evaluate store. " << *Val
2417               << "\n");
2418         return false;
2419       }
2420 
2421       if (ConstantExpr *CE = dyn_cast<ConstantExpr>(Ptr)) {
2422         if (CE->getOpcode() == Instruction::BitCast) {
2423           DEBUG(dbgs() << "Attempting to resolve bitcast on constant ptr.\n");
2424           // If we're evaluating a store through a bitcast, then we need
2425           // to pull the bitcast off the pointer type and push it onto the
2426           // stored value.
2427           Ptr = CE->getOperand(0);
2428 
2429           Type *NewTy = cast<PointerType>(Ptr->getType())->getElementType();
2430 
2431           // In order to push the bitcast onto the stored value, a bitcast
2432           // from NewTy to Val's type must be legal.  If it's not, we can try
2433           // introspecting NewTy to find a legal conversion.
2434           while (!Val->getType()->canLosslesslyBitCastTo(NewTy)) {
2435             // If NewTy is a struct, we can convert the pointer to the struct
2436             // into a pointer to its first member.
2437             // FIXME: This could be extended to support arrays as well.
2438             if (StructType *STy = dyn_cast<StructType>(NewTy)) {
2439               NewTy = STy->getTypeAtIndex(0U);
2440 
2441               IntegerType *IdxTy = IntegerType::get(NewTy->getContext(), 32);
2442               Constant *IdxZero = ConstantInt::get(IdxTy, 0, false);
2443               Constant * const IdxList[] = {IdxZero, IdxZero};
2444 
2445               Ptr = ConstantExpr::getGetElementPtr(Ptr, IdxList);
2446               if (ConstantExpr *CE = dyn_cast<ConstantExpr>(Ptr))
2447                 Ptr = ConstantFoldConstantExpression(CE, TD, TLI);
2448 
2449             // If we can't improve the situation by introspecting NewTy,
2450             // we have to give up.
2451             } else {
2452               DEBUG(dbgs() << "Failed to bitcast constant ptr, can not "
2453                     "evaluate.\n");
2454               return false;
2455             }
2456           }
2457 
2458           // If we found compatible types, go ahead and push the bitcast
2459           // onto the stored value.
2460           Val = ConstantExpr::getBitCast(Val, NewTy);
2461 
2462           DEBUG(dbgs() << "Evaluated bitcast: " << *Val << "\n");
2463         }
2464       }
2465 
2466       MutatedMemory[Ptr] = Val;
2467     } else if (BinaryOperator *BO = dyn_cast<BinaryOperator>(CurInst)) {
2468       InstResult = ConstantExpr::get(BO->getOpcode(),
2469                                      getVal(BO->getOperand(0)),
2470                                      getVal(BO->getOperand(1)));
2471       DEBUG(dbgs() << "Found a BinaryOperator! Simplifying: " << *InstResult
2472             << "\n");
2473     } else if (CmpInst *CI = dyn_cast<CmpInst>(CurInst)) {
2474       InstResult = ConstantExpr::getCompare(CI->getPredicate(),
2475                                             getVal(CI->getOperand(0)),
2476                                             getVal(CI->getOperand(1)));
2477       DEBUG(dbgs() << "Found a CmpInst! Simplifying: " << *InstResult
2478             << "\n");
2479     } else if (CastInst *CI = dyn_cast<CastInst>(CurInst)) {
2480       InstResult = ConstantExpr::getCast(CI->getOpcode(),
2481                                          getVal(CI->getOperand(0)),
2482                                          CI->getType());
2483       DEBUG(dbgs() << "Found a Cast! Simplifying: " << *InstResult
2484             << "\n");
2485     } else if (SelectInst *SI = dyn_cast<SelectInst>(CurInst)) {
2486       InstResult = ConstantExpr::getSelect(getVal(SI->getOperand(0)),
2487                                            getVal(SI->getOperand(1)),
2488                                            getVal(SI->getOperand(2)));
2489       DEBUG(dbgs() << "Found a Select! Simplifying: " << *InstResult
2490             << "\n");
2491     } else if (GetElementPtrInst *GEP = dyn_cast<GetElementPtrInst>(CurInst)) {
2492       Constant *P = getVal(GEP->getOperand(0));
2493       SmallVector<Constant*, 8> GEPOps;
2494       for (User::op_iterator i = GEP->op_begin() + 1, e = GEP->op_end();
2495            i != e; ++i)
2496         GEPOps.push_back(getVal(*i));
2497       InstResult =
2498         ConstantExpr::getGetElementPtr(P, GEPOps,
2499                                        cast<GEPOperator>(GEP)->isInBounds());
2500       DEBUG(dbgs() << "Found a GEP! Simplifying: " << *InstResult
2501             << "\n");
2502     } else if (LoadInst *LI = dyn_cast<LoadInst>(CurInst)) {
2503 
2504       if (!LI->isSimple()) {
2505         DEBUG(dbgs() << "Found a Load! Not a simple load, can not evaluate.\n");
2506         return false;  // no volatile/atomic accesses.
