LLVM 20.0.0git
TypeBasedAliasAnalysis.cpp
Go to the documentation of this file.
1//===- TypeBasedAliasAnalysis.cpp - Type-Based Alias Analysis -------------===//
2//
3// Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
4// See https://llvm.org/LICENSE.txt for license information.
5// SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
6//
7//===----------------------------------------------------------------------===//
8//
9// This file defines the TypeBasedAliasAnalysis pass, which implements
10// metadata-based TBAA.
11//
12// In LLVM IR, memory does not have types, so LLVM's own type system is not
13// suitable for doing TBAA. Instead, metadata is added to the IR to describe
14// a type system of a higher level language. This can be used to implement
15// typical C/C++ TBAA, but it can also be used to implement custom alias
16// analysis behavior for other languages.
17//
18// We now support two types of metadata format: scalar TBAA and struct-path
19// aware TBAA. After all testing cases are upgraded to use struct-path aware
20// TBAA and we can auto-upgrade existing bc files, the support for scalar TBAA
21// can be dropped.
22//
23// The scalar TBAA metadata format is very simple. TBAA MDNodes have up to
24// three fields, e.g.:
25// !0 = !{ !"an example type tree" }
26// !1 = !{ !"int", !0 }
27// !2 = !{ !"float", !0 }
28// !3 = !{ !"const float", !2, i64 1 }
29//
30// The first field is an identity field. It can be any value, usually
31// an MDString, which uniquely identifies the type. The most important
32// name in the tree is the name of the root node. Two trees with
33// different root node names are entirely disjoint, even if they
34// have leaves with common names.
35//
36// The second field identifies the type's parent node in the tree, or
37// is null or omitted for a root node. A type is considered to alias
38// all of its descendants and all of its ancestors in the tree. Also,
39// a type is considered to alias all types in other trees, so that
40// bitcode produced from multiple front-ends is handled conservatively.
41//
42// If the third field is present, it's an integer which if equal to 1
43// indicates that the type is "constant" (meaning pointsToConstantMemory
44// should return true; see
45// http://llvm.org/docs/AliasAnalysis.html#OtherItfs).
46//
47// With struct-path aware TBAA, the MDNodes attached to an instruction using
48// "!tbaa" are called path tag nodes.
49//
50// The path tag node has 4 fields with the last field being optional.
51//
52// The first field is the base type node, it can be a struct type node
53// or a scalar type node. The second field is the access type node, it
54// must be a scalar type node. The third field is the offset into the base type.
55// The last field has the same meaning as the last field of our scalar TBAA:
56// it's an integer which if equal to 1 indicates that the access is "constant".
57//
58// The struct type node has a name and a list of pairs, one pair for each member
59// of the struct. The first element of each pair is a type node (a struct type
60// node or a scalar type node), specifying the type of the member, the second
61// element of each pair is the offset of the member.
62//
63// Given an example
64// typedef struct {
65// short s;
66// } A;
67// typedef struct {
68// uint16_t s;
69// A a;
70// } B;
71//
72// For an access to B.a.s, we attach !5 (a path tag node) to the load/store
73// instruction. The base type is !4 (struct B), the access type is !2 (scalar
74// type short) and the offset is 4.
75//
76// !0 = !{!"Simple C/C++ TBAA"}
77// !1 = !{!"omnipotent char", !0} // Scalar type node
78// !2 = !{!"short", !1} // Scalar type node
79// !3 = !{!"A", !2, i64 0} // Struct type node
80// !4 = !{!"B", !2, i64 0, !3, i64 4}
81// // Struct type node
82// !5 = !{!4, !2, i64 4} // Path tag node
83//
84// The struct type nodes and the scalar type nodes form a type DAG.
85// Root (!0)
86// char (!1) -- edge to Root
87// short (!2) -- edge to char
88// A (!3) -- edge with offset 0 to short
89// B (!4) -- edge with offset 0 to short and edge with offset 4 to A
90//
91// To check if two tags (tagX and tagY) can alias, we start from the base type
92// of tagX, follow the edge with the correct offset in the type DAG and adjust
93// the offset until we reach the base type of tagY or until we reach the Root
94// node.
95// If we reach the base type of tagY, compare the adjusted offset with
96// offset of tagY, return Alias if the offsets are the same, return NoAlias
97// otherwise.
98// If we reach the Root node, perform the above starting from base type of tagY
99// to see if we reach base type of tagX.
100//
101// If they have different roots, they're part of different potentially
102// unrelated type systems, so we return Alias to be conservative.
103// If neither node is an ancestor of the other and they have the same root,
104// then we say NoAlias.
105//
106//===----------------------------------------------------------------------===//
107
109#include "llvm/ADT/SetVector.h"
112#include "llvm/IR/Constants.h"
113#include "llvm/IR/DataLayout.h"
114#include "llvm/IR/DerivedTypes.h"
115#include "llvm/IR/InstrTypes.h"
116#include "llvm/IR/LLVMContext.h"
117#include "llvm/IR/Metadata.h"
119#include "llvm/Pass.h"
120#include "llvm/Support/Casting.h"
123#include <cassert>
124#include <cstdint>
125
126using namespace llvm;
127
128// A handy option for disabling TBAA functionality. The same effect can also be
129// achieved by stripping the !tbaa tags from IR, but this option is sometimes
130// more convenient.
