xref: /openbsd-src/gnu/llvm/llvm/lib/Analysis/StackSafetyAnalysis.cpp (revision d415bd752c734aee168c4ee86ff32e8cc249eb16)
109467b48Spatrick //===- StackSafetyAnalysis.cpp - Stack memory safety analysis -------------===//
209467b48Spatrick //
309467b48Spatrick // Part of the LLVM Project, under the Apache License v2.0 with LLVM Exceptions.
409467b48Spatrick // See https://llvm.org/LICENSE.txt for license information.
509467b48Spatrick // SPDX-License-Identifier: Apache-2.0 WITH LLVM-exception
609467b48Spatrick //
709467b48Spatrick //===----------------------------------------------------------------------===//
809467b48Spatrick //
909467b48Spatrick //===----------------------------------------------------------------------===//
1009467b48Spatrick 
1109467b48Spatrick #include "llvm/Analysis/StackSafetyAnalysis.h"
12097a140dSpatrick #include "llvm/ADT/APInt.h"
13097a140dSpatrick #include "llvm/ADT/SmallPtrSet.h"
14097a140dSpatrick #include "llvm/ADT/SmallVector.h"
15097a140dSpatrick #include "llvm/ADT/Statistic.h"
16097a140dSpatrick #include "llvm/Analysis/ModuleSummaryAnalysis.h"
17*d415bd75Srobert #include "llvm/Analysis/ScalarEvolution.h"
18097a140dSpatrick #include "llvm/Analysis/StackLifetime.h"
19097a140dSpatrick #include "llvm/IR/ConstantRange.h"
20097a140dSpatrick #include "llvm/IR/DerivedTypes.h"
21097a140dSpatrick #include "llvm/IR/GlobalValue.h"
2209467b48Spatrick #include "llvm/IR/InstIterator.h"
23*d415bd75Srobert #include "llvm/IR/Instruction.h"
24097a140dSpatrick #include "llvm/IR/Instructions.h"
2509467b48Spatrick #include "llvm/IR/IntrinsicInst.h"
2673471bf0Spatrick #include "llvm/IR/ModuleSummaryIndex.h"
2709467b48Spatrick #include "llvm/InitializePasses.h"
28097a140dSpatrick #include "llvm/Support/Casting.h"
2909467b48Spatrick #include "llvm/Support/CommandLine.h"
30097a140dSpatrick #include "llvm/Support/FormatVariadic.h"
3109467b48Spatrick #include "llvm/Support/raw_ostream.h"
32097a140dSpatrick #include <algorithm>
33097a140dSpatrick #include <memory>
34*d415bd75Srobert #include <tuple>
3509467b48Spatrick 
3609467b48Spatrick using namespace llvm;
3709467b48Spatrick 
3809467b48Spatrick #define DEBUG_TYPE "stack-safety"
3909467b48Spatrick 
40097a140dSpatrick STATISTIC(NumAllocaStackSafe, "Number of safe allocas");
41097a140dSpatrick STATISTIC(NumAllocaTotal, "Number of total allocas");
42097a140dSpatrick 
4373471bf0Spatrick STATISTIC(NumCombinedCalleeLookupTotal,
4473471bf0Spatrick           "Number of total callee lookups on combined index.");
4573471bf0Spatrick STATISTIC(NumCombinedCalleeLookupFailed,
4673471bf0Spatrick           "Number of failed callee lookups on combined index.");
4773471bf0Spatrick STATISTIC(NumModuleCalleeLookupTotal,
4873471bf0Spatrick           "Number of total callee lookups on module index.");
4973471bf0Spatrick STATISTIC(NumModuleCalleeLookupFailed,
5073471bf0Spatrick           "Number of failed callee lookups on module index.");
5173471bf0Spatrick STATISTIC(NumCombinedParamAccessesBefore,
5273471bf0Spatrick           "Number of total param accesses before generateParamAccessSummary.");
5373471bf0Spatrick STATISTIC(NumCombinedParamAccessesAfter,
5473471bf0Spatrick           "Number of total param accesses after generateParamAccessSummary.");
5573471bf0Spatrick STATISTIC(NumCombinedDataFlowNodes,
5673471bf0Spatrick           "Number of total nodes in combined index for dataflow processing.");
5773471bf0Spatrick STATISTIC(NumIndexCalleeUnhandled, "Number of index callee which are unhandled.");
5873471bf0Spatrick STATISTIC(NumIndexCalleeMultipleWeak, "Number of index callee non-unique weak.");
5973471bf0Spatrick STATISTIC(NumIndexCalleeMultipleExternal, "Number of index callee non-unique external.");
6073471bf0Spatrick 
6173471bf0Spatrick 
6209467b48Spatrick static cl::opt<int> StackSafetyMaxIterations("stack-safety-max-iterations",
6309467b48Spatrick                                              cl::init(20), cl::Hidden);
6409467b48Spatrick 
65097a140dSpatrick static cl::opt<bool> StackSafetyPrint("stack-safety-print", cl::init(false),
66097a140dSpatrick                                       cl::Hidden);
67097a140dSpatrick 
68097a140dSpatrick static cl::opt<bool> StackSafetyRun("stack-safety-run", cl::init(false),
69097a140dSpatrick                                     cl::Hidden);
70097a140dSpatrick 
7109467b48Spatrick namespace {
7209467b48Spatrick 
7373471bf0Spatrick // Check if we should bailout for such ranges.
isUnsafe(const ConstantRange & R)7473471bf0Spatrick bool isUnsafe(const ConstantRange &R) {
7573471bf0Spatrick   return R.isEmptySet() || R.isFullSet() || R.isUpperSignWrapped();
7673471bf0Spatrick }
7773471bf0Spatrick 
addOverflowNever(const ConstantRange & L,const ConstantRange & R)7873471bf0Spatrick ConstantRange addOverflowNever(const ConstantRange &L, const ConstantRange &R) {
7973471bf0Spatrick   assert(!L.isSignWrappedSet());
8073471bf0Spatrick   assert(!R.isSignWrappedSet());
8173471bf0Spatrick   if (L.signedAddMayOverflow(R) !=
8273471bf0Spatrick       ConstantRange::OverflowResult::NeverOverflows)
8373471bf0Spatrick     return ConstantRange::getFull(L.getBitWidth());
8473471bf0Spatrick   ConstantRange Result = L.add(R);
8573471bf0Spatrick   assert(!Result.isSignWrappedSet());
8673471bf0Spatrick   return Result;
8773471bf0Spatrick }
8873471bf0Spatrick 
unionNoWrap(const ConstantRange & L,const ConstantRange & R)8973471bf0Spatrick ConstantRange unionNoWrap(const ConstantRange &L, const ConstantRange &R) {
9073471bf0Spatrick   assert(!L.isSignWrappedSet());
9173471bf0Spatrick   assert(!R.isSignWrappedSet());
9273471bf0Spatrick   auto Result = L.unionWith(R);
9373471bf0Spatrick   // Two non-wrapped sets can produce wrapped.
9473471bf0Spatrick   if (Result.isSignWrappedSet())
9573471bf0Spatrick     Result = ConstantRange::getFull(Result.getBitWidth());
9673471bf0Spatrick   return Result;
9773471bf0Spatrick }
9873471bf0Spatrick 
9909467b48Spatrick /// Describes use of address in as a function call argument.
100097a140dSpatrick template <typename CalleeTy> struct CallInfo {
10109467b48Spatrick   /// Function being called.
102097a140dSpatrick   const CalleeTy *Callee = nullptr;
10309467b48Spatrick   /// Index of argument which pass address.
10409467b48Spatrick   size_t ParamNo = 0;
10509467b48Spatrick 
CallInfo__anonc76328400111::CallInfo10673471bf0Spatrick   CallInfo(const CalleeTy *Callee, size_t ParamNo)
10773471bf0Spatrick       : Callee(Callee), ParamNo(ParamNo) {}
10873471bf0Spatrick 
10973471bf0Spatrick   struct Less {
operator ()__anonc76328400111::CallInfo::Less11073471bf0Spatrick     bool operator()(const CallInfo &L, const CallInfo &R) const {
11173471bf0Spatrick       return std::tie(L.ParamNo, L.Callee) < std::tie(R.ParamNo, R.Callee);
11209467b48Spatrick     }
11373471bf0Spatrick   };
11473471bf0Spatrick };
11509467b48Spatrick 
11609467b48Spatrick /// Describe uses of address (alloca or parameter) inside of the function.
117097a140dSpatrick template <typename CalleeTy> struct UseInfo {
11809467b48Spatrick   // Access range if the address (alloca or parameters).
11909467b48Spatrick   // It is allowed to be empty-set when there are no known accesses.
12009467b48Spatrick   ConstantRange Range;
121*d415bd75Srobert   std::set<const Instruction *> UnsafeAccesses;
12209467b48Spatrick 
12309467b48Spatrick   // List of calls which pass address as an argument.
12473471bf0Spatrick   // Value is offset range of address from base address (alloca or calling
12573471bf0Spatrick   // function argument). Range should never set to empty-set, that is an invalid
12673471bf0Spatrick   // access range that can cause empty-set to be propagated with
12773471bf0Spatrick   // ConstantRange::add
12873471bf0Spatrick   using CallsTy = std::map<CallInfo<CalleeTy>, ConstantRange,
12973471bf0Spatrick                            typename CallInfo<CalleeTy>::Less>;
13073471bf0Spatrick   CallsTy Calls;
13109467b48Spatrick 
UseInfo__anonc76328400111::UseInfo132097a140dSpatrick   UseInfo(unsigned PointerSize) : Range{PointerSize, false} {}
13309467b48Spatrick 
updateRange__anonc76328400111::UseInfo13473471bf0Spatrick   void updateRange(const ConstantRange &R) { Range = unionNoWrap(Range, R); }
addRange__anonc76328400111::UseInfo135*d415bd75Srobert   void addRange(const Instruction *I, const ConstantRange &R, bool IsSafe) {
136*d415bd75Srobert     if (!IsSafe)
137*d415bd75Srobert       UnsafeAccesses.insert(I);
138*d415bd75Srobert     updateRange(R);
139*d415bd75Srobert   }
14009467b48Spatrick };
14109467b48Spatrick 
142097a140dSpatrick template <typename CalleeTy>
operator <<(raw_ostream & OS,const UseInfo<CalleeTy> & U)143097a140dSpatrick raw_ostream &operator<<(raw_ostream &OS, const UseInfo<CalleeTy> &U) {
14409467b48Spatrick   OS << U.Range;
14509467b48Spatrick   for (auto &Call : U.Calls)
14673471bf0Spatrick     OS << ", "
14773471bf0Spatrick        << "@" << Call.first.Callee->getName() << "(arg" << Call.first.ParamNo
14873471bf0Spatrick        << ", " << Call.second << ")";
14909467b48Spatrick   return OS;
15009467b48Spatrick }
15109467b48Spatrick 
152097a140dSpatrick /// Calculate the allocation size of a given alloca. Returns empty range
153097a140dSpatrick // in case of confution.
getStaticAllocaSizeRange(const AllocaInst & AI)154097a140dSpatrick ConstantRange getStaticAllocaSizeRange(const AllocaInst &AI) {
155097a140dSpatrick   const DataLayout &DL = AI.getModule()->getDataLayout();
156097a140dSpatrick   TypeSize TS = DL.getTypeAllocSize(AI.getAllocatedType());
157*d415bd75Srobert   unsigned PointerSize = DL.getPointerTypeSizeInBits(AI.getType());
158097a140dSpatrick   // Fallback to empty range for alloca size.