2507       }
2508 
2509       Constant *Ptr = getVal(LI->getOperand(0));
2510       if (ConstantExpr *CE = dyn_cast<ConstantExpr>(Ptr)) {
2511         Ptr = ConstantFoldConstantExpression(CE, TD, TLI);
2512         DEBUG(dbgs() << "Found a constant pointer expression, constant "
2513               "folding: " << *Ptr << "\n");
2514       }
2515       InstResult = ComputeLoadResult(Ptr);
2516       if (InstResult == 0) {
2517         DEBUG(dbgs() << "Failed to compute load result. Can not evaluate load."
2518               "\n");
2519         return false; // Could not evaluate load.
2520       }
2521 
2522       DEBUG(dbgs() << "Evaluated load: " << *InstResult << "\n");
2523     } else if (AllocaInst *AI = dyn_cast<AllocaInst>(CurInst)) {
2524       if (AI->isArrayAllocation()) {
2525         DEBUG(dbgs() << "Found an array alloca. Can not evaluate.\n");
2526         return false;  // Cannot handle array allocs.
2527       }
2528       Type *Ty = AI->getType()->getElementType();
2529       AllocaTmps.push_back(new GlobalVariable(Ty, false,
2530                                               GlobalValue::InternalLinkage,
2531                                               UndefValue::get(Ty),
2532                                               AI->getName()));
2533       InstResult = AllocaTmps.back();
2534       DEBUG(dbgs() << "Found an alloca. Result: " << *InstResult << "\n");
2535     } else if (isa<CallInst>(CurInst) || isa<InvokeInst>(CurInst)) {
2536       CallSite CS(CurInst);
2537 
2538       // Debug info can safely be ignored here.
2539       if (isa<DbgInfoIntrinsic>(CS.getInstruction())) {
2540         DEBUG(dbgs() << "Ignoring debug info.\n");
2541         ++CurInst;
2542         continue;
2543       }
2544 
2545       // Cannot handle inline asm.
2546       if (isa<InlineAsm>(CS.getCalledValue())) {
2547         DEBUG(dbgs() << "Found inline asm, can not evaluate.\n");
2548         return false;
2549       }
2550 
2551       if (IntrinsicInst *II = dyn_cast<IntrinsicInst>(CS.getInstruction())) {
2552         if (MemSetInst *MSI = dyn_cast<MemSetInst>(II)) {
2553           if (MSI->isVolatile()) {
2554             DEBUG(dbgs() << "Can not optimize a volatile memset " <<
2555                   "intrinsic.\n");
2556             return false;
2557           }
2558           Constant *Ptr = getVal(MSI->getDest());
2559           Constant *Val = getVal(MSI->getValue());
2560           Constant *DestVal = ComputeLoadResult(getVal(Ptr));
2561           if (Val->isNullValue() && DestVal && DestVal->isNullValue()) {
2562             // This memset is a no-op.
2563             DEBUG(dbgs() << "Ignoring no-op memset.\n");
2564             ++CurInst;
2565             continue;
2566           }
2567         }
2568 
2569         if (II->getIntrinsicID() == Intrinsic::lifetime_start ||
2570             II->getIntrinsicID() == Intrinsic::lifetime_end) {
2571           DEBUG(dbgs() << "Ignoring lifetime intrinsic.\n");
2572           ++CurInst;
2573           continue;
2574         }
2575 
2576         if (II->getIntrinsicID() == Intrinsic::invariant_start) {
2577           // We don't insert an entry into Values, as it doesn't have a
2578           // meaningful return value.