131static cl::opt<bool> EnableTBAA("enable-tbaa", cl::init(true), cl::Hidden);
132
133namespace {
134
135/// isNewFormatTypeNode - Return true iff the given type node is in the new
136/// size-aware format.
137static bool isNewFormatTypeNode(const MDNode *N) {
138 if (N->getNumOperands() < 3)
139 return false;
140 // In the old format the first operand is a string.
141 if (!isa<MDNode>(N->getOperand(0)))
142 return false;
143 return true;
144}
145
146/// This is a simple wrapper around an MDNode which provides a higher-level
147/// interface by hiding the details of how alias analysis information is encoded
148/// in its operands.
149template<typename MDNodeTy>
150class TBAANodeImpl {
151 MDNodeTy *Node = nullptr;
152
153public:
154 TBAANodeImpl() = default;
155 explicit TBAANodeImpl(MDNodeTy *N) : Node(N) {}
156
157 /// getNode - Get the MDNode for this TBAANode.
158 MDNodeTy *getNode() const { return Node; }
159
160 /// isNewFormat - Return true iff the wrapped type node is in the new
161 /// size-aware format.
162 bool isNewFormat() const { return isNewFormatTypeNode(Node); }
163
164 /// getParent - Get this TBAANode's Alias tree parent.
165 TBAANodeImpl<MDNodeTy> getParent() const {
166 if (isNewFormat())
167 return TBAANodeImpl(cast<MDNodeTy>(Node->getOperand(0)));
168
169 if (Node->getNumOperands() < 2)
170 return TBAANodeImpl<MDNodeTy>();
171 MDNodeTy *P = dyn_cast_or_null<MDNodeTy>(Node->getOperand(1));
172 if (!P)
173 return TBAANodeImpl<MDNodeTy>();
174 // Ok, this node has a valid parent. Return it.
175 return TBAANodeImpl<MDNodeTy>(P);
176 }
177
178 /// Test if this TBAANode represents a type for objects which are
179 /// not modified (by any means) in the context where this
180 /// AliasAnalysis is relevant.
181 bool isTypeImmutable() const {
182 if (Node->getNumOperands() < 3)
183 return false;
184 ConstantInt *CI = mdconst::dyn_extract<ConstantInt>(Node->getOperand(2));
185 if (!CI)
186 return false;
187 return CI->getValue()[0];
188 }
189};
190
191/// \name Specializations of \c TBAANodeImpl for const and non const qualified
192/// \c MDNode.
193/// @{
194using TBAANode = TBAANodeImpl<const MDNode>;
195using MutableTBAANode = TBAANodeImpl<MDNode>;
196/// @}
197
198/// This is a simple wrapper around an MDNode which provides a
199/// higher-level interface by hiding the details of how alias analysis
200/// information is encoded in its operands.
201template<typename MDNodeTy>
202class TBAAStructTagNodeImpl {
203 /// This node should be created with createTBAAAccessTag().
204 MDNodeTy *Node;
205
206public:
207 explicit TBAAStructTagNodeImpl(MDNodeTy *N) : Node(N) {}
208
209 /// Get the MDNode for this TBAAStructTagNode.
210 MDNodeTy *getNode() const { return Node; }
211
212 /// isNewFormat - Return true iff the wrapped access tag is in the new
213 /// size-aware format.
214 bool isNewFormat() const {
215 if (Node->getNumOperands() < 4)
216 return false;
217 if (MDNodeTy *AccessType = getAccessType())
218 if (!TBAANodeImpl<MDNodeTy>(AccessType).isNewFormat())
219 return false;
220 return true;
221 }
222
223 MDNodeTy *getBaseType() const {
224 return dyn_cast_or_null<MDNode>(Node->getOperand(0));
225 }
226
227 MDNodeTy *getAccessType() const {
228 return dyn_cast_or_null<MDNode>(Node->getOperand(1));
229 }
230
231 uint64_t getOffset() const {
232 return mdconst::extract<ConstantInt>(Node->getOperand(2))->getZExtValue();
233 }
234
235 uint64_t getSize() const {
236 if (!isNewFormat())
237 return UINT64_MAX;
238 return mdconst::extract<ConstantInt>(Node->getOperand(3))->getZExtValue();
239 }
240
241 /// Test if this TBAAStructTagNode represents a type for objects
242 /// which are not modified (by any means) in the context where this
243 /// AliasAnalysis is relevant.
244 bool isTypeImmutable() const {
245 unsigned OpNo = isNewFormat() ? 4 : 3;
246 if (Node->getNumOperands() < OpNo + 1)
247 return false;
248 ConstantInt *CI = mdconst::dyn_extract<ConstantInt>(Node->getOperand(OpNo));
249 if (!CI)
250 return false;
251 return CI->getValue()[0];
252 }
253};
254
255/// \name Specializations of \c TBAAStructTagNodeImpl for const and non const
256/// qualified \c MDNods.
257/// @{
258using TBAAStructTagNode = TBAAStructTagNodeImpl<const MDNode>;
259using MutableTBAAStructTagNode = TBAAStructTagNodeImpl<MDNode>;
260/// @}
261
262/// This is a simple wrapper around an MDNode which provides a
263/// higher-level interface by hiding the details of how alias analysis
264/// information is encoded in its operands.
265class TBAAStructTypeNode {
266 /// This node should be created with createTBAATypeNode().
