1 //===-- LICM.cpp - Loop Invariant Code Motion Pass ------------------------===//
2 //
3 //                     The LLVM Compiler Infrastructure
4 //
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
7 //
8 //===----------------------------------------------------------------------===//
9 //
10 // This pass performs loop invariant code motion, attempting to remove as much
11 // code from the body of a loop as possible.  It does this by either hoisting
12 // code into the preheader block, or by sinking code to the exit blocks if it is
13 // safe.  This pass also promotes must-aliased memory locations in the loop to
14 // live in registers, thus hoisting and sinking "invariant" loads and stores.
15 //
16 // This pass uses alias analysis for two purposes:
17 //
18 //  1. Moving loop invariant loads and calls out of loops.  If we can determine
19 //     that a load or call inside of a loop never aliases anything stored to,
20 //     we can hoist it or sink it like any other instruction.
21 //  2. Scalar Promotion of Memory - If there is a store instruction inside of
22 //     the loop, we try to move the store to happen AFTER the loop instead of
23 //     inside of the loop.  This can only happen if a few conditions are true:
24 //       A. The pointer stored through is loop invariant
25 //       B. There are no stores or loads in the loop which _may_ alias the
26 //          pointer.  There are no calls in the loop which mod/ref the pointer.
27 //     If these conditions are true, we can promote the loads and stores in the
28 //     loop of the pointer to use a temporary alloca'd variable.  We then use
29 //     the SSAUpdater to construct the appropriate SSA form for the value.
30 //
31 //===----------------------------------------------------------------------===//
32 
33 #include "llvm/Transforms/Scalar/LICM.h"
34 #include "llvm/ADT/Statistic.h"
35 #include "llvm/Analysis/AliasAnalysis.h"
36 #include "llvm/Analysis/AliasSetTracker.h"
37 #include "llvm/Analysis/BasicAliasAnalysis.h"
38 #include "llvm/Analysis/CaptureTracking.h"
39 #include "llvm/Analysis/ConstantFolding.h"
40 #include "llvm/Analysis/GlobalsModRef.h"
41 #include "llvm/Analysis/Loads.h"
42 #include "llvm/Analysis/LoopInfo.h"
43 #include "llvm/Analysis/LoopPass.h"
44 #include "llvm/Analysis/MemoryBuiltins.h"
45 #include "llvm/Analysis/MemorySSA.h"
46 #include "llvm/Analysis/OptimizationRemarkEmitter.h"
47 #include "llvm/Analysis/ScalarEvolution.h"
48 #include "llvm/Analysis/ScalarEvolutionAliasAnalysis.h"
49 #include "llvm/Analysis/TargetLibraryInfo.h"
50 #include "llvm/Analysis/ValueTracking.h"
51 #include "llvm/IR/CFG.h"
52 #include "llvm/IR/Constants.h"
53 #include "llvm/IR/DataLayout.h"
54 #include "llvm/IR/DerivedTypes.h"
55 #include "llvm/IR/Dominators.h"
56 #include "llvm/IR/Instructions.h"
57 #include "llvm/IR/IntrinsicInst.h"
58 #include "llvm/IR/LLVMContext.h"
59 #include "llvm/IR/Metadata.h"
60 #include "llvm/IR/PredIteratorCache.h"
61 #include "llvm/Support/CommandLine.h"
62 #include "llvm/Support/Debug.h"
63 #include "llvm/Support/raw_ostream.h"
64 #include "llvm/Transforms/Scalar.h"
65 #include "llvm/Transforms/Scalar/LoopPassManager.h"
66 #include "llvm/Transforms/Utils/BasicBlockUtils.h"
67 #include "llvm/Transforms/Utils/Local.h"
68 #include "llvm/Transforms/Utils/LoopUtils.h"
69 #include "llvm/Transforms/Utils/SSAUpdater.h"
70 #include <algorithm>
71 #include <utility>
72 using namespace llvm;
73 
74 #define DEBUG_TYPE "licm"
75 
76 STATISTIC(NumSunk, "Number of instructions sunk out of loop");
77 STATISTIC(NumHoisted, "Number of instructions hoisted out of loop");
78 STATISTIC(NumMovedLoads, "Number of load insts hoisted or sunk");
79 STATISTIC(NumMovedCalls, "Number of call insts hoisted or sunk");
80 STATISTIC(NumPromoted, "Number of memory locations promoted to registers");
81 
82 /// Memory promotion is enabled by default.
83 static cl::opt<bool>
84     DisablePromotion("disable-licm-promotion", cl::Hidden, cl::init(false),
85                      cl::desc("Disable memory promotion in LICM pass"));
86 
87 static cl::opt<uint32_t> MaxNumUsesTraversed(
88     "licm-max-num-uses-traversed", cl::Hidden, cl::init(8),
89     cl::desc("Max num uses visited for identifying load "
90              "invariance in loop using invariant start (default = 8)"));
91 
92 static bool inSubLoop(BasicBlock *BB, Loop *CurLoop, LoopInfo *LI);
93 static bool isNotUsedInLoop(const Instruction &I, const Loop *CurLoop,
94                             const LoopSafetyInfo *SafetyInfo);
95 static bool hoist(Instruction &I, const DominatorTree *DT, const Loop *CurLoop,
96                   const LoopSafetyInfo *SafetyInfo,
97                   OptimizationRemarkEmitter *ORE);
98 static bool sink(Instruction &I, LoopInfo *LI, DominatorTree *DT,
99                  const Loop *CurLoop, const LoopSafetyInfo *SafetyInfo,
100                  OptimizationRemarkEmitter *ORE);
101 static bool isSafeToExecuteUnconditionally(Instruction &Inst,
102                                            const DominatorTree *DT,
103                                            const Loop *CurLoop,
104                                            const LoopSafetyInfo *SafetyInfo,
105                                            OptimizationRemarkEmitter *ORE,
106                                            const Instruction *CtxI = nullptr);
107 static bool pointerInvalidatedByLoop(Value *V, uint64_t Size,
108                                      const AAMDNodes &AAInfo,
109                                      AliasSetTracker *CurAST);
110 static Instruction *
111 CloneInstructionInExitBlock(Instruction &I, BasicBlock &ExitBlock, PHINode &PN,
112                             const LoopInfo *LI,
113                             const LoopSafetyInfo *SafetyInfo);
114 
115 namespace {
116 struct LoopInvariantCodeMotion {
117   bool runOnLoop(Loop *L, AliasAnalysis *AA, LoopInfo *LI, DominatorTree *DT,
118                  TargetLibraryInfo *TLI, ScalarEvolution *SE, MemorySSA *MSSA,
119                  OptimizationRemarkEmitter *ORE, bool DeleteAST);
120 
121   DenseMap<Loop *, AliasSetTracker *> &getLoopToAliasSetMap() {
122     return LoopToAliasSetMap;
123   }
124 
125 private:
126   DenseMap<Loop *, AliasSetTracker *> LoopToAliasSetMap;
127 
128   AliasSetTracker *collectAliasInfoForLoop(Loop *L, LoopInfo *LI,
129                                            AliasAnalysis *AA);
130 };
131 
132 struct LegacyLICMPass : public LoopPass {
133   static char ID; // Pass identification, replacement for typeid
134   LegacyLICMPass() : LoopPass(ID) {
135     initializeLegacyLICMPassPass(*PassRegistry::getPassRegistry());
136   }
137 
138   bool runOnLoop(Loop *L, LPPassManager &LPM) override {
139     if (skipLoop(L)) {
140       // If we have run LICM on a previous loop but now we are skipping
141       // (because we've hit the opt-bisect limit), we need to clear the
142       // loop alias information.
143       for (auto &LTAS : LICM.getLoopToAliasSetMap())
144         delete LTAS.second;
145       LICM.getLoopToAliasSetMap().clear();
146       return false;
147     }
148 
149     auto *SE = getAnalysisIfAvailable<ScalarEvolutionWrapperPass>();
150     MemorySSA *MSSA = EnableMSSALoopDependency
151                           ? (&getAnalysis<MemorySSAWrapperPass>().getMSSA())
152                           : nullptr;
153     // For the old PM, we can't use OptimizationRemarkEmitter as an analysis
154     // pass.  Function analyses need to be preserved across loop transformations
155     // but ORE cannot be preserved (see comment before the pass definition).
156     OptimizationRemarkEmitter ORE(L->getHeader()->getParent());
157     return LICM.runOnLoop(L,
158                           &getAnalysis<AAResultsWrapperPass>().getAAResults(),
159                           &getAnalysis<LoopInfoWrapperPass>().getLoopInfo(),
160                           &getAnalysis<DominatorTreeWrapperPass>().getDomTree(),
161                           &getAnalysis<TargetLibraryInfoWrapperPass>().getTLI(),
162                           SE ? &SE->getSE() : nullptr, MSSA, &ORE, false);
163   }
164 
165   /// This transformation requires natural loop information & requires that
166   /// loop preheaders be inserted into the CFG...