2579           if (!II->use_empty()) {
2580             DEBUG(dbgs() << "Found unused invariant_start. Cant evaluate.\n");
2581             return false;
2582           }
2583           ConstantInt *Size = cast<ConstantInt>(II->getArgOperand(0));
2584           Value *PtrArg = getVal(II->getArgOperand(1));
2585           Value *Ptr = PtrArg->stripPointerCasts();
2586           if (GlobalVariable *GV = dyn_cast<GlobalVariable>(Ptr)) {
2587             Type *ElemTy = cast<PointerType>(GV->getType())->getElementType();
2588             if (TD && !Size->isAllOnesValue() &&
2589                 Size->getValue().getLimitedValue() >=
2590                 TD->getTypeStoreSize(ElemTy)) {
2591               Invariants.insert(GV);
2592               DEBUG(dbgs() << "Found a global var that is an invariant: " << *GV
2593                     << "\n");
2594             } else {
2595               DEBUG(dbgs() << "Found a global var, but can not treat it as an "
2596                     "invariant.\n");
2597             }
2598           }
2599           // Continue even if we do nothing.
2600           ++CurInst;
2601           continue;
2602         }
2603 
2604         DEBUG(dbgs() << "Unknown intrinsic. Can not evaluate.\n");
2605         return false;
2606       }
2607 
2608       // Resolve function pointers.
2609       Function *Callee = dyn_cast<Function>(getVal(CS.getCalledValue()));
2610       if (!Callee || Callee->mayBeOverridden()) {
2611         DEBUG(dbgs() << "Can not resolve function pointer.\n");
2612         return false;  // Cannot resolve.
2613       }
2614 
2615       SmallVector<Constant*, 8> Formals;
2616       for (User::op_iterator i = CS.arg_begin(), e = CS.arg_end(); i != e; ++i)
2617         Formals.push_back(getVal(*i));
2618 
2619       if (Callee->isDeclaration()) {
2620         // If this is a function we can constant fold, do it.
2621         if (Constant *C = ConstantFoldCall(Callee, Formals, TLI)) {
2622           InstResult = C;
2623           DEBUG(dbgs() << "Constant folded function call. Result: " <<
2624                 *InstResult << "\n");
2625         } else {
2626           DEBUG(dbgs() << "Can not constant fold function call.\n");
2627           return false;
2628         }
2629       } else {
2630         if (Callee->getFunctionType()->isVarArg()) {
2631           DEBUG(dbgs() << "Can not constant fold vararg function call.\n");
2632           return false;
2633         }
2634 
2635         Constant *RetVal = 0;
2636         // Execute the call, if successful, use the return value.
2637         ValueStack.push_back(new DenseMap<Value*, Constant*>);
2638         if (!EvaluateFunction(Callee, RetVal, Formals)) {
2639           DEBUG(dbgs() << "Failed to evaluate function.\n");
2640           return false;
2641         }
2642         delete ValueStack.pop_back_val();
2643         InstResult = RetVal;
2644 
2645         if (InstResult != NULL) {
2646           DEBUG(dbgs() << "Successfully evaluated function. Result: " <<
2647                 InstResult << "\n\n");
2648         } else {
2649           DEBUG(dbgs() << "Successfully evaluated function. Result: 0\n\n");
2650         }
2651       }
2652     } else if (isa<TerminatorInst>(CurInst)) {
2653       DEBUG(dbgs() << "Found a terminator instruction.\n");
2654 
2655       if (BranchInst *BI = dyn_cast<BranchInst>(CurInst)) {
2656         if (BI->isUnconditional()) {
2657           NextBB = BI->getSuccessor(0);
2658         } else {
2659           ConstantInt *Cond =
2660             dyn_cast<ConstantInt>(getVal(BI->getCondition()));
2661           if (!Cond) return false;  // Cannot determine.
2662 
2663           NextBB = BI->getSuccessor(!Cond->getZExtValue());
2664         }
2665       } else if (SwitchInst *SI = dyn_cast<SwitchInst>(CurInst)) {
2666         ConstantInt *Val =
2667           dyn_cast<ConstantInt>(getVal(SI->getCondition()));
2668         if (!Val) return false;  // Cannot determine.
2669         NextBB = SI->findCaseValue(Val).getCaseSuccessor();
2670       } else if (IndirectBrInst *IBI = dyn_cast<IndirectBrInst>(CurInst)) {
2671         Value *Val = getVal(IBI->getAddress())->stripPointerCasts();
2672         if (BlockAddress *BA = dyn_cast<BlockAddress>(Val))
2673           NextBB = BA->getBasicBlock();
2674         else
2675           return false;  // Cannot determine.
2676       } else if (isa<ReturnInst>(CurInst)) {
2677         NextBB = 0;
2678       } else {
2679         // invoke, unwind, resume, unreachable.