267 const MDNode *Node = nullptr;
268
269public:
270 TBAAStructTypeNode() = default;
271 explicit TBAAStructTypeNode(const MDNode *N) : Node(N) {}
272
273 /// Get the MDNode for this TBAAStructTypeNode.
274 const MDNode *getNode() const { return Node; }
275
276 /// isNewFormat - Return true iff the wrapped type node is in the new
277 /// size-aware format.
278 bool isNewFormat() const { return isNewFormatTypeNode(Node); }
279
280 bool operator==(const TBAAStructTypeNode &Other) const {
281 return getNode() == Other.getNode();
282 }
283
284 /// getId - Return type identifier.
285 Metadata *getId() const {
286 return Node->getOperand(isNewFormat() ? 2 : 0);
287 }
288
289 unsigned getNumFields() const {
290 unsigned FirstFieldOpNo = isNewFormat() ? 3 : 1;
291 unsigned NumOpsPerField = isNewFormat() ? 3 : 2;
292 return (getNode()->getNumOperands() - FirstFieldOpNo) / NumOpsPerField;
293 }
294
295 TBAAStructTypeNode getFieldType(unsigned FieldIndex) const {
296 unsigned FirstFieldOpNo = isNewFormat() ? 3 : 1;
297 unsigned NumOpsPerField = isNewFormat() ? 3 : 2;
298 unsigned OpIndex = FirstFieldOpNo + FieldIndex * NumOpsPerField;
299 auto *TypeNode = cast<MDNode>(getNode()->getOperand(OpIndex));
300 return TBAAStructTypeNode(TypeNode);
301 }
302
303 /// Get this TBAAStructTypeNode's field in the type DAG with
304 /// given offset. Update the offset to be relative to the field type.
305 TBAAStructTypeNode getField(uint64_t &Offset) const {
306 bool NewFormat = isNewFormat();
307 const ArrayRef<MDOperand> Operands = Node->operands();
308 const unsigned NumOperands = Operands.size();
309
310 if (NewFormat) {
311 // New-format root and scalar type nodes have no fields.
312 if (NumOperands < 6)
313 return TBAAStructTypeNode();
314 } else {
315 // Parent can be omitted for the root node.
316 if (NumOperands < 2)
317 return TBAAStructTypeNode();
318
319 // Fast path for a scalar type node and a struct type node with a single
320 // field.
321 if (NumOperands <= 3) {
322 uint64_t Cur =
323 NumOperands == 2
324 ? 0
325 : mdconst::extract<ConstantInt>(Operands[2])->getZExtValue();
326 Offset -= Cur;
327 MDNode *P = dyn_cast_or_null<MDNode>(Operands[1]);
328 if (!P)
329 return TBAAStructTypeNode();
330 return TBAAStructTypeNode(P);
331 }
332 }
333
334 // Assume the offsets are in order. We return the previous field if
335 // the current offset is bigger than the given offset.
336 unsigned FirstFieldOpNo = NewFormat ? 3 : 1;
337 unsigned NumOpsPerField = NewFormat ? 3 : 2;
338 unsigned TheIdx = 0;
339
340 for (unsigned Idx = FirstFieldOpNo; Idx < NumOperands;
341 Idx += NumOpsPerField) {
342 uint64_t Cur =
343 mdconst::extract<ConstantInt>(Operands[Idx + 1])->getZExtValue();
344 if (Cur > Offset) {
345 assert(Idx >= FirstFieldOpNo + NumOpsPerField &&
346 "TBAAStructTypeNode::getField should have an offset match!");
347 TheIdx = Idx - NumOpsPerField;
348 break;
349 }
350 }
351 // Move along the last field.
352 if (TheIdx == 0)
353 TheIdx = NumOperands - NumOpsPerField;
354 uint64_t Cur =
355 mdconst::extract<ConstantInt>(Operands[TheIdx + 1])->getZExtValue();
356 Offset -= Cur;
357 MDNode *P = dyn_cast_or_null<MDNode>(Operands[TheIdx]);
358 if (!P)
359 return TBAAStructTypeNode();
360 return TBAAStructTypeNode(P);
361 }
362};
363
364} // end anonymous namespace
365
366/// Check the first operand of the tbaa tag node, if it is a MDNode, we treat
367/// it as struct-path aware TBAA format, otherwise, we treat it as scalar TBAA
368/// format.
369static bool isStructPathTBAA(const MDNode *MD) {
370 // Anonymous TBAA root starts with a MDNode and dragonegg uses it as
371 // a TBAA tag.
372 return isa<MDNode>(MD->getOperand(0)) && MD->getNumOperands() >= 3;
373}
374
376 const MemoryLocation &LocB,
377 AAQueryInfo &AAQI, const Instruction *) {
378 if (!shouldUseTBAA())
380
381 if (Aliases(LocA.AATags.TBAA, LocB.AATags.TBAA))
383
384 // Otherwise return a definitive result.
386}
387
389 AAQueryInfo &AAQI,
390 bool IgnoreLocals) {
391 if (!shouldUseTBAA())
392 return ModRefInfo::ModRef;
393
394 const MDNode *M = Loc.AATags.TBAA;
395 if (!M)
396 return ModRefInfo::ModRef;
397
398 // If this is an "immutable" type, we can assume the pointer is pointing
399 // to constant memory.
