1 //===------ MemoryBuiltins.cpp - Identify calls to memory builtins --------===//
3 // The LLVM Compiler Infrastructure
5 // This file is distributed under the University of Illinois Open Source
6 // License. See LICENSE.TXT for details.
8 //===----------------------------------------------------------------------===//
10 // This family of functions identifies calls to builtin functions that allocate
13 //===----------------------------------------------------------------------===//
15 #include "llvm/Analysis/MemoryBuiltins.h"
16 #include "llvm/Constants.h"
17 #include "llvm/Instructions.h"
18 #include "llvm/Module.h"
19 #include "llvm/Analysis/ConstantFolding.h"
22 //===----------------------------------------------------------------------===//
23 // malloc Call Utility Functions.
26 /// isMalloc - Returns true if the the value is either a malloc call or a
27 /// bitcast of the result of a malloc call.
28 bool llvm::isMalloc(const Value *I) {
29 return extractMallocCall(I) || extractMallocCallFromBitCast(I);
32 static bool isMallocCall(const CallInst *CI) {
36 Function *Callee = CI->getCalledFunction();
37 if (Callee == 0 || !Callee->isDeclaration() || Callee->getName() != "malloc")
40 // Check malloc prototype.
41 // FIXME: workaround for PR5130, this will be obsolete when a nobuiltin
42 // attribute will exist.
43 const FunctionType *FTy = Callee->getFunctionType();
44 if (FTy->getNumParams() != 1)
46 if (IntegerType *ITy = dyn_cast<IntegerType>(FTy->param_begin()->get())) {
47 if (ITy->getBitWidth() != 32 && ITy->getBitWidth() != 64)
55 /// extractMallocCall - Returns the corresponding CallInst if the instruction
56 /// is a malloc call. Since CallInst::CreateMalloc() only creates calls, we
57 /// ignore InvokeInst here.
58 const CallInst *llvm::extractMallocCall(const Value *I) {
59 const CallInst *CI = dyn_cast<CallInst>(I);
60 return (isMallocCall(CI)) ? CI : NULL;
63 CallInst *llvm::extractMallocCall(Value *I) {
64 CallInst *CI = dyn_cast<CallInst>(I);
65 return (isMallocCall(CI)) ? CI : NULL;
68 static bool isBitCastOfMallocCall(const BitCastInst *BCI) {
72 return isMallocCall(dyn_cast<CallInst>(BCI->getOperand(0)));
75 /// extractMallocCallFromBitCast - Returns the corresponding CallInst if the
76 /// instruction is a bitcast of the result of a malloc call.
77 CallInst *llvm::extractMallocCallFromBitCast(Value *I) {
78 BitCastInst *BCI = dyn_cast<BitCastInst>(I);
79 return (isBitCastOfMallocCall(BCI)) ? cast<CallInst>(BCI->getOperand(0))
83 const CallInst *llvm::extractMallocCallFromBitCast(const Value *I) {
84 const BitCastInst *BCI = dyn_cast<BitCastInst>(I);
85 return (isBitCastOfMallocCall(BCI)) ? cast<CallInst>(BCI->getOperand(0))
89 /// isConstantOne - Return true only if val is constant int 1.
90 static bool isConstantOne(Value *val) {
91 return isa<ConstantInt>(val) && cast<ConstantInt>(val)->isOne();
94 static Value *isArrayMallocHelper(const CallInst *CI, const TargetData *TD) {
98 // Type must be known to determine array size.
99 const Type *T = getMallocAllocatedType(CI);
103 Value *MallocArg = CI->getOperand(1);
104 ConstantExpr *CO = dyn_cast<ConstantExpr>(MallocArg);
105 BinaryOperator *BO = dyn_cast<BinaryOperator>(MallocArg);
107 Constant *ElementSize = ConstantExpr::getSizeOf(T);
108 ElementSize = ConstantExpr::getTruncOrBitCast(ElementSize,
109 MallocArg->getType());
110 Constant *FoldedElementSize =
111 ConstantFoldConstantExpression(cast<ConstantExpr>(ElementSize), TD);
113 // First, check if CI is a non-array malloc.
114 if (CO && ((CO == ElementSize) ||
115 (FoldedElementSize && (CO == FoldedElementSize))))
116 // Match CreateMalloc's use of constant 1 array-size for non-array mallocs.
117 return ConstantInt::get(MallocArg->getType(), 1);
119 // Second, check if CI is an array malloc whose array size can be determined.
120 if (isConstantOne(ElementSize) ||
121 (FoldedElementSize && isConstantOne(FoldedElementSize)))
130 if (CO && ((CO->getOpcode() == Instruction::Mul) ||
131 (CO->getOpcode() == Instruction::Shl))) {
132 Op0 = CO->getOperand(0);
133 Op1 = CO->getOperand(1);
134 Opcode = CO->getOpcode();
136 if (BO && ((BO->getOpcode() == Instruction::Mul) ||
137 (BO->getOpcode() == Instruction::Shl))) {
138 Op0 = BO->getOperand(0);
139 Op1 = BO->getOperand(1);
140 Opcode = BO->getOpcode();
143 // Determine array size if malloc's argument is the product of a mul or shl.