167   ///
168   void getAnalysisUsage(AnalysisUsage &AU) const override {
169     AU.setPreservesCFG();
170     AU.addRequired<TargetLibraryInfoWrapperPass>();
171     if (EnableMSSALoopDependency)
172       AU.addRequired<MemorySSAWrapperPass>();
173     getLoopAnalysisUsage(AU);
174   }
175 
176   using llvm::Pass::doFinalization;
177 
178   bool doFinalization() override {
179     assert(LICM.getLoopToAliasSetMap().empty() &&
180            "Didn't free loop alias sets");
181     return false;
182   }
183 
184 private:
185   LoopInvariantCodeMotion LICM;
186 
187   /// cloneBasicBlockAnalysis - Simple Analysis hook. Clone alias set info.
188   void cloneBasicBlockAnalysis(BasicBlock *From, BasicBlock *To,
189                                Loop *L) override;
190 
191   /// deleteAnalysisValue - Simple Analysis hook. Delete value V from alias
192   /// set.
193   void deleteAnalysisValue(Value *V, Loop *L) override;
194 
195   /// Simple Analysis hook. Delete loop L from alias set map.
196   void deleteAnalysisLoop(Loop *L) override;
197 };
198 } // namespace
199 
200 PreservedAnalyses LICMPass::run(Loop &L, LoopAnalysisManager &AM,
201                                 LoopStandardAnalysisResults &AR, LPMUpdater &) {
202   const auto &FAM =
203       AM.getResult<FunctionAnalysisManagerLoopProxy>(L, AR).getManager();
204   Function *F = L.getHeader()->getParent();
205 
206   auto *ORE = FAM.getCachedResult<OptimizationRemarkEmitterAnalysis>(*F);
207   // FIXME: This should probably be optional rather than required.
208   if (!ORE)
209     report_fatal_error("LICM: OptimizationRemarkEmitterAnalysis not "
210                        "cached at a higher level");
211 
212   LoopInvariantCodeMotion LICM;
213   if (!LICM.runOnLoop(&L, &AR.AA, &AR.LI, &AR.DT, &AR.TLI, &AR.SE, AR.MSSA, ORE,
214                       true))
215     return PreservedAnalyses::all();
216 
217   auto PA = getLoopPassPreservedAnalyses();
218   PA.preserveSet<CFGAnalyses>();
219   return PA;
220 }
221 
222 char LegacyLICMPass::ID = 0;
223 INITIALIZE_PASS_BEGIN(LegacyLICMPass, "licm", "Loop Invariant Code Motion",
224                       false, false)
225 INITIALIZE_PASS_DEPENDENCY(LoopPass)
226 INITIALIZE_PASS_DEPENDENCY(TargetLibraryInfoWrapperPass)
227 INITIALIZE_PASS_DEPENDENCY(MemorySSAWrapperPass)
228 INITIALIZE_PASS_END(LegacyLICMPass, "licm", "Loop Invariant Code Motion", false,
229                     false)
230 
231 Pass *llvm::createLICMPass() { return new LegacyLICMPass(); }
232 
233 /// Hoist expressions out of the specified loop. Note, alias info for inner
234 /// loop is not preserved so it is not a good idea to run LICM multiple
235 /// times on one loop.
236 /// We should delete AST for inner loops in the new pass manager to avoid
237 /// memory leak.
238 ///
239 bool LoopInvariantCodeMotion::runOnLoop(Loop *L, AliasAnalysis *AA,
240                                         LoopInfo *LI, DominatorTree *DT,
241                                         TargetLibraryInfo *TLI,
242                                         ScalarEvolution *SE, MemorySSA *MSSA,
243                                         OptimizationRemarkEmitter *ORE,
244                                         bool DeleteAST) {
245   bool Changed = false;
246 
247   assert(L->isLCSSAForm(*DT) && "Loop is not in LCSSA form.");
248 
249   AliasSetTracker *CurAST = collectAliasInfoForLoop(L, LI, AA);
250 
251   // Get the preheader block to move instructions into...
252   BasicBlock *Preheader = L->getLoopPreheader();
253 
254   // Compute loop safety information.
255   LoopSafetyInfo SafetyInfo;
256   computeLoopSafetyInfo(&SafetyInfo, L);
257 
258   // We want to visit all of the instructions in this loop... that are not parts
259   // of our subloops (they have already had their invariants hoisted out of
260   // their loop, into this loop, so there is no need to process the BODIES of
261   // the subloops).
262   //
263   // Traverse the body of the loop in depth first order on the dominator tree so
264   // that we are guaranteed to see definitions before we see uses.  This allows
265   // us to sink instructions in one pass, without iteration.  After sinking
266   // instructions, we perform another pass to hoist them out of the loop.
267   //
268   if (L->hasDedicatedExits())
269     Changed |= sinkRegion(DT->getNode(L->getHeader()), AA, LI, DT, TLI, L,
270                           CurAST, &SafetyInfo, ORE);
271   if (Preheader)
272     Changed |= hoistRegion(DT->getNode(L->getHeader()), AA, LI, DT, TLI, L,
273                            CurAST, &SafetyInfo, ORE);
274 
275   // Now that all loop invariants have been removed from the loop, promote any
276   // memory references to scalars that we can.
277   // Don't sink stores from loops without dedicated block exits. Exits
278   // containing indirect branches are not transformed by loop simplify,
279   // make sure we catch that. An additional load may be generated in the
280   // preheader for SSA updater, so also avoid sinking when no preheader
281   // is available.
282   if (!DisablePromotion && Preheader && L->hasDedicatedExits()) {
283     // Figure out the loop exits and their insertion points
284     SmallVector<BasicBlock *, 8> ExitBlocks;
285     L->getUniqueExitBlocks(ExitBlocks);
286 
287     // We can't insert into a catchswitch.
288     bool HasCatchSwitch = llvm::any_of(ExitBlocks, [](BasicBlock *Exit) {
289       return isa<CatchSwitchInst>(Exit->getTerminator());
290     });
291 
292     if (!HasCatchSwitch) {
293       SmallVector<Instruction *, 8> InsertPts;
294       InsertPts.reserve(ExitBlocks.size());
295       for (BasicBlock *ExitBlock : ExitBlocks)
296         InsertPts.push_back(&*ExitBlock->getFirstInsertionPt());
297 
298       PredIteratorCache PIC;
299 
300       bool Promoted = false;
301 
302       // Loop over all of the alias sets in the tracker object.
303       for (AliasSet &AS : *CurAST) {
304         // We can promote this alias set if it has a store, if it is a "Must"
305         // alias set, if the pointer is loop invariant, and if we are not
306         // eliminating any volatile loads or stores.
307         if (AS.isForwardingAliasSet() || !AS.isMod() || !AS.isMustAlias() ||
308             AS.isVolatile() || !L->isLoopInvariant(AS.begin()->getValue()))
309           continue;
310 
311         assert(
312             !AS.empty() &&
313             "Must alias set should have at least one pointer element in it!");
314 
315         SmallSetVector<Value *, 8> PointerMustAliases;
316         for (const auto &ASI : AS)
317           PointerMustAliases.insert(ASI.getValue());
318 
319         Promoted |= promoteLoopAccessesToScalars(PointerMustAliases, ExitBlocks,
320                                                  InsertPts, PIC, LI, DT, TLI, L,
321                                                  CurAST, &SafetyInfo, ORE);
322       }
323 
324       // Once we have promoted values across the loop body we have to
325       // recursively reform LCSSA as any nested loop may now have values defined
326       // within the loop used in the outer loop.
327       // FIXME: This is really heavy handed. It would be a bit better to use an
328       // SSAUpdater strategy during promotion that was LCSSA aware and reformed
329       // it as it went.
330       if (Promoted)
331         formLCSSARecursively(*L, *DT, LI, SE);
332 
333       Changed |= Promoted;
334     }
335   }
336 
337   // Check that neither this loop nor its parent have had LCSSA broken. LICM is
338   // specifically moving instructions across the loop boundary and so it is
339   // especially in need of sanity checking here.
340   assert(L->isLCSSAForm(*DT) && "Loop not left in LCSSA form after LICM!");
341   assert((!L->getParentLoop() || L->getParentLoop()->isLCSSAForm(*DT)) &&
342          "Parent loop not left in LCSSA form after LICM!");
343 
344   // If this loop is nested inside of another one, save the alias information
345   // for when we process the outer loop.
346   if (L->getParentLoop() && !DeleteAST)
347     LoopToAliasSetMap[L] = CurAST;
348   else
349     delete CurAST;
350 
351   if (Changed && SE)
352     SE->forgetLoopDispositions(L);
353   return Changed;
354 }
355 
356 /// Walk the specified region of the CFG (defined by all blocks dominated by
357 /// the specified block, and that are in the current loop) in reverse depth
358 /// first order w.r.t the DominatorTree.  This allows us to visit uses before
359 /// definitions, allowing us to sink a loop body in one pass without iteration.