2680         DEBUG(dbgs() << "Can not handle terminator.");
2681         return false;  // Cannot handle this terminator.
2682       }
2683 
2684       // We succeeded at evaluating this block!
2685       DEBUG(dbgs() << "Successfully evaluated block.\n");
2686       return true;
2687     } else {
2688       // Did not know how to evaluate this!
2689       DEBUG(dbgs() << "Failed to evaluate block due to unhandled instruction."
2690             "\n");
2691       return false;
2692     }
2693 
2694     if (!CurInst->use_empty()) {
2695       if (ConstantExpr *CE = dyn_cast<ConstantExpr>(InstResult))
2696         InstResult = ConstantFoldConstantExpression(CE, TD, TLI);
2697 
2698       setVal(CurInst, InstResult);
2699     }
2700 
2701     // If we just processed an invoke, we finished evaluating the block.
2702     if (InvokeInst *II = dyn_cast<InvokeInst>(CurInst)) {
2703       NextBB = II->getNormalDest();
2704       DEBUG(dbgs() << "Found an invoke instruction. Finished Block.\n\n");
2705       return true;
2706     }
2707 
2708     // Advance program counter.
2709     ++CurInst;
2710   }
2711 }
2712 
2713 /// EvaluateFunction - Evaluate a call to function F, returning true if
2714 /// successful, false if we can't evaluate it.  ActualArgs contains the formal
2715 /// arguments for the function.
2716 bool Evaluator::EvaluateFunction(Function *F, Constant *&RetVal,
2717                                  const SmallVectorImpl<Constant*> &ActualArgs) {
2718   // Check to see if this function is already executing (recursion).  If so,
2719   // bail out.  TODO: we might want to accept limited recursion.
2720   if (std::find(CallStack.begin(), CallStack.end(), F) != CallStack.end())
2721     return false;
2722 
2723   CallStack.push_back(F);
2724 
2725   // Initialize arguments to the incoming values specified.
2726   unsigned ArgNo = 0;
2727   for (Function::arg_iterator AI = F->arg_begin(), E = F->arg_end(); AI != E;
2728        ++AI, ++ArgNo)
2729     setVal(AI, ActualArgs[ArgNo]);
2730 
2731   // ExecutedBlocks - We only handle non-looping, non-recursive code.  As such,
2732   // we can only evaluate any one basic block at most once.  This set keeps
2733   // track of what we have executed so we can detect recursive cases etc.
2734   SmallPtrSet<BasicBlock*, 32> ExecutedBlocks;
2735 
2736   // CurBB - The current basic block we're evaluating.
2737   BasicBlock *CurBB = F->begin();
2738 
2739   BasicBlock::iterator CurInst = CurBB->begin();
2740 
2741   while (1) {
2742     BasicBlock *NextBB = 0; // Initialized to avoid compiler warnings.
2743     DEBUG(dbgs() << "Trying to evaluate BB: " << *CurBB << "\n");
2744 
2745     if (!EvaluateBlock(CurInst, NextBB))
2746       return false;
2747 
2748     if (NextBB == 0) {
2749       // Successfully running until there's no next block means that we found
2750       // the return.  Fill it the return value and pop the call stack.
2751       ReturnInst *RI = cast<ReturnInst>(CurBB->getTerminator());
2752       if (RI->getNumOperands())
2753         RetVal = getVal(RI->getOperand(0));
2754       CallStack.pop_back();
2755       return true;
2756     }
2757 
2758     // Okay, we succeeded in evaluating this control flow.  See if we have
2759     // executed the new block before.  If so, we have a looping function,
2760     // which we cannot evaluate in reasonable time.
2761     if (!ExecutedBlocks.insert(NextBB))
2762       return false;  // looped!
2763 
2764     // Okay, we have never been in this block before.  Check to see if there
2765     // are any PHI nodes.  If so, evaluate them with information about where
2766     // we came from.
2767     PHINode *PN = 0;
2768     for (CurInst = NextBB->begin();
2769          (PN = dyn_cast<PHINode>(CurInst)); ++CurInst)
2770       setVal(PN, getVal(PN->getIncomingValueForBlock(CurBB)));
2771 
2772     // Advance to the next block.
2773     CurBB = NextBB;
2774   }
2775 }
2776 
2777 /// EvaluateStaticConstructor - Evaluate static constructors in the function, if
2778 /// we can.  Return true if we can, false otherwise.