400 if ((!isStructPathTBAA(M) && TBAANode(M).isTypeImmutable()) ||
401 (isStructPathTBAA(M) && TBAAStructTagNode(M).isTypeImmutable()))
403
404 return ModRefInfo::ModRef;
405}
406
408 AAQueryInfo &AAQI) {
409 if (!shouldUseTBAA())
410 return MemoryEffects::unknown();
411
412 // If this is an "immutable" type, the access is not observable.
413 if (const MDNode *M = Call->getMetadata(LLVMContext::MD_tbaa))
414 if ((!isStructPathTBAA(M) && TBAANode(M).isTypeImmutable()) ||
415 (isStructPathTBAA(M) && TBAAStructTagNode(M).isTypeImmutable()))
416 return MemoryEffects::none();
417
418 return MemoryEffects::unknown();
419}
420
422 // Functions don't have metadata.
423 return MemoryEffects::unknown();
424}
425
427 const MemoryLocation &Loc,
428 AAQueryInfo &AAQI) {
429 if (!shouldUseTBAA())
430 return ModRefInfo::ModRef;
431
432 if (const MDNode *L = Loc.AATags.TBAA)
433 if (const MDNode *M = Call->getMetadata(LLVMContext::MD_tbaa))
434 if (!Aliases(L, M))
436
437 return ModRefInfo::ModRef;
438}
439
441 const CallBase *Call2,
442 AAQueryInfo &AAQI) {
443 if (!shouldUseTBAA())
444 return ModRefInfo::ModRef;
445
446 if (const MDNode *M1 = Call1->getMetadata(LLVMContext::MD_tbaa))
447 if (const MDNode *M2 = Call2->getMetadata(LLVMContext::MD_tbaa))
448 if (!Aliases(M1, M2))
450
451 return ModRefInfo::ModRef;
452}
453
455 if (!isStructPathTBAA(this)) {
456 if (getNumOperands() < 1)
457 return false;
458 if (MDString *Tag1 = dyn_cast<MDString>(getOperand(0))) {
459 if (Tag1->getString() == "vtable pointer")
460 return true;
461 }
462 return false;
463 }
464
465 // For struct-path aware TBAA, we use the access type of the tag.
466 TBAAStructTagNode Tag(this);
467 TBAAStructTypeNode AccessType(Tag.getAccessType());
468 if(auto *Id = dyn_cast<MDString>(AccessType.getId()))
469 if (Id->getString() == "vtable pointer")
470 return true;
471 return false;
472}
473
474static bool matchAccessTags(const MDNode *A, const MDNode *B,
475 const MDNode **GenericTag = nullptr);
476
478 const MDNode *GenericTag;
479 matchAccessTags(A, B, &GenericTag);
480 return const_cast<MDNode*>(GenericTag);
481}
482
483static const MDNode *getLeastCommonType(const MDNode *A, const MDNode *B) {
484 if (!A || !B)
485 return nullptr;
486
487 if (A == B)
488 return A;
489
491 TBAANode TA(A);
492 while (TA.getNode()) {
493 if (!PathA.insert(TA.getNode()))
494 report_fatal_error("Cycle found in TBAA metadata.");
495 TA = TA.getParent();
496 }
497
499 TBAANode TB(B);
500 while (TB.getNode()) {
501 if (!PathB.insert(TB.getNode()))
502 report_fatal_error("Cycle found in TBAA metadata.");
503 TB = TB.getParent();
504 }
505
506 int IA = PathA.size() - 1;
507 int IB = PathB.size() - 1;
508
509 const MDNode *Ret = nullptr;
510 while (IA >= 0 && IB >= 0) {
511 if (PathA[IA] == PathB[IB])
512 Ret = PathA[IA];
513 else
514 break;
515 --IA;
516 --IB;
517 }
518
519 return Ret;
520}
521
523 AAMDNodes Result;
524 Result.TBAA = MDNode::getMostGenericTBAA(TBAA, Other.TBAA);
525 Result.TBAAStruct = nullptr;
526 Result.Scope = MDNode::getMostGenericAliasScope(Scope, Other.Scope);
527 Result.NoAlias = MDNode::intersect(NoAlias, Other.NoAlias);
528 return Result;
529}
530
532 AAMDNodes Result;
533 Result.TBAA = Result.TBAAStruct = nullptr;
534 Result.Scope = MDNode::getMostGenericAliasScope(Scope, Other.Scope);
535 Result.NoAlias = MDNode::intersect(NoAlias, Other.NoAlias);
536 return Result;
537}
538
539static const MDNode *createAccessTag(const MDNode *AccessType) {
540 // If there is no access type or the access type is the root node, then
541 // we don't have any useful access tag to return.
542 if (!AccessType || AccessType->getNumOperands() < 2)
543 return nullptr;
544
545 Type *Int64 = IntegerType::get(AccessType->getContext(), 64);
546 auto *OffsetNode = ConstantAsMetadata::get(ConstantInt::get(Int64, 0));
547
548 if (TBAAStructTypeNode(AccessType).isNewFormat()) {
549 // TODO: Take access ranges into account when matching access tags and
550 // fix this code to generate actual access sizes for generic tags.