159097a140dSpatrick   ConstantRange R = ConstantRange::getEmpty(PointerSize);
160097a140dSpatrick   if (TS.isScalable())
161097a140dSpatrick     return R;
162*d415bd75Srobert   APInt APSize(PointerSize, TS.getFixedValue(), true);
163097a140dSpatrick   if (APSize.isNonPositive())
164097a140dSpatrick     return R;
165097a140dSpatrick   if (AI.isArrayAllocation()) {
166097a140dSpatrick     const auto *C = dyn_cast<ConstantInt>(AI.getArraySize());
16709467b48Spatrick     if (!C)
168097a140dSpatrick       return R;
169097a140dSpatrick     bool Overflow = false;
170097a140dSpatrick     APInt Mul = C->getValue();
171097a140dSpatrick     if (Mul.isNonPositive())
172097a140dSpatrick       return R;
173097a140dSpatrick     Mul = Mul.sextOrTrunc(PointerSize);
174097a140dSpatrick     APSize = APSize.smul_ov(Mul, Overflow);
175097a140dSpatrick     if (Overflow)
176097a140dSpatrick       return R;
17709467b48Spatrick   }
178*d415bd75Srobert   R = ConstantRange(APInt::getZero(PointerSize), APSize);
179097a140dSpatrick   assert(!isUnsafe(R));
180097a140dSpatrick   return R;
18109467b48Spatrick }
18209467b48Spatrick 
183097a140dSpatrick template <typename CalleeTy> struct FunctionInfo {
184097a140dSpatrick   std::map<const AllocaInst *, UseInfo<CalleeTy>> Allocas;
185097a140dSpatrick   std::map<uint32_t, UseInfo<CalleeTy>> Params;
18609467b48Spatrick   // TODO: describe return value as depending on one or more of its arguments.
18709467b48Spatrick 
18809467b48Spatrick   // StackSafetyDataFlowAnalysis counter stored here for faster access.
18909467b48Spatrick   int UpdateCount = 0;
19009467b48Spatrick 
print__anonc76328400111::FunctionInfo191097a140dSpatrick   void print(raw_ostream &O, StringRef Name, const Function *F) const {
19209467b48Spatrick     // TODO: Consider different printout format after
19309467b48Spatrick     // StackSafetyDataFlowAnalysis. Calls and parameters are irrelevant then.
194097a140dSpatrick     O << "  @" << Name << ((F && F->isDSOLocal()) ? "" : " dso_preemptable")
195097a140dSpatrick       << ((F && F->isInterposable()) ? " interposable" : "") << "\n";
196097a140dSpatrick 
19709467b48Spatrick     O << "    args uses:\n";
198097a140dSpatrick     for (auto &KV : Params) {
199097a140dSpatrick       O << "      ";
200097a140dSpatrick       if (F)
201097a140dSpatrick         O << F->getArg(KV.first)->getName();
202097a140dSpatrick       else
203097a140dSpatrick         O << formatv("arg{0}", KV.first);
204097a140dSpatrick       O << "[]: " << KV.second << "\n";
20509467b48Spatrick     }
20609467b48Spatrick 
207097a140dSpatrick     O << "    allocas uses:\n";
208097a140dSpatrick     if (F) {
209*d415bd75Srobert       for (const auto &I : instructions(F)) {
210097a140dSpatrick         if (const AllocaInst *AI = dyn_cast<AllocaInst>(&I)) {
211097a140dSpatrick           auto &AS = Allocas.find(AI)->second;
212097a140dSpatrick           O << "      " << AI->getName() << "["
213097a140dSpatrick             << getStaticAllocaSizeRange(*AI).getUpper() << "]: " << AS << "\n";
214097a140dSpatrick         }
215097a140dSpatrick       }
216097a140dSpatrick     } else {
217097a140dSpatrick       assert(Allocas.empty());
218097a140dSpatrick     }
219097a140dSpatrick   }
22009467b48Spatrick };
22109467b48Spatrick 
222097a140dSpatrick using GVToSSI = std::map<const GlobalValue *, FunctionInfo<GlobalValue>>;
223097a140dSpatrick 
224097a140dSpatrick } // namespace
225097a140dSpatrick 
226097a140dSpatrick struct StackSafetyInfo::InfoTy {
227097a140dSpatrick   FunctionInfo<GlobalValue> Info;
228097a140dSpatrick };
229097a140dSpatrick 
230097a140dSpatrick struct StackSafetyGlobalInfo::InfoTy {
231097a140dSpatrick   GVToSSI Info;
232097a140dSpatrick   SmallPtrSet<const AllocaInst *, 8> SafeAllocas;
233*d415bd75Srobert   std::set<const Instruction *> UnsafeAccesses;
234097a140dSpatrick };
23509467b48Spatrick 
23609467b48Spatrick namespace {
23709467b48Spatrick 
23809467b48Spatrick class StackSafetyLocalAnalysis {
239097a140dSpatrick   Function &F;
24009467b48Spatrick   const DataLayout &DL;
24109467b48Spatrick   ScalarEvolution &SE;
24209467b48Spatrick   unsigned PointerSize = 0;
24309467b48Spatrick 
24409467b48Spatrick   const ConstantRange UnknownRange;
24509467b48Spatrick 
246097a140dSpatrick   ConstantRange offsetFrom(Value *Addr, Value *Base);
247097a140dSpatrick   ConstantRange getAccessRange(Value *Addr, Value *Base,
248097a140dSpatrick                                const ConstantRange &SizeRange);
249097a140dSpatrick   ConstantRange getAccessRange(Value *Addr, Value *Base, TypeSize Size);
25009467b48Spatrick   ConstantRange getMemIntrinsicAccessRange(const MemIntrinsic *MI, const Use &U,
251097a140dSpatrick                                            Value *Base);
25209467b48Spatrick 
253*d415bd75Srobert   void analyzeAllUses(Value *Ptr, UseInfo<GlobalValue> &AS,
254097a140dSpatrick                       const StackLifetime &SL);
25509467b48Spatrick 
256*d415bd75Srobert 
257*d415bd75Srobert   bool isSafeAccess(const Use &U, AllocaInst *AI, const SCEV *AccessSize);
258*d415bd75Srobert   bool isSafeAccess(const Use &U, AllocaInst *AI, Value *V);
259*d415bd75Srobert   bool isSafeAccess(const Use &U, AllocaInst *AI, TypeSize AccessSize);
260*d415bd75Srobert 
26109467b48Spatrick public:
StackSafetyLocalAnalysis(Function & F,ScalarEvolution & SE)262097a140dSpatrick   StackSafetyLocalAnalysis(Function &F, ScalarEvolution &SE)
26309467b48Spatrick       : F(F), DL(F.getParent()->getDataLayout()), SE(SE),
26409467b48Spatrick         PointerSize(DL.getPointerSizeInBits()),
26509467b48Spatrick         UnknownRange(PointerSize, true) {}
26609467b48Spatrick 
26709467b48Spatrick   // Run the transformation on the associated function.
268097a140dSpatrick   FunctionInfo<GlobalValue> run();
26909467b48Spatrick };
27009467b48Spatrick 
offsetFrom(Value * Addr,Value * Base)271097a140dSpatrick ConstantRange StackSafetyLocalAnalysis::offsetFrom(Value *Addr, Value *Base) {
272097a140dSpatrick   if (!SE.isSCEVable(Addr->getType()) || !SE.isSCEVable(Base->getType()))
27309467b48Spatrick     return UnknownRange;
27409467b48Spatrick 
275097a140dSpatrick   auto *PtrTy = IntegerType::getInt8PtrTy(SE.getContext());
276097a140dSpatrick   const SCEV *AddrExp = SE.getTruncateOrZeroExtend(SE.getSCEV(Addr), PtrTy);
277097a140dSpatrick   const SCEV *BaseExp = SE.getTruncateOrZeroExtend(SE.getSCEV(Base), PtrTy);
278097a140dSpatrick   const SCEV *Diff = SE.getMinusSCEV(AddrExp, BaseExp);
27973471bf0Spatrick   if (isa<SCEVCouldNotCompute>(Diff))
28073471bf0Spatrick     return UnknownRange;
281097a140dSpatrick 
282097a140dSpatrick   ConstantRange Offset = SE.getSignedRange(Diff);
283097a140dSpatrick   if (isUnsafe(Offset))
284097a140dSpatrick     return UnknownRange;
285097a140dSpatrick   return Offset.sextOrTrunc(PointerSize);
28609467b48Spatrick }
28709467b48Spatrick 
288097a140dSpatrick ConstantRange
getAccessRange(Value * Addr,Value * Base,const ConstantRange & SizeRange)289097a140dSpatrick StackSafetyLocalAnalysis::getAccessRange(Value *Addr, Value *Base,
290097a140dSpatrick                                          const ConstantRange &SizeRange) {
291097a140dSpatrick   // Zero-size loads and stores do not access memory.