360 ///
361 bool llvm::sinkRegion(DomTreeNode *N, AliasAnalysis *AA, LoopInfo *LI,
362                       DominatorTree *DT, TargetLibraryInfo *TLI, Loop *CurLoop,
363                       AliasSetTracker *CurAST, LoopSafetyInfo *SafetyInfo,
364                       OptimizationRemarkEmitter *ORE) {
365 
366   // Verify inputs.
367   assert(N != nullptr && AA != nullptr && LI != nullptr && DT != nullptr &&
368          CurLoop != nullptr && CurAST != nullptr && SafetyInfo != nullptr &&
369          "Unexpected input to sinkRegion");
370 
371   // We want to visit children before parents. We will enque all the parents
372   // before their children in the worklist and process the worklist in reverse
373   // order.
374   SmallVector<DomTreeNode *, 16> Worklist = collectChildrenInLoop(N, CurLoop);
375 
376   bool Changed = false;
377   for (DomTreeNode *DTN : reverse(Worklist)) {
378     BasicBlock *BB = DTN->getBlock();
379     // Only need to process the contents of this block if it is not part of a
380     // subloop (which would already have been processed).
381     if (inSubLoop(BB, CurLoop, LI))
382       continue;
383 
384     for (BasicBlock::iterator II = BB->end(); II != BB->begin();) {
385       Instruction &I = *--II;
386 
387       // If the instruction is dead, we would try to sink it because it isn't
388       // used in the loop, instead, just delete it.
389       if (isInstructionTriviallyDead(&I, TLI)) {
390         DEBUG(dbgs() << "LICM deleting dead inst: " << I << '\n');
391         ++II;
392         CurAST->deleteValue(&I);
393         I.eraseFromParent();
394         Changed = true;
395         continue;
396       }
397 
398       // Check to see if we can sink this instruction to the exit blocks
399       // of the loop.  We can do this if the all users of the instruction are
400       // outside of the loop.  In this case, it doesn't even matter if the
401       // operands of the instruction are loop invariant.
402       //
403       if (isNotUsedInLoop(I, CurLoop, SafetyInfo) &&
404           canSinkOrHoistInst(I, AA, DT, CurLoop, CurAST, SafetyInfo, ORE)) {
405         if (sink(I, LI, DT, CurLoop, SafetyInfo, ORE)) {
406           ++II;
407           CurAST->deleteValue(&I);
408           I.eraseFromParent();
409           Changed = true;
410         }
411       }
412     }
413   }
414   return Changed;
415 }
416 
417 /// Walk the specified region of the CFG (defined by all blocks dominated by
418 /// the specified block, and that are in the current loop) in depth first
419 /// order w.r.t the DominatorTree.  This allows us to visit definitions before
420 /// uses, allowing us to hoist a loop body in one pass without iteration.
421 ///
422 bool llvm::hoistRegion(DomTreeNode *N, AliasAnalysis *AA, LoopInfo *LI,
423                        DominatorTree *DT, TargetLibraryInfo *TLI, Loop *CurLoop,
424                        AliasSetTracker *CurAST, LoopSafetyInfo *SafetyInfo,
425                        OptimizationRemarkEmitter *ORE) {
426   // Verify inputs.
427   assert(N != nullptr && AA != nullptr && LI != nullptr && DT != nullptr &&
428          CurLoop != nullptr && CurAST != nullptr && SafetyInfo != nullptr &&
429          "Unexpected input to hoistRegion");
430 
431   // We want to visit parents before children. We will enque all the parents
432   // before their children in the worklist and process the worklist in order.
433   SmallVector<DomTreeNode *, 16> Worklist = collectChildrenInLoop(N, CurLoop);
434 
435   bool Changed = false;
436   for (DomTreeNode *DTN : Worklist) {
437     BasicBlock *BB = DTN->getBlock();
438     // Only need to process the contents of this block if it is not part of a
439     // subloop (which would already have been processed).
440     if (!inSubLoop(BB, CurLoop, LI))
441       for (BasicBlock::iterator II = BB->begin(), E = BB->end(); II != E;) {
442         Instruction &I = *II++;
443         // Try constant folding this instruction.  If all the operands are
444         // constants, it is technically hoistable, but it would be better to
445         // just fold it.
446         if (Constant *C = ConstantFoldInstruction(
447                 &I, I.getModule()->getDataLayout(), TLI)) {
448           DEBUG(dbgs() << "LICM folding inst: " << I << "  --> " << *C << '\n');
449           CurAST->copyValue(&I, C);
450           I.replaceAllUsesWith(C);
451           if (isInstructionTriviallyDead(&I, TLI)) {
452             CurAST->deleteValue(&I);
453             I.eraseFromParent();
454           }
455           Changed = true;
456           continue;
457         }
458 
459         // Attempt to remove floating point division out of the loop by
460         // converting it to a reciprocal multiplication.
461         if (I.getOpcode() == Instruction::FDiv &&
462             CurLoop->isLoopInvariant(I.getOperand(1)) &&
463             I.hasAllowReciprocal()) {
464           auto Divisor = I.getOperand(1);
465           auto One = llvm::ConstantFP::get(Divisor->getType(), 1.0);
466           auto ReciprocalDivisor = BinaryOperator::CreateFDiv(One, Divisor);
467           ReciprocalDivisor->setFastMathFlags(I.getFastMathFlags());
468           ReciprocalDivisor->insertBefore(&I);
469 
470           auto Product =
471               BinaryOperator::CreateFMul(I.getOperand(0), ReciprocalDivisor);
472           Product->setFastMathFlags(I.getFastMathFlags());
473           Product->insertAfter(&I);
474           I.replaceAllUsesWith(Product);
475           I.eraseFromParent();
476 
477           hoist(*ReciprocalDivisor, DT, CurLoop, SafetyInfo, ORE);
478           Changed = true;
479           continue;
480         }
481 
482         // Try hoisting the instruction out to the preheader.  We can only do
483         // this if all of the operands of the instruction are loop invariant and
484         // if it is safe to hoist the instruction.
485         //
486         if (CurLoop->hasLoopInvariantOperands(&I) &&
487             canSinkOrHoistInst(I, AA, DT, CurLoop, CurAST, SafetyInfo, ORE) &&
488             isSafeToExecuteUnconditionally(
489                 I, DT, CurLoop, SafetyInfo, ORE,
490                 CurLoop->getLoopPreheader()->getTerminator()))
491           Changed |= hoist(I, DT, CurLoop, SafetyInfo, ORE);
492       }
493   }
494 
495   return Changed;
496 }
497 
498 /// Computes loop safety information, checks loop body & header
499 /// for the possibility of may throw exception.
500 ///
501 void llvm::computeLoopSafetyInfo(LoopSafetyInfo *SafetyInfo, Loop *CurLoop) {
502   assert(CurLoop != nullptr && "CurLoop cant be null");
503   BasicBlock *Header = CurLoop->getHeader();
504   // Setting default safety values.
505   SafetyInfo->MayThrow = false;
506   SafetyInfo->HeaderMayThrow = false;
507   // Iterate over header and compute safety info.
508   for (BasicBlock::iterator I = Header->begin(), E = Header->end();
509        (I != E) && !SafetyInfo->HeaderMayThrow; ++I)
510     SafetyInfo->HeaderMayThrow |=
511         !isGuaranteedToTransferExecutionToSuccessor(&*I);
512 
513   SafetyInfo->MayThrow = SafetyInfo->HeaderMayThrow;
514   // Iterate over loop instructions and compute safety info.
515   // Skip header as it has been computed and stored in HeaderMayThrow.
516   // The first block in loopinfo.Blocks is guaranteed to be the header.
517   assert(Header == *CurLoop->getBlocks().begin() &&
518          "First block must be header");
519   for (Loop::block_iterator BB = std::next(CurLoop->block_begin()),
520                             BBE = CurLoop->block_end();
521        (BB != BBE) && !SafetyInfo->MayThrow; ++BB)
522     for (BasicBlock::iterator I = (*BB)->begin(), E = (*BB)->end();
523          (I != E) && !SafetyInfo->MayThrow; ++I)
524       SafetyInfo->MayThrow |= !isGuaranteedToTransferExecutionToSuccessor(&*I);
525 
526   // Compute funclet colors if we might sink/hoist in a function with a funclet
527   // personality routine.
528   Function *Fn = CurLoop->getHeader()->getParent();
529   if (Fn->hasPersonalityFn())
530     if (Constant *PersonalityFn = Fn->getPersonalityFn())
531       if (isFuncletEHPersonality(classifyEHPersonality(PersonalityFn)))
532         SafetyInfo->BlockColors = colorEHFunclets(*Fn);
533 }
534 
535 // Return true if LI is invariant within scope of the loop. LI is invariant if
536 // CurLoop is dominated by an invariant.start representing the same memory
537 // location and size as the memory location LI loads from, and also the
538 // invariant.start has no uses.