551 uint64_t AccessSize = UINT64_MAX;
552 auto *SizeNode =
553 ConstantAsMetadata::get(ConstantInt::get(Int64, AccessSize));
554 Metadata *Ops[] = {const_cast<MDNode*>(AccessType),
555 const_cast<MDNode*>(AccessType),
556 OffsetNode, SizeNode};
557 return MDNode::get(AccessType->getContext(), Ops);
558 }
559
560 Metadata *Ops[] = {const_cast<MDNode*>(AccessType),
561 const_cast<MDNode*>(AccessType),
562 OffsetNode};
563 return MDNode::get(AccessType->getContext(), Ops);
564}
565
566static bool hasField(TBAAStructTypeNode BaseType,
567 TBAAStructTypeNode FieldType) {
568 for (unsigned I = 0, E = BaseType.getNumFields(); I != E; ++I) {
569 TBAAStructTypeNode T = BaseType.getFieldType(I);
570 if (T == FieldType || hasField(T, FieldType))
571 return true;
572 }
573 return false;
574}
575
576/// Return true if for two given accesses, one of the accessed objects may be a
577/// subobject of the other. The \p BaseTag and \p SubobjectTag parameters
578/// describe the accesses to the base object and the subobject respectively.
579/// \p CommonType must be the metadata node describing the common type of the
580/// accessed objects. On return, \p MayAlias is set to true iff these accesses
581/// may alias and \p Generic, if not null, points to the most generic access
582/// tag for the given two.
583static bool mayBeAccessToSubobjectOf(TBAAStructTagNode BaseTag,
584 TBAAStructTagNode SubobjectTag,
585 const MDNode *CommonType,
586 const MDNode **GenericTag,
587 bool &MayAlias) {
588 // If the base object is of the least common type, then this may be an access
589 // to its subobject.
590 if (BaseTag.getAccessType() == BaseTag.getBaseType() &&
591 BaseTag.getAccessType() == CommonType) {
592 if (GenericTag)
593 *GenericTag = createAccessTag(CommonType);
594 MayAlias = true;
595 return true;
596 }
597
598 // If the access to the base object is through a field of the subobject's
599 // type, then this may be an access to that field. To check for that we start
600 // from the base type, follow the edge with the correct offset in the type DAG
601 // and adjust the offset until we reach the field type or until we reach the
602 // access type.
603 bool NewFormat = BaseTag.isNewFormat();
604 TBAAStructTypeNode BaseType(BaseTag.getBaseType());
605 uint64_t OffsetInBase = BaseTag.getOffset();
606
607 for (;;) {
608 // In the old format there is no distinction between fields and parent
609 // types, so in this case we consider all nodes up to the root.
610 if (!BaseType.getNode()) {
611 assert(!NewFormat && "Did not see access type in access path!");
612 break;
613 }
614
615 if (BaseType.getNode() == SubobjectTag.getBaseType()) {
616 MayAlias = OffsetInBase == SubobjectTag.getOffset() ||
617 BaseType.getNode() == BaseTag.getAccessType() ||
618 SubobjectTag.getBaseType() == SubobjectTag.getAccessType();
619 if (GenericTag) {
620 *GenericTag =
621 MayAlias ? SubobjectTag.getNode() : createAccessTag(CommonType);
622 }
623 return true;
624 }
625
626 // With new-format nodes we stop at the access type.
627 if (NewFormat && BaseType.getNode() == BaseTag.getAccessType())
628 break;
629
630 // Follow the edge with the correct offset. Offset will be adjusted to
631 // be relative to the field type.
632 BaseType = BaseType.getField(OffsetInBase);
633 }
634
635 // If the base object has a direct or indirect field of the subobject's type,
636 // then this may be an access to that field. We need this to check now that
637 // we support aggregates as access types.
638 if (NewFormat) {
639 // TBAAStructTypeNode BaseAccessType(BaseTag.getAccessType());
640 TBAAStructTypeNode FieldType(SubobjectTag.getBaseType());
641 if (hasField(BaseType, FieldType)) {
642 if (GenericTag)
643 *GenericTag = createAccessTag(CommonType);
644 MayAlias = true;
645 return true;
646 }
647 }
648
649 return false;
650}
651
652/// matchTags - Return true if the given couple of accesses are allowed to
653/// overlap. If \arg GenericTag is not null, then on return it points to the
654/// most generic access descriptor for the given two.
655static bool matchAccessTags(const MDNode *A, const MDNode *B,
656 const MDNode **GenericTag) {
657 if (A == B) {
658 if (GenericTag)
659 *GenericTag = A;
660 return true;
661 }
662
663 // Accesses with no TBAA information may alias with any other accesses.
664 if (!A || !B) {
665 if (GenericTag)
666 *GenericTag = nullptr;
667 return true;
668 }
669
670 // Verify that both input nodes are struct-path aware. Auto-upgrade should
671 // have taken care of this.
672 assert(isStructPathTBAA(A) && "Access A is not struct-path aware!");
673 assert(isStructPathTBAA(B) && "Access B is not struct-path aware!");
674
675 TBAAStructTagNode TagA(A), TagB(B);
676 const MDNode *CommonType = getLeastCommonType(TagA.getAccessType(),
677 TagB.getAccessType());
678
679 // If the final access types have different roots, they're part of different
680 // potentially unrelated type systems, so we must be conservative.
681 if (!CommonType) {
682 if (GenericTag)
683 *GenericTag = nullptr;
684 return true;
685 }
686
687 // If one of the accessed objects may be a subobject of the other, then such
688 // accesses may alias.
689 bool MayAlias;
690 if (mayBeAccessToSubobjectOf(/* BaseTag= */ TagA, /* SubobjectTag= */ TagB,
691 CommonType, GenericTag, MayAlias) ||
692 mayBeAccessToSubobjectOf(/* BaseTag= */ TagB, /* SubobjectTag= */ TagA,
693 CommonType, GenericTag, MayAlias))
694 return MayAlias;
695
696 // Otherwise, we've proved there's no alias.