2779 static bool EvaluateStaticConstructor(Function *F, const DataLayout *TD,
2780                                       const TargetLibraryInfo *TLI) {
2781   // Call the function.
2782   Evaluator Eval(TD, TLI);
2783   Constant *RetValDummy;
2784   bool EvalSuccess = Eval.EvaluateFunction(F, RetValDummy,
2785                                            SmallVector<Constant*, 0>());
2786 
2787   if (EvalSuccess) {
2788     // We succeeded at evaluation: commit the result.
2789     DEBUG(dbgs() << "FULLY EVALUATED GLOBAL CTOR FUNCTION '"
2790           << F->getName() << "' to " << Eval.getMutatedMemory().size()
2791           << " stores.\n");
2792     for (DenseMap<Constant*, Constant*>::const_iterator I =
2793            Eval.getMutatedMemory().begin(), E = Eval.getMutatedMemory().end();
2794          I != E; ++I)
2795       CommitValueTo(I->second, I->first);
2796     for (SmallPtrSet<GlobalVariable*, 8>::const_iterator I =
2797            Eval.getInvariants().begin(), E = Eval.getInvariants().end();
2798          I != E; ++I)
2799       (*I)->setConstant(true);
2800   }
2801 
2802   return EvalSuccess;
2803 }
2804 
2805 /// OptimizeGlobalCtorsList - Simplify and evaluation global ctors if possible.
2806 /// Return true if anything changed.
2807 bool GlobalOpt::OptimizeGlobalCtorsList(GlobalVariable *&GCL) {
2808   std::vector<Function*> Ctors = ParseGlobalCtors(GCL);
2809   bool MadeChange = false;
2810   if (Ctors.empty()) return false;
2811 
2812   // Loop over global ctors, optimizing them when we can.
2813   for (unsigned i = 0; i != Ctors.size(); ++i) {
2814     Function *F = Ctors[i];
2815     // Found a null terminator in the middle of the list, prune off the rest of
2816     // the list.
2817     if (F == 0) {
2818       if (i != Ctors.size()-1) {
2819         Ctors.resize(i+1);
2820         MadeChange = true;
2821       }
2822       break;
2823     }
2824     DEBUG(dbgs() << "Optimizing Global Constructor: " << *F << "\n");
2825 
2826     // We cannot simplify external ctor functions.
2827     if (F->empty()) continue;
2828 
2829     // If we can evaluate the ctor at compile time, do.
2830     if (EvaluateStaticConstructor(F, TD, TLI)) {
2831       Ctors.erase(Ctors.begin()+i);
2832       MadeChange = true;
2833       --i;
2834       ++NumCtorsEvaluated;
2835       continue;
2836     }
2837   }
2838 
2839   if (!MadeChange) return false;
2840 
2841   GCL = InstallGlobalCtors(GCL, Ctors);
2842   return true;
2843 }
2844 
2845 static int compareNames(Constant *const *A, Constant *const *B) {
2846   return (*A)->getName().compare((*B)->getName());
2847 }
2848 
2849 static void setUsedInitializer(GlobalVariable &V,
2850                                SmallPtrSet<GlobalValue *, 8> Init) {
2851   if (Init.empty()) {
2852     V.eraseFromParent();
2853     return;
2854   }
2855 
2856   SmallVector<llvm::Constant *, 8> UsedArray;
2857   PointerType *Int8PtrTy = Type::getInt8PtrTy(V.getContext());
2858 
2859   for (SmallPtrSet<GlobalValue *, 8>::iterator I = Init.begin(), E = Init.end();
2860        I != E; ++I) {
2861     Constant *Cast = llvm::ConstantExpr::getBitCast(*I, Int8PtrTy);
2862     UsedArray.push_back(Cast);
2863   }
2864   // Sort to get deterministic order.
2865   array_pod_sort(UsedArray.begin(), UsedArray.end(), compareNames);
2866   ArrayType *ATy = ArrayType::get(Int8PtrTy, UsedArray.size());
2867 
2868   Module *M = V.getParent();
2869   V.removeFromParent();
2870   GlobalVariable *NV =
2871       new GlobalVariable(*M, ATy, false, llvm::GlobalValue::AppendingLinkage,
2872                          llvm::ConstantArray::get(ATy, UsedArray), "");
2873   NV->takeName(&V);
2874   NV->setSection("llvm.metadata");
2875   delete &V;
2876 }
2877 
2878 namespace {
2879 /// \brief An easy to access representation of llvm.used and llvm.compiler.used.