292097a140dSpatrick   if (SizeRange.isEmptySet())
293097a140dSpatrick     return ConstantRange::getEmpty(PointerSize);
294097a140dSpatrick   assert(!isUnsafe(SizeRange));
295097a140dSpatrick 
296097a140dSpatrick   ConstantRange Offsets = offsetFrom(Addr, Base);
297097a140dSpatrick   if (isUnsafe(Offsets))
29809467b48Spatrick     return UnknownRange;
29909467b48Spatrick 
300097a140dSpatrick   Offsets = addOverflowNever(Offsets, SizeRange);
301097a140dSpatrick   if (isUnsafe(Offsets))
302097a140dSpatrick     return UnknownRange;
303097a140dSpatrick   return Offsets;
304097a140dSpatrick }
30509467b48Spatrick 
getAccessRange(Value * Addr,Value * Base,TypeSize Size)306097a140dSpatrick ConstantRange StackSafetyLocalAnalysis::getAccessRange(Value *Addr, Value *Base,
307097a140dSpatrick                                                        TypeSize Size) {
308097a140dSpatrick   if (Size.isScalable())
309097a140dSpatrick     return UnknownRange;
310*d415bd75Srobert   APInt APSize(PointerSize, Size.getFixedValue(), true);
311097a140dSpatrick   if (APSize.isNegative())
312097a140dSpatrick     return UnknownRange;
313*d415bd75Srobert   return getAccessRange(Addr, Base,
314*d415bd75Srobert                         ConstantRange(APInt::getZero(PointerSize), APSize));
31509467b48Spatrick }
31609467b48Spatrick 
getMemIntrinsicAccessRange(const MemIntrinsic * MI,const Use & U,Value * Base)31709467b48Spatrick ConstantRange StackSafetyLocalAnalysis::getMemIntrinsicAccessRange(
318097a140dSpatrick     const MemIntrinsic *MI, const Use &U, Value *Base) {
319097a140dSpatrick   if (const auto *MTI = dyn_cast<MemTransferInst>(MI)) {
32009467b48Spatrick     if (MTI->getRawSource() != U && MTI->getRawDest() != U)
321097a140dSpatrick       return ConstantRange::getEmpty(PointerSize);
32209467b48Spatrick   } else {
32309467b48Spatrick     if (MI->getRawDest() != U)
324097a140dSpatrick       return ConstantRange::getEmpty(PointerSize);
32509467b48Spatrick   }
326097a140dSpatrick 
327097a140dSpatrick   auto *CalculationTy = IntegerType::getIntNTy(SE.getContext(), PointerSize);
328097a140dSpatrick   if (!SE.isSCEVable(MI->getLength()->getType()))
32909467b48Spatrick     return UnknownRange;
330097a140dSpatrick 
331097a140dSpatrick   const SCEV *Expr =
332097a140dSpatrick       SE.getTruncateOrZeroExtend(SE.getSCEV(MI->getLength()), CalculationTy);
333097a140dSpatrick   ConstantRange Sizes = SE.getSignedRange(Expr);
334097a140dSpatrick   if (Sizes.getUpper().isNegative() || isUnsafe(Sizes))
335097a140dSpatrick     return UnknownRange;
336097a140dSpatrick   Sizes = Sizes.sextOrTrunc(PointerSize);
337*d415bd75Srobert   ConstantRange SizeRange(APInt::getZero(PointerSize), Sizes.getUpper() - 1);
338097a140dSpatrick   return getAccessRange(U, Base, SizeRange);
33909467b48Spatrick }
34009467b48Spatrick 
isSafeAccess(const Use & U,AllocaInst * AI,Value * V)341*d415bd75Srobert bool StackSafetyLocalAnalysis::isSafeAccess(const Use &U, AllocaInst *AI,
342*d415bd75Srobert                                             Value *V) {
343*d415bd75Srobert   return isSafeAccess(U, AI, SE.getSCEV(V));
344*d415bd75Srobert }
345*d415bd75Srobert 
isSafeAccess(const Use & U,AllocaInst * AI,TypeSize TS)346*d415bd75Srobert bool StackSafetyLocalAnalysis::isSafeAccess(const Use &U, AllocaInst *AI,
347*d415bd75Srobert                                             TypeSize TS) {
348*d415bd75Srobert   if (TS.isScalable())
349*d415bd75Srobert     return false;
350*d415bd75Srobert   auto *CalculationTy = IntegerType::getIntNTy(SE.getContext(), PointerSize);
351*d415bd75Srobert   const SCEV *SV = SE.getConstant(CalculationTy, TS.getFixedValue());
352*d415bd75Srobert   return isSafeAccess(U, AI, SV);
353*d415bd75Srobert }
354*d415bd75Srobert 
isSafeAccess(const Use & U,AllocaInst * AI,const SCEV * AccessSize)355*d415bd75Srobert bool StackSafetyLocalAnalysis::isSafeAccess(const Use &U, AllocaInst *AI,
356*d415bd75Srobert                                             const SCEV *AccessSize) {
357*d415bd75Srobert 
358*d415bd75Srobert   if (!AI)
359*d415bd75Srobert     return true;
360*d415bd75Srobert   if (isa<SCEVCouldNotCompute>(AccessSize))
361*d415bd75Srobert     return false;
362*d415bd75Srobert 
363*d415bd75Srobert   const auto *I = cast<Instruction>(U.getUser());
364*d415bd75Srobert 
365*d415bd75Srobert   auto ToCharPtr = [&](const SCEV *V) {
366*d415bd75Srobert     auto *PtrTy = IntegerType::getInt8PtrTy(SE.getContext());
367*d415bd75Srobert     return SE.getTruncateOrZeroExtend(V, PtrTy);
368*d415bd75Srobert   };
369*d415bd75Srobert 
370*d415bd75Srobert   const SCEV *AddrExp = ToCharPtr(SE.getSCEV(U.get()));
371*d415bd75Srobert   const SCEV *BaseExp = ToCharPtr(SE.getSCEV(AI));
372*d415bd75Srobert   const SCEV *Diff = SE.getMinusSCEV(AddrExp, BaseExp);
373*d415bd75Srobert   if (isa<SCEVCouldNotCompute>(Diff))
374*d415bd75Srobert     return false;
375*d415bd75Srobert 
376*d415bd75Srobert   auto Size = getStaticAllocaSizeRange(*AI);
377*d415bd75Srobert 
378*d415bd75Srobert   auto *CalculationTy = IntegerType::getIntNTy(SE.getContext(), PointerSize);
379*d415bd75Srobert   auto ToDiffTy = [&](const SCEV *V) {
380*d415bd75Srobert     return SE.getTruncateOrZeroExtend(V, CalculationTy);
381*d415bd75Srobert   };
382*d415bd75Srobert   const SCEV *Min = ToDiffTy(SE.getConstant(Size.getLower()));
383*d415bd75Srobert   const SCEV *Max = SE.getMinusSCEV(ToDiffTy(SE.getConstant(Size.getUpper())),
384*d415bd75Srobert                                     ToDiffTy(AccessSize));
385*d415bd75Srobert   return SE.evaluatePredicateAt(ICmpInst::Predicate::ICMP_SGE, Diff, Min, I)
386*d415bd75Srobert              .value_or(false) &&
387*d415bd75Srobert          SE.evaluatePredicateAt(ICmpInst::Predicate::ICMP_SLE, Diff, Max, I)
388*d415bd75Srobert              .value_or(false);
389*d415bd75Srobert }
390*d415bd75Srobert 
39109467b48Spatrick /// The function analyzes all local uses of Ptr (alloca or argument) and
39209467b48Spatrick /// calculates local access range and all function calls where it was used.
analyzeAllUses(Value * Ptr,UseInfo<GlobalValue> & US,const StackLifetime & SL)393*d415bd75Srobert void StackSafetyLocalAnalysis::analyzeAllUses(Value *Ptr,
394097a140dSpatrick                                               UseInfo<GlobalValue> &US,
395097a140dSpatrick                                               const StackLifetime &SL) {
39609467b48Spatrick   SmallPtrSet<const Value *, 16> Visited;
39709467b48Spatrick   SmallVector<const Value *, 8> WorkList;
39809467b48Spatrick   WorkList.push_back(Ptr);
399*d415bd75Srobert   AllocaInst *AI = dyn_cast<AllocaInst>(Ptr);
40009467b48Spatrick 
40109467b48Spatrick   // A DFS search through all uses of the alloca in bitcasts/PHI/GEPs/etc.
40209467b48Spatrick   while (!WorkList.empty()) {
40309467b48Spatrick     const Value *V = WorkList.pop_back_val();
40409467b48Spatrick     for (const Use &UI : V->uses()) {
405097a140dSpatrick       const auto *I = cast<Instruction>(UI.getUser());
406097a140dSpatrick       if (!SL.isReachable(I))
407097a140dSpatrick         continue;
408097a140dSpatrick 
40909467b48Spatrick       assert(V == UI.get());
41009467b48Spatrick 
41109467b48Spatrick       switch (I->getOpcode()) {
41209467b48Spatrick       case Instruction::Load: {
413097a140dSpatrick         if (AI && !SL.isAliveAfter(AI, I)) {
414*d415bd75Srobert           US.addRange(I, UnknownRange, /*IsSafe=*/false);
415*d415bd75Srobert           break;
416097a140dSpatrick         }
417*d415bd75Srobert         auto TypeSize = DL.getTypeStoreSize(I->getType());
418*d415bd75Srobert         auto AccessRange = getAccessRange(UI, Ptr, TypeSize);
419*d415bd75Srobert         bool Safe = isSafeAccess(UI, AI, TypeSize);
420*d415bd75Srobert         US.addRange(I, AccessRange, Safe);
42109467b48Spatrick         break;
42209467b48Spatrick       }
42309467b48Spatrick 
42409467b48Spatrick       case Instruction::VAArg:
42509467b48Spatrick         // "va-arg" from a pointer is safe.
42609467b48Spatrick         break;
42709467b48Spatrick       case Instruction::Store: {
42809467b48Spatrick         if (V == I->getOperand(0)) {
42909467b48Spatrick           // Stored the pointer - conservatively assume it may be unsafe.