697 if (GenericTag)
698 *GenericTag = createAccessTag(CommonType);
699 return false;
700}
701
702/// Aliases - Test whether the access represented by tag A may alias the
703/// access represented by tag B.
704bool TypeBasedAAResult::Aliases(const MDNode *A, const MDNode *B) const {
705 return matchAccessTags(A, B);
706}
707
708bool TypeBasedAAResult::shouldUseTBAA() const {
709 return EnableTBAA && !UsingTypeSanitizer;
710}
711
712AnalysisKey TypeBasedAA::Key;
713
715 return TypeBasedAAResult(F.hasFnAttribute(Attribute::SanitizeType));
716}
717
719INITIALIZE_PASS(TypeBasedAAWrapperPass, "tbaa", "Type-Based Alias Analysis",
720 false, true)
721
723 return new TypeBasedAAWrapperPass();
724}
725
728}
729
731 Result.reset(new TypeBasedAAResult(/*UsingTypeSanitizer=*/false));
732 return false;
733}
734
736 Result.reset();
737 return false;
738}
739
741 AU.setPreservesAll();
742}
743
745 // Fast path if there's no offset
746 if (Offset == 0)
747 return MD;
748 // Fast path if there's no path tbaa node (and thus scalar)
749 if (!isStructPathTBAA(MD))
750 return MD;
751
752 // The correct behavior here is to add the offset into the TBAA
753 // struct node offset. The base type, however may not have defined
754 // a type at this additional offset, resulting in errors. Since
755 // this method is only used within a given load/store access
756 // the offset provided is only used to subdivide the previous load
757 // maintaining the validity of the previous TBAA.
758 //
759 // This, however, should be revisited in the future.
760 return MD;
761}
762
764 // Fast path if there's no offset
765 if (Offset == 0)
766 return MD;
768 for (size_t i = 0, size = MD->getNumOperands(); i < size; i += 3) {
769 ConstantInt *InnerOffset = mdconst::extract<ConstantInt>(MD->getOperand(i));
770 ConstantInt *InnerSize =
771 mdconst::extract<ConstantInt>(MD->getOperand(i + 1));
772 // Don't include any triples that aren't in bounds
773 if (InnerOffset->getZExtValue() + InnerSize->getZExtValue() <= Offset)
774 continue;
775
776 uint64_t NewSize = InnerSize->getZExtValue();
777 uint64_t NewOffset = InnerOffset->getZExtValue() - Offset;
778 if (InnerOffset->getZExtValue() < Offset) {
779 NewOffset = 0;
780 NewSize -= Offset - InnerOffset->getZExtValue();
781 }
782
783 // Shift the offset of the triple
785 ConstantInt::get(InnerOffset->getType(), NewOffset)));
787 ConstantInt::get(InnerSize->getType(), NewSize)));
788 Sub.push_back(MD->getOperand(i + 2));
789 }
790 return MDNode::get(MD->getContext(), Sub);
791}
792
794 // Fast path if 0-length
795 if (Len == 0)
796 return nullptr;
797
798 // Regular TBAA is invariant of length, so we only need to consider
799 // struct-path TBAA.
800 if (!isStructPathTBAA(MD))
801 return MD;
802
803 TBAAStructTagNode Tag(MD);
804
805 // Only new format TBAA has a size
806 if (!Tag.isNewFormat())
807 return MD;
808
809 // If unknown size, drop the TBAA.
810 if (Len == -1)
811 return nullptr;
812
813 // Otherwise, create TBAA with the new Len
814 ArrayRef<MDOperand> MDOperands = MD->operands();
815 SmallVector<Metadata *, 4> NextNodes(MDOperands);
816 ConstantInt *PreviousSize = mdconst::extract<ConstantInt>(NextNodes[3]);
817
818 // Don't create a new MDNode if it is the same length.
819 if (PreviousSize->equalsInt(Len))
820 return MD;
821
822 NextNodes[3] =
823 ConstantAsMetadata::get(ConstantInt::get(PreviousSize->getType(), Len));
824 return MDNode::get(MD->getContext(), NextNodes);
825}
826
828 AAMDNodes New = *this;
829 MDNode *M = New.TBAAStruct;
830 if (!New.TBAA && M && M->getNumOperands() >= 3 && M->getOperand(0) &&
831 mdconst::hasa<ConstantInt>(M->getOperand(0)) &&
832 mdconst::extract<ConstantInt>(M->getOperand(0))->isZero() &&
833 M->getOperand(1) && mdconst::hasa<ConstantInt>(M->getOperand(1)) &&
834 mdconst::extract<ConstantInt>(M->getOperand(1))->getValue() ==
835 AccessSize &&
836 M->getOperand(2) && isa<MDNode>(M->getOperand(2)))
837 New.TBAA = cast<MDNode>(M->getOperand(2));
838
839 New.TBAAStruct = nullptr;
840 return New;
841}
842
844 const DataLayout &DL) {
845 AAMDNodes New = shift(Offset);
846 if (!DL.typeSizeEqualsStoreSize(AccessTy))
847 return New;
848 TypeSize Size = DL.getTypeStoreSize(AccessTy);
849 if (Size.isScalable())
850 return New;
851
852 return New.adjustForAccess(Size.getKnownMinValue());
853}
854
855AAMDNodes AAMDNodes::adjustForAccess(size_t Offset, unsigned AccessSize) {
856 AAMDNodes New = shift(Offset);
857 return New.adjustForAccess(AccessSize);
858}
static msgpack::DocNode getNode(msgpack::DocNode DN, msgpack::Type Type, MCValue Val)
MachineBasicBlock MachineBasicBlock::iterator DebugLoc DL
static const Function * getParent(const Value *V)
static GCRegistry::Add< OcamlGC > B("ocaml", "ocaml 3.10-compatible GC")
static GCRegistry::Add< ErlangGC > A("erlang", "erlang-compatible garbage collector")
This file contains the declarations for the subclasses of Constant, which represent the different fla...
