mirror of
https://github.com/RPCS3/llvm-mirror.git
synced 2024-11-26 12:43:36 +01:00
6b81c5b99d
When MemCpyOpt performs call slot optimization it will concatenate the `alias.scope` metadata between the function call and the memcpy. However, scoped AA relies on the domains in metadata to be maintained in a caller-callee relationship. Naive concatenation breaks this assumption leading to bad AA results. The fix is to take the intersection of domains then union the scopes within those domains. The original bug came from a case of rust bad codegen which uses this bad aliasing to perform additional memcpy optimizations. As show in the added test case `%src` got forwarded past its lifetime leading to a dereference of garbage data. Testing ninja check-llvm Reviewed By: jeroen.dobbelaere Differential Revision: https://reviews.llvm.org/D91576
40 lines
1.7 KiB
LLVM
40 lines
1.7 KiB
LLVM
; RUN: opt < %s -S -memcpyopt | FileCheck --match-full-lines %s
|
|
|
|
; Make sure callslot optimization merges alias.scope metadata correctly when it merges instructions.
|
|
; Merging here naively generates:
|
|
; call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 8 %dst, i8* align 8 %src, i64 1, i1 false), !alias.scope !3
|
|
; call void @llvm.lifetime.end.p0i8(i64 8, i8* nonnull %src), !noalias !0
|
|
; ...
|
|
; !0 = !{!1}
|
|
; !1 = distinct !{!1, !2, !"callee1: %a"}
|
|
; !2 = distinct !{!2, !"callee1"}
|
|
; !3 = !{!1, !4}
|
|
; !4 = distinct !{!4, !5, !"callee0: %a"}
|
|
; !5 = distinct !{!5, !"callee0"}
|
|
; Which is incorrect because the lifetime.end of %src will now "noalias" the above memcpy.
|
|
define i8 @test(i8 %input) {
|
|
%tmp = alloca i8
|
|
%dst = alloca i8
|
|
%src = alloca i8
|
|
; NOTE: we're matching the full line and looking for the lack of !alias.scope here
|
|
; CHECK: call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 8 %dst, i8* align 8 %src, i64 1, i1 false)
|
|
call void @llvm.lifetime.start.p0i8(i64 8, i8* nonnull %src), !noalias !3
|
|
store i8 %input, i8* %src
|
|
call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 8 %tmp, i8* align 8 %src, i64 1, i1 false), !alias.scope !0
|
|
call void @llvm.lifetime.end.p0i8(i64 8, i8* nonnull %src), !noalias !3
|
|
call void @llvm.memcpy.p0i8.p0i8.i64(i8* align 8 %dst, i8* align 8 %tmp, i64 1, i1 false), !alias.scope !3
|
|
%ret_value = load i8, i8* %dst
|
|
ret i8 %ret_value
|
|
}
|
|
|
|
declare void @llvm.lifetime.start.p0i8(i64, i8* nocapture)
|
|
declare void @llvm.lifetime.end.p0i8(i64, i8* nocapture)
|
|
declare void @llvm.memcpy.p0i8.p0i8.i64(i8*, i8*, i64, i1)
|
|
|
|
!0 = !{!1}
|
|
!1 = distinct !{!1, !2, !"callee0: %a"}
|
|
!2 = distinct !{!2, !"callee0"}
|
|
!3 = !{!4}
|
|
!4 = distinct !{!4, !5, !"callee1: %a"}
|
|
!5 = distinct !{!5, !"callee1"}
|