430*d415bd75Srobert           US.addRange(I, UnknownRange, /*IsSafe=*/false);
431*d415bd75Srobert           break;
43209467b48Spatrick         }
433097a140dSpatrick         if (AI && !SL.isAliveAfter(AI, I)) {
434*d415bd75Srobert           US.addRange(I, UnknownRange, /*IsSafe=*/false);
435*d415bd75Srobert           break;
436097a140dSpatrick         }
437*d415bd75Srobert         auto TypeSize = DL.getTypeStoreSize(I->getOperand(0)->getType());
438*d415bd75Srobert         auto AccessRange = getAccessRange(UI, Ptr, TypeSize);
439*d415bd75Srobert         bool Safe = isSafeAccess(UI, AI, TypeSize);
440*d415bd75Srobert         US.addRange(I, AccessRange, Safe);
44109467b48Spatrick         break;
44209467b48Spatrick       }
44309467b48Spatrick 
44409467b48Spatrick       case Instruction::Ret:
44509467b48Spatrick         // Information leak.
44609467b48Spatrick         // FIXME: Process parameters correctly. This is a leak only if we return
44709467b48Spatrick         // alloca.
448*d415bd75Srobert         US.addRange(I, UnknownRange, /*IsSafe=*/false);
449*d415bd75Srobert         break;
45009467b48Spatrick 
45109467b48Spatrick       case Instruction::Call:
45209467b48Spatrick       case Instruction::Invoke: {
45309467b48Spatrick         if (I->isLifetimeStartOrEnd())
45409467b48Spatrick           break;
45509467b48Spatrick 
456097a140dSpatrick         if (AI && !SL.isAliveAfter(AI, I)) {
457*d415bd75Srobert           US.addRange(I, UnknownRange, /*IsSafe=*/false);
458*d415bd75Srobert           break;
459097a140dSpatrick         }
46009467b48Spatrick         if (const MemIntrinsic *MI = dyn_cast<MemIntrinsic>(I)) {
461*d415bd75Srobert           auto AccessRange = getMemIntrinsicAccessRange(MI, UI, Ptr);
462*d415bd75Srobert           bool Safe = false;
463*d415bd75Srobert           if (const auto *MTI = dyn_cast<MemTransferInst>(MI)) {
464*d415bd75Srobert             if (MTI->getRawSource() != UI && MTI->getRawDest() != UI)
465*d415bd75Srobert               Safe = true;
466*d415bd75Srobert           } else if (MI->getRawDest() != UI) {
467*d415bd75Srobert             Safe = true;
468*d415bd75Srobert           }
469*d415bd75Srobert           Safe = Safe || isSafeAccess(UI, AI, MI->getLength());
470*d415bd75Srobert           US.addRange(I, AccessRange, Safe);
47109467b48Spatrick           break;
47209467b48Spatrick         }
47309467b48Spatrick 
474097a140dSpatrick         const auto &CB = cast<CallBase>(*I);
475*d415bd75Srobert         if (CB.getReturnedArgOperand() == V) {
476*d415bd75Srobert           if (Visited.insert(I).second)
477*d415bd75Srobert             WorkList.push_back(cast<const Instruction>(I));
478*d415bd75Srobert         }
479*d415bd75Srobert 
480097a140dSpatrick         if (!CB.isArgOperand(&UI)) {
481*d415bd75Srobert           US.addRange(I, UnknownRange, /*IsSafe=*/false);
482*d415bd75Srobert           break;
483097a140dSpatrick         }
484097a140dSpatrick 
485097a140dSpatrick         unsigned ArgNo = CB.getArgOperandNo(&UI);
486097a140dSpatrick         if (CB.isByValArgument(ArgNo)) {
487*d415bd75Srobert           auto TypeSize = DL.getTypeStoreSize(CB.getParamByValType(ArgNo));
488*d415bd75Srobert           auto AccessRange = getAccessRange(UI, Ptr, TypeSize);
489*d415bd75Srobert           bool Safe = isSafeAccess(UI, AI, TypeSize);
490*d415bd75Srobert           US.addRange(I, AccessRange, Safe);
491097a140dSpatrick           break;
492097a140dSpatrick         }
493097a140dSpatrick 
49409467b48Spatrick         // FIXME: consult devirt?
49509467b48Spatrick         // Do not follow aliases, otherwise we could inadvertently follow
49609467b48Spatrick         // dso_preemptable aliases or aliases with interposable linkage.
49709467b48Spatrick         const GlobalValue *Callee =
498097a140dSpatrick             dyn_cast<GlobalValue>(CB.getCalledOperand()->stripPointerCasts());
49909467b48Spatrick         if (!Callee) {
500*d415bd75Srobert           US.addRange(I, UnknownRange, /*IsSafe=*/false);
501*d415bd75Srobert           break;
50209467b48Spatrick         }
50309467b48Spatrick 
50409467b48Spatrick         assert(isa<Function>(Callee) || isa<GlobalAlias>(Callee));
50573471bf0Spatrick         ConstantRange Offsets = offsetFrom(UI, Ptr);
50673471bf0Spatrick         auto Insert =
50773471bf0Spatrick             US.Calls.emplace(CallInfo<GlobalValue>(Callee, ArgNo), Offsets);
50873471bf0Spatrick         if (!Insert.second)
50973471bf0Spatrick           Insert.first->second = Insert.first->second.unionWith(Offsets);
51009467b48Spatrick         break;
51109467b48Spatrick       }
51209467b48Spatrick 
51309467b48Spatrick       default:
51409467b48Spatrick         if (Visited.insert(I).second)
51509467b48Spatrick           WorkList.push_back(cast<const Instruction>(I));
51609467b48Spatrick       }
51709467b48Spatrick     }
51809467b48Spatrick   }
51909467b48Spatrick }
52009467b48Spatrick 
run()521097a140dSpatrick FunctionInfo<GlobalValue> StackSafetyLocalAnalysis::run() {
522097a140dSpatrick   FunctionInfo<GlobalValue> Info;
52309467b48Spatrick   assert(!F.isDeclaration() &&
52409467b48Spatrick          "Can't run StackSafety on a function declaration");
52509467b48Spatrick 
52609467b48Spatrick   LLVM_DEBUG(dbgs() << "[StackSafety] " << F.getName() << "\n");
52709467b48Spatrick 
528097a140dSpatrick   SmallVector<AllocaInst *, 64> Allocas;
529097a140dSpatrick   for (auto &I : instructions(F))
530097a140dSpatrick     if (auto *AI = dyn_cast<AllocaInst>(&I))
531097a140dSpatrick       Allocas.push_back(AI);
532097a140dSpatrick   StackLifetime SL(F, Allocas, StackLifetime::LivenessType::Must);
533097a140dSpatrick   SL.run();
534097a140dSpatrick 
535097a140dSpatrick   for (auto *AI : Allocas) {
536097a140dSpatrick     auto &UI = Info.Allocas.emplace(AI, PointerSize).first->second;
537097a140dSpatrick     analyzeAllUses(AI, UI, SL);
538097a140dSpatrick   }
539097a140dSpatrick 
54073471bf0Spatrick   for (Argument &A : F.args()) {
541097a140dSpatrick     // Non pointers and bypass arguments are not going to be used in any global
542097a140dSpatrick     // processing.
543097a140dSpatrick     if (A.getType()->isPointerTy() && !A.hasByValAttr()) {
544097a140dSpatrick       auto &UI = Info.Params.emplace(A.getArgNo(), PointerSize).first->second;
545097a140dSpatrick       analyzeAllUses(&A, UI, SL);
54609467b48Spatrick     }
54709467b48Spatrick   }
54809467b48Spatrick 
549097a140dSpatrick   LLVM_DEBUG(Info.print(dbgs(), F.getName(), &F));
550*d415bd75Srobert   LLVM_DEBUG(dbgs() << "\n[StackSafety] done\n");
551097a140dSpatrick   return Info;
55209467b48Spatrick }
55309467b48Spatrick 
554097a140dSpatrick template <typename CalleeTy> class StackSafetyDataFlowAnalysis {
555097a140dSpatrick   using FunctionMap = std::map<const CalleeTy *, FunctionInfo<CalleeTy>>;
55609467b48Spatrick 
55709467b48Spatrick   FunctionMap Functions;
55809467b48Spatrick   const ConstantRange UnknownRange;
55909467b48Spatrick 
560097a140dSpatrick   // Callee-to-Caller multimap.
561097a140dSpatrick   DenseMap<const CalleeTy *, SmallVector<const CalleeTy *, 4>> Callers;
562097a140dSpatrick   SetVector<const CalleeTy *> WorkList;
563097a140dSpatrick 
564097a140dSpatrick   bool updateOneUse(UseInfo<CalleeTy> &US, bool UpdateToFullSet);
565097a140dSpatrick   void updateOneNode(const CalleeTy *Callee, FunctionInfo<CalleeTy> &FS);
updateOneNode(const CalleeTy * Callee)566097a140dSpatrick   void updateOneNode(const CalleeTy *Callee) {
56709467b48Spatrick     updateOneNode(Callee, Functions.find(Callee)->second);
56809467b48Spatrick   }
updateAllNodes()56909467b48Spatrick   void updateAllNodes() {
57009467b48Spatrick     for (auto &F : Functions)
57109467b48Spatrick       updateOneNode(F.first, F.second);
57209467b48Spatrick   }
57309467b48Spatrick   void runDataFlow();
57409467b48Spatrick #ifndef NDEBUG
57509467b48Spatrick   void verifyFixedPoint();
57609467b48Spatrick #endif
57709467b48Spatrick 
57809467b48Spatrick public:
StackSafetyDataFlowAnalysis(uint32_t PointerBitWidth,FunctionMap Functions)579097a140dSpatrick   StackSafetyDataFlowAnalysis(uint32_t PointerBitWidth, FunctionMap Functions)
580097a140dSpatrick       : Functions(std::move(Functions)),
581097a140dSpatrick         UnknownRange(ConstantRange::getFull(PointerBitWidth)) {}
582097a140dSpatrick 
583097a140dSpatrick   const FunctionMap &run();
584097a140dSpatrick 
585097a140dSpatrick   ConstantRange getArgumentAccessRange(const CalleeTy *Callee, unsigned ParamNo,
586097a140dSpatrick                                        const ConstantRange &Offsets) const;
58709467b48Spatrick };
58809467b48Spatrick 
589097a140dSpatrick template <typename CalleeTy>
getArgumentAccessRange(const CalleeTy * Callee,unsigned ParamNo,const ConstantRange & Offsets) const590097a140dSpatrick ConstantRange StackSafetyDataFlowAnalysis<CalleeTy>::getArgumentAccessRange(
591097a140dSpatrick     const CalleeTy *Callee, unsigned ParamNo,
592097a140dSpatrick     const ConstantRange &Offsets) const {
593097a140dSpatrick   auto FnIt = Functions.find(Callee);
59409467b48Spatrick   // Unknown callee (outside of LTO domain or an indirect call).