Returns the sub type a function will return at a given Idx Should correspond to the result type of an ExtractValue instruction executed with just that one unsigned Idx
uint64_t Size
std::optional< std::vector< StOtherPiece > > Other
Definition: ELFYAML.cpp:1313
static MemAccessTy getAccessType(const TargetTransformInfo &TTI, Instruction *Inst, Value *OperandVal)
Return the type of the memory being accessed.
#define F(x, y, z)
Definition: MD5.cpp:55
#define I(x, y, z)
Definition: MD5.cpp:58
mir Rename Register Operands
This file provides utility analysis objects describing memory locations.
This file contains the declarations for metadata subclasses.
#define P(N)
#define INITIALIZE_PASS(passName, arg, name, cfg, analysis)
Definition: PassSupport.h:38
assert(ImpDefSCC.getReg()==AMDGPU::SCC &&ImpDefSCC.isDef())
unsigned OpIndex
static enum BaseType getBaseType(const Value *Val)
Return the baseType for Val which states whether Val is exclusively derived from constant/null,...
This file implements a set that has insertion order iteration characteristics.
static bool matchAccessTags(const MDNode *A, const MDNode *B, const MDNode **GenericTag=nullptr)
matchTags - Return true if the given couple of accesses are allowed to overlap.
static cl::opt< bool > EnableTBAA("enable-tbaa", cl::init(true), cl::Hidden)
static bool isStructPathTBAA(const MDNode *MD)
Check the first operand of the tbaa tag node, if it is a MDNode, we treat it as struct-path aware TBA...
static bool mayBeAccessToSubobjectOf(TBAAStructTagNode BaseTag, TBAAStructTagNode SubobjectTag, const MDNode *CommonType, const MDNode **GenericTag, bool &MayAlias)
Return true if for two given accesses, one of the accessed objects may be a subobject of the other.
static bool hasField(TBAAStructTypeNode BaseType, TBAAStructTypeNode FieldType)
static const MDNode * createAccessTag(const MDNode *AccessType)
static const MDNode * getLeastCommonType(const MDNode *A, const MDNode *B)
This is the interface for a metadata-based TBAA.
static unsigned getSize(unsigned Kind)
This class stores info we want to provide to or retain within an alias query.
The possible results of an alias query.
Definition: AliasAnalysis.h:77
@ MayAlias
The two locations may or may not alias.
Definition: AliasAnalysis.h:98
@ NoAlias
The two locations do not alias at all.
Definition: AliasAnalysis.h:95
A container for analyses that lazily runs them and caches their results.
Definition: PassManager.h:253
Represent the analysis usage information of a pass.
void setPreservesAll()
Set by analyses that do not transform their input at all.
ArrayRef - Represent a constant reference to an array (0 or more elements consecutively in memory),...
Definition: ArrayRef.h:41
Base class for all callable instructions (InvokeInst and CallInst) Holds everything related to callin...
Definition: InstrTypes.h:1120
static ConstantAsMetadata * get(Constant *C)
Definition: Metadata.h:528
This is the shared class of boolean and integer constants.
Definition: Constants.h:83
uint64_t getZExtValue() const
Return the constant as a 64-bit unsigned integer value after it has been zero extended as appropriate...
Definition: Constants.h:157
bool equalsInt(uint64_t V) const
A helper method that can be used to determine if the constant contained within is equal to a constant...
Definition: Constants.h:183
const APInt & getValue() const
Return the constant as an APInt value reference.
Definition: Constants.h:148
A parsed version of the target data layout string in and methods for querying it.
Definition: DataLayout.h:63
ImmutablePass class - This class is used to provide information that does not need to be run.
Definition: Pass.h:281
MDNode * getMetadata(unsigned KindID) const
Get the metadata of given kind attached to this Instruction.
Definition: Instruction.h:386
static IntegerType * get(LLVMContext &C, unsigned NumBits)
This static method is the primary way of constructing an IntegerType.
Definition: Type.cpp:311
Metadata node.
Definition: Metadata.h:1069
static MDNode * getMostGenericAliasScope(MDNode *A, MDNode *B)
Definition: Metadata.cpp:1141
bool isTBAAVtableAccess() const
Check whether MDNode is a vtable access.
static MDNode * getMostGenericTBAA(MDNode *A, MDNode *B)
const MDOperand & getOperand(unsigned I) const
Definition: Metadata.h:1430
ArrayRef< MDOperand > operands() const
Definition: Metadata.h:1428
static MDTuple * get(LLVMContext &Context, ArrayRef< Metadata * > MDs)
Definition: Metadata.h:1543
unsigned getNumOperands() const
Return number of MDNode operands.