2880 class LLVMUsed {
2881   SmallPtrSet<GlobalValue *, 8> Used;
2882   SmallPtrSet<GlobalValue *, 8> CompilerUsed;
2883   GlobalVariable *UsedV;
2884   GlobalVariable *CompilerUsedV;
2885 
2886 public:
2887   LLVMUsed(Module &M) {
2888     UsedV = collectUsedGlobalVariables(M, Used, false);
2889     CompilerUsedV = collectUsedGlobalVariables(M, CompilerUsed, true);
2890   }
2891   typedef SmallPtrSet<GlobalValue *, 8>::iterator iterator;
2892   iterator usedBegin() { return Used.begin(); }
2893   iterator usedEnd() { return Used.end(); }
2894   iterator compilerUsedBegin() { return CompilerUsed.begin(); }
2895   iterator compilerUsedEnd() { return CompilerUsed.end(); }
2896   bool usedCount(GlobalValue *GV) const { return Used.count(GV); }
2897   bool compilerUsedCount(GlobalValue *GV) const {
2898     return CompilerUsed.count(GV);
2899   }
2900   bool usedErase(GlobalValue *GV) { return Used.erase(GV); }
2901   bool compilerUsedErase(GlobalValue *GV) { return CompilerUsed.erase(GV); }
2902   bool usedInsert(GlobalValue *GV) { return Used.insert(GV); }
2903   bool compilerUsedInsert(GlobalValue *GV) { return CompilerUsed.insert(GV); }
2904 
2905   void syncVariablesAndSets() {
2906     if (UsedV)
2907       setUsedInitializer(*UsedV, Used);
2908     if (CompilerUsedV)
2909       setUsedInitializer(*CompilerUsedV, CompilerUsed);
2910   }
2911 };
2912 }
2913 
2914 static bool hasUseOtherThanLLVMUsed(GlobalAlias &GA, const LLVMUsed &U) {
2915   if (GA.use_empty()) // No use at all.
2916     return false;
2917 
2918   assert((!U.usedCount(&GA) || !U.compilerUsedCount(&GA)) &&
2919          "We should have removed the duplicated "
2920          "element from llvm.compiler.used");
2921   if (!GA.hasOneUse())
2922     // Strictly more than one use. So at least one is not in llvm.used and
2923     // llvm.compiler.used.
2924     return true;
2925 
2926   // Exactly one use. Check if it is in llvm.used or llvm.compiler.used.
2927   return !U.usedCount(&GA) && !U.compilerUsedCount(&GA);
2928 }
2929 
2930 static bool hasMoreThanOneUseOtherThanLLVMUsed(GlobalValue &V,
2931                                                const LLVMUsed &U) {
2932   unsigned N = 2;
2933   assert((!U.usedCount(&V) || !U.compilerUsedCount(&V)) &&
2934          "We should have removed the duplicated "
2935          "element from llvm.compiler.used");
2936   if (U.usedCount(&V) || U.compilerUsedCount(&V))
2937     ++N;
2938   return V.hasNUsesOrMore(N);
2939 }
2940 
2941 static bool mayHaveOtherReferences(GlobalAlias &GA, const LLVMUsed &U) {
2942   if (!GA.hasLocalLinkage())
2943     return true;
2944 
2945   return U.usedCount(&GA) || U.compilerUsedCount(&GA);
2946 }
2947 
2948 static bool hasUsesToReplace(GlobalAlias &GA, LLVMUsed &U, bool &RenameTarget) {
2949   RenameTarget = false;
2950   bool Ret = false;
2951   if (hasUseOtherThanLLVMUsed(GA, U))
2952     Ret = true;
2953 
2954   // If the alias is externally visible, we may still be able to simplify it.
2955   if (!mayHaveOtherReferences(GA, U))
2956     return Ret;
2957 
2958   // If the aliasee has internal linkage, give it the name and linkage
2959   // of the alias, and delete the alias.  This turns:
2960   //   define internal ... @f(...)
2961   //   @a = alias ... @f
2962   // into:
2963   //   define ... @a(...)
2964   Constant *Aliasee = GA.getAliasee();
2965   GlobalValue *Target = cast<GlobalValue>(Aliasee->stripPointerCasts());
2966   if (!Target->hasLocalLinkage())
2967     return Ret;
2968 
2969   // Do not perform the transform if multiple aliases potentially target the
2970   // aliasee. This check also ensures that it is safe to replace the section
2971   // and other attributes of the aliasee with those of the alias.