595097a140dSpatrick   if (FnIt == Functions.end())
59609467b48Spatrick     return UnknownRange;
597097a140dSpatrick   auto &FS = FnIt->second;
598097a140dSpatrick   auto ParamIt = FS.Params.find(ParamNo);
599097a140dSpatrick   if (ParamIt == FS.Params.end())
60009467b48Spatrick     return UnknownRange;
601097a140dSpatrick   auto &Access = ParamIt->second.Range;
602097a140dSpatrick   if (Access.isEmptySet())
603097a140dSpatrick     return Access;
604097a140dSpatrick   if (Access.isFullSet())
60509467b48Spatrick     return UnknownRange;
606097a140dSpatrick   return addOverflowNever(Access, Offsets);
60709467b48Spatrick }
60809467b48Spatrick 
609097a140dSpatrick template <typename CalleeTy>
updateOneUse(UseInfo<CalleeTy> & US,bool UpdateToFullSet)610097a140dSpatrick bool StackSafetyDataFlowAnalysis<CalleeTy>::updateOneUse(UseInfo<CalleeTy> &US,
61109467b48Spatrick                                                          bool UpdateToFullSet) {
61209467b48Spatrick   bool Changed = false;
61373471bf0Spatrick   for (auto &KV : US.Calls) {
61473471bf0Spatrick     assert(!KV.second.isEmptySet() &&
61509467b48Spatrick            "Param range can't be empty-set, invalid offset range");
61609467b48Spatrick 
617097a140dSpatrick     ConstantRange CalleeRange =
61873471bf0Spatrick         getArgumentAccessRange(KV.first.Callee, KV.first.ParamNo, KV.second);
61909467b48Spatrick     if (!US.Range.contains(CalleeRange)) {
62009467b48Spatrick       Changed = true;
62109467b48Spatrick       if (UpdateToFullSet)
62209467b48Spatrick         US.Range = UnknownRange;
62309467b48Spatrick       else
62473471bf0Spatrick         US.updateRange(CalleeRange);
62509467b48Spatrick     }
62609467b48Spatrick   }
62709467b48Spatrick   return Changed;
62809467b48Spatrick }
62909467b48Spatrick 
630097a140dSpatrick template <typename CalleeTy>
updateOneNode(const CalleeTy * Callee,FunctionInfo<CalleeTy> & FS)631097a140dSpatrick void StackSafetyDataFlowAnalysis<CalleeTy>::updateOneNode(
632097a140dSpatrick     const CalleeTy *Callee, FunctionInfo<CalleeTy> &FS) {
63309467b48Spatrick   bool UpdateToFullSet = FS.UpdateCount > StackSafetyMaxIterations;
63409467b48Spatrick   bool Changed = false;
635097a140dSpatrick   for (auto &KV : FS.Params)
636097a140dSpatrick     Changed |= updateOneUse(KV.second, UpdateToFullSet);
63709467b48Spatrick 
63809467b48Spatrick   if (Changed) {
63909467b48Spatrick     LLVM_DEBUG(dbgs() << "=== update [" << FS.UpdateCount
640097a140dSpatrick                       << (UpdateToFullSet ? ", full-set" : "") << "] " << &FS
641097a140dSpatrick                       << "\n");
64209467b48Spatrick     // Callers of this function may need updating.
64309467b48Spatrick     for (auto &CallerID : Callers[Callee])
64409467b48Spatrick       WorkList.insert(CallerID);
64509467b48Spatrick 
64609467b48Spatrick     ++FS.UpdateCount;
64709467b48Spatrick   }
64809467b48Spatrick }
64909467b48Spatrick 
650097a140dSpatrick template <typename CalleeTy>
runDataFlow()651097a140dSpatrick void StackSafetyDataFlowAnalysis<CalleeTy>::runDataFlow() {
652097a140dSpatrick   SmallVector<const CalleeTy *, 16> Callees;
65309467b48Spatrick   for (auto &F : Functions) {
65409467b48Spatrick     Callees.clear();
655097a140dSpatrick     auto &FS = F.second;
656097a140dSpatrick     for (auto &KV : FS.Params)
657097a140dSpatrick       for (auto &CS : KV.second.Calls)
65873471bf0Spatrick         Callees.push_back(CS.first.Callee);
65909467b48Spatrick 
66009467b48Spatrick     llvm::sort(Callees);
66109467b48Spatrick     Callees.erase(std::unique(Callees.begin(), Callees.end()), Callees.end());
66209467b48Spatrick 
66309467b48Spatrick     for (auto &Callee : Callees)
66409467b48Spatrick       Callers[Callee].push_back(F.first);
66509467b48Spatrick   }
66609467b48Spatrick 
66709467b48Spatrick   updateAllNodes();
66809467b48Spatrick 
66909467b48Spatrick   while (!WorkList.empty()) {
670*d415bd75Srobert     const CalleeTy *Callee = WorkList.pop_back_val();
67109467b48Spatrick     updateOneNode(Callee);
67209467b48Spatrick   }
67309467b48Spatrick }
67409467b48Spatrick 
67509467b48Spatrick #ifndef NDEBUG
676097a140dSpatrick template <typename CalleeTy>
verifyFixedPoint()677097a140dSpatrick void StackSafetyDataFlowAnalysis<CalleeTy>::verifyFixedPoint() {
67809467b48Spatrick   WorkList.clear();
67909467b48Spatrick   updateAllNodes();
68009467b48Spatrick   assert(WorkList.empty());
68109467b48Spatrick }
68209467b48Spatrick #endif
68309467b48Spatrick 
684097a140dSpatrick template <typename CalleeTy>
685097a140dSpatrick const typename StackSafetyDataFlowAnalysis<CalleeTy>::FunctionMap &
run()686097a140dSpatrick StackSafetyDataFlowAnalysis<CalleeTy>::run() {
68709467b48Spatrick   runDataFlow();
68809467b48Spatrick   LLVM_DEBUG(verifyFixedPoint());
689097a140dSpatrick   return Functions;
690097a140dSpatrick }
69109467b48Spatrick 
findCalleeFunctionSummary(ValueInfo VI,StringRef ModuleId)69273471bf0Spatrick FunctionSummary *findCalleeFunctionSummary(ValueInfo VI, StringRef ModuleId) {
69373471bf0Spatrick   if (!VI)
69473471bf0Spatrick     return nullptr;
69573471bf0Spatrick   auto SummaryList = VI.getSummaryList();
69673471bf0Spatrick   GlobalValueSummary* S = nullptr;
69773471bf0Spatrick   for (const auto& GVS : SummaryList) {
69873471bf0Spatrick     if (!GVS->isLive())
69973471bf0Spatrick       continue;
70073471bf0Spatrick     if (const AliasSummary *AS = dyn_cast<AliasSummary>(GVS.get()))
70173471bf0Spatrick       if (!AS->hasAliasee())
70273471bf0Spatrick         continue;
70373471bf0Spatrick     if (!isa<FunctionSummary>(GVS->getBaseObject()))
70473471bf0Spatrick       continue;
70573471bf0Spatrick     if (GlobalValue::isLocalLinkage(GVS->linkage())) {
70673471bf0Spatrick       if (GVS->modulePath() == ModuleId) {
70773471bf0Spatrick         S = GVS.get();
70873471bf0Spatrick         break;
70973471bf0Spatrick       }
71073471bf0Spatrick     } else if (GlobalValue::isExternalLinkage(GVS->linkage())) {
71173471bf0Spatrick       if (S) {
71273471bf0Spatrick         ++NumIndexCalleeMultipleExternal;
71373471bf0Spatrick         return nullptr;
71473471bf0Spatrick       }
71573471bf0Spatrick       S = GVS.get();
71673471bf0Spatrick     } else if (GlobalValue::isWeakLinkage(GVS->linkage())) {
71773471bf0Spatrick       if (S) {
71873471bf0Spatrick         ++NumIndexCalleeMultipleWeak;
71973471bf0Spatrick         return nullptr;
72073471bf0Spatrick       }
72173471bf0Spatrick       S = GVS.get();
72273471bf0Spatrick     } else if (GlobalValue::isAvailableExternallyLinkage(GVS->linkage()) ||
72373471bf0Spatrick                GlobalValue::isLinkOnceLinkage(GVS->linkage())) {
72473471bf0Spatrick       if (SummaryList.size() == 1)
72573471bf0Spatrick         S = GVS.get();
72673471bf0Spatrick       // According thinLTOResolvePrevailingGUID these are unlikely prevailing.