145 if (Opcode == Instruction::Mul) {
146 if ((Op1 == ElementSize) ||
147 (FoldedElementSize && (Op1 == FoldedElementSize)))
148 // ArraySize * ElementSize
150 if ((Op0 == ElementSize) ||
151 (FoldedElementSize && (Op0 == FoldedElementSize)))
152 // ElementSize * ArraySize
155 if (Opcode == Instruction::Shl) {
156 ConstantInt *Op1CI = dyn_cast<ConstantInt>(Op1);
157 if (!Op1CI) return NULL;
159 APInt Op1Int = Op1CI->getValue();
160 uint64_t BitToSet = Op1Int.getLimitedValue(Op1Int.getBitWidth() - 1);
161 Value *Op1Pow = ConstantInt::get(Op1CI->getContext(),
162 APInt(Op1Int.getBitWidth(), 0).set(BitToSet));
163 if (Op0 == ElementSize || (FoldedElementSize && Op0 == FoldedElementSize))
164 // ArraySize << log2(ElementSize)
166 if (Op1Pow == ElementSize ||
167 (FoldedElementSize && Op1Pow == FoldedElementSize))
168 // ElementSize << log2(ArraySize)
173 // We could not determine the malloc array size from MallocArg.
177 /// isArrayMalloc - Returns the corresponding CallInst if the instruction
178 /// is a call to malloc whose array size can be determined and the array size
179 /// is not constant 1. Otherwise, return NULL.
180 CallInst *llvm::isArrayMalloc(Value *I, const TargetData *TD) {
181 CallInst *CI = extractMallocCall(I);
182 Value *ArraySize = isArrayMallocHelper(CI, TD);
185 ArraySize != ConstantInt::get(CI->getOperand(1)->getType(), 1))
188 // CI is a non-array malloc or we can't figure out that it is an array malloc.
192 const CallInst *llvm::isArrayMalloc(const Value *I, const TargetData *TD) {
193 const CallInst *CI = extractMallocCall(I);
194 Value *ArraySize = isArrayMallocHelper(CI, TD);
197 ArraySize != ConstantInt::get(CI->getOperand(1)->getType(), 1))
200 // CI is a non-array malloc or we can't figure out that it is an array malloc.
204 /// getMallocType - Returns the PointerType resulting from the malloc call.
205 /// This PointerType is the result type of the call's only bitcast use.
206 /// If there is no unique bitcast use, then return NULL.
207 const PointerType *llvm::getMallocType(const CallInst *CI) {
208 assert(isMalloc(CI) && "GetMallocType and not malloc call");
210 const BitCastInst *BCI = NULL;
212 // Determine if CallInst has a bitcast use.
213 for (Value::use_const_iterator UI = CI->use_begin(), E = CI->use_end();
215 if ((BCI = dyn_cast<BitCastInst>(cast<Instruction>(*UI++))))
218 // Malloc call has 1 bitcast use and no other uses, so type is the bitcast's
220 if (BCI && CI->hasOneUse())
221 return cast<PointerType>(BCI->getDestTy());
223 // Malloc call was not bitcast, so type is the malloc function's return type.
225 return cast<PointerType>(CI->getType());
227 // Type could not be determined.
231 /// getMallocAllocatedType - Returns the Type allocated by malloc call. This
232 /// Type is the result type of the call's only bitcast use. If there is no
233 /// unique bitcast use, then return NULL.
234 const Type *llvm::getMallocAllocatedType(const CallInst *CI) {
235 const PointerType *PT = getMallocType(CI);
236 return PT ? PT->getElementType() : NULL;
239 /// getMallocArraySize - Returns the array size of a malloc call. If the
240 /// argument passed to malloc is a multiple of the size of the malloced type,
241 /// then return that multiple. For non-array mallocs, the multiple is
242 /// constant 1. Otherwise, return NULL for mallocs whose array size cannot be
244 Value *llvm::getMallocArraySize(CallInst *CI, const TargetData *TD) {
245 return isArrayMallocHelper(CI, TD);
248 //===----------------------------------------------------------------------===//
249 // free Call Utility Functions.
252 /// isFreeCall - Returns true if the the value is a call to the builtin free()
253 bool llvm::isFreeCall(const Value *I) {
254 const CallInst *CI = dyn_cast<CallInst>(I);
257 Function *Callee = CI->getCalledFunction();
258 if (Callee == 0 || !Callee->isDeclaration() || Callee->getName() != "free")
261 // Check free prototype.
262 // FIXME: workaround for PR5130, this will be obsolete when a nobuiltin
263 // attribute will exist.
264 const FunctionType *FTy = Callee->getFunctionType();
265 if (!FTy->getReturnType()->isVoidTy())
267 if (FTy->getNumParams() != 1)
269 if (FTy->param_begin()->get() != Type::getInt8PtrTy(Callee->getContext()))