539 static bool isLoadInvariantInLoop(LoadInst *LI, DominatorTree *DT,
540                                   Loop *CurLoop) {
541   Value *Addr = LI->getOperand(0);
542   const DataLayout &DL = LI->getModule()->getDataLayout();
543   const uint32_t LocSizeInBits = DL.getTypeSizeInBits(
544       cast<PointerType>(Addr->getType())->getElementType());
545 
546   // if the type is i8 addrspace(x)*, we know this is the type of
547   // llvm.invariant.start operand
548   auto *PtrInt8Ty = PointerType::get(Type::getInt8Ty(LI->getContext()),
549                                      LI->getPointerAddressSpace());
550   unsigned BitcastsVisited = 0;
551   // Look through bitcasts until we reach the i8* type (this is invariant.start
552   // operand type).
553   while (Addr->getType() != PtrInt8Ty) {
554     auto *BC = dyn_cast<BitCastInst>(Addr);
555     // Avoid traversing high number of bitcast uses.
556     if (++BitcastsVisited > MaxNumUsesTraversed || !BC)
557       return false;
558     Addr = BC->getOperand(0);
559   }
560 
561   unsigned UsesVisited = 0;
562   // Traverse all uses of the load operand value, to see if invariant.start is
563   // one of the uses, and whether it dominates the load instruction.
564   for (auto *U : Addr->users()) {
565     // Avoid traversing for Load operand with high number of users.
566     if (++UsesVisited > MaxNumUsesTraversed)
567       return false;
568     IntrinsicInst *II = dyn_cast<IntrinsicInst>(U);
569     // If there are escaping uses of invariant.start instruction, the load maybe
570     // non-invariant.
571     if (!II || II->getIntrinsicID() != Intrinsic::invariant_start ||
572         !II->use_empty())
573       continue;
574     unsigned InvariantSizeInBits =
575         cast<ConstantInt>(II->getArgOperand(0))->getSExtValue() * 8;
576     // Confirm the invariant.start location size contains the load operand size
577     // in bits. Also, the invariant.start should dominate the load, and we
578     // should not hoist the load out of a loop that contains this dominating
579     // invariant.start.
580     if (LocSizeInBits <= InvariantSizeInBits &&
581         DT->properlyDominates(II->getParent(), CurLoop->getHeader()))
582       return true;
583   }
584 
585   return false;
586 }
587 
588 bool llvm::canSinkOrHoistInst(Instruction &I, AAResults *AA, DominatorTree *DT,
589                               Loop *CurLoop, AliasSetTracker *CurAST,
590                               LoopSafetyInfo *SafetyInfo,
591                               OptimizationRemarkEmitter *ORE) {
592   // SafetyInfo is nullptr if we are checking for sinking from preheader to
593   // loop body.
594   const bool SinkingToLoopBody = !SafetyInfo;
595   // Loads have extra constraints we have to verify before we can hoist them.
596   if (LoadInst *LI = dyn_cast<LoadInst>(&I)) {
597     if (!LI->isUnordered())
598       return false; // Don't sink/hoist volatile or ordered atomic loads!
599 
600     // Loads from constant memory are always safe to move, even if they end up
601     // in the same alias set as something that ends up being modified.
602     if (AA->pointsToConstantMemory(LI->getOperand(0)))
603       return true;
604     if (LI->getMetadata(LLVMContext::MD_invariant_load))
605       return true;
606 
607     if (LI->isAtomic() && SinkingToLoopBody)
608       return false; // Don't sink unordered atomic loads to loop body.
609 
610     // This checks for an invariant.start dominating the load.
611     if (isLoadInvariantInLoop(LI, DT, CurLoop))
612       return true;
613 
614     // Don't hoist loads which have may-aliased stores in loop.
615     uint64_t Size = 0;
616     if (LI->getType()->isSized())
617       Size = I.getModule()->getDataLayout().getTypeStoreSize(LI->getType());
618 
619     AAMDNodes AAInfo;
620     LI->getAAMetadata(AAInfo);
621 
622     bool Invalidated =
623         pointerInvalidatedByLoop(LI->getOperand(0), Size, AAInfo, CurAST);
624     // Check loop-invariant address because this may also be a sinkable load
625     // whose address is not necessarily loop-invariant.
626     if (ORE && Invalidated && CurLoop->isLoopInvariant(LI->getPointerOperand()))
627       ORE->emit([&]() {
628         return OptimizationRemarkMissed(
629                    DEBUG_TYPE, "LoadWithLoopInvariantAddressInvalidated", LI)
630                << "failed to move load with loop-invariant address "
631                   "because the loop may invalidate its value";
632       });
633 
634     return !Invalidated;
635   } else if (CallInst *CI = dyn_cast<CallInst>(&I)) {
636     // Don't sink or hoist dbg info; it's legal, but not useful.
637     if (isa<DbgInfoIntrinsic>(I))
638       return false;
639 
640     // Don't sink calls which can throw.
641     if (CI->mayThrow())
642       return false;
643 
644     // Handle simple cases by querying alias analysis.
645     FunctionModRefBehavior Behavior = AA->getModRefBehavior(CI);
646     if (Behavior == FMRB_DoesNotAccessMemory)
647       return true;
648     if (AliasAnalysis::onlyReadsMemory(Behavior)) {
649       // A readonly argmemonly function only reads from memory pointed to by
650       // it's arguments with arbitrary offsets.  If we can prove there are no
651       // writes to this memory in the loop, we can hoist or sink.
652       if (AliasAnalysis::onlyAccessesArgPointees(Behavior)) {
653         for (Value *Op : CI->arg_operands())
654           if (Op->getType()->isPointerTy() &&
655               pointerInvalidatedByLoop(Op, MemoryLocation::UnknownSize,
656                                        AAMDNodes(), CurAST))
657             return false;
658         return true;
659       }
660       // If this call only reads from memory and there are no writes to memory
661       // in the loop, we can hoist or sink the call as appropriate.
662       bool FoundMod = false;
663       for (AliasSet &AS : *CurAST) {
664         if (!AS.isForwardingAliasSet() && AS.isMod()) {
665           FoundMod = true;
666           break;
667         }
668       }
669       if (!FoundMod)
670         return true;
671     }
672 
673     // FIXME: This should use mod/ref information to see if we can hoist or
674     // sink the call.
675 
676     return false;
677   }
678 
679   // Only these instructions are hoistable/sinkable.
680   if (!isa<BinaryOperator>(I) && !isa<CastInst>(I) && !isa<SelectInst>(I) &&
681       !isa<GetElementPtrInst>(I) && !isa<CmpInst>(I) &&
682       !isa<InsertElementInst>(I) && !isa<ExtractElementInst>(I) &&
683       !isa<ShuffleVectorInst>(I) && !isa<ExtractValueInst>(I) &&
684       !isa<InsertValueInst>(I))
685     return false;
686 
687   // If we are checking for sinking from preheader to loop body it will be
688   // always safe as there is no speculative execution.
689   if (SinkingToLoopBody)
690     return true;
691 
692   // TODO: Plumb the context instruction through to make hoisting and sinking
693   // more powerful. Hoisting of loads already works due to the special casing
694   // above.
695   return isSafeToExecuteUnconditionally(I, DT, CurLoop, SafetyInfo, nullptr);
696 }
697 
698 /// Returns true if a PHINode is a trivially replaceable with an
699 /// Instruction.
700 /// This is true when all incoming values are that instruction.
701 /// This pattern occurs most often with LCSSA PHI nodes.
702 ///
703 static bool isTriviallyReplacablePHI(const PHINode &PN, const Instruction &I) {
704   for (const Value *IncValue : PN.incoming_values())
705     if (IncValue != &I)
706       return false;
707 
708   return true;
709 }
710 
711 /// Return true if the only users of this instruction are outside of
712 /// the loop. If this is true, we can sink the instruction to the exit
713 /// blocks of the loop.
714 ///
715 static bool isNotUsedInLoop(const Instruction &I, const Loop *CurLoop,
716                             const LoopSafetyInfo *SafetyInfo) {
717   const auto &BlockColors = SafetyInfo->BlockColors;
718   for (const User *U : I.users()) {
719     const Instruction *UI = cast<Instruction>(U);
720     if (const PHINode *PN = dyn_cast<PHINode>(UI)) {
721       const BasicBlock *BB = PN->getParent();
722       // We cannot sink uses in catchswitches.
723       if (isa<CatchSwitchInst>(BB->getTerminator()))
724         return false;
725 
726       // We need to sink a callsite to a unique funclet.  Avoid sinking if the
727       // phi use is too muddled.
728       if (isa<CallInst>(I))
729         if (!BlockColors.empty() &&
730             BlockColors.find(const_cast<BasicBlock *>(BB))->second.size() != 1)
731           return false;
732     }
733 
734     if (CurLoop->contains(UI))
735       return false;
736   }
737   return true;
738 }
739 
740 static Instruction *
741 CloneInstructionInExitBlock(Instruction &I, BasicBlock &ExitBlock, PHINode &PN,
742                             const LoopInfo *LI,
743                             const LoopSafetyInfo *SafetyInfo) {
744   Instruction *New;
745   if (auto *CI = dyn_cast<CallInst>(&I)) {
746     const auto &BlockColors = SafetyInfo->BlockColors;
747 
748     // Sinking call-sites need to be handled differently from other
749     // instructions.  The cloned call-site needs a funclet bundle operand
750     // appropriate for it's location in the CFG.