72773471bf0Spatrick     } else {
72873471bf0Spatrick       ++NumIndexCalleeUnhandled;
72973471bf0Spatrick     }
73073471bf0Spatrick   };
731097a140dSpatrick   while (S) {
732097a140dSpatrick     if (!S->isLive() || !S->isDSOLocal())
733097a140dSpatrick       return nullptr;
734097a140dSpatrick     if (FunctionSummary *FS = dyn_cast<FunctionSummary>(S))
735097a140dSpatrick       return FS;
736097a140dSpatrick     AliasSummary *AS = dyn_cast<AliasSummary>(S);
73773471bf0Spatrick     if (!AS || !AS->hasAliasee())
738097a140dSpatrick       return nullptr;
739097a140dSpatrick     S = AS->getBaseObject();
740097a140dSpatrick     if (S == AS)
741097a140dSpatrick       return nullptr;
742097a140dSpatrick   }
743097a140dSpatrick   return nullptr;
744097a140dSpatrick }
745097a140dSpatrick 
findCalleeInModule(const GlobalValue * GV)746097a140dSpatrick const Function *findCalleeInModule(const GlobalValue *GV) {
747097a140dSpatrick   while (GV) {
748097a140dSpatrick     if (GV->isDeclaration() || GV->isInterposable() || !GV->isDSOLocal())
749097a140dSpatrick       return nullptr;
750097a140dSpatrick     if (const Function *F = dyn_cast<Function>(GV))
751097a140dSpatrick       return F;
752097a140dSpatrick     const GlobalAlias *A = dyn_cast<GlobalAlias>(GV);
753097a140dSpatrick     if (!A)
754097a140dSpatrick       return nullptr;
755*d415bd75Srobert     GV = A->getAliaseeObject();
756097a140dSpatrick     if (GV == A)
757097a140dSpatrick       return nullptr;
758097a140dSpatrick   }
759097a140dSpatrick   return nullptr;
760097a140dSpatrick }
761097a140dSpatrick 
findParamAccess(const FunctionSummary & FS,uint32_t ParamNo)762097a140dSpatrick const ConstantRange *findParamAccess(const FunctionSummary &FS,
763097a140dSpatrick                                      uint32_t ParamNo) {
764097a140dSpatrick   assert(FS.isLive());
765097a140dSpatrick   assert(FS.isDSOLocal());
766*d415bd75Srobert   for (const auto &PS : FS.paramAccesses())
767097a140dSpatrick     if (ParamNo == PS.ParamNo)
768097a140dSpatrick       return &PS.Use;
769097a140dSpatrick   return nullptr;
770097a140dSpatrick }
771097a140dSpatrick 
resolveAllCalls(UseInfo<GlobalValue> & Use,const ModuleSummaryIndex * Index)772097a140dSpatrick void resolveAllCalls(UseInfo<GlobalValue> &Use,
773097a140dSpatrick                      const ModuleSummaryIndex *Index) {
774097a140dSpatrick   ConstantRange FullSet(Use.Range.getBitWidth(), true);
77573471bf0Spatrick   // Move Use.Calls to a temp storage and repopulate - don't use std::move as it
77673471bf0Spatrick   // leaves Use.Calls in an undefined state.
77773471bf0Spatrick   UseInfo<GlobalValue>::CallsTy TmpCalls;
77873471bf0Spatrick   std::swap(TmpCalls, Use.Calls);
77973471bf0Spatrick   for (const auto &C : TmpCalls) {
78073471bf0Spatrick     const Function *F = findCalleeInModule(C.first.Callee);
781097a140dSpatrick     if (F) {
78273471bf0Spatrick       Use.Calls.emplace(CallInfo<GlobalValue>(F, C.first.ParamNo), C.second);
783097a140dSpatrick       continue;
784097a140dSpatrick     }
785097a140dSpatrick 
786097a140dSpatrick     if (!Index)
787097a140dSpatrick       return Use.updateRange(FullSet);
78873471bf0Spatrick     FunctionSummary *FS =
78973471bf0Spatrick         findCalleeFunctionSummary(Index->getValueInfo(C.first.Callee->getGUID()),
79073471bf0Spatrick                                   C.first.Callee->getParent()->getModuleIdentifier());
79173471bf0Spatrick     ++NumModuleCalleeLookupTotal;
79273471bf0Spatrick     if (!FS) {
79373471bf0Spatrick       ++NumModuleCalleeLookupFailed;
794097a140dSpatrick       return Use.updateRange(FullSet);
79573471bf0Spatrick     }
79673471bf0Spatrick     const ConstantRange *Found = findParamAccess(*FS, C.first.ParamNo);
79773471bf0Spatrick     if (!Found || Found->isFullSet())
798097a140dSpatrick       return Use.updateRange(FullSet);
799097a140dSpatrick     ConstantRange Access = Found->sextOrTrunc(Use.Range.getBitWidth());
80073471bf0Spatrick     if (!Access.isEmptySet())
80173471bf0Spatrick       Use.updateRange(addOverflowNever(Access, C.second));
802097a140dSpatrick   }
803097a140dSpatrick }
804097a140dSpatrick 
createGlobalStackSafetyInfo(std::map<const GlobalValue *,FunctionInfo<GlobalValue>> Functions,const ModuleSummaryIndex * Index)805097a140dSpatrick GVToSSI createGlobalStackSafetyInfo(
806097a140dSpatrick     std::map<const GlobalValue *, FunctionInfo<GlobalValue>> Functions,
807097a140dSpatrick     const ModuleSummaryIndex *Index) {
808097a140dSpatrick   GVToSSI SSI;
809097a140dSpatrick   if (Functions.empty())
81009467b48Spatrick     return SSI;
811097a140dSpatrick 
812097a140dSpatrick   // FIXME: Simplify printing and remove copying here.
813097a140dSpatrick   auto Copy = Functions;
814097a140dSpatrick 
815097a140dSpatrick   for (auto &FnKV : Copy)
81673471bf0Spatrick     for (auto &KV : FnKV.second.Params) {
817097a140dSpatrick       resolveAllCalls(KV.second, Index);
81873471bf0Spatrick       if (KV.second.Range.isFullSet())
81973471bf0Spatrick         KV.second.Calls.clear();
82073471bf0Spatrick     }
821097a140dSpatrick 
822*d415bd75Srobert   uint32_t PointerSize =
823*d415bd75Srobert       Copy.begin()->first->getParent()->getDataLayout().getPointerSizeInBits();
824097a140dSpatrick   StackSafetyDataFlowAnalysis<GlobalValue> SSDFA(PointerSize, std::move(Copy));
825097a140dSpatrick 
826*d415bd75Srobert   for (const auto &F : SSDFA.run()) {
827097a140dSpatrick     auto FI = F.second;
828097a140dSpatrick     auto &SrcF = Functions[F.first];
829097a140dSpatrick     for (auto &KV : FI.Allocas) {
830097a140dSpatrick       auto &A = KV.second;
831097a140dSpatrick       resolveAllCalls(A, Index);
832097a140dSpatrick       for (auto &C : A.Calls) {
83373471bf0Spatrick         A.updateRange(SSDFA.getArgumentAccessRange(C.first.Callee,
83473471bf0Spatrick                                                    C.first.ParamNo, C.second));
835097a140dSpatrick       }
836097a140dSpatrick       // FIXME: This is needed only to preserve calls in print() results.
837097a140dSpatrick       A.Calls = SrcF.Allocas.find(KV.first)->second.Calls;
838097a140dSpatrick     }
839097a140dSpatrick     for (auto &KV : FI.Params) {
840097a140dSpatrick       auto &P = KV.second;
841097a140dSpatrick       P.Calls = SrcF.Params.find(KV.first)->second.Calls;
842097a140dSpatrick     }
843097a140dSpatrick     SSI[F.first] = std::move(FI);
84409467b48Spatrick   }
84509467b48Spatrick 
846097a140dSpatrick   return SSI;
84709467b48Spatrick }
84809467b48Spatrick 
84909467b48Spatrick } // end anonymous namespace
85009467b48Spatrick 
85109467b48Spatrick StackSafetyInfo::StackSafetyInfo() = default;
85209467b48Spatrick 
StackSafetyInfo(Function * F,std::function<ScalarEvolution & ()> GetSE)853097a140dSpatrick StackSafetyInfo::StackSafetyInfo(Function *F,
854097a140dSpatrick                                  std::function<ScalarEvolution &()> GetSE)
855097a140dSpatrick     : F(F), GetSE(GetSE) {}
856097a140dSpatrick 
857097a140dSpatrick StackSafetyInfo::StackSafetyInfo(StackSafetyInfo &&) = default;
858097a140dSpatrick 
859097a140dSpatrick StackSafetyInfo &StackSafetyInfo::operator=(StackSafetyInfo &&) = default;
86009467b48Spatrick 
86109467b48Spatrick StackSafetyInfo::~StackSafetyInfo() = default;
86209467b48Spatrick 
getInfo() const863097a140dSpatrick const StackSafetyInfo::InfoTy &StackSafetyInfo::getInfo() const {
864097a140dSpatrick   if (!Info) {
865097a140dSpatrick     StackSafetyLocalAnalysis SSLA(*F, GetSE());
866097a140dSpatrick     Info.reset(new InfoTy{SSLA.run()});
867097a140dSpatrick   }
868097a140dSpatrick   return *Info;
869097a140dSpatrick }
870097a140dSpatrick 
print(raw_ostream & O) const871097a140dSpatrick void StackSafetyInfo::print(raw_ostream &O) const {
872097a140dSpatrick   getInfo().Info.print(O, F->getName(), dyn_cast<Function>(F));
873*d415bd75Srobert   O << "\n";
874097a140dSpatrick }
875097a140dSpatrick 
getInfo() const876097a140dSpatrick const StackSafetyGlobalInfo::InfoTy &StackSafetyGlobalInfo::getInfo() const {
877097a140dSpatrick   if (!Info) {
878097a140dSpatrick     std::map<const GlobalValue *, FunctionInfo<GlobalValue>> Functions;
879097a140dSpatrick     for (auto &F : M->functions()) {
880097a140dSpatrick       if (!F.isDeclaration()) {
881097a140dSpatrick         auto FI = GetSSI(F).getInfo().Info;
882097a140dSpatrick         Functions.emplace(&F, std::move(FI));
883097a140dSpatrick       }
884097a140dSpatrick     }
885097a140dSpatrick     Info.reset(new InfoTy{
886*d415bd75Srobert         createGlobalStackSafetyInfo(std::move(Functions), Index), {}, {}});
887*d415bd75Srobert 
888097a140dSpatrick     for (auto &FnKV : Info->Info) {
889097a140dSpatrick       for (auto &KV : FnKV.second.Allocas) {
890097a140dSpatrick         ++NumAllocaTotal;
891097a140dSpatrick         const AllocaInst *AI = KV.first;
892*d415bd75Srobert         auto AIRange = getStaticAllocaSizeRange(*AI);
893*d415bd75Srobert         if (AIRange.contains(KV.second.Range)) {
894097a140dSpatrick           Info->SafeAllocas.insert(AI);
895097a140dSpatrick           ++NumAllocaStackSafe;
896097a140dSpatrick         }
897*d415bd75Srobert         Info->UnsafeAccesses.insert(KV.second.UnsafeAccesses.begin(),
898*d415bd75Srobert                                     KV.second.UnsafeAccesses.end());
899097a140dSpatrick       }
900097a140dSpatrick     }
901*d415bd75Srobert 
902097a140dSpatrick     if (StackSafetyPrint)
903097a140dSpatrick       print(errs());
904097a140dSpatrick   }
905097a140dSpatrick   return *Info;
906097a140dSpatrick }
907097a140dSpatrick 
908097a140dSpatrick std::vector<FunctionSummary::ParamAccess>
getParamAccesses(ModuleSummaryIndex & Index) const90973471bf0Spatrick StackSafetyInfo::getParamAccesses(ModuleSummaryIndex &Index) const {
910097a140dSpatrick   // Implementation transforms internal representation of parameter information
911097a140dSpatrick   // into FunctionSummary format.