Definition: Metadata.h:1436
static MDNode * intersect(MDNode *A, MDNode *B)
Definition: Metadata.cpp:1128
LLVMContext & getContext() const
Definition: Metadata.h:1233
A single uniqued string.
Definition: Metadata.h:720
static MemoryEffectsBase none()
Create MemoryEffectsBase that cannot read or write any memory.
Definition: ModRef.h:117
static MemoryEffectsBase unknown()
Create MemoryEffectsBase that can read and write any memory.
Definition: ModRef.h:112
Representation for a specific memory location.
AAMDNodes AATags
The metadata nodes which describes the aliasing of the location (each member is null if that kind of ...
Root of the metadata hierarchy.
Definition: Metadata.h:62
A Module instance is used to store all the information related to an LLVM module.
Definition: Module.h:65
static PassRegistry * getPassRegistry()
getPassRegistry - Access the global registry object, which is automatically initialized at applicatio...
size_type size() const
Determine the number of elements in the SetVector.
Definition: SetVector.h:98
bool insert(const value_type &X)
Insert a new element into the SetVector.
Definition: SetVector.h:162
A SetVector that performs no allocations if smaller than a certain size.
Definition: SetVector.h:370
void push_back(const T &Elt)
Definition: SmallVector.h:413
This is a 'vector' (really, a variable-sized array), optimized for the case when the array is small.
Definition: SmallVector.h:1196
A simple AA result that uses TBAA metadata to answer queries.
AliasResult alias(const MemoryLocation &LocA, const MemoryLocation &LocB, AAQueryInfo &AAQI, const Instruction *CtxI)
ModRefInfo getModRefInfoMask(const MemoryLocation &Loc, AAQueryInfo &AAQI, bool IgnoreLocals)
ModRefInfo getModRefInfo(const CallBase *Call, const MemoryLocation &Loc, AAQueryInfo &AAQI)
MemoryEffects getMemoryEffects(const CallBase *Call, AAQueryInfo &AAQI)
Legacy wrapper pass to provide the TypeBasedAAResult object.
bool doFinalization(Module &M) override
doFinalization - Virtual method overriden by subclasses to do any necessary clean up after all passes...
bool doInitialization(Module &M) override
doInitialization - Virtual method overridden by subclasses to do any necessary initialization before ...
void getAnalysisUsage(AnalysisUsage &AU) const override
getAnalysisUsage - This function should be overriden by passes that need analysis information to do t...
TypeBasedAAResult run(Function &F, FunctionAnalysisManager &AM)
The instances of the Type class are immutable: once they are created, they are never changed.
Definition: Type.h:45
Type * getType() const
All values are typed, get the type of this value.
Definition: Value.h:255
#define UINT64_MAX
Definition: DataTypes.h:77
initializer< Ty > init(const Ty &Val)
Definition: CommandLine.h:443
This is an optimization pass for GlobalISel generic memory operations.
Definition: AddressRanges.h:18
@ Offset
Definition: DWP.cpp:480
void initializeTypeBasedAAWrapperPassPass(PassRegistry &)
auto size(R &&Range, std::enable_if_t< std::is_base_of< std::random_access_iterator_tag, typename std::iterator_traits< decltype(Range.begin())>::iterator_category >::value, void > *=nullptr)
Get the size of a range.
Definition: STLExtras.h:1697
bool operator==(const AddressRangeValuePair &LHS, const AddressRangeValuePair &RHS)
unsigned M1(unsigned Val)
Definition: VE.h:376
static Error getOffset(const SymbolRef &Sym, SectionRef Sec, uint64_t &Result)
void report_fatal_error(Error Err, bool gen_crash_diag=true)
Report a serious error, calling any installed error handler.
Definition: Error.cpp:167
ModRefInfo
Flags indicating whether a memory access modifies or references memory.
Definition: ModRef.h:27
@ ModRef
The access may reference and may modify the value stored in memory.
@ NoModRef
The access neither references nor modifies the value stored in memory.
@ Other
Any other memory.
ImmutablePass * createTypeBasedAAWrapperPass()
#define N
A collection of metadata nodes that might be associated with a memory access used by the alias-analys...
Definition: Metadata.h:760
AAMDNodes concat(const AAMDNodes &Other) const
Determine the best AAMDNodes after concatenating two different locations together.
static MDNode * shiftTBAAStruct(MDNode *M, size_t off)
MDNode * Scope
The tag for alias scope specification (used with noalias).
Definition: Metadata.h:783
static MDNode * extendToTBAA(MDNode *TBAA, ssize_t len)
MDNode * TBAA
The tag for type-based alias analysis.
Definition: Metadata.h:777
AAMDNodes shift(size_t Offset) const
Create a new AAMDNode that describes this AAMDNode after applying a constant offset to the start of t...
Definition: Metadata.h:814
AAMDNodes merge(const AAMDNodes &Other) const
Given two sets of AAMDNodes applying to potentially different locations, determine the best AAMDNodes...
MDNode * NoAlias
The tag specifying the noalias scope.
Definition: Metadata.h:786
AAMDNodes adjustForAccess(unsigned AccessSize)
Create a new AAMDNode for accessing AccessSize bytes of this AAMDNode.
static MDNode * shiftTBAA(MDNode *M, size_t off)
A special type used by analysis passes to provide an address that identifies that particular analysis...
Definition: Analysis.h:28