751     SmallVector<OperandBundleDef, 1> OpBundles;
752     for (unsigned BundleIdx = 0, BundleEnd = CI->getNumOperandBundles();
753          BundleIdx != BundleEnd; ++BundleIdx) {
754       OperandBundleUse Bundle = CI->getOperandBundleAt(BundleIdx);
755       if (Bundle.getTagID() == LLVMContext::OB_funclet)
756         continue;
757 
758       OpBundles.emplace_back(Bundle);
759     }
760 
761     if (!BlockColors.empty()) {
762       const ColorVector &CV = BlockColors.find(&ExitBlock)->second;
763       assert(CV.size() == 1 && "non-unique color for exit block!");
764       BasicBlock *BBColor = CV.front();
765       Instruction *EHPad = BBColor->getFirstNonPHI();
766       if (EHPad->isEHPad())
767         OpBundles.emplace_back("funclet", EHPad);
768     }
769 
770     New = CallInst::Create(CI, OpBundles);
771   } else {
772     New = I.clone();
773   }
774 
775   ExitBlock.getInstList().insert(ExitBlock.getFirstInsertionPt(), New);
776   if (!I.getName().empty())
777     New->setName(I.getName() + ".le");
778 
779   // Build LCSSA PHI nodes for any in-loop operands. Note that this is
780   // particularly cheap because we can rip off the PHI node that we're
781   // replacing for the number and blocks of the predecessors.
782   // OPT: If this shows up in a profile, we can instead finish sinking all
783   // invariant instructions, and then walk their operands to re-establish
784   // LCSSA. That will eliminate creating PHI nodes just to nuke them when
785   // sinking bottom-up.
786   for (User::op_iterator OI = New->op_begin(), OE = New->op_end(); OI != OE;
787        ++OI)
788     if (Instruction *OInst = dyn_cast<Instruction>(*OI))
789       if (Loop *OLoop = LI->getLoopFor(OInst->getParent()))
790         if (!OLoop->contains(&PN)) {
791           PHINode *OpPN =
792               PHINode::Create(OInst->getType(), PN.getNumIncomingValues(),
793                               OInst->getName() + ".lcssa", &ExitBlock.front());
794           for (unsigned i = 0, e = PN.getNumIncomingValues(); i != e; ++i)
795             OpPN->addIncoming(OInst, PN.getIncomingBlock(i));
796           *OI = OpPN;
797         }
798   return New;
799 }
800 
801 static Instruction *sinkThroughTriviallyReplacablePHI(
802     PHINode *TPN, Instruction *I, LoopInfo *LI,
803     SmallDenseMap<BasicBlock *, Instruction *, 32> &SunkCopies,
804     const LoopSafetyInfo *SafetyInfo, const Loop *CurLoop) {
805   assert(isTriviallyReplacablePHI(*TPN, *I) &&
806          "Expect only trivially replacalbe PHI");
807   BasicBlock *ExitBlock = TPN->getParent();
808   Instruction *New;
809   auto It = SunkCopies.find(ExitBlock);
810   if (It != SunkCopies.end())
811     New = It->second;
812   else
813     New = SunkCopies[ExitBlock] =
814         CloneInstructionInExitBlock(*I, *ExitBlock, *TPN, LI, SafetyInfo);
815   return New;
816 }
817 
818 static bool canSplitPredecessors(PHINode *PN) {
819   BasicBlock *BB = PN->getParent();
820   if (!BB->canSplitPredecessors())
821     return false;
822   for (pred_iterator PI = pred_begin(BB), E = pred_end(BB); PI != E; ++PI) {
823     BasicBlock *BBPred = *PI;
824     if (isa<IndirectBrInst>(BBPred->getTerminator()))
825       return false;
826   }
827   return true;
828 }
829 
830 static void splitPredecessorsOfLoopExit(PHINode *PN, DominatorTree *DT,
831                                         LoopInfo *LI, const Loop *CurLoop) {
832 #ifndef NDEBUG
833   SmallVector<BasicBlock *, 32> ExitBlocks;
834   CurLoop->getUniqueExitBlocks(ExitBlocks);
835   SmallPtrSet<BasicBlock *, 32> ExitBlockSet(ExitBlocks.begin(),
836                                              ExitBlocks.end());
837 #endif
838   BasicBlock *ExitBB = PN->getParent();
839   assert(ExitBlockSet.count(ExitBB) && "Expect the PHI is in an exit block.");
840 
841   // Split predecessors of the loop exit to make instructions in the loop are
842   // exposed to exit blocks through trivially replacable PHIs while keeping the
843   // loop in the canonical form where each predecessor of each exit block should
844   // be contained within the loop. For example, this will convert the loop below
845   // from
846   //
847   // LB1:
848   //   %v1 =
849   //   br %LE, %LB2
850   // LB2:
851   //   %v2 =
852   //   br %LE, %LB1
853   // LE:
854   //   %p = phi [%v1, %LB1], [%v2, %LB2] <-- non-trivially replacable
855   //
856   // to
857   //
858   // LB1:
859   //   %v1 =
860   //   br %LE.split, %LB2
861   // LB2:
862   //   %v2 =
863   //   br %LE.split2, %LB1
864   // LE.split:
865   //   %p1 = phi [%v1, %LB1]  <-- trivially replacable
866   //   br %LE
867   // LE.split2:
868   //   %p2 = phi [%v2, %LB2]  <-- trivially replacable
869   //   br %LE
870   // LE:
871   //   %p = phi [%p1, %LE.split], [%p2, %LE.split2]
872   //
873   SmallSetVector<BasicBlock *, 8> PredBBs(pred_begin(ExitBB), pred_end(ExitBB));
874   while (!PredBBs.empty()) {
875     BasicBlock *PredBB = *PredBBs.begin();
876     assert(CurLoop->contains(PredBB) &&
877            "Expect all predecessors are in the loop");
878     if (PN->getBasicBlockIndex(PredBB) >= 0)
879       SplitBlockPredecessors(ExitBB, PredBB, ".split.loop.exit", DT, LI, true);
880     PredBBs.remove(PredBB);
881   }
882 }
883 
884 /// When an instruction is found to only be used outside of the loop, this
885 /// function moves it to the exit blocks and patches up SSA form as needed.
886 /// This method is guaranteed to remove the original instruction from its
887 /// position, and may either delete it or move it to outside of the loop.
888 ///
889 static bool sink(Instruction &I, LoopInfo *LI, DominatorTree *DT,
890                  const Loop *CurLoop, const LoopSafetyInfo *SafetyInfo,
891                  OptimizationRemarkEmitter *ORE) {
892   DEBUG(dbgs() << "LICM sinking instruction: " << I << "\n");
893   ORE->emit([&]() {
894     return OptimizationRemark(DEBUG_TYPE, "InstSunk", &I)
895            << "sinking " << ore::NV("Inst", &I);
896   });
897   bool Changed = false;
898   if (isa<LoadInst>(I))
899     ++NumMovedLoads;
900   else if (isa<CallInst>(I))
901     ++NumMovedCalls;
902   ++NumSunk;
903   Changed = true;
904 
905   // Iterate over users to be ready for actual sinking. Replace users via
906   // unrechable blocks with undef and make all user PHIs trivially replcable.
907   SmallPtrSet<Instruction *, 8> VisitedUsers;
908   for (Value::user_iterator UI = I.user_begin(), UE = I.user_end(); UI != UE;) {
909     auto *User = cast<Instruction>(*UI);
910     Use &U = UI.getUse();
911     ++UI;
912 
913     if (VisitedUsers.count(User))
914       continue;
915 
916     if (!DT->isReachableFromEntry(User->getParent())) {
917       U = UndefValue::get(I.getType());
918       continue;
919     }
920 
921     // The user must be a PHI node.
922     PHINode *PN = cast<PHINode>(User);
923 
924     // Surprisingly, instructions can be used outside of loops without any
925     // exits.  This can only happen in PHI nodes if the incoming block is
926     // unreachable.
927     BasicBlock *BB = PN->getIncomingBlock(U);
928     if (!DT->isReachableFromEntry(BB)) {
929       U = UndefValue::get(I.getType());
930       continue;
931     }
932 
933     VisitedUsers.insert(PN);
934     if (isTriviallyReplacablePHI(*PN, I))
935       continue;
936 
937     if (!canSplitPredecessors(PN))
938       return false;
939 
940     // Split predecessors of the PHI so that we can make users trivially
941     // replacable.
942     splitPredecessorsOfLoopExit(PN, DT, LI, CurLoop);
943 
944     // Should rebuild the iterators, as they may be invalidated by
945     // splitPredecessorsOfLoopExit().