912097a140dSpatrick   std::vector<FunctionSummary::ParamAccess> ParamAccesses;
913097a140dSpatrick   for (const auto &KV : getInfo().Info.Params) {
914097a140dSpatrick     auto &PS = KV.second;
915097a140dSpatrick     // Parameter accessed by any or unknown offset, represented as FullSet by
916097a140dSpatrick     // StackSafety, is handled as the parameter for which we have no
917097a140dSpatrick     // StackSafety info at all. So drop it to reduce summary size.
918097a140dSpatrick     if (PS.Range.isFullSet())
919097a140dSpatrick       continue;
920097a140dSpatrick 
921097a140dSpatrick     ParamAccesses.emplace_back(KV.first, PS.Range);
922097a140dSpatrick     FunctionSummary::ParamAccess &Param = ParamAccesses.back();
923097a140dSpatrick 
924097a140dSpatrick     Param.Calls.reserve(PS.Calls.size());
925*d415bd75Srobert     for (const auto &C : PS.Calls) {
926097a140dSpatrick       // Parameter forwarded into another function by any or unknown offset
927097a140dSpatrick       // will make ParamAccess::Range as FullSet anyway. So we can drop the
928097a140dSpatrick       // entire parameter like we did above.
929097a140dSpatrick       // TODO(vitalybuka): Return already filtered parameters from getInfo().
93073471bf0Spatrick       if (C.second.isFullSet()) {
931097a140dSpatrick         ParamAccesses.pop_back();
932097a140dSpatrick         break;
933097a140dSpatrick       }
93473471bf0Spatrick       Param.Calls.emplace_back(C.first.ParamNo,
93573471bf0Spatrick                                Index.getOrInsertValueInfo(C.first.Callee),
93673471bf0Spatrick                                C.second);
937097a140dSpatrick     }
938097a140dSpatrick   }
93973471bf0Spatrick   for (FunctionSummary::ParamAccess &Param : ParamAccesses) {
94073471bf0Spatrick     sort(Param.Calls, [](const FunctionSummary::ParamAccess::Call &L,
94173471bf0Spatrick                          const FunctionSummary::ParamAccess::Call &R) {
94273471bf0Spatrick       return std::tie(L.ParamNo, L.Callee) < std::tie(R.ParamNo, R.Callee);
94373471bf0Spatrick     });
94473471bf0Spatrick   }
945097a140dSpatrick   return ParamAccesses;
946097a140dSpatrick }
947097a140dSpatrick 
948097a140dSpatrick StackSafetyGlobalInfo::StackSafetyGlobalInfo() = default;
949097a140dSpatrick 
StackSafetyGlobalInfo(Module * M,std::function<const StackSafetyInfo & (Function & F)> GetSSI,const ModuleSummaryIndex * Index)950097a140dSpatrick StackSafetyGlobalInfo::StackSafetyGlobalInfo(
951097a140dSpatrick     Module *M, std::function<const StackSafetyInfo &(Function &F)> GetSSI,
952097a140dSpatrick     const ModuleSummaryIndex *Index)
953097a140dSpatrick     : M(M), GetSSI(GetSSI), Index(Index) {
954097a140dSpatrick   if (StackSafetyRun)
955097a140dSpatrick     getInfo();
956097a140dSpatrick }
957097a140dSpatrick 
958097a140dSpatrick StackSafetyGlobalInfo::StackSafetyGlobalInfo(StackSafetyGlobalInfo &&) =
959097a140dSpatrick     default;
960097a140dSpatrick 
961097a140dSpatrick StackSafetyGlobalInfo &
962097a140dSpatrick StackSafetyGlobalInfo::operator=(StackSafetyGlobalInfo &&) = default;
963097a140dSpatrick 
964097a140dSpatrick StackSafetyGlobalInfo::~StackSafetyGlobalInfo() = default;
965097a140dSpatrick 
isSafe(const AllocaInst & AI) const966097a140dSpatrick bool StackSafetyGlobalInfo::isSafe(const AllocaInst &AI) const {
967097a140dSpatrick   const auto &Info = getInfo();
968097a140dSpatrick   return Info.SafeAllocas.count(&AI);
969097a140dSpatrick }
970097a140dSpatrick 
stackAccessIsSafe(const Instruction & I) const971*d415bd75Srobert bool StackSafetyGlobalInfo::stackAccessIsSafe(const Instruction &I) const {
972*d415bd75Srobert   const auto &Info = getInfo();
973*d415bd75Srobert   return Info.UnsafeAccesses.find(&I) == Info.UnsafeAccesses.end();
974*d415bd75Srobert }
975*d415bd75Srobert 
print(raw_ostream & O) const976097a140dSpatrick void StackSafetyGlobalInfo::print(raw_ostream &O) const {
977097a140dSpatrick   auto &SSI = getInfo().Info;
978097a140dSpatrick   if (SSI.empty())
979097a140dSpatrick     return;
980097a140dSpatrick   const Module &M = *SSI.begin()->first->getParent();
981*d415bd75Srobert   for (const auto &F : M.functions()) {
982097a140dSpatrick     if (!F.isDeclaration()) {
983097a140dSpatrick       SSI.find(&F)->second.print(O, F.getName(), &F);
984*d415bd75Srobert       O << "    safe accesses:"
985*d415bd75Srobert         << "\n";
986*d415bd75Srobert       for (const auto &I : instructions(F)) {
987*d415bd75Srobert         const CallInst *Call = dyn_cast<CallInst>(&I);
988*d415bd75Srobert         if ((isa<StoreInst>(I) || isa<LoadInst>(I) || isa<MemIntrinsic>(I) ||
989*d415bd75Srobert              (Call && Call->hasByValArgument())) &&
990*d415bd75Srobert             stackAccessIsSafe(I)) {
991*d415bd75Srobert           O << "     " << I << "\n";
992*d415bd75Srobert         }
993*d415bd75Srobert       }
994097a140dSpatrick       O << "\n";
995097a140dSpatrick     }
996097a140dSpatrick   }
997097a140dSpatrick }
998097a140dSpatrick 
dump() const999097a140dSpatrick LLVM_DUMP_METHOD void StackSafetyGlobalInfo::dump() const { print(dbgs()); }
100009467b48Spatrick 
100109467b48Spatrick AnalysisKey StackSafetyAnalysis::Key;
100209467b48Spatrick 
run(Function & F,FunctionAnalysisManager & AM)100309467b48Spatrick StackSafetyInfo StackSafetyAnalysis::run(Function &F,
100409467b48Spatrick                                          FunctionAnalysisManager &AM) {
1005097a140dSpatrick   return StackSafetyInfo(&F, [&AM, &F]() -> ScalarEvolution & {
1006097a140dSpatrick     return AM.getResult<ScalarEvolutionAnalysis>(F);
1007097a140dSpatrick   });
100809467b48Spatrick }
100909467b48Spatrick 
run(Function & F,FunctionAnalysisManager & AM)101009467b48Spatrick PreservedAnalyses StackSafetyPrinterPass::run(Function &F,
101109467b48Spatrick                                               FunctionAnalysisManager &AM) {
101209467b48Spatrick   OS << "'Stack Safety Local Analysis' for function '" << F.getName() << "'\n";
101309467b48Spatrick   AM.getResult<StackSafetyAnalysis>(F).print(OS);
101409467b48Spatrick   return PreservedAnalyses::all();
101509467b48Spatrick }
101609467b48Spatrick 
101709467b48Spatrick char StackSafetyInfoWrapperPass::ID = 0;
101809467b48Spatrick 
StackSafetyInfoWrapperPass()101909467b48Spatrick StackSafetyInfoWrapperPass::StackSafetyInfoWrapperPass() : FunctionPass(ID) {
102009467b48Spatrick   initializeStackSafetyInfoWrapperPassPass(*PassRegistry::getPassRegistry());
102109467b48Spatrick }
102209467b48Spatrick 
getAnalysisUsage(AnalysisUsage & AU) const102309467b48Spatrick void StackSafetyInfoWrapperPass::getAnalysisUsage(AnalysisUsage &AU) const {
1024097a140dSpatrick   AU.addRequiredTransitive<ScalarEvolutionWrapperPass>();
102509467b48Spatrick   AU.setPreservesAll();
102609467b48Spatrick }
102709467b48Spatrick 
print(raw_ostream & O,const Module * M) const102809467b48Spatrick void StackSafetyInfoWrapperPass::print(raw_ostream &O, const Module *M) const {
102909467b48Spatrick   SSI.print(O);
103009467b48Spatrick }
103109467b48Spatrick 
runOnFunction(Function & F)103209467b48Spatrick bool StackSafetyInfoWrapperPass::runOnFunction(Function &F) {
1033097a140dSpatrick   auto *SE = &getAnalysis<ScalarEvolutionWrapperPass>().getSE();
1034097a140dSpatrick   SSI = {&F, [SE]() -> ScalarEvolution & { return *SE; }};
103509467b48Spatrick   return false;
103609467b48Spatrick }
103709467b48Spatrick 
103809467b48Spatrick AnalysisKey StackSafetyGlobalAnalysis::Key;
103909467b48Spatrick 
104009467b48Spatrick StackSafetyGlobalInfo
run(Module & M,ModuleAnalysisManager & AM)104109467b48Spatrick StackSafetyGlobalAnalysis::run(Module &M, ModuleAnalysisManager &AM) {
1042097a140dSpatrick   // FIXME: Lookup Module Summary.