2972   if (hasMoreThanOneUseOtherThanLLVMUsed(*Target, U))
2973     return Ret;
2974 
2975   RenameTarget = true;
2976   return true;
2977 }
2978 
2979 bool GlobalOpt::OptimizeGlobalAliases(Module &M) {
2980   bool Changed = false;
2981   LLVMUsed Used(M);
2982 
2983   for (SmallPtrSet<GlobalValue *, 8>::iterator I = Used.usedBegin(),
2984                                                E = Used.usedEnd();
2985        I != E; ++I)
2986     Used.compilerUsedErase(*I);
2987 
2988   for (Module::alias_iterator I = M.alias_begin(), E = M.alias_end();
2989        I != E;) {
2990     Module::alias_iterator J = I++;
2991     // Aliases without names cannot be referenced outside this module.
2992     if (!J->hasName() && !J->isDeclaration())
2993       J->setLinkage(GlobalValue::InternalLinkage);
2994     // If the aliasee may change at link time, nothing can be done - bail out.
2995     if (J->mayBeOverridden())
2996       continue;
2997 
2998     Constant *Aliasee = J->getAliasee();
2999     GlobalValue *Target = cast<GlobalValue>(Aliasee->stripPointerCasts());
3000     Target->removeDeadConstantUsers();
3001 
3002     // Make all users of the alias use the aliasee instead.
3003     bool RenameTarget;
3004     if (!hasUsesToReplace(*J, Used, RenameTarget))
3005       continue;
3006 
3007     J->replaceAllUsesWith(Aliasee);
3008     ++NumAliasesResolved;
3009     Changed = true;
3010 
3011     if (RenameTarget) {
3012       // Give the aliasee the name, linkage and other attributes of the alias.
3013       Target->takeName(J);
3014       Target->setLinkage(J->getLinkage());
3015       Target->GlobalValue::copyAttributesFrom(J);
3016 
3017       if (Used.usedErase(J))
3018         Used.usedInsert(Target);
3019 
3020       if (Used.compilerUsedErase(J))
3021         Used.compilerUsedInsert(Target);
3022     } else if (mayHaveOtherReferences(*J, Used))
3023       continue;
3024 
3025     // Delete the alias.
3026     M.getAliasList().erase(J);
3027     ++NumAliasesRemoved;
3028     Changed = true;
3029   }
3030 
3031   Used.syncVariablesAndSets();
3032 
3033   return Changed;
3034 }
3035 
3036 static Function *FindCXAAtExit(Module &M, TargetLibraryInfo *TLI) {
3037   if (!TLI->has(LibFunc::cxa_atexit))
3038     return 0;
3039 
3040   Function *Fn = M.getFunction(TLI->getName(LibFunc::cxa_atexit));
3041 
3042   if (!Fn)
3043     return 0;
3044 
3045   FunctionType *FTy = Fn->getFunctionType();
3046 
3047   // Checking that the function has the right return type, the right number of
3048   // parameters and that they all have pointer types should be enough.
3049   if (!FTy->getReturnType()->isIntegerTy() ||
3050       FTy->getNumParams() != 3 ||
3051       !FTy->getParamType(0)->isPointerTy() ||
3052       !FTy->getParamType(1)->isPointerTy() ||
3053       !FTy->getParamType(2)->isPointerTy())
3054     return 0;
3055 
3056   return Fn;
3057 }
3058 
3059 /// cxxDtorIsEmpty - Returns whether the given function is an empty C++
3060 /// destructor and can therefore be eliminated.
3061 /// Note that we assume that other optimization passes have already simplified
3062 /// the code so we only look for a function with a single basic block, where
3063 /// the only allowed instructions are 'ret', 'call' to an empty C++ dtor and
3064 /// other side-effect free instructions.
3065 static bool cxxDtorIsEmpty(const Function &Fn,
3066                            SmallPtrSet<const Function *, 8> &CalledFunctions) {
3067   // FIXME: We could eliminate C++ destructors if they're readonly/readnone and
3068   // nounwind, but that doesn't seem worth doing.
3069   if (Fn.isDeclaration())
3070     return false;
3071 
3072   if (++Fn.begin() != Fn.end())
3073     return false;
3074 
3075   const BasicBlock &EntryBlock = Fn.getEntryBlock();
3076   for (BasicBlock::const_iterator I = EntryBlock.begin(), E = EntryBlock.end();
3077        I != E; ++I) {
3078     if (const CallInst *CI = dyn_cast<CallInst>(I)) {
3079       // Ignore debug intrinsics.