946     UI = I.user_begin();
947     UE = I.user_end();
948   }
949 
950 #ifndef NDEBUG
951   SmallVector<BasicBlock *, 32> ExitBlocks;
952   CurLoop->getUniqueExitBlocks(ExitBlocks);
953   SmallPtrSet<BasicBlock *, 32> ExitBlockSet(ExitBlocks.begin(),
954                                              ExitBlocks.end());
955 #endif
956 
957   // Clones of this instruction. Don't create more than one per exit block!
958   SmallDenseMap<BasicBlock *, Instruction *, 32> SunkCopies;
959 
960   // If this instruction is only used outside of the loop, then all users are
961   // PHI nodes in exit blocks due to LCSSA form. Just RAUW them with clones of
962   // the instruction.
963   while (!I.use_empty()) {
964     Value::user_iterator UI = I.user_begin();
965     PHINode *PN = cast<PHINode>(*UI);
966     assert(ExitBlockSet.count(PN->getParent()) &&
967            "The LCSSA PHI is not in an exit block!");
968     // The PHI must be trivially replacable.
969     Instruction *New = sinkThroughTriviallyReplacablePHI(PN, &I, LI, SunkCopies,
970                                                          SafetyInfo, CurLoop);
971     PN->replaceAllUsesWith(New);
972     PN->eraseFromParent();
973   }
974   return Changed;
975 }
976 
977 /// When an instruction is found to only use loop invariant operands that
978 /// is safe to hoist, this instruction is called to do the dirty work.
979 ///
980 static bool hoist(Instruction &I, const DominatorTree *DT, const Loop *CurLoop,
981                   const LoopSafetyInfo *SafetyInfo,
982                   OptimizationRemarkEmitter *ORE) {
983   auto *Preheader = CurLoop->getLoopPreheader();
984   DEBUG(dbgs() << "LICM hoisting to " << Preheader->getName() << ": " << I
985                << "\n");
986   ORE->emit([&]() {
987     return OptimizationRemark(DEBUG_TYPE, "Hoisted", &I) << "hoisting "
988                                                          << ore::NV("Inst", &I);
989   });
990 
991   // Metadata can be dependent on conditions we are hoisting above.
992   // Conservatively strip all metadata on the instruction unless we were
993   // guaranteed to execute I if we entered the loop, in which case the metadata
994   // is valid in the loop preheader.
995   if (I.hasMetadataOtherThanDebugLoc() &&
996       // The check on hasMetadataOtherThanDebugLoc is to prevent us from burning
997       // time in isGuaranteedToExecute if we don't actually have anything to
998       // drop.  It is a compile time optimization, not required for correctness.
999       !isGuaranteedToExecute(I, DT, CurLoop, SafetyInfo))
1000     I.dropUnknownNonDebugMetadata();
1001 
1002   // Move the new node to the Preheader, before its terminator.
1003   I.moveBefore(Preheader->getTerminator());
1004 
1005   // Do not retain debug locations when we are moving instructions to different
1006   // basic blocks, because we want to avoid jumpy line tables. Calls, however,
1007   // need to retain their debug locs because they may be inlined.
1008   // FIXME: How do we retain source locations without causing poor debugging
1009   // behavior?
1010   if (!isa<CallInst>(I))
1011     I.setDebugLoc(DebugLoc());
1012 
1013   if (isa<LoadInst>(I))
1014     ++NumMovedLoads;
1015   else if (isa<CallInst>(I))
1016     ++NumMovedCalls;
1017   ++NumHoisted;
1018   return true;
1019 }
1020 
1021 /// Only sink or hoist an instruction if it is not a trapping instruction,
1022 /// or if the instruction is known not to trap when moved to the preheader.
1023 /// or if it is a trapping instruction and is guaranteed to execute.
1024 static bool isSafeToExecuteUnconditionally(Instruction &Inst,
1025                                            const DominatorTree *DT,
1026                                            const Loop *CurLoop,
1027                                            const LoopSafetyInfo *SafetyInfo,
1028                                            OptimizationRemarkEmitter *ORE,
1029                                            const Instruction *CtxI) {
1030   if (isSafeToSpeculativelyExecute(&Inst, CtxI, DT))
1031     return true;
1032 
1033   bool GuaranteedToExecute =
1034       isGuaranteedToExecute(Inst, DT, CurLoop, SafetyInfo);
1035 
1036   if (!GuaranteedToExecute) {
1037     auto *LI = dyn_cast<LoadInst>(&Inst);
1038     if (LI && CurLoop->isLoopInvariant(LI->getPointerOperand()))
1039       ORE->emit([&]() {
1040         return OptimizationRemarkMissed(
1041                    DEBUG_TYPE, "LoadWithLoopInvariantAddressCondExecuted", LI)
1042                << "failed to hoist load with loop-invariant address "
1043                   "because load is conditionally executed";
1044       });
1045   }
1046 
1047   return GuaranteedToExecute;
1048 }
1049 
1050 namespace {
1051 class LoopPromoter : public LoadAndStorePromoter {
1052   Value *SomePtr; // Designated pointer to store to.
1053   const SmallSetVector<Value *, 8> &PointerMustAliases;
1054   SmallVectorImpl<BasicBlock *> &LoopExitBlocks;
1055   SmallVectorImpl<Instruction *> &LoopInsertPts;
1056   PredIteratorCache &PredCache;
1057   AliasSetTracker &AST;
1058   LoopInfo &LI;
1059   DebugLoc DL;
1060   int Alignment;
1061   bool UnorderedAtomic;
1062   AAMDNodes AATags;
1063 
1064   Value *maybeInsertLCSSAPHI(Value *V, BasicBlock *BB) const {
1065     if (Instruction *I = dyn_cast<Instruction>(V))
1066       if (Loop *L = LI.getLoopFor(I->getParent()))
1067         if (!L->contains(BB)) {
1068           // We need to create an LCSSA PHI node for the incoming value and
1069           // store that.
1070           PHINode *PN = PHINode::Create(I->getType(), PredCache.size(BB),
1071                                         I->getName() + ".lcssa", &BB->front());
1072           for (BasicBlock *Pred : PredCache.get(BB))
1073             PN->addIncoming(I, Pred);
1074           return PN;
1075         }
1076     return V;
1077   }
1078 
1079 public:
1080   LoopPromoter(Value *SP, ArrayRef<const Instruction *> Insts, SSAUpdater &S,
1081                const SmallSetVector<Value *, 8> &PMA,
1082                SmallVectorImpl<BasicBlock *> &LEB,
1083                SmallVectorImpl<Instruction *> &LIP, PredIteratorCache &PIC,
1084                AliasSetTracker &ast, LoopInfo &li, DebugLoc dl, int alignment,
1085                bool UnorderedAtomic, const AAMDNodes &AATags)
1086       : LoadAndStorePromoter(Insts, S), SomePtr(SP), PointerMustAliases(PMA),
1087         LoopExitBlocks(LEB), LoopInsertPts(LIP), PredCache(PIC), AST(ast),
1088         LI(li), DL(std::move(dl)), Alignment(alignment),
1089         UnorderedAtomic(UnorderedAtomic), AATags(AATags) {}
1090 
1091   bool isInstInList(Instruction *I,
1092                     const SmallVectorImpl<Instruction *> &) const override {
1093     Value *Ptr;
1094     if (LoadInst *LI = dyn_cast<LoadInst>(I))
1095       Ptr = LI->getOperand(0);
1096     else
1097       Ptr = cast<StoreInst>(I)->getPointerOperand();
1098     return PointerMustAliases.count(Ptr);
1099   }
1100 
1101   void doExtraRewritesBeforeFinalDeletion() const override {
1102     // Insert stores after in the loop exit blocks.  Each exit block gets a
1103     // store of the live-out values that feed them.  Since we've already told
1104     // the SSA updater about the defs in the loop and the preheader
1105     // definition, it is all set and we can start using it.
1106     for (unsigned i = 0, e = LoopExitBlocks.size(); i != e; ++i) {
1107       BasicBlock *ExitBlock = LoopExitBlocks[i];
1108       Value *LiveInValue = SSA.GetValueInMiddleOfBlock(ExitBlock);
1109       LiveInValue = maybeInsertLCSSAPHI(LiveInValue, ExitBlock);
1110       Value *Ptr = maybeInsertLCSSAPHI(SomePtr, ExitBlock);
1111       Instruction *InsertPos = LoopInsertPts[i];
1112       StoreInst *NewSI = new StoreInst(LiveInValue, Ptr, InsertPos);
1113       if (UnorderedAtomic)
1114         NewSI->setOrdering(AtomicOrdering::Unordered);
1115       NewSI->setAlignment(Alignment);
1116       NewSI->setDebugLoc(DL);
1117       if (AATags)
1118         NewSI->setAAMetadata(AATags);
1119     }
1120   }
1121 
1122   void replaceLoadWithValue(LoadInst *LI, Value *V) const override {
1123     // Update alias analysis.