104309467b48Spatrick   FunctionAnalysisManager &FAM =
104409467b48Spatrick       AM.getResult<FunctionAnalysisManagerModuleProxy>(M).getManager();
1045097a140dSpatrick   return {&M,
1046097a140dSpatrick           [&FAM](Function &F) -> const StackSafetyInfo & {
104709467b48Spatrick             return FAM.getResult<StackSafetyAnalysis>(F);
1048097a140dSpatrick           },
1049097a140dSpatrick           nullptr};
105009467b48Spatrick }
105109467b48Spatrick 
run(Module & M,ModuleAnalysisManager & AM)105209467b48Spatrick PreservedAnalyses StackSafetyGlobalPrinterPass::run(Module &M,
105309467b48Spatrick                                                     ModuleAnalysisManager &AM) {
105409467b48Spatrick   OS << "'Stack Safety Analysis' for module '" << M.getName() << "'\n";
1055097a140dSpatrick   AM.getResult<StackSafetyGlobalAnalysis>(M).print(OS);
105609467b48Spatrick   return PreservedAnalyses::all();
105709467b48Spatrick }
105809467b48Spatrick 
105909467b48Spatrick char StackSafetyGlobalInfoWrapperPass::ID = 0;
106009467b48Spatrick 
StackSafetyGlobalInfoWrapperPass()106109467b48Spatrick StackSafetyGlobalInfoWrapperPass::StackSafetyGlobalInfoWrapperPass()
106209467b48Spatrick     : ModulePass(ID) {
106309467b48Spatrick   initializeStackSafetyGlobalInfoWrapperPassPass(
106409467b48Spatrick       *PassRegistry::getPassRegistry());
106509467b48Spatrick }
106609467b48Spatrick 
1067097a140dSpatrick StackSafetyGlobalInfoWrapperPass::~StackSafetyGlobalInfoWrapperPass() = default;
1068097a140dSpatrick 
print(raw_ostream & O,const Module * M) const106909467b48Spatrick void StackSafetyGlobalInfoWrapperPass::print(raw_ostream &O,
107009467b48Spatrick                                              const Module *M) const {
1071097a140dSpatrick   SSGI.print(O);
107209467b48Spatrick }
107309467b48Spatrick 
getAnalysisUsage(AnalysisUsage & AU) const107409467b48Spatrick void StackSafetyGlobalInfoWrapperPass::getAnalysisUsage(
107509467b48Spatrick     AnalysisUsage &AU) const {
1076097a140dSpatrick   AU.setPreservesAll();
107709467b48Spatrick   AU.addRequired<StackSafetyInfoWrapperPass>();
107809467b48Spatrick }
107909467b48Spatrick 
runOnModule(Module & M)108009467b48Spatrick bool StackSafetyGlobalInfoWrapperPass::runOnModule(Module &M) {
1081097a140dSpatrick   const ModuleSummaryIndex *ImportSummary = nullptr;
1082097a140dSpatrick   if (auto *IndexWrapperPass =
1083097a140dSpatrick           getAnalysisIfAvailable<ImmutableModuleSummaryIndexWrapperPass>())
1084097a140dSpatrick     ImportSummary = IndexWrapperPass->getIndex();
1085097a140dSpatrick 
1086097a140dSpatrick   SSGI = {&M,
1087097a140dSpatrick           [this](Function &F) -> const StackSafetyInfo & {
108809467b48Spatrick             return getAnalysis<StackSafetyInfoWrapperPass>(F).getResult();
1089097a140dSpatrick           },
1090097a140dSpatrick           ImportSummary};
109109467b48Spatrick   return false;
109209467b48Spatrick }
109309467b48Spatrick 
needsParamAccessSummary(const Module & M)1094097a140dSpatrick bool llvm::needsParamAccessSummary(const Module &M) {
1095097a140dSpatrick   if (StackSafetyRun)
1096097a140dSpatrick     return true;
1097*d415bd75Srobert   for (const auto &F : M.functions())
1098097a140dSpatrick     if (F.hasFnAttribute(Attribute::SanitizeMemTag))
1099097a140dSpatrick       return true;
1100097a140dSpatrick   return false;
1101097a140dSpatrick }
1102097a140dSpatrick 
generateParamAccessSummary(ModuleSummaryIndex & Index)1103097a140dSpatrick void llvm::generateParamAccessSummary(ModuleSummaryIndex &Index) {
110473471bf0Spatrick   if (!Index.hasParamAccess())
110573471bf0Spatrick     return;
1106097a140dSpatrick   const ConstantRange FullSet(FunctionSummary::ParamAccess::RangeWidth, true);
110773471bf0Spatrick 
110873471bf0Spatrick   auto CountParamAccesses = [&](auto &Stat) {
110973471bf0Spatrick     if (!AreStatisticsEnabled())
111073471bf0Spatrick       return;
111173471bf0Spatrick     for (auto &GVS : Index)
111273471bf0Spatrick       for (auto &GV : GVS.second.SummaryList)
111373471bf0Spatrick         if (FunctionSummary *FS = dyn_cast<FunctionSummary>(GV.get()))
111473471bf0Spatrick           Stat += FS->paramAccesses().size();
111573471bf0Spatrick   };
111673471bf0Spatrick 
111773471bf0Spatrick   CountParamAccesses(NumCombinedParamAccessesBefore);
111873471bf0Spatrick 
1119097a140dSpatrick   std::map<const FunctionSummary *, FunctionInfo<FunctionSummary>> Functions;
1120097a140dSpatrick 
1121097a140dSpatrick   // Convert the ModuleSummaryIndex to a FunctionMap
1122097a140dSpatrick   for (auto &GVS : Index) {
1123097a140dSpatrick     for (auto &GV : GVS.second.SummaryList) {
1124097a140dSpatrick       FunctionSummary *FS = dyn_cast<FunctionSummary>(GV.get());
112573471bf0Spatrick       if (!FS || FS->paramAccesses().empty())
1126097a140dSpatrick         continue;
1127097a140dSpatrick       if (FS->isLive() && FS->isDSOLocal()) {
1128097a140dSpatrick         FunctionInfo<FunctionSummary> FI;
1129*d415bd75Srobert         for (const auto &PS : FS->paramAccesses()) {
1130097a140dSpatrick           auto &US =
1131097a140dSpatrick               FI.Params
1132097a140dSpatrick                   .emplace(PS.ParamNo, FunctionSummary::ParamAccess::RangeWidth)
1133097a140dSpatrick                   .first->second;
1134097a140dSpatrick           US.Range = PS.Use;
1135*d415bd75Srobert           for (const auto &Call : PS.Calls) {
1136097a140dSpatrick             assert(!Call.Offsets.isFullSet());
113773471bf0Spatrick             FunctionSummary *S =
113873471bf0Spatrick                 findCalleeFunctionSummary(Call.Callee, FS->modulePath());
113973471bf0Spatrick             ++NumCombinedCalleeLookupTotal;
1140097a140dSpatrick             if (!S) {
114173471bf0Spatrick               ++NumCombinedCalleeLookupFailed;
1142097a140dSpatrick               US.Range = FullSet;
1143097a140dSpatrick               US.Calls.clear();
1144097a140dSpatrick               break;
1145097a140dSpatrick             }
114673471bf0Spatrick             US.Calls.emplace(CallInfo<FunctionSummary>(S, Call.ParamNo),
114773471bf0Spatrick                              Call.Offsets);
1148097a140dSpatrick           }
1149097a140dSpatrick         }
1150097a140dSpatrick         Functions.emplace(FS, std::move(FI));
1151097a140dSpatrick       }
1152097a140dSpatrick       // Reset data for all summaries. Alive and DSO local will be set back from
1153097a140dSpatrick       // of data flow results below. Anything else will not be accessed
1154097a140dSpatrick       // by ThinLTO backend, so we can save on bitcode size.
1155097a140dSpatrick       FS->setParamAccesses({});
1156097a140dSpatrick     }
1157097a140dSpatrick   }
115873471bf0Spatrick   NumCombinedDataFlowNodes += Functions.size();
1159097a140dSpatrick   StackSafetyDataFlowAnalysis<FunctionSummary> SSDFA(
1160097a140dSpatrick       FunctionSummary::ParamAccess::RangeWidth, std::move(Functions));
1161*d415bd75Srobert   for (const auto &KV : SSDFA.run()) {
1162097a140dSpatrick     std::vector<FunctionSummary::ParamAccess> NewParams;
1163097a140dSpatrick     NewParams.reserve(KV.second.Params.size());
1164*d415bd75Srobert     for (const auto &Param : KV.second.Params) {
116573471bf0Spatrick       // It's not needed as FullSet is processed the same as a missing value.
116673471bf0Spatrick       if (Param.second.Range.isFullSet())
116773471bf0Spatrick         continue;
1168097a140dSpatrick       NewParams.emplace_back();
1169097a140dSpatrick       FunctionSummary::ParamAccess &New = NewParams.back();
1170097a140dSpatrick       New.ParamNo = Param.first;
1171097a140dSpatrick       New.Use = Param.second.Range; // Only range is needed.
1172097a140dSpatrick     }
1173097a140dSpatrick     const_cast<FunctionSummary *>(KV.first)->setParamAccesses(
1174097a140dSpatrick         std::move(NewParams));
1175097a140dSpatrick   }
117673471bf0Spatrick 
117773471bf0Spatrick   CountParamAccesses(NumCombinedParamAccessesAfter);
1178097a140dSpatrick }
1179097a140dSpatrick 
118009467b48Spatrick static const char LocalPassArg[] = "stack-safety-local";
118109467b48Spatrick static const char LocalPassName[] = "Stack Safety Local Analysis";
118209467b48Spatrick INITIALIZE_PASS_BEGIN(StackSafetyInfoWrapperPass, LocalPassArg, LocalPassName,
118309467b48Spatrick                       false, true)
118409467b48Spatrick INITIALIZE_PASS_DEPENDENCY(ScalarEvolutionWrapperPass)
118509467b48Spatrick INITIALIZE_PASS_END(StackSafetyInfoWrapperPass, LocalPassArg, LocalPassName,
118609467b48Spatrick                     false, true)
118709467b48Spatrick 
118809467b48Spatrick static const char GlobalPassName[] = "Stack Safety Analysis";
118909467b48Spatrick INITIALIZE_PASS_BEGIN(StackSafetyGlobalInfoWrapperPass, DEBUG_TYPE,
1190097a140dSpatrick                       GlobalPassName, false, true)
119109467b48Spatrick INITIALIZE_PASS_DEPENDENCY(StackSafetyInfoWrapperPass)
1192097a140dSpatrick INITIALIZE_PASS_DEPENDENCY(ImmutableModuleSummaryIndexWrapperPass)
119309467b48Spatrick INITIALIZE_PASS_END(StackSafetyGlobalInfoWrapperPass, DEBUG_TYPE,
1194097a140dSpatrick                     GlobalPassName, false, true)
1195