3080       if (isa<DbgInfoIntrinsic>(CI))
3081         continue;
3082 
3083       const Function *CalledFn = CI->getCalledFunction();
3084 
3085       if (!CalledFn)
3086         return false;
3087 
3088       SmallPtrSet<const Function *, 8> NewCalledFunctions(CalledFunctions);
3089 
3090       // Don't treat recursive functions as empty.
3091       if (!NewCalledFunctions.insert(CalledFn))
3092         return false;
3093 
3094       if (!cxxDtorIsEmpty(*CalledFn, NewCalledFunctions))
3095         return false;
3096     } else if (isa<ReturnInst>(*I))
3097       return true; // We're done.
3098     else if (I->mayHaveSideEffects())
3099       return false; // Destructor with side effects, bail.
3100   }
3101 
3102   return false;
3103 }
3104 
3105 bool GlobalOpt::OptimizeEmptyGlobalCXXDtors(Function *CXAAtExitFn) {
3106   /// Itanium C++ ABI p3.3.5:
3107   ///
3108   ///   After constructing a global (or local static) object, that will require
3109   ///   destruction on exit, a termination function is registered as follows:
3110   ///
3111   ///   extern "C" int __cxa_atexit ( void (*f)(void *), void *p, void *d );
3112   ///
3113   ///   This registration, e.g. __cxa_atexit(f,p,d), is intended to cause the
3114   ///   call f(p) when DSO d is unloaded, before all such termination calls
3115   ///   registered before this one. It returns zero if registration is
3116   ///   successful, nonzero on failure.
3117 
3118   // This pass will look for calls to __cxa_atexit where the function is trivial
3119   // and remove them.
3120   bool Changed = false;
3121 
3122   for (Function::use_iterator I = CXAAtExitFn->use_begin(),
3123        E = CXAAtExitFn->use_end(); I != E;) {
3124     // We're only interested in calls. Theoretically, we could handle invoke
3125     // instructions as well, but neither llvm-gcc nor clang generate invokes
3126     // to __cxa_atexit.
3127     CallInst *CI = dyn_cast<CallInst>(*I++);
3128     if (!CI)
3129       continue;
3130 
3131     Function *DtorFn =
3132       dyn_cast<Function>(CI->getArgOperand(0)->stripPointerCasts());
3133     if (!DtorFn)
3134       continue;
3135 
3136     SmallPtrSet<const Function *, 8> CalledFunctions;
3137     if (!cxxDtorIsEmpty(*DtorFn, CalledFunctions))
3138       continue;
3139 
3140     // Just remove the call.
3141     CI->replaceAllUsesWith(Constant::getNullValue(CI->getType()));
3142     CI->eraseFromParent();
3143 
3144     ++NumCXXDtorsRemoved;
3145 
3146     Changed |= true;
3147   }
3148 
3149   return Changed;
3150 }
3151 
3152 bool GlobalOpt::runOnModule(Module &M) {
3153   bool Changed = false;
3154 
3155   TD = getAnalysisIfAvailable<DataLayout>();
3156   TLI = &getAnalysis<TargetLibraryInfo>();
3157 
3158   // Try to find the llvm.globalctors list.
3159   GlobalVariable *GlobalCtors = FindGlobalCtors(M);
3160 
3161   bool LocalChange = true;
3162   while (LocalChange) {
3163     LocalChange = false;
3164 
3165     // Delete functions that are trivially dead, ccc -> fastcc
3166     LocalChange |= OptimizeFunctions(M);
3167 
3168     // Optimize global_ctors list.
3169     if (GlobalCtors)
3170       LocalChange |= OptimizeGlobalCtorsList(GlobalCtors);
3171 
3172     // Optimize non-address-taken globals.
3173     LocalChange |= OptimizeGlobalVars(M);
3174 
3175     // Resolve aliases, when possible.
3176     LocalChange |= OptimizeGlobalAliases(M);
3177 
3178     // Try to remove trivial global destructors if they are not removed
3179     // already.
3180     Function *CXAAtExitFn = FindCXAAtExit(M, TLI);
3181     if (CXAAtExitFn)
3182       LocalChange |= OptimizeEmptyGlobalCXXDtors(CXAAtExitFn);
3183 
3184     Changed |= LocalChange;
3185   }
3186 
3187   // TODO: Move all global ctors functions to the end of the module for code
3188   // layout.
3189 
3190   return Changed;
3191 }
3192