1124     AST.copyValue(LI, V);
1125   }
1126   void instructionDeleted(Instruction *I) const override { AST.deleteValue(I); }
1127 };
1128 
1129 
1130 /// Return true iff we can prove that a caller of this function can not inspect
1131 /// the contents of the provided object in a well defined program.
1132 bool isKnownNonEscaping(Value *Object, const TargetLibraryInfo *TLI) {
1133   if (isa<AllocaInst>(Object))
1134     // Since the alloca goes out of scope, we know the caller can't retain a
1135     // reference to it and be well defined.  Thus, we don't need to check for
1136     // capture.
1137     return true;
1138 
1139   // For all other objects we need to know that the caller can't possibly
1140   // have gotten a reference to the object.  There are two components of
1141   // that:
1142   //   1) Object can't be escaped by this function.  This is what
1143   //      PointerMayBeCaptured checks.
1144   //   2) Object can't have been captured at definition site.  For this, we
1145   //      need to know the return value is noalias.  At the moment, we use a
1146   //      weaker condition and handle only AllocLikeFunctions (which are
1147   //      known to be noalias).  TODO
1148   return isAllocLikeFn(Object, TLI) &&
1149     !PointerMayBeCaptured(Object, true, true);
1150 }
1151 
1152 } // namespace
1153 
1154 /// Try to promote memory values to scalars by sinking stores out of the
1155 /// loop and moving loads to before the loop.  We do this by looping over
1156 /// the stores in the loop, looking for stores to Must pointers which are
1157 /// loop invariant.
1158 ///
1159 bool llvm::promoteLoopAccessesToScalars(
1160     const SmallSetVector<Value *, 8> &PointerMustAliases,
1161     SmallVectorImpl<BasicBlock *> &ExitBlocks,
1162     SmallVectorImpl<Instruction *> &InsertPts, PredIteratorCache &PIC,
1163     LoopInfo *LI, DominatorTree *DT, const TargetLibraryInfo *TLI,
1164     Loop *CurLoop, AliasSetTracker *CurAST, LoopSafetyInfo *SafetyInfo,
1165     OptimizationRemarkEmitter *ORE) {
1166   // Verify inputs.
1167   assert(LI != nullptr && DT != nullptr && CurLoop != nullptr &&
1168          CurAST != nullptr && SafetyInfo != nullptr &&
1169          "Unexpected Input to promoteLoopAccessesToScalars");
1170 
1171   Value *SomePtr = *PointerMustAliases.begin();
1172   BasicBlock *Preheader = CurLoop->getLoopPreheader();
1173 
1174   // It isn't safe to promote a load/store from the loop if the load/store is
1175   // conditional.  For example, turning:
1176   //
1177   //    for () { if (c) *P += 1; }
1178   //
1179   // into:
1180   //
1181   //    tmp = *P;  for () { if (c) tmp +=1; } *P = tmp;
1182   //
1183   // is not safe, because *P may only be valid to access if 'c' is true.
1184   //
1185   // The safety property divides into two parts:
1186   // p1) The memory may not be dereferenceable on entry to the loop.  In this
1187   //    case, we can't insert the required load in the preheader.
1188   // p2) The memory model does not allow us to insert a store along any dynamic
1189   //    path which did not originally have one.
1190   //
1191   // If at least one store is guaranteed to execute, both properties are
1192   // satisfied, and promotion is legal.
1193   //
1194   // This, however, is not a necessary condition. Even if no store/load is
1195   // guaranteed to execute, we can still establish these properties.
1196   // We can establish (p1) by proving that hoisting the load into the preheader
1197   // is safe (i.e. proving dereferenceability on all paths through the loop). We
1198   // can use any access within the alias set to prove dereferenceability,
1199   // since they're all must alias.
1200   //
1201   // There are two ways establish (p2):
1202   // a) Prove the location is thread-local. In this case the memory model
1203   // requirement does not apply, and stores are safe to insert.
1204   // b) Prove a store dominates every exit block. In this case, if an exit
1205   // blocks is reached, the original dynamic path would have taken us through
1206   // the store, so inserting a store into the exit block is safe. Note that this
1207   // is different from the store being guaranteed to execute. For instance,
1208   // if an exception is thrown on the first iteration of the loop, the original
1209   // store is never executed, but the exit blocks are not executed either.
1210 
1211   bool DereferenceableInPH = false;
1212   bool SafeToInsertStore = false;
1213 
1214   SmallVector<Instruction *, 64> LoopUses;
1215 
1216   // We start with an alignment of one and try to find instructions that allow
1217   // us to prove better alignment.
1218   unsigned Alignment = 1;
1219   // Keep track of which types of access we see
1220   bool SawUnorderedAtomic = false;
1221   bool SawNotAtomic = false;
1222   AAMDNodes AATags;
1223 
1224   const DataLayout &MDL = Preheader->getModule()->getDataLayout();
1225 
1226   bool IsKnownThreadLocalObject = false;
1227   if (SafetyInfo->MayThrow) {
1228     // If a loop can throw, we have to insert a store along each unwind edge.
1229     // That said, we can't actually make the unwind edge explicit. Therefore,
1230     // we have to prove that the store is dead along the unwind edge.  We do
1231     // this by proving that the caller can't have a reference to the object
1232     // after return and thus can't possibly load from the object.
1233     Value *Object = GetUnderlyingObject(SomePtr, MDL);
1234     if (!isKnownNonEscaping(Object, TLI))
1235       return false;
1236     // Subtlety: Alloca's aren't visible to callers, but *are* potentially
1237     // visible to other threads if captured and used during their lifetimes.
1238     IsKnownThreadLocalObject = !isa<AllocaInst>(Object);
1239   }
1240 
1241   // Check that all of the pointers in the alias set have the same type.  We
1242   // cannot (yet) promote a memory location that is loaded and stored in
1243   // different sizes.  While we are at it, collect alignment and AA info.
1244   for (Value *ASIV : PointerMustAliases) {
1245     // Check that all of the pointers in the alias set have the same type.  We
1246     // cannot (yet) promote a memory location that is loaded and stored in
1247     // different sizes.
1248     if (SomePtr->getType() != ASIV->getType())
1249       return false;
1250 
1251     for (User *U : ASIV->users()) {
1252       // Ignore instructions that are outside the loop.
1253       Instruction *UI = dyn_cast<Instruction>(U);
1254       if (!UI || !CurLoop->contains(UI))
1255         continue;
1256 
1257       // If there is an non-load/store instruction in the loop, we can't promote
1258       // it.
1259       if (LoadInst *Load = dyn_cast<LoadInst>(UI)) {
1260         assert(!Load->isVolatile() && "AST broken");
1261         if (!Load->isUnordered())
1262           return false;
1263 
1264         SawUnorderedAtomic |= Load->isAtomic();
1265         SawNotAtomic |= !Load->isAtomic();
1266 
1267         if (!DereferenceableInPH)
1268           DereferenceableInPH = isSafeToExecuteUnconditionally(
1269               *Load, DT, CurLoop, SafetyInfo, ORE, Preheader->getTerminator());
1270       } else if (const StoreInst *Store = dyn_cast<StoreInst>(UI)) {
1271         // Stores *of* the pointer are not interesting, only stores *to* the
1272         // pointer.
1273         if (UI->getOperand(1) != ASIV)
1274           continue;
1275         assert(!Store->isVolatile() && "AST broken");
1276         if (!Store->isUnordered())
1277           return false;
1278 
1279         SawUnorderedAtomic |= Store->isAtomic();
1280         SawNotAtomic |= !Store->isAtomic();
1281 
1282         // If the store is guaranteed to execute, both properties are satisfied.
1283         // We may want to check if a store is guaranteed to execute even if we
1284         // already know that promotion is safe, since it may have higher
1285         // alignment than any other guaranteed stores, in which case we can
1286         // raise the alignment on the promoted store.
1287         unsigned InstAlignment = Store->getAlignment();
1288         if (!InstAlignment)
1289           InstAlignment =
1290               MDL.getABITypeAlignment(Store->getValueOperand()->getType());
1291 
1292         if (!DereferenceableInPH || !SafeToInsertStore ||
1293             (InstAlignment > Alignment)) {
1294           if (isGuaranteedToExecute(*UI, DT, CurLoop, SafetyInfo)) {
1295             DereferenceableInPH = true;
1296             SafeToInsertStore = true;
1297             Alignment = std::max(Alignment, InstAlignment);
1298           }
1299         }
1300 
1301         // If a store dominates all exit blocks, it is safe to sink.
1302         // As explained above, if an exit block was executed, a dominating
1303         // store must have been been executed at least once, so we are not
1304         // introducing stores on paths that did not have them.
1305         // Note that this only looks at explicit exit blocks. If we ever
1306         // start sinking stores into unwind edges (see above), this will break.
1307         if (!SafeToInsertStore)
1308           SafeToInsertStore = llvm::all_of(ExitBlocks, [&](BasicBlock *Exit) {
1309             return DT->dominates(Store->getParent(), Exit);
1310           });
1311 
1312         // If the store is not guaranteed to execute, we may still get
1313         // deref info through it.
1314         if (!DereferenceableInPH) {
1315           DereferenceableInPH = isDereferenceableAndAlignedPointer(
1316               Store->getPointerOperand(), Store->getAlignment(), MDL,
1317               Preheader->getTerminator(), DT);
1318         }
1319       } else
1320         return false; // Not a load or store.
1321 
1322       // Merge the AA tags.
1323       if (LoopUses.empty()) {
1324         // On the first load/store, just take its AA tags.
1325         UI->getAAMetadata(AATags);
1326       } else if (AATags) {
1327         UI->getAAMetadata(AATags, /* Merge = */ true);
1328       }
1329 
1330       LoopUses.push_back(UI);
1331     }
1332   }
1333 
1334   // If we found both an unordered atomic instruction and a non-atomic memory
1335   // access, bail.  We can't blindly promote non-atomic to atomic since we
1336   // might not be able to lower the result.  We can't downgrade since that
1337   // would violate memory model.  Also, align 0 is an error for atomics.
1338   if (SawUnorderedAtomic && SawNotAtomic)
1339     return false;
1340 
1341   // If we couldn't prove we can hoist the load, bail.
1342   if (!DereferenceableInPH)
1343     return false;
1344 
1345   // We know we can hoist the load, but don't have a guaranteed store.
1346   // Check whether the location is thread-local. If it is, then we can insert
1347   // stores along paths which originally didn't have them without violating the
1348   // memory model.
1349   if (!SafeToInsertStore) {
1350     if (IsKnownThreadLocalObject)
1351       SafeToInsertStore = true;
1352     else {
1353       Value *Object = GetUnderlyingObject(SomePtr, MDL);
1354       SafeToInsertStore =
1355           (isAllocLikeFn(Object, TLI) || isa<AllocaInst>(Object)) &&
1356           !PointerMayBeCaptured(Object, true, true);
1357     }
1358   }
1359 
1360   // If we've still failed to prove we can sink the store, give up.
1361   if (!SafeToInsertStore)
1362     return false;
1363 
1364   // Otherwise, this is safe to promote, lets do it!
1365   DEBUG(dbgs() << "LICM: Promoting value stored to in loop: " << *SomePtr
1366                << '\n');
1367   ORE->emit([&]() {
1368     return OptimizationRemark(DEBUG_TYPE, "PromoteLoopAccessesToScalar",
1369                               LoopUses[0])
1370            << "Moving accesses to memory location out of the loop";
1371   });
1372   ++NumPromoted;
1373 
1374   // Grab a debug location for the inserted loads/stores; given that the
1375   // inserted loads/stores have little relation to the original loads/stores,
1376   // this code just arbitrarily picks a location from one, since any debug
1377   // location is better than none.
1378   DebugLoc DL = LoopUses[0]->getDebugLoc();
1379 
1380   // We use the SSAUpdater interface to insert phi nodes as required.
1381   SmallVector<PHINode *, 16> NewPHIs;
1382   SSAUpdater SSA(&NewPHIs);
1383   LoopPromoter Promoter(SomePtr, LoopUses, SSA, PointerMustAliases, ExitBlocks,
1384                         InsertPts, PIC, *CurAST, *LI, DL, Alignment,
1385                         SawUnorderedAtomic, AATags);
1386 
1387   // Set up the preheader to have a definition of the value.  It is the live-out
1388   // value from the preheader that uses in the loop will use.
1389   LoadInst *PreheaderLoad = new LoadInst(
1390       SomePtr, SomePtr->getName() + ".promoted", Preheader->getTerminator());
1391   if (SawUnorderedAtomic)
1392     PreheaderLoad->setOrdering(AtomicOrdering::Unordered);
1393   PreheaderLoad->setAlignment(Alignment);
1394   PreheaderLoad->setDebugLoc(DL);
1395   if (AATags)
1396     PreheaderLoad->setAAMetadata(AATags);
1397   SSA.AddAvailableValue(Preheader, PreheaderLoad);
1398 
1399   // Rewrite all the loads in the loop and remember all the definitions from
1400   // stores in the loop.
1401   Promoter.run(LoopUses);
1402 
1403   // If the SSAUpdater didn't use the load in the preheader, just zap it now.
1404   if (PreheaderLoad->use_empty())
1405     PreheaderLoad->eraseFromParent();
1406 
1407   return true;
1408 }
1409 
1410 /// Returns an owning pointer to an alias set which incorporates aliasing info
1411 /// from L and all subloops of L.
1412 /// FIXME: In new pass manager, there is no helper function to handle loop
1413 /// analysis such as cloneBasicBlockAnalysis, so the AST needs to be recomputed
1414 /// from scratch for every loop. Hook up with the helper functions when
1415 /// available in the new pass manager to avoid redundant computation.
1416 AliasSetTracker *
1417 LoopInvariantCodeMotion::collectAliasInfoForLoop(Loop *L, LoopInfo *LI,
1418                                                  AliasAnalysis *AA) {
1419   AliasSetTracker *CurAST = nullptr;
1420   SmallVector<Loop *, 4> RecomputeLoops;
1421   for (Loop *InnerL : L->getSubLoops()) {
1422     auto MapI = LoopToAliasSetMap.find(InnerL);
1423     // If the AST for this inner loop is missing it may have been merged into
1424     // some other loop's AST and then that loop unrolled, and so we need to
1425     // recompute it.
1426     if (MapI == LoopToAliasSetMap.end()) {
1427       RecomputeLoops.push_back(InnerL);
1428       continue;
1429     }
1430     AliasSetTracker *InnerAST = MapI->second;
1431 
1432     if (CurAST != nullptr) {
1433       // What if InnerLoop was modified by other passes ?
1434       CurAST->add(*InnerAST);
1435 
1436       // Once we've incorporated the inner loop's AST into ours, we don't need
1437       // the subloop's anymore.
1438       delete InnerAST;
1439     } else {
1440       CurAST = InnerAST;
1441     }
1442     LoopToAliasSetMap.erase(MapI);
1443   }
1444   if (CurAST == nullptr)
1445     CurAST = new AliasSetTracker(*AA);
1446 
1447   auto mergeLoop = [&](Loop *L) {
1448     // Loop over the body of this loop, looking for calls, invokes, and stores.
1449     for (BasicBlock *BB : L->blocks())
1450       CurAST->add(*BB); // Incorporate the specified basic block
1451   };
1452 
1453   // Add everything from the sub loops that are no longer directly available.
1454   for (Loop *InnerL : RecomputeLoops)
1455     mergeLoop(InnerL);
1456 
1457   // And merge in this loop.
1458   mergeLoop(L);
1459 
1460   return CurAST;
1461 }
1462 
1463 /// Simple analysis hook. Clone alias set info.
1464 ///
1465 void LegacyLICMPass::cloneBasicBlockAnalysis(BasicBlock *From, BasicBlock *To,
1466                                              Loop *L) {
1467   AliasSetTracker *AST = LICM.getLoopToAliasSetMap().lookup(L);
1468   if (!AST)
1469     return;
1470 
1471   AST->copyValue(From, To);
1472 }
1473 
1474 /// Simple Analysis hook. Delete value V from alias set
1475 ///
1476 void LegacyLICMPass::deleteAnalysisValue(Value *V, Loop *L) {
1477   AliasSetTracker *AST = LICM.getLoopToAliasSetMap().lookup(L);
1478   if (!AST)
1479     return;
1480 
1481   AST->deleteValue(V);
1482 }
1483 
1484 /// Simple Analysis hook. Delete value L from alias set map.
1485 ///
1486 void LegacyLICMPass::deleteAnalysisLoop(Loop *L) {
1487   AliasSetTracker *AST = LICM.getLoopToAliasSetMap().lookup(L);
1488   if (!AST)
1489     return;
1490 
1491   delete AST;
1492   LICM.getLoopToAliasSetMap().erase(L);
1493 }
1494 
1495 /// Return true if the body of this loop may store into the memory
1496 /// location pointed to by V.
1497 ///
1498 static bool pointerInvalidatedByLoop(Value *V, uint64_t Size,
1499                                      const AAMDNodes &AAInfo,
1500                                      AliasSetTracker *CurAST) {
1501   // Check to see if any of the basic blocks in CurLoop invalidate *V.
1502   return CurAST->getAliasSetForPointer(V, Size, AAInfo).isMod();
1503 }
1504 
1505 /// Little predicate that returns true if the specified basic block is in
1506 /// a subloop of the current one, not the current one itself.
1507 ///
1508 static bool inSubLoop(BasicBlock *BB, Loop *CurLoop, LoopInfo *LI) {
1509   assert(CurLoop->contains(BB) && "Only valid if BB is IN the loop");
1510   return LI->getLoopFor(BB) != CurLoop;
1511 }
1512